Jun Zheng 0007

dblp:93/3489-7 · DBLP profile ↗
← Back
26ranked-venue papers
0as first author
16since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 10 · 8 since 2021Databases, data management, data science and information retrieval · 10 · 7 since 2021Computer networks · 7 · 5 since 2021Systems, architecture and hardware · 3 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2025 Toward Mitigating APT Attacks With Zero-Trust Networks Access Control Model
abstract
With the deepening militarization of global cyberspace, cyber threats have evolved into advanced persistent threats (APTs), characterized by high targeting, persistence, and destructiveness, rendering traditional perimeter-based defenses ineffective. In response, researchers have proposed the zero-trust architecture, which enforces strict identity verification for all access requests, whether external or internal, to reduce the attack surface and mitigate APTs lateral movement. However, zero-trust remains largely a conceptual framework rather than a standardized technical solution, with existing approaches primarily integrating conventional security mechanisms under zero-trust principles without systematically deconstructing threats from an APT countermeasure perspective. Consequently, these methods struggle to identify APTs at the tactical and technical level or accurately assess and mitigate APT risks. To address the above problems, this article proposes a access control method within zero-trust network for APT mitigation. First, this article identifies APT tactics, techniques, and procedure that threaten zero-trust by leveraging MITRE ATT&CK mitigations and zero trust maturity model. Next, this article designs an attack detection algorithm using Sigma rules, correlating historical entity behavior with security alerts to uncover APT indicators. Finally, this article establishes a risk assessment framework for network entities based on APT behavioral patterns, devises a trust computation model tailored to APTs, and implements dynamic access control policies weighted by entity trust levels. The experimental results demonstrate the method’s feasibility and effectiveness, achieving 93.1% APT attack detection rate, offering a new approach for mitigating APT attacks.
Jingci Zhang, Jun Zheng 0007, Ning Shi, Zhaohui Ci, Liehuang Zhu
IEEE Internet Things J.2
2025 Enhancing the transferability of adversarial attacks via Scale Enriching
Yuhang Zhao 0003, Jun Zheng 0007, Xianfeng Gao, Quanxin Zhang 0001
Neural Networks2
2024 ATT&CK-based Advanced Persistent Threat attacks risk propagation assessment model for zero trust networks
Jingci Zhang, Jun Zheng 0007, Zheng Zhang 0060, Yu-an Tan 0001, Quanxin Zhang 0001, Yuanzhang Li 0001
Comput. Networks2
2024 Blockchain-and-6G-based Ubiquitous UAV Task Security Management Architecture
Jun Zheng 0007, Shengjun Wei, Changzhen Hu
Comput. Commun.2
2024 Modifying the one-hot encoding technique can enhance the adversarial robustness of the visual model for symbol recognition
Jun Zheng 0007, Huipeng Zhou, Jiaxing Li 0012, Zehui Xiong, Yuanzhang Li 0001
Expert Syst. Appl.2
2024 A blockchain-based ubiquitous entity authentication and management scheme with homomorphic encryption for FANET
Jun Zheng 0007, Teng He, Shengjun Wei, Changzhen Hu
Peer Peer Netw. Appl.2
2023 Clean-label poisoning attacks on federated learning for IoT
abstract
Abstract Federated Learning (FL) is suitable for the application scenarios of distributed edge collaboration of the Internet of Things (IoT). It can provide data security and privacy, which is why it is widely used in the IoT applications such as Industrial IoT (IIoT). Latest research shows that the federated learning framework is vulnerable to poisoning attacks in the case of an active attack by the adversary. However, the existing backdoor attack methods are easy to be detected by the defence methods. To address this challenge, we focus on edge‐cloud synergistic FL clean‐label attacks. Unlike common backdoor attack, to ensure the attack's concealment, we add a small perturbation to realize the clean label attack by judging the cosine similarity between the gradient of the adversarial loss and the gradient of the normal training loss. In order to improve the attack success rate and robustness, the attack is implemented when the global model is about to converge. The experimental results verified that 1% of poisoned data could make an attack successful with a high probability. Our method maintains stealth while performing model poisoning attacks, and the average Peak Signal‐to‐Noise Ratio (PSNR) of poisoning images reaches over 30 dB, and the average Structural SIMilarity (SSIM) is close to 0.93. Most importantly, our attack method can bypass the Byzantine aggregation defence.
Jun Zheng 0007, Thar Baker, Yu-an Tan 0001, Quanxin Zhang 0001
Expert Syst. J. Knowl. Eng.2
2023 TEBDS: A Trusted Execution Environment-and-Blockchain-supported IoT data sharing system
Jun Zheng 0007, Teng He, Shengjun Wei, Changzhen Hu
Future Gener. Comput. Syst.2
2023 B-UAVM: A Blockchain-Supported Secure Multi-UAV Task Management Scheme
abstract
The advent of unmanned aerial vehicle (UAV) swarm technology brings possibilities to help humans complete tasks in no man’s land, such as deserts and rainforests. However, UAV network faces many cyber threats, where attackers can impersonate legitimate entities or tamper with UAV task data. For identity security, most of the existing methods use centralized authentication schemes, which have a single point of failure problem. For data security, the existing methods only secure the task data in the ground system, ignoring the data security in the air network. Therefore, the existing methods are not suitable for ubiquitous UAV scenarios. Blockchain secures data security while eliminating the single point of failure problem, and has been widely used in distributed scenarios. In this article, to secure entity identity and task data, we propose a blockchain-supported secure multi-UAV task management scheme (B-UAVM). Specifically, a three-layer blockchain structure is constructed to secure multitasks, and achieve ubiquitous control of UAV formations. Besides, six types of blocks and three types of transactions are designed to achieve safe processing and storage of task data and entity information. Furthermore, an improved practical byzantine fault tolerance (IPBFT) consensus mechanism and a UAV-formation-action-considered ground station consensus mechanism (UFAGS) are introduced in the Server Network and Ground Control Network, respectively, to accelerate the consensus. The experimental results show that the number of transactions generated per second (TPS) of B-UAVM is about$0.5\times $and$3.7\times $of the existing method when the block size or the number of blockchain nodes increases, respectively.
Jun Zheng 0007, Teng He, Shengjun Wei, Chun Shan, Changzhen Hu
IEEE Internet Things J.2
2023 Deep reinforce learning for joint optimization of condition-based maintenance and spare ordering
Shen-Gang Hao, Jun Zheng 0007, Haipeng Sun, Quanxin Zhang 0001, Li Zhang 0099, Nan Jiang 0021, Yuanzhang Li 0001
Inf. Sci.2
2022 Reward optimization of spatial crowdsourcing for coalition-based maintenance task
abstract
Spatial crowdsourcing (SC) can use the moving workers to achieve location-based tasks. It has been widely used in takeout, data labeling, organizing activities, security and artificial intelligence. Currently, many manufacturers wish to explore SC in maintenance business, as SC can reduce maintenance time, reduce labor costs, and improve customer satisfaction. In maintenance business scenarios, there are two kinds of cooperated participators. One is freedom workers who are sensitive to distance, and the other is employed by manufacturers who are insensitive to distance. Therefore, some methods of SC with one type worker are challenging to apply to maintenance business scenarios directly. To match this scenario, we model the maintenance scenario and prove that this scenario is an NP-hard problem; then, both greedy and Nash equilibrium methods are proposed to complete the tasks for making a high total reward. The greedy algorithm (GA) first assigns the nearest available workers to each task, and the employee will try to join the task to help GM to complete more tasks, on the condition that the task cannot be completed and reaches a particular proportion. The Nash equilibrium algorithm (NA) is used to find a Nash equilibrium for all the workers and employees. The experiments demonstrate the efficiency and effectiveness of the synthetic data set of gMission in small and large data sets. The finished task number of NA is about 5% more than that of GA, and the reward of NA is about 10% more than that of GA.
Shen-Gang Hao, Jun Zheng 0007, Tiancai Liang, Li Zhang 0099
Int. J. Intell. Syst.2
2022 Security of federated learning for cloud-edge intelligence collaborative computing
abstract
Federated Learning (FL) is one of the key technologies to solve privacy protection for cloud-edge intelligent collaborative computing, and its security and privacy issues have attracted extensive attention from academia and industry. FL is a distributed privacy protection framework. Multiple edged nodes or servers jointly train a machine learning model by sharing model parameters without exchanging local data. However, there are still many security risks and privacy threats in FL in edge-cloud collaborative computing. In this paper, we mainly discuss the security and privacy challenges on FL in collaborative computing at the edge. First, we introduce the principle, classification, and threat model of FL in edge-cloud collaboration, which helps understand the challenges faced by edge-cloud collaborative computing. Second, privacy leakage attacks and poisoning attacks launched by adversaries or honest but curious actors are summarized and compared. Then, the problems existing on the attack method are summarized and analyzed. Finally, the future development direction of FL in the field of edge-cloud collaborative computing is further discussed.
Jun Zheng 0007, Zheng Zhang 0060, Q. I. Chen, Duncan S. Wong, Yuanzhang Li 0001
Int. J. Intell. Syst.2
2022 A group key agreement protocol for intelligent internet of things system
abstract
The application of intelligent computing in Internet of Things (IoTs) makes IoTs systems such as telemedicine, in-vehicle IoT, and smart home more intelligent and efficient. Secure communication and secure resource sharing among intelligent terminals are essential. A secure communication channel for intelligent terminals can be established through group key agreement (GKA), thereby ensuring the security communication and resource sharing for intelligent terminals. Taking into account the confidentiality level of the shared resources of each terminal, and the different permissions of the resource sharing of each terminal, a GKA protocol for intelligent IoTs is proposed. Compared with previous work, this protocol mainly has the following advantages: (1) The hidden attribute identity authentication technology can achieve the security of identity authentication and protect personal privacy from being leaked; (2) Only intelligent terminals satisfying the threshold required of the GKA can participate in the GKA, which increases the security of group communication; (3) Low-level group terminals can obtain new permissions to participate in high-level group communication if they meet certain conditions. High-level group terminals can participate in low-level group communication through permission authentication, which increases the flexibility and security of group communication; (4) The intelligent terminals in the group can use their own attribute permission parameters to calculate the group key. They can verify the correctness of the calculated group key through a functional relationship, and does not need to exchange information with other members in the same group. Under the hardness assumption of inverse computational Diffie-Hellman problem and discrete logarithm problem, it is proven that the protocol has high security, and compared with the cited literatures, it has good advantages in terms of computational complexity, time cost and communication energy cost.
Qikun Zhang, Yongjiao Li, Zhaorui Ma, Junling Yuan, Jun Zheng 0007, Shan Ai
Int. J. Intell. Syst.6
2022 Group key agreement protocol among terminals of the intelligent information system for mobile edge computing
abstract
Security communication and information sharing among mobile devices are important application technologies of the intelligent information system (IIS). Because IIS is vulnerable to attacks, so the security of information sharing among mobile devices is seriously threatened. Thence, it is necessary to establish a secure channel for communication among mobile devices of IIS over an opening network. Group key agreement (GKA) can establish a secure channel among mobile devices of IIS by encryption technology. Due to the resource-constraints of mobile devices, such as weak computing power, small storage capacity, and limited communication range. To address these issues, an asymmetric GKA protocol among terminals of IIS for mobile edge computing (GKA–IIS–MEC) network is proposed in this paper. Adopted asymmetric GKA to achieve the group secure communication mechanisms that message sender unfettered in this protocol; the protocol also uses edge computing environment to migrate the computation and communication loads of mobile devices of IIS to edge nodes, thereby ensuring that mobile devices have lightweight computation and communication loads; and the members participating in the GKA can verify whether the group session keys they calculated are correctness. Under the hardness assumption of bilinear inverse Diffie–Hellman problem, the proposed protocol is proven that it can resist negative attacks. After evaluating the performance of the protocol, GKA–IIS–MEC has higher efficiency than the referred works in terms of time cost, communication consumption, and computation consumption.
Qikun Zhang, Junling Yuan, Tiancai Liang, Jun Zheng 0007
Int. J. Intell. Syst.7
2022 Hybrid isolation model for device application sandboxing deployment in Zero Trust architecture
abstract
With recent cyber security attacks, the “border defense” security protection mechanism has often penetrated and broken through, and the “borderless” security defense idea—Zero Trust was proposed. The device application sandbox deployment model is one of the four essential Zero Trust architecture device deployment models. The isolation of the application sandbox directly affects the security of trusted applications. Given the security risks, such as sandbox escape in the sandbox application, we propose a hybrid isolation model based on access behavior and give the formal definition and security characteristics of the model. The model dynamically determines the security identity of the subject according to the access behavior and controls the access operation of the application sandbox. Therefore, the sandbox meets the characteristics of autonomous security, domain isolation, and integrity, ensuring that the system is always in an isolated safe state and easy to use. Finally, we implement the security model based on the container and Linux security module, and test the network and disk performance of this model. What is more, we make security comparison experiments based on the same container escape vulnerability. The experimental results show that the security model proposed in this paper effectively enhances the security of the device application sandboxing deployment model in Zero Trust architecture, and has a better performance compared with Container-SELinux.
Jingci Zhang, Jun Zheng 0007, Zheng Zhang 0060, Kefan Qiu, Quanxin Zhang 0001, Yuanzhang Li 0001
Int. J. Intell. Syst.2
2022 A novel approach based on adaptive online analysis of encrypted traffic for identifying Malware in IIoT
Zequn Niu, Jingfeng Xue, Dacheng Qu, Yong Wang 0010, Jun Zheng 0007
Inf. Sci.5
2020 Butterfly-Based Higher-Order Clustering on Bipartite Networks
Hongchao Qin, Jun Zheng 0007, Fusheng Jin, Rong-Hua Li 0001
KSEM (1)3
2018 Research on Data Recovery Technology Based on Flash Memory Device
Lele Guan, Jun Zheng 0007, Dianxin Wang
ICA3PP (2)2
2018 RootAgency: A digital signature-based root privilege management agency for cloud terminal devices
Yu-an Tan 0001, Yuanzhang Li 0001, Jun Zheng 0007, Quanxin Zhang 0001
Inf. Sci.5
2018 Building covert timing channels by packet rearrangement over mobile networks
Xiaosong Zhang 0002, Quanxin Zhang 0001, Yuanzhang Li 0001, Jun Zheng 0007, Yu-an Tan 0001
Inf. Sci.5
2018 Building packet length covert channel over mobile VoIP traffics
Yu-an Tan 0001, Xiaosong Zhang 0002, Xianmin Wang, Jun Zheng 0007, Quanxin Zhang 0001
J. Netw. Comput. Appl.5
2018 A root privilege management scheme with revocable authorization for Android devices
Yu-an Tan 0001, Jun Zheng 0007, Quanxin Zhang 0001, Yuanzhang Li 0001
J. Netw. Comput. Appl.4
2018 A code protection scheme by process memory relocation for android devices
Xiaosong Zhang 0002, Yu-an Tan 0001, Changyou Zhang, Yuanzhang Li 0001, Jun Zheng 0007
Multim. Tools Appl.6
2018 An optimized data hiding scheme for Deflate codes
Yu-an Tan 0001, Changyou Zhang, Jun Zheng 0007
Soft Comput.5
2017 A round-optimal lattice-based blind signature scheme for cloud services
Yu-an Tan 0001, Xiaosong Zhang 0002, Liehuang Zhu, Changyou Zhang, Jun Zheng 0007
Future Gener. Comput. Syst.6
2015 Virtual experiments for introduction of computing: Using virtual reality technology
abstract
Introduction to Computing is a public course for the first-year non-major undergraduate students, aiming at training students for the abilities in computer science and technology with computational thinking. However, as new computer technologies emerge continuously and rapidly, it is required for this course to accommodate more and more knowledge. Therefore the teaching contents are growing enormously, which makes it very difficult to cover all of them in limited hours, and therefore sets an obstacle in understanding computing principles and building up a clear and general picture of computing, especially for non-major students. As computer science and technology are becoming more and more essential for various disciplines and majors, it is urgent for the education community to find out an effective and propagable way to solve this problem. In this regard, we employ virtual reality technology to the experiment teaching of this course, and have developed 18 virtual experiments to support the whole teaching process. For example, Turing machine is a basic model for computer science and technology. However, since it is not a real machine, it is not easy for the students to imagine the working process of Turing machine and understand the related concepts. Another example, the execution of an instruction is very important to understand the principles of computer organization. However, as the information flow is invisible, it is difficult and time-consuming for the teachers to explain how an instruction is executed inside a computer. Therefore, 3D modeling and animation techniques are used to demonstrate the invisible micro-structure of computers, and human-machine interaction and visualization techniques are used to present the internal process of information evolution, thus constructing a complete virtual experiment system of this course, including demonstration experiments, verification experiments and interaction experiments. Our virtual experiments have applied software copyrights and served more than 12,000 students from five universities of China since 2013. The evaluation demonstrates that the virtual experiments have produced excellent results in both teaching effectiveness and learning efficiency, relieved the conflicts between limited hours and vast knowledge, and helped students understand and build up the knowledge of computing.
Fengxia Li, Jun Zheng 0007, Sanyuan Zhao
FIE3