VLDB 2026 Research / reviewers in the wild / expert
Mi Wen
dblp:93/6953
· DBLP profile ↗
71ranked-venue papers
16as first author
38since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 27 · 6 first-author · 10 since 2021Security and privacy · 18 · 4 first-author · 11 since 2021Artificial intelligence and machine learning · 7 · 2 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 1 first-author · 6 since 2021Systems, architecture and hardware · 3 · 1 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ReasoningGuard: Safeguarding Large Reasoning Models with Inference-time Safety Aha MomentsabstractLarge Reasoning Models (LRMs) have demonstrated impressive performance in reasoningintensive tasks, but they remain vulnerable to harmful content generation, particularly in the mid-to-late steps of their reasoning processes.Current defense methods, however, depend on costly fine-tuning and additional expert knowledge, which limits their scalability.In this work, we propose ReasoningGuard, an inference-time safeguard for LRMs.It injects timely safety aha moments during the reasoning process to guide the model towards harmless yet helpful reasoning.Our approach leverages the internal attention mechanisms of the LRM to accurately identify key points in the reasoning path, triggering safety-oriented reflections.To safeguard both the subsequent reasoning steps and the final answers, we implement a scaling sampling strategy during decoding to select the optimal reasoning path.With minimal additional inference cost, Rea-soningGuard effectively mitigates four types of jailbreak attacks, including recent ones targeting the reasoning process of LRMs.Our approach outperforms nine existing safeguards, providing state-of-the-art defenses while avoiding common exaggerated safety issues. Yuquan Wang, Mi Zhang 0001, Geng Hong, Mi Wen, Xiaoyu You, Min Yang 0002 |
ACL (1) | 5 |
| 2026 | Simulation Model Parameter Calibration via Knowledge-Driven Improved Bayesian Optimization
Danyang Jiang, Minghui Lyu, Zhaopeng Liu, Mi Wen |
ICIC (26) | 4 |
| 2026 | AdvBiTrans: an efficient botnet detection method based on adversarial BiLSTM-Transformer in IIoTabstractAbstract In the Industrial Internet of Things (IIoT), the stealthiness and extensiveness of botnet attacks pose major security challenges, leading to potential data breaches and system outages. While deep learning techniques effectively detect botnets, their increasing complexity often necessitates adding more features. This not only elevates computational costs, but also hinders the timely detection of botnets. Therefore, there is a need for more effective strategies to enhance the security of IIoT systems. We propose an efficient IIoT botnet detection method, AdvBiTrans, that utilizes Pearson Correlation Coefficients Multi-stage Clustering Feature Selection (PMSFCS) and BiLSTM-Transformer framework (BiTrans) with PGD adversarial training, aiming to enhance detection accuracy and reduce feature dependency. The N-BaIoT and CIC-DDoS2019 datasets are analyzed, using data sampling methods to ensure balanced data. Experimental results showed that on the N-BaIoT dataset, the detection accuracy of the most prevalent malware families Mirai and Gafgyt reaches 99.94%, surpassing prior work by 0.44%, with an F1-score of 99.91%. On the CIC-DDoS2019 dataset, the detection accuracy reaches 97.79% after applying data balancing techniques, representing an improvement of 1.89%, with an F1-score of 99.88%. Yong Wang 0055, Zhenyang Yan, Kai Zhang 0016, Mi Wen |
Comput. J. | 4 |
| 2026 | Cdts: a post-quantum threshold signature scheme based on CRYSTALS-dilithium of power grid load regulation systemabstractAbstract Traditional threshold signature schemes, which are based on number-theoretic problems, are vulnerable to attacks in quantum computing environments. Moreover, these schemes incur high communication and computational costs among nodes, which pose significant challenges for meeting the stringent requirements of interactive security and real-time performance in power grid load regulation systems. To address these challenges, this paper introduces a post-quantum threshold signature scheme based on CRYSTALS-Dilithium (CDTS) specifically designed for power grid load regulation systems. Constructed within the Fiat-Shamir framework and integrating a CRYSTALS-Dilithium-based threshold signature, this scheme effectively ensures the system’s fault tolerance and security in the face of quantum computing threats. In terms of efficiency, the CDTS scheme significantly reduces computational overheads through the introduction of rejection sampling techniques and the optimization of the number-theoretic transform algorithm. To further enhance the scheme’s adaptability to the dynamic nature of power grid load regulation, an innovative dynamic threshold adjustment mechanism is proposed. This mechanism monitors load changes in real-time within a $$\Delta T$$ Δ T time window, allowing for flexible adjustments to the threshold parameters. Security analysis confirms that the proposed scheme satisfies the security requirements of power grid load regulation systems, making it a robust solution for ensuring secure and efficient load regulation in the quantum era. We conducted rigorous experimental comparisons under the same security level (NIST Level 3) and system scale ( $$th=5, n=10$$ t h = 5 , n = 10 ), the sizes of the public key (1.32 KB), private key (2.01 KB), and signature (2.45 KB) of the CDTS scheme are almost identical to those of the original Dilithium scheme. This data demonstrates that the threshold construction we proposed is nearly lossless in terms of storage efficiency, significantly outperforming the exponential overhead growth typically brought by traditional scheme. Through rigorous software testing and verification, we evaluated the performance of the CDTS scheme by randomly generating a 59-byte message and iteratively executing the signing process 10,000 times. The results indicate that the CDTS scheme achieves a complete signature and verification process in an average of 506.73 microseconds. This efficiency makes the CDTS scheme highly feasible for practical applications, particularly in environments requiring rapid and secure transaction processing. Mi Wen, Peiqi Li |
Cybersecur. | 1 |
| 2026 | MLDSJ: a multi-level feature joint attribution method for APT group based on threat intelligenceabstractAdvanced persistent threat (APT) attribution is a key defense strategy that can effectively safeguard the security of critical assets and systems. Cyber threat intelligence (CTI) contains rich information about APT groups that can be leveraged for attribution. However, most existing studies focus on a single feature from different perspectives, neglecting the multi-level mining and combined features of CTI, which limits the depth and accuracy of attribution analysis and may even lead to misleading conclusions. To overcome these limitations, we propose a multi-level feature Dempster–Shafer joint (MLDSJ) attribution method for APT groups based on threat intelligence. Specifically, we extract multi-level features such as attack patterns, textual information, and graph topology from CTI reports to construct feature vectors. Subsequently, we classify the three types of features separately using simple machine learning models. Finally, we introduce Dempster–Shafer (DS) evidence theory and apply the Dempster combination rule to integrate the three feature types and determine the final attribution. Experimental results show that our method outperforms the baseline in classification, achieving an accuracy of 89.9%, a recall of 86.5%, and an F1-score of 88.2%. These findings highlight the value of multi-level feature fusion in enhancing APT attribution performance and provide new insights into the design of intelligence-driven defense strategies. Longxuan Duan, Mi Wen, Yun Xiong |
EURASIP J. Inf. Secur. | 2 |
| 2026 | Periodicity Variations Modelling Based on 2D Multi-Scale Patch for Multivariate Time Series Forecasting Using Improved MLP and Depthwise Separable ConvolutionabstractABSTRACT Multivariate time series forecasting (MTSF) involves predicting future values of multiple interrelated variables based on historical observations. While existing models often struggle to capture complex temporal multi‐scale dependencies and simultaneously modelling intraperiod and interperiod variations, thereby limiting their predictive accuracy. To address these limitations, we introduce a novel forecasting model named MTSPnet. This model employs a two‐dimensional (2D) temporal multi‐scale patching strategy, which converts one‐dimensional (1D) time series data into 2D multi‐scale Patch across different time periods. Additionally, MTSPnet incorporates two complementary modules: an interactive multilayer perceptron (MLPmix) module and a dynamic depthwise separable convolution (DDSC) module. These modules enable MTSPnet to efficiently extract both local and global temporal features, further enhancing its ability to model multi‐scale dependencies and periodicity variations. Experimental evaluations on seven real‐world datasets demonstrate that MTSPnet achieves superior performance in long‐term forecasting, proving its effectiveness as a robust and efficient solution for accurate time series prediction. Yachuan Wang, Mi Wen, Jigang Wang |
Expert Syst. J. Knowl. Eng. | 2 |
| 2026 | A Dynamic Differential Privacy Mechanism Based on Feature Importance in Deep LearningabstractThe extensive adoption of deep learning, coupled with the exponential growth of data, has raised concerns regarding potential privacy disclosure, particularly through membership inference attacks where adversaries attempt to determine whether specific data samples were used in model training. Differential privacy has emerged as a prominent technique to mitigate these concerns. However, its application often results in degraded model performance and significant utility loss. This paper proposes a dynamic differential privacy mechanism based on feature importance in deep learning (DPFI) to address this issue.Meanwhile, the introduction of superpixel segmentation not only mitigates the trade-off between accuracy and utility but also reduces the high complexity caused by high-dimensional features. The core concept of DPFI is that the noise level for each feature is determined based on its importance to the model. Specifically, we first initialize and train a model with differential privacy. Then, we perform superpixel segmentation on the dataset and apply Shapley Additive Explanations on the segmented images to calculate the feature importance. Next, we propose a noise addition strategy based on the importance of the features and their distribution. The privacy guarantees are rigorously analyzed through Rényi differential privacy. Experiments demonstrate that DPFI outperforms existing methods in terms of both model accuracy and resistance to membership inference attacks. Mi Wen, Hailun Shen, Xiumin Li, Kang Han, Kejie Lu |
IEEE Internet Things J. | 1 |
| 2026 | An Intelligent Antijamming and Eavesdropping Resistant Framework Based on Diffusion Models With RIS AssistanceabstractIn Internet of Things (IoT) environments, malicious nodes can not only eavesdrop on legitimate communications but also emit jamming signals, which severely undermine secure and reliable communication among nodes. Reconfigurable Intelligent Surfaces (RIS) have emerged as a lightweight and promising technique to mitigate such threats. However, in typical scenarios that simultaneously involve RIS and multiple nodes, existing Deep Reinforcement Learning (DRL)-based methods often suffer from lengthy training procedures and are vulnerable to adversarial perturbations (AP) introduced by malicious nodes. This paper proposes an offline secure and anti-jamming communication decision framework based on a Temporal Convolutional Network (TCN)-based Twin-Efficiency Diffusion Model (TCN-TEDM). The framework effectively alleviates the tendency of traditional offline RL to yield degraded policies under strong jamming due to adversarial perturbations and state missingness. The model reconstructs perturbed states under a limited compute budget, thereby markedly improving decision stability under jamming. Extensive experimental results demonstrate that the proposed framework can efficiently generalize and transfer existing secure-communication and anti-jamming policies without online interaction, achieving superior stability and performance under state-perturbation and missingness scenarios. Runhui Zhao, Hong Wen 0001, Mi Wen, Yingwei Zhao |
IEEE Internet Things J. | 3 |
| 2026 | Taming the long tail in federated learning: A unified global and personalized model framework
Pengsong Zhang 0002, Mi Wen, Zhou Zhu |
Inf. Sci. | 2 |
| 2026 | DEGAN : Towards botnet detection in IIoT with dual-enhanced GAN under imbalanced data
Yong Wang 0055, Zhenyang Yan, Kai Zhang 0016, Mi Wen |
J. Inf. Secur. Appl. | 4 |
| 2026 | Analysis on the Feasibility of D-FACTS Devices for Localizing FDI Attacks in Smart GridsabstractProactive detection with distributed flexible AC transmission system (D-FACTS) devices has been extensively studied for identifying false data injection (FDI) attacks in smart grids, while their potential for localizing remains largely unexplored. To meet this gap, this paper systematically explores the feasibility of localizing FDI attacks with D-FACTS devices. Specifically, we first thoroughly study the rationale underlying FDI localization with D-FACTS devices. We prove that an activated D-FACTS device is capable of localizing FDI attacks targeted on its connected end buses once a bad data detection (BDD) alarm is triggered. In addition, we elaborately analyze the inherent localization limitations: (i) the unlocalizable adversary cases targeting one-degree buses or super-buses; (ii) the localization uncertainty introduced by the defender's blind spots, resulting in huge operational costs and insufficient precision. Following this, a data-prompting framework is designed to over-come the above limitations. This framework integrates a data driven injected error identifier for precise localization and cost reduction, followed by a perturbation strategy with D-FACTS devices that significantly lowers false positive rates. Extensive simulations validate our theoretical findings on the rationale and limitations, while also demonstrating the effectiveness of the proposed framework in addressing limitations and enhancing localization accuracy. Qingyun Du, Mi Wen, Chonghua Wang, Beibei Li 0002, Yan Zhang 0002 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | A Distributed Dual-Stage Localization Strategy for FDIAs Detection in Power Distribution SystemsabstractWith the increasing integration of measurement devices, the control and observation of power distribution systems have become significantly more dependent on cyberspace, making them more vulnerable to false data injection attacks (FDIAs). Contrary to the detection of FDIAs in power transmission systems, less attention has been paid to power distribution systems due to poor data quality, large volume sizes, and unbalanced data. This article proposes a dual-stage localization detection strategy for FDIAs in power distribution systems to detect and localize stealth FDIAs. Considering the time scale, arithmetic, and calculation overhead, this strategy can be transformed into two stages: presence detection and localization detection. Specifically, a cost-sensitive loss convolutional neural network based on Gaussian mixture autoencoder architecture is leveraged to capture data features from unbalanced data in presence detection. In localization detection, a Markov chain based on a cumulative state transfer probability (CSTP) is leveraged to locate the FDIAs exactly after presence detection. In this subject, presence detection can support the operator in rapidly filtering out compromised data, and localization detection can drive the control center to deploy countermeasures accurately. Based on the adjusted IEEE 14 and 118-bus test systems, numerical results indicate the effectiveness of the proposed strategy. Mi Wen, Ruilong Deng, Sha Peng, Yunsheng Xue, Yi Wu 0011 |
IEEE Trans. Ind. Informatics | 2 |
| 2025 | LGAT: A novel model for multivariate time series anomaly detection with improved anomaly transformer and learning graph structures
Mi Wen, Zhehui Chen, Yun Xiong |
Neurocomputing | 1 |
| 2025 | A Sanitizable and Bilateral Access Control Scheme Based on BlockchainabstractDriven by information technology, data trading promotes cross-industry collaboration and uncovers value by integrating multi-source data, yet it requires encryption and access controls to address increasing data security challenges. Existing schemes largely rely on attribute-based unilateral access control to protect data, facing challenges such as data source authenticity and requester autonomy. Bilateral access control requires data providers and requesters to define access policies, allowing decryption only when both policies match, often facilitated by cryptographic primitives such as matchmaking encryption (ME). However, the current bilateral schemes still face challenges of sensitive data leakage, unauthorized data access, and single points of failure. To date, no existing scheme has addressed these issues simultaneously. In this paper, we propose a blockchain-based, sanitizable and bilateral access control scheme with privacy-preserving (SBAC-PP) for data trading. Specifically, by extending ME via hash functions and policy-hidden identifiers to achieve a bilateral access control with privacy-preserving. Secondly, by combining access control encryption (ACE), we design a ciphertext sanitization mechanism to prevent unauthorized data access. Furthermore, by integrating SBAC-PP with blockchain (BC) and the interplanetary file system (IPFS), we use smart contracts for trusted matching and pre-decryption, and store encrypted data in IPFS, thereby achieving decentralized data management to avoid single points of failure. Finally, we analyze the security of SBAC-PP and evaluate its performance to demonstrate its efficiency and practicality. Mi Wen, Miling Xiao, Weiwei Li 0007, Bin Xiao 0001 |
IEEE Internet Things J. | 1 |
| 2025 | Contrastive Graph Semantic Learning via prototype for recommendation
Mi Wen, Weiwei Li 0007, Zizhu Fan, Xiaoqing Yu |
Inf. Sci. | 1 |
| 2025 | IDS-DWKAFL: An intrusion detection scheme based on Dynamic Weighted K-asynchronous Federated Learning for smart grid
Mi Wen, Pengsong Zhang 0002, Liduo Chen |
J. Inf. Secur. Appl. | 1 |
| 2025 | CUOM: A causal unbiased optimization method for federated domain generalization
Mi Wen, Kang Han, Hailun Shen |
Knowl. Based Syst. | 1 |
| 2025 | An Efficient Fuzzy Certificateless Signature-Based Authentication Scheme Using Anonymous Biometric Identities for VANETsabstractVehicular ad hoc networks (VANETs) are essential technologies to ensure safe road traffic management and enhance driving convenience. Nowadays, diversified authentication schemes have been developed in VANETs for the purpose of safer communication between nodes. For instance, biometric technology which employs biometric information as users’ authentic identity is widely adopted in message authentication due to its visible benefits. Nonetheless, there is a significant problem in current biometric identity-based authentication schemes that noise is inevitable in each collection of biometric information, making these schemes lack critical error tolerance. Additionally, anonymous biometric identity is difficult to be realized, which fails to meet the basic standard of VANETs. For solving the above key issues, we propose the first efficient fuzzy certificateless signature-based (FCLS) authentication scheme using anonymous biometric identities for VANETs. In virtue of its superior error tolerance, it enables authentication between two identities represented by two attribute sets within a certain Hamming distance. Besides, the newly developed authentication scheme realizes effective conditional privacy so that drivers’ real biometric identities can be ensured. Through the formal security proof, this FCLS scheme is existentially unforgeable against adaptive chosen message attack (EU-CMA) in the random oracle model (ROM), which reaches the higher security. Compared with current advanced schemes, the new authentication scheme is more efficient in computation and communication according to performance analysis. Liangliang Wang 0001, Jiangwei Xu, Baodong Qin, Mi Wen, Kefei Chen |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | False Data Injection Attacks in Power Distribution Systems Considering the Characteristics of Distributed PhotovoltaicabstractWith the advancement of carbon-neutral and new power system construction, numerous information devices are continuously connected to power distribution systems, gradually breaking the original unobservable state of power distribution systems and making them more vulnerable to false data injection attacks (FDIAs). Contrary to most existing research focusing on the unbalanced network, less attention has been paid to the influence of randomness and fluctuation of distributed photovoltaic (PV) to perform FDIAs in the power distribution system. In this article, the failure mechanism of FDIAs and the improved FDIAs method are proposed simultaneously for the distribution system with a high penetration of distributed PV scenarios. Specifically, based on the reactive power optimization process, the randomness and fluctuation of distributed PV are applied to decrease significantly the stealthiness of the FDIAs. Subsequently, an improved FDIA method, based on time-dependent loss conditional generative adversarial networks, is proposed to enhance the stealth and effectiveness of the attack. Finally, numerical results based on the modified IEEE 33 bus test systems demonstrate the effectiveness of the failure mechanism and the improved FDIAs. Research results can facilitate the execution of countermeasures for distribution systems with a high penetration of distributed PV, posing serious and pressing security concerns in power distribution systems with a high penetration of distributed PV scenarios. Mi Wen, Hong Wen 0001, Ruilong Deng, Sha Peng, Naiwang Guo |
IEEE Trans. Ind. Informatics | 2 |
| 2024 | An Approach for APT Attack Scenario Construction Based on Dynamic Attack GraphsabstractAs network complexities and software intricacies escalate, complex attacks such as Advanced Persistent Threat (APT) are growing more challenging. Because APT attacks often lurk within the target environment for a long time, they are not easily detected. Therefore, we use the attack scenario construction method to identify APT attacks. Existing methods for constructing attack scenarios often neglect the influences of the vulnerability life cycle on atomic attacks. Furthermore, these methods rely on extensive prior data, resulting in the inability to directly update the risk probabilities of nodes. Consequently, the hazardous nodes are difficult to be dynamically and effectively identified. To address the above problems, this paper proposes an approach for APT attack scenario construction based on dynamic attack graph. Firstly, this paper analyzes the impact of the vulnerability life cycle on atomic attacks and quantifies the attack graph by incorporating factors such as vulnerability value, attack cost, attack income, and attack preference. Then, this approach integrates the attack graph with a Bayesian network to build a static attack graph, demonstrating the static risk conditions of the network. Finally, the dynamic attack graph is constructed by using forward and backward updates, thus constructing the attack scenarios and efficiently mining out the hazardous nodes. The experimental results show that the proposed method reliably maintains high dynamic reachable probability and adapts node probabilities to actual conditions, helping network administrators assess threats and address potential attacks beforehand. Mingsi Jiang, Mi Wen, Yun Xiong, Weiwei Li 0007 |
GLOBECOM | 2 |
| 2024 | ADP-VFL: An Adaptive Differential Privacy Scheme for VPP Based on Federated LearningabstractIn recent years, with the remarkable development of Virtual Power Plants (VPP) and the surge in the number of Electric Vehicles (EVs), the issue of data privacy leakage has become increasingly prominent. The effectiveness of existing federated learning schemes in mitigating data privacy leakage, it still faces potential threats such as inference attacks and user and server collusion. To protect the privacy of federated learning, some schemes have introduced differential privacy(DP). Nevertheless, applying DP will inevitably affect the accuracy to some extent. In this paper, we propose an adaptive differential privacy scheme for VPP based on federated learning, named ADP-VFL. Our ADP-VFL scheme can achieve data privacy preservation by transmitting the noise-added data as a chain, defend against inference attacks by innovating offset noise mechanism and a parallel transmission scheme. The performance evaluation results demonstrate that the proposed scheme can improve the aggregation accuracy and reduces the communication overhead. Mi Wen, Weiwei Li 0007, Ben Niu 0001, Weidong Qiu, Fenghua Li 0001 |
ICC | 2 |
| 2024 | Improving Structural and Semantic Global Knowledge in Graph Contrastive Learning with Distillation
Mi Wen, Yunsheng Xue, Hong Wen 0001 |
PAKDD (2) | 1 |
| 2024 | MAGIC: Detecting Advanced Persistent Threats via Masked Graph Representation Learning
Zian Jia, Yun Xiong, Yuhong Nan, Yao Zhang 0009, Jinjing Zhao, Mi Wen |
USENIX Security Symposium | 6 |
| 2024 | An Intrusion Detection Method Based on Attention Mechanism to Improve CNN-BiLSTM ModelabstractAbstract Security of computer information can be improved with the use of a network intrusion detection system. Since the network environment is becoming more complex, more and more new methods of attacking the network have emerged, making the original intrusion detection methods ineffective. Increased network activity also causes intrusion detection systems to identify errors more frequently. We suggest a new intrusion detection technique in this research that combines a Convolutional Neural Network (CNN) model with a Bi-directional Long Short-term Memory Network (BiLSTM) model for adding attention mechanisms. We distinguish our model from existing methods in three ways. First, we use the NCR-SMOTE algorithm to resample the dataset. Secondly, we use recursive feature elimination method based on extreme random tree to select features. Thirdly, we improve the profitability and accuracy of predictions by adding attention mechanism to CNN-BiLSTM. This experiment uses UNSW-UB15 dataset composed of real traffic, and the accuracy rate of multi-classification is 84.5$\%$; the accuracy rate of multi-classification in CSE-IC-IDS2018 dataset reached 98.3$\%$. Dingyu Shou, Chao Li 0080, Zhen Wang 0042, Kai Zhang 0016, Mi Wen, Yong Wang 0055 |
Comput. J. | 7 |
| 2024 | Non-interactive Boolean Searchable Asymmetric Encryption With Bilateral Access ControlabstractAbstract Searchable asymmetric encryption (SAE) enables a client to search over a data owner’s encrypted data. Nevertheless, state-of-the-art SAE schemes allow a data owner to specify access control policy for a client, while they have not considered the threat case of a malicious data owner. To address the problem, this work presents a non-interactive SAE scheme with bilateral access control: (i) allowing data owner and client to both specify policies toward the other party; (ii) allowing client to perform arbitrary boolean queries with sub-linear search complexity. Technically, we extend Cash et al.’s highly scalable SSE into an asymmetric setting and introduce the property of data owner authenticity. By refining identity-based matchmaking encryption, we formalize the syntax and security definition of our SAE with identity-based bilateral access control. Moreover, the security of the proposed SAE can be reduced to discrete logistic assumption and decisional bilinear Diffie–Hellman assumption. As an enhanced extension, we present a non-interactive multi-client SAE scheme with fuzzy identity-based bilateral access control. In addition, we implement the proposed schemes in real cloud platform and evaluate their performance on a real-world dataset. The result confirms that our SAE schemes achieve bilateral access control for both data owner and client with highly acceptable efficiency. Xiwen Wang 0001, Kai Zhang 0016, Jinguo Li, Mi Wen, Shengmin Xu, Jianting Ning |
Comput. J. | 4 |
| 2024 | Enhancing the transferability of adversarial samples with random noise techniques
Mi Wen, Minjie Wei, Yanbing Bi |
Comput. Secur. | 2 |
| 2024 | A Privacy-Preserving Federated Learning Scheme Against Poisoning Attacks in Smart GridabstractPrivacy preservation in federated learning (FL) has received considerable attention and many approaches have been proposed. However, these approaches rendered the uploaded gradients invisible to the server, which poses a significant challenge in defending against poisoning attacks. In poisoning attacks, malicious or compromised participants use poisoned training data or forged local updates to disrupt the training process. It is hard for cloud servers to defend against poisoning attacks due to the invisibility of gradients. To address this issue, we propose a privacy-preserving FL scheme (PFLS) against poisoning attacks to eliminate the impact of model poisoning attacks while protecting the privacy of participants. Specifically, a dynamic adaptive defense mechanism is designed to mitigate the impact of malicious gradients and locate malicious participants. To protect participants’ privacy, a multidimensional homomorphic encryption method is constructed with a hierarchical aggregation architecture. The security analysis illustrates that the PFLS scheme can ensure the privacy of FL participants. The experimental results demonstrate that a high-detection rate of malicious participants and a balance between efficiency and robustness are achieved. Xiumin Li, Mi Wen, Siying He, Rongxing Lu, Liangliang Wang 0001 |
IEEE Internet Things J. | 2 |
| 2024 | DPG: a model to build feature subspace against adversarial patch attack
Yunsheng Xue, Mi Wen, Weiwei Li 0007 |
Mach. Learn. | 2 |
| 2023 | Long-term Incentive Mechanism for Federated Learning: A Dynamic Repeated Game ApproachabstractFederated learning (FL) is capable of using the local data sets from large-scale nodes for distributed model training. In FL tasks, training and updating are usually repeated ping-pong processes, in that the model training process between devices (workers) and task publisher (TP) needs to be repeated for multiple rounds towards the global model convergence. However, a worker is typically selfish to save its local resource, and even with an incentive mechanism in place at the beginning of model training, a worker may not be honest to participate in all training rounds, leading to poor performance in global model convergence. To enable long-term cooperation in FL, however, has rarely been considered in the existing literature which motivates our work. In this paper, the multi-round FL is modeled as a dynamic repeated game. To exploit the long-term cooperation gain, a general trigger strategy is deployed as the punishment for free-riding and the Nash equilibrium (NE) of the repeated game is derived. Based on the game theoretic analysis, we develop a NE-driven incentive mechanism to guide the TP selects the most effective wages to motivate workers towards long-term cooperation and avoid midway free-riding. Simulation results show the effectiveness of our proposal. Jinkai Zheng, Guanjie Li, Wencong Wang, Tom H. Luan, Zhou Su 0001, Mi Wen |
PIMRC | 6 |
| 2023 | Practical black-box adversarial attack on open-set recognition: Towards robust autonomous driving
Kai Zhang 0016, Kejie Lu, Yun Xiong, Mi Wen |
Peer Peer Netw. Appl. | 5 |
| 2023 | DCDPI: Dynamic and Continuous Deep Packet Inspection in Secure Outsourced MiddleboxesabstractSecure outsourced middleboxes are deployed in network function virtualization services that detect malicious activities on communications, which provides privacy-preserving deep packet inspection (DPI) over encrypted traffic. To boost filtering efficiency of packets, the two-layer middlebox architecture has been adopted in recent DPI systems. Nevertheless, state-of-the-art solutions based on two-layer architecture mainly suffer from two limitations: i) cannot support dynamic rule addition; ii) failed to inspect discontinuous token for rule matching. To address these limitations, this work proposes an efficient, dynamic and continuous DPI (DCDPI) system in secure outsourced middleboxes. To achieve dynamic rule addition with forward privacy, we refine a data structure called virtual binary tree (VBTree) and further introduce a variant of VBTree for DCDPI, termed VBTree+. VBTree+ supports two new desirable features: i) taking the rule action information into consideration; ii) achieving both rule identifier and rule action hiding. By introducing a token continuity check mechanism, DCDPI can effectively identify discontinuous tokens and categorize continuous tokens into one group. The extensive experiment over the real dataset and rule set confirms the practicality and efficiency of DCDPI. Compared to state-of-the-art works with same setting, DCDPI is 18%$\sim$110% more efficient for a connection establishment between gateway/client and server. Minjun Deng, Kai Zhang 0016, Pengfei Wu 0003, Mi Wen, Jianting Ning |
IEEE Trans. Cloud Comput. | 4 |
| 2023 | Collusion Detection and Trust Management for Indoor Navigation System With CrowdsourcingabstractThe indoor navigation system supported by spatial crowdsourcing emerges as a promising application to provide customized location service for requesters. An important stage of crowdsourcing is to select trustworthy workers. Workers’ reputation, as an essential criterion of this selection, is usually evaluated by feedback ratings from requesters. However, the reputation in the crowdsourcing-based indoor navigation system is vulnerable to the collusion attack, that is malicious workers (i.e., attackers) collude with requesters to illegally increase reputation. In this paper, we propose a collusion detection scheme to distinguish attackers and provide a secure reputation mechanism. Specifically, we first identify collusive requesters categorized into three different levels according to their feedback rating behaviors. Then, the weighted logistic regression (WLR) is developed to distinguish the collusive requesters who provide exorbitant feedback ratings. Furthermore, we employ an outlying sequence detection based on the maximum mean discrepancy (MMD), to resist the multiple location queries initiated by the same collusive requester through analyzing the distribution distance. In addition, we propose a community detection algorithm, named Fastgreedy, to identify the collusion from many requesters. Finally, the extensive simulation results demonstrate that the proposed scheme can effectively detect collusive requesters and significantly outperform other methods. Weiwei Li 0007, Mi Wen, Zhou Su 0001, Kuan Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Multi-Client Boolean File Retrieval With Adaptable Authorization Switching for Secure Cloud Search ServicesabstractSecure cloud search services provide a cost-effective way for resource-constrained clients to search encrypted files in the cloud, where data owners can customize search authorization. Despite providing fine-grained authorization, traditional attribute-based keyword search (ABKS) solutions generally support single keyword search. Towards expressive queries over encrypted data, multi-client searchable symmetric encryption (MC-SSE) was introduced. However, current search authorizations of existing MC-SSEs: (i) cannot support dynamic updating; (ii) are (semi-)black-box implementations of attribute-based encryption; (iii) incur significant cost during system initialization and file encryption. To address these limitations, we present AasBirch, an MC-SSE system with fast fine-grained authorization that supports adaptable authorization switching from one policy to any other one. AasBirch achieves constant-size storage and lightweight time cost for system initialization, file encryption and file searching. We conduct extensive experiments based on Enron dataset in real cloud environment. Compared to state-of-the-art MC-SSE with fine-grained authorization, AasBirch achieves 30$\sim 200\times$smaller public parameter and secret key size, with the assumed least frequent keyword in a query ($s$-term) as 21. Moreover, it runs 10$\sim 20\times$faster for file encryption and$>20\times$faster for file searching. In addition, AasBirch outperforms 80,000× (resp. 7,850×) faster with$s$-term=1 (resp. =21), as compared to classic dynamic ABKS system. Kai Zhang 0016, Xiwen Wang 0001, Jianting Ning, Mi Wen, Rongxing Lu |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | Attribute-Based Collaborative Access Control Scheme with Constant Ciphertext Length for Smart GridabstractAttribute based encryption (ABE) is usually used for authorization to ensure data confidentiality because it can provide fine-grained access control. However, the data of smart grid is not completely divided, and there are many cases of collaborative access to data. The existing ABE based collaboration schemes have the defect that the ciphertext increases with the increase of attributes. Due to the limited storage and transmission capacity of smart grid equipment, the previous schemes are not suitable for smart grid. An attribute based collaborative access control scheme with constant ciphertext length for smart grid is proposed. By extending the collaborative nature to ABE with constant ciphertext length, the vacancy of collaborative ABE is made up. Performance analysis shows that this scheme is significantly better than the traditional collaborative ABE scheme in terms of storage and computing overhead. Security analysis shows that the scheme can ensure the confidentiality of data and support the revocation of collaborative at any time. Jiangyan Ge, Mi Wen, Liangliang Wang 0001, Rong Xie 0002 |
ICC | 2 |
| 2022 | Efficient Certificateless Online/Offline Signcryption Scheme for Edge IoT DevicesabstractThe emergence of edge computing brings data processing and storage to the vicinity of terminal equipment, which can quickly respond to user needs and reduce the computational burden of the traditional centralized cloud computing model, resulting in a model of edge computing-assisted cloud computing. In this architecture, how to prevent other untrusted entities from leaking user privacy has become one of the most critical concerns. To address this concern, many cryptographic schemes supporting the traditional cloud model to protect the data security sharing of IoT devices have been proposed. However, resource-constrained devices are an essential component of the Internet of Things (IoT). Its characteristics are one of the main reasons that affect the efficiency of schemes, and traditional cryptographic schemes are not suitable for edge computing. Therefore, in order to ensure secure data sharing between IoT devices, we come up with an improved certificateless online/offline signcryption (CLOOSC) scheme and achieve lower computational overhead, when offline calculation is not considered, the resource-constrained IoT device under the cloud-edge collaboration architecture requires only one point multiplication, while only one bilinear pairing is required in the verification phase. In the random oracle model, our scheme is proved to be IND-CCA2 secure. The experiment results show our scheme can be lightweight in terms of time cost. Liangliang Wang 0001, Mi Wen, Kai Zhang 0016, Kefei Chen |
IEEE Internet Things J. | 3 |
| 2022 | FedDetect: A Novel Privacy-Preserving Federated Learning Framework for Energy Theft Detection in Smart GridabstractIn smart grids, a major challenge is how to effectively utilize consumers’ energy consumption data while preserving security and privacy. In this article, we tackle this challenging issue and focus on energy theft detection, which is very important for smart grids. Specifically, we note that most existing energy theft detection schemes are centralized, which may be unscalable, and more importantly, may be very difficult to protect data privacy. To address this issue, we propose a novel privacy-preserving federated learning framework for energy theft detection, namely, FedDetect. In our framework, we consider a federated learning system that consists of a data center (DC), a control center (CC), and multiple detection stations. In this system, each detection station (DTS) can only observe data from local consumers, which can use a local differential privacy (LDP) scheme to process their data to preserve privacy. To facilitate the training of the model, we design a secure protocol so that detection stations can send encrypted training parameters to the CC and the DC, which then use homomorphic encryption to calculate the aggregated parameters and return updated model parameters to detection stations. In our study, we prove the security of the proposed protocol with solid security analysis. To detect energy theft, we design a deep learning model based on the state-of-the-art temporal convolutional network (TCN). Finally, we conduct extensive data-driven experiments using a real-energy consumption data set. The experimental results demonstrate that the proposed federated learning framework can achieve high accuracy of detection with a smaller computation overhead. Mi Wen, Rong Xie 0002, Kejie Lu, Liangliang Wang 0001, Kai Zhang 0016 |
IEEE Internet Things J. | 1 |
| 2021 | Traffic sign detection algorithm based on feature expression enhancement
Mi Wen, Kai Zhang 0016, Ping Meng, Rongcheng Cui |
Multim. Tools Appl. | 2 |
| 2021 | Multi-Client Sub-Linear Boolean Keyword Searching for Encrypted Cloud Storage with Owner-Enforced AuthorizationabstractTo date, cloud computing has emerged as a primary utility for providing remote data storage services for users, since users can thus be relieved from cumbersome document maintenance. Despite of the benefits brought by data outsourcing, the unexpected data breaches raise concerns about data confidentiality and privacy. To deal with this, a straightforward and convincing strategy is to encrypt data before outsourcing them to the cloud. However, securely sharing and searching over outsourced encrypted data has turned into a challenge due to the hindrance led by data encryption. To address the challenge, this article proposes a new highly-scalable searchable encryption scheme for encrypted cloud storage. The scheme achieves sub-linear Boolean keyword searching, and moreover allows the data owner to authorize which clients could search or access the documents in the cloud. Technically, we revisit searchable symmetric encryption primitive by non-trivially combining it with a novel access control technique, and build an inverted index data structure for both attribute-based access control and sub-linear search process. Furthermore, we introduce a formalized security definition for the system, and prove its security in the simulation-based security model. Finally, we conduct a couple of experiments over a representative real-world dataset to show practicality. Kai Zhang 0016, Mi Wen, Rongxing Lu, Kefei Chen |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2020 | An Adversarial Attack with Fusion of Polarization for Unmanned ScenesabstractWith the rise of artificial intelligence, the emergence of unmanned vehicles can alleviate traffic congestion and reduce the risk of traffic accidents, in which image recognition has become one of the key technologies. Yet, with the advent of the concept of adversarial examples, many works have proved that the existence of adversarial examples has huge hidden danger in the field of scene recognition. Currently, in unmanned scene recognition, polarization images are widely used because they can robustly describe important physical properties of the object. However, most of the researches on adversarial examples are based on RGB images, and few people studied polarization-based imaging. Therefore, this paper proposes an adversarial attack with fusion of polarization for unmanned scenes. Theoretically, we analyze that polarization images have better effects on adversarial example attacks than RGB images. Experimentally, we evaluate the performance of the proposed model by generating adversarial examples attack scene recognition classification model. The experiment results show that compared with RGB images, polarization images are less vulnerable to attack and have better effects on robustness, which can improve the security of unmanned scenes. And it can reduce the successful attack rate of adversarial examples by up to 9.4%. Huanhuan Lv, Mi Wen, Rongxing Lu, Xuankai Wang, Jinguo Li |
VTC Fall | 2 |
| 2020 | Cloud-assisted secure and conjunctive publish/subscribe service in smart gridsabstractThe publish/subscribe (P/S) service on Advanced Metering Infrastructure (AMI) servers of smart grid need to deal with huge amount of data, which may lead to data burst on AMI servers and serious server crash. Moreover, for protecting data security, sensitive data must be encrypted before being published. It obstacles traditional data utilisation based on plaintext P/S service. Thus, enabling an encrypted data‐based P/S service is of paramount importance. Considering the huge amount of data and subscribers, it is necessary to allow conjunctive subscriptions containing mixtures of keywords, numeric data etc., and return data according to a reasonable access control mechanism (ACM). In this study, the authors propose a cloud‐assisted secure conjunctive publish/subscribe protocol to challenge the encrypted data‐based P/S service on AMI servers. To overcome the data burst, the P/S computation tasks are shifted from AMI servers to the cloud. To support conjunctive P/S operations in a reasonable ACM, a prefix‐based membership verification algorithm combining with the ciphertext policy attribute‐based encryption is explored. The proposed protocol is proved to be secure against chosen keyword/plaintext attacks under formally defined security models. Experiments on the real‐world data set further show proposed protocol indeed introduce low overhead on computation and communication. Jinguo Li, Mi Wen, Kai Zhang 0016 |
IET Inf. Secur. | 2 |
| 2020 | Toward efficient and effective bullying detection in online social network
Mi Wen, Rongxing Lu, Beibei Li 0002, Jinguo Li |
Peer-to-Peer Netw. Appl. | 2 |
| 2020 | HYBRID-CNN: An Efficient Scheme for Abnormal Flow Detection in the SDN-Based Smart GridabstractSoftware-Defined Network (SDN) can improve the performance of the power communication network and better meet the control demand of the Smart Grid for its centralized management. Unfortunately, the SDN controller is vulnerable to many potential network attacks. The accurate detection of abnormal flow is especially important for the security and reliability of the Smart Grid. Prior works were designed based on traditional machine learning methods, such as Support Vector Machine and Naive Bayes. They are simple and shallow feature learning, with low accuracy for large and high-dimensional network flow. Recently, there have been several related works designed based on Long Short-Term Memory (LSTM), and they show excellent ability on network flow analysis. However, these methods cannot get the deep features from network flow, resulting in low accuracy. To address the above problems, we propose a Hybrid Convolutional Neural Network (HYBRID-CNN) method. Specifically, the HYBRID-CNN utilizes a Deep Neural Network (DNN) to effectively memorize global features by one-dimensional (1D) data and utilizes a CNN to generalize local features by two-dimensional (2D) data. Finally, the proposed method is evaluated by experiments on the datasets of UNSW_NB15 and KDDCup 99. The experimental results show that the HYBRID-CNN significantly outperforms existing methods in terms of accuracy and False Positive Rate (FPR), which successfully demonstrates that it can effectively detect abnormal flow in the SDN-based Smart Grid. Pengpeng Ding, Jinguo Li, Liangliang Wang 0001, Mi Wen, Yuyao Guan |
Secur. Commun. Networks | 4 |
| 2019 | Multi-Keyword Search Guaranteeing Forward and Backward Privacy over Large-Scale Cloud DataabstractUsing searchable encryption (SE), users' data can be outsourced to an untrusted server while ensuring privacy of both the queries and the data. Meanwhile, to efficiently support data updating, dynamic SE (DSE) has also been proposed and applied to a variety of scenarios. However, recent work shows that even with little information leakage on updated keywords, most of existing DSE schemes are also vulnerable to adaptative attacks breaking the privacy of the queries. To address this problem, several privacy-preserving DSE have been exploited to mitigate the two major privacy issues in the data update process: i.e., Forward privacy and Backward privacy. Nevertheless, it is still an open problem to support clients multi-keyword-based searching over dynamic cloud data. In reality, as a promising query requirement, it is assurance that the cost of all participants can be fundamentally reduced by implementing multi-keyword-based querying. To combat that, in this paper, we design the first multi-keyword based search proposals ensuring forward and backward privacy over dynamic cloud data. Specifically, we utilize Symmetric Hidden Vector Encryption (SHVE) as the underlying structure to build multi-keyword search protocol. Then, Bloom filter integrating with pseudo-random function will be further adopted to enhance query efficiency. The security analysis proves the high security of our model, and extensive experiments conducted on real-world data also demonstrate the practical performance of our proposed scheme. Hongwei Li 0001, Guowen Xu, Xizhao Luo, Mi Wen |
GLOBECOM | 5 |
| 2019 | Achieve Revocable Access Control for Fog-Based Smart Grid SystemabstractDue to its prodigious advantages, smart grid technology has received considerable attention in recent years. However, security issues are still currently challenging in smart grid. In this paper, aiming at tackle the security issue of power consumption data, we propose a new Ciphertext Policy Attribute-based Encryption (CP-ABE) scheme with revocation for the fog- based smart grid system. Specifically, in order to achieve attribute revocation without requiring users to be always online, we divide users' attributes into attribute groups, assign an attribute group key to each group, and selectively distribute group key update messages. In addition, our scheme uses the DH (Diffie- Hellman) tree to distribute the group key statelessly, which solves the problem of collusion attack. The combination of attribute revocation and user revocation has been used to improve the efficiency of the revocation mechanism. Furthermore, the proposed scheme outsources unnecessary computing operations to fog nodes, so that the computing overhead of users is independent of the number of attributes. Both security analysis and experimental results demonstrate that our proposed scheme can balance the security objectives with the actual efficiency. Mi Wen, Rongxing Lu, Jinguo Li |
VTC Fall | 2 |
| 2019 | A new VRSA-based pairing-free certificateless signature scheme for fog computingabstractSummary Fog computing is composed of various computers with weak performance instead of servers with strong performance. As history has shown, there has not been a general pairing‐free certificateless signature scheme that is mainly designed with modular exponentiation and modular multiplication that can possess resistance to Type I and Type II adversaries. The lightweight certificateless signature algorithm with low requirements for computing and storage capabilities, which can be practicably implemented in fog computing, needs to be studied. Therefore, a new hard mathematic problem is firstly defined in this paper, which is called variant of RSA problem. Then, a new general pairing‐free certificateless signature scheme is proposed based on the variant of RSA problem and the discrete logarithm problem. Fortunately, the proposed scheme is the first RSA‐based certificateless signature scheme that can possess resistance to Type I and Type II adversaries. A formal security proof is provided to demonstrate that, under adaptively chosen message attacks, the scheme is provably secure against Type I and Type II adversaries in the random oracle model. When compared with other known pairing‐free certificateless signature schemes of the same type, the computation cost of our scheme is slightly higher; however, a higher security level can be achieved. Liangliang Wang 0001, Mi Wen, Kefei Chen, Zhongqin Bi, Yu Long 0001 |
Concurr. Comput. Pract. Exp. | 2 |
| 2019 | PTAS: Privacy-preserving Thin-client Authentication Scheme in blockchain-based PKI
Wenbo Jiang 0001, Hongwei Li 0001, Guowen Xu, Mi Wen, Guishan Dong, Xiaodong Lin 0001 |
Future Gener. Comput. Syst. | 4 |
| 2019 | Energy Theft Detection With Energy Privacy Preservation in the Smart GridabstractAs a prominent early instance of the Internet of Things in the smart grid, the advanced metering infrastructure (AMI) provides real-time information from smart meters to both grid operators and customers, exploiting the full potential of demand response. However, the newly collected information without security protection can be maliciously altered and result in huge loss. In this paper, we propose an energy theft detection scheme with energy privacy preservation in the smart grid. Especially, we use combined convolutional neural networks (CNNs) to detect abnormal behavior of the metering data from a long-period pattern observation. In addition, we employ Paillier algorithm to protect the energy privacy. In other words, the users' energy data are securely protected in the transmission and the data disclosure is minimized. Our security analysis demonstrates that in our scheme data privacy and authentication are both achieved. Experimental results illustrate that our modified CNN model can effectively detect abnormal behaviors at an accuracy up to 92.67%. Donghuan Yao, Mi Wen, Xiaohui Liang 0002, Zipeng Fu, Kai Zhang 0016, Baojia Yang |
IEEE Internet Things J. | 2 |
| 2019 | Secure, flexible and high-efficient similarity search over encrypted data in multiple clouds
Jinguo Li, Mi Wen, Kui Wu 0001, Kejie Lu, Fengyong Li, Hongjiao Li |
Peer-to-Peer Netw. Appl. | 2 |
| 2018 | A Privacy-Preserving Thin-Client Scheme in Blockchain-Based PKIabstractTraditional centralized PKIs are vulnerable due to the single point of failure. A feasible solution is to build a decentralized PKI without certificate authority (CA). Web of Trust is the first step toward realizing a decentralized PKI, but it still has some limitations such as missing incentive and leaking user's privacy. Blockchain's numerous desirable properties, such as cryptographical security, decentralized nature and unalterable transaction record, make it a suitable tool to implement a decentralized PKI. However, the latest research findings about blockchain-based PKI are still incompatible with the thin-clients which have limited storage ability to download the entire blockchain. To combat that, we firstly present a Privacy-preserving Thin-client Scheme (PTS) utilizing the idea of k-anonymity, which enables thin-clients to run normally as full node users and protect user's privacy simultaneously. After that, in order to reduce cost, we further propose an Efficient Privacy preserving Thin-client Scheme (EPTS) employing the method of PIR (private information retrieval). Then security analysis and functional comparison are performed to demonstrate the high security and comprehensive functionality of EPTS compared with existing schemes. Finally, extensive experiments are undertaken to confirm that EPTS can reduce computational cost and communication cost impressively. Wenbo Jiang 0001, Hongwei Li 0001, Guowen Xu, Mi Wen, Guishan Dong, Xiaodong Lin 0001 |
GLOBECOM | 4 |
| 2018 | State Estimation Based Energy Theft Detection Scheme with Privacy Preservation in Smart GridabstractThe increasing deployment of smart meters at individual households has significantly improved people's experience in electricity bill payments and energy savings. It is, however, still challenging to guarantee the accurate detection of attacked meters' behaviors as well as the effective preservation of users'privacy information. In addition, rare existing research studies jointly consider both these two aspects. In this paper, we propose a Privacy-Preserving energy Theft Detection scheme (PPTD) to address the energy theft behaviors and information privacy issues in smart grid. Specifically, we use a recursive filter based on state estimation to estimate the user's energy consumption, and detect the abnormal data. During data transmission, we use the lightweight NTRU algorithm to encrypt the user's data to achieve privacy preservation. Security analysis demonstrates that in the PPTD scheme, only authorized units can transmit/receive data, and data privacy are also preserved. The performance evaluation results illustrate that our PPTD scheme can significantly reduce the communication and computation costs, and effectively detect abnormal users. Mi Wen, Donghuan Yao, Beibei Li 0002, Rongxing Lu |
ICC | 1 |
| 2018 | Unsupervised steganalysis over social networks based on multi-reference sub-image sets
Fengyong Li, Kui Wu 0001, Jingsheng Lei, Mi Wen, Yanli Ren |
Multim. Tools Appl. | 4 |
| 2018 | Efficient steganographer detection over social networks with sampling reconstruction
Fengyong Li, Mi Wen, Jingsheng Lei, Yanli Ren |
Peer-to-Peer Netw. Appl. | 2 |
| 2017 | A Data Aggregation Scheme with Fine-Grained Access Control for the Smart GridabstractWith the rapid development of smart grid, smart meters are deployed at energy consumers' premises to collect real-time usage data. Although such a communication model can help the control center of the energy producer to improve the efficiency and reliability of electricity delivery, it also leads to some security issues. For example, this real-time data involves the customers' privacy. Attackers may violate the privacy for house breaking, or they may tamper with the transmitted data for their own benefits. For this purpose, many data aggregation schemes are proposed for privacy preservation. However, rare of them cares about both the data aggregation and fine- grained access control to improve the data utility. In this paper, we proposes a data aggregation scheme based on attribute decision tree. Security analysis illustrates that our scheme can achieve the data integrity, data privacy preservation and fine- grained data access control. Experiment results show that our scheme are more efficient than existing schemes. Mi Wen, Hongwei Li 0001, Jinguo Li |
VTC Fall | 1 |
| 2017 | A privacy-aware data dissemination scheme for smart grid with abnormal data traceability
Mi Wen, Kejie Lu, Jingsheng Lei |
Comput. Networks | 2 |
| 2016 | PSS: Achieving high-efficiency and privacy-preserving similarity search in multiple cloudsabstractTo preserve privacy, sensitive data in cloud computing needs to be encrypted before outsourcing, which obstacles data utilization based on plaintext search. Thus there spring up several secure schemes which enable encrypted cloud-data search. However, these single-cloud-supported search schemes would suffer from service failure, inefficient application, and privacy problem when they are applied to the multi-cloud applications. In this paper, we propose a Privacy-preserving Similarity Search scheme termed PSS. We exploit the n-grams method and counting bloom filters to define and compute the keyword-order. Based on this order, all indexing elements could be organized in a Chord-ring to support multi-cloud similarity search with high efficiency. Moreover, we extend the prefix technique to obtain strong privacy protection. Finally, a proof for the non-adaptive semantic security and the chosen-keyword attack resistance of PSS is given. Extensive experiments on real-world dataset further confirm the high efficacy and efficiency of PSS scheme. Jinguo Li, Mi Wen, Chunhua Gu, Hongwei Li 0001 |
ICC | 2 |
| 2016 | Group-Based Authentication and Key Agreement With Dynamic Policy Updating for MTC in LTE-A NetworksabstractMachine type communication (MTC) is an important mobile communication approach in the long-term evaluation-advanced (LTE-A) networks. To meet the MTC security requirements, the access authentication processing of MTC devices needs to follow the evolved packet system-authentication and key agreement (EPS-AKA), a protocol defined in the third generation partnership project (3GPP) standard. However, in the emergence of group-based communication scenarios, an independent authentication processing for each MTC device will cause signal congestion in the networks. In addition, the access-policy updating has always been an issue when constructing authentication schemes. In this paper, we propose a group-based AKA (GR-AKA) protocol with dynamic policy updating. Specifically, we choose an asynchronous secret share scheme combining with Diffie-Hellman key exchange scheme to implement distributed authentication and session key establishment in the LTE-A networks, and to achieve dynamic MTC-device access authority updating. Compared with other authentication protocols in the LTE-A networks, our method could not only authenticate several MTC devices simultaneously but also dynamically update the access-policy to control the access authority of MTC devices. Extensive analysis and experiment results have shown the efficiency and efficacy of proposed protocol. Jinguo Li, Mi Wen |
IEEE Internet Things J. | 2 |
| 2016 | PIMRS: achieving privacy and integrity-preserving multi-owner ranked-keyword search over encrypted cloud dataabstractBecause of the flexibility and convenience brought by cloud computing, it has been adopted in many applications. To preserve the privacy of cloud data, data owner often encrypts all sensitive data files, which makes the keyword search application based on plaintext a very challenging task. Therefore, several privacy-preserving keyword search algorithms have been developed recently, and most of these works support only single-data-owner settings. However, there are always more than one data owners in real applications, which are much more complex and challenging than single-owner scenario. To support multi-owner keyword search, those prior search algorithms need to be repeated several times, because each data owner intends to encrypt his own files with a unique private-key separately. It is absolutely not an efficient way. In this paper, we propose a privacy and integrity-preserving multi-owner ranked-keyword search scheme termed PIMRS. In the PIMRS, we exploit an asymmetric scalar-product encryption function based on the TF × IDF rule to preserve data privacy and to obtain more precise search results. Furthermore, a circular bi-direction-linked list based scheme is proposed to preserve the integrity of search results, which also enables the misbehaviors of cloud server to be detected. The security analysis of PIMRS shows its privacy and integrity property, and extensive experiments based on real-world data set confirm the high efficiency of proposed schemes. Copyright © 2016 John Wiley & Sons, Ltd. Jinguo Li, Mi Wen, Kejie Lu, Chunhua Gu |
Secur. Commun. Networks | 2 |
| 2016 | CIT: A credit-based incentive tariff scheme with fraud-traceability for smart gridabstractAbstract The growing peak‐hour power demand has invoked an urgency to increase the peak‐hour supply. Although smart grid has been envisioned as the next generation power system due to its two‐way communication of information and power, the peak‐hour power shortage problem still exists. In this paper, we propose a credit‐based incentive tariff (CIT) scheme with fraud‐traceability for smart grid. Specifically, the CIT encourages retail customers to sell the power generated by their renewable resources back to the grid during peak hours via giving additional incentive rate to them based on their credits. If a fraud is detected during the power transaction, the malicious customer's identity can be traced out and his or her credit can be correspondingly reduced. The security analysis shows that the CIT resists various security threats and makes the incentive tariff fair and more secure. The performance evaluation demonstrates that the CIT can dramatically increase the peak‐hour supply and reduce the peak‐to‐average power demand ratio by up to 7%. Copyright © 2013 John Wiley & Sons, Ltd. Mi Wen, Kuan Zhang 0001, Jingsheng Lei, Xiaohui Liang 0002, Ruilong Deng, Xuemin Shen |
Secur. Commun. Networks | 1 |
| 2016 | Steganalysis Over Large-Scale Social Networks With High-Order Joint Features and Clustering EnsemblesabstractThis paper tackles a recent challenge in identifying culprit actors, who try to hide confidential payload with steganography, among many innocent actors in social media networks. The problem is called steganographer detection problem and is significantly different from the traditional stego detection problem that classifies an individual object as a cover or a stego. To solve the steganographer detection problem over large-scale social media networks, this paper proposes a method that uses high-order joint features and clustering ensembles. It employs 250-D features calculated from the high-order joint matrices of Discrete Cosine Transform (DCT) coefficients of JPEG images, which indicate the dependencies of image content. Furthermore, a number of hierarchical sub-clusterings trained by the features are integrated as a clustering ensemble based on the majority voting strategy, which is used to make optimal decisions on suspicious steganographers. Experimental results show that the proposed scheme is effective and efficient in identifying potential steganographers in large-scale social media networks, and has better performance when tested against the state-of-the-art steganographic methods. Fengyong Li, Kui Wu 0001, Jingsheng Lei, Mi Wen, Zhongqin Bi, Chunhua Gu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2015 | A Novel Deduplication-Based Covert Channel in Cloud Storage ServiceabstractTo efficiently provide cloud storage services, most providers implement data deduplication schemes so as to reduce storage and network bandwidth consumption. Due to its broad application, many security issues about data deduplication have been investigated, such as data security, user privacy, etc. Nevertheless, we note that the threat of establishing covert channel over cloud storage has not been fully investigated. In particular, existing studies only demonstrate the potential of a single-bit channel, in which a sender can upload one of the two predefined files for a receiver to infer the information of "0" and "1". In this paper, we design a more powerful deduplicationbased covert channel that can be used to transmit a complete message. Specifically, the key features of our design include: (1) a synchronization scheme that can establish a covert channel between a sender and a receiver, and (2) a novel coding scheme that allows each file to represent multiple bits in the message. To evaluate the proposed design, we implement the covert channel and conduct extensive experiments in different cloud storage systems. Our work highlights a more severe security threat in cloud storage services. Hermine Hovhannisyan, Kejie Lu, Rongwei Yang, Jianping Wang 0001, Mi Wen |
GLOBECOM | 6 |
| 2015 | Secure and Verifiable Multi-owner Ranked-Keyword Search in Cloud Computing
Jinguo Li, Yaping Lin, Mi Wen, Chunhua Gu, Bo Yin 0004 |
WASA | 3 |
| 2015 | Achieving efficient and privacy-preserving multi-feature search for mobile sensing
Hongwei Li 0001, Yi Yang 0027, Haomiao Yang, Mi Wen |
Comput. Commun. | 4 |
| 2015 | EAPA: An efficient authentication protocol against pollution attack for smart grid
Mi Wen, Jingsheng Lei, Zhongqin Bi |
Peer-to-Peer Netw. Appl. | 1 |
| 2015 | Secure Data Deduplication With Reliable Key Management for Dynamic Updates in CPSSabstractWith the increasing sensing and communication in cyber physical social system (CPSS), the data volume is growing much rapidly in recent years. Secure deduplication has attracted considerable interests of storage provider for data management efficiency and data privacy preserving. One of the most challenging issues in secure deduplication is how to manage data and the convergent key when users frequently update it. To solve this problem, D. Koo et al. use bilinear paring as the key method. However, bilinear paring requires high computation cost for implementations. In this paper, we propose a session-key-based convergent key management scheme, named SKC, to secure the dynamic update in the data deduplication. Specifically, each data owner in SKC can verify the correctness of the session key and dynamically change it with the data update. Furthermore, to enable group combination and remove the aid of gateway (GW), a convergent key sharing scheme, named CKS, is presented. Security analysis demonstrates that both SKC and CKS can protect the confidentiality of the data and the convergent key in the case of dynamic updates. The simulation results show that our SKC and CKS can significantly reduce computation complexity and communication during the data uploading phase. Mi Wen, Kaoru Ota, He Li 0001, Jingsheng Lei, Chunhua Gu, Zhou Su 0001 |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2014 | Secure dynamic searchable symmetric encryption with constant document update costabstractWith the development of cloud computing, data sharing has a new effective method, i.e., outsourced to cloud platform. In this case, since the outsourced data may contain privacy, they only allow to be accessed by the authorized users. Encrypting the data before outsourcing is a commonly used approach, where the data owners only need to send the corresponding encryption key to the authorized users. However, in such approach it is difficult to use the data since the encrypted data obsoletes comprehensive search functionalities of plaintext keyword search. In this paper, we leverage the secure k-nearest neighbor to propose a secure dynamic searchable symmetric encryption scheme. Our scheme can achieve two important security features, i.e., forward privacy and backward privacy which are very challenging in Dynamic Searchable Symmetric Encryption (DSSE) area. In addition, we evaluate the performance of our proposed scheme compared with other DSSE schemes. The comparison results demonstrate the efficiency of our proposed scheme in terms of the storage, search and update complexity. Yi Yang 0027, Hongwei Li 0001, Haomiao Yao, Mi Wen |
GLOBECOM | 5 |
| 2014 | Achieving ranked range query in smart grid auction marketabstractWith the in-depth study of smart grid, energy auction attracts a lot of attention due to its economic benefits. Many schemes have been proposed to support energy auction in smart grid. However, few of them achieve range query and ranked search. In this paper, we propose a ranked range query (RRQ) scheme, which can support both range query and ranked search. Based on the homomorphic Paillier cryptosystem, we use two super-increasing sequences to aggregate multidimensional keywords. The first one is used to aggregate one buyer's or seller's multidimensional keywords to an aggregated number. The second one is used to create a summary number by aggregating the aggregated numbers of all sellers. As a result, the comparison between the keywords of all sellers and those of one buyer can be achieved with only one calculation, and further we use the comparison result to achieve range query and ranked search. Security analysis demonstrates that RRQ can achieve confidentiality of keywords, authentication, data integrity and query privacy. Performance evaluation shows RRQ's efficiency in terms of computation and communication overhead. Yi Yang 0027, Hongwei Li 0001, Mi Wen, Rongxing Lu |
ICC | 3 |
| 2014 | SESA: an efficient searchable encryption scheme for auction in emerging smart grid marketingabstractDistributed energy resources DERs, which are characterized by small-scale power generation technologies to provide an enhancement of the traditional power system, have been strongly encouraged to be integrated into the smart grid, and numerous trading strategies have recently been proposed to support the energy auction in the emerging smart grid marketing. However, few of them consider the security aspects of energy trading, such as privacy preservation, bid integrity, and pre-filtering ability. In this paper, we propose an efficient searchable encryption scheme for auction SESA in emerging smart grid marketing. Specifically, SESA uses a public key encryption with keyword search technique to enable the energy sellers e.g., DERs to inquire suitable bids while preserving the privacy of the energy buyers. Additionally, to facilitate the seller to search for detailed information of the bids, we also propose an extension of SESA to support conjunctive keywords search. Security analysis demonstrates that the proposed SESA and its extension can achieve data and keyword privacy, bid integrity and trapdoor unforgeability. Simulation results also show that both SESA and its extension have less computation and communication overhead than the existing searchable encryption approaches. Copyright © 2013 John Wiley & Sons, Ltd. Mi Wen, Rongxing Lu, Jingsheng Lei, Hongwei Li 0001, Xiaohui Liang 0002, Xuemin Shen |
Secur. Commun. Networks | 1 |
| 2013 | ECQ: An Efficient Conjunctive Query scheme over encrypted multidimensional data in smart gridabstractWith the deployment of smart meters at individual households, smart grid can collect metering data of users' power consumption. However, users' power usage patterns would also be revealed. To preserve the users' privacy, metering data is mostly encrypted by cryptographic algorithms. When data mining is needed to support decision making or ensure reliability, to find useful information from the encrypted data is very important for smart grid. Most of the traditional keyword searching schemes rarely consider both users' data privacy and requesters' query privacy. In particular, the power system data in smart grid has multidimensional attributes; thus, how to query over the encrypted multidimensional data on all dimensions is a challenging issue in smart grid. To achieve finer grained conjunctive query, this paper proposes an Efficient Conjunctive Query (ECQ) scheme. Specificly, the ECQ incorporates the idea of public key encryption and conjunctive keywords search to achieve conjunctive query without data and query privacy leakage. Security analysis demonstrates that the ECQ can achieve the security requirements, namely, data confidentiality, integrity and privacy, as well as query privacy. In addition, simulation results show that the ECQ can reduce users' computation cost and total communication cost. Mi Wen, Rongxing Lu, Jingsheng Lei, Xiaohui Liang 0002, Hongwei Li 0001, Xuemin Shen |
GLOBECOM | 1 |
| 2010 | Classification of Malicious Software Behaviour Detection with Hybrid Set Based Feed Forward Neural Network
Dawu Gu, Mi Wen, Haming Li |
ISNN (2) | 3 |
| 2010 | Denial of Service Detection with Hybrid Fuzzy Set Based Feed Forward Neural Network
Dawu Gu, Mi Wen, Haming Li |
ISNN (2) | 3 |
| 2009 | When is a key establishment protocol correct?abstractAbstract This paper presents sufficient and necessary conditions to guarantee the security of a Key Establishment (KE) protocol based on our formalism of the belief multisets. The formalism is used to express the security of a KE protocol and to reason about beliefs in the protocol. We observe that a freshness identifier such as a nonce may not be fresh for a legitimate party in a particular protocol run, hence we distinguish a trusted freshness identifier from the commonly used freshness identifier in the sense of a participant's beliefs about the security. A central ingredient in our approach is that all the beliefs should be established on the basis of a trusted freshness identifier. The reasoning results of our approach, comparing with the security conditions, can either establish the correctness of a KE protocol when the protocol is in fact correct, or identify the absence of the security properties, which leads to the structure to construct attacks directly. Two examples, the Kerberos pair‐key agreement approach in distributed sensor networks and the Needham—Schroeder public key protocol, are given to show the usability and the efficiency of our approach. Copyright © 2009 John Wiley & Sons, Ltd. Ling Dong, Kefei Chen, Xuejia Lai, Mi Wen |
Secur. Commun. Networks | 4 |