VLDB 2026 Research / reviewers in the wild / expert
Robert H. Deng
dblp:d/RobertHDeng · also Robert Huijie Deng
· DBLP profile ↗
574ranked-venue papers
31as first author
244since 2021 · last 2026
0000-0003-3491-8146ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 334 · 9 first-author · 150 since 2021Computer networks · 94 · 17 first-author · 35 since 2021Systems, architecture and hardware · 38 · 2 first-author · 19 since 2021Applied, interdisciplinary, general and emerging computing · 31 · 10 since 2021Databases, data management, data science and information retrieval · 25 · 8 since 2021Software engineering, systems software and programming languages · 22 · 18 since 2021Graphics, computer vision, multimedia, augmented reality and games · 22 · 3 first-author · 3 since 2021Artificial intelligence and machine learning · 8 · 4 since 2021Theory of computation · 6 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Understanding the Security of Cloud Storage Services: A Case Study and UC-Secure Design
Pengfei Wu 0003, Xiaoguo Li, Guomin Yang, Tao Xiang 0001, Robert H. Deng |
ACISP (2) | 7 |
| 2026 | Abuse Resistant Traceability with Minimal Trust for Encrypted Messaging Systems
Zhongming Wang, Tao Xiang 0001, Xiaoguo Li, Guomin Yang, Biwen Chen, Ze Jiang, Jiacheng Wang 0001, Chuan Ma 0001, Robert H. Deng |
NDSS | 9 |
| 2026 | PriSrv+: Privacy and Usability-Enhanced Wireless Service Discovery with Fast and Expressive Matchmaking Encryption
Yang Yang 0026, Guomin Yang, Yingjiu Li, Pengfei Wu 0003, Minming Huang, Jian Weng 0001, HweeHwa Pang, Robert H. Deng |
NDSS | 9 |
| 2026 | Robot: Robust Threshold BBS+ in Two Rounds
Guofeng Tang, Haiyang Xue, Guomin Yang, Man Ho Au, Robert H. Deng, Kwok-Yan Lam |
SP | 7 |
| 2026 | Efficient Fuzzy Private Set Intersection from Secret-Shared OPRF
Xinpeng Yang, Meng Hao 0001, Chenkai Weng, Robert H. Deng, Yonggang Wen 0001, Tianwei Zhang 0004 |
SP | 4 |
| 2026 | Xemis: Fair and Robust Privacy-Preserving Data Trading based on Distributed Noise SharingabstractPrivacy-preserving data trading allows data owners to sell data to consumers through a data trading web platform, the data market, without disclosing sensitive information in raw data. It enables legitimate data transmission and aggregation, facilitating large-scale data-driven model training. However, existing differential privacy-based approaches struggle to inject precisely calibrated noise in a trustworthy manner without revealing raw data to a third party, thus making them fail in achieving strong fairness and controllable privacy simultaneously, especially when facing malicious external adversaries or a corrupted data market. Xinxin Xing, Yizhong Liu, Banghong Qin, Wangjie Qiu, Jianwei Liu 0001, Qianhong Wu, Willy Susilo, Robert H. Deng |
WWW | 9 |
| 2026 | DIFEX: A One-to-Many Forward-Style Exchangefor Crosschain Electricity TradingabstractIn IoT-enabled electricity markets, trading is often conducted in a forward-style manner, where parties agree on prices and quantities in advance and settle upon future delivery. However, deploying such forward-style exchanges across chains is incompatible with execution-restricted blockchains and typically incurs significant cross-chain gas overhead. Moreover, existing low-overhead cross-chain mechanisms, particularly HTLC-based schemes, inherently rely on pairwise locking and thus cannot efficiently support one-to-many settlement. We propose an inter-chain forward-style exchange framework based on a dual-track validation architecture. The framework integrates a double-spend fraud-proof mechanism to ensure correctness and a proof-of-acceptance (PoAc) mechanism to reduce cross-chain overhead for successful settlements. We further introduce a novel k-directional hash lock enabling one-to-many settlement, allowing a single buy order to be split across multiple sellers. Our analysis shows that the framework resists griefing attacks, prevents adversarial losses, and preserves cross-chain atomicity. Experiments demonstrate support for execution-restricted blockchains such as Bitcoin, scalability to 862,000 sellers per order, and a 78.25% reduction in settlement cost compared to light-client approaches. Fuyang Deng, Qianhong Wu, Qiyuan Gao, Xiaopeng Dai, Yizhong Liu, Willy Susilo, Robert H. Deng |
IEEE Internet Things J. | 8 |
| 2026 | RF-Chain: A rollback-free inter-shard transaction processing scheme against malicious brokersabstractTo improve the transaction processing rate of blockchain, the existing sharding technology divides a blockchain network into subgroups (i.e., shard), and realizes intra-shard transaction processing locally and inter-shard transaction processing via intermediary accounts (i.e., brokers). However, if the inter-shard processing fails due to malicious brokers, the sharding technology has to carry out a rollback process for blockchain safety such that the transaction processing rate is decreased significantly. In this paper, we present a novel inter-shard transaction processing scheme called Rollback-free Blockchain (RF-Chain for short), which can process inter-shard transaction securely without rollbacks in the presence of malicious brokers. To this end, RF-Chain includes a Deposit Mechanism on a global smart contract, so as to refund the transaction victim if a malicious broker behavior is detected. We developed a RF-Chain prototype and conducted abundant experiments using real Ethereum transaction data. Compared with the existing rollback-based schemes, RF-Chain increases the transaction throughput by 98.3% and decreases the transaction confirmation latency by 85.1% in the presence of malicious activities using 3.7% communication overhead. Thus, RF-Chain can effectively mitigate malicious broker behaviors and achieve lightweight rollback-free processing. Jiaying Ma, Yongdong Wu, Shishi Huang, Jiao Lu, Weichu Deng, Robert H. Deng |
Peer Peer Netw. Appl. | 7 |
| 2026 | FGRW: Fine-Grained Reversible Watermarking Based on Distribution-Adaptive Contrastive Augmentation Across Diverse Domains
Ju Jia, Bo Feng 0002, Anran Li 0001, Cong Wu 0003, Siqi Ma 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2026 | SMInject: Specious Malignant Injection Attacks With Semantically-Enhanced Tokens in Cross-Modal RetrievalabstractThe pre-training multimodal models have achieved remarkable success with powerful cross-modal understanding capabilities, while easily being affected by deliberate injection attacks. Although the deceptive injection attacks are harmful, they are valuable in revealing the vulnerability and improving the robustness for multimodal models. Unfortunately, the existing multimodal injection attacks pay less attention to the complicated roles of different modality-related causal correlation, which results in such attacks being susceptible to detection and defense. To alleviate this issue, we propose a novel specious malignant injection attack framework, calledSMInject, which exploits both the irrationality and causal correlation across diverse modalities to stealthily manipulate the space of output. To enhance the stealthiness, we generate deceptive injections to assemble the concepts by analyzing causal correlation under four types of attacks. To further boost the effectiveness, the malignant injections are guided to penetrate in the encoded embedding space by designing the premise-hypothesis consensus alignment. Extensive experiments on representative multimodal models demonstrate that ourSMInjectachieves over 14% higher attack success rate and 6% higher Hit@5 metric than state-of-the-art methods while preserving the overall utility of models. Moreover, we highlight that theSMInjectalso exhibits the desired transferability by investigating the impact of contextual factors, such as similar attack profiles, imperceptible noise perturbations,etc. Our code is available athttps://anonymous.4open.science/r/SMInject-0DBC. Ju Jia, Jiabao Guo, Xiaojun Jia, Siqi Ma 0001, Jie Gui, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2026 | Boosting the Stealthiness of Backdoor Attack Against Data-Free DetectionabstractThe proliferation of model-sharing platforms has intensified the need for data-free backdoor detection, as deployed models are often accessed without accompanying clean validation data. This constraint renders traditional, data-dependent detection methods ineffective. However, existing strategies to evade data-free detection are inadequate; they frequently fail to circumvent the multi-faceted discriminative criteria of modern detectors that analyze model output behavior, and they often compromise the backdoor model's primary task performance, thus failing to balance attack stealth with functionality. To evade these detections, this paper introduces a Stealthy Backdoor Attack (SBdA) based on label smoothing. Our method dynamically adjusts the training labels for backdoor samples by leveraging the feature similarity between each class and the attacker's target class. This optimization shapes the backdoored model's output distributions to closely mimic those of a benign model, thereby evading detection mechanisms that rely on outlier characterization and posterior distribution analysis. Extensive experiments demonstrate that SBdA maintains a high attack success rate (exceeding 91% under all tested conditions, with 75% of models surpassing 96%) while significantly reducing its detectability. On CIFAR-10, the average outlier score for our models was 0.554-merely 0.050 higher than benign models-compared to a 25.517 deviation for conventional attacks. On GTSRB, SBdA reduced the outlier score gap by 82.86% compared to the average-label technique. Furthermore, by carefully calibrating the posterior distribution, SBdA effectively avoids detection by posterior matrix-based methods across all four tested datasets. Tao Jiang 0017, Zhiquan Liu 0001, Yinbin Miao, Peihan Qi, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2026 | EdgeGuard: Blockchain-Enhanced Secure Data Circulation via Aggregatable Distributed Key GenerationabstractData has become a critical driver of innovation in artificial intelligence and the evolution of 6G technologies. The explosive growth of data volume accelerates the convergence of cloud and edge computing, while simultaneously posing heightened challenges to data security and privacy. The emerging cloud-edge-device collaborative paradigm enables dynamic and large-scale data circulation across heterogeneous entities, exposing systems to complex threats such as malicious edge nodes and eavesdropping over untrusted communication channels. In response to these issues, we propose EdgeGuard, a secure and decentralized framework for cloud-edge-device data circulation. EdgeGuard is specifically designed for highly dynamic environments and ensures robust data confidentiality, integrity, traceability, and resilience against both malicious external attackers and compromised edge servers. To underpin its cryptographic foundation, we develop two core primitives. Specifically, we introduce an Aggregatable Publicly Verifiable Secret Sharing (APVSS) scheme that enables efficient sharing of field elements while supporting aggregation and public verifiability. Furthermore, we construct AggDKG, a distributed key generation (DKG) protocol. AggDKG achieves public verifiability and bias resistance with an expected total communication cost of${\mathcal {O}}(\kappa n^{3})$effectively overcoming the scalability limitations inherent in traditional complaint-based protocols. Collectively, these components form a comprehensive framework that strengthens secure and efficient data circulation in cloud-edge-device systems. Experimental data show that AggDKG delivers clear performance gains: across all tested scales, its total running time is only about 8%–65% of that of the DKG of Gurkan et al., and at$n=256$, it reduces per-node runtime by approximately 27% compared with the DKG of Gennaro et al. These results highlight EdgeGuard's superior scalability, lower latency, and stronger Byzantine resilience for secure large-scale deployments. Boyang Liao, Jianwei Liu 0001, Xinxin Xing, Qianhong Wu, Willy Susilo, Robert H. Deng, Yizhong Liu |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2026 | Security-Enhanced Decentralized Conditional Privacy-Preserving Authentication in VANETsabstractTo ensure the legitimacy of communicators while ad dressing the privacy concerns of vehicles in vehicular ad-hoc networks (VANETs), conditional privacy-preserving authentication (CPPA) schemes have been proposed. Given that existing schemes suffer from single point of failure due to centralized authorities, several distributed CPPA schemes have been proposed. However, these schemes all ignore the tight cementation between system secret keys and the authority, which could be a serious threat to system security, that the compromised authority may leak the system secret key. To address these issues, we propose a security enhanced decentralized conditional privacy-preserving authentication (DCPPA) scheme. DCPPA first introduces a decentralized system master key generation (DSMKG) mechanism without a centralized secret sharer, ensuring that the system secret key remains hidden from any single authority. Based on DSMKG, DCPPA then implements a lightweight verifiable pseudonym self-generation strategy without the system master secret key escrow problem, thus providing flexible pseudonym updating and reliable de-anonymization. Moreover, we implement DCPPA over a hyperelliptic curve cryptosystem (HECC) to balance the system performance. Considering the additional communication processes due to the decentralized feature, we introduce a symmetric balanced incomplete block design (SBIBD) to enhance the communication efficiency. We demonstrate the excellent security of DCPPA through an in-depth security analysis, while demonstrate that the overhead of DCPPA is at ms level through experiments. Shuqin Luo, Xinghua Li 0001, Yinbin Miao, Xuelin Cao, Yunwei Wang, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2026 | FEAC: A New Construction of Fast and Expressive Anonymous Credential for Cloud ServiceabstractAnonymous credentials are an essential cryptography primitive to protect user privacy and provide fine-grained access control for proving ownership and rights of specific credentials. There are currently two roadmaps to designing anonymous credentials: one is signature credentials, which are constructed by signature with efficient protocols and non-interactive zero-knowledge proofs, and the other is functional credentials, which are transformed from predicate encryption schemes. However, none of the existing instances of anonymous credentials support$expressive$access policies expressed as conjunction, disjunction, or arbitrary Boolean formulas, which are particularly useful for cloud services. In this paper, we propose a new fast and expressive anonymous credential, called FEAC. It is constructed with the unique$dual$$randomness$$splitting$technique, which combines the most efficient anonymous key-policy attribute-based encryption (USENIX 24) and short randomizable signature (CT-RSA 18) to balance efficiency, expressiveness, and security, demonstrating a new way to instantiate anonymous credentials. Furthermore, our credential presentation protocol offloads most of the time-consuming computation to the cloud server (11 pairing) to reduce the computational burden on the user side (2 pairing). We propose formal definitions and formal security proofs of FEAC. We provide implementations and evaluate the performance of FEAC, comparing it to state-of-the-art work. Huamin Feng, Chunjie Cao, Yang Yang 0026, Baitao Zhang, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2026 | LatInc: A Practical Lattice-Based Privacy-Preserving Incentive SystemabstractIncentive (or point) systems are widely deployed across industries such as retail, tourism, and finance to enhance customer loyalty and create benefits for service providers. However, their operation typically requires the collection and processing of sensitive customer data, leading to significant privacy concerns. Existing privacy-preserving incentive systems predominantly rely on bilinear pairings and the discrete logarithm assumption, which, while efficient in classical settings, are vulnerable to quantum adversaries and thus lack long-term security guarantees. To address this limitation, we present LatInc, a practical lattice-based privacy-preserving incentive system. LatInc integrates state-of-the-art lattice-based signatures with efficient protocols, the ABDLOP commitment, and efficient lattice zero-knowledge proofs, achieving a robust balance between post-quantum security and efficiency. Relying on the hardness of the MLWE and MSIS problems, we formally prove that LatInc achieves unforgeability, anonymity, and framing-resistance in the random oracle model. We implement a demo of the system and evaluate its performance on a standard laptop platform. Experimental results show that the communication overheads for the Earning and Spending protocols are approximately 99 KB and 140 KB, respectively, with execution times of 610 ms and 900 ms, highlighting significant efficiency gains over previous lattice-based incentive constructions. Huamin Feng, Yang Yang 0026, Zhen Guo 0003, Chunjie Cao, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2026 | Hecate: Threshold Anonymous Credentials With Private Verifiers and Issuer-Hiding
Huamin Feng, Yang Yang 0026, Yingjiu Li, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2026 | Traceable Cross-Domain Data Sharing With Expressive Keyword SearchabstractThe Internet of Vehicles (IoV) generates massive sensitive perception data, typically managed by manufacturer-specific domains. While encryption with domain-specific parameters protects confidentiality, many IoV applications require secure cross-domain data sharing to access complementary information, and expressive keyword search for efficient access. However, existing Attribute-Based Keyword Search (ABKS) schemes are designed for single-domain settings, and thus cannot address heterogeneous key management or provide traceability without a universally trusted authority. To address these issues, we propose TCroS, a traceable cross-domain data sharing scheme that generalizes CP-ABE via proxy re-encryption mechanism, enabling ciphertexts generated in one domain to be securely transformed for authorized requesters in another. To provide traceability, TCroS embeds requester identities into decryption keys using Boneh-Boyen signatures, allowing any party (rather than the universally trusted authority) to trace the source of a leaked key. We further extend TCroS to TCroSS, which incorporates privacy-preserving expressive keyword search supporting Boolean queries, thereby enabling efficient retrieval of authorized data while resisting keyword guessing attacks. Formal security analysis proves that our schemes achieve IND-SCPA and IND-SCKA security. Experimental results demonstrate their practicality, showing that cross-domain sharing can be realized with computation and storage overheads comparable to single-domain setting. Qiuyun Tong, Xiyun Yao, Zhe Ren, Yinbin Miao, Xinghua Li 0001, Meng Li 0006, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2026 | HyperSiniel: Guaranteed Output Delivery Comes (Almost) Free in Private Delegation of zkSNARKsabstractZero-knowledge Succinct Non-interactive Argument of Knowledge (zkSNARK) is a powerful cryptographic primitive that enables a prover to convince a verifier that something is true without leaking the private witness. Current zkSNARKs face significant computational costs in generating proofs, which restricts their use in areas like private payments, confidential smart contracts, and anonymous credentials. Private delegation offers a practical solution by outsourcing the heavy computation to powerful external workers without leaking any private information. In this work, we propose HyperSiniel, an efficient private delegation framework for general zkSNARKs that achieves a new feature called guaranteed output delivery (GOD). HyperSiniel is designed to be compatible with any universal zkSNARKs constructed from a polynomial interactive oracle proof (PIOP) and a polynomial commitment scheme (PCS). It enables a computationally limited delegator to outsource proof generation to several workers in a fully non-interactive and privacy-preserving manner. Compared to the most state-of-the-art frameworks (e.g., Siniel [NDSS'25]), HyperSiniel ensures that the delegator always receives a correct proof, regardless of malicious worker behavior. We implement HyperSiniel and compare the performance with Siniel across varying bandwidths and circuit sizes. Under low-bandwidth conditions (10MBps), HyperSiniel incurs only an additional 25% overhead compared with Siniel, while the total running time of HyperSiniel is almost identical to Siniel under high-bandwidth settings (1000MBps). These results show that the strong robustness guarantee of GOD in HyperSiniel comes almost for free, making it a practical and secure solution for real-world zkSNARK delegation. Yunbo Yang, Yuejia Cheng, Junkai Liang, Kailun Wang, Xuanming Liu, Xiaoguo Li, Jianfei Sun, Xiaolei Dong, Zhenfu Cao, Meng Hao 0001, Guomin Yang, Robert H. Deng, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 13 |
| 2026 | CPFL: Lightweight Communication-Efficient and Privacy-Preserving Federated LearningabstractThe combination of Deep Learning (DL) and Federated Learning (FL) makes it a popular paradigm to train powerful models securely on large-scale data in a distributed way. However, current solutions face challenges such as significant communication overheads for clients with limited resources, potential privacy risks arising from FL's distributed nature, and the inability to maintain model accuracy without loss under high compression ratios. To solve these issues, we propose a lightweight Communication-efficient and Privacy-preserving FL scheme CPFL by designing Cyclic Segmented Compressive Sensing (CSCS) and using efficient Symmetric Homomorphic Encryption (SHE), which greatly reduces the number of transmitted model weights without sacrificing model accuracy. Formal analysis shows the security of CPFL against known-plaintext attacks and ensures model convergence. Extensive experiments demonstrate that CPFL achieves remarkable model accuracy under more than 200× compression ratio, and even reduces the communication cost by 99.5% compared with previous solutions. Li Yang 0005, Yinbin Miao, Rongpeng Xie, Xinghua Li 0001, Ju Wu, Guowen Xu, Zhiquan Liu 0001, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 9 |
| 2026 | SeVoAuth: Secure Voiceprint Authentication With Hash-Based Feature TransformationabstractWhile voiceprint authentication offers convenient user authentication and access control through voice feature recognition, a critical research gap remains: existing voiceprint authentication systems fail to simultaneously achieve sound security against replay, spoofing, and adversarial attacks, preserve voice privacy leakage, and satisfy usability demand. Previous efforts have struggled to balance these issues comprehensively. To bridge this gap, we present SeVoAuth, a cloud-based Voiceprint Authentication as a Service (VAaaS) system designed to provide privacy preservation, robust security, and enhanced usability. SeVoAuth stores a synthesized voiceprint of a user in the cloud during user registration, thereby safeguarding the privacy of the real voiceprint of the user. During user authentication, SeVoAuth applies a hash function to continuously transform features of the synthesized voiceprint, dynamically generating new verification targets for voiceprint feature mapping in each authentication session. This dynamic transformation approach effectively mitigates replay, spoofing, and adversarial attacks without requiring complex user interactions. We conduct a thorough analysis on the security and privacy of SeVoAuth and proceed to implement a prototype for performance evaluation through a series of user tests. Experimental results demonstrate that SeVoAuth outperforms cutting-edge approaches, achieving an average authentication accuracy of 99.47%, and an average Precise Detection Rate (PDR) of 98.35% against various attacks. SeVoAuth is evaluated as highly secure, efficient, and user-friendly across various circumstances. Rui Zhang 0081, Zheng Yan 0002, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Txtail: A Practical Transaction Relay Incentive Scheme for BitcoinabstractTransaction propagation delay limits the block interval and is one of the main bottlenecks in improving Bitcoin throughput. However, transaction relay in Bitcoin is entirely voluntary, which results in low bandwidth and high transaction propagation delay. Improving relay motivation by introducing incentives can effectively reduce delay, but it still faces challenges such as Sybil attacks during reward allocation, leakage of network layer privacy, and high on-chain/off-chain overhead. Therefore, this paper proposes Txtail, a practical transaction relay incentive scheme for Bitcoin, based on continuously attaching relay evidence representing the relays’ identity and contribution during transaction propagation. We employ a free pricing mechanism based on the game between relays to allocate rewards fairly. We design an order-insensitive relay evidence structure based on aggregate signatures and public key mapping, which reduces off-chain data overhead while alleviating the leakage of relay paths by obfuscating the relay order. We construct a verifiable lottery mechanism based on Merkle tree commitments to reduce the data that needs to be uploaded to the chain. Both theoretical and experimental results show that Txtail reduces the per-hop off-chain overhead and the overall on-chain overhead by 96.6% and 79.8%, respectively, compared with state-of-the-art baselines, while remaining practical for deployment. Xiaopeng Dai, Qianhong Wu, Fuyang Deng, Mingzhe Zhai, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2026 | SharBipole: Secure and Scalable Sharding Blockchain-Based Federated Learning Against Poisoning AttacksabstractFederated Learning (FL) enables collaborative model training across distributed devices while preserving data privacy. However, it faces critical security challenges, including centralization risks and poisoning attacks, which degrade robustness and scalability. Existing schemes struggle to simultaneously mitigate targeted and untargeted poisoning attacks, impose restrictive adversary ratio assumptions (poison ratio < 50%), and suffer from privacy-performance trade-offs. To address these limitations, we propose SharBipole, a decentralized FL scheme integrating sharding blockchain with a novel dual-metric defense mechanism, Bipole. SharBipole employs a Byzantine Fault Tolerant-enabled sharding architecture to eliminate single points of failure, reduce communication overhead, and enable parallel model aggregation. Meanwhile, the Bipole module defends against poisoning attacks using two adaptive similarity metrics to filter malicious updates dynamically. Reinforcement learning optimizes threshold adjustments, while noise-aware adaptive clipping balances privacy and model utility. Further, we give convergence analysis to prove the theoretical soundness and scalability of SharBipole. Lastly, extensive experimental evaluations demonstrate that SharBipole supports poison ratios exceeding 50% and improves throughput and latency. The model replacement attack with 60% adversaries is entirely ineffective against SharBipole, and the label-flipping attack achieves an attack success rate of only 2.344%. SharBipole establishes a scalable, secure, and privacy-preserving solution for distributed learning in massive environments. ZiAn Jin, Dawei Li 0009, Jianwei Liu 0001, Hao Peng 0001, Qianhong Wu, Zhenyu Guan 0002, Willy Susilo, Robert H. Deng, Yizhong Liu |
IEEE Trans. Inf. Forensics Secur. | 8 |
| 2026 | Multi-Leader Byzantine Fault Tolerance in Blockchain: Performance and Security
Yizhong Liu, Mingzhe Zhai, Xun Lin, Chenhao Ying 0001, Zhenyu Guan 0002, Dawei Li 0009, Qianhong Wu, Jianwei Liu 0001, Willy Susilo, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 11 |
| 2026 | Search Me in the Dark: Access Pattern-Hidden Range Query Over Encrypted Spatial DataabstractWith the widespread use of encrypted spatial data, many range query schemes emerge to address potential security risks caused by access pattern leakage. However, most existing schemes rely on a dual-server model to hide access patterns and often involve complex spatial relation judgments during range comparisons, leading to low query efficiency. To address these issues, we propose a novel Fast and Access Hidden Range Query (FAHRQ) scheme. First, we introduce an efficient range membership verification technique based on Bloom filters and Lagrange interpolation function, combine homomorphic encryption to ensure the confidentiality of spatial data and the computational flexibility of related operations, and realize the access pattern hidden under single server. Then, we construct an index using R-tree and employ Bloom filters and prefix 0-1 encoding to accelerate the minimum bounding rectangle intersection judgment, enabling secure and efficient range queries over encrypted spatial data while maintaining retrieval accuracy. Finally, we give a formal security analysis to show that our scheme achieves access pattern hidden while protecting data security, and conduct extensive experiments to demonstrate that our scheme improves query efficiency by 5 – 7× compared to existing schemes. Yinbin Miao, Xin Wang 0037, Kaifa Zheng, Xinghua Li 0001, Zhiquan Liu 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 8 |
| 2026 | FlyCred: Contractual Anonymous Credentials Based on Oracles and EventsabstractIn a scenario where an issuer wishes to issue an attribute-based anonymous credential to a user, this issuance is conditional on a number of real-world outcomes. These outcomes involve multiple entrusted oracles confirming the occurrence of several events, after which the issuance can proceed successfully. Such contractual credentials can serve as an important building block for blockchain-based Web 3.0 systems and can be used in real-world applications that require privacy-preserving, prescheduled authorization. However, there is currently no work that enables the pre-issuance of credentials based on oracles and events. In this work, we propose contractual anonymous credentials, called FlyCred, to fill this gap. With FlyCred, the issuer can issue an encrypted credential to a user, controlled by a dual-layer authorization policy consisting of oracle-based and event-based expressive policies. As core building blocks, we introduce two novel cryptographic primitives: the Adaptor Anonymous Credential and ABE-based Signature Witness Encryption with Tags, which can serve as independent interests. We provide efficient instantiations of these primitives and evaluate their performance under different security levels and system parameters on a laptop, showing that the computation and communication overhead of the credential pre-issuance is less than 85.8 seconds and 8.7 MB, respectively. Yang Yang 0026, Huamin Feng, Yingjiu Li, Chunjie Cao, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2026 | Robust Identity-Based Signcryption Scheme for Vehicular Ad Hoc NetworksabstractVehicular Ad Hoc Networks (VANETs) are the cornerstone of intelligent transportation systems and autonomous driving. Vehicle-to-road communication, as one of the core services, faces increasing risks of privacy breaches. Signcryption technology effectively ensures secure information transmission. However, existing signcryption schemes still have deficiencies in terms of transmission robustness and identity privacy protection. To solve these issues, this paper proposes a Robust Identity-based Signcryption scheme (RIBSC) for VANETs. In RIBSC, we first design an area session key distribution mechanism based on Chinese Residual Theorem (CRT), which can dynamically revoke the decryption ability of malicious Roadside Units (RSUs) in real time. Only RSUs approved by Trusted Detection Center (TDC) can obtain a valid session private key by conducting one modular operation. We then utilize the traceable pseudonym mechanism to protect the identity privacy of vehicles and RSUs, which can track their true identities when illegal activities occur. We finally provide a rigorous security proof under the random oracle model, and demonstrate the performance advantages of RIBSC through extensive experiments. More attractively, the session information is fixed at only 148 bytes, regardless of the number of RSUs. Xin Wang 0037, Yinbin Miao, Xinghua Li 0001, Hongwei Li 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2026 | Efficient Heterogeneous Signcryption With Forward Privacy for Vehicular Platoon Communication
Xin Wang 0037, Yinbin Miao, Xinghua Li 0001, Zhiquan Liu 0001, Jun Feng 0007, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2026 | RFA-Tex: Range-Flexible Adaptive Physical Adversarial Texture Against Real-World Person Detectors
Mengyao Zhu 0004, Xinghua Li 0001, Decheng Liu, Shunjie Yuan, Yigang Li, Yinbin Miao, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 8 |
| 2026 | Security-Enhanced Spatial Range Query Over Large-Scale Encrypted Mobile Cloud Datasets
Yinbin Miao, Xinghua Li 0001, Jun Feng 0007, Zhiquan Liu 0001, Robert H. Deng |
IEEE Trans. Mob. Comput. | 7 |
| 2026 | Efficient Mobile-Cloud Collaborative Aggregation for Federated Learning With Latency ResilienceabstractWith the rapid growth of mobile and edge computing, federated learning (FL) has emerged as a key technology to enable collaborative model training on mobile devices while preserving user privacy. Secure aggregation is an essential component in FL to protect local gradients and compute the global model, but it is vulnerable to threats from high-latency. When some clients arrive late, the pairwise masks among clients cannot be canceled properly, forcing the server to learn the late clients' masks in order to complete the aggregation. As a result, network uncertainty puts the aggregation process at risk of either service interruption or privacy leakage. While double masking is treated as the most effective solution to achieve both robustness and privacy, its computational and communication costs are prohibitive, especially for resource-constrained mobile devices. To address these challenges, we propose an Efficient Mobile-Cloud Collaborative Aggregation for Federated Learning with Latency Resilience (EFL-LR). We leverage Shamir's secret sharing and a key-homomorphic pseudorandom function to ensure privacy for high-latency clients while reducing computation overheads to$\mathcal {O}(n\log ^{2} n + d)$for clients and$\mathcal {O}(n+d)$for the server. Formal security analysis confirms its latency resilience and privacy guarantees. Experimental results show that EFL-LR achieves 2–$3\times$lower client-side computation cost and accelerates server-side aggregation recovery by at least$10\times$. Yinbin Miao, Zhou Su 0001, Robert H. Deng |
IEEE Trans. Mob. Comput. | 6 |
| 2026 | Defend Against Label Inference Attacks in Vertical Federated Learning via Label CompressionabstractVertical federated learning (VFL) has been widely adopted in various domains for collaborative decision-making. However, recent studies have revealed critical privacy vulnerabilities in VFL, particularly label inference attacks, which significantly undermine label confidentiality and limit the applicability of VFL in privacy-sensitive scenarios. To mitigate such threats, several defense methods have been proposed by incorporating diverse privacy-preserving techniques. Nevertheless, existing defenses fail to effectively prevent the recently proposed model completion-based label inference attacks. To address this limitation, we propose a novel defense method, termed Label Compression-Based Defense (LCD), to defend against this class of attacks. The core idea of LCD is to train the VFL model using fake labels, thereby decoupling the ground-truth labels from the outputs of the malicious bottom model, which constitute the critical component exploited in the model completion-based attacks. Specifically, we introduce a multi-stage training strategy that decomposes the training process into different stages to deceive the malicious bottom model without affecting the original task. In addition, we design a deep feature-based label compression mechanism to generate fake labels for misleading the attacker. To further enhance the defense effectiveness, we propose an embedding compaction strategy based on center loss, which substantially increases the difficulty of label inference. Moreover, we theoretically prove the effectiveness of LCD from an information-theoretic perspective. Extensive experiments on both tabular and image datasets demonstrate that LCD can effectively defend against label inference attacks. The source code of LCD is publicly available at GitHub:https://github.com/YuanShunJie1/LCD. Shunjie Yuan, Xinghua Li 0001, Xuelin Cao, Robert H. Deng, Zhu Han 0001, Mérouane Debbah, Chau Yuen |
IEEE Trans. Mob. Comput. | 5 |
| 2026 | Secure Authentication and Encryption With Distributed Management for SAGIN via Signcryption and Sharding BlockchainabstractWith the development of air transportation, Space-Air-Ground Integrated Network (SAGIN) are playing an increasingly important role in optimizing air traffic management and enhancing flight safety for billions of passengers and trillions dollars of aviation industry. As the key technology of SAGIN, the Automatic Dependent Surveillance-Broadcast (ADS-B) system is widely used due to its simple operation, low construction cost, and high information accuracy. However, the security problems in ADS-B system, including lack of identity authentication between all communication links, crucial information transmitted in plaintext, and susceptibility to the single point of failure, have been serious obstacle to its wide application. Existing solutions fail to account for the unique characteristics of ADS-B and SAGIN, leading to inadequate security and poor performance in these specialized contexts. Aiming to solve the above issues and provide security and scalability for ADS-B system, we conduct the following research. Firstly, an enhanced identity-based broadcast signcryption (e-IBBSC) scheme is designed to keep crucial information confidential and all messages authenticated simultaneously. Secondly, we propose an efficient batch message authentication method combined with the Merkle tree and proposed e-IBBSC, significantly improving the ADS-B message utilization ratio from 1.35% to 74.10%. Thirdly, we utilize the sharding blockchain and Byzantine fault tolerance protocol to design the first sharding-based distributed management system for SAGIN that realizes fault tolerance and scalability. Finally, after a detailed security analysis and comprehensive performance evaluation, we demonstrate that our solution can achieve all proposed system goals including security, scalability, and high performance of 1s flight transaction processing latency and 62KTPS throughput. Yizhong Liu, Xuqi Huang, Runhua Xu, Jianwei Liu 0001, Qianhong Wu, Willy Susilo, Robert H. Deng |
IEEE Trans. Netw. | 9 |
| 2025 | DeGain: Detecting GAN-Based Data Inversion in Collaborative Deep Learning
Zhenzhu Chen, Yansong Gao 0001, Anmin Fu, Fanjian Zeng, Boyu Kuang, Robert H. Deng |
ACISP (3) | 6 |
| 2025 | An Efficient Security-Enhanced Accountable Access Control for Named Data Networking
Jianfei Sun, Xuehuan Yang, Guomin Yang, Robert H. Deng |
ESORICS (4) | 5 |
| 2025 | IvyAPC: Auditable Generalized Payment Channels
Ming Li 0049, Jian Weng 0001, Yingjiu Li, Jia-Si Weng 0001, Junzuo Lai, Robert H. Deng |
FC | 7 |
| 2025 | SecInfer: Secure and Efficient Model Inference on Vertically Partitioned DataabstractDeep learning models have achieved unprecedented success in various domains, such as healthcare and finance. However, deploying model inference in real-world applications, where data is distributed among multiple entities, poses significant privacy concerns. Existing secure model inference work has limitations in computational overhead and scalability, especially when dealing with complex models and multiple parties with vertically partitioned data. In this work, we design and implement an efficient and scalable secure inference framework for vertically partitioned data, supporting execution with a large number of parties. Our work considers a semi-honest setting with all-but-one corruptions. The core of our framework is a series of secure and efficient protocols for complex non-linear functions of the model inference, such as ReLU and Maxpool. These protocols are designed based on secure multi-party computation preliminaries, significantly enhancing efficiency while maintaining rigorous security guarantees. We conduct comprehensive experiments to evaluate the performance of our framework. Experimental results show that SecInfer substantially improves the communication and computation performance of secure naive inference works by up to 3.71 × and 3.42 ×, respectively. Robert H. Deng, Hongwei Li 0001, Hanxiao Chen 0001, Meng Hao 0001, Pengzhi Xing, Jia Hu 0004, Rui Zhang 0086, Wenbo Jiang 0001 |
ICC | 1 |
| 2025 | SPD: Shallow Backdoor Protecting Deep Backdoor Against Backdoor Detection
Shunjie Yuan, Xinghua Li 0001, Xuelin Cao, Mengyao Zhu 0004, Robert H. Deng |
ICCV | 6 |
| 2025 | Multi-Level Normalizing Flow for Comprehensive Anomaly Detection and LocalizationabstractUnsupervised anomaly detection identifies deviations from normal patterns as anomalies. Recently, unsupervised methods have made significant strides in anomaly detection. However, single-scale feature extraction struggles to capture subtle anomalies and existing methods frequently emphasize exclusively on local information while disregarding global semantic information. In this paper, we propose a new normalizing flow called Multi-Level Normalizing Flow (MLFlow) for anomaly detection and localization. First, we input normal images and extract multi-scale features using a pre-trained feature extractor. Second, MLFlow receives the multi-scale feature maps and density estimate. StepFlow and ConvergeFlow are the two main modules of MLFlow. Specifically, the StepFlow independently transforms each layer of feature maps, allowing the lower layer to capture detailed features, the middle layer to extract local features and the top layer to extract semantic information. Additionally, the ConvergeFlow combines transformed multi-scale feature maps, enhancing the comprehensive analysis capability for anomalies. Experimental results on MVTec AD, BeanTech AD and VisA datasets reveal that the proposed method performs exceptionally well in anomaly detection and localization tasks, surpassing existing methods and achieving the state-of-the-art performance. Shijie Guo, Robert H. Deng, Jianan Xie |
ICME | 4 |
| 2025 | Conditional Attribute-Based PRE: Definition and Construction from LWE
Jian Weng 0001, Pengfei Wu 0003, Guofeng Tang, Guomin Yang, Haiyang Xue, Robert H. Deng |
ISC | 7 |
| 2025 | Impact Tracing: Identifying the Culprit of Misinformation in Encrypted Messaging Systems
Zhongming Wang, Tao Xiang 0001, Xiaoguo Li, Biwen Chen, Guomin Yang, Chuan Ma 0001, Robert H. Deng |
NDSS | 7 |
| 2025 | Siniel: Distributed Privacy-Preserving zkSNARK
Yunbo Yang, Yuejia Cheng, Kailun Wang, Xiaoguo Li, Jianfei Sun, Xiaolei Dong, Zhenfu Cao, Guomin Yang, Robert H. Deng |
NDSS | 10 |
| 2025 | Leakage-Resilient Easily Deployable and Efficiently Searchable Encryption (EDESE)abstractEasily Deployable and Efficiently Searchable Encryption (EDESE) is a cryptographic primitive designed for practical searchable applications, offering efficient search and easy deployment. However, it remains vulnerable to Leakage-Abuse attacks, allowing adversaries to exploit keyword-matching processes to extract sensitive information. To address these vulnerabilities, we introduce Leakage-Resilient EDESE (LR-EDESE) with k-indistinguishability and controlled leakage functions. We then propose Volume Leakage-Resilient EDESE (VLR-EDESE), a new scheme to protect against both query and document volume leakage. Our experimental results demonstrate that at k = 5000 (maximum security setting), VLR-EDESE incurs an overhead of 63× compared to the baseline EDESE without leakage protection, outperforming state-of-the-art methods with 320× and 97× overhead, respectively. For smaller k values (10, 20, 50, 100), storage and communication overhead remain within 2× and 2.5× of the baseline EDESE, highlighting VLR-EDESE's flexibility. Finally, we present CloudSec, an implementation of VLR-EDESE that seamlessly integrates with cloud storage platforms, using OneDrive as an example. Jiaming Yuan, Yingjiu Li, Jun Li 0001, Daoyuan Wu, Jianting Ning, Yangguang Tian, Robert H. Deng |
SACMAT | 7 |
| 2025 | Attribute-Based Conditional PRE: A Novel Construction from LWE for Cloud Data-SharingabstractSecure and efficient data sharing is essential in cloud environments, where data owners must delegate decryption rights without re-encrypting data for each user. Proxy Re-Encryption (PRE) addresses this by allowing a proxy to transform ciphertexts for authorized recipients without accessing the plaintext. As a variant, Attribute-Based Conditional PRE (AB-CPRE) enhances traditional PRE by incorporating two key features: (1) attribute-based access control, and (2) conditional ciphertext transformation based on a specified policy. Despite significant advancements, existing AB-CPRE schemes face a trilemma in balancing functionality and security, hindering their use in cloud data-sharing: (1) support limited to single-hop re-encryption, restricting multi-hop scenarios; (2) a weak security model relying on selective security without allowing the adversary to choose the target attributes or policies adaptively; and (3) an insufficient security guarantee only targeting chosen plaintext attacks (CPA), offering no protection against honest re-encryption attacks (HRA).In this paper, we propose the first AB-CPRE scheme tailored to the cloud environment that simultaneously supports multi-hop transformation, adaptive-policy security, and resistance to HRA. Our construction is based on the learning with errors (LWE) assumption in the standard model, making it also quantum-resistant. We prove security through a novel re-encryption key simulatability technique, allowing the simulation of the re-encryption key without knowing the corresponding secret key, which is of independent interest. Through a comprehensive performance comparison, our scheme demonstrates a lower decryption overhead and a comparable re-encryption key size, showing its practicality compared to the state-of-the-art schemes while offering stronger security and functionality. Jian Weng 0001, Pengfei Wu 0003, Guofeng Tang, Haiyang Xue, Guomin Yang, Robert H. Deng |
TrustCom | 7 |
| 2025 | Practical Keyword Private Information Retrieval from Key-to-Index Mappings
Meng Hao 0001, Liqiang Peng, Pengfei Wu 0003, Lei Zhang 0006, Hongwei Li 0001, Robert H. Deng |
USENIX Security Symposium | 8 |
| 2025 | AKMA+: Security and Privacy-Enhanced and Standard-Compatible AKMA for 5G Communication
Yang Yang 0026, Guomin Yang, Yingjiu Li, Minming Huang, Zilin Shen, Imtiaz Karim, Ralf Sasse, David A. Basin, Elisa Bertino, Jian Weng 0001, HweeHwa Pang, Robert H. Deng |
USENIX Security Symposium | 12 |
| 2025 | Efficient Homomorphic-Encryption-Based Secure Search in Multiowner Setting for Internet of ThingsabstractEnsuring the security of data outsourced to cloud is a prerequisite for the application of Internet of Things (IoT) in actual production. Secure search based on homomorphic encryption can provide high security and require no expensive setup procedure, which can be applied to resource-limited devices in IoT. However, the existing schemes usually have poor search performance and do not consider multiowner setting. To solve these issues, we propose an efficient homomorphic encryption-based secure search scheme in multiowner setting. Specifically, we construct a secure search protocol based on multikey homomorphic encryption, which can be deployed in multiowner setting. Meanwhile, we improve the efficiency of our scheme by optimizing the search algorithm. Formal security analysis proves that our scheme is secure against chosen plaintext attack, and extensive experiments demonstrate that our scheme improves the search efficiency by$1000\times $when compared with state-of-the-art solutions. Yinbin Miao, Xinghua Li 0001, Tao Leng, Zhiquan Liu 0001, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Internet Things J. | 8 |
| 2025 | Moving Target Defense Meets Artificial-Intelligence-Driven Network: A Comprehensive SurveyabstractBased on emerging artificial intelligence (AI) tasks, cloud-edge–terminal architecture can provide powerful computing, intelligent interconnection, and real-time response, which can also be regarded as AI-driven network. Unfortunately, multiple network layers in the AI-driven network usually face various types of network threats, such as malicious network reconnaissance, side-channel attacks, and distributed denial of service (DDoS). Traditional security solutions respond to network threats after the occurrence of attacks. To solve this problem, the concept of moving target defense (MTD) has been proposed as a proactive defense mechanism that aims to defend against cyber attacks before they occur. In this article, we first provide a thorough analysis of the threats in the cloud-edge–terminal network. Then, we conduct a comprehensive survey to discuss the concept, design principles, and main classifications of MTD. Next, we further introduce the development potential in terms of AI-powered MTD on each network layer. Meanwhile, we also explore how MTD improves the security of AI algorithms. Lastly, we describe the existing challenges and research directions of MTD. The aim of this article is to provide an in-depth understanding for the readers on how to realize the integration between MTD and AI-driven network. Tao Zhang 0063, Fanyu Kong 0003, Dongshang Deng, Xiangyun Tang, Xuangou Wu, Changqiao Xu, Liehuang Zhu, Jiqiang Liu, Bo Ai 0001, Zhu Han 0001, Robert H. Deng |
IEEE Internet Things J. | 11 |
| 2025 | DCASR: Distributed Collaborative Authentication With Specified Security Strength and Resource Optimization Selection in AAV NetworksabstractCollaborative authentication, boasting-enhanced accuracy, robust resilience, and optimized efficiency, holds immense promise for autonomous aerial vehicle (AAV) networks. However, existing collaborative authentication methods overlook both the credibility evaluation and incentives of participating nodes, thereby compromising authentication accuracy and resulting in failures. Furthermore, reliance on trusted decision-fusion institution introduces vulnerabilities and single points of failure. To address these issues, we design a credibility-weighted soft authentication approach specifically for AAV networks, thereby enhancing accuracy by effectively integrating the trustworthiness of collaborating nodes. To further encourage active participation from nodes, we introduce an incentive-based reputation system. Finally, based on the above approaches, we propose a distributed authentication method by leveraging blockchain technology and optimization theory that not only emphasizes security but also optimizes resource selection in AAV networks. Theoretical analysis demonstrates our scheme’s distributed authentication with minimized resource consumption under specified security strength, mitigating single points of failure and fulfilling efficient mutual authentication requirements. Experimental results show a remarkable 78.45% increase in authentication accuracy and a 44.51% reduction in resource consumption compared to advanced solution. Yunwei Wang, Xinghua Li 0001, Yinbin Miao, Robert H. Deng |
IEEE Internet Things J. | 5 |
| 2025 | Quantum-Resistant Sharding Blockchain and Its Application in Secure Data TransmissionabstractWith the approach of the quantum era, public key cryptography (PKC) faces risks, which also presents challenges to blockchain technologies that utilize PKC as a core component. Sharding blockchain is a promising way to realize scalability, yet current research does not consider quantum-resistant sharding blockchains as it is non-trivial to design cross-shard communication and transaction processing method without PKC. Besides, blockchain enables reliability in data transmission and unbreakable communication while current schemes suffer from high overhead and low throughput. In this paper, we propose a quantum-resistant sharding blockchain (QRShar) and a secure data transmission scheme (QRDT) to fill the above gap. Firstly, we design a secure and efficient cross-shard communication pattern utilizing hash-based message authentication code (HMAC) and erasure code to reduce the transmission load and achieve high efficiency. Secondly, we propose the a quantum-resistant sharding blockchain utilizing optimized cross-shard transaction processing method to decrease the consensus execution frequency. Thirdly, we introduce a quantum-resistant key agreement protocol through the verifiable secret sharing on cryptographic hash function and we also offer a data transmission scheme to realize efficient QRDT. Furthermore, we conduct security analysis and performance evaluations for our schemes. The results show that the QRShar throughput can reach up to 34 KTPS and the latency stays below 2 seconds. The key agreement latency is just 43ms. Yizhong Liu, Xun Lin, Zhenyu Guan 0002, Dawei Li 0009, Jianwei Liu 0001, Qianhong Wu, Willy Susilo, Robert H. Deng |
IEEE J. Sel. Areas Commun. | 9 |
| 2025 | Secure and Efficient Cross-Modal Retrieval Over Encrypted Multimodal DataabstractWith the popularity of social media, mobile devices and the Internet, a large amount of multimodal data (e.g, text, image, audio, video, etc.) is increasingly being outsourced to cloud to save local computing and storage costs. To search through encrypted multimodal data in the cloud, privacy-preserving cross-modal retrieval (PPCMR) techniques have attracted extensive attention. However, most of the existing PPCMR schemes lack the ability to resist quantum attacks and have low search efficiency on large-scale datasets. To solve above problems, we first propose a basic PPCMR scheme FECMR using the enhanced Single-key Function-hiding Inner Product Functional Encryption for Binary strings (SFB-IPFE) and cross-modal hashing technology, which achieves the measurement of similarity over encrypted multimodal data while resisting quantum attacks. Then, we design an efficient index KM-tree utilizing the K-modes clustering algorithm. On this basis, we propose an improved scheme FECMR+, which achieves sub-linear search complexity. Finally, formal security analysis proves that our schemes are secure against quantum attacks, and extensive experiments prove that our schemes are efficient and feasible for practical application. Li Yang 0005, Wei Zhang 0308, Yinbin Miao, Yanrong Liang, Xinghua Li 0001, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Computers | 7 |
| 2025 | Delegatable Multi-Authority Attribute-Based Anonymous CredentialsabstractIn cloud computing, users need to authenticate to access various resources. Attribute-based anonymous credentials (ABCs) provide a tool for privacy-preserving authentication, allowing users to prove possession of a set of attributes to cloud service providers anonymously. Most existing works on ABC deal with credentials on attributes issued by a single authority (issuer). In reality, it is more practical for users to obtain credentials on attributes from multiple authorities. There are a few works on multi-authority ABC, which do not support delegation needed in real deployments. In this article, we present the first delegatable multi-authority attribute-based anonymous credential system, which simultaneously achieves revocation and traceability. We also give the security analysis of our construction. Finally, we implement our system, and the experimental results show its efficiency. Junzuo Lai, Xiaohan Mo, Peng Li 0059, Cheng-Kang Chu, Robert H. Deng |
IEEE Trans. Cloud Comput. | 7 |
| 2025 | Privacy-Preserving User Recruitment With Sensing Quality Evaluation in Mobile CrowdsensingabstractRecruiting users in mobile crowdsensing (MCS) can make the platform obtain high-quality data to provide better services. Although the privacy leakage during the process of user recruitment has received a lot of research attention, none of the existing work considers the evaluation of the sensing quality of privacy-preserving data submitted by users, which makes the platform incapable of recruiting users suitably to obtain high-quality sensing data, thereby reducing the reliability of MCS services. To solve this problem, we first propose a sensing quality evaluation method based on the deviation and variance of sensing data. According to it, the platform can obtain the sensing quality of privacy-preserving data for each user during the recruitment. Then we model the user recruitment with a limited budget platform as aCombinatorial Multi-Armed Bandit (CMAB)game to determine the recruited users based on the sensing quality of data obtained by evaluation. Finally, we theoretically prove that our algorithm satisfies differential privacy and the upper bound on theregretof rewards is restricted. Experimental results show that our proposal is superior in various properties, and our method has a 73.67% advantage in accumulated sensing qualities compared with comparison schemes. Jieying An, Yanbing Ren, Xinghua Li 0001, Man Zhang 0010, Bin Luo 0006, Yinbin Miao, Ximeng Liu, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 8 |
| 2025 | SIGFinger: A Subtle and Interactive GNN Fingerprinting Scheme Via Spatial Structure Inference PerturbationabstractThere have been significant improvements in intellectual property (IP) protection for deep learning models trained on euclidean data. However, the complex and irregular graph-structured data in non-euclidean space poses a huge challenge to the IP protection of graph neural networks (GNNs). To address this issue, we propose a subtle and interactive GNN fingerprinting scheme through spatial structure inference perturbation, which captures the stable coordination patterns of fingerprint to guarantee the reliability of copyright verification. Specifically, the data augmentation based on adaptive graph diffusion is first exploited to generate more samples, which enables the exploration of fingerprint information from coarse to fine. Subsequently, the graph-structured data are manipulated by multi-constrained spectral clustering to analyze intrinsic and extrinsic structure correlations in a causal inference manner. Ultimately, the cycle-consistent statistical optimization is performed to determine the copyright of GNN models from both intra-graph and inter-graph perspectives. Extensive experiments show that our proposed scheme can effectively verify the IP of GNN models on various challenging graph-structured datasets. Furthermore, we reveal that the space causality inference can facilitate the acquisition of inherent structural information, which improves the quality and robustness of the fingerprint under model modification operations and other model stealing attacks. Ju Jia, Cong Wu 0003, Siqi Ma 0001, Lina Wang 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | Privacy-Preserving Ridge Regression Over Encrypted Data Under Multiple Keys
Junzuo Lai, Beibei Song, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | How to Securely Delegate and Revoke Partial Authorization CredentialsabstractAn attribute-based credential (ABC) system allows a user, obtaining a credential on a set of attributes from an issuer, to anonymously prove a subset of attributes to a service provider. Nowadays, delegation is an important requirement of ABC, which allows a user to delegate his credentials to other users. However, traditional delegatable ABC systems only support delegating a credential with all attributes. In many scenarios, an appropriate delegation is a user can delegate his credential on parts of attributes to others. Another requirement is revocation of credentials in case of unexpected events. In this article, we propose a delegatable and revocable attribute-based credential, which simultaneously achieves: (1) a user can delegate a credential on parts of attributes to other entities (devices/users); (2) a user can efficiently revoke his credentials or those delegated by him; (3) a user can selectively disclose some attributes and also can prove that the non-disclosed attributes satisfy some relations. To achieve our delegatable and revocable attribute-based credential, we introduce a new primitive, called purgeable signature (PS). We formally define the security model of PS. We then give an efficient construction with a constant-size signature and present the security proofs of PS. Finally, the experimental results show the efficiency of our system. Junzuo Lai, Wei Wu 0001, Cheng-Kang Chu, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | Sanitizable Cross-Domain Access Control With Policy-Driven Dynamic AuthorizationabstractThe increasing demand for secure and efficient data sharing has underscored the importance of developing robust cryptographic schemes. However, many existing endeavors have overlooked the following critical issues: (1) unauthorized access resulting from malicious information leakage by senders; (2) absence of constraints on write and read permissions for participants; (3) and inflexibility of strategies to dynamically designate ciphertexts to multiple recipients. In this paper, we present SCPA, a cross-domain access control scheme imbued with sanitization features and propelled by policy-driven dynamic authorization, tailored for cloud-based data sharing. This scheme not only facilitates access controls, including regulations for no-read and no-write stipulations, governing the data permissible for senders to transmit and recipients to acquire but also enables the dynamic sharing of a data ciphertext subset with additional recipients beyond the originally sanctioned ones. We also provide comprehensive security proofs rigorously indicating the security of the invented SCPA. Moreover, to assess the efficacy of our SCPA, we undertake thorough theoretical and experimental analyses, showcasing its feasibility and superior performance. Jianfei Sun, Guowen Xu, Hongwei Li 0001, Tianwei Zhang 0004, Cong Wu 0003, Xuehuan Yang, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2025 | Private Reachability Queries on Structured Encrypted Temporal Bipartite GraphsabstractA temporal bipartite graph is a graph model that incorporates time-related information into its edges, making it suitable for modeling real-world phenomena like disease outbreaks. However, this temporal information is often sensitive. To protect the privacy of graph data, researchers have explored various approaches to preserve privacy in graph queries, with reachability queries being popular and fundamental as they determine the possibility of reaching one node from others in a graph. While privacy-preserving reachability queries have been extensively studied, existing efforts often overlook the valuable attribute information present in both edges and nodes of the graphs. Moreover, reachability queries on temporal bipartite graphs have not received sufficient attention in the literature. To bridge this gap, we propose a novel approach to achieve various privatereachabilityqueries onstructured encryptedtemporalbipartitegraphs ($\mathsf{RQ}$-$\mathsf{STBG}$) through a real-world scenario. Specifically, we construct a minimal index using hierarchical 2-hop labels and integrate structured encryption, order-revealing encryption, and garbled Bloom filters to support reachability queries with different label constraints. The proposed scheme is flexible and can cater to the query requirements of diverse users. Security analysis and experimental evaluations demonstrate that the proposed scheme achieves both preferable security and efficiency. Lanxiang Chen, Gaolin Chen, Yi Mu 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | AccCred: Improved Accountable Anonymous Credentials With Dynamic Triple-Hiding CommitteesabstractAccountable anonymous credentials protect user privacy while holding the accountability of ill-intentioned individuals, which is a critical feature for applications such as online payments and other financial services. Existing accountable anonymous credentials rely on a public committee of trustworthy members who are assumed not to collude and are well protected to perform privacy revocation. However, this assumption is unsound in blockchain-based cryptocurrency systems because the selected committees may involve nodes with significant stakes, and public nodes serving as committee members are vulnerable against targeted attacks from high-computing power adversaries. In this paper, we propose an improved accountable anonymous credential called AccCred, allowing users and issuers to randomly select a hidden committee within a set of authenticated candidates for privacy revocation. No one except the members with corresponding private keys knows their identity, preventing proactive attacks. As a core component, we introduce the primitive of dynamic triple-hiding committees (DTHC), which achieves authentication, dynamic join/delete, random selection, and strong anonymity of committee members. As a building block of DTHC, we design a shuffle protocol to provide efficient shuffle proof of randomized public keys. We formally prove our scheme and compare its performance with previous work for demonstration of practicality. Sijiang Xie, Yang Yang 0026, Huiqin Xie, Yingjiu Li, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | General Test-Time Backdoor Detection in Split Neural Network-Based Vertical Federated LearningabstractAs a new distributed machine learning framework, vertical federated learning (VFL) has been widely applied in the industry. However, recent studies have demonstrated that VFL faces serious challenges from backdoor attacks, which significantly hinder its further development. Although a few studies have focused on defending against VFL backdoor attacks, these defenses either do not consider the latest attack methods or show limited effectiveness. Moreover, most existing backdoor defense efforts primarily focus on backdoor attacks in horizontal federated learning (HFL) and centralized learning. Due to the unique architecture of VFL models, these methods cannot be directly applied to backdoor defense in VFL. To mitigate the threat of backdoor attacks in VFL, we propose a general backdoor detection (GBD) scheme for backdoor defense, which detects backdoor samples by analyzing the correlation between backdoor samples and the target label, as well as by leveraging the response differences between clean and backdoor samples. Specifically, we propose two backdoor detection metrics: Class Activation Probability (CAP) and Class Activation Contribution (CAC), which are used to calculate the likelihood of a sample being a backdoor sample. We leverage these two metrics to identify backdoor samples during the inference stage. Evaluation results on both tabular and image datasets show that GBD can detect backdoor samples with high accuracy, demonstrating its effectiveness in backdoor defense. The source code of GBD is available at GitHub: https://github.com/YuanShunJie1/GBD. Shunjie Yuan, Xinghua Li 0001, Xuelin Cao, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | An Incentive Mechanism for Privacy Preserved Data Trading With Verifiable Data DisturbanceabstractTo motivate data owners’ (DOs’) trading willingness, the existing incentive mechanisms allow DOs to independently disturb data following data consumer's (DC’s) availability requirement. However, they cannot motivate DOs’ honest disturbance, which is attributed to DOs’ independent disturbance without any supervision. Thus, we implement an incentive mechanism for privacy preserved data trading with verifiable data disturbance where an honest-but-curious disturbance generator (DG) is additionally introduced to supervise DOs’ local disturbance and assist disturbance verification between DOs and DC. Specifically, DG generates the disturbance strategies and secretly distributes to DOs following private information retrieval, guaranteeing DOs's local disturbance's privacy and verifiability with our proposed three-level verification algorithm. Subsequently, we model the trading as a game and disturbance verification results determine the compensation and punishment for trading bilateral utilities following Nash Equilibrium where DOs honestly disturb data. Theoretical analysis shows that DOs are motivated to honestly disturb data and their raw data privacy is preserved. Extensive experiments using the real-world dataset demonstrate that the deviating DOs in our scheme can be verified with a probability of more than 90% and the statistical result accuracy can be improved by more than 80% compared with the existing works. Man Zhang 0010, Xinghua Li 0001, Bin Luo 0006, Yanbing Ren, Yinbin Miao, Ximeng Liu, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2025 | Accuracy-Enabling Differential Privacy-Preserving Truth DiscoveryabstractPerturbation-based privacy-preserving truth discovery requires the Service Provider (SP) to calculate the truthful aggregation result from perturbed data of the Data Sources (DSs), which inevitably damages the aggregation accuracy due to perturbation noise added in the data. Thus, the existing works attempt to relieve the perturbation errors by reducing noise amounts or adjusting aggregation weights of DSs. However, the former sacrifices DSs' privacy preservation and the latter has the limited accuracy recovery performance. Aiming at it, we propose an accuracy-enabling differential privacy-preserving truth discovery consisting of an independence-guaranteed data perturbation module and a progressive-private noise elimination module. Specifically, in the first module, SP generates mass of noises following DS's desired perturbation parameters and DS privately obtains one of noise based on private information retrieval. Meanwhile, to realize the perturbation's traceability, SP preserves the ciphertext of DSs' acquired noises, assisting the following noise elimination. In the second module, SP first removes his preserved DS's encrypted noise from perturbed truth according to homomorphic encryption, and then requires DS to decrypt this cleaned truth. The above two processes are progressively and iteratively implemented until all DSs have been involved. Theoretical analysis shows that our scheme can protect DSs' raw data privacy in both truth discovery process and noise elimination process. Extensive experiments using the real-world dataset demonstrate that our scheme can effectively eliminate more than 90% of the perturbation noise effects on the truth discovery accuracy. Man Zhang 0010, Xinghua Li 0001, Yinbin Miao, Bin Luo 0006, Siqi Ma 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | FL-CDF: Collaborative Defense Framework for Backdoor Mitigation in Federated LearningabstractFederated learning (FL) is vulnerable to backdoor attacks due to its distributed nature. Existing unilateral defense mechanisms often fail against persistent attack strategies, primarily due to their limited perspectives. To address the challenge of model misclassification on the server side caused by overlooked model similarity drift, and gradient misjudgment on the client side caused by semantic learning imbalances across classes, this paper proposes a collaborative defense framework for federated learning, termed FL-CDF. FL-CDF establishes an end-to-end defense through a bidirectional client-server collaboration mechanism. Specifically: (1) On the client side, an adversarial perturbation-based malicious neuron detection module is introduced. This module measures neuron activation sensitivity by generating adversarial perturbations, and adaptively prunes backdoor neurons exhibiting high sensitivity. (2) On the server side, a multi-dimensional detection scheme is designed, which integrates neuron localization, adversarial sensitivity, and model parameters. By incorporating client-side feedback on malicious neurons, the server performs robust model aggregation. Theoretical analysis verifies the robustness of FL-CDF, and extensive experiments on public benchmarks demonstrate its effectiveness. In the best-case scenario, FL-CDF improves defense performance by 42.5% compared to current state-of-the-art (SOTA) defense. Xinghua Li 0001, Yinbin Miao, Shunjie Yuan, Mengyao Zhu 0004, Ximeng Liu, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2025 | Understanding the Bad Development Practices of Android Custom Permissions in the WildabstractAndroid system provides application developers with the ability to define custom permissions, which serve to regulate the sharing of resources and functionalities with other applications. However, developers' improper development practices can render the permission mechanism ineffective, facilitating easy exploitation by attackers. This paper presents a comprehensive examination of the problematic practices surrounding custom permissions employed by developers, referred to as Bad Practices of Custom Permissions (BPCP issues). To accomplish this, we conducted an empirical study and identified nine common BPCP issue patterns that can lead to various adverse consequences, such as installation failures, crashes, and even component hijacking. To automatically identify these patterns of bad practices, we devised PERMEAGRE, a static analysis tool. Employing PERMEAGRE, we performed a large-scale analysis of 83,085 applications obtained from seven major app markets, aiming to detect instances of BPCP issues. The results revealed that more than 26% of the analyzed apps contained at least one issue, and a significant number of apps had garnered millions of downloads. Our analysis delved into the underlying causes of these issues. Consequently, this analysis sheds light on the potential threat landscape associated with bad practices in custom permissions, emphasizing the urgent requirement for effective mitigation strategies. Zhiyuan Yu 0001, Xinghua Li 0001, Cen Zhang, Cong Sun 0001, Ning Zhang 0017, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2025 | Distributional Black-Box Model Inversion Attack With Multi-Agent Reinforcement LearningabstractModel Inversion (MI) attacks based on Generative Adversarial Networks (GAN) aim to recover private training data from complex deep learning models by searching codes in the latent space. However, this method merely searches in a deterministic latent space, resulting in suboptimal latent codes. Additionally, existing distributional MI schemes assume that an attacker can access the structures and parameters of the target model, which is not always feasible in practice. To address these limitations, this paper proposes a novel Distributional Black-Box Model Inversion (DBB-MI) attack by constructing a probabilistic latent space for searching private data. Specifically, DBB-MI does not require the target model’s parameters or specialized GAN training. Instead, it identifies the latent probability distribution by integrating the output of the target model with multi-agent reinforcement learning techniques. Then, it randomly selects latent codes from the latent probability distribution to uncover private data. As the latent probability distribution closely mirrors the target privacy data in the latent space, the recovered data effectively leaks the privacy of the target model’s training samples. Extensive experiments conducted on diverse datasets and networks demonstrate that our DBB-MI outperforms state-of-the-art MI attacks in terms of attack accuracy, K-nearest neighbor feature distance, and peak signal-to-noise ratio. Huan Bao, Kaimin Wei, Yongdong Wu, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | Keyword-Pair Result Pattern Hiding Structured Encryption for Boolean QueriesabstractCash et al. [CRYPTO2013] proposed the oblivious cross-tags (OXT) protocol to enable highly scalable searchable symmetric encryption (SSE) with support for Boolean queries. More recently, Lai et al. [CCS2018] introduced the hidden cross-tags (HXT) protocol, an enhancement of OXT designed to eliminate “keyword-pair result pattern” (KPRP) leakage in conjunctive queries. However, while HXT prevents KPRP leakage in conjunctive queries, it suffers from low efficiency and remains vulnerable to KPRP leakage in disjunctive queries. In this paper, we propose the first efficient structured encryption scheme for Boolean queries (STE-BQ) that eliminates KPRP leakage for both disjunctive and conjunctive multi-keyword queries. Our approach introduces a novel index construction method based on prime number aggregation, which significantly reduces the number of comparisons required in multi-keyword searches, thereby improving efficiency. Security analysis confirms that STE-BQ satisfies CQA2-security. Experimental evaluations further demonstrate that STE-BQ achieves optimal performance in conjunctive query processing. While its disjunctive query time is slightly slower than that of OXT, STE-BQ is the only scheme that fully eliminates KPRP leakage for both conjunctive and disjunctive queries. Lanxiang Chen, Yi Mu 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Efficient One-to-Many Authentication With Intelligent Illegal Request Identification for UAV NetworksabstractIn Unmanned Aerial Vehicle (UAV) networks, UAVs usually perform tasks in the form of groups. When tasks change, the Ground Control Station (GCS) will assign the complemental UAV to join the group for notification or reinforcement. Since UAVs communicate over open wireless channels, secure authentication is required for complemental UAV joining the group. However, one-by-one authentication between complemental UAV and the group members leads to high overhead and delays. At the same time, when the UAV group is far away from the coverage of the GCS, the GCS is unable to assist the authentication process in real-time. To solve the above problems, we propose a one-to-many UAV authentication scheme using Identity-Based Broadcast Encryption (IBBE) and batch authentication. This scheme does not require a trusted third party to be online in real time. We also design an algorithm based on reinforcement learning for identifying illegal requests during batch authentication, enhancing efficiency and ensuring successful authentication. Our scheme meets UAV networks’ security requirements, defending against various attacks. Experimental results show that it reduces computational overhead by 55.27% and communication overhead by 23.16% compared to similar schemes. Additionally, the illegal request identification algorithm reduces identification numbers by 15.44% to 25.72% and lowers latency by 14.64% to 25.12% compared to existing methods. Zekai Chen 0006, Zhe Ren, Xinghua Li 0001, Yunwei Wang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | Environment-Adaptive Representation Interaction for Privacy-Perturbed Graphs Against Deceptive OOD AttacksabstractGraph neural networks (GNNs) have gained increasing popularity in understanding graph-structured data due to their ability to derive meaningful representations by aggregating complicated topological information. However, privacy operations such as differential privacy mechanisms that inject noise into node features or graph structures to protect sensitive information, and distribution shifts in graph data pose tremendous security risks for the wide application of GNN models. Current researches mainly focus on defending the out-of-distribution (OOD) attacks through robust adversarial training and graph structure purification. Nonetheless, privacy perturbations of graph structures may render OOD attacks more deceptive by obfuscating the distinctiveness of nodes, leading to the failure of existing defense methods. To address these shortcomings, we propose an environment-adaptive representation interaction (EARI) scheme that strengthens the privacy perception of GNNs. Specifically, our scheme leverages the interaction between non-private and private data to enable targeted embedding propagation by the guidance of confidence score feedback. Subsequently, the representation-enriched topological aggregation is implemented to capture more discriminative features by exploiting multi-hop neighborhoods rather than stacked multilayers. Finally, the generalization-enhanced cluster-wise adaptation learning is leveraged to highlight the invariant correlations from nodes across different environments. Extensive experimental results demonstrate that our scheme can enhance the capability of learning representations from privacy-protected graph data, enabling GNNs to effectively defend against deceptive OOD attacks on various graph-structured datasets. Moreover, we reveal that the utilization of interactive topological aggregation can extremely enrich the diversity and guarantee the effectiveness for graph representations. Ju Jia, Cong Wu 0003, Yebo Feng, Siqi Ma 0001, Lina Wang 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2025 | Efficient and Verifiable Proof of Replicated StorageabstractAllowing users to assure that their files are reliably stored into multiple replicas is critically important but challenging for secure cloud storage. Recently, Damgård et al. [1] designed the first publicly verifiable proof of replicated storage (abbreviated as PRI-POREP) in the private client setup without the fine-grained timing assumption. However, it relies on an “ideal” invertible random permutations (IRPs), whose construction with the structured domain/range remains open even in the random oracle model. Also, it is computationally inefficient in terms of both replicas generation and file update. To address challenges regarding both practicality and efficiency while guaranteeing the security of PRI-POREP, this paper aims at constructing a new proof of replicated storage scheme without timing assumption, named as μPRI-POREP. μPRI-POREP is secure against server-side deletion of replica blocks and it works efficiently, saving computation cost by orders of magnitude, compared to PRI-POREP. Moreover, we demonstrate that μPRI-POREP can also support efficient dynamic update and can be further applied to secure the RSA-Hourglass schemes. Finally, we evaluate μPRI-POREP with a prototype implementation and exhibit that it can achieve comparable performance compared to PRI-POREP and support efficient file update operation. Tao Jiang 0017, Yinbin Miao, Xinghua Li 0001, Jianfeng Ma 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | AuditPCH: Auditable Payment Channel Hub With Privacy ProtectionabstractAnonymous Payment Channel Hub (PCH), one of the most promising layer-two solutions, settles the scalability issue in blockchain while guaranteeing the unlinkability of transacting parties. However, such developments bring conflicting requirements, i.e., hiding the sender-to-receiver relationships from any third party but opening the relationship to the auditor. Existing works do not support these requirements simultaneously since off-chain transactions are not recorded in the blockchain. Further, the privacy protection strategies hinder auditors from capturing the payment relationships. Thus, it is still a challenge to audit the finance activities of PCH transacting parties. This paper proposes a novel anonymous PCH solution called AuditPCH to achieve privacy and auditability. Concretely, we design a Linkable Randomizable Puzzle scheme for constructing conditional transactions, allowing a sender to pay for a receiver via the hub. As such, AuditPCH, with the new LRP scheme, ensures that 1) payment relationships can be protected from the hub and 2) an auditor with necessary trapdoors can associate the sender and receiver of a payment. We prove the security of AuditPCH under the Global Universal Composability framework. The extensive experimental evaluations on AuditPCH are established to demonstrate its functionality and flexibility. Jian Weng 0001, Junzuo Lai, Yingjiu Li, Jiahe Wu, Ming Li 0049, Jianfei Sun, Pengfei Wu 0003, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 9 |
| 2025 | Trace Your Footprint: Efficient Spatial Keyword Query Over Encrypted Trajectory DataabstractWith the popularity of mobile devices, spatial-textual trajectory query has been deployed in applications such as trajectory-based navigation and travel route recommendation. Massive trajectory data have been outsourced to cloud servers for storage and sharing such as spatial keyword search. However, existing solutions only support similarity queries in the spatial dimension and still incur high storage and query costs, which cannot scale well in large-scale trajectory data scenarios. To solve the above issues, we first achieve an Efficient Range Query over Encrypted Trajectory Data (ERT) using Douglas-Peucker trajectory compression algorithm, random matrix multiplication, filtering-verification mechanism and polynomial fitting technology. Then, we further propose an enhanced Efficient Spatial Keyword Query over Encrypted Trajectory Data (ESKT) by constructing a unified spatial-textual index structure, which can find relevant trajectories that are within some arbitrary geometric range and contain all query keywords. Finally, we formally prove that our schemes are secure against chosen-plaintext-attack, and conduct extensive experiments to demonstrate that our schemes improve the query efficiency by almost 100× when compared with state-of-the-art solutions. Yinbin Miao, Xin Wang 0037, Xinghua Li 0001, Shujiang Xu, Zhiquan Liu 0001, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 8 |
| 2025 | Forward-Secure Hierarchical Delegable Signature for Smart HomesabstractAiming to provide people with great convenience and comfort, smart home systems have been deployed in thousands of homes. In this paper, we focus on handling the security and privacy issues in such a promising system by customizing a new cryptographic primitive to provide the following security guarantees: 1) fine-grained, privacy-preserving authorization for smart home users and integrity protection of communication contents; 2) flexible self-sovereign permission delegation; 3) forward security of previous messages. To our knowledge, no previous system has been designed to consider these three security and privacy requirements simultaneously. To tackle these challenges, we put forward the first-ever efficient cryptographic primitive called the Forward-secure Hierarchical Delegable Signature (FS-HDS) scheme for smart homes. Specifically, we first propose a new primitive, efficient Hierarchical Delegable Signature (HDS) scheme, which is capable of supporting partial delegation capability while realizing privacy-preserving authorization and integrity guarantee. Then, we present an FS-HDS for smart homes with the efficient HDS as the underlying building block, which not only inherits all the desirable features of HDS but also ensures that the past content integrity is not affected even if the current secret key is compromised. We provide comprehensively strict security proofs to prove the security of our proposed solutions. Its performance is also validated via experimental simulations to showcase its practicability and effectiveness. Jianfei Sun, Guowen Xu, Yang Yang 0026, Xuehuan Yang, Xiaoguo Li, Cong Wu 0003, Zhen Liu 0008, Guomin Yang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 9 |
| 2025 | ROBY: A Byzantine-Robust and Privacy-Preserving Serverless Federated Learning FrameworkabstractFederated Learning (FL) allows multiple data owners to jointly train machine learning models by sharing local models instead of raw private data, alleviating data privacy concerns. However, as the local computation of data owners is unpredictable, it increases its vulnerability to Byzantine attacks, where compromised data owners submit abnormal local models that can severely degrade global model accuracy. Existing Byzantine-robust FL methods depend on a semi-honest server executing predefined Byzantine-robust aggregation rules (ByRules) to filter out abnormal local models, but these methods fail when the server is compromised. Although recent serverless Byzantine-robust FL approaches mitigate the risk of a compromised server, they suffer from challenges in achieving consensus on ByRules and impose a heavy burden on privacy protection. In this paper, we propose ROBY, a novel serverless FL framework that extends existing ByRules to a decentralized setting, effectively defending against Byzantine attacks and ensuring privacy protection for local models. ROBY introduces a shared, dynamically updated consensus dataset that serves as a reliable benchmark for applying ByRules and enabling efficient consensus on ByRules among decentralized data owners. Moreover, we design a dual-layer privacy shielding strategy in ROBY to protect local model privacy without sacrificing global model accuracy or incurring extra computational and communication overhead. Extensive evaluations demonstrate that ROBY substantially enhances both Byzantine robustness and privacy protection compared to server-based FL methods. Xiangyun Tang, Minyang Li, Meng Shen 0001, Jiawen Kang 0001, Liehuang Zhu, Zhiquan Liu 0001, Guomin Yang, Dusit Niyato, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 9 |
| 2025 | Enforcing Differential Privacy in Federated Learning via Long-Term Contribution IncentivesabstractPrivacy-preserving Federated Learning (FL) based on Differential Privacy (DP) protects clients’ data by adding DP noise to samples’ gradients and has emerged as a de facto standard for data privacy in FL. However, the accuracy of global models in DP-based FL may be reduced significantly when rogue clients occur who deviate from the preset DP-based FL approaches and selfishly inject excessive DP noise beyond expectations, thereby applying a smaller privacy budget in the DP mechanism to ensure a higher level of security. Existing DP-based FL fails to prevent such attacks as they are imperceptible. Under the DP-based FL system and random Gaussian noise, the local model parameters of the rogue clients and the honest clients have identical distributions. In particular, the rogue local models show a low performance, but directly filtering out lower-performance local models compromises the generalizability of global models, as local models trained on scarce data also behave with low performance in the early epoch. In this paper, we propose ReFL, a novel privacy-preserving FL system that enforces DP and avoids the accuracy reduction of global models caused by excessive DP noise of rogue clients. Based on the observation that rogue local models with excessive DP noise and honest local models trained on scarce data have different performance patterns in long-term training epochs, we propose a long-term contribution incentives scheme to evaluate clients’ reputations and identify rogue clients. Furthermore, we design a reputation-based aggregation to avoid the damage of rogue clients’ models on the global model accuracy, based on the incentive reputation. Extensive experiments demonstrate ReFL guarantees the global model accuracy performance 0.77% - 81.71% higher than existing DP-based FL methods in the presence of rogue clients. Xiangyun Tang, Luyao Peng, Meng Shen 0001, Liehuang Zhu, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | Oblivious Encrypted Keyword Search With Fine-Grained Access Control for Cloud StorageabstractWith the rapid expansion of data volumes in cloud computing, more data owners are opting to outsource their data to cloud service providers to reduce local storage and management costs. However, data outsourcing deprives data owners of direct physical control over their data, increasing the risk of unauthorized access and exposure of sensitive information. To mitigate these risks, various privacy-preserving keyword search schemes with access control have been developed, but many are vulnerable to leakage-abuse attacks due to the exposure of access, search or volume patterns, which can lead to privacy breaches in outsourced data and queries. To solve this problem, we propose an oblivious encrypted keyword search scheme with fine-grained access control, called OEKA. It enables efficient oblivious keyword search over encrypted multi-maps by using the adapted XOR filter and distributed point function, ensuring protection of access, search and volume patterns. Moreover, OEKA enforces role-based access control by using polynomial-based access strategy and keyword-based private information retrieval, allowing access policies of retrieved objects to be detecting without revealing the objects themselves. A formal security analysis verifies the scheme’s robustness, and experimental results demonstrate its practical efficiency. Qiuyun Tong, Junyi Deng, Xinghua Li 0001, Yinbin Miao, Yunwei Wang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | A Lightweight Consensus Mechanism for Large-Scale UAV Networking
Jingjing Wang 0001, Yizhong Liu, Xin Zhang 0039, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | DkvSSO: Delegatable Keyed-Verification Credentials for Efficient Anonymous Single Sign-OnabstractAnonymous single sign-on (ASSO) is an anonymous multi-service authentication method for end users. However, existing ASSO schemes suffer from heavy ticket requesting and verifying overheads, limiting their applications in large-scale settings. To address this problem, we propose a novel concept called keyed-verification anonymous credentials with disposable delegation (KVAC-DD) in the multi-verifier setting. Next, we extend KVAC-DD to build an efficient ASSO system, dubbed DkvSSO. The construction of DkvSSO can be instantiated in efficient prime-order groups, avoiding costly operations required in previous ASSO systems. We formally prove the security of our proposed constructions. Extensive experiments show that DkvSSO is significantly more efficient than existing ASSO schemes, making it suitable to be deployed in large-scale settings. Wenyi Xue, Yang Yang 0026, Minming Huang, Yingjiu Li, HweeHwa Pang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | DISC: Decentralized Identity System With Self-Sovereign Credential AggregationabstractThe evolution of decentralized identity (DID) and self-sovereign identity (SSI) frameworks, as endorsed by W3C Verifiable Credentials (VC) and eIDAS 2.0, underscores the need for secure, efficient, and privacy-preserving credential management. However, existing credential systems often depend on centralized issuers, lack efficient aggregation mechanisms, or fail to ensure unlinkability across authentication sessions. To address these challenges, we propose DISC (Decentralized Identity System with Self-Sovereign Credential Aggregation), a novel credential system that enables multi-authority credential issuance, user-controlled credential aggregation, and unlinkable authentication. DISC allows users to aggregate credentials from multiple issuers while maintaining constant-size authentication tokens and supporting batch verification for scalable authentication. Additionally, DISC ensures unlinkability of aggregated authentication tokens, preventing verifiers from correlating sessions even when credentials share attributes. Security analysis proves DISC’s unforgeability, anonymity, and unlinkability, while experimental results confirm its efficiency in credential issuance, aggregation, and verification. Compared to existing schemes, DISC offers a scalable, privacy-preserving, and efficient decentralized identity solution, making it well-suited for real-world applications requiring secure and privacy-preserving identity verification. Yang Yang 0026, Wai Keung Ching, Minming Huang, Supachate Innet, Guomin Yang, HweeHwa Pang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2025 | Enhanced Model Poisoning Attack and Multi-Strategy Defense in Federated LearningabstractAs a new paradigm of distributed learning, Federated Learning (FL) has been applied in industrial fields, such as intelligent retail, finance and autonomous driving. However, several schemes that aim to attack robust aggregation rules and reducing the model accuracy have been proposed recently. These schemes do not maintain the sign statistics of gradients unchanged during attacks. Therefore, the sign statistics-based scheme SignGuard can resist most existing attacks. To defeat SignGuard and most existing cosine or distance-based aggregation schemes, we propose an enhanced model poisoning attack, ScaleSign. Specifically, ScaleSign uses a scaling attack and a sign modification component to obtain malicious gradients with higher cosine similarity and modify the sign statistics of malicious gradients, respectively. In addition, these two components have the least impact on the magnitudes of gradients. Then, we propose MSGuard, a Multi-Strategy Byzantine-robust scheme based on cosine mechanisms, symbol statistics, and spectral methods. Formal analysis proves that malicious gradients generated by ScaleSign have a closer cosine similarity than honest gradients. Extensive experiments demonstrate that ScaleSign can attack most of the existing Byzantine-robust rules, especially achieving a success rate of up to 98.23% for attacks on SignGuard. MSGuard can defend against most existing attacks including ScaleSign. Specifically, in the face of ScaleSign attack, the accuracy of MSGuard improves by up to 41.78% compared to SignGuard. Li Yang 0005, Yinbin Miao, Zhiquan Liu 0001, Xinghua Li 0001, Da Kuang, Hongwei Li 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 8 |
| 2025 | Breaking the Trilemma: Toward Efficient, Privacy-Preserving, and Forward-Secure Data Sharing in the Post-Quantum EraabstractCloud-based data sharing has emerged as a prevailing solution for enterprises and end users, supporting various online services in our daily lives. However, the current cloud security solutions are vulnerable to the “harvest now, decrypt later” threat imposed by future quantum computers. To encounter the threat, lattice-based cryptographic solutions for supporting cloud data encryption and search have been extensively investigated by both academia and industry. Despite these efforts, existing lattice-based schemes fall into a trilemma: (1) lack of efficient access control for data retrieval; (2) inadequate protection of keyword privacy in both ciphertext and search token; and (3) difficulty in realizing forward secrecy to safeguard historical data. These limitations result in a substantial burden for lattice-based solutions to be adopted in real-world cloud data sharing. To our knowledge, no prior work has comprehensively addressed these issues at the same time, motivating us to design a more flexible, efficient, and secure lattice-based solution. In this paper, we propose an efficient, privacy-preserving, and forward-secure data sharing framework centered around a novel primitive called Forward-Secure Authenticated Searchable Encryption (FS-ASE). Specifically, we first construct an Authenticated Searchable Encryption (ASE) scheme based on ideal lattices, enabling efficient one-to-many search functionality and ensuring keyword privacy in both ciphertext and search token. On top of this primitive, we present the FS-ASE scheme, which achieves forward secrecy through a highly efficient key evolution mechanism, thereby keeping the confidentiality of historical data even if the current secret key is compromised. Finally, the security of our construction is proven under the Ring Learning With Errors (RLWE) assumption, and experimental results show that it achieves performance improvements of 158× in data retrieval and 350× in token generation over state-of-the-art approaches, indicating its practicality in real use. Jian Weng 0001, Pengfei Wu 0003, Shixin Chen, Jianfei Sun, Guomin Yang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2025 | Robust Federated Learning Client Selection With Combinatorial Class Representations and Data AugmentationabstractThe federated learning (FL) client selection scheme can effectively mitigate global model performance degradation caused by the random aggregation of clients with heterogeneous data. Simultaneously, research has exposed FL’s susceptibility to backdoor attacks. However herein lies the dilemma, traditional client selection methods and backdoor defenses stand at odds, so their integration is an elusive goal. To resolve this, we introduce Grace, a resilient client selection framework blending combinational class sampling with data augmentation. On the client side, Grace first proposes a local model purification method, fortifying the model’s defenses by bolstering its innate robustness. After, local class representations are extracted for server-side client selection. This approach not only shields benign models from backdoor tampering but also allows the server to glean insights into local class representations without infringing upon the client’s privacy. On the server side, Grace introduces a novel representation combination sampling method. Clients are selected based on the interplay of their class representations, a strategy that simultaneously weeds out malicious actors and draws in clients whose data holds unique value. Our extensive experiments highlight Grace’s capabilities. The results are compelling: Grace enhances defense performance by over 50% compared to state-of-the-art (SOTA) backdoor defenses, and, in the best case, improves accuracy by 3.19% compared to SOTA client selection schemes. Consequently, Grace achieves substantial advancements in both security and accuracy. Xinghua Li 0001, Mengfan Xu, Shunjie Yuan, Mengyao Zhu 0004, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | IvyCross: A Privacy-Preserving and Concurrency Control Framework for Blockchain InteroperabilityabstractInteroperability is a fundamental challenge for longenvisioned blockchain applications. A mainstream approach is using Trusted Execution Environment (TEE) to support interoperable off-chain execution. However, this incurs multiple TEE configured with non-trivial storage capabilities running on fragile concurrent processing environments, rendering current strategies based on TEE far from being practical. This paper aims to fill this gap and design a practical interoperability mechanism with simplified TEE as the underlying architecture. Specifically, we present IvyCross, a TEE-based framework that achieves lowcost, privacy-preserving, and race-free blockchain interoperability. IvyCross allows running arbitrary smart contracts across heterogeneous blockchains atop two distributed TEE-powered hosts. We design an incentive scheme based on smart contracts to stimulate the honest behavior of two hosts, bypassing the requirement of the number of TEE and large memory need. We examine the conditions to guarantee the uniqueness of Nash Equilibrium via Game Theory. Furthermore, an extended optimistic concurrency control protocol is designed to ensure the correctness of concurrent contracts execution. We formally prove the security of IvyCross in the Universal Composability (UC) framework and implement a prototype atop Bitcoin, Ethereum, and FISCO BOCS. Extensive experimental results on end-to-end performance and concurrency control demonstrate the efficiency and practicality of IvyCross. Ming Li 0049, Jian Weng 0001, Jia-Si Weng 0001, Yi Li 0008, Yongdong Wu, Dingcheng Li, Guowen Xu, Robert H. Deng |
IEEE Trans. Mob. Comput. | 8 |
| 2025 | Efficient and Secure Geometric Range Search Over Encrypted Spatial Data in Mobile CloudabstractWith the rapid development of mobile computing and the popularity of mobile devices equipped with GPS technology, massive spatial data have become available. Enterprises upload encrypted spatial data to the mobile cloud to save local storage and computation costs. However, the existing secure Geometric Range Search (GRS) solutions are inefficient in terms of building, updating index structure and querying processes. Moreover, the index structures of existing GRS schemes based on Order Preserving Encryption (OPE) leak location order, which may lead to reconstruction attacks. To solve these issues, we first propose an efficient and secure GRS scheme using Radix-Tree, namely GRSRT-I. Specifically, we construct an index structure based on Radix-tree to achieve efficient search and update, then use homomorphic encryption NTRU to resist chosen-plaintext attack, finally design a dual-server architecture to alleviate the burdens on mobile users caused by multiple rounds of interactions. Furthermore, we propose an enhanced scheme, GRSRT-II, by combining Order-Revealing Encryption and OPE, which greatly improves the search efficiency while slightly reducing the security. We formally prove the security of our proposed schemes, and conduct extensive experiments to demonstrate that GRSRT-I can improve the query efficiency by up to at least 1.5 times when compared with previous solutions and GRSRT-II can achieve a higher level of search efficiency. Yinbin Miao, Xinghua Li 0001, Hongwei Li 0001, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Mob. Comput. | 6 |
| 2025 | PLRQ: Practical and Less Leakage Range Query Over Encrypted Mobile Cloud DataabstractAs a fundamental service in mobile cloud computing, range query has attracted extensive attention. But the existing secure range query schemes not only leak data privacy but also have low query efficiency. To address those issues, we first design a novel range-matched code to convert the range query into code set matching, which aims to hide the order relationship of outsourced data as well as the index of most significant different bit. Based on the designed range-matched code, we propose aPractical andLess LeakageRangeQuery scheme over encrypted mobile cloud data (PLRQ) by integrating XOR filter and multiset hash function. Security analysis shows that PLRQ achieves semantic security and avoids data privacy leakage. Extensive experiments using real datasets demonstrate that, compared with two state-of-the-art solutions-RngMatch and LSRQ, our proposed PLRQ improves the query efficiency both by 2 orders of magnitude, and reduces the storage cost on Cloud Service Provider by about 79.5% and 73.6% respectively. Yunwei Wang, Xinghua Li 0001, Yinbin Miao, Qiuyun Tong, Ximeng Liu, Robert H. Deng |
IEEE Trans. Mob. Comput. | 6 |
| 2025 | Combating Noisy Labels by Alleviating the Memorization of DNNs to Noisy LabelsabstractData is the essential fuel for deep neural networks (DNNs), and its quality affects the practical performance of DNNs. In real-world training scenarios, the successful generalization performance of DNNs is severely challenged by noisy samples with incorrect labels. To combat noisy samples in image classification, numerous methods based on sample selection and semi-supervised learning (SSL) have been developed, where sample selection is used to provide the supervision signal for SSL, achieving great success in resisting noisy samples. Due to the necessary warm-up training on noisy datasets and the basic sample selection mechanism, DNNs are still confronted with the challenge of memorizing noisy samples. However, existing methods do not address the memorization of noisy samples by DNNs explicitly, which hinders the generalization performance of DNNs. To alleviate this issue, we present a new approach to combat noisy samples. First, we propose a memorized noise detection method to detect noisy samples that DNNs have already memorized during the training process. Next, we design a noise-excluded sample selection method and a noise-alleviated MixMatch to alleviate the memorization of DNNs to noisy samples. Finally, we integrate our approach with the established method DivideMix, proposing Modified-DivideMix. The experimental results on CIFAR-10, CIFAR-100, and Clothing1M demonstrate the effectiveness of our approach. Shunjie Yuan, Xinghua Li 0001, Yinbin Miao, Ximeng Liu, Robert H. Deng |
IEEE Trans. Multim. | 6 |
| 2025 | DefendFL: A Privacy-Preserving Federated Learning Scheme Against Poisoning AttacksabstractFederated learning (FL) has become a popular mode of learning, allowing model training without the need to share data. Unfortunately, it remains vulnerable to privacy leakage and poisoning attacks, which compromise user data security and degrade model quality. Therefore, numerous privacy-preserving frameworks have been proposed, among which mask-based framework has certain advantages in terms of efficiency and functionality. However, it is more susceptible to poisoning attacks from malicious users, and current works lack practical means to detect such attacks within this framework. To overcome this challenge, we present DefendFL, an efficient, privacy-preserving, and poisoning-detectable mask-based FL scheme. We first leverage collinearity mask to protect users' gradient privacy. Then, cosine similarity is utilized to detect masked gradients to identify poisonous gradients. Meanwhile, a verification mechanism is designed to detect the mask, ensuring the mask's validity in aggregation and preventing poisoning attacks by intentionally changing the mask. Finally, we resist poisoning attacks by removing malicious gradients or lowering their weights in aggregation. Through security analysis and experimental evaluation, DefendFL can effectively detect and mitigate poisoning attacks while outperforming existing privacy-preserving detection works in efficiency. Jiao Liu 0002, Xinghua Li 0001, Ximeng Liu, Yinbin Miao, Robert H. Deng |
IEEE Trans. Neural Networks Learn. Syst. | 6 |
| 2025 | Deep Reinforcement Learning Based Scheduling Strategy in Blockchain Payment Channel NetworksabstractWith the popularity of blockchains, low transaction throughput has become a significant bottleneck in applications such as cryptocurrencies. Payment channel networks (PCNs) have received attention as a way to improve throughput. However, due to the difficulty of predicting future transactions for nodes, the transactions are prone to failure when the channel balances do not meet required conditions. It has been shown that increasing buffers (queues) in PCNs can increase the success rate of transactions and throughput. Nevertheless, there is no effective transaction scheduling strategy in buffers when transaction values are flexible and variable. To solve this problem, we first formulate the Scheduling Problem in PCNs (named PSP), and then prove it is NP-hard. We design a neural network solver based on the Sequence to Sequence (Seq2Seq) architecture and train the solver using the reinforcement learning method. With the solver, we first give two scheduling strategies to maximize transaction throughput, and then design a PCN simulator for performance evaluation. Extensive experiments are conducted to show the superiority and various performances of our proposal and illustrate that our proposal can get a significant advantage in terms of the transaction throughput compared to the existing works. Zhe Ren, Xinghua Li 0001, Yinbin Miao, Zhuowen Li, Ximeng Liu, Robert H. Deng |
IEEE Trans. Netw. | 8 |
| 2025 | Calling Out Trustless Users: A Trust Propagation Scheme for Decentralized Trust ManagementabstractTrust management has been widely employed to determine a user's trustworthiness based on evaluations from other entities, and trustless users are those with low trustworthiness due to dishonest or malicious behaviors. To overcome the defects of traditional centralized trust management, decentralized trust management has been proposed, leveraging blockchain to store trust data, e.g., user interaction evaluations, securely. However, blockchain-based decentralized trust management usually suffers from throughput limitation, hindering timely record users' trust data, delaying expose trustless users. As a result, trustless users may still interact with others in the system with the outdated trustworthiness, undermining the reliability and fairness of the system. Furthermore, decentralized pseudonymous networks suffer from a trust cold-start problem due to lacking users' prior interaction history or endorsements from trusted third parties, making it hard for newly joined users to assess the trustworthiness. To address these issues, we propose TUES in this paper, an efficient Trustless User Exposure Scheme. TUES stores trust data in a trust blockchain collectively maintained by all users. To efficiently expose trustless users, we design a dynamic consensus mechanism for TUES. This dynamic consensus mechanism integrates three novel consensus algorithms, efficiently utilizing network throughput to record trust data of trustless users and ensure the consistency of the blockchain. Additionally, TUES includes a multi-signature-based scheme to allocate initial trust values to users, thus resolving the trust cold-start problem in decentralized pseudonymous networks. Analysis and experiments show that TUES improves the efficiency of exposing trustless users while maintaining the consistency of the trust blockchain. It also increases the cost for adversaries conducting Sybil, whitewashing and Byzantine attacks. Yong Yu 0002, Haochen Yang 0001, Yannan Li 0001, Robert H. Deng |
IEEE Trans. Serv. Comput. | 4 |
| 2024 | Toward Practical Client-Side Encryption in Cloud ComputingabstractData breaches in the cloud are on the rise and are becoming more costly to organizations each year. Client-side encryption refers to the practice of encrypting data on end users' devices before uploading it to the cloud. This approach ensures that data is encrypted during transit and storage, making data inaccessible to anyone without the decryption keys, including service providers and other potential attackers. In this talk, we will first look at the challenges of client-side encryption and provide an overview of the key advancements as well as setbacks in addressing these challenges in the past two decades, including scalable access of encrypted data and search over encrypted data. There are numerous academic publications in this area and the choice of which techniques to use could have significant impact on the system's security, efficiency, and usability. Finally, we will present our design and implementation of a client-side encryption system for enterprise users. Robert H. Deng |
AsiaCCS | 1 |
| 2024 | PIC-BI: Practical and Intelligent Combinatorial Batch Identification for UAV assisted IoT NetworksabstractUnmanned Aerial Vehicle (UAV)-assisted IoT networks are receiving a lot of attention in academia and industry. For instance, a UAV can fly and hover over sensors, during which time the sensors simultaneously initiate batch access requests to the UAV. Typically, UAV employs batch authentication to efficiently handle these batch accesses. However, an attacker can initiate illegal requests, causing batch authentication to fail. There are various batch identification algorithms to find illegal requests, enabling legitimate sensors to establish service connections quickly. Existing work wants to choose a suitable one based on the specific attack scenario. However, existing work assumes that the percentage r% of illegal requests is known in advance, which is impractical in real-world scenarios. Besides, existing work only selects a suitable batch identification algorithm based on r%, limiting the performance of batch identification to the capabilities of the alternative algorithms. Drawing inspiration from the Kalman filter, we first propose an adaptive estimation algorithm for the number of illegal requests to address the above problems. Based on the estimated value e%, we design a combinatorial batch identification using reinforcement learning. This approach allows the combination of different algorithms to achieve superior performance. Extensive experiments demonstrate that, for the estimation algorithm, the relative error is less than 20% in 27 out of 40 experiments. Regarding the combinatorial algorithms, the delay can be reduced by approximately 7.15% to 30.86% compared to existing methods. Zhe Ren, Xinghua Li 0001, Yinbin Miao, Mengyao Zhu 0004, Shunjie Yuan, Robert H. Deng |
CCS | 6 |
| 2024 | Direct Range Proofs for Paillier Cryptosystem and Their ApplicationsabstractThe Paillier cryptosystem is renowned for its applications in electronic voting, threshold ECDSA, multi-party computation, and more, largely due to its additive homomorphism. In these applications, range proofs for the Paillier cryptosystem are crucial for maintaining security, because of the mismatch between the message space in the Paillier system and the operation space in application scenarios. Zhikang Xie, Mengling Liu, Haiyang Xue, Man Ho Au, Robert H. Deng, Siu-Ming Yiu |
CCS | 5 |
| 2024 | PriSrv: Privacy-Enhanced and Highly Usable Service Discovery in Wireless Communications
Yang Yang 0026, Robert H. Deng, Guomin Yang, Yingjiu Li, HweeHwa Pang, Minming Huang, Jian Weng 0001 |
NDSS | 2 |
| 2024 | Make Revocation Cheaper: Hardware-Based Revocable Attribute-Based EncryptionabstractAs an advanced one-to-many public key encryption system, attribute-based encryption (ABE) is widely believed to be a promising technology for achieving flexible and fine-grained access control of encrypted data on untrusted storage servers (e.g., public cloud servers). However, user revocation in ABE is a critical but challenging problem, and designing efficient revocable ABE has been an active research topic in the past decade. Almost all the existing revocable ABE schemes incorporate a timestamp in the encryption algorithm such that revoked users cannot decrypt ciphertexts generated in future time intervals. To prevent revoked users from decrypting past ciphertexts, the storage server needs to perform a process called ciphertext delegation (Sahai et al., CRYPTO’12) that periodically updates the timestamp for all ciphertexts. As the number of ciphertexts could be huge in a storage system, ciphertext delegation could pose a huge computation overhead to the server.Motivated by the popularity of commodity Trusted Execution Environment (TEE) technologies, this paper initiates the study on hardware-based revocable ABE (HR-ABE) to eliminate the (unscalable) ciphertext delegation and prevent collusion attacks between an untrusted storage server and revoked users. We formalize this new notion and present an efficient HR-ABE construction that also supports outsourced decryption for resource-constrained data users. Furthermore, HR-ABE is also designed to address the potential secret leakage problem suffered by TEE (e.g., due to side-channel attacks) so that the leakage of secrets possessed by TEE does not lead to leakage of user data. We prove HR-ABE’s security formally and benchmark its performance experimentally. Xiaoguo Li, Guomin Yang, Tao Xiang 0001, Shengmin Xu, Bowen Zhao 0001, HweeHwa Pang, Robert H. Deng |
SP | 7 |
| 2024 | Towards Privacy-aware IoT Communications: Delegable, Revocable, and EfficientabstractThe Internet of Things (IoT) is widely recognized for its potential to enhance efficiency and productivity across various industries. However, its increasing prevalence has also made it a more attractive target for cybercriminals. While many advanced cryptographic solutions have been developed to secure IoT, some practical security and privacy issues such as self-sovereign delegation, flexible revocation, and lightweight access remain inadequately addressed in existing solutions. In this paper, we propose PLIC, a Privacy-aware Lightweight IoT Communication scheme, which not only enables any authorized user to flexibly delegate their lightweight access privileges to other delegatees, such that they can also access the authorized IoT targets in the same lightweight way, but also supports flexible revocation of access for specific users without affecting non-revoked users. Specifically, our solution leverages wildcard-based access control and tree-based encryption technologies to enable self-sovereign delegation, dynamic membership updates, and stably efficient decryption overhead in IoT. In addition, comprehensive security proofs are rendered to validate the robustness of our approach. Finally, experimental comparisons with similar methodologies demonstrate the practicality and superior performance of our solution, which indicates its effectiveness for practical IoT appli-cations. Pengfei Wu 0003, Jianfei Sun, Guomin Yang, Robert H. Deng |
TrustCom | 4 |
| 2024 | Policy-Based Remote User Authentication From Multi-BiometricsabstractAbstract In this paper, we introduce the first generic framework of policy-based remote user authentication from multiple biometrics. The proposed framework allows an authorized user to remotely authenticate herself to an authentication server using her multiple biometrics, which enhances both the security and usability of user authentications. The authentication server approves a user’s authentication request if and only if the user’s multiple biometrics satisfies an authentication policy. In particular, the authentication policy can be dynamically updated to satisfy different security and usability requirements in practice. We implement an instantiation of the proposed framework and report its performance under various authentication policies. Yangguang Tian, Yingjiu Li, Robert H. Deng, Guomin Yang, Nan Li 0007 |
Comput. J. | 3 |
| 2024 | Practical Revocable Keyword Search Over Mobile Cloud-Assisted Internet of ThingsabstractSearchable encryption (SE) can potentially be used to guarantee both data confidentiality and searchability over mobile cloud-assisted Internet of things. However, existing SE solutions mainly focus on user revocation rather than keyword revocation. The keyword revocation may be required in certain situations. For example, patients do not allow their doctors to access records on some diseases such as syphilis. Hence, we propose a basic Revocable Keyword Search (RKS) scheme over encrypted electronic medical records in the group setting, which supports keyword revocation (by using a revocation list) and authorized access permissions (via a group key exchange protocol). Then, we design an enhanced RKS (called RKS+) to significantly reduce the size of revoked keyword ciphertexts and the costs of token generation and ciphertext retrieval. Our schemes also support efficient user revocation by updating only one index component, and guarantee forward security. The formal security analysis proves that our schemes are secure against both chosen-keyword attacks and chosen-plaintext attacks, and findings from the empirical evaluations demonstrate that our schemes are efficient and practical. Shuqin Liu, Yinbin Miao, Feng Li 0041, Xinghua Li 0001, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Internet Things J. | 6 |
| 2024 | OpenSE: Efficient Verifiable Searchable Encryption With Access and Search Pattern Hidden for Cloud-IoTabstractThe Internet of Things (IoT) has greatly changed our lives and generated a large amount of data. Cloud storage helps IoT limited-resource IOT devices process the massive data. However, cloud servers are untrusted in most scenarios as they may illegally obtain sensitive data. Although existing symmetric searchable encryption (SSE) schemes can protect the privacy of outsourced data while preserve data availability, Most of them leak access and search patterns to the cloud server to gain better performance. Such leakages will be used to recover private information. Meanwhile, semi-honestly secure searchable encryption cannot prevent attacks done by the malicious server such as returning the false search result. Therefore, it is still a challenge to prevent malicious cloud server misbehavior, and preserve patterns, simultaneously. This paper proposes OpenSE to solve the aforementioned problems. First, this paper constructs FastOPE as a major building block. With the OPE protocol, the verifiable searchable encryption OpenSE can be trivially realized. After that, security proofs show that OpenSE is secure against malicious cloud servers with access and search pattern hidden. Finally, we implement experiments on real datasets to compare OpenSE with some state-of-the-art works in terms of running time of setup phase and search phase as well as storage overhead. The experimental results show that OpenSE outperforms the state-of-the-art works in terms of setup phase and storage overhead. In addition, the theoretic comparison shows that OpenSE outperforms most existing works in terms of security, in which OpenSE enjoys both verifiability and pattern hidden. Yunbo Yang, Xiaolei Dong, Zhenfu Cao, Guomin Yang, Robert H. Deng |
IEEE Internet Things J. | 7 |
| 2024 | AnoPas: Practical anonymous transit pass from group signatures with time-bound keys
Yang Yang 0026, Yingjiu Li, Huamin Feng, HweeHwa Pang, Robert H. Deng |
J. Syst. Archit. | 6 |
| 2024 | A Secure and Robust Knowledge Transfer Framework via Stratified-Causality Distribution Adjustment in Intelligent Collaborative ServicesabstractThe rapid development of device-edge-cloud collaborative computing techniques has actively contributed to the popularization and application of intelligent service models. The intensity of knowledge transfer plays a vital role in enhancing the performance of intelligent services. However, the existing knowledge transfer methods are mainly implemented through data fine-tuning and model distillation, which may cause the leakage of data privacy or model copyright in intelligent collaborative systems. To address this issue, we propose a secure and robust knowledge transfer framework through stratified-causality distribution adjustment (SCDA) for device-edge-cloud collaborative services. Specifically, a simple yet effective density-based estimation is first employed to obtain uncertainty scores that guide the space stratification, which is conducive to reconstructing low-density distribution regions from high-density distribution regions more adaptively and accurately. Subsequently, we devise a novel causality-aware generative model to generate synthetic features for the out-of-distribution domain by exploring the relationship between factors and variables. Ultimately, we introduce a cycle-consistent minimax optimization mechanism to ensure the effectiveness and dependability of knowledge transfer through the influence minimization and the diversity maximization. Furthermore, extensive experiments demonstrate that our scheme can protect the security of data privacy and model copyright in intelligent collaborative services through adaptive distribution adjustment. Ju Jia, Siqi Ma 0001, Lina Wang 0001, Yang Liu 0003, Robert H. Deng |
IEEE Trans. Computers | 5 |
| 2024 | REKS: Role-Based Encrypted Keyword Search With Enhanced Access Control for Outsourced Cloud DataabstractKeyword-based search over encrypted data is an important technique to achieve both data confidentiality and utilization in cloud outsourcing services. While commonly used access control mechanisms, such as identity-based encryption and attribute-based encryption, do not generally scale well for hierarchical access permissions. To solve this problem, we propose a Role-based Encrypted Keyword Search (REKS) scheme by using the role-based access control and broadcast encryption. Specifically, REKS allows owners to deploy hierarchical access control by allowing users with parent roles to have access permissions from child roles. Using REKS, we further facilitate token generation preprocessing and efficient user management, thereby significantly reducing the users' final token generation and index update overheads, respectively. Formal security analysis proves that REKS is secure against chosen keyword and internal keyword guessing attacks, and findings from the empirical evaluations demonstrate that REKS is efficient and practical. Yinbin Miao, Feng Li 0041, Xiaohua Jia, Huaxiong Wang, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2024 | Robust Asynchronous Federated Learning With Time-Weighted and Stale Model AggregationabstractFederated Learning (FL) ensures collaborative learning among multiple clients while maintaining data locally. However, the traditional synchronous FL solutions have lower accuracy and require more communication time in scenarios where most devices drop out during learning. Therefore, we propose anAsynchronousFederatedLearning (AsyFL) scheme using time-weighted and stale model aggregation, which effectively solves the problem of poor model performance due to the heterogeneity of devices. Then, we integrate Symmetric Homomorphic Encryption (SHE) into AsyFL to proposeAsynchronousPrivacy-PreservingFederatedLearning (Asy-PPFL), which protects the privacy of clients and achieves lightweight computing. Privacy analysis shows that Asy-PPFL is indistinguishable under Known Plaintext Attack (KPA) and convergence analysis proves the effectiveness of our schemes. A large number of experiments show that AsyFL and Asy-PPFL can achieve the highest accuracy of 58.40% and 58.26% on Cifar-10 dataset when most clients (i.e., 80%) are offline or delayed, respectively. Yinbin Miao, Xinghua Li 0001, Meng Li 0006, Hongwei Li 0001, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2024 | Verifiable Outsourced Attribute-Based Encryption Scheme for Cloud-Assisted Mobile E-Health SystemabstractThe cloud-assisted mobile electronic health (e-health) system facilitates e-health data sharing between healthcare providers and patients, but also raises the security and privacy concerns of e-health data. Although Ciphertext-Policy Attribute-Based Encryption (CP-ABE) has been a promising technique to achieve fine-grained access control over encrypted e-health data, it still incurs high encryption and decryption burdens on mobile users such as smartphones and sensors. In addition, malicious cloud servers may conduct incorrect operations due to various interest incentives (e.g., leaking sensitive information to illegal users, saving computation and storage costs). To solve the above issues, in this paper we first propose an Outsourced CP-ABE (OABE) with verifiable encryption scheme by splitting secret keys corresponding to an attribute set and using the short signature, which not only reduces the encryption and decryption complexities of mobile users but also guarantees that cloud servers correctly perform encryption operations. Then, we extend OABE to construct outsourced CP-ABE with verifiable decryption (OABE+) by utilizing the verifiable tag mechanism, which guarantees that cloud servers correctly conduct the ciphertext transformation. Formal security analysis proves that our schemes are selectively secure against unauthorized accesses and malicious operations. Extensive experiments using various real-world datasets demonstrate that our schemes are efficient and feasible in real applications. Yinbin Miao, Feng Li 0041, Xinghua Li 0001, Jianting Ning, Hongwei Li 0001, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2024 | Efficient and Secure Federated Learning Against Backdoor AttacksabstractDue to the powerful representation ability and superior performance of Deep Neural Networks (DNN), Federated Learning (FL) based on DNN has attracted much attention from both academic and industrial fields. However, its transmitted plaintext data causes privacy disclosure. FL based on Local Differential Privacy (LDP) solutions can provide privacy protection to a certain extent, but these solutions still cannot achieve adaptive perturbation in DNN model. In addition, this kind of schemes cause high communication overheads due to the curse of dimensionality of DNN, and are naturally vulnerable to backdoor attacks due to the inherent distributed characteristic. To solve these issues, we propose anEfficient andSecureFederatedLearning scheme (ESFL) against backdoor attacks by using adaptive LDP and compressive sensing. Formal security analysis proves that ESFL satisfies$\epsilon$-LDP security. Extensive experiments using three datasets demonstrate that ESFL can solve the problems of traditional LDP-based FL schemes without a loss of model accuracy and efficiently resist the backdoor attacks. Yinbin Miao, Rongpeng Xie, Xinghua Li 0001, Zhiquan Liu 0001, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2024 | Double Issuer-Hiding Attribute-Based Credentials From Tag-Based Aggregatable Mercurial SignaturesabstractAttribute-based anonymous credentials offer users fine-grained access control in a privacy-preserving manner. However, in such schemes obtaining a user's credentials requires knowledge of the issuer's public key, which obviously reveals the issuer's identity that must be hidden from users in certain scenarios. Moreover, verifying a user's credentials also requires the knowledge of issuer's public key, which may infer the user's private information from their choice of issuer. In this paper, we introduce the notion of double issuer-hiding attribute-based credentials (${\sf DIHAC}$) to tackle these two problems. In our model, a central authority can issue public-key credentials for a group of issuers, and users can obtain attribute-based credentials from one of the issuers without knowing which one it is. Then, a user can prove that their credential was issued by one of the authenticated issuers without revealing which one to a verifier. We provide a generic construction, as well as a concrete instantiation for${\sf DIHAC}$based on structure-preserving signatures on equivalence classes (JOC's 19) and a novel primitive which we calltag-based aggregatable mercurial signatures. Our construction is efficient without relying on zero-knowledge proofs. We provide rigorous evaluations on personal laptop and smartphone platforms, respectively, to demonstrate its practicability. Yang Yang 0026, Yingjiu Li, Huamin Feng, Guozhen Shi, HweeHwa Pang, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2024 | SIMC 2.0: Improved Secure ML Inference Against Malicious ClientsabstractIn this paper, we study the problem of secure ML inference against a malicious client and a semi-trusted server such that the client only learns the inference output while the server learns nothing. This problem is first formulated by Lehmkuhlet al.with a solution (MUSE, Usenix Security'21), whose performance is then substantially improved by Chandranet al.'s work (SIMC, USENIX Security'22). However, there still exists a nontrivial gap in these efforts towards practicality, giving the challenges of overhead reduction and secure inference acceleration in an all-round way. Based on this, we propose SIMC 2.0, which complies with the underlying structure of SIMC, but significantly optimizes both the linear and non-linear layers of the model. Specifically, (1) we design a new coding method for parallel homomorphic computation between matrices and vectors. (2) We reduce the size of the garbled circuit (GC) (used to calculate non-linear activation functions,e.g., ReLU) in SIMC by about two thirds. Compared with SIMC, our experiments show that SIMC 2.0 achieves a significant speedup by up to$17.4\times$for linear layer computation, and at least$1.3\times$reduction of both the computation and communication overhead in the implementation of non-linear layers under different data dimensions. Meanwhile, SIMC 2.0 demonstrates an encouraging runtime boost by$2.3\sim 4.3\times$over SIMC on different state-of-the-art ML models. Guowen Xu, Xingshuo Han, Tianwei Zhang 0004, Shengmin Xu, Jianting Ning, Xinyi Huang 0001, Hongwei Li 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 8 |
| 2024 | AnoPay: Anonymous Payment for Vehicle Parking With Updatable CredentialabstractMany existing anonymous parking payment schemes lack high efficiency and flexibility. For instance, the calculation and communication costs involved in payment may linearly increase with the payment amount. In this paper, we propose an anonymous payment system (dubbed AnoPay) for vehicle parking, which leverages updatable attribute-based anonymous credentials and efficient zero-knowledge proof (ZKP) to achieve user anonymity and constant overhead for parking fee payment. To further improve the efficiency, we design a secure parking fee aggregation protocol based on linear homomorphic encryption to aggregate parking transactions, where the amount of each parking transaction is hidden and the privacy of the parking lot in terms of its revenue is guaranteed. AnoPay achieves both unlinkability and accountability, malicious payments can be efficiently traced when it is necessary. We provide a security model and rigorous proof for each security property of AnoPay. Extensive experiments and comparisons demonstrate the efficiency and practicality of the system. Yang Yang 0026, Wenyi Xue, Yonghua Zhan, Minming Huang, Yingjiu Li, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2024 | Privacy-Preserved Data Trading Via Verifiable Data DisturbanceabstractTo motivate data owner (DO) to trade data, the existing data trading allows DO to sell the disturbed data to the data consumer (DC), where the disturbance parameter and the data price are negotiated by them, and DO independently adds the disturbance noise to data (usually continuous type) following the negotiation result. However, DOs may violate the negotiated parameter and add more noise to data while obtaining the negotiated price, which damages DC's disturbed data availability. This deficiency is rooted in the absence of supervision and verifiability on DOs' independent disturbances. Aiming at the above problem, we devise a privacy-preserved data trading via verifiable data disturbance. Specifically, the honest-but-curious disturbance server (DS) is introduced to generate encrypted verifiable disturbance noises, and secretly distribute noises to DOs referring to the method of private information retrieval. Using homomorphic encryption, DOs finish data disturbance without knowing noises' specific sizes. Subsequently, DC selects DOs to verify with our proposed anti-forgery verification, where the anti-forgery on both disturbance noise and original data guarantees verification correctness. Theoretical analysis proves that DOs' original data is preserved in data trading. Extensive experiments using the real-world dataset demonstrate that our scheme can detect more than 80% of malicious DOs and decrease their utilities to punish malicious disturbance compared with existing works. Man Zhang 0010, Xinghua Li 0001, Yanbing Ren, Bin Luo 0006, Yinbin Miao, Ximeng Liu, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2024 | EvilScreen Attack: Smart TV Hijacking via Multi-Channel Remote Control MimicryabstractModern smart TVs often communicate with their remote controls (including the smartphone simulated ones) using multiple wireless channels (e.g., Infrared, Bluetooth, and Wi-Fi). However, this multi-channel remote control communication introduces a new attack surface. An inherent security flaw is that remote controls of most smart TVs are designed to work in a benign environment rather than an adversarial one, and thus wireless communications between a smart TV and its remote controls are not strongly protected. Attackers can leverage such a flaw to abuse the remote control communication and compromise smart TV systems. In this paper, we propose EVILSCREEN, a novel attack that exploits ill-protected remote control communications to access protected resources of a smart TV or even control the screen. EVILSCREEN exploits a multi-channel remote control mimicry vulnerability present in today smart TVs. Unlike other attacks, which compromise the TV system by exploiting code vulnerabilities or malicious third-party apps, EVILSCREEN directly reuses commands of different remote controls, combines them together to circumvent deployed authentication and isolation policies, and finally accesses or controls TV resources remotely. We evaluated eight mainstream smart TVs and found that they are all vulnerable to EVILSCREEN attacks, including a Samsung product adopting the ISO/IEC security specification. Yiwei Zhang 0008, Siqi Ma 0001, Tiancheng Chen, Juanru Li, Robert H. Deng, Elisa Bertino |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Lightweight Privacy-Preserving Cross-Cluster Federated Learning With Heterogeneous DataabstractFederated Learning (FL) eliminates data silos that hinder digital transformation while training a shared global model collaboratively. However, training a global model in the context of FL has been highly susceptible to heterogeneity and privacy concerns due to discrepancies in data distribution, which may lead to potential data leakage from uploading model updates. Despite intensive research on above-identical issues, existing approaches fail to balance robustness and privacy in FL. Furthermore, limiting model updates or iterative clustering tends to fall into local optimum problems in heterogeneous (Non-IID) scenarios. In this work, to address these deficiencies, we provide lightweight privacy-preserving cross-cluster federated learning (PrivCrFL) on Non-IID data, to trade off robustness and privacy in Non-IID settings. Our PrivCrFL exploits secure one-shot hierarchical clustering with cross-cluster shifting for optimizing sub-group convergences. Furthermore, we introduce intra-cluster learning and inter-cluster learning with separate aggregation for mutual learning between each group. We perform extensive experimental evaluations on three benchmark datasets and compare our results with state-of-the-art studies. The findings indicate that PrivCrFL offers a notable performance enhancement, with improvements ranging from$0.26\%~\uparrow $to$1.35\%~\uparrow $across different Non-IID settings. PrivCrFL also demonstrates a superior communication compression ratio in secure aggregation, outperforming current state-of-the-art works by 10.59%. Zekai Chen 0010, Shengxing Yu, Farong Chen, Fuyi Wang, Ximeng Liu, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | Privacy-Enhancing and Robust Backdoor Defense for Federated Learning on Heterogeneous DataabstractFederated learning (FL) allows multiple clients to train deep learning models collaboratively while protecting sensitive local datasets. However, FL has been highly susceptible to security for federated backdoor attacks (FBA) through injecting triggers and privacy for potential data leakage from uploaded models in practical application scenarios. FBA defense strategies consider specific and limited attacker models, and a sufficient amount of noise injected can only mitigate rather than eliminate the attack. To address these deficiencies, we introduce a Robust Federated Backdoor Defense Scheme (RFBDS) and Privacy-preserving RFBDS (PrivRFBDS) to ensure the elimination of adversarial backdoors. Our RFBDS to overcome FBA consists of amplified magnitude sparsification, adaptive OPTICS clustering, and adaptive clipping. The experimental evaluation of RFBDS is conducted on three benchmark datasets and an extensive comparison is made with state-of-the-art studies. The results demonstrate the promising defense performance from RFBDS, moderately improved by 31.75% ~ 73.75% in clustering defense methods, and 0.03% ~ 56.90% for Non-IID to the utmost extent for the average FBA success rate over MNIST, FMNIST, and CIFAR10. Besides, our privacy-preserving shuffling in PrivRFBDS maintains is$7.83e^{-5}\,\,\sim \,\,0.42\times $that of state-of-the-art works. Zekai Chen 0010, Shengxing Yu, Mingyuan Fan 0003, Ximeng Liu, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | FDFL: Fair and Discrepancy-Aware Incentive Mechanism for Federated LearningabstractFederated Learning (FL) is an emerging distributed machine learning paradigm crucial for ensuring privacy-preserving learning. In FL, a fair incentive mechanism is indispensable for inspiring more clients to participate in FL training. Nevertheless, achieving a fair incentive mechanism in FL is an arduous endeavor, underscored by two significant challenges that persistently elude resolution within existing methodologies. Firstly, existing works overlook the issue of category distribution heterogeneity in contribution evaluation, leading to incomplete contribution evaluations. Secondly, the fact that malicious servers will dishonestly allocate rewards to save costs is not considered in existing work, which can be a barrier to client participation in FL. This paper introduces FDFL (Fair andDiscrepancy-aware incentive mechanism forFederatedLearning), a novel system addressing these concerns. FDFL encompasses two key elements: 1) Discrepancy-aware contribution evaluation approach; 2) Provable reward allocation approach. Extensive experiments on four model-dataset combinations demonstrate that, under the heterogeneous setting, our scheme improves accuracy by an average of 9.85% and 11.97% compared to FedAvg and FAIR, respectively. Xinghua Li 0001, Yinbin Miao, Man Zhang 0010, Siqi Ma 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 8 |
| 2024 | A Pruned Pendant Vertex Based Index for Shortest Distance Query Under Structured Encrypted GraphabstractThe shortest distance query is used to determine the shortest distance between two vertices. Various graph encryption schemes have been proposed to achieve accurate, efficient and secure shortest distance queries for encrypted graphs. However, the majority of these schemes are inefficient or lack scalability due to the time-consuming index construction and large index storage. Moreover, none of them consider the trade-off between query efficiency and accuracy. To better trade off the query efficiency and accuracy, we propose a Pruned Pendant Vertex based Index for Shortest Distance Query ($\mathsf { PPVI}$-$\mathsf { SDQ}$) under structured encryption. The proposed scheme utilizes the structured encryption technique to encrypt a graph and build indexes. The main idea is to use the recursive method to repeatedly prune the pendant vertex, and thereby reducing the index size and construction time by minimizing the redundant data storage and graph traversal. The proposed scheme achieves accurate, efficient and secure shortest distance query with privacy-preserving for encrypted graph. The security analysis demonstrates that the proposed scheme satisfies CQA2-security. Experimental results with real datasets show that the scheme achieves the optimal accuracy and efficiency. Mengdi Hu, Lanxiang Chen, Gaolin Chen, Yi Mu 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | A Causality-Aligned Structure Rationalization Scheme Against Adversarial Biased Perturbations for Graph Neural NetworksabstractThe graph neural networks (GNNs) are susceptible to adversarial perturbations and distribution biases, which pose potential security concerns for real-world applications. Current endeavors mainly focus on graph matching, while the subtle relationships between the nodes and structures of graph-structured data remain under-explored. Accordingly, two fundamental challenges arise as follows: 1) the intricate connections among nodes may induce the distribution shift of graph samples even under the same scenario, and 2) the perturbations of inherent graph-structured representations can introduce spurious shortcuts, which lead to GNN models relying on biased data to make unstable predictions. To address these problems, we propose a novel causality-aligned structure rationalization (CASR) scheme to construct invariant rationales by probing the coherent and causal patterns, which facilitates GNN models to make stable and reliable predictions in case of adversarial biased perturbations. Specifically, the initial graph samples across domains are leveraged to boost the diversity of datasets and perceive the interaction between shortcuts. Subsequently, the causal invariant rationales can be obtained during the interventions. This allows the GNN model to extrapolate risk variations from a single observed environment to multiple unknown environments. Moreover, the query feedback mechanism can progressively promote the consistency-driven optimal rationalization by reinforcing real essences and eliminating spurious shortcuts. Extensive experiments demonstrate the effectiveness of our scheme against adversarial biased perturbations from data manipulation attacks and out-of-distribution (OOD) shifts on various graph-structured datasets. Notably, we reveal that the capture of distinctive rationales can greatly reduce the dependence on shortcut cues and improve the robustness of OOD generalization. Ju Jia, Siqi Ma 0001, Yang Liu 0003, Lina Wang 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | SDSS: Sequential Data Sharing System in IoTabstractE-healthcare as a significant facet of the Internet of Things (IoT) relies on wearable devices to continuously monitor users’ vital signals for health-related purposes. The sensitive and vast nature of the collected data necessitate secure encryption and storage on the cloud. Simultaneously, there is a need to share these data for healthcare purposes. How to balance the privacy and usability of these data is a challenging problem in the e-healthcare applications. A central problem arose from the continuous data collection is how to effectively share the data collected in one specific time period when users are unwell. We formalize it as the sequential data sharing problem. This problem appears in various IoT applications apart from e-healthcare, such as video surveillance. In this paper, we explain why all existing solutions cannot address the above problem. Then, we propose a novel sequential data sharing system (SDSS), where the data encrypted at any specific time period can be efficiently shared. We first present a practical construction of SDSS that supports securely sharing data within one specific time period in a symmetric manner. The decryption key are retrieved sequentially by utilizing the shared key and hash function. All involved calculations in the system are lightweight. Data pertaining to other non-selected time periods remain unknown. We then extend the SDSS to a multiple-range version, enabling simultaneous sharing data for multiple specific time periods, and show an example. We formalize the definition of security models and analyze the security of our systems. Finally, we evaluate the performance of our systems using SHA-256 and AES-256. Experimental results demonstrate that our systems are highly efficient. It takes less than 1 millisecond to encrypt 100KB data and less than 0.4 milliseconds to decrypt the corresponding cipher data. Our proposed systems provide a solution to balance the privacy and usability in the context of sequentially collected data. We believe that this work will enhance the adoption and practicality of IoT applications. Jianchang Lai, Willy Susilo, Robert H. Deng, Fuchun Guo |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | STDA: Secure Time Series Data Analytics With Practical Efficiency in Wide-Area NetworkabstractTime series data analytics technology significantly benefits modern scientific research, especially in fields such as medical health, financial investment, and transportation. Unfortunately, privacy issues hinder people from handing over the data to a third party for various analytical tasks; because the data may reveal much more individual sensitive information, e.g., disease information from medical data, investment tendency from financial data, or the daily trajectory from transportation data. To break down this barrier, secure computation approaches have shown their importance in processing sensitive data, and have attracted much attention from the industry and research communities. However, when considering the case of secure time-series data analytics (e.g., DTW similarity), we are still far from achieving high efficiency due to high round complexity in communication or expensive computational complexity. We observe that DTW involves a lot of comparison operations and existing approaches in dealing with the comparison require higher communication costs. To this end, this paper studies secure DTW-based analytics with practical efficiency over time series data. Specifically, we propose the framework of secure time series data analytics (STDA) and formulate the problem of top-$k$query for outsourced time series data. Based on threshold Paillier encryption, we present a top-$k$query protocol utilizing the DTW distance as a metric and its security analysis, optimizations, and performance evaluation. The experimental results demonstrate that in a wide-area network with a 10 ms latency, our top-$k$approach outperforms the state-of-the-art by 3x times, while DTW calculation outperforms by 9x times. Correspondingly, the optimized$\mathcal {F}_{\text {DTW}}$achieves 17x times better, and optimized top-$k$achieves 4-10x times better. Xiaoguo Li, Zixi Huang, Bowen Zhao 0001, Guomin Yang, Tao Xiang 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | Efficient and Privacy-Preserving Encode-Based Range Query Over Encrypted Cloud DataabstractPrivacy-preserving range query, which allows the server to implement secure and efficient range query on encrypted data, has been widely studied in recent years. Existing privacy-preserving range query schemes can realize effective range query, but usually suffer from the low efficiency and security. In order to solve the above issues, we propose an Efficient and Privacy-preserving encode-based Range Query over encrypted cloud data (namely basic EPRQ), which encodes the data and range by using Range Encode (REncoder), and then encrypts the codes via Additional Symmetric-Key Hidden Vector Encryption (ASHVE) technology. The basic EPRQ can achieve effective range query while ensuring privacy protection. Then, we split the codes to reduce the storage cost. We further propose an improved scheme, EPRQ+, which constructs a binary tree-based index to achieve faster-than-linear retrieval. Finally, our formal security analysis proves that our schemes are secure against Indistinguishability under Chosen-Plaintext Attack (IND-CPA), and extensive experiments demonstrate that our schemes are feasible in practice, where EPRQ+ scheme improves the storage efficiency by about 4 times and the query efficiency by about 8 times compared to the basic EPRQ. Yanrong Liang, Jianfeng Ma 0001, Yinbin Miao, Yuan Su, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Privacy-Preserving Asynchronous Federated Learning Under Non-IID SettingsabstractTo address the challenges posed by data silos and heterogeneity in distributed machine learning, privacy-preserving asynchronous Federated Learning (FL) has been extensively explored in academic and industrial fields. However, existing privacy-preserving asynchronous FL schemes still suffer from the problem of low model accuracy caused by inconsistency between delayed model updates and current model updates, and even cannot adapt well to Non-Independent and Identically Distributed (Non-IID) settings. To address these issues, we propose a Privacy-preserving Asynchronous Federated Learning based on the alternating direction multiplier method (PAFed), which is able to achieve high-accuracy models in Non-IID settings. Specifically, we utilize vector projection techniques to correct the inconsistency between delayed model updates and current model updates, thereby reducing the impact of delayed model updates on the aggregation of current model updates. Additionally, we employ an optimization method based on alternating direction multipliers to adapt the Non-IID settings to further enhance the global model accuracy. Finally, through extensive experiments, we demonstrate that our scheme improves the model accuracy by up to 12.53% when compared with current state-of-the-art solution FedADMM. Yinbin Miao, Da Kuang, Xinghua Li 0001, Shujiang Xu, Hongwei Li 0001, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2024 | RFed: Robustness-Enhanced Privacy-Preserving Federated Learning Against Poisoning AttackabstractFederated learning not only realizes collaborative training of models, but also effectively maintains user privacy. However, with the widespread application of privacy-preserving federated learning, poisoning attacks threaten the model utility. Existing defense schemes suffer from a series of problems, including low accuracy, low robustness and reliance on strong assumptions, which limit the practicability of federated learning. To solve these problems, we propose a Robustness-enhanced privacy-preserving Federated learning with scaled dot-product attention (RFed) under dual-server model. Specifically, we design a highly robust defense mechanism that uses a dual-server model instead of traditional single-server model to significantly improve model accuracy and completely eliminate the reliance on strong assumptions. Formal security analysis proves that our scheme achieves convergence and provides privacy protection, and extensive experiments demonstrate that our scheme reduces high computational overhead while guaranteeing privacy preservation and model accuracy, and ensures that the failure rate of poisoning attacks is higher than 96%. Yinbin Miao, Xinru Yan, Xinghua Li 0001, Shujiang Xu, Ximeng Liu, Hongwei Li 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2024 | Beyond Result Verification: Efficient Privacy-Preserving Spatial Keyword Query With Suppressed LeakageabstractBoolean range query (BRQ) as a typical type of spatial keyword query that is widely used in geographic information systems, location-based services and other applications. It retrieves the objects inside the query range and containing all query keywords. Many privacy-preserving BRQ schemes have been proposed to support BRQ over encrypted data. However, most of them fail to achieve efficient retrieval and lightweight result verification while suppressing access and search pattern leakage. Thus, in this paper, we propose an efficient verifiable privacy-preserving Boolean range query with suppressed leakage. Firstly, we convert BRQ into multi-keyword query by using Gray code and Bloom filter. Then, we achieve efficient oblivious multi-keyword query by combining distributed point function and PRP-based Cuckoo hashing, which protects the access and search patterns. Moreover, we support lightweight and oblivious result verification based on oblivious query, aggregate MAC, keyed-hashing MAC and XOR-homomorphic pseudorandom function. It enables query users to verify the result integrity with a proof whose size is independent of the size of the outsourced dataset. Finally, formal security analysis and extensive experiments demonstrate that our proposed scheme is adaptively secure and efficient for practical applications, respectively. Qiuyun Tong, Xinghua Li 0001, Yinbin Miao, Yunwei Wang, Ximeng Liu, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | OpenVFL: A Vertical Federated Learning Framework With Stronger Privacy-PreservingabstractFederated learning (FL) allows multiple parties, each holding a dataset, to jointly train a model without leaking any information about their own datasets. In this paper, we focus on vertical FL (VFL). In VFL, each party holds a dataset with the same sample space and different feature spaces. All parties should first agree on the training dataset in the ID alignment phase. However, existing works may leak some information about the training dataset and cause privacy leakage. To address this issue, this paper proposes OpenVFL, a vertical federated learning framework with stronger privacy-preserving. We first propose NCLPSI, a new variant of labeled PSI, in which both parties can invoke this protocol to get the encrypted training dataset without leaking any additional information. After that, both parties train the model over the encrypted training dataset. We also formally analyze the security of OpenVFL. In addition, the experimental results show that OpenVFL achieves the best trade-offs between accuracy, performance, and privacy among the most state-of-the-art works. Yunbo Yang, Yuhao Pan, Zhenfu Cao, Xiaolei Dong, Xiaoguo Li, Jianfei Sun, Guomin Yang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 10 |
| 2024 | PkT-SIN: A Secure Communication Protocol for Space Information Networks With Periodic k-Time Anonymous AuthenticationabstractSpace Information Network (SIN) enables universal Internet connectivity for any object, even in remote and extreme environments where deploying a cellular network is difficult. Access authentication is crucial for ensuring user access control in SIN and preventing unauthorized entities from gaining access to network services. However, due to the complex communication environment in SIN, including exposed links and higher signal delay, designing a secure and efficient authentication scheme presents a significant challenge. In this paper, we propose a secure communication protocol for SIN with periodick-time anonymous authentication (named PkT-SIN) that allows satellite users to anonymously authenticate to ground stations at mostktimes in each single time period. An efficient handover mechanism is designed to ensure seamless communication for satellite users to communicate with different satellites and ground stations, taking into account the dynamic topology of SIN. As a core component of PkT-SIN, we propose a novel primitive, periodick-time keyed-verification anonymous credential (PkT-KVAC), that enables users to derivektokens from a credential for anonymous and unlinkable authentication. On the other hand, a verifier can always recognize a reused token from a dishonest user. PkT-KVAC is of independent contribution to anonymous authentication in pay-per-use business scenarios. Formal security proofs confirm that PkT-SIN and PkT-KVAC have desired security features. The supremacy of their computing features is demonstrated through comprehensive comparison and rigorous performance analysis. Yang Yang 0026, Wenyi Xue, Jianfei Sun, Guomin Yang, Yingjiu Li, HweeHwa Pang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2024 | Privacy-Preserved Data Disturbance and Truthfulness Verification for Data TradingabstractThe advanced data trading allows data generator’s (DG) disturbed data to be traded as both initial and reselling trading modes, which meets DG’s raw data privacy and data consumers’ (DCs) vast data requirement. However, the traded data truthfulness verifiability cannot be guaranteed in the privacy-preserved way. Firstly, due to DG’s independent and random disturbance, DC cannot verify whether the traded data is disturbed under his required disturbance parameter without carrying privacy leakage on DG. Secondly, because the reselling trading is allowed, DC can hardly verify the traded data’s origin truthfulness under the deceiving of data reseller (DR) while protecting his purchase privacy. Aiming at the above problems, we propose the privacy-preserved data disturbance and truthfulness verification for data trading. Specifically, an honest-but-curious trading server (TS) is introduced to assist our devised private-verifiable imprint-embedded disturbance method where imprint is blinding. Subsequently, TS implements the adaptive truthfulness verification by constructing imprint-embedded individual verification formula and requiring verified participants to decrypt the formula result. The verified participants cannot inform the blinding imprint value to forge the correct result, ensuring the accuracy of the devised verification method. Theoretical analysis proves that participants’ privacy is preserved and the traded data’s truthfulness can be guaranteed. Extensive experiments using the real-world dataset demonstrate that without any extra privacy cost, our scheme verifies 100% untruthful traded data compared with the existing solutions’ 50%. Man Zhang 0010, Xinghua Li 0001, Yinbin Miao, Bin Luo 0006, Wanyun Xu, Yanbing Ren, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2024 | SOCI+: An Enhanced Toolkit for Secure Outsourced Computation on IntegersabstractSecure outsourced computation is critical for cloud computing to safeguard data confidentiality and ensure data usability. Recently, secure outsourced computation schemes following a twin-server architecture based on partially homomorphic cryptosystems have received increasing attention. The Secure Outsourced Computation on Integers (SOCI) toolkit is the state-of-the-art among these schemes which can perform secure computation on integers without requiring the costly bootstrapping operation as in fully homomorphic encryption; however, SOCI suffers from relatively large computation and communication overhead. In this paper, we propose SOCI+ which significantly improves the performance of SOCI. Specifically, SOCI+ employs a novel (2, 2)-threshold Paillier cryptosystem with fast encryption and decryption as its cryptographic primitive, and supports a suite of efficient secure arithmetic computation on integers protocols, including a secure multiplication protocol (SMUL), a secure comparison protocol (SCMP), a secure sign bit-acquisition protocol (SSBA), and a secure division protocol (SDIV), all based on the (2, 2)-threshold Paillier cryptosystem with fast encryption and decryption. In addition, SOCI+ incorporates an offline and online computation mechanism to further optimize its performance. We perform rigorous theoretical analysis to prove the correctness and security of SOCI+. Compared with SOCI, our experimental evaluation shows that SOCI+ is up to 5.3 times more efficient in online runtime and 40% less in communication overheads. Bowen Zhao 0001, Weiquan Deng, Xiaoguo Li, Ximeng Liu, Qingqi Pei, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | Efficient Privacy-Preserving Federated Learning With Improved Compressed SensingabstractTo solve the data silos issue in distributed machine learning with privacy leakage, privacy-preserving federated learning (PPFL) has been extensively explored in both academic and industrial fields. However, the existing PPFL solutions still suffer from high computation and communication overheads, which result in excessive consumption of communication bandwidth and slow down the training process of FL. To address these issues, we propose a secure and communication-efficient FL scheme using improved compressed sensing and CKKS homomorphic encryption. Specifically, we implement a lossy compression of the model by using discrete cosine transform, then use CKKS homomorphic encryption to encrypt the data transmitted between clients and center server due to its high efficiency and support for batch encryption. Formal security analysis proves that our scheme is secure against indistinguishability under chosen plaintext attack and extensive experiments demonstrate that our scheme achieves a high accuracy at 0.05% compression rate. Yinbin Miao, Xinghua Li 0001, Linfeng Wei, Zhiquan Liu 0001, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Ind. Informatics | 7 |
| 2024 | FlGan: GAN-Based Unbiased Federated Learning Under Non-IID SettingsabstractFederated Learning (FL) suffers from low convergence and significant accuracy loss due to local biases caused by non-Independent and Identically Distributed (non-IID) data. To enhance the non-IID FL performance, a straightforward idea is to leverage the Generative Adversarial Network (GAN) to mitigate local biases using synthesized samples. Unfortunately, existing GAN-based solutions have inherent limitations, which do not support non-IID data and even compromise user privacy. To tackle the above issues, we propose a GAN-based unbiased FL scheme, calledFlGan, to mitigate local biases using synthesized samples generated by GAN while preserving user-level privacy in the FL setting. Specifically,FlGanfirst presents a federated GAN algorithm using the divide-and-conquer strategy that eliminates the problem of model collapse in non-IID settings. To guarantee user-level privacy,FlGanthen exploits Fully Homomorphic Encryption (FHE) to design the privacy-preserving GAN augmentation method for the unbiased FL. Extensive experiments show thatFlGanachieves unbiased FL with$10\%-60\%$accuracy improvement compared with two state-of-the-art FL baselines (i.e., FedAvg and FedSGD) trained under different non-IID settings. The FHE-based privacy guarantees only cost about 0.53% of the total overhead inFlGan. Zhuoran Ma 0002, Yang Liu 0118, Yinbin Miao, Guowen Xu, Ximeng Liu, Jianfeng Ma 0001, Robert H. Deng |
IEEE Trans. Knowl. Data Eng. | 7 |
| 2024 | Efficient Privacy-Preserving Spatial Data Query in Cloud ComputingabstractWith the rapid development of geographic location technology and the explosive growth of data, a large amount of spatial data is outsourced to the cloud server for reducing the local high storage and computing burdens, but at the same time causes security issues. Thus, extensive privacy-preserving spatial data query schemes have been proposed. Most of the existing schemes use Asymmetric Scalar-Product-Preserving Encryption (ASPE) to encrypt data, but ASPE has proven to be insecure against known plaintext attack. And the existing schemes require users to provide more information about query range and thus generate a large amount of ciphertexts, which causes high storage and computational burdens. To solve these issues, based on enhanced ASPE designed in our conference version, we first propose a basic Privacy-preserving Spatial Data Query (PSDQ) scheme by using a new unified index structure, which only requires users to provide less information about query range. Then, we propose an enhanced PSDQ scheme (PSDQ$^+$) by using Geohash-based$R$-tree structure (called$GR$-tree) and efficient pruning strategy, which greatly reduces the query time. Formal security analysis proves that our schemes achieve Indistinguishability under Chosen Plaintext Attack (IND-CPA), and extensive experiments demonstrate that our schemes are efficient in practice. Yinbin Miao, Yutao Yang, Xinghua Li 0001, Linfeng Wei, Zhiquan Liu 0001, Robert H. Deng |
IEEE Trans. Knowl. Data Eng. | 6 |
| 2024 | BADFL: Backdoor Attack Defense in Federated Learning From Local Model PerspectiveabstractThere is substantial attention to federated learning with its ability to train a powerful global model collaboratively while protecting data privacy. Despite its many advantages, federated learning is vulnerable to backdoor attacks, where an adversary injects malicious weights into the global model, making the global model's targeted predictions incorrect. Existing defenses based on identifying and eliminating malicious weights ignore the similarity variation of the local weights during iterations in the malicious model detection and the presence of benign weights in the malicious model during the malicious local weight elimination, resulting in a poor defense and a degradation of global model accuracy. In this paper, we defend against backdoor attacks from the perspective of local models. First, a malicious model detection method based on interpretability techniques is proposed. The method appends a sampling check after clustering to identify malicious models accurately. We further design a malicious local weight elimination method based on local weight contributions. This method preserves the benign weights in the malicious model to maintain their contributions to the global model. Finally, we analyze the security of the proposed method in terms of model closeness and then verify the effectiveness of the proposed method through experiments. In comparison with existing defenses, the results show that BADFL improves the global model accuracy by 23.14% while reducing the attack success rate to 0.04% in the best case. Xinghua Li 0001, Mengfan Xu, Ximeng Liu, Tong Wu 0011, Jian Weng 0001, Robert H. Deng |
IEEE Trans. Knowl. Data Eng. | 7 |
| 2024 | Time-Controllable Keyword Search Scheme With Efficient Revocation in Mobile E-Health CloudabstractElectronic health (e-health) systems may outsource data such as patient e-health records to mobile cloud servers for efficiency gains (e.g., minimizing local storage and computation costs). However, such a move may result in privacy implications in the presence of semi-honest cloud servers. Searchable Encryption (SE) can potentially facilitate privacy-preserving searches based on keywords for encrypted data stored in the mobile cloud, but most existing SE solutions do not support temporal access control (i.e., a mechanism that grants access permissions to users for specified time ranges). Hence, in this paper we design a time-controllable keyword search scheme by using an attribute-based comparable access control. This allows users to match indexes encrypted at specified time intervals. Then, we improve the basic framework to support efficient user revocation using secret sharing. We then formally prove the security of our proposed frameworks against chosen-keyword attack and key collusion attack, as well as achieving keyword secrecy. We also evaluate the performance of our proposed approach using a real-world dataset to demonstrate their practical utility. Yinbin Miao, Feng Li 0041, Xinghua Li 0001, Zhiquan Liu 0001, Jianting Ning, Hongwei Li 0001, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Mob. Comput. | 8 |
| 2024 | Privacy-Preserving Arbitrary Geometric Range Query in Mobile Internet of VehiclesabstractThe mobile Internet of Vehicles (IoVs) has great potential for intelligent transportation, and creates spatial data query demands to realize the value of data. Outsourcing spatial data to a cloud server eliminates the need for local computation and storage, but it leads to data security and privacy threats caused by untrusted third-parties. Existing privacy-preserving spatial range query solutions based on Homomorphic Encryption (HE) have been developed to increase security. However, in the single server model, the private key is held by the query user, which incurs high computation and communication burdens on query users due to multiple rounds of interactions. Moreover, exposing data access patterns to semi-honest servers is highly vulnerable to frequency and statistical attacks. To solve these issues, in this paper we propose a secure spatial location query within arbitrary geometric range while protecting access pattern. Specifically, we apply Paillier algorithm and polynomial fitting technique to achieve secure arbitrary geometric range query, design secure and efficient search protocol to hide data access patterns and alleviate query users from high computation and communication burdens under dual-server model. Formal security analysis shows that our scheme is secure under semi-honest model, and extensive experiments demonstrate that our work can reduce users' communication costs by more than 90% compared to previous schemes under single server model, which is practice in real-world scenarios. Yinbin Miao, Xinghua Li 0001, Hongwei Li 0001, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Mob. Comput. | 6 |
| 2024 | Intelligent Adaptive Gossip-Based Broadcast Protocol for UAV-MEC Using Multi-Agent Deep Reinforcement LearningabstractUAV-assisted mobile edge computing (UAV-MEC) has been proposed to offer computing resources for smart devices and user equipment. UAV cluster aided MEC rather than one UAV-aided MEC as edge pool is the newest edge computing architecture. Unfortunately, the data packet exchange during edge computing within the UAV cluster hasn't received enough attention. UAVs need to collaborate for the wide implementation of MEC, relying on the gossip-based broadcast protocol. However, gossip has the problem of long propagation delay, where the forwarding probability and neighbors are two factors that are difficult to balance. The existing works improve gossip from only one factor, which cannot select suitable forwarding probability and avoid redundant messages. Besides, these schemes do not consider the historical packet reception of new neighbors when UAVs fly around, which decreases forwarding efficiency. To solve these problems, we first propose a data structure called Bitgraph that can record the historical packet reception of UAVs. Then, we formulate gossip broadcasting as a partially observable Markov decision process. Based on Bitgraph, we design the reward function. Finally, we design a multi-agent reinforcement learning algorithm, Branching Deep Graph Network (BDGN), which simultaneously makes decisions on forwarding probability and neighbors. Extensive experiments illustrate that our proposal gets more than 29% advantage in terms of the propagation delay and 20% advantage in terms of the redundant messages compared to the existing works. Zhe Ren, Xinghua Li 0001, Yinbin Miao, Zhuowen Li, Mengyao Zhu 0004, Ximeng Liu, Robert H. Deng |
IEEE Trans. Mob. Comput. | 8 |
| 2024 | PAM3S: Progressive Two-Stage Auction-Based Multi-Platform Multi-User Mutual Selection Scheme in MCSabstractMobile crowdsensing (MCS) has been applied in various fields to realize data sharing, where multiple platforms and multiple Mobile Users () have appeared recently. However, aiming at mutual selection, the existing works ignore making ’ utilities with the limited resources and platforms’ utilities while achieving the desired sensing data quality maximum as far as possible. Thus, they cannot motivate both and platforms to participate. To address this problem, standing on both sides of and platforms with conflicting interests, we propose a Progressive two-stage Auction-based Multi-platform Multi-user Mutual Selection scheme (). Specifically, in, we treat mutual selection as a two-stage auction and devise the auction models for and platform using forward and reverse auction ideas, presenting and maximizing the utilities from their respective perspectives. Then, based on the proposed progressive two-stage auction structure, we adopt 0-1 knapsack and Myerson’s price theory to construct the first stage -oriented auction and the second stage platform-oriented auction, achieving devised models. Theoretical analysis shows that is economically robust. Extensive experiments on the real dataset demonstrate that respectively promotes platforms’ and ’ utilities by 76.23% and 10.74 times, compared with the existing works. Bin Luo 0006, Xinghua Li 0001, Yinbin Miao, Man Zhang 0010, Ximeng Liu, Yanbing Ren, Xizhao Luo, Robert H. Deng |
IEEE/ACM Trans. Netw. | 8 |
| 2024 | Robust Permissioned Blockchain Consensus for Unstable Communication in FANETabstractThe utilization of blockchain technology as a distributed information sharing system has gained widespread adoption across various domains. However, its application to Flying Ad-Hoc Network (FANET), characterized by severe packet loss, poses significant challenges. The high packet loss rates in FANETs can result in decreased consensus success rates and negatively impact information sharing consistency and efficiency. In this paper, we proposed RoUBC, a novel consensus scheme for Flying Ad-Hoc Networks (FANET), which is based on the Raft protocol and is designed to address the challenges posed by the severe packet loss network in FANET. The proposed scheme consists of two phases: leader election and block consensus. In the leader election phase, we integrate multi-criteria decision-making and link prediction algorithms to design an efficient stable-leader election method. In the block consensus phase, we propose a dynamic block verification algorithm based on historical verification information to achieve efficient block consensus. Our theoretical analysis demonstrates that the proposed consensus protocol is safe and live, effectively ensuring the consistency of message sharing in FANET. Experiment results show that our scheme outperforms traditional Raft schemes, with 35% increase in consensus success rate and 25% improvement in consensus efficiency. Zhuowen Li, Xinghua Li 0001, Yinbin Miao, Yanbing Ren, Yunwei Wang, Zhe Ren, Robert H. Deng |
IEEE/ACM Trans. Netw. | 9 |
| 2024 | FRQ: Fast Range Query Over Large-Scale Encrypted Key-Value DataabstractWith the rapid growth of data size, a large number of data providers outsource their private data to cloud servers to reduce the high storage and computation burdens, but it also leads to security issues such as privacy leakage. Therefore, many privacy-preserving range query schemes have been proposed. However, most of existing secure range query schemes suffer from low query efficiency and expensive computation and update overheads. To address these issues, we propose a novel Fast Range Query (FRQ) scheme for large-scale encrypted Key-Value (KV) data. First, we introduce REMIX, a space-efficient KV index data structure based on Log-Structured Merge-trees (LSM-trees), which maintains a global sorted view of KV pairs across multiple table files for efficient range queries. Besides, we exploit the write-efficiency compression strategy of LSM-trees to ensure efficient dynamic data updates. Finally, we use Czech Havas Majewski (CHM) to protect the index structure, which reduces the computation overhead and ensures the retrieval accuracy. Formal security analysis proves that our scheme can achieve an acceptable level of security. Extensive experiments demonstrate that our scheme improves the query efficiency by nearly$8\times$and update efficiency by$7\times$compared to state-of-the-art solutions over million-level datasets. Yinbin Miao, Xinghua Li 0001, Yanguo Peng, Liang Guo 0013, Hongwei Li 0001, Robert H. Deng |
IEEE Trans. Serv. Comput. | 7 |
| 2024 | An Adaptive Secure and Practical Data Sharing System With Verifiable Outsourced DecryptionabstractCloud computing is the widespread acceptance of a promising paradigm offering a substantial amount of storage and data services on demand. To preserve data confidentiality, many cryptosystems have been introduced. However, current solutions are incompatible with the resource-constrained end-devices because of a variety of vulnerabilities in terms of practicality and security. In this paper, we propose a practical and secure data-sharing system by introducing a new design of attribute-based encryption with verifiable outsourced decryption (VO-ABE for short). Our system offers: (1) data sharing at a fine-grained level; (2) a scalable key issuing protocol without any secure channel; (3) a verifiable outsourced decryption mechanism for resource-constrained end-devices against the malicious cloud service provider; and (4) adaptive security against the real-world attacks. To formalize our solution with cryptographic analysis, we present the formal definition of VO-ABE and its concrete construction with provable security. In particular, our design leverages the techniques of the traditional ABE, verifiable outsourced decryption, and randomness extractor to support fine-grained access control, cost-effective data sharing, and security assurance with high entropy. Moreover, our design is provably secure in the adaptive model under the standard assumption, which offers a stronger security guarantee since the state-of-the-art solution is selectively secure under the non-standard assumption and suffers from a variety of real-world attacks. The implementation and evaluation demonstrate that our solution enjoys superior functionality and better performance than the relevant solutions. More importantly, our solution is compatible with the resource-constrained end-devices since the decryption mechanism takes around 1.1ms and is 22.7x faster than the state-of-the-art solution. Shengmin Xu, Xingshuo Han, Guowen Xu, Jianting Ning, Xinyi Huang 0001, Robert H. Deng |
IEEE Trans. Serv. Comput. | 6 |
| 2024 | A Privacy-Preserving and Redactable Healthcare Blockchain SystemabstractBlockchain as an open and immutable ledger is being posited as the next frontier in healthcare that will help solve the industry's interoperability challenges. However, immutability in processing personal data is no longer legal since the General Data Protection Regulation (GDPR) requires the “right to be forgotten” as a critical data subject right. To observe such data regulation, it is desirable to build a healthcare blockchain with data redaction in a controlled way. Moreover, electronic health records (EHRs) usually are sensitive and the conventional blockchain lacks systematic and formal security analysis of data confidentiality, especially in the multi-user setting. Furthermore, EHRs are typically helpful in medical research for predicting epidemic diseases and valuable in insurance agencies making business plans. Hence, in healthcare blockchain systems, data confidentiality and flexible key distribution have become the most challenging issues that should be urgently resolved. In this paper, we propose a privacy-preserving and redactable healthcare blockchain system (PRHBS). Our solution offers fine-grained block-level data reduction and secure data sharing with flexible key distribution mechanisms. We give the formal definition and security models of PRHBS, and propose a generic construction based on trapdoor-based chameleon-hash function, attribute-based encryption, and puncturable encryption. We present formal security analysis and give an instantiation based on our proposed generic construction. The comprehensive comparison and experimental simulation demonstrate that our implementation exhibits comparable performance, while surpassing the most relevant solutions in terms of functionality. Shengmin Xu, Jianting Ning, Xiaoguo Li, Jiaming Yuan, Xinyi Huang 0001, Robert H. Deng |
IEEE Trans. Serv. Comput. | 6 |
| 2024 | PIAS: Privacy-Preserving Incentive Announcement System Based on Blockchain for Internet of VehiclesabstractMore vehicles are connecting to the Internet of Things (IoT), transforming Vehicle Ad hoc Networks (VANETs) into the Internet of Vehicles (IoV), providing a more environmentally friendly and safer driving experience. Vehicular announcement networks show promise in vehicular communication applications. However, two major issues arise when establishing such a system. First, user privacy cannot be guaranteed when messages are forwarded anonymously, thus the reliability of these messages is in question. Second, users often lack interest in responding to announcements. To address these problems, we introduce a Blockchain-based incentive announcement system called PIAS. This system enables anonymous message commitment in a semi-trusted environment and encourages witnesses to respond to requests for traffic information. Additionally, PIAS uses blockchain accounts as identities to participate in the system with incentives, ensuring privacy in anonymous announcements. PIAS successfully protects the privacy of participants and motivates witnesses to respond to requests. Furthermore, our assessment of security and compatibility shows that PIAS can maintain privacy and incentivization while being compatible with both the Bitcoin and Ethereum blockchains. Further evaluation has confirmed the system's efficiency in terms of performance. Yonghua Zhan, Yang Yang 0026, Hongju Cheng, Xiangyang Luo 0001, Zhangshuang Guan, Robert H. Deng |
IEEE Trans. Serv. Comput. | 6 |
| 2024 | Oasis: Online All-Phase Quality-Aware Incentive Mechanism for MCSabstractTo motivate users to submit high quality data for mobile crowdsensing (MCS), some quality-aware incentive mechanisms have been proposed, which recruit and pay users strategically. However, in the existing mechanisms, the recruitment based only on tasks matching degree leads to the ineffective insistent data quality incentive. Meanwhile, the absence of the reasonable payment strategy cannot motivate users to submit high quality data in the current task. To address the above problems, we propose anOnlineall-phase quality-awareincentive mechanism (Oasis) to realize the quality incentive in both recruitment and payment phases. With the knapsack secretary, Oasis first devises a quality-aware pre-budgeting recruitment strategy, which decides whether the arriving user's long-term data quality and bid satisfy the recruited criterion. Then, in the payment phase, Oasis evaluates and updates the current and long-term data qualities of users. Based on the evaluation results, a two-level payment strategy is devised employing the Myerson theorem, where users submitting higher quality data can obtain more utilities under the budget constraint. Theoretical analysis proves that Oasis satisfies economic feasibility and constant competitiveness while achieving quality incentive in recruitment and payment phases. Extensive experiments using the real-world dataset demonstrate that the sensing result accuracy of Oasis increases 67% compared with the existing works. Man Zhang 0010, Xinghua Li 0001, Yinbin Miao, Bin Luo 0006, Siqi Ma 0001, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Serv. Comput. | 7 |
| 2023 | Efficient and Secure Spatial Range Query over Large-scale Encrypted DataabstractSpatial range query enjoys widespread application scenarios due to the ever-growing geo-positioning technology in recent years. Huge amounts of encrypted geo-location data are being outsourced to cloud servers to alleviate local storage and computational overheads without leaking sensitive information. However, most existing Privacy-preserving Spatial Range Query (PSRQ) cannot achieve high efficiency while satisfying strong security over large-scale encrypted spatial data. To strike a best possible balance between security and efficiency, we propose a novel efficient Privacy-preserving Spatial Range Query (eP-SRQ) scheme in dual-cloud architecture over large-scale dataset. Specifically, we propose an efficient PSRQ scheme by designing a novel index structure based on Geohash algorithm, Circular Shift and Coalesce Zero-Sum Garbled Bloom Filter (CSC-ZGBF) and Symmetric Homomorphic Encryption (SHE), which makes the computational complexity of query process independent of dataset size. Formal security analysis proves that our scheme can achieve Indistinguishability against Chosen-Plaintext Attack (IND-CPA), and extensive experiments prove that our scheme is feasible in real-world applications. Yinbin Miao, Ximeng Liu, Xiangdong Meng, Robert H. Deng |
ICDCS | 6 |
| 2023 | A Multi-CUAV Multi-UAV Electricity Scheduling Scheme: From Charging Location Selection to Electricity TransactionabstractIn unmanned aerial vehicle (UAV) performing tasks, the UAV often faces electricity shortages. The traditional scheme to charge a UAV needs to return to the ground. Using the charging UAV (CUAV) can avoid the waste of electricity caused by the return. However, the existing works only consider a fixed charging location for electricity replenishment. Moreover, fewer works focus on the matching relationship between multi-CUAV and multi-UAV. It is challenging to complete the expected charging work due to the mismatch between the electricity demand and supply. To address this problem, we propose a two-stage electricity scheduling scheme. Specifically, in the charging location selection stage, we solve the Nash equilibrium (NE) of flight consumption between CUAVs and UAVs through the exact potential game, thereby determining the accessible charging position. Then, in the electricity transaction stage, we adopt the Stackelberg game model to determine the Stackelberg equilibrium (SE) between the acceptance rate of CUAVs and the rejection rate of UAVs, ensuring that both CUAVs and UAVs are satisfied with the unit electricity prices and electricity demands. Based on the above two game stages, we propose a supply and demand scheduling (SDS) algorithm to achieve dynamic scheduling between CUAVs and UAVs. Theoretical analysis indicates the exits of NE and SE. Furthermore, the extensive experiments show that our scheme has significant advantages over the baselines in charging cost, charging price, and flight consumption. Peilei Xue, Xinghua Li 0001, Zhongyuan Jiang, Bin Luo 0006, Yinbin Miao, Ximeng Liu, Robert H. Deng |
IEEE Internet Things J. | 7 |
| 2023 | Privacy-Preserving Asynchronous Federated Learning Framework in Distributed IoTabstractTo solve the data island issue in the distributed Internet of Things (IoT) without privacy leakage, privacy-preserving federated learning (PPFL) has been extensively explored in both academic and industrial fields. However, existing PPFL solutions still suffer from a single point of failure and incur untrusted aggregation results caused by a malicious central server, and even cause a loss of model accuracy in an asynchronous setting. To solve these issues, we propose a privacy-preserving asynchronous federated learning scheme by using blockchain. Specifically, we use blockchain to address single points of failure and untrustworthy aggregation results, implement reliable model aggregation utilizing a practical byzantine fault-tolerant protocol in an asynchronous setting, and leverage differential privacy to improve system robustness. Formal security analysis and convergence analysis demonstrate that the proposed scheme is secure and robust, and extensive experiments demonstrate that our scheme can effectively ensure the accuracy of the system when compared with state-of-the-art schemes. Xinru Yan, Yinbin Miao, Xinghua Li 0001, Kim-Kwang Raymond Choo, Xiangdong Meng, Robert H. Deng |
IEEE Internet Things J. | 6 |
| 2023 | PRI: PCH-based privacy-preserving with reusability and interoperability for enhancing blockchain scalability
Jian Weng 0001, Wei Wu 0001, Ming Li 0049, Yingjiu Li, Haoxin Tu, Yongdong Wu, Robert H. Deng |
J. Parallel Distributed Comput. | 8 |
| 2023 | MP-CLF: An effective Model-Preserving Collaborative deep Learning Framework for mitigating data leakage under the GAN
Zhenzhu Chen, Anmin Fu, Mang Su, Robert H. Deng |
Knowl. Based Syst. | 5 |
| 2023 | Privacy-Preserving Bloom Filter-Based Keyword Search Over Large Encrypted Cloud DataabstractTo achieve the search over encrypted data in cloud server, Searchable Encryption (SE) has attracted extensive attention from both academic and industrial fields. The existing Bloom filter-based SE schemes can achieve similarity search, but will generally incur high false positive rates, and even leak the privacy of values in Bloom filters (BF). To solve the above problems, we first propose a basicPrivacy-preservingBloom filter-basedKeywordSearch scheme using the Circular Shift and Coalesce-Bloom Filter (CSC-BF) and Symmetric-key Hidden Vector Encryption (SHVE) technology (namely PBKS), which can achieve effective search while protecting the values in BFs. Then, we design a new index structure T-CSCBF utilizing theTwin Bloom Filter (TBF) technology. Based on this, we propose an improved scheme PBKS+, which assigns a unique inclusion identifier to each position in each BF with privacy protection. Formal security analysis proves that our schemes are secure against Indistinguishability under Selective Chosen-Plaintext Attack (IND-SCPA), and extensive experiments using real-world datasets demonstrate that our schemes are feasible in practice. Yanrong Liang, Jianfeng Ma 0001, Yinbin Miao, Da Kuang, Xiangdong Meng, Robert H. Deng |
IEEE Trans. Computers | 6 |
| 2023 | Towards Efficient Verifiable Boolean Search Over Encrypted Cloud DataabstractSymmetric Searchable Encryption (SSE) schemes facilitate searching over encrypted data, and have been extensively explored to improve function, efficiency or security. There are, however, additional functions that we need to consider in a real-world setting. For example, forward and backward privacy are required to adequately secure newly added documents and deleted documents in Dynamic SSE (DSSE) schemes, and support boolean search (that allows users to search over encrypted data using basic boolean operations) to achieve improved efficiency and retrieval accuracy. Therefore, in this article we first construct the Verifiable Boolean Search over encrypted data (VBS), and then improve VBS to achieve Forward and Backward privacy (VBS-FB). Finally, we formally prove the security of our proposed schemes, and evaluate their performance using real-world datasets. Feng Li 0041, Jianfeng Ma 0001, Yinbin Miao, Zhiquan Liu 0001, Kim-Kwang Raymond Choo, Ximeng Liu, Robert H. Deng |
IEEE Trans. Cloud Comput. | 7 |
| 2023 | Share Your Data Carefree: An Efficient, Scalable and Privacy-Preserving Data Sharing Service in Cloud ComputingabstractBenefiting from the powerful computing and storage capabilities of cloud services, data sharing in the cloud has been permeated across various applications including social networks, e-health and crowdsourcing transportation system. Intuitively, outsourcing data to untrusted cloud commonly raises concerns about data privacy breaches. To combat this, one approach is exploiting Broadcast Based Searchable Encryption (BBSE) for secure data sharing. Nevertheless, the latest proposed BBSE is still defective in either security or efficiency. In this article, we propose ESPD, an Efficient, Scalable and Privacy-preserving Data sharing framework over encrypted cloud dataset. Different from previous works, ESPD supports sharing target data to multiple users with distinct secret keys, and keeps a constant ciphertext length with the changes of the amount of system users. This feature significantly improves search efficiency and makes ESPD scalable in real-world scenarios. We show a formal analysis to prove the security of ESPD in terms of file privacy, keyword privacy and trapdoor privacy. Also, extensive experiments on real-world dataset are conducted to indicate the desirable performance of ESPD compared to other similar schemes. Jianfei Sun, Guowen Xu, Tianwei Zhang 0004, Hu Xiong, Hongwei Li 0001, Robert H. Deng |
IEEE Trans. Cloud Comput. | 6 |
| 2023 | Dual Traceable Distributed Attribute-Based Searchable Encryption and Ownership TransferabstractIn this article, we proposedualtraceabledistributedattributebasedencryption withsubsetkeywordsearch system (DT-DABE-SKS, abbreviated as$\mathcal {DT}$) to simultaneously realize data source trace (secure provenance) and user trace (traitor trace) and flexible subset keyword search from polynomial interpolation. Leveraging non-interactive zero-knowledge proof technology,$\mathcal {DT}$preserves privacy for both data providers and users in normal circumstances, but a trusted authority can disclose their real identities if necessary, such as the providers deceitfully uploading false data or users maliciously leaking secret attribute key. Next, we introduce the new conception of updatable and transferable message-lock encryption (UT-MLE) for block-level dynamic encrypted file update, where the owner does not have to download the whole ciphertext, decrypt, re-encrypt and upload for minor document modifications. In addition, the owner is permitted to transfer file ownership to other system customers with efficient computation in an authenticated manner. A nontrivial integration of$\mathcal {DT}$and UT-MLE lead to the distributed ABSE with ownership transfer system ($\mathcal {DTOT}$) to enjoy the above merits. We formally define$\mathcal {DT}$, UT-MLE, and their security model. Then, the instantiations of$\mathcal {DT}$and UT-MLE, and the formal security proof are presented. Comprehensive comparison and experimental analysis based on real dataset affirm their feasibility. Yang Yang 0026, Robert H. Deng, Wenzhong Guo, Hongju Cheng, Xiangyang Luo 0001, Xianghan Zheng, Chunming Rong |
IEEE Trans. Cloud Comput. | 2 |
| 2023 | PriMPSO: A Privacy-Preserving Multiagent Particle Swarm Optimization AlgorithmabstractCentralized particle swarm optimization (PSO) does not fully exploit the potential of distributed or parallel computing and suffers from single-point-of-failure. Particularly, each particle in PSO comprises a potential solution (e.g., traveling route and neural network model parameters) which is essentially viewed as private data. Unfortunately, previously neither centralized nor distributed PSO algorithms fail to protect privacy effectively. Inspired by secure multiparty computation and multiagent system, this article proposes a privacy-preserving multiagent PSO algorithm (called PriMPSO) to protect each particle's data and enable private data sharing in a privacy-preserving manner. The goal of PriMPSO is to protect each particle's data in a distributed computing paradigm via existing PSO algorithms with competitive performance. Specifically, each particle is executed by an independent agent with its own data, and all agents jointly perform global optimization without sacrificing any particle's data. Thorough investigations show that selecting an exemplar from all particles and updating particles through the exemplar are critical operations for PSO algorithms. To this end, this article designs a privacy-preserving exemplar selection algorithm and a privacy-preserving triple computation protocol to select exemplars and update particles, respectively. Strict privacy analyses and extensive experiments on a benchmark and a realistic task confirm that PriMPSO not only protects particles' privacy but also has uniform convergence performance with the existing PSO algorithm in approximating an optimal solution. Bowen Zhao 0001, Ximeng Liu, An Song, Weineng Chen, Kuei-Kuei Lai, Jun Zhang 0003, Robert H. Deng |
IEEE Trans. Cybern. | 7 |
| 2023 | Achieving Fine-Grained Data Sharing for Hierarchical Organizations in CloudsabstractCloud computing has become an increasingly popular option for users to store and share data. Encryption prior to outsourcing data to the cloud is the best way to protect data security and privacy; however, it hinders sharing of the data that was encrypted. In addition, users in many real-world organizations (e.g., enterprises) have multiple level structures and a higher-level user should have the privilege to decide which data can be shared with a lower-level user. Most solutions in the literature suffer from inefficiency or inflexibility in tackling this problem. In this article, we propose a fine-grained hierarchical data sharing (FHDS) scheme in clouds. With FHDS, the data owner can encrypt data with his public key, and then selectively share encrypted data with users in a hierarchy; if necessary, the users can disseminate the owner's data to their subordinates in the lower levels by generating access keys. In particular, the higher-level users could puncture the keys with some tags such that the part of the owner's data which is labeled by the punctured tags will not be accessible to the lower-level users. The proposed scheme is provable secure under our security model and performance analyses show the efficiency of the scheme. Zheng Qin 0001, Qianhong Wu, Robert H. Deng, Zhenyu Guan 0002, Yupeng Hu 0004, Fangmin Li |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | FeSA: Automatic Federated Swarm Attestation on Dynamic Large-Scale IoT DevicesabstractSwarm attestation, as an important branch of Remote Attestation (RA), enables a trusted party (verifier) to verify the security states of multiple devices (provers) in a large network (swarm) simultaneously via a challenge-response mechanism. However, swarm attestation suffers from significant redundancy overhead since all devices in the swarm need to be attested in each attestation round. Besides, it faces challenges such as verifier-impersonation Denial of Service (DoS) attacks, highly dynamic networks, transient & self-relocating malware, and Time-Of-Check-Time-Of-Use (TOCTOU) attacks. In this paper, considering not only the detection accuracy but also the privacy of swarm owners in real Internet of Things (IoT) scenarios, we propose an Automatic Federated Swarm Attestation scheme (FeSA). Under this scheme, we design a federated-learning-based automatic swarm attestation protocol that enables theverifiersto identify the suspicious devices by a neural network model and then attest them. To the best of our knowledge, this is the first scheme to apply a federated learning method to RA, ruling out the redundancy attestation rounds while preserving data privacy. The FeSA redesigns the interaction model of RA by a challenge-query mechanism to reduce the overhead of an individual device to a constant. In order to evaluate our scheme, we first set up a smart office environment with 12 types of smart IoT devices for real-world data collection up to 21 days. Based on the real dataset, we demonstrate that FeSA can indeed identify the compromised IoT devices while reducing redundancy. We further simulate large-scale swarms of up to 1,000,000 devices to validate the efficiency of FeSA in large-scale swarms. Last, the security analysis proves the ability of FeSA to resist various attacks. Boyu Kuang, Anmin Fu, Yansong Gao 0001, Yuqing Zhang 0001, Jianying Zhou 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2023 | VerifyTL: Secure and Verifiable Collaborative Transfer LearningabstractGetting access to labeled datasets in certain sensitive application domains can be challenging. Hence, one may resort to transfer learning to transfer knowledge learned from a source domain with sufficient labeled data to a target domain with limited labeled data. However, most existing transfer learning techniques only focus on one-way transfer which may not benefit the source domain. In addition, there is the risk of a malicious adversary corrupting a number of domains, which can consequently result in inaccurate prediction or privacy leakage. In this paper, we construct a secure andVerifiable collaborativeTransferLearning scheme, VerifyTL, to support two-way transfer learning over potentially untrusted datasets by improving knowledge transfer from a target domain to a source domain. Furthermore, we equip VerifyTL with a secure and verifiable transfer unit employing SPDZ computation to provide privacy guarantee and verification in the multi-domain setting. Thus, VerifyTL is secure against malicious adversary that can compromise up to$n-1$out of$n$data domains. We analyze the security of VerifyTL and evaluate its performance over four real-world datasets. Experimental results show that VerifyTL achieves significant performance gains over existing secure learning schemes. Zhuoran Ma 0002, Jianfeng Ma 0001, Yinbin Miao, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2023 | Forward/Backward and Content Private DSSE for Spatial Keyword QueriesabstractSpatial keyword queries are attractive techniques that have been widely deployed in real-life applications in recent years, such as social networks and location-based services. However, existing solutions neither support dynamic update nor satisfy the privacy requirements in real applications. In this article, we investigate the problem of Dynamic Searchable Symmetric Encryption (DSSE) for spatial keyword queries. First, we formulate the definition of DSSE for spatial keyword queries (namely, DSSESKQ) and extend the DSSE leakage functions to capture the leakages in DSSESKQ. Then, we present a practical DSSESKQ construction based on geometric prefix encoding inverted-index and encrypted bitmap. Rigorous security analysis proves that our construction can achieve not only forward/backward privacy but content privacy as well, which can resist the most existing leakage-abuse attacks. Evaluation results using real-world datasets demonstrate the efficiency and feasibility of our construction. Comparative analysis reveals that our construction outperforms state-of-the-art schemes in terms of privacy and performance, e.g., our construction is 175x faster than existing schemes with only 51% server storage cost. Xiangyu Wang 0010, Jianfeng Ma 0001, Ximeng Liu, Yinbin Miao, Yang Liu 0118, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2023 | Hercules: Boosting the Performance of Privacy-Preserving Federated LearningabstractIn this paper, we address the problem of privacy-preserving federated neural network training with$N$users. We presentHercules, an efficient and high-precision training framework that can tolerate collusion of up to$N-1$users.Herculesfollows the POSEIDON framework proposed by Sav et al. (NDSS’21), but makes a qualitative leap in performance with the following contributions: (i) we design a novel parallel homomorphic computation method for matrix operations, which enables fast Single Instruction and Multiple Data (SIMD) operations over ciphertexts. For the multiplication of two$h\times h$dimensional matrices, our method reduces the computation complexity from$O(h^{3})$to$O(h)$. This greatly improves the training efficiency of the neural network since the ciphertext computation is dominated by the convolution operations; (ii) we present an efficient approximation on the sign function based on the composite polynomial approximation. It is used to approximate non-polynomial functions (i.e.,ReLUandmax), with the optimal asymptotic complexity. Extensive experiments on various benchmark datasets (BCW, ESR, CREDIT, MNIST, SVHN, CIFAR-10 and CIFAR-100) show that compared with POSEIDON,Herculesobtains up to 4% increase in model accuracy, and up to$60\times$reduction in the computation and communication cost. Guowen Xu, Xingshuo Han, Shengmin Xu, Tianwei Zhang 0004, Hongwei Li 0001, Xinyi Huang 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2023 | A Secure EMR Sharing System With Tamper Resistance and Expressive Access ControlabstractTo reduce the cost of human and material resources and improve the collaborations among medical systems, research laboratories and insurance companies for healthcare researches and commercial activities, electronic medical records (EMRs) have been proposed to shift from paperwork to friendly shareable electronic records. To take advantage of EMRs efficiently and reduce the cost of local storage, EMRs are usually outsourced to the remote cloud for sharing medical data with authorized users. However, cloud service providers are untrustworthy. In this paper, we propose an efficient, secure, and flexible EMR sharing system by introducing a novel cryptosystem called dual-policy revocable attribute-based encryption and tamper resistance blockchain technology. Our proposed system enables EMRs to be shared at a fine-grained level and allows data users to detect any unauthorized manipulation. Moreover, the key generation center can revoke malicious users without affecting the honest users. We provide the formal security model as well as the concrete scheme with security analysis. The experimental simulation and experimental analysis of our proposed scheme demonstrate that our proposed system has superior performances to the most relevant solutions. Shengmin Xu, Jianting Ning, Yingjiu Li, Yinghui Zhang 0002, Guowen Xu, Xinyi Huang 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2023 | VOLERE: Leakage Resilient User Authentication Based on Personal Voice ChallengesabstractVoiceprint Authentication as a Service (VAaS) offers great convenience due to ubiquity, generality, and usability. Despite its attractiveness, it suffers from user voiceprint leakage over the air or at the cloud, which intrudes user voice privacy and retards its wide adoption. The literature still lacks an effective solution on this issue. Traditional methods based on cryptography are too complex to be practically deployed while other approaches distort user voiceprints, which hinders accurate user identification. In this article, we propose a leakage resilient user authentication cloud service with privacy preservation based on random personal voice challenges, named VOLERE (VOice LEakage REsilient). It applies a novel voiceprint synthesis method based on a Log Magnitude Approximate (LMA) vocal tract model to fuse original voices of different speaking modes in order to generate a synthesized voiceprint for authentication. Thus, raw voiceprints of users can be well protected. We implement VOLERE and conduct a series of user tests. Experimental results show sound performance of VOLERE regarding authentication accuracy, efficiency, stability, leakage resilience and user acceptance. In particular, its authentication accuracy is reasonably stable regardless user nationality, gender, age, elapsed time, and environment, as well as variance of speaking modes. Rui Zhang 0081, Zheng Yan 0002, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | Fair Cloud Auditing Based on Blockchain for Resource-Constrained IoT DevicesabstractInternet of Things (IoT) devices upload their data into the cloud for storage because of their limited resources. However, cloud storage data has been subject to potential integrity threats, and consequently auditing techniques are demanded to ensure the integrity of stored data. Unfortunately, existing auditing approaches require owners to undertake expensive tag calculations, which is unsuitable for resource-constrained IoT devices. To resolve the issue, we present aFairCloudAuditing proposal by employing theBlockchain (FCAB). We combine certificateless signatures with the designed dynamic structure to constructively offload the cost of tag computation from the IoT device to the introduced fog node, significantly reducing the local burden. Considering that fog nodes may behave dishonestly during auditing, FCAB enables the IoT device to verify the audit result's authenticity by extracting reliable checking records from the blockchain, thereby achieving auditing fairness, which ensures that thehonestcloud and fog node will gain the corresponding reward. Finally, FCAB is proved to satisfy tag unforgeability, proof unforgeability, privacy preserving, and auditing fairness. Experiment evaluations affirm that FCAB is computationally and communicationally efficient and retains a smaller and fixed computation locally at the data processing stage (mainly including tag computation) than existing auditing methods. Lei Zhou 0026, Anmin Fu, Guomin Yang, Yansong Gao 0001, Shui Yu 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2023 | Authenticable Data Analytics Over Encrypted Data in the CloudabstractStatistical analytics on encrypted data requires a fully-homomorphic encryption (FHE) scheme. However, heavy computation overheads make FHE impractical. In this paper we propose a novel approach to achieve privacy-preserving statistical analysis on an encrypted database. The main idea of this work is to construct a privacy-preserving calculator to calculate attributes’ count values for later statistical analysis. To authenticate these encrypted count values, we adopt an authenticable additive homomorphic encryption scheme to construct the calculator. We formalize the notion of an authenticable privacy-preserving calculator that has properties of broadcasting and additive homomorphism. Further, we propose a cryptosystem based on binary vectors to achieve complex logic expressions for statistical analysis on encrypted data. With the aid of the proposed cryptographic calculator, we design several protocols for statistical analysis including conjunctive, disjunctive and complex logic expressions to achieve more complicated statistical functionalities. Experimental results show that the proposed scheme is feasible and practical. Lanxiang Chen, Yi Mu 0001, Lingfang Zeng, Fatemeh Rezaeibagha, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | Privacy-Preserving Multi-User Outsourced Computation for Boolean CircuitsabstractWith the prevalence of outsourced computation, such as Machine Learning as a Service, protecting the privacy of sensitive data throughout the whole computation is a critical yet challenging task. The problem becomes even more tricky when multiple sources of input and/or multiple recipients of output are involved, who would encrypt/decrypt data using different keys. Considering many computation tasks demand binary operands and operations but there are only outsourced computation constructions for arithmetic calculations [1], in this paper, the authors propose a privacy-preserving outsourced computation framework for Boolean circuits. The proposed framework can protect sensitive data throughout the whole computation, i.e., input, output and all the intermediate values, ensuring privacy for general outsourced tasks. Moreover, it compresses the ciphertext domain of [1] and attains secure protocols for four logic gates (AND, OR, NOT, and XOR) which are the basic operations in Boolean circuits. With the proposed framework as a building block, a novel Privacy-preserved (encrypted) Bloom Filter and a Multi-keyword Searchable Encryption scheme under the multi-user setting are presented. Security proof and experimental results show that the proposal is reliable and practical. Xueqiao Liu, Guomin Yang, Willy Susilo, Robert H. Deng, Jian Weng 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | Efficient Privacy-Preserving Spatial Range Query Over Outsourced Encrypted DataabstractWith the rapid development of Location-Based Services (LBS), a large number of LBS providers outsource spatial data to cloud servers to reduce their high computational and storage burdens, but meanwhile incur some security issues such as location privacy leakage. Thus, extensive privacy-preserving LBS schemes have been proposed. However, the existing solutions using Bloom filter do not take into account the redundant bits that do not map information in Bloom filter, resulting in high computational overheads, and reveal the inclusion relationship in Bloom filter. To solve these issues, we propose an efficient Privacy-preserving Spatial Range Query (PSRQ) scheme by skillfully combining Geohash algorithm with Circular Shift and Coalesce Bloom Filter (CSC-BF) framework and Symmetric-key Hidden Vector Encryption (SHVE), which not only greatly reduces the computational cost of generating token but also speeds up the query efficiency on large-scale datasets. In addition, we design a Confused Bloom Filter (CBF) to confuse the inclusion relationship by confusing the values of 0 and 1 in the Bloom filter. Base on this, we further propose a more secure and practical enhanced scheme PSRQ+by using CBF and Geohash algorithm, which can support more query ranges and achieve adaptive security. Finally, formal security analysis proves that our schemes are secure against Indistinguishability under Chosen-Plaintext Attacks (IND-CPA) and PSRQ+achieves adaptive IND-CPA, and extensive experimental tests demonstrate that our schemes using million-level dataset improve the query efficiency by 100x compared with previous state-of-the-art solutions. Yinbin Miao, Yutao Yang, Xinghua Li 0001, Zhiquan Liu 0001, Hongwei Li 0001, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2023 | Secure Model-Contrastive Federated Learning With Improved Compressive SensingabstractFederated Learning (FL) has been widely used in various fields such as financial risk control, e-government and smart healthcare. To protect data privacy, many privacy-preserving FL approaches have been designed and implemented in various scenarios. However, existing works incur high communication burdens on clients, and affect the training model accuracy due to non-Independently and Identically Distributed (non-IID) data samples separately owned by clients. To solve these issues, in this paper we propose a secure Model-Contrastive Federated Learning with improved Compressive Sensing (MCFL-CS) scheme, motivated by contrastive learning. We combine model-contrastive loss and cross-entropy loss to design the local network architecture of our scheme, which can alleviate the impact of data heterogeneity on model accuracy. Then we utilize improved compressive sensing and local differential privacy to reduce communication costs and prevent clients’ privacy leakage. The formal security analysis shows that our scheme satisfies (ε,δ)-differential privacy. And extensive experiments using five benchmark datasets demonstrate that our scheme improves the model accuracy by 3.45% on average of all datasets under the non-IID setting and reduces the communication costs by more than 95%, when compared with FedAvg. Yinbin Miao, Xinghua Li 0001, Hongwei Li 0001, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2023 | Verifiable, Fair and Privacy-Preserving Broadcast Authorization for Flexible Data Sharing in CloudsabstractThe cloud-based data sharing technology with cryptographic primitives enables data owners to outsource data into paradigms and privately share information with arbitrary recipients without geographic barriers. However, we argue that most of existing efforts for outsourced data sharing are either inefficient, inflexible, or incompletely secure due to the following problems: (1) lack of efficient strategies for dynamically designating target ciphertexts to multiple recipients; (2) how to hide the identity of the recipient and (3) how to verify the correctness of outsourced ciphertext transformation without any denial. To the best of our knowledge, no previous work has thoroughly explored the above three issues, motivating us to design such an efficient and comprehensively secure outsourced data sharing mechanism. We design VF-PPBA, the first Verifiable, Fair and Privacy-preserving Broadcast Authorization framework for flexible data sharing in clouds. In more detail, we first invent a new primitive, privacy-preserving multi-recipient broadcast proxy re-encryption (PPMR-BPRE), which enables the authorization of a given ciphertext to different recipients with efficient ciphertext transformation, and further guarantees that any malicious adversary deduces nothing about the identity of the recipient. Then, we present VF-PPBA for flexible data sharing with PPMR-BPRE as the underlying structure, which in addition to inheriting all the functionalities of PPMR-BPRE, is capable of supporting the verifiability of the outcome correctness of the outsourced conversion task, and being immune to the malicious accusation if the outsourcing outcome is correctly completed. We formalize the adversarial models and render comprehensively strict security proofs to prove the security of our proposed solutions. Its performance is also validated via experimental simulations to showcase the practicability and effectiveness. Jianfei Sun, Guowen Xu, Tianwei Zhang 0004, Xuehuan Yang, Mamoun Alazab, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2023 | Privacy-Aware and Security-Enhanced Efficient Matchmaking EncryptionabstractData sharing technologies enable users to outsource data and privately share information with arbitrary recipients without geographic barriers. However, existing efforts for secure data sharing are either inflexible, insufficiently-secure or inefficient. In this paper, we invent PS-ME, the first Privacy-aware and Security-enhanced efficient Matchmaking Encryption (ME) for flexible data sharing. To be more specific, we first formulate an identity-based broadcast matchmaking encryption (IB-BME) for one-to-many data sharing, which enables both participants to specify respective access policies to the encrypted data, such that the data can be revealed by multiple recipients in the case that both access policies are satisfied. In IB-BME, a general matchmaking transformation solution realizing one-to-many sharing is initialized. We also formulate the PS-ME with the general matchmaking transformation solution of IB-BME as the underlying approach, which in addition to featuring IB-BME’s all desirable properties, enables efficient decryption, identity anonymity and CCA-security, where we address the open problem of ME regarding CCA-security (raised in CRYPTO’2019). Finally, the comprehensively rigorous security proofs indicate the security of the suggested methodologies. The experimental results are also shown to demonstrate their practicability and effectiveness. Jianfei Sun, Guowen Xu, Tianwei Zhang 0004, Xuehuan Yang, Mamoun Alazab, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2023 | Accountable and Fine-Grained Controllable Rewriting in BlockchainsabstractMost blockchains are designed to be immutable such that an object, e.g., a block or a transaction, is persisted once it has been registered. However, blockchain immutability hinders blockchain development due to the increasing abuse of blockchain storage and legal obligations. To break immutability in a controlled way, Derler et al. (NDSS’19) proposed a redactable blockchain with fine-grained controllable rewriting by introducing the notion of policy-based chameleon hash (PCH). Given a PCH-based object associated with an access policy, a trapdoor holder whose rewriting privileges satisfy the access policy can alter the object. Although this work offers an elegant approach to blockchain rewriting, it lacks accountability. In practice, the trapdoor holders may abuse their rewriting privileges, and even use their chameleon trapdoor to build a device in a blackbox manner to gain illegal profits while avoiding being caught. In this paper, we introduce a new design of PCH with blackbox accountability (PCHA). Blackbox accountability offers not only linkability between any modified object and its modifier, but also traceability that enables a central authority to identify responsible trapdoor holders whose secret keys have contributed to the blackbox device. Besides modeling PCHAs, we present a generic construction of PCHAs with rigorous security proofs. We instantiate a concrete construction of PCHA by introducing a practical attribute-based traitor tracing (ABTT) with adaptive security on prime-order pairing groups. The experimental analysis demonstrates that our PCHA and ABTT schemes have modest overheads and superior functionality to the state-of-the-art solutions. In particular, the price of accountability in key generation, hash, and adaption is almost negligible compared to the state-of-the-art solution. Shengmin Xu, Xinyi Huang 0001, Jiaming Yuan, Yingjiu Li, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | ACB-Vote: Efficient, Flexible, and Privacy- Preserving Blockchain-Based Score Voting With Anonymously Convertible BallotsabstractBlockchain has emerged as a decentralized platform for e-voting. Among various blockchain-based voting systems, score voting provides flexible choices and better reflects public opinions. However, existing blockchain-based score voting systems suffer from heavy range proof overheads, and are much inefficient compared with other blockchain-based voting systems. Besides, voter anonymity in these systems is not rigorously addressed. In this paper, we propose an efficient, flexible and privacy-preserving score voting system, named ACB-Vote, from anonymously convertible ballots. ACB-Vote achieves voting anonymity with BBS+ signature and signature of knowledge. Driven by convertibly linkable signatures (CLS), ACB-Vote allows cast ballots to be converted, where the conversion mechanism prevents anonymous voters from multiple voting. Besides, the proposed system avoids heavy range proofs, enables batch ballot verification and facilitates flexible tallying methods. We formally define a security model for ACB-Vote and provide rigorous security proofs. Experiments show that the efficiency of ACB-Vote is competitive compared with the previous score voting systems and is affordable in blockchain environments. Wenyi Xue, Yang Yang 0026, Yingjiu Li, HweeHwa Pang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | CrowdFA: A Privacy-Preserving Mobile Crowdsensing Paradigm via Federated AnalyticsabstractMobile crowdsensing (MCS) systems typically struggle to address the challenge of data aggregation, incentive design, and privacy protection, simultaneously. However, existing solutions usually focus on one or, at most, two of these issues. To this end, this paper presents CROWDFA, a novel paradigm for privacy-preserving MCS through federated analytics (FA), which aims to achieve a well-rounded solution encompassing data aggregation, incentive design, and privacy protection. Specifically, inspired by FA, CRWODFA initiates an MCS computing paradigm that enables data aggregation and incentive design. Participants can perform aggregation operations on their local data, facilitated by CROWDFA, which supports various common data aggregation operations and bidding incentives. To address privacy concerns, CROWDFA relies solely on an efficient cryptographic primitive known as additive secret sharing to simultaneously achieve privacy-preserving data aggregation and privacy-preserving incentive. To instantiate CROWDFA, this paper presents a privacy-preserving data aggregation scheme (PRADA) based on CROWDFA, capable of supporting a range of data aggregation operations. Additionally, a CROWDFA-based privacy-preserving incentive mechanism (PRAED) is designed to ensure truthful and fair incentives for each participant, while maximizing their individual rewards. Theoretical analysis and experimental evaluations demonstrate that CROWDFA protects participants’ data and bid privacy while effectively aggregating sensing data. Notably, CROWDFA outperforms state-of-the-art approaches by achieving up to 22 times faster computation time. Bowen Zhao 0001, Xiaoguo Li, Ximeng Liu, Qingqi Pei, Yingjiu Li, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2023 | LiVoAuth: Liveness Detection in Voiceprint Authentication With Random Challenges and Detection ModesabstractVoiceprint authentication provides great convenience to users in many application scenarios. However, it easily suffers from spoofing attacks including speech synthesis, speech conversion, and speech replay. Liveness detection is an effective way to resist these attacks. But existing methods suffer from many disadvantages, such as extra deployment costs due to precise data collection, environmental disturbance, high computational overhead, and operational complexity. A uniform platform that can offer voiceprint authentication as a service (VAaS) over the cloud is also lacked. Hence, it is imperative to design an economic and effective method for liveness detection in voiceprint authentication. In this article, we propose a novel liveness detection method named LiVoAuth for voiceprint authentication. It applies a randomly generated vector sequence as liveness detection mode (LDM), corresponding to a random challenge code used for authentication. We implement LiVoAuth and conduct a series of user studies to evaluate its performance in terms of accuracy, stability, efficiency, security, and user acceptance. Experimental results demonstrate its advantages compared with cutting-edge methods Rui Zhang 0081, Zheng Yan 0002, Robert H. Deng |
IEEE Trans. Ind. Informatics | 4 |
| 2023 | Comprehensive Survey on Privacy-Preserving Spatial Data Query in Transportation SystemsabstractWith the rapid development of Intelligent Transportation System (ITS), a large number of spatial data are generated in ITS. Although outsourcing spatial data to the cloud server can reduce the high local computation and storage overheads, it will also lead to security and privacy issues. Therefore, it is necessary to have a survey to specifically summarize these advanced privacy-preserving spatial data query schemes. However, the existing surveys considering both location information and keywords of spatial data only summarize the spatial keyword query scheme in plaintext environment, they do not consider the privacy of spatial data. Although there are some surveys on privacy-preserving spatial data query, they only focus on the location information of spatial data without considering descriptive keywords. Therefore, to understand the progress and research trends in the field, we give a comprehensive survey on secure spatial data query in ITS to summarize and analyze the most advanced solutions. Then, we make a comprehensive and detailed comparison of existing solutions in terms of query function, index structure, time complexity, security, etc. Finally, we show some open challenges and potential research directions for privacy-preserving spatial data query. Yinbin Miao, Yutao Yang, Xinghua Li 0001, Kim-Kwang Raymond Choo, Xiangdong Meng, Robert H. Deng |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2023 | Privacy-Preserving Boolean Range Query With Temporal Access Control in Mobile ComputingabstractWith increasingly popular GPS-equipped mobile devices (e.g., smartphones, tablets, laptops), massive spatio-textual data has been outsourced to cloud servers for storage and analysis such as spatial keyword search. However, existing privacy-preserving spatial keyword query schemes only support coarse-grained non-temporal access control in single-user sharing scenarios, which does not scale well in time-related scenes such as message valid period. To solve the above issues, we propose Privacy-preserving Boolean Range Query with Temporal access control in mobile computing (PBRQ-T). Specifically, we first achieve PBRQ with linear search complexity using the adapted Gray code, Bloom filter, and Katz-Sahai-Waters encryption. Then, we provide fine-grained and temporal access control in PBRQ based on the forward/backward derivation function and attribute-based encryption, where PBRQ is executed only when the spatio-textual data is accessible. Finally, an enhanced PBRQ-T (i.e., PBRQ-T+) with faster-than-linear search complexity is proposed by constructing a Quadtree index structure. Our formal security analysis shows that data privacy and index privacy can be guaranteed during the query process. Our extensive experiments using a real-world dataset demonstrate the efficiency and feasibility of our schemes. Qiuyun Tong, Xinghua Li 0001, Yinbin Miao, Ximeng Liu, Jian Weng 0001, Robert H. Deng |
IEEE Trans. Knowl. Data Eng. | 6 |
| 2023 | Verifiable Fuzzy Multi-Keyword Search Over Encrypted Data With Adaptive SecurityabstractTo ensure the security of outsourced data without affecting data availability, one can use Symmetric Searchable Encryption (SSE) to achieve search over encrypted data. Considering that query users may search with misspelled words, the fuzzy search should be supported. However, conventional privacy-preserving fuzzy multi-keyword search schemes are incapable of achieving the result verification and adaptive security. To solve the above challenging issues, in this paper we propose a Verifiable Fuzzy multi-keyword Search scheme with Adaptive security (VFSA). VFSA first employs the locality sensitive hashing to hash the misspelled and correct keywords to the same positions, then designs a twin Bloom filter for each document to store and mask all keywords contained in the document, next constructs an index tree based on the graph-based keyword partition algorithm to achieve adaptive sublinear retrieval, finally combines the Merkle hash tree structure with the adapted multiset accumulator to check the correctness and completeness of search results. Our formal security analysis shows that VFSA is secure under the IND-CKA2 model and achieves query authentication. Our empirical experiments using the real-world dataset demonstrate the practicality of VFSA. Qiuyun Tong, Yinbin Miao, Jian Weng 0001, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Knowl. Data Eng. | 6 |
| 2023 | DistPreserv: Maintaining User Distribution for Privacy-Preserving Location-Based ServicesabstractLocation-Based Services (LBSs) are one of the most frequently used mobile applications in the modern society. Geo-Indistinguishability (Geo-Ind) is a promising privacy protection model for LBSs since it can provide formal security guarantees for location privacy. However, Geo-Ind undermines the statistical location distribution of users on the LBS server because of perturbed locations, thereby disabling the server to provide distribution-based services (e.g., traffic congestion maps). To overcome this issue, we give a privacy definition, called DistPreserv, to enable the LBS server to acquire valid location distributions while providing users with strict location protection. Then we propose a privacy-preserving LBS scheme to benefit both users and the server, in which a location perturbation mechanism is designed to achieve the given definition under the guide of the incentive compatibility, and a retrieval area determination method is presented to ensure query accuracy of users by using the dynamic programming on the two-dimensional map plane. Finally, we theoretically prove that the designed mechanism can achieve the definition of DistPreserv and the property of incentive compatibility. Experimental explorations using a real-world dataset indicate that our proposal prominently improves the availability of users’ location distributions by over 90%, while providing high precision and recall of queries. Yanbing Ren, Xinghua Li 0001, Yinbin Miao, Robert H. Deng, Jian Weng 0001, Siqi Ma 0001, Jianfeng Ma 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2023 | Privacy-Preserving Ranked Spatial Keyword Query in Mobile Cloud-Assisted Fog ComputingabstractWith the increasing popularity of GPS-equipped mobile devices in cloud-assisted fog computing scenarios, massive spatio-textual data is generated and outsourced to cloud servers for storage and analysis. Existing privacy-preserving range query or ranked keyword search schemes does not support a unified index, and are just applicable for the symmetric environment where all users sharing the same secret key. To solve this issue, we propose aPrivacy-preservingRankedSpatial keywordQuery in mobile cloud-assistedFog computing (PRSQ-F). Specifically, we design a novel comparable product encoding strategy that combines both spatial and textual conditions tightly to retrieve the objects in query range and with the highest textual similarity. Then, we use a new conversion protocol and attribute-based encryption to support privacy-preserving retrieval and malicious user traceability in the asymmetric environment where different query users have different keys. Furthermore, we construct an R-tree-based index to achieve faster-than-linear retrieval. Our formal security analysis shows that data security can be guaranteed. Our empirical experiments using a real-world dataset demonstrate the efficiency and feasibility of PRSQ-F. Qiuyun Tong, Yinbin Miao, Hongwei Li 0001, Ximeng Liu, Robert H. Deng |
IEEE Trans. Mob. Comput. | 5 |
| 2023 | CrowdFL: Privacy-Preserving Mobile Crowdsensing System Via Federated LearningabstractAs an emerging sensing data collection paradigm, mobile crowdsensing (MCS) enjoys good scalability and low deployment cost but raises privacy concerns. In this paper, we propose a privacy-preserving MCS system calledCrowdFLby seamlessly integrating federated learning (FL) into MCS. At a high level, in order to protect participants’ privacy and fully explore participants’ computing power, participants inCrowdFLlocally process sensing data via FL paradigm and only upload encrypted training models to the server. To this end, we design a secure aggregation algorithm (SecAgg) through the threshold Paillier cryptosystem to aggregate training models in an encrypted form. Also, to stimulate participation, we present a hybrid incentive mechanism combining the reverse Vickrey auction and posted pricing mechanism, which is proved to be truthful and fail. Results of theoretical analysis and experimental evaluation on a practical MCS scenario (human activity recognition) show thatCrowdFLis effective in protecting participants’ privacy and is efficient in operations. In contrast to existing solutions,CrowdFLis 3× faster in model decryption and improves an order of magnitude in model aggregation. Bowen Zhao 0001, Ximeng Liu, Weineng Chen, Robert H. Deng |
IEEE Trans. Mob. Comput. | 4 |
| 2023 | Owner-free Distributed Symmetric Searchable Encryption Supporting Conjunctive QueriesabstractSymmetric Searchable Encryption (SSE), as an ideal primitive, can ensure data privacy while supporting retrieval over encrypted data. However, existing multi-user SSE schemes require the data owner to share the secret key with all query users or always be online to generate search tokens. While there are some solutions to this problem, they have at least one weakness, such as non-supporting conjunctive query, result decryption assistance of the data owner, and unauthorized access. To solve the above issues, we propose an O wner-free Di stributed S ymmetric searchable encryption supporting C onjunctive query (ODiSC). Specifically, we first evaluate the Learning-Parity-with-Noise weak Pseudorandom Function (LPN-wPRF) in dual-cloud architecture to generate search tokens with the data owner free from sharing key and being online. Then, we provide fine-grained conjunctive query in the distributed architecture using additive secret sharing and symmetric-key hidden vector encryption. Finally, formal security analysis and empirical performance evaluation demonstrate that ODiSC is adaptively simulation-secure and efficient. Qiuyun Tong, Xinghua Li 0001, Yinbin Miao, Yunwei Wang, Ximeng Liu, Robert H. Deng |
ACM Trans. Storage | 6 |
| 2023 | Identifiable, But Not Visible: A Privacy-Preserving Person Reidentification SchemeabstractPerson re-identification (Person Re-ID) is widely regarded as a promising technique to identify a target person through surveillance cameras in the wild. Nevertheless, person Re-ID leads to severe personal image privacy concerns as personal images are stipulated by laws and guidelines as private data. To address these concerns, this article explores the first solution for building a privacy-preserving person Re-ID system. Specifically, this article formulizes privacy-preserving person Re-ID as similarity metrics of encrypted feature vectors because the underlying operation of person Re-ID is to compute the similarity of feature vectors that are extracted from person images by a machine learning model. However, feature vectors are generally denoted by floating-point numbers. To this end, this article exploits a series of new encoding mechanisms and secure batch computing protocols to encrypt floating-point feature vectors and achieve the underlying operation of person Re-ID. Rigorous theoretical analyses demonstrate that this work achieves person Re-ID without compromising any personal image privacy. Furthermore, the proposed secure batch protocols significantly enhance the performance of privacy-preserving person Re-ID while outputting the same precision as the previous method. Bowen Zhao 0001, Yingjiu Li, Ximeng Liu, Xiaoguo Li, HweeHwa Pang, Robert H. Deng |
IEEE Trans. Reliab. | 6 |
| 2023 | CASE-SSE: Context-Aware Semantically Extensible Searchable Symmetric Encryption for Encrypted Cloud DataabstractTraditional searchable symmetric encryption (SSE) schemes rarely support context-aware semantic extension, and then lead to the searched results being incomplete or deviating from the user’s query intention. To address this problem, a new context-aware semantically extensible searchable symmetric encryption based on Word2vec model (CASE-SSE) is proposed to achieve context-aware semantic extension in this article. The proposed scheme utilizes outsourced datasets as corpora to extract all keywords for training the Word2vec model, and the trained results is the ontology knowledge base that can be used to extend the semantics of query keywords directly. Further, to facilitate multi-keyword search using the extended query vector, we use the$k$-means clustering algorithm to classify outsourced datasets. We then construct an AVL-tree index and an inverted index based on the classified results, thereby achieving efficient context-aware semantically extensible SSE. The security analysis indicates it is secure and effective. The experimental results show that our scheme is superior in both efficiency and accuracy. Lanxiang Chen, Yujie Xue, Yi Mu 0001, Lingfang Zeng, Fatemeh Rezaeibagha, Robert H. Deng |
IEEE Trans. Serv. Comput. | 6 |
| 2023 | Catch me if you can: A Secure Bilateral Access Control System With Anonymous CredentialsabstractBilateral access control model, emerging as a novel paradigm in access control, has garnered extensive deployment within the domain of fog computing. This model offers on-demand data services, enabling the efficient identification of sensitive data without resorting to resource-intensive decryption procedures. Nonetheless, prevailing solutions exhibit impracticalities. Specifically, they fall short in supporting adaptive security, while presuming unwavering trustworthiness of the central authority. In this paper, we introduce a pioneering fine-grained and adaptively secure bilateral access control system through enhancements to the matchmaking attribute-based encryption (MABE) framework. We give a formalized definition of MABE, incorporating desirable security features such as blindness and unlinkability, aimed at capturing potential misconduct by the central authority. We propose a generic construction of MABE, drawing upon attribute-based encryption (ABE) and anonymous credential schemes (ACS), with provable security via formal security reduction in the adaptive model. We present an efficient instantiation of the MABE framework by introducing a practical ACS solution, wherein a cryptographic accumulator is employed to enhance performance. Experimental simulations substantiate that our solution not only has superior functionalities but also demonstrates performance on par with state-of-the-art solutions. Jinhua Ma, Shengmin Xu, Jianting Ning, Xinyi Huang 0001, Robert H. Deng |
IEEE Trans. Serv. Comput. | 5 |
| 2023 | Defending Against Membership Inference Attack by Shielding Membership SignalsabstractMember Inference Attack (MIA) is a key measure for evaluating privacy leakage in Machine Learning (ML) models, aiming to distinguish private members from non-members by training the attack model. In addition to the traditional MIA, the recently proposed Generative Adversarial Network (GAN)-based MIA can help the adversary know the distribution of the victim's private dataset, thereby significantly improving attack accuracy. For traditional attacks and this new type of attack, previous defense schemes cannot handle the trade-off between privacy and utility well. To this end, we propose a defense solution using multi-model ensemble framework. Specifically, we train multiple submodels to hide membership signals and resist MIA, achieving reduced privacy leakage while guaranteeing the effectiveness of the target model. Our security analysis shows that our scheme can provide privacy protection while preserving model utility. Experimental results on widely used datasets show that our scheme can effectively resist MIAs with negligible utility loss. Yinbin Miao, Yueming Yu, Xinghua Li 0001, Yu Guo 0003, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Serv. Comput. | 7 |
| 2023 | Ranked Keyword Search Over Encrypted Cloud Data Through Machine Learning MethodabstractRanked keyword search over encrypted data has been extensively studied in cloud computing as it enables data users to find the most relevant results quickly. However, existing ranked multi-keyword search solutions cannot achieve efficient ciphertext search and dynamic updates with forward security simultaneously. To solve the above problems, we first present a basic Machine Learning-based Ranked Keyword Search (ML-RKS) scheme in the static setting by using the k-means clustering algorithm and a balanced binary tree. ML-RKS reduces the search complexity without sacrificing the search accuracy, but is still vulnerable to forward security threats when applied in the dynamic setting. Then, we propose an Enhanced ML-RKS (called ML-RKS$^{+}$) scheme by introducing a permutation matrix. ML-RKS$^{+}$prevents cloud servers from making search queries over newly added files via previous tokens, thereby achieving forward security. The security analysis proves that our schemes protect the privacy of indexes, query tokens and keywords. Empirical experiments using the real-world dataset demonstrate that our schemes are efficient and feasible in practical applications. Yinbin Miao, Xiaohua Jia, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Serv. Comput. | 6 |
| 2023 | Threshold Attribute-Based Credentials With Redactable SignatureabstractThreshold attribute-based credentials are suitable for decentralized systems such as blockchains as such systems generally assume that authenticity, confidentiality, and availability can still be guaranteed in the presence of a threshold number of dishonest or faulty nodes. Coconut (NDSS’19) was the first selective disclosure attribute-based credentials scheme supporting threshold issuance. However, it does not support threshold tracing of user identities and threshold revocation of user credentials, which is desired for internal governance such as identity management, data auditing, and accountability. The communication and computation complexities of Coconut for verifying credentials are linear in the number of each user's attributes and thus costly. Addressing these issues, we propose a novel efficient threshold attribute-based anonymous credential scheme. While retaining all the features of Coconut, our scheme supports threshold tracing of user identities and threshold revocation of user credentials, and it significantly reduces the computational and communication complexities of credential verification. In addition, we prove that our scheme enjoys strong security features, including anonymity, blindness, traceability, and non-frameability. Huamin Feng, Yang Yang 0026, Yingjiu Li, HweeHwa Pang, Robert H. Deng |
IEEE Trans. Serv. Comput. | 7 |
| 2022 | Compressed Federated Learning Based on Adaptive Local Differential PrivacyabstractFederated learning (FL) was once considered secure for keeping clients’ raw data locally without relaying on a central server. However, the transmitted model weights or gradients still reveal private information, which can be exploited to launch various inference attacks. Moreover, FL based on deep neural networks is prone to the curse of dimensionality. In this paper, we propose a compressed and privacy-preserving FL scheme in DNN architecture by using Compressive sensing and Adaptive local differential privacy (called as CAFL). Specifically, we first compress the local models by using Compressive Sensing (CS), then adaptively perturb the remaining weights according to their different centers of variation ranges in different layers and their own offsets from corresponding range centers by using Local Differential Privacy (LDP), finally reconstruct the global model almost perfectly by using the reconstruction algorithm of CS. Formal security analysis shows that our scheme achieves ϵ-LDP security and introduces zero bias to estimating average weights. Extensive experiments using MINIST and Fashion-MINIST datasets demonstrate that our scheme with minimum compression ratio 0.05 can reduce the number of parameters by 95%, and with a lower privacy budget ϵ = 1 can improve the accuracy by 80% on MINIST and 12.7% on Fashion-MINIST compared with state-of-the-art schemes. Yinbin Miao, Rongpeng Xie, Xinghua Li 0001, Ximeng Liu, Zhuo Ma 0001, Robert H. Deng |
ACSAC | 6 |
| 2022 | Lightweight Privacy-Preserving Spatial Keyword Query over Encrypted Cloud DataabstractWith the rapid development of geographic location technology and the explosive growth of data, a large amount of spatio-textual data is outsourced to the cloud server to reduce the local high storage and computing burdens, but at the same time causes security issues such as data privacy leakage. Thus, extensive privacy-preserving spatial keyword query schemes have been proposed. Most of the existing schemes use Asymmetric Scalar-Product-Preserving Encryption (ASPE) for encryption, but ASPE has proven to be insecure. And the existing spatial range query schemes require users to provide more information about the query range and generate a large amount of ciphertext, which causes high storage and computational burdens. To solve these issues, in this paper we introduce some random numbers and a random permutation to enhance the security of ASPE scheme, and then propose a novel privacy-preserving Spatial Keyword Query (SKQ) scheme based on the enhanced ASPE and Geohash algorithm. In addition, we design a more Lightweight Spatial Keyword Query (LSKQ) scheme by using a unified index for spatial range and multiple keywords, which not only greatly decreases SKQ’s storage and computational costs but also requires users to provide little information about query region. Finally, formal security analysis proves that our schemes have Indistinguishability under Chosen Plaintext Attack (IND-CPA), and extensive experiments demonstrate that our enhanced scheme is efficient and practical. Yutao Yang, Yinbin Miao, Kim-Kwang Raymond Choo, Robert H. Deng |
ICDCS | 4 |
| 2022 | M-EDESE: Multi-Domain, Easily Deployable, and Efficiently Searchable Encryption
Jiaming Yuan, Yingjiu Li, Jianting Ning, Robert H. Deng |
ISPEC | 4 |
| 2022 | An Efficient and Secure Scheme of Verifiable Computation for Intel SGXabstractCloud computing offers resource-constrained users big-volume data storage and energy-consuming complicated computation. However, owing to the lack of full trust in the cloud, the cloud users prefer privacy-preserving data computation with correctness verification. However, cryptography-based schemes introduce high computational costs to both the cloud and its users for verifiable computation with privacy preservation, which makes it difficult to support complicated computations in practice. Intel Software Guard Extensions (SGX) as a trusted execution environment is widely researched in various fields, and is regarded as a promising way to achieve efficient outsourced data computation with privacy preservation over the cloud. But we find two types of threats towards the computation with SGX: Disarranging Data-Related Code threat and Output Tampering and Misrouting threat. In this paper, we depict these threats using formal methods and propose an efficient and secure scheme to resist the threats and realize verifiable computation for Intel SGX. We prove the security and show the efficiency and correctness of our proposed scheme through theoretic analysis and extensive experiments. Furthermore, we compare our scheme with some cryptography-based schemes to show its high efficiency. Wenxiu Ding, Zheng Yan 0002, Robert H. Deng, Zhiguo Wan |
TrustCom | 4 |
| 2022 | Policy-Based Editing-Enabled Signatures: Authenticating Fine-Grained and Restricted Data ModificationabstractAbstract Data owners often encrypt their bulk data and upload it to cloud in order to save storage while protecting privacy of their data at the same time. A data owner can allow a third-party entity to decrypt and access her data. However, if that entity wants to modify the data and publish the same in an authenticated way, she has to ask the owner for a signature on the modified data. This incurs substantial communication overhead if the data is modified often. In this work, we introduce the notion of policy-based editing-enabled signatures, where the data owner specifies a policy for her data such that only an entity satisfying this policy can decrypt the data. Moreover, the entity is permitted to produce a valid signature for the modified data (on behalf of the owner) without interacting with the owner every time the data is modified. On the other hand, a policy-based editing-enabled signature (PB-EES) scheme allows the data owner to choose any set of modification operations applicable to her data and still restricts a (possibly untrusted) entity to authenticate the data modified using operations from that set only. We provide two PB-EES constructions, a generic construction and a concrete instantiation. We formalize the security model for PB-EESs and analyze the security of our constructions. Finally, we evaluate the performance of the concrete PB-EES instantiation. Binanda Sengupta, Yingjiu Li, Yangguang Tian, Robert H. Deng, Zheng Yang 0001 |
Comput. J. | 4 |
| 2022 | Secure 5G Positioning With Truth Discovery, Attack Detection, and TracingabstractThe fifth-generation (5G) cellular network is expected to provide submeter positioning accuracy without draining the battery of user equipment (UE). As a solution, ultradense network (UDN) deployment and network-based positioning were proposed. However, the openness of UDN and the vulnerability of network devices [e.g., access nodes (ANs)] make it easy for attackers to poison such a positioning system. However, no existing work explores how to overcome this issue. This article concentrates on jamming and collusion attacks in the network-based positioning system. Specifically, we design a novel scheme that contains three functional modules to erase the influence of these attacks. A truth discovery module applies a clustering-based method aiming to generate the most approximate position value and find out suspicious signals. Based on neural network models, we further develop an attack detection module and an attack tracing module to perceive attacked UE and locate malicious or attacked ANs. Through simulation, we conduct extensive experiments to illustrate the effectiveness of our scheme. The result shows high detection and tracing accuracy with very simple neural network models, which also implies the potential of our proposed scheme in practical deployment. Shushu Liu, Zheng Yan 0002, Robert H. Deng |
IEEE Internet Things J. | 4 |
| 2022 | Time-Controlled Hierarchical Multikeyword Search Over Encrypted Data in Cloud-Assisted IoTabstractInternet of Things (IoT) devices and systems are becoming increasingly commonplace, and as such systems scale up, so do the computational and storage requirements. Hence, one recent trend is to outsource data from IoT devices to remote systems. To facilitate both ciphertext retrieval and data confidentiality in the outsourced data, a number of searchable encryption (SE) approaches have been proposed in the literature. However, due to limited keyword space, a number of SE schemes are vulnerable to keyword guessing attacks (KGAs). In addition, existing SE approaches generally do not consider the hierarchical structure in which users at different levels require varying access privileges. Furthermore, existing SE schemes seldom provide time-controlled access control. Therefore, in this article, we propose a time-controlled hierarchical multikeyword search by using a double-server architecture to mitigate KGA. In our approach, we also build a public key tree to support different access permissions for hierarchical users. Formal security analysis shows that our scheme is secure, and extensive experiments demonstrate that our scheme is practical. Yinbin Miao, Kim-Kwang Raymond Choo, Hongwei Li 0001, Ximeng Liu, Xiangdong Meng, Robert H. Deng |
IEEE Internet Things J. | 7 |
| 2022 | Privacy-Preserving Threshold-Based Image Retrieval in Cloud-Assisted Internet of ThingsabstractEncrypted image retrieval is a promising technique for achieving data confidentiality and searchability the in cloud-assisted Internet of Things (IoT) environment. However, most of the existing top-$k$ranked image retrieval solutions have low retrieval efficiency and may leak the values and orders of similarity scores to the cloud server. Hence, if a malicious server learns user background information through some improper means, then the malicious server can potentially infer user preferences and guess the most similar image content according to similarity scores. To solve the above challenges, we propose a privacy-preserving threshold-based image retrieval scheme using the convolutional neural network (CNN) model and a secure$k$-nearest neighbor (kNN) algorithm, which improves the retrieval efficiency and prevents the cloud server from learning the values and orders of similarity scores. Formal security analysis shows that our proposed scheme can resist both ciphertext-only attack (COA) and chosen-plaintext attack (CPA), and extensive experiments demonstrate that our proposed scheme is efficient and feasible for real-world data sets. Yinbin Miao, Jian Weng 0001, Kim-Kwang Raymond Choo, Ximeng Liu, Robert H. Deng |
IEEE Internet Things J. | 6 |
| 2022 | Structured encryption for knowledge graphs
Yujie Xue, Lanxiang Chen, Yi Mu 0001, Lingfang Zeng, Fatemeh Rezaeibagha, Robert H. Deng |
Inf. Sci. | 6 |
| 2022 | Threshold Multi-Keyword Search for Cloud-Based Group Data SharingabstractSearchable Encryption (SE) is a popular cryptographic primitive for building ciphertexts retrieval systems with far-reaching applications. However, existing SE schemes generally do not support threshold access control (i.e., data users must collaboratively issue search and decryption operations over encrypted cloud data) in a group-oriented cloud data sharing setting, which is increasingly receiving much attention in the research community. Thus, in this article, we first propose a Threshold Multi-keyword Search (TMS) scheme for cloud-based group data sharing (referred to as basic TMS scheme) by utilizing Shamir’s secret sharing technique, to achieve threshold multi-keyword search, threshold decryption, and short record ciphertext size. Then, we extend this basic TMS to realize threshold result verification and threshold traceability (referred to as enhanced TMS). Furthermore, the enhanced TMS is extended to support public result verification and dynamic operations with the public verifier and improved hash tables, respectively. Our formal security analysis proves that both basic TMS and enhanced TMS are semi-adaptively secure and can resist Chosen-Keyword Attack (CKA). Our theoretical evaluation and empirical experiments demonstrate the potential utility of both schemes. Yinbin Miao, Robert H. Deng, Kim-Kwang Raymond Choo, Ximeng Liu, Hongwei Li 0001 |
IEEE Trans. Cloud Comput. | 2 |
| 2022 | Verifiable Searchable Encryption Framework Against Insider Keyword-Guessing Attack in Cloud StorageabstractSearchable encryption (SE) allows cloud tenants to retrieve encrypted data while preserving data confidentiality securely. Many SE solutions have been designed to improve efficiency and security, but most of them are still susceptible to insider Keyword-Guessing Attacks (KGA), which implies that the internal attackers can guess the candidate keywords successfully in an off-line manner. Also in existing SE solutions, a semi-honest-but-curious cloud server may deliver incorrect search results by performing only a fraction of retrieval operations honestly (e.g., to save storage space). To address these two challenging issues, we first construct the basic Verifiable SE Framework (VSEF), which can withstand the inside KGA and achieve verifiable searchability. Based on the basic VSEF, we then present the enhanced VSEF to support multi-keyword search, multi-key encryption and dynamic updates (e.g., data modification, data insertion, and data deletion) at the same time, which highlights the importance of practicability and scalability of SE in real-world application scenarios. We conduct extensive experiments using the Enron email dataset to demonstrate that the enhanced VSEF achieves high efficiency while resisting to the inside KGA and supporting the verifiability of search results. Yinbin Miao, Qiuyun Tong, Robert H. Deng, Kim-Kwang Raymond Choo, Ximeng Liu, Hongwei Li 0001 |
IEEE Trans. Cloud Comput. | 3 |
| 2022 | VPSL: Verifiable Privacy-Preserving Data Search for Cloud-Assisted Internet of ThingsabstractCloud-assisted Internet of Things (IoT) is increasingly prevalent used in various fields, such as the healthcare system. While in such a scenario, sensitive data (e.g., personal electronic medical records) can be easily revealed, which incurs potential security challenges. Thus, Symmetric Searchable Encryption (SSE) has been extensively studied due to its capability of supporting efficient search on encrypted data. However, most SSE schemes require the data owner to share the complete key with query users and take malicious cloud servers out of consideration. Seeking to address these limitations, in this article we propose a Verifiable Privacy-preserving data Search scheme with Limited key-disclosure (VPSL) for cloud-assisted Internet of Things. VPSL first designs a trapdoor generation protocol for obtaining a trapdoor with disclosing limited key information and without revealing plaintext query points to others. Then, VPSL provides an efficient result verification and search processing by employing the Merkle hash tree structure and k-means clustering technique, respectively. VPSL is secure against the level-2 attack. Finally, an enhanced VPSL (called VPSL+) resisting the level-3 attack is constructed by introducing the random splitting technique. Empirical experiments demonstrate the accuracy and efficiency of VPSL or VPSL+ using real-world datasets. Qiuyun Tong, Yinbin Miao, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng, Hongwei Li 0001 |
IEEE Trans. Cloud Comput. | 5 |
| 2022 | Lightweight and Expressive Fine-Grained Access Control for Healthcare Internet-of-ThingsabstractHealthcare Internet-of-Things (IoT) is an emerging paradigm that enables embedded devices to monitor patients vital signals and allows these data to be aggregated and outsourced to the cloud. The cloud enables authorized users to store and share data to enjoy on-demand services. Nevertheless, it also causes many security concerns because of the untrusted network environment, dishonest cloud service providers and resource-limited devices. To preserve patients’ privacy, existing solutions usually apply cryptographic tools to offer access controls. However, fine-grained access control among authorized users is still a challenge, especially for lightweight and resource-limited end-devices. In this paper, we propose a novel healthcare IoT system fusing advantages of attribute-based encryption, cloud and edge computing, which provides an efficient, flexible, secure fine-grained access control mechanism with data verification in healthcare IoT network without any secure channel and enables data users to enjoy the lightweight decryption. We also define the formal security models and present security proofs for our proposed scheme. The extensive comparison and experimental simulation demonstrate that our scheme has better performance than existing solutions. Shengmin Xu, Yingjiu Li, Robert H. Deng, Yinghui Zhang 0002, Xiangyang Luo 0001, Ximeng Liu |
IEEE Trans. Cloud Comput. | 3 |
| 2022 | Privacy-Preserving Medical Treatment System Through Nondeterministic Finite AutomataabstractIn this article, we propose a privacy-preserving medical treatment system using nondeterministic finite automata (NFA), hereafter referred to as P-Med, designed for remote medical environment. P-Med makes use of the nondeterministic transition characteristic of NFA to flexibly represent medical model, which includes illness states, treatment methods and state transitions caused by exerting different treatment methods. A medical model is encrypted and outsourced to cloud to deliver telemedicine service. Using P-Med, patient-centric diagnosis and treatment can be made on-the-fly while protecting the confidentiality of patient’s illness states and treatment recommendation results. Moreover, a new privacy-preserving NFA evaluation method is given in P-Med to get a confidential match result for the evaluation of an encrypted NFA and an encrypted data set, which avoids the cumbersome inner state transition determination. We demonstrate that P-Med realizes treatment procedure recommendation without privacy leakage to unauthorized parties. We conduct extensive experiments and analysis to evaluate the efficiency. Yang Yang 0026, Robert H. Deng, Ximeng Liu, Yongdong Wu, Jian Weng 0001, Xianghan Zheng, Chunming Rong |
IEEE Trans. Cloud Comput. | 2 |
| 2022 | Fine-Grained and Controllably Editable Data Sharing With Accountability in Cloud StorageabstractWith the increasing cloud storage service, users can enjoy non-interactive data sharing. Nonetheless, the data owner cannot timely update the shared data all the while. To ensure the timeliness and the authoritative source of the data, some users should be allowed to update the data on behalf of an authoritative data owner without changing data source. However, this allows harmful information to be injected into the data unnoticeably. How to efficiently realize editable cloud-based data sharing supporting malicious user tracing has not been fully explored. To address the problem, we propose a fine-grained and controllably editable cloud-based data sharing scheme with malicious user accountability. The data owner only needs to sign the shared data before uploading it and can specify a fine-grained access control policy about who can update the data and which portions of the data can be updated. The authorized users non-interactively convert signatures of original data into new ones for the updated data, which are indistinguishable from the original signatures. The proposed scheme also supports malicious user accountability in the sense that malicious users who post harmful information can be traced. We demonstrate the security and practicality of our scheme via formal security analysis and extensive experiments. Huiying Hou, Jianting Ning, Yunlei Zhao, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | Authenticated Data Redaction With Accountability and TransparencyabstractA common practice in data redaction is removing sensitive information prior to data publication or release. In data-driven applications, one must be convinced that the redacted data is still trustworthy. Meanwhile, the data redactor must be held accountable for (malicious) redaction, which could change/hide the meaning of the original data. Motivated by these concerns, we present a novel solution for authenticated data redaction based on a new Redactable Signature Scheme with Implicit Accountability ($\mathsf {RSS}$RSS-$\mathsf {IA}$IA). In the event of a dispute, not only the original data signer but also the redactor can generate an evidence tag to unequivocally identify the party who produced the data/signature pair. Without the evidence tag, the redaction operation is transparent. Furthermore, the redactor can independently prove the trustworthiness of the redacted data, without any interaction with the original data signer. Our design is built on a new approach which adds accountability to any transparent redactable signature schemes. We show that the proposed design satisfies all the security goals with affordable cost. As an extension, we show how to realize accountable, transparent and authenticated data redaction in the multi-redactor setting. Jinhua Ma, Xinyi Huang 0001, Yi Mu 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | Orchestration or Automation: Authentication Flaw Detection in Android AppsabstractPasswords are pervasively used to authenticate users’ identities in mobile apps. To secure passwords against attacks, protection is applied to the password authentication protocol (PAP). The implementation of the protection scheme becomes an important factor in protecting PAP against attacks. We focus on two basic protection in Android, i.e., SSL/TLS-based PAP and timestamp-based PAP. Previously, we proposed an automated tool,GLACIATE, to detect authentication flaws. We were curious whether orchestration (i.e., involving manual-effort) works better than automation. To answer this question, we propose an orchestrated approach,AuthExploitand compare its effectivenessGLACIATE. We study requirements for correct implementation of PAP and then applyGLACIATEto identify protection enhancements automatically. Through dependency analysis,GLACIATEmatches the implementations against the abstracted flaws to recognise defective apps. To evaluateAuthExploit, we collected 1,200 Android apps from Google Play. We comparedAuthExploitwith the automation tool,GLACIATE, and two other orchestration tools,${\sf MalloDroid}$and${\sf SMV-Hunter}$. The results demonstrated that orchestration tools detect flaws more precisely although the F1 score ofGLACIATEis higher thanAuthExploit. Further analysis of the results reveals that highly popular apps and e-commerce apps are not more secure than other apps. Siqi Ma 0001, Juanru Li, Surya Nepal, Diethelm Ostry, David Lo 0001, Sanjay K. Jha, Robert H. Deng, Elisa Bertino |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2022 | Update Recovery Attacks on Encrypted Database Within Two Updates Using Range Queries LeakageabstractRecently, reconstruction attacks on static encrypted database supporting range queries have been proposed. However, attacks on encrypted database within two updates in the similar setting have not been studied extensively. As far as we know, the only work is theupdate recovery attackpresented by Grubbset al.(CCS 2018). Following their seminal work, we present new update recovery attacks fordensedataset (i.e., at least one record corresponding to each value in the range), which enable a deeper understanding of the impact caused by leakages due to updates on dynamic encrypted database. Our first attack aims at recovering the value of a newly added record in the case of one database update. We further demonstrate that the attack can fully reconstruct thedatabase countsif the updated value is either the minimum or maximum in the range. We then consider a setting where two distinct records are added separately, which leads to our second attack. We next extend our attacks to the setting where the update operation is deletion. To the best of our knowledge, update recovery attack on database supporting deletion has not been considered before. We demonstrate practicality of our attack via extensive simulations using real dataset. Jianting Ning, Geong Sen Poh, Xinyi Huang 0001, Robert H. Deng, Shuwei Cao 0002, Ee-Chien Chang |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | Sanitizable Access Control System for Secure Cloud Storage Against Malicious Data PublishersabstractCloud computing is considered as one of the most prominent paradigms in the information technology industry, since it can significantly reduce the costs of hardware and software resources in computing infrastructure. This convenience has enabled corporations to efficiently use the cloud storage as a mechanism to share data among their employees. At the first sight, by merely storing the shared data as plaintext in the cloud storage and protect them using an appropriate access control would be a nice solution. This is assuming that the cloud is fully trusted for not leaking any information, which is impractical as the cloud is owned by a third party. Therefore, encryption is mandatory, and the shared data will need to be stored as a ciphertext using an appropriate access control. However, in practice, some of these employees may be malicious and may want to deviate from the required sharing policy. The existing protection in the literature has been explored to allow only legitimate recipients to decrypt the contents stored in the cloud storage, but unfortunately,no existing workdeals with issues raised due to the presence of malicious data publishers. Malicious data publishers construct data following the given policy, but the ciphertexts can actually be decrypted by unauthorized users without valid keys, or simply, anyone else who is unauthorized. The impact of the involvement of malicious data publishers is detrimental, as it may damage intellectual properties from the corporations. Therefore, it remains an elusive research problem on how to enable a sound approach to resolve the issue when malicious data publishers are involved in the system, which is a very practical question. In this work, we presenta new direction of researchthat can cope with the presence of malicious data publishers. We resolve the aforementioned problem by proposing the notion of Sanitizable Access Control System (SACS), which is designed for a secure cloud storage that can also resist against malicious data publishers. We define the threat model and its formal security model, as well as its design and scheme which is based on$q$q-Parallel Bilinear Diffie-Hellman Exponent Assumption. We provide the security proof of our construction as well as its performance analysis. We believe that this work has opened a new area of research which has never been explored before, even though it is very practical. Therefore, this work will enhance the adoption of secure cloud storage in practice. Willy Susilo, Peng Jiang 0007, Jianchang Lai, Fuchun Guo, Guomin Yang, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2022 | SDAC: A Slow-Aging Solution for Android Malware Detection Using Semantic Distance Based API ClusteringabstractA novel slow-aging solution named SDAC is proposed to address the model aging problem in Android malware detection, which is due to the lack of adapting to the changes in Android specifications during malware detection. Different from periodic retraining of detection models in existing solutions, SDAC evolves effectively by evaluating new APIs’ contributions to malware detection according to existing API’s contributions. In SDAC, the contributions of APIs are evaluated by their contexts in the API call sequences extracted from Android apps. A neural network is applied on the sequences to assign APIs to vectors, among which the differences of API vectors are regarded as the semantic distances. SDAC then clusters all APIs based on their semantic distances to create a feature set in the training phase, and extends the feature set to include all new APIs in the detecting phase. Without being trained by any new set of real-labelled apps, SDAC can adapt to the changes in Android specifications by simply identifying new APIs appearing in the detection phase. In extensive experiments with datasets dated from 2011 to 2016, SDAC achieves a significantly higher accuracy and a significantly slower aging speed compared with MaMaDroid, a state-of-the-art Android malware detection solution which maintains resilience to API changes. Jiayun Xu, Yingjiu Li, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | Privacy-Preserving Federated Deep Learning With Irregular UsersabstractFederated deep learning has been widely used in various fields. To protect data privacy, many privacy-preservingapproaches have been designed and implemented in various scenarios. However, existing works rarely consider a fundamental issue that the data shared by certain users (calledirregular users) may be of low quality. Obviously, in a federated training process, data shared by manyirregular usersmay impair the training accuracy, or worse, lead to the uselessness of the final model. In this article, we propose PPFDL, a Privacy-Preserving Federated Deep Learning framework withirregular users. In specific, we design a novel solution to reduce the negative impact ofirregular userson the training accuracy, which guarantees that the training results are mainly calculated from the contribution of high-quality data. Meanwhile, we exploit Yao's garbled circuits and additively homomorphic cryptosystems to ensure the confidentiality of all user-related information. Moreover, PPFDL is also robust to users dropping out during the whole implementation. This means that each user can be offline at any subprocess of training, as long as the remaining online users can still complete the training task. Extensive experiments demonstrate the superior performance of PPFDL in terms of training accuracy, computation, and communication overheads. Guowen Xu, Hongwei Li 0001, Shengmin Xu, Jianting Ning, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2022 | Match in My Way: Fine-Grained Bilateral Access Control for Secure Cloud-Fog ComputingabstractCloud-fog computing is a novel paradigm to extend the functionality of cloud computing to provide a variety of on-demand data services via the edge network. Many cryptographic tools have been introduced to preserve data confidentiality against the untrustworthy network and cloud servers. However, how to efficiently identify and retrieve useful data from a large number of ciphertexts without a costly decryption mechanism remains a challenging problem. In this article, we introduce a cloud-fog-device data sharing system (CFDS) with data confidentiality and data source identification simultaneously based on a new cryptographic primitive named matchmaking attribute-based encryption (MABE) by extending matchmaking encryption in CRYPTO’19. Our solution offers a secure fine-grained bilateral access control that includes (1) fine-grained sender access control, (2) fine-grained receiver access control, (3) sender privacy, and (4) performance optimization via outsourcing data source identification to fog nodes. We give the formal definition and security models of MABE, and present a concrete construction with formal security proofs. We also offer a detailed security analysis of our proposed CFDS against real-world security threats. The extensive comparison and experimental simulation demonstrate that, by immigrating heavy workload to fog nodes, our scheme has better functionalities and performances than the most related solutions. Shengmin Xu, Jianting Ning, Yingjiu Li, Yinghui Zhang 0002, Guowen Xu, Xinyi Huang 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2022 | LinkBreaker: Breaking the Backdoor-Trigger Link in DNNs via Neurons Consistency CheckabstractBackdoor attacks cause model misbehaving by first implanting backdoors in deep neural networks (DNNs) during training and then activating the backdoor via samples with triggers during inference. The compromised models could pose serious security risks to artificial intelligence systems, such as misidentifying ‘stop’ traffic sign into ‘80km/h’. In this paper, we investigate the connection characteristic between the backdoor and the trigger in DNNs and observe the fact that the backdoor is implanted via establishing a link between a cluster of neurons, representing the backdoor, and the triggers. Based on this observation, we design LinkBreaker, a new generic scheme for defending against backdoor attacks. In particular, LinkBreaker deploys a neuron consistency check mechanism for identifying compromised neuron set related to the trigger. Then, the LinkBreaker regulates the model to make predictions based on benign neuron set only and thus breaks the link between the backdoor and the trigger. Compared to previous defenses, LinkBreaker offers a more general backdoor countermeasure that is not only effective against input-agnostic backdoors but also source-specific backdoors, which the later can not be defeated by majority of state-of-the-arts. Besides, LinkBreaker is robust against adversarial examples, which, to a large extent, provides a holistic defense against adversarial example attacks on DNNs, while almost all current backdoor defenses do not have such consideration and capability. Extensive experimental evaluations on real datasets demonstrate that LinkBreaker is with high efficacy of suppressing trigger inputs while incurring no noticeable accuracy deterioration on benign inputs. Zhenzhu Chen, Shang Wang 0004, Anmin Fu, Yansong Gao 0001, Shui Yu 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2022 | ShieldFL: Mitigating Model Poisoning Attacks in Privacy-Preserving Federated LearningabstractPrivacy-Preserving Federated Learning (PPFL) is an emerging secure distributed learning paradigm that aggregates user-trained local gradients into a federated model through a cryptographic protocol. Unfortunately, PPFL is vulnerable to model poisoning attacks launched by a Byzantine adversary, who crafts malicious local gradients to harm the accuracy of the federated model. To resist model poisoning attacks, existing defense strategies focus on identifying suspicious local gradients over plaintexts. However, the Byzantine adversary submits encrypted poisonous gradients to circumvent existing defense strategies in PPFL, resulting in encrypted model poisoning. To address the issue, in this paper we design a privacy-preserving defense strategy using two-trapdoor homomorphic encryption (referred to as ShieldFL), which can resist encrypted model poisoning without compromising privacy in PPFL. Specially, we first present the secure cosine similarity method aiming to measure the distance between two encrypted gradients. Then, we propose the Byzantine-tolerance aggregation using cosine similarity, which can achieve robustness for both Independently Identically Distribution (IID) and non-IID data. Extensive evaluations on three benchmark datasets (i.e.,MNIST, KDDCup99, and Amazon) show that ShieldFL outperforms existing defense strategies. Especially, ShieldFL can achieve 30%-80% accuracy improvement to defend two state-of-the-art model poisoning attacks in both non-IID and IID settings. Zhuoran Ma 0002, Jianfeng Ma 0001, Yinbin Miao, Yingjiu Li, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2022 | Redactable Blockchain in Decentralized SettingabstractImmutability has been widely accepted as a fundamental property protecting the security of blockchain technology. However, this property impedes the development of blockchain because of the abuse of blockchain storage and legal obligations. To mitigate this issue, a novel construction of blockchain, calledredactable blockchain, was introduced. It enables a central authority to issue the rewriting privilege to a particular party who can rewrite a registered object, e.g., a block or a transaction, in a controlled way. Unfortunately, the central authority must be fully trusted and is an obvious target suffering from various attacks. In this paper, we introduce a redactable blockchain controlled at a fine-grained level in a decentralized setting. In our solution, the rewriting privilege is issued by multiple authorities for reducing the vulnerability of the centralized setting. To formalize our solution, we introduce a novel cryptographic notion, calleddecentralized policy-based chameleon hash(DPCH), with the formal definition and security model. By applying several simple cryptographic tools, such as chameleon hash, digital signature, and multi-authority attribute-based encryption, we present the generic construction of DPCH along with rigorous security proofs. By applying RSA-based chameleon hash and BLS short signature, we give a practical instantiation of DPCH with performance evaluation. The comprehensive evaluation shows that our solution has superior performance than the state-of-the-art solution. Jinhua Ma, Shengmin Xu, Jianting Ning, Xinyi Huang 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2022 | Privacy-Preserving Byzantine-Robust Federated Learning via Blockchain SystemsabstractFederated learning enables clients to train a machine learning model jointly without sharing their local data. However, due to the centrality of federated learning framework and the untrustworthiness of clients, traditional federated learning solutions are vulnerable to poisoning attacks from malicious clients and servers. In this paper, we aim to mitigate the impact of the central server and malicious clients by designing a Privacy-preserving Byzantine-robust Federated Learning (PBFL) scheme based on blockchain. Specifically, we use cosine similarity to judge the malicious gradients uploaded by malicious clients. Then, we adopt fully homomorphic encryption to provide secure aggregation. Finally, we use blockchain system to facilitate transparent processes and implementation of regulations. Our formal analysis proves that our scheme achieves convergence and provides privacy protection. Our extensive experiments on different datasets demonstrate that our scheme is robust and efficient. Even if the root dataset is small, our scheme can achieve the same efficiency as FedSGD. Yinbin Miao, Hongwei Li 0001, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2022 | Towards Privacy-Preserving Spatial Distribution Crowdsensing: A Game Theoretic ApproachabstractAcquiring the spatial distribution of users in mobile crowdsensing (MCS) brings many benefits to users (e.g.,avoiding crowded areas during the COVID-19 pandemic). Although the leakage of users’ location privacy has received a lot of research attention, existing works still ignore the rationality of users, resulting that users may not obtain satisfactory spatial distribution even if they provide true location information. To solve the problem, we employ game theory with incomplete information to model the interactions among users and seek an equilibrium state through learning approaches of the game. Specifically, we first model the service as a game in the satisfaction form and define the equilibrium for this service. Then, we design aLEFSalgorithm for the privacy strategy learning of users when their satisfaction expectations are fixed, and further designLSREthat allows users to have dynamic satisfaction expectations. We theoretically analyze the convergence conditions and characteristics of the proposed algorithms, along with the privacy protection level obtained by our solution. We conduct extensive experiments to show the superiority and various performances of our proposal, which illustrates that our proposal can get more than 85% advantage in terms of the sensing distribution availability compared to the traditional spatial cloaking based solutions. Yanbing Ren, Xinghua Li 0001, Yinbin Miao, Bin Luo 0006, Jian Weng 0001, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2022 | A Practical Fog-Based Privacy-Preserving Online Car-Hailing Service SystemabstractAiming for minimizing passengers waiting time and vehicles vacancy rate, online car-hailing service systems with fog computing has been deployed in various scenarios. In this paper, we focus on addressing the security and privacy issues in such a promising system by customizing a new cryptographic primitive to provide the following security guarantees: (1) private, fine-grained and bilateral order matching between passengers and drivers; (2) authenticity verification of passengers orders in the form of ciphertext, and (3) temporal assurance of passengers’ ciphertext orders. To the best of our knowledge, no previous system has been designed to meet all three requirements. Existing cryptographic primitives (including forward/puncturable encryption (FE/PE) and attribute based matchmaking encryption (AB-ME)) may be leveraged to partially address some of challenges, but there lacks a comprehensive solution. Moreover, the integration of existing works is hampered by the heterogeneity and the weak coupling between distinct cryptographic primitives. As a result, it is infeasible to directly exploit them for the online car-hailing service. To tackle that, we put forward a new cryptographic primitive called Fine-grained Puncturable Matchmaking Encryption (FP-ME) by modifying AB-ME and incorporating PE technology. FP-ME can simultaneously implement fine-grained and bilateral order matching, the authenticity of passengers orders, and meeting the time constraint of passengers orders. We formalize the adversarial models for the proposed FP-ME and then present rigorous security analysis to prove the security of the proposed system. Additionally, we study performance of the system via simulations to demonstrate its practicability and effectiveness in the real-world applications. Jianfei Sun, Guowen Xu, Tianwei Zhang 0004, Mamoun Alazab, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2022 | Lightweight Privacy-Preserving GAN Framework for Model Training and Image SynthesisabstractGenerative adversarial network (GAN) has excellent performance for data generation and is widely used in image synthesis. Outsourcing GAN to cloud platform is a popular way to save local computation resources and improve the efficiency, but it still faces the privacy leakage concerns: (1) the sensitive information of the training dataset may be disclosed in the cloud; (2) the trained model may reveal the privacy of training samples since it extracts the characteristics from the data. In this paper, we propose a lightweight privacy-preserving GAN framework (LP-GAN) for model training and image synthesis based on secret sharing scheme. Specifically, we design a series of efficient secure interactive protocols for different layers (convolution, batch normalization, ReLU, Sigmoid) of neural network (NN) used in GAN. Our protocols are scalable to build secure training or inference tasks for NN-based applications. We utilize edge computing to reduce the latency and all the protocols are executed on two edge servers collaboratively. Compared with the existing schemes, the proposed solution greatly improves efficiency, reduces communication overhead, and guarantees the privacy. We prove the correctness and security of LP-GAN by theoretical analysis. Extensive experiments on different real-world datasets demonstrate the effectiveness, accuracy, and efficiency of our scheme. Yang Yang 0026, Ke Mu, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2022 | SOCI: A Toolkit for Secure Outsourced Computation on IntegersabstractSecure outsourced computation is a key technique for protecting data security and privacy in the cloud. Although fully homomorphic encryption (FHE) enables computations over encrypted data, it suffers from high computation costs in order to support an unlimited number of arithmetic operations. Recently, secure computations based on interactions of multiple computation servers and partially homomorphic encryption (PHE) were proposed in the literature, which enable an unbound number of addition and multiplication operations on encrypted data more efficiently than FHE and do not add any noise to encrypted data; however, these existing solutions are either limited in functionalities (e.g., computation on natural numbers only) or leak information of the underlying data. To tackle these shortcomings, this paper proposes Secure Outsourced Computation on Integers (SOCI) based on PHE and a twin-server architecture. Compared with the existing solutions, SOCI supports computations on encrypted integers (vs. natural numbers) and greatly improves the security and correctness of the computations. Results of theoretical analysis and experimental evaluation show that SOCI outperforms existing solutions in computation and communication efficiencies. Bowen Zhao 0001, Jiaming Yuan, Ximeng Liu, Yongdong Wu, HweeHwa Pang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2022 | Guest Editorial: 5G-Enabled Intelligent Application for Distributed Industrial Internet-of-Thing SystemabstractAs a novel network infrastructure that realizes the interconnection of humans, machines, and things, 5G enables a large number of devices with communication and sensing capabilities to securely, quickly, and reliably connect to the Internet and facilitates Industrial Internet of Things (IIoT) applications such as smart cities, smart homes, and smart grids. The 5G technique has potential applications in various military and civilian settings such as radar anomaly detection, unmanned aerial vehicles (UAV) data storage sharing [A1], [A2], and traffic data analysis. Ximeng Liu, Robert H. Deng, Yinbin Miao, Athanasios V. Vasilakos |
IEEE Trans. Ind. Informatics | 2 |
| 2022 | Verifiable Data Mining Against Malicious Adversaries in Industrial Internet of ThingsabstractWith the large-scaled data generated from various interconnected machines and networks, Industrial Internet of Things (IIoT) provides unprecedented opportunities for facilitating data mining for industrial applications. The current IIoT architecture tends to adopt cloud computing for further timely mining IIoT data, however, the openness of security-critical IIoT becomes challenging in terms of unbearable privacy issues. Most existing privacy-preserving data mining (PPDM) techniques are designed to resist honest-but-curious adversaries (i.e., cloud servers and data users). Due to the complexity and openness in IIoT, PPDM is significantly difficult with the presence of malicious adversaries in IIoT who may incur incorrect learned models and inference results. To solve the aforementioned issues, we propose a framework to extend existing PPDM to guard linear regression against malicious behaviors (hereafter referred to as GuardLR). To prevent dishonest computations of cloud servers and inconsistent inputs of data users, we first design a privacy-preserving verifiable learning scheme for linear regression, which guarantees the correctness of learning. In this article, to avoid malicious clouds from returning incorrect inference results, we design a privacy-preserving prediction scheme with lightweight verification. Our formal security analysis shows that GuardLR achieves privacy, completeness, and soundness. Empirical experiments using real-world datasets also demonstrate that GuardLR has high computational efficiency and accuracy. Zhuoran Ma 0002, Jianfeng Ma 0001, Yinbin Miao, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Ind. Informatics | 7 |
| 2022 | PrivacySignal: Privacy-Preserving Traffic Signal Control for Intelligent Transportation SystemabstractA new trend of using deep reinforcement learning for traffic signal control has become a spotlight in the Intelligent Transportation System (ITS). However, the traditional intelligent traffic signal control system always collects and transmits vehicle information (e.g., vehicle location, speed, etc.) in the form of plaintext, which would result in the leakage of commuters’ privacy and thus bring unnecessary troubles to users. In this paper, we propose a privacy-preserving traffic signal control for an intelligent transportation system (PrivacySignal). It relies on the existing road facilities to achieve the privacy of commuters, which guarantees the practicality of the system. Real-time decision-making and confidentiality of the system can be achieved simultaneously via the design of a series of secure and efficient interactive protocols, that are based on additive secret sharing, to perform the deep$Q$-network (DQN). Moreover, the security of PrivacySignal is testified, meanwhile, the system effectiveness, and the overall efficiency of PrivacySignal is demonstrated through theoretical analysis and simulation experiments. Compared with the existing privacy-preserving schemes of the intelligent traffic signal, PrivacySignal provides a general DQN based privacy-preserving traffic signal control strategy architecture with high efficiency and low-performance loss. Zuobin Ying, Shuanglong Cao, Ximeng Liu, Zhuo Ma 0001, Jianfeng Ma 0001, Robert H. Deng |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2022 | Privacy Protection in 5G Positioning and Location-based Services Based on SGXabstractAs the sensitivity of position, the privacy protection in both 5G positioning and its further application in location-based services (LBSs) has been paid special attention and studied. Solutions based on k-anonymity, homomorphic encryption, and secure multi-party computation have been proposed. However, these solutions either require a trusted third party or incur heavy overheads. Besides, there still lacks an integrated solution that can protect privacy for both positioning and LBS provision. Based on Intel SGX, this article proposes a novel light-weight scheme that can protect privacy in both 5G positioning and its further applications in LBS provision in an integrated way. Through secret sharing, the proposed scheme can also support multiple location-based service providers without frequent key exchange. We seriously analyze the security of our scheme. Based on scheme implementation, its efficiency is proved through the performance evaluation conducted over a real-world database. Zheng Yan 0002, Xinren Qian, Shushu Liu, Robert H. Deng |
ACM Trans. Sens. Networks | 4 |
| 2022 | A Traitor-Resistant and Dynamic Anonymous Communication Service for Cloud-Based VANETsabstractCloud-based VANETs are designed to enable communication between high-speed vehicles. In such a highly dynamic environment, how to provide secure and anonymous communication service is a challenge. In this article, we affirmatively address the challenge by proposing a traitor-resistant and dynamic anonymous communication framework (TD-ACF) for cloud-based VANETs, which supports several advantageous features. In TD-ACF, each vehicle is represented by a set of attributes instead of its real identity, and the driving data is transmitted in encrypted form. Therefore, the anonymous authentication and the confidentiality of driving data are achieved in this way. Meanwhile, TD-ACF supports two practical requirements in cloud-based VANETs: the revocation and the traceability of traitor. For the former, TD-ACF can force a vehicle to exit the communication network at any moment. We employ an efficient binary tree algorithm to reduce the size of key updates for revocation from the traditional linear to the logarithmic level. For the latter, we overcome the barrier of the one-to-many relationship between a vehicle and the shared set of attributes to support traitor tracing. In TD-ACF, unlike most existing schemes, the Semi-Trusted Cloud (STC) can directly capture and punish a traitor instead of querying all the records in the list of unrevoked vehicles. In addition, we solve the key escrow problem that plagues most existing attribute-based schemes. The theoretical analysis and experimental simulation show that the proposed scheme is feasible and effective. Huiying Hou, Jianting Ning, Yunlei Zhao, Robert H. Deng |
IEEE Trans. Serv. Comput. | 4 |
| 2022 | Pocket Diagnosis: Secure Federated Learning Against Poisoning Attack in the CloudabstractFederated learning has become prevalent in medical diagnosis due to its effectiveness in training a federated model among multiple health institutions (i.e., Data Islands (DIs)). However, increasingly massive DI-level poisoning attacks have shed light on a vulnerability in federated learning, which inject poisoned data into certain DIs to corrupt the availability of the federated model. Previous works on federated learning have been inadequate in ensuring the privacy of DIs and the availability of the final federated model. In this article, we design a secure federated learning mechanism with multiple keys to prevent DI-level poisoning attacks for medical diagnosis, calledSFAP. Concretely,SFAPprovides privacy-preserving random forest-based federated learning by using the multi-key secure computation, which guarantees the confidentiality of DI-related information. Meanwhile, a secure defense strategy over encrypted locally-submitted models is proposed to resist DI-level poisoning attacks. Finally, our formal security analysis and empirical tests on a public cloud platform demonstrate the security and efficiency ofSFAPas well as its capability of resisting DI-level poisoning attacks. Zhuoran Ma 0002, Jianfeng Ma 0001, Yinbin Miao, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Serv. Comput. | 6 |
| 2022 | VFIRM: Verifiable Fine-Grained Encrypted Image Retrieval in Multi-Owner Multi-User SettingsabstractTo ensure the security of images outsourced to the malicious cloud without affecting searchability on such outsourced (typically encrypted) images, one could use privacy-preserving Content-Based Image Retrieval (CBIR) primitive. However, conventional privacy-preserving CBIR schemes based on Searchable Symmetric Encryption (SSE) are not capable of supporting efficient fine-grained access control and result verification simultaneously. Therefore, in this article, we propose aVerifiableFine-grained encryptedImageRetrieval scheme in theMulti-owner multi-user settings (VFIRM). VFIRM first utilizes a novel polynomial-based access strategy to provide efficient fine-grained access control. Then, it employs the dual secure$k$-nearest neighbor technique to distribute distinct keys to different data owners and data users, and finally implements an adapted homomorphic MAC technique to check the correctness of search results. Our formal security analysis shows that VFIRM is non-adaptive semantic secure if the client's search key is generated randomly and keeps in secret. Our empirical experiments using two real-world datasets (i.e., Caltech101 and Corel5k) demonstrate the practicality of VFIRM. Qiuyun Tong, Yinbin Miao, Lei Chen 0029, Jian Weng 0001, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Serv. Comput. | 7 |
| 2022 | Reliable Policy Updating Under Efficient Policy Hidden Fine-Grained Access Control Framework for Cloud Data SharingabstractCiphertext-Policy Attribute-Based Encryption (CP-ABE) is one of the potent encryption paradigms in protecting data confidentiality in the cloud data sharing scenario. However, the access policy of the traditional CP-ABE is in plaintext form that reveals significant sensitive information of data owners and data visitors. To mitigate this problem, two approaches have been proposed in the literature. One is partially hidden, where the attributes in the access policy are divided into two parts: the plaintext attribute names and the hidden attribute values. The other approach fully hides the attributes in the access policy which, unfortunately, hinders efficient and correct decryption as well as dynamic policy-updating. In this article, we design a security-enhanced Attribute Cuckoo Filter (se-ACF) to hide the access policy and propose a new CP-ABE system, called Privacy-Preserving Policy Updating ABE (3PU-ABE), which effectively integrates policy hiding and policy updating. We conduct rigorous security analysis and performance evaluation of 3PU-ABE. The results indicate that 3PU-ABE completely hides the access policy without affecting the decryption, and entails better policy-updating efficiency than similar works. Zuobin Ying, Ximeng Liu, Shengmin Xu, Robert H. Deng |
IEEE Trans. Serv. Comput. | 5 |
| 2022 | Secure Cloud Data Deduplication with Efficient Re-EncryptionabstractData deduplication technique has been widely adopted by commercial cloud storage providers, which is both important and necessary in coping with the explosive growth of data. To further protect the security of users’ sensitive data in the outsourced storage mode, many secure data deduplication schemes have been designed and applied in various scenarios. Among these schemes, secure and efficient re-encryption for encrypted data deduplication attracted the attention of many scholars, and many solutions have been designed to support dynamic ownership management. In this paper, we focus on the re-encryption deduplication storage system and show that the recently designed lightweight rekeying-aware encrypted deduplication scheme (REED) is vulnerable to an attack which we call it stub-reserved attack. Furthermore, we propose a secure data deduplication scheme with efficient re-encryption based on the convergent all-or-nothing transform (CAONT) and randomly sampled bits from the Bloom filter. Due to the intrinsic property of one-way hash function, our scheme can resist the stub-reserved attack and guarantee the data privacy of data owners’ sensitive data. Moreover, instead of re-encrypting the entire package, data owners are only required to re-encrypt a small part of it through the CAONT, thereby effectively reducing the computation overhead of the system. Finally, security analysis and experimental results show that our scheme is secure and efficient in re-encryption. Haoran Yuan, Xiaofeng Chen 0001, Jin Li 0002, Tao Jiang 0017, Jianfeng Wang 0001, Robert H. Deng |
IEEE Trans. Serv. Comput. | 6 |
| 2021 | UltraPIN: Inferring PIN Entries via UltrasoundabstractWhile PIN-based user authentication systems such as ATM have long been considered to be secure enough, they are facing new attacks, named UltraPIN, which can be launched from commodity smartphones. As a target user enters a PIN on a PIN-based user authentication system, an attacker may use UltraPIN to infer the PIN from a short distance (50 cm to 100 cm). In this process, UltraPIN leverages smartphone speakers to issue human-inaudible ultrasound signals and uses smartphone microphones to keep recording acoustic signals. It applies a series of signal processing techniques to extract high-quality feature vectors from low-energy and high-noise signals and then applies a combination of machine learning models to classify finger movement patterns during PIN entry and generate a ranked list of highly possible PINs as result. Rigorous experiments show that UltraPIN is highly effective and robust in PIN inference. Yingjiu Li, Robert H. Deng |
AsiaCCS | 3 |
| 2021 | LEAP: Leakage-Abuse Attack on Efficiently Deployable, Efficiently Searchable Encryption with Partially Known DatasetabstractSearchable Encryption (SE) enables private queries on encrypted documents. Most existing SE schemes focus on constructing industrial-ready, practical solutions at the expense of information leakages that are considered acceptable. In particular, ShadowCrypt utilizes a cryptographic approach named ''efficiently deployable, efficiently searchable encryption'' (EDESE) that reveals the encrypted dataset and the query tokens among other information. However, recent attacks showed that such leakages can be exploited to (partially) recover the underlying keywords of query tokens under certain assumptions on the attacker's background knowledge. Jianting Ning, Xinyi Huang 0001, Geong Sen Poh, Jiaming Yuan, Yingjiu Li, Jian Weng 0001, Robert H. Deng |
CCS | 7 |
| 2021 | When Program Analysis Meets Bytecode Search: Targeted and Efficient Inter-procedural Analysis of Modern Android Apps in BackDroidabstractWidely-used Android static program analysis tools, e.g., Amandroid and FlowDroid, perform the whole-app inter-procedural analysis that is comprehensive but fundamentally difficult to handle modern (large) apps. The average app size has increased three to four times over five years. In this paper, we explore a new paradigm of targeted inter-procedural analysis that can skip irrelevant code and focus only on the flows of security-sensitive sink APIs. To this end, we propose a technique called on-the-fly bytecode search, which searches the disassembled app bytecode text just in time when a caller needs to be located. In this way, it guides targeted (and backward) inter-procedural analysis step by step until reaching entry points, without relying on a whole-app graph. Such search-based inter-procedural analysis, however, is challenging due to Java polymorphism, callbacks, asynchronous flows, static initializers, and inter-component communication in Android apps. We overcome these unique obstacles in our context by proposing a set of bytecode search mechanisms that utilize flexible searches and forward object taint analysis. Atop this new inter-procedural analysis, we further adjust the traditional backward slicing and forward constant propagation to provide the complete dataflow tracking of sink API calls. We have implemented a prototype called BackDroid and compared it with Amandroid in analyzing 3,178 modern popular apps for crypto and SSL misconfigurations. The evaluation shows that for such sink-based problems, BackDroid is 37 times faster (2.13v.s. 78.15 minutes) and has no timed-out failure (v.s. 35% in Amandroid) while maintaining close or even better detection effectiveness. Daoyuan Wu, Debin Gao, Robert H. Deng, Rocky K. C. Chang |
DSN | 3 |
| 2021 | Revocable Policy-Based Chameleon Hash
Shengmin Xu, Jianting Ning, Jinhua Ma, Guowen Xu, Jiaming Yuan, Robert H. Deng |
ESORICS (1) | 6 |
| 2021 | Efficient and Verifiable Proof of Replication with Fast Fault LocalizationabstractProof of replication technique has been widely used to verify whether the cloud service providers (CSPs) store multiple replications of a file with dedicated and unique storage space, which effectively prevents CSPs from colluding and storing only one copy of the file. In this field, many representative schemes have been proposed and applied to various scenarios. However, most of the existing schemes are based on the timing assumption (i.e., the verifier rejects the proof of replication if the prover's response is timeout) and do not explicitly consider the problem of batch verification and fault localization. This will bring unnecessary computational overhead to the verifier and reduce the efficiency of batch auditing. To address the above problems, we propose a verifiable proof of replication scheme with fast fault localization and high efficiency. By integrating incompressible encoding and homomorphic linear authenticator, our scheme can effectively audit the integrity of file replications without timing assumptions. To support batch verification and fault localization, we propose a reversed signature aggregation tree (Rev-tree) by integrating the quick binary search and exponent testing. Compared with the traditional binary tree, Rev-tree can further reduce the overhead of batch verification and effectively locate a single fault replication. Moreover, benefit from the property of Rev-tree taking the existing error probability as an estimate of the rest of the tree, our scheme can adjust the verification strategy dynamically to meet with different situations. Finally, security analysis and experimental results show that our scheme is secure and efficient in proof of replication and fast fault localization. Haoran Yuan, Xiaofeng Chen 0001, Guowen Xu, Jianting Ning, Joseph K. Liu, Robert H. Deng |
INFOCOM | 6 |
| 2021 | Differential Training: A Generic Framework to Reduce Label Noises for Android Malware Detection
Jiayun Xu, Yingjiu Li, Robert H. Deng |
NDSS | 3 |
| 2021 | Expressive Bilateral Access Control for Internet-of-Things in Cloud-Fog ComputingabstractAs a versatile system architecture, cloud-fog Internet-of-Things~(IoT) enables multiple resource-constrained devices to communicate and collaborate with each other. By outsourcing local data and immigrating expensive workloads to cloud service providers and fog nodes (FNs), resource-constrained devices can enjoy data services with low latency and minimal cost. To protect data security and privacy in the untrusted cloud-fog environment, many cryptographic mechanisms have been invented. Unfortunately, most of them are impractical when directly applied to cloud-fog IoT computing, mainly due to the large number of resource-constrained end-devices (EDs). In this paper, we present a secure cloud-fog IoT data sharing system with bilateral access control based on a new cryptographic tool called lightweight matchmaking encryption. Our system enforces both sender access control and receiver access control simultaneously and adapts to resource-constrained EDs by outsourcing costly workloads to FNs. We conduct extensive experiments to demonstrate the superior performance of our system to the most relevant solutions in the literature. Shengmin Xu, Jianting Ning, Jinhua Ma, Xinyi Huang 0001, HweeHwa Pang, Robert H. Deng |
SACMAT | 6 |
| 2021 | Secure Collaborative Deep Learning Against GAN Attacks in the Internet of ThingsabstractDeep learning makes the Internet-of-Things (IoT) devices more attractive, and in turn, IoT facilitates the resolution of the contradiction between data collection and privacy concerns. IoT devices with small-scale computing power can contribute to model training without sharing data in collaborative learning. However, collaborative learning is susceptible to generative adversarial network (GAN) attack, where an adversary can pretend to be a participant engaging in the model training and learn other participants' data. In this article, we propose a secure collaborative deep learning model which resists GAN attacks. We isolate the participants from the model parameters, and realize the local model training of participants via the interaction mode, ensuring that neither the participants nor the server would have access to each other's data. In particular, we target convolutional neural networks, the most popular network, design specific algorithms for various functionalities in different layers of the network, making it suitable for deep learning environments. To our best knowledge, this is the first work designing specific protocol against GAN attacks in collaborative learning. The results of our experiments on two real data sets show that our protocol can achieve good accuracy, efficiency, and image processing adaptability. Zhenzhu Chen, Anmin Fu, Yinghui Zhang 0002, Zhe Liu 0001, Fanjian Zeng, Robert H. Deng |
IEEE Internet Things J. | 6 |
| 2021 | Fast and Secure Location-Based Services in Smart Cities on Outsourced DataabstractWith the advancement of mobile Internet, cloud computing, and smart sensing devices, location-based services (LBSs) have become more and more indispensable in the Internet-of-Things (IoT)-based smart cities. Especially, spatial keyword queries have been widely deployed in real-life applications in recent years. Recently, several privacy-preserving spatial keyword queries schemes were proposed to guarantee data security and query privacy on outsourced data. However, these schemes support neither dynamic update nor diverse query types, which cannot meet the requirements in practical applications. This article proposes two secure dynamic spatial keyword queries (SDSKQs) constructions that support expressive query types and dynamic update. First, we present a basic SDSKQ construction based on hidden-vector encryption and order-revealing encryption. Specifically, we propose a secure hybrid index structure forspatio-textualdata, named encrypted textual signature quadtree (ETSQ-tree). Using ETSQ-tree, the server can prune the index tree according to search queries to reduce the search space. Besides, the ETSQ-tree can be updated dynamically. To resist the file-injection attack, which aims to infer query information according to newly inserted objects, we further improve the basic SDSKQ to achieve forward security. We implement our two constructions and evaluate them using real-world data sets. The experimental results show that they are efficient and feasible in practical applications, and the comparative evaluation confirms that the performance of our constructions outperforms that of the state-of-the-art schemes. Xiangyu Wang 0010, Jianfeng Ma 0001, Yinbin Miao, Ximeng Liu, Dan Zhu 0001, Robert H. Deng |
IEEE Internet Things J. | 6 |
| 2021 | PRICE: Privacy and Reliability-Aware Real-Time Incentive System for CrowdsensingabstractCrowdsensing is regarded as a critical component of the Internet of Things (IoT) and has been widely applied in smart city services. Incentive mechanism design, data reliability evaluation, and privacy preservation are the research focuses of crowdsensing. However, most existing incentive mechanisms fail to protect data privacy and evaluate data credibility, simultaneously. Moreover, traditional privacy and reliability-aware incentive schemes are usually challenging to realize real-time reward distribution. To this end, we first point out a single-time slice of failure problem in real-time incentive mechanisms and propose a two-layer truth discovery model (TLTD) to resolve this problem. Then, a reliability-aware real-time incentive mechanism (RRIM) is designed based on the proposed TLTD. In order to evaluate data reliability in a privacy-preserving manner, we build a privacy-preserving truth discovery solution (PriTD) based on secure computation protocols. Finally, our proposed system [privacy and reliability-aware real-time incentive system for crowdsensing (PRICE)] integrating the aforementioned protocols realizes real-time reward distribution, data reliability evaluation, and privacy protection, simultaneously. Theoretical analysis and experimental evaluations on a synthetic and real-world data set demonstrate the feasibility and efficiency of the proposed PRICE. Bowen Zhao 0001, Ximeng Liu, Weineng Chen, Wei Liang 0005, Xinglin Zhang 0001, Robert H. Deng |
IEEE Internet Things J. | 6 |
| 2021 | Secure and verifiable outsourced data dimension reduction on dynamic data
Zhenzhu Chen, Anmin Fu, Robert H. Deng, Ximeng Liu, Yang Yang 0026, Yinghui Zhang 0002 |
Inf. Sci. | 3 |
| 2021 | Lattice-based remote user authentication from reusable fuzzy signatureabstractIn this paper, we introduce a new construction of reusable fuzzy signature based remote user authentication that is secure against quantum computers. We investigate the reusability of fuzzy signature, and we prove that the fuzzy signature schemes provide biometrics reusability (aka. reusable fuzzy signature). We define formal security models for the proposed construction, and we prove that it achieves user authenticity and user privacy. The proposed construction ensures: 1) a user’s biometrics can be securely reused in remote user authentication; 2) a third party having access to the communication channel between a user and the authentication server cannot identify the user. Yangguang Tian, Yingjiu Li, Robert H. Deng, Binanda Sengupta, Guomin Yang |
J. Comput. Secur. | 3 |
| 2021 | Robust and Universal Seamless Handover Authentication in 5G HetNetsabstractThe evolving fifth generation (5G) cellular networks will be a collection of heterogeneous and backward-compatible networks. With the increased heterogeneity and densification of 5G heterogeneous networks (HetNets), it is important to ensure security and efficiency of frequent handovers in 5G wireless roaming environments. However, existing handover authentication mechanisms still have challenging issues, such as anonymity, robust traceability and universality. In this paper, we address these issues by introducing RUSH, a Robust and Universal Seamless Handover authentication protocol for 5G HetNets. In RUSH, anonymous mutual authentication with key agreement is enabled for handovers by exploiting the trapdoor collision property of chameleon hash functions and the tamper-resistance of blockchains. RUSH achieves universal handover authentication for all the diverse mobility scenarios, as exemplified by the handover between 5G new radio and non-3GPP access regardless of the trustworthiness of non-3GPP access and the consistency of the core network. RUSH also achieves perfect forward secrecy, master key forward secrecy, known randomness secrecy, key escrow freeness and robust traceability. Our formal security proofs based on the BAN-logic and formal verification based on AVISPA indicate that RUSH resists various attacks. Comprehensive performance evaluation and comparisons show that RUSH outperforms other schemes in both computation and communication efficiencies. Yinghui Zhang 0002, Robert H. Deng, Elisa Bertino, Dong Zheng 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | Looking Back! Using Early Versions of Android Apps as Attack VectorsabstractAndroid platform is gaining explosive popularity. This leads developers to invest resources to maintain the upward trajectory of the demand. Unfortunately, as the profit potential grows higher, the chances of these Apps getting attacked also get higher. Therefore, developers improved the security of their Apps, which limits attackers ability to compromise upgraded versions of the Apps. However, developers cannot enhance the security of earlier versions that have been released on the Play Store. The earlier versions of the App can be subject to reverse engineering and other attacks. In this paper, we find that attackers can use these earlier versions as attack vectors, which threatens well protected upgraded versions. We show how to attack the upgraded versions of some popular Apps, including Facebook, Sina Weibo and Qihoo360-Cloud-Driven by analyzing the vulnerabilities existing in their earlier versions. We design and implement a tool named DroidSkynet to analyze and find out vulnerable apps from the Play Store. Among 1,500 mainstream Apps collected from the real world, our DroidSkynet indicates the success rate of attacking an App using an earlier version is 34 percent. We also explore possible mitigation solutions to achieve a balance between utility and security of the App update process. Yue Zhang 0025, Jian Weng 0001, Jia-Si Weng 0001, Lin Hou 0002, Anjia Yang, Ming Li 0049, Yang Xiang 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 8 |
| 2021 | Optimized Verifiable Fine-Grained Keyword Search in Dynamic Multi-Owner SettingsabstractCiphertext-Policy Attribute-Based Keyword Search (CP-ABKS) schemes support both fine-grained access control and keyword-based ciphertext retrieval, which make these schemes attractive for resource-constrained users (i.e., mobile or wearable devices, sensor nodes, etc.) to store, share and search encrypted data in the public cloud. However, ciphertext length and decryption overhead in the existing CP-ABKS schemes grow with the complexity of access policies or the number of data users' attributes. Moreover, such schemes generally do not consider the practical multi-owner setting (e.g., each file needs to be signed by multiple data owners before being uploaded to the cloud server) or prevent malicious cloud servers from returning incorrect search results. To overcome these limitations, in this paper we first design an optimized Verifiable Fine-grained Keyword Search scheme in the static Multi-owner setting (termed as basic VFKSM), which achieves short ciphertext length, fast ciphertext transformation, accelerated search process, and authentic search result verification. Then, we extend the basic VFKSM to support multi-keyword search and multi-owner update (also called as extended VFKSM). Finally, we prove that the basic (or extended) VFKSM resists the Chosen-Keyword Attack (CKA) and external Keyword-Guessing Attack (KGA). We also evaluate the performance of these schemes using various public datasets. Yinbin Miao, Robert H. Deng, Kim-Kwang Raymond Choo, Ximeng Liu, Jianting Ning, Hongwei Li 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | Multi-Authority Attribute-Based Keyword Search over Encrypted Cloud DataabstractSearchable Encryption (SE) is an important technique to guarantee data security and usability in the cloud at the same time. Leveraging Ciphertext-Policy Attribute-Based Encryption (CP-ABE), the Ciphertext-Policy Attribute-Based Keyword Search (CP-ABKS) scheme can achieve keyword-based retrieval and fine-grained access control simultaneously. However, the single attribute authority in existing CP-ABKS schemes is tasked with costly user certificate verification and secret key distribution. In addition, this results in a single-point performance bottleneck in distributed cloud systems. Thus, in this paper, we present a secure Multi-authority CP-ABKS (MABKS) system to address such limitations and minimize the computation and storage burden on resource-limited devices in cloud systems. In addition, the MABKS system is extended to support malicious attribute authority tracing and attribute update. Our rigorous security analysis shows that the MABKS system is selectively secure in both selective-matrix and selective-attribute models. Our experimental results using real-world datasets demonstrate the efficiency and utility of the MABKS system in practical applications. Yinbin Miao, Robert H. Deng, Ximeng Liu, Kim-Kwang Raymond Choo, Hongjun Wu 0001, Hongwei Li 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | Privacy-Preserving Attribute-Based Keyword Search in Shared Multi-owner SettingabstractCiphertext-Policy Attribute-Based Keyword Search (CP-ABKS) facilitates search queries and supports fine-grained access control over encrypted data in the cloud. However, prior CP-ABKS schemes were designed to support unshared multi-owner setting, and cannot be directly applied in the shared multi-owner setting (where each record is accredited by a fixed number of data owners), without incurring high computational and storage costs. In addition, due to privacy concerns on access policies, most existing schemes are vulnerable to off-line keyword-guessing attacks if the keyword space is of polynomial size. Furthermore, it is difficult to identify malicious users who leak the secret keys when more than one data user has the same subset of attributes. In this paper, we present a privacy-preserving CP-ABKS system with hidden access policy in Shared Multi-owner setting (basic ABKS-SM system), and demonstrate how it is improved to support malicious user tracing (modified ABKS-SM system). We then prove that the proposed ABKS-SM systems achieve selective security and resist off-line keyword-guessing attack in the generic bilinear group model. We also evaluate their performance using real-world datasets. Yinbin Miao, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng, Jiguo Li 0001, Hongwei Li 0001, Jianfeng Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | Proxy-Free Privacy-Preserving Task Matching with Efficient Revocation in CrowdsourcingabstractTask matching in crowdsourcing has been extensively explored with the increasing popularity of crowdsourcing. However, privacy of tasks and workers is usually ignored in most of exiting solutions. In this paper, we study the problem of privacy-preserving task matching for crowdsourcing with multiple requesters and multiple workers. Instead of utilizing proxy re-encryption, we propose a proxy-free task matching scheme for multi-requester/multi-worker crowdsourcing, which achieves task-worker matching over encrypted data with scalability and non-interaction. We further design two different mechanisms for worker revocation including Server-Local Revocation (SLR) and Global Revocation (GR), which realize efficient worker revocation with minimal overhead on the whole system. The proposed scheme is provably secure in the random oracle model under the Decisional q-Combined Bilinear Diffie-Hellman (q-DCDBH) assumption. Comprehensive theoretical analysis and detailed simulation results show that the proposed scheme outperforms the state-of-the-art work. Jiangang Shu, Kan Yang 0001, Xiaohua Jia, Ximeng Liu, Cong Wang 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2021 | ObliComm: Towards Building an Efficient Oblivious Communication SystemabstractAnonymous Communication (AC) hides traffic patterns and protects message metadata from being leaked during message transmission. Many practical AC systems have been proposed aiming to reduce communication latency and support a large number of users. However, how to design AC systems which possess strong security property and at the same time achieve optimal performance (i.e., the lowest latency or highest horizontal scalability) has been a challenging problem. In this paper, we propose an ObliComm framework, which consists of six modular AC subroutines. We also present a strong security definition for AC, named oblivious communication, encompassing confidentiality, unobservability, and a new requirement sending-and-receiving operation hiding. The AC subroutines in ObliComm allow for modular construction of oblivious communication systems in different network topologies. All constructed systems satisfy oblivious communication definition and can be provably secure in the universal composability (UC) framework. Additionally, we model the relationship between the network topology and communication measurements by queuing theory, which enables the system's efficiency can be optimized and estimated by quantitative analysis and calculation. Through theoretical analyses and empirical experiments, we demonstrate the efficiency of our scheme and soundness of the queuing model. Pengfei Wu 0003, Robert H. Deng, Qingni Shen, Ximeng Liu, Qi Li 0002, Zhonghai Wu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | Privacy-Preserving Proof of Storage for the Pay-As-You-Go Business ModelabstractProof of Storage (PoS) enables a cloud storage provider to prove that a client's data is intact. However, existing PoS protocols are not designed for the pay-as-you-go business model in which payment is made based on both storage volume and duration. In this paper, we propose two PoS protocols suitable for the pay-as-you-go storage business model. The first is a time encapsulated Proof of Retrievability (PoR) protocol that ensures retrievability of the original file upon successful auditing by a client. Considering the large size of outsourced data, we then extend the protocol to a privacy-preserving public auditing protocol which allows a third party auditor to audit outsourced data on behalf of its clients without sacrificing the privacy of the data or the timestamp (i.e., time of storage). We formalize the definition, system model and security model of the proposed PoS system and prove the security of the proposed protocols by a sequence of games in the algebraic group model with a random oracle. We analyze the performance of the protocols both theoretically and experimentally and show that the protocols are practical. Tong Wu 0011, Guomin Yang, Yi Mu 0001, Fuchun Guo, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | Designing Leakage-Resilient Password Entry on Head-Mounted Smart Wearable Glass DevicesabstractWith the boom of Augmented Reality (AR) and Virtual Reality (VR) applications, head-mounted smart wearable glass devices are becoming popular to help users access various services like E-mail freely. However, most existing password entry schemes on smart glasses rely on additional computers or mobile devices connected to smart glasses, which require users to switch between different systems and devices. This may greatly lower the practicability and usability of smart glasses. In this paper, we focus on this challenge and design three practical anti-eavesdropping password entry schemes on stand-alone smart glasses, named gTapper, gRotator and gTalker. The main idea is to break the correlation between the underlying password and the interaction observable to adversaries. In our IRB-approved user study, these schemes are found to be easy-to-use without additional hardware under various test conditions, where the participants can enter their passwords within moderate time, at high accuracy, and in various situations. Yan Li 0075, Weizhi Meng 0001, Yingjiu Li, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2021 | Enabling Efficient Spatial Keyword Queries on Encrypted Data With Strong Security GuaranteesabstractStructured Encryption (STE), which allows a server to provide secure search services on encrypted data structures, has been widely investigated in recent years. To meet expressive search requirements in practical applications, a large number of STE constructions have been proposed either on textual keywords or spatial data. However, STE on spatio-textual data, which are widely used in location-based services, has not been fully investigated. In this paper, we formally define the notion of Spatial Keyword Structured Encryption (SKSE) and propose several concrete SKSE constructions with various efficiency-security trade-offs. Firstly, we propose a basic construction with linear search complexity, which only leaks the private files matching both spatial range query and all query keywords. Then, to improve the search efficiency on large-scale datasets, we present a novel tree-based construction with sub-linear search complexity. Finally, we introduce a post-validation approach to remove false positives and further improve storage and search performance. Our constructions are general in the sense that they can be constructed from any hidden vector encryption schemes, including public-key setting and symmetric-key setting, which can meet different sharing requirements. Our rigorous security analysis and comprehensive performance evaluation demonstrate that the proposed constructions are secure and outperform the start-of-the-art solutions. Xiangyu Wang 0010, Jianfeng Ma 0001, Feng Li 0041, Ximeng Liu, Yinbin Miao, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2021 | Server-Aided Bilateral Access Control for Secure Data Sharing With Dynamic User GroupsabstractAs a versatile technique, cloud-fog computing extends the traditional cloud server to offer various on-demand data services. Maintaining data confidentiality is one of the most crucial requirements for data services, many cryptosystems have been proposed to reserve information privacy against such an untrusted environment. However, in cloud-fog computing, how to confidentially and efficiently share data and fetch desirable data without expensive data decryption for resource-constrained end-devices is challenging. In this paper, we propose a cloud-fog system for the Internet-of-Things (IoT) ecosystem by introducing a cryptographic primitive called server-aided revocable bilateral attribute-based encryption (SRB-ABE). Our solution is a secure and lightweight bilateral access control system with dynamic user groups, including (1) fine-grained data user and data owner access control simultaneously; (2) outsourced data source identification; (3) server-aided user revocation with publicly updatable ciphertexts; and (4) lightweight data decryption mechanism with one exponentiation computation. We present the formal definition and concrete construction of SRB-ABE with security proofs to build cloud-fog systems. The extensive comparison and experimental analysis demonstrate that our construction has superior functionality and comparable performance than the most relevant solutions. Shengmin Xu, Jianting Ning, Xinyi Huang 0001, Jianying Zhou 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2021 | K-Time Modifiable and Epoch-Based Redactable BlockchainabstractAs an immutable append-only distributed ledger, blockchain allows a group of participants to reach a consensus in an untrustworthy ecosystem. Immutability is a blockchain feature that persists data forever, but it is no longer legal in reality. Blockchain has unchangeable improper contents that violate laws. Moreover, data regulation toward “the right to be forgotten” requires blockchain must be modifiable. To address this problem, redactable blockchain has been introduced to relax immutability in a controlled way. However, once a participant is authorized, she/he can rewrite any content and no penalty for the malicious behavior that hinders the wide deployment of redactable blockchain in practice. In this paper, we introduce a new notion, dubbed k-time modifiable and epoch-based redactable blockchain (KERB) with a monetary penalty to control rewriting privileges and penalize malicious behaviors. Our solution is built up from simple building blocks: digital signatures and chameleon hashes. We give a formal definition and security models of KERB, and present a generic construction along with formal proofs. The extensive comparison and experimental analysis illustrate that our solution enjoys superior functionalities and performances than the state-of-the-art solutions. Shengmin Xu, Jianting Ning, Jinhua Ma, Xinyi Huang 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2021 | PriScore: Blockchain-Based Self-Tallying Election System Supporting Score VotingabstractElection and voting play crucial roles in democratic society for an elactorate to make a collective decision. E-voting is one of the most challenging problems in cryptographic research to provide multiple dimensions security assurances. In this paper, we study an important voting paradigm, score voting, with privacy protection, which has not been investigated in previous work. We propose a blockchain based self-tallying election system to support score voting, dubbed “PriScore”, where the ballots are recorded on blockchain to prevent vote forgery or tampering. PriScore makes it possible for each voter to assign different evaluation scores (within a certain range) for the candidates as ranked-choice, where the sum of the scores in each ballot should be a predefined constant, and the evaluation scores are encrypted to maintain confidentiality. A major challenge in score voting is to simultaneously prove two constraint conditions: range proof and sum proof. We introduce a new technique, called dual zero-knowledge proof (dual-ZKP), to prove the scores satisfying two crucial requirements, which integrates “1-out-of-$K$” proof and distributed ElGamal crypto in a non-trivial way. The self-tallying mechanism in PriScore enables any party in the system to calculate and verify the election result, which provides fairness, dispute-freeness. The security analysis demonstrates that PriScore achieves completeness, soundness, eligibility, universal/individual verifiability and multiple-voting detection. We evaluate the performance of PriScore on modern workbench to test the performance, and also on a blockchain platform to measure the resource consumption. The experiments show that PriScore preserves privacy of score voting with reasonable overheads. Yang Yang 0026, Zhangshuang Guan, Zhiguo Wan, Jian Weng 0001, HweeHwa Pang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2021 | Investigating the Adoption of Hybrid Encrypted Cloud Data Deduplication With Game TheoryabstractEncrypted data deduplication, along with different preferences in data access control, brings the birth of hybrid encrypted cloud data deduplication (H-DEDU for short). However, whether H-DEDU can be successfully deployed in practice has not been seriously investigated. Obviously, the adoption of H-DEDU depends on whether it can bring economic benefits to all stakeholders. But existing economic models of cloud storage fail to support H-DEDU due to complicated interactions among stakeholders. In this article, we establish a formal economic model of H-DEDU by formulating the utilities of all involved stakeholders, i.e., data holders, data owners, and Cloud Storage Providers (CSPs). Then, we construct a multi-stage Stackelberg game, which consists of Holder Participation Game, Owner Online Game, and CSP Pricing Game, to capture the interactions among all system stakeholders. We further analyze the conditions of the existence of a sub-game perfect Nash Equilibrium and propose a gradient-based algorithm to help the stakeholders choose near-optimal strategies. Extensive experiments show the feasibility of the proposed algorithm in achieving the Nash Equilibrium of the Stackelberg game. Additionally, we investigate the effects of parameters related to CSP, data owners and data holders on H-DEDU adoption. Our study advises all stakeholders the best strategies to adopt H-DEDU. Xueqin Liang, Zheng Yan 0002, Robert H. Deng |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2021 | Privacy-Preserving Outsourced Clinical Decision Support System in the CloudabstractIn this paper, we propose a privacy-preserving clinical decision support system using Naïve Bayesian (NB) classifier, hereafter referred to as Peneus, designed for the outsourced cloud computing environment. Peneus allows one to use patient health information to train the NB classifier privately, which can then be used to predict a patient's (undiagnosed) disease based on his/her symptoms in a single communication round. Specifically, we design secure Single Instruction Multiple Data (SIMD) integer circuits using the fully homomorphic encryption scheme, which can greatly increase the performance compared with the original secure integer circuit. Then, we present a privacy-preserving historical Personal Health Information (PHI) aggregation protocol to allow different PHI sources to be securely aggregated without the risk of compromising the privacy of individual data owner. Also, secure NB classifier is constructed to achieve secure disease prediction in the cloud without the help of an additional non-colluding computation server. We then demonstrate that Peneus achieves the goal of patient health status monitoring without privacy leakage to unauthorized parties, as well as the utility and the efficiency of Peneus using simulations and analysis. Ximeng Liu, Robert H. Deng, Kim-Kwang Raymond Choo, Yang Yang 0026 |
IEEE Trans. Serv. Comput. | 2 |
| 2021 | Outsourcing Service Fair Payment Based on Blockchain and Its Applications in Cloud ComputingabstractAs a milestone in the development of outsourcing services, cloud computing enables an increasing number of individuals and enterprises to enjoy the most advanced services from outsourcing service providers. Because online payment and data security issues are involved in outsourcing services, the mutual distrust between users and service providers may severely impede the wide adoption of cloud computing. Nevertheless, most existing solutions only consider a specific type of services and rely on a trusted third-party to realize fair payment. In this paper, to realize secure and fair payment of outsourcing services in general without relying on any third-party, trusted or not, we introduce BPay, an outsourcing service fair payment framework based on blockchain in cloud computing. We first propose the system architecture, adversary model and design goals of BPay, then describe the design details. Our security and compatibility analysis indicates that BPay achieves soundness and robust fairness and it is compatible with the Bitcoin blockchain and the Ethereum blockchain. The key to the robust fairness and compatibility lies in an all-or-nothing checking-proof protocol and a top-down checking method. In addition, our experimental results show that BPay is computationally efficient. Finally, we present the applications of BPay in outsourcing services. Yinghui Zhang 0002, Robert H. Deng, Ximeng Liu, Dong Zheng 0001 |
IEEE Trans. Serv. Comput. | 2 |
| 2020 | Secure and Verifiable Inference in Deep Neural NetworksabstractOutsourced inference service has enormously promoted the popularity of deep learning, and helped users to customize a range of personalized applications. However, it also entails a variety of security and privacy issues brought by untrusted service providers. Particularly, a malicious adversary may violate user privacy during the inference process, or worse, return incorrect results to the client through compromising the integrity of the outsourced model. To address these problems, we propose SecureDL to protect the model’s integrity and user’s privacy in Deep Neural Networks (DNNs) inference process. In SecureDL, we first transform complicated non-linear activation functions of DNNs to low-degree polynomials. Then, we give a novel method to generate sensitive-samples, which can verify the integrity of a model’s parameters outsourced to the server with high accuracy. Finally, We exploit Leveled Homomorphic Encryption (LHE) to achieve the privacy-preserving inference. We shown that our sensitive-samples are indeed very sensitive to model changes, such that even a small change in parameters can be reflected in the model outputs. Based on the experiments conducted on real data and different types of attacks, we demonstrate the superior performance of SecureDL in terms of detection accuracy, inference accuracy, computation, and communication overheads. Guowen Xu, Hongwei Li 0001, Hao Ren 0001, Jianfei Sun, Shengmin Xu, Jianting Ning, Haomiao Yang, Kan Yang 0001, Robert H. Deng |
ACSAC | 9 |
| 2020 | Catch You If You Deceive Me: Verifiable and Privacy-Aware Truth Discovery in Crowdsensing SystemsabstractTruth Discovery (TD) is to infer truthful information by estimating the reliability of users in crowdsensing systems. To protect data privacy, many Privacy-Preserving Truth Discovery (PPTD) approaches have been proposed. However, all existing PPTD solutions do not consider a fundamental issue of trust. That is, if the data aggregator (e.g., the cloud server) is not trustworthy, how can an entity be convinced that the data aggregator has correctly performed the PPTD? A "lazy" cloud server may partially follow the deployed protocols to save its computing and communication resources, or worse, maliciously forge the results for some shady deals. In this paper, we propose V-PATD, the first Verifiable and Privacy-Aware Truth Discovery protocol in crowdsensing systems. In V-PATD, a publicly verifiable approach is designed enabling any entity to verify the correctness of aggregated results returned from the server. Since most of the computation burdens are carried by the cloud server, our verification approach is efficient and scalable. Moreover, users' data is perturbed with the principles of local differential privacy. Security analysis shows that the proposed perturbation mechanism guarantees a high aggregation accuracy even if large noises are added. Compared to existing solutions, extensive experiments conducted on real crowdsensing systems demonstrate the superior performance of V-PATD in terms of accuracy, computation and communication overheads. Guowen Xu, Hongwei Li 0001, Shengmin Xu, Hao Ren 0001, Yinghui Zhang 0002, Jianfei Sun, Robert H. Deng |
AsiaCCS | 7 |
| 2020 | Understanding Android VoIP Security: A System-Level Vulnerability Assessment
En He, Daoyuan Wu, Robert H. Deng |
DIMVA | 3 |
| 2020 | Pine: Enabling Privacy-Preserving Deep Packet Inspection on TLS with Rule-Hiding and Fast Connection Establishment
Jianting Ning, Xinyi Huang 0001, Geong Sen Poh, Shengmin Xu, Jia-Ch'ng Loh, Jian Weng 0001, Robert H. Deng |
ESORICS (1) | 7 |
| 2020 | Boosting Privately: Federated Extreme Gradient Boosting for Mobile CrowdsensingabstractRecently, Google and other 24 institutions proposed a series of open challenges towards federated learning (FL), which include application expansion and homomorphic encryption (HE). The former aims to expand the applicable machine learning models of FL. The latter focuses on who holds the secret key when applying HE to FL. For the naive HE scheme, the server is set to master the secret key. Such a setting causes a serious problem that if the server does not conduct aggregation before decryption, a chance is left for the server to access the user’s update. Inspired by the two challenges, we propose FEDXGB, a federated extreme gradient boosting (XGBoost) scheme supporting forced aggregation. FEDXGB mainly achieves the following two breakthroughs. First, FEDXGB involves a new HE based secure aggregation scheme for FL. By combining the advantages of secret sharing and homomorphic encryption, the algorithm can solve the second challenge mentioned above, and is robust to the user dropout. Then, FEDXGB extends FL to a new machine learning model by applying the secure aggregation scheme to the classification and regression tree building of XGBoost. Moreover, we conduct a comprehensive theoretical analysis and extensive experiments to evaluate the security, effectiveness, and efficiency of FEDXGB. The results indicate that FEDXGB achieves less than 1% accuracy loss compared with the original XGBoost, and can provide about 23.9% runtime and 33.3% communication reduction for HE based model update aggregation of FL. Yang Liu 0118, Zhuo Ma 0001, Ximeng Liu, Siqi Ma 0001, Surya Nepal, Robert H. Deng, Kui Ren 0001 |
ICDCS | 6 |
| 2020 | A Deep Learning Framework Supporting Model Ownership Protection and Traitor TracingabstractCloud-based deep learning (DL) solutions have been widely used in applications ranging from image recognition to speech recognition. Meanwhile, as commercial software and services, such solutions have raised the need for intellectual property rights protection of the underlying DL models. Watermarking is the mainstream of existing solutions to address this concern, by primarily embedding pre-defined secrets in a model's training process. However, existing efforts almost exclusively focus on detecting whether a target model is pirated, without considering traitor tracing. In this paper, we present SecureMark_DL, which enables a model owner to embed a unique fingerprint for every customer within parameters of a DL model, extract and verify the fingerprint from a pirated model, and hence trace the rogue customer who illegally distributed his model for profits. We demonstrate that SecureMark_DL is robust against various attacks including fingerprints collusion and network transformation (e.g., model compression and model fine-tuning). Extensive experiments conducted on MNIST and CIFAR10 datasets, as well as various types of deep neural network show the superiority of SecureMark_DL in terms of training accuracy and robustness against various types of attacks. Guowen Xu, Hongwei Li 0001, Yuan Zhang 0006, Xiaodong Lin 0001, Robert H. Deng, Xuemin Shen |
ICPADS | 5 |
| 2020 | Search Me in the Dark: Privacy-preserving Boolean Range Query over Encrypted Spatial DataabstractWith the increasing popularity of geo-positioning technologies and mobile Internet, spatial keyword data services have attracted growing interest from both the industrial and academic communities in recent years. Meanwhile, a massive amount of data is increasingly being outsourced to cloud in the encrypted form for enjoying the advantages of cloud computing while without compromising data privacy. Most existing works primarily focus on the privacy-preserving schemes for either spatial or keyword queries, and they cannot be directly applied to solve the spatial keyword query problem over encrypted data. In this paper, we study the challenging problem of Privacy-preserving Boolean Range Query (PBRQ) over encrypted spatial databases. In particular, we propose two novel PBRQ schemes. Firstly, we present a scheme with linear search complexity based on the space-filling curve code and Symmetric-key Hidden Vector Encryption (SHVE). Then, we use tree structures to achieve faster-than-linear search complexity. Thorough security analysis shows that data security and query privacy can be guaranteed during the query process. Experimental results using real-world datasets show that the proposed schemes are efficient and feasible for practical applications, which is at least ×70 faster than existing techniques in the literature. Xiangyu Wang 0010, Jianfeng Ma 0001, Ximeng Liu, Robert H. Deng, Yinbin Miao, Dan Zhu 0001, Zhuoran Ma 0002 |
INFOCOM | 4 |
| 2020 | A New Construction for Linkable Secret HandshakeabstractAbstract In this paper, we introduce a new construction for linkable secret handshake that allows authenticated users to perform handshake anonymously within allowable times. We define formal security models for the new construction, and prove that it can achieve session key security, anonymity, untraceability and linkable affiliation-hiding. In particular, the proposed construction ensures that (i) anyone can trace the real identities of dishonest users who perform handshakes for more than k times; and (ii) an optimal communication cost between authorized users is achieved by exploiting the proof of knowledges. Yangguang Tian, Yingjiu Li, Robert H. Deng, Nan Li 0007, Guomin Yang, Zheng Yang 0001 |
Comput. J. | 3 |
| 2020 | Game theoretical study on client-controlled cloud data deduplication
Xueqin Liang, Zheng Yan 0002, Robert H. Deng |
Comput. Secur. | 3 |
| 2020 | Server-aided revocable attribute-based encryption for cloud computing servicesabstractSummary Attribute‐based encryption (ABE) has been regarded as a promising solution in cloud computing services to enable scalable access control without compromising the security. Despite of the advantages, efficient user revocation has been a challenge in ABE. One suggestion for user revocation is using the binary tree in the key generation phase of an ABE scheme, which enables a trusted key generation center to periodically distribute the key update information to all nonrevoked users over a public channel. This revocation approach reduces the size of key updates from linear to logarithmic in the number of users. But it requires each user to keep a private key of the logarithmic size, and asks each nonrevoked user to periodically update his/her decryption key for each new time period. To further optimize user revocation in ABE, a server‐aided revocable ABE (SR‐ABE) scheme has been proposed, in which almost all workloads of users incurred by the user revocation are outsourced to an untrusted server, and each user only needs to store a private key of the constant size. In addition, SR‐ABE does not require any secure channel for the key transmission, and a user only needs to perform a small amount of calculations to decrypt a ciphertext. In this paper, we revisit the notion of SR‐ABE, and present a generic construction of SR‐ABE, which can transform a revocable ABE (RABE) scheme to an SR‐ABE scheme. In addition, we give an instantiation of SR‐ABE by applying the generic construction on a concrete RABE scheme, and implement an instantiation of SR‐ABE and an RABE scheme to evaluate the performance of SR‐ABE. Hui Cui 0001, Tsz Hon Yuen, Robert H. Deng, Guilin Wang |
Concurr. Comput. Pract. Exp. | 3 |
| 2020 | Lightning-fast and privacy-preserving outsourced computation in the cloudabstractAbstract In this paper, we propose a framework for lightning-fast privacy-preserving outsourced computation framework in the cloud, which we refer to as LightCom. Using LightCom, a user can securely achieve the outsource data storage and fast, secure data processing in a single cloud server different from the existing multi-server outsourced computation model. Specifically, we first present a general secure computation framework for LightCom under the cloud server equipped with multiple Trusted Processing Units (TPUs), which face the side-channel attack. Under the LightCom, we design two specified fast processing toolkits, which allow the user to achieve the commonly-used secure integer computation and secure floating-point computation against the side-channel information leakage of TPUs, respectively. Furthermore, our LightCom can also guarantee access pattern protection during the data processing and achieve private user information retrieve after the computation. We prove that the proposed LightCom can successfully achieve the goal of single cloud outsourced data processing to avoid the extra computation server and trusted computation server, and demonstrate the utility and the efficiency of LightCom using simulations. Ximeng Liu, Robert H. Deng, Pengfei Wu 0003, Yang Yang 0026 |
Cybersecur. | 2 |
| 2020 | Special Issue on FinTech Security and Privacy
Kuo-Hui Yeh, Robert H. Deng, Hiroaki Kikuchi |
Future Gener. Comput. Syst. | 2 |
| 2020 | Editing-Enabled Signatures: A New Tool for Editing Authenticated DataabstractData authentication primarily serves as a tool to achieve data integrity and source authentication. However, traditional data authentication does not fit well where an intermediate entity (editor) is required to modify the authenticated data provided by the source/data owner before sending the data to other recipients. To ask the data owner for authenticating each modified data can lead to higher communication overhead. In this article, we introduce the notion of editing-enabled signatures where the data owner can choose any set of modification operations applicable on the data and still can restrict any possibly untrusted editor to authenticate the data modified using an operation from this set only. Moreover, the editor does not need to interact with the data owner in order to authenticate the data every time it is modified. We construct an editing-enabled signature (EES) scheme that derives its efficiency from mostly lightweight cryptographic primitives. We formalize the security model for editing-enabled signatures and analyze the security of our EES scheme. Editing-enabled signatures can find numerous applications that involve generic editing tasks and privacy-preserving operations. We demonstrate how our EES scheme can be applied in two privacy-preserving applications. Binanda Sengupta, Yingjiu Li, Yangguang Tian, Robert H. Deng |
IEEE Internet Things J. | 4 |
| 2020 | Lightweight and Privacy-Aware Fine-Grained Access Control for IoT-Oriented Smart HealthabstractWith the booming of Internet of Things (IoT), smart health (s-health) is becoming an emerging and attractive paradigm. It can provide an accurate prediction of various diseases and improve the quality of healthcare. Nevertheless, data security and user privacy concerns still remain issues to be addressed. As a high potential and prospective solution to secure IoT-oriented s-health applications, ciphertext policy attribute-based encryption (CP-ABE) schemes raise challenges, such as heavy overhead and attribute privacy of the end users. To resolve these drawbacks, an optimized vector transformation approach is first proposed to efficiently transform the access policy and user attribute set into respective vectors of shorter length while other approaches result in redundant and longer vectors. Our transformation approach can greatly relieve the costly overheard of key generation, encryption, and decryption phases. Then, based on the transformation approach and the offline/online computation technology, we propose a lightweight policy-hiding CP-ABE scheme for the IoT-oriented s-health application. With our proposed scheme, data users in the s-health system can perform lightweight encryption and decryption without leaking any sensitive privacy about the attributes of the user. Finally, the formal security analysis, the theoretic performance evaluation and experiment results indicate that the solution is secure and efficient. Jianfei Sun, Hu Xiong, Ximeng Liu, Yinghui Zhang 0002, Xuyun Nie, Robert H. Deng |
IEEE Internet Things J. | 6 |
| 2020 | Key regeneration-free ciphertext-policy attribute-based encryption and its application
Hui Cui 0001, Robert H. Deng, Baodong Qin, Jian Weng 0001 |
Inf. Sci. | 2 |
| 2020 | Secure server-aided data sharing clique with attestation
HweeHwa Pang, Robert H. Deng, Yong Ding 0005, Qianhong Wu, Kefeng Fan |
Inf. Sci. | 3 |
| 2020 | A new framework for privacy-preserving biometric-based remote user authenticationabstractIn this paper, we introduce the first general framework for strong privacy-preserving biometric-based remote user authentication based on oblivious RAM (ORAM) protocol and computational fuzzy extractors. We define formal security models for the general framework, and we prove that it can achieve user authenticity and strong privacy. In particular, the general framework ensures that: (1) a strong privacy and a log-linear time-complexity are achieved by using a new tree-based ORAM protocol; (2) a constant bandwidth cost is achieved by exploiting computational fuzzy extractors in the challenge-response phase of remote user authentications. Yangguang Tian, Yingjiu Li, Robert H. Deng, Nan Li 0007, Pengfei Wu 0003, Anyi Liu |
J. Comput. Secur. | 3 |
| 2020 | Privacy-Preserving Outsourced Support Vector Machine Design for Secure Drug DiscoveryabstractIn this paper, we propose a framework for privacy-preserving outsourced drug discovery in the cloud, which we refer to as POD. Specifically, POD is designed to allow the cloud to securely use multiple drug formula providers' drug formulas to train Support Vector Machine (SVM) provided by the analytical model provider. In our approach, we design secure computation protocols to allow the cloud server to perform commonly used integer and fraction computations. To securely train the SVM, we design a secure SVM parameter selection protocol to select two SVM parameters and construct a secure sequential minimal optimization protocol to privately refresh both selected SVM parameters. The trained SVM classifier can be used to determine whether a drug chemical compound is active or not in a privacy-preserving way. Lastly, we prove that the proposed POD achieves the goal of SVM training and chemical compound classification without privacy leakage to unauthorized parties, as well as demonstrating its utility and efficiency using three real-world drug datasets. Ximeng Liu, Robert H. Deng, Kim-Kwang Raymond Choo, Yang Yang 0026 |
IEEE Trans. Cloud Comput. | 2 |
| 2020 | Lightweight Sharable and Traceable Secure Mobile Health SystemabstractMobile health (mHealth) has emerged as a new patient centric model which allows real-time collection of patient data via wearable sensors, aggregation and encryption of these data at mobile devices, and then uploading the encrypted data to the cloud for storage and access by healthcare staff and researchers. However, efficient and scalable sharing of encrypted data has been a very challenging problem. In this paper, we propose a Lightweight Sharable and Traceable (LiST) secure mobile health system in which patient data are encrypted end-to-end from a patient's mobile device to data users. LiST enables efficient keyword search and fine-grained access control of encrypted data, supports tracing of traitors who sell their search and access privileges for monetary gain, and allows on-demand user revocation. LiST is lightweight in the sense that it offloads most of the heavy cryptographic computations to the cloud while only lightweight operations are performed at the end user devices. We formally define the security of LiST and prove that it is secure without random oracle. We also conduct extensive experiments to access the system's performance. Yang Yang 0026, Ximeng Liu, Robert H. Deng, Yingjiu Li |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2020 | Privacy-Preserving Data Processing with Flexible Access ControlabstractCloud computing provides an efficient and convenient platform for cloud users to store, process and control their data. Cloud overcomes the bottlenecks of resource-constrained user devices and greatly releases their storage and computing burdens. However, due to the lack of full trust in cloud service providers, the cloud users generally prefer to outsource their sensitive data in an encrypted form, which, however, seriously complicates data processing, analysis, as well as access control. Homomorphic encryption (HE) as a single key system cannot flexibly control data sharing and access after encrypted data processing. How to realize various computations over encrypted data in an efficient way and at the same time flexibly control the access to data processing results has been an important challenging issue. In this paper, we propose a privacy-preserving data processing scheme with flexible access control. With the cooperation of a data service provider (DSP) and a computation party (CP), our scheme, based on Paillier's partial homomorphic encryption (PHE), realizes seven basic operations, i.e., Addition, Subtraction, Multiplication, Sign Acquisition, Absolute, Comparison, and Equality Test, over outsourced encrypted data. In addition, our scheme, based on the homomorphism of attribute-based encryption (ABE), is also designed to support flexible access control over processing results of encrypted data. We further prove the security of our scheme and demonstrate its efficiency and advantages through simulations and comparisons with existing work. Wenxiu Ding, Zheng Yan 0002, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2020 | Privacy-Preserving Outsourced Calculation Toolkit in the CloudabstractIn this paper, we propose a privacy-preserving outsourced calculation toolkit, Pockit, designed to allow data owners to securely outsource their data to the cloud for storage. The outsourced encrypted data can be processed by the cloud server to achieve commonly-used plaintext arithmetic operations without involving additional servers. Specifically, we design both signed and unsigned integer circuits using a fully homomorphic encryption (FHE) scheme, construct a new packing technique (hereafter referred to as integer packing), and extend the secure circuits to its packed version. This achieves significant improvements in performance compared with the original secure signed/unsigned integer circuit. The secure integer circuits can be used to construct a new data mining application, which we refer to as secure k-nearest neighbours classifier, without compromising the privacy of original data. Finally, we prove that the proposed Pockit achieves the goal of secure computation without privacy leakage to unauthorized parties, and demonstrate the utility and efficiency of Pockit. Ximeng Liu, Robert H. Deng, Kim-Kwang Raymond Choo, Yang Yang 0026, HweeHwa Pang |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2020 | Multi-User Verifiable Searchable Symmetric Encryption for Cloud StorageabstractIn a cloud data storage system, symmetric key encryption is usually used to encrypt files due to its high efficiency. In order allow the untrusted/semi-trusted cloud storage server to perform searching over encrypted data while maintaining data confidentiality, searchable symmetric encryption (SSE) has been proposed. In a typical SSE scheme, a users stores encrypted files on a cloud storage server and later can retrieve the encrypted files containing specific keywords. The basic security requirement of SSE is that the cloud server learns no information about the files or the keywords during the searching process. Some SSE schemes also offer additional functionalities such as detecting cheating behavior of a malicious server (i.e., verifiability) and allowing update (e.g., modifying, deleting and adding) of documents on the server. However, the previous (verifiable) SSE schemes were designed for single users, which means the searching can only be done by the data owner, whereas in reality people often use cloud storage to share files with other users. In this paper we present a multi-user verifiable searchable symmetric encryption (MVSSE) scheme that achieves all the desirable features of a verifiable SSE and allows multiple users to perform searching. We then define an ideal functionality for MVSSE under the Universally Composable (UC-) security framework and prove that our ideal functionality implies the security requirements of a secure MVSSE, and our multi-user verifiable SSE scheme is UC-secure. We also implement our scheme to verify its high performance based on some real dataset. Xueqiao Liu, Guomin Yang, Yi Mu 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2020 | Multi-User Multi-Keyword Rank Search Over Encrypted Data in Arbitrary LanguageabstractMulti-keyword rank searchable encryption (MRSE) returns the top-k results in response to a data user's request of multi-keyword search over encrypted data, and hence provides an efficient way for preserving data privacy in cloud storage systems while without loss of data usability. Many existing MRSE systems are constructed based on an algorithm which we term as k-nearest neighbor for searchable encryption (KNN-SE). Unfortunately, KNN-SE has a number of shortcomings, which limit its practical applications. In this paper, we propose a new MRSE system which overcomes almost all the defects of the KNN-SE based MRSE systems. Specifically, our new system does not require a predefined keyword set and supports keywords in arbitrary languages, is a multi-user system which supports flexible search authorization and time-controlled revocation, and it achieves better data privacy protection since even the cloud server is not able to tell which documents are the top-k results returned to a data user. We also conduct extensive experiments to demonstrate the efficiency of the new system. Yang Yang 0026, Ximeng Liu, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2020 | Identity-Based Encryption Transformation for Flexible Sharing of Encrypted Data in Public CloudabstractWith the rapid development of cloud computing, an increasing number of individuals and organizations are sharing data in the public cloud. To protect the privacy of data stored in the cloud, a data owner usually encrypts his data in such a way that certain designated data users can decrypt the data. This raises a serious problem when the encrypted data needs to be shared to more people beyond those initially designated by the data owner. To address this problem, we introduce and formalize an identity-based encryption transformation (IBET) model by seamlessly integrating two well-established encryption mechanisms, namely identity-based encryption (IBE) and identity-based broadcast encryption (IBBE). In IBET, data users are identified and authorized for data access based on their recognizable identities, which avoids complicated certificate management in usual secure distributed systems. More importantly, IBET provides a transformation mechanism that converts an IBE ciphertext into an IBBE ciphertext so that a new group of users not specified during the IBE encryption can access the underlying data. We design a concrete IBET scheme based on bilinear groups and prove its security against powerful attacks. Thorough theoretical and experimental analyses demonstrate the high efficiency and practicability of the proposed scheme. Zheng Qin 0001, Qianhong Wu, Zhenyu Guan 0002, Robert H. Deng, Yunya Zhou |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2020 | Guest Editorial: Blockchain and Healthcare ComputingabstractThe four papers in this special section focus on the use of blockchain in the healthcare field. With the development of society, health has received increasing attentions. The development of science and technology has also promoted the protection of health. In recent years, the rapid development of computing and networking technologies has improved the ability to collect, measure, and analyze health-related data, and thus tremendous opportunities have opened up for healthcare computing. Meanwhile, these technologies have also brought new challenges and issues. Yulei Wu, Zheng Yan 0002, F. Richard Yu, Robert H. Deng, Vijay Varadharajan, Wei Chen 0015 |
IEEE J. Biomed. Health Informatics | 4 |
| 2020 | An Extended Framework of Privacy-Preserving Computation With Flexible Access ControlabstractCloud computing offers various services based on outsourced data by utilizing its huge volume of resources and great computation capability. However, it also makes users lose full control over their data. To avoid the leakage of user data privacy, encrypted data are preferred to be uploaded and stored in the cloud, which unfortunately complicates data analysis and access control. In particular, few existing works consider the fine-grained access control over the computational results from ciphertexts. Though our previous work proposed a framework to support several basic computations (such as addition, multiplication and comparison) with flexible access control, privacy-preserving division calculations over encrypted data, as a crucial operation in many statistical processes and machine learning algorithms, is neglected. In this paper, we propose four privacy-preserving division computation schemes with flexible access control to fill this gap, which can adapt to various application scenarios. Furthermore, we extend a division scheme over encrypted integers to support privacy-preserving division over multiple data types including fixed-point numbers and fractional numbers. Finally, we give their security proof and show their efficiency and superiority through comprehensive simulations and comparisons with existing work. Wenxiu Ding, Zheng Yan 0002, Xinren Qian, Robert H. Deng, Laurence T. Yang, Mianxiong Dong |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2020 | Privacy-preserving Network Path ValidationabstractThe end-users communicating over a network path currently have no control over the path. For a better quality of service, the source node often opts for a superior (or premium) network path to send packets to the destination node. However, the current Internet architecture provides no assurance that the packets indeed follow the designated path. Network path validation schemes address this issue and enable each node present on a network path to validate whether each packet has followed the specific path so far. In this work, we introduce two notions of privacy— path privacy and index privacy —in the context of network path validation. We show that, in case a network path validation scheme does not satisfy these two properties, the scheme is vulnerable to certain practical attacks (that affect the privacy, reliability, neutrality and quality of service offered by the underlying network). To the best of our knowledge, ours is the first work that addresses privacy issues related to network path validation. We design PrivNPV, a privacy-preserving network path validation protocol, that satisfies both path privacy and index privacy. We discuss several attacks related to network path validation and how PrivNPV defends against these attacks. Finally, we discuss the practicality of PrivNPV based on relevant parameters. Binanda Sengupta, Yingjiu Li, Kai Bu, Robert H. Deng |
ACM Trans. Internet Techn. | 4 |
| 2020 | Flexible Wildcard Searchable Encryption SystemabstractSearchable encryption is an important technique for public cloud storage service to provide user data confidentiality protection and at the same time allow users performing keyword search over their encrypted data. Previous schemes only deal with exact or fuzzy keyword search to correct some spelling errors. In this paper, we propose a new wildcard searchable encryption system to support wildcard keyword queries which has several highly desirable features. First, our system allows multiple keywords search in which any queried keyword may contain zero, one or two wildcards, and a wildcard may appear in any position of a keyword and represent any number of symbols. Second, it supports simultaneous search on multiple data owner's data using only one trapdoor. Third, it provides flexible user authorization and revocation to effectively manage search and decryption privileges. Fourth, it is constructed based on homomorphic encryption rather than Bloom filter and hence completely eliminates the false probability caused by Bloom filter. Finally, it achieves a high level of privacy protection since matching results are unknown to the cloud server in the test phase. The proposed system is thoroughly analyzed and is proved secure. Extensive experimental results indicate that our system is efficient compared with other existing wildcard searchable encryption schemes in the public key setting. Yang Yang 0026, Ximeng Liu, Robert H. Deng, Jian Weng 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2019 | An empirical study of SMS one-time password authentication in Android appsabstractA great quantity of user passwords nowadays has been leaked through security breaches of user accounts. To enhance the security of the Password Authentication Protocol (PAP) in such circumstance, Android app developers often implement a complementary One-Time Password (OTP) authentication by utilizing the short message service (SMS). Unfortunately, SMS is not specially designed as a secure service and thus an SMS One-Time Password is vulnerable to many attacks. To check whether a wide variety of currently used SMS OTP authentication protocols in Android apps are properly implemented, this paper presents an empirical study against them. We first derive a set of rules from RFC documents as the guide to implement secure SMS OTP authentication protocol. Then we implement an automated analysis system, AUTH-EYE, to check whether a real-world OTP authentication scheme violates any of these rules. Without accessing server source code, AUTH-EYE executes Android apps to trigger the OTP-relevant functionalities and then analyzes the OTP implementations including those proprietary ones. By only analyzing SMS responses, AUTH-EYE is able to assess the conformance of those implementations to our recommended rules and identify the potentially insecure apps. In our empirical study, AUTH-EYE analyzed 3,303 popular Android apps and found that 544 of them adopt SMS OTP authentication. The further analysis of AUTH-EYE demonstrated a far-from-optimistic status: the implementations of 536 (98.5%) out of the 544 apps violate at least one of our defined rules. The results indicate that Android app developers should seriously consider our discussed security rules and violations so as to implement SMS OTP properly. Siqi Ma 0001, Runhan Feng, Juanru Li, Yang Liu 0118, Surya Nepal, Diethelm Ostry, Elisa Bertino, Robert H. Deng, Zhuo Ma 0001, Sanjay K. Jha |
ACSAC | 8 |
| 2019 | A Closer Look Tells More: A Facial Distortion Based Liveness Detection for Face AuthenticationabstractFace authentication is vulnerable to media-based virtual face forgery (MVFF) where adversaries display photos/videos or 3D virtual face models of victims to spoof face authentication systems. In this paper, we propose a liveness detection mechanism, called FaceCloseup, to protect the face authentication on mobile devices. FaceCloseup detects MVFF-based attacks by analyzing the distortion of face regions in a user's closeup facial videos captured by built-in camera on mobile device. It can detect MVFF-based attacks with an accuracy of 99.48%. Yan Li 0075, Zilong Wang 0001, Yingjiu Li, Robert H. Deng, Binbin Chen 0001, Weizhi Meng 0001, Hui Li 0006 |
AsiaCCS | 4 |
| 2019 | Towards Understanding Android System Vulnerabilities: Techniques and InsightsabstractAs a common platform for pervasive devices, Android has been targeted by numerous attacks that exploit vulnerabilities in its apps and the operating system. Compared to app vulnerabilities, system-level vulnerabilities in Android, however, were much less explored in the literature. In this paper, we perform the first systematic study of Android system vulnerabilities by comprehensively analyzing all 2,179 vulnerabilities on the Android Security Bulletin program over about three years since its initiation in August 2015. To this end, we propose an automatic analysis framework, upon a hierarchical database structure, to crawl, parse, clean, and analyze vulnerability reports and their publicly available patches. This framework includes (i) a lightweight technique to pinpoint the affected modules of given vulnerabilities; (ii) a robust method to study the complexity of patch code; and most importantly, (iii) a similarity-based algorithm to cluster patch code patterns. Our clustering algorithm first extracts patch code's essential changes that not only concisely reflect syntactic changes but also keep important semantics, and then leverages affinity propagation to automatically generate clusters based on their pairwise similarity. It allows us to obtain 16 vulnerability patterns, including six new ones not known in the literature, and we further analyze their characteristics via case studies. Besides identifying these useful patterns, we also find that 92% Android vulnerabilities are located in the low-level modules (mostly in native libraries and the kernel), whereas the framework layer causes only 5% vulnerabilities, and that half of the vulnerabilities can be fixed in fewer than 10 lines of code each, with 110 out of 1,158 cases requiring only one single line of code change. We further discuss the implications of all these results. Overall, we provide a clear overview and new insights about Android system vulnerabilities. Daoyuan Wu, Debin Gao, Eric K. T. Cheng, Yichen Cao, Jintao Jiang, Robert H. Deng |
AsiaCCS | 6 |
| 2019 | ObliDC: An SGX-based Oblivious Distributed Computing Framework with Formal ProofabstractData privacy is becoming one of the most critical concerns in cloud computing. Several proposals based on Intel SGX such as VC3 [1] and M2R [2] have been introduced in the literature to protect data privacy during job execution in the cloud. However, a comprehensive formal proof of their security guarantees is still lacking. In this paper, we propose ObliDC, a general UC-secure SGX-based oblivious distributed computing framework. First, we model the life-cycle of a distributed computing job as data-flow graphs. Under the assumption of malicious, adaptive adversaries in the cloud, we then formally define data privacy of a distributed computing job by introducing a notion named ODC-privacy, which encompasses both semantic security (to protect data confidentiality during computation and transmission) and oblivious traffic (to prevent data leakage from traffic analysis). ObliDC is composed of four two-party protocols -- job deployment, job initialization, job execution, and results return, which allow for modular construction of concrete privacy-preserving job protocols in different distributed computing frameworks. Finally, inspired by a formal abstraction for trusted processors proposed by R. Pass et al. [3], we formally prove the security of ObliDC under the universal composability (UC) framework. Pengfei Wu 0003, Qingni Shen, Robert H. Deng, Ximeng Liu, Yinghui Zhang 0002, Zhonghai Wu |
AsiaCCS | 3 |
| 2019 | Finding Flaws from Password Authentication Code in Android Apps
Siqi Ma 0001, Elisa Bertino, Surya Nepal, Juanru Li, Diethelm Ostry, Robert H. Deng, Sanjay K. Jha |
ESORICS (1) | 6 |
| 2019 | DroidEvolver: Self-Evolving Android Malware Detection SystemabstractGiven the frequent changes in the Android framework and the continuous evolution of Android malware, it is challenging to detect malware over time in an effective and scalable manner. To address this challenge, we propose DroidEvolver, an Android malware detection system that can automatically and continually update itself during malware detection without any human involvement. While most existing malware detection systems can be updated by retraining on new applications with true labels, DroidEvolver requires neither retraining nor true labels to update itself, mainly due to the insight that DroidEvolver makes necessary and lightweight update using online learning techniques with evolving feature set and pseudo labels. The detection performance of DroidEvolver is evaluated on a dataset of 33,294 benign applications and 34,722 malicious applications developed over a period of six years. Using 6,286 applications dated in 2011 as the initial training set, DroidEvolver achieves high detection F-measure (95.27%), which only declines by 1.06% on average per year over the next five years for classifying 57,539 newly appeared applications. Note that such new applications could use new techniques and new APIs, which are not known to DroidEvolver when initialized with 2011 applications. Compared with the state-of-the-art overtime malware detection system MAMADROID, the F-measure of DroidEvolver is 2.19 times higher on average (10.21 times higher for the fifth year), and the efficiency of DroidEvolver is 28.58 times higher than MAMADROID during malware detection. DroidEvolver is also shown robust against typical code obfuscation techniques. Yingjiu Li, Robert H. Deng, Jiayun Xu |
EuroS&P | 3 |
| 2019 | Computing Maximum and Minimum with Privacy Preservation and Flexible Access ControlabstractWith the fast development of Internet of Things, huge volume of data is being collected from various sensors and devices, aggregated at gateways, and processed in the cloud. Due to privacy concern, data are usually encrypted before being outsourced to the cloud. However, encryption seriously impedes both computation over the data and sharing of the computation results. Computing maximum and minimum among a data set are two of the most basic operations in machine learning and data mining algorithms. In this paper, we study how to compute maximum and minimum over encrypted data and control the access to the computation result in a privacy-preserving manner. We present four schemes to realize privacy-preserving maximum and minimum computations with flexible access control that can adapt to various application scenarios. We further analyze their security and show their efficiency through extensive evaluations and comparisons with existing work. Wenxiu Ding, Zheng Yan 0002, Xinren Qian, Robert H. Deng |
GLOBECOM | 4 |
| 2019 | Understanding Open Ports in Android Applications: Discovery, Diagnosis, and Security Assessment
Daoyuan Wu, Debin Gao, Rocky K. C. Chang, En He, Eric K. T. Cheng, Robert H. Deng |
NDSS | 6 |
| 2019 | When Human cognitive modeling meets PINs: User-independent inter-keystroke timing attacks
Yingjiu Li, Robert H. Deng, Bing Chang, Shujun Li 0001 |
Comput. Secur. | 3 |
| 2019 | A blockchain-based location privacy-preserving crowdsensing system
Mengmeng Yang 0002, Tianqing Zhu, Kaitai Liang, Wanlei Zhou 0001, Robert H. Deng |
Future Gener. Comput. Syst. | 5 |
| 2019 | Toward Highly Secure Yet Efficient KNN Classification Scheme on Outsourced Cloud DataabstractNowadays, outsourcing data and machine learning tasks, e.g.,$k$-nearest neighbor (KNN) classification, to clouds has become a scalable and cost-effective way for large scale data storage, management, and processing. However, data security and privacy issue have been a serious concern in outsourcing data to clouds. In this article, we propose a privacy-preserving KNN classification scheme on cloud data in a twin-cloud model based on an additively homomorphic cryptosystem and secret sharing. Compared with existing works, we redesign a set of lightweight building blocks, such as secure square Euclidean distance, secure comparison, secure sorting, secure minimum, and maximum number finding, and secure frequency calculating, which achieve the same security level but with higher efficiency. In our scheme, data owners stay offline, which is different from secure-multiparty computation-based solutions which require data owners’ stay online during computation. In addition, query users do not interact with the cloud except sending query data and receiving the query results. Our security analysis shows that the scheme protects outsourced data security and query privacy, and hides access patterns. The experiments on real-world dataset indicate that our scheme is significantly more efficient than existing schemes. Lin Liu 0018, Jinshu Su, Ximeng Liu, Rongmao Chen, Robert H. Deng, Xiaofeng Wang 0002 |
IEEE Internet Things J. | 6 |
| 2019 | Fair and Dynamic Data Sharing Framework in Cloud-Assisted Internet of EverythingabstractCloud-assisted Internet of Things (IoT) is increasingly prevalent in our society, for example in home and office environment; hence, it is also known as cloud-assisted Internet of Everything (IoE). While in such a setup, data can be easily shared and disseminated (e.g., between a device, such as Amazon Echo and the cloud, such as Amazon AWS), there are potential security considerations that need to be addressed. Thus, a number of security solutions have been proposed. For example, searchable encryption (SE) has been extensively studied due to its capability to facilitate searching of encrypted data. However, threat models in most existing SE solutions rarely consider the malicious data owner and semi-trusted cloud server at the same time, particularly in dynamic applications. In a real-world deployment, disputes between above two parties may arise as either party will accuse the other of some misbehavior. Furthermore, efficient full-update operations (e.g., data modification, data insertion, and data deletion) are not typically supported in the cloud-assisted IoE deployment. Therefore, in this paper, we present a fair and dynamic data sharing framework (FairDynDSF) in the multiowner setting. Using FairDynDSF, one can check the correctness of search results, achieve fair arbitration, multikeyword search, and dynamic update. We also prove that FairDynDSF is secure against inside keyword guessing attack and demonstrate its efficiency by evaluating its performance using various datasets. Yinbin Miao, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng, Hongjun Wu 0001, Hongwei Li 0001 |
IEEE Internet Things J. | 4 |
| 2019 | Secure Online/Offline Data Sharing Framework for Cloud-Assisted Industrial Internet of ThingsabstractCiphertext-policy attribute-based keyword search (CP-ABKS) schemes facilitate the fine-grained keyword search over encrypted data, such as those sensed/collected from Industrial Internet of Things (IIoT) devices and stored in the cloud. However, existing CP-ABKS schemes generally have significant computation and storage requirements, which are beyond those of resource-constrained IIoT devices. Therefore, in this paper, we design a secure online/offline data sharing framework (DSF), which supports online/offline encryption and outsourced decryption. Using the healthcare setting as a case study, we demonstrate how DSF can be deployed in the cloud-assisted Healthcare IIoT (HealthIIoT) system. We not only prove that the DSF is selectively secure in the chosen access structure security model but also demonstrate its efficiency and feasibility in practical scenarios using experiments. Yinbin Miao, Qiuyun Tong, Kim-Kwang Raymond Choo, Ximeng Liu, Robert H. Deng, Hongwei Li 0001 |
IEEE Internet Things J. | 5 |
| 2019 | SybSub: Privacy-Preserving Expressive Task Subscription With Sybil Detection in CrowdsourcingabstractThe past decade has witnessed the rise of crowdsourcing, and privacy in crowdsourcing has also gained rising concern in the meantime. Task matching or task subscription is one of indispensable services in crowdsourcing, but few mechanisms can achieve the expressive task subscription while protecting the privacy. In this paper, we focus on the privacy leaks and attacks during task subscription in crowdsourcing, and propose a privacy-preserving task subscription scheme with sybil detection, called SybSub. The SybSub scheme achieves the expressiveness of task subscription in the multisubscriber and multipublisher crowdsourcing while protecting the privacy of both subscribers and publishers against the semi-honest crowdsourcing service provider, and meanwhile supports the sybil attack detection against greedy subscribers. We implement the SybSub scheme and evaluate it thoroughly. Performance results validate that the SybSub scheme is efficient and feasible. Jiangang Shu, Ximeng Liu, Kan Yang 0001, Yinghui Zhang 0002, Xiaohua Jia, Robert H. Deng |
IEEE Internet Things J. | 6 |
| 2019 | Situation-Aware Authenticated Video Broadcasting Over Train-Trackside WiFi NetworksabstractLive video programs can bring in better travel experience for subway passengers and earn abundant advertisement revenue for subway operators. However, because the train-trackside channels for video dissemination are easily accessible to anyone, the video traffic are vulnerable to attacks, which may cause deadly tragedies. This paper presents a situation-aware authenticated video broadcasting scheme in the railway network, which consists of train, on-board sensor, trackside global system for mobile communications-railway (GSM-R) device, WiFi access point (AP), and train control center. Specifically, the scheme has four modules: 1) a train uses its on-board sensors to obtain its speed, location, and received signal strength indicator of train-trackside WiFi channel; 2) the train reports these real-time measurements to the railway control center with the legacy GSM-R networks; 3) according to the measurements, the control center or its WiFi AP adaptively customizes the protected codestream bitrate and AP-train handover time; and 4) the train renders the received codestream, which passes the authenticity verification process. As shown in the performance analysis, the present scheme ensures the codestream authenticity and provides high quality of service in the lossy subway WiFi environment. Yongdong Wu, Dengpan Ye, Zhuo Wei, Qian Wang 0002, William Tan, Robert H. Deng |
IEEE Internet Things J. | 6 |
| 2019 | Securing messaging services through efficient signcryption with designated equality test
HweeHwa Pang, Robert H. Deng, Yong Ding 0005, Qianhong Wu |
Inf. Sci. | 3 |
| 2019 | Collusion attacks and fair time-locked deposits for fast-payment transactions in BitcoinabstractIn Bitcoin network, the distributed storage of multiple copies of the block chain opens up possibilities for double-spending, i.e., a payer issues two separate transactions to two different payees transferring the same coins. While Bitcoin has inherent security mechanism to prevent double-spending attacks, it requires a certain amount of time to detect the double-spending attacks after the transaction has been initiated. Therefore, it is impractical to protect the payees from suffering in double-spending attacks in fast payment scenarios where the time between the exchange of currency and goods or services is shorten to few seconds. Although we cannot prevent double-spending attacks immediately for fast payments, decentralized non-equivocation contracts have been proposed to penalize the malicious payer after the attacks have been detected. The basic idea of these contracts is that the payer locks some coins in a deposit when he initiates a transaction with the payee. If the payer double-spends, a cryptographic primitive called accountable assertions can be used to reveal his Bitcoin credentials for the deposit. Thus, the malicious payer could be penalized by the loss of deposit coins. However, such decentralized non-equivocation contracts are subjected to collusion attacks where the payer colludes with the beneficiary of the depoist and transfers the Bitcoin deposit back to himself when he double-spends, resulting in no penalties. On the other hand, even if the beneficiary behaves honestly, the victim payee cannot get any compensation directly from the deposit in the original design. To prevent such collusion attacks, we design fair time-locked deposits for Bitcoin transactions to defend against double-spending. The fair deposits ensure that the payer will be penalized by the loss of his deposit coins if he double-spends and the victim payee’s loss will be compensated within a locked time period. We start with the protocols of making a deposit for one transaction. In particular, for the transaction with single input and output and the transaction with multiple inputs and outputs, we provide different designs of the deposits. We analyze the performance of deposits made for one transaction and show how the fair deposits work efficiently in Bitcoin. We also provide protocols of making a deposit for multiple transactions, which can reduce the burdens of a honest payer. In the end, we extend the fair deposits to non-equivocation contracts for other distributed systems. Xingjie Yu, Michael Thang Shiwen, Yingjiu Li, Robert H. Deng |
J. Comput. Secur. | 4 |
| 2019 | MicroBTC: Efficient, Flexible and Fair Micropayment for Bitcoin Using Hash Chains
Zhiguo Wan, Robert H. Deng |
J. Comput. Sci. Technol. | 2 |
| 2019 | Attribute-Based Storage Supporting Secure Deduplication of Encrypted Data in CloudabstractAttribute-based encryption (ABE) has been widely used in cloud computing where a data provider outsources his/her encrypted data to a cloud service provider, and can share the data with users possessing specific credentials (or attributes). However, the standard ABE system does not support secure deduplication, which is crucial for eliminating duplicate copies of identical data in order to save storage space and network bandwidth. In this paper, we present an attribute-based storage system with secure deduplication in a hybrid cloud setting, where a private cloud is responsible for duplicate detection and a public cloud manages the storage. Compared with the prior data deduplication systems, our system has two advantages. First, it can be used to confidentially share data with users by specifying access policies rather than sharing decryption keys. Second, it achieves the standard notion of semantic security for data confidentiality while existing systems only achieve it by defining a weaker security notion. In addition, we put forth a methodology to modify a ciphertext over one access policy into ciphertexts of the same plaintext but under other access policies without revealing the underlying plaintext. Hui Cui 0001, Robert H. Deng, Yingjiu Li |
IEEE Trans. Big Data | 2 |
| 2019 | Hybrid Keyword-Field Search With Efficient Key Management for Industrial Internet of ThingsabstractEquipped with the emerging cloud computing, clients prefer to outsource the increasing number of Industrial Internet of things (IIoT) data to cloud to reduce the high storage and computation burden. However, existing searchable encryption (SE) schemes just apply to IIoT records containing textual keyword fields rather than both digital and textual keyword ones. Besides, the key management issue still impedes the practicality and availability of SE schemes due to high key storage overhead. To this end, we present an outsourced Hybrid Keyword-Field Search over encrypted data with efficient Keys Management (HKFS-KM) scheme by utilizing the relevance score function and keyed hash tree. Formal security analysis proves that the HKFS-KM scheme can achieve keyword privacy and trapdoor unlinkability in both known ciphertexts attack model and known background attack model. Experimental results using real-world dataset show its efficiency and practicality in practice. Yinbin Miao, Ximeng Liu, Robert H. Deng, Hongjun Wu 0001, Hongwei Li 0001, Jiguo Li 0001, Dapeng Wu 0002 |
IEEE Trans. Ind. Informatics | 3 |
| 2019 | Efficient and Robust Certificateless Signature for Data Crowdsensing in Cloud-Assisted Industrial IoTabstractWith the digitalization of various industries, the combination of cloud computing and the industrial Internet of Things (IIoT) has become an attractive data processing paradigm. However, the cloud-assisted IIoT still has challenging issues, including authenticity of data, untrustworthiness of third parties, and system robustness and efficiency. Recently, a lightweight certificateless signature (CLS) scheme for the cloud-assisted IIoT, that was claimed to address both authenticity of data and untrustworthiness of third parties, has been proposed by Karati et al. (2018). In this paper, we demonstrate that the CLS scheme fails to achieve the claimed security properties by presenting four types of signature forgery attacks. We also propose a robust certificateless signature (RCLS) scheme to address the aforementioned challenges. Our RCLS only needs public channels and is proven secure against both public key replacement attacks and malicious-but-passive third parties in the standard model. Performance evaluation indicates that the RCLS scheme outperforms other CLS schemes and is suitable for the IIoT. Yinghui Zhang 0002, Robert H. Deng, Dong Zheng 0001, Jin Li 0002, Pengfei Wu 0003, Jin Cao 0001 |
IEEE Trans. Ind. Informatics | 2 |
| 2019 | An Attribute-Based Framework for Secure Communications in Vehicular Ad Hoc NetworksabstractIn this paper, we introduce an attribute-based framework to achieve secure communications in vehicular ad hoc networks (VANETs), which enjoys several advantageous features. The proposed framework employs attribute-based signature (ABS) to achieve message authentication and integrity and protect vehicle privacy, which greatly mitigates the overhead caused by pseudonym/private key change or update in the existing solutions for VANETs based on symmetric key, asymmetric key, and identity-based cryptography and group signature. In addition, we extend a standard ABS scheme with traceability and revocation mechanisms and seamlessly integrate them into the proposed framework to support vehicle traceability and revocation by a trusted authority, and thus, the resulting scheme for vehicular communications does not suffer from the anonymity misuse issue, which has been a challenge for anonymous credential-based vehicular protocols. Finally, we implement the proposed ABS scheme using a rapid prototyping tool called Charm to evaluate its performance. Hui Cui 0001, Robert H. Deng, Guilin Wang |
IEEE/ACM Trans. Netw. | 2 |
| 2019 | CrowdBC: A Blockchain-Based Decentralized Framework for CrowdsourcingabstractCrowdsourcing systems which utilize the human intelligence to solve complex tasks have gained considerable interest and adoption in recent years. However, the majority of existing crowdsourcing systems rely on central servers, which are subject to the weaknesses of traditional trust-based model, such as single point of failure. They are also vulnerable to distributed denial of service (DDoS) and Sybil attacks due to malicious users involvement. In addition, high service fees from the crowdsourcing platform may hinder the development of crowdsourcing. How to address these potential issues has both research and substantial value. In this paper, we conceptualize a blockchain-based decentralized framework for crowdsourcing named CrowdBC, in which a requester's task can be solved by a crowd of workers without relying on any third trusted institution, users' privacy can be guaranteed and only low transaction fees are required. In particular, we introduce the architecture of our proposed framework, based on which we give a concrete scheme. We further implement a software prototype on Ethereum public test network with real-world dataset. Experiment results show the feasibility, usability, and scalability of our proposed crowdsourcing system. Ming Li 0049, Jian Weng 0001, Anjia Yang, Wei Lu 0001, Yue Zhang 0025, Lin Hou 0002, Jia-Nan Liu, Yang Xiang 0001, Robert H. Deng |
IEEE Trans. Parallel Distributed Syst. | 9 |
| 2018 | Typing-Proof: Usable, Secure and Low-Cost Two-Factor Authentication Based on Keystroke TimingsabstractTwo-factor authentication (2FA) systems provide another layer of protection to users' accounts beyond password. Traditional hardware token based 2FA and software token based 2FA are not burdenless to users since they require users to read, remember, and type a onetime code in the process, and incur high costs in deployments or operations. Recent 2FA mechanisms such as Sound-Proof, reduce or eliminate users' interactions for the proof of the second factor; however, they are not designed to be used in certain settings (e.g., quiet environments or PCs without built-in microphones), and they are not secure in the presence of certain attacks (e.g., sound-danger attack and co-located attack). Yingjiu Li, Robert H. Deng |
ACSAC | 3 |
| 2018 | Privacy-Preserving Remote User Authentication with k-Times Untraceability
Yangguang Tian, Yingjiu Li, Binanda Sengupta, Robert H. Deng, Albert Ching, Weiwei Liu 0005 |
Inscrypt | 4 |
| 2018 | SCLib: A Practical and Lightweight Defense against Component Hijacking in Android ApplicationsabstractCross-app collaboration via inter-component communication is a fundamental mechanism on Android. Although it brings the benefits such as functionality reuse and data sharing, a threat called component hijacking is also introduced. By hijacking a vulnerable component in victim apps, an attack app can escalate its privilege for operations originally prohibited. Many prior studies have been performed to understand and mitigate this issue, but no defense is being deployed in the wild, largely due to the deployment difficulties and performance concerns. In this paper we present SCLib, a secure component library that performs in-app mandatory access control on behalf of app components. It does not require firmware modification or app repackaging as in previous works. The library-based nature also makes SCLib more accessible to app developers, and enables them produce secure components in the first place over fragmented Android devices. As a proof of concept, we design six mandatory policies and overcome unique implementation challenges to mitigate attacks originated from both system weaknesses and common developer mistakes. Our evaluation using ten high-profile open source apps shows that SCLib can protect their 35 risky components with negligible code footprint (less than 0.3% stub code) and nearly no slowdown to normal intra-app communication. The worst-case performance overhead is only about 5%. Daoyuan Wu, Debin Gao, Yingjiu Li, Robert H. Deng |
CODASPY | 5 |
| 2018 | DeepRefiner: Multi-layer Android Malware Detection System Applying Deep Neural NetworksabstractAs malicious behaviors vary significantly across mobile malware, it is challenging to detect malware both efficiently and effectively. Also due to the continuous evolution of malicious behaviors, it is difficult to extract features by laborious human feature engineering and keep up with the speed of malware evolution. To solve these challenges, we propose DeepRefiner to identify malware both efficiently and effectively. The novel technique enabling effectiveness is the semantic-based deep learning. We use Long Short Term Memory on the semantic structure of Android bytecode, avoiding missing the details of method-level bytecode semantics. To achieve efficiency, we apply Multilayer Perceptron on the xml files based on the finding that most malware can be efficiently identified using information only from xml files. We evaluate the detection performance of DeepRefiner with 62,915 malicious applications and 47,525 benign applications, showing that DeepRefiner effectively detects malware with an accuracy of 97.74% and a false positive rate of 2.54%. We compare DeepRefiner with a state-of-the-art single classifierbased detection system, StormDroid, and ten widely used signature-based anti-virus scanners. The experimental results show that DeepRefiner significantly outperforms StormDroid and anti-virus scanners. In addition, we evaluate the robustness of DeepRefiner against typical obfuscation techniques and adversarial samples. The experimental results demonstrate that DeepRefiner is robust in detecting obfuscated malicious applications. Yingjiu Li, Robert H. Deng |
EuroS&P | 3 |
| 2018 | SybMatch: Sybil Detection for Privacy-Preserving Task Matching in CrowdsourcingabstractThe past decade has witnessed the rise of crowdsourcing, and privacy in crowdsourcing has also gained rising concern in the meantime. In this paper, we focus on the privacy leaks and sybil attacks during the task matching, and propose a privacy-preserving task matching scheme, called SybMatch. The SybMatch scheme can simultaneously protect the privacy of publishers and subscribers against semi-honest crowdsourcing service provider, and meanwhile support the sybil detection against greedy subscribers and efficient user revocation. Detailed security analysis and thorough performance evaluation show that the SybMatch scheme is secure and efficient. Jiangang Shu, Ximeng Liu, Kan Yang 0001, Yinghui Zhang 0002, Xiaohua Jia, Robert H. Deng |
GLOBECOM | 6 |
| 2018 | An efficient and expressive ciphertext-policy attribute-based encryption scheme with partially hidden access structures, revisited
Hui Cui 0001, Robert H. Deng, Junzuo Lai, Xun Yi, Surya Nepal |
Comput. Networks | 2 |
| 2018 | TinyVisor: An extensible secure framework on android platforms
Dong Shen 0001, Zhoujun Li 0001, Xiaojing Su, Jinxin Ma, Robert H. Deng |
Comput. Secur. | 5 |
| 2018 | Making a good thing better: enhancing password/PIN-based user authentication with smartwatchabstractWearing smartwatches becomes increasingly popular in people’s lives. This paper shows that a smartwatch can help its bearer authenticate to a login system effectively and securely even if the bearer’s password has already been revealed. This idea is motivated by our observation that a sensor-rich smartwatch is capable of tracking the wrist motions of its bearer typing a password or PIN, which can be used as an authentication factor. The major challenge in this research is that a sophisticated attacker may imitate a user’s typing behavior as shown in previous research on keystroke dynamics based user authentication. We address this challenge by applying a set of machine learning and deep learning classifiers on the user’s wrist motion data that are collected from a smartwatch worn by the user when inputting his/her password or PIN. Our solution is user-friendly since it does not require users to perform any additional actions when typing passwords or PINs other than wearing smartwatches. We conduct a user study involving 51 participants so as to evaluate the feasibility and performance of our solution. User study results show that the best classifier is the Bagged Decision Trees, which yields 4.58% FRR and 0.12% FAR on a QWERTY keyboard, and 6.13% FRR and 0.16% FAR on a numeric keypad. Bing Chang, Yingjiu Li, Qiongxiao Wang, Wen Tao Zhu, Robert H. Deng |
Cybersecur. | 5 |
| 2018 | Attribute-based cloud storage with secure provenance over encrypted data
Hui Cui 0001, Robert H. Deng, Yingjiu Li |
Future Gener. Comput. Syst. | 2 |
| 2018 | Hybrid privacy-preserving clinical decision support system in fog-cloud computing
Ximeng Liu, Robert H. Deng, Yang Yang 0026, Ngoc Hieu Tran, Shangping Zhong |
Future Gener. Comput. Syst. | 2 |
| 2018 | Anonymous Privacy-Preserving Task Matching in CrowdsourcingabstractWith the development of sharing economy, crowdsourcing as a distributed computing paradigm has become increasingly pervasive. As one of indispensable services for most crowdsourcing applications, task matching has also been extensively explored. However, privacy issues are usually ignored during the task matching and few existing privacy-preserving crowdsourcing mechanisms can simultaneously protect both task privacy and worker privacy. This paper systematically analyzes the privacy leaks and potential threats in the task matching and proposes a single-keyword task matching scheme for the multirequester/multiworker crowdsourcing with efficient worker revocation. The proposed scheme not only protects data confidentiality and identity anonymity against the crowd-server, but also achieves query traceability against dishonest or revoked workers. Detailed privacy analysis and thorough performance evaluation show that the proposed scheme is secure and feasible. Jiangang Shu, Ximeng Liu, Xiaohua Jia, Kan Yang 0001, Robert H. Deng |
IEEE Internet Things J. | 5 |
| 2018 | Security and Privacy in Smart Health: Efficient Policy-Hiding Attribute-Based Access ControlabstractWith the rapid development of the Internet of Things and cloud computing technologies, smart health (s-health) is expected to significantly improve the quality of health care. However, data security and user privacy concerns in s-health have not been adequately addressed. As a well-received solution to realize fine-grained access control, ciphertext-policy attribute-based encryption (CP-ABE) has the potential to ensure data security in s-health. Nevertheless, direct adoption of the traditional CP-ABE in s-health suffers two flaws. For one thing, access policies are in cleartext form and reveal sensitive health-related information in the encrypted s-health records (SHRs). For another, it usually supports small attribute universe, which places an undesirable limitation on practical deployments of CP-ABE because the size of its public parameters grows linearly with the size of the universe. To address these problems, we introduce PASH, a privacy-aware s-health access control system, in which the key ingredient is a large universe CP-ABE with access policies partially hidden. In PASH, attribute values of access policies are hidden in encrypted SHRs and only attribute names are revealed. In fact, attribute values carry much more sensitive information than generic attribute names. Particularly, PASH realizes an efficient SHR decryption test which needs a small number of bilinear pairings. The attribute universe can be exponentially large and the size of public parameters is small and constant. Our security analysis indicates that PASH is fully secure in the standard model. Performance comparisons and experimental results show that PASH is more efficient and expressive than previous schemes. Yinghui Zhang 0002, Dong Zheng 0001, Robert H. Deng |
IEEE Internet Things J. | 3 |
| 2018 | Expressive query over outsourced encrypted data
Yang Yang 0026, Ximeng Liu, Robert H. Deng |
Inf. Sci. | 3 |
| 2018 | Blockchain based efficient and robust fair payment for outsourcing services in cloud computing
Yinghui Zhang 0002, Robert H. Deng, Ximeng Liu, Dong Zheng 0001 |
Inf. Sci. | 2 |
| 2018 | Dual-side privacy-preserving task matching for spatial crowdsourcing
Jiangang Shu, Ximeng Liu, Yinghui Zhang 0002, Xiaohua Jia, Robert H. Deng |
J. Netw. Comput. Appl. | 5 |
| 2018 | Secure smart health with privacy-aware aggregate authentication and access control in Internet of Things
Yinghui Zhang 0002, Robert H. Deng, Dong Zheng 0001 |
J. Netw. Comput. Appl. | 2 |
| 2018 | Efficient and Expressive Keyword Search Over Encrypted Data in CloudabstractSearchable encryption allows a cloud server to conduct keyword search over encrypted data on behalf of the data users without learning the underlying plaintexts. However, most existing searchable encryption schemes only support single or conjunctive keyword search, while a few other schemes that are able to perform expressive keyword search are computationally inefficient since they are built from bilinear pairings over the composite-order groups. In this paper, we propose an expressive public-key searchable encryption scheme in the prime-order groups, which allows keyword search policies (i.e., predicates, access structures) to be expressed in conjunctive, disjunctive or any monotonic Boolean formulas and achieves significant performance improvement over existing schemes. We formally define its security, and prove that it is selectively secure in the standard model. Also, we implement the proposed scheme using a rapid prototyping tool called Charm [37], and conduct several experiments to evaluate it performance. The results demonstrate that our scheme is much more efficient than the ones built over the composite-order groups. Hui Cui 0001, Zhiguo Wan, Robert H. Deng, Guilin Wang, Yingjiu Li |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2018 | Empirical Study of Face Authentication Systems Under OSNFD AttacksabstractFace authentication has been widely available on smartphones, tablets, and laptops. As numerous personal images are published in online social networks (OSNs), OSN-based facial disclosure (OSNFD) creates significant threat against face authentication. We make the first attempt to quantitatively measure OSNFD threat to real-world face authentication systems on smartphones, tablets, and laptops. Our results show that the percentage of vulnerable users that are subject to spoofing attacks is high, which is about 64 percent for laptop users, and 93 percent smartphone/tablet users. We investigate liveness detection methods in the real-world face authentication systems against OSNFD threat. We discover that under protection of liveness detection, the percentage of vulnerable images is 18.8 percent, but the percentage of vulnerable users is as high as 73.3 percent. This evidence suggests that the current face authentication systems are not strong enough under OSNFD attacks. Finally, we develop a risk estimation tool based on logistic regression, and analyze the impacts of key attributes of facial images on the OSNFD risk. Our statistical analysis reveals that the most influential attributes of facial images are image resolution, facial makeup, occluded eyes, and illumination. This tool can be used to evaluate OSNFD risk for OSN images to increase users' awareness of OSNFD. Yan Li 0075, Yingjiu Li, Qiang Yan 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2018 | Efficient and Privacy-Preserving Outsourced Calculation of Rational NumbersabstractIn this paper, we propose a framework for efficient and privacy-preserving outsourced calculation of rational numbers, which we refer to as POCR. Using POCR, a user can securely outsource the storing and processing of rational numbers to a cloud server without compromising the security of the (original) data and the computed results. We present the system architecture of POCR and the associated toolkits required in the privacy preserving calculation of integers and rational numbers to ensure that commonly used outsourced operations can be handled on-the-fly. We then prove that the proposed POCR achieves the goal of secure integer and rational number calculation without resulting in privacy leakage to unauthorized parties, and demonstrate the utility and the efficiency of POCR using simulations. Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng, Rongxing Lu, Jian Weng 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2018 | VPSearch: Achieving Verifiability for Privacy-Preserving Multi-Keyword Search over Encrypted Cloud DataabstractAlthough cloud computing offers elastic computation and storage resources, it poses challenges on verifiability of computations and data privacy. In this work we investigate verifiability for privacy-preserving multi-keyword search over outsourced documents. As the cloud server may return incorrect results due to system faults or incentive to reduce computation cost, it is critical to offer verifiability of search results and privacy protection for outsourced data at the same time. To fulfill these requirements, we design aVerifiablePrivacy-preserving keywordSearch scheme, called VPSearch, by integrating an adapted homomorphic MAC technique with a privacy-preserving multi-keyword search scheme. The proposed scheme enables the client to verify search results efficiently without storing a local copy of the outsourced data. We also propose a random challenge technique with ordering for verifying top-$k$search results, which can detect incorrect top-$k$results with probability close to 1. We provide detailed analysis on security, verifiability, privacy, and efficiency of the proposed scheme. Finally, we implement VPSearch using Matlab and evaluate its performance over three UCI bag-of-words data sets. Experiment results show that authentication tag generation incurs about 3 percent overhead only and a search query over 300,000 documents takes about 0.98 seconds on a laptop. To verify 300,000 similarity scores for one query, VPSearch costs only 0.29 seconds. Zhiguo Wan, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2018 | Secure Fine-Grained Access Control and Data Sharing for Dynamic Groups in the CloudabstractCloud computing is an emerging computing paradigm that enables users to store their data in a cloud server to enjoy scalable and on-demand services. Nevertheless, it also brings many security issues, since cloud service providers (CSPs) are not in the same trusted domain as users. To protect data privacy against untrusted CSPs, existing solutions apply cryptographic methods (e.g., encryption mechanisms) and provide decryption keys only to authorized users. However, sharing cloud data among authorized users at a fine-grained level is still a challenging issue, especially when dealing with dynamic user groups. In this paper, we propose a secure and efficient fine-grained access control and data sharing scheme for dynamic user groups by: 1) defining and enforcing access policies based on the attributes of the data; 2) permitting the key generation center to efficiently update user credentials for dynamic user groups; and 3) allowing some expensive computation tasks to be performed by untrusted CSPs without requiring any delegation key. Specifically, we first design an efficient revocable attribute-based encryption (ABE) scheme with the property of ciphertext delegation by exploiting and uniquely combining techniques of identity-based encryption, ABE, subset-cover framework, and ciphertext encoding mechanism. We then present a fine-grained access control and data sharing system for on-demand services with dynamic user groups in the cloud. The experimental data show that our proposed scheme is more efficient and scalable than the state-of-the-art solution. Shengmin Xu, Guomin Yang, Yi Mu 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2018 | Server-Aided Attribute-Based Signature With Revocation for Resource-Constrained Industrial-Internet-of-Things DevicesabstractThe industrial Internet-of-things (IIoT) can be seen as the usage of Internet-of-things technologies in industries, which provides a way to improve the operational efficiency. An attribute-based signature (ABS) has been a very useful technique for services requiring anonymous authentication in practice, where a signer can sign a message over a set of attributes without disclosing any information about his/her identity, and a signature only attests to the fact that it is created by a signer with several attributes satisfying some claim predicate. However, an ABS scheme requires exponentiation and/or pairing operations in the signature generation and verification algorithms, and hence, it is quite expensive for resource-constrained devices like a sensor in the IIoT network to run an ABS scheme. To reduce the computational overheads for both signers and verifiers, it has been suggested to introduce a server to help with signature generation and verification, but existing results on the ABS with “server-aided computation” either suffer from the security issues or are not sufficiently efficient. In this paper, we consider server-aided ABS one step further, and propose a notion called server-aided ABS with revocation (SA-ABSR), which not only securely mitigates the workloads of users in generating and verifying signatures, but also enables user revocation by having the server immediately stop signature generations for revoked signers. We formally define the security model for SA-ABSR, present a concrete construction of SA-ABSR based on a standard ABS scheme, and prove its security under the defined security model. Also, we implement the proposed SA-ABSR scheme and the underlying standard ABS scheme to evaluate the performance, from which it is easy to see that the proposed SA-ABSR scheme is more efficient than its underlying ABS scheme. Hui Cui 0001, Robert H. Deng, Joseph K. Liu, Xun Yi, Yingjiu Li |
IEEE Trans. Ind. Informatics | 2 |
| 2018 | Lightweight Break-Glass Access Control System for Healthcare Internet-of-ThingsabstractHealthcare Internet-of-things (IoT) has been proposed as a promising means to greatly improve the efficiency and quality of patient care. Medical devices in healthcare IoT measure patients' vital signs and aggregate these data into medical files which are uploaded to the cloud for storage and accessed by healthcare workers. To protect patients' privacy, encryption is normally used to enforce access control of medical files by authorized parties while preventing unauthorized access. In healthcare, it is crucial to enable timely access of patient files in emergency situations. In this paper, we propose a lightweight break-glass access control (LiBAC) system that supports two ways for accessing encrypted medical files: attribute-based access and break-glass access. In normal situations, a medical worker with an attribute set satisfying the access policy of a medical file can decrypt and access the data. In emergent situations, the break-glass access mechanism bypasses the access policy of the medical file to allow timely access to the data by emergency medical care or rescue workers. LiBAC is lightweight since very few calculations are executed by devices in the healthcare IoT network, and the storage and transmission overheads are low. LiBAC is formally proved secure in the standard model and extensive experiments are conducted to demonstrate its efficiency. Yang Yang 0026, Ximeng Liu, Robert H. Deng |
IEEE Trans. Ind. Informatics | 3 |
| 2017 | Attribute-Based Encryption with Expressive and Authorized Keyword Search
Hui Cui 0001, Robert H. Deng, Joseph K. Liu, Yingjiu Li |
ACISP (1) | 2 |
| 2017 | What You See is Not What You Get: Leakage-Resilient Password Entry Schemes for Smart GlassesabstractSmart glasses are becoming popular for users to access various services such as email. To protect these services, password-based user authentication is widely used. Unfortunately, the password-based user authentication has inherent vulnerability against password leakage. Many efforts have been put on designing leakage-resilient password entry schemes on PCs and mobile phones with traditional input equipment including keyboards and touch screens. However, such traditional input equipment is not available on smart glasses. Existing password entry on smart glasses relies on additional PCs or mobile devices. Such solutions force users to switch between different systems, which causes interrupted experience and may lower the practicability and usability of smart glasses. In this paper, we propose a series of leakage-resilient password entry schemes on stand-alone smart glasses, which are gTapper, gRotator, and gTalker. These schemes ensure no leakage in password entry by breaking the correlation between the underlying password and the interaction observable to adversaries. They are practical in the sense that they only require a touch pad, a gyroscope, and a microphone which are commonly available on smart glasses. The usability of the proposed schemes is evaluated by user study under various test conditions which are common in users' daily usage. The results of our user study reveal that the proposed schemes are easy-to-use so that users enter their passwords within moderate time, at high accuracy, and in various situations. Yan Li 0075, Yingjiu Li, Robert H. Deng |
AsiaCCS | 4 |
| 2017 | VuRLE: Automatic Vulnerability Detection and Repair by Learning from Examples
Siqi Ma 0001, Ferdian Thung, David Lo 0001, Cong Sun 0001, Robert H. Deng |
ESORICS (2) | 5 |
| 2017 | Secure Encrypted Data Deduplication with Ownership Proof and User Revocation
Wenxiu Ding, Zheng Yan 0002, Robert H. Deng |
ICA3PP | 3 |
| 2017 | IoVShield: An Efficient Vehicular Intrusion Detection System for Self-driving (Short Paper)
Zhuo Wei, Yanjiang Yang, Rehana Yasmin, Yongdong Wu, Jian Weng 0001, Robert H. Deng |
ISPEC | 6 |
| 2017 | Fuzzy Public-Key Encryption Based on Biometric Data
Hui Cui 0001, Man Ho Au, Baodong Qin, Robert H. Deng, Xun Yi |
ProvSec | 4 |
| 2017 | Encrypted data processing with Homomorphic Re-Encryption
Wenxiu Ding, Zheng Yan 0002, Robert H. Deng |
Inf. Sci. | 3 |
| 2017 | Related-key secure key encapsulation from extended computational bilinear Diffie-Hellman
Baodong Qin, Shengli Liu 0001, Shifeng Sun 0001, Robert H. Deng, Dawu Gu |
Inf. Sci. | 4 |
| 2017 | CCA Secure encryption supporting authorized equality test on ciphertexts in standard model and its applications
HweeHwa Pang, Ngoc Hieu Tran, Robert H. Deng |
Inf. Sci. | 4 |
| 2017 | Cryptography and Data Security in Cloud Computing
Zheng Yan 0002, Robert H. Deng, Vijay Varadharajan |
Inf. Sci. | 2 |
| 2017 | A study on a feasible no-root approach on AndroidabstractRoot is the administrative privilege on Android, which is however inaccessible on stock Android devices. Due to the desire for privileged functionalities and the reluctance of rooting their devices, Android users seek for no-root approaches, which provide users with part of root privileges without rooting their devices. Existing no-root approaches require users to launch a separate service via Android Debug Bridge (ADB) on an Android device, which would perform user-desired tasks. However, it is unusual for a third-party Android application to work with a separate native service via sockets, and it requires the application developers to have extra knowledge such as Linux programming in application development. In this paper, we propose a feasible no-root approach based on new functionalities added on Android, which creates no separate service but an ADB loopback. To ensure such no-root approach is not misused in a proactive instead of reactive manner, we examine its dark side. We find out that while this approach makes it easy for no-root applications to work, it may lead to a “ permission explosion,” which enables any third-party application to attain shell permissions beyond its granted permissions. The permission explosion can further lead to exploits including privacy leakage, account takeover, application UID abuse, and user input inference. A practical experiment is carried out to evaluate the situation in the real world, which shows that many real-world applications from Google Play and four third-party application markets are indeed vulnerable to these exploits. To mitigate the dark side of the new no-root approach and make it more suitable for users to adopt, we identify the causes of the exploits, and propose a permission-based solution. We also provide suggestions to application developers and application markets on how to prevent these exploits. Yingjiu Li, Robert H. Deng, Lingyun Ying |
J. Comput. Secur. | 3 |
| 2017 | Adaptable key-policy attribute-based encryption with time interval
Siqi Ma 0001, Junzuo Lai, Robert H. Deng, Xuhua Ding |
Soft Comput. | 3 |
| 2017 | Universally Composable RFID Mutual AuthenticationabstractUniversally Composable (UC) framework provides the strongest security notion for designing fully trusted cryptographic protocols, and it is very challenging on applying UC security in the design of RFID mutual authentication protocols. In this paper, we formulate the necessary conditions for achieving UC secure RFID mutual authentication protocols which can be fully trusted in arbitrary environment, and indicate the inadequacy of some existing schemes under the UC framework. We define the ideal functionality for RFID mutual authentication and propose the first UC secure RFID mutual authentication protocol based on public key encryption and certain trusted third parties which can be modeled as functionalities. We prove the security of our protocol under the strongest adversary model assuming both the tags' and readers' corruptions. We also present two (public) key update protocols for the cases of multiple readers: one uses Message Authentication Code (MAC) and the other uses trusted certificates in Public Key Infrastructure (PKI). Furthermore, we address the relations between our UC framework and the zero-knowledge privacy model proposed by Deng et al. [1]. Chunhua Su, Bagus Santoso, Yingjiu Li, Robert H. Deng, Xinyi Huang 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2017 | A Secure, Usable, and Transparent Middleware for Permission Managers on AndroidabstractAndroid's permission system offers an all-or-nothing choice when installing an app. To make it more flexible and fine-grained, users may choose a popular app tool, called permission manager, to selectively grant or revoke an app's permissions at runtime. A fundamental requirement for such permission manager is that the granted or revoked permissions should be enforced faithfully. However, we discover that none of existing permission managers meet this requirement due to permission leaks, in which an unprivileged app can exercise certain permissions which are revoked or not-granted through communicating with a privileged app.To address this problem, we propose a secure, usable, and transparent OS-level middleware for any permission manager to defend against the permission leaks. The middleware is provably secure in a sense that it can effectively block all possible permission leaks.The middleware is designed to have a minimal impact on the usability of running apps. In addition, the middleware is transparent to users and app developers and it requires minor modifications on permission managers and Android OS. Finally, our evaluation shows that the middleware incurs relatively low performance overhead and power consumption. Daibin Wang, Haixia Yao, Yingjiu Li, Hai Jin 0001, Deqing Zou, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2017 | Identity-Based Data Outsourcing With Comprehensive Auditing in CloudsabstractCloud storage system provides facilitative file storage and sharing services for distributed clients. To address integrity, controllable outsourcing, and origin auditing concerns on outsourced files, we propose an identity-based data outsourcing (IBDO) scheme equipped with desirable features advantageous over existing proposals in securing outsourced data. First, our IBDO scheme allows a user to authorize dedicated proxies to upload data to the cloud storage server on her behalf, e.g., a company may authorize some employees to upload files to the company's cloud account in a controlled way. The proxies are identified and authorized with their recognizable identities, which eliminates complicated certificate management in usual secure distributed computing systems. Second, our IBDO scheme facilitates comprehensive auditing, i.e., our scheme not only permits regular integrity auditing as in existing schemes for securing outsourced data, but also allows to audit the information on data origin, type, and consistence of outsourced files. Security analysis and experimental evaluation indicate that our IBDO scheme provides strong security with desirable efficiency. Qianhong Wu, Wenchang Shi, Robert H. Deng, Jiankun Hu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2017 | Vulnerabilities, Attacks, and Countermeasures in Balise-Based Train Control SystemsabstractIn modern rail transport systems, balises are widely used to exchange track-train information via air-gap interface. In this paper, we first present the vulnerabilities on the standard balise air-gap interface, and then conduct vulnerability simulations using the system parameters that were specified in the European Train Control System. The simulation results show that the vulnerabilities can be exploited to launch effective and practical attacks, which could lead to catastrophic consequences, such as train derailment or collision. To mitigate the vulnerabilities and attacks, we propose to implement a challenge-response authentication process in the air-gap interface in the existing transport infrastructure. Yongdong Wu, Jian Weng 0001, Robert H. Deng |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2017 | An Efficient Privacy-Preserving Outsourced Computation over Public DataabstractIn this paper, we propose a new efficient privacy-preserving outsourced computation framework over public data, called EPOC. EPOC allows a user to outsource the computation of a function over multi-dimensional public data to the cloud while protecting the privacy of the function and its output. Specifically, we introduce three types of EPOC in order to tradeoff different levels of privacy protection and performance. We present a new cryptosystem called Switchable Homomorphic Encryption with Partially Decryption (SHED) as the core cryptographic primitive for EPOC. We introduce two coding techniques, called message pre-coding technique and message extending and coding technique respectively, for messages encrypted under a composite order group. Furthermore, we propose a Secure Exponent Calculation Protocol with Public Base (SEPB), which serves as the core sub-protocol in EPOC. Detailed security analysis shows that the proposed EPOC achieves the goal of outsourcing computation of a private function over public data without privacy leakage to unauthorized parties. In addition, performance evaluations via extensive simulations demonstrate that EPOC is efficient in both computation and communications. Ximeng Liu, Baodong Qin, Robert H. Deng, Yingjiu Li |
IEEE Trans. Serv. Comput. | 3 |
| 2016 | A Feasible No-Root Approach on Android
Yingjiu Li, Robert H. Deng |
ACISP (2) | 3 |
| 2016 | Generic Anonymous Identity-Based Broadcast Encryption with Chosen-Ciphertext Security
Jian Weng 0001, Man Ho Au, Yijun Mao, Robert H. Deng |
ACISP (2) | 5 |
| 2016 | Anonymous Identity-Based Broadcast Encryption with Chosen-Ciphertext SecurityabstractIn this paper, we propose the first identity-based broadcast encryption scheme, which can simultaneously achieves confidentiality and full anonymity against adaptive chosen-ciphertext attacks under a standard assumption. In addition, two further desirable features are also provided: one is fully-collusion resistant which means that even if all users outside of receivers S collude they cannot obtain any information about the plaintext. The other one is stateless which means that the users in the system do not need to update their private keys when the other users join or leave our system. In particular, our scheme is highly efficient, where the public parameters size, the private key size and the decryption cost are all constant and independent to the number of receivers. Jian Weng 0001, Jia-Nan Liu, Joseph K. Liu, Wei Liu 0240, Robert H. Deng |
AsiaCCS | 6 |
| 2016 | CDRep: Automatic Repair of Cryptographic Misuses in Android ApplicationsabstractCryptography is increasingly being used in mobile applications to provide various security services; from user authentication, data privacy, to secure communications. However, there are plenty of mistakes that developers could accidentally make when using cryptography in their mobile apps and such mistakes can lead to a false sense of security. Recent research efforts indeed show that a significant portion of mobile apps in both Android and iOS platforms misused cryptographic APIs. In this paper, we present CDRep, a tool for automatically repairing cryptographic misuse defects in Android apps. We classify such defects into seven types and manually assemble the corresponding fix patterns based on the best practices in cryptographic implementations. CDRep consists of two phases, a detection phase which identifies defect locations in a mobile app and a repair phase which repairs the vulnerable app automatically. In our validation, CDRep is able to successfully repair 94.5% of 1,262 vulnerable apps. Furthermore, CDRep is lightweight, the average runtime to generate a patch is merely 19.3 seconds and the size of a repaired app increases by only 0.667% on average. Siqi Ma 0001, David Lo 0001, Teng Li 0003, Robert H. Deng |
AsiaCCS | 4 |
| 2016 | Efficient Verifiable Computation of Linear and Quadratic Functions over Encrypted DataabstractIn data outsourcing, a client stores a large amount of data on an untrusted server; subsequently, the client can request the server to compute a function on any subset of the data. This setting naturally leads to two security requirements: confidentiality of input data, and authenticity of computations. Existing approaches that satisfy both requirements simultaneously are built on fully homomorphic encryption, which involves expensive computation on the server and client and hence is impractical. In this paper, we propose two verifiable homomorphic encryption schemes that do not rely on fully homomorphic encryption. The first is a simple and efficient scheme for linear functions. The second scheme supports the class of multivariate quadratic functions, by combining the Paillier cryptosystem with a new homomorphic message authentication code (MAC) scheme. Through formal security analysis, we show that the schemes are semantically secure and unforgeable. Ngoc Hieu Tran, HweeHwa Pang, Robert H. Deng |
AsiaCCS | 3 |
| 2016 | Server-Aided Revocable Attribute-Based Encryption
Hui Cui 0001, Robert H. Deng, Yingjiu Li, Baodong Qin |
ESORICS (2) | 2 |
| 2016 | An Efficient and Expressive Ciphertext-Policy Attribute-Based Encryption Scheme with Partially Hidden Access Structures
Hui Cui 0001, Robert H. Deng, Junzuo Lai |
ProvSec | 2 |
| 2016 | Attribute-Based Encryption with Granular Revocation
Hui Cui 0001, Robert H. Deng, Xuhua Ding, Yingjiu Li |
SecureComm | 2 |
| 2016 | H-Binder: A Hardened Binder Framework on Android Systems
Dong Shen 0001, Zhangkai Zhang, Xuhua Ding, Zhoujun Li 0001, Robert H. Deng |
SecureComm | 5 |
| 2016 | Revocable and Decentralized Attribute-Based EncryptionabstractIn this paper, we propose a revocable and decentralized attribute-based encryption (ABE) system that splits the task of decryption key generation across multiple attribute authorities (AAs) without requiring any central party such that it achieves attribute revocation by simply stopping updating of the corresponding private key. In our system, a party can easily behave as an AA by creating a public and private key pair without any global communication except the creation for the common system parameters, under which it can periodically issue/update private key components for users that reflect their attributes, and an AA can freely leave the system once its corresponding attribute is revoked without communication with other AAs. In addition, to revoke a user, those AAs that have issued private keys to this user easily cease the key updating process for the user without affecting other AAs' execution. For the construction of our system, the technical barrier is to make private keys collusion resistant. Since in our system each component of a user's private key at a time period may come from different AAs and there is no coordination between these AAs, traditional technique of binding together different components (issued by different AAs) of a private key by randomization cannot be employed. To overcome this, we tie the key components together and prevent collusion attacks between different users by embedding distinct identifiers and a commonly shared time attribute in these components. Hui Cui 0001, Robert H. Deng |
Comput. J. | 2 |
| 2016 | Escrow free attribute-based signature with self-revealability
Hui Cui 0001, Guilin Wang, Robert H. Deng, Baodong Qin |
Inf. Sci. | 3 |
| 2016 | Ciphertext-policy attribute-based encryption with partially hidden access structure and its application to privacy-preserving electronic medical record system in cloud environmentabstractAbstract With the development of cloud computing, more and more sensitive data are uploaded to cloud by companies or individuals, which brings forth new challenges for outsourced data security and privacy. Ciphertext‐policy attribute‐based encryption (CP‐ABE) provides fine‐grained access control of encrypted data in the cloud; in a CP‐ABE scheme, an access structure, also referred to as ciphertext‐policy, is sent along with a ciphertext explicitly, and anyone who obtains a ciphertext can know the access structure associated with the ciphertext. In certain applications, access structures contain very sensitive information and must be protected from everyone except the users whose private key attributes satisfy the access structures. In this paper, we propose a new model for CP‐ABE with partially hidden access structure (See Figure 2). In our model, each attribute consists of two parts: an attribute name and its value; if the private key attributes of a user do not satisfy the access structure associated with a ciphertext, the specific attribute values of the access structure are hidden, while other information about the access structure is public. Based on the CP‐ABE scheme proposed by Lewko and Waters recently, we then present a concrete construction of CP‐ABE with partially hidden access structure and prove that it is fully secure in the standard model. In addition, we discuss how our new model can be employed to construct a privacy‐preserving electronic medical record system in the cloud environment. Copyright © 2016 John Wiley & Sons, Ltd. Lixian Liu, Junzuo Lai, Robert H. Deng, Yingjiu Li |
Secur. Commun. Networks | 3 |
| 2016 | Deduplication on Encrypted Big Data in CloudabstractCloud computing offers a new way of service provision by re-arranging various resources over the Internet. The most important and popular cloud service is data storage. In order to preserve the privacy of data holders, data are often stored in cloud in an encrypted form. However, encrypted data introduce new challenges for cloud data deduplication, which becomes crucial for big data storage and processing in cloud. Traditional deduplication schemes cannot work on encrypted data. Existing solutions of encrypted data deduplication suffer from security weakness. They cannot flexibly support data access control and revocation. Therefore, few of them can be readily deployed in practice. In this paper, we propose a scheme to deduplicate encrypted data stored in cloud based on ownership challenge and proxy re-encryption. It integrates cloud data deduplication with access control. We evaluate its performance based on extensive analysis and computer simulations. The results show the superior efficiency and effectiveness of the scheme for potential practical deployment, especially for big data deduplication in cloud storage. Zheng Yan 0002, Wenxiu Ding, Xixun Yu, Haiqi Zhu, Robert H. Deng |
IEEE Trans. Big Data | 5 |
| 2016 | A Privacy-Preserving Outsourced Functional Computation Framework Across Large-Scale Multiple Encrypted DomainsabstractIn this paper, we propose a framework for privacy-preserving outsourced functional computation across large-scale multiple encrypted domains, which we refer to as POFD. With POFD, a user can obtain the output of a function computed over encrypted data from multiple domains while protecting the privacy of the function itself, its input and its output. Specifically, we introduce two notions of POFD, the basic POFD and its enhanced version, in order to tradeoff the levels of privacy protection and performance. We present three protocols, named Multi-domain Secure Multiplication protocol (MSM), Secure Exponent Calculation protocol with private Base (SECB), and Secure Exponent Calculation protocol (SEC), as the core sub-protocols for POFD to securely compute the outsourced function. Detailed security analysis shows that the proposed POFD achieves the goal of calculating a user-defined function across different encrypted domains without privacy leakage to unauthorized parties. Our performance evaluations using simulations demonstrate the utility and the efficiency of POFD. Ximeng Liu, Baodong Qin, Robert H. Deng, Rongxing Lu, Jianfeng Ma 0001 |
IEEE Trans. Computers | 3 |
| 2016 | On the security of two identity-based conditional proxy re-encryption schemes
Jian Weng 0001, Robert H. Deng, Joseph K. Liu |
Theor. Comput. Sci. | 3 |
| 2016 | An Efficient Privacy-Preserving Outsourced Calculation Toolkit With Multiple KeysabstractIn this paper, we propose a toolkit for efficient and privacy-preserving outsourced calculation under multiple encrypted keys (EPOM). Using EPOM, a large scale of users can securely outsource their data to a cloud server for storage. Moreover, encrypted data belonging to multiple users can be processed without compromising on the security of the individual user's (original) data and the final computed results. To reduce the associated key management cost and private key exposure risk in EPOM, we present a distributed two-trapdoor public-key cryptosystem, the core cryptographic primitive. We also present the toolkit to ensure that the commonly used integer operations can be securely handled across different encrypted domains. We then prove that the proposed EPOM achieves the goal of secure integer number processing without resulting in privacy leakage of data to unauthorized parties. Last, we demonstrate the utility and the efficiency of EPOM using simulations. Ximeng Liu, Robert H. Deng, Kim-Kwang Raymond Choo, Jian Weng 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2016 | Privacy-Preserving Outsourced Calculation on Floating Point NumbersabstractIn this paper, we propose a framework for privacy-preserving outsourced calculation on floating point numbers (POCF). Using POCF, a user can securely outsource the storing and processing of floating point numbers to a cloud server without compromising on the security of the (original) data and the computed results. In particular, we first present privacy-preserving integer processing protocols for common integer operations. We then present an approach to outsourcing floating point numbers for storage in a privacy-preserving way, and securely processing commonly used floating point number operations on-the-fly. We prove that the proposed POCF achieves the goal of floating point number processing without privacy leakage to unauthorized parties, and demonstrate the utility and the efficiency of POCF using simulations. Ximeng Liu, Robert H. Deng, Wenxiu Ding, Rongxing Lu, Baodong Qin |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2016 | ICCDetector: ICC-Based Malware Detection on AndroidabstractMost existing mobile malware detection methods (e.g., Kirin and DroidMat) are designed based on the resources required by malwares (e.g., permissions, application programming interface (API) calls, and system calls). These methods capture the interactions between mobile apps and Android system, but ignore the communications among components within or cross application boundaries. As a consequence, the majority of the existing methods are less effective in identifying many typical malwares, which require a few or no suspicious resources, but leverage on inter-component communication (ICC) mechanism when launching stealthy attacks. To address this challenge, we propose a new malware detection method, named ICCDetector. ICCDetector outputs a detection model after training with a set of benign apps and a set of malwares, and employs the trained model for malware detection. The performance of ICCDetector is evaluated with 5264 malwares, and 12026 benign apps. Compared with our benchmark, which is a permission-based method proposed by Peng et al. in 2012 with an accuracy up to 88.2%, ICCDetector achieves an accuracy of 97.4%, roughly 10% higher than the benchmark, with a lower false positive rate of 0.67%, which is only about a half of the benchmark. After manually analyzing false positives, we discover 43 new malwares from the benign data set, and reduce the number of false positives to seven. More importantly, ICCDetector discovers 1708 more advanced malwares than the benchmark, while it misses 220 obvious malwares, which can be easily detected by the benchmark. For the detected malwares, ICCDetector further classifies them into five newly defined malware categories, which help understand the relationship between malicious behaviors and ICC characteristics. We also provide a systemic analysis of ICC patterns of benign apps and malwares. Yingjiu Li, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2016 | Trustworthy Authentication on Scalable Surveillance Video with Background Model SupportabstractH.264/SVC (Scalable Video Coding) codestreams, which consist of a single base layer and multiple enhancement layers, are designed for quality, spatial, and temporal scalabilities. They can be transmitted over networks of different bandwidths and seamlessly accessed by various terminal devices. With a huge amount of video surveillance and various devices becoming an integral part of the security infrastructure, the industry is currently starting to use the SVC standard to process digital video for surveillance applications such that clients with different network bandwidth connections and display capabilities can seamlessly access various SVC surveillance (sub)codestreams. In order to guarantee the trustworthiness and integrity of received SVC codestreams, engineers and researchers have proposed several authentication schemes to protect video data. However, existing algorithms cannot simultaneously satisfy both efficiency and robustness for SVC surveillance codestreams. Hence, in this article, a highly efficient and robust authentication scheme, named TrustSSV (Trust Scalable Surveillance Video), is proposed. Based on quality/spatial scalable characteristics of SVC codestreams, TrustSSV combines cryptographic and content-based authentication techniques to authenticate the base layer and enhancement layers, respectively. Based on temporal scalable characteristics of surveillance codestreams, TrustSSV extracts, updates, and authenticates foreground features for each access unit dynamically with background model support. Using SVC test sequences, our experimental results indicate that the scheme is able to distinguish between content-preserving and content-changing manipulations and to pinpoint tampered locations. Compared with existing schemes, the proposed scheme incurs very small computation and communication costs. Zhuo Wei, Zheng Yan 0002, Yongdong Wu, Robert H. Deng |
ACM Trans. Multim. Comput. Commun. Appl. | 4 |
| 2016 | Editorial: Trust Management for Multimedia Big DataabstractNo abstract available. Zheng Yan 0002, Jun Liu 0002, Robert H. Deng, Francisco Herrera |
ACM Trans. Multim. Comput. Commun. Appl. | 3 |
| 2015 | Efficient Virtualization-Based Application Protection Against Untrusted Operating SystemabstractCommodity monolithic operating systems are abundant with vulnerabilities that lead to rootkit attacks. Once an operating system is subverted, the data and execution of user applications are fully exposed to the adversary, regardless whether they are designed and implemented with security considerations. Existing application protection schemes have various drawbacks, such as high performance overhead, large Trusted Computing Base (TCB), or hardware modification. In this paper, we present the design and implementation of AppShield, a hypervisor-based approach that reliably safeguards code, data and execution integrity of a critical application, in a more efficient way than existing systems. The protection overhead is localized to the protected application only, so that unprotected applications and the operating system run without any performance loss. In addition to the performance advantage, AppShield tackles several newly identified threats in this paper which are not systematically addressed previously. We build a prototype of AppShield with a tiny hypervisor, and experiment with AppShield by running several off-the-shelf applications on a Linux platform. The results testify to AppShield's low performance costs in terms of CPU computation, disk I/O and network I/O. Yueqiang Cheng, Xuhua Ding, Robert H. Deng |
AsiaCCS | 3 |
| 2015 | Seeing Your Face Is Not Enough: An Inertial Sensor-Based Liveness Detection for Face AuthenticationabstractLeveraging built-in cameras on smartphones and tablets, face authentication provides an attractive alternative of legacy passwords due to its memory-less authentication process. However, it has an intrinsic vulnerability against the media-based facial forgery (MFF) where adversaries use photos/videos containing victims' faces to circumvent face authentication systems. In this paper, we propose FaceLive, a practical and robust liveness detection mechanism to strengthen the face authentication on mobile devices in fighting the MFF-based attacks. FaceLive detects the MFF-based attacks by measuring the consistency between device movement data from the inertial sensors and the head pose changes from the facial video captured by built-in camera. FaceLive is practical in the sense that it does not require any additional hardware but a generic front-facing camera, an accelerometer, and a gyroscope, which are pervasively available on today's mobile devices. FaceLive is robust to complex lighting conditions, which may introduce illuminations and lead to low accuracy in detecting important facial landmarks; it is also robust to a range of cumulative errors in detecting head pose changes during face authentication. Yan Li 0075, Yingjiu Li, Qiang Yan 0001, Hancong Kong, Robert H. Deng |
CCS | 5 |
| 2015 | Active Semi-supervised Approach for Checking App Behavior against Its DescriptionabstractMobile applications are popular in recent years. They are often allowed to access and modify users' sensitive data. However, many mobile applications are malwares that inappropriately use these sensitive data. To detect these malwares, Gorla et al. Propose CHABADA which compares app behaviors against its descriptions. Data about known malwares are not used in their work, which limits its effectiveness. In this work, we extend the work by Gorla et al. By proposing an active and semi-supervised approach for detecting malwares. Different from CHABADA, our approach will make use of both known benign and malicious apps to predict other malicious apps. Also, our approach will select a good set of apps for experts to label as malicious or benign to form a set of labeled training data -- it is an active approach. Furthermore, it will make use of both labeled data (known malicious or benign apps) and unlabeled data (unknown apps) -- it is a semi-supervised approach. We have evaluated our approach by using a set of 22,555 Android apps. Our approach achieves a good performance in detecting malicious apps with a precision of 99.82%, recall of 92.50%, and F-measure of 96.02%. Our approach improves CHABADA by 365.8%, 64.8%, 209.6% in terms of precision, recall, and F-measure. Siqi Ma 0001, Shaowei Wang 0002, David Lo 0001, Robert H. Deng, Cong Sun 0001 |
COMPSAC | 4 |
| 2015 | On Security of Content-Based Video Stream AuthenticationabstractContent-based authentication (CBA) schemes are used to authenticate multimedia streams while allowing content-preserving manipulations such as bit-rate transcoding. In this paper, we survey and classify existing transform-domain CBA schemes for videos into two categories, and point out that in contrary to CBA for images, there exists a common design flaw in these schemes. We present the principles (based on video coding concept) on how the flaw can be exploited to mount semantic-changing attacks in the transform domain that cannot be detected by existing CBA schemes. We show attack examples including content removal, modification and insertion attacks. Noting that these CBA schemes are designed at the macroblock level, we discuss, from the attacker’s point of view, the conditions in attacking content-based authenticated macroblocks. Swee-Won Lo, Zhuo Wei, Robert H. Deng, Xuhua Ding |
ESORICS (1) | 3 |
| 2015 | Server-Aided Revocable Identity-Based EncryptionabstractEfficient user revocation in Identity-Based Encryption (IBE) has been a challenging problem and has been the subject of several research efforts in the literature. Among them, the tree-based revocation approach, due to Boldyreva, Goyal and Kumar, is probably the most efficient one. In this approach, a trusted Key Generation Center (KGC) periodically broadcasts a set of key updates to all (non-revoked) users through public channels, where the size of key updates is only $$O(r\log \frac{N}{r})$$ , with N being the number of users and r the number of revoked users, respectively; however, every user needs to keep at least $$O(\log N)$$ long-term secret keys and all non-revoked users are required to communicate with the KGC regularly. These two drawbacks pose challenges to users who have limited resources to store their secret keys or cannot receive key updates in real-time. To alleviate the above problems, we propose a novel system model called server-aided revocable IBE. In our model, almost all of the workloads on users are delegated to an untrusted server which manages users’ public keys and key updates sent by a KGC periodically. The server is untrusted in the sense that it does not possess any secret information. Our system model requires each user to keep just one short secret key and does not require users to communicate with either the KGC or the server during key updating. In addition, the system supports delegation of users’ decryption keys, namely it is secure against decryption key exposure attacks. We present a concrete construction of the system that is provably secure against adaptive-ID chosen plaintext attacks under the DBDH assumption in the standard model. One application of our server-aided revocable IBE is encrypted email supporting lightweight devices (e.g., mobile phones) in which an email server plays the role of the untrusted server so that only non-revoked users can read their email messages. Baodong Qin, Robert H. Deng, Yingjiu Li, Shengli Liu 0001 |
ESORICS (1) | 2 |
| 2015 | Automatic Accident Detection and Alarm SystemabstractAccident detection and alarm system is very important to detect possible accidents or dangers for the peoples using their mobile devices while walking, i.e., distracted walking. In this paper, we introduce an automatic accident detection and alarm system, called AutoADAS, which is fully implemented and tested on the real mobile devices. The proposed system can be activated either manually or automatically when user walks. Under the manual mode, user activates the system before distracted walking while under the automatic mode, a "user behaviour profiling" module is used to recognize (distracted) walking behaviours and an "object detection" module is activated. Using image processing and camera field of view (FOV), the distance and angle between the user and detected objects are estimated and then applied to identify whether any potential accidents can happen. The "accident analysis and prediction" module includes: temporal alarm that inputs the user's walking speed and distance with respect to the detected objects and outputs temporal accident prediction; spatial alarm that inputs the user's walking direction and angle with respect to the detected objects and outputs spatial accident prediction. Once the proposed system positively predicts a potential accident, the "alarm and suggestion" module alerts the user with text, sound or vibration. Zhuo Wei, Swee-Won Lo, Tieyan Li, Jialie Shen 0001, Robert H. Deng |
ACM Multimedia | 6 |
| 2015 | Multidimensional Context Awareness in Mobile Devices
Zhuo Wei, Robert H. Deng, Jialie Shen 0001, Jixiang Zhu, Kun Ouyang, Yongdong Wu |
MMM (2) | 2 |
| 2015 | Electronic Contract Signing Without Using Trusted Third Party
Zhiguo Wan, Robert H. Deng |
NSS | 2 |
| 2015 | CICC: a fine-grained, semantic-aware, and transparent approach to preventing permission leaks for Android permission managersabstractAndroid's permission system offers an all-or-nothing installation choice for users. To make it more flexible, users may choose a popular app tool, called permission manager, to selectively grant or revoke an app's permissions at runtime. A fundamental requirement for such permission manager is that the granted or revoked permissions should be enforced faithfully. However, we discover that none of existing permission managers meet this requirement due to permission leaks. To address this problem, we propose CICC, a fine-grained, semantic-aware, and transparent approach for any permission managers to defend against the permission leaks. Compared to existing solutions, CICC is fine-grained because it detects the permission leaks using call-chain information at the component instance level, instead of at the app level or component level. The fine-grained feature enables it to generate a minimal impact on the usability of running apps. CICC is semantic-aware in a sense that it manages call-chains in the whole lifecycle of each component instance. CICC is transparent to users and app developers, and it requires minor modification to permission managers. Our evaluation shows that CICC incurs relatively low performance overhead and power consumption. Daibin Wang, Haixia Yao, Yingjiu Li, Hai Jin 0001, Deqing Zou, Robert H. Deng |
WISEC | 6 |
| 2015 | Privacy leakage analysis in online social networks
Yan Li 0075, Yingjiu Li, Qiang Yan 0001, Robert H. Deng |
Comput. Secur. | 4 |
| 2015 | Leakage-resilient password entry: Challenges, design, and evaluation
Qiang Yan 0001, Jin Han 0002, Yingjiu Li, Jianying Zhou 0001, Robert H. Deng |
Comput. Secur. | 5 |
| 2015 | Efficient revocable certificateless encryption against decryption key exposureabstractCertificateless public key cryptosystem (CLPKC) improves the identity based public key cryptosystem to be key‐escrow free. Many research works on CLPKC have been presented so far. However, the revocation problem in CLPKC still lacks effective solutions. The current revocation approaches suffer from either low efficiency or security weakness. In this study, we propose the first ‘scalable revocable’ certificateless encryption (RCLE) scheme against ‘decryption key exposure’. The scheme is provably secure in the standard model. Moreover, we give a second interesting RCLE scheme whose decryption key is very short. Yinxia Sun, Futai Zhang, Robert H. Deng |
IET Inf. Secur. | 4 |
| 2015 | On robust image spam filtering via comprehensive visual modeling
Jialie Shen 0001, Robert H. Deng, Zhiyong Cheng 0001, Liqiang Nie, Shuicheng Yan |
Pattern Recognit. | 2 |
| 2015 | A note on the security of KHL scheme
Jian Weng 0001, Yunlei Zhao, Robert H. Deng, Shengli Liu 0001, Yanjiang Yang, Kouichi Sakurai |
Theor. Comput. Sci. | 3 |
| 2015 | Attribute-Based Encryption With Efficient Verifiable Outsourced DecryptionabstractAttribute-based encryption (ABE) with outsourced decryption not only enables fine-grained sharing of encrypted data, but also overcomes the efficiency drawback (in terms of ciphertext size and decryption cost) of the standard ABE schemes. In particular, an ABE scheme with outsourced decryption allows a third party (e.g., a cloud server) to transform an ABE ciphertext into a (short) El Gamal-type ciphertext using a public transformation key provided by a user so that the latter can be decrypted much more efficiently than the former by the user. However, a shortcoming of the original outsourced ABE scheme is that the correctness of the cloud server's transformation cannot be verified by the user. That is, an end user could be cheated into accepting a wrong or maliciously transformed output. In this paper, we first formalize a security model of ABE with verifiable outsourced decryption by introducing a verification key in the output of the encryption algorithm. Then, we present an approach to convert any ABE scheme with outsourced decryption into an ABE scheme with verifiable outsourced decryption. The new approach is simple, general, and almost optimal. Compared with the original outsourced ABE, our verifiable outsourced ABE neither increases the user's and the cloud server's computation costs except some nondominant operations (e.g., hash computations), nor expands the ciphertext size except adding a hash value (which is <;20 byte for 80-bit security level). We show a concrete construction based on Green et al.'s ciphertext-policy ABE scheme with outsourced decryption, and provide a detailed performance evaluation to demonstrate the advantages of our approach. Baodong Qin, Robert H. Deng, Shengli Liu 0001, Siqi Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2015 | Software Puzzle: A Countermeasure to Resource-Inflated Denial-of-Service AttacksabstractDenial-of-service (DoS) and distributed DoS (DDoS) are among the major threats to cyber-security, and client puzzle, which demands a client to perform computationally expensive operations before being granted services from a server, is a well-known countermeasure to them. However, an attacker can inflate its capability of DoS/DDoS attacks with fast puzzle-solving software and/or built-in graphics processing unit (GPU) hardware to significantly weaken the effectiveness of client puzzles. In this paper, we study how to prevent DoS/DDoS attackers from inflating their puzzle-solving capabilities. To this end, we introduce a new client puzzle referred to as software puzzle. Unlike the existing client puzzle schemes, which publish their puzzle algorithms in advance, a puzzle algorithm in the present software puzzle scheme is randomly generated only after a client request is received at the server side and the algorithm is generated such that: 1) an attacker is unable to prepare an implementation to solve the puzzle in advance and 2) the attacker needs considerable effort in translating a central processing unit puzzle software to its functionally equivalent GPU version such that the translation cannot be done in real time. Moreover, we show how to implement software puzzle in the generic server-browser model. Yongdong Wu, Feng Bao 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2014 | Fully secure key-policy attribute-based encryption with constant-size ciphertexts and fast decryptionabstractAttribute-based encryption (ABE), introduced by Sahai and Waters, is a promising cryptographic primitive, which has been widely applied to implement fine-grained access control system for encrypted data. In its key-policy flavor, attribute sets are used to annotate ciphertexts and secret keys are associated with access structures that specify which ciphertexts a user is entitled to decrypt. In most existing key-policy attribute-based encryption (KP-ABE) constructions, the size of the ciphertext is proportional to the number of attributes associated with it and the decryption cost is proportional to the number of attributes used during decryption. In this paper, we present a new construction of KP-ABE. Our proposed construction is the first KP-ABE scheme, which has the following features simultaneously: expressive (i.e., supporting arbitrary monotonic access structures); fully secure in the standard model; constant-size ciphertexts and fast decryption. The downside of our construction is that secret keys have quadratic size in the number of attributes. Junzuo Lai, Robert H. Deng, Yingjiu Li, Jian Weng 0001 |
AsiaCCS | 2 |
| 2014 | Understanding OSN-based facial disclosure against face authentication systemsabstractFace authentication is one of promising biometrics-based user authentication mechanisms that have been widely available in this era of mobile computing. With built-in camera capability on smart phones, tablets, and laptops, face authentication provides an attractive alternative of legacy passwords for its memory-less authentication process. Although it has inherent vulnerability against spoofing attacks, it is generally considered sufficiently secure as an authentication factor for common access protection. However, this belief becomes questionable since image sharing has been popular in online social networks (OSNs). A huge number of personal images are shared every day and accessible to potential adversaries. This OSN-based facial disclosure (OSNFD) creates a significant threat against face authentication. In this paper, we make the first attempt to quantitatively measure the threat of OSNFD. We examine real-world face-authentication systems designed for both smartphones, tablets, and laptops. Interestingly, our results find that the percentage of vulnerable images that can used for spoofing attacks is moderate, but the percentage of vulnerable users that are subject to spoofing attacks is high. The difference between systems designed for smartphones/tablets and laptops is also significant. In our user study, the average percentage of vulnerable users is 64% for laptop-based systems, and 93% for smartphone/tablet-based systems. This evidence suggests that face authentication may not be suitable to use as an authentication factor, as its confidentiality has been significantly compromised due to OSNFD. In order to understand more detailed characteristics of OSNFD, we further develop a risk estimation tool based on logistic regression to extract key attributes affecting the success rate of spoofing attacks. The OSN users can use this tool to calculate risk scores for their shared images so as to increase their awareness of OSNFD. Yan Li 0075, Qiang Yan 0001, Yingjiu Li, Robert H. Deng |
AsiaCCS | 5 |
| 2014 | Verifiable Computation on Outsourced Encrypted Data
Junzuo Lai, Robert H. Deng, HweeHwa Pang, Jian Weng 0001 |
ESORICS (1) | 2 |
| 2014 | Authorized Keyword Search on Encrypted Data
Junzuo Lai, Yingjiu Li, Robert H. Deng, Jian Weng 0001 |
ESORICS (1) | 4 |
| 2014 | Identity-Based Encryption Secure against Selective Opening Chosen-Ciphertext Attack
Junzuo Lai, Robert H. Deng, Shengli Liu 0001, Jian Weng 0001, Yunlei Zhao |
EUROCRYPT | 2 |
| 2014 | ROPecker: A Generic and Practical Approach For Defending Against ROP Attacks
Yueqiang Cheng, Zongwei Zhou, Xuhua Ding, Robert H. Deng |
NDSS | 5 |
| 2014 | Cryptanalysis of a signcryption scheme with fast online signing and short signcryptext
Dehua Zhou, Jian Weng 0001, Chaowen Guan, Robert H. Deng, Min-Rong Chen, Kefei Chen |
Sci. China Inf. Sci. | 4 |
| 2014 | Editorial: Special issue on trust in cyber, physical and social computing
Zheng Yan 0002, Guojun Wang 0001, Valtteri Niemi, Robert H. Deng |
Comput. Secur. | 4 |
| 2014 | Cryptography in Cloud Computing
Robert H. Deng, Yang Xiang 0001, Man Ho Au |
Future Gener. Comput. Syst. | 1 |
| 2014 | Unforgeability of an improved certificateless signature scheme in the standard modelabstractCertificateless signature is an interesting cryptographic primitive which does not suffer from the inherent key escrow problem of identity‐based cryptography and the costly certificate management problem of traditional public key cryptography. Since security proofs in the random oracle model can only be viewed as heuristic arguments and cannot ensure the security in the real implementation, certificateless signature schemes with security proofs in the standard model (i.e. without random oracles) is more desirable. Some attempts have been devoted to propose certificateless signature schemes in the standard model, whereas all of these schemes are later shown to be either insecure or flawed in the security proofs. Recently, a new certificateless signature scheme in the standard model has been proposed. However, in this study the authors show that this scheme cannot resist the key replacement attack, and hence it is not existentially unforgeable. Chaowen Guan, Jian Weng 0001, Robert H. Deng, Min-Rong Chen, Dehua Zhou |
IET Inf. Secur. | 3 |
| 2014 | Towards semantically secure outsourcing of association rule mining on categorical data
Junzuo Lai, Yingjiu Li, Robert H. Deng, Jian Weng 0001, Chaowen Guan, Qiang Yan 0001 |
Inf. Sci. | 3 |
| 2014 | Technique for authenticating H.264/SVC and its performance evaluation over wireless mobile networks
Swee-Won Lo, Robert H. Deng, Xuhua Ding |
J. Comput. Syst. Sci. | 3 |
| 2014 | Efficient block-based transparent encryption for H.264/SVC bitstreams
Robert H. Deng, Xuhua Ding, Yongdong Wu, Zhuo Wei |
Multim. Syst. | 1 |
| 2014 | Efficient authentication and access control of scalable multimedia streams over packet-lossy networksabstractABSTRACT Securing scalable multimedia streams becomes an important issue with the emergence of various scalable multimedia coding standards and their wide spread applications. In this paper, we first propose two novel schemes for authenticating scalable multimedia streams over packet‐lossy networks. The first scheme uses a digital signature to protect the integrity of a group of frames and uses erasure correction coding to combat packet loss. The second scheme employs message authentication code to protect integrity of individual frames, which is completely resilient to packet loss and greatly improves computational efficiency compared with the first scheme. With the second authentication scheme, we further present a scheme that provides both authentication and access control to scalable multimedia streams over packet‐lossy networks. This third scheme uses symmetric encryption to enforce access control by allowing authorized users to decrypt substreams corresponding to their privileges and uses attribute‐based encryption to disseminate secret keys to users. For the first two schemes, we analyze their performance in terms of computation cost, communication overhead, buffer size, and probability of successful authentication, whereas for the third scheme, we demonstrate its application to H.264 scalable video coding encoded streams. Copyright © 2013 John Wiley & Sons, Ltd. Robert H. Deng, Xuhua Ding, Swee-Won Lo |
Secur. Commun. Networks | 1 |
| 2014 | A Hybrid Scheme for Authenticating Scalable Video CodestreamsabstractA scalable video coding (SVC) codestream consists of one base layer and possibly several enhancement layers. The base layer, which contains the lowest quality and resolution images, is the foundation of the SVC codestream and must be delivered to recipients, whereas enhancement layers contain richer contour/texture of images in order to supplement the base layer in resolution, quality, and temporal scalabilities. This paper presents a novel hybrid authentication (HAU) scheme. The HAU employs both cryptographic authentication and content-based authentication techniques to ensure integrity and authenticity of the SVC codestreams. Our analysis and experimental results indicate that the HAU is able to detect malicious manipulations and locate the tampered image regions while is robust to content-preserving manipulations for enhancement layers. Although our focus in this paper is on authenticating H.264/SVC codestreams, the proposed technique is also applicable to authenticate other scalable multimedia contents such as MPEG-4 fine grain scalability and JPEG2000 codestreams. Zhuo Wei, Yongdong Wu, Robert H. Deng, Xuhua Ding |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2014 | Key-Aggregate Cryptosystem for Scalable Data Sharing in Cloud StorageabstractData sharing is an important functionality in cloud storage. In this paper, we show how to securely, efficiently, and flexibly share data with others in cloud storage. We describe new public-key cryptosystems that produce constant-size ciphertexts such that efficient delegation of decryption rights for any set of ciphertexts are possible. The novelty is that one can aggregate any set of secret keys and make them as compact as a single key, but encompassing the power of all the keys being aggregated. In other words, the secret key holder can release a constant-size aggregate key for flexible choices of ciphertext set in cloud storage, but the other encrypted files outside the set remain confidential. This compact aggregate key can be conveniently sent to others or be stored in a smart card with very limited secure storage. We provide formal security analysis of our schemes in the standard model. We also describe other application of our schemes. In particular, our schemes give the first public-key patient-controlled encryption for flexible hierarchy, which was yet to be known. Cheng-Kang Chu, Sherman S. M. Chow, Wen-Guey Tzeng, Jianying Zhou 0001, Robert H. Deng |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2013 | Launching Generic Attacks on iOS with Approved Third-Party Applications
Jin Han 0002, Su Mon Kywe, Qiang Yan 0001, Feng Bao 0001, Robert H. Deng, Debin Gao, Yingjiu Li, Jianying Zhou 0001 |
ACNS | 5 |
| 2013 | Expressive search on encrypted dataabstractDifferent from the traditional public key encryption, searchable public key encryption allows a data owner to encrypt his data under a user's public key in such a way that the user can generate search token keys using her secret key and then query an encryption storage server. On receiving such a search token key, the server filters all or related stored encryptions and returns matched ones as response. Junzuo Lai, Xuhua Zhou, Robert H. Deng, Yingjiu Li, Kefei Chen |
AsiaCCS | 3 |
| 2013 | Designing leakage-resilient password entry on touchscreen mobile devicesabstractTouchscreen mobile devices are becoming commodities as the wide adoption of pervasive computing. These devices allow users to access various services at anytime and anywhere. In order to prevent unauthorized access to these services, passwords have been pervasively used in user authentication. However, password-based authentication has intrinsic weakness in password leakage. This threat could be more serious on mobile devices, as mobile devices are widely used in public places. Qiang Yan 0001, Jin Han 0002, Yingjiu Li, Jianying Zhou 0001, Robert H. Deng |
AsiaCCS | 5 |
| 2013 | Accountable Authority Identity-Based Encryption with Public Traceability
Junzuo Lai, Robert H. Deng, Yunlei Zhao, Jian Weng 0001 |
CT-RSA | 2 |
| 2013 | Anonymous Authentication of Visitors for Mobile Crowd Sensing at Amusement Parks
Divyan M. Konidala, Robert H. Deng, Yingjiu Li, Hoong Chuin Lau, Stephen E. Fienberg |
ISPEC | 2 |
| 2013 | Comparing Mobile Privacy Protection through Cross-Platform Applications
Jin Han 0002, Qiang Yan 0001, Debin Gao, Jianying Zhou 0001, Robert H. Deng |
NDSS | 5 |
| 2013 | Think Twice before You Share: Analyzing Privacy Leakage under Privacy Control in Online Social Networks
Yan Li 0075, Yingjiu Li, Qiang Yan 0001, Robert H. Deng |
NSS | 4 |
| 2013 | Adaptable Ciphertext-Policy Attribute-Based Encryption
Junzuo Lai, Robert H. Deng, Yanjiang Yang, Jian Weng 0001 |
Pairing | 2 |
| 2013 | A novel service-oriented intelligent seamless migration algorithm and application for pervasive computing environments
Haibin Cai, Chao Peng 0004, Robert H. Deng, Linhua Jiang |
Future Gener. Comput. Syst. | 3 |
| 2013 | Attribute-Based Encryption With Verifiable Outsourced DecryptionabstractAttribute-based encryption (ABE) is a public-key-based one-to-many encryption that allows users to encrypt and decrypt data based on user attributes. A promising application of ABE is flexible access control of encrypted data stored in the cloud, using access polices and ascribed attributes associated with private keys and ciphertexts. One of the main efficiency drawbacks of the existing ABE schemes is that decryption involves expensive pairing operations and the number of such operations grows with the complexity of the access policy. Recently, Greenproposed an ABE system with outsourced decryption that largely eliminates the decryption overhead for users. In such a system, a user provides an untrusted server, say a cloud service provider, with a transformation key that allows the cloud to translate any ABE ciphertext satisfied by that user's attributes or access policy into a simple ciphertext, and it only incurs a small computational overhead for the user to recover the plaintext from the transformed ciphertext. Security of an ABE system with outsourced decryption ensures that an adversary (including a malicious cloud) will not be able to learn anything about the encrypted message; however, it does not guarantee the correctness of the transformation done by the cloud. In this paper, we consider a new requirement of ABE with outsourced decryption: verifiability. Informally, verifiability guarantees that a user can efficiently check if the transformation is done correctly. We give the formal model of ABE with verifiable outsourced decryption and propose a concrete scheme. We prove that our new scheme is both secure and verifiable, without relying on random oracles. Finally, we show an implementation of our scheme and result of performance measurements, which indicates a significant reduction on computing resources imposed on users. Junzuo Lai, Robert H. Deng, Chaowen Guan, Jian Weng 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2013 | DriverGuard: Virtualization-Based Fine-Grained Protection on I/O FlowsabstractMost commodity peripheral devices and their drivers are geared to achieve high performance with security functions being opted out. The absence of strong security measures invites attacks on the I/O data and consequently posts threats to those services feeding on them, such as fingerprint-based biometric authentication. In this article, we present a generic solution called DriverGuard, which dynamically protects the secrecy of I/O flows such that the I/O data are not exposed to the malicious kernel. Our design leverages a composite of cryptographic and virtualization techniques to achieve fine-grained protection without using any extra devices and modifications on user applications. We implement the DriverGuard prototype on Xen by adding around 1.7K SLOC. DriverGuard is lightweight as it only needs to protect around 2% of the driver code’s execution. We measure the performance and evaluate the security of DriverGuard with three input devices (keyboard, fingerprint reader and camera) and three output devices (printer, graphic card, and sound card). The experiment results show that DriverGuard induces negligible overhead to the applications. Yueqiang Cheng, Xuhua Ding, Robert H. Deng |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2013 | A Collusion-Resistant Conditional Access System for Flexible-Pay-Per-Channel Pay-TV BroadcastingabstractPay-TV broadcasting system is an extensively deployed application that charges users based on their subscription. To ensure security for the Pay-TV broadcasting application, a conditional access system (CAS) is designed to control TV channel/program access to only the authorized subscribers. Several key management schemes with a four-level hierarchical key structure have been proposed. In this paper, we point out a severe security weakness of these schemes against collusion attacks. Then we propose a new CAS scheme with a three-level hierarchical key structure using ciphertext-policy attribute-set-based encryption (ASBE), an extension of ciphertext-policy attribute-based encryption (CP-ABE). Our scheme achieves scalable, flexible, fine-grained, and most importantly, collusion-resistant access control for Pay-TV broadcasting applications. The proposed scheme is designed to support all operations in Pay-TV applications. We then provide a detailed analysis on security and performance of our scheme. We also implement the scheme and it is showed to be both efficient and flexible for Pay-TV broadcasting applications. Zhiguo Wan, Jun-e Liu, Rui Zhang 0002, Robert H. Deng |
IEEE Trans. Multim. | 4 |
| 2013 | Attribute-Based Access to Scalable Media in Cloud-Assisted Content Sharing NetworksabstractThis paper presents a novel Multi-message Ciphertext Policy Attribute-Based Encryption (MCP-ABE) technique, and employs the MCP-ABE to design an access control scheme for sharing scalable media based on data consumers' attributes (e.g., age, nationality, or gender) rather than an explicit list of the consumers' names. The scheme is efficient and flexible because MCP-ABE allows a content provider to specify an access policy and encrypt multiple messages within one ciphertext such that only the users whose attributes satisfy the access policy can decrypt the ciphertext. Moreover, the paper shows how to support resource-limited mobile devices by offloading computational intensive operations to cloud servers while without compromising data privacy. Yongdong Wu, Zhuo Wei, Robert H. Deng |
IEEE Trans. Multim. | 3 |