EDBT 2026 Demo / reviewers in the wild / expert
Hao Ren 0001
dblp:02/5283-1
· DBLP profile ↗
29ranked-venue papers
7as first author
24since 2021 · last 2026
0000-0001-7909-3753ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 1 first-author · 11 since 2021Computer networks · 6 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 4 · 1 first-author · 4 since 2021Systems, architecture and hardware · 3 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Concretely Efficient Correlated Oblivious Permutation
Xiao Lan, Lei Zhang 0006, Hao Ren 0001, Lin Qu, Yuan Hong 0001 |
AsiaCCS | 5 |
| 2026 | CryptoScope: Utilizing Large Language Models for Automated Cryptographic Logic Vulnerability Detection
Zimo Ji, Hao Ren 0001, Xiao Lan |
ICPR (6) | 4 |
| 2026 | EvoJail: Evolutionary diverse jailbreak prompt generation for large language models
Rui Tang 0020, Kaiyu Xu, Pengsen Cheng, Hao Ren 0001, Haizhou Wang 0001, Shuyu Jiang |
Inf. Process. Manag. | 4 |
| 2026 | CLAD: Robust audio deepfake detection against manipulation attacks with contrastive learning
Haolin Wu 0001, Jing Chen 0003, Ruiying Du, Cong Wu 0003, Kun He 0008, Xingcan Shang, Hao Ren 0001, Guowen Xu |
Knowl. Based Syst. | 7 |
| 2026 | ${\mathsf{KubeSec}} $KubeSec: Automatic Detection of Takeover Risks Introduced by Third-Party Apps in the Kubernetes EcosystemabstractThird-party applications (TPAs) are integral components of managed Kubernetes clusters, but are also frequently exploited in takeover attacks. Recent incidents have demonstrated that TPAs can be weaponized to gain control over clusters. Given their critical role within the Kubernetes ecosystem, it is essential to explore the potential attack surfaces associated with various types of TPAs. To address this, we propose${\sf KubeSec}$, a framework that systematically investigates these risks by analyzing application permission configurations and component code dependencies. This investigation revealed a significant number of insecure RBAC binding patterns, uncovering 562 such patterns and identifying 375 vulnerabilities linked to 134 CVEs. These vulnerabilities impact millions of users, with an average remediation time exceeding 10 months. All findings have been reported to the relevant teams, leading to the assignment of 21 new CVEs by the community. These results highlight substantial security risks associated with TPAs in Kubernetes clusters and emphasize the urgent need for further research to develop more secure cluster management practices. Qiyu Hou, Hao Ren 0001, Xingshu Chen, Gelei Deng, Tianwei Zhang 0004, Guowen Xu, Hongwei Li 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Sanitizer: Blazing-Fast, Private, and Robust Federated LearningabstractRecently, private and robust federated learning (FL) schemes have been proposed to address privacy inference and Byzantine attacks simultaneously. However, existing schemes are inefficient in private and robust aggregation protocols due to the employment of heavy cryptographic techniques. To approach the above problem, we propose Sanitizer, an efficient, private, and robust FL framework. Specifically, we first design a Byzantine-robust defense for communication-efficient sign-based FL. We further propose a customized private and robust aggregation scheme built on our Byzantine-robust defense for FL. The core of our construction is two new efficient protocols, i.e.,high-dimensional boolean summationandweighted boolean majority vote, which serve as the main building blocks of Sanitizer. Extensive evaluations on real-world datasets demonstrate that Sanitizer is blazing fast, achieving 19 ∼ 23× less runtime compared to the state-of-the-art. Meanwhile, Sanitizer achieves the same accuracy as the plaintext and superior Byzantine robustness against various classic attacks. Hanxiao Chen 0001, Hongwei Li 0001, Meng Hao 0001, Jia Hu 0004, Hao Ren 0001, Haomiao Yang, Tianwei Zhang 0004, Guowen Xu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | PrivDNFIS: Privacy-preserving and Efficient Deep Neuro-Fuzzy Inference SystemabstractDeep Neuro-Fuzzy Inference Systems (DNFIS) seamlessly fuse neural networks with the fuzzy inference system enabling intricate decision-making and knowledge representation, while upholding a commendable degree of adaptability and interpretability. However, the challenge of privacy-preserving inference (PI) over DNFIS has remained largely uncharted, with no prior research addressing this critical issue. In this paper, we embark on an exploration of this issue. We introduce an efficient and secure PI framework for DNFIS, named PrivDNFIS, which leverages the post-quantum lattice-based homomorphic encryption to implement secure computation protocols for PI over DNFIS. Our work incorporates several non-trivial performance enhancements. Firstly, it consolidates multiple elements of input feature vectors into a single message, reducing encryption/decryption overhead. Secondly, building upon this novel encoding approach, PrivDNFIS can perform ciphertext aggregation and vector-vector inner production without necessitating time-consuming ciphertext rotation operations. Thirdly, we replace the softmax function in the DNFIS layer with a quadratic function to further enhance inference efficiency, without compromising the inference accuracy. Under the given threat model, we provide formal security proof for PrivDNFIS. In comprehensive experimental results, PrivDNFIS demonstrates an approximately 1.9 to 4.4 times reduction in end-to-end time cost compared to the benchmark. Hao Ren 0001, Xiao Lan, Rui Tang 0020, Xingshu Chen |
AAAI | 1 |
| 2025 | Decentralized Privacy-Preserving Authenticated Key Exchange Using Real-World AttributesabstractWhile decentralized authentication mechanisms have gained significant attention for enabling user-centric identity management without centralized authorities, the critical counterpart - authenticated key exchange (AKE) in decentralized settings - remains understudied. Although it forms the basis for secure communication in decentralized scenarios, shifting existing AKE protocols to decentralized settings is impractical: the trust assumption is different, and the insufficient support for dynamic identity attributes, etc. To address these challenges, we present a novel decentralized AKE protocol that innovatively integrates attribute authentication with key exchange through multi-party secure computation. Building upon MPCAuth's foundational framework (S&P 23), our protocol goes further to provide key exchange based on authentication of real-world attributes such as a digital passport and email address, etc. Our protocol establishes a new paradigm for decentralized AKE without complex credential operations and heavy zero-knowledge proof. The core of our protocol is a distributed way to securely reconstruct the attributes and establish a session key. We further evaluate its performance across multiple servers. Experimental results on servers under 5 demonstrate that it can finish the full AKE procedure in an acceptable time, enabling efficient and scalable multi-party key AKE in distributed environments. Xiao Lan, Hao Ren 0001, Kunpeng Bai |
ACSAC | 3 |
| 2025 | PPNA: Enabling Privacy-Preserving and Efficient Social Network AlignmentabstractSocial network alignment has made significant progress in social network analysis, with representative applications such as cross-domain recommendation and community detection. However, existing approaches require institutions to share raw user data, raising significant privacy concerns. To address this issue, we propose a Privacy-Preserving Network Alignment (PPNA) scheme that eliminates the need for raw data sharing. In concrete, PPNA leverages homomorphic encryption to enable computation over the ciphertext domain without decryption. It ensures provable data privacy. PPNA also presents a secure multiparty computation protocol to eliminate reliance on trusted third-party servers, which is often impractical in real-world scenarios. Furthermore, its well-designed iterative update mechanism is well-suited for iterative alignment algorithms. Comprehensive experimental results have demonstrated that PPNA improves performance compared to the scenario where raw data sharing is unfeasible due to privacy concerns. It achieves an average F1-score increase of 1.65 times and up to 2.28 times. The performance gain is more pronounced in decentralized settings, highlighting PPNA’s practicality in real-world scenarios when multi-institution collaboration is imperative. Rui Tang 0020, Hao Ren 0001, Haizhou Wang 0001, Xingshu Chen, Meng Li 0006, Hongwei Li 0001 |
GLOBECOM | 3 |
| 2025 | BSemiFL: Semi-supervised Federated Learning via a Bayesian ApproachabstractSemi-supervised Federated Learning (SSFL) is a promising approach that allows clients to collaboratively train a global model in the absence of their local data labels. The key step of SSFL is the re-labeling where each client adopts two types of available models, namely global and local models, to re-label the local data. While various technologies such as using the global model or the average of two models have been proposed to conduct the re-labeling step, little literature delves deeply into the performance dominance and limitations of the two models. In this paper, we first theoretically and empirically demonstrate that the local model achieves higher re-labeling accuracy over local data while the global model can progressively improve the re-labeling performance by introducing the extra data knowledge of other clients. Based on these findings, we propose BSemiFL which re-labels the local data through the collaboration between the local and global model in a Bayesian approach. Specifically, to re-label any given local sample, BSemiFL first uses Bayesian inference to assess the closeness of the local/global model to the sample. Then, it applies a weighted combination of their pseudo labels, using the closeness as the weights. Theoretical analysis shows that the labeling error of our method is smaller than that of simply using the global model, the local model, or their simple average. Experimental results show that BSemiFL improves the performance by up to $9.8\%$ as compared to state-of-the-art methods. Haozhao Wang, Shengyu Wang, Hao Ren 0001, Xingshuo Han, Wenchao Xu 0001, Shangwei Guo, Tianwei Zhang 0004, Ruixuan Li 0001 |
ICML | 4 |
| 2025 | VuldiffFinder: Discovering inconsistencies in unstructured vulnerability information
Qindong Li, Wenyi Tang, Xingshu Chen, Hao Ren 0001 |
Comput. Secur. | 4 |
| 2025 | An efficient and commercial proof of storage scheme supporting dynamic data updates
Zhenwu Xu, Xingshu Chen, Liangguo Chen, Xiao Lan, Hao Ren 0001, Changxiang Shen |
Comput. Secur. | 5 |
| 2025 | Decomposition, Synthesis, and Attack: A Multi-Instruction Fusion Method for Jailbreaking LLMsabstractLarge language models (LLMs) can transform natural language instructions into executable commands for IoT devices like unmanned aerial vehicles (UAVs), creating new development opportunities. However, safety concerns about LLMs translating commands into machine or program control instructions cannot be overlooked. Currently, jailbreak instructions used to test the LLM security are often restricted to specific modes or tasks, resulting in a lack of diversity and leaving some tasks unexplored. To address this issue, we introduce a Multi-Instruction Fusion (MIF) method that can automatically fuse harmful prompts and various task instructions into jailbreaks. Firstly, we adopt a reverse decomposition strategy to acquire sufficient supervised data for fusing harmful prompts and instructions into jailbreaks and construct a task instruction synthesizer based on it. Then, to determine the optimal instruction combinations in the vast combination space, we propose a representative-node-based selection strategy, ReNB, to rank and filter the instruction combinations on a few representative samples, thereby accelerating the identification of the valid ones. Experimental results demonstrate that MIF significantly improves the attack success rate, achieving over 90% on GPT-4o-mini, LLaMa2-70B and Qwen2-7B models, outperforming the state-of-the-art baselines. Shuyu Jiang, Xingshu Chen, Kaiyu Xu, Liangguo Chen, Hao Ren 0001, Rui Tang 0020 |
IEEE Internet Things J. | 5 |
| 2025 | Efficient privacy-preserving federated logistic regression with poor-quality users
Xingshu Chen, Hao Ren 0001, Changxiang Shen |
Peer Peer Netw. Appl. | 4 |
| 2025 | Rethinking the Design of Backdoor Triggers and Adversarial Perturbations: A Color Space PerspectiveabstractDeep neural networks (DNNs) are known to be susceptible to various malicious attacks, such as adversarial and backdoor attacks. However, most of these attacks utilize additive adversarial perturbations (or backdoor triggers) within an$L_{p}$-norm constraint. They can be easily defeated by image preprocessing strategies, such as image compression and image super-resolution. To address this limitation, instead of using additive adversarial perturbations (or backdoor triggers) in the pixel space, this work revisits the design of adversarial perturbations (or backdoor triggers) from the perspective of color space and conducts a comprehensive analysis. Specifically, we propose a color space backdoor attack and a color space adversarial attack where the color space shift is used as the trigger and perturbation. To find the optimal trigger or perturbation in the black-box scenario, we perform an iterative optimization process with the Particle Swarm Optimization algorithm. Experimental results confirm the robustness of the proposed color space attacks against image preprocessing defenses as well as other mainstream defense methods. In addition, we also design adaptive defense strategies and evaluate their effectiveness against color space attacks. Our work emphasizes the importance of the color space when developing malicious attacks against DNN and urges more research in this area. Wenbo Jiang 0001, Hongwei Li 0001, Guowen Xu, Hao Ren 0001, Haomiao Yang, Tianwei Zhang 0004, Shui Yu 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Efficiency Boosting of Secure Cross-Platform Recommender Systems Over Sparse DataabstractFueled by its successful commercialization, the recommender system (RS) has gained widespread attention. However, as the training data fed into the RS models are often highly sensitive, it ultimately leads to severe privacy concerns, especially when data are shared among different platforms. In this paper, we follow the tune of existing works to investigate the problem of secure sparse matrix multiplication for cross-platform RSs. Two fundamental and critical issues are addressed: preserving the training data privacy and breaking the data silo problem. Specifically, we propose two concrete constructions with significantly boosted efficiency. They are designed for the sparse location insensitive case and location sensitive case, respectively. State-of-the-art cryptography building blocks including homomorphic encryption (HE) and private information retrieval (PIR) are fused into our protocols with non-trivial optimizations. As a result, our schemes can enjoy the HE acceleration technique without privacy trade-offs. We give formal security proofs for the proposed schemes and conduct extensive experiments on both real and large-scale simulated datasets. Compared with state-of-the-art works, our two schemes compress the running time roughly by$10\times$and$2.8\times$. They also attain up to$15\times$and$2.3\times$communication reduction without accuracy loss. Hao Ren 0001, Guowen Xu, Tianwei Zhang 0004, Jianting Ning, Xinyi Huang 0001, Hongwei Li 0001, Rongxing Lu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Gupacker: Generalized Unpacking Framework for Android MalwareabstractAndroid malware authors often use packers to evade analysis. Although many unpacking tools have been proposed, they face two significant challenges: 1) They are easily impeded by anti-analysis techniques employed by packers, preventing efficient collection of hidden Dex data. 2) They are typically designed to unpack a specific packer and cannot handle malware packed with mixed packers. Consequently, many packed malware samples evade detection. To bridge this gap, we propose Gupacker, a novel generalized unpacking framework. Gupacker offers a generic solution for first-generation holistic packer by customizing the Android system source code. It identifies the type of packer and selects an appropriate unpacking function, constructs a deeper active call chain to achieve generic unpacking of second-generation function extraction packers, and usesJNIfunction and instruction monitoring to handle third-generation virtual obfuscation packer. On this basis, we counteract a diverse array of anti-analysis techniques. We conduct extensive experiments on 5K packed Android malware samples, comparing Gupacker with 2 commercial and 4 state-of-the-art academic unpacking tools. The results demonstrate that Gupacker significantly improves the efficiency of Android malware unpacking with acceptable system overhead. We analyze real packed applications based on Gupacker and found several are second-packed by attackers, including WPS for Android, with tens of millions of users. We receive and responsibly report 13 0day vulnerabilities and also assist in the remediation of all vulnerabilities. Qiyu Hou, Xingshu Chen, Hao Ren 0001, Meng Li 0006, Hongwei Li 0001, Changxiang Shen |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | VBSF: Vulnerability Behavior Scanning Framework for Intelligent Autonomous Transport SystemsabstractVulnerability behavior scanning plays a crucial role in securing Intelligent Autonomous Transportation Systems by ensuring protected communications and maintaining data integrity. Current scanning solutions, however, demonstrate several critical shortcomings: (1) their dependence on static analysis methods with predetermined scanning locations prevents dynamic adjustment of scanning strategies; (2) their limited capacity to capture data across multiple system layers fails to address sophisticated multi-layered attack patterns; and (3) their inability to dynamically activate monitoring probes hinders timely responses to newly emerging threats. To resolve these limitations, we present$\textsf {VBSF}$, an efficient and non-intrusive vulnerability scanning framework built upon extended Berkeley Packet Filter technology. The proposed system incorporates two key innovations: a dynamic probe activation mechanism that intelligently adjusts scanning locations in real-time to optimize resource usage, and a standardized data format that enables integrated analysis of vulnerability behaviors across different system layers. Experimental evaluations confirm that$\textsf {VBSF}$effectively identifies critical vulnerability behaviors in diverse attack scenarios while introducing only 1.47% additional system overhead. Hao Ren 0001, Lei Zhang 0101, Wenxian Wang, Meng Li 0006, Hongwei Li 0001 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2024 | FedDSE: Distribution-aware Sub-model Extraction for Federated Learning over Resource-constrained DevicesabstractSub-model extraction based federated learning has emerged as a popular strategy for training models on resource-constrained devices. However, existing methods treat all clients equally and extract sub-models using predetermined rules, which disregard the statistical heterogeneity across clients and may lead to fierce competition among them. Specifically, this paper identifies that when making predictions, different clients tend to activate different neurons of the entire model related to their respective distributions. If highly activated neurons from some clients with one distribution are incorporated into the sub-model allocated to other clients with different distributions, they will be forced to fit the new distributions, which can hinder their activation over the previous clients and result in a performance reduction. Motivated by this finding, we propose a novel method called FedDSE, which can reduce the conflicts among clients by extracting sub-models based on the data distribution of each client. The core idea of FedDSE is to empower each client to adaptively extract neurons from the entire model based on their activation over the local dataset. We theoretically show that FedDSE can achieve an improved classification score and convergence over general neural networks with the ReLU activation function. Experimental results on various datasets and models show that FedDSE outperforms all state-of-the-art baselines. Haozhao Wang, Yabo Jia, Meng Zhang 0045, Qinghao Hu 0004, Hao Ren 0001, Peng Sun 0006, Yonggang Wen 0001, Tianwei Zhang 0004 |
WWW | 5 |
| 2024 | Rethinking Membership Inference Attacks Against Transfer LearningabstractTransfer learning, successful in knowledge translation across related tasks, faces a substantial privacy threat from membership inference attacks (MIAs). These attacks, despite posing significant risk to ML model’s training data, remain limited-explored in transfer learning. The interaction between teacher and student models in transfer learning has not been thoroughly explored in MIAs, potentially resulting in an under-examined aspect of privacy vulnerabilities within transfer learning. In this paper, we propose a new MIA vector against transfer learning, to determine whether a specific data point was used to train the teacher model while only accessing the student model in a white-box setting. Our method delves into the intricate relationship between teacher and student models, analyzing the discrepancies in hidden layer representations between the student model and its shadow counterpart. These identified differences are then adeptly utilized to refine the shadow model’s training process and to inform membership inference decisions effectively. Our method, evaluated across four datasets in diverse transfer learning tasks, reveals that even when an attacker only has access to the student model, the teacher model’s training data remains susceptible to MIAs. We believe our work unveils the unexplored risk of membership inference in transfer learning. Cong Wu 0003, Jing Chen 0003, Qianru Fang, Kun He 0008, Ziming Zhao 0001, Hao Ren 0001, Guowen Xu, Yang Liu 0003, Yang Xiang 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2023 | Efficient Homomorphic Convolution for Secure Deep Learning InferenceabstractTo mitigate the ever-increasing privacy concerns of model inference, intensive efforts have been put to develop cryptograph-based private deep learning inference, that preserves the confidentiality of the submitted query and its inference result. However, privacy is not free but expensive as the secure computation over the ciphertext domain is time-consuming for both linear and non-linear layers, especially the homomorphic operations. To boost efficiency, a novel optimization is proposed for the evaluation of homomorphic convolutions, which is the most computation-intensive component throughout the entire inference processing. In specific, our approach involves the following critical designs. First, the Winograd fast convolution algorithm is applied to minimize the number of multiplications in convolutions. Second, we fuse this algorithm with the SIMD-enabled additive homomorphic encryption to expedite homomorphic convolution evaluation. Third, the sparsity of the model parameters is explored to further compress the computational cost brought by homomorphic encryption. In addition, it is non-trivial to extend the original Winograd algorithm to accommodate convolution operations, when kernels are larger than 3 × 3 and strides are greater than 1. We conquer this technical challenge and enable the applicability of the proposed optimizations for general convolution parameter configurations. In terms of performance, our scheme outperforms state-of-the-art secure inference methods, demonstrating a 2× reduction in the number of multiplications for convolution evaluation and a 30% improvement in end-to-end latency. Xiaoyuan Liu 0002, Hongwei Li 0001, Qinyuan Qian, Hao Ren 0001 |
PST | 4 |
| 2022 | Privacy-Preserving Efficient Verifiable Deep Packet Inspection for Cloud-Assisted MiddleboxabstractWith the increasing traffic volume, enterprises choose to outsource their middlebox services, such as deep packet inspection, to the cloud to acquire rich computational and communication resources. However, since the traffic is redirected to the public cloud, information leakages, such as packet payload and inspection rules, arouse privacy concerns of both middlebox owner and packet senders. To address the concerns, we propose an efficient verifiable deep packet inspection (EV-DPI) scheme with strong privacy guarantees. Specifically, a two-layer architecture is designed and deployed over two non-collusion cloud servers. The first layer fast filters out most of legitimate packets and the second layer supports exact rule matching. During the inspection, the privacy of packet payload and the confidentiality of inspection rules are well preserved. To improve the efficiency, only fast symmetric crypto-systems, such as hash functions, are used. Moreover, the proposed scheme allows the network administrator to verify the execution results, which offers a strong control of outsourced services. To validate the performance of the proposed EV-DPI scheme, we conduct extensive experiments on the Amazon Cloud. Large-scale dataset (millions of packets) is tested to obtain the key performance metrics. The experimental results demonstrate that EV-DPI not only preserves the packet privacy, but also achieves high packet inspection efficiency. Hao Ren 0001, Hongwei Li 0001, Guowen Xu, Nan Cheng 0001, Xuemin Shen |
IEEE Trans. Cloud Comput. | 1 |
| 2022 | Enabling Secure and Versatile Packet Inspection With Probable Cause Privacy for Outsourced MiddleboxabstractMiddlebox is an intermediary network equipment which can be outsourced to remote cloud servers for low-cost and customizable network services, such as load balancer and intrusion detection. A fundamental function of the middlebox is packet inspection, where both the packet header and payload are extracted and analyzed based on inspection rules. However, as the packet may contain sensitive individual or organizational information, it may raise severe privacy concerns without proper countermeasures. In this article, we propose a secure and versatile packet inspection scheme for outsourced middlebox. The proposed scheme builds upon two non-collusion cloud servers, where the first server conducts the inspection task over the ciphertext domain and the second reveal the inspection results. By doing so, the proposed scheme achieves versatile inspection functionalities: range-query-based header inspection and token-based payload inspection, while preserving the privacy of packet header, payload, and inspection rules. Moreover, we identify and address two challenging issues in the state-of-the-art literatures. First, we tailor the design of mis-operation resistant searchable homomorphic encryption (MR-SHE) and somewhat homomorphic encryption in the two-server model, to resistoffline dictionary attack on payload headers. Second, we propose a key management mechanism with compelled access for the middlebox, to achievefine-grained probable cause privacy. We also conduct extensive experiments and compare the results with existing schemes to demonstrate the feasibility of the proposed scheme. Hao Ren 0001, Hongwei Li 0001, Guowen Xu, Xuemin Shen |
IEEE Trans. Cloud Comput. | 1 |
| 2022 | DNA Similarity Search With Access Control Over Encrypted Cloud DataabstractDNA similarity search has been widely applied in human genomic studies including DNA marking, genomic sequencing and genetic disease prediction. Meanwhile, with the explosive growth of data, users are increasingly inclining to store DNA data on the cloud for saving local cost. However, the high sensitivity of DNA data has forced the government to strictly control its acquisition and utilization. One potential solution is to encrypt DNA data before outsourcing them to the cloud. Nevertheless, private DNA similarity query has been an active research issue, state-of-the-art results are still defective in security, functionality, and efficiency. In this article, we propose EFSS, an efficient and fine-grained similarity search scheme over encrypted DNA data. In specific, first, we design an approximation algorithm to efficiently calculate the edit distances between two sequences. Second, we put forward a novel Boolean search strategy to achieve complicated logic queries such as mixed “AND” and “NO” operations on genes. Third, data access control is also supported in our EFSS through a variant of polynomial based design. Moreover, the K-means clustering algorithm is exploited to further improve the efficiency of execution. In the end, security analysis and extensive experiments demonstrate the high performance of EFSS compared with existing schemes. Guowen Xu, Hongwei Li 0001, Hao Ren 0001, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Cloud Comput. | 3 |
| 2020 | Secure and Verifiable Inference in Deep Neural NetworksabstractOutsourced inference service has enormously promoted the popularity of deep learning, and helped users to customize a range of personalized applications. However, it also entails a variety of security and privacy issues brought by untrusted service providers. Particularly, a malicious adversary may violate user privacy during the inference process, or worse, return incorrect results to the client through compromising the integrity of the outsourced model. To address these problems, we propose SecureDL to protect the model’s integrity and user’s privacy in Deep Neural Networks (DNNs) inference process. In SecureDL, we first transform complicated non-linear activation functions of DNNs to low-degree polynomials. Then, we give a novel method to generate sensitive-samples, which can verify the integrity of a model’s parameters outsourced to the server with high accuracy. Finally, We exploit Leveled Homomorphic Encryption (LHE) to achieve the privacy-preserving inference. We shown that our sensitive-samples are indeed very sensitive to model changes, such that even a small change in parameters can be reflected in the model outputs. Based on the experiments conducted on real data and different types of attacks, we demonstrate the superior performance of SecureDL in terms of detection accuracy, inference accuracy, computation, and communication overheads. Guowen Xu, Hongwei Li 0001, Hao Ren 0001, Jianfei Sun, Shengmin Xu, Jianting Ning, Haomiao Yang, Kan Yang 0001, Robert H. Deng |
ACSAC | 3 |
| 2020 | Catch You If You Deceive Me: Verifiable and Privacy-Aware Truth Discovery in Crowdsensing SystemsabstractTruth Discovery (TD) is to infer truthful information by estimating the reliability of users in crowdsensing systems. To protect data privacy, many Privacy-Preserving Truth Discovery (PPTD) approaches have been proposed. However, all existing PPTD solutions do not consider a fundamental issue of trust. That is, if the data aggregator (e.g., the cloud server) is not trustworthy, how can an entity be convinced that the data aggregator has correctly performed the PPTD? A "lazy" cloud server may partially follow the deployed protocols to save its computing and communication resources, or worse, maliciously forge the results for some shady deals. In this paper, we propose V-PATD, the first Verifiable and Privacy-Aware Truth Discovery protocol in crowdsensing systems. In V-PATD, a publicly verifiable approach is designed enabling any entity to verify the correctness of aggregated results returned from the server. Since most of the computation burdens are carried by the cloud server, our verification approach is efficient and scalable. Moreover, users' data is perturbed with the principles of local differential privacy. Security analysis shows that the proposed perturbation mechanism guarantees a high aggregation accuracy even if large noises are added. Compared to existing solutions, extensive experiments conducted on real crowdsensing systems demonstrate the superior performance of V-PATD in terms of accuracy, computation and communication overheads. Guowen Xu, Hongwei Li 0001, Shengmin Xu, Hao Ren 0001, Yinghui Zhang 0002, Jianfei Sun, Robert H. Deng |
AsiaCCS | 4 |
| 2019 | Toward Efficient and Secure Deep Packet Inspection for Outsourced MiddleboxabstractWith the increasing network traffic volume in the big data era, enterprises have paid significant attentions on outsourcing middlebox services to the public cloud. While offering appealing benefits, including network resource scalability and management cost reduction, it also raises severe privacy and security issues, such as the exposure of packet payload and middlebox rules. Since the traffic is redirected to cloud server, the exposure of packet payload and middlebox rule becomes inevitable. Simply encrypting the traffic can mitigate this problem at the cost of sacrificing data utility, which poses great challenges on deep packet inspection. In this paper, an efficient and secure Deep Packet Inspection (DPI) scheme is proposed based on non-collusion two cloud servers to enable data utility, while protecting the packet payload and middlebox rules. We leverage encrypted Matryoshka filter and T-set to process DPI. Since both the middlebox rule and packet payload are encrypted, cloud server cannot breach the confidentiality of them. We also build a secure hash chain to prevent the leakage of token order information. Extensive experiments demonstrate that proposed scheme performances better in terms of packet processing, rule preparation and rule matching. Hao Ren 0001, Hongwei Li 0001, Xuemin Shen |
ICC | 1 |
| 2016 | Towards Efficient Privacy-Preserving Truth Discovery in Crowd Sensing SystemsabstractWith the rapid development of portable mobile devices, crowd sensing systems have been recognized as a key technology to utilize the data collected by the portable mobile devices towards scalable and flexible mobile services. However, since the information provided by devices may not be reliable, the aggregated results of the collected data may not be accurate. To tackle this challenge, various truth discovery schemes have been proposed. On the other hand, a practical issue of privacy protection is not considered in most existing truth discovery schemes. In this paper, we propose an Efficient Privacy-preserving Truth Discovery (EPTD) in Crowd Sensing Systems, which can protect the privacy of users' observed values and weights in truth discovery process. Finally, we show the performance of our scheme is better than existing models in terms of computation overhead. Guowen Xu, Hongwei Li 0001, Hao Ren 0001, Yuan-Shun Dai, Xiaohui Liang 0002 |
GLOBECOM | 4 |
| 2016 | Efficient privacy-preserving circular range search on outsourced spatial dataabstractWith the growing popularity of outsourcing data and services to the cloud, performing queries on encrypted data becomes a promising technique. Searchable encryption (SE) allows encryption while still enabling search for a variety of data. However, most of the existing arts focus on rectangular range query on common database. Query on encrypted spatial database has not been well studied. Moreover, as a vital type of geometric query on spatial data, the circular range search (CRS) is widely utilized in Location-Based Services (LBSs) and computational geometry. A recently proposed CRS scheme achieved security and privacy requirements. However, it exhibits low performance in terms of encryption and search efficiency. In this paper, we propose an Efficient Privacy-preserving CRS scheme (EP-CRS) on outsourced spatial data. Specifically, our scheme achieves CRS by leveraging an R-tree based SE scheme and adding a trusted-third party (TTP) to system. Security analysis indicates that EP-CRS can preserve data and query privacy. In addition, we conduct real experiments and compare EP-CRS with the existing one to show that the proposal is more efficient in terms of data encryption, token generation and search. Hao Ren 0001, Hongwei Li 0001, Michael Kpiebaareh, Lian Zhao |
ICC | 1 |