Ruizhong Du

dblp:03/4574 · DBLP profile ↗
← Back
84ranked-venue papers
45as first author
79since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 23 · 11 first-author · 22 since 2021Computer networks · 21 · 13 first-author · 18 since 2021Security and privacy · 13 · 9 first-author · 13 since 2021Applied, interdisciplinary, general and emerging computing · 9 · 4 first-author · 9 since 2021Human-computer interaction and ubiquitous computing · 8 · 2 first-author · 8 since 2021Artificial intelligence and machine learning · 4 · 2 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 2 first-author · 4 since 2021Software engineering, systems software and programming languages · 3 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Joint Design of Positioning and Beamforming for Wideband Multi-User Movable Antenna Systems
Ruizhong Du, Songjie Yang, Chadi Assi
ICC2
2026 Practical collusion-resistant conjunctive dynamic searchable encryption with result pattern hiding
Honggang Wan, Ruizhong Du, Guanxiong Ha, Xiaoyun Guang
J. Inf. Secur. Appl.3
2026 DABD: Direction alignment-based backdoor defense with sign consensus in federated learning
Ruizhong Du
Knowl. Based Syst.2
2026 LPPUBR: Lightweight Privacy-Preserving Unsupervised Medical Image Bitmap Retrieval in IoT
abstract
With the widespread application of Internet of Things (IoT) technology in the medical field, real-time collection and transmission of medical images become feasible. However, existing privacy-preserving image retrieval schemes often suffer from low efficiency and high communication overhead when operated in resource-constrained IoT environments due to the lack of efficient models. Thus, achieving efficient and secure medicalimage retrieval on limited-resource devices has emerged as a critical challenge. To address this, we propose LPPUBR, a lightweight, privacy-preserving, unsupervised bitmap retrieval scheme designed for IoT environments with constrained resources. LPPUBR utilizes a secure and lightweight deep learning model to extract deep feature descriptors from images and employs product quantization (PQ) to encode them into binary bitmaps, enhancing retrieval efficiency while reducing computational and storage costs. Particularly, a cross-quantization contrastive learning strategy is applied to jointly train the neural network model and PQ codewords for unsupervised learning. Furthermore, to improve interaction efficiency and reduce communication costs among multiple servers, we optimize the intermediate value recovery operation and redesign the related protocols in n-party secret sharing using a group communication strategy. A comprehensive theoretical analysis and experimental evaluation demonstrate that LPPUBR maintains retrieval accuracy comparable to the original unsupervised model while ensuring data security. Moreover, LPPUBR surpasses existing schemes in terms of computational cost, communication overhead, and retrieval efficiency.
Ruizhong Du, Dongliang Xu, Chunfu Jia, Can Mei
IEEE Trans. Computers2
2026 Differentiated Privacy-Preserving Task Assignment Scheme Based on Generative Adversarial Networks in Spatial Crowdsourcing
abstract
Spatial crowdsourcing can quickly assign tasks and obtain feedback based on task requirements and workers’ locations, which brings great convenience to task assignment. However, sensitive information can also be easily obtained by spatial crowdsourcing platforms. To prevent information leakage, various privacy-preserving task assignment schemes have been proposed. However, existing schemes have low query efficiency and may leak pattern privacy, task content, or worker preference. To address the above challenges, this paper proposes a differentiated privacy-preserving task assignment scheme based on generative adversarial networks in spatial crowdsourcing–DPGAN-SC. This scheme leverages generative adversarial networks to generate disguised locations for both tasks and workers, which are then used in the task-matching process. Within the standard area range, no location can be distinguished, ensuring location privacy while preventing adversaries from analyzing search patterns through matching results. The combination of location disguise and task content encryption makes it impossible for adversaries to infer worker preferences and access patterns through the matching process. In addition, to meet differentiated privacy requirements, DPGAN-SC leverages generative adversarial networks to design a three-level privacy-classification mechanism. This mechanism categorizes private data while minimizing unnecessary privacy overhead. Compared to existing schemes, DPGAN-SC improves query efficiency by 100 times while ensuring comprehensive privacy preservation.
Caixia Ma, Weishuo Yuan, Chunfu Jia, Ruizhong Du, Guanxiong Ha
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.5
2026 BCEDAS: A Blockchain and Chameleon Hash-Based Efficient Decentralized Authentication Scheme for Internet of Vehicles With Multi-Scenario
abstract
The Internet of Vehicles (IoV) is a crucial component of Intelligent Transportation Systems, enhancing the intelligence and connectivity of transportation networks through comprehensive data support and communication capabilities. However, since each communication entity within the IoV operates in an open network environment, it is vulnerable to various threats, including user data leakage and vehicle operational security issues. Moreover, the IoV is highly time-sensitive, necessitating the design of a secure and efficient authenticated key agreement (AKA) protocol in IoV. Unfortunately, most current solutions only achieve one-to-one authentication and lack scalability for one-to-many or cross-domain scenarios. As a result, their efficiency remains limited, while alternative AKA schemes that support these use cases tend to introduce linearly increasing costs and computational overhead. To address these challenges simultaneously, we propose BCEDAS that utilizes chameleon hash function, physical unclonable functions and blockchain technology, which minimizes reliance on centralized trusted party while meeting essential security features, including unlinkability, non-repudiation, and side-channel attack mitigation. It also enables cross-domain authentication and multi-vehicle authentication across diverse scenarios. We conducted a comprehensive security deployment analysis by employing widely recognized Real-Or-Random model, along with the ProVerif tool. Furthermore, it exhibits competitive performance metrics in terms of computational efficiency, communication overhead, energy consumption, and average packet loss rate, which demonstrate the potential usability of BCEDAS in various environments.
Ruizhong Du
IEEE Trans. Intell. Transp. Syst.2
2026 Privacy-Preserving Image Retrieval With Deep Learning in Edge Computing
abstract
With the rapid development of edge computing and the explosive growth of image data generated by IoT and mobile devices, an increasing number of users prefer to perform privacy-preserving image storage and retrieval tasks directly at the edge. However, existing solutions typically rely on basic encryption methods and shallow feature extraction, leading to inadequate data security and poor retrieval performance. In this paper, we propose a Dynamic Multi-Stage Encryption (DMSE) method combined with a semantically rich fusion feature to achieve high-precision and privacy-preserving image retrieval in edge environments. Specifically, the proposed method first divides the image into blocks and applies random shuffling, followed by channel and pixel-level XOR encryption to generate a hybrid encrypted image. Then, we extract global features from the encrypted image using the histogram of Discrete Cosine Transform (DCT) coefficients. In addition, a multi-scale convolution block is designed to extract stable and robust local features under encryption. Finally, deep learning is utilized to fuse the global and local features, capturing both the holistic structure and fine-grained semantics of the image. This comprehensive feature representation significantly improves retrieval accuracy while ensuring privacy. Extensive experiments validate that our approach outperforms existing methods in both security and retrieval effectiveness, making it well-suited for edge computing scenarios with limited resources and high privacy demands.
Ruizhong Du, Chunfu Jia, Guanxiong Ha
IEEE Trans. Mob. Comput.3
2026 STDFL: A Spatio-Temporal-Aware Dynamic Federated Learning Framework for Spatial Crowdsourcing
Caixia Ma, Chunfu Jia, Liuling Qi, Ruizhong Du
IEEE Trans. Mob. Comput.6
2025 Multi-feature Fusion Leakage Abuse Attacks Against Dynamic Searchable Symmetric Encryption
Ruizhong Du
Inscrypt (1)1
2025 Collaborative Optimization of Label Protection in Large Language Models with an Adaptive Rényi Divergence Approach
abstract
Advancements in large language models (LLMs) are driving progress towards general artificial intelligence. Ensuring differential privacy during fine-tuning and inference on domain-specific data is essential, but balancing privacy and utility, especially for sequential and label data, remains challenging. Existing methods protect sequential data well but struggle with label data due to traditional definitions of label differential privacy, which ignore label-feature correlations and weaken label privacy. We propose an optimized privacy-utility trade-off for label data by introducing a new definition for conditional feature-label differential privacy and enhancing the double randomized response (DRR) mechanism with a Rényi divergence optimizer. Additionally, a dynamic perturbation factor function improves usability across various tasks. Experimental results show that our method enhances resistance to label inference attacks by over 20% while maintaining similar accuracy, offering stronger privacy with a reduced privacy overhead and achieving an optimal balance during LLMs fine-tuning and inference.
Siyi Zhang 0015, Xiaoyan Liang, Ruizhong Du, Jian Geng
CSCWD3
2025 Carchain: A Blockchain-Based Federated Learning Optimization Scheme in Autonomous-Driving Scenario
abstract
The aggregation process inherent in federated learning lacks auditability, rendering it susceptible to the influence of malicious nodes that may upload compromised models, thereby undermining the accuracy of the global model or potentially preventing successful aggregation altogether. In response to these challenges, this paper introduces “carchain”, a blockchain-based ecosystem designed to counteract poisoning and deception attacks within federated learning, while also establishing a framework of trust and incentives. Carchain employs a committee consensus mechanism to verify the accuracy of model updates off-chain. Additionally, it incorporates a reputation calculation mechanism that assesses the quality of model updates, coupled with an incentive structure based on reputation values to motivate the participation of high-quality nodes in the federated learning process. The results of experment indicate that carchain significantly enhances the security and efficiency of the system: when subjected to an attack involving 50% malicious trainers, the final model's loss is reduced to 86.9% compared to that of the BLFC methods; under an attack involving 50% malicious evaluators, the final model's loss is only 25.2% of that observed with direct detection methods. Additionally, the new incentive mechanism allows participants who contribute more data to earn additional tokens, thereby increasing motivation. Lastly, the storage overhead associated with the blockchain is reduced to 50.6% of that required by a single-chain structure.
Ruizhong Du
CSCWD1
2025 Lyapunov-Guided Deep Reinforcement Learning for Computation Offloading in Ocean Internet of Things
abstract
The Ocean Internet of Things consists of heteroge-neous network nodes, creating complex challenges for optimizing computation offloading within ocean mobile edge computing. To address these challenges, a new offloading framework is introduced that leverages attention-based deep reinforcement learning combined with Lyapunov optimization. This framework effectively addresses the coupling issues in multi-frame decision- making. The approach begins by transforming the original multi-stage, mixed-integer nonlinear programming problem into a deterministic form for each time frame using Lyapunov opti-mization. Deep reinforcement learning is then applied to manage long-term constraints. Furthermore, to improve environmental perception and action control, a Convolutional Neural Network with an enhanced parameter-sharing Deep Neural Network architecture is used to approximate policy and value functions. Additionally, a squeeze-and-excitation attention mechanism is integrated to strengthen feature extraction capabilities. Extensive simulations validate the superiority of this framework. Comparative results show that, in contrast to a framework only incorporating a CNN with a squeeze-and-excitation mechanism, this enhanced framework achieves roughly a 17 % reduction in training loss and a 5 % decrease in energy consumption.
Ruizhong Du
CSCWD1
2025 Joint Perturbation and Aggregation for Sparse Gradients in Federated Learning
abstract
Federated learning (FL) has become increasingly popular as a privacy-preserving, distributed training approach. However, recent studies have demonstrated that sensitive information can still be inferred from FL frameworks through certain attacks. Local differential privacy (LDP) provides privacy guarantees for FL and can help reduce potential privacy breaches. Despite this, current LDP-FL frameworks suffer from utility loss because the noise injected is directly proportional to the parameter dimension. To minimize noise, recent studies have employed private selection of the Top-k dimensions of the gradient vector. Yet, these methods are limited by their perturbations to individual data points and fail to address the dimensional dependency issue inherent in LDP. To overcome this challenge, we propose a novel joint perturbation method for sparse gradients, which is divided into two stages: perturbation of the gradient index vector and assignment of gradient values. Our method perturbs high-dimensional sparse gradient vectors as a whole, rather than individual gradients, thus reducing the noise injected into model gradients while preserving the necessary level of privacy. Moreover, to counteract the impact of the randomness introduced by perturbation on model performance, we integrate the Central Limit Theorem (CLT) into the gradient aggregation process, which we call CLT-Agg. We have validated our framework using public datasets, and our findings show a significant improvement over state-of-the-art methods. Extensive experiments have confirmed the effectiveness and efficiency of our proposed framework.
Yongwei Lu, Xiaoyan Liang, Ruizhong Du
CSCWD3
2025 AIDPFL: An Adaptive Improvement Approach for Differential Privacy Federated Learning
abstract
Federated learning enables participants to train on their local dataset, which solves the privacy preservation problem to some extent. However, attackers can still infer participants' private information from the uploaded parameters. Therefore, adding differential privacy further protects privacy. The key to differential privacy techniques is gradient clipping and gradient noise addition. In gradient clipping, a hyperparameter clipping threshold is introduced. Different combinations of clipping thresholds and learning rates lead to significant variations in accuracy, resulting in increased computational costs when searching for the optimal combination. In gradient noise addition, the gradient gradually decreases with training iterations. Adding fixed noise significantly affects the later stages of the model, leading to a decline in accuracy. In order to solve the above problems, this paper proposes An Adaptive Improvement Approach for Differential Privacy Federated Learning (AIDPFL), specifically (i) adjusting the clipping formula to combine the learning rate and the clipping thresholds under the premise of preserving the gradient information, only the learning rate needs to be adjusted. The clipping threshold size is adjusted in each round. (ii) Dynamically adjust the noise scale according to the gradient change, realize the dynamic decay rate to adjust the noise scale, and ensure that the privacy budget is reasonably allocated in the training process. Our method has higher usability and accuracy than the current primary adaptive differential privacy methods.
Jinkun Pan, Xiaoyan Liang, Ruizhong Du
CSCWD3
2025 ADMMOA: Attribute-Driven Multimodal Optimization for Face Recognition Adversarial Attacks
Ruizhong Du, Luman Zhao, Yidan Li, Shenyu Li, Caixia Ma
CVM (3)1
2025 ECPIR: Efficient and Controllable Privacy-Preserving Image Retrieval in Cloud-Assisted System
Ruizhong Du, Chunfu Jia
DASFAA (5)3
2025 Update Recovery Attacks on Two-Dimensional Encrypted Databases: Exploiting Volume Pattern Leakage in Range Queries
Ruizhong Du
ICIC (4)1
2025 MSIAA: Multi-scale Inversion Adversarial Attack on Face Recognition
Ruizhong Du, Shenyu Li
ICIC (4)1
2025 PDT-DPFL: Using Polynomial Data Transformations Realize Accurate, Differentially Private Federated Learning
Ruizhong Du, Xiaoyan Liang
ICIC (9)3
2025 Multilevel Matching Geometric Range Query Over Encrypted Spatial Data with Forward and Backward Privacy
abstract
The proliferation of spatial data applications (e.g., location-based services) has driven massive outsourcing of geospatial datasets to public clouds, yet exposing critical vulnerabilities to external hackers and internal adversaries. To address the dual challenges of securing fundamental geometric range queries while supporting dynamic updates, this paper proposes a dynamic searchable symmetric encryption scheme for geometric range search that complies with both forward privacy and backward privacy. Specifically, we build a multi-level balanced matching query index and constructthree layers of ciphertext to perform screeningand verification, enhancing query efficiencythrough three rounds of matching andscreening. Furthermore, we establish dual index directories deployed across two isolated servers, implementing cross-server query verification to guarantee single-dimensional range visibility per node. This architecture effectively conceals access patterns through spatial information segregation. Subsequently, we propose a ciphertext-update mechanism with embedded covert cryptographic operators, systematically detecting and neutralizing information leakage during update operations, thereby preserving both forward and backward privacy. Conclusively, comprehensive empirical evaluations demonstrate the scheme's operational efficiency and real-world applicability.
Yuehui Zhang, Ruizhong Du, Chunfu Jia
ICPADS3
2025 BRAFL: Byzantine-Robust Aggregation Scheme for Federated Learning under Data Heterogeneity
abstract
In federated learning, clients train models locally and upload only the model updates, while the server aggregates these updates through weighted averaging, effectively addressing the issues of data silos and privacy protection. However, in practical applications, some malicious clients may upload arbitrary model updates to the server, thereby hindering the convergence of the global model and ultimately leading to a decline in model performance. To address this problem, several Byzantine-robust aggregation schemes have been proposed. However, their effectiveness is significantly reduced in scenarios with data heterogeneity, and some robust schemes rely on prior knowledge of the number of malicious clients or require additional auxiliary datasets. Therefore, we propose a new Byzantine-robust aggregation scheme to mitigate the above issues. Specifically, we first use the median absolute deviation to identify anomalous gradient magnitudes and clip them to the median of the L2-norms, thereby avoiding excessively large gradient magnitudes that could alter the aggregation direction or lead to overly large updates. Next, we calculate the cosine distance between clients and apply the DBSCAN clustering method to group the updates, selecting the cluster with the largest number of elements as benign updates for aggregation while excluding malicious updates. Finally, an adaptive optimizer is employed on the server side to further mitigate data heterogeneity. Extensive experiments demonstrate that our method achieves superior performance under various Byzantine attacks in scenarios with data heterogeneity.
Mengxing Qiu, Ruizhong Du, Xiaoyan Liang
IJCNN3
2025 Saliency Semantic Ranking with Quality Restoration Synergistic Adversarial Attack on Face Recognition
Fengchen Shi, Jiashuo Mi, Ruizhong Du
PRCV (7)4
2025 GFPrompt: A Feedback-Driven Framework that Synergizes GRASP with LLMs for Discrete Prompt Optimization
abstract
While prompt engineering is crucial for leveraging large language models (LLMs), existing optimization methods struggle to balance exploration of the vast prompt space with exploitation of high-quality candidates. To address this imbalance, we propose GRASP-Feedback Prompt (GFPrompt), a novel framework that integrates a dynamic grouping strategy with a teacher-model feedback mechanism. GFPrompt partitions prompts based on their performance: low-scoring prompts are sent to a global exploration operator to ensure diversity, while high-scoring ones undergo local refinement to enhance quality. A teacher model further provides semantic feedback to accelerate convergence. Experiments on six NLP tasks demonstrate that GFPrompt significantly outperforms standard baselines, expert-designed prompts, and state-of-the-art automated methods by up to 10.6%, 6.6%, and 1.4%, respectively. Furthermore, it reduces token consumption by up to 10.3% compared to leading evolutionary approaches under the same iteration count. Our results validate GFPrompt’s effectiveness in achieving superior prompt quality and computational efficiency.
Xiaoyan Liang, Ruizhong Du
SMC3
2025 ConCloneDep: A Confidence-Aware Clone-Based Dependency Identification Approach in C/C++ Open-Source Components
abstract
With the growing importance of software supply chain security, automated identification of code reuse and dependency relationships among open-source components has become a critical task for building high-quality Software Bills of Materials (SBOMs). Existing code clone analysis methods such as CNEPS assist in component attribution and dependency extraction for C/C++ projects by utilizing function-level clone features. However, they exhibit significant shortcomings in complex multi-candidate component scenarios: their reliance on a single metric (clone function count) to determine the dominant component, combined with the lack of quantitative modeling for clone distribution uncertainty and component credibility, results in unstable dominant component selection and incorrect dependency edges.To address these limitations, we propose ConCloneDep, a method that preserves CNEPS’s module construction mechanism while introducing three key innovations: (1)a path-distance-first preliminary attribution strategy,(2)clone distribution entropy analysis, and (3)dominant component confidence modeling, thereby enabling quantitative evaluation of component attribution stability. For modules exhibiting high uncertainty, the method innovatively incorporates a neutral module mechanism to effectively mitigate the propagation of misjudged dependency edges. Experiments on 50 real-world open-source projects show that ConCloneDep achieves 85.2% dependency identification accuracy (versus CNEPS’s 79.1%) while maintaining 86.9% recall. It reduces incorrect dependency edges by 42.7% and improves average dependency edge confidence by 11%, significantly enhancing the reliability and accuracy of dependency analysis.
Jianxing He, Shan Yao, Xiaoyan Liang, Ruizhong Du
TrustCom5
2025 Deep reinforcement learning with dual-Q and Kolmogorov-Arnold Networks for computation offloading in Industrial IoT
Jinru Wu, Ruizhong Du
Comput. Networks2
2025 A Multi-Level Role-Based Provable Data Possession Scheme for Medical Cloud Storage
abstract
ABSTRACT Medical institutions are increasingly leveraging cloud servers to store electronic health records (EHRs), highlighting the need for robust data security measures to protect the sensitive personal information they contain. Our study introduces a blockchain‐enabled, fine‐grained data integrity auditing scheme that not only safeguards the confidentiality and integrity of EHRs within cloud‐based healthcare environments but also demonstrates a significant enhancement in data security with our statistical results, reinforcing the trustworthiness of cloud storage for sensitive medical data. The proposed scheme is notable for its support of dynamic user revocation, implementing a multi‐tiered role hierarchy that facilitates the efficient access revocation. In this hierarchy, adding new users or updating existing ones involves merely altering the edge labels, thereby obviating the need for a comprehensive recalculation of cryptographic keys. We have developed a smart contract‐based access control mechanism to ensure privacy while enabling granular access control. This mechanism leverages password and role‐based authentication to empower multi‐tiered roles with the ability to perform data integrity audits by their designated permissions. Through security analysis, we have substantiated that our protocol withstands attacks aimed at subversion, counterfeiting, and tag inconsistency. Compared to existing works, our approach uniquely integrates multi‐level role hierarchies with blockchain‐based dynamic revocation, achieving higher granularity and adaptability.
Ruizhong Du, Yuan Wan
Concurr. Comput. Pract. Exp.1
2025 TreePPFL: A Verifiable Secure and Efficient Federated Learning Framework
abstract
ABSTRACT In the context of federated learning, there are certain doubts about the credibility of cloud servers as third parties, as they have the potential to extract sensitive information from participants' local data from gradients. In addition, cloud servers may even resort to forging aggregation results, leading to the destruction of the global model and successfully avoiding detection mechanisms. Therefore, in building a secure federated learning system, it is crucial to ensure the privacy and aggregation correctness of upload gradients. This article proposes a secure and efficient federated learning privacy protection scheme TreePPFL (Tree Privacy Protection Federated Learning) based on hop‐by‐hop communication verifiability. By using single concealment technology to encrypt model parameters, the privacy of the uploaded gradient is protected. At the same time, a bidirectional verification scheme was designed, which applies a homomorphic hash algorithm to enable the cloud server to verify the legitimacy of the client, while also enabling the client to verify the aggregation correctness of the cloud server. The client transmits information through hop‐by‐hop communication, improving the training and verification efficiency of the cloud server and the entire federated learning system. The security of the scheme was verified through security analysis. The empirical experiment used two publicly available datasets, MNIST and CIFAR‐100, and compared them in iid and noniid scenarios. The results showed that the TreePPFL scheme exhibited superior performance compared to other schemes.
Ce Zhai, Wenchao Zhao, Ruizhong Du, Gang Hou
Concurr. Comput. Pract. Exp.5
2025 Secure Computation Offloading Using Enhanced Genetic Algorithm for Ocean IoT
Ruizhong Du
J. Grid Comput.1
2025 EVPIR: Efficient and Verifiable Privacy-Preserving Image Retrieval in Cloud-Assisted Internet of Things
abstract
With the proliferation of mobile devices and the advancement of cloud computing capabilities, cloud-assisted Internet of Things (IoT) attracts increased attention based on its computational and storage advantages. Upon these conveniences, there also raises privacy concerns that numerous solutions have been proposed to solve it. However, existing methods suffer from challenges such as low retrieval accuracy, inefficiency in large-scale image retrieval, and lack of efficient result verification. In this article, we propose an efficient verifiable privacy-preserving image retrieval scheme (EVPIR). Specifically, we design a hierarchical graph index to significantly enhance retrieval efficiency, which organizes image feature vectors into a multilevel structure, establishing connections between neighboring nodes within each layer and creating a highly structured and efficient retrieval framework. During the retrieval process, we employ a greedy search algorithm to navigate these connections and identify the closest neighbors across different levels, which makes the proposed multilevel approach reduce the search space at each level, achieving faster and more accurate retrieval. Furthermore, we design an efficient dynamic verifiable framework leveraging Chameleon hash functions and BLS signatures where we utilize Chameleon hash nodes based on Merkle hash trees (MHTs) to enable dynamic updates of the verification tree and employ BLS signatures to construct multiple verification nodes for effectively shortening the verification path. Finally, security analysis shows that EVPIR can defend various threat models and extensive experiments further demonstrate that EVPIR can improve retrieval and verification efficiency.
Ruizhong Du, Chunfu Jia
IEEE Internet Things J.3
2025 LP²CR-IoT: Lightweight and Privacy-Preserving Cross-Modal Retrieval in IoT
abstract
As a pivotal link between visual and linguistic relationships, image-text cross-modal retrieval has received widespread attention. However, existing studies primarily focus on intricate machine learning models to enhance retrieval accuracy and overlook the critical aspect of privacy preservation for images and texts, rendering them unsuitable for lightweight IoT environments. To tackle these challenges, we propose LPCR-IoT, a lightweight and privacy-preserving cross-modal retrieval scheme tailored to IoT environments. LPCR-IoT employs knowledge distillation to train lightweight student models for extracting feature vectors from images and texts, subsequently embedding them into a unified semantic space. Significantly, we propose a new training metric (i.e., Intra-modal Consistent Contrast Loss), which improves the retrieval accuracy by increasing the semantic consistency of the image and text in the common embedding space. Additionally, a novel quadtree index structure leveraging hybrid representation vectors is designed to effectively mitigate retrieval overhead, where feature vectors of images and texts alongside representation vectors are encrypted using a secure kNN algorithm based on LWE, enabling image-text matching in a large-scale ciphertext environment. Finally, we provide a detailed formal analysis to evaluate the security of LPCR-IoT and validate its practicality through extensive experiments on three real-world datasets, namely COCO, Flickr30k and NUS-WIDE.
Ruizhong Du, Chunfu Jia
IEEE Internet Things J.3
2025 Efficient Conjunctive Geometric Range Query Over Encrypted Spatial Data With Learned Index
abstract
With the increasing popularity of geo-positioning technologies and mobile Internet, spatial data query services have attracted extensive attention. To protect the confidentiality of sensitive information outsourced to cloud servers, much efforts have been devoted to designing geometric range query schemes over encrypted spatial data without affecting availability. However, existing works focus on the privacy-preserving schemes with traditional tree indexes, causing more computing and storage issues. In this paper, we propose an efficient conjunctive geometric range query scheme over encrypted spatial data with a learned index. In particular, we design a new privacy-preserving learned index for spatial data to reduce the search space and storage overhead. The main idea is to add noise disturbance to the objective function instead of directly adding it to output results, reducing the leakage of private information and ensuring the correctness of output results. Moreover, we propose a spatial segmentation algorithm to avoid accessing a large number of unnecessary Z codes in the query process. The formal security analysis shows that our scheme ensures index data security and query privacy. Simulation results show that the query efficiency is improved while the storage overhead is significantly reduced compared with the state-of-the-art schemes.
Chunfu Jia, Ruizhong Du, Guanxiong Ha
IEEE Trans. Computers3
2025 Verifiable Encrypted Image Retrieval With Reversible Data Hiding in Cloud Environment
abstract
With growing numbers of users outsourcing images to cloud servers, privacy-preserving content-based image retrieval (CBIR) is widely studied. However, existing privacy-preserving CBIR schemes have limitations in terms of low search accuracy and efficiency due to the use of unreasonable index structures or retrieval methods. Meanwhile, existing result verification schemes do not consider the privacy of verification information. To address these problems, we propose a new secure verification encrypted image retrieval scheme. Specifically, we design an additional homomorphic bitmap index structure by using a pre-trained CNN model with modified fully connected layers to extract image feature vectors and organize them into a bitmap. It makes the extracted features more representative and robust compared to manually designed features, and only performs vector addition during the search process, improving search efficiency and accuracy. Moreover, we design a reversible data hiding (RDH) technique with color images, which embeds the verification information into the least significant bits of the encrypted image pixels to improve the security of the verification information. Finally, we analyze the security of our scheme against chosen-plaintext attacks (CPA) in the security analysis and demonstrate the effectiveness of our scheme on two real-world datasets (i.e., COCO and Flickr-25 k) through experiments.
Ruizhong Du, Chunfu Jia
IEEE Trans. Cloud Comput.3
2025 Type classification and identification of IoT devices by using traffic characteristics
Ruizhong Du
Wirel. Networks1
2024 DP-Discriminator: A Differential Privacy Evaluation Tool Based on GAN
abstract
Differential privacy has become increasingly popular in private machine learning applications due to its provable ability to limit information leakage. However, there are often vulnerabilities in the practical implementation of differentially private algorithms, making it necessary to have effective tools for evaluating them before deployment. Unfortunately, the current state of the art classifier-based evaluation tools for differential privacy are still weakly distinguishable and need to be improved. In this paper, we propose a DP-Discriminator to automatically detect the ξ-differential distinguishability (ξ-DD) for specific algorithms, which is able to efficiently discover violations of differential privacy. Specially, we give a new attack definition of ξ-DD, based on a mathematical observation, which conduce to find a larger ξ. In addition, the proposed DP-Discriminator learns the overall distribution of features across samples depending on the ability of the generating adversarial network to capture the latent features. Benefiting from powerful classifiers, DP-Discriminator is able to automatically and accurately evaluate differential privacy with minimal time consumption. The experimental results demonstrate the effectiveness of the proposed method in estimating the ξ-DD for various practical randomized algorithms. For example, the latest work that detects the ξ-DD of the algorithm RAPPOR(0.4-DP) is 0.301, whereas our tool detects ξ-DD=0.369, with an error that is one order of magnitude lower.
Yushan Zhang, Xiaoyan Liang, Ruizhong Du
CF3
2024 Full Database Reconstruction: Leakage-Abuse Attacks Based on Expected Distributions
Ruizhong Du, Xijie She
ICIC (9)1
2024 Privacy-Preserving Retrieval Scheme Over Medical Images Based on Vision Transformer
Ruizhong Du
ICIC (8)1
2024 Privacy-preserving Searchable Encryption Based on Anonymization and Differential privacy
abstract
With the rapid development of cloud computing, more and more users are storing sensitive data on cloud servers, making the privacy-preserving of data particularly important. Dynamic searchable symmetric encryption enables efficient retrieval of encrypted data in cloud computing environments while preserving data privacy. However, existing solutions are not effective in defending against various query-recovery attacks. Therefore, this paper focuses on the privacy-preserving of dynamic searchable symmetric encryption, and proposes a privacy-preserving dynamic searchable symmetric encryption based on anonymization and differential privacy – DADP. Firstly, the original indexes are synthesized into fake indexes using the anonymization hash technology. The synthetic indexes possess randomness and irreversibility, making it impossible for adversaries to infer the generation process of the synthetic indexes or recover the original indexes. Additionally, by using differential privacy to process composite indexes, the privacy of keywords and index information is protected, preventing adversaries from inferring sensitive information based on query results. This approach provides dual privacy-preserving. Compared to other schemes, our scheme achieves type-I backward privacy and can withstand seven types of query recovery attacks. And it improves update and query efficiency by 10-100 times.
Caixia Ma, Chunfu Jia, Ruizhong Du, Guanxiong Ha
ICWS3
2024 Multi-attribute Semantic Adversarial Attack Based on Cross-layer Interpolation for Face Recognition
abstract
With the extensive research and application on Face Recognition (FR) model in daily life, the security of FR has attracted much attention as it is easily attacked by adversarial examples. Specifically, adversarial attacks can cause the model to make completely erroneous judgments by making very subtle changes to the source image. Therefore, it is of great significance for studying adversarial attacks that can improve the robustness and security of FR models. However, most of the existing attacks have low transferability of attack and high vulnerability to denoising defense models. To solve the above problems, a multi-attribute semantic adversarial attack based on cross-layer interpolation(C&A Adv) is proposed, which can generate imperceptible adversarial images whith high success rate and robustness to denoising defense methods. Particularly, C&A Adv semantically edit images by cross-layer feature space interpolation, which not only generates high quality adversarial images, but also has the robustness to partial denoising defense methods. In addition, to improve the success rate of the attack, several attributes are selected to edit instead of just one. According to the marginal gain of each attribute calculated in different face images, several attributes with the greatest marginal gain are selected to edit. Comparison and verification on CelebA dataset show that the C&A Adv achieves good experimental result.
Ruizhong Du, Yidan Li, Jinjia Peng, Caixia Ma
IJCNN1
2024 A Behavioral Recognition-Based Federated Learning Framework for IoT Environments
abstract
Identifying the behavior and intent of various Internet of Things (IoT) devices distributed across different environments is a challenge. The previous centralized modeling approach ran the risk of invading privacy. This study develops a federated learning approach enhanced by Long short-term memory (LSTM) networks to improve the accuracy of modeling the behavior of iot devices in decentralized networks. We extract periodic communication features locally at each node, focusing on relevant behavior sequences while protecting privacy. Applying LSTM to these periodic sequences captures the temporal dynamics necessary for behavioral modeling. The federated LSTM model then aggregates the locally learned behavior patterns to classify device sequences and interactions without sharing the raw data. Experiments show that this method can accurately identify the key behaviors of iot devices. By focusing on periodic communication, our technology enables collaborative device behavior identification across distributed nodes without compromising user privacy. This provides a pathway for privacy-protecting behavioral intelligent federated learning in iot environments.
Ruizhong Du, Pengyuan Zhao
IJCNN1
2024 MoonCross: Efficient and Secure Blockchain Sharding Scheme for Satellite-based IoT
abstract
Thanks to its vast and boundless coverage, Satellite-based Internet of Things (S-IoT) has been gaining increasing popularity in larger-scale modern intelligent applications. However, the scalability and security challenges triggered by distributed communication and services are severe in S-IoT. Long-distance communication and excessive devices and data contribute to increased latency, low throughput, and high resource consumption in most existing blockchain-based solutions for S-IoT. To address these challenges, we propose the blockchain sharding scheme MoonCross. Firstly, MoonCross leverages the concepts of relay chains and asynchronous consensus zones to achieve a space-ground collaborative sharding blockchain network, with Low Earth Orbit (LEO) satellites serving as the communication mediation. Secondly, to ensure the atomicity of cross-shard transactions in S-IoT of poor communication conditions and limited node resources, a blockchain rewriting mechanism named RBCVC is introduced. Thirdly, we conduct experimental evaluations of MoonCross’s performance. Results show that MoonCross outperforms state-of-the-art solutions in terms of efficiency and security for S-IoT.
Ruizhong Du
ISPA1
2024 Integrity Audit Scheme Based on Collaborative Cache in Industrial Internet of Things Environment
abstract
Edge caching can provide a limited delay guarantee for delay-sensitive industrial applications. However, in a highly distributed edge environment, cached data is prone to be damaged, and its integrity must be ensured. In this paper, we propose an integrity audit scheme based on collaborative caching in the Industrial Internet of Things (IIoT) environment. This scheme shifts the data storage function from the cloud core network to the edge network, allowing cooperation to fulfill user requests. Firstly, an end-edge-cloud collaborative caching mechanism is designed, partitioning cache space and achieving hierarchical placement through edge collaboration. Secondly, a cache value function combining content recommendation and cost is proposed; cache hit rate and value serve as constraints for replacement and update to dynamically adjust cache data in the edge network. Finally, the analysis proves the correctness and reliability of the scheme. Experimental results show that this scheme can quickly and effectively audit cached data, reduce waiting delay of industrial tasks, and address resource waste from invalid audits.
Ruizhong Du
ISPA1
2024 High-Precision Encrypted Image Retrieval Scheme Using Dual-Stream Convolution Feature Fusion in Cloud Computing
abstract
The retrieval of encrypted images in cloud computing is a research hotspot at present. However, the existing schemes have the problem of low image retrieval accuracy since it is difficult to obtain accurate feature information through convolutional neural network from encrypted image. In this paper, a secure image retrieval method using dual-stream convolution structure for feature fusion is proposed. Specifically, the stream cryptographic image containing contour features and the Fourier transform image containing frequency domain features are used as the two inputs of the convolutional network stream, where the weighted average gate function helps to integrate the feature information in these streams to achieve a more comprehensive feature representation and improve the retrieval accuracy. Furthermore, to keep the contour features of the encrypted image, the fuzzy image and Arnold mapping algorithm are selected randomly to encrypt the encrypted image twice. Experimental evaluation on three datasets, MNIST, Fashion-MNIST and CIFAR-100, shows that the proposed encryption method has higher security than AES and stream cipher encryption. In addition, the retrieval average accuracy (mAP) of this scheme is superior to the existing methods.
Liudong Zheng, Ruizhong Du, Chunfu Jia
ISPA4
2024 Secure Verification Encrypted Image Retrieval Scheme with Addition Homomorphic Bitmap Index
abstract
With growing numbers of users outsourcing images to cloud servers, privacy-preserving content-based image retrieval (CBIR) is widely studied. However, existing privacy-preserving CBIR schemes have limitations in terms of low search accuracy and efficiency due to the use of unreasonable indexing structures or retrieval methods. Meanwhile, existing result verification schemes do not consider the privacy of verification information. To address these problems, we propose a new secure verification encrypted image retrieval scheme. Specifically, we design an additional homomorphic bitmap index structure by using a pre-trained CNN model with modified fully connected layers to extract image feature vectors and organize them into a bitmap. It makes the extracted features more representative and robust compared to manually designed features, and only performs vector addition during the search process, improving search efficiency and accuracy. Moreover, we design a reversible data hiding (RDH) technique with color images, which embeds the verification information into the least significant bits of the encrypted image pixels to improve the security of the verification information and reduce the storage overhead. Finally, we analyze the security of our scheme against chosen-plaintext attacks (CPA) in the security analysis and demonstrate the effectiveness of our scheme on two real-world datasets (i.e., COCO and Flickr-25k) through experiments.
Ruizhong Du, Chunfu Jia
ICMR3
2024 AODPFL: An Adaptive Optimization Method for Differentially Private Federated Learning
abstract
Federated learning addresses the issues of data silos and privacy to some extent by training models locally on client devices, only uploading model parameters, and aggregating them on the central server. However, attackers can still infer private data information from the uploaded parameters. To solve this issue, differential privacy technology is introduced. The key to differential privacy lies in gradient clipping and noise addition. However, the traditional gradient clipping method often faces the gradient distortion issue and will be ineffective if the noise is large enough. Regarding noise addition, commonly used fixed or fixed decay rate noise scale settings often overlook the characteristics of gradients during training, which might lead to adding improper noise to gradients. To address these issues, we propose an adaptive optimization method for differentially private federated learning (AODPFL). Specifically, we adopt a strategy of clipping the gradient by grouping, effectively reducing gradient distortion. We design an adaptive clipping threshold based on the gradient changes during training to improve model accuracy under large noise conditions. We design a noise scale decay method with a dynamic decay rate to allocate the privacy budget more reasonably and inject appropriate noise into gradients. Experimental results show that compared to other gradient clipping and noise addition methods, our method achieves higher accuracy under the same privacy budget.
Mengxing Qiu, Xiaoyan Liang, Ruizhong Du
SMC3
2024 BTVD-BERT: A Bilingual Domain-Adaptation Pre-Trained Model for Textural Vulnerability Descriptions
abstract
Textural Vulnerability Descriptions(TVD) refers to the natural language description of a vulnerability in databases like National Vulnerability Database(NVD) and China National Vulnerability Database(CNVD), which typically provides a concise summary of critical vulnerability details. To facilitate the understanding of domain-specific terms in TVD and the accurate extraction of information, we have introduced a bilingual domain-adaptation pre-trained model called BTVD-BERT, aimed at enhancing the model's capability to process and understand vulnerability descriptions in both Chinese and English. We explore three issues, the first being the impact of catastrophic forgetting on the model. Second, how should the dataset be proportioned to best enhance the model's generalization capabilities across both Chinese and English. Third, the addition of extra task-related metric information to the original dataset to construct a higher quality dataset, and whether training with this high-quality dataset can further improve model performance. We attempted to study the issues from a data engineering perspective and conducted numerous ablation experiments to find answers to these three questions. The experimental results indicate that catastrophic forgetting adversely affects the model, causing it to forget previously acquired knowledge while better retaining more recently obtained information. By employing a training approach using a mix of Chinese and English data, we were able to mitigate the impact of catastrophic forgetting on the model to some extent. Optimizing data proportions and improving data quality can effectively enhance the overall performance of the model. This study not only enhances the identification and analysis of security vulnerabilities but also offers new perspectives and empirical support for the research of multilingual domain-adaptive models.
Xiaoyan Liang, Ruizhong Du
SMC3
2024 Trusted Networking for Drones: Reputation-Based Security Mechanisms for Node Access and Information Synchronization
abstract
In complex environments such as maritime search and rescue, the application of drone swarms has significantly improved the efficiency of search and rescue and effectively reduced the risk of casualties. However, they face serious security and privacy challenges, particularly when dealing with internal malicious node attacks and communication security threats, which can lead to leakage or tampering of rescue information, severely affecting the effectiveness of rescue operations and the safety of participants. To address these challenges, this paper proposes an innovative trustworthy drone networking framework that integrates trusted domain construction and information synchronization technologies. Firstly, a reputation-based voting mechanism is designed to ensure that only drones with good reputations are granted access to the trusted domain, thereby enhancing the overall credibility and reliability of the network. next, an improved lattice-based aggregate signature algorithm is developed for the information synchronization scheme, ensuring the authenticity of information and the integrity of data, effectively preventing information leakage and tampering. Through experimental validation, the proposed trustworthy drone networking framework demonstrates significant advantages over existing solutions in promptly detecting and responding to malicious attacks, with efficiency improved by 10%. Additionally, the designed aggregate signature algorithm successfully reduces time costs by approximately 9.16%, providing maritime search and rescue operations with more efficient, accurate, and secure communication support.
Ruizhong Du, Jiajia Kang
TrustCom1
2024 OFLGI: An Optimization-based Feature-Level Gradient Inversion Attack
abstract
Federated learning has become the leading paradigm for privacy-preserving distributed learning, as it only requires the upload of model gradients, not private data. However, recent studies have shown that these exchanged gradients can still lead to privacy leakage; for instance, attackers can recover private images through optimization-based gradient inversion attacks. In these attacks, pixel values in a dummy image are iteratively updated to approximate those of the private image. Yet, such optimization-based attacks often face challenges due to the large search space of the optimization task and struggle to accurately recover all labels in a batch. To tackle these, we propose the Optimization-based Feature-Level Gradient Inversion (OFLGI) attack, which focuses on optimizing image features rather than pixel values. This approach reduces the search space of the optimization task and enhances the quality of the reconstructed images. Our method formulates an optimization task to convert random noise features into natural image features, matching gradients while regularizing image fidelity. Notably, we are the first to utilize image features for gradient inversion attacks. Additionally, we introduce a novel batch label reconstruction algorithm that leverages the gradients of the biases in the final fully connected layer, surpassing existing methods even in the presence of duplicate labels. Furthermore, OFLGI demonstrates superior resistance to multiple gradient defense strategies, being able to recover high-quality private images even from degraded gradients. Extensive experiments have demonstrated the superiority of OFLGI over state-of-the-art gradient inversion techniques.
Yongwei Lu, Xiaoyan Liang, Ruizhong Du
TrustCom3
2024 StarCross: Redactable blockchain-based secure and lightweight data sharing framework for satellite-based IoT
Ruizhong Du
Comput. Networks1
2024 Privacy-preserving quadratic truth discovery based on Precision partitioning
Ruizhong Du, Zhuang Liang, Xiaoyan Liang
Comput. Secur.1
2024 Anonymous federated learning framework in the internet of things
abstract
Abstract With the continuous development of the internet of things (IoT), federated learning is being widely applied. This technology keeps data locally to protect data security. However, during the process of uploading gradients from local clients, there is a possibility of leaking sensitive information such as identities. To address this issue, this paper presents a secure and efficient anonymous federated learning framework. In our proposed, we first design a lightweight key‐sharing protocol based on elliptic curve cryptography (ECC) to generate shared keys and ensure secure communication. We then describe the improved process of federated learning, where clients communicate with the cloud server using pseudonyms to achieve anonymity. The security of our protocol is analyzed from both formal and informal perspectives, demonstrating that our proposed protocol satisfies “session key security.” We also employ the formal verification tool ProVerif to validate the security of the protocol in terms of mutual authentication and key configuration in the Dolve–Yao threat model. Finally, the computational and communication costs of the proposed anonymous federated learning framework are evaluated, showing that both the computational and communication expenses are relatively low. A comparison was made between the proposed federated learning process and three other federated learning processes, demonstrating the clear advantages of our proposed.
Ruizhong Du
Concurr. Comput. Pract. Exp.1
2024 DRC-EDI: An integrity protection scheme based on data right confirmation for mobile edge computing
abstract
As far as mobile edge computing is concerned, it is necessary to ensure the data integrity of latency-sensitive applications during the process of computing. While certain research programs have demonstrated efficacy, challenges persist, including the inefficient utilization of computing resources, network backhaul issues, and the occurrence of false-negative detections. To solve these problems, an integrity protection scheme is proposed in this paper on the basis of data right confirmation (DRC). Under this scheme, a two-layer consensus algorithm is developed. The outer algorithm is applied to establish a data authorization mechanism by marking the original data source to avoid the false negative results caused by network attacks from the data source. In addition, blockchain-based mobile edge computing (BMEC) technology is applied to enable data sharing in the context of mobile edge computing while minimizing the network backhaul of edge computing. Based on the Merkle Tree algorithm, the inner layer algorithm is capable not only of accurately locating and promptly repairing damaged data but also of verifying all servers in the mobile edge computing network either regularly or on demand. Finally, our proposal is evaluated against two existing research schemes. The experimental results show that our proposed scheme is not only effective in ensuring data integrity in mobile edge computing, but it is also capable of achieving better performance.
Ruizhong Du
J. Comput. Secur.2
2024 MSLShard: An efficient sharding-based trust management framework for blockchain-empowered IoT access control
Ruizhong Du
J. Parallel Distributed Comput.3
2024 Collaborative framework for UAVs-assisted mobile edge computing: a proximity policy optimization approach
Ruizhong Du, Bowen Cao
J. Supercomput.1
2024 Computing offloading and resource scheduling based on DDPG in ultra-dense edge computing networks
Ruizhong Du
J. Supercomput.1
2024 Dual-Q network deep reinforcement learning-based computation offloading method for industrial internet of things
Ruizhong Du, Jinru Wu
J. Supercomput.1
2024 MSLTChain: A Trust Model Based on the Multi-Dimensional Subjective Logic for Tree Sharding Blockchain System
abstract
Sharding is a popular technology for blockchain systems that addresses scalability while ensuring security and decentralization. However, there are still many issues. Firstly, the existing sharding solutions exhibit a high percentage of cross-shard transactions, which place a substantial burden on system resources and result in a significant degradation of performance. Secondly, none of these solutions adequately accounts for the inherent heterogeneity among nodes, and the interoperability of different nodes is constrained by security concerns, thereby impeding the practical advancement of blockchain applications. In this paper, a novel subjective logical trust-based tree sharding system, MSLTChain, is introduced to alleviate the processing workload of cross-shard transactions. The proposal encompasses a tree sharding structure and a trust management model, enabling the processing and validation of cross-shard transactions within the parent shard. Moreover, an adaptive algorithm is incorporated to dynamically fine-tune scalability, further augmenting system throughput. A subjective logical trust model is employed to portray the heterogeneity between nodes and enhance the system’s security level. The paper also conducts a comprehensive theoretical analysis, evaluating the security, scalability, and performance aspects. Finally, the experimental findings substantiate the capability of MSLTChain to satisfy the dual imperatives of scalability and security within the context of sharding blockchain.
Ruizhong Du
IEEE Trans. Netw. Serv. Manag.3
2024 A collaborative offloading framework for multiple UAV considering service caching
Ruizhong Du, Guangwen Yang 0001
Wirel. Networks1
2023 A Multi-label Privacy-Preserving Image Retrieval Scheme Based on Object Detection for Efficient and Secure Cloud Retrieval
Ruizhong Du
CGI (1)1
2023 A Highly Accurate Statistical Attack against Searchable Symmetric Encryption
abstract
Searchable symmetric encryption schemes(SSE) allow clients to search encrypted data stored on remote servers but ensure efficient retrieval by revealing specific information about the queries, such as access patterns. Honest but curious servers can then use these leakages to infer keywords queried by users. However, most attack schemes can only achieve considerable recovery accuracy (over 30%) under favorable conditions. When the auxiliary information is weak, the inference attack schemes using statistical information can achieve the same or even better recovery accuracy. In this paper, an attack based on statistical information is proposed. Our attack iteratively solves the quadratic recovery query problem using a linear optimization solver. With a tiny number of known queries (which can be deleted by the server), the query recovery accuracy can reach about 95% without knowing the exact background knowledge of the documents stored by the client. This process not only makes our scheme outperforms other attack schemes in accuracy but also makes our attack execution more efficient than other schemes, up to a maximum difference of 1000 seconds. The attack can still achieve considerable accuracy even when the defense is applied to the SSE scheme; defenses can help the SSE scheme obfuscate the pattern leakages.
Ruizhong Du, Yuchi Tai
ICPADS1
2023 Pattern-protecting Dynamic Searchable Symmetric Encryption Based on Differential privacy
abstract
Because it allows users to browse encrypted documents on an untrusted cloud server, searchable symmetric encryption has gotten a great deal of interest. However, based on the leakage of access and search patterns, the cloud server can infer users’ private data. Despite the fact that researchers have presented a number of strategies for protecting access or search patterns, all of them have a substantial computational and communication overhead. To that aim, this paper utilizes differential privacy technology to provide an efficient pattern-protecting dynamic searchable symmetric encryption scheme (DF-DSSE). Specifically, differential privacy’s false positives and false negatives are used to obfuscate the documents associated with each keyword, protecting access patterns. In particular, to reduce the computational and communication overhead associated by obfuscating query results, a tag symmetric encryption primitive is provided to encrypt indexes and query tokens. Furthermore, since the DF-DSSE scheme stores the token tags using the Bid Compress compression structure and accesses the documents corresponding to each keyword independently, an adversary cannot obtain the number of keywords or the frequency with which they are accessed, achieving the goal of protecting search patterns. In comparison to previous schemes, the DF-DSSE scheme enhances update and query efficiency and security, according to the security analysis and simulation experiment results.
Ruizhong Du, Caixia Ma
ICWS1
2023 Multi-Client Searchable Symmetric Encryption in Redactable Blockchain for Conjunctive Queries
abstract
Sharing and searching encrypted data securely in outsourced environments poses a challenge due to possible cooperation between compromised users and untrusted servers. This paper studies the problem of multi-client dynamic searchable symmetric encryption, where a data owner stores encrypted documents on an untrusted remote server and selectively allows multiple users to access them through keyword search queries. The paper proposes a practical multi-client conjunctive searchable symmetric encryption scheme in a redactable blockchain to address this challenge. This scheme achieves multi-client sublinear conjunctive keyword search, and the data owner can authorize clients to access the documents. The scheme combines encryption primitives with novel access control techniques and constructs a redactable blockchain$\zeta$-oblivious group cross tags for sublinear search. The system's security is proven in a simulation-based security model. A prototype implementation using a blockchain-based approach is developed and evaluated on a real-world database containing millions of documents to demonstrate its practicality.
Ruizhong Du, Caixia Ma
ISCC1
2023 RVDSE: Efficient Result Verifiable Searchable Encryption in Redactable Blockchain
abstract
To solve the inefficiencies, inflexibility in updates, and high storage costs associated with current result verifiable searchable encryption schemes, we propose an efficient scheme that result verifiable dynamic searchable encryption in a redactable blockchain (RVDSE). By dividing the inverted index into blocks, uploading corresponding verification tags to the blockchain, and using smart contracts to verify query results, we improve query and verification performance. Additionally, we employ blockchain rewriting technology to update tags in the result checklist, thereby improving blockchain data update performance and scalability while maintaining constant storage overhead. Security analysis confirms that our solution guarantees query result accuracy and completeness. Experimental results demonstrate that our approach enhances query and result verification efficiency, even with low-speed blockchain data scale growth, particularly as data collection scales increase.
Ruizhong Du
ISCC1
2023 CEIVS: A Scalable and Secure Encrypted Image Retrieval Scheme with Vertical Subspace Clustering
abstract
With the growing prominence of outsourcing services and increasing user concerns about security, existing encryption image retrieval schemes suffer from several limitations, such as low retrieval efficiency, poor retrieval accuracy, and inadequate scalability. Therefore, we propose an encrypted image retrieval scheme by dividing the clustering subspace with vertical parallels to construct indexes. Concretely, the data owners upload preprocessed classified datasets to a fully trusted auxiliary server. Subsequently, the auxiliary server clusters the images with the proximity relationships among their vector representations and employs the vertical bisecting lines of the key points to partition the clustered subspaces to encrypted indexes, namely the clustering encryption index of vertical subspace (CEIVS). This process efficiently filters out irrelevant images in advance, thereby enhancing the efficiency of encrypted retrieval. Ultimately, the Enhanced Asymmetric Scalar Product-preserving Encryption (E-ASPE) technique is adopted to ensure the security of the feature vectors, and a binary verification mechanism is proposed to detect data tampering, thereby ensuring the integrity of the retrieval results. While achieving data security, it is crucial to ensure that the results returned by the searchable encrypted image retrieval system align with the user queries, thereby enhancing the integrity of search results. Through comparative experimental analysis, this method outperforms existing solutions in terms of retrieval time and accuracy.
Ruizhong Du
TrustCom1
2023 Block verifiable dynamic searchable encryption using redactable blockchain
Ruizhong Du
J. Inf. Secur. Appl.1
2023 Refined statistical attacks against searchable symmetric encryption using non-indexed documents
Ruizhong Du, Yuchi Tai
J. Inf. Secur. Appl.1
2023 Enabling efficient and verifiable secure search on cloud-based encrypted big data
Ruizhong Du, Chenghao Yu
Peer Peer Netw. Appl.1
2023 Forward and Backward Secure Searchable Encryption Scheme Supporting Conjunctive Queries Over Bipartite Graphs
abstract
Dynamic searchable encryption, which allows clients to outsource their encrypted data to cloud servers and retain the ability to query and update data, has received wide attention. In the setting, it is essential to ensure that a server infers as little as possible about the content of the outsourced data and the queries it processes. In this article, we propose a forward and backward secure searchable encryption scheme on bipartite graphs (FBSSE-BG) that offers the strongest level of backward security. In particular, we introduce the notion of update counter to construct a new bi-directional index structure, which realizes conjunctive queries over bipartite graphs and supports flexible updates of outsourced data. Besides, to minimize the information revealed to servers, we propose a new oblivious data structure to store the bi-directional index and use a semantically-secure encryption scheme to encrypt node information, such that servers can only observe a series of ORAM locations and encrypted paths. Finally, we prove the security of FBSSE-BG by using the real-world versus ideal-world formalization and provide experimental efficiency evaluations for its implementations.
Chunfu Jia, Ruizhong Du
IEEE Trans. Cloud Comput.3
2023 DSE-RB: A Privacy-Preserving Dynamic Searchable Encryption Framework on Redactable Blockchain
abstract
With the development of various applications of blockchain, blockchain-assisted searchable encryption technology has received wide attention as it can eliminate misbehaviours of malicious servers through the verification and incentive mechanism of blockchain. However, most existing solutions update the encrypted data by means of appending new transactions, which does not scale and wastes resources. In this paper, we explore the potential of redactable blockchain and propose a privacy-preserving dynamic searchable encryption framework (DSE-RB), which is a general scheme that guarantees reliable queries and updates on encrypted data. In particular, we first use transaction-level editing technology to achieve a more flexible update operation of encrypted data without additional transactions while avoiding the waste of storage on the chain. To better support practical applications, we use an index partition method to divide the traditional binary tree index into a plurality of sub-indexes and introduce the concept of polynomials to simplify the whole access control mechanism. We define the security model and conduct repeated experiments on real data sets to test the efficiency. Experimental results and theoretical analysis show the practicability and security of our scheme.
Chunfu Jia, Ruizhong Du, Guanxiong Ha
IEEE Trans. Cloud Comput.3
2022 Real-time Audit Scheme Based on Multilevel Roles in a Medical Cloud Environment
abstract
To support the confidentiality and integrity requirements of electronic health records (EHRs) in the medical cloud storage environment, we propose a multilevel, role-based, real-time auditing scheme. Because of the special and sensitive nature of the data structures of shared EHRs, we adopt real-time auditing and deterministic auditing to improve the audit accuracies. By the use of fine-grained level access controls, we implement hierarchical auditing using different roles to avoid centralized auditing from suffering a single point of failure. The cloud server also supports accountability traceability to achieve nonrepudiation of the audit results. In comparisons with existing schemes, our scheme has lower storage overheads and better scalability than the existing solutions.
Ruizhong Du
ISCC1
2022 Blockchain-Based Ciphertext Policy-Hiding Access Control Scheme
Ruizhong Du, Tianhe Zhang
SecureComm1
2022 Authentication Mechanism Based on Physical Layer Security in Industrial Wireless Sensor Networks
Ruizhong Du, Lin Zhen, Yan Liu 0051
WASA (1)1
2022 Multiuser physical layer security mechanism in the wireless communication system of the IIOT
Ruizhong Du, Lin Zhen
Comput. Secur.1
2022 Collaborative Cloud-Edge-End Task Offloading in NOMA-Enabled Mobile Edge Computing Using Deep Learning
Ruizhong Du, Cui Liu, PengNan Hao
J. Grid Comput.1
2022 Fine-grained Web Service Trust Detection: A Joint Method of Machine Learning and Blockchain
abstract
Current website defacement detection methods often ignore security and credibility in the detection process. Furthermore, with the gradual development of dynamic websites, false positives and underreports of website defacement have periodically occurred. Therefore, to enhance the credibility of website defacement detection and reduce the false-positive rate and the false-negative rate of website defacement, this paper proposes a fine-grained trust detection scheme called WebTD, that combines machine learning and blockchain. WebTD consists of two parts: an analysis layer and a verification layer. The analysis layer is the key to improving the success rate of website defacement detection. This layer mainly uses the naive Bayes (NB) algorithm to decouple and segment different types of web page content, and then preprocess the segmented data to establish a complete analysis model. Second, the verification layer is the key to establishing a credible detection mechanism. WebTD develops a new blockchain model and proposes a multi-value verification algorithm to achieve a multilayer detection mechanism for the blockchain. In addition, to quickly locate and repair the defaced data of the website, the Merkle tree (MT) algorithm is used to calculate the preprocessed data. Finally, we evaluate WebTD against two state-of-the-art research schemes. The experimental results and the security analysis show that WebTD not only establishes a credible web service detection mechanism but also keeps the detection success rate above 98%, which can effectively ensure the integrity of the website.
Ruizhong Du, Cui Liu
J. Web Eng.1
2022 Support Vector Machine Intrusion Detection Scheme Based on Cloud-Fog Collaboration
Ruizhong Du, Xiaoyan Liang
Mob. Networks Appl.1
2022 Towards Multi-user Searchable Encryption Scheme with Support for SQL Queries
Ruizhong Du, Chunfu Jia
Mob. Networks Appl.2
2022 A Lightweight Flow Feature-Based IoT Device Identification Scheme
abstract
Internet of Things (IoT) device identification is a key step in the management of IoT devices. The devices connected to the network must be controlled by the manager. For this purpose, many schemes are proposed to identify IoT devices, especially the schemes working on the gateway. However, almost all researchers do not pay close attention to the cost. Thus, considering the gateway’s limited storage and computational resources, a new lightweight IoT device identification scheme is proposed. First, the DFI (deep/dynamic flow inspection) technology is utilized to efficiently extract flow-related statistical features based on in-depth studies. Then, combined with symmetric uncertainty and correlation coefficient, we proposed a novel filter feature selection method based on NSGA-III to select effective features for IoT device identification. We evaluate our proposed method by using a real smart home IoT data set and three different ML algorithms. The experimental results showed that our proposed method is lightweight and the feature selection algorithm is also effective, only using 6 features can achieve 99.5% accuracy with a 3-minute time interval.
Ruizhong Du, Jingze Wang
Secur. Commun. Networks1
2021 A Cross-domain Authentication Scheme Based on Zero-Knowledge Proof
Ruizhong Du
ICA3PP (2)1
2021 Identification of IoT Devices Based on Feature Vector Split
abstract
Device identification and management effectively prevent security issues caused by the massive access of Internet of Things (IoT) devices. However, when there is access of new devices and firmware upgrade of known devices in IoT, frequent model re-training based on multi-classing becomes difficult, which problem could be solved by developing a separate identification model for each device, but the identification accuracy is usually low due to model overlapping. In this article, we propose a method of feature vector splitting to reduce the overlap between models and develop a Sub-Vector Joint Model Group based on K-means algorithm, which can detect normal network behavior of each device and classify them in real-time. We evaluate the efficacy of our scheme with public dataset, and the result shows that the method we proposed could reach an overall accuracy of over 98%, and effectively reduce the training time and storage cost of the model simultaneously.
Ruizhong Du
ISCC1
2020 Virtual Machine Security Migration Strategy Based on the Edge Computing Environment
abstract
For mobile edge computing, the migration time between traditional cloud servers and edge devices is long, and there are security issues such as man-in-the-middle attacks in the process. In this regard, a migration scheme centered on edge nodes is proposed. The edge node is closer to the edge device, which can shorten the migration time. The solution uses the Transport Layer Security (TLS) protocol for key exchange to establish a session-secure communication channel, and virtual machine migration between edge devices is carried out in the channel by dynamic migration. The simulation results show that compared with that of other schemes, the migration time of the virtual machines is shortened. Security analysis shows that this solution can not only meet the requirements of data confidentiality and integrity but also resist man-in-the-middle attacks.
Ruizhong Du, Wangkai He
MSN1
2020 Verifiable Blockchain-Based Searchable Encryption with forward and backward privacy
abstract
Symmetric Searchable Encryption (SSE) is an ideal technology to secure searches. SSE is dedicated to improving data confidentiality without sacrificing the searchability of data. Currently, most SSE schemes work using a semihonest or curious cloud server model in which the search results are not absolutely trustworthy. Therefore, a verifiable SSE (VSSE) scheme is proposed to achieve data integrity verification. Although there are some solutions to the result verification problem, most of the schemes concentrate on a static environment and do not consider the issue of result verification in a dynamic environment. Therefore, this paper proposes a Verifiable Blockchain-Based Searchable Encryption with forward and backward privacy scheme (VBSEFB). First, VBSEFB supports local verification of the data returned by the cloud server in a dynamic environment. Second, our solution perfectly realizes forward and backward privacy and better guarantees data security than other methods. Finally, under the one-to-many model, the data owner's access control to data users is realized. A large number of experiments and evaluations prove the practicality of dynamically updating encrypted data.
Ruizhong Du
MSN1
2020 A lightweight heterogeneous network clustering algorithm based on edge computing for 5G
Ruizhong Du, Yan Liu 0051, Wenpeng Du
Wirel. Networks1
2005 A New Data Fusion Model of Intrusion Detection-IDSFP
Ruizhong Du
ISPA3
2005 D-S Evidence Theory and its Data Fusion Application in Intrusion Detection
abstract
Based on the D-S Evidence Theory and its Data Fusion technology, a new Intrusion Detection Data Fusion Model-IDSDFM is presented. This model can merge alerts of different types of IDSs, make intelligent inference by applying the D-S Evidence Theory, and estimate the current security situation according to the fusion result. Then some IDSs in the network are dynamically adjusted to strengthen the detection of the data that relate to the attack attempt. Consequently, the false positive rate and the false negative rate are effectively reduced, and the detection efficiency of IDS is accordingly improved.
Ruizhong Du
PDCAT3