EDBT 2026 Demo / reviewers in the wild / expert
Qin Liu 0001
dblp:06/2123-1
· DBLP profile ↗
82ranked-venue papers
25as first author
37since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 30 · 9 first-author · 16 since 2021Systems, architecture and hardware · 24 · 8 first-author · 6 since 2021Databases, data management, data science and information retrieval · 8 · 3 first-author · 3 since 2021Security and privacy · 7 · 2 first-author · 5 since 2021Software engineering, systems software and programming languages · 5 · 2 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Boosting Adversarial Transferability via Ensemble Non-AttentionabstractEnsemble attacks integrate the outputs of surrogate models with diverse architectures, which can be combined with various gradient-based attacks to improve adversarial transferability. However, previous work shows unsatisfactory attack performance when transferring across heterogeneous model architectures. The main reason is that the gradient update directions of heterogeneous surrogate models differ widely, making it hard to reduce the gradient variance of ensemble models while making the best of individual model. To tackle this challenge, we design a novel ensemble attack, NAMEA, which for the first time integrates the gradients from the non-attention areas of ensemble models into the iterative gradient optimization process. Our design is inspired by the observation that the attention areas of heterogeneous models vary sharply, thus the non-attention areas of ViTs are likely to be the focus of CNNs and vice versa. Therefore, we merge the gradients respectively from the attention and non-attention areas of ensemble models so as to fuse the transfer information of CNNs and ViTs. Specifically, we pioneer a new way of decoupling the gradients of non-attention areas from those of attention areas, while merging gradients by meta-learning. Empirical evaluations on ImageNet dataset indicate that NAMEA outperforms AdaEA and SMER, the state-of-the-art ensemble attacks by an average of 15.0% and 9.6%, respectively. This work is the first attempt to explore the power of ensemble non-attention in boosting cross-architecture transferability, providing new insights into launching ensemble attacks. Yipeng Zou, Qin Liu 0001, Jie Wu 0001, Yu Peng 0003, Guo Chen 0001, Hui Zhou 0014, Guanghui Ye |
AAAI | 2 |
| 2026 | LO-GDRL: Privacy-preserving online task allocation based on Lyapunov optimization and graph-based deep reinforcement learning in mobile crowdsensingabstractIn Mobile Crowdsensing (MCS), online task allocation ensures timely task completion and improves overall system performance in dynamic environments through real-time scheduling and optimizing resource utilization. Existing Deep Reinforcement Learning methods have several limitations, including poor model performance, low system stability, and the problem of data privacy leakage. To address these issues, this paper proposes a lightweight privacy-preserving online task allocation framework called LO-GDRL (Lyapunov Optimization with Graph-based Deep Reinforcement Learning). LO-GDRL formulates NP-hard online task allocation as a graph-constrained optimization problem and designs a Deep Reinforcement Learning method with a new Dual-branch Graph Attention Dueling Network to enhance dynamic environment adaptation and complex dependency capture capability. To improve system stability, LO-GDRL establishes a dynamic-queue mechanism for dynamic resource coordination based on Lyapunov Optimization. Additionally, while preserving worker location privacy through differential privacy, the system achieves an optimal privacy-performance trade-off. The case studies on the simulation data of MCS systems based on the two real-world datasets verify the effectiveness of the proposed framework and demonstrate that our framework achieves more stable and superior performance across diverse environments compared to state-of-the-art methods. Yuhong Tan, Tao Peng 0011, Guojun Wang 0001, Qin Liu 0001, Tian Wang 0001 |
Comput. Networks | 4 |
| 2026 | VulTrLM: LLM-assisted vulnerability detection via AST decomposition and comment enhancement
Shaobo Zhang 0001, Qianzhi Wang, Qin Liu 0001, Tao Peng 0011 |
Empir. Softw. Eng. | 3 |
| 2026 | CAA: Toward Camouflaged and Transferable Adversarial ExamplesabstractTransferable adversarial examples (AEs) are visually indistinguishable from benign images, but can successfully mislead unknown deep neural networks. However, existing AEs normally vary considerably from benign images in the feature space, making them hard to pass label checking and adversarial detection. Therefore, how to make AEs camouflaged, disguising as benign images during detection is still an open problem. In this paper, we propose a novel camouflaged adversarial attack (CAA), which produces camouflaged adversarial examples (CAEs) for the first time. Our main idea is to make CAEs’ adversarial properties keep “dormant” state until the target model inadvertently triggers the “activated” state. To this end, we craftattackandcamouflageperturbations, so that CAEs are visually and feature/label-wise indistinguishable from benign images at first, but will implicitly turn into AEs once being triggered. Specifically, we exploit two common preprocessing operations, image scaling and JPEG compression, as the trigger, and propose a two-stage optimization strategy. As the preprocessing details of target models are unknown, the first stage trains a well-designed generative adversarial network under varying scaling/compression parameters to enhance the robustness of attack perturbations. The second stage uses feature (dis)similarities and contrastive distances to improve the transferability of camouflage perturbations. Extensive experiments on ImageNet dataset validate the effectiveness of CAA. Especially for robust models, the average fooling rate after preprocessing could reach 96.3% outperforming the state-of-the-art adversarial attack by 13.5%. Yipeng Zou, Qin Liu 0001, Jie Wu 0001, Tian Wang 0001, Guo Chen 0001, Tao Peng 0011, Guojun Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | EdgeManager: Online Adaptive Resource Management for Hierarchical DNN Inference in Collaborative Edge EnvironmentsabstractThe rapid integration of Artificial Intelligence (AI) and Internet of Things (IoT) technologies has led to the pro liferation of AIoT applications, significantly escalating demands for computing and communication resources in multi-user, multitask scenarios. A critical challenge lies in efficiently managing resource allocation to ensure Quality of Service (QoS) for diverse Deep Neural Network (DNN) inference tasks. Existing edge cloud collaborative inference approaches partially address this by hierarchical resource management; however, these methods often overlook the joint optimization of computation, communication, and data quality, and neglect long-term system stability in dynamic environments. To address these limitations, we propose EdgeManager, an online adaptive resource management frame work for hierarchical DNN inference in collaborative heterogeneous edge environments. Specifically, we formulate a Mixed Integer Nonlinear Programming (MINLP) optimization problem aimed at balancing inference accuracy and latency. Leveraging Lyapunov optimization, we transform the complex, multi-stage dynamic optimization problem into manageable deterministic sub-problems for each time slot, ensuring long-term stability. Furthermore, we introduce HyDRL-MO, a hybrid approach integrating model-free Deep Reinforcement Learning (DRL) and model-based multi-decision optimization techniques to achieve efficient and stable resource allocation. Extensive experimental evaluations demonstrate that EdgeManager significantly improves system performance, achieving up to 42.08% enhancement in average system benefits compared to state-of-the-art solutions. Wenhua Wang 0003, Qin Liu 0001, Wentao Fan 0001, Weifeng Su, Weijia Jia 0001, Tian Wang 0001, Jiannong Cao 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2025 | As-Stg: Spatio-Temporal Graph Learning with Active Sampling for Dynamic IoT SensingabstractEfficient sensing is critical for Internet of Things (IoT) applications, such as environmental monitoring and traffic management, where high quality sensing data is essential for decision-making. Traditional sensing methods, however, are often plagued by high deployment costs and incomplete data coverage, significantly limiting their practicality. Despite recent progress, these methods continue to face challenges in maintaining data accuracy, ultimately degrading the Quality of Service (QoS) for IoT applications. To address these limitations, we propose ASSTG, a novel framework that combines an Active Sampling strategy with Spatio-Temporal Graph learning to enable efficient and accurate IoT sensing. At its core, AS-STG is designed to minimize the sampling cost while ensuring the accuracy of the data. The framework begins by analyzing historical data to determine the minimum sampling requirements for accurate inference in subsequent time slots. It then constructs a spatio-temporal graph to model the complex relationships between sensing grids, capturing both spatial and temporal dynamics. To supplement the spatio-temporal information and further optimize representations, we introduce two contrastive learning tasks. Leveraging the refined representation, AS-STG strategically selects informationrich regions for sampling, ensuring that even a sparse subset of samples can provide comprehensive coverage of the entire sensing area. Finally, AS-STG employs matrix completion techniques to reconstruct the complete sensing data from these sparse samples. Extensive experiments on real-world datasets demonstrate that AS-STG significantly outperforms baselines in terms of inference accuracy, cost-efficiency, and scalability. By effectively reducing sampling costs without compromising QoS, AS-STG offers a robust and scalable solution for dynamic IoT sensing systems. Yaxin Mei, Jiandian Zeng, Huiling Qin, Guangxue Zhang, James Xi Zheng, Qin Liu 0001, Tian Wang 0001 |
IWQoS | 6 |
| 2025 | VADP: Visitor-attribute-based adaptive differential privacy for IoMT data sharing
Shaobo Zhang 0001, Lujie Zhang, Tao Peng 0011, Qin Liu 0001, Xiong Li 0002 |
Comput. Secur. | 4 |
| 2025 | P2-TaskMP: Privacy-Preserving Task Allocation Optimization Based on Mobility Prediction
Zhidong Xie, Tao Peng 0011, Guojun Wang 0001, Qin Liu 0001 |
Future Gener. Comput. Syst. | 5 |
| 2025 | Online Dependent Task Offloading by Application Partitioning in Edge Intelligence for Internet of VehiclesabstractThe Internet of Vehicles offers a comprehensive perception of environment, which enhance transportation efficiency. To handle the large amount of collected data, distributed edge intelligence is a promising paradigm in which the edge server share data and computing resources with each other, providing low-latency services for local devices. However, offloading the computing-intensive application fully to one edge server might lead to a large latency as the computing resource of edge servers are usually limited. To solve this problem and elevate Quality of Service (QoS) to new heights, existing methodologies merely partition applications into modules, overlooking the crucial fact that these modules harbor distinct input requirements, posing a pivotal challenge in scheduling optimization. In this article, we study dependent task offloading by partitioning applications and dividing modules into two categories: 1) stateful modules and 2) statelss modules. The stateful modules necessitate the incorporation of previous calculation results, while stateless modules operate independently. We subsequently frame this intricate dependent task offloading challenge as an optimization problem, boldly acknowledging its NP-hard nature. Considering this, we unveil an innovative online collaborative dependent task offloading (OCDTO) algorithm, grounded in a two-layer collaborative edge computing architecture. This algorithm meticulously minimizes the make-span, redefining the benchmarks for efficiency. Our rigorous experimentation not only validates but also showcases the superiority of our approach, consistently achieving the lowest average system cost compared to the state-of-the-art, which verifies the effectiveness of our proposed approach in latency-sensitive and computing-intensive scenarios. Wenhua Wang 0003, Qin Liu 0001, Tian Wang 0001, Weijia Jia 0001 |
IEEE Internet Things J. | 4 |
| 2025 | APBAM: Adversarial perturbation-driven backdoor attack in multimodal learning
Shaobo Zhang 0001, Xiong Li 0002, Qin Liu 0001, Guojun Wang 0001 |
Inf. Sci. | 4 |
| 2025 | Enhancing Collaborative Inference on Heterogeneous Edge Devices via Adaptive Ensemble Knowledge DistillationabstractThe integration of edge computing with deep neural networks (DNNs) is crucial for intelligent industrial cyber-physical systems. Typically, deploying DNNs on heterogeneous edge devices relies on methods like model compression and partitioning. However, these approaches often result in homogeneous models across devices. This homogeneity limits the collective capability of edge computing systems, particularly in terms of generalization to diverse data distributions and adaptation to dynamic industrial environments. In this work, we propose to treat each DNN on an edge device as an independent model, aggregating their capabilities via ensemble learning to enhance generalization and dynamic adaptability. To realize this, we introduce the Adaptive Ensemble Knowledge Distillation Framework (AEKDF), combining cloud-based model training with edge computing based collaborative inference. In the cloud, AEKDF develops an enhanced Born Again Network that generates diverse, lightweight models tailored to specific edge devices through knowledge distillation. This process ensures model diversity which is critical to effective ensemble learning. On the edge, AEKDF employs an adaptive ensemble technique that aggregates prediction logits across devices, enabling rapid adaptation to changing environments and maintaining inference efficiency. Our extensive evaluations conducted on a realistic prototype demonstrate the substantial boost in predictive performance achieved by our AEKDF, showcasing a 4% to 10% accuracy improvement on the CIFAR-100 compared to conventional single-model approaches, while maintaining low latency. Shangrui Wu, Yupeng Li 0001, Wenhua Wang 0003, Jianxiong Guo, Wentao Fan 0001, Qin Liu 0001, Weijia Jia 0001, Shui Yu 0001, Jiannong Cao 0001, Tian Wang 0001 |
IEEE J. Sel. Areas Commun. | 6 |
| 2025 | Heterogeneous Device Collaboration Based Federated Learning for Big Data ApplicationsabstractIn the era of Big Data, artificial intelligence and information science are the key technologies to extract the value of data and enhance the competitiveness of enterprises. The characteristics of distributed, small-scale, and sparse lead to the isolated data island problem. To solve these problems, Federated Learning is proposed. However, a large number of terminal models need to be uploaded to the server in Federated Learning, especially for the actual scenario of Internet of Things. Therefore, huge communication costs are required which dramatically increases the pressure on the backbone network. Furthermore, the low quality of the local model will lead to decreased accuracy and convergence rates of the model. To overcome the above limitations, we propose heterogeneous device collaboration based federated learning (HDCFL), which constructs a three-layer structure for Federated Learning by leveraging edge computing and designs a heterogeneous device collaboration method that groups the terminals based on their computing power, communication time, and data volume to train the model. Then, we conduct a theoretical analysis of the proposed algorithm which verifies its advantage. At last, the experimental result demonstrates that the proposed algorithm consistently achieves superior performance in terms of both convergence speed and accuracy compared with state-of-the-art baselines. Wenhua Wang 0003, Quan Yang, Yuzhu Liang, Yang Xu 0013, Qin Liu 0001, Tian Wang 0001 |
IEEE Trans. Big Data | 5 |
| 2025 | DRMQ: Dynamic Resource Management for Enhanced QoS in Collaborative Edge-Edge Industrial EnvironmentsabstractIn the fast-developing industrial environments, extensive focus on resource management within Mobile Edge Computing (MEC) aims to ensure low-latency QoS, however, some tasks offloaded to the cloud still experience high latency. Additionally, high energy consumption, poor link reliability, and excessive processing delays are intolerable for industrial applications. Compared to general servers, edge computing devices based on Arm architecture exhibit lower latency and higher energy efficiency. This highlights the need for improved heterogeneous Collaborative Edge-Edge Industrial Environments (CEIE) and precise multi-user QoS metrics. Thus, we focus on dynamic resource management within the CEIE architecture to better satisfy diverse industrial applications, formulating a multi-stage Mixed Integer Nonlinear Programming (MINLP) problem to minimize system costs. To reduce the computational complexity of solving the MINLP, we decompose the original problem into multi-user task offloading, Communication Resource Allocation (CmRA), and Computational Resource Allocation (CpRA) problems. These transformed problems are then tackled using DRMQ: an integrated learning optimization approach that combines model-free, priority experience replay-based Double Deep Q-Network (iDDQN) with model-based optimization, accelerating the Q-value function's convergence speed and reducing training time. Extensive simulations show that our proposed optimization scheme can reduce the average weighted system cost by at least 43.168% . Moreover, testbed experiments demonstrate that the proposed algorithm can reduce the average system cost by at least 42.650% in real-world applications, outperforming existing methods. Wenhua Wang 0003, Qin Liu 0001, Wentao Fan 0001, Jianxiong Guo, Weijia Jia 0001, Jiannong Cao 0001, Tian Wang 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2025 | Collaborative Edge Server Placement for Maximizing QoS With Distributed Data CleaningabstractThe proliferation of contaminated data on Internet of Things (IoT) devices has the potential to undermine the accuracy of data-driven decision-making by altering the distribution of original data. Existing data cleaning methods primarily depend on cloud center or cloud-edge cooperation, leading to prolonged data transmission delays and reduced cleaning accuracy. In this study, we identify edge server placement as a crucial step aligned with data cleaning and view the collaborative edge server placement with distributed data cleaning (SPDC) as a holistic problem. We comprehensively quantify the complexity of our issue through the analysis of numerous scenarios. To address this problem, we introduce a novel distributed collaborative edge framework comprising two key stages: server placement and data cleaning. We propose an optimized clustering algorithm for the former, considering the data distribution on the IoT layer and the constraints of the edge layer. For the latter, we introduce a gossip-based data cleaning algorithm that fully utilizes edge collaboration to enhance data cleaning accuracy. The algorithm exhibits an approximate performance complexity of O($\ln m$), where$m$represents the number of users’ tasks. Both theoretical analysis and experimental results reveal that our algorithm an average improvement in data cleaning accuracy of 9.02% and a reduction in delay of 36.61%, surpassing the performance of state-of-the-art works in various scenarios. Yuzhu Liang, Mujun Yin, Wenhua Wang 0003, Qin Liu 0001, Liang Wang 0017, James Xi Zheng, Tian Wang 0001 |
IEEE Trans. Serv. Comput. | 4 |
| 2024 | Efficient Request Scheduling in Cross-Regional Edge Collaboration via Digital Twin NetworksabstractIn cloud computing, user requests sent to centralized servers often encounter delay due to network unpredictability, impacting the Quality of Service (QoS) for time-sensitive applications. We propose edge collaboration, utilizing the coordination of edge nodes within regions to handle requests more efficiently and reduce latency. However, edge nodes across different regions struggle with lack of immediate data on resources cached elsewhere, complicating inter-regional request scheduling. To address it, we introduce a federated digital twin model that creates a network linking edge nodes to reflect and update resource statuses in real time. Additionally, we refine the Dijkstra algorithm to optimize routing to the nearest edge nodes based on current network conditions, thereby minimizing delay. Our analyses show that our method significantly lowers delay, enhancing effectiveness over baseline methods. Yuzhu Liang, Jianxiong Guo, Qin Liu 0001, James Xi Zheng, Tian Wang 0001 |
IWQoS | 4 |
| 2024 | Edge-Intelligence-Based Computation Offloading Technology for Distributed Internet of Unmanned Aerial VehiclesabstractWith the development of networks and smart devices, artificial intelligence has drawn more and more attention, especially in the Unmanned Aerial Vehicles. Therefore, it is quite critical to train and run DNNs on resource-limited and hardware-constrained UAVs. The traditional methods fail to adjust offloading strategy due to the dynamic environment, while recently proposed intelligent computation offloading techniques rely on accessing IoT devices’ private data, which leads to privacy and security problem. To alleviate the above problems, we propose an novel edge-intelligent-based computation offloading technology via Federated Learning (FL). Specially, we utilize Multi-Layer Perceptron (MLP) to learn the computation tasks features and offload different tasks to different smart devices. Besides, to protect data privacy and improve the system’s security, a hierarchical FL framework is utilized to train the model of the computation tasks features extraction. Finally, performance analysis results obtained by experiments demonstrate the performance of our proposed approach. Wenhua Wang 0003, Qin Liu 0001, Tian Wang 0001, Weijia Jia 0001 |
IEEE Internet Things J. | 3 |
| 2024 | $\mathsf{MARS}$MARS: Enabling Verifiable Range-Aggregate Queries in Multi-Source EnvironmentsabstractThe huge values created by Big Data and the recent advances in cloud computing have been driving data from different sources into cloud repositories for comprehensive query services. However, cloud-based data fusion makes it challenging to verify if an untrusted server faithfully integrates data and executes queries or not. This is even harder for range-aggregate queries that apply aggregate operations on data within given ranges. In this paper, we propose a query authentication scheme, named${\sf MARS}$, enabling a user to efficiently authenticate range-aggregate queries on multi-source data. Specifically,${\sf MARS}$creates a VG-tree by subtly integrating Expressive Set Accumulator into a multi-dimensional G-tree while signing the root digest with a multi-source aggregate signature scheme. Compared with previous solutions,${\sf MARS}$has the following merits: (1)Practicality.Instead of treating range and aggregate queries separately, the user can directly verify the statistical result of selected data. (2)Scalability.Instead of authenticating the individual result from each source, the user can perform an aggregative validation on the integrated result from multiple sources. The experimental results demonstrate the effectiveness of MARS. For large-scale data fusion, the user-side verification time increases by only 103 ms as the amount of data sources increases by five times. Qin Liu 0001, Yu Peng 0003, Hongbo Jiang 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001, Shaobo Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | veffChain: Enabling Freshness Authentication of Rich Queries Over Blockchain DatabasesabstractWith the wide adoption of blockchains in data-intensive applications, enabling verifiable queries over a blockchain database is urgently required. Aiming at reducing costs, previous solutions embed a small-sized authenticated data structure (ADS) in each block header, so that a user can verify search results without maintaining a full copy of blockchain databases. However, existing studies focus on exact queries with difficulty to guarantee the freshness of search results. In this article, we propose two frameworks, called$\mathsf{veffChain}$and$\mathsf{veffChain++}$, to realize freshness authentication of rich queries over blockchain databases. Specifically,$\mathsf{veffChain}$concerns about verifiable latest-$K$exact queries and employs RSA accumulator to generate constant-size ADSs;$\mathsf{veffChain++}$integrates RSA accumulator into the Trie tree to further authenticate latest-$K$fuzzy queries. For improved scalability, an adaptive keyword splitting (AKS) solution is proposed to enable ADSs to be incrementally updated. Compared with the state-of-the-art work, our frameworks have the following merits: (1)Freshness Guarantee. The user can efficiently retrieve the freshest data from a blockchain database in a verifiable way. (2)Flexibility. The user can specify different query patterns on demand to retrieve data as accurately as possible. The detailed security analysis and extensive experiments validate the practicality of our frameworks. Qin Liu 0001, Yu Peng 0003, Hongbo Jiang 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001 |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2024 | MPV: Enabling Fine-Grained Query Authentication in Hybrid-Storage BlockchainabstractDue to the large-scale data streams produced by distributed terminals, hybrid-storage blockchain (HSB) that combines on-chain and off-chain storages has emerged as a promising solution for secure data storage in decentralized applications. Because all the raw data is outsourced to an untrusted service provider (SP), existing solutions suggest to utilize an on-chain authenticated data structure (ADS) to verify query results retrieved off-chain. However, existing solutions support onlycoarse-grained authenticationmaking a user abandon all the query results once the validation fails. In this paper, we focus on realizingfine-grained authenticationfor range queries, enabling a user to distinguish authentic data from falsified results. Considering the heavy gas consumption of on-chain storage, we propose two multi-dimensional parity-based verification (MPV) schemes with a trade-off between off-chain and on-chain efficiencies. Our main idea is to design an accumulator-based ADS to summarize well-designed verifiable hypercubes, so that fake results can be quickly located by combining multi-dimensional faces failed validation. Compared with previous solutions, our MPV schemes allow a user to make efficient use of query results by filtering out errors, and thus have higher data utility. The detailed security analysis and extensive experiments demonstrate the security and effectiveness of our MPV schemes, respectively. Qin Liu 0001, Yu Peng 0003, Mingzuo Xu, Hongbo Jiang 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001 |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2024 | Authorized Keyword Search on Mobile Devices in Secure Data OutsourcingabstractWith the increasing awareness of secure data outsourcing, dynamic searchable symmetric encryption (DSSE) that enables searches and updates over encrypted data has begun to receive growing attention. Despite promising, existing DSSE schemes with forward and backward privacy are still hard to achieve authorized keyword searches on mobile devices while supporting secure and flexible updates. In this article, we propose a DSSE scheme, named$\mathsf{FLY_{++}}$based on a flexible index structure$\mathsf{Hybrid}$that incorporates the merits of inverted indexes and forward indexes while compacting the index size. Specifically,$\mathsf{FLY_{++}}$encrypts the newly added data with a fresh key and disperses previous keys into$\mathsf{Hybrid}$for forward privacy, while applying symmetric puncturable encryption (SPE) and a dual-key mechanism to realize backward privacy further. Compared with the state-of-the-art work,$\mathsf{FLY_{++}}$has the following advantages: (1)Authorized search. It dispenses with caching or re-encrypting search results, enabling a mobile device to search only designated keywords over the data outsourced before authorization. (2)Flexibility.It not only allows for sublinear search time, but also simultaneously supports fine-grained and coarse-grained updates of outsourced data. The detailed security analysis and extensive experiments conducted on a real dataset demonstrate the security and practicality of$\mathsf{FLY_{++}}$, respectively. Qin Liu 0001, Yu Peng 0003, Hongbo Jiang 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | Protecting Inference Privacy With Accuracy Improvement in Mobile-Cloud Deep LearningabstractWith the wide spread of data-driven deep learning applications, a growing number of users outsource compute-intensive inference processes to the cloud. To protect inference privacy, Liu (INFOCOM 2022) proposed two steganography-based solutions, named GHOST and GHOST+, relying on the mobile-cloud collaborative framework, where the mobile device hides sensitive images into public cover images before feature extraction, while launching adversarial attacks on the cloud-side deep neural network (DNN) to obtain desired results. Although both solutions demonstrate significant advantages in private deep learning, they suffer from limited practicality; since the inference accuracy decreases sharply as the hiding ratio increases. To address this, we propose two improved solutions, IGHO and IGHO+, which ensure high inference accuracy even when abundant sensitive images need to be hidden. Specifically, IGHO as the improved version of GHOST proposes two feature fusion methods, feature synthesis and pixel synthesis, to preprocess cover images, making the poisoned DNN learn hidden sensitive features better, while IGHO+as the improved version of GHOST+designs a novel feature mining generative adversarial network (FMGAN) to craft adversarial perturbations highly robust against variable sensitive types. Experimental results show that the proposed solutions highly improve the practicality of GHOST and GHOST+. Shulan Wang, Qin Liu 0001, Yang Xu 0013, Hongbo Jiang 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2024 | Privacy-Enhanced Cooperative Storage Scheme for Contact-Free Sensory Data in AIoT with Efficient SynchronizationabstractThe growing popularity of contact-free smart sensing has contributed to the development of the Artificial Intelligence of Things (AIoT). The contact-free sensory data has great potential to mine and analyze the hidden information for AIoT-enabled applications. However, due to the limited storage resource of contact-free smart sensing devices, data is naturally stored in the cloud, which is at risk of privacy leakage. Cloud storage is generally considered insecure. On one hand, the openness of the cloud environment makes the data easy to be attacked, and the complex AIoT environment also makes the data transmission process vulnerable to the third party. On the other hand, the Cloud Service Provider (CSP) is untrusted. In this article, to ensure the security of data from contact-free smart sensing devices, a Cloud-Edge-End cooperative storage scheme is proposed, which takes full advantage of the differences in the cloud, edge, and end. Firstly, the processed sensory data is stored separately in the three layers by utilizing well-designed data partitioning strategy. This scheme can increase the difficulty of privacy leakage in the transmission process and avoid internal and external attacks. Besides, the contact-free sensory data is highly time-dependent. Therefore, combined with the Cloud-Edge-End cooperation model, this article proposes a delta-based data update method and extends it into a hybrid update mode to improve the synchronization efficiency. Theoretical analysis and experimental results show that the proposed cooperative storage method can resist various security threats in bad situations and outperform other update methods in synchronization efficiency, significantly reducing the synchronization overhead in AIoT. Yaxin Mei, Wenhua Wang 0003, Yuzhu Liang, Qin Liu 0001, Shuhong Chen, Tian Wang 0001 |
ACM Trans. Sens. Networks | 4 |
| 2023 | Collaborative Edge Service Placement for Maximizing QoS with Distributed Data CleaningabstractThe proliferation of dirty data on Internet of Things (IoT) devices can undermine the accuracy of data-driven decision-making by affecting the distribution of original data. The Quality of Service (QoS) of data cleaning on these devices is heavily impacted by processing delay and accuracy. In this paper, we find that edge service placement is a key step aligned with data cleaning and consider the collaborative edge service placement with distributed data cleaning (SPDC) problem. To address this issue, we propose a novel distributed collaborative edge-based architecture that effectively balances the demands of storage, communication, computation, and load constraints. Experimental results show that the proposed approach significantly improves the accuracy of data cleaning by 0.31%-86.07% and reduces delay by 2.73%-58.71% compared to state-of-the-art baselines. Yuzhu Liang, Wenhua Wang 0003, James Xi Zheng, Qin Liu 0001, Liang Wang 0017, Tian Wang 0001 |
IWQoS | 4 |
| 2023 | EKDF: An Ensemble Knowledge Distillation Framework for Robust Collaborative Inference on Heterogeneous Edge DevicesabstractThe integration of edge computing and deep neural networks (DNNs) holds great promise for enhancing application intelligence. Edge devices generate or collect vast amounts of data, which DNNs can leverage to make informed decisions. Nevertheless, the limited resources of edge devices pose a significant challenge for deploying DNNs. To accommodate some edge devices (e.g. smart watches), lightweight models are often required. However, the accuracy of these models may not meet user expectations. In this paper, we present EKDF, an ensemble knowledge distillation framework that crafts lightweight models for collaborative DNN inferences. More specifically, we utilize knowledge distillation to compress DNN models. On this basis, we introduce multi-teacher joint supervision and dropout in knowledge distillation to improve model performance and preserve the diversity between the generated DNN models. This process produces a range of compact models of varying computational complexity for different edge devices. The experimental results demonstrate that our proposed EKDF can greatly improve the overall predictive ability. Shangrui Wu, Yupeng Li 0001, Yang Xu 0013, Qin Liu 0001, Weijia Jia 0001, Tian Wang 0001 |
MSN | 4 |
| 2023 | ALPS: Achieving accuracy-aware location privacy service via assisted regions
Shaobo Zhang 0001, Qin Liu 0001, Kim-Kwang Raymond Choo, Guojun Wang 0001 |
Future Gener. Comput. Syst. | 3 |
| 2023 | A traceable and revocable decentralized multi-authority privacy protection scheme for social metaverse
Shaobo Zhang 0001, Yuechao Wang, Qin Liu 0001, Ke Gu 0002, Guojun Wang 0001 |
J. Syst. Archit. | 4 |
| 2023 | SlimBox: Lightweight Packet Inspection over Encrypted TrafficabstractDue to the explosive increase of enterprise network traffic, middleboxes that inspect packets through customized rules have been widely outsourced for cost-saving. Despite promising, redirecting enterprise traffic to remote middleboxes raises privacy concerns about the exposure of corporate secrets. To address this, existing solutions mainly apply searchable encryption (SE) to encrypt traffic and rules, enabling middlebox to perform pattern matching over ciphertexts without learning any sensitive information. However, SE is designed for searching pre-chosen keywords, and may cause extensive costs when applied directly to inspecting traffic in which the keywords cannot be determined in advance. The inefficiency of existing SE-based approaches motivates us to investigate a privacy-preserving and lightweight middlebox. To this end, this paper designs$\mathsf{SlimBox}$, which rapidly screens out potentially malicious packets in constant time while incurring only moderate communication overhead. Our main idea is to fragment a traffic/rule string into sub-patterns to achieve conjunctive sub-pattern matching over ciphertexts, while incorporating the position information into the secure matching process to avoid false positives. Experiment results on real datasets show that$\mathsf{SlimBox}$can achieve a good tradeoff between matching latency and communication cost compared to prior work. Qin Liu 0001, Yu Peng 0003, Hongbo Jiang 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | When Deep Learning Meets Steganography: Protecting Inference Privacy in the DarkabstractWhile cloud-based deep learning benefits for high-accuracy inference, it leads to potential privacy risks when exposing sensitive data to untrusted servers. In this paper, we work on exploring the feasibility of steganography in preserving inference privacy. Specifically, we devise GHOST and GHOST+, two private inference solutions employing steganography to make sensitive images invisible in the inference phase. Motivated by the fact that deep neural networks (DNNs) are inherently vulnerable to adversarial attacks, our main idea is turning this vulnerability into the weapon for data privacy, enabling the DNN to misclassify a stego image into the class of the sensitive image hidden in it. The main difference is that GHOST retrains the DNN into a poisoned network to learn the hidden features of sensitive images, but GHOST+ leverages a generative adversarial network (GAN) to produce adversarial perturbations without altering the DNN. For enhanced privacy and a better computation-communication trade-off, both solutions adopt the edge-cloud collaborative framework. Compared with the previous solutions, this is the first work that successfully integrates steganography and the nature of DNNs to achieve private inference while ensuring high accuracy. Extensive experiments validate that steganography has excellent ability in accuracy-aware privacy protection of deep learning. Qin Liu 0001, Jiamin Yang, Hongbo Jiang 0001, Jie Wu 0001, Tao Peng 0011, Tian Wang 0001, Guojun Wang 0001 |
INFOCOM | 1 |
| 2022 | A collaborative deep learning microservice for backdoor defenses in Industrial IoT networks
Qin Liu 0001, Liqiong Chen, Hongbo Jiang 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001 |
Ad Hoc Networks | 1 |
| 2022 | On authenticated skyline query processing over road networksabstractSummary In recent times, many location‐based service providers (LBSPs) choose to outsource data query services to third‐party cloud service providers (CSPs). This allows users to easily search for points of interests (POIs), such as restaurants and parking lots in their vicinity, using their mobile devices and in‐vehicle infotainment units. Skyline query is one potential technique to be deployed for road networks. However, the untrusted CSPs may forge or omit query results, intentionally or not. Therefore, in this article, we posit that by observing the unique properties of skyline query results in road networks, we can bind each POI with four nearby POIs with special properties using signature chain technology. Our proposed approach not only provides users with skyline query result authentication ability over the road network, but also have low communication overhead. Specifically, the overhead analysis and experimental results show that our proposed approach decreases the communication overhead. Jie Wu 0001, Wei Chang 0001, Md. Zakirul Alam Bhuiyan, Kim-Kwang Raymond Choo, Fang Qi, Qin Liu 0001, Guojun Wang 0001 |
Concurr. Comput. Pract. Exp. | 7 |
| 2022 | Preface of special issue on Artificial Intelligence: The security & privacy opportunities and challenges for emerging applications
Qin Liu 0001, Guojun Wang 0001, Jiankun Hu, Jie Wu 0001 |
Future Gener. Comput. Syst. | 1 |
| 2022 | Prime Inner Product Encoding for Effective Wildcard-Based Multi-Keyword Fuzzy SearchabstractWith the prevalence of cloud computing, a growing number of users are delegating clouds to host their sensitive data. To preserve user privacy, it is suggested that data is encrypted before outsourcing. However, data encryption makes keyword-based searches over ciphertexts extremely difficult. This is even challenging forfuzzy searchthat allows uncertainties or misspellings of keywords in a query. In this article, we propose a prime inner product encoding (PIPE) scheme, which makes use of theindecomposableproperty of prime numbers to provide efficient, highly accurate, and flexible multi-keyword fuzzy search. Our main idea is to encode either a query keyword or an index keyword into a vector filled with primes or reciprocals of primes, such that the result of vectors’ inner product is an integer only when two keywords are similar. Specifically, we first construct$\text{PIPE}_{0}$that is secure in the known ciphertext model. Unlike existing works that have difficulty supporting AND and OR semantics simultaneously,$\text{PIPE}_{0}$gives users the flexibility to specify different search semantics in their queries. Then, we construct$\text{PIPE}_{\text{S}}$that subtly adds random noises to a query vector to resist linear analyses. Both theoretical analyses and experiment results demonstrate the effectiveness of our scheme. Qin Liu 0001, Yu Peng 0003, Shuyu Pei, Jie Wu 0001, Tao Peng 0011, Guojun Wang 0001 |
IEEE Trans. Serv. Comput. | 1 |
| 2022 | Enabling Verifiable and Dynamic Ranked Search over Outsourced DataabstractCloud computing as a promising computing paradigm is increasingly utilized as potential hosts for users’ massive dataset. Since the cloud service provider (CSP) is outside the users’ trusted domain, existing research suggests encrypting sensitive data before outsourcing and adopting Searchable Symmetric Encryption (SSE) to facilitate keyword-based searches over the ciphertexts. However, it remains a challenging task to design an effective SSE scheme that simultaneously supportssublinear search time,efficient update and verification, andon-demand information retrieval. To address this, we propose a Verifiable Dynamic Encryption with Ranked Search (VDERS) scheme that allows a user to perform top-$K$Ksearches on adynamicdocument collection and verify the correctness of the search results in a secure and efficient way. Specifically, we first provide a basic construction,$\mathsf {VDERS}^0$VDERS0, where aranked inverted indexand averifiable matrixare constructed to enable verifiable document insertion in top-$K$Ksearches. Then, an advanced construction,$\mathsf {VDERS}^{\star }$VDERS★, is devised to further support document deletion with a reduced communication cost. Extensive experiments on real datasets demonstrate the efficiency and effectiveness of our VDERS scheme. Qin Liu 0001, Jie Wu 0001, Tao Peng 0011, Guojun Wang 0001 |
IEEE Trans. Serv. Comput. | 1 |
| 2021 | Dynamic Searchable Symmetric Encryption with Forward and Backward PrivacyabstractDynamic searchable symmetric encryption (DSSE) that enables a client to perform searches and updates on encrypted data has been intensively studied in cloud computing. Recently, forward privacy and backward privacy has engaged significant attention to protect DSSE from the leakage of updates. However, the research in this field almost focused on keyword-level updates. That is, the client needs to know the keywords of the documents in advance. In this paper, we proposed a document-level update scheme, DBP, which supports immediate deletion while guaranteeing forward privacy and backward privacy. Compared with existing forward and backward private DSSE schemes, our DBP scheme has the following merits: 1) Practicality. It achieves deletion based on document identifiers rather than document/keyword pairs; 2) Efficiency. It utilizes only lightweight primitives to realize backward privacy while supporting immediate deletion. Experimental evaluation on two real datasets demonstrates the practical efficiency of our scheme. Yu Peng 0003, Qin Liu 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001 |
TrustCom | 2 |
| 2021 | Efficient personalized search over encrypted data for mobile edge-assisted cloud storage
Qiang Zhang 0017, Guojun Wang 0001, Wenjuan Tang, Karim Alinani, Qin Liu 0001 |
Comput. Commun. | 5 |
| 2021 | SecVKQ: Secure and verifiable kNN queries in sensor-cloud systems
Qin Liu 0001, Zhengzheng Hao, Yu Peng 0003, Hongbo Jiang 0001, Jie Wu 0001, Tao Peng 0011, Guojun Wang 0001, Shaobo Zhang 0001 |
J. Syst. Archit. | 1 |
| 2021 | Secure Multi-keyword Fuzzy Searches With Enhanced Service Quality in Cloud ComputingabstractWith the ever-increasing amount of data resided in a cloud, how to provide users with secure and practical query services has become the key to improve the quality of cloud services. Fuzzy searchable encryption (FSE) is identified as one of the most promising approaches for enabling secure query services, since it allows searching encrypted data by using keywords with spelling errors. However, existing FSE schemes are far from the practical use for the following reasons: (1)Inflexibility.It is hard for them to simultaneously support AND and OR semantics in a multi-keyword query. (2)Inefficiency.They require sequentially scanning a whole dataset to find matched files, and thus are difficult to apply to a large-scale dataset. (3)Limited robustness.It is difficult for them to resist the linear analysis attack in the known-background model. To fix the above problems, this article proposes matrix-based multi-keyword fuzzy search (M2FS) schemes, which support approximate keyword matching by exploiting the indecomposable property of primes. Specifically, we first present a basic scheme, called M2FS-B, where multiple keywords in a query or a file are constructed as prime-related matrices such that the result of matrix multiplication can be employed to determine the level of matching for different query semantics. Then, we construct an advanced scheme, named M2FS-E, which builds a searchable index as a keyword balanced binary (KBB) tree for dynamic and parallel searches, while adding random noises into a query matrix for enhanced robustness. Extensive analyses and experiments demonstrate the validity of our M2FS schemes. Qin Liu 0001, Yu Peng 0003, Jie Wu 0001, Tian Wang 0001, Guojun Wang 0001 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2020 | Dynamic multi-client searchable symmetric encryption with support for boolean queries
Leilei Du 0001, Kenli Li 0001, Qin Liu 0001, Zhiqiang Wu 0001, Shaobo Zhang 0001 |
Inf. Sci. | 3 |
| 2020 | Preface: Security & privacy in social big data
Qin Liu 0001, Md. Zakirul Alam Bhuiyan, Jiankun Hu, Jie Wu 0001 |
J. Parallel Distributed Comput. | 1 |
| 2019 | Multidimensional privacy preservation in location-based services
Tao Peng 0011, Qin Liu 0001, Guojun Wang 0001, Yang Xiang 0001, Shuhong Chen |
Future Gener. Comput. Syst. | 2 |
| 2019 | Enabling Cooperative Privacy-preserving Personalized search in cloud environments
Qiang Zhang 0017, Guojun Wang 0001, Qin Liu 0001 |
Inf. Sci. | 3 |
| 2019 | Intelligent route planning on large road networks with efficiency and privacy
Qin Liu 0001, Panlin Hou, Guojun Wang 0001, Tao Peng 0011, Shaobo Zhang 0001 |
J. Parallel Distributed Comput. | 1 |
| 2019 | Topic-based rank search with verifiable social data outsourcing
Xin Yao 0002, Yizhu Zou, Zhigang Chen 0001, Ming Zhao 0007, Qin Liu 0001 |
J. Parallel Distributed Comput. | 5 |
| 2018 | Authentication of Multi-Dimensional Top-$K$ Query on Untrusted ServerabstractConsider a database where each record has multiple attributes. An untrusted server is in charge of processing queries over this database, and we want to provide a mechanism for users to verify the correctness of their query results. Here each query, referred to as a multi-dimensional top-k query, retrieves k records whose output with user-supplied ranking function is among top k. Multi-dimensional top-k query is widely used in real applications. However, as the traditional query authentication methods cannot be directly deployed on multi-dimensional top-k query, it is still a challenging problem to authenticate the multi-dimensional top-k query results. In this paper, we propose an authentication solution to support multi-dimensional top-k query based on signature chain. By using signature chain for each record and its successors on each dimension, our solution allows users to efficiently verify the soundness and completeness of multi-dimensional top-k query results. Through theoretical analysis and simulation, we demonstrate the effectiveness of our proposed solution. Jie Wu 0001, Wei Chang 0001, Guojun Wang 0001, Qin Liu 0001 |
IWQoS | 5 |
| 2018 | Enhancing privacy through uniform grid and caching in location-based services
Shaobo Zhang 0001, Kim-Kwang Raymond Choo, Qin Liu 0001, Guojun Wang 0001 |
Future Gener. Comput. Syst. | 3 |
| 2018 | A Dual Privacy Preserving Scheme in Continuous Location-Based ServicesabstractWith the development of wireless communication and positioning technology, location-based services (LBSs) have been gaining tremendous popularity, due to its ability to greatly facilitate the people's daily lives. Meanwhile, it also entails the risk of location privacy disclosure. To address this issue, general solutions introduce a single trusted anonymizer between the users and the location service provider (LSP). However, a single anonymizer offers limited privacy guarantees and incurs high communication overhead in continuous LBSs. Once the anonymizer is compromised, it may put the user information in jeopardy. In this paper, we propose a dual privacy preserving (DPP) scheme in continuous LBSs to protect the users' trajectory and query privacy. Our scheme introduces multiple anonymizers between the users and LSP, and combines with Shamir threshold mechanism, dynamic pseudonym mechanism, and K-anonymity technology to improve the users' trajectory and content privacy in continuous LBSs. An anonymizer alone cannot get the users' trajectory and query contents, and it thus can be semi-trusted. Our scheme can enhance the users' privacy and effectively solve the single point of failure in single anonymizer structure. At the same time, the query authentication can guarantee the correctness of the query results. The analysis and simulation results demonstrate that the proposed scheme has the ability to protect users' trajectory and content privacy effectively, and to reduce the computation and communication overhead of the single anonymizer. Shaobo Zhang 0001, Guojun Wang 0001, Md. Zakirul Alam Bhuiyan, Qin Liu 0001 |
IEEE Internet Things J. | 4 |
| 2018 | A trajectory privacy-preserving scheme based on query exchange in mobile social networks
Shaobo Zhang 0001, Guojun Wang 0001, Qin Liu 0001, Jemal H. Abawajy |
Soft Comput. | 3 |
| 2017 | DABKS: Dynamic attribute-based keyword search in cloud computingabstractDue to its fast deployment and scalability, cloud computing has become a significant technology trend. Organizations with limited budgets can achieve great flexibility at a low price by outsourcing their data and query services to the cloud. Since the cloud is outside the organization's trusted domain, existing research suggests encrypting data before outsourcing to preserve user privacy. Two main problems that the cloud user faces while searching over encrypted data are how to achieve a fine-grained search authorization and how to efficiently update the search permission. The existing attribute-based keyword search (ABKS) scheme addresses the first problem, which allows a data owner to control the search of the outsourced encrypted data according to an access policy. This paper proposes a dynamic attribute-based keyword search (DABKS) scheme that incorporates proxy re-encryption (PRE) and a secret sharing scheme (SSS) into ABKS. The DABKS scheme, which allows the data owner to delegate policy updating operations to the cloud, takes full advantage of cloud resources. We conduct experiments on real data sets to validate the effectiveness and efficiency of our proposed scheme. Baishuang Hu, Qin Liu 0001, Xuhui Liu, Tao Peng 0011, Guojun Wang 0001, Jie Wu 0001 |
ICC | 2 |
| 2017 | Verifiable Ranked Search over dynamic encrypted data in cloud computingabstractBig data has become a hot topic in many areas where the volume and growth rate of data require cloud-based platforms for processing and analysis. Due to open cloud environments with very limited user-side control, existing research suggests encrypting data before outsourcing and adopting Searchable Symmetric Encryption (SSE) to facilitate keyword-based searches on the ciphertexts. However, no prior SSE constructions can simultaneously achieve sublinear search time, efficient update and verification, and on-demand file retrieval, which are all essential to the development of big data. To address this, we propose a Verifiable Ranked Searchable Symmetric Encryption (VRSSE) scheme that allows a user to perform top-K searches on a dynamic file collection while efficiently verifying the correctness of the search results. VRSSE is constructed based on the ranked inverted index, which contains multiple inverted lists that link sets of file nodes relating a specific keyword. For verifiable ranked searches, file nodes are ordered according to their ranks for such a keyword, and information about a node's prior/following neighbor will be encoded with the RSA accumulator. Extensive experiments on real data sets demonstrate the efficiency and effectiveness of our proposed scheme. Qin Liu 0001, Xiaohong Nie, Xuhui Liu, Tao Peng 0011, Jie Wu 0001 |
IWQoS | 1 |
| 2017 | Secure hitch in location based social networks
Shiwen Zhang 0004, Yaping Lin, Qin Liu 0001, Junqiang Jiang, Bo Yin 0004, Kim-Kwang Raymond Choo |
Comput. Commun. | 3 |
| 2017 | Preface: Security and privacy in big data clouds
Qin Liu 0001, Avinash Srinivasan, Jiankun Hu, Guojun Wang 0001 |
Future Gener. Comput. Syst. | 1 |
| 2017 | Privacy-preserving multi-hop profile-matching protocol for proximity mobile social networks
Qin Liu 0001, Jemal H. Abawajy, Guojun Wang 0001 |
Future Gener. Comput. Syst. | 2 |
| 2017 | Anonymizing popularity in online social networks with full utility
Shiwen Zhang 0004, Qin Liu 0001, Yaping Lin |
Future Gener. Comput. Syst. | 2 |
| 2017 | Dynamic access policy in cloud-based personal health record (PHR) systems
Xuhui Liu, Qin Liu 0001, Tao Peng 0011, Jie Wu 0001 |
Inf. Sci. | 2 |
| 2017 | Collaborative trajectory privacy preserving scheme in location-based services
Tao Peng 0011, Qin Liu 0001, Dacheng Meng, Guojun Wang 0001 |
Inf. Sci. | 2 |
| 2017 | Effective Query Grouping Strategy in Clouds
Qin Liu 0001, Yuhong Guo, Jie Wu 0001, Guojun Wang 0001 |
J. Comput. Sci. Technol. | 1 |
| 2017 | Preserving Privacy with Probabilistic Indistinguishability in Weighted Social NetworksabstractThe increasing popularity of social networks has inspired recent research to explore social graphs for marketing and data mining. As social networks often contain sensitive information about individuals, preserving privacy when publishing social graphs becomes an important issue. In this paper, we consider the identity disclosure problem in releasingweightedsocial graphs. We identifyweighted 1*-neighborhood attacks, which assume that an attacker has knowledge about not only a target's one-hop neighbors and connections between them (1-neighborhood graph), but also related node degrees and edge weights. With this information, an attacker may re-identify a target with high confidence, even if any node's 1-neighborhood graph is isomorphic with$k-1$other nodes’ graphs. To counter this attack while preserving high utility of the published graph, we define a key privacy property,probabilistic indistinguishability, and propose a heuristic indistinguishable group anonymization (HIGA) scheme to anonymize a weighted social graph with such a property. Extensive experiments on both real and synthetic data sets illustrate the effectiveness and efficiency of the proposed scheme. Qin Liu 0001, Guojun Wang 0001, Feng Li 0001, Jie Wu 0001 |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2016 | Dynamic Verifiable Search Over Encrypted Data in Untrusted Clouds
Xiaohong Nie, Qin Liu 0001, Xuhui Liu, Tao Peng 0011, Yapin Lin |
ICA3PP | 2 |
| 2016 | A secure hierarchical deduplication system in cloud storageabstractData deduplication is commonly adopted in cloud storage services to improve storage utilization and reduce transmission bandwidth. It, however, conflicts with the requirement for data confidentiality offered by data encryption. Hierarchical authorized deduplication alleviates the tension between data deduplication and confidentiality and allows a cloud user to perform privilege-based duplicate checks before uploading the data. Existing hierarchical authorized deduplication systems permit the cloud server to profile cloud users according to their privileges. In this paper, we propose a secure hierarchical deduplication system to support privilege-based duplicate checks and also prevent privilege-based user profiling by the cloud server. Our system also supports dynamic privilege changes. Detailed theoretical analysis and experimental studies confirm the security and high efficiency of our system. Xin Yao 0002, Yaping Lin, Qin Liu 0001 |
IWQoS | 3 |
| 2015 | HCBE: Achieving Fine-Grained Access Control in Cloud-Based PHR Systems
Xuhui Liu, Qin Liu 0001, Tao Peng 0011, Jie Wu 0001 |
ICA3PP (3) | 2 |
| 2015 | NMHP: A Privacy Preserving Profile Matching Protocol in Multi-hop Proximity Mobile Social Networks
Qin Liu 0001, Guojun Wang 0001 |
ICA3PP (3) | 2 |
| 2015 | Deviation-Based Location Switching Protocol for Trajectory Privacy Protection
Shaobo Zhang 0001, Qin Liu 0001, Guojun Wang 0001 |
ICA3PP (3) | 2 |
| 2015 | Verifiable Dynamic Fuzzy Search Over Encrypted Data in Cloud Computing
Qin Liu 0001, Guojun Wang 0001 |
ICA3PP (3) | 2 |
| 2015 | Efficient and privacy-preserving search in multi-source personal health record cloudsabstractPersonal Health Record (PHR) systems have been widely used to manage individuals' medical history. Meanwhile, with a rapid growth of the volume of PHRs, individuals outsource PHR systems to the cloud to facilitate management. In this paper, we consider a multi-source cloud-based PHR environment, where hospitals as the data providers are authorized to upload an individual's medical data to the cloud. In this environment, a data provider builds an index as an Multi-Dimensional B-tree from an individual's medical data for fast lookup, and encrypts both the index and data before uploading, to preserve data privacy. To achieve efficient and privacy-preserving query on the encrypted medical data in cloud computing, we propose a Multi-source Encrypted Indexes Merging (MEIM) mechanism, where the indexes encrypted with a novel Multi-source Order-Preserving Symmetric Encryption (MOPSE) solution can be effectively merged by the cloud. The main merit of MEIM is that an individual only needs to issue one encrypted query to efficiently retrieve the PHRs of her interests, even if the indexes are encrypted under different symmetric keys. We prove that the query processing with MEIM for data user is n times faster than the tradition OPSE, where n denotes the number of data providers. Xin Yao 0002, Yaping Lin, Qin Liu 0001, Shuai Long |
ISCC | 3 |
| 2014 | Secure distributed keyword search in multiple cloudsabstractCloud computing provides abundant benefits including easy access, decreased costs and flexible resource management. For privacy concerns, sensitive data have to be encrypted before outsourcing, which obsoletes traditional data utilization based on plaintext keyword search. Therefore, developing a secure search service over encrypted cloud data is of paramount importance. There are several researches concerned about this problem. However, all these schemes are based on a single cloud model which has the threat of single point of failure, loss and corruption of data, loss of availability and loss of privacy. In this paper, we explore the problem of secure distributed keyword search in a multi-cloud paradigm. We first define a distributed search model. Based on this model, we propose two schemes. In scheme_I, we propose to cross-store all encrypted file slices, keywords and keys. In scheme_II, we systematically construct a keyword distributing strategy and a file distributing strategy. Further, we extend both schemes with Shamir's secret schemes to achieve better availability and robustness. Extensive experiments on real-world datasets confirm the efficacy and efficiency of our schemes. Wei Zhang 0074, Yaping Lin, Sheng Xiao, Qin Liu 0001 |
IWQoS | 4 |
| 2014 | Secure and Efficient Video Surveillance in Cloud ComputingabstractVideo Surveillance has been widely used in business establishments. Since digital cameras everlastingly collect the video data, the volume of sampled data is extensively large, which is hard to be stored and managed locally. Outsourcing surveillance video data to the cloud can achieve cost saving and flexibility, but also will incur potential privacy leakage. In this paper, we utilize the Compressed Sensing (CS) technique for sampling and compressing, to achieve secure and efficient video surveillance in cloud computing. Firstly, we identify the known-plaintext attack in such environment. That is, given sufficient information about the original signal and corresponding CS measurements, the attacker is likely to calculate the measurement matrix. Then, we propose a Dynamic Compressive Sensing(DCS) scheme to resist such an attack. Specifically, we use a dynamic measurement matrix that is changeable over time to prevent the attackers from gaining sufficient information to calculate the measurement matrix. Furthermore, we allow the cloud to help users decode the non-reference frames without leaking any information, to take full advantage of the powerful computing. Experimental results show that the proposed scheme effectively protects the security of the surveillance video, and provides a good recovery quality for users to conduct further analysis. Shiwen Zhang 0004, Yaping Lin, Qin Liu 0001 |
MASS | 3 |
| 2014 | Time-based proxy re-encryption scheme for secure data sharing in a cloud environment
Qin Liu 0001, Guojun Wang 0001, Jie Wu 0001 |
Inf. Sci. | 1 |
| 2014 | Consistency as a Service: Auditing Cloud ConsistencyabstractCloud storage services have become commercially popular due to their overwhelming advantages. To provide ubiquitous always-on access, a cloud service provider (CSP) maintains multiple replicas for each piece of data on geographically distributed servers. A key problem of using the replication technique in clouds is that it is very expensive to achieve strong consistency on a worldwide scale. In this paper, we first present a novel consistency as a service (CaaS) model, which consists of a large data cloud and multiple small audit clouds. In the CaaS model, a data cloud is maintained by a CSP, and a group of users that constitute an audit cloud can verify whether the data cloud provides the promised level of consistency or not. We propose a two-level auditing architecture, which only requires a loosely synchronized clock in the audit cloud. Then, we design algorithms to quantify the severity of violations with two metrics: the commonality of violations, and the staleness of the value of a read. Finally, we devise a heuristic auditing strategy (HAS) to reveal as many violations as possible. Extensive experiments were performed using a combination of simulations and real cloud deployments to validate HAS. Qin Liu 0001, Guojun Wang 0001, Jie Wu 0001 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2014 | Towards Differential Query Services in Cost-Efficient CloudsabstractCloud computing as an emerging technology trend is expected to reshape the advances in information technology. In a cost-efficient cloud environment, a user can tolerate a certain degree of delay while retrieving information from the cloud to reduce costs. In this paper, we address two fundamental issues in such an environment: privacy and efficiency. We first review a private keyword-based file retrieval scheme that was originally proposed by Ostrovsky. Their scheme allows a user to retrieve files of interest from an untrusted server without leaking any information. The main drawback is that it will cause a heavy querying overhead incurred on the cloud and thus goes against the original intention of cost efficiency. In this paper, we present three efficient information retrieval for ranked query (EIRQ) schemes to reduce querying overhead incurred on the cloud. In EIRQ, queries are classified into multiple ranks, where a higher ranked query can retrieve a higher percentage of matched files. A user can retrieve files on demand by choosing queries of different ranks. This feature is useful when there are a large number of matched files, but the user only needs a small subset of them. Under different parameter settings, extensive evaluations have been conducted on both analytical models and on a real cloud environment, in order to examine the effectiveness of our schemes. Qin Liu 0001, Chiu C. Tan 0001, Jie Wu 0001, Guojun Wang 0001 |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2013 | Outsourcing privacy-preserving social networks to a cloudabstractIn the real world, companies would publish social networks to a third party, e.g., a cloud service provider, for marketing reasons. Preserving privacy when publishing social network data becomes an important issue. In this paper, we identify a novel type of privacy attack, termed 1∗-neighborhood attack. We assume that an attacker has knowledge about the degrees of a target's one-hop neighbors, in addition to the target's 1-neighborhood graph, which consists of the one-hop neighbors of the target and the relationships among these neighbors. With this information, an attacker may re-identify the target from a k-anonymity social network with a probability higher than 1/k, where any node's 1-neighborhood graph is isomorphic with k-1 other nodes' graphs. To resist the 1∗-neighborhood attack, we define a key privacy property, probability indistinguishability, for an outsourced social network, and propose a heuristic indistinguishable group anonymization (HIGA) scheme to generate an anonymized social network with this privacy property. The empirical study indicates that the anonymized social networks can still be used to answer aggregate queries with high accuracy. Guojun Wang 0001, Qin Liu 0001, Feng Li 0001, Jie Wu 0001 |
INFOCOM | 2 |
| 2013 | A secure self-destructing scheme for electronic data
Guojun Wang 0001, Fengshun Yue, Qin Liu 0001 |
J. Comput. Syst. Sci. | 3 |
| 2013 | A scalable encryption scheme for multi-privileged group communications
Guojun Wang 0001, Qiushuang Du, Qin Liu 0001 |
J. Supercomput. | 4 |
| 2012 | Efficient information retrieval for ranked queries in cost-effective cloud environmentsabstractCloud computing as an emerging technology trend is expected to reshape the advances in information technology. In this paper, we address two fundamental issues in a cloud environment: privacy and efficiency. We first review a private keyword-based file retrieval scheme proposed by Ostrovsky et. al. Then, based on an aggregation and distribution layer (ADL), we present a scheme, termed efficient information retrieval for ranked query (EIRQ), to further reduce querying costs incurred in the cloud. Queries are classified into multiple ranks, where a higher ranked query can retrieve a higher percentage of matched files. Extensive evaluations have been conducted on an analytical model to examine the effectiveness of our scheme. Qin Liu 0001, Chiu C. Tan 0001, Jie Wu 0001, Guojun Wang 0001 |
INFOCOM | 1 |
| 2012 | Secure and privacy preserving keyword searching for cloud storage services
Qin Liu 0001, Guojun Wang 0001, Jie Wu 0001 |
J. Netw. Comput. Appl. | 1 |
| 2012 | Cooperative private searching in clouds
Qin Liu 0001, Chiu C. Tan 0001, Jie Wu 0001, Guojun Wang 0001 |
J. Parallel Distributed Comput. | 1 |
| 2011 | Secure Locking for Untrusted CloudsabstractMigrating applications with strong consistency requirements to public cloud platforms remains risky since the data owner cannot verify the correctness of the public cloud's locking algorithm. In this paper, we identify new attacks that an untrusted cloud provider can launch via control of the locking mechanism, and propose an extension to existing locking scheme to address such attacks. Our solution modifies the locks to include a short history to allow data users to determine correctness, and can also prevent the cloud from re-ordering operations for financial gain. Chiu C. Tan 0001, Qin Liu 0001, Jie Wu 0001 |
IEEE CLOUD | 2 |
| 2011 | Reliable Re-Encryption in Unreliable CloudsabstractA key approach to secure cloud computing is for the data owner to store encrypted data in the cloud, and issue decryption keys to authorized users. Then, when a user is revoked, the data owner will issue re-encryption commands to the cloud to re-encrypt the data, to prevent the revoked user from decrypting the data, and to generate new decryption keys to valid users, so that they can continue to access the data. However, since a cloud computing environment is comprised of many cloud servers, such commands may not be received and executed by all of the cloud servers due to unreliable network communications. In this paper, we solve this problem by proposing a time-based re-encryption scheme, which enables the cloud servers to automatically re-encrypt data based on their internal clocks. Our solution is built on top of a new encryption scheme, attribute-based encryption, to allow fine-grain access control, and does not require perfect clock synchronization for correctness. Qin Liu 0001, Chiu C. Tan 0001, Jie Wu 0001, Guojun Wang 0001 |
GLOBECOM | 1 |
| 2011 | Hierarchical attribute-based encryption and scalable user revocation for sharing data in cloud servers
Guojun Wang 0001, Qin Liu 0001, Jie Wu 0001, Minyi Guo |
Comput. Secur. | 2 |
| 2011 | Achieving fine-grained access control for secure data sharing on cloud serversabstractAbstract With more and more enterprises sharing their sensitive data on cloud servers, building a secure cloud environment for data sharing has attracted a lot of attention in both the industry and academic communities. In this paper, we propose a conjunctive precise and fuzzy identity‐based encryption (PFIBE) scheme for secure data sharing on cloud servers, which allows the encryption of data by specifying a recipient identity (ID) set or a disjunctive normal form (DNF) access control policy over attributes, so that only the user whose ID belongs to the ID set or attributes satisfy the DNF access control policy can decrypt the corresponding data. Our design goal is to propose a novel encryption scheme, which simultaneously achieves a fine‐grained access control, flexibility, high performance, and full key delegation, so as to help enterprise users to enjoy more secure, comprehensive, and flexible services. We achieve this goal by first combining the hierarchical identity‐based encryption (HIBE) system and the ciphertext‐policy attribute‐based encryption (CP‐ABE) system, and then marking each user with both an ID and a set of descriptive attributes, finally separating the access control policy into two parts: a recipient ID set and a DNF attribute‐based access control policy. Copyright © 2011 John Wiley & Sons, Ltd. Guojun Wang 0001, Qin Liu 0001, Jie Wu 0001 |
Concurr. Comput. Pract. Exp. | 2 |
| 2010 | Hierarchical attribute-based encryption for fine-grained access control in cloud storage servicesabstractCloud computing, as an emerging computing paradigm, enables users to remotely store their data into a cloud so as to enjoy scalable services on-demand. Especially for small and medium-sized enterprises with limited budgets, they can achieve cost savings and productivity enhancements by using cloud-based services to manage projects, to make collaborations, and the like. However, allowing cloud service providers (CSPs), which are not in the same trusted domains as enterprise users, to take care of confidential data, may raise potential security and privacy issues. To keep the sensitive user data confidential against untrusted CSPs, a natural way is to apply cryptographic approaches, by disclosing decryption keys only to authorized users. However, when enterprise users outsource confidential data for sharing on cloud servers, the adopted encryption system should not only support fine-grained access control, but also provide high performance, full delegation, and scalability, so as to best serve the needs of accessing data anytime and anywhere, delegating within enterprises, and achieving a dynamic set of users. In this paper, we propose a scheme to help enterprises to efficiently share confidential data on cloud servers. We achieve this goal by first combining the hierarchical identity-based encryption (HIBE) system and the ciphertext-policy attribute-based encryption (CP-ABE) system, and then making a performance-expressivity tradeoff, finally applying proxy re-encryption and lazy re-encryption to our scheme. Guojun Wang 0001, Qin Liu 0001, Jie Wu 0001 |
CCS | 2 |
| 2010 | A Scalable Encryption Scheme for Multi-Privileged Group CommunicationsabstractSecurity issues in multi-privileged group communications containing multiple data streams are rather difficult to solve, as there are multiple access privileges among users. Traditional key management schemes use a key graph to manage all the keys in a group, which makes one key being shared by many users resulting in the "one-affect-many" problem. In a key-policy attribute-based encryption (KP-ABE) system, a ciphertext is labeled with a set of attributes and users' keys are associated with access policies, so that a ciphertext can be decrypted by multiple users when the attributes associated with the ciphertext satisfy an access policy in the users' keys. However, KP-ABE can not achieve a scalable revocation mechanism when applied to multi-privileged group communications. In this paper, we propose a scalable encryption scheme for multi-privileged group communications (EMGC), which uniquely combines a collusion resistant broadcast encryption system and a KP-ABE system with a non-monotone access control. Using our scheme, a user can not only join/leave a group at will, but also change his access privilege on demand, while requiring a small number of re-keying operations. Therefore, our scheme, which can accommodate a dynamic group of users, is more applicable to multi-privileged group communications. Qiushuang Du, Guojun Wang 0001, Qin Liu 0001 |
EUC | 3 |
| 2010 | A Secure Self-Destructing Scheme for Electronic DataabstractAs more and more services and applications are emerging in the Internet, exposing user sensitive data in the Internet becomes more easily. The simplest way to protect the security of sensitive user data is to encrypt the data in advance, and then disclose the data decryption key only to those authorized users. However, the sensitive user data will be leaked while the decryption key is exposed to unauthorized users. In this paper, we propose a secure self-destructing scheme for electronic data (SSDD for short). We achieve this goal by first encrypting the data, and then distributing both the decryption key and a part of the cipher text into the distributed hash table (DHT) network. By security analysis, we show that our SSDD scheme can resist against not only the traditional cryptanalysis and the brute-force attacks, but also the attacks in the DHT network, such as the store sniffing attack, the lookup sniffing attack, and the standard DHT attacks. Fengshun Yue, Guojun Wang 0001, Qin Liu 0001 |
EUC | 3 |