EDBT 2026 Demo / reviewers in the wild / expert
Shujun Li 0001
dblp:09/6954-1
· DBLP profile ↗
75ranked-venue papers
14as first author
28since 2021 · last 2026
0000-0001-5628-7328ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 25 · 4 first-author · 9 since 2021Graphics, computer vision, multimedia, augmented reality and games · 19 · 7 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 14 · 10 since 2021Artificial intelligence and machine learning · 8 · 5 since 2021Databases, data management, data science and information retrieval · 6 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 3 since 2021Software engineering, systems software and programming languages · 5 · 2 first-authorComputer networks · 2 · 1 first-authorTheory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | When the World Opens Up: Journeys of People with Intellectual Disabilities in Social Virtual RealityabstractAdults with intellectual disabilities (ID) face systemic social exclusion that narrows autonomy and life opportunities. While social virtual reality (VR) offers a powerful medium for identity expression and community belonging, research often adopts a remedial paradigm, focusing on training functional skills in scripted environments. This paper challenges this deficit-based model by treating social VR as an open world for participation. Following 11 adults with ID across multi-session engagements with VRChat, we employed an adaptive, relational method to scaffold participant leadership. Findings reveal that participants used the platform for interest-driven discovery, sustained through interdependent care webs. Crucially, the study demonstrates how social VR supports transferable confidence and emerging digital citizenship, enabling some users to transition from novices to community leaders. We contribute six Disability Justice-aligned design principles articulating a world-making paradigm that reorients Human-Computer Interaction toward supporting personhood and self-determination in mainstream digital publics. Alexandra Covaci, Winnie Tsang, Sophia Ppali, Paraskevi Triantafyllopoulou, Monica Perusquía-Hernández, Oscar Zhou, Fotis Liarokapis, Marios Constantinides, Mohamed Khamis, Shujun Li 0001 |
CHI | 10 |
| 2026 | Characterizing Scam-Driven Human Trafficking Across Chinese Borders and Online Community Responses on RedNoteabstractA new form of human trafficking has emerged across Chinese borders, where individuals are lured to Southeast Asia with fraudulent job offers and then coerced into operating online scams. Despite its massive economic and human toll, this scam-driven trafficking remains underexplored in academic research. Through qualitative analysis of 158 RedNote posts, we examined how Chinese online communities respond to this threat. Our findings reveal that perpetrators exploit cultural ties to recruit victims for cybercriminal roles within self-sustaining compounds, using sophisticated manipulation tactics. Survivors face serious reintegration barriers, including family rejection, as the cultural values that enable trafficking also hinder their recovery. While communities present protective strategies, efforts are complicated by doubts about the reliability of support and cross-border coordination. We discuss key implications for prevention, platform governance, and international cooperation against scam-driven trafficking. Warning: This paper contains descriptions of physical, psychological, and sexual abuse. Yue Deng 0003, Jessica Chen, Shujun Li 0001, Yixin Zou |
CHI | 4 |
| 2026 | A Comprehensive Study on GDPR-Oriented Analysis of Privacy Policies: Taxonomy, Corpus and GDPR Concept ClassifiersabstractMachine learning (ML) based classifiers that take a privacy policy as the input and predict relevant concepts are useful in different applications such as (semi-)automated compliance analysis against requirements of a specific data protection law such as the EU GDPR. Although many researchers have studied ML-based privacy policy concept classifiers, we observed multiple research gaps, e.g., the lack of a more complete GDPR taxonomy and the less consideration of hierarchical information in privacy policies. To fill such research gaps, we produced a more complete GDPR-oriented privacy policy concept taxonomy, constructed the first privacy policy corpus with explicitly hierarchical information at three levels, and conducted the most comprehensive performance evaluation study of GDPR concept classifiers for privacy policies, cover many aspects that have not been studied systematically. Our work led to multiple findings and insights, including the usefulness of considering hierarchical contextual features and different hierarchical structures, the observation that a “one size fits all” approach may not work, the reduced performance of such classifiers on our newly constructed corpus especially after the first level, and the necessity to split the training and testing sets by documents. Peng Tang 0002, Weidong Qiu, Haochen Mei, Allison Holmes, Fenghua Li 0001, Shujun Li 0001 |
IEEE Trans. Dependable Secur. Comput. | 8 |
| 2025 | FACTors: A New Dataset for Studying the Fact-checking EcosystemabstractOur fight against false information is spearheaded by fact-checkers. They investigate the veracity of claims and document their findings as fact-checking reports. With the rapid increase in the amount of false information circulating online, the use of automation in fact-checking processes aims to strengthen this ecosystem by enhancing scalability. Datasets containing fact-checked claims play a key role in developing such automated solutions. However, to the best of our knowledge, there is no fact-checking dataset at the ecosystem level, covering claims from a sufficiently long period of time and sourced from a wide range of actors reflecting the entire ecosystem that admittedly follows widely-accepted codes and principles of fact-checking. Enes Altuncu, Can Baskent, Sanjay Bhattacherjee, Shujun Li 0001, Dwaipayan Roy 0001 |
SIGIR | 4 |
| 2025 | Everyone's Privacy Matters! An Analysis of Privacy Leakage from Real-World Facial Images on Twitter and Associated User BehaviorsabstractOnline users often post facial images of themselves and other people on online social networks (OSNs) and other Web 2.0 platforms, which can lead to potential privacy leakage of people whose faces are included in such images. There is limited research on understanding face privacy in social media while considering user behavior. It is crucial to consider privacy of subjects and bystanders separately. This calls for the development of privacy-aware face detection classifiers that can distinguish between subjects and bystanders automatically. This paper introduces such a classifier trained on face-based features, which outperforms the two state-of-the-art methods with a significant margin (by 13.1% and 3.1% for OSN images, and by 17.9% and 5.9% for non-OSN images). We developed a semi-automated framework for conducting a large-scale analysis of the face privacy problem by using our novel bystander-subject classifier. We collected 27,800 images, each including at least one face, shared by 6,423 Twitter users. We then applied our framework to analyze this dataset thoroughly. Our analysis reveals eight key findings of different aspects of Twitter users' real-world behaviors on face privacy, and we provide quantitative and qualitative results to better explain these findings. We share the practical implications of our study to empower online platforms and users in addressing the face privacy problem efficiently. Yuqi Niu, Weidong Qiu, Peng Tang 0002, Lifan Wang, Shujun Li 0001, Nadin Kökciyan, Ben Niu 0001 |
Proc. ACM Hum. Comput. Interact. | 6 |
| 2025 | Adaptive Backdoor Attacks With Reasonable Constraints on Graph Neural NetworksabstractRecent studies show that graph neural networks (GNNs) are vulnerable to backdoor attacks. Existing backdoor attacks against GNNs use fixed-pattern triggers and lack reasonable trigger constraints, overlooking individual graph characteristics and rendering insufficient evasiveness. To tackle the above issues, we propose ABARC, the firstAdaptiveBackdoorAttack withReasonableConstraints, applying to both graph-level and node-level tasks in GNNs. For graph-level tasks, we propose a subgraph backdoor attack independent of the graph's topology. It dynamically selects trigger nodes for each target graph and modifies node features with constraints based on graph similarity, feature range, and feature type. For node-level tasks, our attack begins with an analysis of node features, followed by selecting and modifying trigger features, which are then constrained by node similarity, feature range, and feature type. Furthermore, an adaptive edge-pruning mechanism is designed to reduce the impact of neighbors on target nodes, ensuring a high attack success rate (ASR). Experimental results show that even with reasonable constraints for attack evasiveness, our attack achieves a high ASR while incurring a marginal clean accuracy drop (CAD). When combined with the state-of-the-art defense randomized smoothing (RS) method, our attack maintains an ASR over 94%, surpassing existing attacks by more than 7%. Xuewen Dong, Shujun Li 0001, Zhichao You, Qiang Qu 0001, Yaroslav Kholodov, Yulong Shen 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | FLAD: Byzantine-Robust Federated Learning Based on Gradient Feature Anomaly DetectionabstractFederated Learning (FL) has gained significant attention due to its ability to jointly train global models by exchanging local gradients instead of raw local datasets. However, poisoning attacks have emerged as a severe threat to FL security, where malicious clients submit crafted gradients to compromise the integrity and availability of the model. Although researchers have worked on countering these attacks to achieve Byzantine-robust FL, it remains challenging to balance high accuracy, robustness, and efficiency simultaneously. We propose FLAD, a novel Byzantine-robust FL approach based on gradient feature anomaly detection, which is the first approach that uses neural networks to adaptively learn gradient features and measure feature similarity to counteract various types of poisoning attacks. Specifically, FLAD employs a small clean dataset to bootstrap trust and trains Feature Extraction Models (FEM). With FEM and DBSCAN clustering, abnormal gradients from malicious clients are detected and eliminated. Extensive experiments on both Non-IID and IID datasets demonstrate that FLAD achieves superior accuracy, robustness, efficiency, and generalizability compared to state-of-the-art approaches. Additionally, we implement privacy-preserving FLAD (PFLAD) using CKKS and Random Permutation techniques to ensure transmitted gradient privacy. Peng Tang 0002, Weidong Qiu, Zhenyu Mu, Shujun Li 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | SE#PCFG: Semantically Enhanced PCFG for Password Analysis and CrackingabstractMuch research has been done on user-generated textual passwords. Surprisingly, semantic information in such passwords remain under-investigated, with passwords created by English- and/or Chinese-speaking users being more studied with limited semantics. This article fills this gap by proposing ageneral frameworkbased onsemantically enhancedPCFG (probabilistic context-free grammars) named SE#PCFG. It allowed us to consider 43 types of semantic information, the richest set considered so far, for password analysis. Applying SE#PCFG to 17 large leaked password databases of user speaking four languages (English, Chinese, German and French), we demonstrate its usefulness and report a wide range of new insights about password semantics at different levels such as cross-website password correlations. Furthermore, based on SE#PCFG and a new systematic smoothing method, we proposed the Semantically Enhanced Password Cracking Architecture (SEPCA), and compared its performance against three SOTA (state-of-the-art) benchmarks in terms of the password coverage rate: two other PCFG variants and neural network. Our experimental results showed that SEPCA outperformed all the three benchmarks consistently and significantly across 52 test cases, by up to 21.53%, 52.55% and 7.86%, respectively, at the user-level (with duplicate passwords). At the level of unique passwords, SEPCA also beats the three counterparts by up to 43.83%, 94.11% and 11.16%, respectively. Yangde Wang, Weidong Qiu, Peng Tang 0002, Shujun Li 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Local Differential Privacy Is Not Enough: A Sample Reconstruction Attack Against Federated Learning With Local Differential PrivacyabstractReconstruction attacks against federated learning (FL) aim to reconstruct users’ samples through users’ uploaded gradients. Local differential privacy (LDP) is regarded as an effective defense against various attacks, including sample reconstruction in FL, where gradients are clipped and perturbed. Existing attacks are ineffective in FL with LDP since clipped and perturbed gradients obliterate most sample information for reconstruction. Besides, existing attacks embed additional sample information into gradients to improve the attack effect and cause gradient expansion, leading to a more severe gradient clipping in FL with LDP. In this paper, we propose a sample reconstruction attack against LDP-based FL with any target models to reconstruct victims’ sensitive samples to illustrate that FL with LDP is not flawless. Considering gradient expansion in reconstruction attacks and noise in LDP, the core of the proposed attack is gradient compression and reconstructed sample denoising. For gradient compression, an inference structure based on sample characteristics is presented to reduce redundant gradients against LDP. For reconstructed sample denoising, we artificially introduce zero gradients to observe noise distribution and scale confidence interval to filter the noise. Theoretical proof guarantees the effectiveness of the proposed attack. Evaluations show that the proposed attack is the only attack that reconstructs victims’ training samples in LDP-based FL and has little impact on the target model’s accuracy. We conclude that LDP-based FL needs further improvements to defend against sample reconstruction attacks effectively. Zhichao You, Xuewen Dong, Shujun Li 0001, Ximeng Liu, Siqi Ma 0001, Yulong Shen 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | PassTSL: Modeling Human-Created Passwords Through Two-Stage Learning
Haozhang Li, Yangde Wang, Weidong Qiu, Shujun Li 0001, Peng Tang 0002 |
ACISP (3) | 4 |
| 2024 | Multi-Granular Evaluation of Diverse Counterfactual ExplanationsabstractAs a popular approach in Explainable AI (XAI), an increasing number of counterfactual explanation algorithms have been proposed in the context of making machine learning classifiers more trustworthy and transparent. This paper reports our evaluations of algorithms that can output diverse counterfactuals for one instance. We first evaluate the performance of DiCE-Random, DiCE-KDTree, DiCE-Genetic and Alibi-CFRL, taking XGBoost as the machine learning model for binary classification problems. Then, we compare their suggested feature changes with feature importance by SHAP. Moreover, our study highlights that synthetic counterfactuals, drawn from the input domain but not necessarily the training data, outperform native counterfactuals from the training data regarding data privacy and validity. This research aims to guide practitioners in choosing the most suitable algorithm for generating diverse counterfactual explanations. Yining Yuan 0002, Kevin McAreavey, Shujun Li 0001, Weiru Liu |
ICAART (2) | 3 |
| 2024 | When graph convolution meets double attention: online privacy disclosure detection with multi-label text classificationabstractAbstract With the rise of Web 2.0 platforms such as online social media, people’s private information, such as their location, occupation and even family information, is often inadvertently disclosed through online discussions. Therefore, it is important to detect such unwanted privacy disclosures to help alert people affected and the online platform. In this paper, privacy disclosure detection is modeled as a multi-label text classification (MLTC) problem, and a new privacy disclosure detection model is proposed to construct an MLTC classifier for detecting online privacy disclosures. This classifier takes an online post as the input and outputs multiple labels, each reflecting a possible privacy disclosure. The proposed presentation method combines three different sources of information, the input text itself, the label-to-text correlation and the label-to-label correlation. A double-attention mechanism is used to combine the first two sources of information, and a graph convolutional network is employed to extract the third source of information that is then used to help fuse features extracted from the first two sources of information. Our extensive experimental results, obtained on a public dataset of privacy-disclosing posts on Twitter, demonstrated that our proposed privacy disclosure detection method significantly and consistently outperformed other state-of-the-art methods in terms of all key performance indicators. Zhanbo Liang, Jie Guo 0011, Weidong Qiu, Shujun Li 0001 |
Data Min. Knowl. Discov. | 5 |
| 2024 | Recovering sign bits of DCT coefficients in digital images as an optimization problemabstractRecovering unknown, missing, damaged, distorted, or lost information in DCT coefficients is a common task in multiple applications of digital image processing, including image compression, selective image encryption, and image communication. This paper investigates the recovery of sign bits in DCT coefficients of digital images, by proposing two different approximation methods to solve a mixed integer linear programming (MILP) problem, which is NP-hard in general. One method is a relaxation of the MILP problem to a linear programming (LP) problem, and the other splits the original MILP problem into some smaller MILP problems and an LP problem. We considered how the proposed methods can be applied to JPEG-encoded images and conducted extensive experiments to validate their performances. The experimental results showed that the proposed methods outperformed other existing methods by a substantial margin, both according to objective quality metrics and our subjective evaluation. Ruiyuan Lin, Sheng Liu 0025, Shujun Li 0001, Chengqing Li, C.-C. Jay Kuo |
J. Vis. Commun. Image Represent. | 4 |
| 2024 | Security and Privacy Perspectives of People Living in Shared Home EnvironmentsabstractSecurity and privacy (S&P) perspectives of people in a multi-user home are a growing area of research, with many researchers reflecting on the complicated power imbalance and challenging access control issues of the devices involved. However, these studies primarily focused on the multi-user scenarios in traditional family home settings, leaving other types of multi-user home environments, such as homes shared by co-habitants without a familial relationship, under-studied. This paper closes this research gap via quantitative and qualitative analysis of results from an online survey and qualitative content analysis of sampled online posts on Reddit. The study explores the complex roles of shared home users, which depend on various factors unique to the shared home environment, e.g., who owns what home devices, how home devices are used by multiple users, and more complicated relationships between the landlord and people in the shared home and among co-habitants. Half (50.7%) of our survey participants thought that devices in a shared home are less secure than in a traditional family home. This perception was found statistically significantly associated with factors such as the fear of devices being tampered with in their absence and (lack of) trust in other co-habitants and their visitors. We observed cyber-physical threats being a prominent topic discussed in Reddit posts. Our study revealed new user types and user relationships in a multi-user environment such as ExternalPrimary-InternalPrimary while analysing the landlord and shared home resident relationship with regard to shared home device use. Based on the results of the online survey and the Reddit data, we propose a threat actor model for shared home environments, which has a focus on possible malicious behaviours of current and past co-habitants of a shared home, as a special type of insider threat in a home environment. We also recommend further research to understand the complex roles co-habitants can play in navigating and adapting to a shared home environment's security and privacy landscape. Nandita Pattnaik, Shujun Li 0001, Jason R. C. Nurse |
Proc. ACM Hum. Comput. Interact. | 2 |
| 2023 | Support or Refute: Analyzing the Stance of Evidence to Detect Out-of-Context Mis- and DisinformationabstractMis-and disinformation online have become a major societal problem as major sources of online harms of different kinds.One common form of mis-and disinformation is outof-context (OOC) information, where different pieces of information are falsely associated, e.g., a real image combined with a false textual caption or a misleading textual description.Although some past studies have attempted to defend against OOC mis-and disinformation through external evidence, they tend to disregard the role of different pieces of evidence with different stances.Motivated by the intuition that the stance of evidence represents a bias towards different detection results, we propose a stance extraction network (SEN) that can extract the stances of different pieces of multi-modal evidence in a unified framework.Moreover, we introduce a support-refutation score calculated based on the co-occurrence relations of named entities into the textual SEN.Extensive experiments on a public large-scale dataset demonstrated that our proposed method outperformed the state-ofthe-art baselines, with the best model achieving a performance gain of 3.2% in accuracy.* Corresponding co-authors 1 In the literature the terms "misinformation" and "disinformation" often have inconsistent definitions.In our work, we adopt the more established definitions by the United Nations (https://www.undp.org/eurasia/dis/ misinformation): misinformation refers to information that is false but not created with the intention of causing harm and disinformation to information that is false and deliberately created to cause harm.Our work can be applied to both mis-and disinformation, so we will mostly use the term "mis-/disinformation". Xin Yuan 0011, Jie Guo 0011, Weidong Qiu, Shujun Li 0001 |
EMNLP | 5 |
| 2023 | PassViz: An Interactive Visualisation System for Analysing Leaked PasswordsabstractPasswords remain the most widely used form of user authentication, despite advancements in other methods. However, their limitations, such as susceptibility to attacks, especially weak passwords defined by human users, are well-documented. The existence of weak human-defined passwords has led to repeated password leaks from websites, many of which are of large scale. While such password leaks are unfortunate security incidents, they provide security researchers and practitioners with good opportunities to learn valuable insights from such leaked passwords, in order to identify ways to improve password policies and other security controls on passwords. Researchers have proposed different data visualisation techniques to help analyse leaked passwords. However, many approaches rely solely on frequency analysis, with limited exploration of distance-based graphs. This paper reports PassViz, a novel method that combines the edit distance with the t-SNE (t-distributed stochastic neighbour embedding) dimensionality reduction algorithm [19] for visualising and analysing leaked passwords in a 2-D space. We implemented PassViz as an easy-to-use command-line tool for visualising large-scale password databases, and also as a graphical user interface (GUI) to support interactive visual analytics of small password databases. Using the “000webhost” leaked database as an example, we show how PassViz can be used to visually analyse different aspects of leaked passwords and to facilitate the discovery of previously unknown password patterns. Overall, our approach empowers researchers and practitioners to gain valuable insights and improve password security through effective data visualisation and analysis. Sam Parker, Haiyue Yuan, Shujun Li 0001 |
VizSec | 3 |
| 2023 | A systematic literature review of the tension between the GDPR and public blockchain systemsabstractThe blockchain technology has been rapidly growing since Bitcoin was invented in 2008. The most common type of blockchain systems, public (permissionless) blockchain systems have some unique features that lead to a tension with European Union's General Data Protection Regulation (GDPR) and other similar data protection laws. In this paper, we report the results of a systematic literature review (SLR) on 114 research papers discussing and/or addressing such a tension. To the best of our knowledge, our SLR is the most comprehensive review of this topic, leading a more in-depth and broader analysis of related research work on this important topic. Our results revealed three main types of issues: (i) difficulties in exercising data subjects' rights such as the ‘right to be forgotten’ (RTBF) due to the immutable nature of public blockchains; (ii) difficulties in identifying roles and responsibilities in the public blockchain data processing ecosystem (particularly on the identification of data controllers and data processors); (iii) ambiguities regarding the application of the relevant law(s) due to the distributed nature of blockchains. Our work also led to a better understanding of solutions for improving the GDPR compliance of public blockchain systems. Our work can help inform not only blockchain researchers and developers, but also policy makers and law markers to consider how to reconcile the tension between public blockchain systems and data protection laws (the GDPR and beyond). Rahime Belen Saglam, Enes Altuncu, Shujun Li 0001 |
Blockchain Res. Appl. | 4 |
| 2023 | Perspectives of non-expert users on cyber security and privacy: An analysis of online discussions on twitterabstractMany researchers have studied non-expert users’ perspectives of cyber security and privacy aspects of computing devices at home, but their studies are mostly small-scale empirical studies based on online surveys and interviews and limited to one or a few specific types of devices, such as smart speakers. This paper reports our work on an online social media analysis of a large-scale Twitter dataset, covering cyber security and privacy aspects of many different types of computing devices discussed by non-expert users in the real world. We developed two new machine learning based classifiers to automatically create the Twitter dataset with 435,207 tweets posted by 337,604 non-expert users in January and February of 2019, 2020 and 2021. We analyzed the dataset using both quantitative (topic modeling and sentiment analysis) and qualitative analysis methods, leading to various previously unknown findings. For instance, we observed a sharp (more than doubled) increase of non-expert users’ tweets on cyber security and privacy during the pandemic in 2021, compare to in the pre-COVID years (2019 and 2020). Our analysis revealed a diverse range of topics discussed by non-expert users, including VPNs, Wi-Fi, smartphones, laptops, smart home devices, financial security, help-seeking, and roles of different stakeholders. Overall negative sentiment was observed across almost all topics in all the three years. Our results indicate the multi-faceted nature of non-expert users’ perspectives on cyber security and privacy and call for more holistic, comprehensive and nuanced research on their perspectives. Nandita Pattnaik, Shujun Li 0001, Jason R. C. Nurse |
Comput. Secur. | 2 |
| 2023 | AnoFed: Adaptive anomaly detection for digital health using transformer-based federated learning and support vector data description
Ali Raza 0005, Kim Phuc Tran, Ludovic Koehl, Shujun Li 0001 |
Eng. Appl. Artif. Intell. | 4 |
| 2022 | Out of the Shadows: Analyzing Anonymous' Twitter Resurgence during the 2020 Black Lives Matter Protests
Keenan Jones, Jason R. C. Nurse, Shujun Li 0001 |
ICWSM | 3 |
| 2022 | Are You Robert or RoBERTa? Deceiving Online Authorship Attribution Models Using Neural Text Generators
Keenan Jones, Jason R. C. Nurse, Shujun Li 0001 |
ICWSM | 3 |
| 2022 | "Comments Matter and The More The Better!": Improving Rumor Detection with User CommentsabstractWhile many online platforms bring great benefits to their users by allowing user-generated content, they have also facilitated generation and spreading of harmful content such as rumors. Researcher have proposed different rumor detection methods based on features extracted from the original post and/or associated comments, but how comments affect the performance of such methods remains largely less understood. In this paper, we first propose a new BERT-based rumor detection method that can outperform other state-of-the-art methods, and then used it to study the role of comments in rumor detection. Our proposed method concatenates the original post and associated comments to form a single long text, which is then segmented into shorter chunks more suitable for BERT-based vectorization. Features extracted from all trunks are fed into a classifier based on an LSTM network or a transformer layer for the classification task. The experimental results on the PHEME and Ma-Weibo datasets proved the superior performance of our method. We conducted additional experiments on different settings of our proposed method to study different aspects of the role comments play in the rumor detection task. These additional experiments led to some very interesting findings, including the surprising result that fixed-length segmentation is better than natural segmentation, and the observation that including more comments can help improve the rumor detector’s performance. Some of these findings have profound operational implications for online platforms, e.g., commentators can contribute to rumor detection positively so online platforms can leverage the crowd intelligence to detect online rumors more effectively without applying overstrict content consensus policies. Jie Guo 0011, Weidong Qiu, Enes Altuncu, Shujun Li 0001 |
TrustCom | 6 |
| 2022 | Designing ECG monitoring healthcare system with federated transfer learning and explainable AI
Ali Raza 0005, Kim Phuc Tran, Ludovic Koehl, Shujun Li 0001 |
Knowl. Based Syst. | 4 |
| 2022 | "You Just Assume It Is In There, I Guess": Understanding UK Families' Application and Knowledge of Smart Home Cyber SecurityabstractThe Internet of Things (IoT) is increasingly present in many family homes, yet it is unclear precisely how well families understand the cyber security threats and risks of using such devices, and how possible it is for them to educate themselves on these topics. Using a survey of 553 parents and interviews with 25 families in the UK, we find that families do not consider home IoT devices to be significantly different in terms of threats than more traditional home computers, and believe the major risks to be largely mitigated through consumer protection regulation. As a result, parents focus on teaching being careful with devices to prolong device life use, exposing their families to additional security risks and modeling incorrect security behaviors to their children. This is a risk for the present and also one for the future, as children are not taught about the IoT, and appropriate cyber security management of such devices, at school. We go on to suggest that steps must be taken by manufacturers and governments or appropriate trusted institutions to improve the cyber security knowledge and behaviors of both adults and children in relation to the use of home IoT devices. Sarah Turner, Nandita Pattnaik, Jason R. C. Nurse, Shujun Li 0001 |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2021 | Detecting cyber security related Twitter accounts and different sub-groups: a multi-classifier approachabstractMany cyber security experts, organizations, and cyber criminals are active users on online social networks (OSNs). Therefore, detecting cyber security related accounts on OSNs and monitoring their activities can be very useful for different purposes such as cyber threat intelligence, detecting and preventing cyber attacks and online harms on OSNs, and evaluating the effectiveness of cyber security awareness activities on OSNs. In this paper, we report our work on developing several machine learning based classifiers for detecting cyber security related accounts on Twitter, including a base-line classifier for detecting cyber security related accounts in general, and three sub-classifiers for detecting three subsets of cyber security related accounts (individuals, hackers, and academia). To train and test the classifiers, we followed a more systemic approach (based on a cyber security taxonomy, real-time sampling of tweets, and crowdsourcing) to construct a dataset of cyber security related accounts with multiple tags assigned to each account. For each classifier, we considered a richer set of features than those used in past studies. Among five machine learning models tested, the Random Forest model achieved the best performance: 93% for the baseline classifier, 88-91% for the three sub-classifiers. We also studied feature reduction of the base-line classifier and showed that using just six features we can already achieve the same performance. Mohamad Imad Mahaini, Shujun Li 0001 |
ASONAM | 2 |
| 2021 | Special issue on low complexity methods for multimedia security
Guorui Feng, Sheng Li 0006, Haoliang Li, Shujun Li 0001 |
Multim. Syst. | 4 |
| 2021 | Audio steganography with less modification to the optimal matching CNV-QIM path with the minimal hamming distance expected value to a secret
Xinhao Sun, Kaixi Wang, Shujun Li 0001 |
Multim. Syst. | 3 |
| 2021 | CogTool+: Modeling Human Performance at Large ScaleabstractCognitive modeling tools have been widely used by researchers and practitioners to help design, evaluate, and study computer user interfaces (UIs). Despite their usefulness, large-scale modeling tasks can still be very challenging due to the amount of manual work needed. To address this scalability challenge, we propose CogTool+, a new cognitive modeling software framework developed on top of the well-known software tool CogTool. CogTool+ addresses the scalability problem by supporting the following key features: (1) a higher level of parameterization and automation; (2) algorithmic components; (3) interfaces for using external data; and (4) a clear separation of tasks, which allows programmers and psychologists to define reusable components (e.g., algorithmic modules and behavioral templates) that can be used by UI/UX researchers and designers without the need to understand the low-level implementation details of such components. CogTool+ also supports mixed cognitive models required for many large-scale modeling tasks and provides an offline analyzer of simulation results. In order to show how CogTool+ can reduce the human effort required for large-scale modeling, we illustrate how it works using a pedagogical example, and demonstrate its actual performance by applying it to large-scale modeling tasks of two real-world user-authentication systems. Haiyue Yuan, Shujun Li 0001, Patrice Rusconi |
ACM Trans. Comput. Hum. Interact. | 2 |
| 2020 | Behind the Mask: A Computational Study of Anonymous' Presence on Twitter
Keenan Jones, Jason R. C. Nurse, Shujun Li 0001 |
ICWSM | 3 |
| 2020 | When GDPR Meets CRAs (Credit Reference Agencies): Looking through the Lens of TwitterabstractCollecting information about consumers and businesses from various sources, Credit reference agencies (CRAs) help many organizations such as financial institutions to assess creditworthiness of applicants and customers of their services. CRAs’ business model depends on processing a high volume of personal data including highly sensitive ones, which must be processed within the relevant legal frameworks in different countries they operate their business, e.g., the European Union’s new GDPR (General Data Protection Regulation). This paper reports a data-driven analysis of CRA- and GDPR-related discussions on Twitter. Our analysis covers the three largest multi-national CRAs: Equifax, Experian and TransUnion and we also looked at the UK’s data protection authority, ICO, and two UK-based privacy-advocating NGOs, Privacy International and Open Rights Group (ORG). We have analyzed public tweets of their official Twitter accounts and other public tweets talking about them. Our analysis revealed a very surprising lack of awareness of CRA- and GDPR-related data privacy issues within the general public and an astonishing lack of active communications of CRAs to the general public on relevant GDPR-related privacy issues: out of 39,549 collected tweets we identified only 153 relevant tweets (0.387%). This small number of tweets are dominated by mentions of security issues (%73.2), especially data breaches affecting CRAs, not data subject rights or privacy issues directly. Other tweets are mainly about complaints regarding inaccurate data in credit files and questions about how to exercise right to rectification, just two of many data subject rights defined in the GDPR. Kubra Aydin, Rahime Belen Saglam, Shujun Li 0001, Abdullah Bulbul |
SIN | 3 |
| 2020 | Tension between GDPR and Public Blockchains: A Data-Driven Analysis of Online DiscussionsabstractSince coming into effect in May 2018, the EU General Data Protection Regulation (GDPR) has raised serious concerns among users of public (permissionless) blockchain systems. Such concerns are triggered by a tension between some unique characteristics of public blockchain systems and some new data subject rights introduced in the GDPR, e.g., the data immutability and the “right to erasure” (a.k.a. “the right to be forgotten”). The aim of this work is to understand how service providers and developers behind public blockchain systems have communicated about such GDPR-related challenges to their users and how the users have perceived such GDPR-related issues. To this end, for 50 public blockchain systems whose corresponding cryptocurrency had a capital market size over $150 million, we analyzed relevant communications and discussions on the following three online channels: blog and forums posts, GitHub repositories, and discussions on Twitter. Our results show that service providers and developers of the selected public blockchain systems did not play an active role in GDPR-related online discussions on Twitter. They also did not communicate with their users about GDPR on their forums and blogs frequently, where we could identify only 56 posts out of 17,821 posts for the period we studied. Our study also reveals that only an extreme minority of the studied systems (4) mentioned GDPR in their GitHub repositories. Our work adds new evidence on the lack of transparency and active communications of the public blockchain sector on the challenging GDPR compliance issue of public blockchain systems. Zeynep Chousein, Haci Yakup Tetik, Rahime Belen Saglam, Abdullah Bulbul, Shujun Li 0001 |
SIN | 5 |
| 2020 | All about uncertainties and traps: Statistical oracle-based attacks on a new CAPTCHA protection against oracle attacks
Carlos Javier Hernández-Castro, Shujun Li 0001, María Dolores Rodríguez-Moreno |
Comput. Secur. | 2 |
| 2019 | Building Taxonomies based on Human-Machine Teaming: Cyber Security as an ExampleabstractTaxonomies and ontologies are handy tools in many application domains such as knowledge systematization and automatic reasoning. In the cyber security field, many researchers have proposed such taxonomies and ontologies, most of which were built based on manual work. Some researchers proposed the use of computing tools to automate the building process, but mainly on very narrow sub-areas of cyber security. Thus, there is a lack of general cyber security taxonomies and ontologies, possibly due to the difficulties of manually curating keywords and concepts for such a diverse, inter-disciplinary and dynamically evolving field. Mohamad Imad Mahaini, Shujun Li 0001, Rahime Belen Saglam |
ARES | 2 |
| 2019 | Privacy Protection in Tourism: Where We Are and Where We Should Be Heading For
Iis P. Tussyadiah, Shujun Li 0001, Graham Miller |
ENTER | 2 |
| 2019 | When Human cognitive modeling meets PINs: User-independent inter-keystroke timing attacks
Yingjiu Li, Robert H. Deng, Bing Chang, Shujun Li 0001 |
Comput. Secur. | 5 |
| 2018 | 2nd International Workshop on Multimedia Privacy and SecurityabstractThis workshop addresses the security and privacy issues that have developed as our society has become more interconnected, specifically with respect to multimedia data generated in the context of the Internet of Things (IoT) and Web 2.0/3.0. The word "multimedia" here has expanded beyond its original scope. With the rise of social media and online P2P sharing services, large quantities of multimedia data (e.g., pictures, videos, audio, and computer graphics) are being created and shared constantly. When all these data are stored in a networked environment, many people can connect to it for viewing, sharing, commenting, and storing information. Particularly, multimedia data in IoT networks serves a significant purpose as many people's status, locations, and live actions can be seen, disseminated, tracked, commented on, and monitored in real time. IoT opens up many possibilities for attacks since more people can broadcast themselves and allow their networks and networks' networks to view and share in their lives. Roger Hallman, Shujun Li 0001, Victor Chang 0001 |
CCS | 2 |
| 2018 | Data-driven multimedia forensics and security
Anderson Rocha 0001, Shujun Li 0001, C.-C. Jay Kuo, Alessandro Piva, Jiwu Huang |
J. Vis. Commun. Image Represent. | 2 |
| 2018 | User Authentication in the IoE Era: Attacks, Challenges, Evaluation, and New DesignsabstractWe are venturing into the new era of Internet of Everything (IoE) where smaller and smarter computing devices have begun to be integrated into our environments.Despite its great potential, IoE also exposes devices to new security and privacy threats, such as the exposure of devices to attacks emanating from the Internet.User authentication, as a first line of defense, has been widely deployed to prevent unauthorized access, and, in many cases, it is also the primary line of defense.However, conventional user authentication mechanisms are not capable of dealing with this new situation.Firstly, it is not possible to directly utilize Internet-centric security solutions because of the inherently heterogeneous characteristics of IoE devices (e.g., the limited computational capabilities and power supply).Secondly, constrained devices may lack conventional user interfaces, such as keyboard, mice, and touch screen.In summary, the subjects of authentication in IoE are compelling yet largely unexploited, as well as unexplored topics that are in need of more intense interest and research from both the industry and academia.This special issue aims to provide a forum for researchers to publish and exchange their recent research ideas and results about authentication in IoE.In response to the call for papers, after rigorous review and careful revision, the following 5 papers were included in this special issue, ranging from novel understanding of traditional textual passwords, new cryptographic primitives for user authentication, and privacy-preserving biometric authentication to interesting contemporary key users authentication in microblogging. Ding Wang 0002, Shujun Li 0001, Qi Jiang 0001 |
Secur. Commun. Networks | 2 |
| 2017 | PPAndroid-Benchmarker: Benchmarking Privacy Protection Systems on Android DevicesabstractMobile devices are ubiquitous in today's digital world. While people enjoy the convenience brought by mobile devices, it has been proven that many mobile apps leak personal information without user consent or even awareness. That can occur due to many reasons, such as careless programming errors, intention of developers to collect private information, infection of innocent apps by malware, etc. Thus, the research community has proposed many methods and systems to detect privacy leakage and prevent such detected leakage on mobile devices. This is a to do note at margin While it is obviously essential to evaluate the accuracy and effectiveness of privacy protection systems, we are not aware of any automated system that can benchmark performance of privacy protection systems on Android devices. In this paper, we report PPAndroid-Benchmarker, the first system of this kind, which can fairly benchmark any privacy protection systems dynamically (i.e., in run time) or statically. PPAndroid-Benchmarker has been released as an open-source tool and we believe that it will help the research community, developers and even end users to analyze, improve, and choose privacy protection systems on Android devices. We applied PPAndroid-Benchmarker in dynamic mode to 165 Android apps with some privacy protection features, selected from variant app markets and the research community, and showed effectiveness of the tool. We also illustrate two components of PPAndroid-Benchmarker on the design level, which are Automatic Test Apps Generator for benchmarking static analysis based tools and Reconfigurability Engine that allows any instance of PPAndroid-Benchmarker to be reconfigured including but not limited to adding and removing information sources and sinks. Furthermore, we give some insights about current status of mobile privacy protection and prevention in app markets based upon our analysis. Saeed Ibrahim Alqahtani, Shujun Li 0001 |
ARES | 2 |
| 2017 | The Konstanz natural video database (KoNViD-1k)abstractSubjective video quality assessment (VQA) strongly depends on semantics, context, and the types of visual distortions. Currently, all existing VQA databases include only a small number of video sequences with artificial distortions. The development and evaluation of objective quality assessment methods would benefit from having larger datasets of real-world video sequences with corresponding subjective mean opinion scores (MOS), in particular for deep learning purposes. In addition, the training and validation of any VQA method intended to be ‘general purpose’ requires a large dataset of video sequences that are representative of the whole spectrum of available video content and all types of distortions. We report our work on KoNViD-1k, a subjectively annotated VQA database consisting of 1,200 public-domain video sequences, fairly sampled from a large public video dataset, YFCC100m. We present the challenges and choices we have made in creating such a database aimed at ‘in the wild’ authentic distortions, depicting a wide variety of content. Vlad Hosu, Franz Götz-Hahn, Mohsen Jenadeleh, Hanhe Lin, Hui Men, Tamás Szirányi, Shujun Li 0001, Dietmar Saupe |
QoMEX | 7 |
| 2017 | Fast recovery of unknown coefficients in DCT-transformed images
Simying Ong, Shujun Li 0001, Koksheik Wong, KuanYew Tan |
Signal Process. Image Commun. | 2 |
| 2015 | Content-Fragile Commutative Watermarking-Encryption Based on Pixel Entropy
Roland Schmitz, Shujun Li 0001, Christos Grecos, Xinpeng Zhang 0001 |
ACIVS | 2 |
| 2015 | Fortune cookies and smartphones: Weakly unrelayable channels to counter relay attacks
Mario Cagalj, Toni Perkovic, Marin Bugaric, Shujun Li 0001 |
Pervasive Mob. Comput. | 4 |
| 2015 | On the Linearization of Human Identification Protocols: Attacks Based on Linear Algebra, Coding Theory, and LatticesabstractHuman identification protocols are challenge-response protocols that rely on human computational ability to reply to random challenges from the server based on a public function of a shared secret and the challenge to authenticate the human user. One security criterion for a human identification protocol is the number of challenge-response pairs the adversary needs to observe before it can deduce the secret. In order to increase this number, protocol designers have tried to construct protocols that cannot be represented as a system of linear equations or congruences. In this paper, we take a closer look at different ways from algebra, lattices, and coding theory to obtain the secret from a system of linear congruences. We then show two examples of human identification protocols from literature that can be transformed into a system of linear congruences. The resulting attack limits the number of authentication sessions these protocols can be used before secret renewal. Prior to this paper, these protocols had no known upper bound on the number of allowable sessions per secret. Hassan Jameel Asghar, Ron Steinfeld, Shujun Li 0001, Mohamed Ali Kâafar, Josef Pieprzyk |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2014 | jCAPTCHA: Accessible Human Validation
Matthew Davidson, Karen Renaud, Shujun Li 0001 |
ICCHP (1) | 3 |
| 2014 | Enhanced perceptual image authentication with tamper localization and self-restorationabstractIn this paper, an enhanced perceptual image authentication approach is proposed with extra ability of tamper localization and image self-restoration by combining perceptual hashing and digital watermarking technologies. Compared with other perceptual hashing schemes, this proposed approach could locate the maliciously tampered regions and further recover these regions to some extent. Another advantage of this approach is its robustness to various non-malicious image processing operations. This approach could provide better robustness to most content-based image processing operations such as JPEG compression and additive Gaussian noises than most existing semi-fragile watermarking methods. Experimental results demonstrated the high authentication accuracy rate to non-malicious and malicious image processing operations. Moreover, maliciously tampered regions could be correctly localized and the original images can be recovered with good quality as well. Fang Liu 0024, Hui Wang 0020, Lee-Ming Cheng, Anthony Tung Shuen Ho, Shujun Li 0001 |
ICME | 5 |
| 2014 | Special issue on threat detection, analysis and defense
Shujun Li 0001, Konrad Rieck, Alan Woodward |
J. Inf. Secur. Appl. | 1 |
| 2014 | A novel image restoration scheme based on structured side information and its application to image watermarking
Hui Wang 0020, Anthony Tung Shuen Ho, Shujun Li 0001 |
Signal Process. Image Commun. | 3 |
| 2013 | Performance benchmarking of RVC based multimedia specificationsabstractThe Reconfigurable Video Coding (RVC) framework was developed to specify video codecs as abstract and as much as possible implementation-agnostic descriptions, which are supposed to be processed by code synthesis tools to automatically generate implementations for different target languages and platforms. However, there are still questions about if the run-time performance of these automatically generated RVC-based codec implementations is good enough to run efficiently on different target platforms. In this paper, we present a performance benchmarking study on various RVC-based multimedia specifications (H.264/AVC and JPEG codecs, and four multimedia security systems based on these codecs), which covers the following two aspects: 1) the run-time performance against their corresponding non-RVC implementations on a single-core machine; 2) the performance gain these RVC-based implementations on a dual-core machine. Based on our benchmarking results, which show that RVC-based multimedia implementations achieve adequate/acceptable performance, we conclude that RVC has the potential to become a general-purpose but still performance-efficient development framework for many application domains. Junaid Jameel Ahmad, Shujun Li 0001, Marco Mattavelli |
ICIP | 2 |
| 2013 | Towards More Robust Commutative Watermarking-Encryption of ImagesabstractHistogram-based watermarking schemes are invariant against pixel permutations and can be combined with permutation-based ciphers. However, typical histogram-based watermarking schemes based on comparison of histogram bins are prone to de-synchronization attacks, where the whole histogram is shifted by a certain amount. In this paper we investigate the possibility of avoiding this kind of attacks by synchronizing the embedding and detection processes, using the mean of the histogram as a calibration point. The resulting watermarking scheme is resistant to three common types of shifts of the histogram, while the advantages of previous histogram-based schemes, especially commutativity of watermarking and permutation-based encryption, are preserved. Roland Schmitz, Shujun Li 0001, Christos Grecos, Xinpeng Zhang 0001 |
ISM | 2 |
| 2013 | Does Counting Still Count? Revisiting the Security of Counting based User Authentication Protocols against Statistical Attacks
Hassan Jameel Asghar, Shujun Li 0001, Ron Steinfeld, Josef Pieprzyk |
NDSS | 2 |
| 2013 | Secure computing with the MPEG RVC framework
Junaid Jameel Ahmad, Shujun Li 0001, Richard Thavot, Marco Mattavelli |
Signal Process. Image Commun. | 2 |
| 2012 | Leveling the GridabstractMotivated by an application in image processing, we introduce the grid-leveling problem. It turns out to be the dual of a minimum cost flow problem for an apex graph with a grid graph as its basis. We present an O(n3/2) algorithm for this problem. The optimum solution recovers missing DC coefficients from image and video coding by Discrete Cosine Transform used in popular standards like JPEG and MPEG. Generally, we prove that there is an O(n3/2) min-cost flow algorithm for networks that, after removing one node, are planar, have bounded degrees, and have bounded capacities. The costs may be arbitrary. Sabine Cornelsen, Andreas Karrenbauer, Shujun Li 0001 |
ALENEX | 3 |
| 2011 | Recovering missing coefficients in DCT-transformed imagesabstractA general method for recovering missing DCT coefficients in DCT-transformed images is presented in this work. We model the DCT coefficients recovery problem as an optimization problem and recover all missing DCT coefficients via linear programming. The visual quality of the recovered image gradually decreases as the number of missing DCT coefficients increases. For some images, the quality is surprisingly good even when more than 10 most significant DCT coefficients are missing. When only the DC coefficient is missing, the proposed algorithm outperforms existing methods according to experimental results conducted on 200 test images. The proposed recovery method can be used for cryptanalysis of DCT based selective encryption schemes and other applications. Shujun Li 0001, Andreas Karrenbauer, Dietmar Saupe, C.-C. Jay Kuo |
ICIP | 1 |
| 2011 | On the security of a secure Lempel-Ziv-Welch (LZW) algorithmabstractThis paper re-evaluates the security of a secure Lempel-Ziv-Welch (LZW) algorithm proposed at ICME'2008. A chosen-plaintext attack is proposed to break all ciphertext indices corresponding to single-symbol dictionary entries. For short plaintexts the chosen-plaintext attack works well because string-symbol strings appear very frequently. The number of required chosen plaintexts is at the order of the alphabet size. The complexity of the chosen-plaintext attack is O(ML), where M is the number of chosen plaintexts and L is the size of the ciphertext. The chosen-plaintext attack can also be generalized to chosen-ciphertext attack. In addition to the security problem, we point out that the secure LZW algorithm has a lower compression efficiency compared with the original LZW algorithm. Finally we propose several enhancements to the secure LZW algorithm under study. Shujun Li 0001, Chengqing Li, C.-C. Jay Kuo |
ICME | 1 |
| 2011 | Breaking undercover: exploiting design flaws and nonuniform human behaviorabstractThis paper reports two attacks on Undercover, a human authentication scheme against passive observers proposed at CHI 2008. The first attack exploits nonuniform human behavior in responding to authentication challenges and the second one is based on information leaked from authentication challenges or responses visible to the attacker. The second attack can be generalized to break two alternative Undercover designs presented at Pervasive 2009. All the attacks exploit design flaws of the Undercover implementations. Toni Perkovic, Shujun Li 0001, Asma Mumtaz, Syed Ali Khayam, Yousra Javed, Mario Cagalj |
SOUPS | 2 |
| 2010 | Breaking e-banking CAPTCHAsabstractMany financial institutions have deployed CAPTCHAs to protect their services (e.g., e-banking) from automated attacks. In addition to CAPTCHAs for login, CAPTCHAs are also used to prevent malicious manipulation of e-banking transactions by automated Man-in-the-Middle (MitM) attackers. Despite serious financial risks, security of e-banking CAPTCHAs is largely unexplored. In this paper, we report the first comprehensive study on e-banking CAPTCHAs deployed around the world. A new set of image processing and pattern recognition techniques is proposed to break all e-banking CAPTCHA schemes that we found over the Internet, including three e-banking CAPTCHA schemes for transaction verification and 41 schemes for login. These broken e-banking CAPTCHA schemes are used by thousands of financial institutions worldwide, which are serving hundreds of millions of e-banking customers. The success rate of our proposed attacks are either equal to or close to 100%. We also discuss possible improvements to these e-banking CAPTCHA schemes and show essential difficulties of designing e-banking CAPTCHAs that are both secure and usable. Shujun Li 0001, S. Amier Haider Shah, M. Asad Usman Khan, Syed Ali Khayam, Ahmad-Reza Sadeghi, Roland Schmitz |
ACSAC | 1 |
| 2010 | Breaking Randomized Linear Generation Functions Based Virtual Password SystemabstractIn ICC2008 and subsequent work, Lei et al. proposed a user authentication system (virtual password system), which is claimed to be secure against identity theft attacks, including phishing, keylogging and shoulder surfing. Their authentication system is a challenge-response protocol based on a randomized linear generation function, which uses a random integer in the responses of each login session to offer security against assorted attacks. In this paper we show that their virtual password system is insecure and vulnerable to multiple attacks. We show that with high probability an attacker can recover an equivalent password with only two (or a few more) observed login sessions. We also give a brief survey of the related work and discuss the main challenges in designing user authentication methods secure against identity theft. Shujun Li 0001, Syed Ali Khayam, Ahmad-Reza Sadeghi, Roland Schmitz |
ICC | 1 |
| 2010 | An improved DC recovery method from AC coefficients of DCT-transformed imagesabstractMotivated by the work of Uehara et al. [1], an improved method to recover DC coefficients from AC coefficients of DCT-transformed images is investigated in this work, which finds applications in cryptanalysis of selective multimedia encryption. The proposed under/over-flow rate minimization (FRM) method employs an optimization process to get a statistically more accurate estimation of unknown DC coefficients, thus achieving a better recovery performance. It was shown by experimental results based on 200 test images that the proposed DC recovery method significantly improves the quality of most recovered images in terms of the PSNR values and several state-of-the-art objective image quality assessment (IQA) metrics such as SSIM and MS-SSIM. Shujun Li 0001, Junaid Jameel Ahmad, Dietmar Saupe, C.-C. Jay Kuo |
ICIP | 1 |
| 2010 | Cryptanalysis of the Convex Hull Click Human Identification Protocol
Hassan Jameel Asghar, Shujun Li 0001, Josef Pieprzyk, Huaxiong Wang |
ISC | 2 |
| 2010 | A differential cryptanalysis of Yen-Chen-Wu multimedia cryptography system
Chengqing Li, Shujun Li 0001, Kwok-Tung Lo, Kyandoghere Kyamakya |
J. Syst. Softw. | 2 |
| 2009 | On the Security of PAS (Predicate-Based Authentication Service)abstractRecently a new human authentication scheme called PAS (predicate-based authentication service) was proposed, which does not require the assistance of any supplementary device. The main security claim of PAS is to resist passive adversaries who can observe the whole authentication session between the human user and the remote server. In this paper we show that PAS is insecure against both brute force attack and a probabilistic attack. In particular, we show that its security against brute force attack was strongly overestimated. Furthermore, we introduce a probabilistic attack, which can break part of the password even with a very small number of observed authentication sessions. Although the proposed attack cannot completely break the password, it can downgrade the PAS system to a much weaker system similar to common OTP (one-time password) systems. Shujun Li 0001, Hassan Jameel Asghar, Josef Pieprzyk, Ahmad-Reza Sadeghi, Roland Schmitz, Huaxiong Wang |
ACSAC | 1 |
| 2009 | On the Security of an MPEG-Video Encryption Scheme Based on Secret Huffman Tables
Shujun Li 0001, Guanrong Chen, Albert Cheung, Kwok-Tung Lo, Mohan Kankanhalli |
PSIVT | 1 |
| 2009 | On the security defects of an image encryption scheme
Chengqing Li, Shujun Li 0001, Muhammad Asim 0009, Juana Nunez, Gonzalo Álvarez, Guanrong Chen |
Image Vis. Comput. | 2 |
| 2009 | Cryptanalysis of an image encryption scheme based on a compound chaotic sequence
Chengqing Li, Shujun Li 0001, Guanrong Chen, Wolfgang A. Halang |
Image Vis. Comput. | 2 |
| 2008 | Cryptanalysis of the RCES/RSES image encryption scheme
Shujun Li 0001, Chengqing Li, Guanrong Chen, Kwok-Tung Lo |
J. Syst. Softw. | 1 |
| 2008 | A general quantitative cryptanalysis of permutation-only multimedia ciphers against plaintext attacks
Shujun Li 0001, Chengqing Li, Guanrong Chen, Nikolaos G. Bourbakis, Kwok-Tung Lo |
Signal Process. Image Commun. | 1 |
| 2008 | Cryptanalysis of an Image Scrambling Scheme Without Bandwidth ExpansionabstractRecently, a new image scrambling (i.e., encryption) scheme without bandwidth expansion was proposed based on two-dimensional discrete prolate spheroidal sequences. A comprehensive cryptanalysis is given here on this image scrambling scheme, showing that it is not sufficiently secure against various cryptographical attacks including ciphertext-only attack, known/chosen-plaintext attack, and chosen-ciphertext attack. Detailed cryptanalytic results suggest that the image scrambling scheme can only be used to realize perceptual encryption but not to provide content protection for digital images. Shujun Li 0001, Chengqing Li, Kwok-Tung Lo, Guanrong Chen |
IEEE Trans. Circuits Syst. Video Technol. | 1 |
| 2007 | Security problems with improper implementations of improved FEA-M
Shujun Li 0001, Kwok-Tung Lo |
J. Syst. Softw. | 1 |
| 2007 | On the Design of Perceptual MPEG-Video Encryption AlgorithmsabstractIn this paper, some existing perceptual encryption algorithms of MPEG videos are reviewed and some problems, especially security defects of two recently proposed MPEG-video perceptual encryption schemes, are pointed out. Then, a simpler and more effective design is suggested, which selectively encrypts fixed-length codewords in MPEG-video bit streams under the control of three perceptibility factors. The proposed design is actually an encryption configuration that can work with any stream cipher or block cipher. Compared with the previously-proposed schemes, the new design provides more useful features, such as strict size-preservation, on-the-fly encryption and multiple perceptibility, which make it possible to support more applications with different requirements. In addition, four different measures are suggested to provide better security against known/chosen-plaintext attacks. Shujun Li 0001, Guanrong Chen, Albert Cheung, Bharat K. Bhargava, Kwok-Tung Lo |
IEEE Trans. Circuits Syst. Video Technol. | 1 |
| 2006 | On the security of the Yen-Guo's domino signal encryption algorithm (DSEA)
Chengqing Li, Shujun Li 0001, Der-Chyuan Lou |
J. Syst. Softw. | 2 |
| 2006 | Erratum to "On the security of the Yen-Guo's domino signal encryption algorithm (DSEA)" [The Journal of Systems and Software 79 (2006) 253-258]
Chengqing Li, Shujun Li 0001, Der-Chyuan Lou |
J. Syst. Softw. | 2 |
| 2005 | Chosen-Plaintext Cryptanalysis of a Clipped-Neural-Network-Based Chaotic Cipher
Chengqing Li, Shujun Li 0001, Guanrong Chen |
ISNN (2) | 2 |
| 2004 | Breaking network security based on synchronized chaos
Gonzalo Álvarez, Shujun Li 0001 |
Comput. Commun. | 2 |
| 2001 | Statistical Properties of Digital Piecewise Linear Chaotic Maps and Their Roles in Cryptography and Pseudo-Random Coding
Shujun Li 0001, Xuanqin Mou, Yuanlong Cai |
IMACC | 1 |