Jinguo Li

dblp:12/10207 · DBLP profile ↗
← Back
38ranked-venue papers
13as first author
25since 2021 · last 2026
0000-0002-7980-0312ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 5 first-author · 6 since 2021Computer networks · 8 · 5 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 1 first-author · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 4 since 2021Artificial intelligence and machine learning · 3 · 2 first-author · 3 since 2021Systems, architecture and hardware · 3 · 3 since 2021
YearPublicationVenuePosition
2026 FlexDPI: Verifiable and privacy-preserving deep packet inspection with flexible rule subscription
Xiaopin Lv, Kai Zhang 0016, Jinguo Li, Lifei Wei, Jianting Ning
J. Inf. Secur. Appl.3
2026 DC-DPSGD: Double clipping differentially private stochastic gradient descent
Jinguo Li, Mengcheng Liu, Baoxin Xu
Knowl. Based Syst.2
2025 Range Dynamic Searchable Symmetric Encryption: Combating Volume Leakage and Enabling Non-interactive Deletion
abstract
Most existing range Searchable Symmetric Encryption (SSE) schemes are static, making them vulnerable to volume pattern leakage attacks. While Volume-Hiding Range SSE (VH-RSSE) was proposed to mitigate such leakage, it does not support dynamic data updates. Dynamic SSE (DSSE) addresses this limitation, but directly combining VH-RSSE with DSSE for range queries presents significant challenges, including: (i) lack of backward privacy support, (ii) inaccurate search results, and (iii) high storage and communication overhead. Moreover, current schemes typically require multiple client-server interactions to perform deletions. In this paper, we introduce a volume-hiding range DSSE scheme that is the first to support non-interactive deletion, while concealing the identifier volumes associated with keyword values during query execution. Specifically, we propose the Revocable Inverted Index (RII), which integrates an order-accumulated inverted index and bitmap structures to efficiently handle range queries. By combining RII with DSSE and symmetric revocable encryption, we enable the client to directly manage ciphertext deletions, thus achieving non-interactive deletion and eliminating the need for additional communication overhead. We provide a formal analysis of the leakage functions to demonstrate that our scheme offers the desired security guarantees. Extensive experimental results show that our approach significantly enhances efficiency when compared to existing solutions.
Jinguo Li, Junqin Huang, Linghe Kong
TrustCom1
2025 PCIR: Privacy-Preserving Convolutional Neural Network Inference With Rapid Responsiveness
abstract
ABSTRACT Several companies leverage trained convolutional neural networks (CNNs) to offer predictive services to users. These companies capitalize on CNNs' superior performance in image processing tasks, such as autonomous driving or face recognition. To safeguard data privacy and model parameters, various algorithms have been proposed. Most of them are predominantly designed using secure multi‐party computation (MPC) or hardware‐assisted solutions. However, certain limitations persist. First, MPC‐based approaches (e.g., garbled circuits, homomorphic encryption) fail to meet rapid responsiveness requirements. Additionally, hardware‐assisted solutions impose extra burdens to realize secure inference tasks. The primary reasons for these shortcomings can be summarized as follows: (1) high computation and communication delays are introduced by heavy cryptographic operations during the online phase. (2) Additional overhead for sharing triples. In this article, we propose PCIR, a secure protocol for privacy‐preserving convolutional neural network inference (PCIR). PCIR aims to address the aforementioned issues based on a pre‐shared secret sharing mechanism. It can achieve rapid responses to user requirements and preserve privacy of data and model for the following reasons: (1) it circumvents computationally expensive operations, such as an operation for permuting plaintext slots, which runs 56 times slower than a homomorphic addition operation, and 34 times slower than a homomorphic multiplication operation. (2) Computational operations, such as homomorphic additions or multiplications, are conducted during the pre‐computation phase. It can significantly reduce the online computing costs. (3) PCIR conducts secure multiplication based on pre‐shared secret shares. It results in much lower communication and computation costs compared with the use of multiplicative triples. Finally, we evaluate PCIR with benchmark neural networks trained on the MNIST and CIFAR‐10 datasets. The results have shown that PCIR requires less time and less communication cost than previous methodologies.
Jinguo Li, Kai Zhang 0016, Chunlin Li 0015, Peichun Yuan
Comput. Intell.1
2025 F2PQNN: a fast and secure two-party inference on quantized convolutional neural networks
abstract
Abstract The machine learning as a service (MLaaS) paradigm has been widely adopted across various applications. However, it also raises significant privacy concerns, particularly regarding the exposure of input data and trained models. Two-party computation in convolutional neural network (CNN) inference has emerged as a promising solution to address these privacy issues in MLaaS. Nevertheless, most existing privacy-preserving CNN architectures rely on computationally expensive encryption methods, resulting in prolonged inference times and increased communication overhead. In this paper, we propose F2PQNN, a fast and secure two-party inference framework for quantized CNNs. To minimize reliance on computationally intensive encryption, F2PQNN utilizes two non-colluding servers and integrates secret sharing with oblivious transfer techniques. Furthermore, F2PQNN incorporates quantization techniques, along with batching and asynchronous computation, to significantly accelerate inference predictions. We evaluate the performance of F2PQNN on the MNIST, Fashion-MNIST, CIFAR-10, and STL-10 datasets. Experimental results demonstrate that F2PQNN outperforms existing solutions, achieving a $9.14\times $ speedup and reducing communication overhead by $59.8\times $ on the MNIST dataset.
Jinguo Li, Peichun Yuan, Jin Zhang 0018, Sheng Shen 0015, Yin He, Ruyang Xiao
Comput. J.1
2025 Verifiable and Privacy-Enhanced Authorized Keyword Search for Mobile Cloud Storage
abstract
Mobile cloud storage enables IoT devices to use on-demand resources and share data with different mobile devices, where these outsourced data on the cloud are encrypted due to data confidentiality concern. Although dynamic searchable symmetric encryption (DSSE) allows data owners to directly search and update its encrypted data, it rarely considers implementing authorized search toward different mobile devices. Existing authorized keyword search systems for mobile cloud storage suffer from the following limitations: 1) only achieves Type-III backward privacy; 2) no support for verification of search result; and 3) incurs high time overhead for data update and search. Therefore, we propose$\textsf {VE}{-}\textsf {FLY}{++}$, an efficient, verifiable, and authorized DSSE system with forward and enhanced backward privacy for mobile cloud storage. Technically,$\textsf {VE}{-}\textsf {FLY}{++}$presents a verifiable inverted bitmap index (VIBI) to achieve forward privacy and enhanced Type-I (a.k.a.,$\textrm {Type-I}^{-}$) backward privacy, with supporting verification of search results. In addition, we combine symmetric encryption with homomorphic addition with the introduced VIBI for a fast authorized search function. To further enable efficiently handling hundreds of millions of files, we adopt chunking technology to present a highly scalable$\textsf {VE}{-}\textsf {FLY}{++}$. Finally, we use Raspberry Pi, Rock Pi, and Huawei Cloud on real datasets to conduct extensive experiments to clarify the practical efficiency of$\textsf {VE}{-}\textsf {FLY}{++}$.
Zhentao Long, Kai Zhang 0016, Jinguo Li, Pengfei Wu 0003, Jianting Ning
IEEE Internet Things J.3
2025 MSBC-Net: Automatic rectal cancer segmentation from MR scans
Ping Meng, Jinguo Li, Zichao Wang 0009, Jihong Sun
Multim. Tools Appl.2
2025 Pattern-Hiding Encrypted Multi-Maps With Support for Join Queries
abstract
The recently proposed Join Cross-Tags Protocol (JXT) addresses the long-standing issue of excessive query overhead in table joins within Searchable Symmetric Encryption (SSE). As a purely symmetric-key solution, JXT supports efficient conjunctive queries over equi-joins of encrypted tables without requiring any pre-computation during the setup phase. However, JXT has a potential limitation: it may inadvertently reveal the actual volumes of identifiers corresponding to attribute-value pairs, as well as the result values of the join queries. In this paper, we propose JXTMM (JXT multi-map), the first join query scheme designed to hide both volume patterns and result patterns. JXTMM is capable of concealing identifier volumes, preventing the server from learning the actual volumes of attribute-value pairs, and shifting the checkability of join results to the client side, thereby eliminating result pattern leakage. We provide a formal security proof for JXTMM, along with a comprehensive efficiency analysis. Experimental results demonstrate that JXTMM not only performs efficiently on table join queries but also effectively achieves volume-hiding in such queries.
Jinguo Li, Delong Cui, Junqin Huang, Linghe Kong
IEEE Trans. Inf. Forensics Secur.1
2024 Privacy-Preserving Breast Cancer Prediction Based on Logistic Regression
abstract
Abstract With the increasing strain on today’s healthcare resources, there is a growing demand for pre-diagnosis testing. In response, researchers have suggested diverse machine learning models for disease prediction, among which logistic regression stands out as one of the most effective models. Its objective is to enhance the accuracy and efficiency of pre-diagnosis testing, thereby alleviating the burden on healthcare resources. However, when multiple medical institutions collaborate to train models, the untrusted cloud server may pose a risk of private data leakage, enabling participants to steal data from one another. Existing privacy-preserving methods often suffer from drawbacks such as high communication costs, long training times and lack of security proofs. Therefore, it is imperative to jointly train an excellent model collaboratively and uphold data privacy. In this paper, we develop a highly optimized two-party logistic regression algorithm based on CKKS scheme. The algorithm optimizes ciphertext operations by employing ciphertext segmentation and minimizing the multiplication depth, resulting in time savings. Furthermore, it utilizes least squares to approximate sigmoid functions within specific intervals that cannot be handled by homomorphic encryption. Finally, the proposed algorithm is evaluated on a breast cancer dataset, and simulation experiments demonstrate that the model’s prediction accuracy, after machine learning training, exceeds 96% for two-sided encrypted data.
Shuangquan Chen, Jinguo Li, Kai Zhang 0016, Aoran Di, Mengli Lu
Comput. J.2
2024 CM-UTC: A Cost-sensitive Matrix based Method for Unknown Encrypted Traffic Classification
abstract
Abstract Deep learning has been widely adopted in the field of network traffic classification due to its unique advantages in handling encrypted network traffic. However, most existing deep learning models can only classify known encrypted traffic that has been sampled and labeled. In this paper, we propose CM-UTC, a cost-sensitive matrix-based method for classifying unknown encrypted traffic. CM-UTC explores the probability distribution of the DNN output layer to filter out the unknown classes and further designs a cost-sensitive matrix to address the class imbalance problem. Additionally, we propose the utilization of the Harris Hawk optimization algorithm to modify the model parameters and improve its performance. The experiments are validated on two different datasets, and the results demonstrate that CM-UTC not only outperforms existing methods in terms of overall performance but also exhibits superior capability in correctly identifying samples from the minority class.
Jinguo Li, Liangliang Wang 0001, Yin He, Peichun Yuan
Comput. J.2
2024 FedEVCP: Federated Learning-Based Anomalies Detection for Electric Vehicle Charging Pile
abstract
Abstract Vehicle-to-Grid (V2G) is a technology that enables electric vehicles to use smart charging methods to harness low-cost and renewable energy when it is available, and obtain income by feeding energy back into the grid. With the rise of V2G technology, the use of electric vehicles has begun to increase dramatically, which relies on the reliable Electric Vehicle Charging Pile (EVCP). However, most EVCPs are online and networked, introducing many potential network threats, such as Electricity Theft, Identity Theft and False Data Injection etc. Prior work has mostly focused on machine learning, which is not able to effectively capture the relationships and structures in network traffic, making it difficult to deal with the propagation and infection of the novel network attacks. Moreover, most neural network models collect and transfer data from EVCPs to the central server for training, which makes the central server attractive to attackers. It poses a serious threat to user privacy. To address these issues, propose an anomaly detection model that incorporates Federated Learning and Deep Autoencoder, which can increase the amount and diversity of data used to train deep learning models without compromising privacy. The proposed model forms a layer-by-layer unsupervised representation learning algorithm by autoencoder stacking, while batch normalization of hidden layers accelerates the convergence of the model to avoid overfitting and local optima, and introduces an attention mechanism to enhance key features of sequences composed of data vectors to improve the accuracy rate. To prevent the risk of user privacy leakage on the central server, EVCP is allowed to retain local data for model training and send model parameters to the central server for constructing new global models. Experimental results show that the proposed scheme achieves improved detection accuracy with superior performance than other similar models.
Zhaoliang Lin, Jinguo Li
Comput. J.2
2024 Non-interactive Boolean Searchable Asymmetric Encryption With Bilateral Access Control
abstract
Abstract Searchable asymmetric encryption (SAE) enables a client to search over a data owner’s encrypted data. Nevertheless, state-of-the-art SAE schemes allow a data owner to specify access control policy for a client, while they have not considered the threat case of a malicious data owner. To address the problem, this work presents a non-interactive SAE scheme with bilateral access control: (i) allowing data owner and client to both specify policies toward the other party; (ii) allowing client to perform arbitrary boolean queries with sub-linear search complexity. Technically, we extend Cash et al.’s highly scalable SSE into an asymmetric setting and introduce the property of data owner authenticity. By refining identity-based matchmaking encryption, we formalize the syntax and security definition of our SAE with identity-based bilateral access control. Moreover, the security of the proposed SAE can be reduced to discrete logistic assumption and decisional bilinear Diffie–Hellman assumption. As an enhanced extension, we present a non-interactive multi-client SAE scheme with fuzzy identity-based bilateral access control. In addition, we implement the proposed schemes in real cloud platform and evaluate their performance on a real-world dataset. The result confirms that our SAE schemes achieve bilateral access control for both data owner and client with highly acceptable efficiency.
Xiwen Wang 0001, Kai Zhang 0016, Jinguo Li, Mi Wen, Shengmin Xu, Jianting Ning
Comput. J.3
2024 A Contract-Based Privacy-Preserving Longitudinal Data Trading Mechanism for IoT
abstract
Internet of Things (IoT) devices generate vast amounts of real-time data across diverse sectors, offering lucrative opportunities in the data trading market. This facilitates the conversion of raw data into valuable products and services, resulting in significant economic and social benefits. To issue data security problems in trading mechanisms, several solutions based on local differential privacy (LDP) provide lightweight methods for privacy preservation and efficient data exchange. However, most solutions lack effective mechanisms for longitudinal data. Moreover, LDP needs to address the data quality problem in IoT. At last, the pricing of privacy-preserving longitudinal data remains unresolved. To address these problems, we propose a privacy-preserving data trading (PPDT) scheme for IoT in this article. Specifically, to guarantee the security of longitudinal data, we utilize two perturbation techniques to accommodate data owners with varying privacy preferences. To enhance data availability, we devise a binary tree-based aggregation algorithm combined with a weighted average strategy and maximum likelihood estimation. Additionally, we derive an optimal contract that considers different levels of privacy preservation and data trading prices. In scenarios with incomplete information, the contract can provide appropriate incentives to the involved parties. Finally, we demonstrate the efficiency and effectiveness of the proposed data trading scheme through theoretical analysis and extensive experiments.
Jinguo Li, Yun Ni, Jin Zhang 0018, Yin He
IEEE Internet Things J.1
2024 An LDP-Based Privacy-Preserving Longitudinal and Multidimensional Range Query Scheme in IoT
abstract
Range queries are extensively used in various Internet of Things (IoT) applications as an essential functional requirement to provide intelligent and personalized services to users. In IoT environments, diverse types of data are generated, necessitating the design of range query schemes for multidimensional data. Privacy preservation is a key concern for range queries, leading to the proposal of several privacy-preserving solutions. However, most of these solutions are either inefficient or impractical. Moreover, existing approaches often suffer from the problem of longitudinal data privacy leakage, posing a serious threat to user privacy. Although some efforts have addressed the privacy issues of longitudinal data, practical implementations have been hesitant. To tackle these challenges, we propose a local differential privacy-based (LDP) privacy-preserving scheme called the privacy-preserving longitudinal and multidimensional range query (PLMRQ) for IoT. Our scheme focuses on lightweight privacy preservation and eliminates the need for a trusted third party (TTP). First, it is designed based on a double randomizer, ensuring effective privacy preservation of longitudinal data over time. Second, to mitigate excessive noise injection, PLMRQ dynamically constructs a binary tree structure by hierarchically decomposing the entire domain. Finally, through the utilization of a post-processing technique, the mean square error is efficiently reduced. Theoretical and experimental results demonstrate that the proposed PLMRQ maintains competitive utility while rigorously satisfying$\ln {({e^{\epsilon _{1}+t\epsilon _{2}}+1}/{e^{\epsilon _{1}}+e^{t\epsilon _{2}}})}$-LDP with an upper bound of$\epsilon _{1}$and a lower bound of$\epsilon _{2}$.
Yun Ni, Jinguo Li, Wenming Chang, Jifei Xiao
IEEE Internet Things J.2
2024 TRA-PS: Accountable data Pub/Sub service with fast and fine-grained controllable subscription
Kai Zhang 0016, Xiaobing Shi, Jinguo Li, Yi Wu 0011, Jianting Ning
J. Syst. Archit.3
2024 Federated learning on non-IID and long-tailed data via dual-decoupling
abstract
Federated learning (FL), a cutting-edge distributed machine learning training paradigm, aims to generate a global model by collaborating on the training of client models without revealing local private data. The cooccurrence of non-independent and identically distributed (non-IID) and long-tailed distribution in FL is one challenge that substantially degrades aggregate performance. In this paper, we present a corresponding solution called federated dual-decoupling via model and logit calibration (FedDDC) for non-IID and long-tailed distributions. The model is characterized by three aspects. First, we decouple the global model into the feature extractor and the classifier to fine-tune the components affected by the joint problem. For the biased feature extractor, we propose a client confidence re-weighting scheme to assist calibration, which assigns optimal weights to each client. For the biased classifier, we apply the classifier re-balancing method for fine-tuning. Then, we calibrate and integrate the client confidence re-weighted logits with the re-balanced logits to obtain the unbiased logits. Finally, we use decoupled knowledge distillation for the first time in the joint problem to enhance the accuracy of the global model by extracting the knowledge of the unbiased model. Numerous experiments demonstrate that on non-IID and long-tailed data in FL, our approach outperforms state-of-the-art methods.
Hongjiao Li, Jinguo Li, Renhao Hu, Baojin Wang
Frontiers Inf. Technol. Electron. Eng.3
2024 FPCNN: A fast privacy-preserving outsourced convolutional neural network with low-bandwidth
Jinguo Li, Kai Zhang 0016, Chunlin Li 0015, Peichun Yuan
Knowl. Based Syst.1
2024 Continuous release of temporal correlation location statistics with local differential privacy
Renhao Hu, Hongjiao Li, Jinguo Li, Baojin Wang
Multim. Tools Appl.3
2023 Attention-YOLOV4: a real-time and high-accurate traffic sign detection algorithm
Jinguo Li, Ping Meng
Multim. Tools Appl.2
2023 FedLVR: a federated learning-based fine-grained vehicle recognition scheme in intelligent traffic system
Jianqiu Zeng, Kai Zhang 0016, Liangliang Wang 0001, Jinguo Li
Multim. Tools Appl.4
2023 Verifiable Cloud-Based Data Publish-Subscribe Service With Hidden Access Policy
abstract
Cloud-based publish-subscribe (pub-sub) services provide a decoupling method for publishers and subscribers to effectively exchange targeted information and massive data on the cloud platform. Data publishers implement fine-grained access control to set subscription privileges for outsourced data through an access policy. However, in the context of semi-honest cloud platforms, the publisher's access policy may be collected, and incomplete or incorrect subscription results may be returned (e.g., to save communication costs). Existing solutions pay little attention to protecting the data publisher's access policy and cannot provide efficient verification for local results. In this article, we propose a verifiable multi-keyword data publish-subscribe scheme with a hidden access policy (VMP/S). Specifically, VMP/S combines attribute-based keyword search and data aggregation technology to achieve secure fine-grained access control, thereby protecting the privacy of the access policy. Additionally, the scheme provides an effective method for verifying local results by using equal-length verification information to confirm the correctness of feedback subscription data. Furthermore, we introduce a novel verification method for access control to enhance subscription performance efficiency. We demonstrate that VMP/S achieves IND-CKA security and ensures the privacy of the access policy through a comprehensive security analysis. Through experimental simulations, we confirm its effectiveness.
Chunlin Li 0015, Jinguo Li, Kai Zhang 0016, Jianting Ning
IEEE Trans. Cloud Comput.2
2022 A Blockchain-assisted Collaborative Ensemble Learning for Network Intrusion Detection
abstract
With the rapid growth of the Internet network, cyber attacks (mainly DDOS, U2R, Probe, Infiltration and Heart-bleed etc) on networks and computer systems have also increased expeditiously. Intrusion detection system has proven to be one of the most effective methods to resist cyber attacks. Most traditional machine learning methods can only learn shallow features of the data, so they are weak in detecting complex data. Recently, ensemble learning has begun to be applied in network intrusion detection due to their excellent generalization ability. However, most of them are designed based on machine learning methods. They usually do not have multiple hidden layers, which will lead to low detection accuracy. Furthermore, when the base learners in ensemble learning make voting decisions, the data can be easily tampered, which incurs wrong detection results. To solve the above problems, we propose an intrusion detection method based on blockchain and collaborative ensemble learning. In detail, to address the low detection rate of machine learning model, we design an ensemble deep learning approach combining with a weighted dynamic voting mechanism, which can enhance base learners with excellent performance and weaken base learners with poor performance. To solve the problem of data tampering during individual model voting decisions, we explore blockchain to verify the detection results of the individual model and the final results of the voting. Finally, we evaluate the performance of the proposed system on the CICIDS-2017 dataset. The experimental results demonstrate the accuracy and effectiveness of our proposed system.
Lijian Liu, Jinguo Li
TrustCom2
2022 AnoGLA: An efficient scheme to improve network anomaly detection
Qingfeng Ding, Jinguo Li
J. Inf. Secur. Appl.2
2022 An efficient conditional privacy-preserving authentication scheme with scalable revocation for VANETs
Leyan Shen, Liangliang Wang 0001, Kai Zhang 0016, Jinguo Li, Kefei Chen
J. Syst. Archit.4
2021 An Effective Intrusion Detection Model for Class-imbalanced Learning Based on SMOTE and Attention Mechanism
abstract
With the rapid development of the Internet of Things, the continuous emergence of network attacks has brought great threats to network security. Many methods based on deep learning have been applied in detecting intrusion. However, most of these studies ignore the imbalance of network traffic, and the focus on intrusion detection is to find a small number of attack samples. Therefore, they have low accuracy in classifying network attack samples that are far less than normal traffic. In this article, we establish an intrusion detection model SE-DAS(SMOTE and Edited Nearest Neighbours with Dual Attention SRU, SEDAS), which uses the SE algorithm to balance the minority samples in network intrusion detection. Specifically, we use the feature attention mechanism to analyze the relationship between historical information and input features, and extract important features. A timing attention mechanism is used to independently select historical information at key time points in the SRU(Simple Recurrent Units) network to improve the stability of the model detection efficiency. The experimental results on the UNSW-NB15 dataset show that the detection effect of the model on minority categories is 0.037 higher than the macro-average ROC(Receiver Operating Characteristic Curve) area using the original SMOTE algorithm, and the recall rate reaches 98.65%, which is better than similar deep learning models.
Xubin Jiao, Jinguo Li
PST2
2020 An Adversarial Attack with Fusion of Polarization for Unmanned Scenes
abstract
With the rise of artificial intelligence, the emergence of unmanned vehicles can alleviate traffic congestion and reduce the risk of traffic accidents, in which image recognition has become one of the key technologies. Yet, with the advent of the concept of adversarial examples, many works have proved that the existence of adversarial examples has huge hidden danger in the field of scene recognition. Currently, in unmanned scene recognition, polarization images are widely used because they can robustly describe important physical properties of the object. However, most of the researches on adversarial examples are based on RGB images, and few people studied polarization-based imaging. Therefore, this paper proposes an adversarial attack with fusion of polarization for unmanned scenes. Theoretically, we analyze that polarization images have better effects on adversarial example attacks than RGB images. Experimentally, we evaluate the performance of the proposed model by generating adversarial examples attack scene recognition classification model. The experiment results show that compared with RGB images, polarization images are less vulnerable to attack and have better effects on robustness, which can improve the security of unmanned scenes. And it can reduce the successful attack rate of adversarial examples by up to 9.4%.
Huanhuan Lv, Mi Wen, Rongxing Lu, Xuankai Wang, Jinguo Li
VTC Fall5
2020 Cloud-assisted secure and conjunctive publish/subscribe service in smart grids
abstract
The publish/subscribe (P/S) service on Advanced Metering Infrastructure (AMI) servers of smart grid need to deal with huge amount of data, which may lead to data burst on AMI servers and serious server crash. Moreover, for protecting data security, sensitive data must be encrypted before being published. It obstacles traditional data utilisation based on plaintext P/S service. Thus, enabling an encrypted data‐based P/S service is of paramount importance. Considering the huge amount of data and subscribers, it is necessary to allow conjunctive subscriptions containing mixtures of keywords, numeric data etc., and return data according to a reasonable access control mechanism (ACM). In this study, the authors propose a cloud‐assisted secure conjunctive publish/subscribe protocol to challenge the encrypted data‐based P/S service on AMI servers. To overcome the data burst, the P/S computation tasks are shifted from AMI servers to the cloud. To support conjunctive P/S operations in a reasonable ACM, a prefix‐based membership verification algorithm combining with the ciphertext policy attribute‐based encryption is explored. The proposed protocol is proved to be secure against chosen keyword/plaintext attacks under formally defined security models. Experiments on the real‐world data set further show proposed protocol indeed introduce low overhead on computation and communication.
Jinguo Li, Mi Wen, Kai Zhang 0016
IET Inf. Secur.1
2020 Toward efficient and effective bullying detection in online social network
Mi Wen, Rongxing Lu, Beibei Li 0002, Jinguo Li
Peer-to-Peer Netw. Appl.5
2020 HYBRID-CNN: An Efficient Scheme for Abnormal Flow Detection in the SDN-Based Smart Grid
abstract
Software-Defined Network (SDN) can improve the performance of the power communication network and better meet the control demand of the Smart Grid for its centralized management. Unfortunately, the SDN controller is vulnerable to many potential network attacks. The accurate detection of abnormal flow is especially important for the security and reliability of the Smart Grid. Prior works were designed based on traditional machine learning methods, such as Support Vector Machine and Naive Bayes. They are simple and shallow feature learning, with low accuracy for large and high-dimensional network flow. Recently, there have been several related works designed based on Long Short-Term Memory (LSTM), and they show excellent ability on network flow analysis. However, these methods cannot get the deep features from network flow, resulting in low accuracy. To address the above problems, we propose a Hybrid Convolutional Neural Network (HYBRID-CNN) method. Specifically, the HYBRID-CNN utilizes a Deep Neural Network (DNN) to effectively memorize global features by one-dimensional (1D) data and utilizes a CNN to generalize local features by two-dimensional (2D) data. Finally, the proposed method is evaluated by experiments on the datasets of UNSW_NB15 and KDDCup 99. The experimental results show that the HYBRID-CNN significantly outperforms existing methods in terms of accuracy and False Positive Rate (FPR), which successfully demonstrates that it can effectively detect abnormal flow in the SDN-based Smart Grid.
Pengpeng Ding, Jinguo Li, Liangliang Wang 0001, Mi Wen, Yuyao Guan
Secur. Commun. Networks2
2019 Achieve Revocable Access Control for Fog-Based Smart Grid System
abstract
Due to its prodigious advantages, smart grid technology has received considerable attention in recent years. However, security issues are still currently challenging in smart grid. In this paper, aiming at tackle the security issue of power consumption data, we propose a new Ciphertext Policy Attribute-based Encryption (CP-ABE) scheme with revocation for the fog- based smart grid system. Specifically, in order to achieve attribute revocation without requiring users to be always online, we divide users' attributes into attribute groups, assign an attribute group key to each group, and selectively distribute group key update messages. In addition, our scheme uses the DH (Diffie- Hellman) tree to distribute the group key statelessly, which solves the problem of collusion attack. The combination of attribute revocation and user revocation has been used to improve the efficiency of the revocation mechanism. Furthermore, the proposed scheme outsources unnecessary computing operations to fog nodes, so that the computing overhead of users is independent of the number of attributes. Both security analysis and experimental results demonstrate that our proposed scheme can balance the security objectives with the actual efficiency.
Mi Wen, Rongxing Lu, Jinguo Li
VTC Fall4
2019 Secure, flexible and high-efficient similarity search over encrypted data in multiple clouds
Jinguo Li, Mi Wen, Kui Wu 0001, Kejie Lu, Fengyong Li, Hongjiao Li
Peer-to-Peer Netw. Appl.1
2017 A Data Aggregation Scheme with Fine-Grained Access Control for the Smart Grid
abstract
With the rapid development of smart grid, smart meters are deployed at energy consumers' premises to collect real-time usage data. Although such a communication model can help the control center of the energy producer to improve the efficiency and reliability of electricity delivery, it also leads to some security issues. For example, this real-time data involves the customers' privacy. Attackers may violate the privacy for house breaking, or they may tamper with the transmitted data for their own benefits. For this purpose, many data aggregation schemes are proposed for privacy preservation. However, rare of them cares about both the data aggregation and fine- grained access control to improve the data utility. In this paper, we proposes a data aggregation scheme based on attribute decision tree. Security analysis illustrates that our scheme can achieve the data integrity, data privacy preservation and fine- grained data access control. Experiment results show that our scheme are more efficient than existing schemes.
Mi Wen, Hongwei Li 0001, Jinguo Li
VTC Fall4
2016 PSS: Achieving high-efficiency and privacy-preserving similarity search in multiple clouds
abstract
To preserve privacy, sensitive data in cloud computing needs to be encrypted before outsourcing, which obstacles data utilization based on plaintext search. Thus there spring up several secure schemes which enable encrypted cloud-data search. However, these single-cloud-supported search schemes would suffer from service failure, inefficient application, and privacy problem when they are applied to the multi-cloud applications. In this paper, we propose a Privacy-preserving Similarity Search scheme termed PSS. We exploit the n-grams method and counting bloom filters to define and compute the keyword-order. Based on this order, all indexing elements could be organized in a Chord-ring to support multi-cloud similarity search with high efficiency. Moreover, we extend the prefix technique to obtain strong privacy protection. Finally, a proof for the non-adaptive semantic security and the chosen-keyword attack resistance of PSS is given. Extensive experiments on real-world dataset further confirm the high efficacy and efficiency of PSS scheme.
Jinguo Li, Mi Wen, Chunhua Gu, Hongwei Li 0001
ICC1
2016 Group-Based Authentication and Key Agreement With Dynamic Policy Updating for MTC in LTE-A Networks
abstract
Machine type communication (MTC) is an important mobile communication approach in the long-term evaluation-advanced (LTE-A) networks. To meet the MTC security requirements, the access authentication processing of MTC devices needs to follow the evolved packet system-authentication and key agreement (EPS-AKA), a protocol defined in the third generation partnership project (3GPP) standard. However, in the emergence of group-based communication scenarios, an independent authentication processing for each MTC device will cause signal congestion in the networks. In addition, the access-policy updating has always been an issue when constructing authentication schemes. In this paper, we propose a group-based AKA (GR-AKA) protocol with dynamic policy updating. Specifically, we choose an asynchronous secret share scheme combining with Diffie-Hellman key exchange scheme to implement distributed authentication and session key establishment in the LTE-A networks, and to achieve dynamic MTC-device access authority updating. Compared with other authentication protocols in the LTE-A networks, our method could not only authenticate several MTC devices simultaneously but also dynamically update the access-policy to control the access authority of MTC devices. Extensive analysis and experiment results have shown the efficiency and efficacy of proposed protocol.
Jinguo Li, Mi Wen
IEEE Internet Things J.1
2016 PIMRS: achieving privacy and integrity-preserving multi-owner ranked-keyword search over encrypted cloud data
abstract
Because of the flexibility and convenience brought by cloud computing, it has been adopted in many applications. To preserve the privacy of cloud data, data owner often encrypts all sensitive data files, which makes the keyword search application based on plaintext a very challenging task. Therefore, several privacy-preserving keyword search algorithms have been developed recently, and most of these works support only single-data-owner settings. However, there are always more than one data owners in real applications, which are much more complex and challenging than single-owner scenario. To support multi-owner keyword search, those prior search algorithms need to be repeated several times, because each data owner intends to encrypt his own files with a unique private-key separately. It is absolutely not an efficient way. In this paper, we propose a privacy and integrity-preserving multi-owner ranked-keyword search scheme termed PIMRS. In the PIMRS, we exploit an asymmetric scalar-product encryption function based on the TF × IDF rule to preserve data privacy and to obtain more precise search results. Furthermore, a circular bi-direction-linked list based scheme is proposed to preserve the integrity of search results, which also enables the misbehaviors of cloud server to be detected. The security analysis of PIMRS shows its privacy and integrity property, and extensive experiments based on real-world data set confirm the high efficiency of proposed schemes. Copyright © 2016 John Wiley & Sons, Ltd.
Jinguo Li, Mi Wen, Kejie Lu, Chunhua Gu
Secur. Commun. Networks1
2015 Secure and Verifiable Multi-owner Ranked-Keyword Search in Cloud Computing
Jinguo Li, Yaping Lin, Mi Wen, Chunhua Gu, Bo Yin 0004
WASA1
2014 Privacy and integrity preserving skyline queries in tiered sensor networks
abstract
Storage nodes in two-tiered sensor networks are responsible for storing sensor-collected data and processing the sink-issued queries. Therefore, storage nodes are vulnerable to attack because of their importance. In this paper, we propose a privacy and integrity preserving protocol called SSQ, which is able to prevent compromised storage nodes from leaking sensitive data and allows the sink to detect the misbehaviors of compromised storage nodes. For privacy preserving, a size-limited bucketing technique is proposed to mix the data in a range, and a prefix membership verification technique based on Bloom filters is developed to perform skyline queries on encrypted data items. For integrity preserving, a Merkle hash tree-based technique is investigated to prevent compromised storage nodes from tampering and dropping data. Detailed performance evaluations confirm the high efficacy and efficiency of SSQ. Copyright © 2013 John Wiley & Sons, Ltd.
Jinguo Li, Yaping Lin, Rui Li 0020, Bo Yin 0004
Secur. Commun. Networks1
2013 Secure and Verifiable Top-k Query in Two-Tiered Sensor Networks
Yaping Lin, Wei Zhang 0074, Sheng Xiao, Jinguo Li
SecureComm5