EDBT 2026 Demo / reviewers in the wild / expert
Taeho Jung
dblp:12/11514
· DBLP profile ↗
65ranked-venue papers
8as first author
20since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 28 · 3 first-authorSecurity and privacy · 24 · 5 first-author · 14 since 2021Systems, architecture and hardware · 6 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Artificial intelligence and machine learning · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Scalable Private Set Intersection over Distributed Encrypted DataabstractFinding intersections across sensitive data is a core operation in many real-world data-driven applications, such as healthcare, anti-money laundering, financial fraud, or watchlist applications. These applications often require large-scale collaboration across thousands or more independent sources, such as hospitals, financial institutions, or identity bureaus, where all records must remain encrypted during storage and computation, and are typically outsourced to dedicated/cloud servers. Such a highly distributed, large-scale, and encrypted setting makes it very challenging to apply existing solutions, e.g., (multi-party) private set intersection (PSI) or private membership test (PMT). Seunghun Paik, Nirajan Koirala, Jack Nero, Hyunjung Son, Yunki Kim, Jae Hong Seo, Taeho Jung |
AsiaCCS | 7 |
| 2026 | Select-Then-Compute: Encrypted Label Selection and Analytics over Distributed Datasets using FHE
Nirajan Koirala, Seunghun Paik, Sam Martin, Helena Berens, Tasha Januszewicz, Jonathan Takeshita, Jae Hong Seo, Taeho Jung |
NDSS | 8 |
| 2026 | PPIMCE: In-Memory Computing Fabric for Privacy Preserving Computing
Jianqiao Mo, Dayane Reis, Jonathan Takeshita, Taeho Jung, Brandon Reagen, Michael T. Niemier, Xiaobo Sharon Hu |
J. Comput. Sci. Technol. | 5 |
| 2025 | HyDia: FHE-based Facial Matching with Hybrid Approximations and DiagonalizationabstractSecure facial matching systems play a crucial role in privacy preserving biometric authentication, particularly in domains such as law enforcement, border control, and healthcare. Traditional facial matching systems require direct access to biometric data, raising significant privacy concerns. This paper presents HyDia, a novel protocol for scalable FHE-based facial matching with high computation and communication efficiencies, enabling secure one-to-many facial matching without exposing biometric data in plaintext. Our protocol adapts diagonalized matrix multiplication techniques to accommodate highly imbalanced matrix computations, enabling our novel non-rotational inner product algorithm that substantially reduces the homomorphic computation overhead compared to prior works. We further propose a hybrid approximation method for homomorphic thresholding, which achieves better approximation than the state-of-the-art approach (Chebyshev approximation) at the same multiplicative depths. More importantly, our design does not reveal exact similarity scores to the querier; instead, it provides only a threshold-based match decision or matching sources, strengthening privacy by withholding granular database information. We implement HyDia and competing approaches and provide both formal security proof and extensive experimental validation. Our results show that HyDia achieves practical query times at scale, significantly outperforming existing HE-based solutions in both computation and communication overhead. Notably, HyDia is the only viable FHE-based approach in common bandwidth settings (2Mbps & 1Gbps), outperforming the state-of-the-art approaches by 5.2x-227.4x in end-to-end latency under different settings. Finally, our experiments on real-face datasets show that HyDia incurs negligible accuracy loss, by achieving the same F1 score of 0.9968 as the corresponding plaintext facial matching baselines. This work advances the feasibility of privacy-preserving biometric identification, offering a scalable, bandwidth-efficient, and accurate solution for real-world deployments. Sam Martin, Nirajan Koirala, Helena Berens, Tamás Rozgonyi, Micah Brody, Taeho Jung |
Proc. Priv. Enhancing Technol. | 6 |
| 2024 | PrivHChain: Monitoring the Supply Chain of Controlled Substances with Privacy-Preserving Hierarchical BlockchainabstractWith rapidly increasing drug abuse across the world, it is imperative to monitor their supply chain with sufficient transparency. Blockchain is a common solution for achieving transparency in supply chain monitoring, but it does not have sufficient throughput for large-scale supply chains. It is challenging to achieve throughput and privacy simultaneously because complex dependencies among the supply chain events and the need for aggregation both make the application of ZKP challenging. We present PrivHChain, a privacy-preserving hierarchical blockchain that preserves transaction privacy even against blockchain peers while allowing them to verify record consistencies. This is enabled by novel modeling of supply chain events which makes it possible to use novel efficient zero-knowledge protocol schemes to verify the complex dependencies. Novel aggregation techniques are proposed to enable the proof aggregation, and the proofs are used to design monitoring protocols. PrivHChain is implemented and validated with extensive experiments and simulations. The results indicate that (i) the extra overhead of encryption and ZKP schemes is acceptable or negligible, and (ii) the throughput is improved by up to 5 times in simulations even with all the encryption/ZKP schemes. Hyeonbum Lee, Kyuhwan Lee, Wenyi Tang, Shankha Shubhra Mukherjee, Jae Hong Seo, Taeho Jung |
ICBC | 6 |
| 2024 | PPSA: Polynomial Private Stream Aggregation for Time-Series Data Analysis
Antonia Januszewicz, Daniela Medrano Gutiérrez, Nirajan Koirala, Jonathan Takeshita, Taeho Jung |
SecureComm (1) | 7 |
| 2024 | Summation-based Private Segmented Membership Test from Threshold-Fully Homomorphic EncryptionabstractIn many real-world scenarios, there are cases where a client wishes to check if a data element they hold is included in a set segmented across a large number of data holders. To protect user privacy, the client's query and the data holders' sets should remain encrypted throughout the whole process. Prior work on Private Set Intersection (PSI), Multi-Party PSI (MPSI), Private Membership Test (PMT), and Oblivious RAM (ORAM) falls short in this scenario in many ways. They either require data holders to possess the sets in plaintext, incur prohibitively high latency for aggregating results from a large number of data holders, leak the information about the party holding the intersection element, or induce a high false positive. This paper introduces the primitive of a Private Segmented Membership Test (PSMT). We give a basic construction of a protocol to solve PSMT using a threshold variant of approximate-arithmetic homomorphic encryption and show how to overcome existing challenges to construct a PSMT protocol without leaking information about the party holding the intersection element or false positives for a large number of data holders ensuring IND-CPA^D security. Our novel approach is superior to existing state-of-the-art approaches in scalability with regard to the number of supported data holders. This is enabled by a novel summation-based homomorphic membership check rather than a product-based one, as well as various novel ideas addressing technical challenges. Our PSMT protocol supports many more parties (up to 4096 in experiments) compared to prior related work that supports only around 100 parties efficiently. Our experimental evaluation shows that our method's aggregation of results from data holders can run in 92.5s for 1024 data holders and a set size of 2^25, and our method's overhead increases very slowly with the increasing number of senders. We also compare our PSMT protocol to other state-of-the-art PSI and MPSI protocols and discuss our improvements in usability with a better privacy model and a larger number of parties. Nirajan Koirala, Jonathan Takeshita, Jeremy Stevens, Taeho Jung |
Proc. Priv. Enhancing Technol. | 4 |
| 2024 | Accelerating Finite-Field and Torus Fully Homomorphic Encryption via Compute-Enabled (S)RAMabstractFully Homomorphic Encryption (FHE) allows outsourced computation on clients’ encrypted data while preserving data privacy. FHE’s high computational intensity incurs high overhead from data transfer with hardware such as CPU, GPU, and FPGA, due to the inherent separation between computing and data. To overcome this limitation, Compute-Enabled RAM (CE-RAM) has been explored; however, prior work using CE-RAM to accelerate FHE only explores a simple implementation of a finite-field FHE scheme and did not explore algorithmic optimizations.In this paper, we investigate CE-RAM acceleration FHE more deeply, implementing both the finite-field B/FV and torus-based TFHE cryptosystems in CE-RAM with common FHE optimizations. This is the first work to explore using CE-RAM to accelerate TFHE. For B/FV, we explore parameter-specific algorithmic optimizations specifically designed for CE-RAM friendliness. We evaluate our implementation as compared to prior work in CE-RAM FHE acceleration and other hardware acceleration strategies. We demonstrate speedups of up to 784x for B/FV homomorphic multiplication and 38x for TFHE bootstrapping as compared to CPU implementations. We also discuss the overhead of CE-RAM for FHE on energy and area consumption, showing comparable or improved performance as compared to other work or hypothetical near-memory accelerators. Jonathan Takeshita, Dayane Reis, Michael T. Niemier, Xiaobo Sharon Hu, Taeho Jung |
IEEE Trans. Computers | 6 |
| 2024 | Fair$^{2}$2Trade: Digital Trading Platform Ensuring Exchange and Distribution FairnessabstractOnline data trading is increasingly prevalent as data are becoming valuable assets. In most common conventional data trading scenarios, three parties (seller, broker, and buyer) exist, and fairness in trading is essential. This paper discusses and solves the fairness problem in two aspects. First, we considerexchange fairness, which requires payments and data exchanged correctly between buyers and the broker. In existing solutions, keys of encrypted data are traded. However, these solutions failed to provide a complete and secure design for validating keys' correctness unless they used generic theoretical but expensive methods, e.g., zk-SNARK. We address this security issue by designing a new key verification mechanism. We also present a novel atomic exchange protocol based on Hashed Timelock Contracts on Ethereum, reducing gas consumption compared to the existing approach. Second, we considerdistribution fairness, which requires correctly splitting income between the broker and sellers. Straightforward solutions are impractical, i.e., sellers participating in every transaction or traversing the blockchain. Therefore, we design a verifiable statement protocol for sellers to verify the income split efficiently. Further, analysis and experimental results indicate that extra fairness properties are securely achieved, and our protocol reduces users' on-chain participation compared to state-of-the-art protocols. Changhao Chenli, Wenyi Tang, Hyeonbum Lee, Taeho Jung |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | Reputation as Contextual Knowledge: Incentives and External Value in Truthful Blockchain OraclesabstractThe primary strengths of blockchain systems come from strong guarantees of immutability and reliability, and these systems can be extended with programmatic logic through Smart Contracts. Many such programmatic use cases would benefit from the use of external data. However, the method of bringing that data onto the blockchain needs to be trustworthy and secure. Otherwise, the benefits of blockchain, namely distributed trust, no single points of failure, and immutability, would be at risk. Blockchain oracles are proposed as a conceptual solution to this problem. A blockchain oracle acts as a trusted intermediary to external data. In this work we analyze existing proposals for Discernible event oracle mechanisms, which seek to address oracle queries with a broad knowledgeable answering population, to characterize problems related to the incentives imposed by external value that depends on oracle outcomes. In doing so, we focus on continued challenges to voting based oracles, including trust limitations and the need to match questions to knowledgeable answering parties. To address these difficulties, we propose an extension to existing oracle protocols to utilize reputation as a tool to measure value and as a tool to associate questions with context. By providing a method to track contextual knowledge, our proposal allows for context-based query matching and enables higher probability of correctness for a given population size as well as stronger participation incentives. Michael Bartholic, Eric William Burger, Shin'ichiro Matsuo, Taeho Jung |
ICBC | 4 |
| 2023 | SLAP: Simpler, Improved Private Stream Aggregation from Ring Learning with Errors
Jonathan Takeshita, Ryan Karl, Taeho Jung |
J. Cryptol. | 4 |
| 2022 | TERSE: Tiny Encryptions and Really Speedy Execution for Post-Quantum Private Stream Aggregation
Jonathan Takeshita, Zachariah Carmichael, Ryan Karl, Taeho Jung |
SecureComm | 4 |
| 2022 | A collaboration strategy in the mining pool for proof-of-neural-architecture consensusabstractIn most popular public accessible cryptocurrency systems, the mining pool plays a key role because mining cryptocurrency with the mining pool turns the non-profitable situation into profitable for individual miners. In many recent novel blockchain consensuses, the deep learning training procedure becomes the task for miners to prove their workload. Thus, the computation power of miners will not purely be spent on the hash puzzle. In this way, the hardware and energy will support the blockchain service and deep learning training simultaneously. While the incentive of miners is to earn tokens, individual miners are motivated to join mining pools to become more competitive. In this paper, we are the first to demonstrate a mining pool solution for novel consensuses based on deep learning. The mining pool manager partitions the full searching space into subspaces, and all miners are scheduled to collaborate on the Neural architecture search (NAS) tasks in the assigned subspace. Experiments demonstrate that the performance of this type of mining pool is more competitive than that of an individual miner. Due to the uncertainty of miners' behaviors, the mining pool manager checks the standard deviation of the performance of high reward miners and prepares backup miners to ensure completion of the tasks of high reward miners. Boyang Li 0003, Qing Lu 0001, Weiwen Jiang, Taeho Jung, Yiyu Shi 0001 |
Blockchain Res. Appl. | 4 |
| 2022 | ProvNet: Networked bi-directional blockchain for data sharing with verifiable provenance
Changhao Chenli, Wenyi Tang, Frank Gomulka, Taeho Jung |
J. Parallel Distributed Comput. | 4 |
| 2022 | Federated Dynamic Graph Neural Networks with Secure Aggregation for Video-based Distributed SurveillanceabstractDistributed surveillance systems have the ability to detect, track, and snapshot objects moving around in a certain space. The systems generate video data from multiple personal devices or street cameras. Intelligent video-analysis models are needed to learn dynamic representation of the objects for detection and tracking. Can we exploit the structural and dynamic information without storing the spatiotemporal video data at a central server that leads to a violation of user privacy? In this work, we introduce Federated Dynamic Graph Neural Network (Feddy), a distributed and secured framework to learn the object representations from graph sequences: (1) It aggregates structural information from nearby objects in the current graph as well as dynamic information from those in the previous graph. It uses a self-supervised loss of predicting the trajectories of objects. (2) It is trained in a federated learning manner. The centrally located server sends the model to user devices. Local models on the respective user devices learn and periodically send their learning to the central server without ever exposing the user’s data to server. (3) Studies showed that the aggregated parameters could be inspected though decrypted when broadcast to clients for model synchronizing, after the server performed a weighted average. We design an appropriate aggregation mechanism of secure aggregation primitives that can protect the security and privacy in federated learning with scalability. Experiments on four video camera datasets as well as simulation demonstrate that Feddy achieves great effectiveness and security. Meng Jiang 0001, Taeho Jung, Ryan Karl, Tong Zhao 0003 |
ACM Trans. Intell. Syst. Technol. | 2 |
| 2021 | CryptoGram: Fast Private Calculations of Histograms over Multiple Users' InputsabstractHistograms have a large variety of useful applications in data analysis, e.g., tracking the spread of diseases and analyzing public health issues. However, most data analysis techniques used in practice operate over plaintext data, putting the privacy of users’ data at risk. We consider the problem of allowing an untrusted aggregator to privately compute a histogram over multiple users’ private inputs (e.g., number of contacts at a place) without learning anything other than the final histogram. This is a challenging problem to solve when the aggregators and the users may be malicious and collude with each other to infer others’ private inputs, as existing black box techniques incur high communication and computational overhead that limit scalability. We address these concerns by building a novel, efficient, and scalable protocol that intelligently combines a Trusted Execution Environment (TEE) and the Durstenfeld-Knuth uniformly random shuffling algorithm to update a mapping between buckets and keys by using a deterministic cryptographically secure pseudorandom number generator. In addition to being provably secure, experimental evaluations of our technique indicate that it generally outperforms existing work by several orders of magnitude, and can achieve performance that is within one order of magnitude of protocols operating over plaintexts that do not offer any security. Ryan Karl, Jonathan Takeshita, Alamin Mohammed, Aaron Striegel, Taeho Jung |
DCOSS | 5 |
| 2021 | Cryptonite: A Framework for Flexible Time-Series Secure Aggregation with Non-interactive Fault Recovery
Ryan Karl, Jonathan Takeshita, Taeho Jung |
SecureComm (1) | 3 |
| 2021 | Cryptonomial: A Framework for Private Time-Series Polynomial Calculations
Ryan Karl, Jonathan Takeshita, Alamin Mohammed, Aaron Striegel, Taeho Jung |
SecureComm (1) | 5 |
| 2021 | Provably Secure Contact Tracing with Conditional Private Set Intersection
Jonathan Takeshita, Ryan Karl, Alamin Mohammed, Aaron Striegel, Taeho Jung |
SecureComm (1) | 5 |
| 2021 | Speech Sanitizer: Speech Content Desensitization and Voice AnonymizationabstractVoice input users’ speech recordings are being collected by service providers and shared with third parties, who may abuse users’ voiceprints, identify them by voice, and learn their sensitive speech content. In this work, we designSpeech Sanitizerto perturb users’ speech recordings so that the sanitized speech can be safely shared with third parties. First, we desensitize speech content by identifying sensitive words, localizing them in the audio using DTW-based keyword spotting, and substituting them with safe words. Both common and personalized sensitive words are identified and replaced. Then, we anonymize users’ voiceprints with a carefully designed voice conversion mechanism that is resistant to de-anonymization attacks. Meanwhile, we try to preserve the utility of the sanitized speech, measured by the accuracy of speech recognition performed on it. We implement Speech Sanitizer and present extensive experimental results that validate the effectiveness and efficiency of our algorithms. It is demonstrated that we are able to reduce the chance of a user's voice being identified from 50 people by 83.7 percent while keeping the drop of speech recognition accuracy within 19.1 percent. We can also easily relax the privacy level to improve speech recognition accuracy. Jianwei Qian, Haohua Du, Jiahui Hou, Taeho Jung, Xiang-Yang Li 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2020 | Secure Single-Server Nearly-Identical Image DeduplicationabstractCloud computing is often utilized for file storage. Clients of cloud storage services want to ensure the privacy of their data, and both clients and servers want to use as little storage as possible. Cross-user deduplication is one method to reduce the amount of storage a server uses. Deduplication and privacy are naturally conflicting goals, especially for nearly-identical ("fuzzy") deduplication, as some information about the data must be used to perform deduplication. Prior solutions thus utilize multiple servers, or only function for exact deduplication. In this paper, we present a single-server protocol for cross-user nearly-identical deduplication based on secure LSH (SLSH). We formally define our ideal security, and rigorously prove our protocol secure against fully malicious, colluding adversaries with a proof by simulation. We show experimentally that the individual parts of the protocol are computationally feasible, and further discuss practical issues of security and efficiency. Jonathan Takeshita, Ryan Karl, Taeho Jung |
ICCCN | 3 |
| 2020 | Algorithmic Acceleration of B/FV-Like Somewhat Homomorphic Encryption for Compute-Enabled RAM
Jonathan Takeshita, Dayane Reis, Michael T. Niemier, Xiaobo Sharon Hu, Taeho Jung |
SAC | 6 |
| 2020 | PatronuS: A System for Privacy-Preserving Cloud Video SurveillanceabstractPrivacy has become one of the major concerns in cloud video surveillance. Privacy protection of the surveillance videos strive to protect users' privacy information without hampering regular security tasks of the surveillance, meanwhile retains the system's high accuracy and efficiency. The current state of the art in protecting the video privacy is mainly realized through Privacy Region Protection, which only protects the privacy regions while keeps the non-privacy regions visually intact so that processing in the cloud is still feasible. However, the problem of determining the privacy regions has been ignored and not properly addressed. In this paper, we propose a novel notion - concept graph, and with the aid of that, we develop our system - PatronuS to determine the privacy regions subject to satisfying both privacy and security requirements. We further propose an event distilling model and a privacy inference model to assist in determining specific privacy regions. And we evaluate PatronuS in real-world settings and demonstrate its efficiency in privacy protection without degrading system's surveillance functionality. Haohua Du, Jianwei Qian, Jiahui Hou, Taeho Jung, Xiang-Yang Li 0001 |
IEEE J. Sel. Areas Commun. | 5 |
| 2020 | Computing-in-Memory for Performance and Energy-Efficient Homomorphic EncryptionabstractHomomorphic encryption (HE) allows direct computations on encrypted data. Despite numerous research efforts, the practicality of HE schemes remains to be demonstrated. In this regard, the enormous size of ciphertexts involved in HE computations degrades computational efficiency. Near-memory processing (NMP) and computing-in-memory (CiM)—paradigms where computation is done within the memory boundaries—represent architectural solutions for reducing latency and energy associated with data transfers in data-intensive applications, such as HE. This article introduces CiM-HE, a CiM architecture that can support operations for the Brakerski/Fan–Vercauteren (B/FV) scheme, a somewhat HE scheme for general computation. CiM-HE hardware consists of customized peripherals, such as sense amplifiers, adders, bit shifters, and sequencing circuits. The peripherals are based on CMOS technology and could support computations with memory cells of different technologies. Circuit-level simulations are used to evaluate our CiM-HE framework assuming a 6T-SRAM memory. We compare our CiM-HE implementation against: 1) two optimized CPU HE implementations and 2) a field-programmable gate array (FPGA)-based HE accelerator implementation. Compared with a CPU solution, CiM-HE obtains speedups between$4.6\times $and$9.1\times $and energy savings between$266.4\times $and$532.8\times $for homomorphic multiplications (the most expensive HE operation). Also, a set of four end-to-end tasks, i.e., mean, variance, linear regression, and inference, are up to$1.1\times $,$7.7\times $,$7.1\times $, and$7.5\times $faster (and$301.1\times $,$404.6\times $,$532.3\times $, and$532.8\times $more energy efficient). Compared with CPU-based HE in previous work, CiM-HE obtains$14.3\times $speedup and$> 2600\times $energy savings. Finally, our design offers$2.2\times $speedup with$88.1\times $energy savings compared with a state-of-the-art FPGA-based accelerator. Dayane Reis, Jonathan Takeshita, Taeho Jung, Michael T. Niemier, Xiaobo Sharon Hu |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2019 | Non-Interactive MPC with Trusted Hardware Secure Against Residual Function Attacks
Ryan Karl, Timothy Burchfield, Jonathan Takeshita, Taeho Jung |
SecureComm (2) | 4 |
| 2019 | Social Network De-Anonymization and Privacy Inference with Knowledge Graph ModelabstractSocial network data is widely shared, transferred and published for research purposes and business interests, but it has raised much concern on users' privacy. Even though users' identity information is always removed, attackers can still de-anonymize users with the help of auxiliary information. To protect against de-anonymization attack, various privacy protection techniques for social networks have been proposed. However, most existing approaches assume specific and restrict network structure as background knowledge and ignore semantic level prior belief of attackers, which are not always realistic in practice and do not apply to arbitrary privacy scenarios. Moreover, the privacy inference attack in the presence of semantic background knowledge is barely investigated. To address these shortcomings, in this work, we introduce knowledge graphs to explicitly express arbitrary prior belief of the attacker for any individual user. The processes of de-anonymization and privacy inference are accordingly formulated based on knowledge graphs. Our experiment on data of real social networks shows that knowledge graphs can power de-anonymization and inference attacks, and thus increase the risk of privacy disclosure. This suggests the validity of knowledge graphs as a general effective model of attackers' background knowledge for social network attack and privacy preservation. Jianwei Qian, Xiang-Yang Li 0001, Chunhong Zhang, Taeho Jung, Junze Han |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2019 | AccountTrade: Accountability Against Dishonest Big Data Buyers and SellersabstractIn this paper, a set of accountable protocols denoted as AccountTrade is proposed for big data trading among dishonest consumers. For achieving a secure big data trading environment, AccountTrade achieves book-keeping ability and accountability against dishonest consumers throughout the trading (i.e., buying and selling) of datasets. We investigate the consumers' responsibilities in the dataset trading, then we design AccountTrade to achieve accountability against dishonest consumers that are likely to deviate from the responsibilities. Specifically, a uniqueness index is defined and proposed, which is a new rigorous measurement of the data uniqueness for this purpose. Furthermore, several accountable trading protocols are presented to enable data brokers to blame the misbehaving entities when misbehavior is detected. The accountability of AccountTrade is formally defined, proved, and evaluated by an automatic verification tool as well as extensive simulation with real-world datasets. Our evaluation shows that AccountTrade incurs at most 10-kB storage overhead per file, and it is capable of 8-1000 concurrent data upload requests per server. Taeho Jung, Xiang-Yang Li 0001, Wenchao Huang 0001, Zhongying Qiao, Jianwei Qian, Junze Han, Jiahui Hou |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | Social Network De-anonymization: More Adversarial Knowledge, More Users Re-identified?abstractPrevious works on social network de-anonymization focus on designing accurate and efficient de-anonymization methods. We attempt to investigate the intrinsic relationship between the attacker’s knowledge and the expected de-anonymization gain. A common intuition is that more knowledge results in more successful de-anonymization. However, our analysis shows this is not necessarily true if the attacker uses the full background knowledge for de-anonymization. Our findings leave intriguing implications for the attacker to make better use of the background knowledge for de-anonymization and for the data owners to better measure the privacy risk when releasing their data to third parties. Jianwei Qian, Xiang-Yang Li 0001, Taeho Jung, Yu Wang 0003, Shaojie Tang 0001 |
ACM Trans. Internet Techn. | 3 |
| 2018 | Crowdlearning: Crowded Deep Learning with Data PrivacyabstractDeep Learning has shown promising performance in a variety of pattern recognition tasks owning to large quantities of training data and complex structures of neural networks. However conventional deep neural network (DNN) training involves centrally collecting and storing the training data, and then centrally training the neural network, which raises much privacy concerns for the data producers. In this paper, we study how to enable deep learning without disclosing individual data to the DNN trainer. We analyze the risks in conventional deep learning training, then propose a novel idea - Crowdlearning, which decentralizes the heavy- load training procedure and deploys the training into a crowd of computation-restricted mobile devices who generate the training data. Finally, we propose SliceNet, which ensures mobile devices can afford the computation cost and simultaneously minimize the total communication cost. The combination of Crowdlearning and SliceNet ensures the sensitive data generated by mobile devices never leave the devices, and the training procedure will hardly disclose any inferable contents. We numerically simulate our prototype of SliceNet which crowdlearns an accurate DNN for image classification, and demonstrate the high performance, acceptable calculation and communication cost, satisfiable privacy protection, and preferable convergence rate, on the benchmark DNN structure and dataset. Taeho Jung, Haohua Du, Jianwei Qian, Jiahui Hou, Xiang-Yang Li 0001 |
SECON | 2 |
| 2018 | Hidebehind: Enjoy Voice Input with Voiceprint Unclonability and AnonymityabstractWe are speeding toward a not-too-distant future when we can perform human-computer interaction using solely our voice. Speech recognition is the key technology that powers voice input, and it is usually outsourced to the cloud for the best performance. However, user privacy is at risk because voiceprints are directly exposed to the cloud, which gives rise to security issues such as spoof attacks on speaker authentication systems. Additionally, it may cause privacy issues as well, for instance, the speech content could be abused for user profiling. To address this unexplored problem, we propose to add an intermediary between users and the cloud, named VoiceMask, to anonymize speech data before sending it to the cloud for speech recognition. It aims to mitigate the security and privacy risks by concealing voiceprints from the cloud. VoiceMask is built upon voice conversion but is much more than that; it is resistant to two de-anonymization attacks and satisfies differential privacy. It performs anonymization in resource-limited mobile devices while still maintaining the usability of the cloud-based voice input service. We implement VoiceMask on Android and present extensive experimental results. The evaluation substantiates the efficacy of VoiceMask, e.g., it is able to reduce the chance of a user's voice being identified from 50 people by a mean of 84%, while reducing voice input accuracy no more than 14.2%. Jianwei Qian, Haohua Du, Jiahui Hou, Taeho Jung, Xiang-Yang Li 0001 |
SenSys | 5 |
| 2018 | MIS2: Misinformation and Misbehavior Mining on the WebabstractMisinformation and misbehavior mining on the web(MIS2) workshop is held in Los Angeles, California, USA on February 9, 2018, and co-located with the 11th ACM International Conference on Web Search and Data Mining(WSDM 2018). Web is a dynamic ecosystem that enables malicious users to create and spread deceptive information to a wide audience in a matter of minutes. These malicious actors work on a wide variety of platforms, such as social media, e-commerce, and more. The main object of MIS2 is to discuss new and upcoming research on modeling, discovery, detection, and mitigation methods of misbehavior and misinformation on the web. MIS2 is an interdisciplinary venue for leading researchers and practitioners from the areas of data mining, social network analysis, cybersecurity, communications, human-computer interaction, and natural language processing. The topics addressed in MIS2 are extremely timely and the research presented by refereed papers and invited keynote speakers will participants a full dose of emerging research. Srijan Kumar, Meng Jiang 0001, Taeho Jung, Roger Jie Luo, Jure Leskovec |
WSDM | 3 |
| 2018 | PDA: Semantically Secure Time-Series Data Analytics with Dynamic User GroupsabstractThird-party analysis on private records is becoming increasingly important due to the widespread data collection for various analysis purposes. However, the data in its original form often contains sensitive information about individuals, and its publication will severely breach their privacy. In this paper, we present a novel Privacy-preserving Data Analytics framework PDA, which allows a third-party aggregator to obliviously conduct many different types of polynomial-based analysis on private data records provided by a dynamic sub-group of users. Notably, every user needs to keep only O(n) keys to join data analysis among O(2n) different groups of users, and any data analysis that is represented by polynomials is supported by our framework. Besides, a real implementation shows the performance of our framework is comparable to the peer works who present ad-hoc solutions for specific data analysis applications. Despite such nice properties of PDA, it is provably secure against a very powerful attacker (chosen-plaintext attack) even in the Dolev-Yao network model where all communication channels are insecure. Taeho Jung, Junze Han, Xiang-Yang Li 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2018 | CASTLE: Enhancing the Utility of Inequality Query Auditing Without Denial ThreatsabstractWe consider a private data set composed of a set of individuals, and the data are outsourced to a remote cloud server. We revisit the classic query auditing problem in this outsourcing scenario; the cloud audits each newly arrived query on a single attribute, and the query is rejected if answering it compromises any individual's privacy. Various query auditing issues have been studied and addressed before. However, previous auditing schemes either have the difficulty of removing denial threats, or lack the analysis of utility (which is defined as the number of answered queries). In this paper, we study the auditing of a sequence of polynomial-time computable queries. Each query is of format f(X̃) a, where f is any polynomial function, X̃ is a subset of the private data set, and the answer is either “yes” or “no”. Existing methods cannot be applied directly to audit such a query, because it intermingles several types of functions (e.g., sum and max/min). Hence, we propose CASTLE, which is an inequality query auditing scheme that evaluates the risk of answering a query based on the query history and determines whether a newly arrived query should be answered correctly against a denial threat. Furthermore, to overcome the limitations of the existing query auditing mechanisms, which are of low utility, we relax CASTLE to increase the utility by returning answers with slight perturbations. We show that our method can be applied to audit intermingled equality queries with an extension. Experiments are conducted to evaluate the efficiency and effectiveness of our methods. Jiahui Hou, Xiang-Yang Li 0001, Taeho Jung, Yu Wang 0003, Daren Zheng |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2017 | AccountTrade: Accountable protocols for big data trading against dishonest consumersabstractWe propose AccountTrade, a set of accountable protocols, for big data trading among dishonest consumers. To secure the big data trading environment, our protocols achieve book-keeping ability and accountability against dishonest consumers who may misbehave throughout the dataset transactions. Specifically, we study the responsibilities of the consumers in the dataset trading and design AccountTrade to achieve accountability against the dishonest consumers who may try to deviate from their responsibilities. Specifically, we propose uniqueness index, a new rigorous measurement of the data uniqueness, as well as several accountable trading protocols to enable data brokers to blame the dishonest consumer when misbehavior is detected. We formally define, prove, and evaluate the accountability of our protocols by an automatic verification tool as well as extensive evaluation in real-world datasets. Our evaluation shows that AccountTrade incurs negligible constant storage overhead per file (<;10KB), and it is able to handle 8-1000 concurrent data uploading per server depending on the data types. Taeho Jung, Xiang-Yang Li 0001, Wenchao Huang 0001, Jianwei Qian, Junze Han, Jiahui Hou |
INFOCOM | 1 |
| 2017 | FBS-Radar: Uncovering Fake Base Stations at Scale in the Wild
Zhenhua Li 0001, Weiwei Wang 0002, Christo Wilson, Chen Qian 0001, Taeho Jung, Lan Zhang 0002, Kebin Liu 0001, Xiang-Yang Li 0001, Yunhao Liu 0001 |
NDSS | 6 |
| 2017 | Scalable privacy-preserving participant selection in mobile crowd sensingabstractAuction based participant selection has been widely used for mobile crowd sensing (MCS) to achieve user incentive and assignment optimization. However, mobile crowd sensing problems solved with auction-based approaches usually involve participants' privacy concerns because a participant's bids may contain her private information (such as location visiting patterns), and disclosure participants' bids may disclose their private information as well. In this paper, we study how to protect such bid privacy in a temporally and spatially dynamic MCS system. We assume that both sensing tasks and mobile participants have dynamic characteristics over spatial and temporal domains. Following the classical VCG auction, we carefully design a scalable grouping based privacy-preserving participant selection scheme, which leverages Lagrange polynomial interpolation to perturb participants' bids within groups. The proposed solution does not affect the operation of current MCS platform. Both theoretical analysis and real-life tracing data simulations verify the efficiency and security of the proposed solution. Ting Li 0010, Taeho Jung, Hanshang Li, Lijuan Cao, Weichao Wang, Xiang-Yang Li 0001, Yu Wang 0003 |
PerCom | 2 |
| 2017 | Detecting Driver's Smartphone Usage via Nonintrusively Sensing Driving DynamicsabstractIn this paper, we address a critical task of dynamically detecting the simultaneous behavior of driving and texting using smartphone as the sensor. We propose, design, and implement TEXIVE which achieves the goal of detecting texting operations during driving utilizing irregularities and rich micro-movements of users. Without relying on any external infrastructures and additional devices, and no need to bring any modification to vehicles, TEXIVE is able to successfully detect dangerous operations with good sensitivity, specificity, and accuracy by leveraging the inertial sensors integrated in regular smartphones. To validate our approach, we conduct extensive experiments involving in a number of volunteers on various of vehicles and smartphones. Our evaluation results show that TEXIVE has a classification accuracy of 87.18%, and precision of 96.67%. Cheng Bo, Xuesi Jian, Taeho Jung, Junze Han, Xiang-Yang Li 0001, Xufei Mao, Yu Wang 0003 |
IEEE Internet Things J. | 3 |
| 2017 | Martian: Message Broadcast via LED Lights to Heterogeneous SmartphonesabstractVisible light communication (VLC) has been shown to have several advantages over traditional wireless communication. In this paper, we envision an LED-light-to-smartphone VLC protocol for delivering messages to a group of randomly arriving smartphone receivers. Our goal is to increase the throughput for large message delivery, as well as to reduce the delay of message broadcast. Key challenges for implementing such a VLC message broadcast protocol are: 1) the imperfect synchronization among receivers and the transmitter; 2) the receivers' arbitrary arrival times; and 3) the diversity of receivers' smartphones (e.g., location, capability, and frame-rates). In this paper, we propose a new modulation scheme and design link-layer protocols for improving the network data rate. We carefully design and implement our protocol, Martian, which allows smooth communication from the LED lights to a group of smartphone embedded cameras. Across several phone models, Martian can achieve data rate of about 1.6 kb/s even with NLOS -light. It also has a stable and small delay for broadcasting messages to the randomly arriving receivers. Haohua Du, Junze Han, Xuesi Jian, Taeho Jung, Cheng Bo, Yu Wang 0003, Xiang-Yang Li 0001 |
IEEE J. Sel. Areas Commun. | 4 |
| 2017 | Joint Route Selection and Update Scheduling for Low-Latency Update in SDNsabstractDue to flow dynamics, a software defined network (SDN) may need to frequently update its data plane so as to optimize various performance objectives, such as load balancing. Most previous solutions first determine a new route configuration based on the current flow status, and then update the forwarding paths of existing flows. However, due to slow update operations of Ternary Content Addressable Memory-based flow tables, unacceptable update delays may occur, especially in a large or frequently changed network. According to recent studies, most flows have short duration and the workload of the entire network will vary significantly after a long duration. As a result, the new route configuration may be no longer efficient for the workload after the update, if the update duration takes too long. In this paper, we address the real-time route update, which jointly considers the optimization of flow route selection in the control plane and update scheduling in the data plane. We formulate the delay-satisfied route update problem, and prove its NP-hardness. Two algorithms with bounded approximation factors are designed to solve this problem. We implement the proposed methods on our SDN test bed. The experimental results and extensive simulation results show that our method can reduce the route update delay by about 60% compared with previous route update methods while preserving a similar routing performance (with link load ratio increased less than 3%). Hongli Xu 0001, Zhuolong Yu, Xiang-Yang Li 0001, Liusheng Huang, Chen Qian 0001, Taeho Jung |
IEEE/ACM Trans. Netw. | 6 |
| 2017 | PIC: Enable Large-Scale Privacy Preserving Content-Based Image Search on CloudabstractMany cloud platforms emerge to meet urgent requirements for large-volume personal image store, sharing and search. Though most would agree that images contain rich sensitive information (e.g., people, location and event) and people's privacy concerns hinder their participation into untrusted services, today's cloud platforms provide little support for image privacy protection. Facing large-scale images from multiple users, it is extremely challenging for the cloud to maintain the index structure and schedule parallel computation without learning anything about the image content and indices. In this work, we introduce a novel system PIC: A Privacy-preserving Image search system on Cloud, which is a step towards feasible cloud services which provide secure content-based large-scale image search with fine-grained access control. Users can search on others' images if they are authorized by the image owners. Majority of the computationally intensive jobs are handled by the cloud, and a querier can now simply send the query and receive the result. Specially, to deal with massive images, we design our system suitable for distributed and parallel computation and introduce several optimizations to further expedite the search process. Our security analysis and prototype system evaluation results show that PIC successfully protects the image privacy at a low cost of computation and communication. Lan Zhang 0002, Taeho Jung, Kebin Liu 0001, Xiang-Yang Li 0001, Jiaxi Gu, Yunhao Liu 0001 |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2016 | Real-time update with joint optimization of route selection and update scheduling for SDNsabstractDue to flow dynamics, a software defined network (SDN) may need to frequently update its data plane so as to optimize various performance objectives, such as load balancing. Most previous solutions first determine a new route configuration based on the current flow status, and then update the forwarding paths of existing flows. However, due to slow update operations of Ternary Content Addressable Memory (TCAM) based flow tables, unacceptable update delays may occur, especially in a large or frequently changed network. According to recent studies, most flows have short duration and the workload of the entire network may vary after a long duration. As a result, the new route configuration may be no longer efficient for the workload after the update, if the update duration takes too long. In this paper, we address the real-time route update, which jointly considers the optimization of flow route selection in the control plane and update scheduling in the data plane. We formulate the delay-satisfied route update (DSRU) problem, and prove its NP-Hardness. Two algorithms with bounded approximation factors are designed to solve this problem. We implement the proposed methods on our SDN testbed. The experimental results and extensive simulation results show that our method can reduce the route update delay by about 60% compared with previous route update methods while preserving a similar routing performance (with link load ratio increased less than 3%). Hongli Xu 0001, Zhuolong Yu, Xiang-Yang Li 0001, Chen Qian 0001, Liusheng Huang, Taeho Jung |
ICNP | 6 |
| 2016 | Graph-based privacy-preserving data publicationabstractWe propose a graph-based framework for privacy preserving data publication, which is a systematic abstraction of existing anonymity approaches and privacy criteria. Graph is explored for dataset representation, background knowledge specification, anonymity operation design, as well as attack inferring analysis. The framework is designed to accommodate various datasets including social networks, relational tables, temporal and spatial sequences, and even possible unknown data models. The privacy and utility measurements of the anonymity datasets are also quantified in terms of graph features. Our experiments show that the framework is capable of facilitating privacy protection by different anonymity approaches for various datasets with desirable performance. Xiang-Yang Li 0001, Chunhong Zhang, Taeho Jung, Jianwei Qian |
INFOCOM | 3 |
| 2016 | User-Demand-Oriented Privacy-Preservation in Video DeliveringabstractThis paper presents a framework for privacy-preserving video delivery system to fulfill users' privacy demands. The proposed framework leverages the inference channels in sensitive behavior prediction and object tracking in a video surveillance system for the sequence privacy protection. For such a goal, we need to capture different pieces of evidence which are used to infer the identity. The temporal, spatial and context features are extracted from the surveillance video as the observations to perceive the privacy demands and their correlations. Taking advantage of quantifying various evidence and utility, we let users subscribe videos with a viewer-dependent pattern. We implement a prototype system for off-line and on-line requirements in two typical monitoring scenarios to construct extensive experiments. The evaluation results show that our system can efficiently satisfy users' privacy demands while saving over 25% more video information compared to traditional video privacy protection schemes. Haohua Du, Taeho Jung, Xuesi Jian, Yiqing Hu, Jiahui Hou, Xiang-Yang Li 0001 |
MSN | 2 |
| 2016 | Ensuring Semantic Validity in Privacy-Preserving Aggregate StatisticsabstractAggregate statistics are becoming increasingly commonplace for mobile sensing applications which crowdsources data from individual users. In order to relieve user's concerns for privacy leakage, privacy preserving mechanisms have to be applied to enable the aggregator to compute aggregate statistics without learning each individual data. Although the aggregator will not know the value of the data, it is necessary to ensure the (semantic) validity of the data contributed by users. In this work, we design a privacy-preserving protocol for an aggregator to compute corrected aggregated statistics over users' data that can both preserve user's privacy and verify the semantic validity of the data. We evaluated our protocol on real-world dataset and demonstrated the efficiency of our protocol. Junze Han, Taeho Jung, Xiang-Yang Li 0001, Lili Du |
MSN | 2 |
| 2016 | Privacy Inference on Knowledge Graphs: Hardness and ApproximationabstractThe rapid information propagation facilitates our work and life without precedent in history, but it has tremendously exaggerated the risk and consequences of privacy invasion. Today's attackers are becoming more and more powerful in gathering personal information from many sources and mining these data to further uncover users' privacy. A great number of previous works have shown that, with adequate background knowledge, attackers are even able to infer sensitive information that is not revealed to anyone malicious before. In this paper, we model the attacker's knowledge using a knowledge graph and formally define the privacy inference problem. We show its #P-hardness and design an approximation algorithm to perform privacy inference in an iterative fashion, which also reflects real-life network evolution. The simulations on two data sets demonstrate the feasibility and efficacy of privacy inference using knowledge graphs. Jianwei Qian, Shaojie Tang 0001, Huiqi Liu, Taeho Jung, Xiang-Yang Li 0001 |
MSN | 4 |
| 2016 | Rebuttal to "Comments on 'Control Cloud Data Access Privilege and Anonymity With Fully Anonymous Attribute-Based Encryption"'abstractMa et al. recently submitted a comment correspondence which points out a flaw in our paper (a sequel of our earlier paper published in the Proceedings of IEEE INFOCOM). The flaw led to the leakage of the system-wide master key; therefore, we improved our own scheme by addressing it. Taeho Jung, Xiang-Yang Li 0001, Zhiguo Wan, Meng Wan |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2016 | Real-Time Charging Station Recommendation System for Electric-Vehicle TaxisabstractElectric vehicle (EV) taxis have been introduced into the public transportation systems to increase EV market penetration. Different from regular taxis that can refuel in minutes, EV taxis' recharging cycles can be as long as one hour. Due to the long cycle, the bad decision on the charging station, i.e., choosing one without empty charging piles, may lead to a long waiting time of more than an hour in the worst case. Therefore, choosing the right charging station is very important to reduce the overall waiting time. Considering that the waiting time can be a nonnegligible portion to the total work hours, the decision will naturally affect the revenue of individual EV taxis. The current practice of a taxi driver is to choose a station heuristically without a global knowledge. However, the heuristical choice can be a bad one that leads to more waiting time. Such cases can be easily observed in current collected taxi data in Shenzhen, China. Our analysis shows that there exists a large room for improvement in the extra waiting time as large as 30 min/driver. In this paper, we provide a real-time charging station recommendation system for EV taxis via large-scale GPS data mining. By combining each EV taxi's historical recharging events and real-time GPS trajectories, the current operational state of each taxi is predicted. Based on this information, for an EV taxi requesting a recommendation, we can recommend a charging station that leads to the minimal total time before its recharging starts. Extensive experiments verified that our predicted time is relatively accurate and can reduce the cost time of EV taxis by 50% in Shenzhen. Taeho Jung, Yi Wang 0049, Fan Zhang 0019, Lai Tu, Cheng-Zhong Xu 0001, Chen Tian 0001, Xiang-Yang Li 0001 |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2015 | POP: Privacy-Preserving Outsourced Photo Sharing and Searching for Mobile DevicesabstractFacing a large number of personal photos and limited resource of mobile devices, cloud plays an important role in photo storing, sharing and searching. Meanwhile, some recent reputation damage and stalk events caused by photo leakage increase people's concern about photo privacy. Though most would agree that photo search function and privacy are both valuable, few cloud system supports both of them simultaneously. The center of such an ideal system is privacy-preserving outsourced image similarity measurement, which is extremely challenging when the cloud is untrusted and a high extra overhead is disliked. In this work, we introduce a framework POP, which enables privacy-seeking mobile device users to outsource burdensome photo sharing and searching safely to untrusted servers. Unauthorized parties, including the server, learn nothing about photos or search queries. This is achieved by our carefully designed architecture and novel non-interactive privacy-preserving protocols for image similarity computation. Our framework is compatible with the state-of-the-art image search techniques, and it requires few changes to existing cloud systems. For efficiency and good user experience, our framework allows users to define personalized private content by a simple check-box configuration and then enjoy the sharing and searching services as usual. All privacy protection modules are transparent to users. The evaluation of our prototype implementation with 31,772 real-life images shows little extra communication and computation overhead caused by our system. Lan Zhang 0002, Taeho Jung, Cihang Liu, Xiang-Yang Li 0001, Yunhao Liu 0001 |
ICDCS | 2 |
| 2015 | PIC: Enable Large-Scale Privacy Preserving Content-Based Image Search on CloudabstractMany cloud platforms emerge to meet urgent requirements for large-volume personal image store, sharing and search. Though most would agree that images contain rich sensitive information (e.g., People, location and event) and people's privacy concerns hinder their participation into untrusted services, today's cloud platforms provide little support for image privacy protection. Facing large-scale images from multiple users, it is extremely challenging for the cloud to maintain the index structure and schedule parallel computation without learning anything about the image content and indices. In this work, we introduce a novel system PIC: a Privacy-preserving Image search system on Cloud, which is a step towards feasible cloud services which provide secure content-based large-scale image search with fine-grained access control. Users can search on others' images if they are authorized by the image owners. Majority of the computationally intensive jobs are handled by the cloud, and a querier can now simply send the query and receive the result. Specially, to deal with massive images, we design our system suitable for distributed and parallel computation and introduce several optimizations to further expedite the search process. Our security analysis and prototype system evaluation results show that PIC successfully protects the image privacy at a low cost of computation and communication. Lan Zhang 0002, Taeho Jung, Puchun Feng, Kebin Liu 0001, Xiang-Yang Li 0001, Yunhao Liu 0001 |
ICPP | 2 |
| 2015 | Collusion-Tolerable Privacy-Preserving Sum and Product Calculation without Secure ChannelabstractMuch research has been conducted to securely outsource multiple parties' data aggregation to an untrusted aggregator without disclosing each individual's privately owned data, or to enable multiple parties to jointly aggregate their data while preserving privacy. However, those works either require secure pair-wise communication channels or suffer from high complexity. In this paper, we consider how an external aggregator or multiple parties can learn some algebraic statistics (e.g., sum, product) over participants' privately owned data while preserving the data privacy. We assume all channels are subject to eavesdropping attacks, and all the communications throughout the aggregation are open to others. We first propose several protocols that successfully guarantee data privacy under semi-honest model, and then present advanced protocols which tolerate up to k passive adversaries who do not try to tamper the computation. Under this weak assumption, we limit both the communication and computation complexity of each participant to a small constant. At the end, we present applications which solve several interesting problems via our protocols. Taeho Jung, Xiang-Yang Li 0001, Meng Wan |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2015 | Control Cloud Data Access Privilege and Anonymity With Fully Anonymous Attribute-Based EncryptionabstractCloud computing is a revolutionary computing paradigm, which enables flexible, on-demand, and low-cost usage of computing resources, but the data is outsourced to some cloud servers, and various privacy concerns emerge from it. Various schemes based on the attribute-based encryption have been proposed to secure the cloud storage. However, most work focuses on the data contents privacy and the access control, while less attention is paid to the privilege control and the identity privacy. In this paper, we present a semianonymous privilege control scheme AnonyControl to address not only the data privacy, but also the user identity privacy in existing access control schemes. AnonyControl decentralizes the central authority to limit the identity leakage and thus achieves semianonymity. Besides, it also generalizes the file access control to the privilege control, by which privileges of all operations on the cloud data can be managed in a fine-grained manner. Subsequently, we present the AnonyControl-F, which fully prevents the identity leakage and achieve the full anonymity. Our security analysis shows that both AnonyControl and AnonyControl-F are secure under the decisional bilinear Diffie-Hellman assumption, and our performance evaluation exhibits the feasibility of our schemes. Taeho Jung, Xiang-Yang Li 0001, Zhiguo Wan, Meng Wan |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2015 | Message in a Sealed Bottle: Privacy Preserving Friending in Mobile Social NetworksabstractMany proximity-based mobile social networks are developed to facilitate connections between any two people, or to help a user to find people with a matched profile within a certain distance. A challenging task in these applications is to protect the privacy of the participants’ profiles and communications. In this paper, we design novel mechanisms, when given a preference-profile submitted by a user, that search persons with matching-profile in decentralized mobile social networks. Meanwhile, our mechanisms establish a secure communication channel between the initiator and matching users at the time when a matching user is found. These techniques can also be applied to conduct privacy preserving keywords based search without any secure communication channel. Our analysis shows that our mechanism is privacy-preserving (no participants’ profile and the submitted preference-profile are exposed), verifiable (both the initiator and any unmatched user cannot cheat each other to pretend to be matched), and efficient in both communication and computation. Extensive evaluations using real social network data, and actual system implementation on smart phones show that our mechanisms are significantly more efficient than existing solutions. Lan Zhang 0002, Xiang-Yang Li 0001, Kebin Liu 0001, Taeho Jung, Yunhao Liu 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2014 | Achieving differential privacy of data disclosure in the smart gridabstractThe smart grid introduces new privacy implications to individuals and their family due to the fine-grained usage data collection. For example, smart metering data could reveal highly accurate real-time home appliance energy load, which may be used to infer the human activities inside the houses. One effective way to hide actual appliance loads from the outsiders is Battery-based Load Hiding (BLH), in which a battery is installed for each household and smartly controlled to store and supply power to the appliances. Even though such technique has been demonstrated useful and can prevent certain types of attacks, none of existing BLH works can provide probably privacy-preserving mechanisms. In this paper, we investigate the privacy of smart meters via differential privacy. We first analyze the current existing BLH methods and show that they cannot guarantee differential privacy in the BLH problem. We then propose a novel randomized BLH algorithm which successfully assures differential privacy, and further propose the Multitasking-BLH-Exp3 algorithm which adaptively updates the BLH algorithm based on the context and the constraints. Results from extensive simulations show the efficiency and effectiveness of the proposed method over existing BLH methods. Taeho Jung, Yu Wang 0003, Xiang-Yang Li 0001 |
INFOCOM | 2 |
| 2014 | Continuous user identification via touch and movement behavioral biometricsabstractWith the increased popularity of smartphones, various security threats and privacy leakages targeting them are discovered and investigated. In this work, we present SilentSense, a framework to authenticate users silently and transparently by exploiting dynamics mined from the user touch behavior biometrics and the micro-movement of the device caused by user's screen-touch actions. We build a “touch-based biometrics” model of the owner by extracting some principle features, and then verify whether the current user is the owner or guest/attacker. When using the smartphone, some unique operating dynamics of the user is detected and learnt by collecting the sensor data and touch events silently. When users are mobile, the micro-movement of mobile devices caused by touch is suppressed by that due to the large scale user-movement which will render the touch-based biometrics ineffective. To address this, we integrate a movement-based biometrics for each user with previous touch-based biometrics. We conduct extensive evaluations of our approaches on the Android smartphone, we show that the user identification accuracy is over 99%. Cheng Bo, Lan Zhang 0002, Taeho Jung, Junze Han, Xiang-Yang Li 0001, Yu Wang 0003 |
IPCCC | 3 |
| 2014 | Network agile preference-based prefetching for mobile devicesabstractFor mobile devices, communication via cellular networks consumes more energy than via WiFi networks, and suffers an expensive limited data plan. On the other hand, as the coverage and the density of WiFI networks are smaller than those of the cellular networks, users cannot purely rely on WiFi to access the Internet. In this work we present a behavior-aware and preference-based approach to prefetch news webpages for the user to visit in the near future, by exploiting the WiFi network connections to reduce the energy and monetary cost. We first design an efficient preference learning algorithm to keep track of the user's changing interests, and then by predicting the appearance and durations of the WiFi network connections, our prefetch approach optimizes when to prefetch to maximize the user experience while lowing the prefetch cost. Our prefetch approach also exploits the idle period of WiFi connections to reduce the tail-energy consumption. We implement our approach in iPhone and our extensive evaluations show that our system achieves about 60% hit ratio, saves about 50% cellular data usage, and reduces the energy cost by 7%. Junze Han, Xiang-Yang Li 0001, Taeho Jung, Ju-Min Zhao, Zenghua Zhao |
IPCCC | 3 |
| 2014 | It starts with iGaze: visual attention driven networking with smart glassesabstractIn this work, we explore a new networking mechanism with smart glasses, through which users can express their interest and connect to a target simply by a gaze. Doing this, we attempt to let wearable devices understand human attention and intention, and pair devices carried by users according to such attention and intention. To achieve this ambitious goal, we propose a proof-of-concept system iGaze, a visual attention driven networking suite: an iGaze glass (hardware), and a networking protocol VAN (software). Our glass, iGaze glass, is a low-cost head-mounted glass with a camera, orientation sensors, microphone and speakers, which are embedded with our software for visual attention capture and networking. A visual attention driven networking protocol (VAN) is carefully designed and implemented. In VAN, we design an energy efficient and highly accurate visual attention determination scheme using single camera to capture user's communication interest and a double-matching scheme based on visual direction detection and Doppler effect of acoustic signal to lock the target devices. Using our system, we conduct a series of trials for various application scenarios to demonstrate the effectiveness of our system. Lan Zhang 0002, Xiang-Yang Li 0001, Wenchao Huang 0001, Kebin Liu 0001, Shuwei Zong, Xuesi Jian, Puchun Feng, Taeho Jung, Yunhao Liu 0001 |
MobiCom | 8 |
| 2014 | Demo: visual attention driven networking with smart glassesabstractIn this demo, we propose a proof-of-concept networking system for smart glasses, through which users can express their interest and connect to a target simply by a gaze. Our system iGaze is a visual attention driven networking suite: an iGaze glass (hardware) and a networking protocol VAN (software). Our glass is a low-cost head-mounted glass with a camera, orientation sensors, microphone and speakers, which are embedded with our software for visual attention capture and networking. A visual attention driven networking protocol (VAN) is carefully designed and implemented. In VAN, we design an energy efficient and highly accurate visual attention determination scheme using single camera to capture user's communication interest and a double-matching scheme based on visual direction detection and Doppler effect of acoustic signal to lock the target devices. iGaze has separated and modularized hardware and software design. It can run on top of existing networking protocols, e.g., Wi-Fi. Lan Zhang 0002, Xiang-Yang Li 0001, Wenchao Huang 0001, Kebin Liu 0001, Shuwei Zong, Xuesi Jian, Puchun Feng, Taeho Jung, Yunhao Liu 0001 |
MobiCom | 8 |
| 2014 | Compressive sensing meets unreliable link: sparsest random scheduling for compressive data gathering in lossy WSNsabstractCompressive Sensing (CS) has been recognized as a promising technique to reduce and balance the transmission cost in wireless sensor networks (WSNs). Existing efforts mainly focus on applying CS to reliable WSNs, namely, each wireless link is 100% reliable. However, our experimental results show that traditional compressive data gathering (CDG) could result in arbitrarily bad recovery performance, when the wireless links are lossy. In this paper, we study the impact of packet loss on compressive data gathering and ways to improve its robustness using sparsest random scheduling (SRS). The key idea of our scheme is to treat each sampling value as one CS measurement, which helps us to reduce the impact of packet loss on the recovery accuracy. Our scheme also outperforms the tradition CDG in reliable WSNs in that our scheme has significantly lowered transmission cost. To achieve this, we present a sparsest measurement matrix where each row has only one nonzero element. More importantly, we propose a representation basis to sparsify the gathering data, and prove that our measurement matrix satisfies the restricted isometric property (RIP) with high probability. Extensive experimental results show our scheme can recover the data accurately with packet loss ratio up to $15\%$, while traditional CDG can hardly recover the data under similar or even better conditions. Xuangou Wu, Panlong Yang, Taeho Jung, Yan Xiong 0001 |
MobiHoc | 3 |
| 2014 | Predicting the influencers on wireless subscriber churnabstractWireless carriers have various churn models that are mainly based on profiling the customers and assigning churn probabilities to them. Profiling is usually limited to their individual data, such as their subscription history, demographics, usage, etc. However, our analysis of a major wireless carrier data shows that such churn prediction methods do not fully model wireless subscriber churn, and that the subscribers can be influenced by other subscribers' churn in their social network. We propose a novel method to identify `churn influencers', whose influence makes their social contacts churn subsequently. To build our model, we scored the subscribers' influence level in a way that can take current churn models into account. We further used large scale call records to identify social network and communication features that abstract the strong influencers. Using real world churn data, we trained classification tools to classify high influencers with up to ninety nine percent precision. Sara Gatmir-Motahari, Taeho Jung, Hui Zang, Krishna Janakiraman, Xiang-Yang Li 0001, Kevin Soo Hoo |
WCNC | 2 |
| 2013 | Privacy preserving cloud data access with multi-authoritiesabstractCloud computing is a revolutionary computing paradigm which enables flexible, on-demand and low-cost usage of computing resources. Those advantages, ironically, are the causes of security and privacy problems, which emerge because the data owned by different users are stored in some cloud servers instead of under their own control. To deal with security problems, various schemes based on the Attribute-Based Encryption have been proposed recently. However, the privacy problem of cloud computing is yet to be solved. This paper presents an anonymous privilege control scheme AnonyControl to address not only the data privacy problem in a cloud storage, but also the user identity privacy issues in existing access control schemes. By using multiple authorities in cloud computing system, our proposed scheme achieves anonymous cloud data access and fine-grained privilege control. Our security proof and performance analysis shows that AnonyControl is both secure and efficient for cloud computing environment. Taeho Jung, Xiang-Yang Li 0001, Zhiguo Wan, Meng Wan |
INFOCOM | 1 |
| 2013 | Privacy-preserving data aggregation without secure channel: Multivariate polynomial evaluationabstractMuch research has been conducted to securely outsource multiple parties' data aggregation to an untrusted aggregator without disclosing each individual's privately owned data, or to enable multiple parties to jointly aggregate their data while preserving privacy. However, those works either require secure pair-wise communication channels or suffer from high complexity. In this paper, we consider how an external aggregator or multiple parties can learn some algebraic statistics (e.g., sum, product) over participants' privately owned data while preserving the data privacy. We assume all channels are subject to eavesdropping attacks, and all the communications throughout the aggregation are open to others. We propose several protocols that successfully guarantee data privacy under this weak assumption while limiting both the communication and computation complexity of each participant to a small constant. Taeho Jung, Xufei Mao, Xiang-Yang Li 0001, Shaojie Tang 0001, Wei Gong 0001, Lan Zhang 0002 |
INFOCOM | 1 |
| 2013 | Search me if you can: Privacy-preserving location query serviceabstractLocation-Based Service (LBS) becomes increasingly popular with the dramatic growth of smartphones and social network services (SNS), and its context-rich functionalities attract considerable users. Many LBS providers use users' location information to offer them convenience and useful functions. However, the LBS could greatly breach personal privacy because location itself contains much information. Hence, preserving location privacy while achieving utility from it is still an challenging question now. This paper tackles this non-trivial challenge by designing a suite of novel fine-grained Privacy-preserving Location Query Protocol (PLQP). Our protocol allows different levels of location query on encrypted location information for different users, and it is efficient enough to be applied in mobile platforms. Xiang-Yang Li 0001, Taeho Jung |
INFOCOM | 2 |
| 2013 | Verifiable private multi-party computation: Ranging and rankingabstractThe existing work on distributed secure multi-party computation, e.g., set operations, dot product, ranking, focus on the privacy protection aspects, while the verifiability of user inputs and outcomes are neglected. Most of the existing works assume that the involved parties will follow the protocol honestly. In practice, a malicious adversary can easily forge his/her input values to achieve incorrect outcomes or simply lie about the computation results to cheat other parities. In this work, we focus on the problem of verifiable privacy preserving multiparty computation. We thoroughly analyze the attacks on existing privacy preserving multi-party computation approaches and design a series of protocols for dot product, ranging and ranking, which are proved to be privacy preserving and verifiable. We implement our protocols on laptops and mobile phones. The results show that our verifiable private computation protocols are efficient both in computation and communication. Lan Zhang 0002, Xiang-Yang Li 0001, Yunhao Liu 0001, Taeho Jung |
INFOCOM | 4 |
| 2013 | SmartLoc: push the limit of the inertial sensor based metropolitan localization using smartphoneabstractWe present SmartLoc, a localization system to estimate the location and the traveling distance by leveraging the lower-power inertial sensors embedded in smartphones as a supplementary to GPS. To minimize the negative impact of sensor noises, SmartLoc exploits the intermittent strong GPS signals and uses the linear regression to build a prediction model which is based on the trace estimated from inertial sensors and the one computed from the GPS. Furthermore, we utilize landmarks (e.g., bridge, traffic lights) detected automatically and special driving patterns (e.g., turning, uphill, and downhill) from inertial sensory data to improve the localization accuracy when the GPS signal is weak. Our evaluations of SmartLoc in the city demonstrates its technique viability and significant localization accuracy improvement compared with GPS and other approaches: the error is approximately 20m for 90% of time while the known mean error of GPS is 42.22m. Cheng Bo, Xiang-Yang Li 0001, Taeho Jung, Xufei Mao, Yue Tao, Lan Yao |
MobiCom | 3 |
| 2012 | Closing the gap in the multicast capacity of hybrid wireless networksabstractWe study the multicast capacity of a random wireless network consisting of n randomly placed ordinary wireless nodes and m regularly placed base stations in a square region, known as a hybrid network. All ordinary wireless nodes have the uniform transmission range r and uniform interference range R=θ(r) and they can transmit/receive at Wa-bps. Each base station can communicate with adjacent base stations directly with a data rate WB-bps and the data transmission rate between a base station and a wireless node is assumed to be Wc-bps. Assume that there is a random set of ns ordinary wireless nodes that will serve as the source nodes of ns multicast flows (each has randomly selected k-1 receivers). Each flow will have data rate λi bps. We found that the minimum per-flow multicast capacity min n s over i = 1 λi for hybrid networks has three regimes, and for each regime we derive matching asymptotic upper and lower bounds. Thus it closes the gap of previous results in the literature. Shaojie Tang 0001, Xufei Mao, Taeho Jung, Junze Han, Xiang-Yang Li 0001, Boliu Xu |
MobiHoc | 3 |