Ke Gu 0002

dblp:13/9079-2 · DBLP profile ↗
← Back
46ranked-venue papers
22as first author
35since 2021 · last 2026
0000-0002-0793-5218ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 15 · 8 first-author · 11 since 2021Computer networks · 9 · 6 first-author · 8 since 2021Systems, architecture and hardware · 7 · 2 first-author · 7 since 2021Security and privacy · 6 · 2 first-author · 5 since 2021Artificial intelligence and machine learning · 5 · 2 first-author · 3 since 2021Theory of computation · 2 · 2 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Two-Dimensional Privacy-Preserving Federated Learning Scheme Against Poisoning Attacks
Ke Gu 0002, Wenwu Zhao, Jingjing Tan, Xiong Li 0002, Weijia Jia 0001
IEEE Trans. Dependable Secur. Comput.1
2026 A Verifiable Federated Learning Scheme With Privacy-Preserving in MCS
abstract
The popularity of edge smart devices and the explosive growth of generated data have driven the development of mobile crowd sensing (MCS). Also, federated learning (FL), as a new paradigm of privacy-preserving distributed machine learning, integrates with MCS to offer a novel approach for processing large-scale edge device data. However, it also brings about many security risks. In this paper, we propose a verifiable federated learning scheme with privacy-preserving for mobile crowd sensing. In our federated learning scheme, the double-layer random mask partition method combined with homomorphic encryption is constructed to protect the local gradients and enhance system security (strong anti-collusion ability) based on the multi-cluster structure of federated learning. Also, a sampling verification mechanism is proposed to allow the mobile sensing clients to quickly and efficiently verify the correctness of their received gradient aggregation results. Further, a dropout handling mechanism is constructed to improve the robustness of mobile crowd sensing-based federated learning. Related experimental results demonstrate that our verifiable federated learning scheme is effective and efficient in mobile crowd sensing environments.
Ke Gu 0002, Jiaqi Lei, Jingjing Tan, Xiong Li 0002
IEEE Trans. Netw. Serv. Manag.1
2025 NSshard: Low-Cross-Shard Sharding via Account Partitioning for Blockchain-Based IoT
abstract
The Internet of Things (IoT) links the physical world to computing systems, and blockchain presents an opportunity to address the issues of weak interoperability and security flaws within IoT. However, blockchain faces the challenge of low throughput and scalability. Sharding is a promising solution, but it divides the blockchain into multiple committees, making the attack cost of malicious nodes lower. Sharding also leads to a large number of cross-committee transactions, which degrades the system’s performance. In this article, we propose the NSshard sharding framework that provides secure and low-cross-committee scaling. NSshard consists of network sharding and state sharding. We first propose a reputation score-based network sharding, which assigns each node a reputation score to reward its honest verification of transactions and penalizes its malicious behavior. This network sharding uses a random but balanced distribution of reputation scores, thereby decreasing the risk of collusion. We also propose a graph-based account partitioning scheme for state partitioning. To reduce the amount of cross-committee transactions, the scheme uses an undirected weighted graph to depict accounts and transactions. We design two algorithms based on edge splitting and overlapping community discovery, respectively. We also propose a dynamic sharding method to handle new transactions. We conduct extensive experiments to evaluate the efficiency of the proposed framework based on Ethereum transaction data. The experimental results show that our proposed framework can reduce the number of cross-committee transactions by 34.8% at 128 committees compared to the Metis algorithm.
Bo Yin 0004, Qianwen Xie, Ke Gu 0002
IEEE Internet Things J.4
2025 Overlapping community-based malicious user detection scheme in social networks
Ke Gu 0002, Deng Yang, Wenwu Zhao, Xiong Li 0002
Knowl. Based Syst.1
2025 Multi-Layer Task Offloading Scheme in Fog Computing-Based VANETs With Optimized Completion Delay
abstract
Due to the characteristics of high mobility, low latency and short connection, task offloading in vehicular ad-hoc networks (VANETs) is facing many issues. In this paper, we propose a multi-layer task offloading scheme in fog computing-based VANETs, whose task completion delay can be optimized to an approximate minimum by a dynamical task offloading process. In our proposed scheme, a vehicle movement model is constructed to predict the position of each vehicle in a short time. Then, the link reliability evaluation metrics are constructed based on the vehicular willingness, the degree of vehicle connection and the expected count of task transmission. Furthermore, an evaluation model of processing delay and resource quantity is established to further estimate the selection of offloaded vehicles according to node degree, resource degree, computation capacity and transmission capacity. Finally, the multi-layer task offloading scheme is proposed, where we build an optimization model to minimize the task transmission and computation (completion) delays. Related experiments show our multi-layer task offloading scheme is efficient by optimizing task completion delay in fog computing-based VANETs.
Ke Gu 0002, Jingjing Tan, Long Cai
IEEE Trans. Intell. Transp. Syst.1
2025 Location-Aware Reliable Task Cooperative-Computation Scheme Under Fog Computing-Based IoVs
abstract
Although many existing schemes were proposed to solve the time delay, energy consumption and system architecture issues of task offloading in internet of vehicles (IoVs), few task offloading schemes focus on the location and mobility of vehicle nodes, the reliability of vehicle nodes and communication links, and the workload of fog servers. In this paper, we propose a location-aware reliable task cooperative-computation scheme under fog computing-based IoVs. In comparison to many existing vehicular cooperative computing schemes, our scheme introduces a dual-layer (single-hop and multi-hop) cooperative vehicle assessment and selection mechanism based on the location-aware principle (such as proximity). The proposed mechanism involves a detailed evaluation for cooperative vehicles from three perspectives: the reliability of cooperative vehicle nodes, the reliability of communication links, and the availability of idle computing resources. The comprehensive evaluation is designed to further facilitate the task allocation between the required tasks and the cooperative vehicles. Under the condition of meeting task requirements, the fog server can select closer (single-hop), more reliable vehicles with greater available computing resources to accomplish related sub-tasks for customer vehicles. Additionally, we further propose an enhanced Hungarian algorithm for task allocation among required sub-tasks and selected cooperative vehicles, which can effectively assign corresponding sub-tasks to suitable cooperative vehicles to reduce the fragmentation of vehicular resources and enhance the utilization of vehicular resources. Experimental results demonstrate the effectiveness of our location-aware reliable task cooperative-computation scheme under fog computing-based IoVs.
Ke Gu 0002, Zhenlin Liu, Weijia Jia 0001
IEEE Trans. Intell. Transp. Syst.1
2025 DATI-IDS: Domain Adaptation and Time-Series Imaging-Based Intrusion Detection System for Connected Autonomous Vehicles
abstract
With the advancement of artificial intelligence, automobiles are progressively transitioning from traditional mechanization to Connected Autonomous Vehicles (CAVs), significantly enhancing driving comfort and safety. As the standard communication protocol in CAVs, the Controller Area Network (CAN) remains vulnerable to attacks due to the lack of robust security mechanisms. While existing deep learning-based vehicle network intrusion detection systems can effectively identify known attacks, their ability to detect unknown attacks is limited due to the same data distribution in the source and target domain. To address this issue, we propose a domain adaptation and time-series imaging-based intrusion detection system (DATI-IDS) to detect known and unknown attacks, where the deep domain adaptation method is used to solve the source and target domain data distribution difference problem by optimizing the multiple kernel maximum mean discrepancy (MK-MMD) between the source domain and target domain images and the classification loss, and the time-series imaging method is used to capture temporal dependencies and improve efficiency by transforming the CAN ID sequence into a two-dimensional gramian angular summation field (GASF) image. The effectiveness of the proposed model is evaluated across nine distinct unknown attack scenarios using the Car-Hacking dataset and the survival analysis dataset. Comparative analysis with previous studies demonstrates superior performance, faster inference times, and reduced model complexity.
Jingjing Tan, Longfei Huang, Zhuoqun Xia, Ke Gu 0002, Wei Hao 0002, Kejun Long, Lingxuan Zeng
IEEE Trans. Intell. Transp. Syst.4
2025 Achieving Efficient and Privacy-Preserving Reverse Skyline Query Over Single Cloud
abstract
Reverse skyline query (RSQ) has been widely used in practice since it can pick out the data of interest to the query vector. To save storage resources and facilitate service provision, data owners usually outsource data to the cloud for RSQ services, which poses huge challenges to data security and privacy protection. Existing privacy-preserving RSQ schemes are either based on a two-cloud model or cannot fully protect privacy. To this end, we propose an efficient privacy-preserving reverse skyline query scheme over a single cloud (ePRSQ). Specifically, we first design a privacy-preserving inner product's sign determination scheme (PIPSD), which can determine whether the inner product of two vectors satisfies a specific relation with 0 without leaking the vectors’ information. Next, we propose a privacy-preserving reverse dominance checking scheme (PRDC) based on symmetric homomorphic encryption. Finally, we achieve ePRSQ based on PIPSD and PRDC. Security analysis shows that PIPSD and PRDC are both secure in the real/ideal world model, and ePRSQ can protect the security of the dataset, the privacy of query requests and query results. Extensive experiments show that ePRSQ is efficient. Specifically, for a 3-dimensional dataset of size 1000, the computational and communication overheads of ePRSQ for a query are 79.47 s and 0.0021 MB, respectively. The efficiency is improved by$3.78\times$(300.58 s) and$928.57\times$(1.95 MB) respectively compared with PPARS, and by$61.31\times$(4872.55 s) and$407309\times$(855.35 MB) respectively compared with OPPRS.
Yubo Peng, Xiong Li 0002, Ke Gu 0002, Jinjun Chen, Sajal K. Das 0001, Xiaosong Zhang 0001
IEEE Trans. Knowl. Data Eng.3
2025 Dual-Layered Model Protection Scheme Against Backdoor Attacks in Fog Computing-Based Federated Learning
abstract
With the growing popularity of federated learning, the security of training models against backdoor attacks has become a key challenge. Existing defense schemes often fail to address the complexity and diversity of such attacks so as to make training models vulnerable. In this paper, we propose a comprehensive dual-layered model protection scheme for fog computing-based federated learning framework. In our scheme, we first introduce a multi-metric defense mechanism deployed on fog servers to defend against malicious backdoor attacks from edge devices. The proposed defense mechanism employs multiple detection indicators to simultaneously evaluate and detect gradient and model training attributes, so that the abnormal local gradients are identified effectively. Further, we construct a second-layered defense scheme deployed on aggregation servers to regularly monitor the participation status of fog servers, whose purpose is to detect the distribution of uploaded gradients and eliminate malicious gradients from compromised fog servers. Additionally, we design an adaptive gradient adjustment method to mitigate the influence of deleting malicious gradients on the global model training process. Experimental results show that our dual-layered model protection scheme can perform well against three type of backdoor attacks (BadNet, Blended and WaNet).
Ke Gu 0002, Yiming Zuo 0004, Jingjing Tan, Bo Yin 0004, Xiong Li 0002
IEEE Trans. Netw. Serv. Manag.1
2025 Conditional Data-Sharing Privacy-Preserving Scheme in Blockchain-Based Social Internet of Vehicles
abstract
Social Internet of Vehicles (SIoVs) is an important information exchange platform to provide comprehensive traffic services by sharing vehicle-aware data. However, traditional data sharing methods can not provide the security of decentralized data sharing, making it possible for some malicious third parties to initiate dishonest behaviors. Additionally, the lack of access control for data sharing in SIoVs easily leads to unauthorized data sharing, thus user privacy is threatened and the source of false data is difficult to be traced. In this paper, we propose a conditional data-sharing privacy-preserving scheme for blockchain-based social internet of vehicles. In our scheme, a lightweight ledger-based blockchain system is designed, which combines with the ciphertext-policy attribute-based encryption method to realize anonymous one-to-many sharing of data with fine-grained access management. Also, a collaborative identity tracing method is constructed to trace malicious users who provide false data. Our scheme can effectively prevent second-hand data sharing and safeguard user privacy. Moreover, related experimental results validate the efficiency of our scheme.
Zhuoqun Xia, Jiahuan Man, Ke Gu 0002, Xiong Li 0002, Longfei Huang
IEEE Trans. Sustain. Comput.3
2024 Efficient and Verifiable Dynamic Skyline Queries in Blockchain Networks
abstract
Blockchain technology, which eliminates the need for intermediaries or centralized control, offers a decentralized and transparent platform for distributed data storage and exchange. With the widespread application of blockchain, the amount of data stored on blockchain is rapidly increasing. As data is considered a potential commercial resource, it is critical to provide secure data query services in blockchain. In this paper, we focus on the dynamic skyline query, which is important in multi-objective decision-making, and propose a query framework to support efficient query processing and the authentication of dynamic skyline results. The key technique is the authenticated data structure (ADS) called the Grid-based Verkle tree (GV tree). It combines the grid-based index and the vector commitment. The minimum bounding rectangle (MBR) is used as the search key of the ADS. By pruning cells of the grid that are dynamically dominated by a data point, the GV tree filters out non-skyline points in a batch, thereby promoting query efficiency. By using the vector commitment, the GV tree enables the verification that data points are not tampered with using a small-size verification object. We present schemes for GV tree-based dynamic skyline query processing and result verification. We conducted extensive experiments, and the experimental results showed promising results for the query framework.
Bo Yin 0004, Binyao Xu, Mariam Suleiman Silima, Ke Gu 0002
TrustCom5
2024 A Lightweight Privacy-Preserving and Verifiable Federated Learning-Based Protocol
abstract
Federated learning is a combination of distributed technology and machine learning technology, which does not require model training participants to share their original data, but only requires these participants to share their local models (or gradients) with a third party for aggregation. However, existing researches suggest that shared original models (or gradients) may also lead to privacy breaches for some participants. Some third parties performing aggregation tasks may also return falsified aggregation results to the participants. Thus, federated learning still faces many security challenges. In this paper, we propose a lightweight privacy-preserving verifiable federated learning-based protocol. Specifically, we protect the original model parameters by splitting the model and masking the split model with a mask, which effectively protects the original model parameters even in the case of collusion among multiple entities. In addition, we design a lightweight dropout handling scheme and a verification scheme to allow the participants to quickly verify the aggregation results from the server, which reduces the harmful effects of erroneous model updates on the entire federated learning system. Finally, we test our proposed scheme on several popular public datasets and compare it with several schemes. The experimental results show that our scheme can guarantee high accuracy and verification efficiency even while providing privacy-preserving and verifiable aggregation results.
Jiaqi Lei, Ke Gu 0002, Long Cai
TrustCom2
2024 Social Privacy-Preserving Modeling Based on Graphical Evolutionary Game and Infectious Disease Dissemination Dynamics
abstract
Although social network provides more convenience for people’s daily communication, it also faces the risk of personal privacy leakage. How to effectively evaluate and protect personal privacy has become a challenging issue in social networks. In this article, we propose a risk assessment-based privacy-preserving model for social networks, which is based on graphical evolutionary game theory and infectious disease dissemination dynamics model. In our scheme, a privacy risk assessment model is constructed to evaluate the importance degree of users’ privacy information and measure the leakage risk of users’ privacy information. Second, due to the heterogeneity of social networks, a graphical evolutionary game model of user privacy information forwarding behaviors is built to quantify and measure the strategy (or behavior) changes of different social users. Further, we construct a privacy-preserving information dissemination model, which is based on infectious disease dissemination model combined with graphical evolutionary game theory. Our risk assessment-based privacy-preserving model is to accurately characterize the dissemination of privacy information and reduce the transmission of privacy information, so as to protect social users’ privacy information. Related experimental results show the effectiveness of our privacy-preserving model by adjusting the payoff of social users.
Ke Gu 0002, CaoQianJin Li
IEEE Trans. Comput. Soc. Syst.1
2024 A Robust Privacy-Preserving Data Aggregation Scheme for Edge-Supported IIoT
abstract
Edge-supported Industrial Internet of Things (IIoT) has received remarkable attention recently since edge computing can not only reduce bandwidth consumption but also decrease the response time of industrial systems. However, the sensed data in the industrial environment is considered private. Thus, the data cannot be directly aggregated at the server due to privacy leakage. Although several privacy-preserving-aggregated schemes have been proposed, their security goals are not strong enough. Besides, most schemes are inefficient for resource-constrained devices. Aiming at solving the abovementioned problems, this article proposes a robust privacy-preserving data aggregation scheme for edge-supported IIoT. Specifically, the scheme adopts the Paillier cryptosystem to protect the privacy of users. Additionally, it utilizes ECDSA signature to support batch verification of multiple signatures from different signers, which significantly improves efficiency. Security analysis shows that the proposed scheme not only guarantees the integrity of the data and mutual authentication among entities but also realizes differential privacy protection. Extensive experiments are conducted to compare our scheme with the related work. The results show that our method outperforms most of the compared schemes with respect to communication. Moreover, compared with the related work, our scheme reduces the computational cost by an average of 6.7%, 16.9%, and 27.8% in sensor, edge server, and control center sides, respectively.
Shuai Shang, Xiong Li 0002, Ke Gu 0002, Lei Li 0031, Xiaosong Zhang 0001, Pandi Vijayakumar
IEEE Trans. Ind. Informatics3
2024 Malicious Vehicle Detection Scheme Based on Spatio-Temporal Features of Traffic Flow Under Cloud-Fog Computing-Based IoVs
abstract
Internet of vehicles (IoVs) is an important information exchange platform for intelligent transportation systems (ITSs) to provide traffic services. However, the appearance of malicious vehicles in IoVs can damage the security and stability of ITSs, which may provide false traffic data to cause serious traffic accidents. Also, many existing cryptography-based malicious vehicle detection scheme can only be used to resist some external attacks, while some internal malicious vehicles are easy to use their legal identities to provide false traffic data for other honest vehicles. In this paper, we propose a malicious vehicle detection scheme based on spatio-temporal features of traffic flow under cloud-fog computing-based IoVs. In our scheme, a traffic subarea division method based on spatial correlation degrees of road intersections is proposed to divide the urban road network into multiple traffic subareas. Based on the divided traffic subareas, an improved subarea-based graph attention model is proposed to extract the spatial features of traffic flow by the fog server. Then a gated recurrent unit method with attention mechanism is constructed to extract the temporal features of traffic flow by the cloud server, and a short-term traffic flow prediction model is built on the extracted spatio-temporal features of traffic flow. Further, a reputation calculation mechanism is established to score each vehicle by the fog server according to the verification of the traffic data uploaded by the vehicle and the traffic data predicted by our constructed prediction model, which is used to judge whether the vehicle is malicious according to its reputation score. Related experimental results show our scheme is effective and efficient to detect malicious vehicles under cloud-fog computing-based IoVs.
Ke Gu 0002, Xin OuYang, Yi Wang 0094
IEEE Trans. Intell. Transp. Syst.1
2024 Blockchain-Based Data Deduplication and Distributed Audit for Shared Data in Cloud-Fog Computing-Based VANETs
abstract
With the extensive deployment of vehicular ad-hoc networks (VANETs), it becomes an inevitable choice to provide enhanced in-vehicle services for uploading a vast amount of shared vehicular data to cloud storage. However, there is still a lack of effective deduplication and audit methods for cloud-stored data in VANET scenarios. To address the securities of cloud-stored data in VANETs, we propose a blockchain-based data deduplication and distributed audit scheme for shared data under cloud-fog computing-based VANETs in this paper. In our scheme, we construct a distributed audit model for VANETs, where road side units (RSUs) are partitioned as multiple management areas. Each management area can solely make their consensus for data integrity verification to audit the cloud storage provider without depending on any third-party auditors (TPAs). Also, we establish a blockchain-based monitoring mechanism maintained by the fog servers to ensure the integrity of the uploading and auditing records and enable related entities within the system to verify corresponding audit results (or records). Furthermore, we propose a lightweight dual-verifier structure to adapt to resource-constrained VANET scenarios. Through our dual-verifier mechanism, our scheme can effectively resist proof-replay attacks. Related theoretical analysis and experimental results show our data deduplication and distributed audit scheme is efficient and effective for VANET scenarios.
Ke Gu 0002, Yi Wang 0094, Xiong Li 0002, Jianming Zhang 0003
IEEE Trans. Netw. Serv. Manag.1
2024 Dynamic Outsourced Data Audit Scheme for Merkle Hash Grid-Based Fog Storage With Privacy-Preserving
abstract
The security of fog computing has been researched and concerned with its development, where malicious attacks pose a greater threat to distributed data storage based on fog computing. Also, the rapid increasing on the number of terminal devices has raised the importance of fog computing-based distributed data storage. In response to this demand, it is essential to establish a secure and privacy-preserving distributed data auditing method that enables security protection of stored data and effective control over identities of auditors. In this paper, we propose a dynamic outsourced data audit scheme for Merkle hash grid-based fog storage with privacy-preserving, where fog servers are used to undertake partial outsourced computation and data storage. Our scheme can provide the function of privacy-preserving for outsourced data by blinding original stored data, and supports data owners to define their auditing access policies by the linear secret-sharing scheme to control the identities of auditors. Further, the construction of Merkle hash grid is used to improve the efficiency of dynamic data operations. Also, a server locating approach is proposed to enable the third-part auditor to identify specific malicious data fog servers within distributed data storage. Under the proposed security model, the security of our scheme can be proved, which can further provide collusion resistance and privacy-preserving for outsourced data. Additionally, both theoretical and experimental evaluations illustrate the efficiency of our proposed scheme.
Ke Gu 0002, Xingqiang Wang, Xiong Li 0002
IEEE Trans. Sustain. Comput.1
2023 Fed_ADBN: An efficient intrusion detection framework based on client selection in AMI network
abstract
Abstract Data transmission between smart meters and data center is facing network security threats in advanced metering infrastructure of smart grid. The traditional solution is to move the data to the data center to build a centralized attack detection model, or divide the collected data into several independent and identically distributed datasets to build a distributed attack detection model. However, the long‐distance transmission and the centralized storage of data not only increase the communication overhead and time overhead, but also increase the risk of being attacked, causing privacy disclosure during the process of building the model. In this paper, we propose an efficient intrusion detection framework Fed_ADBN based on federated attention deep belief network and client selection. Clients cooperate with the data center to jointly build a horizontal federated learning framework. Under the premise of protecting data security by keeping data on the clients, we design a client selection algorithm based on client computing power, communication quality and security risks, which can improve the operating efficiency of federated learning. We also deploy a deep belief neural network with attention mechanism in each client to accurately detect possible network attacks in AMI network in real time. Experimental results show that compared with state‐of‐the‐art methods, the proposed framework can not only maintain good detection accuracy but also protect privacy.
Zhuoqun Xia, Yaling Chen, Bo Yin 0004, Haolan Liang, Hongmei Zhou, Ke Gu 0002, Fei Yu 0009
Expert Syst. J. Knowl. Eng.6
2023 A traceable and revocable decentralized multi-authority privacy protection scheme for social metaverse
Shaobo Zhang 0001, Yuechao Wang, Qin Liu 0001, Ke Gu 0002, Guojun Wang 0001
J. Syst. Archit.5
2023 Adaptive Area-Based Traffic Congestion Control and Management Scheme Based on Fog Computing
abstract
How to globally construct the effective traffic congestion control and management method on large-scale urban road network is an important research challenge. Since an urban region can be divided into many areas to be managed, grid management has great potential to improve traffic management on large-scale urban road network. In this paper, we propose an adaptive area-based traffic congestion control and management scheme, which is based on fog computing-based internet of vehicles. In our proposed scheme, an urban region is divided to many traffic management areas. Based on the real-time dynamic traffic tightness degrees and the static correlation degrees between these divided management areas, we can obtain the complete real-time regional traffic correlations of these divided management areas. Further, when a traffic congestion occurs, the fog servers use the constructed measures to control the signal lights in real time and effectively guide the traffic flow through the cooperation between these divided management areas. The experimental results show our proposed scheme can effectively implement the road guidance and traffic light control to alleviate or eliminate traffic congestion when a traffic congestion occurs.
Ke Gu 0002, Jieyu Hu, Weijia Jia 0001
IEEE Trans. Intell. Transp. Syst.1
2023 An Identity-Based Data Integrity Auditing Scheme for Cloud-Based Maritime Transportation Systems
abstract
With the development of Internet of Things (IoT)-enabled Maritime Transportation Systems (MTS), massive data generated in the system not only requires to be stored reliably and cheaply, but also needs to be analyzed timely. The Cloud-based Maritime Transportation Systems (CMTS) allow users to upload the data without worrying about the price, capacity, location and so on. However, CMTS also brings some security issues, where the integrity protection of outsourced data is one of the most important issues since it is crucial for the safety, reliability and efficiency of sea lanes. To solve this problem, we propose an identity-based dynamic data integrity auditing scheme for CMTS. Our scheme decreases the burden of key management and improves the auditing efficiency by batch auditing. Besides, our scheme also supports dynamic operations on the outsourced data for CMTS. The security analysis shows that our scheme can ensure the feature of storage correctness and resist common attacks. In addition, the performance comparison results with other related schemes show that our scheme not only has the lowest computational cost on all entities, but also greatly reduces the communication overhead of the auditing phase. Therefore, our scheme is very suitable for data integrity verification in CMTS.
Xiong Li 0002, Shuai Shang, Shanpeng Liu, Ke Gu 0002, Mian Ahmad Jan, Xiaosong Zhang 0001, Fazlullah Khan
IEEE Trans. Intell. Transp. Syst.4
2023 Dual Attribute-Based Auditing Scheme for Fog Computing-Based Data Dynamic Storage With Distributed Collaborative Verification
abstract
Compared with cloud computing-based data storage, distributed data storage in fog computing is more vulnerable to malicious attacks. So, it is very necessary to provide a secure distributed auditing mechanism with protecting the identity privacy of data owners and controlling the identities of auditors under fog computing-based data storage. In this paper, we propose a dual attribute-based auditing scheme for fog computing-based data dynamic storage. Our auditing scheme can protect the identity privacy of data owners, and provide an attribute-based access control for corresponding audits with a distributed collaborative verification between related fog servers. In our scheme, a data owner can securely upload his divided and blinded file blocks with corresponding block authenticators (related with his attribute set) to related fog servers. To prevent malicious auditors from consuming system resources by abusing audit requests, the data owner can provide an attribute-based access control for corresponding audits, where the data owner specifies the attribute set of corresponding auditors who have the right to check the integrity of related data. Further, a distributed collaborative verification mechanism between related fog servers is constructed to reduce the disadvantages of centralized verification, where the Shamir’s secret-sharing method is used to decompose the picked blinding factor as the shared sub-secrets sent to each fog server respectively. Compared with cloud computing-based data storage, our collaborative verification mechanism can implement distributed auditing consent of stored data between multiple fog servers. Our auditing scheme can further audit out specific suspicious fog servers. Additionally, we provide a dynamic data operation mechanism to efficiently support the updating of users’ data under fog computing-based data storage. Furthermore, related theoretical analysis and experimental evaluation show our scheme is secure and efficient.
Ke Gu 0002, Wenbin Zhang 0002, Xingqiang Wang, Xiong Li 0002, Weijia Jia 0001
IEEE Trans. Netw. Serv. Manag.1
2023 Privacy-Preserving Electricity Data Classification Scheme Based on CNN Model With Fully Homomorphism
abstract
Data classification of users’ electricity consumption provides an in-depth analysis for users’ electricity consumption status, which plays a vital role in the management and distribution of electric energy. So, some data classification methods have been proposed to solve the classification problem of electricity consumption data. However, plaintext-based data classification may bring about the privacy leakage of electricity consumption data. In this paper, we propose a privacy-preserving classification scheme for electricity consumption data under fog computing-based smart metering system, which is based on convolutional neural network (CNN) model with fully homomorphic method (CKKS). The target of our proposed scheme is to solve the leakage problem of private electricity consumption data during the classification procedure. In our scheme, an improved K-means-based labeling algorithm is constructed to process historical electricity consumption data, which is used as the sample data to train the CNN classification model by cloud server. Also, the fog nodes are only permitted to obtain the related ciphertext parameters of the trained CNN model, and perform the classification of ciphertext-based electricity consumption data generated by fully homomorphic method. Based on the classical testing data, the experimental results show that our proposed classification scheme can provide the high classification accuracy of electricity data while protecting the privacy of electricity data.
Zhuoqun Xia, Dan Yin, Ke Gu 0002, Xiong Li 0002
IEEE Trans. Sustain. Comput.3
2022 CECAS: A cloud-edge collaboration authentication scheme based on V2G short randomizable signature
abstract
With the growing demand for energy-efficient and environmentally friendly transportation solutions, electric vehicles have become an emerging mode of transportation. However, a large number of security issues have affected its further development. Existing schemes use identity-based restricted partial blind signature technique to implement authentication schemes with high computational cost. Local aggregators suffer from tampering with transaction records. Malicious EVs continuously listen to power transactions to infer the lifestyle of EV users. This scheme designs a cloud-edge collaboration authentication scheme based on V2G short randomizable signature. Specifically, privacy during EV power transactions is guaranteed using lightweight cryptographic primitives. EVs evaluate the reputation value of local aggregators through additive secret sharing. Cloud computing center and edge servers are capable of collaborative authentication and collaborative tracking. This scheme can improve the authentication efficiency of V2G network.
Zhuoqun Xia, Hongrui Li, Ke Gu 0002
TrustCom3
2022 A novel authentication scheme for edge computing-enabled Internet of Vehicles providing anonymity and identity tracing with drone-assistance
Fan Wu 0003, Xiong Li 0002, Xiangyang Luo 0001, Ke Gu 0002
J. Syst. Archit.4
2022 Malicious Node Detection Scheme Based on Correlation of Data and Network Topology in Fog Computing-Based VANETs
abstract
In vehicle ad hoc networks (VANETs), if a legal vehicle node becomes malicious, then it is more likely to tamper with transferred data or provide false data easily. Because the malicious node is a valid internal user in VANETs, its behavior is difficult to be detected only through some cryptographic methods. Then the behavior may cause many serious traffic accidents. Based on the available (unencrypted) data only, how to detect out the internal malicious vehicle nodes by some lightweight methods needs to be researched in VANETs. Additionally, fog computing seamlessly integrates heterogeneous computing resources widely distributed in edge networks and then provides stronger computing services for users. Therefore, in this article, we propose a malicious node detection scheme in fog computing-based VANETs, where the fog server uses the reputation calculation to score each suspicious node based on the correlation of acquired data and network topology. In our proposed scheme, we build a reputation mechanism to score each suspicious node according to the correlation between outlier detection of acquired data and influence of nodes. Based on our proposed experiments, our proposed scheme can efficiently and effectively detect out malicious vehicle nodes so that fog server can acquire more true data.
Ke Gu 0002, Xinying Dong, Weijia Jia 0001
IEEE Trans. Cloud Comput.1
2022 Two-Dimensional Behavior-Marker-Based Data Forwarding Incentive Scheme for Fog-Computing-Based SIoVs
abstract
In social Internet of Vehicles (SIoVs), vehicles can usually act as data-relaying nodes to forward data. However, vehicle nodes often show their personal and social selfishness in data forwarding (namely vehicle nodes are not willing to forward data), whose selfishness greatly influences the delivery ratio of data forwarding. In this article, we propose a 2-D behavior-marker-based data-forwarding incentive scheme to motivate vehicle nodes to participate in data forwarding in fog-computing-based SIoVs. First, we design a 2-D behavior marker mechanism, which can be used to completely evaluate vehicle nodes. Second, we construct a currency credit-based data-forwarding incentive strategy based on the 2-D marker and the social attributes of vehicle nodes, which is used to deal with vehicular normal behavior, vehicular selfish behavior, and vehicular malicious behavior. Compared with other related schemes, our proposed scheme can completely evaluate the behaviors of vehicle nodes and can further promote the cooperation of data-forwarding between selfish nodes. The experimental results show that our scheme is more efficient and stable in data forwarding in fog-computing-based SIoVs.
Zhuoqun Xia, Xiaoxiao Mao, Ke Gu 0002, Weijia Jia 0001
IEEE Trans. Comput. Soc. Syst.3
2022 An Efficient Privacy-Preserving Public Auditing Protocol for Cloud-Based Medical Storage System
abstract
The booming Internet of Things makes smart healthcare a reality, while cloud-based medical storage systems solve the problems of large-scale storage and real-time access of medical data. The integrity of medical data outsourced in cloud-based medical storage systems has become crucial since only complete data can make a correct diagnosis, and public auditing protocol is a key technique to solve this problem. To guarantee the integrity of medical data and reduce the burden of the data owner, we propose an efficient privacy-preserving public auditing protocol for the cloud-based medical storage systems, which supports the functions of batch auditing and dynamic update of data. Detailed security analysis shows that our protocol is secure under the defined security model. In addition, we have conducted extensive performance evaluations, and the results indicate that our protocol not only remarkably reduces the computational costs of both the data owner and the third-party auditor (TPA), but also significantly improves the communication efficiency between the TPA and the cloud server. Specifically, compared with other related work, the computational cost of the TPA in our protocol is negligible and the data owner saves more than 2/3 of computational cost. In addition, as the number of challenged blocks increases, our protocol saves nearly 90% of communication overhead between the TPA and the cloud server.
Xiong Li 0002, Shanpeng Liu, Rongxing Lu, Muhammad Khurram Khan, Ke Gu 0002, Xiaosong Zhang 0001
IEEE J. Biomed. Health Informatics5
2022 Multi-Fogs-Based Traceable Privacy-Preserving Scheme for Vehicular Identity in Internet of Vehicles
abstract
Internet of Vehicles (IoV) is a variant of Vehicular Ad-Hoc Network (VANET), it is being developed as an important communication way between vehicles. However, when some traffic messages are collected in IoV, these messages are usually linked to specific identifiable information. Therefore, there exists the privacy-preserving problem of vehicular identities in IoV. On the other hand, if the private information of vehicles is fully protected in IoV, then the true vehicular identities cannot be determined because the transferred messages are not related with the specific information of vehicles. Then it will also lead to more security problems in IoV. Additionally, fog computing seamlessly integrates heterogeneous computing resources widely distributed in edge networks and then provides stronger computing services for users. Therefore, in this paper we propose a decentralized traceable privacy-preserving scheme for vehicular identity in fog computing-based IoV, where our scheme uses multiple fog servers to trace the specific identity and most likely trajectory of a vehicle by the collected data under certain conditions. In our scheme, the true identity of a vehicle is hidden to some related parameters generated by the certificate authority; further the secret sharing scheme is used to hide and trace the true identity of a vehicle. We construct a voting mechanism to generate the most reliable fog server, which is able to calculate the true identity and corresponding trajectory of a vehicle by reconstructing the polynomial based on the secret sharing scheme. Additionally, we analyze that our scheme can satisfy the security requirements, and formally prove that the data collection procedure is secure under the real-or-random model. Also, the experimental results show our scheme is efficient in IoV.
Ke Gu 0002, Keming Wang, Xiong Li 0002, Weijia Jia 0001
IEEE Trans. Intell. Transp. Syst.1
2022 Self-Verifiable Attribute-Based Keyword Search Scheme for Distributed Data Storage in Fog Computing With Fast Decryption
abstract
Presently many searchable encryption schemes have been proposed for cloud and fog computing, which use fog nodes (or fog servers) to partly undertake some computational tasks. However, these related schemes still retain cloud servers to undertake most computational tasks, which result in large communication costs between edge devices and cloud servers. Therefore, in this paper we propose a self-verifiable attribute-based keyword search scheme for distributed data storage (SV-KSDS) in full fog computing, where each decryption operation on the data required by a user must meet the negotiated decryption rule between fog servers. Our SV-KSDS scheme first provides attribute-based distributed data storage among fog servers through the$(w, \sigma)$threshold secret-sharing scheme, where fog servers can provide self-verifiable keyword search and data decryption for terminal users. Compared with the data storage in cloud computing, our scheme extends it to the distributed structure while providing fine-grained access control for distributed data storage through attribute-based encryption. The access control policy of our scheme is constructed on linear secret-sharing scheme, whose security is reduced to the decisional bilinear Diffie-Hellman assumption against chosen-keyword attack and the decisional${q}$-parallel bilinear Diffie-Hellman assumption against chosen-plaintext attack in the standard model. Based on theoretical analysis and practical testing, our SV-KSDS scheme generates less computation and communication costs, which further unloads some computational tasks from terminal users to fog servers so as to reduce computing costs of terminal users.
Ke Gu 0002, Wenbin Zhang 0002, Xiong Li 0002, Weijia Jia 0001
IEEE Trans. Netw. Serv. Manag.1
2022 Dual-Mode Data Forwarding Scheme Based on Interest Tags for Fog Computing-Based SIoVs
abstract
Social Internet of vehicles (SIoVs) is a combination of vehicular ad-hoc networks (VANETs) and mobile social networks (MSNs). Although social relationships between vehicle nodes are more stable than location changes of vehicle nodes in SIoVs, there always are the problems of data forwarding optimization and adaptability for dynamic networks. In this paper, we propose a dual-mode data forwarding scheme based on interest tags for fog computing-based SIoVs. In the first data forwarding mode, the vehicle nodes calculate and use the cooperation degrees to select the next cooperative forwarding nodes until the data is forwarded to the destination node. In the second data forwarding mode, the RSUs assist the data forwarding of vehicle nodes based on the RSU ranking mechanism of interests, where the fog servers calculate the RSU ranking table of all the interests and the related RSU selects the top-${k}$RSUs to forward the data according to the RSU ranking table. The experimental results show that our proposed scheme is more efficient and stable than other related schemes by the comparisons of delivery ratio, overhead ratio and average hop count.
Zhuoqun Xia, Xiaoxiao Mao, Ke Gu 0002, Weijia Jia 0001
IEEE Trans. Netw. Serv. Manag.3
2022 Conditional Identity Privacy-preserving Authentication Scheme Based on Cooperation of Multiple Fog Servers under Fog Computing-based IoVs
abstract
Internet of vehicles (IoVs) is a variant of vehicular ad hoc network, which provides an efficient communication method for vehicles. However, some traffic messages usually include sensitive identity information, which is easy to bring about the leakage of vehicular identities during data communications. Further, if vehicular identities are fully protected, then it can lead to trusted authority cannot reveal the real identities of malicious vehicles, which incurs more security issues in IoVs. Therefore, in this article, we propose an efficient conditional identity privacy-preserving authentication scheme based on cooperation of multiple fog servers under fog computing-based IoVs, where fog servers are used to verify (authenticate) the legitimacy of vehicles without revealing their real identities. Further, an associated vehicular identity updating mechanism is constructed to solve the problem that some compromised fog servers may leak their stored verification information to pool real vehicular identities. Additionally, a malicious vehicular identity tracing mechanism is proposed to support related fog servers that receive signed false messages can trace the real identities of malicious vehicles. Compared with other related schemes, our scheme further improves its security. Experimental results show our scheme is efficient under fog computing-based IoVs.
Zhuoqun Xia, Lingxuan Zeng, Ke Gu 0002, Xiong Li 0002, Weijia Jia 0001
ACM Trans. Internet Techn.3
2021 Image super-resolution reconstruction based on feature map attention mechanism
Yuantao Chen, Linwu Liu, Volachith Phonevilay, Ke Gu 0002, Runlong Xia, Jingbo Xie, Qian Zhang 0079, Kai Yang 0010
Appl. Intell.4
2021 Effective charging identity authentication scheme based on fog computing in V2G networks
Zhuoqun Xia, Zhenwei Fang, Ke Gu 0002, Jin Wang 0001, Jingjing Tan
J. Inf. Secur. Appl.3
2021 Detection resource allocation scheme for two-layer cooperative IDSs in smart grids
Zhuoqun Xia, Jingjing Tan, Ke Gu 0002, Weijia Jia 0001
J. Parallel Distributed Comput.3
2020 Secure Computing Resource Allocation Framework For Open Fog Computing
abstract
Abstract Fog computing has become an emerging environment that provides data storage, computing and some other services on the edge of network. It not only can acquire data from terminal devices, but also can provide computing services to users by opening computing resources. Compared with cloud computing, fog devices can collaborate to provide users with powerful computing services through resource allocation. However, as many of fog devices are not monitored, there are some security problems. For example, since fog server processes and maintains user information, device information, task parameters and so on, fog server is easy to perform illegal resource allocation for extra benefits. In this paper, we propose a secure computing resource allocation framework for open fog computing. In our scheme, the fog server is responsible for processing computing requests and resource allocations, and the cloud audit center is responsible for auditing the behaviors of the fog servers and fog nodes. Based on the proposed security framework, our proposed scheme can resist the attack of single malicious node and the collusion attack of fog server and computing devices. Furthermore, the experiments show our proposed scheme is efficient. For example, when the number of initial idle service devices is 40, the rejection rate of allocated tasks is 10% and the total number of sub-tasks is changed from 150 to 200, the total allocation time of our scheme is only changed from 15 ms to 25 ms; additionally, when the task of 5000 order matrix multiplication is tested on 10 service devices, the total computing time of our scheme is $\sim$250 s, which is better than that of single computer (where single computer needs more than 1500 s). Therefore, our proposed scheme has obvious advantages when it faces some tasks that require more computational cost, such as complex scientific computing, distributed massive data query, distributed image processing and so on.
Jiafu Jiang, Linyu Tang, Ke Gu 0002, Weijia Jia 0001
Comput. J.3
2020 Resource Allocation Scheme for Community-Based Fog Computing Based on Reputation Mechanism
abstract
Fog computing needs to seamlessly integrate heterogeneous computing resources widely distributed in edge networks, and then, it can provide unified resources and services for users. However, due to a large number of fog nodes, there are still many security problems in the fog computing process. For example, when fog servers make resource allocation between users' tasks and fog nodes, some fog nodes can falsely claim that they have more resources than their actual ability, so as to get more task processing qualifications. Thus, it will greatly damage the interests of users and affect the quality of service. In this article, we propose a resource allocation scheme for community-based fog computing based on a reputation mechanism. When fog network provides computing services for users, we use a reputation mechanism to enable users to obtain reliable resources in fog computing. In our proposed scheme, a user first submits his/her task request to the community-based fog network, and then, the fog server makes a reliable resource allocation process based on multiple-layer communities and reputation calculation. Based on our experiments, our scheme enables users to obtain reliable resources and improves the service quality of computing resources in fog computing.
Ke Gu 0002, Linyu Tang, Jiafu Jiang, Weijia Jia 0001
IEEE Trans. Comput. Soc. Syst.1
2020 An Industrial Dynamic Skyline Based Similarity Joins For Multidimensional Big Data Applications
abstract
In the era of data deluge, data analysis has become a key task for many industrial applications, e.g., master data management, and data integration. In particular, similarity join is an important primitive operator to support data analysis, which is to find similar pairs based on similarity functions and thresholds. In this article, we first propose a new similarity join operation called the dynamic skyline join without having to specify any similarity function or similarity threshold, which measures the similarity through multicriteria optimization. The dynamic skyline join operator makes the similarity join more flexible to support different criteria in multidimensional space. However, it is nontrivial to achieve dynamic skyline joins as both join operations and dynamic skyline queries are computationally complex in the increasing volume of real-world data. Therefore, we further propose Grid-SkyJoin, a framework to enable efficient parallel dynamic skyline joins on a shared-nothing cluster. Specifically, we use a grid partitioning to facilitate the data filtering and grouping strategies to provide load balancing and reduce the number of replicas. We also propose a multilevel filtering scheme to prune away a large fraction of unpromising points that do not fit into join results without actual join operations. Extensive experiments using benchmark datasets demonstrate that our filtering scheme can greatly reduce the number of data points to be joined, and our approach is about two times faster compared with the straightforward method in average.
Bo Yin 0004, Xuetao Wei, Jin Wang 0001, Naixue Xiong, Ke Gu 0002
IEEE Trans. Ind. Informatics5
2020 Secure Data Query Framework for Cloud and Fog Computing
abstract
Fog computing is mainly used to process a large amount of data produced by terminal devices. As fog nodes are the closest acquirers to the terminal devices, the processed data may be tampered with or illegally captured by some malicious nodes while the data is transferred or aggregated. When some applications need to require real-time process with high security, cloud service may sample some data from fog service to check final results. In this paper, we propose a secure data query framework for cloud and fog computing. We use cloud service to check queried data from fog network when fog network provides queried data to users. In the framework, cloud server pre-designates some data aggregation topology trees to fog network, and then fog network may acquire related data from fog nodes according to one of the pre-designated data aggregation trees. Additionally, some fog nodes are assigned as sampled nodes that can feed back related data to cloud server. Based on the security requirements of fog computing, we analyze the security of our proposed framework. Our framework not only guarantees the reliability of required data but also effectively protects data against man-in-the-middle attack, single node attack and collusion attack of malicious users. Also, the experiments show our framework is effective and efficient.
Ke Gu 0002, Bo Yin 0004, Weijia Jia 0001
IEEE Trans. Netw. Serv. Manag.1
2019 Traceable attribute-based signature
Ke Gu 0002, Keming Wang
J. Inf. Secur. Appl.1
2019 Social community detection and message propagation scheme based on personal willingness in social network
Ke Gu 0002, LinYu Wang 0001, Bo Yin 0004
Soft Comput.1
2018 A cost-efficient framework for finding prospective customers based on reverse skyline queries
Bo Yin 0004, Ke Gu 0002, Xuetao Wei, Siwang Zhou, Yonghe Liu
Knowl. Based Syst.2
2017 Efficient and secure attribute-based signature for monotone predicates
Ke Gu 0002, Weijia Jia 0001, Guojun Wang 0001, Sheng Wen
Acta Informatica1
2017 Identity-Based Multi-Proxy Signature Scheme in the Standard Model
abstract
Multi-proxy signature is a variant of proxy signature, which allows that a delegator (original signer) may delegate his signing rights to many proxy signers. Comparing with proxy signatures, multi-proxy signatures can effectively prevent that some of proxy signers abuse signing rights. Also, with the rapid development of identity-based cryptography, identity-based multi-proxy signature (IBMPS) schemes have been proposed. Comparing with proxy signature based on public key cryptography, IBMPS can simplify key management and be used for more applications. Presently, many identity-based multi-proxy signature schemes have been proposed, but most of them are constructed in the random oracle model. Also, the existing security model for identity-based multi-proxy signature is not enough complete according to the Boldyreva et al.’s work. In this paper, we present a framework for IBMPS on n + 1 users ( n is the number of proxy signers participating in signing), and show a detailed security model for IBMPS. Under our framework, we present an identity-based multi-proxy signature scheme in the standard model. Comparing with other identity-based multi-proxy signature schemes, the proposed scheme has more complete security.
Ke Gu 0002, Weijia Jia 0001, Jianming Zhang 0003
Fundam. Informaticae1
2015 Efficient Identity-Based Proxy Signature in the Standard Model
abstract
Presently, many identity-based proxy signature (IBPS) schemes have been proposed, but most of them are constructed in the random oracle model. Also, the proposed security model for IBPS is not enough complete according to Boldyreva's work. Cao and Cao proposed an IBPS scheme in the standard model. However, their scheme is not secure because of not resisting the attack of delegator and requires more computation cost. In this paper, we present a framework for IBPS and show a detailed security model for IBPS. Under our framework, we present an efficient IBPS scheme in the standard model. Compared with other IBPS schemes, the proposed scheme has more complete security and is more efficient.
Ke Gu 0002, Weijia Jia 0001, Chunlin Jiang
Comput. J.1
2010 Optimization of AMR Speech Codec on ARMv5E Platform
abstract
This paper introduces AMR (Adaptive Multi Rate) codec algorithm and the basic characteristics of ARM architecture, and focus on the optimization methods of AMR algorithm based on ARM platform, making use of ARMv5E core hardware features. Firstly the CPU usage rate of AMR key functions are analyzed, then two methods including inline optimization and assembly optimization are discussed, finally optimization result is verified through experiment in smart phones. Experiments prove that the running speed of optimized code have been significantly increased in ARM core smart phones.
Chunlin Jiang, Lizhuo Zhang, Ke Gu 0002, Weijia Jia 0001
APSCC3