Haotian Chi

dblp:132/7795 · DBLP profile ↗
← Back
36ranked-venue papers
10as first author
26since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 25 · 4 first-author · 16 since 2021Security and privacy · 6 · 4 first-author · 5 since 2021Artificial intelligence and machine learning · 3 · 2 first-author · 3 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A framework for single-node failure protection in hybrid Software-Defined Networking
Haijun Geng, Zhixuan Guo, Haotian Chi, Runfa Zhang 0001
Comput. Networks4
2026 IoTAudVeri: Audio-Assisted Verification of Smart Home IoT Events Against Event-Targeted Attacks
Haotian Chi, Xiangyi Hao, Rong Zhang 0012, Haijun Geng
IEEE Internet Things J.1
2026 State transition difference prediction for deep reinforcement learning
Haotian Chi, Zhaogeng Liu, Xing Chen 0022, Bohao Qu, Jifeng Hu, Yuan Jiang 0007, Hechang Chen, Yi Chang 0001
Pattern Recognit.1
2025 TS-Net: Dual-Channel IoT Intrusion Detection with Temporal and Spatial Modeling
abstract
The rapid growth of the Internet of Things (IoT) has introduced significant security challenges, particularly in detecting intrusions within complex IoT networks. This paper presents TS-Net, a robust dual-channel model that combines temporal and spatial feature learning to enhance IoT intrusion detection. By partitioning network traffic into temporal and spatial features, TS-Net processes them through separate channels. The temporal channel utilizes Bidirectional Gated Recurrent Units (BiGRU) paired with a self-attention mechanism to capture dynamic sequential dependencies, while the spatial channel employs multi-scale dilated convolutions to extract patterns from varying spatial perspectives. These two channels are then fused to improve the model accuracy in detecting anomalous traffic. Experimental results on three publicly available datasets demonstrate that TS-Net outperforms existing intrusion detection models, achieving higher precision, recall, and F1-scores, demonstrating its effectiveness in addressing the unique security needs of IoT networks.
Haotian Chi, Haijun Geng, Xiaojiang Du, Yuede Ji
GLOBECOM1
2025 Blockchain-Enabled EHR Sharing Framework with Dual-Protection: Integrating Attribute-Based Encryption and Hierarchical Role Access Control
abstract
The global healthcare landscape has witnessed accelerated adoption of digital transformation initiatives, with electronic health records (EHRs) emerging as the cornerstone technology for modern medical data management. While EHR systems effectively consolidate patient information and improve clinical continuity, their predominant centralised architectures create data silos that impede cross-institutional interoperability and patient sovereignty over personal health data. In this paper, we propose a blockchain-enabled EHR sharing framework that integrates attribute-based encryption with hierarchical role-based access control (RBAC) mechanisms. Our dual-protection architecture combines 1) an attribute-oriented privacy preservation scheme that ensures data immutability and fine-grained access through cryptographic proofs, with 2) a multi-level role hierarchy system that enables efficient permission management among healthcare stakeholders. By establishing dynamic mappings between user attributes and institutional roles, we achieve secure yet flexible authorization processes without compromising system performance. Experimental evaluations demonstrate superior performance metrics in cryptographic operations and access verification latency, validating the practicality of the framework for real-world EHR exchange scenarios.
Shunrong Jiang, Chengcheng Zhang 0003, YuQi Zhang, Haotian Chi, Xiaojiang Du
GLOBECOM5
2025 FedU-KAN: Cloud-Enhanced Privacy-Preserving Federated Learning for Medical Image Segmentation Based on U-KAN
abstract
Machine learning is gradually transforming medical image segmentation. However, its accuracy often relies on large-scale medical datasets, while centralized data collection raises serious privacy concerns. To address this issue, federated learning (FL) enables collaborative model training without sharing raw data, thus effectively protecting patient privacy. Despite this advantage, commonly used segmentation models, such as U-Net and its variants, typically have large parameter sizes, making them inefficient for local training on FL clients. To overcome this challenge, we propose FedU-KAN, a framework built upon the lightweight U-KAN architecture, tailored for federated medical image segmentation tasks. Moreover, we design an adaptive differential privacy mechanism that dynamically adjusts gradient clipping based on feature importance. This approach helps preserve anatomical details while reducing the risk of privacy leakage. We evaluate FedU-KAN on the CVC-ClinicDB and Kvasir-SEG datasets, where it achieves IoU scores of 87.09% and 83.38%, respectively—outperforming standard FL baselines. These results demonstrate that FedU-KAN can effectively balance privacy protection and model performance in real-world medical segmentation scenarios.
Haotian Chi, Shunrong Jiang, Xiaojiang Du, Nadjib Aitsaadi
GLOBECOM2
2025 Smart Contract Vulnerability Detection via Heterogeneous Graph Representation and Dual Attention Mechanisms
Yingying Qu, Jiangtao Cui, Haotian Chi, Haijun Geng, Shunrong Jiang, Xiaojiang Du
GLOBECOM3
2025 Privacy-Preserving Distributed Optimization Scheme for Battery Swapping and Charging System With Homomorphic Encryption to Protect Wireless Communications
abstract
The proliferation of electric vehicles (EVs) has spurred a growing demand for efficient battery exchange and charging services, making the battery swapping-charging system (BSCS) an attractive solution.The various subsystems of the BSCS exchange data in real-time through wireless communication. However, due to the openness of wireless communication, data can be easily intercepted and tampered with during transmission, which may lead to the leakage of sensitive information. To address this, we introduce a privacy-preserving distributed optimization algorithm, leveraging homomorphic encryption and multi-party secure computing in the BSCS context. Initially, we formulate the operation management problem of BSCS problem as a constrained mixed integer programming (MIP) and employ the alternating direction method of multipliers (ADMM) for optimal resolution. Subsequently, we integrate ADMM with the Paillier cryptosystem for privacy protection. Empirical validation substantiates the algorithm security and convergence, ensuring that adversaries cannot deduce private information. Notably, the proposed algorithm yields a solution closely resembling the centralized solution, with a superior convergence rate compared to alternative methods.
Zhuocheng Sun, Haotian Chi, Shunrong Jiang, Xiaojiang Du, Nadjib Aitsaadi
GLOBECOM2
2025 Effective Dual-Layer Poison Attacks Detection in Privacy-preserving Federated Learning
abstract
Although federated learning offers a certain degree of privacy by aggregating user gradients instead of raw data, it remains vulnerable to various attacks, such as model poisoning. Existing defense mechanisms often address poisoning threats at the cost of exposing gradient information, which can lead to privacy risks such as member inference attacks. While techniques like cryptography or differential privacy can be employed to mitigate these risks, they often come with significant efficiency trade-offs. At the same time, a non-IID heterogeneous environment is also a big challenge. To address these challenges holistically, this paper proposes a dual-layer detection scheme (EDDFL). It combines norm-based filtering and isolation forest detection to effectively filter out malicious gradients, thereby preserving model accuracy even in adversarial environments. Furthermore, we incorporate a gradient quantization method that not only protects gradient privacy but also improves communication efficiency. Compared with existing approaches, the proposed method effectively addresses the challenges of model poisoning, gradient leakage, and data heterogeneity under non-IID settings. Experimental results demonstrate that our scheme significantly reduces both computational and communication overhead while maintaining privacy guarantees.
Xiao Zhang 0047, Haotian Chi, Shunrong Jiang, Xiaojiang Du, Danny Hughes 0001
GLOBECOM2
2025 InstructFlow: Adaptive Symbolic Constraint-Guided Code Generation for Long-Horizon Planning
abstract
Long-horizon planning in robotic manipulation tasks requires translating underspecified, symbolic goals into executable control programs satisfying spatial, temporal, and physical constraints. However, language model-based planners often struggle with long-horizon task decomposition, robust constraint satisfaction, and adaptive failure recovery. We introduce InstructFlow, a multi-agent framework that establishes a symbolic, feedback-driven flow of information for code generation in robotic manipulation tasks. InstructFlow employs a InstructFlow Planner to construct and traverse a hierarchical instruction graph that decomposes goals into semantically meaningful subtasks, while a Code Generator generates executable code snippets conditioned on this graph. Crucially, when execution failures occur, a Constraint Generator analyzes feedback and induces symbolic constraints, which are propagated back into the instruction graph to guide targeted code refinement without regenerating from scratch. This dynamic, graph-guided flow enables structured, interpretable, and failure-resilient planning, significantly improving task success rates and robustness across diverse manipulation benchmarks, especially in constraint-sensitive and long-horizon scenarios.
Haotian Chi, Zeyu Feng, Yueming Lyu, Chengqi Zheng, Linbo Luo 0001, Yew-Soon Ong, Ivor W. Tsang, Hechang Chen, Yi Chang 0001, Haiyan Yin
NeurIPS1
2025 DUdetector: A dual-granularity unsupervised model for network anomaly detection
Haijun Geng, Haotian Chi
Comput. Networks3
2025 Accountable federated learning against local poisoning attacks
Yuan Gao 0019, Yuanqiao Zhang, Haijun Geng, Haotian Chi
Knowl. Based Syst.5
2025 Hybrid Makes Better: Hybrid Differential Privacy Medical Image Classification Based on Federated Learning
abstract
Machine learning has the potential to revolutionize medical image classification. However, machine learning requires large medical datasets to improve accuracy, which will compromise patient privacy. Federated learning is a promising technique that protects patient privacy and improves the accuracy of medical image classification. Unfortunately, current research shows that federated learning faces the risk of privacy leakage. In this paper, we propose a privacy-preserving federal learning scheme via hybrid differential privacy for medical image classification (FHDM). Specifically, we construct a local hybrid differential privacy algorithm (LHDP) against patients' privacy leakage. This hybrid algorithm combines Gaussian and Laplace differential privacy without enlarging the privacy budget. We prove that the algorithm applies to the model parameter. Moreover, we design loss optimization and global optimization strategies on the algorithm to achieve higher accuracy in medical image classification. Finally, we validate FHDM in terms of privacy-preserving and model accuracy on real datasets. Experiments show that FHDM effectively protects privacy and improves the average accuracy by 9.60% compared to previous differential privacy schemes with the same medical image dataset and privacy budget.
Shunrong Jiang, Haotian Chi, Xiaojiang Du
IEEE Trans. Dependable Secur. Comput.5
2025 ECAKM: Efficient Conditional Anonymous Authentication Scheme With On-Chain Key Management in VANETs
abstract
Conditional anonymous authentication can provide anonymity and traceability to Vehicular Ad-Hoc Networks (VANETs), which protects users’ privacy while resisting malicious users and false messages. However, existing schemes suffer from various disadvantages, such as unavailable batch verification, unrenewable user public keys/certificates, and untimely revocation. In this paper, we propose an efficient conditional anonymous authentication scheme with on-chain key management (ECAKM) in VANETs. To achieve lightweight authentication, we design an efficient Signature of Knowledge (SoK) and a batch verification algorithm. We also employ a Bloom filter on the chain to manage the information about revoked anonymous public keys to further improve the efficiency of our scheme. Moreover, we adopt hash chain technology to update users’ anonymous public keys and protect vehicles against linkage attacks. In addition, based on the blockchain and smart contract (SC), we can manage anonymous public keys of users efficiently and transparently. Security analysis and experimental results demonstrate that our scheme ensures conditional privacy with a reduced authentication overhead.
Shunrong Jiang, Xiao Zhang 0047, Guohuai Sang, Haotian Chi, Yong Zhou 0003
IEEE Trans. Intell. Transp. Syst.4
2024 Audio-Assisted Smart Home Security Monitoring with Few Samples
abstract
Smart home IoT devices have always been the target of various cyber attacks. By leveraging the smart home monitoring infrastructure, event-based anomaly detection is effective to detect anomalies that cause unfavorable working state of IoT devices. However, IoT events are proven to be vulnerable to event-targeted attacks which could be achieved by exploiting the vulnerabilities embedded in IoT devices, protocols and/or platforms. Thus, existing event-based anomaly detection is not robust in the case of unreliable input. To address this issue, our insight is that the embedded microphone components in many off-the-shelf home devices (e.g., smart doorbells, speakers, cameras, tablets, laptops, etc.) could be utilized to gather acoustic information to help increase the reliability and capability of smart home security monitoring systems. To verify this idea, we propose an audio-assisted framework IoTAudMon for detecting event-targeted attacks. Considering the heterogeneity and sparsity nature of smart homes IoT devices and events, we employ transfer learning to design a practical pipeline for extracting semantic information from audio, eliminating the requirement of human labeling and mitigating the cold start issue in existing solutions. Experiments on public datasets and real devices demonstrate the effectiveness of IoTAudMon.
Haotian Chi, Chenglong Fu 0002, Haijun Geng, Xiaojiang Du
GLOBECOM1
2024 DPFedSAM-Meas: Comparison Of Differential Privacy Federated Learning In Medical Image Classification
abstract
Machine learning is widely used in medical image classification tasks. However, medical images often exhibit uneven distribution and high sensitivity to noise. A feasible solution involves using federated learning (FL) with differential privacy (DP), a distributed training method that protects patient privacy. In this work, many studies have proposed improved solutions for localized differential-private federated learning (DP-FL) frameworks. However, these studies are isolated, which would be detrimental to privacy practitioners in designing and using the algorithms. To provide a comprehensive analysis of these algorithms, we propose DPFedSAM-Meas, as a framework for comprehensive utility analysis of DP-FL. In this framework, we employed the state-of-the-art federated learning framework FedSAM. Moreover, we categorize DP algorithms into Laplace DP and Gaussian DP by the underlying DP mechanisms, and into Gradient DP and Parameter DP by the DP position in FL train. DPFedSAM-Meas allows a comparative analysis of these four DP techniques, measuring their model utility, privacy leakage, and overhead when FL uses different network structures. Finally, we evaluate DPFedSAM-Meas on datasets of Pneumonia, Blood, and Path, aiming to investigate the performance of different DP techniques on mainstream deep learning algorithms, including Convolutional Neural Networks (CNN) and Vision Transformers (ViT).
Shunrong Jiang, Haotian Chi, Xiaojiang Du
GLOBECOM6
2024 Hybrid Makes Better: Privacy-Preserving Medical Image Classification Based on Federated Learning
abstract
The power of machine learning makes it available for medical image classification. However, machine learning requires large medical datasets to improve accuracy, which will involve patients’ private information and lead to their privacy leakage. Federated learning is a trending technique to both protect patients’ privacy and improve the accuracy of medical image classification. Unfortunately, current research shows that federated learning faces the risk of privacy leakage. In this paper, we propose a privacy-preserving scheme FHDM. Specifically, we construct a local hybrid differential privacy algorithm (LHDP) against patients’ privacy leakage. This hybrid algorithm utilizes both Gaussian and Laplace differential privacy without enlarging the privacy budget. We prove that the algorithm applies to the model parameter. Moreover, we design loss optimization and global optimization strategies on the algorithm to achieve higher accuracy in medical image classification. Finally, we validate FHDM in terms of privacy-preserving and model accuracy on real datasets. Experiments show that FHDM effectively protects privacy and improves the average accuracy by 10.0% compared to adopting the LDP-based scheme with the same medical image dataset and privacy budget.
Haotian Chi, Shunrong Jiang, Xiaojiang Du, Mohsen Guizani
GLOBECOM2
2024 Sample Efficient Offline-to-Online Reinforcement Learning
abstract
Offline reinforcement learning (RL) makes it possible to train the agents entirely from a previously collected dataset. However, constrained by the quality of the offline dataset, offline RL agents typically have limited performance and cannot be directly deployed. Thus, it is desirable to further finetune the pretrained offline RL agents via online interactions with the environment. Existing offline-to-online RL algorithms suffer from the low sample efficiency issue, due to two inherent challenges, i.e., exploration limitation and distribution shift. To this end, we propose a sample-efficient offline-to-online RL algorithm via Optimistic Exploration and Meta Adaptation (OEMA). Specifically, we first propose an optimistic exploration strategy according to the principle of optimism in the face of uncertainty. This allows agents to sufficiently explore the environment in a stable manner. Moreover, we propose a meta learning based adaptation method, which can reduce the distribution shift and accelerate the offline-to-online adaptation process. We empirically demonstrate that OEMA improves the sample efficiency on D4RL benchmark. Besides, we provide in-depth analyses to verify the effectiveness of both optimistic exploration and meta adaptation.
Siyuan Guo 0001, Lixin Zou, Hechang Chen, Bohao Qu, Haotian Chi, Philip S. Yu, Yi Chang 0001
IEEE Trans. Knowl. Data Eng.5
2023 DCAMM: Dynamic Curve-Based Automated Market Maker
abstract
Decentralized Exchanges (DEX) allow cryptocurrencies to trade autonomously with each other without involving any centralized financial intermediaries. Among these DEX models, Automated Market Maker (AMM) is most commonly used by major platforms like Uniswap and Curve. However, a typical AMM suffers three main challenges. First, arbitrage trading may cause AMM-based liquidity providers to lose liquidity in assets. Second, adversaries extract on a monthly basis over 10 million USD from AMM traders via sandwich attacks. Third, the volatility of asset prices in AMM may violate the fairness of trading. In this work, we propose a new AMM design, Dynamic Curve-based Automated Market Maker (DCAMM), which utilizes a price oracle with real-time market price feedback to automatically adjust the pool's asset price to match the market price. In DCAMM, there is no space for price manipulation, and traders' slippage losses are converted into equal gains for the liquidity pool. Thus, DCAMM provides the resistance to arbitrage trading and sandwich attacks. Moreover, DCAMM provides a more stable asset price through a strict price adjustment, benefiting traders and safeguarding trading fairness.
Shunrong Jiang, Fengjiao Li, Haijun Geng, Haotian Chi
GLOBECOM5
2023 EAKM: Efficient Conditional Privacy-Preserving Authentication Scheme with On-Chain Key Management in VANETs
abstract
Conditional privacy-preserving authentication can provide anonymity and traceability to Vehicular Ad-Hoc Networks (VANETs), which protects users' privacy while resisting malicious users and false messages. However, existing schemes suffer from various disadvantages, such as unavailable batch verification, unrenewable user public keys/certificates, and untimely revocation. In this work, we design an efficient conditional privacy-preserving authentication scheme with the on-chain key management (EAKM) for VANETs. To achieve lightweight authentication, we design an efficient Signature of Knowledge (SoK) and a batch verification algorithm. Moreover, we use the hash chain technology to update users' anonymous public keys. In addition, based on the blockchain technology and smart contract, we could manage users' anonymous public keys efficiently and transparently. Security analysis and simulation results show that EAKM ensures conditional privacy with less authentication overhead.
Shunrong Jiang, Guohuai Sang, Xuedan Jia, Fengjiao Li, Haotian Chi
GLOBECOM5
2023 No More Companion Apps Hacking but One Dongle: Hub-Based Blackbox Fuzzing of IoT Firmware
abstract
Given the massive difficulty in emulating IoT firmware, blackbox fuzzing of IoT devices for vulnerability discovery has become an attractive option. However, existing blackbox IoT fuzzers need much time and tedious effort to reverse engineer the IoT companion app (or manually collect test scripts) of each IoT device, which is unscalable when analyzing many devices. Moreover, fuzzing through a companion app is impeded by the input sanitization inside the app and limited to the manually revealed functions. We notice that IoT devices are typically able to connect a hub using standard wireless protocols (such as ZigBee, Z-Wave, and WiFi). We thus propose a uniform hub-based architecture for fuzzing various IoT devices, without reverse engineering any companion apps. It exploits the messages exchanged between a hub and an IoT device to automatically discover all the functions, and then launches systematic function-oriented message-semantics-guided fuzzing. It avoids sanitization imposed by a companion app. In addition, it conducts device state-sensitive fuzzing, which we find very effective in finding IoT bugs. We implement the system named HubFuzzer. The evaluation shows that HubFuzzer leads to much higher coverage than prior state of the art. We test 21 IoT devices and find 23 zero-day vulnerabilities. Four CVEs have been assigned.
Qiang Zeng 0001, Haotian Chi, Lannan Luo
MobiSys3
2023 Detecting and Handling IoT Interaction Threats in Multi-Platform Multi-Control-Channel Smart Homes
Haotian Chi, Qiang Zeng 0001, Xiaojiang Du
USENIX Security Symposium1
2022 IoT Phantom-Delay Attacks: Demystifying and Exploiting IoT Timeout Behaviors
abstract
This paper unveils a set of new attacks against Internet of Things (IoT) automation systems. We first propose two novel IoT attack primitives: Event Message Delay and Command Message Delay (event messages are generated by IoT devices to report device states, and command messages are used to control IoT devices). Our insight is that timeout detection in the TCP layer is decoupled from data protection in the Transport Layer Security (TLS) layer. As a result, even when a session is protected by TLS, its IoT event and/or command messages can still be significantly delayed without triggering alerts. It is worth highlighting that, by compromising/controlling one WiFi device in a smart environment, the attacker can delay the IoT messages of other non-compromised IoT devices; we thus call the attacks IoT Phantom-Delay Attacks. Our study shows the attack primitives can be used to build rich attacks and some of them can induce persistent effects. The presented attacks are very different from jamming. 1) Unlike jamming, our attacks do not discard any packets and thus do not trigger re-transmission. 2) Our attacks do not cause disconnection or timeout alerts. 3) Unlike reactive jamming, which usually relies on special hardware, our attacks can be launched from an ordinary WiFi device. Our evaluation involves 50 popular IoT devices and demonstrates that they are all vulnerable to the phantom-delay attacks. Finally, we discuss the countermeasures. We have contacted multiple IoT platforms regarding the vulnerable IoT timeout behaviors, and Google, Ring and SimpliSafe have acknowledged the problem.
Chenglong Fu 0002, Qiang Zeng 0001, Haotian Chi, Xiaojiang Du, Siva Likitha Valluru
DSN3
2022 DICE-Enabled Distributed Security Schemes for the Air Force Internet of Things
abstract
Security for Internet of Things requires balancing power consumption and memory usage in devices. In this work, we propose symmetric DICE-based schemes for distributed IoT systems, which aims to have effective security and recovery procedures through symmetric keys while achieving energy efficiency. Our security schemes utilize an efficient security primitive for IoT Device Identifier Composition Engine (DICE). Our schemes enhance security and flexibility in distributed IoT systems, allowing for a secure dynamic bootstrapping and a node recovery mechanism in IoT system.
Haotian Chi, Luke Jakielaszek, Xiaojiang Du, E. Paul Ratazzi
ICC1
2022 Delay Wreaks Havoc on Your Smart Home: Delay-based Automation Interference Attacks
abstract
With the proliferation of Internet of Things (IoT) devices and platforms, it becomes a trend that IoT devices associated with different IoT platforms coexist in a smart home, demonstrating the following characteristics. First, a smart home may use more than one platform to support its devices and automation. Second, IoT devices of a home may transmit messages over different paths. By selectively delaying IoT messages, our study finds that two issues, inconsistency and disorder, can be exacerbated by attackers significantly. We then explore how these issues can be exploited and present seven types of exploitation, collectively referred to as Delay-based Automation Interference (DAI) attacks. DAI attacks cause home automation to yield incorrect interaction results, placing the IoT devices and smart home in insecure, unsafe, or unexpected states. It is worth highlighting that DAI attacks do not depend on any IoT implementation vulnerabilities or leaked keys/tokens, and they do not trigger alarms at any layers of the IoT protocol stack. To demonstrate and evaluate the new attacks, we set up two real-world testbeds, where commercial IoT devices and apps are deployed. The week-long experiments from both testbeds show that an attacker has adequate opportunities to launch DAI attacks that cause security or safety issues.
Haotian Chi, Chenglong Fu 0002, Qiang Zeng 0001, Xiaojiang Du
SP1
2021 PFirewall: Semantics-Aware Customizable Data Flow Control for Smart Home Privacy Protection
Haotian Chi, Qiang Zeng 0001, Xiaojiang Du, Lannan Luo
NDSS1
2020 Cross-App Interference Threats in Smart Homes: Categorization, Detection and Handling
abstract
Internet of Thing platforms prosper home automation applications (apps). Prior research concerns intra-app security. Our work reveals that automation apps, even secured individually, still cause a family of threats when they interplay, termed as Cross-App Interference (CAI) threats. We systematically categorize such threats and encode them using satisfiability modulo theories (SMT). We present HomeGuard, a system for detecting and handling CAI threats in real deployments. A symbolic executor is built to extract rule semantics, and instrumentation is utilized to capture configuration during app installation. Rules and configuration are checked against SMT models, the solutions of which indicate the existence of corresponding CAI threats. We further combine app functionalities, device attributes and CAI types to label the risk level of CAI instances. In our evaluation, HomeGuard discovers 663 CAI instances from 146 SmartThings market apps, imposing minor latency upon app installation and no runtime overhead.
Haotian Chi, Qiang Zeng 0001, Xiaojiang Du, Jiaping Yu
DSN1
2018 Privacy Leakage in Smart Homes and Its Mitigation: IFTTT as a Case Study
abstract
The combination of an appified smart home platform and third-party apps have enabled developers to contribute their novel ideas to bring more convenience to their users. However, this also brings the potential of privacy leakage. If a third-party app is permitted to monitor a user day and night, then it will learn the behavior pattern of this user before long. In this paper, we exploited how IFTTT monitors the daily life of a user in several ways that are hardly noticeable. We propose the “Specific-fuzzification” to protect the privacy of a user in two steps: filter the unnecessary events to the IFTTT, then fuzz the value of the events that must be uploaded. We evaluated the “Specific-fuzzification” on event records of seven users, the result showed comparing the original IFTTT, the modified IFTTT patched with “Specific-fuzzification” only gained rare events and thus could no longer recognize any behavior patterns of a user.
Rixin Xu, Qiang Zeng 0001, Liehuang Zhu, Haotian Chi, Xiaojiang Du
IPCCC4
2016 Personalized Location Recommendations with Local Feature Awareness
abstract
Location-based social networks (LBSNs) make it possible for servers to record users' location histories, mine their life patterns, and infer individual preferences. As an important component of LBSNs, recommender systems gained popularity in recent years. Recommender systems can automatically list candidate locations for users according to their preferences, which is different from traditional search methods. However, making effective recommendations suffers from data sparsity. In order to relieve this problem and achieve high effectiveness, we take context information into consideration and present a personalized location recommender system considering both user preference and local features in this paper. To be specific, we apply Labeled-LDA in user preference learning and local features inference processes, which are denoted as UL-LDA model and CL-LDA model, respectively. Because of this, we can make recommendations even on the condition that users are in a new city and have little information about the city. We evaluate our approach with extensive experiments on a large-scale Foursquare dataset. The experimental results clearly validate the effectiveness of our approach.
Xiaoyan Zhu 0005, Ripei Hao, Haotian Chi, Xiaojiang Du
GLOBECOM3
2015 Verification of Boolean Queries over Outsourced Encrypted Data Based on Counting Bloom Filter
abstract
Recent years witness the rapid development of cloud computing and more and more data owners outsource their data to the cloud. To eliminate the disclosure of authorized data users' privacy in cloud services (e.g., cloud storage or cloud-assisted computing)-since the cloud providers cannot be fully trustworthy-several previous works have proposed considerable privacy-preserving schemes by exploiting searchable encryption. However, owing to its feature of untrusty, issue arises on how data users can verify whether the cloud has faithfully executed the search operations or not. Motivated by this question, in this paper, we propose a searchable and verifiable query scheme over encrypted data based on Counting Bloom Filter (CBF). Specifically, we deploy counting bloom filters to generate proofs for data users' queries in the private cloud; using the consistence between algebra operations on counting bloom filters and on data sets, we can verify the integrity of search result. The security analysis and performance evaluation show that the proposed scheme is privacy-preserving and is feasible to implement.
Xiaoyan Zhu 0005, Ripei Hao, Shunrong Jiang, Haotian Chi, Hongning Li
GLOBECOM4
2015 Lightweight and privacy-preserving agent data transmission for mobile Healthcare
abstract
With the pervasiveness of smartphones and the advance of wireless body sensor networks (WBSNs), mobile healthcare (m-healthcare) has attracted considerable interest recently. In m-Healthcare, users' smartphones serve as bridges connecting their WBSNs and the healthcare center (HCC), i.e., send users' personal health information (PHI) collected by WBSNs to the HCC and receive the feedback. However, users' smartphones are not always available (e.g., left at home or out of power), resulting in an unexpected interruption of medical services sometimes, which are not considered in most existing schemes for m-healthcare. In this paper, we propose a lightweight and privacy-preserving agent data transmission scheme for m-healthcare in opportunistic social networks on condition that the smartphone is not available. By using the proposed protocol, we can provide uninterrupted healthcare while keeping the user's identity and PHI private during the agent transmitting of PHI. Security and performance analysis show that the proposed scheme can realize privacy-preservation and achieve secure end-to-end communication for m-healthcare, and is suitable for resource-limited WBSNs.
Shunrong Jiang, Xiaoyan Zhu 0005, Ripei Hao, Haotian Chi, Hui Li 0006, Liangmin Wang 0001
ICC4
2014 Two-party and multi-party private matching for proximity-based mobile social networks
abstract
Proximity-based mobile social networks (PMSNs) are a novel type of social networks, where mobile users can choose potential friends in vicinity by comparing the similarity degree between their private attributes and make new connections through the WiFi/Bluetooth interfaces on their mobile devices. Since users' personal attributes usually contain some sensitive information, users may have increasing privacy concerns and do not want to reveal their attributes to others in the process of friend discovery. In this paper, we first propose a two-party private matching algorithm, which achieves a fine-grained match and protects users' privacy preferably without reliance on any Trusted Third Party (TTP). Based on the two-party protocol, we then present a multi-party matching protocol, where a responder who satisfies the pre-defined threshold can match with a group of users without breaching their privacy. By the detailed analysis and simulations, we evaluate our two matching schemes in terms of security, communication overhead and computation overhead, which show a better performance than other related protocols.
Xiaoyan Zhu 0005, Zengbao Chen, Haotian Chi, Shunrong Jiang
ICC3
2014 Using dynamic pseudo-IDs to protect privacy in location-based services
abstract
Location-based services (LBSs) are attracting more and more attentions with the increasing popularity of mobile devices and online social networking. In LBSs, users can conveniently obtain their interested information by sending queries to the LBS server. However, users' queries include their identities, locations, interests, etc, which may result in the leakage of users' trajectory and other sensitive information. Although the existing obfuscation and location anonymization techniques along with a long-term pseudonym can protect users' location privacy to some extent, users' real identities and moving trajectories can still be deduced through long-term observation and side information aided inference attacks. To address these problems, we propose a dynamic pseudo-ID system, where unlinkable pseudo-IDs are used by users to completely hide their identities in the queries, in order to break the link between users' identities and their locations. Moreover, we employ certificates to ensure the verifiability and traceability of the dynamic pseudo-IDs. Security analysis and evaluation results show that the proposed scheme can enhance user' privacy and is feasible to implement into mobile devices.
Xiaoyan Zhu 0005, Haotian Chi, Shunrong Jiang, Xiaosan Lei, Hui Li 0006
ICC2
2013 MobiCache: When k-anonymity meets cache
abstract
Location-Based Services (LBSs) are becoming increasingly popular in our daily life. In some scenarios, multiple users may seek data of same interest from a LBS server simultaneously or one by one, and they may need to provide their exact locations to the un-trusted LBS server in order to enjoy such a location-based service. Unfortunately, this will breach users' location privacy and security. To address this problem, we propose a novel collaborative system, MobiCache, which combines k-anonymity with caching together to protect user's location privacy while improving the cache hit ratio. Different from the traditional k-anonymity, our Dummy Selection Algorithm (DSA) chooses dummy locations which have not been queried before to increase the cache hit ratio. We also propose an enhanced-DSA to further improve the user's privacy as well as the cache hit ratio by assigning dummy locations which can make more contributions to cache hit ratio. Evaluation results show that the proposed DSA can increase the cache hit ratio and the enhanced-DSA can further improve the cache hit ratio as well as the user's privacy.
Xiaoyan Zhu 0005, Haotian Chi, Ben Niu 0001, Zan Li 0001, Hui Li 0006
GLOBECOM2
2013 P-Match: Priority-Aware Friend Discovery for Proximity-Based Mobile Social Networks
abstract
With rapid developments of mobile devices and online social networks, users of Proximity-based Mobile Social Networks (PMSNs) can easily discover and make new social interactions with others at the cost of their growing privacy concerns. To address this problem, we propose a third party free scheme, P-match, to privately match the similarity with potential friends in vicinity. Unlike most existing work, P-match considers both the number of common interests and the corresponding priorities on each of them individually. The security and performance overhead of our scheme are then thoroughly analyzed and evaluated via detailed simulations.
Ben Niu 0001, Xiaoyan Zhu 0005, Tanran Zhang, Haotian Chi, Hui Li 0006
MASS4
2013 3PLUS: Privacy-preserving pseudo-location updating system in location-based services
abstract
Location-Based Services (LBSs) are becoming increasingly popular with rapid developments of social networks and location aware devices, such as smartphones and tablets. Users query the LBSs server and get service information about their surroundings. Unfortunately, these queries may lead to serious security and privacy concerns. It is very hard for users to access LBSs while keeping their privacy at the same time. To deal with this problem, we propose a novel scheme, called 3PLUS. It can significantly improve users' location privacy without reliance on the Trusted Third Party (TTP). Further more, it is simple to implement, and does not require changing the current structure of LBSs server. Users use a buffer to record the pseudo-locations, which come from both the history locations of herself and the encountered users. When two users encounter, by using their pseudonyms, they randomly choose a pseudo-location from their buffers and exchange with each other. Then she can find and submit k valid locations together to un-trusted LBSs server easily when the service is needed. Our evaluation results indicate us a hidden relationship between k, the buffer size S and exchanging number N.
Ben Niu 0001, Xiaoyan Zhu 0005, Haotian Chi, Hui Li 0006
WCNC3