Zhitao Guan

dblp:14/190 · DBLP profile ↗
← Back
50ranked-venue papers
14as first author
27since 2021 · last 2026
0000-0003-0901-8621ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 25 · 6 first-author · 11 since 2021Security and privacy · 8 · 1 first-author · 7 since 2021Systems, architecture and hardware · 7 · 3 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 3 first-author · 3 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021
YearPublicationVenuePosition
2026 An epoch-weighted privacy budget allocation framework for fine-tuning large language models
Peisheng Zhang, Naiyu Wang, Longfei Wu, Liehuang Zhu, Zhitao Guan
Sci. China Inf. Sci.5
2026 An efficient privacy-preserving transformer inference scheme for cloud-based intelligent decision-making in AIoT
Mingshun Luo, Haolei He, Wenti Yang, Shuai Yuan 0006, Zhitao Guan
J. Syst. Archit.5
2026 Singular transformation attack: Enhancing targeted transferability of adversarial examples via feature importance perturbation
Weizhi Meng 0001, Zhitao Guan, Yu-an Tan 0001
Knowl. Based Syst.4
2026 Unveiling Ethereum Mixing Services Using Enhanced Graph Structure Learning
abstract
As cryptocurrency prices continue to recover, crypto crimes such as money laundering are becoming increasingly rampant. Mixing services such as Tornado Cash have become the primary tools for obfuscating illegal financial transactions due to their inherent anonymity mechanisms. Tornado Cash is a non-custodial, smart contract-based mixing service (SC-CMS) that breaks the direct mapping between deposit and withdrawal accounts, hindering regulators from tracking illicit fund flows. Existing deanonymization methods for Tornado Cash suffer from several challenges, including vague theoretical concepts, evolving mixing mechanisms, and insufficient labeled samples. To address these concerns, this paper proposes the first formal concept of SC-CMS to facilitate and evaluate the deanonymization efforts systematically. We design a novel linkability attack, LASC, based on enhanced graph structure learning, to associate mixing accounts on Tornado Cash and mathematically prove its feasibility. Comprehensive experiments on real Ethereum transactions demonstrate that LASC outperforms state-of-the-art works in both performance and efficiency.
Yan Wu 0014, Cong Wu 0003, Yebo Feng, Jiahang Sun, Zijian Zhang 0001, Jincheng An, Zhitao Guan, Liehuang Zhu
IEEE Trans. Dependable Secur. Comput.11
2025 Privacy-Preserving and Control-Compliant Authenticated Access for the AI-Enabled Industrial Internet of Things
abstract
Artificial intelligence (AI) revolutionizes the productivity model and efficiency of the Industrial Internet of Things (IIoT). As a derivative of the AI era, AI-enabled IIoT drives frequent data access and intelligent industrial productivity. However, the rise of intelligence brings more sophisticated and hard-to-defend attacks against IIoT systems, such as deep identity forgery and malicious access, posing a major threat to intelligent development. Password-based Authenticated Key Agreement (AKA) is an effective cryptographic method for access security in IIoT, but current AKA schemes cannot address balancing between security, functionality and efficiency in the smart setting. To fill this gap, we propose a new password-based AKA scheme, where oblivious pseudorandom function, hash function and encryption are utilized to realize anonymous identity authentication. Considering malicious data access, we design a new token-tag mechanism with identity information to realize malicious identity tracing. In addition, our scheme supports a fast login function, helping the authorized party access data without repeating key agreements. Furthermore, formal security proofs and heuristic analyses demonstrate that our scheme is secure under multiple attacks. Finally, we compare the proposed scheme with the related schemes, and the results show that our scheme achieves the balance between safety, function and efficiency.
Yumeng Xie, Zhitao Guan, Yongshuang Wei, Chuan Zhang 0003, Liehuang Zhu
TrustCom3
2025 FedESP: Effective, Stealthy, and Persistent backdoor attack on federated learning
Sitian Wang, Xuan Li 0007, Shuai Yuan 0006, Zhitao Guan
J. Inf. Secur. Appl.5
2025 Robust and Scalable Federated Learning Framework for Client Data Heterogeneity Based on Optimal Clustering
Shuai Yuan 0006, Zhitao Guan
J. Parallel Distributed Comput.3
2025 Balancing Differential Privacy and Utility: A Relevance-Based Adaptive Private Fine-Tuning Framework for Language Models
abstract
Differential privacy (DP) has been proven to be an effective universal solution for privacy protection in language models. Nevertheless, the introduction of DP incurs significant computational overhead. One promising approach to this challenge is to integrate Parameter Efficient Fine-Tuning (PEFT) with DP, leveraging the memory-efficient characteristics of PEFT to reduce the substantial memory consumption of DP. Given that fine-tuning aims to quickly adapt pretrained models to downstream tasks, it is crucial to balance privacy protection with model utility to avoid excessive performance compromise. In this paper, we propose a Relevance-based Adaptive Private Fine-Tuning (Rap-FT) framework, the first approach designed to mitigate model utility loss caused by DP perturbations in the PEFT context, and to achieve a balance between differential privacy and model utility. Specifically, we introduce an enhanced layer-wise relevance propagation process to analyze the relevance of trainable parameters, which can be adapted to the three major categories of PEFT methods. Based on the relevance map generated, we partition the parameter space dimensionally, and develop an adaptive gradient perturbation strategy that adjusts the noise addition to mitigate the adverse impacts of perturbations. Extensive experimental evaluations are conducted to demonstrate that our Rap-FT framework can improve the utility of the fine-tuned model compared to the baseline differentially private fine-tuning methods, while maintaining a comparable level of privacy protection.
Naiyu Wang, Shen Wang 0012, Meng Li 0006, Longfei Wu, Zijian Zhang 0001, Zhitao Guan, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.6
2025 VSecNN: Verifiable and Privacy-Preserving Neural Network Inference in Cloud Service
abstract
Neural network inference in cloud service offers tangible benefits to users, from individuals and small institutions to large companies. However, two crucial concerns must be addressed. The first arises in satisfying the privacy of the model, the input data, and the inference results throughout the inference process. The second pertains to verifying that the inferences are derived from the designated neural network model. Although Secure Multi-Party Computation (MPC) and Zero-Knowledge Proof (ZKP) are typically adopted to mitigate such issues, the major challenge lies in achieving privacy preservation and verifiability simultaneously. In this study, we address both issues by proposing VSecNN, a verifiable and privacy-preserving neural network inference scheme. Specifically, we integrate MPC with the Zero-Knowledge Succinct Non-Interactive Argument of Knowledge (zk-SNARK) protocol to achieve zero-knowledge proof generation for multiple parties. Subsequently, we perform adaptive optimizations on the multi-party proof generation approach to align with the neural network, thereby achieving both privacy-preserving capabilities and verifiability. Experimental results demonstrate an improvement in the efficiency. For example, the computation time for completing our multi-party proof generation could be as low as 1.7 times that of the single-party proof generation, while the verification requires only 169ms on the MNIST dataset.
Wenti Yang, Xuan Li 0007, Meng Li 0006, Zijian Zhang 0001, Zhitao Guan, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.5
2024 PVWA: Privacy-preserving and Verifiable Weighted Aggregation for Federated Learning
abstract
Federated learning provides clients with a means of collaboratively training a global model without sharing their local data, managed by a central server. However, this server cannot always be trusted, as it may act dishonestly and compromise the privacy of clients’ local data. Consequently, mechanisms for privacy preservation and aggregation verification become crucial components of a secure federated learning system. In addition, support for weighted aggregation is also essential to address the challenges posed by non-IID training data. In this article, we present the Privacy-Preserving and Verifiable Weighted Aggregation (PVWA) scheme. Our approach introduces a new privacy-preserving solution by leveraging masking and homomorphic encryption techniques to protect local and global models, respectively. The masking protocol facilitates secure weighted aggregation, whereas a verification mechanism based upon homomorphic hashing and bilinear aggregated signatures ensures the correctness of aggregated results. Experimental evaluations of the performance, compared against alternative methods on two datasets, demonstrate its effectiveness and efficiency.
Xiaodong Wang 0025, Shuai Yuan 0006, Zhitao Guan, Xiaojiang Du, Mohsen Guizani
GLOBECOM4
2024 MulDoor: A Multi-target Backdoor Attack Against Federated Learning System
abstract
In recent years, with the development of wireless communication networks, federated learning (FL) has been widely deployed in distributed scenarios as a privacy-preserving machine learning paradigm. Due to its inherent features, FL shows vulnerability to backdoor attacks. In a backdoor attack, an adversary manipulates the global model’s output by compromising the model of one or multiple participants. Existing backdoor attacks are constrained to outputting a single specified target label during the inference phase, limiting the adversary’s flexibility to alter the model’s output when different target labels are required. In this paper, we study the multi-target attack scenario within the federated learning context, where the adversary aims to manipulate the global model to output various specified labels by inserting different types of triggers. To effectively insert multiple backdoors simultaneously without reducing the attack’s effectiveness, we propose MulDoor, a novel multi-target backdoor attack scheme. MulDoor incorporates the concept of supervised contrastive learning to learn the discrepancies among different types of triggers and mitigate interference between them. The experimental results demonstrate that MulDoor achieves better attack effectiveness compared to existing backdoor attacks in a multi-target backdoor attack setting.
Xuan Li 0007, Longfei Wu, Zhitao Guan, Xiaojiang Du, Nadjib Aitsaadi, Mohsen Guizani
GLOBECOM3
2024 FUSE: a federated learning and U-shape split learning-based electricity theft detection framework
Xuan Li 0007, Naiyu Wang, Liehuang Zhu, Shuai Yuan 0006, Zhitao Guan
Sci. China Inf. Sci.5
2024 FedIMP: Parameter Importance-based Model Poisoning attack against Federated learning system
Xuan Li 0007, Naiyu Wang, Shuai Yuan 0006, Zhitao Guan
Comput. Secur.4
2024 Decentralized Fair IoT Data Trading via Searchable Proxy Re-Encryption
abstract
The Internet of Things (IoT) is a network composed of information-gathering devices, sensors, and computing devices assembled in an intelligent manner, and the most important element in this system is data. IoT data trading plays a vital role in the area of personalized business nowadays. Individual IoT devices generate large amounts of private data, which data owners can sell to enterprises as important digital assets to make money, while enterprises collect IoT data to improve the accuracy of their services. Cloud storage services have been widely used in IoT data trading. In IoT data trading, cloud storage services have been widely used for individuals to store IoT data and for enterprises to automatically facilitate data trading. However, there are still two crucial drawbacks to be solved. From the point of security, it is difficult for data buyers to check the validity of the search result without getting the decryption key of the data owner. From the point of fairness, there is a lack of a punishment mechanism to transfer money from the cheating party to the honest party. To tackle the two challenges, we propose a searchable re-encryption scheme to maintain traditional security without sacrificing service quality. Next, we design a fair trading protocol based on smart contracts to automatically detect any cheating behaviors. Formal security analysis proves that the scheme provides expected security. Experimental results show that the scheme achieve good performance.
Zijian Zhang 0001, Tyler Zhou, Tao Niu, Meng Li 0006, Zhitao Guan, Liehuang Zhu
IEEE Internet Things J.6
2024 GradDiff: Gradient-based membership inference attacks against federated distillation with differential comparison
Xiaodong Wang 0025, Longfei Wu, Zhitao Guan
Inf. Sci.3
2024 WEDA: Exploring Copyright Protection for Large Language Model Downstream Alignment
abstract
Large Language Models (LLMs) have shown incomparable representation and generalization capabilities, which have led to significant advancements in Natural Language Processing (NLP). Before deployment, the pre-trained LLMs often need to be tailored to specific downstream tasks for improved performance, which is commonly referred to as downstream alignment. This is a costly effort considering the needed manpower, training resources, and downstream-specific data. While much attention has been paid to protecting the copyright of the models themselves, the copyright protection of LLM alignment has been largely overlooked. In this paper, we present Watermark Embedding for Downstream Alignment (WEDA) scheme, which can provide effective copyright protection for two popular LLM alignment techniques parameter-efficient fine-tuning (PEFT) and in-context learning (ICL). For alignment through PEFT, we propose a Chain of Thought (CoT) based solution to embed watermarks into the PEFT weights. Furthermore, we extend this solution to safeguard alignment through ICL by utilizing the prefix-integrated CoT to watermark examples embedded within ICL prompts. We conduct an extensive experimental evaluation to demonstrate the effectiveness of our proposed scheme.
Shen Wang 0012, Jialiang Dong, Longfei Wu, Zhitao Guan
IEEE ACM Trans. Audio Speech Lang. Process.4
2023 FeatureMix: A General Adversarial Defense Method for Pretrained Language Models
abstract
Pretrained language models (PLMs) that are trained over large-scale data and then finetuned on downstream tasks have achieved great success. However, they are vulnerable to adversarial attacks. Adversarial training with both clean and adversarial data is a widely-used technique to improve model robustness. In this paper, we propose FeatureMix, a straightforward yet effective adversarial defense strategy for PLMs by finetuning on both discrete adversarial examples and online virtual examples. During finetuning, we augment clean data with discrete attacks first and generate virtual examples in each finetuning epoch by randomly mixing local latent features in the hidden layers of augmented data pairs. The virtual examples serve as additional training signals, regularizing the PLMs to favor mixing of latent features between discrete augmented examples and thus enhance adversarial robustness. The experimental evaluation results show that FeatureMix outperforms prevailing baseline methods in terms of robustness against adversarial attacks, without significantly reducing generalization performance.
Huoyuan Dong, Longfei Wu, Zhitao Guan
GLOBECOM3
2023 GBMIA: Gradient-based Membership Inference Attack in Federated Learning
abstract
Membership inference attack (MIA) has been proved to pose a serious threat to federated learning (FL). However, most of the existing membership inference attacks against FL rely on the specific attack models built from the target model behaviors, which make the attacks costly and complicated. In addition, directly adopting the inference attacks that are originally designed for machine learning models into the federated scenarios can lead to poor performance. We propose GBMIA, an attack model-free membership inference method based on gradient. We take full advantage of the federated learning process by observing the target model's behaviors after gradient ascent tuning. And we combine prediction correctness and the gradient norm-based metric for membership inference. The proposed GBMIA can be conducted by both global and local attackers. We conduct experimental evaluations on three real-world datasets to demonstrate that GBMIA can achieve a high attack accuracy. We further apply the arbitration mechanism to increase the effectiveness of GBMIA which can lead to an attack accuracy close to 1 on all three datasets. We also conduct experiments to substantiate that clients going offline and the overlap of clients' training sets have great effect on the membership leakage in FL.
Xiaodong Wang 0025, Naiyu Wang, Longfei Wu, Zhitao Guan, Xiaojiang Du, Mohsen Guizani
ICC4
2023 An Efficient Post-Quantum Multi-Signature Scheme for the Internet of Vehicles
abstract
Multi-signature scheme is a unique type of digital signature where a group of participants are capable of producing a signature interactively on a shared message, thus significantly reducing the signature size. This is especially important for Internet of Vehicles (IoV) systems where higher efficiency and lower costs are required during the communication. Most approaches so far, however, are developed by traditional methods such as the integer factoring assumption, which result in potential vulnerability to quantum computing attacks. Although a few lattice-based multi-signature candidates have been proposed, they either rely on hash-and-sign process with higher costs or may be compromised by larger size of public key and signature. Motivated by the Bimodal Lattice Signature Scheme (BLISS) model [1], we propose a new lattice-based multi-signature scheme (Multi-BLISS, MB) in this paper. Our scheme can also be transformed into an aggregate signature scheme (Aggregate MB, AMB) with similar level of performance. We evaluate both schemes by setting security levels of 128, 160 and 192 bits in the experiments, and the results demonstrate significant improvement on security and efficiency comparing to existing lattice-based multi-signature schemes.
Qianyi Zhang, Shuai Yuan 0006, Zhitao Guan, Xiaojiang Du, Mohsen Guizani
ICC3
2023 Transferable adversarial distribution learning: Query-efficient adversarial attack against large language models
Huoyuan Dong, Jialiang Dong, Shaohua Wan 0001, Shuai Yuan 0006, Zhitao Guan
Comput. Secur.5
2022 A Blockchain-Based Dual-Side Privacy-Preserving Multiparty Computation Scheme for Edge-Enabled Smart Grid
abstract
Unlike a traditional centralized and producer-controlled power grid, the smart grid is a more complicated distributed power system consisted of many resources and applications. In smart grid, huge amounts of data generated by edge devices are collected by different parties. To achieve high operation efficiency, it is important to enable the data sharing and cooperative computation among different parties. How to protect the security and privacy of the utility data and the identities of their owners has become a major concern. There have been some studies on this issue. However, most of these works failed to consider the privacy protection in the dual sides of the data owner and receiver. In this article, we propose BPM4SG, a blockchain-based dual-side privacy-preserving multiparty computation (MPC) scheme for edge-enabled smart grid. In BPM4SG, the data segmentation method is adopted to ensure the security of MPC (e.g., summation) in edge nodes. The consortium blockchain and smart contract are used to further increase the system security and avoid the dependency on trusted third parties. Additionally, a data obfuscation method based on the ring signatures and a new one-time address scheme are proposed to protect the privacy of both the data owner and data receiver. The analysis shows that BPM4SG can meet the security and privacy requirements of smart grid. The experimental evaluation results demonstrate that our scheme has a better performance compared with other popular schemes.
Zhitao Guan, Xiao Zhou 0025, Peng Liu 0027, Longfei Wu, Wenti Yang
IEEE Internet Things J.1
2021 BPFL: A Blockchain Based Privacy-Preserving Federated Learning Scheme
abstract
Federated Learning (FL), which allows multiple participants to co-train machine Learning models without exposing local data, has been recognized as a promising method in the past few years. However, in the FL process, the server side may steal sensitive information of users, while the client side may also upload malicious data to compromise the training of the global model. Most existing privacy-preservation FL schemes seldom deal with threats from both of these two sides at the same time. In this paper, we propose a Blockchain based Privacy-preserving Federated Learning scheme named BPFL, which uses blockchain as the underlying distributed framework of FL. Homomorphic encryption and Multi-Krum technology are combined to achieve ciphertext-level model aggregation and model filtering, which can guarantee the verifiability of local models while realizing privacy-preservation. Security analysis and performance evaluation prove that the proposed scheme can achieve enhanced security and improve the performance of the FL model.
Naiyu Wang, Wenti Yang, Zhitao Guan, Xiaojiang Du, Mohsen Guizani
GLOBECOM3
2021 Achieving adaptively secure data access control with privacy protection for lightweight IoT devices
Zhitao Guan, Wenti Yang, Liehuang Zhu, Longfei Wu, Ruimiao Wang
Sci. China Inf. Sci.1
2021 A sentence-level text adversarial attack algorithm against IIoT based smart grid
Jialiang Dong, Zhitao Guan, Longfei Wu, Xiaojiang Du, Mohsen Guizani
Comput. Networks2
2021 Secure Data Access Control With Fair Accountability in Smart Grid Data Sharing: An Edge Blockchain Approach
abstract
Nowadays, the advance of smart grid technology has fostered the development of microgrids, which can efficiently control and manage the distributed energy resources (DERs). In smart grid, IoT devices generate huge amounts of data, which are collected and shared among DERs, microgrids, and the main grid. To protect the shared data, it is necessary to implement the secure and efficient data access control. Ciphertext policy attribute-based encryption (CP-ABE) is a promising solution for the distributed system. However, lightweight IoT devices with limited computing capability cannot handle the computationally intensive ABE algorithms. To overcome this constraint, the decryption phase of CP-ABE is usually outsourced to the cloud, but this is inefficient and not safe enough in the distributed environment. In this article, we propose an edge blockchain empowered secure data access control scheme with fair accountability for the smart grid. The computation workloads of end user devices are outsourced to the edge nodes in a consortium blockchain system We adopt an on-chain/off-chain approach to ensure the flexible data sharing. Additionally, we adopt the threshold secret sharing scheme to establish a distributed authority. The security analysis and performance evaluation are conducted to prove the security and efficiency of our scheme. We use the Raspberry Pi to simulate lightweight IoT devices in the Hyperledger fabric platform to prove the usability of our scheme.
Wenti Yang, Zhitao Guan, Longfei Wu, Xiaojiang Du, Mohsen Guizani
IEEE Internet Things J.2
2021 Achieving efficient and Privacy-preserving energy trading based on blockchain and ABE in smart grid
Zhitao Guan, Wenti Yang, Longfei Wu, Naiyu Wang, Zijian Zhang 0001
J. Parallel Distributed Comput.1
2021 Achieving Secure Search over Encrypted Data for e-Commerce: A Blockchain Approach
abstract
The advances of Internet technology has resulted in the rapid and pervasive development of e-commerce, which has not only changed the production and operation mode of many enterprises, but also affected the economic development mode of the whole society. This trend has incurred a strong need to store and process large amounts of sensitive data. The traditional data storage and search solutions cannot meet such requirements. To tackle this problem, in this article, we proposed Consortium Blockchain-based Distributed Secure Search (CBDSS) Scheme over encrypted data in e-Commerce environment. By integrating the blockchain and searchable encryption model, sensitive data can be effectively protected. The consortium blockchain can ensure that only authorized nodes can join the system. To fairly assign nodes for the search tasks, we developed an endorsement strategy in which two agent roles are set up to divide and match the search tasks with the virtual resources according to the load capacity of each node. The security analysis and experiments are conducted to evaluate the performance of our proposed scheme. The evaluation results have proved the reliability and security of our scheme over existing methods.
Zhitao Guan, Naiyu Wang, Xunfeng Fan, Xueyan Liu 0007, Longfei Wu, Shaohua Wan 0001
ACM Trans. Internet Techn.1
2020 Autonomous and Privacy-preserving Energy Trading Based on Redactable Blockchain in Smart Grid
abstract
With the development of information and communication technologies in smart grid, peer-to-peer (P2P) energy trading for distributed energy resources (DER) has achieved an efficient two-way flow of information and power. The adoption of blockchain technology makes the P2P energy trading more secure and transparent. Considering that users with extra energy may be reluctant to participate in the energy trading due to privacy concerns, many researchers have focused on potential privacy issues. However, most of the existing works are built on top of a semi-decentralized energy blockchain in which only a few certified third-party nodes are authorized to manage and verify transactions - once these authorized nodes are attacked, the system will be threatened. In this paper, we use the Ciphertext Policy Attribute-Based Encryption (CP-ABE) scheme to establish a blockchain based P2P energy trading approach with privacy preservation, which allows peer nodes, including sellers and purchasers, to manage and verify transactions autonomously without needing any additional third-party nodes. In addition, we introduce the redactable blockchain technology into our scheme to ensure users can modify their sensitive information uploaded to the blockchain. Furthermore, we improve the CP-ABE scheme to provide low latency in the system. The experimental evaluations show that our scheme is efficient and practical.
Wenti Yang, Zhitao Guan, Longfei Wu, Xiaojiang Du, Zefang Lv, Mohsen Guizani
GLOBECOM2
2020 A Lightweight Attribute Based Encryption Scheme with Constant Size Ciphertext for Internet of Things
abstract
The Internet of Things technology has been used in a wide range of fields, ranging from industrial applications to individual lives. As a result, a massive amount of sensitive data is generated and transmitted by IoT devices. Those data may be accessed by a large number of complex users. Therefore, it is necessary to adopt an encryption scheme with access control to achieve more flexible and secure access to sensitive data. The Ciphertext Policy Attribute-Based Encryption (CP-ABE) can achieve access control while encrypting data can match the requirements mentioned above. However, the long ciphertext and the slow decryption operation makes it difficult to be used in most IoT devices which have limited memory size and computing capability. This paper proposes a modified CP-ABE scheme, which can implement the full security (adaptive security) under the access structure of AND gate. Moreover, the decryption overhead and the length of ciphertext are constant. Finally, the analysis and experiments prove the feasibility of our scheme.
Wenti Yang, Ruimiao Wang, Zhitao Guan, Longfei Wu, Xiaojiang Du, Mohsen Guizani
ICC3
2020 A Differentially Private Classification Algorithm With High Utility for Wireless Body Area Networks
abstract
The advancement of the wireless body area networks (WBAN) and sensor technologies allows us to collect a variety of physiological and behavioral data from human body. And appropriate application of machine learning methods can greatly promote the development of e-health. Nevertheless, the collected data contains personal privacy information. When using the machine learning methods to analyze the collected data, some information of the training data will be stored in the learning models unconsciously. To handle such information disclosure problem, we propose a differentially private classification algorithm based on ensemble decision tree with high utility for wireless body area networks. In order to improve the accuracy and stableness of classification, the bagging framework of ensemble learning is used in our algorithm. We aggregate the results of multiple private decision trees as the final classification in a weight-based voting way. For each private decision tree trained on the bootstrap samples, we offer a novel privacy budget allocation strategy that allows the nodes in larger depth to get more privacy budget, which can mitigate the problem of excessive noise introduced to leaf nodes to some extent. The better classification accuracy and stableness of this new algorithm, especially on small dataset, are demonstrated by simulation experiments.
Xianwen Sun, Lingyun Shi, Longfei Wu, Zhitao Guan, Xiaojiang Du, Mohsen Guizani
WCNC4
2020 A differentially private greedy decision forest classification algorithm with high utility
Zhitao Guan, Xianwen Sun, Lingyun Shi, Longfei Wu, Xiaojiang Du
Comput. Secur.1
2020 Towards secure and efficient energy trading in IIoT-enabled energy internet: A blockchain approach
Zhitao Guan, Naiyu Wang, Jun Wu 0001, Xiaojiang Du, Mohsen Guizani
Future Gener. Comput. Syst.1
2020 Cross-lingual multi-keyword rank search with semantic extension over encrypted data
Zhitao Guan, Xueyan Liu 0007, Longfei Wu, Jun Wu 0001, Ruzhi Xu, Jinhu Zhang, Yuanzhang Li 0001
Inf. Sci.1
2019 An Efficient and Privacy-Preserving Energy Trading Scheme Based on Blockchain
abstract
Distributed transaction model has gradually replaced the traditional centralized transaction model and has become the leading direction of development in energy trading. As the underlying support, blockchain technology is attracting more and more attention due to its advantages, i.e., integrity and non-repudiation. However, most blockchain-based trading models face the problem of privacy protection. In this paper, to solve this problem, Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is introduced as the core algorithm to reconstruct the transaction model. Specifically, we build a general model for distributed transaction called PP-BCTS (Privacy- Preserving Blockchain Trading Scheme). It can achieve fine-grained access control through transaction arbitration in ciphertext form. This design can maximize the protection of private information and can greatly improve the security and reliability of the transaction model. Additionally, a credibility-based equity proof consensus mechanism is proposed in PP-BCTS, which can greatly improve the operational efficiency. Security analysis and experimental evaluations are conducted to prove the validity and practicability of our proposed scheme.
Zhitao Guan, Xiao Zhou 0025, Longfei Wu, Xiaojiang Du, Mohsen Guizani
GLOBECOM2
2019 Achieving Secure and Efficient Cloud Search Services: Cross-Lingual Multi-Keyword Rank Search Over Encrypted Cloud Data
abstract
Multi-user multi-keyword ranked search scheme in arbitrary language is a novel multi-keyword rank searchable encryption (MRSE) framework based on Paillier Cryptosystem with Threshold Decryption (PCTD). Compared to previous MRSE schemes constructed based on the k-nearest neighbor searchable encryption (KNN-SE) algorithm, it can mitigate some drawbacks and achieve better performance in terms of functionality and efficiency. Additionally, it does not require a predefined keyword set and support keywords in arbitrary languages. However, due to the pattern of exact matching of keywords in the new MRSE scheme, multilingual search is limited to each language and cannot be searched across languages. In this paper, we propose a cross-lingual multi-keyword rank search (CLRSE) scheme which eliminates the barrier of languages and achieves semantic extension with using the Open Multilingual Wordnet. Our CLRSE scheme also realizes intelligent and personalized search through flexible keyword and language preference settings. We evaluate the performance of our scheme in terms of security, functionality, precision and efficiency, via extensive experiments.
Xueyan Liu 0007, Zhitao Guan, Xiaojiang Du, Longfei Wu, Zain Ul Abedin, Mohsen Guizani
ICC2
2019 Efficient Electric Vehicles Assignment for Platoon-based Charging
abstract
To fulfil the increasing charging requests of Electric Vehicles (EVs), various means have been proposed such as improving charging efficiency at charging stations, optimal locating of charging stations, enabling V2V trading and so on. Most existing work requires vehicles to be stationary while being charged. Mobile wireless charging is a promising trend to fix this problem since vehicles can perform moving and charging simultaneously. In this paper, a new concept called platoon-based charging is presented, which combines the energy-aware driving and mobile charging. In the design, an EV may have to detour to follow the platoon. To minimize the additional energy cost and delay brought by that, we studied the optimal assignment problem between EVs and charging platoons and converted it to a dynamic weight bipartite matching. The experiment results show that our algorithm outperforms the exiting ones.
Peng Liu 0027, Zhitao Guan
WCNC4
2019 EFFECT: an efficient flexible privacy-preserving data aggregation scheme with authentication in smart grid
Zhitao Guan, Yue Zhang 0027, Liehuang Zhu, Longfei Wu, Shui Yu 0001
Sci. China Inf. Sci.1
2019 Achieving differential privacy against non-intrusive load monitoring in smart grid: A fog computing approach
abstract
Summary Fog computing, a non‐trivial extension of cloud computing to the edge of the network, has great advantage in providing services with a lower latency. In smart grid, the application of fog computing can greatly facilitate the collection of consumer's fine‐grained energy consumption data, which can then be used to draw the load curve and develop a plan or model for power generation. However, such data may also reveal customer's daily activities. Non‐intrusive load monitoring (NILM) can monitor an electrical circuit that powers a number of appliances switching on and off independently. If an adversary analyzes the meter readings together with the data measured by an NILM device, the customer's privacy will be disclosed. In this paper, we propose an effective privacy‐preserving scheme for electric load monitoring, which can guarantee differential privacy of data disclosure in smart grid. In the proposed scheme, an energy consumption behavior model based on Factorial Hidden Markov Model (FHMM) is established. In addition, noise is added to the behavior parameter, which is different from the traditional methods that usually add noise to the energy consumption data. The analysis shows that the proposed scheme can get a better trade‐off between utility and privacy compared with other popular methods.
Longfei Wu, Zhitao Guan, Xiaojiang Du
Concurr. Comput. Pract. Exp.4
2019 Achieving data utility-privacy tradeoff in Internet of Medical Things: A machine learning approach
Zhitao Guan, Zefang Lv, Xiaojiang Du, Longfei Wu, Mohsen Guizani
Future Gener. Comput. Syst.1
2019 APPA: An anonymous and privacy preserving data aggregation scheme for fog-enhanced IoT
Zhitao Guan, Yue Zhang 0027, Longfei Wu, Jun Wu 0001, Jing Li 0006, Yinglong Ma 0001
J. Netw. Comput. Appl.1
2019 Achieving Privacy-Friendly Storage and Secure Statistics for Smart Meter Data on Outsourced Clouds
abstract
Smart meters have already been widely used for electric utilities to provide reliable power service. Since those meters keep reporting customer's energy consumption data in minute-level or even second-level, Terabyte-level big data has to be stored and analyzed for the companies. To relieve the storage and computation pressure, some companies attempt to outsource their data on the cloud. However, this exposes customer's privacy at risk, because customer's activities can be inferred from analyzing the meter readings. In this paper, we propose a privacy-friendly cloud storage (PCS) scheme and three secure cloud statistic (SCS) schemes for smart meter data on outsourced clouds. Putting these schemes together achieves three queries from the electric companies. Next, we provably analyze the privacy and the security for these schemes. Finally, we design MapReduce algorithms to show the performance for the cloud statistic.
Zijian Zhang 0001, Mianxiong Dong, Liehuang Zhu, Zhitao Guan, Ruoyu Chen 0002, Rixin Xu, Kaoru Ota
IEEE Trans. Cloud Comput.4
2018 A Multi-Feature Based Automatic Approach to Geospatial Record Linking
abstract
This article describes how geographic information systems (GISs) can enable, enrich and enhance geospatial applications and services. Accurate calculation of the similarity among geospatial entities that belong to different data sources is of great importance for geospatial data linking. At present, most research works use the name or category of the entity to measure the similarity of geographic information. Although the geospatial relationship is significant for geographic similarity measure, it has been ignored by most of the previous works. This article introduces the geospatial relationship and topology, and proposes an approach to compute the geospatial record similarity based on multiple features including the geospatial relationships, category and name tags. In order to improve the flexibility and operability, supervised machine learning such as SVM is used for the task of classifying pairs of mapping records. The authors test their approach using three sources, namely, OpenStreetMap, Google and Wikimapia. The results showed that the proposed approach obtained high correlation with the human judgements.
Ying Zhang 0010, Puhai Yang, Chaopeng Li, Zhitao Guan
Int. J. Semantic Web Inf. Syst.8
2018 Big Data Analysis-Based Secure Cluster Management for Optimized Control Plane in Software-Defined Networks
abstract
In software-defined networks (SDNs), the abstracted control plane is its symbolic characteristic, whose core component is the software-based controller. The control plane is logically centralized, but the controllers can be physically distributed and composed of multiple nodes. To meet the service management requirements of large-scale network scenarios, the control plane is usually implemented in the form of distributed controller clusters. Cluster management technology monitors all types of events and must maintain a consistent global network status, which usually leads to big data in SDNs. Simultaneously, the cluster security is an open issue because of the programmable and dynamic features of SDNs. To address the above challenges, this paper proposes a big data analysis-based secure cluster management architecture for the optimized control plane. A security authentication scheme is proposed for cluster management. Moreover, we propose an ant colony optimization approach that enables big data analysis scheme and the implementation system that optimizes the control plane. Simulations and comparisons show the feasibility and efficiency of the proposed scheme. The proposed scheme is significant in improving the security and efficiency SDN control plane.
Jun Wu 0001, Mianxiong Dong, Kaoru Ota, Jianhua Li 0001, Zhitao Guan
IEEE Trans. Netw. Serv. Manag.5
2017 Protecting user privacy based on secret sharing with fault tolerance for big data in smart grid
abstract
In smart grid, large quantities of data is collected from various applications, such as smart metering substation state monitoring, electric energy data acquisition, and smart home. Big data acquired in smart grid applications is usually sensitive. For instance, in order to dispatch accurately and support the dynamic price, lots of smart meters are installed at user's house to collect the real-time data, but all these collected data are related to user privacy. In this paper, we propose a data aggregation scheme based on secret sharing with fault tolerance in smart grid, which ensures that control center gets the integrated data without revealing user's privacy. Meanwhile, we also consider fault tolerance during the data aggregation. At last, we analyze the security of our scheme and carry out experiments to validate the results.
Zhitao Guan, Guanlin Si, Xiaojiang Du, Peng Liu 0027, Zijian Zhang 0001, Zhenyu Zhou 0001
ICC1
2017 An efficient encryption scheme with verifiable outsourced decryption in mobile cloud computing
abstract
With the increasing number of mobile applications and the popularity of cloud computing, the combination of these two techniques that named mobile cloud computing (MCC) attracts great attention in recent years. A promising public key encryption scheme, Attribute-Based Encryption (ABE), especially the Ciphertext Policy Attribute-Based Encryption (CP-ABE), has been used for realizing fine-grained access control on encrypted data stored in MCC. However, the computational overhead of encryption and decryption grow with the complexity of the access policy. Thus, maintaining data security as well as efficiency of data processing in MCC are important and challenging issues. In this paper, we propose an efficient encryption method based on CP-ABE, which can lower the overhead on data owners. To further reduce the decryption overhead on data receivers, we additionally propose a verifiable outsourced decryption scheme. By security analysis and performance evaluation, the proposed scheme is proved to be secure as well as efficient.
Jing Li 0006, Zhitao Guan, Xiaojiang Du, Zijian Zhang 0001, Jun Wu 0001
ICC2
2017 Privacy-Preserving and Traceable Data Aggregation in Energy Internet
Yue Zhang 0027, Zhitao Guan
MSN2
2017 A Low-Latency Secure Data Outsourcing Scheme for Cloud-WSN
abstract
With the support of cloud computing, large quantities of data collected from various WSN applications can be managed efficiently. However, maintaining data security and efficiency of data processing in cloud- WSN (C-WSN) are important and challenging issues. In this paper, we present an efficient data outsourcing scheme based on CP-ABE, which can not only guarantee secure data access, but also reduce overall data processing time. In our proposed scheme, a large file is divided into several data blocks by data owner (DO) firstly. Then, the data blocks are encrypted and transferred to the cloud server in parallel. For data receiver (DR), data decryption and data transmission is also processed in parallel. In addition, data integrity can be checked by DR without any master key components. The security analysis shows that the proposed scheme can meet the security requirement of C-WSN. By performance evaluation, it shows that our scheme can dramatically improve data processing efficiency compared to the traditional CP-ABE method.
Jing Li 0006, Zhitao Guan, Xiaojiang Du, Zijian Zhang 0001, Zhenyu Zhou 0001
WCNC2
2017 Achieving Efficient and Secure Data Acquisition for Cloud-Supported Internet of Things in Smart Grid
abstract
Cloud-supported Internet of Things (Cloud-IoT) has been broadly deployed in smart grid systems. The IoT front-ends are responsible for data acquisition and status supervision, while the substantial amount of data is stored and managed in the cloud server. Achieving data security and system efficiency in the data acquisition and transmission process are of great significance and challenging, because the power grid-related data is sensitive and in huge amount. In this paper, we present an efficient and secure data acquisition scheme based on ciphertext policy attribute-based encryption. Data acquired from the terminals will be partitioned into blocks and encrypted with its corresponding access subtree in sequence, thereby the data encryption and data transmission can be processed in parallel. Furthermore, we protect the information about the access tree with threshold secret sharing method, which can preserve the data privacy and integrity from users with the unauthorized sets of attributes. The formal analysis demonstrates that the proposed scheme can fulfill the security requirements of the Cloud-IoT in smart grid. The numerical analysis and experimental results indicate that our scheme can effectively reduce the time cost compared with other popular approaches.
Zhitao Guan, Jing Li 0006, Longfei Wu, Yue Zhang 0027, Jun Wu 0001, Xiaojiang Du
IEEE Internet Things J.1
2017 Toward Delay-Tolerant Flexible Data Access Control for Smart Grid With Renewable Energy Resources
abstract
In the smart grid with renewable energy resources (RERs), the residential units (RUs) with distributed energy resources are considered to be both power consumers and suppliers. Specifically, RUs with excessive renewable generations can trade with the utility in deficit of power supplies for mutual benefits. It causes two challenging issues. First, the trading data of RUs are quite sensitive, which should be only accessed by authorized users with fine-grained policies. Second, the behaviors of the RUs to generate trading data are spontaneous and unpredictable, and then the problem is how to guarantee system efficiency and delay tolerance simultaneously. In this paper, we propose a delay-tolerant flexible data access control scheme based on key policy attribute-based encryption for smart grid with RERs. We adopt the secret-sharing scheme to realize a flexible access control with encryption delay tolerance. Furthermore, there is no central trusted server to perform the encryption/decryption. We reduce the computation cost on RUs and operators via a semitrusted model. The analysis shows that the proposed scheme can meet the data security requirement of the smart grid with RERs, and it also has less cost compared with other popular models.
Zhitao Guan, Jing Li 0006, Liehuang Zhu, Zijian Zhang 0001, Xiaojiang Du, Mohsen Guizani
IEEE Trans. Ind. Informatics1
2016 Secure data access for wireless body sensor networks
abstract
Recently, with the support of mobile cloud computing, large number of health-related data collected from various body sensor networks can be managed efficiently. However, it is an important and challenging issue to keep data security and data privacy in cloud-integrated body sensor network (C-BSN). In this paper, we present a novel secure access control mechanism MC-ABE (Mask Certificate-Attribute Based Encryption) for cloud-integrated body sensor networks. A specific signature is designed to mask the plaintext, then the masked data can be securely outsourced to cloud severs. An authorization certificate composing of the signature and related privilege items is constructed that is used to grant privileges to data receivers. To ensure security, a unique value is chosen to mask the certificate for each data receiver. The analysis shows that the proposed scheme has less computation cost and storage cost compared with other popular models.
Zhitao Guan, Xiaojiang Du, Mohsen Guizani
WCNC1