Tianbo Wang 0001

dblp:155/0398-1 · DBLP profile ↗
← Back
35ranked-venue papers
7as first author
28since 2021 · last 2026
0000-0002-0227-9557ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 3 first-author · 11 since 2021Systems, architecture and hardware · 6 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 5 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 3 since 2021Computer networks · 3 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 CASET: a cascaded attention-based framework for semantic explainability of toxicity in large language models
Chen Chen 0098, Hanyang Xia, Weidong Zhou 0001, Chunhe Xia, Mengyao Liu 0001, Tianbo Wang 0001
Appl. Intell.7
2026 A multi-scale representation and multi-level decision learning network for multimodal sentiment analysis
Xiang Li 0117, Zhiqiang Dong, Xianfu Cheng, Dezhuang Miao, Haijun Zhang 0007, Tianbo Wang 0001, Xiaoming Zhang 0001, Zhoujun Li 0001
Expert Syst. Appl.6
2026 Enhancing large language model for fake news video detection via cross-modal retrieval
Linfeng Han, Tianbo Wang 0001, Zhiqiang Dong
Inf. Process. Manag.3
2026 LogMUSE: Log Anomaly Detection via Multi-Scale Semantic Representation
abstract
Logs serve as an effective data source for recording and judging system states and abnormal events in complex systems. Current deep learning-based methods have proven effective in detecting anomalies in these system logs. However, existing anomaly detection methods, which predominantly rely on template-based and global window-based approaches, still face challenges in terms of flexibility and practicality. Template-based methods, while widely adopted for their simplicity and efficiency, overlook parameter information and fail to capture the true execution semantics. And global window-based methods, despite their effectiveness in modeling global dependencies, cannot simultaneously capture both global and local dependencies, leading to the obscuration of important local features. To address these issues, we propose aLoganomaly detection method based onMUlti-scaleSEmantic representation,LogMUSE. Specifically, LogMUSE obtains template and parameter information through log parsing, employs a pre-trained Bidirectional Encoder Representations from Transformers (BERT) model for template semantic embedding, and enhances log entry representations via cross-attention mechanisms to effectively capture different parameter features under the same template. Additionally, we design the multi-scale Transformer model to capture global and local anomaly patterns, which enable fixed-length log sequences to focus on features at different scales. Extensive experiments on real-world benchmark datasets, including BGL, Thunderbird and Spirit, show that LogMUSE outperforms existing methods in log anomaly detection, achieving F1-scores of 98.62%, 94.32%, and 99.20% respectively. These results surpass the performance of current state-of-the-art methods and demonstrate the strong generalization across different system scenarios.
Mengyao Liu 0001, Tianbo Wang 0001, Chunhe Xia, Yingming Zeng
IEEE Trans. Serv. Comput.2
2025 FBChain: A Blockchain-Based Federated Learning Model with Communication Efficiency Consensus Algorithm
Yang Li 0222, Chunhe Xia, Tianbo Wang 0001
ICA3PP (6)3
2025 SERA: Semantic Entity Recognition and Alignment for Threat Intelligence Representation
abstract
With the increasing sophistication of cyber attacks, traditional defense mechanisms have become inadequate due to information asymmetry between attackers and defenders. While threat intelligence sharing helps bridge this gap, existing entity recognition methods face two critical challenges: (1) difficulty in handling domain-specific features and entity ambiguity in cybersecurity texts; and (2) ineffective alignment of heterogeneous entities across multi-source threat intelligence. To address these issues, we propose the Semantic Entity Recognition and Alignment (SERA) framework, which employs SecureBERT to construct security-domain semantic representations and learn specialized threat intelligence features. The framework combines bidirectional long short-Term memory (BiLSTM) to capture contextual dependencies, incorporates an attention mechanism to enhance key semantic modeling, and finally utilizes a Conditional Random Field (CRF) layer to improve label sequence consistency. To resolve entity naming inconsistencies and representation redundancy, we integrate three types of information—semantic similarity, structural embedding similarity, and contextual similarity—and perform multi-source entity alignment through weighted scoring, effectively improving cross-source entity unification. Experimental results on the DNRTI dataset demonstrate that the SERA model achieves superior performance compared to baseline models, with an F1-score of 0.7821, precision of 0.7625, recall of 0.8152, and entity recognition accuracy of 0.9387.
Tianbo Wang 0001, Chunhe Xia, Yingming Zeng, Ruidong Wang 0001
TrustCom2
2025 Enhancing encrypted traffic analysis via source APIs: A robust approach for malicious traffic detection
Wanshuang Lin, Chunhe Xia, Tianbo Wang 0001, Mengyao Liu 0001, Yang Li 0222
Comput. Secur.3
2025 HIDIM: A novel framework of network intrusion detection for hierarchical dependency and class imbalance
Weidong Zhou 0001, Chunhe Xia, Tianbo Wang 0001, Xiaopeng Liang, Wanshuang Lin, Xiaojian Li 0002
Comput. Secur.3
2025 BRFL: A blockchain-based byzantine-robust federated learning model
Yang Li 0222, Chunhe Xia, Tianbo Wang 0001
J. Parallel Distributed Comput.4
2025 HHG-Bot: A Hyperheterogeneous Graph-Based Twitter Bot Detection Model
abstract
Detecting Twitter bots is essential for combating misinformation and maintaining the integrity of online social networks. Existing methods often overlook the high-order interactions and heterogeneous relationships among users and tweets, limiting their effectiveness in addressing sophisticated bot behaviors. This article introduces HHG-Bot, a novel hyper-heterogeneous graph-based framework for Twitter bot detection. The proposed approach integrates heterogeneous graph convolutional networks with a trainable hypergraph aggregation model to capture complex, high-order interactions. To overcome the challenge of labeled data scarcity, HHG-Bot employs a meta-learning paradigm that enhances the model’s generalization capability across different bot types. Experiments conducted on the Twibot-20 benchmark dataset demonstrate that HHG-Bot achieves state-of-the-art performance, surpassing existing methods in terms of accuracy (86.17%), F1-score (87.51%), and Matthews correlation coefficient (MCC) (71.75%). The results validate the effectiveness of leveraging hypergraphs and meta-learning for detecting Twitter bots, particularly in scenarios with limited labeled data.
Tianbo Wang 0001, Huacheng Li, Chunhe Xia
IEEE Trans. Comput. Soc. Syst.1
2025 ArchSentry: Enhanced Android Malware Detection via Hierarchical Semantic Extraction
abstract
Android malware poses a significant challenge for mobile platforms. To evade detection, contemporary malware variants use API substitution or obfuscation techniques to hide malicious activities and mask their shallow semantic characteristics. However, existing research lacks analysis of the hierarchical semantic associated with Android apps. To address this problem, we propose ArchSentry, an enhanced Android malware detection via hierarchical semantic extraction. First, we select entities and their relationships relevant to Android software behavior through the software architecture and represent them using a heterogeneous graph. Then, we structure meta-paths to represent rich semantic information to achieve semantic enhancement and improve efficiency. Next, we design a meta-path semantic selection method based on KL Divergence to identify and eliminate redundant features. To achieve a comprehensive representation of the overall software semantics and improve performance, we construct a feature fusion approach based on Restricted Boltzmann Machines (RBM) and AutoEncoder (AE) during the pre-training phase, while preserving the probability distribution characteristics of various meta-paths. Finally, Deep Neural Networks (DNN) process fusion features for comprehensive feature sets. Experimental results on real-world application samples indicate that ArchSentry achieves a remarkable 99.2% detection rate for Android malware, with a low false positive rate below 1%. These results surpass the performance of current state-of-the-art approaches.
Tianbo Wang 0001, Mengyao Liu 0001, Huacheng Li, Lei Zhao 0012, Changnan Jiang, Chunhe Xia, Baojiang Cui
IEEE Trans. Netw. Serv. Manag.1
2024 FedDRC: A Robust Federated Learning-based Android Malware Classifier under Heterogeneous Distribution
abstract
In the traditional centralized Android malware classification framework, privacy concerns exist due to collected users’ apps containing sensitive information. A new classification framework based on Federated Learning (FL) has emerged to protect privacy. However, significant spatiotemporal heterogeneity exists in the distribution of Android malware samples in different clients. It presents a huge challenge to existing FL schemes, as trained local models differ significantly, resulting in slower model convergence and lower classification accuracy. To bridge this gap, we propose FedDRC, a robust FL-based Android malware classifier. First, we design a functional semantic embedding mechanism of API features, FSEM, using word embedding to improve the robustness of the model to the time heterogeneity of the client’s samples. Secondly, we use the idea of Information Bottleneck (IB) and transfer learning to design a robust local model, PAMIB, to deal with the model degradation caused by the space heterogeneity of the distribution of client samples. Extensive experiments on the Androzoo dataset show that FedDRC has the best robustness for Android malware classification tasks in various heterogeneity distribution settings: fastest convergence and best classification accuracy.
Changnan Jiang, Chunhe Xia, Mengyao Liu 0001, Chen Chen 0098, Huacheng Li, Tianbo Wang 0001
CSCWD6
2024 Multi-Signal Fusion of Social Diffusion Graph with Bi-Directional Semantic Consistency
abstract
Devising diffusion graph to learn user representations is a crucial step in studying information propagation prediction. However, previous works mainly focused on structural and temporal features. To better incorporate content features, we introduce the Backward Decomposition and Forward Preservation mechanisms. The former involves decomposing content features for initializing node signals in the diffusion graph, thus fusing user features with content features. The latter aims to maintain node features generated by graph encoder consistent with the original content features. A series of experiments demonstrate that our model outperforms state-of-the-art models, and both mechanisms significantly enhance the prediction performance. Furthermore, our methods enables the features generated by the diffusion graph to more effectively incorporate features from various semantic spaces, whether encoded by language models or generated by graph embedding algorithms.
Huacheng Li, Chunhe Xia, Tianbo Wang 0001, Wanshuang Lin, Changnan Jiang, Chen Chen 0098
ICASSP3
2024 FedDADP: A Privacy-Risk-Adaptive Differential Privacy Protection Method for Federated Android Malware Classifier
abstract
The federated Android malware classifier has attracted much attention owing to its advantages of privacy protection and multi-party joint modeling. However, the research indicates that the gradient transmitted within the federated classifier still encodes the user's sensitive information, exposing it to indirect privacy inference threats from curious servers. Differential privacy is a recognized and effective way to address this privacy breach threat by adding noise to the user's model parameters to limit the attacker's inference of sensitive information. However, the protection effect of existing differential privacy methods is at the cost of significantly reducing the model's classification accuracy, and it cannot be reasonably balanced. To address this challenge, we propose a privacy protection method, FedDADP. FedDADP performs adaptive, lightweight privacy configuration in its training time dimension and model space dimension according to the privacy risk distribution law in the federated Android malware classifier to protect users' privacy while maintaining the model's utility. Numerous experiments on the Androzoo dataset and multiple baseline classifiers show that FedDADP protects users' sensitive information better (7% more effectiveness against adversaries' inference) than baseline differential privacy methods and achieves better model utility (classification accuracy improves by about 8%) with the same privacy budget.
Changnan Jiang, Chunhe Xia, Mengyao Liu 0001, Huacheng Li, Tianbo Wang 0001
IJCNN7
2024 Few-shot Encrypted Malicious Traffic Classification via Hierarchical Semantics and Adaptive Prototype Learning
abstract
While encrypted traffic improves security, it is also used by attackers to hide the transmission content to evade detection. Currently, traffic side-channel features combined with Deep Learning (DL) are widely used for malicious traffic classification, but traditional DL-based methods require large training samples and struggle with new threats. Prototypical networks in meta-learning have been effective in few-shot malicious traffic classification. However, existing methods face challenges such as "overlooking hierarchical traffic dependencies" and "bias in class prototype generation". The former means that the existing methods lack the representation design based on the hierarchical structure of traffic, resulting in insufficient feature extraction, and the latter indicates that the existing methods struggle to capture the diverse distribution of traffic features, resulting in unstable classification performance. To address the above problems, this paper proposes a few-shot encrypted malicious traffic classification method based on Hierarchical Semantics and Adaptive Prototype Learning Network (HANet). First, network traffic’s fine-grained features are represented in a multi-level matrix, with a hierarchical network structure designed to extract features comprehensively. Then, class prototypes are dynamically generated using a neighborhood partitioning method to balance simple and complex traffic feature distributions, enhancing generalization. Experiments on the CICandMal2017 dataset show that HANet offers significant performance over other few-shot malicious traffic classification methods. HANet has achieved a classification accuracy of more than 80% with only 5, 10, and 15 labeled traffic samples, realizing effective detection of few-shot encrypted malicious traffic.
Chunhe Xia, Tianbo Wang 0001, Mengyao Liu 0001, Yang Li 0222
TrustCom3
2024 AIDE: Attack Inference Based on Heterogeneous Dependency Graphs with MITRE ATT&CK
Weidong Zhou 0001, Chunhe Xia, Xinyi Pan, Tianbo Wang 0001, Xiaojian Li 0002
TrustCom5
2024 HL-DPoS: An enhanced anti-long-range attack DPoS algorithm
Yang Li 0222, Chunhe Xia, Chen Chen 0098, Tianbo Wang 0001
Comput. Networks6
2024 Secure Data Integrity Check Based on Verified Public Key Encryption With Equality Test for Multi-Cloud Storage
abstract
Cloud computing eliminates the need for local hardware, addressing the challenge of high computing expenses. However, entrusting data to the cloud may pose the risk of unintentional data loss. Using multiple copies and multi-cloud servers is promising because even if the data on one cloud storage server is compromised, the data proprietor can retrieve the information from alternate cloud storage servers. To protect data security, data needs to be encrypted before uploading to the cloud. However, users cannot directly confirm whether their encrypted documents and copies are stored securely and with integrity on cloud servers. To verify data copies on remote servers without downloading and decrypting, we propose Public Verification Public Key Encryption with Equality Test (PVPKEET). Under PVPKEET, users upload encrypted data to cloud servers, and then the test result and proof will be provided by the cloud server without decryption. The publicly verified proof can be examined by all users, allowing everyone to witness the copies stored correctly. Our approach is resistant to chosen-plaintext attacks and is verifiable. A comparison with prior research demonstrates the efficiency and feasibility of our design.
Willy Susilo, Chunhe Xia, Luqi Huang, Fuchun Guo, Tianbo Wang 0001
IEEE Trans. Dependable Secur. Comput.6
2024 GRASS: Learning Spatial-Temporal Properties From Chainlike Cascade Data for Microscopic Diffusion Prediction
abstract
Information diffusion prediction captures diffusion dynamics of online messages in social networks. Thus, it is the basis of many essential tasks such as popularity prediction and viral marketing. However, there are two thorny problems caused by the loss of spatial-temporal properties of cascade data: "position-hopping" and "branch-independency." The former means no exact propagation relationship between any two consecutive infected users. The latter indicates that not all previously infected users contribute to the prediction of the next infected user. This article proposes the GRU-like Attention Unit and Structural Spreading (GRASS) model for microscopic cascade prediction to overcome the above two problems. First, we introduce the attention mechanism into the gated recurrent unit (GRU) component to expand the restricted receptive field of the recurrent neural network (RNN)-type module, thus addressing the "position-hopping" problem. Second, the structural spreading (SS) mechanism leverages structural features to filter out related users and controls the generation of cascade hidden states, thereby solving the "branch-independency" problem. Experiments on multiple real-world datasets show that our model significantly outperforms state-of-the-art baseline models on both hits@κ and map@κ metrics. Furthermore, the visualization of latent representations by t-distributed stochastic neighbor embedding (t-SNE) indicates that our model makes different cascades more discriminative during the encoding process.
Huacheng Li, Chunhe Xia, Tianbo Wang 0001, Peng Cui 0001, Xiaojian Li 0002
IEEE Trans. Neural Networks Learn. Syst.3
2023 FedDroidADP: An Adaptive Privacy-Preserving Framework for Federated-Learning-Based Android Malware Classification System
Changnan Jiang, Chunhe Xia, Zhuodong Liu, Tianbo Wang 0001
KSEM (3)4
2023 EFwork: An Efficient Framework for Constructing a Malware Knowledge Graph
abstract
Malware Knowledge Graph (MKG) serves as an essential auxiliary tool for malware detection and analysis. However, the construction of MKG faces several challenges, such as inadequate dataset quality, incomplete entity feature extraction, and the limitations imposed by deep learning techniques. To address these issues, we present an Efficient Framework for constructing a malware knowledge graph (EFwork). Firstly, we build a High-Quality Dataset (HQDataset) and introduce a metric for data quality assessment based on knowledge coverage, timeliness, and density. Subsequently, we develop a Named Entity Recognition (NER) model that extracts character features, part-of-speech features, and word features from the data, leveraging deep learning models to identify malware-related entities. Finally, we implement a rule-based filtering mechanism, utilizing a comprehensive Rule Database to eliminate entities that do not conform to predefined rules. Experimental result shows that our HQDataset demonstrates superior data quality when compared to other open-source datasets. Furthermore, our NER model combined with our Rule Database outperforms existing models, achieving improvements of 0.67%, 0.74%, and 0.69% in Precision, Recall, and F1-Score, respectively.
Chen Chen 0098, Chunhe Xia, Tianbo Wang 0001, Wanshuang Lin, Yang Li 0222
TrustCom3
2023 FedDLM: A Fine-Grained Assessment Scheme for Risk of Sensitive Information Leakage in Federated Learning-based Android Malware Classifier
abstract
In the traditional centralized Android malware classification framework, privacy concerns arise as it requires collecting users’ app samples containing sensitive information directly. To address this problem, new classification frameworks based on Federated Learning (FL) have emerged for privacy preservation. However, research shows that these frameworks still face risks of indirect information leakage due to adversary inference. Unfortunately, existing research lacks an effective assessment of the extent and location of this leakage risk. To bridge the gap, we propose the FedDLM, which provides a fine-grained assessment of the risk of sensitive information leakage in an FL-based Android malware classifier. FedDLM estimates attackers’ theoretical maximum inference ability from the information theory perspective to gauge the degree of leakage risk in the classifier effectively. It precisely identifies critical positions in the shared gradient where the leakage risk exists by utilizing characteristics of class activation in classifiers. Through extensive experiments on the Androzoo dataset, FedDLM demonstrates its superior effectiveness and precision compared to baseline methods in evaluating the risk of sensitive information leakage. The evaluation results provide valuable insights into information leakage problems in classifiers and targeted privacy protection methods.
Changnan Jiang, Chunhe Xia, Chen Chen 0098, Huacheng Li, Tianbo Wang 0001, Xiaojian Li 0002
TrustCom5
2023 REDA: Malicious Traffic Detection Based on Record Length and Frequency Domain Analysis
abstract
The TLS encryption protocol plays a vital role in securing data transmission, but it also presents challenges for payload-based Network Intrusion Detection Systems (NIDS). Existing methods utilize statistical characteristics of side-channel features, such as the mean packet length, to identify encrypted traffic. However, packet lengths are constrained by the Maximum Segment Size (MSS) of the TCP protocol. This constraint causes the length-varied sequence to be encapsulated into segments of equal length, resulting in information loss. Moreover, flow-level statistical features are vulnerable to interference from noisy packets, making it challenging to detect malicious traffic injected with benign packets effectively. In this paper, we propose an encrypted traffic detection model based on Record length and frEquency Domain Analysis (REDA). First, we reconstruct the TLS Record Length Sequence (TRLS), which is a length-varied sequence, to capture differences in traffic content during transmission. Second, we employ the Discrete Fourier Transform (DFT) to extract frequency domain features of the TRLS, which are resistant to attacker interference. Finally, an improved One-Class Support Vector Machine (OCSVM) algorithm is devised for the unsupervised detection of malicious traffic, enabling the identification of unknown attacks. Experiments show that REDA is superior to other state-of-the-art methods in terms of accuracy by 2.44%.
Wanshuang Lin, Chunhe Xia, Tianbo Wang 0001, Chen Chen 0098, Weidong Zhou 0001
TrustCom3
2023 HF-Mid: A Hybrid Framework of Network Intrusion Detection for Multi-type and Imbalanced Data
abstract
The data-driven deep learning methods have brought significant progress and potential to intrusion detection. However, there are two thorny problems caused by the characteristics of intrusion data: "multi-type features" and "data imbalance". The former means that forcefully and improperly transforming intrusion features from distinct metric spaces can result in semantic loss and noise. The latter indicates that the intrusion data is imbalanced in quantity and quality due to its complex spatial distribution. We propose a Hybrid Framework for Multi-type and Imbalance Data (HF-Mid) to address the above two problems. Firstly, we divide the intrusion features into equivalent and non-equivalent groups, and then embed them sequentially using Supervised Paragraph Vector-Distributed Memory (SPV-DM), which excels at modeling co-occurrence relationships, and Deep Neural Network (DNN), which is suitable for modeling non-linear relationships, thereby solving the "multitype features" problem. Secondly, we adopt a low-noise collective matrix factorization (CMF) model to fuse the two obtained features for dimensionality reduction. Finally, we employ a multiple classifier to detect intrusion. During the classifier training stage, we design a genetic algorithm-based proportional sampling method to select high-quality samples in each training batch. thus addressing the "data imbalance" problem. The experimental results demonstrate the proposed framework exhibits an overall improvement of 5.9% and 1.5% in terms of accuracy and false positive rate on average, respectively.
Weidong Zhou 0001, Tianbo Wang 0001, Guotao Huang, Xiaopeng Liang, Chunhe Xia, Xiaojian Li 0002
TrustCom2
2023 From the Dialectical Perspective: Modeling and Exploiting of Hybrid Worm Propagation
abstract
The hierarchical network is the more effective platform, which provides multiple channels for various worm propagation. Thus, emerging worms can infect vulnerable hosts by scanning strategy and social media. However, the spread of scan-based worm is restrained due to uneven distribution of vulnerable hosts and NAT (Network Address Translation) technique. Meanwhile, topological dependency dictates to topology-based worm only infecting those hosts in social networks. To avoid their respective disadvantages, modern hybrid worm, which combines the above two propagation mechanisms, can implement efficient IP-address scanning by enhanced combination-scanning strategy, and spread more aggressively in social networks using enhanced reinfection mechanism. This paper presents a Hierarchical-Stochastic Propagation model to understand hybrid worm propagation. Inspired by hybrid worm, we design a new vaccine based on the Hierarchical-Measure Immunization strategy. For physical networking layer, we can estimate vulnerable-host distribution to find vulnerable hosts effectively through Maximum Likelihood estimation. For social networking layer, we use a novel propagation centrality measure to discover vital social nodes accurately. The experimental results show that our model can characterize the propagation mechanism of hybrid worms more comprehensively, and greatly outperforms state of the art models in terms of estimation accuracy. Meanwhile, our strategy is more effective to restrain the hybrid worm from spreading in networks.
Tianbo Wang 0001, Huacheng Li, Chunhe Xia, Han Zhang 0009, Pei Zhang 0003
IEEE Trans. Inf. Forensics Secur.1
2022 Applying Value-Based Deep Reinforcement Learning on KPI Time Series Anomaly Detection
abstract
Time series anomaly detection has become more critical with the rapid development of network technology, especially in cloud monitoring. We focus on applying deep reinforcement learning (DRL) in this question. It is not feasible to simply use the traditional value-based DRL method because DRL cannot accurately capture important time information in time series. Most of the existing methods resort to the RNN mechanism, which in turn brings about the problem of sequence learning. In this paper, we conduct progressive research work on applying value-based DRL in time series anomaly detection. Firstly, because of the poor performance of traditional DQN, we propose an improved DQN-D method, whose performance is improved by 62% compared with DQN. Second, for RNN-based DRL, we propose a method based on improved experience replay pool (DRQN) to make up for the shortcomings of existing work and achieve excellent performance. Finally, we propose a Transformer-based DRL anomaly detection method to verify the effectiveness of the Transformer structure. Experimental results show that our DQN-D can obtain performance close to RNN-based DRL, DRQN and DTQN perform well on the dataset, and all methods are proven effective.
Tianbo Wang 0001
CLOUD2
2022 Secure and Temporary Access Delegation With Equality Test for Cloud-Assisted IoV
abstract
With the continuous development of the Internet of Vehicles (IoV), the cloud-assisted IoV is becoming an emerging and attractive paradigm, in which a growing number of IoV users use the cloud server to store the data collected from their smart devices, thereby relieving local costs to a great extent. In this case, considering that the third-party cloud as a commercial mechanism cannot guarantee data security, users choose to encrypt their own data before uploading it to the cloud server. Although the privacy and confidentiality of the uploaded data can be protected, the encryption method hinders data search due to its inherent “decrypt all-or-nothing” feature. To achieve encryption and data search on privacy-preserving data, many existing works of literature design various public key encryption with keyword search schemes that, however, suffers the disadvantage that they can work only between ciphertext encrypted under the same public key, which means that it is not suitable for some computations on cloud. Furthermore, most schemes also have failed to find out how to delegate the searched data securely and efficiently when the data owner is not convenient to address the data. Therefore, this study tends to test the equivalence between messages encrypted under different public keys for basic secure computation and delegating the right of decrypting searched data to the specified user. Then, a lightweight proxy re-encryption scheme with the equality test and temporary delegation (PRE-ET-TD) was put forward for the cloud-assisted IoV. Besides, the proposed scheme is collusion-resistant and proven secure against chosen ciphertext attack (CCA) in the random oracle model. Meanwhile, the experimental simulation indicates that the presented PRE-ET-TD is feasible and efficient.
Chunhe Xia, Tianbo Wang 0001
IEEE Trans. Intell. Transp. Syst.4
2022 Epidemic Heterogeneity and Hierarchy: A Study of Wireless Hybrid Worm Propagation
abstract
With the growth in the use of smart mobile devices and the development of information technologies, worms and malware can spread from mobile networks into heterogeneous and hierarchical networks. Thus, the spread of these worms constitutes an increasing potential threat. For understanding the propagation of the aforementioned wireless hybrid worms, current researches have three critical problems:Structural simplification of network topologies(previous research object for wireless worms is the mobile network),Homogenous population of network devices(properties of network devices are the same), andInaccuracy of propagation models(traditional deterministic differential or stochastic difference models cannot model propagation of wireless hybrid worms accurately). To address them, we propose a novel compartmental population-based propagation model oriented towards heterogeneous and hierarchical networks with human behaviors, and then study the impacts of user mobility and operation behaviors on worm propagation. Meanwhile, we conduct extensive simulations to show our model can characterize propagation features accurately. The results in this paper not only provide a deep understanding of new worm propagation, but also serve as fundamental defense guidelines.
Tianbo Wang 0001, Chunhe Xia, Xiaojian Li 0002, Yang Xiang 0001
IEEE Trans. Mob. Comput.1
2020 H2P: A Novel Model to Study the Propagation of Modern Hybrid Worm in Hierarchical Networks
Tianbo Wang 0001, Chunhe Xia
ICA3PP (3)1
2020 A behavior-aware SLA-based framework for guaranteeing the security conformance of cloud service
Chunhe Xia, Tianbo Wang 0001, Xiaojian Li 0002
Frontiers Comput. Sci.3
2019 Topic Reconstruction: A Novel Method Based on LDA Oriented to Intrusion Detection
Shengwei Lei, Chunhe Xia, Tianbo Wang 0001, Shizhao Wang
ICA3PP (1)3
2019 Which Node Properties Identify the Propagation Source in Networks?
Chunhe Xia, Tianbo Wang 0001
ICA3PP (1)3
2019 Feature Generation: A Novel Intrusion Detection Model Based on Prototypical Network
Shizhao Wang, Chunhe Xia, Tianbo Wang 0001
ICA3PP (1)3
2019 SADI: A Novel Model to Study the Propagation of Social Worms in Hierarchical Networks
abstract
As more and more people rely on social networks for business and life, social worms constitute one of the major security threats to our society. Modern social worms exhibit two new features,message notificationandthe temporal characteristic of human mobility. Message notification indicates a user will get a reminder once a new message comes to a social account. The temporal characteristic of human mobility indicates a user can operate corresponding computer in different locations with different resting time. Previous scholars have proposed some analytical models for the propagation dynamics of social worms. However, they did not consider the above two features and there is one critical problem unrealized, which isstructural imperfection of network topology. Previous models have not taken into account the hierarchical topology structure, which results from a many-to-many relationship between users and hosts. To address these problems, we model propagation dynamics of social worms oriented hierarchical networks in this paper, and the proposed model accurately describes the propagation behavior of social worms. We conduct both a theoretical analyses and extensive simulations to show our model can overcome inaccuracy in the number of infected nodes and provide a stronger approximation for the worm propagation. The results show that our model presented in this paper achieves a greater accuracy in characterizing the propagation of modern social worms.
Tianbo Wang 0001, Chunhe Xia, Sheng Wen, Yang Xiang 0001, Shouzhong Tu
IEEE Trans. Dependable Secur. Comput.1
2017 The Spatial-Temporal Perspective: The Study of the Propagation of Modern Social Worms
abstract
Due to the critical security threats imposed by social worms, such as Twitter and Facebook, modeling and simulation study of the propagation dynamics of social worms is essential to predict their potential for damage and to understand the propagation characteristics. Modern social worms exhibit one new feature,reinfection-notification. It indicates that malicious messages are sent by neighbors whenever any susceptible or infected recipients open the malicious attachments, and a user will get reminders when new messages come to a social account. Meanwhile, there are two critical problems:dynamic host usageandtemporal message processing. First, from aspatialperspective, previous models have not taken into account that public hosts in different locations are shared by several users arising from human mobility, namely,dynamic host usage. Second, from atemporalperspective, the problem of temporal message processing results from the improper assumption that during this period of message checking, unread messages all are read by default, or under the condition that some parts of messages have been read, but the rest of unread messages are no longer processed afterward. To address these problems, we present a novel social worm simulation model in this paper, which adopts “social network-based sharing” and “sorting and attenuation” methods. We perform comprehensive theoretical analyses and experimental evaluation to validate our simulation model. The results show that our model is more suitable for modeling the complicated propagation behaviors of modern social worms in hierarchical networks.
Tianbo Wang 0001, Chunhe Xia, Yang Xiang 0001
IEEE Trans. Inf. Forensics Secur.1