EDBT 2026 Demo / reviewers in the wild / expert
Yuchuan Luo
dblp:166/1871
· DBLP profile ↗
64ranked-venue papers
6as first author
51since 2021 · last 2026
0000-0002-0720-4925ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 2 first-author · 15 since 2021Computer networks · 16 · 3 first-author · 9 since 2021Databases, data management, data science and information retrieval · 10 · 7 since 2021Artificial intelligence and machine learning · 8 · 6 since 2021Systems, architecture and hardware · 8 · 7 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 1 first-author · 6 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Theory of computation · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Toward Efficient Membership Inference Attacks Against Federated Large Language Models: A Projection Residual Approach
Guilin Deng, Silong Chen, Yuchuan Luo, Yi Liu 0057, Songlei Wang, Zhiping Cai, Lin Liu 0018, Xiaohua Jia, Shaojing Fu |
SP | 3 |
| 2026 | Euston: Efficient and User-Friendly Secure Transformer Inference with Non-Interactivity
Xinwen Gao, Shaojing Fu, Lin Liu 0018, Zhuotao Liu, Yuchuan Luo |
SP | 5 |
| 2026 | Reconstructing Training Data from Adapter-based Federated Large Language ModelsabstractAdapter-based Federated Large Language Models (FedLLMs) are widely adopted to reduce the computational, storage, and communication overhead of full-parameter fine-tuning for web-scale applications while preserving user privacy. By freezing the backbone and training only compact low-rank adapters, these methods appear to limit gradient leakage and thwart existing Gradient Inversion Attacks (GIAs). Contrary to this assumption, we show that low-rank adapters create new, exploitable leakage channels. We propose the Unordered-word-bag-based Text Reconstruction (UTR) attack, a novel GIA tailored to the unique structure of adapter-based FedLLMs. UTR overcomes three core challenges—low-dimensional gradients, frozen backbones, and combinatorially large reconstruction spaces—by: (i) inferring token presence from attention patterns in frozen layers, (ii) performing sentence-level inversion within the low-rank subspace of adapter gradients, and (iii) enforcing semantic coherence through constrained greedy decoding guided by language priors. Extensive experiments across diverse models (GPT2-Large, BERT, Qwen2.5-7B) and datasets (CoLA, SST-2, Rotten Tomatoes) demonstrate that UTR achieves near-perfect reconstruction accuracy (ROUGE-1/2 > 99), even with large batch sizes—settings where prior GIAs fail completely. Our results reveal a fundamental tension between parameter efficiency and privacy in FedLLMs, challenging the prevailing belief that lightweight adaptation inherently enhances security. Our code and data are available at https://github.com/shwksnshwowk-wq/GIA Silong Chen, Yuchuan Luo, Guilin Deng, Yi Liu 0057, Ming Xu 0002, Shaojing Fu, Xiaohua Jia |
WWW | 2 |
| 2026 | PriSEG: A Privacy-Preserving Scheme for Image Segmentation SystemabstractImage segmentation, a crucial technology in computer vision, is being applied in an increasingly wide range of fields. However, as data processing involves privacy, corresponding security issues have also emerged. The straightforward application of conventional security protocols in extensive image segmentation networks tends to yield suboptimal results, primarily due to the accumulation of errors. To protect sensitive or personal data, we introduce PriSEG — the first practical privacy-preserving image segmentation scheme based on Secure Multi-Party Computation (SMPC) technology. This study employs additive secret sharing and develops high-precision secure computation protocols for critical operations such as division and nonlinear activation functions (e.g., Sigmoid and ReLU) within neural networks. Our novel protocols facilitate secure inference in large and complex image segmentation networks. Additionally, our system design incorporates a tripartite service provider model, enhancing the system's robustness by ensuring it remains operational despite the dropout of any service provider. We have also validated the security of PriSEG under a semi-honest model. The experimental results on real-world datasets demonstrate that our scheme achieves performance comparable to plaintext implementations, with only a 0.005 degradation on average Mean Absolute Error (aveMAE). This proves the effectiveness and practicality of our scheme. Yuchuan Luo, Lin Liu 0018, Shaojing Fu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | FLUTE: FSS-Based Secure Two-Party LLM Inference Using Partial Transformer EncryptionabstractRecently, transformer-based large language models (LLMs) have become mainstream, particularly when used as agents. However, users with exceedingly sensitive data cannot benefit due to a lack of high-performance devices to train LLMs or limited access to large companies' LLM APIs. Secure two-party computing (2PC), especially the recently popular function secret sharing (FSS), enables secure inference of LLMs by protecting both users' inputs and LLM parameters from leakage. In this paper, we propose${\sf FLUTE}$, the first FSS-based 2PC inference framework for LLMs with partial transformer encryption. We first identify a subset of transformer core blocks by simulating an adversary$\mathcal {A}$attempting to recover model parameters layer by layer, and then design GPU-friendly FSS protocols for each module within the core blocks, optimizing communication using the matrix multiplication protocol of${\sf ABY2.0}$. Security analysis shows that our partial encryption scheme provides security comparable to encrypting the entire LLM, thereby enhancing the performance-security trade-off of the entire end-to-end secure inference. The experimental results in the latest LLM, Llama 3.1-8B, show that${\sf FLUTE}$outperforms the SOTA (SIGMA) by$3\times$in both latency and communication, and it achieves even greater advantages in larger LLMs, such as Llama 3.1-70B. Yujie Xue, Lin Liu 0018, Yuchuan Luo, Shaojing Fu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Risk-Aware Privacy Preservation for LLM InferenceabstractLarge Language Model (LLM) inference services like ChatGPT are popular for enabling diverse tasks via prompts, yet they exacerbate privacy risks due to the potential exposure of sensitive data in user inputs. Existing local differential privacy (LDP)-based text sanitization mechanisms offer lightweight protection suitable for cloud-based LLM inference. Nevertheless, uniform privacy budget allocation and generalized sanitization mechanisms neglect the critical protection needs of sensitive user data, such as Personally Identifiable Information (PII). Empirical evidence of this work reveals that even with a strict privacy budget (ϵ=0.1), the sensitive information leakage rate can reach an alarmingly high 71.74%. To address these challenges, this paper proposes Rap-LI, a risk-aware privacy preservation framework for LLM inference, designed to be plug-and-play. Rap-LI performs risk identification and personalized labeling on user prompts, then develops a risk-aware LDP mechanism for text sanitization, formally proven to satisfy both token-level and sentence-level LDP guarantees. Extensive experimental results demonstrate Rap-LI’s superior privacy-utility balance. It improves privacy protection against sensitive information leakage by an average of 51.68% compared to methods with comparable utility. Our code is available at https://github.com/Cristliu/RapLI. Zhihuang Liu, Zhangdong Wang, Tongqing Zhou, Yonghao Tang, Yuchuan Luo, Zhiping Cai |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | MSFS: Maliciously Secure 3-Party Feature Selection via Mutual Information
Peijun Zhao, Lin Liu 0018, Shaojing Fu, Yuchuan Luo |
Inscrypt (2) | 4 |
| 2025 | Making Local Models Learn Autonomously with Global Feature Tracking and Client Drift Releasing for Federated Learning
Silong Chen, Yuchuan Luo, Liang Gao 0001, Shaojing Fu, Ming Xu 0002 |
DASFAA (1) | 2 |
| 2025 | DecFLLM: A Privacy-Preserving Fine-Tuning Framework for Federated Large Language Models via Adapter Decomposition
Maojiang Wang, Silong Chen, Xu Yang 0028, Zhenyu Qiu, Yingwen Chen 0001, Yuchuan Luo, Shaojing Fu |
ICA3PP (4) | 6 |
| 2025 | Security-Enhanced Data Transmission Scheme for IoT-Based Healthcare in Remote AreasabstractIn remote areas without continuous internet connectivity, patients often need to travel long distances to access healthcare services. Ensuring secure and efficient healthcare in remote areas has become a significant challenge. Inspired by delay tolerant networks and identity authentication protocols, we propose a security-enhanced data transmission scheme for healthcare in remote areas. The scheme leverages vehicles as data mules to address network intermittency, transporting data collected by wearable devices from remote areas to urban centers. It incorporates a novel key agreement mechanism based on Chebyshev polynomials and hash functions to protect patient privacy, along with a dynamic update method for pseudonyms and credentials to achieve lightweight anonymous authentication. Finally, we rigorously verify the security of the scheme using the Real-or-Random (ROR) model and demonstrate that it outperforms related methods in terms of performance. Zhenbin Guo, Yuchuan Luo, Shaojing Fu, Ming Xu 0002 |
ICASSP | 2 |
| 2025 | HumanSAM: Classifying Human-Centric Forgery Videos in Human Spatial, Appearance, and Motion Anomaly
Yunfan Ye, Fan Zhang 0144, Qingyang Zhou, Yuchuan Luo, Zhiping Cai |
ICCV | 5 |
| 2025 | PPAGAN: A Privacy-Preserving Self-attention GAN Framework for Image Synthesis
Maojiang Wang, Yuchuan Luo, Yingwen Chen 0001, Xu Yang 0028, Shaojing Fu |
ICIC (4) | 2 |
| 2025 | Stealthy Backdoors in Vertical Federated Learning
Xu Yang 0028, Yuchuan Luo, Shaojing Fu, Ming Xu 0001 |
ICIC (4) | 2 |
| 2025 | PrivMLLM: Efficient Three-Party Multimodal Large Language Model Secure Inference Supported Prompt PrivacyabstractMultimodal Large Language Models (MLLMs) represent the next frontier in artificial intelligence (AI), capable of processing and integrating diverse data types (text, images, audio and video) for richer understanding and generation. However, their potential is limited by privacy constraints: sensitive data resides with different owners who must keep it local, while MLLM parameters themselves require protection. We address this challenge by pioneering complete end-to-end privacy protection that simultaneously secures prompts, multimedia data, and MLLM parameters.In this work, we present PrivMLLM, the first general-purpose secure three-party (3PC) inference framework for MLLMs that serves two data owners while protecting both model parameters and inputs. Our approach is based on three key insights: (1) domain knowledge-aware optimization of fixed-point arithmetic for global performance gains, (2) hybrid secret-sharing protocols that reduce communication and rounds for linear/non-linear operations, and (3) constant-round function secret sharing (FSS)-based protocols for private embedding and maximum.We formally prove PrivMLLM’s security under the rigorous Universal Composability (UC) framework and demonstrate the first end-to-end secure inference system for MLLMs. Experimental results show that our solution enables secure inference for Llama3.2-11B-vision in under 0:5-minute per token, achieving 16 and 8 speedups compared to our implementations built with the SOTA 2PC (CrypTen+) and 3PC (ABY3+) privacypreserving machine learning (PPML) frameworks respectively. Moreover, we benchmark the submodules ViT and LLM against the SOTA schemes, SHAFT (NDSS 2025) and SIGMA (PETS 2024), achieving 1:3~3× performance gains. Yujie Xue, Lin Liu 0018, Yuchuan Luo, Shaojing Fu |
ICNP | 3 |
| 2025 | ENSI: Efficient Non-Interactive Secure Inference for Large Language ModelsabstractSecure inference enables privacy-preserving machine learning by leveraging cryptographic protocols that support computations on sensitive user data without exposing it. However, integrating cryptographic protocols with large language models (LLMs) presents significant challenges, as the inherent complexity of these protocols, together with LLMs' massive parameter scale and sophisticated architectures, severely limits practical usability. In this work, we propose ENSI, a novel non-interactive secure inference framework for LLMs, based on the principle of codesigning the cryptographic protocols and LLM architecture. ENSI employs an optimized encoding strategy that seamlessly integrates CKKS scheme with a lightweight LLM variant, BitNet, significantly reducing the computational complexity of encrypted matrix multiplications. In response to the prohibitive computational demands of softmax under homomorphic encryption (HE), we pioneer the integration of the sigmoid attention mechanism with HE as a seamless, retraining-free alternative. Furthermore, by embedding the Bootstrapping operation within the RMSNorm process, we efficiently refresh ciphertexts while markedly decreasing the frequency of costly bootstrapping invocations. Experimental evaluations demonstrate that ENSI achieves approximately an$8 \times$acceleration in matrix multiplications and a$2.6 \times$speedup in softmax inference on CPU compared to state-of-the-art method, with the proportion of bootstrapping is reduced to just 1 %. Maojiang Wang, Xinwen Gao, Yuchuan Luo, Lin Liu 0018, Shaojing Fu |
SRDS | 4 |
| 2025 | LEA: Label Enumeration Attack in Vertical Federated LearningabstractA typical Vertical Federated Learning (VFL) scenario involves several participants collaboratively training a machine learning model, where each party has different features for the same samples, with labels held exclusively by one party. Since labels contain sensitive information, VFL must ensure the privacy of labels. However, existing VFL-targeted label inference attacks are either limited to specific scenarios or require auxiliary data, rendering them impractical in real-world applications. We introduce a novel Label Enumeration Attack (LEA) that, for the first time, achieves applicability across multiple VFL scenarios and eschews the need for auxiliary data. Our intuition is that an adversary, employing clustering to enumerate mappings between samples and labels, ascertains the accurate label mappings by evaluating the similarity between the benign model and the simulated models trained under each mapping. To achieve that, the first challenge is how to measure model similarity, as models trained on the same data can have different weights. Drawing from our findings, we propose an efficient approach for assessing congruence based on the cosine similarity of the first-round loss gradients, which offers superior efficiency and precision compared to the comparison of parameter similarities. However, the computational cost may be prohibitive due to the necessity of training and comparing the vast number of simulated models generated through enumeration. To overcome this challenge, we propose Binary-LEA from the perspective of reducing the number of models and eliminating futile training, which lowers the number of enumerations from$\mathcal{O}(n!)$to$\mathcal{O}\left(n^{3}\right)$. Experiments across different VFL settings confirm LEA's effectiveness. In the absence of auxiliary datasets, LEA demonstrates a$\mathbf{5 0 \%}$to$\mathbf{9 0 \%}$enhancement in attack accuracy over the existing state-of-the-art label inference attacks in VFL. Moreover, LEA is resilient against common defense mechanisms such as gradient noise and gradient compression. Shaojing Fu, Yuchuan Luo, Lin Liu 0018 |
SRDS | 3 |
| 2025 | pNILM: Whole-process privacy preservation for non-intrusive load monitoring based on deep neural networks
Liqiang Wu, Shaojing Fu, Yiliang Han, Yuchuan Luo, Ming Xu 0002 |
Expert Syst. Appl. | 4 |
| 2025 | The Analysis of Encrypted Video Stream Based on Low-Dimensional Embedding MethodabstractIn recent years, encrypted video streaming takes up an increasing proportion of mobile network traffic, with encrypted video streams playing a significant role in illegal video detection. However, there are challenges in performing content analysis of encrypted video streams, including label limitations and complex calculations. In this paper, we proposed a low-dimensional embedding method based on Byte Rate Sequences (BRS), named EVS2vec (Encrypted Video Stream to Vector), to solve these problems effectively. It can represent the content of encrypted video streams with low-dimensional vectors by mapping the indefinite-length sequence into a low-dimensional Euclidean space. EVS2vec can thereby be applied for not only supervised analysis but also unsupervised analysis. Furthermore, using BRS can also save the time overhead on fine-grained network traffic parsing. In order to ensure the content-related distinguishability of the embedding result, inspired by contrastive learning, we designed a network structure based on Recurrent Neural Network (RNN) with self-attention mechanism in EVS2vec and trained it using triplet network. The experiments on a public dataset show that EVS2vec saves storage overhead while containing enough video content information. EVS2vec can achieve a high accuracy of similarity threshold, reaching 96.89%. An 8-dimensional fingerprint for each video is constructed. Moreover, classification and clustering analysis can also be performed with acceptable results. Luming Yang, Shaojing Fu, Lin Liu 0018, Yuchuan Luo |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | Resource allocation based on optimized cellular network AP layout for visible light communication heterogeneous network
Yuchuan Luo |
J. Supercomput. | 3 |
| 2025 | An Efficient Replication-Based Aggregation Verification and Correctness Assurance Scheme for Federated LearningabstractFederated learning(FL), enabling multiple clients collaboratively to train a model via a parameter server, is an effective approach to address the issue of data silos. However, due to the self-interest and laziness of servers, they may not correctly aggregate the global model parameters, which will cause the final model trained to deviate from the training goal. In the existing proposals, the cryptography-based verification scheme involves heavy computation overheads. On the other hand, the replication-based verification method, relying on a dual-server architecture, can ensure the correctness of aggregation and reduce computation overheads, but incur at least twice the communication cost as that of the task itself. To address these issues, we propose a novel replication-based aggregation scheme for FL, which enables efficient verification and stronger correctness assurance. The scheme employs a main-secondary server architecture, which allows the secondary servers to partakes in aggregation tasks at a predetermined probability, consequently mitigating the validation overhead. Moreover, we resort to the game theory and design a Learning Contract to impose penalties on dishonest servers, enforcing rational servers to correctly compute global model parameters. Under the use of Betrayal Contract to prevent collusion among servers, we further design a training game to efficiently verify global model parameters and ensure their correctness. Finally, we analyze the correctness of the proposed scheme and demonstrate that the computational overhead of our scheme is$\frac{{n + 1}}{{2n}}$of the previous replication-based validation scheme, obtaining a significant reduction in communication cost, where$n$means the training rounds. Experimental results further validate our deduction. Shihong Wu, Yuchuan Luo, Shaojing Fu, Yingwen Chen 0001, Ming Xu 0002 |
IEEE Trans. Serv. Comput. | 2 |
| 2024 | Diffusion-based Adversarial Attack to Automatic Speech Recognition
Yuchuan Luo, Shaojing Fu, Zhenyu Qiu, Lin Liu 0018 |
ACML | 2 |
| 2024 | Privacy-Preserving Byzantine-Robust Federated Learning via Multiparty Homomorphic Encryption
Songwei Luo, Shaojing Fu, Lin Liu 0018, Yuchuan Luo |
COCOON (2) | 5 |
| 2024 | FedSV: A Privacy-Preserving Byzantine-Robust Federated Learning Scheme with Self-validation
Shaojing Fu, Yuchuan Luo, Lin Liu 0018 |
ICA3PP (1) | 3 |
| 2024 | Defend from Scratch: A Diffusion-Based Proactive Defense Method for Unauthorized Speech Synthesis
Yuchuan Luo, Zhenyu Qiu, Lin Liu 0018, Shaojing Fu |
ICONIP (1) | 2 |
| 2024 | Edge-feature Modeling-based Topological Graph Neural Networks for Phishing Scams Detection on EthereumabstractDetecting phishing scams has become an important task in blockchain-based cryptocurrency applications. While many network representation learning-based approaches have been proposed for this task, they suffer from various issues including (1) the requirement of handcrafted features, which may not capture complex relationships and patterns in graph data, and/or (2) considering only node features while ignoring the more significant edge features, and/or (3) incapability of preserving complete network topology, which affects the generalization ability. In this paper, we propose a novel Edge-feature modeling-based Topological Graph Neural Network (ETGNN) to detect phishing scams on Ethereum, which avoids all aforementioned issues of existing approaches. Specifically, ETGNN involves two key components, one responsible for learning weighted features of nodes and edges in the Ethereum transaction graph, and the other responsible for incorporating global topological information of the graph using persistent homology. Finally, phishing scams are detected based on these two learned features. The experimental results demonstrate that ETGNN outperforms the state-of-the-art method with an improvement rate of 14.38% on F1-score. Shuhui Fan, Shaojing Fu, Yuchuan Luo, Ming Xu 0002 |
IWQoS | 4 |
| 2024 | BVDFed: Byzantine-resilient and verifiable aggregation for differentially private federated learning
Xinwen Gao, Shaojing Fu, Lin Liu 0018, Yuchuan Luo |
Frontiers Comput. Sci. | 4 |
| 2024 | A Robust and Lightweight Privacy-Preserving Data Aggregation Scheme for Smart GridabstractPrivacy-preserving data aggregation (PPDA) enables data availability and privacy preservation simultaneously in smart grid. However, existing methods, such as masking and homomorphic encryption, cannot simultaneously offer strong privacy preservation, fault tolerance for both smart meters and aggregators, verifiable aggregation, and lightweight encryption. To tackle these challenges, we design HTV-PRE, a homomorphic threshold proxy re-encryption scheme with re-encryption verifiability. HTV-PRE involves only linear operations and resists quantum attacks after being instanced by ideal lattices. By leveraging HTV-PRE, we propose a robust and lightweight data aggregation scheme with strong privacy preservation for smart grid. Robustness ensures fault tolerance and error detection. Even if some smart meters or aggregators are faulty, data aggregation can still work without imposing expensive computation on other smart meters or requiring additional trust assumptions. Additionally, to detect aggregators' errors, a proof for the aggregated result is presented so that anyone can verify whether the result has been correctly computed or not. The verifiable aggregation adds no computation/communication overhead on the user side. The performance evaluations demonstrate that our PPDA scheme significantly offloads computation overhead from smart meters and control center to the edge, and its user encryption is up to 4x faster than existing approaches. Liqiang Wu, Shaojing Fu, Yuchuan Luo, Hongyang Yan, Heyuan Shi, Ming Xu 0002 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | SecTCN: Privacy-Preserving Short-Term Residential Electrical Load ForecastingabstractShort-term residential electrical load forecasting (SRLF) as a cloud service usually requires fine-grained electricity consumption data as input. However, those data are closely related to users' lifestyles, thus bringing about privacy concerns. We adapt homomorphic encryption into temporal convolutional networks (TCN) to yield an efficient design for SRLF, named SecTCN, which preserves privacy for both user data and model parameters. First, a homomorphic-encryption-friendly model is proposed through novel Ticktock approximations. Second, secure load forecasting over the encrypted data is executed by cloud–edge collaboration. Third, a novel data representation and related ciphertext computations are proposed to accelerate forecasting, and a position shuffler is devised to protect models from equation-solving attacks. Experimental evaluations demonstrate that SecTCN reduces a root-mean-squared error by 21.75 averagely and a mean absolute percentage error by 4.22%$\text{ to } $22.16%, compared to unencrypted long short-term memory (LSTM) and TCN. On average, SecTCN requires only 1.10 s to make forecasting with 10.27 MB communication traffic. Liqiang Wu, Shaojing Fu, Yuchuan Luo, Ming Xu 0002 |
IEEE Trans. Ind. Informatics | 3 |
| 2024 | SecDM: A Secure and Lossless Human Mobility Prediction SystemabstractWith the rapid development of deep neural network research, many deep neural network prediction services are provided for cloud service users. However, due to the untrusted nature of cloud computing, there are risks associated with this. To secure user data and cloud servers at the same time, we designed a secure prediction system, named SecDM (SecureDeepMove), which focuses on an attentional recurrent network for human mobility prediction. A neural network inference system that allows two parties to work together securely and efficiently without revealing any data is presented in this work. To design it, with the help of secret sharing technology, we first propose several secure, efficient, and lossless two-party protocols, which can securely calculate non-linear functions in the model, such as sigmoid, tanh, and softmax. In addition, a secure and effective strategy is introduced to maintain the accuracy of the calculation. Moreover, we also prove the security of our scheme in the semi-honest model. Finally, experimental results validate that the prediction result of our SecDM is not only as accurate as the non-privacy-preserving scheme but also highly efficient. Lin Liu 0018, Shaojing Fu, XueLun Huang, Yuchuan Luo, Xuyun Zhang, Kim-Kwang Raymond Choo |
IEEE Trans. Serv. Comput. | 4 |
| 2023 | Achieving Privacy-preserving and Lightweight Truth Discovery in Mobile Crowdsensing (Extended abstract)abstractTo obtain reliable results from conflicting data in mobile crowdsensing, numerous truth discovery protocols have been proposed in the past decade. However, most of them do not consider the data privacy of entities involved (e.g., workers and servers), and several existing privacy-preserving truth discovery protocols either provide limited privacy protection or have heavy computation and communication overheads due to iterative computation and transmission over large ciphertexts.In this paper, we aim to propose privacy-preserving and lightweight truth discovery protocols to tackle the above problems. Specifically, we carefully design an anonymization protocol named AnonymTD to delink workers from their data, where workers’ data are computed and transmitted without complicated encryption. To further reduce each worker’s overheads in the scenarios where workers are willing to share their weights, we resort to the perturbation technology to propose a more lightweight truth discovery protocol named PerturbTD. Based on workers’ perturbed data, two cloud servers in PerturbTD complete most of the workload of truth discovery together, which avoids the frequent involvement of workers. The theoretical analysis and the comparative experiments in this paper demonstrate that our two protocols can achieve our security goals with low computation and communication overheads. Jianchao Tang, Shaojing Fu, Ximeng Liu, Yuchuan Luo, Ming Xu 0002 |
ICDE | 4 |
| 2023 | Privacy-Preserving Federated Learning with Hierarchical Clustering to Improve Training on Non-IID Data
Songwei Luo, Shaojing Fu, Yuchuan Luo, Lin Liu 0018, Yanxiang Deng |
NSS | 3 |
| 2023 | Privacy Preserving Outsourced K-means Clustering Using Kd-tree
Yanxiang Deng, Lin Liu 0018, Shaojing Fu, Yuchuan Luo, Wei Wu 0015 |
ProvSec | 4 |
| 2023 | EVS2vec: A Low-dimensional Embedding Method for Encrypted Video Stream AnalysisabstractThe rise in video streaming has led to an increase in network traffic, with encrypted video streams playing a significant role in illegal video detection. However, there are challenges in performing content analysis of encrypted video streams, including label limitations and complex calculations. In this paper, we proposed a low-dimensional embedding method based on Byte Rate Sequences (BRS), named EVS2vec (Encrypted Video Stream to Vector), to solve these problems effectively. It can represent the content of encrypted video streams with low-dimensional vectors by mapping the indefinite-length sequence into a low-dimensional Euclidean space. EVS2vec can thereby be applied for not only supervised analysis but also unsupervised analysis. Furthermore, using BRS can also save the time overhead on fine-grained network traffic parsing. In order to ensure the content-related distinguishability of the embedding result, inspired by contrastive learning, we designed a network structure based on Recurrent Neural Network (RNN) with self-attention mechanism in EVS2vec and trained it using siamese network. The experiments on a public dataset show that EVS2vec saves storage overhead while containing enough video content information. EVS2vec can achieve a high accuracy of similarity threshold, reaching 96.71%. An 8-dimensional fingerprint for each video is constructed. Moreover, classification and clustering analysis can also be performed with acceptable results. Luming Yang, Shaojing Fu, Lin Liu 0018, Yuchuan Luo |
SECON | 5 |
| 2023 | EzBoost: Fast And Secure Vertical Federated Tree Boosting Framework via EzPCabstractFederated learning (FL) has emerged as a prominent methodology for collaboratively training machine learning models among multiple participants while alleviating data privacy leakage through data localization. However, recent studies have shown that the transferred intermediate parameters still contain sensitive information that needs to be further protected. More-over, real-world institutions often possess diverse data attributes, necessitating the adoption of Vertical Federated Learning (VFL) for cooperative learning tasks. Existing researches in VFL have proposed some frameworks with privacy-preservation functionality, yet they suffer from high participant overhead or low model accuracy, etc. To address these challenges, in this paper, we propose EzBoost, a fast and secure vertical federated tree boosting framework built upon XGBoost. Specifically, we leverages the efficient Secure Multi-party Computation (MPC) framework, EzPC, to facilitate the design and implementation of EzBoost. By carefully designing our framework with two non-collusive servers for secure two-party computation, EzBoost significantly accelerates the runtime of model training and querying at most 20×, and reduces the participant overheads at most 300×. In addition, we identify a potential privacy leakage problem in recent researches and propose a more robust solution for addressing it. Through comprehensive security analysis and comparative experiments with existing approaches, we demonstrate that EzBoost achieves stronger privacy-preservation, higher accuracy and higher efficiency simultaneously. Xinwen Gao, Shaojing Fu, Lin Liu 0018, Yuchuan Luo, Luming Yang |
TrustCom | 4 |
| 2023 | SecGAN: Honest-Majority Maliciously 3PC Framework for Privacy-Preserving Image SynthesisabstractThe Generative Adversarial Network (GAN) is capable of generating high-quality images, surpassing earlier generative models by producing fake images. To effectively handle the high computational workload and the large number of parameters involved, outsourcing to cloud servers is a more suitable option. However, utilizing cloud servers for image synthesis also presents the risk of privacy breaches. Additionally, existing privacy-preserving GANs operate on a semi-honest model with two parties, which fails to resist malicious attacks. This paper introduces a novel image synthesis framework that involves three parties, enabling privacy-preserving Deep Convolutional GAN(DCGAN) on the cloud in both semi-honest and malicious scenarios. The secure data reconstruction implemented in this framework detects adversary attacks under the malicious model and aborts computation upon detection. Furthermore, we offer a range of highly efficient and accurate secure computation protocols specifically designed for DCGAN-based image synthesis. Extensive experimental results demonstrate that our secure GAN(SecGAN) can produce image quality comparable to that of the plaintext method. Lin Liu 0018, Shaojing Fu, Yuchuan Luo |
TrustCom | 5 |
| 2023 | Randomization is all you need: A privacy-preserving federated learning framework for news recommendation
Xinyi Huang 0001, Yuchuan Luo, Lin Liu 0018, Shaojing Fu |
Inf. Sci. | 2 |
| 2023 | BFCRI: A Blockchain-Based Framework for Crowdsourcing With Reputation and IncentiveabstractWith the rapid development of cloud computing and the sharing economy, crowdsourcing aroused widespread interest and adoption in providing intelligent and efficient services for humans. The majority of existing works focus on effective crowdsourcing task assignment and privacy protection, mostly relying on central servers and assuming that participants are$honest$-$and$-$curious$and proactive. However, in reality, workers may be unwilling to participate, and there may be malicious behavior among participants, thus harming the enthusiasm and interests of other participants. The central server has weaknesses such as single point of failure. To address above problems, we propose a blockchain-based framework for crowdsourcing with reputation and incentive. We first design a worker selection scheme to select credible and capable workers. We leverage reputation as a metric of workers’ credibility, which is calculated through the improved subjective logic model. Then we utilize contract theory to design incentive mechanisms to attract more workers, especially high-quality workers to participate. Experimental results show that our proposed method can detect and prevent malicious participants and resist malicious collusion when the proportion of malicious participants is no more than 1/3. And encourage more workers to actively, honestly and continuously participate in crowdsourcing. Shaojing Fu, XueLun Huang, Lin Liu 0018, Yuchuan Luo |
IEEE Trans. Cloud Comput. | 4 |
| 2023 | P2Ride: Practical and Privacy-Preserving Ride-Matching Scheme for RidesharingabstractAs a popular instance of sharing economy, ridesharing has been widely adopted in recent years. To use the convenient ridesharing service, riders and drivers have to share with the service provider their private trip information, which impedes users from freely enjoying the benefits of ridesharing. However, existing studies in ridesharing mainly focus on the optimization of rider-driver matching but ignore the protection of privacy of users. In this paper, we propose P2Ride, a Practical and Privacy-preserving Ride-matching scheme for ridesharing, which enables the service provider to efficiently match drivers with appropriate riders without learning the privacy of both drivers and riders. In P2Ride, we first convert the complex ride-matching computation into equality testing by leveraging overlapping partition systems, and then achieve the privacy-preserving ride-matching by designing a novel non-interactive private equality testing protocol. We prove the security of the proposed P2Ride theoretically. Moreover, a prototype of the P2Ride is implemented, and the experiment results over a real-world dataset demonstrate that the proposed P2Ride can achieve both high ride-matching accuracy and practical efficiency. Yuchuan Luo, Shaojing Fu, Xiaohua Jia, Ming Xu 0002, Yingwen Chen 0001 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2022 | Smart Contract Scams Detection with Topological Data Analysis on Account InteractionabstractThe skyrocketing market value of cryptocurrencies has prompted more investors to pour funds into cryptocurrencies to seek asset hedging. However, the anonymity of blockchain makes cryptocurrency naturally a tool of choice for criminals to commit smart contract scams. Consequently, smart contract scam detection is particularly critical for investors to avoid economic loss. Previous methods mainly leverage specific code logic of smart contracts and/or design rules based on abnormal transaction behaviors for scam detection. Although these methods gain success at detecting particular scams, they perform worse when applied to scams with highly similar codes. Besides, well-designed decision rules rely on expert knowledge and tedious data collection steps, which causes poor flexibility. To combat these challenges, we consider the problem of smart contract scam detection via mining topological features of account interaction information that dynamically evolves. We adopt interactive features extracted from dynamic interaction information of accounts and propose a framework named TTG-SCSD to utilize the features and Topological Data Analysis for smart contract scams detection. The TTG-SCSD constructs discrete dynamic interaction graphs for each contract and designs interactive features that characterize account behaviors. The features are modeled combined with a topology quantification mechanism to capture contract intentions in transactions. Experimental results on real-world transaction datasets from Ethereum show that TTG-SCSD obtains better generalizability and improves the performance of the bare versions of the comparison methods. Shuhui Fan, Shaojing Fu, Yuchuan Luo, Xuyun Zhang, Ming Xu 0002 |
CIKM | 3 |
| 2022 | pCOVID: A Privacy-Preserving COVID-19 Inference Framework
Yinqiu Wang, Yuchuan Luo, Lin Liu 0018, Shaojing Fu |
ICA3PP | 2 |
| 2022 | Accelerating Privacy-Preserving Image Retrieval with Multi-Index HashingabstractWith the explosive growth of data, a large amount of image data is stored on cloud servers. However, cloud servers can easily collect sensitive information about stored images, which brings serious privacy issues. Although uploading encrypted images to cloud servers could solve the privacy problem, most of the existing privacy-preserving schemes inevitably reduce the accuracy and efficiency of image retrieval. To address the above challenging issues, we propose a privacy-preserving content-based image retrieval scheme based on multi-indexed hashing (MIH) in this paper. To improve the retrieval precision, the ViT model is first used to extract feature descriptors of images and ITQ method is utilized to downscale the feature vectors into binary vectors. Subsequently, based on additive secret sharing, we propose a new secure Hamming distance calculation protocol to perform similarity measure, which protects the data privacy of image features. Finally, we design a secure multi-index hash structure to filter the dataset to improve the search efficiency. Experiments on the dataset demonstrate the efficiency and security of the scheme. Jingnan Huang, Yuchuan Luo, Ming Xu 0002, Shaojing Fu |
SEC | 2 |
| 2022 | TForm-RF: An Efficient Data Augmentation for Website Fingerprinting AttackabstractWebsite fingerprinting (WF) attacks have become a significant threat to users’ privacy, even against Tor, one of the most famous anonymous communication tools. However, some limitations have prevented them from applying to the real world. A severe limitation for traditional deep-learning-based WF attacks is that a large amount of training data is required to gain classification capabilities. In this paper, we considered a more practical setting where the attacker could only obtain a few traffic trace instances for each target website, called the few-shot WF problem. Unlike previous work using transfer learning and demanding additional pre-training data, we leveraged data augmentation to generate additional virtual samples from the training sample neighborhood. It can expand the support for the distribution of training data, thereby solving the data hunger problem of deep-learning-based WF attacks. Specifically, we proposed a new augmentation method called Trace-Form Based Refill (TForm-RF), which is tailored to the intrinsic properties of website traffic trace. From cell sequences, we extract TForms to figuratively represent traffic patterns and refill them randomly to generate meaningful new instances. We evaluate this idea with several reasonable experiments. We illustrated that TForm-RF is much more effective than prior HDA and has a competitive advantage over TF in both closed-world and open-world scenarios. Lumming Yang, Yuchuan Luo, Mantun Chen |
IPCCC | 4 |
| 2022 | Approximate Shortest Distance Queries with Advanced Graph Analytics over Large-scale Encrypted GraphsabstractUnderstanding graph characteristics is of great importance for graph analytics. Among the many properties, shortest path distance is the fundamental and widely used one. With the advent of cloud computing, it is a natural choice for the data owners to host their massive graphs on the cloud and outsource the shortest distance querying service to it. However, the new paradigm brings serious security concerns as graph data and shortest distance queries may contain sensitive information of data owners and users. In this paper, we propose a novel scheme to support privacy-preserving approximate shortest distance queries with advanced graph analytics over large-scale encrypted graphs, which enables an untrusted cloud to answer shortest distance queries as well as advanced graph metrics (e.g., node centrality) without knowing the content of queries and the sensitive information of outsourced graphs. Compared with the state-of-the-art solutions, our design can support not only efficient and accurate shortest distance approximation, but also advanced graph analytics. We prove that our scheme is secure under the chosen-plaintext model. Experimental results over real-world datasets show that our scheme achieves high approximation accuracy with practical efficiency. Yuchuan Luo, Dongsheng Wang 0004, Shaojing Fu, Ming Xu 0002, Yingwen Chen 0001 |
MSN | 1 |
| 2022 | Collusion-Tolerant Data Aggregation Method for Smart Grid
Yingwen Chen 0001, Kaiyu Cai, Dongsheng Wang 0004, Yuchuan Luo, Guangtao Xue |
WASA (1) | 5 |
| 2022 | Privacy-preserving WiFi Fingerprint Localization Based on Spatial Linear Correlation
Xu Yang 0028, Yuchuan Luo, Ming Xu 0001, Shaojing Fu, Yingwen Chen 0001 |
WASA (1) | 2 |
| 2022 | Towards differential access control and privacy-preserving for secure media data sharing in the cloud
Tengfei Zheng, Yuchuan Luo, Tongqing Zhou, Zhiping Cai |
Comput. Secur. | 2 |
| 2022 | FPDA: Fault-Tolerant and Privacy-Enhanced Data Aggregation Scheme in Fog-Assisted Smart GridabstractThe data aggregation approach in smart grid (SG) is an effective solution to make data available while keeping privacy preserving at the same time. The fault tolerance means decryption can still be carried out successfully even if some smart meters (SMs) are breaking down. It is a challenging issue to design an efficient, fault-tolerant data aggregation scheme with no help of centralized trusted authority (TA) or key update after each fault recovery. Recently, a fault-tolerant data aggregation scheme FESDA (Saleemet al.,2020) was presented. However, we identify a serious and inherent vulnerability in its fault tolerance. Specifically, given an equivalent ciphertext derived from each SM’s private key aiming at resiting faults, the control center can abuse it to obtain any SM’s reading. An effective attack is launched with both theoretical proof and experimentative verification. Furthermore, to fix it and solve the challenging issue, we first design an extended Shamir’s threshold secret-sharing scheme (tSSS) with master secret security and reusability, allowing SMs to reconstruct subsequent multiple secrets without leaking their original secret shares. Then, if some SMs fail to submit data successfully, the fog node (FN) starts extra request–response interactivities among itself and a limited number of SMs. Finally, a privacy-enhanced aggregation of normal reports can also be achieved. Extensive experiments demonstrate that the majority of computation costs and communication overload to acquire fault tolerance are offload on FNs, while SMs are computationally economical. Liqiang Wu, Ming Xu 0002, Shaojing Fu, Yuchuan Luo, Yuechuan Wei |
IEEE Internet Things J. | 4 |
| 2022 | Achieving Privacy-Preserving and Lightweight Truth Discovery in Mobile CrowdsensingabstractTo obtain reliable results from conflicting data in mobile crowdsensing, numerous truth discovery protocols have been proposed in the past decade. However, most of them do not consider the data privacy of entities involved (e.g., workers and servers), and several existing privacy-preserving truth discovery protocols either provide limited privacy protection or have heavy computation and communication overheads due to iterative computation and transmission over large ciphertexts. In this paper, we aim to propose privacy-preserving and lightweight truth discovery protocols to tackle the above problems. Specifically, we carefully design an anonymization protocol named AnonymTD to delink workers from their data, where workers’ data are computed and transmitted without complicated encryption. To further reduce each worker's overheads in the scenarios where workers are willing to share their weights, we resort to the perturbation technology to propose a more lightweight truth discovery protocol named PerturbTD. Based on workers’ perturbed data, two cloud servers in PerturbTD complete most of the workload of truth discovery together, which avoids the frequent involvement of workers. The theoretical analysis and the comparative experiments in this paper demonstrate that our two protocols can achieve our security goals with low computation and communication overheads. Jianchao Tang, Shaojing Fu, Ximeng Liu, Yuchuan Luo, Ming Xu 0002 |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2021 | Reliable and Privacy-Preserving Task Matching in Blockchain-Based CrowdsourcingabstractWith the number of users in crowdsourcing increasing rapidly, task matching service is attracting more and more attention. However, it also causes many security concerns, one of which is the leakage of sensitive information. Privacy-preserving task matching techniques can protect the private information of task requesters and workers. Whereas existing privacy-preserving task matching schemes are constructed on a central server, and thereby they may suffer from potential wrongdoings of a malicious server. In addition, most of them only provide accurate task matching, which means that they cannot tolerate keyword spelling errors, leading to the decline of task matching accuracy. In this paper, we propose a Reliable and Privacy-preserving Task Matching scheme (RPTM) for crowdsourcing. To guarantee the reliability of task matching results, RPTM employs smart contracts to ensure that operations of RPTM are faithfully performed. However, it may still disclose the privacy of users due to the transparency of the blockchain. In order to deal with this problem, RPTM can perform task matching service without compromising the privacy of task requesters and workers by leveraging a novel integer vector encryption scheme. Moreover, RPTM supports multi-keyword fuzzy matching by exploiting locality sensitive hashing and Bloom filter, which can tolerate keyword spelling errors and different expression formats. Extensive analysis and experiments based on a test net of EOS show that RPTM is efficient and secure. Baolai Wang, Shaojing Fu, Xuyun Zhang, Tao Xie 0012, Lingjuan Lyu, Yuchuan Luo |
CIKM | 6 |
| 2021 | Privacy-Preserving Swarm Learning Based on Homomorphic Encryption
Lijie Chen 0007, Shaojing Fu, Lin Liu 0018, Yuchuan Luo |
ICA3PP (3) | 4 |
| 2021 | A Clustering Method of Encrypted Video Traffic Based on Levenshtein DistanceabstractIn order to detect the playback of illegal videos, it is necessary for supervisors to monitor the network by analyzing traffic from devices. However, many popular video sites, such as YouTube, have applied encryption to protect users’ privacy, which makes it difficult to analyze network traffic at the same time. Many researches suggest that DASH (Dynamic Adaptive Streaming over HTTP) will leak the information of video segmentation, which is related to the video content. Consequently, it is possible to analyze the content of encrypted video traffic without decryption. At present, most of the encrypted video traffic analysis adopts supervised learning methods, and there is little research on its unsupervised methods. Analysts are usually faced with unlabeled data, in reality, so the existing approaches will not work. The encrypted video traffic analysis methods based on unsupervised learning are required. In this paper, we proposed a clustering method based on Levenshtein distance for title analysis of encrypted video traffic. We also run a thorough set of experiments that verify the robustness and practicability of the method. As far as I am concerned, it is the first work to apply cluster analysis for encrypted video traffic analysis. Luming Yang, Shaojing Fu, Yuchuan Luo |
MSN | 3 |
| 2020 | Practical Privacy Protection Scheme In WiFi Fingerprint-based LocalizationabstractThe solution of using existing WiFi devices for measurement and maintenance, and establishing a WiFi fingerprint database for precise localization has become a popular method for indoor localization. The traditional WiFi fingerprint privacy protection scheme increases the calculation amount of the client, but cannot completely protect the security of the client and the fingerprint database. In this paper, we make use of WiFi devices to present a Practical Privacy Protection Scheme In WiFi Fingerprint-based Localization PPWFL. In PPWFL, the localization server establishes a pre-partition in the fingerprint database through the E-M clustering algorithm, we divide the entire fingerprint database into several partitions. The server uses WiFi fingerprint entries with partitions as training data and trains a machine learning model. This model can accurately predict the client's partition based on fingerprint entries. The client uses the trained machine learning model to obtain its partition location accurately, picks up WiFi fingerprint entries in its partition, and calculates its geographic location with the localization server through secure multi-party computing. Compared with the traditional solution, our solution only uses the WiFi fingerprint entries in the client's partition rather than the entire fingerprint database. PPWFL can reduce not only unnecessary calculations but also avoid accidental errors (Unexpected errors in fingerprint similarity between non-adjacent locations due to multipath effects of electromagnetic waves during the propagation of complex indoor environments) in fingerprint distance calculation. In particular, due to the use of Secure Multi-Party Computation, most of the calculations are performed in the local offline phase, the client only exchanges data with the localization server during the distance calculation phase. No additional equipment is needed; our solution uses only existing WiFi devices in the building to achieve fast localization based on privacy protection. We prove that PPWFL is secure under the honest but curious attacker. Experiments show that PPWFL achieves efficiency and accuracy than the traditional WiFi fingerprint localization scheme. Wenxiang Wu, Shaojing Fu, Yuchuan Luo |
DSAA | 3 |
| 2020 | BIMP: Blockchain-Based Incentive Mechanism with Privacy Preserving in Location Proof
Yuchuan Luo, Shaojing Fu, Tao Xie 0012 |
ICA3PP (3) | 2 |
| 2020 | Location Privacy-Preserving Truth Discovery in Mobile Crowd SensingabstractTruth discovery techniques are commonly used in mobile crowd sensing (MCS) applications to infer accurate aggregated results based on quality-aware data aggregation. However, the location information of participants may be exposed when they upload their sensitive geo-tagged sensory data to relative platforms. While there are considerable existing privacy preserving truth discovery schemes for MCS, they mainly focus on protecting the privacy of sensory data, neglecting the tagged location information which is of equal if not higher importance for the privacy of participants. In this paper, we propose a novel and efficient location privacy preserving truth discovery (LoPPTD) mechanism, which can achieve data aggregation with high accuracy, while protecting both location privacy and data privacy of users. By structuring multi-dimensional sensory data obtained at different locations and exploiting homomorphic Paillier encryption, our approach can prevent leakage of both sensory data and tagged locations effectively. Also, super-increasing sequence techniques are employed in Lo-PPTD to ensure efficiency and feasibility. Theoretical analysis and thorough experiments performed on real-world datasets demonstrate that the proposed scheme can achieve high aggregation accuracy while providing complete privacy protection for users. Jingsheng Gao, Shaojing Fu, Yuchuan Luo, Tao Xie 0012 |
ICCCN | 3 |
| 2020 | Markov Probability Fingerprints: A Method for Identifying Encrypted Video TrafficabstractDetecting illegal video plays an important role in preventing and countering crime in daily life. It is effective for supervisors to monitor the network by analyzing traffic from devices. In this way, illegal video can be detected when it is played on the network. Most Internet traffic is encrypted, which brings difficulties to traffic analysis. However, many researches suggest that even if the video traffic is encrypted, the segmentation prescribed by Dynamic Adaptive Streaming over HTTP (DASH) causes content-dependent fragments, which can be used to identify the encrypted video traffic without decryption. This paper presents Markov probability fingerprint for video, and then designs an algorithm for encrypted video streaming title identification. We demonstrate that an external attacker can identify the video title by analyzing the fragment sequence of encrypted video traffic. Based on the m-order Markov chain, we use the transition tensor of the fragment sequence generated by the video traffic as the video fingerprint, and prove its effectiveness. Then we explore approaches that can further improve the performance of methods in terms of discrimination accuracy. We make promising observations that the higher-order Markov chain, larger training set, and more detailed binning of fragments contribute to encrypted video traffic discrimination. We run a thorough set of experiments that illustrate that our method can achieve an outstanding accuracy rate up to 97.5%, which is superior to previous work. Luming Yang, Shaojing Fu, Yuchuan Luo, Jiangyong Shi |
MSN | 3 |
| 2020 | Privacy-Preserving Reputation Management for Blockchain-Based Mobile CrowdsensingabstractMobile crowdsensing (MCS) is an emerging data acquisition technique that combines crowdsourcing with mobile devices to collect massive data in a cost-satisfactory manner. Two notable challenges of MCS are leakage of privacy and the challenge of malicious users, privacy-preserving reputation management scheme is an efficient method to tackle these challenges. However, most existing schemes rely on a semi-honest server and process data in plaintext domain without considering single point of failure and privacy of participants. In this paper we propose a reputation management scheme with blockchain to identify malicious users and protect users’ privacy simultaneously in MCS scenario. The secure and open nature of blockchain are exploited to build a dependable and efficient reputation management platform. Moreover, we adopt a distributed computing algorithm, Eigentrust, to construct a distributed reputation management framework, nevertheless, it neglects to preserve users’ privacy. So we leverage a verifiable secret sharing scheme into Eigentrust algorithm, which can prevent users’ personal information from being disclosed. The extensive analysis and experiments performed on EOS blockchain demonstrate that our system can effectively identify malicious users while preserving privacy. Yuchuan Luo, Shaojing Fu, Tao Xie 0012 |
SECON | 2 |
| 2019 | Achieve Privacy-Preserving Truth Discovery in Crowdsensing SystemsabstractTo solve the problem that the data collected in crowdsensing systems are not reliable, a large number of truth discovery protocols have been proposed. However, most of them neglect the privacy protection existing in crowdsensing systems. Some truth discovery protocols that consider privacy only provide limited privacy protection, such as only protecting the privacy of collected data. To bridge the gap, in this paper, we propose a more comprehensive privacy-preserving truth discovery protocol that can simultaneously protect the privacy of participants and truth results. Specifically, our protocol encrypts participants' observed data based on Paillier Homomorphic Cryptosystem. Then, through the interaction between two servers, we can calculate participants' weights and estimate the truth results in the encrypted domain. Moreover, based on the data perturbation technology, the privacy of sensitive data exchanged between the two servers is protected in our protocol. Theoretical analysis and experimental results demonstrate that our protocol can effectively protect the privacy of participants and truth results without losing the accuracy of truth results. Jianchao Tang, Shaojing Fu, Ming Xu 0002, Yuchuan Luo |
CIKM | 4 |
| 2019 | PDCS: A Privacy-Preserving Distinct Counting Scheme for Mobile Sensing
Ming Xu 0002, Shaojing Fu, Yuchuan Luo |
DASFAA (1) | 4 |
| 2019 | pRide: private ride request for online ride hailing service with secure hardware enclaveabstractPromising unprecedented convenience, Online Ride Hailing (ORH) service such as Uber and Didi has gained increasing popularity. Different from traditional taxi service, this new on-demand transportation service allows users to request rides from the online service providers at the touch of their fingers. Despite such great convenience, existing ORH systems require the users to expose their locations when requesting rides - a severe privacy issue in the face of untrusted or compromised service providers. In this paper, we propose a private yet efficient ride request scheme, allowing the user to enjoy public ORH service without sacrificing privacy. Unlike previous works, we consider a more practical setting where the information about the drivers and road networks is public. This poses an open challenge to achieve strong security and high efficiency for the secure ORH service. Our main leverage in addressing this problem is hardware-enforced Trusted Execution Environment, in particular Intel SGX enclave. However, the use of secure enclave does not lead to an immediate solution due to the hardware's inherent resource constraint and security limitation. To tackle the limited enclave space, we first design an efficient ride-matching algorithm utilizing hub-based labeling technique, which avoids loading massive road network data into enclave during online processing. To defend against side-channel attacks, we take the next step to make the ride-matching algorithm data-oblivious, by augmenting it with oblivious label access and oblivious distance computation. The proposed solution provides high efficiency of real-time response and strong security guarantee of data-obliviousness. We implement a prototype system of the proposed scheme and thoroughly evaluate it from both theoretical and experimental aspects. The results show that the proposed scheme permits accurate and real-time ride-matching with provable security. Yuchuan Luo, Xiaohua Jia, Huayi Duan, Cong Wang 0001, Ming Xu 0002, Shaojing Fu |
IWQoS | 1 |
| 2019 | pRide: Privacy-Preserving Ride Matching Over Road Networks for Online Ride-Hailing ServiceabstractAn online ride-hailing (ORH) service, such as Uber and Didi Chuxing, can provide on-demand transportation service to users via mobile phones, which brings great convenience to people's daily lives. Along with the convenience, high privacy concerns are also raised when using an ORH service since users and drivers must share their real-time locations with the ORH server, which results in the leakage of the mobility patterns and additional privacy of users and drivers. In this paper, we propose a privacy-preserving ride-matching scheme, called pRide, for ORH service. pRide allows an ORH server to efficiently match rider and drivers based on their distances in the road network without revealing the location privacy of riders and drivers. Specifically, we make use of the road network embedding technique together with cryptographic primitives and design a scheme to securely and efficiently estimate the shortest distances between riders and drivers in road networks approximately. Moreover, by incorporating garbled circuits, the proposed scheme is able to output the nearest driver around a rider. We implement the scheme and evaluate it on the representative real-world datasets. The theoretical analysis and experimental results demonstrate that pRide achieves an efficient, secure, and yet accurate ride matching for ORH service. Yuchuan Luo, Xiaohua Jia, Shaojing Fu, Ming Xu 0002 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2018 | Efficient auditing for shared data in the cloud with secure user revocation and computations outsourcing
Yuchuan Luo, Ming Xu 0002, Dongsheng Wang 0004, Shaojing Fu |
Comput. Secur. | 1 |
| 2017 | Efficient and generalized geometric range search on encrypted spatial data in the cloudabstractWith cloud services, users can easily host their data in the cloud and retrieve the part needed by search. Searchable encryption is proposed to conduct such process in a privacy-preserving way, which allows a cloud server to perform search over the encrypted data in the cloud according to the search token submitted by the user. However, existing works mainly focus on textual data and merely take numerical spatial data into account. Especially, geometric range search is an important queries on spatial data and has wide applications in machine learning, location-based services(LBS), computer-aided design(CAD), and computational geometry. In this paper, we proposed an efficient and generalized symmetric-key geometric range search scheme on encrypted spatial data in the cloud, which supports queries with different range shapes and dimensions. To provide secure and efficient search, we extend the secure kNN computation with dynamic geometric transformation, which dynamically transforms the points in the dataset and the queried geometric range simultaneously. Besides, we further extend the proposed scheme to support sub-linear search efficiency through novel usage of tree structures. We also present extensive experiments to evaluate the proposed schemes on a real-world dataset. The results show that the proposed schemes are efficient over encrypted datasets and secure against the curious cloud servers. Yuchuan Luo, Shaojing Fu, Dongsheng Wang 0004, Ming Xu 0002, Xiaohua Jia |
IWQoS | 1 |
| 2016 | Efficient, secure and non-iterative outsourcing of large-scale systems of linear equationsabstractSolving large-scale systems of linear equations (L-SLE) is a common scientific and engineering computational task. But such problem involves enormous computing resources, which is burdensome for the resource-limited clients. Cloud computing enables computational resource-limited clients to economically outsource such problems to the cloud server. However, outsourcing LSLE to the cloud brings great security concerns and challenges since the LSLE usually contains sensitive information. Previous works for secure outsourcing LSLE are mainly based on iterative methods which cause heavy computation cost for the client side. And they usually neglect to protect the number and position privacy of zero elements in the coefficient matrix, which is not secure enough for many applications. In this paper, with a series of disguise-based techniques, we propose a new efficient and non-iterative algorithm for securely outsourcing LSLE. Our algorithm only requires two rounds of communication between the client and cloud. Furthermore, the number and positions of zero elements in coefficient matrix can be hidden from the cloud with low computational complexity. Finally, we provide extensive theoretical analysis and experimental evaluation to show its high-efficiency and security compared to the previous works. Yunpeng Yu, Yuchuan Luo, Dongsheng Wang 0004, Shaojing Fu, Ming Xu 0002 |
ICC | 2 |
| 2015 | Privacy-Preserving Public Auditing Together with Efficient User Revocation in the Mobile Environments
Feng Chen 0015, Yuchuan Luo, Yingwen Chen 0001 |
WASA | 3 |