Zheng Zhang 0060

dblp:181/2621-60 · DBLP profile ↗
← Back
3ranked-venue papers in the field
0as first author
3since 2021 · last 2022
0000-0001-9190-6454ORCID · conflict

Domains — venue-derived; a paper can count in several

Other / Interdisciplinary · 3
YearPublicationVenuePosition
2022 Towards robust and stealthy communication for wireless intelligent terminals
abstract
Fifth-generation (5G) wireless systems provide an opportunity for improving the existing Voice over Internet Protocol communication service's user experience. To mitigate the security risk of 5G data leakage, building covert channel is an alternative approach of providing confidential data transmission. Due to the high transmission rate of 5G, the interpacket intervals become small and derandomized, this caused the encoding phase of the covert timing channel imports relatively large modulation errors. rearranging is a widespread phenomenon that is occurred over the data communications. In this paper, we propose a rearrangement covert channel approach named Hybrid Variable-length Packet Rearrangement Covert Timing Channel (HVPR-CTC), which artificially chooses the delimiter packets and identification (ID) packets from the overt traffics, and encodes the packet sending order between adjacent delimiter packets according to a generated hybrid variable-length codeword dictionary, and embeds the secret message by rearranging the sending order of the ID packets. The experiments demonstrate that the HVPR-CTC scheme can effectively perform strategy adjustment: its minimum Location Square Deviation is 0.832 and minimum Swap Deviation is 139. the maximum throughput reaches 14.37 bps, and the optimal Bit Error Rate is 3.27% and 9.70% for low-channel noise and high-channel noise communication conditions, respectively.
Kefan Qiu, Zheng Zhang 0060, Yuanzhang Li 0001
Int. J. Intell. Syst.3
2022 Security of federated learning for cloud-edge intelligence collaborative computing
abstract
Federated Learning (FL) is one of the key technologies to solve privacy protection for cloud-edge intelligent collaborative computing, and its security and privacy issues have attracted extensive attention from academia and industry. FL is a distributed privacy protection framework. Multiple edged nodes or servers jointly train a machine learning model by sharing model parameters without exchanging local data. However, there are still many security risks and privacy threats in FL in edge-cloud collaborative computing. In this paper, we mainly discuss the security and privacy challenges on FL in collaborative computing at the edge. First, we introduce the principle, classification, and threat model of FL in edge-cloud collaboration, which helps understand the challenges faced by edge-cloud collaborative computing. Second, privacy leakage attacks and poisoning attacks launched by adversaries or honest but curious actors are summarized and compared. Then, the problems existing on the attack method are summarized and analyzed. Finally, the future development direction of FL in the field of edge-cloud collaborative computing is further discussed.
Jun Zheng 0007, Zheng Zhang 0060, Q. I. Chen, Duncan S. Wong, Yuanzhang Li 0001
Int. J. Intell. Syst.3
2022 Hybrid isolation model for device application sandboxing deployment in Zero Trust architecture
abstract
With recent cyber security attacks, the “border defense” security protection mechanism has often penetrated and broken through, and the “borderless” security defense idea—Zero Trust was proposed. The device application sandbox deployment model is one of the four essential Zero Trust architecture device deployment models. The isolation of the application sandbox directly affects the security of trusted applications. Given the security risks, such as sandbox escape in the sandbox application, we propose a hybrid isolation model based on access behavior and give the formal definition and security characteristics of the model. The model dynamically determines the security identity of the subject according to the access behavior and controls the access operation of the application sandbox. Therefore, the sandbox meets the characteristics of autonomous security, domain isolation, and integrity, ensuring that the system is always in an isolated safe state and easy to use. Finally, we implement the security model based on the container and Linux security module, and test the network and disk performance of this model. What is more, we make security comparison experiments based on the same container escape vulnerability. The experimental results show that the security model proposed in this paper effectively enhances the security of the device application sandboxing deployment model in Zero Trust architecture, and has a better performance compared with Container-SELinux.
Jingci Zhang, Jun Zheng 0007, Zheng Zhang 0060, Kefan Qiu, Quanxin Zhang 0001, Yuanzhang Li 0001
Int. J. Intell. Syst.3