Yaxing Chen

dblp:219/7732 · DBLP profile ↗
← Back
12ranked-venue papers
4as first author
9since 2021 · last 2024
0000-0003-3945-8468ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 3 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Computer networks · 2 · 2 since 2021Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2024 FlexiGuard: Self-Adaptive and Dynamic Context-Based Access Control for Cross-Domain Data Sharing
abstract
Access control for data sharing among multiple autonomous organizations remains a challenging problem, as existing solutions typically rely on predefined static rules and cannot adapt well to such a scenario featured by hierarchical cross-domain data circulation with dynamic control contexts. While zero trust emerges as a promising tool to solve the problem, integrating it with a data-centric access control model that can dynamically generate context-aware policies and efficiently enforce trustworthy authorization and authentication is a non-trivial task. In this paper, we propose a self-adaptive and dynamic access control framework for cross-domain data sharing, which follows up zero-trust security principles and exploits blockchains coupled with rule learning to facilitate context-based access control. Specifically, our approach utilizes real-time contextual information for dynamic rule learning and compiles multiple rule clusters guided by Dempster-Shafer evidence theory to generate precise and adaptive control policies. Experimental results show that the proposed framework achieves desired security goals with a minimal performance overhead (approximately no more than 13 milliseconds), even for large-scale networks with high-concurrency tasks.
Yaxing Chen, Bo Zhang 0119, Feifei Bu, Shiqian Wang, Zhipeng Shao, Zhiwen Yu 0001
MSN2
2023 Practical Earphone Eavesdropping with Built-in Motion Sensors
abstract
The rising popularity of ear-wear devices equipped with motion sensors has brought concerns regarding privacy issues due to their powerful sensing capabilities. Previous studies have shown the potential for speech eavesdropping using earphone motion sensors with a sampling frequency of 1000 Hz. However, as the risks of such attacks continue to escalate, mobile operating systems like Android have imposed limitations on the sampling frequency, typically no more than 200 Hz, to avoid such attacks. The lower sampling frequency reduces the amount of collected information within the same timeframe, potentially leading to decreased accuracy. In this paper, we further investigate the effectiveness of utilizing earphone motion sensors for inferring sensitive information at a sampling frequency of 200 Hz while directly using raw data without any data transformation to prevent information loss. We employ a channel attention mechanism to dynamically adjust axis weights to address the varying energy levels across different sensor axes. Meanwhile, we analyze the impact of sampling frequency, environment, and volume on speech recognition performance. Additionally, we explore the extraction of other information from speech signals, such as speaker identity and gender. Our experiments on two datasets demonstrate high recognition accuracy for all three tasks at the 200Hz sampling frequency. We expect our work to raise awareness among manufacturers regarding the privacy issues associated with earphone motion sensors.
Mengzhen Gao, Helei Cui, Yanze Xie, Yaxing Chen, Zhiwen Yu 0001, Bin Guo 0001, Xingliang Yuan
ICPADS4
2023 Harnessing Edge Computing Resources for Accelerating Industrial Tasks
abstract
Cloud-edge collaboration, as an emerging computing paradigm, aims to solve the shortcomings of remote transmission of conventional cloud computing. More precisely, it combines the powerful resource service capability of cloud computing with the advantages of low latency and relatively low energy consumption of edge computing to achieve the goal of optimization of various applications. However, with the rapid growth of computation-intensive industrial tasks, the overload problem of edge networks is becoming increasingly serious. Prior studies usually assume that the real-time state of edge resources has been known when selecting the offloading strategy so as to classify and execute tasks, but do not consider the fragmentation and heterogeneity features of edge computing resources. In light of these, we first generalize and model the computing resources of the edge nodes uniformly and then propose new heterogeneous task classification and recognition methods empowered by edge intelligence. We conduct intensive experiments to justify that our proposed design can minimize the data transmission delay caused by repeated computational tasks while saving energy consumption.
Tao Xing, Helei Cui, Yaxing Chen, Zihui Luo, Bin Guo 0001, Zhiwen Yu 0001, Xiaobing Guo, Yirong Ma
MSN3
2023 Decentralized and secure deduplication with dynamic ownership in MLaaS
Bo Zhang 0119, Helei Cui, Xiaoning Liu 0002, Yaxing Chen, Zhiwen Yu 0001, Bin Guo 0001
J. Inf. Secur. Appl.4
2023 ESMAC: Efficient and Secure Multi-Owner Access Control With TEE in Multi-Level Data Processing
abstract
Traditional data access control schemes only prevent unauthorized access to private data with a single owner. They are not suitable for application in a Multi-Level Data Processing (MLDP) scenario, where data are processed by a series of parties who also insert new data. Hence, the accumulated dataset should be protected through access control handled by hierarchically-structured parties who are at least partial data owners in MLDP. Existing multi-owner access control schemes mainly focus on controlling access to co-owned data of multiple entities with the equal ownership, but seldom investigates how to apply access control in MLDP. In this paper, we base the off-the-shelf Trusted Execution Environment (TEE), Intel SGX, to propose an Efficient and Secure Multi-owner Access Control scheme (ESMAC) for access authorization in MLDP. Moreover, to prevent unauthorized data disclosure by non-root data owners aiming to gain extra profits, we further introduce undercover polices to supervise their behaviors. Specifically, we design a data protection scheme based on game theory to decide the payoffs and punishments of honest and dishonest data owners, which motivates data owners to behave honestly when claiming ownership over data. Through comprehensive security analysis and performance evaluation, we demonstrate ESMAC's security and effectiveness.
Zheng Yan 0002, Wenxiu Ding, Yaxing Chen, Zhiguo Wan
IEEE Trans. Dependable Secur. Comput.5
2023 Efficient Bi-objective SQL Optimization for Enclaved Cloud Databases with Differentially Private Padding
abstract
Hardware-enabled enclaves have been applied to efficiently enforce data security and privacy protection in cloud database services. Such enclaved systems, however, are reported to suffer from I/O-size (also referred to as communication-volume)-based side-channel attacks. Albeit differentially private padding has been exploited to defend against these attacks as a principle method, it introduces a challenging bi-objective parametric query optimization (BPQO) problem and current solutions are still not satisfactory. Concretely, the goal in BPQO is to find a Pareto-optimal plan that makes a tradeoff between query performance and privacy loss; existing solutions are subjected to poor computational efficiency and high cloud resource waste. In this article, we propose a two-phase optimization algorithm called TPOA to solve the BPQO problem. TPOA incorporates two novel ideas:divide-and-conquerto separately handle parameters according to their types in optimization for dimensionality reduction;on-demand-optimizationto progressively build a set of necessary Pareto-optimal plans instead of seeking a complete set for saving resources. Besides, we introduce an acceleration mechanism in TPOA to improve its efficiency, which prunes the non-optimal candidate plans in advance. We theoretically prove the correctness of TPOA, numerically analyze its complexity, and formally give an end-to-end privacy analysis. Through a comprehensive evaluation on its efficiency by running baseline algorithms over synthetic and test-bed benchmarks, we can conclude that TPOA outperforms all benchmarked methods with an overall efficiency improvement of roughly two orders of magnitude; moreover, the acceleration mechanism speeds up TPOA by 10-200×.
Yaxing Chen, Zheng Yan 0002
ACM Trans. Database Syst.1
2022 eSwin-UNet: A Collaborative Model for Industrial Surface Defect Detection
abstract
Surface inspection of industrial equipment defection plays a vital role in real production. Traditional inspection routines require a large number of inspection workers, which not only affects production efficiency but also leads to unreliable results. Computer vision-based detection approaches, e.g., using the deep learning method, have shown great potential in this trend. Specifically, the semantic segmentation algorithm based on Convolutional Neural Network (CNN) can extract relatively complete feature information. And the Transformer, which emerged from the field of Natural Language Processing (NLP), also performs well in maintaining and transmitting semantic information. In light of these, we propose to design a segmentation model called eSwin-UNet, i.e., enhanced Swin-UNet, that leverages the advantages of the CNN and Transformer. It uses multi-scale information fusion to better integrate the feature information in the CNN and Transformer branches. Moreover, it also utilizes deep supervision and makes two branches for collaborative training to further improve accuracy. By testing with the MVTec ITODD dataset, Fl-Score and Jaccard achieve results of 0.7891 and 0.6516 respectively, which outperform most current models.
Helei Cui, Tao Xing, Jiaju Ren, Yaxing Chen, Zhiwen Yu 0001, Bin Guo 0001, Xiaobing Guo
ICPADS4
2022 Enabling Secure Deduplication in Encrypted Decentralized Storage
Bo Zhang 0119, Helei Cui, Yaxing Chen, Xiaoning Liu 0002, Zhiwen Yu 0001, Bin Guo 0001
NSS3
2021 QShield: Protecting Outsourced Cloud Data Queries With Multi-User Access Control Based on SGX
abstract
Due to the concern on cloud security, digital encryption is applied before outsourcing data to the cloud for utilization. This introduces a challenge about how to efficiently perform queries over ciphertexts. Crypto-based solutions currently suffer from limited operation support, high computational complexity, weak generality, and poor verifiability. An alternative method that utilizes hardware-assisted Trusted Execution Environment (TEE), i.e., Intel SGX, has emerged to offer high computational efficiency, generality and flexibility. However, SGX-based solutions lack support on multi-user query control and suffer from security compromises caused by untrustworthy TEE function invocation, e.g., key revocation failure, incorrect query results, and sensitive information leakage. In this article, we leverage SGX and propose a secure and efficient SQL-style query framework named QShield. Notably, we propose a novel lightweight secret sharing scheme in QShield to enable multi-user query control; it effectively circumvents key revocation and avoids cumbersome remote attestation for authentication. We further embed a trust-proof mechanism into QShield to guarantee the trustworthiness of TEE function invocation; it ensures the correctness of query results and alleviates side-channel attacks. Through formal security analysis, proof-of-concept implementation and performance evaluation, we show that QShield can securely query over outsourced data with high efficiency and scalable multi-user support.
Yaxing Chen, Zheng Yan 0002
IEEE Trans. Parallel Distributed Syst.1
2019 Towards Efficient Fine-Grained Access Control and Trustworthy Data Processing for Remote Monitoring Services in IoT
abstract
As an important application of the Internet of Things, many remote monitoring systems adopt a device-to-cloud network paradigm. In a remote patient monitoring case, various resource-constrained devices are used to measure the health conditions of a target patient in a distant non-clinical environment and the collected data are sent to the cloud backend of an authorized health care service for processing and decision making. As the measurements involve private patient information, access control and trustworthy processing of the confidential data become very important. Software-based solutions that adopt advanced cryptographic tools, such as attribute-based encryption and fully homomorphic encryption, can address the problem, but they also impose substantial computation overhead on both client and server sides. In this paper, we deviate from the conventional software-based solutions and propose a secure and efficient remote monitoring framework, called SRM, using the latest hardware-based trustworthy computing technology, such as Intel SGX. In addition, we present a robust and lightweight “heartbeat” protocol to handle notoriously difficult key revocation problem. We implemented a prototype of the framework for SRM and show that SRM can protect user data privacy against unauthorized parties, with minimum performance cost compared to existing software-based solutions.
Yaxing Chen, Wenhai Sun, Ning Zhang 0017, Wenjing Lou, Y. Thomas Hou 0001
IEEE Trans. Inf. Forensics Secur.1
2018 A Secure Remote Monitoring Framework Supporting Efficient Fine-Grained Access Control and Data Processing in IoT
Yaxing Chen, Wenhai Sun, Ning Zhang 0017, Wenjing Lou, Y. Thomas Hou 0001
SecureComm (1)1
2018 Associate multi-task scheduling algorithm based on self-adaptive inertia weight particle swarm optimization with disruption operator and chaos operator in cloud environment
Rong Zhang 0011, Feng Tian 0002, Xiaochun Ren, Yaxing Chen, Kuo-Ming Chao, Ruomeng Zhao, Bo Dong 0001, Wei Wang 0114
Serv. Oriented Comput. Appl.4