Jinyuan Sun

dblp:22/1105 · also Jinyuan Stella Sun · DBLP profile ↗
← Back
39ranked-venue papers
9as first author
9since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 23 · 5 first-author · 2 since 2021Security and privacy · 7 · 1 first-author · 4 since 2021Systems, architecture and hardware · 5 · 3 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 IntraShuffler: A Privacy Preserving Framework for Heterogeneous DP Federated Learning
Farhin Farhad Riya, Olivera Kotevska, Jinyuan Sun
DBSec3
2026 UserIA: User-Centered Implicit Authentication Leveraging Operant Conditioning
abstract
Traditionally, authentication systems have followed a non-feedback approach, requiring users to present credentials before accessing resources. Over time, users have become accustomed to this oblivious form of authentication. However, this model offers no opportunity for users to provide feedback that could enhance the system's effectiveness. Similarly, biometric-based implicit authentication, while transparent, often excludes users entirely from the feedback loop. Incorporating user feedback into authentication systems has the potential to significantly improve their performance. Achieving this, however, requires a novel framework capable of standardizing user input, extracting meaningful information from feedback, and integrating the user more closely into the system. To this end, we challenge conventional authentication paradigms and introduce User-Centered Implicit Authentication (UserIA)-a customizable approach that extends beyond the limits of traditional schemes. UserIA maintains the transparency of implicit authentication while delivering improved accuracy and reduced overhead. To enable secure feedback-driven feature adaptation, UserIA introduces a new technique calledbehavior alignment. Additionally, it appliesuser operant conditioningfrom psychology to reinforce user behavior and further enhance authentication accuracy. We have implemented and thoroughly evaluated UserIA in a real-world environment. Experimental results demonstrate that UserIA achieves a lower Equal Error Rate (EER) and consumes less time and energy compared to existing methods.
Yingyuan Yang, Xueli Huang, Farhin Farhad Riya, Jinyuan Sun
IEEE Trans. Dependable Secur. Comput.5
2025 Balancing Trade-offs: Adaptive Differential Privacy in Interpretable Machine Learning Models
abstract
In the advancing field of machine learning, balancing accuracy, interpretability, and privacy represents a significant challenge. The problem is exacerbated by the widespread deployment of pre-trained models locally in diverse applications, which could lead to various amounts of privacy leakage. Conventional Differential Privacy strategies, in which uniform noises are applied to model gradients, guarantee data privacy at the expense of accuracy and interpretability. This paper introduces a Feature-Sensitive Adaptive Differential Privacy (FADP) framework with a unique noise-adding strategy. Noises are adaptively added based on feature importance clustering, where important features are considered for interpretability. By employing a unique masking technique, FADP selectively preserves crucial features with minimal noise interference, maintaining accuracy while enhancing interpretability. The FADP framework addresses the limitations of traditional DP methods by preserving critical channels and improving interpretability — a vital requirement in machine learning applications that demand transparency in model decisions. Through comprehensive testing, FADP is shown to balance the trade-offs among accuracy, privacy, and interpretability, marking a substantial advancement in the field of privacy-preserving machine learning.
Farhin Farhad Riya, Shahinul Hoque, Yingyuan Yang, Jinyuan Sun, Olivera Kotevska
PST4
2023 Towards Adversarial-Resilient Deep Neural Networks for False Data Injection Attack Detection in Power Grids
abstract
False data injection attacks (FDIAs) pose a significant security threat to power system state estimation. To detect such attacks, recent studies have proposed machine learning (ML) techniques, particularly deep neural networks (DNNs). However, most of these methods fail to account for the risk posed by adversarial measurements, which can compromise the reliability of DNNs in various ML applications. In this paper, we present a DNN-based FDIA detection approach that is resilient to adversarial attacks. We first analyze several adversarial defense mechanisms used in computer vision and show their inherent limitations in FDIA detection. We then propose an adversarial-resilient DNN detection framework for FDIA that incorporates random input padding in both the training and inference phases. Our simulations, based on an IEEE standard power system, demonstrate that this framework significantly reduces the effectiveness of adversarial attacks while having a negligible impact on the DNNs' detection performance. Index Terms-False Data Injection Attack, Smart Grid Communication, Deep Learning, Adversarial Attacks
Yingyuan Yang, Jinyuan Sun, Kevin Tomsovic, Hairong Qi 0001
ICCCN3
2023 Thinking Image Color Aesthetics Assessment: Models, Datasets and Benchmarks
abstract
We present a comprehensive study on a new task named image color aesthetics assessment (ICAA), which aims to assess color aesthetics based on human perception. ICAA is important for various applications such as imaging measurement and image analysis. However, due to the highly diverse aesthetic preferences and numerous color combinations, ICAA presents more challenges than conventional image quality assessment tasks. To advance ICAA research, 1) we propose a baseline model called the Delegate Transformer, which not only deploys deformable transformers to adaptively allocate interest points, but also learns human color space segmentation behavior by the dedicated module. 2) We elaborately build a color-oriented dataset, ICAA17K, containing 17K images, covering 30 popular color combinations, 80 devices and 50 scenes, with each image densely annotated by more than 1,500 people. Moreover, we develop a large-scale benchmark of 15 methods, the most comprehensive one thus far based on two datasets, SPAQ and ICAA17K. Our work, not only achieves state-of-the-art performance, but more importantly offers the community a roadmap to explore solutions for ICAA. Code and dataset are available in here.
Anlong Ming, Jinyuan Sun, Shuntian Zheng, Huadong Ma
ICCV4
2023 BubbleMap: Privilege Mapping for Behavior-Based Implicit Authentication Systems
abstract
Leveraging users' behavioral data sampled by various sensors during the identification process, implicit authentication (IA) relieves users from explicit actions such as remembering and entering passwords. Various IA schemes have been proposed based on different behavioral and contextual features such as gait, touch, and GPS. However, existing IA schemes suffer from false positives, i.e., falsely accepting an adversary, and false negatives, i.e., falsely rejecting the legitimate user due to users' behavior change and noise. To deal with this problem, we propose BubbleMap (BMap), a framework that can be seamlessly incorporated into any existing IA system to balance between security (reducing false positives) and usability (reducing false negatives) as well as reducing the equal error rate (EER). To evaluate the proposed framework, we implemented BMap on five state-of-the-art IA systems. We also conducted an experiment in a real-world environment from 2016 to 2020. Most of the experimental results show that BMap can greatly enhance the IA schemes' performances in terms of the EER, security, and usability, with a small amount of penalty on energy consumption.
Yingyuan Yang, Xueli Huang, Jinyuan Sun
IEEE Trans. Mob. Comput.4
2021 ConAML: Constrained Adversarial Machine Learning for Cyber-Physical Systems
abstract
Recent research demonstrated that the superficially well-trained machine learning (ML) models are highly vulnerable to adversarial examples. As ML techniques are becoming a popular solution for cyber-physical systems (CPSs) applications in research literatures, the security of these applications is of concern. However, current studies on adversarial machine learning (AML) mainly focus on pure cyberspace domains. The risks the adversarial examples can bring to the CPS applications have not been well investigated. In particular, due to the distributed property of data sources and the inherent physical constraints imposed by CPSs, the widely-used threat models and the state-of-the-art AML algorithms in previous cyberspace research become infeasible.
Yingyuan Yang, Jinyuan Sun, Kevin Tomsovic, Hairong Qi 0001
AsiaCCS3
2021 Differentially Private Binary- and Matrix-Valued Data Query: An XOR Mechanism
abstract
Differential privacy has been widely adopted to release continuous- and scalar-valued information on a database without compromising the privacy of individual data records in it. The problem of querying binary- and matrix-valued information on a database in a differentially private manner has rarely been studied. However, binary- and matrix-valued data are ubiquitous in real-world applications, whose privacy concerns may arise under a variety of circumstances. In this paper, we devise an exclusive or (XOR) mechanism that perturbs binary- and matrix-valued query result by conducting an XOR operation on the query result with calibrated noises attributed to a matrix-valued Bernoulli distribution. We first rigorously analyze the privacy and utility guarantee of the proposed XOR mechanism. Then, to generate the parameters in the matrix-valued Bernoulli distribution, we develop a heuristic approach to minimize the expected square query error rate under ϵ -differential privacy constraint. Additionally, to address the intractability of calculating the probability density function (PDF) of this distribution and efficiently generate samples from it, we adapt an Exact Hamiltonian Monte Carlo based sampling scheme. Finally, we experimentally demonstrate the efficacy of the XOR mechanism by considering binary data classification and social network analysis, all in a differentially private manner. Experiment results show that the XOR mechanism notably outperforms other state-of-the-art differentially private methods in terms of utility (such as classification accuracy and F 1 score), and even achieves comparable utility to the non-private mechanisms.
Tianxi Ji, Pan Li 0001, Emre Yilmaz 0002, Erman Ayday, Yanfang Ye 0001, Jinyuan Sun
Proc. VLDB Endow.6
2021 Profit-Oriented False Data Injection on Electricity Market: Reviews, Analyses, and Insights
abstract
The rapid evolution of sensor technologies and communication networks is tightly coupling the cyber and physical layers of power systems. Because a few power grids have fallen victim to cyber intrusions causing unexpected device failure and large-scale power outages, enhancing power system cybersecurity is the utmost focus of power grid development today. Financially, the deregulation of the electricity market opens the gate to profit-oriented cyberattacks. Real-time market auctions rely heavily on the accuracy of state estimation, which is susceptible to cyberattacks. Extensive reviews have been conducted on modern power system cybersecurity. However, the lack of a comprehensive and in-depth review of electricity market cyberattacks prevents independent system operators from systematically analyzing the financial consequences of cyberattacks and limits public awareness of the significant monetary loss. This article briefly summarizes previous review works and analyzes the two-settlement market design from a cybersecurity perspective. Then the current achievements of electricity market cyberattacks are discussed, and state-of-the-art works are analyzed based on their contributions. Additionally, a few possible improvements and future directions are presented.
Fangxing Li 0001, Qingxin Shi, Kevin Tomsovic, Jinyuan Sun, Lingyu Ren
IEEE Trans. Ind. Informatics5
2020 Dynamic Multi-level Privilege Control in Behavior-based Implicit Authentication Systems Leveraging Mobile Devices
abstract
Implicit authentication (IA) is gaining popularity over recent years due to its use of user behavior as the main input, relieving users from explicit actions such as remembering and entering passwords. However, such convenience comes with a cost of authentication accuracy and delay which we propose to improve in this paper. Authentication accuracy deteriorates as users' behaviors change as a result of mood, age, a change of routine, etc. Current authentication systems handle failed authentication attempts by locking the users out of their mobile devices. It is unsuitable for IA whose accuracy deterioration induces a high false reject rate, rendering the IA system unusable. Furthermore, existing IA systems leverage computationally expensive machine learning, which can introduce a large authentication delay. It is challenging to improve the authentication accuracy of these systems without sacrificing authentication delay. In this paper, we propose a multi-level privilege control (MPC) scheme that dynamically adjusts users' access privilege based on their behavior change. MPC increases the system's confidence in users' legitimacy even when their behaviors deviate from historical data, thus improving authentication accuracy. It is a lightweight feature added to the existing IA schemes that helps avoid frequent and expensive retraining of machine learning models, thus improving authentication delay. We demonstrate that MPC increases authentication accuracy by 18.63% and reduces authentication delay by 7.02 minutes on average, using a public dataset that contains comprehensive user behavior data.
Yingyuan Yang, Xueli Huang, Yanhui Guo 0001, Jinyuan Sun
MASS4
2019 A Practical Searchable Symmetric Encryption Scheme for Smart Grid Data
abstract
Outsourcing data storage to the remote cloud can be an economical solution to enhance data management in the smart grid ecosystem. To protect the privacy of data, the utility company may choose to encrypt the data before uploading them to the cloud. However, while encryption provides confidentiality to data, it also sacrifices the data owners' ability to query a special segment in their data. Searchable symmetric encryption is a technology that enables users to store documents in ciphertext form while keeping the functionality to search keywords in the documents. However, most state-of-the-art SSE algorithms are only focusing on general document storage, which may become unsuitable for smart grid applications. In this paper, we propose a simple, practical SSE scheme that aims to protect the privacy of data generated in the smart grid. Our scheme achieves high space complexity with small information disclosure that was acceptable for practical smart grid application. We also implement a prototype over the statistical data of advanced meter infrastructure to show the effectiveness of our approach.
Xiangyu Niu, Jinyuan Sun
ICC3
2019 PersonaIA: A Lightweight Implicit Authentication System Based on Customized User Behavior Selection
abstract
Motivated by the great potential of implicit and seamless user authentication, we attempt to build an implicit authentication (IA) system with adaptive sampling that automatically selects dynamic sets of activities for user behavior extraction. Various activities, such as user location, application usage, user motion, and battery usage have been popular choices to generate behaviors, the soft biometrics, for implicit authentication. Unlike password-based or hard biometric-based authentication, implicit authentication does not require explicit user action or expensive hardware. However, user behaviors can change unpredictably which renders it more challenging to develop systems that depend on them. In addition to dynamic behavior extraction, the proposed implicit authentication system differs from the existing systems in terms of energy efficiency for battery-powered mobile devices. Since implicit authentication systems including the proposed one rely on machine learning, the expensive training process needs be outsourced to the remote server. However, mobile devices may not always have reliable network connections to send real-time data to the server for training. We overcome this limitation by proposing a W-layer, an overlay that provides a practical and energy-efficient solution for implicit authentication on mobile devices. We implemented partially labeled Dirichlet allocation (PLDA) on the server side for more accurate feature extraction, and achieved 93.3 percent precision and 98.6 percent accuracy in the synthetic dataset. Furthermore, we tested the power consumption of the smartphones used for our experiments and found that our method consumed 14.5 percent of the devices' total battery usage.
Yingyuan Yang, Jinyuan Sun, Linke Guo
IEEE Trans. Dependable Secur. Comput.2
2018 Economic-Robust Transmission Opportunity Auction for D2D Communications in Cognitive Mesh Assisted Cellular Networks
abstract
Device-to-device (D2D) communications can potentially alleviate cellular network congestion by utilizing local available links, and have attracted intensive attention recently. Cognitive radio (CR) allows users to opportunistically access unused licensed spectrums. It thus serves as a great candidate technology for D2D communications, but has not been widely employed in cellular networks due to hardware development limitations. In this paper, we propose a new architecture, called cognitive mesh assisted cellular network (CMCN), in which several secondary service providers (SSPs) deploy CR routers to facilitate D2D communications among wireless users. To address the competition among the SSPs, we further construct a secondary spectrum auction market. Although a few works have studied spectrum auctions, most of them are designed for single-hop communications, and it is usually not clear whom a winning user communicates with. Uncertain spectrum availability is not considered in previous schemes either. In this paper, we propose a transmission opportunity auction scheme, called TOA, which can address these problems. Extensive simulations are conducted to validate the efficiency of the CMCN architecture and that of the TOA scheme.
Ming Li 0006, Weixian Liao, Jinyuan Sun, Xiaoxia Huang 0004, Pan Li 0001
IEEE Trans. Mob. Comput.4
2017 Energy-efficient W-layer for behavior-based implicit authentication on mobile devices
abstract
Motivated by the great potential of implicit and seamless user authentication, we attempt to build an efficient middle layer running on mobile devices to support implicit authentication (IA) systems with adaptive sampling. Various activities, such as user location, application usage, user motion, and battery usage have been popular choices to generate behaviors, the soft biometrics, for implicit authentication. Unlike password-based or hard biometric-based authentication, implicit authentication does not require explicit user action or expensive hardware. However, user behaviors can change unpredictably which renders it more challenging to develop systems that depend on them. Various machine learning algorithms have been used to address this challenge. The expensive training process is usually outsourced to the remote server but this can potentially increase the chance of data leakage. In addition, mobile devices may not always have reliable network connections to send real-time data to the server for training. Motivated by these limitations, we propose a W-layer, an overlay that provides an energy-efficient solution for real-time implicit authentication on mobile devices. The size of the data the system needs to collect at different times depends on the legitimacy of the user. This in turn affects how the sampling rate is adjusted which can reduce energy consumption. To evaluate our method, we conducted several experiments on both synthetic and real datasets. The average accuracy of identifying legitimate users is 96.73% using the synthetic dataset and 96.70% using the real dataset. Furthermore, we tested the power consumption on a low-end Nexus S smartphone to obtain a more pessimistic result. We found that our method consumed 14.5% of the device's total battery usage. The power consumption performance is expected to improve significantly on high-end mobile devices.
Yingyuan Yang, Jinyuan Sun
INFOCOM2
2016 Password-Controlled Encryption with Accountable Break-Glass Access
abstract
We propose the notion of password-controlled encryption, a two-factor scheme involving a user-chosen password and the master public/secret key pair. The data owner obtains a secret key generated from a password and the master secret key of a key generation center (KGC) after authentication, and shares this password with encryptors and an emergency contact. In normal circumstances, the data owners can enforce access control by themselves. In emergency when the data owner is unavailable, any one with the same password can request for the decryption key from a KGC, without letting the KGC to know the password. At the same time, the KGC is held accountable if the key generation process is abused. Password-controlled encryption is especially applicable for protecting electronic medical record, which provides confidentiality with break-glass access, without relying on a key-escrow server or trusted hardware.
Tao Zhang 0014, Sherman S. M. Chow, Jinyuan Sun
AsiaCCS3
2016 SPA: A Secure and Private Auction Framework for Decentralized Online Social Networks
abstract
The security and privacy threats on e-commerce have attracted intensive attention recently. The explosive growth of online social networks (OSNs) has made them potential new great marketplaces for e-commerce, which, however, raise serious security and privacyconcerns. This is mainly due to the centralized system architecture where the service provider knows all users’ private data and becomes the single point of failure. To this end, we propose a secure and private auction framework, called SPA, for decentralized online social networks (DOSNs). SPA consists of three phases: identity initiation, buyer-seller matching, and private auction. It requires no trust among the participants but can provide security, privacy, authenticity, non-repudiation, and correctness for the auctions. We analyze the computation and communication complexities of the proposed private auction scheme, which are$O(n+K)$for each node where$n$is the number of bidders and$K$is the number of pricing points. In contrast, those of previous auction schemes are$O(nK)$at best. The storage complexity is significantly lower than before as well. Security and privacy of SPA are also analyzed. Extensive experiments are conducted to validate the efficiency of SPA.
Arun Thapa, Weixian Liao, Ming Li 0006, Pan Li 0001, Jinyuan Sun
IEEE Trans. Parallel Distributed Syst.5
2015 Outsourcing Power System Simulations
abstract
The advancement of cloud-computing technologies opens new possibilities to outsource to the third-party cloud the computation-intensive and time-consuming dynamic simulations needed in power grid system research and operations. Outsourcing makes it possible to conduct dynamic simulations much faster and with lower cost than to keep all computations local. On the other hand, outsourcing, however, also gives rise to the risk of information leak, as the outsourced simulation contains sensitive information, such as critical operational parameters and projected states of the power grid. In this paper, a novel secure outsourcing scheme, combining disguising technique and code obfuscation, was proposed to enable efficient outsourcing while preserving the confidentiality of the information. It was shown that our scheme can limit the adversary's capability to obtain the sensitive information in the context of outsourcing of power system dynamic simulations.
Yue Tong, Jinyuan Sun, Kai Sun 0001, Pan Li 0001
GLOBECOM2
2015 Network steganography based on traffic behavior in dynamically changing wireless sensor networks
abstract
Previous work on network steganography mainly focused on which field(s) in the cover packet should be used to embed secret information, while largely ignoring how to generate the cover packet in the first place to make it hard to detect. As a result, the cover packet itself may raise suspicions which would defeat the purpose of network steganography. In this paper, we propose a novel traffic behavior learning scheme that can be leveraged to construct hard-to-detect cover packets even if the network traffic is analyzed at a deeper level (i.e., traffic patterns or behaviors). An unsupervised learning method based on the topic model is adopted to discover network traffic behavior. Previously captured network traces in a given network environment are used to train the topic model to learn traffic behavior. The results serve as reference to generate typical network traffic in any given environment and adapt to the network even if it is dynamically changing. In addition to traffic behavior, our model is able to capture network nodes' behavior. This is useful in that both traffic information (what packets to mimic) and node information (which nodes to mimic) can be taken into account when crafting cover packets. Our extensive simulation results show the effectiveness of the proposed scheme learning traffic behavior, indicating that the scheme can potentially be applied to other applications where traffic behavior is needed, besides network steganography.
Xiangyu Niu, Jinyuan Sun, Husheng Li
ICC2
2015 Retraining and Dynamic Privilege for Implicit Authentication Systems
abstract
With the rapid growth of the smart device market, associated security issues become more threatening and diverse than ever before. Due to the limitations of the traditional explicit authentication mechanisms (e.g., Password-based, biometrics), researchers and the industry have been promoting implicit authentication (IA) that does not require explicit user action and potentially enhances user experience to further protect devices from misuse. IA typically leverages various types of behavioral data to deduce a user behavior model for authentication purpose. However, IA systems are still at their infancy and exhibit many limitations, one of which is how to determine the best retraining frequency when updating the user behavior model. Another limitation is how to gracefully degrade user privilege, when authentication fails to identify legitimate users (i.e., False negatives) for a practical IA system. To address the first problem, we propose an algorithm that utilizes Jensen-Shannon (JS)-dis(tance) to determine the optimal retraining frequency. For the second problem, we introduce a dynamic privilege mechanism, again based on JS-dis(tance), to achieve multi-level fine-grained access control. Our simulation results show that the proposed techniques can successfully detect the degradation of accuracy of the user behavior model, as well as automatically determine and adjust to the best retraining frequency. It is also shown that the dynamic privilege-based access control reduces the impact of false negatives on legitimate users and enhances system reliability and user experience compared with the traditional lock-only method in case of authentication failure.
Yingyuan Yang, Jinyuan Sun, Chi Zhang 0001, Pan Li 0001
MASS2
2015 Guest Editorial Special Issue on Internet of Things for Smart and Connected Health
abstract
The articles in this special section are focused on two major aspects of Internet of things (IoT) technologies for smart and connected health services (SCH): 1) monitoring and assisting individuals by means of smart systems including sensors, devices, and robotics; and 2) creating interoperable digital health information infrastructures to increase medical/health information availability and use. The papers published in this SI provide evidence that SCH tools that rely upon IoT technologiescould significantly improve clinical outcomes and thequality of life of individuals undergoing monitoring.
Honggang Wang 0001, Roozbeh Jafari, Gang Zhou 0002, Krishna K. Venkatasubramanian, Jinyuan Sun, Paolo Bonato, Dalei Wu
IEEE Internet Things J.5
2015 MAC-Layer Selfish Misbehavior in IEEE 802.11 Ad Hoc Networks: Detection and Defense
abstract
In ad hoc networks, selfish nodes deviating from the standard MAC (Medium Access Control) protocol can significantly degrade normal nodes' performance and are usually difficult to detect. In this paper, we propose detection and defense schemes to identify and defend against MAC-layer selfish misbehavior, respectively, in IEEE 802.11 multi-hop ad hoc networks. Specifically, the non-deterministic nature of the IEEE 802.11 MAC protocol imposes great challenges to distinguishing selfish nodes from well-behaved nodes. Most traditional selfish misbehavior detection approaches are for wireless local area networks (WLANs) only. They either rely on a large amount of historical data to perform statistical detection, or employ throughput or delay models that are only valid in WLANs for detection. In contrast, we propose a realtime selfish misbehavior detection scheme for multi-hop ad hoc networks. It requires only several samples, and hence is more efficient and can adapt to channel dynamics more quickly. Then, based on the proposed detection scheme, we design three selfish misbehavior defense schemes against three typical kinds of smart selfish nodes. We find that the smart selfish nodes cannot degrade normal nodes' performance much without getting detected. Extensive simulation results are finally presented to validate the proposed detection and defense schemes.
Ming Li 0006, Sergio Salinas 0001, Pan Li 0001, Jinyuan Sun, Xiaoxia Huang 0004
IEEE Trans. Mob. Comput.4
2014 Cloud-Assisted Mobile-Access of Health Data With Privacy and Auditability
abstract
Motivated by the privacy issues, curbing the adoption of electronic healthcare systems and the wild success of cloud service models, we propose to build privacy into mobile healthcare systems with the help of the private cloud. Our system offers salient features including efficient key management, privacy-preserving data storage, and retrieval, especially for retrieval at emergencies, and auditability for misusing health data. Specifically, we propose to integrate key management from pseudorandom number generator for unlinkability, a secure indexing method for privacy-preserving keyword search which hides both search and access patterns based on redundancy, and integrate the concept of attribute-based encryption with threshold signing for providing role-based access control with auditability to prevent potential misbehavior, in both normal and emergency cases.
Yue Tong, Jinyuan Sun, Sherman S. M. Chow, Pan Li 0001
IEEE J. Biomed. Health Informatics2
2014 A Privacy-Preserving Attribute-Based Authentication System for Mobile Health Networks
abstract
Electronic healthcare (eHealth) systems have replaced paper-based medical systems due to the attractive features such as universal accessibility, high accuracy, and low cost. As a major component of eHealth systems, mobile healthcare (mHealth) applies mobile devices, such as smartphones and tablets, to enable patient-to-physician and patient-to-patient communications for better healthcare and quality of life (QoL). Unfortunately, patients' concerns on potential leakage of personal health records (PHRs) is the biggest stumbling block. In current eHealth/mHealth networks, patients' medical records are usually associated with a set of attributes like existing symptoms and undergoing treatments based on the information collected from portable devices. To guarantee the authenticity of those attributes, PHRs should be verifiable. However, due to the linkability between identities and PHRs, existing mHealth systems fail to preserve patient identity privacy while providing medical services. To solve this problem, we propose a decentralized system that leverages users' verifiable attributes to authenticate each other while preserving attribute and identity privacy. Moreover, we design authentication strategies with progressive privacy requirements in different interactions among participating entities. Finally, we have thoroughly evaluated the security and computational overheads for our proposed schemes via extensive simulations and experiments.
Linke Guo, Chi Zhang 0001, Jinyuan Sun, Yuguang Fang
IEEE Trans. Mob. Comput.3
2013 Economic-robust transmission opportunity auction in multi-hop wireless networks
abstract
The rapid growth of wireless devices and services exacerbates the problem of spectrum scarcity in wireless networks. Recently, spectrum auction has emerged as one of the most promising techniques to enhance spectrum utilization and mitigate this problem. Although there exist some works studying spectrum auction, most of them are designed for single-hop communications, and it is usually not clear whom a winning user communicates with. Moreover, most previous auction schemes only focus on satisfying the incentive compatibility property, also called truthfulness, but ignore another two critical properties: individual rationality, and budget balance. Thus, they may not be economic-robust. In this paper, we propose a transmission opportunity auction scheme, called TOA, which can support multi-hop data traffic, ensure economic-robustness, and generate high revenue for the auctioneer. Specifically, in TOA, instead of spectrum bands as in traditional spectrum auction schemes, users bid for transmission opportunities (TOs). A TO is defined as the permit of data transmission on a specific link using a certain band, i.e., a link-band pair. The TOA scheme is composed of three procedures: TO allocation, TO scheduling, and pricing, which are performed sequentially and iteratively until the aforementioned goals are reached. We prove that TOA is economic-robust, and conduct extensive simulations to show its effectiveness and efficiency.
Ming Li 0006, Pan Li 0001, Miao Pan, Jinyuan Sun
INFOCOM4
2013 Privacy-Preserving Profile Matching for Proximity-Based Mobile Social Networking
abstract
Proximity-based mobile social networking (PMSN) refers to the social interaction among physically proximate mobile users. The first step toward effective PMSN is for mobile users to choose whom to interact with. Profile matching refers to two users comparing their personal profiles and is promising for user selection in PMSN. It, however, conflicts with users' growing privacy concerns about disclosing their personal profiles to complete strangers. This paper tackles this open challenge by designing novel fine-grained private matching protocols. Our protocols enable two users to perform profile matching without disclosing any information about their profiles beyond the comparison result. In contrast to existing coarse-grained private matching schemes for PMSN, our protocols allow finer differentiation between PMSN users and can support a wide range of matching metrics at different privacy levels. The performance of our protocols is thoroughly analyzed and evaluated via real smartphone experiments.
Rui Zhang 0007, Jinxue Zhang, Jinyuan Sun, Guanhua Yan
IEEE J. Sel. Areas Commun.4
2012 PAAS: A Privacy-Preserving Attribute-Based Authentication System for eHealth Networks
abstract
Recently, eHealth systems have replaced paper based medical system due to its prominent features of convenience and accuracy. Also, since the medical data can be stored on any kind of digital devices, people can easily obtain medical services at any time and any place. However, privacy concern over patient medical data draws an increasing attention. In the current eHealth networks, patients are assigned multiple attributes which directly reflect their symptoms, undergoing treatments, etc. Those life-threatened attributes need to be verified by an authorized medical facilities, such as hospitals and clinics. When there is a need for medical services, patients have to be authenticated by showing their identities and the corresponding attributes in order to take appropriate healthcare actions. However, directly disclosing those attributes for verification may expose real identities. Therefore, existing eHealth systems fail to preserve patients' private attribute information while maintaining original functionalities of medical services. To solve this dilemma, we propose a framework called PAAS which leverages users' verifiable attributes to authenticate users in eHealth systems while preserving their privacy issues. In our system, instead of letting centralized infrastructures take care of authentication, our scheme only involves two end users. We also offer authentication strategies with progressive privacy requirements among patients or between patients and physicians. Based on the security and efficiency analysis, we show our framework is better than existing eHealth systems in terms of privacy preservation and practicality.
Linke Guo, Chi Zhang 0001, Jinyuan Sun, Yuguang Fang
ICDCS3
2012 Fine-grained private matching for proximity-based mobile social networking
abstract
Proximity-based mobile social networking (PMSN) refers to the social interaction among physically proximate mobile users directly through the Bluetooth/WiFi interfaces on their smartphones or other mobile devices. It becomes increasingly popular due to the recently explosive growth of smartphone users. Profile matching means two users comparing their personal profiles and is often the first step towards effective PMSN. It, however, conflicts with users' growing privacy concerns about disclosing their personal profiles to complete strangers before deciding to interact with them. This paper tackles this open challenge by designing a suite of novel fine-grained private matching protocols. Our protocols enable two users to perform profile matching without disclosing any information about their profiles beyond the comparison result. In contrast to existing coarse-grained private matching schemes for PMSN, our protocols allow finer differentiation between PMSN users and can support a wide range of matching metrics at different privacy levels. The security and communication/computation overhead of our protocols are thoroughly analyzed and evaluated via detailed simulations.
Rui Zhang 0007, Jinyuan Sun, Guanhua Yan
INFOCOM3
2012 Secure Cooperative Data Storage and Query Processing in Unattended Tiered Sensor Networks
abstract
We consider an unattended tiered sensor network (UTSN) consisting of resource-rich master nodes at the upper tier and resource-poor sensor nodes at the lower tier. Sensor nodes submit data to nearby master nodes which store the data and answer the queries from the network owner on behalf of sensor nodes. Such a cooperative data storage and query processing paradigm offers a number of advantages over traditional Homogeneous unattended sensor networks. Relying on master nodes for data storage and query processing, however, raises severe concerns about data confidentiality and query-result correctness when the sensor network is deployed in hostile environments. In particular, a compromised master node may leak hosted sensitive data to the adversary; it may also return juggled or incomplete query results to the network owner. In this paper, we take multidimensional range queries as an example to investigate secure cooperative data storage and query processing in UTSNs. We present a suite of novel schemes that can ensure data confidentiality against master nodes and also enable the network owner to verify with very high probability the authenticity and completeness of any query result by inspecting the spatial and temporal relationships among the returned data. Detailed performance evaluations confirm the high efficacy and efficiency of the proposed schemes.
Rui Zhang 0007, Jing Shi 0002, Jinyuan Sun
IEEE J. Sel. Areas Commun.4
2011 HCPP: Cryptography Based Secure EHR System for Patient Privacy and Emergency Healthcare
abstract
Privacy concern is arguably the major barrier that hinders the deployment of electronic health record (EHR) systems which are considered more efficient, less error-prone, and of higher availability compared to traditional paper record systems. Patients are unwilling to accept the EHR system unless their protected health information (PHI) containing highly confidential data is guaranteed proper use and disclosure, which cannot be easily achieved without patients' control over their own PHI. However, cautions must be taken to handle emergencies in which the patient may be physically incompetent to retrieve the controlled PHI for emergency treatment. In this paper, we propose a secure EHR system, HCPP (Healthcaresystem for Patient Privacy), based on cryptographic constructions and existing wireless network infrastructures, to provide privacy protection to patients under any circumstances while enabling timelyPHI retrieval for life-saving treatment in emergency situations. Furthermore, our HCPP system restricts PHI access to authorized (not arbitrary) physicians, who can be traced and held accountable if the accessed PHI is found improperly disclosed. Last but not least, HCPP leverages wireless network access to support efficient and private storage/retrieval of PHI, which underlies a secure and feasible EHR system.
Jinyuan Sun, Xiaoyan Zhu 0005, Chi Zhang 0001, Yuguang Fang
ICDCS1
2011 Fast identification of the missing tags in a large RFID system
abstract
RFID (radio-frequency identification) is an emerging technology with extensive applications such as transportation and logistics, object tracking, and inventory management. How to quickly identify the missing RFID tags and thus their associated objects is a practically important problem in many large-scale RFID systems. This paper presents three novel methods to quickly identify the missing tags in a large-scale RFID system of thousands of tags. Our protocols can reduce the time for identifying all the missing tags by up to 75% in comparison to the state of art.
Rui Zhang 0007, Yunzhong Liu, Jinyuan Sun
SECON4
2011 Purging the Back-Room Dealing: Secure Spectrum Auction Leveraging Paillier Cryptosystem
abstract
Microeconomics-inspired spectrum auctions can dramatically improve the spectrum utilization for wireless networks to satisfy the ever increasing service demands. However, the back-room dealing (i.e., the frauds of the insincere auctioneer and the bid-rigging between the greedy bidders and the auctioneer) poses significant security challenges, and fails all existing secure auction designs to allocate spectrum bands when considering the frequency reuse in wireless networks. In this paper, we propose THEMIS, a secure spectrum auction leveraging the Paillier cryptosystem to prevent the frauds of the insincere auctioneer as well as the bid-rigging between the bidders and the auctioneer. THEMIS incorporates cryptographic technique into spectrum auction to address the challenges of back-room dealing. It computes and reveals the results of spectrum auction while the actual bidding values of bidders are kept confidential. THEMIS also provides a novel procedure for implementing secure spectrum auction under interference constraints. It has been shown that THEMIS can effectively purge the back-room dealing with limited communication and computational complexity, and achieve similar performance compared with existing insecure spectrum auction designs in terms of spectrum utilization, revenue of the auctioneer, and bidders' satisfaction.
Miao Pan, Jinyuan Sun, Yuguang Fang
IEEE J. Sel. Areas Commun.2
2011 RescueMe: Location-Based Secure and Dependable VANETs for Disaster Rescue
abstract
Natural disasters and terrorism threaten our nation's safety and security, rendering post-disaster rescue mission critical. It is of paramount importance to carry out rescue work relying on secure and dependable networking. In this paper, we propose RescueMe, location-based vehicular ad hoc networks (VANETs), to aid in secure and dependable rescue planning for the efficient allocation of rescue resources. RescueMe leverages the location information stored during normal network operations to facilitate post-disaster rescue planning, while guaranteeing that the sensitive user location information is not exploited to trace a user's whereabouts when disasters are absent, even if the most powerful collusion attack is allowed. We provide a novel construction for the location update message, and propose several enhancements, to achieve the functional and security goals of RescueMe.
Jinyuan Sun, Xiaoyan Zhu 0005, Chi Zhang 0001, Yuguang Fang
IEEE J. Sel. Areas Commun.1
2011 SAT: A Security Architecture Achieving Anonymity and Traceability in Wireless Mesh Networks
abstract
Anonymity has received increasing attention in the literature due to the users' awareness of their privacy nowadays. Anonymity provides protection for users to enjoy network services without being traced. While anonymity-related issues have been extensively studied in payment-based systems such as e-cash and peer-to-peer (P2P) systems, little effort has been devoted to wireless mesh networks (WMNs). On the other hand, the network authority requires conditional anonymity such that misbehaving entities in the network remain traceable. In this paper, we propose a security architecture to ensure unconditional anonymity for honest users and traceability of misbehaving users for network authorities in WMNs. The proposed architecture strives to resolve the conflicts between the anonymity and traceability objectives, in addition to guaranteeing fundamental security requirements including authentication, confidentiality, data integrity, and nonrepudiation. Thorough analysis on security and efficiency is incorporated, demonstrating the feasibility and effectiveness of the proposed architecture.
Jinyuan Sun, Chi Zhang 0001, Yuguang Fang
IEEE Trans. Dependable Secur. Comput.1
2010 Preserving Privacy in Emergency Response Based on Wireless Body Sensor Networks
abstract
E-healthcare is becoming a vital part of our living environment and exhibits advantages over paper-based legacy systems. Wireless body sensor networks are indispensable in one application of e-healthcare, the remote monitoring or remote care services. However, privacy is the foremost concern of the patients and the biggest impediment of the deployment of e-healthcare systems. In addressing privacy issues, conflicts from the functional requirements must be taken into account. One such requirement is the efficient and effective response to medical emergencies. In this paper, we propose to solve these conflicting goals based on suitable cryptographic schemes. In addition, security enhancements are proposed which satisfy other fundamental security goals besides the privacy requirements.
Jinyuan Sun, Xiaoyan Zhu 0005, Yuguang Fang
GLOBECOM1
2010 A Privacy-Preserving Scheme for Online Social Networks with Efficient Revocation
abstract
Online social networks (OSNs) are attractive applications which enable a group of users to share data and stay connected. Facebook, Myspace, and Twitter are among the most popular applications of OSNs where personal information is shared among group contacts. Due to the private nature of the shared information, data privacy is an indispensable security requirement in OSN applications. In this paper, we propose a privacy-preserving scheme for data sharing in OSNs, with efficient revocation for deterring a contact's access right to the private data once the contact is removed from the social group. In addition, the proposed scheme offers advanced features such as efficient search over encrypted data files and dynamic changes to group membership. With slight modification, we extend the application of the proposed scheme to anonymous online social networks of different security and functional requirements. The proposed scheme is demonstrated to be secure, effective, and efficient.
Jinyuan Sun, Xiaoyan Zhu 0005, Yuguang Fang
INFOCOM1
2010 Cross-Domain Data Sharing in Distributed Electronic Health Record Systems
abstract
Cross-organization or cross-domain cooperation takes place from time to time in Electronic Health Record (EHR) system for necessary and high-quality patient treatment. Cautious design of delegation mechanism must be in place as a building block of cross-domain cooperation, since the cooperation inevitably involves exchanging and sharing relevant patient data that are considered highly private and confidential. The delegation mechanism grants permission to and restricts access rights of a cooperating partner. Patients are unwilling to accept the EHR system unless their health data are guaranteed proper use and disclosure, which cannot be easily achieved without cross-domain authentication and fine-grained access control. In addition, revocation of the delegated rights should be possible at any time during the cooperation. In this paper, we propose a secure EHR system, based on cryptographic constructions, to enable secure sharing of sensitive patient data during cooperation and preserve patient data privacy. Our EHR system further incorporates advanced mechanisms for fine-grained access control, and on-demand revocation, as enhancements to the basic access control offered by the delegation mechanism, and the basic revocation mechanism, respectively. The proposed EHR system is demonstrated to fulfill objectives specific to the cross-domain delegation scenario of interest.
Jinyuan Sun, Yuguang Fang
IEEE Trans. Parallel Distributed Syst.1
2010 An Identity-Based Security System for User Privacy in Vehicular Ad Hoc Networks
abstract
Vehicular ad hoc network (VANET) can offer various services and benefits to users and thus deserves deployment effort. Attacking and misusing such network could cause destructive consequences. It is therefore necessary to integrate security requirements into the design of VANETs and defend VANET systems against misbehavior, in order to ensure correct and smooth operations of the network. In this paper, we propose a security system for VANETs to achieve privacy desired by vehicles and traceability required by law enforcement authorities, in addition to satisfying fundamental security requirements including authentication, nonrepudiation, message integrity, and confidentiality. Moreover, we propose a privacy-preserving defense technique for network authorities to handle misbehavior in VANET access, considering the challenge that privacy provides avenue for misbehavior. The proposed system employs an identity-based cryptosystem where certificates are not needed for authentication. We show the fulfillment and feasibility of our system with respect to the security goals and efficiency.
Jinyuan Sun, Chi Zhang 0001, Yuguang Fang
IEEE Trans. Parallel Distributed Syst.1
2009 Defense against misbehavior in anonymous vehicular ad hoc networks
Jinyuan Sun, Yuguang Fang
Ad Hoc Networks1
2008 A Security Architecture Achieving Anonymity and Traceability in Wireless Mesh Networks
abstract
Anonymity has received increasing attention in the literature due to the users' awareness of their privacy nowadays. Anonymity provides protection for users to enjoy network services without being traced. While anonymity related issues have been extensively studied in payment-based systems such as e-cash [1] and peer-to-peer (P2P) [2] systems, little effort has been devoted to wireless mesh networks (WMNs). On the other hand, the network authority requires conditional anonymity such that misbehaving entities in the network remain traceable. In this paper, we propose a security architecture to ensure unconditional anonymity for honest users and traceability of misbehaving users for network authorities in WMNs. The proposed architecture strives to resolve the conflicts between the anonymity and traceability objectives, in addition to guaranteeing fundamental security requirements including authentication, confidentiality, data integrity, and non-repudiation [3]. Further security enhancements can be incorporated, rendering the proposed architecture conditionally anonymous in terms of network access activities, location information, and communication paths.
Jinyuan Sun, Chi Zhang 0001, Yuguang Fang
INFOCOM1