EDBT 2026 Demo / reviewers in the wild / expert
Haojin Zhu
dblp:22/5702
· DBLP profile ↗
174ranked-venue papers
9as first author
61since 2021 · last 2026
0000-0001-5079-4556ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 97 · 8 first-author · 22 since 2021Security and privacy · 55 · 32 since 2021Systems, architecture and hardware · 10 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 4Applied, interdisciplinary, general and emerging computing · 4 · 2 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | EXIA: Trusted Transitions for Enclaves via External-Input Attestation
Yidi Kao, Sanchuan Chen, Guoxing Chen, Yan Meng 0001, Haojin Zhu |
NDSS | 6 |
| 2026 | Spatially Aware Covert and Jam-Resilience Terahertz Uncrewed Aerial Vehicle CommunicationsabstractTerahertz (THz) band unmanned aerial vehicle (UAV) links exploit ultra-wide spectra and high directivity to deliver multi-Gbps secure data for remote sensing and wireless backhaul, but their open three-dimensional flight paths increase vulnerability to covert detection and jamming. Altitude-dependent atmospheric loss, negligible in microwave or terrestrial THz studies, becomes critical in this band owing to triple selectivity, where propagation varies sharply with frequency, distance, and environment. In this paper, a spatially-aware transmission framework is proposed that jointly allocates spectrum and power according to node altitude and beam orientation to maximize jam-resilience covert throughput. Specifically, a three-dimensional propagation model incorporating altitude-dependent molecular absorption, weather loss, and turbulence is established, closed-form expressions for covert outage probability and throughput are derived, and the resulting nonconvex band-wise optimization is solved. Simulation results verify significant gains in covert throughput and jamming robustness and reveal that downward transmissions are more secure than upward counterparts, as their propagation path traverses denser and more absorptive air, whereas the upward path quickly rises into thinner layers that expose the signal to remote eavesdroppers. These analytical insights furnish a quantitative basis for altitude-aware spectrum planning and multilayer topology design in future space-air-ground integrated networks. Weijun Gao 0001, Chong Han 0001, Zhi Chen 0002, Haojin Zhu |
IEEE J. Sel. Areas Commun. | 4 |
| 2026 | Guard Against Infringement: An Anti-Distillation Federated Learning Watermarking FrameworkabstractTo balance the gap between data privacy and the need for data fusion, federated learning (FL) has been proposed and has become a hot-point method to address data silos and privacy issues. However, AI models exchanged in FL face risks such as illegal copying, redistribution and/or free-riding. To address these risks, FL watermarking frameworks have been proposed to assert and protect the intellectual property (IP) of models, which are resistant to popular watermark removal attacks. Knowledge distillation has recently been of significant contribution to FL convergence performance optimization but brings vulnerability to FL watermark robustness with distillation attack, which enables attackers to maintain high performance on the main task while erasing the watermarks. In response, we introduce a new FL watermarking framework called FedRW, which focuses specifically on anti-distillation. FedRW employs model regularization techniques to bind the main task parameters with the watermark task parameters, thereby enhancing resistance to distillation attacks. Extensive experiments confirm the threat of distillation attacks in FL and demonstrate that FedRW is more resistant to distillation compared to existing FL watermarking frameworks. Xiao Yi, Hengrun Zhang 0001, Huiqun Yu, Guisheng Fan, Haojin Zhu |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | Vetting Privacy Policies in Virtual Reality Platforms With Longitudinal AnalysisabstractWith the help of advanced sensors, virtual reality (VR) apps provide users with an immersive experience, but they also have the potential to collect a wider range of user data compared to traditional web and mobile apps. As a result, increasing numbers of regulations are being introduced globally, emphasizing the need for app developers to provide privacy policies that inform users about data collection, usage, and sharing (CUS) process. Unfortunately, despite the significant efforts made by VR developers to improve app performance, it remains unclear how they ensure their privacy policies comply with regulations and meet user expectations. In this study, we proposeVPVetto automatically vet privacy policy issues for VR apps. We first summarize five vetting criteria based on a study of privacy policies from popular apps: availability, completeness, granularity, minimization, and consistency. We then dissect VR data and entity ontologies and manually generate VR-related CUS sentences to fine-tune privacy policy language models, overcoming performance degradation when handling VR domain-specific sentences. Finally, we construct the largest VR privacy policy dataset to date, namedVRPP, consisting of privacy policies from 11,923 VR apps across 10 mainstream platforms. These policies were crawled in late 2022 and early 2025 to investigate the evolution of the VR ecosystem. Our vetting process examines platform, app category, and longitudinal perspectives, revealing that VR privacy policies have shown severe privacy issues over the past few years, including limited availability, poor quality, coarse granularity, a lack of adaptation to VR-specific traits, and inconsistencies between CUS statements and actual app behaviors. Yan Meng 0001, Yuxia Zhan, Lichuan Ma, Guoxing Chen, Qingqi Pei, Haojin Zhu |
IEEE Trans. Netw. | 8 |
| 2025 | PipID: Light-Pupillary Response Based User Authentication for Virtual RealityabstractDuring the use of Virtual Reality (VR) applications such as gaming, education, and military training, sensitive information may be generated or collected by VR sensors, raising user concerns about potential data leakage. This highlights the critical need for effective user authentication to prevent unauthorized access. Existing authentication methods for VR are often either cumbersome (e.g., entering passwords via handheld controllers), reliant on specialized hardware (e.g., iris recognition), or vulnerable to credential replay attacks. In this study, we propose PipID, a lightweight VR authentication approach that leverages commercial off-the-shelf (COTS) eye trackers integrated into VR headsets. PipID is based on the fact that users' pupillary responses to visual stimuli vary uniquely. Thus, by displaying lights of randomly selected colors (i.e., wavelengths) on the VR screen, PipID can utilize pupil diameter responses to these wavelengths as the basis for authentication. For pupil data collected by precision-limited COTS eye trackers, PipID mitigates the impact of unrelated eye movements (e.g., blinks) and leverages pupillary response differences between the left and right eyes to further enhance the granularity of authentication features. Additionally, the randomized sequence of light colors helps prevent replay attacks. We implemented PipID on a COTS VR headset and tested it with 52 participants. Experimental results show that PipID achieves an accuracy of 98.65% and maintains robust performance under various conditions (e.g., keeping 98% and 91% accuracy after 7 and 14 days respectively). Muchen Pan, Yan Meng 0001, Yuxia Zhan, Guoxing Chen, Haojin Zhu |
CCS | 5 |
| 2025 | Latte: Layered Attestation for Portable Enclaved ApplicationsabstractTrusted Execution Environment (TEE) has become increasingly popular in privacy-protected cloud computing, and its rapid development has led to the availability of various heterogeneous TEE platforms on cloud servers. To facilitate portable TEE applications on heterogeneous TEE platforms, portable languages or intermediate representations (IRs) with platform-dependent TEE runtimes are adopted. However, existing remote attestation solutions for portable TEE applications follow a nested attestation pattern, i.e., attesting only the TEE runtime and relying on the TEE runtime to measure the loaded portable application, leading to potential security issues. On the other hand, directly packing the TEE runtime and the portable application into an enclave for secure attestation undermines the portability of the portable TEE applications.In this paper, we introduce the concept of portable identities to identify portable TEE applications, and propose a layered attestation framework, Latte, achieving both security and portability in attesting portable TEE applications. We provide a prototype implementation of Latte to validate its practicality, with WebAssembly as the portable IR, and Intel SGX and RISC-V Penglai as the exemplar heterogeneous TEEs. The evaluation demonstrates that Latte introduces minimal performance overhead compared with the nested attestation pattern. Jia Xiang, Guoxing Chen, Yan Meng 0001, Haojin Zhu |
EuroS&P | 6 |
| 2025 | The Feasibility of Location Anonymity: An Empirical Study towards a Real-world Location Privacy Protection System in Takeout Services
Ruoxu Yang, Lichuan Ma, Guoxing Chen, Haojin Zhu, Qingqi Pei |
INFOCOM | 5 |
| 2025 | The Philosopher's Stone: Trojaning Plugins of Large Language Models
Tian Dong 0003, Minhui Xue 0001, Guoxing Chen, Rayne Holland, Yan Meng 0001, Shaofeng Li 0001, Zhen Liu 0008, Haojin Zhu |
NDSS | 8 |
| 2025 | A Formal Approach to Multi-Layered Privileges for Enclaves
Ganxiang Yang, Guoxing Chen, Hongfei Fu 0001, Haojin Zhu |
NDSS | 7 |
| 2025 | Blind Points Between ASR and Intent Inferring: Vulnerability Discovering via Fuzzing in-Vehicle Voice AssistanceabstractCurrently, in-vehicle Voice Assistants (VAs) have been widely integrated into in-vehicle infotainment (IVI) systems to enhance driver safety when performing functions such as navigation and phone calls while driving. Although various studies have demonstrated the existence of vulnerabilities in general-purpose VAs, there is a lack of research specifically targeting in-vehicle VAs, which operate in a closed and black-box environment. In this paper, we utilize fuzzing testing to analyze how speech errors in voice commands affect the recognition performance of in-vehicle VAs. First, we simulate speech errors by applying linguistic knowledge to mutate voice commands. Then, we adopt a genetic algorithm to efficiently generate additional erroneous commands. To further improve the quality of these mutated commands, we assign a risk level to each original command and prioritize the mutation of those whose misrecognition by the in-vehicle VA results in an increased risk level. We conducted comprehensive fuzzing experiments on both local (Whisper–DistilBERT-based) and cloud-based (Amazon Lex) in-vehicle VA systems. Our approach generated 59112 speech-error commands in the local VA, achieving a 60.13% misrecognition rate, significantly outperforming Baseline-Fuzzing, which had an effectiveness of 40.26%. On the cloud-based VA, the effectiveness improved from 2.83% to 33.24%. These results confirm the superiority of our method in generating high-impact erroneous commands. Peilin Luo, Wei Teng, Jiachun Li 0001, Yan Meng 0001, Haojin Zhu |
TrustCom | 5 |
| 2025 | Depth Gives a False Sense of Privacy: LLM Internal States Inversion
Tian Dong 0003, Yan Meng 0001, Shaofeng Li 0001, Guoxing Chen, Zhen Liu 0008, Haojin Zhu |
USENIX Security Symposium | 6 |
| 2025 | Artificial intelligence security and privacy: a surveyabstractAbstract Artificial intelligence (AI) is revolutionizing both industries and reshaping the global economy. However, the rapid advancement of AI technologies brings significant security and privacy challenges. Recent incidents highlight vulnerabilities in AI systems, such as data leakage and malicious code injection, leading to severe financial losses and privacy breaches. Although existing studies have discussed specific security threats, they often lack detailed granularity and cover a limited scope. In this survey, we fill this gap by systematically categorizing and analyzing the threats and countermeasures in AI systems, which span both the training and inference stages, encompass centralized and distributed settings, and address both conventional and foundation AI models. By reviewing existing literature, we aim to provide AI researchers and practitioners with a thorough understanding of system vulnerabilities and current countermeasures. We hope to inspire further research into robust solutions, ultimately contributing to the development of resilient AI technologies. Xinlei He 0001, Guowen Xu, Xingshuo Han, Qian Wang 0002, Lingchen Zhao, Chao Shen 0001, Chenhao Lin, Zhengyu Zhao 0001, Qian Li 0024, Le Yang 0007, Shouling Ji, Shaofeng Li 0001, Haojin Zhu, Zhibo Wang 0001, Tianqing Zhu, Qi Li 0002, Chaoxiang He, Hongsheng Hu, Shuo Wang 0012, Shifeng Sun 0001, Hongwei Yao, Qinyu Zhang 0001, Kai Chen 0012, Yue Zhao 0027, Hongwei Li 0001, Xinyi Huang 0001, Dengguo Feng |
Sci. China Inf. Sci. | 13 |
| 2025 | A Magnetic Signal Based Device Fingerprinting Scheme in Wireless ChargingabstractWireless charging is widely used to charge smart devices with limited battery capacity. However, it is susceptible to the identity spoofing attack, where adversaries can impersonate malicious devices as legitimate ones to gain unauthorized access and potentially disrupt the wireless charging system (e.g., resulting in incorrect billing, overheating, or even explosions). Device fingerprinting is a classical method for defending against identity spoofing attacks. However, applying existing schemes in wireless charging scenarios has drawbacks such as inconvenience (e.g., requiring specialized devices or user participation) and ineffectiveness (e.g., vulnerability to spoofing). Thus, we design a novel passive, effective, and robust device fingerprinting scheme called MagID for wireless charging systems. The insight of MagID lies in the fact that during wireless charging, the magnetic signal around a device can reflect inherent hardware differences. These differences can be extracted as unique fingerprints for authentication purposes. MagID leverages a novel scheme, SUPER-ARRAY, to precisely measure magnetic data and generate effective fingerprints for authenticating a device's identity before starting charging progress. Experimental results demonstrate that MagID achieves an accuracy rate of 98.14% across various charging devices. We have also tested its performance under different impact factors and verified its compatibility with various wireless charging pads. Jiachun Li 0001, Yan Meng 0001, Guoxing Chen, Yuan Tian 0001, Haojin Zhu |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | HDWSA$^{2}$2: A Secure Hierarchical Deterministic Wallet Supporting Stealth Address and Signature AggregationabstractHierarchical Deterministic Wallet (HDW) and Stealth Address (SA) are widely used in cryptocurrency communities due to their functionality and security. In the preliminary version of this work (ESORICS 2022), we formally define the syntax and security models of Hierarchical Deterministic Wallet supporting Stealth Address (HDWSA), capturing the functionality and security requirements imposed by the practice in cryptocurrency. We propose a concrete HDWSA construction and prove its security in the random oracle model. Note that when applied in blockchain, in practice, signature aggregation could reduce the cost of computation, storage, and communication dramatically. In this full version, we develop HDWSA definition to further support signature aggregation (referred to as HDWSA$^{2}$). In particular, we first formally define HDWSA$^{2}$, which, besides enjoying all the virtues of HDWSA on functionality and security, allows multiple signatures on different messages to be aggregated into one signature. We propose a concrete HDWSA$^{2}$construction and prove its security in the random oracle model. We implement the HDWSA$^{2}$construction and the experimental results show that verification of an aggregate signature is about 13$\boldsymbol{\times }$faster than sequential verification of all the individual signatures. We can reduce the size of signatures in a single block by about 60% after aggregation. Zhen Liu 0008, Guomin Yang, Guoxing Chen, Haojin Zhu |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Binary-Level Formal Verification Based Automatic Security Ensurement for PLC in Industrial IoTabstractCurrently, the security of the control logic of Programmable Logic Controllers (PLCs) is facing a serious threat, significantly impacting industrial production. Consequently, ensuring the security of PLC control logic becomes imperative. Formal verification emerges as a promising methodology for verifing PLC security through behavioral modeling and security testing. However, existing formal verification approaches primarily focus on modeling the PLC source code, overlooking the identification of compile-time errors and real-time runtime logic checks. Therefore, it is essential to apply formal verification to PLC control logic at the binary level. In this study, we introduce VoICS, a system designed to facilitate binary-level formal verification. Using reverse engineering, VoICS automatically parses PLC programs written by various programming languages at the binary level and constructs control flow graphs (CFGs). Furthermore, we use an algorithm combining two model optimization methods (i.e., trim invalid states and unnecessary states compression) to convert the reversed PLC assembly program into nuXmv format model. Lastly, VoICS establishes the corresponding constraints and performs formal verification on the model using nuXmv. The evaluation results demonstrate the capability of VoICS in identifying instances of unreliable control logic within PLC control programs, thus reinforcing the dependability of the industrial automation system. Xuankai Zhang, Jianhua Li 0001, Jun Wu 0001, Guoxing Chen, Yan Meng 0001, Haojin Zhu, Xiaosong Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | Silent Penetrator: Breaching Cross-Domain Federated Fine-Tuning via Feature Shift-Induced BackdoorabstractTo improve communication efficiency and handle data heterogeneity challenges in federated learning (FL), fine-tuning the pre-trained large models rather than training neural networks from scratch has received increasing attention in recent years, especially under cross-domain settings. However, such a cross-domain federated fine-tuning scenario opens up a broader attack surface for new threats, especially backdoors, posing significant security risks. Existing backdoor attacks mainly focus on label shift scenarios and use explicit triggers, which lack transferability and effectiveness in cross-domain settings, thereby exhibiting significant weaknesses. In this paper, we propose Silent Penetrator, an innovative penetration scheme tailored for cross-domain federated fine-tuning, which exploits a feature shift-induced backdoor to elicit specific symptoms in the trusted private data of targeted victims. In Silent Penetrator, the attacker can obtain a high-quality poisoned dataset by leveraging the available domain information as the text prompts for Stable Diffusion, and inject a domain-sensitive backdoor that can be unconsciously triggered by unmodified private data of the victims. To achieve stronger and more persistent penetration, we thoroughly explore the adversary’s configurable space and enhance our backdoor injection utilizing contrastive-enhanced boundary deviation and cross-domain predictive confrontation. Extensive experiments on three cross-domain datasets and four state-of-the-art federated fine-tuning frameworks validate the effectiveness of Silent Penetrator in successfully compromising target clients. Furthermore, our backdoor enhancement strategy improves the penetration accuracy by over 10% in most scenarios and significantly enhances the durability of the penetration compared to four state-of-the-art backdoor enhancement techniques. Wenkai Huang 0003, Gaolei Li, Mingzhe Chen, Jianhua Li 0001, Haojin Zhu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | Synergistic Multi-Modal Keystroke Eavesdropping in Virtual Reality With Vision and Wi-FiabstractIn panoramic and immersive virtual reality (VR) scenarios, users type on a floating and invisible keyboard, which cannot be observed by external adversaries, creating the illusion that their input is confidential. While recent studies have demonstrated the feasibility of leveraging side-channel information (e.g., vision, Wi-Fi) to eavesdrop on keystrokes in VR, they assume users typically type with fixed gestures, similar to using traditional physical keyboards. However, in real world scenarios, VR creates a 3D immersive environment, allowing users to type from varying orientations. This variation significantly degrades the quality of side-channel information (e.g., occlusion in vision, instability in Wi-Fi channels), leading to ineffective inference. In this study, we propose a multi-modal keystroke eavesdropping attack called WiViLeak, which combines Wi-Fi and vision information to complement each other. To address low-quality side-channel data caused by users’ varying orientations, we develop a theoretical model to explore the relationship between users’ hand movements in physical space (from the vision modality) and fluctuating Wi-Fi signals (from the wireless modality) as users change orientation. Based on this, we design a fully transformer based orientation calibration module to recover users’ vision data, aligning it as if they were facing the camera (i.e., in a front-facing view). Meanwhile, WiViLeak reconstructs Wi-Fi data to correspond to the front-facing view, utilizing the orientation angle derived from vision data. Finally, WiViLeak extracts effective features from reconstructed, high-quality vision and Wi-Fi data to predict keystrokes. We implement a WiViLeak prototype, achieving 89.2% accuracy in eavesdropping keystrokes and 93.6% top-100 password theft accuracy, while also demonstrating robustness across various real world VR scenarios, including payments, chatting, and meetings. Jiachun Li 0001, Yan Meng 0001, Fazhong Liu, Tian Dong 0003, Suguo Du, Guoxing Chen, Yuling Chen 0002, Haojin Zhu |
IEEE Trans. Inf. Forensics Secur. | 8 |
| 2025 | Beyond Access Pattern: Efficient Volume-Hiding Multi-Range Queries Over Outsourced Data ServicesabstractMulti-range query (MRQ) is a typical multi-attribute data query widely used in various practical applications. It is capable of searching all data objects contained in a query request. Many privacy-preserving MRQ schemes have been proposed to realize MRQ on encrypted data. However, existing MRQ schemes only consider the security threat caused by access pattern leakage, not the harm of volume pattern leakage. Moreover, most existing schemes cannot achieve efficient queries and updates while preserving the access pattern. In this paper, we propose an efficient MRQ scheme for hiding volume and access patterns. We first design a joint data index using Order-Revealing Encryption (ORE) and Pseudo-random functions (PRFs) to realize volume-hiding range queries. Then, we combine the private set intersection (PSI) and hardware Software Guard Extensions (SGX) to compute each attribute’s intersection of query results. In addition, we preserve access patterns during queries by designing a batch refresh algorithm and an update protocol. Finally, rigorous security analysis and extensive experiments demonstrate the security and performance of our scheme in real-world scenarios. Haoyang Wang 0005, Kai Fan 0001, Chong Yu 0002, Kuan Zhang 0001, Fenghua Li 0001, Haojin Zhu |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | Hide Yourself: Multi-Dimensional Range Queries for Responses-Hiding Over Outsourced DataabstractMulti-dimensional range query (MRQ) over outsourced data has been extensively applied in various domains. However, security and efficiency are still two aspects that cannot be easily balanced in private MRQs, as improving security inevitably incurs high computation, storage, and communication costs. Several schemes perform encrypted data retrieval in the trusted execution environment (TEE), which balances security and performance. Unfortunately, they focused on keywords or single-dimensional range queries, failing to address private MRQs. With the TEE (i.e., Intel SGX), we propose a response-hiding MRQ scheme over encrypted data (SGX-MRQ) in this paper. We first design an index structure called SDic, which can achieve efficient range queries while hiding the responses to each query from the server. Moreover, based on the security properties of SGX, we construct the encrypted polynomials of each dimension on the enclave and implement the intersection computation of multi-attribute queries by the server, which greatly improves the system efficiency. We present the formal definition of SGX-MRQ and perform a rigorous proof. We implement a prototype of SGX-MRQ and conduct extensive experiments on real datasets. The evaluation results validate the feasibility of our scheme in practical applications. Haoyang Wang 0005, Kai Fan 0001, Chong Yu 0002, Kuan Zhang 0001, Fenghua Li 0001, Haojin Zhu |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | VR-Fi: Positioning and Recognizing Hand Gestures via VR-Embedded Wi-Fi SensingabstractAccurate gesture-based interactions are crucial for enhancing the immersive experience in VR (virtual reality) systems; they in turn necessitate gesture positioning and recognition inphysical world. However, existing VR gesture recognition methods are predominantly vision-based, incurring high computational demands and raising privacy concerns. Meanwhile, Wi-Fi-based gesture recognition methods, deemed as promising complement to vision-based ones, typically lack gesture positioning capabilities. To this end, we propose VR-Fi, a gesture positioning and recognition system leveraging VR(-headset)-embedded Wi-Fi. To position gestures across different areas, VR-Fi innovates in afrequency-hopping bandwidth expansion(FHBE) technique to improve spatial resolution for locating a target. Additionally, VR-Fi innovates in neural models to process the FHBE-enhanced Wi-Fi CSI (channel state information) and enable the multi-task requirements of the joint positioning and recognition of hand gestures. Extensive experimental results demonstrate that VR-Fi achieves a positioning accuracy of 94.47%, a recognition accuracy of 92.13%, and a joint accuracy of 89.47%. Xin Li 0070, Jiachun Li 0001, Haojin Zhu, Jun Luo 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | Collaborative Ad Fraud Detection in Ad NetworksabstractMobile advertising has been significantly propelled by the advent of in-app programmatic advertising and Real-Time Bidding (RTB) technologies. However, it suffers from ad fraud incidents in ad networks, including click injection, covert background ad activities, and etc. While previous research has predominantly focused on ad fraud localized within individual apps or specific devices, this paper delineates a newly identified form of collusion-based ad fraud, termed ad attribution laundering fraud (ALF).ALFinvolves multiple apps conspiring to obfuscate the true origins of where advertisements are displayed, thereby allowing lower-quality apps to leverage the reputations of ostensibly legitimate ones. To detectALF, we developed the detection tool, AlfScan-X, which efficiently identifies potential collaborative apps among millions in the wild by heuristically prioritizing candidate apps likely to be involved inALFfor prompt analysis. AlfScan-Xmaintains an online APK crawler and an$\textsf {AppID}$database to enhance AlfScan-X’s responsiveness, adaptability, and reduce false negatives. Overcoming challenges of identity extraction from diverse and obfuscated apps, AlfScan-Xutilizes a combination of static and dynamic analysis techniques to cross-verify app identities, pinpointing instances ofALF. Our evaluation of AlfScan-Xon a 200-app ground truth dataset yielded high effectiveness with 92% precision and 92% recall. AlfScan-Xidentified$4,515$unique fraudulent apps and$1,483$fraudulent clusters, revealing significant patterns and implications of fraudulent apps and highlighting reliability issues in both third-party app development frameworks and advertising networks. Guoxing Chen, Yan Meng 0001, Haojin Zhu |
IEEE Trans. Netw. | 6 |
| 2024 | VPVet: Vetting Privacy Policies of Virtual Reality AppsabstractVirtual reality (VR) apps can harvest a wider range of user data than web/mobile apps running on personal computers or smartphones. Existing law and privacy regulations emphasize that VR developers should inform users of what data are collected/used/shared (CUS) through privacy policies. However, privacy policies in the VR ecosystem are still in their early stages, and many developers fail to write appropriate privacy policies that comply with regulations and meet user expectations. In this paper, we propose VPVet to automatically vet privacy policy compliance issues for VR apps. VPVet first analyzes the availability and completeness of a VR privacy policy and then refines its analysis based on three key criteria: granularity, minimization, and consistency of CUS statements. Our study establishes the first and currently largest VR privacy policy dataset named VRPP, consisting of privacy policies of 11,923 different VR apps from 10 mainstream platforms. Our vetting results reveal severe privacy issues within the VR ecosystem, including the limited availability and poor quality of privacy policies, along with their coarse granularity, lack of adaptation to VR traits and the inconsistency between CUS statements in privacy policies and their actual behaviors. We open-source VPVet system along with our findings at repository https://github.com/kalamoo/PPAudit, aiming to raise awareness within the VR community and pave the way for further research in this field. Yuxia Zhan, Yan Meng 0001, Yichang Xiong, Xiaokuan Zhang, Lichuan Ma, Guoxing Chen, Qingqi Pei, Haojin Zhu |
CCS | 9 |
| 2024 | Unveiling Collusion-Based Ad Attribution Laundering Fraud: Detection, Analysis, and Security ImplicationsabstractIn recent years, the growth of mobile advertising has been driven by in-app programmatic advertising and technologies like Real-Time Bidding (RTB). However, this growth has also led to an increase in ad fraud, such as click injection, background ad activity, etc. While existing studies have primarily concentrated on ad fraud within individual apps or devices, this paper introduces a new form of collusion-based ad fraud, named ad attribution laundering fraud (ALF). ALF involves multiple apps collaborating to deceive advertisers by misrepresenting the app where ads are displayed. The collusion-based approach allows lower-quality apps to exploit the reputable identities of seemingly legitimate apps. This deceives advertisers or ad networks into believing that the advertisements they place are reaching potentially valid end-users on the legitimate app. The seemingly legitimate ad events and ad attribution procedures employed by individual apps in such attacks can evade detection by existing tools. Chaofan Shou, Guoxing Chen, Xiaokuan Zhang, Yan Meng 0001, Shuang Hao 0001, Haojin Zhu |
CCS | 8 |
| 2024 | Inferring Activities and Profiles of Users Based on Trajectory Leakage in Mobile Ad NetworkabstractWith the widespread use of smartphones and the development of ad networks, mobile in-app targeted ads have become more and more prevalent, leveraging users' geolocation for targeting purposes. This service involves a large amount of user location data, which may not only expose sensitive locations closely associated with the users, but also reveal the users' activities and profiles. Previous studies have utilized various machine learning methods to infer users' activities or predict their future activities based on the location data from location-based social networks (LBSNs). These approaches, however, often require large datasets for training and are also resource-intensive. Unlike active behaviors, such as checking in, where users intentionally record their location, location data are passively recorded by mobile apps in the background, making inferring activities more challenging. Considering the rapid progress in the reasoning abilities of the large language models (LLMs) in recent years, we aim to evaluate user's activity and profile leakage through LLMs with the assistance of map APIs. We conduct the experiment on the location dataset, which is generated according to specified profiles. The results of the experiment show that the LLM can infer users' activities with an accuracy rate scoring up to 96.1 %, and there is also a high probability of predicting the users' profiles, such as the occupation. Le Yu 0002, Tian Dong 0003, Yan Meng 0001, Shaofeng Li 0001, Guoxing Chen, Haojin Zhu |
MSN | 7 |
| 2024 | A Duty to Forget, a Right to be Assured? Exposing Vulnerabilities in Machine Unlearning Services
Hongsheng Hu, Shuo Wang 0012, Jiamin Chang, Haonan Zhong, Ruoxi Sun 0001, Shuang Hao 0001, Haojin Zhu, Minhui Xue 0001 |
NDSS | 7 |
| 2024 | Yes, One-Bit-Flip Matters! Universal DNN Model Inference Depletion with Runtime Code Fault Injection
Shaofeng Li 0001, Xinyu Wang 0004, Minhui Xue 0001, Haojin Zhu, Zhi Zhang 0001, Yansong Gao 0001, Wen Wu 0003, Xuemin Shen |
USENIX Security Symposium | 4 |
| 2024 | DevDet: Detecting IoT Device Impersonation Attacks via Traffic Based Identification
Hongliang Yong, Le Yu 0002, Tian Dong 0003, Yan Meng 0001, Guoxing Chen, Haojin Zhu |
WASA (2) | 6 |
| 2024 | Privacy-Preserving Liveness Detection for Securing Smart Voice InterfacesabstractSmart speakers are widely used as the primary user interface in intelligent systems, including smart homes and industrial IoT. However, they are vulnerable to voice spoofing attacks which result in malicious command execution or privacy information leakage. Passive liveness detection, which thwarts voice spoofing via analyzing the collected audio rather than deploying sensors to distinguish between live-human and spoofing voices, has drawn increasing attention. But existing schemes either face performance degradation under environmental factor changes or require the user to keep fixed gestures, which limit their deployment in real-world scenarios. Besides, the space distributed property of smart speakers causes building a universal classifier for all involved users to be cumbersome and increases privacy leakage issues. To address the challenges mentioned above, we propose LIVEARRAY, an efficient, lightweight, and privacy-preserving passive liveness detection system. LIVEARRAY exploits a novel liveness feature, array fingerprint, which utilizes the microphone array inherently adopted by the smart speaker to improve the accuracy of liveness detection. LIVEARRAY's further employs the federated learning-based architecture to reduce the dataset collection overhead during classifier building and eliminate the potential privacy leakage during data transmission. Experimental results show that LIVEARRAY achieves an accuracy of 99.16%, which is superior to existing passive schemes Yan Meng 0001, Jiachun Li 0001, Haojin Zhu, Yuan Tian 0001, Jiming Chen 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Dangers Behind Charging VR Devices: Hidden Side Channel Attacks via Charging CablesabstractVirtual reality (VR), offering 3D visuals and stereophonic sounds, significantly enhances users’ immersive experiences and has become a milestone in the era of the metaverse. However, due to the limited battery capacity of VR devices, it is common for users to rely on charging cables, which serve the dual purpose of power supply and audio output, to recharge their VR devices while in use. In this study, we propose an inconspicuous and stealthy side channel attack, coined as LineTalker, which can unveil visual-related and audio-related activities from VR devices during the charging process. The insight behind LineTalker is rooted in the observation that visual-related activities (e.g., 3D image rendering) are power-intensive and result in fluctuations in the current strength of the cable’s power supply line, which can be leveraged as side channel information. Similarly, audio-related activities (e.g., playing music) leave traces on the cable’s audio output line. Rather than providing a user with a compromised charging cable (i.e., embedding a current sensor) to measure the current strength, to make the attack less conspicuous, LineTalker employs the Hall effect to indirectly access side channel information. This is achieved by capturing magnetic signals using a Hall sensor placed near the target cable in a contactless manner. Experimental results demonstrate that LineTalker achieves an overall accuracy of 94.60% and 64.38% in inferring user activities in VR devices with intrusive and non-intrusive attack manners, respectively. Jiachun Li 0001, Yan Meng 0001, Yuxia Zhan, Haojin Zhu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | De-Anonymizing Avatars in Virtual Reality: Attacks and CountermeasuresabstractBy providing users with an immersive visual and acoustic experience, virtual reality (VR) serves as a foundational technique for the emerging metaverse. One of the most promising aspects of VR is its ability to protect users’ identities by transforming their physical appearances into avatars with arbitrary appearances in the virtual world. However, the increasing threat of de-anonymization attacks that seek to reveal users’ identities poses significant privacy risks. We propose AvatarHunter, a non-intrusive and user-unaware de-anonymization attack leveraging victims’ inherent movement signatures. AvatarHunter discreetly collects the avatar's gait information by recording videos in the VR scenario without requiring any permissions. Notably, we designed a Unity-based feature extractor that maintains the avatar's movement signature while enabling AvatarHunter to be resistant to changes in the avatar's appearance. We conduct real-world experiments on VRChat to evaluate AvatarHunter's effectiveness. The results demonstrate that in commercial settings, AvatarHunter achieves attack success rates (ASR) of 92.1% and 66.9% in closed-world and open-world avatar scenarios, respectively, significantly surpassing existing benchmarks. Additionally, simulations using an open-source dataset confirm that AvatarHunter can attain over 78% ASR in full-body tracking scenarios. Finally, we discuss several countermeasures and implement an obfuscation mechanism during the avatar rendering phase, significantly reducing the ASR. Yan Meng 0001, Yuxia Zhan, Jiachun Li 0001, Suguo Du, Haojin Zhu, Xuemin Shen |
IEEE Trans. Mob. Comput. | 5 |
| 2024 | Privacy-Preserving Location-Based Advertising via Longitudinal Geo-IndistinguishabilityabstractAs location data have been increasingly adopted in location-based advertising (LBA), revealing locations to untrusted service providers has raised severe privacy concerns. Recent studies propose obfuscation mechanisms built upon geo-indistinguishability (geo-IND) to provide formal privacy guarantee. Unfortunately, due to the high degree of spatiotemporal regularity in human mobility pattern, the privacy cost will be unacceptably high in this situation, leading to accurate inference of user real locations. In this study, we identify this privacy risk in LBA scenarios under long-term and multi-platform assumption. We demonstrate an attacker can infer 75%∼90% of top-1 locations within a range of only 200 meters. To address it, we proposePrivLocAd, a novel system which can provide longitudinal privacy guarantee. The novelty of PrivLocAd stems from a novel surrogate-based obfuscation, which generates multiple surrogate locations to improve the privacy-utility trade-off. In addition, two novel obfuscation mechanisms, the two-stage Gaussian and multi-level surrogate generation mechanism in charge of surrogate generation can achieve the longitudinal privacy guarantee in intra- and inter-platform condition respectively. Our experimental results demonstrate PrivLocAd is able to defend against the attack, which reduces the inference rate to less than 1% of user top-1 locations in the 200 meter range. Le Yu 0002, Shufan Zhang 0001, Yan Meng 0001, Suguo Du, Yuling Chen 0002, Yanli Ren, Haojin Zhu |
IEEE Trans. Mob. Comput. | 7 |
| 2024 | LSPSS: Constructing Lightweight and Secure Scheme for Private Data Storage and Sharing in Aerial ComputingabstractAerial computing is gradually playing an essential role in edge and fog computing paradigms by virtue of mobility, availability, scalability, flexibility, and simultaneity, where the Low-altitude Computing (LAC) platform, as the end close to the data sources, is mainly responsible for data collection and storage. However, because of the long physical distance of data transmission and the vulnerability of the transmission link to various attacks, how to efficiently share the stored data while ensuring data privacy is a critical issue for LAC at present. In this paper, we propose a lightweight and secure private data storage and sharing scheme to support range queries over encrypted multi-dimensional data. Specifically, we first propose two data conversion methods for transforming location features and collected log files with multi-dimensional attributes in Unmanned Aerial Vehicles (UAVs). Based on the ideas of asymmetric scalar-product-preserving encryption (ASPE) and inner product comparison (IPC), we design a privacy-preserving storage and sharing technique for the converted data. In addition, to achieve secure and efficient data querying and result verification, we design a secure data index and build a data authentication structure (DAS) with G-tree. Finally, we rigorously analyze the security of our proposed scheme and conduct extensive experiments on a real-world database to prove that our proposed scheme is secure and easy to use in practical application scenarios. Haoyang Wang 0005, Kai Fan 0001, Chong Yu 0002, Kuan Zhang 0001, Fenghua Li 0001, Hui Li 0006, Yintang Yang, Haojin Zhu |
IEEE Trans. Serv. Comput. | 8 |
| 2023 | Privacy Computing with Right to Be Forgotten in Trusted Execution EnvironmentabstractSharing private data is at risk of potential data breaches, including the violation of the “right to be forgot-ten” principle, undermining people's willingness to share their data. A common solution is to involve the Trusted Execution Environment (TEE), which allows the data provider to verify the computation process without trusting others. However, previous works have either encountered incomplete computations or lacked scalability. In this paper, we propose TEERASE,a secure data-sharing framework that addresses these issues. TEERASEprotects every phase of the data lifecycle and enables individuals to share personal data with a predefined privacy budget. In particular, TEERASEapplies comprehensive privacy budgeting mechanisms to efficiently manage privacy budgets and employs an asynchronized execution approach that decouples budget consumption from data computation. TEERASErecords the predefined privacy budgets, verifies privacy consumption requests, updates the remaining budgets, and deletes data that have exhausted their budgets by preventing any attempts to access them. We implement a prototype of TEERASEand evaluate its effectiveness with a realistic case study on Genome-Wide Association Study. Hongzhi Luo, Shaofeng Li 0001, Tian Dong 0003, Guoxing Chen, Yan Meng 0001, Haojin Zhu |
GLOBECOM | 7 |
| 2023 | Understanding and Identifying Cross-Platform UI Framework Based Potentially Unwanted AppsabstractCross-platform UI frameworks may facilitate a new category of Potentially Unwanted Apps, dubbed XPUAs, which uses framework-specific language to implement its UI in the form of cross-platform payload. XPUAs are able to bypass the existing app vetting procedures leveraging their unique technical characteristics and make revenue on addicitive contents that are strictly prohibited by either local laws or app market regulations. In this paper, we first examined the profit chain of XPUAs and then proposed PUAXray, a novel detection system that utilized machine learning to identify XPUAs. PUAXray used a binary classifier that was trained on features extracted from cross-platform payloads, including semantics information and third-party library usage information. We evaluated PUAXray on a dataset that was created for the first time in the community with benign apps from reputable app markets and XPUAs from an industry collaborator. PUAXray achieved 95.4% F1-score in the XPUAs identification task, and proved capable to be extended to other cross-platform UI frameworks. Guoxing Chen, Yan Meng 0001, Haojin Zhu |
GLOBECOM | 4 |
| 2023 | Data Poisoning Attack Against Anomaly Detectors in Digital Twin-Based NetworksabstractIn this paper, we study the abnormal behaviors detection and the corresponding data poisoning attacks in digital twin (DT)-based networks. We first analyze the abnormal behaviors existing in the DT-based networks, including environment anomalies, hardware and software faults, and network attacks. Specially, we design a machine learning (ML)-based anomaly detector to identify network attacks. Furthermore, due to the strong dependency of ML models on training data, in which the outputs of the trained ML models can be affected by the poisoned samples. We design a data poisoning attack scheme against the proposed ML-based anomaly detector, in which attackers can effectively compromise the output of anomaly detectors. Extensive experimental results adopting three commonly used ML-based models demonstrate that the attack can compromise these detectors with over 80% probability. Shaofeng Li 0001, Wen Wu 0003, Yan Meng 0001, Jiachun Li 0001, Haojin Zhu, Xuemin Shen |
ICC | 5 |
| 2023 | MagFingerprint: A Magnetic Based Device Fingerprinting in Wireless Charging
Jiachun Li 0001, Yan Meng 0001, Guoxing Chen, Yuan Tian 0001, Haojin Zhu, Xuemin Shen |
INFOCOM | 6 |
| 2023 | De-anonymization Attacks on MetaverseabstractVirtual reality (VR) can provide users with an immersive experience in the metaverse. One of the most promising properties of VR is that users’ identities can be protected by changing their physical world appearances into arbitrary virtual avatars. However, recent proposed de-anonymization attacks demonstrate the feasibility of recognizing the user’s identity behind the VR avatar’s masking. In this paper, we propose AvatarHunter, a non-intrusive and user-unconscious de-anonymization attack based on victims’ inherent movement signatures. AvatarHunter imperceptibly collects the victim avatar’s gait information via recording videos from multiple views in the VR scenario without requiring any permission. A Unity-based feature extractor is designed that preserves the avatar’s movement signature while immune to the avatar’s appearance changes. Real-world experiments are conducted in VRChat, one of the most popular VR applications. The experimental results demonstrate that AvatarHunter can achieve attack success rates of 92.1% and 66.9% in closed-world and open-world avatar settings, respectively, which are much better than existing works. Yan Meng 0001, Yuxia Zhan, Jiachun Li 0001, Suguo Du, Haojin Zhu, Xuemin Shen |
INFOCOM | 5 |
| 2023 | RAI2: Responsible Identity Audit Governing the Artificial Intelligence
Tian Dong 0003, Shaofeng Li 0001, Guoxing Chen, Minhui Xue 0001, Haojin Zhu, Zhen Liu 0008 |
NDSS | 5 |
| 2023 | Mate! Are You Really Aware? An Explainability-Guided Testing Framework for Robustness of Malware DetectorsabstractNumerous open-source and commercial malware detectors are available. However, their efficacy is threatened by new adversarial attacks, whereby malware attempts to evade detection, e.g., by performing feature-space manipulation. In this work, we propose an explainability-guided and model-agnostic testing framework for robustness of malware detectors when confronted with adversarial attacks. The framework introduces the concept of Accrued Malicious Magnitude (AMM) to identify which malware features could be manipulated to maximize the likelihood of evading detection. We then use this framework to test several state-of-the-art malware detectors' ability to detect manipulated malware. We find that (i) commercial antivirus engines are vulnerable to AMM-guided test cases; (ii) the ability of a manipulated malware generated using one detector to evade detection by another detector (i.e., transferability) depends on the overlap of features with large AMM values between the different detectors; and (iii) AMM values effectively measure the fragility of features (i.e., capability of feature-space manipulation to flip the prediction results) and explain the robustness of malware detectors facing evasion attacks. Our findings shed light on the limitations of current malware detectors, as well as how they can be improved. Ruoxi Sun 0001, Minhui Xue 0001, Gareth Tyson, Tian Dong 0003, Shaofeng Li 0001, Shuo Wang 0012, Haojin Zhu, Seyit Ahmet Çamtepe, Surya Nepal |
ESEC/SIGSOFT FSE | 7 |
| 2023 | POLICYCOMP: Counterpart Comparison of Privacy Policies Uncovers Overbroad Personal Data Collection Practices
Chengyongxiao Wei, Guoxing Chen, Xiaokuan Zhang, Suguo Du, Haojin Zhu |
USENIX Security Symposium | 8 |
| 2022 | Fingerprinting Deep Neural Networks Globally via Universal Adversarial PerturbationsabstractIn this paper, we propose a novel and practical mechanism to enable the service provider to verify whether a suspect model is stolen from the victim model via model extraction attacks. Our key insight is that the profile of a DNN model's decision boundary can be uniquely characterized by its Universal Adversarial Perturbations (UAPs). UAPs belong to a low-dimensional subspace and piracy models' subspaces are more consistent with victim model's subspace compared with non-piracy model. Based on this, we propose a UAP fingerprinting method for DNN models and train an encoder via contrastive learning that takes fingerprints as inputs, outputs a similarity score. Extensive studies show that our framework can detect model Intellectual Property (IP) breaches with confidence > 99.99 % within only 20 fingerprints of the suspect model. It also has good generalizability across different model architectures and is robust against post-modifications on stolen models. Zirui Peng, Shaofeng Li 0001, Guoxing Chen, Cheng Zhang 0014, Haojin Zhu, Minhui Xue 0001 |
CVPR | 5 |
| 2022 | Secure Hierarchical Deterministic Wallet Supporting Stealth Address
Zhen Liu 0008, Guomin Yang, Guoxing Chen, Haojin Zhu |
ESORICS (1) | 5 |
| 2022 | Tradeoff between Privacy and Utility for Location-based Recommendation ServicesabstractLocation-based recommendation services (LBRS) are widely used by people to find new places of interest. However, the prevalence of LBRS poses a severe threat to users’ privacy, because LBRS queries contain sensitive information such as users’ preferences and location. Many Location Privacy Protection Mechanisms (LPPMs) have been proposed to mitigate the threat by obfuscating actual location in the query with a noise-based privacy-preserving technique. However, disguised location information can potentially harm the user experience with LBRS. In this work, we evaluate the impact of the noise-based privacy-preserving technique on user-perceived utility measured as nDCG (normalized Discounted Cumulative Gain) ranks. We empirically evaluate user-perceived utility under different noise levels to explore the trade-off between privacy and utility. A variety of factors, including service density and mechanism employed by service providers, are found to impact the utility loss, including but not limited to different service providers, different service types, and different sorts of areas (e.g., urban v.s. rural). Zhaoyu Gao, Ahmad Sepahi, Shahrooz Pouryousef, Haojin Zhu |
ICC | 5 |
| 2022 | Thwarting Longitudinal Location Exposure Attacks in Advertising Ecosystem via Edge ComputingabstractAs geo-location data has been increasingly adopted as a high-profile feature in targeted advertising, exposing user real locations to untrusted cloud services or advertisers has raised severe privacy concerns. To protect location privacy with formal guarantee, a wide-stretched line of recent studies focuses on injecting controlled geo-indistinguishability (geo-IND) noise as per each location exposure. However, in advertising, over the course of 2 years, a single user can report and contribute near 1k location data points on average, which allows a longitudinal attacker to infer some statistics from the perturbed locations.In this study, we demonstrate the above-mentioned privacy risk via revealing an inference attack mechanism, coined as a longitudinal location exposure attack. This novel attack illustrates the possibility of recovering 75%∼90% of user top-1 locations (within only 200-meter range) among 37k users. In light of this deficiency, we propose a novel edge-assisted location privacy protection system, entitled Edge-PrivLocAd, that is adapted to location-based advertising. The novelty of Edge-PrivLocAd stems from our n-fold Gaussian mechanism, which adds permanent noise to the statistical user location profile and thus can defend against longitudinal attackers while balancing the privacy-utility trade-off. In addition, our system incorporates a posterior-based sampling technique into the location re-mapping process, that boosts location utility without privacy loss. We develop a fully-functioning prototype and empirically evaluate the proposed system. Our experimental results show that Edge-PrivLocAd is practical and scalable in real-world scenarios. Le Yu 0002, Shufan Zhang 0001, Yan Meng 0001, Suguo Du, Haojin Zhu |
ICDCS | 6 |
| 2022 | Thwarting Unauthorized Voice Eavesdropping via Touch Sensing in Mobile SystemsabstractEnormous mobile applications (apps) now support voice functionality for convenient user-device interaction. However, these voice-enabled apps may spitefully invoke microphone to realize voice eavesdropping with arousing security risks and privacy concerns. To explore the issue of voice eavesdropping, in this work, we first design eavesdropping apps through native development and injection development to conduct eavesdropping attacks on a series of smart devices. The results demonstrate that eavesdropping could be carried out freely without any hint. To thwart voice eavesdropping, we propose a valid eavesdropping detection (EarDet) scheme based on the discovery that the activation of voice function in most apps requires authorization from the user by touching a specific voice icon. In the scheme, we construct a request-response time model using the Unix time stamps of touching the voice icon and microphone invoked. Through numerical analysis and hypothesis testing to effectively verify the pattern of the app’s normal access under user authorization to the microphone, we could detect eavesdropping attacks by sensing whether there is a touch operation. Finally, we apply the scheme to different smart devices and test several apps. The experimental results show that the proposed EarDet scheme can achieve a high detection accuracy. Wenbin Huang 0003, Wenjuan Tang, Kuan Zhang 0001, Haojin Zhu, Yaoxue Zhang |
INFOCOM | 4 |
| 2022 | Your Microphone Array Retains Your Identity: A Robust Voice Liveness Detection System for Smart Speakers
Yan Meng 0001, Jiachun Li 0001, Matthew Pillari, Arjun Deopujari, Liam Brennan, Hafsah Shamsie, Haojin Zhu, Yuan Tian 0001 |
USENIX Security Symposium | 7 |
| 2022 | WiCapose: Multi-modal fusion based transparent authentication in mobile environments
Zhuo Chang, Yan Meng 0001, Haojin Zhu, Lin Wang 0023 |
J. Inf. Secur. Appl. | 4 |
| 2022 | A Federated Learning Based Privacy-Preserving Smart Healthcare SystemabstractThe rapid development of the smart healthcare system makes the early-stage detection of dementia disease more user-friendly and affordable. However, the main concern is the potential serious privacy leakage of the system. In this article, we take Alzheimer's disease (AD) as an example and design a convenient and privacy-preserving system namedADDetectorwith the assistance of Internet of Things (IoT) devices and security mechanisms. Particularly, to achieve effective AD detection,ADDetectoronly collects user's audio by IoT devices widely deployed in the smart home environment and utilizes novel topic-based linguistic features to improve the detection accuracy. For the privacy breach existing in data, feature, and model levels,ADDetectorachieves privacy-preserving by employing a unique three-layer (i.e., user, client, cloud, etc.) architecture. Moreover,ADDetectorexploitsfederated learning (FL) based schemeto ensure the user owns the integrity of raw data and secure the confidentiality of the classification model and implementdifferential privacy (DP) mechanismto enhance the privacy level of the feature. Furthermore, to secure the model aggregation process between clients and cloud in FL-based scheme, a novelasynchronous privacy-preserving aggregation frameworkis designed. We evaluateADDetectoron 1010 AD detection trials from 99 health and AD users. The experimental results show thatADDetectorachieves high accuracy of 81.9% and low time overhead of 0.7 s when implementing all privacy-preserving mechanisms (i.e., FL, DP, and cryptography-based aggregation). Jiachun Li 0001, Yan Meng 0001, Lichuan Ma, Suguo Du, Haojin Zhu, Qingqi Pei, Xuemin Shen |
IEEE Trans. Ind. Informatics | 5 |
| 2022 | Wireless Training-Free Keystroke Inference Attack and DefenseabstractExisting research work has identified a new class of attacks that can eavesdrop on the keystrokes in a non-invasive way without infecting the target computer to install malware. The common idea is that pressing a key of a keyboard can cause a unique and subtle environmental change, which can be captured and analyzed by the eavesdropper to learn the keystrokes. For these attacks, however, a training phase must be accomplished to establish the relationship between an observed environmental change and the action of pressing a specific key. This significantly limits the impact and practicality of these attacks. In this paper, we discover that it is possible to design keystroke eavesdropping attacks without requiring the training phase. We create this attack based on the channel state information extracted from the wireless signal. To eavesdrop on keystrokes, we establish a mapping between typing each letter and its respective environmental change by exploiting the correlation among observed changes and known structures of dictionary words. To defend against this attack, we propose a reactive jamming mechanism that launches the jamming only during the typing period. Experimental results on software-defined radio platforms validate the impact of the attack and the performance of the defense. Edwin Yang, Song Fang 0001, Ian D. Markwood, Yao Liu 0007, Shangqing Zhao, Haojin Zhu |
IEEE/ACM Trans. Netw. | 7 |
| 2021 | POSTER: ReAvatar: Virtual Reality De-anonymization Attack Through Correlating Movement SignaturesabstractVirtual reality (VR) is on the precipice of entering mainstream entertainment with devices equipped with a multitude of sensing, tracking, and internet capabilities that can reshape the current infotainment industry such as online gaming or conferences with novel features. With VR techniques, the online gamer or conference attendances could choose to keep their identity anonymous by easily altering their appearances (i.e., avatars). However, in this study, we present ReAvatar, a novel de-anonymization attack that identifies users by their virtual avatar via a correlation in specific recorded movements. Using 3D pose estimation, we train a sophisticated machine learning model with user movement data recorded while performing a set of movements in real life and then again with their avatars. We then map correlations between these two sets of movement data using a bespoke agglomerative clustering algorithm and establish relationship between the user's virtual and real-life identity. ReAvatar achieves 89.60% accuracy in detecting a unique user among multiple avatars. The security and privacy implications of this paper will be foundational for users and researchers alike that explore the realm of virtual reality. Brandon Falk, Yan Meng 0001, Yuxia Zhan, Haojin Zhu |
CCS | 4 |
| 2021 | Hidden Backdoors in Human-Centric Language ModelsabstractNatural language processing (NLP) systems have been proven to be vulnerable to backdoor attacks, whereby hidden features (backdoors) are trained into a language model and may only be activated by specific inputs (called triggers), to trick the model into producing unexpected behaviors. In this paper, we create covert and natural triggers for textual backdoor attacks, hidden backdoors, where triggers can fool both modern language models and human inspection. We deploy our hidden backdoors through two state-of-the-art trigger embedding methods. The first approach via homograph replacement, embeds the trigger into deep neural networks through the visual spoofing of lookalike characters replacement. The second approach uses subtle differences between text generated by language models and real natural text to produce trigger sentences with correct grammar and high fluency. We demonstrate that the proposed hidden backdoors can be effective across three downstream security-critical NLP tasks, representative of modern human-centric NLP systems, including toxic comment detection, neural machine translation (NMT), and question answering (QA). Our two hidden backdoor attacks can achieve an Attack Success Rate (ASR) of at least 97% with an injection rate of only 3% in toxic comment detection, 95.1% ASR in NMT with less than 0.5% injected data, and finally 91.12% ASR against QA updated with only 27 poisoning data samples on a model previously trained with 92,024 samples (0.029%). We are able to demonstrate the adversary's high success rate of attacks, while maintaining functionality for regular users, with triggers inconspicuous by the human administrators. Shaofeng Li 0001, Tian Dong 0003, Benjamin Zi Hao Zhao, Minhui Xue 0001, Haojin Zhu |
CCS | 6 |
| 2021 | Understanding and Detecting Mobile Ad Fraud Through the Lens of Invalid TrafficabstractAlong with gaining popularity of Real-Time Bidding (RTB) based programmatic advertising, the click farm based invalid traffic, which leverages massive real smartphones to carry out large-scale ad fraud campaigns, is becoming one of the major threats against online advertisement. In this study, we take an initial step towards the detection and large-scale measurement of the click farm based invalid traffic. Our study begins with a measurement on the device's features using a real-world labeled dataset, which reveals a series of features distinguishing the fraudulent devices from the benign ones. Based on these features, we develop EvilHunter, a system for detecting fraudulent devices through ad bid request logs with a focus on clustering fraudulent devices. EvilHunter functions by 1) building a classifier to distinguish fraudulent and benign devices; 2) clustering devices based on app usage patterns; and 3) relabeling devices in clusters through majority voting. EvilHunter demonstrates 97% precision and 95% recall on a real-world labeled dataset. By investigating a super click farm, we reveal several cheating strategies that are commonly adopted by fraudulent clusters. We further reduce the overhead of EvilHunter and discuss how to deploy the optimized EvilHunter in a real-world system. We are in partnership with a leading ad verification company to integrate EvilHunter into their industrial platform. Suibin Sun, Le Yu 0002, Xiaokuan Zhang, Minhui Xue 0001, Ren Zhou, Haojin Zhu, Shuang Hao 0001, Xiaodong Lin 0001 |
CCS | 6 |
| 2021 | Dissecting Click Fraud Autonomy in the WildabstractAlthough the use of pay-per-click mechanisms stimulates the prosperity of the mobile advertisement network, fraudulent ad clicks result in huge financial losses for advertisers. Extensive studies identify click fraud according to click/traffic patterns based on dynamic analysis. However, in this study, we identify a novel click fraud, named humanoid attack, which can circumvent existing detection schemes by generating fraudulent clicks with similar patterns to normal clicks. We implement the first tool ClickScanner to detect humanoid attacks on Android apps based on static analysis and variational AutoEncoders (VAEs) with limited knowledge of fraudulent examples. We define novel features to characterize the patterns of humanoid attacks in the apps' bytecode level. ClickScanner builds a data dependency graph (DDG) based on static analysis to extract these key features and form a feature vector. We then propose a classification model only trained on benign datasets to overcome the limited knowledge of humanoid attacks. Yan Meng 0001, Haotian Hu, Xiaokuan Zhang, Minhui Xue 0001, Haojin Zhu |
CCS | 6 |
| 2021 | BatFL: Backdoor Detection on Federated Learning in e-HealthabstractFederated Learning (FL) has received significant interest both from the research field and industry perspective. One of the most promising cross-silo applications on FL is electronic health records mining which trains a model on siloed data. In this application, clients can be different hospitals or health centers that are located in geo-distributed data centers. A central orchestration server (superior health center) organizes the training, while never seeing patients’ raw data. In this paper, we demonstrate that any local hospital in such a collaborative training framework can introduce hidden backdoor functionality into the joint global model. The backdoored joint global model will produce an adversary-expected output when a predefined trigger is attached to its input but it will behave normally for clean inputs. This vulnerability is exacerbated by the distributed nature of FL, making detecting backdoor attacks on FL a challenging work. Based on the coalitional game and Shapley value, we propose an effective and real-time backdoor detection system on FL. Extensive experiments over two machine learning tasks show that our techniques achieve high accuracy and are robust against multi-attackers settings. Binhan Xi, Shaofeng Li 0001, Jiachun Li 0001, Haojin Zhu |
IWQoS | 6 |
| 2021 | Federated Data Cleaning: Collaborative and Privacy-Preserving Data Cleaning for Edge IntelligenceabstractAs an important driving factor of emerging Internet-of-Things (IoT) applications, machine learning algorithms are currently facing the challenge of how to “clean” data noise, that is introduced during the training process (e.g., asynchronous execution and lossy data compression and quantization). In an attempt to guarantee data quality, various data cleaning approaches have been proposed to filter out abnormal data entries based on the global data distribution. However, most existing data cleaning approaches are based on a centralized paradigm and thus cannot be applied to future edge-based IoT applications, where each edge node (EN) has only a limited view of the global data distribution. Moreover, the increasing demand for privacy preservation largely prevents ENs from combining their data for centralized cleaning. In this study, we propose a federated data cleaning protocol, coined as FedClean, for edge intelligence (EI) scenarios that is designed to achieve data cleaning without compromising data privacy. More specifically, different ENs first generate Boolean shares of their data and distribute them to two noncolluding servers. These two servers then run the FedClean protocol to privately and efficiently compute the attribute value frequency (AVF) scores of the collected data entries, which are then sorted in ascending order via a bitonic sorting network without revealing their values. As a result, data entries with lower AVF scores are considered as abnormal and filtered out. The security, efficiency, and effectiveness of the proposed approach are then demonstrated via concrete security analysis and comprehensive experiments. Lichuan Ma, Qingqi Pei, Haojin Zhu, Licheng Wang 0004, Yusheng Ji |
IEEE Internet Things J. | 4 |
| 2021 | Automatic Permission Optimization Framework for Privacy Enhancement of Mobile ApplicationsabstractMobile applications play a crucial role in the IoT system, which is experiencing unprecedented growth. However, users possessing little knowledge of permission configurations often accept app permission requests without reading them, which opens a backdoor for the potential adversaries to launch the future attacks. Proposing an automatic permission management scheme is an attractive solution to solve this issue, but since users have varying attitudes toward privacy, such a scheme would be neither straightforward nor user friendly. In this study, an automatic permission optimization framework, Permizer, is proposed to recommend different app permission configurations to users with different privacy preferences. Permizer estimates the permission risks and builds the permission-functionality mapping to each app, then regulates the relationship between permission and app functionality. Permizer is the first module to achieve a balance between privacy protection and app functionality under the personal privacy preference condition. Finally, we develop Permizer as a one-button service on the real-world Android OS with 58 apps. Case studies conducted on TikTok and Amazon Alexa also demonstrate its practicability and effectiveness. Yiting Qu, Suguo Du, Shaofeng Li 0001, Yan Meng 0001, Haojin Zhu |
IEEE Internet Things J. | 6 |
| 2021 | Collective Memory for Detecting Nonconcurrent Clones: A Localized Approach for Global Topology and Identity Tracing in IoT NetworksabstractClone attack is considered as a severely destructive threat in Internet of Things (IoT), because: 1) the attack may be easily launched due to the deficiency of hardware architecture and the limited resources against physical capture and compromise and 2) it may trigger a large variety of insider and outsider attacks. Different from traditional clone attack detection approaches that ground on a large amount of data traversing the network (e.g., locations and identities), this article tackles this problem by answering the following fundamental questions: do we really need so much raw information? whether there is an alternative for local event detection by a node far away from that event? when acquiring/tracing global knowledge of a system/network, do we really need a global collection effort? These questions are of much importance in a large variety of networks. Specifically, this article provides a collective memory design for global topology and identity tracing (GTI Tracing), via a localized computing paradigm within neighborhood. This localized paradigm computationally builds a connection of identity and topology from time and space domain to a new computation domain. Such a computation domain retains four properties: 1) transitivity; 2) global convergence; 3) determinacy; and 4) causality. With byte-size information at an arbitrary device, it can recover and keep tracing global topology and identity information, and thus providing deterministic detection of clones. Both theoretical analysis and experimental study have shown the advantages of the proposed design in both detection accuracy and privacy protection, at a cost of light communication, storage, and computation overhead at each device. Jing Xu 0007, Chi Zhang 0001, Shuo Zhang 0011, Zhonghu Xu, Chunlin Zhong, Haojin Zhu, Zheng Yang 0002, Yunhao Liu 0001 |
IEEE Internet Things J. | 7 |
| 2021 | Advances in privacy-preserving computing
Kaiping Xue, Zhe Liu 0001, Haojin Zhu, Miao Pan, David S. L. Wei |
Peer-to-Peer Netw. Appl. | 3 |
| 2021 | Grus: Toward Unified-memory-efficient High-performance Graph Processing on GPUabstractToday’s GPU graph processing frameworks face scalability and efficiency issues as the graph size exceeds GPU-dedicated memory limit. Although recent GPUs can over-subscribe memory with Unified Memory (UM), they incur significant overhead when handling graph-structured data. In addition, many popular processing frameworks suffer sub-optimal efficiency due to heavy atomic operations when tracking the active vertices. This article presents Grus, a novel system framework that allows GPU graph processing to stay competitive with the ever-growing graph complexity. Grus improves space efficiency through a UM trimming scheme tailored to the data access behaviors of graph workloads. It also uses a lightweight frontier structure to further reduce atomic operations. With easy-to-use interface that abstracts the above details, Grus shows up to 6.4× average speedup over the state-of-the-art in-memory GPU graph processing framework. It allows one to process large graphs of 5.5 billion edges in seconds with a single GPU. Pengyu Wang 0003, Jing Wang 0055, Chao Li 0009, Jianzong Wang, Haojin Zhu, Minyi Guo |
ACM Trans. Archit. Code Optim. | 5 |
| 2021 | Invisible Backdoor Attacks on Deep Neural Networks Via Steganography and RegularizationabstractDeep neural networks (DNNs) have been proven vulnerable to backdoor attacks, where hidden features (patterns) trained to a normal model, which is only activated by some specific input (called triggers), trick the model into producing unexpected behavior. In this article, we create covert and scattered triggers for backdoor attacks, invisible backdoors, where triggers can fool both DNN models and human inspection. We apply our invisible backdoors through two state-of-the-art methods of embedding triggers for backdoor attacks. The first approach on Badnets embeds the trigger into DNNs through steganography. The second approach of a trojan attack uses two types of additional regularization terms to generate the triggers with irregular shape and size. We use the Attack Success Rate and Functionality to measure the performance of our attacks. We introduce two novel definitions of invisibility for human perception; one is conceptualized by the Perceptual Adversarial Similarity Score (PASS) and the other is Learned Perceptual Image Patch Similarity (LPIPS). We show that the proposed invisible backdoors can be fairly effective across various DNN models as well as four datasets MNIST, CIFAR-10, CIFAR-100, and GTSRB, by measuring their attack success rates for the adversary, functionality for the normal users, and invisibility scores for the administrators. We finally argue that the proposed invisible backdoor attacks can effectively thwart the state-of-the-art trojan backdoor detection approaches. Shaofeng Li 0001, Minhui Xue 0001, Benjamin Zi Hao Zhao, Haojin Zhu, Xinpeng Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | Liveness Detection for Voice User Interface via Wireless Signals in IoT EnvironmentabstractVoice interface has been a dominant User Interface (UI) channel in the popular smart home environment. Although Voice Control System (VCS) brings users conveniences, it is extremely vulnerable to spoofing attacks (e.g., hidden/inaudible command attack) due to its broadcast nature. In this study, to thwart spoofing attacks, we propose WSVA, a device-free voice liveness detection system based on the prevalent wireless signals generated by IoT devices without requiring user to carry any additional sensor or device. The basic insight of WSVA to distinguish the authentic voice command from a spoofed one is checking the consistency between the voice signal and its corresponding mouth motions, which can be captured by wireless signals. To achieve this goal, WSVA builds a theoretical model to describe the correlations among the wireless signal changes, the mouth motions, and the syllables in the voice command. Then, WSVA selects appropriate features from both voice and wireless signals, and calculates the consistency between these two types of signals to determine whether the VCS is suffering from the spoofing attack. To demonstrate the feasibility of WSVA, we conduct a case study on Samsung SmartThings platform and include WSVA as a new application, which is expected to significantly enhance the security of the existing VCS. We evaluate WSVA with various voice commands in different scenarios. Experimental results demonstrate that WSVA achieves the overall 99 percent true accept rate with 1 percent false accept rate with a good scalability and low latency. Yan Meng 0001, Haojin Zhu, Jinlei Li, Jin Li 0002, Yao Liu 0007 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2020 | Securing App Behaviors in Smart Home: A Human-App Interaction PerspectiveabstractSmart home has become a mainstream lifestyle due to the maturity of the IoT platform and the popularity of smart devices. While offering great convenience and entertainment, smart home suffers from malicious attacks that inject improper commands and actions to home devices, which may breach the user's safety and privacy. Traditional solutions mainly focus on generating security policies relying on app analysis to constraint apps' behaviors. However, these policies lack flexibility to adapt to the highly dynamic smart home system. We need to consider not only the app behaviors but also the user behaviors for enforcing an appropriate security policy. In this study, we propose WiPolicy, a cross-layer security enforcement system for smart home by monitoring the behaviors of both apps and users. The key novelty of WiPolicy is incorporating user activity recognition via the physical-layer wireless signals into the definition and enforcement of security policies to constraint the app behavior. We implement WiPolicy on the Samsung SmartThings platform with 187 SmartApps, and 24 behavior policies are defined and enforced. The case study demonstrates the effectiveness of WiPolicy on thwarting app's misbehavior. Jinlei Li, Yan Meng 0001, Haojin Zhu |
ICPADS | 4 |
| 2020 | Voiceprint Mimicry Attack Towards Speaker Verification System in Smart HomeabstractThe advancement of voice controllable systems (VC-Ses) has dramatically affected our daily lifestyle and catalyzed the smart home's deployment. Currently, most VCSes exploit automatic speaker verification (ASV) to prevent various voice attacks (e.g., replay attack). In this study, we present VMask, a novel and practical voiceprint mimicry attack that could fool ASV in smart home and inject the malicious voice command disguised as a legitimate user. The key observation behind VMask is that the deep learning models utilized by ASV are vulnerable to the subtle perturbations in the voice input space. To generate these subtle perturbations, VMask leverages the idea of adversarial examples. Then by adding the subtle perturbations to the recordings from an arbitrary speaker, VMask can mislead the ASV into classifying the crafted speech samples, which mirror the former speaker for human, as the targeted victim. Moreover, psychoacoustic masking is employed to manipulate the adversarial perturbations under human perception threshold, thus making victim unaware of ongoing attacks. We validate the effectiveness of VMask by performing comprehensive experiments on both grey box (VGGVox) and black box (Microsoft Azure Speaker Verification) ASVs. Additionally, a real-world case study on Apple HomeKit proves the VMask's practicability on smart home platforms. Yan Meng 0001, Jiahao Yu 0001, Chong Xiang 0001, Brandon Falk, Haojin Zhu |
INFOCOM | 6 |
| 2020 | iOS, Your OS, Everybody's OS: Vetting and Analyzing Network Services of iOS Applications
Zhushou Tang, Minhui Xue 0001, Yuan Tian 0001, Sen Chen 0001, Muhammad Ikram 0001, Tielei Wang, Haojin Zhu |
USENIX Security Symposium | 8 |
| 2020 | MobiKey: Mobility-Based Secret Key Generation in Smart HomeabstractConsumer Internet-of-Things platforms, especially in smart home, have received widespread attention. A large number of end-to-end and edge-to-end wireless communication links are subject to significant security and privacy risks. Key generation using radio link side-channel information is a burgeoning technology to solve this problem. This article designs a symmetric key generation method without environmental constraints, namely, MobiKey. The basic idea is taking the human mobility in home or the swing of the antenna to generate symmetric keys based on channel reciprocity. We leverage the practical phase information as the channel feature to generate symmetric keys between two communicating parties. To overcome the effects of noise on both communication sides and get a better performance, MobiKey harnesses the adaptive quantization method to make the bit generation rate and bit matching rate higher. MobiKey also uses the adaptive inconsecutive samples to increase the confusion of the adversary. Moreover, we propose the D-Gray code to enhance the randomness of quantization. MobiKey is implemented on different commercial devices, and the results show that it has comparative advantages in key generation consistency, randomness, and security. In addition, the performance in preventing predictable channel attacks and eavesdropping attack is discussed. Lin Wang 0023, Haonan An 0002, Haojin Zhu |
IEEE Internet Things J. | 3 |
| 2020 | A novel routing verification approach based on blockchain for inter-domain routing in smart metropolitan area networks
Shuo Zhang 0011, Haojin Zhu, Peng-Jun Wan, Lixin Gao 0001, Yaoxue Zhang, Zhihong Tian 0001 |
J. Parallel Distributed Comput. | 3 |
| 2020 | Privacy Leakage via De-Anonymization and Aggregation in Heterogeneous Social NetworksabstractThough representing a promising approach for personalization, targeting, and recommendation, aggregation of user profiles from multiple social networks will inevitably incur a serious privacy leakage issue. In this paper, we propose a Novel Heterogeneous De-anonymization Scheme (NHDS) aiming at de-anonymizing heterogeneous social networks. NHDS first leverages the network graph structure to significantly reduce the size of candidate set, then exploits user profile information to identify the correct mapping users with a high confidence. Performance evaluation on real-world social network datasets shows that NHDS significantly outperforms the prior schemes. Finally, we perform an empirical study on privacy leakage arising from cross-network aggregation based on four real-world social network datasets. Our findings show that 39.9 percent more information is disclosed through de-anonymization and the de-anonymized ratio is 84 percent. The detailed privacy leakage of user demographics and interests is also examined, which demonstrates the practicality of the identified privacy leakage issue. Huaxin Li, Qingrong Chen, Haojin Zhu, Di Ma 0001, Hong Wen 0001, Xuemin Shen |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2020 | Revealing Your Mobile Password via WiFi Signals: Attacks and CountermeasuresabstractIn this study, we present WindTalker, a novel and practical keystroke inference framework that can be used to infer the sensitive keystrokes on a mobile device through WiFi-based side-channel information. WindTalker is motivated from an observation that keystrokes on mobile devices will lead to different hand coverage and the finger motions, which will introduce a unique interference to the multi-path signals and can be reflected by the channel state information (CSI). An attacker can exploit the strong correlation between the CSI fluctuation and the keystrokes to infer the user's password input. Compared with the previous keystroke inference approaches, WindTalker neither deploys external equipment physically close to the target device nor compromises the target device. Instead, it employs a more practical setting by deploying a free public WiFi hotspot and collects the CSI data from the target device as long as the device is connected to the hotspot. In addition, to improve inference accuracy and efficiency, it analyzes the WiFi traffic to selectively collect CSI only for the sensitive period where password entering occurs. WindTalker can be implemented without the requirement of visually seeing the target device, or installing any malware on the device. We tested Windtalker on several mobile phones and performed a detailed case study to evaluate the practicality of the password inference towards Alipay, the largest mobile payment platform in the world. Furthermore, we proposed a novel CSI obfuscation countermeasure to thwart the inference attack. The evaluation results show that the performance of WindTalker can be dramatically reduced by adopting the proposed countermeasures. Yan Meng 0001, Jinlei Li, Haojin Zhu, Xiaohui Liang 0002, Yao Liu 0007, Na Ruan |
IEEE Trans. Mob. Comput. | 3 |
| 2019 | An Ensemble Approach for Suspicious Traffic Detection from High Recall Network AlertsabstractWeb services from large-scale systems are prevalent all over the world. However, these systems are naturally vulnerable and incline to be intruded by adversaries for illegal benefits. To detect anomalous events, previous works focus on inspecting raw system logs by identifying the outliers in workflows or relying on machine learning methods. Though those works successfully identify the anomalies, their models use large training set and process whole system logs. To reduce the quantity of logs that need to be processed, high recall suspicious network alert systems can be applied to preprocess system logs. Only the logs that trigger alerts are retrieved for further usage. Due to the universally usage of network traffic alerts among Security Operations Center, anomalies detection problems could be transformed to classify truly suspicious network traffic alerts from false alerts. In this work, we propose an ensemble model to distinguish truly suspicious alerts from false alerts. Our model consists of two sub-models with different feature extraction strategies to ensure the diversity and generalization. We use decision tree based boosters and deep neural networks to build ensemble models for classification. Finally, we evaluate our approach on suspicious network alerts dataset provided by 2019 IEEE BigData Cup: Suspicious Network Event Recognition. Under the metric of AUC scores, our model achieves 0.9068 on the whole testing set. Jinlei Li, Yan Meng 0001, Haojin Zhu |
IEEE BigData | 4 |
| 2019 | No-jump-into-latency in China's internet!: toward last-mile hop count based IP geo-localizationabstractLast-mile geo-localization plays an essential role in many location-based services, such as fraud detection and targeted advertising. In this study, we point out that round trip time (RTT) latency shows an extremely weak correlation with physical distance estimation in China's Internet, since a path between a vantage point and a destination can often be circuitous and inflated by queuing and processing delays. To sidestep the latency measurement, we perform a three-tier hop count based IP geo-localization mapping for China's Internet, on the assumption that each provincial router only serves a limited area. The mapping approach begins at the first tier using a single vantage point to fetch large-scale traceroute paths from the server to landmarks and target IPs. At the second tier, we try to find the last common routers along the traceroute paths of targets and landmarks and aggregate their hop count distances. At the third tier, we estimate the physical distances from hop count distances and provincial router radii, and geo-localize the targets to the nearest landmarks. Through large-scale experiments, we show that our approach is both cost-efficient and reliable, and can achieve last-ten-kilometer IP geo-localization for approximately 65% of the total 48874 pingable target IP addresses with a single ping server, and our hop count based approach completely outperforms the RTT based method. Chong Xiang 0001, Xinyu Wang 0004, Qingrong Chen, Minhui Xue 0001, Zhaoyu Gao, Haojin Zhu, Cailian Chen, Qiuhua Fan |
IWQoS | 6 |
| 2019 | An Enhanced Verifiable Inter-domain Routing Protocol Based on Blockchain
Shuo Zhang 0011, Haojin Zhu, Peng-Jun Wan, Lixin Gao 0001, Yaoxue Zhang |
SecureComm (1) | 3 |
| 2019 | Measuring and Analyzing Search Engine Poisoning of Linguistic CollisionsabstractMisspelled keywords have become an appealing target in search poisoning, since they are less competitive to promote than the correct queries and account for a considerable amount of search traffic. Search engines have adopted several countermeasure strategies, e.g., Google applies automated corrections on queried keywords and returns search results of the corrected versions directly. However, a sophisticated class of attack, which we term as linguistic-collision misspelling, can evade auto-correction and poison search results. Cybercriminals target special queries where the misspelled terms are existent words, even in other languages (e.g., "idobe", a misspelling of the English word "adobe", is a legitimate word in the Nigerian language). In this paper, we perform the first large-scale analysis on linguistic-collision search poisoning attacks. In particular, we check 1.77 million misspelled search terms on Google and Baidu and analyze both English and Chinese languages, which are the top two languages used by Internet users. We leverage edit distance operations and linguistic properties to generate misspelling candidates. To more efficiently identify linguistic-collision search terms, we design a deep learning model that can improve collection rate by 2.84x compared to random sampling. Our results show that the abuse is prevalent: around 1.19% of linguistic-collision search terms on Google and Baidu have results on the first page directing to malicious websites. We also find that cybercriminals mainly target categories of gambling, drugs, and adult content. Mobile-device users disproportionately search for misspelled keywords, presumably due to small screen for input. Our work highlights this new class of search engine poisoning and provides insights to help mitigate the threat. Matthew Joslin, Neng Li, Shuang Hao 0001, Minhui Xue 0001, Haojin Zhu |
IEEE Symposium on Security and Privacy | 5 |
| 2019 | Automated and Personalized Privacy Policy Extraction Under GDPR Consideration
Huaxin Li, Suguo Du, Haojin Zhu |
WASA | 6 |
| 2019 | Who Leaks My Privacy: Towards Automatic and Association Detection with GDPR Compliance
Qiwei Jia, Huaxin Li, Ruoxu Yang, Suguo Du, Haojin Zhu |
WASA | 6 |
| 2019 | Securing android applications via edge assistant third-party library detection
Zhushou Tang, Minhui Xue 0001, Guozhu Meng, Chengguo Ying, Yugeng Liu, Jianan He, Haojin Zhu, Yang Liu 0003 |
Comput. Secur. | 7 |
| 2019 | Edge-Assisted Stream Scheduling Scheme for the Green-Communication-Based IoTabstractThe consumer Internet of Things (IoT), which exploits wireless personal area network (WPAN) technology, is undergoing rapid growth. Although the consumer IoT enables users to control many devices and offers conveniences and benefits for daily life, its long-term operation capabilities are subject to a bottleneck related to power management. To save energy and prolong the lifetime of an IoT system, the basic idea is to allow idle devices to go to sleep. Because excessively frequent switching between the awake and asleep phases will consume a significant amount of power, it is essential to properly schedule the order of multiple communication streams among multiple devices such that the total number of wake-up events is as small as possible. Based on the typical communication protocols deployed in IoT systems, this problem can be divided into two cases: 1) the inter-superframe case and the 2) intrasuperframe case. The former case has been well studied in existing works, whereas research on the latter case is currently immature. In this paper, we propose an efficient scheme for addressing the stream order scheduling (SOS) problem in the intrasuperframe case. Mobile edge computing technology is utilized in the proposed scheme to reduce the network load, and three heuristic algorithms are proposed to improve the scheme's performance. We report various tests conducted on 4800 random original IoT topologies and 19000 random Hamiltonian edge-dual topologies, and the experimental results demonstrate that our scheme achieves optimal solutions with a very high success probability. Licheng Wang 0004, Yan Meng 0001, Haojin Zhu, Minxing Tang, Kaoru Ota |
IEEE Internet Things J. | 3 |
| 2019 | Achieving Differentially Private Location Privacy in Edge-Assistant Connected VehiclesabstractConnected vehicles can provide safer and more satisfying services for drivers by using information sensing and sharing. However, current network architecture cannot support massive and real-time data transmissions due to the poor-quality wireless links. To provide real-time data processing and improve drivers' security, edge computing is regarded as a promising method to offer more efficient services by placing computing and storage resources at the network edge. In this paper, we will introduce the concept of edge-assistant connected vehicles and propose some promising applications to reduce the network traffic and provide real-time services with the help of massive edge nodes. Unlike in the traditional cloud-based connected vehicles, edge nodes are introduced to enable vehicles to obtain real-time and distributed processing services. Furthermore, considering the location privacy issue in the new architecture, we propose a novel differentially privacy-preserving location-based service usage framework deployed on the edge node, designed to provide an adjustable privacy protection solution to balance the utility and privacy. Finally, we conduct extensive experiments to verify the proposed framework. Le Yu 0002, Suguo Du, Haojin Zhu, Cailian Chen |
IEEE Internet Things J. | 4 |
| 2019 | Pri-RTB: Privacy-preserving real-time bidding for securing mobile advertisement in ubiquitous computing
Erdong Deng, Fei Guo 0003, Zhen Liu 0008, Haojin Zhu, Zhenfu Cao |
Inf. Sci. | 6 |
| 2019 | Smart contract for secure billing in ride-hailing service via blockchain
Erdong Deng, Haojin Zhu, Zhenfu Cao |
Peer-to-Peer Netw. Appl. | 3 |
| 2019 | Location Privacy in Usage-Based Automotive Insurance: Attacks and CountermeasuresabstractUsage-based insurance (UBI) is regarded as a promising way to provide accurate automotive insurance rates by analyzing the driving behaviors (e.g., speed, mileage, and harsh braking/accelerating) of drivers. The best practice that has been adopted by many insurance programs to protect users' location privacy is the use of driving speed rather than GPS data. However, in this paper, we challenge this approach by presenting a novel speed-based location trajectory inference framework. The basic strategy of the proposed inference framework is motivated by the following observations. In practice, many environmental factors, such as real-time traffic and traffic regulations, can influence the driving speed. These factors provide side-channel information about the driving route, which can be exploited to infer the vehicle's trace. We implement our discovered attack on a public data set in New Jersey. The experimental results show that the attacker has a nearly 60% probability of obtaining the real route if he chooses the top 10 candidate routes. To thwart the proposed attack, we design a privacy preserving scoring and data audition framework that enhances drivers' control on location privacy without affecting the utility of UBI. Our defense framework can also detect users' dishonest behavior (e.g., modification of speed data) via a probabilistic audition scheme. Extensive experimental results validate the effectiveness of the defense framework. Suguo Du, Haojin Zhu, Cailian Chen, Kaoru Ota, Mianxiong Dong |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2018 | No Training Hurdles: Fast Training-Agnostic Attacks to Infer Your TypingabstractTraditional methods to eavesdrop keystrokes leverage some malware installed in a target computer to record the keystrokes for an adversary. Existing research work has identified a new class of attacks that can eavesdrop the keystrokes in a non-invasive way without infecting the target computer to install a malware. The common idea is that pressing a key of a keyboard can cause a unique and subtle environmental change, which can be captured and analyzed by the eavesdropper to learn the keystrokes. For these attacks, however, a training phase must be accomplished to establish the relationship between an observed environmental change and the action of pressing a specific key. This significantly limits the impact and practicality of these attacks. In this paper, we discover that it is possible to design keystroke eavesdropping attacks without requiring the training phase. We create this attack based on the channel state information extracted from wireless signal. To eavesdrop keystrokes, we establish a mapping between typing each letter and its respective environmental change by exploiting the correlation among observed changes and known structures of dictionary words. We implement this attack on software-defined radio platforms and conduct a suite of experiments to validate the impact of this attack. We point out that this paper does not propose to use wireless signal for inferring keystrokes, since such work already exists. Instead, the main goal of this paper is to propose new techniques to remove the training process, which can make existing work unpractical. Song Fang 0001, Ian D. Markwood, Yao Liu 0007, Shangqing Zhao, Haojin Zhu |
CCS | 6 |
| 2018 | HoMonit: Monitoring Smart Home Apps from Encrypted TrafficabstractSmart home is an emerging technology for intelligently connecting a large variety of smart sensors and devices to facilitate automation of home appliances, lighting, heating and cooling systems, and security and safety systems. Our research revolves around Samsung SmartThings, a smart home platform with the largest number of apps among currently available smart home platforms. The previous research has revealed several security flaws in the design of SmartThings, which allow malicious smart home apps (or SmartApps) to possess more privileges than they were designed and to eavesdrop or spoof events in the SmartThings platform. To address these problems, this paper leverages side-channel inference capabilities to design and develop a system, dubbed HoMonit, to monitor SmartApps from encrypted wireless traffic. To detect anomaly, HoMonit compares the SmartApps activities inferred from the encrypted traffic with their expected behaviors dictated in their source code or UI interfaces. To evaluate the effectiveness of HoMonit, we analyzed 181 official SmartApps and performed evaluation on 60 malicious SmartApps, which either performed over-privileged accesses to smart devices or conducted event-spoofing attacks. The evaluation results suggest that HoMonit can effectively validate the working logic of SmartApps and achieve a high accuracy in the detection of SmartApp misbehaviors. Wei Zhang 0001, Yan Meng 0001, Yugeng Liu, Xiaokuan Zhang, Yinqian Zhang, Haojin Zhu |
CCS | 6 |
| 2018 | Detecting Vehicle Anomaly by Sensor Consistency: An Edge Computing Based MechanismabstractAutonomous vehicles are expected to be a disruptive technology that has the potential to revolutionize the human mobility. However, the recent research progress on intra-vehicle network (e.g., the revealing of a series of security vulnerabilities of CAN design) has demonstrated that the security issue still represents one of the major challenges of future self-driving cars. In this study, we propose a novel edge based anomaly detection system, coined VeAnDe, which exploits edge based sensor data fusion to identify the anomaly events. VeAnDe analyzes pair-wise correlations between different intra-vehicle sensors, and utilizes these correlations to examine whether an anomaly has occurred within the vehicle. More specifically, the pair-wise correlations are organized as ring architecture to reduce the computation overhead. Furthermore, the major components of VeAnDe are embedded in edge computing devices, which enables VeAnDe to be more efficient and privacy-preserving. We evaluate the performance of VeAnDe under different scenarios, and our experimental results demonstrate its feasibility and efficiency. Zichang Wang, Fei Guo 0003, Yan Meng 0001, Huaxin Li, Haojin Zhu, Zhenfu Cao |
GLOBECOM | 5 |
| 2018 | APPCLASSIFIER: Automated App Inference on Encrypted Traffic via Meta Data AnalysisabstractAs smart phones gradually become the dominant network traffic generators, app traffic analysis methods have gained great interests for network management and targeted advertisement. Specifically, previous works have shown that the scalability of app inference via traffic meta-data has the edge over traditional payload based analysis. However, such works mainly considered the ideal inference scenario where only one app is running on the client's device, without any background traffic noise interfered. In this paper, we extend the research to a more practical scenario, by assuming that multiple apps simultaneously run on a smart phone in the noisy background with complex traffic generated by the operating system. To that end, we propose APPCLASSIFIER, an Android app fingerprinting scheme for real-time app inference. We first leverage the observed differences in packet size distributions and traffic sequential behaviors to boost inference accuracy for noise-free traffic analysis. We then propose novel heuristic based methods to re-correct mislabeled traffic flows to realize real-time traffic inference. As a result, APPCLASSIFIER achieves inference accuracy of 82.3% for noise-free traffic analysis and reduces error rate from 66.7% to 36.4% for real-time traffic inference. Chong Xiang 0001, Qingrong Chen, Minhui Xue 0001, Haojin Zhu |
GLOBECOM | 4 |
| 2018 | WiVo: Enhancing the Security of Voice Control System via Wireless Signal in IoT EnvironmentabstractWith the prevalent of smart devices and home automations, voice command has become a popular User Interface (UI) channel in the IoT environment. Although Voice Control System (VCS) has the advantages of great convenience, it is extremely vulnerable to the spoofing attack (e.g., replay attack, hidden/inaudible command attack) due to its broadcast nature. In this study, we present WiVo, a device-free voice liveness detection system based on the prevalent wireless signals generated by IoT devices without any additional devices or sensors carried by the users. The basic motivation of WiVo is to distinguish the authentic voice command from a spoofed one via its corresponding mouth motions, which can be captured and recognized by wireless signals. To achieve this goal, WiVo builds a theoretical model to characterize the correlation between wireless signal dynamics and the user's voice syllables. WiVo extracts the unique features from both voice and wireless signals, and then calculates the consistency between these different types of signals in order to determine whether the voice command is generated by the authentic user of VCS or an adversary. To evaluate the effectiveness of WiVo, we build a testbed based on Samsung SmartThings framework and include WiVo as a new application, which is expected to significantly enhance the security of the existing VCS. We have evaluated WiVo with 6 participants and different voice commands. Experimental evaluation results demonstrate that WiVo achieves the overall 99% detection rate with 1% false accept rate and has a low latency. Yan Meng 0001, Zichang Wang, Wei Zhang 0001, Haojin Zhu, Xiaohui Liang 0002, Yao Liu 0007 |
MobiHoc | 5 |
| 2018 | Smoke Screener or Straight Shooter: Detecting Elite Sybil Attacks in User-Review Social Networks
Haizhong Zheng, Minhui Xue 0001, Shuang Hao 0001, Haojin Zhu, Xiaohui Liang 0002, Keith W. Ross |
NDSS | 5 |
| 2018 | Automated poisoning attacks and defenses in malware detection systems: An adversarial machine learning approachabstractThe evolution of mobile malware poses a serious threat to smartphone security. Today, sophisticated attackers can adapt by maximally sabotaging machine-learning classifiers via polluting training data , rendering most recent machine learning-based malware detection tools (such as D rebin , D roid APIM iner , and M a M a D roid ) ineffective. In this paper, we explore the feasibility of constructing crafted malware samples ; examine how machine-learning classifiers can be misled under three different threat models; then conclude that injecting carefully crafted data into training data can significantly reduce detection accuracy. To tackle the problem, we propose K uafu D et , a two-phase learning enhancing approach that learns mobile malware by adversarial detection. K uafu D et includes an offline training phase that selects and extracts features from the training set, and an online detection phase that utilizes the classifier trained by the first phase. To further address the adversarial environment, these two phases are intertwined through a self-adaptive learning scheme, wherein an automated camouflage detector is introduced to filter the suspicious false negatives and feed them back into the training phase. We finally show that K uafu D et can significantly reduce false negatives and boost the detection accuracy by at least 15%. Experiments on more than 250,000 mobile applications demonstrate that K uafu D et is scalable and can be highly effective as a standalone system. Sen Chen 0001, Minhui Xue 0001, Lingling Fan 0003, Shuang Hao 0001, Lihua Xu, Haojin Zhu, Bo Li 0026 |
Comput. Secur. | 6 |
| 2018 | Privacy Leakage of Location Sharing in Mobile Social Networks: Attacks and DefenseabstractAlong with the popularity of mobile social networks (MSNs) is the increasing danger of privacy breaches due to user location exposures. In this work, we take an initial step towards quantifying location privacy leakage from MSNs by matching the users’ shared locations with their real mobility traces. We conduct a three-week real-world experiment with 30 participants and discover that both direct location sharing (e.g., Weibo or Renren) and indirect location sharing (e.g., Wechat or Skout) can reveal a small percentage of users’ real points of interests (POIs). We further propose a novel attack to allow an external adversary to infer the demographics (e.g., age, gender, education) after observing users’ exposed location profiles. We implement such an attack in a large real-world dataset involving 22,843 mobile users. The experimental results show that the attacker can effectively predict demographic attributes about users with some shared locations. To resist such attacks, we propose SmartMask, a context-based system-level privacy protection solution, designed to automatically learn users’ privacy preferences under different contexts and provide a transparent privacy control for MSN users. The effectiveness and efficiency of SmartMask have been well validated by extensive experiments. Huaxin Li, Haojin Zhu, Suguo Du, Xiaohui Liang 0002, Xuemin Shen |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2018 | Secret Key Establishment via RSS Trajectory Matching Between Wearable DevicesabstractRecently, people have witnessed a remarkable growth in the number of smart wearable devices. Accompanied with the development of a contactless data transmission technique, the lack of effective secret key establishment between lightweight wearable devices which support contactless data transmission technique becomes a security bottleneck. In this paper, we propose a novel wireless key establishment method by moving or shaking the wearable wireless devices. Instead of received signal strength (RSS) itself, we denote the RSS trajectories of two moving wireless devices as the materials of secret key. Moreover, inspired by channel reciprocity in a channel feature-based key establishment technique, we propose the concept of reciprocity of RSS trajectory that guarantees that even when the RSSs of two devices are the same, the identical RSS trajectories of two devices can successfully generate the secret key. In addition, to effectively utilize the RSS trajectories, we design a novel quantization scheme by considering the entropy and efficiency of key generation. Furthermore, we analyze the security of this key establishment procedure in an eavesdropped and monitored environment. We also perform an evaluation of 64-, 128-, 192-, and 256-b key generation in indoor/outdoor environment, and the results indicate that the times are 0.22/0.33, 0.61/0.74, 0.95/1.02, and 1.28/1.46 s, respectively. In addition, the ranges of efficiency and entropy are 0.654-0.795 and 0.968-0.993. Qingqi Pei, Ian D. Markwood, Yao Liu 0007, Haojin Zhu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2018 | Corrections to "Secret Key Establishment via RSS Trajectory Matching Between Wearable Devices" [Mar 18 802-817]abstractIn the above paper, the following acknowledgment of financial support was not included, due to a publication error. Qingqi Pei, Ian D. Markwood, Yao Liu 0007, Haojin Zhu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2018 | Demographic Information Inference through Meta-Data Analysis of Wi-Fi TrafficabstractPrivacy inference through meta-data (e.g., IP, Host) analysis of Wi-Fi traffic poses a potentially more serious threat to user privacy. First, it provides a more efficient and scalable approach to infer users' sensitive information without checking the content of Wi-Fi traffic. Second, meta-data based demographics inference can work on both unencrypted and encrypted traffic (e.g., HTTPS traffic). In this study, we present a novel approach to infer user demographic information by exploiting the meta-data of Wi-Fi traffic. We develop an inference framework based on machine learning and evaluate its performance on a real-world dataset, which includes the Wi-Fi access of 28,158 users in five months. The framework extracts four kinds of features from real-world Wi-Fi traffic and applies a novel machine learning technique (XGBoost) to predict user demographics. Our analytical results show that, the overall accuracy of inferring gender and education level of users can be 82 and 78 percent, respectively. It is surprising to show that, even for HTTPS traffic, user demographics can still be predicted at accuracy of 69 and 76 percent, respectively, which well demonstrates the practicality of the proposed privacy inference scheme. Finally, we discuss and evaluate potential mitigation methods for such inference attacks. Huaxin Li, Haojin Zhu, Di Ma 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2017 | Speed-Based Location Tracking in Usage-Based Automotive InsuranceabstractUsage-based Insurance (UBI) is regarded as a promising way to offer more accurate insurance premium by profiling driving behaviors. Compared with traditional insurance which considers drivers' history of accidents, traffic violations and etc, UBI focuses on driving data and can give a more reasonable insurance premium based on the current driving behaviors. Insurers use sensors in smartphone or vehicle to collect driving data (e.g. mileage, speed, hark braking) and compute a risk score based on these data to recalculate insurance premium. Many insurance programs, which are advertised as being privacy-preserving, do not directly use the GPS-based tracking, but it is not enough to protect driver's location privacy. In real world, many environment factors such as real-time traffic and traffic regulations can influence driving speed. These factors provide the side-channel information about the driving route, which can be exploited to infer the vehicle's trace. Based on the observation, we propose a novel speed based trajectory inference algorithm which can track drivers only with the speed data and original location. We implement the attack on a public dataset in New Jersey. The evaluation results show that the attacker can recover the route with a high successful rate. Qingrong Chen, Zutian Luo, Haojin Zhu, Cailian Chen |
ICDCS | 4 |
| 2017 | Privacy-Preserving Fraud Detection via Cooperative Mobile Carriers with Improved AccuracyabstractWith the explosive growth of users in mobile carrier, telecommunication fraud causes a serious loss to both of the users and carriers. The academia has an increasing interest in the issue of detecting and recognizing fraudster, and varies strategies have been proposed to prevent the attack and fraudulent activity. However, fraudsters are always inclined to hide their identity and perform the fraudulent activity through different mobile carriers, which makes the previous methods less effective in fraud detection. In this paper, we propose a novel strategy with a high accuracy and security through the cooperation among mobile carriers. We introduce the Latent Dirichlet Allocation (LDA) model to profile users in different carriers. In order to match the fraud accounts, we propose a strategy based on Maximum Mean Discrepancy (MMD) to analyze and compare the distribution of statistical samples. Meantime, during the cooperation of carriers, there is a risk of privacy disclosure. To deal with this weakness, we also demonstrate that our method can detect the fraudulent accounts without leaking the private records and data of user accounts based on the differential privacy. Wenyan Yao, Na Ruan, Feifan Yu, Weijia Jia 0001, Haojin Zhu |
SECON | 5 |
| 2017 | Security Modeling and Analysis on Intra Vehicular NetworkabstractController Area Network (CAN), the de facto standard in-vehicle network protocol, prompts modern automobile an integrated system that achieves real-time interactions with roads, vehicles and people. Yet such connectivity makes it feasible to illegally access, or even attack the CAN, causing not only privacy disclosure, property damage, but also life threat. In this paper, we analyze intrinsic weakness in CAN protocol that is mostly exploited by attackers and comprehensively survey the existing attacks based on CAN interfaces. Furthermore, we propose an attack evaluation system based on attack tree model and Markov chain to assess the probability of compromising CAN and the steady state of CAN system at the presence of these attacks. Finally, we simulate new steady state when altering the difficulty of a certain attack and the results demonstrate that sometimes improving defense of an attack declines the security level of the entire system instead. Jinli Zhong, Suguo Du, Haojin Zhu, Cailian Chen, Qingshui Xue |
VTC Fall | 4 |
| 2017 | Detect SIP Flooding Attacks in VoLTE by Utilizing and Compressing Counting Bloom Filter
Na Ruan, Shiheng Ma, Haojin Zhu, Weijia Jia 0001, Qingshui Xue |
WASA | 4 |
| 2017 | SPFM: Scalable and Privacy-Preserving Friend Matching in Mobile CloudabstractProfile (e.g., contact list, interest, and mobility) matching is more than important for fostering the wide use of mobile social networks. The social networks such as Facebook, Line, or WeChat recommend the friends for the users based on users personal data such as common contact list or mobility traces. However, outsourcing users' personal information to the cloud for friend matching will raise a serious privacy concern due to the potential risk of data abusing. In this paper, we propose a novel scalable and privacy-preserving friend matching (SPFM) protocol, which aims to provide a scalable friend matching and recommendation solutions without revealing the users personal data to the cloud. Different from the previous works which involves multiple rounds of protocols, SPFM presents a scalable solution which can prevent honest-but-curious mobile cloud from obtaining the original data and support the friend matching of multiple users simultaneously. We give detailed feasibility and security analysis on SPFM and its accuracy and security have been well demonstrated via extensive simulations. The result show that our scheme works even better when original data is large. Mengyuan Li 0004, Na Ruan, Qiyang Qian, Haojin Zhu, Xiaohui Liang 0002, Le Yu 0002 |
IEEE Internet Things J. | 4 |
| 2017 | Guest editorial: Special issue on algorithms, systems and applications in mobile social networks
Haojin Zhu, Kuai Xu, Xiang Lu 0004 |
Peer-to-Peer Netw. Appl. | 1 |
| 2017 | NFC Secure Payment and Verification Scheme with CS E-TicketabstractAs one of the most important techniques in IoT, NFC (Near Field Communication) is more interesting than ever. NFC is a short-range, high-frequency communication technology well suited for electronic tickets, micropayment, and access control function, which is widely used in the financial industry, traffic transport, road ban control, and other fields. However, NFC is becoming increasingly popular in the relevant field, but its secure problems, such as man-in-the-middle-attack and brute force attack, have hindered its further development. To address the security problems and specific application scenarios, we propose a NFC mobile electronic ticket secure payment and verification scheme in the paper. The proposed scheme uses a CS E-Ticket and offline session key generation and distribution technology to prevent major attacks and increase the security of NFC. As a result, the proposed scheme can not only be a good alternative to mobile e-ticket system but also be used in many NFC fields. Furthermore, compared with other existing schemes, the proposed scheme provides a higher security. Kai Fan 0001, Panfei Song, Zhao Du, Haojin Zhu, Hui Li 0006, Yintang Yang, Xinghua Li 0001, Chao Yang 0016 |
Secur. Commun. Networks | 4 |
| 2017 | Virtual Multipath Attack and Defense for Location Distinction in Wireless NetworksabstractIn wireless networks, location distinction aims to detect location changes or facilitate authentication of wireless users. To achieve location distinction, recent research has focused on investigating the spatial uncorrelation property of wireless channels. Specifically, differences in wireless channel characteristics are used to distinguish locations or identify location changes. However, we discover a new attack against all existing location distinction approaches that are built on the spatial uncorrelation property of wireless channels. In such an attack, the adversary can easily hide her location changes or impersonate movements by injecting fake wireless channel characteristics into a target receiver. To defend against this attack, we propose a detection technique that utilizes an auxiliary receiver or antenna to identify these fake channel characteristics. We also discuss such attacks and corresponding defenses in OFDM systems. Experimental results on our USRP-based prototype show that the discovered attack can craft any desired channel characteristic with a successful probability of 95.0 percent to defeat spatial uncorrelation based location distinction schemes and our novel detection method achieves a detection rate higher than 91.2 percent while maintaining a very low false alarm rate. Song Fang 0001, Yao Liu 0007, Wenbo Shen, Haojin Zhu, Tao Wang 0026 |
IEEE Trans. Mob. Comput. | 4 |
| 2016 | StormDroid: A Streaminglized Machine Learning-Based System for Detecting Android MalwareabstractMobile devices are especially vulnerable nowadays to malware attacks, thanks to the current trend of increased app downloads. Despite the significant security and privacy concerns it received, effective malware detection (MD) remains a significant challenge. This paper tackles this challenge by introducing a streaminglized machine learning-based MD framework, StormDroid: (i) The core of StormDroid is based on machine learning, enhanced with a novel combination of contributed features that we observed over a fairly large collection of data set; and (ii) we streaminglize the whole MD process to support large-scale analysis, yielding an efficient and scalable MD technique that observes app behaviors statically and dynamically. Evaluated on roughly 8,000 applications, our combination of contributed features improves MD accuracy by almost 10% compared with state-of-the-art antivirus systems; in parallel our streaminglized process, StormDroid, further improves efficiency rate by approximately three times than a single thread. Sen Chen 0001, Minhui Xue 0001, Zhushou Tang, Lihua Xu, Haojin Zhu |
AsiaCCS | 5 |
| 2016 | POSTER: Accuracy vs. Time Cost: Detecting Android Malware through Pareto Ensemble PruningabstractThis paper proposes Begonia, a malware detection system through Pareto ensemble pruning. We convert the malware detection problem into the bi-objective Pareto optimization, aiming to trade off the classification accuracy and the size of classifiers as two objectives. We automatically generate several groups of base classifiers using SVM and generate solutions through bi-objective Pareto optimization. We then select the ensembles with highest accuracy of each group to form the final solutions, among which we hit the optimal solution where the combined loss function is minimal considering the trade-off between accuracy and time cost. We expect users to provide different trade-off levels to their different requirements to select the best solution. Experimental results show that Begonia can achieve higher accuracy with relatively lower overhead compared to the ensemble containing all the classifiers and can make a good trade-off to different requirements. Lingling Fan 0003, Minhui Xue 0001, Sen Chen 0001, Lihua Xu, Haojin Zhu |
CCS | 5 |
| 2016 | When CSI Meets Public WiFi: Inferring Your Mobile Phone Password via WiFi SignalsabstractIn this study, we present WindTalker, a novel and practical keystroke inference framework that allows an attacker to infer the sensitive keystrokes on a mobile device through WiFi-based side-channel information. WindTalker is motivated from the observation that keystrokes on mobile devices will lead to different hand coverage and the finger motions, which will introduce a unique interference to the multi-path signals and can be reflected by the channel state information (CSI). The adversary can exploit the strong correlation between the CSI fluctuation and the keystrokes to infer the user's number input. WindTalker presents a novel approach to collect the target's CSI data by deploying a public WiFi hotspot. Compared with the previous keystroke inference approach, WindTalker neither deploys external devices close to the target device nor compromises the target device. Instead, it utilizes the public WiFi to collect user's CSI data, which is easy-to-deploy and difficult-to-detect. In addition, it jointly analyzes the traffic and the CSI to launch the keystroke inference only for the sensitive period where password entering occurs. WindTalker can be launched without the requirement of visually seeing the smart phone user's input process, backside motion, or installing any malware on the tablet. We implemented Windtalker on several mobile phones and performed a detailed case study to evaluate the practicality of the password inference towards Alipay, the largest mobile payment platform in the world. The evaluation results show that the attacker can recover the key with a high successful rate. Mengyuan Li 0004, Yan Meng 0001, Haojin Zhu, Xiaohui Liang 0002, Yao Liu 0007, Na Ruan |
CCS | 4 |
| 2016 | Who Moved My Cheese: Towards Automatic and Fine-Grained Classification and Modeling Ad NetworkabstractThe mobile advertisement (ad) network is gaining an increasing interest due to the high popularity of smart phones. Previous researches on the security issues of ad network primarily focus on the privacy, permission and malware detection while less attention has been paid to the traffic consumption issue incurred by ad network. Though it is well known that ad network plays an important role in network consumption, it represents a great challenge of giving a fine-grained classification of ad networks. Inspired by this, different from any previous researches, in this study, we take the initial step towards modeling the network consumption of Ad network in Android. We develop an automatic ad analysis platform to quantify the ad network traffic consumed by android applications (app). To achieve a fine-grained quantification, we combine two sources of network traffic. On one hand, we modify the android webview and log system in system level to capture network traffic accurately. On the other hand, we capture network traffic in router level to collect detailed information of traffic packets, such as packet size and URI. We have evaluated the developed system in terms of normal apps, repacked apps and malicious apps based on the real-world dataset, which is comprised of 93 Android apps. We find out that ad traffic takes major percentage of the whole network traffic caused by Android app. We have also studied the ad library mechanism for 10 popular ad libraries. We found ads from some ad libraries use much more network traffic because they have to be fetched from remote ad libraries each time they are shown to users while other ad libraries allow apps to store ads locally. Jiafa Liu, Huaxin Li, Haojin Zhu, Na Ruan, Di Ma 0001 |
GLOBECOM | 4 |
| 2016 | A Traffic Based Lightweight Attack Detection Scheme for VoLTEabstractWith rapid growth of LTE network and Voice-over-LTE(VoLTE), detecting and preventing security threats like Denial of Service attack becomes a necessary and urgent requirement. VoLTE is an voice solution based on Internet Protocol and 4G LTE technology, at the same time exposing many vulnerabilities when using packet-switched network. There are many heavy weighted detection systems using content analysis, while high demands of computing resource constraint their practical use. In this paper, we purpose a lightweight detection scheme for VoLTE network security, based on analysis of data traffic flow. To optimize parameters in our scheme, we formulate a Bayesian game model. Bayesian game has the features of incomplete information and asymmetry, similar to practical attack-defense model. Besides, The dynamic Bayesian game is more realistic, since both sides can update believes about their opponents. Simulation results provide some guidances on parameter selection, as well as verifying the superiority of our scheme. Na Ruan, Haojin Zhu, Qingshui Xue, Weijia Jia 0001, Jingyu Cui |
GLOBECOM | 4 |
| 2016 | Efficient and secure message authentication in cooperative driving: A game-theoretic approachabstractRequirement of safety, roadway capacity and efficiency in vehicular network, which makes autonomous driving concept continue to be of interest. To achieve automated cooperative driving, vehicles form a platoon. For the authentication in vehicular platoons, efficiency and security are the two things of great significance. Cooperative authentication is a way to help recognize false identities and messages as well as saving resources. However, selfish behaviors of the vehicles may be caused by the concern of privacy leakage and unfair resources consuming. To deal with these weaknesses, we devised an enhanced cooperative authentication protocol based on mechanisms which discourages non-cooperating behavior. An infinitely repeated game for our designed protocol in is proposed to analyze the utility of all users to help analyse the threat of selfish behavior. We also proposed a method to optimize the system parameters in our designed protocol to achieve better efficiency and security. Na Ruan, Haojin Zhu |
ICC | 3 |
| 2016 | Toward Optimal DoS-Resistant Authentication in Crowdsensing Networks via Evolutionary GameabstractWith the increasing demand of Quality of Service(QoS) in Crowdsensing Networks, providing broadcast authentication and preventing Denial of Service (DoS) attacks become not only a fundamental issue but also a challenging security service. The multi-level TESLA is a series of lightweight broadcast authentication protocols, which can effectively mitigate DoS attacks via randomly selected messages. However, the rule of the parameter selection still remains a problem. In this paper, we formulate the attack-defense model as an evolutionary game accordingly, and then present an optimal solution, which achieves security assurance along with minimum resource cost. We then analyze the stability of our evolutionary strategy theoretically. Simulation results are given to evaluate the performance of the proposed algorithm under low QoS channels and severe DoS attacks, which demonstrates that our proposed protocol canworks even in the extreme case. Na Ruan, Haojin Zhu, Weijia Jia 0001 |
ICDCS | 3 |
| 2016 | Demographics inference through Wi-Fi network traffic analysisabstractAlthough privacy leaking through content analysis of Wi-Fi traffic has received an increased attention, privacy inference through meta-data (e.g. IP, Host) analysis of Wi-Fi traffic represents a potentially more serious threat to user privacy. Firstly, it represents a more efficient and scalable approach to infer users' sensitive information without checking the content of Wi-Fi traffic. Secondly, meta-data based demographics inference can work on both unencrypted and encrypted traffic (e.g., HTTPS traffic). In this study, we present a novel approach to infer user demographic information by exploiting the meta-data of Wi-Fi traffic. We develop a proof-of-concept prototype, Demographic Information Predictor (DIP) system, and evaluate its performance on a real-world dataset, which includes the Wi-Fi access of 28,158 users in 5 months. DIP extracts four kinds of features from real-world Wi-Fi traffic and proposes a novel machine learning based inference technique to predict user demographics. Our analytical results show that, for unencrypted traffic, DIP can predict gender and education level of users with an accuracy of 78% and 74% respectively. It is surprising to show that, even for HTTPS traffic, user demographics can still be predicted at a precision of 67% and 72% respectively, which well demonstrates the practicality of the proposed privacy inference scheme. Huaxin Li, Zheyu Xu, Haojin Zhu, Di Ma 0001 |
INFOCOM | 3 |
| 2016 | Automatic Detection of SIP-Aware Attacks on VoLTE DeviceabstractDue to the worldwide deployment of Long Term Evolution (LTE), the fourth-generation (4G) mobile cellular networking technology, Voice over LTE (VoLTE) [2] has been also well developed in past few years. It exploits packet-switched network to provide call services instead of the traditional circuit- switched telephony. Similar to the Voice over IP (VoIP), VoLTE adopts Session Initiation Protocol (SIP) to achieve some control functions. Therefore, it means attack techniques against the SIP will also be effective against VoLTE devices. In this paper, we propose a novel device-side SIP-aware detecting system against two kinds of SIP attacks, SIP message flooding attack and malformed SIP message attack. To detect the message flooding attack, we set threshold for the traffic of SIP message received from VoLTE interface within one minute. And for the malformed message attack, we provide the structure and formalization rules of SIP messages to detect malformed SIP messages by utilizing ontology descriptions. This paper presents the design and implementation of this detecting system. The simulation test shows that this system will improve the security level of VoLTE service in real applications. Zhushou Tang, Na Ruan, Haojin Zhu |
VTC Fall | 6 |
| 2016 | NFC Secure Payment and Verification Scheme for Mobile Payment
Kai Fan 0001, Panfei Song, Zhao Du, Haojin Zhu, Hui Li 0006, Yintang Yang, Xinghua Li 0001, Chao Yang 0016 |
WASA | 4 |
| 2016 | Privacy-Preserving Location Proof for Securing Large-Scale Database-Driven Cognitive Radio NetworksabstractThe latest Federal Communications Commission (FCC) ruling has enforced database-driven cognitive radio networks (CRNs), in which all secondary users (SUs) can query a database to obtain spectrum availability information (SAI). Database-driven CRNs are regarded as a promising approach for dynamic and highly efficient spectrum management paradigm for large-scale Internet of Things (IoT). However, as a typical location-based service (LBS), before providing services to the user, there is no verification of the queried location, which is very vulnerable to location spoofing attack. A malicious user can report a fake location to the database and access the channels that may not be available for its location. This will introduce serious interference to the primary users (PUs). In this study, we identify a new kind of attack coined as location cheating attack, which allows an attacker to spoof other users to another location and make them query the database with wrong location, or allows a malicious user to forge location arbitrarily and query the database for services. To thwart this attack, we propose a novel infrastructure-based approach that relies on the existing WiFi or cellular network access points (or AP) to provide privacy-preserving location proof. With the proposed solution, the database can verify the locations without knowing the user's accurate location. We perform comprehensive experiments to evaluate the performance of the proposed approach. Experimental results show that our approach, besides providing location proofs effectively, can significantly improve the user's location privacy. Yi Li 0008, Haojin Zhu, Limin Sun 0001 |
IEEE Internet Things J. | 3 |
| 2016 | You Can Jam But You Cannot Hide: Defending Against Jamming Attacks for Geo-Location Database Driven Spectrum SharingabstractThe emerging paradigm for dynamic spectrum sharing is based on allowing secondary users (SUs) to exploit white space frequency that is not occupied by primary users. White space database provides an opportunity for SUs to obtain spectrum availability information by submitting a location-based query. However, this new paradigm can also be exploited by the attackers to significantly enhance their jamming capability due to the available channel information from spectrum queries, which is expected to increasingly block SUs. The challenge is that the unique characteristics (e.g., lack of the wide range frequencies or continuous broadband) make existing anti-jamming techniques (e.g., direct-sequence spread spectrum and frequency hopping spread spectrum) difficult to be applied. In this paper, we present a novel Jammer Inference-based Jamming Defense (jDefender) framework. The main idea of jDefender is inferring the likelihood of a user being a jammer based on the observed jamming events and then utilizing the inferred attack likelihood to enhance the effectiveness of a series of the proposed anti-jamming strategies. Specifically, we first propose the Channel Allocation-based Jammer Inference scheme to infer the likelihood of an SU being a jammer based on the channels occupied by SUs even under the collusion attack performed by multiple jammers. The strength of the anti-jamming strategies (e.g., puzzle difficulties, available spectrum resources) will be correlated with the possibility of an SU being a jammer to achieve the tradeoff between system performance and jamming tolerance. We then implement the proposed scheme on Universal Software Radio Peripheral and PC. Extensive evaluations are performed to validate the effectiveness of the attacks and countermeasures. Haojin Zhu, Chenliaohui Fang, Yao Liu 0007, Cailian Chen, Mengyuan Li 0004, Xuemin Shen |
IEEE J. Sel. Areas Commun. | 1 |
| 2016 | Cyber security, crime, and forensics of wireless networks and applicationsabstractThe recent advances in cutting-edge electronic and computer technologies and wireless communications have paved the way for the proliferation of wireless networks, encompassing cellular, vehicular, body area, underwater, mobile ad hoc, and sensor networks. Wireless networks, allowing communications from any device, anywhere and anytime, bring a wide range of emerging and disruptive applications in manufacturing, healthcare, military, personal entertainment, safety, and rescue. However, the increasing sophistication and scale of cyber security and crimes in wireless networks have challenged traditional techniques of securing devices, applications, and traffic of wireless networks. Particularly, as the threats and vulnerabilities continue to grow in ubiquitous wireless networks, devices, and applications, it is crucial and imperative for researchers and practitioners of wireless networks to understand the entire cyber-attack and crime spectrum on wireless networks and applications and explore new technologies to mitigate and thwart these attacks, as well as to monitor, capture, and analyze security attacks via forensics analysis. The editorial committees have accepted 12 submissions in this special issue and all the papers have gone through a regular reviewing process. Among these accepted papers, four of them are related to Cloud Computing security. In the paper titled ‘PIMRS: achieving privacy and integrity-preserving multi-owner ranked-keyword search over encrypted cloud data’, Li et al. propose a privacy and integrity-preserving multi-owner ranked-keyword search scheme named PIMRS, where an asymmetric scalar-product encryption function is adopted to preserve data privacy and to obtain more precise search results. In the paper titled ‘MEDAPs: Secure Multi-Entities Delegated Authentication Protocols for Mobile Cloud Computing’, three secure multi-entities delegated authentication protocols are proposed for mobile cloud computing. In these protocols, multiple mobile data owners can authorize a group-designated cloud server with signing rights. Irfan et al. present a framework based on security information and event management to efficiently collect evidence for crime investigation, which can benefit cloud forensics in their paper ‘A framework for cloud forensics evidence collection and analysis using security information and event management’. In the paper ‘Efficient Keyword Search over Encrypted Data in Multi-cloud Setting’, Miao et al. propose two keyword search schemes over encrypted data in multi-cloud setting scenarios. The proposed schemes can guarantee data privacy and reliability. Furthermore, the experimental results indicate that the proposed schemes are feasible and efficient in practical applications. Besides cloud computing security, this special issue also involves another 8 papers covering a wide variety of topics. In the paper titled ‘Secure the Internet, one home at a time’, Xu et al. propose a Bloom-filter based analytics framework to capture persistent threats towards the same home routers and to identify correlated attacks towards distributed home networks. This work is the first one to characterize cyber threats towards home networks. In the paper titled ‘Secure multi-unit sealed first-price auction mechanisms’, Li et al. propose three secure, multi-unit, sealed-bid, and first-price auction schemes. An auctioneer is able to verify that the winners have paid the correct amounts in these three schemes. Theoretical analysis is provided to evaluate the security properties, computational complexity, and communication complexity of the auctions. Zhang et al. propose a data aggregation approach where an untrustful aggregator in mobile sensing can collect statistic data from mobile users in their paper titled ‘An Efficient Privacy Preserving Data Aggregation Approach for Mobile Sensing’. This approach preserves user privacy and can perform data integrity verification. Lai et al. propose a secure and privacy-preserving group setup framework, SPGS, for platoon-based VCPS in their paper titled ‘SPGS: A Secure and Privacy-Preserving Group Setup Framework for Platoon-Based Vehicular Cyber-Physical Systems’. Two authentication protocols are also provided accordingly. The security feature and efficiency of SPGS are verified by the thorough analysis. In the paper titled ‘Multi-proxy multi-signature binding positioning protocol’, Xue et al. propose a multi-proxy multi-signature binding positioning protocol, based on which a multi-proxy multi-signature binding positioning protocol is designed. The correctness and security features of the proposed protocols are analyzed. Qi et al. propose an effective steganography attacking method which is not limited by the types of the steganography method in their paper titled ‘Generic attack against robust steganography based on spring transform and geometrization’. The experiment results indicate that the peak signal-to-noise ratio of images can be above 32 dB Q4 while the stego data are destroyed. In the paper titled ‘Active jamming for multi-user information security improvement with the access statuses of users’, Xu et al. propose a novel physical layer scheme for improving multiple users' information security in the next-generation communication systems. The proposed scheme is linear without iteration and it is feasible for multi-user security enhancement. In the paper titled ‘Secured measurement fusion scheme against deceptive ECM attack in radar network’, in order to prevent electronic countermeasure attacks in radar networks, Yang et al. propose a new measurement fusion scheme, which shows better security performance when a DECM attack happens. The authors also perform simulations to demonstrate the superior of their novel scheme. On behalf of the editorial committee, we would like to thank all the authors for contributing their high quality papers to this special issue. We also want to thank all the reviewers for volunteering their time to review the papers and providing valuable comments, which help with improving the quality of the papers. We are also grateful to Prof. Hsiao-Hwa Chen and Prof. Hamid R. Sharif, who are the Editor-in-Chiefs of Security and Communication Networks, for providing us the opportunity to organize this special issue and for their support during the whole publication process. Xiuzhen Cheng, Miroslaw Kutylowski, Kuai Xu, Haojin Zhu |
Secur. Commun. Networks | 4 |
| 2016 | Cloud-based privacy-preserving aggregation architecture in multi-domain wireless networksabstractAbstract Enabling privacy preserving outsourced data aggregation is regarded as an important issue for multi‐domain wireless networks. In this paper, we present a novel hybrid cloud‐based privacy‐preserving outsourced data aggregation framework. To achieve this, we introduce a hybrid storage cloud and aggregator cloud architecture, in which both of the storage clouds and aggregator cloud are assumed to be untrusted. On the basis of this security assumption, we firstly propose two novel basic protocols, including the proactive privacy‐preserving aggregation and reactive privacy‐preserving aggregation schemes, which are based on the idea of secret sharing. The proactive scheme allows the user to proactively split their data to multiple storage clouds to avoid data leaking while the reactive scheme allows the users to store their encrypted data in storage cloud and aggregator to finish the data aggregation based on the encrypted data. Moreover, on the basis of the proactive privacy‐preserving data aggregation and reactive privacy‐preserving data aggregation, we further propose an advanced protocol, which can resist the malicious data mining attack. The detailed performance simulations are given to demonstrate the security, effectiveness, and efficiency of the proposed scheme. Copyright © 2014 John Wiley & Sons, Ltd. Haojin Zhu, Suguo Du, Xiaolei Dong, Zhenfu Cao |
Secur. Commun. Networks | 2 |
| 2015 | Optimal strategies for defending location inference attack in database-driven CRNsabstractDatabase-driven Cognitive Radio Network (CRN) has been proposed to replace the requirement of spectrum sensing of terminal devices so that the operation of users is simplified. However, location privacy issues introduce a big challenge for securing database-driven CRN due to spectrum availability information. The existing works consider either PU or SU's location privacy while not the both. In this study, we identify a unified attack framework in which a curious user could infer a target's location based on the spectrum availability/utilization information. Further, we propose a location privacy protection mechanism, which allows both SU and PU to protect their location privacy by adopting a series of countermeasures. The location privacy and spectrum utility are the trade-off. In the countermeasures of location privacy preserving spectrum query process, both SU and database aim to maximize the location privacy with constraints of spectrum utility. Thus, they can obtain higher location privacy level with sacrifice of spectrum utility as long as the spectrum utility meets the requirements. We evaluate the unified attack and defence approaches based on simulation and demonstrate the effectiveness of the proposed location privacy preserving approaches. Long Zhang 0003, Chenliaohui Fang, Yi Li 0008, Haojin Zhu, Mianxiong Dong |
ICC | 4 |
| 2015 | Secure and Privacy-Preserving Location Proof in Database-Driven Cognitive Radio Networks
Yi Li 0008, Haojin Zhu, Limin Sun 0001 |
WASA | 3 |
| 2015 | Guest editorial: Security and privacy of P2P networks in emerging smart city
Hongwei Li 0001, Haojin Zhu, Bong Jun Choi 0001 |
Peer-to-Peer Netw. Appl. | 2 |
| 2014 | POSTER: LocMask: A Location Privacy Protection Framework in Android SystemabstractThe mobile users are facing a serious risk of losing location privacy (e.g., users' location information transmitted by open advertisement network, and the reported event of involuntary tracking of mobile users in popular mobile social apps). In this study, we design and implement LocMask, a system-level solution that provides location privacy protection in Android system. LocMask achieves the tradeoff of the privacy and the utility of location based services by providing the Quality of Protection (QoP) on demand, which sets different privacy protection levels to different locations based on how sensitive these locations are. Motivated by the fact that Top locations (e.g, user's home or office) are more sensitive than less visiting locations, LocMask provides location profile management module that records the user's mobility history and ranks the locations in terms of the user's visiting frequency. With users' location profiles, LocMask can automatically determines the sensitiveness of these locations as well as their corresponding privacy protection level. LocMask is also designed to incorporate various obfuscation techniques. The effectiveness of LocMask is supported by extensive real-world data based evaluations. Qiuyu Xiao, Le Yu 0002, Huaxin Li, Haojin Zhu, Muyuan Li, Kui Ren 0001 |
CCS | 5 |
| 2014 | Sybil-aware least cost rumor blocking in social networksabstractRumor blocking and Sybil Attack are regarded as two main security threats in online social networks. The existing work on rumor blocking mainly considers how to minimize the number of protectors used to protect bridge ends. In this study, our experiments based on the Twitter data set show that the existence of the sybil users will dramatically reduce the effectiveness of the rumor blocking by 30%. Motivated by this, we propose a novel sybil-aware least cost rumor blocking framework which jointly considering how to minimize the impact sybil attacks on rumor blocking and optimize the rumor blocking effectiveness. The proposed SLCRB algorithm is well demonstrated by extensive simulations and discussions. Yabin Ping, Zhenfu Cao, Haojin Zhu |
GLOBECOM | 3 |
| 2014 | You are where you have been: Sybil detection via geo-location analysis in OSNsabstractOnline Social Networks (OSNs) are facing an increasing threat of sybil attacks. Sybil detection is regarded as one of major challenges for OSN security. The existing sybil detection proposals that leverage graph theory or exploit the unique clickstream patterns are either based on unrealistic assumptions or limited to the service providers. In this study, we introduce a novel sybil detection approach by exploiting the fundamental mobility patterns that separate real users from sybil ones. The proposed approach is motivated as follows. On the one hand, OSNs including Yelp and Dianping allow us to obtain the users' mobility trajectories based on their online reviews and the locations of their visited shops/restaurants. On the other side, a real user's mobility is generally predictable and confined to a limited neighborhood while the sybils' mobility is forged based on the paid review missions. To exploit the mobility differences between the real and sybil users, we introduce an entropy based definition to capture users' mobility patterns. Then we design a new sybil detection model by incorporating the newly defined location entropy based metrics into other traditional feature sets. The proposed sybil detection model can significantly improve the performance of sybil detections, which is well demonstrated by extensive evaluations based on the data set from Dianping. Xiaokuan Zhang, Haizhong Zheng, Suguo Du, Haojin Zhu |
GLOBECOM | 5 |
| 2014 | Information leaks out: Attacks and countermeasures on compressive data gathering in wireless sensor networksabstractCompressive sensing (CS) has been viewed as a promising technology to greatly improve the communication efficiency of data gathering in wireless sensor networks. However, this new data collection paradigm may bring in new threats but few study has paid attention to prevent information leakage during compressive data gathering. In this paper, we identify two statistical inference attacks and demonstrate that traditional compressive data gathering may suffer from serious information leakage under these attacks. In our theoretical analysis, we quantitatively analyze the estimation error of compressive data gathering through extensive statistical analysis, based on which we propose a new secure compressive data aggregation scheme by adaptively changing the measurement coefficients at each sensor and correspondingly at the sink without the need of time synchronization. In our analysis, we show that the proposed scheme could significantly improve data confidentiality at light computational and communication overhead. Pengfei Hu 0001, Xiuzhen Cheng, Haojin Zhu |
INFOCOM | 5 |
| 2014 | Achieving privacy preservation in WiFi fingerprint-based localizationabstractWiFi fingerprint-based localization is regarded as one of the most promising techniques for indoor localization. The location of a to-be-localized client is estimated by mapping the measured fingerprint (WiFi signal strengths) against a database owned by the localization service provider. A common concern of this approach that has never been addressed in literature is that it may leak the client's location information or disclose the service provider's data privacy. In this paper, we first analyze the privacy issues of WiFi fingerprint-based localization and then propose a Privacy-Preserving WiFi Fingerprint Localization scheme (PriWFL) that can protect both the client's location privacy and the service provider's data privacy. To reduce the computational overhead at the client side, we also present a performance enhancement algorithm by exploiting the indoor mobility prediction. Theoretical performance analysis and experimental study are carried out to validate the effectiveness of PriWFL. Our implementation of PriWFL in a typical Android smartphone and experimental results demonstrate the practicality and efficiency of PriWFL in real-world environments. Hong Li 0004, Limin Sun 0001, Haojin Zhu, Xiang Lu 0004, Xiuzhen Cheng |
INFOCOM | 3 |
| 2014 | Where are you from?: confusing location distinction using virtual multipath camouflageabstractIn wireless networks, location distinction aims to detect location changes or facilitate authentication of wireless users. To achieve location distinction, recent research has been focused on investigating the spatial uncorrelation property of wireless channels. Specifically, the differences of wireless channel characteristics are used to distinguish locations or identify location changes. Song Fang 0001, Yao Liu 0007, Wenbo Shen, Haojin Zhu |
MobiCom | 4 |
| 2014 | All your location are belong to us: breaking mobile social networks for automated user location trackingabstractLocation-based social networks (LBSNs) feature friend discovery by location proximity that has attracted hundreds of millions of users world-wide. While leading LBSN providers claim the well-protection of their users' location privacy, for the first time we show through real world attacks that these claims do not hold. In our identified attacks, a malicious individual with the capability of no more than a regular LBSN user can easily break most LBSNs by manipulating location information fed to LBSN client apps and running them as location oracles. We further develop an automated user location tracking system and test it on leading LBSNs including Wechat, Skout, and Momo. We demonstrate its effectiveness and efficiency via a 3 week real-world experiment on 30 volunteers and show that we could geo-locate any target with high accuracy and readily recover his/her top 5 locations. Finally, we also develop a framework that explores a grid reference system and location classifications to mitigate the attacks. Our result serves as a critical security reminder of the current LBSNs pertaining to a vast number of users. Muyuan Li, Haojin Zhu, Zhaoyu Gao, Si Chen 0009, Le Yu 0002, Shangqian Hu, Kui Ren 0001 |
MobiHoc | 2 |
| 2014 | A Paralleling Broadcast Authentication Protocol for Sparse RSUs in Internet of VehiclesabstractSince the era of Internet of Vehicles (IoVs) is coming in next few years, real-time data transmission between vehicles and road-side sensor nodes has many application scenarios. However, due to different characteristics of IoVs and WSNs (Wireless Sensor Networks), real-time traffic data transmission is too complicated and slow when emergencies occurred in many RSUs-sparse (Road Side Units) areas. We build a simple integrated network model and propose a broadcast authentication protocol, namely Paralleling Broadcast Authentication Protocol (PBAP), aiming at enhance energy efficiency and providing network security in the direct communication between vehicles and WSNs. The simulation results demonstrate that the protocol can effectively extend lifetime of WSNs by improving the utilization rate of the keys and show nice properties in different channel loss ratio and different degrees of DoS attacks. Mengyuan Li 0004, Na Ruan, Haojin Zhu, Jie Li 0002 |
MSN | 3 |
| 2014 | Security and privacy for storage and computation in cloud computing
Lifei Wei, Haojin Zhu, Zhenfu Cao, Xiaolei Dong, Yunlu Chen, Athanasios V. Vasilakos |
Inf. Sci. | 2 |
| 2014 | Constant-round adaptive zero-knowledge proofs for NP
Zongyang Zhang, Zhenfu Cao, Haojin Zhu |
Inf. Sci. | 3 |
| 2014 | An attack-and-defence game for security assessment in vehicular ad hoc networks
Suguo Du, Junbo Du, Haojin Zhu |
Peer-to-Peer Netw. Appl. | 4 |
| 2014 | UAV-assisted data gathering in wireless sensor networks
Mianxiong Dong, Kaoru Ota, Man Lin, Zunyi Tang, Suguo Du, Haojin Zhu |
J. Supercomput. | 6 |
| 2014 | A Probabilistic Misbehavior Detection Scheme toward Efficient Trust Establishment in Delay-Tolerant NetworksabstractMalicious and selfish behaviors represent a serious threat against routing in delay/disruption tolerant networks (DTNs). Due to the unique network characteristics, designing a misbehavior detection scheme in DTN is regarded as a great challenge. In this paper, we propose iTrust, a probabilistic misbehavior detection scheme, for secure DTN routing toward efficient trust establishment. The basic idea of iTrust is introducing a periodically available Trusted Authority (TA) to judge the node's behavior based on the collected routing evidences and probabilistically checking. We model iTrust as the inspection game and use game theoretical analysis to demonstrate that, by setting an appropriate investigation probability, TA could ensure the security of DTN routing at a reduced cost. To further improve the efficiency of the proposed scheme, we correlate detection probability with a node's reputation, which allows a dynamic detection probability determined by the trust of the users. The extensive analysis and simulation results demonstrate the effectiveness and efficiency of the proposed scheme. Haojin Zhu, Suguo Du, Zhaoyu Gao, Mianxiong Dong, Zhenfu Cao |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2013 | Detecting GPS information leakage in Android applicationsabstractLocation Based Service(LBS) becomes very popular in mobile computing platforms, such as Android. However, it could also leak highly personal information about the phone owner if used by Malwares. It has been witnessed that an increased number of malicious Android applications use LBS to obtain users' locations and transmit them to attackers without users' acknowledgement, causing users' privacy breach. In this paper, we first discuss the common way in which privacy can be breached in Android applications, and then define a classification algorithm for GPS information leakage. Furthermore, we develop a location information leakage detection tool named Brox. Brox is based on dalvik-opcode specification, which uses data flow analysis framework equipped with flow-sensitive, context-sensitive, and inter-procedure techniques to detect potential information leakage path in Android malicious applications. Specifically, Brox uses inter-procedure analysis and dependency calculation to understand the intention for each sensitive operation; by using reachable analysis, connection between privacy access operation and leakage operation is established. More importantly, Brox confirms whether the sending out operation contains location information or not using static taint analysis. At last, we classify the detection results with the help of identification of interaction and non-user interaction entry points in order to discover stealthy leaks of GPS location. The extensive experiments results show that the proposed method can effectively detect privacy leakage in Android applications with a high accuracy rate. Zhushou Tang, Qiuyu Xiao, Jiafa Liu, Tran Triet Duong, Xiaodong Lin 0001, Haojin Zhu |
GLOBECOM | 7 |
| 2013 | Location Privacy Preserving Dynamic Spectrum Auction in Cognitive Radio NetworkabstractDynamic spectrum auction offers the flexibility and capability for bidders to request and acquire unoccupied channels from spectrum license holders. Compared with the conventional auction, spectrum auction allows various buyers to utilize the same channel simultaneously based on their locations, which is denoted as spectrum reusability. In this paper, we consider a novel kind of attack, which could compromise location privacy of bidders by observing the bid items as well as bid price. To thwart this attack, we introduce a new Location Privacy Preserving Dynamic Spectrum Auction (LPPA) scheme which consists of two components: Privacy Preserving Bid Submission protocol (PPBS) and Private Spectrum Distribution protocol (PSD). Based on the prefix membership verification scheme, PPBS allows the auctioneer to construct the conflict relationship between different users and obtain the maximum value of bids on various channels without leaking users' location information. Furthermore, PSD is proposed to efficiently distribute the spectrum among bidders and securely charge the winners with the help of periodically available TTP (Trusted Third Party). To demonstrate the effectivenss of the proposed scheme, we implement our attack and scheme on data extracted from Google Earth Coverage Maps released by FCC. The experiment results show the efficacy and efficiency of our approach. Haojin Zhu, Cailian Chen, Xin-Ping Guan |
ICDCS | 2 |
| 2013 | Location privacy in database-driven Cognitive Radio Networks: Attacks and countermeasuresabstractCognitive Radio Network (CRN) is regarded as a promising way to address the increasing demand for wireless channel resources. It solves the channel resource shortage problem by allowing a Secondary User (SU) to access the channel of a Primary User (PU) when the channel is not occupied by the PU. The latest FCC's rule in May 2012 enforces database-driven CRNs, in which an SU queries a database to obtain spectrum availability information by submitting a location based query. However, one concern about database-driven CRNs is that the queries sent by SUs will inevitably leak the location information. In this study, we identify a new kind of attack against location privacy of database-drive CRNs. Instead of directly learning the SUs' locations from their queries, our discovered attacks can infer an SU's location through his used channels. We propose Spectrum Utilization based Location Inferring Algorithm that enables the attacker to geo-locate an SU. To thwart location privacy leaking from query process, we propose a novel Private Spectrum Availability Information Retrieval scheme that utilizes a blind factor to hide the location of the SU. To defend against the discovered attack, we propose a novel prediction based Private Channel Utilization protocol that reduces the possibilities of location privacy leaking by choosing the most stable channels. We implement our discovered attack and proposed scheme on the data extracted from Google Earth Coverage Maps released by FCC. Experiment results show that the proposed protocols can significantly improve the location privacy. Zhaoyu Gao, Haojin Zhu, Yao Liu 0007, Muyuan Li, Zhenfu Cao |
INFOCOM | 2 |
| 2013 | YouSense: Mitigating entropy selfishness in distributed collaborative spectrum sensingabstractCollaborative spectrum sensing has been recognized as a promising approach to improve the sensing performance via exploiting the spatial diversity of the secondary users. In this study, a new selfishness issue is identified, that selfish users sense no spectrum in collaborative sensing. For easier presentation, it's denoted as entropy selfishness. This selfish behavior is difficult to distinguish, making existing detection based incentive schemes fail to work. To thwart entropy selfishness in distributed collaborative sensing, we propose YouSense, a One-Time Pad (OTP) based incentive design that could naturally isolate entropy selfish users from the honest users without selfish node detection. The basic idea of YouSense is to construct a trapdoor onetime pad for each sensing report by combining the original report and a random key. Such a one-time pad based encryption could prevent entropy selfish users from accessing the original sensing report while enabling the honest users to recover the report. Different from traditional cryptography based OTP which requires the key delivery, YouSense allows an honest user to recover the pad (or key) by exploiting a unique characteristic of collaborative sensing that different secondary users share some common observations on the same radio spectrum. We further extend YouSense to improve the recovery successful rate by reducing the cardinality of set of the possible pads. By extensive USRP based experiments, we show that YouSense can successfully thwart entropy selfishness with low system overhead. Haojin Zhu, Zhaoyu Gao, Xin-Ping Guan |
INFOCOM | 2 |
| 2013 | Mutual privacy-preserving regression modeling in participatory sensingabstractAs the advancement of sensing and networking technologies, participatory sensing has raised more and more attention as it provides a promising way enabling public and professional users to gather and analyze private data to understand the world. However, in these participatory sensing applications both data at the individuals and analysis results obtained at the users are usually private and sensitive to be disclosed, e.g., locations, salaries, utility usage, consumptions, behaviors, etc. A natural question, also an important but challenging problem is how to keep both participants and users data privacy while still producing the best analysis to explain a phenomenon. In this paper, we have addressed this issue and proposed M-PERM, a mutual privacy preserving regression modeling approach. Particularly, we launch a series of data transformation and aggregation operations at the participatory nodes, the clusters, and the user. During regression model fitting, we provide a new way for model fitting without any need of the original private data or the exact knowledge of the model expression. To evaluate our approach, we conduct both theoretical analysis and simulation study. The evaluation results show that the proposed approach produces exactly the same best model as if the original private data were used without leakage of the fitted model to any participatory nodes, which is a significant advance compared with the existing approaches [1-5]. It is also shown that the data gathering design is able to reach maximum privacy protection under certain conditions and be robust against collusion attack. Furthermore, compared with existing works under the same context (e.g., [1-5]), to our best knowledge it is the first work showing that not only the model coefficients estimation but also a series of regression analysis and model selection methods are reachable in mutual privacy preserving data analysis scenarios such as participatory sensing. Zhiguo Wan, Pengfei Hu 0001, Haojin Zhu, Yuepeng Wang 0001, Xi Chen 0014, Yang Wang 0015, Liusheng Huang |
INFOCOM | 4 |
| 2013 | A localized backbone renovating algorithm for wireless ad hoc and sensor networksabstractIn this paper we propose and analyze a localized backbone renovating algorithm (LBR) to renovate a broken backbone in the network. This research is motivated by the problem of virtual backbone maintenance in wireless ad hoc and sensor networks, where the coverage area of nodes are disks with identical radii. According to our theoretical analysis, the proposed algorithm has the ability to renovate the backbone in a purely localized manner with a guaranteed connectivity of the network, while keeping the backbone size within a constant factor from that of the minimum CDS. Both the communication overhead and computation overhead of the LBR algorithm are O(k), where k is the number of nodes broken or added. We also conduct extensive simulation study on connectivity, backbone size, and the communication/computation overhead. The simulation results show that the proposed algorithm can always keep the renovated backbone being connected at low communication/computation overhead with a relatively small backbone, compared with other existing schemes. Furthermore, the LBR algorithm has the ability to deal with arbitrary number of node failures and additions in the network. Shuo Zhang 0011, Lei Shi 0011, Haojin Zhu, Yuepeng Wang 0001 |
INFOCOM | 4 |
| 2012 | Location privacy leaking from spectrum utilization information in database-driven cognitive radio networkabstractThe Database-driven Cognitive Radio Network is regarded as a promising way for a better utilization of radio channels without introducing the interference to the primary user. However, it is also facing a series of security threats. In this study, we identify a new kind of location privacy related attack which could geo-locate a secondary user from the spectrum he used. We propose a Spectrum Utilization based Location Inference Algorithm, which is based on the intersection of the possible location sets revealed by each channel access or channel transition event under the presence of the primary user. We implement our algorithm on the data extracted from Google Earth Coverage Maps released by FCC. Our experiement results show that, $80\%$ SUs could be located to 10 cells based on 25 or less channels. Zhaoyu Gao, Haojin Zhu, Yao Liu 0007, Muyuan Li, Zhenfu Cao |
CCS | 2 |
| 2012 | PriMatch: Fairness-aware secure friend discovery protocol in mobile social networkabstractMobile social networks are expected to substantially enrich interaction with ubiquitous computing environments by integrating social context information into local interactions. However, in mobile social networks, the mobile users may face the risk of leaking their personal information and their location privacy. In this study, we first model the secure friend discovery process as a generalized privacy-preserving interest/profile matching problem. Then, we identify a new security threat arising from existing secure friend discovery protocols, coined as runaway attack, which is expected to introduce serious fairness issue. To address this new threat, we introduce a novel blind vector transformation technique, which could hide the correlation between the original vector and the transformed result. Based on it, we propose our fairness-aware privacy preserving interest/profile matching protocol, which enables one party to match its interest with the profile of another, without revealing its real interest and profile and vice versa. The detailed security analysis as well as real-world implementations demonstrate the effectiveness and the efficiency of the proposed protocol. Muyuan Li, Zhaoyu Gao, Suguo Du, Haojin Zhu, Mianxiong Dong, Kaoru Ota |
GLOBECOM | 4 |
| 2012 | An Adaptive Deviation-tolerant Secure Scheme for distributed cooperative spectrum sensingabstractDistributed collaborative spectrum sensing is a promising method to improve the precision and efficiency of primary user detection in cognitive radio networks. Despite its performance advantages, it introduces new security issues that malicious or selfish nodes may manipulate false sensing data to degrade or even covert the sensing result of the whole network. Existing research often utilizes a threshold to distinguish honest users and malicious ones. However, determining such a threshold is difficult due to the dynamic characteristic of cognitive radio networks, and it is likely to misjudge an honest node with a relatively large deviation to be malicious. In this paper, we propose an Adaptive Deviation-tolerant Secure Scheme (ADS) for distributed collaborative spectrum sensing, which aims to mitigate the misbehaviors of inside malicious nodes and, at the same time, tolerant the large deviation introduced by honest users. ADS achieves the trade off of sensing security and deviation tolerance by assigning a dynamic weight to each sensing node and utilizes an adaptive threshold to minimize the negative effect on honest users. We evaluate the performance of the scheme through both analytical and simulation based study. Haojin Zhu, Xu Li 0001, Cailian Chen, Xin-Ping Guan |
GLOBECOM | 2 |
| 2012 | Towards addressing group selfishness of cluster-based collaborative spectrum sensing in cognitive radio networksabstractCollaborative spectrum sensing has been recognized as a promising way to ameliorate the sensing performance in cognitive radio networks. Unfortunately, it also introduces some system overhead to users, and as a result some selfish secondary users might be unwilling to contribute to collaborative spectrum sensing. In this paper, we propose a new selfishness model in cluster-based collaborative spectrum sensing, which is referred to Overclaim Selfishness (OS). An OS group may gain benefit by sharing nominally equal but actually much less sensing reports than it declares. To deal with this problem, we propose an Overclaim Selfishness Detection Scheme (OSDS) to detect the potential OS groups. We find that a single secondary user tends to have one special type of sensing reports correlated with his physical location, thus the cluster number estimated by OSDS should be no much less than the number of users the group contains. Further, we adopt an incentive scheme to stimulate rational groups to behave honestly. Finally, a real world experiment is adopted to demonstrate the effectiveness of our proposed scheme OSDS. Yiyong Sun, Zhaoyu Gao, Suguo Du, Haojin Zhu, Xiaodong Lin 0001 |
GLOBECOM | 5 |
| 2012 | PMDS: A probabilistic misbehavior detection scheme in DTNabstractMalicious and selfish behaviors represent a serious threat against routing in Delay or Disruption Tolerant Networks (DTNs). Due to the unique network characteristics, designing a misbehavior detection scheme in DTN represents a great challenge. In this paper, we propose PMDS, a probabilistic misbehavior detection scheme, for secure DTN routing. The basic idea of PMDS is introducing a periodically available Trusted Authority (TA), which judges the node's behavior based on the collected routing evidences. We model PMDS as the Inspection Game and use game theoretical analysis to demonstrate that, by setting an appropriate investigation probability, TA could ensure the security of DTN routing at a reduced cost. To further improve the efficiency of the proposed scheme, we correlate detection probability with a node's reputation, which allows a dynamic detection probability determined by a node's reputation. The extensive analysis and simulation results show that the proposed scheme substantiates the effectiveness and efficiency of the proposed scheme. Zhaoyu Gao, Haojin Zhu, Suguo Du, Chengxin Xiao, Rongxing Lu |
ICC | 2 |
| 2012 | Towards a game theoretical modeling of rational collaborative spectrum sensing in Cognitive Radio networksabstractCollaborative spectrum sensing has been proposed recently to improve the sensing performance in Cognitive Radio networks. However, cooperative sensing will also introduce extra cost to the collaborator, such as the cooperative time and energy consumption. In reality, whether the rational secondary users have incentive to join the collaboration depends upon whether the benefit of the collaboration could outweigh the cost. In this paper, we model it as the Cooperative Spectrum Sensing Game (CSSG). In this game, every secondary user could choose to collaborate or not in each time slot, and the payoff is measured in terms of data throughput. Since the effectiveness of collaboration is proportional to the number of the collaborators, secondary users' decisions are based on how many users will choose to collaborate. Thus, CSSG could be modeled as the classic game: the Stag Hunt Game. In addition, to avoid the cooperation failure, we propose Cooperative Communication Incentive Scheme (CCIS) to enhance the collaborative sensing. At last, the numerical analysis about CSSG as well as the proposed scheme CCIS is given. Haojin Zhu, Bo Yang 0006, Cailian Chen, Xin-Ping Guan, Xiaodong Lin 0001 |
ICC | 2 |
| 2012 | Location privacy preservation in collaborative spectrum sensingabstractCollaborative spectrum sensing has been regarded as a promising approach to enable secondary users to detect primary users by exploiting spatial diversity. In this paper, we consider a converse question: could space diversity be exploited by a malicious entity, e.g., an external attacker or an untrusted Fusion Center (FC), to achieve involuntary geolocation of a secondary user by linking his location-dependent sensing report to his physical position. We answer this question by identifying a new security threat in collaborative sensing from testbed implementation, and it is shown that the attackers could geo-locate a secondary user from its sensing report with a successful rate of above 90% even in the presence of data aggregation. We then introduce a novel location privacy definition to quantify the location privacy leaking in collaborative sensing. We propose a Privacy Preserving collaborative Spectrum Sensing (PPSS) scheme, which includes two primitive protocols: Privacy Preserving Sensing Report Aggregation protocol (PPSRA) and Distributed Dummy Report Injection Protocol (DDRI). Specifically, PPSRA scheme utilizes applied cryptographic techniques to allow the FC to obtain the aggregated result from various secondary users without learning each individual's values while DDRI algorithm can provide differential location privacy for secondary users by introducing a novel sensing data randomization technique. We implement and evaluate the PPSS scheme in a real-world testbed. The evaluation results show that PPSS can significantly improve the secondary user's location privacy with a reasonable security overhead in collaborative sensing. Haojin Zhu, Zhaoyu Gao, Xin-Ping Guan, Xuemin Shen |
INFOCOM | 2 |
| 2012 | Leveraging Cloud Computing for Privacy Preserving Aggregation in Multi-domain Wireless Networks
Chengxin Xiao, Haojin Zhu, Suguo Du, Zhenfu Cao |
WASA | 3 |
| 2012 | BECAN: A Bandwidth-Efficient Cooperative Authentication Scheme for Filtering Injected False Data in Wireless Sensor NetworksabstractInjecting false data attack is a well known serious threat to wireless sensor network, for which an adversary reports bogus information to sink causing error decision at upper level and energy waste in en-route nodes. In this paper, we propose a novel bandwidth-efficient cooperative authentication (BECAN) scheme for filtering injected false data. Based on the random graph characteristics of sensor node deployment and the cooperative bit-compressed authentication technique, the proposed BECAN scheme can save energy by early detecting and filtering the majority of injected false data with minor extra overheads at the en-route nodes. In addition, only a very small fraction of injected false data needs to be checked by the sink, which thus largely reduces the burden of the sink. Both theoretical and simulation results are given to demonstrate the effectiveness of the proposed scheme in terms of high filtering probability and energy saving. Rongxing Lu, Xiaodong Lin 0001, Haojin Zhu, Xiaohui Liang 0002, Xuemin Shen |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2011 | How to design space efficient revocable IBE from non-monotonic ABEabstractSince there always exists a possibility that some users' private keys are stolen or expired in practice, it is important for identity based encryption (IBE) system to provide a solution to revocation. The current most efficient revocable IBE system has a private key of size O(log ns) and update information of size O(r log(n/r)) where r is the number of revoked users. In this paper, we present a new revocable IBE system in which the private key only contains two group elements and the update information size is O(r). We show that the proposed constructions for the revocation mechanism are more efficient in terms of space cost and provide a generic methodology to transform a non-monotonic attribute based encryption into a revocable IBE. We also demonstrate how the proposed method can be employed to develop an efficient hierarchical revocable IBE system. Huang Lin, Zhenfu Cao, Yuguang Fang, Muxin Zhou, Haojin Zhu |
AsiaCCS | 5 |
| 2011 | MobiGame: A User-Centric Reputation Based Incentive Protocol for Delay/Disruption Tolerant NetworksabstractDelay/Disruption tolerant networks (DTNs) are self-organized wireless networks, where end-to-end network connectivity is not available and the data forwarding relies on the assumption that the intermediate nodes are ready to "store, carry and forward" messages in an opportunistic way. This assumption can be easily violated by the selfish nodes which may be unwilling to use their precious resources by serving as relays. Due to the unique network characteristics, incentive issue is extraordinarily challenging in DTNs. To tackle this issue, in this paper, we propose MobiGame, a user-centric reputation based incentive protocol for DTNs, which allows a node to manage its reputation evidence. For the fairness requirement, we define a game-theoretic framework to design reasonable costs and reward parameters in the MobiGame's bundle forwarding, which leads to a Perfect Bayesian Equilibrium. Performance simulations are given to demonstrate the security, effectiveness and efficiency. Lifei Wei, Zhenfu Cao, Haojin Zhu |
GLOBECOM | 3 |
| 2011 | Believe Yourself: A User-Centric Misbehavior Detection Scheme for Secure Collaborative Spectrum SensingabstractCollaborative spectrum sensing has been proposed recently to facilitate precise detection of Primary Users in Cognitive Radio networks. However, it simultaneously introduces new security issue that the selfish or even misbehaving users could cheat a secondary user by depriving its access opportunity. To address this problem, we propose a novel User-centric Misbehavior Detection Scheme (UMDS) in this paper to detect malicious behaviors in collaborative spectrum sensing. The basic idea of UMDS is motivated by the fact that a mobile user tends to trust the sensing report generated by itself rather than the reports from other nodes. Therefore, a secondary user could independently determine if a sensing partner is malicious or not by calculating the correlation between the secondary user's own reports and those of other sensing nodes. We also discuss how to further improve the performance of the UMDS by choosing an optimized threshold. The effectiveness and efficiency of the proposed scheme is demonstrated by extensive analysis and numerical results. Haojin Zhu, Bo Yang 0006, Cailian Chen, Xin-Ping Guan |
ICC | 2 |
| 2011 | A Novel Attack Tree Based Risk Assessment Approach for Location Privacy Preservation in the VANETsabstractEven though emerging as a promising approach to increase road safety, efficiency and convenience, Vehicular Ad hoc Networks (VANETs) pose many new research challenges, especially on the aspect of location privacy. The existing literatures focus on preventive techniques to achieve location privacy protection, however the location privacy risk assessment receives less attention. In this paper, we introduce a novel risk assessment method to evaluate the security risk of VANET's privacy based on attack tree. The proposed scheme provides a general analysis framework to estimate the degree that a certain threat might bring to the VANETs. We also use the constructed attack tree to identify possible attack scenarios that an attacker may launch towards the privacy preserving system in VANETs, which is expected to further improve the system security. Dandan Ren, Suguo Du, Haojin Zhu |
ICC | 3 |
| 2011 | Automatic inference of movements from contact historiesabstractThis paper introduces a new security problem in which individuals movement traces (in terms of accurate routes) can be inferred from just a series of mutual contact records and the map of the area in which they roam around. Such contact records may be obtained through the bluetooth communication on mobile phones. Zhaoyu Gao, Xinhui Xu, Yujiao Zhou, Haojin Zhu, Kenny Q. Zhu |
SIGCOMM | 5 |
| 2011 | Network Coding Based Privacy Preservation against Traffic Analysis in Multi-Hop Wireless NetworksabstractPrivacy threat is one of the critical issues in multi-hop wireless networks, where attacks such as traffic analysis and flow tracing can be easily launched by a malicious adversary due to the open wireless medium. Network coding has the potential to thwart these attacks since the coding/mixing operation is encouraged at intermediate nodes. However, the simple deployment of network coding cannot achieve the goal once enough packets are collected by the adversaries. On the other hand, the coding/mixing nature precludes the feasibility of employing the existing privacy-preserving techniques, such as Onion Routing. In this paper, we propose a novel network coding based privacy-preserving scheme against traffic analysis in multi-hop wireless networks. With homomorphic encryption on Global Encoding Vectors (GEVs), the proposed scheme offers two significant privacy-preserving features, packet flow untraceability and message content confidentiality, for efficiently thwarting the traffic analysis attacks. Moreover, the proposed scheme keeps the random coding feature, and each sink can recover the source packets by inverting the GEVs with a very high probability. Theoretical analysis and simulative evaluation demonstrate the validity and efficiency of the proposed scheme. Yanfei Fan, Yixin Jiang, Haojin Zhu, Jiming Chen 0001, Xuemin Shen |
IEEE Trans. Wirel. Commun. | 3 |
| 2010 | How to Construct Interval Encryption from Binary Tree Encryption
Huang Lin, Zhenfu Cao, Xiaohui Liang 0002, Muxin Zhou, Haojin Zhu, Dongsheng Xing |
ACNS | 5 |
| 2010 | SAS: A Secure Data Aggregation Scheme in Vehicular Sensing NetworksabstractVehicular ad hoc networks support a wide range of promising applications including vehicular sensing networks, which enable vehicles to cooperatively collect and transmit the aggregated traffic data for the purpose of traffic monitoring. The reported literatures mainly focus on how to achieve the data aggregation in dynamic vehicular environment while the security issue especially on the authenticity and integrity of aggregation results receive less attention. In this study, we introduce a secure probabilistic data aggregation scheme based on Flajolet-Martin sketch and \emph{sketch proof} technique. We also discuss the tradeoff between the bandwidth efficiency and the estimation accuracy. Extensive simulations and analysis demonstrate the efficiency and effectiveness of the proposed scheme. Suguo Du, Dandan Ren, Haojin Zhu |
ICC | 4 |
| 2010 | TESP2: Timed Efficient Source Privacy Preservation Scheme for Wireless Sensor NetworksabstractSource privacy preservation against global eavesdroppers' traffic analysis attack is one of the most challenge issues in wireless sensor networks. In this paper, we present a new timed efficient source privacy preservation (TESP2) scheme. In the TESP2 scheme, each sensor node broadcasts timed data collection request to its upstream nodes, and then each upstream node will return the real data's ciphertext if it has detected something, or a dummy data's ciphertext if it hasn't. After receiving ciphertexts from upstream nodes, the sensor node will filter the dummy data, re-encrypt and forward the real data's ciphertexts to its downstream node to achieve the source privacy preservation. Security analysis and extensive simulation results demonstrate the proposed TESP2 scheme can resist the traffic analysis attack and achieve high source privacy preservation with some tolerant latency. Rongxing Lu, Xiaodong Lin 0001, Haojin Zhu, Xuemin Shen |
ICC | 3 |
| 2010 | An Opportunistic Batch Bundle Authentication Scheme for Energy Constrained DTNsabstractBundle Authentication is a critical security service in Delay Tolerant Networks (DTNs) that ensures authenticity and integrity of bundles during multi-hop transmissions. Public key signatures, which have been suggested in existing bundle security protocol specification, achieve bundle authentication at the cost of an increased computational, transmission overhead and a higher energy consumption, which is not desirable for energy-constrained DTNs. On the other hand, the unique ``store-carry-and-forward'' transmission characteristic of DTNs implies that bundles from distinct/common senders can be buffered opportunistically at some common intermediate nodes. This ``buffering'' characteristic distinguishes DTN from any other traditional wireless networks, for which an intermediate cache is not supported. To exploit such a buffering characteristic, in this paper, we propose an Opportunistic Batch Bundle Authentication Scheme (OBBA) to achieve efficient bundle authentication. The proposed scheme adopts batch verification techniques, allowing a computational overhead to be bounded by the number of opportunistic contacts instead of the number of messages. Furthermore, we introduce a novel concept of a fragment authentication tree to minimize communication cost by choosing an optimal tree height. Finally, we implement OBBA in a specific DTN scenario setting: packet-switched networks on campus. The simulation results in terms of computation time, transmission overhead and power consumption are given to demonstrate the efficiency and effectiveness of the proposed schemes. Haojin Zhu, Xiaodong Lin 0001, Rongxing Lu, Xuemin Shen, Dongsheng Xing, Zhenfu Cao |
INFOCOM | 1 |
| 2010 | An efficient dynamic-identity based signature scheme for secure network coding
Yixin Jiang, Haojin Zhu, Minghui Shi, Xuemin Shen, Chuang Lin 0002 |
Comput. Networks | 2 |
| 2010 | PIE: cooperative peer-to-peer information exchange in network coding enabled wireless networksabstractIn this paper, we study the issue of scheduling transmission opportunities among nodes (peers) to achieve higher network throughput and lower transmission delay for network coding enabled wireless networks. By conducting an in-depth investigation on the scheduling principles, we propose a cooperative Peer-to-peer Information Exchange (PIE) scheme with an efficient and light-weight scheduling algorithm. PIE can not only fully exploit the broadcast nature of wireless channels, but also take advantage of cooperative peer-to-peer information exchange. Qualitative analysis and extensive simulations demonstrate the effectiveness and efficiency of PIE. Yanfei Fan, Yixin Jiang, Haojin Zhu, Xuemin Shen |
IEEE Trans. Wirel. Commun. | 3 |
| 2010 | Pi: a practical incentive protocol for delay tolerant networksabstractDelay Tolerant Networks (DTNs) are a class of networks characterized by lack of guaranteed connectivity, typically low frequency of encounters between DTN nodes and long propagation delays within the network. As a result, the message propagation process in DTNs follows a store-carryand- forward manner, and the in-transit bundle messages can be opportunistically routed towards the destinations through intermittent connections under the hypothesis that each individual DTN node is willing to help with forwarding. Unfortunately, there may exist some selfish nodes, especially in a cooperative network like DTN, and the presence of selfish DTN nodes could cause catastrophic damage to any well designed opportunistic routing scheme and jeopardize the whole network. In this paper, to address the selfishness problem in DTNs, we propose a practical incentive protocol, called Pi, such that when a source node sends a bundle message, it also attaches some incentive on the bundle, which is not only attractive but also fair to all participating DTN nodes. With the fair incentive, the selfish DTN nodes could be stimulated to help with forwarding bundles to achieve better packet delivery performance. In addition, the proposed Pi protocol can also thwart various attacks, which could be launched by selfish DTN nodes, such as free ride attack, layer removing and adding attacks. Extensive simulation results demonstrate the effectiveness of the proposed Pi protocol in terms of high delivery ratio and lower average delay. Rongxing Lu, Xiaodong Lin 0001, Haojin Zhu, Xuemin Shen, Bruno R. Preiss |
IEEE Trans. Wirel. Commun. | 3 |
| 2009 | Cooperative Peer-to-Peer Information Exchange via Wireless Network CodingabstractNetwork coding has been widely recognized as a promising information dissemination approach for wireless networks. However, in practical wireless networks enabled with network coding, different peer sending sequences make significant impact on overall network throughput and transmission delay. In this paper, we study the peer scheduling problem, which is defined as how to intelligently schedule the sending sequence among a group of peers to maximize the wireless coding gain. By conducting an in-depth investigation on the peer scheduling principles in wireless network coding, we propose a cooperative Peer-to-peer Information Exchange (PIE) scheme with an efficient and light-weight peer scheduling algorithm. The PIE scheme can not only fully exploit the broadcast nature of wireless channels, but also utilize the advantage of cooperative peer-to-peer information exchange. Finally, the effectiveness and efficiency of the PIE scheme are demonstrated through qualitative analysis and extensive simulations. Yanfei Fan, Yixin Jiang, Haojin Zhu, Xuemin Shen |
GLOBECOM | 3 |
| 2009 | An Efficient Privacy-Preserving Scheme against Traffic Analysis Attacks in Network CodingabstractPrivacy threat is one of the critical issues in network coding, where attacks such as traffic analysis can be easily launched by a malicious adversary once enough encoded packets are collected. Furthermore, the encoding/mixing nature of network coding precludes the feasibility of employing the existing privacy-preserving techniques, such as Onion routing, in network coding enabled networks. In this paper, we propose a novel privacy-preserving scheme against traffic analysis in network coding. With homomorphic encryption operation on global encoding vectors (GEVs), the proposed scheme offers two significant privacy-preserving features, packet flow untraceability and message content confidentiality, for efficiently thwarting the traffic analysis attacks. Moreover, the proposed scheme keeps the random coding feature, and each sink can recover the source packets by inverting the GEVs with a very high probability. Theoretical analysis and simulative evaluation demonstrate the validity and efficiency of the proposed scheme. Yanfei Fan, Yixin Jiang, Haojin Zhu, Xuemin Shen |
INFOCOM | 3 |
| 2009 | SPARK: A New VANET-Based Smart Parking Scheme for Large Parking LotsabstractSearching for a vacant parking space in a congested area or a large parking lot and preventing auto theft are major concerns to our daily lives. In this paper, we propose a new smart parking scheme for large parking lots through vehicular communication. The proposed scheme can provide the drivers with real-time parking navigation service, intelligent anti-theft protection, and friendly parking information dissemination. Performance analysis via extensive simulations demonstrates its efficiency and practicality. Rongxing Lu, Xiaodong Lin 0001, Haojin Zhu, Xuemin Shen |
INFOCOM | 3 |
| 2008 | BBA: An Efficient Batch Bundle Authentication Scheme for Delay Tolerant NetworksabstractTo realize efficient in-transit messages (bundles) authentication in delay tolerant networks (DTNs), this paper introduces a novel batch bundle authentication (BBA) scheme to validate the bundles in a batch instead of authenticating them one by one. We take the advantage of identity based cryptography to dramatically reduce the transmission cost, and adopt batch signature technique to realize the efficient bundle signature verification. Compared with existing message authentication approaches, our scheme has the superiority on improved efficiency even under the invalid signature attack. Simulation results demonstrate that the proposed scheme can be an enhancement for current bundle security protocol specification. Haojin Zhu, Xiaodong Lin 0001, Rongxing Lu, Xuemin Shen, Pin-Han Ho |
GLOBECOM | 1 |
| 2008 | Provably Secure Self-Certified Partially Blind Signature Scheme from Bilinear PairingsabstractTo enable the practical electronic cash systems, significant attention has been paid to the partially blind signature because of its unlinkability and unforgeability. To the best of our knowledge, most of partially blind signature schemes are constructed under either the traditional public key certificate based system or the ID-based system, which may incur significant efforts in certification management and/or revocation. In this paper, we introduce a novel approach for partially blind signature with self-certified public keys. This is the first research effort for significantly reducing the certificate management and revocation in partially blind signature, and is characterized by the adoption of bilinear pairings and the analytic techniques of provable security. Xiaodong Lin 0001, Rongxing Lu, Haojin Zhu, Pin-Han Ho, Xuemin Shen |
ICC | 3 |
| 2008 | AICN: An Efficient Algorithm to Identify Compromised Nodes in Wireless Sensor NetworkabstractWireless sensor networking is an emerging technology, which potentially supports many emerging applications for both civilian and military purposes, ranging from environmental monitoring to battlefield surveillance. However, since sensor nodes are inexpensive devices, which could be easily compromised and controlled by an adversary, the compromised nodes could report false sensed results and degrade the reliability of the whole network. Therefore, how to identify these compromised nodes in a wireless sensor network is a very important security issue. To solve this problem, we propose an efficient algorithm, called AICN, to logically identify the compromised nodes in an efficient and effective way. Based on the network reliability estimation (NRE), we also present its enhanced version to further improve the efficiency. Rongxing Lu, Xiaodong Lin 0001, Chenxi Zhang 0002, Haojin Zhu, Pin-Han Ho, Xuemin Shen |
ICC | 4 |
| 2008 | AEMA: An Aggregated Emergency Message Authentication Scheme for Enhancing the Security of Vehicular Ad Hoc NetworksabstractTo achieve efficient authentication on emergency events in vehicular ad hoc networks, we introduce a novel aggregated emergency message authentication (AEMA) scheme to validate an emergency event. We make use of syntactic aggregation and cryptographic aggregation techniques to dramatically reduce the transmission cost, and adopt batch verification technique for efficient emergency messages verification. Compared with existing emergency message authentication approaches, our scheme shows the superiority on generality, enhanced security and efficiency. Haojin Zhu, Xiaodong Lin 0001, Rongxing Lu, Pin-Han Ho, Xuemin Shen |
ICC | 1 |
| 2008 | ECPP: Efficient Conditional Privacy Preservation Protocol for Secure Vehicular CommunicationsabstractWe introduce an efficient conditional privacy preservation (ECPP) protocol in vehicular ad hoc networks (VANETs) to address the issue on anonymous authentication for safety messages with authority traceability. The proposed protocol is characterized by the generation of on-the-fly short-time anonymous keys between on-board units (OBUs) and roadside units (RSUs), which can provide fast anonymous authentication and privacy tracking while minimizing the required storage for short-time anonymous keys. We demonstrate the merits gained by the proposed protocol through extensive analysis. Rongxing Lu, Xiaodong Lin 0001, Haojin Zhu, Pin-Han Ho, Xuemin Shen |
INFOCOM | 3 |
| 2008 | A New Dynamic Group Key Management Scheme with Low Rekeying CostabstractTo achieve secure group communications, it is critical to develop a secure group key management strategy to guarantee security of the group keys. In this paper, based on the forward security and secret sharing techniques, we propose a new dynamic group key management scheme to minimize the rekeying cost. The forward security technique reduces the rekeying operations in joining event, while the secret sharing technique ensures the scalability in leaving event. In addition, the proposed scheme can provide anonymous authentication as well as forward and backward confidentiality. Theoretical analysis also confirms the efficiency of the proposed scheme. Rongxing Lu, Xiaodong Lin 0001, Haojin Zhu, Pin-Han Ho, Xuemin Shen, Zhenfu Cao |
WCNC | 3 |
| 2008 | A Novel Fair Incentive Protocol for Mobile Ad Hoc NetworksabstractTo enhance the overall performance of a mobile ad hoc network (MANET), people have tried to solve the issue of node selfishness, which has sparked a surge of research interests in credit-based incentive protocols. The core idea of credit-based incentive is to provide incentives for selfish nodes to faithfully forward packets in a MANET. Recently, several credit-based incentive protocols have been proposed. However, the fairness issue in those reported credit-based incentive protocols has never been well addressed yet. Without the fairness guarantees, the whole network still cannot reach its optimum cooperative status. Therefore, in this paper, aiming at fairness, we first define the fairness principle for credit-based incentive protocol, and then present a novel fair incentive protocol (FIP) for MANETs. Rongxing Lu, Xiaodong Lin 0001, Haojin Zhu, Chenxi Zhang 0002, Pin-Han Ho, Xuemin Shen |
WCNC | 3 |
| 2008 | SLAB: A secure localized authentication and billing scheme for wireless mesh networksabstractThe future metropolitan-area wireless mesh networks (WMNs) are expected to contain compromise-prone Mesh Access Points (MAPs) with a high frequency of inter-domain roaming/handoff events. This paper introduces a novel secure localized authentication and billing (SLAB) scheme, which aims to address both security guarantee and performance in terms of system compromise resilience capability, inter-domain handoff authentication latency, and workload of the roaming broker (RB). With extensive analysis and simulation, we demonstrate that the proposed scheme can be a practical solution for achieving secure roaming and billing in metropolitan-area WMNs. Haojin Zhu, Xiaodong Lin 0001, Rongxing Lu, Pin-Han Ho, Xuemin Shen |
IEEE Trans. Wirel. Commun. | 1 |
| 2007 | Secure Localized Authentication and Billing for Wireless Mesh NetworksabstractThe future metropolitan-area wireless mesh networks (WMNs) are expected to have compromise-prone mesh access points (MAPs) with high frequency of inter-domain roaming/handoff events. To achieve security without losing efficiency, this paper introduces a novel secure localized authentication and billing (SLAB) scheme. Our scheme aims to address both security guarantee and performance in terms of system compromise resilience capability, inter-domain handoff authentication latency, and workload of the roaming broker (RB). We demonstrate that the proposed scheme can be a practical solution for achieving secure roaming and billing in metropolitan-area WMNs. Haojin Zhu, Xiaodong Lin 0001, Rongxing Lu, Pin-Han Ho, Xuemin Shen |
GLOBECOM | 1 |
| 2007 | ASRPAKE: An Anonymous Secure Routing Protocol with Authenticated Key Exchange for Wireless Ad Hoc NetworksabstractIn this paper, we present a novel anonymous secure routing protocol for mobile ad hoc networks (MANETs). The proposed protocol not only provides anonymity from all the intermediate nodes, but also integrates the authenticated key exchange mechanisms into the routing algorithm design. Furthermore, a new attack on anonymous services, called snare attack, is introduced, where a compromised node lures a very important node (VIN) into communicating with him and traces back to the VIN by following the route path. An adversary can then snare the VIN and launch decapitation strike on the VIN. Finally, we present a novel DECOY mechanism as a countermeasure to enhance anonymity of VINs and defeat snare attack. Xiaodong Lin 0001, Rongxing Lu, Haojin Zhu, Pin-Han Ho, Xuemin Shen, Zhenfu Cao |
ICC | 3 |
| 2007 | Two-Factor Localized Authentication Scheme for WLAN RoamingabstractIn the paper, we propose an efficient two-factor localized authentication scheme suitable for WLAN roaming. The proposed authentication scheme can greatly improve the security compared with the previously reported counterparts, where two independent factors, such as "what you know" and "what you have", are utilized in the authentication process for a mobile user (MO). Some important issues specific to the wireless environment are considered in the design of the scheme, such as limited computation power, memory space, and battery capacity of mobile stations (MSs), and ping-pong movement problem when roaming across WLANs. The detailed implementation of the proposed scheme is presented, where some of the key performance measures and security are analyzed. Numerical results demonstrate that the proposed scheme can significantly outperform the legacy authentication schemes in terms of signaling overhead, power consumption, and authentication latency without losing the capability of preserving the system security. Xiaodong Lin 0001, Haojin Zhu, Pin-Han Ho, Xuemin Shen |
ICC | 2 |
| 2007 | TTP Based Privacy Preserving Inter-WISP Roaming Architecture for Wireless Metropolitan Area NetworksabstractWe propose a novel inter-WISP roaming architecture based on trusted third party (TTP) and partially blind signature technique in wireless metropolitan area networks (WMAN). The proposed architecture aims to not only greatly improve user privacy and identity anonymity even in the presence of cooperation between the wireless Internet service provider (WISPs) and the TTP, but also dramatically reduce the required size of central database devised to minimize any possible service abuse. In addition, an efficient billing scheme among mobile users (MUs), WISPs and TTP, is introduced to address billing issues associated with roaming. Moreover, a localized inter-WISP authentication scheme is also proposed to support seamless handoff. Detailed analysis on a number of important performance metrics, such as computation time, handoff latency and power consumption, is conducted to verify the performance of the proposed schemes. Haojin Zhu, Xiaodong Lin 0001, Pin-Han Ho, Xuemin Shen, Minghui Shi |
WCNC | 1 |
| 2006 | A Novel Voting Mechanism for Compromised Node Revocation in Wireless Ad Hoc NetworksabstractDue to the nature of wireless ad hoc networks such as dynamic infrastructure and non-centralized management, the routing process has a huge exposure to malicious hacking and intrusions. This fact results in a likelihood of node compromise, leading to a disruption of the legitimate network functions/services. Most reported studies in coping with the problem have focused on the effort of protection on route discovery and data transmission against various attacks. In this paper, we solve the problem from a different perspective by targeting the node compromise revocation, i.e., isolating and breaking off the misbehaving nodes. To mitigate the security breaches from internal compromised nodes and eventually eliminate compromised nodes from the wireless ad hoc networks, we propose an energy efficient malicious node removal mechanism. Further, a new attack on routing service called entrap attack is introduced, where an innocent node is incriminated as a malicious node. Xiaodong Lin 0001, Haojin Zhu, Bin Lin 0001, Pin-Han Ho, Xuemin Shen |
GLOBECOM | 2 |
| 2006 | Provably secure robust threshold partial blind signature
Zhenfu Cao, Haojin Zhu, Rongxing Lu |
Sci. China Ser. F Inf. Sci. | 2 |