EDBT 2026 Demo / reviewers in the wild / expert
Chuan Zhang 0003
dblp:23/1788-3
· DBLP profile ↗
108ranked-venue papers
22as first author
91since 2021 · last 2026
0000-0001-7684-8540ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 44 · 7 first-author · 38 since 2021Security and privacy · 25 · 6 first-author · 24 since 2021Systems, architecture and hardware · 19 · 5 first-author · 16 since 2021Databases, data management, data science and information retrieval · 8 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 6 · 5 since 2021Software engineering, systems software and programming languages · 5 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | vProChain: Efficient Provenance Verification in Industrial Internet of Things (IIoT)abstractThe Industrial Internet of Things (IIoT) has been widely deployed to enable real-time monitoring and automation. Within IIoT-driven production, supply chain management plays a critical role, necessitating verifiable provenance to ensure the authenticity and traceability of goods across multi-stakeholder networks. While blockchain provides a tamper-proof foundation, traditional storage structures suffer from unsecured data integrity, poor query efficiency, and scalability over provenance data. To address these challenges, we propose vProChain, an efficient provenance verification system to support verifiable and parallel queries over graph-structured provenance data. First, we design an Adaptive DAG Verkle Tree (ADVT) that deterministically maps supply chain dependencies into a graph-native authenticated data structure, enabling constant-size proofs and low-overhead verification. Second, we introduce the Merkle Inverted Patricia Trie (MIPT) to facilitate fast, verifiable multi-dimensional Boolean queries. Third, we develop a parallel provenance query algorithm that accelerates multi-hop path retrieval via consistent hashing and weighted bipartite matching. Finally, formal security analysis and extensive empirical evaluations demonstrate that vProChain can provide provable cryptographic guarantees for the soundness of provenance proofs and the completeness of query retrievals, while achieving high query efficiency in a large-scale IIoT environment. Jiamin Deng, Zhe Peng, Chuan Zhang 0003, Shuhang Gu, Xin Xie 0001, Bin Xiao 0001 |
IEEE Internet Things J. | 3 |
| 2026 | Enabling Privacy-Preserving and Verifiable AGI in Low-Altitude Economy NetworksabstractIn low-altitude economy (LAE) networks, Artificial General Intelligence (AGI) models play a critical role in tasks such as path planning, object recognition, and task allocation. Support Vector Machine (SVM) models serve as fundamental components in AGI frameworks due to their robust capabilities in classification and regression tasks, which are essential for decision-making in LAE networks. However, distributed deployment and real-time inference of SVM models face significant challenges in security and privacy protection, including leakage of model parameters, exposure to data privacy, and reliability of prediction results. To address these issues, we propose a privacy-preserving and verifiable SVM prediction scheme (pvSVM) that can achieve the desirable properties of model privacy, data privacy, and private/public prediction verifiability. To be specific, we employ homomorphic encryption in conjunction with secret sharing to realize efficient and privacy-preserving model prediction in the edge. Then, we design two secure verification strategies to allow UAVs and any third party to check the correctness of predictions. To further support the verification of large-scale predictions, our scheme uses batch verification to reduce computational and communication overheads. Detailed analysis and extensive experiments prove the security and efficiency of our scheme. Mingtao Jiang, Chenfei Hu, Xuhao Ren, Chuan Zhang 0003, Hongchen Guo, Liehuang Zhu |
IEEE Internet Things J. | 4 |
| 2026 | Secure Dynamic and Verifiable Skyline Query for Low-Altitude EconomyabstractWith the rapid development of the low-altitude economy, skyline queries play a crucial role in identifying relevant data based on specific query requirements. To reduce storage overhead and improve query efficiency, data owners increasingly outsource their data to cloud servers. However, cloud servers may be untrusted and can potentially return incorrect or incomplete query results. Furthermore, most existing skyline query schemes do not support dynamic data updates and fail to satisfy the privacy and verifiability requirements essential for real-world low-altitude economic scenarios. In this paper, we propose a Secure Dynamic and Verifiable Skyline Query (SDVSQ) scheme, which supports dynamic and verifiable searchable encryption for skyline queries. We first devise a novel index structure, SDVR-tree, designed for efficient skyline query processing, where each data object is represented as a linked list in the leaf nodes. Each node in the linked list corresponds to a raw data object encrypted using a modified Paillier cryptosystem, ensuring that users accessing a list node cannot infer its sub-nodes. To support secure skyline computation, we design privacy-preserving protocols for squared Euclidean distance, comparison, and minimum operations. Additionally, SDVSQ ensures public verifiability of query result correctness and completeness by leveraging blockchain to store verification objects, while avoiding heavy on-chain computation. Formal security analysis shows that SDVSQ ensures forward privacy, data privacy, and query privacy while supporting result verification. Extensive experimental results demonstrate that SDVSQ significantly reduces computational overhead for both updates and skyline queries. Fuyuan Song, Chuan Zhang 0003, Zhangjie Fu 0001 |
IEEE Internet Things J. | 4 |
| 2026 | Achieving Privacy-Preserving and Communication-Efficient Federated Learning in Internet of Unmanned AgentsabstractWith the rapid advancement of ubiquitous connectivity, the Internet of Unmanned Agents (IUA) has emerged as a promising paradigm for distributed intelligent perception and decision-making. In such systems, numerous unmanned agents collaboratively collect environmental data to support coordinated tasks. To preserve data privacy, Federated Learning (FL), as a decentralized machine learning framework, enables collaborative training of a global model across agents without directly exchanging raw data. However, FL faces several critical challenges in IUA environments, including high communication overhead under constrained wireless bandwidth, potential privacy leakage from shared model parameters, and agent dropouts caused by unstable connectivity. To address these challenges, we propose PPE-FL, a privacy-preserving and communication-efficient federated learning scheme designed for IUA scenarios. PPE-FL replaces conventional high-dimensional gradient uploads with lightweight ranking-based votes, substantially reducing communication overhead. Then, we design an obfuscation mechanism to protect the privacy of locally generated ranking-based votes, safeguarding both raw data and intermediate parameters. Furthermore, PPE-FL supports mask reconstruction through partial interactions among online unmanned agents, enabling robust aggregation under dynamic network conditions. Experimental results demonstrate that the proposed PPE-FL reduces communication costs by 89.5% compared to VCD-FL and by 87.7% compared to PPML, while maintaining model accuracy and privacy protection. Yuhua Xu 0010, Chenfei Hu, Chuan Zhang 0003, Shan Fu, Nan Cheng 0001, Song Yang 0002, Liehuang Zhu |
IEEE Internet Things J. | 4 |
| 2026 | LMT-SDNN: A Lightweight Malicious Traffic Detection Method for the Internet of Things Based on Multiteacher DistillationabstractThe rapid proliferation of Internet of Things (IoT) devices, coupled with their inherent security vulnerabilities, has significantly expanded the attack surface, intensifying threats such as man-in-the-middle attacks, traffic hijacking, and distributed denial-of-service (DDoS) attacks, thereby posing serious risks to the security and reliability of the entire ecosystem. The network traffic associated with IoT devices is diverse and dynamic, often exhibiting complex structural features such as periodic fluctuations, varying packet sizes, and time-varying patterns that make detection challenging. Although deep learning has demonstrated strong capabilities in efficiently identifying complex and dynamic malicious traffic through powerful feature extraction and adaptive learning abilities, its high model complexity, substantial computational demands, and large parameter sizes hinder direct deployment on resource-constrained IoT devices. In order to tackle this issue, this paper proposes a malicious traffic detection framework for the Internet of Things (IoT) based on multi-teacher knowledge distillation. The proposed model, termed the Lightweight Multi-Teacher Spatiotemporal Distillation Neural Network (LMT-SDNN), employs two high-performance teacher models: Residual Inception and a One-Dimension Convolution Netural Network (1D-CNN) integrated with idirectional Long Short-Term Memory (BiLSTM), to effectively capture the complex structural features of network traffic. Furthermore, a novel Time-Related Window Loss (TRW) function is design to enhance the student’s ability to capture temporal features, thereby improving its overall performance. The effectiveness of LMT-SDNN is validated through comparisons with five baseline models on two publicly available datasets, ToN_IoT and BoT_IoT. Experimental results show that LMT-SDNN achieves a compression rate of over 99% in both model complexity and parameter count, while maintaining an accuracy exceeding 99%, indicating its strong potential for multiclass malicious traffic detection in IoT environments. Yunfang Liang, Chunhai Li, Chuan Zhang 0003, Liehuang Zhu, Jian Zhao 0006 |
IEEE Internet Things J. | 5 |
| 2026 | Entropy-aware dynamic bias watermarking for LLM-generated emotional contentabstractThe application of large language models(LLMs) in affective computing-ranging from empathetic chatbots to creative writing-has intensified the demand for distinguishing and authenticating AI-generated emotional content. Watermarking, by embedding detectable signals into the outputs of language models, offers a promising solution. However, a critical challenge persists: emotional texts often exhibit low entropy or complex spiky entropy distributions, which severely undermine the performance of existing watermarking methods. Unlike prior works that primarily treated spiky entropy as an external metric, we focus specifically on its role within the text generation process itself. To address the challenges of watermarking under low-entropy and complex entropy distributions, we propose DBW (Dynamic Bias Watermarking)-an entropy-aware watermarking algorithm for LLMs. DBW dynamically adjusts the watermarking bias in real time based on the entropy of each token. This innovation ensures a stronger watermark signal (increased green token count) in high-entropy contexts, while minimizing interference and quality degradation in fragile low-entropy emotional segments. Experimental results demonstrate that the proposed DBW algorithm outperforms the KGW watermarking method in both complex entropy distribution and low-entropy text generation scenarios. DBW achieves higher detection accuracy without sacrificing text quality. Furthermore, comparative experiments show that our proposed DBW algorithm demonstrates superior robustness under different attacks. Our work provides a reliable and adaptive tool for safeguarding emotion-AI generated content, contributing to the secure and trustworthy deployment of large-scale pre-trained models in affective computing. Xuyang Dong, Chunhai Li, Baokun Zheng, Chuan Zhang 0003, Liehuang Zhu |
Pattern Recognit. | 5 |
| 2026 | Joint Trajectory and Power Optimization for Dynamic Spectrum Control-Assisted Secure UAV CommunicationsabstractUnmanned aerial vehicles (UAVs) play a crucial role in modern communication systems owing to their high mobility and broad coverage. However, due to the inherent open nature of the wireless channels, UAV-to-ground links are facing significant security threats from eavesdroppers and malicious jammers. To address these challenges, we propose a dynamic spectrum control (DSC) scheme integrating joint UAV trajectory and transmit power optimization to enhance UAV communication security in this paper. This scheme divides transmission channels from time and frequency dimensions and intelligently generates secure decision sequences using cryptographic principles based on real-time channel states, enabling transmissions for legitimate users without intra-cell interference. Based on a rapid-flooding time synchronization protocol, we analyze inter-cell collision probability (CP) and formulate an optimization problem for the secrecy rate. To further enhance security, we conduct a joint UAV trajectory and transmit power optimization. Through the successive convex approximation (SCA) method, we transform the non-convex optimization problem into a tractable convex form, obtaining a suboptimal solution. Simulations demonstrate that our proposed scheme significantly enhances security compared to conventional UAV communication methods. Pu Cao, Zan Li 0001, Haixia Peng, Chuan Zhang 0003 |
IEEE Trans. Commun. | 6 |
| 2026 | Epass: Efficient and Privacy-Preserving Asynchronous Payment on BlockchainabstractBuy Now Pay Later (BNPL) is a rapidly proliferating e-commerce model, offering consumers to get the product immediately and defer payments. Meanwhile, emerging blockchain technologies endow BNPL platforms with digital currency transactions, allowing BNPL platforms to integrate with digital wallets. However, the transparency of transactions causes critical privacy concerns because malicious participants may derive consumers' financial statuses from on-chain asynchronous payments. Furthermore, the newly created transactions for deferred payments introduce additional time overhead, which weakens the scalability of BNPL services. To address these issues, we propose an efficient and privacy-preserving blockchain-based asynchronous payment scheme (Epass), which has promising scalability while protecting the privacy of on-chain consumer transactions. Specifically, Epass leverages locally verifiable signatures to guarantee the privacy of consumer transactions against malicious acts. Then, a privacy-preserving asynchronous payment protocol is further constructed by leveraging time-release encryption to control trapdoors of the redactable blockchain, reducing time overhead by modifying transactions for deferred payment. We give formal definitions and security models, generic structures, and formal proofs for Epass. Extensive comparisons and experimental analysis show that Epass achieves KB-level communication costs, and reduces time overhead by more than four times in comparisons with locally verifiable signatures and Go-Ethereum private test networks. Weijie Wang 0018, Jinwen Liang, Chuan Zhang 0003, Ximeng Liu, Liehuang Zhu, Song Guo 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Boosting Adversarial Transferability of Vision TransformersabstractVision Transformers (ViTs) have emerged as a dominant backbone architecture for a variety of visual tasks; however, their vulnerability to adversarial examples continues to pose a significant challenge. Unlike Convolutional Neural Networks (CNNs), ViTs fundamentally rely on self-attention mechanisms, leading to a distinct architectural design. The limited transferability of existing adversarial attacks on ViTs can be attributed to the neglect of these unique features. To address this, we introduce a novel self-attention-oriented Adversarial Block Skip (ABS) method specifically designed to generate transferable adversarial examples. ABS aims to create a diverse range of structures by applying skip connections to blocks within the transformer encoder, thereby activating the uncertainty of the attention mechanism. This disrupts the global interaction between different features captured by ViTs, thereby confounding the model's decision-making process. The results unequivocally demonstrate that the ABS not only establishes a versatile and efficacious attack mechanism but also supports transfer attacks across a diverse array of ViTs and CNNs. This finding emphasizes the significant generalization capabilities of ViTs within the adversarial landscape, suggesting that their resilience and adaptability under such conditions may surpass previous assumptions. Comprehensive empirical evaluations involving various prominent transformer models on the ImageNet dataset substantiate that ABS markedly surpasses existing baseline methods in terms of effectiveness. Furthermore, ABS is highly compatible with prevailing adversarial attack frameworks, augmenting their efficacy upon integration. Such versatility renders ABS an indispensable component of the toolkit for executing advanced and effective adversarial attacks in the realm of machine learning security. Chuan Zhang 0003, Huipeng Zhou, Zuobin Ying, Zehui Xiong, Wanlei Zhou 0001, Liehuang Zhu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | A Decentralized Blockchain Transaction Verification Scheme in the Weighted SettingabstractBlockchain transaction verification is fundamental to decentralized financial applications, ensuring both transaction authorization and integrity. Most existing verification schemes utilize an equal weight model that grants identical rights to all participants. However, these schemes fail to capture real-world scenarios like Proof-of-Stake blockchains, where participants have right discrepancies. Additionally, many schemes depend on trusted third parties for key generation, introducing single points of failure and compromising security. To address these limitations, we propose WBlock that is a weighted and decentralized verification scheme. WBlock involves a distributed key generation protocol that embeds each entity's weight into its secret share, eliminating the need for trusted third parties. It further employs a Schnorr-type weighted threshold signing protocol, enabling distributed transaction authorization while reflecting participant weight in signature shares. Security analysis shows that WBlock achieves both correctness and unforgeability. Comparative theoretical analysis shows that our key generation and signing protocols outperform existing methods in terms of round complexity, communication overhead and data size. Experimental results confirm that WBlock achieves a balance between security and efficiency, with acceptable overhead for real-world blockchain deployment. Yumeng Xie, Tong Wu 0011, Cong Zuo 0001, Weixiao Wang, Chuan Zhang 0003, Liehuang Zhu |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2026 | $\mathsf {Trident}$Trident: A Secure Framework for Flexible Artificial Intelligence Model Lifecycle Management in Public CloudsabstractThe growing demand for computing power drives more artificial intelligence (AI) model owners to outsource their models to public clouds, relying on cloud servers to manage which users can use, train, or upgrade AI models. Unfortunately, existing work cannot simultaneously manage the entire model lifecycle in public clouds when considering model stealing attacks, where cloud servers covertly replicate AI models and deliver AI services to unauthorized users for profit. As a result, model owners are forced to conduct training and upgrades in private environments before deploying models to clouds for service delivery, which poses significant challenges in collaboration and maintenance, particularly for models requiring frequent upgrades. In this paper, we introduce$\mathsf {Trident}$, the first secure cloud-based framework for flexible AI model lifecycle management, including availability, trainability, and upgradability. By leveraging multiple cryptographic techniques, such as access control trees,$\mathsf {Trident}$ensures that AI models and their management policies are tightly coupled, compelling cloud servers to execute only specified model operations without violating management policies, thereby resisting model stealing attacks. Rather than straightforward cryptographic applications, we address a series of technical challenges, including shifting the focus of access control trees from data to model management and maintaining downward-compatible model management rights. We propose two detailed constructions: Semi-$\mathsf {Trident}$and Full-$\mathsf {Trident}$, tailored for semi-delegation and full-delegation scenarios, i.e., whether model owners need to interact with cloud servers while delivering AI services. Theoretical complexity analysis and security analysis prove the competitive efficiency and security. Experimental results show that compared to assembling existing partial-function schemes, Semi-$\mathsf {Trident}$and Full-$\mathsf {Trident}$achieve around$3.6\times$improvement in time costs and$5\times$improvement in communication overhead. Mingyang Zhao 0002, Zekai Yu, Chuan Zhang 0003, Song Guo 0001, Bin Xiao 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | Garland: Graph Neural Network-Based Federated Recommendation With Malicious Security via Secret-Shared ShuffleabstractRecommendation systems based on graph neural networks (GNNs) have emerged as a promising paradigm due to their ability to capture high-order interactions between users and items. However, in federated scenarios, this advantage is compromised, as each user can access only a first-order subgraph composed of its directly interacted items. To address this issue, most existing solutions introduce a trusted server to assist users in expanding their local subgraphs. However, the server in reality is often untrusted and may deviate from the protocol for its own improper benefit. Furthermore, these solutions primarily focus on the privacy of items while neglecting the privacy of potential relationships between users. To this end, we propose Garland, a GNN-based federated recommendation scheme with malicious security. Garland departs from existing work by ensuring both item and relationship privacy while supporting integrity checks to defend against malicious servers. Specifically, we employ a trending cryptographic primitive of secret-shared shuffle to expand subgraphs in a privacy-preserving and verifiable manner. We also design a pre-shuffle triple-salt encryption mechanism and a post-shuffle user-governed expansion mechanism to reduce communication costs and achieve secure distribution of neighbor information, respectively. Moreover, we develop a secret-shared aggregation mechanism to enable privacy-preserving and verifiable federated training. Theoretical analysis demonstrates the privacy and integrity of Garland. Extensive experimental evaluations on four datasets show that Garland outperforms state-of-the-art solutions. Chenfei Hu, Chuan Zhang 0003, Ruichen Zhang 0001, Dusit Niyato, Liehuang Zhu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2026 | Secure and Customized Data Sharing With Identical Sub-Policy and Bilateral Access Control
Fuyuan Song, Chuan Zhang 0003, Zhangjie Fu 0001, Meng Li 0006, Zheng Qin 0001, Liehuang Zhu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | Scriptless Atomic Swap With Batch Processing
Menghao Wang, Mengxuan Liu, Meng Li 0006, Chuan Zhang 0003, Licheng Wang 0004, Liehuang Zhu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2026 | PODS: Efficient and Secure Identity-Based Hierarchical Data Processing Control in Mobile Cloud StorageabstractNowadays, mobile cloud storage has become increasingly prevalent for processing mobile data due to its convenience and resources. Towards the right to restriction of processing in current data regulations, some solutions have been proposed to empower data owners with identity-based hierarchical control for equality, comparison, and plaintext analytics operations. However, existing solutions either rely on specific hardware environments (i.e., trusted execution environments) or face two significant issues: identity privacy breaches, where attackers can identify targeted users, and excessive overhead in multi-user scenarios, as each user requires a distinct ciphertext. In this paper, we leverage multiple cryptographic primitives to introduce PODS, an efficient and secure hierarchical data processing control scheme for multi-user mobile cloud storage. PODS allows the data owner to generate a single ciphertext for multiple users without hardware reliance. Technically, we reconstruct identity-based encryption by leveraging well-designed common and private parameters, thereby shifting the focus from data itself to data processing operations. Then, we encode multiple targeted identities as polynomial coefficients and integrate these coefficients into identity-based data processing control. We achieve threefold benefits, effectively reducing overhead, hierarchically processing users' rights, and concealing the identities of targeted users to protect privacy. Security analysis proves the security of PODS. Experiments demonstrate that PODS achieves around$8\times$and$37\times$improvement in computation and communication compared to existing related works. Mingyang Zhao 0002, Zhuoyu Sun, Chuan Zhang 0003, Liehuang Zhu, Song Guo 0001, Bin Xiao 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2025 | Onion Encryption Revisited: Relations Among Security Notions
Daichong Chao, Liehuang Zhu, Tong Wu 0011, Chuan Zhang 0003, Fuchun Guo |
Inscrypt (1) | 5 |
| 2025 | Energy Efficient Trajectory Control and Resource Allocation in Multi-UAV-assisted MEC via Deep Reinforcement LearningabstractMobile edge computing (MEC) is a promising technique to improve the computational capacity of smart devices (SDs) in Internet of Things (IoT). However, the performance of MEC is restricted due to its fixed location and limited service scope. Hence, we investigate an unmanned aerial vehicle (UAV)assisted MEC system, where multiple UAVs are dispatched and each UAV can simultaneously provide computing service for multiple SDs. To improve the performance of system, we formulated a UAV-based trajectory control and resource allocation multi-objective optimization problem (TCRAMOP) to simultaneously maximize the offloading number of UAVs and minimize total offloading delay and total energy consumption of UAVs by optimizing the flight paths of UAVs as well as the computing resource allocated to served SDs. Then, consider that the solution of TCRAMOP requires continuous decision-making and the system is dynamic, we propose an enhanced deep reinforcement learning (DRL) algorithm, namely, distributed proximal policy optimization with imitation learning (DPPOIL). This algorithm incorporates the generative adversarial imitation learning technique to improve the policy performance. Simulation results demonstrate the effectiveness of our proposed DPPOIL and prove that the learned strategy of DPPOIL is better compared with other baseline methods. Saichao Liu, Geng Sun 0001, Chuan Zhang 0003, Xuejie Liu, Jiacheng Wang 0001, Changyuan Zhao, Dusit Niyato |
GLOBECOM | 3 |
| 2025 | Dynamic Spectrum Control Transmission Scheme Based on Chaotic Mapping Switching for Satellite Covert CommunicationabstractSatellite communication has shown great potential for providing ubiquitous connectivity and broadband mobile communications, owing to its advantages of wide coverage, large system capacity, and high transmission rate. However, the increasing complexity of the electromagnetic scenarios poses an unprecedented threat to the security and reliability of satellite covert communication. In this paper, a dynamic spectrum control (DSC) transmission scheme for enhancing the covertness of satellite communications is proposed. The scheme generates a sequence family based on chaotic mapping, controls data decisions and switching processing. With the assistance of this sequence family, the authorized satellite user can unpredictably and dynamically occupy frequency slots for transmitting information. Then, the closed-form expressions of Bit Error Rate (BER) and detection probability is derived. Numerical results demonstrate that the proposed scheme outperforms the benchmark scheme in terms of the overall system performance. Besides, the influences of key parameters in the proposed scheme on the covertness of the system are further analyzed. Yujie Ling, Zan Li 0001, Chuan Zhang 0003, Wenting Wei |
ICC | 4 |
| 2025 | MDDM: Practical Message-Driven Generative Image Steganography Based on Diffusion ModelsabstractGenerative image steganography (GIS) is an emerging technique that conceals secret messages in the generation of images. Compared to GAN-based or flow-based GIS schemes, diffusion model-based solutions can provide high-quality and more diverse images, thus receiving considerable attention recently. However, previous GIS schemes still face challenges in terms of extraction accuracy, controllability, and practicality. To address the above issues, this paper proposes a practical message-driven GIS framework based on diffusion models, called MDDM. Specifically, by utilizing the Cardan grille, we encode messages into Gaussian noise, which serves as the initial input for image generation, enabling users to generate diverse images via controllable prompts without additional training. During the information extraction process, receivers only need to use the pre-shared Cardan grille to perform diffusion inversion and recover the messages without requiring the image generation seeds or prompts. Experimental results demonstrate that MDDM offers notable advantages in terms of accuracy, controllability, practicality, and security. With flexible strategies, MDDM can achieve accuracy close to 100\% under appropriate settings. Additionally, MDDM demonstrates certain robustness and potential for application in watermarking tasks. Chuan Zhang 0003 |
ICML | 4 |
| 2025 | Spatiotemporal Feature Enhancement Adversarial Attack for Multivariate Time Series PredictionabstractThe rise of multivariate time series (MTS) data has made prediction crucial, with deep learning models dominant yet vulnerable to adversarial attacks. These attacks use small perturbations on inputs to cause mispredictions. MTS data's inherent complexity and sensitivity demand stringent perturbation handling. To address this, we propose TFCA, an adversarial attack method focusing on feature dimension impact. TFCA calculates each feature's gradient contribution to predictions independently, establishing a feature importance ranking. It enhances temporal characteristics by integrating multi-dimensional elements (e.g., volatility, cosine direction) to constrain adversarial sample realism. Guided by this ranking, TFCA targets specific attack ratios on subsets of the time series, ensuring attack effectiveness while reducing perturbation size and improving stealthiness. Experiments on real MTS datasets against models (TCN, LSTNet, CNN) demonstrate TFCA's effectiveness, stealthiness, applicability, and transferability. The integration of post hoc explainable AI algorithms also provides interpretability. This research offers insights for enhancing MTS model robustness and security in practice. Zhenzhong Zhu, Chunhai Li, Yong Ding 0005, Chuan Zhang 0003 |
ICPADS | 5 |
| 2025 | ChainAttack: Black-Box Adversarial Attacks on Generative AI Services via Chain-of-ThoughtabstractThe advancement of large language models (LLMs) has made generative AI services an indispensable component of modern web applications, offering powerful capabilities through API-based interactions. However, the black-box nature of these services, where users lack access to internal mechanisms such as training or fine-tuning processes, poses significant challenges for adversarial attack research. Traditional attack methods typically require access to model parameters or gradients, which is impractical in real-world scenarios. In this paper, we introduce ChainAttack, a black-box adversarial method that exploits LLMs' incontext learning by crafting Chain-of-Thought (CoT) adversarial prompts. This method manipulates intermediate reasoning steps to elicit harmful outputs without requiring access to model internals. Our evaluation across six benchmarks demonstrates that ChainAttack achieves a 34.4% success rate, particularly excelling in logic-intensive tasks such as mathematical problem solving. This work exposes critical vulnerabilities in CoT prompting and underscores the need for future research on building more robust and trustworthy generative AI systems. Xixi Zheng, Xuhao Ren, Chuan Zhang 0003, Liehuang Zhu |
ICWS | 4 |
| 2025 | SecPoS: Slashable Proof-of-Stake Consensus with Low Transaction Delays and Checkpoint CostsabstractNowadays, checkpoints have been proven to be an effective solution to ensure slashability in proof-of-stake (PoS) consensus, and Tas et al.'s cutting-edge solution in S&P 2023 is a typical example. Unfortunately, despite progress, hour-level transaction delays and annually around 10 K dollar checkpoint costs make existing related solutions still unacceptable in realworld PoS applications. In this paper, we propose SecPoS, a slashable PoS consensus with second-level transaction delays and one-time checkpoint costs. To achieve these design goals, we draw inspiration from Pixel+ signatures and chameleon hash functions to design a novel bilateral blockchain structure, achieving twoblock transaction finalization via only uploading the first block of our chain as checkpoints. Next, considering practical application requirements, we address a series of following challenges, such as bilateral immutability, blockchain forks, determination of the main chain, and malicious attacks from PoS members. In detail, we propose two constructions of SecPoS, i.e., SecPoS – A and SecPoS – B. SecPoS – A and SecPoS – B have a tradeoff between transaction delays and block numbers packed in an epoch. Compatible with most existing one-way blockchains, we implement and outsource a prototype SecPoS to facilitate research11https://github.com/Academic-Paper-Codes/SecPoS-Consensus, and prove the security of SecPoS. Experiments on this prototype show that SecPoS – A and SecPoS – B require around 5s and 100s transaction delays, respectively, and both require 2 dollars one-time checkpoint costs. Chuan Zhang 0003, Zekai Yu, Zhe Peng, Mingyang Zhao 0002, Liehuang Zhu, Bin Xiao 0001 |
IWQoS | 1 |
| 2025 | Federated Rank Learning with Dimensionality Reduction and Clustering for Electricity Load Forecasting
Yuchong Liu, Jianchao Zheng, Chuan Zhang 0003, Liehuang Zhu |
KSEM (5) | 6 |
| 2025 | Privacy-Preserving Shortest Path Queries on Encrypted Attributed IIoT Graphs
Weixiao Wang, Chuan Zhang 0003, Liehuang Zhu |
KSEM (3) | 4 |
| 2025 | SepVAMark: Deep Separable Visual-Audio Fusion Watermarking for Source Tracing and Deepfake DetectionabstractVisual-audio Deepfake has become increasingly prevalent in today's online environment. Passive detection methods, lacking preventive measures, struggle with detecting unknown forgery techniques, limiting their effectiveness. While proactive detection methods offer greater robustness, unimodal watermarking approaches remain vulnerable in visual-audio Deepfake scenarios, posing challenges to reliable forensics. To address these challenges, we propose a novel Separable Visual-Audio waterMark framework, called SepVAMark, for proactive Deepfake detection. SepVAMark incorporates a multi-layer perceptron-based mixer layer to fuse intra-modality and inter-modality features from both audio and visual data. We introduce the concept of separable visual-audio watermark, along with a bimodal robust extractor for traceability and two unimodal semi-robust extractors for Deepfake detection. This design ensures reliable copyright protection for source audio-video content while enabling authenticity verification for redistributed content. Experimental results on the FakeAVCeleb dataset demonstrate that SepVAMark effectively detects a wide range of advanced Deepfake manipulations, outperforming existing single-modal and multi-modal watermarking methods with superior robustness. Chuan Zhang 0003, Xuhao Ren, Liehuang Zhu |
ACM Multimedia | 1 |
| 2025 | Privacy-Preserving and Control-Compliant Authenticated Access for the AI-Enabled Industrial Internet of ThingsabstractArtificial intelligence (AI) revolutionizes the productivity model and efficiency of the Industrial Internet of Things (IIoT). As a derivative of the AI era, AI-enabled IIoT drives frequent data access and intelligent industrial productivity. However, the rise of intelligence brings more sophisticated and hard-to-defend attacks against IIoT systems, such as deep identity forgery and malicious access, posing a major threat to intelligent development. Password-based Authenticated Key Agreement (AKA) is an effective cryptographic method for access security in IIoT, but current AKA schemes cannot address balancing between security, functionality and efficiency in the smart setting. To fill this gap, we propose a new password-based AKA scheme, where oblivious pseudorandom function, hash function and encryption are utilized to realize anonymous identity authentication. Considering malicious data access, we design a new token-tag mechanism with identity information to realize malicious identity tracing. In addition, our scheme supports a fast login function, helping the authorized party access data without repeating key agreements. Furthermore, formal security proofs and heuristic analyses demonstrate that our scheme is secure under multiple attacks. Finally, we compare the proposed scheme with the related schemes, and the results show that our scheme achieves the balance between safety, function and efficiency. Yumeng Xie, Zhitao Guan, Yongshuang Wei, Chuan Zhang 0003, Liehuang Zhu |
TrustCom | 6 |
| 2025 | Parallelizing Universal Atomic Swaps for Multi-Chain Cryptocurrency Exchanges
Danlei Xiao, Chuan Zhang 0003, Jinwen Liang, Licheng Wang 0004, Liehuang Zhu |
USENIX Security Symposium | 2 |
| 2025 | Securing Data Privacy in NIDS: Black-Box Adversarial Attacks
Yunfang Liang, Yunfan Yang, Baokun Zheng, Chuan Zhang 0003, Liehuang Zhu |
Int. J. Intell. Syst. | 6 |
| 2025 | Federated Capsule Graph Neural Networks With Enhanced Privacy ProtectionabstractFederated learning (FL) has gained significant traction as a paradigm for decentralized learning, enabling multiple clients to collaboratively train models without sharing their local data. However, applying FL to graph-structured data introduces unique challenges, such as handling non-IID data and preserving the structural dependencies between nodes. Additionally, existing approaches to federated learning with Graph Neural Networks (GNNs) often struggle to capture complex relationships within graph data and are vulnerable to privacy breaches, including membership inference and model inversion attacks. In this paper, we propose Federated Capsule Graph Neural Networks (FCGNN), a novel architecture that integrates the dynamic routing capabilities of capsule networks with the structure-preserving power of GNNs in a federated setting. FCGNN is designed to effectively model hierarchical and part-whole relationships within graph data, enabling it to outperform traditional federated GNN approaches. We enhance the privacy of FCGNN by incorporating differential privacy and secure aggregation techniques, ensuring that individual client updates remain confidential while maintaining strong model performance. We evaluate FCGNN on several benchmark graph datasets, including Cora, Citeseer, PubMed, and PROTEINS, and demonstrate that it consistently achieves higher accuracy and F1-scores compared to existing FL methods. Our experiments show that FCGNN converges faster and incurs lower communication costs, making it highly efficient for real-world FL applications. Furthermore, FCGNN is robust across different numbers of participating clients, maintaining high performance even in non-IID scenarios. These results highlight the potential of FCGNN as a scalable and privacy-preserving solution for decentralized learning on graph-structured data. Wennan Wang, Zijie Pan, Tuli Chen, Fu Luo, Chuan Zhang 0003 |
IEEE Internet Things J. | 7 |
| 2025 | Large Language Model-Driven Security Assistant for Internet of Things via Chain-of-ThoughtabstractThe rapid development of Internet of Things (IoT) technology has transformed people’s way of life and has a profound impact on both production and daily activities. However, with the rapid advancement of IoT technology, the security of IoT devices has become an unavoidable issue in both research and applications. Although some efforts have been made to detect or mitigate IoT security vulnerabilities, they often struggle to adapt to the complexity of IoT environments, especially when dealing with dynamic security scenarios. How to automatically, efficiently, and accurately understand these vulnerabilities remains a challenge. To address this, we propose an IoT security assistant driven by a Large Language Model (LLM), which, through the ICoT process, enhances the LLM’s understanding of IoT security vulnerabilities and related threats. The ICoT method we propose aims to enable the LLM to understand security issues by breaking down the various dimensions of security vulnerabilities and generating responses tailored to the user’s specific needs and expertise level. By incorporating ICoT, LLM can gradually analyze and reason through complex security scenarios, resulting in more accurate, in-depth, and personalized security recommendations and solutions. Experimental results show that, compared to methods relying solely on LLMs, our proposed LLM-driven IoT security assistant significantly improves the understanding of IoT security issues and provides personalized solutions based on user identity through the ICoT approach. From the evaluator’s perspective, it performs better across five dimensions. Mingfei Zeng, Xixi Zheng, Chunhai Li, Chuan Zhang 0003, Liehuang Zhu |
IEEE Internet Things J. | 5 |
| 2025 | P 2 FedRec: Towards Privacy-Preserving and Personalized Federated Recommendation via Relationship AwarenessabstractPersonalized federated recommendation systems can not only extract common prior knowledge from extensive decentralized data but also provide personalized models for different users to achieve independent and customized services. Incorporating user relationship graphs to enhance personalized modeling is highly promising in federated recommendation. However, it is challenging to construct such graphs and further capture personalized user information while guaranteeing multi-level (i.e., data-level and edge-level) privacy in reality. To this end, in this paper, we propose P 2 FedRec, a relationship-aware P rivacy-preserving and P ersonalized Fed erated Rec ommendation scheme, which can achieve multi-level privacy protection with personalized modeling guarantees. Specifically, we first develop a user-server collaborative mechanism for relationship graph generation and user-specific preferences capture in a privacy-preserving manner. Then, we design an embedding-shared local graph construction module and a noisy global graph-guided aggregation module to safeguard the data-level and edge-level privacy, respectively. Moreover, we introduce a personalized model training module that enables users to learn tailored local models. Theoretical analysis demonstrates that P 2 FedRec achieves both data-level and edge-level privacy preservation on the user and server sides. Extensive experiments conducted on five real-world datasets highlight the outstanding performance of P 2 FedRec. Chenfei Hu, Tong Wu 0011, Chuan Zhang 0003, Liehuang Zhu |
Proc. ACM Manag. Data | 5 |
| 2025 | EC2P: Cost-Effective Cross-Chain Payments via Hubs Resisting the Abort AttackabstractCross-chain technology facilitates the interoperability among isolated blockchains, where users can transfer and exchange coins. While the heterogeneity between Turing-complete (TC) blockchains like Ethereum and non-Turing-complete (NTC) blockchains like Bitcoin presents a significant challenge for cross-chain transactions. Payment Channel Hubs (PCHs) offer a promising solution for enabling TC-NTC cross-chain payments with high throughput and low confirmation delays. However, existing schemes still face two key challenges: (i) significant computation and communication overhead for variable-amount payment, and (ii) limited unlinkability, i.e., vulnerable to the abort attack. This paper proposes EC2P, the first TC-NTC cross-chain PCH that achieves variable-amount payment unlinkability while resisting the abort attack and minimizing reliance on non-interactive zero-knowledge (NIZK) proofs. EC2P introduces two protocols: the NTC-to-TC and TC-to-NTC payment protocols. The NTC-to-TC payment protocol replaces the traditional puzzle-promise and puzzle-solve paradigm with a semi-blind approach, where only one side is blinded and the blinded side’s interactions are eliminated. This achieves unlinkability and resists the abort attack without NIZK. The TC-to-NTC payment protocol enhances the paradigm by utilizing Turing-complete functionality to constrain the inability to carry out an abort attack. Through rigorous security analysis, we show that EC2P is secure and variable-amount payment unlinkable while resisting the abort attack. We implement EC2P on Ethereum and Bitcoin test networks. Our evaluation demonstrates that EC2P outperforms both in terms of communication and computation overhead and reduces communication costs by 3 orders of magnitude compared to existing variable-amount methods. Danlei Xiao, Shaobo Xu, Chuan Zhang 0003, Licheng Wang 0004, Xiulong Liu 0001, Liehuang Zhu |
IEEE Trans. Computers | 3 |
| 2025 | Forward-Secure Multi-User Graph Searchable Encryption for Exact Shortest Path Queries
Weixiao Wang, Chuan Zhang 0003, Cong Zuo 0001, Liehuang Zhu |
IEEE Trans. Cloud Comput. | 3 |
| 2025 | SecPQ: Secure Prediction Queries on Encrypted Outsourced DatabasesabstractPrediction queries have revolutionized data search by integrating machine learning models and traditional data processing operations for advanced analytics. However, existing prediction query frameworks for outsourced databases face a critical security vulnerability: data flows are processed in plaintext on semi-honest servers, making them susceptible to data breaches. The main challenge in achieving secure prediction queries is that machine learning inference and data processing operations are distinct functionalities, while most current cryptographic frameworks support only a single type of operation on specific encrypted data. To bridge this crucial gap, we propose$\mathsf {SecPQ}$, the first framework tailored for secure prediction queries. Our approach unifies decision tree pipelines and data processing operations, such as selection, projection, and equality-joining, through equality matching on encrypted outsourced data. This enables the design of secure prediction queries with decision tree pipelines operating on encrypted data. We provide formal security definitions and proofs for$\mathsf {SecPQ}$. To further optimize the efficiency of secure prediction queries, we leverage order-preserving encryption to construct$\mathsf {SecPQ}_{{{ope}}}$, which offers improved query efficiency at the expense of weaker security properties compared with$\mathsf {SecPQ}$. Extensive experimental evaluations on billions of records demonstrate the feasibility and effectiveness of both$\mathsf {SecPQ}$and$\mathsf {SecPQ}_{{{ope}}}$. Jinwen Liang, Song Guo 0001, Zicong Hong, Enyuan Zhou, Chuan Zhang 0003, Bin Xiao 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | BESA: Boosting Encoder Stealing Attack With Perturbation RecoveryabstractTo boost the encoder stealing attack under the perturbation-based defense that hinders the attack performance, we propose a boosting encoder stealing attack with perturbation recovery named BESA. It aims to overcome perturbation-based defenses. The core of BESA consists of two modules: perturbation detection and perturbation recovery, which can be combined with canonical encoder stealing attacks. The perturbation detection module utilizes the feature vectors obtained from the target encoder to infer the defense mechanism employed by the service provider. Once the defense mechanism is detected, the perturbation recovery module leverages the well-designed generative model to restore a clean feature vector from the perturbed one. Through extensive evaluations based on various datasets, we demonstrate that BESA significantly enhances the surrogate encoder accuracy of existing encoder stealing attacks by up to 24.63% when facing state-of-the-art defenses and combinations of multiple defenses. Xuhao Ren, Haotian Liang, Chuan Zhang 0003, Zehui Xiong, Liehuang Zhu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Feature-Based Machine Unlearning for Vertical Federated Learning in IoT NetworksabstractIn the era of the Internet of Things (IoT), managing the deluge of data generated by distributed devices presents unique challenges, particularly concerning privacy and the efficient use of computational resources. Vertical Federated Learning (VFL) offers a promising avenue for collaborative machine learning without centralizing data, thereby addressing privacy concerns inherent in traditional approaches. However, as data privacy laws and personal data deletion requests become more prevalent, the necessity for effective machine unlearning strategies within VFL frameworks grows increasingly important. To this end, this paper introduces a novel approach to feature-based machine unlearning tailored specifically for VFL systems in IoT networks. Our methodology enables the selective removal of data influence from trained models without the need for full retraining, thus preserving model utility while ensuring compliance with privacy requirements. By integrating a combination of feature relevance measuring techniques and efficient communication protocols, our solution minimizes the data footprint on network nodes, reduces bandwidth consumption, and maintains the integrity and performance of the learning models. To the best of our knowledge, our proposed framework represents the first practical approach to enable machine unlearning within vertical federated learning environments. We demonstrate the effectiveness of our approach through rigorous evaluation using several IoT datasets, highlighting significant improvements in unlearning efficiency and model robustness compared to existing techniques. Our work not only furthers the development of sustainable and compliant machine learning models in IoT but also sets a foundational framework for future research in secure and efficient data management within federated environments. Zijie Pan, Zuobin Ying, Chuan Zhang 0003, Weiting Zhang, Wanlei Zhou 0001, Liehuang Zhu |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | High-Dimensional and Secure Spatial Keyword Query With Arbitrary Ranges in Mobile CloudabstractSpatial keyword query has emerged as a critical service in mobile cloud, enabling cloud servers to retrieve spatiotextual objects within a mobile user's query range that contain specified query keywords. Numerous secure spatial keyword query schemes have been developed to enable geometric range queries and keyword searches on encrypted spatial data. However, spatial keyword queries are typically designed for searching high-dimensional spatial data across arbitrary geographic ranges. Most of them fail to handle arbitrary geometric range queries and efficient spatial keyword query over high-dimensional encrypted data. To address these issues, we propose a high-dimEnsional and Privacy-preserving Spatial Keyword Query (EPSKQ) scheme with arbitrary geometric ranges over encrypted spatial data, leveraging Hilbert curve encoding and Enhanced Matrix-based Inner Product Encryption (EMIPE). In EPSKQ, spatial locations and multi-keywords are encoded into compact vectors, and arbitrary geometric range queries are transformed into range intersection tests. To reduce computational overhead, we employ vector bucketing technique to partition large-size vectors into several small-size sub-vectors. Furthermore, we design a novel index structure called Hilbert Binary tree (HB-tree) to optimize range intersection tests. Based on HB-tree, we propose an enhanced spatial keyword query scheme, named EPSKQ+, which further improves query performance. Security analysis demonstrates that both EPSKQ and EPSKQ+ achieve semantic security against indistinguishability under chosen-plaintext attack (INDCPA). Extensive experimental evaluations show that the proposed EPSKQ and EPSKQ+ schemes significantly outperform state-ofthe-art schemes in terms of computational and communication costs, with EPSKQ+ being 9× and 3× faster than the state-ofthe-art schemes in the index build and query phase, respectively Fuyuan Song, Mingyang Zhao 0002, Chuan Zhang 0003, Zheng Qin 0001, Bin Xiao 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | Energy Efficiency Optimization for UAV-Assisted Cellular Networks: A Periodic Clustering-Based MATD3 ApproachabstractWith the advancement of unmanned aerial vehicles (UAVs) technology, UAV-assisted cellular networks (UACNs) have emerged as a new communication paradigm aimed at enhancing the coverage and capacity of ground networks. Unfortunately, the limited energy capacity of UAVs significantly restricts their operational duration, so optimizing energy efficiency is of importance. However, existing optimization schemes often overlook the impact of ground user mobility on user association, lacking ability to achieve optimal energy efficiency. In this paper, the K-Means method is applied to optimize user association by periodically clustering users. Additionally, given the dynamic nature of the wireless channels, we utilize the Multi-Agent Twin Delayed Deep Deterministic Policy Gradient (MATD3) approach to jointly optimize 3D trajectory and power allocation. The objective is to maximize the sum energy efficiency while meeting the constraints included maximum power, minimum achievable data rate and spatial limitation. Simulation results demonstrate the effectiveness of the proposed algorithm compared with other benchmark algorithms. Fuhao Liu, Haoqiang Chen, Jiansong Miao, Tao Zhang 0063, Chuan Zhang 0003, Jiawen Kang 0001, Dusit Niyato |
GLOBECOM | 5 |
| 2024 | Two-Stage Resource Scheduling for Deterministic Communication and Computation IntegrationabstractIn this paper, we investigate a resource orchestration and transmission scheduling problem for data-intensive services with diversified service requirements. A three-layer collaborative architecture is presented to support dynamic networking and computing resource allocation. To obtain optimal orchestration and scheduling policies, we formulate a constrained resource scheduling problem with the objective to maximizing resource utilization and scheduling success ratio. Since the complicated coupled constraints among decisions, we decouple the problem into a two-stage sub-problems of resource orchestration and transmission scheduling. To realize cross-domain resource orchestration and deterministic transmission of large-scale computing tasks, a two-stage resource scheduling scheme is proposed. Specifically, the first stage makes the resource orchestration decision by a greedy algorithm, and the second stage makes the transmission scheduling decision based on a deep reinforcement learning algorithm. Simulation results show that the proposed solution can effectively improve resource utilization and scheduling success ratio while satisfying diversified service requirements, as compared with benchmarks. Weiting Zhang, Nian Tang, Chuan Zhang 0003, Ruibin Guo, Chenhao Ying 0001 |
GLOBECOM | 3 |
| 2024 | A Secure Cross-Account Audit Scheme for Cross-Chain Transactions
Licheng Wang 0004, Liehuang Zhu, Chuan Zhang 0003 |
ICA3PP (3) | 6 |
| 2024 | Efficient and Privacy-Preserving Ranking-Based Federated Learning
Xuhao Ren, Huishu Wu, Chuan Zhang 0003 |
ICA3PP (4) | 5 |
| 2024 | Cross-Chain Transaction Auditing with Truth Discovery
Huishu Wu, Xuhao Ren, Mengxuan Liu, Chuan Zhang 0003, Liehuang Zhu |
ICA3PP (6) | 6 |
| 2024 | Defense Against Textual Backdoors via Elastic Weighted Consolidation-Based Machine Unlearning
Haojun Xuan, Huishu Wu, Chuan Zhang 0003, Liehuang Zhu |
ICA3PP (6) | 5 |
| 2024 | Data-Free Encoder Stealing Attack in Self-supervised Learning
Chuan Zhang 0003, Xuhao Ren, Haotian Liang, Xiangyun Tang, Chunhai Li, Liehuang Zhu |
ICA3PP (1) | 1 |
| 2024 | Achieving Privacy-Preserving and Scalable Graph Neural Network Prediction in Cloud EnvironmentsabstractGraph neural networks (GNNs) have been widely applied in various graph analysis tasks. To provide more convenient and faster predictive services, many enterprises are choosing to deploy GNNs in cloud environments. However, given the increasing privacy concerns about GNNs models and graph data, as well as the need to quickly generate embeddings for new nodes in real-world applications, a critical issue in this emerging paradigm is to ensure the security and scalability of GNN predictions. In this paper, we propose a privacy-preserving and scalable GNN prediction scheme, named PS-GNN, to address the privacy issues in cloud environments. Specifically, PS-GNN utilizes a customized array structure to store graph data and employs secret sharing to preserve the confidentiality of both the GNN model and graph data. Besides, the scalability of PS-GNN is achieved by aggregating feature information from local node neighborhoods in parallel. Through a detailed analysis, we demonstrate the security of PS-GNN. Extensive experiments on real-world datasets demonstrate that PS-GNN outperforms existing schemes in terms of computational and communication overhead, and reaches state-of-the-art performance on large graphs. Yanli Yuan, Dian Lei, Chuan Zhang 0003, Ximeng Liu, Zehui Xiong, Liehuang Zhu |
ICC | 3 |
| 2024 | Multi-domain collaborative two-level DDoS detection via hybrid deep learning
Huifen Feng, Weiting Zhang, Ying Liu 0018, Chuan Zhang 0003, Chenhao Ying 0001, Zhenzhen Jiao |
Comput. Networks | 4 |
| 2024 | Privacy-Preserving and Revocable Redactable Blockchains With Expressive Policies in IoTabstractWith integrity and traceability, blockchains have been widely applied in Internet of Things (IoT) systems. However, immutable blockchains contradict recent data regulations (e.g., the right to be forgotten in General Data Protection Regulation), making redactable blockchain-based IoT emerge as a promising paradigm. In this paradigm, IoT users can specify expressive policies (i.e., containing multiple logical AND and OR operators) to achieve controllable data editability. Unfortunately, existing related schemes with expressive policies face several issues: high communication costs, data privacy leakage (i.e., data can be read by all users), and inefficient user revocation. This article proposes a privacy-preserving and revocable redactable blockchain scheme in IoT systems, named BlockENC. BlockENC allows owners to specify expressive policies for controlling which users can read or edit their data and ensures downward compatible privileges (i.e., editable users own the privilege of readable users but not vice versa) under only$\mathcal {O}(n)$communication costs$(\mathcal {O}(n^{2})$in other schemes). The punchline of BlockENC is to define readability policies as subsets of editability policies and introduce access control trees to embed these policies in distributing data decryption keys and chameleon hash trapdoors. Moreover, drawing inspiration from ciphertext division mechanisms in proxy re-encryption techniques, BlockENC creates globally unique random values to reconstruct user keys, converting updating all existing keys or ciphertexts when user revocation cases occur into simply invalidating corresponding keys. Security analysis proves that BlockENC is secure against chosen-plaintext attacks. Experiments on the FISCO blockchain platform show that BlockENC achieves around$5\times $computation and$10\times $communication improvement over related works. Hongchen Guo, Liren Chen, Xuhao Ren, Mingyang Zhao 0002, Chunhai Li, Jingfeng Xue, Liehuang Zhu, Chuan Zhang 0003 |
IEEE Internet Things J. | 8 |
| 2024 | Multiround Efficient and Secure Truth Discovery in Mobile Crowdsensing SystemsabstractPrivacy-preserving truth discovery, as a data aggregation algorithm that can extract reliable results from disparate and conflicting data in a privacy-preserving manner, has received a lot of attention in ensuring the reliability and privacy of data in mobile crowdsensing systems. However, most of the existing work requires that workers must stay online all the time during the full process of truth discovery. Although a few recent schemes have been proposed to tolerate worker dropout, they are tailored for a single-round setting. Repeating these schemes several times to adapt to the truth discovery will introduce significant computational and communication overheads, especially for the workers. To solve the above challenges, in this paper, we propose a multi-round efficient and secure truth discovery scheme in mobile crowdsensing systems that can balance the 3-way trade-off between privacy protection, dropout tolerance, and protocol efficiency. Specifically, we devise a novel mask generation capable of reusing secrets to eliminate the costly overhead of workers needing to recompute new secrets each round. Besides, we design a lightweight dropout tolerance mechanism to guarantee that even if workers drop out halfway, the server can still acquire meaningful truth. Rigorous security analysis and extensive experimental results demonstrate the privacy and efficiency of our scheme, respectively. Chenfei Hu, Yuhua Xu 0010, Chuan Zhang 0003, Ximeng Liu, Daojing He, Liehuang Zhu |
IEEE Internet Things J. | 4 |
| 2024 | Publicly Verifiable and Secure SVM Classification for Cloud-Based Health Monitoring ServicesabstractIn cloud-based health monitoring services, healthcare centers often outsource support vector machine (SVM)-based clinical decision models to provide remote users with clinical decisions. During service provisioning, authorized external organizations like insurance companies aim to verify decision correctness to prevent fraudulent medical reimbursements. However, existing verifiable and secure SVM classification schemes have predominantly focused on user self-verification, thereby introducing potential risks of privacy leakage (such as input data exposure) in publicly verifiable scenarios. To address the aforementioned limitation, we propose a publicly verifiable and secure SVM classification scheme (PVSSVM) for cloud-based health monitoring services in a malicious setting, which can accommodate the verification needs of users or authorized external organizations with respect to potential malicious results returned by cloud servers. Specifically, we utilize homomorphic encryption and secret sharing to protect the model and data confidentiality in the cloud server, respectively. Based on a multiserver verifiable computation framework, PVSSVM achieves public verification of predicted results. Additionally, we further investigate its performance. Experimental evaluations demonstrate that PVSSVM outperforms existing state-of-the-art solutions in terms of computation and communication overhead. Notably, in the verification scenario of large-scale predictions, the proposed scheme achieves a reduction of approximately 83.71% in computation overhead through batch verification, as compared to one-by-one verification. Dian Lei, Jinwen Liang, Chuan Zhang 0003, Ximeng Liu, Daojing He, Liehuang Zhu, Song Guo 0001 |
IEEE Internet Things J. | 3 |
| 2024 | One-Shot Backdoor Removal for Federated LearningabstractFederated learning is a distributed machine learning approach that enables multiple participants to collaboratively train a model without sharing their data, thus preserving privacy. However, the decentralized nature of federated learning also makes it susceptible to backdoor attacks, where malicious participants can embed hidden vulnerabilities within the model. Addressing these threats efficiently and effectively is crucial, especially given the impracticality of iterative and resource-intensive detection methods in federated learning environments. This article presents a novel framework for one-shot backdoor removal in federated learning. Our approach integrates advanced anomaly detection techniques with a unique model update aggregation strategy, allowing for the identification and neutralization of backdoor influences in a single update cycle without the need for extensive data access or communication between participants. Extensive experiments across various federated architectures and data distributions demonstrate that our method effectively mitigates backdoor threats while maintaining model performance and scalability. This work not only enhances the security of federated models but also contributes to the broader applicability of federated learning in sensitive and critical domains. Zijie Pan, Zuobin Ying, Chuan Zhang 0003, Chunhai Li, Liehuang Zhu |
IEEE Internet Things J. | 4 |
| 2024 | Toward Fine-Grained Task Allocation With Bilateral Access Control for Intelligent Transportation SystemsabstractIn this article, we propose a secure fine-grained task allocation scheme with bilateral access control (FTA-BAC) for intelligent transportation systems. To enhance the security, we formulate bilateral access control in task allocation, by adopting the matchmaking encryption (ME) to encrypt the task requirements/interests for secure task matching. In this way, both task requesters and workers can specify their match policies simultaneously, without revealing their sensitive information (i.e., attributes and geographical location). To realize fine-grained task allocation, we use a linear integer secret sharing (LISS) scheme to represent task requirements/interests, supporting theAND/ORoperation on match policies. To further improve the efficiency, we design a delegation mechanism to reduce the computation burden on resource-limited end devices, by diverting the high-frequency matching operations to edge nodes. Then, we prove the security of FTA-BAC under formally defined security model. Finally, we analyze the performance of FTA-BAC through theoretical analysis and experimental evaluation, demonstrating that FTA-BAC can provide practical task allocation for intelligent transportation systems compared with the state-of-the-art works. Tong Wu 0011, Chuan Zhang 0003, Ximeng Liu, Guomin Yang, Liehuang Zhu |
IEEE Internet Things J. | 3 |
| 2024 | Toward Efficient and Robust Federated Unlearning in IoT NetworksabstractOwing to its practical configuration to edge computing and privacy preservation capabilities, federated learning (FL) has been increasingly appealing in Internet of Things (IoT) networks. However, due to the inherent openness of IoT network architectures, FL clients are susceptible to various attacks, resulting in unreliable local model updates. To address this challenge, federated unlearning (FU) emerges as a viable solution, which can erase such unreliable updates from the FL model using the unlearning operation while preserving model accuracy. Existing FU studies have significant potential, but they are not directly applicable to IoT networks because of their high computational costs and limited capacity to defend against prevalent dynamic attacks in mobile network environments. In this work, we propose FedRemover, a novel FU method specifically tailored for deployment in IoT networks. The key insight behind FedRemover is that model updates will exhibit inconsistency when exposed to attacks. Therefore, we devise a real-time malicious client detection scheme by examining the performance consistency of model updates. Upon detecting malicious clients, FedRemover promptly executes the unlearning operation, achieving an unlearned global model within a minimal number of rounds. This makes FedRemover highly efficient and robust against dynamic attacks, enabling it well-suited for practical deployment in IoT networks. Experiments on three standard datasets demonstrate the efficiency and robustness of FedRemover, with an obvious speed-up of 10× and comparable robustness guarantees compared with benchmark algorithms. Yanli Yuan, Chuan Zhang 0003, Zehui Xiong, Chunhai Li, Liehuang Zhu |
IEEE Internet Things J. | 3 |
| 2024 | EPDB: An Efficient and Privacy-Preserving Electric Charging Scheme in Internet of Robotic ThingsabstractIn recent years, electric vehicles (EVs) have emerged as a promising mode of transportation. With the development of Internet of Robotic Things (IoRT) technology, charging stations are employing interconnected robots to charge EVs, automating the collection and transmission of user charging information. However, charging processes pose risks of privacy leakage to users, as malicious attackers could potentially exploit the collected charging information to infer the real identities and behavioral habits of EV users. Existing studies leverage the decentralization and anonymity of blockchain to achieve privacy-preserving charging management. Due to the increasing number of users and limited battery capacity, there is a large volume of charging requests demand to be processed. However, the consensus mechanism of blockchain limits the system throughput. Therefore, it is a challenge to preserve the privacy of EV users and simultaneously improve the system processing efficiency. To address these concerns, we propose an efficient and privacy-preserving EV charging scheme (EPDB), which leverages decentralized identifier (DID) and Pedersen commitment scheme to achieve reliable charging reservations while hiding EV User’s charging information. Additionally, we propose an efficient blockchain consensus protocol, which serves as the underlying storage for DID, thus significantly improving the system throughput. Furthermore, our proposed consensus protocol maintains high throughput even when encountering Byzantine attacks. Our theoretical analysis indicates that EPDB scheme effectively mitigate Byzantine attacks, preserve privacy and prevents deception of charging services, and our experimental results demonstrate the high efficiency of EPDB scheme. Di Zhai, Jiqiang Liu, Tao Zhang 0063, Jian Wang 0015, Hongyang Du 0001, Tianxi Wang, Chuan Zhang 0003, Jiawen Kang 0001, Dusit Niyato |
IEEE Internet Things J. | 8 |
| 2024 | VSpatial: Enabling Private and Verifiable Spatial Keyword-Based Positioning in 6G-Oriented IoTabstractFor increasing Internet of Things (IoT) devices, 6G wireless technology aims for ubiquitous communications in which positioning services are necessary. Private spatial keyword-based positioning service is promising in 6G-oriented IoT since it positions users based on spatial locations and textual keywords while protecting user privacy. However, due to economic benefits or malicious attacks, positioning service providers may return erroneous or incomplete results, which cause tremendous economic damage and security threats, e.g., always assigning a selective driver for the specific car-hailing user. A technical challenge for extending existing private schemes to enable users to verify the correctness and completeness of positioning results is the distinctive positioning paradigm between compared spatial locations and matched textual keywords. This paper proposes a private and verifiable spatial keyword positioning scheme named VSpatial in 6G-oriented IoT. VSpatial enables users to verify the correctness and completeness of spatial keyword-based positioning results while preserving user privacy. The main inspiration for addressing the technical challenge is converting both spatial locations and textual keywords into an internal status, i.e., adapting comparison and matching to existence judging by multiple cryptographic tools, such as hierarchical cube and pseudorandom function. Based on this inspiration, we design a novel private authenticated data structure (named PVTree), and then propose two constructions of VSpatial, i.e., VSpatial-S and VSpatial-D, to suit static and dynamic environments, respectively. The core idea for adapting VSpatial-S to VSpatial-D is transferring one whole PVTree into multiple exponential-size partitions. Security analysis proves the security and verifiability of VSpatial. Theoretical and experimental evaluations show that VSpatial achieves faster-than-linear positioning efficiency and linear verification overhead. Weiting Zhang, Mingyang Zhao 0002, Zhuoyu Sun, Chuan Zhang 0003, Jinwen Liang, Liehuang Zhu, Song Guo 0001 |
IEEE J. Sel. Areas Commun. | 4 |
| 2024 | Privacy-Preserving Identity-Based Data Rights Governance for Blockchain-Empowered Human-Centric Metaverse CommunicationsabstractMetaverse provides human-centric immersive communication experiences where humans can teleport across different virtual landscapes and build real-time communications via digital identities with others in the same landscape. Despite great benefits, a natural question in human-centric metaverse communications is how to secure digital content among humans. In this regard, blockchain has been widely applied due to its distinct features (e.g., decentralization, transparency, and immutability). Unfortunately, the inherent properties of the blockchain also hinder humans from further deploying preferences to flexibly govern the digital content (i.e., who can read and who can edit), limiting human-centric communication abilities. Some redactable blockchain-based solutions have been proposed, but most of them suffer from the issues of data and preference leakage. To address the issues, we propose a privacy-preserving identity-based data governance (IDRG) scheme for blockchain-empowered human-centric metaverse communications. Combining digital identities, IDRG cryptographically allows humans to govern readability and editability with the right downward compatibility (i.e., humans with editability are endowed with readability) while protecting policy privacy. Specifically, IDRG leverages the polynomial function technique to break through the bottleneck of the traditional identity-based encryption technique (i.e., a policy only contains a user) to achieve a policy for multiple users. Subsequently, the optimized policies are utilized to enrich chameleon hash-based redactable blockchains for comprehensive rights governance. Further, IDRG supports user accountability and revocation by combining the proxy re-encryption technique. Security analysis proves the security of IDRG under the chosen-ciphertext attack. Experiments on the FISCO blockchain platform demonstrate that IDRG requires approximately 0.1 s to process an encryption request, 0.01 s for a reading request, and 1 s for an editing request. Overall, IDRG achieves a$3\times $reduction in computational costs compared with state-of-the-art solutions. Chuan Zhang 0003, Mingyang Zhao 0002, Weiting Zhang, Jianbing Ni, Liehuang Zhu |
IEEE J. Sel. Areas Commun. | 1 |
| 2024 | FutureDID: A Fully Decentralized Identity System With Multi-Party VerificationabstractDecentralized identity (DID) systems conforming to the World Wide Web Consortium (W3C) Decentralized Identifiers (DIDs) and Verifiable Credentials Data Model recommendations have recently attracted attention due to their better autonomy, interoperability, and openness design. However, those W3C recommendations lack a design for addressing the single point of failure (SPOF) and identity revocation, which could seriously compromise the robustness and practicality of DID systems. To remedy these limitations, we propose FutureDID, a DID system that enables multiple parties to jointly issue credentials and efficiently revoke DID identities, providing a robust and practical DID system. FutureDID is designed with a multi-party credential issuing mechanism based on distributed key generation technology, which transforms trust from a single entity to distributed committees and facilitates authentication between issuers, making it more resistant to SPOF. Moreover, the underlying blockchain system is built on a chameleon hash function to ensure tamper-proof and enable efficient identity revocation. We have implemented a prototype system using FISCO BCOS and conducted extensive evaluations to demonstrate the effectiveness and practicality of our system. Our evaluations have shown that FutureDID provides a significant improvement in efficiency, achieving at least a 60 × efficiency improvement in identity revocation compared to state-of-the-art systems. Jinwen Liang, Chuan Zhang 0003, Ximeng Liu, Liehuang Zhu, Song Guo 0001 |
IEEE Trans. Computers | 3 |
| 2024 | Achieving Efficient and Privacy-Preserving Location-Based Task Recommendation in Spatial CrowdsourcingabstractIn spatial crowdsourcing, location-based task recommendation schemes are widely used to match appropriate workers in desired geographic areas with relevant tasks from data requesters. To ensure data confidentiality, various privacy-preserving location-based task recommendation schemes have been proposed, as cloud servers behave semi-honestly. However, existing schemes reveal access patterns, and the dimension of the geographic query increases significantly when additional information beyond locations is used to filter appropriate workers. To address the above challenges, this paper proposes two efficient and privacy-preserving location-based task recommendation (EPTR) schemes that support high-dimensional queries and access pattern privacy protection. First, we propose a basic EPTR scheme (EPTR-I) that utilizes randomizable matrix multiplication and public position intersection test (PPIT) to achieve linear search complexity and full access pattern privacy protection. Then, we explore the trade-off between efficiency and security and develop a tree-based EPTR scheme (EPTR-II) to achieve sub-linear search complexity. Security analysis demonstrates that both schemes protect the confidentiality of worker locations, requester queries, and query results and achieve different security properties on access pattern assurance. Extensive performance evaluation shows that both EPTR schemes are efficient in terms of computational cost, with EPTR-II being$10^{3}\times$faster than the state-of-the-art scheme in task recommendation. Fuyuan Song, Jinwen Liang, Chuan Zhang 0003, Zhangjie Fu 0001, Zheng Qin 0001, Song Guo 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | NANO: Cryptographic Enforcement of Readability and Editability Governance in Blockchain DatabasesabstractRecently, increasing personal data has been stored in blockchain databases, ensuring data integrity by consensus. Although transparent and immutable blockchains are mainly adopted, the need to deploy preferences on which users canreadandeditthe data is growing in importance. Based on chameleon hashes, recent blockchains support editability governance but can hardly prevent data breaches because the data is readable to all participants in plaintexts. This motivates us to propose NANO, the first permissioned blockchain database that provides downward compatible readability and editability governance (i.e., users who caneditthe data can alsoreadthe data). Two challenges are protecting policy privacy and efficiently revoking malicious users (e.g., users who abuse their editability privileges). The punchline is leveraging Newton's interpolation formula-based secret sharing to hide policies into polynomial parameters and govern the distribution of data decryption keys and chameleon hash trapdoors. Inspired by proxy re-encryption, NANO integrates unique user symbols into user keys, achieving linear user revocation overhead. Security analysis proves that NANO provides comprehensive privacy preservation under the chosen-ciphertext attack. Experiments on the FISCO blockchain platform demonstrate that compared with state-of-the-art related solutions, NANO achieves a 7× improvement on average regarding computational costs, gas consumption, and communication overhead. Chuan Zhang 0003, Mingyang Zhao 0002, Jinwen Liang, Liehuang Zhu, Song Guo 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Boosting the Transferability of Adversarial Attacks With Frequency-Aware PerturbationabstractDeep neural networks (DNNs) are vulnerable to adversarial examples, with transfer attacks in black-box scenarios posing a severe real-world threat. Adversarial perturbation is often globally manipulated image disturbances crafted in the spatial domain, leading to perceptible noise due to overfitting to the source model. Both the human visual system (HVS) and DNNs (endeavoring to mimic HVS behavior) exhibit unequal sensitivity to different frequency components of an image. In this paper, we intend to exploit this characteristic to create frequency-aware perturbation. Concentrating adversarial perturbations on components within images that contribute more significantly to model inference to enhance the performance of transfer attacks. We devise a systematic approach to select and constrain adversarial optimization in a subset of frequency components that are more critical to model prediction. Specifically, we measure the contributions of each individual frequency component and devise a scheme to concentrate adversarial optimization on these important frequency components, thereby creating frequency-aware perturbations. Our approach confines perturbations within model-agnostic critical frequency components, significantly reducing overfitting to the source model. Our approach can be seamlessly integrated with existing state-of-the-art attacks. Experiments demonstrate that while concentrating perturbation within selected frequency components yields a smaller perturbation magnitude overall, our approach does not sacrifice adversarial effectiveness. Conversely, our frequency-aware perturbation manifests superior performance, boosting imperceptibility, transferability, and evasion against various defenses. Shangbo Wu, Ximeng Liu, Wanlei Zhou 0001, Liehuang Zhu, Chuan Zhang 0003 |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2024 | Accountable and Secure Threshold EdDSA Signature and Its ApplicationsabstractThreshold signatures as a method to realize multi-party cooperation and trust distribution in blockchain have been widely studied in recent years. However, among these researches, few threshold signature schemes achieve all the properties of accountability, privacy, and key protection for the EdDSA-based blockchain systems. To fill this gap, we propose an EdDSA-based accountable threshold signature protocol with privacy and proactive refresh, named TAPS-PR. Meanwhile, we define new security models and give a detailed analysis to prove protocol security. In TAPS-PR, the threshold is variable and hidden with the signing quorum from the public view. However, the signing quorum can be traced when threshold signatures related to fraudulent events are generated. We also enhance the key security of each signer by proactive refresh, which realizes updating the private key while the public key remains unchanged. Apart from that, we present ATS-PR with increased efficiency and reduced communication cost at the cost of weaker security. The theoretical analysis and experimental results indicate that our protocols perform efficiently in terms of communication and computation overhead. Furthermore, we use Tezos, a blockchain project employing EdDSA, as a case study to demonstrate the compatibility of our protocol with real-world blockchain applications. Yumeng Xie, Chuan Zhang 0003, Tong Wu 0011, Yuao Zhou, Debiao He, Liehuang Zhu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Blockchain-Based Dynamic Time-Encapsulated Data Auditing for Outsourcing StorageabstractOutsourcing storage has emerged as an effective solution to manage the increasing volume of data. With the popularity of pay-as-you-go payment models in outsourcing storage, data auditing schemes that prioritize timeliness can be valuable evidence for elastic bill settlement. Unfortunately, existing data auditing schemes do not sufficiently consider timeliness during auditing. Furthermore, practical data auditing schemes should have the capability to check the integrity of scalable data. In this paper, we propose a blockchain-based dynamic data auditing scheme with strong timeliness to ensure that data stored in outsourcing storage systems remain intact. Our scheme encapsulates timestamps into homomorphic verifiable tags to simultaneously check data integrity and timestamp validity. To achieve dynamicity, we utilize the Merkle hash tree to store the tags, allowing for block-level dynamic operations. Additionally, by leveraging the transparency, non-repudiation, and tamper resistance of blockchain technology, we design a blockchain-based data auditing framework to prevent malicious behavior from all entities. We then formally prove the soundness and privacy of our scheme. Finally, we conduct theoretical analysis and experimental evaluation to demonstrate that the performance of our scheme is of acceptable efficiency to existing works in terms of computation cost, communication overhead, and storage overhead. Chuan Zhang 0003, Haojun Xuan, Tong Wu 0011, Ximeng Liu, Guomin Yang, Liehuang Zhu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Revocable and Privacy-Preserving Bilateral Access Control for Cloud Data SharingabstractIn this paper, we propose a revocable and privacy-preserving bilateral access control scheme (named PriBAC) for general cloud data sharing (i.e., end-cloud-based data sharing). PriBAC ensures that preference matching is successful only when both parties’ preferences are satisfied simultaneously. Otherwise, nothing is leaked beyond whether the preference matching occurs. There are three challenges in designing PriBAC. The first challenge is protecting matching information, i.e., concealing two preference matching processes, in a single cloud server. The second challenge is protecting preference content while preventing receivers from receiving much useless information. The third challenge is how to integrate efficient user revocation mechanisms into bilateral access control to handle frequent user revocation cases in practical cloud data sharing applications. To address the above challenges, the punchline in PriBAC is to leverage Newton’s interpolation formula-based secret sharing to enrich the matchmaking encryption technique for constructing a privacy-preserving preference matching mechanism. To achieve efficient user revocation, we integrate a unique symbol into each user’s keys and efficiently revoke users by invaliding the corresponding keys. Security analysis proves that PriBAC can resist the chosen-ciphertext attack and preserves preference privacy and matching privacy. Experiments show that PriBAC achieves approximately$3\times $user performance improvement compared with current state-of-the-art related schemes. Mingyang Zhao 0002, Chuan Zhang 0003, Tong Wu 0011, Jianbing Ni, Ximeng Liu, Liehuang Zhu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | A Cooperative Analysis to Incentivize Communication-Efficient Federated LearningabstractFederated Learning (FL)has achieved state-of-the-art performance in training a global model in a decentralized and privacy-preserving manner. Many recent works have demonstrated that incentive mechanism is of paramount importance for the success of FL. Existing incentives to FL either neglect communication efficiency, or consider communication efficiency but design the incentive mechanisms using non-cooperative games under complete information assumption, or study incentive mechanism under incomplete information but only apply to the sequential interaction setting. We shed light on this problem from the cooperative perspective and propose an incentive mechanism for communication-efficient FL based on the Nash bargaining theory. Specially, we formulate our incentive mechanism as a one-to-manyconcurrent bargaininggame among the aggregator and clients, and systematically analyze the Nash bargaining solution (NBS, game equilibrium) to design the incentive mechanism. It should be noted that the existingsequential bargainingis not suitable for incentivizing FL due to high (exponential) time complexity, which deteriorates the straggler problem in FL. Our formulated bargaining game is challenging due to the NP-hardness. We propose a probabilistic greedy-based client selection algorithm and derive an analytical payment solution as an approximate NBS. We prove the convergence guarantee of our incentive mechanism for communication-efficient FL. Finally, we conduct experiments over real-world datasets to evaluate the performance of our incentive mechanism. Youqi Li, Fan Li 0001, Song Yang 0002, Chuan Zhang 0003, Liehuang Zhu, Yu Wang 0003 |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | DetFed: Dynamic Resource Scheduling for Deterministic Federated Learning Over Time-Sensitive NetworksabstractIn this paper, we present a three-layer (i.e., device, field, and factory layers) deterministic federated learning (FL) framework, named DetFed, which accelerates collaborative learning process for ultra-reliable and low-latency industrial Internet of Things (IoT) via integrating 6G-oriented Time-sensitive Networks (TSN). Utilizing dispersive local data, industrial IoT devices distributively train a deep neural network (DNN) model, and the updated model parameters are aggregated at their associated field servers every round or at a centralized factory server every a few rounds. Aiming at optimizing the learning accuracy of FL without affecting the co-transmission of burst traffic (e.g., safety-critical traffic), an integrated TSN is considered to establish connections among the three layers, where a cyclic queuing and forwarding mechanism is deployed in each switch to support deterministic model parameter transmission with microsecond-level delay and near-zero packet loss requirements. To improve the FL performance, we formulate a multi-objective stochastic optimization problem to simultaneously maximize the scheduling success ratio and learning accuracy while satisfying the deterministic requirements of delay, jitter, and packet loss. Since the objective function is implicit and the available time slots of the considered TSN in each FL round are temporally correlated, the problem is difficult to solve in real time. Therefore, we transform the problem into a Markov decision process formulation and propose a dynamic resource scheduling algorithm, based on deep reinforcement learning, to make optimal resource scheduling decisions while adapting to device heterogeneity and network dynamics. Experimental results based on real-world dataset demonstrate that the proposed DetFed significantly accelerates FL convergence and improves learning accuracy as compared to state-of-the-art benchmarks. Dong Yang 0001, Weiting Zhang, Qiang Ye 0002, Chuan Zhang 0003, Ning Zhang 0007, Chuan Huang 0001, Hongke Zhang, Xuemin Shen |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | POTA: Privacy-Preserving Online Multi-Task Assignment With Path PlanningabstractPrivacy-preserving online multi-task assignment is a crucial aspect of spatial crowdsensing on untrusted platforms, where multiple real-time tasks are allocated to appropriate workers in a privacy-preserving manner. While existing schemes ensure the privacy of tasks and users, they seldom focus on minimizing the total moving distances for crowdsensing workers when assigning multiple tasks in real time, which adversely impacts the efficiency of online multi-task assignments. To address this issue, we propose POTA, the first privacy-preserving online multi-task assignment scheme with path planning that minimizes the total moving distances for crowdsensing workers without additional noise. POTA cryptographically implements the extended minimum-cost flow model, which models the encrypted data of workers and tasks in a graph and later produces optimized routing. With such a secure path-planning component, POTA reduces the total moving distances by$25.19\%-52.78\%$in the tested dataset compared with the state-of-the-art schemes with obfuscated path planning. Security analysis proves that POTA guarantees the confidentiality of sensitive data, a stronger security property than introducing obfuscation to sensitive data. Experimental evaluations on real-world datasets demonstrate the feasibility of POTA in terms of running time and its ability to achieve minimized total moving distances. Chuan Zhang 0003, Xingqi Luo, Jinwen Liang, Ximeng Liu, Liehuang Zhu, Song Guo 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | An Authentic and Privacy-Preserving Scheme Towards E-Health Data Transmission ServiceabstractThe e-health system enables online healthcare by supporting health data transmission services on medical platforms. Considering the frequent privacy breaches in e-health systems and the issuance of relevant regulations, it is important to ensure the authenticity and privacy of health data. Existing e-health systems either fail to provide data authenticity or neglect privacy protection after patients leave the system. In this article, we put forward a secure and efficient e-health system for data transmission, named PPED, to solve this dilemma. In PPED, we explore a regular signature and a forward-secure signature, which guarantee data authenticity and give the signature a valid period. Then, a specific epochal signature scheme is designed by combining two signature schemes with the time-lock puzzle. Since expired epochal signatures are forgeable, patients after leaving the e-health system can forge expired signatures to deny their relationship with the signed data, thus achieving privacy protection. Detailed security analysis demonstrates the PPED realizes data authenticity and user privacy. Extensive experiments evaluate our system and the results show it is practical in terms of running time. Yumeng Xie, Chuan Zhang 0003, Ximeng Liu, Liehuang Zhu |
IEEE Trans. Serv. Comput. | 3 |
| 2023 | Fine-Grained Data Rights Governance in Blockchain-Based Cloud-Edge CommunicationsabstractNowadays, cloud-edge communication has emerged as a promising communication paradigm, which leverages edge devices to provide a series of advantages, such as a fast response for end devices. However, considering complicated communication environments, a practical requirement is improving security by constructing decentralized and traceable communications. Currently, blockchains have been widely applied in cloud-edge communications to ensure decentralization and traceability by consensus. Despite these promising benefits, existing transparent and immutable blockchains inevitably introduce two limitations to data rights governance in blockchain-based cloud-edge communications. The first limitation is that transparent blockchains can hardly guarantee data confidentiality since data is accessible to all users, especially unauthorized users. The second limitation is that immutable blockchains can hardly support improper content redaction, which violates the right to be forgotten in GDPR. This paper proposes FDRG, the first fine-grained data rights governance scheme in blockchain-based cloud-edge communications. FDRG cryptographically ensures the right downward compatibility and user collusion resistance. Specifically, based on attributes and policies, FDRG partitions users into three roles (i.e., unauthorized user, readable user, and editable user) and ensures that editable users are compatible with the rights of readable users. The punchline is that FDRG leverages the linear secret sharing matrix-based secret sharing to govern the distribution of data decryption keys and chameleon hashes trapdoors. Formal security analysis proves the security of FDRG under the chosen-plaintext attack in the random oracle model. A full implementation on the FISCO blockchain platform shows that FDRG achieves competitive efficiency compared to state-of-the-art related schemes. Weilin Gan, Mingyang Zhao 0002, Hongchen Guo, Chuan Zhang 0003, Jianan Hong, Liehuang Zhu |
GLOBECOM | 4 |
| 2023 | Enabling privacy-preserving multi-server collaborative search in smart healthcare
Chuan Zhang 0003, Xingqi Luo, Tong Wu 0011, Liehuang Zhu |
Future Gener. Comput. Syst. | 1 |
| 2023 | Enabling efficient and secure health data sharing for Healthcare IoT systems
Liehuang Zhu, Yumeng Xie, Yuao Zhou, Chuan Zhang 0003, Ximeng Liu |
Future Gener. Comput. Syst. | 5 |
| 2023 | Blockchain-Based Anonymous Data Sharing With Accountability for Internet of ThingsabstractBlockchain has been a promising infrastructure for enabling secure data sharing for the Internet of Things (IoT). With the widespread of IoT applications, security issues, such as data privacy, anonymity, and accountability become critical concerns for the users, which are essential principles for secure communication in those applications. However, the existing blockchain-based data-sharing schemes mainly consider data privacy. Only a few works can support anonymity with strong, trusted assumptions. Thus, there is a research gap on the anonymity of blockchain-based data sharing for IoT, which does not rely on any trusted party. In this article, we propose a blockchain-based anonymous data-sharing scheme (BA-DS) by adopting a novel public key encryption derived from a ring signature. In BA-DS, we remove the trusted party and ensure anonymity by using an unconditional linkable ring signature and Signature of Knowledge (SoK). During the revocation, we apply blockchain infrastructure to record the valid revocation list and generate a tag for data stored on the cloud, providing solid accountability. The formal security analysis shows that BA-DS is selective indistinguishable secure in the random oracle model. Additionally, we also prove that BA-DS holds anonymity, data privacy, accountability, and authenticity. The extensive experiments indicate that our proposed BA-DS achieves reasonable efficiency in terms of computational complexity, communication overhead, and consumption on the blockchain. Tong Wu 0011, Weijie Wang 0010, Chuan Zhang 0003, Weiting Zhang, Liehuang Zhu, Keke Gai |
IEEE Internet Things J. | 3 |
| 2023 | Efficient Strong Privacy-Preserving Conjunctive Keyword Search Over Encrypted Cloud DataabstractSearchable symmetric encryption (SSE) supports keyword search over outsourced symmetrically encrypted data. Dynamic searchable symmetric encryption (DSSE), a variant of SSE, further enables data updating. Most DSSE works with conjunctive keyword search primarily consider forward and backward privacy. Ideally, the server should only learn the result sets involving all keywords in the conjunction. However, existing schemes suffer from keyword pair result pattern (KPRP) leakage, revealing the partial result sets containing two of query keywords. We propose the first DSSE scheme to address aforementioned concerns that achieves strong privacy-preserving conjunctive keyword search. Specifically, our scheme can maintain forward and backward privacy and eliminate KPRP leakage, offering a higher level of security. The search complexity scales with the number of documents stored in the database in several existing schemes. However, the complexity of our scheme scales with the update frequency of the least frequent keyword in the conjunction, which is much smaller than the size of the entire database. Besides, we devise a least frequent keyword acquisition protocol to reduce frequent interactions between clients. Finally, we analyze the security of our scheme and evaluate its performance theoretically and experimentally. The results show that our scheme has strong privacy preservation and efficiency. Chang Xu 0004, Ruijuan Wang, Liehuang Zhu, Chuan Zhang 0003, Rongxing Lu, Kashif Sharif |
IEEE Trans. Big Data | 4 |
| 2023 | Achieving Efficient and Privacy-Preserving Neural Network Training and Prediction in Cloud EnvironmentsabstractThe neural network has been widely used to train predictive models for applications such as image processing, disease prediction, and face recognition. To produce more accurate models, powerful third parties (e.g., clouds) are usually employed to collect data from a large number of users, which however may raise concerns about user privacy. In this paper, we propose an Efficient and Privacy-preserving Neural Network scheme, named EPNN, to deal with the privacy issues in cloud-based neural networks. EPNN is designed based on a two-cloud model and techniques of data perturbation and additively homomorphic cryptosystem. This scheme enables two clouds to cooperatively perform neural network training and prediction in a privacy-preserving manner and significantly reduces the computation and communication overhead among participating entities. Through a detailed analysis, we demonstrate the security of EPNN. Extensive experiments based on real-world datasets show EPNN is more efficient than existing schemes in terms of computational costs and communication overhead. Chuan Zhang 0003, Chenfei Hu, Tong Wu 0011, Liehuang Zhu, Ximeng Liu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Achieving Privacy-Preserving and Verifiable Support Vector Machine Training in the CloudabstractWith the proliferation of machine learning, the cloud server has been employed to collect massive data and train machine learning models. Several privacy-preserving machine learning schemes have been suggested recently to guarantee data and model privacy in the cloud. However, these schemes either mandate the involvement of the data owner in model training or utilize high-cost cryptographic techniques, resulting in excessive computational and communication overheads. Furthermore, none of the existing work considers the malicious behavior of the cloud server during model training. In this paper, we propose the first privacy-preserving and verifiable support vector machine training scheme by employing a two-cloud platform. Specifically, based on the homomorphic verification tag, we design a verification mechanism to enable verifiable machine learning training. Meanwhile, to improve the efficiency of model training, we combine homomorphic encryption and data perturbation to design an efficient multiplication operation for the encryption domain. A rigorous theoretical analysis demonstrates the security and reliability of our scheme. The experimental results indicate that our scheme can reduce computational and communication overheads by at least 43.94% and 99.58%, respectively, compared to state-of-the-art SVM training methods. Chenfei Hu, Chuan Zhang 0003, Dian Lei, Tong Wu 0011, Ximeng Liu, Liehuang Zhu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | EGIA: An External Gradient Inversion Attack in Federated LearningabstractFederated learning (FL) has achieved state-of-the-art performance in distributed learning tasks with privacy requirements. However, it has been discovered that FL is vulnerable to adversarial attacks. The typical gradient inversion attacks primarily focus on attempting to obtain the client’s private input in a white-box manner, where the adversary is assumed to be either the client or the server. However, if both the clients and the server are honest and fully trusted, is the FL secure? In this paper, we propose a novel method called External Gradient Inversion Attack (EGIA) in the grey-box settings. Specifically, we concentrate on the point that public-shared gradients in FL are always transmitted through the intermediary nodes, which has been widely ignored. On this basis, we demonstrate that an external adversary can reconstruct the private input using gradients even if both the clients and the server are honest and fully trusted. We also provide a comprehensive theoretical analysis of the black-box attack scenario in which the adversary has only the gradients. We perform extensive experiments on multiple real-world datasets to test the effectiveness of EGIA. The outcomes of our experiments validate that the EGIA method is highly effective. Haotian Liang, Youqi Li, Chuan Zhang 0003, Ximeng Liu, Liehuang Zhu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Non-Interactive Multi-Client Searchable Symmetric Encryption With Small Client StorageabstractConsiderable attention has been paid to dynamic searchable symmetric encryption (DSSE) which allows users to search on dynamically updated encrypted databases. To improve the performance of real-world applications, recent non-interactive multi-client DSSE schemes are targeted at avoiding per-query interaction between data owners and data users. However, existing non-interactive multi-client DSSE schemes do not consider forward privacy or backward privacy, making them exposed to leakage abuse attacks. Besides, most existing DSSE schemes with forward and backward privacy rely on keeping a keyword operation counter or an inverted index, resulting in a heavy storage burden on the data owner side. To address these issues, we propose a non-interactive multi-client DSSE scheme with small client storage, and our proposed scheme can provide both forward privacy and backward privacy. Specifically, we first design a lightweight storage chain structure that binds all keywords to a single state to reduce the storage cost. Then, we present a Hidden Key technique, which preserves non-interactive forward privacy through time range queries, ensuring that data with newer timestamps cannot match earlier time ranges. We conduct extensive experiments to validate our methods, which demonstrate computational efficiency. Moreover, security analysis proves the privacy-preserving property of our methods. Chang Xu 0004, Rongxing Lu, Liehuang Zhu, Chuan Zhang 0003, Yunguo Guan |
IEEE Trans. Serv. Comput. | 5 |
| 2023 | Non-Interactive DSSE for Medical Data Sharing With Forward and Backward PrivacyabstractIn medical cloud computing, more medical data owners are preferred to outsource their sensitive data to the cloud after encryption. Meanwhile, dynamic searchable symmetric encryption (DSSE) provides the capability for data users to query over the dynamically-updated encrypted database. To reduce update leakage, a secure DSSE scheme usually requires forward and backward privacy. However, existing multi-client DSSE schemes with forward and backward privacy require the data owner to keep online to respond to per-query interaction from data users. To address this issue, we propose a multi-client non-interactive DSSE scheme with forward and backward privacy, namely MCNI. The core design of MCNI is leveraging time range queries to achieve non-interactive forward privacy since the past queries cannot be used to search the newly-added timestamps. To enable efficient time range queries, we convert the timestamp and time range into the boolean wildcard form and develop Boolean Wildcard Matching (BWM) algorithm that formulates the match as a dot product calculation problem. Finally, we combine the polynomial fitting technique, time range query, and random matrix multiplication technique to achieve efficient keyword searches without revealing sensitive information. Theoretical analysis and extensive experiments demonstrate the security and effectiveness of our proposed scheme, respectively. Chang Xu 0004, Liehuang Zhu, Chuan Zhang 0003, Rongxing Lu, Yunguo Guan, Kashif Sharif |
IEEE Trans. Sustain. Comput. | 4 |
| 2022 | Achieving a Blockchain-based Privacy-preserving Quality-aware Knowledge Marketplace in CrowdsensingabstractIt is increasingly popular to utilize the wisdom of the crowd for knowledge discovery and monetization. Most of the existing knowledge marketplaces in crowdsensing are implemented by a third-party platform, which may compromise users' rights and be vulnerable to incurring attacks in practice. To eliminate the untrustworthy behaviors of the third party and improve tolerance for the attacks, some blockchain-based knowledge marketplaces in crowdsensing have been proposed. However, the existing blockchain-based knowledge marketplaces fail to simultaneously guarantee privacy (i.e., data privacy and task privacy) and quality awareness. In this paper, we design a blockchain-based privacy-preserving quality-aware knowledge marketplace (PQKM) based on truth discovery, secure K-nearest neighbor computation, matrix decomposition, and data perturbation. PQKM privately calculates users' data quality and automatically rewards users based on their data quality. Detailed security analysis demonstrates that PQKM can preserve data privacy and task privacy during knowledge discovery and monetization. Extensive experiments are conducted on the open real-world dataset to show that PQKM has acceptable efficiency and affordable performance. Mingyang Zhao 0002, Weiting Zhang, Jinyang Dong, Tong Wu 0011, Chuan Zhang 0003, Liehuang Zhu |
EUC | 7 |
| 2022 | Stealing Secrecy from Outside: A Novel Gradient Inversion Attack in Federated LearningabstractKnowing model parameters has been regarded as a vital factor for recovering sensitive information from the gradients in federated learning. But is it safe to use federated learning when the model parameters are unavailable for adversaries, i.e., external adversaries’ In this paper, we answer this question by proposing a novel gradient inversion attack. Speciffically, we observe a widely ignored fact in federated learning that the participants’ gradient data are usually transmitted via the intermediary node. Based on this fact, we show that an external adversary is able to recover the private input from the gradients, even if it does not have the model parameters. Through extensive experiments based on several real-world datasets, we demonstrate that our proposed new attack can recover the input with pixelwise accuracy and feasible efficiency. Chuan Zhang 0003, Haotian Liang, Youqi Li, Tong Wu 0011, Liehuang Zhu, Weiting Zhang |
ICPADS | 1 |
| 2022 | Privacy-Preserving and Fault-Tolerant Aggregation of Time-Series Data With a Semi-Trusted AuthorityabstractTime-series data aggregation in Internet of Things applications is a useful operation, where the time-series data is sensed by a group of users, and gathered by the aggregator for real-time analysis. However, some security and privacy challenges still affect the collection and aggregation process. Although existing privacy-preserving solutions achieve strong privacy guarantees, they introduce a fully trusted TA that is difficult to realize in the real world. Besides, they cannot be directly applied in time-series data aggregation scenarios due to unacceptable efficiency. In this article, we propose a privacy-preserving time-series data aggregation scheme with a semi-trusted authority. Moreover, our scheme also supports arbitrary aggregate functions and fault tolerance to enhance the reliability and scalability of data aggregation. Security analysis demonstrates that our proposed scheme achieves$(n-k)$-source anonymity even if$k(k\leq (n-2))$data providers collude with the cloud server. We also conduct thorough experiments based on a simulated data aggregation scenario to show the high computation and communication efficiency of our scheme. Chang Xu 0004, Run Yin, Liehuang Zhu, Chuan Zhang 0003, Can Zhang 0002, Kashif Sharif |
IEEE Internet Things J. | 4 |
| 2022 | Reliable and Privacy-Preserving Top-k Disease Matching Schemes for E-Healthcare SystemsabstractThe integration of body sensors, cloud computing, and mobile communication technologies has significantly improved the development and availability of e-healthcare systems. In an e-healthcare system, health service providers upload real patients’ clinical data and diagnostic treatments to the cloud server. Afterward, the users can submit queries with specific body sensor parameters, to obtaining pertinent${k}$diagnostic files. The results are ranked based on ranking algorithms that match the query parameters to the ones in diagnostic files. However, privacy concerns arise while matching disease, since the clinical data and diagnostic files contain sensitive information. In this work, we propose two reliable and privacy-preserving Top-${k}$disease matching schemes. The first scheme is constructed based on our proposed weighted Euclidean distance comparison algorithm under secure${k}$-nearest neighbor technique to get${k}$diagnostic files. It allows users to set different weights for each body indicator as per their needs. The second scheme is designed by comparing Euclidean distances under the modified Paillier homomorphic encryption algorithm where a superlinear sequence is used to reduce the computational and communication overhead. The user side incurs slightly higher computational costs, but the trusted party does not need to execute encryption operations. Hence, the proposed two schemes can be applied in different application scenarios. Simulations on synthetic and real data prove the efficiency of the schemes, and security analysis establishes the privacy-preservation properties. Chang Xu 0004, Liehuang Zhu, Chuan Zhang 0003, Kashif Sharif, Huishu Wu |
IEEE Internet Things J. | 4 |
| 2022 | FRUIT: A Blockchain-Based Efficient and Privacy-Preserving Quality-Aware Incentive SchemeabstractIncentive plays an important role in knowledge discovery, as it impels users to provide high-quality knowledge. To promise incentive schemes with transparency, blockchain technology has been widely used in incentive schemes. Currently, privacy, reliability, streamlined processing, and quality awareness are major challenges in designing blockchain-based incentive schemes. In this paper, we design a blockchain-based eFficient and pRivacy-preserving qUality-aware IncenTive scheme called FRUIT. With well-designed smart contracts, FRUIT achieves privacy, reliability, streamlined processing, and quality awareness during the whole procedure. Specifically, we design a novel lightweight encryption method by combining matrix decomposition with proxy re-encryption and a privacy-preserving task allocation based on the polynomial fitting function and hash function. Then, we leverage our proposed lightweight encryption and task allocation to build an efficient and privacy-preserving knowledge discovery protocol in order to securely calculate the data quality and truthful knowledge. To promise user reliability in the incentive scheme, we utilize the Dirichlet distribution to realize the automatic reputation prediction based on the data quality by deploying the reputation management on the blockchain. Moreover, we also deploy the payment management on the blockchain, endowing the incentive scheme to reward participants based on the data quality automatically. Through a detailed security analysis, we demonstrate that data privacy and task privacy are well preserved during the whole process. Theoretical analysis and extensive experiments on real-world datasets demonstrate that FRUIT has acceptable efficiency and affordable performance in terms of computation cost, communication overhead, and gas consumption. Chuan Zhang 0003, Mingyang Zhao 0002, Liehuang Zhu, Weiting Zhang, Tong Wu 0011, Jianbing Ni |
IEEE J. Sel. Areas Commun. | 1 |
| 2022 | EPDL: An efficient and privacy-preserving deep learning for crowdsensing
Chang Xu 0004, Guoxie Jin, Liehuang Zhu, Chuan Zhang 0003 |
Peer-to-Peer Netw. Appl. | 4 |
| 2022 | Enabling Efficient and Strong Privacy-Preserving Truth Discovery in Mobile CrowdsensingabstractMobile crowdsensing has emerged as a popular platform to solve many challenging problems by utilizing users’ wisdom and resources. Due to user diversity, the data provided by different individuals may vary significantly, and thus it is important to analyze data quality during data aggregation. Truth discovery is effective in capturing data quality and obtaining accurate mobile crowdsensing results. Existing works on truth discovery either cannot protect both task privacy and data privacy, or introduce tremendous computational costs. In this paper, we propose an efficient and strong privacy-preserving truth discovery scheme, named EPTD, to protect users’ task privacy and data privacy simultaneously in the truth discovery procedure. In EPTD, we first exploit the randomizable matrix to express users’ tasks and sensory data. Then, based on the matrix computation properties, we design key derivation and (re-)encryption mechanisms to enable truth discovery to be performed in an efficient and privacy-preserving manner. Through a detailed security analysis, we demonstrate that data privacy and task privacy are well preserved. Extensive experiments based on real-world and simulated mobile crowdsensing applications show EPTD has practical efficiency in terms of computational cost and communication overhead. Chuan Zhang 0003, Mingyang Zhao 0002, Liehuang Zhu, Tong Wu 0011, Ximeng Liu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | Location Privacy-Preserving Task Recommendation With Geometric Range Query in Mobile CrowdsensingabstractIn mobile crowdsensing, location-based task recommendation requires each data requester to submit a task-related geometric range to crowdsensing service providers such that they can match suitable workers within this range. Generally, a trusted server (i.e., database owner) should be deployed to protect location privacy during the process, which is not desirable in practice. In this paper, we propose the location privacy-preserving task recommendation (PPTR) schemes with geometric range query in mobile crowdsensing without the trusted database owner. Specifically, we first propose a PPTR scheme with linear search complexity, named PPTR-L, based on a two-server model. By leveraging techniques of polynomial fitting and randomizable matrix multiplication, PPTR-L enables the service provider to find the workers located in the data requester’s arbitrary geometric query range without disclosing the sensitive location privacy. To further improve query efficiency, we design a novel data structure for task recommendation and propose PPTR-F to achieve faster-than-linear search complexity. Through security analysis, it is shown that our schemes can protect the confidentiality of workers’ locations and data requesters’ queries. Extensive experiments are performed to demonstrate that our schemes can achieve high computational efficiency in terms of geometric range query. Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004, Jianbing Ni, Cheng Huang 0001, Xuemin Shen |
IEEE Trans. Mob. Comput. | 1 |
| 2022 | TDFL: Truth Discovery Based Byzantine Robust Federated LearningabstractFederated learning (FL) enables data owners to train a joint global model without sharing private data. However, it is vulnerable to Byzantine attackers that can launch poisoning attacks to destroy model training. Existing defense strategies rely on the additional datasets to train trustable server models or trusted execution environments to mitigate attacks. Besides, these strategies can only tolerate a small number of malicious users or resist a few types of poisoning attacks. To address these challenges, we design a novel federated learning methodTDFL,TruthDiscovery basedFederatedLearning, which can defend against multiple poisoning attacks without additional datasets even when the Byzantine users are$\geq 50\%$. Specifically, the TDFL considers different scenarios with different malicious proportions. For Honest-majority setting (Byzantine$< 50\%$), we design a special robust truth discovery aggregation scheme to remove malicious model updates, which can assign weights according to users’ contribution; for Byzantine-majority setting (Byzantine$\geq 50\%$), we use maximum clique-based filter to guarantee global model quality. To the best of our knowledge, this is the first study that uses truth discovery to defend against poisoning attacks. It is also the first scheme which can achieve strong robustness under multiple kinds of attacks launched by high proportion attackers without root datasets. Extensive comparative experiments are designed with five state-of-the-art aggregation rules under five types of classical poisoning attacks on different datasets. The experimental results demonstrate that TDFL is practical and achieves reasonable Byzantine-robustness. Chang Xu 0004, Liehuang Zhu, Chuan Zhang 0003, Guoxie Jin, Kashif Sharif |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2022 | TPPR: A Trust-Based and Privacy-Preserving Platoon Recommendation Scheme in VANETabstractVehicle platoon, a novel vehicle driving paradigm that organizes a group of vehicles in the nose-to-tail structure, has been considered as a potential solution to reduce traffic congestion and increase travel comfort. In such a platoon system, head vehicles’ performances are usually evaluated by user vehicles’ feedbacks. Selection of an appropriate and reliable head vehicle while not disclosing user vehicles’ privacy has become an interesting problem. In this article, we present a trust-based and privacy-preserving platoon recommendation scheme, called TPPR, to enable potential user vehicles to avoid selecting the malicious head vehicles. The basic concept of TPPR is that each user vehicle holds a trust value, and the reputation score of the head vehicle is calculated via a truth discovery process. To preserve vehicles’ privacy, pseudonyms and Paillier cryptosystem are applied. In addition, novel authentication protocols are designed to ensure that only the valid vehicles (i.e., the vehicles holding the truthful trust values and joining the vehicle platoon) can pass the authentication. A comprehensive security analysis is conducted to prove that the proposed TPPR scheme is secure against several sophisticated attacks in vehicular ad hoc networks. Moreover, extensive simulations are conducted to demonstrate the correctness and effectiveness of the proposed scheme. Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004, Kashif Sharif, Kai Ding 0008, Ximeng Liu, Xiaojiang Du, Mohsen Guizani |
IEEE Trans. Serv. Comput. | 1 |
| 2022 | Dynamic Data Transaction in Crowdsensing Based on Multi-Armed Bandits and Shapley ValueabstractCrowdsensing gradually forms a big data market where workers are willing to trade reusable data with different data collectors. It is challenging for the data collector to choose the transaction party due to the changeable value of the data, while determining the transaction price is also a tough issue. In this paper, we research the dynamic data transaction in crowdsensing. The contribution of the new data to the collector is modeled as the Shapley value, with each worker as a player in the cooperative game. The data collector then judges the contribution of the worker and determines the transaction object. To maximum the profit in the transaction, the collector will dynamically adjust the offering price to workers. The contextual bandit model is utilized in the price decision, with each candidate price as an arm and the time-variant data value as the context. Based on the classic LinUCB learning policy, we learn the mapping of the observed data value and the reward, and estimate the optimal reward in current transaction. The simulation on the data demonstrates that the actual reward got by the collector is close to the maximum reward he can get, which verifies the effectiveness of our scheme. Chang Xu 0004, Yayun Si, Liehuang Zhu, Chuan Zhang 0003, Kashif Sharif, Huishu Wu |
IEEE Trans. Sustain. Comput. | 4 |
| 2021 | V-EPTD: A Verifiable and Efficient Scheme for Privacy-Preserving Truth Discovery
Chang Xu 0004, Hongzhou Rao, Liehuang Zhu, Chuan Zhang 0003, Kashif Sharif |
ICA3PP (3) | 4 |
| 2021 | Achieving Efficient and Privacy-preserving Biometric Identification in Cloud ComputingabstractBiometrics identification has been used in a growing number of fields in recent years, since it is more secure, classified and convenient. With the development of cloud computing, database systems are able to upload large amounts of biometric data to cloud server for storage and identification to save local memory and improve computational efficiency. However, this involves potential privacy concerns because of the introduction of third-party platforms. In this paper, we achieve computational and communication efficiency in biometric identification, while preserving the privacy of data. Specifically, the database system firstly encrypts all biometric data and query data. Then, it sends the ciphertext to a cloud server to carry out matching tasks. Finally, the cloud server returns the index of final matches to the system so that it can check whether the biometric vector is legal or not. Detailed security analysis indicates that the proposed scheme can resist powerful attacks. Beyond that, Experiments show that the scheme is more efficient in computation and communication than stat of art biometric identification schemes. Chang Xu 0004, Lvhan Zhang, Liehuang Zhu, Chuan Zhang 0003, Kashif Sharif |
TrustCom | 4 |
| 2021 | Enabling privacy-preserving multi-level attribute based medical service recommendation in eHealthcare systems
Chang Xu 0004, Jiachen Wang 0006, Liehuang Zhu, Kashif Sharif, Chuan Zhang 0003, Can Zhang 0002 |
Peer-to-Peer Netw. Appl. | 5 |
| 2021 | Reliable and Privacy-Preserving Truth Discovery for Mobile Crowdsensing SystemsabstractTruth discovery has received considerable attention in mobile crowdsensing systems. In real practice, it is vital to resolve conflicts among a large amount of sensory data and estimate the truthful information. Although truth discovery has been widely explored to improve aggregation accuracy, numerous security and privacy issues still need to be addressed. Existing schemes either do not guarantee the privacy of each participating user, or fail to consider practical needs in crowdsensing systems. In this paper, we present two reliable and privacy-preserving truth discovery schemes for different scenarios. Our first design is fit for applications where users are relatively stable. By employing the homomorphic Paillier encryption, one-way hash chain, and super-increasing sequence techniques, this approach not only guarantees strong privacy, but also is highly efficient and practical. Our second design suits applications where users are frequently moving. In such an application, we explore data perturbation and homomorphic Paillier encryption to shift all user workloads to the server side, without compromising users' privacy. Through detailed security analysis, we demonstrate that both schemes are secure, practical, and privacy-preserving. Moreover, extensive experiments based on real world and simulated mobile crowdsensing systems, we demonstrate the efficiency of our proposed schemes. Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004, Ximeng Liu, Kashif Sharif |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | A Privacy-Preserving Location-Aware and Traffic Order-Based Route Collection Scheme in VANETsabstractCollecting driving routes is effective in predicting traffic patterns and alleviating traffic jams. However, due to the sensitivity of the location information, drivers are usually reluctant to share their route information. Although some efforts have been made to address this challenge, most of them either do not consider traffic order issues or fall short of achieving practical efficiency. In this paper, we propose an efficient and privacy-preserving route collection scheme, named EPRC, to solve the above-mentioned problems. The main idea of EPRC is to perform location-aware and traffic order-based route aggregation on drivers' encrypted data using super-increasing sequences and a homomorphic encryption cryptosystem. The proposed scheme achieves better computation and communication efficiency by reducing computational complexity and communication overhead from O(M) to O(1), where M denotes the number of road segments. Security analysis demonstrates the privacy of an individual driver's route is preserved under standard cryptographic assumptions. Performance evaluations via implementing EPRC on mobile devices and systems show EPRC's efficiency in terms of computation and communication costs. Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004, Kashif Sharif |
GLOBECOM | 1 |
| 2020 | Efficient and Privacy-Preserving Non-Interactive Truth Discovery for Mobile CrowdsensingabstractTruth discovery is one of the key technologies to extract truthful information from unreliable sensory data collected by different mobile devices in mobile crowdsensing, but the sensory data and the outputs of truth discovery (i.e., truths and mobile devices' weights) may contain sensitive information and cause serious privacy concerns. In this paper, we propose an efficient and privacy-preServing non-interActive Truth discovEry scheme (SATE) in mobile crowdsensing. Specifically, SATE is designed based on a two-cloud model. First, the sensory data is encoded into two parts (i.e., perturbed data and noises) at the mobile device, which are maintained by two clouds separately. Second, by utilizing an adapted distributed public key homomorphic cryptosystem, two clouds can co-operatively exchange the intermediate weights and truths in a privacy preserving manner and thus achieve privacy-preserving truth discovery without the participation of the mobile devices. Security analysis demonstrates that SATE can provide full privacy protection for sensory data, weights, and truths. Performance evaluation also shows that SATE can achieve high computational efficiency and low communication overhead on the mobile devices, since there is no time-consuming cryptographic operation involved. Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004, Jianbing Ni, Cheng Huang 0001, Xuemin Shen |
GLOBECOM | 1 |
| 2020 | PPLS: a privacy-preserving location-sharing scheme in mobile online social networks
Chang Xu 0004, Liehuang Zhu, Kashif Sharif, Chuan Zhang 0003, Xiaojiang Du, Mohsen Guizani |
Sci. China Inf. Sci. | 5 |
| 2020 | An efficient and privacy-preserving truth discovery scheme in crowdsensing applications
Chuan Zhang 0003, Chang Xu 0004, Liehuang Zhu, Can Zhang 0002, Huishu Wu |
Comput. Secur. | 1 |
| 2020 | Aggregate in my way: Privacy-preserving data aggregation without trusted authority in ICN
Chang Xu 0004, Lvhan Zhang, Liehuang Zhu, Chuan Zhang 0003, Xiaojiang Du, Mohsen Guizani, Kashif Sharif |
Future Gener. Comput. Syst. | 4 |
| 2020 | PGAS: Privacy-preserving graph encryption for accurate constrained shortest distance queries
Can Zhang 0002, Liehuang Zhu, Chang Xu 0004, Kashif Sharif, Chuan Zhang 0003, Ximeng Liu |
Inf. Sci. | 5 |
| 2019 | LPTD: Achieving lightweight and privacy-preserving truth discovery in CIoT
Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004, Kashif Sharif, Xiaojiang Du, Mohsen Guizani |
Future Gener. Comput. Syst. | 1 |
| 2019 | Pay as How You Behave: A Truthful Incentive Mechanism for Mobile CrowdsensingabstractMobile crowdsensing (MCS) is widely applied in large-scale distributed networks for collecting sensing data from workers. In an MCS system, workers are recruited to complete tasks for data requesters, and they will get profits. Accordingly, how to establish an effective incentive mechanism has become an important issue to consider. Since workers are naturally selfish, they try to maximize individual benefits while minimize costs. In this article, we propose a truthful incentive mechanism which pays for the workers by the workers' performance in the task just completed and the reputation. For each worker, through the future prediction function, we get the reputation of the worker by utilizing the previous performances. In the proposed scheme, partial payment for the workers is distributed depending on workers' reputation. The final payment is based on punishments and rewards according to the performances. Moreover, data accuracy and response time are introduced to evaluate the worker performance in the task. It can be demonstrated that the mechanism provides continuous incentives to workers compared to the single ex-ante and ex-post pricing schemes. The experimental results show that our mechanism is effective. Chang Xu 0004, Yayun Si, Liehuang Zhu, Chuan Zhang 0003, Kashif Sharif, Can Zhang 0002 |
IEEE Internet Things J. | 4 |
| 2019 | Achieving Searchable and Privacy-Preserving Data Sharing for Cloud-Assisted E-Healthcare SystemabstractThe integration of wearable wireless devices and cloud computing in e-health systems has significantly improved their effectiveness and availability. Patients can upload their personal health information (PHI) files to the cloud, from where the health service providers (HSPs) can obtain appropriate information to determine the health state. This system not only reduces the costs associated to healthcare but also provides timely diagnosis to save lives. However, a number of privacy concerns arise while sharing sensitive information. In this paper, we propose a novel privacy-preserving patient health information sharing scheme, which allows HSPs to access and search PHI files in a secure yet efficient manner. We make use of the searchable encryption technique with keyword range search and multikeyword search. The proposed privacy-preserving equality test protocol allows different types of numeric comparison searches on encrypted data. We also use a variant of bloom filter and message authentication code to classify PHI files, filter false data, and check integrity of search results. The simulations on real-world and synthetic data show the feasibility and efficiency of the system, and security analysis proves the privacy-preservation properties. Chang Xu 0004, Liehuang Zhu, Kashif Sharif, Chuan Zhang 0003 |
IEEE Internet Things J. | 5 |
| 2019 | PPMR: A Privacy-Preserving Online Medical Service Recommendation Scheme in eHealthcare SystemabstractWith the continuous development of eHealthcare systems, medical service recommendation has received great attention. However, although it can recommend doctors to users, there are still challenges in ensuring the accuracy and privacy of recommendation. In this paper, to ensure the accuracy of the recommendation, we consider doctors' reputation scores and similarities between users' demands and doctors' information as the basis of the medical service recommendation. The doctors' reputation scores are measured by multiple feedbacks from users. We propose two concrete algorithms to compute the similarity and the reputation scores in a privacy-preserving way based on the modified Paillier cryptosystem, truth discovery technology, and the Dirichlet distribution. Detailed security analysis is given to show its security prosperities. In addition, extensive experiments demonstrate the efficiency in terms of computational time for truth discovery and recommendation process. Chang Xu 0004, Jiachen Wang 0006, Liehuang Zhu, Chuan Zhang 0003, Kashif Sharif |
IEEE Internet Things J. | 4 |
| 2019 | SUAA: A Secure User Authentication Scheme with Anonymity for the Single & Multi-server Environments
Nassoro M. R. Lwamo, Liehuang Zhu, Chang Xu 0004, Kashif Sharif, Ximeng Liu, Chuan Zhang 0003 |
Inf. Sci. | 6 |
| 2019 | PPTDS: A privacy-preserving truth discovery scheme in crowd sensing systems
Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004, Kashif Sharif, Ximeng Liu |
Inf. Sci. | 1 |
| 2018 | A New Satellite Constellation Networking Certification and Reliable Maintenance Protocol (S)abstractWith the rapid development of satellite technology, the deployment of intensive service applications through satellite has become a trend.In the process of establishing a satellite communication system, there will be some security threats such as counterfeiting, forgery, tampering.This must establish a secure satellite communication system.In this paper, according to the characteristics of satellite communication system, a protocol of satellite network authentication and trusted maintenance is designed.The protocol can accomplish two-way authentication between entities in the satellite network and the credible maintenance of the communication link.The protocol is based on the symmetric encryption system and can adapt to the current satellite load is small, the computing power is limited.This paper also analyses the security of the protocol and can resist replay attacks and man-in-the-middle attacks.Experiments show that the proposed network authentication protocol is 28% faster than the symmetric encryption system.The average time to keep the agreement credible is 254.64 ms. Congyu Huang, Liehuang Zhu, Chunlei Li 0003, Chuan Zhang 0003, Zijian Zhang 0001 |
SEKE | 4 |
| 2018 | PPDP: An efficient and privacy-preserving disease prediction scheme in cloud-based e-Healthcare system
Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004, Rongxing Lu |
Future Gener. Comput. Syst. | 1 |
| 2018 | PRIF: A Privacy-Preserving Interest-Based Forwarding Scheme for Social Internet of VehiclesabstractRecent advances in socially aware networks (SANs) have allowed its use in many domains, out of which the Social Internet of Vehicles (SIOV) is of prime importance. SANs can provide a promising routing and forwarding paradigm for SIOV by using interest-based communication. Though able to improve the forwarding performance, existing interest-based schemes fail to consider the important issue of protecting users' interest information. In this paper, we propose a privacy-preserving interest-based forwarding scheme (PRIF) for SIOV, which not only protects the interest information but also improves the forwarding performance. We propose a privacy-preserving authentication protocol to recognize communities among mobile nodes. During data routing and forwarding, a node can know others' interests only if they are affiliated with the same community. Moreover, to improve forwarding performance, a new metric community energy is introduced to indicate vehicular social proximity. Community energy is generated when two nodes encounter one another and information is shared among them. PRIF considers this energy metric to select forwarders toward the destination node or the destination community. Security analysis indicates PRIF can protect nodes' interest information. In addition, extensive simulations have been conducted to demonstrate that PRIF outperforms the existing algorithms, including the BEEINFO, Epidemic, and PRoPHET. Liehuang Zhu, Chuan Zhang 0003, Chang Xu 0004, Xiaojiang Du, Rixin Xu, Kashif Sharif, Mohsen Guizani |
IEEE Internet Things J. | 2 |
| 2018 | Scalable and Privacy-Preserving Data Sharing Based on Blockchain
Baokun Zheng, Liehuang Zhu, Meng Shen 0001, Feng Gao 0019, Chuan Zhang 0003, Yandong Li |
J. Comput. Sci. Technol. | 5 |
| 2017 | PTBI: An efficient privacy-preserving biometric identification based on perturbed term in the cloud
Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004 |
Inf. Sci. | 1 |