Xuru Li

dblp:233/9348 · DBLP profile ↗
← Back
8ranked-venue papers
2as first author
8since 2021 · last 2026
0000-0003-0027-0142ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 4 since 2021Security and privacy · 4 · 2 first-author · 4 since 2021
YearPublicationVenuePosition
2026 $\mathsf{AnniMask}$ : Efficient and Dynamic Secure Aggregation Based on Double-Point Annihilation Mask
abstract
Existing secret sharing-based secure aggregation protocols suffer from high overhead and inflexibility in handling dynamic clients. To address these issues, this paper introduces AnniMask, an efficient and dynamic secure aggregation protocol. By replacing conventional secret sharing with a double-point annihilation function for mask generation, AnniMask reduces the state-of-the-art aggregation overhead fromO(nlog2n) in computation andO(nlogn) in communication to linear. Moreover, the protocol achieves linear complexity for handling dynamic clients, representing a progressive improvement over previous approaches. Crucially, AnniMask remains robust under arbitrary client dropout rates, whereas the tolerance of existing masking schemes is fundamentally limited by their secret sharing threshold. Formal security analysis proves that AnniMask provides stronger resilience against collusion attacks while ensuring privacy and integrity. Comprehensive experimental results demonstrate that AnniMask achieves superior efficiency while maintaining high model accuracy, showcasing its robustness even under a client dropout rate as high as 90%.
Jianguo Shen, Xuru Li, Lifei Wei, Jianting Ning
IEEE Internet Things J.2
2026 NiIas: Non-Interactive Instant Authentication and Secure Data Delivery Protocol for Multi-Access Edge Computing
abstract
The inherent heterogeneity and mobility of Multi access Edge Computing (MEC) necessitate security protocols that ensure instant connectivity while maintaining resilience against resource exhaustion. This paper presents NiIas, a non-interactive instant authentication and secure data delivery proto col. Unlike conventional protocols that require prior handshakes, NiIas enables immediate payload transmission without session resumption delays. The protocol leverages a multi-authorization identity-based cryptosystem to decentralize trust and eliminate certificate management overhead. Furthermore, NiIas employs an authenticate-before-decryption mechanism as a lightweight admission control. This design filters unauthorized traffic prior to decryption and effectively protects edge verifiers from denial of-service attacks. Rigorous security analysis formally establishes the protocol's cryptographic guarantees. Moreover, numerical simulations on resource-constrained devices and M/D/1 queuing theoretic analysis demonstrate that NiIas achieves superior availability and stability compared to state-of-the-art protocols.
Xuru Li, Daojing He, Lifei Wei, Sammy Chan, Kim-Kwang Raymond Choo, Dezhi Han
IEEE Trans. Dependable Secur. Comput.1
2024 GSASG: Global Sparsification With Adaptive Aggregated Stochastic Gradients for Communication-Efficient Federated Learning
abstract
This article addresses the challenge of communication efficiency in federated learning by the proposed algorithm called global sparsification with adaptive aggregated stochastic gradients (GSASGs). GSASG leverages the advantages of local sparse communication, global sparsification communication, and adaptive aggregated gradients. More specifically, we devise an efficient global top-$k^{\prime }$sparsification operator. By applying this operator to the aggregated gradients obtained from the top-k sparsification, the global model parameter is rarefied to reduce the download transmitted bits from$O(dMT)$to$O(k^{\prime }MT)$, where d is the dimension of the gradient, M is the number of workers, T is the total number of epochs, and$k^{\prime } \leq k\lt d$. Meanwhile, the adaptive aggregated gradient method is adopted to skip meaningless communication and reduce communication rounds. The deep neural network training experiment demonstrates that, compared to the previous algorithms GSASG significantly reduces communication cost without sacrificing the model performance. For instance, when considering the MNIST data set with$k=1\% d$and$k^{\prime }=0.5\% d$, in terms of communication rounds, GSASG outperforms sparse communication by 91%, adaptive aggregated gradients by 90%, and the combination of sparse communication with adaptive aggregated gradients by 56%. In terms of communication bits, GSASG yields 1% of the communication bits needed with previous algorithms.
Runmeng Du, Daojing He, Zikang Ding, Sammy Chan, Xuru Li
IEEE Internet Things J.6
2024 A Lightweight and Secure Communication Protocol for the IoT Environment
abstract
Ensuring secure communications for the Internet of Things (IoT) systems remains a challenge. Due to exacting resource limitations of computing, memory, and communication in IoT environments, communication schemes based on asymmetric cryptographic systems can be challenging to deploy. An alternative is to deploy symmetric encryption schemes based on pre-shared keys. However, there are also challenges in designing such schemes and examples include how to achieve an optimal trade-off between security and performance levels while meeting resource consumption requirements. Hence, this paper presents a lightweight key synchronization update algorithm, which is then used as a building block in our proposed lightweight secure communication protocol. The security of the protocol is analyzed to show that it can resist common attacks, such as replay attacks, and man-in-the-middle attacks. We then use Tamarin, a widely accepted security protocol verification tool, for formal verification. In addition, we evaluate the randomness and computational performance of the lightweight key synchronization update algorithm and demonstrate that it outperforms other schemes. We also evaluate the performance of the protocol, in terms of computational and communication costs, to demonstrate utility.
Zikang Ding, Daojing He, Qi Qiao, Xuru Li, Sammy Chan, Kim-Kwang Raymond Choo
IEEE Trans. Dependable Secur. Comput.4
2024 Toward Secure and Verifiable Hybrid Federated Learning
abstract
Reducing computation cost and ensuring update integrity, are key challenges in federated learning (FL). In this paper, we present a secure and verifiable hybrid FL system for training, namely SVHFL. SVHFL enables training models on both plaintext and encrypted data simultaneously. Furthermore, we propose a mutual verification scheme for the integrity of updates in FL. It is a general and efficient scheme that can eliminate malformed updates from clients and enforce the integrity checks of the aggregation results from the server. The training and verification schemes of SVHFL have reduced the computation cost from a quadratic cost to a linear cost. The experimental results demonstrate the practicality of SVHFL.
Runmeng Du, Xuru Li, Daojing He, Kim-Kwang Raymond Choo
IEEE Trans. Inf. Forensics Secur.2
2023 LIGHT: Lightweight Authentication for Intra Embedded Integrated Electronic Systems
abstract
As embedded integrated electronic systems (EIESs) become more pervasive (including in mission-critical applications), the need to ensure the security of data exchange in such a system against various malicious activities becomes more pronounced. However, designing secure and efficient solutions, such as authentication protocols, for the many different embedded systems with varying internal communication modes remains challenging. Therefore, in this paper, we propose a lightweight authenticated key-exchange (AKE) protocol for EIESs based on half-duplex and “command/response” bus. Specifically, the proposed protocol is designed to operate on resource-constrained devices, as well as having minimal number of interactions. We then prove the security of the proposed protocol and present the security parameter selection strategy for protocol implementation based on the empirical evaluations. Moreover, efficiency analysis also shows that the protocol can be effectively deployed in the EIESs environment.
Xuru Li, Daojing He, Ximeng Liu, Sammy Chan, Manghan Pan, Kim-Kwang Raymond Choo
IEEE Trans. Dependable Secur. Comput.1
2022 Design and Formal Analysis of a Lightweight MIPv6 Authentication Scheme
abstract
The emergence of mobile IPv6 (MIPv6) significantly affected how we live and work, while it still faces more security threats than traditional wireless networks. On the other hand, most mobile devices have constrained computing and storage resources. The network environment is complex, and the network topology also changes very frequently. Although various security protocols have been proposed for authentication in MIPv6, there are still some challenges. First, most of the subsisting authentication schemes cannot work in resource-constrained environments. Second, each of these authentication protocols has some defects, which may lead to serious consequences. So it is valuable and crucial to conduct security analysis at the design stage of protocols. Currently, most researchers attempt adopting informal methods, which are not as effective and suitable as formal methods. Some researchers have been conscious of the advantages of using formal methods to verify protocols. However, the approaches are too complex to understand for those who are not familiar with formal methods. In light of these challenges, we propose a lightweight MIPv6 authentication scheme for environments with low resources. We conduct a security analysis and performance comparison of the proposed authentication scheme. In particular, we use the SVO logic to formally analyze its security. We also explain how to use this formal method, which can be regarded as an example to better illustrate the application of formal analysis in MIPv6 authentication schemes.
Daojing He, Xuru Li, Sammy Chan, Mohsen Guizani
IEEE Internet Things J.3
2021 A Lightweight Certificateless Non-interactive Authentication and Key Exchange Protocol for IoT Environments
abstract
In order to protect user privacy and provide better access control in Internet of Things (IoT) environments, designing an appropriate two-party authentication and key exchange protocol is a prominent challenge. In this paper, we propose a lightweight certificateless non-interactive authentication and key exchange (CNAKE) protocol for mutual authentication between remote users and smart devices. Based on elliptic curves, our lightweight protocol provides high security performance, realizes non-interactive authentication between the two entities, and effectively reduces communication overhead. Under the random oracle model, the proposed protocol is provably secure based on the Computational Diffie-Hellman and Bilinear Diffie-Hellman hardness assumption. Finally, through a series of experiments and comprehensive performance analysis, we demonstrate that our scheme is fast and secure.
Menghan Pan, Daojing He, Xuru Li, Sammy Chan, Emmanouil A. Panaousis
ISCC3