Xiangli Xiao

dblp:241/3076 · DBLP profile ↗
← Back
30ranked-venue papers
7as first author
29since 2021 · last 2026
0000-0002-3250-0603ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 14 · 3 first-author · 13 since 2021Graphics, computer vision, multimedia, augmented reality and games · 8 · 1 first-author · 8 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Towards trustworthy management of AIGC copyright: blockchain-enabled full lifecycle recording and multi-party auditing approach
abstract
Abstract With the escalating proliferation of artificial intelligence technologies, AI-generated content (AIGC) has progressively permeated across diverse domains. However, this explosive application has also sparked widespread public discussion about the copyright of AIGC. Existing copyright legal frameworks, originally designed around human creators, now face a paradigm shift. As human involvement in the generation of AIGC diminishes, where creative expression increasingly hinges on AI. This discrepancy has introduced multifaceted complexities and challenges in determining the copyright ownership of AIGC within established legal boundaries. Given this, meticulous recording and auditing of contributions from all parties in AIGC generation becomes imperative. Blockchain, with its decentralized storage, offers a robust technical foundation for AIGC copyright management. Yet existing blockchain-based solutions have clear limitations: most only focus on certifying final generated products, ignoring the management of critical intermediate data across the full lifecycle, thus failing to meet the needs of core scenarios like copyright confirmation and multi-party profit distribution. For this purpose, this paper introduces AIGC-Chain, a trustworthy AIGC copyright management system. It conducts a comprehensive recording of intermediate data generated across the full lifecycle of AIGC. Such data is deposited into a decentralized blockchain for secure multi-party auditing, thereby constructing a trustworthy management for AIGC copyright. In copyright dispute scenarios, auditors can retrieve critical proof from the blockchain, facilitating precise determination of the copyright ownership of AIGC products. Both theoretical and experimental analyses confirm that this scheme shows exceptional performance and security in AIGC copyright management.
Moting Su, Aiqun Wu, Fengshu Li, Xiangli Xiao, Yushu Zhang 0001
Cybersecur.5
2026 FLSAMW: Mitigating backdoor attacks in federated learning based on SVD and amplified model weight
Xingxing Xiong, Zuowen Tan, Xiangli Xiao, Xiaojie Tao, Mengjun Liu
J. Syst. Archit.4
2026 Unlocking the Metaverse: A Gateway to Multiplayer Game via 3-D Object Security Technologies
abstract
Due to the widespread use of 3D objects, they gradually matter in various fields. Selective encryption and secret sharing are common methods to protect 3D objects. However, currently, there is no existing work that integrates these two methods into a unified scheme for 3D objects. This paper proposes a technological scheme tailored for the initial stage of metaverse games, serving as a gateway for players to embark on their game adventure. In this scheme, encryption and secret sharing technologies are harmoniously integrated, not only exploring innovative applications in the realm of 3D object security but also potentially paving the way for future research that bridges the metaverse games and 3D object security domains. Experimental results confirm the feasibility and effectiveness of the proposed scheme, further highlighting its robust adaptability across diverse representations of 3D objects without incurring any additional ciphertext expansion during its processing.
Xiangli Xiao, Qingxiao Guan, Yushu Zhang 0001
IEEE Trans. Games2
2026 Building an Invisible Shield to Enable Traceable Privacy Protection for Medical Images in Telemedicine
abstract
As telemedicine continues to expand, the frequent transmission and sharing of medical images over networks has become central to remote diagnostics. However, these images often contain sensitive lesion information. Once they are illicitly obtained during transmission or storage, they can be misused to train malicious segmentation models, resulting in serious patient privacy violations. While encryption and steganography provide basic protection, encrypted content may draw adversarial attention, and some stego-images may be exposed due to abnormal formats or semantics. More critically, most existing modes lack traceability, making it difficult to identify the source once a privacy breach occurs. To address these challenges, we present a traceable robust adversarial watermarking model that acts as an invisible shield to protect medical image privacy in telemedicine scenarios. This model seamlessly integrates invisibility, privacy protection, and traceability into a unified watermark embedding framework, enabling proactive defense against segmentation-based attacks while maintaining diagnostic quality. Specifically, receiver identity information is embedded into medical images through adversarial perturbations. These perturbations suppress lesion extraction by attackers while allowing reliable identity decoding in case of data leakage. Experimental results show that the model achieves strong privacy protection on various polyp and ISIC datasets. Moreover, the model maintains reliable ID extraction under different noise perturbations, validating its robustness and traceability. Visual quality assessments further confirm the invisibility of the embedded watermark, Ensuring that diagnostic usability remains unaffected. This provides a promising direction for safeguarding medical image privacy in telemedicine environments.
Wenying Wen, Xiangli Xiao, Xuji Tu, Yushu Zhang 0001
IEEE Trans. Circuits Syst. Video Technol.3
2026 I've Got Proof! Dataset-Specific Watermarking for Detecting Excessive Dataset Usage in Text-to-Image Diffusion Model Fine-Tuning
abstract
Currently, text-to-image diffusion models, which exhibit remarkable proficiency in image generation, have prompted the emergence of diverse fine-tuning methodologies due to the considerable resource demands entailed in their training. Simultaneously, apprehensions have arisen regarding the excessive utilization of open-source datasets for fine-tuning the models. Therefore, intellectual property protection for such datasets is important and necessary. In this regard, watermarking is a commonly employed method. However, the existing watermarking methods fail to establish an accurate correspondence between the watermarked dataset and the malicious model, which may lead to erroneous accusations against the model. In this paper, we propose a dataset-specific watermarking method, DSW, to detect excessive usage of protected datasets by suspect diffusion models fine-tuned using LoRA. DSW can establish a one-to-one correspondence between the watermarked dataset and the malicious model, thereby enhancing the accuracy of intellectual property verification. We simultaneously train an encoder and a decoder based on a bi-level optimization strategy. The encoder embeds a watermark image, which symbolizes the dataset owner's identity, into the dataset samples to yield a watermarked dataset. For a text-to-image diffusion model fine-tuned on this watermarked dataset, the decoder extracts the watermark from the generated image. Comprehensive experiments validate the availability, effectiveness, and stealthiness of DSW. The code is available athttps://github.com/hzhwis/DSW.
Xiangli Xiao, Yushu Zhang 0001, Yuming Fang 0001
IEEE Trans. Dependable Secur. Comput.2
2026 Non-Iterative Reversible Information Hiding in the Sharing Domain With Adjustable Capacity
Kaili Qi, Jibin Yang, Tieyong Cao, Xiangli Xiao, Xiongwei Zhang, Yushu Zhang 0001, Zehang Wang
IEEE Trans. Dependable Secur. Comput.4
2026 Medical Archive in an Image: Generating a High-Capacity Customizable Cover Image for Medical Privacy Protection
abstract
The rapid development of medical information technology promotes the popularization of telemedicine. With remote transmission of patient archives, medical institutions can provide more efficient diagnostic service. Because of the highly sensitive nature of medical data, medical archives typically require the support of encryption to prevent leakage of patient privacy. However, the encrypted archives visually appear as snowflake-like noise, which is easily perceived by an attacker and thus appealing to the crack. In this paper, we propose an imperceptible medical archive construction scheme, which can hide personal medical data in a high-capacity customizable cover image, thus making it impossible for attackers to perceive its presence. Specifically, we first conduct a fusion of multimodal medical image data, integrating image information from various imaging techniques into a unified image, thereby enhancing diagnostic efficacy. Secondly, a high-capacity customizable cover image is generated based on the patient facial mask. Lastly, the unified image with patient demographic information is hidden in the cover image to construct the imperceptible medical archive. To enhance the hiding capacity of the cover image, we propose a Collaborative Steganography Generation Model (CSGM), which increases the low-frequency components during image synthesis, enabling more data to be embedded while maintaining high visual quality. CSGM also supports identity-aware customization using facial structure and semantic text. Experiments show that CSGM improves the PSNR of stego images by 6.95 dB and the PSNR of recovered secret images by 2.98 dB compared to state-of-the-art methods, confirming its effectiveness in imperceptibility and data recovery.
Wenying Wen, Zhouxin Wu, Yushu Zhang 0001, Tao Wang 0084, Xiangli Xiao, Yuming Fang 0001
IEEE Trans. Dependable Secur. Comput.5
2026 DeVIL: A Dual Verification Framework for Integrity and Ownership of Light Field Images With Customizable Watermarking
abstract
Light field (LF) images capture both spatial and angular data, providing enhanced detail in multi-view and 3D scenes, which makes them highly applicable across various domains. Thus, compared to traditional images, LF images not only contain more complex data and are more susceptible to unauthorized tampering or malicious uses during transmission due to their unique structure, thereby increasing the need for verification. Existing dual watermarking techniques are designed for single-view images and lack adaptability to the multi-view structure and geometric consistency of LF images, making it difficult to simultaneously address integrity verification and ownership verification for LF images. Given the multi-view characteristics and geometric consistency of LF images, there is an urgent need for a highly robust and adaptable dual watermarking method. Therefore, we propose a dual verification framework with customizable watermarking, called DeVIL, which specifically designed for LF images and enables both ownership and integrity verification. By embedding reversible ownership watermarks into the sub-aperture images (SAIs), affiliation can be verified after transmission. Among them, the embedding technique can flexibly choose either a reversible robust watermarking technique or a robust zero-watermarking technique based on different application scenarios. Subsequently, we perform Arnold transformation on key SAIs and embed them into non-key SAIs to create stego images, effectively reducing the risk of information leakage. Furthermore, integrity watermarks are embedded in the stego images, forming stego images with integrity watermarks to detect subtle tampering during transmission. Experimental results show that DeVIL can successfully recover SAIs and demonstrates strong robustness and adaptability against various attacks. Compared to state-of-the-art methods, DeVIL reduces the average bit error rate by 9.32% under different attacks, with average normalized cross-correlation improvement of 0.17, significantly enhancing the robustness of ownership protection in different datasets.
Wenying Wen, Xiangli Xiao, Yuming Fang 0001, Yushu Zhang 0001
IEEE Trans. Dependable Secur. Comput.3
2026 A Dual-Protection Method for 3D Object Security and Copyright: Watermark Embedding During Decryption
abstract
With advancements in the computer industry, 3D objects are now widely used in various applications, including game development, animation production, and industrial design. This growing adoption has increased the need for effective content security and copyright protection for 3D objects. However, existing encryption and watermarking techniques often operate independently, leading to low efficiency and weak coupling between security and copyright protection. To address these gaps, this paper presents a novel method that integrates watermark embedding into the 3D object decryption process, simultaneously ensuring content security and copyright protection. Specifically, a Look-Up Table (LUT)-based encryption method is employed to secure 3D object data, while a Spread Transform Dither Modulation (ST-DM)-based watermarking method is used to embed user-specific identity information during decryption. Unlike conventional approaches that apply encryption and watermarking separately, the proposed method enables efficient 3D object sharing, as the owner only needs to encrypt the object once, regardless of the number of authorized users. The encrypted model can then be distributed securely via multicast and caching. Decryption with personalized keys produces distinct watermarked 3D objects, allowing for reliable traceability of unauthorized redistribution. Experimental results and theoretical evaluations demonstrate that the proposed method delivers satisfactory visual quality, efficiency, robustness, and security.
Xiangli Xiao, Yushu Zhang 0001, Zhongyun Hua, Wenying Wen, Yuming Fang 0001
IEEE Trans. Dependable Secur. Comput.1
2026 Tracing the Use of Open-Source Training Datasets for Neural Radiance Field Models
Yushu Zhang 0001, Xiangli Xiao, Zhongyun Hua, Yuming Fang 0001
IEEE Trans. Inf. Forensics Secur.3
2026 Revealing Photoshop Inpainting Traces Under JPEG Compressions
abstract
Photoshop inpainting has become one of the most challenging targets in image forensics, as its content-aware and patch-based editing mechanisms produce visually coherent manipulations with weak and localized forensic artifacts. This difficulty is further amplified by JPEG compression, which is routinely introduced during online transmission and tends to suppress the high-frequency tampering traces on which existing forensic detectors largely depend. As a result, current methods face an inherent trade-off: Photoshop-oriented detectors provide strong discriminability under clean conditions but lack robustness to compression, whereas compression-robust forensic methods often fail to capture subtle inpainting artifacts. To overcome this tension, this paper proposes a JPEG-resistant Photoshop inpainting localization method based on multi-frequency representation. The proposed framework employs a set of parameterized frequency-selective filters to extract complementary representations across multiple spectral bands. Each frequency branch is trained independently as a dedicated detector, and a fusion module integrates their outputs to generate a comprehensive localization map that balances discriminability and robustness. A theoretical analysis in the frequency domain is further provided to explain how low-frequency representations remain stable under JPEG-induced attenuation, supporting the design rationale of the proposed framework. In addition, a multi-quality JPEG augmentation strategy is adopted during training to mitigate the mismatch between training and testing compression levels. Extensive experiments on both script-created and hand-created Photoshop inpainting datasets demonstrate that the proposed method consistently outperforms representative forgery localization methods under various JPEG compression strengths. We further evaluate the method on images transmitted through Wechat, Weibo, and Twitter, confirming its effectiveness in practical online social network scenarios. These results demonstrate that the proposed multi-frequency representation strategy offers a principled and effective approach to robust image forensic analysis.
Yushu Zhang 0001, Xiangli Xiao, Wenying Wen
IEEE Trans. Image Process.4
2026 Combating Free-Riding in AIGC Service System: A Decentralized Reputation-Based Model Management Approach
abstract
Blockchain strengthens copyright protection for AI generated content (AIGC) by establishing a transparent and traceable management framework, which encourages model providers to participate in forming an AIGC service system, collectively driving the development of AIGC and offering high-quality, reliable content generation services to a broader audience. Despite blockchain enabling full traceability in AIGC generation, some malicious model providers may exploit free riding actions by intercepting user requests and forwarding them to other providers to save computational resources or pursue greater profits, and then returning the generated product to users directly or with slight modifications. Such behavior hinders users from accessing high-quality AIGC service resources and threatens the legitimate rights of honest model providers, which may ultimately diminish their enthusiasm to participate in the AIGC service system, disrupting the balance of value co-creation within the system. To combat such free-riding behaviors and ensure equitable benefit distribution among participants, we propose a decentralized reputation-based model management approach within the blockchain-enabled AIGC service system, reducing the probability of malicious service providers par ticipating while providing users with a reliable reference for model selection. Moreover, it protects the content generation through a timestamp-based watermark to prevent malicious alteration and unauthorized use, safeguarding the interests of all participants during the generation process and enhancing the reliability and security of the AIGC service system. Experimental results demonstrate that the proposed approach can effectively constrain and supervise model behaviors, successfully combating free-riding actions in the AIGC service system, and providing a reliable and intuitive reference for users in model selection.
Moting Su, Fengshu Li, Xiangli Xiao, Yushu Zhang 0001
IEEE Trans. Serv. Comput.4
2025 High-precision privacy-protected image retrieval based on multi-feature fusion
Moting Su, Xiangli Xiao, Zhongyun Hua, Yushu Zhang 0001
Knowl. Based Syst.3
2025 Preview Helps Selection: Previewable Image Watermarking With Client-Side Embedding
abstract
The increasing sharing of images on social networks is prompting the involvement of digital watermarking to protect copyright and combat illegal redistribution. Owner-side embedding and client-side embedding are two modes of digital watermarking, among which the latter enables better system scalability than the former due to its higher owner-side efficiency. However, the existing client-side watermarking schemes do not take into account the preview needs of users, in which users are prevented from acquiring any visual information about the original image before decryption because it is encrypted to be fully blurred. As a result, users cannot select the desired one by previewing when a batch of encrypted images is given. To solve this problem, we overcome the incompatibility between techniques and innovatively combine client-side watermarking with thumbnail-preserving encryption to render the degraded visual perception of the original image onto the encrypted one. Specifically, the image is first fully encrypted as usual client-side watermarking, and then pixel adjustments are performed to approximate the sum of the original pixels in each block for rendering the degraded visual perception. In this way, two schemes with different performance emphasis are proposed, which implement watermark embedding based on spread spectrum and quantization index modulation separately. In terms of performance evaluation, the security of both schemes is thoroughly demonstrated, and experiments are conducted to assess their feasibility, robustness, and efficiency.
Xiangli Xiao, Yushu Zhang 0001, Zhongyun Hua, Zhihua Xia, Jian Weng 0001
IEEE Trans. Dependable Secur. Comput.1
2025 Beyond Privacy: Generating Privacy-Preserving Faces Supporting Robust Image Authentication
abstract
The prevalence of face capturing along with the advancement of face recognition poses a potential threat to individual privacy. To protect privacy, plenty of methods have been proposed to change identity in the face, thus blocking malicious face recognition. However, these methods fail to satisfy authentication requirements for special application scenarios, e.g., face authentication in surveillance capture. In this paper, we propose a novel face privacy protection model, which supports robust image authentication via information-conditional identity transformation. Specifically, we first introduce a basic face manipulation model (FMM), which can preserve identity-irrelevant attributes when manipulating identity. Based on FMM, we further design a lightweight protector called AIDPro, outputting a transformed identity which is different from the original one and is embedded a message presenting authentication information. Benefiting from the semantic robustness, our model does not require noise layers to achieve accurate message extraction after various image distortions. In addition, the message can be the condition to guide the identity transformation for privacy protection, which avoids extra resource consumption from supporting image authentication. Extensive experimental results demonstrate our model has comparable privacy protection performance, superior attribute preservation performance, and robust authentication performance especially in JPEG compression and screen shooting. Our code is available athttps://github.com/daizigege/AIDPro.
Tao Wang 0084, Wenying Wen, Xiangli Xiao, Zhongyun Hua, Yushu Zhang 0001, Yuming Fang 0001
IEEE Trans. Inf. Forensics Secur.3
2025 Hard EXIF: Protecting Image Authorship Through Metadata, Hardware, and Content
abstract
With the rapid proliferation of digital image content and advancements in image editing technologies, the protection of digital image authorship has become an increasingly important issue. Traditional methods for authorship protection include registering authorship through certification organization, utilizing image metadata such as Exchangeable Image File Format (EXIF) data, and employing watermarking techniques to prove ownership. In recent years, blockchain-based technologies have also been introduced to enhance authorship protection further. However, these approaches face challenges in balancing four key attributes: strong legal validity, high security, low cost, and high usability. Authorship registration is often cumbersome, EXIF metadata can be easily extracted and tampered with, watermarking techniques are vulnerable to various forms of attack, and blockchain technology is complex to implement and requires long-term maintenance. In response to these challenges, this paper introduces a new framework Hard EXIF, designed to balance these multiple attributes while delivering improved performance. The proposed method integrates metadata with physically unclonable functions (PUFs) for the first time, creating unique device fingerprints and embedding them into images using watermarking techniques. By leveraging the security and simplicity of hash functions and PUFs, this method enhances EXIF security while minimizing costs. Experimental results demonstrate that the Hard EXIF framework achieves an average peak signal-to-noise ratio (PSNR) of 42.89 dB, with a similarity of 99.46% between the original and watermarked images, and the extraction error rate is only 0.0017. These results show that the Hard EXIF framework balances legal validity, security, cost, and usability, promising authorship protection with great potential for wider application.
Yushu Zhang 0001, Xiangli Xiao, Ping Wang 0029, Wenying Wen
IEEE Trans. Image Process.4
2024 Make Privacy Renewable! Generating Privacy-Preserving Faces Supporting Cancelable Biometric Recognition
Tao Wang 0084, Yushu Zhang 0001, Xiangli Xiao, Lin Yuan 0002, Zhihua Xia, Jian Weng 0001
ACM Multimedia3
2024 A privacy-preserving image retrieval scheme with access control based on searchable encryption in media cloud
abstract
Abstract With the popularity of the media cloud computing industry, individuals and organizations outsource image computation and storage to the media cloud server to reduce the storage burden. Media images usually contain a large amount of private information. To prevent disclosure of privacy of the image owners, media images are encrypted before uploading to the server. However, this operation will greatly limit the utilization of the image for the user, such as content-based image retrieval. We propose an efficient similarity query algorithm with access control based on Bkd-tree in this paper, in which a searchable encryption scheme is designed for similarity image retrieval, and the encrypted image is used to extract image features by a pre-trained CNN model. The Bkd-tree is utilized to generate an index tree for the image features to speed up retrieval and make it faster than linear indexing. Finally, the security performances of the proposed scheme is analyzed and the performance of this scheme is evaluated by experiments. The results show that the security of the image content and image features can be ensured, and it has a shorter retrieval time and higher retrieval efficiency.
Yushu Zhang 0001, Xiangli Xiao, Wenying Wen
Cybersecur.4
2024 Client-Side Watermarking for Images With Solid-Color Backgrounds
abstract
The ever-growing popularity of image sharing underscores the claim for copyright protection. Digital watermarking plays a pivotal role in combating illegal redistribution and safeguarding copyright. This methodology includes two embedding modes, namely owner-side and client-side embedding, with the latter having an advantage in terms of owner-side efficiency. However, all current client-side watermarking schemes overlook the applicability to images with solid-color backgrounds. Building upon existing researches, this letter uses the lookup table method to realize the client-side embedding of watermarking, and puts forward two schemes specifically tailored for images with solid-color backgrounds. Both two schemes achieve global encryption while successfully limiting the residual watermark effects after decryption to the subject matter of the image. Separately, one scheme adopts the principle of spread spectrum, while the other relies on the principle of spread transform dither modulation. These two schemes exhibit distinct performance trade-offs, and through experimental verification, we demonstrate their decent visual performance, robustness, and efficiency.
Xiangli Xiao, Rushi Lan, Wenying Wen, Yushu Zhang 0001
IEEE Signal Process. Lett.1
2024 FairCMS: Cloud Media Sharing With Fair Copyright Protection
abstract
The onerous media sharing task prompts resource-constrained media owners to seek help from a cloud platform, i.e., storing media contents in the cloud and letting the cloud do the sharing. There are three key security/privacy problems that need to be solved in the cloud media sharing scenario, including data privacy leakage and access control in the cloud, infringement on the owner’s copyright, and infringement on the user’s rights. In view of the fact that no single technique can solve the above three problems simultaneously, two cloud media sharing schemes are proposed in this article, named FairCMS-I and FairCMS-II. By cleverly utilizing the proxy re-encryption technique and the asymmetric fingerprinting (AFP) technique, FairCMS-I and FairCMS-II solve the above three problems with different privacy/efficiency tradeoffs. Among them, FairCMS-I focuses more on cloud-side efficiency while FairCMS-II focuses more on the security of the media content, which provides owners with flexibility of choice. In addition, FairCMS-I and FairCMS-II also have advantages over existing cloud media sharing efforts in terms of optional indistinguishability under chosen-plaintext attack (IND-CPA) security and high cloud-side efficiency, as well as exemption from needing a trusted third party. Furthermore, FairCMS-I and FairCMS-II allow owners to reap significant local resource savings and thus can be seen as the privacy-preserving outsourcing of AFP. Finally, the feasibility and efficiency of FairCMS-I and FairCMS-II are demonstrated by experiments.
Xiangli Xiao, Yushu Zhang 0001, Leo Yu Zhang, Zhongyun Hua, Zhe Liu 0001, Jiwu Huang
IEEE Trans. Comput. Soc. Syst.1
2024 Secure and Efficient Federated Learning via Novel Authenticable Multi-Party Computation and Compressed Sensing
abstract
Federated learning (FL) facilitates collaborative training of a global model without sharing the participants’ raw data. Nevertheless, existing FL approaches still face three major issues: 1) How to propose a more efficient and secure privacy-preserving method; 2) How to verify the identity of participants to ensure they are not impersonators; 3) How to reduce the significant communication cost. To address the aforementioned concerns, several schemes have been proposed. However, these schemes suffer from flaws in security, efficiency, and functionality. Furthermore, few researches have considered the possibility of adversaries impersonating legitimate participants to undermine the integrity and availability of the model or launch a free-riding attack. In this paper, we first combine the advantages of secret sharing, Diffie-Hellman key agreement, and functional encryption to develop an authenticable secure multi-party computing algorithm (SDF-ASMC). This algorithm can guarantee the security of transmitted data and provide authentication functionality in the absence of a trusted third party. Moreover, an efficient, secure, and authenticable FL algorithm (ESAFL), which leverages compressed sensing and all-or-nothing transform, is introduced to reduce the transmission and encryption of local gradients. Then, only the final element of the transformed measurements is encrypted by our proposed SDF-ASMC to protect all the measurements. This method effectively improves the efficiency of our algorithm. In addition, ESAFL also tolerates participants’ dropout. Security analysis demonstrates that our proposed algorithms can securely aggregate local gradients. Finally, the extensive experiments demonstrate the practical performance of our proposed algorithms.
Lvjun Chen, Di Xiao 0001, Xiangli Xiao, Yushu Zhang 0001
IEEE Trans. Inf. Forensics Secur.3
2024 Client-Side Embedding of Screen-Shooting Resilient Image Watermarking
abstract
The proliferation of portable camera devices, represented by smartphones, is increasing the risk of sensitive internal data being leaked by screen shooting. To trace the leak source, a lot of research has been done on screen-shooting resilient watermarking technique, which is capable of extracting the previously embedded watermark from the screen-shot image. However, all existing screen-shooting resilient watermarking schemes follow the owner-side embedding mode. In this mode, the management center will suffer heavy computational and communication burden in the case of numerous screens, which hinders the system scalability. As another embedding mode of digital watermarking, client-side embedding can solve the above scalability problem by migrating the watermark embedding operation to the same time when the screen decrypts the image. By designing a pair of image encryption and personalized decryption algorithms based on matrix operation, this paper is the first to realize the client-side embedding of screen-shooting resilient watermarking. In this implementation, challenges are overcome and the following key achievements are attained. First, our scheme embeds watermark using the algorithm of Fanget al. without modification, and thus fully inherits its robustness against screen shooting. Second, the original image is securely encrypted and the watermarked image can be directly retrieved through decryption. Third, the secrecy of the screen watermark is ensured by concealing the embedding pattern. Finally, our scheme is validated by experiments, which shows that the efficiency advantage of client-side embedding is realized while maintaining robustness.
Xiangli Xiao, Yushu Zhang 0001, Zhongyun Hua, Zhihua Xia, Jian Weng 0001
IEEE Trans. Inf. Forensics Secur.1
2023 Usability Enhanced Thumbnail-Preserving Encryption Based on Data Hiding for JPEG Images
abstract
As an increasing number of people tend to upload personal images to cloud platforms such as iCloud, Google Drive, and Baidu Cloud, the issue of image privacy protection in clouds has attracted widespread attention. Thumbnail-preserving encryption (TPE) is a newly proposed technology especially for balancing usability and privacy of images stored in clouds. The TPE-encrypted image does not reveal anything other than the thumbnail and size of the original one. Although many well-designed TPE schemes have been put forward, they almost all operate in the spatial domain and are not compatible with JPEG images. The only two schemes that can be applied in the frequency domain were proposed by Wright et al. and Marohn et al., but both of them have disadvantages and do not consider non-visual usability. In this paper, we propose a usability enhanced TPE scheme especially for JPEG images by utilizing reversible data hiding and image encryption in the frequency domain. We first transform the original image into the frequency domain and select some specific locations for extra information recording in every block. The original coefficient values at the selected locations are then collected and embedded into the rest of the block before encryption. Finally, the extra information is expected to be recorded into the selected locations of every block for non-visual usability. Experiments confirm that the proposed scheme achieves the target of balancing enhanced usability and privacy.
Xi Ye 0004, Yushu Zhang 0001, Xiangli Xiao, Rushi Lan
IEEE Signal Process. Lett.3
2023 A Reversible Framework for Efficient and Secure Visual Privacy Protection
abstract
The number of images produced by people everyday is rapidly increasing in recent years and their local storage space may be not big enough for storing all these images. As a result, people are currently accustomed to uploading images to cloud platforms, which raises privacy concerns. Traditional image encryption is a way to protect image privacy without preserving visual usability, so that image owners fail to conveniently browse and manage their images stored in the cloud. Hence some visual privacy protection schemes were proposed to balance image privacy and usability, while many of them are irreversible. Recently, a novel reversible technology, called Thumbnail-Preserving Encryption (TPE), has been a hot topic. However, existing TPE schemes are either inefficient, or cannot perfectly restore the original image and meanwhile achieve Nonce-Respecting (NR) security. In view of this, we propose a reversible framework for efficient and secure visual privacy protection, which tunably preserves image visual usability for image owners with the idea of data hiding. In the framework, the original image is firstly divided into several regions by our proposed region division methods and one of the regions is vacated by data hiding. Then, the vacated region is utilized to preserve the original thumbnail by pixel adjustment after image encryption. Finally, pixels in each sub block are permuted for security. According to our theoretical analysis, the above processes are completely reversible and the processed image achieves NR security. Furthermore, we conduct extensive experiments, including recognition by various application programming interfaces, user surveys, and efficiency comparison, to demonstrate that our framework is efficient and strikes a good balance between privacy and usability.
Yushu Zhang 0001, Xi Ye 0004, Xiangli Xiao, Tao Xiang 0001, Hongwei Li 0001, Xiaochun Cao
IEEE Trans. Inf. Forensics Secur.3
2023 FingerChain: Copyrighted Multi-Owner Media Sharing by Introducing Asymmetric Fingerprinting Into Blockchain
abstract
Nowadays, more and more people are engaged in media creation and sharing for income. A common way to earn income is to upload media to an intermediary platform and then let the platform distribute some profits. However, intermediary platforms generally not only extract most of the profits, but also lack transparency in their operation, where owners lose direct control over the media. Nevertheless, individual sharing is not feasible for owners because each owner holds too little media to attract enough users independently. Blockchain is a solution to the above problem by gathering media from multiple owners without intermediaries. Though a lot of works have studied the use of blockchain for decentralized management of media data, many of them either did not consider sharing needs or tracing the illegal redistribution by malicious users. As for other works, most of them adopted symmetric digital watermarking in their blockchain networks, and thus fail to protect the rights of users who may be framed by malicious owners. Although asymmetric watermarking has been used by two existing works, the owner-side embedding pattern results in low owner-side efficiency. In view of this, we design a media sharing blockchain network in which the asymmetric fingerprinting (i.e., watermarking) with user-side embedding is introduced. Besides superior owner-side efficiency, our scheme also outperforms the above two ones in terms of TTP-free. Moreover, our scheme is designed to offer a user-friendly experience and support record traceability. The performance of our scheme is verified by both theoretical and experimental evaluations.
Xiangli Xiao, Yushu Zhang 0001, Youwen Zhu, Pengfei Hu 0001, Xiaochun Cao
IEEE Trans. Netw. Serv. Manag.1
2023 Fair Outsourcing Paid in Fiat Money Using Blockchain
abstract
Seeking outsourcing from cloud service providers is common for resource-constrained users to complete complex computing. Conventional cloud computing outsourcing solutions focus on guiding users to verify the returned results, which is unfair since malicious users can refuse to pay by falsely claiming that the results are wrong. To address this problem, fair payment schemes, both blockchain-free and blockchain-based, have been proposed. However, the former is usually inefficient and the latter only supports payment through cryptocurrencies. The use of cryptocurrencies faces hurdles as it exposes cloud service providers to a significant risk of sharp currency price fluctuations, as well as vulnerability to government bans due to regulatory concerns. In contrast, fiat money payment is not only more in line with the business norm, but also naturally avoids the above troubles. Motivated by this, a blockchain-based fair outsourcing scheme to support payment in fiat money is proposed in this paper. The proposed scheme has broad compatibility and, as an example, is subsequently instantiated with a conventional outsourcing solution of eigen-decomposition. The performance of the scheme in fairness, privacy, and efficiency is verified by both theoretical and experimental evaluations.
Xiangli Xiao, Yushu Zhang 0001, Xuewen Dong, Liangmin Wang 0001, Yong Xiang 0001, Xiaochun Cao
IEEE Trans. Serv. Comput.1
2022 Noise-free thumbnail-preserving image encryption based on MSB prediction
Ye Zhu 0002, Yushu Zhang 0001, Xiangli Xiao, Rushi Lan, Yong Xiang 0001
Inf. Sci.4
2022 HF-TPE: High-Fidelity Thumbnail- Preserving Encryption
abstract
With the popularity of cloud storage services, people are increasingly accustomed to storing images in the cloud. However, cloud storage services raise privacy concerns, e.g., leakage of images to unauthorized third parties and service providers may exploit image detection technologies to portrait users without permission. Although privacy concerns can be solved by encrypting images before they are uploaded to the cloud, traditional encryption methods significantly affect the usability and user experience, for example, users cannot preview images in the cloud. Recently, Marohnet al.proposed two approximate thumbnail-preserving encryption schemes, called DRPE and TPE-LSB, to balance the privacy and usability of images in the cloud. However, both schemes have defects that either the decryption may fail or the ciphertext images have poor performance in perceived quality and too many noise points after decryption. To this end, we pertinently propose a high-fidelity thumbnail-preserving encryption scheme (HF-TPE). Compared with the previous works, on the one hand, the HF-TPE scheme not only ensures the correct decryption of ciphertext images, but also makes the ciphertext thumbnails more close to the plaintext images perceptually. On the other hand, the decrypted thumbnails have lower noise intensity and upper limit of the number of noises. In addition, simulation experiments further show that the HF-TPE scheme can guarantee users’ usability.
Yushu Zhang 0001, Xiangli Xiao, Rushi Lan, Zhe Liu 0001, Xinpeng Zhang 0001
IEEE Trans. Circuits Syst. Video Technol.3
2021 TPE2: Three-Pixel Exact Thumbnail-Preserving Image Encryption
Yushu Zhang 0001, Xiangli Xiao, Xi Ye 0004, Rushi Lan
Signal Process.3
2020 Secure and Efficient Outsourcing of PCA-Based Face Recognition
abstract
Face recognition has become increasingly popular in recent years. However, in some special cases, many face recognition calculations cannot be performed effectively due to the lack of sufficient computing power of the terminal, which poses a challenge to the practical application of face recognition technology. Cloud computing provides a good platform for solving this problem due to its abundant computing resources. However, cloud computing poses new challenges, such as how to protect clients' data privacy without reducing efficiency. In this paper, we review some of the results of previous research and analyze an outsourcing protocol for eigen decomposition and singular value decomposition. On this basis, we propose a secure and efficient outsourcing protocol for face recognition through principal component analysis. In the proposed protocol, information privacy is well protected, and computational resources are saved by means of conversions of the original image information. In addition, local verification is supported to cope with the laziness of the cloud. We show the feasibility and advancement of our protocol from both theoretical and experimental perspectives.
Yushu Zhang 0001, Xiangli Xiao, Lu-Xing Yang, Yong Xiang 0001, Sheng Zhong 0002
IEEE Trans. Inf. Forensics Secur.2