Jyh-Haw Yeh

dblp:25/2216 · also Jyh-haw Yeh · DBLP profile ↗
← Back
21ranked-venue papers
10as first author
7since 2021 · last 2025
0000-0003-1069-9655ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 2 first-author · 5 since 2021Databases, data management, data science and information retrieval · 5 · 5 first-authorSystems, architecture and hardware · 4 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 2 since 2021Theory of computation · 3 · 3 first-authorArtificial intelligence and machine learning · 1 · 1 first-authorComputer networks · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2025 Adversarial Assembly: Leveraging LLMs to Evade CNN-Based Windows Malware Detection
Md Mashrur Arifin, Brodie Abrew, Devyn Hubbs, Jyh-Haw Yeh
PDCAT4
2024 Unveiling the Efficacy of BERT's Attention in Memory Obfuscated Malware Detection
Md Mashrur Arifin, Troy Suyehara Tolman, Jyh-Haw Yeh
ISPEC3
2024 cTIMS: Correlated Textual and Image based Metrics Suites for Assessing GAN-Synthesized Android Malware Images
abstract
Generative Adversarial Networks (GANs) have revolutionized the generation of synthetic malware images, providing significant applications in cybersecurity. Traditional image-based metrics such as Inception Score (IS) and Fréchet Inception Distance (FID) evaluate the visual quality of these images but fail to capture their malicious nature fully. We propose a novel evaluation framework, cTIMS (Correlated Textual-Based and Image-Based Metric Suites), which integrates both image and text-based metrics to provide a comprehensive assessment. Utilizing the multimodal image captioning model BLIP, we extract textual descriptions of GAN-synthesized malware images and analyze the correlation between image metrics (IS, FID) and text metrics (BLEU, METEOR, ROUGE). Additionally, we introduce Kolmogrov-Arnold Network (KAN)-based CNN architectures (VGG16-KAN, VGG19-KAN), demonstrating significant performance improvements in malware classification. The effectiveness of the Train Real Test Synthetic (TRTS) approach in validating these correlations is also evaluated, confirming the method’s reliability in selecting high-quality GAN-generated images.
Md Mashrur Arifin, Jyh-Haw Yeh
PRDC2
2024 Integrity coded databases - protecting data integrity for outsourced databases
Jyh-Haw Yeh, Md Mashrur Arifin, Ujwal Karki, Archana Nanjundarao
Comput. Secur.1
2022 Network traffic prediction based on least squares support vector machine with simple estimation of Gaussian kernel width
Gang Ke, Ruey-Shun Chen, Shanshan Ji, Jyh-Haw Yeh
Int. J. Inf. Comput. Secur.4
2021 A Practical and Secure Stateless Order Preserving Encryption for Outsourced Databases
abstract
Order-preserving encryption (OPE) plays an important role in securing outsourced databases. OPE schemes can be either Stateless or Stateful. Stateful schemes can achieve the ideal security of order-preserving encryption, i.e., “reveal no information about the plaintexts besides order.” However, comparing to stateless schemes, stateful schemes require maintaining some state information locally besides encryption keys and the ciphertexts are mutable. On the other hand, stateless schemes only require remembering encryption keys and thus is more efficient. It is a common belief that stateless schemes cannot provide the same level of security as stateful ones because stateless schemes reveal the relative distance among their corresponding plaintext. In real world applications, such security defects may lead to the leakage of statistical and sensitive information, e.g., the data distribution, or even negates the whole encryption. In this paper, we propose a practical and secure stateless order-preserving encryption scheme. With prior knowledge of the data to be encrypted, our scheme can achieve IND-CCPA (INDistinguishability under Committed ordered Chosen Plaintext Attacks) security for static data set. Though the IND-CCPA security can't be met for dynamic data set, our new scheme can still significantly improve the security in real world applications. Along with the encryption scheme, in this paper we also provide methods to eliminate access pattern leakage in communications and thus prevents some common attacks to OPE schemes in practice.
Jyh-Haw Yeh, Chien-Ming Chen 0001
PRDC2
2021 Intelligent monitor for typhoon in IoT system of smart city
Ke Wang 0068, Saru Kumari, Jyh-Haw Yeh, Chien-Ming Chen 0001
J. Supercomput.4
2020 Data storage security for the Internet of Things
Yuntao Duan, Jiangdai Li, Gautam Srivastava 0001, Jyh-Haw Yeh
J. Supercomput.4
2019 A Sustainable Model for High-School Teacher Preparation in Computer Science
abstract
In this Research to Practice paper, we present a sustainable model for teaching training in Computer Science. To address issues related to self-efficacy and teacher preparation, we started a formal program (IDoCode) that not only provides teacher training through the academic year, but also provides teachers the opportunity to obtain a Masters in STEM Education degree or a Graduate Certificate in Computer Science Teacher Endorsement.Through our program, we have shown that teachers feel more confident in their ability to teach computer science courses such as Exploring CS, AP CS Principles, and the Java-based AP CS A, as well as leading the students in a capstone project. In this paper, we present a sustainable approach to make a cultural change in the landscape of Computer Science education in the state of Idaho. We discuss various factors including working with the State Board of Education, local software companies, the university, and other invested partners to help CS courses in high school count towards graduation. We have also been active with respect to community engagement by organizing an annual meeting with counselors and principals to encourage women and minorities to take computer science courses and conducting summer professional development workshops for new teachers.
Alark Joshi, Ernie Covelli, Jyh-Haw Yeh, Tim Andersen
FIE4
2018 A Certificateless One-Way Group Key Agreement Protocol for End-to-End Email Encryption
abstract
Over the years, email has evolved into one of the most widely used communication channels for both individuals and organizations. However, despite near ubiquitous use in much of the world, current information technology standards do not place emphasis on email security. Not until recently, webmail services such as Yahoo's mail and Google's gmail started to encrypt emails for privacy protection. However, the encrypted emails will be decrypted and stored in the service provider's servers. If the servers are malicious or compromised, all the stored emails can be read, copied and altered. Thus, there is a strong need for end-to-end (E2E) email encryption to protect email user's privacy. In this paper, we present a certificateless one-way group key agreement protocol with the following features, which are suitable to implement E2E email encryption: (1) certificateless and thus there is no key escrow problem and no public key certificate infrastructure is required; (2) one-way group key agreement and thus no back-and-forth message exchange is required; and (3) n-party group key agreement (not just 2- or 3-party). This paper also provides a security proof for the proposed protocol using "proof by simulation". Finally, efficiency analysis of the protocol is presented at the end of the paper.
Jyh-Haw Yeh, Srisarguru Sridhar, Gaby G. Dagher, Kathleen Dakota White
PRDC1
2018 A Shoulder Surfing Resistant Graphical Authentication System
abstract
Authentication based on passwords is used largely in applications for computer security and privacy. However, human actions such as choosing bad passwords and inputting passwords in an insecure way are regarded as “the weakest link” in the authentication chain. Rather than arbitrary alphanumeric strings, users tend to choose passwords either short or meaningful for easy memorization. With web applications and mobile apps piling up, people can access these applications anytime and anywhere with various devices. This evolution brings great convenience but also increases the probability of exposing passwords to shoulder surfing attacks. Attackers can observe directly or use external recording devices to collect users' credentials. To overcome this problem, we proposed a novel authentication system PassMatrix, based on graphical passwords to resist shoulder surfing attacks. With a one-time valid login indicator and circulative horizontal and vertical bars covering the entire scope of pass-images, PassMatrix offers no hint for attackers to figure out or narrow down the password even they conduct multiple camera-based attacks. We also implemented a PassMatrix prototype on Android and carried out real user experiments to evaluate its memorability and usability. From the experimental result, the proposed system achieves better resistance to shoulder surfing attacks while maintaining usability.
Shiuan-Tung Chen, Jyh-Haw Yeh, Chia-Yun Cheng
IEEE Trans. Dependable Secur. Comput.3
2017 Development of an Intelligent Equipment Lock Management System with RFID Technology
abstract
The equipment lock has been an important tool for the power company to protect the electricity metering equipment. However, the conventional equipment lock has two potential problems: vandalism and counterfeiting. To fulfill the control and track the potential illegal behavior, the human labor and paper are required to proceed with related operations, resulting in the consumption of a large amount of human resources and maintenance costs. This study focused on the design of RFID technology applied to the traditional equipment lock, which, through the mobile and electronic technology, strengthens the management/operating convenience of the lock and provides the solutions for anti-counterfeiting and spoilage detection so that the national energy can be properly protected and fairly distributed.
Yeh-Cheng Chen, C. N. Chu, H. M. Sun, Jyh-Haw Yeh, Ruey-Shun Chen, Chorng-Shiuh Koong
PDCAT4
2017 Analysis on the Security and Use of Password Managers
abstract
Cybersecurity has become one of the largest growing fields in computer science and the technology industry. Faulty security has cost the global economy immense losses. Oftentimes, the pitfall in such financial loss is due to the security of passwords. Companies and regular people alike do not do enough to enforce strict password guidelines like the NIST (National Institute of Standard Technology) recommends. When big security breaches happen, thousands to millions of passwords can be exposed and stored into files, meaning people are susceptible to dictionary and rainbow table attacks. Those are only two examples of attacks that are used to crack passwords. In this paper, we will be going over three open-source password managers, each chosen for their own uniqueness. Our results will conclude on the overall security of each password manager using a list of established attacks and development of new potential attacks on such software. Additionally, we will compare our research with the limited research already conducted on password managers. Finally, we will provide some general guidelines of how to develop a better and more secure password manager.
Carlos Luevanos, John Elizarraras, Khai Hirschi, Jyh-Haw Yeh
PDCAT4
2014 P2P email encryption by an identity-based one-way group key agreement protocol
abstract
As a result of high-tech companies such as Google, Yahoo, and Microsoft offering free email services, email has become a primary channel of communication. However, email service providers have traditionally offered little in the way of message privacy protection. This has made emails, of which billions are sent around the world on any day, an attractive data source for personal identity information thieves. Google was one of the first companies to provide substantial email privacy protection when they began using the HTTPS always-on option to encrypt messages sent through their email service, Gmail. Unfortunately, Gmail's encryption option does not offer true point-to-point encryption since the encrypted emails are decrypted and stored in plaintext form on Google's servers. This type of approach poses a security vulnerability which is unacceptable to security-minded users such as highly sensitive government agencies and private companies. For these users, true point-to-point encryption is needed. This paper introduces an identity-based one-way group key agreement protocol and describes a point-to-point email encryption scheme based on the protocol. Both the security proofs and the efficiency analysis, with experimental results, of the new scheme are provided.
Jyh-Haw Yeh, Fiona Zeng, Thomas Long
ICPADS1
2014 The insecurity of two proxy signcryption schemes: proxy credential forgery attack and how to prevent it
Jyh-Haw Yeh
J. Supercomput.1
2009 Enforcing non-hierarchical access policies by hierarchical key assignment schemes
Jyh-Haw Yeh
Inf. Process. Lett.1
2008 A secure time-bound hierarchical key assignment scheme based on RSA public key cryptosystem
Jyh-Haw Yeh
Inf. Process. Lett.1
2005 An RSA-based time-bound hierarchical key assignment scheme for electronic article subscription
abstract
The time-bound hierarchical key assignment problem is to assign time sensitive keys to security classes in a partially ordered hierarchy so that legal data accesses among classes can be enforced. Two time-bound hierarchical key assignment schemes have been proposed in the literature, but both of them were proved insecure against collusive attacks. In this paper, we will propose an RSA-based time-bound hierarchical key assignment scheme and describe its possible application. The security analysis shows that the new scheme is safe against the collusive attacks.
Jyh-Haw Yeh
CIKM1
2005 Design and simulation of a supplemental protocol for BGP
Jyh-Haw Yeh, Wen-Chen Hu, Chung-wei Lee
Comput. Networks1
2005 Modifying YCN key assignment scheme to resist the attack from Hwang
Jyh-Haw Yeh, Marion Scheepers, Wen-Chen Hu
Inf. Process. Lett.1
2003 Key assignment for enforcing access control policy exceptions in distributed systems
Jyh-Haw Yeh, Randy Chow, Richard E. Newman
Inf. Sci.1