Jing Chen 0003

dblp:27/4364-3 · DBLP profile ↗
← Back
136ranked-venue papers
22as first author
101since 2021 · last 2026
0000-0002-7212-5297ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 65 · 9 first-author · 54 since 2021Computer networks · 37 · 9 first-author · 23 since 2021Systems, architecture and hardware · 10 · 3 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 7 · 7 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 6 since 2021Software engineering, systems software and programming languages · 5 · 1 first-author · 4 since 2021Databases, data management, data science and information retrieval · 4 · 1 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021
YearPublicationVenuePosition
2026 Formal Analysis of BLE Secure Connection Pairing and Revelation of the PE Confusion Attack
Yongkang Xiao, Jing Chen 0003, Kun He 0008, Ruiying Du
NDSS3
2026 A distributed, scalable cross-chain state channel scheme based on recursive state synchronization
abstract
As cross-chain technology continues to advance, the scale of cross-chain transactions is experiencing significant expansion. To improve scalability, researchers have turned to the study of cross-chain state channels. However, most of the existing schemes rely on trusted parties to support channel operations. To address this issue, we present Interpipe: a distributed cross-chain state channel scheme. Specifically, we propose a real-time cross-chain synchronization scheme to ensure consistent operations between two blockchains to a cross-chain state channel. Moreover, we propose a batch transaction proof scheme based on recursive SNARK to meet the cross-chain verification needs of large-scale users. Based on the above designs, Interpipe offers protocols for opening, updating, closing, and disputing operations to cross-chain state channels. Security analysis shows that Interpipe has consistency and resistance, and experimental results demonstrate that a cross-chain state channel can be nearly as efficient as an existing intra-chain state channel.
Ruiying Du, Jing Chen 0003, Yu Zhang 0036, Shuangxi Cao, Yufeng Wei, Shixiong Yao
Blockchain Res. Appl.3
2026 Fake news detection with GAN-augmented contrastive learning and multimodal attention
abstract
Abstract The rapid proliferation of fake news in digital media has emerged as a major threat to information credibility and public trust. Although recent advances have explored multimodal learning for fake news detection, existing models often fail to effectively integrate heterogeneous data sources and remain vulnerable to adversarial manipulations. To address these challenges, we propose (Multimodal Adversarial Deep Semantic Learning), a robust multimodal fake news detection framework that unifies generative adversarial networks (GANs) with supervised contrastive learning. Specifically, employs a multi-layer joint attention mechanism to align and fuse textual and visual features, while adversarial training encourages the extraction of event-invariant representations, enhancing generalizability across unseen news events. Additionally, contrastive learning with adversarial perturbations further strengthens feature discrimination and robustness against attacks. Extensive experiments on benchmark Twitter and Weibo datasets demonstrate that achieves state-of-the-art accuracy (85.3%) and maintains stable performance with only a 1.1% drop under adversarial conditions, outperforming existing methods in both detection accuracy and resilience. These results underscore ’s effectiveness in advancing robust multimodal fake news detection and promoting digital information integrity.
Cong Wu 0003, Jing Chen 0003, Yebo Feng, Ju Jia, Zijian Zhang 0001, Jiahua Xu 0002, Teng Li 0003, Yang Liu 0003
Cybersecur.2
2026 CANDICE: An explainable and intelligent framework for network intrusion detection
Ruiying Du, Jing Chen 0003, Kun He 0008, Cong Wu 0003, Yebo Feng
Future Gener. Comput. Syst.3
2026 CLAD: Robust audio deepfake detection against manipulation attacks with contrastive learning
Haolin Wu 0001, Jing Chen 0003, Ruiying Du, Cong Wu 0003, Kun He 0008, Xingcan Shang, Hao Ren 0001, Guowen Xu
Knowl. Based Syst.2
2026 An Efficient and Secure Information Management Approach for Remote PPG Biometric Authentication Systems
abstract
Despite the fact that biometric systems won many desirable advantages such as high security and convenience, biometric data are vulnerable to various attacks. Once the biometric data are compromised during any point of the authentication process, they are lost forever. In this paper, we propose a security information management approach to address privacy concerns emerging from the management of biometric data in remote Photoplethysmogram (rPPG) biometric authentication systems. In our design, Fully Homomorphic Encryption (FHE) is introduced to protect PPG signals in the transmission and storage phases. We further design an efficient FHE-based Convolutional Neural Network (CNN) model and encrypt the key model parameters of the CNN to realize secure inference. In addition, Principal Component Analysis, Max-Relevance and Min-Redundancy, and Relative Mutual Information methods are employed in the feature extraction stage to screen out the most representative PPG features, thus improving the accuracy of PPG authentication. In the experiments, we adopt eight publicly PPG/rPPG databases and our own rPPG dataset collected via a remote camera to evaluate our proposed biometric authentication system. The experimental results show that our proposed remote PPG biometric authentication system outperforms the state-of-the-art related work in terms of balancing authentication accuracy and biometric privacy protection.
Liping Zhang 0003, Wenjie Deng, Hewen Pan, Kim-Kwang Raymond Choo, Jing Chen 0003
IEEE Trans. Computers6
2026 Fully Private Shortest Path Computation With Single-Round Interaction
abstract
In real-world scenarios, computing the shortest path between given source and destination is widely prevalent, such as seeking the optimal route in a road network for navigation. However, in traditional non-private solutions, the user discloses its location information to the server in order to obtain the targeted shortest path, giving rise to a significant privacy leakage problem. Existing private shortest path computation schemes either provide limited privacy guarantees or require multiple interactions between the user and the server. In this paper, we introduce a fully private shortest path computation scheme, named Srchpa. This scheme ensures full privacy for both the location information provided by the user and the routing information held by the server. Furthermore, we propose a locally iterative computation method, achieving single-round interaction between the user and the server to obtain the targeted shortest path. Finally, we present the formal security analyses and comprehensive experiment evaluations. The security analyses demonstrate that our scheme achieves full privacy even if the server is malicious. The experiment evaluation results show that our scheme has lower computation, communication and storage costs on the user side, thus is practical for the lightweight user with limited resources.
Jing Chen 0003, Ruifeng Zhu, Kun He 0008, Chenbin Zhao, Ruiying Du
IEEE Trans. Dependable Secur. Comput.1
2026 Privacy-Preserving and Aggregated Proofs of Assets in Multiple Banks
abstract
Proof of reserves/assets is widely used for visa application, loan, and auction in practice, where provers display balance proofs generated by banks to verifiers to prove their balances. In real world, a prover usually deposits money in multiple banks and needs to prove her/his total balances in those banks. Based on existing technologies, a prover can either request those banks to interactively generate an aggregated proofs of assets or prove her/his balances one by one, and they are inefficient and have a low privacy protection effect. In this paper, we present privacy-preserving and aggregated proofs of assets in multiple banks. Specifically, we design a liability auditing and balance proving architecture that supports proofs of liabilities for banks and proofs of assets for provers. Then, we propose a generic construction of aggregated proofs of assets scheme, where provers can aggregate balances in multiple banks without the help of any bank and banks do not need to interact with each other. Moreover, the provers can prove the aggregated balance is more than a threshold without exposing the specific values or the bank information. We conduct experiments on our system and the results demonstrate that it is suitable in practice.
Jing Chen 0003, Kun He 0008, Erjun Zhou, Jielun Zeng, Ruiying Du
IEEE Trans. Dependable Secur. Comput.2
2026 PrivESD: A Privacy-Preserving Cloud-Edge Collaborative Logistic Regression Model Over Encrypted Streaming Data
abstract
Outsourcing logistic regression classification services to the cloud is highly beneficial for streaming data. However, it raises critical privacy concerns for the input data and the training models. Current solutions for encrypted logistic regression classification fall short in the processing of encrypted streaming data. In this paper, we propose a privacy-preserving logistic regression model (PrivESD), which allows computation over encrypted streaming data. First, we propose a lightweight framework, which creates a collaborative workload between the cloud and the edge thereby reducing the computation complexity of the cloud and the number of communications between the data owners and the cloud. Second, we develop a tailored building block library with strong data confidentiality that supports comparison operations. This library has then been used to construct logistic regression. Finally, we devise a processing scheme that uses stochastic gradient descent with momentum to train the model to prevent the problem of local optimal convergence with streaming data. We have conducted extensive performance analysis demonstrating that the proposed protocols such as our secure compare protocol outperforms existing schemes such as Bost [44] and Guo [45], and that the encryption and decryption operations of PrivESD are similar to that of Paillier [42] with$2^{30}$keys.
Chen Wang 0042, Jian Xu 0004, Jing Chen 0003, Vijay Varadharajan, Cody Lewis
IEEE Trans. Dependable Secur. Comput.3
2026 Catching Scam Tokens With Temporal Graph Learning in Decentralized Finance
abstract
Decentralized finance has experienced phenomenal growth, revolutionizing the landscape of financial transactions and asset management via blockchain. Yet, this swift growth brings with it substantial challenges, notably the surge in scam tokens, imposing significant security threats on cryptocurrency investments and trading. Existing detection methods of scam token, primarily relying on analyzing contract codes or transaction patterns, struggle to catch increasingly sophisticated tactics employed by scammers. For example, contract-based analysis are unable to identify scams lacking overt malicious code, e.g., most rugpulls, while transaction-based methods generally lack the foresight to early-detect potential risks. In this paper, we present TOKENSCOUT, the first temporal GNN-based framework for scam token early detection. TOKEN SCOUT formulates token transfer data as a dynamic temporal attributed multigraph and leverages the temporal graph learning model to learn graph representations. It also builds a graph rep resentation refining model based on contrastive learning to learn a more discriminative representation space for risk identification. We evaluated TOKENSCOUT using a comprehensive dataset of 214,084 standard ERC20 tokens from 2015 to February 2023. TOKENSCOUT achieves a balanced accuracy of 98.41%. Additionally, from March to May 2023, deploying TOKENSCOUT on Ethereum effectively identified 706 rugpulls, 174 honeypots, and 90 Ponzi schemes, thereby alerting to potential risks exceeding $240 million.
Cong Wu 0003, Jing Chen 0003, Jian Shen 0001, Guowen Xu, Yueming Wu 0001, Haijun Wang 0002, Hongwei Li 0001, Yang Liu 0003, Yang Xiang 0001
IEEE Trans. Dependable Secur. Comput.2
2026 MsgFilter: Proactive Anti-Harassment Sender-Anonymous Messaging System
abstract
Anonymous submissions inspire people to speak up since hiding their identities can protect them from negative influence by their own words. However, the abuse of anonymity may bring harassment to those public submission callers. Existing works only handle DoS attacks or block harassment senders in an active manner, which behave poorly in the early prevention of uncharacterized harassment. In this paper, we propose MsgFliter, a sender-anonymous messaging system with proactive anti-harassment mechanism. Our core idea is to prevent unanswered senders from sending messages continually while keeping their identities, messages, and sender types secret. To meet the functionality and security requirements of MsgFliter, we propose the Anti-Harassment Anonymous Authentication (AHAA) protocol. We associate messages from the same sender through linkable tags and invalidate linkability when a message is replied to. To achieve session indistinguishability, we further combine the proposed anonymous authentication with zero-knowledge proofs of disjunctive relations. We implement MsgFliter and compare its performance with related solutions. Experimental results show that our solution is practicable.
Siqin Li, Kun He 0008, Ruiying Du, Jing Chen 0003
IEEE Trans. Inf. Forensics Secur.6
2026 N Truths and a Lie: Consistency-Based Backdoor Defense for Vertical Federated Learning
Zijun Zhang 0003, Kun He 0008, Jing Chen 0003, Ruiying Du
IEEE Trans. Inf. Forensics Secur.4
2026 MagLive: Robust Voice Liveness Detection on Smartphones Using Magnetic Pattern Changes
abstract
Voice authentication has been widely used on smartphones. However, it remains vulnerable to spoofing attacks, where the attacker replays recorded voice samples from authentic humans using loudspeakers to bypass the voice authentication system. In this paper, we present MagLive, a robust voice liveness detection scheme designed for smartphones to mitigate such spoofing attacks. MagLive leverages the differences in magnetic pattern changes generated by different speakers (i.e., humans or loudspeakers) when speaking for liveness detection, which are captured by the built-in magnetometer on smartphones. To extract effective and robust magnetic features, MagLive utilizes a TF-CNN-SAF model as the feature extractor, which includes a time-frequency convolutional neural network (TF-CNN) combined with a self-attention-based fusion (SAF) model. Supervised contrastive learning is then employed to achieve user-irrelevance, device-irrelevance, and content-irrelevance. MagLive imposes no additional burden on users and does not rely on active sensing or specialized hardware. We conducted comprehensive experiments with various settings to evaluate the security and robustness of MagLive. Our results demonstrate that MagLive effectively distinguishes between humans and attackers (i.e., loudspeakers), achieving an average balanced accuracy (BAC) of 99.01% and an equal error rate (EER) of 0.77%.
Xiping Sun, Jing Chen 0003, Cong Wu 0003, Kun He 0008, Haozhe Xu, Yebo Feng, Ruiying Du, Xianhao Chen
IEEE Trans. Inf. Forensics Secur.2
2026 Realhybrid: A Hybrid Blockchain Consensus With Node-Level Switching
abstract
Blockchain consensus can be divided into synchronous consensus and asynchronous consensus according to the network status. In a real network environment, the network status of each node is constantly fluctuating. Hybrid consensus schemes adapt to network fluctuations through switching consensus protocol between asynchronous and synchronous. However, existing schemes are system-level switching, resulting in low efficiency. In this paper, we present Realhybrid, a hybrid consensus scheme with node-level switching, which enables every node to select appropriate consensus protocols based on their network status. We design corresponding protocols for each node to achieve efficient consensus under network fluctuations. Moreover, we establish a Realhybrid network model and quantify the relationship between its performance and system parameters. We conduct experiments on Realhybrid and the results show that it has 29% lower transaction waiting volume and 17% lower transaction confirmation latency compared to other hybrid consensus schemes.
Jing Chen 0003, Ruiying Du, Kun He 0008
IEEE Trans. Inf. Forensics Secur.2
2026 An Efficient and Anonymous Authentication Scheme With Session Key Agreement for Vehicular Ad Hoc Networks
abstract
Vehicular Ad hoc Networks (VANETs) enable vehicles and roadside units (RSUs) to exchange safety-related information over public wireless channels, thereby enhancing transportation system security and efficiency. However, malicious adversaries may impersonate RSUs to disseminate false information or masquerade as legitimate vehicles to gain unauthorized services. To counter such threats, mutual authentication between vehicles and RSUs is crucial. This task is particularly challenging due to the high mobility of vehicles and the resource constraints of both vehicles and RSUs. In this paper, we propose an Efficient and Anonymous Authentication Scheme with Session Key Agreement (EA2S2KA), which leverages Elliptic Curve Cryptography (ECC) and Physical Unclonable Functions (PUFs) to achieve lightweight, fast, and secure authentication. We conduct an informal security analysis, a formal security proof under the real-or-random (RoR) model, and formal security verification using AVISPA, all of which confirm that EA2S2KA resists a broad range of security threats in VANETs. Performance comparisons with recently proposed schemes show that EA2S2KA provides stronger security guarantees while achieving the lowest total computation cost and ranking among the top three in communication efficiency. Furthermore, NS-3 simulations confirm its practicality in large-scale and dynamic environments through evaluations of the authentication success rate, average authentication delay, and authentication message throughput.
Jiping Li, Jing Chen 0003, Yi-Ning Liu 0002, Shouyin Liu, Yuanyuan Zhang 0015
IEEE Trans. Intell. Transp. Syst.2
2026 POWER: High-Throughput Blockchain Based on Computing Power Utilization
abstract
Proof-of-Work (PoW) based blockchain reaches consensus by solving computational puzzles, with only the winners generating blocks. In other words, most nodes waste their computing power, resulting in a mismatch between transaction throughput and system scale (i.e., the number of nodes). In this paper, we propose POWER, a high transaction throughput blockchain architecture that utilizes node computing power. Specifically, by introducing hook block and transaction block, we design a parallel structure to increase the utilization of the computing power of nodes that package and add transactions to the blockchain. In the parallel structure, the hook block hangs the transaction block and solves the problem of transaction redundancy. We also present a round interval confirmation mechanism to increase the utilization of the computing power of nodes that confirm transactions. We conduct experiments on POWER and the experiment results show that POWER has a 63% higher transaction throughput and a 51% lower transaction confirmation latency compared to other schemes. In particular, the transaction confirmation accuracy of POWER is 5.9 times better than that of OHIE.
Jing Chen 0003, Kun He 0008, Ruiying Du
IEEE Trans. Netw.2
2026 Avatar: Securing Anonymous Communication With Relay Anonymity
abstract
Onion routing and mix networks are designed to provide users with anonymous Internet access and to prevent the disclosure of real IP addresses. In practice, anonymous networks serve various legitimate purposes, such as whistleblowing, circum-venting censorship, and safeguarding personal online privacy and security. These systems typically achieve anonymity by introducing a series of relays between the sender and the receiver. An anonymous path, or circuit, is usually composed of multiple relays (commonly three), and onion routing systems such as Tor rely on these circuits to relay traffic and ensure anonymity. Although Tor employs hidden relays (known as bridges) to resist censorship and blocking, most relays are publicly listed, and their identities are visible to circuit initiators during circuit construction, making them susceptible to surveillance and targeted attacks. A malicious relay deviating from the protocol (e.g.,injecting modified onions) poses serious threats to system security. An interesting question is how to preserve relay identity privacy while maintaining network functionality. In this paper, we introduce an innovative method for protecting relay privacy within circuits. This is achieved through the application of anonymous credentials, anonymous verifiable random functions (AVRFs), and signatures with key blinding. Additionally, if more than half of the directory authority servers within the current Tor network are compromised, the entire network could collapse. To mitigate this risk, our design distributes trust among more entities, enhancing the network’s resilience against potential adversaries. We have named this approach Avatar to enable users to navigate the online realm with the same freedom, privacy, and anonymity as an Avatar, allowing them to maintain full control over their digital identity. Furthermore, we provide a comprehensive analysis and evaluation of the Avatar framework. The findings indicate that, in comparison to the original Tor network’s onion routing protocol, our proposed protocol exhibits superior time efficiency in many network environments.
Mei Wang 0003, Zengpeng Li 0001, Jing Chen 0003
IEEE Trans. Netw.4
2025 HARE Attack: Inaudible Harmony in Voice Enrollment
abstract
Speaker verification (SV) constitutes a prevalent biometric recognition technology safeguarding the security of sensitive data and regulating access to vital infrastructure. Current audio adversarial attack researches predominantly concentrate on deceiving systems through an touching on inference parameters of the underlying model architectures. This work introduces a pragmatic and formidable attack scenario wherein adversarial perturbations are introduced during the SV enrollment phase. These meticulously engineered distortions subtly alter voice embedding extraction, consequently influencing the verification outcome for the adversary. To enable this assault, we posit perturbations comprised of inaudible high-frequency noise and optimize them within an energy-based framework. Under black-box conditions, an evolutionary algorithm, differential evolution, resolves the intricate optimization challenge. Furthermore, we leverage a spectrum of realistic constraints, including absolute hearing thresholds, signal-to-noise ratios, and over-the-air propagation effects, to augment the robustness of our methodology. Rigorous experimentation across four voice identity datasets affirms the efficacy of our approach, demonstrating success rates exceeding 90% in digital environments and 78% in physical settings against four widely employed SV models.
Xingcan Shang, Haolin Wu 0001, Kun He 0008, Jing Chen 0003
ICPADS4
2025 EmbedX: Embedding-Based Cross-Trigger Backdoor Attack Against Large Language Models
Nan Yan 0001, Yuqing Li 0001, Xiong Wang 0006, Jing Chen 0003, Kun He 0008, Bo Li 0001
USENIX Security Symposium4
2025 When Translators Refuse to Translate: A Novel Attack to Speech Translation Systems
Haolin Wu 0001, Chang Liu 0089, Jing Chen 0003, Ruiying Du, Kun He 0008, Yu Zhang 0036, Cong Wu 0003, Tianwei Zhang 0004, Qing Guo 0005, Jie Zhang 0073
USENIX Security Symposium3
2025 An efficient encrypted search with owner-level and attribute-level access controls
Yang Yang 0022, Yanjiao Chen, Fei Chen 0003, Jing Chen 0003
Comput. Networks6
2025 EyeAuth: smartphone user authentication via reflexive eye movements
Zhixiang He, Jing Chen 0003, Kun He 0008, Cong Wu 0003, Xiangyu Qu, Yangyang Gu, Xiping Sun, Ruiying Du
Frontiers Comput. Sci.2
2025 An Efficient and Revocable PUF-Based Authentication Scheme for Secure V2R Mutual Communication in VANETs
abstract
In vehicular Ad hoc networks (VANETs), vehicles and roadside units (RSUs) utilize open wireless channels to exchange safety-critical data, facilitating real-time decision-making for enhanced road safety and traffic management efficiency in intelligent transportation systems (ITS). However, the openness of these channels exposes them to various security threats. Malicious adversaries may impersonate RSUs to forge and distribute harmful commands, manipulating vehicular behavior, or masquerade as legitimate vehicles to bypass authentication protocols and gain unauthorized access. Such attacks jeopardize the security and functionality of the VANETs, underscoring the necessity of robust mutual authentication between vehicles and RSUs. Existing centralized trust authority (TA)-dependent schemes for vehicle-to-RSU (V2R) authentication incur high computational overhead, introduce authentication latency, and cause a single point of failure, particularly in dense traffic scenarios. To address these challenges, we propose ERAS2KN, an efficient and revocable authentication scheme with session key negotiation. By integrating Physical Unclonable Functions (PUFs) with lightweight cryptography, such as one-way hash functions, bitwise XOR, and symmetric encryption, ERAS2KN enables rapid mutual authentication and secure session key establishment. Comprehensive security analysis, including informal evaluation, formal security proof based on the Real-or-Random (RoR) model, and automated validation using AVISPA, confirms ERAS2KN’s resilience against vehicle impersonation, eavesdropping, vehicle/RSU compromise, man-in-the-middle, and other advance attacks. Performance evaluations demonstrate that ERAS2KN surpasses existing schemes by delivering enhanced security features while achieving the lowest computational overhead, communication overhead, and energy consumption cost, making it ideal for high-density VANETs environments.
Jiping Li, Jing Chen 0003, Yi-Ning Liu 0002, Shouyin Liu, Yuanyuan Zhang 0015
IEEE Internet Things J.2
2025 HeteroSample: Meta-Path Guided Sampling for Heterogeneous Graph Representation Learning
abstract
The rapid expansion of Internet of Things (IoT) has resulted in vast, heterogeneous graphs that capture complex interactions among devices, sensors, and systems. Efficient analysis of these graphs is critical for deriving insights in IoT scenarios, such as smart cities, industrial IoT, and intelligent transportation systems. However, the scale and diversity of IoT-generated data present significant challenges, and existing methods often struggle with preserving the structural integrity and semantic richness of these complex graphs. Many current approaches fail to maintain the balance between computational efficiency and the quality of the insights generated, leading to potential loss of critical information necessary for accurate decision-making in IoT applications. We introduce HeteroSample, a novel sampling method designed to address these challenges by preserving the structural integrity, node and edge type distributions, and semantic patterns of IoT-related graphs. HeteroSample works by incorporating the novel top-leader selection, balanced neighborhood expansion, and meta-path guided sampling strategies. The key idea is to leverage the inherent heterogeneous structure and semantic relationships encoded by meta-paths to guide the sampling process. This approach ensures that the resulting subgraphs are representative of the original data while significantly reducing computational overhead. Extensive experiments demonstrate that HeteroSample outperforms state-of-the-art methods, achieving up to 15% higher F1 scores in tasks, such as link prediction and node classification, while reducing runtime by 20%. These advantages make HeteroSample a transformative tool for scalable and accurate IoT applications, enabling more effective and efficient analysis of complex IoT systems, ultimately driving advancements in smart cities, industrial IoT, and beyond.
Jing Chen 0003, Ruiying Du, Cong Wu 0003, Yebo Feng, Teng Li 0003, Jianfeng Ma 0001
IEEE Internet Things J.2
2025 DynaShard: Secure and Adaptive Blockchain Sharding Protocol With Hybrid Consensus and Dynamic Shard Management
abstract
Blockchain sharding has emerged as a promising solution to the scalability challenges in traditional blockchain systems by partitioning the network into smaller, manageable subsets called shards. Despite its potential, existing sharding solutions face significant limitations in handling dynamic workloads, ensuring secure cross-shard transactions, and maintaining system integrity. To address these gaps, we propose DynaShard, a dynamic and secure cross-shard transaction processing mechanism designed to enhance blockchain sharding efficiency and security. DynaShard combines adaptive shard management, a hybrid consensus approach, plus an efficient state synchronization and dispute resolution protocol. Our performance evaluation, conducted using a robust experimental setup with real-world network conditions and transaction workloads, demonstrates DynaShard's superior throughput, reduced latency, and improved shard utilization compared to the fast transaction scheduling in blockchain sharding (FTSBS) method. Specifically, DynaShard achieves up to a 42.6% reduction in latency and a 78.77% improvement in shard utilization under high transaction volumes and varying cross-shard transaction ratios. These results highlight DynaShard's ability to outperform state-of-the-art sharding methods, ensuring scalable and resilient blockchain systems. We believe that DynaShard's innovative approach will significantly impact future developments in blockchain technology, paving the way for more efficient and secure distributed systems.
Jing Chen 0003, Kun He 0008, Ruiying Du, Jiahua Xu 0002, Cong Wu 0003, Yebo Feng, Teng Li 0003, Jianfeng Ma 0001
IEEE Internet Things J.2
2025 Formal Analyzing, Attacking, and Patching of Bluetooth Pairing Protocols
abstract
Bluetooth pairing is a protocol that authenticates two Bluetooth devices and derives a shared secret key between them. The Bluetooth standard consists of Bluetooth low energy (BLE) and Bluetooth classic (BC) and the latest pairing protocols in them are BLE secure connections (BLE-SCs) and secure simple pairing with secure connections (SSP-SCs), respectively. Although these two pairing protocols employ well-studied cryptographic primitives to guarantee their security, recent studies disclosed logic flaws in them. In this article, we develop the first comprehensive formal models of BLE-SC and SSP-SC pairing protocols. The models cover all pairing phases of the two protocols and all association models in the specification to discover attacks caused by the interplay between different association models. We also partly loosen the perfect cryptography assumption in traditional symbolic analysis approaches by designing a low-entropy key oracle to detect attacks caused by poorly derived keys. Our analysis confirms two existing attacks and discloses a new attack that we implemented on real-world devices. We propose a countermeasure to fix the flaws found in the BLE-SC and SSP-SC pairing protocols and discuss the backward compatibility. Moreover, we extend our models to verify the countermeasure, and the results demonstrate its effectiveness in our extended models.
Jing Chen 0003, Kun He 0008, Ruiying Du
IEEE Internet Things J.2
2025 A Formal Analysis of Bluetooth Mesh Provisioning Protocol
abstract
Bluetooth Mesh is a wireless mesh networking technology based on Bluetooth Low Energy, where new devices need to be provisioned to join an existing network. Currently, security research on the Bluetooth Mesh provisioning protocol primarily focuses on the manual analysis of potential vulnerabilities, while existing formal models are too simplistic to capture all the attacks present in the protocol. In this paper, we utilize Tamarin Prover to conduct a comprehensive formal analysis of the Bluetooth Mesh provisioning protocol. Our model encompasses all phases of the protocol from beaconing to data distribution, and includes the modeling of all public key exchanges and authentication methods specified in the Bluetooth Mesh specification. Additionally, we accurately model the AES-CMAC primitive used in the protocol, with the help of deconstruction rules and built-in message theories in Tamarin. This AES-CMAC model enables the analysis of subtle behaviors that were previously beyond the scope of symbolic analysis. Our model successfully reproduces reflection and primitive misuse attacks found in previous studies and identifies two new vulnerabilities. We propose countermeasures for the aforementioned attacks and extend our provisioning model to verify the effectiveness of these countermeasures.
Jing Chen 0003, Kun He 0008, Ruiying Du
IEEE Internet Things J.2
2025 Transferable and Robust Dynamic Adversarial Attack Against Object Detection Models
abstract
Object detection models have been widely deployed in physical world applications, and they are vulnerable to adversarial attacks. However, most adversarial attacks are implemented in a glass box setting, and under ideal shooting conditions, such as fixed distances and angles, and thus have limited attack success rate (ASR) in practice. In this article, we present a transferable and robust dynamic adversarial attack where the adversarial patches can be printed on or attached to nonrigid objects, such as clothes. We develop a cascade module with a momentum-based technique to optimize adversarial patches against various object detection models, achieving better transferability of the patches in a closed box setting. We also develop a strategy of distance-adaptive patch generation and employ perspective transformation to enhance the robustness of patches. To evaluate the attack performance, we conduct extensive experiments on seven mainstream object detection models at different distances and angles. The results show that our method can achieve an average ASR of 69.85%, which is 3.27 times that of the baseline method at 3 m.
Jing Chen 0003, Zijun Zhang 0003, Kun He 0008, Zongru Wu, Ruiying Du, Gongshen Liu
IEEE Internet Things J.2
2025 Universal and Efficient Adversarial Training Framework With Membership Inference Resistance
abstract
Adversarial training is an effective approach to enhance the robustness of machine learning models via adding adversarial examples into the training phase. However, existing adversarial training methods increase the advantage of membership inference attacks, which aim to determine from the model whether an example is in the training dataset. In this article, we propose an adversarial training framework that guarantees both robustness and membership privacy by introducing a tailor-made example called reverse-symmetry example. Moreover, our framework reduces the number of required adversarial examples compared with existing adversarial training methods. We implement our framework using four adversarial training methods on the FMNIST and CIFAR10 datasets and compare its performance with deep learning differential privacy. Our experimental findings demonstrate that our framework mitigates model overfitting and outperforms the original adversarial training with respect to the overall performance of accuracy, robustness, privacy, and runtime.
Ran Yan 0001, Ruiying Du, Kun He 0008, Jing Chen 0003, Cong Wu 0003
IEEE Internet Things J.4
2025 Efficient Verifiable Dynamic Searchable Symmetric Encryption With Forward and Backward Security
abstract
In the realm of secure data outsourcing, verifiable dynamic searchable symmetric encryption (VDSSE) enables a client to verify search results obtained from an untrusted server while protecting the data privacy. Nevertheless, the storage cost of verification structure in some schemes escalates linearly with the number of keywords, and the generation of proofs demands a substantial number of exponentiation operations. Moreover, some schemes overlook forward and backward security in the dynamic database. In this article, we introduce FB-VDSSE, an advanced VDSSE scheme that ensures both forward and backward security. Specifically, we introduce an efficient accumulation commitment verification structure (AC-VS) that attains a commitment verification value with a constant-size storage cost. Based on the AC-VS, we further propose a forward and backward secure VDSSE scheme. Within this scheme, the server exclusively generates a membership proof at the corresponding index of the vector, reducing the computation cost associated with the search operation. Finally, we provide the security proof and functional comparison, demonstrating that our scheme effectively ensures forward security, backward security, and verifiability. Additionally, the experimental evaluations underscore the efficiency of our scheme, showcasing its superior performance compared to relevant schemes in practical scenarios.
Chenbin Zhao, Ruiying Du, Kun He 0008, Jing Chen 0003, Jiguo Li 0001, Ximeng Liu, Jianting Ning
IEEE Internet Things J.4
2025 Fast Payment System in Cryptocurrencies Through Off-Chain Transaction Aggregation
abstract
Blockchain technology is widely used in the field of digital currency, however, the typical blockchain systems suffer from high transaction confirmation latency and expensive fees, which make it difficult to meet the needs of daily payment scenarios. Schemes such as state channel and payment center shift the on-chain payment confirmation process off-chain, thereby reducing latency. Yet these solutions require locking in additional funds or introducing a trusted third party, and seldom consider the issue of lowering transaction fees. In this paper, we propose a cryptocurrency fast payment scheme that organises off-chain participants through smart contracts to enable fast payments. The transaction parties update their state off-chain to ensure fast confirmation. At settlement, off-chain transactions between customer and multiple merchants or merchant and multiple customers are aggregated into a single on-chain transaction, effectively reducing overall transaction fees. We protect transaction privacy by hiding the transaction amount and balance through range proof. We conduct experiments on Ethereum platform, and the results show that the system latency meets the needs of real-world scenarios.
Ruiying Du, Jing Chen 0003, Kun He 0008, Yuanzheng Wang
IEEE Internet Things J.3
2025 An auditable and privacy-preserving user-controllable group signature scheme in blockchain
Jing Chen 0003, Shixiong Yao, Kun He 0008, Ruiying Du
J. Inf. Secur. Appl.2
2025 Efficient Single-Server Private Inference Outsourcing for Convolutional Neural Networks
abstract
Private inference outsourcing ensures the privacy of both clients and model owners when model owners deliver inference services to clients through third-party cloud servers. Existing solutions either reduce inference accuracy due to model approximations or rely on the unrealistic assumption of non-colluding servers. Moreover, their efficiency falls short of HELiKs, a solution focused solely on client privacy protection. In this paper, we propose Skybolt, a single-server private inference outsourcing framework without resorting to model approximations, achieving greater efficiency than HELiKs. Skybolt is built upon efficient secure two-party computation protocols that safeguard the privacy of both clients and model owners. For the linear calculation protocol, we devise a ciphertext packing algorithm for homomorphic matrix multiplication, effectively reducing both computational and communication overheads. Additionally, our nonlinear calculation protocol features a lightweight online phase, involving only the addition and multiplication on secret shares. This stands in contrast to existing protocols, which entail resource-intensive techniques such as oblivious transfer. Extensive experiments on popular models, including ResNet50 and DenseNet121, show that Skybolt achieves a 5.4 − 7.3× reduction in inference latency, accompanied by a 20.1 − 39.6× decrease in communication cost compared to HELiKs.
Xuanang Yang, Jing Chen 0003, Yuqing Li 0001, Kun He 0008, Zikuan Jiang, Ruiying Du
IEEE Trans. Circuits Syst. Video Technol.2
2025 GetFed: Accurate, Differentially Private Federated Learning With GAN-Based Data Generation
abstract
Federated Learning (FL) aims to train neural network models using distributed data resources from multiple clients without sharing raw data. One of the key challenges in FL is non-independent and identically distributed (non-IID) data, which may affect model accuracy. To address this issue, some schemes leverage Generative Adversarial Networks (GANs) to generate virtual data and combine it with the real data to achieve a balanced data distribution. However, there are risks of privacy leakage from the collected virtual data and aggregated gradients. In this paper, we propose GetFed, an accurate and differentially private FL framework with GAN-based Data Generation on non-IID Data. We integrate Differential Privacy (DP) into the GAN training and federated aggregation phases to prevent clients’ privacy leakage. To balance privacy and accuracy, we first design a privacy-preserving virtual sample generation algorithm for GAN training that dynamically reduces unnecessary noise as the quality of virtual samples improves. Additionally, we design an adaptive DP-based secure aggregation algorithm that decreases the added noise as the model approaches convergence. Furthermore, we implement a real-virtual ensemble training algorithm, employing an ensemble learning strategy to better mix virtual and real samples for enhanced global model accuracy. This approach ensures clients benefit from both the authenticity of real samples and the balanced data distribution provided by virtual samples, effectively mitigating the data heterogeneity inherent in non-IID scenarios. Extensive experiments demonstrate that compared with state-of-the-art schemes, GetFedimproves model accuracy by 6–47% and reduces training time by 50%.
Kun He 0008, Yuqing Li 0001, Jing Chen 0003, Zhongmou Liu, Xuanang Yang, Ruiying Du
IEEE Trans. Dependable Secur. Comput.4
2025 FedPHE: A Secure and Efficient Federated Learning via Packed Homomorphic Encryption
abstract
Cross-silo federated learning (FL) enables multiple institutions (clients) to collaboratively build a global model without sharing private data. To prevent privacy leakage during aggregation, homomorphic encryption (HE) is widely used to encrypt model updates, yet incurs high computation and communication overheads. To reduce these overheads,packedHE (PHE) has been proposed to encrypt multiple plaintexts into a single ciphertext. However, the original design of PHE assumes all clients share a single private key, making the system vulnerable to security threats of ciphertexts being intercepted and decrypted byhonest-but-curious clients. Also, it does not consider theheterogeneityamong different clients, resulting in undermined training efficiency with slow convergence and stragglers. To address these challenges, we propose FedPHE, a secure and efficient FL framework with PHE by jointly exploiting contribution-aware secure aggregation and straggler-resistant client selection. Using CKKS with sparsification and blinding, FedPHE achieves efficient secure aggregation that allows clients to only provideobscuredencrypted updates while the server can perform aggregation by accounting forcontributionsof local updates. To mitigate the straggler effect, we devise aperturbed sketch-based selection to cherry-pick representative clients withheterogeneous models and computing capabilitiesin a communication-efficient and privacy-preserving manner. We show, through rigorous security analysis and extensive experiments, that FedPHE can efficiently safeguard clients' privacy, achieve$2.45-6.56\times$training speedup, cut the communication overhead by$1.32-24.85\times$, and reduce straggler effects by$1.89-2.78\times$.
Yuqing Li 0001, Nan Yan 0001, Jing Chen 0003, Xiong Wang 0006, Jianan Hong, Kun He 0008, Wei Wang 0030, Bo Li 0001
IEEE Trans. Dependable Secur. Comput.3
2025 Practical Multi-User Dynamic Searchable Symmetric Encryption With Hierarchical Authorization
abstract
Searchable symmetric encryption (SSE) in the multi-user setting is designed for scenarios where data owners outsource their encrypted data to the cloud while allowing legitimate data users to search on it. However, existing multi-user SSE schemes are not practical in real scenarios with hierarchical user structure such as enterprises and hospitals. Specifically, most schemes require real-time participation of data owners in the authorization or search process, and are not efficient in authorization adjustment, placing a large computational burden on them. In this paper, we focus on hierarchical authorization in the multi-user setting and propose a forward secure scheme, called DSSEHA. In particular, we develop a hierarchical authorization mechanism where the data owner chooses to share her/his data with specific legitimate users who can continue to share with low-level users, thus reducing computational pressure on the data owner. Experiments show that the computation cost of DSSEHA in search is close to the state-of-the-art solution, while the computation cost in update and authorization (e.g., less than 0.1 ms per document for online authorization and less than 0.6 ms for offline authorization) and storage cost (e.g., less than 50.7 MB for Enron subset with 10,000 documents) are much smaller than existing schemes.
Beining Wang, Jing Chen 0003, Kun He 0008, Bei Shen, Sicheng Nian, Ruiying Du
IEEE Trans. Dependable Secur. Comput.2
2025 Forward Secure Similarity Search Over Encrypted Data for Hamming Distance
abstract
Similarity search on encrypted data can identify similar data and handle misspelled keywords in a privacy-preserving manner and thus has received a lot of attention. However, existing schemes suffer from imprecise or predefined distance thresholds, which means that they do not always return the expected search results. Moreover, these schemes either do not consider document addition or lack forward security in this dynamic setting. In this article, we present a Similar Keyword Matching (SKM) framework that accurately calculates the Hamming distance between keywords through a new keyword representation called uni-pos-gram. Based on our framework, we propose a basic scheme for similarity search over encrypted data called SimSE that offers adjustable Hamming distance thresholds and an enhanced scheme called SimSE-F that provides forward security. Security analysis demonstrates that our schemes effectively safeguard the privacy of documents, indexes, and searches. Empirical experiments using real-world datasets demonstrate the efficiency and practical applicability of our schemes.
Beining Wang, Kun He 0008, Jing Chen 0003, Chenbin Zhao, Ruiying Du
IEEE Trans. Dependable Secur. Comput.4
2025 WAFBooster: Automatic Boosting of WAF Security Against Mutated Malicious Payloads
abstract
Web application firewall (WAF) examines malicious traffic to and from a web application via a set of security rules. It plays a significant role in securing Web applications against web attacks. However, as web attacks grow in sophistication, it is becoming increasingly difficult for WAFs to block the mutated malicious payloads designed to bypass their defenses. In response to this critical security issue, we have developed a novel learning-based framework calledWAFBooster, designed to unveil potential bypasses in WAF detections and suggest rules to fortify their security. Using a combination of shadow models and payload generation techniques, we can identify malicious payloads and remove or modify them as needed.WAFBoostergenerates signatures for these malicious payloads using advanced clustering and regular expression matching techniques to repair any security gaps we uncover. In our comprehensive evaluation of eight real-world WAFs,WAFBoosterimproved the true rejection rate of mutated malicious payloads from 21% to 96%, with no false rejections.WAFBoosterachieves a false acceptance rate 3× lower than State-of-the-Art methods for generating malicious payloads. WithWAFBooster, we have taken a step forward in securing web applications against the ever-evolving threats.
Cong Wu 0003, Jing Chen 0003, Simeng Zhu, Wenqi Feng, Kun He 0008, Ruiying Du, Yang Xiang 0001
IEEE Trans. Dependable Secur. Comput.2
2025 High Accuracy and Presentation Attack Resistant Hand Authentication via Acoustic Sensing for Commodity Mobile Devices
abstract
Biometric authentication schemes, i.e., fingerprint and face authentication, raise serious privacy concerns. To alleviate such concerns, hand authentication has been proposed recently. Existing hand authentication schemes, however, use dedicated hardware, such as infrared or depth cameras, which are not available on commodity mobile devices. In this paper, we presentEchoHand, a high accuracy and presentation attack resistant authentication scheme that complements camera-based 2-dimensional hand geometry recognition of one hand with an active acoustic sensing of the other hand. To this end,EchoHandplays an inaudible acoustic signal using the speaker to actively sense the holding hand and collects the echoes using the microphone.EchoHanddoes not rely on any specialized hardware but uses the built-in speaker, microphone and camera.EchoHanddoes not place more burdens on users than existing hand authentication methods. We conduct comprehensive experiments to evaluate the reliability, security, and usability ofEchoHand. The results show thatEchoHandhas a low equal error rate of 2.45% with as few as 10 training data points and it defeats presentation attacks. The results of the user study also suggest that the required hand gestures are easy to perform, andEchoHandis very user-friendly with low latency.
Cong Wu 0003, Kun He 0008, Jing Chen 0003, Ruiying Du, Ran Yan 0001, Ziming Zhao 0001
IEEE Trans. Dependable Secur. Comput.3
2025 Decentralized Self-Auditing Multiple Cloud Storage in Compressed Provable Data Possession
abstract
As cloud storage becomes popular, more and more users tend to outsource their data to powerful cloud severs. To prevent a single point of failure, users prefer to store data on multiple cloud servers from different cloud service providers. However, after outsourcing data to cloud servers, users lose the control of their data, which may incur many serious security issues, such as abnormal data tampering and deleting. It is necessary for users to audit multiple cloud storage aperiodically. In this article, we aim to design a decentralized self-auditing solution for multiple cloud storage, in which cloud servers can audit the integrity of each other, and thus no third-party entity is required. First, based on basic algebra, our protocol realizes decentralized self-auditing multiple cloud storage that only involves encrypted user data. Second, we design a proof exchanging mechanism, making any number of cloud servers form the same final integrity proof with a linear number of interactions. Third, our solution can achieve cloud dynamics, which can freely enable and disable a cloud server to provide storage service. At last, security proof and performance evaluation show that the proposed protocol has provable security and high efficiency.
Yang Yang 0022, Yanjiao Chen, Ping Xiong 0001, Fei Chen 0003, Jing Chen 0003
IEEE Trans. Dependable Secur. Comput.5
2025 Multi-Authority Anonymous Credentials With Efficient and Decentralized Supervision
abstract
Anonymous credential is widely used in online services, where issuers in authorities issue credentials to users and then users can selectively and privately prove their identities and attributes. However, users may misbehave under anonymous settings. Therefore, we need to trace the credential proof to obtain the user’s identity and link credential proofs to achieve supervision. Existing solutions either have the single point of failure problem or require multiple supervisors perform threshold computations on all users’ identities, it is inefficient in practice especially when the number of users increases. In this paper, we present a credential management system in multiple authorities with efficient and decentralized supervision. Specifically, we design a multi-authority credential management architecture, where each issuer in authorities issues credentials to users and supervisors trace and link credential proofs in multiple authorities. Then, we present efficient and decentralized credential proof tracing and linking protocols, where more than threshold supervisors can trace credential proofs to obtain users’ identities and generate users’ linking keys. Verifiers can link each malicious user’s credential proofs efficiently with those linking keys. We conduct experiments on our system in the WAN and LAN settings and compare it with another threshold attribute-based credential scheme. The experimental results demonstrate that our solution is efficient in practice.
Jing Chen 0003, Yuanzheng Wang, Kun He 0008, Ruiying Du
IEEE Trans. Inf. Forensics Secur.2
2025 Vulseye: Detect Smart Contract Vulnerabilities via Stateful Directed Graybox Fuzzing
abstract
Smart contracts, the cornerstone of decentralized applications, have become increasingly prominent in revolutionizing the digital landscape. However, vulnerabilities in smart contracts pose great risks to user assets and undermine overall trust in decentralized systems. Fuzzing, a prominent security testing technique, is extensively explored to detect vulnerabilities. But current smart contract fuzzers fall short of expectations in testing efficiency for two primary reasons. Firstly, smart contracts are stateful programs, and existing approaches, primarily coverage-guided, lack effective feedback from the contract state. Consequently, they struggle to effectively explore the contract state space. Secondly, coverage-guided fuzzers, aiming for comprehensive program coverage, may lead to a wastage of testing resources on benign code areas. This wastage worsens in smart contract testing, as the mix of code and state spaces further complicates comprehensive testing. To address these challenges, we propose Vulseye, a stateful directed graybox fuzzer for smart contracts guided by vulnerabilities. Different from prior works, Vulseyeachieves stateful directed fuzzing by prioritizing testing resources to code areas and contract states that are more prone to vulnerabilities. We introduceCode TargetsandState Targetsinto fuzzing loops as the testing targets of Vulseye. We use static analysis and pattern matching to pinpointCode Targets, and propose a scalable backward analysis algorithm to specifyState Targets. We design a novel fitness metric that leverages feedback from both the contract code space and state space, directing fuzzing toward these targets. With the guidance of code and state targets, Vulseyealleviates the wastage of testing resources on benign code areas and achieves effective stateful fuzzing. In comparison with state-of-the-art fuzzers, Vulseyedemonstrated superior effectiveness and efficiency. Notably, it uncovered 4,845 vulnerabilities in 42,738 real-world smart contracts, outperforming existing approaches by up to$9.7\times $, and identified 11 previously unknown vulnerabilities within the top 50 Ethereum DApps, involving approximately 2,500,000 USD.
Ruichao Liang, Jing Chen 0003, Cong Wu 0003, Kun He 0008, Yueming Wu 0001, Ruochen Cao, Ruiying Du, Ziming Zhao 0001, Yang Liu 0003
IEEE Trans. Inf. Forensics Secur.2
2025 Detecting DeFi Fraud With a Graph-Transformer Language Model
Wei Ma 0014, Jiaxi Qiu, Cong Wu 0003, Jing Chen 0003, Lingxiao Jiang, Shangqing Liu, Yang Liu 0003, Yang Xiang 0001
IEEE Trans. Inf. Forensics Secur.5
2025 SCR-Auth: Secure Call Receiver Authentication on Smartphones Using Outer Ear Echoes
abstract
Receiving calls is one of the most universal functions of smartphones, involving sensitive information and critical operations. Unfortunately, to prioritize convenience, the current call receiving process bypasses smartphone authentication mechanisms (e.g., passwords, fingerprint recognition, and face recognition), leaving a significant security gap. To address this issue, we propose SCR-Auth, a secure call receiver authentication scheme for smartphones that leverages outer ear echoes. It sends inaudible acoustic signals through the earpiece speaker to actively sense the call receiver’s outer ear structure and records the resulting echoes using the top microphone. These echoes are then analyzed to extract unique outer ear biometric information for authentication. It operates implicitly, without requiring extra hardware or imposing additional burden. Comprehensive experiments conducted under diverse conditions demonstrate SCR-Auth’s effectiveness and security, showing an average balanced accuracy of 96.95% and resilience against potential attacks.
Xiping Sun, Jing Chen 0003, Kun He 0008, Zhixiang He, Ruiying Du, Yebo Feng, Qingchuan Zhao, Cong Wu 0003
IEEE Trans. Inf. Forensics Secur.2
2025 Forward and Backward Private Conjunctive Dynamic Searchable Symmetric Encryption With Refined Leakage Function and Low Communication
abstract
Dynamic searchable symmetric encryption (DSSE) enables updates and keyword searches on outsourced encrypted data while minimizing the information revealed to the server. However, existing DSSE schemes that support conjunctive keyword searches disclose added documents or fail to filter deleted ones in certain circumstances, thus violating forward and backward privacy. Besides, the size of their search tokens increases with the number of documents, which incurs a heavy communication cost. In this paper, we develop a conjunctive DSSE scheme that has a search token size only related to the conjunction size and fully supports forward and backward privacy. Our scheme is based on a new three-dimensional chain structure called CUBE. We also rethink the leakage function of conjunctive queries and prove that our scheme satisfies the refined security definition. Experimental results demonstrate that compared with the state-of-the-art schemes, our scheme increases the computational cost by at most 9.62% but reduces the communication cost by 99.78% when searching six conjunctive keywords.
Beining Wang, Yinuo Li, Jing Chen 0003, Kun He 0008, Ruiying Du
IEEE Trans. Inf. Forensics Secur.3
2025 RugScreener: Leveraging Temporal Graph Neural Network for Rugpull Detection in DeFi
abstract
The advent of decentralized finance has ushered in a transformative era in the financial sector, leveraging blockchain technology to facilitate peer-to-peer transactions without traditional intermediaries. Amidst this innovation, the DeFi landscape faces the pervasive threat of rugpulls, where developers abruptly abandon projects post-fundraising, leaving investors with devalued assets. This growing concern highlights a critical research gap in the proactive detection and prevention of such fraudulent schemes. To combat this, we propose RUGSCREENER, a temporal graph neural network-based solution to identify rugpull risks within DeFi transactions. It employs a dynamic representation of blockchain interactions, enriched with comprehensive node attributes and effective temporal graph learning techniques based on memory and attention mechanisms, effectively capturing the rapid-moving and complex transaction patterns indicative of potential fraud. Our evaluation is based on a newly compiled Ethereum dataset that includes two subsets: an unlabeled set with 1,882,114 transactions from 29,595 tokens for temporal graph representation learning, and a labeled set with 128,819 transactions from 1,000 tokens (500 rugpull and 500 benign) for downstream evaluation. Using this dataset, RUGSCREENER achieves a balanced accuracy of 95.7% in detecting rugpull tokens. Our extensive evaluation, utilizing the Ethereum dataset comprising 1000 tokens, showcases its robust performance with a balanced accuracy of 95.7% in detecting rugpull tokens. Remarkably, RUGSCREENER surpasses existing state-of-the-art graph learning models in detecting rugpull tokens with enhanced accuracy and reliability.
Cong Wu 0003, Hangcheng Cao, Jing Chen 0003, Xiyu Yan, Guowen Xu, Ziming Zhao 0001, Yang Liu 0003, Hongbo Jiang 0001
IEEE Trans. Inf. Forensics Secur.3
2025 Profit or Deceit? Mitigating Pump and Dump in DeFi via Graph and Contrastive Learning
abstract
Pump-and-Dump (PD) schemes pose a significant threat to the stability and fairness of Decentralized Finance (DeFi) markets, often resulting in substantial financial losses for investors. The early and accurate detection of these schemes is crucial for preserving trust in the rapidly expanding cryptocurrency ecosystem. However, existing detection methods primarily rely on post-event analysis and heuristic-based approaches, which are often inadequate for real-time and precise identification of PD activities. In this paper, we present PUMPWATCHER, an innovative framework that employs Graph Neural Networks (GNNs) and contrastive learning to detect PD schemes by modeling transaction behaviors within temporal graphs. PUMPWATCHER integrates advanced transaction graph construction, temporal GNNs, and contrastive learning techniques to enhance node and edge representations, thereby improving the detection of intricate and covert PD operations. We validate PUMPWATCHER on a dataset from Uniswap, encompassing 924,508 transactions across 858 tokens within December 2022. The results show that PUMPWATCHER outperforms state-of-the-art models, achieving a superior balanced accuracy of 92.3%, while significantly minimizing false positives and negatives. These outcomes highlight its potential to set a new standard in real-time detection of market manipulation, paving the way for more secure and resilient DeFi ecosystems.
Cong Wu 0003, Jing Chen 0003, Jiahua Xu 0002, Ju Jia, Yebo Feng, Yang Liu 0003, Yang Xiang 0001
IEEE Trans. Inf. Forensics Secur.2
2025 $\mathsf{TCG}\text{-}\mathsf{IDS}$ : Robust Network Intrusion Detection via Temporal Contrastive Graph Learning
abstract
In the era of zero trust security models and next-generation networks (NGN), the primary challenge is that network nodes may be untrusted, even if they have been verified, necessitating continuous validation and scrutiny. Effective intrusion detection systems (IDS) are crucial for continuously monitoring network traffic and identifying potential threats. However, traditional IDS approaches often struggle to keep pace with evolving threats, requiring extensive supervised training on labeled datasets. This limitation leads to high false positive rates, low detection accuracy, and a failure to provide real-time detection, thereby undermining the security of NGNs. This paper proposed the first self-supervised learning-based IDS, designed on temporal contrastive graph neural network (GNN), namely$\mathsf{TCG}\text{-}\mathsf{IDS}$. It innovatively integrates three contrastive learning strategies: temporal contrasting to capture temporal dependencies, asymmetric contrasting to account for the diverse interactions within network data, and masked contrasting to enhance the learning of node representations by masking parts of the data during training. Performance evaluation was conducted on two publicly available network traffic datasets, NF-CSE-CIC-IDS2018-V2 and NF-UNSW-NB15-V2.$\mathsf{TCG}\text{-}\mathsf{IDS}$achieved a balanced accuracy of 99.48% and 91.48% on two datasets respectively, significantly outperforming state-of-the-art graph learning models. In multi-class detection,$\mathsf{TCG}\text{-}\mathsf{IDS}$attained a mean false positive rate of 4.15% and 3.34% on the two datasets respectively. Besides, it exhibits high efficiency with its running time of 0.37s and 0.51s on the two datasets to predict per batch of 100 samples. Results highlight the effectiveness and efficiency of$\mathsf{TCG}\text{-}\mathsf{IDS}$in accurately detecting various types of network intrusions. This work significantly advances the field of network intrusion detection via self-supervised temporal graph learning, offering a promising solution for future network security systems.
Cong Wu 0003, Jianfei Sun, Jing Chen 0003, Mamoun Alazab, Yang Liu 0003, Yang Xiang 0001
IEEE Trans. Inf. Forensics Secur.3
2025 Volia: An Efficient and Light Asynchronous BFT Protocol
abstract
Byzantine Fault Tolerance (BFT) protocols can be divided into synchronous BFT protocols, partially synchronous BFT protocols, and asynchronous BFT protocols according to communication delay. Asynchronous BFT protocols are widely used because they can tolerate uncertain communication delays in the real world. However, asynchronous BFT protocols need to perform many rounds of broadcasts to reach agreement on a transaction subset, which consumes a lot of communication, computing, and storage resources. In this paper, we present Volia, an asynchronous BFT protocol which resolves above problem.We design new broadcast protocol to reduce the number of broadcast rounds needed for agreement. It reduces the communication overhead. Voting broadcast is used to maintain the order of transaction subsets rather than threshold signature to reduce computation cost. Above mechanisms speeds up the agreement phase, reduces the accumulated transaction subsets waiting for agreement and thus saves storage resources. We conduct experiment on Volia and the results show that Volia exhibits about 2~65× throughput, 2~25% latency, and 30% storage cost compared to other asynchronous BFT protocols.
Jing Chen 0003, Kewen Pan, Kun He 0008, Ruiying Du
IEEE Trans. Inf. Forensics Secur.2
2025 Breaking the Illusion: A Critical Study of Backdoor Defense in Federated Learning With Non-IID Data
abstract
Existing backdoor defense methods for federated learning (FL) usually try to distinguish between benign and malicious clients. The key insight is that benign clients are densely distributed, whereas malicious clients tend to be outliers outside this distribution. However, this only holds when data is independent and identically distributed (IID), and the effectiveness of these methods under non-IID data has not been systematically examined. In this paper, we present a comprehensive systematization of FL backdoor defense by breaking down its overall pipeline into three key components, i.e., metrics for evaluating clients, techniques for amplifying the difference between benign and malicious clients, and mechanisms for identifying malicious clients. We conduct an empirical study of FL backdoor defense methods under non-IID data settings to explore whether benign and malicious clients can be fully distinguished. Experimental results show that the defense performance degrades significantly when data is non-IID. Our results also reveal how evaluation metrics, amplification techniques and identification mechanisms perform under diverse settings. Contrary to the established belief, we further conclude that these defenses have inherent shortcomings, due to lack of stability and robustness in detecting malicious clients. We believe that our findings can better facilitate the development of FL backdoor defenses.
Pei Ye, Yuqing Li 0001, Kun He 0008, Tianjie Qin, Xiong Wang 0006, Kaige Yang, Chujun Zhang, Jing Chen 0003
IEEE Trans. Inf. Forensics Secur.9
2025 Lightweight Dynamic Conjunctive Keyword Searchable Encryption With Result Pattern Hiding
abstract
With the rapid growth of cloud storage technology, the demand for efficient and secure search of outsourced encrypted data has become increasingly critical. However, existing conjunctive keyword dynamic searchable encryption schemes often expose the Keyword Pair Result Pattern (KPRP) during index matching, compromising privacy. Additionally, frequent index updates require expensive group exponentiations, leading to high client-side overhead. To tackle these challenges, we propose LRP-HDSE, a lightweight dynamic conjunctive keyword searchable encryption scheme that hides KPRP while minimizing client computation costs. To enhance privacy, we introduce the Vector Hidden Subset Predicate Encryption (VH-SPE) mechanism, which enables the server to implicitly detect cross-tag in the membership matching index, effectively mitigating KPRP leakage. For improved efficiency, the scheme designs a lightweight membership matching index structure, LSet, based on low-cost multiset hash operations, reducing reliance on costly exponentiations and lowering client overhead. Our security analysis confirms that LRP-HDSE provides robust KPRP hiding along with forward and backward security in dynamic environments. Asymptotic analysis, along with experiment evaluations on two real-world datasets, show that our scheme offers superior client-side computational efficiency compared to existing approaches, making it both practical and effective.
Chenbin Zhao, Ruiying Du, Jing Chen 0003, Kun He 0008, Ximeng Liu, Yang Xiang 0001
IEEE Trans. Inf. Forensics Secur.3
2025 Boreas: Fully Anonymous Sealed-Bid Auction
abstract
With the rise of e-commerce, sealed-bid auctions are widely used in various online scenarios. In auctions, bidders’ bids and participants’ identities are considered critical private information. However, existing works either only achieve bid privacy or fail to provide complete protection of identity. In this work, we propose the first sealed-bid auction scheme that achieves both bid privacy and identity privacy, calledBoreas. We propose three fundamental protocols as the building blocks. In particular,anonymous submissionenables sellers to submit items anonymously,oblivious biddingandlocker transactionenable the seller and the winner to confirm the auction results and complete the transaction without knowing each other’s identity. Meanwhile, we formally define the security goal of identity privacy and formalize a new security property called:fully anonymous. We prove the security of our scheme in the semi-honest adversary model. We implement Boreas and run experiments comparing its performance against existing schemes. Our experiments show that Boreas improves computation time by 12.6% and reduces communication costs by 103× in handling a large-scale auction, while offering stronger security guarantee.
Erjun Zhou, Jing Chen 0003, Zhengdi Huang, Kun He 0008, Ruiying Du
IEEE Trans. Inf. Forensics Secur.2
2025 CSIPose: Unveiling Human Poses Using Commodity WiFi Devices Through the Wall
abstract
The popularity of WiFi devices and the development of WiFi sensing have alerted people to the threat of WiFi sensing-based privacy leakage, especially the privacy of human poses. Existing work on human pose estimation is deployed in indoor scenarios or simple occlusion (e.g., a wooden screen) scenarios, which are less privacy-threatening in attack scenarios. To reveal the risk of leakage of the pose privacy to users from commodity WiFi devices, we propose CSIPose, a privacy-acquisition attack that passively estimates dynamic and static human poses in through-the-wall scenarios. We design a three-branch network based on transfer learning, auto-encoder, and self-attention mechanisms to realize the supervision of video frames over CSI frames to generate human pose skeleton frames. Notably, we designAveCSI, a unified framework for preprocessing and feature extraction of CSI data corresponding to dynamic and static poses. This framework uses the average of CSI measurements to generate CSI frames to mitigate the instability of passively collected CSI data, and utilizes a self-attention mechanism to enhance key features. We evaluate the performance of CSIPose across different room layouts, subjects, devices, subject locations, and device locations. Evaluation results emphasize the generalizability of CSIPose. Finally, we discuss measures to mitigate this attack.
Yangyang Gu, Jing Chen 0003, Congrui Chen, Kun He 0008, Ju Jia, Yebo Feng, Ruiying Du, Cong Wu 0003
IEEE Trans. Mob. Comput.2
2025 HeadSonic: Usable Bone Conduction Earphone Authentication via Head-Conducted Sounds
abstract
Earables (ear wearables) are rapidly emerging as a new platform encompassing a diverse of personal applications, prompting the development of authentication schemes to protect user privacy. Existing earable authentication methods are all specifically designed for air-conduction earphones, which are not suited for bone conduction earphones (BCEs) that rely on bone conduction mechanisms. In this paper, we propose HeadSonic, a usable BCE authentication system based on the unique head-conducted sounds, which can be acquired when the user wears the BCE device. Specifically, the system emits a millisecond-level sound to initiate the authentication session. The signal captured by the BCE microphone is propagated through the user's head, which is unique in density, geometry, and bone-tissue ratio. It operates implicitly, while maintaining robustness across different behaviors. Extensive experiments involving 60 subjects demonstrate that HeadSonic achieves a commendable balanced accuracy of 96.59%, proving its efficacy and resilience against replay and synthesis attacks. Our dataset and source codes are available athttps://anonymous.4open.science/r/HeadSonic-1CE4.
Zhixiang He, Jing Chen 0003, Kun He 0008, Yangyang Gu, Qiyi Deng, Zijian Zhang 0001, Ruiying Du, Qingchuan Zhao, Cong Wu 0003
IEEE Trans. Mob. Comput.2
2025 EP-GSPR: An Efficient Privacy-Preserving Graph Shortest Path Retrieval Scheme
abstract
The continuous development of mobile terminal applications, online maps, and other navigation services have become widely used, simultaneously giving rise to significant security risks. To address the issues of privacy leakage and low efficiency in traditional graph shortest path retrieval schemes, an efficient privacy-preserving graph shortest path retrieval scheme is proposed, called EP-GSPR. Specifically, this scheme addresses the privacy security problems in the existing graph shortest path retrieval solutions by ensuring the bilateral privacy protection of the user's query location and the database privacy of the cloud server. Throughout the retrieval process, the cloud server cannot obtain the user's location information, and the user cannot access any database information other than the retrieval results. To overcome the performance bottlenecks in existing schemes, a progressive iterative retrieval framework is designed as the fundamental modular, called Pirf, achieving sub-linear retrieval costs and low storage overhead on the cloud server side. Finally, the security analyses demonstrate the EP-GSPR scheme achieves the bilateral privacy-preserving in terms of user and server sides. The comprehensive experiment evaluations also state the efficiency and practicality of the proposed scheme
Chenbin Zhao, Ruifeng Zhu, Jing Chen 0003, Ruiying Du, Kun He 0008, Jianting Ning, Yang Xiang 0001
IEEE Trans. Mob. Comput.3
2025 ACE-pFL: Accurate, Efficient Personalized Federated Learning With Knowledge Distillation
abstract
Personalized Federated Learning (pFL) can collaboratively personalize models for multiple clients without sharing their private data. However, many pFL methods rely on server-side model parameters aggregation, which requires all models to have the same structure and size. One promising approach is leveraging knowledge distillation (KD) to transfer knowledge between models by exchanging soft predictions rather than model parameters, thus training heterogeneous models. Nevertheless, existing KD-based pFL solutions suffer from accuracy loss due to inadequate knowledge extraction as well as huge computing and communication overheads. In this paper, we present an accurate and efficient KD-based pFL framework, called ACE-pFL. Specifically, we first propose a privacy-preserving client clustering to reduce the impact of non-independent and identically distributed (non-IID) data on model accuracy and convergence, grouping clients with similar data distributions into the same cluster. Since the distillation temperature of traditional KD is fixed, which does not consider the dynamic model training process, we design a dynamic distillation temperature adjustment to accommodate this process, where clients incrementally increase the distillation temperature as training proceeds to facilitate model generalization to new data. Finally, we employ the triple distillation strategy to provide diverse and abundant knowledge, including explicit global knowledge, implicit local knowledge, and implicit global knowledge. Experiments on multiple datasets and tasks show that compared with existing schemes, ACE-pFL can significantly improve the test accuracy by 17.18%, reduce the training time by 57% and the communication overhead by$59.12\times $on average.
Kun He 0008, Yuqing Li 0001, Jing Chen 0003, Ruiying Du
IEEE Trans. Netw.4
2025 A Formal Analysis of 5G EAP-TLS Protocol
abstract
The emergence of private 5G networks has garnered significant attention from enterprises. To ensure the security of communication devices within these networks, the 3GPP group proposed the 5G Extensible Authentication Protocol-Transport Layer Security (EAP-TLS). Despite its critical role, the security of 5G EAP-TLS has not been systematically studied. In this paper, we present the first comprehensive formal model of the 5G EAP-TLS protocol, detailing its flow and incorporating all parties and the certificate distribution mechanism as defined by the 5G specification. Additionally, we extract and interpret the security requirements outlined in the specification. Using the automated symbolic tool Tamarin, we analyze the protocol’s security goals and identify potential vulnerabilities. We propose and verify solutions to these issues, enhancing the protocol’s security. This work provides a foundational understanding and improvements for securing private 5G networks.
Jing Chen 0003, Kun He 0008, Ruiying Du
IEEE Trans. Netw.2
2025 Towards Effective Detection of Ponzi Schemes on Ethereum with Contract Runtime Behavior Graph
abstract
Ponzi schemes, a form of scam, have been discovered in Ethereum smart contracts in recent years, causing massive financial losses. Existing detection methods primarily focus on rule-based approaches and machine learning techniques that utilize static information as features. However, these methods have significant limitations. Rule-based approaches rely on pre-defined rules with limited capabilities and domain knowledge dependency. Using static information like opcodes for machine learning fails to effectively characterize Ponzi contracts, resulting in poor reliability and interpretability. Our research shows no significant difference between Ponzi and non-Ponzi contracts at the opcode level. Moreover, relying on static information like transactions for machine learning requires a certain number of transactions to achieve detection, which limits the scalability of detection and hinders the identification of 0-day Ponzi schemes. In this article, we propose PonziGuard , an efficient Ponzi scheme detection approach based on contract runtime behavior. Inspired by the observation that a contract’s runtime behavior is more effective in disguising Ponzi contracts from the innocent contracts, PonziGuard establishes a comprehensive graph representation called contract runtime behavior graph (CRBG), to accurately depict the behavior of Ponzi contracts. Furthermore, it formulates the detection process as a graph classification task on CRBG, enhancing its overall effectiveness. The experiment results show that PonziGuard surpasses the current state-of-the-art approaches in the ground-truth dataset, achieving a precision of 96.9%, recall of 98.2%, and F1-score of 97.5%. It also exhibits the highest level of interpretability among the current tools. We applied PonziGuard to Ethereum Mainnet and demonstrated its effectiveness in real-world scenarios. Using PonziGuard , we identified 805 Ponzi contracts on Ethereum Mainnet, which have resulted in an estimated economic loss of 281,700 Ether or approximately \($\) 500 million USD. We also found 0-day Ponzi schemes in the recently deployed 10,000 smart contracts.
Ruichao Liang, Jing Chen 0003, Cong Wu 0003, Kun He 0008, Yueming Wu 0001, Weisong Sun, Ruiying Du, Qingchuan Zhao, Yang Liu 0003
ACM Trans. Softw. Eng. Methodol.2
2025 Practical Multiuser Dynamic Searchable Symmetric Encryption With Collusion Resistance
abstract
As data sharing becomes more prevalent, there is growing interest in multiuser dynamic searchable symmetric encryption (MU-DSSE). It enables multiple authorized users to search the encrypted database while safeguarding data privacy. However, most existing schemes are inefficient due to complex computation operations and unaffordable storage burdens. In addition, some are susceptible to collusion attacks between cloud server and compromised users, leading to the leakage of search privacy from other legitimate users. To overcome these challenges, we propose a practical MU-DSSE scheme featuring an unlinkable key derivation mechanism to thwart collusion attacks. Moreover, the MU-DSSE scheme ensures both forward and backward securities in the dynamic setting. To enhance efficiency, we introduce an innovative identity-based key encapsulation mechanism for distributing authorization information to multiple users, significantly optimizing computation and storage costs on user sides and the data owner. Furthermore, we provide the formal security proof and performance analyses. The experimental results demonstrate that MU-DSSE incurs the constant-size storage cost on user sides and the data owner, and outperforms the existing schemes in practice.
Chenbin Zhao, Ruiying Du, Jing Chen 0003, Kun He 0008, Li Xu 0002, Jiguo Li 0001
IEEE Trans. Reliab.3
2024 TokenScout: Early Detection of Ethereum Scam Tokens via Temporal Graph Learning
abstract
Decentralized finance has experienced phenomenal growth, revolutionizing the landscape of financial transactions and asset management via blockchain. Yet, this swift growth brings with it substantial challenges, notably the surge in scam tokens, imposing significant security threats on cryptocurrency investments and trading. Existing detection methods of scam token, primarily relying on analyzing contract codes or transaction patterns, struggle to catch increasingly sophisticated tactics employed by scammers. For example, contract-based analysis are unable to identify scams lacking overt malicious code, e.g., most rugpulls, while transaction-based methods generally lack the foresight to early-detect potential risks.
Cong Wu 0003, Jing Chen 0003, Ziming Zhao 0001, Kun He 0008, Guowen Xu, Yueming Wu 0001, Haijun Wang 0002, Hongwei Li 0001, Yang Liu 0003, Yang Xiang 0001
CCS2
2024 PonziGuard: Detecting Ponzi Schemes on Ethereum with Contract Runtime Behavior Graph (CRBG)
abstract
Ponzi schemes, a form of scam, have been discovered in Ethereum smart contracts in recent years, causing massive financial losses. Rule-based detection approaches rely on pre-defined rules with limited capabilities and domain knowledge dependency. Additionally, using static information like opcodes and transactions for machine learning models fails to effectively characterize the Ponzi contracts, resulting in poor reliability and interpretability.
Ruichao Liang, Jing Chen 0003, Kun He 0008, Yueming Wu 0001, Gelei Deng, Ruiying Du, Cong Wu 0003
ICSE2
2024 Efficient and Straggler-Resistant Homomorphic Encryption for Heterogeneous Federated Learning
abstract
Cross-silo federated learning (FL) enables multiple institutions (clients) to collaboratively build a global model without sharing their private data. To prevent privacy leakage during aggregation, homomorphic encryption (HE) is widely used to encrypt model updates, yet incurs high computation and communication overheads. To reduce these overheads, packed HE (PHE) has been proposed to encrypt multiple plaintexts into a single ciphertext. However, the original design of PHE does not consider the heterogeneity among different clients, an intrinsic problem in cross-silo FL, often resulting in undermined training efficiency with slow convergence and stragglers. In this work, we propose FedPHE, an efficiently packed homomorphically encrypted FL framework with secure weighted aggregation and client selection to tackle the heterogeneity problem. Specifically, using CKKS with sparsification, FedPHE can achieve efficient encrypted weighted aggregation by accounting for contributions of local updates to the global model. To mitigate the straggler effect, we devise a sketching-based client selection scheme to cherry-pick representative clients with heterogeneous models and computing capabilities. We show, through rigorous security analysis and extensive experiments, that FedPHE can efficiently safeguard clients’ privacy, achieve a training speedup of 1.85 − 4.44×, cut the communication overhead by 1.24 − 22.62× , and reduce the straggler effect by up to 1.71 − 2.39×.
Nan Yan 0001, Yuqing Li 0001, Jing Chen 0003, Xiong Wang 0006, Jianan Hong, Kun He 0008, Wei Wang 0030
INFOCOM3
2024 Semantic Sleuth: Identifying Ponzi Contracts via Large Language Models
abstract
Smart contracts, self-executing agreements directly encoded in code, are fundamental to blockchain technology, especially in decentralized finance (DeFi) and Web3. However, the rise of Ponzi schemes in smart contracts poses significant risks, leading to substantial financial losses and eroding trust in blockchain systems. Existing detection methods, such as PonziGuard, depend on large amounts of labeled data and struggle to identify unseen Ponzi schemes, limiting their reliability and generalizability. In contrast, we introduce PonziSleuth, the first LLM-driven approach for detecting Ponzi smart contracts, which requires no labeled training data. PonziSleuth utilizes advanced language understanding capabilities of LLMs to analyze smart contract source code through a novel two-step zero-shot chain-of-thought prompting technique. Our extensive evaluation on benchmark datasets and real-world contracts demonstrates that PonziSleuth delivers comparable, and often superior, performance without the extensive data requirements, achieving a balanced detection accuracy of 96.06% with GPT-3.5-turbo, 93.91% with LLAMA3, and 94.27% with Mistral. In real-world detection, PonziSleuth successfully identified 15 new Ponzi schemes from 4,597 contracts verified by Etherscan in March 2024, with a false negative rate of 0% and a false positive rate of 0.29%. These results highlight PonziSleuth's capability to detect diverse and novel Ponzi schemes, marking a significant advancement in leveraging LLMs for enhancing blockchain security and mitigating financial scams.
Cong Wu 0003, Jing Chen 0003, Ruichao Liang, Ruiying Du
ASE2
2024 CD-BCM:Cross-Domain Batch Certificates Management Based On Blockchain
abstract
Abstract With the development of information networks, the entities from different network domains interact with each other more and more frequently. Therefore, identity management and authentication are essential in cross-domain setting. The traditional Public Key Infrastructure (PKI) architecture has some problems, including single point of failure, inefficient certificate revocation status management and also lack of privacy protection, which cannot meet the demand of cross-domain identity authentication. Blockchain is suitable for multi-participant collaboration in multi-trust domain scenarios. In this paper, a cross-domain certificate management scheme CD-BCM based on the consortium blockchain is proposed. For the issue of Certificate Authority’s single point of failure, we design a multi-signature algorithm. In addition, we propose a unified structure for batch certificates verification and conversion, which improve the efficiency of erroneous certificate identification. Finally, by comparing with current related schemes, our scheme achieves good functionality and scalability in the scenario of cross-domain certificate management.
Shixiong Yao, Jing Chen 0003, Yuexing Zeng, Jiageng Chen
Comput. J.3
2024 Model-agnostic adversarial example detection via high-frequency amplification
Jing Chen 0003, Kun He 0008, Zijun Zhang 0003, Ruiying Du, Jisi She
Comput. Secur.2
2024 Corrigendum to "Model-agnostic Adversarial Example Detection via High-Frequency Amplification" [Computers & Security, Volume 141, June 2024, 103791]
Jing Chen 0003, Kun He 0008, Zijun Zhang 0003, Ruiying Du, Jisi She
Comput. Secur.2
2024 Secure and Scalable Cross-Domain Data Sharing in Zero-Trust Cloud-Edge-End Environment Based on Sharding Blockchain
abstract
The cloud-edge-end architecture is suitable for many essential scenarios, such as 5 G, the Internet of Things (IoT), and mobile edge computing. Under this architecture, cross-domain and cross-layer data sharing is commonly in need. Considering cross-domain data sharing under the zero-trust model, where each entity does not trust the others, existing solutions have certain problems regarding security, fairness, scalability, and efficiency. Aiming at solving these issues, we conduct the following research. First, a new plaintext checkable encryption scheme is constructed, which can be used on lightweight IoT devices to verify the ciphertext validity sent by a data owner. Second, we propose a new multi-domain cloud-edge-end architecture based on sharding blockchains and design a cross-domain data sharing scheme under the partial trust model to achieve security, scalability, and high performance. Third, a cross-domain data sharing scheme under the zero trust model is further designed, which can ensure the fairness of both parties in data sharing. Fourth, we give a formal security definition and analysis of cross-domain data sharing. Fifth, we conduct a detailed theoretical analysis of the protocol and give an in-depth functional test and performance test, including the throughput and latency of data sharing policy registration and execution.
Yizhong Liu, Xinxin Xing, Ziheng Tong, Xun Lin, Jing Chen 0003, Zhenyu Guan 0002, Qianhong Wu, Willy Susilo
IEEE Trans. Dependable Secur. Comput.5
2024 Generic Construction of Threshold Credential Management With User-Autonomy Aggregation
abstract
Credential management is widely used in online services such as electronic identity cards, e-health, and e-voting, in which users prove their identity or attributes with credentials issued by authorities. Under some circumstances, a user needs to prove her/his identity or attributes in multiple credentials to a verifier. In existing credential management systems, a user either proves her/his credentials one by one or requests new credentials from authorities with the original ones, and they are inefficient in practice. Moreover, existing decentralized credential management systems either rely on multiple single parties or do not support attribute revocation. In this paper, we present a threshold credential management system with threshold issuance and revocation and user-autonomy aggregation. Specifically, we design a decentralized credential management architecture where multiple authorities form an alliance and manage credentials collaboratively. Then, we propose a threshold credential management scheme, where user issuance and revocation must be approved by multiple credential managers, and a user can aggregate her/his credentials and prove them to a verifier simultaneously. We conduct experiments on our system and the results demonstrate that it is suitable in practice.
Jing Chen 0003, Kun He 0008, Yuanzheng Wang, Ruiying Du
IEEE Trans. Inf. Forensics Secur.2
2024 MaskAuct: Seller-Autonomous Auction With Bidder Anonymity and Bidding Confidentiality
abstract
Electronic auctions, popular in the digital era, raise great privacy concerns that may impact participant interests. However, traditional privacy-preserving auction systems fall short in facilitating seller autonomy, particularly in identifying and excluding previously mischievous anonymous bidders. In this paper, we propose MaskAuct, a seller-autonomous auction system with the privacy of bidder identity and bidding price. To enable seller autonomy without compromising bidder privacy, we present a new cryptographic primitive, called Zero-Knowledge Blacklistable Group Signature (ZKBGS), which can invalidate signatures from users in the blacklist without opening user identity. We construct MaskAuct from fully homomorphic encryption and ZKBGS, and introduce the distributed privacy server provider to address the collusion problem. The experimental results show ZKBGS has a smaller signature size (8320 bytes) and running time (635 ms for signing and 24 ms for verification) than the linkable ring signature, even when the length of the blacklist is$2^{9}$. In contrast to the sealed-bid auction scheme SEAL, MaskAuct provides better communication complexity, and is$27\times $faster on bidder computation.
Siqin Li, Kun He 0008, Jing Chen 0003, Ruiying Du
IEEE Trans. Inf. Forensics Secur.3
2024 Rethinking Membership Inference Attacks Against Transfer Learning
abstract
Transfer learning, successful in knowledge translation across related tasks, faces a substantial privacy threat from membership inference attacks (MIAs). These attacks, despite posing significant risk to ML model’s training data, remain limited-explored in transfer learning. The interaction between teacher and student models in transfer learning has not been thoroughly explored in MIAs, potentially resulting in an under-examined aspect of privacy vulnerabilities within transfer learning. In this paper, we propose a new MIA vector against transfer learning, to determine whether a specific data point was used to train the teacher model while only accessing the student model in a white-box setting. Our method delves into the intricate relationship between teacher and student models, analyzing the discrepancies in hidden layer representations between the student model and its shadow counterpart. These identified differences are then adeptly utilized to refine the shadow model’s training process and to inform membership inference decisions effectively. Our method, evaluated across four datasets in diverse transfer learning tasks, reveals that even when an attacker only has access to the student model, the teacher model’s training data remains susceptible to MIAs. We believe our work unveils the unexplored risk of membership inference in transfer learning.
Cong Wu 0003, Jing Chen 0003, Qianru Fang, Kun He 0008, Ziming Zhao 0001, Hao Ren 0001, Guowen Xu, Yang Liu 0003, Yang Xiang 0001
IEEE Trans. Inf. Forensics Secur.2
2024 Fregata: Fast Private Inference With Unified Secure Two-Party Protocols
abstract
Private Inference (PI) safeguards client and server privacy when the client utilizes the server’s model to make predictions. Existing PI solutions for Convolutional Neural Networks (CNNs) employ distinct cryptographic primitives to customize secure two-party protocols for linear and non-linear layers. This requires data to be converted into a specific form to switch between protocols, thus leading to a significant increase in inference latency. In this paper, we present Fregata, a fast PI scheme for CNNs by leveraging identical cryptographic primitives to calculate both linear and nonlinear layers. Specifically, our protocols utilize homomorphic encryption to obtain additive secret shares of matrix products during the offline phase, followed by lightweight multiplication and addition operations on these shares in the latency-sensitive online phase. Benefiting from uniformity, we accelerate inference from a holistic perspective by decoupling certain procedures of our protocols and executing them asynchronously. Moreover, to improve the efficiency of the offline phase, we elaborate a homomorphic matrix multiplication calculation method with reduced computation and communication complexity compared to existing approaches. Furthermore, we minimize inference latency by employing graphics processing units to parallelize the operations on the shares during the online phase. Experimental evaluations on popular CNN models such as SqueezeNet, ResNet, and DenseNet demonstrate that Fregata reduces 35-45 times inference latency over the state-of-the-art counterparts, accompanied by a 1.6-2.8 times decrease in communication overhead. In terms of total runtime, Fregata maintains a reduction of approximately 3 times.
Xuanang Yang, Jing Chen 0003, Yuqing Li 0001, Kun He 0008, Zikuan Jiang, Ruiying Du
IEEE Trans. Inf. Forensics Secur.2
2024 WiFiLeaks: Exposing Stationary Human Presence Through a Wall With Commodity Mobile Devices
abstract
WiFi devices are ubiquitous and may leak user and household privacy. In this paper, we report an attack, namely WiFiLeaks, which uses a commodity mobile device to passively detect stationary human presence through a wall by analyzing the channel state information of wireless signals transmitted by indoor WiFi devices. In our adversarial scenario, attackers cannot control the WiFi transmitter or use advanced radio devices. The main challenge of this attack is how to extract robust features from non-customized signals for stationary human presence. To address this challenge, we first combine methods based on outliers and wavelet denoising to enhance the low-frequency information related to human presence. Then we propose a novel feature extraction method based on the correlation among subcarriers since stationary human presence can enhance their correlations. We evaluate WiFiLeaks using nine different WiFi transmitter and one commodity smartphone in four different settings. The evaluations show WiFiLeaks can still achieve accuracy rates of 83.33% and 100% for human presence and absence at 20 meters between the monitor device and the transmitter in through-the-wall scenarios.
Yangyang Gu, Jing Chen 0003, Kun He 0008, Cong Wu 0003, Ziming Zhao 0001, Ruiying Du
IEEE Trans. Mob. Comput.2
2024 UFinAKA: Fingerprint-Based Authentication and Key Agreement With Updatable Blind Credentials
abstract
Authentication and key agreement are two basic functionalities to guarantee secure network communications, which are naturally integrated as an Authentication and Key Agreement (AKA) protocol. AKAs usually either need a dedicated device to store a cryptographic key or require the user to remember a password. In recent years, AKAs built on biometrics, e.g., human fingerprints, have gained research attention since they avoid these issues. Unlike keys or passwords that can be updated, biometrics are at greater risk that cannot be reused once disclosed. However, existing mechanisms either explicitly expose the biometrics to the server or consume a massive amount of resources. This paper proposes UFinAKA, a privacy-preserving fingerprint-based authentication and key agreement system with updatable blind credentials. UFinAKA explores a fingerprint-based blind credential authentication scheme as a building block such that the server has no access to the fingerprint data hidden within the credential. Furthermore, UFinAKA provides an updatable fingerprint-based credentials AKA protocol, which allows the server to update the blind credentials and guarantees anonymous fingerprint authentication to mitigate further leakage when the server is corrupted. We perform security analysis and experimental evaluation on UFinAKA. The evaluation results show that UFinAKA requires only linear computation overhead for the client, a single round of interaction, and roughly linear computation and storage cost for the server. The running time of UFinAKA is at least 4 times faster than the state-of-the-art solutions, and the storage cost of these solutions is at least 100 times more than UFinAKA.
Mei Wang 0003, Jing Chen 0003, Kun He 0008, Ruozhou Yu, Ruiying Du
IEEE/ACM Trans. Netw.2
2024 FACT: Sealed-Bid Auction With Full Privacy via Threshold Fully Homomorphic Encryption
abstract
Sealed-bid auction is a common mechanism for selling and buying commodities. However, existing auction schemes to protect bids require at least squared computation and communication complexity for the bidders or rely on trusted auctioneers or third parties. To address the above problems, we propose a secure and efficient sealed-bid auction framework, called FACT. We design a lightweight threshold fully homomorphic encryption scheme as the building block. Our framework does not rely on any trusted auctioneer and fulfills a stronger security guarantee, called full privacy, i.e., only the seller and the winning bidder can determine the auction result. While our framework applies to first-price sealed-bid, it can easily be extended to support second-price sealed-bid (i.e., Vickrey auction) with the same security guaranteed. Our framework also supports the dynamic joining and exiting of sellers and bidders. Meanwhile, our framework reduces the bidders’ overhead and the number of interactions to a constant level. We formally prove the security of our framework in the semi-honest adversary model. We implement FACT and run experiments comparing its performance against existing schemes. We find that our framework not only achieves a stronger security guarantee but also shows significant performance improvement compared to existing schemes.
Erjun Zhou, Jing Chen 0003, Kun He 0008, Ruiying Du, Mei Wang 0003, Yunyu Yao
IEEE Trans. Serv. Comput.2
2023 What can Discriminator do? Towards Box-free Ownership Verification of Generative Adversarial Networks
abstract
In recent decades, Generative Adversarial Network (GAN) and its variants have achieved unprecedented success in image synthesis. However, well-trained GANs are under the threat of illegal steal or leakage. The prior studies on remote ownership verification assume a black-box setting where the defender can query the suspicious model with specific inputs, which we identify is not enough for generation tasks. To this end, in this paper, we propose a novel IP protection scheme for GANs where ownership verification can be done by checking outputs only, without choosing the inputs (i.e., box-free setting). Specifically, we make use of the unexploited potential of the discriminator to learn a hypersphere that captures the unique distribution learned by the paired generator. Extensive evaluations on two popular GAN tasks and more than 10 GAN architectures demonstrate our proposed scheme to effectively verify the ownership. Our proposed scheme shown to be immune to popular input-based removal attacks and robust against other existing attacks. The source code and models are available at https://github.com/AbstractTeen/gan_ownership_verification.
Ziheng Huang 0008, Boheng Li, Yan Cai 0015, Run Wang 0001, Shangwei Guo, Liming Fang 0001, Jing Chen 0003, Lina Wang 0001
ICCV7
2023 Free Fine-tuning: A Plug-and-Play Watermarking Scheme for Deep Neural Networks
abstract
Watermarking has been widely adopted for protecting the intellectual property (IP) of Deep Neural Networks (DNN) to defend the unauthorized distribution. Unfortunately, studies have shown that the popular data-poisoning DNN watermarking scheme via tedious model fine-tuning on a poisoned dataset (carefully-crafted sample-label pairs) is not efficient in tackling the tasks on challenging datasets and production-level DNN model protection. To address the aforementioned limitation, in this paper, we propose a plug-and-play watermarking scheme for DNN models by injecting an independent proprietary model into the target model to serve the watermark embedding and ownership verification. In contrast to the prior studies, our proposed method by incorporating a proprietary model is free of target model fine-tuning without involving any parameters update of the target model, thus the fidelity is well preserved and scalable to challenging real tasks. Experimental results on real-world challenging datasets (e.g., ImageNet) and production-level DNN models demonstrated its effectiveness, fidelity w.r.t. the functionality preservation of the target model, robustness against popular watermark removal attacks, and the plug-and-play deployment. The source code and models are available at https://github.com/AntigoneRandy/PTYNet.
Run Wang 0001, Jixing Ren, Boheng Li, Tianyi She, Liming Fang 0001, Jing Chen 0003, Lina Wang 0001
ACM Multimedia7
2023 Efficient Adversarial Training with Membership Inference Resistance
Ran Yan 0001, Ruiying Du, Kun He 0008, Jing Chen 0003
PRCV (1)4
2023 Formal Analysis and Patching of BLE-SC Pairing
Jing Chen 0003, Kun He 0008, Ruiying Du
USENIX Security Symposium2
2023 Efficient Privacy-Preserving Inference Outsourcing for Convolutional Neural Networks
abstract
Inference outsourcing enables model owners to deploy their machine learning models on cloud servers to serve users. In this paradigm, the privacy of model owners and users should be considered. Existing solutions focus on Convolutional Neural Networks (CNNs) but their efficiency is much lower than GALA, which is a solution that only protects user privacy. Furthermore, these solutions adopt approximations that reduce the model accuracy and thus require model owners to retrain the models. In this paper, we present an efficient CNN inference outsourcing solution that protects the privacy of both model owners and users. Specifically, we design secure two-party computation protocols based on two non-colluding cloud servers, which calculate with additive secret shares of the model and the user’s input. Our protocols avoid the expensive permutation operations in linear calculations and approximations in non-linear calculations. We implement our solution on realistic CNNs and experimental results show that our solution is even 2–4 times faster than GALA.
Xuanang Yang, Jing Chen 0003, Kun He 0008, Cong Wu 0003, Ruiying Du
IEEE Trans. Inf. Forensics Secur.2
2023 Dynamic Personalized POI Sequence Recommendation with Fine-Grained Contexts
abstract
The Point Of Interest (POI) sequence recommendation is the key task in itinerary and travel route planning. Existing works usually consider the temporal and spatial factors in travel planning. However, the external environment, such as the weather, is usually overlooked. In fact, the weather is an important factor because it can affect a user’s check-in behaviors. Furthermore, most of the existing research is based on a static environment for POI sequence recommendation. While the external environment (e.g., the weather) may change during travel, it is difficult for existing works to adjust the POI sequence in time. What’s more, people usually prefer the attractive routes when traveling. To address these issues, we first conduct comprehensive data analysis on two real-world check-in datasets to study the effects of weather and time, as well as the features of the POI sequence. Based on this, we propose a model of Dynamic Personalized POI Sequence Recommendation with fine-grained contexts ( DPSR for short). It extracts user interest and POI popularity with fine-grained contexts and captures the attractiveness of the POI sequence. Next, we apply the Monte Carlo Tree Search model (MCTS for short) to simulate the process of recommending POI sequence in the dynamic environment, i.e., the weather and time change after visiting a POI. What’s more, we consider different speeds to reflect the fact that people may take different transportation to transfer between POIs. To validate the efficacy of DPSR , we conduct extensive experiments. The results show that our model can improve the accuracy of the recommendation significantly. Furthermore, it can better meet user preferences and enhance experiences.
Jing Chen 0003, Jie Wu 0001, Kenli Li 0001, Keqin Li 0001
ACM Trans. Internet Techn.1
2022 EchoHand: High Accuracy and Presentation Attack Resistant Hand Authentication on Commodity Mobile Devices
abstract
Biometric authentication schemes, i.e., fingerprint and face authentication, raise serious privacy concerns. To alleviate such concerns, hand authentication has been proposed recently. However, existing hand authentication schemes use dedicated hardware, such as infrared or depth cameras, which are not available on commodity mobile devices. In this paper, we present EchoHand, a high accuracy and presentation attack resistant authentication scheme that complements camera-based 2-dimensional hand geometry recognition of one hand with active acoustic sensing of the other holding hand. EchoHand plays an inaudible acoustic signal using the speaker to actively sense the holding hand and collects the echoes using the microphone. EchoHand does not rely on any specialized hardware but uses the built-in speaker, microphone and camera. Moreover, EchoHand does not place more burdens on users than existing hand authentication methods. We conduct comprehensive experiments to evaluate the reliability and security of EchoHand. The results show that EchoHand has a low equal error rate of 2.45% with as few as 10 training data points and it defeats presentation attacks.
Cong Wu 0003, Jing Chen 0003, Kun He 0008, Ziming Zhao 0001, Ruiying Du
CCS2
2022 Anti-Forgery: Towards a Stealthy and Robust DeepFake Disruption Attack via Adversarial Perceptual-aware Perturbations
abstract
DeepFake is becoming a real risk to society and brings potential threats to both individual privacy and political security due to the DeepFaked multimedia are realistic and convincing. However, the popular DeepFake passive detection is an ex-post forensics countermeasure and failed in blocking the disinformation spreading in advance. To address this limitation, researchers study the proactive defense techniques by adding adversarial noises into the source data to disrupt the DeepFake manipulation. However, the existing studies on proactive DeepFake defense via injecting adversarial noises are not robust, which could be easily bypassed by employing simple image reconstruction revealed in a recent study MagDR. In this paper, we investigate the vulnerability of the existing forgery techniques and propose a novel anti-forgery technique that helps users protect the shared facial images from attackers who are capable of applying the popular forgery techniques. Our proposed method generates perceptual-aware perturbations in an incessant manner which is vastly different from the prior studies by adding adversarial noises that is sparse. Experimental results reveal that our perceptual-aware perturbations are robust to diverse image transformations, especially the competitive evasion technique, MagDR via image reconstruction. Our findings potentially open up a new research direction towards thorough understanding and investigation of perceptual-aware adversarial attack for protecting facial images against DeepFakes in a proactive and robust manner. Code is available at https://github.com/AbstractTeen/AntiForgery.
Run Wang 0001, Ziheng Huang 0008, Jing Chen 0003, Lina Wang 0001
IJCAI5
2022 Rethinking the Vulnerability of DNN Watermarking: Are Watermarks Robust against Naturalness-aware Perturbations?
abstract
Training Deep Neural Networks (DNN) is a time-consuming process and requires a large amount of training data, which motivates studies working on protecting the intellectual property (IP) of DNN models by employing various watermarking techniques. Unfortunately, in recent years, adversaries have been exploiting the vulnerabilities of the employed watermarking techniques to remove the embedded watermarks. In this paper, we investigate and introduce a novel watermark removal attack, called AdvNP, against all the existing four different types of DNN watermarking schemes via input preprocessing by injecting Adversarial Naturalness-aware Perturbations. In contrast to the prior studies, our proposed method is the first work that generalizes all the existing four watermarking schemes well without involving any model modification, which preserves the fidelity of the target model. We conduct the experiments against four state-of-the-art (SOTA) watermarking schemes on two real tasks (e.g., image classification on ImageNet, face recognition on CelebA) across multiple DNN models. Overall, our proposed AdvNP significantly invalidates the watermarks against the four watermarking schemes on two real-world datasets, i.e., 60.9% on the average attack success rate and up to 97% in the worse case. Moreover, our AdvNP could well survive the image denoising techniques and outperforms the baseline in both the fidelity preserving and watermark removal. Furthermore, we introduce two defense methods to enhance the robustness of DNN watermarking against our AdvNP. Our experimental results pose real threats to the existing watermarking schemes and call for more practical and robust watermarking techniques to protect the copyright of pre-trained DNN models. The source code and models are available at ttps://github.com/GitKJ123/AdvNP.
Run Wang 0001, Lingzhou Mu, Jixing Ren, Shangwei Guo, Liming Fang 0001, Jing Chen 0003, Lina Wang 0001
ACM Multimedia8
2022 PANDA: Lightweight non-interactive privacy-preserving data aggregation for constrained devices
Mei Wang 0003, Kun He 0008, Jing Chen 0003, Ruiying Du, Bingsheng Zhang, Zengpeng Li 0001
Future Gener. Comput. Syst.3
2022 Identity-Based Cloud Storage Auditing for Data Sharing With Access Control of Sensitive Information
abstract
Remote data integrity auditing ensures the integrity of cloud storage. In practice, cloud users may not want their sensitive data to be exposed to others. Thus, it is meaningful to investigate how to realize data sharing with sensitive information hiding in cloud storage auditing. Up to now, cloud storage has been proven to achieve the sensitive information hiding property through a third-party sanitizer dedicated to sanitize user data, which leads to high outlays on purchasing and maintaining a special server. To meet this challenge, we design a novel cloud storage auditing protocol to support sensitive information hiding without the need of a third-party sanitizer. In addition, our scheme allows data owners to enable or disable other users to access their sensitive information with the help of the cloud that dose not deviate from the agreement during access control. To be specific, only after receiving the delegations from the data owner, the users can compute the valid warrants that can pass the access verification of the cloud. The proposed protocol is built on identity-based cryptography, thus avoiding the complex certificate management. We validate the advantages of the proposed protocol through massive theoretical analysis and experimental results.
Yang Yang 0022, Yanjiao Chen, Fei Chen 0003, Jing Chen 0003
IEEE Internet Things J.4
2022 DELIA: Distributed Efficient Log Integrity Audit Based on Hierarchal Multi-Party State Channel
abstract
Audit log contains the trace of different activities in computing systems, which makes it critical for security management, censorship, and forensics. However, experienced attackers may delete or modify the audit log after their attacks, which makes the audit log unavailable in attack investigation. In this article, we focus on the log integrity audit in the same domain, in which a number of servers update audit logs for a single or several organizations as an alliance. We propose a distributed efficient log integrity audit framework, called DELIA, which employs the distributed ledger technique to protect audit information, and utilizes the idea of state channel to improve the throughput of distributed ledger. To generate stable state from the rapidly-updated logs in the domain, we propose a log state generation scheme, which not only generates state suitable for audit logs, but also enables mutual supervision within the domain. To overcome the high latency in existing state channel schemes, we propose a hierarchal multi-party state channel scheme, which makes the latency in our framework independent of the number of servers in the domain. We implement DELIA on Ethereum and evaluate its performance. The results show that our framework is efficient and secure in practice.
Jing Chen 0003, Kun He 0008, Ruiying Du, Weihang Chen, Yang Xiang 0001
IEEE Trans. Dependable Secur. Comput.1
2022 XAuth: Efficient Privacy-Preserving Cross-Domain Authentication
abstract
It is well known that each Public Key Infrastructure (PKI) system forms a closed security domain and only recognizes certificates in its own domain (such as medical systems, financial systems, and 5G networks). When users need to access services in other domains, their identities often cannot be recognized or PKI systems require extremely complex operations to authenticate the users’ identities. This is the cross-domain authentication problem. The distributed consensus feature of blockchain provides a technical approach to solve this problem. However, there are some unresolved problems in existing blockchain-based schemes. On one hand, due to the low throughput of blockchain systems, the response speed may be insufferable when the number of cross-domain authentication requirements becomes enormous. On the other hand, these schemes insufficiently consider the privacy risk in the cross-domain scenario. In this article, we propose an efficient privacy-preserving cross-domain authentication scheme called XAuth that is integrated naturally with the existing PKI and Certificate Transparency (CT) systems. Specifically, we design a lightweight correctness verification protocol based on Multiple Merkle Hash Tree for rapid response. To protect users’ privacy, we present an anonymous authentication protocol for cross-domain authentication. The security analysis and experimental results demonstrate that XAuth is secure and efficient.
Jing Chen 0003, Zeyi Zhan, Kun He 0008, Ruiying Du
IEEE Trans. Dependable Secur. Comput.1
2022 Toward Robust Detection of Puppet Attacks via Characterizing Fingertip-Touch Behaviors
abstract
Fingerprint authentication has gained increasing popularity on mobile devices in recent years. However, it is vulnerable to presentation attacks, which include that an attacker spoofs with an artificial replica. Many liveness detection solutions have been proposed to defeat such presentation attacks; however, they all fail to defend against a particular type of presentation attack, namelypuppet attack, in which an attacker places an unwilling victim's finger on the fingerprint sensor. In this article, we proposeFinAuth, an effective and efficient software-only solution, to complement fingerprint authentication by defeating both synthetic spoofs and puppet attacks usingfingertip-touchcharacteristics.FinAuthcharacterizes intrinsic fingertip-touch behaviors including the acceleration and the rotation angle of mobile devices when a legitimate user authenticates.FinAuthonly utilizes common sensors equipped on mobile devices and does not introduce extra usability burdens on users. To evaluate the effectiveness ofFinAuth, we carried out experiments on datasets collected from 90 subjects after the IRB approval. The results show thatFinAuthcan achieve the average balanced accuracy of 96.04% with 5 training data points and 99.28% with 100 training data points. Security experiments also demonstrate thatFinAuthis resilient against possible attacks. In addition, we report the usability analysis results ofFinAuth, including user authentication delay and overhead.
Cong Wu 0003, Kun He 0008, Jing Chen 0003, Ziming Zhao 0001, Ruiying Du
IEEE Trans. Dependable Secur. Comput.3
2022 Redactable Blockchain From Decentralized Chameleon Hash Functions
abstract
Blockchain is a technology with decentralization and immutability features and has been employed for auditing by many applications. However, immutability sometimes limits the application of blockchain technology. For example, vulnerable smart contracts on blockchain cannot be redacted due to immutability. The existing redactable blockchain solutions either have a low efficiency or violate the decentralization feature. Moreover, those solutions lack mechanisms for tracing redaction history and checking block consistency. In this paper, we present an efficient redactable blockchain with traceability in the decentralized setting. Specifically, we propose a decentralized chameleon hash function for redactable blockchain that every redaction must be approved by multiple blockchain nodes. We also design a redactable blockchain structure that maintains all redactions of a block and encodes the redacted blocks into an RSA accumulator. Then, we propose an efficient block consistency check protocol based on the RSA accumulator. Finally, we conduct experiments and compare our scheme with another decentralized redactable blockchain to demonstrate that our solution is efficient in practice.
Jing Chen 0003, Kun He 0008, Ruiying Du, Mingxi Lai
IEEE Trans. Inf. Forensics Secur.2
2022 An Efficient Identity-Based Provable Data Possession Protocol With Compressed Cloud Storage
abstract
Cloud storage is more and more prevalent in practice, and thus how to check its integrity becomes increasingly essential. A classical solution is identity-based (ID-based) provable data possession (PDP), which supports certificateless cloud storage auditing without entire user data. However, existing ID-PDP protocols always require that cloud users outsource data blocks, authenticators and a small-sized file tag to the cloud, and make use of the heavy elliptic curve cryptography over bilinear pairing. These disadvantages would result in vast storage, communication, and computation costs, which is unexpected, especially for resource-limited cloud users. To improve the performance, this paper proposes a novel cryptographic primitive: ID-based PDP with compressed cloud storage. In this model, cloud storage auditing can be achieved by using only encrypted data blocks in a self-verified way, and original data blocks can be reconstructed from the outsourced data. Thus, data owners no longer need to store original data blocks on the cloud. We also use some basic algebraic operations to realize a concrete ID-based PDP protocol with compressed cloud storage, which is quite efficient due to no heavy cryptographic operations involved. The proposed protocol can easily be extended to support the other practical functions by using the primitive replacement technique. The proposed protocol is strictly proven to have the properties of correctness, privacy, unforgeability and detectability. Finally, we give plenty of theoretical analysis and experimental results to validate the efficiency of the proposed protocol.
Yang Yang 0022, Yanjiao Chen, Fei Chen 0003, Jing Chen 0003
IEEE Trans. Inf. Forensics Secur.4
2021 Backdoor Pre-trained Models Can Transfer to All
abstract
Pre-trained general-purpose language models have been a dominating component in enabling real-world natural language processing (NLP) applications. However, a pre-trained model with backdoor can be a severe threat to the applications. Most existing backdoor attacks in NLP are conducted in the fine-tuning phase by introducing malicious triggers in the targeted class, thus relying greatly on the prior knowledge of the fine-tuning task. In this paper, we propose a new approach to map the inputs containing triggers directly to a predefined output representation of the pre-trained NLP models, e.g., a predefined output representation for the classification token in BERT, instead of a target label. It can thus introduce backdoor to a wide range of downstream tasks without any prior knowledge. Additionally, in light of the unique properties of triggers in NLP, we propose two new metrics to measure the performance of backdoor attacks in terms of both effectiveness and stealthiness. Our experiments with various types of triggers show that our method is widely applicable to different fine-tuning tasks (classification and named entity recognition) and to different models (such as BERT, XLNet, BART), which poses a severe threat. Furthermore, by collaborating with the popular online model repository Hugging Face, the threat brought by our method has been confirmed. Finally, we analyze the factors that may affect the attack performance and share insights on the causes of the success of our backdoor attack.
Lujia Shen, Shouling Ji, Xuhong Zhang 0002, Jing Chen 0003, Chengfang Fang, Jianwei Yin, Ting Wang 0006
CCS5
2021 Biometrics-Authenticated Key Exchange for Secure Messaging
abstract
Secure messaging heavily relies on a session key negotiated by an Authenticated Key Exchange (AKE) protocol. However, existing AKE protocols only verify the existence of a random secret key (corresponding to a certificated public key) stored in the terminal, rather than a legal user who uses the messaging application. In this paper, we propose a Biometrics-Authenticated Key Exchange (BAKE) framework, in which a secret key is derived from a user's biometric characteristics that are not necessary to be stored. To protect the privacy of users' biometric characteristics and realize one-round key exchange, we present an Asymmetric Fuzzy Encapsulation Mechanism (AFEM) to encapsulate messages with a public key derived from a biometric secret key, such that only a similar secret key can decapsulate them. To manifest the practicality, we present two AFEM constructions for two types of biometric secret keys and instantiate them with irises and fingerprints, respectively. We perform security analysis of BAKE and show its performance through extensive experiments.
Mei Wang 0003, Kun He 0008, Jing Chen 0003, Zengpeng Li 0001, Wei Zhao 0054, Ruiying Du
CCS3
2021 HIAWare: Speculate Handwriting on Mobile Devices with Built-In Sensors
Jing Chen 0003, Peidong Jiang, Kun He 0008, Ruiying Du
ICICS (1)1
2021 PROCESS: Privacy-Preserving On-Chain Certificate Status Service
abstract
Clients (e.g., browsers) and servers require public key certificates to establish secure connections. When a client accesses a server, it needs to check the signature, expiration time, and revocation status of the certificate to determine whether the server is reliable. The existing solutions for checking certificate status either have a long update cycle (e.g., CRL, CRLite) or violate clients' privacy (e.g., OCSP, CCSP), and these solutions also have the problem of trust concentration. In this paper, we present PROCESS, an online privacy-preserving on-chain certificate status service based on the blockchain architecture, which can ensure decentralized trust and provide privacy protection for clients. Specifically, we design Counting Garbled Bloom Filter (CGBF) that supports efficient queries and BlockOriented Revocation List (BORL) to update CGBF timely in the blockchain. With CGBF, we design a privacy-preserving protocol to protect clients' privacy when they check the certificate statuses from the blockchain nodes. Finally, we conduct experiments and compare PROCESS with another blockchain-based solution to demonstrate that PROCESS is suitable in practice.
Kun He 0008, Jing Chen 0003, Ruiying Du, Weihang Chen, Zhihong Tian 0001, Shouling Ji
INFOCOM3
2021 Consistency-Constancy Bi-Knowledge Learning for Pedestrian Detection in Night Surveillance
abstract
Pedestrian detection in the night surveillance is a challenging yet not largely explored task. As the success of the detector in the daytime surveillance and the convenient acquisition of all-weather data, we learn knowledge from these data to benefit pedestrian detection in night surveillance. We find two key properties of surveillance: distribution cross-time consistency and background cross-frame constancy. This paper proposes a consistency-constancy bi-knowledge learning (CCBL) for pedestrian detection in night surveillance, which is able to simultaneously achieve the night pedestrian detection's useful knowledge, coming from day and night surveillance. Firstly, based on the robustness of the existing detector in day surveillance, we obtain pedestrians' distribution in the daytime scene using the detector's detection results in the daytime scene. Based on the consistency of pedestrians' distribution during the day and night in the same scene, the pedestrian distribution from daytime is used as the consistency-knowledge for pedestrian detection in night surveillance. Secondly, the background as a constant knowledge of the surveillance scene is extractable and contributes to the division of the foreground, which contains most of the pedestrian regions and helps in pedestrian detection for night surveillance. Finally, we add bi-knowledge representation to promote each other and merge them together as the final pedestrian representation. Through extensive experiments, our CCBL significantly outperforms the state-of-the-art methods on public pedestrian detection datasets. In the NightSurveillance dataset, CCBL reduced the average missed detection rate by 3.04% compared to the existing best method.
Xiao Wang 0029, Zheng Wang 0007, Wu Liu 0005, Xin Xu 0007, Jing Chen 0003, Chia-Wen Lin
ACM Multimedia5
2021 SeCrowd: Efficient secure interactive crowdsourcing via permission-based signatures
Jing Chen 0003, Kun He 0008, Ruiying Du
Future Gener. Comput. Syst.1
2021 Semantics-Aware Privacy Risk Assessment Using Self-Learning Weight Assignment for Mobile Apps
abstract
Most of the existing mobile application (app) vetting mechanisms only estimate risks at a coarse-grained level by analyzing app syntax but not semantics. We propose a semantics-aware privacy risk assessment framework (SPRisk), which considers the sensitivity discrepancy of privacy-related factors at semantic level. Our framework can provide qualitative (i.e., risk level) and quantitative (i.e., risk score) assessment results, both of which help users make decisions to install an app or not. Furthermore, to find the reasonable weight distribution of each factor automatically, we exploit a self-learning weight assignment method, which is based on fuzzy clustering and knowledge dependency theory. We implement a prototype system and evaluate the effectiveness of SPRisk with 192,445 normal apps and 7,111 malicious apps. A measurement study further reveals some interesting findings, such as the privacy risk distribution of Google Play Store, the diversity of official and unofficial marketplaces, which provide insights into understanding the seriousness of privacy threat in the Android ecosystem.
Jing Chen 0003, Chiheng Wang, Kun He 0008, Ziming Zhao 0001, Min Chen 0003, Ruiying Du, Gail-Joon Ahn
IEEE Trans. Dependable Secur. Comput.1
2021 Dynamic Group-Oriented Provable Data Possession in the Cloud
abstract
As an important security property of cloud storage, data integrity has not been sufficiently studied under the multi-writer model, where a group of users work on shared files collaboratively and any group member can update the data by modification, insertion, and deletion operations. Existing works under such multi-writer model would bring large storage cost to the third-party verifiers. Furthermore, to the best of our knowledge, none of the existing works for shared files supports fully dynamic operations, which implies that users cannot freely perform the update operations. In this paper, we propose the first public auditing scheme for shared data that supports fully dynamic operations and achieves constant storage cost for the verifiers. Our scheme, named PRAYS, is boosted by a new paradigm for remote data integrity checking. To implement the new paradigm, we proposed a specially designed authenticated structure, called blockless Merkle tree, and a novel cryptographic primitive, called permission-based signature. Extensive evaluation demonstrates that PRAYS is as efficient as the existing less-functional solutions. We believe that PRAYS is an important step towards designing practical multi-writer cloud storage systems.
Kun He 0008, Jing Chen 0003, Quan Yuan 0003, Shouling Ji, Debiao He, Ruiying Du
IEEE Trans. Dependable Secur. Comput.2
2021 Secure Dynamic Searchable Symmetric Encryption With Constant Client Storage Cost
abstract
Dynamic Searchable Symmetric Encryption (DSSE) enables users to search on the encrypted database stored on a semi-trusted server while keeping the search and update information under acceptable leakage. However, most existing DSSE schemes are not efficient enough in practice due to the complex structures and cryptographic primitives. Moreover, the storage cost on the client side grows linearly with the number of keywords in the database, which induces unaffordable storage cost when the size of keyword set is large. In this article, we focus on secure dynamic searchable symmetric encryption with constant client storage cost. Our framework is boosted by fish-bone chain, a novel two-level structure which consists of Logical Keyword Index Chain (LoKIC) and Document Index Chain (DIC). To instantiate the proposed framework, we propose a forward secure DSSE scheme, called CLOSE-F, and a forward and backward secure DSSE scheme, called CLOSE-FB. Experiments showed that the computation cost of CLOSE-F and CLOSE-FB are as efficient as the state-of-the-art solutions, while the storage costs on the client side are constant in both CLOSE-F and CLOSE-FB, which are much smaller than existing schemes.
Kun He 0008, Jing Chen 0003, Qinxi Zhou, Ruiying Du, Yang Xiang 0001
IEEE Trans. Inf. Forensics Secur.2
2021 Optimal Location Privacy Preserving and Service Quality Guaranteed Task Allocation in Vehicle-Based Crowdsensing Networks
abstract
With increasing popularity of related applications of mobile crowdsensing, especially in the field of Internet of Vehicles (IoV), task allocation has attracted wide attention. How to select appropriate participants is a key problem in vehicle-based crowdsensing networks. Some traditional methods choose participants based on minimizing distance, which requires participants to submit their current locations. In this case, participants' location privacy is violated, which influences disclosure of participants' sensitive information. Many privacy preserving task allocation mechanisms have been proposed to encourage users to participate in mobile crowdsensing. However, most of them assume that different participants' task completion quality is the same, which is not reasonable in reality. In this paper, we propose an optimal location privacy preserving and service quality guaranteed task allocation in vehicle-based crowdsensing networks. Specifically, we utilize differential privacy to preserve participants' location privacy, where every participant can submit the obfuscated location to the platform instead of the real one. Based on the obfuscated locations, we design an optimal problem to minimize the moving distance and maximize the task completion quality simultaneously. In order to solve this problem, we decompose it into two linear optimization problems. We conduct extensive experiments to demonstrate the effectiveness of our proposed mechanism.
Yongfeng Qian, Yujun Ma, Jing Chen 0003, Di Wu 0001, Daxin Tian, Kai Hwang 0001
IEEE Trans. Intell. Transp. Syst.3
2021 Review Summary Generation in Online Systems: Frameworks for Supervised and Unsupervised Scenarios
abstract
In online systems, including e-commerce platforms, many users resort to the reviews or comments generated by previous consumers for decision making, while their time is limited to deal with many reviews. Therefore, a review summary, which contains all important features in user-generated reviews, is expected. In this article, we study “how to generate a comprehensive review summary from a large number of user-generated reviews.” This can be implemented by text summarization, which mainly has two types of extractive and abstractive approaches. Both of these approaches can deal with both supervised and unsupervised scenarios, but the former may generate redundant and incoherent summaries, while the latter can avoid redundancy but usually can only deal with short sequences. Moreover, both approaches may neglect the sentiment information. To address the above issues, we propose comprehensive Review Summary Generation frameworks to deal with the supervised and unsupervised scenarios. We design two different preprocess models of re-ranking and selecting to identify the important sentences while keeping users’ sentiment in the original reviews. These sentences can be further used to generate review summaries with text summarization methods. Experimental results in seven real-world datasets (Idebate, Rotten Tomatoes Amazon, Yelp, and three unlabelled product review datasets in Amazon) demonstrate that our work performs well in review summary generation. Moreover, the re-ranking and selecting models show different characteristics.
Jing Chen 0003, Xiaofei Ding, Jie Wu 0001, Jiawei He 0003, Guojun Wang 0001
ACM Trans. Web2
2020 De-Health: All Your Online Health Information Are Belong to Us
abstract
In this paper, we study the privacy of online health data. We present a novel online health data De-Anonymization (DA) framework, named De-Health. Leveraging two real world online health datasets WebMD and HealthBoards, we validate the DA efficacy of De-Health. We also present a linkage attack framework which can link online health/medical information to real world people. Through a proof-of-concept attack, we link 347 out of 2805 WebMD users to real world people, and find the full names, medical/health information, birthdates, phone numbers, and other sensitive information for most of the re-identified users. This clearly illustrates the fragility of the privacy of those who use online health forums.
Shouling Ji, Qinchen Gu, Haiqin Weng, Qianjun Liu, Pan Zhou 0001, Jing Chen 0003, Zhao Li 0007, Raheem A. Beyah, Ting Wang 0006
ICDE6
2020 Liveness is Not Enough: Enhancing Fingerprint Authentication with Behavioral Biometrics to Defeat Puppet Attacks
Cong Wu 0003, Kun He 0008, Jing Chen 0003, Ziming Zhao 0001, Ruiying Du
USENIX Security Symposium3
2020 Secure and Lightweight Authentication With Key Agreement for Smart Wearable Systems
abstract
Nowadays, an increasing number of wearable devices (WDs) have been widely deployed in smart wearable systems to collect health status measures and body information of users. Due to the openness of wireless transmission and the low capabilities of WDs in terms of energy and computation, it is of a great challenge to ensure the security of the users' physiological information. In this article, we propose a secure and lightweight authentication and key agreement scheme (SLAKA) by using the fuzzy extractor, the cryptographic hash function, and the bitwise exclusive-or operation. In SLAKA, mutual authentication between a WD and the mobile terminal (MT) can be achieved, after that, a session key can be negotiated at both ends for future secure communications. Detailed security analysis shows that SLAKA has the resilience against various well-known attacks, such as replay attacks, stolen/lost MT/WD attacks, man-in-the-middle attacks, MT/WD impersonation attacks, password change attacks, anonymity and untraceability attacks, and privileged-insider attacks. Through performance comparison and extensive simulation, SLAKA is demonstrated to be more efficient than the existing schemes, while providing more extractive features and security guarantees.
Jiping Li, Ning Zhang 0007, Jianbing Ni, Jing Chen 0003, Ruiying Du
IEEE Internet Things J.4
2020 CaIAuth: Context-Aware Implicit Authentication When the Screen Is Awake
abstract
Relieving users from the burden of remembering and inputting authentication information explicitly, such as passwords/PINs and lock patterns, implicit authentication mechanisms have gained an increasing concern. When providing authentication, the existing implicit methods only depend on a specific behavior, such as typing on the screen, performing gestures, or taking a walk. However, in real applications, a user's behavioral characteristics are also decided by the context where behavior is performed. Thus, those existing methods show limited authentication accuracy and usability. To address these issues, we propose CaIAuth, a reliable context-aware implicit authentication framework, which profiles users' behavior and context characteristics in a holistic fashion. It observes the states of context-sensing entities for different smartphone usage patterns and builds a context-aware model to distinguish between legitimate users and illegal ones. We conducted extensive experiments to evaluate system performance with a large data set collected from 142 subjects. The experimental results show that our system achieves a low equal error rate (EER) (e.g., less 7%) and is resilient against common threats, including zero-effect attack and mimicry attack. In addition, CaIAuth achieves a low authentication delay and overhead.
Cong Wu 0003, Kun He 0008, Jing Chen 0003, Ruiying Du, Yang Xiang 0001
IEEE Internet Things J.3
2020 PowerPrint: Identifying Smartphones through Power Consumption of the Battery
abstract
Device fingerprinting technologies are widely employed in smartphones. However, the features used in existing schemes may bring the privacy disclosure problems because of their fixed and invariable nature (such as IMEI and OS version), or the draconian of their experimental conditions may lead to a large reduction in practicality. Finding a new, secure, and effective smartphone fingerprint is, however, a surprisingly challenging task due to the restrictions on technology and mobile phone manufacturers. To tackle this challenge, we propose a battery-based fingerprinting method, named PowerPrint, which captures the feature of power consumption rather than invariable information of the battery. Furthermore, power consumption information can be easily obtained without strict conditions. We design an unsupervised learning-based algorithm to fingerprint the battery, which is stimulated with different power consumption of tasks to improve the performance. We use 15 smartphones to evaluate the performance of PowerPrint in both laboratory and public conditions. The experimental results indicate that battery fingerprint can be efficiently used to identify smartphones with low overhead. At the same time, it will not bring privacy problems, since the power consumption information is changing in real time.
Kun He 0008, Jing Chen 0003, Yingying Fang, Ruiying Du
Secur. Commun. Networks3
2020 Privacy Protection and Intrusion Avoidance for Cloudlet-Based Medical Data Sharing
abstract
With the popularity of wearable devices, along with the development of clouds and cloudlet technology, there has been increasing need to provide better medical care. The processing chain of medical data mainly includes data collection, data storage and data sharing, etc. Traditional healthcare system often requires the delivery of medical data to the cloud, which involves users' sensitive information and causes communication energy consumption. Practically, medical data sharing is a critical and challenging issue. Thus in this paper, we build up a novel healthcare system by utilizing the flexibility of cloudlet. The functions of cloudlet include privacy protection, data sharing and intrusion detection. In the stage of data collection, we first utilize Number Theory Research Unit (NTRU) method to encrypt user's body data collected by wearable devices. Those data will be transmitted to nearby cloudlet in an energy efficient fashion. Second, we present a new trust model to help users to select trustable partners who want to share stored data in the cloudlet. The trust model also helps similar patients to communicate with each other about their diseases. Third, we divide users' medical data stored in remote cloud of hospital into three parts, and give them proper protection. Finally, in order to protect the healthcare system from malicious attacks, we develop a novel collaborative intrusion detection system (IDS) method based on cloudlet mesh, which can effectively prevent the remote healthcare big data cloud from attacks. Our experiments demonstrate the effectiveness of the proposed scheme.
Min Chen 0003, Yongfeng Qian, Jing Chen 0003, Kai Hwang 0001, Shiwen Mao, Long Hu
IEEE Trans. Cloud Comput.3
2020 EliMFS: Achieving Efficient, Leakage-Resilient, and Multi-Keyword Fuzzy Search on Encrypted Cloud Data
abstract
Motivated by privacy preservation requirements for outsourced data, keyword searches over encrypted cloud data have become a hot topic. Compared to single-keyword exact searches, multi-keyword fuzzy search schemes attract more attention because of their improvements in search accuracy, typo tolerance, and user experience in general. However, existing multi-keyword fuzzy search solutions are not sufficiently efficient when the file set in the cloud is large. To address this, we propose an Efficient Leakage-resilient Multi-keyword Fuzzy Search (EliMFS) framework over encrypted cloud data. In this framework, a novel two-stage index structure is exploited to ensure that search time is independent of file set size. The multi-keyword fuzzy search function is achieved through a delicate design based on the Gram Counting Order, the Bloom filter, and the Locality-Sensitive Hashing. Furthermore, considering the leakages caused by the two-stage index structure, we propose two specific schemes to resist these potential attacks in different threat models. Extensive analysis and experiments show that our schemes are highly efficient and leakage-resilient.
Jing Chen 0003, Kun He 0008, Lan Deng, Quan Yuan 0003, Ruiying Du, Yang Xiang 0001, Jie Wu 0001
IEEE Trans. Serv. Comput.1
2019 ICAuth: Implicit and Continuous Authentication When the Screen Is Awake
abstract
Implicit authentication has become increasingly popular over recent years due to the fact that it relieves users from explicit actions such as remembering and entering passwords. This paper puts forward ICAuth, a general and simple implicit authentication method for mobile devices, to authenticate the current user implicitly and continuously when the screen is awake. Distinct from existing implicit user authentication methods which only focus on behavioral characteristics and ignore contextual information, ICAuth is devised to understand different behaviors in various contexts. We investigate the correlations between the behavioral characteristics and contextual information via sensors on mobile devices and observe that user's behavioral characteristics are strongly related to the context. These sensors are divided into two kinds, including fine-grained sensors and coarse-grained sensors, where fine-grained sensor data represent behavioral features and the coarse-grained depict contextual information. ICAuth provides continuous authentication without the involvement of users. It promotes security via authenticating the current user continuously and improves the usability via eliminating the limitation of specific behaviors. We evaluate ICAuth comprehensively with a large dataset including 340842 samples collected from 142 subjects. Our approach achieves an accuracy of 96.85%, FNR of 2.95%, and FPR of 4.01%. Security analysis is also conducted to demonstrate that ICAuth is resilient against common smartphone authentication threats. Finally, we show the low power consumption and authentication latency with 2.2 seconds of ICAuth.
Cong Wu 0003, Kun He 0008, Jing Chen 0003, Ruiying Du
ICC3
2019 Privacy-aware service placement for mobile edge computing via federated learning
Yongfeng Qian, Long Hu, Jing Chen 0003, Xin Guan 0003, Mohammad Mehedi Hassan, Abdulhameed Alelaiwi
Inf. Sci.3
2019 Photo Crowdsourcing Based Privacy-Protected Healthcare
abstract
In this paper, the concept of crowdsourcing is applied to the medical field and a health monitoring mechanism based on photo crowdsourcing is proposed. Specifically, with photo crowdsourcing by many participators, the routine circumstances of users may be represented. However, these photos may include other people than the user, such as the visibility requestor, the invisibility requestor, and the passerby. The visibility and invisibility requestor are the participators in the system, whose identity can be set as visible or invisible, while the passerbys do not participate in the system. Hence, a privacy protection mechanism is proposed for this system, which includes two categories: i) The image fuzzy processing is provided for the invisibility requestor, while the original image is reserved for the visibility requestor. ii) The passerby's image is directly fuzzy processed for privacy protection.
Long Hu, Yongfeng Qian, Jing Chen 0003, Xiaobo Shi, Jing Zhang 0025, Shiwen Mao
IEEE Trans. Sustain. Comput.3
2018 CertChain: Public and Efficient Certificate Audit Based on Blockchain for TLS Connections
abstract
In recent years, real-world attacks against PKI take place frequently. For example, malicious domains' certificates issued by compromised CAs are widespread, and revoked certificates are still trusted by clients. In spite of a lot of research to improve the security of SSL/TLS connections, there are still some problems unsolved. On one hand, although log-based schemes provided certificate audit service to quickly detect CAs' misbehavior, the security and data consistency of log servers are ignored. On the other hand, revoked certificates checking is neglected due to the incomplete, insecure and inefficient certificate revocation mechanisms. Further, existing revoked certificates checking schemes are centralized which would bring safety bottlenecks. In this paper, we propose a blockchain-based public and efficient audit scheme for TLS connections, which is called Certchain. Specially, we propose a dependability-rank based consensus protocol in our blockchain system and a new data structure to support certificate forward traceability. Furthermore, we present a method that utilizes dual counting bloom filter (DCBF) with eliminating false positives to achieve economic space and efficient query for certificate revocation checking. The security analysis and experimental results demonstrate that CertChain is suitable in practice with moderate overhead.
Jing Chen 0003, Shixiong Yao, Quan Yuan 0003, Kun He 0008, Shouling Ji, Ruiying Du
INFOCOM1
2018 Secure Enforcement in Cognitive Internet of Vehicles
abstract
As for deployment of security strategy, corresponding forwarding rules for switches can be given in allusion to different traffic conditions. However, due to lack of global cognitive control for security strategy deployment in traditional Internet of Vehicles (IoV), it is quite difficult to realize global and optimized security strategy deployment scheme so as to meet security requirements in different traffic conditions. On basis of traditional IoV, cognitive engine is added in cognitive IoV (CIoV) to enhance the intelligence of traditional IoV. In allusion to CIoV, and in consideration of restrictions on transmission delay, the security strategy deployment for switches on core network is formulated in this paper, thus not only the safe transmission rules are met, but the transmission delay can also be the lowest. To be specific, the path selection of switches is modeled as 0-1 programming problem in this paper, and that optimization problem is proved to be a nonconvex optimization problem. Then we convert that problem into a convex optimization problem by log-det heuristic algorithm, thus to give path selection scheme to meet security requirements with the lowest delay on the whole. Experiment proves that cognitive engine-based security strategy deployment put forth in this paper is much better than other schemes.
Yongfeng Qian, Min Chen 0003, Jing Chen 0003, M. Shamim Hossain, Atif Alamri
IEEE Internet Things J.3
2018 Uncovering the Face of Android Ransomware: Characterization and Real-Time Detection
abstract
In recent years, we witnessed a drastic increase of ransomware, especially on popular mobile platforms including Android. Ransomware extorts victims for a sum of money by taking control of their devices or files. In light of their rapid growth, there is a pressing need to develop effective countermeasure solutions. However, the research community is still constrained by the lack of a comprehensive data set, and there exists no insightful understanding of mobile ransomware in the wild. In this paper, we focus on the Android platform and aim to characterize existing Android ransomware. Specifically, we have managed to collect 2,721 ransomware samples that cover the majority of existing Android ransomware families. Based on these samples, we systematically characterize them from several aspects, including timeline and malicious features. In addition, the detection results of existing anti-virus tools are rather disappointing, which clearly calls for customized anti-mobile-ransomware solutions. To detect ransomware that extorts users by encrypting data, we propose a novel real-time detection system, called RansomProber. By analyzing the user interface widgets of related activities and the coordinates of users' finger movements, RansomProber can infer whether the file encryption operations are initiated by users. The experimental results show that RansomProber can effectively detect encrypting ransomware with high accuracy and acceptable runtime performance.
Jing Chen 0003, Chiheng Wang, Ziming Zhao 0001, Kai Chen 0012, Ruiying Du, Gail-Joon Ahn
IEEE Trans. Inf. Forensics Secur.1
2018 Blind Filtering at Third Parties: An Efficient Privacy-Preserving Framework for Location-Based Services
abstract
Location-based service (LBS) has gained increasing popularity recently, but protecting users' privacy in LBS remains challenging. Depending on whether a trusted third party (TTP) is used, existing solutions can be classified into: TTP-based and TTP-free. The former relies on a TTP for user privacy protection, which creates a single-point-failure and is thus impractical in reality. The latter does not require any TTP, but usually introduces redundant point-of-interest (POI) records in query result and thus incurs significant computation and communication costs on the user side, making them unsuitable for resource-constrained mobile devices. In this paper, we propose a novel framework to protect user privacy while ensuring efficiency. Our framework also uses redundant POI records to protect privacy against LBS provider but employs a semi-trusted third party, called proxy, to filter out redundant POI records. To protect privacy against proxy, we design a novel filtering protocol, Blind filter, to allow the proxy to filter out redundant encrypted POI records in a blind way. In comparison with existing solutions, our framework is not only resilient to dual identity attack, but also incurs lower communication and computation overhead. Comprehensive analysis and experiments show that our framework is secure and highly efficient in mobile environments.
Jing Chen 0003, Kun He 0008, Quan Yuan 0003, Min Chen 0003, Ruiying Du, Yang Xiang 0001
IEEE Trans. Mob. Comput.1
2017 Charge-Depleting of the Batteries Makes Smartphones Recognizable
abstract
Many components of smartphones are used to generate device fingerprinting, such as screens, CPUs and various sensors. These device fingerprinting can be used to identify the smartphones. However, there are many restrictions with these device fingerprinting. Invariable information in screens and CPUs may lead to privacy risks. Moreover, strict experimental steps are required when fingerprinting the sensors. The effectiveness and effeciency of these device fingerprinting is reduced in practice. In this paper, we present a novel hardware fingerprinting based on the battery. Instead of relying on invariable information of the battery, we focus on the charge-depleting of the smartphone. The discrepencies on manufacturing of smartphones make that the charge-depleting is different when performs the same task. Moreover, charge-depleting information can easily be obtained without strict operating steps. We design a highly accurate algorithm to fingerprint the batteries which is based on the unsupervised learning. Besides, we stimulate the algorithm with different charge-depleting of tasks to improve the performance. We use 15 smartphones to evaluate the performance of the battery fingerprinting in both laboratory and public conditions. The experimental results show that battery fingerprinting is quite effective, the recognition accuracy rate can reach 86%.
Jing Chen 0003, Yingying Fang, Kun He 0008, Ruiying Du
ICPADS1
2017 Checks and balances: A tripartite public key infrastructure for secure web-based connections
abstract
Recent real-world attacks against Certification Authorities (CAs) and fraudulently issued certificates arouse the public to rethink the security of public key infrastructure for web-based connections. To distribute the trust of CAs, notaries, as an independent party, are introduced to record certificates, and a client can request an audit proof of certificates from notaries directly. However, there are two challenges. On one hand, existing works consider the security of notaries insufficiently. Due to lack of systematic mutual verification, notaries might bring safety bottlenecks. On the other hand, the service of these works is not sustainable, when any party leaks its private key or fails. In this paper, we propose a Tripartite Public Key Infrastructure (TriPKI), using Certificates Authorities, Integrity Log Servers, and Domain Name Servers, to provide a basis for establishing secure SSL/TLS connections. Specifically, we apply checks-and balances among those three parties in the structure to make them verify mutually, which avoids any single party compromise. Furthermore, we design a collaborative certificate management scheme to provide sustainable services. The security analysis and experiment results demonstrate that our scheme is suitable for practical usage with moderate overhead.
Jing Chen 0003, Shixiong Yao, Quan Yuan 0003, Ruiying Du, Guoliang Xue
INFOCOM1
2017 A general framework to design secure cloud storage protocol using homomorphic encryption scheme
Jian Zhang 0010, Yang Yang 0022, Yanjiao Chen, Jing Chen 0003, Qian Zhang 0001
Comput. Networks4
2017 Secure independent-update concise-expression access control for video on demand in cloud
Kun He 0008, Jing Chen 0003, Yu Zhang 0036, Ruiying Du, Yang Xiang 0001, Mohammad Mehedi Hassan, Abdulhameed Alelaiwi
Inf. Sci.2
2017 Towards human-like and transhuman perception in AI 2.0: a review
abstract
Perception is the interaction interface between an intelligent system and the real world. Without sophisticated and flexible perceptual capabilities, it is impossible to create advanced artificial intelligence (AI) systems. For the next-generation AI, called ‘AI 2.0’, one of the most significant features will be that AI is empowered with intelligent perceptual capabilities, which can simulate human brain’s mechanisms and are likely to surpass human brain in terms of performance. In this paper, we briefly review the state-of-the-art advances across different areas of perception, including visual perception, auditory perception, speech perception, and perceptual information processing and learning engines. On this basis, we envision several R&D trends in intelligent perception for the forthcoming era of AI 2.0, including: (1) human-like and transhuman active vision; (2) auditory perception and computation in an actual auditory setting; (3) speech perception and computation in a natural interaction setting; (4) autonomous learning of perceptual information; (5) large-scale perceptual information processing and learning platforms; and (6) urban omnidirectional intelligent perception and reasoning engines. We believe these research directions should be highlighted in the future plans for AI 2.0.
Yonghong Tian 0001, Xilin Chen 0001, Hongkai Xiong, Li-Rong Dai 0001, Jing Chen 0002, Junliang Xing, Jing Chen 0003, Xihong Wu, Weiming Hu 0004, Yu Hu 0003, Tiejun Huang 0001, Wen Gao 0001
Frontiers Inf. Technol. Electron. Eng.8
2017 Batch Identification Game Model for Invalid Signatures in Wireless Mobile Networks
abstract
Secure access is one of the fundamental problems in wireless mobile networks. Digital signature is a widely used technique to protect messages' authenticity and nodes' identities. From the practical perspective, to ensure the quality of services in wireless mobile networks, ideally the process of signature verification should introduce minimum delay. Batch cryptography technique is a powerful tool to reduce verification time. However, most of the existing works focus on designing batch verification algorithms for wireless mobile networks without sufficiently considering the impact of invalid signatures, which can lead to verification failures and performance degradation. In this paper, we propose a Batch Identification Game Model (BIGM) in wireless mobile networks, enabling nodes to find invalid signatures with reasonable delay no matter whether the game scenario is complete information or incomplete information. Specifically, we analyze and prove the existence of Nash Equilibriums (NEs) in both scenarios, to select the dominant algorithm for identifying invalid signatures. To optimize the identification algorithm selection, we propose a self-adaptive auto-match protocol which estimates the strategies and states of attackers based on historical information. Comprehensive simulation results in terms of NE reasonability, algorithm selection accuracy, and identification delay are provided to demonstrate that BIGM can identify invalid signatures more efficiently than existing algorithms.
Jing Chen 0003, Kun He 0008, Quan Yuan 0003, Guoliang Xue, Ruiying Du, Lina Wang 0001
IEEE Trans. Mob. Comput.1
2016 Distributed Greedy Coding-aware Deterministic Routing for multi-flow in wireless networks
Jing Chen 0003, Kun He 0008, Quan Yuan 0003, Ruiying Du, Lina Wang 0001, Jie Wu 0001
Comput. Networks1
2016 A γ-Strawman privacy-preserving scheme in weighted social networks
abstract
Abstract With the dramatic development of social network applications, such as the Facebook, Twitter, and MySpace, privacy‐preserving problem is getting increasingly concerned. Apart from node information, researchers have found that structure information can also leak data providers' privacy, especially in weighted social networks. However, most of the existing private‐preserving schemes focus on a single aspect. The comprehensive consideration introduces two challenges. On one hand, the different anonymity demands of node and structure information lead to the collision of different design criteria, which is called as consistency matching problem. On the other hand, the simple combination of existing schemes may introduce large amounts of unnecessary changes, which makes the published information meaningless. Thus, we must find the balance between anonymity demands and changes, which is called as optimization trade‐off problem. In this paper, we propose aγ‐Strawman privacy‐preserving scheme in weighted social networks to solve these challenges. To address consistency matching problem, we propose a greedy algorithm based on a user trade‐off metric. For optimization tradeoff problem, a closeness edge‐editing technology is considered, which can change the private information slightly. Finally, we evaluate our scheme on real‐world datasets, the experimental results show that theγ‐Strawman scheme is efficient. Copyright © 2017 John Wiley & Sons, Ltd.
Jing Chen 0003, Min Chen 0003, Quan Yuan 0003, Ruiying Du
Secur. Commun. Networks1
2016 Message-locked proof of ownership and retrievability with remote repairing in cloud
abstract
Cloud storage services are widely deployed and employed in recent years. A number of data checking techniques have been proposed for secure cloud storage services. These state-of-the-art schemes only focus on some aspects, such as data integrity, users' ownership, and data resiliency, but the overall safety of cloud storage services is not discussed sufficiently. Considering cloud storage requirements as a whole, in this paper, we propose a model of message-locked proof of ownership and retrievability with remote repairing, which provides data confidentiality, secure cross-user deduplication at the client-side, file retrievability, ownership privacy-preserving, random block accessing, and remote repairing simultaneously. In addition, we also propose a concrete construction and prove its security in the random oracle model. The experimental results show that our construction is efficient in practice. Copyright © 2016 John Wiley & Sons, Ltd.
Jing Chen 0003, Kun He 0008, Min Chen 0003, Ruiying Du, Lina Wang 0001
Secur. Commun. Networks1
2016 ESDR: an efficient and secure data repairing paradigm in cloud storage
abstract
With the dramatic development of cloud computing, more and more challenges emerge for storing massive amounts of data. Data repairing is a main technique to provide data availability in the distributed storage system, such as cloud platform, once storage corruption occurs. In cloud storage, the redundant data are commonly stored in different places for better capability of disaster recovery and are transferred through the open channel, such as Internet. Because the data are of great importance for organizations, it is essential to systematically preserve the confidentiality, integrity, and authenticity of the data, which counters threats such as wiretapping, tampering, and pollution attacks. To address these challenges, we put forward a new data repairing paradigm, referred to as efficient and secure data repairing ESDR paradigm. In ESDR, the components of the redundant data are distributed to other storage units after being preprocessed and can be collected and reassembled onto the corrupted unit. Following this paradigm, we propose an ESDR scheme by using regenerating code and certificateless signcryption technique. Furthermore, the proposed enc2-mac - signcrypt preprocessing promotes security and efficiency notably. Both theoretical analysis and experimental evaluation confirm that this scheme is practical and efficient to secure data repairing in cloud storage. Copyright © 2016 John Wiley & Sons, Ltd.
Shungan Zhou, Ruiying Du, Jing Chen 0003, Debiao He
Secur. Commun. Networks3
2016 DeyPoS: Deduplicatable Dynamic Proof of Storage for Multi-User Environments
abstract
Dynamic Proof of Storage (PoS) is a useful cryptographic primitive that enables a user to check the integrity of outsourced files and to efficiently update the files in a cloud server. Although researchers have proposed many dynamic PoS schemes in singleuser environments, the problem in multi-user environments has not been investigated sufficiently. A practical multi-user cloud storage system needs the secure client-side cross-user deduplication technique, which allows a user to skip the uploading process and obtain the ownership of the files immediately, when other owners of the same files have uploaded them to the cloud server. To the best of our knowledge, none of the existing dynamic PoSs can support this technique. In this paper, we introduce the concept of deduplicatable dynamic proof of storage and propose an efficient construction called DeyPoS, to achieve dynamic PoS and secure cross-user deduplication, simultaneously. Considering the challenges of structure diversity and private tag generation, we exploit a novel tool called Homomorphic Authenticated Tree (HAT). We prove the security of our construction, and the theoretical analysis and experimental results show that our construction is efficient in practice.
Kun He 0008, Jing Chen 0003, Ruiying Du, Qianhong Wu, Guoliang Xue, Xiang Zhang 0005
IEEE Trans. Computers2
2015 Multi-Copy Routing with Trajectory Prediction in Social Delay-Tolerant Networks
abstract
Routing in Delay-Tolerant Networks (DTNs) remains a challenging problem due to sporadic connectivity and high delays. To deal with this issue, researchers have investigated multi-copy schemes with predicting future contacts. However, most of the previous work has focused on the prediction of future contacts, without sufficiently considering contact times. This paper proposes McRTP, a multi- copy routing protocol with trajectory prediction for social DTNs. Based on estimating the probability distribution of future contact times, McRTP evaluates and selects multiple paths with the highest delivery probability for routing. Also, to control network traffic overhead, we develop a copy count assignment scheme limiting the number of message copies in networks. A simulation study shows that, with the estimation of both contact probability and contact times, and the path selection scheme, our McRTP outperforms traditional DTN multi-copy routing schemes, especially in sparse networks.
Quan Yuan 0003, Ionut Cardei, Jing Chen 0003, Jie Wu 0001
GLOBECOM3
2015 Game-theory-based batch identification of invalid signatures in wireless mobile networks
abstract
Digital signature has been widely employed in wireless mobile networks to ensure the authenticity of messages and identity of nodes. A paramount concern in signature verification is reducing the verification delay to ensure the network QoS. To address this issue, researchers have proposed the batch cryptography technology. However, most of the existing works focus on designing batch verification algorithms without sufficiently considering the impact of invalid signatures. The performance of batch verification could dramatically drop, if there are verification failures caused by invalid signatures. In this paper, we propose a Game-theory-based Batch Identification Model (GBIM) for wireless mobile networks, enabling nodes to find invalid signatures with the optimal delay under heterogeneous and dynamic attack scenarios. Specifically, we design an incomplete information game model between a verifier and its attackers, and prove the existence of Nash Equilibrium, to select the dominant algorithm for identifying invalid signatures. Moreover, we propose an auto-match protocol to optimize the identification algorithm selection, when the attack strategies can be estimated based on history information. Comprehensive simulation results demonstrate that GBIM can identify invalid signatures more efficiently than existing algorithms.
Jing Chen 0003, Quan Yuan 0003, Guoliang Xue, Ruiying Du
INFOCOM1
2015 MuCAR: A greedy multi-flow-based coding-aware routing in wireless networks
abstract
It has been proved that network coding can optimize routing in wireless networks. Thus, in deterministic routing, coding is considered as an important factor for route selection. While the existing deterministic routing solutions detect paths with coding opportunities based on the two-flow coding, little attention has been drawn to the multi-flow situation. Coding multiple flows directly, however, can improve the coding benefit when multiple flows intersect at coding nodes. In this paper, we analyze the challenges of the multi-flow coding, and propose a Greedy Multi-flow-based Coding-aware Routing (MuCAR) protocol in wireless networks. The main idea is to define the decoding policy and the coding condition in the multi-flow environment, and code the multiple intersecting flows in a greedy way. Meanwhile, we discuss the interference issue in the multi-flow coding and its solution. We show that MuCAR can induce competitive performance in terms of increased coding benefit and decreased delay, which is verified by extensive simulations.
Jing Chen 0003, Quan Yuan 0003, Ruiying Du, Jie Wu 0001
SECON1
2015 Dominating Set and Network Coding-Based Routing in Wireless Mesh Networks
abstract
Wireless mesh networks are widely applied in many fields such as industrial controlling, environmental monitoring, and military operations. Network coding is promising technology that can improve the performance of wireless mesh networks. In particular, network coding is suitable for wireless mesh networks as the fixed backbone of wireless mesh is usually unlimited energy. However, coding collision is a severe problem affecting network performance. To avoid this, routing should be effectively designed with an optimum combination of coding opportunity and coding validity. In this paper, we propose a Connected Dominating Set (CDS)-based and Flow-oriented Coding-aware Routing (CFCR) mechanism to actively increase potential coding opportunities. Our work provides two major contributions. First, it effectively deals with the coding collision problem of flows by introducing the information conformation process, which effectively decreases the failure rate of decoding. Secondly, our routing process considers the benefit of CDS and flow coding simultaneously. Through formalized analysis of the routing parameters, CFCR can choose optimized routing with reliable transmission and small cost. Our evaluation shows CFCR has a lower packet loss ratio and higher throughput than existing methods, such as Adaptive Control of Packet Overhead in XOR Network Coding (ACPO), or Distributed Coding-Aware Routing (DCAR).
Jing Chen 0003, Kun He 0008, Ruiying Du, Minghui Zheng, Yang Xiang 0001, Quan Yuan 0003
IEEE Trans. Parallel Distributed Syst.1
2014 Proofs of Ownership and Retrievability in Cloud Storage
abstract
With the development and maturity of cloud computing technology, the demand for cloud storage is growing. Deduplication is a basic requirement for cloud storage to save storage space of cloud servers. And as clients are untrusted from the perspective of the server, the notion of Proofs of Ownership (PoWs) has been proposed in client-side deduplication. On the other hand, the clients cannot completely trust the server either, thus clients have to know whether their files are stored integrally in the cloud. However, most existing works only focus on one-way validation. In this paper, we introduce a framework called Proofs of Ownership and Retrievability (PoOR) considering the requirement of mutual validation. In our PoOR scheme, clients can prove to the server their ownership of files and verify the retrievability of the files without uploading or downloading them. For ensuring the recoverability and security of files in server, we encode files by erasure code. In order to keep the communication cost in constant, we employ Merkle Tree and homomorphic verifiable tags which also induce acceptable storage overheads. At last, we implemente our scheme and compare it with other schemes. The result shows that the PoOR scheme is efficient in computation performance, especially when the size of the file is large.
Ruiying Du, Lan Deng, Jing Chen 0003, Kun He 0008, Minghui Zheng
TrustCom3
2014 A Survey of Security Network Coding toward Various Attacks
abstract
As one of the emerging technologies with most potential for developing, Network Coding (NC) has gained significant momentum. Due to encode-and-forward model, NC has natural privacy in communication, but it also induces that attackers become more imperceptible and impact on NC caused by them becomes more far-reaching. This requires that the security schemes should consider the characteristics of different attacks in NC. In this paper, we provide a survey of secure network coding toward various attacks. First of all, we summarize four types of representative attacks in NC system including entropy attack, Byzantine attack, pollution attack and eavesdropping attack, and compare the differences of these attacks between in traditional store-and-forward mode and network coding mode. Secondly, we give a comprehensive investigation of numerous defense approaches and mechanisms classified by these attacks. Finally, for stimulating stream of thoughts about secure network coding schemes, several open issues are proposed and discussed.
Shixiong Yao, Jing Chen 0003, Ruiying Du, Lan Deng, Chiheng Wang
TrustCom2
2014 FEACS: A Flexible and Efficient Access Control Scheme for Cloud Computing
abstract
In the past few years, cloud computing has emerged as one of the most influential paradigms in the IT industry. As promising as it is, this paradigm brings forth many new challenges for data security because users have to outsource sensitive data on untrusted cloud servers for sharing. In this paper, to guarantee the confidentiality and security of data sharing in cloud environment, we propose a Flexible and Efficient Access Control Scheme (FEACS) based on Attribute-Based Encryption, which is suitable for fine-grained access control. Compared with existing state-of-the-art schemes, FEACS is more practical by following functions. First of all, considering the factor that the user membership may change frequently in cloud environment, FEACS has the capability of coping with dynamic membership efficiently. Secondly, full logic expression is supported to make the access policy described accurately and efficiently. Besides, we prove in the standard model that FEACS is secure based on the Decisional Bilinear Diffie-Hellman assumption. To evaluate the practicality of FEACS, we provide a detailed theoretical performance analysis and a simulation comparison with existing schemes. Both the theoretical analysis and the experimental results prove that our scheme is efficient and effective for cloud environment.
Yu Zhang 0036, Jing Chen 0003, Ruiying Du, Lan Deng, Yang Xiang 0001
TrustCom2
2013 Fault-Tolerant Topology Control Based on Artificial Immune Theory in WMNs
Jing Chen 0003, Ruiying Du, Chiheng Wang, Minghui Zheng, Yang Xiang 0001
NSS1
2012 A key distribution scheme using network coding for mobile ad hoc network
abstract
ABSTRACT Network coding offers an excellent solution for maximizing throughput in various networks. Because of its simplicity and high efficiency, the idea of network coding can also be used for designing lightweight key distribution schemes for wireless ad hoc network. This paper presents a key distribution scheme that exploits the inherent security properties of network coding. The new scheme relies on simple XOR network coding operations to provide data confidentiality and uses message authentication codes to guarantee the integrity of the distributed keys. We also show that our scheme can resist a series of attacks in wireless ad hoc network and has better performance compared with previous schemes proposed in the literature. Copyright © 2011 John Wiley & Sons, Ltd.
Jianwei Liu 0001, Ruiying Du, Jing Chen 0003, Kun He 0008
Secur. Commun. Networks3
2010 A hybrid game model based on reputation for spectrum allocation in wireless networks
Jing Chen 0003, Shiguo Lian, Cai Fu, Ruiying Du
Comput. Commun.1