EDBT 2026 Demo / reviewers in the wild / expert
Shang Gao 0006
dblp:28/435-6
· DBLP profile ↗
40ranked-venue papers
8as first author
28since 2021 · last 2027
0000-0003-2692-057XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 21 · 4 first-author · 12 since 2021Security and privacy · 15 · 4 first-author · 13 since 2021Systems, architecture and hardware · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2027 | Structured evidence consolidation for reliable low-resource named entity recognition
Yubo Song, Boran Shao, Shang Gao 0006, Liquan Chen |
Expert Syst. Appl. | 4 |
| 2026 | R.S.D: A Regulatory Anonymity System with Decentralized Identity
Xuyuan Cai, Shang Gao 0006, Zhe Peng, Bin Xiao 0001 |
ICC | 3 |
| 2026 | Deceptive Electricity Theft: New Attacks and Countermeasures in Multiple-Pricing Smart Grids
Chengpeng Huang, Shang Gao 0006, Qingqing Gan, Guyue Li, Bin Xiao 0001 |
ICDCS | 2 |
| 2026 | Fine-Grained IoT Device Fingerprinting Using Active Probing
Yubo Song, Yuncong Ma, Guyue Li, Liquan Chen, Shang Gao 0006, Bin Xiao 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | Toward Efficient Multi-User Access Control Encrypted Search for Web Data ManagementabstractWeb data management has become crucial to data sharing among users and servers. One promising approach to guaranteeing the privacy of shared data is searchable encryption (SE), which allows users to outsource encrypted data to the web server, which can then respond confidentially to keyword queries. Several SE schemes support access control to meet data-sharing requirements. However, several works (e.g., Zhang TSC'23, Zhang TCC'21) only focus on single-user access control and ignore the need for multi-user scenarios. Besides, a malicious data owner may send useless ciphertexts to the web server, potentially making the system insecure and impractical (e.g., Wang TPDS'22, Xu TDSC'20). As a result, research regarding owner authentication and multiuser access control in SE schemes remains underexplored. In this work, we construct SEOMA, the first multi-keyword encrypted search primitive supporting owner authentication and multi-user access control for Web data management. Unlike existing solutions, our design achieves owner authentication and multi-user access control simultaneously in a malicious setting. We incorporate attribute encryption to realize the attribute authentication for a data owner. Then, we leverage the policy tree and linear secret-sharing techniques to achieve hierarchical access control for users. We also formalize and demonstrate its security in a random oracle model by reducing to the DBDH and CBDH problem. Eventually, we conduct comprehensive performance evaluations compared to existing state-of-the-art schemes. Specifically, the computation and communication overhead is only 0.05-0.4× and 0.07-0.47× compared to prior arts, respectively. Shiyuan Xu, Yu Guo 0003, Shang Gao 0006, Siu-Ming Yiu, Bin Xiao 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | Blockchain-Based Lightweight Key Management Scheme for Secure UAV Swarm Task AllocationabstractUnmanned Aerial Vehicle (UAV) swarms are a cornerstone technology in the rapidly growing low-altitude economy, with significant applications in logistics, smart cities, and emergency response. However, their deployment is constrained by challenges in secure communication, dynamic group coordination, and resource constraints. Although there are various cryptographic techniques, efficient and scalable group key management plays a critical role in secure task allocation in UAV swarms. Existing group key agreement schemes, both symmetric and asymmetric, often fail to adequately address these challenges due to their reliance on centralized control, high computational overhead, sender restrictions, and insufficient protection against physical attacks. To address these issues, we propose PCDCB (Pairing-free Certificateless Dynamic Contributory Broadcast encryption), a blockchain-assisted lightweight key management scheme designed for UAV swarm task allocation. PCDCB is particularly suitable for swarm operations as it supports efficient one-to-many broadcast of task commands, enables dynamic node join/leave, and eliminates key escrow by combining certificateless cryptography with Physical Unclonable Functions (PUFs) for hardware-bound key regeneration. Blockchain is used to maintain tamper-resistant update tables and ensure auditability, while a privacy-preserving mechanism with pseudonyms and a round mapping table provides task anonymity and unlinkability. Comprehensive security analysis confirms that PCDCB is secure and resistant to multiple attacks. Performance evaluation shows that, in large-scale swarm scenarios (n = 100), PCDCB reduces the cost of group key computation by 54.4% (up to 96.9%) and reduces the time to generate the decryption keys by at least 29.7%. In addition, PCDCB achieves the lowest communication cost among all compared schemes and demonstrates strong scalability with increasing group size. Yaqing Zhu, Liquan Chen, Suhui Liu, Bo Yang 0069, Shang Gao 0006 |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2025 | Compressed Sigma Protocols: New Model and Aggregation Techniques
Yuxi Xue, Tianyu Zheng, Shang Gao 0006, Bin Xiao 0001, Man Ho Au |
ACISP (1) | 3 |
| 2025 | Mining Attack with Zero Knowledge in the Blockchain
Jiaping Yu, Shang Gao 0006, Rui Song 0010, Zhiping Cai, Bin Xiao 0001 |
AsiaCCS | 2 |
| 2025 | Lattice-Based Zero-Knowledge Proofs for Blockchain Confidential Transactions
Shang Gao 0006, Tianyu Zheng, Yu Guo 0003, Zhe Peng, Bin Xiao 0001 |
PKC (5) | 1 |
| 2025 | From Σ-Protocol-Based Signatures to Ring Signatures: General Construction and ApplicationsabstractPublic Key Infrastructure (PKI) has gained widespread attention for ensuring the security and integrity of data communication. While existing PKI mainly supports digital signatures, it is lacking in crucial anonymity, leading to the leakage of a signer’s identity information. To alleviate the issue, ring signatures are a suitable choice to provide anonymity as they allow users to create their own rings without the need for an administrator. Unfortunately, the utilization of ring signatures in PKI may present compatibility challenges within the system. Thus, proposing a general mechanism to convert a standardized$\Sigma $-based signature to a ring signature is far-reaching. In this paper, we propose a general construction for converting$\Sigma $-based signatures into ring signatures. To achieve this, we first introduce a$\Sigma $-based general model, providing a general transformation to convert existing$\Sigma $-based signatures into a$\Sigma $-protocol form. Subsequently, we incorporate our redesigned one-out-of-many relation within our general model and proceed to devise ring signatures leveraging on one-out-of-many proofs. Furthermore, to reduce the signature size, we employ the Bulletproofs folding technique, enabling the attainment of logarithmic size ring signatures. To demonstrate the wide applicability of our general construction, we present four prominent signatures as case studies. Ultimately, we conduct a rigorous security analysis and benchmark experimental evaluation. The signing and verification times are 0.44 to 0.97 times and 0.27 to 0.91 times compared to other state-of-the-art schemes, respectively. Additionally, we exhibit the lowest signature size to date. Shang Gao 0006, Shiyuan Xu, Liquan Chen, Siu-Ming Yiu, Bin Xiao 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Efficient and Secure Post-Quantum Certificateless Signcryption With Linkability for IoMTabstractThe Internet of Medical Things (IoMT) has gained significant research focus in both academic and medical institutions. Nevertheless, the sensitive data involved in IoMT raises concerns regarding user validation and data privacy. To address these concerns, certificateless signcryption (CLSC) has emerged as a promising solution, offering authenticity, confidentiality, and unforgeability. Unfortunately, most existing CLSC schemes are impractical for IoMT due to their heavy computational and storage requirements. Additionally, these schemes are vulnerable to quantum computing attacks. Therefore, research focusing on designing an efficient post-quantum CLSC scheme is still far-reaching. In this work, we propose PQ-CLSCL, a novel post-quantum CLSC scheme with linkability for IoMT. Our proposed design facilitates secure transmission of medical data between physicians and patients, effectively validating user legitimacy and minimizing the risk of private information leakage. To achieve this, we leverage lattice sampling algorithms and hash functions to generate the partial secret key, then employ the sign-then-encrypt method and design a link label. We also formalize and prove the security of our design, including indistinguishability against chosen-ciphertext attacks (IND-CCA2), existential unforgeability against chosen-message attacks (EU-CMA), and linkability. Finally, through comprehensive performance evaluation, our computation overhead is just 5% of other existing schemes. The evaluation results demonstrate that our solution is practical and efficient. Shiyuan Xu, Yu Guo 0003, Siu-Ming Yiu, Shang Gao 0006, Bin Xiao 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Authenticated Decentralized Identifier Retrieval for Blockchain-based Web 3.0abstractWeb 3.0 is viewed as the next generation of the Internet, with the aim of establishing a decentralized network where users can control their digital identities and data. Due to its decentralization feature, blockchain has become a promising solution for secure data storage and retrieval for abundant de-centralized applications in Web 3.0. In this context, decentralized identifiers (DIDs) are rapidly emerging as a key infrastructure for blockchain-based Web 3.0. However, with more and more DIDs generated and stored on the blockchain, it is challenging to support efficient retrieval of DIDs with data integrity assurance. In this paper, we propose a novel authenticated DID retrieval system for blockchain-based Web 3.0. Specifically, a new authenticated data structure (ADS) with the corresponding data verification algorithm is designed to enable efficient retrieval and verification for both DID records and their historical updates. Theoretical analysis has been performed to prove the security and efficiency of our proposed system. We implement our system and conduct experiments to evaluate the performance. Experimental results demonstrate that our proposed scheme exhibits higher system efficiency compared to the baseline solution. Jiawei Sheng, Jiamin Deng, Shang Gao 0006, Huawei Huang, Zhe Peng |
GLOBECOM | 3 |
| 2024 | vDID: Blockchain-Enabled Verifiable Decentralized Identity Management for Web 3.0abstractWeb 3.0 has been proposed as a new generation of the Internet, which shifts towards system decentralization, improved data security, and self-sovereign identity. With the proliferation of networked entities, the proper management and verification of their identities play a vital role in Web 3.0. Decentralized identity is a promising paradigm to enhance data security and restore sovereignty over personal data to users. However, the data security in existing centralized solutions is often severely limited. In this paper, we propose vDID, a novel blockchain-enabled verifiable decentralized identity management system for Web 3.0. First, we design a generic verifiable DID structure, which is capable of capturing and expressing the inherent relationships between different entities with high granularity. Second, we develop an identity verification scheme to support efficient integrity verification for identities and their relationships in the decentralized framework. We implement vDID and conduct experiments to evaluate the system performance. Experimental results demonstrate the effectiveness of our proposed system. Zhe Peng, Jiamin Deng, Shang Gao 0006, Helei Cui, Bin Xiao 0001 |
IWQoS | 3 |
| 2024 | FS-LLRS: Lattice-Based Linkable Ring Signature With Forward Security for Cloud-Assisted Electronic Medical RecordsabstractRing signatures have been extensively researched for Cloud-assisted Electronic Medical Records (EMRs) sharing, aiming to address the challenge of “medical information silos” while safeguarding the privacy of patients’ personal information and the security of EMRs. However, most existing EMRs sharing systems that utilize ring signatures are vulnerable to quantum attacks, posing a severe challenge for the e-health scenario. To alleviate this issue, some studies have been conducted on lattice-based ring signatures. Nevertheless, there still exist two challenges. Firstly, current schemes fail to verify if multiple EMRs come from the same signer, undermining e-health reliability. Additionally, adversaries can exploit weaknesses in the network security of signers’ secret keys to forge signatures. In this paper, we propose an efficient lattice-based linkable ring signature (LLRS) for EMRs sharing to ensure patient privacy through anonymity, EMRs security through unforgeability, and checking the linkability for multiple signatures. We then present an enhancement scheme, called FS-LLRS, to additionally offer forward security, ensuring the security of previous ring signatures even if the current key has been compromised. To achieve this, we introduce a binary tree structure to divide time periods and leverage lattice basis algorithms for one-way secret key evolution, allowing users to update the secret keys periodically. Ultimately, we conduct a rigorous security analysis and compare our primitives with prior arts. In computational cost, the best performance of our LLRS and FS-LLRS schemes are just 0.17 and 0.34 times compared to others, respectively. Our LLRS scheme only incurs 0.08 times the communication overhead of others. Shiyuan Xu, Shang Gao 0006, Yu Guo 0003, Siu-Ming Yiu, Bin Xiao 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | SAMCU: Secure and Anonymous Multi-Channel Updates in Payment Channel NetworksabstractThe Payment Channel Network (PCN) has emerged as an extensively adopted solution to address the scalability issues of Bitcoin by efficient off-chain updates. However, conflicts arise while existing update protocols are pursuing multiple goals of security, privacy, and expressiveness. In this work, we propose a new off-chain update protocol, Secure and Anonymous Multi-Channel Updates (SAMCU), which is developed on the basis of Unspent Transaction Output (UTXO). SAMCU aims at achieving goals of internal anonymity, balance security, and multi-channel updates simultaneously, which has not been done before. To achieve these goals, we exploit the technique of updating graph splitting (UGS) to make participants aware of only the identities of their neighboring sub-graphs, thereby ensuring internal anonymity in multi-channel updates. Then, to avoid security issues arising from equal sub-graphs, we further propose an Enable Payment Transaction Tree (EPTT) to guarantee balance security for each honest protocol participant. Moreover, we optimize the performance of our solution, reducing transaction fees by splitting transactions and the number of communication connections by hierarchical communication. To evaluate the performance of the SAMCU, we implement a prototype involving up to 100 updating payment channels. Experimental results demonstrate that SAMCU outperforms the state-of-the-art, resulting in approximately 70% savings in communication connections and a 66% reduction in on-chain transaction fees when the number of updating payment channels is 100. Jianhuan Wang, Shang Gao 0006, Guyue Li, Keke Gai, Bin Xiao 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | On the Profitability of Selfish Mining Attack Under the Checkpoint MechanismabstractThough designed with security in mind, blockchains are vulnerable to various kinds of attacks, especially when the network computational power is low. Selfish mining is one of the most rudimentary and notorious attacks, which maliciously renders blocks found by honest miners orphaned by strategically withholding and revealing the found blocks. In this paper, we analyze the profitability of selfish mining under the checkpoint mechanism—a mechanism that has been adopted as a finality gadget by many blockchains like Ethereum and Bitcoin Cash. We develop a rigorous analysis method and conduct quantitative evaluations in various scenarios to explore the mechanism's suppression effect on selfish mining. The results illustrate that the checkpoint mechanism can restrict the profit of selfish mining and increase the threshold of computational power that makes selfish mining profitable, suggesting that it is a practical defense mechanism against selfish mining. Yu Zhou 0047, Shang Gao 0006, Weiwei Qiu, Kai Lei, Bin Xiao 0001 |
GLOBECOM | 2 |
| 2023 | Leaking Arbitrarily Many Secrets: Any-out-of-Many Proofs and Applications to RingCT ProtocolsabstractRing Confidential Transaction (RingCT) protocol is an effective cryptographic component for preserving the privacy of cryptocurrencies. However, existing RingCT protocols are instantiated from one-out-of-many proofs with only one secret, leading to low efficiency and weak anonymity when handling transactions with multiple inputs. Additionally, current partial knowledge proofs with multiple secrets are neither secure nor efficient to be applied in a RingCT protocol.In this paper, we propose a novel any-out-of-many proof, a logarithmic-sized zero-knowledge proof scheme for showing the knowledge of arbitrarily many secrets out of a public list. Unlike other partial knowledge proofs that have to reveal the number of secrets [ACF21], our approach proves the knowledge of multiple secrets without leaking the exact number of them. Furthermore, we improve the efficiency of our method with a generic inner-product transformation to adopt the Bulletproofs compression [BBB+18], which reduces the proof size to 2⌈log2(N)⌉+9.Based on our proposed proof scheme, we further construct a compact RingCT protocol for privacy cryptocurrencies, which can provide a logarithmic-sized communication complexity for transactions with multiple inputs. More importantly, as the only known RingCT protocol instantiated from the partial knowledge proofs, our protocol can achieve the highest anonymity level compared with other approaches like Omniring [LRR+19]. For other applications, such as multiple ring signatures, our protocol can also be applied with some modifications. We believe our techniques are also applicable in other privacy-preserving scenarios, such as multiple ring signatures and coin-mixing in the blockchain. Tianyu Zheng, Shang Gao 0006, Yubo Song, Bin Xiao 0001 |
SP | 2 |
| 2023 | SymmeProof: Compact Zero-Knowledge Argument for Blockchain Confidential TransactionsabstractTo reduce the transmission cost of blockchain confidential transactions, we propose SymmeProof, a novel communication efficient non-interactive zero-knowledge range proof protocol without a trusted setup. We design and integrate two new techniques in SymmeProof, namely vector compression and inner-product range proof. The proposed vector compression is able to reduce the communication cost to log(n) for n-size vectors. The proposed inner-product range proof converts a range proof relation into an inner-product form, which can further reduce the range proof size with the vector compression technique. Based on these two techniques, SymmeProof can eventually achieve a log(n)-size range proof. The proposed SymmeProof can be used in many important applications such as blockchain confidential transactions as well as arguments for arithmetic circuits satisfiability. We evaluate the performance of SymmeProof. The results show that SymmeProof substantially outperforms representative methods such as Bulletproofs in the proof size without a trusted setup. Shang Gao 0006, Zhe Peng, Yuanqing Zheng, Bin Xiao 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | LFS-AS: Lightweight Forward Secure Aggregate Signature for e-Health ScenariosabstractThe advancement of Internet of Medical Things (IoMT) leading to the proliferation of electronic healthcare scenarios, with an expanding trend of hospitals and healthcare organizations employing Electronic Medical Records (EMRs) with uploading to the cloud for sharing. However, security challenges exist during the generation and uploading of medical records, such as record tampering, key attacks, etc., which will become the maximum bottleneck restricting the development of e-Health scenarios in the near future. Some scholars consider digital signature techniques, such as Attribute-based Signature, to address the security challenges but ignoring its overwhelming efficiency. In this paper, we propose a lightweight forward secure aggregate signature for e-Health scenarios. We devise a lightweight secure aggregate signature to provide unforgeability and forward security for medical records, which is the first aggregate signature scheme that enables forward security in e-Health scenarios. Furthermore, our scheme offers superior lightweight properties, requiring only 5.78ms for aggregation and 4.85ms for verification of 1000 signatures, which is significantly lower than existing schemes, especially suitable for medical systems with enormous data volume. Security analysis and experimental evaluation indicate that our scheme assures correctness, unforgeability and forward security, while fulfilling lightweight demands that outperform existing schemes. Shiyuan Xu, Yunhua He, Shang Gao 0006 |
ICC | 6 |
| 2022 | : A Traceable and Privacy-Preserving Data Exchange Scheme based on Non-Fungible Token and Zero-KnowledgeabstractWith the advent of the Big Data era, industry, business and academia have developed various data exchange schemes to make data more economically beneficial. Unfortunately, most of the existing systems provide only one-time data exchanges without the ability to track the provenance and transformations of datasets. In addition, existing systems encrypt the data to protect data privacy, which hinders demanders from verifying the correctness of the data and evaluating its value.To provide data traceability and privacy while ensuring fairness during data exchanges, we design and implement ZKDET, a traceable data exchange scheme based on non-fungible token and zero-knowledge, which is able to (i) track all transformations of data during their lifecycle and record them on the blockchain; (ii) provide zero-knowledge proofs to securely guarantee that all complex transformations and data contents are correct and meet specific requirements; and (iii) warrant exchange fairness and data privacy in public storage platforms. Security analysis and evaluations on ZKDET show that it can support traceable data exchange while preserving data privacy and maintaining high throughput despite large data volumes. Rui Song 0010, Shang Gao 0006, Yubo Song, Bin Xiao 0001 |
ICDCS | 2 |
| 2022 | Reducing Gas Consumption of Tornado Cash and Other Smart Contracts in EthereumabstractEthereum, the largest blockchain for running smart contracts, has been widely used, especially in financial and cryptocurrency exchange applications. Among them, Tornado Cash is a typical financial application that protects the privacy of users with anonymous transactions. However, users need to pay prohibitively high gas (transaction fees for smart contract calls) for anonymous transactions, which hinders Tornado Cash from wide applications. To address this issue, we introduced a new approach that shifts the high gas-consuming operations on smart contracts to local users. Furthermore, we use zero-knowledge proofs to ensure the operations are properly executed. The smart contract only needs to verify and update the results, which significantly reduces the gas fees of Tornado Cash. To validate our approach, we implemented a prototype and showed that our proposed method could save more than 61% of gas consumption of current operations while maintaining the privacy feature of Tornado Cash. Finally, we discussed further applications and open problems of our approach. Jingyan Yang, Shang Gao 0006, Guyue Li, Rui Song 0010, Bin Xiao 0001 |
TrustCom | 2 |
| 2022 | VMT: Secure VANETs Message Transmission Scheme with Encryption and Blockchain
Shiyuan Xu, Yunhua He, Yibo Cao, Shang Gao 0006 |
WASA (1) | 5 |
| 2022 | AQ-ABS: Anti-Quantum Attribute-based Signature for EMRs Sharing with BlockchainabstractWith the advancement of medical science, the implementation of Electronic Medical Records (EMRs) for enhancing the efficiency and reliability of healthcare services has become a widespread phenomenon. However, EMRs are stored in hospitals and medical institutions independently, leading to sharing challenges. Moreover, the highly sensitive EMRs are prone to be tampered with and abused, posing privacy and security threats. To address the aforementioned issues, we propose an Anti- Quantum Attribute-based Signature(AQ — ABS) for Secure EMRs Sharing with Blockchain. Initially, We are the first ones to design an Attribute-based Signature (ABS) that can resist quantum attacks in E-health, called AQ — ABS. Further, the owner and provider of the EMR encrypt and sign it via the AQ — ABS scheme, then store EMR to a secure and distributed file storage system, i.e. Interplanetary File System (IPFS). Finally, the index hashes generated by IPFS and keywords are re-signed and stored in the consortium blockchain. Security analysis indicates that our proposed scheme fulfills the properties of signers’ anonymity, EMRs unforgeability, EMRs shareability, and fine-grained access control. Comprehensive experimental evaluation demonstrates that our proposed scheme performs low overhead as well as outperforms existing ABS and EMR systems. Shiyuan Xu, Shang Gao 0006, Weimin Kong |
WCNC | 5 |
| 2022 | Griffin: Real-Time Network Intrusion Detection System via Ensemble of Autoencoder in SDNabstractMany efforts have been devoted to the development of efficient Network Intrusion Detection System (NIDS) using machine learning approaches in Software-defined Network (SDN). Unfortunately, existing solutions failed to detect real-time and zero-day attacks due to their limited throughput and prior knowledge-based detection. To this end, we propose Griffin, a NIDS that uses unsupervised machine learning expertise to detect both known and zero-day intrusion attacks in real-time with high accuracy. Specifically, Griffin uses an efficient feature extraction framework to capture the sequential features of the traffic packets. Then, it utilizes cluster analysis to reduce the feature scale to achieve low throughput. Moreover, an ensemble autoencoder is built automatically to further extract features with low complexity and high precision to train the model. We evaluate the accuracy, robustness, and complexity of the system using open datasets. The result shows that Griffin’s complexity is about 40% lower, and its accuracy is at most 19% higher than existing NIDS.Additionally, even in the situation with evasion, the Griffin has at most 9% decrease of AUC, which is a good performance compared with other solutions. Furthermore, this paper also utilizes the differential privacy framework during training autoencoders to protect datasets’ privacy which is inherent in machine learning approaches. Liyan Yang, Yubo Song, Shang Gao 0006, Aiqun Hu, Bin Xiao 0001 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2021 | IoT-ID: Robust IoT Device Identification Based on Feature Drift AdaptationabstractInternet of Things (IoT) devices deployed in publicly accessible locations increasingly encounter security threats from device replacement and impersonation attacks. Unfortunately, the limited memory and poor computing capability on such devices make solutions involving complex algorithms or enhanced authentication protocols untenable. To address this issue, device identification technologies based on traffic characteristics finger-printing have been proposed to prevent illegal device intrusion and impersonation. However, because of time-dependent distribution of traffic characteristics, these approaches often become less accurate over time. Meanwhile insufficient attention has been paid to the impact of possible changes on the accuracy of device identification. Therefore, we propose a novel feature selection method based on degree of feature drift and genetic algorithm to keep high accuracy and stability of device identification. The degree of feature drift— relevance of features through time and gain ratio are combined as a composite metric to filter out stable features. Furthermore, in order to perform equally well in device identification, we use the genetic algorithm to select the most discriminate feature subset. Experiments show that the accuracy of device recognition compared with other methods is increased from 86.4% to 94.5%, and the robustness of recognition is also improved. Yubo Song, Brendan Jennings, Fan Zhang 0077, Bin Xiao 0001, Shang Gao 0006 |
GLOBECOM | 6 |
| 2021 | You Can Hear But You Cannot Record: Privacy Protection by Jamming Audio RecordingabstractUnauthorized voice recording via smartphones can leak the talking content stealthily. This would be a serious security threat to those individuals, enterprises and the government who need to keep the conversation confidential. Furthermore, due to the size miniaturization of smartphones, it is hard to find the covert recording from malicious attendees. Existing solutions usually jam the recording with audible noise or electromagnetic emitting. However, the audible noise will seriously interfere with conversation and the effect of electromagnetic emitting will be limited by the distance. In this paper, we propose UltraArray, a pioneering silent ultrasonic anti-recording jammer, which can covertly block recording for a long distance. The principle of covert blocking is inspired by acoustic parametric array theory, which suggests that the audible frequency wave can be spread through the air silently while it is modulated to an inaudible ultrasonic frequency. The modulation used in this paper is double sideband (DSB) modulation. The microphone on the phone will record the audible frequency and filtering out the ultrasonic frequency. The jammer we developed uses an acoustics array to form a beam to spread the signal further. The evaluation shows that the device has a good jamming effect on more than 5 meters for most Android smartphones. It will also work well with more than 2.5 meters effective distance on iPhone XR, which has the active noise control (ANC) function. Those results achieve ten times the interference ability of existing solutions. Xiaosong Ma, Yubo Song, Shang Gao 0006, Bin Xiao 0001, Aiqun Hu |
ICC | 4 |
| 2021 | My Site Knows Where You Are: A Novel Browser Fingerprint to Track User PositionabstractUtilizing browsers to identify and track users has become a routine on the Web in recent years. It is easy for the browser to collect sensitive information and construct comprehensive user profiles while the users are still unaware. As the problem mentioned above, several anti-fingerprint mechanisms have been adopted to protect user privacy. However, our research finds a novel method based on localization fingerprints that may still threaten user privacy. The location fingerprint obtains the response delay of data transmission over the link between the users and the third-party sites. Since the physical link state information between the host and the remote website is distinct and steady, it can be used to extract statistical features and construct user profiles. We implement a multilateration cross-site image resource request scheme to collect link-state information of users and develop a prototype called PingLoc to evaluate the effectiveness. About 1,093 users from all over the world are involved in our experiment. The evaluation shows that the delay features collected are stable, and the accuracy of the localization fingerprint is up to 98%. Pressure testing shows that the PingLoc is robust against various anti-fingerprint mechanisms and achieves 93.5% accuracy for browser switching, 80.6% accuracy for virtual machine disguising, and 88.2% accuracy for IP rotation. Yubo Song, Fan Zhang 0077, Shang Gao 0006, Bin Chen 0007 |
ICC | 4 |
| 2021 | Permission Sensitivity-Based Malicious Application Detection for AndroidabstractSince a growing number of malicious applications attempt to steal users’ private data by illegally invoking permissions, application stores have carried out many malware detection methods based on application permissions. However, most of them ignore specific permission combinations and application categories that affect the detection accuracy. The features they extracted are neither representative enough to distinguish benign and malicious applications. For these problems, an Android malware detection method based on permission sensitivity is proposed. First, for each kind of application categories, the permission features and permission combination features are extracted. The sensitive permission feature set corresponding to each category label is then obtained by the feature selection method based on permission sensitivity. In the following step, the permission call situation of the application to be detected is compared with the sensitive permission feature set, and the weight allocation method is used to quantify this information into numerical features. In the proposed method of malicious application detection, three machine-learning algorithms are selected to construct the classifier model and optimize the parameters. Compared with traditional methods, the proposed method consumed 60.94% less time while still achieving high accuracy of up to 92.17%. Yubo Song, Yijin Geng, Shang Gao 0006 |
Secur. Commun. Networks | 4 |
| 2020 | Griffin: An Ensemble of AutoEncoders for Anomaly Traffic Detection in SDNabstractThe Network Intrusion Detection Systems (NIDS) with machine learning in SDN become increasingly popular solutions. NIDS uses abnormal traffic detection to identify unknown network attacks. Most of today's abnormal traffic detection systems are supposed to continuously update the recognition model in time based on the features from newly collected packets to accurately identify unknown network attack behaviors. However, those existing solutions always require a large number of packets to train the recognition model offline. That means it is impossible to accurately detect the emergence of new cyber-attacks immediately. This paper proposes Griffin, a per-packet anomaly detection system that can dynamically update the training model based on neural networks. The Griffin is executed in SDN environment, utilizing a novel ensemble of autoencoders to collectively filter out abnormal traffic from normal traffic. Meanwhile, the autoencoders are updated based on the root mean square error to adjust the training model. The adjustment is done in an unsupervised manner, which needs no expert to label the network traffic or update the model from time to time. Our evaluations, with the open Datasets provided by Yisroel Mirsky, show that Griffin's time delay is around 0. 1s and its accuracy is 98%. Moreover, we also compare Griffin with other four similar NIDSs and find that Griffin performs the best in terms of Matthews Correlation Coefficient and complexity. Liyan Yang, Yubo Song, Shang Gao 0006, Bin Xiao 0001, Aiqun Hu |
GLOBECOM | 3 |
| 2020 | Detection and Mitigation of DoS Attacks in Software Defined NetworksabstractThe introduction of software-defined networking (SDN) has emerged as a new network paradigm for network innovations. By decoupling the control plane from the data plane in traditional networks, SDN provides high programmability to control and manage networks. However, the communication between the two planes can be a bottleneck of the whole network. SDN-aimed DoS attacks can cause long packet delay and high packet loss rate by using massive table-miss packets to jam links between the two planes. To detect and mitigate SDN-aimed DoS attacks, this paper presents FloodDefender, an efficient and protocol-independent defense framework for SDN/OpenFlow networks. FloodDefender stands between the controller platform and other controller apps, and conforms to the OpenFlow policy without additional devices. The detection module in FloodDefender utilizes new frequency features to precisely identify SDN-aimed DoS attacks. The mitigation module uses three new techniques to efficiently mitigate attack traffic: table-miss engineering to prevent the communication bandwidth from being exhausted; packet filter to filter out attack traffic and save computational resources of the control plane; and flow rule management to eliminate most of useless flow entries in the switch flow table. Our evaluation on a prototype implementation of FloodDefender shows that the defense framework can precisely identify and efficiently mitigate the SDN-aimed DoS attacks with very little overhead. Shang Gao 0006, Zhe Peng, Bin Xiao 0001, Aiqun Hu, Yubo Song, Kui Ren 0001 |
IEEE/ACM Trans. Netw. | 1 |
| 2019 | Power Adjusting and Bribery Racing: Novel Mining Attacks in the Bitcoin SystemabstractMining attacks allow attackers to gain an unfair share of the mining reward by deviating from the honest mining strategy in the Bitcoin system. Among the most well-known are block withholding (BWH), fork after withholding (FAW), and selfish mining. In this paper, we propose two new strategies: power adjusting and bribery racing, and introduce two novel mining attacks, Power Adjusting Withholding (PAW) and Bribery Selfish Mining (BSM) adopting the new strategies. Both attacks can increase the reward of attackers. Furthermore, we show PAW can avoid the "miner's dilemma" in BWH attacks. BSM introduces a new "venal miner's dilemma", which results in all targets (bribes) willing to help the attacker but getting less reward finally. Quantitative analyses and simulations are conducted to verify the effectiveness of our attacks. We propose some countermeasures to mitigate the new attacks, but a practical and efficient solution remains to be an open problem. Shang Gao 0006, Zecheng Li 0001, Zhe Peng, Bin Xiao 0001 |
CCS | 1 |
| 2018 | Software-Defined Firewall: Enabling Malware Traffic Detection and Programmable Security ControlabstractNetwork-based malware has posed serious threats to the security of host machines. When malware adopts a private TCP/IP stack for communications, personal and network firewalls may fail to identify the malicious traffic. Current firewall policies do not have a convenient update mechanism, which makes the malicious traffic detection difficult. Shang Gao 0006, Zecheng Li 0001, Yuan Yao 0004, Bin Xiao 0001, Songtao Guo, Yuanyuan Yang 0001 |
AsiaCCS | 1 |
| 2018 | I Know What You Type: Leaking User Privacy via Novel Frequency-Based Side-Channel AttacksabstractSmartphone sensors have been applied to record the movement of users for healthy use. However, the motion sensor readings recorded by malicious applications can be utilized as a side-channel to leak user privacy by keystroke inference. Most existing approaches use time-domain statistical characteristics for keystroke inference. Their systems are poor to show the subtle changes in short time period, since the time- domain statistical features can only reflect the characteristics in a long-time interval. In this paper, we propose a novel framework to perform keystroke inference on smartphones. This framework introduces an improved MFCC algorithm to extract frequency- domain features for more comprehensive use of raw data. Since the frequency-domain energy distribution of motion signals is concentrated, and the specificity of signals is strong, MFCC can improve the inference accuracies under complex scenarios. Based on this framework, we present a prototype called FreqKey, which is an inference system to leak user privacy such as PINs and passwords. FreqKey collects motion sensor readings during keystroke events and constructs classification models with machine learning algorithms. Experimental results show that FreqKey improves the performance in a variety of complex scenarios. Especially, even in web platform whose sampling rate is lower than 80Hz, FreqKey can achieve relatively high accuracy of 74.6%. To mitigate the frequency-based side-channel attack and protect user privacy, we propose a defense solution which contains sensor- activity monitoring, malicious program identification and interference signal injection. Rui Song 0010, Yubo Song, Shang Gao 0006, Bin Xiao 0001, Aiqun Hu |
GLOBECOM | 3 |
| 2018 | Indoor Floor Plan Construction Through Sensing Data Collected From SmartphonesabstractWith the development of sensing technology, smartphones can provide various kinds of data, including inertial sensing data, WiFi data, depth data, and images. These data make it possible to construct accurate indoor floor plans that are the critical foundations of flourishing indoor location-based services for smartphone. However, even with the popular crowdsourcing approach, the wide construction of indoor floor plans has not yet to be realized due to the intensive time consumption. In this paper, we utilize deep learning techniques to build PlanSketcher, a system that enables one user to construct fine-grained and facility-labeled indoor floor plans accurately. First, the proposed system extracts novel integrated features to recognize diverse landmarks. Second, traverse-independent hallway topologies are constructed based on the sensing data, depth data, and images through the proposed hallway construction algorithms. Finally, PlanSketcher constructs the room shape and labels recognized facilities in their corresponding positions to generate a complete indoor floor plan. Because PlanSketcher exploits different kinds of data collected from smartphones with new feature extraction method, it can obtain accurate indoor floor plan topology and facility labels. We implement PlanSketcher and conduct extensive experiments in three large indoor settings. The evaluation results show that the 90th percentile accuracy of positions and orientations of facilities are 1 m–2.5 m and 4°–6°, while 85%–95% facilities are recognized and labeled precisely. Zhe Peng, Shang Gao 0006, Bin Xiao 0001, Guiyi Wei, Songtao Guo, Yuanyuan Yang 0001 |
IEEE Internet Things J. | 2 |
| 2018 | CrowdGIS: Updating Digital Maps via Mobile CrowdsensingabstractAccurate digital maps play a crucial role in various location-based services and applications. However, store information is usually missing or outdated in current maps. In this paper, we propose CrowdGIS, an automatic store selfupdating system for digital maps that leverages street views and sensing data crowdsourced from mobile users. We first develop a new weighted artificial neural network to learn the underlying relationship between estimated positions and real positions to localize user's shooting positions. Then, a novel text detection method is designed by considering two valuable features, including the color and texture information of letters. In this way, we can recognize complete store name instead of individual letters as in the previous study. Furthermore, we transfer the shooting position to the location of recognized stores in the map. Finally, CrowdGIS considers three updating categories (replacing, adding, and deleting) to update changed stores in the map based on the kernel density estimate model. We implement CrowdGIS and conduct extensive experiments in a real outdoor region for 1 month. The evaluation results demonstrate that CrowdGIS effectively accommodates store variations and updates stores to maintain an up-to-date map with high accuracy. Zhe Peng, Shang Gao 0006, Bin Xiao 0001, Songtao Guo, Yuanyuan Yang 0001 |
IEEE Trans Autom. Sci. Eng. | 2 |
| 2017 | Novel attacks in OSPF networks to poison routing tableabstractLink State Advertisement (LSA) reflects the current status of all incident links of a router in an Autonomous System (AS). A fake LSA with false link status information will pollute the view of the network topology on routers. In this paper, we present two novel attacks that inject malicious Link State Advertisements (LSAs) to modify the routing tables: adjacency spoofing and single path injection. Adjacency spoofing attack makes attacker access to routing networks by disguising as a legitimate router. Single path injection attack evades the “fight-back” mechanism and affects routing advertisements of routers. Unlike existing LSA injection attacks, which need to be launched by malicious routers, a common host can launch these attacks and control the transmission path of data traffic in an AS. Simulation and real-world experiment results show that these two attacks can efficiently modify the routing tables of routers, and further lead to DNS spoofing, phishing Website, eavesdropping, and manin-the-middle attacks. Furthermore, we also implement a security vulnerability detection system to detect the existing vulnerabilities of routing protocol deployed in real-world routers. Yubo Song, Shang Gao 0006, Aiqun Hu, Bin Xiao 0001 |
ICC | 2 |
| 2017 | FloodDefender: Protecting data and control plane resources under SDN-aimed DoS attacksabstractThe separated control and data planes in software-defined networking (SDN) with high programmability introduce a more flexible way to manage and control network traffic. However, SDN will experience long packet delay and high packet loss rate when the communication link between two planes is jammed by SDN-aimed DoS attacks with massive table-miss packets. In this paper, we propose FloodDefender, an efficient and protocol-independent defense framework for SDN/OpenFlow networks to mitigate DoS attacks. It stands between the controller platform and other controller apps, and can protect both the data and control plane resources by leveraging three new techniques: table-miss engineering to prevent the communication bandwidth from being exhausted; packet filter to identify attack traffic and save computational resources of the control plane; and flow rule management to eliminate most of useless flow entries in the switch flow table. All designs of FloodDefender conform to the OpenFlow policy, requiring no additional devices. We implement a prototype of FloodDefender and evaluate its performance in both software and hardware environments. Experimental results show that FloodDefender can efficiently mitigate the SDN-aimed DoS attacks, incurring less than 0.5% CPU computation to handle attack traffic, only 18ms packet delay and 5% packet loss rate under attacks. Shang Gao 0006, Zhe Peng, Bin Xiao 0001, Aiqun Hu, Kui Ren 0001 |
INFOCOM | 1 |
| 2017 | SCoP: Smartphone energy saving by merging push services in Fog computingabstractEnergy saving solutions on smartphone devices can greatly extend a smartphone's lasting time. However, today's push services require keep-alive connections to notify users of incoming messages, which cause costly energy consuming and drain a smartphone's battery quickly in cellular communications. Most keep-alive connections force smartphones to frequently send heartbeat packets that create additional energy-consuming radio-tails. No previous work has addressed the high-energy consumption of keep-alive connections in smartphones push services. In this paper, we propose Single Connection Proxy (SCoP) system based on fog computing to merge multiple keep-alive connections into one, and push messages in an energy-saving way. The new design of SCoP can satisfy a predefined message delay constraint and minimize the smartphone energy consumption for both real-time and delay-tolerant apps. SCoP is transparent to both smartphones and push servers, which does not need any changes on today's push service framework. Theoretical analysis shows that, given the Poisson distribution of incoming messages, SCoP can reduce the energy consumption by up to 50%. We implement SCoP system, including both the local proxy on the smartphone and remote proxy on the “Fog”. Experimental results show that the proposed system consumes 30% less energy than the current push service for real-time apps, and 60% less energy for delay-tolerant apps. Shang Gao 0006, Zhe Peng, Bin Xiao 0001, Qingjun Xiao, Yubo Song |
IWQoS | 1 |
| 2017 | Smartphone-assisted energy efficient data communication for wearable devices
Zhe Peng, Shang Gao 0006, Bin Xiao 0001, Henry C. B. Chan |
Comput. Commun. | 3 |
| 2016 | Secure and energy efficient prefetching design for smartphonesabstractEnergy efficient prefetching systems for smart-phones can greatly reduce energy consumption and data transmission, and maintain the timely response when information is prefetched. However, the proxy structure of the system can cause security problem to reveal private information to the third party. The end-to-end encryption (SSL) in traditional prefetching systems cannot solve the security problem in this new, complex energy efficient prefetching system. In this paper, we propose Secure and Energy Efficient Prefetching (SEEP) to meet the security requirement of HTTPS connections and to save smartphone's energy consumption and data transmission. The new design of SEEP includes two parts: the local proxy on the smartphone to verify the validity of prefetched responses, and the remote proxy (e.g. on the cloudlet) to store encrypted prefetched responses. SEEP is transparent to both smartphones and web servers, which does not need to change today's Browser/Server framework. Security analysis shows that SEEP protects the confidentiality of requests and responses, and is able to resist replay attack from malicious proxy. Experimental results show that the proposed system consumes 25% less energy and 95% less data when prefetching 10 outbound webpages than the traditional prefetching system in Wi-Fi networks. Shang Gao 0006, Zhe Peng, Bin Xiao 0001, Yubo Song |
ICC | 1 |