EDBT 2026 Demo / reviewers in the wild / expert
Ning Lu 0005
dblp:29/2864-5
· DBLP profile ↗
32ranked-venue papers
7as first author
25since 2021 · last 2026
0000-0001-7325-7307ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 5 first-author · 9 since 2021Computer networks · 9 · 1 first-author · 9 since 2021Systems, architecture and hardware · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Anti-APhish: A robust and adaptive detection approach against evolving AI-powered phishing URLs
Ning Lu 0005, Zhiquan Liu 0001 |
Expert Syst. Appl. | 3 |
| 2026 | RD-PCN: A Secure Role-Differentiated Payment Channel Network for Heterogeneous NodesabstractScalability is a critical challenge for blockchain-based cryptocurrencies and has become a significant bottleneck in large-scale applications such as retail. Payment channel networks (PCNs) are among the most promising solutions to this challenge. However, nodes in real-world PCNs exhibit heterogeneous behaviors and capabilities, causing existing schemes to perform poorly when deployed in practical environments. In this paper, we first demonstrate, through a measurement study, the existence of node heterogeneity in real-world PCNs; and then propose RD-PCN, a role-differentiated PCN that accommodates such heterogeneity by explicitly separating node roles and responsibilities. We address two key challenges in realizing RD-PCN. To improve channel fund utilization, RD-PCN introduces multi-party payment channels (MPCs) to selectively connect nodes at the network edge. We accordingly design a PCN-compatible MPC, termed PC-MPC, representing the first practical solution for deploying MPCs in PCNs. To securely outsource routing tasks to resource-rich nodes, we design a privacy-preserving and fair routing scheme based on trusted execution environments and the proposed topology synchronization mechanism. We prove the security of PC-MPC and the routing scheme under the universally composable framework. Experiments show that RD-PCN improves the payment success ratio by at least 18.9% compared to representative schemes, while increasing fund utilization by 60%. Qinghao Wang, Ning Lu 0005, Zhiquan Liu 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Loop-Filter: A Feedback Control Approach for Eliminating Link Flooding AttackabstractThe Link Flooding Attack (LFA) poses a significant threat to the network as a novel form of indirect, distributed denial-of-service attack. There is an urgent need for a defense capable of eliminating LFA. LFA operates as a closed-loop, continuously monitoring target links and adjusting traffic to adapt to network changes, thereby sustaining the attack. This implies that the effective defense against LFA should be feedback-control-based, enabling adaptive responses to evolving attack strategies. However, existing works for eliminating LFA operate using an open-loop way, which lacks feedback throughout the defense process, preventing them from efficiently detecting and blocking attack flows. In this paper, we adopt the concept of feedback control to propose Loop-Filter, which first filters part of the traffic on the attacked link and then refines the detected attack flows based on feedback from the link and flows to optimize traffic filtering. This process is repeated iteratively until the attacked link returns to normal. To implement the concept, we propose a blockchain-based collaboration defense architecture, along with economic incentives, to promote cooperation between domains. Meanwhile, we leverage reinforcement learning to learn how to rapidly and accurately adjust the detection results of flows based on the feedback. We also design a lossless compression method of filtering rules and dynamically deploy them to drop attack traffic maximally. Finally, we validate the effectiveness and efficiency of Loop-Filter under various traffic conditions. Qinghao Wang, Ning Lu 0005 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2026 | SegFlow: High-Performance Routing in Payment Channel Networks via Network Partitioning
Qinghao Wang, Ning Lu 0005 |
IEEE Trans. Netw. | 4 |
| 2025 | AdaptPUD: An accurate URL-based detection approach against tailored deceptive phishing websites
Jinmin Wu, Ning Lu 0005, Zhiquan Liu 0001 |
Comput. Networks | 3 |
| 2025 | ATSDetector: An Android Trojan spyware detection approach with multi-features
Haiyong Wu, Ning Lu 0005, Zhiquan Liu 0001 |
Comput. Secur. | 3 |
| 2025 | ESDI: An efficient and secure data integrity verification scheme for indoor navigation
Tailong Yang, Athanasios V. Vasilakos, Ning Lu 0005 |
Future Gener. Comput. Syst. | 5 |
| 2025 | Blockchain-based secure and fair data trading mechanism for healthcare
Kuan Fan, Shiyue Zhou, Ning Lu 0005 |
J. Inf. Secur. Appl. | 5 |
| 2024 | A precise method of identifying Android application familyabstractAbstract Implementing the necessary countermeasures to detect the growing and highly destructive family of malware is an urgent obligation. The proliferation and diversity of malware make these problems more challenging. For beginners, it is arduous to attain crucial features for multi‐class family classification and extract valuable information from the obtained features. Another issue is that building a classification model that effectively absorbs multi‐class samples and adapts to various features is challenging. This work indicates a precise identification method for Android application families (ANDF) to tackle these issues. It perceptively analyzes the features that multi‐class families can utilize to identify members and further excavates the relationship between implicit information and the severity of those distinctions. A more appropriate classification model is developed for the heterogeneous file formats, and a more beneficial feature with a diverse array of heterogeneous information is chosen as the replacement representation of the sample. It is capable of upgrading learning ability and mastering the multi‐modal traits of the family malware. The application of ANDF to real data sets yields effective classification results. It is capable of 0.9800 in f1‐macro and has a classification accuracy of 98.61%. It performs, respectively, 0.0088 points better than the two‐feature comparison classification model and 0.0872 points better than the single‐feature comparison classification model. The kappa coefficient can also exceed 0.9830, which is at least 0.1044 higher than other contrasting classifiers and is 0.0105 greater than that of the contrasted model containing two features, which is 0.1046 larger than the classifier with a contrasting single feature. Dan Li 0028, Ning Lu 0005, Chang Choi |
Expert Syst. J. Knowl. Eng. | 2 |
| 2024 | Traceable ring signature schemes based on SM2 digital signature algorithm and its applications in the data sharing scheme
Hong Lei 0001, Qinghao Wang, Ning Lu 0005, Bangdao Chen, Qiuling Yue |
Frontiers Comput. Sci. | 5 |
| 2024 | Practical Privacy-Preserving Scheme With Fault Tolerance for Smart GridsabstractIn smart grid services, the leakage of crowdsourced consumption data on smart meters (SMs) poses potential risks of privacy disclosure and data misuse. Existing solutions, which rely on complex encrypted computations, are often impractical for resource-limited SMs due to their high computation and storage resource requirements. To address these challenges, this article proposes a practical privacy-preserving scheme with fault tolerance for smart grid services named 3PFT. In our scheme, we employ a masking approach that ensures user privacy preservation on SMs while consuming minimal resources. Unlike existing masking schemes, 3PFT provides fault tolerance, supports complex data analysis tasks, and mitigates vulnerabilities to key leakage attacks. To achieve these objectives, we incorporate a secret sharing technique into the masking approach, enabling the recovery of the master key using only a portion of the data. Additionally, we design a flexible data aggregation protocol for 3PFT, facilitating the execution of diverse data analysis missions, such as load forecasting, in smart grids. Furthermore, we introduce a negotiation-based key update method to enhance the protocol’s forward security and alleviate the additional overhead on SMs. Finally, we provide a rigorous proof of privacy preservation and fault tolerance for our scheme and validate its feasibility and effectiveness through extensive simulations. Ning Lu 0005, Zhou Su 0001, Weizhi Meng 0001 |
IEEE Internet Things J. | 3 |
| 2024 | PACTA: An IoT Data Privacy Regulation Compliance Scheme Using TEE and BlockchainabstractDespite the existence of data privacy regulations, such as the general data protection regulation (GDPR), data leaks in the Internet of Things (IoT) still occur and cause significant harm due to the noncompliance of data users. To address this issue, a notable solution involves recording the process in an open, immutable blockchain and utilizing the trusted execution environment (TEE) for reliable compliance verification. Although substantial progress has been made in designing compliance schemes in recent years, current approaches suffer from various limitations, including compliance incompleteness, regulation faultiness, and privacy leak. This article introduces PACTA, an IoT data privacy regulation compliance scheme that leverages TEE and blockchain technology. In the protocol, PACTA efficiently handles both dynamic and static consent of data owners and utilizes TEE for compliance analysis of requests and processes. By storing encrypted critical data, the blockchain facilitates privacy-preserving audits of the entire compliance process. Additionally, we have designed a challenge–response protocol to address the silent behavior of the TEE. We demonstrate that PACTA effectively enforces regulation compliance while safeguarding privacy. We thoroughly evaluate our implementation’s efficiency and effectiveness using Ethereum and Intel SGX platforms. Hong Lei 0001, Zijian Bao, Ning Lu 0005, Bangdao Chen |
IEEE Internet Things J. | 5 |
| 2024 | SEA: Secure and Efficient Public Auditing for Edge-Assisted IoT Aggregated Data Sharing
Ning Lu 0005, Yihong Wen, Qingfeng Cheng |
Mob. Networks Appl. | 2 |
| 2024 | SG-Audit: An Efficient and Robust Cloud Auditing Scheme for Smart GridabstractCloud auditing allows users to leverage digital signature evidences to undertake remote data verification and consequently determine the integrity of their data stored in the cloud. While there are many cloud auditing schemes proposed for cloud services, deployments on large scale smart grid (SG) are known to be challenging in practice, for example in terms of inefficiency and lack of robustness. In this paper, we propose an efficient and robust cloud auditing scheme for SG (hereafter referred to as SG-Audit). Specifically, we utilize mobile edge computing (served as proxy signer) to offload the signature computation loads incurred by smart meters (SMs), as well as devising an efficient proxy signer recommendation strategy to ensure each SM obtains high quality service, a scalable index structure to reduce the signature evidence access time during data verification, and a deduplication and sampling based challenge data index generation strategy to narrow down the verification scope. Moreover, we also define three strategic threat scenarios supported by SG-Audit, and further devise a secure cloud auditing protocol to improve robustness. Through rigorous mathematical analysis and extensive experiments, we demonstrate that SG-Audit achieves increased auditing efficiency (by about 42% on average) in comparison to prior work. Ning Lu 0005, Ximeng Liu, Kim-Kwang Raymond Choo |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | V-Digger: An Efficient and Secure Vulnerability Assessment for Large-Scale ISP NetworkabstractVulnerability assessment allows cyber security professionals to discover vulnerable end devices. Generally, in such a process one extracts the default Service Banner (SB) from the application layer message of each device, prior to matching the SB with each Common Vulnerabilities and Exposures (CVE) in the public National Vulnerability Database (NVD). However, such an approach is not practical in large-scale ISP networks due to the efforts involved (e.g., collecting of SBs, and CVE matching) and potential vulnerability information leakage. In this paper, we propose V-Digger, an efficient and secure vulnerability assessment approach. Specifically, we adopt a flexible distributed architecture based on Local Area Network (LAN), which allows each LAN of the respective ISP network to participate in vulnerability assessment and share vulnerability data as per demand. To obtain more SBs, we design a system parameter evaluation method, which ensures that the collection task is performed under light network load. To expedite CVE matching, we devise an efficient SB-to-CPE transformer and a fast CVE searching algorithm. To prevent vulnerability leakage, we also design a secure vulnerability sharing protocol. We then undertake extensive theoretical analysis and real-world experiments to prove the effectiveness and efficiency of V-Digger. The results show that the assessment accuracy can achieve almost 85%, and its assessment rate is about 330 seconds per 1,000 devices. Ning Lu 0005, Ruxiao Huang, Mingliang Yao, Kim-Kwang Raymond Choo |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Location-Aware and Privacy-Preserving Data Cleaning for Intelligent TransportationabstractThe widespread use of machine learning in location-related scenarios is propelling the rapid development of intelligent transportation. To assist users in making more informed travel plans, the demand for improving prediction accuracy is growing. Prior to model training, data cleaning is a common method used to eliminate redundant, erroneous and outlier samples. However, in intelligent transportation, there are serious issues with location awareness and privacy protection of existing data cleaning schemes. Therefore, we propose a location-aware and privacy-preserving data cleaning framework (PriSPA) which provides a cleaned dataset consisting of the samples from adopted data suppliers at qualified locations while ensuring the privacy of locations, spatial constraints and sensitive samples. We combine boolean secret sharing with XOR operations to make sure that it is possible to figure out whether a location complies with spatial constraints without leakage. More specifically, we ensure privacy using key agreement, secret sharing, authenticated encryption and random permutation. We seriously analyze the security of PriSPA and conduct comprehensive experiments to prove its security, effectiveness and efficiency. Based on the comparisons with the raw traffic forecasting framework, we observe that PriSPA improves the precision of the model with 17.6% - 32.7% error reduction. Junwei Zhang 0008, Zhuo Ma 0001, Ning Lu 0005, Teng Li 0003, Jianfeng Ma 0001 |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2024 | ARdetector: android ransomware detection framework
Dan Li 0028, Ning Lu 0005, Sang-Su Lee |
J. Supercomput. | 3 |
| 2023 | OWL: A data sharing scheme with controllable anonymity and integrity for group users
Zijian Bao, Qinghao Wang, Ning Lu 0005, Bangdao Chen, Hong Lei 0001 |
Comput. Commun. | 4 |
| 2022 | Traceable Ring Signature Schemes Based on SM2 Digital Signature Algorithm and Its Applications in the Evidence-Storage System
Qinghao Wang, Ning Lu 0005, Hong Lei 0001 |
BlockSys | 3 |
| 2022 | A Secure Access Control Framework for Cloud Management
Jiawei Zhang 0011, Ning Lu 0005, Jianfeng Ma 0001, Ruixiao Wang 0002 |
Mob. Networks Appl. | 2 |
| 2022 | CoinLayering: An Efficient Coin Mixing Scheme for Large Scale Bitcoin TransactionsabstractCoin mixing can be used to preserve identity privacy of Bitcoin owners, by engaging a set of middlepersons (i.e.,$Mix$) to temporarily hold the transacting Bitcoins and remove the linkage between the transacting parties. However, existing schemes are generally not scalable due to limitations associated with the anonymity set and self-credibility. In this article, we propose an efficient coin mixing scheme (hereafter referred to as CoinLayering). To achieve strong anonymity, CoinLayering randomly selects two sets of middlepersons to respectively execute Bitcoin holding and Bitcoin trading. The seller can also select lower-loaded sets of middlepersons in the shortest time possible. We also design two coin mixing protocols, CoinLayering-PA and CoinLayering-PB, to mitigate the risk due to misbehaving middlepersons and$Supervisor$. We then mathematically prove that CoinLayering achieves both strong anonymity and self-credibility, and evaluate its performance to demonstrate its scalability. Ning Lu 0005, Kim-Kwang Raymond Choo |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | STOP: A Service Oriented Internet Purification Against Link Flooding AttacksabstractInternet purification is a necessary technique to defend against Distributed Denial-of-Service (DDoS) attack. It can help Internet Service Provider (ISP) to completely and precisely scrub attack traffic through establishing the sender-receiver pair based filtering rules in networks. However, when faced with the Link Flooding Attacks (LFA), a new kind of DDoS, existing relevant schemes suffer the drawbacks, including the weak willingness of defense cooperation between Autonomous Systems (ASes), lower filtering efficiency and poor robustness. For this, we propose STOP, a service-oriented Internet purification technique designed to defend against LFA. In STOP, malicious traffic filtering is viewed as a value-added service and each filter contributor (i.e., AS) can get some benefit from it. This helps ASes to strengthen the willing of defense cooperation. Moreover, we devise a filter recommendation algorithm to maximize the filtering efficiency, with minimum service cost and bandwidth damages. Furthermore, in the face of the strategic threats that aim to paralyze or bypass STOP, we devise relevant defense techniques to make it more robust. Through rigorous mathematical analysis and extensive experiments based on real-world topology, we demonstrate that compared with prior work, STOP increases the filtering efficiency by 12%. Ning Lu 0005, Junwei Zhang 0001, Ximeng Liu, Jianfeng Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2021 | An efficient combined deep neural network based malware detection framework in 5G environment
Ning Lu 0005, Dan Li 0028, Pandi Vijayakumar, Francesco Piccialli, Victor Chang 0001 |
Comput. Networks | 1 |
| 2021 | NeuCheck: A more practical Ethereum smart contract security analysis toolabstractSummary Ethereum is one of the currently popular trading platform, where any one can exchange, buy, or sell cryptocurrencies. Smart contract, a computer program, can help Ethereum to encode rules or scripts for processing transactions. Because the smart contract usually handles large number of cryptocurrencies worth billions of dollars apiece, its security has gained considerable attention. In this paper, we first investigate the security of smart contracts running on the Ethereum and introduce several new security vulnerabilities that allow adversaries to exploit and gain financial benefits. Then, we propose a more practical smart contract analysis tool termed NeuCheck, in which we introduce the syntax tree in the syntactical analyzer to complete the transformation from source code to intermediate representation, and then adopt the open source library working with XML to analyze such tree. We have built a prototype of NeuCheck for Ethereum and evaluate it with over 52 000 existing Ethereum smart contracts. The results show that (1) our new documented vulnerabilities are prevalent; (2) NeuCheck improves the analysis speed by at least 17.2 times compared to other popular analysis tools (eg, Securify and Mythril; and (3) allows for cross‐platform deployment. Ning Lu 0005, Christian Esposito 0001 |
Softw. Pract. Exp. | 1 |
| 2021 | Enabling Efficient Decentralized and Privacy Preserving Data Sharing in Mobile Cloud ComputingabstractMobile cloud computing (MCC) is embracing rapid development these days and able to provide data outsourcing and sharing services for cloud users with pervasively smart mobile devices. Although these services bring various conveniences, many security concerns such as illegally access and user privacy leakage are inflicted. Aiming to protect the security of cloud data sharing against unauthorized accesses, many studies have been conducted for fine‐grained access control using ciphertext‐policy attribute‐based encryption (CP‐ABE). However, a practical and secure data sharing scheme that simultaneously supports fine‐grained access control, large university, key escrow free, and privacy protection in MCC with expressive access policy, high efficiency, verifiability, and exculpability on resource‐limited mobile devices has not been fully explored yet. Therefore, we investigate the challenge and propose an Efficient and Multiauthority Large Universe Policy‐Hiding Data Sharing (EMA‐LUPHDS) scheme. In this scheme, we employ fully hidden policy to preserve the user privacy in access policy. To adapt to large scale and distributed MCC environment, we optimize multiauthority CP‐ABE to be compatible with large attribute universe. Meanwhile, for the efficiency purpose, online/offline and verifiable outsourced decryption techniques with exculpability are leveraged in our scheme. In the end, we demonstrate the flexibility and high efficiency of our proposal for data sharing in MCC by extensive performance evaluation. Jiawei Zhang 0011, Ning Lu 0005, Teng Li 0003, Jianfeng Ma 0001 |
Wirel. Commun. Mob. Comput. | 2 |
| 2020 | A secure and scalable data integrity auditing scheme based on hyperledger fabric
Ning Lu 0005, Saru Kumari, Kim-Kwang Raymond Choo |
Comput. Secur. | 1 |
| 2020 | Opcode sequence analysis of Android malware by a convolutional neural networkabstractSummary The number of malware has exploded due to the openness of the Android platform, and the endless stream of malware poses a threat to the privacy, tariffs, and device of mobile phone users. A novel Android mobile malware detection system is proposed, which employs an optimized deep convolutional neural network to learn from opcode sequences. The optimized convolutional neural network is trained multiple times by the raw opcode sequences extracted from the decompiled Android file, so that the feature information can be effectively learned and the malicious program can be detected more accurately. More critically, the k‐max pooling method with better results is adopted in the pooling operation phase, which improves the detection effect of the proposed method. The experimental results show that the detection system achieved the accuracy of 99%, which is 2%‐11% higher than the accuracy of the machine learning detection algorithms when using the same data set. It also ensures that the indicators, such as F1‐score, recall, and precision, are maintained above 97%. Based on the detection system, a multi–data set comparison experiment is carried out. The introduced k‐max pooling is deeply studied, and the effect of k of k‐max pooling on the overall detection effect is observed. Dan Li 0028, Lichao Zhao, Qingfeng Cheng, Ning Lu 0005 |
Concurr. Comput. Pract. Exp. | 4 |
| 2019 | Universally composable secure geographic area verification without pre-shared secret
Junwei Zhang 0001, Ning Lu 0005, Jianfeng Ma 0001, Chao Yang 0016 |
Sci. China Inf. Sci. | 2 |
| 2017 | A privacy-preserving degree-matching multi-attribute auction scheme in smart grid auction market
Zijian Bao, Jiaqi Wang 0011, Ning Lu 0005, Jian Shen 0001 |
Pers. Ubiquitous Comput. | 4 |
| 2017 | A Security and Efficient Routing Scheme with Misbehavior Detection in Delay-Tolerant NetworksabstractDue to the unique network characteristics, the security and efficient routing in DTNs are considered as two great challenges. In this paper, we design a security and efficient routing scheme, called SER, which integrates the routing decision and the attacks detection mechanisms. In SER scheme, each DTNs node locally maintains a one-dimensional vector table to record the summary information about the contact with other nodes and the trust degree of other nodes. To obtain the global status and the contact relationship among all nodes, the trusted routing table consisting of vectors of all nodes is built in each DTNs node. The method for detecting malicious nodes and selfish nodes is proposed, which exploits the global summary information to analyze the history forwarding behavior of node and judge whether it is a malicious node or selfish node. The routing decision method is proposed based on trust degree of forwarding messages between nodes, which adopts trust degree as relay node selection strategy. Simulation results show that compared with existing schemes SER scheme could detect the attacks behavior of malicious nodes and selfish nodes, at the same time, with higher delivery rate and lower average delivery delay. Feng Li 0017, Yali Si, Ning Lu 0005, Zhen Chen 0007 |
Secur. Commun. Networks | 3 |
| 2016 | A Secure Reverse Multi-Attribute First-Price E-Auction Mechanism Using Multiple Auctioneer Servers (Work in Progress)
Jiaqi Wang 0011, Ning Lu 0005 |
ProvSec | 3 |
| 2015 | Postfix automata
Maohua Jing, Yixian Yang, Ning Lu 0005, Changyong Yu |
Theor. Comput. Sci. | 3 |