Tong Li 0011

dblp:29/3826-11 · DBLP profile ↗
← Back
47ranked-venue papers
8as first author
23since 2021 · last 2026
0000-0003-3678-8402ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 15 · 3 first-author · 12 since 2021Databases, data management, data science and information retrieval · 12 · 2 first-author · 6 since 2021Systems, architecture and hardware · 7Computer networks · 6 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 4 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Theory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2026 CTRAP: Embedding Collapse Trap to Safeguard Large Language Models from Harmful Fine-Tuning
abstract
Fine-tuning-as-a-service, while commercially successful for Large Language Model (LLM) providers, exposes models to harmful finetuning attacks.As a widely explored defense paradigm against such attacks, unlearning attempts to remove malicious knowledge from LLMs, thereby essentially preventing them from being used to perform malicious tasks.However, we highlight a critical flaw: the inherent general adaptability of LLMs allows them to easily bypass selective unlearning by rapidly relearning or repurposing their general capabilities for harmful tasks.To address this fundamental limitation, we propose a paradigm shift: instead of selective removal, we advocate for inducing model collapse, effectively forcing the model to "unlearn everything", specifically in response to updates characteristic of malicious adaptation.This collapse directly neutralizes the very general capabilities that attackers exploit, tackling the core issue unaddressed by selective unlearning.We introduce the Collapse Trap (CTRAP) as a practical mechanism to implement this concept conditionally.Embedded during alignment, CTRAP pre-configures the model's reaction to subsequent fine-tuning dynamics.If updates during fine-tuning constitute a persistent attempt to reverse safety alignment, the pre-configured trap triggers a progressive degradation of the model's core language modeling abilities, ultimately rendering it inert and useless for the attacker.Crucially, this collapse mechanism remains dormant during benign fine-tuning, ensuring the model's utility and general capabilities are preserved.1
Biao Yi, Tiansheng Huang, Baolei Zhang, Tong Li 0011, Lihai Nie, Zheli Liu, Li Shen 0008
ACL (1)4
2026 Practical Poisoning Attacks against Retrieval-Augmented Generation
abstract
Large language models (LLMs) have demonstrated impressive natural language processing abilities but face challenges such as hallucination and outdated knowledge. Retrieval-Augmented Generation (RAG) has emerged as a state-of-the-art approach to mitigate these issues. While RAG enhances LLM outputs, it remains vulnerable to poisoning attacks. Recent studies show that injecting poisoned texts into the knowledge database can compromise RAG systems, but most existing attacks assume that the attacker can insert a sufficient number of poisoned texts per query to outnumber correct-answer texts in retrieval, an assumption that is often unrealistic. To address this limitation, we propose CorruptRAG, a practical poisoning attack against RAG systems in which the attacker injects only a single poisoned text, enhancing both feasibility and stealth. Extensive experiments conducted on multiple large-scale datasets demonstrate that CorruptRAG achieves higher attack success rates than existing baselines.
Baolei Zhang, Zhuqing Liu, Lihai Nie, Tong Li 0011, Zheli Liu, Minghong Fang
SACMAT5
2026 Who Taught the Lie? Responsibility Attribution for Poisoned Knowledge in Retrieval-Augmented Generation
abstract
Retrieval-Augmented Generation (RAG) integrates external knowledge into large language models to improve response quality. However, recent work has shown that RAG systems are highly vulnerable to poisoning attacks, where malicious texts are inserted into the knowledge database to influence model outputs. While several defenses have been proposed, they are often circumvented by more adaptive or sophisticated attacks. This paper presents RAGOrigin, a black-box responsibility attribution framework designed to identify which texts in the knowledge database are responsible for misleading or incorrect generations. Our method constructs a focused attribution scope tailored to each misgeneration event and assigns a responsibility score to each candidate text by evaluating its retrieval ranking, semantic relevance, and influence on the generated response. The system then isolates poisoned texts using an unsupervised clustering method. We evaluate RAGOrigin across seven datasets and fifteen poisoning attacks, including newly developed adaptive poisoning strategies and multi-attacker scenarios. Our approach outperforms existing baselines in identifying poisoned content and remains robust under dynamic and noisy conditions. These results suggest that RAGOrigin provides a practical and effective solution for tracing the origins of corrupted knowledge in RAG systems. Our code is available at: https://github.com/zhangbl6618/RAG-Responsibility-Attribution
Baolei Zhang, Haoran Xin 0002, Zhuqing Liu, Biao Yi, Tong Li 0011, Lihai Nie, Zheli Liu, Minghong Fang
SP6
2026 SIsomap: Secure Collaborative Manifold Learning with Reducing Communication Costs
abstract
Secure manifold learning on datasets distributed among multiple data owners can benefit or even spawn many applications. For example, multiple service providers can jointly fit low-dimensional embeddings of their users' network behavior data to improve the accuracy of anomaly detection while addressing their privacy concerns about the datasets. In this paper, we focus on a classic manifold learning technique, known as isometric mapping (Isomap), and propose SIsomap, the first secure, distributed manifold learning system. We construct SIsomap based on secret sharing techniques and introduce careful optimizations. In particular, we propose two communication-efficient secure building blocks that focus on top-k and all-pairs shortest paths computation, respectively, and reduce secure operations by leveraging the characteristics of Isomap. Experimental results on both synthetic and real-world datasets demonstrate that our secure top-k and all-pairs shortest paths protocols are respectively up to 13.6× and 1818.5× faster than the state-of-the-art methods, and SIsomap as a whole is 11.1× to 28.8× faster than the baseline solution.
Peizhao Zhou, Xiaojie Guo 0004, Pinzhi Chen, Ranyang Liu, Lihai Nie, Tong Li 0011, Zheli Liu
WWW6
2026 SecureCA: Communication- and Round-Efficient Join and Group-By-Aggregation in Secure Database Services
Pinzhi Chen, Peizhao Zhou, Xiaojie Guo 0004, Tong Li 0011, Zheli Liu
IEEE Trans. Dependable Secur. Comput.6
2026 Efficient Circuit-PSI and Extensions via Distributed Key-Value Store
Ranyang Liu, Xiaojie Guo 0004, Tong Li 0011, Xiaofeng Chen 0001, Zheli Liu
IEEE Trans. Dependable Secur. Comput.3
2026 BOMAP: A Round-Efficient Construction of Oblivious Maps
abstract
Oblivious map is a cryptographic data structure for programs whose data access patterns exhibit some degree of predictability, which plays a pivot role in constructing high-security searchable encryption schemes that protect both search and access patterns. Typically, oblivious map schemes adopt the combination of an index tree and Oblivious RAM (ORAM) in their construction. However, the round complexity of access operations in these schemes is inherently linked to the height of the index tree, which is logarithmically proportional to the total number of blocks, denoted as$N$. This results in a traditional requirement of$O(\log N)$rounds of interaction per access, which is a significant inefficiency that hampers the practical applicability of oblivious maps. To this end, we design a new fixed-height index tree structure and employ it to construct a new oblivious map scheme, called BOMAP. This scheme features a small number of interaction rounds and does not require the client to store state information beyond the cache. Additionally, BOMAP achieves obliviousness with reduced padding in each access operation. We analyze the theoretical communication size for BOMAP and conclude that BOMAP has obvious advantages when an adaptive height is selected based on$N$(e.g., a 4-level index tree when$N=2^{24}$). Experimental results further demonstrate that the fewer interaction rounds and less padding strategy make BOMAP more efficient than previous oblivious map schemes.
Siyi Lv, Xiang Li 0156, Haoshuai Gong, Zheli Liu, Tong Li 0011, Liang Guo 0013
IEEE Trans. Dependable Secur. Comput.6
2026 A Unified Framework of Private Set Operations With Stronger Security
Ranyang Liu, Xiaojie Guo 0004, Tong Li 0011, Zheli Liu
IEEE Trans. Inf. Forensics Secur.3
2026 Practical Framework for Privacy-Preserving and Byzantine-Robust Federated Learning
abstract
Federated Learning (FL) allows multiple clients to collaboratively train a model without sharing their private data. However, FL is vulnerable toByzantine attacks, where adversaries manipulate client models to compromise the federated model, andprivacy inference attacks, where adversaries exploit client models to infer private data. Existing defenses against both backdoor and privacy inference attacks introduce significant computational and communication overhead, creating a gap between theory and practice. To address this, we propose ABBR, a practical framework for Byzantine-robust and privacy-preserving FL. We are the first to utilize dimensionality reduction to speed up the private computation of complex filtering rules in privacy-preserving FL. Additionally, we analyze the accuracy loss of vector-wise filtering in low-dimensional space and introduce an adaptive tuning strategy to minimize the impact of malicious models that bypass filtering on the global model. We implement ABBR with state-of-the-art Byzantine-robust aggregation rules and evaluate it on public datasets, showing that it runs significantly faster, has minimal communication overhead, and maintains nearly the same Byzantine-resilience as the baselines.
Baolei Zhang, Minghong Fang, Zhuqing Liu, Biao Yi, Peizhao Zhou, Tong Li 0011, Zheli Liu
IEEE Trans. Inf. Forensics Secur.7
2025 Prompt-Guided Internal States for Hallucination Detection of Large Language Models
abstract
Large Language Models (LLMs) have demonstrated remarkable capabilities across a variety of tasks in different domains. However, they sometimes generate responses that are logically coherent but factually incorrect or misleading, which is known as LLM hallucinations. Data-driven supervised methods train hallucination detectors by leveraging the internal states of LLMs, but detectors trained on specific domains often struggle to generalize well to other domains. In this paper, we aim to enhance the cross-domain performance of supervised detectors with only in-domain data. We propose a novel framework, prompt-guided internal states for hallucination detection of LLMs, namely PRISM. By utilizing appropriate prompts to guide changes to the structure related to text truthfulness in LLMs’ internal states, we make this structure more salient and consistent across texts from different domains. We integrated our framework with existing hallucination detection methods and conducted experiments on datasets from different domains. The experimental results indicate that our framework significantly enhances the cross-domain generalization of existing hallucination detection methods.
Fujie Zhang, Peiqi Yu, Biao Yi, Baolei Zhang, Tong Li 0011, Zheli Liu
ACL (1)5
2025 Probe before You Talk: Towards Black-box Defense against Backdoor Unalignment for Large Language Models
abstract
Backdoor unalignment attacks against Large Language Models (LLMs) enable the stealthy compromise of safety alignment using a hidden trigger while evading normal safety auditing. These attacks pose significant threats to the applications of LLMs in the real-world Large Language Model as a Service (LLMaaS) setting, where the deployed model is a fully black-box system that can only interact through text. Furthermore, the sample-dependent nature of the attack target exacerbates the threat. Instead of outputting a fixed label, the backdoored LLM follows the semantics of any malicious command with the hidden trigger, significantly expanding the target space. In this paper, we introduce BEAT, a black-box defense that detects triggered samples during inference to deactivate the backdoor. It is motivated by an intriguing observation (dubbed the **probe concatenate effect**), where concatenated triggered samples significantly reduce the refusal rate of the backdoored LLM towards a malicious probe, while non-triggered samples have little effect. Specifically, BEAT identifies whether an input is triggered by measuring the degree of distortion in the output distribution of the probe before and after concatenation with the input. Our method addresses the challenges of sample-dependent targets from an opposite perspective. It captures the impact of the trigger on the refusal signal (which is sample-independent) instead of sample-specific successful attack behaviors. It overcomes black-box access limitations by using multiple sampling to approximate the output distribution. Extensive experiments are conducted on various backdoor attacks and LLMs (including the closed-source GPT-3.5-turbo), verifying the effectiveness and efficiency of our defense. Besides, we also preliminarily verify that BEAT can effectively defend against popular jailbreak attacks, as they can be regarded as "natural backdoors". Our source code is available at https://github.com/clearloveclearlove/BEAT.
Biao Yi, Tiansheng Huang, Sishuo Chen, Tong Li 0011, Zheli Liu, Zhixuan Chu, Yiming Li 0004
ICLR4
2025 Traceback of Poisoning Attacks to Retrieval-Augmented Generation
abstract
Large language models (LLMs) integrated with retrieval-augmented generation (RAG) systems improve accuracy by leveraging external knowledge sources. However, recent research has revealed RAG's susceptibility to poisoning attacks, where the attacker injects poisoned texts into the knowledge database, leading to attacker-desired responses. Existing defenses, which predominantly focus on inference-time mitigation, have proven insufficient against sophisticated attacks. In this paper, we introduce RAGForensics, the first traceback system for RAG, designed to identify poisoned texts within the knowledge database that are responsible for the attacks. RAGForensics operates iteratively, first retrieving a subset of texts from the database and then utilizing a specially crafted prompt to guide an LLM in detecting potential poisoning texts. Empirical evaluations across multiple datasets demonstrate the effectiveness of RAGForensics against state-of-the-art poisoning attacks. This work pioneers the traceback of poisoned texts in RAG systems, providing a practical and promising defense mechanism to enhance their security.
Baolei Zhang, Haoran Xin 0002, Minghong Fang, Zhuqing Liu, Biao Yi, Tong Li 0011, Zheli Liu
WWW6
2025 LUNA: Efficient Backward-Private Dynamic Symmetric Searchable Encryption Scheme With Secure Deletion in Encrypted Database
abstract
Dynamic symmetric searchable encryption (SSE) enables clients to perform searches and updates on an encrypted database outsourced to an untrusted server while preserving the privacy of data and queries. For restricting information leakage, it is very important to limit what the server can learn about the deleted data during searches after the deletion, i.e., to satisfy backward privacy. However, previous backward privacy definitions only considered the logical deletion of keywords in documents while ignoring security risks caused by the actual deletion of documents. Moreover, existing SSE schemes often depend on heavy cryptographic primitives for achieving high-level backward privacy, which greatly degrades the end-to-end performance. To this end, we define a new backward privacy notion named BP-DEL, which restricts the information leakage of the actual deletion. Moreover, we design a hybrid index structure that provides BP-DEL for SSE schemes such that they support deletions securely. Based on the hybrid index, we propose a BP-DEL construction named LUNA and design its protocols with a trusted execution environment (TEE) to maintain the index efficiently. Finally, we implement LUNA in the MySQL database by encapsulating it in UDFs. The experimental results show that LUNA has a performance much better than previous works satisfying BP-DEL.
Siyi Lv, Yanyu Huang, Tong Li 0011, Liang Guo 0013, Xiaofeng Chen 0001, Zheli Liu
IEEE Trans. Knowl. Data Eng.4
2025 SMPCache: Towards More Efficient SQL Queries in Multi-Party Collaborative Data Analysis
abstract
Privacy-preserving collaborative data analysis is a popular research direction in recent years. Among all such analysis tasks, privacy-preserving SQL queries on multi-party databases are of particular industrial interest. Although the privacy concern can be addressed by many cryptographic tools, such as secure multi-party computation (MPC), the efficiency of executing such SQL queries is far from satisfactory, especially for high-volume databases. In particular, existing MPC-based solutions treat each SQL query as an isolated task and launch it from scratch, in spite of the nature that many SQL queries are done regularly and somewhat overlap in their functionalities. In this work, we are motivated to exploit this nature to improve the efficiency of MPC-based, privacy-preserving SQL queries. We introduce a cache-like optimization mechanism. To ensure a higher cache hit rate and reduce redundant MPC operators, we present a cache structure different from that of plain databases and design a set of cache strategies. Our optimization mechanism, SMPCache, can be built upon secret-sharing-based MPC frameworks, which attract much attention from the industry. To demonstrate the utility of SMPCache, we implement it on Rosetta, an open-source MPC library, and use real-world datasets to launch extensive experiments on some basic SQL operators (e.g., Filter, Order-by, Aggregation, and Inner-Join) and some representative composite SQL queries. To give a data point, we note that SMPCache can achieve most up to 3536× efficiency improvement on the TPC-DS dataset and 562× on the TPC-H dataset at a moderate storage cost. We also apply SMPCache to the basic SQL operators (Filter, Order-by, Group-by, Aggregation, and Inner-join) of the Secrecy framework, achieving up to 127.3× efficiency improvement.
Junjian Shi, Xiaojie Guo 0004, Zekun Fei, Zheli Liu, Siyi Lv, Tong Li 0011
IEEE Trans. Knowl. Data Eng.7
2025 EdgeSyn: Privacy-Preserving Data Publishing on Edge Network over Infinite Multimedia Data Stream
abstract
To privately publish sensitive multimedia data in an edge network with fog devices, one of the best privacy-preserving solutions is to use differential privacy (DP) mechanisms. However, existing DP data publication mechanisms for the infinite data stream of edge networks mainly focus on publishing data with specific types of data or a set of predetermined queries. This approach is not suitable for multimedia data with numerous features that require a more flexible data publishing mechanism. In this article, we propose EdgeSyn, a novel mechanism for accurately publishing multimedia data over infinite data streams in an edge network. It allocates privacy budgets with a sliding window, adopting data synthesis mechanisms to support dynamic publishing without loss of accuracy. In more detail, EdgeSyn addresses the limitations associated with data types in prior data stream publishing approaches and introduces a privacy budget management strategy that optimally allocates budgets for the implementation of data synthesis mechanisms over an infinite data stream. The experimental results show that EdgeSyn performs well under different privacy budgets and various lengths of active windows.
Zhewei Liu, Zhengdao Li, Jingyu Jia, Siyi Lv, Tong Li 0011, Zheli Liu
ACM Trans. Multim. Comput. Commun. Appl.6
2024 Shortcut: Making MPC-based Collaborative Analytics Efficient on Dynamic Databases
abstract
Secure Multi-party Computation (MPC) provides a promising solution for privacy-preserving multi-source data analytics. However, existing MPC-based collaborative analytics systems (MCASs) have unsatisfying performance for scenarios with dynamic databases. Naively running an MCAS on a dynamic database would lead to significant redundant costs and raise performance concerns, due to the substantial duplicate contents between the pre-updating and post-updating databases.
Peizhao Zhou, Xiaojie Guo 0004, Pinzhi Chen, Tong Li 0011, Siyi Lv, Zheli Liu
CCS4
2024 Low-cost fuzzing drone control system for configuration errors threatening flight safety in edge terminals
Zhiwei Chang, Hanfeng Zhang, Yan Jia 0009, Sihan Xu, Tong Li 0011, Zheli Liu
Comput. Commun.5
2024 New approach for efficient malicious multiparty private set intersection
Siyi Lv, Yu Wei 0007, Jingyu Jia, Tong Li 0011, Zheli Liu, Xiaofeng Chen 0001, Liang Guo 0013
Inf. Sci.5
2024 Poison-Tolerant Collaborative Filtering Against Poisoning Attacks on Recommender Systems
abstract
Personalized recommendation is deemed ubiquitous. Indeed, it has been applied to several online services (e.g., E-commerce, advertising, and social media applications, to name a few). Learning unknown user preferences from user-provided data lies at the core of modern collaborative filtering recommender systems. However, there is an incentive for malicious attackers to manipulate the learned preferences, which could affect business decision making, by injecting poisoned data. In the face of such a poisoning attack, while previous works have proposed a number of defense methods succeeding in other machine learning (ML) tasks, little is effective for collaborative filtering (CF). Thereof, we present a new defense scheme called poison-tolerant collaborative filtering (PTCF), which is highly robust against poisoning attacks on collaborative filtering. Different from the defenses that remove outliers or search a min-loss subset, the PTCF scheme enables collaborative filtering on an attacked training dataset while guarantees system's availability and integrity. We evaluate extensively the PTCF scheme on a public dataset (Jester) and two real-world datasets (Movie and E-Shopping), and demonstrate that the PTCF scheme is significantly effective in providing robustness.
Thar Baker, Tong Li 0011, Jingyu Jia, Baolei Zhang, Albert Y. Zomaya
IEEE Trans. Dependable Secur. Comput.2
2024 ABSyn: An Accurate Differentially Private Data Synthesis Scheme With Adaptive Selection and Batch Processes
abstract
In private data publishing, a promising solution is generating synthetic data that enables any query on the private dataset while satisfying differential privacy. Over the past decade, researchers mainly focused on improving the query accuracy of synthetic data. However, the limitations of existing works restrict them from achieving a better trade-off between accuracy and privacy. In this paper, we propose ABSyn, a novel scheme for differentially private data synthesis. Under the Select-Measure-Generate paradigm, ABSyn has an adaptive mechanism for precisely selecting marginals and follows the batch processes. Our adaptive-batch scheme can provide a well-selected marginal set and the optimal allocation of privacy budget, which makes its synthetic data achieve high accuracy without compromising privacy. We implement an efficient prototype of ABSyn and compare it with existing works by analyzing public datasets. Experimental results show that ABSyn achieves query accuracy on synthetic datasets by a factor of$1.26\times $and efficiency by a factor of$18.60\times $over the state-of-the-art scheme on average.
Jingyu Jia, Tong Li 0011, Zhewei Liu, Siyi Lv, Liang Guo 0013, Changyu Dong, Zheli Liu
IEEE Trans. Inf. Forensics Secur.3
2022 Efficient and Secure Outsourcing of Differentially Private Data Publishing With Multiple Evaluators
abstract
Since big data becomes a main impetus to the next generation of IT industry, data privacy has received considerable attention in recent years. To deal with the privacy challenges, differential privacy has been widely discussed and related private mechanisms are proposed as privacy-enhancing techniques. However, with today’s differential privacy techniques, it is difficult to generate a sanitized dataset that can suit every machine learning task. In order to adapt to various tasks and budgets, different kinds of privacy mechanisms have to be implemented, which inevitably incur enormous costs for computation and interaction. To this end, in this article, we propose two novel schemes for outsourcing differential privacy. The first scheme efficiently achieves outsourcing differential privacy by using our preprocessing method and secure building blocks. To support the queries from multiple evaluators, we give the second scheme that employs a trusted execution environment to aggregately implement privacy mechanisms on multiple queries. During data publishing, our proposed schemes allow providers to go off-line after uploading their datasets, so that they achieve a low communication cost which is one of the critical requirements for a practical system. Finally, we report an experimental evaluation on UCI datasets, which confirms the effectiveness of our schemes.
Jin Li 0002, Heng Ye, Tong Li 0011, Wei Wang 0012, Wenjing Lou, Y. Thomas Hou 0001, Jiqiang Liu, Rongxing Lu
IEEE Trans. Dependable Secur. Comput.3
2021 Frequency-Hiding Order-Preserving Encryption with Small Client Storage
abstract
The range query on encrypted databases is usually implemented using the order-preserving encryption (OPE) technique which preserves the order of plaintexts. Since the frequency leakage of plaintexts makes OPE vulnerable to frequency-analyzing attacks, some frequency-hiding order-preserving encryption (FH-OPE) schemes are proposed. However, existing FH-OPE schemes require either the large client storage of size O ( n ) or O (log n ) rounds of interactions for each query, where n is the total number of plaintexts. To this end, we propose a FH-OPE scheme that achieves the small client storage without additional client-server interactions. In detail, our scheme achieves O ( N ) client storage and 1 interaction per query, where N is the number of distinct plaintexts and N ≤ n . Especially, our scheme has a remarkable performance when N ≪ n . Moreover, we design a new coding tree for producing the order-preserving encoding which indicates the order of each ciphertext in the database. The coding strategy of our coding tree ensures that encodings update in the low frequency when inserting new ciphertexts. Experimental results show that the single round interaction and low-frequency encoding updates make our scheme more efficient than previous FH-OPE schemes.
Siyi Lv, Yanyu Huang, Yijing Liu 0007, Tong Li 0011, Zheli Liu, Liang Guo 0013
Proc. VLDB Endow.5
2021 NPMML: A Framework for Non-Interactive Privacy-Preserving Multi-Party Machine Learning
abstract
In the recent decade, deep learning techniques have been widely adopted for founding artificial Intelligent applications, which led to successes in many data analysis tasks, such as risk assessment, medical predictions, and face recognition. Since the effectiveness of deep learning is directly proportional to the amount of data available, a large-scale collection of massive data is essential. Considering privacy and security concerns often prevent data owners from contributing sensitive data for training, researchers proposed several techniques to provide privacy guarantees of data in machine learning systems that contains multiple parties. However, all these works incurred frequent interactions between data owners during training, such that they came at a high communicational cost for data owners. To this end, in this article, we propose a new server-aid framework called non-interactive privacy-preserving multi-party machine learning (NPMML), which supports secure machine learning tasks without the participation of data owners. The NPMML framework significantly reduces data owners’ communicational overheads in multi-party machine learning. Moreover, we design a concrete construction for multi-layer neural networks based on NPMML. Finally, we evaluate the performance of NPMML by prototype implementation. The experimental result demonstrates that NPMML is communicational-efficient for data owners.
Tong Li 0011, Jin Li 0002, Xiaofeng Chen 0001, Zheli Liu, Wenjing Lou, Y. Thomas Hou 0001
IEEE Trans. Dependable Secur. Comput.1
2020 Secure and efficient outsourcing differential privacy data release scheme in Cyber-physical system
Heng Ye, Jiqiang Liu, Wei Wang 0012, Ping Li 0018, Tong Li 0011, Jin Li 0002
Future Gener. Comput. Syst.5
2020 A training-integrity privacy-preserving federated learning scheme with trusted execution environment
Tong Li 0011, Tao Xiang 0001, Zheli Liu, Jin Li 0002
Inf. Sci.3
2019 Data security against receiver corruptions: SOA security for receivers from simulatable DEMs
Zhengan Huang, Junzuo Lai, Wenbin Chen 0003, Tong Li 0011, Yang Xiang 0001
Inf. Sci.4
2019 Communication-efficient outsourced privacy-preserving classification service using trusted processor
Tong Li 0011, Xuan Li 0007, Xingyi Zhong, Nan Jiang 0013, Chong-zhi Gao
Inf. Sci.1
2019 Publicly verifiable privacy-preserving aggregation and its application in IoT
Tong Li 0011, Chong-zhi Gao, Liaoliang Jiang, Witold Pedrycz, Jian Shen 0001
J. Netw. Comput. Appl.1
2019 Dynamic pricing with traffic engineering for adaptive video streaming over software-defined content delivery networking
Pingting Hao, Liang Hu 0001, Kuo Zhao, Jingyan Jiang, Tong Li 0011, Xilong Che
Multim. Tools Appl.5
2019 Secure Deduplication System with Active Key Update and Its Application in IoT
abstract
The rich cloud services in the Internet of Things create certain needs for edge computing, in which devices should be able to handle storage tasks securely, reliably, and efficiently. When processing the storage requests from edge devices, each cloud server is supposed to eliminate duplicate copies of repeating data to reduce the amount of storage space and save on bandwidth. To protect data confidentiality while supporting deduplication, some convergent-encryption-based techniques have been proposed to encrypt the data before uploading. However, all these works cannot meet two requirements while preventing brute-force attacks: (i) power-constrained edge nodes should update encryption keys efficiently when an edge node is abandoned; and (ii) the access privacy of edge nodes should be guaranteed. In this article, we propose a novel encryption scheme for secure chunk-level deduplication. Based on this scheme, we present two constructions of the secure deduplication system that support an efficient key update protocol. The key update protocol does not involve any edge node in computational tasks, so that the deduplication system can adopt an active key update strategy. Moreover, one of our constructions, which is called advance construction, can provide access privacy assurances for edge nodes. The security analysis is given in terms of the proposed threat model. The experimental analysis demonstrates that the proposed deduplication system is practical.
Jin Li 0002, Tong Li 0011, Zheli Liu, Xiaofeng Chen 0001
ACM Trans. Intell. Syst. Technol.2
2019 A countermeasure against cryptographic key leakage in cloud: public-key encryption with continuous leakage and tampering resilience
Chengyu Hu 0001, Rupeng Yang, Pengtao Liu, Tong Li 0011
J. Supercomput.4
2018 Harden Tamper-Proofing to Combat MATE Attack
Chunfu Jia, Tongtong Lv, Tong Li 0011
ICA3PP (4)4
2018 Privacy-preserving machine learning with multiple data providers
Ping Li 0018, Tong Li 0011, Heng Ye, Jin Li 0002, Xiaofeng Chen 0001, Yang Xiang 0001
Future Gener. Comput. Syst.2
2018 Verifiable searchable encryption with aggregate keys for data sharing system
Zheli Liu, Tong Li 0011, Ping Li 0018, Chunfu Jia, Jin Li 0002
Future Gener. Comput. Syst.2
2018 Attribute-based handshake protocol for mobile healthcare social networks
Yi Liu 0029, Hao Wang 0007, Tong Li 0011, Ping Li 0018, Jie Ling 0002
Future Gener. Comput. Syst.3
2018 Differentially private Naive Bayes learning over multiple data sources
Tong Li 0011, Jin Li 0002, Zheli Liu, Ping Li 0018, Chunfu Jia
Inf. Sci.1
2018 Secure data uploading scheme for a smart home system
Jian Shen 0001, Chen Wang 0015, Tong Li 0011, Xiaofeng Chen 0001, Xinyi Huang 0001, Zhi-hui Zhan
Inf. Sci.3
2018 Outsourced privacy-preserving classification service over encrypted data
Tong Li 0011, Zhengan Huang, Ping Li 0018, Zheli Liu, Chunfu Jia
J. Netw. Comput. Appl.1
2018 A Homomorphic Network Coding Signature Scheme for Multiple Sources and its Application in IoT
abstract
As a method for increasing throughput and improving reliability of routing, network coding has been widely used in decentralized IoT systems. When files are shared in the system, network coding signature techniques can help authenticate whether a modified packet in files is injected or not. However, in an IoT system, there are often multiple source devices each of which has its own authentication key, where existing single-source network coding signature schemes cannot work. In this paper, we study the problem of designing secure network coding signatures in the network with multiple sources and propose the multisource homomorphic network coding signature. We also give construction and prove its security.
Tong Li 0011, Wenbin Chen 0003, Yi Tang 0001, Hongyang Yan
Secur. Commun. Networks1
2018 A Novel Security Scheme Based on Instant Encrypted Transmission for Internet of Things
abstract
Internet of Things (IoT) is a research field that has been continuously developed and innovated in recent years and is also an important driving force for the improvement of people’s life in the future. There are lots of scenarios in IoT where we need to collaborate through devices to complete tasks; that is, a device sends data to other devices, and other devices operate on the aid of the data. These transmitted data are often users’ privacy data, such as medical data and grid data. We propose an instant encrypted transmission based security scheme for such scenarios in IoT. The analysis in this paper indicates that our scheme can guarantee the security of users’ data while ensuring rapid transmission and acquisition of instant IoT data.
Chen Wang 0015, Jian Shen 0001, Qi Liu 0001, Yongjun Ren, Tong Li 0011
Secur. Commun. Networks5
2018 GMM and CNN Hybrid Method for Short Utterance Speaker Recognition
abstract
During the last few years, the speaker recognition technique has been widely attractive for its extensive application in many fields, such as speech communications, domestics services, and smart terminals. As a critical method, the Gaussian mixture model (GMM) makes it possible to achieve the recognition capability that is close to the hearing ability of human in a long speech. However, the GMM is failing to recognize a short utterance speaker with a high accuracy. Aiming at solving this problem, in this paper, we propose a novel model to enhance the recognition accuracy of the short utterance speaker recognition system. Different from traditional models based on the GMM, we design a method to train a convolutional neural network to process spectrograms, which can describe speakers better. Thus, the recognition system gains the considerable accuracy as well as the reasonable convergence speed. The experiment results show that our model can help to decrease the equal error rate of the recognition from 4.9% to 2.5%.
Zheli Liu, Zhendong Wu, Tong Li 0011, Jin Li 0002, Chao Shen 0001
IEEE Trans. Ind. Informatics3
2018 Lightweight Cryptographic Techniques for Automotive Cybersecurity
abstract
A new integration of wireless communication technologies into the automobile industry has instigated a momentous research interest in the field of Vehicular Ad Hoc Network (VANET) security. Intelligent Transportation Systems (ITS) are set up, aiming to offer promising applications for efficient and safe communication for future automotive technology. Vehicular networks are unique in terms of characteristics, challenges, architecture, and applications. Consequently, security requirements related to vehicular networks are more complex as compared to mobile networks and conventional wireless networks. This article presents a survey about developments in vehicular networks from the perspective of lightweight cryptographic protocols and privacy preserving algorithms. Unique characteristics of vehicular networks are presented which make the embedded security applications computationally hard as well as memory constrained. The current study also deals with the fundamental security requirements, essential for vehicular communication. Furthermore, awareness of security threats and their cryptographic solutions in terms of future automotive industry are discussed. In addition, asymmetric, symmetric, and lightweight cryptographic solutions are summarized. These strategies can be enhanced or incorporated all in all to meet the security perquisites of future cars security.
Ahmer Khan Jadoon, Licheng Wang 0004, Tong Li 0011, Muhammad Azam Zia
Wirel. Commun. Mob. Comput.3
2018 Anonymous Communication via Anonymous Identity-Based Encryption and Its Application in IoT
abstract
Under the environment of the big data, the correlation between the data makes people have a greater demand for privacy. Moreover, the world has become more diversified and democratic than ever before. Freedom of speech is considered to be very important; thus, anonymity is also a very important security demand. The research of our paper proposes a scheme which can ensure both the privacy and the anonymity of a communication system, that is, the protection of message privacy while ensuring the users’ anonymity. It is based on anonymous identity‐based encryption (IBE), by which the users’ m e t a d a t a are protected. We implement our scheme in JAVA with Java pairing‐based cryptography library (JPBC); the experiment shows that our scheme has significant advantage in efficiency compared with other anonymous communication system. Internet‐of‐Things (IoT) involves many devices, and privacy of devices is very significant. Anonymous communication system provides a secure environment without leaking metadata, which has many application scenarios in IoT.
Liaoliang Jiang, Tong Li 0011, Xuan Li 0007, Mohammed Atiquzzaman, Haseeb Ahmad, Xianmin Wang
Wirel. Commun. Mob. Comput.2
2017 Multi-key privacy-preserving deep learning in cloud computing
Ping Li 0018, Jin Li 0002, Zhengan Huang, Tong Li 0011, Chong-zhi Gao, Siu-Ming Yiu, Kai Chen 0012
Future Gener. Comput. Syst.4
2017 CDPS: A cryptographic data publishing system
Tong Li 0011, Zheli Liu, Jin Li 0002, Chunfu Jia, Kuanching Li
J. Comput. Syst. Sci.1
2017 Privacy-preserving outsourcing of image feature extraction in cloud computing
Ping Li 0018, Tong Li 0011, Zheng-an Yao, Chunming Tang 0003, Jin Li 0002
Soft Comput.2
2016 Verifiable Searchable Encryption with Aggregate Keys for Data Sharing in Outsourcing Storage
Tong Li 0011, Zheli Liu, Ping Li 0018, Chunfu Jia, Zoe Lin Jiang, Jin Li 0002
ACISP (2)1