Jie Huang 0016

dblp:29/6643-16 · DBLP profile ↗
← Back
28ranked-venue papers
1as first author
24since 2021 · last 2026
0000-0002-8011-5603ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 7 since 2021Security and privacy · 9 · 1 first-author · 7 since 2021Systems, architecture and hardware · 3 · 3 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Theoretical Explanation and Upper Boundary of Model Extraction Attacks
Chuang Liang, Jie Huang 0016, Chunyang Qi
ICC2
2026 Enhancing AKA protocol with radio frequency fingerprint for 5G network cross-layer authentication
Jie Huang 0016, Hebing Wang, Chunyang Qi
Comput. Secur.2
2026 MDV: Resolving the Auxiliary Data Dilemma in Model Extraction Defenses
abstract
Current studies have discovered that model extraction attacks (MEA) can steal the functionality of deep learning (DL) models, thus causing economic loss and other security threats. Extraction attackers can build a clone model locally that has a different structure but similar functionality to the victim model. To counter MEA, defenders utilize realistic auxiliary data to enhance the victim model and produce misleading predictions for attack data. However, these defense methods have three critical problems caused by utilizing realistic auxiliary data. First, in some scenarios, realistic auxiliary data is absent and difficult to obtain. Secondly, the defense effectiveness brought by realistic auxiliary data is unstable. Finally, the realistic auxiliary data did not protect all categories of training data, resulting in higher clone accuracy for some categories. To address these issues, we propose Model Defense Variational Autoencoder (MDV) to generate virtual auxiliary data as a replacement for realistic auxiliary data. MDV combines the Variational Autoencoder (VAE) and classifier, compelling the latent features to obey different multivariate Gaussian distributions according to the categories. Then, MDV samples deep features from low-likelihood regions of different distributions as realistic auxiliary data. During the experimental phase, we apply our auxiliary data to different defense methods that use auxiliary data and compare the defense effects in different scenarios. Experimental results demonstrate that our method effectively addressed the three aforementioned issues.
Chuang Liang, Jie Huang 0016, Zeping Zhang
IEEE Trans. Inf. Forensics Secur.2
2026 Enhancing RAFT Consensus With Network Reliability in Permissioned Blockchains
abstract
Driven by distributed computing, blockchain and large language model, etc., computational tasks are gradually shifting from centralized simple tasks to decentralized complex tasks. In a decentralized task scenario, all the participants are on an equal footing. Determining whether the participating parties are trustworthy, and reaching a credible consensus in situations where untrustworthy parties exist, has always been a tricky issue. To address this issue, we utilize the reliability of the network to enhance the RAFT algorithm and put forward a novel consensus algorithm NR-RAFT. In NR-RAFT, we integrate node reliability and link reliability to quantitatively evaluate the reliability of consensus results, which is called consensus reliability. Specifically, the reliability of nodes depends on their reputation and the reliability of links that are connected to them. We achieve the evaluation by running an improved ET algorithm and a packet statistics-based approach, respectively. Furthermore, we introduce a “maximum reliability election principle” to avoid the conflicts in the process of leader election. To improve the reliability and efficiency of consensus, we select the highly trustworthy members in the network to form the consensus committee and introduce a salp swarm algorithm-based member optimization method to provide flexibility in the composition of the committee and protection against targeted attacks by malicious nodes. Finally, the experimental results prove the effectiveness of NR-RAFT.
Jie Huang 0016
IEEE Trans. Reliab.2
2025 Semantic Heat Guided Relational Privacy Inference Based on Panoptic Scene Graph
abstract
Privacy is a subjective concept that depends on human perception and contextual interpretation, based on interaction between subject and object. With the increasing occurrence of privacy leaking incidents, awareness about implicit risks has been evolving. The leakage and misuse of relational information between critical objects emerge as core issues in such security events, defined in this study as “relational privacy”. In images, relational privacy primarily manifests through semantic relations between object pairs. To identify pairs with higher privacy potential, we propose the concept of “semantic heat”. To ensure interpretability and avoid rigid logical judgments, Probabilistic Soft Logic (PSL) is employed to construct semantic heat levels. Scene graph, providing structured semantic representations of image contents, is highly suitable for investigating relational privacy. We utilize panoptic scene graphs to mitigate noise introduced by traditional bounding boxes and leverage contextual information between object pairs. Additionally, a mask crossattention mechanism guided by textual instruction is proposed to extract interactive features between objects effectively. Finally, a two-stage relation decoder based on a Large Multi-modal Model (LMM) is designed to perform open-set relation prediction and strength judgment. Experimental results demonstrated that the proposed method achieved performance close to the state-of-theart and showed certain advantages in recall rate, enabling a more comprehensive detection of relational privacy.
Jie Huang 0016, Changhao Ding, Zeping Zhang
RAID2
2025 A Novel Access Control and Privacy-Enhancing Approach for Models in Edge Computing
abstract
With the widespread adoption of edge computing technologies and the increasing prevalence of deep learning models in these environments, the security risks and privacy threats to models and data have grown more acute. Attackers can exploit various techniques to illegally obtain models or misuse data, leading to serious issues such as intellectual property infringement and privacy breaches. Existing model access control technologies primarily rely on traditional encryption and authentication methods; however, these approaches exhibit significant limitations in terms of flexibility and adaptability in dynamic environments. Although there have been advancements in model watermarking techniques for marking model ownership, they remain limited in their ability to proactively protect intellectual property and prevent unauthorized access. To address these challenges, we propose a novel model access control method tailored for edge computing environments. This method leverages image style as a licensing mechanism, embedding style recognition into the model's operational framework to enable intrinsic access control. Consequently, models deployed on edge platforms are designed to correctly infer only on license data with specific style, rendering them ineffective on any other data. By restricting the input data to the edge model, this approach not only prevents attackers from gaining unauthorized access to the model but also enhances the privacy of data on terminal devices. We conducted extensive experiments on benchmark datasets, including MNIST, CIFAR-10, and FACESCRUB, and the results demonstrate that our method effectively prevents unauthorized access to the model while maintaining accuracy. Additionally, the model shows strong resistance against attacks such as forged licenses and fine-tuning. These results underscore the method's usability, security, and robustness.
Peihao Li 0002, Jie Huang 0016
WCNC2
2025 BAT-CA: A Blockchain-Based Anonymous and Traceable Cross-Domain Authentication Approach for Interner of Things
abstract
With the growing interconnectivity in Internet of Things (IoT) fields like smart home, smart city, and Internet of Vehicles (IoV), the need for secure cross-domain authentication is crucial. Existing methods face issues such as centralized control, high overhead, and lack of anonymity and traceability. To address these issues, we propose BAT-CA, a blockchain-based crossdomain authentication solution. BAT-CA utilizes a consortium blockchain for decentralized authentication, leveraging public key hash addresses for anonymity and traceability. This approach includes intra-domain and cross-domain authentication methods tailored for devices within domains and across domains. Intradomain authentication leverages Schnorr signatures to incorporate domain node endorsement proofs for secure and efficient authentication. For cross-domain authentication, a transaction token based on blockchain transaction structures is designed, combining distributed key generation and aggregated threshold signatures. Device real IDs are encrypted and stored on the blockchain, enabling anonymous device traceability through decrypted fragments collected from domain node voting. A series of experiments in physical environments validate the effectiveness and efficiency of the proposed approach.
Jie Huang 0016, Peihao Li 0002
WCNC2
2025 DynaTrac: A Decentralized Cross-Domain Authentication Framework With Dynamic Reputation Weighting and Accountable Tracing
abstract
The rapid growth of Internet of Things (IoT) boosts device connectivity but complicates cross-domain interoperability. Centralized authentication faces single-point failures, while blockchain’s decentralized, tamper-resistant nature overcomes these limits. Current work optimizes blockchain-based cross-domain authentication efficiency and user privacy, yet IoT’s dynamic environments require tailored mechanisms. To tackle these issues, we designed a decentralized cross-domain authentication framework, DynaTrac, with dynamic reputation weighting and accountable tracing mechanisms. DynaTrac uses Distributed Key Generation (DKG) and Aggregate Threshold Signatures (ATS) protocols to generate shared keys and signatures, avoiding the involvement of trusted third parties. In order to adapt the mobility of the device, we design a dynamic reputation-weighted DKG-ATS protocol to cope with the frequent entry and exit of IoT devices. This protocol dynamically adjusts the reputation and weights of the nodes based on behavioral metrics. The updated reputation weights govern nodes’ participation shares in key negotiation and authentication processes, effectively minimizing disruptions caused by low-weight devices. The framework employs authentication tokens, which are inspired by blockchain transaction structures, to enable efficient cross-domain verification. Additionally, a signature-based traceability mechanism embeds traceable tags into threshold signatures to ensure node anonymity during normal operations while enabling the identification of malicious behaviors. Finally, security analysis and simulation experiments validate the effectiveness of DynaTrac.
Jie Huang 0016
IEEE Internet Things J.2
2025 LicenseNet: Proactively safeguarding intellectual property of AI models through model license
Peihao Li 0002, Jie Huang 0016
J. Syst. Archit.2
2025 Analyze and Improve Differentially Private Federated Learning: A Model Robustness Perspective
abstract
Differentially Private Federated learning (DPFL) applies differential privacy (DP) techniques to preserve clients’ privacy in Federated Learning (FL). Existing methods based on Gaussian Mechanism require the operations of model updates clipping and noise injection, which lead to a serious degradation in model accuracies. Several improved methods are proposed to mitigate the accuracy degradation by decreasing the scale of the injected noise. Different from previous methods, we firstly propose to enhance the model robustness against the DP noise for the accuracy improvement. In this paper, we develop a novel FL scheme with improved model robustness, called FedIMR, which can provide the client-level DP guarantee while maintaining a high model accuracy. We find that the injected noise leads to the fluctuation of loss values in the local training, hindering the model convergence seriously. This motivates us to improve the model robustness for narrowing down the bias of model outputs caused by the noise. The model robustness is evaluated with the signal-to-noise ratio (SNR) of each layer’s outputs. Two techniques are proposed to improve the output SNR, including the logit vector normalization (LVN) and dynamic clipping threshold (DCT). Specifically, LVN normalizes the logit vertor to make the optimization algorithm keep increasing the model output, which is the signal item of the output SNR. DCT dynamically adjusts the clipping threshold to reduce the noise item of the output SNR. We also provide the privacy analysis and convergence results. Experiments are conducted over three famous datasets to evaluate the effectiveness of our method. Both the theoretical results and empirical experiments confirm that our FedIMR can achieve a better accuracy-privacy tradeoff than previous methods.
Jie Huang 0016, Peihao Li 0002
IEEE Trans. Inf. Forensics Secur.2
2024 Proactive Privacy and Intellectual Property Protection of Multimedia Retrieval Models in Edge Intelligence
abstract
Edge intelligence can significantly enhance the real-time performance and robustness of multimedia retrieval. However, its privacy and intellectual property security face various challenges. In this paper, we propose a model training framework based on the gradient optimization concept, synchronously optimizing model parameters and model license. This approach ensures that the trained model only correctly retrieves information for inputs containing the correct license, actively protecting its intellectual property by restricting its usability. Additionally, we devise a data irreversibility standardization method based on random perturbation to safeguard the privacy of both data and license. We conduct extensive experiments in edge intelligence scenarios, and the results demonstrate that, compared to the state-of-the-art approaches in this field, our method achieves accuracy closer to the baseline model. The injected license are more covertly secured, and the anti-fine-tuning capability is improved by an average of more than 25.1%.
Peihao Li 0002, Jie Huang 0016, Chunyang Qi
ICMR2
2024 Proactive Intellectual Property Protection for Edge AI Models
Peihao Li 0002, Jie Huang 0016, Chunyang Qi
NPC (2)2
2024 Attack Data is Not Solely Paramount: A Universal Model Extraction Enhancement Method
abstract
Model extraction (ME) attacks, aiming to steal the functionality or parameters of the victim model, have become a widespread research topic. Most functional ME attack methodologies follow a uniform framework, which we summarize in three steps: initially choosing appropriate attack data, then querying the victim model with this data, and finally, training an incipient clone model based on the victim model’s outputs. Despite much focus on data selection, the latter two steps have been somewhat neglected. Noticing this, we explore a method for the information of attack data labels to enhance the accuracy of the clone model. Specifically, we utilized the incipient clone model to identify similarities between the leaked private data and the attack data, subsequently appending the labels from the leaked data to those of the attack data. Then, we employed these modified attack data labels to fine-tune the incipient clone model, obtaining an enhanced clone model with higher accuracy. The enhancement was applied to three representative ME attack methodologies that primarily focus on the first step. Results show that the enhanced model reveals a higher accuracy than the three basic attacks. In summary, our approach suggests that future research should extend beyond data selection.
Chuang Liang, Jie Huang 0016
TrustCom2
2024 SecureEI: Proactive intellectual property protection of AI models for edge intelligence
Peihao Li 0002, Jie Huang 0016, Chunyang Qi
Comput. Networks2
2024 Defending against model extraction attacks with OOD feature learning and decision boundary confusion
Chuang Liang, Jie Huang 0016, Zeping Zhang
Comput. Secur.2
2024 Differentially private federated learning with local momentum updates and gradients filtering
Jie Huang 0016, Peihao Li 0002, Chuang Liang
Inf. Sci.2
2024 SecureNet: Proactive intellectual property protection and model security defense for DNNs based on backdoor learning
Peihao Li 0002, Jie Huang 0016, Huaqing Wu, Zeping Zhang, Chunyang Qi
Neural Networks2
2024 Aligning the domains in cross domain model inversion attack
Zeping Zhang, Jie Huang 0016
Neural Networks2
2023 BGET: A Blockchain-Based Grouping-EigenTrust Reputation Management Approach for P2P Networks
Jie Huang 0016, Sirui Zhou, Zixuan Ju, Peihao Li 0002
CollaborateCom (1)2
2023 Compromise privacy in large-batch Federated Learning via model poisoning
Jie Huang 0016, Zeping Zhang, Peihao Li 0002, Chunyang Qi
Inf. Sci.2
2023 Analysis and Utilization of Hidden Information in Model Inversion Attacks
abstract
The widely applications of deep learning have raised concerns about the privacy issues in deep neural networks. Model inversion attack aims to reconstruct specific details of each private training sample from a given neural network. However, limited to the availability of useful information, reconstructing distinctive private training samples still has a long way to go. In this paper, the requirements to reconstruct distinctive private training samples are investigated using information entropy. We find that more information is needed to reconstruct distinctive samples and propose to use the often ignored hidden information to achieve this goal. To better utilize this information, Amplified-MIA is proposed. In Amplified-MIA, a nonlinear amplification layer is inserted between the target network and the attack network. This nonlinear amplification layer further contains a nonlinear amplification function. The definition of the nonlinear amplification function is given and the effect of this nonlinear amplification function on the entropy of the hidden information is derived. The proposed nonlinear amplification function can amplify the small prediction vector entries and enlarge the differences between different prediction vectors in the same class. Thus, the hidden information can be better utilized by the attack network and distinctive private samples can be reconstructed. Various experiments are performed to empirically analyze the effects of the nonlinear amplification function on the reconstruction results. The reconstruction results on three different datasets show that the proposed Amplified-MIA outperforms existing works on almost all tasks. Especially, it achieves up to 68% performance gain of the Pixel Accuracy score over the direct inversion method on the hardest face reconstruction task.
Zeping Zhang, Jie Huang 0016
IEEE Trans. Inf. Forensics Secur.3
2022 Defending Against DDOS Attacks on IoT Network Throughput: A Trust-Stackelberg Game Model
abstract
IoTs generally rely on resource-constrained devices to sense, relay, and collect data, which are highly vulnerable to Distributed-Denial-of-Services (DDOS) attacks on network throughput. In this paper, we propose a trust-based method to optimize the network throughput of IoTs under DDOS attacks. Specifically, with the assistance of a small number of dedicatedly deployed defense nodes as defenders, a network controller can first measure the behavior of other IoT nodes and categorize them into three types (i.e., innocent, selfish, and attack) through a well-designed trust evaluation model. Then, a Stackelberg game model is constructed accordingly, where defenders are leaders and other nodes are followers. We carefully define the utilities of the leaders and the followers in the game, and transform the optimization problem of the network throughput into the maximization problem of the defenders' utilities considering the utilities of the followers. We adopt the Dinkelbach Programming (DP)-based algorithm to solve the maximization problem such that a Stackelberg equilibrium can be reached with optimized network throughput. Extensive simulations are performed to demonstrate that the proposed defense method can significantly increase the IoT network throughput under different DDOS attack intensities.
Chunyang Qi, Jie Huang 0016, Cheng Huang 0001, Huaqing Wu, Xuemin Shen
GLOBECOM2
2022 Compromise Privacy in Large-Batch Federated Learning via Malicious Model Parameters
Jie Huang 0016, Zeping Zhang, Chunyang Qi
ICA3PP2
2021 A Novel Privacy-Preserving Mobile-Coverage Scheme Based on Trustworthiness in HWSNs
abstract
To solve the problem of security deployment in a hybrid wireless sensor network, a novel privacy‐preserving mobile coverage scheme based on trustworthiness is proposed. The novel scheme can efficiently mitigate some malicious attacks such as eavesdropping and pollution and optimize the coverage of hybrid wireless sensor networks (HWSNs) at the same time. Compared with the traditional mobile coverage scheme, the security of data transmission and mobility are considered in the deployment of HWSNs. Firstly, our scheme can mitigate the eavesdropping attacks efficiently utilizing privacy‐preserving signature. Then, the trust mobile protocol based on the trustworthiness is used to defend the pollution attacks and improve the security of mobility. In privacy‐preserving signature, the hardness of discrete logarithm determines the degree of security of the privacy‐preserving signature. The correctness and effectiveness of signature algorithm are proven by the probabilities of the native messages which can be recovered and forged which is negligible. Furthermore, a mobile scheme based on the trustworthiness (MSTW) is proposed to optimize the network coverage and improve the security of mobility. Finally, the simulation compared with a previous algorithm is carried out, in which the communication overhead, computational complexity, and the coverage are given. The result of the simulation shows that our scheme has roughly the same network coverage as the previous schemes on the basis of ensuring the security of the data transmission and mobility.
Chunyang Qi, Jie Huang 0016, Bin Wang 0062
Wirel. Commun. Mob. Comput.2
2020 Universal resource allocation framework for preventing pollution attacks in network-coded wireless mesh networks
Xiang Liu 0004, Teng Joon Lim, Jie Huang 0016
Ad Hoc Networks3
2020 Defending pollution attacks in network coding enabled wireless ad hoc networks: a game-theoretic framework
abstract
Network coding is a promising technique to improve the throughput and robustness of wireless ad hoc networks. However, the packet‐mixing nature of network coding also renders it more prone to pollution attacks. Most existing schemes to combat pollution attacks did not consider the defender's resource limit, nor the trade‐off between defensive performance and other metrics such as delay and resource consumption. The authors investigate how to achieve such a trade‐off optimally by proposing a two‐player strategic game model between the attack and the defender. In this model, the utilities of both players are well defined, and thus the defender can obtain its best strategy by maximising its utility. To do so, a graph‐based simulated annealing algorithm is proposed to derive the utility‐maximising strategy. Finally, they conduct extensive experiments to evaluate their scheme from different aspects. The results show that their scheme can achieve better utility than existing schemes, and is more computationally efficient in the meanwhile. Moreover, their scheme can obtain a sub‐optimal solution within a small number of iterations, which implies that it can be implemented in the short‐session communication scenario where it is required to find a sufficiently good solution within a short time.
Xiang Liu 0004, Jie Huang 0016, Yiyang Yao, Chunyang Qi, Guowen Zong
IET Commun.2
2020 Optimal Byzantine Attacker Identification Based on Game Theory in Network Coding Enabled Wireless Ad Hoc Networks
abstract
Byzantine attack is a severe security concern in network coding enabled wireless ad hoc networks, because the malicious nodes can easily inject bogus packets into the information flow and cause an epidemic propagation of pollution. In this paper, we address the Byzantine attack by proposing a malicious node identification scheme, which can achieve a high identification accuracy on malicious nodes and protect the benign nodes from being mis-identified as attackers. We consider two practical challenges, namely, 1) only a fraction of the intermediate nodes can be deployed as defenders; and 2) the malicious nodes are intelligent-they pretend to be legitimate nodes probabilistically to reduce the chances of being identified. Theoretical analysis and extensive simulations show that our scheme performs well even under the conditions mentioned above. Furthermore, we conduct a series of comparisons between our scheme and several existing schemes, which show that our scheme outperforms them in both identification accuracy and valid throughput during the identification procedure. Finally, we present a two-player game theory framework to find the optimal strategy for the defender, and also provide a case study of the defender's strategy optimization.
Xiang Liu 0004, Teng Joon Lim, Jie Huang 0016
IEEE Trans. Inf. Forensics Secur.3
2014 A security key distribution scheme based on energy efficiency for hybrid wireless sensor networks
abstract
ABSTRACT In wireless sensor networks (WSNs), due to low cost, limited resource, and large scale, symmetric key‐based key pre‐distribution schemes are considered to be very suitable, but they cannot thoroughly solve authentication problem and resilience problem against physical capture. So, some researchers attempt to improve the traditional public‐key cryptography to meet security requirements of the WSNs. In this paper, at first, to create the hybrid network model, the number range of cluster heads is determined according to the change of the average path length with the probability that the nodes are selected as the cluster heads. Next, based on the characteristics of the hybrid WSNs, a novel security mechanism is proposed by making use of the advantages of the symmetric cryptography and asymmetric cryptography. Our scheme can provide different security mechanism for the vital link and the ordinary link, respectively. In order to balance the energy consumption over all nodes, a selecting cluster head algorithm is proposed to rotate periodically cluster heads among all nodes and to compute the optimal number of times transmitting data per round. At last, our experiment shows that our scheme not only can provide sufficient security but also have the lowest energy overhead and the perfect connectivity. Copyright © 2013 John Wiley & Sons, Ltd.
Jie Huang 0016, Bei Huang
Secur. Commun. Networks1