Fushan Wei

dblp:32/8638 · also Fushan S. Wei · DBLP profile ↗
← Back
37ranked-venue papers
9as first author
11since 2021 · last 2025
0000-0003-2790-7254ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 15 · 1 first-author · 5 since 2021Security and privacy · 11 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 3Systems, architecture and hardware · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 2 first-authorTheory of computation · 2 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 1 since 2021
YearPublicationVenuePosition
2025 DLET-Classifier: A Dynamic and Lightweight Method for Encrypted Traffic Classification
abstract
In recent years, encrypted traffic has become a critical means of ensuring user information security. However, the widespread adoption of encrypted traffic also introduces new challenges, such as enabling attackers to conceal malicious activities within encrypted channels. Consequently, accurate encrypted traffic classification is crucial for strengthening network security defenses. However, encrypted traffic classification methods often employing complex model structures and feature extraction techniques, while neglecting efficiency and latency, which makes them difficult to apply in low-resource scenarios with slow CPU computation speed, limited memory, and a scarce number of training samples. To address these issues, we propose the Dynamic and Lightweight Encrypted Traffic Classifier (DLET-Classifier), which uses the depthwise separable convolutional neural network and the channel attention mechanism to extract features from encrypted traffic. It efficiently captures byte-level features and the relationships between packets for effective classification. To enable the model to update rapidly and adapt to the ever-changing real-world network environment, we propose the Multi2One algorithm. This algorithm first updates the base model, an ensemble of multiple binary classifiers. Then, we use the knowledge distillation technique to transfer knowledge from the base model to a lightweight model. This process allows for model updates and extensions. The results of the multi-class classification comparison experiment show that among all the compared methods, the DLET-Classifier is the model with the smallest number of parameters and the highest throughput, while also achieving excellent classification accuracy. Incremental expansion experiments demonstrate that the Multi2One algorithm enables fast knowledge updates and extensions for the lightweight model (LWG) while maintaining its classification accuracy above 96%, making our method adapt to complex network environments.
Jiayong Wu, Weina Niu, Fushan Wei, Shaofeng Li 0001, Shiping Huang, Jiacheng Gong, Xiaosong Zhang 0001
IEEE Internet Things J.3
2025 Combining model learning and formal analysis: A framework for protocol implementation verification
Fushan Wei, Xieli Zhang, Jiaxing Guo
J. Inf. Secur. Appl.3
2025 A feature vector-based modeling attack method on symmetrical obfuscated interconnection PUF
Huanwei Wang, Fushan Wei, Fagen Li, Jing Jing 0004, Tieming Liu, Wei Liu 0164
J. Inf. Secur. Appl.2
2023 Improved Herrmann-May's Attack with Merging Variables and Lower LLL Bound
Qingfeng Cheng, Chunzhi Zhao, Jinzheng Cao, Fushan Wei
Inscrypt (2)4
2023 Towards Efficient and Privacy-Preserving Anomaly Detection of Blockchain-Based Cryptocurrency Transactions
Yuhan Song, Yuefei Zhu, Fushan Wei
ICICS3
2022 Few-Shot Open-Set Traffic Classification Based on Self-Supervised Learning
abstract
Encrypted traffic classification is a key technology for network monitoring and management, and its recent research results are mostly based on deep learning. Due to the difficulty in obtaining sufficient labeled data, few-shot traffic classification has received considerable attention. However, most of the existing results have two defects. First, they are mostly based on the assumption of a labeled base dataset for pre-training. Second, they neglect the problem of unknown traffic discovery under open-set conditions. In this paper, aiming at the problem of few-shot open-set encrypted traffic classification, a corresponding framework FSOSTC is constructed under the condition of unsupervised pre-training. Two data augmentation methods for packet feature map are proposed to assist the pre-training through self-supervised learning, which is combined with parameter fine-tuning, unknown discovery and class extension strategies. Experiments on public datasets verify the effectiveness of FSOSTC. For the few-shot open-set malicious traffic classification task, the CSA reaches 95.41% and the AUROC reaches 0.8664.
Ji Li 0004, Luan Luan, Fushan Wei, Wenfen Liu
LCN4
2022 Anomaly Detection as a Service: An Outsourced Anomaly Detection Scheme for Blockchain in a Privacy-Preserving Manner
abstract
Attacks against blockchain networks have proliferated in recent years. Due to its immense economic value, Bitcoin has been subject to numerous malicious theft activities through the exchange platforms. This poses a severe threat to the credibility of the entire Bitcoin ecosystem. Therefore, it is necessary to provide detection and prediction services of malicious events for Bitcoin Exchanges to prevent them in a precise and timely manner. Meanwhile, preserving the privacy of transaction data to prevent de-anonymization attacks during the detection process is also of great importance. In this paper, we present a general framework for privacy-preserving anomaly detection in blockchain networks. Based on this framework, we propose ADaaS, an anomaly detection service scheme that adopts a supervised machine learning model and achieves privacy preservation by using vector homomorphic encryption and matrix perturbation strategies. We also analyze the security, communication and computation costs of ADaaS. Experimental results demonstrate that ADaaS can achieve high detection effectiveness while providing privacy guarantees and is applicable in real scenarios of detecting Bitcoin transactions due to its reasonable efficiency.
Yuhan Song, Fushan Wei, Kaijie Zhu, Yuefei Zhu
IEEE Trans. Netw. Serv. Manag.2
2022 Privacy-Preserving Distributed Multi-Task Learning against Inference Attack in Cloud Computing
abstract
Because of the powerful computing and storage capability in cloud computing, machine learning as a service (MLaaS) has recently been valued by the organizations for machine learning training over some related representative datasets. When these datasets are collected from different organizations and have different distributions, multi-task learning (MTL) is usually used to improve the generalization performance by scheduling the related training tasks into the virtual machines in MLaaS and transferring the related knowledge between those tasks. However, because of concerns about privacy breaches (e.g., property inference attack and model inverse attack), organizations cannot directly outsource their training data to MLaaS or share their extracted knowledge in plaintext, especially the organizations in sensitive domains. In this article, we propose a novel privacy-preserving mechanism for distributed MTL, namely NOInfer, to allow several task nodes to train the model locally and transfer their shared knowledge privately. Specifically, we construct a single-server architecture to achieve the private MTL, which protects task nodes’ local data even if n-1 out of n nodes colluded. Then, a new protocol for the Alternating Direction Method of Multipliers (ADMM) is designed to perform the privacy-preserving model training, which resists the inference attack through the intermediate results and ensures that the training efficiency is independent of the number of training samples. When releasing the trained model, we also design a differentially private model releasing mechanism to resist the membership inference attack. Furthermore, we analyze the privacy preservation and efficiency of NOInfer in theory. Finally, we evaluate our NOInfer over two testing datasets and evaluation results demonstrate that NOInfer efficiently and effectively achieves the distributed MTL.
XinDi Ma, Jianfeng Ma 0001, Saru Kumari, Fushan Wei, Mohammad Shojafar, Mamoun Alazab
ACM Trans. Internet Techn.4
2021 Privacy-Preserving Implicit Authentication Protocol Using Cosine Similarity for Internet of Things
abstract
Internet of Things provides complicated value-added services to mobile intelligent terminal users. Different sensors collect various data from the users and transmit the data to the mobile intelligent terminal for storage. Consequently, a great amount of personal and sensitive information related to these rich and colorful applications is stored in the mobile intelligent terminal. Mobile intelligent terminals have become the prominent target of network attackers. Security breach and privacy leakage severely thread the application development of the Internet of Things. We present a privacy-preserving implicit authentication framework using users' behavior features sensed by the mobile intelligent terminal based on the artificial intelligence methodology. More precisely, we first summarize the security and privacy requirements for the security authentication of the mobile intelligent terminal. Then, we present a privacy-preserving implicit authentication framework using the cosine similarity and partial homomorphic public-key encryption scheme. Finally, a performance evaluation of the proposed protocol is conducted. The result shows that the communication and computation efficiency of our protocol is more efficient than other related protocols.
Fushan Wei, Pandi Vijayakumar, Neeraj Kumar 0001, Qingfeng Cheng
IEEE Internet Things J.1
2021 Bitcoin Theft Detection Based on Supervised Machine Learning Algorithms
abstract
Since its inception, Bitcoin has been subject to numerous thefts due to its enormous economic value. Hackers steal Bitcoin wallet keys to transfer Bitcoin from compromised users, causing huge economic losses to victims. To address the security threat of Bitcoin theft, supervised learning methods were used in this study to detect and provide warnings about Bitcoin theft events. To overcome the shortcomings of the existing work, more comprehensive features of Bitcoin transaction data were extracted, the unbalanced dataset was equalized, and five supervised methods—the k-nearest neighbor (KNN), support vector machine (SVM), random forest (RF), adaptive boosting (AdaBoost), and multi-layer perceptron (MLP) techniques—as well as three unsupervised methods—the local outlier factor (LOF), one-class support vector machine (OCSVM), and Mahalanobis distance-based approach (MDB)—were used for detection. The best performer among these algorithms was the RF algorithm, which achieved recall, precision, and F1 values of 95.9%. The experimental results showed that the designed features are more effective than the currently used ones. The results of the supervised methods were significantly better than those of the unsupervised methods, and the results of the supervised methods could be further improved after equalizing the training set.
Binjie Chen, Fushan Wei
Secur. Commun. Networks2
2021 An Intelligent Terminal Based Privacy-Preserving Multi-Modal Implicit Authentication Protocol for Internet of Connected Vehicles
abstract
The Internet of connected Vehicles (IOV) can collect, process, compute and release the information of intelligent transportation systems. IOV is an integrated service system that can support the applications for automatic driving, intelligent transport and information services. As the number of incidents on IOV has been on the rise in the past few years, IOV security is becoming increasingly important in the IOV architecture. One of the most notable risks of IOV faces is intelligent terminal security. The vehicle's intelligent terminal can be used to launch for further attacks on the on-board operating system to penetrate into the internal network of connected vehicle, and consequently threaten the safety of the vehicle. Thus, it is of paramount importance that we protect the security of the intelligent terminal. We propose two intelligent terminal based privacy-preserving multi-modal implicit authentication protocols to protect the security of the intelligent terminal in IOV. The proposed protocols use the password and the vehicle owner's behavior features as the authentication factors to protect the security of the intelligent terminal. Since the vehicle owner's behavior features are sensitive and the privacy information of the user must be protected, we also consider the privacy protection of the behavior features. Our protocols do not reveal any information about the vehicle owner's behavior features to the authentication server and the adversary except the ciphertext size of the feature vector. We analyze the security of our proposed protocol and compare them with other related protocols in terms of computation and communications costs. Our results demonstrate that our proposed protocols yield better security and efficiency.
Fushan Wei, Sherali Zeadally, Pandi Vijayakumar, Neeraj Kumar 0001, Debiao He
IEEE Trans. Intell. Transp. Syst.1
2020 Efficient cloud-aided verifiable secret sharing scheme with batch verification for smart cities
Jian Shen 0001, Dengzhi Liu, Xingming Sun, Fushan Wei, Yang Xiang 0001
Future Gener. Comput. Syst.4
2020 Gateway-oriented two-server password authenticated key exchange protocol for unmanned aerial vehicles in mobile edge computing
abstract
With the popularity of unmanned aerial vehicles (UAVs), more and more valuable data can be collected by UAVs. In order to balance the data usage and communication cost, the data can be preprocessed in UAVs rather than directly transmitting to the data centre in the edge computing paradigm. Users can obtain information of interest by accessing the data centre remotely by authenticating themselves to the data centre using the most pervasive password authentication method. Unfortunately, the data centre becomes the main attack target because it not only stores the data but also maintains the passwords of all the users. Aiming at protecting the data as well as the password in the UAV‐enabled mobile edge computing environment, the authors combine the advantages of gateway‐oriented password authenticated key exchange (PAKE) protocols and two‐server PAKE protocols and put forward an efficient gateway‐oriented two‐server PAKE protocol. The security of the proposed protocol is given in the random oracle model. The performance comparison shows their proposal has comparable efficiency in computation and communication costs. Their protocol provides better protection to the password without sacrificing efficiency. Consequently, their protocol is more suitable for real applications in UAV‐enabled mobile edge computing environment.
Saru Kumari, Mohammad S. Obaidat, Fushan Wei
IET Commun.4
2020 A Mobile Intelligent Terminal Based Anonymous Authenticated Key Exchange Protocol for Roaming Service in Global Mobility Networks
abstract
With the rapid development of mobile intelligent terminals, users can conveniently enjoy ubiquitous services in global mobility networks. User authentication and user privacy protection are two important issues for providing secure roaming service in global mobility networks. Until now, many authentication protocols for roaming service with user anonymity are proposed. Unfortunately, most of the existing protocols only have heuristic informal security arguments. Moreover, current works only achieve weak anonymity. A user's identity is only anonymous against eavesdroppers and is known to the home agent and sometimes even the foreign agent. In order to overcome these weaknesses, we propose a privacy-preserving password-authenticated key exchange protocol for roaming service in global mobility networks. The proposed protocol is proven secure in the random oracle model under the CDH and the q-SDH assumptions. Our protocol achieves stronger user anonymity than other related protocols. The performance comparison shows that our protocol is more efficient in terms of on-line computation and enjoys optimal communication complexity. Consequently, it is more suitable for real applications in global mobility networks.
Fushan Wei, Pandi Vijayakumar, Qi Jiang 0001
IEEE Trans. Sustain. Comput.1
2019 A Survey on Blockchain Anomaly Detection Using Data Mining Techniques
Ji Li 0004, Fushan Wei, Xi Chen 0045
BlockSys3
2018 A general compiler for password-authenticated group key exchange protocol in the standard model
Fushan Wei, Neeraj Kumar 0001, Debiao He, Sang-Soo Yeo
Discret. Appl. Math.1
2018 A Provably Secure Anonymous Two-Factor Authenticated Key Exchange Protocol for Cloud Computing
abstract
Two-factor authenticated key exchange (TFAKE) protocols are critical tools for ensuring identity authentication and secure data transmission for cloud computing. Until now, numerous TFAKE protocols based on smart cards and passwords are proposed under this circumstance. Unfortunately, most of them are found insecure against various attacks. Researchers focus on cryptanalysis of these protocols and then fixing the loopholes. Little attention has been paid to design rationales and formal security models of these protocols. In this paper, we summarize the security requirements and put forward a formal security model for TFAKE protocols for cloud computing. We then present an efficient TFAKE protocol without using expensive asymmetric cryptology mechanisms to achieve high efficiency. Our protocol can be proven secure in the random oracle model and achieves user anonymity. Compared with other TFAKE protocols, our protocol is more efficient and enjoys provable security.
Fushan Wei, Chuangui Ma
Fundam. Informaticae1
2018 Privacy-Preserving and Lightweight Key Agreement Protocol for V2G in the Social Internet of Things
abstract
The concept of the Social Internet of Things (SIoT) can be viewed as the integration of prevailing social networking and the Internet of Things, which is making inroads into the daily operation of many industries. Smart grids, which are cost-effective and environmentally friendly applications, are a promising field of the SIoT. However, security and privacy concerns are the dark aspects of smart grids. The goal of this paper is to address the security and privacy issues in the vehicle-togrid (V2G) networks with the intention of promoting a more extensive deployment of V2G networks for smart grids. Driven by this motivation, in this paper, we propose a robust key agreement protocol that can achieve mutual authentication without exposing the real identities of users. Efficiency is also a major concern in resource-constrained environments. By leveraging only hash functions and bitwise exclusive-OR operations, the proposed protocol is highly efficient compared with pairing-based protocols. In addition, we define a formal security model for our privacy-preserving key agreement protocol for V2G networks. Using this model, a formal security analysis shows that the proposed protocol is secure. Moreover, an informal security analysis demonstrates that our protocol can withstand different types of attacks.
Jian Shen 0001, Tianqi Zhou, Fushan Wei, Xingming Sun, Yang Xiang 0001
IEEE Internet Things J.3
2018 VMKDO: Verifiable multi-keyword search over encrypted cloud data for dynamic data-owner
Yinbin Miao, Jianfeng Ma 0001, Ximeng Liu, Zhiquan Liu 0001, Fushan Wei
Peer-to-Peer Netw. Appl.6
2018 DOAS: Efficient data owner authorized search over encrypted cloud data
Yinbin Miao, Jianfeng Ma 0001, Ximeng Liu, Zhiquan Liu 0001, Junwei Zhang 0001, Fushan Wei
Peer-to-Peer Netw. Appl.6
2018 Cryptanalysis and Security Enhancement of Three Authentication Schemes in Wireless Sensor Networks
abstract
Nowadays wireless sensor networks (WSNs) have drawn great attention from both industrial world and academic community. To facilitate real‐time data access for external users from the sensor nodes directly, password‐based authentication has become the prevalent authentication mechanism in the past decades. In this work, we investigate three foremost protocols in the area of password‐based user authentication scheme for WSNs. Firstly, we analyze an efficient and anonymous protocol and demonstrate that though this protocol is equipped with a formal proof, it actually has several security loopholes been overlooked, such that it cannot resist against smart card loss attack and violate forward secrecy. Secondly, we scrutinize a lightweight protocol and point out that it cannot achieve the claimed security goal of forward secrecy, as well as suffering from user anonymity violation attack and offline password guessing attack. Thirdly, we find that an anonymous scheme fails to preserve two critical properties of forward secrecy and user friendliness. In addition, by adopting the “perfect forward secrecy (PFS)” principle, we provide several effective countermeasures to remedy the identified weaknesses. To test the necessity and effectiveness of our suggestions, we conduct a comparison of 10 representative schemes in terms of the underlying cryptographic primitives used for realizing forward secrecy.
Wenting Li 0002, Ping Wang 0003, Fushan Wei
Wirel. Commun. Mob. Comput.5
2018 A Provably Secure Anonymous Authenticated Key Exchange Protocol Based on ECC for Wireless Sensor Networks
abstract
In wireless sensor networks, users sometimes need to retrieve real‐time data directly from the sensor nodes. Many authentication protocols are proposed to address the security and privacy aspects of this scenario. However, these protocols still have security loopholes and fail to provide strong user anonymity. In order to overcome these shortcomings, we propose an anonymous authenticated key exchange protocol based on Elliptic Curves Cryptography (ECC). The novel protocol provides strong user anonymity such that even the gateway node and the sensor nodes do not know the real identity of the user. The security of the proposed protocol is conducted in a well‐defined security model under the CDH assumption. Compared with other related protocols, our protocol is efficient in terms of communication and enjoys stronger security. The only disadvantage is that our protocol consumes more computation resources due to the usage of asymmetric cryptography mechanisms to realize strong anonymity. Consequently, our protocol is suitable for applications which require strong anonymity and high security in wireless sensor networks.
Ke Zhang 0007, Fushan Wei
Wirel. Commun. Mob. Comput.3
2017 Improved Cryptanalysis of an ISO Standard Lightweight Block Cipher with Refined MILP Modelling
Chuyan Ma, Lijun Lyu, Jian Song 0001, Chuangui Ma, Fushan Wei
Inscrypt7
2017 Medical image classification based on multi-scale non-negative sparse coding
Jian Shen 0001, Fushan Wei, Xiong Li 0002, Arun Kumar Sangaiah
Artif. Intell. Medicine3
2017 An efficient and practical threshold gateway-oriented password-authenticated key exchange protocol in the standard model
Fushan Wei, Jianfeng Ma 0001, Chuangui Ma, Xu An Wang 0014
Sci. China Inf. Sci.1
2017 A Secure and Efficient ID-Based Aggregate Signature Scheme for Wireless Sensor Networks
abstract
Affording secure and efficient big data aggregation methods is very attractive in the field of wireless sensor networks (WSNs) research. In real settings, the WSNs have been broadly applied, such as target tracking and environment remote monitoring. However, data can be easily compromised by a vast of attacks, such as data interception and data tampering, etc. In this paper, we mainly focus on data integrity protection, give an identity-based aggregate signature (IBAS) scheme with a designated verifier for WSNs. According to the advantage of aggregate signatures, our scheme not only can keep data integrity, but also can reduce bandwidth and storage cost for WSNs. Furthermore, the security of our IBAS scheme is rigorously presented based on the computational Diffie-Hellman assumption in random oracle model.
Jianfeng Ma 0001, Ximeng Liu, Fushan Wei, Meixia Miao
IEEE Internet Things J.4
2017 VCSE: Verifiable conjunctive keywords search over encrypted data without secure-channel
Yinbin Miao, Jianfeng Ma 0001, Fushan Wei, Zhiquan Liu 0001, Xu An Wang 0014, Cunbo Lu
Peer-to-Peer Netw. Appl.3
2017 Secure and efficient ECC speeding up algorithms for wireless sensor networks
Yunqi Dou, Jiang Weng, Chuangui Ma, Fushan Wei
Soft Comput.4
2016 An untraceable temporal-credential-based two-factor authentication scheme using ECC for wireless sensor networks
Qi Jiang 0001, Jianfeng Ma 0001, Fushan Wei, Youliang Tian, Jian Shen 0001
J. Netw. Comput. Appl.3
2015 A Lightweight Anonymous Authentication Protocol Using k-Pseudonym Set in Wireless Networks
abstract
In recent years, since people pay more and more attention to the protection of their privacy, anonymous authentication in wireless networks has become a hot topic. Currently, most anonymous authentication schemes are based on the asymmetric keys whose tedious computation leads to serious resource consumption, therefore, they are unsuitable for mobile devices with limited capacity. To solve this problem, by introducing the k-pseudonym set we propose an anonymous authentication protocol based on a shared secret key. In the authentication process, the user sends the k- pseudonym set which includes his real identity and other k-1 pseudonyms. After the authentication server traversals the shared keys with each of the users in the set and verifies the authentication information, it can determine the real user and complete the authentication. In this methodology, the construction of the pseudonym set is a key issue, and we give two attack models and respectively present the construction methods of the k-pseudonym set under those two models. Compared with the existing schemes, our scheme outperforms them in the security and practicality. Especially, user untractability can be realized. A testbed is set up and extensive experiments are conducted, and the results show the authentication latency of our scheme is short and it changes a little with the increase of k.
Xinghua Li 0001, Hai Liu 0011, Fushan Wei, Jianfeng Ma 0001, Weidong Yang 0002
GLOBECOM3
2015 Strongly Secure Key Exchange Protocol with Minimal KEM
Baoping Tian, Fushan Wei, Chuangui Ma
ISPEC2
2014 Certificateless Non-Interactive Key Exchange Protocol without Pairings
Fushan Wei, Chuangui Ma
SECRYPT2
2014 E2LSH based multiple kernel approach for object detection
Fushan Wei, Bicheng Li
Neurocomputing2
2012 Gateway-oriented password-authenticated key exchange protocol in the standard model
Fushan Wei, Zhenfeng Zhang, Chuangui Ma
J. Syst. Softw.1
2012 Corrigendum to "Gateway-oriented password-authenticated key exchange protocol in the standard model" [J. Syst. Softw. 85 (March (3)) (2012) 760-768]
Fushan Wei, Zhenfeng Zhang, Chuangui Ma
J. Syst. Softw.1
2011 Gateway-Oriented Password-Authenticated Key Exchange Protocol with Stronger Security
Fushan Wei, Chuangui Ma, Zhenfeng Zhang
ProvSec1
2010 Multi-Factor Authenticated Key Exchange Protocol in the Three-Party Setting
Fushan Wei, Chuangui Ma
Inscrypt2