Chengjie Gu

dblp:36/8599 · DBLP profile ↗
← Back
27ranked-venue papers
1as first author
26since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 11 · 11 since 2021Security and privacy · 6 · 6 since 2021Systems, architecture and hardware · 4 · 4 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Cloud Data Sharing System With Enhanced Effectiveness for Flexible User Revocation
abstract
Attribute revocation is a secure data-sharing system that allows user revocation of shared data. The most effective attribute revocation scheme is still less effective in the revocation process. When revoking a user's access rights to a specified ciphertext, both that ciphertext and the keys of all other users must be updated. Similarly, when revoking a user from accessing all ciphertexts, all ciphertexts related to the revoked user and the keys of all non-revoked users must be updated, with computational cost linear to the number of attributes associated with the revoked user. In this work, to enhance the effectiveness of revocation, we design a cloud data-sharing system that supports flexible revocation. By introducing edge-server-assisted key puncturing techniques, our approach eliminates the need to update ciphertext and other users' keys when revoking a user's access rights to a specific ciphertext. Additionally, we leverage key splitting technology to divide data users' permissions between the data owner and the authority, ensuring that the update overhead for non-revoked users remains constant when revoking a user's access to all ciphertexts. On resource-constrained devices, when involving 50 attributes, non-revoked users only need approximately 0.02 milliseconds to update their keys, resulting in a 25x improvement in update speed.
Hong Zhong 0001, Jie Cui 0004, Chengjie Gu, Debiao He
IEEE Trans. Dependable Secur. Comput.4
2026 Generative Image Steganography With Minimum-Distance Guidance
abstract
Image steganography conceals secret data within a digital image while preserving its innocent appearance. The advent of artificial intelligence generative models has given rise to a new paradigm known as generative image steganography, which hides secret data directly into the image generation process. However, existing generative image steganographic methods are typically only applicable to unquantized stego images, severely limiting their practicality in real-world scenarios. To address this limitation, we propose a generative image steganography with minimum-distance guidance based on a diffusion model, called MDStega. During the hiding phase, MDStega designs a secret data-driven residual image sampling mechanism, which establishes a dynamic mapping relationship between discrete secret data and continuous probability distributions, strictly preserving the distribution consistency between stego images and normally generated images. During the extraction phase, the minimum-distance guidance rule effectively suppresses the interference caused by stego image quantization on the extraction accuracy of secret data. Furthermore, MDStega does not require fine-tuning pre-trained models or training additional models, which significantly reduces computational overhead and training time. Experimental results demonstrate that MDStega is superior to state-of-the-art methods by not only ensuring secure concealment at 3 bits per pixel (bpp) in PNG format but also achieving a recovery accuracy of up to 99%, demonstrating strong practical potential.
Yinyin Peng, Chengjie Gu, Donghui Hu, Yaofei Wang, Xianjin Rong, Zhao-Xia Yin
IEEE Trans. Dependable Secur. Comput.2
2025 Visible-thermal multiple object tracking: Large-scale video dataset and progressive fusion approach
Yabin Zhu, Qianwu Wang, Chenglong Li 0002, Jin Tang 0001, Chengjie Gu, Zhixiang Huang
Pattern Recognit.5
2025 LSHSC: Lightweight and Secure Handover Scheme With Conditional Privacy-Preserving for Group-Based SDVN
abstract
Introducing the SDN paradigm can further improve the handover efficiency of mobile nodes, and researchers have proposed corresponding solutions to the security problems in the handover process. Some existing cryptography-based schemes delegate authentication to the fog nodes to accelerate the handover process, however, the computation and communication overheads are not low enough to satisfy the requirements of delay-sensitive vehicular applications. To realize secure handover of vehicles in software defined vehicular networks (SDVN), in this paper, based on symmetric cryptography, we propose a lightweight and secure handover scheme with conditional privacy-preserving for group-based SDVN. The handover authentication only involves lightweight operation, without based on elliptic curve cryptography or involving complex bilinear pairing operations. After successfully authenticating with the SDN controller, the vehicle can directly authenticate with the fog nodes in the same group. The polynomial and one-way hash chain are used to realize group key update. We use BAN logic and ProVerif to formally analyze and test the security of our scheme. The detailed security analyses show that the scheme can resist common types of attacks and meet the essential security and privacy requirements. Compared with other related and represented works, our scheme exhibits better performance in computation and communication overheads.
Hong Zhong 0001, Jie Cui 0004, Irina Pavlovna Bolodurina, Chengjie Gu, Debiao He
IEEE Trans. Dependable Secur. Comput.5
2025 RRMAC: A Multi-Data Owner Access Control Scheme With Robust Revocation for Co-Owned Data Sharing
abstract
Due to the rising requirement for data sharing, multi-data owner access control schemes have emerged, where a single data file is jointly owned by multiple data owners. Since the shared files contain information from multiple data owners, it is crucial to revoke malicious users to minimize harm when data leakage occurs. However, current multi-data owner solutions typically rely on a single data owner to encrypt and share data and fail to provide robust user revocation. When revocation is managed by a single entity, it may fail to protect the rights of all data owners and can introduce a single point of failure in multi-data owner settings. On the other hand, if revocation requires the participation of all data owners, user access may fail if some owners are offline or compromised. To address these issues, we propose a robust multi-data owner access control scheme with efficient user revocation. We construct a secret resharing protocol based on secret sharing technology and proposed a multi-data owner access control scheme. Only users who obtain a sufficient number of private keys can decrypt the ciphertext. To achieve multi-owner controlled revocation, we use key splitting to divide the user’s private key into an authorization key and an update key and embed a period into the update keys. During user revocation, the cloud updates the ciphertext and the data user can decrypt the ciphertext without obtaining the update keys of all data owners. The thorough performance analysis shows that the overhead of the proposed scheme is acceptable. Specifically, the proposed scheme takes approximately 0.5 seconds to encrypt, and with preprocessing, this time is reduced to 0.06 seconds, while decryption requires around 0.15 seconds on the Raspberry Pi.
Hong Zhong 0001, Jie Cui 0004, Chengjie Gu, Debiao He
IEEE Trans. Inf. Forensics Secur.4
2025 CPA-TAM: channel patch aggregation and topological association mining for visible-infrared person re-identification
Huilin Liu, Chengjie Gu
J. Supercomput.5
2024 Efficient Blockchain-Based Mutual Authentication and Session Key Agreement for Cross-Domain IIoT
abstract
Several studies have introduced edge computing and blockchain into the Industrial Internet of Things (IIoT) to satisfy the requirements of delay-sensitive applications and support cross-domain authentication. Although there have been many protocols to ensure the security and privacy of devices in the IIoT, existing protocols still suffer from problems. Updating keys and pseudonyms of devices by a trusted third party (e.g., certificate authority) will cause high communication and computation overhead, especially when the number of devices becomes much larger. Furthermore, an increasing number of transactions also cause high storage overhead on the blockchain. Therefore, we propose a blockchain-based cross-domain authentication protocol. Specifically, we propose a privacy-preserving method based on pseudonyms that offloads the task of generating pseudonyms from a trusted third party to edge servers to ensure the conditional anonymity of the devices. The device is allowed to request pseudonyms in bulk to reduce the number of transactions, thus reducing the storage overhead on the blockchain. Security analysis and experimental results demonstrate that our scheme achieves an efficient tradeoff between security and efficiency.
Jie Cui 0004, Yihu Zhu, Hong Zhong 0001, Qingyang Zhang 0001, Chengjie Gu, Debiao He
IEEE Internet Things J.5
2024 Lightweight and Secure Data Sharing Based on Proxy Re-Encryption for Blockchain-Enabled Industrial Internet of Things
abstract
In the Industrial Internet of Things (IIoT), data sharing is crucial for promoting the intelligent development of industrial production. To achieve effective data supervision, introducing blockchain into traditional cloud-based data-sharing frameworks has attracted widespread attention. However, existing blockchain-based data-sharing schemes still have issues with security and efficiency. Therefore, we propose a blockchain-enabled data-sharing scheme based on proxy re-encryption. First, the scheme considers both storage and access authentication, guaranteeing data sources’ trustworthiness and preventing data misuse. Second, the scheme uses an on-chain and off-chain cooperative storage mechanism, saving the storage resources of the blockchain. Third, the scheme supports data packing, which effectively improves data storage efficiency. The security analysis shows that our scheme satisfies the security requirements. Finally, we build a blockchain platform using the hyperledger fabric. The performance evaluation shows that our scheme is more advantageous regarding computational overhead than other related schemes.
Fengqun Wang, Jie Cui 0004, Qingyang Zhang 0001, Debiao He, Chengjie Gu, Hong Zhong 0001
IEEE Internet Things J.5
2024 Efficient and effective (k, P)-core-based community search over attributed heterogeneous information networks
Yuxiang Wang 0001, Chengjie Gu, Xiaoliang Xu 0001, Xinjun Zeng, Xiangyu Ke, Tianxing Wu 0001
Inf. Sci.2
2024 Global-Margin Uncertainty and Collaborative Sampling for Active Learning in Complex Aerial Images Object Detection
abstract
Object detection in aerial images based on deep learning requires a large amount of labeled data, whereas manual annotation of aerial images is time-consuming and laborious. As a branch of machine learning, active learning can help humans find the valuable samples by designing some corresponding query strategies, which effectively reduces the cost of manual labeling. However, objects in aerial images are usually small, dense, and accompanied by the interference from complex backgrounds. These brings considerable challenges for active learning in selecting high-value aerial image samples. Currently, there is a relatively lack of study on active learning for aerial images object detection. Therefore, this paper proposes an novel active learning method, using global-margin uncertainty (GMU) and collaborative sampling (CS) to find out the high valuable aerial image samples to reduce the annotation cost and improve the training efficiency of models. In GMU, the predicted scores of categories are applied to calculate the global uncertainty and margin uncertainty of unlabeled aerial images, then those aerial images with high uncertainty scores are selected as the candidate samples. In CS, we train a main model and an auxiliary model respectively to detect the candidate samples, where the samples with large differences in detection results of the two models are selected for manual annotation. The experiments conduct on VisDrone2019 and DOTA-v1.5 datasets, which showes that the proposed method has a better performance compared with several state-of-the-art active learning methods.
Dongjun Zhu, Chengjie Gu, Yuyou Yao, Dayu Tan
IEEE Geosci. Remote. Sens. Lett.2
2024 Revocable and Efficient Blockchain-Based Fine-Grained Access Control Against EDoS Attacks in Cloud Storage
abstract
Users have become accustomed to storing data on the cloud using ciphertext policy attribute-based encryption (CP-ABE) for fine-grained access control. However, this encryption method does not consider the ability of malicious users to launch thousands of file download requests when launching an economic denial of sustainability attack (EDoS), which may be more expensive for data owners. Existing solutions typically use a cloud server to verify the download permissions of the data users. However, cloud servers are not completely trusted and cloud server providers and colluding data users can still launch an EDoS attack. With our scheme, using CP-ABE, a blockchain is introduced for verifying the download permission of data users. In addition, we propose a new mechanism to solve the problem of malicious user revocations under EDoS attacks by updating the ciphertext and symmetric encryption technology. A formal security proof has demonstrated that the proposed scheme is suitable for plaintext attack security. Theoretical and experimental analyses show that our scheme performs more efficiently than previous methods.
Qingyang Zhang 0001, Chang Xu 0015, Hong Zhong 0001, Chengjie Gu, Jie Cui 0004
IEEE Trans. Computers4
2024 DSChain: A Blockchain System for Complete Lifecycle Security of Data in Internet of Things
abstract
There is a growing concern about the complete lifecycle security of data in Internet of Things (IoT). This may cause privacy and trust problems for users regarding data sources, data storage, and access control for data sharing. Blockchain is a valuable solution to the above problems through distributed ledger technology, and it has been widely applied in various fields such as public services, finance, and IoT. However, the data in IoT are characterized by a large quantity, large capacity, and timely response, and existing blockchain systems only partially resolve them for data security and performance. We propose DSChain for IoT data security to address the challenges mentioned above. Our system uses a certificateless signature to ensure a trusted data source and public auditing to ensure the integrity of stored data while using ciphertext-policy attribute-based encryption to control access to shared data. Moreover, we propose a packaging mechanism based on the Merkle Hash Tree that effectively improves system performance. We implement the DSChain and provide a detailed analysis of performance and security. The experimental results indicate that DSChain can achieve approximately 1,035 transactions per second on a single peer and is scalable.
Jie Cui 0004, Yatao Li, Qingyang Zhang 0001, Hong Zhong 0001, Chengjie Gu, Debiao He
IEEE Trans. Dependable Secur. Comput.5
2024 Blockchain-Based Lightweight Message Authentication for Edge-Assisted Cross-Domain Industrial Internet of Things
abstract
In edge-assisted cross-domain Industrial Internet of Things (IIoT), blockchain-based authentication is an effective way to build cross-domain trust and secure cross-domain data. However, existing authentication schemes still have serious challenges in terms of efficiency and security. In this paper, we propose a blockchain-based lightweight message authentication scheme. First, to address efficiency challenges, we build a blockchain-enabled edge-assisted lightweight authentication framework. This framework uses edge servers to assist smart devices in achieving cross-domain authentication and effectively reduce redundant interactions between entities. Second, to resolve the security challenges, we design a lightweight message authentication algorithm for cross-domain IIoT. The algorithm guarantees message security with low computational overhead and is suitable for multi-receiver cross-domain IIoT. The security proof and analysis demonstrate that the proposed scheme is secure under the random oracle model and can resist various attacks. The performance evaluation shows that our proposed scheme is superior in terms of computation and communication overhead when compared with other related schemes.
Fengqun Wang, Jie Cui 0004, Qingyang Zhang 0001, Debiao He, Chengjie Gu, Hong Zhong 0001
IEEE Trans. Dependable Secur. Comput.5
2024 A Decentralized Authenticated Key Agreement Scheme Based on Smart Contract for Securing Vehicular Ad-Hoc Networks
abstract
Since the communication channels in vehicular ad-hoc networks (VANETs) are wireless and open, malicious adversaries can monitor or fabricate messages transmitted across them. To secure vehicular communications, an authenticated key agreement (AKA) scheme needs to be designed for VNAETs. Traditional VANETs AKA schemes require the trusted authority (TA) to authenticate the legality of message and corresponding sender. However, the TA in these schemes is vulnerable to suffer from single-point-of-failure issues. Some blockchain-based VANETs AKA schemes have been proposed recently to address the deficiency. However, these schemes rely on the consortium or private blockchain in which TAs are still required for key generation, resulting that the practicality is limited. To solve the issue, we design a smart contract-based VANETs AKA scheme, where the AKA algorithm of our proposed scheme is implemented on smart contract deployed on a public blockchain system and the TA that is responsible for key generation will not be required. The security proof and analysis show that our proposed scheme satisfies the session-key semantic security and essential security and privacy requirements, respectively. The performance analysis demonstrates that our proposed scheme outperforms existing blockchain-based VANETs AKA schemes.
Lu Wei 0003, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Chengjie Gu, Debiao He
IEEE Trans. Mob. Comput.5
2023 Multi-factor based session secret key agreement for the Industrial Internet of Things
Jie Cui 0004, Fangzheng Cheng, Hong Zhong 0001, Qingyang Zhang 0001, Chengjie Gu, Lu Liu 0001
Ad Hoc Networks5
2023 Conditional privacy-preserving message authentication scheme for cross-domain Industrial Internet of Things
Hong Zhong 0001, Chengdong Gu, Qingyang Zhang 0001, Jie Cui 0004, Chengjie Gu, Debiao He
Ad Hoc Networks5
2023 Efficient Integrity Auditing Mechanism With Secure Deduplication for Blockchain Storage
abstract
Massive nodes in a blockchain form an off-chain distributed storage network to provide storage resources for users to meet large data upload requirements. However, this storage approach introduces security and performance issues. Firstly, it is difficult to guarantee the integrity of the data uploaded, and these data may be easily corrupted or lost. Moreover, uploading excessive duplicate data leads to a waste of storage resources. In this study, to address these issues, with a double-copy storage model for blockchain off-chain storage, a novel public auditing scheme with client-side deduplication is proposed to reduce the storage overhead of nodes and check the integrity of the off-chain data. Based on smart contracts, our scheme could realize efficient user ownership and off-chain data integrity verification automatically. In addition, both data encryption and deduplication are achieved based on message-locked encryption and an improved authenticator generation algorithm. Security analysis and experimental comparisons show that the proposed scheme is effective and practical.
Qingyang Zhang 0001, Dongfang Sui, Jie Cui 0004, Chengjie Gu, Hong Zhong 0001
IEEE Trans. Computers4
2023 AC-SDVN: An Access Control Protocol for Video Multicast in Software Defined Vehicular Networks
abstract
The way to use limited bandwidth resources to achieve high-quality video services in vehicular networks is an important research topic. A large number of studies have shown that the fast-growing field of software defined networking (SDN) can provide solutions to the problems encountered by traditional IP networks when implementing video multicasting. However, there is no research addressing the security issues for this scenario. In this paper, we explore the application scenarios of video multicast in software defined vehicular networks (SDVN), and propose a secure and effective access control protocol to solve multicast security issues. This protocol realizes the authentication of multicast video requesting vehicles and RSUs. According to the authentication results, the SDN controller constructs multicast paths that only reach legitimate RSUs and vehicles, and only the vehicle passing the authentication can obtain video decryption keys. The protocol resists common attacks and satisfies the security requirements in vehicular networks. In addition, the scheme supports batch verification, which reduces the time cost of authentication, and adopts broadcast encryption technology to effectively reduce the communication load. Compared with related schemes, our protocol performs better in terms of computation and communication cost, packet loss rate, and time delay.
Hong Zhong 0001, Jie Cui 0004, Chengjie Gu, Irina Pavlovna Bolodurina, Lu Liu 0001
IEEE Trans. Mob. Comput.4
2023 Efficient Batch Authentication Scheme Based on Edge Computing in IIoT
abstract
In the industrial Internet of Things (IIoT) environment (e.g., a smart factory), smart devices with limited computing power can bring large amounts of privacy-sensitive data into insecure networks when they interact. If a network attacker intercepts and tampers with this data, it may cause chaos in production and even paralyze the entire IIoT system. Therefore, to ensure the regular operation of intelligent production, data receivers must authenticate the data before using them. However, existing message authentication schemes in the IIoT environment authenticate each message individually, which creates many redundant operations. Hence, to ensure data security among smart devices and reduce the computational overhead of data processing, we propose a batch authentication scheme based on edge computing in IIoT. Specifically, we design a lightweight batch authentication algorithm and use edge servers to assist smart devices in authenticating data, thus reducing the computational burden on smart devices and improving the efficiency of message authentication. The security analysis shows that the proposed scheme is secure in the random oracle model and meets the series of security requirements of the IIoT. In addition, we illustrate the efficiency of the scheme through experiments.
Jie Cui 0004, Fengqun Wang, Qingyang Zhang 0001, Chengjie Gu, Hong Zhong 0001
IEEE Trans. Netw. Serv. Manag.4
2023 Efficient Blockchain-Based Data Integrity Auditing for Multi-Copy in Decentralized Storage
abstract
As the disruptor of cloud storage, decentralized storage could lead to a major shift in how organizations store data in the future. To ensure data availability, users generally encrypt the data and distribute it to multiple storage service providers. It is necessary to study data integrity verification in decentralized storage. Although some recent studies have proposed the using blockchain technology to assist auditing work in decentralized storage networks, the on-chain overhead still increases linearly with an increase in audit requests. Blockchain networks will inevitably be overloaded. In this study, we propose an efficient data integrity auditing scheme for multiple copies in decentralized storage. Particularly, using different polynomial commitment schemes, we first propose a basic scheme for verifying multiple copies of a single file, and then we propose an efficient batch auditing scheme for multiple copies of multiple files. Our scheme can significantly reduce the computation overhead of storage service providers while keeping the on-chain storage overhead constant. Security analysis and performance analysis show that our scheme is efficient and practical.
Qingyang Zhang 0001, Jie Cui 0004, Hong Zhong 0001, Yang Li 0215, Chengjie Gu, Debiao He
IEEE Trans. Parallel Distributed Syst.6
2022 Dataset for Evaluation of DDoS Attacks Detection in Vehicular Ad-Hoc Networks
Hong Zhong 0001, Lu Wei 0003, Jing Zhang 0024, Chengjie Gu, Jie Cui 0004
WASA (3)5
2022 Prediction-based dual-weight switch migration scheme for SDN load balancing
Hong Zhong 0001, Jinshan Xu, Jie Cui 0004, Xiuwen Sun, Chengjie Gu, Lu Liu 0001
Comput. Networks5
2022 Parallel Key-Insulated Multiuser Searchable Encryption for Industrial Internet of Things
abstract
With the rapid development of the industrial Internet of Things (IIoT) and cloud computing, an increasing number of companies outsource their data to cloud servers to save costs. To protect data privacy, sensitive industrial data must be encrypted before being outsourced to cloud servers. A multiuser searchable encryption (MUSE) scheme was introduced to ensure high efficiency of encrypted data retrieval. In an IIoT system with numerous users, the existing MUSE schemes suffer from certain key exposure problems owing to the limited key protection of smart devices and frequent queries by users. In this article, we propose a parallel key-insulated MUSE scheme for IIoT. This scheme utilizes broadcast encryption technology to implement MUSE. In addition, our scheme introduces a key-insulated primitive to improve the tolerance to key exposure. The security of our scheme is proved in the random oracle model. The experimental results show that our scheme achieves high computational efficiency.
Jie Cui 0004, Hong Zhong 0001, Qingyang Zhang 0001, Chengjie Gu, Lu Liu 0001
IEEE Trans. Ind. Informatics5
2021 Secure and Efficient Certificateless Provable Data Possession for Cloud-Based Data Management Systems
Jing Zhang 0024, Jie Cui 0004, Hong Zhong 0001, Chengjie Gu, Lu Liu 0001
DASFAA (1)4
2021 Scalable QoS-Aware Multicast for SVC Streams in Software-Defined Networks
abstract
Because network nodes are transparent in media streaming applications, traditional networks cannot utilize the scalability feature of Scalable video coding (SVC). Compared with the traditional network, SDN supports various flows in a more fine-grained and scalable manner via the OpenFlow protocol, making QoS requirements easier and more feasible. In previous studies, a Ternary Content-Addressable Memory (TCAM) space in the switch has not been considered. This paper proposes a scalable QoS-aware multicast scheme for SVC streams, and formulates the scalable QoS-aware multicast routing problem as a nonlinear programming model. Then, we design heuristic algorithms that reduce the TCAM space consumption and construct the multicast tree for SVC layers according to video streaming requests. To alleviate video quality degradation, a dynamic layered multicast routing algorithm is proposed. Our experimental results demonstrate the performance of this method in terms of the packet loss ratio, scalability, the average satisfaction, and system utility.
Jie Cui 0004, Lingbiao Kong, Hong Zhong 0001, Xiuwen Sun, Chengjie Gu, Jianfeng Ma 0001
ISCC5
2021 Adaptive Data Transmission and Task Scheduling for High-Definition Map Update
Zhen Wang 0053, Chi Zhang 0001, Chengjie Gu, Miao Pan
WASA (3)4
2011 Online Internet Intrusion Detection Based on Flow Statistical Characteristics
Chengjie Gu, Shunyi Zhang, Hanhua Lu
KSEM1