Lin Yao 0001

dblp:37/752-1 · DBLP profile ↗
← Back
52ranked-venue papers
25as first author
29since 2021 · last 2026
0000-0001-8138-6045ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 16 · 6 first-author · 8 since 2021Security and privacy · 15 · 8 first-author · 11 since 2021Databases, data management, data science and information retrieval · 8 · 5 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 3 first-author · 2 since 2021Systems, architecture and hardware · 4 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Theory of computation · 1
YearPublicationVenuePosition
2026 B-HFA: Parameter-Efficient Vision-Language Retrieval via Block-shared Adapters and Hierarchical Aggregation
abstract
Full fine-tuning of large vision-language models (VLMs) for cross-modal retrieval is computationally expensive and prone to overfitting. Adapter-based parameter-efficient transfer learning offers a practical alternative, but existing designs often suffer from structural redundancy and the loss of fine-grained visual details critical for accurate matching. These limitations are particularly detrimental for retrieval, which demands fine-grained perceptual discrimination beyond semantic alignment. To address these challenges, we propose B-HFA, a parameter-efficient framework for vision-language retrieval. B-HFA introduces a Block-wise Shared Adapter (B-Adapter) to reduce redundancy through structured parameter sharing, and a Hierarchical Feature Aggregation (HFA) module that dynamically integrates intermediate visual features guided by textual semantics. This design enables efficient adaptation while preserving visual fidelity essential for retrieval. Extensive experiments on multiple retrieval benchmarks demonstrate that B-HFA achieves competitive performance with only 0.13% of trainable parameters. Moreover, its competitive results on visual question answering suggest the generality of the proposed framework beyond retrieval tasks.
Lin Yao 0001, Xuyun Zhang, Guowei Wu 0001
ICMR2
2026 DFLPMA: A communication-efficient framework for Decentralized Federated Learning using pruning and multi-aggregator coordination
Faisal Alshami, Lin Yao 0001, Huanle Xu, Guowei Wu 0001, Abid Sultan
Ad Hoc Networks2
2026 SIDF: Secure IoT data fusion approach with computation efficiency
Abid Sultan, Lin Yao 0001, Xin Wang 0001, Guowei Wu 0001, Faisal Alshami
Future Gener. Comput. Syst.2
2026 SIM-IBN: Surgical Event Time Imputation in Intent-Based Networking for Internet of Medical Things
abstract
The rapid development of the Internet of Medical Things (IoMT) enables automatic recording of surgical reports via interconnected medical devices. However, the reliability of these data is often compromised by missing data, frequently stemming from intermittent IoT communication issues like network disruptions or device malfunctions. This incomplete data critically hinders downstream medical applications and violates implicit network intents related to data integrity and timeliness within an Intent-based Networking (IBN), essential for supporting proactive resource allocation in operating rooms and optimized surgical scheduling. While existing studies focus on addressing missing event types, event time imputation remains a significant, underexplored challenge due to the need to capture implicit temporal contexts and complex cross surgical procedures dependencies. To tackle this for IoMT, we propose a novel Surgical event time IMputation in Intent-Based Networking(SIM-IBN) model. SIM-IBN employs continuous-time LSTMs with attention mechanisms to learn intra-and inter-sequence correlations, effectively recovering missing timestamps. By enhancing data reliability at the source, SIM-IBN serves as a crucial component enabling IBN systems to better fulfill intents for dependable IoMT operations. Rigorous evaluation on real-world surgical event datasets demonstrates SIM-IBN’s superiority over state-of-the-art baselines by up to 11.88% across various missing data scenarios, validating its potential to enable more reliable IoMT systems and enhance operational efficiency in smart healthcare environments.
Yixian Chen 0001, Zhaocheng He, Ali Kashif Bashir, Norah Saleh Alghamdi, Lin Yao 0001, Yuhuan Lu 0001, Wei Wang 0077
IEEE Internet Things J.7
2026 Multi-source data outlier detection based on secure multi-party computation
Lin Yao 0001, Zhaolong Zheng, Tian Wei, Guowei Wu 0001
Inf. Syst.1
2026 Data Flipping Attack and Defense in Web Edge Caching Systems
abstract
Caching web data on edge servers has become a common practice in latency-sensitive services to minimize data retrieval delays for web users. However, the geographic distribution of edge servers and frequent data transmissions make these systems vulnerable to security threats, particularly cache pollution attacks (CPAs). In such attacks, malicious users send excessive requests for unpopular data at abnormal frequencies, causing irrelevant content to be cached and degrading the system’s performance. Traditional CPAs, though impactful in conventional caching systems, are less effective in edge environments where user requests are more diverse and edge servers collaborate in caching strategies. In this paper, we identify a novel attack named data flipping attack (DFA) that targets the data transmission process among edge servers. This attack manipulates request distribution by swapping the frequencies of popular and unpopular data requests, all while maintaining other characteristics like request timing and user identity. This tactic disrupts caching strategies without raising suspicion. Experimental results indicate DFA is independent of user request patterns and demonstrates substantial effectiveness and robustness, successfully forcing edge web users to retrieve data from the cloud across various scales and configurations of edge networks. Furthermore, it evades detection by state-of-the-art methods that rely on specific distribution patterns, such as the Zipf distribution. To counter this attack, we propose an effective defense method that alters the request distribution by frequency distillation, mitigating its impact.
Mengsha Kou, Xiaoyu Xia 0001, Ibrahim Khalil 0001, Ziqi Wang 0008, Xiuzhen Zhang 0001, Lin Yao 0001, Minhui Xue 0001
IEEE Trans. Inf. Forensics Secur.6
2026 Privacy-Preserving GAN for Synthetic Data against Membership Inference Attack
abstract
High-quality data are essential for machine learning and data-driven research, yet data scarcity and privacy concerns remain major obstacles in many domains. Generative models have recently emerged as a promising approach to synthesize data that follow the same statistical distribution as real datasets. However, generative models are vulnerable to membership inference attacks, which threaten data confidentiality by exploiting model outputs to infer whether specific samples were used in training. Existing defense strategies struggle to simultaneously preserve data utility and provide robust privacy protection. To address this challenge, we propose our PPGM-GAN, a Privacy-Preserving GAN for synthetic data against membership inference attack to balance both data utility and data privacy. PPGM-GAN balances privacy and utility through a privacy-utility tradeoff function that quantifies and optimizes both aspects under different adversarial knowledge. To enhance data utility, we incorporate conditional generation and key-attribute screening to ensure sufficient representation of infrequent attribute values. Additionally, differential privacy is employed during training to prevent overfitting and reduce privacy leakage. Experimental results demonstrate that PPGM-GAN outperforms state-of-the-art privacy-preserving generative models, producing high-utility synthetic data under the same privacy constraints.
Guizhang Cui, Guowei Wu 0001, Lin Yao 0001, Haibo Hu 0001
ACM Trans. Priv. Secur.3
2025 SCDFL: A Spectral Clustering-based framework for accelerating convergence in Decentralized Federated Learning
Faisal Alshami, Lin Yao 0001, Xin Wang 0001, Guowei Wu 0001
Comput. Networks2
2025 Points of the local optimal privacy utility tradeoff
Lin Yao 0001, Haibo Hu 0001, Guowei Wu 0001
Comput. Secur.2
2025 REDA: A Real-Time Event-Detection Approach to Minimize IoT Visual Data Generation With Computation Efficiency
abstract
The Internet of Things (IoT) offers vast potential to enhance the quality of life, but the excessive visual data generated during environmental monitoring presents significant challenges. Existing visual data minimization methods struggle with real-time data reduction, often applying uniform minimization ratios to compress already generated data, which leads to high computational overhead and distortion. To address these limitations, this paper introduces REDA, a real-time event-driven approach for minimizing visual data generation. REDA employs an event estimation method that integrates motion and multi-scale object detection to reduce false alarms, missed detections, and computational costs. Additionally, it introduces an Optimal-IoU loss function to handle gradient challenges and applies contextual optical flow and filtering techniques to minimize data loss and distortion. Theoretical analysis and experimental results demonstrate that REDA achieves superior real-time data minimization and efficiency compared to existing state-of-the-art solutions.
Abid Sultan, Lin Yao 0001, Xin Wang 0001, Guowei Wu 0001
IEEE Internet Things J.2
2025 $\eta$η-Inference: A Data-Aware and High-Utility Privacy Model for Relational Data Publishing
abstract
Current privacy-preservation data publishing technologies primarily focus on anonymizing datasets, often overlooking the inherent privacy degrees embedded within the data. This oversight makes it challenging to balance privacy and utility effectively. To address this issue, we introduce the Privacy Evaluation and Validation scheme to Measure the original Privacy Degree (PEVMPD), anchored in a novel$\eta$-inference model. PEVMPD operates in two phases: the identification of risk elements and the evaluation of privacy degrees. In the first phase, attributes are appraised using entropy and KL divergence to pinpoint sensitive attributes. Concurrently, the maximum entropy principle is employed to identify critical quasi-identifiers. The second phase involves applying these risk elements within our$\eta$-inference model to locate data vulnerable to privacy breaches and to quantify the corresponding privacy degree. This methodology enables data owners to make informed decisions about achieving an optimal privacy-utility tradeoff during data anonymization. Experimental results on real datasets validate the effectiveness of PEVMPD in enhancing privacy measures.
Lin Yao 0001, Haibo Hu 0001, Guowei Wu 0001
IEEE Trans. Dependable Secur. Comput.2
2025 HeavyFinder: A Lightweight Network Measurement Framework for Detecting High-Frequency Elements in Skewed Data Streams
abstract
Skewed data streams are characterized by uneven distributions in which a small fraction of elements occur with much higher frequency than others. The detection of these high-frequency elements presents significant practical challenges, particularly under stringent memory constraints, as existing detection techniques have typically relied on predefined thresholds that require significant memory usage. However, this approach is highly inefficient since not all elements require equal storage space. To address these limitations, we introduce HeavyFinder (HF), a novel lightweight network measurement architecture designed to detect high-frequency elements in skewed data. HF employs a threshold-free update strategy that enables dynamic adaptation to variable data, thereby providing greater flexibility for tracking high-frequency elements without requiring fixed thresholds. Furthermore, an included memory-light strategy enables high accuracy for non-uniform distributions, even with limited memory allocation. Experimental results showed that HF significantly improved performance in four query tasks, producing an accuracy of 99.81% when identifying the top-k elements. The average absolute error (AAE) was also reduced to 10-4 using only 100KB of memory, which was significantly lower than that of conventional methods.
Lin Yao 0001, Weizhe Zhang
IEEE Trans. Netw. Serv. Manag.2
2024 Enhancing Privacy in Big Data Publishing: η-Inference Model
Lin Yao 0001, Guowei Wu 0001, Shisong Geng
ADMA (6)2
2024 Hybrid aggregation for federated learning under blockchain framework
Xinjiao Li, Guowei Wu 0001, Lin Yao 0001, Shisong Geng
Comput. Commun.3
2024 A Utility-Aware Anonymization Model for Multiple Sensitive Attributes Based on Association Concealment
abstract
Relational data usually contain multiple Sensitive Attributes (SAs) and Quasi-Identifiers (QIs). Privacy leakage may occur if they are published directly. Therefore, many privacy models have been proposed. However, one of the most challenging issues is the association between attributes, which can cause both identity disclosure and attribute disclosure. Furthermore, these models always prioritize privacy over utility, so a rigorous (but often unnecessary) setting of privacy parameters could cause poor utility or even useless data. In this paper we propose a scheme called MSAAC that addresses both issues. To balance data privacy and utility, MSAAC adopts a utility-aware ($\alpha ,\beta$) privacy model. To guide data publishers to set$\alpha$and$\beta$reasonably, MSAAC has built-in measures on privacy gain and utility loss, and quantitatively trades privacy for utility and vice versa. Our second contribution is quantifying the association ofSA-SAusing lift degree and the association ofQI-SAusing a chi-square value. Based on them, MSAAC applies suppression and permutation techniques to properly anonymize them. Through both theoretical and experimental results, we show MSAAC can achieve better privacy while retaining higher utility than state-of-the-art solutions.
Lin Yao 0001, Haibo Hu 0001, Guowei Wu 0001
IEEE Trans. Dependable Secur. Comput.1
2024 More Modalities Mean Better: Vessel Target Recognition and Localization Through Symbiotic Transformer and Multiview Regression
abstract
Vessel target recognition and localization are typically modeled using underwater acoustic signals, which contain a large amount of vessel operating characteristics and condition information. However, extracting operating characteristics from single signals faces heavy noise and non-stationarity challenges. Meanwhile, feature extraction using multimodal data faces the challenges of conflicting gradients between different modalities and ensuring the separability of vessel targets. To tackle these issues, we propose an audio-visual-textual features fusion method to recognize and localize vessel targets through Symbiotic Transformer (Symb-Trans) and Multi-View Regression (MVR) models. Specifically, the audio-visual samples are first preprocessed into paired time series and then projected into a unified optimization landscape via a Heterogeneous Batch Normalization (HetBN) layer to avoid gradient conflicts. Second, the Symb-Trans trains parallel encoders with cross-modal attention and embeds audio-visual representations for vessel target recognition. Finally, the MVR method learns neighboring target properties of a graph model from different perspectives, audio-visual-textual representations, to infer the collector-target distance. Since no off-the-shell multimodal dataset is available for vessel targets, we combine multiple public datasets, consisting of acoustic, and/or visual, and/or textural data, to obtain multimodal materials for model training and validation. Through experimental results and theoretical analysis, we show that Symb-Trans and MVR models outperform unimodal and generic multimodal state-of-the-art solutions for vessel target recognition and localization.
Shipei Liu, Xiaoya Fan, Guowei Wu 0001, Lin Yao 0001, Shisong Geng
IEEE Trans. Geosci. Remote. Sens.4
2024 Utility-aware Privacy Perturbation for Training Data
abstract
Data perturbation under differential privacy constraint is an important approach of protecting data privacy. However, as the data dimensions increase, the privacy budget allocated to each dimension decreases and thus the amount of noise added increases, which eventually leads to lower data utility in training tasks. To protect the privacy of training data while enhancing data utility, we propose a Utility-aware training data Privacy Perturbation scheme based on attribute Partition and budget Allocation (UPPPA). UPPPA includes three procedures: the quantification of attribute privacy and attribute importance, attribute partition, and budget allocation. The quantification of attribute privacy and attribute importance based on information entropy and attribute correlation provide an arithmetic basis for attribute partition and budget allocation. During the attribute partition, all attributes of training data are classified into high and low classes to achieve privacy amplification and utility enhancement. During the budget allocation, a γ-privacy model is proposed to balance data privacy and data utility so as to provide privacy constraint and guide budget allocation. Three comprehensive sets of real-world data are applied to evaluate the performance of UPPPA. Experiments and privacy analysis show that our scheme can achieve the tradeoff between privacy and utility.
Xinjiao Li, Guowei Wu 0001, Lin Yao 0001, Zhaolong Zheng, Shisong Geng
ACM Trans. Knowl. Discov. Data3
2023 Detection of Cache Pollution Attack Based on Federated Learning in Ultra-Dense Network
Lin Yao 0001, Jing Deng 0001, Guowei Wu 0001
Comput. Secur.1
2023 A Privacy-Preserving Hybrid Range Search Scheme Over Encrypted Electronic Medical Data in IoT Systems
abstract
Electronic wearable devices play an important role in the Internet of Things (IoT) systems for collecting medical data. Searching over such numerical medical data help to provide better service and treatment. However, user and data security is a major barrier to public adoption. Existing approaches designed to facilitate secure (range) searches over encrypted data generally incur expensive computational overhead suffer from unexpected information leakage, and/or have high false-positive results. Therefore, in this article, we design a hybrid searchable encryption scheme that supports efficient, secure, and accurate range searches over encrypted data sensed and collected from medical IoT devices. The designed graph structure helps to filter out most of the false data, and the batching processing on ciphertexts accelerates the removal of irrelevant data. Unlike most prior works, the proposed random index hides the distribution of data, and the probabilistic fixed-length trapdoor hides the range size and repetition of the query. If necessary, all the encrypted data can be refreshed by the cloud server after a range search. The scheme is proven to be secure in a simulation-based model. Then, we evaluate the performance of our proposed scheme on Microsoft Azure cloud servers and Azure IoT Central. The comparisons with several prior works demonstrate that our scheme supports more efficient secure range searches.
Pengxu Tian, Cheng Guo 0001, Kim-Kwang Raymond Choo, Xinyu Tang 0001, Lin Yao 0001
IEEE Internet Things J.5
2023 Scan-free verifiable public-key searchable encryption supporting efficient user updates in distributed systems
Pengxu Tian, Cheng Guo 0001, Yingmo Jie, Yi-Ning Liu 0002, Lin Yao 0001
J. Inf. Secur. Appl.5
2023 Detection of Cache Pollution Attack Based on Ensemble Learning in ICN-Based VANET
abstract
Content Centric Network (CCN) can be extended to efficiently and reliably support content delivery and solve the network performance degradation caused by dynamic topology and intermittent connectivity of Vehicle Ad hoc NETwork (VANET). However, the in-network caching mechanism of Vehicular Content Centric Network (VCCN) is vulnerable against Cache Pollution Attack (CPA), where attackers aim to fill the buffer space with non-popular contents by releasing fake requests. Unavoidably, the cache hit ratio of content requests from legal users is degraded and the content retrieval latency is increased under CPA. Hence, it is critical to detect and mitigate CPA. The current solutions for static CCN cannot be directly applied into dynamic VCCN. In this article, we propose a detection scheme based on hybrid heterogeneous multi-classifier ensemble learning, where CPA is determined by the cooperation of multiple vehicles. In our scheme, each vehicle can build or join a cluster whose head possesses more common moving attributes of position, speed and direction with other members. Besides, the cluster head as a base learner is responsible for training its own classifier by making some relevant statistics on requests and hit ratio. Specifically, the problem of ensemble classifier making from the individual classifiers is formulated as a linear optimization problem, with the goal of minimizing the false ratio of detecting CPA. The generalization ability of ensemble learning can make very accurate predictions on CPA. By comparison, our detection scheme outperforms the existing schemes in terms of detection ratio, hit ratio, retrieval delay. Besides, simulations have proved that the overfitting problem of adopting a singe base learning algorithm can be alleviated in our scheme.
Lin Yao 0001, Zhaolong Zheng, Xin Wang 0001, Yujie Zeng, Guowei Wu 0001
IEEE Trans. Dependable Secur. Comput.1
2022 Exploiting Non-Cooperative Game Against Cache Pollution Attack in Vehicular Content Centric Network
abstract
Vehicular Content Centric Network (VCCN) has been proposed to address the issues of user mobility and sporadic connectivity in Vehicular Ad hoc Network (VANET). The in-network caching of VCCN can indeed improve the performance of content distribution in terms of cache hit and delivery latency by making each node store frequently accessed data. However, data caching unfortunately suffers from Cache Pollution Attack (CPA) that sends out fabricated requests to pollute the data cache. To prevent the degradation of network performance caused by such an attack, we propose a detection and defense scheme for CPA by adopting game theory. We model the attack scenario into a non-cooperative game model. First, we prove the non-existence of pure strategy Nash Equilibrium (NE) in the attacker and defender game, and propose a normal form game model with complete information and an extensive Bayesian form game model with incomplete information. Under the guidance of NE, we propose a punishment strategy to prevent the conspiracy attack and make the attackers behave normally. Moreover, we propose a cooperative detection scheme to give the Road Side Unit (RSU) the final decision on CPA based on the direct and indirect suspicious lists which are generated by each node according to the observed traffic pattern. Simulation evaluations demonstrate that our scheme outperforms state-of-the-art schemes in terms of cache hit, detecting ratio, and cache accuracy for detecting and defending CPA.
Lin Yao 0001, Haipeng Dai 0001, Guowei Wu 0001
IEEE Trans. Dependable Secur. Comput.1
2022 Privacy Preservation for Trajectory Publication Based on Differential Privacy
abstract
With the proliferation of location-aware devices, trajectory data have been used widely in real-life applications. However, trajectory data are often associated with sensitive labels, such as users’ purchase transactions and planned activities. As such, inappropriate sharing or publishing of these data could threaten users’ privacy, especially when an adversary has sufficient background knowledge about a trajectory through other data sources, such as social media (check-in tags). Though differential privacy has been used to address the privacy of trajectory data, no existing method can protect the privacy of both trajectory data and sensitive labels. In this article, we propose a comprehensive trajectory publishing algorithm with three effective procedures. First, we apply density-based clustering to determine hotspots and outliers and then blur their locations by generalization. Second, we propose a graph-based model to efficiently capture the relationship among sensitive labels and trajectory points in all records and leverage Laplace noise to achieve differential privacy. Finally, we generate and publish trajectories by traversing and updating this graph until we travel all vertexes. Our experiments on synthetic and real-life datasets demonstrate that our algorithm effectively protects the privacy of both sensitive labels and location data in trajectory publication. Compared with existing works on trajectory publishing, our algorithm can also achieve higher data utility.
Lin Yao 0001, Haibo Hu 0001, Guowei Wu 0001, Bin Wu 0011
ACM Trans. Intell. Syst. Technol.1
2022 A Cooperative Caching Scheme for VCCN With Mobility Prediction and Consistent Hashing
abstract
In order to mitigate the performance degradation of intermittent vehicular network caused by traffic mobility and sporadic connectivity issues, Vehicular Content Centric Network (VCCN) has been proposed to apply many technologies in Content Centric Network (CCN) into vehicular ad hoc networks. The open in-network caching strategy of CCN enables sharing and coordination of the cached data among multiple nodes as an efficient data access without relying on remote fetching. Nonetheless, few studies have considered the effective use of overall cache capacity with these cooperative nodes, especially the issues of cache duplication. Furthermore, most content replacement polices have ignored the needs of cooperative contents when making cache decisions. In this paper, we design a novel Cooperative Caching scheme by using Mobility Prediction and Consistent Hash for VCCN (called CCMPCH). Specifically, based on the observation that vehicles with the same trajectory are more likely to maintain stable communication links, we adopt Prediction by Partial Matching (PPM) to forecast each vehicle’s path and cluster the vehicles with similar future path, moving direction, and moving speed into one group. In each cluster, the consistent hash algorithm is used to allocate contents among cooperative nodes, thereby reducing unnecessary cache duplication while maintaining strong content availability. A popularity-based cache replacement policy is also developed to prioritize cooperative contents. We evaluate CCMPCH via extensive simulations, which demonstrates its higher cache hit ratio, shorter content access delay, and lower hop count compared to other state-of-the-art schemes.
Lin Yao 0001, Xiaoying Xu, Jing Deng 0001, Guowei Wu 0001
IEEE Trans. Intell. Transp. Syst.1
2021 New Dynamic Switch Migration Technique Based on Deep Q-learning
abstract
By decoupling the control and data planes, Software-Defined Networking (SDN) can implement centralized manage-ment on the network. With the increasing scale of the network, the multi-controller SDN architecture is becoming more and more popular, because it can handle what SDN with a single controller is not able to address. However, the controller load imbalance may happen due to traffic dynamics in an SDN with multiple controllers, which results in congestion at a certain controller and seriously affects the scalability of the control plane. Though switch migration is an effective solution to this problem, how to migrate the traffic is an NP-hard problem. In this work, we propose a switch migration scheme based on deep Q-learning (DQN) by combining the powerful perception of deep learning with the decision-making ability of Q-learning. We first describe the SDN state formally. Then, the network state is represented by the two-dimensional array as the input of the Q network. The network features are extracted through the convolution layer, and the full connection layer is achieved. Finally, the output layer to predict the migration action in some states of a network is extracted. After the migration action is performed, we will get an instant reward or penalty. We implement our algorithm based on the keras deep learning framework and compare it with the classic Q-learning algorithm. The results show that our scheme is superior to the traditional method in terms of resource utilization and load balancing ability.
Lin Yao 0001, Guowei Wu 0001, Bin Wu 0011
EUC1
2021 Sensitive attribute privacy preservation of trajectory data publishing based on l-diversity
Lin Yao 0001, Haibo Hu 0001, Guowei Wu 0001, Bin Wu 0011
Distributed Parallel Databases1
2021 Sensitive Label Privacy Preservation with Anatomization for Data Publishing
abstract
Data in its original form, however, typically contain sensitive information about individuals. Directly publishing raw data will violate the privacy of people involed. Consequently, it becomes increasingly important to preserve the privacy of published data. An attacker is apt to identify an individual from the published tables, with attacks through the record linkage, attribute linkage, table linkage or probabilistic attack. Although algorithms based on generalization and suppression have been proposed to protect the sensitive attributes and resist these multiple types of attacks, they often suffer from large information loss by replacing specific values with more general ones. Alternatively, anatomization and permutation operations can de-link the relation between attributes without modifying them. In this paper, we propose a scheme Sensitive Label Privacy Preservation with Anatomization (SLPPA) to protect the privacy of published data. SLPPA includes two procedures, table division and group division. During the table division, we adopt entropy and mean-square contingency coefficient to partition attributes into separate tables to inject uncertainty for reconstructing the original table. During the group division, all the individuals in the original table are partitioned into non-overlapping groups so that the published data satisfies the pre-defined privacy requirements of our (α; β; γ; δ) model. Two comprehensive sets of real-world relationship data are applied to evaluate the performance of our anonymization approach. Simulations and privacy analysis show our scheme possesses better privacy while ensuring higher utility.
Lin Yao 0001, Xin Wang 0001, Guowei Wu 0001
IEEE Trans. Dependable Secur. Comput.1
2021 Detection and Defense of Cache Pollution Based on Popularity Prediction in Named Data Networking
abstract
Named Data Networking (NDN) is one of the most promising information-centric networking architectures that can improve the network performance by supporting the large scale content distribution. However, the use of in-network caching mechanism increases the opportunity of cache pollution attack, where the attackers intend to reduce the cache hit of legal users by releasing fake requests to fill the precious cache with non-popular contents. To prevent the degradation of network performance caused by such an attack, it is becoming particularly important to detect the attack and then throttle it. In this article, we propose a detection and defense scheme with the help of grey forecast, which can effectively exploit the regularity of past Interests and popularity by comprehensively considering three major factors to predict the future popularity of each cached content. If the predicted popularity of any content differs too much from the actually calculated one in several consecutive slices, the pollution attack will be determined. Once the attack is detected, the defense will be taken by suppressing the popularity increase of the suspicious content to mitigate the damage of the pollution attack. We also consider a special case, where there exists a sudden burst of traffic from legal users that cannot be simply dropped. The simulations in ndnSIM indicate that our proposed method is effective in detecting and defending the pollution attack with higher cache hit, higher detecting ratio, and lower hop count compared to other state-of-the-art schemes.
Lin Yao 0001, Yujie Zeng, Xin Wang 0001, Ailun Chen, Guowei Wu 0001
IEEE Trans. Dependable Secur. Comput.1
2021 Cooperative Caching in Vehicular Content Centric Network Based on Social Attributes and Mobility
abstract
Communications in vehicular ad-hoc network (VANET) are subject to performance degradation as results of channel fading and intermittent network connectivity. The emerging Vehicular Content Centric Network (VCCN) is promising in supporting the needs of contents and alleviating the communication problems in VANET. Specifically, to improve the cache hit ratio and reduce the access delay of content retrieval, it helps to choose the appropriate vehicles to cache the frequently accessed data items. In this paper, we propose a Cooperative Caching scheme based on Social Attributes and Mobility Prediction (CCSAMP) for VCCN. CCSAMP is based on the observation that vehicles move around and are liable to contact each other according to drivers' common interests or social similarities. A caching node sharing more social attributes with the content requester is more likely to be interested in the same contents and distribute the contents to others with similar interests. Furthermore, a caching node that frequently meets other nodes is a better candidate to keep cache copies. To increase the network performance, CCSAMP also exploits the regularity of vehicle moving behaviors to predict the chance for a vehicle to reach hot zones based on Hidden Markov Model (HMM). We evaluate CCSAMP through the ONE simulator to demonstrate its higher cache hit ratio and lower content access delay compared to other state-of-the-art schemes.
Lin Yao 0001, Xin Wang 0001, Guowei Wu 0001
IEEE Trans. Mob. Comput.1
2020 Detection and Defense of Cache Pollution Attacks Using Clustering in Named Data Networks
abstract
Named Data Network (NDN), as a promising information-centric networking architecture, is expected to support next-generation of large-scale content distribution with open in-network cachings. However, such open in-network caches are vulnerable against Cache Pollution Attacks (CPAs) with the goal of filling cache storage with non-popular contents. The detection and defense against such attacks are especially difficult because of CPA's similarities with normal fluctuations of content requests. In this work, we use a clustering technique to detect and defend against CPAs. By clustering the content interests, our scheme is able to distinguish whether they have followed the Zipf-like distribution or not for accurate detections. Once any attack is detected, an attack table will be updated to record the abnormal requests. While such requests are still forwarded, the corresponding content chunks are not cached. Extensive simulations in ndnSIM demonstrate that our scheme can resist CPA effectively with higher cache hit, higher detecting ratio, lower hop count, and lower algorithm complexity compared to other state-of-the-art schemes.
Lin Yao 0001, Zhenzhen Fan, Jing Deng 0001, Xin Fan 0001, Guowei Wu 0001
IEEE Trans. Dependable Secur. Comput.1
2019 LSTM-Based Detection for Timing Attacks in Named Data Network
abstract
Named Data Network (NDN) is an alternative to host-centric networking exemplified by today's Internet. One key feature of NDN is in-network caching that reduces access delay and query overhead by caching popular contents at the source as well as at a few other nodes. Unfortunately, in-network caching suffers various privacy risks by different attacks, one of which is termed timing attack. This is an attack to infer whether a consumer has recently requested certain contents based on the time difference between the delivery time of those contents that are currently cached and those that are not cached. In order to prevent the privacy leakage and resist such kind of attacks, we propose a detection scheme by adopting Long Short-term Memory (LSTM) model. Based on the four input features of LSTM, cache hit ratio, average request interval, request frequency, and types of requested contents, we timely capture more important eigenvalues by dividing a constant time window size into a few small slices in order to detect timing attacks accurately. We have performed extensive simulations to compare our scheme with several other state-of-the-art schemes in classification accuracy, detection ratio, false alarm ratio, and F-measure. It has been shown that our scheme possesses a better performance in all cases studied.
Lin Yao 0001, Binyao Jiang, Jing Deng 0001, Mohammad S. Obaidat
GLOBECOM1
2019 Publishing Sensitive Trajectory Data Under Enhanced l-Diversity Model
abstract
With the proliferation of location-aware devices, trajectory data have been widely collected, published, and analyzed in real-life applications. However, published trajectory data often contain sensitive attributes, so an attacker who can identify an individual from such data through record linkage, attribute linkage, or similarity attacks can gain sensitive information about this individual. To resist from these attacks, we propose a scheme called Data Privacy Preservation with Perturbation (DPPP). To protect the privacy of sensitive information, we first determine those critical location sequences that can identify specific individuals. Then we perturb these sequences by adding or deleting some moving points while ensuring the published data satisfy (l, α, β)-privacy, an enhanced privacy model from ldiversity. Our experiments on both synthetic and real-life datasets suggest that DPPP achieves better privacy while still ensuring high utility, compared with existing privacy preservation schemes on trajectory.
Lin Yao 0001, Xin Wang 0001, Haibo Hu 0001, Guowei Wu 0001
MDM1
2019 Popularity Prediction Caching Using Hidden Markov Model for Vehicular Content Centric Networks
abstract
Vehicular Content Centric Network (VCCN) is proposed to cope with mobility and intermittent connectivity issues of vehicular ad hoc networks by enabling the Content Centric Network (CCN) model in vehicular networks. The ubiquitous in-network caching of VCCN allows nodes to cache contents frequently accessed data items, improving the hit ratio of content retrieval and reducing the data access delay. Furthermore, it can significantly mitigate bandwidth pressure. Therefore, it is crucial to cache more popular contents at various caching nodes. In this paper, we propose a novel cache replacement scheme named Popularity-based Content Caching (PopCC), which incorporates the future popularity of contents into our decision making. We adopt Hidden Markov Model (HMM) to predict the content popularity based on the inherent characters of the received interests, request ratio, request frequency and content priority. To evaluate the performance of our proposed scheme PopCC, we compare it with some state-of-the-art schemes in terms of cache hit, average access delay, average hop count and average storage usage. Simulations demonstrate that the proposed scheme possesses a better performance.
Lin Yao 0001, Qiufen Xia
MDM1
2018 A QoS and Cost Aware Fault Tolerant Scheme Insult-Controller SDNs
abstract
Software Defined Networking (SDN) is envisioned as a novel technology to enable reliable and scalable network management by decoupling the control plane and data plane. As the network scale increases, multiple controllers have been proposed to solve the problems of scalability and reliability caused by single controller. Although some controller placement schemes based on controller replication have been proposed to recover the controller failure in SDNs, few of them can solve the failure with the existing controllers. In this paper, we propose a QoS and cost aware fault tolerant scheme in multi-controller SDNs by exploring a fine-grained trade-off between controller cost and recovery time. With considering the controlle cost, load and communication delay in the failure recovery, we propose a heuristic algorithm to select backup controllers aiming to minimize the average recovery time, meanwhile avoiding the load oscillation in switch migration. Extensive simulations highlight that our scheme can improve the recovery efficiency compared with some other existing approaches.
Guowei Wu 0001, Likun Wang 0004, Zichuan Xu, Lin Yao 0001, Mohammad S. Obaidat
GLOBECOM4
2018 The Community Characteristic Based Controller Deployment Strategy for SDNs
abstract
To solve the bottleneck of a single controller in software-defined networks (SDNs), most of current works based on multiple controllers focus on decreasing propagation delay between the switch and the corresponding controller. However,this kind of methods ignores the synchronization between controllers, which may affect the network performance. Moreover, the controller deployment based on out-band has neglected the association between switches, which is quite costly. In this paper, we propose a community characteristic based strategy to achieve controller placement with optimal latency and balanced controller load. We first divide the network domain according to the relevance between switches, and then we design our controller deployment strategy by reconciling the propagation delay between controllers and the control delay between controllers and switches. We adopt in- band control mode instead of Euclidean distance to compute the distance among network entities. The simulation results show that our strategy can gain lower propagation delay latency and better load balance.
Lin Yao 0001, Xin Zhao 0007, Guowei Wu 0001, Mohammad S. Obaidat
GLOBECOM1
2018 DoS Mitigation Mechanism Based on Non-Cooperative Repeated Game for SDN
abstract
Software defined network (SDN)can manage the whole network flexibly because of its programmability and logically centralized architecture. However, the centralized architecture of SDN makes it more vulnerable to Denial of Service (DoS)attack which is launched by sending a large number of malicious packet_in packets to consume the resources of the controller and data planes. In order to protect the normal operation of the network from DoS, we propose an effective DoS mitigation framework based on non-cooperative repeated game called PrioGuard. DoS can be detected based on the information entropy, packet_in rate and packet_in response rate. Furthermore, the penalty-incentive mechanism of repeated game is adopted to punish these attackers by lowering their priority in order to postpone their requests. The requests from attackers will be migrated to data plane cache, which can mitigate the interface cache of control plane and make the controller process the normal requests effectively. We have implemented a prototype system of PrioGuard. Simulation evaluations demonstrate that our scheme is very effective with less response time, less packet loss rate and lower controller load.
Guowei Wu 0001, Zhaoxin Li, Lin Yao 0001
ICPADS3
2018 V2X Routing in a VANET Based on the Hidden Markov Model
abstract
It is very difficult to establish and maintain end-to-end connections in a vehicle ad hoc network (VANET) as a result of high vehicle speed, long inter-vehicle distance, and varying vehicle density. Instead, a store-and-forward strategy has been considered for vehicle communications. The success of this strategy, however, depends heavily on the cooperation among nodes. Different from exiting store-and-forward solutions, we propose predictive routing based on the hidden Markov model (PRHMM) for VANETS, which exploits the regularity of vehicle moving behaviors to increase the transmission performance. As vehicle movements often exhibit a high degree of repetition, including regular visits to certain places and regular contacts during daily activities, we can predict a vehicle's future locations based on the knowledge of past traces and the hidden Markov model. Consequently, the short-term route of a vehicle and its packet delivery probability for a specific mobile destination can be predicted. Moreover, PRHMM enables seamless handoff between vehicle-to-vehicle and vehicle-to-infrastructure communications so that the transmission performance will not be constrained by the vehicle density and moving speed. Simulation evaluation demonstrates that PRHMM performs much better in terms of delivery ratio, end-to-end delay, traffic overhead, and buffer occupancy.
Lin Yao 0001, Jie Wang 0043, Xin Wang 0001, Ailun Chen
IEEE Trans. Intell. Transp. Syst.1
2017 Preserving the Relationship Privacy of the published social-network data based on Compressive Sensing
abstract
With the constant increase of social-network data published, the privacy preservation becomes more and more important. Although some literature algorithms apply K-anonymity to the relational data to prevent an adversary from significantly perpetrating privacy breaches, the inappropriate choice of K has a big impact on the quality of privacy protection and data utility. We propose a technique named Relationship Privacy Preservation based on Compressive Sensing (RPPCS) in this paper to anonymize the relationship data of social networks. The network links are randomized from the recovery of the random measurements of the sparse relationship matrix to both preserve the privacy and data utility. Two comprehensive sets of real-world relationship data on social networks are applied to evaluate the performance of our anonymization technique. Our performance evaluations based on Collaboration Network and Gnutella Network demonstrate that our scheme can better preserve the utility of the anonymized data compared to peer schemes. Privacy analysis shows that our scheme can resist the background knowledge attack.
Lin Yao 0001, Xin Wang 0001, Guowei Wu 0001
IWQoS1
2016 MREA: a minimum resource expenditure node capture attack in wireless sensor networks
abstract
Abstract Because of the stochastic key pre‐distribution and complicated network topology, designing an energy‐efficient node capture attack algorithm is of great challenge. Although many algorithms have been proposed for node capture attack, previous methods lack of concerning minimizing resource expenditure in modeling attacking behavior. In this paper, we propose a novel way of modeling the node capture attack. First, we transform the problem into a set covering problem with a shortest Hamiltonian cycle problem, which has been shown to be NP‐hard. Consequently, we also develop a heuristic called minimum resource expenditure node capture attack (MREA) to maximize destructiveness while minimizing resource expenditure. Moreover, extensive simulations are conducted to show the performance of MREA. Simulation results show that MREA outperforms other algorithms in reducing the attack rounds and saving resource expenditure. Copyright © 2016 John Wiley & Sons, Ltd.
Chi Lin 0001, Tie Qiu 0001, Mohammad S. Obaidat, James Chang Wu Yu, Lin Yao 0001, Guowei Wu 0001
Secur. Commun. Networks5
2016 Secure Routing Based on Social Similarity in Opportunistic Networks
abstract
The lack of pre-existing infrastructure or dynamic topology makes it impossible to establish end-to-end connections in opportunistic networks (OppNets). Instead, a store-and-forward strategy can be employed. However, such loosely knit routing paths depend heavily on the cooperation among participating nodes. Selfish or malicious behaviors of nodes impact greatly on the network performance. In this paper, we design and validate a dynamic trust management model for secure routing optimization. We propose the concept of incorporating social trust into the routing decision process and design a trust routing based on social similarity (TRSS) scheme. TRSS is based on the observation that nodes move around and contact each other according to their common interests or social similarities. A node sharing more social features in social history record with the destination is more likely to travel close to the latter in the near future and should be chosen as the next-hop forwarder. Furthermore, social trust can be established based on an observed node's trustworthiness and its encounter history. Based on direct and recommended trust, those untrustworthy nodes will be detected and purged from the trusted list. Since only trusted nodes' packets will be forwarded, the selfish nodes have the incentives to behave well again. Simulation evaluation demonstrates that TRSS is very effective in detecting selfish or even malicious nodes and achieving better performance.
Lin Yao 0001, Yanmao Man, Jing Deng 0001, Xin Wang 0001
IEEE Trans. Wirel. Commun.1
2015 A Trust Routing for Multimedia Social Networks
abstract
Due to the disconnected and store-and-forward architecture in multimedia social networks (MSNs), routing becomes a great challenge with the frequent path disruptions. Moreover, some nodes in MSNs tend to be selfish or malicious, e.g. they sometimes will not forward packets for other nodes or will launch passive and active attacks in order to save their limited resources such as bandwidth, battery or storage. In order to address this issue, we propose a fuzzy-based trust management technique for context-based routing in MSNs. We incorporate social trust metrics and quality of service metrics into our trust model. By adopting fuzzy sets, every node can evaluate the credibility of other nodes based on the direct and indirect relationship. By ranking all its neighbors according to the trust values, each node can purge untrustworthy nodes. Since only trusted nodes’ packets will be forwarded, the selfish or malicious nodes have the incentive to behave well again in order to be able to send packets. Additionally, we perform extensive security and performance evaluation with the opportunistic network environment simulator. The simulation results show that our trust model can dynamically update the trust value in real time, effectively measure the trust relationship and correctly identify malicious or selfish nodes. Furthermore, the proposed trust routing is a lightweight protocol balancing the message overhead and delivery ratio.
Guowei Wu 0001, Zuosong Liu, Lin Yao 0001, Jing Deng 0001, Jie Wang 0043
Comput. J.3
2015 A-CACHE: An anchor-based public key caching scheme in large wireless networks
Lin Yao 0001, Jing Deng 0001, Jie Wang 0043, Guowei Wu 0001
Comput. Networks1
2015 Protecting source-location privacy based on multirings in wireless sensor networks
abstract
Summary Wireless sensor networks (WSNs) are expected to be widely deployed to collect data in military and civilian applications. Because of the open nature of WSNs, it is easy for an adversary to eavesdrop sensor communication and to trace packets, causing privacy concern for the sensor devices. The privacy issue, especially location privacy, can be critical for monitoring applications in WSNs. A unique case of location privacy is that of the sources, which are vulnerable of being captured and target attacks. In this paper, we propose a scheme to protect the source–location privacy based on a novel use of multiring topology. To achieve a uniformly distributed traffic pattern throughout the network, the source node selects two random rings each from its external rings and internal rings and a set of two random angles with a sum of 180 degrees for each packet. The packet is sent at one of the angles in each ring. Fake packets are also injected to provide path diversity and to increase attack time, which is defined as the time that the adversary takes to locate the source successfully. These techniques protect the source node from packet tracing attacks as well as traffic analysis attacks. Our analysis and simulations, performed in the NS2 simulator and MATLAB, demonstrate that our proposed scheme can provide better spatial traffic evenness and longer attack time, along with a modest increase of hop count and energy consumption.Copyright © 2013 John Wiley & Sons, Ltd.
Lin Yao 0001, Lin Kang, Fangyu Deng, Jing Deng 0001, Guowei Wu 0001
Concurr. Comput. Pract. Exp.1
2015 Maximizing destructiveness of node capture attack in wireless sensor networks
Chi Lin 0001, Guowei Wu 0001, James Chang Wu Yu, Lin Yao 0001
J. Supercomput.4
2014 Guaranteeing Fault-Tolerant Requirement Load Balancing Scheme Based on VM Migration
abstract
Virtualization is an important enabling technology for many large data centers and cloud computing environments, and virtual machine (VM) migration plays a key role in the load balancing among the hosts of the data center. However, the existing load balancing schemes based on VM migration have serious influence on the fault-tolerant level of the services in the data center, and thus the reliability of the services cannot be guaranteed. In this paper, a novel guaranteeing fault-tolerant requirement load balancing scheme (GFTLBS) is proposed. GFTLBS migrates the VMs to balance the load without violating the fault-tolerant requirement of all services. The simulation results show that the scheme can guarantee the fault-tolerant requirements of all services while keeping the load balance.
Lin Yao 0001, Guowei Wu 0001, Jiankang Ren, Yanwei Zhu
Comput. J.1
2013 Enhancing Efficiency of Node Compromise Attacks in Vehicular Ad-hoc Networks Using Connected Dominating Set
Chi Lin 0001, Guowei Wu 0001, Feng Xia 0001, Lin Yao 0001
Mob. Networks Appl.4
2013 A sensitive data aggregation scheme for body sensor networks based on data hiding
Jiankang Ren, Guowei Wu 0001, Lin Yao 0001
Pers. Ubiquitous Comput.3
2013 Protecting the sink location privacy in wireless sensor networks
Lin Yao 0001, Lin Kang, Pengfei Shang, Guowei Wu 0001
Pers. Ubiquitous Comput.1
2012 Location Anonymity Based on Fake Queries in Continuous Location-Based Services
abstract
The large-scale deployment of location-based services (LBSs) brings about the potential abuse of their clients' personal information. Therefore, location privacy in LBSs is significant. Ensuring location privacy for mobile users is an effort to prevent semi-honest or dishonest service providers from abusing the location information. Though there exist several techniques to preserve location privacy of mobile users, these techniques cannot effectively protect the location privacy in continuous location-based services. In this paper, we propose a location anonymity scheme based on the fake queries in continuous location-based services. To prevent attackers from tracing a mobile user by his continuous queries, some fake continuous queries will be injected by some neighbors. These fake queries can produce equivalent fake paths similar to the user's mobile path, because they are generated according to the user's speed and mobile direction. It is so difficult for the attackers to distinguish the real continuous queries from other fake queries. Security analysis shows that our scheme can resist the continuous queries attack, maximum speed attack and abnormal points attack. Experimental results manifest that our scheme can provide stringent privacy guarantees and is beyond the limitation of existing algorithms based on K-anonymity technique.
Lin Yao 0001, Chi Lin 0001, Guangya Liu, Fangyu Deng, Guowei Wu 0001
ARES1
2012 A Combined Clustering Scheme for Protecting Location Privacy and Query Privacy in Pervasive Environments
abstract
Privacy protection in pervasive environments has attracted great interests in recent years. Two kinds of privacy issues, location privacy and query privacy, are threatening the security of the users. In this paper, a novel combined clustering algorithm for protecting location privacy and query privacy, namely ECC, is proposed. ECC applies a iterative K-means clustering method to group the user requests into clusters for providing location safety while utilizing a hierarchical clustering method for preserving the query privacy. ECC provides the mobile users with their desired anonymity levels and spatial tolerances. Experimental results manifest that the ECC algorithm shows merits in shorter cloaking time and is able to preserve location privacy and query privacy in continuous location based services.
Chi Lin 0001, Guowei Wu 0001, Lin Yao 0001, Zuosong Liu
TrustCom3
2012 Energy efficient ant colony algorithms for data aggregation in wireless sensor networks
Chi Lin 0001, Guowei Wu 0001, Feng Xia 0001, Mingchu Li, Lin Yao 0001, Zhongyi Pei
J. Comput. Syst. Sci.5
2011 ITFBS: adaptive intrusion-tolerant scheme for body sensor networks in smart space applications
abstract
As an important part of the smart space, body sensor networks (BSNs) provide continuous health monitoring and automation assistance for smart environment residents. A high degree of security and reliability for BSN is extremely required. An adaptive and flexible intrusion-tolerant scheme for BSN, namely ITFBS, is proposed. ITFBS dynamically detects intrusions according to the collected intrusion-related information, and it can provide an adaptive intrusion-tolerant strategy with passive replication by utilising two-step threshold-based intrusion detection and replicas classification. The correctness and effectiveness of ITFBS is theoretically proved, and the experimental results show that ITFBS can effectively tolerate intrusions with low power consumption and high adaptability.
Guowei Wu 0001, Jiankang Ren, Lin Yao 0001, Zichuan Xu
IET Commun.3