EDBT 2026 Demo / reviewers in the wild / expert
Jian Wang 0038
dblp:39/449-38
· DBLP profile ↗
57ranked-venue papers
0as first author
27since 2021 · last 2026
0000-0002-8376-5898ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 22 · 8 since 2021Systems, architecture and hardware · 10 · 3 since 2021Computer networks · 9 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 5 since 2021Artificial intelligence and machine learning · 5 · 4 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Decoupled and Privacy-Preserving Key Generation in ABE Under the Minimal Disclosure PrincipleabstractAttribute-Based Encryption (ABE) enables fine-grained access control over outsourced data, but its key generation process typically requires users to disclose their complete attribute sets, introducing significant privacy risks. Existing privacy-preserving approaches—such as those based on zero-knowledge proofs or tightly coupled interactive protocols—suffer from limited scalability, high communication costs, and insufficient support for selective attribute disclosure. To address these limitations, we propose a privacy-enhancing key generation protocol guided by the principle ofMinimal Disclosure, which ensures that users disclose only the minimally necessary subset of attributes required for authorization. Our protocol decouples attribute verification from key issuance: users first obtain cryptographically verifiable attribute tokens, and later issue blinded key requests over selectively chosen attributes. This design enables selective disclosure, supports reusable attribute credentials, and enhances user autonomy. To improve scalability, we introduce a lightweight batch verification mechanism that reduces computation and communication overhead for the attribute authority. We prove that our protocol achieves thebindingandhidingproperties under standard cryptographic assumptions, and we formally verify these guarantees in the symbolic model using the ProVerif tool. In addition, we propose two privacy metrics—AttributeInference Gain (AIG) andPrivacy Gain (PG)—alongside an entropy-based analysis to quantify resistance against attribute inference attacks. Experimental results show that our scheme effectively mitigates inference leakage while offering substantial efficiency gains compared to existing schemes. Youwen Zhu, Xiaodong Yang 0006, Changhee Hahn, Jian Wang 0038, Junbeom Hur |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2026 | GBC-UG: An Advanced Location Data Distribution Estimation Mechanism Under Geo-IndistinguishabilityabstractThe statistical distribution of user geographic location data is widely used in various mobile applications. Although geo-indistinguishability (GI) has emerged as an effective privacy-preserving framework for processing location data, due to the lack of robust perturbation probability calculation and post-processing for eliminating statistical errors caused by random perturbation on user-side data, GI exhibits low accuracy when directly applied to two-dimensional continuous location data distribution estimation. To overcome this, we propose a novel and efficient location data distribution estimation mechanism by improving GI, termed gamma-based circle and uniform grids (GBC-UG). The GBC-UG mechanism consists of two key algorithms: i) the gamma-based circle (GBC) algorithm, which perturbs users' location data and ensures the calculability of perturbation probabilities on the server side, and ii) the uniform grids (UG) algorithm, which post-processes the perturbed data to accurately estimate the original distribution. We provide a theoretical analyses of the upper and lower bounds of the statistical error in distribution estimation and identify optimal parameter values to minimize this error. Experimental results on multiple real-world datasets demonstrate that the proposed GBC-UG mechanism can significantly improve the accuracy of distribution estimation, as well as the prediction accuracy of both the top-k and popularity ranking while guaranteeing user privacy, outperforming existing GI-based approaches. Cong Tang, Youwen Zhu, Ruoyang Chen, Changyan Yi, Jian Wang 0038 |
IEEE Trans. Mob. Comput. | 5 |
| 2025 | Semi-Trusted Edge-Node-Assisted Batch Authentication and Key Agreement Scheme for IIoT
Jian Wang 0038, Yongxuan Zhao |
IEEE Internet Things J. | 2 |
| 2025 | A Verifiable Deletion Protocol for Enhancing Constraints on Public CloudsabstractPublic cloud environments enable multiparty collaboration and data sharing but are also prone to significant security challenges, particularly regarding verifiable data deletion. Existing tightly coupled protocols fall short in ensuring that deletion behaviors are executed honestly, leaving users unable to verify if their data has been truly erased. In this article, we address this critical issue by proposing a novel protocol paradigm to verify deletion behavior in public clouds. Our approach introduces the concepts of uncertainty requests and uncertainty roles, which obfuscate the cloud’s attack perspective by decoupling the relationship between deletion requests and credential responses. This decoupling prevents the cloud from identifying the requester’s identity or linking credentials to specific deletion requests, thereby imposing strict constraints on deletion behavior and enhancing resistance to unauthorized data retention. We formally define the security properties of our paradigm and provide a concrete instantiation of the protocol. Our security proofs demonstrate that the proposed protocol not only verifies deletion behavior but also resists backup attacks, targeting users, data blocks, and deletion requests. For performance, our experiments demonstrate from both computational efficiency and effectiveness evaluation. The results reveal lower computational overhead and superior security, making it highly suitable for practical deployment in public cloud environments. Youwen Zhu, Jian Wang 0038, Yan Jiang 0002 |
IEEE Internet Things J. | 3 |
| 2025 | Lightweight batch authentication and key agreement scheme for IIoT gateways
Jian Wang 0038, Yongxuan Zhao |
J. Syst. Archit. | 2 |
| 2025 | A Lightweight and Generic Access Rights Update Mechanism for Attribute-Based Encryption in cloud storage
Youwen Zhu, Jian Wang 0038, Junbeom Hur |
J. Syst. Archit. | 4 |
| 2025 | GFD: An Effective Defense Against Targeted Poisoning Attacks for Local Differential Privacy Frequency EstimationabstractLocal Differential Privacy (LDP) enables an untrusted server to collect and analyze sensitive data while preserving user privacy. Recent studies reveal that LDP protocols are vulnerable to poisoning attacks, in which an adversary can manipulate aggregated frequencies by controlling malicious users to send forged data to the server. Some countermeasures have been proposed to mitigate poisoning attacks, but they have limitations: 1) requiring prior knowledge of the attack type; 2) exhibiting poor resistance to the adaptive maximal gain attack, i.e., MGA-A. To address the two limitations, in this paper, we propose a novel detection scheme named Group Filter Detection (GFD) to defend against poisoning attacks on LDP frequency estimation. GFD is a universal defense scheme, which can be applied to any LDP frequency estimation protocol without the prior knowledge of attack types, and exhibits high robustness against various poisoning attacks. GFD can first identify the adversary’s target itemset and then filters the suspicious perturbed data (from malicious users). In this way, GFD can exclude malicious data with high confidence, thereby improving the accuracy of LDP frequency estimation. Compared with the existing solutions, experimental results demonstrate the highest effectiveness of GFD. Youwen Zhu, Shaowei Wang 0003, Qiao Xue, Jian Wang 0038 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Indexing dynamic encrypted database in cloud for efficient secure k-nearest neighbor query
Xingxin Li, Youwen Zhu, Jian Wang 0038, Yushu Zhang 0001 |
Frontiers Comput. Sci. | 4 |
| 2023 | Compression-resistant backdoor attack against deep neural networks
Mingfu Xue, Xin Wang 0241, Shichang Sun, Yushu Zhang 0001, Jian Wang 0038, Weiqiang Liu 0001 |
Appl. Intell. | 5 |
| 2023 | Dataset authorization control: protect the intellectual property of dataset via reversible feature space adversarial examples
Mingfu Xue, Yinghao Wu, Yushu Zhang 0001, Jian Wang 0038, Weiqiang Liu 0001 |
Appl. Intell. | 4 |
| 2023 | Fully distributed identity-based threshold signatures with identifiable aborts
Yan Jiang 0002, Youwen Zhu, Jian Wang 0038, Xingxin Li |
Frontiers Comput. Sci. | 3 |
| 2023 | Detecting backdoor in deep neural networks via intentional adversarial perturbations
Mingfu Xue, Yinghao Wu, Zhiyu Wu, Yushu Zhang 0001, Jian Wang 0038, Weiqiang Liu 0001 |
Inf. Sci. | 5 |
| 2023 | DDRM: A Continual Frequency Estimation Mechanism With Local Differential PrivacyabstractMany applications rely on continual data collection to provide real-time information services, e.g., real-time road traffic forecasts. However, the collection of original data brings risks to user privacy. Recently, local differential privacy (LDP) has emerged as a private data collection framework for mass population. However, for continual data collection, existing LDP schemes, e.g., those employing the memoization technique, are known to have privacy leakage on data change points over time. In this paper, we propose a new scheme with stronger privacy guarantee for continual frequency estimation under LDP, namely, Dynamic Difference Report Mechanism (DDRM). In DDRM, we introduce difference trees to capture the data changes over time, which well addresses possible privacy leakage on data change points. As for the utility enhancement, DDRM exploits the common case of no data change in time series and thereby suppresses the consumption of privacy budget in such cases. Meanwhile, an optimal privacy budget allocation scheme is proposed to encourage users to report more data for better estimation accuracy. By both theoretical analysis and experimental evaluations, we show DDRM achieves highly accurate frequency estimation in real time. Qiao Xue, Qingqing Ye 0001, Haibo Hu 0001, Youwen Zhu, Jian Wang 0038 |
IEEE Trans. Knowl. Data Eng. | 5 |
| 2023 | Privacy-Preserving Classification in Multiple Clouds eHealthcareabstractInternet of Things (IoT) is increasingly being used in real life, especially in the eHealthcare field. Among eHealthcare, the application of predicting patients' health status based on their daily activity data which is collected by IoT equipment has attracted extensive attentions and researches. In this application, patients' data which are treated as time-series data are transmitted to healthcare center (HC), then HC makes predictions based on an established classification model. However, making predictions using classification models requires a lot of computing resources, while HC usually cannot afford such numerous calculations. The use of the cloud solves the problem of insufficient computing resources, but it causes another problem, namely the leakage of user privacy. In particular, not only patients' data leak patients' privacy information, the classification model also causes the privacy disclosure of patients and HC. We design a new system model and propose an algorithm which can protect patients' data and classification model from leakage and offload calculation to multiple clouds. Our algorithm can better protect privacy of patients and HC in more complex classification scene, and can effectively reduce the computational cost of the healthcare center Shenqing Wang, Chunpeng Ge 0001, Lu Zhou 0002, Huaqun Wang, Zhe Liu 0001, Jian Wang 0038 |
IEEE Trans. Serv. Comput. | 6 |
| 2022 | Active intellectual property protection for deep neural networks through stealthy backdoor and users' identities authentication
Mingfu Xue, Shichang Sun, Yushu Zhang 0001, Jian Wang 0038, Weiqiang Liu 0001 |
Appl. Intell. | 4 |
| 2022 | PTB: Robust physical backdoor attacks against deep neural networks in real world
Mingfu Xue, Can He, Yinghao Wu, Shichang Sun, Yushu Zhang 0001, Jian Wang 0038, Weiqiang Liu 0001 |
Comput. Secur. | 6 |
| 2022 | Mean estimation over numeric data with personalized local differential privacy
Qiao Xue, Youwen Zhu, Jian Wang 0038 |
Frontiers Comput. Sci. | 3 |
| 2022 | A multi-server biometric authentication scheme based on extended chaotic map for telecare medical information system
Xiao-Ying Zhai, Jian Wang 0038 |
Multim. Tools Appl. | 2 |
| 2022 | One-to-N & N-to-One: Two Advanced Backdoor Attacks Against Deep Learning ModelsabstractIn recent years, deep learning models have been widely deployed in various application scenarios. The training processes of deep neural network (DNN) models are time-consuming, and require massive training data and large hardware overhead. These issues have led to the outsourced training procedure, pre-trained models supplied from third parties, or massive training data from untrusted users. However, a few recent researches indicate that, by injecting some well-designed backdoor instances into the training set, the attackers can create a concealed backdoor in the DNN model. In this way, the attacked model still works normally on the benign inputs, but when a backdoor instance is submitted, some specific abnormal behaviors will be triggered. Existing studies all focus on attacking a single target that triggered by a single backdoor (referred to as One-to-One attack), while the backdoor attacks against multiple target classes, and backdoor attacks triggered by multiple backdoors have not been studied yet. In this article, for the first time, we propose two advanced backdoor attacks, the multi-target backdoor attacks and multi-trigger backdoor attacks: 1) One-to-N attack, where the attacker can trigger multiple backdoor targets by controlling the different intensities of the same backdoor; 2) N-to-One attack, where such attack is triggered only when all the$N$backdoors are satisfied. Compared with existing One-to-One attacks, the proposed two backdoor attacks are more flexible, more powerful and more difficult to be detected. Besides, the proposed backdoor attacks can be applied under the weak attack model, where the attacker has no knowledge about the parameters and architectures of the DNN models. Experimental results show that these two attacks can achieve better or similar performances when injecting a much smaller proportion or same proportion of backdoor instances than those existing One-to-One backdoor attacks. The two attack methods can achieve high attack success rates (up to 100 percent in MNIST dataset and 92.22 percent in CIFAR-10 dataset), while the test accuracy of the DNN model has hardly dropped (as low as 0 percent in LeNet-5 model and 0.76 percent in VGG-16 model), thus will not raise administrator’s suspicions. Further, the two attacks are also evaluated on a large and realistic dataset (Youtube Aligned Face dataset), where the maximum attack success rate reaches 90 percent (One-to-N) and 94 percent (N-to-One), and the accuracy degradation of target face recognition model (VGGFace model) is only 0.05 percent. The proposed One-to-N and N-to-One attacks are demonstrated to be effective and stealthy against two state-of-the-art defense methods. Mingfu Xue, Can He, Jian Wang 0038, Weiqiang Liu 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | VAGA: Towards Accurate and Interpretable Outlier Detection Based on Variational Auto-Encoder and Genetic Algorithm for High-Dimensional DataabstractThe curse of dimensionality in high-dimensional data makes it difficult to capture the abnormality of data points in full data space. To deal with this problem, we propose an outlier detection model based on Variational Autoencoder and Genetic Algorithm for subspace outlier analysis of high-dimensional data (VAGA). The proposed VAGA model constructs a variational autoencoder (VAE) to preliminarily detect outliers. Then the genetic algorithm (GA) is used to search the abnormal subspace of the outliers obtained by the VAE layer to provide a basis for subspace outlier analysis. The subsequent clustering of the abnormal subspaces help filter out the false positives which are fed back to the VAE layer to adjust network weights. The comparative experiments performed on three public benchmark datasets show that the outlier detection results of the proposed VAGA model are highly interpretable and have better accuracy performance than the state-of-the-art outlier detection methods. Jiamu Li, Ji Zhang 0001, Jian Wang 0038, Youwen Zhu, Mohamed Jaward Bah, Gaoming Yang, Yuquan Gan |
IEEE BigData | 3 |
| 2021 | DNN Intellectual Property Protection: Taxonomy, Attacks and Evaluations (Invited Paper)abstractSince the training of deep neural networks (DNN) models requires massive training data, time and expensive hardware resources, the trained DNN model is oftentimes regarded as an intellectual property (IP). Recent researches show that DNN is vulnerable to illegal copy, redistribution and abuse. In order to protect DNN from infringement, a number of DNN IP protection solutions have been proposed in recent years. This paper presents a survey on DNN IP protection methods. First, we propose the first taxonomy for DNN IP protection methods in terms of six attributes: scenario, mechanism, capacity, type, function, and target models. Then, we summarize the existing DNN IP protection works with a focus on the challenges they face as well as their ability to provide proactive protection and resist different levels of attacks. After that, the potential attacks on existing methods from the aspects of model modifications, evasion attacks, and active attacks are analyzed, and a systematic evaluation method for DNN IP protection methods with respect to basic functional metrics, attack-resistance metrics, and customized metrics for different application scenarios is given. Finally, future research opportunities and challenges on DNN IP protection are prospected. Mingfu Xue, Jian Wang 0038, Weiqiang Liu 0001 |
ACM Great Lakes Symposium on VLSI | 2 |
| 2021 | Detect and Remove Watermark in Deep Neural Networks via Generative Adversarial Networks
Shichang Sun, Mingfu Xue, Yushu Zhang 0001, Jian Wang 0038, Weiqiang Liu 0001 |
ISC | 5 |
| 2021 | Robust Backdoor Attacks against Deep Neural Networks in Real Physical WorldabstractDeep neural networks (DNN) have been widely deployed in various applications. However, many researches indicated that DNN is vulnerable to backdoor attacks. The attacker can create a hidden backdoor in target DNN model, and trigger the malicious behaviors by submitting specific backdoor instance. However, almost all the existing backdoor works focused on the digital domain, while few studies investigate the backdoor attacks in real physical world. Restricted to a variety of physical constraints, the performance of backdoor attacks in the real physical world will be severely degraded. In this paper, we propose a robust physical backdoor attack method, PTB (physical transformations for backdoors), to implement the backdoor attacks against deep learning models in the real physical world. Specifically, in the training phase, we perform a series of physical transformations on these injected backdoor instances at each round of model training, so as to simulate various transformations that a backdoor may experience in real world, thus improves its physical robustness. Experimental results on the state-of-the-art face recognition model show that, compared with the backdoor methods that without PTB, the proposed attack method can significantly improve the performance of backdoor attacks in real physical world. Under various complex physical conditions, by injecting only a very small ratio (0.5 %) of backdoor instances, the attack success rate of physical backdoor attacks with the PTB method on VGGFace is 82%, while the attack success rate of backdoor attacks without the proposed PTB method is lower than 11%. Meanwhile, the normal performance of the target DNN model has not been affected. Mingfu Xue, Can He, Shichang Sun, Jian Wang 0038, Weiqiang Liu 0001 |
TrustCom | 4 |
| 2021 | Locally differentially private distributed algorithms for set intersection and union
Qiao Xue, Youwen Zhu, Jian Wang 0038, Xingxin Li, Ji Zhang 0001 |
Sci. China Inf. Sci. | 3 |
| 2021 | SocialGuard: An adversarial example based privacy-preserving technique for social images
Mingfu Xue, Shichang Sun, Zhiyu Wu, Can He, Jian Wang 0038, Weiqiang Liu 0001 |
J. Inf. Secur. Appl. | 5 |
| 2021 | NaturalAE: Natural and robust physical adversarial examples for object detectors
Mingfu Xue, Chengxiang Yuan, Can He, Jian Wang 0038, Weiqiang Liu 0001 |
J. Inf. Secur. Appl. | 4 |
| 2021 | Backdoors hidden in facial features: a novel invisible backdoor attack against face recognition systems
Mingfu Xue, Can He, Jian Wang 0038, Weiqiang Liu 0001 |
Peer-to-Peer Netw. Appl. | 3 |
| 2020 | Intelligent Detection Algorithm Against UAVs' GPS Spoofing AttackabstractUnmanned Aerial Vehicle (UAV) technology is more and more widely used in the field of civil and military information acquisition. GPS plays the most critical part of UAVs' navigation and positioning. However, since the communication channel of the GPS signals is open, attackers can disguise as real GPS signals to launch GPS spoofing attacks on civilian UAVs. At present, the detection schemes for GPS spoofing attacks can be divided into three categories respectively based on encryption and digital signatures, the characteristics of the GPS signal and various external characteristics of UAVs. However, there are some problems in these methods, such as low computing efficiency, difficulty in equipment upgrading, and limited application scenarios. To solve these problems, we propose a new GPS spoofing attack detection method based on Long Short-Term Memory (LSTM) which is a machine learning algorithm. In order to improve the detection ratio, after the machine learning algorithm, we let the UAVs fly according to the path of a specific shape to accurately detect GPS spoofing attacks. This is also the first time machine learning has been used to detect GPS spoofing attacks. According to our algorithm, we can detect GPS spoofing attacks accurately and quickly in a short time. This paper describes in detail the algorithm we proposed to resist GPS spoofing attacks, and the corresponding experiments are carried out in the simulation environment. The experimental results show that our method can quickly and accurately detect UAV GPS spoofing attacks without requiring upgrades to existing equipment. Shenqing Wang, Jian Wang 0038, Chunhua Su, Xinshu Ma |
ICPADS | 2 |
| 2020 | Active DNN IP Protection: A Novel User Fingerprint Management and DNN Authorization Control TechniqueabstractThe training process of deep learning model is costly. As such, deep learning model can be treated as an intellectual property (IP) of the model creator. However, a pirate can illegally copy, redistribute or abuse the model without permission. In recent years, a few Deep Neural Networks (DNN) IP protection works have been proposed. However, most of existing works passively verify the copyright of the model after the piracy occurs, and lack of user identity management, thus cannot provide commercial copyright management functions. In this paper, a novel user fingerprint management and DNN authorization control technique based on backdoor is proposed to provide active DNN IP protection. The proposed method can not only verify the ownership of the model, but can also authenticate and manage the user's unique identity, so as to provide a commercially applicable DNN IP management mechanism. Experimental results on CIFAR-10, CIFAR-100 and Fashion-MNIST datasets show that the proposed method can achieve high detection rate for user authentication (up to 100% in the three datasets). Illegal users with forged fingerprints cannot pass authentication as the detection rates are all 0 % in the three datasets. Model owner can verify his ownership since he can trigger the backdoor with a high confidence. In addition, the accuracy drops are only 0.52%, 1.61 % and -0.65% on CIFAR-10, CIFAR-100 and Fashion-MNIST, respectively, which indicate that the proposed method will not affect the performance of the DNN models. The proposed method is also robust to model fine-tuning and pruning attacks. The detection rates for owner verification on CIFAR-10, CIFAR-100 and Fashion-MNIST are all 100% after model pruning attack, and are 90 %, 83 % and 93 % respectively after model fine-tuning attack, on the premise that the attacker wants to preserve the accuracy of the model. Mingfu Xue, Zhiyu Wu, Can He, Jian Wang 0038, Weiqiang Liu 0001 |
TrustCom | 4 |
| 2020 | Secure Outsourcing Algorithms of Modular Exponentiations in Edge ComputingabstractAs one of the most expensive computations in public-key cryptosystems, modular exponentiation is typically out-sourced to the cloud servers. Traditional cloud-based outsourcing algorithms depend on multiple untrusted servers to guarantee the security, which may lead to vulnerability to the collusion attack. Although recent single-server multiple-requests outsourcing algorithms are more secure, they have to perform multiple requests to the single untrusted server to guarantee the security and checkability of the data, which will incur unacceptable latency and local computational costs. In comparison, the edge computing paradigm enhances security since it has multiple computational nodes, including some highly secure local computational nodes. In this paper, we propose the secure outsourcing algorithm of modular exponentiation for the edge computing paradigm. To address the dilemma that the computational resources of different nodes vary significantly, we design two lightweight algorithms to adaptively separate the modular exponentiation to the nodes based on the computational resources. To guarantee the outsourcing checkability, we propose a protocol verify the result returned from each node. We formally prove the security and checkability of our algorithm and validate the efficiency of our algorithm based on experiments and case studies. Jian Wang 0038 |
TrustCom | 2 |
| 2020 | LOPA: A linear offset based poisoning attack method against adaptive fingerprint authentication system
Mingfu Xue, Can He, Jian Wang 0038, Weiqiang Liu 0001 |
Comput. Secur. | 3 |
| 2020 | A survey of authenticated key agreement protocols for multi-server architecture
Inam ul Haq, Jian Wang 0038, Youwen Zhu, Saad Maqbool |
J. Inf. Secur. Appl. | 2 |
| 2020 | Exploiting Multiple Correlations Among Urban Regions for Crowd Flow Prediction
Jingjing Gu, Chao Ling, Yi Zhuang 0002, Jian Wang 0038 |
J. Comput. Sci. Technol. | 6 |
| 2020 | Secure two-factor lightweight authentication protocol using self-certified public key cryptography for multi-server 5G networks
Inam ul Haq, Jian Wang 0038, Youwen Zhu |
J. Netw. Comput. Appl. | 2 |
| 2020 | Efficient authentication protocol with anonymity and key protection for mobile Internet users
Yan Jiang 0002, Youwen Zhu, Jian Wang 0038, Yong Xiang 0001 |
J. Parallel Distributed Comput. | 3 |
| 2020 | DPAEG: A Dependency Parse-Based Adversarial Examples Generation Method for Intelligent Q&A RobotsabstractRecently, the natural language processing- (NLP-) based intelligent question and answer (Q&A) robots have been used ubiquitously. However, the robustness and security of current Q&A robots are still unsatisfactory, e.g., a slight typo in the user’s question may cause the Q&A robot unable to return the correct answer. In this paper, we propose a fast and automatic test dataset generation method for the robustness and security evaluation of current Q&A robots, which can work in black-box scenarios and thus can be applied to a variety of different Q&A robots. Specifically, we propose a dependency parse-based adversarial examples generation (DPAEG) method for Q&A robots. DPAEG first uses the proposed dependency parse-based keywords extraction algorithm to extract keywords from a question. Then, the proposed algorithm generates adversarial words according to the extracted keywords, which include typos and words that are spelled similarly to the keywords. Finally, these adversarial words are used to generate a large number of adversarial questions. The generated adversarial questions which are similar to the original questions do not affect human’s understanding, but the Q&A robots cannot answer these adversarial questions correctly. Moreover, the proposed method works in a black-box scenario, which means it does not need the knowledge of the target Q&A robots. Experiment results show that the generated adversarial examples have a high success rate on two state-of-the-art Q&A robots, DrQA and Google Assistant. In addition, the generated adversarial examples not only affect the correct answer (top-1) returned by DrQA but also affect the top-k candidate answers returned by DrQA. The adversarial examples make the top-k candidate answers contain fewer correct answers and make the correct answers rank lower in the top-k candidate answers. The human evaluation results show that participants with different genders, ages, and mother tongues can understand the meaning of most of the generated adversarial examples, which means that the generated adversarial examples do not affect human’s understanding. Mingfu Xue, Chengxiang Yuan, Jian Wang 0038, Weiqiang Liu 0001 |
Secur. Commun. Networks | 3 |
| 2020 | Cloud-assisted secure biometric identification with sub-linear search efficiency
Youwen Zhu, Xingxin Li, Jian Wang 0038 |
Soft Comput. | 3 |
| 2019 | Trajectory Protection Scheme Based on Fog Computing and K-anonymity in IoTabstractWith the development of cloud computing technology in the Internet of Things (IoT), the trajectory privacy in location-based services (LBSs) has attracted much attention. Most of the existing work adopts point-to-point and centralized models, which will bring a heavy burden to the user and cause performance bottlenecks. Moreover, previous schemes did not consider both online and offline trajectory protection and ignored some hidden background information. Therefore, in this paper, we design a trajectory protection scheme based on fog computing and k-anonymity for real-time trajectory privacy protection in continuous queries and offline trajectory data protection in trajectory publication. Fog computing provides the user with local storage and mobility to ensure physical control, and k-anonymity constructs the cloaking region for each snapshot in terms of time-dependent query probability and transition probability. In this way, two k-anonymity-based dummy generation algorithms are proposed, which achieve the maximum entropy of online and offline trajectory protection. Security analysis and simulation results indicate that our scheme can realize trajectory protection effectively and efficiently. Jian Wang 0038 |
APNOMS | 2 |
| 2019 | Efficient and secure multi-dimensional geometric range query over encrypted data in cloud
Xingxin Li, Youwen Zhu, Jian Wang 0038, Ji Zhang 0001 |
J. Parallel Distributed Comput. | 3 |
| 2019 | SSL: A Novel Image Hashing Technique Using SIFT Keypoints with Saliency Detection and LBP Feature Extraction against Combinatorial ManipulationsabstractImage hashing schemes have been widely used in content authentication, image retrieval, and digital forensic. In this paper, a novel image hashing algorithm (SSL) by incorporating the most stable keypoints and local region features is proposed, which is robust against various content-preserving manipulations, even multiple combinatorial manipulations. The proposed algorithm combines S_ cale invariant feature transform (SIFT) with S_ aliency detection to extract the most stable keypoints. Then, the L_ ocal binary pattern (LBP) feature extraction method is exploited to generate local region features based on these keypoints. After that, the information of keypoints and local region features are merged into a hash vector. Finally, a secret key is used to randomize the hash vector, which can prevent attackers from forging the image and the hash value. Experimental results demonstrate that the proposed hashing algorithm can identify visually similar images which are under both single and combinatorial content-preserving manipulations, even multiple combinations of manipulations. It can also identify maliciously forged images which are under various content-changing manipulations. The collision probability between hashes of different images is nearly zero. Besides, the evaluation of key-dependent security shows that the proposed scheme is secure that an attacker cannot forge or estimate the correct hash value without the knowledge of the secret key. Mingfu Xue, Chengxiang Yuan, Zhe Liu 0001, Jian Wang 0038 |
Secur. Commun. Networks | 4 |
| 2018 | Improved Differential Fault Analysis on Authenticated Encryption of PAEQ-128
Ruyan Wang, Xiaohan Meng, Yang Li 0001, Jian Wang 0038 |
Inscrypt | 4 |
| 2018 | Detecting Advanced Persistent Threats Based on Entropy and Support Vector Machine
Jiayu Tan, Jian Wang 0038 |
ICA3PP (4) | 2 |
| 2018 | Recovering Memory Access Sequence with Differential Flush+Reload Attack
Zhiwei Yuan, Yang Li 0001, Kazuo Sakiyama, Takeshi Sugawara 0001, Jian Wang 0038 |
ISPEC | 5 |
| 2018 | Towards Optimized DFA Attacks on AES under Multibyte Random Fault ModelabstractDifferential Fault Analysis (DFA) is one of the most practical methods to recover the secret keys from real cryptographic devices. In particular, DFA on Advanced Encryption Standard (AES) has been massively researched for many years for both single-byte and multibyte fault model. For AES, the first proposed DFA attack requires 6 pairs of ciphertexts to identify the secret key under multibyte fault model. Until now, the most efficient DFA under multibyte fault model proposed in 2017 can complete most of the attacks within 3 pairs of ciphertexts. However, we note that the attack is not fully optimized since no clear optimization goal was set. In this work, we introduce two optimization goals as the fewest ciphertext pairs and the least computational complexity. For these goals, we manage to figure out the corresponding optimized key recovery strategies, which further increase the efficiency of DFA attacks on AES. A more accurate security assessment of AES can be completed based on our study of DFA attacks on AES. Considering the variations of fault distribution, the improvement to the attack has been analyzed and verified. Ruyan Wang, Xiaohan Meng, Yang Li 0022, Jian Wang 0038 |
Secur. Commun. Networks | 4 |
| 2018 | On the Soundness and Security of Privacy-Preserving SVM for Outsourcing Data ClassificationabstractRecently, Rahulamathavan et al. propose a privacy preserving scheme for outsourcing SVM classification. Their core contribution is a secure protocol to attain the sign of numbers in encrypted form. In this paper, we observe that Rahulamathavan et al.'s protocol will suffer from some soundness and security problems. Then, we propose a new scheme to securely obtain the encrypted numbers' sign. Theoretical analysis and experiment results show our proposed scheme can not only fix the soundness and security problems, but also achieve higher efficiency. Xingxin Li, Youwen Zhu, Jian Wang 0038, Zhe Liu 0001, Yining Liu 0001, Mingwu Zhang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2017 | A Strict Key Enumeration Algorithm for Dependent Score Lists of Side-Channel Attacks
Yang Li 0022, Jian Wang 0038 |
CARDIS | 4 |
| 2017 | Distributed Set Intersection and Union with Local Differential PrivacyabstractPrivacy-preserving distributed set intersection and union have been widely applied in many scenarios and lots of work has paid attention to the problem. Existing solutions to privacy-preserving set intersection and union are built on secure multiparty computation protocols, which can theoretically solve it, but result in heavy computation and communication overhead. Worse still, most of the existing schemes cannot work once some participant fails. In this paper, we propose two differentially private approaches for distributed set intersection and union, respectively. In our schemes, each data contributor possesses a secret data set and perturbs it by randomized response technique to satisfy local differential privacy. Then the collector gathers all contributors' perturbed data sets and utilizes maximum likelihood estimation to gain an accurate estimation of intersection and union. Compared to existing schemes, the proposed schemes can dramatically reduce computation and communication overhead, and tolerate participant's failure. We formally prove that the proposed schemes satisfy local differential privacy, and leverage extensive experiments to evaluate the proposed approaches. The results indicate that our schemes have low computation and communication complexity, strong robustness and good utility. Qiao Xue, Youwen Zhu, Jian Wang 0038, Xingxin Li |
ICPADS | 3 |
| 2017 | A Virtual Middleboxes Network Placement Algorithm in Multi-tenant Datacenter NetworksabstractHardware middleboxes are widely used in current cloud datacenter to provide network functions such as firewalls, intrusion detection system, load balancers, etc. Unfortunately, they are expensive and unable to offer customized functions for individual tenant. To overcome this issue, there is an increasing interest in deploying software middleboxes to enable flexible security, network access functionality. This paper addresses the software middleboxes placement problem with minimum bandwidth guarantee. We first specify the model of tenants' requirement that specifies the need for virtual machines of application and middleboxes, as well as communication traffic. A virtual middlebox placement algorithm called MISSILE is then proposed to offer predictable network performance for each accepted tenant, and minimize datacenter bandwidth utilization. Extensive simulation results based on current large-scale datacenter networks verify that MISSILE is effective and provides network performance guarantee for tenants. Xiaoliang Wang 0001, Cam-Tu Nguyen, Jian Wang 0038, Zhuzhong Qian, Sanglu Lu |
ICPADS | 4 |
| 2017 | Secure Multi-label Classification over Encrypted Data in Cloud
Xingxin Li, Youwen Zhu, Jian Wang 0038, Zhe Liu 0001 |
ProvSec | 4 |
| 2017 | Reduction in the Number of Fault Injections for Blind Fault Attack on SPN Block CiphersabstractIn 2014, a new fault analysis called blind fault attack (BFA) was proposed, in which attackers can only obtain the number of different faulty outputs without knowing the public data. The original BFA requires 480,000 fault injections to recover a 128-bit AES key. This work attempts to reduce the number of fault injections under the same attack assumptions. We analyze BFA from an information theoretical perspective and introduce a new probability-based distinguisher. Three approaches are proposed for different attack scenarios. The best one realized a 66.8% reduction of the number of fault injections on AES. Yang Li 0022, Zhe Liu 0001, Jian Wang 0038 |
ACM Trans. Embed. Comput. Syst. | 4 |
| 2016 | On efficiently harnessing cloud to securely solve linear regression and other matrix operationsabstractIn this paper, we propose a new efficient solution for securely outsourcing linear regression to a public cloud with robust answer verification. Additionally, we show our construction can be utilized to efficiently and securely outsource other large-scale matrix operations, such as determinant computation. Youwen Zhu, Zhikuan Wang, Jian Wang 0038 |
IWQoS | 4 |
| 2016 | Collusion-resisting secure nearest neighbor query over encrypted data in cloud, revisitedabstractIt is a challenging problem to securely resist the collusion of cloud server and query users while implementing nearest neighbor query over encrypted data in cloud. Recently, CloudBI-II is put forward to support nearest neighbor query on encrypted cloud data, and declared to be secure while cloud server colludes with some untrusted query users. In this paper, we propose an efficient attack method which indicates CloudBI-II will reveal the difference vectors under the collusion attack. Further, we show that the difference vector disclosure will result in serious privacy breach, and thus attain an efficient attack method to break CloudBI-II. Namely, CloudBI-II cannot achieve their declared security. Through theoretical analysis and experiment evaluation, we confirm our proposed attack approach can fast recover the original data from the encrypted data set in CloudBI-II. Finally, we provide an enhanced scheme which can efficiently resist the collusion attack. Youwen Zhu, Zhikuan Wang, Jian Wang 0038 |
IWQoS | 3 |
| 2016 | Secure Naïve Bayesian Classification over Encrypted Data in Cloud
Xingxin Li, Youwen Zhu, Jian Wang 0038 |
ProvSec | 3 |
| 2015 | Fast Secure Scalar Product Protocol with (almost) Optimal Efficiency
Youwen Zhu, Zhikuan Wang, Bilal Hassan, Jian Wang 0038 |
CollaborateCom | 5 |
| 2014 | eXtensible Markup Language access control model with filtering privacy based on matrix storageabstractWith eXtensible Markup Language (XML) becoming a ubiquitous language for data storage and transmission in various domains, effectively safeguarding the XML document containing sensitive information is a critical issue. In this study, the authors propose a new access control model with filtering privacy. Based on the idea of separating the structure and content of the XML document, they provide a method to extract the main structure of the XML document and use matrix to save the structure information, at the same time, the start–end region encoding is used to combine the corresponding structure and content skillfully. These not only save the storage space but also efficiently speed up the search and make it convenient to find the relevant elements, especially the finding of the related content. In order to evaluate the security and efficiency of this model, the security analysis and simulation experiment verify its performance in this work. Lihong Guo, Jian Wang 0038, He Du |
IET Commun. | 2 |
| 2010 | Key Sharing in Hierarchical Wireless Sensor NetworksabstractHierarchical wireless sensor networks (HSNs) have been widely used in many applications, especially in military areas. They usually consist of different types of nodes and behave better in performances and reliability than traditional flat wireless sensor networks (FSNs). In this paper, a novel key pre-distribution scheme is proposed for a three-tier HSN. Shamir's secret sharing technique is implemented in intracluster pairwise key establishment. Compared with existing key management schemes, our scheme guarantees a fully connected network with less storage requirement and communication overhead of sensors. Besides, it substantially improves the network resilience against nodes capture attack and collusion attack. Jian Wang 0038, He Du |
EUC | 2 |
| 2005 | Dynamic Security Service Negotiation to Ensure Security for Information Sharing on the Internet
Zhengyou Xia, Yichuan Jiang, Jian Wang 0038 |
ISI | 3 |