EDBT 2026 Demo / reviewers in the wild / expert
Xukai Zou
dblp:41/592
· DBLP profile ↗
63ranked-venue papers
6as first author
14since 2021 · last 2025
0000-0001-5762-8876ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 39 · 4 first-author · 8 since 2021Security and privacy · 10 · 1 first-author · 2 since 2021Systems, architecture and hardware · 7 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 4 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Vigilante Defender: A Vaccination-based Defense Against Backdoor Attacks on 3D Point Clouds Using Particle Swarm OptimizationabstractBackdoor attacks on 3D Point Clouds (PCs) pose a serious threat by embedding hidden triggers into a subset of the training data. These triggers cause targeted misclassifications at inference time while leaving the model’s behavior unaffected in the absence of triggers, making them stealthy and difficult to detect. In distributed learning settings, where a central trainer aggregates data from multiple sources and offers only black-box access to the model, a single malicious contributor can compromise the model’s integrity if defenses are not in place. We propose a novel client-side defense that empowers individual contributors to act as vigilante defenders. By injecting benign ‘vaccination’ triggers—identified via Particle Swarm Optimization—into their local training data, defenders can proactively neutralize potential backdoors without prior knowledge of their location or structure. Experiments on standard benchmarks with PointNet and DGCNN show our method significantly reduces attack success while preserving classification accuracy, outperforming existing defenses. Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Yucheng Xie, Ryan Hosler |
ICCCN | 3 |
| 2025 | Case Study 2: Mapping between an E-Voting Curriculum and the DHS/NSA CAE Knowledge UnitsabstractTo become a DHS/NSA Center of Academic Excellence in Cyber Defense (CAE-CD), academic institutions must satisfy several specific Knowledge Units (KUs). How they achieve this is up to the institutions. In this case study, we follow the methodology of an earlier work to demonstrate how key parts of an electronic voting (E-voting)-oriented cybersecurity curriculum, proposed by Hostler et al. [4] in 2021, maps into the DHS/NSA KUs supporting the CAE-CD designation, from two aspects: E-voting principle based topics, i.e., from theory and a plug-and-play e-voting system's composing components, i.e., from practice. We grouped CAE-CD KUs into those required as prerequisites, closely related, related/supported, and not covered by the E-voting curriculum. Teachers can then choose which KUs they will use and teach using only the parts of the E-voting-oriented curriculum they deem relevant, and in a depth they find appropriate to their educational objectives, while meeting the requirements of the selected KUs. We conclude with a discussion of how LLMs (Large Language Models) and quantum computing might be added to the E-voting-oriented curriculum. Edwin Antonio Sanchez, Muwei Zheng, Matt Bishop, Xukai Zou |
SIGCSE (1) | 4 |
| 2025 | Can We Trust the Similarity Measurement in Federated Learning?abstractIs it secure to measure the reliability of local models by similarity in federated learning (FL)? This paper delves into an unexplored security threat concerning applying similarity metrics, such as the$L_{2}$norm, Euclidean distance, and cosine similarity, in protecting FL. We first uncover the deficiencies of similarity metrics that high-dimensional local models, including benign and poisoned models, may be evaluated to have the same similarity while being significantly different in the parameter values. We then leverage this finding to devise a novel untargeted model poisoning attack, Faker, which launches the attack by simultaneously maximizing the evaluated similarity of the poisoned local model and the difference in the parameter values. Experimental results based on seven datasets and eight defenses show that Faker outperforms the state-of-the-art benchmark attacks by1.1-9.0Xin reducing accuracy and1.2-8.0Xin saving time cost, which even holds for the case of a single malicious client with limited knowledge about the FL system. Moreover, Faker can degrade the performance of the global model by attacking only once. We also preliminarily explore extending Faker to other attacks, such as backdoor attacks and Sybil attacks. Lastly, we provide a model evaluation strategy, called the similarity of partial parameters (SPP), to defend against Faker. Given that numerous mechanisms in FL utilize similarity metrics to assess local models, this work suggests that we should be vigilant regarding the potential risks of using these metrics. The code will be released soon. Zhilin Wang, Qin Hu 0001, Xukai Zou, Pengfei Hu 0001, Xiuzhen Cheng |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Vaccination Against Backdoor Attacks on Federated Learning Systems
Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Tianchong Gao, Ryan Hosler |
IEEE Trans. Syst. Man Cybern. Syst. | 3 |
| 2024 | Subjective Logic-based Decentralized Federated Learning for Non-IID DataabstractExisting Federated Learning (FL) methods are highly influenced by the training data distribution. In the single global model FL systems, users with highly non-IID data do not improve the global model, and neither does the global model work well on their local data distribution. Even with the clustering-based FL approaches, not all participants get clustered adequately enough for the models to fulfill their local demands. In this work, we design a modified subjective logic-based FL system utilizing the distribution-based similarity among users. Each participant has complete control over their own aggregated model, with handpicked contributions from other participants. The existing clustered model only satisfies a subset of clients, while our individual aggregated models satisfy all the clients. We design a decentralized FL approach, which functions without a trusted central server; the communication and computation overhead is distributed among the clients. We also develop a layer-wise secret-sharing scheme to amplify privacy. We experimentally show that our approach improves the performance of each participant’s aggregated model on their local distribution over the existing single global model and clustering-based approach. Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Tianchong Gao |
ARES | 3 |
| 2024 | Graph Representation Learning on Novel Feature Based Graphs for Network Intrusion DetectionabstractNetwork Intrusions are an ever present threat in the modern age of instant transmission of data over the cyberspace. Ideally, an effective cybersecurity mechanism will detect an attack before it affects a given network. Hence, organizations utilize Network Intrusion Detection Systems (NIDS) to monitor incoming network traffic for all potential misuses. For this research, we present a novel method for aggregating network traffic into a graph for representation learning capable of outperforming existing NIDS in literature. We apply and validate our methods on numerous publically available network flow datasets for demonstrable and concrete performance evaluation. Ryan Hosler, Agnideven Palanisamy Sundar, Xukai Zou, Feng Li 0001, Tianchong Gao |
GLOBECOM | 3 |
| 2024 | Toward Multimodal Vertical Federated Learning: A Traffic Analysis Case StudyabstractFederated Learning (FL) is an emerging subclass of Artificial Intelligence that decentralizes the learning process. Unlike the well-studied Horizontal Federated Learning (HFL), which requires the feature space of all participants to be the same, the newly emerging Vertical Federated Learning (VFL) allows participants to hold different features, provided the sample space is the same. This unique aspect enables VFL to incorporate features from different data modalities, a capability that has not yet been sufficiently explored. Currently, VFL researchers adapt datasets originally used for HFL by splitting the data vertically, whether it is text, tabular, or image data. In this paper, we extend the application of VFL to multimodal datasets, specifically in the field of Intelligent Transportation. We build models by combining local models from participants holding CCTV image datasets and Traffic flow tabular datasets. Due to the absence of suitable existing datasets, we introduce a new dataset, the INDOT traffic dataset, which also supports sequential training across time and distance. Our experiments demonstrate the efficiency of VFL in the multimodal traffic analysis scenario and aim to expand the scope of VFL research. Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Tianchong Gao |
ICCCN | 3 |
| 2023 | Unsupervised Deep Learning for an Image Based Network Intrusion Detection SystemabstractThe most cost-effective method of cybersecurity is prevention. Therefore, organizations and individuals utilize Network Intrusion Detection Systems (NIDS) to inspect network flow for potential intrusions. However, Deep Learning based NIDS still struggle with high false alarm rates and detecting novel and unseen attacks. Therefore, in this paper, we propose a novel NIDS framework based on generating images from feature vectors and applying Unsupervised Deep Learning. For evaluation, we apply this method on four publicly available datasets and have demonstrated an accuracy improvement of up to 8.25 % when compared to Deep Learning models applied to the original feature vectors. Ryan Hosler, Agnideven Palanisamy Sundar, Xukai Zou, Feng Li 0001, Tianchong Gao |
GLOBECOM | 3 |
| 2023 | Advancing Active Authentication for User Privacy and Revocability with BioCapsulesabstractBiometric Facial Authentication has become a pervasive mode of authentication in recent years. With this surge in popularity, concerns over the security and privacy of biometrics-based systems have grown. Therefore, there is a need for a system that can address security and privacy issues while remaining user-friendly and practical. The BioCapsule scheme is a flexible solution that can be embedded in existing biometrics systems in order to provide robust security and privacy protections. While BioCapsules have been evaluated for their static face authentication capabilities, this paper extends the scheme to Active Authentication, where a user is continuously authenticated throughout a session. We use the MOBIO dataset, which contains video recordings of 150 individuals using mobile devices over several sessions, in order to evaluate the BioCapsule scheme within the domain of Active Authentication. We find that the BioCapsule scheme not only performs comparably to baseline, unsecured system performance, but in some cases exceeds baseline performance in terms of False Acceptance Rate, False Rejection Rate, and Equal Error Rate. Through our experiments, we demonstrate that the BioCapsule scheme is a powerful and practical addition to existing biometrics-based Active Authentication systems to provide robust security and privacy protections. Edwin Antonio Sanchez, Anthony Weyer, Joseph Palackal, Kai Wang 0026, Tyler Phillips 0001, Xukai Zou |
MobiHoc | 6 |
| 2023 | Case Study: Mapping an E-Voting Based Curriculum to CSEC2017abstractAn electronic voting (E-voting) oriented cybersecurity curriculum, proposed by Hostler et al. [4] in 2021, leverages the rich security features of E-voting systems and E-voting process to teach essential concepts of cybersecurity. Existing curricular guidelines describe topics in computer security, but do not instantiate them with examples. This is because their goals are different. In this case study, we map the e-voting curriculum into the CSEC2017 curriculum guidelines, to demonstrate how such a mapping is done. Further, this enables teachers to select the parts of the e-voting curriculum most relevant to their classes, by basing the selection on the relevant CSEC2017 learning objectives. We conclude with a brief discussion on generalizing this mapping to other curricular guidelines. Muwei Zheng, Nathan Swearingen, Steven Mills, Croix Gyurek, Matt Bishop, Xukai Zou |
SIGCSE (1) | 6 |
| 2022 | Distributed Swift and Stealthy Backdoor Attack on Federated LearningabstractFederated Learning (FL) provides enhanced privacy over traditional centralized learning; unfortunately, it is also as susceptible to backdoor attacks, just like its centralized counterpart. Conventionally, in data poisoning-based backdoor attacks, all the malicious participants overlay the same single trigger pattern on a subset of their private data during local training. The same trigger is used to induce the backdoor in the otherwise benign global model at inference time. Such single trigger attacks can be detected and removed with relative ease as they undermine the distributed nature of FL. In this work, we focus on building an attack scheme where each batch of malicious clients uses sizably discrete local triggers during local training, with the ability to invoke the attack with a single small inference trigger during the global model testing. The larger size of the trigger pattern ensures prolonged attack longevity even after the termination of the attack. We conduct extensive experiments to show that our approach is far faster, stealthier, and more effective than the centralized trigger approach. The stealthiness of our work is explained using the DeepLIFT visual feature interpretation method. Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Tianchong Gao |
NAS | 3 |
| 2021 | Energy-Efficient Device Selection in Federated Edge LearningabstractDue to the increasing demand from mobile devices for the real-time response of cloud computing services, federated edge learning (FEL) emerges as a new computing paradigm, which utilizes edge devices to achieve efficient machine learning while protecting their data privacy. Implementing efficient FEL suffers from the challenges of devices’ limited computing and communication resources, as well as unevenly distributed datasets, which inspires several existing research focusing on device selection to optimize time consumption and data diversity. However, these studies fail to consider the energy consumption of edge devices given their limited power supply, which can seriously affect the cost-efficiency of FEL with unexpected device dropouts. To fill this gap, we propose a device selection model capturing both energy consumption and data diversity optimization, under the constraints of time consumption and training data amount. Then we solve the optimization problem by reformulating the original model and designing a novel algorithm, named E2DS, to reduce the time complexity greatly. By comparing with two classical FEL schemes, we validate the superiority of our proposed device selection mechanism for FEL with extensive experimental results. Qin Hu 0001, Jianan Chen 0009, Kyubyung Kang, Feng Li 0001, Xukai Zou |
ICCCN | 6 |
| 2021 | Hardware Speculation Vulnerabilities and MitigationsabstractThis paper will discuss speculation vulnerabilities, which arise from hardware speculation, an optimization technique. Unlike many other types of vulnerabilities, these are very difficult to patch completely, and there are techniques developed to mitigate them. We will look at many of the variants of this type of vulnerability. We will look at the techniques mitigating those vulnerabilities and the effectiveness and scope of each. Finally, we will compare and evaluate different vulnerabilities and mitigation techniques and recommend how various mitigation techniques apply to different situations. Nathan Swearingen, Ryan Hosler, Xukai Zou |
MASS | 3 |
| 2021 | Learning Discriminative Features for Adversarial RobustnessabstractDeep Learning models have shown incredible image classification capabilities that extend beyond humans. However, they remain susceptible to image perturbations that a human could not perceive. A slightly modified input, known as an Adversarial Example, will result in drastically different model behavior. The use of Adversarial Machine Learning to generate Adversarial Examples remains a security threat in the field of Deep Learning. Hence, defending against such attacks is a studied field of Deep Learning Security. In this paper, we present the Adversarial Robustness of discriminative loss functions. Such loss functions specialize in either inter-class or intra-class compactness. Therefore, generating an Adversarial Example should be more difficult since the decision barrier between different classes will be more significant. We conducted White-Box and Black-Box attacks on Deep Learning models trained with different discriminative loss functions to test this. Moreover, each discriminative loss function will be optimized with and without Adversarial Robustness in mind. From our experimentation, we found White-Box attacks to be effective against all models, even those trained for Adversarial Robustness, with varying degrees of effectiveness. However, state-of-the-art Deep Learning models, such as Arcface, will show significant Adversarial Robustness against Black-Box attacks while paired with adversarial defense methods. Moreover, by exploring Black-Box attacks, we demonstrate the transferability of Adversarial Examples while using surrogate models optimized with different discriminative loss functions. Ryan Hosler, Tyler Phillips 0001, Xiaoyuan Yu, Agnideven Palanisamy Sundar, Xukai Zou, Feng Li 0001 |
MSN | 5 |
| 2020 | Correlated Participation Decision Making for Federated Edge LearningabstractDriven by the sheer amount of data generated at the network edge and improved computation capabilities of mobile devices, federated edge learning (FEL) emerges as a novel paradigm to achieve edge intelligence with a favorable property of protecting privacy for data generators, i.e., edge devices. However, limited computation and communication resources at the edge make it challenging to execute FEL cost-efficiently in practice. Faced with this challenge, lots of existing work focus on the optimization control during the learning process. However, these research take no precaution in terms of composing the FEL system given heterogeneous candidate devices, which can severely impact the implementation performance. To solve this issue, we define a participation game to capture the dependent but competitive relationships among edge devices with respect to making decisions on whether to participate in a round of FEL. Then we propose a correlated equilibrium based participation decision making strategy to achieve individual rationality and global profit maximization at the same time, which can maintain the efficiency and sustainability of FEL in the long term. Furthermore, we devise an improved method with polynomial computational cost to enhance the scalability of the game-theoretic solution. The performance of our proposed scheme is evaluated through extensive experimental results. Qin Hu 0001, Feng Li 0001, Xukai Zou, Yinhao Xiao |
GLOBECOM | 3 |
| 2020 | Deep Dynamic Clustering of Spam Reviewers using Behavior-Anomaly-based Graph EmbeddingabstractOnline reviews have become an increasingly important factor in the purchase decision of a customer. However, many spammers write deceptive reviews to alter the credibility of a product/service. Often than not, these spammers exhibit group behavior, which can be exploited to differentiate them from authentic reviewers. Such behaviors are found in spammers working together as well as with crowdsourced review manipulators. The existing graph-based spammer detection approaches do not capture the dynamic and nonlinear relationship between the users. This paper aims to address this issue by introducing a method to use a deep structure embedding approach that preserves highly nonlinear structural information along with the dynamic aspects of user reviews to identify and cluster the spam users. It is worth mentioning that, in the experiment with real datasets, our method captures about 92% of all spam reviewers using an unsupervised learning approach. Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Tianchong Gao |
GLOBECOM | 3 |
| 2020 | User-Friendly Design of Cryptographically-Enforced Hierarchical Role-based Access Control ModelsabstractData access control is a critical issue for any organization generating, recording or leveraging sensitive information. The popular Role-based Access Control (RBAC) model is well- suited for large organizations with various groups of personnel, each needing their own set of data access privileges. Unfortunately, the traditional RBAC model does not involve the use of cryptographic keys needed to enforce access control policies and protect data privacy. Cryptography-based Hierarchical Access Control (CHAC) models, on the other hand, have been proposed to facilitate RBAC models and directly enforce data privacy and access controls through the use of key management schemes. Though CHAC models and efficient key management schemes can support large and dynamic organizations, they are difficult to design and maintain without intimate knowledge of symmetric encryption, key management and hierarchical access control models. Therefore, in this paper we propose an efficient algorithm which automatically generates a fine-grained CHAC model based on the input of a highly user-friendly representation of access control policies. The generated CHAC model, the dual-level key management (DLKM) scheme, leverages the collusion-resistant Access Control Polynomial (ACP) and Atallah's Efficient Key Management scheme in order to provide privacy at both the data and user levels. As a result, the proposed model generation algorithm serves to democratize the use of CHAC. We analyze each component of our proposed system and evaluate the resulting performance of the user-friendly CHAC model generation algorithm, as well as the DLKM model itself, along several dimensions. Xiaoyuan Yu, Brandon Haakenson, Tyler Phillips 0001, Xukai Zou |
ICCCN | 4 |
| 2020 | Multi-Armed-Bandit-based Shilling Attack on Collaborative Filtering Recommender SystemsabstractCollaborative Filtering (CF) is a popular recommendation system that makes recommendations based on similar users’ preferences. Though it is widely used, CF is prone to Shilling/Profile Injection attacks, where fake profiles are injected into the CF system to alter its outcome. Most of the existing shilling attacks do not work on online systems and cannot be efficiently implemented in real-world applications. In this paper, we introduce an efficient Multi-Armed-Bandit-based reinforcement learning method to practically execute online shilling attacks. Our method works by reducing the uncertainty associated with the item selection process and finds the most optimal items to enhance attack reach. Such practical online attacks open new avenues for research in building more robust recommender systems. We treat the recommender system as a black box, making our method effective irrespective of the type of CF used. Finally, we also experimentally test our approach against popular state-of-the-art shilling attacks. Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Qin Hu 0001, Tianchong Gao |
MASS | 3 |
| 2019 | Koinonia: verifiable e-voting with long-term privacyabstractDespite years of research, many existing e-voting systems do not adequately protect voting privacy. In most cases, such systems only achieve "immediate privacy", that is, they only protect voting privacy against today's adversaries, but not against a future adversary, who may possess better attack technologies like new cryptanalysis algorithms and/or quantum computers. Previous attempts at providing long-term voting privacy (dubbed "everlasting privacy" in the literature) often require additional trusts in parties that do not need to be trusted for immediate privacy. Huangyi Ge, Sze Yiu Chau, Victor E. Gonsalves, Huian Li, Tianhao Wang 0001, Xukai Zou, Ninghui Li 0001 |
ACSAC | 6 |
| 2019 | Enhancing Biometric-Capsule-based Authentication and Facial Recognition via Deep LearningabstractIn recent years, developers have used the proliferation of biometric sensors in smart devices, along with recent advances in deep learning, to implement an array of biometrics-based authentication systems. Though these systems demonstrate remarkable performance and have seen wide acceptance, they present unique and pressing security and privacy concerns. One proposed method which addresses these concerns is the elegant, fusion-based BioCapsule method. The BioCapsule method is provably secure, privacy-preserving, cancellable and flexible in its secure feature fusion design. In this work, we extend BioCapsule to face-based recognition. Moreover, we incorporate state-of-art deep learning techniques into a BioCapsule-based facial authentication system to further enhance secure recognition accuracy. We compare the performance of an underlying recognition system to the performance of the BioCapsule-embedded system in order to demonstrate the minimal effects of the BioCapsule scheme on underlying system performance. We also demonstrate that the BioCapsule scheme outperforms or performs as well as many other proposed secure biometric techniques. Tyler Phillips 0001, Xukai Zou, Feng Li 0001, Ninghui Li 0001 |
SACMAT | 2 |
| 2018 | Local Differential Privately Anonymizing Online Social Networks Under HRG-Based ModelabstractFollowing the trend of online social networks (OSNs) data sharing and publishing, users raise serious concerns on OSN privacy. Differential privacy is a mechanism to anonymize sensitive data. It employs graph abstraction models, such as the hierarchical random graph (HRG) model, to extract graph features and then add sufficient noise. However, the noise amount, determined by the sensitivity, is usually proportional to the size of the whole network. Therefore, achieving global differential privacy may harm the utility of releasing graphs. In this paper, we define the notion of group-based local differential privacy. In particular, by resolving the network into 1-neighborhood graphs and applying HRG-based methods, our scheme preserves differential privacy and reduces the noise scale on the local graphs. By deploying the grouping algorithm, our scheme abandons the attempt to anonymize every relationship to be ordinary, but we focus on the similarities in HRG models. In the final released graph, each individual user in one group is not distinguishable, which greatly enhances the OSN privacy. We experimentally evaluate our approach on three real-world OSNs. It produces synthetic graphs that are more closely matched with the originals compared with the existing differential-privacy results. Tianchong Gao, Feng Li 0001, Yu Chen 0002, Xukai Zou |
IEEE Trans. Comput. Soc. Syst. | 4 |
| 2017 | A Cancellable and Privacy-Preserving Facial Biometric Authentication SchemeabstractIn recent years, biometric, or "who you are," authentication has grown rapidly in acceptance and use. Biometric authentication offers users the convenience of not having to carry a password, PIN, smartcard, etc. Instead, users will use their inherent biometric traits for authentication and, as a result, risk their biometric information being stolen. The security of users’ biometric information is of critical importance within a biometric authentication scheme as compromised data can reveal sensitive information: race, gender, illness, etc. A cancellable biometric scheme, the "BioCapsule" scheme, proposed by researchers from Indiana University Purdue University Indianapolis, aims to mask users’ biometric information and preserve users’ privacy. The BioCapsule scheme can be easily embedded into existing biometric authentication systems, and it has been shown to preserve user-privacy, be resistant to several types of attacks, and have minimal effects on biometric authentication system accuracy.In this research we present a facial authentication system which employs several cutting-edge techniques. We tested our proposed system on several face databases, both with and without the BioCapsule scheme being embedded into our system. By comparing our results, we quantify the effects the BioCapsule scheme, and its security benefits, have on the accuracy of our facial authentication system. Tyler Phillips 0001, Xukai Zou, Feng Li 0001 |
MASS | 2 |
| 2017 | Preserving Local Differential Privacy in Online Social Networks
Tianchong Gao, Feng Li 0001, Yu Chen 0002, Xukai Zou |
WASA | 4 |
| 2016 | Survey of return-oriented programming defense mechanismsabstractA prominent software security violation-buffer overflow attack has taken various forms and poses serious threats until today. One such vulnerability is return-oriented programming attack. An return-oriented programming attack circumvents the dynamic execution prevention, which is employed in modern operating systems to prevent execution of data segments, and attempts to execute unintended instructions by overwriting the stack exploiting the buffer overflow vulnerability. Numerous defense mechanisms have been proposed in the past few years to mitigate/prevent the attack – compile time methods that add checking logic to the program code before compilation, dynamic methods that monitor the control-flow integrity during execution and randomization methods that aim at randomizing instruction locations. This paper discusses (i) these different static, dynamic, and randomization techniques proposed recently and (ii) compares the techniques based on their effectiveness and performances. Yefeng Ruan, Sivapriya Kalyanasundaram, Xukai Zou |
Secur. Commun. Networks | 3 |
| 2015 | Temporal coverage based content distribution in heterogeneous smart device networksabstractThe present work studies content distribution in heterogeneous smart device networks, in which all smartphones/ tablets can communicate through proximity channels such as Bluetooth/NFC/Wi-Fi Direct when they are in proximity, but only some devices have the cellular data communication capability. In the context of recent applications of content distribution in smart device networks such as mobile offloading and enterprise network defense prioritization, we propose a temporal coverage based scheme that exploits nodes' encounter regularity and content's delivery delay tolerance to reduce content delivery costs. Using kernel-density estimation (KDE) on the readily available proximity encounter records, we propose a network structural property, T-covering set, and a corresponding localized algorithm that distributedly elects a T-covering set from the underlying network. Using real Bluetooth encounter traces, we demonstrate that temporal coverage based content distribution using T-covering set can significantly reduce content delivery cost with minimal delay and no sacrifice in coverage. Wei Peng 0007, Feng Li 0001, Xukai Zou |
ICC | 3 |
| 2015 | Enhancing and Implementing Fully Transparent Internet VotingabstractVoting over the internet has been the focus of significant research with the potential to solve many problems. Current implementations typically suffer from a lack of transparency, where the connection between vote casting and result tallying is seen as a black box by voters. A new protocol was recently proposed that allows full transparency, never obfuscating any step of the process, and splits authority between mutually-constraining conflicting parties. Achieving such transparency brings with it challenging issues. In this paper we propose an efficient algorithm for generating unique, anonymous identifiers (voting locations) that is based on the Chinese Remainder Theorem, we extend the functionality of an election to allow for races with multiple winners, and we introduce a prototype of this voting system implemented as a multiplatform web application. Kevin Butterfield, Huian Li, Xukai Zou, Feng Li 0001 |
ICCCN | 3 |
| 2014 | A moving-target defense strategy for Cloud-based services with heterogeneous and dynamic attack surfacesabstractDue to deep automation, the configuration of many Cloud infrastructures is static and homogeneous, which, while easing administration, significantly decreases a potential attacker's uncertainty on a deployed Cloud-based service and hence increases the chance of the service being compromised. Moving-target defense (MTD) is a promising solution to the configuration staticity and homogeneity problem. This paper presents our findings on whether and to what extent MTD is effective in protecting a Cloud-based service with heterogeneous and dynamic attack surfaces — these attributes, which match the reality of current Cloud infrastructures, have not been investigated together in previous works on MTD in general network settings. We 1) formulate a Cloud-based service security model that incorporates Cloud-specific features such as VM migration/snapshotting and the diversity/compatibility of migration, 2) consider the accumulative effect of the attacker's intelligence on the target service's attack surface, 3) model the heterogeneity and dynamics of the service's attack surfaces, as defined by the (dynamic) probability of the service being compromised, as an S-shaped generalized logistic function, and 4) propose a probabilistic MTD service deployment strategy that exploits the dynamics and heterogeneity of attack surfaces for protecting the service against attackers. Through simulation, we identify the conditions and extent of the proposed MTD strategy's effectiveness in protecting Cloud-based services. Namely, 1) MTD is more effective when the service deployment is dense in the replacement pool and/or when the attack is strong, and 2) attack-surface heterogeneity-and-dynamics awareness helps in improving MTD's effectiveness. Wei Peng 0007, Feng Li 0001, Chin-Tser Huang, Xukai Zou |
ICC | 4 |
| 2014 | A taxonomy and comparison of remote voting schemesabstractRemote voting has been an active research field for application of cryptographic techniques in the last two decades with many schemes and systems in publication. In this paper we present an overview of recent efforts in developing voting schemes and security models that involve a variety of real world constraints to ensure election integrity. We classify voting schemes based on their primary cryptographic techniques. We analyze recent typical schemes and systems against the basic and counter attack requirements with brief description. Such analysis shows difference among these security requirements and aids in design of future schemes. Our conclusion is provided regarding suitability of a particular voting system/scheme under various conditions. Huian Li, Abhishek Reddy Kankanala, Xukai Zou |
ICCCN | 3 |
| 2014 | Assurable, transparent, and mutual restraining e-voting involving multiple conflicting partiesabstractE-voting techniques and systems have not been widely accepted and deployed by society due to various concerns and problems. One particular issue associated with many existing e-voting techniques is the lack of transparency, leading to the failure to deliver voter assurance. In this work, we propose an assurable, transparent, and mutual restraining e-voting protocol that exploits the existing two-party political dynamics in the US. The proposed e-voting protocol consists of three original technical contributions — universal verifiable voting vector, forward and backward mutual lock voting, and in-process check and enforcement — that, in combination, resolves the apparent conflicts in voting such as anonymity vs. accountability and privacy vs. verifiability. Especially, the trust is split equally among tallying authorities who have conflicting interests and will technically restrain each other. The voting and tallying processes are transparent to voters and any third party, which allow any voter to verify that his vote is indeed counted and also allow any third party to audit the tally. Xukai Zou, Huian Li, Yan Sui, Wei Peng 0007, Feng Li 0001 |
INFOCOM | 1 |
| 2014 | Analysis and Implementation of Internet Based Remote VotingabstractVoting over the internet has been a topic of great interest for many years. We researched E-Voting: its theory, its practice, and its examples. We found many potential problems with E-Voting; concerns both for election integrity and voter privacy. We found many strengths of E-Voting as well; advantages it has over traditional, booth-based voting systems such as guaranteed accuracy, resilience against corruption, and strength against unauthorized voting. As well as the concept of E-Voting, three real-world E-Voting systems were researched and an implementation of the most recent was developed. Kevin Butterfield, Xukai Zou |
MASS | 2 |
| 2014 | A Two-Stage Deanonymization Attack against Anonymized Social NetworksabstractDigital traces left by users of online social networking services, even after anonymization, are susceptible to privacy breaches. This is exacerbated by the increasing overlap in user-bases among various services. To alert fellow researchers in both the academia and the industry to the feasibility of such an attack, we propose an algorithm, Seed-and-Grow, to identify users from an anonymized social graph, based solely on graph structure. The algorithm first identifies a seed subgraph, either planted by an attacker or divulged by a collusion of a small group of users, and then grows the seed larger based on the attacker's existing knowledge of the users' social relations. Our work identifies and relaxes implicit assumptions taken by previous works, eliminates arbitrary parameters, and improves identification effectiveness and accuracy. Simulations on real-world collected data sets verify our claim. Wei Peng 0007, Feng Li 0001, Xukai Zou, Jie Wu 0001 |
IEEE Trans. Computers | 3 |
| 2014 | Design and Analysis of a Highly User-Friendly, Secure, Privacy-Preserving, and Revocable Authentication MethodabstractA large portion of system breaches are caused by authentication failure, either during the login process or in the post-authentication session; these failures are themselves related to the limitations associated with existing authentication methods. Current authentication methods, whether proxy based or biometrics based, are not user-centric and/or endanger users’ (biometric) security and privacy. In this paper, we propose a biometrics based user-centric authentication approach. This method involves introducing a reference subject (RS), securely fusing the user’s biometrics with the RS, generating a BioCapsule (BC) from the fused biometrics, and employing BCs for authentication. Such an approach is user friendly, identity bearing yet privacy-preserving, resilient, and revocable once a BC is compromised. It also supports “one-click sign-on” across systems by fusing the user’s biometrics with a distinct RS on each system. Moreover, active and non-intrusive authentication can be automatically performed during post-authentication sessions. We formally prove that the secure fusion based approach is secure against various attacks. Extensive experiments and detailed comparison with existing approaches show that its performance (i.e., authentication accuracy) is comparable to existing typical biometric approaches and the new BC based approach also possesses many desirable features such as diversity and revocability. Yan Sui, Xukai Zou, Yingzi Du, Feng Li 0001 |
IEEE Trans. Computers | 2 |
| 2014 | Behavioral Malware Detection in Delay Tolerant NetworksabstractThe delay-tolerant-network (DTN) model is becoming a viable communication alternative to the traditional infrastructural model for modern mobile consumer electronics equipped with short-range communication technologies such as Bluetooth, NFC, and Wi-Fi Direct. Proximity malware is a class of malware that exploits the opportunistic contacts and distributed nature of DTNs for propagation. Behavioral characterization of malware is an effective alternative to pattern matching in detecting malware, especially when dealing with polymorphic or obfuscated malware. In this paper, we first propose a general behavioral characterization of proximity malware which based on naive Bayesian model, which has been successfully applied in non-DTN settings such as filtering email spams and detecting botnets. We identify two unique challenges for extending Bayesian malware detection to DTNs ("insufficient evidence versus evidence collection risk" and "filtering false evidence sequentially and distributedly"), and propose a simple yet effective method, look ahead, to address the challenges. Furthermore, we propose two extensions to look ahead, dogmatic filtering, and adaptive look ahead, to address the challenge of "malicious nodes sharing false evidence." Real mobile network traces are used to verify the effectiveness of the proposed methods. Wei Peng 0007, Feng Li 0001, Xukai Zou, Jie Wu 0001 |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2013 | Smartphone strategic sampling in defending enterprise network securityabstractSmartphones have made their inroads in enterprise environment, manifested in the Bring Your Own Device (BYOD) policy: More employees are bringing their own smartphones to work and are using them to access enterprise information assets. The dilemma between responsiveness to security incidents and convenience/cost-effectiveness demands BYOD security solutions beyond the straightforward all-inclusive full-scanning or uniformly random sampling approaches. In this paper, we propose a carefully planned but otherwise random, or strategic, sampling approach out of this dilemma. Strategic sampling provides a balance between security responsiveness and cost effectiveness by identifying and periodically sampling those representative smartphones (security-wise). We validate the efficiency and effectiveness of the proposed strategic sampling via simulations driven by publicly available, real-world collected traces. Feng Li 0001, Wei Peng 0007, Chin-Tser Huang, Xukai Zou |
ICC | 4 |
| 2013 | The Virtue of Patience: Offloading Topical Cellular Content through Opportunistic LinksabstractMobile data offloading is an approach to alleviating overloaded cellular traffic through alternative communication technologies on smartphones. Inspired by the prospect of spontaneous, peer-assisted, bulk data transfer through NFC or Wi-Fi Direct between proximate users' smartphones, we propose a model for mobile data offloading through the opportunistic proximity (e.g., Wi-Fi Direct) links with bounded content delivery delay and differential interests in content. Unlike the previous formulation of mobile data offloading as a target-set selection problem, which, essentially, asks the question "who (will download the content through the cellular link)," we ask "who" and "when." We present methods for individual users to locally estimate (their and their acquaintances') topological importance on the opportunistic proximity-link-based networks and aggregated interests in content. These factors are consolidated into a time-dependent function that embodies the concept of users' patience for the content. Each individual user, then, periodically make a probabilistic cellular download decision based on its patience at that time. Our motivation and insights are: 1) Involving topologically important, but otherwise disinterested, users in downloading and forwarding content helps improve offloading efficiency, 2) situation awareness embodied in the time-dependent patience function is desirable, since it allows users to react to hard-to-predict contact opportunities on the fly. Through trace-driven simulations, we corroborate our insights, and demonstrate the effectiveness of our proposed method in reducing cellular costs. Wei Peng 0007, Feng Li 0001, Xukai Zou, Jie Wu 0001 |
MASS | 3 |
| 2012 | Seed and Grow: An attack against anonymized social networksabstractDigital traces left by a user of an online social networking service can be abused by a malicious party to compromise the person's privacy. This is exacerbated by the increasing overlap in user-bases among various services. In this paper, we propose an algorithm, Seed and Grow, to identify users from an anonymized social graph based solely on graph structure. The algorithm first identifies a seed sub-graph, either planted by an attacker or divulged by collusion of a small group of users, and then grows the seed larger based on the attacker's existing knowledge of the users' social relations. Our work identifies and relaxes implicit assumptions taken by previous works, eliminates arbitrary parameters, and improves identification effectiveness and accuracy. Experiments on real-world collected datasets further corroborate our expectation and claim. Wei Peng 0007, Feng Li 0001, Xukai Zou, Jie Wu 0001 |
SECON | 3 |
| 2012 | A privacy-preserving social-aware incentive system for word-of-mouth advertisement dissemination on smart mobile devicesabstractThe recent penetration of smart mobile devices into the consumer market sets a stage for novel network applications. In particular, we envision a paradigm shift in the commercial advertising model facilitated by the widespread uses of these devices: advertisements circulate in a word-of-mouth fashion among device users and reach potential customers based on the users' knowledge about their contacts. In this paper, we identify two major challenges baffling the deployment of such an application: users' selfishness and their privacy concerns. We address the selfishness issue by proposing an incentive scheme which aligns users' interest with that of advertisers in a way that the users are willing to fully explore their social knowledge for effective advertisement deliveries - the emphasis is not only on users' participation but also on the extent and effectiveness of their contributions. We address the privacy concerns by designing a privacy-preserving evidence-collection mechanism, on which the incentive scheme is based. In addition, our design is 1) appealing to advertisers by guaranteeing effectiveness and controllability of the incentive dispensing and 2) robust against users' misbehaviors. We perceive incentive and enforcement as the keys to unlock the power of users' collective intelligence for effective information dissemination. Wei Peng 0007, Feng Li 0001, Xukai Zou, Jie Wu 0001 |
SECON | 3 |
| 2012 | Secure and privacy-preserving biometrics based active authenticationabstractUser authentication is critical in preventing system breaches. Existing authentication approaches usually do a onetime log-in authentication, but rarely incorporate mechanisms to differentiate the initial log-in user and the user who is currently taking control of the system, which may cause post-authentication breaches. In this paper, we study user authentication for both login session and post-authentication session and propose a biometrics based active authentication approach. Moreover, concerning the usage of biometrics, the system is biometrics-secure and privacy-preserving. Security analysis and experimental results prove that the proposed approach is secure, resilient to various attacks and effective. Yan Sui, Xukai Zou, Yingzi Du, Feng Li 0001 |
SMC | 2 |
| 2012 | Active User Authentication for Mobile Devices
Yan Sui, Xukai Zou, Feng Li 0001, Yingzi Du |
WASA | 2 |
| 2011 | Biometrics-Based Authentication: A New ApproachabstractAuthentication is a fundamental issue to any trust-oriented computing system and also a critical part in many security protocols. Performing authentication is notoriously difficult. Biometrics has been widely used and adopted as a promising authentication method due to its advantages over some existing methods, particularly, its resistance to losses incurred by theft of passwords and smart cards. However, biometrics introduces its own challenges, such as being irreplaceable once compromised. Moreover, the use of biometrics introduces privacy concern. In this paper, we propose a simple yet effective biometrics-based authentication solution. The proposed approach introduces new constructs - Reference Subject and Biometric Capsule, and stores the ``difference'' (called Biometric Capsule) between the user and the Reference Subject for authentication without revealing a user's original biometric information. This approach supports replaceability and protect users' privacy. Moreover, the proposed approach creates more advantages: (a) being user-friendly without any additional burden on users and possessing one-for-all power; (b) being generic enough to be applied to various biometrics (e.g., fingerprint, face, iris) or combinations of them; and (c) being adaptive in terms of security and privacy to fit different authentication models, application requirements, available resources, and trusted or non-fully-trusted environments. The experimental results on iris validate its performance and prove it a practical mechanism. Yan Sui, Xukai Zou, Yingzi Du |
ICCCN | 2 |
| 2011 | A New Approach to Weighted Multi-Secret SharingabstractSecret sharing is important in information and network security and has broad applications in the real world. Since an elegant secret sharing mechanism was first proposed by Shamir in 1979, many schemes have appeared in literature. These schemes deal with either single or multiple secrets and their shares have either the same weight or different weights. Weighted shares mean that different shares have different capabilities in recovering the secret(s) -- a more (less) weighted share needs fewer (more) other shares to recover the secret(s). In this paper, we identify a direct relation between the length (i.e., the number of bits) and the weight of shares and, based on this relation, present a new Chinese Remainder Theorem (CRT) based weighted multiple secret sharing scheme. This scheme can also be naturally applied to other cases such as sharing a single secret with same-weight shares and is remarkably simple and easy to implement. Compared to both Shamir's scheme and Mignotte's scheme -- the representative of existing CRT based secret sharing schemes, the new scheme is more efficient than both schemes in share computation and more efficient than Shamir's scheme (and as efficient as Mignotte's scheme) in secret recovery. One prominent advantage of the new scheme is that the sizes of shares can vary distantly to fit different requirements and constraints of various devices such as sensors, PDAs, cell phones, iPads, hence, the new scheme is able to apply to broader applications involving wireless/sensor networks and pervasive computing. Xukai Zou, Fabio Maino, Elisa Bertino, Yan Sui, Kai Wang 0026, Feng Li 0001 |
ICCCN | 1 |
| 2011 | Behavioral Detection and Containment of Proximity Malware in Delay Tolerant NetworksabstractWith the universal presence of short-range connectivity technologies (e.g., Bluetooth and, more recently, Wi-Fi Direct) in the consumer electronics market, the delay-tolerant-network (DTN) model is becoming a viable alternative to the traditional infrastructural model. Proximity malware, which exploits the temporal dimension and distributed nature of DTNs in self-propagation, poses threats to users of new technologies. In this paper, we address the proximity malware detection and containment problem with explicit consideration for the unique characteristics of DTNs. We formulate the malware detection process as a decision problem under a general behavioral malware characterization framework. We analyze the risk associated with the decision problem and design a simple yet effective malware containment strategy, look-ahead, which is distributed by nature and reflects an individual node's intrinsic trade-off between staying connected (with other nodes) and staying safe (from malware). Furthermore, we consider the benefits of sharing assessments among directly connected nodes and address the challenges derived from the DTN model to such sharing in the presence of liars (i.e., malicious nodes sharing false assessments) and defectors (i.e., good nodes that have turned malicious due to malware infection). Real mobile network traces are used to verify our analysis. Wei Peng 0007, Feng Li 0001, Xukai Zou, Jie Wu 0001 |
MASS | 3 |
| 2011 | New threats to health data privacyabstractBACKGROUND: Along with the rapid digitalization of health data (e.g. Electronic Health Records), there is an increasing concern on maintaining data privacy while garnering the benefits, especially when the data are required to be published for secondary use. Most of the current research on protecting health data privacy is centered around data de-identification and data anonymization, which removes the identifiable information from the published health data to prevent an adversary from reasoning about the privacy of the patients. However, published health data is not the only source that the adversaries can count on: with a large amount of information that people voluntarily share on the Web, sophisticated attacks that join disparate information pieces from multiple sources against health data privacy become practical. Limited efforts have been devoted to studying these attacks yet. RESULTS: We study how patient privacy could be compromised with the help of today's information technologies. In particular, we show that private healthcare information could be collected by aggregating and associating disparate pieces of information from multiple online data sources including online social networks, public records and search engine results. We demonstrate a real-world case study to show user identity and privacy are highly vulnerable to the attribution, inference and aggregation attacks. We also show that people are highly identifiable to adversaries even with inaccurate information pieces about the target, with real data analysis. CONCLUSION: We claim that too much information has been made available electronic and available online that people are very vulnerable without effective privacy protection. Fengjun Li, Xukai Zou, Peng Liu 0005, Jake Yue Chen |
BMC Bioinform. | 2 |
| 2010 | Fuzzy Closeness-Based Delegation Forwarding in Delay Tolerant NetworksabstractDelay tolerant networks (DTNs) are envisioned to provide promising applications and services. One critical issue in DTNs is efficiently forwarding the messages within the delay requirements while avoiding the cost associated with blind flooding. To guide the forwarding process, nodes can evaluate their relationships with each other, in terms of ``closeness'', which summarizes both temporal and spacial information, based on contact history. However, due to the uncertainty in nodal mobility, the contact history usually contains fuzziness and incomplete information. In this paper, we first define and utilize a fuzzy trust evaluation system for nodes to summarize their relationships to other nodes, in terms of closeness. We then propose the fuzzy clustering to organize nodes into overlapped fuzzy communities based on nodes' evaluations of closeness. On top of the fuzzy communities, a novel fuzzy-weight-based delegation forwarding scheme is proposed to propagate the messages into all communities while avoiding repeated forwarding in the same community. Extensive simulation results based on real traces are presented to support the effectiveness of our scheme. Feng Li 0001, Yinying Yang, Jie Wu 0001, Xukai Zou |
NAS | 4 |
| 2010 | An efficient scheme for removing compromised sensor nodes from wireless sensor networksabstractAbstract The goal of key management is to establish the required keys between sensor nodes which exchange data. A key management protocol includes two aspects: key distribution and key revocation. Key distribution has been extensively studied in the context of sensor networks. However, key revocation has received relatively little attention. In this paper, we first review and summarize the current key revocation schemes for sensor networks. Then, we present an efficient scheme, KeyRev, for removing compromised sensor nodes from a wireless sensor network (WSN). Unlike most proposed key revocation schemes focusing on removing the compromised keys on the sensor nodes, the KeyRev scheme uses key update techniques to obsolesce the keys owned by the compromised sensor nodes and thus remove the nodes from the network. We analyze the security of the KeyRev scheme and compare its performance against another centralized key revocation scheme and a distributed key revocation scheme. Our analyses show that the KeyRev scheme is secure in spite of not removing the pre‐distributed key materials at compromised sensor nodes. Simulation results also indicate that the KeyRev scheme is scalable and performs very well compared with other key revocation schemes in WSNs. Copyright © 2008 John Wiley & Sons, Ltd. Byrav Ramamurthy, Xukai Zou, Yuyan Xue |
Secur. Commun. Networks | 3 |
| 2009 | An Efficient Time-Bound Access Control Scheme for Dynamic Access HierarchyabstractEmbedding user subscription time into cryptographic key generation and assignment for hierarchical access control has raised tremendous interest among researchers and practitioners in multicast, broadcast, and secure group communication fields. During the subscription period, a user of a higher class can compute the (time-bound) keys of his/her own class and also derive the keys of all its descendant classes in the access hierarchy. However, after the subscription expires, the user cannot compute/derive the keys. Unfortunately, due to the inclusion of time in the keys, existing schemes either suffer from (colluding) attacks or are only applicable to static access hierarchies. In this paper, we propose a new key generation and assignment scheme for this kind of time-bound hierarchy access control. The new scheme is able not only to prevent colluding attacks but also to support dynamics of access hierarchies in a simple and efficient way. Yan Sui, Fabio Maino, Kai Wang 0026, Xukai Zou |
MSN | 5 |
| 2008 | A security framework for wireless sensor networks utilizing a unique session keyabstractKey management is a core mechanism to ensure the security of applications and network services in wireless sensor networks. It includes two aspects: key distribution and key revocation. Many key management protocols have been specifically designed for wireless sensor networks. However, most of the key management protocols focus on the establishment of the required keys or the removal of the compromised keys. The design of these key management protocols does not consider the support of higher level security applications. When the applications are integrated later in sensor networks, new mechanisms must be designed. In this paper, we propose a security framework, uKeying, for wireless sensor networks. This framework can be easily extended to support many security applications. It includes three components: a security mechanism to provide secrecy for communications in sensor networks, an efficient session key distribution scheme, and a centralized key revocation scheme. The proposed framework does not depend on a specific key distribution scheme and can be used to support many security applications, such as secure group communications. Our analysis shows that the framework is secure, efficient, and extensible. The simulation and results also reveal for the first time that a centralized key revocation scheme can also attain a high efficiency. Byrav Ramamurthy, Yuyan Xue, Xukai Zou |
BROADNETS | 4 |
| 2008 | A Practical and Flexible Key Management Mechanism For Trusted Collaborative ComputingabstractTrusted collaborative computing (TCC) is a new research and application paradigm. Two important challenges in such a context are represented by secure information transmission among the collaborating parties and selective differentiated access to data among members of collaborating groups. Addressing such challenges requires, among other things, developing techniques for secure group communication (SGQ), secure dynamic conferencing (SDC), differential access control (DIF-AC), and hierarchical access control (HAC). Cryptography and key management have been intensively investigated and widely applied in order to secure information. However, there is a lack of key management mechanisms which are general and flexible enough to address all requirements arising from information transmission and data access. This paper proposes the first holistic group key management scheme which can directly support all these functions yet retain efficiency. The proposed scheme is based on the innovative concept of access control polynomial (ACP) that can efficiently and effectively support full dynamics, flexible access control with fine-tuned granularity, and anonymity. The new scheme is immune from various attacks from both external and internal malicious parties. Xukai Zou, Yuan-Shun Dai, Elisa Bertino |
INFOCOM | 1 |
| 2008 | An efficient and attack-resistant key agreement scheme for secure group communications in mobile ad-hoc networksabstractAbstract As a result of the growing popularity of wireless networks, in particular mobile ad hoc networks (MANET), security over such networks has become very important. Trust establishment, key management, authentication, and authorization are important areas that need to be thoroughly researched before security in MANETs becomes a reality. This work studies the problem of secure group communications (SGCs) and key management over MANETs. It identifies the key features of any SGC scheme over such networks. AUTH‐CRTDH, an efficient key agreement scheme with authentication capability for SGC over MANETs, is proposed. Compared to the existing schemes, the proposed scheme has many desirable features such as contributory and efficient computation of group key, uniform work load for all members, few rounds of rekeying, efficient support for user dynamics, key agreement without member serialization and defense against the Man‐in‐the‐Middle attack, and the Least Common Multiple (LCM) attack. These properties make the proposed scheme well suited for MANETs. The implementation results show that the proposed scheme is computationally efficient and scales well to a large number of mobile users. Copyright © 2007 John Wiley & Sons, Ltd. Ravi K. Balachandran, Xukai Zou, Byrav Ramamurthy, Amandeep Thukral, N. V. Vinodchandran |
Wirel. Commun. Mob. Comput. | 2 |
| 2007 | KeyRev: An Efficient Key Revocation Scheme for Wireless Sensor NetworksabstractKey management is a core mechanism to ensure the security of applications and network services in wireless sensor networks. It includes two aspects: key distribution and key revocation. Key distribution has been extensively studied in the context of sensor networks. However, key revocation has received relatively little attention. Existing key revocation schemes can be divided into two categories: centralized key revocation scheme and distributed key revocation scheme. In this paper, we first summarize the current key revocation schemes for sensor networks. Then, we propose an efficient centralized key revocation scheme, KeyRev, for wireless sensor networks. Unlike most proposed key revocation schemes focusing on removing the compromised keys, we propose to use key updating techniques to obsolesce the keys owned by the compromised sensor nodes and thus remove the nodes from the network. Our analyses show that the KeyRev scheme is secure inspite of not removing the pre-distributed key materials at compromised sensor nodes. Simulation results also indicate that the KeyRev scheme is scalable and performs very well in wireless sensor networks. Byrav Ramamurthy, Xukai Zou |
ICC | 3 |
| 2007 | Dual-Level Key Management for secure grid communication in dynamic and hierarchical groups
Xukai Zou, Yuan-Shun Dai, Xiang Ran |
Future Gener. Comput. Syst. | 1 |
| 2007 | A Hierarchical Modeling and Analysis for Grid Service ReliabilityabstractGrid computing is a recently developed technology. Although the developmental tools and techniques for the grid have been extensively studied, grid reliability analysis is not easy because of its complexity. This paper is the first one that presents a hierarchical model for the grid service reliability analysis and evaluation. The hierarchical modeling is mapped to the physical and logical architecture of the grid service system and makes the evaluation and calculation tractable by identifying the independence among layers. Various types of failures are interleaved in the grid computing environment, such as blocking failures, time-out failures, matchmaking failures, network failures, program failures, and resource failures. This paper investigates all of them to achieve a complete picture about grid service reliability. Markov models, queuing theory, and graph theory are mainly used to model, evaluate, and analyze the grid service reliability. Numerical examples are illustrated Yuan-Shun Dai, Yi Pan 0001, Xukai Zou |
IEEE Trans. Computers | 3 |
| 2006 | A Prototype Model for Self-Healing and Self-Reproduction In Swarm Robotics SystemabstractA swarm robotics system is a special type of wide-area and large-scale distributed system, which focuses on a group of robots cooperating to achieve the same goal using swarm intelligence. To treat the swarm robotics system with the self-healing and self-reproduction functions, this paper studied a prototype model based on the virtual neurons, autonomous self-diagnosis, consequence-oriented prescription, autonomous self-curing, and self-reproduction. This prototype system with self-healing has been implemented in the Trusted Electronics and Grid Obfuscation (TEGO) research center. Several practical cases were studied to show the effectiveness and efficiency of the model. The results demonstrate that the self-healing mechanism makes the system more reliable and the performance much improved, not only against failures, but also against failure propagations Yuan-Shun Dai, Michael G. Hinchey, Manish Madhusoodan, James L. Rash, Xukai Zou |
DASC | 5 |
| 2006 | Autonomic Security and Self-Protection based on Feature-Recognition with Virtual NeuronsabstractThe Internet and networks are not security-oriented by design so that myriad problems are compromising today's computer systems. This paper presented an autonomic security mechanism based on the virtual neurons and feature recognition. A prototype model of the virtual neuron is designed and the distributed virtual neurons are organized in a compound peer-to-peer and hierarchical structure. Then, the autonomic security mechanism is implemented via features recognized by the distributed virtual neurons. The paper presented how the feature recognition and virtual neurons work to automatically detect various security problems that are currently hard to defend against, including eavesdropping, replay, masquerading, spoofing, and DoS. A simulation system was developed and different cases were studied Yuan-Shun Dai, Michael G. Hinchey, Mingrui Qi, Xukai Zou |
DASC | 4 |
| 2006 | Composing Access Control Policies of Distributed ComponentsabstractSoftware realization of distributed computing systems (DCS) is achieved through the component based software development (CBSD) approach. DCS are generated by composing individual components. While creating such DCS, care must be taken to include the aspects of access control and obtain the resultant access control policy as a function of individual access control policies of the underlying components. A formal framework is needed to achieve this task of composing access control policies. In this paper, we propose an algebra that enables the composition of access control policies of individual components using the interaction patterns between them. A case study is presented which justifies the proposed algebra Omkar J. Tilak, Rajeev R. Raje, Xukai Zou |
DASC | 3 |
| 2006 | A New Cryptographic Scheme for Securing Dynamic Conferences in Data NetworksabstractDynamic conferencing refers to a scenario wherein any subset of users in a universe of users form a conference for sharing confidential information among themselves. The key distribution (KD) problem in dynamic conferencing is to compute a shared secret key for such a dynamically formed conference. In literature, the KD schemes for dynamic conferencing either are computationally unscalable or require communication among users, which is undesirable. The extended symmetric polynomial based dynamic conferencing scheme (ESPDCS) is one such KD scheme which has a high computational complexity that is universe size dependent. In this paper we present an enhancement to the ESPDCS scheme to develop a KD scheme called universe-independent SPDCS (UI-SPDCS) such that its complexity is independent of the universe size. However, the UI-SPDCS scheme does not scale with the conference size. We propose a relatively scalable KD scheme termed as DH-SPDCS that uses the UI-SPDCS scheme and the tree-based group Diffie-Hellman (TGDH) key exchange protocol. The proposed DH-SPDCS scheme provides a configurable trade-off between computation and communication complexity of the scheme. Sarang Deshpande, Ajay Kumar Todimala, Ravi K. Balachandran, Byrav Ramamurthy, Xukai Zou, N. V. Vinodchandran |
ICC | 5 |
| 2006 | The Performance of Elliptic Curve Based Group Diffie-Hellman Protocols for Secure Group Communication over Ad Hoc NetworksabstractThe security of the two party Diffie-Hellman key exchange protocol is currently based on the discrete logarithm problem (DLP). However, it can also be built upon the elliptic curve discrete logarithm problem (ECDLP). Most proposed secure group communication schemes employ the DLP-based Diffie-Hellman protocol. This paper proposes the ECDLP-based Diffie-Hellman protocols for secure group communication and evaluates their performance on wireless ad hoc networks. The proposed schemes are compared at the same security level with DLP-based group protocols under different channel conditions. Our experiments and analysis show that the Tree-based Group Elliptic Curve Diffie-Hellman (TGECDH) protocol is the best in overall performance for secure group communication among the four schemes discussed in the paper. Low communication overhead, relatively low computation load and short packets are the main reasons for the good performance of the TGECDH protocol. Byrav Ramamurthy, Xukai Zou |
ICC | 3 |
| 2006 | An Authenticated Key Agreement Protocol for Mobile Ad Hoc Networks
Xukai Zou, Amandeep Thukral, Byrav Ramamurthy |
MSN | 1 |
| 2005 | CRTDH: an efficient key agreement scheme for secure group communications in wireless ad hoc networksabstractAs a result of the growing popularity of wireless networks, in particular ad hoc networks, security over such networks has become very important. In this paper, we study the problem of secure group communications (SGC) and key management over ad hoc networks. We identify the key features of any SGC protocol for such networks. We also propose an efficient key agreement scheme for SGC. The scheme solves two important problems that exist in most current SGC schemes: requirement of member serialization and existence of a central entity. Besides this, the protocol also has many highly desirable properties such as contributory and efficient computation of group key, uniform work load for all the members, few rounds of rekeying (2 rounds for the initial key formation and join and 1 round for leave), and efficient support for high dynamics. These properties make the protocol well suited for wireless ad hoc networks. Ravi K. Balachandran, Byrav Ramamurthy, Xukai Zou, N. V. Vinodchandran |
ICC | 3 |
| 2005 | A balanced key tree approach for dynamic secure group communicationabstractLogical key hierarchy (LKH) is a promising solution to handle group key distribution in secure group communication. Several recent studies have investigated different approaches to reduce the re-keying cost of LKH. For certain group communication applications, such as the subscription pay TV; a member's departure time is available when the member joins the group. The proposed scheme aims to improve the re-keying cost for such applications. It uses a combination of an AVL tree and a binary search tree called the leaving tree as the topology of its key tree. Both the AVL tree and the leaving tree are searchable by members' departure times. Our analysis shows that the average costs in terms of the number of key updates for the member join and leave are O(logn) and O(loglog n), respectively. Our simulation results show that the proposed scheme achieves better performance than other balanced tree based solutions. Geng Hao, N. V. Vinodchandran, Byrav Ramamurthy, Xukai Zou |
ICCCN | 4 |
| 2005 | KTDCKM-SDC: A Distributed Conference Key Management Scheme for Secure Dynamic ConferencingabstractSecure dynamic conferencing (SDC) is a scenario where given a group of participants, any subset of participants can form a privileged subgroup, called a conference, and communicate securely among themselves. The existing SDC schemes belong to two classes: centralized and distributed. The former incurs the single-point of failure, the central point of attack and performance bottleneck. The two existing distributed dynamic conferencing schemes, which are based on public key cryptosystems, are inefficient and imply that anyone, as long as having a pair of public and private keys, can be in the group, thus, lacking the concept of group and the group membership management. In this paper, we first introduce two new concepts based on the well-known key tree scheme: sponsors and co-distributors and then, propose a new distributed dynamic conferencing scheme by designing an efficient algorithm for finding a sponsor or co-distributors. The new scheme enforces group/conference membership management and surpasses all the existing SDC schemes in terms of simplicity, efficiency and scalability. Pratima Adusumilli, Xukai Zou |
ISCC | 2 |
| 2001 | Hierarchy-based access control in distributed environmentsabstractAccess control is a fundamental concern in any system that manages resources, e.g., operating systems, file systems, databases and communications systems. The problem we address is how to specify, enforce, and implement access control in distributed environments. This problem occurs in many applications such as management of distributed project resources, e-newspaper and pay TV subscription services. Starting from an access relation between users and resources, we derive a user hierarchy, a resource hierarchy, and a unified hierarchy. The unified hierarchy is then used to specify the access relation in a way that is compact and that allows efficient queries. It is also used in cryptographic schemes that enforce the access relation. We introduce three specific cryptography based hierarchical schemes, which can effectively enforce and implement access control and are designed for distributed environments because they do not need the presence of a central authority (except perhaps for setup). Jean-Camille Birget, Xukai Zou, Guevara Noubir, Byrav Ramamurthy |
ICC | 2 |
| 2001 | Chinese Remainder Theorem Based Hierarchical Access Control for Secure Group Communication
Xukai Zou, Byrav Ramamurthy, Spyros S. Magliveras |
ICICS | 1 |