Zijian Zhang 0001

dblp:43/6524-1 · DBLP profile ↗
← Back
92ranked-venue papers
9as first author
63since 2021 · last 2026
0000-0002-6313-4407ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 30 · 3 first-author · 18 since 2021Security and privacy · 26 · 2 first-author · 24 since 2021Applied, interdisciplinary, general and emerging computing · 12 · 7 since 2021Artificial intelligence and machine learning · 8 · 1 first-author · 4 since 2021Systems, architecture and hardware · 8 · 1 first-author · 4 since 2021Databases, data management, data science and information retrieval · 8 · 2 first-author · 5 since 2021Software engineering, systems software and programming languages · 6 · 1 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 Accurate, Secure, and Efficient Semi-Constrained Navigation with Multiple Spatial Restrictions
Meng Li 0006, Yan Qiao 0001, Zijian Zhang 0001, Liehuang Zhu, Mauro Conti
DSN4
2026 Reputation-Based Leader Election under Partial Synchrony: Towards a Protocol-Independent Abstraction with Enhanced Guarantees
abstract
Leader election serves a well-defined role in leader-based Byzantine Fault Tolerant (BFT) protocols. Existing reputation-based leader election frameworks for partially synchronous BFTs suffer from either protocol-specific proofs, narrow applicability, or unbounded recovery after network stabilization, leaving an open problem. This paper presents a novel protocol-independent abstraction formalizing generic correctness properties and effectiveness guarantees for leader election under partial synchrony, enabling protocol-independent analysis and design. Building on this, we design the Sliding Window Leader Election (SWLE) mechanism. SWLE dynamically adjusts leader nominations via consensus-behavior-based reputation scores, enforcing Byzantine-cost amplification. We demonstrate SWLE introduces minimal extra overhead to the base protocol and prove it satisfies all abstraction properties and provides superior effectiveness. We show, with a 16-server deployment across 4 different regions in northern China, SWLE achieves up to 4.2x higher throughput, 75% lower latency and 27% Byzantine leader frequency compared to the state-of-the-art solution under common Byzantine faults, while maintaining efficiency in fault-free scenarios.
Zijian Zhang 0001, Jiahang Sun, Jiamou Liu, Peng Jiang 0007
INFOCOM2
2026 Multi-source Multi-level Multi-token Ethereum Dataset and Benchmark Platform
Mengxiao Zhang 0002, Maoyuan Li, Jianzheng Li, Zijian Zhang 0001, Shuangyan Deng, Jiamou Liu
WWW5
2026 Combating Knowledge Corruption in Agent Systems: A Byzantine-Tolerant Secure Collaborative RAG Framework
abstract
While retrieval-augmented generation systems partially address the hallucination issues in large language models, it also introduces new vulnerabilities to knowledge corruption attacks. Adversaries exploit these vulnerabilities by poisoning documents provided by RAG system to manipulate LLM outputs. To counter this threat, we propose SecureCollaRAG, a Byzantine-tolerant collaborative RAG framework leveraging Multi-source Knowledge Validation Mechanism. Our approach enables agent system to securely verify document provenance through dynamic GNN-based credibility scoring, effectively preventing stealthy knowledge corruption attacks while preserving essential domain knowledge integrity. Through extensive evaluations and formal analysis, we demonstrate that SecureCollaRAG maintains robustness against attackers under non-IID data distributions.
Daqing He, Zijian Zhang 0001, Ye Liu 0012, Jiamou Liu, Zhirui Zeng, Zhan Qin, Xin Li 0033, Hongwei Yao, Jincheng An, Yi Li 0008, Xiulei Liu, Liehuang Zhu
WWW3
2026 Fake news detection with GAN-augmented contrastive learning and multimodal attention
abstract
Abstract The rapid proliferation of fake news in digital media has emerged as a major threat to information credibility and public trust. Although recent advances have explored multimodal learning for fake news detection, existing models often fail to effectively integrate heterogeneous data sources and remain vulnerable to adversarial manipulations. To address these challenges, we propose (Multimodal Adversarial Deep Semantic Learning), a robust multimodal fake news detection framework that unifies generative adversarial networks (GANs) with supervised contrastive learning. Specifically, employs a multi-layer joint attention mechanism to align and fuse textual and visual features, while adversarial training encourages the extraction of event-invariant representations, enhancing generalizability across unseen news events. Additionally, contrastive learning with adversarial perturbations further strengthens feature discrimination and robustness against attacks. Extensive experiments on benchmark Twitter and Weibo datasets demonstrate that achieves state-of-the-art accuracy (85.3%) and maintains stable performance with only a 1.1% drop under adversarial conditions, outperforming existing methods in both detection accuracy and resilience. These results underscore ’s effectiveness in advancing robust multimodal fake news detection and promoting digital information integrity.
Cong Wu 0003, Jing Chen 0003, Yebo Feng, Ju Jia, Zijian Zhang 0001, Jiahua Xu 0002, Teng Li 0003, Yang Liu 0003
Cybersecur.6
2026 FQAS: A Fidelity-Aware Qubit Allocation System for Efficient Distributed Quantum Computing
Hongding Zhang, Wei Liang 0005, Naixue Xiong, Sheng Huo, Zijian Zhang 0001, Jie Wu 0001
IEEE Internet Things J.6
2026 Hydra: Support Dynamic BFT With Weaker Assumptions and Explicit Request Handling
abstract
This paper presents Hydra, a dynamic BFT protocol that allows replicas to join and leave the system dynamically. It addresses the limitations of traditional static BFTs in managing membership changes and can be used to simplify the implementation of many features in modern blockchain applications. Hydra relies on weaker assumptions to achieve standard properties compared to the existing solution Dyno and introduces a configuration auto-transition protocol to ensure liveness. Through temporary configurations and explicitly defined replica responsibilities for request handling, Hydra pipelines membership requests alongside regular requests and realizes clarity, achieving a more efficient and smoother configuration transitions. It also employs a non-blocking configuration discovery mechanism, enabling new replicas to participate in consensus quickly. We formally prove Hydra's correctness under the dynamic BFT model. Experimental results demonstrate Hydra's ability to maintain throughput fluctuations within 5% during various replica join and leave scenarios, outperforming Dyno and existing BFT system supporting reconfiguration in both stability and efficiency. Hydra effectively manages scenarios that Dyno circumvents with stronger assumptions and quickly restores throughput to normal levels.
Zijian Zhang 0001, Haibo Sun, Meng Li 0006, Jing Sun 0002, Jiamou Liu, Lei Xu 0016, Jincheng An, Mauro Conti, Liehuang Zhu
IEEE Trans. Dependable Secur. Comput.2
2026 Unveiling Ethereum Mixing Services Using Enhanced Graph Structure Learning
abstract
As cryptocurrency prices continue to recover, crypto crimes such as money laundering are becoming increasingly rampant. Mixing services such as Tornado Cash have become the primary tools for obfuscating illegal financial transactions due to their inherent anonymity mechanisms. Tornado Cash is a non-custodial, smart contract-based mixing service (SC-CMS) that breaks the direct mapping between deposit and withdrawal accounts, hindering regulators from tracking illicit fund flows. Existing deanonymization methods for Tornado Cash suffer from several challenges, including vague theoretical concepts, evolving mixing mechanisms, and insufficient labeled samples. To address these concerns, this paper proposes the first formal concept of SC-CMS to facilitate and evaluate the deanonymization efforts systematically. We design a novel linkability attack, LASC, based on enhanced graph structure learning, to associate mixing accounts on Tornado Cash and mathematically prove its feasibility. Comprehensive experiments on real Ethereum transactions demonstrate that LASC outperforms state-of-the-art works in both performance and efficiency.
Yan Wu 0014, Cong Wu 0003, Yebo Feng, Jiahang Sun, Zijian Zhang 0001, Jincheng An, Zhitao Guan, Liehuang Zhu
IEEE Trans. Dependable Secur. Comput.8
2026 BAVote: Blockchain-Based Electronic Voting System With Privacy and Accountability
abstract
Blockchain-based electronic voting systems can achieve voter identity anonymity via cryptographic techniques such as ring signatures and blind signatures. However, fully hiding of voter information mitigates the capability of traceability. Previous mechanisms provide limited traceability, typically by preventing double-voting attacks while compromising the anonymity. From the cryptographic point, threshold signature with private accountability seems to offer a balanced solution between privacy and accountability. If directly applying it into blockchain-based electronic voting systems, it needs to fix all voters and each verification has to pre-store all voters’ public keys, incurring at least linear-size storage overhead and poor scalability. How to optimize the storage and scalability while guaranteeing both anonymity and traceability remains to be challenging. In this paper, we propose BAVote, an efficient and scalable blockchain-based electronic voting system with anonymity and traceability. It is built on top of a new threshold signature scheme named ConsATS that features a constant-size verification key. ConsATS compress all voters’ public keys into a single verification key, allowing an aggregated ballot to be verified without storing or processing per-voter public keys, thereby reducing on-chain storage overhead and improving scalability in BAVote. The aggregated signature serving as the ballot is encrypted in ConsATS, while BAVote further combines one-time addresses and a commit–reveal mechanism to protect intermediate on-chain data during voting. The corresponding tracing key enables authorized tracer to identify malicious voters during authorized audits. We implement a prototype of BAVote in both a local blockchain environment and the Ethereum Sepolia testnet. The experimental results show that the storage cost of verification keys in our system is reduced by more than 90% and the verification time is 7x faster compared to existing schemes.
Peng Jiang 0007, Zijian Zhang 0001, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.3
2026 HKT-SmartAudit: Distilling Lightweight Models for Smart Contract Auditing
abstract
The rapid growth of blockchain technology has driven the widespread adoption of smart contracts; however, their inherent vulnerabilities have led to significant financial losses. Traditional auditing methods, while essential, struggle to keep pace with the increasing complexity and scale of smart contracts. Large language models (LLMs) offer promising capabilities for automating vulnerability detection, but their adoption is often limited by high computational costs. Although prior work has explored leveraging large models through agents or workflows, relatively little attention has been given to improving the performance of smaller, fine-tuned models—a critical factor for achieving both efficiency and data privacy. In this paper, we introduce HKT-SmartAudit, a framework for developing lightweight models optimized for smart contract auditing. It features a multi-stage knowledge distillation pipeline that integrates classical distillation, external domain knowledge, and reward-guided learning to transfer high-quality insights from large teacher models. A single-task learning strategy is employed to train compact student models that maintain high accuracy and robustness while significantly reducing computational overhead. Experimental results show that our distilled models outperform both commercial tools and larger models in detecting complex vulnerabilities and logical flaws, offering a practical, secure, and scalable solution for smart contract auditing. The source code is available in the GitHub repository1.
Jing Sun 0002, Zijian Zhang 0001, Xianhao Zhang, Meng Li 0006, Yuqiang Sun 0001, Daoyuan Wu, Yang Liu 0003, Chunmiao Li, Mingchao Wan, Jin Dong 0004
IEEE Trans. Inf. Forensics Secur.3
2025 S-RAG: A Novel Audit Framework for Detecting Unauthorized Use of Personal Data in RAG Systems
abstract
Retrieval-Augmented Generation (RAG) systems combine external data retrieval with text generation and have become essential in applications requiring accurate and context-specific responses. However, their reliance on external data raises critical concerns about unauthorized collection and usage of personal information. To ensure compliance with data protection regulations like GDPR and detect improper use of data, we propose the Shadow RAG Auditing Data Provenance (S-RAG) framework. S-RAG enables users to determine whether their textual data has been utilized in RAG systems, even in black-box settings with no prior system knowledge. It is effective across open-source and closed-source RAG systems and resilient to defense strategies. Experiments demonstrate that S-RAG achieves an improvement in Accuracy by 19.9% (compared to the best baseline), while maintaining strong performance under adversarial defenses. Furthermore, we analyze how the auditor’s knowledge of the target system affects performance, offering practical insights for privacy-preserving AI systems. Our code is open-sourced online.
Zhirui Zeng, Jiamou Liu, Meng-Fen Chiang, Jialing He, Zijian Zhang 0001
ACL (1)5
2025 Verifiable Predicate-based Access Control Encryption with Dynamic Revocation
abstract
In wireless communication, data is typically encrypted before transmission to ensure confidentiality, which complicates the implementation of access control.Predicate encryption based (PE-based) access control enables fine-grained and secure control over encrypted data. The previous PE-based access control systems only guarantee the access of the authorized receivers but not control illegal senders, and have to execute re-authorization due to its static setting. In this paper, we propose a verifiable predicate-based access control encryption supporting dynamic revocation scheme (dvPACE), which is a dynamic access control mechanism on both senders and receivers. In contrast to existing access control, dvPACE controls not only "who can access" but also "who can send". It involves an additional sanitizer to handle the cipher data and embraces multi-verification against illegal entities. To achieve efficiency and scalability, dvPACE embeds inner-product predicate encryption and borrows the idea of identity-based revocation systems. dvPACE achieves about 19ms computational cost of data access, a comparable performance over conventional mechanisms with improvements of functionalities.
Peng Jiang 0007, Zijian Zhang 0001, Liehuang Zhu
IWCMC3
2025 CamLopa: A Hidden Wireless Camera Localization Framework via Signal Propagation Path Analysis
abstract
Hidden wireless cameras pose significant privacy threats, necessitating effective detection and localization methods. However, existing localization solutions often require impractical activity spaces, expensive specialized devices, or pre-collected training data, limiting their practical deployment. To address these limitations, we introduce CamLopa, a training-free wireless camera localization framework that operates with minimal activity space constraints using low-cost, commercial-off-the-shelf (COTS) devices. CamLopa can achieve detection and localization in just 45 seconds of user activities with a Raspberry Pi board. During this short period, it analyzes the causal relationship between wireless traffic and user movement to detect the presence of a hidden camera. Upon detection, CamLopa utilizes a novel azimuth localization model based on wireless signal propagation path analysis for localization. This model leverages the time ratio of user paths crossing the First Fresnel Zone (FFZ) to determine the camera's azimuth angle. Subsequently, CamLopa refines the localization by identifying the camera's quadrant. We evaluate CamLopa across various devices and environments, demonstrating its effectiveness with a 95.37% detection accuracy for snooping cameras and an average localization error of 17.23°, under the significantly reduced activity space requirements and without the need for training. Our code and demo are available at https://github.com/CamLoPA/CamLoPA-Code.
Xiang Zhang 0011, Jie Zhang 0073, Zehua Ma, Jinyang Huang, Meng Li 0006, Huan Yan 0004, Peng Zhao 0024, Zijian Zhang 0001, Bin Liu 0016, Qing Guo 0005, Tianwei Zhang 0004, Nenghai Yu
SP8
2025 Covert Transmission via Steganography and Smart Contract
abstract
The Internet of Things (IoT) system gathers data through diverse smart devices and sensors to make thorough decisions tailored to specific needs. Yet, in intricate IoT setups, privacy infringement occurs through various means like data collection, initial data handling, and data sharing. Therefore, the concealment of data during transmission should receive sufficient attention. The communication approach that merges blockchain technology with covert communication has shown progress in addressing the aforementioned issues. However, this integration has also led to challenges, such as low-data embedding rates and distinctive features in blockchain transactions containing covert data. To seek a solution with high-embedding rates that do not make generated transactions stand out distinctly, this article analyzes the Ethereum transaction field formats, identifies the input data field with high concealment and large capacity as the embedding target, then proposes a data covert transmission scheme based on hybrid embedding in contract fields. This scheme utilizes LSB steganography to embed high-capacity covert data in images, and embeds the URL of the image into the input data field of the Ethereum smart contract transaction, thereby increasing the embedding rates. Subsequently, to further enhance the concealment of this scheme, a data embedding method based on contract relationships is proposed. Through this technique, for the first time, covert data transmission is achieved solely through the invocation relationships of smart contracts within the blockchain covert communication environment, instead of directly embedding covert data into transactions. This method results in transactions that are theoretically indistinguishable from regular transactions, greatly enhancing the security of the scheme. Finally, an evaluation of undetectability, embedding rate, and scalability was conducted for the proposed schemes, concluding that the schemes presented in this article have significant advantages in all three areas.
Yingxue Liu, Jing Sun 0002, Zhuo Chen 0001, Feng Gao 0019, Xiangbo Yuan, Zijian Zhang 0001, Lei Zhang 0101, Meng Li 0006, Liehuang Zhu
IEEE Internet Things J.6
2025 Accurate, Secure, and Efficient Semi-Constrained Navigation Over Encrypted City Maps
abstract
Navigation services enable users to find the shortest path from a starting point$S$to a destination$D$, reducing time, gas, and traffic congestion. Still, navigation users risk the exposure of their sensitive location data. Our motivation arises from how users can accurately, securely, and efficiently navigate from$S$to$D$while passing through$k$unordered stops, i.e., midway locations with a non-fixed visiting order. In this work, we formally define Semi-Constrained Navigation (SCN) and present a novel scheme Hermes to achieve accurate, secure, and efficient SCN. Specifically, we propose a divide-and-conquer approach to strike a good balance between accuracy and efficiency. It recursively depth-first-searches the whole area (a navigation tree) and invokes five carefully-crafted strategies stop-by-stop to compute three subpaths in three sequential subareas. We construct a path-distance oracle to encrypt the road graph and securely implement the strategies by using homomorphic encryption and garble circuits. We formally prove the security in the random oracle model and analyze the search complexity to be less than$O(k^{2})$. We experiment over a real-world city map and compare with six baselines. Results show that path search with$k=4$among$N=1000$intersections requires 5.58 seconds with a 3.2% distance deviation rate and an 82.5% path similarity.
Meng Li 0006, Yifei Chen 0005, Jingyu Wu, Zijian Zhang 0001, Jialing He, Liehuang Zhu, Mauro Conti, Xiaodong Lin 0001
IEEE Trans. Dependable Secur. Comput.5
2025 Group BFT: Two-Round BFT Protocols Via Replica Grouping
abstract
This paper seeks to enhance the performance of large-scale leader-based Byzantine Fault Tolerant (BFT) systems by proposing a novel Group BFT scheme. The scheme utilizes a two-round message transmission process to distribute the load from a single leader across multiple replicas by dividing the entire consensus network into groups, each with an equal number of replicas. Each group has a leader to process the group's voting messages into a single aggregated voting message during the first round, which is then transmitted to the consensus leader in the second round (similar process for proposing). We establish a formal system framework for Group BFT protocols with a versatile set of base components and explicit definitions, addressing the challenges inherent in designing such a system. We further design and implement two highly efficient Group BFT protocols: one that supports inter-group member exchange and the other one that does not. We theoretically prove the safety, liveness, and responsiveness of the Group BFT protocols. We conduct a formal analysis of Group BFTs' tolerance and complexity. Experimental results show that the two Group BFT protocols significantly alleviate the processing bottlenecks of the leader and highly improve throughput in large-scale systems.
Zijian Zhang 0001, Meng Li 0006, Lei Xu 0016, Meng Ao, Liehuang Zhu
IEEE Trans. Dependable Secur. Comput.2
2025 Trust in a Decentralized World: Data Governance From Faithful, Private, Verifiable, and Traceable Data Feeds
abstract
Blockchain technology autonomously executes smart contracts that require external data to facilitate specific applications, underscoring the necessity for Authenticated Data Feeds (ADF). Existing solutions fall short in providing genuine authentication of data, lack private and verifiable computations across multiple data sources, and overlook data traceability, rendering current systems inadequate for complex applications. We present WuKong (WK), a data governance system that offers authenticated, privately verifiable, and traceable data feeds. WK enables a server to collect faithful data through an oracle committee and to prove computation correctness in zero-knowledge proofs, and empowers legal entities to trace a leakage source conditionally. We formally define and prove the security of WK in the universal composability framework. We implement three applications that seamlessly integrate with WK. Experimental results indicate that WK effectively liberates sensitive data from distributed, untrusted, and anonymous providers, making it accessible to various services and establishing trust in a decentralized world.
Meng Li 0006, Yifei Chen 0005, Yan Qiao 0001, Guixin Ye, Zijian Zhang 0001, Liehuang Zhu, Mauro Conti
IEEE Trans. Inf. Forensics Secur.5
2025 Threshold Signatures With Verifiably Timed Combining and Message-Dependent Tracing
Meng Li 0006, Hanni Ding, Yifei Chen 0005, Yan Qiao 0001, Zijian Zhang 0001, Liehuang Zhu, Mauro Conti
IEEE Trans. Inf. Forensics Secur.5
2025 The Deferred Byzantine Generals Problem
abstract
This paper introduces the Deferred Byzantine Generals Problem, a variant of the Byzantine Generals Problem which focuses on ensuring replicas maintain consistency over timed-release secret operations (operations that can only be known after a specified time or event). The solution to the problem is called the Deferred Byzantine Fault Tolerant (DBFT) consensus. DBFT can operate exclusive or be interleave with BFTs to handle specific tasks at designated sequence numbers or views, thereby facilitating the implementation of certain system-desirable features or supporting novel applications. It does not rely on existing timed-release primitives, but instead ensures its timed-release property through voting interactions. We presents the system model of DBFT SMR under partial synchronization using Threshold Public Key Encryption (TPKE) as the cryptographic primitives, highlighting the core issues. Then we design and implement the DBFT protocol using PBFT notations, focusing on the unique parts to facilitate expansions to other paradigms. Through experimental results, we show the impact of different executing modes and parameter choices on performance and discuss potential optimizations.
Zijian Zhang 0001, Peng Jiang 0007, Meng Li 0006, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.2
2025 PraVFed: Practical Heterogeneous Vertical Federated Learning via Representation Learning
abstract
Vertical federated learning (VFL) provides a privacy-preserving method for machine learning, enabling collaborative training across multiple institutions with vertically distributed data. Existing VFL methods assume that participants passively gain local models of the same structure and communicate with active pary during each training batch. However, due to the heterogeneity of participating institutions, VFL with heterogeneous models for efficient communication is indispensable in real-life scenarios. To address this challenge, we propose a new VFL method called Practical Heterogeneous Vertical Federated Learning via Representation Learning (PraVFed) to support the training of parties with heterogeneous local models and reduce communication costs. Specifically, PraVFed employs weighted aggregation of local embedding values from the passive party to mitigate the influence of heterogeneous local model information on the global model. Furthermore, to safeguard the passive party’s local sample features, we utilize blinding factors to protect its local embedding values. To reduce communication costs, the passive party performs multiple rounds of local pre-model training while preserving label privacy. We conducted a comprehensive theoretical analysis and extensive experimentation to demonstrate that PraVFed reduces communication overhead under heterogeneous models and outperforms other approaches. For example, when the target accuracy is set at 60% under the CINIC10 dataset, the communication cost of PraVFed is reduced by 70.57% compared to the baseline method. Our code is available athttps://github.com/wangshuo105/PraVFed_main.
Shuo Wang 0026, Keke Gai, Jing Yu 0007, Zijian Zhang 0001, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.4
2025 Balancing Differential Privacy and Utility: A Relevance-Based Adaptive Private Fine-Tuning Framework for Language Models
abstract
Differential privacy (DP) has been proven to be an effective universal solution for privacy protection in language models. Nevertheless, the introduction of DP incurs significant computational overhead. One promising approach to this challenge is to integrate Parameter Efficient Fine-Tuning (PEFT) with DP, leveraging the memory-efficient characteristics of PEFT to reduce the substantial memory consumption of DP. Given that fine-tuning aims to quickly adapt pretrained models to downstream tasks, it is crucial to balance privacy protection with model utility to avoid excessive performance compromise. In this paper, we propose a Relevance-based Adaptive Private Fine-Tuning (Rap-FT) framework, the first approach designed to mitigate model utility loss caused by DP perturbations in the PEFT context, and to achieve a balance between differential privacy and model utility. Specifically, we introduce an enhanced layer-wise relevance propagation process to analyze the relevance of trainable parameters, which can be adapted to the three major categories of PEFT methods. Based on the relevance map generated, we partition the parameter space dimensionally, and develop an adaptive gradient perturbation strategy that adjusts the noise addition to mitigate the adverse impacts of perturbations. Extensive experimental evaluations are conducted to demonstrate that our Rap-FT framework can improve the utility of the fine-tuned model compared to the baseline differentially private fine-tuning methods, while maintaining a comparable level of privacy protection.
Naiyu Wang, Shen Wang 0012, Meng Li 0006, Longfei Wu, Zijian Zhang 0001, Zhitao Guan, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.5
2025 Resisting Poisoning Attacks in Federated Learning via Dual-Domain Distance and Trust Assessment
abstract
Subsequently, by executing various attacks on benchmark datasets such as MNIST, we construct Federated Learning Malicious Parameter Identification (FLMPID) dataset to enable malicious client detection. Building on this dataset, we propose FORTRESS (Federated POisoning-Resistance Defense via Dual-Domain Distance and TRust AssESSment), a framework designed to detect and mitigate malicious updates from clients. FORTRESS employs a unique encoder-decoder architecture. The encoder utilizes dual-domain distance metrics on weights and gradients to extract hidden representations, while the decoder leverages Actor-Critic (AC) reinforcement learning for trust assessment. We evaluated FORTRESS under multiple attack scenarios and demonstrated its defense effectiveness, making it a promising solution for enhancing the security of FL systems.
Zijian Zhang 0001, Yan Wu 0014, Ye Liu 0012, Meng Li 0006, Xin Li 0033, Jincheng An, Wei Liang 0005, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.2
2025 VSecNN: Verifiable and Privacy-Preserving Neural Network Inference in Cloud Service
abstract
Neural network inference in cloud service offers tangible benefits to users, from individuals and small institutions to large companies. However, two crucial concerns must be addressed. The first arises in satisfying the privacy of the model, the input data, and the inference results throughout the inference process. The second pertains to verifying that the inferences are derived from the designated neural network model. Although Secure Multi-Party Computation (MPC) and Zero-Knowledge Proof (ZKP) are typically adopted to mitigate such issues, the major challenge lies in achieving privacy preservation and verifiability simultaneously. In this study, we address both issues by proposing VSecNN, a verifiable and privacy-preserving neural network inference scheme. Specifically, we integrate MPC with the Zero-Knowledge Succinct Non-Interactive Argument of Knowledge (zk-SNARK) protocol to achieve zero-knowledge proof generation for multiple parties. Subsequently, we perform adaptive optimizations on the multi-party proof generation approach to align with the neural network, thereby achieving both privacy-preserving capabilities and verifiability. Experimental results demonstrate an improvement in the efficiency. For example, the computation time for completing our multi-party proof generation could be as low as 1.7 times that of the single-party proof generation, while the verification requires only 169ms on the MNIST dataset.
Wenti Yang, Xuan Li 0007, Meng Li 0006, Zijian Zhang 0001, Zhitao Guan, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.4
2025 Web-FTP: A Feature Transferring-Based Pre-Trained Model for Web Attack Detection
abstract
Web attack is a major threat to cyberspace security, so web attack detection models have become a critical task. Traditional supervised learning methods learn features of web attacks with large amounts of high-confidence labeled data, which are extremely expensive in the real world. Pre-trained models offer a novel solution with their ability to learn generic features on large unlabeled datasets. However, designing and deploying a pre-trained model for real-world web attack detection remains challenges. In this paper, we present a pre-trained model for web attack detection, including a pre-processing module, a pre-training module, and a deployment scheme. Our model significantly improves classification performance on several web attack detection datasets. Moreover, we deploy the model in real-world systems and show its potential for industrial applications.
Qinghua Shang, Xin Li 0033, Chengyi Li, Zijian Zhang 0001, Jincheng An, Chuanming Huang, Yang Chen 0028, Yuguang Cai
IEEE Trans. Knowl. Data Eng.5
2025 HeadSonic: Usable Bone Conduction Earphone Authentication via Head-Conducted Sounds
abstract
Earables (ear wearables) are rapidly emerging as a new platform encompassing a diverse of personal applications, prompting the development of authentication schemes to protect user privacy. Existing earable authentication methods are all specifically designed for air-conduction earphones, which are not suited for bone conduction earphones (BCEs) that rely on bone conduction mechanisms. In this paper, we propose HeadSonic, a usable BCE authentication system based on the unique head-conducted sounds, which can be acquired when the user wears the BCE device. Specifically, the system emits a millisecond-level sound to initiate the authentication session. The signal captured by the BCE microphone is propagated through the user's head, which is unique in density, geometry, and bone-tissue ratio. It operates implicitly, while maintaining robustness across different behaviors. Extensive experiments involving 60 subjects demonstrate that HeadSonic achieves a commendable balanced accuracy of 96.59%, proving its efficacy and resilience against replay and synthesis attacks. Our dataset and source codes are available athttps://anonymous.4open.science/r/HeadSonic-1CE4.
Zhixiang He, Jing Chen 0003, Kun He 0008, Yangyang Gu, Qiyi Deng, Zijian Zhang 0001, Ruiying Du, Qingchuan Zhao, Cong Wu 0003
IEEE Trans. Mob. Comput.6
2025 ABSE: Adaptive Baseline Score-Based Election for Leader-Based BFT Systems
abstract
Leader-based BFT systems face potential disruption and performance degradation from malicious leaders, with current solutions often lacking scalability or greatly increasing complexity. In this paper, we introduce ABSE, an Adaptive Baseline Score-based Election approach to mitigate the negative impact of malicious leaders on leader-based BFT systems. ABSE is fully localized and proposes to accumulate scores for processes based on their contribution to consensus advancement, aiming to bypass less reliable participants when electing leaders. We present a formal treatment of ABSE, addressing the primary design and implementation challenges, defining its generic components and rules for adherence to ensure global consistency. We also apply ABSE to two different BFT protocols, demonstrating its scalability and negligible impact on protocol complexity. Finally, by building a system prototype and conducting experiments on it, we demonstrate that ABSE-enhanced protocols can effectively minimize the disruptions caused by malicious leaders, whilst incurring minimal additional resource overhead and maintaining base performance.
Zijian Zhang 0001, Meng Li 0006, Jiamou Liu, Mauro Conti, Liehuang Zhu
IEEE Trans. Parallel Distributed Syst.2
2025 Advanced Smart Contract Vulnerability Detection via LLM-Powered Multi-Agent Systems
abstract
Blockchain’s inherent immutability, while transformative, creates critical security risks in smart contracts, where undetected vulnerabilities can result in irreversible financial losses. Current auditing tools and approaches often address specific vulnerability types, yet there is a need for a comprehensive solution that can detect a wide range of vulnerabilities with high accuracy. We propose LLM-SmartAudit, a novel framework that leverages Large Language Models (LLMs) to automate smart contract vulnerability detection and analysis. Using a multi-agent conversational architecture with a buffer-of-thought mechanism, LLM-SmartAudit maintains a dynamic record of insights generated throughout the audit process. This enables a collaborative system of specialized agents to iteratively refine their assessments, enhancing the accuracy and depth of vulnerability detection. To evaluate its effectiveness, LLM-SmartAudit was tested on three datasets: a benchmark for common vulnerabilities, a real-world project corpus, and a CVE dataset. It outperformed existing tools with 98% accuracy on common vulnerabilities and demonstrates higher accuracy in real-world scenarios. Additionally, it successfully identifies 12 out of 13 CVEs, surpassing other LLM-based methods. These results demonstrate the effectiveness of multi-agent collaboration in automated smart contract auditing, offering a scalable, adaptive, and highly efficient solution for blockchain security analysis.
Jing Sun 0002, Yuqiang Sun 0001, Ye Liu 0012, Daoyuan Wu, Zijian Zhang 0001, Xianhao Zhang, Meng Li 0006, Yang Liu 0003, Chunmiao Li, Mingchao Wan, Jin Dong 0004, Liehuang Zhu
IEEE Trans. Software Eng.6
2024 Threshold Signatures with Private Accountability via Secretly Designated Witnesses
Meng Li 0006, Hanni Ding, Qing Wang 0060, Zijian Zhang 0001, Mauro Conti
ACISP (1)4
2024 Validating Smart Contracts Using GPT Assistant
abstract
This paper presents SCareGPT, an advanced smart contract auditing tool that harnesses domain-specific GPT Assistant technology to enhance vulnerability detection and analysis. We created a standardized dataset featuring 100 labeled vulnera-ble smart contracts and performed comparative benchmarks between SCareGPT and ten traditional smart contract vulnerability detection tools. Our findings demonstrate that SCareGPT excels beyond these competitors in the majority of assessed vulnerability categories, affirming its superiority and utility in the rapidly evolving domain of smart contract security.
Xianhao Zhang, Jing Sun 0002, Zijian Zhang 0001
COMPSAC4
2024 Secure, Available, Verifiable, and Efficient Range Query Processing on Outsourced Datasets
abstract
Range queries allow data users to outsource their data to a Cloud Server (CS) that responds to data users who submit a request with range conditions. However, security concerns hinder the wide-scale adoption. Existing works neglect item availability, fail to protect secure verification or sacrifice search accuracy for efficiency. In this paper, we propose Secure, Available, Verifiable, and Efficient (SAVE) range query processing, which has three distinctive features. (1) Secure availability checking against a malicious CS: we design a keyed index-based secure verification mechanism to check the availability of matched nodes, including validity and freshness. (2) Secure result verification: we design a targeted verification mechanism for result correctness and completeness while not compromising security. (3) Improved efficiency and accuracy: we design a lay-ered encoding method to improve search efficiency and accuracy. We formally stated and proved the security of SAVE in the random oracle model. We conducted extensive experiments over the Yelp and FourSquare dataset to validate the efficiency, e.g., a query over 10 thousand data items only needs 19.4 ms to get queried results and 3.5 ms for local verification.
Meng Li 0006, Zijian Zhang 0001, Mauro Conti, Mamoun Alazab
ICC3
2024 A Generic Blockchain-based Steganography Framework with High Capacity via Reversible GAN
abstract
Blockchain-based steganography enables data hiding via encoding the covert data into a specific blockchain transaction field. However, previous works focus on the specific field-embedding methods while lacking a consideration on required field-generation embedding. In this paper, we propose GBSF, a generic framework for blockchain-based steganography. The sender generates the required fields, where the additional covert data is embedded to enhance the channel capacity. Based on GBSF, we design R-GAN that utilizes the generative adversarial network (GAN) with a reversible generator to generate the required fields and encode additional covert data into the input noise of the reversible generator. We then explore the performance flaw of R-GAN and introduce CCR-GAN as an improvement. CCR-GAN employs a counter-intuitive data preprocessing mechanism to reduce decoding errors in covert data. It incurs gradient explosion for model convergence and we design a custom activation function. We conduct experiments using the transaction amount of the Bitcoin mainnet as the required field. The results demonstrate that R-GAN and CCR-GAN allow to embed 11-bit (embedding rate of 17.2%) and 24-bit (embedding rate of 37.5%) covert data within a transaction amount, and enhance the channel capacity of state-of-the-art works by 4.30% to 91.67% and 9.38% to 200.00%, respectively.
Zhuo Chen 0001, Liehuang Zhu, Peng Jiang 0007, Jialing He, Zijian Zhang 0001
INFOCOM5
2024 Trusted Execution Environment With Rollback Protection for Smart Contract-Based IoT Data Trading
abstract
Blockchain uses smart contract technology to automate the execution of Internet of Things (IoT) data trading and facilitate the flow and application of IoT data. The verifiability of the blockchain system requires data to be open and transparent. Directly using smart contracts for IoT data trading may expose sensitive data generated by IoT devices, thereby increasing the risk of data leakage and abuse. The trusted execution environment represented by software guard extension (SGX) provides new ideas for trusted execution of IoT data trading based on smart contracts. SGXs is a set of hardware security enhancement technologies launched by Intel, which aims to protect the execution of sensitive data and code through the hardware isolation and security encryption capabilities provided by the processor. However, we found that due to SGX’s lack of a checksum mechanism for the execution state of smart contracts, a rollback attack can lead to errors when the account state of IoT data trading is replayed. To address the above issues, we propose a trusted execution environment for IoT data trading with rollback protection. First, we design a freshness checking mechanism for the execution state of IoT data trading contracts for rollback protection. In addition, we propose a “chain-of-trust”-based authentication model to realize trust metrics and remote proofs for the proposed trusted execution environment for IoT data trading. Finally, we then provide a formal security analysis and comprehensive performance evaluation.
Zijian Zhang 0001, Meng Li 0006, Tyler Zhou, Liehuang Zhu
IEEE Internet Things J.2
2024 Decentralized Fair IoT Data Trading via Searchable Proxy Re-Encryption
abstract
The Internet of Things (IoT) is a network composed of information-gathering devices, sensors, and computing devices assembled in an intelligent manner, and the most important element in this system is data. IoT data trading plays a vital role in the area of personalized business nowadays. Individual IoT devices generate large amounts of private data, which data owners can sell to enterprises as important digital assets to make money, while enterprises collect IoT data to improve the accuracy of their services. Cloud storage services have been widely used in IoT data trading. In IoT data trading, cloud storage services have been widely used for individuals to store IoT data and for enterprises to automatically facilitate data trading. However, there are still two crucial drawbacks to be solved. From the point of security, it is difficult for data buyers to check the validity of the search result without getting the decryption key of the data owner. From the point of fairness, there is a lack of a punishment mechanism to transfer money from the cheating party to the honest party. To tackle the two challenges, we propose a searchable re-encryption scheme to maintain traditional security without sacrificing service quality. Next, we design a fair trading protocol based on smart contracts to automatically detect any cheating behaviors. Formal security analysis proves that the scheme provides expected security. Experimental results show that the scheme achieve good performance.
Zijian Zhang 0001, Tyler Zhou, Tao Niu, Meng Li 0006, Zhitao Guan, Liehuang Zhu
IEEE Internet Things J.2
2024 A Blockchain-Based Privacy-Preserving Scheme for Sealed-Bid Auction
abstract
The sealed-bid auction enables bidders to secretly send their bids to the auctioneer, which compares all bids and publishes the winning one on the bid-opening day. This type of auction is friendly for protecting the bid privacy, and sufficiently fair for all bidders if the auctioneer acts faithfully. Unfortunately, the auctioneer may not always be trustworthy. The auctioneer has the ability to deliberately leak any bid information to a part of bidders for raising the final winning price based on the investigation. Meanwhile, the auctioneer can appoint any bidder as the winner, as long as the bidder accepts a higher winning price than the current highest bid. Since bidders cannot obtain any bid information from others, to the best of our knowledge, it is difficult to prevent bid leakage from the auctioneer, and support bidders to verify the bid comparison results without disclosing the winning bid, simultaneously. To alleviate these problems, we first construct a homomorphic encryption(HE)-based bid comparison circuit. All bidders can directly compute a cipher of the winning bid by using this circuit; hence, the winning bid does not need to be exposed to all bidders. Then, we propose a blockchain-based sealed-bid scheme (BSS) by integrating the circuit with commitment and zero-knowledge proof. The auctioneer only obtains the commitments of bids before the bid-opening day, and he has to prove that the winner's bid is the same as the plaintext of the bidders' computed cipher. Thus, the auctioneer can neither leak the bid information nor publish a higher winning price during in the auction. Detailed performance analysis shows that the computational complexity of BSS is linear with the binary length of bids.
Zijian Zhang 0001, Meng Li 0006, Jincheng An, Yang Yu 0001, Liehuang Zhu, Jiamou Liu, Bakhadyr Khoussainov
IEEE Trans. Dependable Secur. Comput.1
2024 HCA: Hashchain-Based Consensus Acceleration Via Re-Voting
abstract
In the context of consortium blockchain, consensus protocols set permission mechanisms to maintain a relatively fixed group of participants. They can easily use distributed consistent algorithms for achieving deterministic and efficient consensus and generate incessant blocks as the ledger. However, most of the existing consensus protocols do not sufficiently leverage the chain structure of blocks, and therefore leaving room for performance improvement. In this paper, we first propose a Hashchain-based Consensus Acceleration (HCA) protocol. The HCA protocol enables a leader to generate blocks that contain a quorum of votes on the previous block, and allow voters to re-vote for accelerating the block generation to Byzantine Fault Tolerance (BFT) consensus protocols. Then, we present a rolling-based leader selection (RLS) scheme to further optimize the HCA protocol. In the RLS scheme, the leader is changed in a round-robin fashion. Finally, theoretical analysis proves the safety, liveness and responsiveness of the optimized HCA protocol, while experimental evaluation shows that the optimized HCA protocol outperforms the existing BFT consensus protocols, from the viewpoint of efficiency.
Zijian Zhang 0001, Meng Li 0006, Liehuang Zhu, Bakhadyr Khoussainov, Keke Gai
IEEE Trans. Dependable Secur. Comput.1
2024 Blockchain-Based Covert Communication: A Detection Attack and Efficient Improvement
abstract
Covert channels in blockchain networks achieve undetectable and reliable communication, while transactions incorporating secret data are perpetually stored on the chain, thereby leaving the secret data continuously susceptible to extraction. MTMM (IEEE Transactions on Computers 2023) is a state-of-the-art blockchain-based covert channel. It utilizes Bitcoin network traffic that will not be recorded on the chain to embed data, thus mitigating the above issues. However, we identify a distinctive pattern in MTMM, based on which we propose a comparison attack to accurately detect MTMM traffic. To defend against the attack, we present an improvement named ORIM, which exploits the permutation of transaction hashes within inventory messages to transmit secret data. ORIM leverages a pseudo-random function to obscure the transaction hashes involved in the permutation to ensure unobservability. The obfuscated values, rather than the original transaction hashes, are utilized to encode the confidential data. Furthermore, we introduce a variable-length encoding scheme predicated on complete binary trees. This scheme considerably amplifies the bandwidth and facilitates efficient encoding and decoding of secret data. Experimental results indicate that ORIM maintains unobservability and that ORIM’s bandwidth is approximately$3.7\times $of MTMM.
Zhuo Chen 0001, Liehuang Zhu, Peng Jiang 0007, Zijian Zhang 0001, Chengxiang Si
IEEE Trans. Inf. Forensics Secur.4
2024 Graph-Based Covert Transaction Detection and Protection in Blockchain
abstract
Covert communication is an method that plays an important role in secure data transmission. The technology embeds covert information into data and propagates it through covert channels. The communication quality depends on the choice of channel and data embedding techniques. Recently, blockchain has emerged to become the preferred channel to carry out covert communication for its decentralization and anonymity features. Existing covert transaction methods are constructed transaction-by-transaction, which makes them immune to text analysis-based detection methods. However, it is easy to expose their features on the transaction graph level. Unfortunately, there is yet no method to detect covert transactions by the features of transaction graph. In this paper, we propose a covert transaction detection method based on graph structure. By analyzing the statistical features of graph structure for addresses, we can infer whether they are the participants of covert transactions. Furthermore, we design a protection method of covert transactions based on graph generation networks. By adjusting the structural features between different addresses, our method enhances the security of multiple interrelated covert transactions. Experimental analysis on the Bitcoin Testnet verifies the security and the efficiency of the proposed methods.
Xin Li 0033, Jiamou Liu, Zijian Zhang 0001, Meng Li 0006, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.4
2024 Decentralized Threshold Signatures With Dynamically Private Accountability
abstract
Threshold signature is a fundamental cryptographic primitive used in many practical applications. As proposed by Boneh and Komlo (CRYPTO’22), TAPS is a threshold signature that is a hybrid of privacy and accountability. It enables a combiner to combine$t$signature shares while revealing nothing about the threshold$t$or signing quorum to the public and asks a tracer to track a signature to the quorum that generates it. However, TAPS has three disadvantages: it 1) structures upon a centralized model, 2) assumes that both combiner and tracer are honest, and 3) leaves the tracing unnotarized and static. In this work, we introduce Decentralized, Threshold, dynamically Accountable and Private Signature (DeTAPS) that provides decentralized combining and tracing, enhanced privacy against untrusted combiners (tracers), and notarized and dynamic tracing. Specifically, we adopt Dynamic Threshold Public-Key Encryption (DTPKE) to dynamically notarize the tracing process, design non-interactive zero knowledge proofs to achieve public verifiability of notaries, and utilize the Key-Aggregate Searchable Encryption to bridge TAPS and DTPKE so as to awaken the notaries securely and efficiently. In addition, we formalize the definitions and security requirements for DeTAPS. Then we present a concrete construction and formally prove its security and privacy. To evaluate the performance, we build a prototype based on SGX2 and Ethereum.
Meng Li 0006, Hanni Ding, Qing Wang 0060, Weizhi Meng 0001, Liehuang Zhu, Zijian Zhang 0001, Xiaodong Lin 0001
IEEE Trans. Inf. Forensics Secur.7
2024 Anonymous, Secure, Traceable, and Efficient Decentralized Digital Forensics
abstract
Digital forensics is crucial to fight crimes around the world. Decentralized Digital Forensics (DDF) promotes it to another level by channeling the power of blockchain into digital investigations. In this work, we focus on the privacy and security of DDF. Our motivations arise from (1) how to track an anonymous-and-malicious data user who leaks only a part of the previously requested data, (2) how to achieve access control while protecting data from untrusted data centers, and (3) how to enable efficient and secure search on the blockchain. To address these issues, we propose Themis: an anonymous and secure DDF scheme with traceable anonymity, private access control, and efficient search. Our framework is boosted by establishing a Trusted Execution Environment in each authority (blockchain node) for securing the uploading, requesting, and searching. To instantiate the framework, we design a secure and robust watermarking scheme in conjunction with decentralized anonymous authentication, a private and fine-grained access control scheme, and an efficient and secure search scheme based on a dynamically updated data structure. We formally define and prove the privacy and security of Themis. We build a prototype with Ethereum and Intel SGX2 to evaluate its performance, which supports processing data from a considerable number of data providers and investigators.
Meng Li 0006, Yanzhe Shen, Guixin Ye, Jialing He, Zijian Zhang 0001, Liehuang Zhu, Mauro Conti
IEEE Trans. Knowl. Data Eng.6
2024 Decentralized and Privacy-Preserving Smart Parking With Secure Repetition and Full Verifiability
abstract
Smart Parking Services (SPSs) enable cruising drivers to find the nearest parking lot with available spots, reducing the traveling time, gas, and traffic congestion. However, drivers risk the exposure of sensitive location data during parking query to an untrusted Smart Parking Service Provider (SPSP). Our motivation arises from a repetitive query to an updated database, i.e., how a driver can be repetitively paired with a previously-matched-but-forgotten lot. Meanwhile, we aim to achieve repetitive query in an oblivious and unlinkable manner. In this work, we present Mnemosyne2 : decentralized and privacy-preserving smart parking with secure repetition and full verifiability. Specifically, we design repetitive, oblivious, and unlinkable Secure k Nearest Neighbor (SkNN) with basic verifiability (correctness and completeness) for encrypted-andupdated databases. We build a local Ethereum blockchain to perform driver-lot matching via smart contracts. To adapt to the lot count update, we resort to the immutable blockchain for advanced verifiability (truthfulness). Last, we utilize decentralized blacklistable anonymous credentials to guarantee identity privacy. Finally, we formally define and prove privacy and security. We conduct extensive experiments over a real-world dataset and compare Mnemosyne2 with existing work. The results show that a query only needs 8 seconds (175 ms) on average for service waiting (verification) among 500 drivers.
Meng Li 0006, Liehuang Zhu, Zijian Zhang 0001, Mauro Conti, Mamoun Alazab
IEEE Trans. Mob. Comput.4
2024 Dolphin: Efficient Non-Blocking Consensus via Concurrent Block Generation
abstract
Blockchain technology has become a research hotspot in distributed systems, aiming to sustain a decentralized ledger via consensus. Traditional consensus solutions exhibit slow processing speed and response time, resulting in poor performance. To address this issue, several consensus protocols have been proposed. One such popular protocol is HotStuff, a Byzantine fault-tolerant consensus (BFT) that achieves high throughput at the cost of latency. However, its throughput suffers from a proportional decrease with the increase in latency, posing a significant challenge. In this paper, we propose a new protocol called Dolphin that builds upon HotStuff. It operates in a partially synchronous network with$n$replicas, up to$f$byzantine faults, where$n \ge 3f+1$, and achieves higher throughput in high-latency environments by leveraging non-blocking concurrent block generation. Specifically, we formalize our strategy as a generic Asynchronization Procedure Patch and prove that it does not affect the execution process of the original protocol. Theoretical analysis validates that Dolphin preserves the safety, liveness, and responsiveness properties while enhancing the throughput. The evaluation demonstrates that Dolphin typically achieves more than 10x higher throughput in Wide Area Network (WAN) environments with lower latency compared to HotStuff and its variants, and exhibits similar bandwidth utilization to DAG-based protocols such as Narwhal.
Kaiyu Feng, Zijian Zhang 0001, Meng Li 0006, Wenqian Lai, Liehuang Zhu
IEEE Trans. Mob. Comput.3
2024 RAC-Chain: An Asynchronous Consensus-based Cross-chain Approach to Scalable Blockchain for Metaverse
abstract
The metaverse, as an emerging technical term, conceptually aims to construct a virtual digital space that runs parallel to the physical world. Due to human behaviors and interactions being represented in the virtual world, security in the metaverse is a challenging issue in which the traditional centralized service model is one of the threat sources. To conquer the obstacle caused by centralized computing, blockchain-based solutions are potential problem-solving methods. However, it is difficult for a single blockchain to support large-scale data and business services in the metaverse, due to the scalability restrictions. Moreover, multi-chain settings also encounter the interoperability issues. In this work, we propose a Relay chain and Asynchronous consensus-based Consortium blockchain cross-Chain model, which realizes message transmission and cross-chain transactions in multiple chains by adopting the relay chain and cross-chain gateways. All nodes of the application chains and the relay chain execute cross-chain transactions in sequence and reach a consensus on transactions at any transmission delay. Our experiment evaluations demonstrate that our approach performs well in atomicity, security, and functionality (cross-chain transactions), such that the performance of blockchain scalability in the metaverse can be improved, compared with the traditional relay chain schemes.
Tianxiu Xie, Keke Gai, Liehuang Zhu, Shuo Wang 0026, Zijian Zhang 0001
ACM Trans. Multim. Comput. Commun. Appl.5
2024 ABDP: Accurate Billing on Differentially Private Data Reporting for Smart Grids
abstract
While smart grid significantly facilitates energy efficiency by using users’ power consumption data, it poses privacy leakage risk for user personal behaviors. Differential privacy (DP) has emerged as a promising solution to address this issue. However, existing approaches suffer from severe data utility degradation due to the intensive noise introduced by DP. Additionally, some of these methods are vulnerable to security attacks. To bridge this gap, in this paper, we propose ABDP (accuratebilling-enableddifferentiallyprivate), a mechanism that achieves high-strength DP while ensuring accurate aggregation and billing operations without compromising security. In particular, we propose aggregated and individual noise cancellation algorithms to counteract the negative effects of noise on data utility. Specifically, our ABDP ensures precise aggregation and accurate billing calculations for the power grid and individual users, respectively Furthermore, we present a Blockchain smart contract exploiting the pseudo random function to enforce a fair and secure data reporting process. Theoretical analysis is provided to evaluate the privacy and security guarantees of ABDP. Experimental results on real-world datasets, namely NERL-DATA and REDD, demonstrate that ABDP achieves error-free aggregation and billing calculation, offers arbitrary intensity privacy protection against non-intrusive load monitoring and filtering attacks, and outperforms existing state-of-the-art approaches.
Jialing He, Ning Wang 0003, Tao Xiang 0001, Yiqiao Wei, Zijian Zhang 0001, Meng Li 0006, Liehuang Zhu
IEEE Trans. Serv. Comput.5
2024 Time-Restricted, Verifiable, and Efficient Query Processing Over Encrypted Data on Cloud
abstract
Outsourcing data users’ location data to a cloud server (CS) enables them to obtain$k$nearest points of interest. However, data users’ privacy concerns hinder the wide-scale use. Several studies have achieved Secure k Nearest Neighbor (SkNN) query, but do not addresstime-restricted accessorresult privacy, and randomly partition data items which degrades efficiency. In this article, we proposeTime-restricted,verifiable, andefficientQueryProcessing (TiveQP). TiveQP has three distinguishing features. 1) Expand SkNN: data users can query$k$nearest locations open at a specific time. 2) Adopt a stronger threat model: we assume the CS is malicious and proposecomplementary set(i.e., transform proving “in” a set to proving “in” its complementary set) to allow data users to verify results without leaking unqueried data items’ information. 3) Improve efficiency: we design a space encoding technique and a pruning strategy to improve efficiency in query processing and result verification. We formally proved the security of TiveQP in the random oracle model. We conducted extensive evaluations over a Yelp dataset to show that TiveQP significantly improves over existing work, e.g., top-10NN query over 100 thousand data items only needs 10 ms to get queried results and 1.4 ms for verification.
Meng Li 0006, Liehuang Zhu, Zijian Zhang 0001, Chhagan Lal, Mauro Conti
IEEE Trans. Serv. Comput.4
2024 Phantasm: Adaptive Scalable Mining Toward Stable BlockDAG
abstract
Blockchain technology builds an immutable and append-only ledger in peer-to-peer networks, which attracts attention from various fields. However, traditional chain-based blockchain systems typically have the problem of low throughput, leading to unsatisfactory performance. Among the proposed solutions, introducing a structure of the Directed Acyclic Graph (DAG) into the blockchain reaches a high transaction throughput. Such an approach enables blocks to refer to more than one previous block, thus processing blocks in parallel with better performance. However, existing DAG-based blockchain schemes do not establish a deterministic rule for block reference priority. Adversaries can initiate a splitting attack to select block references to affect DAG topology, making the consensus unstable. In this paper, we propose a more stable consensus protocol named Phantasm, aiming to stabilize the ordering result in the consensus protocol. The referred blocks can be decided after computing a solution to the block puzzle and the difficulty of this solution affects the number of block references. We design two strategies to guide the honest nodes to select references so that they can resist the splitting attacks to stabilize the ordering. Theoretical analysis and simulation experiments show that Phantasm is more stable than the classic DAG-based blockchain consensus protocol Phantom regarding the ordering results.
Zijian Zhang 0001, Kaiyu Feng, Mingchao Wan, Meng Li 0006, Jin Dong 0004, Liehuang Zhu
IEEE Trans. Serv. Comput.1
2023 MSDC: Exploiting Multi-State Power Consumption in Non-intrusive Load Monitoring Based on a Dual-CNN Model
abstract
Non-intrusive load monitoring (NILM) aims to decompose aggregated electrical usage signal into appliance-specific power consumption and it amounts to a classical example of blind source separation tasks. Leveraging recent progress on deep learning techniques, we design a new neural NILM model {\em Multi-State Dual CNN} (MSDC). Different from previous models, MSDC explicitly extracts information about the appliance's multiple states and state transitions, which in turn regulates the prediction of signals for appliances. More specifically, we employ a dual-CNN architecture: one CNN for outputting state distributions and the other for predicting the power of each state. A new technique is invented that utilizes conditional random fields (CRF) to capture state transitions. Experiments on two real-world datasets REDD and UK-DALE demonstrate that our model significantly outperform state-of-the-art models while having good generalization capacity, achieving 6%-10% MAE gain and 33%-51% SAE gain to unseen appliances.
Jialing He, Jiamou Liu, Zijian Zhang 0001, Yang Chen 0028, Bakhadyr Khoussainov, Liehuang Zhu
AAAI3
2023 RSGNN: A Model-agnostic Approach for Enhancing the Robustness of Signed Graph Neural Networks
abstract
Signed graphs model complex relations using both positive and negative edges. Signed graph neural networks (SGNN) are powerful tools to analyze signed graphs. We address the vulnerability of SGNN to potential edge noise in the input graph. Our goal is to strengthen existing SGNN allowing them to withstand edge noises by extracting robust representations for signed graphs. First, we analyze the expressiveness of SGNN using an extended Weisfeiler-Lehman (WL) graph isomorphism test and identify the limitations to SGNN over triangles that are unbalanced. Then, we design some structure-based regularizers to be used in conjunction with an SGNN that highlight intrinsic properties of a signed graph. The tools and insights above allow us to propose a novel framework, Robust Signed Graph Neural Network (RSGNN), which adopts a dual architecture that simultaneously denoises the graph while learning node representations. We validate the performance of our model empirically on four real-world signed graph datasets, i.e., Bitcoin_OTC, Bitcoin_Alpha, Epinion and Slashdot, RSGNN can clearly improve the robustness of popular SGNN models. When the signed graphs are affected by random noise, our method outperforms baselines by up to 9.35% Binary-F1 for link sign prediction. Our implementation is available in PyTorch1.
Zeyu Zhang 0004, Jiamou Liu, Xianda Zheng, Yifei Wang 0003, Pengqian Han, Yupan Wang, Kaiqi Zhao 0001, Zijian Zhang 0001
WWW8
2023 SmartAuction: A blockchain-based secure implementation of private data queries
Mengxiao Zhang 0002, Jiamou Liu, Kaiyu Feng, Fernando Beltrán 0001, Zijian Zhang 0001
Future Gener. Comput. Syst.5
2023 EBDL: Effective blockchain-based covert storage channel with dynamic labels
Can Zhang 0002, Liehuang Zhu, Chang Xu 0004, Zijian Zhang 0001, Rongxing Lu
J. Netw. Comput. Appl.4
2023 Guest Editorial Special Issue on Multi-Modal Biomedical Computing-Deep Transfer Learning
abstract
In Recent years, the development of biomedical imaging techniques, integrative sensors, and artificial intelligence has brought many benefits to the protection of health. We can collect, measure, and analyze vast volumes of health-related data using the technologies of computing and networking, leading to tremendous opportunities for the health and biomedical community. Biomedical intelligence, especially precision medicine, is considered one of the most promising directions for healthcare development. This special issue aims to prompt Deep Transfer Learning techniques in Multi-modal Biomedical Computing. After a rigorous review according to relevance, originality, technical novelties, and presentation quality, we selected 21 high-quality manuscripts. A summary is outlined below.
Honghao Gao, Zijian Zhang 0001, Ramón J. Durán
IEEE ACM Trans. Comput. Biol. Bioinform.2
2023 Blockchain-Based Multisignature Lock for UAC in Metaverse
abstract
As an emerging digital concept offering interconnections across multiple platforms, the metaverse provides digital transformations for various aspects of the physical world, facilitated by a few novel technologies, for example, cloud computing offers data support for the digital world. Humans immersed in the metaverse are digital entities who communicate with others or objects, such that ubiquitous access controls (UACs) are indispensable sectors for multiple platforms. However, in the metaverse, UACs have opened a wide scope of bridges for individuals to shuttle the virtual world, which implies that numerous threats exist at the access layer due to a great pool of entries. In this paper, to solve security issues in the UAC setting of the metaverse, we propose a novel blockchain-based multisignature lock for UAC (BMSL-UAC) scheme. All data institutions reconstruct a consortium blockchain system. In addition, our proposed scheme ensures that only authorized users can access an institution’s data. Finally, we abstract the user’s data access behaviors into the transaction information of the consortium blockchain system to realize full life-cycle data management and traceability. To verify the performance of our scheme, a series of experiments are carried out on the Hyperledger, and evaluation results have demonstrated that the resource consumption, delay, and throughput of this scheme are all within a reasonable range.
Keke Gai, Shuo Wang 0026, Hui Zhao 0002, Yufeng She, Zijian Zhang 0001, Liehuang Zhu
IEEE Trans. Comput. Soc. Syst.5
2023 Astraea: Anonymous and Secure Auditing Based on Private Smart Contracts for Donation Systems
abstract
Many regions are in urgent need of facial masks for slowing down the spread of COVID-19. To fight the pandemic, people are contributing masks through donation systems. Most existing systems are built on a centralized architecture which is prone to the single point of failure and lack of transparency. Blockchain-based solutions neglect fundamental privacy concerns (donation privacy) and security attacks (collusion attack, stealing attack). Moreover, current auditing solutions are not designed to achieve donation privacy, thus not appropriate in our context. In this work, we design a decentralized, anonymous, and secure auditing frameworkAstraeabased on private smart contracts for donation systems. Specifically, we integrate a Distribute Smart Contract (DiSC) with an SGX Enclave to distribute donations, prove the integrity of donation number (intention) and donation sum while preserving donation privacy. With DiSC, we design a Donation Smart Contract to refund deposits and defend against the stealing attack the collusion attack from malicious collector and transponder. We formally define and prove the privacy and security of Astraea by using security reduction. We build a prototype of Astraea to conduct extensive performance analysis. Experimental results demonstrate that Astraea is practically efficient in terms of both computation and communication.
Meng Li 0006, Yifei Chen 0005, Liehuang Zhu, Zijian Zhang 0001, Jianbing Ni, Chhagan Lal, Mauro Conti
IEEE Trans. Dependable Secur. Comput.4
2022 Graph Encryption for Shortest Path Queries with k Unsorted Nodes
abstract
Shortest distance queries over large-scale graphs bring great benefits to various applications, i.e., save planning time and travelling expenses. To protect the sensitive nodes and edges in the graph, a user outsources an encrypted graph to an untrusted server without losing the query ability. However, no prior work has considered the user requirement of the shortest path with k unsorted nodes. In particular, we are concerned with how to securely find the shortest path by passing k nodes that do not have a fixed traverse order. To solve the problems, we propose Gespun (stands for Graph encryption for shortest path queries with k unordered nodes). It includes an oracle encryption scheme that is provably secure against the semi-honest server. Specifically, we compute the shortest paths and distances for all nodes locally to obtain path-distance oracles. We transform the shortest paths to a sequence of secure codes by using a pseudo-random permutation to protect the structure privacy. We encrypt the shortest distance by using additively homomorphic encryption. Second, we pack the oracles in link-list nodes and store them in an array-based dictionary after another permutation. Next, we construct a search graph to compute the shortest path while guaranteeing that the path passes the required k nodes. We formally prove that Gespun is adaptively semantically-secure in the random oracle. We implement a prototype of Gespun and evaluate its performance. Experiments results demonstrate that Gespun is efficient, e.g., a query over 6301 nodes, 20777 edges, and 5 unsorted nodes only needs 483 ms to get queried results. We believe that our research problem span new research that soon promotes a new line of graph encryption schemes.
Meng Li 0006, Zijian Zhang 0001, Chaoping Fu, Chhagan Lal, Mauro Conti
TrustCom3
2022 Practical Blockchain-Based Steganographic Communication Via Adversarial AI: A Case Study In Bitcoin
abstract
Abstract With the development of 5G, the wireless Internet of Things (IoT) has become possible; how to provide privacy protections for the communication of IoT devices in a more vulnerable wireless transmission environment is a huge challenge. Thus, steganography is introduced as a safe and effective technology. Blockchain systems have been widely used in the area of steganography. Several works attempted to embed covert data into transactions in public blockchain systems such as Bitcoin, Ethereum and Monero. However, most of them merely focus on putting covert data into certain fields in transactions based on cryptographic algorithms. In this paper, a Covert Transaction Recognition (CTR) model is proposed by the Text Convolutional Neural Networks and Back Propagation Neural Networks. When utilizing the covert data-embedded field for recognizing, our CTR model can attain 0.79 precision and 0.83 recall on average for seven covert transaction construction schemes. The precision and recall can increase by at most 43 and 47%, respectively, if other unembedded fields were additionally exploited for recognition. We further propose a Practical Covert Transaction Construction (PCTC) model. This model fixes the contents in the embedded fields of the constructed transactions, and generates the contents in other fields using Generative Adversarial Networks. Experimental results demonstrated that the precision and recall are greatly decreased when identifying the covert transactions generated by our PCTC model. The data underlying this article are available in ‘covert-transaction-model’, at https://github.com/1997mint/covert-transaction-model.
Minxian Wang, Zijian Zhang 0001, Jialing He, Feng Gao 0019, Meng Li 0006, Shubin Xu, Liehuang Zhu
Comput. J.2
2022 Chain-Based Covert Data Embedding Schemes in Blockchain
abstract
The quality of covert communications is determined by the choice of communication channels and the design of data embedding schemes. Recently, the Bitcoin system is prevalent as a covert communication channel. The consensus mechanism requires participants to spread their found valid blocks under an adjustable difficulty, which provides a stable periodic broadcast channel. Moreover, senders and receivers are difficult to be traced, because the Bitcoin system is pseudonymous. However, since the historical data in the ledger cannot be removed from the Bitcoin system, the openness and the persistent storage of the ledger in the Bitcoin system post new challenges when designing data embedding schemes. More concreteness, most traditional data embedding schemes either design by heuristic or empirical algorithms or use a fixed field to embed data in the transactions. Therefore, the covert data can be recognized once the algorithm is leaked or the pattern is explored. In this article, we first propose a hash chain-based covert data embedding (HC-CDE) scheme. The embedded transactions are difficult to be discovered. We further propose an elliptic curve Diffie–Hellman chain-based covert data embedding (ECDHC-CDE) scheme to enhance the security of the HC-CDE scheme. Experimental analysis on the Bitcoin Testnet verifies the security and the efficiency of the proposed schemes.
Feng Gao 0019, Zijian Zhang 0001, Bakhadyr Khoussainov, Shubin Xu, Liehuang Zhu
IEEE Internet Things J.4
2022 Proof of Continuous Work for Reliable Data Storage Over Permissionless Blockchain
abstract
Bitcoin first proposed the Nakamoto consensus that applies proof of work into the blockchain structure to build a trustless append-only ledger. The Nakamoto consensus solves the distributed consistency problem in the public network but wastes too much computing power. Instead of consuming computing resources, many improved consensus schemes address this problem by leveraging miners’ storage resources. However, these schemes fail to let miners store data constantly and usually rely on a dealer to assign data, which is hard to build a reliable decentralized storage system. In this article, we first design a variant consensus algorithm named Proof of Continuous Work (PoCW) with a storage-related incentive mechanism. Miners can accumulate mining advantage by continuously submitting proofs of storage. Then, we present a hash ring-based data allocation algorithm using the blockchain’s state. Combined with both of them, we build a reliable blockchain-based storage system without relying on any third parties. The theoretical analysis and simulation results demonstrate that the proposed system has higher reliability than those existing systems, and we also give practical suggestions about system parameters. Finally, we discuss additional benefits that our system brings.
Zijian Zhang 0001, Jialing He, Liran Ma, Liehuang Zhu, Meng Li 0006, Bakhadyr Khoussainov
IEEE Internet Things J.2
2022 Video Aficionado: We Know What You Are Watching
abstract
Users enjoy the convenience of watching videos on smart devices. However, video watching records can be exposed without users’ knowledge and be exploited to infer private information. In this paper, we design and implement a new side-channel attack system, namedvideo aficionado, which can identify video watching information without violating any access control policies on Android. Our system only needs to collect power consumption data of a video playing app, which does not require explicit user permission. The collected data is sent to a remote server, where noise is cleaned and identified by a multi-layer perceptron (MLP) trained classifier. We evaluate our proposed system through a set of carefully designed experiments. Experimental results demonstrate that our system can make an identification with 74.5 percent accuracy on average for each 20-second power measurement segment out of 3918 segments collected from 20 videos. To the best of our knowledge, video aficionado is the first real-time power consumption-based video identification system on smart devices.
Jialing He, Zijian Zhang 0001, Liran Ma, Bakhadyr Khoussainov, Liehuang Zhu
IEEE Trans. Mob. Comput.2
2022 User-Defined Privacy-Preserving Traffic Monitoring Against n-by-1 Jamming Attack
abstract
Traffic monitoring services collect traffic reports and respond to users’ traffic queries. However, the reports and queries may reveal the user’s identity and location. Although different anonymization techniques have been applied to protect user privacy, a new security threat arises, namely, n-by-1 jamming attack, in which an anonymous contributing driver impersonates$n$drivers and uploads$n$normal reports by using$n$reporting devices. Such an attack will mislead the traffic monitoring service provider and further degrade the service quality. Existing traffic monitoring services do not support customized queries, and private information retrieval techniques cannot be applied directly in traffic monitoring. We formally define the new attack and propose a traffic monitoring scheme TraJ to defend the attack and achieve user-defined location privacy. Specifically, we bridge anonymous contributing drivers without disclosing their speed set by using private set intersection. Each RSU collects time traffic reports and structures a weighted proximity graph to filter out malicious colluding drivers. We design a user-defined privacy-preserving query method by encoding complex road network. We leverage the uploading phase from private aggregation to collect traffic conditions and allow requesting drivers to dynamically and privately query traffic conditions. We provide a formal analysis of TraJ to prove its privacy and security properties. We also construct a prototype based on a real-world dataset and Android smartphones to demonstrate its feasibility and efficiency. A formal analysis demonstrates the privacy and security properties. Extensive experiments illustrate the performance and defense efficacy.
Meng Li 0006, Liehuang Zhu, Zijian Zhang 0001, Chhagan Lal, Mauro Conti, Mamoun Alazab
IEEE/ACM Trans. Netw.3
2021 From Local to Global Norm Emergence: Dissolving Self-reinforcing Substructures with Incremental Social Instruments
abstract
Norm emergence is a process where agents in a multi-agent system establish self-enforcing conformity through repeated interactions. When such interactions are confined to a social topology, several self-reinforcing substructures (SRS) may emerge within the population. This prevents a formation of a global norm. We propose incremental social instruments (ISI) to dissolve these SRSs by creating ties between agents. Establishing ties requires some effort and cost. Hence, it is worth to design methods that build a small number of ties yet dissolve the SRSs. By using the notion of information entropy, we propose an indicator called the BA-ratio that measures the current SRSs. We find that by building ties with minimal BA-ratio, our ISI is effective in facilitating the global norm emergence. We explain this through our experiments and theoretical results. Furthermore, we propose the small-degree principle in minimising the BA-ratio that helps us to design efficient ISI algorithms for finding the optimal ties. Experiments on both synthetic and real-world network topologies demonstrate that our adaptive ISI is efficient at dissolving SRS.
Jiamou Liu, Kaibin Wan, Zhan Qin, Zijian Zhang 0001, Bakhadyr Khoussainov, Liehuang Zhu
ICML5
2021 Exploring active attacks for three incorrect implementations of the ISO/IEC 9798 in satellite networks
Zhengjia Zhu, Zijian Zhang 0001, Tielei Li, Jiamou Liu, Bakhadyr Khoussainov, Chang Xu 0004
Comput. Commun.3
2021 Achieving efficient and Privacy-preserving energy trading based on blockchain and ABE in smart grid
Zhitao Guan, Wenti Yang, Longfei Wu, Naiyu Wang, Zijian Zhang 0001
J. Parallel Distributed Comput.6
2021 On improving knowledge graph facilitated simple question answering system
Xin Li 0033, Hongyu Zang, Xiaoyun Yu, Hao Wu 0066, Zijian Zhang 0001, Jiamou Liu, Mingzhong Wang
Neural Comput. Appl.5
2021 Anonymous and Verifiable Reputation System for E-Commerce Platforms Based on Blockchain
abstract
E-commerce platforms incorporate reputation systems that allow customers to rate suppliers following financial transactions. Existing reputation systems cannot defend the centralized server against arbitrarily tampering with the supplier’s reputation. Furthermore, they do not offer reputation access across platforms. Rates are faced with privacy leakages because rating activities are correlated with privacy (e.g., identity and rating). Meanwhile, raters could be malicious and initiate multiple rating attacks and abnormal rating attacks. Determining how to address these issues have both research and practical value. In this paper, we propose a blockchain-based privacy-preserving reputation system for e-commerce platforms named RepChain; our system allows cross-platform reputation access and anonymous and private ratings. Using RepChain, all e-commerce platforms collaborate and share users’ reputations by co-constructing a consortium blockchain and modeling the rating process as a finite state machine. In particular, we facilitate one-show anonymous credentials constructed from two-move blind signatures to protect customers’ identities and resist multiple rating attacks, leverage zero-knowledge range proof to verify the correctness of ratings and defend against abnormal rating attacks, design a secure sum computation protocol among nodes to update reputations, and verify ratings via batch processing and consensus hashes. Finally, we demonstrate the security and privacy of RepChain via a formal analysis and evaluate its performance based on Ethereum test network.
Meng Li 0006, Liehuang Zhu, Zijian Zhang 0001, Chhagan Lal, Mauro Conti, Mamoun Alazab
IEEE Trans. Netw. Serv. Manag.3
2020 Blockchain Meets DAG: A BlockDAG Consensus Mechanism
Keke Gai, Ziyue Hu, Liehuang Zhu, Ruili Wang 0001, Zijian Zhang 0001
ICA3PP (3)5
2020 WiPOS: A POS Terminal Password Inference System Based on Wireless Signals
abstract
WiFi access points are sources of considerable security risks as the wireless signals have the potential to leak important private information such as passwords. This article examines the security issues posed by point-of-sale (POS) terminals which are widely used in WiFi-covered environments, such as restaurants, banks, and libraries. In particular, we envisage an attack model on passwords entered on POS terminals. We put forward the WiPOS, a password inference system based on wireless signals. Specifically, the WiPOS is a device-free system that uses two commercial off-the-shelf (COTS) devices to collect WiFi signals. Implementing a new keystroke segmentation algorithm and adopting support vector machine (SVM) classifiers with global alignment kernel (GAK), the WiPOS achieves improvement on both keystroke recognition and password prediction. The experimental results show that the WiPOS can achieve more than 73% accuracy for 6-digit password with the top 100 candidates. This article calls the community to take a closer look at the risks posed by the current ubiquitous WiFi devices.
Zijian Zhang 0001, Nurilla Avazov, Jiamou Liu, Bakhadyr Khoussainov, Xin Li 0033, Keke Gai, Liehuang Zhu
IEEE Internet Things J.1
2020 Blockchain-based anomaly detection of electricity consumption in smart grids
Meng Li 0006, Keli Zhang, Jiamou Liu, Hanxiao Gong, Zijian Zhang 0001
Pattern Recognit. Lett.5
2020 ASAP: An Anonymous Smart-Parking and Payment Scheme in Vehicular Networks
abstract
Cruising for a vacant and economical parking spot causes not only time-consuming and frustrating driving experiences, but fuel waste and air pollution. Public parking spots in crowded cities are scarce and expensive. On the contrary, private parking spots usually have low utilization rates, and the spot suppliers are willing to provide their extra parking resources due to a maintenance cost by charging parking fees. Given this situation, it is imperative to call for a smart parking system that collects and provides private parking spots (e.g., around home or workplace) to ease public parking concerns. However, when the suppliers (drivers) are providing (querying for) parking spots, their privacy (e.g., location, identity) is inevitable to be disclosed and existing parking schemes cannot achieve anonymous authentication and anonymous payment simultaneously. To tackle these problems, we propose an anonymous smart-parking and payment (ASAP) scheme in vehicular networks. Specifically, we use short randomizable signature to provide anonymity and conditional privacy. We achieve quick result matching with hashmap and anonymous payment with E-cash. Security analysis and experimental results show that ASAP can protect privacy in a conditional way and has low computational costs and communication overhead.
Liehuang Zhu, Meng Li 0006, Zijian Zhang 0001, Zhan Qin
IEEE Trans. Dependable Secur. Comput.3
2020 Differential Privacy-Based Blockchain for Industrial Internet-of-Things
abstract
Contemporarily, two emerging techniques, blockchain and edge computing, are driving a dramatical rapid growth in the field of Internet-of-Things (IoT). Benefits of applying edge computing is an adoptable complementarity for cloud computing; blockchain is an alternative for constructing transparent secure environment for data storage/governance. Instead of using these two techniques independently, in this article, we propose a novel approach that integrates IoT with edge computing and blockchain, which is called blockchain-based Internet of Edge model. The proposed model, designed for a scalable and controllable IoT system, sufficiently exploits advantages of edge computing and blockchain to establish a privacy-preserving mechanism while considering other constraints, such as energy cost. We implement experiment evaluations running on Ethereum. According to our data collections, the proposed model improves privacy protections without lowering down the performance in an energy-efficient manner.
Keke Gai, Yulu Wu, Liehuang Zhu, Zijian Zhang 0001, Meikang Qiu
IEEE Trans. Ind. Informatics4
2020 Blockchain-Enabled Secure Energy Trading With Verifiable Fairness in Industrial Internet of Things
abstract
Energy trading in Industrial Internet of Things (IIoT), a fundamental approach to realize Industry 4.0, plays a vital role in satisfying energy demands and optimizing system efficiency. Existing research works utilize a utility company to distribute energy to energy nodes with the help of energy brokers. Afterwards, they apply blockchain to provide transparency, immutability, and auditability of peer-to-peer (P2P) energy trading. However, their schemes are constructed on a weak security model and do not consider the cheating attack initiated by energy sellers. Such an attack refers to an energy seller refusing to transfer the negotiated energy to an energy purchaser who already paid money. In this article, we propose FeneChain, a blockchain-based energy trading scheme to supervise and manage the energy trading process toward building a secure energy trading system and improving energy quality for Industry 4.0. Specifically, we leverage anonymous authentication to protect user privacy, and we design a timed-commitments-based mechanism to guarantee the verifiable fairness during energy trading. Moreover, we utilize fine-grained access control for energy trading services. We also build a consortium blockchain among energy brokers to verify and record energy trading transactions. Finally, we formally analyze the security and privacy of FeneChain and evaluate its performance (i.e., computational costs and communication overhead) by implementing a prototype via a local Ethereum test network and Raspberry Pi.
Meng Li 0006, Donghui Hu, Chhagan Lal, Mauro Conti, Zijian Zhang 0001
IEEE Trans. Ind. Informatics5
2019 An Approach of Secure Two-Way-Pegged Multi-sidechain
Jinnan Guo, Keke Gai, Liehuang Zhu, Zijian Zhang 0001
ICA3PP (2)4
2019 REM: From Structural Entropy to Community Structure Deception
abstract
This paper focuses on the privacy risks of disclosing the community structure in an online social network. By exploiting the community affiliations of user accounts, an attacker may infer sensitive user attributes. This raises the problem of community structure deception (CSD), which asks for ways to minimally modify the network so that a given community structure maximally hides itself from community detection algorithms. We investigate CSD through an information-theoretic lens. To this end, we propose a community-based structural entropy to express the amount of information revealed by a community structure. This notion allows us to devise residual entropy minimization (REM) as an efficient procedure to solve CSD. Experimental results over 9 real-world networks and 6 community detection algorithms show that REM is very effective in obfuscating the community structure as compared to other benchmark methods.
Jiamou Liu, Zijian Zhang 0001, Liehuang Zhu, Angsheng Li
NeurIPS3
2019 An Efficient and Accurate Nonintrusive Load Monitoring Scheme for Power Consumption
abstract
Nonintrusive load monitoring (NILM) has attracted tremendous attention owing to its cost efficiency in electricity and sustainable development. NILM aims at acquiring individual appliance power consumption rates using an aggregated power smart meter reading. Each individual appliance's power consumption enables users to monitor their electricity usage habits for rational saving strategies. This is also a valuable tool for detecting failure in appliances. However, the major barriers facing NILM schemes are issues of accurately capturing the features of each appliance and decreasing the computing time. Motivated by these challenges, we propose a new, efficient, and accurate NILM scheme, consisting of a learning step and a decomposing step. In the learning step, we propose the fast search-and-find of density peaks (FSFDPs) clustering algorithm aimed at capturing the features of the power consumption patterns of appliances. In the decomposing step, we propose a genetic algorithm (GA)-based matching algorithm to estimate the power consumption of each individual appliance using the aggregated power reading. Using elitist and catastrophic strategies, this step reduces the searching space to achieve considerable efficiency. Experimental results using the reference energy disaggregation dataset (REDD) indicate that our proposed scheme promotes accuracy by 10% and reduces the decomposing time by half.
Jialing He, Zijian Zhang 0001, Liehuang Zhu, Zhesi Zhu, Jiamou Liu, Keke Gai
IEEE Internet Things J.2
2019 Secure Fog-Assisted Crowdsensing With Collusion Resistance: From Data Reporting to Data Requesting
abstract
The development and ubiquity of smart mobile devices have produced the idea of crowdsensing, where people report and request data in a community via a cloud server. Recently, fog is introduced to assist the cloud server by providing location-sensitive and latency-aware local data management. However, interaction between users and server without appropriate sanitation puts serious security threats to user' privacy (e.g., data content and preference). While existing work already has a wide range of privacy-preserving schemes, they hardly consider collusion attacks (CAs) between the server and users, let alone CAs between fog nodes and users. To solve this problem, we first define four specific CAs in fog-assisted crowdsensing and propose a novel privacy-preserving data reporting and requesting (PARE) scheme with collusion resistance. PARE is constructed by leveraging one-way hash chains, marked mix-nets, and grouping-based secure searchable encryption to securely collect users' reports and respond to users' requests under CAs. Then, we consider one extreme scenario and provide a solution by introducing a role of sentry reporter while reducing computational costs and communication overhead. Thorough security and privacy analysis shows that PARE is secure and collusion resistant and we also quantitatively measure privacy with mutual information. Extensive performance evaluation results indicate that PARE is lightweight with respect to computational cost and communication overhead. To the best of our knowledge, this paper is the first one that gives four formal definitions of CAs in fog-assisted crowdsensing and aim to defend them at the same time.
Liehuang Zhu, Meng Li 0006, Zijian Zhang 0001
IEEE Internet Things J.3
2019 Achieving Privacy-Friendly Storage and Secure Statistics for Smart Meter Data on Outsourced Clouds
abstract
Smart meters have already been widely used for electric utilities to provide reliable power service. Since those meters keep reporting customer's energy consumption data in minute-level or even second-level, Terabyte-level big data has to be stored and analyzed for the companies. To relieve the storage and computation pressure, some companies attempt to outsource their data on the cloud. However, this exposes customer's privacy at risk, because customer's activities can be inferred from analyzing the meter readings. In this paper, we propose a privacy-friendly cloud storage (PCS) scheme and three secure cloud statistic (SCS) schemes for smart meter data on outsourced clouds. Putting these schemes together achieves three queries from the electric companies. Next, we provably analyze the privacy and the security for these schemes. Finally, we design MapReduce algorithms to show the performance for the cloud statistic.
Zijian Zhang 0001, Mianxiong Dong, Liehuang Zhu, Zhitao Guan, Ruoyu Chen 0002, Rixin Xu, Kaoru Ota
IEEE Trans. Cloud Comput.1
2018 A New Satellite Constellation Networking Certification and Reliable Maintenance Protocol (S)
abstract
With the rapid development of satellite technology, the deployment of intensive service applications through satellite has become a trend.In the process of establishing a satellite communication system, there will be some security threats such as counterfeiting, forgery, tampering.This must establish a secure satellite communication system.In this paper, according to the characteristics of satellite communication system, a protocol of satellite network authentication and trusted maintenance is designed.The protocol can accomplish two-way authentication between entities in the satellite network and the credible maintenance of the communication link.The protocol is based on the symmetric encryption system and can adapt to the current satellite load is small, the computing power is limited.This paper also analyses the security of the protocol and can resist replay attacks and man-in-the-middle attacks.Experiments show that the proposed network authentication protocol is 28% faster than the symmetric encryption system.The average time to keep the agreement credible is 254.64 ms.
Congyu Huang, Liehuang Zhu, Chunlei Li 0003, Chuan Zhang 0003, Zijian Zhang 0001
SEKE6
2018 Accountable and Transparent TLS Certificate Management: An Alternate Public-Key Infrastructure with Verifiable Trusted Parties
abstract
Current Transport Layer Security (TLS) Public-Key Infrastructure (PKI) is a vast and complex system; it consists of processes, policies, and entities that are responsible for a secure certificate management process. Among them, Certificate Authority (CA) is the central and most trusted entity. However, recent compromises of CA result in the desire for some other secure and transparent alternative approaches. To distribute the trust and mitigate the threats and security issues of current PKI, publicly verifiable log-based approaches have been proposed. However, still, these schemes have vulnerabilities and inefficiency problems due to lack of specifying proper monitoring, data structure, and extra latency. We propose Accountable and Transparent TLS Certificate Management: an alternate Public-Key Infrastructure (PKI) with verifiable trusted parties (ATCM) that makes certificate management phases; certificate issuance, registration, revocation, and validation publicly verifiable. It also guarantees strong security by preventing man-in-middle-attack (MitM) when at least one entity is trusted out of all entities taking part in the protocol signing and verification. Accountable and Transparent TLS Certificate Management: an alternate Public-Key Infrastructure (PKI) with verifiable trusted parties (ATCM) can handle CA hierarchy and introduces an improved revocation system and revocation policy. We have compared our performance results with state-of-the-art log-based protocols. The performance results and evaluations show that it is feasible for practical use. Moreover, we have performed formal verification of our proposed protocol to verify its core security properties using Tamarin Prover.
Salabat Khan, Zijian Zhang 0001, Liehuang Zhu, Meng Li 0006, Qamas Gul Khan Safi, Xiaobing Chen
Secur. Commun. Networks2
2017 From Secrete Admirer to Cyberstalker: A Measure of Online Interpersonal Surveillance
abstract
By persistently gathering information over social networks, a person can extract detailed accounts of the lives of others and monitor their daily routines. Such surveillance behaviors have posed serious privacy concerns. This paper addresses the question, "who is surveilling you through social networking?". Viewing a network as interconnected agents who interact through posting and retrieving information, we provide a measure to quantify the level of attention a person pays towards another. This measure allows us to capture online interpersonal surveillance.
Zijian Zhang 0001, Jiamou Liu, Ziheng Wei, Yingying Tao, Quan Bai 0001
ASONAM1
2017 Protecting user privacy based on secret sharing with fault tolerance for big data in smart grid
abstract
In smart grid, large quantities of data is collected from various applications, such as smart metering substation state monitoring, electric energy data acquisition, and smart home. Big data acquired in smart grid applications is usually sensitive. For instance, in order to dispatch accurately and support the dynamic price, lots of smart meters are installed at user's house to collect the real-time data, but all these collected data are related to user privacy. In this paper, we propose a data aggregation scheme based on secret sharing with fault tolerance in smart grid, which ensures that control center gets the integrated data without revealing user's privacy. Meanwhile, we also consider fault tolerance during the data aggregation. At last, we analyze the security of our scheme and carry out experiments to validate the results.
Zhitao Guan, Guanlin Si, Xiaojiang Du, Peng Liu 0027, Zijian Zhang 0001, Zhenyu Zhou 0001
ICC5
2017 An efficient encryption scheme with verifiable outsourced decryption in mobile cloud computing
abstract
With the increasing number of mobile applications and the popularity of cloud computing, the combination of these two techniques that named mobile cloud computing (MCC) attracts great attention in recent years. A promising public key encryption scheme, Attribute-Based Encryption (ABE), especially the Ciphertext Policy Attribute-Based Encryption (CP-ABE), has been used for realizing fine-grained access control on encrypted data stored in MCC. However, the computational overhead of encryption and decryption grow with the complexity of the access policy. Thus, maintaining data security as well as efficiency of data processing in MCC are important and challenging issues. In this paper, we propose an efficient encryption method based on CP-ABE, which can lower the overhead on data owners. To further reduce the decryption overhead on data receivers, we additionally propose a verifiable outsourced decryption scheme. By security analysis and performance evaluation, the proposed scheme is proved to be secure as well as efficient.
Jing Li 0006, Zhitao Guan, Xiaojiang Du, Zijian Zhang 0001, Jun Wu 0001
ICC4
2017 When privacy meets economics: Enabling differentially-private battery-supported meter reporting in smart grid
abstract
Millions of the smart meters, as essential components, are being deployed ubiquitously in the next generation power system. However, the public privacy concerns over the users' power consumption leakage raise, since the smart meters' unintermittent readings contain customers' behavior patterns. To alleviate this problem, the state-of-the-art techniques are common to use a rechargeable battery to hide the actual power consumption. Unfortunately, none of the existing works completely provide a rigorous privacy protection with reasonable cost under real-world battery settings, i.e., achieving the well-known differential privacy guarantee economically using batteries with limited charge/discharge rate and capacity. To attain this goal, this paper proposes a differentially private meter reading report mechanism. The main idea is to first narrow down the domain of the noise distribution parameter, in order to decrease the possibility of violating the battery limits. It also combines a multi-armed bandit algorithm to further reduce the cost as much as possible. In addition, a novel switch mechanism is proposed to prevent the meter from reporting its reading when the battery limitations might be violated. The theoretical analysis provides a formal proof of the privacy guarantee of the proposed scheme. Besides, experimental results show that the privacy protection of the proposed scheme is at least nine times stronger than that of the existing solutions with acceptable extra cost.
Zijian Zhang 0001, Wenqiang Cao, Zhan Qin, Liehuang Zhu, Zhengtao Yu 0001, Kui Ren 0001
IWQoS1
2017 An Efficient Sparse Coding-Based Data-Mining Scheme in Smart Grid
Dongshu Wang, Jialing He, Mussadiq Abdul Rahim, Zijian Zhang 0001, Liehuang Zhu
MSN4
2017 Facility Location Selection Using Community-Based Single Swap: A Case Study
Rixin Xu, Zijian Zhang 0001, Jiamou Liu, Nathan Situ, Jun Ho Jin
MSN2
2017 Achieving Communication Effectiveness of Web Authentication Protocol with Key Update
Zijian Zhang 0001, Chongxi Shen, Liehuang Zhu, Salabat Khan, Chuyi Chen
MSN1
2017 A Low-Latency Secure Data Outsourcing Scheme for Cloud-WSN
abstract
With the support of cloud computing, large quantities of data collected from various WSN applications can be managed efficiently. However, maintaining data security and efficiency of data processing in cloud- WSN (C-WSN) are important and challenging issues. In this paper, we present an efficient data outsourcing scheme based on CP-ABE, which can not only guarantee secure data access, but also reduce overall data processing time. In our proposed scheme, a large file is divided into several data blocks by data owner (DO) firstly. Then, the data blocks are encrypted and transferred to the cloud server in parallel. For data receiver (DR), data decryption and data transmission is also processed in parallel. In addition, data integrity can be checked by DR without any master key components. The security analysis shows that the proposed scheme can meet the security requirement of C-WSN. By performance evaluation, it shows that our scheme can dramatically improve data processing efficiency compared to the traditional CP-ABE method.
Jing Li 0006, Zhitao Guan, Xiaojiang Du, Zijian Zhang 0001, Zhenyu Zhou 0001
WCNC4
2017 A privacy-preserving video subscription scheme with the limitation of expire date
Liehuang Zhu, Mingxin Chen, Zijian Zhang 0001, Ange Tong
Sci. China Inf. Sci.3
2017 Achieving differential privacy of trajectory data publishing in participatory sensing
Meng Li 0006, Liehuang Zhu, Zijian Zhang 0001, Rixin Xu
Inf. Sci.3
2017 Toward Delay-Tolerant Flexible Data Access Control for Smart Grid With Renewable Energy Resources
abstract
In the smart grid with renewable energy resources (RERs), the residential units (RUs) with distributed energy resources are considered to be both power consumers and suppliers. Specifically, RUs with excessive renewable generations can trade with the utility in deficit of power supplies for mutual benefits. It causes two challenging issues. First, the trading data of RUs are quite sensitive, which should be only accessed by authorized users with fine-grained policies. Second, the behaviors of the RUs to generate trading data are spontaneous and unpredictable, and then the problem is how to guarantee system efficiency and delay tolerance simultaneously. In this paper, we propose a delay-tolerant flexible data access control scheme based on key policy attribute-based encryption for smart grid with RERs. We adopt the secret-sharing scheme to realize a flexible access control with encryption delay tolerance. Furthermore, there is no central trusted server to perform the encryption/decryption. We reduce the computation cost on RUs and operators via a semitrusted model. The analysis shows that the proposed scheme can meet the data security requirement of the smart grid with RERs, and it also has less cost compared with other popular models.
Zhitao Guan, Jing Li 0006, Liehuang Zhu, Zijian Zhang 0001, Xiaojiang Du, Mohsen Guizani
IEEE Trans. Ind. Informatics4
2016 Risk-aware intermediate dataset backup strategy in cloud-based data intensive workflows
Mingzhong Wang, Liehuang Zhu, Zijian Zhang 0001
Future Gener. Comput. Syst.3
2015 How to protect query and report privacy without sacrificing service quality in participatory sensing
abstract
The ubiquity of mobile devices has brought forth the concept of participatory sensing, whereby people can collect and share data from ambient environment for the benefit of themselves or community. To encourage participation of all stakeholders and guarantee system functionality, a privacy-preserving participatory sensing system should be established to hide querier's and participant's sensitive information(e.g., interest, location and content). Meanwhile, it is also imperative for server to provide an accurate and quick service(match the “need” with “supply” and retrieve the desired result from collected data set) for queriers when queries and reports are encrypted to protect privacy. In this paper, we propose Query and Report privacy-preserving protocol(QueRe) in participatory sensing system aiming to protect the query privacy and report privacy without sacrificing the service quality. Security analysis and performance simulation show our method achieves superior performance in privacy protection and service quality. To the best of our knowledge, our work is first attempt for protecting query privacy and report privacy while considering server's service quality.
Meng Li 0006, Fan Wu 0006, Guihai Chen, Liehuang Zhu, Zijian Zhang 0001
IPCCC5
2015 Scalable protocol for cross-domain group password-based authenticated key exchange
Cong Guo 0001, Zijian Zhang 0001, Liehuang Zhu, Yu-an Tan 0001, Zhen Yang 0003
Frontiers Comput. Sci.2
2013 Enhanced Privacy Preserving Pattern-Code Based Data Aggregation in Wireless Sensor Networks
abstract
In their nature, wireless sensor nodes are resource restrained, such as low power capabilities and small memory. These limitations inevitably affect secure energy-efficient wireless sensor networks protocols in such way that some cryptographic algorithms such as asymmetric algorithms are not convenient to be used in wireless sensor nodes. In this paper, based on perturbation-based efficient confidentiality preserving scheme and Energy-Efficient Secure Pattern Based Data Aggregation for Wireless Sensor Networks scheme, we achieve higher energy-efficiency by using pattern-codes approach to avoid energy wastage due to sending redundant data to cluster-heads. Symmetric cryptographic algorithms such as perturbation algorithm used are more convenient to wireless sensors by providing high data privacy and confidentiality as well.
Bernard Ntirenganya, Zijian Zhang 0001, Liehuang Zhu, Yu-an Tan 0001, Zhen Yang 0003, Cong Guo 0001
MSN2
2012 Computationally sound symbolic security reduction analysis of the group key exchange protocols using bilinear pairings
Zijian Zhang 0001, Liehuang Zhu, Lejian Liao, Mingzhong Wang
Inf. Sci.1