EDBT 2026 Demo / reviewers in the wild / expert
Guangquan Xu
dblp:46/241
· DBLP profile ↗
111ranked-venue papers
23as first author
55since 2021 · last 2026
0000-0001-8701-3944ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 25 · 8 first-author · 14 since 2021Computer networks · 22 · 5 first-author · 12 since 2021Systems, architecture and hardware · 16 · 3 first-author · 7 since 2021Software engineering, systems software and programming languages · 13 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 12 · 2 first-author · 6 since 2021Artificial intelligence and machine learning · 11 · 9 since 2021Databases, data management, data science and information retrieval · 6 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 6 · 3 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DualDis: A Dual Disentanglement Network for Vehicle Re-identification
Wenying He, Guangquan Xu, Yude Bai, Fei Guo 0001 |
WWW | 3 |
| 2026 | Quantum-resistant and extractable bilateral fine-grained access control for EMRs sharing
Chenghe Dong, Guangquan Xu, Guohua Xin, Jianhong Zhang 0001, Cong Wang 0004 |
Expert Syst. Appl. | 2 |
| 2026 | HMMShard: An HMM-based adaptive sharding framework for IIoT blockchain
Guangquan Xu, Cong Wang 0004, Jingyi Cui, Zenghao Yang |
J. Netw. Comput. Appl. | 2 |
| 2026 | A NMF framework based on dynamic symmetric inertia for anomaly detection of temporal community evolution
Shihong Wu, Guangquan Xu, Hongpeng Bai, Weiyan Yang, Peiliang Sun |
Pattern Recognit. | 3 |
| 2026 | Rubato: Efficient Post-Quantum Asynchronous Distributed Randomness Beacon With Integrated ConsensusabstractDistributed randomness beacons are essential for distributed systems (e.g., blockchain and MPC), providing un biased and unpredictable shared randomness. However, implementations in asynchronous networks often suffer from poor scal ability, low throughput, and high resource consumption when deployed as independent protocols. The state-of-the-art HashRand (CCS'24) achieves high throughput and low computational in tensity using only lightweight post-quantum cryptographic primitives for an independent asynchronous beacon. Building further on this, we propose Rubato, a low-overhead, high-throughput beacon protocol that leverages lightweight batched Asynchronous Complete Secret Sharing with Byzantine Atomic Broadcast-based state machine replication (via our tailored RubatoSMR). Rubato reduces communication complexity by an O(clogn) factor compared to HashRand and resolves the circular dependency between beacon and BAB-SMR in asynchronous settings. Experiments on AWSdemonstrate that Rubato achieves ideal overall performance in scalability, resource usage, and throughput; for instance, at n = 121nodes, it produces an average of 174 beacons per minute, with RubatoSMR further optimizing memory and bandwidth consumption. Linghe Yang, Tonghong Chong, Jian Liu 0004, Jingyi Cui, Guangquan Xu, Yude Bai, Lei Zhang 0024, Tao Luo 0010 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | Knowledge is Power: A Knowledge Graph-Based Approach for Mobile Malware Traceability Analysis
Yao Zhang 0019, Guangquan Xu, Xiaohong Li 0001, Sen Chen 0001, Zhenchang Xing, Yude Bai, Yongqiang Lyu 0001, Wei Gong 0001, Xibin Zhao |
IEEE Trans. Mob. Comput. | 2 |
| 2026 | UFG-AFLNET: A Greybox Fuzzing Framework With Fine-Grained State Modeling and Gradient-Guided Mutation for Network ProtocolsabstractGreybox fuzzing has become an effective technique for uncovering vulnerabilities in network protocol implementations. However, existing approaches still face several significant challenges: (1) state modeling is overly coarse-grained, failing to accurately capture subtle state transitions during protocol execution, (2) focusing solely on the first mutation point that reaches the target state, overlooking other regions that may equally impact the target state, (3) neglecting the non-uniform contribution of different message regions to path coverage. To address these issues, we propose UFG-AFLNET, a unified greybox fuzzing framework. UFG-AFLNET significantly enhances fuzzing efficiency and vulnerability discovery through fine-grained state machine modeling, gradient-guided sequence selection, and lightweight dynamic taint inference. Specifically, UFG-AFLNET introduces a state clustering learner that uses the Single-Pass clustering algorithm to extend response state machines into fine-grained path state machines, thereby enabling more precise state differentiation. Additionally, to select the most critical mutation points, we employ a recurrent neural network to compute the sensitivity gradients between target path states and message regions. Finally, we use a message sequence mutator supported by dynamic taint inference to assign weights to each byte and prioritize mutations on those most likely to expose new execution paths. Experiments on five widely used protocol implementations show that UFG-AFLNET significantly outperforms baseline fuzzers in path coverage, the number of vulnerabilities discovered and so on. These results demonstrate the potential of UFG-AFLNET in advancing the field of network protocol security testing. Guangquan Xu, Tuoyu Chen, Guohua Xin, Wei Yu 0016, Hongpeng Bai |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2025 | Graph Agent Network: Empowering Nodes with Inference Capabilities for Adversarial ResilienceabstractEnd-to-end training with global optimization have popularized graph neural networks (GNNs) for node classification, yet inadvertently introduced vulnerabilities to adversarial edge-perturbing attacks. Adversaries can exploit the inherent opened interfaces of GNNs' input and output, perturbing critical edges and thus manipulating the classification results. Current defenses, due to their persistent utilization of global-optimization-based end-to-end training schemes, inherently encapsulate the vulnerabilities of GNNs. This is specifically evidenced in their inability to defend against targeted secondary attacks. In this paper, we propose the Graph Agent Network (GAgN) to address the aforementioned vulnerabilities of GNNs. GAgN is a graph-structured agent network in which each node is designed as an 1-hop-view agent. Through the decentralized interactions between agents, they can learn to infer global perceptions to perform tasks including inferring embeddings, degrees and neighbor relationships for given nodes. This empowers nodes to filtering adversarial edges while carrying out classification tasks. Furthermore, agents' limited view prevents malicious messages from propagating globally in GAgN, thereby resisting global-optimization-based secondary attacks. We prove that single-hidden-layer multilayer perceptrons (MLPs) are theoretically sufficient to achieve these functionalities. Experimental results show that GAgN effectively implements all its intended capabilities and, compared to state-of-the-art defenses, achieves optimal classification accuracy on the perturbed datasets. Ao Liu 0005, Wenshan Li 0001, Tao Li 0016, Beibei Li 0002, Guangquan Xu, Pan Zhou 0001, Wengang Ma, Hanyuan Huang |
AAAI | 5 |
| 2025 | Coupling the Generator with Teacher for Effective Data-Free Knowledge Distillation
Xu Chen 0053, Yang Li 0251, Yahong Han, Guangquan Xu, Jialie Shen 0001 |
ICCV | 4 |
| 2025 | AEDroid: Adaptive Enhanced Android Malware Detection-Based on Interpretability of Deep LearningabstractAs the most widely used operating system in the world, Android has naturally become the main target of malicious hackers. The current research on Android malware detection relies on manually defined sensitive API feature sets. With the continuous innovation and change of malicious behavior, new threats and attack methods have emerged. If we still rely on the original sensitive API set, malicious applications will not be discovered. To address this issue, we do not use the existing sensitive API feature set but instead design a key activation mechanism (KAM) based on convolutional neural networks (CNNs) to obtain sensitive API. We use this mechanism to automatically mine API features that play an important role in determining maliciousness from application datasets. And we use the API group (ApiG) obtained through this mechanism for template generalization, and obtain a method called AEDroid that can delay model aging. By analyzing these API features, it was found that they not only cover the existing sensitive API feature types but also include sensitive APIs for seven new types of malicious behavior. The experimental results show that with the addition of the newly discovered sensitive API, the Android malware detection rate has increased by more than 5%, especially on newly emerged malicious datasets, where the effect is more pronounced. Guangquan Xu, Wenxia Wang |
IET Inf. Secur. | 2 |
| 2025 | Dummy-Trajectory Synthesis: A Privacy-Preserving Approach for Semantic Trajectory Data in IoT-Based LBSNabstractTrajectory data analysis is crucial in various applications but presents significant privacy risks, as location data can reveal sensitive information. Existing privacy protection methods, such as spatiotemporal K-anonymity and L-diversity, are vulnerable to semantic inference attacks, where public data is exploited to re-identify users. To address these challenges, we propose dummy-trajectory synthesis (DTS), an efficient privacy protection scheme for location-based social networks (LBSNs). DTS enhances privacy by leveraging users’ frequent behavioral sequences to generate synthetic dummy trajectories. Unlike traditional approaches, DTS considers both geographic and semantic data by segmenting historical trajectories into time periods using the OPTICS clustering algorithm. This enables the identification of regions with specific semantic attributes and the mining of semantic trajectory sequences. DTS optimizes dummy trajectory generation by combining Euclidean distances and semantic similarity, ranking historical points and establishing transition relationships. Experimental results show that DTS significantly improves privacy protection and performance compared to existing methods, without compromising service quality. DTS offers a robust solution for protecting trajectory data privacy in LBSNs against transition probability attack for joint time periods. Minhong Dong, Ze Wang 0016, Zhuo Han, Yude Bai, Xiaohu Ye, Guangquan Xu, Naixue Xiong |
IEEE Internet Things J. | 7 |
| 2025 | PEFN: A Patches Enhancement and Hierarchical Fusion Network for Robust Vehicle ReidentificationabstractVehicle Re-Identification (Re-ID), which is a significant application in the Internet of Things, aims to accurately retrieve the remaining images of a given vehicle across different cameras views. The improvement in vehicle Re-ID performance largely stems from better addressing the issues of inter-class similarity and intra-class variance. Existing methods, relying solely on max or average pooling after using attention modules, fail to obtain significantly complete and pure global and local features, and neglect the false guidance that some unique individual information on images bring to re-identification. Moreover, models combining global and local features have shown good results in vehicle Re-ID, but these successes neglect the interaction between features across different convolutional layers, resulting in the loss of crucial details for vehicle Re-ID. To tackle these issues, we introduce a Patches Enhancement and hierarchical Fusion Network (PEFN) based on a multi-branch architecture, divided into a Global and Local Attention Supplement (GLAS) branch, and an Enhanced Hierarchical feature fusion (EnHi) branch. The GLAS branch, through the Identity-related Feature Remodeling (IDFR) module’s staged supplementation of spatial and channel features, has achieved the enhancement of both global and local features and effectively mitigated the negative impacts of individual information. The EnHi branch enhances the robustness of feature representation by interacting hierarchical features. Extensive experiments on two large-scale vehicle re-identification datasets demonstrate that our PEFN method outperforms state-of-the-art vehicle re-identification approaches. Specifically, without utilizing extra data and re-ranking, our model achieves 85.15% mAP on the VeRi776 dataset. Code is available at https://github.com/711L/PEFN. Wenying He, Yude Bai, Naixue Xiong, Guangquan Xu, Fei Guo 0001 |
IEEE Internet Things J. | 5 |
| 2025 | BAS-NDN: BlockChain based mobile producer authentication scheme for Named Data Networking
Guangquan Xu, Chenghe Dong, Cong Wang 0004 |
J. Netw. Comput. Appl. | 1 |
| 2025 | RobustPFL: Robust Personalized Federated LearningabstractConventional federated learning (FL) coordinated by a central server focuses on training a global model and protecting the privacy of clients' training data by storing it locally. However, the statistical heterogeneity hinders the global model from adapting to the non-IID distributions among clients. Moreover, untrusted and unreliable central servers and malicious clients may compromise model integrity and availability, thus degrading the robustness of FL. To address these challenges, we present RobustPFL, a decentralized personalized federated learning (PFL) approach that combines$\alpha$-based Layer-position Normalized Similarity ($\alpha$-LNS) and local collaborative training to improve personalized performance while utilizing a blockchain-based committee mechanism to coordinate the aggregation process, thereby achieving high personalized accuracy and robustness. Extensive experiments show that our RobustPFL approach outperforms multiple algorithms, including Local training, FedAvg, FedReptile, Per-FedAvg, FedBN, and SPFL, on MNIST, CIFAR10, EMNIST, and N-BaIoT datasets in four non-IID settings. We also evaluate RobustPFL's effectiveness against attacks—poisoning attacks and free-riding attacks. Particularly, for three prevalent poisoning attacks (backdoor, label flipping, and model poisoning attacks), we compare non-defensive (FedAvg) and defensive (Krum, trimmed mean, Bulyan, FedBN, FLAME, and FangTrmean) methods with our proposed RobustPFL. The results show that our approach achieves significant defensive effects. Wei Wang 0012, Yufang Wu, Chao Li 0023, Guangquan Xu, Shouling Ji, Tao Li 0022, Meng Shen 0001, Yufei Han 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Differential-Trust-Mechanism-Based Trade-Off Method Between Privacy and Accuracy in Recommender SystemsabstractIn the era where Web3.0 values data security and privacy, adopting groundbreaking methods to enhance privacy in recommender systems is crucial. Recommender systems need to balance privacy and accuracy, while also having the ability to overcome cold start problems. The Differential Trust Mechanism (DTM) introduced in this paper is such an approach. The DTM provides a unique use of Gaussian distributions in modeling trust relationships within data, offering a novel way to balance recommendation accuracy with user privacy. This mechanism innovatively applies differential privacy principles, using Gaussian noise addition to protect individual user data from inference attacks, while maintaining the integrity and utility of the overall dataset. Unlike traditional anonymization techniques that often compromise data utility or vulnerability to reverse engineering, DTM provides a robust solution by dynamically adjusting privacy levels based on the trustworthiness of data requests. By combining DTM with existing mainstream recommendation algorithms, the prediction accuracy of MAE and RMSE increases by at least 6.60% and 2.69%, respectively. This dual benefit positions DTM as a significant advancement in secure data processing, especially relevant for online businesses and platforms where personalized recommendations are crucial yet privacy concerns are paramount. Guangquan Xu, Shicheng Feng, Hao Xi, Qingyang Yan, Wenshan Li 0001, Cong Wang 0004, Wei Wang 0012, Shaoying Liu, Zhihong Tian 0001, James Xi Zheng |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | VFLMonitor: Defending One-Party Hijacking Attacks in Vertical Federated LearningabstractVertical Federated Learning (VFL) is susceptible to various one-party hijacking attacks, such as Replay and Generation attacks, where a single malicious client can manipulate the model to produce attacker-specified results, thereby compromising its reliability in real-world deployments. In this paper, we first uncover the underlying mechanisms of these attacks and observe that successful attacks induce significant discrepancies in the embedding-label associations across different clients. We establish a theoretical framework demonstrating how these discrepancies can serve as reliable indicators for detecting hijacking attempts. Building upon this insight, we propose VFLMonitor, a robust defense mechanism that leverages these embedding-label discrepancies to detect and mitigate hijacking attacks. Specifically, VFLMonitor identifies suspicious queries by analyzing differences in label estimations from multiple clients and applies a majority voting rule to correct or filter out these malicious queries. Moreover, VFLMonitor introduces a novel regularization strategy during training to reduce intra-class variance in embeddings, thereby enhancing their discriminative power and improving defense effectiveness. Extensive experi21 ments were conducted on 5 real-world datasets against 2 different attack types under 3 attack scenarios. The results demonstrate that VFLMonitor can effectively identify and exclude potential hijacked requests in all types of one-party hijacking attacks, while maintaining a meager false positive rate for legitimate queries. Xiangrui Xu 0001, Yufei Han 0001, Yongsheng Zhu, Zhen Han 0001, Guangquan Xu, Bin Wang 0062, Shouling Ji, Wei Wang 0012 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | Toward Cross-Environment Continuous Gesture User Authentication With Commercial Wi-FiabstractBehavior biometrics-based user authentication with Wi-Fi gains significant attention due to its ubiquitous and contact-free manners. An individual’s identity can be verified by analyzing activities induced signal variances, excellently balancing the security demands and user experience. However, the inherent complexity of Wi-Fi signals presents significant challenges for behavior biometrics-based user authentication. The susceptibility of Wi-Fi signals results in a poor cross-environment generalization capability, which is overlooked by the existing research. In addition, most existing works of behavior-based user authentication are based on one-off activity. This makes them vulnerable to zero-effort attacks and imitation attacks. To address these issues, we propose a cross-environment continuous gesture-based user authentication framework with Wi-Fi, dubbed Wi-CGAuth. Specifically, the cross-environment generalization capability is enhanced by the cross-layer joint optimization approach. At the lowest signal layer, the signals’ time, spatial, and frequency diversity are extended maximally, by a novel, subcarrier-level, cost-effective signal optimization strategy. At the middle layer, the multi-view fusion method, i.e., multi-transfer component analysis (TCA), is applied to refine the signals from transceiver pairs after signal preprocessing. The continuous gesture segmentation problem is modeled as the classification problem, which is solved by CNN. At the upper layer, a Convolutional Neural Network-Transformer (CNN-Transformer) model is employed to achieve the dual task of effective user authentication and accurate gesture recognition. After extensive experiments in three typical indoor scenarios, Wi-CGAuth can achieve an average authentication accuracy of 92.7%, demonstrating its robustness and effectiveness. Lei Zhang 0024, Yazhou Ma, Mingzi Zuo, Zhen Ling 0001, Changyu Dong, Guangquan Xu, Xiaochen Fan, Qian Zhang 0001 |
IEEE Trans. Netw. | 6 |
| 2025 | IRHunter: Universal Detection of Instruction Reordering Vulnerabilities for Enhanced Concurrency in Distributed and Parallel SystemsabstractInstruction reordering is an essential optimization technique used in both compilers and multi-core processors to enhance parallelism and resource utilization. Although the original intent of this technique is to benefit the program, some improper reordering can significantly impact the program correctness, which we call instruction reordering vulnerability (IRV). However, existing methods detect IRV by defining CPU instruction reordering rules to schedule execution paths while neglecting compiler reordering, and thus generate false positives that require manual filtering and resulting in inefficiency. To bridge this gap, in this paper, we propose the IRV detection method, , which analyzes IRV characteristics and extracts vulnerability patterns, integrating program dependency analysis for compiler reordering and memory model constraints for CPU reordering. Specifically, we use static analysis based on specific patterns to narrow the analysis scope, and adopt log-based dynamic analysis to confirm vulnerability by checking the log constraints. We built the IRV benchmark to compare IRHunter with five state-of-the-art tools (i.e., GENMC, Nidhugg, CBMC, SHB, BiRD). IRHunter detected all 19 errors, doubling the best model checking tools' performance, with half the false positive rate of leading data race detectors. It was 10× faster on small programs and outperformed data race detectors on large programs. Guohua Xin, Guangquan Xu, Yao Zhang 0019, Cheng Wen 0002, Cen Zhang, Xiaofei Xie, Naixue Xiong, Shaoying Liu, Pan Gao 0006 |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2024 | Improving Distinguishability of Class for Graph Neural NetworksabstractGraph Neural Networks (GNNs) have received widespread attention and applications due to their excellent performance in graph representation learning. Most existing GNNs can only aggregate 1-hop neighbors in a GNN layer, so they usually stack multiple GNN layers to obtain more information from larger neighborhoods. However, many studies have shown that model performance experiences a significant degradation with the increase of GNN layers. In this paper, we first introduce the concept of distinguishability of class to indirectly evaluate the learned node representations, and verify the positive correlation between distinguishability of class and model performance. Then, we propose a Graph Neural Network guided by Distinguishability of class (Disc-GNN) to monitor the representation learning, so as to learn better node representations and improve model performance. Specifically, we first perform inter-layer filtering and initial compensation based on Local Distinguishability of Class (LDC) in each layer, so that the learned node representations have the ability to distinguish different classes. Furthermore, we add a regularization term based on Global Distinguishability of Class (GDC) to achieve global optimization of model performance. Extensive experiments on six real-world datasets have shown that the competitive performance of Disc-GNN to the state-of-the-art methods on node classification and node clustering tasks. Dongxiao He, Shuwei Liu, Meng Ge, Zhizhi Yu, Guangquan Xu, Zhiyong Feng 0002 |
AAAI | 5 |
| 2024 | AEGAN: A Novel Machine Learning Model to Attribute Network Community DetectionabstractGraph Convolutional Networks (GCNs) utilize topology and content information for attribute network community detection. However, there are issues such as insufficient adaptation to unsupervised learning, limited depth of GCN layers, and inadequate information fusion in the task. Therefore, this paper proposes a novel community detection model named AE-GAN (Autoencoder-enhanced Graph Attention Network). Firstly, AEGAN introduces a self-attention mechanism and a self-encoder module to learn node content information, transmitting the acquired content information to the GCN module. Meanwhile, the GCN module integrates the learned content information with the topology information through convolution, extending the depth of the GCN layer and solving the problem of imbalance in the fusion of the two types of information. Finally, we propose a triple self-supervised module under this model to automatically guide unsupervised learning tasks. In a series of comparative experiments, AEGAN demonstrates significant improvements in evaluation metrics such as ACC and NMI, highlighting its effectiveness in attribute network community detection. Xiaoming Li 0006, Guangquan Xu |
IJCNN | 4 |
| 2024 | Lurking in the shadows: Unveiling Stealthy Backdoor Attacks against Personalized Federated Learning
Xiaoting Lyu, Yufei Han 0001, Wei Wang 0012, Jingkai Liu, Yongsheng Zhu, Guangquan Xu, Jiqiang Liu, Xiangliang Zhang 0001 |
USENIX Security Symposium | 6 |
| 2024 | NNTBFV: Simplifying and Verifying Neural Networks Using Testing-Based Formal VerificationabstractNeural networks are extensively employed in safety-critical systems. However, these critical systems incorporating neural networks continue to pose risks due to the presence of adversarial examples. Although the security of neural networks can be enhanced by verification, verifying neural networks is an NP-hard problem, making the application of verification algorithms to large-scale neural networks a challenging task. For this reason, we propose NNTBFV, a framework that utilizes the principles of Testing-Based Formal Verification (TBFV) to simplify neural networks and verify the simplified networks. Unlike conventional neural network pruning techniques, this approach is based on specifications, with the goal of deriving approximate execution paths under given preconditions. To mitigate the potential issue of unverifiable conditions due to overly broad preconditions, we also propose a precondition partition method. Empirical evidence shows that as the range of preconditions narrows, the size of the execution paths also reduces accordingly. The execution path generated by NNTBFV is still a neural network, so it can be verified by verification tools. In response to the results from the verification tool, we provide a theoretical method for analysis. We evaluate the effectiveness of NNTBFV on the ACAS Xu model project, choosing Verification-based and Random-based neural network simplification algorithms as the baselines for NNTBFV. Experiment results show that NNTBFV can effectively approximate the baseline in terms of simplification capability, and it surpasses the efficiency of the random-based method. Shaoying Liu, Guangquan Xu, Ai Liu, Dingbang Fang |
Int. J. Softw. Eng. Knowl. Eng. | 3 |
| 2024 | Multilevel Deep Neural Network Approach for Enhanced Distributed Denial-of-Service Attack Detection and Classification in Software-Defined Internet of Things NetworksabstractWith the increasing rates of interconnected Internet of Things (IoT) devices within Software-Defined Networking (SDN) environments, distributed denial of service (DDoS) attacks have become increasingly common. As a result of this challenge, novel detection and classification methods must be developed based on the unique characteristics of SDN-supported IoT networks. This paper proposes a novel approach to detecting and categorizing DDoS attacks that has been optimized specifically for such environments. As part of our methodology, we integrate convolutional neural networks (CNN) and long-short-term memory (LSTM) models into a multilevel deep neural network architecture. With this hybrid architecture, complex spatial and temporal patterns can be automatically extracted from raw network traffic data to facilitate comprehensive analysis and accurate identification of DDoS attacks. We validate the efficacy and superiority of our proposed approach over traditional machine learning algorithms by conducting rigorous experiments on real-world datasets. Our findings underscore the potential of the multi-level deep neural network approach as a robust and scalable solution for mitigating DDoS attacks in SDN-supported IoT networks. By improving network security and resilience to evolving threats, our methodology contributes to safeguarding critical infrastructures in the era of interconnected IoT ecosystems. Yawar Abbas Abid, Jinsong Wu 0001, Guangquan Xu, Shihui Fu, Muhammad Waqas 0007 |
IEEE Internet Things J. | 3 |
| 2024 | A Graph Neural Network Model for Live Face Anti-Spoofing Detection Camera SystemsabstractAs the demand for the Internet of Things (IoT) grows, it becomes crucial to possess systems capable of detecting any data leakage used for authentication. Within IoT camera systems based on facial bio-metric recognition, there is a risk of Deepfake Bypassed Facial Feature Authentication due to the widespread use of deepfake video technologies, such as DeepFaceLive and expression manipulation. Traditional Face Anti-Spoofing Detection techniques may struggle to detect real-time deepfake videos within IoT contexts. Moreover, constrained by the scale of Face Anti-Spoofing Detection datasets, current detection models primarily focus on recognizing the entire face in videos, neglecting the inter-component correlations of facial features. However, our investigation indicates that different parts of the face have varying impacts on deepfake detection. To address this issue, we segment the face into several regions within video frames and explore the relationships between these regions. Our approach involves constructing feature graphs that represent such correlations, aiming to leverage the relationships between facial regions and the temporal characteristics of real-time facial manipulation videos for use in live facial detection cameras. Initially, features for each facial region are extracted via Convolutional Neural Networks (CNNs). Subsequently, with these features as vertices and their correlations as edges, a feature graph of the entire video is constructed. Ultimately, a Graph Neural Network (GNN) is employed to determine whether the video has been tampered with. Experiments conducted on several publicly accessible datasets demonstrate that our proposed method outperforms other state-of-the-art Face Anti-Spoofing Detection techniques in most scenarios. Thus, the aforementioned advanced Graph Neural Network model exhibits exceptional performance in real-time deepfake detection tailored for live facial detection cameras. Weiguo Lin, Wenqing Fan, Keqiu Li, Xiulong Liu 0001, Guangquan Xu, Shengwei Yi |
IEEE Internet Things J. | 7 |
| 2024 | TextJuggler: Fooling text classification tasks by generating high-quality adversarial examples
Hao Peng 0002, Zhe Wang 0017, Dandan Zhao 0003, Guangquan Xu, Jianming Han, Shixin Guo, Ming Zhong 0009, Shouling Ji |
Knowl. Based Syst. | 5 |
| 2024 | Enhancing human-machine pair inspection with risk number and code inspection diagramabstractAbstract Software inspection is a widely-used approach to software quality assurance. Human-Machine Pair Inspection (HMPI) is a novel software inspection technology proposed in our previous work, which is characterized by machine guiding programmers to inspect their own code during programming. While our previous studies have shown the effectiveness of HMPI in telling risky code fragments to the programmer, little attention has been paid to the issue of how the programmer can be effectively guided to carry out inspections. To address this important problem, in this paper we propose to combine Risk Number with Code Inspection Diagram (CID) to provide accurate guidance for the programmer to efficiently carry out inspections of his/her own programs. By following the Code Inspection Diagram, the programmer will inspect every checking item shown in the CID to efficiently determine whether it actually contain bugs. We describe a case study to evaluate the performance of this method by comparing its inspection time and number of detected errors with our previous work. The result shows that the method is likely to guide the programmer to inspect the faulty code earlier and be more efficient in detecting defects than the previous HMPI established based on Cognitive Complexity. Yujun Dai, Shaoying Liu, Guangquan Xu |
Softw. Qual. J. | 3 |
| 2024 | OFEI: A Semi-Black-Box Android Adversarial Sample Attack Framework Against DLaaSabstractWith the growing popularity of Android devices, Android malware is seriously threatening the safety of users. Although such threats can be detected by deep learning as a service (DLaaS), deep neural networks as the weakest part of DLaaS are often deceived by the adversarial samples elaborated by attackers. In this paper, we propose a new semi-black-box attack framework called one-feature-each-iteration (OFEI) to craft Android adversarial samples. This framework modifies as few features as possible and requires less classifier information to fool the classifier. We conduct a controlled experiment to evaluate our OFEI framework by comparing it with the benchmark methods JSMF, GenAttack and pointwise attack. The experimental results show that our OFEI has a higher misclassification rate of 98.25%. Furthermore, OFEI can extend the traditional white-box attack methods in the image field, such as fast gradient sign method (FGSM) and DeepFool, to craft adversarial samples for Android. Finally, to enhance the security of DLaaS, we use two uncertainties of the Bayesian neural network to construct the combined uncertainty, which is used to detect adversarial samples and achieves a high detection rate of 99.28%. Guangquan Xu, Guohua Xin, Litao Jiao, Jian Liu 0004, Shaoying Liu, Meiqi Feng, James Xi Zheng |
IEEE Trans. Computers | 1 |
| 2024 | MRFS: Mining Rating Fraud Subgraph in Bipartite Graph for Users and ProductsabstractFraud in e-commerce fields (e.g., Amazon, Taobao, and so on) and social networks (e.g., Twitter and Weibo) has recently brought a very bad user experience. Rating fraud detection is an urgent issue for improving user experiences. However, existing methods have lots of limitations in some respects, because it is always very hard to acquire sufficient labeled data for fraud detection and detect new fraud patterns. Fortunately, the relationship for users rating (e.g., purchasing and following) products can be represented as a bipartite graph. So the problem of rating fraud detection can be transformed into the problem of abnormal subgraph detection in the bipartite graph. The major challenge of fraud detection is to distinguish fake rates from real user rates. In this article, we focus on mining rating fraud-connected subgraphs in a bipartite graph. The motivation for this work is fraud detection tasks, which can usually be formulated as mining a bipartite graph formed by source nodes (followers and users) and target nodes (followees and products) for malicious patterns. Now, smart fraudsters evade existing detection methods by buying a large pool of users and hijacking honest users, making them look “normal”-this behavior is called “camouflage.” Accordingly, we propose a fraud detection approach for mining rating fraud subgraph (MRFS), which addresses the problem from the intrinsic metric (e.g., fraudulence, badness and unreliability). The proposed MRFS mines the intrinsic characteristics of nodes and edges from node behavior information, which is an effective and scalable (linear on the input size) algorithm. A large number of comparative experimental results on real-world rating networks show that our proposed MRFS is efficient and universal. Wei Yu 0016, Guangquan Xu, Huaming Wu, Hongyan Li 0003, Jun Wang 0193, Xiaoming Li 0006 |
IEEE Trans. Comput. Soc. Syst. | 3 |
| 2024 | ValidCNN: A Large-Scale CNN Predictive Integrity Verification Scheme Based on zk-SNARKabstractThe integrity of cloud-based convolutional neural network (CNN) prediction services can be jeopardized by a malicious cloud server. Although zero-knowledge proof approaches can be used to verify integrity, they are difficult to use for larger CNN models like LeNet-5 and VGG16, due to the large cost (in terms of time and storage) of generating a proof. This paper proposes ValidCNN, which can efficiently generate integrity proofs based zk-SNARK. At the heart of ValidCNN, it is a novel usage of Freivald's concepts for circuit construction, and a more efficient way for verifying matrix multiplication. Our experimental results demonstrate that VaildCNN significantly outperforms the state-of-the-art approaches that are based on zk-SNARK. For example, compared with ZEN, VaildCNN achieves a 12-fold improvement in time and a 31-fold improvement in storage. Compared with vCNN, VaildCNN achieves a 195-fold and 279-fold improvement in time and storage respectively. Yongkai Fan, Kaile Ma, Linlin Zhang 0005, Guangquan Xu, Gang Tan |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Toward Robust and Effective Behavior Based User Authentication With Off-the-Shelf Wi-FiabstractBehavior-based Wi-Fi user authentication has gained popularity in user-centered smart systems. However, its wide adoption has been hindered by certain critical issues, including significant performance degradation when the environment changes, the inability to handle unknown activities, and weak security due to basing authentication on the recognition of a single, one-off activity. In this paper, we propose Wi-Dist, which authenticates a user using a behavior password, i.e. a pre-chosen sequence of activities. Wi-Dist addressed the previously mentioned technical challenges through a cross-layer joint optimization framework. In particular, we address environment dependency by incorporating adversarial learning and optimizing both the signal layer and the domain adaptation layer. This enhances the performance of the learned model across various environments. To effectively handle unknown behaviors, we utilize an adversarial learning-based network. This network establishes a pseudo-decision boundary between samples from known and unknown sources, ensuring robust authentication. Additionally, for authentication using continuous activities, we employ double-sliding windows activity monitoring. This approach, coupled with activity state correction, partitions activities for accurate recognition. We also conducted extensive experiments in indoor environments to demonstrate that Wi-Dist is effective and robust. Lei Zhang 0024, Yazhou Ma, Shiwen Mao, Wenyuan Huang, Zhiyong Yu 0001, Xiaochen Fan, Guangquan Xu, Changyu Dong |
IEEE Trans. Inf. Forensics Secur. | 10 |
| 2024 | Privacy-Preserving Distributed Transfer Learning and Its Application in Intelligent TransportationabstractWith the rapid development of intelligent transportation systems (ITS), more and more intelligent applications for ITS have received widespread attention, such as the vehicle detection, inference of typical routes, and traffic forecasting. In these applications, deep learning is widely used as a key artificial intelligence technology. However, most ITS providers fail to collect enough labeled traffic data for model training. As a complement to deep learning, transfer learning is an effective way to solve the scarcity of labeled data, which can transfer knowledge from labeled datasets to unlabeled datasets, thus improving the accuracy of prediction and classification. Nevertheless, when the labeled dataset and the unlabeled dataset are held by different entities, it is still unrealistic for two mutually distrustful entities to cooperate in transfer learning regarding data security and privacy preservation. Although some existing works provide privacy-preserving transfer learning methods, such methods fail to apply to traffic data with high sample dimensions due to their high computational cost and round complexity. To address this problem, we design an efficient privacy-preserving distributed transfer learning protocol, which is appropriate for traffic data. Compared to existing works, our protocol addresses the privacy-preserving problem of transfer learning for traffic data with high sample dimensions. In addition, our protocol has fewer interaction rounds and can be proved in the semi-honest model. Finally, we validate the effectiveness, efficiency and security of the proposed protocol via experiments. Furthermore, we show the application of the proposed protocol in intelligent transportation systems. Zhi Li 0056, Hao Wang 0007, Guangquan Xu, Alireza Jolfaei, James Xi Zheng, Chunhua Su, Wenying Zhang 0001 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2024 | ID-SR: Privacy-Preserving Social Recommendation Based on Infinite Divisibility for Trustworthy AIabstractRecommendation systems powered by artificial intelligence (AI) are widely used to improve user experience. However, AI inevitably raises privacy leakage and other security issues due to the utilization of extensive user data. Addressing these challenges can protect users’ personal information, benefit service providers, and foster service ecosystems. Presently, numerous techniques based on differential privacy have been proposed to solve this problem. However, existing solutions encounter issues such as inadequate data utilization and a tenuous trade-off between privacy protection and recommendation effectiveness. To enhance recommendation accuracy and protect users’ private data, we propose ID-SR, a novel privacy-preserving social recommendation scheme for trustworthy AI based on the infinite divisibility of Laplace distribution. We first introduce a novel recommendation method adopted in ID-SR, which is established based on matrix factorization with a newly designed social regularization term for improving recommendation effectiveness. We then propose a differential privacy-preserving scheme tailored to the above method that leverages the Laplace distribution’s characteristics to safeguard user data. Theoretical analysis and experimentation evaluation on two publicly available datasets demonstrate that our scheme achieves a superior balance between privacy protection and recommendation effectiveness, ultimately delivering an enhanced user experience. Jingyi Cui, Guangquan Xu, Jian Liu 0004, Shicheng Feng, Jianli Wang, Hao Peng 0002, Shihui Fu, Zhaohua Zheng, James Xi Zheng, Shaoying Liu |
ACM Trans. Knowl. Discov. Data | 2 |
| 2024 | FedPKR: Federated Learning With Non-IID Data via Periodic Knowledge Review in Edge ComputingabstractFederated learning is a distributed learning paradigm, which is usually combined with edge computing to meet the joint training of IoT devices. A significant challenge in federated learning lies in the statistical heterogeneity, characterized by non-independent and identically distributed (non-IID) local data across diverse parties. This heterogeneity can result in inconsistent optimization within individual local models. Although previous research has endeavored to tackle issues stemming from heterogeneous data, our findings indicate that these attempts have not yielded high-performance neural network models. To overcome this fundamental challenge, we introduce the framework called FedPKR in this paper, which facilitates efficient federated learning through knowledge review. The core principle of FedPKR involves leveraging the knowledge representation generated by the global and local model layers to conduct periodic layer-by-layer comparative learning in a reciprocal manner. This strategy rectifies local model training, leading to enhanced outcomes. Our experimental results and subsequent analysis substantiate that FedPKR effectively augments model accuracy in image classification tasks, meanwhile demonstrating resilience to statistical heterogeneity across all participating entities. Code is available athttps://github.com/jbwangnb/FedPKR. Ruijin Wang, Guangquan Xu, Donglin He, Xikai Pei, Fengli Zhang |
IEEE Trans. Sustain. Comput. | 3 |
| 2023 | IGA : An Improved Genetic Algorithm to Construct Weightwise (Almost) Perfectly Balanced Boolean Functions with High Weightwise NonlinearityabstractThe Boolean functions satisfying secure properties on the restricted sets of inputs are studied recently due to their importance in the framework of the FLIP stream cipher. However, finding Boolean functions with optimal cryptographic properties is an open research problem in the cryptographic community. This paper presents an Improved Genetic Algorithm (IGA) with the directed changes that keep the weightwise balancedness of Boolean functions. A cross-protection strategy is proposed to ensure that the offspring has the same weightwise balancedness characteristics of the parents while implementing crossover. Then, a large number of weightwise (almost) perfectly balanced (W(A)PB) functions with a good nonlinearity profile are obtained based on IGA. Finally, we make comparisons between our constructions and relevant works. The comparisons show that IGA has a significant advantage for reaching the W(A)PB functions with high weightwise nonlinearity. Moreover, it is the first time to obtain the 8-variable WPB functions with the weightwise nonlinearity of 28 in the restricted sets of inputs with Hamming weight of 4, and list the statistical indicators of the weightwise nonlinearity for W(A)PB functions for input size n = 9, 10. Jingyi Cui, Jian Liu 0004, Guangquan Xu, Lidong Han, Alireza Jolfaei, James Xi Zheng |
AsiaCCS | 4 |
| 2023 | GDTM: Gaussian Differential Trust Mechanism for Optimal Recommender System
Lixiao Gong, Guangquan Xu, Jingyi Cui, Shihui Fu, James Xi Zheng, Shaoying Liu |
ICA3PP (6) | 2 |
| 2023 | Utilizing Risk Number and Program Slicing to Improve Human-Machine Pair InspectionabstractHuman-Machine Pair Inspection (HMPI) is a novel code inspection technology proposed in our previous work, which is the style that machine will intelligently guide the programmer to carry out inspections of the program code during programming. For large-scale software projects, the efficiency of HMPI needs to be improved due to the inaccurate measurement of the code structure and the excessive inspection scope. In this paper, to alleviate the above deficiencies, we propose the Risk Number, a code evaluation metric generated based on historical error data. The Risk Number is calculated by a statistical tool called regression analysis, which more accurately indicates the relationship between the nested structure of the code and the likelihood of containing bugs than Cognitive Complexity. Additionally, HMPI is supported by utilizing Risk Number to point out high-risk code and program slicing techniques to extract statements that have dependencies on the code to generate checklists, thereby reducing the scope of inspection. We describe a case study to evaluate the performance of this method by comparing its inspection time and number of detected errors with our previous work. The result shows that the method is likely to guide the programmer to inspect the faulty code earlier and be more efficient in detecting defects than HMPI based on Cognitive Complexity. Yujun Dai, Shaoying Liu, Guangquan Xu, Ai Liu |
ICECCS | 3 |
| 2023 | UAF-GUARD: Defending the use-after-free exploits via fine-grained memory permission management
Guangquan Xu, Wenqing Lei, Lixiao Gong, Jian Liu 0004, Hongpeng Bai, Kai Chen 0012, Wei Wang 0012, Kaitai Liang, Weizhi Meng 0001, Shaoying Liu |
Comput. Secur. | 1 |
| 2023 | GenDroid: A query-efficient black-box android adversarial attack framework
Guangquan Xu, Hongfei Shao, Jingyi Cui, Hongpeng Bai, Guangdong Bai, Shaoying Liu, Weizhi Meng 0001, James Xi Zheng |
Comput. Secur. | 1 |
| 2023 | Local node feature modeling for edge computing based on network embedding in dynamic networks
Xiaoming Li 0006, Naixue Xiong, Wei Yu 0016, Guangquan Xu, Changzheng Liu |
J. Parallel Distributed Comput. | 5 |
| 2023 | A Privacy-Preserving Medical Data Sharing Scheme Based on BlockchainabstractWith the increasing penetration of the Internet of things (IoT) into people's lives, the limitations of traditional medical systems are emerging. First, the typical way of handling sensitive information can easily lead to privacy disclosure. Second, the medical system is relatively isolated. It is difficult for one medical system to share data with another, and the scope of users' activities is limited within the system boundary. To solve these two problems, we propose a new privacy-preserving medical data-sharing scheme by introducing the authorization mechanism and attribute-based encryption (ABE) based on blockchain, which breaks system boundaries and realizes data sharing among several medical institutions. ABE is used to realize scalable access control. In addition, doctors can share their knowledge to diagnose users by introducing many-to-many matching, which means that patients' health data can be represented by multiple keywords and doctors' expertise can be represented by multiple interests. We provide the correctness and security analysis of our scheme and implement a prototype tool on Ethereum. The experimental results show that our scheme solves the contradiction between the privacy preservation of medical data and the necessity of data sharing. Guangquan Xu, Chen Qi, Wenyu Dong, Lixiao Gong, Shaoying Liu, Si Chen 0009, Jian Liu 0004, James Xi Zheng |
IEEE J. Biomed. Health Informatics | 1 |
| 2023 | ASQ-FastBM3D: An Adaptive Denoising Framework for Defending Adversarial Attacks in Machine Learning Enabled SystemsabstractMachine learning has made significant progress in image recognition, natural language processing, and autonomous driving. However, the generation of adversarial examples has proved that the machine learning system is unreliable. By adding imperceptible perturbations to clean images can fool the well-trained machine learning systems. To solve this problem, we propose an adaptive image denoising framework Adaptive Scalar Quantization (ASQ-FastBM3D). TheASQ-FastBM3Dframework combines theASQmethod with theFastBM3Dalgorithm. The adaptive scalar quantization is the improvement of scalar quantization, which is used to eliminate most of the perturbations.FastBM3Dis proposed to improve the quality of the quantified image. The running time ofFastBM3Dis 50% less than that ofBM3D. Compared with some traditional filter methods and some state-of-the-art neural network methods for recovering the adversarial examples, the accuracy rate of ourASQ-FastBM3Dmethod is 99.73% and the F1 score is 98.01%, which is the highest. Guangquan Xu, Zhengbo Han, Lixiao Gong, Litao Jiao, Hongpeng Bai, Shaoying Liu, James Xi Zheng |
IEEE Trans. Reliab. | 1 |
| 2023 | Multi-Misconfiguration Diagnosis via Identifying Correlated Configuration ParametersabstractSoftware configuration requires that the user sets appropriate values to specified variables, known as configuration parameters, which potentially affect the behaviors of software system. It is an essential means for software reliability, but how to ensure correct configurations remains a great challenge, especially when a large number of parameter settings are involved. Existing studies on misconfiguration diagnosis treat all configurations independently, ignoring the constraints and correlations among different configurations. In this article, we reveal the phenomenon of multi-misconfigurations and present a tool, MMD, for multi-misconfigurations diagnosis. Specifically, MMD consists of two modules: Correlated Configurations Analysis and Primary Misconfigurations Diagnosis. The former determines the correlation among each pair of configurations by analyzing the control and data flows related to each configuration. The latter is responsible for collecting a list of configurations ranked according to their suspiciousness. Combining the outputs of two modules, MMD is able to assist the user in multi-misconfigurations diagnosis. We evaluate MMD on seven popular Java projects: Randoop, Soot, Synoptic, Hdfs, Hbase, Yarn, and Zookeeper. MMD identifies 510 configuration correlations with a 4.9% false positive rate. Furthermore, it effectively diagnoses 22 multi-misconfigurations collected from StackOverflow, outperforming two state-of-the-art baselines. Yingnan Zhou, Sihan Xu, Yan Jia 0009, Yuhao Liu 0007, Guangquan Xu, Wei Wang 0012, Shaoying Liu, Thar Baker |
IEEE Trans. Software Eng. | 7 |
| 2022 | A Holistic Client Selection Scheme in Federated Mobile CrowdSensing Based on Reverse AuctionabstractFederated Mobile CrowdSensing is applied to collect massive sensory data and exploits the computing power of mobile devices brought by their embedded specialized computing engines (e.g., Neural Engine in iPhone) to train machine learning (ML) models. However, the heterogeneity of mobile devices includes significant differences in the size and quality of datasets, different computing power, and some unreliable clients using unreliable data for training. The heterogeneity of mobile devices reduces FL’s performance. Therefore, selecting high-quality clients for Federated learning (FL) is vital. This study proposes a client selection scheme based on the reverse auction. First, each client’s training time is predicted, the total FL time threshold is optimized, and the reputation value is calculated based on the historical performance of each client. Then, each client’s current computing power and dataset size are converted into an efficiency value. Finally, the selection value of each client is calculated based on the efficiency value and reputation value. The results of the experiments show that our scheme can select high-quality clients. Compared with FedRep, our scheme can reduce training time by 91.5%. Compared with FedEff, our scheme can reduce communication rounds by 87.5%. In the same communication rounds (5000), our scheme has higher accuracy than RandomFL, and the average accuracy is improved by about 4.4%. Zhaohua Zheng, Zhaobin Qin, Deshun Li, Keqiu Li, Guangquan Xu |
CSCWD | 5 |
| 2022 | SG-PBFT: A secure and highly efficient distributed blockchain PBFT consensus algorithm for intelligent Internet of vehicles
Guangquan Xu, Hongpeng Bai, Jun Xing, Tao Luo 0010, Naixue Xiong, Xiaochun Cheng, Shaoying Liu, James Xi Zheng |
J. Parallel Distributed Comput. | 1 |
| 2022 | DynaComm: Accelerating Distributed CNN Training Between Edges and Clouds Through Dynamic Communication SchedulingabstractTo reduce uploading bandwidth and address privacy concerns, deep learning at the network edge has been an emerging topic. Typically, edge devices collaboratively train a shared model using real-time generated data through the Parameter Server framework. Although all the edge devices can share the computing workloads, the distributed training processes over edge networks are still time-consuming due to the parameters and gradients transmission procedures between parameter servers and edge devices. Focusing on accelerating distributed Convolutional Neural Networks (CNNs) training at the network edge, we present DynaComm, a novel scheduler that dynamically decomposes each transmission procedure into several segments to achieve optimal layer-wise communications and computations overlapping during run-time. Through experiments, we verify that DynaComm manages to achieve optimal layer-wise scheduling for all cases compared to competing strategies while the model accuracy remains untouched. Shangming Cai, Dongsheng Wang 0002, Haixia Wang 0001, Yongqiang Lyu 0001, Guangquan Xu, James Xi Zheng, Athanasios V. Vasilakos |
IEEE J. Sel. Areas Commun. | 5 |
| 2022 | JOSP: Joint Optimization of Flow Path Scheduling and Virtual Network Function Placement for Delay-Sensitive Applications
Qing Lyu 0005, Yonghang Zhou, Qilin Fan, Yongqiang Lyu 0001, James Xi Zheng, Guangquan Xu |
Mob. Networks Appl. | 6 |
| 2022 | JSCSP: A Novel Policy-Based XSS Defense Mechanism for BrowsersabstractTo mitigate cross-site scripting attacks (XSS), the W3C group recommends web service providers to employ a computer security standard called Content Security Policy (CSP). However, less than 3.7 percent of real-world websites are equipped with CSP according to Google’s survey. The low scalability of CSP is incurred by the difficulty of deployment and non-compatibility for state-of-art browsers. To explore the scalability of CSP, in this article, we propose JavaScript based CSP (JSCSP), which is able to support most of real-world browsers but also to generate security policies automatically. Specifically, JSCSP offers a novel self-defined security policy which enforces essential confinements to related items, including JavaScript functions, DOM elements and data access. Meanwhile, JSCSP has an efficient algorithm to automatically generate the policy directives and enforce them in a cascading way, which is more fine-grained and practical than the functionalities provided by CSP. We further implement JSCSP on a Chrome extension, and our evaluation shows that the extension is compatible with popular JavaScript libraries. Our JSCSP extension can detect and block the tested attacking vectors extracted from the prevalent web applications. We state that JSCSP delivers better performance compared to other XSS defense solutions. Guangquan Xu, Xiaofei Xie, Shuhan Huang, Jun Zhang 0010, Lei Pan 0002, Wei Lou, Kaitai Liang |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | A Feature Discretization Method Based on Fuzzy Rough Sets for High-Resolution Remote Sensing Big Data Under Linear Spectral ModelabstractAs one of the most relevant data preprocessing techniques, discretization has played an important role in data mining, which is widely applied in industrial control. It can transform continuous features to discrete ones, thus improving the efficiency of data processing and adapting to learning algorithms that require discrete data as inputs. However, traditional discretization methods have shortcomings, such as highly complex programs, excessive numbers of intervals obtained, and significant loss of necessary information in the preprocessing of high-resolution remote sensing big data. Moreover, the large number of mixed pixels in the image is a primary reason for the uncertainty of remote sensing information systems, and current discretization methods are based on the assumption that one pixel only corresponds to the spectral information of a single object, without considering the influence of the uncertainty caused by a mixed spectrum, which causes the classification accuracy to drop after discretization. We propose a discretization method for high-resolution remote sensing big data. We determine the membership degree of each pixel in training samples through linear decomposition and establish the individual fitness function based on a fuzzy rough model. An adaptive genetic algorithm selects discrete breakpoints, and a MapReduce framework calculates the individual fitness of the population in parallel to obtain the optimal discretization scheme in the minimum time. Our method is compared to the best state-of-the-art discretization algorithms on the authentic remote sensing datasets. Experiments verified the effectiveness of the proposed method, which provides strong support for the subsequent processing of images. Mengxing Huang, Hao Wang 0003, Guangquan Xu |
IEEE Trans. Fuzzy Syst. | 4 |
| 2022 | CPFL: An Effective Secure Cognitive Personalized Federated Learning Mechanism for Industry 4.0abstractWhile promoting the intelligence in industrial production, Industry 4.0 has also caused privacy leaks concurrently. As a possible solution, the existing personalized federated learning relies too much on a good global model to fine-tune or limit local drift, which lacks intelligent cognitive ability. When faced with heterogeneous data or poisoning attacks, even a few low-quality local models will affect the whole federation effect. In this article, we design a cognitive personalized federated learning (CPFL) mechanism for Industry 4.0, which can selectively improve the collaboration capabilities between more relevant devices. We use the parameters in the local training process as the cognitive basis and calculate Earth mover’s distance to quantify the differences between different models. When the gradient distribution is closer, the local data are more similar. By adaptively adjusting the weight distribution during the aggregation process, self-learning and cooperative learning are balanced, and the interference of heterogeneous data on the federated training process is reduced. Therefore, the global model can better fit most heterogeneous industrial data and achieve personalization. Comparative experimental results show that our proposed CPFL mechanism can increase the average accuracy of personalized models by 5%–10% in non independent and identically distributed situations, and it has certain effects against poisoning attacks and noise interference. Guangquan Xu, Wenqing Lei, Lixiao Gong, James Xi Zheng, Shaoying Liu |
IEEE Trans. Ind. Informatics | 2 |
| 2021 | MFF-AMD: Multivariate Feature Fusion for Android Malware Detection
Guangquan Xu, Meiqi Feng, Litao Jiao, Jian Liu 0004, Hongning Dai, Emmanouil A. Panaousis, James Xi Zheng |
CollaborateCom (1) | 1 |
| 2021 | Higher-Order Multiple-Feature-based Community Evolution Model with Potential Applications in Criminal Network Investigation
Xiaoming Li 0006, Guangquan Xu, Changzheng Liu, Wei Yu 0016, Zhenhuan Wu |
Future Gener. Comput. Syst. | 2 |
| 2021 | TT-SVD: An Efficient Sparse Decision-Making Model With Two-Way Trust Recommendation in the AI-Enabled IoT SystemsabstractThe convergence of AI and IoT enables data to be quickly explored and turned into vital decisions, and however, there are still some challenging issues to be further addressed. For example, lacking of enough data in AI-based decision making [so-called sparse decision making (SDM)] will decrease the efficiency dramatically, or even disable the intelligent IoT networks. Taking the intelligent IoT networks as the network infrastructure, the recommendation systems have been facing such SDM problems. A naive solution is to introduce trust information. However, trust information may also face the difficulty of sparse trust evidence (also known as sparse trust problem). In our work, an accurate SDM model with two-way trust recommendation in the AI-enabled IoT systems is proposed, named TT-SVD. Our model incorporates both trust information and rating information more thoroughly, which can efficiently alleviate the above-mentioned sparse trust problem and therefore be able to solve the cold start and data sparsity problems. Specifically, we first consider the twofold trust influences from both trustees and trusters, which can be represented by a factor named trust propensity. To this end, we propose a dual model, including a truster model (TrusterSVD) and a trustee model (TrusteeSVD) based on an existing rating-only recommendation model called SVD++, which are integrated by the weighted average and yield the final model, TT-SVD. The experimental results show that our model outperforms the state-of-the-art, including SVD and TrustSVD in both the “all users” and “cold start users” cases, and the accuracy improvement can reach a maximum of 29%. Complexity analysis shows that our model is equally suitable for the case of large sparse data sets. In summary, our model can effectively solve the sparse decision problem by introducing the two-way trust recommendation, and hence improve the efficiency of the intelligent recommendation systems. Guangquan Xu, Litao Jiao, Meiqi Feng, Zhong Ji, Emmanouil A. Panaousis, Si Chen 0009, James Xi Zheng |
IEEE Internet Things J. | 1 |
| 2021 | FNet: A Two-Stream Model for Detecting Adversarial Attacks against 5G-Based Deep Learning ServicesabstractWith the extensive application of artificial intelligence technology in 5G and Beyond Fifth Generation (B5G) networks, it has become a common trend for artificial intelligence to integrate into modern communication networks. Deep learning is a subset of machine learning and has recently led to significant improvements in many fields. In particular, many 5G-based services use deep learning technology to provide better services. Although deep learning is powerful, it is still vulnerable when faced with 5G-based deep learning services. Because of the nonlinearity of deep learning algorithms, slight perturbation input by the attacker will result in big changes in the output. Although many researchers have proposed methods against adversarial attacks, these methods are not always effective against powerful attacks such as CW. In this paper, we propose a new two-stream network which includes RGB stream and spatial rich model (SRM) noise stream to discover the difference between adversarial examples and clean examples. The RGB stream uses raw data to capture subtle differences in adversarial samples. The SRM noise stream uses the SRM filters to get noise features. We regard the noise features as additional evidence for adversarial detection. Then, we adopt bilinear pooling to fuse the RGB features and the SRM features. Finally, the final features are input into the decision network to decide whether the image is adversarial or not. Experimental results show that our proposed method can accurately detect adversarial examples. Even with powerful attacks, we can still achieve a detection rate of 91.3%. Moreover, our method has good transferability to generalize to other adversaries. Guangquan Xu, Guofeng Feng, Litao Jiao, Meiqi Feng, James Xi Zheng, Jian Liu 0004 |
Secur. Commun. Networks | 1 |
| 2021 | Generalized Centered 2-D Principal Component AnalysisabstractMost existing robust principal component analysis (PCA) and 2-D PCA (2DPCA) methods involving the l2-norm can mitigate the sensitivity to outliers in the domains of image analysis and pattern recognition. However, existing approaches neither preserve the structural information of data in the optimization objective nor have the robustness of generalized performance. To address the above problems, we propose two novel center-weight-based models, namely, centered PCA (C-PCA) and generalized centered 2DPCA with l2,p-norm minimization (GC-2DPCA), which are developed for vector- and matrix-based data, respectively. The C-PCA can preserve the structural information of data by measuring the similarity between the data points and can also retain the PCA's original desirable properties such as the rotational invariance. Furthermore, GC-2DPCA can learn efficient and robust projection matrices to suppress outliers by utilizing the variations between each row of the image matrix and employing power p of l2,1-norm. We also propose an efficient algorithm to solve the C-PCA model and an iterative optimization algorithm to solve the GC-2DPCA model, and we theoretically analyze their convergence properties. Experiments on three public databases show that our models yield significant improvements over the state-of-the-art PCA and 2DPCA approaches. Gongyu Zhou, Guangquan Xu, Jianye Hao, Shizhan Chen, James Xi Zheng |
IEEE Trans. Cybern. | 2 |
| 2021 | Sparse Trust Data MiningabstractAs recommendation systems continue to evolve, researchers are using trust data to improve the accuracy of recommendation prediction and help users find relevant information. However, large recommendation systems with trust data suffer from the sparse trust problem, which leads to grade inflation and severely affects the reliability of trust propagation. This paper presents a novel research on sparse trust data mining, which includes the new concept of sparse trust, a sparse trust model, and a trust mining framework. It lays a foundation for the trust-related research in large recommended systems. The new trust mining framework is based on customized normalization functions and a novel transitive gossip trust model, which discovers potential trust information between entities in a large-scale user network and applies it to a recommendation system. We conducts a comprehensive performance evaluation on both real-world and synthetic datasets. The results confirm that our framework mines new trust and effectively ameliorates sparse trust problem. Pengli Nie, Guangquan Xu, Litao Jiao, Shaoying Liu, Jian Liu 0004, Weizhi Meng 0001, Hongyue Wu, Meiqi Feng, Zhengjun Jing, James Xi Zheng |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2020 | Defending Use-After-Free via Relationship Between Memory and Pointer
Guangquan Xu, Kai Chen 0012, Wei Wang 0012, Kaitai Liang, Qiang Tang 0005, Shaoying Liu |
CollaborateCom (1) | 1 |
| 2020 | A Variational Generative Network Based Network Threat Situation Assessment
Hongyu Yang 0003, Renyun Zeng, Fengyan Wang, Guangquan Xu, Jiyong Zhang 0001 |
ICICS | 4 |
| 2020 | Security analysis of indistinguishable obfuscation for internet of medical things applications
Zhengjun Jing, Chunsheng Gu, Mengshi Zhang, Guangquan Xu, Alireza Jolfaei, Peizhong Shi, Chenkai Tan, James Xi Zheng |
Comput. Commun. | 5 |
| 2020 | Am I eclipsed? A smart detector of eclipse attacks for Ethereum
Guangquan Xu, Bingjiang Guo, Chunhua Su, James Xi Zheng, Kaitai Liang, Duncan S. Wong, Hao Wang 0003 |
Comput. Secur. | 1 |
| 2020 | Location Privacy-Preserving Distance Computation for Spatial CrowdsourcingabstractData privacy, especially location privacy, is paramountly important for protecting individual's information in smart cities in the big data era. One of the examples is in spatial crowdsourcing (SC). It enables people not only to issue spatiotemporal tasks to ask for help as requesters but also to solve others' tasks as workers on the SC platform. While SC brings convenience to people, it also produces severe location privacy problems, which have been recently paid more attention from both academia and industries. In this article, we address the location privacy problem in SC in a practical and secure way. We propose a location privacy-preserving framework for almost all existed mainstream distance computations in the SC system, namely, Euclidean-L3P, Minkowski-L3P, Manhattan-L3P, and Chebyshev-L3P, among which the first two are constructed based on homomorphic encryption and composite-order multilinear mapping while the latter two on the homomorphic encryption and prefix membership verification approach. Location privacy is resolved because of the above techniques having enabled that all distance computations are evaluated through ciphertexts without disclosing any location information. Security analysis shows that our framework can prevent a strong adversary from obtaining participants' location privacy. Performance analysis evaluates computation and communication overheads between protocols. The results show that Euclidean-L3P is more efficient than Manhattan-L3P and Chebyshev-L3P in terms of computation overheads when the SC applications require a small number of participants, a large plaintext space, and a small number of base stations. Moreover, compared with Manhattan-L3P and Chebyshev-L3P, Euclidean-L3P is a better choice in terms of communication overhead. Song Han 0006, Jianhong Lin, Guangquan Xu, Siqi Ren, Daojing He, Licheng Wang 0004, Leyun Shi |
IEEE Internet Things J. | 4 |
| 2020 | Integrating NFV and ICN for Advanced Driver-Assistance SystemsabstractAdvanced driver-assistance systems (ADASs) have been proposed as an alternative to driverless vehicles to provide support for automotive vehicle decisions. As a significant driving force for ADASs, the augmented reality (AR) provides comprehensive location-based content services for in-vehicle consumers. With the increase in request for information sharing, the current standalone mode of ADASs needs a shift to the multiuser sharing mode. In this article, to address the high mobility and real time requirements of ADASs in 5G environments, and also to address the resource orchestration and service management of big data in intelligent transportation systems, we integrate the information-centric network (ICN) and the network function virtualization (NFV) with ADASs to support an efficient AR-assisted content sharing and distribution. This integration eliminates the imbalance between the content requests and the resource limitation by splitting the virtual resources and providing an on-demand network and resource slicing in ADASs. We propose an incentive trading model for assistance content caching services and also propose a novel mechanism for optimal content cache allocation. Our extensive evaluation confirms that our proposed mechanism outperforms the past literature in terms of the cache hit ratio and latency. Jun Wu 0001, Guangquan Xu, Jianhua Li 0001, James Xi Zheng, Alireza Jolfaei |
IEEE Internet Things J. | 3 |
| 2020 | SoProtector: Safeguard Privacy for Native SO Files in Evolving Mobile IoT ApplicationsabstractAndroid Apps have become the most important mobile applications in the evolving mobile IoT systems, whose security and privacy are confronted with ever more challenges, since such mobile devices as smartphones involve too much personal privacy information. Meanwhile, the developers prefer to put core functions (e.g., encryption function and T9 search function) of Android applications in the native layer for execution efficiency. However, there are no automated security analysis tools to protect the security and privacy of the Android native layer, especially for those dynamically loaded third-party SO libraries. In order to solve the previous problem, which is confusing, we propose a novel and scalable system, called SoProtector, to prevent privacy from leaking via the analysis of data flow between the Java and native layers. For detection of the malicious function implanted in the SO libraries, SoProtector realizes a real-time engine. We derive the malware features via three steps: 1) present binary files in native family as a grayscale image; 2) with use of the ARM instructions set reversely obtain the code of the SO file and using Python to obtain the opcode sequence; and 3) each file is transformed as the form of assembly language by IDA Pro, which includes a gdl file as an accompaniment. Our experiment, which involved 3400 applications, demonstrates that SoProtector is able to detect more sinks, sources, and smudges. It effectively inspects and blocks at least 82% of the applications that are loading malicious third-party SO dynamically, and it has relatively low overhead in the meantime, compared to most of the existing static analysis tools (e.g., FlowDroid and AndroidLeaks). Guangquan Xu, Wei Wang 0012, Litao Jiao, Kaitai Liang, James Xi Zheng, Wenjuan Lian, Hequn Xian, Honghao Gao |
IEEE Internet Things J. | 1 |
| 2020 | Privacy-preserving categorization of mobile applications based on large-scale usage data
Guangquan Xu, Wenjuan Lian, Hequn Xian, Wei Wang 0012 |
Inf. Sci. | 3 |
| 2020 | Identifying vulnerabilities of SSL/TLS certificate verification in Android apps with static and dynamic analysis
Guangquan Xu, Weixuan Mao, Chengxiang Si, Witold Pedrycz, Wei Wang 0012 |
J. Syst. Softw. | 2 |
| 2020 | An Unsupervised Learning-Based Network Threat Situation Assessment Model for Internet of ThingsabstractWith the wide application of network technology, the Internet of Things (IoT) systems are facing the increasingly serious situation of network threats; the network threat situation assessment becomes an important approach to solve these problems. Aiming at the traditional methods based on data category tag that has high modeling cost and low efficiency in the network threat situation assessment, this paper proposes a network threat situation assessment model based on unsupervised learning for IoT. Firstly, we combine the encoder of variational autoencoder (VAE) and the discriminator of generative adversarial networks (GAN) to form the V-G network. Then, we obtain the reconstruction error of each layer network by training the network collection layer of the V-G network with normal network traffic. Besides, we conduct the reconstruction error learning by the 3-layer variational autoencoder of the output layer and calculate the abnormal threshold of the training. Moreover, we carry out the group threat testing with the test dataset containing abnormal network traffic and calculate the threat probability of each test group. Finally, we obtain the threat situation value (TSV) according to the threat probability and the threat impact. The simulation results show that, compared with the other methods, this proposed method can evaluate the overall situation of network security threat more intuitively and has a stronger characterization ability for network threats. Hongyu Yang 0003, Renyun Zeng, Fengyan Wang, Guangquan Xu, Jiyong Zhang 0001 |
Secur. Commun. Networks | 4 |
| 2020 | HUCDO: A Hybrid User-centric Data Outsourcing SchemeabstractOutsourcing helps relocate data from the cyber-physical system (CPS) for efficient storage at low cost. Current server-based outsourcing mainly focuses on the benefits of servers. This cannot attract users well, as their security, efficiency, and economy are not guaranteed. To solve with this issue, a hybrid outsourcing model that exploits both cloud server and edge devices to store data is needed. Meanwhile, the requirements of security and efficiency are different under specific scenarios. There is a lack of a comprehensive solution that considers all of the above issues. In this work, we overcome the above issues by proposing the first hybrid user-centric data outsourcing (HUCDO) scheme. It allows users to outsource data securely, efficiently, and economically via different CPSs. Brielly, our contributions consist of theories, implementations, and evaluations. Our theories include the first homomorphic collision-resistant chameleon hash (HCCH) and homomorphic designated-receiver signcryption (HDRS). As implementations, we instantiate how to use our proposals to outsource small- or large-scale data through distinct CPS, respectively. Additionally, a blockchain with proof-of-discrete-logarithm (B-PoDL) is instantiated to help improve our performance. Last, as demonstrated by our evaluations, our proposals are secure, efficient, and economic for users to implement while outsourcing their data via CPSs. Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Guangquan Xu, Hao Wang 0003, James Xi Zheng, Guomin Yang, Qi Xia 0001, Xiaojiang Du |
ACM Trans. Cyber Phys. Syst. | 6 |
| 2020 | Sensing Users' Emotional Intelligence in Social NetworksabstractSocial networks have integrated into the daily lives of most people in the way of interactions and of lifestyles. The users' identity, relationships, or other characteristics can be explored from the social networking data, in order to provide personalized services to the users. In this article, we focus on predicting the user's emotional intelligence (EI) based on social networking data. As an essential facet of users' psychological characteristics, EI plays an important role on well-being, interpersonal relationships, and overall success in people's life. Perception of EI contributes to predicting one's behavior or group behavior. Most existing work on predicting people's EI is based on questionnaires that may collect dishonest answers or unconscientious responses, thus leading in potentially inaccurate prediction results. In this article, we are motivated to propose EI prediction models based on the sentiment analysis of social networking data. The models are represented by four dimensions, including self-awareness, self-regulation, self-motivation, and social relationships. The EI of a user is then measured by four numerical values or the sum of them. In the experiments, we predict the EIs of over a hundred thousand users based on one of the largest social networks of China, Weibo. The predicting results demonstrate the effectiveness of our models. The results show that the distribution of the four EI's dimensions of users is roughly normal. The results also indicate that EI scores of females are generally higher than males' EI scores. This is consistent with previous findings. In addition, the four dimensions of EI are correlated. We finally analyze the advantages and the disadvantages of our models in predicting users' EI with social networking data. Guangquan Xu, Hao Wang 0003, Zhen Han 0001, Wei Wang 0012 |
IEEE Trans. Comput. Soc. Syst. | 2 |
| 2020 | An Effective Evolutionary Analysis Scheme for Industrial Software Access Control ModelsabstractAccess control is an essential feature of industrial software systems security mechanisms. Role-based access control (RBAC), which is likely the most popular access-control technique, specifies “user roles” and associates each role with “permissions” to access distinct system functionalities. These role-permissions assignment rules, as well as the types of system users and system functionalities, evolve over time. In this paper, we describe a methodology for analyzing and understanding the RBAC-configuration evolution, its relation to the overall evolutionary lifecycle of industrial systems, and its impact on security vulnerabilities from which the system may suffer. Our methodology considers two different sources of information regarding the RBAC-configuration evolution: 1) the role-permissions matrices of subsequent system versions; and 2) the corresponding concept lattices, implied by these matrices. By examining the evolution of these two system properties, developers can easily notice which versions involve more and more complex RBAC-configuration changes that may indicate higher security risks. We demonstrate our methodology using a study of four popular real-world systems: 1) MediaWiki; 2) Moodle; 3) Joomla; and 4) WordPress. Our findings show that the proposed metrics have strong, positive linear correlations with the security vulnerabilities' properties. Zhuobing Han, Xiaohong Li 0001, Guangquan Xu, Naixue Xiong, Ettore Merlo, Eleni Stroulia |
IEEE Trans. Ind. Informatics | 3 |
| 2020 | A Secure Random Key Distribution Scheme Against Node Replication Attacks in Industrial Wireless Sensor SystemsabstractWith the wide deployment of wireless sensor networks in smart industrial systems, lots of unauthorized attacking from the adversary are greatly threatening the security and privacy of the entire industrial systems, of which node replication attacks can hardly be defended, since it is conducted in the physical layer. To solve this problem, we propose a secure random key distribution (SRKD) scheme, which provides a new method for the defense against the attack. Specifically, we combine a localized algorithm with a voting mechanism to support the detection and revocation of malicious nodes. We further change the meaning of the parameter s to help prevent the replication attack. Furthermore, the experimental results show that the detection ratio of replicate nodes exceeds 90% when the number of network nodes reaches 200, which demonstrates the security and effectiveness of our scheme. Compared with existing state-of-the-art schemes, the SRKD scheme also has good storage and communication efficiency. Longpeng Li, Guangquan Xu, Litao Jiao, Hao Wang 0003, Jing Hu 0007, Hequn Xian, Wenjuan Lian, Honghao Gao |
IEEE Trans. Ind. Informatics | 2 |
| 2020 | Energy-Efficient and Trustworthy Data Collection Protocol Based on Mobile Fog Computing in Internet of ThingsabstractThe tremendous growth of interconnected things/devices in the whole world advances to the new paradigm, i.e., Internet of Things (IoT). The IoT use sensor-based embedded systems to interact with others, providing a wide range of applications and services to upper-level users. Undoubtedly, the data collected by the underlying IoTs are the basis of the upper-layer decision and the foundation for all the applications, which requires efficient energy protocols. Moreover, if the collected data are erroneous and untrustworthy, the data protection and application becomes an unrealistic goal, which further leads to unnecessary energy cost. However, the traditional methods cannot solve this problem efficiently and trustworthily. To achieve this goal, in this paper we design a novel energy-efficient and trustworthy protocol based on mobile fog computing. By establishing a trust model on fog elements to evaluate the sensor nodes, the mobile data collection path with the largest utility value is generated, which can avoid visiting unnecessary sensors and collecting untrustworthy data. Theoretical analysis and experimental results validate that our proposed architecture and method outperform traditional data collection methods in both energy and delay. Tian Wang 0001, Lei Qiu 0005, Arun Kumar Sangaiah, Guangquan Xu, Anfeng Liu |
IEEE Trans. Ind. Informatics | 4 |
| 2020 | SSL-SVD: Semi-supervised Learning-based Sparse Trust RecommendationabstractRecommendation systems have been widely used in large e-commerce websites, but cold start and data sparsity seriously affect the accuracy of recommendation. To solve these problems, we propose SSL-SVD, which works to mine the sparse trust between users and improve the performance of the recommendation system. Specifically, we mine sparse trust relationships by decomposing trust impact into fine-grained factors and employing the Transductive Support Vector Machine algorithm to combine these factors. Then, we incorporate both social trust and sparse trust information into the SVD++ model, which can effectively utilize the explicit and implicit influence of trust for rating prediction in the recommendation system. Experiments show that our SSL-SVD increases the trust density degree of each dataset by more than 65% and improves the recommendation accuracy by up to 4.3%. Zhengdi Hu, Guangquan Xu, James Xi Zheng, Zhangbing Li, Quan Z. Sheng, Wenjuan Lian, Hequn Xian |
ACM Trans. Internet Techn. | 2 |
| 2019 | SSL-STR: Semi-Supervised Learning for Sparse Trust RecommendationabstractTrust is widely applied in recommender systems to improve recommendation performance by alleviating well-known problems, such as cold start, data sparsity, and so on. However, trust data itself also faces sparse problems. To solve these problems, we propose a novel sparse trust recommendation model, SSL-STR. Specifically, we decompose the aspects influencing trust-building into finer-grained factors, and combine these factors to mine the implicit sparse trust relationships among users by employing the Transductive Support Vector Machine algorithm. Then we extend SVD++ model with social trust and sparse trust information for rating prediction in the recommendation system. Experiments show that our SSL-STR improves the recommendation accuracy by up to 4.3%. Zhengdi Hu, Guangquan Xu, James Xi Zheng, Xiaojiang Du |
GLOBECOM | 2 |
| 2019 | An Efficient Vulnerability Detection Model for Ethereum Smart Contracts
Jingjing Song, Haiwu He, Zhuo Lv, Chunhua Su, Guangquan Xu, Wei Wang 0012 |
NSS | 5 |
| 2019 | One-round provably secure yoking-proof for RFID applicationsabstractSummary The yoking‐proof is the evidence that two or more RFID (Radio Frequency Identification) tags have been scanned simultaneously. Thanks to the IoT (Internet of Things), the yoking‐proof scheme becomes a very useful mechanism in many application areas such as health care and supply chain. However, the existing yoking‐proof schemes require two or more rounds of communication to generate the yoking‐proof. Following our idea presented in IEEE TrustCom 2017, we further investigate how to design the one‐round yoking‐proof scheme with efficiency advantage. Our contributions are threefold: (1) we propose a new timestamp‐based scheme for the RFID tag pair; (2) we prove the security and privacy of the proposed scheme under our models; (3) the proposed scheme is extended for the m > 2 RFID tags. In addition, the extended scheme still maintains one‐round of communication to generate the yoking‐proof. Da-Zhi Sun, Ze-Guang Zhu, Guangquan Xu, Wei Guo 0005 |
Concurr. Comput. Pract. Exp. | 3 |
| 2019 | Polynomial-based modifiable blockchain structure for removing fraud transactions
Lichen Cheng, Jiqiang Liu, Chunhua Su, Kaitai Liang, Guangquan Xu, Wei Wang 0012 |
Future Gener. Comput. Syst. | 5 |
| 2019 | E-AUA: An Efficient Anonymous User Authentication Protocol for Mobile IoTabstractThe emergence of the mobile Internet of Things (IoT) has made our lives smarter, relying on its various mobile IoT devices and services provided. However, with the explosively emerging mobile IoT services, malicious attackers can access them in an unauthorized way. In this paper, we designed an Efficient Anonymous User Authentication (E-AUA) protocol between the users and servers based on multiserver architectures, which contain multiple servers to address the problem of network congestion in mobile IoT. Furthermore, the E-AUA protocol was designed with a dual messages mechanism with strong anti-attack ability, lower communication and computation costs. Comparing with the state of the art protocols, our E-AUA protocol reduced both communication and computation costs. We also provided a security analysis to demonstrate that our E-AUA protocol is secure and meets a variety of security requirements in a motivated mobile IoT scenario. Xianjiao Zeng, Guangquan Xu, James Xi Zheng, Yang Xiang 0001, Wanlei Zhou 0001 |
IEEE Internet Things J. | 2 |
| 2019 | Spatio-temporal deep learning method for ADHD fMRI classification
Zhenyu Mao, Guangquan Xu, Yu Huang 0004, Weihua Yue, Naixue Xiong |
Inf. Sci. | 3 |
| 2019 | CSP-E2: An abuse-free contract signing protocol with low-storage TTP for energy-efficient electronic transaction ecosystems
Guangquan Xu, Yao Zhang 0019, Arun Kumar Sangaiah, Xiaohong Li 0001, Aniello Castiglione, James Xi Zheng |
Inf. Sci. | 1 |
| 2019 | SCTSC: A Semicentralized Traffic Signal Control Mode With Attribute-Based Blockchain in IoVsabstractAssisting traffic control is one of the most important applications on the Internet of Vehicles (IoVs). Traffic information provided by vehicles is desired since drivers or vehicle sensors are sensitive in perceiving or detecting nuances on roads. However, the availability and privacy preservation of this information are critical while conflicted with each other in the vehicular communication. In this paper, we propose a semicentralized mode with attribute-based blockchain in IoVs to balance the tradeoff between the availability and the privacy preservation. In this mode, a method of control-by-vehicles is used to control signals of traffic lights to increase traffic efficiency. Users are grouped their attributes such as locations and directions before starting the communication. The users reach an agreement on determining a temporary signal timing by interacting with each other without leaking privacy. Final decisions are verifiable to all users, even if they have no a priori agreement and processes of consensus. The mode not only achieves the aim of privacy preservation but also supports responsibility investigation for historical agreements via ciphertext-policy attribute-based encryption (CP-ABE) and blockchain technology. Extensive experimental results demonstrated that our mode is efficient and practical. Lichen Cheng, Jiqiang Liu, Guangquan Xu, Zonghua Zhang, Hao Wang 0003, Hongning Dai, Yulei Wu, Wei Wang 0012 |
IEEE Trans. Comput. Soc. Syst. | 3 |
| 2019 | Using Sparse Representation to Detect Anomalies in Complex WSNsabstractIn recent years, wireless sensor networks (WSNs) have become an active area of research for monitoring physical and environmental conditions. Due to the interdependence of sensors, a functional anomaly in one sensor can cause a functional anomaly in another sensor, which can further lead to the malfunctioning of the entire sensor network. Existing research work has analysed faulty sensor anomalies but fails to show the effectiveness throughout the entire interdependent network system. In this article, a dictionary learning algorithm based on a non-negative constraint is developed, and a sparse representation anomaly node detection method for sensor networks is proposed based on the dictionary learning. Through experiment on a specific thermal power plant in China, we verify the robustness of our proposed method in detecting abnormal nodes against four state of the art approaches and proved our method is more robust. Furthermore, the experiments are conducted on the obtained abnormal nodes to prove the interdependence of multi-layer sensor networks and reveal the conditions and causes of a system crash. Xiaoming Li 0006, Guangquan Xu, James Xi Zheng, Kaitai Liang, Emmanouil A. Panaousis, Tao Li 0022, Wei Wang 0012, Chao Shen 0001 |
ACM Trans. Intell. Syst. Technol. | 2 |
| 2019 | Anonymous three-factor authenticated key agreement for wireless sensor networks
Yanrong Lu, Guangquan Xu, Lixiang Li 0001, Yixian Yang |
Wirel. Networks | 2 |
| 2018 | Roundtable Gossip Algorithm: A Novel Sparse Trust Mining Method for Large-Scale Recommendation Systems
Guangquan Xu, Jun Zhang 0010, Rajan Shankaran, James Xi Zheng, Zonghua Zhang |
ICA3PP (4) | 2 |
| 2018 | SoProtector: Securing Native C/C++ Libraries for Mobile Applications
Guangquan Xu, Guozhu Meng, James Xi Zheng |
ICA3PP (3) | 2 |
| 2018 | EasyGo: Low-cost and robust geographic opportunistic sensing routing in a strip topology wireless sensor network
Chen Liu 0002, Dingyi Fang, Yue Hu 0004, Shensheng Tang, Dan Xu 0003, Wen Cui, Xiaojiang Chen, Baoying Liu, Guangquan Xu |
Comput. Networks | 9 |
| 2018 | A novel optimized vertical handover framework for seamless networking integration in cyber-enabled systems
Xiaohong Li 0001, Zhiyong Feng 0002, Guangquan Xu, Zhangjie Fu 0001 |
Future Gener. Comput. Syst. | 4 |
| 2018 | A novel efficient MAKA protocol with desynchronization for anonymous roaming service in Global Mobility Networks
Guangquan Xu, Yanrong Lu, Xianjiao Zeng, Yao Zhang 0019, Xiaoming Li 0006 |
J. Netw. Comput. Appl. | 1 |
| 2018 | TT-XSS: A novel taint tracking based dynamic detection framework for DOM Cross-Site Scripting
Guangquan Xu, Xianjiao Zeng, Xiaohong Li 0001, Zhiyong Feng 0002 |
J. Parallel Distributed Comput. | 2 |
| 2018 | Scalable platforms and advanced algorithms for IoT and cyber-enabled applications
Xiaokang Zhou, Guangquan Xu, Jianhua Ma 0002, Ivan Ruchkin |
J. Parallel Distributed Comput. | 2 |
| 2018 | Community detection for multi-layer social network based on local random walk
Xiaoming Li 0006, Guangquan Xu, Minghu Tang |
J. Vis. Commun. Image Represent. | 2 |
| 2017 | An Efficient Critical Incident Propagation Model for Social Networks Based on Trust Factor
Xiaoming Li 0006, Limengzi Yuan, Chaochao Liu, Wei Yu 0016, Xue Chen 0005, Guangquan Xu |
CollaborateCom | 6 |
| 2017 | FESR: A Framework for Eliciting Security Requirements Based on Integration of Common Criteria and Weakness Detection Formal ModelabstractIt is critical and foremost to come up with the corresponding security requirements first which the following implementations are based on. However, previous security requirement elicitation work based on Common Criteria (CC) rarely addresses the detailed elicitation process of threats from specific functional requirements, which thus results in the widen gap between specific functional requirements and their corresponding threats. To this end, this paper proposes a framework for eliciting corresponding security requirements of specific functional requirements from the requirements specification. A formal model is built in the framework to assist requirement analysts in half-automatic collecting threats. To enhance the framework's automaticity and reusability, a security property base is constructed based on authoritative sources of security properties to support the framework. A practical information system is applied to verify the framework's practicability. Finally the framework's advantages and limitations are discussed thoroughly compared with previous approaches and useful insights are revealed. Hongbo Li 0003, Xiaohong Li 0001, Jianye Hao, Guangquan Xu, Zhiyong Feng 0002, Xiaofei Xie |
QRS | 4 |
| 2017 | HFA-MD: An Efficient Hybrid Features Analysis Based Android Malware Detection Method
Guangquan Xu, Yao Zhang 0019 |
QSHINE | 2 |
| 2017 | POQAS-S: a Novel Programmer-Oriented Online Question Answering System With Semantic ComprehensionabstractTo improve the ability and efficiency of acquiring kno wledge for programmers, programmer-oriented online question a nswering system (POQAS) has been advanced recently.However, current POQAS systems are short of semantic sensing ability.To solve this problem, this paper proposed a novel programmer-ori ented online question answering system with semantic comprehen sion (POQAS-S), which is based on the TuringOS.Since semantic comprehension is introduced, our POQAS-S system can underst and the input information more precisely.Further, POQAS-S is a ble to give a more precise answer to users than traditional POQA S systems.In this paper, we developed a concrete POQAS-S syste m on the android platform, which demonstrated well in contrast t o other traditional POQAS systems in a more precise answering providing.Our POQAS-S can be referred to develop more other similar POQAS-S systems besides out built android APP in this p aper. Guangquan Xu, Kaili Qiu |
SEKE | 2 |
| 2017 | Automated Software Security Requirements Recommendation Based on FT-SR ModelabstractSince security is recommended to be evaluated at the beginning of the software development process, specifying software security requirements is inevitable in developing Critical Information Security Systems.However, according to the ISO/IEC 15408 (known as Common Criteria), determining detailed software security requirements (SRs) is quite challenging, complex which needs lots of expert knowledge of security.In this paper, a data-driven Functionality Topic-Security Requirement (FT-SR) model is proposed to recommend software SRs based on the relationship between software functionality specification and SRs from software Security Target (ST) which have been written in accordance with ISO/IEC 15408.First, we extract descriptions of functionality and tag SRs all from software STs.Second, Latent Dirichlet Allocation (LDA) is adopted to build functionality topics for product functionality description.Third, a FT-SR model is developed based on the mapping between product functionality topics and SRs which have been tagged in ST documents.Finally, a recommendation strategy is proposed to recommend SRs based on the FT-SR model for software products.Our experiments are performed on ST documents of over 600 software products provided by Common Criteria.Experimental results show that the proposed approach can generate a set of recommended SRs reducing the difficulty of SRs recommending even for people lack knowledge of security. Jiangjuan Wang, Xiaohong Li 0001, Zhiyong Feng 0002, Jianye Hao, Guangquan Xu, Zhuobing Han |
SEKE | 5 |
| 2017 | MP-MID: Multi-Protocol Oriented Middleware-level Intrusion Detection method for wireless sensor networks
Xiaohong Li 0001, Guangquan Xu, Zhiyong Feng 0002 |
Future Gener. Comput. Syst. | 3 |
| 2017 | A multi-attribute rating based trust model: improving the personalized trust modeling framework
Guangquan Xu, Gaoxu Zhang, Chao Xu 0003, Mingquan Li, Xiaohong Li 0001, Zhiyong Feng 0002, Degan Zhang 0001 |
Multim. Tools Appl. | 1 |
| 2016 | Universal Analysis and Detection Framework for Location Aided RoutingabstractIn the MANETs (Mobile Ad Hoc Networks), attack detection in Location Aided Routing (LAR) has become a challenging problem due to the dynamic network topology and diverse routing attacks. This paper proposes a universal framework to analyze and detect attack traces for various potential attack targets. In this framework, the attack targets are identified by matching key events, and a reverse search algorithm based on iteration is employed to obtain attack traces and attack conditions, which are guidance for generation of detection rules. Algebra for Wireless Mesh Networks (AWN) is extended to specify the core functionality of LAR, and detection rules are validated by NS-2 platform. The results demonstrate that the approach is correct and efficient. Xiaohong Li 0001, Zhiyong Feng 0002, Guangquan Xu |
ICECCS | 4 |
| 2016 | Fepchecker: An Automatic Model Checker for Verifying Fairness and Non-Repudiation of Security Protocols in Web ServiceabstractEnsuring the fairness and non-repudiation in the security exchange protocol of web service is critical. Model checking is often used for automatic verification for the security properties of protocol. However, the current model checker tools cannot support formalizing protocols with cryptographic primitives, specifying properties with linear temporal logic (LTL) and automatically generating resilient intruder model simultaneously and the application range of them is severely limited. To solve this problem, a model checker Fepchecker is proposed to verify the fairness and non-repudiation properties, which are critical features in security exchange protocols. Firstly, applied pi-calculus is extended to specify the protocols, and the LTL assertion is used for precisely describing fairness and non-repudiation. Secondly, an intruder model is applied to construct their behavior sequences automatically and the protocol sessions and message pattern are used to alleviate the states explosion problem. Thirdly, in our model checking algorithm, the fairness and non-repudiation properties are verified based on Labeled Transition System (LTS) semantics model and the MakeOneMove method is used to explore the state space on-the-fly in the verification process. Finally, Fepchecker is applied to verify six representative protocols and the results show that Fepchecker can effectively verify their fairness and non-repudiation properties. Xiaohong Li 0001, Guangquan Xu, Jianye Hao, Xiaoru Li, Zhiyong Feng 0002, Honghao Gao |
Int. J. Softw. Eng. Knowl. Eng. | 3 |
| 2015 | Towards Trustworthy Participants in Social Participatory NetworksabstractBy leveraging online social networks as an underlying infrastructure, Social Participatory Network (SPN) has been becoming a new paradigm of participatory sensing systems. However, a significant barrier to the widespread use of SPN applications is their vulnerability to various forms of malicious attacks. Such threats inhibit human participation and thus the viability of SPN systems in everyday use. To solve this problem, this paper proposes a trust evaluation framework for participants to encourage wider human participation in SPN. The proposal is based on the Tianjin University's own existing SPN system, named CRCS (ClassRoom Cloud System), which enables participants to use the cloud resources for online lessons or library study. It derives the trust value of participants by using entropy-weight method and data mining algorithms to deal with the behaviors data of participants. Our proposed solution can detect malicious participants easily, and more importantly, it outperforms other work for its low cost and simple deployment. For now, though our solution is based on a specified SPN system, we are confident that this solution is highly applicable to most other SPN systems. Guangquan Xu, Yuanyuan Ren, Runhe Huang, Gaoxu Zhang, Zhiyong Feng 0002, Xiaohong Li 0001 |
CSCloud | 1 |
| 2015 | PEM4RFID: Privacy Enhancement Model for RFID Systems
Guangquan Xu, Yuanyuan Ren, Gaoxu Zhang, Xiaohong Li 0001, Zhiyong Feng 0002 |
ICA3PP (3) | 1 |
| 2015 | POSTER: API-Level Multi-policy Access Control Enforcement for Android Middleware
Dongdong Tian, Xiaohong Li 0001, Jing Hu 0007, Guangquan Xu, Zhiyong Feng 0002 |
SecureComm | 4 |
| 2014 | An Extended UML Method for the Verification of Security ProtocolsabstractThis paper presents a formal modeling method of security protocols based on the extended UML framework. In order to simplify the process and reduce the difficulty of security protocol modelling, extending mechanisms for the class diagram and sequence diagram of UML are presented, which provide an engineering specification for the security protocol formalizing. Therefore, for verifying the confidentiality and correspondence of security protocols by Prover if, a transformation from extended UML model to Prover if Spi calculus model is realized with matching rules and knowledge reasoning, and then the verifying results are analyzed through a regular expression. Finally, the handshake, NS public key and buyer-seller watermarking protocols are verified, the attack traces of unsatisfied security properties are exported, that show the validity and applicability of the approach provided by this paper. Xiaohong Li 0001, Guangquan Xu, Jing Hu 0007, Zhiyong Feng 0002 |
ICECCS | 4 |
| 2014 | OOPN-SRAM: A Novel Method for Software Risk AssessmentabstractThis paper proposes a Software Risk Assessment Method based on Object-Oriented Petri Net (OOPN-SRAM), in which risk assessment procedure is divided into four steps, expressed as four corresponding objects, including asset recognition, weakness analysis, consequence property confirmation and risk calculation. Each object is modeled with Petri net. Specialists recognize software assets by the 1-9 scales method of Analytic Hierarchy Process (AHP). The weaknesses in a system are found by the vulnerability scanner. The damage degree and the exploitation likelihood of a weakness are evaluated by such authorities as Common Weakness Enumeration (CWE). The consequence properties are confirmed by specialists according to the software requirements. Finally, in the risk calculation, risk degree and overall risk value are calculated by using exponential method and weighted average method respectively. Furthermore, we illustrate the application of our OOPN-SRAM method with realistic examples including web-banking and forum, and make a comparison with traditional methods. The results show that OOPN-SRAM not only increases the efficiency of the evaluation process, but also makes the evaluation result more objective and accurate. Xiaohong Li 0001, Guangquan Xu, Jing Hu 0007, Zhiyong Feng 0002 |
ICECCS | 4 |
| 2014 | Hybrid Detection Using Permission Analysis for Android Malware
Haofeng Jiao, Xiaohong Li 0001, Lei Zhang 0024, Guangquan Xu, Zhiyong Feng 0002 |
SecureComm (1) | 4 |
| 2014 | A Three-Dimensional Model for Software Security EvaluationabstractSoftware security evaluation is considered as a significant and indispensible activity in all phases of software development lifecycle, and there are also many factors that should be taken into account such as the environment, risks, and development documents. Despite the achievements of the past several decades, there is still a lack of methodology in evaluating software security systematically. In this paper, we propose a comprehensive model for evaluating the software security from three different but complementary points of view: technology, management and engineering. The technological dimension is 7 security levels based on Evaluation Assurance Levels (EALs) from ISO/IEC15408, the management dimension mainly concerns the management of software infrastructures, development documents and risks, and the engineering dimension focuses on 5 stages of software development lifecycle. Experts evaluate software security through the evidence items which are collected from these three dimensions and provide their assessments. Relying on Analytic Hierarchy Process (AHP) and Dempster-Shafer Evidence Theory, assessments obtained from the experts can be combined and merged to get a score which presents the security degree of software. A case study illustrates how the evaluators may use the proposed approach to evaluate security of their system. Zhuobing Han, Xiaohong Li 0001, Jing Hu 0007, Guangquan Xu, Zhiyong Feng 0002 |
TASE | 5 |
| 2014 | Mining Specification of Insecure Browser Extension BehaviorabstractIn this paper, a method about how to identify insecure behaviors of browser extensions is proposed. Typically, the identification of insecure extension behaviors is based on knowledge which is got by investigating known malicious or vulnerable extensions. We present an automatic technique that can ease the laborious manual investigating process. Our technique mines the difference between the behavior graphs of insecure and secure extensions based on graph mining algorithm. The difference between them is the specification of insecure extension behaviors which can be further analyzed manually or automatically to help people make a better decision about whether an extension is secure or not. We developed a prototype and the experimental results show that this kind of technique can effectively extract insecure extension behaviors. Hongbin Pei, Xiaohong Li 0001, Guangquan Xu, Zhiyong Feng 0002 |
TrustCom | 3 |
| 2014 | Attack Tree Based Android Malware Detection with Hybrid AnalysisabstractThis paper proposes an Android malware detection approach based on attack tree. Attack tree model is extended to provide a novel way to organize and exploit behavior rules. Connections between attack goals and application capability are represented by an attack tree structure and behavior rules are assigned to every attack path in the attack tree. In this way, fine-grained and comprehensive static capability estimation and dynamic behavior detection can be achieved. This approach employs a hybrid static-dynamic analysis method. Static analysis tags attack tree nodes based on application capability. It filters the obviously benign applications and highlights the potential attacks in suspicious ones. Dynamic analysis selects rules corresponding to the capability and conducts detection according to runtime behaviors. In dynamic analysis, events are simulated to trigger behaviors based on application components, and hence it achieves high code coverage. Finally, in this way, we implement an automatic malware detection prototype system called AM Detector. The experiment result shows that the true positive rate is 88.14% and the false positive rate is as low as 1.80%. Xiaohong Li 0001, Guangquan Xu, Lei Zhang 0024, Zhiyong Feng 0002 |
TrustCom | 3 |
| 2014 | Unified threat model for analyzing and evaluating software threatsabstractABSTRACT Design‐level vulnerabilities are a major source of security problems in software programs. For the purpose of improving the trustworthiness of software designs, this paper presents a unified threat model for representing, analyzing, and evaluating software threats at various design stages. Unified threat models represent software threats via tree structures with AND/OR logical relationships and evaluates software threats in a cost‐effective way based on attack paths. Mitigation measures for software threats are designed and prioritized based on the evaluation results, which make it possible to design high‐quality software security programs that resist identified software threats. A case study for an online banking system is given to systematically demonstrate the application of unified threat models in software threat analysis and evaluation. The results from the case study demonstrate that the unified threat model is superior to traditional threat trees in accurately evaluating results, designing mitigation measures, and guiding software security testing. Copyright © 2012 John Wiley & Sons, Ltd. Xiaohong Li 0001, Zhiyong Feng 0002, Guangquan Xu |
Secur. Commun. Networks | 4 |
| 2013 | On the security and improvement of a two-factor user authentication scheme in wireless sensor networks
Da-Zhi Sun, Jianxin Li 0002, Zhiyong Feng 0002, Zhenfu Cao, Guangquan Xu |
Pers. Ubiquitous Comput. | 5 |
| 2013 | An algorithm on fairness verification of mobile sink routing in wireless sensor network
Guangquan Xu, Weisheng Li 0001, Yingyuan Xiao, Honghao Gao, Xiaohong Li 0001, Zhiyong Feng 0002, Jia Mei |
Pers. Ubiquitous Comput. | 1 |
| 2009 | TSM-Trust: A Time-Cognition Based Computational Model for Trust Dynamics
Guangquan Xu, Zhiyong Feng 0002, Xiaohong Li 0001, Hutong Wu, Yongxin Yu, Shizhan Chen, Guozheng Rao |
ICICS | 1 |