Wenchao Huang 0001

dblp:47/7564-1 · DBLP profile ↗
← Back
35ranked-venue papers
5as first author
10since 2021 · last 2026
0000-0002-2043-2439ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 14 · 1 first-author · 7 since 2021Computer networks · 9 · 3 first-authorArtificial intelligence and machine learning · 4Databases, data management, data science and information retrieval · 3Software engineering, systems software and programming languages · 2 · 2 since 2021Theory of computation · 2Systems, architecture and hardware · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 MalFlows: Context-Aware Fusion of Heterogeneous Flow Semantics for Android Malware Detection
Zhaoyi Meng, Fenglei Xu, Wenxiang Zhao, Wansen Wang 0001, Wenchao Huang 0001, Jie Cui 0004, Hong Zhong 0001, Yan Xiong 0001
IEEE Trans. Dependable Secur. Comput.5
2026 JANUS: A Difference-Oriented Analyzer for Financial Centralized Risks in Smart Contracts
abstract
Some smart contracts violate decentralization principles by defining privileged accounts that manage other users' assets without permission, introducing centralized risks that have caused financial losses. Existing methods, however, face challenges in accurately detecting diverse centralized risks due to their dependence on predefined behavior patterns. In this paper, we propose JANUS, an automated analyzer for Solidity smart contracts that detects financial centralized risks independently of their specific behaviors. JANUS identifies differences between states reached by privileged and ordinary accounts, and analyzes whether these differences are finance-related. Focusing on the impact of risks rather than behaviors, JANUS achieves improved accuracy compared to existing tools and can uncover centralized risks with unknown patterns. To evaluate JANUS's performance, we compare it with other tools using a dataset of 540 contracts. Our evaluation demonstrates that JANUS outperforms representative tools in terms of detection accuracy for financial centralized risks. Additionally, we evaluate JANUS on a real-world dataset of 33,151 contracts, successfully identifying two types of risks that other tools fail to detect. We also prove that the state traversal method and variable summaries, which are used in JANUS to reduce the number of states to be compared, do not introduce false alarms or omissions in detection.
Wansen Wang 0001, Renjie Ji, Wenchao Huang 0001, Zhaoyi Meng, Jie Cui 0004, Hong Zhong 0001, Yan Xiong 0001
IEEE Trans. Dependable Secur. Comput.4
2026 WACANA: A Concolic Analyzer for Detecting On-chain Data Vulnerabilities in WASM Smart Contracts
abstract
WebAssembly (WASM) has emerged as a crucial technology in smart contract development for several blockchain platforms. Unfortunately, since their introduction, WASM smart contracts have been subject to several security incidents caused by contract vulnerabilities, resulting in substantial economic losses. However, existing tools for detecting WASM contract vulnerabilities have accuracy limitations, one of the main reasons being the coarse-grained emulation of the on-chain data APIs. In this article, we introduce WACANA, an analyzer for WASM contracts that accurately detects vulnerabilities through fine-grained emulation of on-chain data APIs. WACANA precisely simulates both the structure of on-chain data tables and their corresponding API functions, and integrates concrete and symbolic execution within a coverage-guided loop to balance accuracy and efficiency. Evaluations on a vulnerability dataset of 2,012 contracts show WACANA outperforming state-of-the-art tools in accuracy. Further validation on 5,602 real-world contracts confirms WACANA’s practical effectiveness.
Wansen Wang 0001, Caichang Tu, Zhaoyi Meng, Wenchao Huang 0001, Yan Xiong 0001
ACM Trans. Softw. Eng. Methodol.4
2025 Place Protections at the Right Place: Targeted Hardening for Cryptographic Code against Spectre v1
Wenchao Huang 0001, Yan Xiong 0001
USENIX Security Symposium2
2025 Detecting Android Malware by Visualizing App Behaviors From Multiple Complementary Views
abstract
Deep learning has emerged as a promising technology for achieving Android malware detection. To further unleash its detection potentials, software visualization can be integrated for analyzing the details of app behaviors clearly. However, facing increasingly sophisticated malware, existing visualization-based methods, analyzing from one or randomly-selected few views, can only detect limited attack types. We propose and implement LensDroid, a novel technique that detects Android malware by visualizing app behaviors from multiple complementary views. Our goal is to harness the power of combining deep learning and software visualization to automatically capture and aggregate high-level features that are not inherently linked, thereby revealing hidden maliciousness of Android app behaviors. To thoroughly comprehend the details of apps, we visualize app behaviors from three related but distinct views of behavioral sensitivities, operational contexts and supported environments. We then extract high-order semantics based on the views accordingly. To exploit semantic complementarity of the views, we design a deep neural network based model for fusing the visualized features from local to global based on their contributions to downstream tasks. A comprehensive comparison with six baseline techniques is performed on datasets of more than 51K apps in three real-world typical scenarios, including overall threats, app evolution and zero-day malware. The experimental results show that the overall effectiveness of LensDroid is better than the baseline techniques. We also validate the complementarity of the views and demonstrate that the multi-view fusion in LensDroid enhances Android malware detection.
Zhaoyi Meng, Jiale Zhang 0002, Wansen Wang 0001, Wenchao Huang 0001, Jie Cui 0004, Hong Zhong 0001, Yan Xiong 0001
IEEE Trans. Inf. Forensics Secur.5
2024 Advancing the Automation Capability of Verifying Security Protocols
abstract
Current formal approaches have been successfully used to find design flaws in many security protocols. However, it is still challenging to automatically analyze protocols due to their large or infinite state spaces. In this paper, we propose SmartVerif, a novel and general framework that pushes the limit of automation capability of Tamarin, a state-of-the-art protocol verifier. The primary technical contribution is thedynamicstrategy inside SmartVerif, which can be used to smartly search proof trees. Different from the existing static strategies, our dynamic strategy can automatically optimize itself according to the security protocols without any human intervention. We implement the strategy by modifying Tamarin and introducing a reinforcement learning algorithm to avoid non-terminating paths in the proof tree. Besides, to improve SmartVerif, we add multiple extracted information for training the reinforcement learning network and design a submodule of Non-termination Estimation to collect training data precisely and rapidly. Experimental results show that SmartVerif can automatically verify all security protocols studied in this paper. The case study validates the efficiency of our dynamic strategy. The experimental results also demonstrate the effectiveness of our extracted information, and the accuracy of the submodule of Non-termination Estimation.
Wansen Wang 0001, Wenchao Huang 0001, Zhaoyi Meng, Yan Xiong 0001
IEEE Trans. Dependable Secur. Comput.2
2023 Automated Inference on Financial Security of Ethereum Smart Contracts
Wansen Wang 0001, Wenchao Huang 0001, Zhaoyi Meng, Yan Xiong 0001, Fuyou Miao 0001, Xianjin Fang, Caichang Tu, Renjie Ji
USENIX Security Symposium2
2021 Static Type Inference for Foreign Functions of Python
abstract
Static type inference is an effective way to maintain the safety of programs written in a dynamically typed language. However, foreign functions implemented in another programming language are often outside the inference range. Python, a popular dynamically typed language, has a lot of widely used packages which follow the multilingual structure with C/C++ extension modules. Existing deterministic Python static type inference tools which are not based on type annotations can do nothing about these foreign functions. In this paper, we propose a novel method to infer the type signature of foreign functions by analyzing implicit information in the layer of foreign function interface. We design a static type inference system, its evaluation on CPython, NumPy and Pillow shows that our method soundly infers the number and type of arguments for most foreign functions. Our results can further work as a complement to the state-of-the-art Python static type inference tool and enable it to analyze programs with foreign function calls. We catch 48 bugs of mismatch between foreign function declaration and its implementation, which make a parameter-free foreign function take argument of any type. 8 of the bugs we reported have been confirmed and fixed by communities.
Mingzhe Hu, Yu Zhang 0086, Wenchao Huang 0001, Yan Xiong 0001
ISSRE3
2021 A proactive secret sharing scheme based on Chinese remainder theorem
Keju Meng, Fuyou Miao 0001, Wenchao Huang 0001, Yan Xiong 0001, Chin-Chen Chang 0001
Frontiers Comput. Sci.4
2021 AppAngio: Revealing Contextual Information of Android App Behaviors by API-Level Audit Logs
abstract
Android users are now suffering severe threats from unwanted behaviors of various apps. The analysis of apps' audit logs is one of the essential methods for the security analysts of various companies to unveil the underlying maliciousness within apps. We propose and implement AppAngio, a novel system that reveals contextual information in Android app behaviors by API-level audit logs. Our goal is to help security analysts understand how the target apps worked and facilitate the identification of the maliciousness within apps. The key module of AppAngio is identifying the path matched with the logs on the app's control-flow graphs (CFGs). The challenge, however, is that the limited-quantity logs may incur high computational complexity in the log matching, where there are a large number of candidates caused by the coupling relation of successive logs. To address the challenge, we propose a divide and conquer strategy that precisely positions the nodes matched with log records on the corresponding CFGs and connects the nodes with as few backtracks as possible. Our experiments show that AppAngio reveals contextual information of behaviors in real-world apps. Moreover, the revealed results assist the analysts in identifying the maliciousness of app behaviors and complement existing analysis schemes. Meanwhile, AppAngio incurs negligible performance overhead on the real device in the experiments.
Zhaoyi Meng, Yan Xiong 0001, Wenchao Huang 0001, Fuyou Miao 0001, Jianmeng Huang
IEEE Trans. Inf. Forensics Secur.3
2020 SmartVerif: Push the Limit of Automation Capability of Verifying Security Protocols by Dynamic Strategies
Yan Xiong 0001, Wenchao Huang 0001, Fuyou Miao 0001, Wansen Wang 0001, Hengyi Ouyang
USENIX Security Symposium3
2020 Threshold changeable secret sharing with secure secret reconstruction
Keju Meng, Fuyou Miao 0001, Wenchao Huang 0001, Yan Xiong 0001
Inf. Process. Lett.3
2020 Incremental learning imbalanced data streams with concept drift: The dynamic updated ensemble algorithm
Wenchao Huang 0001, Yan Xiong 0001, Siqi Ren, Tuanfei Zhu
Knowl. Based Syst.2
2020 Limiting Privacy Breaches in Average-Distance Query
abstract
Querying average distances is useful for real-world applications such as business decision and medical diagnosis, as it can help a decision maker to better understand the users’ data in a database. However, privacy has been an increasing concern. People are now suffering serious privacy leakage from various kinds of sources, especially service providers who provide insufficient protection on user’s private data. In this paper, we discover a new type of attack in an average-distance query (AVGD query) with noisy results. The attack is general that it can be used to reveal private data of different dimensions. We theoretically analyze how different factors affect the accuracy of the attack and propose the privacy-preserving mechanism based on the analysis. We experiment on two real-life datasets to show the feasibility and severity of the attack. The results show that the severity of the attack is mainly influenced by the factors including the noise magnitude, the number of queries, and the number of users in each query. Also, we validate the correctness of our theoretical analysis by comparing with the experimental results and confirm the effectiveness of the privacy-preserving mechanism.
Huihua Xia, Yan Xiong 0001, Wenchao Huang 0001, Zhaoyi Meng, Fuyou Miao 0001
Secur. Commun. Networks3
2019 Tightly coupled multi-group threshold secret sharing based on Chinese Remainder Theorem
Keju Meng, Fuyou Miao 0001, Wenchao Huang 0001, Yan Xiong 0001
Discret. Appl. Math.3
2019 AppScalpel: Combining static analysis and outlier detection to identify and prune undesirable usage of sensitive data in Android applications
Zhaoyi Meng, Yan Xiong 0001, Wenchao Huang 0001, Hongbing Yan
Neurocomputing3
2019 AccountTrade: Accountability Against Dishonest Big Data Buyers and Sellers
abstract
In this paper, a set of accountable protocols denoted as AccountTrade is proposed for big data trading among dishonest consumers. For achieving a secure big data trading environment, AccountTrade achieves book-keeping ability and accountability against dishonest consumers throughout the trading (i.e., buying and selling) of datasets. We investigate the consumers' responsibilities in the dataset trading, then we design AccountTrade to achieve accountability against dishonest consumers that are likely to deviate from the responsibilities. Specifically, a uniqueness index is defined and proposed, which is a new rigorous measurement of the data uniqueness for this purpose. Furthermore, several accountable trading protocols are presented to enable data brokers to blame the misbehaving entities when misbehavior is detected. The accountability of AccountTrade is formally defined, proved, and evaluated by an automatic verification tool as well as extensive simulation with real-world datasets. Our evaluation shows that AccountTrade incurs at most 10-kB storage overhead per file, and it is capable of 8-1000 concurrent data upload requests per server.
Taeho Jung, Xiang-Yang Li 0001, Wenchao Huang 0001, Zhongying Qiao, Jianwei Qian, Junze Han, Jiahui Hou
IEEE Trans. Inf. Forensics Secur.3
2018 Constructing Ideal Secret Sharing Schemes Based on Chinese Remainder Theorem
Fuyou Miao 0001, Wenchao Huang 0001, Keju Meng, Yan Xiong 0001, Xingfu Wang
ASIACRYPT (3)3
2018 AppDNA: App Behavior Profiling via Graph-based Deep Learning
abstract
Better understanding of mobile applications' behaviors would lead to better malware detection/classification and better app recommendation for users. In this work, we design a framework AppDNA to automatically generate a compact representation for each app to comprehensively profile its behaviors. The behavior difference between two apps can be measured by the distance between their representations. As a result, the versatile representation can be generated once for each app, and then be used for a wide variety of objectives, including malware detection, app categorizing, plagiarism detection, etc. Based on a systematic and deep understanding of an app's behavior, we propose to perform a function-call-graph-based app profiling. We carefully design a graph-encoding method to convert a typically extremely large call-graph to a 64-dimension fix-size vector to achieve robust app profiling. Our extensive evaluations based on 86,332 benign and malicious apps demonstrate that our system performs app profiling (thus malware detection, classification, and app recommendation) to a high accuracy with extremely low computation cost: it classifies 4024 (benign/malware) apps using around 5.06 second with accuracy about 93.07%; it classifies 570 malware's family (total 21 families) using around 0.83 second with accuracy 82.3%; it classifies 9,730 apps' functionality with accuracy 33.3% for a total of 7 categories and accuracy of 88.1 % for 2 categories.
Shuangshuang Xue, Lan Zhang 0002, Anran Li 0001, Xiang-Yang Li 0001, Chaoyi Ruan, Wenchao Huang 0001
INFOCOM6
2017 AccountTrade: Accountable protocols for big data trading against dishonest consumers
abstract
We propose AccountTrade, a set of accountable protocols, for big data trading among dishonest consumers. To secure the big data trading environment, our protocols achieve book-keeping ability and accountability against dishonest consumers who may misbehave throughout the dataset transactions. Specifically, we study the responsibilities of the consumers in the dataset trading and design AccountTrade to achieve accountability against the dishonest consumers who may try to deviate from their responsibilities. Specifically, we propose uniqueness index, a new rigorous measurement of the data uniqueness, as well as several accountable trading protocols to enable data brokers to blame the dishonest consumer when misbehavior is detected. We formally define, prove, and evaluate the accountability of our protocols by an automatic verification tool as well as extensive evaluation in real-world datasets. Our evaluation shows that AccountTrade incurs negligible constant storage overhead per file (<;10KB), and it is able to handle 8-1000 concurrent data uploading per server depending on the data types.
Taeho Jung, Xiang-Yang Li 0001, Wenchao Huang 0001, Jianwei Qian, Junze Han, Jiahui Hou
INFOCOM3
2017 Stride-in-the-Loop Relative Positioning Between Users and Dummy Acoustic Speakers
abstract
We propose and implement a novel positioning system, WalkieLokie, which directly calculates the relative position from a smart device to a target. The requirement of the target is simple: it is attached with a “dummy” acoustic speaker, which does not have any other rich capabilities, such as audio recording, communication, or computation. Hence, the proliferation of smart devices, together with the cheap accessory (e.g., dummy speaker) embedded in daily used items (e.g., smart clothes), paves the way for WalkieLokie applications. WalkieLokie leverages the walking motion for locating an acoustic speaker. The key insight is that the distance between the user and the speaker varies in real time when the user walks, and the pattern of the variance implies the relative position. We design a novel algorithm to estimate the position and signal processing methods to support accurate positioning. The experiment results show that the mean errors of ranging and direction estimation are 0.63 m and 2.46°, respectively. Extensive experiments conducted in noisy environments validate the robustness of WalkieLokie.
Wenchao Huang 0001, Xiang-Yang Li 0001, Yan Xiong 0001, Panlong Yang, Yiqing Hu, Xufei Mao, Fuyou Miao 0001, Baohua Zhao, Ju-Min Zhao
IEEE J. Sel. Areas Commun.1
2016 WalkieLokie: sensing relative positions of surrounding presenters by acoustic signals
abstract
In this paper, we propose and implement WalkieLokie, a novel acoustic-based relative positioning system. WalkieLokie facilitates a multitude of Augmented Reality (AR) applications: users with smart devices can passively acquire surrounding information in real time, similar to the commercial AR system Wikitude; the surrounding presenters, who want to share information or introduce themselves, can actively launch the function on demand. The key rational of WalkieLokie is that a user can perceive a series of spatial-related acoustic signals emitted from a presenter, which depicts the relation position between the user and the presenter. The proliferation of smart devices, together with the cheap accessory (e.g., dummy speaker) embedded in daily used items (e.g., smart clothes), paves the way for WalkieLokie applications. We design a novel algorithm to estimate the position and signal processing methods to support accurate positioning. The experiment results show that the mean error of ranging and direction estimation is 0.63m and 2.46 degrees respectively. Extensive experiments conducted in noisy environments validate the robustness of WalkieLokie.
Wenchao Huang 0001, Xiang-Yang Li 0001, Yan Xiong 0001, Panlong Yang, Yiqing Hu, Xufei Mao, Fuyou Miao 0001, Baohua Zhao, Ju-Min Zhao
UbiComp1
2015 Fast Similarity Search of Multi-Dimensional Time Series via Segment Rotation
Xudong Gong, Yan Xiong 0001, Wenchao Huang 0001, Lei Chen 0002, Qiwei Lu, Yiqing Hu
DASFAA (1)3
2015 Lightitude: Indoor Positioning Using Ubiquitous Visible Lights and COTS Devices
abstract
In this paper, we propose a novel indoor localization scheme, Lightitude, by exploiting ubiquitous visible lights, which are necessarily and densely deployed in almost all indoor environments. Different from existing positioning systems that exploit special LEDs, ubiquitous visible lights lack fingerprints that can uniquely identify the light source, which results in an ambiguity problem that an RLS may correspond to multiple candidate positions. Moreover, received light strength (RLS) is not only determined by device's position, but also seriously affected by its orientation, which causes great complexity in site-survey. To address these challenges, we first propose and validate a realistic light strength model to avoid the expensive site-survey, then harness user's mobility to generate spatial-related RLS to tackle single RLS's position-ambiguity problem. Experiment results show that Lightitude achieves mean accuracy 1.93m and 2.24m in office (720m2) and library scenario (960m2) respectively.
Yiqing Hu, Yan Xiong 0001, Wenchao Huang 0001, Xiang-Yang Li 0001, Xufei Mao, Panlong Yang, Caimei Wang
ICDCS3
2015 Magemite: Character inputting system based on magnetic sensor
abstract
We propose Magemite, a fine-grained input system that exploits the around device space (ADS) as an expansion of the limited input area. The key insight underlying Magemite is, magnetic sensor integrated in smart devices can sense nearby magnetic field strength. Using a permanent magnet, users could “write” in ADS to communicate with matched devices. Different from previous magnetic-sensing schemes that recognize only coarse-grained gestures, Magemite can recognize user's fine-grained input like characters. However, individual's diverse writing patterns affect the recognition accuracy. To address this challenge, we preprocess the input trajectories and abstract different features of trajectories to uniquely identify user's input, then use these feature vectors to train several pattern recognition models for character recognition. We evaluate Magemite in various scenarios, and experimental results show Magemite can achieve average recognition accuracy over 85%.
Yuyang Ke, Yan Xiong 0001, Yiqing Hu, Xudong Gong, Wenchao Huang 0001
WOWMOM5
2015 Swadloon: Direction Finding and Indoor Localization Using Acoustic Signal by Shaking Smartphones
abstract
We propose an accurate acoustic direction finding scheme, Swadloon, according to the arbitrary pattern of phone shaking in a rough horizontal plane. Swadloon leverages sensors of the smartphone without the requirement of any specialized devices. Our Swadloon design exploits a key observation: the relative displacement and velocity of the phone-shaking movement corresponds to the subtle phase and frequency shift of the Doppler effects experienced in the received acoustic signal by the phone. Swadloon tracks the displacement of smartphone relative to the acoustic direction with the resolution less than 1 millimeter. The direction is then obtained by combining the velocity from the displacement with the one from the inertial sensors. Major challenges in implementing Swadloon are to measure the displacement precisely and to estimate the shaking velocity accurately when the speed of phone-shaking is low and changes arbitrarily. We propose rigorous methods to address these challenges, and apply Swadloon to several case studies: Phone-to-Phone direction finding, indoor localization and tracking. Our extensive experiments show that the mean error of direction finding is around 2.1 degree within the range of 32 m. For indoor localization, the 90-percentile errors are under 0.92 m. For real-time tracking, the errors are within 0.4 m for walks of 51 m.
Wenchao Huang 0001, Yan Xiong 0001, Xiang-Yang Li 0001, Hao Lin 0005, Xufei Mao, Panlong Yang, Yunhao Liu 0001, Xingfu Wang
IEEE Trans. Mob. Comput.1
2014 Shake and walk: Acoustic direction finding and fine-grained indoor localization using smartphones
abstract
We propose an accurate acoustic direction finding scheme, Swadloon, according to the arbitrary pattern of phone shaking in rough horizontal plane. Swadloon tracks the displacement of smartphone relative to the acoustic direction with the resolution less than 1 millimeter. The direction is then obtained by combining the velocity from the displacement with the one from the inertial sensors. Major challenges in implementing Swadloon are to measure the displacement precisely and to estimate the shaking velocity accurately when the speed of phone-shaking is low and changes arbitrarily. We propose rigorous methods to address these challenges, and apply Swadloon to several case studies: Phone-to-Phone direction finding, indoor localization and tracking. Our extensive experiments show that the mean error of direction finding is around 2.1° within the range of 32 m. For indoor localization, the 90-percentile errors are under 0.92 m. For real-time tracking, the errors are within 0.4 m for walks of 51 m.
Wenchao Huang 0001, Yan Xiong 0001, Xiang-Yang Li 0001, Hao Lin 0005, Xufei Mao, Panlong Yang, Yunhao Liu 0001
INFOCOM1
2014 It starts with iGaze: visual attention driven networking with smart glasses
abstract
In this work, we explore a new networking mechanism with smart glasses, through which users can express their interest and connect to a target simply by a gaze. Doing this, we attempt to let wearable devices understand human attention and intention, and pair devices carried by users according to such attention and intention. To achieve this ambitious goal, we propose a proof-of-concept system iGaze, a visual attention driven networking suite: an iGaze glass (hardware), and a networking protocol VAN (software). Our glass, iGaze glass, is a low-cost head-mounted glass with a camera, orientation sensors, microphone and speakers, which are embedded with our software for visual attention capture and networking. A visual attention driven networking protocol (VAN) is carefully designed and implemented. In VAN, we design an energy efficient and highly accurate visual attention determination scheme using single camera to capture user's communication interest and a double-matching scheme based on visual direction detection and Doppler effect of acoustic signal to lock the target devices. Using our system, we conduct a series of trials for various application scenarios to demonstrate the effectiveness of our system.
Lan Zhang 0002, Xiang-Yang Li 0001, Wenchao Huang 0001, Kebin Liu 0001, Shuwei Zong, Xuesi Jian, Puchun Feng, Taeho Jung, Yunhao Liu 0001
MobiCom3
2014 Demo: visual attention driven networking with smart glasses
abstract
In this demo, we propose a proof-of-concept networking system for smart glasses, through which users can express their interest and connect to a target simply by a gaze. Our system iGaze is a visual attention driven networking suite: an iGaze glass (hardware) and a networking protocol VAN (software). Our glass is a low-cost head-mounted glass with a camera, orientation sensors, microphone and speakers, which are embedded with our software for visual attention capture and networking. A visual attention driven networking protocol (VAN) is carefully designed and implemented. In VAN, we design an energy efficient and highly accurate visual attention determination scheme using single camera to capture user's communication interest and a double-matching scheme based on visual direction detection and Doppler effect of acoustic signal to lock the target devices. iGaze has separated and modularized hardware and software design. It can run on top of existing networking protocols, e.g., Wi-Fi.
Lan Zhang 0002, Xiang-Yang Li 0001, Wenchao Huang 0001, Kebin Liu 0001, Shuwei Zong, Xuesi Jian, Puchun Feng, Taeho Jung, Yunhao Liu 0001
MobiCom3
2014 Sparsest Random Scheduling for Compressive Data Gathering in Wireless Sensor Networks
abstract
Compressive sensing (CS)-based in-network data processing is a promising approach to reduce packet transmission in wireless sensor networks. Existing CS-based data gathering methods require a large number of sensors involved in each CS measurement gathering, leading to the relatively high data transmission cost. In this paper, we propose a sparsest random scheduling for compressive data gathering scheme, which decreases each measurement transmission cost from O(N) to O(log(N)) without increasing the number of CS measurements as well. In our scheme, we present a sparsest measurement matrix, where each row has only one nonzero entry. To satisfy the restricted isometric property, we propose a design method for representation basis, which is properly generated according to the sparsest measurement matrix and sensory data. With extensive experiments over real sensory data of CitySee, we demonstrate that our scheme can recover the real sensory data accurately. Surprisingly, our scheme outperforms the dense measurement matrix with a discrete cosine transformation basis over 5 dB on data recovery quality. Simulation results also show that our scheme reduces almost 10 × energy consumption compared with the dense measurement matrix for CS-based data gathering.
Xuangou Wu, Yan Xiong 0001, Panlong Yang, Shouhong Wan, Wenchao Huang 0001
IEEE Trans. Wirel. Commun.5
2013 Integrating Social Information into Collaborative Filtering for Celebrities Recommendation
Qingwen Liu 0002, Yan Xiong 0001, Wenchao Huang 0001
ACIIDS (2)3
2013 Fine-Grained Refinement on TPM-Based Protocol Applications
abstract
Trusted Platform Module (TPM) is a coprocessor for detecting platform integrity and attesting the integrity to the remote entity. There are two obstacles in the application of TPM: minimizing trusted computing base (TCB) for reducing risk of flaws in TCB, for which a number of convincing solutions have been developed; formal guarantees on each level of TCB, where the formal methods on analyzing the application level have not been well addressed. To the best of our knowledge, there is no general formal framework for developing the TPM-based protocol applications, which not only guarantees the security but also makes it easier for design. In this paper, we make fine-grained refinement on TPM-based security protocols to illustrate our formal solution on the application level by using the Event-B language. First, we modify the classical Dolev-Yao attacker model, which assumes normal entity's compliance with the protocol even without TPM's protection. Thus, the classical security protocols are vulnerable in this modified attacker model. Second, we make stepwise refinement of the security protocol by refining the protocol events and adding security constraints. From the fifth refinement, we make a case study to illustrate the entire refinement and further formally prove the key agreement protocol from DAAODV, the TPM-based routing protocol, under the extended Dolev-Yao attacker model. The refinement provides another way of formal modeling the TPM-based security protocols and a more fine-grained model to satisfy with the rigorous security requirement of applying TPM. Finally, we prove all the proof obligations generated by Rodin, an Eclipse-based IDE for Event-B, to ensure the soundness of our proposal.
Wenchao Huang 0001, Yan Xiong 0001, Xingfu Wang, Fuyou Miao 0001, Chengyi Wu, Xudong Gong, Qiwei Lu
IEEE Trans. Inf. Forensics Secur.1
2012 Replicator Dynamic Inspired Differential Evolution Algorithm for Global Optimization
Shichen Liu, Yan Xiong 0001, Qiwei Lu, Wenchao Huang 0001
IJCCI4
2012 Secure Collaborative Outsourced Data Mining with Multi-owner in Cloud Computing
abstract
Data mining is an important technology for the information society. Due to the limited computation resources of data owners and the prevalence of cloud computing, outsourced data mining is becoming more and more attractive. The privacy and security issues are becoming outstanding recently. Though the existing model of cloud computing consists of multiple data owners, there is little consideration for the collaboration between them. But such collaboration is necessary with the trend of data partition among different entities nowadays. Besides, most of the existing work are based on the semi-honest cloud assumption and can not deal with the malicious cloud situation well. In this paper, we explore the secure and practical outsourced collaborative data mining scheme in cloud computing scenarios. We design a simple framework for it and propose several enhanced frameworks and detailed schemes in an incremental way with stronger security considerations. The final framework utilizes trusted computing technology to design the scheme under the malicious cloud assumption. Finally, we give a summary of security and efficiency analysis about them. As a case of study, we prove the correctness of the frameworks with three classical methods KNN, K-means and SVM respectively in such outsourced collaborative computing scenario.
Qiwei Lu, Yan Xiong 0001, Xudong Gong, Wenchao Huang 0001
TrustCom4
2012 A Distributed ECC-DSS Authentication Scheme Based on CRT-VSS and Trusted Computing in MANET
abstract
With the rapid development of MANET, the secure and practical authentication problem in it increasingly becomes outstanding. The existing work study the problem from two aspects, i.e. secure key division/distributed storage and secure distributed authentication. But existing cheating problems and fault attack possibility will break the security. Besides, efficiency performance of such schemes is not good enough due to the exponential arithmetic with Shamir's scheme. Due to these problems above, we explore the property of verifiable secret sharing(VSS) schemes with Chinese Remainder Theorem(CRT). Then a secret key distributed storage scheme based on CRT-VSS and trusted computing is proposed for MANET. We utilize trusted computing technology to solve two existing cheating problems in secret sharing area before. After that we do some analysis of the homomorphism property with CRT-VSS scheme. Compared with the secure shares-product sharing scheme based on Shamir's scheme, we design the corresponding scheme base on CRT-VSS scheme with better concision and equal security later. On such basis, a distributed Elliptic Curve-Digital Signature Standard signature (ECC-DSS) authentication scheme based on CRT-VSS scheme and trusted computing is proposed. The choice of the trusted authentication node can eliminates the possibility of traditional DoS and fault attack. At last, we do some security analysis towards our schemes proposed above.
Qiwei Lu, Yan Xiong 0001, Wenchao Huang 0001, Xudong Gong, Fuyou Miao 0001
TrustCom3