EDBT 2026 Demo / reviewers in the wild / expert
Yuan Zhang 0004
dblp:48/2168-4
· DBLP profile ↗
49ranked-venue papers
13as first author
22since 2021 · last 2026
0000-0001-9682-5231ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 6 first-author · 12 since 2021Computer networks · 16 · 4 first-author · 5 since 2021Artificial intelligence and machine learning · 3 · 2 first-authorSystems, architecture and hardware · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Reliable Interpretations of Deep Learning-Based Malware Detectors via Deep Q-NetworksabstractDeep learning has become widely used in Android malware detection, but its black-box nature raises trust concerns, limiting its use in critical security areas. To address this, various interpretation methods have been proposed. Unfortunately, these solutions often suffer from inconsistent results and poor adaptability to model updates. In this work, we propose XDQNMal, a Deep Q-Networks (DQN)-based global interpretation framework designed to uncover the critical features that drive decisions in deep learning-based malware detectors. To enhance the reliability of interpretation, XDQNMal captures API call frequency features derived from the runtime behavior of each application (App). Then, it unites a DQN model with the TabPFN detection model to work collaboratively, using variations in detection results as reward signals. These signals guide the DQN model to gradually identify the most impactful features as interpretations for the detection model’s decisions. Our experimental evaluation on real-world datasets demonstrates that the proposed XDQNMal framework generates reliable interpretation for deep learning-based malware detection models. For instance, suppressing the critical features identified by XDQNMal leads to an average decrease of 20.30% in the probability that the malicious sample is predicted as malicious, highlighting the pivotal role these features play in the model’s decision-making. Huijuan Zhu 0001, Chenhao Zheng, Zhongyuan Liu, Yuan Zhang 0004 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2025 | Efficient and Privacy-Preserving Collaborative Driving for Accurate Vehicle PositioningabstractCollaborative driving has emerged as a promising approach to improve vehicle positioning accuracy. However, existing collaborative driving systems often face substantial privacy leakage issues. In this paper, we propose EPPCoDrive, a novel, efficient, and privacy-preserving collaborative driving protocol tailored for real-world vehicular networks. Specifically, EPPCoDrive leverages lightweight cryptographic mechanisms to protect vehicle identifiers and locations against potential adversaries. Experimental results show that our system preserves a positioning accuracy comparable to traditional, non-privacy solutions, while introducing minimal computational overhead. ZhiQiang Ru, Siqin Tan, Yuan Zhang 0004, Sheng Zhong 0002 |
GLOBECOM | 5 |
| 2025 | Privacy-Preserving, Secure and Certificate-Based Integrity Auditing for Cloud Storage
Yinxia Sun, Yuan Zhang 0004, Sheng Zhong 0002 |
ICICS (1) | 4 |
| 2025 | RCS: A High-Success-Rate and Privacy-Preserving Payment Channel Network Routing ProtocolabstractPayment channel networks (PCNs) offer a crucial solution to the scalability challenges of blockchain-based transaction systems. However, most existing PCN routing protocols employ a “guess-and-check” approach, which undermines their transaction success rate and efficiency. In this paper, we propose a routing protocol named RCS, based on a novel “Refined Confirm-and-Send” approach. Utilizing PCN topology statistics, RCS performs a refined probing of possible transaction paths and verifies whether a path has sufficient available balance before executing the transaction through it. This method effectively improves the transaction success rate while maintaining restrained overhead. Additionally, to address users' privacy concerns, we design a privacy-preserving version of RCS, named RCS+. RCS+ uses secure comparisons to identify paths with sufficient funds without disclosing channel balances or transaction amounts. Extensive simulations with real-world and synthetic datasets demonstrate that RCS and RCS+ outperform existing state-of-the-art protocols. RCS and RCS+ achieve a$\mathbf{1 0 \%}$higher transaction success rate compared to the Shortest Path approach, which serves as the core of Lightning Network's current routing mechanism. In terms of overhead, RCS maintains the lowest cost among all tested protocols, e.g., only 20 % of the Flash protocol. While RCS+ incurs marginally higher overhead due to its enhanced privacy guarantees, its cost remains just 30 % of Flash's overhead. Furthermore, RCS/RCS+ exhibits robust adaptability to dynamic changes in PCN topologies, ensuring scalability as the network evolves. Chen Tian 0001, Yuan Zhang 0004, Sheng Zhong 0002 |
SRDS | 3 |
| 2025 | Blockchain-Enhanced Data Privacy Preservation and Secure Sharing Scheme for Healthcare IoTabstractData privacy preservation and secure sharing are key technical challenges faced by smart wearable healthcare Internet of Things (IoT) systems. Blockchain technology enables privacy preservation for medical data through encryption. However, conventional data encryption hampers data analysis and sharing, and decrypted data still carries the risk of leakage. Homomorphic encryption is a technique that allows computation directly on encrypted data without decryption, thus reducing the risk of data leakage during sharing. In this article, we propose a blockchain-based privacy preservation and sharing scheme for healthcare IoT data. First, we use an improved homomorphic encryption technique to encrypt and process electronic health records (EHRs), optimizing the modular exponentiation process with a fast exponentiation algorithm, enabling users to efficiently perform data computation and analysis while keeping the data encrypted. Second, we employ symmetric searchable encryption (SSE) to encrypt homomorphic keys and user identity information, and use a Bloom filter as the mapping structure between data keywords and unique identifiers. This approach enhances search efficiency while preserving data privacy, allowing for secure search and analysis on ciphertext. Finally, smart contracts are designed to implement access control during the data-sharing process, increasing the security and transparency of data sharing. Experimental results show that the proposed homomorphic encryption scheme reduces the encryption and decryption time by an average of 34% under different key sizes, while the optimized SSE technique keeps ciphertext retrieval time at a constant level. The proposed scheme provides an effective solution for secure and efficient data analysis and retrieval, ensuring privacy preservation for the secure use and sharing of medical data. Shaopeng Guan, Youliang Cao, Yuan Zhang 0004 |
IEEE Internet Things J. | 3 |
| 2025 | Sectric: Towards Accurate, Privacy-preserving and Efficient Triangle CountingabstractGraph data analysis, particularly local triangle counting, plays a pivotal role in deciphering complex relationships within graph data. This method is invaluable across diverse fields such as social networks, transportation, and cybersecurity. However, this process often involves handling sensitive information, necessitating that the relationship between any two nodes is considered private. Differential privacy (DP) is a formal model to address privacy concerns and can be categorized into two types: the central DP (CDP) model, which achieves better result accuracy, and the local DP (LDP) model, which does not assume a trusted server. To bridge the gap between the two models, we propose Sectric, a server-aided crypto-assisted local triangle counting protocol, in this paper. It can achieve the same result accuracy with the same privacy budget as the CDP model without assuming a trusted server. Sectric also explores a new approach in crypto-assisted graph data analysis algorithms that represents a node's neighbors using a set instead of an adjacency vector, and successfully achieves higher efficiency compared to other crypto-assisted solutions. We also conduct theoretical and empirical evaluations to demonstrate that Sectric achieves the design principles. Minze Xu, Zhentai Xie, Zhibin Wang 0002, Guangzhan Wang, Longbin Lai, Yuan Zhang 0004, Chen Tian 0001, Sheng Zhong 0002 |
Proc. VLDB Endow. | 6 |
| 2025 | OPRE: Towards Better Availability of PCNs Through RecoveringabstractThe Payment Channel Network (PCN) stands out as one of the most promising technologies for scaling blockchain-based cryptocurrencies. However, a noteworthy challenge arises during the utilization of PCNs, where a substantial portion of payment channels gradually becomes exhausted, leading to a reduction in the overall availability of PCNs. This issue is crucial in the context of blockchain off-chain PCNs and warrants a comprehensive investigation. In this paper, we introduce the problem of optimal recover and propose OPtimal REcovering protocols, denoted asOPREandOPRE+, to address this challenge. The protocols target at recovering the optimal number of nearly exhausted channels in the PCN. OPRE provides a basic solution, and OPRE+ is an augmentation which provides a more efficient and effective solution. Furthermore, to address users’ privacy concerns, we propose privacy-preserving versions of the protocols, ensuring that users’ balance on payment channels remains undisclosed during the execution of the protocols. Beyond the theoretical design and analysis, we implement these protocols and conduct experimental evaluations to assess their performance. The results affirm that our protocols exhibit efficiency and effectiveness in significantly improving the availability of PCNs. Minze Xu, Yue Li 0002, Chenglu Shi, Yuan Zhang 0004, Yongchuan Niu, Fengyuan Xu, Sheng Zhong 0002 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Towards Payment Channel Watchtowers With Collateral-Free Security and RobustnessabstractRecently, watchtowers emerge as a critical service within payment channel networks (PCNs). Existing payment channels necessitate that channel owners periodically monitor the blockchain to ensure their fund security, or enlist the watchtower services for this task. Presently, watchtower proposals mandate the implementer to provide collateral as a safeguard against its collusion with potential adversaries. However, this collateral substantially inflates the implementation costs, consequently leading to higher service fees for users. Furthermore, most watchtowers are typically operated by a third-party entity, creating a single point of failure. To ameliorate the status quo, we propose a novel approach where PCN nodes collaboratively implement a watchtower system named “SilenTower.” Our proposal is rooted in the fundamental principles of blockchain systems, emphasizing maintenance by a community with an honest majority. SilenTower’s security no longer relies on collateral but rather on the inherent difficulty of a large proportion of collusion. SilenTower also allows inaccessible participants and thus obtains robustness. Through a rigorous theoretical analysis, we demonstrate that participants’ optimal strategy is to remain accessible and faithfully adhere to the SilenTower protocol. Furthermore, we assess the practical performance of SilenTower through comprehensive benchmarking, and the results reveal that it introduces lightweight overheads. Minze Xu, Yuan Zhang 0004, Sheng Zhong 0002 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Toward Efficient and Secure Collaborative SQL Analyses of Billion-Scale DatasetsabstractDesigning an efficient and secure collaborative SQL analysis system that supports large-scale dataset inputs is a very challenging task. In this paper, we present FedQuery, an MPC-based solution for efficient and secure collaborative analysis that is able to handle billion-scale dataset inputs. FedQuery introduces novel designs in its system architecture, the underlying MPC primitives, and oblivious SQL operators as well as their combinations, significantly reducing communication and computation overhead. Comprehensive experiments on real-world datasets show that FedQuery achieves large performance improvements over state-of-the-art baselines at both the operator and query levels. Additionally, it can handle complex SQL queries on datasets up to ten billion entries in less than 14 hours. Qizhi Zhang 0007, Yuan Zhang 0004, Quanwei Cai 0003, Jue Hong, Sheng Zhong 0002 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Differentially Private K-Means Publishing with Distributed DimensionsabstractIn this paper, we address the critical concerns related to dataset privacy in the context of k-means clustering publishing within a distributed dimension setting. By leveraging differential privacy mechanisms, we propose a novel framework that integrates a differentially private classifier, constructed through voting based on raw clustering results, and an enhanced generative adversarial network (GAN) simulating the classifier’s behavior in inferring class labels for a public dataset. Our approach generates synthetic clustering results that mimic real outcomes in classification tasks, ensuring differential privacy and minimizing noise. Our contributions include a comprehensive exploration of privacy issues, the introduction of a novel privacy-preserving k-means clustering framework, and theoretical analyses demonstrating sensitivity and differential privacy guarantees. Evaluation on the MNIST dataset demonstrates the effectiveness of the framework, achieving 82.22% accuracy with a (10.48, 10−9)-differential-privacy guarantee, compared to 83.45% accuracy without privacy-preserving. Boyu Zhu, Yuan Zhang 0004, Tingting Chen 0001, Sheng Zhong 0002 |
CSCWD | 2 |
| 2024 | GameTE: A Game-Theoretic Distributed Traffic Engineering in Trustless Multi-Domain SDNabstractWith growing network service demands, rational and efficient multi-domain resource allocation is paramount. Research aims to develop intelligent Traffic Engineering (TE) algorithms that can dynamically allocate resources, adapt to changing conditions, and meet user needs. TE algorithms based on Software-Defined Networking (SDN) have proven effective for this goal by leveraging the centralized control plane and programmable data plane of SDN. This enables flexible and dynamic optimization of routing and resource allocation across multiple domains to meet traffic demands. However, domains operated by different service providers may exhibit non-cooperative behavior due to conflicts of interest and competition. Some domains may act selfishly by hiding bandwidth or exaggerating inter-domain requests to reserve more resources for themselves. This complicates TE design as algorithms can no longer assume universal cooperation in multi-domain networks. Game theory provides a framework to model competition between domains through behaviors like request forwarding, dropping and study cooperation strategies. This paper presents GameTE, a game-theoretic distributed TE algorithm for multi-domain SDN environments without trusted relationships between domains. By incorporating incentives and punishments, our algorithm suppresses selfish behaviors and promotes efficient resource utilization. Evaluation results demonstrate that GameTE is effective in curbing deception, enhancing resource sharing between domains, and improving overall network performance compared to baseline schemes. Jingyu Hua, Yuan Zhang 0004, Sheng Zhong 0002 |
ICDCS | 3 |
| 2024 | Unbalanced private set intersection with linear communication complexity
Quanyu Zhao, Bingbing Jiang 0002, Yuan Zhang 0004, Yunlong Mao, Sheng Zhong 0002 |
Sci. China Inf. Sci. | 3 |
| 2024 | Revisiting Privacy-Preserving Min and k-th Min Protocols for Mobile SensingabstractExploiting participants’ data without knowing them is the center topic of secure mobile sensing data aggregation. In this article, we study how to improve existing protocols for computing the minimum or$k$-th minimum of all participants’ data in a privacy-preserving manner. Existing protocols for these two computations require relatively high communication cost or frequent interactions, which leads to unbearable time consumption when the network delay is high. We improve the min computation protocol proposed by Zhang et al. 2017, cutting down on its need for interactions and thus making it perform better in terms of efficiency. We also propose a new protocol as a secure substitute of the Bit-choosing Algorithm designed by Yu et al. 2018. It helps participants generate a secret permutation, which will be further used in the$k$-th min computation protocol to achieve higher accuracy and efficiency. Theoretical analyses are done to help predict and understand our new protocols’ performances, and later evaluations show that both these new protocols perform notably better in comparison to the existing ones. Jiacheng Gao, Yuan Zhang 0004, Sheng Zhong 0002 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Solution Probing Attack Against Coin Mixing Based Privacy-Preserving Crowdsourcing PlatformsabstractConventional crowdsourcing platforms primarily rely on a central server as the broker for information exchange. Although many efforts have been made, centralized platforms are still vulnerable to underlying security issues, such as an untrusted central server and single-point failure. Fortunately, blockchain has emerged as an alternative infrastructure for building crowdsourcing platforms. Many excellent designs of blockchain-based decentralized crowdsourcing (BDCS) solutions have been proposed. Benefiting from blockchain, BDCS can provide fascinating features, like tampering resistance and anonymity. However, a new attack surface appears in BDCS. Recently, a new attack against BDCS named solution probing attack has been identified. The solution-probing adversary can take advantage of the anonymity of BDCS to probe valid solutions using a generative model. Due to the transparency of blockchain transactions, the probing attack is effective even if solutions are encrypted. Nevertheless, we find transaction-mixing techniques effective in defending against probing attacks. In this paper, we introduce the solution probing attack and an improved variant, which can attack coin mixing-based BDCS. We evaluate probing attacks on large-scale crowdsourcing tasks. Experimental results show that the adversary is capable of deceiving BDCS with a limited number of probing, even if the BDCS is protected by solution encryption and coin mixing techniques. Yunlong Mao, Ziqin Dang, Yuan Zhang 0004, Sheng Zhong 0002 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | Toward Universal Detection of Adversarial Examples via Pseudorandom ClassifiersabstractAdversarial examples that can fool neural network classifiers have attracted much attention. Existing approaches to detect adversarial examples leverage a supervised scheme in generating attacks (either targeted or non-targeted) for training the detectors, which means the detectors are geared to the attacks chosen at the training time and could be circumvented if the adversary does not act as expected. In this paper, we borrow ideas from cryptography and present a novel approach called pseudorandom classifier. In a nutshell, a pseudorandom classifier is a classifier equipped with a mapping to encode the category labels into random multi-bit labels, and a keyed pseudorandom injective function to transform the input to the classifier. The multi-bit labels enable attack-independent and probabilistic detection if the input sample is adversarial. The pseudorandom injection makes the existing white-box adversarial example generation methods, largely based on back-propagation, no longer applicable. We empirically evaluate our method on MNIST, CIFAR10, Imagenette, CIFAR100, and GTSRB. The results suggest that its performance against adversarial examples is comparable to the state-of-the-art. Boyu Zhu, Changyu Dong, Yuan Zhang 0004, Yunlong Mao, Sheng Zhong 0002 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | FLSwitch: Towards Secure and Fast Model Aggregation for Federated Deep Learning with a Learning State-Aware Switch
Yunlong Mao, Ziqin Dang, Tianling Zhang, Yuan Zhang 0004, Jingyu Hua, Sheng Zhong 0002 |
ACNS (1) | 5 |
| 2023 | SilenTower: A Robust, Scalable and Secure Watchtower with Silent ExecutorsabstractPayment channels emerge as a promising solution to the scalability issues of blockchain-based digital currency systems, but they implicitly assume that channel owners can periodically monitor the blockchain, which may be impractical for most ordinary users. To address this issue, watchtowers are developed to monitor the blockchain on behalf of its hirers, allowing them to stay offline without security concerns. Despite their usefulness, current watchtower implementations face a security and scalability dilemma. They either require hirers to trust watchtowers, making hirers' funds vulnerable if the watchtower colludes with the counterparty, or require the watchtower to deposit collateral for each hirer, restricting the service scalability due to the watchtower's limited funds. To overcome this dilemma, we propose SilenTower, a mul-tiparty watchtower protocol. It allows a given proportion of collusive protocol participants and provides fund security without collateral. Thus, SilenTower achieves security and scalability simultaneously. Moreover, we propose a quantified definition for watchtower robustness and prove that SilenTower has better robustness than state-of-the-art implementations. We also assess SilenTower's performance through thorough benchmarking and demonstrate that it has lightweight overheads for both partici-pants and hirers. Minze Xu, Yuan Zhang 0004, Sheng Zhong 0002 |
SRDS | 2 |
| 2022 | On Designing Secure Cross-user Redundancy Elimination for WAN OptimizationabstractRedundancy elimination (RE) systems allow network users to remove duplicate parts in their messages by introducing caches at both message senders’ and receivers’ sides. While RE systems have been successfully deployed for handling unencrypted traffic, making them work over encrypted links is still open. A few solutions have been proposed recently, however they either completely violate end-to-end security or focus on single-user setting. In this paper, we present a highly secure RE solution which supports cross-user redundancy eliminations on encrypted traffics. Our solution not only preserves the end-to-end security against outside adversaries, but also protects users’ privacy against semi-honest RE agents. Furthermore, our solution can defend malicious users’ poisoning attack, which is crucial for cross-user RE systems but has never been studied before. In cross-user RE systems, since all users inside a LAN write into a shared, global cache and use it to recover their original messages from deduplicated ones, the poisoning attack is prone to happen, and cause systematic damage to all users even when only one user is malicious and injects poisoned data into the cache. We rigorously prove our solution’s security properties, and demonstrate its promising performance via testing the proof-of-concept implementation with real-world internet traffic data. Yuan Zhang 0004, Minze Xu, Chen Tian 0001, Sheng Zhong 0002 |
INFOCOM | 1 |
| 2022 | Secure deduplication schemes for content delivery in mobile edge computing
Yunlong Mao, Yuan Zhang 0004, Sheng Zhong 0002 |
Comput. Secur. | 3 |
| 2022 | Secure Deep Neural Network Models Publishing Against Membership Inference Attacks Via Training Task ParallelismabstractVast data and computing resources are commonly needed to train deep neural networks, causing an unaffordable price for individual users. Motivated by the increasing demands of deep learning applications, sharing well-trained models becomes popular. The owner of a pre-trained model can share it by publishing the model directly or providing a prediction interface. Either way, individual users can benefit from deep learning without much cost, and computing resources can be saved. However, recent studies of machine learning security have identified severe threats to these model publishing approaches. This paper will focus on the privacy leakage issue of publishing well-trained deep neural network models. To tackle this problem, we propose a series of secure model publishing solutions based on training task parallelism. Specifically, we show how to estimate private model parameters through parallel model training and generate new model parameters in a privacy-preserving manner to replace the original ones for publishing. Based on data parallelism and parameter generating techniques, we design another two solutions concentrating on model quality and parameter privacy, respectively. Through privacy leakage analysis and experimental attack evaluation, we conclude that deep neural network models published with our solutions can provide on-demand model quality guarantees and resist membership inference attacks. Yunlong Mao, Wenbo Hong, Boyu Zhu, Zhifei Zhu, Yuan Zhang 0004, Sheng Zhong 0002 |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2021 | Privacy-Preserving Optimal Recovering for the Nearly Exhausted Payment ChannelsabstractPayment Channel Network (PCN) is one of the most promising technologies for scaling the capacity of blockchain-based cryptocurrencies and improving the quality of blockchain-based services. However, during the use of PCNs, a significant portion of the payment channels gradually become exhausted, which triggers additional consumption of on-chain resources and makes PCNs less useful. This is a fundamental problem for blockchain-based cryptocurrencies, worthy of a thorough investigation.In this paper, we propose OPRE, a protocol for OPtimal off-chain REcovering of payment channels, to solve this problem. It is optimal in that it recovers the maximum number of nearly exhausted channels in the PCN. Furthermore, we consider users’ privacy concerns and design a privacy-preserving version of this protocol, so that users’ balance information does not need to be revealed. This protocol maintains optimality in recovering payment channels while providing cryptographically strong privacy guarantee. In addition to the theoretical design and analysis, we also implement OPRE and experimentally evaluate its performance. The results show that the OPRE protocol is both efficient and effective. Minze Xu, Yuan Zhang 0004, Fengyuan Xu, Sheng Zhong 0002 |
IWQoS | 2 |
| 2021 | Towards Thwarting Template Side-Channel Attacks in Secure Cloud DeduplicationsabstractAs one of a few critical technologies to cloud storage service, deduplication allows cloud servers to save storage space by deleting redundant file copies. However, it often leaks side channel information regarding whether an uploading file gets deduplicated or not. Exploiting this information, adversaries can easily launch a template side-channel attack and severely harm cloud users' privacy. To thwart this kind of attack, we resort to the k-anonymity privacy concept to design secure threshold deduplication protocols. Specifically, we have devised a novel cryptographic primitive called “dispersed convergent encryption” (DCE) scheme, and proposed two different constructions of it. With these DCE schemes, we successfully construct secure threshold deduplication protocols that do not rely on any trusted third party. Our protocols not only support confidentiality protections and ownership verifications, but also enjoy formal security guarantee against template side-channel attacks even when the cloud server could be a “covert adversary” who may violate the predefined threshold and perform deduplication covertly. Experimental evaluations show our protocols enjoy very good performance in practice. Yuan Zhang 0004, Yunlong Mao, Minze Xu, Fengyuan Xu, Sheng Zhong 0002 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | Private Deep Neural Network Models Publishing for Machine Learning as a ServiceabstractMachine learning as a service has emerged recently to relieve tensions between heavy deep learning tasks and increasing application demands. A deep learning service provider could help its clients to benefit from deep learning techniques at an affordable price instead of huge resource consumption. However, the service provider may have serious concerns about model privacy when a deep neural network model is published. Previous model publishing solutions mainly depend on additional artificial noise. By adding elaborated noises to parameters or gradients during the training phase, strong privacy guarantees like differential privacy could be achieved. However, this kind of approach cannot give guarantees on some other aspects, such as the quality of the disturbingly trained model and the convergence of the modified learning algorithm. In this paper, we propose an alternative private deep neural network model publishing solution, which caused no interference in the original training phase. We provide privacy, convergence and quality guarantees for the published model at the same time. Furthermore, our solution can achieve a smaller privacy budget when compared with artificial noise based training solutions proposed in previous works. Specifically, our solution gives an acceptable test accuracy with privacy budget ϵ = 1. Meanwhile, membership inference attack accuracy will be deceased from nearly 90% to around 60% across all classes. Yunlong Mao, Boyu Zhu, Wenbo Hong, Zhifei Zhu, Yuan Zhang 0004, Sheng Zhong 0002 |
IWQoS | 5 |
| 2020 | Blockchain-based privacy-preserving remote data integrity checking scheme for IoT information systems
Quanyu Zhao, Zheli Liu, Thar Baker, Yuan Zhang 0004 |
Inf. Process. Manag. | 5 |
| 2020 | Secure Inter-Domain Forwarding Loop Test in Software Defined NetworksabstractDebugging a traditional network is notoriously difficult due to network devices' heterogeneity and protocols' decentralized nature, but Software-Defined Networking (SDN) is changing this predicament. Recent works have provided very nice approaches for an administrator to perform several fundamental network tests in a single-domain SDN network. However, how to perform these tests securely in multi-domain networks still remains open. In this paper, we study the highly challenging problem of inter-domain forwarding loop test in a SDN environment. We present two novel testing protocols that can be used for inter-domain loop tests. Both protocols are secure in the sense that they protect each domain's private information about its topology and configuration. The first protocol, based on random sampling, is highly efficient with a small error probability diminishing exponentially in the sample size. The second protocol, based on secure set intersection test, guarantees 100 percent accuracy of the result, although not as efficient as the first one. We provide rigorous proofs for the security and accuracy guarantees, and show our protocols have very good efficiency by testing them with real-world network data. Yuan Zhang 0004, Boyu Zhu, Yixin Fang, Suxin Guo, Aidong Zhang 0001, Sheng Zhong 0002 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | Secure TDD MIMO Networks Against Training Sequence Based Eavesdropping AttackabstractMulti-User MIMO (MU-MIMO) has attracted much attention due to its significant advantage of increasing the utilization ratio of wireless channels. However, Frequency-Division Duplex (FDD) systems are vulnerable to eavesdropping, since the explicit CSI feedback can be manipulated. In this paper, we show that Time-Division Duplex (TDD) systems are insecure as well. In particular, we show that it is possible to eavesdrop on other users' downloads by tuning training sequences. In order to defend MU-MIMO against such threats, we propose a secure CSI estimation scheme, which can provide correct estimates of CSI when adversarial users are in presence. We prove that our scheme is secure against training sequence based eavesdropping attack. We have implemented our scheme for TDD MU-MIMO systems and performed a series of experiments. Results demonstrate that our secure CSI estimation scheme is highly effective in protecting TDD MIMO networks against eavesdropping attack. Furthermore, we extend our scheme to support massive MU-MIMO networks, with a carefully redesigned uplink protocol and optimized power allocation to achieve higher spectral efficiency. To be more practical, we also take mismatch channel issue into our consideration. An enhancement scheme is proposed and we show that our scheme with enhancement is secure and correct under mismatch channel. Yunlong Mao, Yuan Zhang 0004, Jingyu Hua, Sheng Zhong 0002 |
IEEE Trans. Mob. Comput. | 3 |
| 2019 | On repeated stackelberg security game with the cooperative human behavior model for wildlife protection
Binru Wang, Yuan Zhang 0004, Zhi-Hua Zhou, Sheng Zhong 0002 |
Appl. Intell. | 2 |
| 2018 | Securely min and k-th min computations with fully homomorphic encryption
Bingbing Jiang 0002, Yuan Zhang 0004 |
Sci. China Inf. Sci. | 2 |
| 2018 | Location privacy in public access points positioning: An optimization and geometry approach
Yunlong Mao, Yuan Zhang 0004, Fengyuan Xu, Sheng Zhong 0002 |
Comput. Secur. | 2 |
| 2017 | Incentive Mechanism Design in Mobile Crowd Sensing Systems with Budget Restriction and Capacity LimitabstractWith the popularization of human-carried devices, it is possible for Mobile Crowd Sensing (MCS) applications to perform large scale sensing with sensors embedded in these devices. Many incentive mechanisms for MCS applications have been proposed due to the importance of attracting more worker to participate. However, these mechanisms failed to consider situations where there are constraints on both crowdsourcer's budget and workers' capacity. In contrast, we design mechanisms which ensure approximately maximized value of services provided by selected workers under both constraints based on reverse auctions. Not only do we study the scenario where every worker is trusted and will not infer others' bids, but we also investigate the scenario where there are some honest-but-curious workers. For the former, we design a truthful, individual rational, and computationally efficient incentive mechanism that achieves nearly optimal benefits. For the latter, we design an approximately truthful, individual rational, computationally efficient, and differentially private incentive mechanism that helps to protect workers' privacy from the infringement of curious workers and achieves nearly optimal benefits. Rigorous theoretical analyses and extensive simulations are given to validate the above properties and evaluate the performance of our incentive mechanisms. Yuan Zhang 0004, Sheng Zhong 0002 |
ICCCN | 2 |
| 2017 | SecHome: A Secure Large-Scale Smart Home System Using Hierarchical Identity Based Encryption
Yazhe Wang, Yuan Zhang 0004 |
ICICS | 3 |
| 2017 | Efficient and Privacy-Preserving Min and kth Min Computations in Mobile Sensing SystemsabstractProtecting the privacy of mobile phone user participants is extremely important for mobile phone sensing applications. In this paper, we study how an aggregator can expeditiously compute the minimum value or the kth minimum value of all users' data without knowing them. We construct two secure protocols using probabilistic coding schemes and a cipher system that allows homomorphic bitwise XOR computations for our problems. Following the standard cryptographic security definition in the semi-honest model, we formally prove our protocols' security. The protocols proposed by us can support time-series data and need not to assume the aggregator is trusted. Moreover, different from existing protocols that are based on secure arithmetic sum computations, our protocols are based on secure bitwise XOR computations, thus are more efficient. Yuan Zhang 0004, Qingjun Chen, Sheng Zhong 0002 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2017 | Towards Privacy-Preserving Aggregation for Collaborative Spectrum SensingabstractCollaborative spectrum sensing has become increasingly popular in cognitive radio networks to enable unlicensed secondary users to coexist with the licensed primary users and share spectrum without interference. Despite its promise in performance enhancement, collaborative sensing is still facing a lot of security challenges. The problem of revealing secondary users' location information through sensing reports has been reported recently. Unlike any existing work, in this paper we not only address the location privacy issue in the collaborative sensing to be against semi-honest adversaries, but also take malicious adversaries into consideration. We propose efficient schemes to protect secondary users' reports from being revealed in the aggregation process at the fusion center. We rigorously prove that our privacy-preserving collaborative sensing schemes are secure against attacks from both the fusion center and secondary users. We also evaluate our schemes extensively and verify its efficiency and feasibility. Yunlong Mao, Tingting Chen 0001, Yuan Zhang 0004, Tiancong Wang, Sheng Zhong 0002 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2017 | Cost-Efficient Indoor White Space Exploration Through Compressive SensingabstractExploring the utilization of white spaces (vacant VHF and UHF TV channels) is a promising way to satisfy the rapidly growing radio frequency (RF) demand. Although a few white space exploration methods have been proposed in the past few years, they mainly focused on outdoor scenarios. In this paper, we propose a novel cost-efficient indoor white space exploration method by exploiting the location dependence and channel dependence of TV spectrum in indoor environments. We first measure the UHF TV channels in a building, and study the spatial and spectral features of indoor white spaces. Then, we design a cost-eFficient Indoor White space EXploration (FIWEX) mechanism based on the extracted features. Furthermore, we build a prototype of FIWEX and extensively evaluate its performance in real-world environments. The evaluation results show that FIWEX can identify 30.0% more indoor white spaces with 51.2% less false alarms compared with the best known existing solution. Fan Wu 0006, Dongxin Liu, Yuan Zhang 0004, Guihai Chen |
IEEE/ACM Trans. Netw. | 4 |
| 2016 | Stemming Downlink Leakage from Training Sequences in Multi-User MIMO NetworksabstractMulti-User MIMO has attracted much attention due to its significant advantage of increasing the utilization ratio of wireless channels. Recently a serious eavesdropping attack, which exploits the CSI feedback of the FDD system, is discovered in MU-MIMO networks. In this paper, we firstly show a similar eavesdropping attack for the TDD system is also possible by proposing a novel, feasible attack approach. Following it, a malicious user can eavesdrop on other users' downloads by transforming training sequences. To prevent this attack, we propose a secure CSI estimation scheme for instantaneous CSI. Furthermore, we extend this scheme to achieve adaptive security when CSI is relatively statistical. We have implemented our scheme for both uplink and downlink of MU-MIMO and performed a series of experiments. Results show that our secure CSI estimation scheme is highly effective in preventing downlink leakage against malicious users. Yunlong Mao, Yuan Zhang 0004, Sheng Zhong 0002 |
CCS | 2 |
| 2016 | Competitive auctions for cost-aware cellular traffic offloading with optimized capacity gainabstractOffloading part of cellular traffic through existing alternative wireless networks, such as femtocells and WiFi networks, is one promising solution to the severe traffic overload faced by cellular network providers (CSPs) nowadays. Most existing cellular offloading auction mechanisms assume the CSP has the knowledge of incoming overloaded traffic demand, and satisfy the demand by offloading. However, in practice, with the explosive growth of mobile device communications, the overloaded traffic demand at CSPs is very likely to pass over the total capability that third-party resource owners can provide. Then it is critical to enable CSPs to optimize the traffic handling capacity gain through offloading with budget constraints. In this paper, we propose two efficient Competitive Auction MEchanisms for mObile offloading, CAMEO-min and CAMEO-ws. Both mechanisms are proven to be non-budget-deficit, individually rational and incentive-compatible, and have guaranteed lower bounds on the ratio of the CSP's gain achieved in them to the maximum gain that the CSP could achieve in any omniscient auction (the auction with an omniscient auctioneer). Our extensive evaluations show that CAMEOs achieve very good performance in terms of the maximization of the CSP's gain especially when the global bidder dominance or the region dominance is big. Yuan Zhang 0004, Tingting Chen 0001, Sheng Zhong 0002 |
INFOCOM | 1 |
| 2016 | Joint Differentially Private Gale-Shapley Mechanisms for Location Privacy Protection in Mobile Traffic Offloading SystemsabstractBeing an important application of spectrum sharing in cellular networks, mobile traffic offloading, which advocates third-party owners of network resource on unlicensed/licensed spectrum to share their spectrum and provide data offloading services, is considered a promising solution to severe spectrum shortage faced by cellular network service providers. In this paper, we consider a general mobile traffic offloading system that adopts the widely used Gale-Shapley algorithm to optimize its mobile phone users (MUs) to offloading stations allocation plan. We notice that without careful protection, such a system could cause serious threat to MUs' location privacy, and thus design effective countermeasures based on the powerful state-of-the-art differential privacy concept. Specifically, we have proposed two joint differentially private Gale-Shapley mechanisms with strong privacy protections for mobile traffic offloading systems. The first mechanism is able to protect each user's location privacy even when all other users collude against this user assuming the system administrator can be trusted. The second mechanism is able to achieve the same privacy guarantee against colluding users, and moreover against an untrusted semi-honest system administrator. We perform extensive experiments to evaluate our mechanisms, and the results show that our mechanisms have good efficiency, accuracy, and privacy protection. Yuan Zhang 0004, Yunlong Mao, Sheng Zhong 0002 |
IEEE J. Sel. Areas Commun. | 1 |
| 2016 | Privacy-Preserving Data Aggregation in Mobile Phone SensingabstractMobile phone sensing provides a promising paradigm for collecting sensing data and has been receiving increasing attention in recent years. Different from most existing works, which protect participants' privacy by hiding the content of their data and allow the aggregator to compute some simple aggregation functions, we propose a new approach to protect participants' privacy by delinking data from its sources. This approach allows the aggregator to get the exact distribution of the data aggregation and, therefore, enables the aggregator to efficiently compute arbitrary/complicated aggregation functions. In particular, we first present an efficient protocol that allows an untrusted data aggregator to periodically collect sensed data from a group of mobile phone users without knowing which data belong to which user. Assume there are n users in the group. Our protocol achieves n-source anonymity in the sense that the aggregator only learns that the source of a piece of data is one of the n users. Then, we consider a practical scenario where users may have different source anonymity requirements and provide a solution based on dividing users into groups. This solution optimizes the efficiency of data aggregation and meets all users' requirements at the same time. Yuan Zhang 0004, Qingjun Chen, Sheng Zhong 0002 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2016 | On Designing Satisfaction-Ratio-Aware Truthful Incentive Mechanisms for k-Anonymity Location PrivacyabstractTo protect individuals' location privacy, an important privacy protection technique that can be used is k -anonymity, which requires at least k users to participate in an anonymity set, so that any user in the set cannot be distinguished from the other k-1 users. However, a significant part of users may not be concerned about their location privacy and therefore may not be interested in participating in the anonymity set. Hence, a prerequisite for achieving k-anonymity location privacy is to stimulate users to participate. In this paper, we revisit the problem of stimulating users that are privacy-indifferent to participate in the anonymity set and providing k-anonymity location privacy for privacy-sensitive users. We first study the case where all privacy-sensitive users have the same requirement of privacy. Then, we extend our study to a more general setting, where privacy-sensitive users have different requirements. For both cases, we design auction-based mechanisms and rigorously prove that the mechanisms are truthful. More importantly, our mechanisms can achieve higher satisfaction ratio than the existing work, i.e., our mechanisms greatly increase the number of privacy-sensitive users successfully winning the auction and receiving privacy protection. We evaluate our mechanisms by using extensive numerical experiments and simulations on a real-world data set. Evaluation results show that our mechanisms achieve much better performance regarding the satisfaction ratio compared with the state-of-the-art mechanisms, and that the computational efficiency is good. Yuan Zhang 0004, Sheng Zhong 0002 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2016 | Designing Secure and Dependable Mobile Sensing Mechanisms With Revenue GuaranteesabstractIn many existing incentive-based mobile sensing applications, the sensing job owner runs an auction with the mobile phone users to maximize its purchased sensing resource. We notice that both the mobile phone users and the job owner could behave dishonestly to pursue their own interests. This motivates us to design secure and dependable auction mechanisms that generate the correct, promising output even when both of them could cheat. In particular, in this paper, we consider a general auction in which a buyer, who acts as the auctioneer, purchases the resource under a limited budget from a group of sellers who act as the bidders. Considering bidders' privacy and their limited computing capacity, we construct our mechanisms by integrating the innovative game theoretical techniques, logic deductions, and efficient cryptographic operations. Our mechanisms are not only proved to be strategy-proof against dishonest bidders in the sense that they are incentivized to bid their private types truthfully, but also enable all the bidders to efficiently verify the correctness of the auction's outcome, that is computed by the auctioneer, without revealing their private types to each other. Meanwhile, our mechanisms are proved to have the theoretical guarantee that the auctioneer/buyer's expected revenue (i.e. the amount of service it acquires after the auction) is no less than a certain portion of the optimal revenue that the auctioneer can acquire when it knows all the bidders' types at no cost. Our extensive evaluations show that our mechanisms achieve good performance in terms of the revenue maximization and their efficiency. Yuan Zhang 0004, Sheng Zhong 0002 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2015 | Privacy Preserving Market Schemes for Mobile SensingabstractTo put mobile sensing into large-scale deployments, we have to take care of sensing participants' incentives and privacy first. In this paper, we study how to protect the sensing participants' privacy in the mobile sensing market where multiple sensing jobs reside in one consolidated place. Our problem is highly challenging due to the facts that incentives are introduced and we consider both the sensing job owner and the market administrator could invade the sensing participants' privacy. We propose two privacy-preserving market mechanisms that are able to protect the sensing participants' privacy to solve our problem. Experiments also demonstrate that our mechanisms have good efficiency. Yuan Zhang 0004, Yunlong Mao, Sheng Zhong 0002 |
ICPP | 1 |
| 2015 | Privacy-preserving min and k-th min computations with fully homomorphic encryptionabstractWe design a secure protocol that a server can compute the minimum number of all participants' data while kept unknown additional information about the users' data in its execution. Ours protocol is based on fully homomorphic encryption and we utilize it to fix the problem of securely computing the minimum value. Besides, the used FHE scheme is a lattice-based cryptosystem that can resist some quantum adversaries who can carry out quantum computations on classical queries. We also expand the secure min computing protocol to the privacy-preserving the k-th min computing protocol, and present the security analysis of the two protocols on the assumption of the semi-honest model. In the previous literature, their solutions are based on secure arithmetic sum computations as well as secure bitwise XOR computations. Our protocols are more secure with the comparison to them. Bingbing Jiang 0002, Yuan Zhang 0004 |
IPCCC | 2 |
| 2015 | FIWEX: Compressive Sensing Based Cost-Efficient Indoor White Space ExplorationabstractExploring the utilization of white spaces (vacant VHF and UHF TV channels) is a promising way to satisfy the rapid growth of the radio frequency (RF) demand. Although a few outdoor white space exploration methods have been proposed in the past few years, researches that focus on indoor white space exploration just emerge recently. In this paper, we propose a novel cost-efficient indoor white space exploration method by exploiting the location dependence and channel dependence of TV channels' signal strength in indoor environments. We measure the UHF TV channels in a building, and study the temporal and spatial features of indoor white spaces. Based on the extracted features, we design a cost-eficient Indoor White space EXploration mechanism, namely FIWEX. Furthermore, we build a prototype of FIWEX and extensively evaluate its performance in real world environments. The evaluation results show that FIWEX can identify 47.8% more indoor white spaces with 38.4% less false alarms compared with the best known existing solution. Dongxin Liu, Fan Wu 0006, Yuan Zhang 0004, Guihai Chen |
MobiHoc | 4 |
| 2015 | An Incentive Scheme for Packet Forwarding and Payment Reduction in Wireless Ad-hoc Networks Using XOR Network CodingabstractIn wireless ad-hoc networks using XOR network coding, intermediate nodes are required to XOR packets whenever possible. Although there are lots of existing incentive compatible schemes aiming to provide incentives for intermediate nodes to forward packets, they are not suitable for XOR network coding. In this paper, we first present a basic payment scheme to provide incentives to intermediate nodes to follow XOR network coding protocol. We prove that, under our scheme each intermediate node has incentives to follow the XOR protocol. Then we consider the overpayment in the basic scheme, and propose an enhanced payment scheme using SVM model to reduce the payment to a reasonable level. The results show that under the enhanced scheme, the payments can be reduced by up to 70%, and these payment are close to the real forwarding costs. Yuan Zhang 0004, Sheng Zhong 0002, Haifan Yao |
MSN | 1 |
| 2015 | Protecting Location Information in Collaborative Sensing of Cognitive Radio NetworksabstractCollaborative sensing has become increasingly popular in cognitive radio networks to enable unlicensed secondary users to coexist with the licensed primary users and share spectrum without interference. Despite its promise in performance enhancement, collaborative sensing is still facing a lot of security challenges. The problem of revealing secondary users' location information through sensing reports has been reported recently. Unlike any existing work, in this paper we not only address the location privacy issues in the collaborative sensing process against semi-honest adversaries, but also take the malicious adversaries into consideration. We propose efficient schemes to protect secondary users' report from being revealed in the report aggregation process at the fusion center. We rigorously prove that our privacy-preserving collaborative sensing schemes are secure against the fusion center and the secondary users in semi-honest model. We also evaluate our scheme extensively and verify its efficiency. Yunlong Mao, Tingting Chen 0001, Yuan Zhang 0004, Tiancong Wang, Sheng Zhong 0002 |
MSWiM | 3 |
| 2013 | Using Electronic Health Records To Assess Generalizability of Clinical Trials
Chunhua Weng, George Hripcsak, Yuan Zhang 0004, J. Thomas Bigger |
AMIA | 4 |
| 2013 | Privacy preserving perceptron learning in malicious model
Yuan Zhang 0004, Sheng Zhong 0002 |
Neural Comput. Appl. | 1 |
| 2013 | A privacy-preserving algorithm for distributed training of neural network ensembles
Yuan Zhang 0004, Sheng Zhong 0002 |
Neural Comput. Appl. | 1 |
| 2013 | How to Select Optimal Gateway in Multi-Domain Wireless Networks: Alternative Solutions without LearningabstractGateways are a crucial part of wireless networks. In multi-domain wireless networks, the existing solution to the problem of optimal gateway selection is based on distributed learning. While such a solution is interesting and useful, it has a fundamental limitation: the learning algorithm may stay for long time in a Nash Equilibrium that does not correspond to the optimal gateway selection. This stay can be so long that people can hardly wait for the convergence of the learning algorithm to the optimal gateway selection. In this paper, we present a systematic study of the gateway selection problem. We distinguish three cases and present an alternative solution to the problem in each of these cases: for public link costs, an algorithm to compute the optimal gateway selection directly; for two domains with private link costs, a cryptographic protocol; for three or more domains with private link costs, a perturbation-based protocol. In all the three cases, our solutions accurately compute the optimal gateway selection within reasonable amounts of time, although we emphasize that our solutions are NOT improvements to the gateway selection solutions based on distributed learning (mainly because our solutions are centralized instead of distributed). Sheng Zhong 0002, Yuan Zhang 0004 |
IEEE Trans. Wirel. Commun. | 2 |