EDBT 2026 Demo / reviewers in the wild / expert
Chengfang Fang
dblp:48/254
· DBLP profile ↗
29ranked-venue papers
7as first author
16since 2021 · last 2026
0000-0002-8313-0980ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 5 first-author · 9 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 4 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Computer networks · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-authorTheory of computation · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Semantic-aware testing for object detection systems
Hsiao-Ying Lin, Chengfang Fang, Wenhai Wang |
Inf. Softw. Technol. | 4 |
| 2026 | LabelDP Leaks Privacy - A Tightened Correlation-Aware Privacy Model for Labeled Training DataabstractIt is well understood that the accuracy of machine learning models heavily depends on the amount of training data collected from individuals. However, the collection of sensitive information brings privacy risks to users. Recently, differential privacy (DP) has emerged as a rigorous privacy model for sensitive data collection. When applying DP to training data collection, a common practice to improve utility is that labels are sanitized whereas attribute values are not, a.k.a., label differential privacy (LabelDP). In this paper, we point out that LabelDP can hardly guarantee the expected privacy on labels due to the correlation between attributes and labels. To address this privacy leakage, we propose a stronger privacy model,correlation-aware label local differential privacy(CLLDP), to protect each individual user with the consideration of correlations between attributes and labels. Under CLLDP, we propose a perturbation protocol$k$heads response($k$HR) to estimate the joint probabilistic distribution of attributes and labels. This distribution can be used for a variety of machine learning tasks, such as Naïve Bayes and decision tree, both of which are illustrated in this paper. Through extensive experiments, we show the strong privacy guarantee of CLLDP and its effectiveness in real-life machine learning tasks. Qiao Xue, Qingqing Ye 0001, Haibo Hu 0001, Jian Lou 0001, Jin Li 0002, Chengfang Fang, Jie Shi 0005 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | RMR: A Relative Membership Risk Measure for Machine Learning ModelsabstractPrivacy leakage poses a significant threat when machine learning foundation models trained on private data are released. One such threat is membership inference attacks (MIA), which determine whether a specific example was included in a model's training set. This article shifts focus from developing new MIA algorithms to measuring a model's risk under MIA. We introduce a novel metric, Relative Membership Risk (RMR), which assesses a model's MIA vulnerability from a comparative standpoint. RMR calculates the difference in prediction loss for training examples relative to a predefined reference model, enabling risk comparison across models without needing to delve into details like training strategy, architecture, or data distribution. We also explore the selection of the reference model and show that using a high-risk reference model enhances the accuracy of the RMR measure. To identify the most vulnerable reference model, we propose an efficient iterative algorithm that selects the optimal model from a set of candidates. Through extensive empirical evaluations on various datasets and network architectures, we demonstrate that RMR is an accurate and efficient tool for measuring the membership privacy risk of both individual training examples and the overall machine learning model. Li Bai 0004, Haibo Hu 0001, Qingqing Ye 0001, Jianliang Xu, Jin Li 0002, Chengfang Fang, Jie Shi 0005 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2024 | ADVSV: An Over-the-Air Adversarial Attack Dataset for Speaker VerificationabstractIt is known that deep neural networks are vulnerable to adversarial attacks. Although Automatic Speaker Verification (ASV) built on top of deep neural networks exhibits robust performance in controlled scenarios, many studies confirm that ASV is vulnerable to adversarial attacks. The lack of a standard dataset is a bottleneck for further research, especially reproducible research. In this study, we developed an open-source adversarial attack dataset for speaker verification research. As an initial step, we focused on the over-the-air attack. An over-the-air adversarial attack involves a perturbation generation algorithm, a loudspeaker, a microphone, and an acoustic environment. The variations in the recording configurations make it very challenging to reproduce previous research. The AdvSV dataset is constructed using the Voxceleb1 Verification test set as its foundation. This dataset employs representative ASV models subjected to adversarial attacks and records adversarial samples to simulate over-the-air attack settings. The scope of the dataset can be easily extended to include more types of adversarial attacks. The dataset will be released to the public under the CC BY-SA 4.0. In addition, we also provide a detection baseline for reproducible research. Jiaqi Li 0030, Jiahao Zheng 0002, Chengfang Fang, Jie Shi 0005, Zhizheng Wu 0001 |
ICASSP | 8 |
| 2023 | QUDA: Query-Limited Data-Free Model ExtractionabstractModel extraction attack typically refers to extracting non-public information from a black-box machine learning model. Its unauthorized nature poses significant threat to intellectual property rights of the model owners. By using the well-designed queries and the predictions returned from the victim model, the adversary is able to train a clone model from scratch to obtain similar functionality as victim model. Recently, some methods have been proposed to perform model extraction attacks without using any in-distribution data (Data-free setting). Although these methods have been shown to achieve high clone accuracy, their query budgets are typically around 10 million or even exceed 20 million in some datasets, which lead to a high cost of model stealing and can be easily defended by limiting the number of queries. To illustrate the severe threats induced by model extraction attacks with limited query budget in realistic scenarios, we propose QUDA – a novel QUey-limited DAta-free model extraction attack that incorporates GAN pre-trained by public unrelated dataset to provide weak image prior and the technique of deep reinforcement learning to make query generation strategy more efficient. Compared with the state-of-the-art data-free model extraction method, QUDA achieves better results under query-limited condition (0.1M query budget) in FMNIST and CIFAR-10 datasets, and even outperforms the baseline method in most cases when QUDA uses only 10% query budget of its. QUDA issued a warning that solely relying on the limited numbers of queries or the confidentiality of training data is not reliable to protect model’s security and privacy. Potential countermeasures, such as detection-based defense approach, are also provided. Zijun Lin 0001, Chengfang Fang, Huadi Zheng, Aneez Ahmed Jaheezuddin, Jie Shi 0005 |
AsiaCCS | 3 |
| 2023 | Mitigating Adversarial Attacks by Distributing Different Copies to Different BuyersabstractMachine learning models are vulnerable to adversarial attacks. In this paper, we consider the scenario where a model is distributed to multiple buyers, among which a malicious buyer attempts to attack another buyer. The malicious buyer probes its copy of the model to search for adversarial samples and then presents the found samples to the victim’s copy of the model in order to replicate the attack. We point out that by distributing different copies of the model to different buyers, we can mitigate the attack such that adversarial samples found on one copy would not work on another copy. We observed that training a model with different randomness indeed mitigates such replication to a certain degree. However, there is no guarantee and retraining is computationally expensive. A number of works extended the retraining method to enhance the differences among models. However, a very limited number of models can be produced using such methods and the computational cost becomes even higher. Therefore, we propose a flexible parameter rewriting method that directly modifies the model’s parameters. This method does not require additional training and is able to generate a large number of copies in a more controllable manner, where each copy induces different adversarial regions. Experimentation studies show that rewriting can significantly mitigate the attacks while retaining high classification accuracy. For instance, on GTSRB dataset with respect to Hop Skip Jump attack, using attractor-based rewriter can reduce the success rate of replicating the attack to 0.5% while independently training copies with different randomness can reduce the success rate to 6.5%. From this study, we believe that there are many further directions worth exploring. Jiyi Zhang, Han Fang 0004, Wesley Joon-Wie Tann, Chengfang Fang, Ee-Chien Chang |
AsiaCCS | 5 |
| 2023 | Tracing the Origin of Adversarial Attack for Forensic Investigation and DeterrenceabstractDeep neural networks are vulnerable to adversarial attacks. In this paper, we take the role of investigators who want to trace the attack and identify the source, that is, the particular model which the adversarial examples are generated from. Techniques derived would aid forensic investigation of attack incidents and serve as deterrence to potential attacks. We consider the buyers-seller setting where a machine learning model is to be distributed to various buyers and each buyer receives a slightly different copy with the same functionality. A malicious buyer generates adversarial examples from a particular copy ${\mathcal{M}_i}$ and uses them to attack other copies. From these adversarial examples, the investigator wants to identify the source ${\mathcal{M}_i}$. To address this problem, we propose a two-stage separate-and-trace framework. The model separation stage generates multiple copies of a model for the same classification task. This process injects unique features into each copy so that adversarial examples generated have distinct and traceable features. We give a parallel structure which pairs a unique tracer with the original classification model in each copy and a variational autoencoder (VAE)-based training method to achieve this goal. The tracing stage takes in adversarial examples and a few candidate models, and identifies the likely source. Based on the unique features induced by the tracer, we could effectively trace the potential adversarial copy by considering the output logits from each tracer. Empirical results show that it is possible to trace the origin of the adversarial example and the mechanism can be applied to a wide range of architectures and datasets. Jiyi Zhang, Yupeng Qiu, Chengfang Fang, Ee-Chien Chang |
ICCV | 6 |
| 2023 | Differential Aggregation against General Colluding AttackersabstractLocal Differential Privacy (LDP) is now widely adopted in large-scale systems to collect and analyze sensitive data while preserving users’ privacy. However, almost all LDP protocols rely on a semi-trust model where users are curious-but-honest, which rarely holds in real-world scenarios. Recent works [6], [11], [62] show poor estimation accuracy of many LDP protocols under malicious threat models. Although a few works have proposed some countermeasures to address these attacks, they all require prior knowledge of either the attacking pattern or the poison value distribution, which is impractical as they can be easily evaded by the attackers.In this paper, we adopt a general opportunistic-and-colluding threat model and propose a multi-group Differential Aggregation Protocol (DAP) to improve the accuracy of mean estimation under LDP. Different from all existing works that detect poison values on individual basis, DAP mitigates the overall impact of poison values on the estimated mean. It relies on a new probing mechanism EMF (i.e., Expectation-Maximization Filter) to estimate features of the attackers. In addition to EMF, DAP also consists of two EMF post-processing procedures (EMF* and CEMF*), and a group-wise mean aggregation scheme to optimize the final estimated mean to achieve the smallest variance. Extensive experimental results on both synthetic and real-world datasets demonstrate the superior performance of DAP over state-of-the-art solutions. Rong Du 0001, Qingqing Ye 0001, Haibo Hu 0001, Jin Li 0002, Chengfang Fang, Jie Shi 0005 |
ICDE | 6 |
| 2023 | DoubleDeceiver: Deceiving the Speaker Verification System Protected by Spoofing Countermeasures
Mengao Zhang, Lei Wang 0020, Chengfang Fang |
INTERSPEECH | 5 |
| 2023 | DeNoL: A Few-Shot-Sample-Based Decoupling Noise Layer for Cross-channel Watermarking RobustnessabstractCross-channel (e.g. Screen-to-Camera) robustness is an urgent requirement for modern watermarking systems. To realize such robustness, training a network that can precisely simulate the cross-channel distortion as the noise layer for deep watermarking training is an effective way. However, network training requires massive data, and generating the data is laborious. Meanwhile, directly using limited data to train may lead to an over-fitting issue. To address such limitation, we proposed DeNoL, a decoupling noise layer for cross-channel simulation which only needs few-shot samples. We believe the overfitting issue comes from the overlearning of the training image content rather than only simulating the distortion style. Consequently, we design a network that can decouple the image content and the distortion style into different components. Thus, by fixing the content representation component and fine-tuning a new style component accordingly, the network can efficiently learn and only learn the distortion style. Such learning can be done with only few-shot samples. Besides, in order to enhance adaptability, we also proposed a diversification operation to cooperate with DeNoL. Experimental results show that DeNoL can effectively simulate cross-channel distortion with only 20 image pairs and assist in training a general and robust watermarking network. Han Fang 0004, Kejiang Chen, Yupeng Qiu, Chengfang Fang, Weiming Zhang 0001, Ee-Chien Chang |
ACM Multimedia | 6 |
| 2023 | 3DFed: Adaptive and Extensible Framework for Covert Backdoor Attack in Federated LearningabstractFederated Learning (FL), the de-facto distributed machine learning paradigm that locally trains datasets at individual devices, is vulnerable to backdoor model poisoning attacks. By compromising or impersonating those devices, an attacker can upload crafted malicious model updates to manipulate the global model with backdoor behavior upon attacker-specified triggers. However, existing backdoor attacks require more information on the victim FL system beyond a practical black-box setting. Furthermore, they are often specialized to optimize for a single objective, which becomes ineffective as modern FL systems tend to adopt in-depth defense that detects backdoor models from different perspectives. Motivated by these concerns, in this paper, we propose 3DFed, an adaptive, extensible, and multi-layered framework to launch covert FL backdoor attacks in a black-box setting. 3DFed sports three evasion modules that camouflage backdoor models: backdoor training with constrained loss, noise mask, and decoy model. By implanting indicators into a backdoor model, 3DFed can obtain the attack feedback in the previous epoch from the global model and dynamically adjust the hyper-parameters of these backdoor evasion modules. Through extensive experimental results, we show that when all its components work together, 3DFed can evade the detection of all state-of-the-art FL backdoor defenses, including Deepsight, Foolsgold, FLAME, FL-Detector, and RFLBAT. New evasion modules can also be incorporated in 3DFed in the future as it is an extensible framework. Haoyang Li 0018, Qingqing Ye 0001, Haibo Hu 0001, Jin Li 0002, Leixia Wang, Chengfang Fang, Jie Shi 0005 |
SP | 6 |
| 2023 | PrivKVM*: Revisiting Key-Value Statistics Estimation With Local Differential PrivacyabstractA key factor in big data analytics and artificial intelligence is the collection of user data from a large population. However, the collection of user data comes at the price of privacy risks, not only for users but also for businesses who are vulnerable to internal and external data breaches. To address privacy issues, local differential privacy (LDP) has been proposed to enable an untrusted collector to obtain accurate statistical estimation on sensitive user data (e.g., location, health, and financial data) without actually accessing the true records. As key-value data is an extremely popular NoSQL data model, there are a few works in the literature that study LDP-based statistical estimation on key-value data. However, these works have some major limitations, including supporting small key space only, fixed key collection range, difficulty in choosing an appropriate padding length, and high communication cost. In this article, we propose a two-phase mechanism$PrivKVM^*$as an optimized and highly-complete solution to LDP-based key-value data collection and statistics estimation. We verify its correctness and effectiveness through rigorous theoretical analysis and extensive experimental results. Qingqing Ye 0001, Haibo Hu 0001, Xiaofeng Meng 0001, Huadi Zheng, Kai Huang 0011, Chengfang Fang, Jie Shi 0005 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2022 | MExMI: Pool-based Active Model Extraction Crossover Membership InferenceabstractWith increasing popularity of Machine Learning as a Service (MLaaS), ML models trained from public and proprietary data are deployed in the cloud and deliver prediction services to users. However, as the prediction API becomes a new attack surface, growing concerns have arisen on the confidentiality of ML models. Existing literatures show their vulnerability under model extraction (ME) attacks, while their private training data is vulnerable to another type of attacks, namely, membership inference (MI). In this paper, we show that ME and MI can reinforce each other through a chained and iterative reaction, which can significantly boost ME attack accuracy and improve MI by saving the query cost. As such, we build a framework MExMI for pool-based active model extraction (PAME) to exploit MI through three modules: “MI Pre-Filter”, “MI Post-Filter”, and “semi-supervised boosting”. Experimental results show that MExMI can improve up to 11.14% from the best known PAME attack and reach 94.07% fidelity with only 16k queries. Furthermore, the precision and recall of the MI attack in MExMI are on par with state-of-the-art MI attack which needs 150k queries. Yaxin Xiao, Qingqing Ye 0001, Haibo Hu 0001, Huadi Zheng, Chengfang Fang, Jie Shi 0005 |
NeurIPS | 5 |
| 2022 | Protecting Decision Boundary of Machine Learning Model With Differentially Private PerturbationabstractMachine learning service API allows model owners to monetize proprietary models by offering prediction services to third-party users. However, existing literature shows that model parameters are vulnerable to extraction attacks which accumulate prediction queries and their responses to train a replica model. As countermeasures, researchers have proposed to reduce the rich API output, such as hiding the precise confidence. Nonetheless, even with response being only one bit, an adversary can still exploit fine-tuned queries with differential property to infer the decision boundary of the underlying model. In this article, we propose boundary differential privacy (BDP) against such attacks by obfuscating the prediction responses with noises. BDP guarantees an adversary cannot learn the decision boundary of any two classes by a predefined precision no matter how many queries are issued to the prediction API. We first design a perturbation algorithm called boundary randomized response for a binary model. Then we prove it satisfies$\epsilon$-BDP, followed by a generalization of this algorithm to a multiclass model. Finally, we generalize a hard boundary to soft boundary and design an adaptive perturbation algorithm that can still work in the latter case. The effectiveness and high utility of our solution are verified by extensive experiments on both linear and non-linear models. Huadi Zheng, Qingqing Ye 0001, Haibo Hu 0001, Chengfang Fang, Jie Shi 0005 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | Cert-RNN: Towards Certifying the Robustness of Recurrent Neural NetworksabstractCertifiable robustness, the functionality of verifying whether the given region surrounding a data point admits any adversarial example, provides guaranteed security for neural networks deployed in adversarial environments. A plethora of work has been proposed to certify the robustness of feed-forward networks, e.g., FCNs and CNNs. Yet, most existing methods cannot be directly applied to recurrent neural networks (RNNs), due to their sequential inputs and unique operations. Tianyu Du, Shouling Ji, Lujia Shen, Yao Zhang 0019, Chengfang Fang, Jianwei Yin, Raheem A. Beyah, Ting Wang 0006 |
CCS | 7 |
| 2021 | Backdoor Pre-trained Models Can Transfer to AllabstractPre-trained general-purpose language models have been a dominating component in enabling real-world natural language processing (NLP) applications. However, a pre-trained model with backdoor can be a severe threat to the applications. Most existing backdoor attacks in NLP are conducted in the fine-tuning phase by introducing malicious triggers in the targeted class, thus relying greatly on the prior knowledge of the fine-tuning task. In this paper, we propose a new approach to map the inputs containing triggers directly to a predefined output representation of the pre-trained NLP models, e.g., a predefined output representation for the classification token in BERT, instead of a target label. It can thus introduce backdoor to a wide range of downstream tasks without any prior knowledge. Additionally, in light of the unique properties of triggers in NLP, we propose two new metrics to measure the performance of backdoor attacks in terms of both effectiveness and stealthiness. Our experiments with various types of triggers show that our method is widely applicable to different fine-tuning tasks (classification and named entity recognition) and to different models (such as BERT, XLNet, BART), which poses a severe threat. Furthermore, by collaborating with the popular online model repository Hugging Face, the threat brought by our method has been confirmed. Finally, we analyze the factors that may affect the attack performance and share insights on the causes of the success of our backdoor attack. Lujia Shen, Shouling Ji, Xuhong Zhang 0002, Jing Chen 0003, Chengfang Fang, Jianwei Yin, Ting Wang 0006 |
CCS | 7 |
| 2020 | Bident Structure for Neural Network Model Protection
Hsiao-Ying Lin, Chengfang Fang |
ICISSP | 2 |
| 2019 | BDPL: A Boundary Differentially Private Layer Against Machine Learning Model Extraction Attacks
Huadi Zheng, Qingqing Ye 0001, Haibo Hu 0001, Chengfang Fang, Jie Shi 0005 |
ESORICS (1) | 4 |
| 2014 | Differential privacy with δ-neighbourhood for spatial and dynamic datasetsabstractDifferential privacy provides a strong guarantee in protecting privacy of individuals who contributed to a published dataset. In this paper, we focus on spatial datasets and dynamic datasets, and attempt to exploit the intuition that farther-apart entities should have lesser influences to each other, and thus more privacy budget should be invested to protect close-by entities. To capture such intuition, we propose embedding the underlying spatial or temporal distance function into the notion of dataset neighbourhood. We called the proposed neighbourhood δ-neighbourhood, and discuss its implications in both spatial and dynamic datasets. For dynamic datasets, while there are known negative results on the standard differential privacy, it is possible to continuously and indefinitely publish under δ-neighbourhood by reusing the privacy budgets. Although known mechanisms, by definition, are also differentially private under δ-neighbourhood, they are not designed to exploit the relaxed notion for better utility. For spatial datasets, we propose an approach on 2D spatial points that re-allocates more budgets to nearby entities and thus obtains significantly higher utility. In addition, we give mechanisms that achieve "sustainable privacy" on dynamic datasets under both online and offline setting. Chengfang Fang, Ee-Chien Chang |
AsiaCCS | 1 |
| 2014 | An Optimization Model for Aesthetic Two-Dimensional Barcodes
Chengfang Fang, Chunwang Zhang, Ee-Chien Chang |
MMM (1) | 1 |
| 2014 | Optimal strategy of coupon subset collection when each package contains half of the coupons
Chengfang Fang, Ee-Chien Chang |
Inf. Process. Lett. | 1 |
| 2012 | Adaptive Differentially Private Histogram of Low-Dimensional Data
Chengfang Fang, Ee-Chien Chang |
Privacy Enhancing Technologies | 1 |
| 2011 | Identity leakage mitigation on asymmetric secure sketchabstractWe consider secure sketch construction in an asymmetric setting, that is, multiple samples are acquired during enrollment, but only a single sample is obtained during verification. Known protection methods apply secure sketch constructions on the average of the samples, while publishing the auxiliary information extracted from the set of samples, such as variances or weights of the features, in clear. Since the auxiliary information is revealed, an adversary can potentially use it to determine the relationship among multiple sketches, and gather information on the identity of the sketches. In this paper, we give a formal formulation of secure sketch under the asymmetric setting, and propose two schemes that mix the identity-dependent auxiliary information within the sketch. Our analysis shows that while our schemes maintain similar bounds of information loss compared to schemes that reveal the auxiliary information, they offer better privacy protection by limiting the linkages among sketches. Chengfang Fang, Ee-Chien Chang |
IJCB | 1 |
| 2011 | ID Repetition in Structured P2P NetworksabstractIdentity (ID) uniqueness is essential in distributed hash table (DHT)-based systems, as peer lookup and resource searching rely on ID matching. However, many DHT implementations in the wild, such as Kad and Mainline, do not enforce such uniqueness. Most previous works and measurements on DHTs do not take into account that IDs among peers may not be unique. Unfortunately, we observe that a significant portion of peers, i.e. 19.5% of the peers in Kad and 4.0% of the peers in Mainline, do not have unique IDs. These repetitions would mislead the measurements and modeling on those networks. We further focus on investigating the repetition in Kad considering its wider usage and more serious situation of repetition. We observe that there are a large number of peers that frequently change their UDP ports, and there are a few IDs that repeat for a large number of times and all peers with these IDs do not respond to Kad protocol. We also analyze the effects of ID repetitions under simplified settings and find that the current repetition degrades Kad's performance on publishing and searching, but has insignificant effect on lookup process. These measurement and analysis are useful to further determine the sources of repetitions and are also useful for finding suitable parameters in publishing and searching processes in DHT networks without compulsive ID uniqueness. Jie Yu 0008, Zhoujun Li 0001, Chengfang Fang, Jia Xu 0006, Ee-Chien Chang |
Comput. J. | 4 |
| 2011 | Intrusion diagnosis and prediction with expert systemabstractAbstract Network diagnosis and attack prediction can help the network administrator to take timely actions to defend against well‐planned attacks that exploit a chain of vulnerabilities. One important data source for such analysis is the alerts generated by intrusion detection systems (IDS) deployed over the network. However, IDS typically generates overwhelming amount of alerts, where one cannot simply aggregate or discard. In addition, the chance of a successful exploit depends on many hidden factors such as system status and attacker power, and thus the dependencies among exploits and conditions are typically too complicated to analyze under probability framework. In this paper, we employ expert system to deal with such uncertainties and conduct certainty factor inference. We show that analysis in fuzzy system is tractable and we propose an algorithm to analyze the network status and predict the potential attacks. Finally, we give a case study to illustrate our algorithm and evaluate the effectiveness of our approach on the DARPA data sets. Copyright © 2011 John Wiley & Sons, Ltd. Xuejiao Liu 0002, Chengfang Fang, Debao Xiao |
Secur. Commun. Networks | 2 |
| 2010 | Secure Sketch for Multiple Secrets
Chengfang Fang, Ee-Chien Chang |
ACNS | 1 |
| 2010 | Securing interactive sessions using mobile device through visual channel and visual inspectionabstractAbstract. Communication channel established from a display to a device’s camera is known as visual channel, and it is helpful in securing key exchange protocol [18]. In this paper, we study how visual channel can be exploited by a network terminal and mobile device to jointly verify information in an interactive session, and how such information can be jointly presented in a user-friendly manner, taking into account that the mobile device can only capture and display a small region, and the user may only want to authenticate selective regions-of-interests. Motivated by applications in Kiosk computing and multi-factor authentication, we consider three security mod-els: (1) the mobile device is trusted, (2) at most one of the terminal or the mobile device is dishonest, and (3) both the terminal and device are dishonest but they do not collude or communicate. We give two protocols and investigate them under the abovementioned models. We point out a form of replay attack that renders some other straightforward implementations cumbersome to use. To enhance user-friendliness, we propose a solution using visual cues embedded into the 2D barcodes and incorporate the framework of “augmented reality ” for easy verifications through visual inspec-tion. We give a proof-of-concept implementation to show that our scheme is feasible in practice. Chengfang Fang, Ee-Chien Chang |
ACSAC | 1 |
| 2010 | A chameleon encryption scheme resistant to known-plaintext attackabstractFrom a ciphertext and a secret key assigned to a user, the decryption of a Chameleon encryption scheme produces a message which is the plaintext embedded with a watermark associated to the user. Most existing constructions of Chameleon encryption scheme are LUT (lookup table)-based, where a secret LUT plays the role of the master key and each user has a noisy version of the secret LUT. LUT-based methods have the limitation that the secrecy of the master key, under known-plaintext attack (KPA), relies on the difficulty in solving large linear system. In other words, with some knowledge of the plaintext, a dishonest user is able to derive the LUT, or an approximation of the LUT by solving a linear system. Resistance to such attack is crucial in the context of multimedia encryption since multimedia objects inherently contain high redundancies. Furthermore, for efficiency in decryption, the underlying linear system is likely to be sparse or not overly large, and hence can be solved using reasonable computing resource. In our experiment, a desktop PC is able to find a LUT (with 216 entries) within 2 hours. We propose a scheme that is resistant to KPA. The core of the scheme is a MUTABLE-PRNG (Pseudo Random Number Generator) whereby different but similar sequences are generated from related seeds. We generate such sequence from multiple pseudo random sequences based on majority-vote, and enhance its performance using error-correcting code. The proposed scheme is very simple and it is easy to show that it is resistant to KPA under reasonable cryptographic assumptions. However, it is not clear how much information on the original plaintext is leaked from the watermarked copies. We analyze the scheme and quantify the information loss using average conditional entropy. Ee-Chien Chang, Chengfang Fang, Jia Xu 0006 |
Digital Rights Management Workshop | 2 |
| 2009 | ID Repetition in KadabstractID uniqueness is essential in DHT-based systems as peer lookup and resource searching rely on ID-matching. Many previous works and measurements on Kad do not take into account that IDs among peers may not be unique. We observe that a significant portion of peers, 19.5% of the peers in routing tables and 4.5% of the active peers (those who respond to Kad protocol), do not have unique IDs. These repetitions would mislead the measurements of Kad network. We further observe that there are a large number of peers that frequently change their UDP ports, and there are a few IDs that repeat for a large number of times and all peers with these IDs do not respond to Kad protocol. We analyze the effects of ID repetitions under simplified settings and find that ID repetition degrades Kad's performance on publishing and searching, but has insignificant effect on lookup process. These measurement and analysis are useful in determining the sources of repetitions and are also useful in finding suitable parameters for publishing and searching. Jie Yu 0008, Chengfang Fang, Jia Xu 0006, Ee-Chien Chang, Zhoujun Li 0001 |
Peer-to-Peer Computing | 2 |