Kuan Zhang 0001

dblp:50/7188-1 · DBLP profile ↗
← Back
128ranked-venue papers
7as first author
65since 2021 · last 2026
0000-0002-4262-153XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 89 · 4 first-author · 44 since 2021Security and privacy · 16 · 1 first-author · 11 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 1 first-author · 4 since 2021Databases, data management, data science and information retrieval · 5 · 1 first-authorSystems, architecture and hardware · 3 · 2 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Multidimensional Auditable Lattice-Based Privacy-Preserving Data Aggregation Scheme in Smart Grids
abstract
The massive growth of data has brought vigorous vitality to Internet-of-Things (IoT). It has also brought new challenges, such as confidentiality privacy protection and redundant data transmission. Concerning this regard, data aggregation serves as an efficient technique to minimize the transmission frequency among massive objects in smart grid(SG). By aggregating a large amount of the same type of data while satisfying the protection of user privacy. With the advent of the post-quantum era, a good aggregation scheme must provide quantum resistance while ensuring the secure aggregation of ciphertext power data. However, the excessive overhead limits anti-quantum algorithms from being widely used in SG where resource devices are limited. Therefore, it is an important part of the current private data security aggregation technology to find a low cost and lightweight inverse quantum algorithm to achieve user data security aggregation. In this paper, we propose an improved NTRU-based cryptosystem with multidimensional coding, referred to as multidimensional coding NTRU (MC-NTRU). and use the lattice batch signature technique, which improves the efficiency of the scheme while satisfying the anti-quantum attack. Based on these, we design the multidimensional auditable lattice-based privacy-preserving data aggregation scheme(MA-PPDA) for privacy data on resource-limited IoT devices such as smart grids. In addition to this, the scheme achieves fault tolerance of the scheme by adding zeros and random numbers to the user data. The comparative study against existing approaches demonstrates that the proposed scheme not only adheres to critical security aspects including user privacy, data confidentiality, integrity, and authenticity, but also decreases both communication and computational burdens on the system. This makes our scheme particularly apt for IoT environments characterized by constrained device resources.
Kai Fan 0001, Xuyang Ma, Guanglu Wei, Kuan Zhang 0001, Hui Li 0006, Yintang Yang, Lianhai Wang
IEEE Internet Things J.4
2026 NeuDFL: Efficient Neuron-Based Defense Against Label Flipping Attacks on Non-IID Data
abstract
Federated Learning (FL) enables collaborative model training while preserving data privacy, making it particularly attractive for large-scale Internet of Things (IoT) systems. However, in practical deployments, data collected by distributed clients are often non-independent and identically distributed (Non-IID), which amplifies the vulnerability of FL to poisoning attacks. Among them, Label-Flipping Attacks (LFA) are especially stealthy, as they can induce targeted misclassification without noticeably affecting overall accuracy, posing serious risks to safety-critical IoT applications. In this paper, we propose NeuDFL, a lightweight and robust defense framework against LFA under Non-IID settings. Unlike many existing defenses that primarily rely on gradient analysis over the full model update space or auxiliary clean datasets, NeuDFL exploits lightweight class-wise parameter statistics extracted from the final fully connected layer. By leveraging the cumulative and task-aligned nature of model parameters, NeuDFL enables reliable identification of attacked classes and filters malicious clients via an adaptive statistical threshold, improving robustness to data heterogeneity while incurring low computational overhead. Extensive experiments on multiple datasets demonstrate that NeuDFL offers an effective and efficient defense against label-flipping attacks, providing a robust solution for federated learning in complex real-world environments.
Kai Fan 0001, Huixuan Wang, Wenjie Li 0008, Hui Li 0006, Kuan Zhang 0001, Yintang Yang, Lianhai Wang
IEEE Internet Things J.6
2026 HBA: Hijacking-Based Backdoor Attack for Vertical Federated Learning
abstract
Vertical Federated Learning (VFL) is a distributed machine learning paradigm designed for scenarios with vertically partitioned data features, making it highly compatible with Internet of Things (IoT) ecosystems. While promoting collaborative modeling among IoT devices, VFL also introduces new security risks, particularly backdoor attacks. Existing VFL backdoor attacks typically establish associations between triggers and target labels during the training phase by manipulating intermediate model outputs, making them easily detectable by advanced defense mechanisms. This paper proposes Hijacking-based Backdoor Attack (HBA), which for the first time innovatively achieves backdoor attack by exchanging the forward embeddings during VFL prediction phase, without embedding traditional triggers. HBA leverages intrinsic semantic relationships in the embedding space to hijack the decision-making process of the top model during inference. HBA’s effectiveness depends on the discriminative nature of the features extracted by the bottom model, and since it does not alter the training process, it can evade most defense mechanisms based on training behavior monitoring. Experiments demonstrate that HBA achieves an attack success rate of 99.9% in classification tasks without compromising the original task’s accuracy. Furthermore, existing defense mechanisms struggle to effectively counter HBA without degrading the model’s original task performance.
Pingle Zhang, Kai Fan 0001, Xiang Li 0214, Kuan Zhang 0001, Hui Li 0006, Yintang Yang, Lianhai Wang
IEEE Internet Things J.5
2026 Cancelable Biometrics and Quantum-Resistant Two-Factor Authenticated Key Agreement for Mobile Device
Guanglu Wei, Kai Fan 0001, Kuan Zhang 0001, Yuhan Bai, Zhanpeng Guo, Hui Li 0006, Yintang Yang
IEEE Trans. Dependable Secur. Comput.3
2026 Dynamic Asymmetric Group Key Agreement Without Pairing for Distributed Online Social Networks
abstract
Online social networks (OSN) such as Twitter, Facebook, etc. have an overall user base of more than 5 billion as of today. Traditional centralized OSN users’ data and content are stored in centralized servers, which has the risk of data leakage and privacy violation. Distributed OSN (DOSN) address the single-point-of-failure and user data privacy concerns faced by centralized OSN by enabling the operation of network infrastructures and services without centralized ownership or control. However, DOSN face privacy protection issues. The group key agreement (GKA) is an important method to construct secure channels to protect the secure communication of network group members. Asymmetric GKA methods allow external members to securely communicate with group members without having to join the group. However, it is worth noting that existing AGKA schemes rely on bilinear pairing, resulting in a high computational overhead. Meanwhile, considering scenarios where external users join, or group members leave, we design a dynamic asymmetric group key agreement (DAGKAwP) scheme based on Schnorr batch multi-signature that does not depend on bilinear pairing. During the key generation phase, the members generate self-authenticating public-private key pairs to resist malicious public key attacks. For group key agreement, new hash functions are embedded in Schnorr signatures to generate aggregated public keys, and this scheme supports external member addition and internal member exit. In group message encryption, sender anonymity and message non-repudiation are realized. The security comparison with related DAGKA schemes reveals that the DAGKAwP scheme offers more comprehensive security. Performance evaluations suggest that this scheme offers computational efficiency and lower communication overhead than related Dynamic AGKA schemes.
Kai Fan 0001, Guanglu Wei, Kuan Zhang 0001, Hui Li 0006, Yintang Yang
IEEE Trans. Netw.3
2026 Joint Dynamic Tracking and Robust Secure Beamforming for Full-Duplex ISAC Systems
abstract
Integrated sensing and communication (ISAC) has emerged as a promising paradigm for next-generation mobile wireless communication systems. In this paper, we propose a novel framework for full-duplex ISAC systems that jointly incorporates dynamic tracking and robust secure beamforming. Specifically, a dual-functional radar-communication base station employs an extended Kalman filter to dynamically estimate the trajectories of mobile downlink (DL) users. To mitigate the impact of imperfect channel state information from multiple eavesdroppers, a robust beamforming strategy is devised by quantifying angular uncertainty via the Cramér–Rao bound (CRB). A total transmit power minimization problem is formulated under secrecy rate constraints for both DL and uplink (UL) communications, while simultaneously ensuring sensing accuracy through CRB and beam tracking mean squared error metrics. The optimization jointly considers the beamforming matrices, artificial noise covariance matrix, and UL power allocation strategy. To address the formulated non-convex problem, the S-procedure is employed to transform semi-infinite constraints into linear matrix inequalities. Successive convex approximation technique is then iteratively applied to obtain high-quality solutions. Extensive simulations verify the effectiveness of the proposed framework, demonstrating superiority in secrecy rate and power efficiency compared to benchmark schemes. Moreover, the results highlight the inherent trade-offs between secure communications performance and sensing accuracy, thereby offering insights into the design of future full-duplex ISAC systems.
Bozhang Hua, Haixia Peng, Nan Cheng 0001, Kuan Zhang 0001, Zhou Su 0001
IEEE Trans. Wirel. Commun.5
2025 Blockchain-based anonymous and self-tallying voting with time-bounded ballot secrecy
Yijie Shi, Kai Fan 0001, Yuhan Bai, Chonglin Zhang, Kuan Zhang 0001, Hui Li 0006, Yintang Yang
Comput. Networks5
2025 SECR: A Secure and Efficient Charging Reservation Scheme Based on Digital Twin in Vehicular Network
abstract
Despite the rapid growth of electric vehicles (EVs), charging remains a time-consuming issue that requires effective management. An important solution uses digital twin (DT) technology, which acts as a virtual agent for EVs in the digital space. DT can analyze real-time vehicle data to develop optimal charging schedules and reserve charging providers in advance through the vehicular network, leading to more efficient charging processes. However, the vehicular network exposes the automated reservation process of the DT to security attacks. Additionally, there is a risk that the actual charging process may deviate from the scheduled requirements set by the DT, resulting in wasted charging resources. To address these issues, this article proposes a secure and efficient charging reservation scheme based on DT technology. To prevent malicious attacks, we first design a secure and privacy-preserving reservation authentication protocol using the extended Chebyshev chaotic maps, taking into account the computational resources of the EV. Furthermore, we develop a reputation mechanism to evaluate and incentivize the charging behavior of EVs. Formal verification and further discussions are conducted to show diverse security functionalities of the proposed scheme can be achieved. We evaluate that the proposed scheme outperforms existing schemes in terms of computation and communication overheads, while also assessing the impact of EV charging behavior on reputation and charging level.
Guanjie Li, Tom H. Luan, Jinkai Zheng, Chengzhe Lai, Kuan Zhang 0001, Shui Yu 0001
IEEE Internet Things J.5
2025 TMAE: Entropy-Aware Masked Autoencoder for Low-Cost Traffic Flow Map Inference
abstract
Accurate traffic flow measurement is essential for the development of smart cities, yet the deployment of ubiquitous monitoring sensors using traditional methods is often cost-prohibitive. This paper proposes an innovative entropy-aware masked autoencoder framework, namely TMAE, for low-cost traffic flow inference. TMAE leverages a small number of selectively measured regions with few deployed sensors to infer traffic flow across entire urban areas, incorporating prior knowledge from road distribution maps. Specifically, TMAE employs a shared encoder to process traffic flow context, using self-attention scores to identify the importance of each region and guide a masking policy that retains regions rich in traffic flow information. The road distribution map, reflecting inherent traffic flow patterns, is incorporated as prior knowledge by substituting masked tokens during training. A cross-attention mechanism in the decoder further refines inference, where embeddings from the road distribution map serve as queries, and retained visible patches act as keys and values. Additionally, regional traffic entropy is introduced to quantify the information richness of each region, enabling the selection of minimal measurement regions to optimize inference for other areas. Extensive experiments conducted on datasets from various cities demonstrate the effectiveness and efficiency of TMAE, highlighting its potential as a scalable solution for low-cost traffic flow inference in urban environments. The source code of this work is released at https://github.com/TextGraph/TMAE.
Xucheng Luo, Ye Wang 0002, Kuan Zhang 0001, Hongning Dai, Dajiang Chen
IEEE Internet Things J.4
2025 Multidiffusion Information Centrality for the Identification of Influential Spreaders in Temporal Social Networks
abstract
Identifying influential spreaders in a temporal social network, which has potential applications including network immunization, epidemic control, and viral marketing, is a fundamental class of problems. In this context, various centrality algorithms have been introduced to quantify influential spreaders, focusing on three categories: topology-based methods, dynamics-based methods, and machine learning-based methods. However, topology-based methods tend to consider single temporal features, while the consideration of multi-temporal features is subject to the same challenges of high temporal complexity as dynamics-based methods, and machine learning-based methods face challenges related to dependency on the training dataset. In this paper, we propose a novel centrality algorithm based on multiple diffusion information (RPT: Multi-diffusion information centrality based on R-path trees) to identify the influential node in a temporal social network. This algorithm considers three different temporal features and has lower temporal complexity using a newly proposed representation structure known as an R-path tree (a distinctive inverted tree that encompasses the earliest arrival paths from other nodes to the root node). Through experiments carried out on 12 empirical social networks, the results show that the effectiveness of RPT in identifying influential spreaders generally exceeds that of other baseline measures.
Xuelong Yu, Shukun Yang, Hai Zhao 0002, Kuan Zhang 0001, Chong Yu 0002
IEEE Internet Things J.5
2025 MU-MRQ: Enabling Multi-User Verifiable and Secure Multi-Dimensional Range Query Over Encrypted Data
abstract
In recent years, multi-dimensional range query (MRQ) over encrypted data has been increasingly applied in various scenarios, making it one of the mainstream services for secure large-scale data storage and sharing in cloud computing. However, although existing privacy-preserving MRQ schemes can ensure query and data privacy, they still fail to fully protect single-dimensional privacy and path pattern. Moreover, most schemes lack mechanisms to verify the completeness and correctness of query results, making it impossible to guarantee their validity. To address these issues, this paper proposes a secure and efficient MRQ scheme with result verification for multiple users (MU-MRQ). First, we design a secure and efficient multi-dimensional data index based on the G-tree, incorporating a timestamp mechanism to verify the correctness and completeness of query results. Additionally, we propose two novel intersection predicate encryption protocols to achieve efficient retrieval while preserving single-dimensional privacy and path pattern. Rigorous security analysis demonstrates that our MU-MRQ scheme achieves security under the known background model. Comprehensive experiments on real-world datasets validate the efficiency of the MU-MRQ scheme.
Haoyang Wang 0005, Kai Fan 0001, Kuan Zhang 0001, Fenghua Li 0001, Hui Li 0006, Yintang Yang
IEEE Trans. Dependable Secur. Comput.3
2025 PDSA-FL: A Poisoning-Defense Secure Aggregation in Federated Learning
abstract
Federated learning (FL) has become a promising technology to provide edge Artificial Intelligence (AI) due to its advantages in privacy protection and reduced communication costs. However, FL is still confronted with privacy leakage issues because the sharing local model may expose the training data information. Existing works typically utilize secure aggregation techniques to eliminate privacy leakage, where local model parameters in FL are obfuscated before they are sent to the aggregator. Nevertheless, secure aggregation makes poisoning attacks more convenient given that existing anomaly detection methods mostly require access to plaintext local models. A Poisoning-Defense Secure Aggregation in FL (PDSA-FL) is proposed to enhance the privacy protection of honest clients and defend against poisoning attacks from malicious clients. Specifically, a Secure Aggregation scheme based on Random Parameters Decomposition (SARPD) is designed to protect client privacy during the FL aggregation process and eliminates the impact of dropped clients on the aggregation results. Secondly, a Poisoning Detection method based on Similarity Grouping (PDSG) is proposed to mitigate the impact of poisoning attacks on the global model of FL without leaking client model parameters. The security analysis discusses the effectiveness of the proposed PDSA-FL in terms of privacy protection. Extensive simulation results show that PDSA-FL can effectively defend against poisoning attacks, significantly improve the convergence performance of global models, and reduce the computation time of clients.
Zixuan Huang 0007, Yuanguo Bi, Kuan Zhang 0001, Zhou Su 0001, Chong Tai, Xukun Luan
IEEE Trans. Inf. Forensics Secur.3
2025 Beyond Access Pattern: Efficient Volume-Hiding Multi-Range Queries Over Outsourced Data Services
abstract
Multi-range query (MRQ) is a typical multi-attribute data query widely used in various practical applications. It is capable of searching all data objects contained in a query request. Many privacy-preserving MRQ schemes have been proposed to realize MRQ on encrypted data. However, existing MRQ schemes only consider the security threat caused by access pattern leakage, not the harm of volume pattern leakage. Moreover, most existing schemes cannot achieve efficient queries and updates while preserving the access pattern. In this paper, we propose an efficient MRQ scheme for hiding volume and access patterns. We first design a joint data index using Order-Revealing Encryption (ORE) and Pseudo-random functions (PRFs) to realize volume-hiding range queries. Then, we combine the private set intersection (PSI) and hardware Software Guard Extensions (SGX) to compute each attribute’s intersection of query results. In addition, we preserve access patterns during queries by designing a batch refresh algorithm and an update protocol. Finally, rigorous security analysis and extensive experiments demonstrate the security and performance of our scheme in real-world scenarios.
Haoyang Wang 0005, Kai Fan 0001, Chong Yu 0002, Kuan Zhang 0001, Fenghua Li 0001, Haojin Zhu
IEEE Trans. Inf. Forensics Secur.4
2025 Hide Yourself: Multi-Dimensional Range Queries for Responses-Hiding Over Outsourced Data
abstract
Multi-dimensional range query (MRQ) over outsourced data has been extensively applied in various domains. However, security and efficiency are still two aspects that cannot be easily balanced in private MRQs, as improving security inevitably incurs high computation, storage, and communication costs. Several schemes perform encrypted data retrieval in the trusted execution environment (TEE), which balances security and performance. Unfortunately, they focused on keywords or single-dimensional range queries, failing to address private MRQs. With the TEE (i.e., Intel SGX), we propose a response-hiding MRQ scheme over encrypted data (SGX-MRQ) in this paper. We first design an index structure called SDic, which can achieve efficient range queries while hiding the responses to each query from the server. Moreover, based on the security properties of SGX, we construct the encrypted polynomials of each dimension on the enclave and implement the intersection computation of multi-attribute queries by the server, which greatly improves the system efficiency. We present the formal definition of SGX-MRQ and perform a rigorous proof. We implement a prototype of SGX-MRQ and conduct extensive experiments on real datasets. The evaluation results validate the feasibility of our scheme in practical applications.
Haoyang Wang 0005, Kai Fan 0001, Chong Yu 0002, Kuan Zhang 0001, Fenghua Li 0001, Haojin Zhu
IEEE Trans. Inf. Forensics Secur.4
2025 Enabling Gradient Inversion Attack Against SplitFed Learning via L2 Norm Amplification
abstract
SplitFed Learning (SFL) represents a compelling distributed learning paradigm tailored for resource-constrained edge computing scenarios, wherein the privacy threat posed by Gradient Inversion Attacks (GIA) remains challenging. The unique architecture of SFL restricts the fed server’s access only to the client-side model’sdeficient gradients, which lack essential information about the original data. This absence of complete gradient information hinders traditional GIA methods, which rely on complete gradient information for effective data reconstruction, thereby significantly diminishing their effectiveness in the SFL context. In this paper, we propose a novel attack against SFL calledDeficient Gradient-based Inversion Attack(DGIA), which reconstructs original training data by artificially amplifying the ℓ2norm of deficient gradients. Through extensive evaluation of how GIA performance varies with different gradient magnitudes, we observe a definitive correlation between the gradient ℓ2norm and attack performance. Based on this correlation, we further optimize DGIA to identify the optimal gradient amplification scale that maximizes the information encoded in deficient gradients. This compensates for the restricted access to complete gradients and enhances the attack performance. We conduct extensive experiments to demonstrate DGIA’s performance across various SFL scenarios compared with other GIA schemes and show attack efficacy under general defenses.
Jianan Zhao 0005, Wenjuan Tang, Kuan Zhang 0001, Hongbo Jiang 0001
IEEE Trans. Inf. Forensics Secur.3
2025 Joint Communication and Control Optimization of a Multi-Vehicle Platooning System
abstract
In the context of vehicle-road-cloud integration, multi-vehicle platooning systems have become an important approach for improving road traffic efficiency, driver comfort, driving safety, energy consumption, and mitigating traffic congestion. However, under high-speed mobility, Vehicle-to-Vehicle (V2V) communication within multi-vehicle platoons is susceptible to delays caused by interference and the inherent uncertainties of wireless communication channels. These delays present considerable challenges to achieving effective multi-vehicle cooperative control. To overcome the limitations of existing research, this paper proposes a joint communication and control optimization strategy for multi-vehicle platooning systems. A novel spacing error metric is introduced, which uses the real-time velocity of each vehicle to improve the platooning system responsiveness. Furthermore, we derive the Signal-to-Interference-plus-Noise Ratio (SINR) threshold to ensure the stability and reliability of the platoon. This ensures safe distances and synchronized speeds among all vehicles, even when communication delays occur. Finally, the proposed joint optimization strategy is validated through performance comparisons, demonstrating its effectiveness and superior performance.
Xuelong Yu, Fa Zhu, Xingchi Chen, Kuan Zhang 0001, Chong Yu 0002, Hai Zhao 0002, Athanasios V. Vasilakos
IEEE Trans. Intell. Transp. Syst.5
2025 Secure and Efficient Federated Learning Against Model Poisoning Attacks in Horizontal and Vertical Data Partitioning
abstract
In distributed systems, data may partially overlap in sample and feature spaces, that is, horizontal and vertical data partitioning. By combining horizontal and vertical federated learning (FL), hybrid FL emerges as a promising solution to simultaneously deal with data overlapping in both sample and feature spaces. Due to its decentralized nature, hybrid FL is vulnerable to model poisoning attacks, where malicious devices corrupt the global model by sending crafted model updates to the server. Existing work usually analyzes the statistical characteristics of all updates to resist model poisoning attacks. However, training local models in hybrid FL requires additional communication and computation steps, increasing the detection cost. In addition, due to data diversity in hybrid FL, solutions based on the assumption that malicious models are distinct from honest models may incorrectly classify honest ones as malicious, resulting in low accuracy. To this end, we propose a secure and efficient hybrid FL against model poisoning attacks. Specifically, we first identify two attacks to define how attackers manipulate local models in a harmful yet covert way. Then, we analyze the execution time and energy consumption in hybrid FL. Based on the analysis, we formulate an optimization problem to minimize training costs while guaranteeing accuracy considering the effect of attacks. To solve the formulated problem, we transform it into a Markov decision process and model it as a multiagent reinforcement learning (MARL) problem. Then, we propose a malicious device detection (MDD) method based on MARL to select honest devices to participate in training and improve efficiency. In addition, we propose an alternative poisoned model detection (PMD) method considering model change consistency. This method aims to prevent poisoned models from being used in the model aggregation. Experimental results validate that under the random local model poisoning attack, the proposed MDD method can save over 50% training costs while guaranteeing accuracy. When facing the advanced adaptive local model poisoning (ALMP) attack, utilizing both the proposed MDD and PMD methods achieves the desired accuracy while reducing execution time and energy consumption.
Chong Yu 0002, Zhenyu Meng, Wenmiao Zhang, Lei Lei 0004, Jianbing Ni, Kuan Zhang 0001, Hai Zhao 0002
IEEE Trans. Neural Networks Learn. Syst.6
2025 Communication-Efficient Hybrid Federated Learning for E-Health With Horizontal and Vertical Data Partitioning
abstract
Electronic healthcare (e-health) allows smart devices and medical institutions to collaboratively collect patients' data, which is trained by artificial intelligence (AI) technologies to help doctors make diagnosis. By allowing multiple devices to train models collaboratively, federated learning is a promising solution to address the communication and privacy issues in e-health. However, applying federated learning in e-health faces many challenges. First, medical data are both horizontally and vertically partitioned. Since single horizontal federated learning (HFL) or vertical federated learning (VFL) techniques cannot deal with both types of data partitioning, directly applying them may consume excessive communication cost due to transmitting a part of raw data when requiring high modeling accuracy. Second, a naive combination of HFL and VFL has limitations including low training efficiency, unsound convergence analysis, and lack of parameter tuning strategies. In this article, we provide a thorough study on an effective integration of HFL and VFL, to achieve communication efficiency and overcome the above limitations when data are both horizontally and vertically partitioned. Specifically, we propose a hybrid federated learning framework with one intermediate result exchange and two aggregation phases. Based on this framework, we develop a hybrid stochastic gradient descent (HSGD) algorithm to train models. Then, we theoretically analyze the convergence upper bound of the proposed algorithm. Using the convergence results, we design adaptive strategies to adjust the training parameters and shrink the size of transmitted data. The experimental results validate that the proposed HSGD algorithm can achieve the desired accuracy while reducing communication cost, and they also verify the effectiveness of the adaptive strategies.
Chong Yu 0002, Shuaiqi Shen, Shiqiang Wang 0001, Kuan Zhang 0001, Hai Zhao 0002
IEEE Trans. Neural Networks Learn. Syst.4
2024 Secure Interaction-Based Feature Selection for Vertical Federated Learning
abstract
Federated learning enables decentralized data own-ers to collaborate and train models in a distributed manner. A special type is Vertical Federated Learning (VFL), where each of the participated data owners only has a portion of the data features. To maintain a high accuracy and reasonable computational cost, selecting a set of features among the entire dataset is essential. Although some existing work selects features by calculating their individual contributions to the learning outcomes, knowing the joint contribution from multiple features becomes necessary but challenging. Meanwhile, security concerns are raised when calculating the joint contribution of a set of features where the feature data are stored by different owners. Using homomorphic encryption or secure computing over en-crypted data is possible, but it may cost too much when complex calculations are involved and repeated. To this end, this paper proposes a privacy-preserving feature selection protocol that considers the interactions between features stored across different data owners. Specifically, we first propose an interaction-based feature selection algorithm for vertically distributed datasets. This algorithm estimates the features' joint contributions to the model training outcomes. Then, we propose a privacy-preservation protocol to prevent the semi-honest cloud server from obtaining or inferring the raw data when aggregating the knowledge and calculating the complex interaction measure for feature selection. We create a new approximation method for interaction measures to address the high computational cost when securely calculating the interaction measure while maintaining the training accuracy. The security discussions show that the proposed protocol preserves data owner's privacy. The extensive simulations validate the achieved training accuracy and efficiency.
Zhenyu Meng, Wenmiao Zhang, Shuaiqi Shen, Chong Yu 0002, Kuan Zhang 0001
ICC5
2024 Explore Patterns to Detect Sybil Attack during Federated Learning in Mobile Digital Twin Network
abstract
Digital twins represent users in the cyber world and interact between users and network controllers to better manage the mobile network. Due to communications and other resource constraints, transmitting raw data for a traditional, centralized machine learning in the mobile network has been replaced by federated learning. Federated learning allows participants to train a complex model in a distributed manner, through a group of participants' local training and a global aggregation with model updates as feedback. Although federated learning can save communications costs, address data heterogeneity and protect privacy by stopping the raw data transmission, it faces various se-curity challenges. For example, poisoning attacks may inject false models or modify existing model parameters to bias the gradient descent of federated learning. Some literature attempted to detect poisoning attacks, but the attackers can still strengthen their power by creating many identities to build their group advantage, which overturns the existing detection. In this paper, we propose a digital-twin-based Sybil detection by creating new community detection among participants in federated learning. Specifically, we first identify Sybil attackers on several levels according to their attacking strength and strategies. Then, we integrate digital twins as a side channel to distinguish Sybil identities which in fact belong to the same attacker. This could leak the attacker's correlated behavior patterns which are automatically recorded in digital twins. Under this observation, we build a DT-graph that tightly connects Sybil-controlled identities belonging to the same attacker. We propose a graph-based community detection algorithm to further partition the DT-graph and distinguish Sybil attacks. Extensive simulations validate our proposed method compared with existing work.
Wenmiao Zhang, Chong Yu 0002, Zhenyu Meng, Shuaiqi Shen, Kuan Zhang 0001
ICC5
2024 SC-Chain: An Efficient Blockchain Framework for Smart City
abstract
To overcome the challenges of urbanization and population growth, smart cities use cutting-edge technologies, such as IoT and AI to offer improved public services. Although these advancements have brought convenience, they have raised security and privacy concerns. Blockchain technology has the potential to address these concerns, but existing blockchain frameworks have issues of scalability and efficiency that hinder their ability to meet the smart city demands. In this article, we propose a novel blockchain framework for smart cities, named SC-Chain. Specifically, SC-Chain incorporates a decentralized access mechanism that leverages threshold signatures and BFT-like consensus for efficient node registration and authentication in decentralized systems. Furthermore, we propose a consensus mechanism that utilizes the verifiable random function (VRF) to achieve efficient miner node election, ensuring efficiency, fairness, and security in large-scale smart city systems. We demonstrate the effectiveness and feasibility of the SC-Chain through theoretical analysis and simulations, showcasing its potential to enable the development of secure and efficient smart city infrastructure.
Kai Fan 0001, Hengrui Lu, Yuhan Bai, Yintang Yang, Kuan Zhang 0001, Hui Li 0006
IEEE Internet Things J.6
2024 CR-FH-CPABE: Secure File Hierarchy Attribute-Based Encryption Scheme Supporting User Collusion Resistance in Cloud Computing
abstract
The attribute-based encryption (ABE) scheme, which can set specific conditions to control user access to data, has been widely studied and applied to cloud storage services. Considering file hierarchy in practical scenarios, the ABE scheme can set a hierarchical access control policy so multiple files can be associated with one access structure to reduce users’ computing overhead and save the cloud server’s storage space. However, the existing systems have the risk of user collusion due to the hierarchical access control structure parameters. This paper proposes a secure file hierarchy ABE scheme supporting user collusion resistance (CR-FH-CPABE) in cloud computing. We add a data noise vector without changing the hierarchical access control structure to prevent user ultra vires. Technically, we break the relationships that colluding users could exploit, prevent malicious users from colluding with their computing results, and extract meaningful information from the ciphertext. In addition, we provide an improved CR-FH-CPABE scheme with outsourced decryption, which helps resource-limited devices obtain computing services. Finally, we demonstrate our scheme is CPA secure and show outstanding performance through simulation results.
Yuhan Bai, Kai Fan 0001, Kuan Zhang 0001, Hui Li 0006, Yintang Yang
IEEE Internet Things J.3
2024 Fault-Tolerant and Collusion-Resistant Lattice-Based Multidimensional Privacy-Preserving Data Aggregation in Edge-Based Smart Grid
abstract
The smart grid, which is an important component of smart cities, is developing rapidly nowadays, while the confidentiality and integrity of consumption data of customers become significant security issues. Although existing privacy-preserving aggregation schemes reduce the communication overhead and protect the privacy of users’ multidimensional power data, most of them are vulnerable and possess no quantum-resistant properties. In this article, we combine the Chinese remainder theorem (CRT) and the bit decomposition method to provide multibit homomorphic properties for the quantum-resistant algorithm number theory research unit (NTRU), and propose the partial-homomorphic NTRU (PH-NTRU). Then, based on the algorithm, we design the lattice-based multidimensional data privacy-preserving data aggregation scheme named FTCR-LMPPDA, in which the edge devices work as aggregator gateways. Specifically, smart meters participating in the aggregation process share zero-sum numbers to resist collusion attacks. Error retransmission mechanism and random number reconstruction algorithm are introduced to enhance the robustness of this scheme and provide our system with the ability to recover from faults. In addition, security analysis shows our scheme can resist quantum attacks, collusion attacks, and other internal and external attacks as well as keep the security features, such as confidentiality, privacy and integrity of users’ data. Finally, performance evaluation demonstrates that our scheme is more efficient than existing schemes and is more suitable for devices with constrained resources.
Kai Fan 0001, Yuanshuai Ren, Yuhan Bai, Guanglu Wei, Kuan Zhang 0001, Hui Li 0006, Yintang Yang
IEEE Internet Things J.5
2024 Ciphertext Retrieval With Identity Bidirectional Authentication and Matrix Index in IoT
abstract
Ciphertext retrieval for cloud-based Internet of Things has been widely explored with the increasing popularity of cloud computing. However, in most existing solutions, the security and efficiency of the retrieval process are difficult to achieve simultaneously. To this end, we develop a novel secure matrix index, and we utilize identity-based encryption to encrypt keywords and homomorphic encryption to encrypt matrix values. The former can guarantee the security of the keyword, and the latter can realize the efficiency of the operation while ensuring safety. Then, we develop an identity-based bidirectional authentication algorithm to ensure that only authenticated users can retrieve ciphertext. In addition, we use different scoring formulas to calculate the relevance scores of documents with different lengths, ensuring that the documents are appropriately returned to users. Finally, we design a new retrieval structure to protect the privacy of the correspondence between keywords and ciphertexts. The security proof shows that the index and trapdoor can resist chosen keyword attack and keyword Guessing attack. The extensive simulation shows that our scheme is efficient.
Nan Gao 0003, Kai Fan 0001, Haoyang Wang 0005, Kuan Zhang 0001, Hui Li 0006, Yintang Yang
IEEE Internet Things J.5
2024 Public-Key Inverted-Index Keyword Search With Designated Tester and Multiuser Key Decryption in IoT
abstract
Searchable encryption for Cloud-based Internet of Things has been widely explored with the increasing popularity of cloud computing. The public-key encryption with keyword search (PEKS) system support multiuser retrieval. However, the PEKS search time is linearly increasing as the index keyword number growth, and the search time would be huge if the index keywords consistently increase. In this article, we introduce a novel scheme named as public-key inverted-index keyword search with designated tester and multiuser key decryption (IDPEKS). First of all, we design an inverted index based on B-plus tree to reduce the search time to a logarithmic level. On this basis, we optimized the TF-IDF formula and added user preference factor and font size factor to make the relevance score calculation more consistent with needs of receiver. Besides, we design a multiuser key decryption algorithm to protect the system symmetric key. In addition, we set index server to perform the index-trapdoor retrieval process. The designated index server tester can resist the attack of the cloud server on keywords. The security proof shows that the scheme can resist the chosen keyword attack (CKA), keyword guessing attack (KGA), and key guessing attack (KeyGA). The experimental results show that the algorithm can improve retrieval efficiency while have a short encryption time.
Nan Gao 0003, Kai Fan 0001, Haoyang Wang 0005, Kuan Zhang 0001, Hui Li 0006, Yintang Yang
IEEE Internet Things J.4
2024 Quantum-Safe Lattice-Based Certificateless Anonymous Authenticated Key Agreement for Internet of Things
abstract
In recent years, the Internet of Things (IoT) has gained immense popularity in various aspects of work, learning, and daily life. Within the IoT realm, there is a growing concern regarding communication security issues between users and servers. However, addressing the communication security between servers is equally imperative, which has not received as much attention. To this end, we propose a certificateless anonymous authenticated key agreement (AKA) algorithm based on learning with errors (LWEs) and inhomogeneous small integer solution (ISIS) security assumptions. Our scheme provides strong resistance to quantum attacks and protects the privacy of communication servers. It also has constant communication costs and lower computational requirements than existing lattice-based anonymous AKA algorithms on the broadcast channel. Additionally, the proposed scheme eliminates the resource consumption of managing complex certificates and addresses the security risks associated with key escrow in the key generation center (KGC). Through security and performance analysis, we demonstrate that our approach can enhance the security of IoT-based healthcare systems while significantly improving communication efficiency. Our proposed scheme provides a promising solution to security issues related to server communication in IoT systems.
Guanglu Wei, Kai Fan 0001, Kuan Zhang 0001, Haoyang Wang 0005, Hui Li 0006, Yintang Yang
IEEE Internet Things J.3
2024 LsiA3CS: Deep-Reinforcement-Learning-Based Cloud-Edge Collaborative Task Scheduling in Large-Scale IIoT
abstract
Task scheduling in large-scale industrial Internet of Things (IIoT) is characterized by the presence of diverse resources and the requirement for efficient and synchronized processing across distributed edge clouds, raising a significant challenge. This paper proposes a task scheduling framework across edge clouds, namely LsiA3CS, which employs deep reinforcement learning (DRL) and heuristic guidance to achieve distributed, asynchronous task scheduling for large-scale IIoT. Specifically, the Markov game-based model and the asynchronous advantage actor-critic (A3C) algorithm are leveraged to orchestrate diverse computational resources, effectively balancing workloads and reducing communication latency. Moreover, the incorporation of heuristic policy annealing and action masking techniques further refines the adaptability of the proposed framework to the unpredictable requirements of large-scale IIoT systems. Real-world task datasets are utilized to conduct extensive experimental evaluations on a simulated large-scale multi-edge cloud IIoT. The results shows that LsiA3CS significantly reduces task completion times and energy consumption while managing unpredictable task arrivals and variable resource capacities.
Fengli Zhang, Zehui Xiong, Kuan Zhang 0001, Dajiang Chen
IEEE Internet Things J.4
2024 Lower rounds lattice-based anonymous AKA under the seCK model for the IoT
Guanglu Wei, Kai Fan 0001, Kuan Zhang 0001, Haoyang Wang 0005, Kan Yang 0001, Hui Li 0006, Yintang Yang
Peer Peer Netw. Appl.3
2024 MFSSE: Multi-Keyword Fuzzy Ranked Symmetric Searchable Encryption With Pattern Hidden in Mobile Cloud Computing
abstract
In this paper, we propose a novel Multi-keyword Fuzzy Symmetric Searchable Encryption (SSE) with patterns hidden, namely MFSSE. In MFSSE, the search trapdoor can be modified differently each time even if the keywords are the same when performing multi-keyword search to prevent the leakage of search patterns. Moreover, MFSSE modifies the search trapdoor by introducing random false negative and false positive errors to resist access pattern leakage. Furthermore, MFSSE utilizes efficient cryptographic algorithms (e.g., Locality-Sensitive Hashing) and lightweight operations (such as, integer addition, matrix multiplication, etc.) to minimize computational and communication, and storage overheads on mobile devices while meeting security and functional requirements. Specifically, its query process requires only a single round of communication, in which, the communication cost is linearly related to the number of the documents in the database, and is independent of the total number of keywords and the number of queried keywords; its computational complexity for matching a document is$O(1)$; and it requires only a small amount of fixed local storage (i.e., secret key) to be suitable for mobile scenarios. The experimental results demonstrate that MFSSE can prevent the leakage of access patterns and search patterns, while keeping a low communication and computation overheads.
Dajiang Chen, Zeyu Liao, Zhidong Xie, Rui-dong Chen, Zhen Qin 0002, Mingsheng Cao 0001, Hongning Dai, Kuan Zhang 0001
IEEE Trans. Cloud Comput.8
2024 Privacy-Preserving Anomaly Detection of Encrypted Smart Contract for Blockchain-Based Data Trading
abstract
In a blockchain-based data trading platform, data users can purchase data sets and computing power through encrypted smart contracts. The security of smart contracts is important as it relates to that of the data platform. However, due to the inability to apply to detection rules with complex structures and the inefficiency of detection, existing malicious code detection methods are not suitable for the encrypted smart contracts in blockchain-based data trading platforms with high transaction rate requirements. In this paper, a practical and privacy-preserving malicious code detection method is proposed for encrypted smart contract in blockchain-based data trading platform. Specifically, we design two kinds of miners to act as the malicious rule processor and the detector respectively for inspecting the encrypted smart contract. The rule processor generates an obfuscated map with the original open-source malicious rule set. The detector performs a malicious inspection algorithm by inputting the obfuscated map and the randomized tokens, where the latter is generated from smart contract. Then, we theoretically analyze the security syntax of the proposed method. The analysis results demonstrate the proposed scheme can achieve$\mathcal {L}$-secure against adaptive attacks. Extensive experiments are carried out through the open-source real rule sets, which show that the proposed scheme can reduce communication time and communication overhead.
Dajiang Chen, Zeyu Liao, Rui-dong Chen, Hao Wang 0229, Chong Yu 0002, Kuan Zhang 0001, Ning Zhang 0007, Xuemin Shen
IEEE Trans. Dependable Secur. Comput.6
2024 LSPSS: Constructing Lightweight and Secure Scheme for Private Data Storage and Sharing in Aerial Computing
abstract
Aerial computing is gradually playing an essential role in edge and fog computing paradigms by virtue of mobility, availability, scalability, flexibility, and simultaneity, where the Low-altitude Computing (LAC) platform, as the end close to the data sources, is mainly responsible for data collection and storage. However, because of the long physical distance of data transmission and the vulnerability of the transmission link to various attacks, how to efficiently share the stored data while ensuring data privacy is a critical issue for LAC at present. In this paper, we propose a lightweight and secure private data storage and sharing scheme to support range queries over encrypted multi-dimensional data. Specifically, we first propose two data conversion methods for transforming location features and collected log files with multi-dimensional attributes in Unmanned Aerial Vehicles (UAVs). Based on the ideas of asymmetric scalar-product-preserving encryption (ASPE) and inner product comparison (IPC), we design a privacy-preserving storage and sharing technique for the converted data. In addition, to achieve secure and efficient data querying and result verification, we design a secure data index and build a data authentication structure (DAS) with G-tree. Finally, we rigorously analyze the security of our proposed scheme and conduct extensive experiments on a real-world database to prove that our proposed scheme is secure and easy to use in practical application scenarios.
Haoyang Wang 0005, Kai Fan 0001, Chong Yu 0002, Kuan Zhang 0001, Fenghua Li 0001, Hui Li 0006, Yintang Yang, Haojin Zhu
IEEE Trans. Serv. Comput.4
2023 A Secure and Efficient Two-Party Protocol Enabling Ownership Transfer of RFID Objects
abstract
Modern business models improve the efficiency of supply chain management by attaching tags to products. These tagged products typically change owners multiple times during their life cycles. The ownership transfer protocol authorizes the new owner by replacing the old owner’s authentication information stored in the tag with the new owner’s. Until now, a considerable amount of literature has proposed solutions to the problem of RFID ownership transfer. Unfortunately, these existing protocols are either flawed in some security properties especially in protecting new and old owners’ privacy, or are associated with huge computational overheads. In this article, we propose an ultralightweight RFID ownership transfer protocol based on permutation function. The tag and reader only use efficient bit operations, which greatly reduce the computational overhead. An important feature of the proposed protocol is that the new owner can impose calculations on data that has been encrypted by the old owner. The new owner is authorized by the old owner and does not have access to the tag’s key, which protects the old owner’s privacy stored in the tag side. We compare our protocol with existing work, and show the advantages in terms of security, computational overhead, and time cost.
Ye Bi, Kai Fan 0001, Kuan Zhang 0001, Yuhan Bai, Hui Li 0006, Yintang Yang
IEEE Internet Things J.3
2023 Autonomous Platoon Control With Integrated Deep Reinforcement Learning and Dynamic Programming
abstract
Autonomous vehicles in a platoon determine the control inputs based on the system state information collected and shared by the Internet of Things (IoT) devices. Deep reinforcement learning (DRL) is regarded as a potential method for car-following control and has been mostly studied to support a single following vehicle. However, it is more challenging to learn an efficient car-following policy with convergence stability when there are multiple following vehicles in a platoon, especially with unpredictable leading vehicle behavior. In this context, we adopt an integrated DRL and dynamic programming (DP) approach to learn autonomous platoon control policies, which embeds the deep deterministic policy gradient (DDPG) algorithm into a finite-horizon value iteration framework. Although the DP framework can improve the stability and performance of DDPG, it has the limitations of lower sampling and training efficiency. In this article, we propose an algorithm, namely, finite-horizon-DDPG with sweeping through reduced state space using stationary approximation (FH-DDPG-SS), which uses three key ideas to overcome the above limitations, i.e., transferring network weights backward in time, stationary policy approximation for earlier time steps, and sweeping through reduced state space. In order to verify the effectiveness of FH-DDPG-SS, simulation using real driving data is performed, where the performance of FH-DDPG-SS is compared with those of the benchmark algorithms. Finally, platoon safety and string stability for FH-DDPG-SS are demonstrated.
Tong Liu 0035, Lei Lei 0004, Kan Zheng, Kuan Zhang 0001
IEEE Internet Things J.4
2023 MSIAP: A Dynamic Searchable Encryption for Privacy-Protection on Smart Grid With Cloud-Edge-End
abstract
With the advent of 5G and the Internet of Things, edge computing and cloud computing with their respective strengths are bound as Cloud-Edge-End Orchestrated (CEEO). The CEEO network integrates artificial intelligence and provides innovative technologies for smart grid applications and services. With massive data transmission on the CEEO network, the trustworthiness of the service node exerts an enormous influence on data privacy. To realize securely share data and decrease the local storage, end-user prefer to encrypt data and upload it to the cloud. Meanwhile, the challenge is how to balance efficiency and security perfectly when users need to find relevant documents containing specific keywords from the CEEO network. In this article, we innovatively propose a searchable encryption scheme that supports multi-keyword subset retrieval, named MSIAP. Specifically, we enhance the Apriori, a data mining algorithm, to mine the relevance of files from massive information and build a multi-level index structure. On this basis, we achieve efficient multi-keyword subset retrieval and dynamic update with insignificant information disclosure in the smart grid. Furthermore, our MSIAP strengthens the present data retrieval methods and enormously reduces the time complexity to accommodate the system of distributed smart grid. Finally, we provide the security analysis and performance evaluations by comparing them with existing works.
Kai Fan 0001, Ruidan Su, Kuan Zhang 0001, Haoyang Wang 0005, Hui Li 0006, Yintang Yang
IEEE Trans. Cloud Comput.4
2023 Collusion Detection and Trust Management for Indoor Navigation System With Crowdsourcing
abstract
The indoor navigation system supported by spatial crowdsourcing emerges as a promising application to provide customized location service for requesters. An important stage of crowdsourcing is to select trustworthy workers. Workers’ reputation, as an essential criterion of this selection, is usually evaluated by feedback ratings from requesters. However, the reputation in the crowdsourcing-based indoor navigation system is vulnerable to the collusion attack, that is malicious workers (i.e., attackers) collude with requesters to illegally increase reputation. In this paper, we propose a collusion detection scheme to distinguish attackers and provide a secure reputation mechanism. Specifically, we first identify collusive requesters categorized into three different levels according to their feedback rating behaviors. Then, the weighted logistic regression (WLR) is developed to distinguish the collusive requesters who provide exorbitant feedback ratings. Furthermore, we employ an outlying sequence detection based on the maximum mean discrepancy (MMD), to resist the multiple location queries initiated by the same collusive requester through analyzing the distribution distance. In addition, we propose a community detection algorithm, named Fastgreedy, to identify the collusion from many requesters. Finally, the extensive simulation results demonstrate that the proposed scheme can effectively detect collusive requesters and significantly outperform other methods.
Weiwei Li 0007, Mi Wen, Zhou Su 0001, Kuan Zhang 0001
IEEE Trans. Dependable Secur. Comput.4
2023 Joint Biological ID : A Secure and Efficient Lightweight Biometric Authentication Scheme
abstract
Biometric applications makes biometric authentication replace the traditional password in many cases. Biometric recognition technology has the advantages of convenience and high stability, facilitating identity recognition. However, the shortcoming of biometric authentication is easy to be stolen and leaked, which raises security concerns. In this paper, we design a lightweight joint biometric authentication scheme (SELBA) based on face and fingerprint. We improve searchable encryption (SE) to protect the privacy security of extracted biometric features in the storage and authentication stage. Because of the problem that biometric features cannot be changed or retrieved once leaked in existing schemes, we propose a cancelable mechanism to reconstruct stolen or damaged biometric templates. Moreover, we make a complete security analysis of the SELBA to meet the confidentiality, renewability, revocability, irreversibility and unlinkability of template in biometric recognition. Meanwhile, we conduct experiments on real data sets to show that SELBA is secure, efficient and easy to use in practical application scenarios.
Haoyang Wang 0005, Kai Fan 0001, Kuan Zhang 0001, Fenghua Li 0001, Hui Li 0006, Yintang Yang
IEEE Trans. Dependable Secur. Comput.5
2023 Reservoir Inflow Forecasting in Hydropower Industry: A Generative Flow-Based Approach
abstract
Forecasting the inflow of reservoirs plays an essential role in the hydropower industry. Existing studies are either limited to point estimates or inefficient in capturing higher-order dynamic correlations across data. It is nevertheless necessary to estimate data uncertainty in actual dam operation. This article presents a novel inflow prediction method that exploits generative flows to model complex multivariate hydrological time series. Our flow-to-flow method (F2F) augments the deterministic models with the normalizing flow-based generative networks to explicitly capture the multivariate correlations and approximate the predictive inflow distribution. Besides, F2F can quantify the prediction uncertainty to help interpret model behavior and predicted results while facilitating safety-critical decision-making on real-time reservoir operation. We conduct extensive experiments on real-world datasets collected from large-scale hydropower stations. The experimental results show that our method consistently outperforms existing methods while accounting for uncertain observations and providing tractable multistep ahead inflow forecasts.
Fan Zhou 0002, Zhiyuan Wang 0006, Dajiang Chen, Kuan Zhang 0001
IEEE Trans. Ind. Informatics4
2023 P2AE: Preserving Privacy, Accuracy, and Efficiency in Location-Dependent Mobile Crowdsensing
abstract
With the widespread prevalence of smart devices, mobile crowdsensing (MCS) becomes a new trend to encourage mobile nodes to participate in cooperative data collection in various Internet of Things (IoT) applications. In location-dependent MCS, location information of mobile nodes are collected and analyzed by service provider to assist in task allocation. If the service provider is not fully trusted, mobile node's privacy is leaked and accessed by unauthorized parties. How to preserve privacy while maintaining task allocation accuracy and efficiency becomes challenging. To this end, we propose a learning-based mechanism that involves two parts: 1) privacy-preserving task release and task allocation; 2) accurate and efficient task allocation. In the first part, we design a location-based symmetric key generator, which enables two parties to self-generate a symmetric key without depending on fully trusted authorities. By utilizing this key generator and Proxy Re-encryption, we propose a privacy preserving protocol to protect location information in task release and task allocation. In the second part, we design a reinforcement learning based task allocation algorithm to optimize the winners selection, which obtains high accuracy and efficiency. The performance analysis reveals that our proposed mechanism achieves accurate and efficient task allocation while preserving privacy in location-dependent MCS.
Yili Jiang, Kuan Zhang 0001, Yi Qian 0001, Liang Zhou 0002
IEEE Trans. Mob. Comput.2
2022 Collaborative Edge Caching with Personalized Modeling of Content Popularity over Indoor Mobile Social Networks
abstract
Mobile social networks allow users to acquire multimedia contents to their mobile devices via wireless communications. To alleviate the network traffic and latency for transmitting contents, user preferences can be predicted and popular contents can be cached at the edge of network. However, for edge caching over the indoor mobile social networks raises challenging issues. The user preference for mobile data is location-dependent in different areas of indoor environment, such that various edge nodes need to maintain its distinctive prediction model instead of using the universal one. The limited computing power for edge nodes over indoor mobile social networks also hinders effective model training on the edge. In this paper, we propose a collaborative edge caching framework that enables personalized modeling for content popularity prediction. Specifically, a non-additive measure based feature selection scheme is proposed to realize efficient yet accurate modeling on resource-constrained edge nodes. A collaborative learning algorithm is designed to reduce the computational overheads over mobile social networks by extracting global knowledge on simplifying model training through feature selection. Extensive simulation validates the effectiveness and efficiency of our proposed framework.
Shuaiqi Shen, Chong Yu 0002, Kuan Zhang 0001, Song Ci
ICC3
2022 Efficient Multi-Layer Stochastic Gradient Descent Algorithm for Federated Learning in E-health
abstract
E-health systems consist of intelligent devices, medical institutions, edge nodes, and cloud servers to improve healthcare service quality and efficiency. In e-health systems, patients’ data are cooperatively collected by their wearable devices and the hospital they have visited, i.e., vertically distributed data. The data on wearable devices share the same feature set but are different in sample spaces, i.e., horizontally partitioned data. Meanwhile, hospitals target various user groups resulting in high data diversity, i.e., non-identically distributed data. These three characteristics cause that existing federated learning frameworks cannot efficiently train models on medical data. Furthermore, model training in e-health is time-sensitive because some diseases mutate very quickly and spread easily, which requires fast convergence of machine learning algorithms. In this paper, we address the problem of how to efficiently and rapidly train global models on e-health data. Specifically, we propose a multilayer federated learning framework to cope with data that are vertically, horizontally, and non-identically distributed. Moreover, we develop a Multi-Layer Stochastic Gradient Descent (MLSGD) algorithm towards the proposed framework to learn the optimal global model. To improve training efficiency, partial models learned by devices are aggregated on edge nodes before exchanging intermediate results with hospitals. The weight of local models is proportional to local data size when performing global aggregation to balance the impact of local models on the global model. We also prove the convergence of the MLSGD algorithm from a theoretical perspective. The experimental results from the real-world dataset MIMIC-III validate that the proposed algorithm converges fast and achieves desired accuracy.
Chong Yu 0002, Shuaiqi Shen, Shiqiang Wang 0001, Kuan Zhang 0001, Hai Zhao 0002
ICC4
2022 Thwarting Unauthorized Voice Eavesdropping via Touch Sensing in Mobile Systems
abstract
Enormous mobile applications (apps) now support voice functionality for convenient user-device interaction. However, these voice-enabled apps may spitefully invoke microphone to realize voice eavesdropping with arousing security risks and privacy concerns. To explore the issue of voice eavesdropping, in this work, we first design eavesdropping apps through native development and injection development to conduct eavesdropping attacks on a series of smart devices. The results demonstrate that eavesdropping could be carried out freely without any hint. To thwart voice eavesdropping, we propose a valid eavesdropping detection (EarDet) scheme based on the discovery that the activation of voice function in most apps requires authorization from the user by touching a specific voice icon. In the scheme, we construct a request-response time model using the Unix time stamps of touching the voice icon and microphone invoked. Through numerical analysis and hypothesis testing to effectively verify the pattern of the app’s normal access under user authorization to the microphone, we could detect eavesdropping attacks by sensing whether there is a touch operation. Finally, we apply the scheme to different smart devices and test several apps. The experimental results show that the proposed EarDet scheme can achieve a high detection accuracy.
Wenbin Huang 0003, Wenjuan Tang, Kuan Zhang 0001, Haojin Zhu, Yaoxue Zhang
INFOCOM3
2022 Preserving Location Privacy and Accurate Task Allocation in Edge-assisted Mobile Crowdsensing
abstract
Mobile crowdsensing enables collaborative data sensing between cloud server and mobile nodes. To participate in the sensing task, mobile nodes upload their locations to the centralized cloud for task allocation. However, revealing locations to an untrusted cloud results in privacy leakage, such as trajectories tracking and home address exposal, threatening the personal security. Obfuscation and cryptography based schemes are two main solutions to protect the location privacy. However, these schemes may either degrade the accuracy of task allocation or rely on some strong assumptions. Thus, how to protect location privacy without strong assumptions while remaining high accuracy in task allocation is challenging. In this paper, we propose a secure protocol for edge-assisted mobile crowdsensing, which removes the assumption that the cloud cannot collude with mobile nodes. Specifically, we deploy homomorphic encryption among service requestor, cloud server and edge nodes in a collaborative manner. Benefiting from the additive property of the cryptosystem, the cloud is able to securely calculate the mobile node’s travel distance while knowing nothing about the mobile mode’s location and task location. Based on the protocol, two types of location-dependent task allocation, travel distance based task allocation and spatial distribution based task allocation, can be implemented with location privacy preservation. Experimental results show the effectiveness of our work in task allocation. In addition, comprehensive privacy discussion indicates that the proposed protocol is secure from the collusion between cloud and mobile nodes, while preserving the task location and location privacy of mobile nodes.
Yili Jiang, Kuan Zhang 0001, Yi Qian 0001, Rose Qingyang Hu
WCNC2
2022 Energy-Aware Device Scheduling for Joint Federated Learning in Edge-assisted Internet of Agriculture Things
abstract
Edge-assisted Internet of Agriculture Things (Edge-IoAT) connects massive smart devices managed by edge nodes to collect crop data for distributed computing, such as federated learning, to guide agricultural production. In Edge-IoAT, data are cooperatively collected by edge nodes and the server, i.e., vertically partitioned. In addition, sample size and distribution are different for edge nodes, i.e., horizontally partitioned. Existing federated learning frameworks are not applicable for Edge-IoAT because they do not consider both types of data partitioning simultaneously. Moreover, the excessive energy consumption may cause premature interruption of model training, and spectrum scarcity prevents a portion of edge nodes from communicating with the server. Given limited energy and communication resources, training accuracy relies on how to schedule devices. In this paper, we first propose a joint federated learning framework for Edge-IoAT to cope with both vertically and horizontally partitioned data. After that, we formulate an energy-aware device scheduling problem to assign communication resources to the optimal edge node subset for minimizing the global loss function. Then, we develop a greedy algorithm to find the optimal solution. Experiments in a Nebraska farm show that the proposed framework with energy-aware device scheduling achieves a fast convergence rate, low communication cost, and high modeling accuracy under resource constraints.
Chong Yu 0002, Shuaiqi Shen, Kuan Zhang 0001, Hai Zhao 0002, Yeyin Shi
WCNC3
2022 Privacy-Preserving Encrypted Traffic Inspection With Symmetric Cryptographic Techniques in IoT
abstract
To ensure the security of Internet of Things (IoT) communications, one can use deep packet inspection (DPI) on network middleboxes to detect and mitigate anomalies and suspicious activities in network traffic of IoT, although doing so over encrypted traffic is challenging. Therefore, in this article, an efficient and privacy-preserving encrypted traffic detection scheme is proposed. The scheme uses only lightweight cryptographic operations (i.e., symmetric encryption, hash functions, and pseudorandom functions) to achieve both privacy and security within an inspection round. A dispute resolution mechanism is also designed to address potential disputes between client(s) and server(s). We also present the corresponding security proof and experimental evaluation, which demonstrate that our proposed scheme achieves strong security and privacy preservation and good performance.
Dajiang Chen, Hao Wang 0003, Ning Zhang 0007, Xuyun Nie, Hongning Dai, Kuan Zhang 0001, Kim-Kwang Raymond Choo
IEEE Internet Things J.6
2022 Encrypted Data Retrieval and Sharing Scheme in Space-Air-Ground-Integrated Vehicular Networks
abstract
As a smart transportation application of the Internet of Things, the Internet of Vehicles (IoV) depresses the chances of traffic accidents, while improving transportation efficiency and user driving experience. However, as the number of vehicles continues to grow, the original ground-based IoV system is difficult to meet the ever-increasing demand. To this end, space–air–ground-integrated network (SAGIN) incorporates satellite systems, aerial network and terrestrial communications. However, because SAGIN integrates multiple network services and communication modes, which makes SAGIN more vulnerable to various types of attacks and security threats. This article first presents the dominating security threats in data storage, transmission and sharing of space–air–ground integrated vehicular network (SAGIVN). Moreover, for guaranteeing the safety and effectiveness of the model, we advance a safe and effective encrypted data retrieval and sharing scheme in SAGIVN (ERDSS) for possible threats, the ERDSS can execute fuzzy retrieval over misspelling keywords and sort results by relevance scores to realize precise retrieval. We perform a comprehensive security discussion and execute experiments based on real-world data sets. The consequences demonstrate that the ERDSS is safe and efficient.
Haoyang Wang 0005, Kai Fan 0001, Kuan Zhang 0001, Zilong Wang 0001, Hui Li 0006, Yintang Yang
IEEE Internet Things J.3
2022 Secure and Efficient Data-Privacy-Preserving Scheme for Mobile Cyber-Physical Systems
abstract
Research on mobile cyber–physical systems (MCPSs) that have the superiorities of cyber–physical systems (CPSs) and expand their application range has become a trend in recent years. The applications of MCPS in fields, such as intelligent transportation systems, smart home appliances, and mobile education, have also become increasingly mature. However, MCPS also has some shortcomings that need to be solved urgently. Sensors carried on mobile devices collect data and upload huge amounts of data to the cloud for statistics and analysis. Mobile devices need to directly interact with the cloud, causing both parties to bear huge computing and communication costs. Since the interaction process includes data sharing and storage, it is particularly important to protect the data itself and the security of sharing. Searchable encryption ensures the safety of communication among the MPEs and the cloud, while protecting the privacy of data on the cloud. However, the existing searchable encryption technology cannot provide efficient and reliable data storage and sharing services for MPEs in MCPS under the premise of ensuring security. In this article, we present a secure and efficient data sharing and privacy protection scheme in MCPS on the basis of the edge computing model (NESPS). Meanwhile, the introduction of edge computing (EC) significantly reduces the communication consumption between the device and the cloud. Furthermore, attribute-based encryption (ABE) enables the NESPS to achieve fine-grained management of device authorities. Moreover, we have carried out security analysis and simulation on the NESPS, the results demonstrate that the NESPS meets the proposed requirements.
Haoyang Wang 0005, Kai Fan 0001, Kuan Zhang 0001, Zilong Wang 0001, Hui Li 0006, Yintang Yang
IEEE Internet Things J.3
2022 Leveraging Energy, Latency, and Robustness for Routing Path Selection in Internet of Battlefield Things
abstract
Internet of Battlefield Things (IoBT) connects massive tactical devices to collect battlefield situations and share perceived information. The IoBT can enhance the intelligent battlefield command, collaborative attack, and other applications, such as landmine trigger and post-war clearance. Existing routing path selection methods designed for wireless sensor networks (WSNs) are effective but still face challenges in IoBT scenarios. First, tactical devices follow nonuniform distributions with high density on boundaries in IoBT to prevent the location of devices from being speculated and protect strategic positions, which results in unbalanced energy consumption. Second, increasing latency in IoBT is caused by various data generation probabilities of tactical devices. Third, the military task features, such as landmine explosion, disconnection, and failure of tactical devices, may put forward special requirements on network robustness. To this end, we propose a routing path selection method with joint optimization in IoBT based on nonuniform node distributions and location-related data generation probabilities. Specifically, we first investigate and formulate the distribution and data generation probability of tactical devices. Based on the special features, energy consumption, latency, and network robustness are analyzed during multihop communications in IoBT. Then, a joint optimization problem is formulated to minimize energy consumption and latency, while maximizing the network robustness simultaneously. Furthermore, two path assignment algorithms are developed to solve this optimization problem. Finally, our simulation results show that the proposed routing path selection method can reduce energy consumption and latency with the guaranteed robustness of IoBT.
Chong Yu 0002, Shuaiqi Shen, Haojun Yang, Kuan Zhang 0001, Hai Zhao 0002
IEEE Internet Things J.4
2022 A Behavior Decision Method Based on Reinforcement Learning for Autonomous Driving
abstract
Autonomous driving vehicles can reduce congestion and improve safety while increasing traffic efficiency. To reflect the quality of driving more comprehensively, the driving safety, efficiency, and occupant comfort should be jointly optimized for autonomous vehicles. Furthermore, in order to cope with complicated traffic environments and achieve satisfactory driving performance, a powerful behavior decision-making module is indispensable for autonomous vehicles. Toward this end, we study a reinforcement-learning (RL)-based method to intelligently make the behavior decision in this article. A Markov decision process (MDP) model is first formulated with a comprehensive reward function, including the effects of driving safety, efficiency, and comfort. The knowledge of the surrounding vehicles is also leveraged to exploit the behavior prediction of the target vehicle. We then propose a behavior decision strategy based on the actor–critic (AC) mechanism, which can efficiently learn both a Gaussian policy function and a linear value function. Finally, the real traffic data are used to build up the simulations for evaluating the performances of the proposed method thoroughly. Simulation results show that our proposed method can significantly reduce the collision rate for autonomous vehicles.
Kan Zheng, Haojun Yang, Shiwen Liu, Kuan Zhang 0001, Lei Lei 0004
IEEE Internet Things J.4
2022 Vulnerability Analysis of Smart Contract for Blockchain-Based IoT Applications: A Machine Learning Approach
abstract
With the emergence of Blockchain-based Internet of Things (BIoT) applications, smart contracts have become one of the most appealing aspects because they reduce the cost and complexity of distributed administration. However, the immaturity of smart contracts may result in significant financial losses or the leakage of sensitive information. This article first investigates the taxonomy of security issues associated with smart contracts considering BIoT scenarios. To address these security concerns and overcome the limitations of existing methods, a tree-based machine learning vulnerability detection (TMLVD) method is proposed to perform the vulnerability analysis of smart contracts. TMLVD feeds the intermediate representations of smart contracts derived from abstract syntax trees (AST) into a tree-based training network for building the prediction model. Multidimensional features are captured by this model to identify smart contracts as vulnerable. The detection phase can be implemented quickly with limited computing resources and the accuracy of the detection results is guaranteed. The experimental evaluation demonstrated the effectiveness and efficiency of TMLVD on a data set comprised of Ethereum smart contracts.
Kan Zheng, Kuan Zhang 0001, Lu Hou 0001, Xianbin Wang 0001
IEEE Internet Things J.3
2022 Blockchain-based trust management for verifiable time synchronization service in IoT
Kai Fan 0001, Zeyu Shi, Ruidan Su, Yuhan Bai, Pei Huang 0013, Kuan Zhang 0001, Hui Li 0006, Yintang Yang
Peer-to-Peer Netw. Appl.6
2022 Clustered NOMA-based downlink adaptive relay coordinated transmission scheme for future 6G cell-free edge network
Xuefei Peng, Xiaoming Yuan 0002, Kuan Zhang 0001
Peer-to-Peer Netw. Appl.3
2022 Identity-Based Provable Data Possession From RSA Assumption for Secure Cloud Storage
abstract
As cloud storage services have become popular nowadays, the integrity of outsourced data stored at untrusted servers received increased attention. Provable data possession (PDP) provides an effective and efficient solution for cloud data integrity by asking the cloud server to prove that the stored data are not tampered with or maliciously discarded without returning the actual data to users. In this article, we propose an efficient identity-based privacy-preserving provable data possession scheme (ID-P$^3$DP) based on the RSA assumption for secure cloud storage. In ID-P$^3$DP, a cloud user takes the outsourcing file and a global parameter in a time period as inputs to generate identity-based homomorphic authenticators, and any third-party auditor (TPA) can check the integrity of the outsourced file by verifying the validity of homomorphic authenticators. The distinguished feature of ID-P$^3$DP is to support the aggregation of identity-based homomorphic authenticators generated by different users under the RSA assumption, which is an open problem in provable data possession. Specifically, we transfer the identity-based homomorphic authenticators generated in distinct time periods into those with the same period parameter, and the cloud can compress the homomorphic authenticators of different users to generate a data possession proof for integrity verification. Besides, by exploiting zero-knowledge proof, the leakage of outsourced data to TPA can be prevented. The soundness of ID-P$^3$DP is proved based on the RSA assumption, and the privacy against TPA is perfectly preserved. Finally, we demonstrate ID-P$^3$DP is more efficient on integrity verification than the existing BLS-based schemes, and cross-user aggregate verification can significantly reduce computational and communication overhead for TPA.
Jianbing Ni, Kuan Zhang 0001, Yong Yu 0002, Tingting Yang 0001
IEEE Trans. Dependable Secur. Comput.2
2022 Anonymous and Efficient Authentication Scheme for Privacy-Preserving Distributed Learning
abstract
Distributed learning is proposed as a promising technique to reduce heavy data transmissions in centralized machine learning. By allowing the participants training the model locally, raw data is unnecessarily uploaded to the centralized cloud server, reducing the risks of privacy leakage as well. However, the existing studies have shown that an adversary is able to derive the raw data by analyzing the obtained machine learning models. To tackle this challenge, the state-of-the-art solutions mainly depend on differential privacy and encryption techniques (e.g., homomorphic encryption). Whereas, differential privacy degrades data utility and leads to inaccurate learning, while encryption based approaches are not effective to all machine learning algorithms due to the limited operations and excessive computation cost. In this work, we propose a novel scheme to resolve the privacy issues from the anonymous authentication approach. Different from the two types of existing solutions, this approach is generalized to all machine learning algorithms without reducing data utility, while guaranteeing privacy preservation. In addition, it can be integrated with detection schemes against data poisoning attacks and free-rider attacks, being more practical for distributed learning. To this end, we first design a pairing-based certificateless signature scheme. Based on the signature scheme, we further propose an anonymous and efficient authentication protocol which supports dynamic batch verification. The proposed protocol guarantees the desired security properties while being computationally efficient. Formal security proof and analysis have been provided to demonstrate the achieved security properties, including confidentiality, anonymity, mutual authentication, unlinkability, unforgeability, forward security, backward security, and non-repudiation. In addition, the performance analysis reveals that our proposed protocol significantly reduces the time consumption in batch verification, achieving high computational efficiency.
Yili Jiang, Kuan Zhang 0001, Yi Qian 0001, Liang Zhou 0002
IEEE Trans. Inf. Forensics Secur.2
2022 A Deep One-Class Intrusion Detection Scheme in Software-Defined Industrial Networks
abstract
The unprecedented development of intelligent manufacturing requires to customize and change the network traffic strategies frequently. With the advantages of highagility and programmability, software-defined networking can dynamically manage industrial networks, which makes it a promising networking technology for intelligent manufacturing. However, the software-defined industrial network architecture is vulnerable to network attacks, which may degrade manufacturing productivity, and even cause accidents. In this article, we propose a deep learning-based one-class intrusion detection scheme (DO-IDS) to improve the security of industrial networks. Firstly, DO-IDS periodically extracts the flow statistics of the industrial network traffic to generate network status features. Then, it utilizes a deep learning-based dimension reduction approach to filter redundant features. In addition, a deep learning-based one-class detector is designed to calculate the abnormal scores of the network status features. Finally, we conduct extensive simulations, which demonstrates that DO-IDS can detect abnormal traffic with enhanced accuracy and high efficiency.
Yuanguo Bi, Mingjian Zhi, Kuan Zhang 0001, Feihong Yan, Qian Zhang 0060
IEEE Trans. Ind. Informatics4
2022 A Stable AI-Based Binary and Multiple Class Heart Disease Prediction Model for IoMT
abstract
Heart disease seriously threatens human life due to high morbidity and mortality. Accurate prediction and diagnosis become more critical for early prevention, detection, and treatment. The Internet of Medical Things and artificial intelligence support healthcare services in heart disease monitoring, prediction, and diagnosis. However, most prediction models only predict whether people are sick, and rarely further determine the severity of the disease. In this article, we propose a machine learning based prediction model to achieve binary and multiple classification heart disease prediction simultaneously. We first design a Fuzzy-GBDT algorithm combining fuzzy logic and gradient boosting decision tree (GBDT) to reduce data complexity and increase the generalization of binary classification prediction. Then, we integrate Fuzzy-GBDT with bagging to avoid overfitting. The Bagging-Fuzzy-GBDT for multiclassification prediction further classify the severity of heart disease. Evaluation results demonstrate the Bagging-Fuzzy-GBDT has excellent accuracy and stability in both binary and multiple classification predictions.
Xiaoming Yuan 0002, Kuan Zhang 0001, Yuan Wu 0001, Tingting Yang 0001
IEEE Trans. Ind. Informatics3
2021 Cooperative Task Allocation in Edge Computing Assisted Vehicular Crowdsensing
abstract
As a popular scenario of mobile crowdsensing, edge computing assisted vehicular crowdsensing (EVCS) encourages vehicles to participate in sensing data with the equipped devices. Due to the vehicular mobility, vehicles may dynamically enter and leave the coverage area of an edge node, leading to recurrent task allocations that consume excessive communication and computational resources. How to avoid recurring recruitment in task allocation is challenging. In this paper, we propose an optimization framework to facilitate task allocation by utilizing the cooperation between edge nodes. The proposed framework avoids complicated recruitment procedures while maximizing the connection time between the recruited vehicles and the edge node. Due to the NP-hardness of the formulated optimization problem, we design a reinforcement learning based algorithm to solve the problem with high accuracy and efficiency. Simulation results show the effectiveness of our proposed framework.
Yili Jiang, Kuan Zhang 0001, Yi Qian 0001, Rose Qingyang Hu
GLOBECOM2
2021 Exploiting Ensemble Learning for Edge-assisted Anomaly Detection Scheme in e-healthcare System
abstract
With the thriving of wearable devices and the widespread use of smartphones, the e-healthcare system emerges to cope with the high demand of health services. However, this integrated smart health system is vulnerable to various attacks, including intrusion attacks. Traditional detection schemes generally lack the classifier diversity to identify attacks in complex scenarios that contain a small amount of training data. Moreover, the use of cloud-based attack detection may result in higher detection latency. In this paper, we propose an Edge-assisted Anomaly Detection (EAD) scheme to detect malicious attacks. Specifically, we first identify four types of attackers according to their attacking capabilities. To distinguish attacks from normal behaviors, we then propose a wrapper feature selection method. This selection method eliminates the impact of irrelevant and redundant features so that the detection accuracy can be improved. Moreover, we investigate the diversity of classifiers and exploit ensemble learning to improve the detection rate. To reduce high detection latency in the cloud, edge nodes are used to concurrently implement the proposed lightweight scheme. We evaluate the EAD performance based on two real-world datasets, i.e., NSL-KDD and UNSW-NB15 datasets. The simulation results show that the EAD outperforms other state-of-the-art methods in terms of accuracy, detection rate, and computational complexity. The analysis of detection time validates the fast detection of the proposed EAD compared with cloud-assisted schemes.
Wei Yao 0016, Kuan Zhang 0001, Chong Yu 0002, Hai Zhao 0002
GLOBECOM2
2021 Exploiting Feature Interactions for Malicious Website Detection with Overhead-accuracy Tradeoff
abstract
Malicious websites attempt to install malware on user’s devices without permission, which can disrupt device operation, steal personal information, and even acquire access to the device for future attacks. Accurate detection of malicious website behaviors is crucial for network security but still faces challenges. Firstly, various types and semantics of website features are required to identity the wide range of malicious characteristics, leading to massive training data and computational overhead. Secondly, to reduce model dimensionality, a proper selection of website features is essential but difficult due to the complex relations among features that can affect each other’s contribution to detection outcomes. In this paper, we propose a lightweight feature-based detection scheme against malicious websites considering the interaction measures among features and the overhead-accuracy tradeoff. Specifically, we systematically characterize the interactions among website features in a non-additive manner to indicate the aggregated impacts of feature subsets. Then we propose a quantification method to measure the feature interactions based on multivariate regression. With this method, important features are selected to substantially reduce the model dimension and computational complexity while maintaining desirable accuracy. Meanwhile, the proposed scheme provides an interpretable model that preserves the physical meanings of original features. It allows users to balance the overhead-accuracy tradeoff for detection model training through feature subset selection to fit the requirements and constraints of real applications.
Shuaiqi Shen, Chong Yu 0002, Kuan Zhang 0001, Song Ci
ICC3
2021 Communication-Efficient Federated Learning for Connected Vehicles with Constrained Resources
abstract
With the upcoming next generation wireless network, vehicles are expected to be empowered by artificial intelligence (AI). By connecting vehicles and cloud server via wireless communication, federated learning (FL) allows vehicles to collaboratively train deep learning models to support intelligent services, such as autonomous driving. However, the large number of vehicles and increasing size of model parameters bring challenges to FL-empowered connected vehicles. Since communication bandwidth is insufficient to upload full-precision local models from numerous vehicles, model compression is usually conducted to reduce transmitted data size. Nevertheless, conventional model compression methods may not be practical for resource-constrained vehicles due to the increasing computational overhead for FL training. The overhead for downloading global model can also be omitted by existing methods since they are originally designed for centralized learning instead of FL. In this paper, we propose a ternary quantization based model compression method on communication-efficient FL for resource-constrained connected vehicles. Specifically, we firstly propose a ternary quantization based local model training algorithm that optimizes quantization factors and parameters simultaneously. Then, we design a communication-efficient FL approach that reduces overhead for both upstream and downstream communications. Finally, simulation results validate that the proposed method demands the lowest communication and computational overheads for FL training, while maintaining desired model accuracy compared to existing model compression methods.
Shuaiqi Shen, Chong Yu 0002, Kuan Zhang 0001, Song Ci
IWCMC3
2021 A Quantitative Study of Energy Consumption for Embedded Security
abstract
Due to the vulnerability of the Internet of Things (IoT), it is indispensable to provide adequate security services. These services are generally implemented through security protocols or algorithms and running on energy-sensitive IoT devices. In order to design energy-efficient algorithms to prolong the lifetime of IoT devices, the energy characteristics of those algorithms should be analyzed primarily. In this paper, we conduct an integrated static analysis method with dynamic tracing to provide a quantitative energy profile for popular security algorithms such as AES128, RSA, and SHA256. Specifically, binary instructions executed in the invoked function are measured and counted through remotely debugging each program on the Arm development board. Then, the fine-grained energy consumption inside a program is revealed by combining the instruction statistics and instruction-level energy model. The experimental results show that the energy consumption of a program is mainly consumed by a few primary functions and CPU-memory interaction instructions, and hence the functions can be implemented in different ways to reduce energy consumption. This meaningful energy consumption evaluation method for security algorithms is able to guide to optimizing existing algorithms for embedded security.
Yang Yang 0001, Yanglin Zhou, Kuan Zhang 0001, Song Ci
WCNC4
2021 An ultra light weight and secure RFID batch authentication scheme for IoMT
Junbin Kang, Kai Fan 0001, Kuan Zhang 0001, Xiaochun Cheng, Hui Li 0006, Yintang Yang
Comput. Commun.3
2021 Reinforcement-Learning-Based Query Optimization in Differentially Private IoT Data Publishing
abstract
With the advancement of Internet of Things (IoT) and computing paradigms, massive data are collected and processed to enhance intelligent applications. However, by deliberately sending some queries, an attacker may be able to derive the sensitive information of IoT data owners. To prevent privacy leakage during IoT data query, differential privacy (DP) hides private information by introducing noise to the query results. As DP introduces randomized noise that will affect query accuracy (data utility), the tradeoff between privacy preservation and data utility is a challenge. In this article, we first propose a novel optimization framework for single query to minimize the privacy cost, while satisfying both personalized DP and customized data utility. We design a reinforcement learning-based algorithm for single query optimization framework (SQOF_RL) to solve the optimization problem efficiently. Then, we propose a SQOF_RL and SVT-based batch query optimization mechanism (S2BQOM) to answer more queries privately. The performance evaluation shows that SQOF_RL and S2BQOM can effectively optimize single query and batch queries in terms of privacy cost, data utility, personalized privacy, and query satisfaction. Finally, the performance analysis reveals that our work can be applied to multiple linear/nonlinear query functions instead of one particular query function.
Yili Jiang, Kuan Zhang 0001, Yi Qian 0001, Liang Zhou 0002
IEEE Internet Things J.2
2021 Adaptive Artificial Intelligence for Resource-Constrained Connected Vehicles in Cybertwin-Driven 6G Network
abstract
The emerging technology of cybertwin is expected to bring revolutionary benefits to the sixth-generation (6G) network in respect of communication, resources allocation, and digital asset management. Empowered by ubiquitous artificial intelligence (AI), cybertwin is capable of adjusting the requests for computing resources to support network services by analyzing user’s demands for quality of experience and resource scarcity in the market. For resource-constrained applications, such as connected vehicles in the 6G network, cybertwin can intelligently determine the time-varying requests of computing resources for various vehicles at different times. However, the current service architecture executes AI algorithms with universal configurations for all vehicles. This causes the difficulty of customizing the complexity of AI algorithms to maintain adaptive to cybertwin’s decisions on dynamic resources allocation. In this article, we propose an adaptive AI framework based on efficient feature selection to cooperate with cybertwin’s resource allocation. This proposed framework can adaptively customizing AI model complexity with available computing resources. Specifically, we systematically characterize the aggregated impacts of all feature combinations on the modeling outcomes of AI algorithms. By utilizing nonadditive measures, the interactions among features can be quantified to indicate their contributions to the modeling process. Then, we propose an efficient algorithm to obtain accurate interaction measures for adaptive feature selection to balance the tradeoff between modeling accuracy and computational overhead. Finally, extensive simulations are conducted to validate that our proposed framework substantially reduces the overhead of AI algorithms while guaranteeing desired modeling accuracy for cybertwin-driven connected vehicles in 6G.
Shuaiqi Shen, Chong Yu 0002, Kuan Zhang 0001, Song Ci
IEEE Internet Things J.3
2021 Fast Containment of Infectious Diseases With E-Healthcare Mobile Social Internet of Things
abstract
The infectious disease presents great hazards to public health, due to their high infectivities and potential lethalities. One of the effective methods to hinder the spread of infectious disease is vaccination. However, due to the limitation of resource and the medical budget, vaccinating all people is not feasible in practice. Besides, the vaccinating effects are difficult to be timely observed through traditional ways, such as outpatient services. To tackle the above problems, we propose an e-healthcare mobile social Internet of Things (MSIoTs)-based targeted vaccination scheme to fast contain the spread of the infectious disease. Specifically, we first develop an e-healthcare MSIoT architecture by integrating the e-healthcare system and MSIoTs, whereby the spread status of the infectious disease is timely collected. Furthermore, a graph coloring and spreading centrality-based optional candidate searching algorithm is devised to hunt for the candidates that are powerfully capable of preventing infectious disease. Especially, in order to reduce the vaccination cost, we design an optimal vaccinated target selection algorithm to choose a minimum number of targets whose locations are differentially distributed. Extensive simulations demonstrate that the proposed scheme can effectively prevent infectious disease as compared to conventional schemes.
Qichao Xu, Zhou Su 0001, Kuan Zhang 0001, Shui Yu 0001
IEEE Internet Things J.3
2021 No Need of Data Pre-processing: A General Framework for Radio-based Device-free Context Awareness
abstract
Device-free context awareness is important to many applications. There are two broadly used approaches for device-free context awareness, i.e., video-based and radio-based. Video-based approaches can deliver good performance, but privacy is a serious concern. Radio-based context awareness applications have drawn researchers' attention instead, because it does not violate privacy and radio signal can penetrate obstacles. The existing works design explicit methods for each radio-based application. Furthermore, they use one additional step to extract features before conducting classification and exploit deep learning as a classification tool. Although this feature extraction step helps explore patterns of raw signals, it generates unnecessary noise and information loss. The use of raw CSI signal without initial data processing was, however, considered as no usable patterns. In this article, we are the first to propose an innovative deep learning–based general framework for both signal processing and classification. The key novelty of this article is that the framework can be generalised for all the radio-based context awareness applications with the use of raw CSI. We also eliminate the extra work to extract features from raw radio signals. We conduct extensive evaluations to show the superior performance of our proposed method and its generalisation.
Bo Wei 0003, Kai Li 0002, Chengwen Luo 0001, Weitao Xu, Jin Zhang 0013, Kuan Zhang 0001
ACM Trans. Internet Things6
2020 Defending Malicious Check-in Based on Access Point Selection for Indoor Positioning System
abstract
WiFi fingerprint-based positioning system emerges to offer fundamental location information for indoor mobile users. It facilitates the check-in to point of interest (POI) through submitting received signal strength (RSS) fingerprints in order to evaluate the crowd traffic. However, the crowd traffic evaluation with RSS fingerprints is vulnerable to the malicious check-in attacks. Attackers who are not at the target POI may still submit the self-modified RSS fingerprints located at the target POI in order to illegally increase its crowd traffic and eventually profit from this fake information. In this paper, we propose a defense scheme against malicious check-in based on access point (AP) selection to significantly reduce the success rate of fingerprint modification from attackers. Specifically, we first exploit fingerprint distance between POIs for AP selection. Then, we explore the mutual information between different POI classes to select APs with high robustness. In addition, the level set method (LSM) is developed to search the optimal modified fingerprint to assess attacker's costs. The extensive simulation results show that the proposed scheme can effectively resist attackers with high accuracy and facilitate crowd traffic evaluation of target POI according to the submitted RSS fingerprints.
Weiwei Li 0007, Zhou Su 0001, Kuan Zhang 0001, Abderrahim Benslimane
ICC3
2020 An Optimization Framework for Privacy-preserving Access Control in Cloud-Fog Computing Systems
abstract
The cloud-based Internet-of-Things (IoT) has been applied to support ubiquitous data collection and centralized data processing among various applications. Equipped with powerful resources, a semi-trusted cloud is able to deduce private information by launching inference attack. Homomorphic Encryption (HE) has been proposed as an effective way to preserve privacy from inference attack while allowing certain computation over ciphertext. However, HE leads to longer latency due to additional communication and computation overheads. In this paper, we propose an optimization framework in privacy-preserving access control under cloud-fog computing systems. The optimization goal is to maximize the average user satisfaction in the system, where cost and latency serve as key metrics measuring user satisfaction. Due to the NP-hardness of the formulated problem, we propose a low-complexity suboptimal algorithm to solve it, where the access offloading decision making, user cooperation, and resource allocation are considered. Simulation results are presented to show the advantages of our proposed algorithm in terms of the average USI (User Satisfaction Index) and the number of users with zero USI.
Yili Jiang, Kuan Zhang 0001, Yi Qian 0001, Liang Zhou 0002
VTC Fall2
2020 A Decentralized Car-Sharing Control Scheme Based on Smart Contract in Internet-of-Vehicles
abstract
Car sharing allows car owners to share their cars to tenants, making the control rights of vehicles to be frequently transferred among individuals. The existing control schemes for car shearing with centralized architecture are faced with several threatens, e.g., the single point of failure and lack of mutual trust. To this end, we propose a decentralized car-sharing control scheme by using blockchain and smart contracts. Massive base stations of Internet-of-Vehicles (IoV) deployed over wide areas are used to jointly build the distributed system with blockchain to replace the untrusted third-party server. Having the smart contract, access control procedures can be performed automatically by an arbitrary base station in the decentralized architecture. The scheme provides a secure platform for the interactions among vehicles, individuals and application providers to avoid some security issues. Several simulations are conducted to validate the feasibility and effectiveness of the proposed scheme.
Zhe Yang 0006, Kuan Zhang 0001, Kan Zheng
VTC Spring3
2020 Security in edge-assisted Internet of Things: challenges and solutions
Shuaiqi Shen, Kuan Zhang 0001, Yi Zhou 0004, Song Ci
Sci. China Inf. Sci.2
2020 Privacy-preserving searchable encryption in the intelligent edge computing
Kai Fan 0001, Kuan Zhang 0001, Haoyang Wang 0005, Hui Li 0006, Yingtang Yang
Comput. Commun.3
2020 Performance modeling and analysis of a Hyperledger-based system using GSPN
Pu Yuan 0002, Kan Zheng, Kuan Zhang 0001, Lei Lei 0004
Comput. Commun.4
2020 An AUV-Assisted Data Gathering Scheme Based on Clustering and Matrix Completion for Smart Ocean
abstract
The oceans cover more than 71% of the Earth's surface and have a surging amount of data. It is of great significance to seek energy-effective and ultrareliable communication and transmission mechanism for effectively gathering abundant maritime data. In this article, we propose an autonomous underwater vehicle (AUV)-assisted data gathering scheme based on clustering and matrix completion (ACMC) to improve the data gathering efficiency in the underwater wireless sensor network (UWSN). Specifically, we first improve the K-means algorithm by adopting the Elbow method to determine the optimal K and setting a distance threshold to select the separate initial cluster centers. Then, we introduce a two-phase AUV trajectory optimization mechanism to effectively reduce the trajectory length of the AUV. In the first phase, the optimized trajectory of the AUV is planned by adopting the greedy algorithm. In the second phase, the ordinary nodes close to the AUV trajectory are selected as secondary cluster heads to share the workload of cluster heads. Finally, we present an in-cluster data collection mechanism based on matrix completion. An extensive experiment validates the effectiveness of our proposed scheme in terms of energy and data collection delay.
Mingfeng Huang, Kuan Zhang 0001, Tian Wang 0001, Yuxin Liu 0001
IEEE Internet Things J.2
2020 Leveraging Linear Quadratic Regulator Cost and Energy Consumption for Ultrareliable and Low-Latency IoT Control Systems
abstract
To efficiently support real-time control applications, networked control systems operating with ultrareliable and low-latency communications (URLLCs) become a fundamental technology for the future Internet of Things (IoT). However, the design of control, sensing, and communications is generally isolated at present. In this article, we investigate the joint optimization of control cost and energy consumption for a centralized wireless networked control system. Specifically, with the “sensing-then-control” protocol, we first develop an optimization framework that jointly takes control, sensing, and communications into account. In this framework, we derive the spectral efficiency, linear quadratic regulator cost, and energy consumption. Then, a novel performance metric called the energy-to-control efficiency (ECE) is proposed for the IoT control system. In addition, we optimize the ECE while guaranteeing the requirements of URLLCs, thereupon a general and complex max-min joint optimization problem is formulated for the IoT control system. To optimally solve the formulated problem by reasonable complexity, we propose two radio resource allocation algorithms. Finally, simulation results show that our proposed algorithms can significantly improve the ECE for the IoT control system with URLLCs.
Haojun Yang, Kuan Zhang 0001, Kan Zheng, Yi Qian 0001
IEEE Internet Things J.2
2020 Cloud-based lightweight secure RFID mutual authentication protocol in IoT
Kai Fan 0001, Kuan Zhang 0001, Yintang Yang
Inf. Sci.3
2020 Privacy-preserving task recommendation with win-win incentives for mobile crowdsourcing
Wenjuan Tang, Kuan Zhang 0001, Ju Ren 0001, Yaoxue Zhang, Xuemin Shen
Inf. Sci.2
2020 A secure and efficient outsourced computation on data sharing scheme for privacy computing
Kai Fan 0001, Kuan Zhang 0001, Hui Li 0006, Yintang Yang
J. Parallel Distributed Comput.3
2020 Physical Layer based Message Authentication with Secure Channel Codes
abstract
In this paper, we investigate physical (PHY) layer message authentication to combat adversaries with infinite computational capacity. Specifically, a PHY-layer authentication framework over a wiretap channel (W1; W2) is proposed to achieve information theoretic security with the same key. We develop a theorem to reveal the requirements/conditions for the authentication framework to be information-theoretic secure for authenticating a polynomial number of messages in terms of n. Based on this theorem, we design an authentication protocol that can guarantee the security requirements, and prove its authentication rate can approach infinity when n goes to infinity. Furthermore, we design and implement a feasible and efficient message authentication protocol over binary symmetric wiretap channel (BSWC) by using Linear Feedback Shifting Register based (LFSR-based) hash functions and strong secure polar code. Through extensive simulations, it is demonstrated that the proposed protocol can achieve high authentication rate, with low time cost and authentication error rate.
Dajiang Chen, Ning Zhang 0007, Nan Cheng 0001, Kuan Zhang 0001, Zhiguang Qin, Xuemin Shen
IEEE Trans. Dependable Secur. Comput.4
2020 Providing Task Allocation and Secure Deduplication for Mobile Crowdsensing via Fog Computing
abstract
Mobile crowdsensing enables a crowd of individuals to cooperatively collect data for special interest customers using their mobile devices. The success of mobile crowdsensing largely depends on the participating mobile users. The broader participation, the more sensing data are collected; nevertheless, the more replicate data may be generated, thereby bringing unnecessary heavy communication overhead. Hence it is critical to eliminate duplicate data to improve communication efficiency, a.k.a., data deduplication. Unfortunately, sensing data is usually protected, making its deduplication challenging. In this paper, we propose a fog-assisted mobile crowdsensing framework, enabling fog nodes to allocate tasks based on user mobility for improving the accuracy of task assignment. Further, a fog-assisted secure data deduplication scheme (Fo-SDD) is introduced to improve communication efficiency while guaranteeing data confidentiality. Specifically, a BLS-oblivious pseudo-random function is designed to enable fog nodes to detect and remove replicate data in sensing reports without exposing the content of reports. To protect the privacy of mobile users, we further extend the Fo-SDD to hide users' identities during data collection. In doing so, Chameleon hash function is leveraged to achieve contribution claim and reward retrieval for anonymous mobile users. Finally, we demonstrate that both schemes achieve secure, efficient data deduplication.
Jianbing Ni, Kuan Zhang 0001, Yong Yu 0002, Xiaodong Lin 0001, Xuemin Shen
IEEE Trans. Dependable Secur. Comput.2
2020 Enabling Strong Privacy Preservation and Accurate Task Allocation for Mobile Crowdsensing
abstract
Mobile crowdsensing engages a crowd of individuals to use their mobile devices to cooperatively collect data about social events and phenomena for customers with common interest. It can reduce the cost on sensor deployment and improve data quality with human intelligence. To enhance data trustworthiness, it is critical for the service provider to recruit mobile users based on their personal features, e.g., mobility pattern and reputation, but it leads to the privacy leakage of mobile users. Therefore, how to resolve the contradiction between user privacy and task allocation is challenging in mobile crowdsensing. In this paper, we propose SPOON, a strong privacy-preserving mobile crowdsensing scheme supporting accurate task allocation based on geographic information and credit points of mobile users. In SPOON, the service provider enables to recruit mobile users based on their locations, and select proper sensing reports according to their trust levels without invading user privacy. By utilizing proxy re-encryption and BBS+ signature, sensing tasks are protected and reports are anonymized to prevent privacy leakage. In addition, a privacy-preserving credit management mechanism is introduced to achieve decentralized trust management and secure credit proof for mobile users. Finally, we show the security properties of SPOON and demonstrate its efficiency in terms of computation and communication.
Jianbing Ni, Kuan Zhang 0001, Qi Xia 0001, Xiaodong Lin 0001, Xuemin Shen
IEEE Trans. Mob. Comput.2
2020 Joint Frame Design and Resource Allocation for Ultra-Reliable and Low-Latency Vehicular Networks
abstract
The rapid development of the fifth generation mobile communication systems accelerates the implementation of vehicle-to-everything communications. Compared with the other types of vehicular communications, vehicle-to-vehicle (V2V) communications mainly focus on the exchange of driving safety information with neighboring vehicles, which requires ultra-reliable and low-latency communications (URLLCs). However, the frame size is significantly shortened in V2V URLLCs because of the rigorous latency requirements, and thus the overhead is no longer negligible compared with the payload information from the perspective of size. In this paper, we investigate the frame design and resource allocation for an urban V2V URLLC system in which the uplink cellular resources are reused at the underlay mode. Specifically, we first analyze the lower bounds of performance for V2V pairs and cellular users based on the regular pilot scheme and superimposed pilot scheme. Then, we propose a frame design algorithm and a semi-persistent scheduling algorithm to achieve the optimal frame design and resource allocation with the reasonable complexity. Finally, our simulation results show that the proposed frame design and resource allocation scheme can greatly satisfy the URLLC requirements of V2V pairs and guarantee the communication quality of cellular users.
Haojun Yang, Kuan Zhang 0001, Kan Zheng, Yi Qian 0001
IEEE Trans. Wirel. Commun.2
2019 Secure Edge Caching for Layered Multimedia Contents in Heterogeneous Networks
abstract
To meet the exponentially increasing mobile services and applications, heterogenous networks (HetNets) have been envisioned as a promising technology. In HetNets, multiple caching-enabled small-cell based stations (SBSs) are deployed within the coverage of a macro-cell base station (MBS) to cache multimedia contents for mobile users. However, due to security threats of untrusted SBSs, the cached contents may be illegally accessed by owners of these untrusted SBSs, resulting in the content privacy leakage. To tackle this problem, we propose a secure edge caching scheme for layered multimedia contents in HetNets. Specifically, considering the layered features of contents, we first develop a secure edge caching framework based on the cooperations of SBSs and MBS. In this framework, the critical base layer subfile of the content are directly delivered by the trusted MBS, whereas the enhancement layer subfiles are cached on untrusted SBSs. Furthermore, according to the limited caching capacities of SBSs and dynamic content demands of mobile users, we formulate the enhancement layer subfile caching problem as a non-convex 0-1 integer programming problem. To solve this problem, we devise a distributed alternating direction method of multipliers (ADMM) and secure the edge caching for each SBS to iteratively search the optimal caching strategy. Simulation results show that the proposed scheme provides secure and efficient multimedia content caching for mobile users.
Qichao Xu, Zhou Su 0001, Ying Wang 0002, Kuan Zhang 0001
GLOBECOM4
2019 2TM-MAC: A Two-Tier Multi-Channel Interference Mitigation MAC Protocol for Coexisting WBANs
abstract
Wireless Body Area Networks (WBANs) have been developed rapidly with the increasing popularity of wireless network and wearable technologies. The inherent characteristics of convenience and efficiency for health monitoring facilitate the depth and width of WBAN applications. However, the inter-WBAN interference problem affects the network performance in intensive WBAN scenarios, degrading reliability and increasing latency of health data. In this paper, we propose a Two-Tier Multi-channel Medium Access Control (2TM-MAC) protocol with interference mitigation for reliable health monitoring. Specially, the 2TM-MAC establishes an inter-WBAN interference matrix for every WBAN to show the mutual interference among coexisting WBANs. We design a multi-channel selection algorithm at the first tier to select different numbers of channels for each WBAN to avoid inter-WBAN interference and collisions. At the second tier, the hub of each WBAN schedules the available channels assigned from the first tier to sensor nodes according to their traffic requirements, mitigating the intra-WBAN interference as well. 2TM-MAC protocol enhances the reliability of emergency data and service experience in healthcare applications. Simulation results show the 2TM-MAC protocol significantly improves the network throughput and decreases the average packet delay compared with IEEE 802.15.6 for densely deployed coexisting WBANs scenarios.
Xiaoming Yuan 0002, Jiaxin Han, Kuan Zhang 0001, Changle Li, Qiang Ye 0002
GLOBECOM4
2019 HMM Based Cache Pollution Attack Detection for Edge Computing Enabled Mobile Social Networks
abstract
With the rapid advances of wireless technologies and popularization of mobile devices, edge computing boosts mobile social networks (MSNs) to allow mobile users to deliver, share, and exchange contents with each other. In particular, with edge caching, various content services can be provided to mobile users with improved Quality-of-Experience (QoE). However, edge caching is vulnerable to cache pollution attack (CPAttack), degrading content delivery. To tackle these problems, in this paper, we propose a hidden Markov model (HMM) based detection scheme against CPAttack in edge computing enabled MSNs. Specifically, we first present the CPAttack model with the observations of malicious behaviors. According to the CPAttack model, the caching state of each edge device is characterized in terms of request rate and cache hit rate. The HMM is exploited to detect the CPAttack with observation sequence of caching states. The simulation results demonstrate that the proposed scheme can efficiently improve edge devices' capability to detect CPAttack.
Qichao Xu, Zhou Su 0001, Kuan Zhang 0001
ICC3
2019 Shake to Communicate: Secure Handshake Acceleration-Based Pairing Mechanism for Wrist Worn Devices
abstract
With the booming penetration of wrist worn smart devices in daily lives, a wide range of applications have been enabled, such as exchanging social information, sharing sports data, and sending messages. Securing data exchange between these devices has become a challenging issue, considering the high security requirements and low computation capabilities of these wrist worn devices. In this paper, we propose a secure wrist worn smart device pairing scheme by exploiting the motion signal of the devices generated by the handshake to negotiate a reliable key between users. To ensure the security of key negotiation, a novel fuzzy cryptography algorithm is further developed. Compared with existing algorithms, the proposed algorithm avoids complicated error correction algorithms and has low requirements for data coincidence on the premise of individual differentiation. At the same time, the security is guaranteed by feature reordering and protection of auxiliary data. Extensive experimental results are provided, which demonstrate that the proposed handshake acceleration-based pairing scheme is robust, secure, and efficient.
Qi Jiang 0001, Xiaohan Huang 0002, Ning Zhang 0007, Kuan Zhang 0001, XinDi Ma, Jianfeng Ma 0001
IEEE Internet Things J.4
2019 Learning-Aided User Identification Using Smartphone Sensors for Smart Homes
abstract
Smart homes expects to improve the convenience, comfort, and energy efficiency of the residents by connecting and controlling various appliances. As the personal information and computing hub for smart homes, smartphones allow people to monitor and control their homes anytime and anywhere. Therefore, the security and privacy of smartphones and the stored data are crucial in smart homes. To protect smartphones from potential attacks, various built-in sensors can be utilized for user authentication/identification and access control to achieve enhanced security. In this paper, we propose a framework, smartphone sensor user identification (SSUI), in order to facilitate user identification based on the relationships between different types of sensor data and smartphone users. Specifically in SSUI, the time and frequency features are extracted and learned separately using convolution neural network (CNN). The CNN outputs are then processed using recurrent neural network, according to several time bins. Using both of our own dataset (collected from 17 participants) and a publicly available dataset (i.e., Heterogeneity Dataset for Human Activity Recognition), we demonstrate the effectiveness of the proposed SSUI framework, where we achieve an accuracy rate of over 91.45% in various scenarios.
Zhen Qin 0002, Lingzhou Hu, Ning Zhang 0007, Dajiang Chen, Kuan Zhang 0001, Zhiguang Qin, Kim-Kwang Raymond Choo
IEEE Internet Things J.5
2019 Game Theoretical Secure Caching Scheme in Multihoming Edge Computing-Enabled Heterogeneous Networks
abstract
Caching contents on edge computing-enabled small cell base stations (ECSBSs) has become a promising technology for mitigating burdens of macro cell base stations and offloading data from mobile users. However, as ECSBSs may be malicious, providing a secure caching scheme becomes a challenge. In this paper, we propose a novel secure caching scheme in heterogeneous networks for multihoming users. First, to provide the cached contents, a trust mechanism is designed to verify the reliability of each ECSBS. Then, in order to guarantee the integrity of cached contents and preserve the privacy of mobile users, a Chinese remainder theorem-based privacy preservation protocol is proposed. Next, we investigate the interactions among mobile users and ECSBSs by Stackelberg game, where the trusted ECSBSs are selected to provide caching resources for mobile users with multihoming access. In addition, we analyze the Stackelberg equilibrium to jointly maximize the utilities of ECSBSs and mobile users. Extensive simulations validate the efficiency of the proposed scheme with the reliability and effectiveness to cache contents.
Qichao Xu, Zhou Su 0001, Minnan Luo, Bo Dong 0001, Kuan Zhang 0001
IEEE Internet Things J.6
2019 A Novel Classifier Exploiting Mobility Behaviors for Sybil Detection in Connected Vehicle Systems
abstract
A Sybil attacker is able to obtain more than one identities and disguise as multiple vehicles in order to interfere the normal operations of the connected vehicle system (CVS). In this paper, we propose a novel classifier to detect Sybil attackers according to their mobility behaviors. Specifically, three levels of Sybil attackers are first defined according to their attack abilities. Through analyzing the mobility behaviors of vehicles, a learning-based model is used in the central server (CS) to extract mobility features and distinguish Sybil attackers from benign vehicles. Three classification algorithms are tested and compared, i.e., the naive Bayes, decision tree, and support vector machine. Furthermore, location certificates issued by base stations are used to resist location forgery by attackers. Based on the location certificates, the CS is able to evaluate the credibilities of uploaded locations using the subjective logic theory. In addition, we develop an edge betweenness-based community detection algorithm to handle the collusion among multiple Sybil attackers. Simulations are conducted based on a real-world vehicle trajectory dataset, which indicate that the proposed scheme is effective to resist Sybil attackers in CVS.
Zhe Yang 0006, Kuan Zhang 0001, Lei Lei 0004, Kan Zheng
IEEE Internet Things J.2
2019 Efficient and Privacy-preserving Fog-assisted Health Data Sharing Scheme
abstract
Pervasive data collected from e-healthcare devices possess significant medical value through data sharing with professional healthcare service providers. However, health data sharing poses several security issues, such as access control and privacy leakage, as well as faces critical challenges to obtain efficient data analysis and services. In this article, we propose an efficient and privacy-preserving fog-assisted health data sharing (PFHDS) scheme for e-healthcare systems. Specifically, we integrate the fog node to classify the shared data into different categories according to disease risks for efficient health data analysis. Meanwhile, we design an enhanced attribute-based encryption method through combination of a personal access policy on patients and a professional access policy on the fog node for effective medical service provision. Furthermore, we achieve significant encryption consumption reduction for patients by offloading a portion of the computation and storage burden from patients to the fog node. Security discussions show that PFHDS realizes data confidentiality and fine-grained access control with collusion resistance. Performance evaluations demonstrate cost-efficient encryption computation, storage and energy consumption.
Wenjuan Tang, Ju Ren 0001, Kuan Zhang 0001, Yaoxue Zhang, Xuemin Shen
ACM Trans. Intell. Syst. Technol.3
2019 Flexible and Efficient Authenticated Key Agreement Scheme for BANs Based on Physiological Features
abstract
In Body Area Networks (BANs), bio-sensors can collect personal health information and cooperate with each other to provide intelligent health care services for medical users. Since personal health information is highly privacy-sensitive, the flourish of BANs still faces critical security challenges, especially secure communication between bio-sensors. In this paper, we propose a flexible and efficient authenticated key agreement scheme (PBAKA) to provide secure communication for BANs. Specifically, we employ a control unit (e.g., smart phone) to launch authentication based on physiological features collected from BANs, and integrate bilinear pairings to negotiate session keys for bio-sensors. Since physiological features can be collected from various kinds of bio-sensors in real time, PBAKA is flexible for adding new bio-sensors without pre-distributed keys. Meanwhile, PBAKA is computationally efficient by offloading authentication burden from resource-limited bio-sensors to the control unit. Security analysis demonstrates that PBAKA is provably secure under the decisional bilinear Diffie-Hellman assumption. Extensive experimental results validate efficient communication, computation and energy consumption of our scheme when compared with several existing solutions.
Wenjuan Tang, Kuan Zhang 0001, Ju Ren 0001, Yaoxue Zhang, Xuemin Shen
IEEE Trans. Mob. Comput.2
2018 Anomalous Path Detection for Spatial Crowdsourcing-Based Indoor Navigation System
abstract
Indoor navigation system provides customized path planning for requesters who are unfamiliar with the indoor environment, such as shopping mall and airport. Spatial crowd-sourcing technology can be applied to indoor navigation to offer fundamental services related to location. However, spatial crowdsourcing-based indoor navigation is vulnerable to the intrusion of injected anomalous paths from attackers. In this paper, we propose an anomalous path detection (APD) scheme to classify attackers according to their reputation management and abnormal trajectory sequence. Specifically, we first develop a crowdsourcing system to support the indoor location service using the fog as the spatial crowdsourcing server. Then, we identify two levels of attackers, i.e., the malicious responders and the semi-honest responders in the indoor environment according to their attacking purposes. Through the responders' historical records from the fog server, we analyze a series of trajectory sequences consisting of the distance between the current position and the destination to distinguish the semi-honest responders from the normal. In addition, we propose a semi-supervised learning with hidden Markov model (HMM) to detect the semi-honest responders. Finally, the extensive simulations show that the APD scheme can achieve higher accuracy with the acceptable false rate.
Weiwei Li 0007, Kuan Zhang 0001, Zhou Su 0001, Rongxing Lu, Ying Wang 0002
GLOBECOM2
2018 Game Theoretical Secure Caching Scheme in Multi-Homing Heterogeneous Networks
abstract
Caching contents in small cell base stations (SBSs), namely, caching-enabled SBSs, has become a promising technology for mitigating burdens of macro cell base stations and backbone links. However, as some SBSs may be malicious, how to provide a secure caching scheme becomes challenging. In this paper, we propose a novel secure caching scheme in heterogeneous networks for multi-homing users. Firstly, to achieve availability of cached contents, a trust mechanism is designed to verify the reliability of each SBS. Then, we investigate the interactions among mobile users and SBSs according to Stackelberg game, where the trusted SBSs are selected to provide caching space for mobile users with multi-homing access. In addition, we investigate the Stackelberg equilibrium (SE) to jointly maximize the utilities of SBSs and mobile users. Extensive simulations validates the efficiency of the proposed scheme by evaluating the reliability and effectiveness to cache contents.
Qichao Xu, Zhou Su 0001, Kuan Zhang 0001
ICC3
2018 Dynamic Interference Analysis of Coexisting Mobile WBANs for Health Monitoring
abstract
Wireless Body Area Network (WBAN) technology jumps into popularity owing to its real-time ability and high reliability in health monitoring. The accompanying interference problem must be highly concerned in coexisting densely deployed WBANs since the inter-WBAN interference results in high delay and low reliability data transmissions, especially with the movement of human body. In the paper, we analyze the dynamic interference with human mobility in multiple coexisting WBANs with the consideration of different distances between inter-WBANs and varying number of coexisting WBANs. Moreover, we investigate the influence of inter- WBAN interference on the performance of normalized throughput and average access delay of different traffic types. The results show that the interference generated by mobile neighbour WBANs extremely decreases the throughput of the target WBAN and increases the average packet delay 1.76 times of emergency data compared with the target WBAN without interference. The dynamic interference analysis provides insights on the practical WBAN management and interference mitigation protocol design, especially for the deeply deployed coexisting WBAN scenarios.
Xiaoming Yuan 0002, Changle Li, Kuan Zhang 0001, Qiang Ye 0002, Nan Cheng 0001, Ning Zhang 0007, Xuemin Shen
ICC3
2018 An LDPC Code Based Physical Layer Message Authentication Scheme With Prefect Security
abstract
In this paper, we study physical layer message authentication with perfect security for wireless networks, regardless of the computational power of adversaries. Specifically, we propose an efficient and feasible authentication scheme based on low-density parity-check (LDPC) codes and ϵ-AU2hash functions over binary-input wiretap channel. First, a multimessage authentication scheme for noiseless main channel case is presented by leveraging a novel ϵ-AU2hash function family and the dual of large-girth LDPC codes. Concretely, the sender Alice first generates a message tag T with message M and key K by using a lightweight ϵ-AU2hash functions; then Alice encodes T to a codeword Xnwith the dual of large-girth LDPC codes; finally, Alice sends (M, Xn) to the receiver Bob noiselessly. An adversary Eve has infinite computational capacity, and he can obtain M and the output Znof the BEC with input Xn. Then, an authentication scheme over binary erasure channel and binary-input wiretapper's channel is further developed, which can reduce the noisy main channel case to noiseless main channel case by leveraging public discussion. We theoretically prove that, the proposed schemes are perfect secure if the number of attacks from Eve is upper bounded by a polynomial times in terms of n. Furthermore, the simulation results are provided to demonstrate that the proposed schemes can achieve high authentication rate with low time latency.
Dajiang Chen, Ning Zhang 0007, Rongxing Lu, Xiaojie Fang, Kuan Zhang 0001, Zhiguang Qin, Xuemin Shen
IEEE J. Sel. Areas Commun.5
2018 Exploiting Social Network to Enhance Human-to-Human Infection Analysis without Privacy Leakage
abstract
Human-to-human infection, as a type of fatal public health threats, can rapidly spread, resulting in a large amount of labor and health cost for treatment, control and prevention. To slow down the spread of infection, social network is envisioned to provide detailed contact statistics to isolate susceptive people who has frequent contacts with infected patients. In this paper, we propose a novel human-to-human infection analysis approach by exploiting social network data and health data that are collected by social network and e-healthcare technologies. We enable the social cloud server and health cloud server to exchange social contact information of infected patients and user's health condition in a privacy-preserving way. Specifically, we propose a privacy-preserving data query method based on conditional oblivious transfer to guarantee that only the authorized entities can query users’ social data and the social cloud server cannot infer anything during the query. In addition, we propose a privacy-preserving classification-based infection analysis method that can be performed by untrusted cloud servers without accessing the users’ health data. The performance evaluation shows that the proposed approach achieves higher infection analysis accuracy with the acceptable computational overhead.
Kuan Zhang 0001, Xiaohui Liang 0002, Jianbing Ni, Kan Yang 0001, Xuemin Shen
IEEE Trans. Dependable Secur. Comput.1
2018 Performance Analysis of IEEE 802.15.6-Based Coexisting Mobile WBANs With Prioritized Traffic and Dynamic Interference
abstract
Intelligent wireless body area networks (WBANs) have entered into an incredible explosive popularization stage. WBAN technologies facilitate real-time and reliable health monitoring in e-healthcare and creative applications in other fields. However, due to the limited space and medical resources, deeply deployed WBANs are suffering severe interference problems. The interference affects the reliability and timeliness of data transmissions, and the impacts of interference become more serious in mobile WBANs because of the uncertainty of human movement. In this paper, we analyze the dynamic interference taking human mobility into consideration. The dynamic interference is investigated in different situations for WBANs coexistence. To guarantee the performance of different traffic types, a health critical index is proposed to ensure the transmission privilege of emergency data for intra- and inter-WBANs. Furthermore, the performance of the target WBAN, i.e., normalized throughput and average access delay, under different interference intensity are evaluated using a developed three-dimensional Markov chain model. Extensive numerical results show that the interference generated by mobile neighbor WBANs results in 70% throughput decrease for general medical data and doubles the packet delay experienced by the target WBAN for emergency data compared with single WBAN. The evaluation results greatly benefit the network design and management as well as the interference mitigation protocols design.
Xiaoming Yuan 0002, Changle Li, Qiang Ye 0002, Kuan Zhang 0001, Nan Cheng 0001, Ning Zhang 0007, Xuemin Shen
IEEE Trans. Wirel. Commun.4
2018 Crowdsourcing for Mobile Networks and IoT
Xiping Hu, Zhaolong Ning, Kuan Zhang 0001, Edith C. H. Ngai, Fei Wang 0001
Wirel. Commun. Mob. Comput.3
2018 Adaptive Transmission Range Based Topology Control Scheme for Fast and Reliable Data Collection
abstract
An Adaptive Transmission Range Based Topology Control (ATRTC) scheme is proposed to reduce delay and improve reliability for data collection in delay and loss sensitive wireless sensor network. The core idea of the ATRTC scheme is to extend the transmission range to speed up data collection and improve the reliability of data collection. The main innovations of our work are as follows: (1) an adaptive transmission range adjustment method is proposed to improve data collection reliability and reduce data collection delay. The expansion of the transmission range will allow the data packet to be received by more receivers, thus improving the reliability of data transmission. On the other hand, by extending the transmission range, data packets can be transmitted to the sink with fewer hops. Thereby the delay of data collection is reduced and the reliability of data transmission is improved. Extending the transmission range will consume more energy. Fortunately, we found the imbalanced energy consumption of the network. There is a large amount of energy remains when the network died. ATRTC scheme proposed in this paper can make full use of the residual energy to extend the transmission range of nodes. Because of the expansion of transmission range, nodes in the network form multiple paths for data collection to the sink node. Therefore, the volume of data received and sent by the near‐sink nodes is reduced, the energy consumption of the near‐sink nodes is reduced, and the network lifetime is increased as well. (2) According to the analysis in this paper, compared with the CTPR scheme, the ATRTC scheme reduces the maximum energy consumption by 9%, increases the network lifetime by 10%, increases the data collection reliability by 7.3%, and reduces the network data collection time by 23%.
Haojun Teng, Kuan Zhang 0001, Mianxiong Dong, Kaoru Ota, Anfeng Liu, Ming Zhao 0007, Tian Wang 0001
Wirel. Commun. Mob. Comput.2
2017 Channel-Based Sampling Rate and Queuing State Control in Delay-Constraint Industrial WSNs
abstract
Industrial Wireless Sensor Networks (IWSNs) improve the transmission precision of control signaling as well as contributing to the real-time data monitoring and instrument fault diagnosing throughout the manufacturing production. However, wireless channel effects, such as multipath attenuations, noise and co- channel interference, may have unpredictable and time-varying impacts on keeping packets transmission delay. To address this issue, we propose a Channel-based Sampling rate and Queuing state Control (CSQC) scheme to minimize the packet transmission delay in IWSNs. Specifically, we explore the rapid fading characteristics of the industrial wireless channel by studying the level crossing rate (LCR). We develop a continuous-time Markov model to evaluate the packet sojourn time and design an expectation-maximization (EM) algorithm to timely calibrate the transition rate in the model. Finally, we optimize the sensor sampling rate and queuing state to minimize the packet queuing delay in IWSNs. Simulation results show that the CSQC scheme has lower delay than IEEE 802.15.4 standard does under varying interference effects.
Qihao Li, Kuan Zhang 0001, Michael Cheffena, Xuemin Shen
GLOBECOM2
2017 Channel-Based Sybil Detection in Industrial Wireless Sensor Networks: A Multi-Kernel Approach
abstract
Industrial Wireless Sensor Networks (IWSNs) integrate various types of sensors to measure and control industrial production. However, the unattended open environment makes IWSNs vulnerable to malicious attacks, such as Sybil attacks, which may degrade the network performance. In addition, multipath distortion, impulse noise and interference effects in the harsh industrial environment may influence the accuracy of attack detection. In this paper, we propose a Sybil detection scheme based on power gain and delay spread analysis by exploiting the spatial variability from their channel responses. Specifically, we utilize channel-vectors to represent the sensor features based on the power gain and delay spread extracted from channel response. Furthermore, we develop a kernel-oriented method to distinguish Sybil attackers from benign sensors by clustering the channel-vectors. In addition, to alleviate the impact of industrial noise and interference effects, we design a multi-kernel based fuzzy c-means method to map the extracted channel-vectors into a new feature space such that the dispersive effects on the channel-vectors can be reduced. We also propose a parameter selection method to optimize the employed kernels. The simulation results show that the proposed multi-kernel scheme can achieve high accuracy in detecting the packets from Sybil attackers, and tolerate the dispersive attenuation and interference effects in the industrial environments.
Qihao Li, Kuan Zhang 0001, Michael Cheffena, Xuemin Shen
GLOBECOM2
2017 Lightweight and Privacy-Preserving Fog-Assisted Information Sharing Scheme for Health Big Data
abstract
With the advancements of electronic medical equipment, e-healthcare system becomes a promising paradigm to continuously monitor health conditions and remotely diagnose phenomena. Meanwhile, it generates a large volume of health data and poses several security challenges, such as access control and privacy leakage. In this paper, we propose a lightweight and privacy- preserving fog-assisted information sharing scheme (PFHD) for health big data. Specifically, we integrate fog computing into e-healthcare system to pre-process the raw health data and improve the efficiency of health data analysis. Furthermore, to prevent privacy leakage, we design a hierarchical attribute-based encryption method by encrypting the profile and health data with different access policies. In addition, we reduce the computation cost on devices by offloading health data encryption from devices to fog servers. Security discussions show that PFHD can achieve fine- grained health data sharing with privacy preservation. Performance evaluations demonstrate the efficiency of PFHD, especially in terms of encryption computation and storage costs.
Wenjuan Tang, Kuan Zhang 0001, Ju Ren 0001, Yaoxue Zhang, Xuemin Shen
GLOBECOM2
2017 Impact factor-based group recommendation scheme with privacy preservation in MSNs
abstract
Mobile Social Networks (MSNs) provide a variety of social networking applications in mobile environment, where social group finds and recruits potential members easily. Unfortunately, users enjoy these conveniences at the cost of revealing their personal data. Additionally, people usually ignore a critical factor, Impact Factor (IF), which is used to quantify group members' influence on their groups, since a group member with larger IF generally has a greater influence on potential new member recommendation. In this paper, we propose IF-RG, an IF-based group recommendation scheme with privacy preservation in MSNs. First, we construct a transmission matrix and exploit PageRank algorithm to compute and update group members' IFs. The average variation of IF is formed to measure convergence speed of the iteration method of computing IF. To make sure that the larger IFs, the more influence, IF, Ochiai similarity function and weighted majority rule are integrated in the novel matching degree between stranger and group. The fuzzy matrix algorithm not only protects users' privacy, but also helps our scheme to support group recommendation when not every one in the groups is online. Finally, security and performance are analyzed and evaluated via detailed simulations.
Yuanyuan He 0002, Kuan Zhang 0001, Fenghua Li 0001, Ben Niu 0001, Hui Li 0006
ICC2
2017 A measurement-based boundary estimation approach for localization in industrial WSNs
abstract
Localization in Industrial Wireless Sensor Networks (IWSNs) promotes innovations in manufacturing applications, such as structural status mapping, instrument fault diagnosing and oriented automation system associating. However, dispersive distortion, impulse noise and interference effects causing unpredictable and time-variant effects of the signal, decrease the localization accuracy in harsh manufacturing environments. In this paper, we propose a noise reduction localization scheme in IWSNs, called Support Vector Semidefinite (SVSD), based on practical industrial wireless channel measurements. We introduce an e-insensitive error function to evade the effects of impulse noise and interference by applying a new statistical path-loss model obtained from the measurements. We further relieve the noise effects by estimating the boundaries of the sensor locations before addressing the localization. Considering the boundaries, we obtain the sensor locations by utilizing semidefinite programming (SDP) relaxation. Simulation results show that the SVSD scheme provides higher location estimation accuracy than the SDP scheme under varying noise effects.
Qihao Li, Kuan Zhang 0001, Michael Cheffena, Xuemin Shen
ICC2
2017 Privacy-preserving mobile crowdsensing for located-based applications
abstract
Mobile crowdsensing is a new paradigm which explores the mobility and intelligence of mobile users to collect high-quality data from social events and phenomena for conducting complex sensing tasks. Nevertheless, privacy preservation and task allocation become main obstacles that need additional attention. To achieve accurate task allocation, it is inevitable to share some sensitive information of mobile users and customers, such as identities, location and points of interest. In this paper, we propose a privacy-preserving mobile crowdsensing framework (PPMC) for location-based applications to balance the tradeoff between privacy preservation and task allocation. In PPMC, we develop a matrix-based location matching mechanism for the service provider to achieve location-based task allocation without disclosing the location of mobile users and the sensing area of tasks. We also extend BBS+ signature and proxy reencryption to preserve identity privacy and data privacy for both customers and mobile users under the condition that they are honest to release and perform tasks, respectively. Finally, we discuss security properties and demonstrate the efficiency of PPMC in terms of computational and communication overhead.
Jianbing Ni, Kuan Zhang 0001, Xiaodong Lin 0001, Qi Xia 0001, Xuemin Shen
ICC2
2017 Multi-message Authentication over Noisy Channel with Polar Codes
abstract
In this paper, we investigate multi-message authentication to combat adversaries with infinite computational capacity. An authentication framework over a wiretap channel (W_1, W_2) is proposed to achieve information-theoretic security with the same key. The proposed framework bridges the two research areas in physical (PHY) layer security: secure transmission and message authentication. Specifically, the sender Alice first transmits message M to the receiver Bob over (W_1, W_2) with an error correction code; then Alice employs a hash function (i.e., ε-AWU_2 hash functions) to generate a message tag S of message M using key K, and encodes S to a codeword X^n by leveraging an existing strongly secure channel coding with exponentially small (in code length n) average probability of error; finally, Alice sends X^n over (W_1, W_2) to Bob who authenticates the received messages. We develop a theorem regarding the requirements/conditions for the authentication framework to be information-theoretic secure for authenticating a polynomial number of messages. Based on this theorem, we propose and implement an efficient and feasible authentication protocol over binary symmetric wiretap channel (BSWC) by using Linear Feedback Shifting Register based (LFSR-based) hash functions and strong secure polar code. Through extensive experiments, it is demonstrated that the proposed protocol can achieve low time cost, high authentication rate, and low authentication error rate.
Dajiang Chen, Nan Cheng 0001, Ning Zhang 0007, Kuan Zhang 0001, Zhiguang Qin, Xuemin Shen
MASS4
2017 Privacy-preserving attribute-keyword based data publish-subscribe service on cloud platforms
Kan Yang 0001, Kuan Zhang 0001, Xiaohua Jia, M. Anwar Hasan, Xuemin Shen
Inf. Sci.2
2017 SIRC: A Secure Incentive Scheme for Reliable Cooperative Downloading in Highway VANETs
abstract
In this paper, we propose a secure incentive scheme to achieve fair and reliable cooperative (SIRC) downloading in highway vehicular ad hoc networks (VANETs). SIRC can stimulate vehicle users to help download-and-forward packets for each other and consists of cooperative downloading and forwarding phase. During the cooperative downloading phase, SIRC utilizes “virtual checks” associated with the designated verifier signature to ensure fair and secure cooperation. Meanwhile, to minimize the payment risk of the client vehicle, partial prepayment strategy is adopted, i.e., the vehicles involved in downloading packets can only obtain part of the check before the client vehicle confirms the packet reception. During the cooperative forwarding phase, a profit-sharing model associated with an aggregating Camenisch-Lysyanskaya (CL) signature can stimulate cooperation and reduce the authentication overhead. In addition, we develop a reputation system to encourage cooperation and punish malicious vehicles. The aggregating CL signature and the symmetric cryptosystem are applied to resist various attacks, including injection/removing attack, free riding attack, submission refusal attack, and denial of service attacks. Extensive simulation results are given to show that the proposed SIRC can achieve a high download success rate and low average download delay with moderate cryptographic computation and communication overhead.
Chengzhe Lai, Kuan Zhang 0001, Nan Cheng 0001, Hui Li 0006, Xuemin Shen
IEEE Trans. Intell. Transp. Syst.2
2016 Secure and Deduplicated Spatial Crowdsourcing: A Fog-Based Approach
abstract
With the proliferation of mobile devices, spatial crowdsourcing is rising as a new paradigm that enables individuals to participate in tasks related to some locations in the physical world. Nevertheless, how to allocate these tasks to proper mobile users and improve communication efficiency are critical in spatial crowdsourcing. In this paper, we propose Fo-DSC, a fog-based deduplicated spatial crowdsourcing framework to achieve precise task allocation and secure data deduplication. Specifically, by integrating fog computing, we design a two-step task allocation mechanism to improve the accuracy of tasks allocation in spatial crowdsourcing. The fog nodes can detect and erase the repeated data in crowdsensing reports without learning any information about the reports. Furthermore, Fo-DSC efficiently records the contributions of mobile users whose data are reduplicated and deleted. As a result, these users do not become discouraged. Finally, we demonstrate that Fo-DSC satisfies the properties of fog-based task allocation and secure data deduplication with low computational and communication overheads.
Jianbing Ni, Xiaodong Lin 0001, Kuan Zhang 0001, Yong Yu 0002
GLOBECOM3
2016 EDAT: Efficient data aggregation without TTP for privacy-assured smart metering
abstract
Smart meters are integral to power dispatch in the emerging smart grid, by periodically collecting and reporting the electricity consumption of users to the control center to satisfy practical requirements. However, the real-time electricity measurements of individual households may contain plenty of users' privacy, e.g., activities and habits. To resist the privacy exposure from the individual measurements, we propose an Efficient Data AggregaTion (EDAT) scheme, in which every smart meter in the residential area uses a random noise to protect the concrete reading from being exposed to the attackers and the local gateway aggregates the individual measurements into a compact report before forwarding to the control center. In EDAT scheme, we remove the trusted third party and allow the smart meters to negotiate and generate the sum of the noise using polynomials, by which the control center can recover the power consumption of a residential area, other than a specific household. The security of the EDAT scheme can be reduced to the Decisional Diffie-Hellman assumption, and both the computational and communication overhead of each smart meter are small.
Jianbing Ni, Kuan Zhang 0001, Xiaodong Lin 0001, Xuemin Shen
ICC2
2016 AMA: Anonymous mutual authentication with traceability in carpooling systems
abstract
Carpooling, as an effective and eco-friendly travel mode, becomes a kind of public spontaneous behavior with multiple travellers sharing a vehicle to reduce individuals' travel cost, carbon emissions and traffic congestion. Although ubiquitous network access offers great convenience for travellers to find carpools, the safety becomes a big obstacle for them to accept this emerging travel mode. To address the safety concern, it seems inevitable to sacrifice the identity privacy for both drivers and passengers. In this paper, we propose an Anonymous Mutual Authentication (AMA) protocol to solve the contradiction between safety and privacy preservation by utilizing the BBS+ signature. In AMA, the passenger and the driver can mutually authenticate the identities without exposing their actual identities, but showing their membership of a trustable group. The AMA also allows to trace the identity of the driver (the passenger) on behalf of a judger if the passenger (the driver) complains the misbehavior of the driver (the passenger). The AMA is secure and efficient for real applications.
Jianbing Ni, Kuan Zhang 0001, Xiaodong Lin 0001, Haomiao Yang, Xuemin Shen
ICC2
2016 Cloud-Based Privacy-Preserving Parking Navigation Through Vehicular Communications
Jianbing Ni, Kuan Zhang 0001, Xiaodong Lin 0001, Yong Yu 0002, Xuemin Shen
SecureComm2
2016 Privacy-Preserving Real-Time Navigation System Using Vehicular Crowdsourcing
abstract
Traffic congestions cause not only the time- consuming and frustrating experiences to drivers, but also other critical problems, such as fuel waste, air pollution and accidents. Real-time traffic information exchange can avoid vehicles being congested on roads. However, when the drivers are acquiring the traffic information, their privacy is inevitable to be disclosed. To preserve the driver's privacy, in this paper, we propose a privacy-preserving real-time navigation system (PRIN) using vehicular crowdsourcing. In PRIN, the RSUs cooperatively find an optimal path for the querying vehicle to the destination according to the real-time traffic information crowdsourced by the vehicles in their coverage areas. The querying vehicle retrieves the navigation result from each RSU successively when entering its coverage area, and follows the proper driving route to the next RSU, until reaching its destination. During these querying, crowdsourcing and retrieving processes, the driver's personal information, such as location, identity, is protected from being disclosed to attackers. In addition, a trusted authority can trace the drivers' identities if they upload false traffic information. Finally, we discuss the properties of conditional privacy preservation and demonstrate the efficiency of PRIN.
Jianbing Ni, Xiaodong Lin 0001, Kuan Zhang 0001, Xuemin Shen
VTC Fall3
2016 CIT: A credit-based incentive tariff scheme with fraud-traceability for smart grid
abstract
Abstract The growing peak‐hour power demand has invoked an urgency to increase the peak‐hour supply. Although smart grid has been envisioned as the next generation power system due to its two‐way communication of information and power, the peak‐hour power shortage problem still exists. In this paper, we propose a credit‐based incentive tariff (CIT) scheme with fraud‐traceability for smart grid. Specifically, the CIT encourages retail customers to sell the power generated by their renewable resources back to the grid during peak hours via giving additional incentive rate to them based on their credits. If a fraud is detected during the power transaction, the malicious customer's identity can be traced out and his or her credit can be correspondingly reduced. The security analysis shows that the CIT resists various security threats and makes the incentive tariff fair and more secure. The performance evaluation demonstrates that the CIT can dramatically increase the peak‐hour supply and reduce the peak‐to‐average power demand ratio by up to 7%. Copyright © 2013 John Wiley & Sons, Ltd.
Mi Wen, Kuan Zhang 0001, Jingsheng Lei, Xiaohui Liang 0002, Ruilong Deng, Xuemin Shen
Secur. Commun. Networks2
2016 Lifetime and Energy Hole Evolution Analysis in Data-Gathering Wireless Sensor Networks
abstract
Network lifetime is a crucial performance metric to evaluate data-gathering wireless sensor networks (WSNs) where battery-powered sensor nodes periodically sense the environment and forward collected samples to a sink node. In this paper, we propose an analytic model to estimate the entire network lifetime from network initialization until it is completely disabled, and determine the boundary of energy hole in a data-gathering WSN. Specifically, we theoretically estimate the traffic load, energy consumption, and lifetime of sensor nodes during the entire network lifetime. Furthermore, we investigate the temporal and spatial evolution of energy hole and apply our analytical results to WSN routing in order to balance the energy consumption and improve the network lifetime. Extensive simulation results are provided to demonstrate the validity of the proposed analytic model in estimating the network lifetime and energy hole evolution process.
Ju Ren 0001, Yaoxue Zhang, Kuan Zhang 0001, Anfeng Liu, Jianer Chen, Xuemin Shen
IEEE Trans. Ind. Informatics3
2016 Exploiting Secure and Energy-Efficient Collaborative Spectrum Sensing for Cognitive Radio Sensor Networks
abstract
Cognitive radio sensor network (CRSN) has emerged as a promising solution to address the spectrum scarcity problem in traditional sensor networks, by enabling sensor nodes to opportunistically access licensed spectrum. To protect the transmission of primary users and enhance spectrum utilization, collaborative spectrum sensing is generally adopted for improving spectrum sensing accuracy. However, as sensor nodes may be compromised by adversaries, these nodes can send false sensing reports to mislead the spectrum sensing decision, making CRSNs vulnerable to spectrum sensing data falsification (SSDF) attacks. Meanwhile, since the energy consumption of spectrum sensing is considerable for energy-limited sensor nodes, SSDF attack countermeasures should be carefully devised with the consideration of energy efficiency. To this end, we propose a secure and energy-efficient collaborative spectrum sensing scheme to resist SSDF attacks and enhance the energy efficiency in CRSNs. Specifically, we theoretically analyze the impacts of two types of attacks, i.e., independent and collaborative SSDF attacks, on the accuracy of collaborative spectrum sensing in a probabilistic way. To maximize the energy efficiency of spectrum sensing, we calculate the minimum number of sensor nodes needed for spectrum sensing to guarantee the desired accuracy of sensing results. Moreover, a trust evaluation scheme, named FastDtec, is developed to evaluate the spectrum sensing behaviors and fast identify compromised nodes. Finally, a secure and energy-efficient collaborative spectrum sensing scheme is proposed to further improve the energy efficiency of collaborative spectrum sensing, by adaptively isolating the identified compromised nodes from spectrum sensing. Extensive simulation results demonstrate that our proposed scheme can resist SSDF attacks and significantly improve the energy efficiency of collaborative spectrum sensing.
Ju Ren 0001, Yaoxue Zhang, Qiang Ye 0002, Kan Yang 0001, Kuan Zhang 0001, Xuemin Shen
IEEE Trans. Wirel. Commun.5
2016 Adaptive and Channel-Aware Detection of Selective Forwarding Attacks in Wireless Sensor Networks
abstract
Wireless sensor networks (WSNs) are vulnerable to selective forwarding attacks that can maliciously drop a subset of forwarding packets to degrade network performance and jeopardize the information integrity. Meanwhile, due to the unstable wireless channel in WSNs, the packet loss rate during the communication of sensor nodes may be high and vary from time to time. It poses a great challenge to distinguish the malicious drop and normal packet loss. In this paper, we propose a channel-aware reputation system with adaptive detection threshold (CRS-A) to detect selective forwarding attacks in WSNs. The CRS-A evaluates the data forwarding behaviors of sensor nodes, according to the deviation of the monitored packet loss and the estimated normal loss. To optimize the detection accuracy of CRS-A, we theoretically derive the optimal threshold for forwarding evaluation, which is adaptive to the time-varied channel condition and the estimated attack probabilities of compromised nodes. Furthermore, an attack-tolerant data forwarding scheme is developed to collaborate with CRS-A for stimulating the forwarding cooperation of compromised nodes and improving the data delivery ratio of the network. Extensive simulation results demonstrate that CRS-A can accurately detect selective forwarding attacks and identify the compromised sensor nodes, while the attack-tolerant data forwarding scheme can significantly improve the data delivery ratio of the network.
Ju Ren 0001, Yaoxue Zhang, Kuan Zhang 0001, Xuemin Shen
IEEE Trans. Wirel. Commun.3
2016 CSMA/CA-based medium access control for indoor millimeter wave networks
abstract
Abstract Millimeter wave (mmWave) communication is a promising technology to support high‐rate (e.g., multi‐Gbps) multimedia applications because of its large available bandwidth. Multipacket reception is one of the important capabilities of mmWave networks to capture a few packets simultaneously. This capability has the potential to improve medium access control layer performance. Because of the severe propagation loss in mmWave band, traditional backoff mechanisms in carrier sensing multiple access/collision avoidance (CSMA/CA) designed for narrowband systems can result not only in unfairness but also in significant throughput reduction. This paper proposes a novel backoff mechanism in CSMA/CA by giving a higher transmission probability to the node with a transmission failure than that with a transmission success, aiming to improve the system throughput. The transmission probability is adjusted by changing the contention window size according to the congestion status of each node and the whole network. The analysis demonstrates the effectiveness of the proposed backoff mechanism on reducing transmission collisions and increasing network throughput. Extensive simulations show that the proposed backoff mechanism can efficiently utilize network resources and significantly improve the network performance on system throughput and fairness. Copyright © 2014 John Wiley & Sons, Ltd.
Jian Qiao, Xuemin Shen, Jon W. Mark, Bin Cao 0003, Zhiguo Shi 0001, Kuan Zhang 0001
Wirel. Commun. Mob. Comput.6
2015 Exploiting mobile social behaviors for Sybil detection
abstract
In this paper, we propose a Social-based Mobile Sybil Detection (SMSD) scheme to detect Sybil attackers from their abnormal contacts and pseudonym changing behaviors. Specifically, we first define four levels of Sybil attackers in mobile environments according to their attacking capabilities. We then exploit mobile users' contacts and their pseudonym changing behaviors to distinguish Sybil attackers from normal users. To alleviate the storage and computation burden of mobile users, the cloud server is introduced to store mobile user's contact information and to perform the Sybil detection. Furthermore, we utilize a ring structure associated with mobile user's contact signatures to resist the contact forgery by mobile users and cloud servers. In addition, investigating mobile user's contact distribution and social proximity, we propose a semi-supervised learning with Hidden Markov Model to detect the colluded mobile users. Security analysis demonstrates that the SMSD can resist the Sybil attackers from the defined four levels, and the extensive trace-driven simulation shows that the SMSD can detect these Sybil attackers with high accuracy.
Kuan Zhang 0001, Xiaohui Liang 0002, Rongxing Lu, Kan Yang 0001, Xuemin Shen
INFOCOM1
2015 SACRM: Social Aware Crowdsourcing with Reputation Management in mobile sensing
Ju Ren 0001, Yaoxue Zhang, Kuan Zhang 0001, Xuemin Shen
Comput. Commun.3
2015 PIF: A Personalized Fine-Grained Spam Filtering Scheme With Privacy Preservation in Mobile Social Networks
abstract
Mobile social network (MSN) emerges as a promising social network paradigm that enables mobile users' information sharing in the proximity and facilitates their cyber-physical-social interactions. As the advertisements, rumors, and spams spread in MSNs, it is necessary to filter spams before they arrive at the recipients to make the MSN energy efficient. To this end, we propose a personalized fine-grained filtering scheme (PIF) with privacy preservation in MSNs. Specifically, we first develop a social-assisted filter distribution scheme, where the filter creators send filters to their social friends (i.e., filter holders). These filter holders store filters and decide to block spams or relay the desired packets through coarse-grained and fine-grained keyword filtering schemes. Meanwhile, the developed cryptographic filtering schemes protect creator's private information (i.e., keyword) embedded in the filters from directly disclosing to other users. In addition, we establish a Merkle Hash tree to store filters as leaf nodes where filter creators can check if the distributed filters need to be updated by retrieving the value of root node. It is demonstrated that the PIF can protect users' private keywords included in the filter from disclosure to others and detect forged filters. We also conduct the trace-driven simulations to show that the PIF can not only filter spams efficiently but also achieve high delivery ratio and low latency with acceptable resource consumption.
Kuan Zhang 0001, Xiaohui Liang 0002, Rongxing Lu, Xuemin Shen
IEEE Trans. Comput. Soc. Syst.1
2014 PMQC: A privacy-preserving multi-quality charging scheme in V2G network
abstract
Multi-quality charging, which provides the electric vehicles (EVs) with multiple levels of charging services, including quality-guaranteed service (QGS) and best effort service (BES), can guarantee the charging service quality for the qualified EVs in vehicle-to-grid (V2G) network. To perform the multi-quality charging, the evaluation on the EVs attributes is necessary to determine which level of charging service can be offered to this EV. However, the EV owner's privacy such as real identity, lifestyle, location, and sensitive information in the attributes may be disclosed during the evaluation and authentication. In this paper, we propose a privacy-preserving multi-quality charging (PMQC) scheme in V2G network to evaluate the EVs attributes, authenticate its service eligibility and generate its bill without revealing the EVs private information. Specifically, we propose an evaluation mechanism on the EVs attributes to determine its charging service quality. With attribute based encryption, PMQC can prevent the EVs attributes from being disclosed to other entities during the evaluation. In addition, PMQC can authenticate the EV without revealing its real identity. Security analysis demonstrates that the EVs privacy mentioned above can be preserved by PMQC. Performance evaluation results show that PMQC can achieve higher efficiency in authentication compared with other schemes in terms of computation overhead.
Kuan Zhang 0001, Xuemin Shen
GLOBECOM2
2014 Exploiting channel-aware reputation system against selective forwarding attacks in WSNs
abstract
Wireless sensor networks (WSNs) are vulnerable to selective forwarding attacks that selectively drop a subset of the forwarding packets to degrade network performances. Due to unstable wireless channels, the packet loss rate between sensor nodes might be high, especially in hostile environments. Therefore, it is difficult to distinguish the malicious drop and normal packet loss. In this paper, we propose a Channel-aware deputation System (CRS) to identify selective forwarding misbehaviours from normal packet losses caused by poor channel quality or medium access collision. Specifically, CRS is based on normal packet loss estimation and neighbour monitoring. Each node maintains a reputation table to evaluate forwarding behaviours of its neighbours. Reputation value is determined by the deviation of the monitored packet loss rate and estimated normal loss rate. The nodes with reputation below a threshold are identified as misbehaving nodes and isolated from data forwarding paths. Furthermore, we develop weighted reputation propagation and integration functions to improve detection efficiency. Through theoretical analysis and extensive simulations, we demonstrate that CRS can accurately detect selective forwarding attacks and significantly improve the network throughput.
Ju Ren 0001, Yaoxue Zhang, Kuan Zhang 0001, Xuemin Shen
GLOBECOM3
2014 CPAL: A Conditional Privacy-Preserving Authentication With Access Linkability for Roaming Service
abstract
The roaming service enables mobile subscribers to access the internet service anytime and anywhere, which can fulfill the requirement of ubiquitous access for the emerging paradigm of networking, e.g., the Internet of Things (IoT). In this paper, we propose a conditional privacy-preserving authentication with access linkability (CPAL) for roaming service, to provide universal secure roaming service and multilevel privacy preservation. CPAL provides an anonymous user linking function by utilizing a novel group signature technique, which can not only efficiently hide users’ identities but also enables the authorized entities to link all the access information of the same user without knowing the user’s real identity. Specifically, by using the master linking key possessed by the trust linking server, the authorized foreign network operators or service providers can link the access information from the user to improve its service, while preserving user anonymity, e.g., using individual access information to analyze user preferences without revealing user’s identity. Furthermore, the subscribers can also use this functionality to anonymously query their usage of service. In addition, CPAL has an efficient revocation function, which revokes a group of users at the same time. Through extensive analysis, we demonstrate that CPAL resists various security threats and provides more flexible privacy preservation compared to the existing schemes. Meanwhile, performance evaluations demonstrate its efficiency in terms of communication and computation overhead.
Chengzhe Lai, Hui Li 0006, Xiaohui Liang 0002, Rongxing Lu, Kuan Zhang 0001, Xuemin Shen
IEEE Internet Things J.5
2014 Sybil Attacks and Their Defenses in the Internet of Things
abstract
The emerging Internet-of-Things (IoT) are vulnerable to Sybil attacks where attackers can manipulate fake identities or abuse pseudoidentities to compromise the effectiveness of the IoT and even disseminate spam. In this paper, we survey Sybil attacks and defense schemes in IoT. Specifically, we first define three types Sybil attacks: SA-1, SA-2, and SA-3 according to the Sybil attacker's capabilities. We then present some Sybil defense schemes, including social graph-based Sybil detection (SGSD), behavior classification-based Sybil detection (BCSD), and mobile Sybil detection with the comprehensive comparisons. Finally, we discuss the challenging research issues and future directions for Sybil defense in IoT.
Kuan Zhang 0001, Xiaohui Liang 0002, Rongxing Lu, Xuemin Shen
IEEE Internet Things J.1
2014 PHDA: A priority based health data aggregation with privacy preservation for cloud assisted WBANs
Kuan Zhang 0001, Xiaohui Liang 0002, Mrinmoy Barua, Rongxing Lu, Xuemin Shen
Inf. Sci.1
2013 SAFE: A social based updatable filtering protocol with privacy-preserving in mobile social networks
abstract
Mobile Social Networks (MSN), as an emerging social networking platform, facilitates social interaction and information sharing among users in the proximity. Spam filtering protocols are extremely important to reduce communication and storage overhead when many spam packets without specific destinations are diffused in MSNs. In this paper, we propose an effective social based updatable filtering protocol (SAFE) with privacy preservation in MSNs. Specifically, we firstly construct a filter Hash tree based on the properties of Merkle tree. Then, we exploit social relationships, and select those users with more than a specific number of common attributes with the filter creator. The selected users are able to store filters in order to block spams or relay regular packets. Furthermore, we develop a cryptographic filtering scheme without disclosing the creator's private information or interests. In addition, we propose a filter update mechanism to allow users to update their distributed filters in time. The security analysis demonstrates that the SAFE can protect user's private information from filter's disclosure to other users and resist filter forgery attack. Through extensive trace-driven simulations, we show that the SAFE is effective and efficient to filter spam packets in terms of delivery ratio, average delay, and communication overhead.
Kuan Zhang 0001, Xiaohui Liang 0002, Rongxing Lu, Xuemin Shen
ICC1
2013 A novel low-power mixed-mode implementation of weight update in particle PHD filters
abstract
Power dissipation and hardware cost are two major design concerns in the hardware implementation of particle probability hypothesis density (PHD) filters, wherein the weight update is a crucial design task due to its complicated operation and sequential nature. In this paper, we propose a novel mixed-mode implementation of the weight update in particle PHD filter, which outperforms its counterpart digital-form implementation in terms of power dissipation and hardware resource consumption. In specific, the mixed-mode implementation uses multiple-input translinear element (MITE) networks to realize the likelihood function of weight update in the analog domain. The MITE networks, which are operated in subthreshold region, contribute to the low-power implementation of the particle PHD filters, and can lead to parallel implementation of the weight update with lower hardware cost. Extensive simulations are conducted with circuit models and parameters from the Taiwan Semiconductor Manufacturing Company (TSMC) 0.18μm CMOS technology library for mixed-mode implementation of weight update, and the results show that the analog errors in this mixed mode implementation are negligible when used to support real-world multi-target tracking.
Yingbin Liu, Zhiguo Shi 0001, Kuan Zhang 0001, Yunmei Zheng, Rongxing Lu, Xuemin Shen
WCNC3
2013 Fully Anonymous Profile Matching in Mobile Social Networks
abstract
In this paper, we study user profile matching with privacy-preservation in mobile social networks (MSNs) and introduce a family of novel profile matching protocols. We first propose an explicit Comparison-based Profile Matching protocol (eCPM) which runs between two parties, an initiator and a responder. The eCPM enables the initiator to obtain the comparison-based matching result about a specified attribute in their profiles, while preventing their attribute values from disclosure. We then propose an implicit Comparison-based Profile Matching protocol (iCPM) which allows the initiator to directly obtain some messages instead of the comparison result from the responder. The messages unrelated to user profile can be divided into multiple categories by the responder. The initiator implicitly chooses the interested category which is unknown to the responder. Two messages in each category are prepared by the responder, and only one message can be obtained by the initiator according to the comparison result on a single attribute. We further generalize the iCPM to an implicit Predicate-based Profile Matching protocol (iPPM) which allows complex comparison criteria spanning multiple attributes. The anonymity analysis shows all these protocols achieve the confidentiality of user profiles. In addition, the eCPM reveals the comparison result to the initiator and provides only conditional anonymity; the iCPM and the iPPM do not reveal the result at all and provide full anonymity. We analyze the communication overhead and the anonymity strength of the protocols. We then present an enhanced version of the eCPM, called eCPM+, by combining the eCPM with a novel prediction-based adaptive pseudonym change strategy. The performance of the eCPM and the eCPM+ are comparatively studied through extensive trace-based simulations. Simulation results demonstrate that the eCPM+ achieves significantly higher anonymity strength with slightly larger number of pseudonyms than the eCPM.
Xiaohui Liang 0002, Xu Li 0001, Kuan Zhang 0001, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen
IEEE J. Sel. Areas Commun.3
2012 VSLP: Voronoi-socialspot-aided packet forwarding protocol with receiver Location Privacy in MSNs
abstract
With the pervasive use of smart phones in the daily life, location privacy has become one of cruxes for the success of mobile social networks (MSNs). In this paper, we propose a Voronoi-social-spot-aided Location Privacy-preserving (VSLP) packet forwarding protocol to improve the packet forwarding efficiency and at the same time protect receiver's location privacy. In VSLP, we first identify the social spot locations according to the user mobility information, and then build a Voronoi diagram based on the defined social spots. On the edge of Delaunay triangulation over the Voronoi diagram, we deploy multiple storage devices to help receivers to temporarily store the packets. With the security analysis, we show that the location privacy can be achieved. Using extensive simulations, we show that VSLP can enhance the packet forwarding efficiency with improved packet delivery ratio and reduced average packet delay.
Kuan Zhang 0001, Xiaohui Liang 0002, Rongxing Lu, Xuemin Shen, Hai Zhao 0002
GLOBECOM1