Fei Duan

dblp:56/6571 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
6since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 first-author · 5 since 2021Systems, architecture and hardware · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
YearPublicationVenuePosition
2026 Success Rates Doubled with Only One Character: Mask Password Guessing
Yunkai Zou, Ding Wang 0002, Fei Duan
NDSS3
2026 On the Insecurity of Internally Sampled Honeyword Schemes
abstract
Honeywords are plausible-looking decoy passwords associated with each user’s real password to timely detect password leakage. The more indistinguishable the honeywords are, the more secure a honeyword scheme is. However, honeyword schemes that externally generate honeywords can only approximate, but not equate, the distribution of user-chosen passwords, so they are unlikely to achieve the ideal indistinguishability. To address this issue, internally sampled honeyword schemes that sample honeywords from other users’ passwords have been proposed. In this work, we first reveal two critical security and two critical usability flaws in existing internally sampled honeyword schemes, i.e., Honeyindex (TDSC’16) and Superword (COSE’21). We then formalize agenericframework for sound internally sampled honeyword schemes, and propose variants for both Honeyindex and Superword. To principally evaluate the security of our framework, we propose Bayesian and intersection attack theories leading to attackers’ optimal distinguishing strategies, and evaluate them under three major attacker models each with varied capabilities (e.g., using leaked datasets and users’ personal information). Evaluation results show that, when 40 sweetwords are associated with each user (as recommended at IEEE S&P’22), with only one guess per account, the basic attacker’s success rate can reach 3.82%∼4.12%, and she can identify 4.31%∼5.04% of all real passwords with 104honeyword login attempts, breaking the ideal 2.50%(=1/40) security. Two more advanced attackers can identify 18.6%∼44.8% and 20.6%∼43.6% of all real passwords in 104honeyword login attempts, respectively. When multiple password files are available, the intersection attack alone identifies 18.3%∼18.6% of real passwords. We also explore the impacts of denial-of-service attacks. In all, this work reveals theinherentinsecurity of internally sampled honeyword schemes.
Ding Wang 0002, Tingwei Fan, Fei Duan, Zhenduo Hou
IEEE Trans. Inf. Forensics Secur.3
2025 How to Design Secure Honey Vault Schemes
abstract
Password vaults enable a user to store multiple passwords with a single master password.Honey encryption (HE) protected password vaults (called honey vaults), are promising in resisting offline master password guessing attacks.Trial-decrypted with incorrect master passwords, honey vaults are designed to yield plausible-looking decoy vaults to confuse attackers, forcing them to perform online verifications to know whether a decrypted vault is the real one.In this paper, we demonstrate how to design secure honey vault schemes in a principled approach.We first identify three major types of vulnerabilities, and propose three critical design criteria based on rigorous theories, with each aiming to address one type of vulnerability.These criteria are: (1) Employing an accurate password probability model (PPM) in the natural language encoder (NLE, a key component of a honey vault) to resist distribution-aware distinguishing attacks; (2) Employing sequence-based PPMs for unique passwords, and sufficiently concise reuse models to resist encoding attacks (USENIX SEC'19); (3) Hiding a user's real-vault-related (i.e., adaptive) PPM to resist extraction attacks (USENIX SEC'21).To meet these key criteria, we propose VaultGuard with an innovative NLE and HE-Adaptive to honey-encrypt a user's real vault and the adaptive PPM, respectively.Our NLE eliminates the first and second vulnerabilities, while HE-Adaptive addresses the third.Security evaluations on real-world data reveal that our VaultGuard can significantly enhance honey vault security, forcing attackers to perform 1.10∼3.98times online verifications.We also provide an efficient proof-of-concept VaultGuard implementation on the client side.We believe this work provides general principles and actionable guidelines for designing secure honey vault schemes.
Zhenduo Hou, Tingwei Fan, Fei Duan, Ding Wang 0002
CCS3
2024 A Security Analysis of Honey Vaults
abstract
Honey encryption (HE) protected password vaults (called honey vaults) are promising tools that allow a user to store multiple passwords (called a password vault) and encrypt them with a master password using HE. In case password vaults are somehow leaked and the attackers launch offline password guessing, honey vaults can yield decoy password vaults for incorrect guesses, forcing an offline guessing attacker to interact with the authentication server to identify whether passwords in decrypted vaults are correct or not. Therefore, honey vaults transform the offline guessing attacker into an online guessing attacker, i.e., honey vault distinguishing attacker.In online guessing, attackers can adopt various attacks to perform multiple guesses against multiple vaults, but the existing theoretical message recovery (MR) security for HE only focuses on the advantage of one-time guess against a single vault, which cannot accurately model realistic attackers and thus can not provide practical advice for users’ vault security. To address this issue, we propose a theoretically-grounded optimal strategy for distinguishing attackers, and manage to derive a much tighter upper bound on the advantage against MR security. Particularly, we provide much tighter upper/lower bounds for advantage against HE-related cryptographic security games, i.e., the security of distribution transforming encoder (DTE), known message attack, and known side information attack. This provides a better understanding of the actual security of honey encryption.To better understand the security of honey vault systems, we instantiate our optimal strategy into three practical attacks and propose an encoding attack. Extensive experiments against two major honey vault systems demonstrate that our four attacks can improve the attack success rate by 1.15-4.35 times compared with their counterparts. For the intersection attack, we propose a feature attack against Cheng et al.’s incremental update mechanism (at USENIX SEC’21), and our attack can breach their mechanism with 87%-93% advantage.
Fei Duan, Ding Wang 0002, Chunfu Jia
SP1
2024 Impacts of Increasing Temperature and Relative Humidity in Air-Cooled Tropical Data Centers
abstract
Data centers (DCs) are power-intensive facilities which use a significant amount of energy for cooling the servers. Increasing the temperature and relative humidity (RH) setpoints is a rule-of-thumb approach to reducing the DC energy usage. However, the high temperature and RH may undermine the server's reliability. Before we can choose the proper temperature and RH settings, it is essential to understand how the temperature and RH setpoints affect the DC power usage and server's reliability. To this end, we constructed and experimented with an air-cooled DC testbed in Singapore, which consists of a direct expansion cooling system and 521 servers running real-world application workloads. This paper presents the key measurement results and observations from our 11-month experiments. Our results suggest that by operating at a supply air temperature setpoints of 29${}^{\circ }$C, our testbed achieves substantial cooling power saving with little impact on the server's reliability. Furthermore, we present a total cost of ownership (TCO) analysis framework which guides settings of the temperature and RH for a DC. Our observations and TCO analysis framework will be useful to future efforts in building and operating air-cooled DCs in tropics and beyond.
Duc Van Le, Rui Tan 0001, Fei Duan
IEEE Trans. Sustain. Comput.5
2021 RLS-PSM: A Robust and Accurate Password Strength Meter Based on Reuse, Leet and Separation
abstract
Password strength meters (PSMs) are being widely used, but they often give conflicting, inaccurate and misleading feedback, which defeats their purpose. Except for fuzzyPSM, all PSMs assume passwords are newly constructed, which is not true in reality. FuzzyPSM considers password reuse, six major leet transformations and initial capitalization, and performs the best as evaluated by Golla and Dürmuth at ACM CCS’18. On the basis of fuzzyPSM, we propose a new PSM based onReuse,Leet andSeparation, namely RLS-PSM. First, we classify password reuse behaviors into capitalization and those that use special characters for leet or separation, and calculate the corresponding probabilities. Then, to balance efficiency and precision, we use Long Short-Term Memory to calculate the probabilities of alphanumeric strings. Besides, we propose to usebenchmark passwordsto show therelative strengthof a password. Due to the varied impacts of different service types and diversified economic value of websites, we consider parameter settings of RLS-PSM under six different service types. Finally, we use the Monte Carlo method and weighted Spearman coefficient to measure and compare the robustness and accuracy of RLS-PSM, leading PSMs (including Markov-based PSM, PCFG-based PSM, fuzzyPSM, RNN, and Zxcvbn), and password cracking tools (including JtR and Hashcat). We find that the robustness of RLS-PSM is significantly higher than all counterparts whenevaluating attempts> 104(e.g., on average, Fraction of Successfully Evaluated passwords of RLS-PSM is 18.9% higher than fuzzyPSM). The accuracy of RLS-PSM is also better than other mainstream PSMs used for comparison in this paper, except for fuzzyPSM.
Qiying Dong, Chunfu Jia, Fei Duan, Ding Wang 0002
IEEE Trans. Inf. Forensics Secur.3
2010 A Highly Effective Impulse Noise Detection Algorithm for Switching Median Filters
abstract
Under the framework of switching median filtering, a highly effective algorithm for impulse noise detection is proposed aiming at providing solid basis for subsequent filtering. This algorithm consists of two iterations to make the decision as accurate as possible. Two robust and reliable decision criteria are proposed for each iteration. Extensive simulation results show that the false alarm rate and miss detection rate of the proposed algorithm are both very low and substantially outperform existing state-of-the-art algorithms. At the same time, the proposed algorithm is in principle simpler as it is intuitive and it is easy to implement as it has uncomplicated structure and few codes.
Fei Duan, Yu-Jin Zhang
IEEE Signal Process. Lett.1