Lu-Xing Yang

dblp:59/10736 · also Luxing Yang · DBLP profile ↗
← Back
30ranked-venue papers
3as first author
21since 2021 · last 2026
0000-0002-9229-5787ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 2 first-author · 8 since 2021Databases, data management, data science and information retrieval · 6 · 3 since 2021Human-computer interaction and ubiquitous computing · 4 · 1 first-author · 4 since 2021Computer networks · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Theory of computation · 2Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Mitigating malware prevalence in networks with arbitrary topologies: a Flip-It cyber game approach integrated with epidemic modeling
abstract
Cyber threats have evolved in complexity, aiming at a wide range of sectors using advanced methods and tools. This evolving threat landscape challenges existing cybersecurity frameworks, many of which lack the adaptability to counteract the complex tactics of sophisticated adversaries. Developing robust cyber defense strategies requires simulating dynamic interactions between attackers and defenders across high, moderate, and low-impact scenarios. The Flip-It cyber game serves as an intelligent framework for simulating these interactions, enabling the analysis of adaptive strategies in cybersecurity. This paper aims to address the problem of mitigating malware prevalence in full consideration of attack/defense capabilities in arbitrary network topologies. This paper proposes a sophisticated discrete-time epidemic model to characterize security state transitions over time for all three scenarios within the Flip-It game framework. On this basis, the original problem is modeled as a closed-loop control problem to seek the optimal containment strategy. Deep Reinforcement Learning (DRL) is then used to tackle the problem, generating efficient defense strategies that are well-adapted to changing cybersecurity environments. Numerical simulations based on small-world networks, scale-free networks, and router networks are then carried out to generate corresponding strategies. Additionally, we have evaluated the performance of the proposed method against the State-Of-The-Art (SOTA) in terms of attack/defense objective function, control actions, number of devices under the control of the attacker and defender, stability, execution time, and scalability. This comprehensive approach integrates epidemiological modeling, game theory, and advanced machine learning to effectively tackle the complexities of contemporary cybersecurity threats. • Mitigates malware across low, medium, and high-impact cyberattacks. • Integrates the Flip-It game for attacker-defender dynamic interactions. • Employs DRL to enable adaptive and optimized defense strategies. • Evaluates defense evolution across diverse network topologies.
Mousa Tayseer Jafar, Lu-Xing Yang, Gang Li 0009, Robin Doss, Kon Mouzakis, Rajesh Vasa, Helge Janicke, Ahmed Ibrahim 0002, Ahmed Mohsin, Iqbal H. Sarker, Kristen Moore, Seyit Ahmet Çamtepe, Diksha Goel
Inf. Sci.2
2026 Attack Graph-Epidemic Hybrid Modeling for Mitigating Cyber Threats Propagation
abstract
Despite notable advancements in applying epidemic models to cybersecurity, current approaches often underperform in practice. Research indicates that these models can produce substantial prediction errors due to challenges in parameter estimation, the complexity and heterogeneity of real-world networks, and limitations in accurately evaluating model performance against empirical data. Prior models frequently rely on generalized or static parameters, which can further exacerbate prediction inaccuracies, particularly when estimating infection spread in complex and heterogeneous network environments. Such inaccuracies limit their ability to support timely and effective threat response. To address this gap, this article presents a novel hybrid framework that integrates attack graphs with epidemic modeling. Attack graphs provide a structured representation of potential attack paths and interdependencies within a network, enabling the incorporation of real, context-aware values into the epidemic model. This integration enhances parameter accuracy and improves predictive capability. Experimental evaluations demonstrate that the proposed framework (PFW) achieves a 91.25% improvement in performance. More specifically, the results indicate that the average number of infected devices using the proposed method with an attack graph for multivulnerabilities is 5, while for single-vulnerability cases it is 18. In comparison, traditional epidemic models without attack graph integration result in an average of 70 infected devices. These findings highlight the effectiveness of our approach in minimizing infection spread under diverse vulnerability conditions. Overall, the results demonstrate the value of grounding epidemic models in realistic network conditions, thereby advancing adaptive threat modeling, proactive defense strategies, and informed decision-making. Our work bridges the gap between theoretical modeling and real-world application, offering a significant step toward practical epidemic-based approaches in cybersecurity.
Mousa Tayseer Jafar, Lu-Xing Yang, Gang Li 0009
IEEE Trans. Comput. Soc. Syst.3
2026 Mitigating Insider-Facilitated Advanced Persistent Threat: A Three-Player Differential Game Approach
abstract
Advanced Persistent Threat (APT) presents a significant challenge to the cybersecurity of contemporary organizations. This challenge is further exacerbated when APT actors collaborate with malicious insiders. The involvement of the insider transforms a bilateral adversarial scenario into a triadic strategic interaction, introducing additional layers of complexity in modeling and defense planning. Effective defense against insider-facilitated APT necessitates a comprehensive treatment of two critical aspects: (i) the dynamic strategic interactions among the three players—the defender, the insider, and the APT actor—and (ii) the impact of these interactions on the evolving state of the intranet. However, both dimensions are insufficiently addressed in existing research. To bridge this gap, we first develop an expected state evolution model that captures the real-time influence of the dynamic strategies of the players on the expected compromise state of the intranet. Building upon this, we formulate a three-player differential game model that explicitly incorporates the dynamic interactions of all participants. The associated optimality system is derived and numerically solved using a proposed iterative algorithm. The proposed algorithm achieves a 27.5% improvement in the organization’s expected payoff compared to baseline permissible strategies. Subsequently, we analyze key properties of the proposed framework and empirically evaluate the cost-effectiveness of the resulting defense strategy. To the best of our knowledge, this work represents the first application of three-player differential game theory in the domain of cybersecurity, offering a novel approach to defending against insider-facilitated APT.
Lu-Xing Yang, Xiaofan Yang 0001, Gang Li 0009, Robin Doss
IEEE Trans. Inf. Forensics Secur.2
2025 Large Language Model and Variational Autoencoder Based Deep Neural Framework for Cyber Attack Detection
Jyotheesh Gaddam, Ishara Bandara, Ming Liu 0028, Sutharshan Rajasegarar, Muneeb Ul Hassan 0001, Lu-Xing Yang, Gang Li 0009, Maia Angelova
PAKDD (4)8
2025 An innovative practical roadmap for optimal control strategies in malware propagation through the integration of RL with MPC
Mousa Tayseer Jafar, Lu-Xing Yang, Gang Li 0009
Comput. Secur.2
2025 Impulse Strategies for Suppressing Cyber Propaganda With Awareness
abstract
Cyber propaganda has become an increasingly sophisticated tool for manipulating public perception and discourse within online social networks (OSNs). The effectiveness of cyber propaganda is strongly influenced by the interplay between individual awareness and the underlying topology of OSNs that facilitates the spread of propaganda. However, existing interventions primarily focus on continuous control strategies, which may not be feasible in certain real-world scenarios. Therefore, effectively suppressing the spread of cyber propaganda while taking into account the above impact factors remains a challenging problem. In this study, we propose a methodology that combines the optimal impulse control (OIC) theory with a novel propagation model to address this problem. Our propagation model is the first to take into account the effects of the cognitive differences and interconnectivity of OSNs on the dynamics of cyber propaganda. By employing the OIC framework and our newly developed propagation model, we formulate an OIC problem. The goal is to find impulse strategies that optimally balance the cost of intervention against its effectiveness. Using the impulse maximum principle, we establish the necessary conditions for optimal impulse strategies and construct an algorithm to solve the OIC problem. Our numerical experiments, conducted on three distinct social networks, demonstrated that: 1) awareness levels play a crucial role in effectively suppressing the spread of cyber propaganda on OSNs; and 2) our impulse strategies are significantly superior to random strategies in terms of suppression effect, thereby evidencing their cost-effectiveness.
Xiaojuan Cheng, Lu-Xing Yang, Qingyi Zhu, Chenquan Gan, Gang Li 0009
IEEE Trans. Comput. Soc. Syst.2
2025 Modeling and Mitigating Social Engineering Malware: Integrating Malware-Opinion Dynamics With Optimal Impulse Control Approaches
abstract
Social engineering malware, which exploits both technical and human vulnerabilities, presents challenging for individuals and organizations. However, existing studies typically focus on either technical or human vulnerabilities through case studies or questionnaires, ignoring their combined importance in mitigating such threats. This study pioneers the introduction of a mathematical model to analyze and mitigate the dynamics associated with these combined vulnerabilities. To achieve this, this study proposes an innovative framework, which integrates (a) acoupled malware-opinion dynamics modelto capture the interplay between both types of vulnerabilities, and (b) anoptimal impulse control approachto strategically mitigatingsocial engineering malware. Within this framework, we define an optimization problem, aimed at balancing control costs and malware severity. We derive theoretical conditions for optimal impulse strategies that achieve this balance and develop an iterative algorithm, the convergence and scalability of which have been empirically validated. Experimental results on three real-world social networks and synthetic scale-free networks demonstrate that our strategies consistently achieve an optimal balance by minimizing total expenses, including control costs and losses associated with malware. This finding underscores the effectiveness of routine patching and ongoing security awareness training in standard cybersecurity practices. Further experiments indicate that the strategic, early, and frequent deployment of patches in specific scenarios can effectively reduce unnecessary losses, enhancing overall cybersecurity resilience.
Xiaojuan Cheng, Lu-Xing Yang, Gang Li 0009, Zenan Ma, Tianqing Zhu, Lidan Wang 0001, Shukai Duan 0001
IEEE Trans. Inf. Forensics Secur.2
2024 POSTER: Addressing the Privacy by Use Challenges in Verifiable Credential based Digital Wallets
abstract
The concept of Verifiable Credentials (VC) has emerged as a viable alternative to federated identity systems and can offer greater levels of control and ownership to users over their Digital Identity. However, the inability of users to make optimal decisions in relation to the use of VC results in privacy risks. To address this gap in VC technology, we present game-theoretic models for optimising the privacy of users and simultaneously ensuring minimum disclosure of PII in line with privacy safeguards around CDR and GDPR expectations around anonymity and unlinkability and demonstrate these properties through a digital credential wallet (DCW). The developed technology will deliver a novel DCW which embeds decision-making ability to quantify, benchmark and recommend the optimal usage of credentials that are held within the DCW.
Jongkil Jeong, Lu-Xing Yang, Robin Doss, Praveen Gauravaram, Zoe Wang, Mohamed Almorsy, Ashish Nanda, Keerthivasan Viswanathan
AsiaCCS2
2024 Detecting Change Intervalswith Isolation Distributional Kernel (Abstract Reprint)
Yang Cao 0019, Ye Zhu 0002, Kai Ming Ting, Flora D. Salim, Hong Xian Li, Lu-Xing Yang, Gang Li 0009
IJCAI6
2024 Malware containment with immediate response in IoT networks: An optimal control approach
Mousa Tayseer Jafar, Lu-Xing Yang, Gang Li 0009, Qingyi Zhu, Chenquan Gan, Xiaofan Yang 0001
Comput. Commun.2
2024 Impact of cybersecurity awareness on mobile malware propagation: A dynamical model
Qingyi Zhu, Xuhang Luo, Chenquan Gan, Yu Wu 0001, Lu-Xing Yang
Comput. Commun.6
2024 Modeling and study of defense outsourcing against advanced persistent threat through impulsive differential game approach
Xiaofan Yang 0001, Lu-Xing Yang, Kaifan Huang
Comput. Secur.3
2024 Game-theoretic modeling and analysis of cyberbullying spreading on OSNs
Qi Chu 0007, Lu-Xing Yang, Xiaofan Yang 0001
Inf. Sci.3
2024 Detecting Change Intervals with Isolation Distributional Kernel
abstract
Detecting abrupt changes in data distribution is one of the most significant tasks in streaming data analysis. Although many unsupervised Change-Point Detection (CPD) methods have been proposed recently to identify those changes, they still suffer from missing subtle changes, poor scalability, or/and sensitivity to outliers. To meet these challenges, we are the first to generalise the CPD problem as a special case of the Change-Interval Detection (CID) problem. Then we propose a CID method, named iCID, based on a recent Isolation Distributional Kernel (IDK). iCID identifies the change interval if there is a high dissimilarity score between two non-homogeneous temporal adjacent intervals. The data-dependent property and finite feature map of IDK enabled iCID to efficiently identify various types of change-points in data streams with the tolerance of outliers. Moreover, the proposed online and offline versions of iCID have the ability to optimise key parameter settings. The effectiveness and efficiency of iCID have been systematically verified on both synthetic and real-world datasets.
Yang Cao 0019, Ye Zhu 0002, Kai Ming Ting, Flora D. Salim, Hong Xian Li, Lu-Xing Yang, Gang Li 0009
J. Artif. Intell. Res.6
2024 Cost-Effective Hybrid Control Strategies for Dynamical Propaganda War Game
abstract
Cyber propaganda wars significantly impact users on Online Social Networks (OSNs), potentially altering their psychological/ideological attitudes and behaviors. Understanding these behavioral dynamics necessitates models that can effectively capture the propagation of dual competitive information, encompassing both propaganda and counter-propaganda campaigns by both conflicting parties. However, current models do not adequately account for competitive information spreading in dual setting and it lacks efficient strategies for managing both propaganda and counter-propaganda investments. To bridge these gaps, our study presents an innovative netwORked dIfferENTial gAme wiTh hybrId cONtrol (ORIENTATION) framework that integrates differential game with 1) a degree-based network model characterizing the spreading dynamics of dual competitive information for both parties; and 2) a dual hybrid control mechanism consisting of investment rates by continuous-time propaganda and discrete-time counter-propaganda. Using this framework, we formulate the Hybrid-contrOlled Differential GamE (HODGE) problem. We theoretically derive the necessary conditions for Nash equilibrium, and develop an iterative algorithm, termed theHODGEalgorithm, to numerically approximate the Nash equilibrium. Our experiments, performed on different groups of OSNs, reveal that the resulting strategy profiles consistently outperform several alternative profiles in terms of cost-effectiveness. Scalability assessment for theHODGEalgorithm is then carried out on OSNs with different scales, demonstrating its strong performance in terms of computational efficiency, scalability and practicability. Additional experimental results suggest that a decrease in the lower bounds of the investment rates in both propaganda and counter-propaganda campaigns and an early implementation of counter-propaganda strategies can significantly enhance cost-effectiveness, offering strategic insights for those engaged in cyber propaganda war.
Xiaojuan Cheng, Lu-Xing Yang, Qingyi Zhu, Chenquan Gan, Xiaofan Yang 0001, Gang Li 0009
IEEE Trans. Inf. Forensics Secur.2
2024 Minimizing Malware Propagation in Internet of Things Networks: An Optimal Control Using Feedback Loop Approach
abstract
Despite extensive research on optimal control formulations for cyber threat mitigation, a significant gap persists between theoretical and practical implementation in real-time scenarios. The open-loop structure of the optimal control framework is insufficiently robust for effectively addressing cyber threats. To overcome this, adopting a model learning process that iteratively updates the optimal control strategy is proposed. This paper proposes an innovative approach to addressing cybersecurity attacks in the Internet of Things (IoT) networks by integrating reinforcement learning (RL) and model predictive control (MPC) in a hybrid framework to optimize control parameters and enhance system effectiveness in combating malware. This novel approach aims to overcome the limitations of the previous approaches and establish superior control strategies for IoT network security. This approach enhances the adaptability and responsiveness of the mitigation process, improving the handling of evolving cyber threats in real-world applications. This framework enhances the security and resilience of IoT networks against malicious activities, offering a robust solution for mitigating cyber threats by leveraging RL algorithms and the proactive capabilities of MPC. A comprehensive evaluation demonstrates the effectiveness and efficiency of the hybrid framework, highlighting its potential to protect IoT networks from evolving cybersecurity risks. The primary aim extends beyond using an RL agent solely for computing control actions to optimize closed-loop performance and stability. It also leverages RL to estimate model parameters that are currently unknown but within known bounds. Our main objective in using the RL agent is to accurately estimate unidentified model parameters within specified limits. The simulation results provide compelling evidence supporting the effectiveness of this methodology in mitigating malware propagation, highlighting its superior performance compared to state-of-the-art methods. RLMPC rapidly initiated recovery, achieving full network restoration in 8 seconds and recovering 60 IoT devices. Also, the evaluation focused on average speed, scalability, and performance under various cyber-attack scenarios.
Mousa Tayseer Jafar, Lu-Xing Yang, Gang Li 0009, Qingyi Zhu, Chenquan Gan
IEEE Trans. Inf. Forensics Secur.2
2024 Cost-Effective Company Response Policy for Product Co-Creation in Company-Sponsored Online Community
abstract
Product co-creation based on company-sponsored online community has come to be a paradigm of developing new products collaboratively with customers. In such a product co-creation campaign, the sponsoring company needs to interact intensively with active community members about the design scheme of the product. We call the collection of the rates of the company’s response to active community members at all time in the co-creation campaign as a company response policy (CRP). This article addresses the problem of finding a cost-effective CRP (the CRP problem). First, we introduce a novel community state evolutionary model and, thereby, establish an optimal control model for the CRP problem (the CRP model). Second, based on the optimality system for the CRP model, we present an iterative algorithm for solving the CRP model (the CRP algorithm). Third, through extensive numerical experiments, we conclude that the CRP algorithm converges and the resulting CRP exhibits excellent cost benefit. Consequently, we recommend the resulting CRP to companies that embrace product co-creation. Next, we discuss how to implement the resulting CRP. Finally, we investigate the effect of some factors on the cost benefit of the resulting CRP. To our knowledge, this work is the first attempt to study value co-creation through optimal control theoretic approach.
Lu-Xing Yang, Xiaofan Yang 0001, Kaifan Huang, Gang Li 0009, Yong Xiang 0001
IEEE Trans. Syst. Man Cybern. Syst.2
2023 Impulsive Artificial Defense Against Advanced Persistent Threat
abstract
Advanced persistent threat (APT) as a new type of cyber espionage poses a severe threat to modern organizations. Artificial APT defense, in which an organization engages experienced cybersecurity experts to artificially check if there exist rootkits implanted by APT actors within the organizational internet and, if so, artificially remove the discovered rootkits, is recognized as an indispensable part of APT defense. There are two different ways of artificial APT defenses: continuous artificial defense (CAD), where the defense work is conducted at all time points, and impulsive artificial defense (IAD), where the defense work is conducted at a scheduled sequence of time points. IAD is superior to CAD in terms of the overall service cost. In the context of IAD, we refer to each sequence of service costs as an IAD policy. This paper addresses the problem of developing a cost-effective IAD policy (the IAD problem). First, by introducing an impulsive state evolutionary model for the organizational intranet, the IAD problem is reduced to an optimal impulsive control model (the IAD model). Second, by deriving the optimality system for the IAD model, an iterative algorithm for solving the IAD model (the IAD algorithm) is presented. Next, the convergence and effectiveness of the IAD algorithm are validated through numerical experiments. Finally, the effect of some factors is inspected. To our knowledge, this is the first time IAD is inspected from the perspective of optimal impulsive control theory.
Xiaofan Yang 0001, Lu-Xing Yang, Kaifan Huang, Gang Li 0009
IEEE Trans. Inf. Forensics Secur.3
2022 MGC-GAN: Multi-Graph Convolutional Generative Adversarial Networks for Accurate Citywide Traffic Flow Prediction
abstract
Accurate citywide traffic flow prediction is of great importance to intelligent transportation system. Existing methods typically assume the complete citywide traffic data can be obtained in real-time, which is impossible in applications. Furthermore, many recent works only consider one single kind of spatial correlation in traffic network when building graph representations. This work proposes an adversarial learning framework named Multi-Graph Convolutional Generative Adversarial Networks (MGC-GAN) to address the aforementioned challenges. To generate citywide traffic flow predictions using limited traffic data, we construct three kinds of graphs using easily accessed geographical and semantic information to model the complex spatial correlations in citywide transportation networks. Following that, a parallel GCN layer is designed to separately process multiple graphs. In addition, we design the Parallel Graph Convolution and Temporal Convolution Module (PGTCM) to effectively capture the heterogeneous spatial-temporal dependencies. Extensive experiments are carried out on two citywide traffic datasets, demonstrating that MGC-GAN outperforms several state-of-the-art baseline methods.
Lincan Li, Jichao Bi, Kaixiang Yang 0001, Fengji Luo, Lu-Xing Yang
SMC5
2022 Effective Multiplatform Advertising Policy
abstract
Multiplatform advertising (MPA) is recognized as an effective means of enhancing marketing revenue. In the context, we refer to the scheme of dynamically allocating the advertising expenditure among the selected media platforms as an MPA policy, and we refer to the problem of developing an MPA policy with maximum benefit as the MPA problem. This article is devoted to the solution of the MPA problem. An evolutionary model for the expected market state, in which the influence of both advertising and word-of-mouth (WOM) propagation is accounted for, is established. On this basis, the expected benefit of an MPA policy is calculated. Thereby, the MPA problem is reduced to an optimal control problem we refer to as the MPA model, where the objective functional stands for the expected benefit of an MPA strategy. The optimality system for the MPA model is derived. We refer to the MPA policy obtained by solving the optimality system as the promising MPA policy. The structure of the promising MPA policy is inspected. Through extensive comparative experiments, it is concluded that the promising MPA policy is superior to the majority of MPA policies in terms of expected benefit. Finally, how the expected benefit of the promising MPA policy is influenced by some factors is investigated.
Kaifan Huang, Lu-Xing Yang, Xiaofan Yang 0001, Yuan Yan Tang
IEEE Trans. Syst. Man Cybern. Syst.2
2021 Effective Quarantine and Recovery Scheme Against Advanced Persistent Threat
abstract
Advanced persistent threat (APT) for cyber espionage poses a great threat to modern organizations. In order to mitigate the impact of APT on an organization, all the compromised systems in the organization must be quarantined and recovered in a timely and effective way. This article focuses on the problem of customizing a dynamic quarantine and recovery (QAR) scheme for an organization so that the APT impact is minimized. Based on a novel node-level epidemic model characterizing the effect of the QAR scheme on the expected state of the underlying network, we estimate the expected impact of APT under a QAR scheme. On this basis, we model the original problem as an optimal control problem. By use of optimal control theory, we derive the optimality system for the optimal control problem and thereby introduce the concept of normal potential optimal (NPO) control. Next, through comparative experiments, we find that the NPO control outperforms a set of heuristic controls. Hence, the QAR scheme associated with the NPO control is satisfactory in terms of the effectiveness of defending against APT. Finally, we examine the effect of some factors on the expected APT impact under the NPO control. This article would be helpful to the defense against APT for cyber espionage.
Lu-Xing Yang, Pengdeng Li, Xiaofan Yang 0001, Yong Xiang 0001, Frank Jiang 0001, Wanlei Zhou 0001
IEEE Trans. Syst. Man Cybern. Syst.1
2020 A Risk Management Approach to Defending Against the Advanced Persistent Threat
abstract
The advanced persistent threat (APT) as a new kind of cyber attack has posed a severe threat to modern organizations. When the APT has been detected, the organization has to deal with the APT response problem, i.e., to allocate the available response resources to fix her insecure hosts so as to mitigate her potential loss. This paper addresses the APT response problem by using the risk management approach. First, we introduce a model characterizing the evolution of the organization's expected state. By analyzing this model, we find the organization's expected state approaches a common limit expected state. Then, we use the organization's expected loss per unit time to measure her potential loss, and we find this measure is determined by the organization's limit expected state. On this basis, we model the APT response problem as a game-theoretic problem (the APT response game) in which the organization seeks a Nash equilibrium. We present a greedy algorithm for solving the game. Comparative experiments show that the algorithm is effective. Therefore, we recommend the response strategy generated by performing the algorithm. These findings contribute to defending against the APT. To our knowledge, this is the first time the APT response problem is addressed.
Lu-Xing Yang, Pengdeng Li, Xiaofan Yang 0001, Yuan Yan Tang
IEEE Trans. Dependable Secur. Comput.1
2020 Secure and Efficient Outsourcing of PCA-Based Face Recognition
abstract
Face recognition has become increasingly popular in recent years. However, in some special cases, many face recognition calculations cannot be performed effectively due to the lack of sufficient computing power of the terminal, which poses a challenge to the practical application of face recognition technology. Cloud computing provides a good platform for solving this problem due to its abundant computing resources. However, cloud computing poses new challenges, such as how to protect clients' data privacy without reducing efficiency. In this paper, we review some of the results of previous research and analyze an outsourcing protocol for eigen decomposition and singular value decomposition. On this basis, we propose a secure and efficient outsourcing protocol for face recognition through principal component analysis. In the proposed protocol, information privacy is well protected, and computational resources are saved by means of conversions of the original image information. In addition, local verification is supported to cope with the laziness of the cloud. We show the feasibility and advancement of our protocol from both theoretical and experimental perspectives.
Yushu Zhang 0001, Xiangli Xiao, Lu-Xing Yang, Yong Xiang 0001, Sheng Zhong 0002
IEEE Trans. Inf. Forensics Secur.3
2019 Enhanced Smart Meter Privacy Protection Using Rechargeable Batteries
abstract
Due to the rapid growth of smart grids, use of smart meters (SMs) have increased in the recent days. The main problem with the use of SMs is that by observing the SMs reading, it is possible to infer the daily activities of the consumers. Therefore, protection of privacy is a major concern related to SMs. Using rechargeable batteries (RBs) is a popular method in protecting the privacy in SMs as these methods do not tamper with SM readings. The major problem in RB-based mechanism is that the energy management unit (EMU) cannot protect privacy, if the demand is lower or higher for a longer period. To overcome this problem, in this paper a heuristic method has been proposed by considering time varying target output load based on the three major properties of artificial fish swarm optimization algorithm. For the optimal choice of the time varying target output load, RB constraints as well as reduction of the average cost of energy have been considered in our proposed method. We have proposed two privacy preserving mechanisms for both offline and online scenarios. The proposed method preserves privacy while reducing the cost of energy. Simulation results show that the proposed method is able to provide privacy by overcoming the problem identified in the existing methods.
Mohammad Belayet Hossain, Iynkaran Natgunanathan, Yong Xiang 0001, Lu-Xing Yang, Guangyan Huang
IEEE Internet Things J.4
2019 Efficiently and securely outsourcing compressed sensing reconstruction to a cloud
Yushu Zhang 0001, Yong Xiang 0001, Leo Yu Zhang, Lu-Xing Yang, Jiantao Zhou 0001
Inf. Sci.4
2019 Seeking Best-Balanced Patch-Injecting Strategies through Optimal Control Approach
abstract
To restrain escalating computer viruses, new virus patches must be constantly injected into networks. In this scenario, the patch-developing cost should be balanced against the negative impact of virus. This article focuses on seeking best-balanced patch-injecting strategies. First, based on a novel virus-patch interactive model, the original problem is reduced to an optimal control problem, in which (a) each admissible control stands for a feasible patch-injecting strategy and (b) the objective functional measures the balance of a feasible patch-injecting strategy. Second, the solvability of the optimal control problem is proved, and the optimality system for solving the problem is derived. Next, a few best-balanced patch-injecting strategies are presented by solving the corresponding optimality systems. Finally, the effects of some factors on the best balance of a patch-injecting strategy are examined. Our results will be helpful in defending against virus attacks in a cost-effective way.
Kaifan Huang, Pengdeng Li, Lu-Xing Yang, Xiaofan Yang 0001, Yuan Yan Tang
Secur. Commun. Networks3
2019 Mathematical Models for Malware Propagation
abstract
Mathematical models for malware propagation
Ángel Martín del Rey, Lu-Xing Yang, Vasileios Karyotis
Secur. Commun. Networks2
2019 Effective Repair Strategy Against Advanced Persistent Threat: A Differential Game Approach
abstract
Advanced persistent threat (APT) is a new kind of cyberattack that poses a serious threat to modern society. When an APT campaign on an organization has been identified, the available repair resources must be reasonably allocated to the potentially insecure hosts to mitigate the potential loss of the organization. We refer to the feasible repair resource allocation strategies as repair strategies. This paper focuses on the APT repair problem, i.e., the problem of developing effective repair strategies for organizations. First, for an organization with time-varying communication relationship, we establish an evolution model of the organization's expected state, in which the impact of lateral movement of APT is accommodated. On this basis, we model the APT repair problem as a differential Nash game problem (the APT repair game) in which the attacker attempts to maximize his potential benefit, and the organization manages to minimize its potential loss. Second, we derive a system (the potential system) for calculating a potential Nash equilibrium of an APT repair game, and we examine the structure of the potential attack and repair strategies in a potential Nash equilibrium. Next, we solve some potential systems to get the corresponding potential Nash equilibria. Finally, by comparison with a large number of randomly generated attack and repair strategies, we conclude that the potential Nash equilibrium of each APT repair game is a Nash equilibrium of the game. Therefore, we recommend to organizations their respective potential repair strategies. Our findings help to better understand and effectively defend against APT.
Lu-Xing Yang, Pengdeng Li, Yushu Zhang 0001, Xiaofan Yang 0001, Yong Xiang 0001, Wanlei Zhou 0001
IEEE Trans. Inf. Forensics Secur.1
2012 Optimal broadcasting for locally twisted cubes
Xiaofan Yang 0001, Lu-Xing Yang
Inf. Process. Lett.3
2012 Routing and wavelength assignment for 3-ary n-cube in array-based optical network
Cui Yu, Xiaofan Yang 0001, Lu-Xing Yang
Inf. Process. Lett.3