Rui Zhang 0007

dblp:60/2536-7 · DBLP profile ↗
← Back
70ranked-venue papers
17as first author
17since 2021 · last 2025
0000-0001-5230-5998ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 56 · 13 first-author · 13 since 2021Security and privacy · 8 · 1 first-author · 2 since 2021Systems, architecture and hardware · 3 · 3 first-authorDatabases, data management, data science and information retrieval · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Byzantine-Robust Federated Learning
abstract
Federated Learning (FL) is a transformative paradigm for training global machine learning models using decentralized datasets hosted by edge or client devices, without requiring centralized data aggregation. This makes FL particularly valuable for privacy-sensitive applications deployed in edge-cloud environments. However, FL is vulnerable to Byzantine attacks, where malicious clients provide falsified local model updates to compromise the performance of the global model. Such vulnerabilities are especially problematic in heterogeneous and resource-constrained edge-cloud systems, where ensuring trust across distributed clients is a significant challenge. This paper introduces a novel Byzantine-Robust FL method designed to address these challenges in edge-cloud computing scenarios. Our method leverages a central server equipped with a small clean dataset as an initial root of trust to evaluate the trustworthiness of client updates. Unlike prior approaches, our method iteratively builds a dynamic set of trusted clients, gradually incorporating their updates into the training process to refine the global model. This dynamic trust mechanism reduces reliance on the quality of the initial clean dataset, ensuring robustness even in the presence of a significant number of malicious clients. Extensive experiments on real-world datasets demonstrate the effectiveness of our approach in achieving high model accuracy and maintaining robustness against Byzantine attacks. Our method is particularly well-suited for edge-cloud environments, addressing critical challenges such as resource constraints, distributed learning management, and the reliability of collaborative AI systems.
Zheyuan Liu 0007, Aishah Aseeri, Depeng Li 0002, Rui Zhang 0007
ICCCN6
2024 Privacy-Preserving Ridesharing via Probabilistic Matching
abstract
The widespread use of smartphones has made ridesharing a popular transportation option, connecting passengers with drivers seamlessly. However, existing ridesharing models raise privacy concerns as users must disclose their travel plans without assurance of a match. Previous privacy solutions are either impractical or insecure. To address this, we propose a novel privacy-preserving ridesharing mechanism based on probabilistic matching. Our approach ensures robust privacy protection for both drivers and riders while maintaining efficiency.
Tianye Ma, Yukun Dong, Rui Zhang 0007
IWQoS4
2023 Location Inference under Temporal Correlation
abstract
Location Based Services (LBSs) have become increasingly popular in the past decade, allowing mobile users to access location-dependent information and services. To protect user privacy while using LBSs, various Location Privacy Protection Mechanisms (LPPMs) have been proposed that obfuscate users' true locations through random perturbation. However, adversaries can still exploit the temporal correlation between a user's locations in multiple LBS queries to improve inference accuracy. In this paper, we introduce a novel location inference attack that strikes a good balance between inference accuracy and computational complexity by effectively exploiting temporal correlation. Simulation studies using synthetic and real datasets confirm the advantages of our proposed attack.
Yukun Dong, Aishah Aseeri, Depeng Li 0002, Rui Zhang 0007
ICCCN5
2023 Freshness Authentication for Outsourced Multi-Version Key-Value Stores
abstract
Data outsourcing is a promising technical paradigm to facilitate cost-effective real-time data storage, processing, and dissemination. In data outsourcing, a data owner proactively pushes a stream of data records to a third-party cloud server for storage, which in turn processes various types of queries from end users on the data owner’s behalf. However, the popular outsourced multi-version key-value stores pose a critical security challenge that a third-party cloud server cannot be fully trusted to return both authentic and fresh data in response to end users’ queries. Although several recent attempts have been made on authenticating data freshness in outsourced key-value stores, they either incur excessively high communication cost or can only offer very limited real-time guarantee. To fill this gap, this article introduces KV-Fresh, a novel freshness authentication scheme for outsourced key-value stores that offers strong real-time guarantee for both point query and range query. KV-Fresh is designed based on a novel data structure, Linked Key Span Merkle Hash Tree, which enables highly efficient freshness proof by embedding chaining relationship among records generated at different time. Extensive simulation studies using a synthetic dataset generated from real data confirm the efficacy and efficiency of KV-Fresh.
Xin Yao 0002, Rui Zhang 0007
IEEE Trans. Dependable Secur. Comput.3
2023 VeriDedup: A Verifiable Cloud Data Deduplication Scheme With Integrity and Duplication Proof
abstract
Data deduplication is a technique to eliminate duplicate data in order to save storage space and enlarge upload bandwidth, which has been applied by cloud storage systems. However, a cloud storage provider (CSP) may tamper user data or cheat users to pay unused storage for duplicate data that are only stored once. Although previous solutions adopt message-locked encryption along with Proof of Retrievability (PoR) to check the integrity of deduplicated encrypted data, they ignore proving the correctness of duplication check during data upload and require the same file to be derived into same verification tags, which suffers from brute-force attacks and restricts users from flexibly creating their own individual verification tags. In this paper, we propose a verifiable deduplication scheme called VeriDedup to address the above problems. It can guarantee the correctness of duplication check and support flexible tag generation for integrity check over encrypted data deduplication in an integrative way. Concretely, we propose a novel Tag-flexible Deduplication-supported Integrity Check Protocol (TDICP) based on Private Information Retrieval (PIR) by introducing a novel verification tag called${note\ set}$, which allows multiple users holding the same file to generate their individual verification tags and still supports tag deduplication at the CSP. Furthermore, we make the first attempt to guarantee the correctness of data duplication check by introducing a novel User Determined Duplication Check Protocol (UDDCP) based on Private Set Intersection (PSI), which can resist a CSP from providing a fake duplication check result to users. Security analysis shows the correctness and soundness of our scheme. Simulation studies based on real data show the efficacy and efficiency of our proposed scheme and its significant advantages over prior arts.
Xixun Yu, Zheng Yan 0002, Rui Zhang 0007
IEEE Trans. Dependable Secur. Comput.4
2023 Rhythmic RFID Authentication
abstract
Passive RFID technology is widely used in user authentication and access control. We propose RF-Rhythm, a secure and usable two-factor RFID authentication system with strong resilience to lost/stolen/cloned RFID cards. In RF-Rhythm, each legitimate user performs a sequence of taps on his/her RFID card according to a self-chosen secret melody. Such rhythmic taps can induce phase changes in the backscattered signals, which the RFID reader can detect to recover the user’s tapping rhythm. In addition to verifying the RFID card’s identification information as usual, the backend server compares the extracted tapping rhythm with what it acquires in the user enrollment phase. The user passes authentication checks if and only if both verifications succeed. We also propose a novel phase-hopping protocol in which the RFID reader emits Continuous Wave (CW) with random phases for extracting the user’s secret tapping rhythm. Our protocol can prevent a capable adversary from extracting and then replaying a legitimate tapping rhythm from sniffed RFID signals. Comprehensive user experiments confirm the high security and usability of RF-Rhythm with false-positive and false-negative rates close to zero.
Jiawei Li 0010, Ang Li 0013, Dianqi Han, Yan Zhang 0091, Jinhang Zuo, Rui Zhang 0007, Lei Xie 0004
IEEE/ACM Trans. Netw.7
2022 Locally Differentially Private Quantile Summary Aggregation in Wireless Sensor Networks
Aishah Aseeri, Rui Zhang 0007
ACIIDS (1)2
2022 ImPos: An Image-Based Indoor Positioning System
abstract
Recent years have witnessed growing interests from both academia and industry in developing effective Indoor Positioning Systems (IPSes). An IPS allows users to learn their locations and navigate in large unfamiliar indoor venues such as shopping malls, hospitals, and airports, where GPS signals are often absent or unreliable. Among different types of IPSes, images-based IPSes estimate a user’s location from one or more pictures the user took of nearby landmarks, which explore the deep penetration of smartphones into people’s everyday life and do not require any costly infrastructure upgrade. While several image-based IPSes have been proposed in the literature, most of them suffer from large processing delay due to computationally intensive 3D reconstructing or low positioning accuracy caused by inaccurate angle estimation. In this paper, we introduce the design and evaluation of ImPos, a novel image-based IPS that achieves high positioning accuracy by improved angle estimation and fully utilizing all recognized landmarks. Detailed experiment studies confirm the significant advantages of ImPos over prior image-based solutions.
Rajeswari Hita Kambhamettu, Rui Zhang 0007
CCNC4
2022 PriHorus: Privacy-Preserving RSS-Based Indoor Positioning
abstract
Indoor positioning service (IPS) allows users to navigate in large and unfamiliar indoor venues with no or unreliable GPS signals. Received Signal Strength (RSS)-based IPS has received much attentions during the past decade because it does not require costly infrastructure update but makes use of WiFi infrastructure readily available and ubiquitous smartphones. While IPS can greatly facilitate human indoor activities, it also raises serious privacy concerns as periodical location queries submitted by users allow the IPS server to continuously track users’ whereabout. In addition, a curious user may infer the fingerprint database stored at the IPS server. This paper introduces PriHorus, a privacy-preserving indoor positioning scheme built upon Horus, a representative RSS-based indoor positioning system. PriHorus can protect both users’ location privacy and IPS server’s data privacy while achieving the same level of location accuracy as in the original Horus system.
Guosong Jiang, Rui Zhang 0007, Mande Xie
ICC4
2022 (In)secure Acoustic Mobile Authentication
abstract
Acoustic fingerprinting aims to identify a mobile device based on its internal microphone(s) and speaker(s) which are unique due to manufacturing imperfection. This paper seeks a thorough understanding of the (in)security of exploring acoustic fingerprints for achieving distributed mobile authentication. Our contributions are threefold. First, we present a new acoustic fingerprint-emulation attack and demonstrate that it is a common vulnerability of acoustic mobile authentication systems. Second, we propose a dynamic challenge-response defense to secure acoustic mobile authentication systems against the acoustic fingerprint-emulation attack. Finally, we thoroughly investigate existing acoustic fingerprinting schemes and identify the best option for accurate, secure, and deployable acoustic mobile authentication systems.
Dianqi Han, Ang Li 0013, Tao Li 0042, Yan Zhang 0091, Jiawei Li 0010, Rui Zhang 0007
IEEE Trans. Mob. Comput.7
2022 SpecKriging: GNN-Based Secure Cooperative Spectrum Sensing
abstract
Cooperative spectrum sensing (CSS) adopted by spectrum-sensing providers (SSPs) plays a key role for dynamic spectrum access and is essential for avoiding interference with licensed primary users (PUs). A typical SSP system consists of geographically distributed spectrum sensors which can be compromised to submit fake spectrum-sensing reports. In this paper, we propose SpecKriging, a new spatial-interpolation technique based on Inductive Graph Neural Network Kriging (IGNNK) for secure CSS. In SpecKriging, we first pretrain a graphical neural network (GNN) model with the historical sensing records of a few trusted anchor sensors. During system runtime, we use the trained model to evaluate the trustworthiness of non-anchor sensors’ data and also use them along with anchor sensors’ new data to retrain the model. SpecKriging outputs trustworthy sensor reports for spectrum-occupancy detection. To the best of our knowledge, SpecKriging is the first work that explores GNNs for trustworthy CSS and also incorporates the hardware heterogeneity of spectrum sensors. Extensive experiments confirm the high efficacy and efficiency of SpecKriging for trustworthy spectrum-occupancy detection even when malicious spectrum sensors constitute the majority.
Yan Zhang 0091, Ang Li 0013, Jiawei Li 0010, Dianqi Han, Tao Li 0042, Rui Zhang 0007
IEEE Trans. Wirel. Commun.6
2021 Your Home is Insecure: Practical Attacks on Wireless Home Alarm Systems
abstract
Wireless home alarm systems are being widely deployed, but their security has not been well studied. Existing attacks on wireless home alarm systems exploit the vulnerabilities of networking protocols while neglecting the problems arising from the physical component of IoT devices. In this paper, we present new event-eliminating and event-spoofing attacks on commercial wireless home alarm systems by interfering with the reed switch in almost all COTS alarm sensors. In both attacks, the external adversary uses his own magnet to control the state of the reed switch in order to either eliminate legitimate alarms or spoof false alarms. We also present a new battery-depletion attack with programmable electromagnets to deplete the alarm sensor's battery quickly and stealthily in hours which is expected to last a few years. The efficacy of our attacks is confirmed by detailed experiments on a representative Ring alarm system.
Tao Li 0042, Dianqi Han, Jiawei Li 0010, Ang Li 0013, Yan Zhang 0091, Rui Zhang 0007
INFOCOM6
2021 Differential Privacy-Preserving User Linkage across Online Social Networks
abstract
Many people maintain accounts at multiple online social networks (OSNs). Multi-OSN user linkage seeks to link the same person’s web profiles and integrate his/her data across different OSNs. It has been widely recognized as the key enabler for many important network applications. User linkage is unfortunately accompanied by growing privacy concerns about real identity leakage and the disclosure of sensitive user attributes. This paper initiates the study on privacy-preserving user linkage across multiple OSNs. We consider a social data collector (SDC) which collects perturbed user data from multiple OSNs and then performs user linkage for commercial data applications. To ensure strong user privacy, we introduce two novel differential privacy notions, ϵ-attribute indistinguishability and ϵ-profile indistinguishability, which ensure that any two users’ similar attributes and profiles cannot be distinguished after perturbation. We then present a novel Multivariate Laplace Mechanism (MLM) to achieve ϵ-attribute indistinguishability and ϵ-profile indistinguishability. We finally propose a novel differential privacy-preserving user linkage framework in which the SDC trains a classifier for user linkage across different OSNs. Extensive experimental studies based on three real datasets confirm the efficacy of our proposed framework.
Xin Yao 0002, Rui Zhang 0007
IWQoS2
2021 Secure Outsourced Top-k Selection Queries against Untrusted Cloud Service Providers
abstract
As cloud computing reshapes the global IT industry, an increasing number of business owners have outsourced their datasets to third-party cloud service providers (CSP), which in turn answer data queries from end users on their behalf. A well known security challenge in data outsourcing is that the CSP cannot be fully trusted, which may return inauthentic or unsound query results for various reasons. This paper considers top-k selection queries, an important type of queries widely used in practice. In a top-k selection query, a user specifies a scoring function and asks for the k objects with the highest scores. Despite several recent efforts, existing solutions can only support a limited range of scoring functions with explicit forms known in advance. This paper presents three novel schemes that allow a user to verify the integrity and soundness of any top-k selection query result returned by an untrusted CSP. The first two schemes support monotone scoring functions, and the third scheme supports scoring functions comprised of both monotonically non-decreasing and non-increasing subscoring functions. Detailed simulation studies using a real dataset confirm the efficacy and efficiency of the proposed schemes and their significant advantages over prior solutions.
Xixun Yu, Rui Zhang 0007, Zheng Yan 0002
IWQoS3
2021 SecQSA: Secure Sampling-Based Quantile Summary Aggregation in Wireless Sensor Networks
abstract
Wireless sensor networks are widely expected to play a key role in the emerging Internet of Things (IoT)-based smart cities in which a large number of resource-constrained sensor nodes collect data about our physical environment to assist intelligent decision making. Since blindly forwarding all the sensed data to the base station may quickly deplete sensor nodes’ limited energy, secure data aggregation has been considered as a key functionality in wireless sensor networks that allow the base station to acquire important statistics about the sensed data. While many secure data aggregation schemes have been proposed in the literature, most of them target simple statistics such as Sum, Count, Min/Max, and Median. In contrast, a quantile summary allows a base station to extract the $\phi-$ quantile for any 0 < $\phi$ < 1 of all the sensor readings in the network and can provide a more accurate characterization of the data distribution. How to realize secure quantile summary aggregation in wireless sensor networks remains an open challenge. In this paper, we fill this void by first evaluating the impact of a range of attacks on quantile summary aggregation using simulation and then introduce a novel secure quantile summary aggregation protocol for wireless sensor networks. Detailed simulation studies confirm the efficacy and efficiency of the proposed protocol.
Aishah Aseeri, Rui Zhang 0007
MSN2
2021 Secure Connected Vehicle-based Traffic Signal Systems Against Data Spoofing Attacks
Tianye Ma, Rui Zhang 0007, Mark M. Nejad
WCNC2
2021 Verifiable Query Processing Over Outsourced Social Graph
abstract
Social data outsourcing is an emerging paradigm for effective and efficient access to the social data. In such a system, a third-party Social Data Provider (SDP) purchases social network datasets from Online Social Network (OSN) operators and then resells them to data consumers who can be any individuals or entities desiring social data through query interfaces. The SDP cannot be fully trusted and may return forged or incomplete query results to data consumers for various reasons, e.g., in favor of the businesses willing to pay. In this paper, we initiate the study on verifiable query processing over outsourced social graph whereby a data consumer can verify both the integrity and completeness of any query result returned by an untrusted SDP. We propose three schemes for single-attribute queries and another scheme for multi-attribute queries over outsourced social data. The four schemes all require the OSN provider to generate some cryptographic auxiliary information, based on which the SDP can construct a verification object to allow the data consumer to verify the integrity and completeness of the query result. They, however, differ in how the auxiliary information is generated and how the verification object is constructed and verified. Detailed analysis and extensive experiments using a real Twitter dataset confirm the efficacy and efficiency of the proposed schemes.
Xin Yao 0002, Rui Zhang 0007, Dingquan Huang
IEEE/ACM Trans. Netw.2
2020 KV-Fresh: Freshness Authentication for Outsourced Multi-Version Key-Value Stores
abstract
Data outsourcing is a promising technical paradigm to facilitate cost-effective real-time data storage, processing, and dissemination. In such a system, a data owner proactively pushes a stream of data records to a third-party cloud server for storage, which in turn processes various types of queries from end users on the data owner's behalf. This paper considers outsourced multi-version key-value stores that have gained increasing popularity in recent years, where a critical security challenge is to ensure that the cloud server returns both authentic and fresh data in response to end users' queries. Despite several recent attempts on authenticating data freshness in outsourced key-value stores, they either incur excessively high communication cost or can only offer very limited real-time guarantee. To fill this gap, this paper introduces KV-Fresh, a novel freshness authentication scheme for outsourced key-value stores that offers strong real-time guarantee. KV-Fresh is designed based on a novel data structure, Linked Key Span Merkle Hash Tree, which enables highly efficient freshness proof by embedding chaining relationship among records generated at different time. Detailed simulation studies using a synthetic dataset generated from real data confirm the efficacy and efficiency of KV-Fresh.
Rui Zhang 0007
INFOCOM2
2020 RF-Rhythm: Secure and Usable Two-Factor RFID Authentication
abstract
Passive RFID technology is widely used in user authentication and access control. We propose RF-Rhythm, a secure and usable two-factor RFID authentication system with strong resilience to lost/stolen/cloned RFID cards. In RF-Rhythm, each legitimate user performs a sequence of taps on his/her RFID card according to a self-chosen secret melody. Such rhythmic taps can induce phase changes in the backscattered signals, which the RFID reader can detect to recover the user’s tapping rhythm. In addition to verifying the RFID card’s identification information as usual, the backend server compares the extracted tapping rhythm with what it acquires in the user enrollment phase. The user passes authentication checks if and only if both verifications succeed. We also propose a novel phase-hopping protocol in which the RFID reader emits Continuous Wave (CW) with random phases for extracting the user’s secret tapping rhythm. Our protocol can prevent a capable adversary from extracting and then replaying a legitimate tapping rhythm from sniffed RFID signals. Comprehensive user experiments confirm the high security and usability of RF-Rhythm with false-positive and false-negative rates close to zero.
Jiawei Li 0010, Ang Li 0013, Dianqi Han, Yan Zhang 0091, Jinhang Zuo, Rui Zhang 0007, Lei Xie 0004
INFOCOM7
2020 A Spatiotemporal Approach for Secure Crowdsourced Radio Environment Map Construction
abstract
Database-driven Dynamic Spectrum Sharing (DSS) is the de-facto technical paradigm adopted by Federal Communications Commission for increasing spectrum efficiency, which allows licensed spectrum to be opportunistically used by secondary users. In database-driven DSS, a geo-location database administrator (DBA) maintains spectrum availability information over its service region in the form of a Radio Environment Map (REM), where the received signal strength from the primary user at every location is either directly measured via spectrum sensing or estimated via statistical spatial interpolation. Crowdsourcing-based spectrum sensing is a promising approach for periodically collecting spectrum measurements over a large geographic area but is unfortunately vulnerable to false spectrum measurements. Despite a large body of prior work on secure cooperative spectrum sensing, how to construct an accurate REM in the presence of false measurements remains an open challenge. In this paper, we introduce ST-REM, a novel spatiotemporal approach for securely constructing an REM in the presence of false spectrum measurements. Inspired by the self-label techniques developed for semi-supervised learning, ST-REM iteratively constructs an REM from a small number of spectrum measurements from trusted anchor sensors and many more measurements from mobile users. During each iteration, the DBA evaluates the trustworthiness of each measurement by jointly considering its spatial fitness with other trusted measurements and the mobile user's long-term behavior. By gradually incorporating the most trustworthy spectrum measurements, the DBA is able to construct a REM with high accuracy. Extensive simulation studies using a real spectrum measurement dataset confirm the efficacy and efficiency of ST-REM.
Rui Zhang 0007
IEEE/ACM Trans. Netw.2
2020 IndoorWaze: A Crowdsourcing-Based Context-Aware Indoor Navigation System
abstract
Indoor navigation systems are very useful in large complex indoor environments such as shopping malls. Current systems focus on improving indoor localization accuracy and must be combined with an accurate labeled floor plan to provide usable indoor navigation services. Such labeled floor plans are often unavailable or involve a prohibitive cost to manually obtain. In this paper, we present IndoorWaze, a novel crowdsourcing-based context-aware indoor navigation system that can automatically generate an accurate context-aware floor plan with labeled indoor POIs for the first time in literature. IndoorWaze combines the Wi-Fi fingerprints of indoor walkers with the Wi-Fi fingerprints and POI labels provided by POI employees to produce a high-fidelity labeled floor plan. As a lightweight crowdsourcing-based system, IndoorWaze involves very little effort from indoor walkers and POI employees. We prototype IndoorWaze on Android smartphones and evaluate it in a large shopping mall. Our results show that IndoorWaze can generate a high-fidelity labeled floor plan, in which all the stores are correctly labeled and arranged, all the pathways and crossings are correctly shown, and the median estimation error for the store dimension is below 12%.
Tao Li 0042, Dianqi Han, Yimin Chen 0004, Rui Zhang 0007, Terri Hedgpeth
IEEE Trans. Wirel. Commun.4
2019 Secure Data Aggregation in Wireless Sensor Networks: Enumeration Attack and Countermeasure
abstract
Data aggregation is a key primitive in wireless sensor networks and refers to the process in which the sensed data are processed and aggregated en-route by intermediate sensor nodes. Since sensor nodes are commonly resource constrained, they may be compromised by attackers and instructed to launch various attacks. Despite the rich literature on secure data aggregation, most of the prior work focuses on detecting intermediate nodes from modifying partial aggregation results with two security challenges remaining. First, a compromised sensor node can report arbitrary reading of its own, which is fundamentally difficult to detect but widely considered to have limited impact on the final aggregation result. Second, a compromised sensor node can repeatedly attack the aggregation process to prevent the base station from receiving correct aggregation results, leading to a special form of Denial-of-Service attack. VMAT [1] (published in ICDCS 2011) is a representative secure data aggregation scheme with the capability of pinpointing and revoking compromised sensor nodes, which relies on a secure MIN aggregation scheme and converts other additive aggregation functions such as SUM and COUNT to MIN aggregations. In this paper, we introduce a novel enumeration attack against VMAT to highlight the security vulnerability of a sensor node reporting an arbitrary reading of its own. The enumeration attack allows a single compromised sensor node to significantly inflate the final aggregation result without being detected. As a countermeasure, we also introduce an effective defense against the enumeration attack. Theoretical analysis and simulation studies confirm the severe impact of the enumeration attack and the effectiveness of the countermeasure.
Aishah Aseeri, Rui Zhang 0007
ICC2
2019 Differentially-Private Incentive Mechanism for Crowdsourced Radio Environment Map Construction
abstract
Database-driven Dynamic Spectrum Sharing (DSS) is a promising technical paradigm for enhancing spectrum efficiency by allowing secondary user to opportunistically access licenced spectrum channels without interfering with primary users' transmissions. In database-driven DSS, a geo-location database administrator (DBA) maintains the spectrum availability in its service region in the form of a radio environment map (REM) and grant or deny secondary users' spectrum access requests based on primary users' activities. Crowdsourcing-based spectrum sensing has great potential in improving the accuracy of the REM at the DBA but requires strong incentives and privacy protection to simulate mobile users' participation. To tackle this challenge, this paper introduces a novel differentially-private reverse auction mechanism for crowdsourcing-based spectrum sensing. The proposed mechanism allows the DBA to select spectrum sensing participants under a budget constraint while offering differential bid privacy, approximate truthfulness, and approximate accuracy maximization. Extensive simulation studies using a real spectrum measurement dataset confirm the efficacy and efficiency of the proposed mechanism.
Rui Zhang 0007
INFOCOM2
2019 Secure indoor positioning against signal strength attacks via optimized multi-voting
abstract
Indoor positioning systems (IPSes) can enable many location-based services in large indoor venues where GPS signals are unavailable or unreliable. Among the most viable types of IPSes, RSS-IPSes rely on ubiquitous smartphones and indoor WiFi infrastructures and explore distinguishable received signal strength (RSS) measurements at different indoor locations as their location fingerprints. RSS-IPSes are unfortunately vulnerable to physical-layer RSS attacks that cannot be thwarted by conventional cryptographic techniques. Existing defenses against RSS attacks are all subject to an inherent tradeoff between indoor positioning accuracy and attack resilience. This paper presents the design and evaluation of MV-IPS, a novel RSS-IPS based on weighted multi-voting, which does not suffer from this tradeoff. In MV-IPS, every WiFi access point (AP) that receives a user's RSS measurement gives a weighted vote for every reference location, and the reference location that receives the highest accumulative votes from all APs is output as the user's most likely position. Trace-driven simulation studies based on real RSS measurements demonstrate that MV-IPS can achieve much higher positioning accuracy than prior solutions no matter whether RSS attacks are present.
Rui Zhang 0007, Terri Hedgpeth
IWQoS3
2019 Verifiable outsourced computation over encrypted data
Xixun Yu, Zheng Yan 0002, Rui Zhang 0007
Inf. Sci.3
2018 Secure Crowdsourced Indoor Positioning Systems
abstract
Indoor positioning systems (IPSes) can enable many location-based services in large indoor environments where GPS is not available or reliable. Mobile crowdsourcing is widely advocated as an effective way to construct IPS maps. This paper presents the first systematic study of security issues in crowd-sourced WiFi-based IPSes to promote security considerations in designing and deploying crowdsourced IPSes. We identify three attacks on crowdsourced WiFi-based IPSes and propose the corresponding countermeasures. The efficacy of the attacks and also our countermeasures are experimentally validated on a prototype system. The attacks and countermeasures can be easily extended to other crowdsourced IPSes.
Tao Li 0042, Yimin Chen 0004, Rui Zhang 0007, Terri Hedgpeth
INFOCOM3
2018 Privacy-Preserving Social Media Data Outsourcing
abstract
User-generated social media data are exploding and of high demand in public and private sectors. The disclosure of intact social media data exacerbates the threats to user privacy. In this paper, we first identify a text-based user-linkage attack on current data outsourcing practices, in which the real users in an anonymized dataset can be pinpointed based on the users' unprotected text data. Then we propose a framework for differentially privacy-preserving social media data outsourcing for the first time in literature. Within our framework, social media data service providers can outsource perturbed datasets to provide users differential privacy while offering high data utility to social media data consumers. Our differential privacy mechanism is based on a novel notion of E - text indistinguishability, which we propose to thwart the text-based user-linkage attack. Extensive experiments on real-world and synthetic datasets confirm that our framework can enable high-level differential privacy protection and also high data utility.
Jinxue Zhang, Jingchao Sun, Rui Zhang 0007, Xia Ben Hu
INFOCOM3
2018 Proximity-Proof: Secure and Usable Mobile Two-Factor Authentication
abstract
Mobile two-factor authentication (2FA) has become commonplace along with the popularity of mobile devices. Current mobile 2FA solutions all require some form of user effort which may seriously affect the experience of mobile users, especially senior citizens or those with disability such as visually impaired users. In this paper, we propose Proximity-Proof, a secure and usable mobile 2FA system without involving user interactions. Proximity-Proof automatically transmits a user's 2FA response via inaudible OFDM-modulated acoustic signals to the login browser. We propose a novel technique to extract individual speaker and microphone fingerprints of a mobile device to defend against the powerful man-in-the-middle (MiM) attack. In addition, Proximity-Proof explores two-way acoustic ranging to thwart the co-located attack. To the best of our knowledge, Proximity-Proof is the first mobile 2FA scheme resilient to the MiM and co-located attacks. We empirically analyze that Proximity-Proof is at least as secure as existing mobile 2FA solutions while being highly usable. We also prototype Proximity-Proof and confirm its high security, usability, and efficiency through comprehensive user experiments.
Dianqi Han, Yimin Chen 0004, Tao Li 0042, Rui Zhang 0007, Terri Hedgpeth
MobiCom4
2018 EyeTell: Video-Assisted Touchscreen Keystroke Inference from Eye Movements
abstract
Keystroke inference attacks pose an increasing threat to ubiquitous mobile devices. This paper presents EyeTell, a novel video-assisted attack that can infer a victim's keystrokes on his touchscreen device from a video capturing his eye movements. EyeTell explores the observation that human eyes naturally focus on and follow the keys they type, so a typing sequence on a soft keyboard results in a unique gaze trace of continuous eye movements. In contrast to prior work, EyeTell requires neither the attacker to visually observe the victim's inputting process nor the victim device to be placed on a static holder. Comprehensive experiments on iOS and Android devices confirm the high efficacy of EyeTell for inferring PINs, lock patterns, and English words under various environmental conditions.
Yimin Chen 0004, Tao Li 0042, Rui Zhang 0007, Terri Hedgpeth
IEEE Symposium on Security and Privacy3
2018 Beware of What You Share: Inferring User Locations in Venmo
abstract
Mobile payment apps are seeing explosive usage worldwide. This paper focuses on Venmo, a very popular mobile person-to-person payment service owned by Paypal. Venmo allows money transfers between users with a mandatory transaction note. More than half of transaction records in Venmo are public information. In this paper, we propose a multilayer location inference (MLLI) technique to infer user locations from public transaction records in Venmo. MLLI explores two observations. First, many Venmo transaction notes contain implicit location cues. Second, the types and temporal patterns of user transactions have strong ties to their location closeness. With a large dataset of 2.12M users and 20.23M Venmo transaction records, we show that MLLI can identify the top-1, top-3, and top-5 possible locations for a Venmo user with accuracy up to 50%, 80%, and 90%, respectively. Our results highlight the danger of sharing transaction notes on Venmo or similar mobile payment apps.
Xin Yao 0002, Yimin Chen 0004, Rui Zhang 0007, Yaping Lin
IEEE Internet Things J.3
2018 The Rise of Social Botnets: Attacks and Countermeasures
abstract
Online social networks (OSNs) are increasingly threatened by social bots which are software-controlled OSN accounts that mimic human users with malicious intentions. A social botnet refers to a group of social bots under the control of a single botmaster, which collaborate to conduct malicious behavior while mimicking the interactions among normal OSN users to reduce their individual risk of being detected. We demonstrate the effectiveness and advantages of exploiting a social botnet for spam distribution and digital-influence manipulation through real experiments on Twitter and also trace-driven simulations. We also propose the corresponding countermeasures and evaluate their effectiveness. Our results can help understand the potentially detrimental effects of social botnets and help OSNs improve their bot(net) detection systems.
Jinxue Zhang, Rui Zhang 0007, Guanhua Yan
IEEE Trans. Dependable Secur. Comput.2
2018 SpecGuard: Spectrum Misuse Detection in Dynamic Spectrum Access Systems
abstract
Dynamic spectrum access (DSA) is the key to solving worldwide spectrum shortage. The open wireless medium subjects DSA systems to unauthorized spectrum use by illegitimate users. Secondary-user authentication is thus critical to ensure the proper operations of DSA systems. This paper presents SpecGuard, the first crowdsourced spectrum misuse detection framework for DSA systems. In SpecGuard, a transmitter is required to embed a spectrum permit into its physical-layer signals, which can be decoded and verified by ubiquitous mobile users. We propose three novel schemes for embedding and detecting a spectrum permit at the physical layer. The first scheme relies on a higher transmission power to embed the spectrum permit. To alleviate the assumptions on the additional transmission power, the second scheme is proposed with a limited negative impact on the normal data transmission. The third scheme takes a different approach by adopting a novel constellation design and exploiting the trust between the transmitter and the receiver. Crowdsourced spectrum misuse detection eliminates the need for the deployment of dedicated sensors and thus greatly reduces the deployment and maintenance cost. Detailed theoretical analyses, MATLAB simulations, and USRP experiments confirm that our schemes can achieve correct, low-intrusive, and fast spectrum misuse detection.
Xiaocong Jin, Jingchao Sun, Rui Zhang 0007, Chi Zhang 0001
IEEE Trans. Mob. Comput.3
2017 Secure crowdsourced radio environment map construction
abstract
Database-driven Dynamic Spectrum Sharing (DSS) is the de-facto technical paradigm adopted by Federal Communications Commission (FCC) for increasing spectrum efficiency. In such a system, a geo-location database administrator (DBA) maintains spectrum availability information over its service region whereby to determines whether a secondary user can access a licensed spectrum band at his desired location and time. To maintain spectrum availability in its service region, it is desirable for the DBA to periodically collect spectrum measurements whereby to construct and maintain a Radio Environment Map (REM), where the received signal strength at every location of interest is either directly measured or estimated via proper statistical spatial interpolation techniques. Crowdsourcing-based spectrum sensing is a promising approach for periodically collecting spectrum measurements over a large geographic area, which is, unfortunately, vulnerable to false spectrum measurements. How to construct an accurate REM in the presence of false measurements remains an open challenge. This paper introduces SecREM, a novel scheme for securely constructing a REM in the presence of false spectrum measurements. SecREM relies on a small number of trusted spectrum measurements whereby to evaluate the trustworthiness of the measurements from mobile users and gradually incorporate the most trustworthy ones to construct an accurate REM. Extensive simulation studies based on a real spectrum measurement dataset confirm the efficacy and efficiency of SecREM.
Rui Zhang 0007
ICNP2
2017 POWERFUL: Mobile app fingerprinting via power analysis
abstract
Which apps a mobile user has and how they are used can disclose significant private information about the user. In this paper, we present the design and evaluation of POWERFUL, a new attack which can fingerprint sensitive mobile apps (or infer sensitive app usage) by analyzing the power consumption profiles on Android devices. POWERFUL works on the observation that distinct apps and their different usage patterns all lead to distinguishable power consumption profiles. Since the power profiles on Android devices require no permission to access, POWERFUL is very difficult to detect and can pose a serious threat against user privacy. Extensive experiments involving popular and sensitive apps in Google Play Store show that POWERFUL can identify the app used at any particular time with accuracy up to 92.9%, demonstrating the feasibility of POWERFUL.
Yimin Chen 0004, Xiaocong Jin, Jingchao Sun, Rui Zhang 0007
INFOCOM4
2017 Your face your heart: Secure mobile face authentication with photoplethysmograms
abstract
Face authentication emerges as a powerful method for preventing unauthorized access to mobile devices. It is, however, vulnerable to photo-based forgery attacks (PFA) and videobased forgery attacks (VFA), in which the adversary exploits a photo or video containing the user's frontal face. Effective defenses against PFA and VFA often rely on liveness detection, which seeks to find a live indicator that the submitted face photo or video of the legitimate user is indeed captured in real time. In this paper, we propose FaceHeart, a novel and practical face authentication system for mobile devices. FaceHeart simultaneously takes a face video with the front camera and a fingertip video with the rear camera on COTS mobile devices. It then achieves liveness detection by comparing the two photoplethysmograms independently extracted from the face and fingertip videos, which should be highly consistent if the two videos are for the same live person and taken at the same time. As photoplethysmograms are closely tied to human cardiac activity and almost impossible to forge or control, FaceHeart is strongly resilient to PFA and VFA. Extensive user experiments on Samsung Galaxy S5 have confirmed the high efficacy and efficiency of FaceHeart.
Yimin Chen 0004, Jingchao Sun, Xiaocong Jin, Tao Li 0042, Rui Zhang 0007
INFOCOM5
2017 Verifiable social data outsourcing
abstract
Social data outsourcing is an emerging paradigm for effective and efficient access to the social data. In such a system, a third-party Social Data Provider (SDP) purchases complete social datasets from Online Social Network (OSN) operators and then resells them to data consumers who can be any individuals or entities desiring the complete social data satisfying some criteria. The SDP cannot be fully trusted and may return wrong query results to data consumers by adding fake data and deleting/modifying true data in favor of the businesses willing to pay. In this paper, we initiate the study on verifiable social data outsourcing whereby a data consumer can verify the trustworthiness of the social data returned by the SDP. We propose three schemes for verifiable queries over outsourced social data. The three schemes all require the OSN provider to generate some cryptographic auxiliary information, based on which the SDP can construct a verification object for the data consumer to verify the query-result trustworthiness. They differ in how the auxiliary information is generated and how the verification object is constructed and verified. Extensive experiments based on a real Twitter dataset confirm the high efficacy and efficiency of our schemes.
Xin Yao 0002, Rui Zhang 0007, Yaping Lin
INFOCOM2
2017 A Multisecret Value Access Control Framework for Airliner in Multinational Air Traffic Management
abstract
When been threatened by hijacking or suicide-bypilots, the airliner may either crash itself or be shot down due to the potential of the suicide attack. There exist some solutions that allow air traffic controllers or federal agents to take over pilots' authority in the emergency. Though rarely, an air traffic controller may abuse this privilege to mishandle airliners that leads to catastrophic events. In this paper, to mitigate such risks, we propose a multisecret value access control framework based on new designed and existing cryptographic techniques such as XOR-based secret sharing schemes (SSSs). It not only satisfies the efficiency requirement but also assures that each nation owns a unique secret value. We further develop and implement the XOR-based SSS on Linux system. Both experimental results and performance evaluation demonstrate that our solution is not only efficient and bust also secure by design for the multinational air traffic management.
Depeng Li 0002, Rui Zhang 0007, Yingfei Dong, Fangjin Zhu, Dusko Pavlovic
IEEE Internet Things J.2
2016 DPSense: Differentially Private Crowdsourced Spectrum Sensing
abstract
Dynamic spectrum access (DSA) has great potential to address worldwide spectrum shortage by enhancing spectrum efficiency. It allows unlicensed secondary users to access the underutilized licensed spectrum when the licensed primary users are not transmitting. As a key enabler for DSA systems, crowdsourced spectrum sensing (CSS) allows a spectrum sensing provider (SSP) to outsource the sensing of spectrum occupancy to distributed mobile users. In this paper, we propose DPSense, a novel framework that allows the SSP to select mobile users for executing spatiotemporal spectrum-sensing tasks without violating the location privacy of mobile users. Detailed evaluations on real location traces confirm that DPSense can provide differential location privacy to mobile users while ensuring that the SSP can accomplish spectrum-sensing tasks with overwhelming probability and also the minimal cost.
Xiaocong Jin, Rui Zhang 0007, Yimin Chen 0004, Tao Li 0042
CCS2
2016 Secure outsourced skyline query processing via untrusted cloud service providers
abstract
Recent years have witnessed a growing number of location-based service providers (LBSPs) outsourcing their points of interest (POI) datasets to third-party cloud service providers (CSPs), which in turn answer various data queries from mobile users on their behalf. A main challenge in such systems is that the CSPs cannot be fully trusted, which may return fake query results for various bad motives, e.g., in favor of POIs willing to pay. As an important type of queries, location-based skyline queries (LBSQs) ask for the POIs that are not spatially dominated by any other POI with respect to some query position. In this paper, we propose three novel schemes that enable efficient verification of any LBSQ result returned by an untrusted CSP by embedding and exploring a novel neighboring relationship among POIs. The efficacy and efficiency of our schemes are thoroughly analyzed and evaluated.
Mengjun Liu, Rui Zhang 0007
INFOCOM3
2016 PriStream: Privacy-preserving distributed stream monitoring of thresholded PERCENTILE statistics
abstract
Distributed stream monitoring has numerous potential applications in future smart cities. Communication efficiency, and data privacy are two main challenges for distributed stream monitoring services. In this paper, we propose PriStream, the first communication-efficient and privacy-preserving distributed stream monitoring system for thresholded PERCENTILE aggregates. PriStream allows the monitoring service provider to evaluate an arbitrary function over a desired percentile of distributed data reports and monitor when the output exceeds a predetermined system threshold. Detailed theoretical analysis and evaluations show that PriStream has high accuracy and communication efficiency, and differential privacy guarantees under a strong adversary model.
Jingchao Sun, Rui Zhang 0007, Jinxue Zhang
INFOCOM2
2016 VISIBLE: Video-Assisted Keystroke Inference from Tablet Backside Motion
Jingchao Sun, Xiaocong Jin, Yimin Chen 0004, Jinxue Zhang, Rui Zhang 0007
NDSS6
2016 Privacy-Preserving Spatiotemporal Matching for Secure Device-to-Device Communications
abstract
Device-to-device (D2D) communications are emerging due to the explosive growth of smartphones and tablets. Given the possible presence of attackers, a fundamental challenge in secure D2D communications is to develop sound mobile authentication techniques whereby mobile users can select the most trustworthy D2D communication partners from possibly many candidates. This paper tackles this open challenge and proposes spatiotemporal matching as a promising enabler for secure D2D communications. Spatiotemporal matching is built upon the location-aware capability of D2D devices. In particular, a mobile user could very easily maintain his spatiotemporal profile recording his continuous whereabouts in time, and the level of his spatiotemporal profile matching that of the other user can be translated into the level of trust they two can have in each other. Since spatiotemporal profiles contain very sensitive personal information, privacy-preserving spatiotemporal matching is needed to ensure that as little information as possible about the spatiotemporal profile of either matching participant is disclosed beyond the matching result. Toward this end, we propose two novel privacy-preserving spatiotemporal matching protocols, which are thoroughly analyzed and evaluated through detailed simulation studies driven by experimental data.
Jingchao Sun, Rui Zhang 0007
IEEE Internet Things J.2
2016 TrueTop: A Sybil-Resilient System for User Influence Measurement on Twitter
abstract
Influential users have great potential for accelerating information dissemination and acquisition on Twitter. How to measure the influence of Twitter users has attracted significant academic and industrial attention. Existing influence measurement techniques are vulnerable to sybil users that are thriving on Twitter. Although sybil defenses for online social networks have been extensively investigated, they commonly assume unique mappings from human-established trust relationships to online social associations and thus do not apply to Twitter where users can freely follow each other. This paper presents TrueTop, the first sybil-resilient system to measure the influence of Twitter users. TrueTop is rooted in two observations from real Twitter datasets. First, although non-sybil users may incautiously follow strangers, they tend to be more careful and selective in retweeting, replying to, and mentioning other users. Second, influential users usually get much more retweets, replies, and mentions than non-influential users. Detailed theoretical studies and synthetic simulations show that TrueTop can generate very accurate influence measurement results with strong resilience to sybil attacks.
Jinxue Zhang, Rui Zhang 0007, Jingchao Sun, Chi Zhang 0001
IEEE/ACM Trans. Netw.2
2016 SecureFind: Secure and Privacy-Preserving Object Finding via Mobile Crowdsourcing
abstract
The plummeting cost of Bluetooth tags and the ubiquity of mobile devices are revolutionizing the traditional lost-and-found service. This paper presents SecureFind, a secure and privacy-preserving object-finding system via mobile crowdsourcing. In SecureFind, a unique Bluetooth tag is attached to every valuable object, and the owner of a lost object submits an object-finding request to many mobile users via the SecureFind service provider. Each mobile user involved searches his vicinity for the lost object on behalf of the object owner who can infer the location of his lost object based on the responses from mobile users. SecureFind is designed to ensure strong object security such that only the object owner can discover the location of his lost object as well as offering location privacy to mobile users involved. The high efficacy and efficiency of SecureFind are confirmed by extensive simulations.
Jingchao Sun, Rui Zhang 0007, Xiaocong Jin
IEEE Trans. Wirel. Commun.2
2015 SafeDSA: Safeguard Dynamic Spectrum Access against Fake Secondary Users
abstract
Dynamic spectrum access (DSA) is the key to solving worldwide wireless spectrum shortage. In a DSA system, unlicensed secondary users can opportunistically use a spectrum band when it is not used by the licensed primary user. The open nature of the wireless medium means that any secondary user can freely use any given spectrum band. Secondary-user authentication is thus essential to ensure the proper operations of DSA systems. We propose SafeDSA, a novel PHY-based scheme for authenticating secondary users in DSA systems. In SafeDSA, the secondary user embeds his spectrum-use authorization into the cyclic prefix of each physical-layer symbol, which can be detected and authenticated by a verifier. In contrast to previous work, SafeDSA achieves robust and efficient authentication of secondary users with negligible impact on normal data transmissions. We validate the efficacy and efficiency of SafeDSA through detailed MATLAB simulations and USRP experiments. Our results show that SafeDSA can detect fake secondary users with a maximum false-positive rate of 0.091 and a negligible false-negative rate based on USRP experiments.
Xiaocong Jin, Jingchao Sun, Rui Zhang 0007
CCS3
2015 Your song your way: Rhythm-based two-factor authentication for multi-touch mobile devices
abstract
Multi-touch mobile devices have penetrated into everyday life to support personal and business communications. Secure and usable authentication techniques are indispensable for preventing illegitimate access to mobile devices. This paper presents RhyAuth, a novel two-factor rhythm-based authentication scheme for multi-touch mobile devices. RhyAuth requires a user to perform a sequence of rhythmic taps/slides on a device screen to unlock the device. The user is authenticated and admitted only when the features extracted from her rhythmic taps/slides match those stored on the device. RhyAuth is a two-factor authentication scheme that depends on a user-chosen rhythm and also the behavioral metrics for inputting the rhythm. Through a 32-user experiment on Android devices, we show that RhyAuth is highly secure against various attacks and also very usable for both sighted and visually impaired people.
Yimin Chen 0004, Jingchao Sun, Rui Zhang 0007
INFOCOM3
2015 SpecGuard: Spectrum misuse detection in dynamic spectrum access systems
abstract
Dynamic spectrum access is the key to solving worldwide spectrum shortage. The open wireless medium subjects DSA systems to unauthorized spectrum use by illegitimate users. This paper presents SpecGuard, the first crowdsourced spectrum misuse detection framework for DSA systems. In SpecGuard, a transmitter is required to embed a spectrum permit into its physical-layer signals, which can be decoded and verified by ubiquitous mobile users. We propose three novel schemes for embedding and detecting a spectrum permit at the physical layer. Detailed theoretical analyses, MATLAB simulations, and USRP experiments confirm that our schemes can achieve correct, low-intrusive, and fast spectrum misuse detection.
Xiaocong Jin, Jingchao Sun, Rui Zhang 0007, Chi Zhang 0001
INFOCOM3
2015 Secure Spatial Top-k Query Processing via Untrusted Location-Based Service Providers
abstract
This paper considers a novel distributed system for collaborative location-based information generation and sharing which become increasingly popular due to the explosive growth of Internet-capable and location-aware mobile devices. The system consists of a data collector, data contributors, location-based service providers (LBSPs), and system users. The data collector gathers reviews about points-of-interest (POIs) from data contributors, while LBSPs purchase POI data sets from the data collector and allow users to perform spatial top-k queries which ask for the POIs in a certain region and with the highest k ratings for an interested POI attribute. In practice, LBSPs are untrusted and may return fake query results for various bad motives, e.g., in favor of POIs willing to pay. This paper presents three novel schemes for users to detect fake spatial snapshot and moving top-k query results as an effort to foster the practical deployment and use of the proposed system. The efficacy and efficiency of our schemes are thoroughly analyzed and evaluated.
Rui Zhang 0007, Jingchao Sun, Chi Zhang 0001
IEEE Trans. Dependable Secur. Comput.1
2015 Jamming-Resilient Secure Neighbor Discovery in Mobile Ad Hoc Networks
abstract
Secure neighbor discovery is fundamental to mobile ad hoc networks (MANETs) deployed in hostile environments and refers to the process in which two neighboring nodes exchange messages to discover and authenticate each other. It is vulnerable to the jamming attack in which the adversary intentionally transmits radio signals to prevent neighboring nodes from exchanging messages. Anti-jamming communications often rely on spread-spectrum techniques, which depend on a spreading code common to the communicating parties but unknown to the jammer. The spread code, however, is impossible to establish before the communicating parties successfully discover each other. While several elegant approaches have been recently proposed to break this circular dependence, the unique features of neighbor discovery in MANETs make them not directly applicable. In this paper, we propose JR-SND, a jamming-resilient secure neighbor discovery scheme for MANETs based on direct-sequence spread spectrum and random spread-code predistribution. JR-SND enables neighboring nodes to securely discover each other with overwhelming probability despite the presence of omnipresent jammers. Detailed theoretical and simulation results confirm the efficacy and efficiency of JR-SND.
Rui Zhang 0007, Jingchao Sun, Xiaoxia Huang 0004
IEEE Trans. Wirel. Commun.1
2014 TIGHT: A Geographic Routing Protocol for Cognitive Radio Mobile Ad Hoc Networks
abstract
This paper presents TIGHT, a geographic routing protocol for cognitive radio mobile ad hoc networks. TIGHT offers three routing modes and allows secondary users to fully explore the transmission opportunities over a primary channel without affecting primary users (PUs). The greedy mode routes a packet via greedy geographic forwarding until a PU region is encountered and then further routes the packet around the PU region to where greedy forwarding can resume. It works best when the PUs are only occasionally active. In contrast, the optimal and suboptimal modes route a packet along optimal and suboptimal trajectories to the destination, respectively. They work best when the PUs are active most of the time. The suboptimal mode is computationally more efficient than the optimal mode at the cost of using suboptimal trajectories in rare cases. The efficacy of TIGHT is confirmed by extensive simulations.
Xiaocong Jin, Rui Zhang 0007, Jingchao Sun
IEEE Trans. Wirel. Commun.2
2013 Secure crowdsourcing-based cooperative pectrum sensing
abstract
Cooperative (spectrum) sensing is a key function for dynamic spectrum access and is essential for avoiding interference with licensed primary users and identifying spectrum holes. A promising approach for effective cooperative sensing over a large geographic region is to rely on special spectrum-sensing providers (SSPs), which outsource spectrum-sensing tasks to distributed mobile users. Its feasibility is deeply rooted in the ubiquitous penetration of mobile devices into everyday life. Crowdsourcing-based cooperative spectrum sensing is, however, vulnerable to malicious sensing data injection attack, in which a malicious CR users submit false sensing reports containing power measurements much larger (or smaller) than the true value to inflate (or deflate) the final average, in which case the SSP may falsely determine that the channel is busy (or vacant). In this paper, we propose a novel scheme to enable secure crowdsourcing-based cooperative spectrum sensing by jointly considering the instantaneous trustworthiness of mobile detectors in combination with their reputation scores during data fusion. Our scheme can enable robust cooperative sensing even if the malicious CR users are the majority. The efficacy and efficiency of our scheme have been confirmed by extensive simulation studies.
Rui Zhang 0007, Jinxue Zhang, Chi Zhang 0001
INFOCOM1
2013 Privacy-preserving spatiotemporal matching
abstract
The explosive growth of mobile-connected and location-aware devices makes it possible to have a new way of establishing trust relationships, which we coin as spatiotemporal matching. In particular, a mobile user could very easily maintain his spatiotemporal profile recording his continuous whereabouts in time, and the level of his spatiotemporal profile matching that of the other user can be translated into the level of trust they two can have in each other. Since spatiotemporal profiles contain very sensitive personal information, privacy-preserving spatiotemporal matching is needed to ensure that as little information as possible about the spatiotemporal profile of either matching participant is disclosed beyond the matching result. We propose a cryptographic solution based on Private Set Intersection Cardinality and a more efficient non-cryptographic solution involving a novel use of the Bloom filter. We thoroughly analyze both solutions and compare their efficacy and efficiency via detailed simulation studies.
Jingchao Sun, Rui Zhang 0007
INFOCOM2
2013 Verifiable Privacy-Preserving Aggregation in People-Centric Urban Sensing Systems
abstract
People-centric urban sensing systems (PC-USSs) refer to using human-carried mobile devices such as smartphones and tablets for urban-scale distributed data collection, analysis, and sharing to facilitate interaction between humans and their surrounding environments. A main obstacle to the widespread deployment and adoption of PC-USSs are the privacy concerns of participating individuals as well as the concerns about data integrity. To tackle this open challenge, this paper presents the design and evaluation of VPA, a novel peer-to-peer based solution to verifiable privacy-preserving data aggregation in PC-USSs. VPA achieves strong user privacy by letting each user exchange random shares of its datum with other peers, while at the same time ensures data integrity through a combination of Trusted Platform Module and homomorphic message authentication code. VPA can support a wide range of statistical additive and non-additive aggregation functions such as Sum, Average, Variance, Count, Max/Min, Median, Histogram, and Percentile with accurate aggregation results. The efficacy and efficiency of VPA are confirmed by thorough analytical and simulation results.
Rui Zhang 0007, Jing Shi 0002, Chi Zhang 0001
IEEE J. Sel. Areas Commun.1
2013 Privacy-Preserving Profile Matching for Proximity-Based Mobile Social Networking
abstract
Proximity-based mobile social networking (PMSN) refers to the social interaction among physically proximate mobile users. The first step toward effective PMSN is for mobile users to choose whom to interact with. Profile matching refers to two users comparing their personal profiles and is promising for user selection in PMSN. It, however, conflicts with users' growing privacy concerns about disclosing their personal profiles to complete strangers. This paper tackles this open challenge by designing novel fine-grained private matching protocols. Our protocols enable two users to perform profile matching without disclosing any information about their profiles beyond the comparison result. In contrast to existing coarse-grained private matching schemes for PMSN, our protocols allow finer differentiation between PMSN users and can support a wide range of matching metrics at different privacy levels. The performance of our protocols is thoroughly analyzed and evaluated via real smartphone experiments.
Rui Zhang 0007, Jinxue Zhang, Jinyuan Sun, Guanhua Yan
IEEE J. Sel. Areas Commun.1
2012 Fine-grained private matching for proximity-based mobile social networking
abstract
Proximity-based mobile social networking (PMSN) refers to the social interaction among physically proximate mobile users directly through the Bluetooth/WiFi interfaces on their smartphones or other mobile devices. It becomes increasingly popular due to the recently explosive growth of smartphone users. Profile matching means two users comparing their personal profiles and is often the first step towards effective PMSN. It, however, conflicts with users' growing privacy concerns about disclosing their personal profiles to complete strangers before deciding to interact with them. This paper tackles this open challenge by designing a suite of novel fine-grained private matching protocols. Our protocols enable two users to perform profile matching without disclosing any information about their profiles beyond the comparison result. In contrast to existing coarse-grained private matching schemes for PMSN, our protocols allow finer differentiation between PMSN users and can support a wide range of matching metrics at different privacy levels. The security and communication/computation overhead of our protocols are thoroughly analyzed and evaluated via detailed simulations.
Rui Zhang 0007, Jinyuan Sun, Guanhua Yan
INFOCOM1
2012 Secure top-k query processing via untrusted location-based service providers
abstract
This paper considers a novel distributed system for collaborative location-based information generation and sharing which become increasingly popular due to the explosive growth of Internet-capable and location-aware mobile devices. The system consists of a data collector, data contributors, location-based service providers (LBSPs), and system users. The data collector gathers reviews about points-of-interest (POIs) from data contributors, while LBSPs purchase POI data sets from the data collector and allow users to perform location-based top-k queries which ask for the POIs in a certain region and with the highest k ratings for an interested POI attribute. In practice, LBSPs are untrusted and may return fake query results for various bad motives, e.g., in favor of POIs willing to pay. This paper presents two novel schemes for users to detect fake top-k query results as an effort to foster the practical deployment and use of the proposed system. The efficacy and efficiency of our schemes are thoroughly analyzed and evaluated.
Rui Zhang 0007, Chi Zhang 0001
INFOCOM1
2012 Secure Cooperative Data Storage and Query Processing in Unattended Tiered Sensor Networks
abstract
We consider an unattended tiered sensor network (UTSN) consisting of resource-rich master nodes at the upper tier and resource-poor sensor nodes at the lower tier. Sensor nodes submit data to nearby master nodes which store the data and answer the queries from the network owner on behalf of sensor nodes. Such a cooperative data storage and query processing paradigm offers a number of advantages over traditional Homogeneous unattended sensor networks. Relying on master nodes for data storage and query processing, however, raises severe concerns about data confidentiality and query-result correctness when the sensor network is deployed in hostile environments. In particular, a compromised master node may leak hosted sensitive data to the adversary; it may also return juggled or incomplete query results to the network owner. In this paper, we take multidimensional range queries as an example to investigate secure cooperative data storage and query processing in UTSNs. We present a suite of novel schemes that can ensure data confidentiality against master nodes and also enable the network owner to verify with very high probability the authenticity and completeness of any query result by inspecting the spatial and temporal relationships among the returned data. Detailed performance evaluations confirm the high efficacy and efficiency of the proposed schemes.
Rui Zhang 0007, Jing Shi 0002, Jinyuan Sun
IEEE J. Sel. Areas Commun.1
2012 Distributed Privacy-Preserving Access Control in Sensor Networks
abstract
The owner and users of a sensor network may be different, which necessitates privacy-preserving access control. On the one hand, the network owner need enforce strict access control so that the sensed data are only accessible to users willing to pay. On the other hand, users wish to protect their respective data access patterns whose disclosure may be used against their interests. This paper presents DP2AC, a Distributed Privacy-Preserving Access Control scheme for sensor networks, which is the first work of its kind. Users in DP2AC purchase tokens from the network owner whereby to query data from sensor nodes which will reply only after validating the tokens. The use of blind signatures in token generation ensures that tokens are publicly verifiable yet unlinkable to user identities, so privacy-preserving access control is achieved. A central component in DP2AC is to prevent malicious users from reusing tokens, for which we propose a suite of distributed token reuse detection (DTRD) schemes without involving the base station. These schemes share the essential idea that a sensor node checks with some other nodes (called witnesses) whether a token has been used, but they differ in how the witnesses are chosen. We thoroughly compare their performance with regard to TRD capability, communication overhead, storage overhead, and attack resilience. The efficacy and efficiency of DP2AC are confirmed by detailed performance evaluations.
Rui Zhang 0007, Kui Ren 0001
IEEE Trans. Parallel Distributed Syst.1
2011 LR-Seluge: Loss-Resilient and Secure Code Dissemination in Wireless Sensor Networks
abstract
Code dissemination in wireless sensor networks refers to the process of disseminating a new code image via wireless links to all sensor nodes after they are deployed. It is desirable and often necessary due to the need for, e.g., removing program bugs and adding new functionalities in a multi-task sensor network. A sound code dissemination scheme need be both loss-resilient and attack-resilient, which are crucial for sensor networks deployed in lossy and hostile environments. To the best of our knowledge, no existing scheme simultaneously satisfies both requirements. This paper fills this gap with the design and evaluation of LR-Seluge, a novel loss-resilient and secure code dissemination scheme. The efficacy and efficiency of LR-Seluge are confirmed by both theoretical analysis and extensive simulation results. In particular, LR-Seluge can reduce up to 40% communication overhead in lossy environments with the same level of attack resilience in contrast to existing schemes.
Rui Zhang 0007
ICDCS1
2011 JR-SND: Jamming-Resilient Secure Neighbor Discovery in Mobile Ad Hoc Networks
abstract
Secure neighbor discovery is fundamental to mobile ad hoc networks (MANETs) deployed in hostile environments and refers to the process in which two neighboring nodes exchange messages to discover and authenticate each other. It is vulnerable to the jamming attack in which the adversary intentionally sends radio signals to prevent neighboring nodes from exchanging messages. Anti-jamming communications often rely on spread-spectrum techniques which depend on a spreading code common to the communicating parties but unknown to the jammer. The spread code is, however, impossible to establish before the communicating parties successfully discover each other. While several elegant approaches have been recently proposed to break this circular dependency, the unique features of neighbor discovery in MANETs make them not directly applicable. In this paper, we propose JR-SND, a jamming-resilient secure neighbor discovery scheme for MANETs based on Direct Sequence Spread Spectrum and random spread-code pre-distribution. JR-SND enables neighboring nodes to securely discover each other with overwhelming probability despite the presence of omnipresent jammers. Detailed theoretical and simulation results confirm the efficacy and efficiency of JR-SND.
Rui Zhang 0007, Xiaoxia Huang 0004
ICDCS1
2011 Fast identification of the missing tags in a large RFID system
abstract
RFID (radio-frequency identification) is an emerging technology with extensive applications such as transportation and logistics, object tracking, and inventory management. How to quickly identify the missing RFID tags and thus their associated objects is a practically important problem in many large-scale RFID systems. This paper presents three novel methods to quickly identify the missing tags in a large-scale RFID system of thousands of tags. Our protocols can reduce the time for identifying all the missing tags by up to 75% in comparison to the state of art.
Rui Zhang 0007, Yunzhong Liu, Jinyuan Sun
SECON1
2011 A Spatiotemporal Approach for Secure Range Queries in Tiered Sensor Networks
abstract
We target a two-tier sensor network with resource-rich master nodes at the upper tier and resource-poor sensor nodes at the lower tier. Master nodes collect data from sensor nodes and answer the queries from the network owner. The reliance on master nodes for data storage and query processing raises serious concerns about both data confidentiality and query-result correctness in hostile environments. In particular, a compromised master node may leak hosted sensitive data to the adversary; it may also return juggled or incomplete data in response to a query. This paper presents a novel spatiotemporal approach to ensure secure range queries in event-driven two-tier sensor networks. It offers data confidentiality by preventing master nodes from reading hosted data and also enables efficient range-query processing. More importantly, it allows the network owner to verify with very high probability whether a query result is authentic and complete by examining the spatial and temporal relationships among the returned data. The high efficacy and efficiency of our approach are confirmed by detailed performance evaluations.
Jing Shi 0002, Rui Zhang 0007
IEEE Trans. Wirel. Commun.2
2011 AOS: an anonymous overlay system for mobile ad hoc networks
Rui Zhang 0007, Yuguang Fang
Wirel. Networks1
2010 PriSense: Privacy-Preserving Data Aggregation in People-Centric Urban Sensing Systems
abstract
People-centric urban sensing is a new paradigm gaining popularity. A main obstacle to its widespread deployment and adoption are the privacy concerns of participating individuals. To tackle this open challenge, this paper presents the design and evaluation of PriSense, a novel solution to privacy-preserving data aggregation in people-centric urban sensing systems. PriSense is based on the concept of data slicing and mixing and can support a wide range of statistical additive and non-additive aggregation functions such as Sum, Average, Variance, Count, Max/Min, Median, Histogram, and Percentile with accurate aggregation results. PriSense can support strong user privacy against a tunable threshold number of colluding users and aggregation servers. The efficacy and efficiency of PriSense are confirmed by thorough analytical and simulation results.
Jing Shi 0002, Rui Zhang 0007, Yunzhong Liu
INFOCOM2
2010 Verifiable Fine-Grained Top-k Queries in Tiered Sensor Networks
abstract
Most large-scale sensor networks are expected to follow a two-tier architecture with resource-poor sensor nodes at the lower tier and resource-rich master nodes at the upper tier. Master nodes collect data from sensor nodes and then answer the queries from the network owner on their behalf. In hostile environments, master nodes may be compromised by the adversary and then instructed to return fake and/or incomplete data in response to data queries. Such application-level attacks are more harmful and difficult to detect than blind DoS attacks on network communications, especially when the query results are the basis for making critical decisions such as military actions. This paper presents three schemes whereby the network owner can verify the authenticity and completeness of fine-grained top-k query results in tired sensor networks, which is the first work of its kind. The proposed schemes are built upon symmetric cryptographic primitives and force compromised master nodes to return both authentic and complete top-k query results to avoid being caught. Detailed theoretical and quantitative results confirm the high efficacy and efficiency of the proposed schemes.
Rui Zhang 0007, Jing Shi 0002, Yunzhong Liu
INFOCOM1
2010 Wormhole-Resilient Secure Neighbor Discovery in Underwater Acoustic Networks
abstract
Neighbor discovery is a fundamental requirement and need be done frequently in underwater acoustic networks (UANs) with floating node mobility. In hostile environments, neighbor discovery is vulnerable to the wormhole attack by which the adversary uses secret wormhole links to make distant nodes falsely accept each other as neighbors. The wormhole attack may lead to many undesirable consequences and cannot be solved by cryptographic methods. Existing wormhole defenses for ground wireless networks cannot be directly applied to UANs where most of their assumptions no longer hold. This paper presents a suite of novel protocols to enable wormhole-resilient secure neighbor discovery in UANs. Our protocols are based on the Direction of Arrival (DoA) estimation of acoustic signals, a basic functionality readily available in current UANs. The proposed protocols can thwart the wormhole attack with overwhelming probability without conventional hard requirements on secure and accurate time synchronization and localization. Detailed theoretical analysis and simulation results confirm the high performance of the proposed protocols.
Rui Zhang 0007
INFOCOM1
2010 Traffic Inference in Anonymous MANETs
abstract
The open wireless medium in a mobile ad-hoc network (MANET) enables malicious traffic analysis to dynamically infer the network traffic pattern in hostile environments. The disclosure of the traffic pattern and its changes is often devastating in a mission-critical MANET. A number of anonymous routing protocols have been recently proposed as an effective countermeasure against traffic analysis in MANETs. In this paper, we propose a novel traffic inference algorithm, called TIA, which enables a passive global adversary to accurately infer the traffic pattern in an anonymous MANET without compromising any node. As the first work of its kind, TIA works on existing on-demand anonymous MANET routing protocols. Detailed simulations show that TIA can infer the traffic pattern with an accuracy as high as 95%. Our results in this paper highlight the necessity for cross-layer designs to defend a MANET against traffic analysis.
Yunzhong Liu, Rui Zhang 0007, Jing Shi 0002
SECON2
2009 Secure Range Queries in Tiered Sensor Networks
abstract
We envision a two-tier sensor network which consists of resource-rich master nodes at the upper tier and resource- poor sensor nodes at the lower tier. Master nodes collect data from sensor nodes and answer the queries from the network owner. The reliance on master nodes for data storage and query processing raises concerns about both data confidentiality and query-result correctness in hostile environments. In particular, a compromised master node may leak hosted sensitive data to the adversary; it may also return juggled or incomplete data in response to a query. This paper presents a novel spatiotemporal crosscheck approach to ensure secure range queries in event- driven two-tier sensor networks. It offers data confidentiality by preventing master nodes from reading hosted data and also enables efficient range-query processing. More importantly, it allows the network owner to verify with very high probability whether a query result is authentic and complete by examining the spatial and temporal relationships among the returned data. The high efficacy and efficiency of our approach are confirmed by detailed performance evaluations.
Jing Shi 0002, Rui Zhang 0007
INFOCOM2
2009 DP2AC: Distributed Privacy-Preserving Access Control in Sensor Networks
abstract
The owner and users of a sensor network may be different, which necessitates privacy-preserving access control. On the one hand, the network owner need enforce strict access control so that the sensed data are only accessible to users willing to pay. On the other hand, users wish to protect their respective data access patterns whose disclosure may be used against their interests. This paper presents DP2AC, a Distributed Privacy- Preserving Access Control scheme for sensor networks, which is the first work of its kind. Users in DP2AC purchase tokens from the network owner whereby to query data from sensor nodes which will reply only after validating the tokens. The use of blind signatures in token generation ensures that tokens are publicly verifiable yet unlinkable to user identities, so privacy- preserving access control is achieved. A central component in DP2AC is to prevent malicious users from reusing tokens. We propose a suite of distributed techniques for token-reuse detection (TRD) and thoroughly compare their performance with regard to TRD capability, communication overhead, storage overhead, and attack resilience. The efficacy and efficiency of DP2AC are confirmed by detailed performance evaluations.
Rui Zhang 0007, Kui Ren 0001
INFOCOM1
2009 Secure multidimensional range queries in sensor networks
abstract
Most future large-scale sensor networks are expected to follow a two-tier architecture which consists of resource-rich master nodes at the upper tier and resource-poor sensor nodes at the lower tier. Sensor nodes submit data to nearby master nodes which then answer the queries from the network owner on behalf of sensor nodes. Relying on master nodes for data storage and query processing raises severe concerns about data confidentiality and query-result correctness when the sensor network is deployed in hostile environments. In particular, a compromised master node may leak hosted sensitive data to the adversary; it may also return juggled or incomplete query results to the network owner. This paper, for the first time in the literature, presents a suite of novel schemes to secure multidimensional range queries in tiered sensor networks. The proposed schemes can ensure data confidentiality against master nodes and also enable the network owner to verify with very high probability the authenticity and completeness of any query result by inspecting the spatial and temporal relationships among the returned data. Detailed performance evaluations confirm the high efficacy and efficiency of the proposed schemes.
Rui Zhang 0007, Jing Shi 0002
MobiHoc1