EDBT 2026 Demo / reviewers in the wild / expert
Yang Xu 0013
dblp:61/3906-13
· DBLP profile ↗
49ranked-venue papers
16as first author
40since 2021 · last 2026
0000-0002-3194-8369ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 18 · 6 first-author · 17 since 2021Systems, architecture and hardware · 10 · 3 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 2 first-author · 7 since 2021Security and privacy · 5 · 2 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MSCFL: Model Structure-Aware Clustered Federated Learning for System Heterogeneity and Data DriftabstractFederated Learning (FL) faces significant challenges arising from both data and system heterogeneity. While Clustered Federated Learning (CFL) mitigates data heterogeneity by grouping clients with similar data distributions, it remains vulnerable to system heterogeneity, which can slow convergence due to performance disparities among clients. Moreover, data drift may degrade clustering accuracy and training efficiency over time. In this work, we propose a Model Structure-aware Clustered Federated Learning (MSCFL) framework that simultaneously addresses the issues of data heterogeneity, system heterogeneity, and data drift. MSCFL incorporates model pruning (MP) into the CFL framework to enhance training efficiency under system heterogeneity. To enable this integration, we address the key challenge of performing effective clustering based on heterogeneous, pruned local models with varying structures. To this end, we design a model structure-based similarity computation algorithm to integrate CFL with MP. To effectively address data drift, we propose a dynamic cluster migration strategy that efficiently monitors model structures via Hamming Distance and triggers re-clustering only when necessary. Extensive experimental results show that MSCFL improves the accuracy and convergence speed of cluster models, outperforming traditional CFL in various settings. Yang Xu 0013, Zifeng Xu, Cheng Zhang 0035, Ju Ren 0001, Yaoxue Zhang |
AAAI | 1 |
| 2026 | Physics-Inspired Decomposition for Weak Low-Rank Spatiotemporal Completion in Sparse Crowdsensing
Mijia Zhang, En Wang, Yang Xu 0013, Bo Yang 0002, Jie Wu 0001 |
ICDCS | 5 |
| 2026 | ModelFreeUP: Attacking Sparse Network Monitoring via Model-Free Universal Adversarial PerturbationabstractSparse network monitoring, a breakthrough technology for cost-effective network-wide monitoring, has garnered significant attention from researchers and network equipment providers. By measuring only a subset of paths and nodes, it leverages the network’s low-rank property to obtain comprehensive monitoring data. However, a previously unnoticed vulnerability called the"global diffusion vulnerability"poses a significant threat to sparse network monitoring. This vulnerability suggests that if a few measurement samples are tainted, the entire network monitoring data can become inaccurate, leading to potential network failures and adverse effects on routing and bandwidth allocation. This paper presents the first exploration of the"global diffusion vulnerability"to launch effective attacks on sparse network monitoring. Sparse monitoring often employs various imputation models to estimate unmeasured data and collects multiple perspectives of network-wide data over extended periods. The challenges in attacking sparse monitoring lie in designing perturbations that can impact all views of network-wide data over time, regardless of the specific imputation models, while remaining unobtrusive. To tackle these challenges, we propose ModelFreeUP, the first perturbation generation algorithm designed for sparse network monitoring. ModelFreeUP creates imputation model-free, universal, and unobtrusive perturbations that exert a significant influence on multiple perspectives of network-wide data over time. Our experiments demonstrate that ModelFreeUP effectively disrupts the sparse monitoring process, causing substantial deviations in the network-wide monitoring data at a relatively low attack cost. Furthermore, when the manipulated monitoring data is used for downstream routing tasks, it triggers 100% Maximum Link Utilization in the Abilene network, indicating network congestion or failure. By shedding light on these critical mismeasurement issues, our work emphasizes the need for robust countermeasures against adversarial attacks in the network monitoring domain. Ruotian Xie, Kun Xie 0001, Jiazheng Tian, Jing Wang 0066, Jigang Wen, Yang Xu 0013, Guangxing Zhang, Wei Liang 0005, Gaogang Xie |
IEEE Trans. Netw. | 6 |
| 2026 | Pricing and Trading of Data Options on Data-as-a-Service PlatformsabstractIn current Data-as-a-Service (DaaS) platforms, data marketplaces are the primary mechanism by which data owners deliver data products and services to users. However, data owners incur substantial costs to collect or produce data before selling it, exposing them to economic risks due to market price fluctuations. Options trading, used in traditional commodity markets, can alleviate sellers' financial burdens with forward contracts at fixed option prices and pre-paid option premiums. To our knowledge, the application of option trading in data marketplaces has not been thoroughly studied or implemented. In this work, we advocate for the first data options marketplace on a DaaS platform that mitigates price fluctuation risks and reduces market entry barriers. Designing such a marketplace involves several key challenges, including the easy replication of data and the difficulty in assessing data quality before production. To address these challenges, we first design a data quality prediction method based on sellers' reputation. Following this, we model and quantify the competitive relationships among buyers. On this basis, we model the interactions between sellers and buyers in the data options market as a two-stage Stackelberg game, focusing on maximizing sellers' profit. We formally derive the perfect subgame equilibrium for option trading and derive each seller's optimal pricing strategy. Numerical experiments demonstrate the superiority of data options trading over conventional data trading methods in DaaS platforms. Cheng Zhang 0035, Yang Xu 0013, Runyu Kang, Hangfan Li, Shihao Xiao, Peng Sun 0003 |
IEEE Trans. Serv. Comput. | 2 |
| 2025 | Rethinking Removal Attack and Fingerprinting Defense for Model Intellectual Property Protection: A Frequency PerspectiveabstractTraining deep neural networks is resource-intensive, making it crucial to protect their intellectual property from infringement. However, current model ownership resolution (MOR) methods predominantly address general removal attacks that involve weight modifications, with limited research considering alternative attack perspectives. In this work, we propose a frequency-based model ownership removal attack, grounded in a key observation: modifying a model's high-frequency coefficients does not significantly impact its performance but does alter its weights and decision boundary. This change invalidates the existing MOR methods. We further propose a frequency-based fingerprinting technique as a defense mechanism. By extracting frequency-domain characteristics instead of decision boundary or model weights, our fingerprinting defense effectively against the proposed frequency-based removal attack and demonstrates robustness against existing general removal attacks. The experimental results show that the frequency-based removal attack can easily defeat state-of-the-art white-box watermarking and fingerprinting schemes while preserving model performance, and the proposed defense method is also effective. Our code is released at: https://github.com/huangtingqiao/RRA-IJCAI25. Cheng Zhang 0035, Yang Xu 0013, Tingqiao Huang, Zixing Zhang 0001 |
IJCAI | 2 |
| 2025 | PTalker: Personalized Speech-Driven 3D Talking Head Animation via Style Disentanglement and Modality AlignmentabstractSpeech-driven 3D talking head generation aims to produce lifelike facial animations precisely synchronized with speech. While considerable progress has been made in achieving high lip-synchronization accuracy, existing methods largely overlook the intricate nuances of individual speaking styles, which limits personalization and realism. In this work, we present a novel framework for personalized 3D talking head animation, namely ''PTalker''. This framework preserves speaking style through style disentanglement from audio and facial motion sequences and enhances lip-synchronization accuracy through a three-level alignment mechanism between audio and mesh modalities. Specifically, to effectively disentangle style and content, we design disentanglement constraints that encode driven audio and motion sequences into distinct style and content spaces to enhance speaking style representation. To improve lip-synchronization accuracy, we adopt a modality alignment mechanism incorporating three aspects: spatial alignment using Graph Attention Networks to capture vertex connectivity in the 3D mesh structure, temporal alignment using cross-attention to capture and synchronize temporal dependencies, and feature alignment by top-k bidirectional contrastive losses and KL divergence constraints to ensure consistency between speech and mesh modalities. Extensive qualitative and quantitative experiments on public datasets demonstrate that PTalker effectively generates realistic, stylized 3D talking heads that accurately match identity-specific speaking styles, outperforming state-of-the-art methods. The source code and supplementary videos are available at: PTalker. Yang Xu 0013, Huan Zhao 0003, Hao Zhang 0139, Zixing Zhang 0001 |
ACM Multimedia | 2 |
| 2025 | MingledPie: A Cluster Mingling Approach for Mitigating Preference Profiling in CFL
Cheng Zhang 0035, Yang Xu 0013, Jianghao Tan, Jiajie An, Wenqiang Jin |
NDSS | 2 |
| 2025 | Price-aware resource management for multi-modal DNN inference in collaborative heterogeneous edge environments
Wenhua Wang 0003, Jianxiong Guo, Wentao Fan 0001, Yang Xu 0013, Tian Wang 0001, Jiannong Cao 0001 |
J. Parallel Distributed Comput. | 5 |
| 2025 | Heterogeneous Device Collaboration Based Federated Learning for Big Data ApplicationsabstractIn the era of Big Data, artificial intelligence and information science are the key technologies to extract the value of data and enhance the competitiveness of enterprises. The characteristics of distributed, small-scale, and sparse lead to the isolated data island problem. To solve these problems, Federated Learning is proposed. However, a large number of terminal models need to be uploaded to the server in Federated Learning, especially for the actual scenario of Internet of Things. Therefore, huge communication costs are required which dramatically increases the pressure on the backbone network. Furthermore, the low quality of the local model will lead to decreased accuracy and convergence rates of the model. To overcome the above limitations, we propose heterogeneous device collaboration based federated learning (HDCFL), which constructs a three-layer structure for Federated Learning by leveraging edge computing and designs a heterogeneous device collaboration method that groups the terminals based on their computing power, communication time, and data volume to train the model. Then, we conduct a theoretical analysis of the proposed algorithm which verifies its advantage. At last, the experimental result demonstrates that the proposed algorithm consistently achieves superior performance in terms of both convergence speed and accuracy compared with state-of-the-art baselines. Wenhua Wang 0003, Quan Yang, Yuzhu Liang, Yang Xu 0013, Qin Liu 0001, Tian Wang 0001 |
IEEE Trans. Big Data | 4 |
| 2025 | SRVC: Highly Compatible Bidirectional Self-Regulatory Virtual ChannelabstractThe Payment Channel Network (PCN) provides an off-chain payment model to alleviate the problem of limited blockchain throughput. However, PCNs typically rely on third-party regulators to monitor the blockchain states continuously to prevent honest users’ funds from being lost, which increases user overhead and compromises transaction privacy. To overcome these challenges, we propose a highly compatible bidirectional Self-Regulatory Virtual Channel (SRVC) that eliminates third-party reliance while enhancing privacy and reducing overhead. By leveraging absolute time locks, we establish a self-regulatory mechanism where users only need to monitor the blockchain online for a short time window to ensure the security of their funds, effectively removing the need for third-party monitoring. Additionally, we introduce a novel payment paradigm and a punishment mechanism based on adaptor signatures across underlying channels to ensure transaction privacy and security, while also reducing transaction overhead. We formalize the security properties of SRVC as an ideal functionality and prove that SRVC is secure in the Universal Composability framework. Performance analysis demonstrates that, compared to other virtual channel protocols based on Lightning channels, SRVC reduces communication overhead by approximately 46.8% in the open operation and 62.9% in the update operation. In high-concurrency payment scenarios, SRVC further decreases communication overhead by about 57.8% and reduces the number of transactions by around 52.8% compared to Sleepy Channel’s Virtual Channel (SCVC) implementation. Yang Xu 0013, Yaqin Liu, Songyou Xie, Yu Long 0001, Wei Liang 0005, Yaoxue Zhang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Blockchain-Enabled Multiple Sensitive Task-Offloading Mechanism for MEC ApplicationsabstractAs mobile devices proliferate and mobile applications diversify, Mobile Edge Computing (MEC) has become widely adopted to efficiently allocate computing resources at the network edge and alleviate network congestion. In the MEC initial phase, the absence of vital information presents challenges in devising task-offloading policies, and identifying malicious devices responsible for providing inaccurate feedback is complex. To fill in such gaps, we introduce a consortium blockchain-enabledCommitteeVoting basedTaskOffloadingModel (CVTOM) to collaboratively formulate resource allocation policies and establish deterrence against malicious servers producing erroneous results intentionally. Different voting principle mechanisms of each committee member are first designed in a Blockchain-enabled system which helps to represent the system's resource status. Additionally, we propose a Multi-armed Bandits relatedThompsonSampling basedAdaptivePreferenceOptimization (TSAPO) algorithm for task-offloading policy, enhancing the timely identification of potent edge servers to improve computing resource utilization which first considers dynamic edge server space and parallel computing scenarios. The solid proof process greatly contributes to the theoretical analysis of the TSAPO. The simulation experiments demonstrate the delay and budget can be reduced by around 25% and 10% respectively, showcasing the superior performance of our approach. Yang Xu 0013, Hangfan Li, Cheng Zhang 0035, Zhiqing Tang, Xiaoxiong Zhong, Ju Ren 0001, Hongbo Jiang 0001, Yaoxue Zhang |
IEEE Trans. Mob. Comput. | 1 |
| 2025 | Towards Privacy-Enhanced and Robust Clustered Federated LearningabstractClustered federated learning (CFL) leverages data distribution similarities to cluster clients, facilitating personalized model training under data heterogeneity. However, most existing CFL schemes pose potential privacy risks for clients (e.g., gradient inversion attacks) as they rely on individual gradients for clustering. This also renders them incompatible with secure aggregation mechanisms that are widely employed in federated learning for privacy protection. Moreover, CFL introduces the risk of malicious clients dominating several clusters and conducting poisoning attacks therein, thereby threatening secure model training. To address these issues, we propose ProCFL, a Privacy-Enhanced and Robust CFL framework incorporating gradient-free clustering and peer validation. Specifically, we first design a new protocol for measuring data distribution similarity among clients without using their gradient information. Then, we transform the client clustering process into a weighted set covering problem and introduce a diversity-optimized clustering algorithm to achieve near-optimal clustering results while eliminating any need for prior knowledge. Furthermore, we develop a post-hoc detection mechanism that employs peer validation to identify and discard malicious client models. Extensive experimental evaluation of ProCFL validates its superior model robustness and accuracy performance compared to existing schemes. Yang Xu 0013, Yunlin Tan, Cheng Zhang 0035, Peng Sun 0003, Yibang Zhang, Ju Ren 0001, Hongbo Jiang 0001, Yaoxue Zhang |
IEEE Trans. Mob. Comput. | 1 |
| 2025 | Collaborative Edge and Cloud Computing: Optimal Configuration and Computation ManagementabstractMobile Edge Computing (MEC) plays an increasingly important role in the rapidly increasing mobile applications by providing high-quality computing services. The majority of current research has focused on designing efficient computing task offloading schemes to ensure the effectiveness of the MEC system. However, the configuration and resource management of the MEC system, which are crucial for its scattered feature, have not received due attention. This paper investigates the configuration and computation resource management problem for the MEC system by formulating a profit maximization problem. To address this problem, we first analyze the relationship among mobile users' offloading decisions, the configuration and computation management of the MEC system, and the service quality. Then, we design an optimal configuration and computation management scheme of the MEC system, which can not only maintain the efficiency of computing processes but also make a good trade-off between the profitability and the service quality. In such a way, the total expected profit of the MEC system can be maximized. Numerical evaluations show that the proposed optimal configuration and computation management scheme can efficiently improve the total profit of the MEC system. Yongmin Zhang, Wei Wang 0343, Junfan Zhou, Yang Xu 0013, Ju Ren 0001, Yaoxue Zhang |
IEEE Trans. Mob. Comput. | 5 |
| 2024 | ORL-EPM: A Profit-Aware and Load-Driven Heterogeneous Resource Management Scheme with Collaborative Edge Computing
Wenhua Wang 0003, Jianxiong Guo, Yang Xu 0013, Wentao Fan 0001, Tian Wang 0001 |
ICA3PP (3) | 5 |
| 2024 | Few-Shot Data Completion for New Tasks in Sparse CrowdsensingabstractMobile Crowdsensing is a type of technology that utilizes mobile devices and volunteers to gather data about specific topics at large scales in real-time. However, in practice, limited participation leads to missing data, i.e., the collected data may be sparse, which makes it difficult to perform accurate analysis. A possible technique called sparse crowdsensing incorporates the sparse case with data completion, where unsensed data could be estimated through inference. However, sparse crowdsensing typically suffers from poor performance during the data completion stage due to various challenges: the sparsity of the sensed data, reliance on numerous timeslots, and uncertain spatiotemporal connections. To resolve such few-shot issues, the proposed solution uses the Correlated Data Fusion for Matrix Completion (CDFMC) approach, which leverages a small amount of objective data to retrain an auxiliary dataset-based pre-trained model that can estimate unsensed data efficiently. CDFMC is trained using a combination of the traditional Deep Matrix Factorization and the Kalman Filtering, which not only enables the efficient representation and comparison of data samples but also fuses the objective data and auxiliary data effectively. Evaluation results show that the proposed CDFMC outperforms baseline techniques, achieving high accuracy in completing unsensed data with minimal training data. En Wang, Mijia Zhang, Bo Yang 0002, Yang Xu 0013, Zixuan Song, Yongjian Yang 0001 |
INFOCOM | 4 |
| 2024 | A Semi-Asynchronous Decentralized Federated Learning Framework via Tree-Graph BlockchainabstractDecentralized federated learning (DFL) overcomes the single point of failure issue of centralized federated learning. Building upon DFL, blockchain-based federated learning (BFL) takes further strides in establishing trust, enhancing security, and fault tolerance. However, BFL based on the classical linear blockchain exhibits diminished training efficiency in heterogeneous environments and is limited by the performance bottleneck of blockchain. Recent solutions introduce the directed acyclic graph (DAG) blockchain to address these issues, yet they compromise the verifiability of BFL, struggle with handling outdated models, and have a slow convergence speed. In this paper, we propose TGFL, a decentralized federated learning framework based on the Tree-Graph blockchain. The underlying blockchain structure of TGFL is designed as a block-centered DAG to support verifiable and semi-asynchronous training. To facilitate fast convergence, we design a pivot chain generation algorithm that topologically sorts the semi-asynchronous training process, guiding participants in sampling appropriate models. The consensus mechanism, which is closely integrated with federated learning, ensures that the TGFL can effectively resist attacks on the model and the blockchain system. Extensive experiments in various settings demonstrate that TGFL can achieve better training efficiency and model accuracy compared to three baselines. Cheng Zhang 0035, Yang Xu 0013, En Wang, Hongbo Jiang 0001, Yaoxue Zhang |
INFOCOM | 2 |
| 2024 | A Domain Embedding Model for Botnet Detection Based on Smart BlockchainabstractThe use of smart contracts enhances the capabilities of blockchain-based botnets, allowing for greater information capacity, richer application scenarios, and the deployment of program functions directly on the blockchain. However, smart blockchains offer a better solution for the intelligence of IoT systems, but they also come with some security risks. Botnet is a highly insecure community because it is used to do hazardous things like Distributed Denial of Service (DDoS). It is extremely essential to detect botnets with some useful tools, such as artificial intelligence (AI) algorithms, because these algorithms can assist us to monitor the network automatically. We need to pay the utmost attention to some feature engineering work, as recognition rates of AI models are considerably improved with suitable features. In this article, we propose domain embedding (DE) models to generate low-dimensional features for domains with unsupervised learning algorithms. We also explore some key parameters of the DE model to obtain decent effects on domain features. A modified version of the$k$-means algorithm called extended$k$-means, is used to cluster these domains in certain hubs and botnets that can be found for smart blockchain-based IoT systems. In the experiments, some domain correlation scores can be computed during the DE model, and similar domains have higher correlation scores. Xiaodan Yan, Yang Xu 0013, Shuang Yao |
IEEE Internet Things J. | 2 |
| 2024 | Enhancing privacy in cyber-physical systems: An efficient blockchain-assisted data-sharing scheme with deniability
Yang Xu 0013, Ziyu Peng, Cheng Zhang 0035, Gaocai Wang, Hongbo Jiang 0001, Yaoxue Zhang |
J. Syst. Archit. | 1 |
| 2024 | HPDK: A Hybrid PM-DRAM Key-Value Store for High I/O ThroughputabstractThis paper explores the design of an architecture that replaces Disk with Persistent Memory (PM) to achieve the highest I/O throughput in Log-Structured Merge Tree (LSM-Tree) based key-value stores (KVS). Most existing LSM-Tree based KVSs use PM as an intermediate or smoothing layer, which fails to fully exploit PM’s unique advantages to maximize I/O throughput. However, due to PM’s distinct characteristics, such as byte addressability and short erasure time, simply replacing existing storage with PM does not yield optimal I/O performance. Furthermore, LSM-Tree based KVSs often face slow read performance. To tackle these challenges, this paper presents HPDK, a hybrid PM-DRAM KVS that combines level compression for LSM-Trees in PM with a B+-tree based in-memory search index in DRAM, resulting in high write and read throughput. HPDK also employs a key-value separation design and a live-item rate-based dynamic merge method to reduce the volume of PM writes. We implement and evaluate HPDK using a real PM drive, and our extensive experiments show that HPDK provides 1.25-11.8 and 1.47-36.4 times higher read and write throughput, respectively, compared to other state-of-the-art LSM-Tree based approaches. Bihui Liu, Zhenyu Ye, Qiao Hu 0005, Yupeng Hu 0004, Yuchong Hu, Yang Xu 0013, Keqin Li 0001 |
IEEE Trans. Computers | 6 |
| 2024 | Protecting Inference Privacy With Accuracy Improvement in Mobile-Cloud Deep LearningabstractWith the wide spread of data-driven deep learning applications, a growing number of users outsource compute-intensive inference processes to the cloud. To protect inference privacy, Liu (INFOCOM 2022) proposed two steganography-based solutions, named GHOST and GHOST+, relying on the mobile-cloud collaborative framework, where the mobile device hides sensitive images into public cover images before feature extraction, while launching adversarial attacks on the cloud-side deep neural network (DNN) to obtain desired results. Although both solutions demonstrate significant advantages in private deep learning, they suffer from limited practicality; since the inference accuracy decreases sharply as the hiding ratio increases. To address this, we propose two improved solutions, IGHO and IGHO+, which ensure high inference accuracy even when abundant sensitive images need to be hidden. Specifically, IGHO as the improved version of GHOST proposes two feature fusion methods, feature synthesis and pixel synthesis, to preprocess cover images, making the poisoned DNN learn hidden sensitive features better, while IGHO+as the improved version of GHOST+designs a novel feature mining generative adversarial network (FMGAN) to craft adversarial perturbations highly robust against variable sensitive types. Experimental results show that the proposed solutions highly improve the practicality of GHOST and GHOST+. Shulan Wang, Qin Liu 0001, Yang Xu 0013, Hongbo Jiang 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | Amount-Based Covert Communication Over BlockchainabstractRecent years have witnessed the booming growth of 5G and 6G technology, which has brought unprecedented massive data transmission, causing severe privacy issues. However, traditional information encryption and multimedia covert communication fail to protect the identities of communication parties and the originality of messages. The emergence of blockchain provides a promising solution to solve these problems. Its anonymity manages to hide the identities of communication parties, and immutability ensures the message is undestroyable. However, the existing blockchain-based covert communication schemes suffer the issues of low embedding capacity and high time cost. In this paper, an amount-based covert communication scheme over the blockchain is proposed, in which a unique coding method is devised for hiding messages into transaction amounts to improve the embedding capacity. Compared with existing address-based methods, the proposed scheme can apply any address and reduce the time of obtaining special addresses. Besides, we innovate the way to prove the concealment by calculating the relative entropy of the transaction amount between Bitcoin and the proposed scheme. The security of our method is demonstrated by comparing the probability of attackers acquiring secret messages under different adversary capabilities. The experimental results verify that the proposed approach outperforms the existing schemes regarding embedding capacity, time costs, number of transactions, concealment, and security. Yang Tian 0004, Xin Liao 0001, Li Dong 0006, Yang Xu 0013, Hongbo Jiang 0001 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2024 | Redactable Blockchain-Based Secure and Accountable Data ManagementabstractBlockchain provides trustworthy properties such as decentralization, traceability, and transparency, and has been applied in various fields. Given the complexity of guaranteeing the accuracy of the input data, erroneous data may be stored on the blockchain, making it hard to modify. As an effective solution, redactable blockchain allows on-chain data to be modified by introducing a chameleon hash function with a trapdoor, which enables on-chain erroneous data to be corrected. However, existing redactable blockchain solutions often require trusted third parties, have huge overhead, or lack effective accountability mechanisms to meet data security needs. Therefore, this paper proposes a secure, efficient and accountable data management scheme based on redactable blockchain. To cope with the possible frequent editing needs, we design an efficient and accountable distributed trapdoor recovery mechanism that reliably maintains data security while avoiding the security risks associated with centralized management. Various information during the trapdoor management process is also recorded on the chain as the basis for implementing accountability mechanisms. In addition, the one-time trapdoor technology allows the blockchain system to reduce the maintenance complexity of the system by eliminating the need to frequently update the system parameters when partial trapdoor information needs to be published. Theoretical and experimental results show that our scheme can achieve an efficient accountability mechanism while modifying the data on the chain at low cost. Yang Xu 0013, Shihao Xiao, Cheng Zhang 0035, Zhifei Ni, Guojun Wang 0001 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2024 | Improving completeness and consistency of co-reference annotation standard
Yang Xu 0013, Fadi Farha, Yueliang Wan, Jiabo Xu, Hong Liu 0006, Huansheng Ning |
Wirel. Networks | 1 |
| 2023 | EKDF: An Ensemble Knowledge Distillation Framework for Robust Collaborative Inference on Heterogeneous Edge DevicesabstractThe integration of edge computing and deep neural networks (DNNs) holds great promise for enhancing application intelligence. Edge devices generate or collect vast amounts of data, which DNNs can leverage to make informed decisions. Nevertheless, the limited resources of edge devices pose a significant challenge for deploying DNNs. To accommodate some edge devices (e.g. smart watches), lightweight models are often required. However, the accuracy of these models may not meet user expectations. In this paper, we present EKDF, an ensemble knowledge distillation framework that crafts lightweight models for collaborative DNN inferences. More specifically, we utilize knowledge distillation to compress DNN models. On this basis, we introduce multi-teacher joint supervision and dropout in knowledge distillation to improve model performance and preserve the diversity between the generated DNN models. This process produces a range of compact models of varying computational complexity for different edge devices. The experimental results demonstrate that our proposed EKDF can greatly improve the overall predictive ability. Shangrui Wu, Yupeng Li 0001, Yang Xu 0013, Qin Liu 0001, Weijia Jia 0001, Tian Wang 0001 |
MSN | 3 |
| 2023 | A Blockchain-Based Model Migration Approach for Secure and Sustainable Federated Learning in IoT SystemsabstractModel migration can accelerate model convergence during federated learning on the Internet of Things (IoT) devices and reduce training costs by transferring feature extractors from fast to slow devices, which, in turn, enables sustainable computing. However, malicious or lazy devices may migrate the fake models or resist sharing models for their benefit, reducing the desired efficiency and reliability of a federated learning system. To this end, this work presents a blockchain-based model migration approach for resource-constrained IoT systems. The proposed approach aims to achieve secure model migration and speed up model training while minimizing computation cost. We first develop an incentive mechanism considering the economic benefits of fast devices, which breaks the Nash equilibrium established by lazy devices and encourages capable devices to train and share models. Second, we design a clustering-based algorithm for identifying malicious devices and preventing them from defrauding incentives. Third, we use blockchain to ensure trustworthiness in model migration and incentive processes. Blockchain records the interaction between the central server and IoT devices and runs the incentive algorithm without exposing the devices’ private data. Theoretical analysis and experimental results show that the proposed approach can accelerate federated learning rates, reduce model training computation costs to increase sustainability, and resist malicious attacks. Cheng Zhang 0035, Yang Xu 0013, Haroon Elahi, Yunlin Tan, Junxian Chen, Yaoxue Zhang |
IEEE Internet Things J. | 2 |
| 2023 | A decentralized trust management mechanism for crowdfunding
Yang Xu 0013, Quanlin Li, Cheng Zhang 0035, Yunlin Tan, Guojun Wang 0001, Yaoxue Zhang |
Inf. Sci. | 1 |
| 2023 | C-FDRL: Context-Aware Privacy-Preserving Offloading Through Federated Deep Reinforcement Learning in Cloud-Enabled IoTabstractRecently, artificial intelligence approaches are widely suggested to optimize numerous offloading task-scheduling purposes. However, they confront difficulties in maintaining data privacy regarding the context of the data offloading during the course of offloading in the different stages. To address this problem, in this article we proposeC-fDRL, a framework to provide context-aware federated deep reinforcement learning (fDRL) to maintain the context-aware privacy of the task offloading. We perform this in three stages (CloudAI, EdgeAI, and DeviceAI) of the overall system.C-fDRLchecks whether the privacy of high-context-aware data with the task being offloaded is maintained locally at the DeviceAI, and low-context-aware data distributedly at the EdgeAI. When there is an offloading task request or a user needs to offload the data,C-fDRLuses a context-aware data management approach to decouple the context-aware (privacy) data from the tasks. This separates the context-aware data from the task for local computation and allows a new scheduling technique called “context-aware multilevel scheduler.” This places high-context-aware data on local devices and low-context-aware data at the edge device for computation before the actual task execution. We performed experiments to evaluate the data privacy with the offloading tasks and the federated DRL. The results show that the proposedC-fDRLperforms better than the existing framework. Yang Xu 0013, Md. Zakirul Alam Bhuiyan, Tian Wang 0001, Xiaokang Zhou, Amit Kumar Singh 0001 |
IEEE Trans. Ind. Informatics | 1 |
| 2023 | TRUCON: Blockchain-Based Trusted Data Sharing With Congestion Control in Internet of VehiclesabstractThe Internet of vehicles (IoV) has a substantial impact on traffic efficiency improvement and accidents avoidance. Due to restricted resources, vehicles must share observed data with RSUs and other vehicles to execute some time-tolerant computing tasks. However, data provided by vehicles cannot always be trusted due to the presence of attackers. Fake messages could have catastrophic ramifications, such as vehicle collisions. Furthermore, extensive data sharing might cause channel congestion, resulting in the loss of vital messages during delivery. To overcome the aforementioned issues, we propose TRUCON, a blockchain-based trusted data sharing mechanism with congestion control in IoV. Firstly, we propose a Kademlia algorithm-based traffic data forwarding method to control channel congestion state. By adjusting the bucket size and distance threshold, source vehicles can limit the number of reference vehicles forwarded. Secondly, we present a cuckoo filter-based traffic data deduplication and discrimination approach. To avoid repetitive sharing, vehicles and RSUs can check their local filters to verify if the current data report has been shared. Based on the foregoing, we propose a blockchain-based trust management mechanism with congestion control. RSUs serve as full nodes while vehicles are light nodes in the blockchain. Finally, we develop a trust management prototype system with congestion control that incorporates both on-chain and off-chain parts. It signifies that our scheme is both feasible and effective. Mingyang Yuan, Yang Xu 0013, Cheng Zhang 0035, Yunlin Tan, Yichuan Wang 0003, Ju Ren 0001, Yaoxue Zhang |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2022 | TrustBuilder: A non-repudiation scheme for IoT cloud applications
Fei Chen 0003, Jianqiang Li 0001, Yang Xu 0013, Cheng Zhang 0035, Tao Xiang 0001 |
Comput. Secur. | 4 |
| 2022 | Deep Neural Network Security Collaborative Filtering Scheme for Service Recommendation in Intelligent Cyber-Physical SystemsabstractCyber–physical systems (CPSs) is a security real-time embedded system. CPS integrates the information sensed by the current physical sensors, through high-speed real-time transmission, and then carries out powerful information processing to effectively interact and integrate the physical and the information worlds. With the aim to improve the quality of service, optimize the existing physical space, and increase security, collaborative filtering algorithms have also been widely used in various recommendation models for Internet of Things (IoT) services. However, general collaborative filtering algorithms cannot capture complex interactive information in the sparse Mashup–Web service call matrix, which leads to lower recommendation performance. Based on the artificial intelligence technology, this study proposes a recommendation algorithm for a security collaborative filtering service that integrates content similarity. A security collaborative filtering module is used to capture the complex interaction information between Mashup and Web services. By applying the content similarity module to extract the semantic similarity information between the Mashup and Web services, the two modules are seamlessly integrated into a deep neural network to accurately and quickly predict the rating information of Mashup for the Web services. Real data set on the intelligent CPS is captured and then compared with mainstream service recommendation algorithms. Experimental results show that the proposed algorithm not only efficiently completes the Web service recommendation task under the premise of sparse data but also shows better accuracy, effectivity, and privacy. Thus, the proposed method is highly suitable for the application of intelligence CPS. Wei Liang 0005, Songyou Xie, Jiahong Cai, Jianbo Xu, Yupeng Hu 0004, Yang Xu 0013, Meikang Qiu |
IEEE Internet Things J. | 6 |
| 2022 | Blockchain-Based Trustworthy Energy Dispatching Approach for High Renewable Energy Penetrated Power SystemsabstractRenewable energy sources (RES) and low-carbon technology users play a vital role in modern power systems. However, RES generation is easily affected by the environment. Meanwhile, the load, such as electric vehicles (EVs) and prosumers, accounts for most low-carbon technology users. Their power is usually superimposed on peak loads without dispatching, which also exacerbates the instability of the power system. Current optimal dispatching mechanisms mainly rely on centralized organizations, while their dispatching process is not open and transparent. In this article, we propose a blockchain-based trustworthy dispatching approach for the distribution network in high renewable energy penetrated power systems. We first develop an optimal dispatching model considering EVs’ charging behavior and the prosumers’ economic benefits. With the model, prosumers can be dispatched to balance power and consume renewable energy, reducing the impact of disorderly charging on the grid and the abandonment of RES generation. An orderly charging iteration optimization (OCIO) algorithm is proposed to implement orderly EV charging while considering the charging cost and the period. We also propose a modified particle swarm optimization (mPSO) algorithm to publish dispatching tasks based on real-time power balance. Furthermore, blockchain is applied as an open and transparent ledger to record each entity’s power generation and consumption information, ensuring that the dispatching process is trustworthy. Finally, the effectiveness of the dispatching approach is verified in the modified IEEE 33-bus test system and Ethereum-based smart contracts. Yang Xu 0013, Cheng Zhang 0035, Ju Ren 0001, Yaoxue Zhang, Xuemin Shen |
IEEE Internet Things J. | 1 |
| 2022 | AntiConcealer: Reliable Detection of Adversary Concealed Behaviors in EdgeAI-Assisted IoTabstractInternet of Things (IoT) is one of the rapidly developing technologies today that attract huge real-world applications. However, the reality is that IoT is easily vulnerable to numerous types of cyberattacks and anomalies. Detecting them is becoming increasingly challenging day by day due to limitations with IoT devices and threat intelligence. Particularly, one of the most challenging problems is to detect the existence of malicious adversaries that continuously adapt or conceal their behaviors in IoT to hide their actions and to make the IoT security protocol ineffective. In this article, we study this problem at the IoT device level that can be a great idea to avoid potential attacks. We presentAntiConcealer, an edge-aided IoT framework, and propose an edge artificial intelligence-enabled approach (EdgeAI) for detecting adversary concealed behaviors in the IoT. We first develop an adversary behavior model and use this to identify mid-attack temporal patterns by learning the multivariate Hawkes process (MHP), a kind of point process as a random and finite series of events (e.g., behaviors) controlled by a probabilistic model. Naturally, learning MHP processed on EdgeAI reveals the influence of the concealed behaviors of adversaries in the IoT. These concealed behaviors are then grouped using a nonnegative weighted influence matrix. To observe the performance of theAntiConcealerframework through evaluation, we employ honeypots integrated with edge servers and verify the usability and reliability of adversary behavioral identification. Jiwei Zhang 0007, Md. Zakirul Alam Bhuiyan, Yang Xu 0013, Tian Wang 0001, Xuesong Xu, Thaier Hayajneh, Faiza Khan |
IEEE Internet Things J. | 3 |
| 2022 | Quantitative understanding serial-parallel hybrid sfc services: a dependability perspective
Jing Bai 0009, Xiaolin Chang, Fumio Machida, Zhen Han 0001, Yang Xu 0013, Kishor S. Trivedi |
Peer-to-Peer Netw. Appl. | 5 |
| 2022 | A Blockchain-Based Multi-Cloud Storage Data Auditing Scheme to Locate FaultsabstractNetwork storage services have benefited countless users worldwide due to the notable features of convenience, economy and high availability. Since a single service provider is not always reliable enough, more complex multi-cloud storage systems are developed for mitigating the data corruption risk. While a data auditing scheme is still needed in multi-cloud storage to help users confirm the integrity of their outsourced data. Unfortunately, most of the corresponding schemes rely on trusted institutions such as the centralized third-party auditor (TPA) and the cloud service organizer, and it is difficult to identify malicious service providers after service disputes. Therefore, we present a blockchain-based multi-cloud storage data auditing scheme to protect data integrity and accurately arbitrate service disputes. We not only introduce the blockchain to record the interactions among users, service providers, and organizers in data auditing process as evidence, but also employ the smart contract to detect service dispute, so as to enforce the untrusted organizer to honestly identify malicious service providers. We also use the blockchain network and homomorphic verifiable tags to achieve the low-cost batch verification without TPA. Theoretical analyses and experiments reveal that the scheme is effective in multi-cloud environments and the cost is acceptable. Cheng Zhang 0035, Yang Xu 0013, Yupeng Hu 0004, Jiajing Wu, Ju Ren 0001, Yaoxue Zhang |
IEEE Trans. Cloud Comput. | 2 |
| 2022 | Zeroing Neural Networks for Dynamic Quaternion-Valued Matrix InversionabstractThis article, for the first time, extends the zeroing neural network (ZNN) method to address the problem of dynamic quaternion-valued matrix inversion. Due to the noncommutative property of quaternion multiplication, the complex representation method is first adopted to transform quaternion-valued matrices into the corresponding complex-valued matrices. Then, based on two kinds of ways to deal with nonlinear activation functions in the complex-valued domain, this article proposes two quaternion-valued ZNN (QVZNN) models for dynamic quaternion-valued matrix inversion. In addition, a novel nonlinear activation function is given to accelerate the convergence rate of the models to reach the predefined-time convergence. The detailed theoretical analysis, together with four theorems, are given to show the excellent properties of the QVZNN models. Furthermore, the upper bound of the convergence time is derived analytically with the residual error being zero theoretically. Finally, two numerical examples are provided to verify the theoretical results and the effectiveness of the QVZNN models for the dynamic quaternion-valued matrix inversion, and an application to mobile manipulator control is provided to indicate the practical application value of the QVZNN models. Lin Xiao 0002, Sai Liu, Xin Wang 0028, Yongjun He 0001, Lei Jia 0001, Yang Xu 0013 |
IEEE Trans. Ind. Informatics | 6 |
| 2022 | Trustworthy Target Tracking With Collaborative Deep Reinforcement Learning in EdgeAI-Aided IoTabstractMobile target tracking with artificial intelligence (AI) approaches such as deep reinforcement learning (DRL) in edge-assisted Internet of Things (Edge-IoT) platform can be promising. In this article, we proposeDRLTrack, a framework for target tracking with a collaborative DRL called C-DRL in Edge-IoT with the aim to obtain two major objectives: high quality of tracking (QoT) and resource-efficient network performance. InDRLTrack, a huge number of IoT devices are employed to collect data about a target of interest. One or two edge devices in the network coordinate with a group of IoT devices and collaboratively detect the target by using the C-DRL approach and form an area around the target by the group of IoT devices. To maintain such an area during the tracking time, we employ a deep Q-network to track the target from one group to another. An EdgeAI sitting on the top of the edge devices has the control of the C-DRL approach during tracking and can identify a sequence of tracks.DRLTrackis said to betrustworthyas it shows trustworthy performance in terms of QoT, dynamic environments, and even under certain cyberattacks. We validate the performance ofDRLTrackconsidering the objectives through simulations and it demonstrates superior performance compared with existing work. Jiwei Zhang 0007, Md. Zakirul Alam Bhuiyan, Yang Xu 0013, Amit Kumar Singh 0001, D. Frank Hsu |
IEEE Trans. Ind. Informatics | 3 |
| 2021 | Revocable Data Sharing Methodology Based on SGX and Blockchain
Liang Zhang 0043, Haibin Kan, Yang Xu 0013, Jinhao Ran |
NSS | 3 |
| 2021 | A trustworthy industrial data management scheme based on redactable blockchain
Cheng Zhang 0035, Zhifei Ni, Yang Xu 0013, Linweiya Chen, Yaoxue Zhang |
J. Parallel Distributed Comput. | 3 |
| 2021 | A Method of Information Protection for Collaborative Deep Learning under GAN Model AttackabstractDeep learning is widely used in the medical field owing to its high accuracy in medical image classification and biological applications. However, under collaborative deep learning, there is a serious risk of information leakage based on the deep convolutional generation against the network's privacy protection method. Moreover, the risk of such information leakage is greater in the medical field. This paper proposes a deep convolution generative adversarial networks (DCGAN) based privacy protection method to protect the information of collaborative deep learning training and enhance its stability. The proposed method adopts encrypted transmission in the process of deep network parameter transmission. By setting the buried point to detect a generative adversarial network (GAN) attack in the network and adjusting the training parameters, training based on the GAN model attack is forced to be invalid, and the information is effectively protected. Xiaodan Yan, Baojiang Cui, Yang Xu 0013, Peilin Shi |
IEEE ACM Trans. Comput. Biol. Bioinform. | 3 |
| 2021 | A Unified Predefined-Time Convergent and Robust ZNN Model for Constrained Quadratic ProgrammingabstractA variety of realistic industrial problems can be constructed into quadratic programming (QP) problems, especially their time-varying versions. A zeroing neural network (ZNN) as a good approach for dynamic problems can solve QP problems subject to equality constraints in the past. In this article, we propose a unified predefined-time convergent and robust ZNN (PTCR-ZNN) model for solving time-varying QP problems subject to equality or inequality constraints. Compared with the normal ZNN model, the PTCR-ZNN model mainly has advantages in the following three aspects: 1) solving QP problems with or without inequality constraints in a unified model; 2) converging to the optimal solution of QP problems within a predefined time that can be determined in advance; and 3) resisting many external noises with tiny and predictable residual error. These improvements have been rigorously proved in theory. By conducting both qualitative and quantitative simulations with comparisons, the superior properties of the PTCR-ZNN model are further validated. Finally, the application of the PTCR-ZNN model to image fusion task illustrates the efficiency together with its applicability. Zeshan Hu, Lin Xiao 0002, Jianhua Dai 0003, Yang Xu 0013, Qiuyue Zuo, Chubo Liu |
IEEE Trans. Ind. Informatics | 4 |
| 2020 | An efficient privacy-enhanced attribute-based access control mechanismabstractSummary Owing to the rapid progress of network researching, attribute‐based access control (ABAC) has attracted more and more attention due to its appreciable expressiveness, flexibility, and scalability. Unfortunately, collecting user attributes is necessary to complete the standard ABAC decision process, which increases the risk of privacy disclosure. This problem increases public doubts about ABAC and hinders its popularization. In this paper, a privacy‐protected and efficient attribute‐based access control (EPABAC) scheme is proposed to prevent the privacy leakage of access subject in the decision‐making process of ABAC by introducing a novel hash‐based binary search tree. The analyses and experimental evaluations show that the EPABAC achieves user privacy protection in the decision‐making process with acceptable additional computing overhead. Yang Xu 0013, Quanrun Zeng, Guojun Wang 0001, Cheng Zhang 0035, Ju Ren 0001, Yaoxue Zhang |
Concurr. Comput. Pract. Exp. | 1 |
| 2020 | Learning URL Embedding for Malicious Website DetectionabstractThe emergence of artificial intelligence technology has promoted the development of the Internet of Things. However, this promising cyber technology can encounter serious security problems while accessing the internet. A malicious website can disguise itself as a normal website, and obtain users' private information. Thus, it is very important to detect malicious websites using tools such as machine learning (ML) algorithms, as these algorithms can help us to identify abnormal information hidden in the mass traffic more easily. Accordingly, many feature engineering tasks must be performed from memory, as a strong machine learning model is greatly improved with good features. In this article, we propose an unsupervised learning algorithm that learns URL embedding. We also explore some key parameters regarding a domain embedding model to obtain a good effect on domain features. Xiaodan Yan, Yang Xu 0013, Baojiang Cui, Taibiao Guo, Chaoliang Li |
IEEE Trans. Ind. Informatics | 2 |
| 2020 | Trustworthy Network Anomaly Detection Based on an Adaptive Learning Rate and Momentum in IIoTabstractWhile the industrial Internet of Things (IIoT) brings convenience to the industry, it also brings security problems. Due to the massive amount of data generated by the surge of IIoT devices, it is impossible to ensure whether these data contain an attack or untrustworthy data, therefore, how to ensure the security and trustworthiness of IIoT devices has become an urgent problem to solve. In this article, we design a new hinge classification algorithm based on mini-batch gradient descent with an adaptive learning rate and momentum (HCA-MBGDALRM) to minimize the effects of security attacks. The algorithm significantly improves the performance of deep network training compared with traditional neural networks, decision trees and logistic regression in terms of scale and speed. In addition, we have solved the data skew problem in the shuffle phase, and we implement a parallel framework for HCA-MBGDALRM to accelerate the processing speed of very large traffic data sets. Xiaodan Yan, Yang Xu 0013, Xiaofei Xing, Baojiang Cui, Taibiao Guo |
IEEE Trans. Ind. Informatics | 2 |
| 2020 | Blockchain Empowered Arbitrable Data Auditing Scheme for Network Storage as a ServiceabstractThe maturity of network storage technology drives users to outsource local data to remote servers. Since these servers are not reliable enough for keeping users' data, remote data auditing mechanisms are studied for mitigating the threat to data integrity. However, many traditional schemes achieve verifiable data integrity for users only without resolutions to data possession disputes, while others depend on centralized third-party auditors (TPAs) for credible arbitrations. Recently, the emergence of blockchain technology promotes inspiring countermeasures. In this article, we propose a decentralized arbitrable remote data auditing scheme for network storage service based on blockchain techniques. We use a smart contract to notarize integrity metadata of outsourced data recognized by users and servers on the blockchain, and also utilize the blockchain network as the self-recording channel for achieving non-repudiation verification interactions. We also propose a fairly arbitrable data auditing protocol with the support of the commutative hash technique, defending against dishonest provers and verifiers. Additionally, a decentralized adjudication mechanism is implemented by using the smart contract technique for creditably resolving data possession disputes without TPAs. The theoretical analysis and experimental evaluation reveal its effectiveness in undisputable data auditing and the limited requirement of costs. Yang Xu 0013, Ju Ren 0001, Yan Zhang 0002, Cheng Zhang 0035, Bo Shen 0002, Yaoxue Zhang |
IEEE Trans. Serv. Comput. | 1 |
| 2019 | An adaptive and configurable protection framework against android privilege escalation threats
Yang Xu 0013, Guojun Wang 0001, Ju Ren 0001, Yaoxue Zhang |
Future Gener. Comput. Syst. | 1 |
| 2019 | A Blockchain-Based Nonrepudiation Network Computing Service Scheme for Industrial IoTabstractEmerging network computing technologies extend the functionalities of industrial IoT (IIoT) terminals. However, this promising service-provisioning scheme encounters problems in untrusted and distributed IIoT scenarios because malicious service providers or clients may deny service provisions or usage for their own interests. Traditional nonrepudiation solutions fade in IIoT environments due to requirements of trusted third parties or unacceptable overheads. Fortunately, the blockchain revolution facilitates innovative solutions. In this paper, we propose a blockchain-based fair nonrepudiation service provisioning scheme for IIoT scenarios in which the blockchain is used as a service publisher and an evidence recorder. Each service is separately delivered via on-chain and off-chain channels with mandatory evidence submissions for nonrepudiation purpose. Moreover, a homomorphic-hash-based service verification method is designed that can function with mere on-chain evidence. And an impartial smart contract is implemented to resolve disputes. The security analysis demonstrates the dependability, and the evaluations reveal the effectiveness and efficiency. Yang Xu 0013, Ju Ren 0001, Guojun Wang 0001, Cheng Zhang 0035, Jidian Yang, Yaoxue Zhang |
IEEE Trans. Ind. Informatics | 1 |
| 2018 | A Feasible Fuzzy-Extended Attribute-Based Access Control TechniqueabstractAttribute-based access control (ABAC) is a maturing authorization technique with outstanding expressiveness and scalability, which shows its overwhelmingly competitive advantage, especially in complicated dynamic environments. Unfortunately, the absence of a flexible exceptional approval mechanism in ABAC impairs the resource usability and business time efficiency in current practice, which could limit its growth. In this paper, we propose a feasible fuzzy-extended ABAC (FBAC) technique to improve the flexibility in urgent exceptional authorizations and thereby improving the resource usability and business timeliness. We use the fuzzy assessment mechanism to evaluate the policy-matching degrees of the requests that do not comply with policies, so that the system can make special approval decisions accordingly to achieve unattended exceptional authorizations. We also designed an auxiliary credit mechanism accompanied by periodic credit adjustment auditing to regulate expediential authorizations for mitigating risks. Theoretical analyses and experimental evaluations show that the FBAC approach enhances resource immediacy and usability with controllable risk. Yang Xu 0013, Wuqiang Gao, Quanrun Zeng, Guojun Wang 0001, Ju Ren 0001, Yaoxue Zhang |
Secur. Commun. Networks | 1 |
| 2018 | Towards Secure Network Computing Services for Lightweight Clients Using BlockchainabstractThe emerging network computing technologies have significantly extended the abilities of the resource‐constrained IoT devices through the network‐based service sharing techniques. However, such a flexible and scalable service provisioning paradigm brings increased security risks to terminals due to the untrustworthy exogenous service codes loading from the open network. Many existing security approaches are unsuitable for IoT environments due to the high difficulty of maintenance or the dependencies upon extra resources like specific hardware. Fortunately, the rise of blockchain technology has facilitated the development of service sharing methods and, at the same time, it appears a viable solution to numerous security problems. In this paper, we propose a novel blockchain‐based secure service provisioning mechanism for protecting lightweight clients from insecure services in network computing scenarios. We introduce the blockchain to maintain all the validity states of the off‐chain services and edge service providers for the IoT terminals to help them get rid of untrusted or discarded services through provider identification and service verification. In addition, we take advantage of smart contracts which can be triggered by the lightweight clients to help them check the validities of service providers and service codes according to the on‐chain transactions, thereby reducing the direct overhead on the IoT devices. Moreover, the adoptions of the consortium blockchain and the proof of authority consensus mechanism also help to achieve a high throughput. The theoretical security analysis and evaluation results show that our approach helps the lightweight clients get rid of untrusted edge service providers and insecure services effectively with acceptable latency and affordable costs. Yang Xu 0013, Guojun Wang 0001, Jidian Yang, Ju Ren 0001, Yaoxue Zhang, Cheng Zhang 0035 |
Wirel. Commun. Mob. Comput. | 1 |
| 2016 | Decentralized group key management for hierarchical access control using multilinear formsabstractSummary Key management becomes more difficult in multiprivileged group communications due to the dynamic membership and the complex relations between users and resources. Because centralized key management schemes have the drawbacks of the single point of failure, and performance bottleneck and distributed key management schemes are not scalable and lack of central control, decentralized key management schemes are proposed as a tradeoff between them. In this paper, we propose a decentralized group key management scheme using multilinear forms for dynamic multiprivileged groups. Once users join/leave the group and change their privileges, the related session keys should be updated. The rekeying in the joining operation is relatively simple because the keys are deduced from the previous keys based on a one‐way function. When rekeying for one leaving/switching operation, a uniform rekeying material is negotiated between the related service groups (SGs) by using multilinear forms. Compared with other schemes in which several rounds of negotiations are executed for rekeying in each joining/leaving/switching operation, only one round of negotiation is required in each leaving/switching operation of our decentralized group key management scheme. At last, the affected session keys can be deduced by the related SGs. Our proposed scheme also supports the dynamic formation and decomposition of SGs, which provides good scalability. Security analysis is provided to show that the proposed scheme is secure. The performance analysis and the simulation results show that the proposed scheme reduces the communication cost greatly. Copyright © 2014 John Wiley & Sons, Ltd. Yang Xu 0013, Guojun Wang 0001 |
Concurr. Comput. Pract. Exp. | 2 |