EDBT 2026 Demo / reviewers in the wild / expert
Xiong Li 0002
dblp:63/6031-2
· DBLP profile ↗
164ranked-venue papers
22as first author
95since 2021 · last 2026
0000-0001-6619-554XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 54 · 8 first-author · 38 since 2021Systems, architecture and hardware · 33 · 3 first-author · 14 since 2021Security and privacy · 30 · 4 first-author · 14 since 2021Applied, interdisciplinary, general and emerging computing · 19 · 6 first-author · 17 since 2021Artificial intelligence and machine learning · 11 · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 10 · 2 since 2021Human-computer interaction and ubiquitous computing · 4 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A visionary dual-scale hybrid network for abdominal multi-organ segmentation
Miao Liao, Shiyuan Gong, Xiong Li 0002, Shuanhu Di, Weihong Lai, Xiaomei Jiang |
Eng. Appl. Artif. Intell. | 3 |
| 2026 | Efficient Dual-Revocation CP-ABE for Secure and Fine-Grained Data Sharing in IoMTabstractThe Internet of Medical Things (IoMT) enables large-scale sensing and cloud-based sharing of sensitive medical data, where access control must remain fine-grained, dynamic, and robust. In practical healthcare scenarios, access privileges frequently change due to real-world incidents such as physician resignation, role reassignment, emergency response, or patient consent withdrawal, which require both user-level and attribute-level revocation mechanisms. To address these challenges, we propose a Dual Revocable CP-ABE (DABE) scheme that unifies direct and indirect revocation within a single framework, to support diverse medical data sharing scenarios. The proposed system allows data owners to flexibly select revocation modes based on operational needs: indirect revocation efficiently handles large-scale updates for remote medical records via a semi-trusted cloud server, while direct revocation enables immediate access termination through ciphertext updates for highly sensitive data. This dual-mode design improves system robustness and fault tolerance, thus avoiding a single point of failure. Moreover, DABE supports verifiable outsourced decryption to accommodate resource-constrained IoMT devices. Formal security analysis proves IND-CPA security and resistance to collusion attacks, while experimental results demonstrate practical efficiency: the decryption time remains nearly constant (approximately 15–20 ms) regardless of policy complexity, achieving an improvement of over two orders of magnitude compared to existing schemes, with only modest overhead in other phases. These results show that DABE is well-suited for large-scale, dynamic IoMT systems. Lei Mei, Ke Huang 0002, Xiong Li 0002, Xiaosong Zhang 0001 |
IEEE Internet Things J. | 3 |
| 2026 | Digital Twin-Enabled Context-Aware Authentication Protocol for IoT-Based Healthcare ApplicationsabstractThe convergence of Digital Twin (DT) technology with Internet of Things (IoT)-based healthcare systems offers promising capabilities for real-time monitoring, personalized treatment, and predictive diagnostics. However, the integration of context-aware data flows and dynamic device interactions introduces critical security and privacy challenges such as impersonation, desynchronization, and physical tampering attacks. To address these concerns, this paper proposes a lightweight, context-aware authentication protocol using Authenticated Encryption with Associated Data (AEAD), Physical Unclonable Functions (PUFs), and cryptographic hash functions within a DT-enabled framework. The protocol supports mutual authentication and secure key establishment among sensing devices, gateways, and medical servers, while protecting device identities and ensuring data confidentiality and integrity without relying on stored credentials. A key innovation of this work is context enforcement through data-type authorization, where each sensing device is restricted to transmit only predefined categories of physiological data (e.g., temperature, oxygen saturation), thereby achieving fine-grained, semantics-driven access control. Security analysis under the Real-Or-Random (ROR) model confirms the protocol’s resistance to impersonation, desynchronization, replay, and leakage of ephemeral secrets. Performance evaluation demonstrates a 25.85% reduction in computational overhead and a 31.59% reduction in communication cost compared to relevant baseline protocols. These results validate the protocol’s effectiveness for securing resource-constrained, real-time healthcare systems in DT-enabled IoT environments. Muhammad Asad Saleem, Xiong Li 0002, Khalid Mahmood 0002, Salman Shamshad, Zahid Ghaffar |
IEEE Internet Things J. | 2 |
| 2026 | SWBA: A Sparse and Stealthy Backdoor Attack via Discrete Wavelet Transform for Image Classification
Yazhi Liu, Xingchun Ru, Xiong Li 0002 |
IEEE Signal Process. Lett. | 3 |
| 2026 | Two-Dimensional Privacy-Preserving Federated Learning Scheme Against Poisoning Attacks
Ke Gu 0002, Wenwu Zhao, Jingjing Tan, Xiong Li 0002, Weijia Jia 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | Privacy-Preserving Similarity Queries for Outsourced Trajectory DataabstractTrajectory similarity query can retrieve a set of trajectories similar to the user's query from the database and is widely used in various fields such as travel recommendations. Previous studies mainly focused on accelerating trajectory similarity search in plaintext. However, with the increasing concern about privacy protection in outsourced cloud environments, conducting trajectory similarity queries while preserving privacy becomes a significant challenge. This paper proposes efficient privacy-preserving top-$k$and range similarity queries over trajectory data. We leverage Discrete Synchronous Euclidean Distance (DSED) to measure the spatio-temporal similarity of trajectory data, and employ a filter-then-refine strategy to enhance efficiency. Specifically, Hilbert curve-based filtering is first applied to exclude a large portion of dissimilar trajectories, followed by homomorphic encryption-based refinement to retrieve precise results. Security analysis demonstrates that our schemes protect the privacy of trajectory data, query requests, and query results. Finally, extensive experimental results indicate that the proposed methods achieve a trade-off between data availability and privacy, achieving over 99% average precision while initially filtering out 90% of dissimilar trajectories, and improving query efficiency by at least an order of magnitude. Kelai Yi, Yuchen Su 0001, Shiyue Huang, Yuefeng Chen, Xiong Li 0002, Hongbo Liu 0002 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | Time Updatable Policy-Based Chameleon Hash for Traceable and Accountable Redactable BlockchainabstractAteniese et al. (EuroS&P 2017) proposed the notion of redactable blockchains (RBs), in which a designated party uses a secret key to modify blockchain history without causing a hard fork. Nevertheless, redactions may be performed mistakenly or maliciously due to misbehavior or operational errors. From a regulatory perspective, any RB design must therefore incorporate accountability and traceability mechanisms to ensure that redactions are non-abusive and publicly verifiable. As a countermeasure, we propose the notion of time-updatable policy-based chameleon hash (TPCH). This construction addresses regulatory concerns by enabling publicly verifiable proofs of redaction and traceable user identities. Our basic building block, termed time-updatable chameleon hash (TUCH), provides redaction accountability through an intrinsic property formalized as Type-2 Trapdoor Collisions. TUCH is functionally versatile and achieves acceptably efficient performance compared to peer chameleon hash schemes. Following the heuristics of Camenisch et al. (PKC 2017) and Derler et al. (NDSS 2019), we further extend TUCH by integrating attribute-based encryption (ABE) to obtain a time-updatable, policy-based variant, namely TPCH. The resulting scheme overcomes the limitations of coarse-grained redaction and the impracticality of specifying the exact modifier in advance. Overall, TPCH provides a secure, efficient, and comprehensive solution for accountable and traceable redactable blockchains under practical regulatory requirements. Our systematic analysis further demonstrates the suitability of TPCH for small scale deployment. Ke Huang 0002, Xiong Li 0002, Fatemeh Rezaeibagha, Linghao Zhang, Xiaosong Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | Privacy-Preserving Joint Distribution Analysis for Set-Valued Data via Local Differential PrivacyabstractSet-valued data, an important data form expressing diversity and uncertainty, is widely used in fields such as recommendation systems and social network analysis. However, such data often contains fine-grained records, which may lead to the leakage of users’ sensitive information. To this end, some privacy-preserving set-valued data analysis schemes have been proposed. This paper first proposes a joint shift inference attack against the cyclic shift-based local differential privacy (LDP) protocol introduced by Huang et al. (10.1109/TIFS.2024.3423657), it exploits deterministic cyclic-shift patterns and significant frequency differences to infer the user’s original data. Experimental results demonstrate that the user’s original data can be inferred with a probability exceeding 96%. Theoretically, the cyclic-shift mechanism violates the core requirement of local differential privacy due to its non-surjective output space. To overcome the limitations of existing schemes, we propose a privacy-preserving joint distribution analysis scheme for set-valued data via LDP (SVJDA). It employs the Sparse Vector Mean Estimation (SVME) mechanism and utilizes a sign-based hashing function to compress data, allowing privacy-preserving joint distribution analysis while introducing only minimal additional noise. Theoretical analysis shows that SVJDA satisfies ϵ-LDP with minimal estimation error. The experimental results confirm that SVJDA achieves higher accuracy in joint distribution estimation while ensuring the accuracy of frequent itemset identification. For ϵ ∈ [0.4, 1], the L∞ error of SVJDA is only 7.208%–21.725% of SVSM and 2.821%–7.279% of LDP-RM, while its MSE is 0.00364%–2.338% of SVSM and 0.017%–0.068% of LDP-RM, demonstrating its superior performance. Xiong Li 0002, Shuai Shang, Wei Liang 0005, Jinjun Chen, Xiaosong Zhang 0001, Keqin Li 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | A Byzantine-Robust Secure Federated Learning Scheme in Heterogeneous Data
Ruijin Wang, Zengpeng Li 0001, Fengli Zhang, Jingwei Li 0001, Xiong Li 0002 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2026 | Exploiting Cyber Threat Intelligence for Indirect Attacks Against Serverless InfrastructuresabstractCyber Threat Intelligence (CTI) and serverless computing are two emerging technologies that have significantly impacted their respective domains in recent years. However, their interaction remains surprisingly underexplored. In this work, through in-depth semi-structured interviews with cybersecurity experts, we identify the trust issues within the CTI ecosystem that can be exploited to introduce fake CTI manipulation, enabling indirect attacks against entities with dynamic IP allocation, such as those in serverless computing. Furthermore, these attacks can be amplified by commercial CTI platforms due to their widespread adoption and sharing mechanisms. Based on these insights, we propose Ares, a novel attack strategy that leverages fake CTI manipulation to enable large-scale, stealthy indirect denial-of-service attacks against serverless infrastructures. We demonstrate the feasibility and impact of Ares through extensive evaluations in a controlled experimental environment. Our results show that Ares can rapidly and widely disseminate fake CTI within the CTI ecosystem, leading to an overall average reject rate of 23.03% and a high reject rate of up to 45.42% when accessing top websites in certain industries, while maintaining a low detection rate across state-of-the-art serverless security systems. These findings underscore the urgent need for more frequent communication and collaboration among CTI platforms and related stakeholders to develop a more robust trustworthiness model across the ecosystem. Baojin Wang, Yongzhao Zhang, Xiong Li 0002, Jie Yang 0003, Ting Chen 0002, Xiaosong Zhang 0001, Dian Ding, Yi-Chao Chen 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2026 | Federated Contrastive Diffusion Prototypes for Robust Private LearningabstractThe secure deployment of Federated Learning (FL) is critically undermined by statistical data heterogeneity and a profound vulnerability to adversarial attacks, these weaknesses are exacerbated by FL’s privacy-preserving preclusion of large-scale, centralized data for robust training. Existing proto-typebased methods suffer from representation collapse when naively aggregating from non-IID clients, while generative approaches often lack a principled mechanism for synthesizing features that confer adversarial resilience. We introduce Federated Contrastive Diffusion Prototypes (Fed-CDP), a novel paradigm that transforms the server from a passive aggregator into an active synthesis hub for robust features. Fed-CDP aggregates lightweight client prototypes to serve as semantic anchors, guiding a server-side diffusion model via a contrastive objective. This process synthesizes a high-fidelity feature space explicitly optimized for maximal inter-class separability, a property intrinsically linked to robust generalization. These server-generated features are then distributed to clients as a potent regularizer, aligning disparate local models and directly mitigating client drift. Our extensive evaluations across multiple challenging datasets establish that Fed-CDP outperforms existing state-of-the-art baselines. For instance, on CIFAR-100 under severe heterogeneity (α = 0.1), Fed-CDP surpasses leading methods by nearly 5% in standard accuracy and over 9% in robust accuracy under Projected Gradient Descent attacks. Fed-CDP provides a new blueprint for building secure and high-performance collaborative AI, laying the foundation for trustworthy systems in critical sectors like finance and multi-institutional healthcare. Xiong Li 0002, Wei Liu 0077, Muhammad Khurram Khan, Jinjun Chen |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | TrustSearch: Toward Secure and Efficient Reverse Image Search via SGXabstractOutsourcing image management to a cloud should not only protect the confidentiality of image data, but also maintain the capability of reverse image search, which requires identifying the existing stored images that are similar to an input image. Previous studies build on cryptographic approaches to realize reverse image search on encrypted images, yet failing to achieve either security or performance. This paper explores trusted image search, which uses Intel SGX to realize reverse image search in an enclave, in order to provide security guarantees via SGX while performing search on plain data (inside the enclave) for performance. However, due to the resource limits of SGX, directly realizing the search process in the enclave incurs high performance overhead. We present TRUSTSEARCH, which implements various design approaches to mitigate the resource overhead of SGX. We evaluate TRUSTSEARCH using real-world image datasets, and show that it outperforms state-of-the-art approaches for search performance while preserving space efficiency for the enclave. Fang Zou, Jingwei Li 0001, Dayan Wu, Xiong Li 0002, Hongwei Li 0001, Ting Chen 0002, Xiaosong Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2026 | CPFTransGAN: A Cross Perception Fusion Transformer-Based Generative Adversarial Network for Head and Neck Cancer Dose Prediction in RadiotherapyabstractRadiation therapyis one of the primary treatment modalities for head and neck (H&N) cancer in clinical practice, aiming to deliver sufficient dose to Planning Target Volume (PTV) while protecting surrounding Organs at Risk (OAR) from or minimizing exposure to radiation. Quantitative dose prediction of various tissues and organs is a prerequisite for implementing intelligent precision radiotherapy. In order to improve dose prediction accuracy, we propose a generative adversarial network CPFTransGAN based on Cross Perception Fusion Transformer (CPF Transformer). Specifically, we design a CPF Transformer module through deeply integrating CNN and Transformer. Using the CPF Transformer as basic unit, we constructed a generator with four-stage encoding-decoding structure called CPFTransGenerator. An adaptive weight loss is used to train the discriminator to alleviate the issues of imbalance training in adversarial learning. To further improve the prediction accuracy, a multiscale cross-window encoding network is designed, which can constrain the differences between predicted dose and the reference one at different granularity levels by calculating feature losses between them at different scales. The proposed method is evaluated on two public head and neck cancer datasets and a local clinical dataset. Extensive experiments demonstrate the superior performance of our method compared with the state-of-the-art ones. Miao Liao, Enyu Zhou, Xiong Li 0002, Wei Liang 0005, Yuqian Zhao 0001, Shuanhu Di, Victor Chang 0001 |
IEEE J. Biomed. Health Informatics | 3 |
| 2026 | A Verifiable Federated Learning Scheme With Privacy-Preserving in MCSabstractThe popularity of edge smart devices and the explosive growth of generated data have driven the development of mobile crowd sensing (MCS). Also, federated learning (FL), as a new paradigm of privacy-preserving distributed machine learning, integrates with MCS to offer a novel approach for processing large-scale edge device data. However, it also brings about many security risks. In this paper, we propose a verifiable federated learning scheme with privacy-preserving for mobile crowd sensing. In our federated learning scheme, the double-layer random mask partition method combined with homomorphic encryption is constructed to protect the local gradients and enhance system security (strong anti-collusion ability) based on the multi-cluster structure of federated learning. Also, a sampling verification mechanism is proposed to allow the mobile sensing clients to quickly and efficiently verify the correctness of their received gradient aggregation results. Further, a dropout handling mechanism is constructed to improve the robustness of mobile crowd sensing-based federated learning. Related experimental results demonstrate that our verifiable federated learning scheme is effective and efficient in mobile crowd sensing environments. Ke Gu 0002, Jiaqi Lei, Jingjing Tan, Xiong Li 0002 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2026 | DroneSec: Efficient and Secure Communication for Resource-Constrained Drones in IoD SystemsabstractThe Internet of Drones (IoD) represents an emerging paradigm of the Internet of Things (IoT), enabling seamless, coordinated communication among drones and integration with other connected systems. This interconnected network enables autonomous decision-making among drones. As this IoD paradigm continues to expand it faces significant challenges due to its reliance on public channel. Therefore, existing methods often suffer from impersonation, cloning, anonymity violation, and fails to offer end-to-end key secrecy. Moreover, they require high computation resources which present challenges of deployment in resource-constrained IoD environment. To address these challenges, we propose a secure and efficient protocol that provides mutual authentication among participating entities. The protocol resists impersonation, cloning, anonymity violation and offers end-to-end key secrecy. The protocol employs Physical Unclonable Function (PUF) and Elliptic Curve Cryptography (ECC), along with a fuzzy extractor, to ensure secure communication. The resilience of the proposed protocol was evaluated through an informal analysis. Its security properties were rigorously verified using formal analysis based on the Real-Or-Random (ROR) model. Evaluation of its performance shows that the proposed protocol outperforms existing solutions, achieving reductions of 20.9% in computation cost and 32.6% in communication overhead. The results demonstrate that the protocol improves security and provides reliability under the evaluated scenarios of IoD systems. Anum Lodhi, Xiong Li 0002, Muhammad Asad Saleem, Muhammad Ali Lodhi, Khalid Mahmood 0002, Salman Shamshad |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2025 | Clean-Label Data Poisoning Attack based on Representation-Conditioned Data GenerationabstractThe growing demand for large-scale training data in deep learning has promoted the use of open data collection, thereby increasing the risk of data poisoning attacks. Clean-label data poisoning attacks aim to compromise models by injecting malicious samples into the training set, while being constrained to maintain consistency between the visual features of the samples and their assigned labels. Though this constraint enhances attack feasibility in real-world settings, it also introduces significant technical challenges, such as reliance on white-box assumptions and limitations in stealth and effectiveness. To address these limitations, this paper proposes a novel clean-label data poisoning attack scheme based on representation-conditioned data generation (CPRCG). The scheme identifies "natural poisoned data" from open datasets, extracts their deep representations as constraints, and generates numerous new samples using the conditional data generation model MAsked Generative Encoder (MAGE). These samples preserve core similarities while introducing random variations in form and behavior. Experimental results show that samples generated by CPRCG achieve high stealth and diversity, outperforming MetaPoison by 4.1% in centralized learning and approaching the effectiveness of dirty-label attacks in federated learning. Xiong Li 0002, Jiguo Yu, Vijayakumar P, Mohammad S. Obaidat, Xiaosong Zhang 0001 |
GLOBECOM | 2 |
| 2025 | Virtualization Native Cloud Data Center NetworkabstractCloud computing, as a novel paradigm for resource utilization and service deployment, virtualizes computing, storage, and network resources to form a logical resource pool. It provides users with an on-demand, self-service resource acquisition model, significantly lowering the barrier to resource access and offering strong elasticity in scaling applications. Traditional cloud data center networks are typically built on Ethernet and IP technologies. Most cloud data centers adopt a Spine-Leaf architecture, where the underlying physical network is interconnected via Ethernet links, and data transmission is realized through dynamic routing protocols and equal-cost multipath (ECMP) forwarding at the IP layer. Network virtualization functions are commonly achieved through tunneling technologies such as VXLAN, NVGRE, and UDP tunnels. However, this approach presents notable limitations. Firstly, conventional Ethernet and IP technologies were not originally designed for the specific requirements of modern cloud data center scenarios. As a result, they fail to address the particular technical demands and service characteristics of cloud computing networks. Secondly, tunneling technologies—especially those based on transport-layer tunneling—operate at higher layers of the protocol stack. When physical servers send and receive virtual network traffic, a considerable amount of computational resources (e.g., CPU and memory) is consumed, leading to both increased overhead and reduced network throughput. As a foundational infrastructure tailored for virtualized workloads, cloud data centers represent a typical vertically specialized application scenario. Therefore, it is feasible to design a novel cloud data center network architecture specifically optimized for this context. This paper proposes a new implementation approach for cloud data center networks, introducing a novel addressing, routing, and forwarding mechanism that natively integrates network virtualization functions into the network substrate. By embedding virtualization at the architectural layer, this design fundamentally addresses the limitations of conventional network virtualization techniques and enhances overall performance. Zhangfeng Hu, Qiuzheng Ren, Xiong Li 0002, Liang Sun 0007 |
INDIN | 7 |
| 2025 | ShieldReduce: Fine-Grained Shielded Data Reduction
Jingyuan Yang 0018, Jun Wu 0001, Ruilin Wu, Jingwei Li 0001, Patrick P. C. Lee, Xiong Li 0002, Xiaosong Zhang 0001 |
USENIX ATC | 6 |
| 2025 | VADP: Visitor-attribute-based adaptive differential privacy for IoMT data sharing
Shaobo Zhang 0001, Lujie Zhang, Tao Peng 0011, Qin Liu 0001, Xiong Li 0002 |
Comput. Secur. | 5 |
| 2025 | Vupsi: Verifiable Unbalanced Private Set Intersection Based on Homomorphic EncryptionabstractABSTRACT Unbalanced private set intersection (UPSI), a cryptographic technique for securely computing set intersections in asymmetrical setups while preserving privacy, has been extensively studied. However, existing protocols often require clients with small sets to participate in computations, are highly interactive, and lack result verifiability. In this paper, we propose VuPSI, a verifiable unbalanced PSI scheme designed to overcome the limitations of existing protocols. VuPSI offloads the computational burden to the server, reducing client‐side processing and simplifying the overall workflow. In addition, VuPSI incorporates an efficient zero‐knowledge verification mechanism that allows clients to efficiently verify the correctness of intersection results with minimal computational overhead. This approach significantly improves the reliability of PSI outcomes. Our design implements a low‐interaction protocol that ensures scalability and efficiency, especially for large‐scale dynamic datasets. Experimental evaluations show that VuPSI is both efficient and practical. Specifically, VuPSI can process 1,024 client‐side items and 1,000,000 server‐side items within seconds using 32 threads, achieving 40× the communication efficiency of comparable protocols such as DiPSI. Its lower computational overhead and faster data preprocessing make it well‐suited for real‐time, dynamic server environments. Ruirui Gao, Shuai Shang, Ke Huang 0002, Xiong Li 0002 |
Concurr. Comput. Pract. Exp. | 6 |
| 2025 | Provably Secure Efficient Key-Exchange Protocol for Intelligent Supply Line Surveillance in Smart GridsabstractIntelligent supply line surveillance is critical for modern smart grids (SGs). Smart sensors and gateway nodes are strategically deployed along supply lines to achieve intelligent surveillance. They collect data continuously and transmit it to the control centre in real-time. It enables real-time monitoring, fault detection, and efficient energy management across distribution networks. This advanced surveillance system ensures continuous monitoring of supply lines, detecting anomalies, and optimizing operations to maintain the stability and reliability of the SG. However, the reliance of all participating nodes on public communication channels to transmit supply line surveillance data exposes these systems to critical cyber attacks. These cyber attacks include impersonation, physical tampering, ephemeral secret leakage (ESL), and desynchronization attacks. To address these issues, existing key-exchange protocols often fail to ensure robust security while imposing high computation and communication overheads, limiting their practicality for resource-constrained environments. Therefore, we propose a secure and efficient key exchange and tamper-resistant authentication protocol using elliptic curve cryptography (ECC) and physical unclonable functions (PUFs). The PUF mechanism provides robust resistance against physical tampering and cloning attacks, ensuring enhanced physical security for supply line devices. We validate the security robustness of the devised protocol using the random or real (ROR) model. Furthermore, informal security analysis demonstrates the protocol’s robustness in rigorously resisting various attacks, including physical tampering, impersonation, ESL and desynchronization. Moreover, we determine the performance evaluation that reveals the protocol’s superior efficiency compared to competing protocols, achieving significant reductions of 28.64% in computation overhead and 9.96% in communication overhead. Muhammad Faizan Ayub, Xiong Li 0002, Khalid Mahmood 0002, Mohammed J. F. Alenazi, Ashok Kumar Das |
IEEE Internet Things J. | 2 |
| 2025 | A Robust Key Exchange and Tamper-Resistant Protocol for HAN and NAN Networks in Smart GridsabstractSmart grids (SGs) rely on home area networks (HANs) and neighborhood area networks (NANs) to ensure efficient power distribution, real-time monitoring, and seamless communication between smart devices. Despite these advantages, the use of public communication channels in HAN and NAN networks introduces critical challenges, such as vulnerability to impersonation, physical tampering, and scalability issues in resource-constrained environments. These issues compromise the stability, reliability, and security of SG environments. Existing protocols often fail to adequately address these challenges, particularly in ensuring resistance to physical tampering of supply lines and impersonation attacks. Additionally, they struggle to minimize the computation, communication, and energy costs associated with securing a resource-constrained SG environment. Therefore, we propose a robust key exchange and tamper-resistant protocol for HAN and NAN networks to address these limitations. The proposed protocol leverages the physical unclonable function (PUF) mechanism to offer physical tampering resistance to smart meters. We validate our protocol formally using the Random or Real (RoR) model, which confirms its security robustness. Additionally, our informal security analysis highlights the protocol’s resilience against impersonation, physical tampering attacks, etc. We analyze and compare the performance of the proposed protocol, which further demonstrates our protocol’s effectiveness and security compared to competing protocols. Moreover, the proposed protocol achieves resource efficiency with 45.99% and 58.85% substantial reductions in computation overhead and energy overhead, respectively, compared to competing protocols. These results showcase the protocol’s enhanced security and practicality for resource-constrained SG environments. Muhammad Faizan Ayub, Xiong Li 0002, Khalid Mahmood 0002, Salman Shamshad, Ashok Kumar Das |
IEEE Internet Things J. | 2 |
| 2025 | MASS: A Multiattribute Sketch Secure Data Sharing Scheme for IoT Wearable Medical Devices Based on BlockchainabstractWith the swift advancement of the Internet of Things (IoT) and artificial intelligence (AI), various technologies have been integrated into wearable medical health devices, improving users’ awareness of their physical states and enabling the analysis of a greater amount of human data. However, these sensitive pieces of information are prone to tampering or theft during storage and transmission, posing security risks. In this article, we propose a multiattribute sketch secure data sharing scheme for IoT wearable medical devices based on blockchain (MASS). We introduce a multiattribute sketch storage method that stores the encrypted hash of health data transmitted by medical wearable devices on the blockchain. This work also designs a ciphertext-policy attribute-based encryption (CP-ABE) access control mechanism that effectively addresses the secure sharing of data from wearable medical devices among healthcare professionals. Experimental findings indicate that with the rise in the number of medical health data documents, the costs associated with index generation and search time decrease by 55.3% and 10.83%, respectively. Additionally, as the frequency of data access increases, there is a 13.5% reduction in encryption time, and the implementation of multiattribute sketches results in a 24.8% and 11.3% reduction in index generation and search times, respectively. Lin Chen 0033, Wei Liang 0005, Xiong Li 0002, Kuanching Li, Jin Wang 0001, Naixue Xiong |
IEEE Internet Things J. | 4 |
| 2025 | DSCR: A Dynamic Secure Clustering Routing Scheme for UANETs Based on Reputation MechanismabstractIn Unmanned Aerial Vehicle Ad Hoc Networks (UANETs), rapid movement of nodes leads to frequent changes in network topology, increasing the risk of packet loss and affecting data transmission. Furthermore, current research on drone clustering lacks security considerations, which reduces the reliability of data transmission. Due to this, improving the stability and reliability of network data transmission in dynamically changing UANETs remains a challenge. In this work, we propose the reputation mechanism DSCR (Dynamically Secure Cluster Routing) Scheme for UANETs, a design for cluster head election in UANETs using the evaluated value and reputation value of drones and forms clusters through this reputation mechanism to avoid malicious nodes from interfering with the clusters to improve the security of UANETs. We apply a residual link survival time-based intra-and inter-cluster algorithm based on residual link survival time for data forwarding of nodes, optimizing the dynamic routing strategy and reducing the packet loss rate of nodes. In addition, reinforcement learning is used in UANETs to achieve cluster decisions based on the current network state and cluster dynamics, effectively improving the stability of clusters. Experiments were conducted on the proposed method to verify its efficiency and stability. Compared to the ICRA, RICR, and DCA algorithms, the stability of the cluster is improved by 11.92%, 28.12%, and 75.2%, respectively, and the packet loss rate reduced by 41.48%, 44.17%, and 55.74%, demonstrating that DSCR is a compelling dynamic routing solution applicable to UANETs. Yinyan Gong, Kuanching Li, Wei Liang 0005, Xiong Li 0002, Jin Wang 0001, Yang Xiang 0001 |
IEEE Internet Things J. | 5 |
| 2025 | PDFed-ALD: Adaptive Primal-Dual Federated Learning Under Industrial Internet of ThingsabstractFederated Learning (FL) is a distributed training paradigm that enables multiple devices in the Industrial Internet of Things (IIoT) to collaboratively train a global model without sharing private data. However, non-IID data in FL leads to client drift, which significantly degrades the performance of the global model in IIoT scenarios. While the primal-dual update method effectively mitigates client drift through dynamic regularization, optimizing the global model remains a significant challenge in IIoT due to the high degree of data heterogeneity. To address this challenge, we propose a novel FL method, PDFed-ALD, which effectively mitigates client drift and improves global model’s performance under high data heterogeneity. The core of PDFed-ALD is adaptive local distillation mechanism, which employs an adaptive distillation temperature based on the relative degree of data heterogeneity, dynamically correcting gradient updates, alleviating the issue of client drift. Furthermore, to reduce variance among local gradients, PDFed-ALD introduces a momentum-based minimum sharpness gradient correction method, which enhances local consistency by minimizing the variance between gradients across clients. Extensive experiments on image classification tasks using CIFAR-10, CIFAR-100 and MVTEC datasets demonstrate that PDFed-ALD outperforms state-of-the-art (SOTA) methods in terms of both accuracy and convergence speed across various settings, including client scale, participation rate, and degree of data heterogeneity. Jinshan Lai, Muhammad Khurram Khan, Fengli Zhang, Jieying Zhao, Ruijin Wang, Xiong Li 0002 |
IEEE Internet Things J. | 7 |
| 2025 | CDAP-PFMs: A Cross-Domain Authentication Protocol for Edge Inference-Based PFMsabstractThe Pre-trained Foundation Models (PFMs) based on edge inference reduce communication latency from the cloud server to the user mobile devices, and support different edge nodes to provide adaptive Artificial Intelligence (AI) services to the users. The complex network environment has attracted widespread attention to the communication security of cross-domain AI services. Authentication protocol is an important way to ensure the communication security among entities. However, existing cross-domain authentication protocols have not taken into account the communication delay caused by complex cryptographic operations on the mobile devices. To address these issues, a Cross-Domain Inference Authentication (CDIA) protocol for PFMs is proposed in this paper. The complex cryptographic operations are executed collaboratively by the servers from different domains to realizes decentralized authentication. Besides, the correctness and security of CDIA protocol is proved by formal analysis. The security of CDIA protocol is verified by using the Automated Validation of Internet Security Protocols and Applications (AVISPA) tool. The security of negotiated group key is proved by Real-or-Random (RoR) model. Finally, the performance of CDIA protocol is evaluated to show its efficiency. Compared with related protocols, the computing cost and communication overhead of CDIA protocol are at least 52.38% and 11.9%, respectively. Yufeng Xiao, Wei Liang 0005, Weifan Xu, Zisang Xu, Xiong Li 0002, Naixue Xiong |
IEEE Internet Things J. | 6 |
| 2025 | Provably Secure Authenticated Key-Management Mechanism for e-Healthcare EnvironmentabstractThe Internet of Things (IoT) is rapidly permeating all aspects of human life, involving a network of devices that share sensitive data. A notable application is the e-healthcare systems, which employ connected sensors, medical servers, and wearable devices. However, the public nature of communication in e-healthcare systems poses challenges such as security, privacy, and authentication of participating entities. Recently, many authentication protocols have been introduced to address these challenges. However, most of these protocols remain vulnerable to various security attacks, including device or medical server impersonation, denial of service, physical or cloning, and de-synchronization attacks. Therefore, we introduce an authenticated key-management protocol utilizing hash functions and Cipher-Block Chaining-Advanced Encryption Standard encryption (CBC-AES) encryption. The proposed protocol also employs the Physical Unclonable Function (PUF), which makes it more robust and efficient in resisting physical or cloning attacks. Additionally, the proposed scheme resists various security threats, including impersonation, session key leakage, ephemeral secret leakage, and de-synchronization attacks. We analyze the scheme’s security and reliability through formal and informal analysis. The informal analysis demonstrates that the scheme encompasses crucial security features, while the formal analysis substantiates. Moreover, performance analysis of the proposed protocol with various competing results indicates that our protocol achieves an average reduction in communication and computation overheads by 36.03.% and 41.79%, respectively. Muhammad Asad Saleem, Xiong Li 0002, Khalid Mahmood 0002, Zahid Ghaffar, Yong Xie 0003 |
IEEE Internet Things J. | 2 |
| 2025 | APBAM: Adversarial perturbation-driven backdoor attack in multimodal learning
Shaobo Zhang 0001, Xiong Li 0002, Qin Liu 0001, Guojun Wang 0001 |
Inf. Sci. | 3 |
| 2025 | Active cybersecurity: vision, model, and key technologiesabstractNoncooperative computer systems and network confrontation present a core challenge in cyberspace security. Traditional cybersecurity technologies predominantly rely on passive response mechanisms, which exhibit significant limitations when addressing real-world complex and unknown threats. This paper introduces the concept of “active cybersecurity,” aiming to enhance network security not only through technical measures but also by leveraging strategy-level defenses. The core assumption of this concept is that attackers and defenders, in the context of network confrontations, act as rational decision-makers seeking to maximize their respective objectives. Building on this observation, this paper integrates game theory to analyze the interdependent relationships between attackers and defenders, thereby optimizing their strategies. Guided by this foundational idea, we propose an active cybersecurity model involving intelligent threat sensing, in-depth behavior analysis, comprehensive path profiling, and dynamic countermeasures, termed SAPC, designed to foster an integrated defense capability encompassing threat perception, analysis, tracing, and response. At its core, SAPC incorporates theoretical analyses of adversarial behavior and the optimization of corresponding strategies informed by game theory. By profiling adversaries and modeling confrontation as a “game,” the model establishes a comprehensive framework that provides both theoretical insights into and practical guidance for cybersecurity. The proposed active cybersecurity model marks a transformative shift from passive defense to proactive perception and confrontation. It facilitates the evolution of cybersecurity technologies toward a new paradigm characterized by active prediction, prevention, and strategic guidance. Xiaosong Zhang 0001, Yukun Zhu, Xiong Li 0002, Yongzhao Zhang, Weina Niu, Fenghua Xu, Junpeng He, Shiping Huang |
Frontiers Inf. Technol. Electron. Eng. | 3 |
| 2025 | Overlapping community-based malicious user detection scheme in social networks
Ke Gu 0002, Deng Yang, Wenwu Zhao, Xiong Li 0002 |
Knowl. Based Syst. | 4 |
| 2025 | Parsilo-CDR: Privacy-aware cross-domain recommendation for data silo
Shanpeng Liu, Buqing Cao, Jianxun Liu 0001, Xiong Li 0002 |
Knowl. Based Syst. | 6 |
| 2025 | A Synthetic Data-Assisted Satellite Terrestrial Integrated Network Intrusion Detection FrameworkabstractThe Satellite-Terrestrial Integrated Network (STIN) is an emerging paradigm offering seamless network services across geographical boundaries, yet it faces significant security challenges, including limited intrusion prevention capabilities. Federated learning (FL) provides a viable solution by aggregating traffic data from STIN clients (e.g., ground stations and edge routers) to train models for network intrusion detection systems (NIDS). However, satellite and terrestrial domain data’s non-independent and identically distributed (non-IID) nature hinders training efficiency and performance. This paper proposes STINIDF, a novel STIN intrusion detection framework leveraging FL-based data augmentation. STINIDF utilizes FL to collaboratively train a conditional diffusion model across STIN nodes while preserving privacy via differential privacy mechanisms, generating global traffic data representative of the STIN distribution. Each node then integrates global and local traffic data to train a local model for NIDS, addressing non-IID challenges by balancing data distribution through data augmentation. Using a simulation environment developed with OMNeT++ and INET, a Satellite-Terrestrial Integrated (STI) traffic dataset was created, including intrusion scenarios such as signal disruption, UDP flooding, and jamming attacks. Experimental results indicate that STINIDF outperforms existing data augmentation-based approaches under non-IID conditions, achieving$\mathbf {96.63\%(2.41\%\uparrow)}$accuracy,$\mathbf {96.71\% (3.14\%\uparrow)}$precision,$\mathbf {96.54\%(1.65\%\uparrow)}$recall and$\mathbf {96.66\%(2.7\%\uparrow)}$F1 score. Furthermore, when compared to methods integrating data augmentation with differential privacy, STINIDF demonstrates an effective balance between privacy preservation and intrusion detection performance, attaining an accuracy of$\mathbf {96.14\%(2.57\%\uparrow)}$and a FID of$\mathbf {17.88(7.41\downarrow)}$. Junpeng He, Xiong Li 0002, Xiaosong Zhang 0001, Weina Niu, Fagen Li |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Grapeseed: Generative Split-Learning for Privacy Preserving Sequential Recommendation in Vehicular Cloud-Powered Intelligent Transportation SystemsabstractThe adoption of vehicular cloud computing for sequential recommendation offers flexible, reliable, and scalable computing resources in intelligent transportation systems. However, it also raises privacy concerns of drivers/passengers regarding the upload of sensitive data and models to vehicular cloud servers. To address this issue, we propose a novel privacy-preserving sequential recommendation method for intelligent transportation systems (named Grapeseed) based on split learning and variational autoencoder (VAE). Specifically, the vehicular client first inputs raw data into an encoder to produce latent variables locally and uploads these variables to the vehicular cloud server. Then, the vehicular cloud server generates and returns intermediate variables derived from these latent variables. Upon receiving these intermediate variables, the vehicular client calculates the final recommendation results. Extensive experiment results and analyses demonstrate that the proposed method improves both performance and communication efficiency between vehicular cloud servers and clients while preserving privacy. Buqing Cao, Shanpeng Liu, Jianxun Liu 0001, Min Shi 0001, Xiong Li 0002 |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2025 | Achieving Efficient and Privacy-Preserving Reverse Skyline Query Over Single CloudabstractReverse skyline query (RSQ) has been widely used in practice since it can pick out the data of interest to the query vector. To save storage resources and facilitate service provision, data owners usually outsource data to the cloud for RSQ services, which poses huge challenges to data security and privacy protection. Existing privacy-preserving RSQ schemes are either based on a two-cloud model or cannot fully protect privacy. To this end, we propose an efficient privacy-preserving reverse skyline query scheme over a single cloud (ePRSQ). Specifically, we first design a privacy-preserving inner product's sign determination scheme (PIPSD), which can determine whether the inner product of two vectors satisfies a specific relation with 0 without leaking the vectors’ information. Next, we propose a privacy-preserving reverse dominance checking scheme (PRDC) based on symmetric homomorphic encryption. Finally, we achieve ePRSQ based on PIPSD and PRDC. Security analysis shows that PIPSD and PRDC are both secure in the real/ideal world model, and ePRSQ can protect the security of the dataset, the privacy of query requests and query results. Extensive experiments show that ePRSQ is efficient. Specifically, for a 3-dimensional dataset of size 1000, the computational and communication overheads of ePRSQ for a query are 79.47 s and 0.0021 MB, respectively. The efficiency is improved by$3.78\times$(300.58 s) and$928.57\times$(1.95 MB) respectively compared with PPARS, and by$61.31\times$(4872.55 s) and$407309\times$(855.35 MB) respectively compared with OPPRS. Yubo Peng, Xiong Li 0002, Ke Gu 0002, Jinjun Chen, Sajal K. Das 0001, Xiaosong Zhang 0001 |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2025 | EPREAR:An Efficient Attribute-Based Proxy Re-Encryption Scheme With Fast Revocation for Data Sharing in AIoTabstractThe Artificial Intelligence of Things (AIoT) is driving human society from “information” to “intelligence”, and the information technology industry is undergoing tremendous changes. However, AIoT data faces security threats such as leakage and illegal access when assisted by third parties. Therefore, some scholars use attribute-based proxy re-encryption (ABPRE) for secure sharing of data. However, the existing ABPRE schemes suffer from high computational overhead and inefficient attribution revocation, which seriously hinders practical application. To solve these problems, in this paper, we propose an efficient attribute-based proxy re-encryption scheme with fast attribute revocation (EPREAR). We design a non-interactive zero-knowledge proof protocol based on blockchain to ensure the verifiability of the key during attribute revocation. Furthermore, we devise a boundless encryption and decryption mechanism to enable the system's encryption and decryption with a fixed computation overhead, regardless of the size of the attribute set. And EPREAR possesses the ability to add infinite attributes without re-initializing the system. Finally, we perform theoretical and experimental analyses that show EPREAR has excellent computational performance. As a consequence, it has better application value in AIoT. Yong Xie 0003, Cong Peng 0005, Xiong Li 0002, Zhili Zhou 0001 |
IEEE Trans. Mob. Comput. | 5 |
| 2025 | Dual-Layered Model Protection Scheme Against Backdoor Attacks in Fog Computing-Based Federated LearningabstractWith the growing popularity of federated learning, the security of training models against backdoor attacks has become a key challenge. Existing defense schemes often fail to address the complexity and diversity of such attacks so as to make training models vulnerable. In this paper, we propose a comprehensive dual-layered model protection scheme for fog computing-based federated learning framework. In our scheme, we first introduce a multi-metric defense mechanism deployed on fog servers to defend against malicious backdoor attacks from edge devices. The proposed defense mechanism employs multiple detection indicators to simultaneously evaluate and detect gradient and model training attributes, so that the abnormal local gradients are identified effectively. Further, we construct a second-layered defense scheme deployed on aggregation servers to regularly monitor the participation status of fog servers, whose purpose is to detect the distribution of uploaded gradients and eliminate malicious gradients from compromised fog servers. Additionally, we design an adaptive gradient adjustment method to mitigate the influence of deleting malicious gradients on the global model training process. Experimental results show that our dual-layered model protection scheme can perform well against three type of backdoor attacks (BadNet, Blended and WaNet). Ke Gu 0002, Yiming Zuo 0004, Jingjing Tan, Bo Yin 0004, Xiong Li 0002 |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2025 | Conditional Data-Sharing Privacy-Preserving Scheme in Blockchain-Based Social Internet of VehiclesabstractSocial Internet of Vehicles (SIoVs) is an important information exchange platform to provide comprehensive traffic services by sharing vehicle-aware data. However, traditional data sharing methods can not provide the security of decentralized data sharing, making it possible for some malicious third parties to initiate dishonest behaviors. Additionally, the lack of access control for data sharing in SIoVs easily leads to unauthorized data sharing, thus user privacy is threatened and the source of false data is difficult to be traced. In this paper, we propose a conditional data-sharing privacy-preserving scheme for blockchain-based social internet of vehicles. In our scheme, a lightweight ledger-based blockchain system is designed, which combines with the ciphertext-policy attribute-based encryption method to realize anonymous one-to-many sharing of data with fine-grained access management. Also, a collaborative identity tracing method is constructed to trace malicious users who provide false data. Our scheme can effectively prevent second-hand data sharing and safeguard user privacy. Moreover, related experimental results validate the efficiency of our scheme. Zhuoqun Xia, Jiahuan Man, Ke Gu 0002, Xiong Li 0002, Longfei Huang |
IEEE Trans. Sustain. Comput. | 4 |
| 2025 | Adaptive diffusion landmark dynamic rendering for realistic talking face video generation
Tang Ying, Yazhi Liu, Xiong Li 0002 |
Vis. Comput. | 3 |
| 2024 | Towards Efficient Delegated Private Set Intersection Cardinality ProtocolabstractPrivate set intersection cardinality (PSI-CA) can compute the intersection cardinality of sets held by two participants in a privacy-preserving manner, and it has a wide range of applications in life. Since the existing PSI-CA protocol is often difficult to apply in real life due to its high communication overhead and computational cost, we designed an efficient PSI-CA protocol based on technologies such as PRF and OKVS. The security analysis shows that our PSI-CA protocol is secure under the semi-honest security model and does not leak the private information of the participants. Extensive experiments and performance evaluation analysis show that our protocol is much more efficient than other related protocols in terms of communication and computation. Specifically, for the intersection cardinality computation of two sets both of size 220, the running time (62.2s) of our PSI-CA protocol is only 3.3% (1854s) and 10.3% (601s) of other PSI-CA protocols, and the communication overhead of our PSI-CA protocol is 48.5% and 48.7% of related protocols. Xiong Li 0002, Shuai Shang, Ke Huang 0002, Xiaosong Zhang 0001 |
CSCWD | 3 |
| 2024 | Multiple-Round Aggregation of Abstract Semantics for Secure Heterogeneous Federated Learning
Xiong Li 0002, Wei Liang 0005 |
ICA3PP (4) | 2 |
| 2024 | Local Augmentation with Functionality-Preservation for Semi-Supervised Graph Intrusion DetectionabstractRecently, deep learning (DL)-driven intrusion detection technology has been rising gradually to reduce the economic and privacy losses caused by the dramatic increase in cyber attacks. Besides exploiting the statistical network traffic features, the inherent attack topologies are also important as they are highly associated with attack behaviors. Thus, many works use graph neural networks (GNN) to make use of them to improve the detection performance. Nevertheless, these topologies contain many isolated IPs that interact with far fewer targets than other non-isolated IPs. Due to the message-passing scheme, information from isolated IPs is less likely to be transmitted in GNN training, resulting in poor model understanding of the traffic connecting these isolated IPs. Therefore, the performance of GNN-based intrusion detection models is not satisfactory for this traffic. To address this problem, we implement a generation algorithm with traffic functionality preservation to improve the performance of GNN-based intrusion detectors by locally augmenting this type of traffic. The proposed method first converts the IP-based graph of the traffic dataset into a line graph, and then utilizes a conditional denoising diffusion probabilistic model to generate new graph snapshots to enhance the expressiveness of isolated IP in GNN message aggregation. We evaluate the performance of our method and compare it with state-of-the-art works on three datasets, i.e., NF-BoT-IoT-V2, NF-ToN-IoT-V2, and NF-CSECIC-IDS2018-V2, and the results show it achieves accuracy of 99.11%(↑0.11%), 93.84%(↑2.47%), and 97.15%(↑3.94%), respectively. Case study shows that the proposed local augmentation can improve detection performance under different isolated thresholds. Moreover, our method can alleviate the over-smoothing problem to a certain extent, and the augmented traffic also possesses better quality. Junpeng He, Hanyue Kong, Shihe Zhang, Xiong Li 0002, Weina Niu, Xiaosong Zhang 0001, Fagen Li |
ICC | 4 |
| 2024 | Predicting Multi-Scale Information Diffusion via Minimal Substitution Neural NetworksabstractIn social media platforms such as Weibo, Twitter, and Facebook, a variety of information is diffused daily. Exploring and exploiting the diffusion patterns in this information play crucial roles in areas such as viral marketing, recommendation systems, and public opinion management. However, the diffusion of this information is not merely sequential propagation among users, as most researchers assume. When we observe the diffusion of information in the entire network from a macroscopic perspective, we discover that these phenomena of information diffusion exhibit a series of interconnected relationships, such as alternation or dependency. In traditional methods of information diffusion prediction (IDP), these aspects are often overlooked. To address this, we introduce a substitution theory of information diffusion, minimal substitution (MS), and we combine it with neural networks to design a network model known as MSNN. First, the incorporation of MS theory enables our model to effectively capture the complex interrelations among pieces of information. Second, we analyze the relationship of the multi-scale IDP task, develop a one-step MS-based microscopic IDP method and a dynamic MS-based macroscopic IDP method, and utilize these two methods for joint training to achieve multi-scale prediction. Finally, we validate the accuracy of the proposed MSNN model through training on two real-world datasets with different growth patterns. Ranran Wang 0001, Yin Zhang 0002, Wenchao Wan, Xiong Li 0002, Min Chen 0003 |
INFOCOM | 4 |
| 2024 | Model-agnostic generation-enhanced technology for few-shot intrusion detection
Junpeng He, Lingfeng Yao, Xiong Li 0002, Muhammad Khurram Khan, Weina Niu, Xiaosong Zhang 0001, Fagen Li |
Appl. Intell. | 3 |
| 2024 | Improved gradient leakage attack against compressed gradients in federated learning
Xuyang Ding, Zhengqi Liu, Xintong You, Xiong Li 0002, Athanasios V. Vasilakos |
Neurocomputing | 4 |
| 2024 | Data Verifiable Personalized Access Control Electronic Healthcare Record Sharing Based on Blockchain in IoT EnvironmentabstractElectronic health records (EHRs) based on the Internet of Things (IoT) can provide real-time health data for quick intelligent medical services and give convenience to many data-sharing scenarios. However, EHRs also face various security threats since they are highly private. To the best of our knowledge, no recognized data-sharing work can satisfy the stringent privacy requirements of EHRs. Motivated by this, we propose a blockchain-based personalized access control EHR-sharing scheme with data verifiability, which can safeguard the interests of data owners (DOs) and users simultaneously. First, we take ciphertext-policy attribute-based encryption to achieve personalized access control for DOs. Second, we design an interactive zero-knowledge proof protocol between DOs and users, which can provide authenticity verification of EHR for users and prevent EHR away from forgery. In addition, smart contracts and the interplanetary file system are used to reduce the computation and storage costs of patients. Finally, the security analysis shows that the proposed scheme meets the predefined security goals. The performance analysis demonstrates that the proposed scheme is efficient and can be applied to practical electronic medical record sharing scenarios. Hui Wang 0124, Yong Xie 0003, Yi-Ning Liu 0002, Xiong Li 0002, Phuntsog Dorje |
IEEE Internet Things J. | 4 |
| 2024 | Versatile Remote Data Checking Scheme for Cloud-Assisted Internet of ThingsabstractInternet of Things (IoT) revolutionizes data collection, especially in e-healthcare, where patients data from wearables and sensors improves medical services. However, IoT’s limitations in computing and storage require cloud outsourcing. Combining IoT with the cloud has potential but raises concerns about data security. Leveraging cloud storage presents an attractive solution for accommodating the substantial volume of data outsourced by IoT devices. As the outsourcing of real-time data to cloud storage becomes commonplace, the adoption of data auditing schemes emerges as a means to ensure data integrity. To curtail operational expenses, various deduplication techniques are commonly employed on outsourced data, effectively sidestepping redundant data and resulting in storage and bandwidth efficiencies. Although real-time data typically remains distinct due to its diverse origins, scenarios, such as data sharing or trading in data-driven services and datamarkets, can lead to data redundancy. Moreover, in order to fortify against any potential information leakage, encryption is implemented prior to deduplication. Convergent encryption (CE) stands as a prominent exemplar of this approach. Effectively integrating data auditing, deduplication, and encryption for wireless sensor devices is no trivial task. To efficiently and securely accommodate data while authenticating them through a heterogeneous framework, we present a novel remote data checking scheme, denoted as the VRDC scheme. This scheme empowers IoT data to be encrypted, updated, deduplicated, and audited, aligning with the imperatives of security, privacy, and efficiency. Through comprehensive security analysis, we establish that our VRDC scheme is fortified against potential threats. Our experimental findings highlight the efficiency of our approach in the realms of auditing, deduplication, and updates. Furthermore, the evidence highlights the potential for optimization within our scheme when compared to related works. This is achieved through the careful management of dynamic update scales within a file. Ying Xie 0008, Ke Huang 0002, Sheng Yuan, Xiong Li 0002, Fagen Li |
IEEE Internet Things J. | 4 |
| 2024 | Two-Phase Sparsification With Secure Aggregation for Privacy-Aware Federated LearningabstractAs a typical privacy-aware machine learning paradigm, federated learning (FL) provides facilities to individually train edge clients with their private data and aggregate the central global model. In this way, privacy leakage can be prevented. Massive communication overhead caused by exchanging updated weights between clients and the server is one of the main obstacles in this strategy. Prior work advocates compressing the weights by employing quantization, gradient sparsification, and knowledge distillation approaches. However, most of them cannot be readily applied to secure aggregation in privacy-aware FL. Some research has made great progress in directly utilizing benchmark secure aggregation protocols on top of the non-privacy-aware FL. Graph-based and gradient-based sparsification has been widely adopted in previous studies. However, the results of reducing communication costs are still unsatisfactory. In this paper, we present a novel communication-efficient privacy-ware FL algorithm from a distinct perspective. We design a new Two-Phase Sparsification with Secure Aggregation (TPSSA) algorithm. In the subnetwork phase, we identify sparse subnetworks by freezing the initial random weights in sufficiently overparametrized networks. All edge clients collaboratively train to discover their subnetwork inside a dense randomly weighted neural network. Then the server aggregates to compute the global model. In the gradient phase, for each pair of edge clients, we introduce pairwise multiplicative random masks to identify the sparsification pattern. Then updates from surviving clients can be correctly cancelled out during the aggregation process in the server. Theoretical analysis reveals convergence, privacy and performance guarantee. We show improvements in accuracy, communication, and computation over traditional and sparsified secure aggregation benchmarks on two real-world datasets. Xiong Li 0002, Wei Liang 0005, Pandi Vijayakumar, Fayez Alqahtani 0001, Amr Tolba |
IEEE Internet Things J. | 2 |
| 2024 | RPIFL: Reliable and Privacy-Preserving Federated Learning for the Internet of Things
Ruijin Wang, Jinshan Lai, Xiong Li 0002, Donglin He, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 3 |
| 2024 | CESA: Communication efficient secure aggregation scheme via sparse graph in federated learningabstractAs a distributed learning paradigm , federated learning can be effectively applied to the decentralized system since it can resolve the “data island” problem. However, it is also vulnerable to serious privacy breaches . Although existing secure aggregation technique can address privacy concerns, they also incur significant additional computation and communication costs. To address these challenges, this paper offers a C ommunication E fficient S ecure A ggregation scheme. Firstly, the central server uses the communication delay between terminals as the weight of the fully terminal-connected graph to transform it into a sparse connected graph based on the minimal spanning tree. Secondly, instead of relying on central server for key advertisement , the terminals advertise keys via a neighboring terminal forwarding approach based on sparsely graph. Thirdly, we propose using the central server for auxiliary advertising to address unexpected terminal dropout. Simultaneously, we theoretically demonstrate our scheme’s security and have lower computation and communication costs. Experiments show that CESA can reduce the running time by 28.2% without sacrificing security and model accuracy compared to conventional secure aggregation when there are 10 terminals in the system. Ruijin Wang, Xiong Li 0002, Jinshan Lai, Fengli Zhang, Xikai Pei, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 3 |
| 2024 | Monero With Multi-Grained RedactionabstractMonero is a privacy-centric cryptocurrency that allows users to obscure their transactions with multiple input and output addresses. Current research on Monero mainly focuses on identifying design vulnerabilities or optimizing towards stronger privacy, security, etc. For example, improving the design of ring confidential transaction (RingCT) protocol proposed by Noether et al. As revealed by Ali et al. in USENIX 2016, new blockchains have inadequate nodes and network computing resources to resist powerful attack (e.g., 51% attack). Obviously, Monero blockchain is not an exception. Ateniese et al. proposed the notion of redactable blockchain in EuroS$ \& amp;$P 2017, which begins the trend of formalizing blockchain with extra cryptographic primitives. The motivation is to turn an immutable blockchain into a mutable ledger by adapting the blockchain design and integrating with new cryptographic schemes. In such a setting, users could use their private keys to perform the secure multi-party computation to reverse blockchain history. The idea of redactable blockchain has attracted many researchers to pursuit this topic. However, few works have considered the privacy-preserving setting. Even fewer have practised their designs in an actual cryptocurrency. In this paper, we seek to adapt the RingCT protocol with several building blocks. Our proposal achieves most of the desired properties for blockchain redaction. It allows multiple tracing authorities to collaboratively trace users’ identities, and a system manager to perform multi-grained (including block-level, transaction-level, accumulator-level and commitment-level) redaction on block contents. Our proposal can be seen as an extension of RingCT protocol. We give rigorous security requirements and comprehensive analysis of our scheme. The performance evaluation suggested that our scheme suffers from some unscalabilities in large-scale implementations. A more elegant design to achieve stronger security and ideal scalability is deemed as a challenging and interesting future work. Ke Huang 0002, Yi Mu 0001, Fatemeh Rezaeibagha, Xiaosong Zhang 0001, Xiong Li 0002 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | AnotherMe: A Location Privacy Protection System Based on Online Virtual Trajectory GenerationabstractNowadays, location-based services (LBS) are becoming increasingly important and popular. However, many LBSs are probable to collect the location information of users, which leads to the leakage of location privacy. To address this problem, dummy-based schemes have been proposed by researchers. Nevertheless, most of them only consider semantic information instead of points of interest (POIs), so the virtual trajectories may be detected by advanced data mining techniques. Besides, some of them are offline or non-local, which are not suitable for online LBS scenarios. In this paper, we design AnotherMe, an online and local location privacy-preserving system based on virtual trajectory generation, and develop the system on Android and iOS platforms. The AnotherMe system has two main functions. One is to generate virtual users located in different cities by imitating the real user's moving pattern and mapping the real user's POIs, and the other is to generate virtual trajectories that are indistinguishable from real trajectories with the help of Amap API. Therefore, the AnotherMe system can preserve continuous location privacy, and even advanced data mining techniques are difficult to distinguish between the real trajectory and the corresponding virtual trajectory. Due to low response time and battery consumption, the AnotherMe system is practical for location privacy protection. Furthermore, experimental results show that the virtual trajectories generated by our solution are more indistinguishable from real trajectories than similar solutions, and the average recognition rate of virtual trajectories is 53.8%, which is close to random guessing (50%). Yuanfei Li, Xiong Li 0002, Xiangyang Luo 0001, Zhetao Li, Hongwei Li 0001, Xiaosong Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | An Unsupervised Image Dehazing Method Using Patch-Line and Fuzzy Clustering-Line PriorsabstractOutdoor images taken in haze usually exhibit contrast reduction, color distortion, and detail loss. Removing the haze from a given image is a tough issue owing to its highly ill-posed property. To restore the haze-free image effectively, we develop an unsupervised dehazing method using patch-line and fuzzy clustering-line priors in this paper. The method obtains the dehazed image by inversely solving the atmospheric scattering model, which involves in estimating two key parameters, including atmospheric light and scene transmission. First, the orientation of atmospheric light is achieved by using a patch-line prior. Then, a quadtree subspace hierarchical searching scheme is designed to get the magnitude by calculating the differences between the mean and variance of each component for local regions. Besides, a fuzzy clustering-line prior combined with a guided filtering is proposed to estimate the scene transmission for each pixel. The proposed method can obtain the dehazed image directly without any training process and achieve much better performance than many existing ones with less space and time cost. Miao Liao, Xiong Li 0002, Shuanhu Di, Wei Liang 0005, Victor Chang 0001 |
IEEE Trans. Fuzzy Syst. | 3 |
| 2024 | MC-DSC: A Dynamic Secure Resource Configuration Scheme Based on Medical Consortium BlockchainabstractBlockchain technology, with its unique decentralized and tamper-resistant features, is being utilized to address the issue of information silos in traditional electronic healthcare. However, as healthcare data sources become increasingly complex and numerous, the limited scalability and transaction throughput of traditional blockchains result in challenges such as slow processing efficiency and vulnerability to attacks in modern healthcare blockchain systems. To address these issues, we propose a Dynamic Security Resource Configuration scheme based on Medical Consortium Blockchain (MC-DSC). This scheme allows for dynamic blockchain configuration based on the varying urgency levels of data, enhancing data processing efficiency. It ensures the security of the data processing process through identity control and data encryption methods. Experimental results demonstrate that, compared to existing blockchain configuration algorithms (SsHealth and Medge-Chain), the proposed scheme achieves approximately a 15% performance improvement by dynamically configuring the blockchain for three data types (secure, urgent, and normal). Additionally, the security module accounts for only 7% of the total time overhead, efficiently safeguarding the security of healthcare data while effectively handling data with different urgency levels. Wei Liang 0005, Siqi Xie, Kuanching Li, Xiong Li 0002, Xiaoyan Kui, Albert Y. Zomaya |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | A Robust Privacy-Preserving Data Aggregation Scheme for Edge-Supported IIoTabstractEdge-supported Industrial Internet of Things (IIoT) has received remarkable attention recently since edge computing can not only reduce bandwidth consumption but also decrease the response time of industrial systems. However, the sensed data in the industrial environment is considered private. Thus, the data cannot be directly aggregated at the server due to privacy leakage. Although several privacy-preserving-aggregated schemes have been proposed, their security goals are not strong enough. Besides, most schemes are inefficient for resource-constrained devices. Aiming at solving the abovementioned problems, this article proposes a robust privacy-preserving data aggregation scheme for edge-supported IIoT. Specifically, the scheme adopts the Paillier cryptosystem to protect the privacy of users. Additionally, it utilizes ECDSA signature to support batch verification of multiple signatures from different signers, which significantly improves efficiency. Security analysis shows that the proposed scheme not only guarantees the integrity of the data and mutual authentication among entities but also realizes differential privacy protection. Extensive experiments are conducted to compare our scheme with the related work. The results show that our method outperforms most of the compared schemes with respect to communication. Moreover, compared with the related work, our scheme reduces the computational cost by an average of 6.7%, 16.9%, and 27.8% in sensor, edge server, and control center sides, respectively. Shuai Shang, Xiong Li 0002, Ke Gu 0002, Lei Li 0031, Xiaosong Zhang 0001, Pandi Vijayakumar |
IEEE Trans. Ind. Informatics | 2 |
| 2024 | A Cost-Efficient Anonymous Authenticated and Key Agreement Scheme for V2I-Based Vehicular Ad-Hoc NetworksabstractThe rise of smart cities is directly connected to the increasing use of vehicles. The growing vehicle utilization has driven the emergence of Vehicular Ad-hoc Networks (VANETs), facilitating instant information exchange among vehicles. The system provides essential information regarding road conditions, traffic patterns, and more relevant data. VANETs encompass two fundamental categories of communication exchanges, namely Vehicle-to-Vehicle (V2V) and Vehicle-to-Infrastructure (V2I). V2I technology facilitates the integration of cars and transportation infrastructure, enabling effective communication between vehicles and infrastructure. Nevertheless, the potential of V2I communication has various security concerns arising from prevalent security threats. Current authentication techniques encounter challenges regarding complexity, security, and privacy considerations. We designed a hash-based lightweight and anonymous authentication scheme to address the aforementioned restrictions and enhance the effectiveness of authentication in V2I architecture. This scheme effectively combines identity, password, and bio-metric to enhance resistance against impersonation, denial of service, and privileged insider attacks. The devised scheme distinguishes itself by a comparative analysis and security proofs, highlighting its superior capability in guaranteeing secure authentication in V2I communication. The comprehensive security analysis conducted formally and informally showcases the robustness of the proposed solution against several threats. The performance evaluation results show that our scheme demonstrates a decrease in the computational cost of 51.40% approximately and a reduction in communication overhead of around 22.57%. These results establish the efficiency and scalability of the proposed scheme as a viable solution for V2I architecture. Muhammad Asad Saleem, Xiong Li 0002, Khalid Mahmood 0002, Salman Shamshad, Mohammed J. F. Alenazi, Ashok Kumar Das |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2024 | Secure RFID-Assisted Authentication Protocol for Vehicular Cloud Computing EnvironmentabstractVehicular network technology has made substantial advancements in recent years in the field of Intelligent Transportation Systems. Vehicular Cloud Computing (VCC) has emerged as a novel paradigm with a substantial increase in data exchange within Vehicular ad-hoc networks (VANETs). VCC integrates cloud computing, vehicular networking, and Internet of Things (IoT) technologies. It enables Infrastructure-to-Vehicle (I2V), Vehicle-to-Vehicle (V2V), and Vehicle-to-Device (V2D) communication. VCC optimizes vehicle, cloud infrastructure, and IoT resources while addressing significant communication security and vehicle-user privacy challenges. To address these issues, we developed an RFID-based authentication protocol for VCC based on a Henon map using a hash function. In addition, we also incorporated a Physical Unclonable Function (PUF) to resist physical tampering attacks. We validate the protocol’s security formally and informally. The formal security analysis is conducted through a widely used RoR model. We use the Scyther simulation tool to verify the proposed protocol’s security against various attacks. Moreover, we compare the performance of our protocol with similar existing protocols across important performance parameters such as communication and computation overheads and security attributes. The proposed protocol yields substantial improvements, demonstrating a 40.74% reduction in computation overhead and a 13.03% decrease in communication overhead as compared to related protocols, delivering both enhanced performance and resource efficiency. The analysis demonstrates its capacity to support secure communication in the VCC environment and satisfy desirable security attributes. Muhammad Asad Saleem, Xiong Li 0002, Khalid Mahmood 0002, Tayyaba Tariq, Mohammed J. F. Alenazi, Ashok Kumar Das |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2024 | REC-Fed: A Robust and Efficient Clustered Federated System for Dynamic Edge NetworksabstractAs a promising approach, Clustered Federated Learning (CFL) enables personalized model aggregation for heterogeneous clients. However, facing dynamic and open edge networks, previous CFL rarely considers the impact of dynamic client data on clustering validity, or sensitively identifies low-quality parameters from highly heterogeneous client models. Moreover, the device heterogeneity in each cluster leads to unbalanced model transmission delay, thus reducing the system efficiency. To tackle the above issues, this paper proposes a Robust and Efficient Clustered Federated System (REC-Fed). First, a Hierarchical Attention based Robust Aggregation (HARA) method is designed to realize layer-wise model customization for clients, meanwhile keeping the clustering validity under dynamic client data distribution. In addition, the fine-grained parameter detection in HARA provides a natural advantage to detect low-quality parameters, which improves the robustness of CFL systems. Second, to realize efficient synchronous model transmission, an Adaptive Model Transmission Optimization (AMTO) is proposed to jointly optimize the model compression and bandwidth allocation for heterogenous clients. Finally, we theoretically analyze the convergence of REC-Fed and conduct experiments on several personalization tasks, which demonstrate that our REC-Fed has significant improvement on flexibility, robustness and efficiency. Jialin Guo, Zhetao Li, Anfeng Liu, Xiong Li 0002, Ting Chen 0002 |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | Blockchain-Based Data Deduplication and Distributed Audit for Shared Data in Cloud-Fog Computing-Based VANETsabstractWith the extensive deployment of vehicular ad-hoc networks (VANETs), it becomes an inevitable choice to provide enhanced in-vehicle services for uploading a vast amount of shared vehicular data to cloud storage. However, there is still a lack of effective deduplication and audit methods for cloud-stored data in VANET scenarios. To address the securities of cloud-stored data in VANETs, we propose a blockchain-based data deduplication and distributed audit scheme for shared data under cloud-fog computing-based VANETs in this paper. In our scheme, we construct a distributed audit model for VANETs, where road side units (RSUs) are partitioned as multiple management areas. Each management area can solely make their consensus for data integrity verification to audit the cloud storage provider without depending on any third-party auditors (TPAs). Also, we establish a blockchain-based monitoring mechanism maintained by the fog servers to ensure the integrity of the uploading and auditing records and enable related entities within the system to verify corresponding audit results (or records). Furthermore, we propose a lightweight dual-verifier structure to adapt to resource-constrained VANET scenarios. Through our dual-verifier mechanism, our scheme can effectively resist proof-replay attacks. Related theoretical analysis and experimental results show our data deduplication and distributed audit scheme is efficient and effective for VANET scenarios. Ke Gu 0002, Yi Wang 0094, Xiong Li 0002, Jianming Zhang 0003 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2024 | Dynamic Outsourced Data Audit Scheme for Merkle Hash Grid-Based Fog Storage With Privacy-PreservingabstractThe security of fog computing has been researched and concerned with its development, where malicious attacks pose a greater threat to distributed data storage based on fog computing. Also, the rapid increasing on the number of terminal devices has raised the importance of fog computing-based distributed data storage. In response to this demand, it is essential to establish a secure and privacy-preserving distributed data auditing method that enables security protection of stored data and effective control over identities of auditors. In this paper, we propose a dynamic outsourced data audit scheme for Merkle hash grid-based fog storage with privacy-preserving, where fog servers are used to undertake partial outsourced computation and data storage. Our scheme can provide the function of privacy-preserving for outsourced data by blinding original stored data, and supports data owners to define their auditing access policies by the linear secret-sharing scheme to control the identities of auditors. Further, the construction of Merkle hash grid is used to improve the efficiency of dynamic data operations. Also, a server locating approach is proposed to enable the third-part auditor to identify specific malicious data fog servers within distributed data storage. Under the proposed security model, the security of our scheme can be proved, which can further provide collusion resistance and privacy-preserving for outsourced data. Additionally, both theoretical and experimental evaluations illustrate the efficiency of our proposed scheme. Ke Gu 0002, Xingqiang Wang, Xiong Li 0002 |
IEEE Trans. Sustain. Comput. | 3 |
| 2023 | SD-Transformer: A System-Level Denoising Transformer for Encrypted Traffic Behavior IdentificationabstractEncrypted behavior identification is crucial in ensuring network security. Most existing solutions in this area recognize behavior by observing encrypted traffic patterns between users and applications. However, such solutions rely on features such as timing, packet sequence, and packet length, which may be affected by network fluctuations, and thus have weak generalization capabilities. In this paper, we first analyze the impact of noise on the network, such as parameters and network delays during API requests. By combining a noise-based traffic collector with an improved Transformer model, we propose a system-level denoising Transformer method for encrypted traffic behavior identification called SD-Transformer. It is able to filter system noise by utilizing an attention mechanism and targeted noise packet masking. We evaluate the performance of SD-Transformer on three datasets, i.e., ISCX-VPN, USTC-TFC, and our generated noise-containing Web Application Traffic dataset (WEB-APP), and it achieves an accuracy of 95.97%, 93.59%, and 99.82%, respectively. Besides, compared to the state-of-the-art methods, the accuracy is increased to 96.82% (↑16.0%) and 85.41% (↑17.76%) on the WEB-APP dataset under different API parameters and network latency environments, respectively. Additionally, the target mask of the SD-Transformer achieves 96.45% accuracy with an improvement of 11.29% on the WEB-APP dataset with latency. Yizhuo Zhao, Yukun Zhu, Xiong Li 0002, Rui-dong Chen, Mohammad S. Obaidat, Pandi Vijayakumar |
GLOBECOM | 3 |
| 2023 | Batch Verification-Based Anonymous and Traceable Data Sharing Scheme in Industrial Internet of ThingsabstractThe Industrial Internet of Things (IIoT) has become increasingly significant, facilitating the development of production and manufacturing, etc. It will generate a large amount of valuable private industrial data, which can help managers draw up strategies. Data sharing technology is utilized to enable the data to flow among the participants. However, several problems, such as privacy breaches, behavior profile building, and collusion attacks, hinder this data sharing. To address these problems, we introduce a batch verification-based anonymous and traceable data sharing scheme in the Industrial Internet of Things. We formally prove that our scheme realizes security attributes of anonymity, confidentiality, unforgeability, etc. The experimental results show that our scheme costs less than 60% of the time compared to other related work. Xiong Li 0002, Baojin Wang, Xiaosong Zhang 0001 |
ICPADS | 2 |
| 2023 | Ubiquitous intelligent federated learning privacy-preserving scheme under edge computing
Jinshan Lai, Ruijin Wang, Xiong Li 0002, Pandi Vijayakumar, Brij B. Gupta, Wadee Alhalabi |
Future Gener. Comput. Syst. | 4 |
| 2023 | GTxChain: A Secure IoT Smart Blockchain Architecture Based on Graph Neural NetworkabstractWith the expansion of scale, the Internet of Things (IoT) suffers more and more security threats, and vulnerability and sensitivity to attacks are also increasing. As a distributed and secure network architecture, Blockchain is suitable for protecting the security and privacy of the IoT. In this article, we propose a secure smart blockchain IoT architecture based on Graph Neural Networks (GNN) named GTxChain, using a distributed intelligent prophecy machine to obtain off-chain data and construct the transaction data structure of the blockchain through the blockchain-directed acyclic graph (DAG). In the off-chain transaction and off-chain storage part, we use the lightning network, improved IPFS and GNN to obtain transaction information and continuously update the blockchain network and blockchain for transaction verification and other operations. GTxChain employs an IPFS storage architecture to enhance user privacy and reduce data processing time. Compared to other blockchain architectures, it improves by 10.51% and has better efficiency and stability in terms of Merkle-proof time overhead. Experimental results show that the GTxChain architecture can effectively ensure the IoT’s trustworthiness, security, and privacy (TSP). Jiahong Cai, Wei Liang 0005, Xiong Li 0002, Kuanching Li, Zhenwen Gui, Muhammad Khurram Khan |
IEEE Internet Things J. | 3 |
| 2023 | GCDroid: Android Malware Detection Based on Graph Compression With Reachability Relationship Extraction for IoT DevicesabstractWith the widespread popularity of Internet of Things (IoT) devices based on the Android system, the amount of Android malware targeting IoT devices continues to increase, causing great economic losses. Accordingly, efficient and accurate Android malware detection methods are particularly important. Recently, many Android malware detection and classification methods have been proposed, but most of them ignore the deep relationships among software. In this article, we propose a graph compression algorithm with reachability relationship extraction (GCRR) and design an Android malware detection and classification method called GCDroid based on this algorithm. A theoretical analysis shows that GCRR can reasonably extract the reachability relationships among APKs and compress a large heterogeneous APK–API relationship graph into a homogeneous APKs graph. Experiments show that GCDroid based on GCRR greatly reduces the required time consumption while improving detection accuracy. Compared with the existing excellent static Android malware detection methods, GCDroid improves upon their detection accuracies by 1.53%–39.13% on different data sets and outperforms the benchmark methods in terms of Android malware classification. Furthermore, compared with those of the baseline methods that are similar to GCDroid, GCDroid’s time consumption for model training and other aspects is only one-tenth as high or even less. Weina Niu, Xiong Li 0002, Xiaosong Zhang 0001 |
IEEE Internet Things J. | 5 |
| 2023 | An authentication and signature scheme for UAV-assisted vehicular ad hoc network providing anonymity
Qi Xia 0001, Xiong Li 0002, Jianbin Gao, Xiaosong Zhang 0001 |
J. Syst. Archit. | 3 |
| 2023 | AKN-FGD: Adaptive Kohonen Network Based Fine-Grained Detection of LDoS AttacksabstractLow-rate denial of service (LDoS) attacks exploit the security vulnerabilities of network protocols adaptive mechanisms to launch periodic bursts. These attacks result in the severe destruction of the quality of service of TCP applications. Therefore, detection of LDoS attacks is a concern among scientific communities. However, the existing coarse-scale detection methods yield poor detection performance and adaptability. To achieve the accurate detection of LDoS attacks, an adaptive Kohonen Network based fine-grained detection (AKN-FGD) model for LDoS attacks is proposed. Based on the burst and periodicity characteristics of attack traffic, the Smith-Waterman (SW) algorithm is used to estimate the pulse period, which is the length of the detection unit. Subsequently, cluster analysis is performed for each detection unit using the adaptive Kohonen network (AKN) algorithm because the discreteness of traffic suffering from LDoS attacks is more pronounced than that of legitimate traffic. Finally, the existence of LDoS attacks can be verified in view of a novel decision metric, denoted as the anomaly degree, based on the clustering results. We conducted experiments not solely in traditional networks using NS3 and in a test-bed environment but also in a software-defined network (SDN), with accuracies of 99.7%, 99.8%, and 95.6% for detecting LDoS bursts, respectively. The experimental results show that the AKN-FGD scheme not only enables accurate fine-grained detection, that is, it can detect every attack burst, but also estimates the start and end times of the attacks. Moreover, we have compared the AKN-FGD scheme with some other detection methods, and a comparison of the results show that our proposed approach displays better detection performance. Dan Tang 0003, Xiyin Wang, Xiong Li 0002, Pandi Vijayakumar, Neeraj Kumar 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | TD-Net: A Hybrid End-to-End Network for Automatic Liver Tumor Segmentation From CT ImagesabstractLiver tumor segmentation plays an essential role in diagnosis and treatment of hepatocellular carcinoma or metastasis. However, accurate and automatic tumor segmentation remains a challenging task, owing to vague boundaries and large variations in shapes, sizes, and locations of liver tumors. In this paper, we propose a novel hybrid end-to-end network, called TD-Net, which incorporates Transformer and direction information into convolution network to segment liver tumor from CT images automatically. The proposed TD-Net is composed of a shared encoder, two decoding branches, four skip connections, and a direction guidance block. The shared encoder is utilized to extract multi-level feature information, and the two decoding branches are respectively designed to produce initial segmentation map and direction information. To preserve spatial information, four skip connections are used to concatenate each encoder layer and its corresponding decoder layer, and in the fourth skip connection a Transformer module is constructed to extract global context. Furthermore, a direction guidance block is well-designed to rectify feature maps to further improve segmentation accuracy. Extensive experiments conducted on public LiTS and 3DIRCADb datasets validate that the proposed TD-Net can effectively segment liver tumor from CT images in an end-to-end manner and its segmentation accuracy surpasses those of many existing methods. Shuanhu Di, Yuqian Zhao 0001, Miao Liao, Fan Zhang 0106, Xiong Li 0002 |
IEEE J. Biomed. Health Informatics | 5 |
| 2023 | Privacy-Preserving Federated Learning for Internet of Medical Things Under Edge ComputingabstractEdge intelligent computing is widely used in the fields, such as the Internet of Medical Things (IoMT), which has advantages, including high data processing efficiency, strong real-time performance and low network delay. However, there are many problems including privacy disclosure, limited calculation force, as well as scheduling and coordination issues. Federated learning can greatly improves training efficiency. However, due to the sensitive nature of the healthcare data, the aforementioned approach of transferring the patient's data to the servers may create serious security and privacy issues. Therefore, this article proposes a Privacy Protection Scheme for Federated Learning under Edge Computing (PPFLEC). First of all, we propose a lightweight privacy protection protocol based on a shared secret and weight mask, which is based on a random mask scheme of secret sharing. It is more accurate and efficient than,homomorphic encryption. It can not only protect gradient privacy without losing model accuracy, but also resist equipment dropping and collusion attacks between devices. Second, we design an algorithm based on a digital signature and hash function, which achieves the integrity and consistency of the message, as well as resisting replay attacks. Finally, we propose a periodic average training strategy, compared with differential privacy to prove that our scheme is 40 % faster in efficiency than in deferential privacy. Meanwhile, compared with federated learning, we can achieve the same efficiency under the condition of ensuring safety. Therefore, our scheme can work well in unstable edge computing environments such as smart healthcare. Ruijin Wang, Jinshan Lai, Xiong Li 0002, Pandi Vijayakumar, Marimuthu Karuppiah |
IEEE J. Biomed. Health Informatics | 4 |
| 2023 | An Identity-Based Data Integrity Auditing Scheme for Cloud-Based Maritime Transportation SystemsabstractWith the development of Internet of Things (IoT)-enabled Maritime Transportation Systems (MTS), massive data generated in the system not only requires to be stored reliably and cheaply, but also needs to be analyzed timely. The Cloud-based Maritime Transportation Systems (CMTS) allow users to upload the data without worrying about the price, capacity, location and so on. However, CMTS also brings some security issues, where the integrity protection of outsourced data is one of the most important issues since it is crucial for the safety, reliability and efficiency of sea lanes. To solve this problem, we propose an identity-based dynamic data integrity auditing scheme for CMTS. Our scheme decreases the burden of key management and improves the auditing efficiency by batch auditing. Besides, our scheme also supports dynamic operations on the outsourced data for CMTS. The security analysis shows that our scheme can ensure the feature of storage correctness and resist common attacks. In addition, the performance comparison results with other related schemes show that our scheme not only has the lowest computational cost on all entities, but also greatly reduces the communication overhead of the auditing phase. Therefore, our scheme is very suitable for data integrity verification in CMTS. Xiong Li 0002, Shuai Shang, Shanpeng Liu, Ke Gu 0002, Mian Ahmad Jan, Xiaosong Zhang 0001, Fazlullah Khan |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2023 | An Efficient and Physically Secure Privacy-Preserving Key-Agreement Protocol for Vehicular Ad-Hoc NetworkabstractThe popularity of vehicles promotes the evolution of smart cities. This development makes vehicular ad-hoc network (VANET) a widely used inter-vehicular communication to obtain information about road conditions, speed, vehicle location and traffic congestion. Such a public network is vulnerable to different security threats. Overall, the security of private data in VANET is a critical task. It has been observed that various authentication protocols have been devised for VANETs. However, most of the proposed protocols are not secure and reliable because of different security threats, including denial of service, replay, forgery and impersonation attacks, etc. Furthermore, the existing protocols used extra communication overhead and computational cost, so they become infeasible for resource-constrained environments. In this article, we design a lightweight and secure privacy-preserving key agreement protocol for VANETs using the hashing technique, which provides an efficient and secure data transmission mechanism over a public communication channel. Detailed security analysis shows that the proposed protocol is secure against various attacks. To evaluate the performance of the protocol, we simulate key cryptographic operations of vehicles, a roadside unit, and a trusted party agent on Arduino, low-end and high-end devices, respectively. The experimental results show that compared with the other related protocols, the computational cost and communication overhead of our protocol are reduced on average by 8.797% and 22.06 %, respectively. Additionally, simulation results on NS3 show that our protocol consistently achieves a packet delivery ratio higher than 99.91 %. Therefore, our protocol is secure and reliable for VANET environment. Muhammad Asad Saleem, Xiong Li 0002, Muhammad Faizan Ayub, Salman Shamshad, Fan Wu 0003, Haider Abbas |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2023 | Dual Attribute-Based Auditing Scheme for Fog Computing-Based Data Dynamic Storage With Distributed Collaborative VerificationabstractCompared with cloud computing-based data storage, distributed data storage in fog computing is more vulnerable to malicious attacks. So, it is very necessary to provide a secure distributed auditing mechanism with protecting the identity privacy of data owners and controlling the identities of auditors under fog computing-based data storage. In this paper, we propose a dual attribute-based auditing scheme for fog computing-based data dynamic storage. Our auditing scheme can protect the identity privacy of data owners, and provide an attribute-based access control for corresponding audits with a distributed collaborative verification between related fog servers. In our scheme, a data owner can securely upload his divided and blinded file blocks with corresponding block authenticators (related with his attribute set) to related fog servers. To prevent malicious auditors from consuming system resources by abusing audit requests, the data owner can provide an attribute-based access control for corresponding audits, where the data owner specifies the attribute set of corresponding auditors who have the right to check the integrity of related data. Further, a distributed collaborative verification mechanism between related fog servers is constructed to reduce the disadvantages of centralized verification, where the Shamir’s secret-sharing method is used to decompose the picked blinding factor as the shared sub-secrets sent to each fog server respectively. Compared with cloud computing-based data storage, our collaborative verification mechanism can implement distributed auditing consent of stored data between multiple fog servers. Our auditing scheme can further audit out specific suspicious fog servers. Additionally, we provide a dynamic data operation mechanism to efficiently support the updating of users’ data under fog computing-based data storage. Furthermore, related theoretical analysis and experimental evaluation show our scheme is secure and efficient. Ke Gu 0002, Wenbin Zhang 0002, Xingqiang Wang, Xiong Li 0002, Weijia Jia 0001 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2023 | Nondeterministic Evaluation Mechanism for User Recruitment in Mobile Crowd-SensingabstractBased on the Internet of Behavior (IoB), mobile crowd-sensing (MCS) utilizes the Internet of Things (IoT) to recruit users by analyzing behavioral patterns. MCS is widely used in numerous large-scale and complex monitoring services, but it cannot provide stable and high-quality services due to nondeterministic user mobility and behaviors, which has a vital impact on recruiting high-quality users. In this article, a stochastic semi-algebraic hybrid system (SSAHS) model is constructed to characterize the user mobility and behaviors of the MCS systems. Based on the definition of probabilistic path and task execution rate, a nondeterministic evaluation mechanism is proposed to measure nondeterministic user mobility and behaviors and to give the probability of the user completing the MCS task under the specified time bound and space conditions. The greater the probability is, the higher the quality of the user. Furthermore, a user recruitment scheme based on a nondeterministic evaluation mechanism (NUR) is developed. The NUR employs historical user data to predict user mobility and behaviors; high-quality users are recruited to quickly upload reliable sensing data. We conduct simulation experiments based on a real-world user trace dataset, Geolife.The results show that compared with competing recruitment strategies, NUR achieves a higher quality of service for the same MCS sensing tasks. Ying Xie 0008, Mohammad S. Obaidat, Xiong Li 0002, Pandi Vijayakumar |
ACM Trans. Sens. Networks | 4 |
| 2023 | Privacy-Preserving Electricity Data Classification Scheme Based on CNN Model With Fully HomomorphismabstractData classification of users’ electricity consumption provides an in-depth analysis for users’ electricity consumption status, which plays a vital role in the management and distribution of electric energy. So, some data classification methods have been proposed to solve the classification problem of electricity consumption data. However, plaintext-based data classification may bring about the privacy leakage of electricity consumption data. In this paper, we propose a privacy-preserving classification scheme for electricity consumption data under fog computing-based smart metering system, which is based on convolutional neural network (CNN) model with fully homomorphic method (CKKS). The target of our proposed scheme is to solve the leakage problem of private electricity consumption data during the classification procedure. In our scheme, an improved K-means-based labeling algorithm is constructed to process historical electricity consumption data, which is used as the sample data to train the CNN classification model by cloud server. Also, the fog nodes are only permitted to obtain the related ciphertext parameters of the trained CNN model, and perform the classification of ciphertext-based electricity consumption data generated by fully homomorphic method. Based on the classical testing data, the experimental results show that our proposed classification scheme can provide the high classification accuracy of electricity data while protecting the privacy of electricity data. Zhuoqun Xia, Dan Yin, Ke Gu 0002, Xiong Li 0002 |
IEEE Trans. Sustain. Comput. | 4 |
| 2022 | A Stochastic Gradient Descent Algorithm Based on Adaptive Differential Privacy
Yupeng Deng 0003, Xiong Li 0002, Jiabei He 0001, Wei Liang 0005 |
CollaborateCom (2) | 2 |
| 2022 | Defending Data Poisoning Attack via Trusted Platform Module and Blockchain OracleabstractWith the development of Internet of Things (IoT) technology, the digital pill has been employed as an IoT system for emerging remote health monitoring to detect the impact of medicine intake on patients’ biological index. The medical data is then used for model training with federated learning. An adversary can launch poisoning attacks by tampering with patients’ medical data, which will lead to misdiagnosis of the patients’ conditions. Lots of studies have been conducted to defend against poisoning attacks based on blockchain or hardware. However, 1) Blockchain-based schemes can only exploit on-chain data to deal with poisoning attacks due to the lack of off-chain trusted entities. 2) Typical hardware-based schemes have the bottleneck of single point of failure. To overcome these defects, we propose a defense scheme via multiple Trusted Platform Modules (TPMs) and blockchain oracle. Benefitting from multiple TPMs verification results, a distributed blockchain oracle is proposed to obtain off-chain verification results for smart contracts. Then, the smart contracts could utilize the off-chain verification result to identify poisoning attacks and store the unique identifiers of the non-threatening IoT device immutably on the blockchain as a whitelist of federated learning participants. Finally, we analyze the security features and evaluate the performance of our scheme, which shows the robustness and efficiency of the proposed work. Mingyuan Huang, Xiong Li 0002, Ke Huang 0002, Xiaosong Zhang 0001 |
ICC | 3 |
| 2022 | TSHN: A Trajectory Similarity Hybrid Networks for Dummy Trajectory IdentificationabstractNowadays, people pay more and more attention to privacy protection with the continuous occurrence of data breaches. In location-based services, dummy trajectory generation is a popular location privacy protection method. However, this method is used by some malicious users for benefits, which results in economic losses and the waste of resources of the locationbased services provider. For this problem, dummy trajectory identification has been proposed by researchers. Nevertheless, with the continuous development of dummy trajectory generation algorithms, the existing dummy trajectory identification methods are unsuitable. In this paper, we propose a hybrid neural network framework for dummy trajectory identification, called trajectory similarity hybrid networks (TSHN). The main idea of TSHN is to identify whether a target trajectory is a virtual trajectory according to the similarity score between historical trajectories and the target trajectory. For each historical trajectory of the user, the mobility and individual features are extracted to train TSHN. The trajectory similarity score generated by the TSHN is used to identify dummy trajectories. The experimental results show that our proposed TSHN can identify the dummy trajectory with an accuracy of 0.97, which significantly outperforms the existing dummy trajectory identification methods. Yuanfei Li, Xiong Li 0002, Shuai Shang, Xiaosong Zhang 0001 |
ICPADS | 2 |
| 2022 | Multi-dimensional Data Quick Query for Blockchain-Based Federated Learning
Jiaxi Yang 0003, Peng Xiangli, Xiong Li 0002, Xiaosong Zhang 0001 |
WASA (3) | 4 |
| 2022 | An energy-efficient and secure identity based RFID authentication scheme for vehicular cloud computing
Waseem Akram 0003, Khalid Mahmood 0002, Xiong Li 0002, Mazhar Sadiq, Zhihan Lyu, Shehzad Ashraf Chaudhry |
Comput. Networks | 3 |
| 2022 | A PUF-based lightweight authentication and key agreement protocol for smart UAV networksabstractAbstract With the advancement of information technology and the reduction of costs, the application of unmanned aerial vehicle (UAV) has gradually expanded from the military field to the industrial field and civilian field. It brings great convenience to people in surveillance, detection, transportation, emergency rescue etc. However, UAVs usually work in harsh natural environments, and their communication security confronts various challenges. Due to UAVs' limited resources, such as computing capability, storage space, and energy, traditional security protection schemes based on complex cryptographic algorithms are not suitable for UAV systems directly. Therefore, a two‐stage lightweight identity authentication and key agreement protocol for UAV is proposed in this paper. The entire process only uses hash and XOR operations, which significantly improves the authentication efficiency. Simultaneously, the physical unclonable function (PUF) is introduced and embedded into the UAV hardware to ensure UAV network communication security when a UAV suffers a physical capture attack. In the paper, the security of the proposed protocol is proved with Burrows–Abadi–Needham (BAN) logic, Real‐or‐Random (ROR) model, and AVISPA simulation tools. An informal security analysis is also provided to illustrate that the protocol satisfies the security requirements of UAV networks. Finally, the protocol is compared with other existing protocols regarding function properties, computation cost, and communication cost, which shows that the proposed protocol has effectiveness and practicality. Li Zhang 0096, Jianbo Xu, Mohammad S. Obaidat, Xiong Li 0002, Pandi Vijayakumar |
IET Commun. | 4 |
| 2022 | A Lightweight and Verifiable Access Control Scheme With Constant Size Ciphertext in Edge-Computing-Assisted IoTabstractAs an extension of cloud computing, edge computing has attracted the attention of academia and industry because of its characteristics of low latency, high bandwidth, and low energy consumption. However, due to limited terminal resources and insufficient security design, the edge computing environment still faces many challenges in terms of data security and privacy protection. Among them, how to effectively control access to outsourced data is one of the main issues. In this article, we propose a lightweight and verifiable ciphertext-policy attribute-based encryption (CP-ABE)-based multiauthority access control scheme for edge computing-assisted Internet of Things (IoT), which adopts the method of outsourcing decryption to mitigate the computational cost of data users with limited resources. In addition, our scheme realizes the feature of attribute revocation, and the design of the multiauthority mechanism enables our scheme to avoid the problem of key escrow. Therefore, our proposed scheme not only ensures data confidentiality but also can resist the collusion attack. Besides, our scheme is secure against the chosen plaintext attack in the random oracle model under the decision$q$-BDHE assumption. Finally, we compared our scheme with some related work in performance, and the results demonstrate that our scheme is efficient in computation and communication. Because our scheme greatly mitigates the overhead of data users, it is very suitable for edge computing supported IoT applications with restricted computation resources. Xiong Li 0002, Chaoyang Chen 0001, Qingfeng Cheng, Xiaosong Zhang 0001, Neeraj Kumar 0001 |
IEEE Internet Things J. | 1 |
| 2022 | A Privacy-Preserving Multidimensional Range Query Scheme for Edge-Supported Industrial IoTabstractEdge-supported Industrial Internet of Things (IIoT) has recently received significant attention since the edge computing can greatly improve the service quality of IIoT applications. However, edge servers are not fully trusted and are often deployed at the edge of the network. Therefore, there are some security challenges that need to be addressed. For edge-supported IIoT, a privacy-preserving range query is one of the most important functional requirements. Recently, some privacy-preserving range query solutions have been proposed in different fields. However, most of them only support single-dimensional range query, which are inefficient for the requirement of multidimensional range query. To address these problems, we propose a privacy-preserving multidimensional range query scheme for edge-supported IIoT, called Edge-PPMRQ, in this article. In Edge-PPMRQ, a novel range division algorithm is designed, through which the multidimensional ranges can be merged into one range, so as to achieve multidimensional range query through one query request. In addition, Edge-PPMRQ also supports the range queries for continuous, discontinuous, and arbitrary boundary ranges. The detailed security analysis proves that Edge-PPMRQ is privacy preserving for the query ranges, the query results, and the sensed data of IIoT devices. Furthermore, extensive comparison experiments also illustrate that Edge-PPMRQ is efficient in communication and computation. Shuai Shang, Xiong Li 0002, Rongxing Lu, Jianwei Niu 0002, Xiaosong Zhang 0001, Mohsen Guizani |
IEEE Internet Things J. | 2 |
| 2022 | An Efficient Certificateless Ring Signcryption Scheme With Conditional Privacy-Preserving in VANETs
Rui Guo 0005, Xiong Li 0002, Yinghui Zhang 0002, Xuelei Li |
J. Syst. Archit. | 3 |
| 2022 | A novel authentication scheme for edge computing-enabled Internet of Vehicles providing anonymity and identity tracing with drone-assistance
Fan Wu 0003, Xiong Li 0002, Xiangyang Luo 0001, Ke Gu 0002 |
J. Syst. Archit. | 2 |
| 2022 | A Verifiable Privacy-Preserving Machine Learning Prediction Scheme for Edge-Enhanced HCPSsabstractAs a highly integrated industrial system, human cyber-physical systems (HCPSs) provide accurate and high-quality services for Industry 5.0. In HCPSs, machine learning (ML) prediction provides reliable prediction results for users based on matured models, while security and privacy protection are considerable issues. In this article, based on the modified Okamoto–Uchiyama homomorphic encryption, we propose a verifiable privacy-preserving machine learning prediction scheme for the edge-enhanced HCPSs, which outputs the verifiable prediction results for users without privacy leakage. Specifically, a batch of prediction results can be verified at one time, which improves the efficiency of verification. Security analysis shows that our scheme protects the privacy of inputs, ML model, and prediction results. The experiment results demonstrate that the edge computing architecture remarkably alleviates the computational burden of the cloud server. Furthermore, compared with other related schemes, our scheme shows the best execution efficiency, and batch verification optimizes the performance by about 15% compared with single verification on the same scale. Xiong Li 0002, Jiabei He 0001, Pandi Vijayakumar, Xiaosong Zhang 0001, Victor Chang 0001 |
IEEE Trans. Ind. Informatics | 1 |
| 2022 | Imitation Learning Based Heavy-Hitter Scheduling Scheme in Software-Defined Industrial NetworksabstractTo realize flexible networking and on-demand topology reconstructing, software-defined industrial networks (SDINs) are increasingly embracing the flat structure. Similar to software defined networks (SDN), SDIN suffers from low traffic scheduling efficiency caused by large and imbalanced flows, known as the heavy hitters problem. Due to such heavy hitters, industrial networks may fail to satisfy application’s QoS requirements, which results in more severe damages. To improve flow scheduling efficiency under heavy hitters, this article introduces a novel imitation learning-based flow scheduling (ILFS) method. ILFS utilizes P4-based In-band Network Telemetry (INT) to collect fine-grained, real-time traffic data from SDIN’s data plane. In the control plane, it integrates the Generative Adversarial Imitation Learning (GAIL) model with a soft actor critic to preserve the experiences of flow, thereby better scheduling large flows. Our experiments thoroughly compare ILFS’s performance with several state-of-the-art traffic scheduling strategies. The results indicate that ILFS successfully controls the link bandwidth the utilization between 10$\%$and 80$\%$and significantly improves the average network throughput and link utilization rate. Yazhi Liu, Qianqian Wu 0005, Jianwei Niu 0002, Xiong Li 0002, Zheng Song 0001 |
IEEE Trans. Ind. Informatics | 4 |
| 2022 | An Efficient Privacy-Preserving Public Auditing Protocol for Cloud-Based Medical Storage SystemabstractThe booming Internet of Things makes smart healthcare a reality, while cloud-based medical storage systems solve the problems of large-scale storage and real-time access of medical data. The integrity of medical data outsourced in cloud-based medical storage systems has become crucial since only complete data can make a correct diagnosis, and public auditing protocol is a key technique to solve this problem. To guarantee the integrity of medical data and reduce the burden of the data owner, we propose an efficient privacy-preserving public auditing protocol for the cloud-based medical storage systems, which supports the functions of batch auditing and dynamic update of data. Detailed security analysis shows that our protocol is secure under the defined security model. In addition, we have conducted extensive performance evaluations, and the results indicate that our protocol not only remarkably reduces the computational costs of both the data owner and the third-party auditor (TPA), but also significantly improves the communication efficiency between the TPA and the cloud server. Specifically, compared with other related work, the computational cost of the TPA in our protocol is negligible and the data owner saves more than 2/3 of computational cost. In addition, as the number of challenged blocks increases, our protocol saves nearly 90% of communication overhead between the TPA and the cloud server. Xiong Li 0002, Shanpeng Liu, Rongxing Lu, Muhammad Khurram Khan, Ke Gu 0002, Xiaosong Zhang 0001 |
IEEE J. Biomed. Health Informatics | 1 |
| 2022 | Multi-Fogs-Based Traceable Privacy-Preserving Scheme for Vehicular Identity in Internet of VehiclesabstractInternet of Vehicles (IoV) is a variant of Vehicular Ad-Hoc Network (VANET), it is being developed as an important communication way between vehicles. However, when some traffic messages are collected in IoV, these messages are usually linked to specific identifiable information. Therefore, there exists the privacy-preserving problem of vehicular identities in IoV. On the other hand, if the private information of vehicles is fully protected in IoV, then the true vehicular identities cannot be determined because the transferred messages are not related with the specific information of vehicles. Then it will also lead to more security problems in IoV. Additionally, fog computing seamlessly integrates heterogeneous computing resources widely distributed in edge networks and then provides stronger computing services for users. Therefore, in this paper we propose a decentralized traceable privacy-preserving scheme for vehicular identity in fog computing-based IoV, where our scheme uses multiple fog servers to trace the specific identity and most likely trajectory of a vehicle by the collected data under certain conditions. In our scheme, the true identity of a vehicle is hidden to some related parameters generated by the certificate authority; further the secret sharing scheme is used to hide and trace the true identity of a vehicle. We construct a voting mechanism to generate the most reliable fog server, which is able to calculate the true identity and corresponding trajectory of a vehicle by reconstructing the polynomial based on the secret sharing scheme. Additionally, we analyze that our scheme can satisfy the security requirements, and formally prove that the data collection procedure is secure under the real-or-random model. Also, the experimental results show our scheme is efficient in IoV. Ke Gu 0002, Keming Wang, Xiong Li 0002, Weijia Jia 0001 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2022 | Self-Verifiable Attribute-Based Keyword Search Scheme for Distributed Data Storage in Fog Computing With Fast DecryptionabstractPresently many searchable encryption schemes have been proposed for cloud and fog computing, which use fog nodes (or fog servers) to partly undertake some computational tasks. However, these related schemes still retain cloud servers to undertake most computational tasks, which result in large communication costs between edge devices and cloud servers. Therefore, in this paper we propose a self-verifiable attribute-based keyword search scheme for distributed data storage (SV-KSDS) in full fog computing, where each decryption operation on the data required by a user must meet the negotiated decryption rule between fog servers. Our SV-KSDS scheme first provides attribute-based distributed data storage among fog servers through the$(w, \sigma)$threshold secret-sharing scheme, where fog servers can provide self-verifiable keyword search and data decryption for terminal users. Compared with the data storage in cloud computing, our scheme extends it to the distributed structure while providing fine-grained access control for distributed data storage through attribute-based encryption. The access control policy of our scheme is constructed on linear secret-sharing scheme, whose security is reduced to the decisional bilinear Diffie-Hellman assumption against chosen-keyword attack and the decisional${q}$-parallel bilinear Diffie-Hellman assumption against chosen-plaintext attack in the standard model. Based on theoretical analysis and practical testing, our SV-KSDS scheme generates less computation and communication costs, which further unloads some computational tasks from terminal users to fog servers so as to reduce computing costs of terminal users. Ke Gu 0002, Wenbin Zhang 0002, Xiong Li 0002, Weijia Jia 0001 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2022 | A Mutual Security Authentication Method for RFID-PUF Circuit Based on Deep LearningabstractThe Industrial Internet of Things ( IIoT ) is designed to refine and optimize the process controls, thereby leveraging improvements in economic benefits, such as efficiency and productivity. However, the Radio Frequency Identification ( RFID ) technology in an IIoT environment has problems such as low security and high cost. To overcome such issues, a mutual authentication scheme that is suitable for RFID systems, wherein techniques in Deep Learning ( DL ) are incorporated onto the Arbiter Physical Unclonable Function ( APUF ) for the secured access authentication of the IC circuits on the IoT, is proposed. The design applies the APUF-MPUF mutual authentication structure obtained by DL to generate essential real-time authentication information, thereby taking advantage of the feature that the tag in the PUF circuit structure does not need to store any essential information and resolving the problem of key storage. The proposed scheme also uses a bitwise comparison method, which hides the PUF response information and effectively reduces the resource overhead of the system during the verification process, to verify the correctness of the two strings. Security analysis demonstrates that the proposed scheme has high robustness and security against different conventional attack methods, and the storage and communication costs are 95.7% and 42.0% lower than the existing schemes, respectively. Wei Liang 0005, Songyou Xie, Da-Fang Zhang 0001, Xiong Li 0002, Kuanching Li |
ACM Trans. Internet Techn. | 4 |
| 2022 | Conditional Identity Privacy-preserving Authentication Scheme Based on Cooperation of Multiple Fog Servers under Fog Computing-based IoVsabstractInternet of vehicles (IoVs) is a variant of vehicular ad hoc network, which provides an efficient communication method for vehicles. However, some traffic messages usually include sensitive identity information, which is easy to bring about the leakage of vehicular identities during data communications. Further, if vehicular identities are fully protected, then it can lead to trusted authority cannot reveal the real identities of malicious vehicles, which incurs more security issues in IoVs. Therefore, in this article, we propose an efficient conditional identity privacy-preserving authentication scheme based on cooperation of multiple fog servers under fog computing-based IoVs, where fog servers are used to verify (authenticate) the legitimacy of vehicles without revealing their real identities. Further, an associated vehicular identity updating mechanism is constructed to solve the problem that some compromised fog servers may leak their stored verification information to pool real vehicular identities. Additionally, a malicious vehicular identity tracing mechanism is proposed to support related fog servers that receive signed false messages can trace the real identities of malicious vehicles. Compared with other related schemes, our scheme further improves its security. Experimental results show our scheme is efficient under fog computing-based IoVs. Zhuoqun Xia, Lingxuan Zeng, Ke Gu 0002, Xiong Li 0002, Weijia Jia 0001 |
ACM Trans. Internet Techn. | 4 |
| 2021 | An enhanced lightweight and secured authentication protocol for vehicular ad-hoc network
Tarak Nandy, Mohd Yamani Idna Bin Idris, Rafidah Md Noor, Ashok Kumar Das, Xiong Li 0002, Norjihan Binti Abdul Ghani, Sananda Bhattacharyya |
Comput. Commun. | 5 |
| 2021 | Cloud-based privacy- and integrity-protecting density peaks clustering
Haomiao Yang, Shaopeng Liang, Xiong Li 0002 |
Future Gener. Comput. Syst. | 4 |
| 2021 | On Security of an Identity-Based Dynamic Data Auditing Protocol for Big Data StorageabstractIn this article, we point out the security weakness of Shanget al.’s identity-based dynamic data auditing protocol for big data storage. Specifically, we identify that their protocol is vulnerable to a secret key reveal attack, i.e., the service provider (SP) can reveal the secret key of the data owner (DO) from the stored data. Further, SP can also generate a proof to pass the challenge of TPA (third party auditor) even if all block and tag pairs have been deleted. We hope that by identifying these design flaws, similar weaknesses can be avoided in future designs. Xiong Li 0002, Shanpeng Liu, Rongxing Lu, Xiaosong Zhang 0001 |
IEEE Trans. Big Data | 1 |
| 2021 | Designing Anonymous Signature-Based Authenticated Key Exchange Scheme for Internet of Things-Enabled Smart Grid SystemsabstractRecent technological evolution in the Internet of Things (IoT) age supports better solutions to magnify the management of the power quality and reliability concerns, and imposes the measures of a smart grid. In smart grid environment, a smart meter needs to securely access the services from a service provider via insecure channel. However, since the communication is via public channel, it imposes various security threats by an adversary. To deal with this, in this article we design a new anonymous signature-based authenticated key exchange scheme for IoT-enabled smart grid environment, called AAS-IoTSG. The dynamic smart meter addition phase is also permissible in AAS-IoTSG after initial deployment. The security of AAS-IoTSG has been tested rigorously using formal security analysis under the real-or-random (ROR) model which is one of the broadly-accepted standard random oracle models, formal security verification under the broadly-used automated validation of Internet security protocols and applications (AVISPA) tool and also using informal security analysis. Finally, an exhaustive comparative study unveils that AAS-IoTSG supports better security and functionality features and requires less communication and computation overheads as compared to the existing state-of-art authentication mechanisms in smart grid systems. Jangirala Srinivas, Ashok Kumar Das, Xiong Li 0002, Muhammad Khurram Khan, Minho Jo 0001 |
IEEE Trans. Ind. Informatics | 3 |
| 2021 | A Novel UAV-Enabled Data Collection Scheme for Intelligent Transportation System Through UAV Speed ControlabstractThe rapid and convenient travel of people and the timely transportation of goods depend on the correct decision of the Intelligent Transportation Systems (ITS). Due to the decision-making of ITS requires a large amount of data to support, UAV-enabled periodic data collection is an effective method. However, due to the limited resources of UAV, UAV cannot directly collect data from all storage devices, resulting in unfair data collection. Therefore, we propose a UAV Speed Control based Fairness Data Collection (USCFDC) scheme. First, since the fairness of data collection will affect the decision-making of ITS, a framework for controlling the flight speed of the UAV is proposed to improve the fairness of data collection. The flight speed of UAV will slow down in areas with a large number of nodes, thereby improving the fairness of data collection. Second, a novel method is proposed to maximize the amount of data collected by UAV from each node. With this method, the value of the amount of data will be used as the dichotomous value in the dichotomy algorithm, and the UAV must collect a certain amount of data from each node. The upper and lower limits of the dichotomy algorithm are adjusted according to the time duration for UAV to collect data. Compared with previous schemes, the fairness of data collection can be improved by a maximum of 15.89% under the same flight time of UAV. Besides, the energy consumption is reduced by 49.31%-52.55% and the flight time of the UAV is reduced by 48%-62.38% when the amount of collected data is the same. Xiong Li 0002, Jiawei Tan, Anfeng Liu, Pandi Vijayakumar, Neeraj Kumar 0001, Mamoun Alazab |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2020 | A privacy-preserving scheme with identity traceable property for smart grid
Fan Wu 0003, Xiong Li 0002, Saru Kumari |
Comput. Commun. | 2 |
| 2020 | MF-Adaboost: LDoS attack detection based on multi-features and improved Adaboost
Dan Tang 0003, Xiong Li 0002, Joel J. P. C. Rodrigues |
Future Gener. Comput. Syst. | 5 |
| 2020 | Logarithmic encryption scheme for cyber-physical systems employing Fibonacci Q-matrix
Tianqi Zhou, Jian Shen 0001, Xiong Li 0002, Chen Wang 0015, Haowen Tan |
Future Gener. Comput. Syst. | 3 |
| 2020 | Comments on "A Public Auditing Protocol With Novel Dynamic Structure for Cloud Data"abstractIn this paper, we discuss a security weakness of Shenet al.’s public auditing protocol for cloud data [IEEE Transactions on Information Forensics and Security, 12(10): 2402-2415, 2017.]. Specifically, we point out their protocol is vulnerable to a data privacy breach attack,i.e., an adversary, once he compromises the third-party auditor latently, can also obtain all data owners’ outsourced data by constructing appropriate challenges. As a result, it breaks the property of “privacy preserving”. We hope that by identifying this design flaw, similar weaknesses can be avoided in future designs. Xiong Li 0002, Shanpeng Liu, Rongxing Lu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | An attribute-based encryption scheme with multiple authorities on hierarchical personal health record in cloud
Rui Guo 0005, Xiong Li 0002, Dong Zheng 0001, Yinghui Zhang 0002 |
J. Supercomput. | 2 |
| 2019 | Pixel-wise depth based intelligent station for inferring fine-grained PM2.5
Teng Xi, Ye Tian 0008, Xiong Li 0002, Hui Gao 0002, Wendong Wang 0003 |
Future Gener. Comput. Syst. | 3 |
| 2019 | A caching and spatial K-anonymity driven privacy enhancement scheme in continuous location-based services
Shaobo Zhang 0001, Xiong Li 0002, Zhiyuan Tan 0001, Tao Peng 0011, Guojun Wang 0001 |
Future Gener. Comput. Syst. | 2 |
| 2019 | Lightweight IoT-based authentication scheme in cloud computing circumstance
Lu Zhou 0002, Xiong Li 0002, Kuo-Hui Yeh, Chunhua Su, Wayne Chiu |
Future Gener. Comput. Syst. | 2 |
| 2019 | Privacy Preserving Data Aggregation Scheme for Mobile Edge Computing Assisted IoT ApplicationsabstractAs the rapid development of 5G and Internet of Things (IoT) techniques, more and more mobile devices with specific sensing capabilities access to the network and large amounts of data. The traditional architecture of the cloud computing cannot satisfy the requirements, such as low latency, fast data access for IoT applications. Mobile edge computing (MEC) can solve these problems, and improve the execution efficiency of the system. In this paper, we propose a privacy preserving data aggregation scheme for MEC assisted IoT applications. In our model, there are three participants, i.e., terminal device (TD), edge server (ES), and public cloud center (PCC). The data generated by the TDs is encrypted and transmitted to the ES, then the ES aggregates the data of the TDs and submits the aggregated data to the PCC. At last, the aggregated plaintext data can be recovered by PCC through its private key. Our scheme not only guarantees data privacy of the TDs but also provides source authentication and integrity. Compared with traditional model, our scheme can save half of communication cost, and is very suitable for MEC assisted IoT applications. Xiong Li 0002, Shanpeng Liu, Fan Wu 0003, Saru Kumari, Joel J. P. C. Rodrigues |
IEEE Internet Things J. | 1 |
| 2019 | A provably secure and anonymous message authentication scheme for smart grids
Xiong Li 0002, Fan Wu 0003, Saru Kumari, Arun Kumar Sangaiah, Kim-Kwang Raymond Choo |
J. Parallel Distributed Comput. | 1 |
| 2019 | Secure Remote User Mutual Authentication Scheme with Key Agreement for Cloud Environment
Marimuthu Karuppiah, Ashok Kumar Das, Xiong Li 0002, Saru Kumari, Fan Wu 0003, Shehzad Ashraf Chaudhry, Niranchana Radhakrishnan |
Mob. Networks Appl. | 3 |
| 2019 | Efficient User Profiling Based Intelligent Travel Recommender System for Individual and Group of Users
Logesh Ravi, Subramaniyaswamy Vairavasundaram, Varadarajan Vijayakumar 0001, Xiong Li 0002 |
Mob. Networks Appl. | 4 |
| 2019 | Pattern Recognition Techniques for Non Verbal Human Behavior (NVHB)
Wankou Yang, Pritee Khanna, Xiong Li 0002 |
Pattern Recognit. Lett. | 4 |
| 2019 | Optimality criteria for fuzzy-valued fractional multi-objective optimization problem
Deepika Agarwal, Pitam Singh, Xiong Li 0002, Saru Kumari |
Soft Comput. | 3 |
| 2019 | Secure CLS and CL-AS schemes designed for VANETs
Pankaj Kumar 0006, Saru Kumari, Vishnu Sharma, Xiong Li 0002, Arun Kumar Sangaiah, SK Hafizul Islam |
J. Supercomput. | 4 |
| 2018 | Privacy-preserving scheme in social participatory sensing based on Secure Multi-party Cooperation
Ye Tian 0008, Xiong Li 0002, Arun Kumar Sangaiah, Edith C. H. Ngai, Zheng Song 0001, Lanshan Zhang, Wendong Wang 0003 |
Comput. Commun. | 2 |
| 2018 | Design and implementation of a multibiometric system based on hand's traits
Javad Khodadoust, Ali Mohammad Khodadoust, Xiong Li 0002, Saru Kumari |
Expert Syst. Appl. | 3 |
| 2018 | A secure chaotic map-based remote authentication scheme for telecare medicine information systems
Xiong Li 0002, Fan Wu 0003, Muhammad Khurram Khan, Jian Shen 0001, Minho Jo 0001 |
Future Gener. Comput. Syst. | 1 |
| 2018 | Self-healing group key distribution protocol in wireless sensor networks for secure IoT communications
Hua Guo 0001, Yandong Zheng, Xiong Li 0002, Zhoujun Li 0001, Chunhe Xia |
Future Gener. Comput. Syst. | 3 |
| 2018 | A robust biometrics based three-factor authentication scheme for Global Mobility Networks in smart city
Xiong Li 0002, Jianwei Niu 0002, Saru Kumari, Fan Wu 0003, Kim-Kwang Raymond Choo |
Future Gener. Comput. Syst. | 1 |
| 2018 | An elliptic curve cryptography based lightweight authentication scheme for smart grid communication
Khalid Mahmood 0002, Shehzad Ashraf Chaudhry, Syed Husnain Abbas Naqvi, Saru Kumari, Xiong Li 0002, Arun Kumar Sangaiah |
Future Gener. Comput. Syst. | 5 |
| 2018 | Pairing based anonymous and secure key agreement protocol for smart grid edge computing infrastructure
Khalid Mahmood 0002, Xiong Li 0002, Shehzad Ashraf Chaudhry, Syed Husnain Abbas Naqvi, Saru Kumari, Arun Kumar Sangaiah, Joel J. P. C. Rodrigues |
Future Gener. Comput. Syst. | 2 |
| 2018 | A lightweight and robust two-factor authentication scheme for personalized healthcare systems using wireless medical sensor networks
Fan Wu 0003, Xiong Li 0002, Arun Kumar Sangaiah, Saru Kumari, Liuxi Wu, Jian Shen 0001 |
Future Gener. Comput. Syst. | 2 |
| 2018 | A Robust and Energy Efficient Authentication Protocol for Industrial Internet of ThingsabstractThe Internet of Things (IoT) is an emerging technology and expected to provide solutions for various industrial fields. As a basic technology of the IoT, wireless sensor networks (WSNs) can be used to collect the required environment parameters for specific applications. Due to the resource limitation of sensor node and the open nature of wireless channel, security has become an enormous challenge in WSN. Authentication as a basic security service can be used to guarantee the legality of data access in WSN. Recently, Chang and Le proposed two authentication protocols for WSN for different security requirements. However, their protocol cannot provide proper mutual authentication and has other security and functionality defects. We present a three-factor user authentication protocol for WSN to remove the weaknesses of previous protocols. The security of the proposed protocol is analyzed, and the security, functionality and performance of our protocol are compared with other related protocols. The comparison results and simulation results by NS-3 show that the proposed protocol is robust and energy efficient for IoT applications. Xiong Li 0002, Jieyao Peng, Jianwei Niu 0002, Fan Wu 0003, Junguo Liao, Kim-Kwang Raymond Choo |
IEEE Internet Things J. | 1 |
| 2018 | A three-factor anonymous authentication scheme for wireless sensor networks in internet of things environments
Xiong Li 0002, Jianwei Niu 0002, Saru Kumari, Fan Wu 0003, Arun Kumar Sangaiah, Kim-Kwang Raymond Choo |
J. Netw. Comput. Appl. | 1 |
| 2018 | Using convolution control block for Chinese sentiment analysis
Xiong Li 0002, Qiuwei Yang, Jiayi Du, Arun Kumar Sangaiah |
J. Parallel Distributed Comput. | 2 |
| 2018 | A secure mutual authenticated key agreement of user with multiple servers for critical systems
Azeem Irshad, Shehzad Ashraf Chaudhry, Saru Kumari, Arun Kumar Sangaiah, Xiong Li 0002, Fan Wu 0003 |
Multim. Tools Appl. | 6 |
| 2018 | A provably secure biometrics-based authenticated key agreement scheme for multi-server environments
Saru Kumari, Ashok Kumar Das, Xiong Li 0002, Fan Wu 0003, Muhammad Khurram Khan, Qi Jiang 0001, SK Hafizul Islam |
Multim. Tools Appl. | 3 |
| 2018 | New cubic reference table based image steganography
Xin Liao 0001, Sujin Guo, Jiaojiao Yin, Xiong Li 0002, Arun Kumar Sangaiah |
Multim. Tools Appl. | 5 |
| 2018 | Classify social image by integrating multi-modal content
Xiaoming Zhang 0001, Xiong Li 0002, Zhoujun Li 0001, Senzhang Wang |
Multim. Tools Appl. | 3 |
| 2018 | An improved and provably secure three-factor user authentication scheme for wireless sensor networks
Fan Wu 0003, Saru Kumari, Xiong Li 0002 |
Peer-to-Peer Netw. Appl. | 4 |
| 2018 | Quantum Cryptography for the Future Internet and the Security AnalysisabstractCyberspace has become the most popular carrier of information exchange in every corner of our life, which is beneficial for our life in almost all aspects. With the continuous development of science and technology, especially the quantum computer, cyberspace security has become the most critical problem for the Internet in near future. In this paper, we focus on analyzing characteristics of the quantum cryptography and exploring of the advantages of it in the future Internet. It is worth noting that we analyze the quantum key distribution (QKD) protocol in the noise-free channel. Moreover, in order to simulate real situations in the future Internet, we also search the QKD protocol in the noisy channel. The results reflect the unconditional security of quantum cryptography theoretically, which is suitable for the Internet as ever-increasing challenges are inevitable in the future. Tianqi Zhou, Jian Shen 0001, Xiong Li 0002, Chen Wang 0015, Jun Shen 0006 |
Secur. Commun. Networks | 3 |
| 2018 | Fuzzy encryption in cloud computation: efficient verifiable outsourced attribute-based encryption
Jing Li 0045, Xiong Li 0002, Licheng Wang 0004, Debiao He, Haseeb Ahmad, Xinxin Niu |
Soft Comput. | 2 |
| 2018 | A Robust ECC-Based Provable Secure Authentication Protocol With Privacy Preserving for Industrial Internet of ThingsabstractWireless sensor networks (WSNs) play an important role in the industrial Internet of Things (IIoT) and have been widely used in many industrial fields to gather data of monitoring area. However, due to the open nature of wireless channel and resource-constrained feature of sensor nodes, how to guarantee that the sensitive sensor data can only be accessed by a valid user becomes a key challenge in IIoT environment. Some user authentication protocols for WSNs have been proposed to address this issue. However, previous works more or less have their own weaknesses, such as not providing user anonymity and other ideal functions or being vulnerable to some attacks. To provide secure communication for IIoT, a user authentication protocol scheme with privacy protection for IIoT has been proposed. The security of the proposed scheme is proved under a random oracle model, and other security discussions show that the proposed protocol is robust to various attacks. Furthermore, the comparison results with other related protocols and the simulation by NS-3 show that the proposed protocol is secure and efficient for IIoT. Xiong Li 0002, Jianwei Niu 0002, Md. Zakirul Alam Bhuiyan, Fan Wu 0003, Marimuthu Karuppiah, Saru Kumari |
IEEE Trans. Ind. Informatics | 1 |
| 2018 | A secure authentication scheme based on elliptic curve cryptography for IoT and cloud servers
Saru Kumari, Marimuthu Karuppiah, Ashok Kumar Das, Xiong Li 0002, Fan Wu 0003, Neeraj Kumar 0001 |
J. Supercomput. | 4 |
| 2018 | A Secure Three-Factor Multiserver Authentication Protocol against the Honest-But-Curious ServersabstractThree‐factor multiserver authentication protocols become a prevalence in recent years. Among these protocols, almost all of them do not involve the registration center into the authentication process. To improve the protocol’s efficiency, a common secret key is shared among all severs, which leads to a serious weakness; i.e., we find that these protocols cannot resist the passive attack from the honest‐but‐curious servers. This paper takes Wang et al.’s protocol as an example, to exhibit how an honest‐but‐curious server attacks their protocol. To remedy this weakness, a novel three‐factor multiserver authentication protocol is presented. By introducing the registration center into the authentication process, the new protocol can resist the passive attack from the honest‐but‐curious servers. Security analyses including formal and informal analyses are given, demonstrating the correctness and validity of the new protocol. Compared with related protocols, the new protocol possesses more secure properties and more practical functionalities than others at a relatively low computation cost and communication cost. Hua Guo 0001, Chen Chen 0094, Xiong Li 0002, Jiongchao Jin |
Wirel. Commun. Mob. Comput. | 4 |
| 2017 | Medical image classification based on multi-scale non-negative sparse coding
Jian Shen 0001, Fushan Wei, Xiong Li 0002, Arun Kumar Sangaiah |
Artif. Intell. Medicine | 4 |
| 2017 | Anonymous mutual authentication and key agreement scheme for wearable sensors in wireless body area networks
Xiong Li 0002, Maged Hamada Ibrahim, Saru Kumari, Arun Kumar Sangaiah, Vidushi Gupta, Kim-Kwang Raymond Choo |
Comput. Networks | 1 |
| 2017 | On the design of a secure user authentication and key agreement scheme for wireless sensor networksabstractSummary A wireless sensor network (WSN) typically consists of a large number of resource‐constrained sensor nodes and several control or gateway nodes. Ensuring the security of the asymmetric nature of WSN is challenging, and designing secure and efficient user authentication and key agreement schemes for WSNs is an active research area. For example, in 2016, Farash et al. proposed a user authentication and key agreement scheme for WSNs. However, we reveal previously unpublished vulnerabilities in their scheme, which allow an attacker to carry out sensor node spoofing, password guessing, user/sensor node anonymity, and user impersonation attacks. We then present a scheme, which does not suffer from the identified vulnerabilities. To demonstrate the practicality of the scheme, we evaluate the scheme using NS‐2 simulator. We then prove the scheme secure using Burrows–Abadi–Needham logic. Copyright © 2016 John Wiley & Sons, Ltd. Saru Kumari, Ashok Kumar Das, Mohammad Wazid, Xiong Li 0002, Fan Wu 0003, Kim-Kwang Raymond Choo, Muhammad Khurram Khan |
Concurr. Comput. Pract. Exp. | 4 |
| 2017 | Design of a provably secure biometrics-based multi-cloud-server authentication scheme
Saru Kumari, Xiong Li 0002, Fan Wu 0003, Ashok Kumar Das, Kim-Kwang Raymond Choo, Jian Shen 0001 |
Future Gener. Comput. Syst. | 2 |
| 2017 | An efficient authentication and key agreement scheme for multi-gateway wireless sensor networks in IoT deployment
Fan Wu 0003, Saru Kumari, Xiong Li 0002, Jian Shen 0001, Kim-Kwang Raymond Choo, Mohammad Wazid, Ashok Kumar Das |
J. Netw. Comput. Appl. | 4 |
| 2017 | An improved and anonymous two-factor authentication protocol for health-care applications with wireless medical sensor networks
Fan Wu 0003, Saru Kumari, Xiong Li 0002 |
Multim. Syst. | 4 |
| 2017 | A password based authentication scheme for wireless multimedia systems
Nishant Doshi, Saru Kumari, Dheerendra Mishra, Xiong Li 0002, Kim-Kwang Raymond Choo, Arun Kumar Sangaiah |
Multim. Tools Appl. | 4 |
| 2017 | An improved smart card based authentication scheme for session initiation protocol
Saru Kumari, Shehzad Ashraf Chaudhry, Fan Wu 0003, Xiong Li 0002, Mohammad Sabzinejad Farash, Muhammad Khurram Khan |
Peer-to-Peer Netw. Appl. | 4 |
| 2017 | A new and secure authentication scheme for wireless sensor networks with formal proof
Fan Wu 0003, Saru Kumari, Xiong Li 0002 |
Peer-to-Peer Netw. Appl. | 4 |
| 2017 | An efficient authentication and key agreement scheme with user anonymity for roaming service in smart city
Xiong Li 0002, Arun Kumar Sangaiah, Saru Kumari, Fan Wu 0003, Jian Shen 0001, Muhammad Khurram Khan |
Pers. Ubiquitous Comput. | 1 |
| 2016 | A user friendly mutual authentication and key agreement scheme for wireless sensor networks using chaotic maps
Saru Kumari, Xiong Li 0002, Fan Wu 0003, Ashok Kumar Das, Hamed Arshad, Muhammad Khurram Khan |
Future Gener. Comput. Syst. | 2 |
| 2016 | A more secure digital rights management authentication scheme based on smart card
Saru Kumari, Muhammad Khurram Khan, Xiong Li 0002 |
Multim. Tools Appl. | 3 |
| 2016 | Single round-trip SIP authentication scheme with provable security for Voice over Internet Protocol using smart card
Saru Kumari, Fan Wu 0003, Xiong Li 0002, Mohammad Sabzinejad Farash, Qi Jiang 0001, Muhammad Khurram Khan, Ashok Kumar Das |
Multim. Tools Appl. | 3 |
| 2016 | Android platform-based individual privacy information protection system
Weizhe Zhang, Xiong Li 0002, Naixue Xiong, Athanasios V. Vasilakos |
Pers. Ubiquitous Comput. | 2 |
| 2016 | Provably secure three-factor authentication and key agreement scheme for session initiation protocolabstractAbstract Session initiation protocol (SIP) is a widely used authentication protocol for the Voice over IP communications. Over the years, several protocols have been proposed in the literature to strengthen the security of SIP. In this paper, we present an efficient elliptic curve cryptography (ECC)‐based provably secure three‐factor authentication and session key agreement scheme for SIP, which uses the identity, password, and personal biometrics of a user as three factors. Our scheme aims to resolve the security weaknesses and drawbacks in existing SIP authentication protocols. In addition, our scheme supports password and biometric update phase without involving the server and the user mobile device revocation phase in case the mobile device is lost/stolen. Formal security analysis under the standard model and the broadly accepted Burrows–Abadi–Needham logic ensures that the proposed scheme can withstand several known security attacks. The proposed scheme has also been analyzed informally. Simulation for formal security verification using the widely known automated validation of internet security protocols and applications tool shows the replay, and the man‐in‐the‐middle attacks are protected by the scheme. High security and low communication and computation costs make the proposed scheme more suitable for practical application as compared with other existing related ECC‐based schemes. Copyright © 2016 John Wiley & Sons, Ltd. Sravani Challa, Ashok Kumar Das, Saru Kumari, Vanga Odelu, Fan Wu 0003, Xiong Li 0002 |
Secur. Commun. Networks | 6 |
| 2016 | Provably secure user authentication and key agreement scheme for wireless sensor networksabstractIn recent years, user authentication has emerged as an interesting field of research in wireless sensor networks. Most recently, in 2016, Chang and Le presented a scheme to authenticate the users in wireless sensor network using a password and smart card. They proposed two protocols and . is based on exclusive or (XOR) and hash functions, while deploys elliptic curve cryptography in addition to the two functions used in . Although their protocols are efficient, we point out that both and are vulnerable to session specific temporary information attack and offline password guessing attack, while is also vulnerable to session key breach attack. In addition, we show that both the protocols and are inefficient in authentication and password change phases. To withstand these weaknesses found in their protocols, we aim to design a new authentication and key agreement scheme using elliptic curve cryptography. Rigorous formal security proofs using the broadly accepted, the random oracle models, and the Burrows–Abadi–Needham logic and verification using the well-known Automated Validation of Internet Security Protocols and Applications tool are preformed on our scheme. The analysis shows that our designed scheme has the ability to resist a number of known attacks comprising those found in both Chang–Le's protocols. Copyright © 2016 John Wiley & Sons, Ltd. Ashok Kumar Das, Saru Kumari, Vanga Odelu, Xiong Li 0002, Fan Wu 0003, Xinyi Huang 0001 |
Secur. Commun. Networks | 4 |
| 2016 | An efficient multi-gateway-based three-factor user authentication and key agreement scheme in hierarchical wireless sensor networksabstractAbstract User authentication in wireless sensor network (WSN) plays a very important role in which a legal registered user is allowed to access the real‐time sensing information from the sensor nodes inside WSN. To allow such access, a user needs to be authenticated by the accessed sensor nodes as well as gateway nodes inside WSNs. Because of resource limitations and vulnerability to physical capture of some sensor nodes by an attacker, design of a secure user authentication in WSN continues to be an important and challenging research area in recent years. In this paper, we propose a new three‐factor user authentication scheme based on the multi‐gateway WSN architecture. Through the widely‐accepted Burrows–Abadi–Needham logic, we prove that our scheme provides the secure mutual authentication. We then present the formal security verification of our proposed scheme using AVISPA tool, which is a powerful validation tool for network security applications, and show that our scheme is secure. In addition, the rigorous informal security analysis shows that our scheme is also secure against possible other known attacks including the sensor node capture attack. Furthermore, we present the additional functionality features that our scheme offers, which are efficient in communication and computation. Copyright © 2016 John Wiley & Sons, Ltd. Ashok Kumar Das, Anil Kumar Sutrala, Saru Kumari, Vanga Odelu, Mohammad Wazid, Xiong Li 0002 |
Secur. Commun. Networks | 6 |
| 2016 | A secure lightweight authentication scheme with user anonymity for roaming service in ubiquitous networksabstractAbstract Ubiquitous networks provide effective roaming services for mobile users (MUs). Through the worldwide roaming technology, authorized MUs can avail ubiquitous network services. Important security issues to be considered in ubiquitous networks are authentication of roaming MUs and protection of privacy of MUs. However, because of the broadcast nature of wireless channel and resource limitations of terminals, providing efficient user authentication with privacy preservation is a challenging task. Very recently, Farash et al. proposed an authentication scheme with anonymity for consumer roaming in ubiquitous networks and claimed their scheme achieves all security requirements. In this paper, we show that the scheme of Farash et al. fails to achieve user anonymity and mutual authentication. Their scheme also fails to provide local password verification, and it has a faulty password change phase. Moreover, their scheme is vulnerable to replay, offline password guessing, and forgery attacks. To fix the security flaws of the scheme of Farash et al., we present an improved authentication scheme for accessing roaming service provided by ubiquitous networks. We then formally verify the security properties of our scheme by the widely‐accepted push‐button tool called Automated Validation of Internet Security Protocols and Applications. Security and performance analyses show that our scheme is more powerful, efficient, and secure when it is compared with existing schemes. Copyright © 2016 John Wiley & Sons, Ltd. Marimuthu Karuppiah, Saru Kumari, Ashok Kumar Das, Xiong Li 0002, Fan Wu 0003, Sayantani Basu |
Secur. Commun. Networks | 4 |
| 2016 | An enhanced and secure trust-extended authentication mechanism for vehicular ad-hoc networksabstractAbstract Vehicular Ad‐hoc Networks (VANETs) are a move towards regulating safe traffic and intelligent transportation system. A VANETs is characterized by extremely dynamic topographical conditions owing to speedily moving vehicles. In VANETs, vehicles can transmit messages within a pre‐defined area to achieve safety and efficiency of the system. Then ensuring authenticity of origin of messages to the receiver in such a dynamic environment is a crucial challenge. Another concern in VANET is preservation of privacy of user/vehicle. Recently, Chuang and Lee proposed a trust‐extended authentication mechanism (TEAM) for vehicle‐to‐vehicle communications in VANETs. TEAM not only satisfies various security features but also enhances the performance of the authentication process using transitive trust relationship among vehicles. Nonetheless, our analysis shows that TEAM is vulnerable to insider attack, privacy breach, impersonation attacks and some other problems. In this paper, to eradicate the vulnerabilities found in Chuang‐Lee's scheme, an enhanced trust‐extended authentication scheme for VANET is proposed. We display the efficiency of our scheme through security analysis and comparison. Through simulation results using widely accepted NS‐2 simulator, we show that our scheme authenticates vehicles faster than Chuang‐Lee's scheme. Copyright © 2016 John Wiley & Sons, Ltd. Saru Kumari, Marimuthu Karuppiah, Xiong Li 0002, Fan Wu 0003, Ashok Kumar Das, Vanga Odelu |
Secur. Commun. Networks | 3 |
| 2016 | A new authentication protocol for healthcare applications using wireless medical sensor networks with user anonymityabstractABSTRACT With the development and maturation of the wireless communication technologies, the wireless sensor networks have been widely applied in different environments to acquire specific information. The wireless medical sensor networks (WMSNs), as a professional application of the wireless sensor networks in medicine, have attracted more and more attention because of its potential in improving the quality of healthcare services. Through the WMSNs, the parameters of patients' vital signs can be gathered from the sensor nodes equipped on the body of the patients and then can be accessed by the healthcare professionals by using a mobile device. By reason of the open feature of wireless communication, how to guarantee secure communication becomes an important issue. On the other hand, because the vital signs parameters are sensitive to the patients' health status and no one wants to reveal it to the others except the healthcare professionals, the protection of patients' privacy becomes another key issue for WMSNs applications. User authentication protocol with anonymity is the most basic and commonly used method to resolve the security and privacy issues of WMSNs. Recently, He et al. proposed an enhanced authentication protocol for healthcare applications using WMSNs to protect the security and privacy problems. However, we find that their scheme is incorrect in authentication and session key agreement phase. Besides, their scheme has no wrong password detection mechanism, which will not only waste the unnecessary computation and communication costs, but also may deduce the denial of service problem. In this paper, the biometric is introduced as the third authentication factor, and a new user anonymous authentication protocol based on WMSNs is designed so as to remove the drawbacks of the protocol of He et al. Compared with previous protocols, the new presented protocol enhances the security and also keeps the computation efficiency. Copyright © 2015 John Wiley & Sons, Ltd. Xiong Li 0002, Jianwei Niu 0002, Saru Kumari, Junguo Liao, Wei Liang 0005, Muhammad Khurram Khan |
Secur. Commun. Networks | 1 |
| 2016 | Robust three-factor remote user authentication scheme with key agreement for multimedia systemsabstractAbstract As the fast growth of multimedia information, the security of multimedia systems is becoming a rather important topic nowadays. Multimedia systems are often suffering attacks when users access the information and online services. Because of the excellent features of the biometric, many biometric‐based three‐factor remote user authentication schemes have been proposed to provide high level of security for different network‐based application systems. Recently, An pointed out the weaknesses of Das's three‐factor remote user authentication scheme and proposed an improved biometric‐based three‐factor remote user authentication scheme. An's scheme improves the security problems of previous schemes while keeping the efficiency. However, after detailed analysis, we find that An's scheme exists some weaknesses such as vulnerable to denial‐of‐service attack and forgery attack, cannot detect unauthorized login quickly, and does not provide session key agreement. In order to provide high level of security for multimedia systems, we design a robust three‐factor remote user authentication scheme with key agreement using elliptic curve cryptosystem. Copyright © 2014 John Wiley & Sons, Ltd. Xiong Li 0002, Jianwei Niu 0002, Muhammad Khurram Khan, Junguo Liao, Xiaoke Zhao |
Secur. Commun. Networks | 1 |
| 2016 | Design of an efficient and provably secure anonymity preserving three-factor user authentication and key agreement scheme for TMISabstractAbstract Several remote user authentication techniques for telecare medicine information system (TMIS) have been proposed in the literature. But most existing techniques have limitations such as vulnerable to various attacks, lack of functionalities, and inefficiency. Recently, Amin and Biswas proposed a three‐factor authentication and key agreement technique for TMIS. But their scheme is inefficient and has several security drawbacks. The attacks such as privileged‐insider, user impersonation, and strong reply attacks are possible on their scheme. It also has flaw in password update phase. In order to overcome drawbacks of their scheme, a new provably secure and efficient three‐factor remote user authentication scheme for TMIS is proposed in this paper. The proposed scheme overcomes all drawbacks of their scheme and also provides additional features such as user unlinkability, user anonymity, efficient password, and biometric update. The rigorous informal and formal security analysis using random oracle models and the mostly acceptable Automated Validation of Internet Security Protocols and Applications tool is also performed. During the experimentation, it has been observed that the proposed scheme is secure against various known attacks that include replay and man‐in‐the‐middle attacks. Furthermore, the analysis of computation and communication cost estimation of the proposed scheme depicts that our scheme is efficient as compared with other related exiting schemes. Copyright © 2016 John Wiley & Sons, Ltd. Mohammad Wazid, Ashok Kumar Das, Saru Kumari, Xiong Li 0002, Fan Wu 0003 |
Secur. Commun. Networks | 4 |
| 2016 | Provably secure biometric-based user authentication and key agreement scheme in cloud computingabstractAbstract Cloud computing, the conjoin of many types of computing, has made a great impact on the life of everyone. People from anywhere can access the different cloud‐based services by using the Internet. A user, who wants to access some cloud‐based service, needs to register himself/herself to an authority (service provider), and after that, he/she can use the service. To access the service, each user needs to authenticate to that particular cloud server. Several user authentication schemes for cloud computing have been presented but mostly have limitations/drawbacks as they are prone to various known attacks, such as privileged insider, user and server impersonation, and strong reply attacks, and they also have lack of functionality features. Moreover, these schemes do not provide efficient password change phase. In order to overcome these drawbacks, we propose a new provably secure biometric‐based user authentication and key agreement scheme for cloud computing. The proposed scheme overcomes the weaknesses of the existing schemes and supports extra functionality features including user anonymity and efficient password and biometric update phase for multi‐server environment. The careful formal security analysis under standard model and informal security analysis and the simulation results for formal security verification using the most acceptable AVISPA tool show that the proposed scheme is secure against various known possible attacks. The analysis of computation and communication overheads of our scheme depicts its efficiency over other related existing schemes, and thus, the proposed scheme is suitable for the cloud computing environment. Copyright © 2016 John Wiley & Sons, Ltd. Mohammad Wazid, Ashok Kumar Das, Saru Kumari, Xiong Li 0002, Fan Wu 0003 |
Secur. Commun. Networks | 4 |
| 2016 | A novel and provably secure authentication and key agreement scheme with user anonymity for global mobility networksabstractUbiquitous networks support the roaming service for mobile communication devices. The mobile user can use the services in the foreign network with the help of the home network. Mutual authentication plays an important role in the roaming services, and researchers put their interests on the authentication schemes. Recently, in 2016, Gope and Hwang found that mutual authentication scheme of He et al. for global mobility networks had security disadvantages such as vulnerability to forgery attacks, unfair key agreement, and destitution of user anonymity. Then, they presented an improved scheme. However, we find that the scheme cannot resist the off-line guessing attack and the de-synchronization attack. Also, it lacks strong forward security. Moreover, the session key is known to HA in that scheme. To get over the weaknesses, we propose a new two-factor authentication scheme for global mobility networks. We use formal proof with random oracle model, formal verification with the tool Proverif, and informal analysis to demonstrate the security of the proposed scheme. Compared with some very recent schemes, our scheme is more applicable. Copyright © 2016 John Wiley & Sons, Ltd. Fan Wu 0003, Saru Kumari, Xiong Li 0002, Ashok Kumar Das, Muhammad Khurram Khan, Marimuthu Karuppiah, Renuka Baliyan |
Secur. Commun. Networks | 4 |
| 2015 | A new authenticated key agreement scheme based on smart cards providing user anonymity with formal proofabstractAbstract Nowadays, smart‐card‐based user authentication becomes one of the most important security issues. But many schemes of that kind are under different attacks. Recently, Kumari et al. pointed that Chen et al.‘s scheme and Li et al.‘s scheme with the smart card were not secure. They proposed two improved schemes. Unfortunately, we find that the two schemes are not secure. The first scheme of Kumari et al. is under the de‐synchronization attack and lacks strong forward security. The second has the weaknesses including no user anonymity and password leaking. Also, it cannot withstand the user‐impersonation attack. We present a new scheme also based on the smart card overcoming common disadvantages and give a formal proof. We also use the tool ProVerif to verify the security of our scheme. Compared with some recent schemes, our scheme performs well, and it is fit for network applications. Copyright © 2015 John Wiley & Sons, Ltd. Fan Wu 0003, Saru Kumari, Xiong Li 0002, Abdulhameed Alelaiwi |
Secur. Commun. Networks | 4 |
| 2014 | An improved timestamp-based password authentication scheme: comments, cryptanalysis, and improvementabstractABSTRACT In 2003, Shen et al. proposed a timestamp‐based password authentication scheme by using smart card. Later, in 2005 and 2008, this scheme was found susceptible to forged login attacks by some researchers, and improved schemes were proposed. In 2011, Awasthi et al. pointed out an additional security threat on the scheme of Shen et al. and also suggested remedy by proposing an enhanced scheme. In this paper, we analyze the additional attack identified by Awasthi et al. on the scheme of Shen et al. show its flaws and rectify it. Further, we find that the scheme of Awasthi et al. still fails to withstand forged login attack, smart card loss attack, offline password guessing attack, and so on, and also inherits some weaknesses from the original scheme. Therefore, we propose an improved version of the scheme of Awasthi et al. Our improved scheme not only resists the attacks that we depict on the scheme of Awasthi et al. but is also free from the attacks pointed out so far on the scheme of Shen et al. Copyright © 2013 John Wiley & Sons, Ltd. Saru Kumari, Mridul Kumar Gupta, Muhammad Khurram Khan, Xiong Li 0002 |
Secur. Commun. Networks | 4 |
| 2014 | Applying biometrics to design three-factor remote user authentication scheme with key agreementabstractABSTRACT There are some biometrics‐based three‐factor remote user authentication schemes proposed by researchers for ensure high security features for network‐based application systems. Recently, Das pointed out the security flaws of Li and Hwang's three‐factor remote user authentication scheme, and proposed an enhanced biometrics‐based three‐factor remote user authentication scheme. Das's scheme overcomes the defects of Li and Hwang's scheme, and maintains the advantages of Li and Hwang's scheme at the same time. However, after detailed analysis, we find that Das's scheme remains vulnerable to forgery attack and stolen smart card attack; at the same time, Das's scheme cannot provide the session key agreement after the mutual authentication. To provide more security features, we design a three‐factor remote user authentication scheme with key agreement using biometrics. Copyright © 2013 John Wiley & Sons, Ltd. Xiong Li 0002, Jianwei Niu 0002, Zhibo Wang 0001, Cai-Sen Chen |
Secur. Commun. Networks | 1 |
| 2014 | A novel user authentication scheme with anonymity for wireless communicationsabstractABSTRACT User authentication and privacy protection are important issues for wireless and mobile communication systems such as GSM, 3G, and 4G wireless networks. Recently, Yoon et al. proposed a user‐friendly authentication scheme with anonymity for wireless communications. However, in this paper, we show that user anonymity of their scheme is not achieved under the eavesdropping attack and their scheme is not fair in the key agreement. In order to ensure security authentication and protect user anonymity for wireless communications, we propose a novel user authentication scheme with anonymity based on elliptic curve cryptosystem, which can resist various known types of attacks and is more practical for wireless and mobile communications. Copyright © 2012 John Wiley & Sons, Ltd. Jianwei Niu 0002, Xiong Li 0002 |
Secur. Commun. Networks | 2 |
| 2013 | An enhanced smart card based remote user password authentication scheme
Xiong Li 0002, Jianwei Niu 0002, Muhammad Khurram Khan, Junguo Liao |
J. Netw. Comput. Appl. | 1 |
| 2013 | Improvement of trace-driven I-Cache timing attack on the RSA algorithm
Cai-Sen Chen, YingZhan Kou, Xiaocen Chen, Xiong Li 0002 |
J. Syst. Softw. | 5 |
| 2012 | Multiple ant colony algorithm method for selecting tag SNPs
Xiong Li 0002, Wen Zhu, Renfa Li, Shulin Wang |
J. Biomed. Informatics | 2 |
| 2012 | An efficient and security dynamic identity based authentication protocol for multi-server architecture using smart cards
Xiong Li 0002, Yongping Xiong, Jian Ma 0001, Wendong Wang 0003 |
J. Netw. Comput. Appl. | 1 |
| 2011 | Cryptanalysis and improvement of a biometrics-based remote user authentication scheme using smart cards
Xiong Li 0002, Jianwei Niu 0002, Jian Ma 0001, Wendong Wang 0003, Chenglian Liu |
J. Netw. Comput. Appl. | 1 |