Fengjun Li

dblp:66/6000 · DBLP profile ↗
← Back
61ranked-venue papers
10as first author
32since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 37 · 3 first-author · 20 since 2021Artificial intelligence and machine learning · 7 · 2 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 1 first-author · 5 since 2021Computer networks · 4 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-authorSystems, architecture and hardware · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Beyond Conventional Triggers: Auto-Contextualized Covert Triggers for Android Logic Bombs
Bo Luo, Fengjun Li
NDSS3
2025 InteractionShield: Harnessing Event Relations for Interaction Threat Detection and Resolution in Smart Homes
abstract
The widespread adoption of IoT devices and applications in smart homes has transformed the way we engage with our living environments. While enabling seamless automation and intelligent functionalities, interactions between different IoT applications, typically through trigger-condition-action (TCA) rules, may introduce new interaction threats due to rule conflicts, which sometimes lead to severe security and safety risks. However, existing detection and defense approaches often tackle specific threat categories in isolation, thereby failing to deliver a holistic perspective and robust, comprehensive protection. In this paper, we present InteractionShield, a novel framework that systematically detects and resolves rule conflicts by leveraging a logic analysis model based on event relations. The InteractionShield framework formalizes event relationships, detects event interferences, and classifies rule conflicts. It generates risk scores and conflict rankings to enable comprehensive conflict detection and risk assessment. To address the identified interaction threats, an optimization-based approach is employed to mitigate risks while maintaining system functionality. Evaluated on large-scale real-world IoT datasets, InteractionShield effectively enhances system reliability, offering a robust solution for detecting and resolving rule conflicts in smart environments.
Zhaohui Wang 0004, Bo Luo, Fengjun Li
ACSAC3
2025 ACM CCS Young Scholars Development Program
abstract
In this short document, we introduce The ACM CCS Young Scholars Development Program (YSDP); a new initiative aiming at supporting early-career researchers within the computer security community. YSDP is created and organized by dedicated chairs. The program promotes collaboration, communication, and professional growth through structured events such as talks, panels, and breakout technical discussions sessions. It emphasizes skill-building and networking, with a focus on integrating young scholars into the broader academic ecosystem. In this report, we detail the planning, selection, and execution of the program, and highlight its role in shaping a stronger research environment.
F. Betül Durak, Fengjun Li, Sophie Stephenson
CCS2
2025 Reconstruction-Free Classification for Lensless Imaging Systems
abstract
Lensless imaging offers a promising, privacy-preserving alternative to traditional cameras by capturing unintelligible diffraction patterns instead of direct scene images. This enables compact, lightweight, and energy-efficient imaging systems suitable for resource-constrained surveillance applications such as UAVs and wearable devices. However, conventional lensless systems require computationally intensive image reconstruction, which compromises both privacy and efficiency. In this work, we propose a robust, reconstruction-free lensless image classification framework based on a modified ResNet18 architecture. To address the lack of structure in lensless data, we introduce a frequency-domain learning strategy using block-DCT applied to non-overlapping spatial blocks. Our method achieves 97.61% accuracy on a real-world lensless face recognition dataset and 93.98% on a simulated remote sensing benchmark, outperforming prior reconstruction-free approaches. These results demonstrate the feasibility of high-accuracy lensless recognition without reconstruction and pave the way for practical, privacy-aware deployment in real-world surveillance scenarios.
Pramil Paudel, Fengjun Li
ICMLA2
2025 PrivacyGuard: Exploring Hidden Cross-App Privacy Leakage Threats In IoT Apps
abstract
The increasing use of the Internet of Things (IoT) technology has made our lives convenient, however, it also poses new security and privacy threats. In this work, we study a new type of privacy threat enabled by cross-app chains built among multiple seemingly benign IoT apps. We find that interactions among apps could leak privacy-sensitive information, e.g., users' identification, location and tracking, activity patterns, etc. To tackle this challenge, we introduce PrivacyGuard, which extracts cross-app chains in the form of trigger-condition-action rules and identifies the corresponding privacy leakage risk with an inference probability. PrivacyGuard supports a fine-grained categorization of privacy threats to generate detailed alerts about privacy leakages. We evaluated PrivacyGuard on a dataset with 2,101 SmartApps, 2,788 IFTTT rules, and 2,086 OpenHAB rules, respectively. The results show that PrivacyGuard could uncover hidden privacy leaks that existing studies fail to detect. For example, 7.67% chains constructed by two seemingly benign IoT apps could leak at least one type of privacy information, while over 80% of the leaks involved privacy information regarding Localization & Tracking and Activity Profiling.
Zhaohui Wang 0004, Bo Luo, Fengjun Li
Proc. Priv. Enhancing Technol.3
2024 Eunomia: A Real-time Privacy Compliance Firewall for Alexa Skills
abstract
Voice assistants (VAs), such as Amazon Alexa, are integrated with numerous smart home devices to process user requests using apps called skills. With their growing popularity, VAs also pose serious privacy concerns. Sensitive user data captured by VAs may be transmitted to third-party skills without users’ consent or knowledge about how their data is handled. Privacy policies are a standard medium to inform the users of the skills’ data practices. However, privacy policy compliance verification of such skills is challenging, since the source code is controlled by the skill developers, who can make arbitrary changes to the behaviors of the skill without being audited; hence, conventional defense mechanisms using static/dynamic code analysis can be easily evaded. In this paper, we present Eunomia, the first real-time privacy compliance firewall for Alexa skills. As the skills interact with the users, Eunomia hijacks and examines their communications from the skills to the users, and validates them against the published privacy policies that are parsed using a BERT-based policy analysis module. When non-compliant skill behaviors are detected, Eunomia stops the interaction and warns the user about the non-compliance. We evaluate Eunomia with 55,898 skills on Amazon skills store to demonstrate its effectiveness and to provide a privacy compliance landscape of Alexa skills.
Javaria Ahmad, Fengjun Li, Razvan Beuran, Bo Luo
ACSAC2
2024 On the Detectability of ChatGPT Content: Benchmarking, Methodology, and Evaluation through the Lens of Academic Writing
abstract
With ChatGPT under the spotlight, utilizing large language models (LLMs) to assist academic writing has drawn a significant amount of debate in the community. In this paper, we aim to present a comprehensive study of the detectability of ChatGPT-generated content within the academic literature, particularly focusing on the abstracts of scientific papers, to offer holistic support for the future development of LLM applications and policies in academia. Specifically, we first present GPABench2, a benchmarking dataset of over 2.8 million comparative samples of human-written, GPT-written, GPT-completed, and GPT-polished abstracts of scientific writing in computer science, physics, and humanities and social sciences. Second, we explore the methodology for detecting ChatGPT content. We start by examining the unsatisfactory performance of existing ChatGPT detecting tools and the challenges faced by human evaluators (including more than 240 researchers or students). We then test the hand-crafted linguistic features models as a baseline and develop a deep neural framework named CheckGPT to better capture the subtle and deep semantic and linguistic patterns in ChatGPT written literature. Last, we conduct comprehensive experiments to validate the proposed CheckGPT framework in each benchmarking task over different disciplines. To evaluate the detectability of ChatGPT content, we conduct extensive experiments on the transferability, prompt engineering, and robustness of CheckGPT.
Zeyan Liu, Zijun Yao 0001, Fengjun Li, Bo Luo
CCS3
2024 The Invisible Polyjuice Potion: an Effective Physical Adversarial Attack against Face Recognition
abstract
Face recognition systems have been targeted by recent physical adversarial machine learning attacks, which attach or project visible patterns on adversaries' faces to trick backend FR models. While these attacks have demonstrated effectiveness in the literature, they often rely on visibly suspicious patterns, are susceptible to environmental noise, or exhibit limited success rates in practice. In this paper, we propose a novel physical adversarial attack against deep face recognition systems, namely Agile (Adversarial Glasses with Infrared LasEr). It generates adjustable, invisible laser perturbations and emits them into the camera CMOS to launch dodging and impersonation attacks against facial biometrics systems. To do so, we first theoretically model physical adversarial perturbations and convert them to the digital domain. The generated synthesized attack signals are utilized to guide real-world laser settings. Our experiments with real-world attackers and a benchmark face database show that Agile is highly effective in DoS, dodging, and impersonation attacks. More importantly, the candidate impersonation target and optimal attack settings identified by Agile's attack synthesis approach are highly consistent with real-world physical attack results. The grey-box and black-box evaluation against commercial FR models also confirms the effectiveness of the Agile attack.
Zeyan Liu, Bo Luo, Rongqing Hui, Fengjun Li
CCS5
2024 The Adversarial AI-Art: Understanding, Generation, Detection, and Benchmarking
Zeyan Liu, Liangqin Ren, Fengjun Li, Jiebo Luo 0001, Bo Luo
ESORICS (1)5
2024 Companion Apps or Backdoors? On the Security of Automotive Companion Apps
Prashanthi Mallojula, Fengjun Li, Xiaojiang Du, Bo Luo
ESORICS (3)2
2024 Certificate Transparency Revisited: The Public Inspections on Third-party Monitors
Aozhuo Sun, Jingqiang Lin 0001, Wei Wang 0314, Zeyan Liu, Bingyu Li 0003, Shushang Wen, Qiongxiao Wang, Fengjun Li
NDSS8
2024 PrivDNN: A Secure Multi-Party Computation Framework for Deep Learning using Partial DNN Encryption
abstract
In the past decade, we have witnessed an exponential growth of deep learning models, platforms, and applications. While existing DL applications and Machine Learning as a service (MLaaS) frameworks assume fully trusted models, the need for privacy-preserving DNN evaluation arises. In a secure multi-party computation scenario, both the model and the data are considered proprietary, i.e., the model owner does not want to reveal the highly valuable DL model to the user, while the user does not wish to disclose their private data samples either. Conventional privacy-preserving deep learning solutions ask the users to send encrypted samples to the model owners, who must handle the heavy lifting of ciphertext-domain computation with homomorphic encryption. In this paper, we present a novel solution, namely, PrivDNN, which (1) offloads the computation to the user side by sharing an encrypted deep learning model with them, (2) significantly improves the efficiency of DNN evaluation using partial DNN encryption, (3) ensures model accuracy and model privacy using a core neuron selection and encryption scheme. Experimental results show that PrivDNN reduces privacy-preserving DNN inference time and memory requirement by up to 97% while maintaining model performance and privacy. Codes can be found at https://github.com/LiangqinRen/PrivDNN
Liangqin Ren, Zeyan Liu, Fengjun Li, Kaitai Liang, Bo Luo
Proc. Priv. Enhancing Technol.3
2023 Poster: Ethics of Computer Security and Privacy Research - Trends and Standards from a Data Perspective
abstract
Ethics is an important criterion for security research. This work presents the current status and trends that security researchers have taken to address ethical concerns in their studies from a data perspective. In particular, we created a dataset of 3,756 papers published in three top-tier conferences between 2010 and 2022, among which 963 papers were identified with ethical concerns. With this dataset, we provided answers to three questions regarding the current practices and trends: (1) What is the landscape of ethical considerations in security research? For example, how many security research projects have raised ethical concerns in their studies, and which research areas are likely to cause ethical risks and concerns? (2) What are the current practices to address these ethical risks? And (3) What are the important factors impacting the ethical awareness of researchers?
Zhaohui Wang 0004, Bo Luo, Fengjun Li
CCS5
2023 Enhanced Ticket Transparency (eTT) Framework for Single Sign-On Services with Pseudonyms
abstract
Recently, a series of vulnerabilities occurred to divulge or forge single sign-on tickets, such as the famous SolarWinds incident Once malicious attackers obtain fraudulent tickets, they can pry into user privacy as well as compromise the system by impersonating the victim user. Inspired by certificate transparency, a ticket transparency (TT) framework for detecting fraudulent tickets is proposed. However, it suffers from inefficiency and potential failure. In this paper, we further propose an enhanced ticket transparency (eTT) scheme, which ensures that all fraudulent tickets can be detected efficiently through a novel dual-backup structure to store ticket entries in the public log. Meanwhile, we design specific calculations for pairwise pseudonymous identifiers (PPIDs), to support fraudulent-detection towards tickets in which user identifiers are pseudonyms. We implemented the prototype system, and the experimental evaluation shows that eTT framework introduces acceptable overheads in the sign-on process.
Guangqi Liu, Jingqiang Lin 0001, Dawei Chu, Qiongxiao Wang, Cunqing Ma, Fengjun Li, Dingfeng Ye
TrustCom7
2023 Preassigned-time projective synchronization of delayed fully quaternion-valued discontinuous neural networks with parameter uncertainties
Hao Pu, Fengjun Li, Pengzhen Li
Neural Networks2
2023 Siamese Graph Learning for Semi-Supervised Age Estimation
abstract
In this paper, we propose a Siamese graph learning (SGL) approach to alleviate aging dataset bias. While numerous semi-supervised algorithms have been successfully applied to classification tasks, most of them assume that both the labeled and unlabeled samples are drawn from identical distributions. However, this assumption may not hold due to the heterogeneity of face aging data, which gives rise to a bias and unpromising prediction. Motivated by this, our SGL learns to align the sparse distribution with the dense one for dataset debias with preserving the real aging smoothness. To achieve this, we adopt a mixup strategy to plausibly generate hallucinatory samples, which leverages amounts of unlabeled data to enhance the diversity of unbalanced classes. Moreover, we develop a graph contrastive regularization to suppress the noise introduced by auxiliary unlabeled samples. Extensive experimental results show compelling performance by only utilizing the limited scalability of training annotations.
Hao Liu 0019, Mei Ma, Zixian Gao, Zongyong Deng, Fengjun Li
IEEE Trans. Multim.5
2022 LoneNeuron: A Highly-Effective Feature-Domain Neural Trojan Using Invisible and Polymorphic Watermarks
abstract
The wide adoption of deep neural networks (DNNs) in real-world applications raises increasing security concerns. Neural Trojans embedded in pre-trained neural networks are a harmful attack against the DNN model supply chain. They generate false outputs when certain stealthy triggers appear in the inputs. While data-poisoning attacks have been well studied in the literature, code-poisoning and model-poisoning backdoors only start to attract attention until recently. We present a novel model-poisoning neural Trojan, namely LoneNeuron, which responds to feature-domain patterns that transform into invisible, sample-specific, and polymorphic pixel-domain watermarks. With high attack specificity, LoneNeuron achieves a 100% attack success rate, while not affecting the main task performance. With LoneNeuron's unique watermark polymorphism property, the same feature-domain trigger is resolved to multiple watermarks in the pixel domain, which further improves watermark randomness, stealthiness, and resistance against Trojan detection. Extensive experiments show that LoneNeuron could escape state-of-the-art Trojan detectors. LoneNeuron~is also the first effective backdoor attack against vision transformers (ViTs).
Zeyan Liu, Fengjun Li, Zhu Li 0001, Bo Luo
CCS2
2022 IoTPrivComp: A Measurement Study of Privacy Compliance in IoT Apps
Javaria Ahmad, Fengjun Li, Bo Luo
ESORICS (2)2
2022 Hide and Seek: On the Stealthiness of Attacks Against Deep Learning Systems
Zeyan Liu, Fengjun Li, Jingqiang Lin 0001, Zhu Li 0001, Bo Luo
ESORICS (3)2
2022 Aggregating Global Features into Local Vision Transformer
abstract
Local Transformer-based classification models have recently achieved promising results with relatively low computational costs. However, the effect of aggregating spatial global information of local Transformer-based architecture is not clear. This work investigates the outcome of applying a global attention-based module named multi-resolution overlapped attention (MOA) in the local window-based transformer after each stage. The proposed MOA employs slightly larger and overlapped patches in the key to enable neighborhood pixel information transmission, which leads to significant performance gain. In addition, we thoroughly investigate the effect of the dimension of essential architecture components through extensive experiments and discover an optimum architecture design. Extensive experimental results CIFAR-10, CIFAR-100, and ImageNet-1K datasets demonstrate that the proposed approach outperforms previous vision Transformers with a comparatively fewer number of parameters. The source code and models are publicly available at: https://github.com/krushi1992/MOA-transformer
Krushi Patel, Andrés M. Bur, Fengjun Li, Guanghui Wang 0001
ICPR3
2022 $\mu AFL$: Non-intrusive Feedback-driven Fuzzing for Microcontroller Firmware
abstract
Fuzzing is one of the most effective approaches to finding software flaws. However, applying it to microcontroller firmware incurs many challenges. For example, rehosting-based solutions cannot accurately model peripheral behaviors and thus cannot be used to fuzz the corresponding driver code. In this work, we present μAFL, a hardware-in-the-loop approach to fuzzing microcontroller firmware. It leverages debugging tools in existing embedded system development to construct an AFL-compatible fuzzing framework. Specifically, we use the debug dongle to bridge the fuzzing environment on the PC and the target firmware on the microcontroller device. To collect code coverage information without costly code instrumentation, μAFL relies on the ARM ETM hardware debugging feature, which transparently collects the instruction trace and streams the results to the PC. However, the raw ETM data is obscure and needs enormous computing resources to recover the actual instruction flow. We therefore propose an alternative representation of code coverage, which retains the same path sensitivity as the original AFL algorithm, but can directly work on the raw ETM data without matching them with disassembled instructions. To further reduce the workload, we use the DWT hardware feature to selectively collect runtime information of interest. We evaluated μAFL on two real evaluation boards from two major vendors: NXP and STMicroelectronics. With our prototype, we discovered ten zero-day bugs in the driver code shipped with the SDK of STMicroelectronics and three zero-day bugs in the SDK of NXP. Eight CVEs have been allocated for them. Considering the wide adoption of vendor SDKs in real products, our results are alarming.
Jiameng Shi, Fengjun Li, Jingqiang Lin 0001, Wei Wang 0314, Le Guan
ICSE3
2022 Learning Generalizable Latent Representations for Novel Degradations in Super-Resolution
abstract
Typical methods for blind image super-resolution (SR) focus on dealing with unknown degradations by directly estimating them or learning the degradation representations in a latent space. A potential limitation of these methods is that they assume the unknown degradations can be simulated by the integration of various handcrafted degradations (e.g., bicubic downsampling), which is not necessarily true. The real-world degradations can be beyond the simulation scope by the handcrafted degradations, which are referred to as novel degradations. In this work, we propose to learn a latent representation space for degradations, which can be generalized from handcrafted (base) degradations to novel degradations. Furthermore, we perform variational inference to match the posterior of degradations in latent representation space with a prior distribution (e.g., Gaussian distribution). Consequently, we are able to sample more high-quality representations for a novel degradation to augment the training data for SR model. We conduct extensive experiments on both synthetic and real-world datasets to validate the effectiveness and advantages of our method for blind super-resolution with novel degradations.
Fengjun Li, Xin Feng 0005, Fanglin Chen 0001, Guangming Lu 0002, Wenjie Pei
ACM Multimedia1
2022 Preassigned-Time Synchronization of Delayed Fuzzy Cellular Neural Networks with Discontinuous Activations
Hao Pu, Fengjun Li
Neural Process. Lett.2
2022 Generative Memory-Guided Semantic Reasoning Model for Image Inpainting
abstract
The critical challenge of single image inpainting stems from accurate semantic inference via limited information while maintaining image quality. Typical methods for semantic image inpainting train an encoder-decoder network by learning a one-to-one mapping from the corrupted image to the inpainted version. While such methods perform well on images with small corrupted regions, it is challenging for these methods to deal with images with large corrupted area due to two potential limitations. 1) Such one-to-one mapping paradigm tends to overfit each single training pair of images; 2) The inter-image prior knowledge about the general distribution patterns of visual semantics, which can be transferred across images sharing similar semantics, is not explicitly exploited. In this paper, we propose the Generative Memory-guided Semantic Reasoning Model (GM-SRM), which infers the content of corrupted regions based on not only the known regions of the corrupted image, but also the learned inter-image reasoning priors characterizing the generalizable semantic distribution patterns between similar images. In particular, the proposed GM-SRM first pre-learns a generative memory from the whole training data to explicitly learn the distribution of different semantic patterns. Then the learned memory are leveraged to retrieve the matching semantics for the current corrupted image to perform semantic reasoning during image inpainting. While the encoder-decoder network is used for guaranteeing the pixel-level content consistency, our generative priors are favorable for performing high-level semantic reasoning, which is particularly effective for inferring semantic content for large corrupted area. Extensive experiments on Paris Street View, CelebA-HQ, and Places2 benchmarks demonstrate that our GM-SRM outperforms the state-of-the-art methods for image inpainting in terms of both visual quality and quantitative metrics.
Xin Feng 0005, Wenjie Pei, Fengjun Li, Fanglin Chen 0001, David Zhang 0001, Guangming Lu 0002
IEEE Trans. Circuits Syst. Video Technol.3
2022 Interpreting Adversarial Examples and Robustness for Deep Learning-Based Auto-Driving Systems
abstract
Deep learning-based auto-driving systems are vulnerable to adversarial examples attacks which may result in wrong decision making and accidents. An adversarial example can fool the well trained neural networks by adding barely imperceptible perturbations to clean data. In this paper, we explore the mechanism of adversarial examples and adversarial robustness from the perspective of statistical mechanics, and propose an statistical mechanics-based interpretation model of adversarial robustness. The state transition caused by adversarial training based on the theory of fluctuation dissipation disequilibrium in statistical mechanics is formally constructed. Besides, we fully study the adversarial example attacks and training process on system robustness, including the influence of different training processes on network robustness. Our work is helpful to understand and explain the adversarial examples problems and improve the robustness of deep learning-based auto-driving systems.
Ke Wang 0068, Fengjun Li, Chien-Ming Chen 0001, Mohammad Mehedi Hassan, Jinyi Long, Neeraj Kumar 0001
IEEE Trans. Intell. Transp. Syst.2
2022 The Invisible Side of Certificate Transparency: Exploring the Reliability of Monitors in the Wild
abstract
To detect fraudulent TLS server certificates and improve the accountability of certification authorities (CAs), certificate transparency (CT) is proposed to record certificates in publicly-visible logs, from which the monitors fetch all certificates and watch for suspicious ones. However, if the monitors, either domain owners themselves or third-party services, fail to return a complete set of certificates issued for a domain of interest, potentially fraudulent certificates may not be detected and then the CT framework becomes less reliable. This paper presents the first systematic study on CT monitors. We analyze the data in 88 public logs and the services of 5 active third-party monitors regarding 3,000,431 certificates of 6,000 selected Alexa Top-1M websites. We find that although CT allows ordinary domain owners to act as monitors, it is impractical for them to perform reliable processing by themselves, due to the rapidly increasing volume of certificates in public logs (e.g., on average about 5 million records or 28.29 GB daily for the minimal set of logs that need to be monitored in 2018, or more than 7 million records per day in 2020, according to the Chrome CT policy). Moreover, our study discloses that (${a}$) none of the third-party monitors guarantees to return the complete set of certificates for a domain, and (${b}$) for some domains, even the union of the certificates returned by the five third-party monitors can probably be incomplete. As a result, the certificates accepted by CT-enabled browsers are not actually visible to the claimed domain owners, even when CT is adopted with well-functioning logs. The risk of invisible fraudulent certificates in public logs raises doubts on the reliability of CT in practice.
Bingyu Li 0003, Jingqiang Lin 0001, Fengjun Li, Qiongxiao Wang, Wei Wang 0314, Qi Li 0002, Guangshen Cheng, Jiwu Jing, Congli Wang
IEEE/ACM Trans. Netw.3
2021 Two Souls in an Adversarial Image: Towards Universal Adversarial Example Detection using Multi-view Inconsistency
abstract
In the evasion attacks against deep neural networks (DNN), the attacker generates adversarial instances that are visually indistinguishable from benign samples and sends them to the target DNN to trigger misclassifications. In this paper, we propose a novel multi-view adversarial image detector, namely Argos, based on a novel observation. That is, there exist two “souls” in an adversarial instance, i.e., the visually unchanged content, which corresponds to the true label, and the added invisible perturbation, which corresponds to the misclassified label. Such inconsistencies could be further amplified through an autoregressive generative approach that generates images with seed pixels selected from the original image, a selected label, and pixel distributions learned from the training data. The generated images (i.e., the “views”) will deviate significantly from the original one if the label is adversarial, demonstrating inconsistencies that Argos expects to detect. To this end, Argos first amplifies the discrepancies between the visual content of an image and its misclassified label induced by the attack using a set of regeneration mechanisms and then identifies an image as adversarial if the reproduced views deviate to a preset degree. Our experimental results show that Argos significantly outperforms two representative adversarial detectors in both detection accuracy and robustness against six well-known adversarial attacks. Code is available at: https://github.com/sohaib730/Argos-Adversarial_Detection
Sohaib Kiani, Sana Awan, Chao Lan, Fengjun Li, Bo Luo
ACSAC4
2021 CONTRA: Defending Against Poisoning Attacks in Federated Learning
Sana Awan, Bo Luo, Fengjun Li
ESORICS (1)3
2021 Exploiting Invariance of Mining Facial Landmarks
abstract
In this paper, we propose an invariant learning method for facial landmark mining in a self-supervised manner. The conventional methods mostly train with raw data of paired facial appearances and landmarks, assuming that they are evenly distributed. However, assumptions like this tend to lead to failures in challenging cases even undergo costly training since they usually don't hold in real-world scenarios. To address this issue, our model achieves to be invariant to facial biases by learning through the landmark-anchored distributions. Specifically, we generate faces from these distributions, then group them based on the appearance sources and the probe facial landmarks into intra-identities and intra-landmarks classes, respectively. Thus, we construct intra-class invariance losses to disentangle the spatial structures from appearances. In addition, we adopt a reconstruction loss to produce more realistic faces with probe landmarks. Extensive experimental results on four standard facial landmark datasets demonstrate that our method achieves compelling performance compared with supervised and unsupervised methods.
Jiangming Shi, Zixian Gao, Hao Liu 0019, Zekuan Yu, Fengjun Li
ACM Multimedia5
2021 From Library Portability to Para-rehosting: Natively Executing Microcontroller Software on Commodity Hardware
Le Guan, Jingqiang Lin 0001, Jiameng Shi, Fengjun Li
NDSS5
2021 You Are (not) Who Your Peers Are: Identification of Potentially Excessive Permission Requests in Android Apps
abstract
Millions of Android applications are now deployed on billions of smartphones and tablet devices. An enormous amount of users' private data are being collected and made accessible to such apps. Extensive research efforts have been devoted to smartphone app security. In particular, the current practice of the app markets and app security scanners is to ensure that the requested permissions are consistent with the used permissions. On the other hand, mobile apps need to seek consent from users to approve various permissions to access user information. However, users often blindly accept permission requests and apps start to abuse this mechanism. For example, a flashlight app may obtain users' locations and send them out to the server. As long as a permission is requested by the app developer and approved by the users, the state-of-art detection mechanisms will treat it as benign. In this paper, we ask the question “are the permission requests really necessary?” The question is difficult to answer because it is hard to autonomously “comprehend” whether a permission is needed for the functionality of the app. We take the first attempt to tackle this challenge by comparing an app's permission requests with its peer apps, i.e., apps with similar functionalities. An app that requests/uses significantly more permissions than its peers is considered potentially malicious that will require further investigation. With this idea, we design a statistical approach to identify potentially excessive permission requests and evaluate it with apps from Play Store. Experiment results and case studies show that the proposed mechanism could effectively identify highly suspicious apps, which request many permissions that are not relevant to their functionalities.
Prashanthi Mallojula, Javaria Ahmad, Fengjun Li, Bo Luo
TrustCom3
2021 Lattice-based weak-key analysis on single-server outsourcing protocols of modular exponentiations and basic countermeasures
Yunhai Zheng, Chengliang Tian, Hanlin Zhang 0001, Jia Yu 0003, Fengjun Li
J. Comput. Syst. Sci.5
2020 CANSentry: Securing CAN-Based Cyber-Physical Systems against Denial and Spoofing Attacks
Abdulmalik Humayed 0001, Fengjun Li, Jingqiang Lin 0001, Bo Luo
ESORICS (1)2
2020 How to securely outsource the extended euclidean algorithm for large-scale polynomials over finite fields
Chengliang Tian, Hanlin Zhang 0001, Jia Yu 0003, Fengjun Li
Inf. Sci.5
2019 Poster: A Reliable and Accountable Privacy-Preserving Federated Learning Framework using the Blockchain
abstract
Federated learning (FL) is promising in supporting collaborative learning applications that involve large datasets, massively distributed data owners and unreliable network connectivity. To protect data privacy, existing FL approaches adopt (k,n)-threshold secret sharing schemes, based on the semi-honest assumption for clients, to enable secure multiparty computation in local model update exchange which deals with random client dropouts at the cost of increasing data size. These approaches adopt the semi-honest assumption for clients, therefore they are vulnerable to malicious clients. In this work, we propose a blockchain-based privacy-preserving federated learning (BC-based PPFL) framework, which leverages the immutability and decentralized trust properties of blockchain to provide provenance of model updates. Our proof-of-concept implementation of BC-based PPFL demonstrates it is practical for secure aggregation of local model updates in the federated setting.
Sana Awan, Fengjun Li, Bo Luo
CCS2
2019 Certificate Transparency in the Wild: Exploring the Reliability of Monitors
abstract
To detect fraudulent TLS server certificates and improve the accountability of certification authorities (CAs), certificate transparency (CT) is proposed to record certificates in publicly-visible logs, from which the monitors fetch all certificates and watch for suspicious ones. However, if the monitors, either domain owners themselves or third-party services, fail to return a complete set of certificates issued for a domain of interest, potentially fraudulent certificates may not be detected and then the CT framework becomes less reliable. This paper presents the first systematic study on CT monitors. We analyze the data in 88 public logs and the services of 5 active third-party monitors regarding 3,000,431 certificates of 6,000 selected Alexa Top-1M websites. We find that although CT allows ordinary domain owners to act as monitors, it is impractical for them to perform reliable processing by themselves, due to the rapidly increasing volume of certificates in public logs (e.g., on average 5 million records or 28.29 GB daily for the minimal set of logs that need to be monitored). Moreover, our study discloses that (a) none of the third-party monitors guarantees to return the complete set of certificates for a domain, and (b) for some domains, even the union of the certificates returned by the five third-party monitors can probably be incomplete. As a result, the certificates accepted by CT-enabled browsers are not absolutely visible to the claimed domain owners, even when CT is adopted with well-functioning logs. The risk of invisible fraudulent certificates in public logs raises doubts on the reliability of CT in practice.
Bingyu Li 0003, Jingqiang Lin 0001, Fengjun Li, Qiongxiao Wang, Qi Li 0002, Jiwu Jing, Congli Wang
CCS3
2019 Secure Cryptography Infrastructures in the Cloud
abstract
Information systems are deployed in clouds as virtual machines (VMs) for better agility, elasticity and reliability. It is necessary to safekeep their cryptographic keys, e.g., the private keys used in TLS and SSH, against various attacks. However, existing virtualization solutions do not improve the cryptography facilities of in-cloud systems. This paper presents SECRIN, a secure cryptography infrastructure for VMs in the cloud. SECRIN is composed of a) virtual cryptographic devices implemented in VM monitors (VMMs), and b) a device management tool integrated in the virtualization management system. A virtual device receives requests from VMs, computes with cryptographic keys within the VMM and returns results. The keys appear only in the VMM's memory space, so that they are kept secret even if the VMs were compromised. With the management tool, the operator of virtualization management systems assigns virtual cryptographic devices to a VM as well as other resources, while the tenant (or owner) of a VM still holds proper controls on the keys. The virtual devices work compatibly with live migration, and the cryptographic computations are not interrupted when the VMs are moving from a host to another. We develop the SECRIN prototype with KVM-QEMU and oVirt. Experimental results show that, it works compatibly with existing virtualization solutions, provides reliable cryptographic computing services for applications, and is secure against attacks happening in VMs.
Dawei Chu, Kaijie Zhu, Quanwei Cai 0001, Jingqiang Lin 0001, Fengjun Li, Le Guan, Lingchen Zhang
GLOBECOM5
2019 Arcana: Enabling Private Posts on Public Microblog Platforms
Anirudh Narasimman, Qiaozhi Wang, Fengjun Li, Dongwon Lee 0001, Bo Luo
SEC3
2019 Ticket Transparency: Accountable Single Sign-On with Privacy-Preserving Public Logs
Dawei Chu, Jingqiang Lin 0001, Fengjun Li, Qiongxiao Wang, Guangqi Liu
SecureComm (1)3
2019 #DontTweetThis: Scoring Private Information in Social Networks
abstract
Abstract With the growing popularity of online social networks, a large amount of private or sensitive information has been posted online. In particular, studies show that users sometimes reveal too much information or unintentionally release regretful messages, especially when they are careless, emotional, or unaware of privacy risks. As such, there exist great needs to be able to identify potentially-sensitive online contents, so that users could be alerted with such findings. In this paper, we propose a context-aware, text-based quantitative model for private information assessment, namelyPrivScore, which is expected to serve as the foundation of a privacy leakage alerting mechanism. We first solicit diverse opinions on the sensitiveness of private information from crowdsourcing workers, and examine the responses to discover a perceptual model behind the consensuses and disagreements. We then develop a computational scheme using deep neural networks to compute a context-free PrivScore (i.e., the “consensus” privacy score among average users). Finally, we integrate tweet histories, topic preferences and social contexts to generate a personalized context-aware PrivScore. This privacy scoring mechanism could be employed to identify potentially-private messages and alert users to think again before posting them to OSNs.
Qiaozhi Wang, Hao Xue 0002, Fengjun Li, Dongwon Lee 0001, Bo Luo
Proc. Priv. Enhancing Technol.3
2018 Hide Your Hackable Smart Home from Remote Attacks: The Multipath Onion IoT Gateways
Lei Yang 0037, Chris Seasholtz, Bo Luo, Fengjun Li
ESORICS (1)4
2017 Understanding rating behavior based on moral foundations: The case of Yelp reviews
abstract
Moral inclinations expressed in user-generated content such as online reviews can provide useful insight to understand and predict people's rating behavior. In this work, we extracted a corpus of over 7,000 online reviews on Yelp that express moral concerns, and associated them to five moral factors defined in Moral Foundations Theory using the Doc2Vec natural language processing technique. We compared the rating distributions between the regular reviewers and the moral-concerned reviewers, and found that their rating patterns significantly differ from each other. Our findings also indicate that people with moral concerns tend to rate lower if a moral foundation is violated. Moreover, among the five moral factors, purity is the most distinctive moral foundation.
Pegah Nokhiz, Fengjun Li
IEEE BigData2
2017 A Content-Aware Trust Index for Online Review Spam Detection
Hao Xue 0002, Fengjun Li
DBSec2
2017 A time-synchronized ZigBee building network for smart water management
abstract
Water management is an important issue in economics and environment. Recently, amount of water control system has been proposed and developed. For the type of intelligent water control, the related parameters will be the input of the control system. Hence, there is a need of developing a scalable, flexible and reliable sensor network for related parameters monitoring. To install and replace water sensors in building networks, wireless connection will be the first priority. However, improper time synchronization in the network will cause packet loss and long latency which degrades the network performance. In this paper, time-synchronized ZigBee building network (TS-ZBN) is proposed for water management. The node-to-node time synchronization is proposed. The concept is to calculate the clock difference by studying the propagation delay model. The simulation result shows that the mean synchronization error and variance are low.
Chung Kit Wu, Hongxu Zhu, Loi Lei Lai, Anna S. F. Chang, Fengjun Li, Kim Fung Tsang, Roy Kalawsky
INDIN5
2017 Cyber-Physical Systems Security - A Survey
abstract
With the exponential growth of cyber-physical systems (CPSs), new security challenges have emerged. Various vulnerabilities, threats, attacks, and controls have been introduced for the new generation of CPS. However, there lacks a systematic review of the CPS security literature. In particular, the heterogeneity of CPS components and the diversity of CPS systems have made it difficult to study the problem with one generalized model. In this paper, we study and systematize existing research on CPS security under a unified framework. The framework consists of three orthogonal coordinates: 1) from the security perspective, we follow the well-known taxonomy of threats, vulnerabilities, attacks and controls; 2) from the CPS components perspective, we focus on cyber, physical, and cyberphysical components; and 3) from the CPS systems perspective, we explore general CPS features as well as representative systems (e.g., smart grids, medical CPS, and smart cars). The model can be both abstract to show general interactions of components in a CPS application, and specific to capture any details when needed. By doing so, we aim to build a model that is abstract enough to be applicable to various heterogeneous CPS applications; and to gain a modular view of the tightly coupled CPS components. Such abstract decoupling makes it possible to gain a systematic understanding of CPS security, and to highlight the potential sources of attacks and ways of protection. With this intensive literature review, we attempt to summarize the state-of-the-art on CPS security, provide researchers with a comprehensive list of references, and also encourage the audience to further explore this emerging field.
Abdulmalik Humayed 0001, Jingqiang Lin 0001, Fengjun Li, Bo Luo
IEEE Internet Things J.3
2016 A multi-cloud based privacy-preserving data publishing scheme for the internet of things
Lei Yang 0037, Abdulmalik Humayed 0001, Fengjun Li
ACSAC3
2015 POSTER: A Hardware Fingerprint Using GPU Core Frequency Variations
abstract
Hardware primitives provide significant promises to support cryptographic primitives and security mechanisms against various forms of compromises. In this work, we study the intrinsic hardware characteristics of modern graphics processing units (GPUs) due to random manufacturing variations, and exploits the inherent randomness to generate device-specific signatures. In particular, we present a novel GPU-based hardware fingerprint scheme to generate a unique, stable, physically unclonable, unpredictable, and random bit string from the inherent hardware features of a general purpose GPU (GPGPU). The generated fingerprint can be used to implement a physically unclonable function (PUF), and thus to create a trusted computing environment with GPUs as the trust anchor.
Fengjun Li, Xin Fu 0001, Bo Luo
CCS1
2015 Enhancing Traffic Analysis Resistance for Tor Hidden Services with Multipath Routing
Lei Yang 0037, Fengjun Li
SecureComm2
2014 SEDB: Building Secure Database Services for Sensitive Data
Quanwei Cai 0001, Jingqiang Lin 0001, Fengjun Li, Qiongxiao Wang
ICICS3
2014 EFS: Efficient and Fault-Scalable Byzantine Fault Tolerant Systems Against Faulty Clients
Quanwei Cai 0001, Jingqiang Lin 0001, Fengjun Li, Qiongxiao Wang, Daren Zha
SecureComm (1)3
2014 virtio-ct: A Secure Cryptographic Token Service in Hypervisors
Le Guan, Fengjun Li, Jiwu Jing, Ziqiang Ma
SecureComm (2)2
2013 Enforcing Secure and Privacy-Preserving Information Brokering in Distributed Information Sharing
abstract
Today's organizations raise an increasing need for information sharing via on-demand access. Information brokering systems (IBSs) have been proposed to connect large-scale loosely federated data sources via a brokering overlay, in which the brokers make routing decisions to direct client queries to the requested data servers. Many existing IBSs assume that brokers are trusted and thus only adopt server-side access control for data confidentiality. However, privacy of data location and data consumer can still be inferred from metadata (such as query and access control rules) exchanged within the IBS, but little attention has been put on its protection. In this paper, we propose a novel approach to preserve privacy of multiple stakeholders involved in the information brokering process. We are among the first to formally define two privacy attacks, namely attribute-correlation attack and inference attack, and propose two countermeasure schemes automaton segmentation and query segment encryption to securely share the routing decision-making responsibility among a selected set of brokering servers. With comprehensive security analysis and experimental results, we show that our approach seamlessly integrates security enforcement with query routing to provide system-wide security with insignificant overhead.
Fengjun Li, Bo Luo, Peng Liu 0005, Dongwon Lee 0001, Chao-Hsien Chu
IEEE Trans. Inf. Forensics Secur.1
2012 Stalking online: on user privacy in social networks
abstract
With the extreme popularity of Web and online social networks, a large amount of personal information has been made available over the Internet. On the other hand, advances in information retrieval, data mining and knowledge discovery technologies have enabled users to efficiently satisfy their information needs over the Internet or from large-scale data sets. However, such technologies also help the adversaries such as web stalkers to discover private information about their victims from mass data.
Yuhao Yang 0007, Jonathan Lutes, Fengjun Li, Bo Luo, Peng Liu 0005
CODASPY3
2012 Detecting review spam: Challenges and opportunities
abstract
Online customer reviews for both products or merchants have greatly affected others’ decision making in purchase. Considering the easily accessibility of the reviews and the significant impacts to the retailers, there is an increasing incentive to manipulate the reviews, mostly profit-driven. With
Fengjun Li
CollaborateCom2
2011 Privacy Preserving Group Linkage
Fengjun Li, Yuxin Chen 0001, Bo Luo, Dongwon Lee 0001, Peng Liu 0005
SSDBM1
2011 New threats to health data privacy
abstract
BACKGROUND: Along with the rapid digitalization of health data (e.g. Electronic Health Records), there is an increasing concern on maintaining data privacy while garnering the benefits, especially when the data are required to be published for secondary use. Most of the current research on protecting health data privacy is centered around data de-identification and data anonymization, which removes the identifiable information from the published health data to prevent an adversary from reasoning about the privacy of the patients. However, published health data is not the only source that the adversaries can count on: with a large amount of information that people voluntarily share on the Web, sophisticated attacks that join disparate information pieces from multiple sources against health data privacy become practical. Limited efforts have been devoted to studying these attacks yet. RESULTS: We study how patient privacy could be compromised with the help of today's information technologies. In particular, we show that private healthcare information could be collected by aggregating and associating disparate pieces of information from multiple online data sources including online social networks, public records and search engine results. We demonstrate a real-world case study to show user identity and privacy are highly vulnerable to the attribution, inference and aggregation attacks. We also show that people are highly identifiable to adversaries even with inaccurate information pieces about the target, with real data analysis. CONCLUSION: We claim that too much information has been made available electronic and available online that people are very vulnerable without effective privacy protection.
Fengjun Li, Xukai Zou, Peng Liu 0005, Jake Yue Chen
BMC Bioinform.1
2010 A Node-failure-resilient Anonymous Communication Protocol through Commutative Path Hopping
abstract
With rising concerns on user privacy over the Internet, anonymous communication systems that hide the identity of a participant from its partner or third parties are highly desired. Existing approaches either rely on a relative small set of pre-selected relay servers to redirect the messages, or use structured peer-to-peer systems to multicast messages among a set of relay groups. The pre-selection approaches provide good anonymity, but suffer from node failures and scalability problem. The peer-to-peer approaches are subject to node churns and high maintenance overhead, which are the intrinsic problems of P2P systems. In this paper, we present CAT, a node-failure-resilient anonymous communication protocol. In this protocol, relay servers are randomly assigned to relay groups. The initiator of a connection selects a set of relay groups instead of relay servers to set up anonymous paths. A valid path consists of relay servers, one from each selected relay group. The initiator explores valid anonymous paths via a probing process. Since the relative positions of relay servers in the path are commutative, there exist multiple anonymous yet commutative paths, which form an anonymous tunnel. When a connection encounters a node failure, it quickly switches to a nearest backup path in the tunnel through "path hopping", without tampering the initiator or renegotiating the keys. Hence, the protocol is resilient to node failures. We also show that the protocol provides good anonymity even when facing types of active and passive attacks. Finally, the operating cost of CAT is analyzed and shown to be similar to other node-based anonymous communication protocols.
Fengjun Li, Bo Luo, Peng Liu 0005, Chao-Hsien Chu
INFOCOM1
2009 Approximation to Nonlinear Discrete-Time Systems by Recurrent Neural Networks
Fengjun Li
ISNN (4)1
2008 Defending against Attribute-Correlation Attacks in Privacy-Aware Information Brokering
Fengjun Li, Bo Luo, Peng Liu 0005, Anna Cinzia Squicciarini, Dongwon Lee 0001, Chao-Hsien Chu
CollaborateCom1
2008 Function Approximation by Neural Networks
Fengjun Li
ISNN (1)1
2007 Automaton segmentation: a new approach to preserve privacy in xml information brokering
abstract
A Distributed Information Brokering System (DIBS) is a peer-to-peer overlay network that comprises diverse data servers and brokering components helping client queries locate the data server(s). Many existing information brokering systems adopt server side access control deployment and honest assumptions on brokers. However, little attention has been drawn on privacy of data and metadata stored and exchanged within DIBS. In this paper, we address privacy-preserving information sharing via on-demand information access. We propose a flexible and scalable system using a broker-coordinator overlay network. Through an innovative automaton segmentation scheme, distributed access control enforcement, and query segment encryption, our system integrates security enforcement and query forwarding while preserving system-wide privacy. We present the automaton segmentation approach, analyze privacy preservation in details, and finally examine the end-to-end performance and scalability through experiments and analysis.
Fengjun Li, Bo Luo, Peng Liu 0005, Dongwon Lee 0001, Chao-Hsien Chu
CCS1