Xinyu Wang 0007

dblp:68/1277-7 · DBLP profile ↗
← Back
20ranked-venue papers
1as first author
4since 2021 · last 2024
0000-0002-2602-5551ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 1 first-author · 3 since 2021Computer networks · 7 · 1 since 2021Systems, architecture and hardware · 3 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2
YearPublicationVenuePosition
2024 Toward Evaluating Robustness of Reinforcement Learning with Adversarial Policy
abstract
Reinforcement learning agents are susceptible to evasion attacks during deployment. In single-agent environments, these attacks can occur through imperceptible perturbations injected into the inputs of the victim policy network. In multi-agent environments, an attacker can manipulate an adversarial opponent to influence the victim policy's observations indirectly. While adversarial policies offer a promising technique to craft such attacks, current methods are either sample-inefficient due to poor exploration strategies or require extra surrogate model training under the black-box assumption. To address these challenges, in this paper, we propose Intrinsically Motivated Adversarial Policy (IMAP) for efficient black-box adversarial policy learning in both single- and multi-agent environments. We formulate four types of adversarial intrinsic regularizers—maximizing the adversarial state coverage, policy coverage, risk, or divergence—to discover potential vulnerabilities of the victim policy in a principled way. We also present a novel bias-reduction method to balance the extrinsic objective and the adversarial intrinsic regularizers adaptively. Our experiments validate the effectiveness of the four types of adversarial intrinsic regularizers and the bias-reduction method in enhancing black-box adversarial policy learning across a variety of environments. Our IMAP successfully evades two types of defense methods, adversarial training and robust regularizer, decreasing the performance of the state-of-the-art robust WocaR-PPO agents by 34%-54% across four single-agent tasks. IMAP also achieves a state-of-the-art attacking success rate of 83.91% in the multi-agent game YouShallNotPass. Our code is available at https://github.com/x-zheng16/IMAP.
Xingjun Ma, Xinyu Wang 0007, Chao Shen 0001, Cong Wang 0001
DSN4
2023 Boomerang: Metadata-Private Messaging under Hardware Trust
Peipei Jiang 0002, Qian Wang 0002, Jianhao Cheng, Cong Wang 0001, Lei Xu 0019, Xinyu Wang 0007, Xiaoyuan Li 0001, Kui Ren 0001
NSDI6
2022 WebEnclave: Protect Web Secrets From Browser Extensions With Software Enclave
abstract
Browser extensions are widely used nowadays to customize users’ browsers with more functionalities, meanwhile introduce potential risks due to escalated privileges. Existing security mechanisms, such as Same Origin Policy and Content Security Policy, do not apply to browser extensions that can read and write on web applications at any time. In spite of the state-of-the-art industrial efforts that rely on centralized management to inspect and detect malicious behaviors massively, the detection-based method cannot analyze fast-evolving behaviors of malicious browser extensions. To this end, we adopt a novel approach to protect users from malicious browser extensions, where we consider the problem of malicious extensions on the side of web applications. From a high level point of view, web developers are allowed to specify sensitive parts in a web application by using our provided software enclave. With our proposed WebEnclave extension installed, when users visit a web application, sensitive information required for the web application to work normally is sealed into an isolated world locally that malicious extensions cannot access. Extensive evaluation of our built prototype shows it can effectively protect user secrets from malicious extensions with negligible performance overhead and usability inconvenience. We also publish source codes for public use.
Xinyu Wang 0007, Yuefeng Du 0001, Cong Wang 0001, Qian Wang 0002, Liming Fang 0001
IEEE Trans. Dependable Secur. Comput.1
2021 PPSB: An Open and Flexible Platform for Privacy-Preserving Safe Browsing
abstract
Safe Browsing (SB) is an important security feature in modern web browsers to help detect new unsafe websites. Although useful, recent studies have pointed out that the widely adopted SB services, such as Google Safe Browsing and Microsoft SmartScreen, can raise privacy concerns since users' browsing history might be subject to unauthorized leakage to service providers. In this paper, we present a Privacy-Preserving Safe Browsing (PPSB) platform. It bridges the browser that uses the service and the third-party blacklist providers who provide unsafe URLs, with the guaranteed privacy of users and blacklist providers. Particularly, in PPSB, the actual URL to be checked, as well as its associated hashes or hash prefixes, never leave the browser in cleartext. This protects the user's browsing history from being directly leaked or indirectly inferred. Moreover, these lists of unsafe URLs, the most valuable asset for the blacklist providers, are always encrypted and kept private within our platform. Extensive evaluations using real datasets (with over 1 million unsafe URLs) demonstrate that our prototype can function as intended without sacrificing normal user experience, and block unsafe URLs at the millisecond level. All resources, including Chrome extension, Docker image, and source code, are available for public use.
Helei Cui, Yajin Zhou, Cong Wang 0001, Xinyu Wang 0007, Yuefeng Du 0001, Qian Wang 0002
IEEE Trans. Dependable Secur. Comput.4
2019 Enabling Encrypted Rich Queries in Distributed Key-Value Stores
abstract
To accommodate massive digital data, distributed data stores have become the main solution for cloud services. Among others, key-value stores are widely adopted due to their superior performance. But with the rapid growth of cloud storage, there are growing concerns about data privacy. In this paper, we design and build EncKV, an encrypted and distributed key-value store with rich query support. First, EncKV partitions data records with secondary attributes into a set of encrypted key-value pairs to hide relations between data values. Second, EncKV uses the latest cryptographic techniques for searching on encrypted data, i.e., searchable symmetric encryption (SSE) and order-revealing encryption (ORE) to support secure exact-match and range-match queries, respectively. It further employs a framework for encrypted and distributed indexes supporting query processing in parallel. To address inference attacks on ORE, EncKV is equipped with an enhanced ORE scheme with reduced leakage. For practical considerations, EncKV also enables secure system scaling in a minimally intrusive way. We complete the prototype implementation and deploy it on Amazon Cloud. Experimental results confirm that EncKV preserves the efficiency and scalability of distributed key-value stores.
Yu Guo 0003, Xingliang Yuan, Xinyu Wang 0007, Cong Wang 0001, Baochun Li, Xiaohua Jia
IEEE Trans. Parallel Distributed Syst.3
2018 IoT for Next-Generation Racket Sports Training
abstract
We propose an Internet of Things (IoT) framework for next-generation racket sports training. To validate its performance, a wireless wearable sensing device (WSD) based on microelectromechanical systems motion sensors was used to recognize different badminton strokes and classify skill levels from different badminton players. The system includes a customized sensor node for data collection, a mobile app, and a cloud-based data processing unit. The WSD developed is low-cost, easy-to-use, and computationally efficient compared to video-based methods for analyzing badminton strokes. It offers the advantage of dynamic monitoring of multiple players in indoor and outdoor environments. In this paper, we present the hardware design, mobile software implementation, and data processing algorithms of the system. Twelve right-handed male subjects wore the WSD on their wrists while each performed 30 trials of different strokes in a real badminton court. The results show that our system is capable of recognizing three different actions, i.e.,smashes,clears, anddrops, with an accuracy rate of 97%. The skill assessment function can differentiate between professional, subelite, and amateur players from their stroke performance. This IoT framework aims to change the way of racket sports training from experience-driven (subjective) to data-driven (objective), and which can be easily extended to analyze the motions and skill levels of players in other racket sports (e.g., tennis, table tennis, and squash) for training and/or practice.
Meng Chen 0007, Xinyu Wang 0007, Rosa H. M. Chan, Wen Jung Li
IEEE Internet Things J.3
2018 Towards Privacy-Preserving and Practical Image-Centric Social Discovery
abstract
Images are becoming one of the key enablers of user connectivity in social media applications. Many of them are directly exploring image content to suggest new friends with similar interests. To handle the explosive volumes of images, one common trend is to leverage the public cloud as their robust service backend. Despite the convenience, exposing content-rich images to the cloud inevitably raises acute privacy concerns. In this paper, we propose a privacy-preserving architecture for image-centric social discovery services, designed to function over encrypted images. We first adopt the effective Bag-of-Words model to extract the “visual content” of users' images into respective image profile vectors. We then model the core problem as similarity retrieval of encrypted high-dimensional vectors. To achieve scalable services over millions of encrypted images, we design a secure and efficient index structure, which enables practical and accurate social discovery from the cloud, without revealing any image profile or image content. For completeness, we further enrich our service with secure updates, facilitating user's image update. Our implementation is deployed at an Android phone and Amazon Cloud, and extensive experiments are conducted on a large Flickr image dataset which demonstrates the desired quality of services.
Xingliang Yuan, Xinyu Wang 0007, Cong Wang 0001, Anna Cinzia Squicciarini, Kui Ren 0001
IEEE Trans. Dependable Secur. Comput.2
2018 Construction and Mitigation of User-Behavior-Based Covert Channels on Smartphones
abstract
To protect user privacy, many smartphone systems adopt the permission-based mechanism in which a user can evaluate the risk of requests for private information from a mobile app before installing it. However, recent studies show that the permission based mechanism is vulnerable to application collusion attacks because two apps, which appear to be harmless individually, can establish a covert channel and use it to leak confidential information. Consequently, people have designed some covert channel detection schemes, by checking abnormal status of the phone. In this paper, we point out that existing covert channel detection schemes may fail to detect a new type of collusion attacks referred as user-behavior-based covert channels. We implement three covert channels on Android smartphones. Our work sets a new alarm for the security issue of using smartphones. We then study the countermeasures to this new type of covert channels. Instead of trying to directly detect the proposed new type of covert channels, we propose two mitigation solutions to reduce the effectiveness of such covert channels. The mitigation solutions are also valid to other existing sensor-based side channels and/or covert channels on the phone.
Wanfu Ding, Xinyu Wang 0007, Yonghang Jiang, Jianping Wang 0001, Kejie Lu
IEEE Trans. Mob. Comput.3
2017 EncKV: An Encrypted Key-value Store with Rich Queries
abstract
Distributed data stores have been rapidly evolving to serve the needs of large-scale applications such as online gaming and real-time targeting. In particular, distributed key-value stores have been widely adopted due to their superior performance. However, these systems do not guarantee to provide strong protection of data confidentiality, and as a result fall short of addressing serious privacy concerns raised from massive data breaches.
Xingliang Yuan, Yu Guo 0003, Xinyu Wang 0007, Cong Wang 0001, Baochun Li, Xiaohua Jia
AsiaCCS3
2017 Privacy-Preserving Similarity Joins Over Encrypted Data
abstract
Similarity search on high-dimensional data has been intensively studied for data processing and analytics. Despite its broad applicability, data security and privacy concerns along the trend of data outsourcing have not been fully addressed. In this paper, we investigate privacy-preserving similarity join queries, i.e., a pivotal primitive of similarity search that finds pairwise similar data points across two data sets. We start from locality-sensitive hashing and searchable symmetric encryption, i.e., the most practical techniques for similarity search and encrypted search, respectively. However, the immediate combination of two techniques discloses the distribution of the query set, which is exploitable to compromise the confidentiality of queries. To enhance the security, we propose the frequency hiding query scheme, which allows the server to see the flattened query distribution only. To improve the scalability, we further design the result sharing query scheme, which processes a small portion of query points and shares the results with other nearby points. Besides, we set up a strict constraint to carefully select query points to achieve “as-strong-as-possible” guarantees. We formalize the leakage functions in the context of similarity joins, and conduct rigorous security analysis. We implement and evaluate the proposed query schemes on Azure cloud. Experimental results indicate that they have different tradeoffs on security, efficiency, and accuracy, which can flexibly be used for different deployment scenarios.
Xingliang Yuan, Xinyu Wang 0007, Cong Wang 0001, Chenyun Yu, Sarana Nutanong
IEEE Trans. Inf. Forensics Secur.2
2017 Toward Encrypted Cloud Media Center With Secure Deduplication
abstract
The explosive growth of multimedia contents, especially videos, is pushing forward the paradigm of cloud-based media hosting today. However, the wide attacking surface of the public cloud and the growing security awareness from the society are both calling for data encryption before outsourcing to cloud. Under the circumstance of encrypted videos, how to still preserve all the service benefits of cloud media center remains to be fully explored. In this paper, we present a secure system architecture design as our initial effort toward this direction, which bridges together the advancements of video coding techniques and secure deduplication. Our design enables the cloud with the crucial deduplication functionality to completely eliminate the extra storage and bandwidth cost, which would have been incurred by hosting encrypted videos from different entities. The design is also carefully tailored to the scalable video coding (SVC) techniques to support heterogeneous networks and devices for high-quality adaptive video dissemination. We show fully functional system implementations with structure-aware encryption design and structure-aware deduplication strategies that are both completely compliant with the video format in SVC. Extensive security analysis and experiments via our prototype deployed on Azure cloud platform show the practicality of the design. Our work can also be easily extended to support other media applications that employ media files with scalable structures.
Yifeng Zheng 0001, Xingliang Yuan, Xinyu Wang 0007, Jinghua Jiang, Cong Wang 0001, Xiaolin Gui
IEEE Trans. Multim.3
2016 Building an Encrypted, Distributed, and Searchable Key-value Store
abstract
Modern distributed key-value stores are offering superior performance, incremental scalability, and fine availability for data-intensive computing and cloud-based applications. Among those distributed data stores, the designs that ensure the confidentiality of sensitive data, however, have not been fully explored yet. In this paper, we focus on designing and implementing an encrypted, distributed, and searchable key-value store. It achieves strong protection on data privacy while preserving all the above prominent features of plaintext systems. We first design a secure data partition algorithm that distributes encrypted data evenly across a cluster of nodes. Based on this algorithm, we propose a secure transformation layer that supports multiple data models in a privacy-preserving way, and implement two basic APIs for the proposed encrypted key-value store. To enable secure search queries for secondary attributes of data, we leverage searchable symmetric encryption to design the encrypted secondary indexes which consider security, efficiency, and data locality simultaneously, and further enable secure query processing in parallel. For completeness, we present formal security analysis to demonstrate the strong security strength of the proposed designs. We implement the system prototype and deploy it to a cluster at Microsoft Azure. Comprehensive performance evaluation is conducted in terms of Put/Get throughput, Put/Get latency under different workloads, system scaling cost, and secure query performance. The comparison with Redis shows that our prototype can function in a practical manner.
Xingliang Yuan, Xinyu Wang 0007, Cong Wang 0001, Chen Qian 0001, Jianxiong Lin
AsiaCCS2
2016 Privacy-preserving deep packet inspection in outsourced middleboxes
abstract
Middleboxes are essential for a wide range of advanced traffic processing in modern enterprise networks. Recent trend of deploying middleboxes in cloud as virtualized services further expands potential benefits of middleboxes while avoiding local maintenance burdens. Despite promising, designing outsourced middleboxes still faces several security challenges. First, many middlebox processing services, like intrusion detection, require packet payload inspection, while the ever-increasing adoption of HTTPS limits the function due to the end-to-end encryption. Second, many packet inspection rules used by middleboxes can be proprietary in nature. They may contain sensitive information of enterprises, and thus need strong protection when configuring middleboxes in untrusted outsourced environments. In this paper, we propose a practical system architecture for outsourced middleboxes to perform deep packet inspection over encrypted traffic, without revealing either packet payloads or inspection rules. Our first design is an encrypted high-performance rule filter that takes randomized tokens from packet payloads for encrypted inspection. We then elaborate through carefully tailored techniques how to comprehensively support open-source real rulesets. We formally analyze the security strength. Implementations at Amazon Cloud show that our system introduces roughly 100 millisecond latency in each connection initialization, with individual processing throughput over 3500 packets/second for 500 concurrent connections.
Xingliang Yuan, Xinyu Wang 0007, Jianxiong Lin, Cong Wang 0001
INFOCOM2
2016 Enabling Secure and Efficient Video Delivery Through Encrypted In-Network Caching
abstract
In-network content caching has been a natural trend in emerging network architectures to handle the exponential growth of video traffic. However, due to the potentially wide attacking surfaces, caching video content in the increasingly untrusted networked environment inevitably raises new concerns on user privacy exposure and unauthorized video access. Existing encrypted protocols like HTTPs either fall short of fully leveraging in-network caching or require decrypting the traffic in the middle without guaranteeing the end-to-end security. In this paper, we present a new networked system for efficient encrypted video delivery while preserving the benefits of in-network caching. As video chunks are encrypted before distribution, we first design a compact, efficient, yet encrypted video fingerprint index to empower the network with a fully controlled capability of locating the cached encrypted chunks for given encrypted requests. We then explain how to deploy the encrypted design in our proposed architecture and present a secure redundancy elimination protocol to enable fast video delivery via leveraging cached encrypted chunks. We further discuss the full support of cache management, adaptive video delivery, and video access control. Rigorous analysis and prototype evaluations demonstrate the security, efficiency, and effectiveness of the design.
Xingliang Yuan, Xinyu Wang 0007, Jinfan Wang, Yilei Chu, Cong Wang 0001, Jianping Wang 0001, Marie-José Montpetit, Shucheng Liu
IEEE J. Sel. Areas Commun.2
2016 Enabling Secure and Fast Indexing for Privacy-Assured Healthcare Monitoring via Compressive Sensing
abstract
As e-health technology continues to advance, health related multimedia data is being exponentially generated from healthcare monitoring devices and sensors. Coming with it are the challenges on how to efficiently acquire, index, and process such a huge amount of data for effective healthcare and related decision making, while respecting user's data privacy. In this paper, we propose a secure cloud-based framework for privacy-aware healthcare monitoring systems, which allows fast data acquisition and indexing with strong privacy assurance. For efficient data acquisition, we adopt compressive sensing for easy data sampling, compression, and recovery. We then focus on how to secure and fast index the resulting large amount of continuously generated compressed samples, with the goal to achieve secure selected retrieval over compressed storage. Among others, one particular challenge is the practical demand to cope with the incoming data samples in high acquisition rates. For that problem, we carefully exploit recent efforts on encrypted search, efficient content-based indexing techniques, and fine-grained locking algorithms, to design a novel encrypted index with high-performance customization. It achieves memory efficiency, provable security, as well as greatly improved building speed with nontrivial multithread support. Comprehensive evaluations on Amazon Cloud show that our encrypted design can securely index 1 billion compressed data samples within only 12 min, achieving a throughput of indexing almost 1.4 million encrypted samples per second. Accuracy and visual evaluation on a real healthcare dataset shows good quality of high-value retrieval and recovery over encrypted data samples.
Xingliang Yuan, Xinyu Wang 0007, Cong Wang 0001, Jian Weng 0001, Kui Ren 0001
IEEE Trans. Multim.2
2015 Enabling Encrypted Cloud Media Center with Secure Deduplication
abstract
Multimedia contents, especially videos, are being exponentially generated today. Due to the limited local storage, people are willing to store the videos at the remote cloud media center for its low cost and scalable storage. However, videos may have to be encrypted before outsourcing for privacy concerns. For practical purposes, the cloud media center should also provide the deduplication functionality to eliminate the storage and bandwidth redundancy, and adaptively disseminate videos to heterogeneous networks and different devices to ensure the quality of service. In light of the observations, we present a secure architecture enabling the encrypted cloud media center. It builds on top of latest advancements on secure deduplication and video coding techniques, with fully functional system implementations on encrypted video deduplication and adaptive video dissemination services. Specifically, to support efficient adaptive dissemination, we utilize the scalable video coding (SVC) techniques and propose a tailored layer-level secure deduplication strategy to be compatible with the internal structure of SVC. Accordingly, we adopt a structure-compatible encryption mechanism and optimize the way how encrypted SVC videos are stored for fast retrieval and efficient dissemination. We thoroughly analyze the security strength of our system design with strong video protection. Furthermore, we give a prototype implementation with encrypted end-to-end deployment on Amazon cloud platform. Extensive experiments demonstrate the practicality of our system.
Yifeng Zheng 0001, Xingliang Yuan, Xinyu Wang 0007, Jinghua Jiang, Cong Wang 0001, Xiaolin Gui
AsiaCCS3
2015 Enabling Privacy-Assured Similarity Retrieval over Millions of Encrypted Records
Xingliang Yuan, Helei Cui, Xinyu Wang 0007, Cong Wang 0001
ESORICS (2)3
2015 How to Bid the Cloud
abstract
Amazon's Elastic Compute Cloud (EC2) uses auction-based spot pricing to sell spare capacity, allowing users to bid for cloud resources at a highly reduced rate. Amazon sets the spot price dynamically and accepts user bids above this price. Jobs with lower bids (including those already running) are interrupted and must wait for a lower spot price before resuming. Spot pricing thus raises two basic questions: how might the provider set the price, and what prices should users bid? Computing users' bidding strategies is particularly challenging: higher bid prices reduce the probability of, and thus extra time to recover from, interruptions, but may increase users' cost. We address these questions in three steps: (1) modeling the cloud provider's setting of the spot price and matching the model to historically offered prices, (2) deriving optimal bidding strategies for different job requirements and interruption overheads, and (3) adapting these strategies to MapReduce jobs with master and slave nodes having different interruption overheads. We run our strategies on EC2 for a variety of job sizes and instance types, showing that spot pricing reduces user cost by 90% with a modest increase in completion time compared to on-demand pricing.
Liang Zheng 0002, Carlee Joe-Wong, Chee-Wei Tan 0001, Mung Chiang, Xinyu Wang 0007
SIGCOMM5
2014 Enabling Privacy-Preserving Image-Centric Social Discovery
abstract
The increasing popularity of images at social media sites is posing new opportunities for social discovery applications, i.e., suggesting new friends and discovering new social groups with similar interests via exploring images. To effectively handle the explosive growth of images involved in social discovery, one common trend for many emerging social media sites is to leverage the commercial public cloud as their robust backend data center. While extremely convenient, directly exposing content-rich images and the related social discovery results to the public cloud also raises new acute privacy concerns. In light of the observation, in this paper we propose a privacy-preserving social discovery service architecture based on encrypted images. As the core of such social discovery is to compare and quantify similar images, we first adopt the effective Bag-of-Words model to extract the "visual similarity content" of users' images into image profile vectors, and then model the problem as similarity retrieval of encrypted high-dimensional image profiles. To support fast and scalable similarity search over hundreds of thousands of encrypted images, we propose a secure and efficient indexing structure. The resulting design enables social media sites to obtain secure, practical, and accurate social discovery from the public cloud, without disclosing the encrypted image content. We formally prove the security and discuss further extensions on user image update and the compatibility with existing image sharing social functionalities. Extensive experiments on a large Flickr image dataset demonstrate the practical performance of the proposed design. Our qualitative social discovery results show consistency with human perception.
Xingliang Yuan, Xinyu Wang 0007, Cong Wang 0001, Anna Cinzia Squicciarini, Kui Ren 0001
ICDCS2
2014 AI3: application-independent information infrastructure
abstract
In the current Internet architecture, application service providers (ASPs) own users' data and social groups information, which made a handful of ASP companies growing bigger and bigger and denied small and medium companies from entering this business. We propose a new architecture, called Application Independent Information Infrastructure (AI3). The design goals of AI3 are: 1) Decoupling users' data from ASPs and users' social relations from ASPs, such that ASPs become independent from users' data and social relations. 2) Open architecture, such that different ASPs can interoperate with each other. This demo is to show a prototype of AI3. The demo has four parts: 1) ASPindependent data management in AI3; 2) ASP-independent management of users' social relations in AI3; 3) inter-domain data transport and user roaming; 4) real-time communications by using AI3. The demo video can be watched at: http://www.cs.cityu.edu.hk/~jia/AI3_DemoVideo.mp4
Bo Zhang 0036, Jinfan Wang, Xinyu Wang 0007, Tracy Yingying Cheng, Xiaohua Jia, Jianfei He
SIGCOMM3