Dandan Xu

dblp:94/8594 · DBLP profile ↗
← Back
13ranked-venue papers
3as first author
10since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 2 first-author · 5 since 2021Systems, architecture and hardware · 2 · 2 since 2021Computer networks · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 REACTS: robust encrypted search for dynamic spatial-textual data with permission control
abstract
Abstract The proliferation of spatial-textual data applications has created significant challenges in securely managing such data within untrusted cloud environments. Existing encrypted spatial-textual data retrieval schemes primarily focus on static data and overlook the complexities of practical data updates, particularly lacking robustness in managing irrational updates. In this paper, we introduce a novel robust dynamic encrypted spatial-textual data search scheme, called , that enhances existing systems by addressing the challenges of security and robustness in data dynamic settings. This is the first scheme to simultaneously achieve forward security, Type-I $$^-$$ - backward security, and enhanced robustness for boolean range queries on spatial-textual data. We formally define the security model and classify three levels of robustness. Our customized Asymmetric Scalar-Product-Preserving Encryption (ASPE) design incorporates an “update check mechanism” can efficiently mitigate repeated and disruptive update attacks while supporting efficient search and update permission control. Experimental evaluations demonstrate that only maintains 100% precision and recall while showing practical search efficiency, even outperforming the existing static scheme with a similar ASPE-based approach.
Jiabei Wang, Dandan Xu, Yiwen Gao 0001, Yongbin Zhou
Cybersecur.3
2025 Spidey: Secure Dynamic Encrypted Property Graph Search With Lightweight Access Control
abstract
Graph databases, which essentially store network nodes and edge relationships between them, offer a promising solution for managing the large and dynamic Internet of Things (IoT) network. However, as data grows explosively, end devices cannot carry it, forcing organizations to outsource storage to cloud servers, bringing privacy risks, such as data leakage. Existing privacy-preserving graph search schemes either fail to support secure and efficient multigranularity updates over encrypted complicated property graph or neglect multiuser access control, greatly limiting their practicability. In this article, we propose a novel dynamic encrypted property graph search system along with three full-fledged constructions, named Spidey. We model the property graph and introduce two well-designed structures: bidirectional index and delete list, which form the foundation of our schemes. The basic schemeDGraphsupports efficient, fine-grained sublinear queries and updates with the complexity of both attribute-grained update and node-grained deletion being$\mathcal {O}(1)$, while ensuring both forward privacy (FP) and backward privacy (BP). Two enhanced schemes$\mathtt {DGraph\_RW}$and$\mathtt {DGraph\_Role}$further incorporate lightweight operation-based and (hierarchical) role-based access control, respectively, while avoiding encrypted index expansion and minimizing the impact on search efficiency. Both theoretical comparison and experiment results demonstrate their usability and scalability. Notably, for attribute-grained update,DGraphis$2.5\times $faster than ODXT (by Patranabis and Mukhopadhyay), and for node-grained deletion, with each node associated with 12 attributes,DGraphis$30\times $faster than ODXT.
Jiabei Wang, Dandan Xu, Yongbin Zhou
IEEE Internet Things J.3
2024 Rabbit: Secure Encrypted Property Graph Search Scheme Supporting Data and Key Updates
Jiabei Wang, Dandan Xu, Yongbin Zhou
TrustCom3
2024 Racing on the Negative Force: Efficient Vulnerability Root-Cause Analysis through Reinforcement Learning on Counterexamples
Dandan Xu, Di Tang 0001, Yi Chen 0024, XiaoFeng Wang 0001, Kai Chen 0012, Haixu Tang, Longxing Li
USENIX Security Symposium1
2024 AutoPwn: Artifact-Assisted Heap Exploit Generation for CTF PWN Competitions
abstract
Capture-the-flag (CTF) competitions have become highly successful in security education, and heap corruption is considered one of the most difficult and rewarding challenges due to its complexity and real-world impact. However, developing a heap exploit is a challenging task that often requires significant human involvement to manipulate memory layouts and bypass security checks. To facilitate the exploitation of heap corruption, existing solutions develop automated systems that rely on manually crafted patterns to generate exploits. Such manual patterns tend to be specific, which limits their flexibility to cope with the evolving exploit techniques. To address this limitation, we explore the problem of the automatic summarization of exploit patterns. We leverage an observation that public attack artifacts provide key insights into heap exploits. Based upon this observation, we develop AutoPwn, the first artifact-assisted AEG system that automatically summarizes exploit patterns from artifacts of known heap exploits and uses them to guide the exploitation of new programs. Considering the diversity of programs and exploits, we propose to use a novel Exploitation State Machine (ESM), with generic states and transitions to model the exploit patterns, and then efficiently construct it through combining the dynamic monitoring of exploits and the semantic analysis of their text descriptions. We implement a prototype of AutoPwn and evaluate it on 96 testing CTF binaries. The results show that AutoPwn produces 22 successful exploits and 13 partial exploits, preliminarily demonstrating its efficacy.
Dandan Xu, Kai Chen 0012, Miaoqian Lin, Chaoyang Lin, XiaoFeng Wang 0001
IEEE Trans. Inf. Forensics Secur.1
2022 Cop-Flash: Utilizing hybrid storage to construct a large, efficient, and durable computational storage for DNN training
abstract
Traditional computing architectures that separate computing from storage face severe limitations when processing the data that is continuously produced in the cloud and at the edge. Recently, the computational storage device (CSD) is becoming one of the critical cloud infrastructures which can overcome these limitations. Many studies utilize CSD for DNN training to extract useful information and knowledge from the data quickly and efficiently. However, all previous work has used homogeneous storage, which is not fully considered the requirements of DNN training on CSD. Thus, we exploit the leverage of hybrid NAND flash memory to optimize this problem. Nevertheless, typical hybrid storage architectures have limitations when used for DNN training. Moreover, their management strategies can not fully exploit the heterogeneity of hybrid flash memory. To address this issue, we propose a novel SLC-TLC flash memory called Co-Partitioning Flash (Cop-Flash), which utilizes two different hybrid flash memory partitioning methods to divide storage into three different properties of flash memory. Meanwhile, two key technologies are included in Cop-Flash: 1) lifetime-based I/O identifier is proposed to identify data hotness according to data lifetime to maximize the benefits of heterogeneity and minimize the impact of garbage collection. 2) Erase-aware Adaptive Dual-zone Management is proposed to increase bandwidth utilization and guarantee system reliability. We compared Cop-Flash with two related state-of-the-art hybrid storage using hard partitioning and soft partitioning as well as TLC-only flash memory under real DNN training workloads. Experimental results show that Cop-Flash improves the performance by 29.1%, 38.8%, 56.6% and outperforms them by 2.3x, 1.29x, and 8.3x in terms of lifespan.
Chunhua Xiao, Dandan Xu
CLOUD3
2022 SDST-Accelerating GEMM-based Convolution through Smart Data Stream Transformation
abstract
The development of flexible Convolutional Neural Network (CNN) accelerators is critical for large-scale inference and training. Accelerators based on the General Matrix Multiplication (GEMM) kernel have gained popularity due to their ability to accelerate the most prevalent convolutional and fully connected layers in CNNs. However, the convolution inputs must be reshaped and packed into redundant matrices, which is performed by the im2col (image to column) algorithm. As the performance of the GEMM kernel improves, it increases latency and gradually becomes a bottleneck. To address this issue, we propose Smart Data Stream Transformation (SDST), a technique that eliminates explicit data transformation through data stream manipulation. SDST divides the input data into conflict-free streams based on the locality of data redundancy. Additionally, we design the continuity-friendly data layout to unify the transformations across data streams. Our design is evaluated by running the YoloV3-tiny model on an FPGA-based prototype system. Experimental results show that SDST improves the performance of convolutional acceleration by a factor of 1.12 to 5.69 compared to explicit im2col performed on the CPU.
Chunhua Xiao, Dandan Xu, Fangzhu Lin, Kun Ning
CCGRID3
2022 Flexible Gas-Permeable and Resilient Bowtie Antenna for Tensile Strain and Temperature Sensing
abstract
As a wireless basic unit, flexible antennas hold a wide range of applications in wearable electronics, soft robotics, and Internet of Things (IoT). However, most of the current flexible antennas are encapsulated by silicone elastomers with poor gas permeability, which severely hinders the evaporation of skin moisture and sweat. In addition, conventional rigid metals as high-frequency conductors are limited by poor elasticity and susceptibility to oxidation for on-skin application. Here, we developed a highly permeable and stretch-resistant flexible bowtie antenna that can capture changes in tensile strain and temperature. A low-impedance flexible carbon nanotube-silver (CNT-Ag) substrate was fabricated as the conductor of the antenna. By optimizing the multibeam bowed geometry and wrapping it in porous thermoplastic polyurethane (TPU) fibers, the final five-beam antenna was obtained and was able to withstand a relatively large tensile stress of 25.2 MPa, yet achieve a high vapor transmission rate of 48.2 mg cm−2 h−1. The antenna obtained an ideal impedance match at 2.28 GHz with doughnut-like radiation and a high radiation efficiency of over 85%. Furthermore, the antenna was successfully used to capture the strain in the wrist epidermis during bending and to detect thermal changes in the beaker of hot water, respectively. Finally, demonstrations of the antenna, such as permeability, radiation to the human body, and integrality in connection with flexible circuits, were carefully developed to reveal its feasibility in the real world. We expect this work to pave the way for the future establishment of epidermally flexible antennas for soft electronics.
Hongcheng Xu, Weihao Zheng, Yangbo Yuan, Dandan Xu, Yuxin Qin, Ningjuan Zhao, Qikai Duan, Yujian Jin, Yuejiao Wang, Yang Lu 0002, Libo Gao
IEEE Internet Things J.4
2022 PASM: Parallelism Aware Space Management strategy for hybrid SSD towards in-storage DNN training acceleration
Chunhua Xiao, Shi Qiu 0012, Dandan Xu
J. Syst. Archit.3
2021 Bookworm Game: Automatic Discovery of LTE Vulnerabilities Through Documentation Analysis
abstract
In the past decade, the security of cellular networks has been increasingly under scrutiny, leading to the discovery of numerous vulnerabilities that expose the network and its users to a wide range of security risks, from denial of service to information leak. However, most of these findings have been made through ad-hoc manual analysis, which is inadequate for fundamentally enhancing the security assurance of a system as complex as the cellular network. An important observation is that the massive amount of technical documentation of cellular network can provide key insights into the protection it puts in place and help identify potential security flaws. Particularly, we found that such documentation often contains hazard indicators (HIs) – the statement that describes a risky operation (e.g., abort an ongoing procedure) when a certain event happens at a state, which can guide a test on the system to find out whether the operation can indeed be triggered by an unauthorized party to cause harm to the cellular core or legitimate users’ equipment. Based upon this observation, we present in this paper a new framework that makes the first step toward intelligent and systematic security analysis of cellular networks. Our approach, called Atomic, utilizes natural-language processing and machine learning techniques to scan a large amount of LTE documentation for HIs. The HIs discovered are further parsed and analyzed to recover state and event information for generating test cases. These test cases are further utilized to automatically construct tests in an LTE simulation environment, which runs the tests to detect the vulnerabilities in the LTE that allow the risky operations to happen without proper protection. In our research, we implemented Atomic and ran it on the LTE NAS specification, including 549 pages with 13,598 sentences and 283,850 words. In less than 5 hours, our prototype reported 42 vulnerabilities from 192 HIs discovered, including 10 never reported before, under two threat models. All these vulnerabilities have been confirmed through end-to-end attacks, which lead to unauthorized disruption of the LTE service a legitimate user’s equipment receives. We reported our findings to authorized parties and received their confirmation that these vulnerabilities indeed exist in major commercial carriers and $2,000 USD reward from Google.
Yi Chen 0024, Yepeng Yao, XiaoFeng Wang 0001, Dandan Xu, Chang Yue, Xiaozhong Liu 0001, Kai Chen 0012, Haixu Tang, Baoxu Liu
SP4
2019 Demystifying Hidden Privacy Settings in Mobile Apps
abstract
Mobile apps include privacy settings that allow their users to configure how their data should be shared. These settings, however, are often hard to locate and hard to understand by the users, even in popular apps, such as Facebook. More seriously, they are often set to share user data by default, exposing her privacy without proper consent. In this paper, we report the first systematic study on the problem, which is made possible through an in-depth analysis of user perception of the privacy settings. More specifically, we first conduct two user studies (involving nearly one thousand users) to understand privacy settings from the user's perspective, and identify these hard-to-find settings. Then we select 14 features that uniquely characterize such hidden privacy settings and utilize a novel technique called semantics- based UI tracing to extract them from a given app. On top of these features, a classifier is trained to automatically discover the hidden privacy settings, which together with other innovations, has been implemented into a tool called Hound. Over our labeled data set, the tool achieves an accuracy of 93.54%. Further running it on 100,000 latest apps from both Google Play and third-party markets, we find that over a third (36.29%) of the privacy settings identified from these apps are “hidden”. Looking into these settings, we observe that they become hard to discover and hard to understand primarily due to the problematic categorization on the apps' user interfaces and/or confusing descriptions. Further importantly, though more privacy options have been offered to the user over time, also discovered is the persistence of their usability issue, which becomes even more serious, e.g., originally easy-to-find settings now harder to locate. And among all such hidden privacy settings, 82.16% are set to leak user privacy by default. We provide suggestions for improving the usability of these privacy settings at the end of our study.
Yi Chen 0024, Mingming Zha 0001, Nan Zhang 0018, Dandan Xu, Xuan Feng 0005, Kan Yuan, Fnu Suya, Yuan Tian 0001, Kai Chen 0012, XiaoFeng Wang 0001
IEEE Symposium on Security and Privacy4
2018 SpamTracer: Manual Fake Review Detection for O2O Commercial Platforms by Using Geolocation Features
Ruoyu Deng, Na Ruan, Ruidong Jin, Weijia Jia 0001, Chunhua Su, Dandan Xu
Inscrypt7
2013 Person Re-identification by Multi-resolution Saliency-Weighted Color Histograms and Local Structural Sparse Coding
abstract
Person re-identification plays an important role in computer vision, aiming to identify the same person viewed by disjoint cameras at different time instants and locations. In this paper we present a novel appearance-based method by multi-resolution saliency-weighted color histograms and local structural sparse coding for re-identification work. The former descriptor captures global chromatic content while the latter exploits both partial and spatial information of individuals. Specifically, visual saliency is considered as weighting operators to increase the discriminative power of features. Finally a combinational matching strategy is employed to measure the similarity between individuals. Experimental results over two challenging benchmark datasets (VIPeR, ETHZ) demonstrate that our method obtains competitive performance.
Dandan Xu, Huicheng Zheng
ICIG1