EDBT 2026 Demo / reviewers in the wild / expert
Ming Li 0049
dblp:l/MingLi-49
· DBLP profile ↗
25ranked-venue papers
4as first author
24since 2021 · last 2026
0000-0002-0874-5010ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 1 first-author · 12 since 2021Computer networks · 4 · 2 first-author · 4 since 2021Systems, architecture and hardware · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Byzantine-Robust Asynchronous Federated Learning via Feature FingerprintingabstractAsynchronous federated learning (AFL) accelerates collaborative training across heterogeneous devices compared to synchronous federated learning, but increases vulnerability to Byzantine attacks due to its asynchronous aggregation. Existing defenses rely on parametric similarity between models and temporal consistency of updates, which are compromised by data and device heterogeneity, leading to ineffective robustness. To address this limitation, we propose Belisa, a Byzantine-robust AFL framework that enhances fidelity, robustness, and efficiency under heterogeneous scenarios. Belisa introduces novel discrepancies between feature representations of local models to distinguish malicious models from benign ones. By leveraging a reference model trained on publicly available data, Belisa quantifies these discrepancies, referred to as feature fingerprints, and filters out malicious models through clustering. Extensive experiments on six datasets from three types of tasks under five advanced Byzantine attacks demonstrate Belisa’s superiority. Notably, Belisa consistently outperforms existing approaches across both attack and non-attack settings. Under attack scenarios, it lowers the average test error rate to 0.42× that of baseline methods. Furthermore, Belisa accelerates the aggregation process by an average of 12.3× compared to other methods. To the best of our knowledge, Belisa is the first Byzantine-robust AFL framework, which provides a broadly applicable countermeasure in heterogeneous scenarios which are more prevalent in real-world settings. Meng Shen 0001, Bohan Peng, Yi Zhao 0011, Ming Li 0049, Qi Li 0002, Liehuang Zhu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | IvyAPC: Auditable Generalized Payment Channels
Ming Li 0049, Jian Weng 0001, Yingjiu Li, Jia-Si Weng 0001, Junzuo Lai, Robert H. Deng |
FC | 1 |
| 2025 | Inter-view contrastive learning and miRNA fusion for lncRNA-protein interaction prediction in heterogeneous graphsabstractPredicting long non-coding RNA (lncRNA)-protein interactions is essential for understanding biological processes and discovering new therapeutic targets. In this study, we propose a novel model based on inter-view contrastive learning and miRNA fusion for lncRNA-protein interaction (LPI) prediction, called ICMF-LPI, which utilizes a heterogeneous information network to enhance LPI prediction. The model integrates miRNA as a mediator, constructing an lncRNA-miRNA-protein network, and employs metapath to extract diverse relationships from heterogeneous graphs. By fusing miRNA-related information and leveraging contrastive learning across inter-views, ICMF-LPI effectively captures potential interactions. Experimental results, including five-fold cross-validation, demonstrate the model's superior performance compared to several state-of-the-art methods, with significant improvements in the area under the receiver operating characteristic curve and the area under the precision-recall curve metrics. Notably, even when direct LPI connections are excluded, ICMF-LPI still achieves competitive predictive accuracy, performing comparably or better than some existing models. This demonstrates that the proposed model is effective in scenarios where direct interaction data are unavailable. This approach offers a promising direction for developing predictive models in bioinformatics, particularly in challenging conditions. Yijun Mao, Jian Weng 0001, Ming Li 0049, Yunyan Xiong, Wanrong Gu, Rongjin Jiang, Rui Pang, Xudong Lin 0001, Deyu Tang |
Briefings Bioinform. | 4 |
| 2025 | A Fault-Tolerant Group Key Management Scheme for Internet of Things Based on Multilayer BlockchainabstractThe importance of group communication in the context of the Internet of Things (IoT) is growing, yet the security and stability of this communication are facing significant challenges. The prevailing distributed group key management (GKM) schemes are ill-suited to resource-constrained devices. Furthermore, those that rely on servers are vulnerable to single-point failures and Byzantine risks. The distributed, immutable, and automatic execution of smart contracts on blockchains may offer a potential solution to these problems. This article puts forth a multilayer blockchain-based IoT GKM scheme with Byzantine fault tolerance (BFT). The scheme oversees the management of IoT device subgroups through the deployment of blockchain and smart contracts on edge servers while overseeing the entire device group in a hierarchical structure. A redundant selection mechanism based on hash mapping has been designed to guarantee reliable communication between disparate blockchains and devices. Concurrently, the scheme incorporates a server detection mechanism for Byzantine behavior, thereby ensuring the stability of the blockchain. The results of the experimental analysis demonstrate that the scheme exhibits enhanced security and fault tolerance. Zhiwen Hou, Tingrui Pei, Ming Li 0049, Kaimin Wei, Yingyang Chen, Sixing Cao |
IEEE Internet Things J. | 3 |
| 2025 | Multi-feature fusion network with marginal focal dice loss for multi-label therapeutic peptide predictionabstractAccurately predicting the functions of multi-functional therapeutic peptides is crucial for the development of related drugs. However, existing peptide function prediction methods largely rely on either a single type of feature or a single model architecture, limiting prediction accuracy and applicability. Additionally, training better-performing models on datasets with class imbalance issues remains a significant challenge. In this study, we propose the multi-functional therapeutic peptide of multi-feature fusion prediction (MFTP_MFFP) model, a novel method for predicting the functionality of multi-functional therapeutic peptides. This approach uses various encoding techniques to process peptide sequence data, generating multiple features that help the model learn hidden information within the sequences. To maximize the effectiveness of these features, we propose a gated feature fusion module that efficiently integrates them. The module assigns learnable gating weights to each feature, optimizing integration and enhancing fusion efficiency. The fused features are then passed into a neural network model for feature extraction. Additionally, we propose a marginal focal dice loss function (MFDL) to address the class imbalance and improve the model's prediction performance. Experimental results show that the MFTP_MFFP model outperforms existing models in all evaluation metrics, demonstrating its robustness and effectiveness in multi-functional therapeutic peptide prediction tasks. Yijun Mao, Yurong Weng, Jian Weng 0001, Ming Li 0049, Wanrong Gu, Rui Pang, Xudong Lin 0001, Yunyan Xiong, Deyu Tang |
PLoS Comput. Biol. | 4 |
| 2025 | AuditPCH: Auditable Payment Channel Hub With Privacy ProtectionabstractAnonymous Payment Channel Hub (PCH), one of the most promising layer-two solutions, settles the scalability issue in blockchain while guaranteeing the unlinkability of transacting parties. However, such developments bring conflicting requirements, i.e., hiding the sender-to-receiver relationships from any third party but opening the relationship to the auditor. Existing works do not support these requirements simultaneously since off-chain transactions are not recorded in the blockchain. Further, the privacy protection strategies hinder auditors from capturing the payment relationships. Thus, it is still a challenge to audit the finance activities of PCH transacting parties. This paper proposes a novel anonymous PCH solution called AuditPCH to achieve privacy and auditability. Concretely, we design a Linkable Randomizable Puzzle scheme for constructing conditional transactions, allowing a sender to pay for a receiver via the hub. As such, AuditPCH, with the new LRP scheme, ensures that 1) payment relationships can be protected from the hub and 2) an auditor with necessary trapdoors can associate the sender and receiver of a payment. We prove the security of AuditPCH under the Global Universal Composability framework. The extensive experimental evaluations on AuditPCH are established to demonstrate its functionality and flexibility. Jian Weng 0001, Junzuo Lai, Yingjiu Li, Jiahe Wu, Ming Li 0049, Jianfei Sun, Pengfei Wu 0003, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | IvyCross: A Privacy-Preserving and Concurrency Control Framework for Blockchain InteroperabilityabstractInteroperability is a fundamental challenge for longenvisioned blockchain applications. A mainstream approach is using Trusted Execution Environment (TEE) to support interoperable off-chain execution. However, this incurs multiple TEE configured with non-trivial storage capabilities running on fragile concurrent processing environments, rendering current strategies based on TEE far from being practical. This paper aims to fill this gap and design a practical interoperability mechanism with simplified TEE as the underlying architecture. Specifically, we present IvyCross, a TEE-based framework that achieves lowcost, privacy-preserving, and race-free blockchain interoperability. IvyCross allows running arbitrary smart contracts across heterogeneous blockchains atop two distributed TEE-powered hosts. We design an incentive scheme based on smart contracts to stimulate the honest behavior of two hosts, bypassing the requirement of the number of TEE and large memory need. We examine the conditions to guarantee the uniqueness of Nash Equilibrium via Game Theory. Furthermore, an extended optimistic concurrency control protocol is designed to ensure the correctness of concurrent contracts execution. We formally prove the security of IvyCross in the Universal Composability (UC) framework and implement a prototype atop Bitcoin, Ethereum, and FISCO BOCS. Extensive experimental results on end-to-end performance and concurrency control demonstrate the efficiency and practicality of IvyCross. Ming Li 0049, Jian Weng 0001, Jia-Si Weng 0001, Yi Li 0008, Yongdong Wu, Dingcheng Li, Guowen Xu, Robert H. Deng |
IEEE Trans. Mob. Comput. | 1 |
| 2025 | A Statistical Physics Perspective: Understanding the Causality Behind Convolutional Neural Network Adversarial VulnerabilityabstractThe adversarial vulnerability of convolutional neural networks (CNNs) refers to the performance degradation of CNNs under adversarial attacks, leading to incorrect decisions. However, the causes of adversarial vulnerability in CNNs remain unknown. To address this issue, we propose a unique cross-scale analytical approach from a statistical physics perspective. It reveals that the huge amount of nonlinear effects inherent in CNNs is the fundamental cause for the formation and evolution of system vulnerability. Vulnerability is spontaneously formed on the macroscopic level after the symmetry of the system is broken through the nonlinear interaction between microscopic state order parameters. We develop a cascade failure algorithm, visualizing how micro perturbations on neurons' activation can cascade and influence macro decision paths. Our empirical results demonstrate the interplay between microlevel activation maps and macrolevel decision-making and provide a statistical physics perspective to understand the causality behind CNN vulnerability. Our work will help subsequent research to improve the adversarial robustness of CNNs. Ke Wang 0068, Mingjia Zhu, Zicong Chen, Jian Weng 0001, Ming Li 0049, Siu-Ming Yiu, Weiping Ding 0001, Tianlong Gu |
IEEE Trans. Neural Networks Learn. Syst. | 5 |
| 2024 | SecFloatPlus: More Accurate Floating-Point Meets Secure Two-Party Computation
Jian Weng 0001, Jia-Si Weng 0001, Min-Rong Chen, Ming Li 0049 |
ProvSec (1) | 5 |
| 2024 | Time-based attribute-based proxy re-encryption with decryption key update
Feixiang Zhao, Jian Weng 0001, Wenli Xie, Lin Hou 0002, Ming Li 0049 |
Des. Codes Cryptogr. | 5 |
| 2024 | PACDAM: Privacy-Preserving and Adaptive Cross-Chain Digital Asset MarketplaceabstractAs the deployment of blockchains expands across various industries, the demand for exchanging digital assets among blockchain users has risen. Most of existing solutions either solely support asset exchanges among users on the same blockchain, or have limitations by only enabling cross-chain asset exchanges among a few specific blockchains or requiring an intermediary to involve in the cross-chain transaction. To address this problem, in this paper, we propose the concept of cross-chain digital asset marketplace which enables users across different blockchains to exchange their assets securely and efficiently. We then propose a privacy-preserving and adaptive cross-chain digital asset marketplace scheme, denoted as PACDAM. It adaptively matches purchasers’ requests and ensures atomic and privacy-preserving cross-chain transactions. Built on adaptor signatures and randomizable time-lock puzzles, the cross-chain transaction procedure only relies on the underlying blockchain for signature verification, making PACDAM compatible with various blockchains. Furthermore, this protocol eliminates the necessity for third-party involvement (e.g., brokers) in cross-chain transactions, leading to a substantial enhancement in system efficiency and scalability. We also give a comprehensive security analysis of PACDAM, demonstrating its robustness against common attacks and preserving the privacy of transaction participants. Finally, we conduct a series of experiments, and the results validate the effectiveness of our proposed scheme. Jia-Nan Liu, Anjia Yang, Jian Weng 0001, Min-Rong Chen, Zilin Liu, Ming Li 0049 |
IEEE Internet Things J. | 7 |
| 2024 | HRA-secure attribute-based threshold proxy re-encryption from lattices
Feixiang Zhao, Jian Weng 0001, Wenli Xie, Ming Li 0049, Jia-Si Weng 0001 |
Inf. Sci. | 4 |
| 2024 | Privacy-Preserving and Byzantine-Robust Federated LearningabstractFederated learning (FL) trains a model over multiple datasets by collecting the local models rather than raw data, which can help facilitate distributed data analysis in many real-world applications. Since the model parameters can leak information about the training datasets, it is necessary to preserve the privacy of the FL participants’ local models. Furthermore, FL is vulnerable to poisoning attacks which can significantly decrease the model utility. To settle the above issues, we propose a privacy-preserving and Byzantine-robust FL scheme$\Pi _{\text{P2Brofl}}$that maintains robustness in the presence of poisoning attacks and preserves the privacy of local models simultaneously. Specifically,$\Pi _{\text{P2Brofl}}$leverages three-party computation (3 PC) to securely achieve a Byzantine-robust aggregation method. To improve the efficiency of privacy-preserving local model selection and aggregation, we propose a maliciously secure top-$k$protocol$\Pi _{\text{top}-k}$that has low communication overhead. Moreover, we present an efficient maliciously secure shuffling protocol$\Pi _{\text{shuffle}}$since secure shuffling is necessary for our secure top-$k$protocol. The security proof of the scheme is given and experiments on real-world datasets are conducted in this paper. When the proportion of Byzantine participants is 50%, the error rate of the model only increases by 1.05% while it increases by 23.78% without using our protection. Caiqin Dong, Jian Weng 0001, Ming Li 0049, Jia-Nan Liu, Zhiquan Liu 0001, Yudan Cheng, Shui Yu 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | IvyRedaction: Enabling Atomic, Consistent and Accountable Cross-Chain RewritingabstractBlockchain rewriting has become widely explored for addressing data deletion requirements, such as error data deletion, space-saving, and compliance with the “right-to-be-forgotten” rule. However, existing approaches are inadequate for handling cross-chain redaction issues, issues, in facing with the increasing need for inter-chain communication. In particular, transaction rewriting on a blockchain might have relevant effects on the states of other blockchains. The cross-chain interoperability results in inter-chain transactions with more complex dependency relations. The issues pose new challenges to achieve rewriting consistency, for example, ensuring the rewriting of related transactions when a transaction is being modified, and achieve atomic rewriting, whereby two cross-chain transactions must either all, or neither, be processed. This paper introduces a cross-chain solution IvyRedaction, with an emphasis on customizing a decentralized intermediary for generating and maintaining global cross-chain redaction states and transaction dependencies. The paper proposes a novel cross-chain state mapping method with rollback rules, as well as customized block structures and verification algorithms, to address the aforementioned issues. Proof-of-concept experiments are conducted to demonstrate the feasibility of the proposed framework. Shun Hu, Ming Li 0049, Jia-Si Weng 0001, Jia-Nan Liu, Jian Weng 0001, Zhi Li 0045 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | MTDCAP: Moving Target Defense-Based CAN Authentication ProtocolabstractThe convenience behind modern intelligent vehicles is simply that a group of intelligent electronic control units (ECUs) connected to controller area network (CAN) work in concert. However, quite a lot of studies have shown their security concerns about CAN. In this era of rampant cyberattacks, due to the broadcast mechanism of CAN and the lack of necessary security mechanisms such as encryption and authentication, ECUs are easily disturbed by various cyberattacks, thus leading to vehicle failures. To solve this problem, we propose a novel security authentication protocol based on the core concept of moving target defense, namely MTDCAP, which utilizes MaskedID and hash chains to maintain anonymity externally and ensure the authentication of the sender internally. Unlike general hash chain-based authentication, our protocol creatively incorporates a self-renewal mechanism into the hash chain, which effectively reduces the time overhead and security risk of negotiating the update of the hash chain between both communicating parties. In addition, AES serves to encrypt CAN message payload so as to prevent adversaries from eavesdropping. The theoretical analysis for the security against four kinds of attacks (i.e., eavesdropping, impersonation, replay, and bus-off attacks) in MTDCAP is detailed. Afterwards, a series of protocol evaluations are conducted on two kinds of typical hardware platforms, including T-Box from real vehicle supported by XPeng, and the results reveal that the proposed protocol significantly outperforms the existing protocols in the robustness, bus load, and time overhead. In particular, the authentication overhead on T-Box is only 0.18 ms for MTDCAP. Huibiao Su, Jian Weng 0001, Zhiquan Liu 0001, Ming Li 0049, Yi Liu 0053, Yucheng Zhong, Wenzhen Sun |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2023 | PRI: PCH-based privacy-preserving with reusability and interoperability for enhancing blockchain scalability
Jian Weng 0001, Wei Wu 0001, Ming Li 0049, Yingjiu Li, Haoxin Tu, Yongdong Wu, Robert H. Deng |
J. Parallel Distributed Comput. | 4 |
| 2023 | A robust document image watermarking scheme using deep neural network
Sulong Ge, Zhihua Xia, Jianwei Fei, Jian Weng 0001, Ming Li 0049 |
Multim. Tools Appl. | 6 |
| 2023 | pvCNN: Privacy-Preserving and Verifiable Convolutional Neural Network TestingabstractWe propose a new approach for privacy-preserving and verifiable convolutional neural network (CNN) testing in a distrustful multi-stakeholder environment. The approach is aimed to enable that a CNN modeldeveloperconvinces auserof the truthful CNN performance over non-public data frommultiple testers, while respecting model and data privacy. To balance the security and efficiency issues, we appropriately integrate three tools with the CNN testing, including collaborative inference, homomorphic encryption (HE) and zero-knowledge succinct non-interactive argument of knowledge (zk-SNARK). We start with strategically partitioning a CNN model into a private part kept locally by the model developer, and a public part outsourced to an outside server. Then, the private part runs over the HE-protected test data sent by a tester, and transmits its outputs to the public part for accomplishing subsequent computations of the CNN testing. Second, the correctness of the above CNN testing is enforced by generating zk-SNARK based proofs, with an emphasis on optimizing proving overhead for two-dimensional (2-D) convolution operations, since the operations dominate the performance bottleneck during generating proofs. We specifically present a new quadratic matrix program (QMP)-based arithmetic circuit witha single multiplication gatefor expressing 2-D convolution operations between multiple filters and inputs in a batch manner. Third, we aggregate multiple proofs with respect to a same CNN model but different testers’ test data (i.e., different statements) into one proof, and ensure that the validity of the aggregated proof implies the validity of the original multiple proofs. Lastly, our experimental results demonstrate that our QMP-based zk-SNARK performs nearly 13.9× faster than the existing quadratic arithmetic program (QAP)-based zk-SNARK in proving time, and 17.6× faster in Setup time, for high-dimension matrix multiplication. Besides, the limitation on handling a bounded number of multiplications of QAP-based zk-SNARK is relieved. Jia-Si Weng 0001, Jian Weng 0001, Gui Tang, Anjia Yang, Ming Li 0049, Jia-Nan Liu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2022 | Toward Vehicular Digital Forensics From Decentralized Trust: An Accountable, Privacy-Preserving, and Secure RealizationabstractWith the increasing number of traffic accidents and terrorist attacks by modern vehicles, vehicular digital forensics (VDF) has gained significant attention in identifying evidence from the related digital devices. Ensuring the law enforcement agency to accurately integrate various kinds of data is a crucial point to determine the facts. However, malicious attackers or semi-honest participants may undermine the digital forensic procedures. Enabling accountability and privacy preservation while providing secure data access control in VDF is a nontrivial challenge. To mitigate this issue, in this article, we propose a blockchain-based decentralized solution for VDF named BB-VDF, in which the accountable protocols and privacy-preserving algorithm are constructed. The desirable security properties and fine-grained data access control are achieved based on smart contract and the customized cryptographic construction. Specifically, we design a distributed key-policy attribute-based encryption scheme with partially hidden access structures, named DKP-ABE-H, to realize the secure fine-grained forensics data access control. Further, a novel smart contract is designed to model the forensics procedures as a finite state machine, which guarantees accountability that each participant performs auditable cooperation under tamper resistant and traceable transactions. Systematic security analysis and extensive experimental results show the feasibility and practicability of our proposed BB-VDF scheme. Ming Li 0049, Jian Weng 0001, Jia-Nan Liu, Xiaodong Lin 0001, Charlie Obimbo |
IEEE Internet Things J. | 1 |
| 2022 | ZeroCross: A sidechain-based privacy-preserving Cross-chain solution for Monero
Jian Weng 0001, Ming Li 0049, Wei Wu 0001, Jia-Si Weng 0001, Jia-Nan Liu, Shun Hu |
J. Parallel Distributed Comput. | 3 |
| 2022 | Enabling Efficient, Secure and Privacy-Preserving Mobile Cloud StorageabstractMobile cloud storage (MCS) provides clients with convenient cloud storage service. In this article, we propose an efficient, secure and privacy-preserving mobile cloud storage scheme, which protects the data confidentiality and privacy simultaneously, especially the access pattern. Specifically, we propose an oblivious selection and update (OSU) protocol as the underlying primitive of the proposed mobile cloud storage scheme. OSU is based on onion additively homomorphic encryption with constant encryption layers and enables the client to obliviously retrieve an encrypted data item from the cloud and update it with a fresh value by generating a small encrypted vector, which significantly reduces the client’s computation as well as the communication overheads. Compared with previous works, our presented work has valuable properties, such as fine-grained data structure (small item size), lightweight client-side computation (a few of additively homomorphic operations) and constant communication overhead, which make it more suitable for MCS scenario. Moreover, by employing the “verification chunks” method, our scheme can be verifiable to resist malicious cloud. The comparison and evaluation indicate that our scheme is more efficient than existing oblivious storage solutions with the aspects of client and cloud workloads, respectively. Jia-Nan Liu, Xizhao Luo, Jian Weng 0001, Anjia Yang, Xu An Wang 0014, Ming Li 0049, Xiaodong Lin 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2022 | Peripheral-Free Device Pairing by Randomly Switching PowerabstractWith the growing popularity of the Internet-of-Things (IoT), a massive amount of purpose-specific, heterogeneous, inexpensive devices have been deployed. To allow these devices to perform their duties and collaborate efficiently, designing a secure and dependable communication channel is necessary. Pairing, as the fundamental procedure for establishing a trustworthy communication channel, has received extensive attention from security researchers. Previous secure pairing protocols depend on auxiliary peripherals (e.g., displays, speakers) to share the secret message, while for those products featuring with low-price, manufacturers would probably adopt insecure pairing methods to reduce the cost, so the devices may be subject to various attacks. To mitigate such a situation, we design a peripheral-free secure pairing protocol, termed SwitchPairing. Our protocol only requires users to connect the pre-pairing devices to the same power source, then randomly presses and releases the switch to generate a shared secret. It does not require additional peripherals and can defense eavesdropping and replay attacks innately. We implement a prototype via two CC2640R2F development boards and invite volunteers to participate in the experiments about bench-marking security and usability. The result of our experiments show that our protocol can fulfill the security and efficient requirement of various IoT applications. Zhijian Shao, Jian Weng 0001, Yue Zhang 0025, Yongdong Wu, Ming Li 0049, Jia-Si Weng 0001, Weiqi Luo 0002, Shui Yu 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | Looking Back! Using Early Versions of Android Apps as Attack VectorsabstractAndroid platform is gaining explosive popularity. This leads developers to invest resources to maintain the upward trajectory of the demand. Unfortunately, as the profit potential grows higher, the chances of these Apps getting attacked also get higher. Therefore, developers improved the security of their Apps, which limits attackers ability to compromise upgraded versions of the Apps. However, developers cannot enhance the security of earlier versions that have been released on the Play Store. The earlier versions of the App can be subject to reverse engineering and other attacks. In this paper, we find that attackers can use these earlier versions as attack vectors, which threatens well protected upgraded versions. We show how to attack the upgraded versions of some popular Apps, including Facebook, Sina Weibo and Qihoo360-Cloud-Driven by analyzing the vulnerabilities existing in their earlier versions. We design and implement a tool named DroidSkynet to analyze and find out vulnerable apps from the Play Store. Among 1,500 mainstream Apps collected from the real world, our DroidSkynet indicates the success rate of attacking an App using an earlier version is 34 percent. We also explore possible mitigation solutions to achieve a balance between utility and security of the App update process. Yue Zhang 0025, Jian Weng 0001, Jia-Si Weng 0001, Lin Hou 0002, Anjia Yang, Ming Li 0049, Yang Xiang 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2021 | DeepChain: Auditable and Privacy-Preserving Deep Learning with Blockchain-Based IncentiveabstractDeep learning can achieve higher accuracy than traditional machine learning algorithms in a variety of machine learning tasks. Recently, privacy-preserving deep learning has drawn tremendous attention from information security community, in which neither training data nor the training model is expected to be exposed. Federated learning is a popular learning mechanism, where multiple parties upload local gradients to a server and the server updates model parameters with the collected gradients. However, there are many security problems neglected in federated learning, for example, the participants may behave incorrectly in gradient collecting or parameter updating, and the server may be malicious as well. In this article, we present a distributed, secure, and fair deep learning framework named DeepChain to solve these problems. DeepChain provides a value-driven incentive mechanism based on Blockchain to force the participants to behave correctly. Meanwhile, DeepChain guarantees data privacy for each participant and provides auditability for the whole training process. We implement a prototype of DeepChain and conduct experiments on a real dataset for different settings, and the results show that our DeepChain is promising. Jia-Si Weng 0001, Jian Weng 0001, Jilian Zhang, Ming Li 0049, Yue Zhang 0025, Weiqi Luo 0002 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2019 | CrowdBC: A Blockchain-Based Decentralized Framework for CrowdsourcingabstractCrowdsourcing systems which utilize the human intelligence to solve complex tasks have gained considerable interest and adoption in recent years. However, the majority of existing crowdsourcing systems rely on central servers, which are subject to the weaknesses of traditional trust-based model, such as single point of failure. They are also vulnerable to distributed denial of service (DDoS) and Sybil attacks due to malicious users involvement. In addition, high service fees from the crowdsourcing platform may hinder the development of crowdsourcing. How to address these potential issues has both research and substantial value. In this paper, we conceptualize a blockchain-based decentralized framework for crowdsourcing named CrowdBC, in which a requester's task can be solved by a crowd of workers without relying on any third trusted institution, users' privacy can be guaranteed and only low transaction fees are required. In particular, we introduce the architecture of our proposed framework, based on which we give a concrete scheme. We further implement a software prototype on Ethereum public test network with real-world dataset. Experiment results show the feasibility, usability, and scalability of our proposed crowdsourcing system. Ming Li 0049, Jian Weng 0001, Anjia Yang, Wei Lu 0001, Yue Zhang 0025, Lin Hou 0002, Jia-Nan Liu, Yang Xiang 0001, Robert H. Deng |
IEEE Trans. Parallel Distributed Syst. | 1 |