EDBT 2026 Demo / reviewers in the wild / expert
Ming Li 0003
dblp:l/MingLi3 · also Ming (Fred) Li, Ming F. Li 0003
· DBLP profile ↗
117ranked-venue papers
11as first author
31since 2021 · last 2026
0000-0002-4073-0273ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 49 · 7 first-author · 9 since 2021Security and privacy · 47 · 1 first-author · 16 since 2021Systems, architecture and hardware · 10 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 4 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 since 2021Databases, data management, data science and information retrieval · 3 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CP-FREEZER: Latency Attacks Against Vehicular Cooperative PerceptionabstractCooperative perception (CP) enhances situational awareness of connected and autonomous vehicles by exchanging and combining messages from multiple agents. While prior work has explored adversarial integrity attacks that degrade detection accuracy, little is known about CP's robustness against attacks on timeliness (or availability), a safety-critical requirement for autonomous driving. In this paper, we present CP-FREEZER, the first latency attack that maximizes the computation delay of CP algorithms by injecting adversarial perturbation via V2V messages. Our attack resolves several unique challenges, including the non-differentiability of point cloud preprocessing, asynchronous knowledge of the victim’s input due to transmission delays, and uses a novel loss function that effectively maximizes the execution time of the CP pipeline. Extensive experiments show that CP-FREEZER increases end-to-end CP latency by over 90×, pushing per-frame processing time beyond 3 seconds with a 100% success rate on our real-world vehicle testbed. Our findings reveal a critical threat to the availability of CP systems, highlighting the urgent need for robust defenses. Chenyi Wang 0005, Ruoyu Song 0001, Raymond Muller, Jean-Philippe Monteuuis, Z. Berkay Celik, Jonathan Petit, Ryan M. Gerdes, Ming Li 0003 |
AAAI | 8 |
| 2026 | Physics-Informed Parametric Bandits for Beam Alignment in mmWave CommunicationsabstractIn millimeter wave (mmWave) communications, beam alignment and tracking are crucial to combat the significant path loss. As scanning the entire directional space is inefficient, designing an efficient and robust method to identify the optimal beam directions is essential. Since traditional bandit algorithms require a long time horizon to converge under large beam spaces, many existing works propose efficient bandit algorithms for beam alignment by relying on unimodality or multimodality assumptions on the reward function's structure. However, such assumptions often do not hold (or cannot be strictly satisfied) in practice, which causes such algorithms to converge to choosing suboptimal beams. In this work, we propose two physics-informed bandit algorithms \textit{pretc} and \textit{prgreedy} that exploit the sparse multipath property of mmWave channels - a generic but realistic assumption - which is connected to the Phase Retrieval Bandit problem. Our algorithms treat the parameters of each path as black boxes and maintain optimal estimates of them based on sampled historical rewards. \textit{pretc} starts with a random exploration phase and then commits to the optimal beam under the estimated reward function. \textit{prgreedy} performs such estimation in an online manner and chooses the best beam under current estimates. Our algorithms can also be easily adapted to beam tracking in the mobile setting. Through experiments using both the synthetic DeepMIMO dataset and the real-world DeepSense6G dataset, we demonstrate that both algorithms outperform existing approaches in a wide range of scenarios across diverse channel environments, showing their generalizability and robustness. Thang Duong, Ming Li 0003, Chicheng Zhang |
WiOpt | 3 |
| 2026 | Correction to "Local Information Privacy and its Applications to Data Aggregation"abstractIn our previous works [1, 2, 3], we defined$(\epsilon ,\delta )$-Local Information Privacy (LIP) as a context-aware privacy notion and presented the corresponding privacy-preserving mechanism. Then we claim that the mechanism satisfies$(\epsilon ,0)$-LIP for any$\epsilon \gt 0$for arbitrary$P_{X}$. However, this claim is not completely correct. In this document, we provide a correction to the valid range of privacy parameters of our previously proposed LIP mechanism. Further, we propose efficient algorithms to expand the range of valid privacy parameters. Finally, we discuss the impact on our experimental results, the rationale of the proposed correction and corrected results. Proofs of the main results in this paper are provided in our full version [6]. Bo Jiang 0015, Ming Li 0003, Ravi Tandon |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Investigating Physical Latency Attacks Against Camera-Based PerceptionabstractCamera-based perception is a central component to the visual perception of autonomous systems. Recent works have investigated latency attacks against perception pipelines, which can lead to a Denial-of-Service against the autonomous system. Unfortunately, these attacks lack real-world applicability, either relying on digital perturbations or requiring large, unscalable, and highly visible patches that cover up the victim's view. In this paper, we propose Detstorm, a novel physically realizable latency attack against camera-based perception. Detstorm uses projector perturbations to cause delays in perception by creating a large number of adversarial objects. These objects are optimized on four objectives to evade filtering by multiple Non-Maximum Suppression (NMS) approaches. To maximize the number of created objects in a dynamic physical environment, Detstorm takes a unique greedy approach, segmenting the environment into “zones” containing distinct object classes and maximizing the number of created objects per zone. Detstorm adapts to changes in the environment in real time, recombining perturbation patterns via our zone stitching process into a contiguous, physically projectable image. Evaluations in both simulated and real-world experiments show that Detstorm causes a 506% increase in detected objects on average, delaying perception results by up to 8.1 seconds, and capable of causing physical consequences on real-world autonomous driving systems. Raymond Muller, Ruoyu Song 0001, Chenyi Wang 0005, Yuxia Zhan, Jean-Philippe Monteuuis, Yanmao Man, Ming Li 0003, Ryan M. Gerdes, Jonathan Petit, Z. Berkay Celik |
SP | 7 |
| 2025 | DP-BREM: Differentially-Private and Byzantine-Robust Federated Learning with Client Momentum
Xiaolan Gu, Ming Li 0003, Li Xiong 0001 |
USENIX Security Symposium | 2 |
| 2025 | From Threat to Trust: Exploiting Attention Mechanisms for Attacks and Defenses in Cooperative Perception
Chenyi Wang 0005, Raymond Muller, Ruoyu Song 0001, Jean-Philippe Monteuuis, Jonathan Petit, Yanmao Man, Ryan M. Gerdes, Z. Berkay Celik, Ming Li 0003 |
USENIX Security Symposium | 9 |
| 2025 | Harvesting Physical-Layer Randomness in Millimeter Wave BandsabstractThe unpredictability of the wireless channel has been used as a natural source of randomness to build physical-layer security primitives for shared key generation, authentication, access control, proximity verification, and other security properties. Compared to pseudo-random generators, it has the potential to achieve information-theoretic security. In sub-6 GHz frequencies, the randomness is harvested from the small-scale fading effects of RF signal propagation in rich scattering environments. However, the RF propagation characteristics follow sparse models with clustered paths when devices operate in millimeter-wave (mmWave) bands (5G and Next-Generation networks, Wi-Fi in 60GHz). Millimeter-wave transmissions are typically directional to increase the gain and combat high signal attenuation, leading to stable and more predictable channels. In this paper, we first demonstrate that state-of-the-art methods relying on channel state information or received signal strength measurements fail to produce high randomness. Accounting for the unique features of mmWave propagation, we propose a novel randomness extraction mechanism that exploits the random timing of channel blockage to harvest random bits. Compared with the prior art in CSI-based and context-based randomness extraction, our protocol remains secure againstpassive and active Man-in-the-Middle adversaries co-located with the legitimate devices. We demonstrate the security properties of our method in a 28 GHz mmWave testbed in an indoor setting. Ziqi Xu 0006, Jingcheng Li, Yanjun Pan 0001, Ming Li 0003, Loukas Lazos |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | Physical ID-Transfer Attacks against Multi-Object Tracking via Adversarial TrajectoryabstractMulti-Object Tracking (MOT) is a critical task in computer vision, with applications ranging from surveillance systems to autonomous driving. However, threats to MOT algorithms have yet been widely studied. In particular, incorrect association between the tracked objects and their assigned IDs can lead to severe consequences, such as wrong trajectory predictions. Previous attacks against MOT either focused on hijacking the trackers of individual objects, or manipulating the tracker IDs in MOT by attacking the integrated object detection (OD) module in the digital domain, which are model-specific, non-robust, and only able to affect specific samples in offline datasets. In this paper, we present AdvTraj, the first online and physical ID-manipulation attack against tracking-by-detection MOT, in which an attacker uses adversarial trajectories to transfer its ID to a targeted object to confuse the tracking system, without attacking OD. Our simulation results in CARLA show that AdvTraj can fool ID assignments with 100% success rate in various scenarios for white-box attacks against SORT, which also have high attack transferability (up to 93% attack success rate) against state-of-the-art (SOTA) MOT algorithms due to their common design principles. We characterize the patterns of trajectories generated by AdvTraj and propose two universal adversarial maneuvers that can be performed by a human walker/driver in daily scenarios. Our work reveals under-explored weaknesses in the object association phase of SOTA MOT systems, and provides insights into enhancing the robustness of such systems. Chenyi Wang 0005, Yanmao Man, Raymond Muller, Ming Li 0003, Z. Berkay Celik, Ryan M. Gerdes, Jonathan Petit |
ACSAC | 4 |
| 2024 | VOGUES: Validation of Object Guise using Estimated Components
Raymond Muller, Yanmao Man, Ming Li 0003, Ryan M. Gerdes, Jonathan Petit, Z. Berkay Celik |
USENIX Security Symposium | 3 |
| 2024 | Remote Perception Attacks against Camera-based Object Recognition Systems and CountermeasuresabstractIn vision-based object recognition systems, imaging sensors perceive the environment and then objects are detected and classified for decision-making purposes, e.g., to maneuver an automated vehicle around an obstacle or to raise alarms for intruders in surveillance settings. In this work we demonstrate how camera-based perception can be unobtrusively manipulated to enable an attacker to create spurious objects or alter an existing object, by remotely projecting adversarial patterns into cameras, exploiting two common effects in optical imaging systems, viz., lens flare/ghost effects and auto-exposure control. To improve the robustness of the attack, we generate optimal patterns by integrating adversarial machine learning techniques with a trained end-to-end channel model. We experimentally demonstrate our attacks using a low-cost projector on three different cameras, and under different environments. Results show that, depending on the attack distance, attack success rates can reach as high as 100%, including under targeted conditions. We develop a countermeasure that reduces the problem of detecting ghost-based attacks into verifying whether there is a ghost overlapping with a detected object. We leverage spatiotemporal consistency to eliminate false positives. Evaluation on experimental data provides a worst-case equal error rate of 5%. Yanmao Man, Ming Li 0003, Ryan M. Gerdes |
ACM Trans. Cyber Phys. Syst. | 2 |
| 2024 | Online Context-Aware Streaming Data Release With Sequence Information PrivacyabstractPublishing streaming data in a privacy-preserving manner has been a key research focus for many years. This issue presents considerable challenges, particularly due to the correlations prevalent within the data stream. Existing approaches either fall short in effectively leveraging these correlations, leading to a suboptimal utility-privacy tradeoff, or they involve complex mechanism designs that increase the computation complexity with respect to the sequence length. In this paper, we introduce Sequence Information Privacy (SIP), a new privacy notion designed to guarantee privacy for an entire data stream, taking into account the intrinsic data correlations. We show that SIP provides a similar level of privacy guarantee compared to local differential privacy (LDP), and it also enjoys a lightweight modular mechanism design. We further study two online data release models (instantaneous or batched) and propose corresponding privacy-preserving data perturbation mechanisms. We provide a numerical evaluation of how correlations influence noise addition in data streams. Lastly, we conduct experiments using real-world data to compare the utility-privacy tradeoff offered by our approaches with those from existing literature. The results reveal that our mechanisms achieve better utility-privacy tradeoff than the state-of-the-art LDP-based mechanisms. Notably, the improvements become more significant for small privacy budgets. Bo Jiang 0015, Ming Li 0003, Ravi Tandon |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | ZITA: Zero-Interaction Two-Factor Authentication Using Contact Traces and In-Band Proximity VerificationabstractTwo-factor authentication (TFA) provides an additional layer of protection to commonly-occurring password breaches. However, existing TFA methods, often involve special hardware interfaces, or require human effort which is prone to errors and acts as an adoption detractor for older adults and novice technology users. To address these limitations, we propose a zero-interaction, two-factor authentication (ZITA) protocol. In ZITA, the first factor is implemented using the conventional username and password methods. The second factor is completed without any human effort provided that the user is not accessing the service from an unregistered public device and a designated secondary device is physically co-present. To automate the second factor, ZITA exploits the long-term contact between the login device and the secondary device such as a smartphone. Moreover, to thwart man-in-the-middle and co-located attacks, ZITA incorporates a proximity verification test that relies on the randomness of ambient RF signals. Compared with other zero-effort TFA protocols, ZITA remains secure against advanced threats and does not require out-of-band sensors such as microphones, speakers, or photoplethysmography (PPG) sensors. Nirnimesh Ghose, Kaustubh Gupta, Loukas Lazos, Ming Li 0003, Ziqi Xu 0006 |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | Exploiting Successive Interference Cancellation for Spectrum Sharing Over Unlicensed BandsabstractHarmonious coexistence among different unlicensed wireless technologies has became increasingly important due to the spectrum shortage problem. As a representative case, we focus on addressing LTE-LAA and WiFi coexistence in unlicensed bands. Traditionally, collision avoidance-based medium access control (MAC) protocols adopted by both LAA and WiFi have led to low channel utilization and fairness. In this paper, we explore physical-layer interference suppression techniques (e.g., successive interference cancellation, SIC) to enhance the spectrum utilization of coexisting LAA and WiFi networks. We propose a SIC-aware MAC protocol that embraces concurrent transmissions and optimizes the channel access strategy at the MAC layer, so as to mitigate the interference (same-technology or cross-technology) due to excess channel contentions. We theoretically analyze the network throughput by extending Bianchi's Markov model, considering the impact of concurrent transmissions and SIC. We also extend the analysis to consider MIMO and MU-MIMO links with SIC. We validate our theoretical analysis and the effectiveness of the proposed MAC protocol via extensive simulations. We also implement a prototype LAA/WiFi SIC receiver on USRP devices to demonstrate the feasibility of cross-technology SIC and the proposed MAC protocol. Zhiwu Guo, Ming Li 0003, Marwan Krunz |
IEEE Trans. Mob. Comput. | 2 |
| 2023 | That Person Moves Like A Car: Misclassification Attack Detection for Autonomous Systems Using Spatiotemporal Consistency
Yanmao Man, Raymond Muller, Ming Li 0003, Z. Berkay Celik, Ryan M. Gerdes |
USENIX Security Symposium | 3 |
| 2023 | Fair Coexistence of Heterogeneous Networks: A Novel Probabilistic Multi-Armed Bandit ApproachabstractThe licensed spectrum of cellular networks has become increasingly crowded, leading to the standardization of LTE licensed assisted access (LTE-LAA) and 5G NR-U for deployment in unlicensed bands such as 5 GHz. To coexist harmoniously with other unlicensed wireless technologies like WiFi, LAA and 5G NR-U enforce listen-before-talk (LBT) protocol. This paper proposes methods to enhance the overall spectrum efficiency and fairness of each coexisting heterogeneous link. To improve the overall spectrum efficiency, we propose enabling concurrent transmissions of multiple links. Motivated by the need for fair coexistence of heterogeneous networks with concurrent transmissions, we formulate a variant of the multi-armed bandit (MAB) problem that finds a probabilistic transmission strategy to maximize the minimum link throughput. We propose the Fair Probabilistic Explore-Then-Commit (FP-ETC) algorithm, which achieves the expected regret of$O\left(T^{\frac{2}{3}}(K \log T)^{\frac{1}{3}}\right)$. We compare FP-ETC with existing MAB algorithms via extensive simulations, and the results show that FP-ETC significantly outperforms the baseline algorithms. Zhiwu Guo, Chicheng Zhang, Ming Li 0003, Marwan Krunz |
WiOpt | 3 |
| 2023 | FastReach: A system for privacy-preserving reachability queries over location data
Hanyu Quan, Boyang Wang 0001, Ming Li 0003, Iraklis Leontiadis |
Comput. Secur. | 3 |
| 2023 | Cross-Modality Continuous User Authentication and Device Pairing With Respiratory PatternsabstractAt-home screening systems for obstructive sleep apnea (OSA) can bring convenience to remote chronic disease management. However, the unsupervised home environment is subject to spoofing and unintentional interference from the household member. To improve robustness, this work presents SIENNA, an insider-resistant breathing-based authentication/pairing protocol. SIENNA leverages the uniqueness of breathing patterns to automatically and continuously authenticate a user and pairs a mobile OSA app and a physiological monitoring radar system (PRMS). SIENNA does not require biometric enrollment and instead transforms the respiratory measurements taken during the users routine physical checkup into breathing biometrics comparable with the PRMS readings. Furthermore, it can operate within a noisy multi-target home environment and is secure against a co-located attacker through the usage of JADE-ICA, fuzzy commitment, and friendly jamming. We fully implemented SIENNA and evaluated its performance with medium-scale trials. Results show that SIENNA can achieve reliable (> 90% success rate) user authentication and secure device pairing in a noisy environment against an attacker with full knowledge of the authorized users breathing biometrics. Shekh M. M. Islam, Yao Zheng 0004, Yanjun Pan 0001, Marionne Millan, Willy Chang, Ming Li 0003, Olga Boric-Lubecke, Victor Lubecke, Wenhai Sun |
IEEE Internet Things J. | 6 |
| 2023 | Answering Count Queries for Genomic Data With Perfect PrivacyabstractIn this paper, we consider the problem of answering count queries for genomic data subject to perfect privacy constraints. Count queries are often used in applications that collect aggregate (population-wide) information from biomedical Databases (DBs) for analysis, such as Genome-wide association studies. Our goal is to design mechanisms for answering count queries of the following form:How many users in the database have a specific set of genotypes at certain locations in their genome?At the same time, we aim to achieve perfect privacy (zero information leakage) of the sensitive genotypes at a pre-specified set of secret locations. The sensitive genotypes could indicate rare diseases and/or other health traits one may want to keep private. We present both local and central count-query mechanisms for the above problem that achieves perfect information-theoretic privacy for sensitive genotypes while minimizing the expected absolute error (or per-user error probability, depending on the setting) of the query answer. We also derived a lower bound of the per-user probability of error for an arbitrary query-answering mechanism that satisfies perfect privacy. We show that our mechanisms achieve error close to the lower bound, and match the lower bound for some special cases. We numerically show that the performance of each mechanism depends on the data prior distribution, the intersection between the queried and sensitive genotypes, and the strength of the correlation in the genomic data sequence. Bo Jiang 0015, Mohamed Seif, Ravi Tandon, Ming Li 0003 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | Misbehavior Detection in Wi-Fi/LTE Coexistence Over Unlicensed BandsabstractWe address the problem of detecting misbehavior in the coexistence etiquette between LTE and Wi-Fi systems operating in the 5GHz U-NII unlicensed bands. We define selfish misbehavior strategies for the LTE that can yield an unfair share of the spectrum resources. Such strategies are based on manipulating the operational parameters of the LTE-LAA standard, namely the backoff mechanism, the traffic class parameters, the clear channel access (CCA) threshold, and others. Prior methods for detecting misbehavior in homogeneous settings are not applicable in a spectrum sharing scenario because the devices of one system cannot decode the transmissions of another. We develop implicit sensing techniques that can accurately estimate the operational parameters of LTE transmissions under various topological scenarios andwithout decoding.These techniques apply correlation-based signal detection to infer the required information. Our techniques are validated through experiments on a USRP testbed. We further apply a statistical inference framework for determining deviations of the LTE behavior from the coexistence etiquette. By characterizing the detection and false alarm probabilities, we show that our framework yields high detection accuracy at a very low false alarm rate. Although our methods focus on detecting misbehavior of the LTE system, they can be generalized to detect Wi-Fi misbehavior and to other coexistence scenarios. Islam Samy, Loukas Lazos, Ming Li 0003, Yong Xiao 0001, Marwan Krunz |
IEEE Trans. Mob. Comput. | 4 |
| 2022 | Physical Hijacking Attacks against Object TrackersabstractModern autonomous systems rely on both object detection and object tracking in their visual perception pipelines. Although many recent works have attacked the object detection component of autonomous vehicles, these attacks do not work on full pipelines that integrate object tracking to enhance the object detector's accuracy. Meanwhile, existing attacks against object tracking either lack real-world applicability or do not work against a powerful class of object trackers, Siamese trackers. In this paper, we present AttrackZone, a new physically-realizable tracker hijacking attack against Siamese trackers that systematically determines valid regions in an environment that can be used for physical perturbations. AttrackZone exploits the heatmap generation process of Siamese Region Proposal Networks in order to take control of an object's bounding box, resulting in physical consequences including vehicle collisions and masked intrusion of pedestrians into unauthorized areas. Evaluations in both the digital and physical domain show that AttrackZone achieves its attack goals 92% of the time, requiring only 0.3-3 seconds on average. Raymond Muller, Yanmao Man, Z. Berkay Celik, Ming Li 0003, Ryan M. Gerdes |
CCS | 4 |
| 2022 | PoF: Proof-of-Following for Vehicle Platoons
Ziqi Xu 0006, Jingcheng Li, Yanjun Pan 0001, Loukas Lazos, Ming Li 0003, Nirnimesh Ghose |
NDSS | 5 |
| 2022 | Hierarchical Unimodal Bandits
Tianchi Zhao 0001, Chicheng Zhang, Ming Li 0003 |
ECML/PKDD (4) | 3 |
| 2022 | Passive Drone Localization Using LTE SignalsabstractDrones raise significant privacy and security threats, by intruding into the airspace of private properties or unauthorized regions. Being able to detect and localize the encroaching drones is essential to build geofencing systems to prevent drone misuse. While most existing approaches focus on detecting and localizing active drones, passive drones that do not emit signals are particularly challenging to localize, without requiring advanced hardware. In this work, we propose a novel, low-cost passive drone localization approach, by leveraging opportunistic environmental RF signals (e.g., LTE or WiFi) that reflect off the target drone, with only a single wireless receiver. We implement a prototype system on a USRP-device based testbed, with standard LTE signals emitted by multiple distributed transmitters, and conduct experiments on top of a campus building to evaluate its performance. We also perform a drone detection range analysis to extrapolate the real-world applicability of our scheme Mingshun Sun, Zhiwu Guo, Ming Li 0003, Ryan M. Gerdes |
WISEC | 3 |
| 2022 | QuickN: Practical and Secure Nearest Neighbor Search on Encrypted Large-Scale DataabstractIn this article, we propose a scheme, named QuickN, which can efficiently and securely enable nearest neighbor search over encrypted data on untrusted clouds. Specifically, we modify the search algorithm of nearest neighbors in tree structures (e.g., R-trees), such that the modified algorithm adapts to lightweight cryptographic primitives (e.g., Order-Preserving Encryption) without affecting the original faster-than-linear search complexity. Moreover, we propose an optimized algorithm on top of our modified search algorithm, where it can significantly save communication overheads of a client without introducing any additional information leakage. We devise an approximate algorithm to$k$-nearest neighbor search to improve search efficiency by taking a tradeoff in the completeness of search results. In addition, we also demonstrate our design only leaks minimal privacy against advanced inference attacks. Our experimental results on Amazon EC2 show that our algorithms are extremely practical over massive datasets. Boyang Wang 0001, Yantian Hou, Ming Li 0003 |
IEEE Trans. Cloud Comput. | 3 |
| 2022 | Local Information Privacy and Its Application to Privacy-Preserving Data AggregationabstractIn this article, we propose local information privacy (LIP), and design LIP based mechanisms for statistical aggregation while protecting users’ privacy without relying on a trusted third party. The concept of context-awareness is incorporated in LIP, which can be viewed as exploiting of data prior (both in privatizing and post-processing) to enhance data utility. We present an optimization framework to minimize the mean square error of data aggregation while protecting the privacy of each user’s input data or a correlated latent variable by satisfying LIP constraints. Then, we study optimal mechanisms under different scenarios considering the prior uncertainty and correlation with a latent variable. Three types of mechanisms are studied in this article, including randomized response (RR), unary encoding (UE), and local hashing (LH), and we derive closed-form solutions for the optimal perturbation parameters that are prior-dependent. We compare LIP-based mechanisms with those based on LDP, and theoretically show that the former achieve enhanced utility. We then study two applications: (weighted) summation and histogram estimation, and show how proposed mechanisms can be applied to each application. Finally, we validate our analysis by simulations using both synthetic and real-world data. Results show the impact on data utility by different prior distributions, correlations, and input domain sizes. Results also show that our LIP-based mechanisms provide better utility-privacy tradeoffs than LDP-based ones. Bo Jiang 0015, Ming Li 0003, Ravi Tandon |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Privacy-Preserving Aggregate Mobility Data Release: An Information-Theoretic Deep Reinforcement Learning ApproachabstractIt is crucial to protect users’ location traces against inference attacks on aggregate mobility data collected from multiple users in various real-world applications. Most of the existing works on aggregate mobility data are focusing on inference attacks rather than designing privacy-preserving release mechanisms, and a few differential private release mechanisms suffer from poor utility-privacy tradeoffs. In this paper, we propose optimal centralized privacy-preserving aggregate mobility data release mechanisms (PAMDRMs) that minimize the leakage from an information-theoretic perspective by releasing perturbed versions of the raw aggregate location. Specifically, we use mutual information to measure user-level and aggregate-level privacy leakage separately, and formulate leakage minimization problems under utility constraints. As directly solving the optimization problems incur exponential complexity w.r.t. users’ trace length, we transform them into belief state Markov Decision Processes (MDPs), with a focus on the MDP formulation for the user-level privacy problem. We build reinforcement learning (RL) models and leverage the efficient Asynchronous Advantage Actor-Critic RL algorithm to derive the solutions to the MDPs as our optimal PAMDRMs. We compare them with two state-of-the-art privacy protection mechanisms PDPR (context-aware local design) and DMLM (context-free centralized design) in terms of mutual information leakage and adversary’s attack success (evaluated by her expected estimation error and Jensen-Shannon Divergence-based error). Extensive experimental results on both synthetic and real-world datasets demonstrate that the user-level PAMDRM performs the best on both measures thanks to its context-aware property and centralized design. Even though the aggregate-level PAMDRM achieves better privacy-utility tradeoff than the other two, it does not always perform better than them on adversarial success, highlighting the necessity of considering privacy measures from different perspectives to avoid overestimating the level of privacy offered to users. Lastly, we discuss an alternative, fully data-driven approach to derive the optimal PAMDRM by leveraging adversarial training on limited data samples. Wenjing Zhang 0002, Bo Jiang 0015, Ming Li 0003, Xiaodong Lin 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2022 | In-Band Secret-Free Pairing for COTS Wireless DevicesabstractMany IoT devices lack the necessary interfaces (keyboards, screens) for entering passwords or changing default ones. For these devices, bootstrapping trust can be challenging. We address the problem of device pairing in the absence of any shared secrets. Pairing is a two-phase process that requires mutual authentication between the two parties and the agreement to a common key that can be used to further bootstrap essential cryptographic mechanisms. We propose a secret-free and in-band trust establishment protocol that achieves the secure pairing of commercial off-the-shelf (COTS) wireless devices with a hub. As compared to the state-of-the-art, our protocol does not require any hardware/firmware modification to the devices, or any out-of-band channels, but can be applied to any COTS device. Furthermore, our protocol is resistant to active signal manipulations attacks that include recently demonstrated signal nullification at an intended receiver. These security properties are achieved in-band with the assistance of a helper device such as a smartphone and by exploiting hard-to-forge signal propagation laws. We perform extensive theoretical analysis to verify the security of the proposed protocol. In addition, we validate our theoretical results with experiments using COTS devices and USRP radios. Nirnimesh Ghose, Loukas Lazos, Ming Li 0003 |
IEEE Trans. Mob. Comput. | 3 |
| 2021 | Insider-Resistant Context-Based Pairing for Multimodality Sleep Apnea TestabstractThe increasingly sophisticated at-home screening systems for obstructive sleep apnea (OSA), integrated with both contactless and contact-based sensing modalities, bring convenience and reliability to remote chronic disease management. However, the device pairing processes between system components are vulnerable to wireless exploitation from a non-compliant user wishing to manipulate the test results. This work presents SIENNA, an insider-resistant context-based pairing protocol. SIENNA leverages JADE-ICA to uniquely identify a user's respiration pattern within a multi-person environment and fuzzy commitment for automatic device pairing, while using friendly jamming technique to prevent an insider with knowledge of respiration patterns from acquiring the pairing key. Our analysis and test results show that SIENNA can achieve reliable (> 90% success rate) device pairing under a noisy environment and is robust against the attacker with full knowledge of the context information. Yao Zheng 0004, Shekh M. M. Islam, Yanjun Pan 0001, Marionne Millan, Samson Aggelopoulos, Brian Lu, Alvin Yang, Thomas Yang 0003, Stephanie Aelmore, Willy Chang, Alana Power, Ming Li 0003, Olga Boric-Lubecke, Victor Lubecke, Wenhai Sun |
GLOBECOM | 12 |
| 2021 | Man-in-the-Middle Attack Resistant Secret Key Generation via Channel RandomizationabstractPhysical-layer based key generation schemes exploit the channel reciprocity for secret key extraction, which can achieve information-theoretic secrecy against eavesdroppers. Such methods, although practical, have been shown to be vulnerable against man-in-the-middle (MitM) attacks, where an active adversary, Mallory, can influence and infer part of the secret key generated between Alice and Bob by injecting her own packet upon observing highly correlated channel/RSS measurements from Alice and Bob. As all the channels remain stable within the channel coherence time, Mallory's injected packets cause Alice and Bob to measure similar RSS, which allows Mallory to successfully predict the derived key bits. To defend against such a MitM attack, we propose to utilize a reconfigurable antenna at one of the legitimate transceivers to proactively randomize the channel state across different channel probing rounds. The randomization of the antenna mode at every probing round breaks the temporal correlation of the channels from the adversary to the legitimate devices, while preserving the reciprocity of the channel between the latter. This prevents key injection from the adversary without affecting Alice and Bob's ability to measure common randomness. We theoretically analyze the security of the protocol and conduct extensive simulations and real-world experiments to evaluate its performance. Our results show that our approach eliminates the advantage of an active MitM attack by driving down the probability of successfully guessing bits of the secret key to a random guess. Yanjun Pan 0001, Ziqi Xu 0006, Ming Li 0003, Loukas Lazos |
MobiHoc | 3 |
| 2021 | Context-Aware Local Information PrivacyabstractIn this paper, we study Local Information Privacy (LIP). As a context-aware privacy notion, LIP relaxes the de facto standard privacy notion of local differential privacy (LDP) by incorporating prior knowledge and therefore achieving better utility. We study the relationships between LIP and some of the representative privacy notions including LDP, mutual information and maximal leakage. We show that LIP provides strong instance-wise privacy protection compared to other context-aware privacy notions. Moreover, we present some useful properties of LIP, including post-processing, linkage, composability, transferability and robustness to imperfect prior knowledge. Then we study a general utility-privacy tradeoff framework, under which we derive LIP based privacy-preserving mechanisms for both discrete and continuous-valued data. Three types of perturbation mechanisms are studied in this paper: 1) randomized response (RR), 2) random sampling (RS) and 3) additive noise (AN) (e.g., Gaussian mechanism). Our privacy mechanisms incorporate the prior knowledge into the perturbation parameters so as to enhance utility. Finally, we present a comprehensive set of experiments on real datasets to illustrate the advantage of context-awareness and compare the utility-privacy tradeoffs provided by different mechanisms. Bo Jiang 0015, Mohamed Seif, Ravi Tandon, Ming Li 0003 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2021 | Online Learning-Based Reconfigurable Antenna Mode Selection Exploiting Channel CorrelationabstractReconfigurable antennas (RAs) emerged as a promising technology that can deal with channel variations and enhance the capacity and reliability of the wireless channel. To fully exploit the advantage of RAs, optimal antenna modes need to be selected in an online manner. However, the channel statistics are unknown a priori. Multi-armed bandit-based online learning algorithms were proposed to address this challenge, but the main drawback of existing approaches are that their regret scales linearly with the number of antenna modes, which converges slowly when the latter is large. To improve the scalability, we first apply an existing algorithm: Thompson sampling via Gaussian process (TS-GP), and propose two new algorithms for antenna mode selection: upper confidence bound with channel prediction (UCB-CP) and Thompson Sampling with channel prediction (TS-CP). TS-GP uses Gaussian prior to model the reward distribution of each antenna mode, as well as the correlation among them. UCB-CP and TS-CP exploit channel modeling to predict the channel conditions of unexplored antenna modes at each time step, by relating the correlation between different channel states to the underlying antenna modes. We prove the finite-time regret bound of UCB-CP and show that it is independent from the number of arms, when the expected channel estimation errors are small enough. We also extend the algorithms to the mobile setting. Both simulation results and real-world experiments show that all of our proposed learning algorithms can significantly improve the convergence rate and yield much lower regret (thus higher throughput) than existing schemes. Tianchi Zhao 0001, Ming Li 0003, Yanjun Pan 0001 |
IEEE Trans. Wirel. Commun. | 2 |
| 2020 | StegoNet: Turn Deep Neural Network into a StegomalwareabstractDeep Neural Networks (DNNs) are now presenting human-level performance on many real-world applications, and DNN-based intelligent services are becoming more and more popular across all aspects of our lives. Unfortunately, the ever-increasing DNN service implies a dangerous feature which has not yet been well studied–allowing the marriage of existing malware and DNN model for any pre-defined malicious purpose. In this paper, we comprehensively investigate how to turn DNN into a new breed evasive self-contained stegomalware, namely StegoNet, using model parameter as a novel payload injection channel, with no service quality degradation (i.e. accuracy) and the triggering event connected to the physical world by specified DNN inputs. A series of payload injection techniques which take advantage of a variety of unique neural network natures like complex structure, high error resilience capability and huge parameter size, are developed for both uncompressed models (with model redundancy) and deeply compressed models tailored for resource-limited devices (no model redundancy), including LSB substitution, resilience training, value mapping, and sign-mapping. We also proposed a set of triggering techniques like logits trigger, rank trigger and fine-tuned rank trigger to trigger StegoNet by specific physical events under realistic environment variations. We implement the StegoNet prototype on Nvidia Jetson TX2 testbed. Extensive experimental results and discussions on the evasiveness, integrity of proposed payload injection techniques, and the reliability and sensitivity of the triggering techniques, well demonstrate the feasibility and practicality of StegoNet. Tao Liu 0023, Zihao Liu 0015, Qi Liu 0017, Wujie Wen, Wenyao Xu, Ming Li 0003 |
ACSAC | 6 |
| 2020 | Privacy-Utility Tradeoff in Dynamic Spectrum Sharing with Non-Cooperative Incumbent UsersabstractDynamic spectrum access enables opportunistic users (OUs) to access underutilized licensed bands by querying spectrum databases. However, the operational details of the incumbent users may leak to OUs during the query process. Privacy and exclusion zones have been proposed as effective countermeasures to protect the IUs' privacy, while also managing interference. In the case of multiple heterogeneous coexisting IUs, there is an inherent tradeoff between their achieved throughput, which is controlled by the received interference, and the utility provided to OUs, under a fixed privacy constraint. In this paper, we address the problem of maximizing the utility of rational IUs, defined as the weighted sum between the IUs' capacity and compensation from allowing OUs' opportunistic access while meeting the individual IUs' privacy constraints. We formulate the interaction between the heterogeneous IUs as a non-cooperative continuous game and derive the Nash equilibrium that maximizes the utility of each IU. Our simulations show that the NE solution improves the individual utilities of the IUs compared to a joint optimization approach, where the sum of the utilities is maximized while providing more fairness to the IUs. Ahmed M. Salama, Ming Li 0003, Loukas Lazos, Yong Xiao 0001, Marwan Krunz |
ICC | 2 |
| 2020 | Providing Input-Discriminative Protection for Local Differential PrivacyabstractLocal Differential Privacy (LDP) provides provable privacy protection for data collection without the assumption of the trusted data server. In the real-world scenario, different data have different privacy requirements due to the distinct sensitivity levels. However, LDP provides the same protection for all data. In this paper, we tackle the challenge of providing input-discriminative protection to reflect the distinct privacy requirements of different inputs. We first present the Input- Discriminative LDP (ID-LDP) privacy notion and focus on a specific version termed MinID-LDP, which is shown to be a fine-grained version of LDP. Then, we focus on the application of frequency estimation and develop the IDUE mechanism based on Unary Encoding for single-item input and the extended mechanism IDUE-PS (with Padding-and-Sampling protocol) for item-set input. The results on both synthetic and real-world datasets validate the correctness of our theoretical analysis and show that the proposed mechanisms satisfying MinID-LDP have better utility than the state-of-the-art mechanisms satisfying LDP due to the input-discriminative protection. Xiaolan Gu, Ming Li 0003, Li Xiong 0001, Yang Cao 0011 |
ICDE | 2 |
| 2020 | Regret Analysis of Stochastic Multi-armed Bandit Problem with Clustered Information FeedbackabstractIn this paper, we analyze the regret bound of Multi-armed Bandit (MAB) algorithms under the setting where the payoffs of an arbitrary-size cluster of arms are observable in each round. Compared to the well-studied bandit or full feedback setting, where the payoffs of the selected arm or all the arms are observable, the clustered feedback setting can be viewed as a generalization and a connection. We focus on two most representative MAB algorithms: Upper Confidence Bound and Thompson sampling, and adapt them into the clustered feedback setting. Then, we theoretically derive the regret bound for each of them considering the general type of payoffs (value comes from continuous domains). We show that the regret bounds of these two algorithms with clustered information feedback depend only on the number of clusters. Finally, we simulate both synthetic data and real-world data to compare the performance of these algorithms with different numbers of observable payoffs in each round, the results validate our analysis. Tianchi Zhao 0001, Bo Jiang 0015, Ming Li 0003, Ravi Tandon |
IJCNN | 3 |
| 2020 | ROBin: Known-Plaintext Attack Resistant Orthogonal Blinding via Channel RandomizationabstractOrthogonal blinding based schemes for wireless physical layer security aim to achieve secure communication by injecting noise into channels orthogonal to the main channel and corrupting the eavesdropper’s signal reception. These methods, albeit practical, have been proven vulnerable against multiantenna eavesdroppers who can filter the message from the noise. The vulnerability is rooted in the fact that the main channel state remains static in spite of the noise injection, which allows an eavesdropper to estimate it promptly via known symbols and filter out the noise. Our proposed scheme leverages a reconfigurable antenna for Alice to rapidly change the channel state during transmission and a compressive sensing based algorithm for her to predict and cancel the changing effects for Bob. As a result, the communication between Alice and Bob remains clear, whereas randomized channel state prevents Eve from launching the knownplaintext attack. We formally analyze the security of the scheme against both single and multi-antenna eavesdroppers and identify its unique anti-eavesdropping properties due to the artificially created fast-changing channel. We conduct extensive simulations and real-world experiments to evaluate its performance. Empirical results show that our scheme can suppress Eve’s attack success rate to the level of random guessing, even if she knows all the symbols transmitted through other antenna modes. Yanjun Pan 0001, Yao Zheng 0004, Ming Li 0003 |
INFOCOM | 3 |
| 2020 | Wireless Federated Learning with Local Differential PrivacyabstractIn this paper, we study the problem of federated learning (FL) over a wireless channel, modeled by a Gaussian multiple access channel (MAC), subject to local differential privacy (LDP) constraints. We show that the superposition nature of the wireless channel provides a dual benefit of bandwidth efficient gradient aggregation, in conjunction with strong LDP guarantees for the users. We propose a private wireless gradient aggregation scheme, which shows that when aggregating gradients from K users, the privacy leakage per user scales as O(1/√K) compared to orthogonal transmission in which the privacy leakage scales as a constant. We also present analysis for the convergence rate of the proposed private FL aggregation algorithm and study the tradeoffs between wireless resources, convergence, and privacy. Mohamed Seif, Ravi Tandon, Ming Li 0003 |
ISIT | 3 |
| 2020 | Data inference from encrypted databases: a multi-dimensional order-preserving matching approachabstractDue to increasing concerns of data privacy, databases are being encrypted before they are stored on an untrusted server. To enable search operations on the encrypted data, searchable encryption techniques have been proposed. Representative schemes use order-preserving encryption (OPE) for supporting efficient Boolean queries on encrypted databases. Yet, recent works showed the possibility of inferring plaintext data from OPE-encrypted databases, merely using the order-preserving constraints, or combined with an auxiliary plaintext dataset with similar frequency distribution. So far, the effectiveness of such attacks is limited to single-dimensional dense data (most values from the domain are encrypted), but it remains challenging to achieve it on high-dimensional datasets (e.g., spatial data), which are often sparse in nature. In this paper, for the first time, we study data inference attacks on multi-dimensional encrypted databases (with 2-D as a special case). We formulate it as a 2-D order-preserving matching problem and explore both unweighted and weighted cases, where the former maximizes the number of points matched using only order information and the latter further considers points with similar frequencies. We prove that the problem is NP-hard, and then propose a greedy algorithm, along with a polynomial-time algorithm with approximation guarantees. Experimental results on synthetic and real-world datasets show that the data recovery rate is significantly enhanced compared with the previous 1-D matching algorithm. Yanjun Pan 0001, Alon Efrat, Ming Li 0003, Boyang Wang 0001, Hanyu Quan, Joseph S. B. Mitchell, Jie Gao 0001, Esther M. Arkin |
MobiHoc | 3 |
| 2020 | GhostImage: Remote Perception Attacks against Camera-based Image Classification Systems
Yanmao Man, Ming Li 0003, Ryan M. Gerdes |
RAID | 2 |
| 2020 | PCKV: Locally Differentially Private Correlated Key-Value Data Collection with Optimized Utility
Xiaolan Gu, Ming Li 0003, Yueqiang Cheng, Li Xiong 0001, Yang Cao 0011 |
USENIX Security Symposium | 2 |
| 2020 | SVM: secure vehicle motion verification with a single wireless receiverabstractConnected vehicles leverage wireless interfaces to broadcast their motion state information for improved traffic safety and efficiency. It is crucial for their motion claims (location and velocity) to be verified at the receivers to detect spoofing attacks. Existing approaches typically require multiple cooperative distributed verifiers, which is not applicable to vehicular networks. In this work, we propose a secure motion verification scheme based on Angle-of-Arrival and Frequency-of-Arrival that only requires a single verifier, by exploiting opportunistic signal reflection paths in the environment to create multiple virtual verifiers. We analyze the security of our scheme both theoretically and under realistic road topology. We also carry out real-world experiments with two vehicles in a campus environment, and results show that our scheme can accurately detect false motion claims in a low relative speed vehicular network. Mingshun Sun, Yanmao Man, Ming Li 0003, Ryan M. Gerdes |
WISEC | 3 |
| 2020 | Aggregation-based location privacy: An information theoretic approach
Wenjing Zhang 0002, Bo Jiang 0015, Ming Li 0003, Ravi Tandon, Qiao Liu 0002, Hui Li 0006 |
Comput. Secur. | 3 |
| 2020 | Toward Practical Privacy-Preserving Frequent Itemset Mining on Encrypted Cloud DataabstractFrequent itemset mining, which is the essential operation in association rule mining, is one of the most widely used data mining techniques on massive datasets nowadays. With the dramatic increase on the scale of datasets collected and stored with cloud services in recent years, it is promising to carry this computation-intensive mining process in the cloud. Amount of work also transferred the approximate mining computation into the exact computation, where such methods not only improve the accuracy also aim to enhance the efficiency. However, while mining data stored on public clouds, it inevitably introduces privacy concerns on sensitive datasets. In this paper, we propose a new framework for enforcing privacy in frequent itemset mining, where data are both collected and mined in an encrypted form in a public cloud service. We specifically design three secure frequent itemset mining protocols on top of this framework. Our first protocol achieves more efficient mining performance while our second protocol provides a stronger privacy guarantee. In order to further optimize the performance of the second protocol, we leverage a minor trade-off of privacy to get our third protocol. Finally, we evaluate the performance of our protocols with extensive experiments, and the results demonstrate that our protocols obviously outperform previous solutions in performance with the same security level. Shuo Qiu, Boyang Wang 0001, Ming Li 0003, Jiqiang Liu, Yanfeng Shi |
IEEE Trans. Cloud Comput. | 3 |
| 2020 | Message Integrity Protection Over Wireless Channel: Countering Signal Cancellation via Channel RandomizationabstractPhysical layer message integrity protection and authentication by countering signal-cancellation has been shown as a promising alternative to traditional pure cryptographic message authentication protocols, due to the non-necessity of neither pre-shared secrets nor secure channels. However, the security of such an approach remained an open problem due to the lack of systematic security modeling and quantitative analysis. In this paper, we first establish a novel signal cancellation attack framework to study the optimal signal-cancellation attacker's behavior and utility using game-theory, which precisely captures the attacker's knowledge using its correlated channel estimates in various channel environments as well as the online nature of the attack. Based on theoretical results, we propose a practical channel randomization approach to defend against signal cancellation attack, which exploits state diversity and swift reconfigurability of reconfigurable antenna to increase randomness and meanwhile reduce correlation of channel state information. We show that by proactively mimicking the attacker and placing restrictions on the attacker's location, we can bound the attacker's knowledge of channel state information, thereby achieve a guaranteed level of message integrity protection in practice. Besides, we conduct extensive experiments and simulations to show the security and performance of the proposed approach. We believe our novel threat modeling and quantitative security analysis methodology can benefit a wide range of physical layer security problems. Yanjun Pan 0001, Yantian Hou, Ming Li 0003, Ryan M. Gerdes, Kai Zeng 0001, Md. Asaduzzaman Towfiq, Bedri A. Cetiner |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2019 | SIMPLE: single-frame based physical layer identification for intrusion detection and prevention on in-vehicle networksabstractThe Controller Area Network (CAN) is a bus standard commonly used in the automotive industry for connecting Electronic Control Units (ECUs) within a vehicle. The broadcast nature of this protocol, along with the lack of authentication or strong integrity guarantees for frames, allows for arbitrary data injection/modification and impersonation of the ECUs. While mitigation strategies have been proposed to counter these attacks, high implementation costs or violation of backward compatibility hinder their deployment. In this work, we first examine the shortcomings of state-of-the-art CAN intrusion detection and identification systems that rely on multiple frames to detect misbehavior and attribute it to a particular ECU, and show that they are vulnerable to a Hill-Climbing-style attack. Then we propose SIMPLE, a real-time intrusion detection and identification system that exploits physical layer features of ECUs, which would not only allow an attack to be detected using a single frame but also be effectively nullified. SIMPLE has low computational and data acquisition costs, and its efficacy is demonstrated by both in-lab experiments with automotive-grade CAN transceivers as well as in-vehicle experiments, where average equal error rates of close to 0% and 0.8985% are achieved, respectively. Mahsa Foruhandeh, Yanmao Man, Ryan M. Gerdes, Ming Li 0003, Thidapat Chantem |
ACSAC | 4 |
| 2019 | Local Information Privacy with Bounded PriorabstractA localized privacy protection notion: local information privacy (LIP) is studied in this paper. As a context-aware notion that considers prior knowledge, the LIP notion is shown to provide increased utility than local differential privacy (LDP). Within the scope of LIP, we further consider scenarios with uncertainty on the prior knowledge, i.e., the prior is bounded within a certain range or the prior is arbitrary. The former case is defined as bounded-prior LIP (BP-LIP), and the latter as worst-case LIP (WC-LIP). The contributions of this paper are three-fold: We first provide theoretical results which show the connections of these new definitions with LDP; Secondly, we present an optimization framework for privacy-preserving data collection, with the goal of minimizing the expected squared error while satisfying BP-LIP and WC-LIP privacy constraints. Utility-privacy tradeoffs are obtained in closed-form. At last, we validate our conclusions by numerical analysis and real-world data simulation. Our results show that the notion of bounded-prior LIP can achieve better utility-privacy tradeoff compared to context free notion of LDP. Bo Jiang 0015, Ming Li 0003, Ravi Tandon |
ICC | 2 |
| 2019 | Fast Reconfigurable Antenna State Selection with Hierarchical Thompson SamplingabstractReconfigurable antennas (RAs) arised as a promising antenna technology which can adapt to channel variations and enhance wireless link capacity. To fully take advantage of RA's benefits, optimal antenna states need to be selected on-the-fly. However the channel statistics are unknown a priori. Multi-armed bandit (MAB) algorithms have been adopted to cope with this challenge, however the main drawback of existing approaches is that their regret scales linearly with the number of candidate antenna states and converges slowly with time. In this paper, we propose a novel Hierarchical Thompson Sampling (HTS) algorithm. HTS divides the arms into multiple clusters, first uses TS to sample a cluster and then samples an individual arm inside that cluster. Then we apply HTS to anntena state selection, and propose a K-means based antenna state clustering strategy by exploiting antenna radiation pattern correlation. Simulation results using a real-world RA's radiation patterns show that our HTS algorithm can substantially improve the convergence rate and enjoys much lower expected regret than existing schemes, especially for a large number of antenna states. Tianchi Zhao 0001, Ming Li 0003, Matthias Poloczek |
ICC | 2 |
| 2019 | Context Aware Laplacian Mechanism for Local Information PrivacyabstractIn this paper, we consider the problem of designing additive noise mechanisms for data release subject to a local information privacy constraint. While there has been significant prior work on devising additive noise mechanisms for differential privacy (such as Laplacian and Gaussian mechanisms), for the notion of information privacy, which accounts for prior-knowledge about the data, there are no such general purpose additive noise mechanisms. To this end, we devise a prior-aware Laplacian noise mechanism, which satisfies local information privacy. We show that adding context awareness (i.e., via the knowledge of prior of the data) improves the tradeoff between utility and privacy when compared to context-unaware mechanisms. Mohamed Seif, Ravi Tandon, Ming Li 0003 |
ITW | 3 |
| 2019 | Crowdsourced measurements for device fingerprintingabstractPhysical layer identification allows verifying a user's identity based on their transmitter hardware. In contrast with digital identifiers at higher protocol layers, physical layer identification or device fingerprinting can identify unique signal characteristics at the physical layer introduced by manufacturing variability specific to each device. Recently, dynamic spectrum access has been proposed to allow a larger number of devices to efficiently access wireless spectrum. In such a system many low-cost devices may be distributed over a large area with spectrum allocated and managed by a central authority. Traditional authentication methods may not be secure, or adequate to identify existing users in a backwards compatible way: Identifiers such as MAC addresses can be impersonated, and the number of devices and their distributed nature may make key distribution and revocation difficult. Consequently, physical layer identification can be used to augment other security measures. Seth Andrews, Ryan M. Gerdes, Ming Li 0003 |
WiSec | 3 |
| 2019 | FastGeo: Efficient Geometric Range Queries on Encrypted Spatial DataabstractSpatial data have wide applications, e.g., location-based services, and geometric range queries (i.e., finding points inside geometric areas, e.g., circles or polygons) are one of the fundamental search functions over spatial data. The rising demand of outsourcing data is moving large-scale datasets, including large-scale spatial datasets, to public clouds. Meanwhile, due to the concern of insider attackers and hackers on public clouds, the privacy of spatial datasets should be cautiously preserved while querying them at the server side, especially for location-based and medical usage. In this paper, we formalize the concept of Geometrically Searchable Encryption, and propose an efficient scheme, named FastGeo, to protect the privacy of clients' spatial datasets stored and queried at a public server. With FastGeo, which is a novel two-level search for encrypted spatial data, an honest-but-curious server can efficiently perform geometric range queries, and correctly return data points that are inside a geometric range to a client without learning sensitive data points or this private query. FastGeo supports arbitrary geometric areas, achieves sublinear search time, and enables dynamic updates over encrypted spatial datasets. Our scheme is provably secure, and our experimental results on real-world spatial datasets in cloud platform demonstrate that FastGeo can boost search time over 100 times. Boyang Wang 0001, Ming Li 0003, Li Xiong 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2019 | Online Location Trace Privacy: An Information Theoretic ApproachabstractWe consider the problem of protecting individual user's location privacy at the trace-level and study the privacy-utility trade-off, which has key applications in privacy-preserving location-based service. Existing works on Location Privacy Protection Mechanisms (LPPMs) have mainly focused on protecting single location, without taking into account the temporal correlations among locations within the trace, which can lead to higher privacy leakage when considering the whole trace. However, to date, there lacks a formal framework to quantify the trace-level location privacy leakage, and a practical mechanism to release location traces in an optimal and online manner. In this paper, we endeavor to solve this problem using an information-theoretic approach. We first propose a location trace privacy metric based on the mutual information between the original and released trace in an offline setting, and formulate the optimal location trace release problem that minimizes trace-level privacy leakage given a utility constraint. We also propose a privacy metric to capture trace-level privacy leakage in an online setting. As directly computing these metrics incur exponential complexity w.r.t. the trace length, we obtain upper and lower bounds on the trace-level privacy leakage by exploiting the Markov structure of the temporal location correlations, which are efficiently computable. The proposed upper bounds enable us to derive efficient online solutions (i.e., LPPMs) by modifying Blahut-Arimoto algorithm in rate-distortion theory. Then we validate the proposed upper and lower bounds and the actual leakage of our LPPM through extensive experiments over both synthetic and real-world location data sets. Our results show the superiority of our LPPM over existing LPPMs in terms of trace-level privacy-utility tradeoff, which is more conspicuous when the location trace is more correlated. Wenjing Zhang 0002, Ming Li 0003, Ravi Tandon, Hui Li 0006 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2018 | On the Secure Degrees of Freedom of 2 x 2 x 2 Multi-Hop Network with Untrusted RelaysabstractWe study the impact of untrusted relays on the degrees of freedom of multi-antenna multi-hop networks. In par- ticular, we consider the two user two-hop interference network, where two source nodes want to send independent messages securely to their designated receivers through the help of two untrusted relays. The relays are considered untrusted in terms of eavesdropping the messages sent by the sources. Moreover, we also assume that the messages are confidential, i.e., each receiver must not be able to decode the information meant for the other receiver. We assume that all the terminals (i.e., sources, relays, and the receivers) are equipped with multiple number of antennas. The goal of this work is to understand the secure degrees of freedom (SDoF) region of this multi-hop MIMO network under the two constraints of a) untrusted relays; and b) confidential messages. To cope with the untrusted nature of relays, we present achievable schemes in which both sources mix their information symbols with artificial noises so that the signals at each relay are completely immersed in the artificial noises space. However, this mixing must be done carefully, so as to ensure the feasibility of interference neutralization in the second hop to allow successful decoding at the respective destination. To this end, we devise transmission schemes based on interference alignment and interference neutralization techniques. The main contributions of this work are as follows: a) we present an upper bound on the SDoF region as a function of the number of antennas at the terminals, b) we present two achievable schemes, the first scheme is based on secure interference alignment and neutralization and is shown to be information theoretically optimal when all terminals have the same number of antennas; and a second scheme, based on secure sub-space alignment and neutralization, which is shown to be optimal for another specific antenna configuration. To the best of our knowledge, these are the first results on multi-hop MIMO relay networks with untrusted relays and confidential messages. Mohamed Seif, Ravi Tandon, Ming Li 0003 |
ICC | 3 |
| 2018 | SFIRE: Secret-Free-in-band Trust Establishment for COTS Wireless DevicesabstractWe address the problem of trust establishment between wireless devices that do not share any prior secrets. This includes the mutual authentication and agreement to a common key that can be used to further bootstrap essential cryptographic mechanisms. We propose SFIRE, a secret-free trust establishment protocol that allows the secure pairing of commercial off-the-shelf (COTS) wireless devices with a hub. Compared to the state-of-the-art, SFIRE does not require any out-of-band channels, special hardware, or firmware modification, but can be applied to any COTS device. Moreover, SFIRE is resistant to the most advanced active signal manipulations that include recently demonstrated signal nullification at an intended receiver. These security properties are achieved in-band with the assistance of a helper device such as a smartphone and by using the RSS fluctuation patterns to build a robust “RSS authenticator”. We perform extensive experiments using COTS devices and USRP radios and verify the validity of the proposed protocol. Nirnimesh Ghose, Loukas Lazos, Ming Li 0003 |
INFOCOM | 3 |
| 2018 | On the Secure Degrees of Freedom of the K-user Interference Channel with Delayed CSITabstractIn this paper, the K-user interference channel with confidential messages is considered with delayed channel state information at transmitters (CSIT). We propose a novel secure transmission scheme in which the transmitters carefully mix information symbols with artificial noises to ensure confidentiality. Achieving confidentiality is challenging due to the delayed nature of CSIT, and the distributed nature of the transmitters. Our scheme works over two phases: phase one in which each transmitter sends information symbols mixed with artificial noises, and repeats such transmission over multiple rounds. In the next phase, each transmitter uses delayed CSIT of the previous phase and sends a function of the net interference and artificial noises (generated in previous phase), which is simultaneously useful for all receivers. These phases are designed to ensure the decodability of the desired messages while satisfying the confidentiality constraints. The proposed scheme achieves a sum secure degrees of freedom (SDoF) of at least [1/2](√K-6). To the best of our knowledge, this is the first result on the K-user interference channel with confidential messages and delayed CSIT that achieves a SDoF which scales with K -. Mohamed Seif, Ravi Tandon, Ming Li 0003 |
ISIT | 3 |
| 2018 | Are Friends of My Friends Too Social?: Limitations of Location Privacy in a Socially-Connected WorldabstractWith the ubiquitous adoption of smartphones and mobile devices, it is now common practice for one's location to be sensed, collected and likely shared through social platforms. While such data can be helpful for many applications, users start to be aware of the privacy issue in handling location and trajectory data. While some users may voluntarily share their location information (e.g., for receiving location-based services, or for crowdsourcing systems), their location information may lead to information leaks about the whereabouts of other users, through the co-location of events when two users are at the same location at the same time and other side information, such as upper bounds of movement speed. It is therefore crucial to understand how much information one can derive about other's positions through the co-location of events and occasional GPS location leaks of some of the users. In this paper we formulate the problem of inferring locations of mobile agents, present theoretically-proven bounds on the amount of information that could be leaked in this manner, study their geometric nature, and present algorithms matching these bounds. We will show that even if a very weak set of assumptions is made on trajectories' patterns, and users are not obliged to follow any 'reasonable' patterns, one could infer very accurate estimation of users' locations even if they opt not to share them. Furthermore, this information could be obtained using almost linear-time algorithms, suggesting the practicality of the method even for huge volumes of data. Boris Aronov, Alon Efrat, Ming Li 0003, Jie Gao 0001, Joseph S. B. Mitchell, Valentin Polishchuk, Boyang Wang 0001, Hanyu Quan, Jiaxin Ding 0001 |
MobiHoc | 3 |
| 2018 | On the Throughput Limit of Multi-Hop Wireless Networks with Reconfigurable AntennasabstractReconfigurable antenna (RA) has emerged as a disruptive antenna technology with the potential of significantly improving the capacity of wireless links, by agilely reconfiguring its antenna states. Through jointly optimizing antenna state selection, routing and scheduling, it offers another dimension of opportunity to enhance end- to-end (E2E) throughput in multi-hop wireless networks (MWNs). However, the throughput limit of MWNs with RAs has not been well understood, due to challenges in theoretical modeling and computational intractability caused by a large number of states. In this work, we endeavor to systematically study this problem. We first propose a general antenna state-link conflict graph model to capture the intricate state-link association and corresponding interference relationship in the network. Based on this model, we formulate a max-flow based optimization framework to derive the throughput bound of a given MWN. As this problem is NP-hard, we explore column generation to solve it more efficiently, and propose a heuristic algorithm which can also accelerate the optimal solution. Simulation results show that our proposed algorithms can efficiently approach or compute the optimal throughput, and validate the advantage of antenna reconfigurability in MWNs. Yanjun Pan 0001, Ming Li 0003, Neng Fan, Yantian Hou |
SECON | 2 |
| 2018 | Secure Device Bootstrapping Without Secrets Resistant to Signal Manipulation AttacksabstractIn this paper, we address the fundamental problem of securely bootstrapping a group of wireless devices to a hub, when none of the devices share prior associations (secrets) with the hub or between them. This scenario aligns with the secure deployment of body area networks, IoT, medical devices, industrial automation sensors, autonomous vehicles, and others. We develop VERSE, a physical-layer group message integrity verification primitive that effectively detects advanced wireless signal manipulations that can be used to launch man-in-the-middle (MitM) attacks over wireless. Without using shared secrets to establish authenticated channels, such attacks are notoriously difficult to thwart and can undermine the authentication and key establishment processes. VERSE exploits the existence of multiple devices to verify the integrity of the messages exchanged within the group. We then use VERSE to build a bootstrapping protocol, which securely introduces new devices to the network. Compared to the state-of-the-art, VERSE achieves in-band message integrity verification during secure pairing using only the RF modality without relying on out-of-band channels or extensive human involvement. It guarantees security even when the adversary is capable of fully controlling the wireless channel by annihilating and injecting wireless signals. We study the limits of such advanced wireless attacks and prove that the introduction of multiple legitimate devices can be leveraged to increase the security of the pairing process. We validate our claims via theoretical analysis and extensive experimentations on the USRP platform. We further discuss various implementation aspects such as the effect of time synchronization between devices and the effects of multipath and interference. Note that the elimination of shared secrets, default passwords, and public key infrastructures effectively addresses the related key management challenges when these are considered at scale. Nirnimesh Ghose, Loukas Lazos, Ming Li 0003 |
IEEE Symposium on Security and Privacy | 3 |
| 2018 | LTE Misbehavior Detection in Wi-Fi/LTE Coexistence Under the LAA-LTE StandardabstractIn this paper, we consider the fair coexistence between LTE and Wi-Fi systems in unlicensed bands. We focus on the misbehavior opportunities that stem from the heterogeneity of the coexisting systems and the lack of explicit coordination mechanisms. We show that a selfishly behaving LTE can gain an unfair share of the spectrum resources through the manipulation of the parameters defined in the LAA-LTE standard, including the manipulation of the backoff mechanism of LAA, the traffic class, the clear channel assignment threshold and others. We develop a detection mechanism for the Wi-Fi system that can identify a misbehaving LTE system. Our mechanism advances the state of the art by providing an accurate monitoring method of the LTE behavior under various topological scenarios, without explicit cross-system coordination. Deviations from the expected behavior are determined by computing the statistical distance between the protocol-specified and estimated distributions of the LAA-LTE protocol parameters. We analytically characterize the detection and false alarm probabilities and show that our detector yields high detection accuracy at very low false alarm rate, for a wise choice of statistical parameters. Islam Samy, Loukas Lazos, Yong Xiao 0001, Ming Li 0003, Marwan Krunz |
WISEC | 4 |
| 2018 | SpecWatch: A framework for adversarial spectrum monitoring with unknown statistics
Ming Li 0044, Dejun Yang, Jian Lin 0003, Ming Li 0003, Jian Tang 0008 |
Comput. Networks | 4 |
| 2018 | Identity-Based Private Matching over Outsourced Encrypted DatasetsabstractWith wide use of cloud computing and storage services, sensitive information is increasingly centralized into the cloud to reduce the management costs, which raises concerns about data privacy. Encryption is a promising way to maintain the confidentiality of outsourced sensitive data, but it makes effective data utilization to be a very challenging task. In this paper, we focus on the problem of private matching over outsourced encrypted datasets in identity-based cryptosystem that can simplify the certificate management. To solve this problem, we propose an Identity-Based Private Matching scheme (IBPM), which realizes fine-grained authorization that enables the privileged cloud server to perform private matching operations without leaking any private data. We present the rigorous security proof under the Decisional Linear Assumption and Decisional Bilinear Diffie-Hellman Assumption. Furthermore, through the analysis of the asymptotic complexity and the experimental evaluation, we verify that the cost of our IBPM scheme is linear to the size of the dataset and it is more efficient than the existing work of Zheng and Xu [30]. Finally, we apply our IBPM scheme to build two efficient schemes, including identity-based fuzzy private matching as well as identity-based multi-keyword fuzzy search. Shuo Qiu, Jiqiang Liu, Yanfeng Shi, Ming Li 0003, Wei Wang 0012 |
IEEE Trans. Cloud Comput. | 4 |
| 2017 | Mutually Private Location Proximity Detection with Access Control
Michael G. Solomon, Vaidy S. Sunderam, Li Xiong 0001, Ming Li 0003 |
DBSec | 4 |
| 2017 | Regular: Attacker-Induced Traffic Flow Instability in a Stream of Semi-Automated VehiclesabstractWe show that a stream of automated vehicles traveling along the highway can be destabilized to catastrophic effect through modification of the control laws of individual vehicles. Specifically, one active attacker who introduces errors, in addition to one or many passive attackers who amplify the error, may, by the modification of a single parameter, induce oscillatory traffic jams that cause delay, driver discomfort, excess energy expenditure, and increased risk of accidents that could result in serious injury or death. We determine the conditions under which an attacker(s) is able to violate the primary design criterion of automated vehicle streams, known as string stability, to guarantee system instability. Furthermore, we prove that once the stream has been destabilized it will continually deviate from the desired state, even in the absence of additional input to the system-i.e. the jammed condition will self-perpetuate. Through a comparison with a behavioral human driver model, this work demonstrates that automated vehicle systems are more vulnerable to disruption than their non-automated counterparts. The postulated attack is demonstrated on a scaled system and identification of attackers is discussed. Daniel D. Dunn, Samuel A. Mitchell, Imran Sajjad, Ryan M. Gerdes, Rajnikant Sharma, Ming Li 0003 |
DSN | 6 |
| 2017 | Optimal Crowdsourced Channel Monitoring in Cognitive Radio NetworksabstractCrowdsourcing is an emerging paradigm for spectrum access rule enforcement in dynamic spectrum sharing, which leverages a large number of mobile users to help monitoring and detecting spectrum violations and misuse. Its main advantages compared with traditional dedicated monitoring architecture includes enhanced coverage, effectiveness and lower costs. However, how to optimally assign mobile users to monitor the channel usage has not been studied in the crowdsourced setting. The main challenges are: the large number of channels to monitor while mobile users may not be available all the time, the need to consider monitoring costs and incentives, as well as the uncertainty of each channel's traffic patterns. In this paper, we tackle such challenges by formulating a stochastic optimization problem that optimizes the spectrum monitoring task for crowdsourced mobile users. We consider the availability pattern of the mobile users and we assume they are given payments as incentives for participating in monitoring. Simulations show that our method outperforms the risk-averse scenario and has a small gap with the solution under perfect information. Ahmed M. Salama, Ming Li 0003, Dejun Yang |
GLOBECOM | 2 |
| 2017 | HELP: Helper-Enabled In-Band Device Pairing Resistant Against Signal Cancellation
Nirnimesh Ghose, Loukas Lazos, Ming Li 0003 |
USENIX Security Symposium | 3 |
| 2017 | Location Based Handshake and Private Proximity Test with Location TagsabstractA location proximity test service allows mobile users to determine whether they are in close proximity to each other, and has found numerous applications in mobile social networks. Unfortunately, existing solutions usually reveal much of users' private location information during a proximity test. They are also vulnerable to location cheating where an attacker reports false locations to gain an advantage. Moreover, the initial trust establishment among unfamiliar users in large scale mobile social networks has been a challenging task. In this paper, we propose a novel scheme that enables a user to perform (1) a location based handshake that establishes secure communications among strangers, who do not have a pre-shared secret, and (2) a privacy-preserving proximity test without revealing the user's actual location to the server or other users not within the proximity. The proposed scheme is based on a novel concept, i.e., spatial-temporal location tags, and we put forward a location tag construction method using environmental signals that provides an unforgeable location proof. We use Bloom filters to efficiently represent users' location tags and vicinity regions. We exploit fuzzy extractor, a lightweight cryptographic primitive, to extract shared secrets between matching location tags. We conduct extensive analysis, simulation, and real experiments to demonstrate the feasibility, security, and efficiency of our scheme. Yao Zheng 0004, Ming Li 0003, Wenjing Lou, Y. Thomas Hou 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2017 | Making Wireless Body Area Networks Robust Under Cross-Technology InterferenceabstractWireless body area networks (BANs) demand high-quality service. However, as BANs will be widely deployed in densely populated areas, they inevitably face RF cross-technology interference (CTI) from non-protocol-compliant wireless devices operating in the same spectrum range. The main challenges to defending against such a strong CTI come from the scarcity of spectrum resources, the uncertainty of the CTI sources and BAN channel status, and the stringent hardware constraints. In this paper, we first experimentally characterize the adverse effect on BAN reliability caused by the non-protocol-compliant CTI. Then, we formulate a joint routing and power control (JRPC) problem, which aims at minimizing energy consumption under strong CTI while satisfying node reachability and delay constraints. We reformulate our problem into a mixed integer linear programing problem and then derive the optimal results through IBM's CPLEX. A practical protocol, including a heuristic JRPC algorithm, is then proposed, in which we address the challenge of fast link-quality measurement by proposing a passive link-quality estimation and prediction method. Through experiments and simulations, we show that our protocol can assure the robustness of BAN even when the CTI sources are in very close vicinity, using a small amount of energy on commercial-off-the-shelf sensor devices. Yantian Hou, Ming Li 0003, Shucheng Yu |
IEEE Trans. Wirel. Commun. | 2 |
| 2016 | SecReach: Secure Reachability Computation on Encrypted Location Check-in Data
Hanyu Quan, Boyang Wang 0001, Iraklis Leontiadis, Ming Li 0003, Yuqing Zhang 0001 |
CANS | 4 |
| 2016 | SpecWatch: Adversarial spectrum usage monitoring in CRNs with unknown statisticsabstractIn cognitive radio networks (CRNs), dynamic spectrum access has been proposed to improve the spectrum utilization, but it also generates spectrum misuse problems. One common solution to these problems is to deploy monitors to detect misbehaviors on certain channel. However, in multi-channel CRNs, it is very costly to deploy monitors on every channel. With a limited number of monitors, we have to decide which channels to monitor. In addition, we need to determine how long to monitor each channel and in which order to monitor, because switching channels incurs costs. Moreover, the information about the misuse behavior is not available a priori. To answer those questions, we model the spectrum usage monitoring problem as an adversarial multi-armed bandit problem with switching costs and design two effective online algorithms, SpecWatch and SpecWatch+. In SpecWatch, we select strategies based on the monitoring history and repeat the same strategy for certain timeslots to reduce switching costs. We prove its expected weak regret, i.e., the performance difference between the solution of SpecWatch and optimal (fixed) solution, is O(T2/3), where T is the time horizon. Whereas, in SpecWatch+, we select strategies more strategically to improve the performance. We show its actual weak regret is O(T2/3) with probability 1-δ, for any δ e (0,1). Both algorithms are evaluated through extensive simulations. Ming Li 0044, Dejun Yang, Jian Lin 0003, Ming Li 0003, Jian Tang 0008 |
INFOCOM | 4 |
| 2016 | Practical and secure nearest neighbor search on encrypted large-scale dataabstractNearest neighbor search (or k-nearest neighbor search in general) is one of the most fundamental queries on massive datasets, and it has extensive applications such as pattern recognition, statistical classification, graph algorithms, Location-Based Services and online recommendations. With the raising trend of outsourcing massive sensitive datasets to public clouds, it is urgent for companies and organizations to demand fast and secure nearest neighbor search solutions over their outsourced data, but without revealing privacy to untrusted clouds. However, existing solutions for secure nearest neighbor search still face significant limitations, which make them far from practice. In this paper, we propose a new searchable encryption scheme, which can efficiently and securely enable nearest neighbor search over encrypted data on untrusted clouds. Specifically, we modify the search algorithm of nearest neighbors with tree structures (e.g., R-trees), where the modified algorithm adapts to lightweight cryptographic primitives (e.g., Order-Preserving Encryption) without affecting the original faster-than-linear search complexity. As a result, we address all the limitations in the previous works while still maintaining correctness and security. Moreover, our design is general, which can be used for secure k-nearest neighbor search, and it is compatible with other similar tree structures. Our experimental results on Amazon EC2 show that our scheme is extremely practical over massive datasets. Boyang Wang 0001, Yantian Hou, Ming Li 0003 |
INFOCOM | 3 |
| 2016 | Geometric Range Search on Encrypted Spatial DataabstractGeometric range search is a fundamental primitive for spatial data analysis in SQL and NoSQL databases. It has extensive applications in location-based services, computer-aided design, and computational geometry. Due to the dramatic increase in data size, it is necessary for companies and organizations to outsource their spatial data sets to third-party cloud services (e.g., Amazon) in order to reduce storage and query processing costs, but, meanwhile, with the promise of no privacy leakage to the third party. Searchable encryption is a technique to perform meaningful queries on encrypted data without revealing privacy. However, geometric range search on spatial data has not been fully investigated nor supported by existing searchable encryption schemes. In this paper, we design a symmetric-key searchable encryption scheme that can support geometric range queries on encrypted spatial data. One of our major contributions is that our design is a general approach, which can support different types of geometric range queries. In other words, our design on encrypted data is independent from the shapes of geometric range queries. Moreover, we further extend our scheme with the additional use of tree structures to achieve search complexity that is faster than linear. We formally define and prove the security of our scheme with indistinguishability under selective chosen-plaintext attacks, and demonstrate the performance of our scheme with experiments in a real cloud platform (Amazon EC2). Boyang Wang 0001, Ming Li 0003, Haitao Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2016 | Jamming Resilient Communication Using MIMO Interference CancellationabstractJamming attack is a serious threat to the wireless communications. Reactive jamming maximizes the attack efficiency by jamming only when the targets are communicating, which can be readily implemented using software-defined radios. In this paper, we explore the use of the multi-input multi-output (MIMO) technology to achieve jamming resilient orthogonal frequency-division multiplexing (OFDM) communication. In particular, MIMO interference cancellation treats jamming signals as noise and strategically cancels them out, while transmit precoding adjusts the signal directions to optimize the decoding performance. We first investigate the reactive jamming strategies and their impacts on the MIMO-OFDM receivers. We then present a MIMO-based anti-jamming scheme that exploits MIMO interference cancellation and transmit precoding technologies to turn a jammed non-connectivity scenario into an operational network. We implement our jamming resilient communication scheme using software-defined radios. Our testbed evaluation shows the destructive power of reactive jamming attack, and also validates the efficacy and efficiency of our defense mechanisms in the presence of numerous types of reactive jammers with different jamming signal powers. Qiben Yan 0001, Huacheng Zeng, Tingting Jiang 0005, Ming Li 0003, Wenjing Lou, Y. Thomas Hou 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2016 | Cooperative Interference Mitigation for Heterogeneous Multi-Hop Wireless Networks CoexistenceabstractThis paper studies the coexistence of heterogeneous multi-hop networks, which use different physical-layer technologies. We propose a new paradigm, called cooperative interference mitigation (CIM), which exploits recent advancement in interference cancellation (IC), such as technology-independent multiple output. CIM makes it possible for disparate networks to cooperatively mitigate the interference to/from each other to enhance everyone's performance. We first show the feasibility of CIM among heterogeneous multi-hop networks by exploiting only channel-ratio information. Then, we establish two tractable models to characterize the CIM behaviors of both networks by using full IC and receiver-side IC only. We propose two bi-criteria optimization problems aiming at maximizing both networks' throughput, while cooperatively canceling the interference between them based on our two models. Several simulations are carried out to compare the Pareto-optimal throughput curves by using our CIM paradigms and traditional interference-avoidance (IAV) paradigm. By comparing the results from CIM and IAV, we show that CIM could remarkably improve the coexisting networks' throughput in different network settings. Yantian Hou, Ming Li 0003, Xu Yuan 0001, Y. Thomas Hou 0001, Wenjing Lou |
IEEE Trans. Wirel. Commun. | 2 |
| 2015 | Message Integrity Protection over Wireless Channel by Countering Signal Cancellation: Theory and PracticeabstractPhysical layer message integrity protection and authentication by countering signal-cancellation has been shown as a promising alternative to traditional pure cryptographic message authentication protocols, due to the non-necessity of neither pre-shared secrets nor secure channels. However, the security of such an approach remained an open problem due to the lack of systematic security modeling and quantitative analysis. In this paper, we first establish a novel correlated jamming framework to study the optimal signal-cancellation attacker's behavior and utility using game-theory, which precisely captures the attacker's knowledge using its correlated channel estimates in various channel environments. Besides, we design a practical physical layer message integrity protection protocol based on ON/OFF keying and Manchester coding, which provides quantitative security guarantees in the real-world. Such a guarantee is achieved by bounding the attacker's knowledge about the future channel via proactively measuring channel statistics (mimic the attacker), so as to derive a lower-bound to the defender's signal-detection probability under optimal correlated jamming attacks. We conduct extensive experiments and simulations to show the security and performance of the proposed scheme. We believe our novel threat modeling and quantitative security analysis methodology can benefit a wide range of physical layer security problems. Yantian Hou, Ming Li 0003, Ruchir Chauhan, Ryan M. Gerdes, Kai Zeng 0001 |
AsiaCCS | 2 |
| 2015 | Privacy-preserving inference of social relationships from location data: a vision paperabstractSocial relationships between people, e.g., whether they are friends with each other, can be inferred by observing their behaviors in the real world. Thanks to the popularity of GPS-enabled mobile devices or online services, a large amount of high-resolution location data becomes available for such inference studies. However, due to the sensitivity of location data and user privacy concerns, those studies cannot be largely carried out on individually contributed data without privacy guarantees. Furthermore, we observe that the actual location may not be needed for social relationship studies, but rather the fact that two people met and some statistical properties about their meeting locations, which can be computed in a private manner. In this paper, we envision an extensible framework, dubbed Privacy-preserving Location Analytics and Computation Environment (PLACE), which enables social relationship studies by analyzing individually generated location data. PLACE utilizes an untrusted server and computes several building blocks to support various social relationship studies, without disclosing location information to the server and other untrusted parties. We present PLACE with three example social relationship studies which utilize four privacy-preserving blocks with encryption and differential privacy primitives. The successful realization of PLACE will facilitate private location data acquisition from individual devices, thanks to the strong privacy guarantees, and will enable a wide range of applications. Cyrus Shahabi, Liyue Fan, Luciano Nocera, Li Xiong 0001, Ming Li 0003 |
SIGSPATIAL/GIS | 5 |
| 2015 | Circular Range Search on Encrypted Spatial DataabstractSearchable encryption is a promising technique enabling meaningful search operations to be performed on encrypted databases while protecting user privacy from untrusted third-party service providers. However, while most of the existing works focus on common SQL queries, geometric queries on encrypted spatial data have not been well studied. Especially, circular range search is an important type of geometric query on spatial data which has wide applications, such as proximity testing in Location-Based Services and Delaunay triangulation in computational geometry. In this poster, we propose two novel symmetric-key searchable encryption schemes supporting circular range search. Informally, both of our schemes can correctly verify whether a point is inside a circle on encrypted spatial data without revealing data privacy or query privacy to a semi-honest cloud server. We formally define the security of our proposed schemes, prove that they are secure under Selective Chosen-Plaintext Attacks, and evaluate their performance through experiments in a real-world cloud platform (Amazon EC2). To the best of our knowledge, this work represents the first study in secure circular range search on encrypted spatial data. Boyang Wang 0001, Ming Li 0003, Haitao Wang 0001, Hui Li 0006 |
ICDCS | 2 |
| 2015 | MASK-BAN: Movement-Aided Authenticated Secret Key Extraction Utilizing Channel Characteristics in Body Area NetworksabstractRecently, most wireless network security schemes merely based on physical layer characteristics tackle the two fundamental issues-device authentication and secret key extraction separately. It remains an open problem to simultaneously achieve device authentication and fast secret key extraction merely using wireless physical layer characteristics, without the help of advanced hardware or out-of-band channel. In this paper, we answer this open problem in the setting of wireless body area networks (BANs). We propose MASK-BAN, a lightweight fast authenticated secret key extraction scheme for intra-BAN communication. Our scheme neither introduces advanced hardware nor relies on out-of-band channels. To perform device authentication and fast secret key extraction at the same time, we exploit the heterogeneous channel characteristics among the collection of on-body channels during body motion. On one hand, MASK-BAN achieves authentication through multihop stable channels, which greatly reduces the false positive rate as compared to existing work. On the other hand, based on dynamic channels, key extraction between two on-body devices with multihop relay nodes is modeled as a max-flow problem, and a novel collaborative secret key generation algorithm is introduced to maximize the key generation rate. Extensive real-world experiments on low-end commercial-off-the-shelf sensor devices validate MASK-BAN's great authentication capability and high-secret key generation rate. Shucheng Yu, Ming Li 0003 |
IEEE Internet Things J. | 4 |
| 2014 | POSTER: Analysis and Comparison of Secure Localization Schemes for Intelligent Transportation SystemsabstractIn this work, we employ distance bounding (DB) and verifiable trilateration (VT) for secure localization in an intelligent transportation system (ITS). We first demonstrate several possible attack scenarios, and then establish an analytical framework to evaluate the security of these schemes. Results are derived in terms of the probability of a given position being spoofed by maliciously-controlled vehicles assuming randomly distributed colluding attackers. The results show that while VT outperforms DB, both methods have a high probability of being spoofed. Bhaswati Deka, Ryan M. Gerdes, Ming Li 0003, Kevin P. Heaslip |
CCS | 3 |
| 2014 | Maple: scalable multi-dimensional range search over encrypted cloud data with tree-based indexabstractCloud computing promises users massive scale outsourced data storage services with much lower costs than traditional methods. However, privacy concerns compel sensitive data to be stored on the cloud server in an encrypted form. This posts a great challenge for effectively utilizing cloud data, such as executing common SQL queries. A variety of searchable encryption techniques have been proposed to solve this issue; yet efficiency and scalability are still the two main obstacles for their adoptions in real-world datasets, which are multi-dimensional in general. In this paper, we propose a tree-based public-key Multi-Dimensional Range Searchable Encryption (MDRSE) to overcome the above limitations. Specifically, we first formally define the leakage function and security of a tree-based MDRSE. Then, by leveraging an existing predicate encryption in a novel way, our tree-based MDRSE efficiently indexes and searches over encrypted cloud data with multi-dimensional tree structures (i.e., R-trees). Moreover, our scheme is able to protect single-dimensional privacy while previous efficient solutions fail to achieve. Our scheme is selectively secure, and through extensive experimental evaluation on a large-scale real-world dataset, we show the efficiency and scalability of our scheme. Boyang Wang 0001, Yantian Hou, Ming Li 0003, Haitao Wang 0001, Hui Li 0006 |
AsiaCCS | 3 |
| 2014 | Cooperative cross-technology interference mitigation for heterogeneous multi-hop networksabstractThis paper explores a new paradigm for the coexistence among heterogeneous multi-hop networks in unplanned deployment settings, called cooperative interference mitigation (CIM). CIM exploits recent advancements in physical layer technologies such as technology-independent multiple output (TIMO), making it possible for disparate networks to cooperatively mitigate the interference to each other to enhance everyone's performance, even if they possess different wireless technologies. This paper offers a thorough study of the CIM paradigm for unplanned multi-hop networks. We first show the feasibility of CIM among heterogeneous multi-hop networks by exploiting only channel ratio information, and then establish a tractable model to accurately characterize the CIM behaviors of both networks. We also develop a bi-criteria optimization formulation to maximize both networks' throughput, and propose a new methodology to compute the Pareto-optimal throughput curve as performance bound. Simulation results show that CIM provides significant performance gains to both networks compared with the traditional interference-avoidance paradigm. Yantian Hou, Ming Li 0003, Xu Yuan 0001, Y. Thomas Hou 0001, Wenjing Lou |
INFOCOM | 2 |
| 2014 | MIMO-based jamming resilient communication in wireless networksabstractReactive jamming is considered the most powerful jamming attack as the attack efficiency is maximized while the risk of being detected is minimized. Currently, there are no effective anti-jamming solutions to secure OFDM wireless communications under reactive jamming attack. On the other hand, MIMO has emerged as a technology of great research interest in recent years mostly due to its capacity gain. In this paper, we explore the use of MIMO technology for jamming resilient OFDM communication, especially its capability to communicate against the powerful reactive jammer. We first investigate the jamming strategies and their impacts on the OFDM-MIMO receivers. We then present a MIMO-based anti-jamming scheme that exploits interference cancellation and transmit precoding capabilities of MIMO technology to turn a jammed non-connectivity scenario into an operational network. Our testbed evaluation shows the destructive power of reactive jamming attack, and also validates the efficacy and efficiency of our defense mechanisms. Qiben Yan 0001, Huacheng Zeng, Tingting Jiang 0005, Ming Li 0003, Wenjing Lou, Y. Thomas Hou 0001 |
INFOCOM | 4 |
| 2014 | Friendly Jamming for Secure Localization in Vehicular Transportation
Bhaswati Deka, Ryan M. Gerdes, Ming Li 0003, Kevin P. Heaslip |
SecureComm (1) | 3 |
| 2014 | Tree-Based Multi-dimensional Range Search on Encrypted Data with Enhanced Privacy
Boyang Wang 0001, Yantian Hou, Ming Li 0003, Haitao Wang 0001, Hui Li 0006, Fenghua Li 0001 |
SecureComm (1) | 3 |
| 2014 | Privacy-Preserving Multi-Keyword Ranked Search over Encrypted Cloud DataabstractWith the advent of cloud computing, data owners are motivated to outsource their complex data management systems from local sites to the commercial public cloud for great flexibility and economic savings. But for protecting data privacy, sensitive data have to be encrypted before outsourcing, which obsoletes traditional data utilization based on plaintext keyword search. Thus, enabling an encrypted cloud data search service is of paramount importance. Considering the large number of data users and documents in the cloud, it is necessary to allow multiple keywords in the search request and return documents in the order of their relevance to these keywords. Related works on searchable encryption focus on single keyword search or Boolean keyword search, and rarely sort the search results. In this paper, for the first time, we define and solve the challenging problem of privacy-preserving multi-keyword ranked search over encrypted data in cloud computing (MRSE). We establish a set of strict privacy requirements for such a secure cloud data utilization system. Among various multi-keyword semantics, we choose the efficient similarity measure of "coordinate matching," i.e., as many matches as possible, to capture the relevance of data documents to the search query. We further use "inner product similarity" to quantitatively evaluate such similarity measure. We first propose a basic idea for the MRSE based on secure inner product computation, and then give two significantly improved MRSE schemes to achieve various stringent privacy requirements in two different threat models. To improve search experience of the data search service, we further extend these two schemes to support more search semantics. Thorough analysis investigating privacy and efficiency guarantees of proposed schemes is given. Experiments on the real-world data set further show proposed schemes indeed introduce low overhead on computation and communication. Ning Cao 0001, Cong Wang 0001, Ming Li 0003, Kui Ren 0001, Wenjing Lou |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2014 | Verifiable Privacy-Preserving Multi-Keyword Text Search in the Cloud Supporting Similarity-Based RankingabstractWith the growing popularity of cloud computing, huge amount of documents are outsourced to the cloud for reduced management cost and ease of access. Although encryption helps protecting user data confidentiality, it leaves the well-functioning yet practically-efficient secure search functions over encrypted data a challenging problem. In this paper, we present a verifiable privacy-preserving multi-keyword text search (MTS) scheme with similarity-based ranking to address this problem. To support multi-keyword search and search result ranking, we propose to build the search index based on term frequency- and the vector space model with cosine similarity measure to achieve higher search result accuracy. To improve the search efficiency, we propose a tree-based index structure and various adaptive methods for multi-dimensional (MD) algorithm so that the practical search efficiency is much better than that of linear search. To further enhance the search privacy, we propose two secure index schemes to meet the stringent privacy requirements under strong threat models, i.e., known ciphertext model and known background model. In addition, we devise a scheme upon the proposed index tree structure to enable authenticity check over the returned search results. Finally, we demonstrate the effectiveness and efficiency of the proposed schemes through extensive experimental evaluation. Wenhai Sun, Bing Wang 0005, Ning Cao 0001, Ming Li 0003, Wenjing Lou, Y. Thomas Hou 0001, Hui Li 0006 |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2014 | SpecMonitor: Toward Efficient Passive Traffic Monitoring for Cognitive Radio NetworksabstractPassive monitoring by distributed wireless sniffers has been used to strategically capture the network traffic, as the basis of automatic network diagnosis. However, the traditional monitoring techniques fall short in cognitive radio networks (CRNs) due to the much larger number of channels to be monitored and the secondary users' channel availability uncertainty imposed by primary user activities. To better serve CRNs, we propose a systematic passive monitoring framework, i.e., SpecMonitor, for traffic collection using a limited number of sniffers in Wi-Fi-like CRNs. We jointly consider primary user activity and secondary user channel access pattern to optimize the traffic capturing strategy. In particular, we exploit a nonparametric density estimation method to learn and predict secondary users' access pattern in an online fashion, which rapidly adapts to the users' dynamic behaviors and supports accurate estimation of merged access patterns from multiple users. We also design near-optimal monitoring algorithms that maximize two levels of quality-of-monitoring goals based on the predicted channel access patterns. The simulations and experiments show that SpecMonitor outperforms the existing schemes significantly. Qiben Yan 0001, Ming Li 0003, Feng Chen 0001, Tingting Jiang 0005, Wenjing Lou, Y. Thomas Hou 0001, Chang-Tien Lu |
IEEE Trans. Wirel. Commun. | 2 |
| 2013 | Privacy-preserving multi-keyword text search in the cloud supporting similarity-based rankingabstractWith the increasing popularity of cloud computing, huge amount of documents are outsourced to the cloud for reduced management cost and ease of access. Although encryption helps protecting user data confidentiality, it leaves the well-functioning yet practically-efficient secure search functions over encrypted data a challenging problem. In this paper, we present a privacy-preserving multi-keyword text search (MTS) scheme with similarity-based ranking to address this problem. To support multi-keyword search and search result ranking, we propose to build the search index based on term frequency and the vector space model with cosine similarity measure to achieve higher search result accuracy. To improve the search efficiency, we propose a tree-based index structure and various adaption methods for multi-dimensional (MD) algorithm so that the practical search efficiency is much better than that of linear search. To further enhance the search privacy, we propose two secure index schemes to meet the stringent privacy requirements under strong threat models, i.e., known ciphertext model and known background model. Finally, we demonstrate the effectiveness and efficiency of the proposed schemes through extensive experimental evaluation. Wenhai Sun, Bing Wang 0005, Ning Cao 0001, Ming Li 0003, Wenjing Lou, Y. Thomas Hou 0001, Hui Li 0006 |
AsiaCCS | 4 |
| 2013 | Privacy-preserving public auditing for shared cloud data supporting group dynamicsabstractIn the cloud, data is often shared by a group of users. To ensure the long-term correctness of cloud shared data, a third-party public verifier can be introduced to audit data integrity. During the auditing, protecting the privacy of the contributors of shared data from the public auditor is a fundamental issue. However, this makes it challenging to simultaneously support group membership dynamics efficiently, due to the significant amount of computation needed to update the signatures on shared data. In this paper, we propose a novel privacy-preserving public auditing mechanism for shared cloud data. With our proposed mechanism, a public verifier is able to audit the integrity of shared data without retrieving the entire data from the cloud, and also without learning private identity information of the group members. Group dynamics (user join and user revocation) are efficiently handled by outsourcing signature updating operations to the cloud via a secure proxy re-signature scheme. Experimental results show that our mechanism is highly efficient for dynamic groups. Boyang Wang 0001, Hui Li 0006, Ming Li 0003 |
ICC | 3 |
| 2013 | Storing Shared Data on the Cloud via Security-MediatorabstractNowadays, many organizations outsource data storage to the cloud such that a member (owner) of an organization can easily share data with other members (users). Due to the existence of security concerns in the cloud, both owners and users are suggested to verify the integrity of cloud data with Provable Data Possession (PDP) before further utilization on data. However, previous methods either unnecessarily reveal the identity of a data owner to the untrusted cloud or any public verifiers, or introduce significant overheads on verification metadata to preserve anonymity. In this paper, we propose a simple and efficient publicly verifiable approach to ensure cloud data integrity without sacrificing the anonymity of data owners nor requiring significant verification metadata. Specifically, we introduce a security-mediator (SEM), which is able to generate verification metadata (i.e., signatures) on outsourced data for data owners. Our approach decouples the anonymity protection mechanism from the PDP. Thus, an organization can employ its own anonymous authentication mechanism, and the cloud is oblivious to that since it only deals with typical PDP-metadata, Consequently, there is no extra storage overhead when compared with existing non-anonymous PDP solutions. The distinctive features of our scheme also include data privacy, such that the SEM does not learn anything about the data to be uploaded to the cloud at all, which is able to minimize the requirement of trust on the SEM. In addition, we can also extend our scheme to work with the multi-SEM model, which can avoid the potential single point of failure existing in the single-SEM scenario. Security analyses prove our scheme is secure, and experiment results demonstrate our scheme is efficient. Boyang Wang 0001, Sherman S. M. Chow, Ming Li 0003, Hui Li 0006 |
ICDCS | 3 |
| 2013 | Non-parametric passive traffic monitoring in cognitive radio networksabstractPassive monitoring by distributed wireless sniffers has been used to strategically capture the network traffic, as the basis of automatic network diagnosis. However, the traditional monitoring techniques fall short in cognitive radio networks (CRNs) due to the much larger number of channels to be monitored, and the secondary users' channel availability uncertainty imposed by primary user activities. To better serve CRNs, we propose a systematic passive monitoring framework for traffic collection using a limited number of sniffers in WiFi like CRNs. We jointly consider primary user activity and secondary user channel access pattern to optimize the traffic capturing strategy. In particular, we exploit a non-parametric density estimation method to learn and predict secondary users' access pattern in an online fashion, which rapidly adapts to the users' dynamic behaviors and supports accurate estimation of merged access patterns from multiple users. We also design near-optimal monitoring algorithms that maximize two levels of quality-of-monitoring goals respectively, based on the predicted channel access patterns. The simulations and experiments show that our proposed framework outperforms the existing schemes significantly. Qiben Yan 0001, Ming Li 0003, Feng Chen 0001, Tingting Jiang 0005, Wenjing Lou, Y. Thomas Hou 0001, Chang-Tien Lu |
INFOCOM | 2 |
| 2013 | Surviving the RF smog: Making Body Area Networks robust to cross-technology interferenceabstractWireless Body Area Networks (BANs) demand for highly robust communication due to the criticality and time-sensitivity of the medical monitoring data. However, as BANs will be widely deployed in densely populated areas, they inevitably face the RF cross-technology interference (CTI) from non-protocol-compliant wireless devices operating in the same spectrum range, which are persistent, high power, and broadband in nature. The main challenges to defend such strong CTI come from the scarcity of spectrum resources, the uncertainty of the CTI sources and BAN channel status, and the stringent hardware constraints. Existing methods fail because of their need for extra spectrum resources or advanced hardware. In this paper, we first experimentally characterize the adverse effect on BAN reliability caused by the non-protocol-compliant CTI. Then we propose a CTI-aware joint routing and power control (JRPC) approach to ensure desired reliability goals using minimum energy resources even under strong co-channel CTI. To cope with channel uncertainty, we propose a passive link quality estimation method which exploits prediction. Through extensive experiments and simulations, we show that our proposed protocol can assure the robustness of BAN even when the CTI sources are in very close vicinity, using little overall energy and spectrum resources, and can be easily implemented on commercial-off-the-shelf (COTS) devices. Yantian Hou, Ming Li 0003, Shucheng Yu |
SECON | 2 |
| 2013 | Enforcing Spectrum Access Rules in Cognitive Radio Networks through Cooperative Jamming
Yantian Hou, Ming Li 0003 |
WASA | 2 |
| 2013 | Chorus: scalable in-band trust establishment for multiple constrained devices over the insecure wireless channelabstractSecure initial trust establishment for multiple resource constrained devices is a fundamental issue underlying wireless networks. A number of protocols have been proposed for secure key deployment among nodes without prior shared secrets (ad hoc), however so far most of them rely on secure out-of-band (OOB) channels (e.g., audio, visual) which either only work with a small number of devices or require auxiliary hardware. In this paper, for the first time, we design a solution that enables secure initialization of a group of wireless devices, which works merely within the wireless band. Our proposed solution is based on a novel physical-layer primitive for authenticated string comparison over the insecure wireless channel, called Chorus, which simultaneously compares the equality of fixed-length authentication strings held by multiple wireless devices within constant time. The Chorus achieves a key authentication property, which prevents an adversary from tricking each device to believe that all strings are equal when they are not, which is enabled by exploiting the infeasibility of signal cancellation and unidirectional error detection codes. Chorus can be employed as a foundation to provide in-band group message authentication (GMA) and group authenticated key agreement (GAKA), that does not require any prior shared secret. Specifically, we design two GAKA protocols based on Chorus and formally prove their security. The most appealing features of our proposed protocols include: minimal hardware requirement (a common radio interface and a button), minimal user effort (pressing a button on each device on average), nearly constant running time, thus they are scalable to a large group of constrained wireless devices. Through extensive analysis and experimental evaluation, we show the security and robustness of Chorus under a realistic attack model, and demonstrate the high scalability of our GAKA protocols. Yantian Hou, Ming Li 0003, Joshua D. Guttman |
WISEC | 2 |
| 2013 | ASK-BAN: authenticated secret key extraction utilizing channel characteristics for body area networksabstractRecently there has been an increasing interest on bootstrapping security for wireless networks merely using physical layer characteristics. In particular, the focus has been on two fundamental security issues - device authentication and secret key extraction. While most existing works emphasize on tackling the two issues separately, it remains an open problem to simultaneously achieve device authentication and fast secret key extraction merely using wireless physical layer characteristics, without the help of advanced hardware or out-of-band channel. Shucheng Yu, Ming Li 0003 |
WISEC | 4 |
| 2013 | BANA: Body Area Network Authentication Exploiting Channel CharacteristicsabstractIn wireless body area network (BAN), node authentication is essential for trustworthy and reliable gathering of patient's critical health information. Traditional authentication solutions depend on prior trust among nodes whose establishment would require either key pre-distribution or non-intuitive participation by inexperienced users. Most existing non-cryptographic authentication schemes require advanced hardware or significant modifications to the system software, which are impractical for BANs. In this paper, for the first time, we propose a lightweight body area network authentication scheme BANA. Different from previous work, BANA does not depend on prior-trust among nodes and can be efficiently realized on commercial off-the-shelf low-end sensors. We achieve this by exploiting a unique physical layer characteristic naturally arising from the multi-path environment surrounding a BAN, i.e., the distinct received signal strength (RSS) variation behaviors among on-body channels and between on-body and off-body communication channels. Based on distinct RSS variations, BANA adopts clustering analysis to differentiate the signals from an attacker and a legitimate node. We also make use of multi-hop on-body channel characteristics to enhance the robustness of our authentication mechanism. The effectiveness of BANA is validated through extensive real-world experiments under various scenarios. It is shown that BANA can accurately identify multiple attackers with minimal amount of overhead. Ming Li 0003, Shucheng Yu |
IEEE J. Sel. Areas Commun. | 2 |
| 2013 | Secure ad hoc trust initialization and key management in wireless body area networksabstractThe body area network (BAN) is a key enabling technology in e-healthcare. An important security issue is to establish initial trust relationships among the BAN devices before they are actually deployed and generate necessary shared secret keys to protect the subsequent wireless communications. Due to the ad hoc nature of the BAN and the extreme resource constraints of sensor devices, providing secure as well as efficient and user-friendly trust initialization is a challenging task. Traditional solutions for wireless sensor networks mostly depend on key predistribution, which is unsuitable for a BAN in many ways. In this article, we propose group device pairing (GDP), a user-aided multi-party authenticated key agreement protocol. Through GDP, a group of sensor devices that have no pre-shared secrets establish initial trust by generating various shared secret keys out of an unauthenticated channel. Devices authenticate themselves to each other with the aid of a human user who performs visual verifications. The GDP supports fast batch deployment, addition and revocation of sensor devices, does not rely on any additional hardware device, and is mostly based on symmetric key cryptography. We formally prove the security of the proposed protocols, and we implement GDP on a sensor network testbed and report performance evaluation results. Ming Li 0003, Shucheng Yu, Joshua D. Guttman, Wenjing Lou, Kui Ren 0001 |
ACM Trans. Sens. Networks | 1 |
| 2013 | Scalable and Secure Sharing of Personal Health Records in Cloud Computing Using Attribute-Based EncryptionabstractPersonal health record (PHR) is an emerging patient-centric model of health information exchange, which is often outsourced to be stored at a third party, such as cloud providers. However, there have been wide privacy concerns as personal health information could be exposed to those third party servers and to unauthorized parties. To assure the patients' control over access to their own PHRs, it is a promising method to encrypt the PHRs before outsourcing. Yet, issues such as risks of privacy exposure, scalability in key management, flexible access, and efficient user revocation, have remained the most important challenges toward achieving fine-grained, cryptographically enforced data access control. In this paper, we propose a novel patient-centric framework and a suite of mechanisms for data access control to PHRs stored in semitrusted servers. To achieve fine-grained and scalable data access control for PHRs, we leverage attribute-based encryption (ABE) techniques to encrypt each patient's PHR file. Different from previous works in secure data outsourcing, we focus on the multiple data owner scenario, and divide the users in the PHR system into multiple security domains that greatly reduces the key management complexity for owners and users. A high degree of patient privacy is guaranteed simultaneously by exploiting multiauthority ABE. Our scheme also enables dynamic modification of access policies or file attributes, supports efficient on-demand user/attribute revocation and break-glass access under emergency scenarios. Extensive analytical and experimental results are presented which show the security, scalability, and efficiency of our proposed scheme. Ming Li 0003, Shucheng Yu, Yao Zheng 0004, Kui Ren 0001, Wenjing Lou |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2013 | Privacy-Preserving Distributed Profile Matching in Proximity-Based Mobile Social NetworksabstractMaking new connections according to personal preferences is a crucial service in mobile social networking, where an initiating user can find matching users within physical proximity of him/her. In existing systems for such services, usually all the users directly publish their complete profiles for others to search. However, in many applications, the users' personal profiles may contain sensitive information that they do not want to make public. In this paper, we propose FindU, a set of privacy-preserving profile matching schemes for proximity-based mobile social networks. In FindU, an initiating user can find from a group of users the one whose profile best matches with his/her; to limit the risk of privacy exposure, only necessary and minimal information about the private attributes of the participating users is exchanged. Two increasing levels of user privacy are defined, with decreasing amounts of revealed profile information. Leveraging secure multi-party computation (SMC) techniques, we propose novel protocols that realize each of the user privacy levels, which can also be personalized by the users. We provide formal security proofs and performance evaluation on our schemes, and show their advantages in both security and efficiency over state-of-the-art schemes. Ming Li 0003, Shucheng Yu, Ning Cao 0001, Wenjing Lou |
IEEE Trans. Wirel. Commun. | 1 |
| 2012 | Authenticated secret key extraction using channel characteristics for body area networksabstractSimultaneously realizing device authentication and fast secret key extraction is a challenging issue in wireless networks. Most existing works solve this problem by utilizing either advanced hardware or out-of-band channel, which is not always available for commercial-off-the-shelf wireless devices. In this work, we solve this challenging issue under the setting of Wireless Body Area Network (BAN) and propose a lightweight authenticated secret key extraction scheme, namely ASK-BAN. The proposed scheme is just based on wireless channel measurement and does not introduce any advanced hardware or rely on any out-of-band channel. Experimental results show that our proposed scheme can offer a high secret key extraction rate while providing effective device authentication simultaneously. Shucheng Yu, Ming Li 0003 |
CCS | 4 |
| 2012 | SHARP: Private Proximity Test and Secure Handshake with Cheat-Proof Location Tags
Yao Zheng 0004, Ming Li 0003, Wenjing Lou, Y. Thomas Hou 0001 |
ESORICS | 2 |
| 2012 | Vulnerability and protection for distributed consensus-based spectrum sensing in cognitive radio networksabstractCooperative spectrum sensing is key to the success of cognitive radio networks. Recently, fully distributed cooperative spectrum sensing has been proposed for its high performance benefits particularly in cognitive radio ad hoc networks. However, the cooperative and fully distributed natures of such protocol make it highly vulnerable to malicious attacks, and make the defense very difficult. In this paper, we analyze the vulnerabilities of distributed sensing architecture based on a representative distributed consensus-based spectrum sensing algorithm. We find that such distributed algorithm is particularly vulnerable to a novel form of attack called covert adaptive data injection attack. The vulnerabilities are even magnified under multiple colluding attackers. We further propose effective protection mechanisms, which include a robust distributed outlier detection scheme with adaptive local threshold to thwart the covert adaptive data injection attack, and a hash-based computation verification approach to cope with collusion attacks. Through simulation and analysis, we demonstrate the destructive power of the attacks, and validate the efficacy and efficiency of our proposed protection mechanisms. Qiben Yan 0001, Ming Li 0003, Tingting Jiang 0005, Wenjing Lou, Y. Thomas Hou 0001 |
INFOCOM | 2 |
| 2012 | BANA: body area network authentication exploiting channel characteristicsabstractWireless body area network (BAN) is a promising technology for real-time monitoring of physiological signals to support medical applications. In order to ensure the trustworthy and reliable gathering of patient's critical health information, it is essential to provide node authentication service in a BAN, which prevents an attacker from impersonation and false data/command injection. Although quite fundamental, the authentication in BAN still remains a challenging issue. On one hand, traditional authentication solutions depend on prior trust among nodes whose establishment would require either key pre-distribution or non-intuitive participation by inexperienced users, while they are vulnerable to key compromise. On the other hand, most existing non-cryptographic authentication schemes require advanced hardware capabilities or significant modifications to the system software, which are impractical for BANs. Ming Li 0003, Shucheng Yu |
WISEC | 2 |
| 2012 | Throughput Analysis of Cooperative Mobile Content Distribution in Vehicular Network using Symbol Level Network CodingabstractThis paper presents a theoretical study of the throughput of mobile content distribution (MCD) in vehicular ad hoc networks (VANETs). Since VANET is well-known for its fast-changing topology and adverse wireless channel environments, various protocols have been proposed in the literature to enhance the performance of MCD in a vehicular environment, using packet-level network coding (PLNC) and symbol-level network coding (SLNC). However, there still lacks a fundamental understanding of the limits of MCD protocols using network coding in VANETs. In this paper, we develop a theoretical model to compute the achievable throughput of cooperative MCD in VANETs using SLNC. By considering a one-dimensional road topology with an access point (AP) as the content source, the expected achievable throughput for a vehicle at a certain distance from the AP is derived, for both using PLNC and SLNC. Our proposed model is unique since it captures the effects of multiple practical factors, including vehicle distribution and mobility pattern, channel fading and packet collisions. Through numerical results, we provide insights on optimized design choices for network coding-based cooperative MCD systems in VANETs. Qiben Yan 0001, Ming Li 0003, Zhenyu Yang 0007, Wenjing Lou, Hongqiang Zhai |
IEEE J. Sel. Areas Commun. | 2 |
| 2012 | CodePlay: Live Multimedia Streaming in VANETs Using Symbol-Level Network CodingabstractThe fundamental challenges of providing live multimedia streaming (LMS) services in vehicular ad hoc networks (VANETs) come from achieving stable and high streaming rate (smooth playback) for all the interested vehicles while using minimal bandwidth resources, especially under the highly dynamic topology of VANETs and the lossy nature of vehicular wireless communications. Packet level network coding (PLNC) technique has been widely accepted as an effective approach to improve the network performance during the last decade. More recent symbol-level network coding (SLNC) could further improve the efficiency of bandwidth utilization by exploiting both wireless symbol-level diversity and the benefits of network coding. In this paper, we introduce CodePlay, a new LMS scheme in VANETs that fully takes advantage of SLNC through a coordinated local push mechanism. Streaming contents are actively disseminated from dedicated sources to interested vehicles via local coordination of distributively selected relays, each of which will ensure smooth playback for vehicles nearby. Extensive simulations show that simply replacing the SLNC with PLNC technique in previous LMS schemes can not provide satisfiable user experience, and special scheme design based on the unique characteristics of SLNC proposed in CodePlay is necessary for future LMS applications in VANET. Zhenyu Yang 0007, Ming Li 0003, Wenjing Lou |
IEEE Trans. Wirel. Commun. | 2 |
| 2011 | Distributed Data Mining with Differential PrivacyabstractWith recent advances in communication and data storage technology, an explosive amount of information is being collected and stored in the Internet. Even though such vast amount of information presents great opportunities for knowledge discovery, organizations might not want to share their data due to legal or competitive reasons. This posts the challenge of mining knowledge while preserving privacy. Current efficient privacy-preserving data mining algorithms are based on an assumption that it is acceptable to release all the intermediate results during the data mining operations. However, it has been shown that such intermediate results can still leak private information. In this work, we use differential privacy to quantitatively limit such information leak. Differential privacy is a newly emerged privacy definition that is capable of providing strong measurable privacy guarantees. We propose Secure group Differential private Query (SDQ), a new algorithm that combines techniques from differential privacy and secure multiparty computation. Using decision tree induction as a case study, we show that SDQ can achieve stronger privacy than current efficient secure multiparty computation approach, and better accuracy than current differential privacy approach while maintaining efficiency. Ning Zhang 0017, Ming Li 0003, Wenjing Lou |
ICC | 2 |
| 2011 | Authorized Private Keyword Search over Encrypted Data in Cloud ComputingabstractIn cloud computing, clients usually outsource their data to the cloud storage servers to reduce the management costs. While those data may contain sensitive personal information, the cloud servers cannot be fully trusted in protecting them. Encryption is a promising way to protect the confidentiality of the outsourced data, but it also introduces much difficulty to performing effective searches over encrypted information. Most existing works do not support efficient searches with complex query conditions, and care needs to be taken when using them because of the potential privacy leakages about the data owners to the data users or the cloud server. In this paper, using on line Personal Health Record (PHR) as a case study, we first show the necessity of search capability authorization that reduces the privacy exposure resulting from the search results, and establish a scalable framework for Authorized Private Keyword Search (APKS) over encrypted cloud data. We then propose two novel solutions for APKS based on a recent cryptographic primitive, Hierarchical Predicate Encryption (HPE). Our solutions enable efficient multi-dimensional keyword searches with range query, allow delegation and revocation of search capabilities. Moreover, we enhance the query privacy which hides users' query keywords against the server. We implement our scheme on a modern workstation, and experimental results demonstrate its suitability for practical usage. Ming Li 0003, Shucheng Yu, Ning Cao 0001, Wenjing Lou |
ICDCS | 1 |
| 2011 | Privacy-preserving multi-keyword ranked search over encrypted cloud dataabstractWith the advent of cloud computing, data owners are motivated to outsource their complex data management systems from local sites to the commercial public cloud for great flexibility and economic savings. But for protecting data privacy, sensitive data has to be encrypted before outsourcing, which obsoletes traditional data utilization based on plaintext keyword search. Thus, enabling an encrypted cloud data search service is of paramount importance. Considering the large number of data users and documents in the cloud, it is necessary to allow multiple keywords in the search request and return documents in the order of their relevance to these keywords. Related works on searchable encryption focus on single keyword search or Boolean keyword search, and rarely sort the search results. In this paper, for the first time, we define and solve the challenging problem of privacy-preserving multi-keyword ranked search over encrypted cloud data (MRSE). We establish a set of strict privacy requirements for such a secure cloud data utilization system. Among various multi-keyword semantics, we choose the efficient similarity measure of “coordinate matching”, i.e., as many matches as possible, to capture the relevance of data documents to the search query. We further use “inner product similarity” to quantitatively evaluate such similarity measure. We first propose a basic idea for the MRSE based on secure inner product computation, and then give two significantly improved MRSE schemes to achieve various stringent privacy requirements in two different threat models. Thorough analysis investigating privacy and efficiency guarantees of proposed schemes is given. Experiments on the real-world dataset further show proposed schemes indeed introduce low overhead on computation and communication. Ning Cao 0001, Cong Wang 0001, Ming Li 0003, Kui Ren 0001, Wenjing Lou |
INFOCOM | 3 |
| 2011 | FindU: Privacy-preserving personal profile matching in mobile social networksabstractMaking new connections according to personal preferences is a crucial service in mobile social networking, where the initiating user can find matching users within physical proximity of him/her. In existing systems for such services, usually all the users directly publish their complete profiles for others to search. However, in many applications, the users' personal profiles may contain sensitive information that they do not want to make public. In this paper, we propose FindU, the first privacy-preserving personal profile matching schemes for mobile social networks. In FindU, an initiating user can find from a group of users the one whose profile best matches with his/her; to limit the risk of privacy exposure, only necessary and minimal information about the private attributes of the participating users is exchanged. Several increasing levels of user privacy are defined, with decreasing amounts of exchanged profile information. Leveraging secure multi-party computation (SMC) techniques, we propose novel protocols that realize two of the user privacy levels, which can also be personalized by the users. We provide thorough security analysis and performance evaluation on our schemes, and show their advantages in both security and efficiency over state-of-the-art schemes. Ming Li 0003, Ning Cao 0001, Shucheng Yu, Wenjing Lou |
INFOCOM | 1 |
| 2011 | R-Code: Network coding-based reliable broadcast in wireless mesh networks
Zhenyu Yang 0007, Ming Li 0003, Wenjing Lou |
Ad Hoc Networks | 2 |
| 2011 | Opportunistic broadcast of event-driven warning messages in Vehicular Ad Hoc Networks with lossy links
Ming Li 0003, Kai Zeng 0001, Wenjing Lou |
Comput. Networks | 1 |
| 2011 | CodeOn: Cooperative Popular Content Distribution for Vehicular Networks using Symbol Level Network CodingabstractDriven by both safety concerns and commercial interests, one of the key services offered by vehicular networks is popular content distribution (PCD). The fundamental challenges to achieve high speed content downloading come from the highly dynamic topology of vehicular ad hoc network (VANET) and the lossy nature of the vehicular wireless communications. In this paper, we introduce CodeOn, a novel push-based PCD scheme where contents are actively broadcasted to vehicles from road side access points and further distributed among vehicles using a cooperative VANET. In CodeOn, we employ a recent technique, symbol level network coding (SLNC) to combat the lossy wireless transmissions. Through exploiting symbol level diversity, SLNC is robust to transmission errors and encourages more aggressive concurrent transmissions. In order to fully enjoy the benefits of SLNC, we propose a suite of techniques to maximize the downloading rate, including a prioritized and localized relay selection mechanism where the selection criteria is based on the usefulness of vehicles' possessed contents, and a lightweight medium access protocol that naturally exploits the abundant concurrent transmission opportunities. We also propose additional mechanisms to reduce the protocol overhead without sacrificing the performance. Extensive simulation results show that, under a wide range of scenarios, CodeOn significantly outperforms a state-of-the-art PCD scheme based on network coding. Ming Li 0003, Zhenyu Yang 0007, Wenjing Lou |
IEEE J. Sel. Areas Commun. | 1 |
| 2010 | CodePlay: Live multimedia streaming in VANETs using symbol-level network codingabstractLive multimedia streaming (LMS) services are important in vehicular ad hoc networks (VANETs) for their capability of providing comprehensive and user-friendly information. The fundamental challenges come from achieving stable and high streaming rate (smooth playback) for all the interested vehicles while using minimal bandwidth resources, especially under the highly dynamic topology of VANETs and the lossy nature of vehicular wireless communications. A recent technique, symbol-level network coding (SLNC), has been shown to be an effective approach to improve the efficiency of bandwidth utilization, by exploiting both wireless symbol-level diversity and the benefits of network coding. In this paper, we introduce CodePlay, a new LMS scheme in VANETs that fully takes advantage of SLNC through a coordinated local push mechanism. Streaming contents are actively disseminated from dedicated sources to interested vehicles via local coordination of distributively selected relays, each of which will ensure smooth playback for vehicles nearby. CodePlay is designed to simultaneously improve the performance of LMS service in terms of streaming rate, service delivery delay and bandwidth efficiency. We use extensive simulations to show that CodePlay is potentially suitable for future LMS applications in VANET. Zhenyu Yang 0007, Ming Li 0003, Wenjing Lou |
ICNP | 2 |
| 2010 | Group Device Pairing based Secure Sensor Association and Key Management for Body Area NetworksabstractBody Area Networks (BAN) is a key enabling technology in E-healthcare such as remote health monitoring. An important security issue during bootstrap phase of the BAN is to securely associate a group of sensor nodes to a patient, and generate necessary secret keys to protect the subsequent wireless communications. Due to the the ad hoc nature of the BAN and the extreme resource constraints of sensor devices, providing secure, fast, efficient and user-friendly secure sensor association is a challenging task. In this paper, we propose a lightweight scheme for secure sensor association and key management in BAN. A group of sensor nodes, having no prior shared secrets before they meet, establish initial trust through group device pairing (GDP), which is an authenticated group key agreement protocol where the legitimacy of each member node can be visually verified by a human. Various kinds of secret keys can be generated on demand after deployment. The GDP supports batch deployment of sensor nodes to save setup time, does not rely on any additional hardware devices, and is mostly based on symmetric key cryptography, while allowing batch node addition and revocation. We implemented GDP on a sensor network testbed and evaluated its performance. Experimental results show that that GDP indeed achieves the expected design goals. Ming Li 0003, Shucheng Yu, Wenjing Lou, Kui Ren 0001 |
INFOCOM | 1 |
| 2010 | Securing Personal Health Records in Cloud Computing: Patient-Centric and Fine-Grained Data Access Control in Multi-owner Settings
Ming Li 0003, Shucheng Yu, Kui Ren 0001, Wenjing Lou |
SecureComm | 1 |
| 2009 | R-Code: Network Coding Based Reliable Broadcast in Wireless Mesh Networks with Unreliable LinksabstractBroadcast is an important primitive in wireless mesh networks (WMNs). Applications like network-wide software update require reliable reception of the content with low-latency and high scalability (i.e., utilizing little bandwidth resource). In reality, the link layer broadcast transmission in WMNs is unreliable, which makes these goals hard to be attained at the same time. In this paper, we consider one-to-all broadcast scenarios and put forward R-Code, a reliable and efficient broadcast protocol based on intra-flow network coding. The key idea is to construct a minimum spanning tree as a backbone whose link weight is the expected number of transmissions on that link. The broadcast overhead and delay are simultaneously reduced by enabling the non-leaf nodes in the tree to move to the next batch of file segments as early as possible, while ensuring their downstream nodes reliably receive and correctly decode all the packets in the current batch. Opportunistic overhearing is utilized to further reduce the number of transmissions. Extensive simulation results show that our scheme always achieves 100% packet delivery ratio (PDR), while enjoying less broadcast overhead and much shorter delay than AdapCode, 14% and 50%, respectively. Zhenyu Yang 0007, Ming Li 0003, Wenjing Lou |
GLOBECOM | 2 |
| 2009 | OppCast: Opportunistic Broadcast of Warning Messages in VANETs with Unreliable LinksabstractMulti-hop broadcast is a key technique to disseminate important information such as time-sensitive safety warning messages (WMs) in Vehicular Ad hoc Networks (VANETs). Due to the fact that the implementation of broadcast at the link layer uses unreliable transmissions (i.e., lack of positive ACKs), highly reliable, scalable, and fast multi-hop broadcast protocol is particularly difficult to design in VANETs with unreliable links. Schemes that use redundant network layer broadcasts have been proposed. However, the balance between receiving reliability and transmission count in such schemes needs to be carefully considered. In this paper, we propose the opportunistic broadcast protocol (OppCast) that aims at minimizing the number of transmissions while achieving high network packet reception ratio (PRR) and fast multi-hop message propagation simultaneously. A double-phase broadcast strategy is proposed to achieve fast message propagation in one phase and to ensure high PRR in the other. The idea of opportunistic forwarding is exploited at each hop to minimize the propagation latency. An opportunistic forwarding protocol is designed accordingly as a MAC-layer broadcast coordination function, that allows multiple nodes to agree on the actual relay nodes in a distributed fashion. The proposed function also alleviates the hidden terminal problem. Theoretical analysis is carried out to optimize and design both broadcast phases. Extensive simulation results show that, compared with existing competing protocols, OppCast achieves close to 100% PRR and fast dissemination rate under a wide range of vehicle densities, while using significantly smaller number of transmissions. Ming Li 0003, Wenjing Lou, Kai Zeng 0001 |
MASS | 1 |
| 2009 | A Network Coding Approach to Reliable Broadcast in Wireless Mesh Networks
Zhenyu Yang 0007, Ming Li 0003, Wenjing Lou |
WASA | 2 |
| 2008 | Opportunistic broadcast of emergency messages in vehicular ad hoc networks with unreliable linksabstractMulti-hop broadcast is an important means to disseminate safety information like time-sensitive emergency messages (EMs) in Vehicular Ad hoc Networks (VANETs). Providing low-latency, high-coverage and scalable multi-hop EM broadcast is a hard task in VANET with unreliable links. The major challenge Ming Li 0003, Wenjing Lou |
QSHINE | 1 |