
In the future 6G communication era, the demand for spectrum resources will reach unprecedented heights, making dynamic spectrum allocation extremely crucial. Existing dynamic spectrum sharing technologies rely on secondary users querying databases for feedback. However, malicious secondary users can infer the location of primary users through multiple queries and use Bayesian theory to update probability, posing privacy and security threats. To address this, we propose a Blockchain-based anti-Malicious Queries (BMQ)scheme. This scheme combines Dynamic Spectrum Sharing (DSS) with blockchain technology, leveraging its decentralized, tamper-proof, and secure nature to protect privacy. The BMQ scheme ensures unaffected spectrum information queries while constructing a distributed sharing environment. Additionally, we designed a consensus mechanism to detect and prevent malicious queries by determining the legality of user behavior. This mechanism addresses Bayesian-based location inference attacks, enhancing the integration of blockchain and DSS. Privacy analysis and experimental evaluation demonstrate the scheme’s effectiveness and performance advantages.
The operating system kernel, as the core component of modern software systems, plays a pivotal role in ensuring the overall security and reliability of the system. Fuzzing, an efficient vulnerability detection method, has been widely applied in the field of kernel security. The extensive use of kernel fuzzing has significantly enhanced the kernel’s resilience against attacks. This paper presents a comprehensive and systematic review of recent research in the field of kernel fuzzing. It begins by exploring the unique characteristics and potential hazards of kernel vulnerabilities, emphasizing the critical role of fuzzing in detecting these vulnerabilities. The paper then provides a detailed examination of the fundamental concepts, technical architecture, and operational workflows of kernel fuzzing systems. It surveys existing kernel fuzzing methods, highlights the evolution and technological advancements in the field, and proposes a novel taxonomy of current approaches. Finally, the review summarizes the practical achievements of kernel fuzzing and explores promising future research directions. This survey offers a structured reference framework for researchers in the field and serves as a valuable resource for advancing kernel security testing technologies.
Cloud storage has emerged as a prevalent service model for data sharing in the big data era, yet it faces significant integrity threats. While data integrity auditing has been proposed to address this challenge, existing solutions suffer from either heavy certificate overheads or single-point-of-failure risks in single Key Generation Center (KGC) architectures. To overcome these limitations, we propose a multi-KGC certificateless anonymous cloud sharing scheme with threshold-based traceability. Our scheme employs the certificateless signature with multiple KGCs to eliminate certificate overhead while resisting key escrow issues. By incorporating a group-based multisignature mechanism, we prevent attackers from distinguishing actual signers among sharing participants. Furthermore, we develop an anonymous protection and authentication approach where users generate temporary identities by XORing real IDs with secret parameters distributed via Shamir’s secret sharing, enabling threshold-based identity recovery. Cloud servers verify anonymous identifiers to prevent unauthorized access. Notably, the scheme implements threshold-based traceability: a coalition of t KGCs (n KGCs in total) can collaboratively reconstruct secret parameters to reveal a user’s real identity. Theoretical analysis demonstrates the proposal’s correctness and security. Experimental evaluations confirm its practical efficiency.
Credit risk prediction is a crucial component of modern financial analytics. With the widespread use of neural networks and cloud computing, the data owner can obtain the result of credit risk prediction through a neural network model deployed in the cloud. This approach enhances the efficiency and accuracy of credit risk assessment. However, without additional security measures, adversaries may gain access to private data and model parameters. This paper presents a verifiable and privacy-preserving credit prediction model designed to protect both the data owner’s data and the model parameters in credit risk prediction. The scheme employs a functional encryption mechanism to protect the data owner’s data and also ensures model parameters’ privacy by adding fake neurons to two non-colluding cloud servers. We employ the checksum mechanism to ensure the verifiability of the neural network computations. The experimental results demonstrate that the proposed scheme achieves a secure credit risk assessment accuracy of approximately 90
The management of case-involved property is a crucial component of the judicial, prosecutorial, and public security sectors. Ensuring the security, transparency, and compliance of property management is of paramount importance. However, traditional management systems face issues such as data tampering, information leakage, and inflexible access control. Blockchain technology, with its decentralized, tamper-proof, and transparent characteristics, offers an innovative solution to address these problems. This paper analyzes the current status and challenges of traditional case-involved property management, examines the issues associated with blockchain-based property management, and summarizes the features of current access control technologies. Based on attributes and roles, a dual-layer access control model combining internal and external mechanisms is proposed, aiming to enhance the flexibility and accuracy of access control while strengthening privacy protection. This access control mechanism can effectively prevent unauthorized access, ensure data privacy, and improve the transparency and traceability of the system. Additionally, this paper explores the integration of privacy protection technologies and access control mechanisms, as well as the potential for cross-departmental collaboration and information sharing, and anticipates the prospects of future technological optimizations. The research provides theoretical support and technical references for the application of blockchain in case-involved property management, with significant practical implications.
With the rapid development of Optical Networks, ensuring their security against sophisticated cyber attacks has become increasingly challenging. In this paper, we propose a novel path graph-based framework for attack-induced fault diagnosis by modeling system logs as a path graph, where nodes represent individual log entries and edges capture sequential and contextual relationships between adjacent logs. This modeling approach effectively encodes temporal dependencies while avoiding the high computational complexity associated with Transformer-based models. To further enhance fault detection accuracy and interpretability, we design a custom graph neural network (GNN) architecture that leverages both local and global structural information within the path graph to identify anomalies indicative of malicious activities. Experimental results demonstrate that the proposed framework provides a scalable and effective solution for real-time security assessment in Optical Networks, enabling early diagnosis of attack-induced faults with reduced computational overhead.
The increasing prevalence of Artificial Intelligence (AI) generated content, particularly deepfake videos, has raised serious concerns in academia and society. This study explores the use of Head Pose Estimation (HPE) as a discriminative feature for deepfake detection, using a distance-based classification approach via K-Nearest Neighbours (KNN) combined with Dynamic Time Warping (DTW). Three HPE methods - Feature Selective Attention Network (FSA-Net), SynergyNet and Web-Shaped Model (WSM) - were tested on three widely used public datasets: WildDeepfake, Celeb-DF and DeeperForensics-1.0. The results show that the WSM method offers superior performance compared to the other approaches, showing a good balance between the Real and Fake classes, particularly on complex datasets such as DeeperForensics-1.0, demonstrating its stability compared to previous results in literature on this method. The results obtained open up various perspectives and future directions for tackling the problem of deepfake detection by exploiting HPE-based approaches, which are notable for their speed and high reliability.
With the rapid development of cross-chain technology in recent years, the problems of asset interoperability, data sharing and ecosystem interconnection between different blockchains have been solved. However, it still faces challenges in terms of privacy protection. This study begins by addressing the challenges of privacy protection in cross-chain systems. It first introduces the mainstream cross-chain technologies and their typical application scenarios, followed by a comparative analysis. Next, it presents the main technologies for cross-chain privacy protection and lists representative application projects that utilize different privacy protection methods. Based on this, a cross-chain privacy protection scheme CP-ABZP combining Ciphertext-Policy Attribute-Based Encryption (CP-ABE) and zero-knowledge proof (ZKP) is proposed. Finally, the challenges faced by cross-chain privacy protection technologies and their potential future development directions are discussed.
The rapid advancement of generative models, particularly Generative Adversarial Networks (GANs) and Diffusion Models (DMs), has enabled the creation of highly realistic synthetic images that are increasingly difficult to distinguish from authentic ones. This progress presents significant challenges for digital content authentication. Furthermore, deepfake technologies are being actively exploited in cybersecurity attacks, introducing serious risks to information security. The use of hyper-realistic synthetic media in social engineering dramatically enhances the effectiveness of attacks such as identity theft and ransomware. Existing Deep Learning (DL)-based detectors often struggle to generalize to previously unseen generative techniques. To overcome this limitation, we propose a novel detection framework based on Siamese Neural Networks (SNNs), which focus on learning the similarity between image pairs rather than relying on fixed class boundaries. The proposed architecture is coupled with an incremental training strategy, where generators that yield the lowest detection performance are progressively incorporated into the training process. This enables the model to adapt more effectively to a diverse and evolving range of synthetic content. Experimental results show that strong generalization can be achieved using training data from as few as two generators, demonstrating the efficiency and scalability of the proposed approach. However, it is also observed that increasing the number of generators beyond a certain point does not lead to further improvements in performance. This indicates potential limitations in the current SNN training process. Future research will focus on refining training strategies to further improve generalization capabilities.
The double ratchet algorithm, widely used in secure messaging systems like Signal and WhatsApp, ensures forward secrecy and robust key management. This paper proposes two enhancements to strengthen its security and efficiency. First, pre-shared keys (PSKs) are introduced during initialization to improve entropy and defend against active attacks such as state injection and desynchronization. Second, a comparative analysis of SHA-256, BLAKE2s, and BLAKE3 is conducted to evaluate their performance as key derivation functions (KDFs) within the algorithm. Results show that BLAKE3 achieves a strong balance between speed and security. The improved design reduces computational overhead and enhances resilience, making it suitable for resource-limited and latency-sensitive applications.
Deep learning frameworks, as core infrastructure for building artificial intelligence systems, directly impact model reliability through their security. Existing model-level fuzzing approaches exhibit limitations in detecting framework vulnerabilities: model mutation operators lack multi-dimensional design for layer structures, and mutation scheduling strategies fail to effectively utilize code coverage feedback. To address these challenges, this paper proposes a novel model-level fuzzing method named MGtest. First, we design multi-granularity model mutation techniques that generate diverse test cases. By modifying convolutional layer parameters, deep logical errors in frameworks are triggered. Second, we propose a dynamic coverage-guided mutation scheduling algorithm that employs dynamic instrumentation to collect real-time Python code coverage, optimizing seed energy allocation and mutation operator priorities to enhance testing efficiency. Experiments on TensorFlow and PyTorch frameworks validate the method’s effectiveness using 12 classical models. Results demonstrate that MGtest improves code coverage by 26.5
With the increasing demands for privacy preserving of speech in cloud storage, the complex features along with the high overhead of speech computation and storage challenge the search mechanism. Therefore, we proposed a secure multi-user encrypted speech search scheme in cloud-edge-end environments (MUSES). Firstly, the MUSES scheme extracts speech feature vectors through CNN and RNN, employing secure proximity algorithms to obtain high similarity query results. Secondly, for the demands of multi-user scenarios, the MUSES scheme designs a trapdoor generation mechanism that generates specific trapdoors for each user, preserving the privacy of users. Finally, the proxy re-encryption (PRE) technology is utilized to transmit the symmetric key in the way that the edge server cannot recognize, mitigating the risk of data leakage. The analysis of the scheme proves that the MUSES scheme has high efficiency and does not cause privacy leakage in the speech search process. Meanwhile, the performance analysis also indicates the efficient and accurate search characteristics of the MUSES scheme.
This paper proposes a novel collaborative physical layer authentication scheme designed for vehicular ad-hoc networks (VANETs) based on Dempster-Shafer (D-S) evidence theory. Our method enhances the authentication robustness against complex attacks and changing channel conditions. We do this by including a detailed channel model that considers multipath fading and dynamic Doppler shifts, along with a simulated intelligent attack strategy. Each cooperating vehicle extracts channel state information (CSI) features and generates basic probability assignments (BPAs) using a lightweight convolutional neural network (CNN). These BPAs, which indicate the legitimacy or illegitimacy of a transmitting vehicle, are then combined using a modified D-S combination rule with reliability weighting and conflict resolution. Our extensive simulations evaluated the scheme’s performance. The results show its better authentication performance (especially in Equal Error Rate and Area Under Curve) compared to traditional machine learning methods like K-Nearest Neighbors (KNN) and Naive Bayes, and also a standalone CNN. These simulations show how effective our enhanced D-S evidence scheme is at combining uncertain or even conflicting information from multiple cooperators. This leads to more reliable authentication decisions in complex vehicular environments.
Protecting data privacy in the context of big data has become a pressing issue in machine learning. Traditional data protection techniques often struggle to ensure user privacy while maintaining learning efficiency and model accuracy. Differential privacy offers a mathematically provable method for privacy protection, effectively reducing the influence of individual data points on model training and preventing data leakage and other security risks. However, in large-scale learning scenarios, differential privacy faces challenges such as high computational costs and performance degradation due to gradient noise. This project conducts an in-depth analysis of privacy protection requirements in big data environments and identifies the limitations of existing differential privacy techniques. Based on this analysis, the project investigates differential privacy training methods tailored for big data applications. Specifically, it integrates techniques such as gradient clipping optimization, dynamic privacy budget allocation, and efficient noise addition to enhance privacy during training while minimizing performance loss. Experimental results demonstrate that the proposed approach can effectively improve learning efficiency and prediction accuracy in large-scale models, while ensuring user privacy. The findings of this research provide a novel approach to privacy protection in big data environments and offer technical support for its practical implementation.
The wide application of pop-ups in various video platforms has made the study of their sentiment analysis gradually become a hot topic. This study compares the performance of three machine learning methods, namely Support Vector Machine (SVM), Decision Tree (DT), and Naive Bayes (NB), in pop-up sentiment analysis. The captured and preprocessed pop-up data are used to extract features using methods like TF—IDF, and then the above three models are trained separately. The experimental results show that the DT model is better than SVM and NB in pop-up sentiment classification, with an accuracy of 93.5
As demand for data privacy and secure communication grows in areas like the Internet of Things, healthcare, and smart city infrastructure. A reliable way to achieve these requirements is key agreement. Current key agreement protocols often struggle to handle the wide gap in computing power between terminal devices and servers. To tackle this issue, this paper proposes a novel Asymmetric Three-Party Key Agreement Protocol Based on Secure Multiparty Computation. By merging the Diffie-Hellman key exchange mechanism with the complexity of Subset Product Problem (NP-complete), the scheme strategically offloads heavy computation to high-performance nodes, while terminals with limited resources only carry out necessary lightweight operations. This approach significantly reduces the overall computational and communication load without compromising security in the key negotiation process. Meanwhile, the design incorporates a trusted third party (TTP) solely for assisting in key generation and final result computation, enhancing anonymity and privacy protection without revealing any party’s data sources.
The rapid growth of Internet of Things (IoT)-generated data poses significant challenges in storage efficiency and integrity verification, particularly for resource-constrained devices. Existing cloud deduplication and auditing schemes incur excessive bandwidth and computational overhead, while failing to ensure privacy and delegability in IoT environments. To address these limitations, we propose a privacy-preserving delegable auditing scheme with edge-assisted deduplication, enabling IoT devices to offload computationally intensive tasks such as authenticator generation and audit interactions to fog nodes via securely negotiated delegable keys. Our approach integrates Message-Locked Encryption for data privacy and homomorphic hash-based block tags that simultaneously serve as deduplication identifiers and integrity proofs, eliminating redundant storage and communication. Unlike conventional cloud-based deduplication, our edge deduplication strategy filters out redundant data before upload, significantly reducing bandwidth consumption. To ensure accountability, we leverage blockchain to manage anonymous task delegation and incentive distribution, preventing impersonation attacks. Additionally, a sampling-based verification mechanism empowers devices to validate fog nodes’ honesty by auditing historical logs atomically. Security analysis demonstrates robustness against forgery, while experiments confirm practical efficiency of our proposal.
Identity authentication is currently an effective method to ensure the security of satellite communications. However, existing authentication schemes incur excessive overhead, rendering them impractical for resource-constrained satellite system. Thus, we propose Time-Controllable Satellite-Space-Ground Authentication(TCAu), a lightweight authentication scheme enabling direct user-satellite identity verification. TCAu uniquely supports active configuration of authentication credential validity periods, significantly improving satellite authentication efficiency. We formally prove the security of the scheme, demonstrating its resistance to man-in-the-middle attacks. Experimental results further validate its superior performance in both computational and storage overheads compared to existing solutions.
Federated learning has gained widespread attention for its privacy protection and distributed training characteristics, but it is vulnerable to model poisoning attacks. Existing model poisoning attacks often rely on the local model parameters or training data of real clients and are significantly less effective when the server deploys a defense strategy. To address this, we propose a new model poisoning attack, Dynamic Mixed Poisoning Attack (DMPA), which improves the stealthiness of the attack by mixing benign and malicious model updates and dynamically adjusting the size of malicious updates. In addition, DMPA employs the strategy of injecting fake clients to launch the attack in a minimal-knowledge scenario to overcome the limitation of requiring real client information. We further propose a new defense, Median-Norm Credibility Defense (MNCD). MNCD normalizes the magnitudes of uploaded model updates and calculates credibility by comparing each model update’s similarity to the global optimization direction from the previous round, determining aggregation weights. Experimental results show that DMPA bypasses the baseline defense and outperforms the baseline poisoning attack. Compared with the baseline defense, MNCD can effectively resist DMPA and other baseline poisoning attacks. When the fraction of fake clients does not exceed 45
With the widespread use of encrypted transmission and increasingly sophisticated network attacks, ensuring encrypted traffic security has become a major challenge. This paper proposes a deep contrastive learning-based anomaly detection model to address limitations in multi-scale feature extraction, adversarial robustness, and imbalanced traffic. The model combines a Transformer with channel and sequence attention, and a multi-scale 1D dilated convolution module to capture both local and global traffic features. To defend against adversarial samples, we introduce an optimization framework integrating FreeLB adversarial training and Barlow Twins contrastive learning with Double Positive Loss. Moreover, combining CB Loss and Focal Loss improves performance on imbalanced data. Experiments on the CICIDS-2017 dataset show the model achieves an F1-score of 97.72