In view of the problem that the IP address jump law is easy to predict in the current mobile target defense, this paper proposes a network address jump active defense method based on a dynamic random graph, designed to improve the unpredictability of IP address translation. Firstly, in order to make IP address transformation unpredictable in space and time, a random graph model is designed to generate a pseudo-random sequence of IP address randomization; these pseudo-random can meet the unpredictability of IP address translation in both space and time. Then, based on these pseudo-random sequences and IP address pool, a random map generation algorithm is proposed, which generates highly random IP address sequences through chaotic mapping (Logistic mapping) combined with encryption perturbation technology, meeting the requirements of resisting analysis attacks, while these transformed IP addresses are adapted to network target defense. And finally, this article uses buildMininet to build a cloud network trusted environment, by testing the spatial randomization and temporal randomization of the Random mapping model (CRM), the results show that the CRM model has a good effect on improving the local randomness. The test results of the ablation experiment further show that the CRM model can improve the local randomness while maintaining the global randomness.
In the face of an alarming annual increase of over 44,000 Internet security vulnerabilities, traditional static defense has become passive and ineffective. This predicament stems from the inevitability of software vulnerabilities, the asymmetrical cost between attack and defense, and the static nature of conventional network architectures. To overcome the limitations of single-dimensional hopping strategies in Moving Target Defense (MTD), this article proposes a collaborative hopping defense framework named Dual Address Hopping (DAH)-Dynamic Path Weights (DPW). This framework constructs an unpredictable attack surface through the spatio-temporal coordination of dual address hopping and dynamic path-weight-based routing. Leveraging a global collaboration architecture built on software-defined networking (SDN), it significantly reduces control overhead. Furthermore, a behavior-aware model is integrated to accurately identify malicious traffic. Both theoretical analysis and experimental results demonstrate that the proposed approach substantially increases the difficulty for attackers to execute eavesdropping and scanning attacks, thereby markedly enhancing the system’s proactive defense capabilities with acceptable performance overhead.
Privacy concerns hinder the sharing and utilization of trajectory data collected from Internet of Things (IoT) devices. While local differential privacy (LDP) mitigates leakage risks by perturbing data on mobile devices, existing methods primarily focus on enhancing global-level statistical usability of perturbed trajectories (such as spatial distributions and mobility transition patterns), neglecting individual-level semantic usability (such as road network consistency and traffic rule compliance). The resulting trajectories frequently contain unrealistic behaviors that violate traffic rules, severely limiting their applicability. To overcome this challenge, we propose TPIS, a trajectory protection approach with individual semantic utility under LDP. First, we design a semantic-enhanced hierarchical modeling method (SEHM) that leverages traffic rule semantic information and geospatial information to model the road network as a weighted graph, supported by an R-tree index for efficient coarse- and fine-grained trajectory matching. Second, we propose a cascaded perturbation method combining stochastic sampling guided by the hierarchical graph model (SHG) and a multifeature fusion perturbation mechanism based on the delta -location set (MFPD). SHG strategically constrains the perturbation space to preserve global-level statistical usability while ensuring rigorous privacy, and MFPD incorporates a comprehensive trajectory difference metric and delta -location set definition to generate perturbed trajectories that maintain individual-level structural integrity of real-world movement patterns. TPIS efficiently balances privacy and utility and ensures high computational efficiency. Theoretical analysis confirms its differential privacy guarantee and upper bound on perturbation error. Experiments conducted on four real-world datasets demonstrate significant improvements over existing methods, with up to 8 & times; higher utility and 14 & times; greater computational efficiency.
Data correlation is crucial to privacy protection of time series data. Series indistinguishability provides a theoretical basis for ensuring differential privacy on correlated time series data and is implemented with the correlated Laplace mechanism (CLM), which has become a novel privacy-preserving method. CLM requires generating Laplace noise series with original data correlation. However, the existing method (CLM-S) can generate only Laplace noise series with nonnegative autocorrelation, which prevents it from achieving series indistinguishability on negatively correlated data, potentially compromising privacy guarantees in such scenarios. This study proposes a new method named CLM-M as well as its effective implementation (CLM-M-Delta) for generating correlated Laplace noise series through multiplication combination of four Gaussian noises. It has been theoretically proven that CLM-M can match negative correlations. The experimental results demonstrate that CLM-M-Delta effectively adapts to various data correlations and provides improved privacy performance over CLM-S.
Continuous real-time location data is very important in the big data era, but the privacy issues involved is also a considerable topic. It is not only necessary to protect the location privacy at each release moment, but also have to consider the impact of data correlation. Correlated Laplace Mechanism (CLM) is a sophisticated method to implement differential privacy on correlated time series. This paper aims to solve the key problems of applying CLM in continuous location release. Based on the finding that the location increment is approximately stationary in many scenarios, a location correlation estimation method based on the location increment is proposed to solve the problem of nonstationary location data correlation estimation; an adaptive adjustment model for the CLM filter based on parameter quantization idea (QCLM) as well as its effective implementation named QCLM-Lowpass utilizing the lowpass spectral characteristics of location data series is proposed to solve the problem of output deviations due to the undesired transient response of the CLM filter in time-varying environments. Extensive simulations and real data experiments validate the effectiveness of the proposed approach and show that the privacy scheme based on QCLM-Lowpass can offer a better balance between the ability to resist correlation-based attacks and data availability.
Differential privacy, a cornerstone of privacy-preserving techniques, plays an indispensable role in ensuring the secure handling and sharing of sensitive data analysis across domains such as in census, healthcare, and social networks. Histograms, serving as a visually compelling tool for presenting analytical outcomes, are widely employed in these sectors. Currently, numerous algorithms for publishing histograms under differential privacy have been developed, striving to balance privacy protection with the provision of useful data. Nonetheless, the pivotal challenge concerning the effective enhancement of precision for small bins (those intervals that are narrowly defined or contain a relatively small number of data points) within histograms has yet to receive adequate attention and in-depth investigation from experts. In standard DP histogram publishing, adding noise without regard for bin size can result in small data bins being disproportionately influenced by noise, potentially severely impairing the overall accuracy of the histogram. In response to this challenge, this paper introduces the SReB_GCA sanitization algorithm designed to enhance the accuracy of small bins in DP histograms. The SReB_GCA approach involves sorting the bins from smallest to largest and applying a greedy grouping strategy, with a predefined lower bound on the mean relative error required for a bin to be included in a group. Our theoretical analysis reveals that sorting bins in ascending order prior to grouping effectively prioritizes the accuracy of smaller bins. SReB_GCA ensures strict ϵ-DP compliance and strikes a careful balance between reconstruction error and noise error, thereby not only initially improving the accuracy of small bins but also approximately optimizing the mean relative error of the entire histogram. To validate the efficiency of our proposed SReB_GCA method, we conducted extensive experiments using four diverse datasets, including two real-life datasets and two synthetic ones. The experimental results, quantified by the Kullback–Leibler Divergence (KLD), show that the SReB_GCA algorithm achieves substantial performance enhancement compared to the baseline method (DP_BASE) and several other established approaches for differential privacy histogram publication.
Network hopping is a key technology for ensuring network security. Traditional methods for generating IP hopping addresses rely primarily on fixed two-dimensional IP address tables and pseudo-random functions generating IP address sequences that provide limited resistance to certain network attacks. However, these methods often yield IP addresses with low randomness, posing potential security threats. To address this issue, we propose a random graph model to generate a normalized subspace. Based on this subspace and an IP address pool, we introduce a randomized mapping algorithm leveraging a stochastic mapping model to generate spatially and temporally randomized IP addresses. Experimental results demonstrate that Stochastic Atlas Model (SAM) enables IP addresses to change randomly within the network, making it difficult for adversaries to trace their whereabouts, thus achieving the goal of resisting network attacks. Additionally, it is highly practical that does not generate significant interactions that would burden the network and hopping nodes with excessive computational resources and communication overhead.
The rapid growth of GPS technology and mobile devices has led to a massive accumulation of location data, bringing considerable benefits to individuals and society. One of the major usages of such data is travel time prediction, a typical service provided by GPS navigation devices and apps. Meanwhile, the constant collection and analysis of the individual location data also pose unprecedented privacy threats. We leverage the notion of geo-indistinguishability, an extension of differential privacy to the location privacy setting, and propose a procedure for privacy-preserving travel time prediction without collecting actual individual GPS trace data. We propose new concepts to examine the impact of geo-indistinguishability-based sanitization on the usefulness of GPS traces and provide analytical and experimental utility analysis for privacy-preserving travel time prediction. We also propose new metrics to measure the adversary error in learning individual GPS traces from the collected sanitized data. Our experiment results suggest that the proposed procedure provides travel time prediction with satisfactory accuracy at reasonably small privacy costs.
A basic understanding of delayed packet loss is key to successfully applying it to multi-node hopping networks. Given the problem of delayed data loss due to network delay in a hop network environment, we review early time windowing approaches, for which most contributions focus on end-to-end hopping networks. However, they do not apply to the general hopping network environment, where data transmission from the sending host to the receiving host usually requires forwarding at multiple intermediate nodes due to network latency and network cache overflow, which may result in delayed packet loss. To overcome this challenge, we propose a delay time window and a method for estimating the delay time window. By examining the network delays of different data tasks, we obtain network delay estimates for these data tasks, use them as estimates of the delay time window, and validate the estimated results to verify that the results satisfy the delay distribution law. In addition, simulation tests and a discussion of the results were conducted to demonstrate how to maximize the reception of delay groupings. The analysis shows that the method is more general and applicable to multi-node hopping networks than existing time windowing methods.
GPS tracks every user’s movement, creating thus an unlimited input of trajectories. Since the GPS tracking systems are often slightly imprecise, filters exist which try to correct these imprecisions to reconstruct the real trajectories. On the other hand, users’ trajectories contain highly sensitive information which must be anonymized, and one common type of anonymization technique is based on random noise addition. As one could think, if filters can be used to correct GPS impressions, they can potentially be used to undo an anonymization step based on random noise addition, reverting therefore any privacy guarantees.
Differential privacy (DP) has become a de facto standard to achieve data privacy. However, the utility of DP solutions with the premise of privacy priority is often unacceptable in real-world applications. In this paper, we propose the best-effort differential privacy (B-DP) to promise the preference for utility first and design two new metrics including the point belief degree and the regional average belief degree to evaluate its privacy from a new perspective of preference for privacy. Therein, the preference for privacy and utility is referred to as expected privacy protection (EPP) and expected data utility (EDU), respectively. We also investigate how to realize B-DP with an existing DP mechanism (KRR) and a newly constructed mechanism (EXPQ) in the dynamic check-in data collection and publishing. Extensive experiments on two real-world check-in datasets verify the effectiveness of the concept of B-DP. Our newly constructed EXPQ can also satisfy a better B-DP than KRR to provide a good trade-off between privacy and utility.
Advances in network technology have enhanced the concern for network security issues. In order to address the problem that hopping graph are vulnerable to external attacks (e.g., the changing rules of fixed graphs are more easily grasped by attackers) and the challenge of achieving both interactivity and randomness in a network environment, this paper proposed a scheme for a dynamic graph based on chaos and cryptographic random mapping. The scheme allows hopping nodes to compute and obtain dynamically random and uncorrelated graph of other nodes independently of each other without additional interaction after the computational process of synchronous mirroring. We first iterate through the chaos algorithm to generate random seed parameters, which are used as input parameters for the encryption algorithm; secondly, we execute the encryption algorithm to generate a ciphertext of a specified length, which is converted into a fixed point number; and finally, the fixed point number is mapped to the network parameters corresponding to each node. The hopping nodes are independently updated with the same hopping map at each hopping period, and the configuration of their own network parameters is updated, so that the updated graph can effectively prevent external attacks. Finally, we have carried out simulation experiments and related tests on the proposed scheme and demonstrated that the performance requirements of the random graphs can be satisfied in both general and extreme cases.
Among the advanced methods, differential privacy (DP), introducing independent Laplace noise, has become an influential privacy mechanism owing to its provable and rigorous privacy guarantee. Nonetheless, in practice, POI data to be protected is always correlated, while independent noise may cause undesirable information disclosure than expected. Recent researches attempt to optimize the sensitivity function of DP with consideration of the correlation strength between POI—but there is a drawback in a substantial growth of noise level. To remedy this problem, this paper exploits the degradation of DP in expected privacy levels for correlated POI data and proposes a solution to mitigate it. We propose a generalized Laplace mechanism to achieve privacy guarantees. Specifically, we design a practical iteration mechanism, including an update function, to conduct a generalized Laplace mechanism when facing large scale queries. Experimental evaluation on real-world datasets over multiple fields show that our solution consistently outperforms state-of-the-art mechanisms in data utility while providing the same privacy guarantee as other approaches for correlated POI data.
Privacy preserving methods supporting for data aggregating have attracted the attention of researchers in multidisciplinary fields. Among the advanced methods, differential privacy (DP) has become an influential privacy mechanism owing to its rigorous privacy guarantee and high data utility. But DP has no limitation on the bound of noise, leading to a low-level utility. Recently, researchers investigate how to preserving rigorous privacy guarantee while limiting the relative error to a fixed bound. However, these schemes destroy the statistical properties, including the mean, variance and MSE, which are the foundational elements for data aggregating and analyzing. In this paper, we explore the optimal privacy preserving solution, including novel definitions and implementing mechanisms, to maintain the statistical properties while satisfying DP with a fixed relative error bound. Experimental evaluation demonstrates that our mechanism outperforms current schemes in terms of security and utility for large quantities of queries.
Face spoofing attacks based on 3D face images have posed a severe security risk to face recognition systems. Despite the great effort made by the technical community in recent years, existing 3D face spoofing databases, mostly based on 3D masks, still suffer from small sample size, low diversity, or poor authenticity due to the production difficulty and high cost. To fill in this gap, we introduce a new database in this paper with 4-0 0 0 single wax figure faces, named SWFFD (Single Wax Figure Face Database), as a type of super-realistic 3D face presentation attack. Collected from online resources, this database has high diversity in terms of subjects, lighting conditions, facial poses, and recording devices. We have also designed a new detection method, which combines attention-aware features from different face scales to generate discriminative representations for realistic face spoofing attack detection. Extensive experiments have been conducted on the SWFFD as well as the CelebA-HQ database (containing real faces from the online collection). Experimental results have demonstrated the effectiveness of the proposed method in both intra-database and cross-database testing scenarios. (c) 2021 Elsevier B.V. All rights reserved.
许多国家政府都发布了抗击新冠肺炎(covid-19)传播的联系人追踪应用程序,旨在帮助卫生官员发现感染者后追踪接触情况.然而,位置追踪应用程序会对用户隐私造成泄露.因此,为了解决接触者追踪对用户隐私影响,分析、讨论、综述了当前接触者追踪中的隐私风险和保护问题,保证在不降低对公共健康有用性的情况下改善隐私泄露问题.希望通过此研究结果,确保移动联系人追踪应用程序的用户隐私,并鼓励政府努力开发有效的替代解决方案,为用户提供更强的隐私保护.
We have witnessed rapid advances in both face presentation attack models and presentation attack detection (PAD) in recent years. When compared with widely studied 2D face presentation attacks, 3D face spoofing attacks are more challenging because face recognition systems are more easily confused by the 3D characteristics of materials similar to real faces. In this work, we tackle the problem of detecting these realistic 3D face presentation attacks, and propose a novel anti-spoofing method from the perspective of fine-grained classification. Our method, based on factorized bilinear coding of multiple color channels (namely MC_FBC), targets at learning subtle fine-grained differences between real and fake images. By extracting discriminative and fusing complementary information from RGB and YCbCr spaces, we have developed a principled solution to 3D face spoofing detection. A large-scale wax figure face database (WFFD) with both images and videos has also been collected as super-realistic attacks to facilitate the study of 3D face presentation attack detection. Extensive experimental results show that our proposed method achieves the state-of-the-art performance on both our own WFFD and other face spoofing databases under various intra-database and inter-database testing scenarios.
By combining randomized response with Laplace distribution, it obtains a new kind of differential privacy mechanism called Pseudo-Laplace mechanism. By analyzing the privacy and data availability of the mechanism, as well as an optimization problem that provides better privacy protection than the Laplace mechanism based solely on the Laplace distribution (traditional Laplace mechanism) under the same data availability, and the instantiations of the mechanism obtained in the approximate optimization algorithm, it finds that the mechanism could have almost the same privacy protection level in the middle and high privacy protection region (approximately ε < 5 ) and better privacy protection level in the low privacy protection region (approximately ε ≥5 ) than the traditional Laplace mechanism under the same data availability. It has important practical implications for many practical applications where data availability is prioritized while better user privacy is protected.
Despite the impressive progress in face recognition, current systems are vulnerable to presentation attacks, which subvert the face recognition systems by presenting a face artifact. Several techniques have been developed to automatically detect different presentation attacks, mostly for 2D photo print and video replay attacks. However, with the development of 3D modeling and printing technologies, 3D mask has become a more effective way to attack the face recognition systems. Over the last decade, various detection methods for 3D mask attacks have been proposed, but there is no survey yet to summarize the advances. We present a comprehensive overview of the state-of-the-art approaches in 3D mask spoofing and anti-spoofing, including existing databases and countermeasures. In addition, we quantitatively compare the performance of different mask spoofing detection methods on a common ground (i.e., using the same database and evaluation metric). The effectiveness of several 2D presentation attack detection methods is also evaluated on two 3D mask spoofing databases to show whether they are applicable or not for 3D mask attacks. Finally, we present some insights and summarize open issues to address in the future.