The emergent direct-to-cell Low-Earth Orbit (LEO) satellite mega-constellations promise ubiquitous LTE/5G access for mobile users without terrestrial base stations. However, it still faces fake satellite attacks during the bootstrapping process, stemming from the openness of satellite-terrestrial links and the substantially higher user access demands imposed by global coverage compared to terrestrial base stations. Existing protocols make optimistic assumptions regarding satellite trustworthiness. Moreover, their poor scalability results in performance bottlenecks when handling massive authentication requests within short timeframes. To address these challenges, we propose a lightweight and secure extended authentication and key agreement (eAKA) protocol under the Dolev Yao model. The protocol integrates a certificateless signature scheme to resist fake satellite attacks, a lightweight AMAD-based batch authentication mechanism to improve efficiency, and a group key update mechanism based on the Chinese Remainder Theorem (CRT) to support dynamic user management and enhance scalability. Rigorous analysis demonstrates the protocol satisfies satellite authentication security requirements. Compared with the benchmark, it reduces computational, communication, and transmission overhead by $17.24 \%, 36.77 \%$, and 50 %, respectively.
Large Language Models (LLMs) sparked massive applications in 6G. However, the emerging 6G Mobile Edge Computing (MEC) based on LLM caching leaves model protection unconsidered. To protect the LLM assets under the extended Dolev-Yao (DY) threat model, a secure batch LLMs deployment framework is proposed for 6G MEC, which securely delivers the sanitized crafted (san-crafted) LLM and the crafted-random-values (CR-values) from 6G edge to the Rich Execution Environment (REE) and Trusted Execution Environment (TEE) of mobile devices, respectively. Firstly, the 6G MEC cached LLM is san-crafted by an efficiency-improved sanitizable signature to protect the integrity of the LLM during the entire deployment process. Then, a lightweight batch authentication protocol is proposed to improve the efficiency of verifying ultra-massive model requests. Finally, to be compatible with the state-of-the-art secure inference (i.e., Magnitude), the san-crafted LLM delivered into mobile device's REE is verified by sanitizable signatures, and then conducts secure inference with the corresponding CR-values provisioned into the TEE. Rigorous security proofs confirm that our framework meets the security requirements of LLM deployment. Compared to the benchmark, the proposed framework significantly improves both computational and communication efficiency, reducing computational overhead by 89.92% and communication overhead by 47.08%. This framework facilitates the TEE-based LLMs secure inference for ultra-massive mobile devices in 6G MEC.
5G mobile networks are becoming new targets for Advanced Persistent Threat (APT) attacks. While existing provenance-based intrusion detection systems (PIDS) show promise for APT detection, they are inadequate for complex 5G networks due to the absence of explainable investigation results. They generate alert graphs with numerous false positive nodes, imposing substantial cognitive burdens on security analysts. This paper presents SAGE, the first end-to-end framework for automated APT investigation in 5G networks. SAGE presents a two-stage approach. For improved detection precision, SAGE constructs global heterogeneous provenance graphs integrating system and 5G application logs with semantic embeddings for efficient node-level anomaly detection. For automated investigation, SAGE introduces a novel self-reflective and self-reasoning LLM framework with domain-specific Retrieval Augmented Generation (RAG). Through carefully designed APT investigation workflows, it reduces detection false positives and automatically generates comprehensive natural language reports explaining attack tactics, techniques and procedures (TTPs) and impacts, bridging the critical gap between alerts and human-friendly intelligence. Extensive experiments on the constructed 5G APT dataset demonstrate that SAGE’s investigation framework improves node-level detection precision by an average of 12% and generates high-quality investigation reports, achieving superior TTP-level detection performance with over 80% precision, significantly outperforming state-of-the-art methods.
Abstract This paper aims at the requirement of multi-phase controllable excitation signals in plasma processing, designs and implements a high precision multi-channel synchronous pulse waveform generator based on the GD32F407 microcontroller. The system adopts a technical scheme combining timer interrupt driving and a waveform look-up table, which can simultaneously generate 7 channels of independently configurable synchronous pulse waveforms. Each channel contains non-inverting and inverting phase outputs, with a total of 14 output channels. Subsequently, this paper presents a hardware implementation. Tests showed that its maximum frequency could reach 150 KHz, and the 7-channel synchronous pulses could all be freely configured. Finally, this device was connected to drive a tailored wave generator, providing a reliable hardware platform for the subsequent research on plasma energy distribution regulation.
TEE-shielded secure inference offers an efficient solution to protect valuable edge-deployed models from potential thefts. Nevertheless, existing methods are lack of theoretical security analysis, failing to achieve the optimal security. Furthermore, while feasible for small models, existing methods are excessively heavyweight for Large Language Models (LLM). For LLaMA-7B, they introduce GB-level secure memory requirement and hundredfold inference latency, severely compromising real-time utility. To solve these problems, we first present a Bayesian theory framework of Model Stealing (MS) attacks, which decomposes MS into prior and posterior knowledge leakage. Based on this framework, LLMGuard is proposed, which presents two components: First, Intrinsic Parameters Shielding is designed to shield all private parameters, preventing prior knowledge leakage. This approach significantly decreases the secure memory usage and achieves inference speedup. Second, since OTP is not applicable to LLMs, Random Slices Composition is developed to obfuscate intermediate distributions with no computational overhead, minimizing posterior knowledge leakage efficiently. Experimental results demonstrate that LLMGuard downgrades model to black-box inference with negligible accuracy loss, while delivering \(43\times\) inference speedup on LLaMA compared to fully-shielded methods. The proposed LLMGuard effectively addresses concerns related to intellectual property theft on edge, boosting the secure deployment of LLMs on untrusted devices.
Quantization Neural Networks (QNNs) has been widely adopted in resource-constrained edge devices due to their real-time capabilities and low resource requirement. However, concerns have arisen regarding that deployed models are white-box available to model thefts. To address this issue, TEE-shielded secure inference has been introduced as a secure and efficient solution. Nevertheless, existing methods neglect the compatibility with 8-bit quantized computation, which leads to severe integer overflow issue during inference. This issue could result a disastrous degradation in QNNs (to random guessing level), completely destroying model utility. Moreover, the model confidentiality and inference integrity also face a substantial threat due to the limited data representation space. To safeguard accurate and efficient inference for QNNs, TEE-Shielded QNN Partition (TSQP) are proposed, which presents three key insights: Firstly, Quantization Manager is designed to convert white-box inference to black-box by shielding critical scales in TEE. Additionally, overflow concerns are effectively addressed using reduced-range approaches. Secondly, by leveraging the Information Bottleneck theory to enhance model training, we introduce Parameter De-Similarity to defend against powerful Model Stealing attacks that existing methods are vulnerable to. Thirdly, the Integrity Monitor is suggested to detect inference integrity breaches in an oblivious manner. In contrast, existing method can be bypassed due to the lack of obliviousness. Experimental results demonstrate that proposed TSQP maintains high accuracy and achieves accurate integrity breaches detection. Our method achieves more than 8x speedup compared to full TEE inference, while reducing Model Stealing attacks accuracy from 3.99x to 1.29x. To our best knowledge, proposed method is the first TEE-shielded secure inference solution that achieves model confidentiality, inference integrity and model utility on QNNs.
Acoustic detection technology has emerged as a promising, non-destructive and continuous monitoring method for pest early detection at the single tree level. However, field application still encounters problems, especially under complex infestation scenarios, i.e., co-infestations by multiple pest species. This study aims to develop a novel acoustic-based recognition model for detecting forest wood-boring pests, specially designed to enhance monitoring accuracy under complex infestation scenarios. We collected feeding vibration signals from four wood-boring pests: Semanotus bifasciatus, Phloeosinus aubei, Agrilus planipennis, and Streltzoviella insularis. Three infestation scenarios were designed: single-species, co-infestation without mixed signals, and co-infestation with mixed signals. Three machine learning (ML) models (Random Forest, Support Vector Machine, and Artificial Neural Network) based on seven acoustic feature variables, and three deep learning (DL) models (AlexNet, ResNet, and VGG) using spectrograms were employed to classify the signals. Results showed that ML models achieved perfect accuracy (OA: 100%, Kappa: 1) in single-species scenarios but declined significantly under co-infestation scenarios with mixed signals. In contrast, DL models, particularly ResNet, maintained high accuracy (OA: 85.0–88.75%) and effectively discriminated mixed signals. In conclusion, this study demonstrates the superiority of spectrogram-based DL models for acoustic detection under complex infestation scenarios and provides a foundation for developing a general, real-time detection model for integrated pest management in forest ecosystems.
Given the large-scale deployment of 5G, rigorous testing of its core network (5GC) is essential to ensure security and robustness. Fuzzing is currently one of the most popular vulnerability discovery techniques. However, existing fuzzers suffer from low coverage of 3GPP-specified 5GC states, invalid long signaling sequence generation when exploring deep 5GC states, and coarse-grained feedback of closed-source 5G systems. This paper presents 5GC-Fuzz, a black-box fuzzing framework to detect deep stateful vulnerabilities in 5GC implementations. 5GC-Fuzz integrates three innovative techniques: (1) a systematic construction of a 5GC state machine derived from 3GPP specifications to guide the fuzzing process; (2) a 5G grammar-aware signaling sequence mutation method based on protocol stack interception to generate test cases while maximally guaranteeing the syntactic, semantic, and cryptographic correctness; and (3) a fine-grained state-transition-path feedback mechanism based on 5GC logs to optimize test states and sequences selection. The 5GC-Fuzz was evaluated on three popular 5GC implementations and achieves 152.6% more states and 206.7% more state transition paths than the state-of-the-art fuzzers. Moreover, 5GC-Fuzz exposed 22 security-critical vulnerabilities, with 6 CVEs assigned. In general, 5GC- Fuzz could explore deeper states and uncover more vulnerabilities in 5GC, significantly enhancing the security of mobile communication infrastructures.
While Large Language Models (LLMs) have gained remarkable success, they are consistently at risk of being stolen when deployed on untrusted edge devices. As a solution, TEE-based secure inference has been proposed to protect valuable model property. However, we identify a statistical vulnerability in existing protection methods, and furtherly compromise their security guarantees by proposed Model Stealing Attack with Prior. To eliminate this vulnerability, LoRO is presented in this paper, which leverages dense mask to completely obfuscate parameters. LoRO includes two innovations: (1) Low Rank Mask, which uses low-rank factors to generate dense masks efficiently. The computing complexity in TEE is hence reduced by an exponential amount to achieve inference speed up, while providing robust model confidentiality. (2) Factors Multiplexing, which reuses several cornerstone factors to generate masks for all layers. Compared to one-mask-per-layer, the secure memory requirement is reduced from GB-level to tens of MB, hence avoiding the hundred-fold latency introduced by secure memory paging. Experimental results indicate that LoRO achieve a $0.94\times$ Model Stealing (MS) accuracy, while SOTA methods presents $3.37\times$ at least. The averaged inference latency of LoRO is only $1.49\times$, compared to the $112\times$ of TEE-shielded inference. Moreover, LoRO results no accuracy loss, and requires no re-training and structure modification. LoRO can solve the concerns regarding model thefts on edge devices in an efficient and secure manner, facilitating the wide edge application of LLMs.
Deep gradient inversion attacks expose a serious threat to Federated Learning (FL) by accurately recovering private data from shared gradients. However, the state-of-the-art heavily relies on impractical assumptions to access excessive auxiliary data, which violates the basic data partitioning principle of FL. In this paper, a novel method, Gradient Inversion Attack using Practical Image Prior (GI-PIP), is proposed under a revised threat model. GI-PIP exploits anomaly detection models to capture the underlying distribution from fewer data, while GAN-based methods consume significant more data to synthesize images. The extracted distribution is then leveraged to regulate the attack process as Anomaly Score loss. Experimental results show that GI-PIP achieves a 16.12 dB PSNR recovery using only 3.8% data of ImageNet, while GAN-based methods necessitate over 70%. Moreover, GI-PIP exhibits superior capability on distribution generalization compared to GAN-based methods. Our approach significantly alleviates the auxiliary data requirement on both amount and distribution in gradient inversion attacks, hence posing more substantial threat to real-world FL. Our code is available at https://github.com/D1aoBoomm/GI-PIP.
The device fingerprinting technique extracts fingerprints based on the hardware characteristics of the device to identify the device. The primary goal of device fingerprinting is to accurately and uniquely identify a device, which requires the generated device fingerprints to have good stability to achieve long-term tracking of the target device. However, the fingerprints generated by some existing fingerprinting technologies are not stable enough or change frequently, making it impossible to track the target device for a long time. In this paper, we present FPHammer, a novel DRAM-based fingerprinting technique. The device fingerprint generated by our technique has high stability and can be used to track the device for a long time. We leverage the Rowhammer technique to repeatedly and quickly access a row in DRAM to get bit flips in its adjacent row. We then construct a physical fingerprint of the device based on the locations of the collected bit flips. The evaluation results of the uniqueness and reliability of the physical fingerprint show that it can be used to distinguish devices with the same hardware and software configuration. The experimental results on device identification demonstrate that the physical fingerprints engendered by our innovative technique are inherently linked to the entirety of the device rather than just the DRAM module. Even if the device modifies software-level parameters such as MAC address and IP address or even reinstalls the operating system, we can accurately identify the target device. This demonstrates that FPHammer can generate stable fingerprints that are not affected by software layer parameters.
The space-air-ground integrated network (SAGIN) has a stringent demand on the efficiency of authentication protocols deployed in the devices that have been launched into the air and space. In this paper, we define the concept of the security model of conditional physical unclonable function (CPUF) that guarantees the security of the protocol while allowing the use of PUFs that can be modeled. We then propose a CPUF-based authentication and key agreement (AKA) scheme, named CPAKA, that addresses the challenges of device key leakage and inefficient authentication in resource-asymmetric environments. The CPAKA scheme embeds PUFs in weak nodes and deploys prediction models corresponding to the PUFs in strong nodes, eliminating the need to store challenge-response pairs or perform complex calculations. We formally prove the protocol's security under the decisional uniqueness assumption of CPUF and the universal composability framework, and we analyze its secrecy and authentication properties using the Tamarin prover. We also implement an Arbiter PUF on the ZYNQ-7020 FPGA, verify its accuracy through experiments, and show that CPAKA is secure, efficient, and suitable for SAGIN. Our CPAKA scheme greatly reduces computing and storage costs while improving authentication efficiency compared to traditional schemes.
As a distributed machine learning approach that preserves data ownership while releasing data usage rights, federated learning overcomes the challenge of data silos that hinder large-scale modeling with big data. However, the characteristic of only sharing gradients without training data during the federated training process does not guarantee the confidentiality of users' training data. In recent years, novel deep gradient inversion attacks have demonstrated the ability of adversaries to reconstruct private training data from shared gradients, which poses a serious threat to the privacy of federated learning. With the evolution of gradient inversion techniques, adversaries are increasingly capable of reconstructing large volumes of data from deep neural networks, which challenges the Privacy-Preserving Federated Learning (PPFL) with encrypted gradients. Effective defenses mainly rely on perturbation transformations to obscure original gradients, inputs, or features to conceal sensitive information. Firstly, the gradient inversion vulnerability in PPFL is highlighted and the threat model in gradient inversion is presented. Then a detailed review of deep gradient inversion attacks is conducted from the perspectives of paradigms, capabilities, and targets. The perturbation-based defenses are divided into three categories according to the perturbed objects: gradient perturbation, input perturbation, and feature perturbation. The representative works in each category are analyzed in detail. Finally, an outlook on future research directions is provided.
Background: The current method of measuring parameters in spinal imaging manually is time-consuming and prone to inconsistencies. This study proposed and validated a novel method to automate the measurement of pelvic parameters using a one-stage deep learning (DL) model. Methods: Spinopelvic parameters, including pelvic incidence (PI), sacral slope (SS), and pelvic tilt (PT), were measured from full body radiographs of patients by three evaluators and by using our proposed method. Our proposed one-stage DL model was based on keypoint localisation. Landmark localisation error was used to evaluate the performance of landmark localisation. To evaluate the agreement between our method and the human evaluators, the analysis of average error, standard deviation, and intra- and inter-evaluator reliability was conducted using the intraclass correlation coefficient (ICC) and Pearson's correlation coefficient ( R ). Results: The method achieved excellent measurement performance for spinopelvic parameters. The distribution of the landmark localisation errors was within a reasonable range (median error, 2.28–4.01 mm). ICC values for the assessment of the intra- (range: 0.941–0.996) and inter-evaluator (0.994–0.998) reliability of human evaluators were excellent. The method was able to determine spinopelvic parameters with excellent ICC values (0.919-0.997) and R value ( R >0.899, p <0.001, all). Meanwhile, the detection speed of the algorithm was approximately 30 times faster than that of manual measurements of spinopelvic parameters. Conclusions: This one-step automated measurement method is less time-consuming and has excellent reliability and agreement with human evaluators.
As a privacy-preserving enhancement to the Federated Learning (FL) framework, Secure Aggregation (SA) enables multiparty summation without any party needing to reveal their updates to the aggregator in Internet of Things applications. However, conventional threat model underestimates the potential inversion attacks on aggregated gradients from an honest-but-curious client, due to the considering information loss caused by SA. This study for the first time, demonstrates the gradient inversion attack against SA schemes in which gradients are quantized and aggregated. Then an enhanced gradient inversion from client side is proposed to address two roadblocks caused by SA, i.e., aggregation information loss and quantization rounding error. To countermeasure the information loss, we utilize class-wise representation matching to achieve category-level decomposition. This relies on a prior restoration of the class-wise representations and instance-wise labels, whose numerical accuracy is cyclically calibrated through prior-based offset estimation. Since cryptographic operators involved in SA schemes usually operates in the integer domain, gradient quantization is introduced. Regarding the rounding errors from gradient quantization, quantization-aware gradient matching is presented to align with a more precise optimization objective. Extensive experiments demonstrate that a semi-honest client is sufficient to infer sensitive data from the aggregated gradients after even 8-bit quantization. Moreover, a defense scheme based on 1-bit gradient quantization is proposed. The new attack from client side in SA-based FL urges the community to take necessary defensive measures.
Handover authentication in high mobility scenarios is characterized by frequent and short-term parallel execution. Moreover, the penetration loss and Doppler frequency shift caused by high speed also lead to the deterioration of network link quality. Therefore, high mobility scenarios require handover schemes with less handover overhead. However, some existing schemes that meet this requirement cannot provide strong security guarantees, while some schemes that can provide strong security guarantees have large handover overheads. To solve this dilemma, we propose a privacy-preserving handover authentication scheme that can provide strong security guarantees with less computational cost. Based on Orthogonal Time Frequency Space (OTFS) link and Key Encapsulation Mechanism (KEM), we establish the shared key between protocol entities in the initial authentication phase, thereby reducing the overhead in the handover phase. Our proposed scheme can achieve mutual authentication and key agreement among the user equipment, relay node, and authentication server. We demonstrate that our proposed scheme can achieve user anonymity, unlinkability, perfect forward secrecy, and resistance to various attacks through security analysis including the Tamarin. The performance evaluation results show that our scheme has a small computational cost compared with other schemes and can also provide a strong guarantee of security properties.
针对现阶段网络空间安全专业操作系统课程存在的问题,提出面向网络空间安全人才培养的PRIDE教学模式和面向网络空间安全专业的操作系统课程改革方案,从如何融入国产操作系统安全与思政教育、如何增强课程的网络安全特色、如何完善后续课程体系3方面介绍课程建设的内容以及具体实施路径,最后说明课程教学改革成效.
With the continuous advancement of edge intelligence, edge servers undertake more and more intelligent computing tasks. Nowadays, there are a large number of Internet of Things (IoT) devices in the network in an idle state. For instance, the mining process for the consensus of miners in blockchain such as Bitcoin causes a waste of computing resources and energy. A natural question arises: can we couple the idle computing resources of network devices to continuously and credibly share the burden of edge intelligent computing tasks in a secure manner? The answer of this article is yes. We propose a blockchain-based IoT resource monitoring and scheduling framework that supports resource management and trusted edge computing. We analyze the security threats in all phases of distributed edge computing, and utilize the trusted computing and public verifiability features of blockchain to ensure reliability and fairness in the trusted measurement of device computing power, the decomposition of intelligent computing tasks, the matching of task and computing power, and the verification of computing result. Finally, we implement a simulation on the edge network by performing a distributed machine learning task for weather prediction, and the simulation results demonstrate the availability of our scheme.
To compensate for the lack of charging equipment, the charging reservation mechanism has been employed in the vehicle-to-grid (V2G) system, which is vulnerable to some potential risks, such as privacy disclosure, identity impersonation, hardware modification, and so on. In this paper, we first introduce a 5G-V2G system that integrates the 5G network and the power grid to enable the remote transmission of reservation information. On this basis, we propose a scalable reservation authentication and key agreement protocol that can support access of flexible number and guarantee the confidentiality and privacy of critical reservation data. The proposed protocol uses lightweight algorithms like reverse fuzzy extraction to offload the computation overhead on the EVs and embeds physical unclonable function (PUF) in the outfield equipment to resist physical attacks. We evaluate the security properties of the proposed protocol by the formal analysis tool AVISPA and compare it with the existing schemes in terms of computing overhead, transmission overhead, signaling overhead, and security. The comprehensive results indicate that our protocol performs better in all aspects and has higher reliability and scalability. In practice, our protocol can assist the 5G charging reservation mechanism to complete efficient, lightweight, and privacy-preserving reservation information collection and authentication.
Gradient inversion attacks have posed a serious threat to the privacy of federated learning. The attacks search for the optimal pair of input and label best matching the shared gradients and the search space of the attacks can be reduced by pre-restoring labels. Recently, label restoration technique allows for the extraction of labels from gradients analytically, but even the state-of-the-art remains limited to identify the presence of categories (i.e., the class-wise label restoration). This work considers the more real-world settings, where there are multiple instances of each class in a training batch. An analytic method is proposed to perform instance-wise batch label restoration from only the gradient of the final layer. On the basis of the approximate recovered class-wise embeddings and post-softmax probabilities, we establish linear equations of the gradients, probabilities and labels to derive the Number of Instances (NoI) per class by the Moore-Penrose pseudoinverse algorithm. Our experimental evaluations reach over 99% Label existence Accuracy (LeAcc) and exceed 96% Label number Accuracy (LnAcc) in most cases on three image datasets and four classification models. The two metrics are used to evaluate class-wise and instance-wise label restoration accuracy, respectively. And the recovery is made feasible even with a batch size of 4096 and partially negative activations (e.g., Leaky ReLU and Swish). Furthermore, we demonstrate that our method facilitates the existing gradient inversion attacks by exploiting the recovered labels, with an increase of 6-7 in PSNR on both MNIST and CIFAR100. Our code is available at https://github.com/BUAA-CST/iLRG.