Federated Learning (FL) provides a privacy-preserving solution as a paradigm of distributed learning by allowing clients to train models locally. However, traditional FL still faces privacy leakage risks during parameter uploading, and the existing Differential Privacy (DP)-based FL (DPFL) often degrade model performance due to improper noise injection. In this paper, an adaptive DPFL framework ADPFL is proposed, which achieves a trade-off between privacy protection and model utility through dynamic fine-grained privacy budget allocation, adaptive gradient clipping, and optimized client selection. Specifically, ADPFL first controls the noise scale by dynamically adjusting the privacy budget at the global level based on global accuracy differences across training rounds and at the local level based on the importance of CNN layers. Second, the gradient clipping threshold can be adaptively adjusted based on training progress, which also regulates the noise while minimizing information loss and suppressing outlier gradients. Third, ADPFL improves the convergence speed by selecting high-accuracy clients with diverse data distributions, while reducing privacy budget consumption. Finally, theoretical analyses demonstrate that ADPFL satisfies (ϵ, δ)-DP constraints, and provide the convergence bound. Experimental results show that ADPFL outperforms baseline methods in both privacy protection and model utility.
Federated learning (FL) provides a privacy-preserving solution as a paradigm of distributed learning by allowing clients to train models locally. However, traditional FL still faces privacy leakage risks during parameter uploading, and the existing differential privacy (DP)-based FL (DPFL) often degrades model performance due to improper noise injection. In this article, an adaptive DPFL framework, ADPFL, is proposed, which achieves a tradeoff between privacy protection and model utility through dynamic fine-grained privacy budget allocation, adaptive gradient clipping, and optimized client selection. Specifically, ADPFL first controls the noise scale by dynamically adjusting the privacy budget at the global level based on global accuracy differences across training rounds and at the local level based on the importance of CNN layers. Second, the gradient clipping threshold can be adaptively adjusted based on training progress, which also regulates the noise while minimizing information loss and suppressing outlier gradients. Third, ADPFL improves the convergence speed by selecting high-accuracy clients with diverse data distributions, while reducing privacy budget consumption. Finally, theoretical analyses demonstrate that ADPFL satisfies (& varepsilon;,delta) -DP constraints and provide the convergence bound. The experimental results show that ADPFL outperforms baseline methods in both privacy protection and model utility.
The dynamic observation data of the Earth from Low Earth Orbit (LEO) satellites can be used for weather analysis, urban planning, etc. The existing satellite federated learning (FL) schemes have two main drawbacks. First, most of schemes rely on frequent communication between satellites and ground station. Due to the transient and unstable communication links, significant convergence delays are observed. Second, the possibility of unreliable and malicious participants preventing model convergence and degrading performance is not considered. To address the above issues, a secure and efficient FL scheme RAFL for LEO constellations is proposed. RAFL employs aerial networking and hierarchical FL to reduce interactions between satellites and ground station, thereby enhances training efficiency and model performance. A self-adaptive reputation evaluation system is designed that incorporates malicious behavior detection, historical behavior analysis, and performance and contribution assessments of LEO satellites. This system can detect and resist the actions of unreliable and malicious participants, and select appropriate leaders, thereby enhancing the robustness of FL. Extensive experiments show that RAFL not only effectively resists poisoning attacks but also improves the convergence time of FL while maintaining the accuracy of the global model.
Federated learning (FL) is a new distributed machine learning framework that emerged in recent years, which can protect the participants’ data privacy to a certain extent without exchanging the participants’ original data. Unfortunately, it can still be vulnerable to privacy attacks (e.g. membership inference attacks) or security attacks (e.g. model poisoning attacks), which can compromise participants’ data or corrupt the trained model. Inspired by previous works, we propose a novel federated learning framework with data integrity auditing called NSPFL. First, NSPFL protects against privacy attacks by using a single mask to hide the participants’ original data. Second, NSPFL constructs a novel reputation evaluation method to resist security attacks by measuring the distance between the previous and current aggregated gradients. Third, NSPFL utilizes the data stored on the cloud to prevent malicious Byzantine participants from denying behaviors. Finally, sufficient theoretical analysis proves the reliability of the scheme, and a large of experiments demonstrate the effectiveness of the NSPFL.
As a recently distributed machine learning framework, federated learning (FL) has garnered attention for its privacy protection. However, recent researches in recent years have shown malicious entities may still acquire the clients' privacy in FL. Moreover, factors, such as the verifiability of the aggregation model and the huge computational and communication overheads, also make existing solutions less practical. To this end, we design a novel FL architecture named EHFL. First of all, EHFL protects data privacy by concealing the clients' data using a single mask and group key encryption. Second, combined with symmetric balanced incomplete block design (SBIBD), our EHFL dramatically reduces client computational and communication overhead to approximately (k+1)/(k(2)+k+1) compared to traditional FL (e.g., FedAvg). Third, EHFL designs an ingenious verification mechanism to ensure the correctness of the aggregation server's results via the Hamiltonian graph formed by the SBIBD. Finally, sufficient theoretical analyses prove the reliability of EHFL and lots of experiments demonstrate the effectiveness of EHFL.
Attribute-based searchable encryption (ABSE) is a promising encryption mechanism for sharing outsourced encrypted data in clouds, allowing fine-grained access control over data while searching for encrypted data. However, the access policy in the most existing ABSE schemes exists in plaintext, which could expose sensitive information about legitimate data users. Moreover, such schemes delegate complex search operations to a cloud server, which can lead to data tampering and even untrusted results, and single point of failure. In this article, we propose a blockchain (BC)-based anonymous ABSE scheme for data sharing (BADS). First, attributes of the access policy are hidden, thus, providing confidentiality to the set of attributes that satisfy the access policy. Then combining ABSE with BC have features of tamper-proof, integrity verification, and nonrepudiation. In particular, information, such as secure index is stored in BC, while encrypted data is stored in a distributed system called the interplanetary file system (IPFS) to avoid single point of failure. Finally, BADS supports the matching algorithm that perform a fixed number of pairing operations before searching algorithm. We analysis security and evaluate performance to show the efficiency and practicability of BADS.
As well known, Internet of medical things (IoMT) produces large amounts of medical data and promotes the medical data sharing which serves the data user (i.e., physicians) to boost the clinical treatment and medical research. To protect data user’s privacy and data security during the sharing of medical data, data user must have a self-sovereign decentralized identity (DID) and data access authority. In existing solutions, data user’s privacy protection and authenticated-key-agreement (AKA) for protecting data security are worked independently, which easily results in typical security attacks (e.g., phishing inquiry attacks, ephemeral secret leakage attacks) during data access and system computing overload. To solve the challenge, a new credential-embedded authentication and key agreement scheme (CAKA) is proposed, which can seamlessly combine DID-credentials into AKA. First, CAKA supports bilateral authentication by allowing a digital user to authenticate its service provider, which can enhance the security of unilateral scheme (such as CanDID, IEEE S&P, 2021) and prevent phishing query attacks. Second, for secure data session communication, the user’s DID-credentials are used as the kernel of the session key (SK) generation. In security analysis and performance metrics comparisons, the results indicate that CAKA holds a significant advantage, especially, the storage costs, communication costs and computation costs consumed in CAKA are at least 43% reduction, compared to alternatives. In simulation experiments of CAKA, the results show that decentralized identity authentication and session key agreement are both less than 15 ms, that means CAKA is a practical and promising solution to medical data sharing.
Data aggregation technology plays a very important role in improving the efficiency of data collection of the Internet of Things (IoT). Most data collected by sensor nodes (SNs) in IoT is multidimensional. However, there are a few existing multidimensional data aggregation schemes, which are almost based on homomorphic encryption and not suitable for resource-constrained IoT smart devices. In addition, when SNs cannot upload in time for some reason, such as device error or network interruption, the control center cannot get the correct aggregation result, i.e., robustness is not considered in most schemes. Therefore, we propose a lightweight and robust multidimensional data aggregation scheme for IoT. First, multidimensional data is packaged into 1-D data based on the Chinese remainder theorem (CRT), which greatly reduces communication and storage overhead. Second, the encryption in our scheme only uses addition operations without the costly additive homomorphic encryption. At the same time, our proposed scheme supports batch verification, which reduces the computation complexity of bilinear pairs by nearly half. Third, our scheme also supports dynamic SNs management and fault tolerance, enabling scalability and robustness. Finally, performance evaluation shows that our scheme has lower communication overhead and is more suitable for resource-constrained IoT scenarios.
Cloud storage has benefited millions of users with its remarkable advantages of economy and flexibility. Since a single cloud service provider is not always reliable and prone to a single point of failure, multi-cloud storage is proposed to enhance data availability. However, cross multiple clouds (cross-cloud) auditing to provide users with the integrity verification of outsourced data also faces many challenges, such as the fact that a large quantity of existing schemes rely heavily on the trusted third-party. Therefore, we propose a decentralized data storage and integrity auditing scheme for multi-cloud scenarios to eliminate the dependence on the third-party, namely BDDR, and an improved version iBDDR with stronger security. Firstly, both BDDR and iBDDR adopt multi-cloud data storage and support batch auditing to greatly save computation costs. Secondly, our schemes not only get rid of a third-party, but also do not require a dispute arbitration since the outsourced data can be verified by cloud server providers via the homomorphic verifiable tags published on the blockchain. Thirdly, locating the corrupted cloud server providers and accurately recovering the corrupted data at a lower communication and computation costs are supported. Finally, security and performance analyses demonstrate the security and effectiveness of our schemes.
With the rapid development of Internet of Things, the related data are growing explosively. However, IoT devices have limited storage and computing capabilities so that they cannot deal with massive data storage and computing locally. The integration of IoT and cloud is regarded as an effective solution to the above issue, i.e., IoT devices outsource collected data to cloud to enjoy powerful storage and computing resources. Because the data stored in cloud are out of the control of IoT users, some security risks need to be addressed in advance. In this article, we propose a public data integrity verification scheme, called AIVCI, to check the data integrity for Cloud-IoT scenarios. First, based on algebraic signature and homomorphic hash function, AIVCI can efficiently complete data auditing. Second, AIVCI adopts blind technology to prevent the privacy leakage of IoT data and further protect the privacy of IoT users. Third, batch auditing is implemented to improve auditing efficiency and meet realistic demands for Cloud-IoT scenarios. And a new data structure named Improved Divide and Conquer Table (ID&CT) is designed to realize efficient data dynamics. Finally, the security and performance analyses demonstrate that AIVCI is more secure and efficient.
Since the powerful storage capacity of the cloud platform, more and more people are willing to store their files on the cloud service provider (CSP). In order to prevent the privacy of outsourced files from being leaked, data owners will encrypt files before uploading. However, encryption will significantly limit the accurate location of the files. Therefore, this paper mainly introduces a verifiable multi-keyword searchable encryption scheme supporting keywords updating (VMSE). First of all, our proposed VMSE scheme can achieve multiple keywords search while protecting the privacy of the outsourced files and users. Then, our VMSE scheme can also implement the integrity verification and decryption of search results, which are not considered in many existing multi-keyword searchable encryption schemes. Currently, the dynamics in search schemes mostly refer to the dynamic update of outsourced files or user’s search permissions. We consider the keyword dynamic update of outsourced files in this paper, which is a design challenge for searchable encryption schemes and achieved by few searchable encryption schemes. Finally, performance evaluation shows our scheme is efficient and feasible in practical application.
The data aggregation technique has been widely adopted in the Internet of Things (IoT) to protect data privacy while ensuring data availability. Homomorphic encryption is a typical technique that guarantees accurate computing results. However, it brings heavy computation overhead for edge nodes and exposes the aggregated results to the central server, which significantly threatens the confidentiality of results. This article gets rid of the server-centric style existing in most data aggregation schemes and proposes a scalable and decentralized data aggregation scheme for edge-enabled IoT. In the proposed scheme, edge nodes can freely form, join, and exit from the data aggregation group to aggregate data correctly, securely, and efficiently. Besides, two structure-based data aggregation methods are proposed to reduce the aggregation overhead to $O(n\sqrt{n})$ with constant rounds, as opposed to $O(n\log n)$ with $O(n)$ round. Symmetric encryption and online/offline signature computation are adopted to mitigate the online computation burden. Moreover, the proposed scheme can rigorously defend against forgery attack, eavesdropping attack, and collusion attack. The performance evaluation and experiment results show that the proposed scheme improves the efficiency of communication with affordable computation costs for edge nodes.
Cloud storage provides data owners with massive storage and computing resources. To release from heavy data management and maintenance, more and more data owners are willing to outsource data to cloud. However, the data stored in cloud are out of the control of data owners, and may be corrupted and unretrievable. To solve the above problem, this paper proposes a decentralized auditing scheme BVA for the single cloud storage server, and an extended batch auditing scheme E-BVA for distributed storage. Firstly, BVA and E-BVA utilize vector commitment technology to realize lightweight data integrity auditing for outsourced data. Secondly, to avoid privacy and performance risks caused by the third party auditor, both BVA and E-BVA employ a smart contract on the blockchain as an auditor to perform data integrity auditing. Thirdly, both schemes support the verifiability between outsourced data and their corresponding authenticators, which prevents malicious data owners framing cloud storage servers and avoid subsequent dispute arbitration. Finally, based on regenerating code, E-BVA supports data self-repair of corrupted servers, while protecting the privacy of outsourced data and realizing the lightweight computation. The security and performance analyses demonstrate the security and efficiency of BVA and E-BVA.
In vehicular ad-hoc networks (VANETs), road traffic efficiency and road safety can be improved through message interaction and sharing between vehicle users, which inevitably depends on secure identity authentication and message credibility verification. However, security and privacy of message are the critical factors restricting VANETs’ development. Most existing protocols rely on the trusted third-party to achieve identity authentication and message, which are prone to system single points of failure and low efficiency. To address these challenges, in 2021, Vasudev and Das proposed a privacy preserving secure hash based authentication and revelation protocol. They claimed that their protocol can resist various known attacks, e.g. modification, man-in-the-middle, TPD stolen attack, et al. Unfortunately, in this paper, we found that their protocol does not address above-mentioned problems and has other devastating security bugs. Attacker can easily obtain vehicle’s original/real identity, pseudo-identity and password, which are the cornerstone of their protocol security. In other words, the attacker successfully can launch any attacks including those mentioned above to destroy the whole system. Then, a novel secure privacy-preserving traceable authentication protocol (abbreviated to PTAP) is proposed. The PTAP not only mitigates the weaknesses, but has other advantages. First, the PTAP uses semi-honest RSUs to realize interaction between stakeholders without the help of trusted third-party in extremely low computational cost (reducing 32.75% in vehicle side). Second, the PTAP can enable vehicles to enjoy the remote services with identity anonymity protection and location privacy (traceability when needed). Finally, the PTAP is proven to be safe against passive and active attacks under CDHP assumption and CL-eCK model. Hence, these features make the PTAP very suitable for high safety coefficient and computation-limited mobile devices (such as TPD) compared with other related existing protocols.
With the rise of online cloud files, more and more online files are generated by group cooperation in recent years. However, there exist many security problems to be solved urgently for online cooperation files, such as how to verify the integrity of group cooperation files and realize its dynamic update and how to further trace the identity of signer (i.e., operator) who upload or update the group cooperation files. To address the above problems, we propose a secure public integrity auditing scheme for group cooperation files in this paper, named PAGCF. First, PAGCF not only can verify the integrity of group cooperation files, but also supports the dynamic update of group cooperation files via the skip list. Second, any legitimate user can trace the identity of signer to resist malicious tampering and workload disputes of group users. Additionally, PAGCF also achieves user stateless without requiring users to maintain a list locally. Third, PAGCF not only can realize effective group user revocation so that revoked users lose privileges to update the group cooperation file and trace the identity of signer, but also can resist the collusion attack of malicious adversaries and revoked users. Finally, numeric analyses and experiment results demonstrate the efficiency of our proposed scheme.
With the rapid development of 5G technology and wireless networks, new applications such as VR/AR-based immersive online games have developed rapidly. These applications are very sensitive to network delays. To address the time delay of data transfer, the vendors of these delay-sensitive applications often deploy data replicas on edge servers to provide users with a low-latency application experience. However, the edge computing environment is highly distributed and dynamic, which makes the data replicas stored on edge servers often face intentional or unintentional damage. In addition, the computing resources of edge servers are very limited compared to cloud servers. Therefore, how to efficiently audit the integrity of data replicas stored on a large number of edge servers becomes an urgent problem to be solved. This paper first designs a data integrity verification scheme called EDI-DA in edge environment to help application vendors to check the integrity of data replicas stored on distributed edge servers. Then, we extend EDI-DA to allow application vendors to verify the integrity of different edge data replicas simultaneously, i.e., our EDI-DA supports batch auditing of multiple original data. Next, we propose an improved data structure I-SLT based on which EDI-DA supports full data dynamics, including insertion, deletion and modification. Finally, security and performance analyses indicate the security and practicability of our EDI-DA.
With the increase of smart devices, edge computing is becoming a new computing paradigm that coexist with centralized cloud computing to process data distributed at the edge of the network. Based on this new paradigm, app vendors can store data replicas on geographically distributed edge servers to serve surrounding users to reduce access delay. However, since edge servers have limited storage space and computing ability, these edge data are vulnerable to various corruption. Therefore, how to efficiently audit the integrity of edge data has become an urgent problem to be solved. To tackle the Edge Data Integrity (EDI) problem, we propose a lightweight auditing scheme, namely EDI-SA. Firstly, inspired by the shuffle algorithm and the bucket sorting algorithm, we propose an improved sampling algorithm, which is a new lightweight challenge block sampling method. Secondly, based on algebraic signature, EDI-SA can achieve efficient aggregation verification and the signature computation cost is independent of the number of data blocks, which greatly reduces the computation overhead of app vendors and edge servers. Thirdly, EDI-SA supports batch auditing and provable dynamic update, app vendors can also uniquely locate the corrupted edge data. Finally, security and performance analyses demonstrate the security and effectiveness of EDI-SA.
With the popularity of cloud storage, increasing users begin to outsource data to the cloud. In order to resist possible data analysis for centralized outsourced data and improve the fault tolerance, users prefer to distribute data to cloud servers of different cloud service providers. However, once the data have been outsourced, it will be out of user’s control and many security issues may occur, such as outsourced data being illegally tamper with, or rarely accessed data being secretly deleted. In this article, we propose a decentralized self-auditing scheme for multi-cloud storage, called DSAS. First, based on the symmetric balanced incomplete block design, DSAS achieves integrity verification for outsourced data via the interactions of cloud servers and the auditing costs are shared by the participating CSs. Second, DSAS can locate misbehavior cloud server with low computation costs, and resist denial of service attack initiated by malicious cloud servers which attempts to destroy the audit. Third, DSAS can recover the corrupted data without fetching data, and support the revocation of cloud servers and batch auditing. Finally, security proof and function evaluation show that DSAS has comprehensive security and functionality, and performance simulations and experiment results show that DSAS is efficient.
With the rapid development of computer technology and medical imaging technology, medical images present an explosive growth. To save storage and computation overhead, hospitals often choose to outsource digital medical images to cloud server. Since medical images are a major auxiliary means for doctors’ diagnosis or medical researchers’ study, the secure retrieval of outsourced medical images is especially important. To address this problem, we propose a Faster outsourced Medical Image Retrieval scheme with privacy preservation (FMIR) in this paper. FMIR first makes a simple classification to outsourced medical images, which narrows the retrieval range and improves the retrieval efficiency compared with the existing unclassified retrieval schemes. Second, FMIR implements a lightweight access control for each class using polynomial-based access control strategy, which provides the fine-grained access control for better privacy protection of medical images. Third, FMIR reduces the interference of random numbers on relevant score to 0, which further improves the accuracy of the retrieval. Finally, the security and performance analysis show that FMIR is secure, accurate and efficient.
The keyword-based searchable encryption is a very promising technology in the cloud storage, which can supply data users with accurate search services over encrypted data based on queried keywords. An important security objective of this kind of schemes is to resist keyword privacy leakage because it may cause content leakage of to data itself and search preferences of data users. To protect keyword privacy, the existing methods mainly are implemented by keyword ciphertext indistinguishability and trapdoor indistinguishability. And there is few works to resist keyword privacy leakage from access pattern and search pattern simultaneously, which will inevitably affects the further application of this promising technology. In order to avoid keyword privacy leakage from above two patterns, we first construct a novel secure keyword index called the global index pair which is used to construct a k-nearest neighbour search, i.e., a data user can always receive the top-k encrypted files which are the most relevant to the search query. To effectively save computing costs and storage costs for DUs, a new order-preserving transformation is designed in our scheme to generate trapdoor without DUs computing the inverse of matrix. Secondly, our construction is independent of a specific searchable encryption scheme. Any kind of a keyword-based searchable encryption scheme can apply our method to resist the keyword privacy leakage both from access pattern and search pattern. Finally, the detailed security analyses are given to demonstrate that the advantage of any Level-3 attacker launching efficient inside attack from search pattern and access pattern is negligible, i.e., our construction can protect the keyword privacy against an inside attacker.