Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

Singapore Management University

Discipline
Keyword
Publication Year
Publication
Publication Type

Articles 361 - 390 of 1102

Full-Text Articles in Information Security

White-Box Fairness Testing Through Adversarial Sampling, Peixin Zhang, Jingyi Wang, Jun Sun, Guoliang Dong, Xinyu Wang, Xingen Wang, Jin Song Dong, Dai Ting Oct 2020

White-Box Fairness Testing Through Adversarial Sampling, Peixin Zhang, Jingyi Wang, Jun Sun, Guoliang Dong, Xinyu Wang, Xingen Wang, Jin Song Dong, Dai Ting

Research Collection School Of Computing and Information Systems

Although deep neural networks (DNNs) have demonstrated astonishing performance in many applications, there are still concerns on their dependability. One desirable property of DNN for applications with societal impact is fairness (i.e., non-discrimination). In this work, we propose a scalable approach for searching individual discriminatory instances of DNN. Compared with state-of-the-art methods, our approach only employs lightweight procedures like gradient computation and clustering, which makes it significantly more scalable than existing methods. Experimental results show that our approach explores the search space more effectively (9 times) and generates much more individual discriminatory instances (25 times) using much less time (half …


Revisiting The Law Of Confidence In Singapore And A Proposal For A New Tort Of Misuse Of Private Information, Cheng Lim Saw, Zheng Wen Samuel Chan, Wen Min Chai Oct 2020

Revisiting The Law Of Confidence In Singapore And A Proposal For A New Tort Of Misuse Of Private Information, Cheng Lim Saw, Zheng Wen Samuel Chan, Wen Min Chai

Research Collection Yong Pung How School Of Law

This article critically examines the recent Court of Appeal decision in I-Admin (Singapore) Pte Ltd v Hong Ying Ting [2020] 1 SLR 1130 and its implications for the law of confidence. The article begins by setting out the decision at first instance, and then on appeal. It argues that the Court of Appeal’s “modified approach” fails to meaningfully engage the plaintiff ’s wrongful gain interest and places the law’s emphasis primarily, if not wholly, on the plaintiff ’s wrongful loss interest. The new framework also appears to have been influenced by English jurisprudence, which has had a long but unhelpful …


Revocable And Certificateless Public Auditing For Cloud Storage, Yinghui Zhang, Tiantian Zhang, Shengmin Xu, Guowen Xu, Dong Zheng Oct 2020

Revocable And Certificateless Public Auditing For Cloud Storage, Yinghui Zhang, Tiantian Zhang, Shengmin Xu, Guowen Xu, Dong Zheng

Research Collection School Of Computing and Information Systems

Plenty of computing and storage resources in the cloud are provided for users with restricted computing and storage resources, which has attracted the attention of many researchers. A generic blockchain-based cloud data auditing scheme is proposed, which is compatible with any blockchains including the bitcoin blockchain. In the data integrity checking scheme, certificateless signature (CLS) can be used to verify the identity of users. Besides, the key exchange is utilized in the key generation, which can eliminate the security channel to achieve system robustness. Considering the real situation, the users who join the cloud storage system may be revoked for …


Efficient Ciphertext-Policy Attribute-Based Encryption With Blackbox Traceability, Shengmin Xu, Jiaming Yuan, Guowen Xu, Yingjiu Li, Ximeng Liu, Yinghui Zhang, Zuobin Yang Oct 2020

Efficient Ciphertext-Policy Attribute-Based Encryption With Blackbox Traceability, Shengmin Xu, Jiaming Yuan, Guowen Xu, Yingjiu Li, Ximeng Liu, Yinghui Zhang, Zuobin Yang

Research Collection School Of Computing and Information Systems

Traitor tracing scheme is a paradigm to classify the users who illegal use of their decryption keys in cryptosystems. In the ciphertext-policy attribute-based cryptosystem, the decryption key usually contains the users’ attributes, while the real identities are hidden. The decryption key with hidden identities enables malicious users to intentionally leak decryption keys or embed the decryption keys in the decryption device to gain illegal profits with a little risk of being discovered. To mitigate this problem, the concept of blackbox traceability in the ciphertext-policy attribute-based scheme was proposed to identify the malicious user via observing the I/O streams of the …


Catch You If You Deceive Me: Verifiable And Privacy-Aware Truth Discovery In Crowdsensing Systems, Guowen Xu, Hongwei Li, Shengmin Xu, Hao Ren, Yonghui Zhang, Jianfei Sun, Robert H. Deng Oct 2020

Catch You If You Deceive Me: Verifiable And Privacy-Aware Truth Discovery In Crowdsensing Systems, Guowen Xu, Hongwei Li, Shengmin Xu, Hao Ren, Yonghui Zhang, Jianfei Sun, Robert H. Deng

Research Collection School Of Computing and Information Systems

Truth Discovery (TD) is to infer truthful information by estimating the reliability of users in crowdsensing systems. To protect data privacy, many Privacy-Preserving Truth Discovery (PPTD) approaches have been proposed. However, all existing PPTD solutions do not consider a fundamental issue of trust. That is, if the data aggregator (e.g., the cloud server) is not trustworthy, how can an entity be convinced that the data aggregator has correctly performed the PPTD? A "lazy"cloud server may partially follow the deployed protocols to save its computing and communication resources, or worse, maliciously forge the results for some shady deals. In this paper, …


Attribute-Based Fine-Grained Access Control For Outscored Private Set Intersection Computation, Mohammad Ali, Mohajeri Javad, Mohammad-Reza Sadeghi, Ximeng Liu Oct 2020

Attribute-Based Fine-Grained Access Control For Outscored Private Set Intersection Computation, Mohammad Ali, Mohajeri Javad, Mohammad-Reza Sadeghi, Ximeng Liu

Research Collection School Of Computing and Information Systems

Private set intersection (PSI) is a fundamental cryptographic protocol which has a wide range of applications. It enables two clients to compute the intersection of their private datasets without revealing non-matching elements. The advent of cloud computing drives the ambition to reduce computation and data management overhead by outsourcing such computations. However, since the cloud is not trustworthy, some cryptographic methods should be applied to maintain the confidentiality of datasets. But, in doing so, data owners may be excluded from access control on their outsourced datasets. Therefore, to control access rights and to interact with authorized users, they have to …


Towards Systematically Deriving Defence Mechanisms From Functional Requirements Of Cyber-Physical Systems, Cheah Huei Yoong, Venkata Reddy Palleti, Arlindo Silva, Christopher M. Poskitt Oct 2020

Towards Systematically Deriving Defence Mechanisms From Functional Requirements Of Cyber-Physical Systems, Cheah Huei Yoong, Venkata Reddy Palleti, Arlindo Silva, Christopher M. Poskitt

Research Collection School Of Computing and Information Systems

The threats faced by cyber-physical systems (CPSs) in critical infrastructure have motivated the development of different attack detection mechanisms, such as those that monitor for violations of invariants, i.e. properties that always hold in normal operation. Given the complexity of CPSs, several existing approaches focus on deriving invariants automatically from data logs, but these can miss possible system behaviours if they are not represented in that data. Furthermore, resolving any design flaws identified in this process is costly, as the CPS is already built. In this position paper, we propose a systematic method for deriving invariants before a CPS is …


Lis: Lightweight Signature Schemes For Continuous Message Authentication In Cyber-Physical Systems, Zheng Yang, Chenglu Jin, Yangguang Tian, Junyu Lai, Jianying Zhou Oct 2020

Lis: Lightweight Signature Schemes For Continuous Message Authentication In Cyber-Physical Systems, Zheng Yang, Chenglu Jin, Yangguang Tian, Junyu Lai, Jianying Zhou

Research Collection School Of Computing and Information Systems

Cyber-Physical Systems (CPS) provide the foundation of our critical infrastructures, which form the basis of emerging and future smart services and improve our quality of life in many areas. In such CPS, sensor data is transmitted over the network to the controller, which will make real-time control decisions according to the received sensor data. Due to the existence of spoofing attacks (more specifically to CPS, false data injection attacks), one has to protect the authenticity and integrity of the transmitted data. For example, a digital signature can be used to solve this issue. However, the resource-constrained field devices like sensors …


Two-Stage Photograph Cartoonization Via Line Tracing, Simin Li, Qiang Wen, Shuang Zhao, Zixun Sun, Shengfeng He Oct 2020

Two-Stage Photograph Cartoonization Via Line Tracing, Simin Li, Qiang Wen, Shuang Zhao, Zixun Sun, Shengfeng He

Research Collection School Of Computing and Information Systems

Cartoon is highly abstracted with clear edges, which makes it unique from the other art forms. In this paper, we focus on the essential cartoon factors of abstraction and edges, aiming to cartoonize real-world photographs like an artist. To this end, we propose a two-stage network, each stage explicitly targets at producing abstracted shading and crisp edges respectively. In the first abstraction stage, we propose a novel unsupervised bilateral flattening loss, which allows generating high-quality smoothing results in a label-free manner. Together with two other semantic-aware losses, the abstraction stage imposes different forms of regularization for creating cartoon-like flattened images. …


Hierarchical Identity-Based Signature In Polynomial Rings, Zhichao Yang, Dung H. Duong, Willy Susilo, Guomin Yang, Chao Li, Rongmao Chen Oct 2020

Hierarchical Identity-Based Signature In Polynomial Rings, Zhichao Yang, Dung H. Duong, Willy Susilo, Guomin Yang, Chao Li, Rongmao Chen

Research Collection School Of Computing and Information Systems

Hierarchical identity-based signature (HIBS) plays a core role in a large community as it significantly reduces the workload of the root private key generator. To make HIBS still available and secure in post-quantum era, constructing lattice-based schemes is a promising option. In this paper, we present an efficient HIBS scheme in polynomial rings. Although there are many lattice-based signatures proposed in recent years, to the best of our knowledge, our HIBS scheme is the first ring-based construction. In the center of our construction are two new algorithms to extend lattice trapdoors to higher dimensions, which are non-trivial and of independent …


Presentation Of Computer Security Risk Information: Impact Of Framing And Base Size, Xinhui Zhan, Fiona Fui-Hoon Nah, Keng Siau, Richard Hall, Maggie Cheng Oct 2020

Presentation Of Computer Security Risk Information: Impact Of Framing And Base Size, Xinhui Zhan, Fiona Fui-Hoon Nah, Keng Siau, Richard Hall, Maggie Cheng

Research Collection School Of Computing and Information Systems

This research explores how the presentation of computer security risks impacts users’ risk perceptions and behavior. It draws on Prospect Theory to generate hypotheses related to users’ decision-making in the computer security context. A 2 × 3 mixed factorial experimental design (N = 178) was carried out and the results show that framing and base size of information on computer security risks influence users’ perceived risk and risk-taking behavior. More specifically, negative framing and large base size increase users’ perceived risk and reduce users’ risk-taking behavior. The findings from this research suggest that using negative framing and large base size …


Efficient Fine-Grained Data Sharing Mechanism For Electronic Medical Record Systems With Mobile Devices, Hui Ma, Rui Zhang, Guomin Yang, Zishuai Zong, Kai He, Yuting Xiao Sep 2020

Efficient Fine-Grained Data Sharing Mechanism For Electronic Medical Record Systems With Mobile Devices, Hui Ma, Rui Zhang, Guomin Yang, Zishuai Zong, Kai He, Yuting Xiao

Research Collection School Of Computing and Information Systems

Sharing digital medical records on public cloud storage via mobile devices facilitates patients (doctors) to get (offer) medical treatment of high quality and efficiency. However, challenges such as data privacy protection, flexible data sharing, efficient authority delegation, computation efficiency optimization, are remaining toward achieving practical fine-grained access control in the Electronic Medical Record (EMR) system. In this work, we propose an innovative access control model and a fine-grained data sharing mechanism for EMR, which simultaneously achieves the above-mentioned features and is suitable for resource-constrained mobile devices. In the model, complex computation is outsourced to public cloud servers, leaving almost no …


Coronavirus: Pandemics, Artificial Intelligence And Personal Data: How To Manage Pandemics Using Ai And What That Means For Personal Data Protection, Warren B. Chik Sep 2020

Coronavirus: Pandemics, Artificial Intelligence And Personal Data: How To Manage Pandemics Using Ai And What That Means For Personal Data Protection, Warren B. Chik

Research Collection Yong Pung How School Of Law

This chapter discusses the hearing of essential and urgent court matters in the Singapore courts during the COVID-19 pandemic. On 27 march 2020, the Singapore judiciary notified courst users that remote hearings were to be implemented for certain types of hearings by means of video and telephone conferencing facilities. Court users were also provided with indicative lists of matters which might be considered essential and urgent.


Coronavirus: Pandemics, Artificial Intelligence And Personal Data: How To Manage Pandemics Using Ai And What That Means For Personal Data Protection, Warren B. Chik Sep 2020

Coronavirus: Pandemics, Artificial Intelligence And Personal Data: How To Manage Pandemics Using Ai And What That Means For Personal Data Protection, Warren B. Chik

Research Collection Yong Pung How School Of Law

This chapter discusses the hearing of essential and urgent court matters in the Singapore courts during the COVID-19 pandemic. On 27 march 2020, the Singapore judiciary notified courst users that remote hearings were to be implemented for certain types of hearings by means of video and telephone conferencing facilities. Court users were also provided with indicative lists of matters which might be considered essential and urgent.


Pine: Enabling Privacy-Preserving Deep Packet Inspection On Tls With Rule-Hiding And Fast Connection Establishment, Jianting Ning, Xinyi Huang, Geong Sen Poh, Shengmin Xu, Jia-Chng Loh, Jain Weng, Robert H. Deng Sep 2020

Pine: Enabling Privacy-Preserving Deep Packet Inspection On Tls With Rule-Hiding And Fast Connection Establishment, Jianting Ning, Xinyi Huang, Geong Sen Poh, Shengmin Xu, Jia-Chng Loh, Jain Weng, Robert H. Deng

Research Collection School Of Computing and Information Systems

Transport Layer Security Inspection (TLSI) enables enterprises to decrypt, inspect and then re-encrypt users’ traffic before it is routed to the destination. This breaks the end-to-end security guarantee of the TLS specification and implementation. It also raises privacy concerns since users’ traffic is now known by the enterprises, and third-party middlebox providers providing the inspection services may additionally learn the inspection or attack rules, policies of the enterprises. Two recent works, BlindBox (SIGCOMM 2015) and PrivDPI (CCS 2019) propose privacy-preserving approaches that inspect encrypted traffic directly to address the privacy concern of users’ traffic. However, BlindBox incurs high preprocessing overhead …


Privacy-Preserving Outsourced Calculation Toolkit In The Cloud, Ximeng Liu, Robert H. Deng, Kim-Kwang Raymond Choo, Yang Yang, Hwee Hwa Pang Sep 2020

Privacy-Preserving Outsourced Calculation Toolkit In The Cloud, Ximeng Liu, Robert H. Deng, Kim-Kwang Raymond Choo, Yang Yang, Hwee Hwa Pang

Research Collection School Of Computing and Information Systems

In this paper, we propose a privacy-preserving outsourced calculation toolkit, Pockit, designed to allow data owners to securely outsource their data to the cloud for storage. The outsourced encrypted data can be processed by the cloud server to achieve commonly-used plaintext arithmetic operations without involving additional servers. Specifically, we design both signed and unsigned integer circuits using a fully homomorphic encryption (FHE) scheme, construct a new packing technique (hereafter referred to as integer packing), and extend the secure circuits to its packed version. This achieves significant improvements in performance compared with the original secure signed/unsigned integer circuit. The secure integer …


A Lattice-Based Key-Insulated And Privacy-Preserving Signature Scheme With Publicly Derived Public Key, Wenling Liu, Zhen Liu, Khoa Nguyen, Guomin Yang, Yu Yu Sep 2020

A Lattice-Based Key-Insulated And Privacy-Preserving Signature Scheme With Publicly Derived Public Key, Wenling Liu, Zhen Liu, Khoa Nguyen, Guomin Yang, Yu Yu

Research Collection School Of Computing and Information Systems

As a widely used privacy-preserving technique for cryptocurrencies, Stealth Address constitutes a key component of Ring Confidential Transaction (RingCT) protocol and it was adopted by Monero, one of the most popular privacy-centric cryptocurrencies. Recently, Liu et al. [EuroS&P 2019] pointed out a flaw in the current widely used stealth address algorithm that once a derived secret key is compromised, the damage will spread to the corresponding master secret key, and all the derived secret keys thereof. To address this issue, Liu et al. introduced Key-Insulated and Privacy-Preserving Signature Scheme with Publicly Derived Public Key (PDPKS scheme), which captures the functionality, …


Attribute-Based Encryption For Cloud Computing Access Control: A Survey, Yinghui Zhang, Robert H. Deng, Shengmin Xu, Jianfei Sun, Qi Li, Dong Zheng Sep 2020

Attribute-Based Encryption For Cloud Computing Access Control: A Survey, Yinghui Zhang, Robert H. Deng, Shengmin Xu, Jianfei Sun, Qi Li, Dong Zheng

Research Collection School Of Computing and Information Systems

Attribute-based encryption (ABE) for cloud computing access control is reviewed in this article. A taxonomy and comprehensive assessment criteria of ABE are first proposed. In the taxonomy, ABE schemes are assorted into key-policy ABE (KP-ABE) schemes, ciphertext-policy ABE (CP-ABE) schemes, anti-quantum ABE schemes, and generic constructions. In accordance with cryptographically functional features, CP-ABE is further divided into nine subcategories with regard to basic functionality, revocation, accountability, policy hiding, policy updating, multi-authority, hierarchy, offline computation, and outsourced computation. In addition, a systematical methodology for discussing and comparing existing ABE schemes is proposed. For KP-ABE and each type of CP-ABE, the corresponding …


Privacy Preserving Search Services Against Online Attack, Yi Zhao, Jianting Nian, Kaitai Liang, Yanqi Zhao, Liqun Chen, Bo Yang Aug 2020

Privacy Preserving Search Services Against Online Attack, Yi Zhao, Jianting Nian, Kaitai Liang, Yanqi Zhao, Liqun Chen, Bo Yang

Research Collection School Of Computing and Information Systems

Searchable functionality is provided in many online services such as mail services or outsourced data storage. To protect users privacy, data in these services is usually stored after being encrypted using searchable encryption. This enables the data user to securely search encrypted data from a remote server without leaking data and query information. Public key encryption with keyword search is one of the research branches of searchable encryption; this provides privacy-preserving searchable functionality for applications such as encrypted email systems. However, it has an inherent vulnerability in that the information of a query may be leaked using a keyword guessing …


A Generalised Bound For The Wiener Attack On Rsa, Willy Susilo, Joseph Tonien, Guomin Yang Aug 2020

A Generalised Bound For The Wiener Attack On Rsa, Willy Susilo, Joseph Tonien, Guomin Yang

Research Collection School Of Computing and Information Systems

Since Wiener pointed out that the RSA can be broken if the private exponent d is relatively small compared to the modulus N, it has been a general belief that the Wiener attack works for d


Measuring Privacy Concerns With Government Surveillance And Right-To-Be-Forgotten In Nomological Net Of Trust And Willingness-To-Share, Gaurav Bansal, Fiona Fui-Hoon Nah Aug 2020

Measuring Privacy Concerns With Government Surveillance And Right-To-Be-Forgotten In Nomological Net Of Trust And Willingness-To-Share, Gaurav Bansal, Fiona Fui-Hoon Nah

Research Collection School Of Computing and Information Systems

In the post Snowden revelations era, concerns related to government surveillance and oversight have come to the forefront. The ability of the Internet to remember “everything” (or forget anything) also raises a privacy concern associated with the “right to be forgotten”. Hence, in this paper, we propose and examine privacy concerns by extending the Hong and Thong’s (2013) model with the addition of two dimensions: right to be forgotten as well as government surveillance and oversight. We tested two different measurement models using privacy concerns as a second-order and a third-order construct within a nomological net that includes trusting beliefs …


Designing Leakage-Resilient Password Entry On Head-Mounted Smart Wearable Glass Devices, Yan Li, Yao Cheng, Wenzhi Meng, Yingjiu Li, Robert H. Deng Jul 2020

Designing Leakage-Resilient Password Entry On Head-Mounted Smart Wearable Glass Devices, Yan Li, Yao Cheng, Wenzhi Meng, Yingjiu Li, Robert H. Deng

Research Collection School Of Computing and Information Systems

With the boom of Augmented Reality (AR) and Virtual Reality (VR) applications, head-mounted smart wearable glass devices are becoming popular to help users access various services like E-mail freely. However, most existing password entry schemes on smart glasses rely on additional computers or mobile devices connected to smart glasses, which require users to switch between different systems and devices. This may greatly lower the practicability and usability of smart glasses. In this paper, we focus on this challenge and design three practical anti-eavesdropping password entry schemes on stand-alone smart glasses, named gTapper, gRotator and gTalker. The main idea is to …


Search Me In The Dark: Privacy-Preserving Boolean Range Query Over Encrypted Spatial Data, Xiangyu Wang, Jianfeng Ma, Ximeng Liu, Robert H. Deng, Yinbin Miao, Dan Zhu, Zhuoran Ma Jul 2020

Search Me In The Dark: Privacy-Preserving Boolean Range Query Over Encrypted Spatial Data, Xiangyu Wang, Jianfeng Ma, Ximeng Liu, Robert H. Deng, Yinbin Miao, Dan Zhu, Zhuoran Ma

Research Collection School Of Computing and Information Systems

With the increasing popularity of geo-positioning technologies and mobile Internet, spatial keyword data services have attracted growing interest from both the industrial and academic communities in recent years. Meanwhile, a massive amount of data is increasingly being outsourced to cloud in the encrypted form for enjoying the advantages of cloud computing while without compromising data privacy. Most existing works primarily focus on the privacy-preserving schemes for either spatial or keyword queries, and they cannot be directly applied to solve the spatial keyword query problem over encrypted data. In this paper, we study the challenging problem of Privacy-preserving Boolean Range Query …


Camps: Efficient And Privacy-Preserving Medical Primary Diagnosis Over Outsourced Cloud, Jianfeng Hua, Guozhen Shi, Hui Zhu, Fengwei Wang, Ximeng Liu, Hao Li Jul 2020

Camps: Efficient And Privacy-Preserving Medical Primary Diagnosis Over Outsourced Cloud, Jianfeng Hua, Guozhen Shi, Hui Zhu, Fengwei Wang, Ximeng Liu, Hao Li

Research Collection School Of Computing and Information Systems

With the flourishing of ubiquitous healthcare and cloud computing technologies, medical primary diagnosis system, which forms a critical capability to link big data analysis technologies with medical knowledge, has shown great potential in improving the quality of healthcare services. However, it still faces many severe challenges on both users' medical privacy and intellectual property of healthcare service providers, which deters the wide adoption of medical primary diagnosis system. In this paper, we propose an efficient and privacy-preserving medical primary diagnosis framework (CAMPS). Within CAMPS framework, the precise diagnosis models are outsourced to the cloud server in an encrypted manner, and …


Privacy-Enhanced Remote Data Integrity Checking With Updatable Timestamp, Tong Wu, Guomin Yang, Yi Mu, Rongmao Chen, Shengmin Xu Jul 2020

Privacy-Enhanced Remote Data Integrity Checking With Updatable Timestamp, Tong Wu, Guomin Yang, Yi Mu, Rongmao Chen, Shengmin Xu

Research Collection School Of Computing and Information Systems

Remote data integrity checking (RDIC) enables clients to verify whether the outsourced data is intact without keeping a copy locally or downloading it. Nevertheless, the existing RDIC schemes do not support the pay-as-you-go (PAYG) payment model, where the payment is decided by the volume and duration of the outsourced data. Specifically, none of the existing works have considered the client’s control over changes in storage duration. In this paper, we propose an RDIC scheme to simultaneously check the data content and storage duration represented by an updatable timestamp via the third-party auditor (TPA). Also, our proposed scheme achieves indistinguishable privacy …


Lightweight And Privacy-Aware Fine-Grained Access Control For Iot-Oriented Smart Health, Jianfei Sun, Hu Xiong, Ximeng Liu, Yinghui Zhang, Xuyun Nie, Robert H. Deng Jul 2020

Lightweight And Privacy-Aware Fine-Grained Access Control For Iot-Oriented Smart Health, Jianfei Sun, Hu Xiong, Ximeng Liu, Yinghui Zhang, Xuyun Nie, Robert H. Deng

Research Collection School Of Computing and Information Systems

With the booming of Internet of Things (IoT), smart health (s-health) is becoming an emerging and attractive paradigm. It can provide an accurate prediction of various diseases and improve the quality of healthcare. Nevertheless, data security and user privacy concerns still remain issues to be addressed. As a high potential and prospective solution to secure IoT-oriented s-health applications, ciphertext policy attribute-based encryption (CP-ABE) schemes raise challenges, such as heavy overhead and attribute privacy of the end users. To resolve these drawbacks, an optimized vector transformation approach is first proposed to efficiently transform the access policy and user attribute set into …


Answer Ranking For Product-Related Questions Via Multiple Semantic Relations Modeling, Wenxuan Zhang, Yang Deng, Wai Lam Jul 2020

Answer Ranking For Product-Related Questions Via Multiple Semantic Relations Modeling, Wenxuan Zhang, Yang Deng, Wai Lam

Research Collection School Of Computing and Information Systems

Many E-commerce sites now offer product-specific question answering platforms for users to communicate with each other by posting and answering questions during online shopping. However, the multiple answers provided by ordinary users usually vary diversely in their qualities and thus need to be appropriately ranked for each question to improve user satisfaction. It can be observed that product reviews usually provide useful information for a given question, and thus can assist the ranking process. In this paper, we investigate the answer ranking problem for product-related questions, with the relevant reviews treated as auxiliary information that can be exploited for facilitating …


Bridging Hierarchical And Sequential Context Modeling For Question-Driven Extractive Answer Summarization, Yang Deng, Wenxuan Zhang, Yaliang Li, Min Yang, Wai Lam, Ying Shen Jul 2020

Bridging Hierarchical And Sequential Context Modeling For Question-Driven Extractive Answer Summarization, Yang Deng, Wenxuan Zhang, Yaliang Li, Min Yang, Wai Lam, Ying Shen

Research Collection School Of Computing and Information Systems

Non-factoid question answering (QA) is one of the most extensive yet challenging application and research areas of retrieval-based question answering. In particular, answers to non-factoid questions can often be too lengthy and redundant to comprehend, which leads to the great demand on answer sumamrization in non-factoid QA. However, the multi-level interactions between QA pairs and the interrelation among different answer sentences are usually modeled separately on current answer summarization studies. In this paper, we propose a unified model to bridge hierarchical and sequential context modeling for question-driven extractive answer summarization. Specifically, we design a hierarchical compare-aggregate method to integrate the …


Understanding Android Voip Security: A System-Level Vulnerability Assessment, En He, Daoyuan Wu, Robert H. Deng Jun 2020

Understanding Android Voip Security: A System-Level Vulnerability Assessment, En He, Daoyuan Wu, Robert H. Deng

Research Collection School Of Computing and Information Systems

VoIP is a class of new technologies that deliver voice calls over the packet-switched networks, which surpasses the legacy circuit-switched telecom telephony. Android provides the native support of VoIP, including the recent VoLTE and VoWiFi standards. While prior works have analyzed the weaknesses of VoIP network infrastructure and the privacy concerns of third-party VoIP apps, no efforts were attempted to investigate the (in)security of Android’s VoIP integration at the system level. In this paper, we first demystify Android VoIP’s protocol stack and all its four attack surfaces. We then propose a novel vulnerability assessment approach that assembles on-device Intent/API fuzzing, …


Secure Server-Aided Data Sharing Clique With Attestation, Yujue Wang, Hwee Hwa Pang, Robert H. Deng, Yong Ding, Qianhong Wu, Bo Qin, Kefeng Fan Jun 2020

Secure Server-Aided Data Sharing Clique With Attestation, Yujue Wang, Hwee Hwa Pang, Robert H. Deng, Yong Ding, Qianhong Wu, Bo Qin, Kefeng Fan

Research Collection School Of Computing and Information Systems

In this paper, we consider the security issues in data sharing cliques via remote server. We present a public key re-encryption scheme with delegated equality test on ciphertexts (PRE-DET). The scheme allows users to share outsourced data on the server without performing decryption-then-encryption procedures, allows new users to dynamically join the clique, allows clique users to attest the message underlying a ciphertext, and enables the server to partition outsourced user data without any further help of users after being delegated. We introduce the PRE-DET framework, propose a concrete construction and formally prove its security against five types of adversaries regarding …