Change search
Link to record
Permanent link

Direct link
Alternative names
Publications (10 of 20) Show all publications
Cheng, J., Lu, Y., Ni, Z., Li, Y., Zhou, G., Huang, Z. & Gao, S. (2026). A Consensus Resistance-Based Autonomous Vehicle Social Group Self-Adaption Method. IEEE Transactions on Computational Social Systems, 13(2), 1734-1744
Open this publication in new window or tab >>A Consensus Resistance-Based Autonomous Vehicle Social Group Self-Adaption Method
Show others...
2026 (English)In: IEEE Transactions on Computational Social Systems, E-ISSN 2329-924X, Vol. 13, no 2, p. 1734-1744Article in journal (Refereed) Published
Abstract [en]

The advancement of autonomous driving technology has brought significant benefits to modern transportation systems. However, individual autonomous vehicles face challenges such as limited perception range and insufficient autonomous capabilities. Cooperative groups of autonomous vehicles, enabled by advanced communication technologies, can enhance traffic efficiency through information exchange. Existing research primarily focuses on centralized autonomous vehicle groups, where the leading node suffers from weak resilience and high computational load, making it difficult to maintain group collaboration over time. To address these issues, this article proposes a decentralized formation and self-adaptation method for autonomous vehicle social groups based on consensus resistance in closed scenes. First, we introduce consensus resistance as a metric to evaluate social group and member consistency, and develop a decentralized formation approach. Second, we present a self-adaption model for autonomous vehicle social groups, incorporating four evolutionary events: 1) expansion; 2) merging; 3) reduction; and 4) splitting, to ensure the stability of moving social groups. Simulation results demonstrate the proposed method effectively constructs social groups in both real-world and simulated environments, exhibiting robust consistency throughout the self-adaption process.

National Category
Robotics and automation
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-250918 (URN)10.1109/TCSS.2025.3623147 (DOI)001643526700001 ()2-s2.0-105026066222 (Scopus ID)
Available from: 2026-01-08 Created: 2026-01-08 Last updated: 2026-04-15Bibliographically approved
Li, Q. & Li, Y. (2026). Enhancing Explainability in X-IDS through Counterfactuals. In: Rongmao Chen; Robert H. Deng; Moti Yung (Ed.), Information Security and Cryptology: 21st International Conference, Inscrypt 2025, Xi'an, China, October 19-22, 2025, Revised Selected Papers, Part II. Paper presented at The 21st International Conference on Information Security and Cryptology 2025, 19-22 October 2025, Xi'an, China. (pp. 235-252). Springer
Open this publication in new window or tab >>Enhancing Explainability in X-IDS through Counterfactuals
2026 (English)In: Information Security and Cryptology: 21st International Conference, Inscrypt 2025, Xi'an, China, October 19-22, 2025, Revised Selected Papers, Part II / [ed] Rongmao Chen; Robert H. Deng; Moti Yung, Springer , 2026, p. 235-252Conference paper, Published paper (Other academic)
Abstract [en]

The growing use of deep learning in intrusion detection systems (IDS) has increased the need for explainable IDS (X-IDS). Current X-IDS research mainly relies on local surrogate models and their explanations are limited due to the complex features of network traffic. In contrast, counterfactual explanations improve interpretability by contrasting “why P rather than Q”, avoiding complex absolute explanations. In this paper, we outline the theoretical value of counterfactual explanations in X-IDS, and propose a two-stage search method for generating counterfactuals. Moreover, we also propose a submodular pick method for counterfactual explanations that provides diverse explanation instances, aiming to interpret the entire model rather than individual samples. Experimental results demonstrate that our proposed method achieves an 80% improvement in fidelity and is 100 times more computationally efficient compared with LIME within the X-IDS domain.

Place, publisher, year, edition, pages
Springer, 2026
Series
Lecture Notes in Computer Science (LNCS), ISSN 0302-9743, E-ISSN 1611-3349 ; 16409
Keywords
Intrusion detection, Counterfactual explanation, Explainable machine learning, Explainable intrusion detection system (X-IDS)
National Category
Computer Sciences
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-250979 (URN)10.1007/978-981-95-6203-9_13 (DOI)2-s2.0-105028319074 (Scopus ID)978-981-95-6202-2 (ISBN)
Conference
The 21st International Conference on Information Security and Cryptology 2025, 19-22 October 2025, Xi'an, China.
Available from: 2026-01-11 Created: 2026-01-11 Last updated: 2026-02-10Bibliographically approved
Ahmed, K. H., Axelsson, S., Li, Y. & Makki Sagheer, A. (2025). A credit card fraud detection approach based on ensemble machine learning classifier with hybrid data sampling. Machine Learning with Applications, 20, Article ID 100675.
Open this publication in new window or tab >>A credit card fraud detection approach based on ensemble machine learning classifier with hybrid data sampling
2025 (English)In: Machine Learning with Applications, E-ISSN 2666-8270, Vol. 20, article id 100675Article in journal (Refereed) Published
Abstract [en]

The existing fraud detection methods present limitations such as imbalanced data, incorrect identification of fraudulent cases, limited applicability to different scenarios, and difficulties processing data in real-time. This paper proposes an ensemble machine-learning model for detecting fraud in credit card transactions. It also integrates the Synthetic Minority Oversampling Technique (SMOTE) with Edited Nearest Neighbor (ENN) to address the problem of the imbalanced datasets. The experimental results show that our approach performs better than the existing methods. Therefore, it will establish an essential framework for the ongoing investigations in developing more robust and flexible systems for fraud detection.

Keywords
Ensemble model, Machine learning, Data imbalance, Credit card fraud detection
National Category
Security, Privacy and Cryptography
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-245086 (URN)10.1016/j.mlwa.2025.100675 (DOI)001500128200001 ()2-s2.0-105027846249 (Scopus ID)
Available from: 2025-07-21 Created: 2025-07-21 Last updated: 2026-03-05Bibliographically approved
Guo, H., Seid, E., Li, Y. & Blix, F. (2025). Evaluating User Perceptions of Privacy Protection in Smart Healthcare Services. In: Alexander Lawall; Fan Wu (Ed.), SECURWARE 2025: The 19th International Conference on Emerging Security Information, Systems and Technologies. Paper presented at SECURWARE 2025,The 19th International Conference on Emerging Security Information, Systems and Technologies, 26-30 October, 2025, Barcelona, Spain. (pp. 132-138). International Academy, Research and Industry Association (IARIA)
Open this publication in new window or tab >>Evaluating User Perceptions of Privacy Protection in Smart Healthcare Services
2025 (English)In: SECURWARE 2025: The 19th International Conference on Emerging Security Information, Systems and Technologies / [ed] Alexander Lawall; Fan Wu, International Academy, Research and Industry Association (IARIA) , 2025, p. 132-138Conference paper, Published paper (Refereed)
Abstract [en]

As smart healthcare services rapidly evolve, ensuring user privacy has become a critical concern. While prior research has focused extensively on technical solutions, the user perspective on privacy protection remains underexplored. This study addresses that gap by examining how users perceive both technical and organizational privacy protection measures across four smart healthcare service types: wearable devices, mobile health apps, telehealth platforms, and medicine delivery systems. Through qualitative survey, the study uncovers a duality in user perceptions. Positive perceptions relate to multi-layer technical safeguards, regulatory oversight (e.g., General Data Protection Regulation (GDPR), Health Insurance Portability and Accountability Act (HIPAA), and proactive provider practices, such as transparent privacy policies and breach responses. On the other hand, negative perceptions center on lack of transparency, limited user control, forced consent to privacy terms, and both cognitive and operational barriers to engaging with privacy features. These findings reveal a critical imbalance in user-provider power dynamics and call for user-centric privacy strategies that balance protection with usability. The study contributes to theoretical advancements in privacy calculus, Technology Acceptance Model (TAM), and Unified Theory of Acceptance and Use of Technology (UTAUT) by refining constructs, such as perceived control, facilitating conditions, and transparency. Practical recommendations are offered to guide more inclusive, adaptable, and empowering privacy solutions in smart healthcare contexts.

Place, publisher, year, edition, pages
International Academy, Research and Industry Association (IARIA), 2025
Series
International Conference on Emerging Security Information, Systems and Technologies, E-ISSN 2162-2116
Keywords
Privacy protection measures, privacy-preserving techniques, smart healthcare, users’ perception.
National Category
Computer Sciences
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-250023 (URN)9781685583064 (ISBN)
Conference
SECURWARE 2025,The 19th International Conference on Emerging Security Information, Systems and Technologies, 26-30 October, 2025, Barcelona, Spain.
Available from: 2025-11-27 Created: 2025-11-27 Last updated: 2025-12-03Bibliographically approved
Li, Q. & Li, Y. (2025). Intrusion Detection via Federated Learning: Tackling Non-IID Data and Poisoning Attacks. In: Proceedings 2025 IEEE 24th International Conference on Trust, Security and Privacy in Computing and Communications: TrustCom 2025. Paper presented at IEEE 24th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom 2025), Guiyang, China, 14-17 November, 2025 (pp. 1929-1935). Piscataway: IEEE
Open this publication in new window or tab >>Intrusion Detection via Federated Learning: Tackling Non-IID Data and Poisoning Attacks
2025 (English)In: Proceedings 2025 IEEE 24th International Conference on Trust, Security and Privacy in Computing and Communications: TrustCom 2025, Piscataway: IEEE, 2025, p. 1929-1935Conference paper, Published paper (Refereed)
Abstract [en]

Intrusion detection based on Federated Learning has been proven to be an effective method to address security risks in the Internet of Things (IoT). However, it faces challenges in dealing with non-independent and identically distributed (non-IID) data and poisoning attacks in IoT. To address these challenges, we propose an IDS approach named Clustering and Defending Against Poisoning Attacks (CDPA). Through clustering, CDPA not only alleviates the challenges of non-IID data, but also reframes the defense against poisoning attacks as one under nearly IID conditions. CDPA uses a novel federated clustering method to ensure that malicious clients are grouped without leaking additional information, and it adaptively selects the number of clusters. Moreover, CDPA proposes a novel federated aggregation algorithm specifically designed to address the previously overlooked challenge of high malicious client ratios within clusters - a vulnerability particularly exacerbated in cluster-based training scenarios. Extensive experiments demonstrate that CDPA can effectively handle non-IID data and defend against poisoning attacks, achieving a performance gain of approximately 20% over the baseline.

Place, publisher, year, edition, pages
Piscataway: IEEE, 2025
Series
IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), ISSN 2324-898X, E-ISSN 2324-9013
Keywords
Federated Learning (FL), Internet of Things (IoT), Intrusion detection, Non-independent and identically distributed (non-IID), Poisoning attack
National Category
Security, Privacy and Cryptography
Identifiers
urn:nbn:se:su:diva-254766 (URN)10.1109/Trustcom66490.2025.00223 (DOI)001711528900215 ()2-s2.0-105033684377 (Scopus ID)979-8-3315-6532-9 (ISBN)979-8-3315-6533-6 (ISBN)
Conference
IEEE 24th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom 2025), Guiyang, China, 14-17 November, 2025
Available from: 2026-04-29 Created: 2026-04-29 Last updated: 2026-04-29Bibliographically approved
Song, D., Li, Y., Berzinji, A. & Seid, E. (2025). Towards Automated Penetration Testing Using Inverse Soft-Q Learning. In: Alexander Lawall; Fan Wu (Ed.), SECURWARE 2025: The Nineteenth International Conference on Emerging Security Information, Systems and Technologies. Paper presented at SECURWARE 2025 : The Nineteenth International Conference on Emerging Security Information, Systems and Technologies, 26-30 October, 2025, Barcelona, Spain. (pp. 62-68). International Academy, Research and Industry Association (IARIA)
Open this publication in new window or tab >>Towards Automated Penetration Testing Using Inverse Soft-Q Learning
2025 (English)In: SECURWARE 2025: The Nineteenth International Conference on Emerging Security Information, Systems and Technologies / [ed] Alexander Lawall; Fan Wu, International Academy, Research and Industry Association (IARIA) , 2025, p. 62-68Conference paper, Published paper (Refereed)
Abstract [en]

Penetration testing (pentesting), a proactive defensive practice for identifying vulnerabilities and supporting cybersecurity management, has traditionally been conducted manually due to its heavy reliance on specialized knowledge of human experts. In this paper, we propose PT-ISQL, an automated PenTesting approach based on Inverse Soft-Q Learning (ISQL), an imitation learning algorithm that enables efficient policy learning from expert demonstrations. PT-ISQL trains an agent to take optimal actions when interacting with the pentesting environment by effectively mimicking expert behavior. Our evaluation shows that PT-ISQL achieves high performance using significantly fewer expert demonstrations compared with generative adversarial imitation learning approaches. Furthermore, it demonstrates faster convergence, improved stability, and reduced training overhead. These results suggest that PT-ISQL is a promising and practical solution for scalable, automated penetration testing.

Place, publisher, year, edition, pages
International Academy, Research and Industry Association (IARIA), 2025
Series
International Conference on Emerging Security Information, Systems and Technologies, E-ISSN 2162-2116
Keywords
penetration testing, deep reinforcement learning, imitation learning, inverse soft-Q learning, PT-ISQL
National Category
Computer Sciences
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-250029 (URN)9781685583064 (ISBN)
Conference
SECURWARE 2025 : The Nineteenth International Conference on Emerging Security Information, Systems and Technologies, 26-30 October, 2025, Barcelona, Spain.
Available from: 2025-11-27 Created: 2025-11-27 Last updated: 2025-12-03Bibliographically approved
Olegård, J., Axelsson, S. & Li, Y. (2025). When is logging sufficient? — Tracking event causality for improved forensic analysis and correlation. Forensic Science International: Digital Investigation, 52, Article ID 301877.
Open this publication in new window or tab >>When is logging sufficient? — Tracking event causality for improved forensic analysis and correlation
2025 (English)In: Forensic Science International: Digital Investigation, ISSN 2666-2825, Vol. 52, article id 301877Article in journal (Refereed) Published
Abstract [en]

It is generally agreed that logs are necessary for understanding cyberattacks post-incident. However, little is known about what specific information logs should contain to be forensically helpful. This uncertainty, combined with the fact that conventional logs are often not designed with security in mind, often results in logs with too much or too little information. Events in one log are also often challenging to correlate with events in other logs. Most previous research has focused on preserving, filtering, and interpreting logs, rather than addressing what should be logged in the first place. This paper explores logging sufficiency through the lens of Digital Forensic Readiness, and highlights the absence of causal information in conventional logs. To address this gap, we propose a novel logging system leveraging “gretel numbers” to track causal information—such as attacker movement—across multiple applications in a tamper-resistant manner. A prototype, implemented using the Extended Berkeley Packet Filter (EBPF) and an Nginx web server, shows that causality tracking imposes minimal resource overhead, though log size management remains critical for scalability.

Keywords
Anti-anti-forensics, Digital forensics, Event-reconstruction, Logging, Provenance graph
National Category
Computer and Information Sciences
Identifiers
urn:nbn:se:su:diva-242034 (URN)10.1016/j.fsidi.2025.301877 (DOI)001460881900004 ()2-s2.0-105000598471 (Scopus ID)
Available from: 2025-04-14 Created: 2025-04-14 Last updated: 2025-04-24Bibliographically approved
Chen, R., Li, Y. & Rahmani Chianeh, R. (2023). Attribute-based Encryption with Flexible Revocation for IoV. In: Procedia Computer Science: Special Issue, 18th International Conference on Future Networks and Communications / 20th International Conference on Mobile Systems and Pervasive Computing / 13th International Conference on Sustainable Energy Information Technology. Paper presented at The 20th International Conference on Mobile Systems and Pervasive Computing (MobiSPC), August 14-16, 2023, Halifax, Nova Scotia, Canada. (pp. 131-138). Elsevier
Open this publication in new window or tab >>Attribute-based Encryption with Flexible Revocation for IoV
2023 (English)In: Procedia Computer Science: Special Issue, 18th International Conference on Future Networks and Communications / 20th International Conference on Mobile Systems and Pervasive Computing / 13th International Conference on Sustainable Energy Information Technology, Elsevier , 2023, p. 131-138Conference paper, Published paper (Refereed)
Abstract [en]

Attribute-based encryption (ABE) has been used to provide data confidentiality and fine-grained access control in the Internet of Vehicles (IoV). However, the attributes of vehicles in IoV might change frequently due to the movements of vehicles. Thus, the invalid attributes need to be revoked in time and efficiently to ensure the security of the system. In this paper, we propose a data-sharing scheme based on ABE for IoV. By using a binary tree and attribute version keys, flexible revocation can be achieved for IoV. Moreover, the ciphertext can be stored on clouds, and the distribution and revocation of attribute keys can be realized by distributed attribute authorities. We performed the security analysis and proved the security of the proposed scheme. The results showed that the proposed scheme has lower average computing overhead in terms of attribute revocations compared with other schemes based on ABE, and can satisfy the performance requirement of data sharing for IoV.

Place, publisher, year, edition, pages
Elsevier, 2023
Series
Procedia Computer Science, E-ISSN 1877-0509 ; 224
Keywords
Internet of vehicles, attribute-based encryption, revocationdata sharing
National Category
Computer Engineering
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-222621 (URN)10.1016/j.procs.2023.09.020 (DOI)001196890200016 ()2-s2.0-85179127000 (Scopus ID)
Conference
The 20th International Conference on Mobile Systems and Pervasive Computing (MobiSPC), August 14-16, 2023, Halifax, Nova Scotia, Canada.
Available from: 2023-10-13 Created: 2023-10-13 Last updated: 2024-10-16Bibliographically approved
Li, Y., Chen, R. & Rahmani Chianeh, R. (2023). Secure Data Sharing in Internet of Vehicles based on Blockchain and Attribute-based Encryption. In: 2023 IEEE International Conference on Smart Internet of Things (SmartIoT): . Paper presented at 2023 IEEE International Conference on Smart Internet of Things (SmartIoT), Xining, China, 2023. (pp. 56-63). IEEE conference proceedings
Open this publication in new window or tab >>Secure Data Sharing in Internet of Vehicles based on Blockchain and Attribute-based Encryption
2023 (English)In: 2023 IEEE International Conference on Smart Internet of Things (SmartIoT), IEEE conference proceedings , 2023, p. 56-63Conference paper, Published paper (Other academic)
Abstract [en]

Sharing data among vehicles is one of the most important ways to provide safety-related and value-added services to connected vehicles. Nevertheless, access to the shared data must be controlled to prevent the exposure of users' privacy and data leakage or corruption. Attribute-based encryption (ABE) can provide data confidentiality and fine-grained access control. However, the complex and dynamic driving environment of vehicles may cause the attributes of vehicles to change frequently, and thus put a huge burden on the attribute management of the system or degrade the security of the system. In this paper, we propose a secure data sharing method by using ABE and blockchain for Internet of Vehicles. By using ABE, the data owner can stipulate the policy of the data access control based on the attributes of vehicles. The trusted authority is replaced by blockchain, which reduces the burden and solved the problem of single point failure of the trusted authority and increases the transparency of the whole system. An adaptive attribute revocation method is used to balance the revocation time and system cost. Moreover, the shared data are stored in a distributed Inter-Planetary File System (IPFS) to improve the efficiency and security of the data sharing system. The test results show that the proposed method can well satisfy the performance requirement of secure data sharing for Internet of Vehicles.

Place, publisher, year, edition, pages
IEEE conference proceedings, 2023
Series
IEEE International Conference on Smart Internet of Things, ISSN 2770-2669, E-ISSN 2770-2677
National Category
Computer Sciences
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-224985 (URN)10.1109/SmartIoT58732.2023.00016 (DOI)2-s2.0-85178517473 (Scopus ID)979-8-3503-1657-5 (ISBN)
Conference
2023 IEEE International Conference on Smart Internet of Things (SmartIoT), Xining, China, 2023.
Available from: 2024-01-03 Created: 2024-01-03 Last updated: 2024-01-08Bibliographically approved
Li, Y., Rahmani, R. & Hui, P. (2020). Enhancing the Internet of Things with Knowledge-Driven Software-Defined Networking Technology: Future Perspectives. Sensors, 20(12), Article ID 3459.
Open this publication in new window or tab >>Enhancing the Internet of Things with Knowledge-Driven Software-Defined Networking Technology: Future Perspectives
2020 (English)In: Sensors, E-ISSN 1424-8220, Vol. 20, no 12, article id 3459Article, review/survey (Refereed) Published
Abstract [en]

The Internet of Things (IoT) connects smart devices to enable various intelligent services. The deployment of IoT encounters several challenges, such as difficulties in controlling and managing IoT applications and networks, problems in programming existing IoT devices, long service provisioning time, underused resources, as well as complexity, isolation and scalability, among others. One fundamental concern is that current IoT networks lack flexibility and intelligence. A network-wide flexible control and management are missing in IoT networks. In addition, huge numbers of devices and large amounts of data are involved in IoT, but none of them have been tuned for supporting network management and control. In this paper, we argue that Software-defined Networking (SDN) together with the data generated by IoT applications can enhance the control and management of IoT in terms of flexibility and intelligence. We present a review for the evolution of SDN and IoT and analyze the benefits and challenges brought by the integration of SDN and IoT with the help of IoT data. We discuss the perspectives of knowledge-driven SDN for IoT through a new IoT architecture and illustrate how to realize Industry IoT by using the architecture. We also highlight the challenges and future research works toward realizing IoT with the knowledge-driven SDN.

Keywords
Internet of Things (IoT), Software-defined Networking (SDN), knowledge-driving networking, IoT-proxy
National Category
Computer Engineering
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-184113 (URN)10.3390/s20123459 (DOI)000553123200001 ()
Available from: 2020-08-13 Created: 2020-08-13 Last updated: 2022-03-23Bibliographically approved
Organisations
Identifiers
ORCID iD: ORCID iD iconorcid.org/0000-0002-9491-2910

Search in DiVA

Show all publications