Privacy-preserving cross-cloud LDoS threat identification via labelled-threshold private set intersection
Document Type
Article
Publication Date
2026
Department/School
Information Security and Applied Computing
Publication Title
IEEE Transactions on Cloud Computing
Abstract
Industrial Internet of Things (IIoT) systems in sectors like manufacturing, energy, and healthcare are increasingly deployed in cloud-assisted operational environments, where network telemetry and security analytics are routinely processed in the cloud. However, these systems remain highly vulnerable to cyber threats from shared threat actors. Among these, low-rate Denial of Service (LDoS) attacks, marked by subtle periodic traffic patterns, are particularly challenging to detect when analyzed in isolation. Cross-organization collaborative detection across cloud platforms can improve identification accuracy, but sharing threat intelligence risks exposing sensitive operational information. To tackle this challenge, we propose Labelled-Threshold Private Set Intersection (LT-PSI), a cryptographic framework that allows two organizational clouds to securely identify common elements whose associated label vectors satisfy a similarity threshold, without revealing any additional data. Our LT-PSI protocol introduces an innovative combination of position encoding, Diffie-Hellman Oblivious Pseudorandom Functions (DH-OPRF), and Bloom filters, effectively transforming threshold-based label similarity matching into efficient and privacy-preserving set membership tests. Particularly, our protocol achieves sublinear online complexity and is well-suited for cloud execution, integrating an adaptive early termination strategy that significantly reduces the number of OPRF invocations. We provide formal security proofs under the semi-honest model and validate the protocol through extensive experiments across diverse similarity thresholds and dataset sizes. Results show that LT-PSI is significantly more efficient than brute-force threshold matching while preserving privacy. The framework naturally supports cloud-to-cloud collaborative security analytics and generalizes to broader cloud and edge threat intelligence scenarios requiring private, threshold-based feature matching.
Link to Published Version
Recommended Citation
Zhang, X., Lu, R., Zhao, P., Guan, Y., & Ray, S. (2026). Privacy-preserving cross-cloud LDoS threat identification via labelled-threshold private set intersection. IEEE Transactions on Cloud Computing, 14(2), 877–888. https://doi.org/10.1109/TCC.2026.3675155
Comments
Y. Guan is a faculty member in EMU's School of Information Security and Applied Computing.