Chengyu Hu 0001

dblp:10/901-1 · DBLP profile ↗
← Back
32ranked-venue papers
5as first author
20since 2021 · last 2026
0000-0002-5523-2672ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 5 · 1 first-author · 3 since 2021Systems, architecture and hardware · 4 · 1 first-author · 3 since 2021Computer networks · 4 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 4 · 2 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021
YearPublicationVenuePosition
2026 Formal Analysis Framework for E2EE Protocols
abstract
In today's digital communication landscape, the security of End-to-End Encryption (E2EE) protocols is paramount, particularly in safeguarding user privacy and data integrity. Formal verification has emerged as a critical methodology to ensure these protocols' effectiveness and reliability. However, certain scenarios reveal failures in guaranteeing E2EE communication security properties, leading to potential privacy breaches. We conducted a comprehensive survey of mainstream messaging protocols, systematically categorizing their vulnerabilities and causes. By focusing on identity authentication during user registration, key agreement protocols in session establishment, and data encapsulation processes in message transmission, we developed a formal verification framework for E2EE Messaging Protocols. This framework integrates dual perspectives: cryptographic protocol verification and implementation auditing.
Xiaofeng Liu 0013, Chengyu Hu 0001, Shanqing Guo
AsiaCCS4
2026 Secure spatial skyline queries on encrypted data
abstract
Abstract Spatial skyline queries represent a specialized category of skyline queries, applicable in various domains such as facility location, crisis management, and travel or event planning. The emergence of secure spatial skyline queries carries substantial practical implications. In this paper, we address the challenge posed by the point-geometry dependency problem inherent in existing spatial skyline query algorithms. Our approach involves a transformative strategy that simplifies the query into a more tractable range query problem. Building on this transformation approach, we design an efficient and secure spatial skyline query method for encrypted data, which requires alternating between ciphertext and plaintext queries. To ensure both security and optimal performance, we execute plaintext queries within a trusted execution environment. Experiments demonstrate the efficiency and effectiveness of our approach.
Shuxuan Mu, Zhiyuan Su, Pengtao Liu, Chengyu Hu 0001, Fuqiang Ma, Shanqing Guo
Comput. J.5
2026 A unified evaluation framework for cryptographic algorithm identification tools in IoT firmware
Xiao-Yang Zhou, Jie-Wei Du, Chengyu Hu 0001, Shanqing Guo
Frontiers Comput. Sci.4
2026 SGAFuzzer: Stateful GraphQL API fuzzing
Jingge Sun, Xiangpu Song, Xiaofeng Liu 0013, Shanqing Guo, Chengyu Hu 0001
Softw. Qual. J.5
2025 Query Rewriting-Based View Generation for Efficient Multi-Relation Multi-Query with Differential Privacy
Xinglin Du, Peng Tang 0002, Rui Chen 0012, Ning Wang 0026, Chengyu Hu 0001, Shanqing Guo
EDBT5
2025 FLDS: differentially private federated learning with double shufflers
abstract
Abstract Federated learning (FL) often uses local differential privacy (LDP) to prevent leaking data privacy through gradients. However, due to the high dimension of gradients, LDP will encounter the problem of privacy budget explosion in the application, resulting in low accuracy of the training model. To overcome this shortcoming, we propose a differential privacy FL protocol incorporating a control matrix and double shuffles. The control matrix, generated by the analyzer, is responsible for governing the selection and upload of clients’ gradients. Double shufflers shuffle the control matrix and clients’ gradients, respectively, so that the control matrix is invisible to the server and the gradient is anonymous to the server. In addition, the existing differential private FL often uses the same clipping scale for gradients clipping to facilitate determining the noise scale. However, this will bring too many clipping errors for the large gradients and too many noise errors for the small ones. To solve these problems, we propose an adaptive clipping scheme. Experiments on the real-world datasets show that our proposed methods achieve higher testing accuracy.
Qingqiang Qi, Xingye Yang, Chengyu Hu 0001, Peng Tang 0002, Zhiyuan Su, Shanqing Guo
Comput. J.3
2025 PFGRS: A Privacy-preserving Subgraph-level Federated Graph learning for Recommender System
Qingqiang Qi, Chengyu Hu 0001, Tongyaqi Li, Peng Tang 0002, Shanqing Guo
Expert Syst. Appl.2
2025 Safe Driving Adversarial Trajectory Can Mislead: Toward More Stealthy Adversarial Attack Against Autonomous Driving Prediction Module
abstract
The prediction module, powered by deep learning models, constitutes a fundamental component of high-level Autonomous Vehicles (AVs). Given the direct influence of the module’s prediction accuracy on AV driving behavior, ensuring its security is paramount. However, limited studies have explored the adversarial robustness of the prediction modules. Furthermore, existing methods still generate adversarial trajectories that deviate significantly from human driving behavior. These deviations can be easily identified as hazardous by AVs’ anomaly detection models and thus cannot effectively evaluate and reflect the robustness of the prediction modules. To bridge this gap, we propose a stealthy and more effective optimization-based attack method. Specifically, we reformulate the optimization problem using Lagrangian relaxation and design a Frenet-based objective function along with a distinct constraint space. We conduct extensive evaluations on 2 popular prediction models and 2 benchmark datasets. Our results show that our attack is highly effective, with over 87% attack success rates, outperforming all baseline attacks. Moreover, our attack method significantly improves the stealthiness of adversarial trajectories while guaranteeing adherence to physical constraints. Our attack is also found robust to noise from upstream modules, transferable across trajectory prediction models, and high realizability. Lastly, to verify its effectiveness in real-world applications, we conduct further simulation evaluations using a production-grade simulator. These simulations reveal that the adversarial trajectory we created could convincingly induce autonomous vehicles (AVs) to initiate hard braking.
Yingkai Dong, Li Wang 0120, Zheng Li 0023, Hao Li 0092, Peng Tang 0002, Chengyu Hu 0001, Shanqing Guo
ACM Trans. Priv. Secur.6
2024 PFDF: Privacy Preserving Federated Decision Forest for Classification
Tongyaqi Li, Qingqiang Qi, Chengyu Hu 0001, Xuelei Li, Peng Tang 0002, Shanqing Guo
ICA3PP (1)3
2024 TLS-DeepDiffer: Message Tuples-Based Deep Differential Fuzzing for TLS Protocol Implementations
abstract
Logic vulnerabilities associated with TLS protocol implementations often do not exhibit explicit erroneous behaviors, making them difficult to detect by testers. However, these vulnerabilities can pose serious security threats. While testing for TLS protocols lacks uniform test oracles, differential fuzzing effectively addresses this issue. Unfortunately, most of these vulnerabilities are triggered in deep protocol states, and no existing work on differential fuzzing targeting these states exists. In this paper, we propose a deep differential fuzzing framework that focuses on detecting logic issues in deep TLS protocol states. Our approach is based on the message tuples we proposed, which are semi-automatically extracted from RFCs using NLP techniques. We address the problem of test interruptions during early handshakes caused by original data inconsistencies by redefining the consistency determination to achieve deep differential fuzzing. In addition, we use encoding classification statistics to achieve quick and efficient analysis of the massive test results. Based on our approach, we implemented TLS-DeepDiffer and used it to test nine kinds of popular TLS libraries. We found four historical CVEs, one newly discovered high-risk vulnerability, and 24 security or implementation issues, demonstrating the usefulness of our approach.
Xiangpu Song, Qiuyu Zhong, Yingpei Zeng, Chengyu Hu 0001, Shanqing Guo
SANER5
2024 Controlled Search: Building Inverted-Index PEKS With Less Leakage in Multiuser Setting
abstract
The public key encryption with keyword search (PEKS) schemes are mostly applied to small data sets in mail forwarding systems. When retrieving large databases, the typical search mechanism makes them inefficient and impractical. When designing a PEKS scheme, except for remedying the vulnerability of keyword guessing attacks (KGAs), other leakage issues, such as multipattern privacy and forward/backward security are rarely considered, which may lead to information leakage. Moreover, most existing PEKS only consider applications in single-user scenarios, and cannot be directly transferred to multiuser scenarios, which undermines the value of data utilization. To cope with the above concerns, we propose a PEKS scheme based on an inverted index where the bitmap is used to build the index for the first time in PEKS to meet some seemingly conflicting yet desirable characteristics. First, it has high search efficiency under multiwriter and multiuser. Through linear transformation, users quickly retrieve data and control other users’ access to their data without relying on a third party for authentication. Second, we prove its security in an enhanced security model that achieves multipattern privacy and forward and backward security. It can also resist KGA attacks without a designated tester, which makes it more practical. Finally, it can be extended to achieve search result verification. Compare to the scheme (Zhang et al. ICWS 2016), it has absolute advantages in security and computational cost where the search efficiency is improved by two orders of magnitude.
Guiyun Qin, Pengtao Liu, Chengyu Hu 0001, Zengpeng Li 0001, Shanqing Guo
IEEE Internet Things J.3
2024 Subgraph-level federated graph neural network for privacy-preserving recommendation with meta-learning
Zhaoxing Han, Chengyu Hu 0001, Tongyaqi Li, Qingqiang Qi, Peng Tang 0002, Shanqing Guo
Neural Networks2
2023 Multi-Dimensional Data Publishing With Local Differential Privacy
Gaoyuan Liu, Peng Tang 0002, Chengyu Hu 0001, Chongshi Jin, Shanqing Guo
EDBT3
2023 ATTAA: Active Text Traffic Analysis Attacks on Secure Messaging Applications
abstract
Popular Secure Instant Messaging (SIM) applications like Telegram and WhatsApp have deployed state-of-the-art encryption schemes in recent years to protect the security of user communications. However, SIM applications are still not completely secure. Governments can surveil and censor users who participate in groups on sensitive topics based on the leaked information of their SIM clients. In this paper, we find two types of padding flaws in SIM applications where the padding length is not long enough, thereby exposing users' encrypted traffic characteristics. Furthermore, we first present an Active Text Traffic Analysis Attack (ATTAA) that enables the adversary to obtain sensitive information about target users' clients by merely monitoring their encrypted SIM traffic. Specifically, the adversary can quickly identify the participants of target SIM groups with high accuracy. Our study demonstrates a significant, real-world threat to SIM users due to increasing government regulation on social media. We demonstrate the practicality of our ATTAA through extensive experiments on real-world SIM communications. Although SIM applications have various restrictions on message sending, our results show that only ten text messages in 10 seconds are enough to successfully attack Telegram and WhatsApp with an accuracy of 99.94% and 98.66%, and a false positive rate of$4.3\times 10^{-3}$and$1.5\times 10^{-4}$.
Fengyan Lv, Xiaofeng Liu 0013, Chengyu Hu 0001, Shanqing Guo
ICC4
2023 Multi-granularity Deep Vulnerability Detection Using Graph Neural Networks
Tengxiao Yang, Song Lian, Chengyu Hu 0001, Shanqing Guo
ICONIP (15)4
2023 Demystifying Decentralized Matrix Communication Network: Ecosystem and Security
abstract
With the emergence of Web3, decentralized network protocol technologies have been vigorously developed. As a pioneer for decentralized real-time communication systems, Matrix is an open standard based on a federation specification protocol. Anyone can set up a self-hosted homeserver to participate in the global Matrix network and communicate with others in chat rooms. In this paper, we conduct the first in-depth measurement and exploratory research on Matrix’s ecosystem and security. We designed and implemented several investigation techniques to empirically delve into Matrix federation from various aspects (homeservers, rooms, and users). In the end, we identified a number of interesting findings and potential vulnerabilities, including anti-decentralization phenomena, cybersecurity threats in homeservers, and the confidentiality of encrypted rooms being compromised.
Hao Li 0092, Yanbo Wu, Ronghong Huang, Xianghang Mi, Chengyu Hu 0001, Shanqing Guo
ICPADS5
2022 Secure and Efficient Cloud Ciphertext Deduplication Based on SGX
abstract
With the development of data outsourcing technology, the data stored by cloud storage servers are exploding. Secure deduplication for encrypted data helps cloud servers reduce storage overhead in the scenario that cloud users outsource their data in ciphertext. To satisfy client-side semantic security, most existing deduplication schemes for encrypted data need trusted third parties. However, trusted third parties are difficult to deploy and may cause potential risks. Therefore, we propose a secure cloud ciphertext deduplication scheme based on Intel SGX. The proposed scheme uses the Enclave security container provided by Intel SGX as the trusted execution environment on the cloud server to replace the trusted third party to perform sensitive operations. At the same time, our scheme simplifies the secure management of the file encryption keys so that the encryption key of the files with the same data can be securely distributed to other owners of the same file without the need for the original uploader online. We prove the security of the proposed scheme and the experiment shows the efficiency of the scheme.
Guiyun Qin, Pengtao Liu, Chengyu Hu 0001, Shanqing Guo
ICPADS4
2021 TranFuzz: An Ensemble Black-Box Attack Framework Based on Domain Adaptation and Fuzzing
Hao Li 0092, Shanqing Guo, Peng Tang 0002, Chengyu Hu 0001
ICICS (1)4
2021 Verifiable Public-Key Encryption with Keyword Search Secure against Continual Memory Attacks
Chengyu Hu 0001, Pengtao Liu, Rupeng Yang, Shanqing Guo, Hailong Zhang 0001
Mob. Networks Appl.1
2021 Towards Achieving Keyword Search over Dynamic Encrypted Cloud Data with Symmetric-Key Based Verification
abstract
Verifiable Searchable Symmetric Encryption, as an important cloud security technique, allows users to retrieve the encrypted data from the cloud through keywords and verify the validity of the returned results. Dynamic update for cloud data is one of the most common and fundamental requirements for data owners in such schemes. To the best of our knowledge, the existing verifiable SSE schemes supporting data dynamic update are all based on asymmetric-key cryptography verification, which involves time-consuming operations. The overhead of verification may become a significant burden due to the sheer amount of cloud data. Therefore, how to achieve keyword search over dynamic encrypted cloud data with efficient verification is a critical unsolved problem. To address this problem, we explore achieving keyword search over dynamic encrypted cloud data with symmetric-key based verification and propose a practical scheme in this paper. In order to support the efficient verification of dynamic data, we design a novel Accumulative Authentication Tag (AAT) based on the symmetric-key cryptography to generate an authentication tag for each keyword. Benefiting from the accumulation property of our designed AAT, the authentication tag can be conveniently updated when dynamic operations on cloud data occur. In order to achieve efficient data update, we design a new secure index composed by a search table ST based on the orthogonal list and a verification list VL containing AATs. Owing to the connectivity and the flexibility of ST, the update efficiency can be significantly improved. The security analysis and the performance evaluation results show that the proposed scheme is secure and efficient.
Xinrui Ge, Jia Yu 0003, Hanlin Zhang 0001, Chengyu Hu 0001, Zengpeng Li 0001, Zhan Qin, Rong Hao
IEEE Trans. Dependable Secur. Comput.4
2020 An empirical study of potentially malicious third-party libraries in Android apps
abstract
The rapid development of Android apps primarily benefits from third-party libraries that provide well-encapsulated functionalities. On the other hand, more and more malicious libraries are discovered in the wild, which brings new security challenges. Despite some previous studies focusing on the malicious libraries, however, most of them only study specific types of libraries or individual cases. The security community still lacks a comprehensive understanding of potentially malicious libraries (PMLs) in the wild.
Wenrui Diao, Chengyu Hu 0001, Shanqing Guo, Chaoshun Zuo, Li Li 0044
WISEC3
2020 Enabling cloud storage auditing with key-exposure resilience under continual key-leakage
Chengyu Hu 0001, Yuqin Xu, Pengtao Liu, Jia Yu 0003, Shanqing Guo, Minghao Zhao 0001
Inf. Sci.1
2019 How to prove your model belongs to you: a blind-watermark based framework to protect intellectual property of DNN
abstract
Deep learning techniques have made tremendous progress in a variety of challenging tasks, such as image recognition and machine translation, during the past decade. Training deep neural networks is computationally expensive and requires both human and intellectual resources. Therefore, it is necessary to protect the intellectual property of the model and externally verify the ownership of the model. However, previous studies either fail to defend against the evasion attack or have not explicitly dealt with fraudulent claims of ownership by adversaries. Furthermore, they can not establish a clear association between the model and the creator's identity.
Zheng Li 0023, Chengyu Hu 0001, Yang Zhang 0016, Shanqing Guo
ACSAC2
2019 Towards dependable and trustworthy outsourced computing: A comprehensive survey and tutorial
Minghao Zhao 0001, Chengyu Hu 0001, Xiangfu Song
J. Netw. Comput. Appl.2
2019 A countermeasure against cryptographic key leakage in cloud: public-key encryption with continuous leakage and tampering resilience
Chengyu Hu 0001, Rupeng Yang, Pengtao Liu, Tong Li 0011
J. Supercomput.1
2018 DRLgencert: Deep Learning-Based Automated Testing of Certificate Verification in SSL/TLS Implementations
abstract
The Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols are the foundation of network security. The certificate verification in SSL/TLS implementations is vital and may become the "weak link" in the whole network ecosystem. In previous works, some research focused on the automated testing of certificate verification, and the main approaches rely on generating massive certificates through randomly combining parts of seed certificates for fuzzing. Although the generated certificates could meet the semantic constraints, the cost is quite heavy, and the performance is limited due to the randomness. To fill this gap, in this paper, we propose DRLGENCERT, the first framework of applying deep reinforcement learning to the automated testing of certificate verification in SSL/TLS implementations. DRLGENCERT accepts ordinary certificates as input and outputs newly generated certificates which could trigger discrepancies with high efficiency. Benefited by the deep reinforcement learning, when generating certificates, our framework could choose the best next action according to the result of a previous modification, instead of simple random combinations. At the same time, we developed a set of new techniques to support the overall design, like new feature extraction method for X.509 certificates, fine-grained differential testing, and so forth. Also, we implemented a prototype of DRLGENCERT and carried out a series of real-world experiments. The results show DRLGENCERT is quite efficient, and we obtained 84,661 discrepancy-triggering certificates from 181,900 certificate seeds, say around 46.5% effectiveness. Also, we evaluated six popular SSL/TLS implementations, including GnuTLS, MatrixSSL, MbedTLS, NSS, OpenSSL, and wolfSSL. DRLGENCERT successfully discovered 23 serious certificate verification flaws, and most of them were previously unknown.
Wenrui Diao, Yingpei Zeng, Shanqing Guo, Chengyu Hu 0001
ICSME5
2017 NIVAnalyzer: A Tool for Automatically Detecting and Verifying Next-Intent Vulnerabilities in Android Apps
abstract
In the Android system design, any app can start another app's public components to facilitate code reuse by sending an asynchronous message called Intent. In addition, Android also allows an app to have private components that should only be visible to the app itself. However, malicious apps can bypass this system protection and directly invoke private components in vulnerable apps through a class of newly discovered vulnerability, which is called next-intent vulnerability. In this paper, we design an intent flow analysis strategy which accurately tracks the intent in smali code to statically detect next-intent vulnerabilities efficiently and effectively on a large scale. We further propose an automated approach to dynamically verify the discovered vulnerabilities by generating exploit apps. Then we implement a tool named NIVAnalyzer and evaluate it on 20,000 apps downloaded from Google Play. As the result, we successfully confirms 190 vulnerable apps, some of which even have millions of downloads. We also confirmed that an open-source project and a third-party SDK, which are still used by other apps, have next intent vulnerabilities.
Xingmin Cui, Ziming Zhao 0001, Shanqing Guo, Xin-Shun Xu, Chengyu Hu 0001, Tao Ban, Bing Mao 0001
ICST6
2016 Public-key encryption with keyword search secure against continual memory attacks
abstract
Abstract Continual memory attacks, inspired by recent realistic physical attacks, have broken many cryptographic schemes that were considered secure in traditional cryptography model. In this paper, we consider the continual memory leakage resilience in public‐key encryption with keyword search scheme (PEKS). We give the definition of continual memory leakage resilience security for PEKS, which allows continual secret key leakage in the trapdoor generation algorithm rather than leakage of trapdoor itself. We believe that the definition is more suitable for practical PEKS scenario. To construct a concrete PEKS scheme secure against continual memory attacks, we firstly obtain a continual master‐key leakage‐resilient anonymous identity‐based encryption (IBE) scheme by applying the generic tool provided by Lewko et al. to a fully secure anonymous IBE scheme that comes from the fully secure anonymous hierarchical identity‐based encryption (HIBE) scheme of De Caro and colleagues. Then, we transform our continual master‐key leakage‐resilient anonymous IBE scheme to a PEKS scheme using the generic Anonymous IBE‐to‐PEKS transformation and prove its continual leakage‐resilient security. Copyright © 2016 John Wiley & Sons, Ltd.
Chengyu Hu 0001, Rupeng Yang, Pengtao Liu, Zuoxia Yu, Yongbin Zhou, Qiuliang Xu
Secur. Commun. Networks1
2016 Public-key encryption for protecting data in cloud system with intelligent agents against side-channel attacks
Chengyu Hu 0001, Pengtao Liu, Yongbin Zhou, Shanqing Guo, Qiuliang Xu
Soft Comput.1
2016 Fairness in secure computing protocols based on incentives
Leisi Chen, Ho-fung Leung, Chengyu Hu 0001, Beijing Chen
Soft Comput.4
2015 Updatable Hash Proof System and Its Applications
abstract
To tackle with physical attacks to real world cryptosystems, leakage resilient cryptography was developed. In this setting, the adversary is allowed to have access to the internal state of a cryptographic system, thus violates the black-box reduction used in cryptography. Especially when considering continual memory leakage (CML), i.e., there is no predetermined bound on the leakage of the internal information, the task is extremely tough. In this paper, we solve this problem by introducing a new primitive called updatable hash proof system (UHPS). A UHPS can be viewed as a special Hash proof system (HPS), which served as a fundamental tool in constructing public key encryption (PKE) schemes in both leakage-free and leaky settings. A remarkable property of UHPS is that by simply substituting the HPS component with a UHPS component in a PKE scheme, one obtains a new PKE scheme secure in the CML setting. Moreover, the resulting PKE scheme enjoys the same advantage of the original HPS-based PKE, for instance, still “compatible” with known transforms [ 8 , 20 , 24 , 32 ]. We then give instantiations of UHPS from widely-accepted assumptions, including the symmetric external Diffie-Hellman assumption and the d-linear assumption. Interestingly, we notice that when instantiated with concrete assumptions, the resulting chosen-ciphertext secure PKE scheme is by far the most efficient.
Rupeng Yang, Qiuliang Xu, Yongbin Zhou, Rui Zhang 0002, Chengyu Hu 0001, Zuoxia Yu
ESORICS (1)5
2014 How to Compare Selections of Points of Interest for Side-Channel Distinguishers in Practice?
Yingxian Zheng, Yongbin Zhou, Zhenmei Yu, Chengyu Hu 0001, Hailong Zhang 0001
ICICS4