VLDB 2026 Research / reviewers in the wild / expert
Xuelian Cao
dblp:124/4999
· DBLP profile ↗
8ranked-venue papers
4as first author
6since 2021 · last 2026
0000-0002-2227-9896ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 5 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Proof of Persistent AlivenessabstractProof of Aliveness (PoA) has emerged as a useful cryptographic concept for periodically ascertaining the operational status (aliveness) of devices, especially for those in cyber-physical systems. However, existing PoA schemes exhibit shortcomings stemming from intermittent aliveness proofs and a lack of resilience against the threats caused by malicious verifiers. Motivated by this, we introduce a new security notion called Proof of Persistent Aliveness (PoPA), which encompasses two new properties: persistent aliveness (PAlive) and audit (Audit). Our PAlive strengthens prior work by addressing the security concerns associated with generating persistent aliveness proofs in a continuous time manner, while Audit covers the threats posed by malicious verifiers. To efficiently realize PoPA, we developed two new building blocks: a deterministic hash-based Proof of Work (HPoW) scheme and private tweakable hash (PTH) functions. Using these primitives, we propose a scalable and lightweight PoPA construction, named SPAC, which is provably secure in our PoPA model without relying on random oracles. SPAC leverages HPoW and a customized authenticated credential structure that employs a variant of the Winternitz one-time signature scheme derived from PTH, enabling unlimited aliveness proofs with very small proof size. Over 93% of aliveness proofs are 84 bytes in size, with the worst-case proof size being only 372 bytes. Xuelian Cao, Zheng Yang 0001, Jianting Ning, Chenglu Jin, Zhiming Liu 0001, Jianying Zhou 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | EndPCA: Ensemble Defense With Provably Convergent Aggregation Against Poisoning Attacks in Federated LearningabstractDespite its success in many applications, federated learning is increasingly vulnerable to sophisticated poisoning attacks. Existing defenses, particularly Byzantine Robust Aggregation Rules (BRARs), offer some protection but rely on strong assumptions or challenging technical prerequisites. To address these shortcomings, we propose anensemble defense with provably convergent aggregation(EndPCA). By using the entropy weight method to consolidate scores from multiple BRARs into an ensemble trust score, it effectively integrates heterogeneous weak BRARs to resist a wide range of poisoning attacks under practical assumptions. We formally prove that EndPCA can provide theoretical guarantees of convergence with bounded error. Our empirical evaluations show that EndPCA consistently outperforms existing BRARs, demonstrating its effectiveness across various scenarios. Mingyue Zhang 0002, Chenyu Hu, Xuelian Cao, Atul Sajjanhar, Zheng Yang 0001, Muneeb Ul Hassan 0001, Zhi Jin 0001, Jialong Li 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Infiltrated Selfish Mining: Think Win-Win to Escape Dilemmas
Xuelian Cao, Zheng Yang 0001, Tao Xiang 0001, Jianting Ning, Yuhan Liu 0003, Zhiming Liu 0001, Jianying Zhou 0001 |
AsiaCCS | 1 |
| 2024 | Optimizing Proof of Aliveness in Cyber-Physical SystemsabstractAt ACSAC 2019, we introduced a new cryptographic primitive called proof of aliveness (PoA), allowing us to remotely and automatically track the running status (aliveness) of devices in the fields in cyber-physical systems. We proposed to use a one-way function (OWF) chain structure to build an efficient proof of aliveness, such that the prover sends every node on the OWF chain in a reverse order periodically, and it can be verified by a remote verifier with the possession of the tail node (last node) of the OWF chain. However, the practicality of this initial construction is limited by the finite number of nodes on an OWF chain. We enhance our first PoA construction by linking multiple OWF chains together using a pseudo-random generator chain in our second PoA scheme. This enhancement allows us to integrate one-time signature (OTS) schemes into the structure of the second construction to realize the auto-replenishment of the aliveness proofs. This implies that securely an initialized PoA instance can be used forever without interruption for reinitialization. In this work, our primary motivation is to further improve our secondary PoA and auto-replenishment schemes. Instead of storing the tail nodes of multiple OWF chains on the verifier side, we use a Bloom Filter to compress them. This saves$ 4.7$times the storage cost compared to our previous version at ACSAC 2019. Moreover, the OTS-based auto-replenishment solution cannot be applied to our first scheme solely based on OWFs, and it is not so efficient despite its standard model security. To overcome these limitations, we design a new auto-replenishment scheme from a hash-based commitment under the random oracle model in this work, which is much faster and can be used by both PoA schemes. Additionally, we implement and evaluate our PoA constructions on Raspberry Pis to demonstrate their performance. Considering the implementation on a storage/memory-constrained device, we particularly study the strategies for efficiently generating proofs. Zheng Yang 0001, Chenglu Jin, Xuelian Cao, Marten van Dijk, Jianying Zhou 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Dynamic Group Time-Based One-Time PasswordsabstractGroup time-based one-time passwords (GTOTP) is a novel lightweight cryptographic primitive for achieving anonymous client authentication, which enables the efficient generation of time-based one-time passwords on behalf of a group without revealing any information about the actual client’s identity beyond their group membership. The security properties of GTOTP regarding anonymity and traceability have been formulated in a static group management setting (where all group members should be determined during the group initialization phase), yet, a formal treatment for real-world dynamic groups (i.e., group members may join and leave at any time) is still an open question. It is non-trivial to construct an efficient GTOTP scheme that can provide a lightweight password generation procedure run by group members and support dynamic group management, allowing group members to join and leave without affecting other members’ states (non-disruptively). To address the above challenge, we first define the notion and the security model of dynamic group time-based one-time passwords (DGTOTP) in this work. We then present an efficient DGTOTP construction that can generically transform an asymmetric time-based one-time passwords scheme into a DGTOTP scheme utilizing a chameleon hash function family and a Merkle tree scheme. Within our construction, we particularly tailor an outsourcing solution realizing an issue-first-and-join-later (IFJL) strategy, enabling smooth joining and revocation without disrupting other group members. Moreover, our scheme minimizes symmetric cryptographic operations and maintains constant storage for group members, compared to the linear storage cost that grows rapidly with respect to the lifetime of the GTOTP instance in the previous static GTOTP scheme. Our DGTOTP scheme satisfies stronger security guarantees in a dynamic group management setting without random oracles. Our experimental results confirm the efficiency of our DGTOTP scheme. Xuelian Cao, Zheng Yang 0001, Jianting Ning, Chenglu Jin, Rongxing Lu, Zhiming Liu 0001, Jianying Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | A survey on security in consensus and smart contracts
Xuelian Cao, Xuechen Wu, Bo Liu 0033 |
Peer-to-Peer Netw. Appl. | 1 |
| 2020 | Automated Microservice Identification in Legacy Systems with Functional and Non-Functional MetricsabstractSince microservice has merged as a promising architectural style with advantages in maintainability, scalability, evolvability, etc., increasing companies choose to restructure their legacy monolithic software systems as the microservice architecture. However, it is quite a challenge to properly partitioning the systems into suitable parts as microservices. Most approaches perform microservices identification from a function-splitting perspective and with sufficient legacy software artifacts. That may be not realistic in industrial practices and possibly results in generating unexpected microservices. To address this, we proposed an automated microservice identification (AMI) approach that extracts microservices from the execution and performance logs without providing documentation, models or source codes, while taking both functional and non-functional metrics into considerations. Our work firstly collects logs from the executable legacy system. Then, controller objects (COs) are identified as the key objects to converge strongly related subordinate objects (SOs). Subsequently, the relation between each pair of CO and SO is evaluated by a relation matrix from both the functional and non-functional perspective. We ultimately cluster classes(objects) into the microservices by optimizing the multi-objective of high-cohesion-low-coupling and load balance. The usefulness of the proposed approach is illustrated by applying to a case study. Bo Liu 0033, Liyun Dai, Xuelian Cao |
ICSA | 5 |
| 2020 | A survey of model-driven techniques and tools for cyber-physical systemsabstractCyber-physical systems (CPSs) have emerged as a potential enabling technology to handle the challenges in social and economic sustainable development. Since it was proposed in 2006, intensive research has been conducted, showing that the construction of a CPS is a hard and complex engineering process due to the nature of integrating a large number of heterogeneous subsystems. Among other approaches to dealing with the complex design issues, model-driven design of CPSs has shown its advantages. In this review paper, we present a survey of research on model-driven development of CPSs. We are concerned mainly with the widely used methods, techniques, and tools, and discuss how these are applied to CPSs. We also present comparative analyses on the surveyed techniques and tools from various perspectives, including their modeling languages, functionalities, and the challenges which they address in CPS design. With our understanding of the surveyed methods, we believe that model-driven approaches are an inevitable choice in building CPSs and further research effort is needed in the development of model-driven theories, techniques, and tools. We also argue that a unified modeling platform is needed. Such a platform would benefit research in the academic community and practical development in industry, and improve the collaboration between these two communities. Bo Liu 0033, Yuanrui Zhang 0001, Xuelian Cao, Tiexin Wang |
Frontiers Inf. Technol. Electron. Eng. | 3 |