VLDB 2026 Research / reviewers in the wild / expert
Fangyu Gai
dblp:142/0301
· DBLP profile ↗
17ranked-venue papers
8as first author
11since 2021 · last 2025
0000-0002-2114-3313ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 8 · 5 first-author · 4 since 2021Security and privacy · 4 · 4 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Chained HotStuff Under Performance AttackabstractChained HotStuff is a state-of-the-art Byzantine fault-tolerant protocol for building decentralized systems like blockchains. Although chained HotStuff has been widely adopted in many systems, its performance (e.g., throughput and latency) under attacks is still under-explored. In this paper, we develop a multi-metric evaluation framework to quantitatively analyze the performance of chained HotStuff with respect to its chain growth rate, chain quality, and latency. We propose several new attack strategies and evaluate their effects on the performance of chained HotStuff. Our analysis shows that the chain growth rate (resp, chain quality) of chained HotStuff under our attacks can drop to$4/9$(resp,$12/17$) of that without attacks when one-third of nodes are Byzantine. In addition, we use our framework to evaluate a variant of chained HotStuff, DiemBFT and find that some engineering optimizations render it more vulnerable to some attacks than the original chained HotStuff. Finally, we provide two countermeasures, i.e., broadcasting QCs and the longest chain rule, to thwart these attacks. Our analysis shows that the proposed countermeasures can significantly reduce the latency (almost half of that in chained HotStuff) and make it impossible for an attacker to lower the chain quality by simple attacks. Jianyu Niu, Fangyu Gai, Mohammad M. Jalalzai, Yinqian Zhang, Chen Feng 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | A Secure Sidechain for Decentralized Trading in Internet of ThingsabstractSidechains allow transaction dissemination and execution outside the blockchain main network (i.e., the mainchain), enabling a scalable, efficient, and secure financial infrastructure for the Internet of Things (IoT) without trusting any central authority. Existing sidechains either have online requirements or rely on intensive computation on a central operator, which does not meet the needs of IoT for dynamic changes and high performance. This article proposes an alternative sidechain construction, called Cumulus, which meets the needs of IoT by leveraging the classic Byzantine fault-tolerant (BFT) consensus protocols, such as PBFT, that have commonly been applied in permissioned blockchains. Cumulus builds BFT-based sidechains atop public blockchains (e.g., Ethereum) using smart contracts and ensures the bidirectional safety of users’ assets. Cumulus sidechains periodically interact with the mainchain and submit checkpoints through representatives selected in an efficient and decentralized manner. The experiments show that Cumulus sidechains outperform rollup-based sidechains, and state-of-the-art sidechain constructions, achieving two and three orders of magnitude improvement in throughput and latency while retaining comparable operational cost. Fangyu Gai, Jianyu Niu, Mohammad M. Jalalzai, Seyed Ali Tabatabaee, Chen Feng 0001 |
IEEE Internet Things J. | 1 |
| 2024 | Fast-HotStuff: A Fast and Robust BFT Protocol for Blockchainsabstracthe HotStuff protocol is a recent breakthrough in Byzantine Fault Tolerant (BFT) consensus that enjoys both responsiveness and linear view change by creatively adding a round to classic two-round BFT protocols like PBFT. Despite its great advantages, HotStuff has a few limitations. First, the additional round of communication during normal cases results in higher latency. Second, HotStuff is vulnerable to certain performance attacks, which can significantly deteriorate its throughput and latency. To address these limitations, we propose a new two-round BFT protocol called Fast-HotStuff, which enjoys responsiveness and efficient view change that is comparable to the linear view-change in terms of performance. Our Fast-HotStuff has lower latency and is more robust against the performance attacks that HotStuff is susceptible to. Mohammad M. Jalalzai, Jianyu Niu, Chen Feng 0001, Fangyu Gai |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | Scaling Blockchain Consensus via a Robust Shared MempoolabstractLeader-based Byzantine fault-tolerant (BFT) consensus protocols used by permissioned blockchains have limited scalability and robustness. To alleviate the leader bottleneck in BFT consensus, we introduce Stratus, a robust shared mempool protocol that decouples transaction distribution from consensus. Our idea is to have replicas disseminate transactions in a distributed manner and have the leader only propose transaction ids. Stratus uses a provably available broadcast (PAB) protocol to ensure the availability of the referenced transactions. To deal with unbalanced load across replicas, Stratus adopts a distributed load balancing protocol.We implemented and evaluated Stratus by integrating it with state-of-the-art BFT-based blockchain protocols. Our evaluation of these protocols in both LAN and WAN settings shows that Stratus-based protocols achieve 5× to 20× higher throughput than their native counterparts in a network with hundreds of replicas. In addition, the performance of Stratus degrades gracefully in the presence of network asynchrony, Byzantine attackers, and unbalanced workloads. Fangyu Gai, Jianyu Niu, Ivan Beschastnikh, Chen Feng 0001, Sheng Wang 0011 |
ICDE | 1 |
| 2023 | Bitcoin-Enhanced Proof-of-Stake Security: Possibilities and ImpossibilitiesabstractBitcoin is the most secure blockchain in the world, supported by the immense hash power of its Proof-of-Work miners. Proof-of-Stake chains are energy-efficient, have fast finality but face several security issues: susceptibility to non-slashable long-range safety attacks, low liveness resilience and difficulty to bootstrap from low token valuation. We show that these security issues are inherent in any PoS chain without an external trusted source, and propose a new protocol, Babylon, where an off-the-shelf PoS protocol checkpoints onto Bitcoin to resolve these issues. An impossibility result justifies the optimality of Babylon. A use case of Babylon is to reduce the stake withdrawal delay: our experimental results show that this delay can be reduced from weeks in existing PoS chains to less than 5 hours using Babylon, at a transaction cost of less than 10K USD per annum for posting the checkpoints onto Bitcoin. Ertem Nusret Tas, David Tse, Fangyu Gai, Sreeram Kannan, Mohammad Ali Maddah-Ali, Fisher Yu 0002 |
SP | 3 |
| 2023 | Crystal: Enhancing Blockchain Mining Transparency With Quorum CertificateabstractResearchers have discovered a series of theoretical attacks against Bitcoin's Nakamoto consensus; the most damaging ones are selfish mining, double-spending, and consistency delay attacks. These attacks have one common cause: block withholding. This paper proposes Crystal, which leverages quorum certificates to resist block withholding misbehavior. Crystal continuously elects committees from miners and requires each block to have a quorum certificate, i.e., a set of signatures issued by members of its committee. Consequently, an attacker has to publish its blocks to obtain quorum certificates, rendering block withholding impossible. To build Crystal, we design a novel two-round committee election in a Sybil-resistant, unpredictable and non-interactive way, and a reward mechanism to incentivize miners to follow the protocol. Our analysis and evaluations show that Crystal can significantly mitigate selfish mining and double-spending attacks. For example, in Bitcoin, an attacker with 30% of the total computation power will succeed in double-spending attacks with a probability of 15.6% to break the 6-confirmation rule; however, in Crystal, the success probability for the same attacker falls to 0.62%. We provide formal end-to-end safety proofs for Crystal, ensuring no unknown attacks will be introduced. To the best of our knowledge, Crystal is the first protocol that prevents selfish mining and double-spending attacks while providing safety proof. Jianyu Niu, Fangyu Gai, Runchao Han, Ren Zhang 0003, Yinqian Zhang, Chen Feng 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Ubiquitous Verification in Centralized Ledger DatabaseabstractVerifiability is the backbone of most ledger systems to realize credible authentication. However, existing permissioned blockchains and centralized ledger databases lack rigorous verifiability to authenticate all facts (i.e., what-when-who validation). Besides, they suffer from high verification cost to a continually growing immutable storage. In this paper, we introduce verification principles behind LedgerDB, a centralized ledger database that achieves both strong external auditability and fast verification. We coin a novel concept called Dasein Verification that composes of three validation factors what-when-who to formalize ledger auditing. Regarding what, LedgerDB devises fam (fractal accumulating model) to accelerate existence verification, and CM-Tree for efficient lineage verification. Veri-fiable data mutations are also supported. For when, we discuss attacks on existing time pegging protocols that compromise the authenticity of timestamps, and propose a time notary protocol to resolve those threats. Evaluations show that fam and CM- Tree significantly outperform traditional approaches. Compared to Hyperledger Fabric, LedgerDB achieves 23x higher verification throughput with 500 x lower latency in notarization applications, and 3 x higher throughput with 300 x lower latency in lineage tracking applications. As a public-cloud ledger service, the end-to-end verification latencies of LedgerDB are on average 50 x and 1000x lower than that of QLDB in the above applications, respectively. Xinying Yang, Sheng Wang 0011, Feifei Li 0001, Wenyuan Yan, Fangyu Gai, Benquan Yu, Likai Feng, Qun Gao |
ICDE | 6 |
| 2021 | Dissecting the Performance of Chained-BFTabstractPermissioned blockchains employ Byzantine fault-tolerant (BFT) state machine replication (SMR) to reach agreement on an ever-growing, linearly ordered log of transactions. A new paradigm, combined with decades of research in BFT SMR and blockchain (namely chained-BFT, or cBFT), has emerged for directly constructing blockchain protocols. Chained-BFT protocols have a unifying propose-vote scheme instead of multiple different voting phases with a set of voting and commit rules to guarantee safety and liveness. However, distinct voting and commit rules impose varying impacts on performance under different workloads, network conditions, and Byzantine attacks. Therefore, a fair comparison of the proposed protocols poses a challenge that has not yet been addressed by existing work. We fill this gap by studying a family of cBFT protocols with a two-pronged systematic approach. First, we present an evaluation and benchmarking framework, called Bamboo, for quick prototyping of cBFT protocols. To validate Bamboo, we introduce an analytic model using queuing theory which also offers a back-of-the-envelope guide for dissecting these protocols. We build multiple cBFT protocols using Bamboo and we are the first to fairly compare three cBFT representatives (i.e., HotStuff, two-chain HotStuff, and Streamlet). We evaluated these protocols under various parameters and scenarios, including two Byzantine attacks that have not been widely discussed in the literature. Our findings reveal interesting trade-offs (e.g., responsiveness vs. forking-resilience) between different cBFT protocols and their design choices, which provide developers and researchers with insights into the design and implementation of this protocol family. Fangyu Gai, Ali Farahbakhsh, Jianyu Niu, Chen Feng 0001, Ivan Beschastnikh |
ICDCS | 1 |
| 2021 | On the Performance of Pipelined HotStuffabstractHotStuff is a state-of-the-art Byzantine fault-tolerant consensus protocol. It can be pipelined to build large-scale blockchains. One of its variants called LibraBFT is adopted in Facebook's Libra blockchain. Although it is well known that pipelined HotStuff is secure against up to 1/3 of Byzantine nodes, its performance in terms of throughput and delay is still under-explored. In this paper, we develop a multi-metric evaluation framework to quantitatively analyze pipelined HotStuff's performance with respect to its chain growth rate, chain quality, and latency. We then propose several attack strategies and evaluate their effects on the performance of pipelined HotStuff. Our analysis shows that the chain growth rate (resp, chain quality) of pipelined HotStuff under our attacks can drop to as low as 4/9 (resp, 12/17) of that without attacks when 1/3 nodes are Byzantine. As another application, we use our framework to evaluate certain engineering optimizations adopted by LibraBFT. We find that these optimizations make the system more vulnerable to our attacks than the original pipelined HotStuff. Finally, we provide two countermeasures to thwart these attacks. We hope that our studies can shed light on the rigorous understanding of the state-of-the-art pipelined HotStuff protocol as well as its variants. Jianyu Niu, Fangyu Gai, Mohammad M. Jalalzai, Chen Feng 0001 |
INFOCOM | 2 |
| 2021 | Cumulus: A Secure BFT-based Sidechain for Off-chain ScalingabstractSidechains enable off-chain scaling by sending transactions in a private network rather than broadcasting them in the public blockchain (i.e., the mainchain) network. To this end, classic Byzantine fault-tolerant (BFT) consensus protocols such as PBFT seem an excellent fit to fuel sidechains for their permissioned settings and inherent robustness. However, designing a secure and efficient BFT-based sidechain protocol remains an open challenge.This paper presents Cumulus, a novel BFT-based sidechain framework for blockchains to achieve off-chain scaling without compromising any security and efficiency properties of both sides’ consensus protocols. Cumulus encompasses a novel cryptographic sortition algorithm called Proof-of-Wait to fairly select sidechain nodes to communicate with the mainchain in an efficient and decentralized manner. To further reduce the operational cost, Cumulus provides an optimistic checkpointing approach in which the mainchain will not verify checkpoints unless disputes happen. Meanwhile, end-users enjoy a two-step withdrawal protocol, ensuring that they can safely collect assets back to the mainchain without relying on the BFT committee. Our experiments show that Cumulus sidechains outperform ZK-Rollup, another promising sidechain construction, achieving one and two orders of magnitude improvement in throughput and latency while retaining comparable operational cost. Fangyu Gai, Jianyu Niu, Seyed Ali Tabatabaee, Chen Feng 0001, Mohammad M. Jalalzai |
IWQoS | 1 |
| 2021 | Publish or Perish: Defending Withholding Attack in Dfinity ConsensusabstractSynchronous Byzantine consensus has regained its popularity with the rise of permissioned blockchains due to its significantly better fault tolerance (up to minority faults) than its partially synchronous counterpart (less than one third). Dfinity Consensus is a state-of-the-art synchronous Byzantine consensus protocol. However, Dfinity is vulnerable to the withholding attack. For example, adversaries can strategically withhold blocks, resulting in an increase in latency and unbounded message complexity. Motivated by this observation, we present Dfinity++, which can effectively defend such an attack. The key idea behind Dfinity++ is simple. Since honest replicas would timely publish their blocks, one can detect delayed blocks and then trigger a fast switch to the next iteration, leading to better resource usage. Our results show that against a static/mildly adversary, Dfinity++ is able to reduce the latency (of committing a new block) by 10.7%, and at the same time enjoys a message complexity of $O\left(n^{2}\right)$. Hanzheng Lyu, Jianyu Niu, Fangyu Gai, Chen Feng 0001 |
MSN | 3 |
| 2020 | Incentive analysis of Bitcoin-NG, revisited
Jianyu Niu, Ziyu Wang 0009, Fangyu Gai, Chen Feng 0001 |
Perform. Evaluation | 3 |
| 2018 | Proof of Reputation: A Reputation-Based Consensus Protocol for Peer-to-Peer Network
Fangyu Gai, Wenping Deng, Wei Peng 0005 |
DASFAA (2) | 1 |
| 2018 | A Blockchain-Based Authentication and Security Mechanism for IoTabstractThe existing identity authentication of IoT devices mostly depends on an intermediary institution, i.e., a CA server, which suffers from the single-point-failure attack. Even worse, the critical data of authenticated devices can be tampered by inner attacks without being identified. To address these issues, we utilize blockchain technology, which serves as a secure tamper-proof distributed ledger to IoT devices. In the proposed method, we assign a unique ID for each individual device and record them into the blockchain, so that they can authenticate each other without a central authority. We also design a data protection mechanism by hashing significant data (i.e. firmware) into the blockchain where any state changes of the data can be detected immediately. Finally, we implement a prototype based on an open source blockchain platform Hyperledger Fabric to verify the proposed system. Dongxing Li, Wei Peng 0005, Wenping Deng, Fangyu Gai |
ICCCN | 4 |
| 2017 | Multidimensional Trust-Based Anomaly Detection System in Internet of Things
Fangyu Gai, Jiexin Zhang 0001, Peidong Zhu, Xinwen Jiang |
WASA | 1 |
| 2017 | Ratee-Based Trust Management System for Internet of Vehicles
Fangyu Gai, Jiexin Zhang 0001, Peidong Zhu, Xinwen Jiang |
WASA | 1 |
| 2017 | Trust on the Ratee: A Trust Management System for Social Internet of VehiclesabstractThe integration of social networking concepts with Internet of Vehicles (IoV) has led to the novel paradigm “Social Internet of Vehicles (SIoV),” which enables vehicles to establish social relationships autonomously to improve traffic conditions and service discovery. There is a growing requirement for effective trust management in the SIoV, considering the critical consequences of acting on misleading information spread by malicious nodes. However, most existing trust models are rater-based, where the reputation information of each node is stored in other nodes it has interacted with. This is not suitable for vehicular environment due to the ephemeral nature of the network. To fill this gap, we propose a Ratee-based Trust Management (RTM) system, where each node stores its own reputation information rated by others during past transactions, and a credible CA server is introduced to ensure the integrality and the undeniability of the trust information. RTM is built based on the concept of SIoV, so that the relationships established between nodes can be used to increase the accuracy of the trustworthiness. Experimental results demonstrate that our scheme achieves faster information propagation and higher transaction success rate than the rater-based method, and the time cost when calculating trustworthiness can meet the demand of vehicular networks. Fangyu Gai, Jiexin Zhang 0001, Peidong Zhu, Xinwen Jiang |
Wirel. Commun. Mob. Comput. | 1 |