VLDB 2026 Research / reviewers in the wild / expert
Haotian Wu 0001
dblp:145/5323-1
· DBLP profile ↗
11ranked-venue papers
6as first author
7since 2021 · last 2026
0000-0001-9511-2475ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 2 first-author · 3 since 2021Computer networks · 2 · 1 first-authorSecurity and privacy · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SpringFuzz: Comprehensive grey-box fuzzing of spring-based web applications
Dikai Zou, Jun Tao 0003, Kecheng Zhou, Haotian Wu 0001 |
Comput. Secur. | 5 |
| 2025 | HeX: Encrypted Rich Queries With Forward and Backward Privacy Using Trusted HardwareabstractDynamic searchable symmetric encryption (DSSE) schemes empower data owners to outsource their encrypted data to clouds while retaining the ability to update or search on it. Despite a lot of efforts devoted in recent years, there are still several challenges that have not been well addressed. First, the confidentiality of data might be compromised if forward privacy and backward privacy cannot be ensured. Second, only the traditional single keyword-file search has attracted tremendous attention, while other popular queries like Boolean queries and range queries are not fully investigated. Lastly, how to solve these problems on untrusted servers that may deviate from pre-defined protocols is also challenging. In this article, aiming to tackle the above problems, we propose a novel DSSE scheme named${\sf HeX}$based on Trusted Execution Environment (TEE) that supports rich queries on untrusted servers while guaranteeing forward and backward privacy. We achieve strong forward and backward security by designing a deferred obfuscating read-write technique atop the bitmap index. We further extend the basic scheme to realize Boolean queries and range queries by reducing them to basic keyword queries. Strict theoretical analysis is conducted to prove the security of${\sf HeX}$, and extensive evaluations illustrate its efficiency and practicality. Haotian Wu 0001, Zhe Peng, Jiang Xiao 0001, Lei Xue 0001, Chenhao Lin, Sai Ho Chung |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | TELEX: Two-Level Learned Index for Rich Queries on Enclave-Based Blockchain SystemsabstractBlockchain has become a popular paradigm for secure and immutable data storage. Despite its numerous applications across various fields, concerns regarding the user privacy and result integrity during data queries persist. Additionally, the need for rich query functionalities to harness the full potential of blockchain data remains an area ripe for exploration. In order to address these challenges, our paper first utilizes a framework based on the Trusted Execution Environment (TEE) and oblivious RAM technique to achieve both privacy and data integrity. To enhance the query efficiency over the entire blockchain, we then devise a two-level learned indexing methodology named TELEX within the TEE for both integer and string keys. We also propose different query processing algorithms for versatile query types, including exact queries, aggregate queries, Boolean queries, and range queries. By implementing the prototype and conducting extensive evaluation, we demonstrate the feasibility and remarkable improvement in efficiency compared to existing solutions. Haotian Wu 0001, Yuzhe Tang, Zhaoyan Shen, Jun Tao 0003, Chenhao Lin, Zhe Peng |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2023 | Enabling Privacy-Preserving and Efficient Authenticated Graph Queries on Blockchain-Assisted CloudsabstractPrior research has introduced a new scenario of blockchain-assisted clouds where the data owner outsources original data to cloud servers and stores some metadata on the blockchain. Despite some research on key-value query and range query in this hybrid-storage scenario, other more complicated data types are not yet supported. In this article, we conduct pioneering research on authenticated queries for graph data, which is a popular data type such as the knowledge graph data, on the blockchain-assisted cloud. The primary challenge is how to design an authenticated data structure (ADS) that supports authenticated queries and can be easily maintained by the blockchain. To this end, we propose a novel ADS, named PAGB, based on the RSA accumulator and completeness set. It can also prevent the original data from being revealed to the public through blockchain or irrelevant queries. We further optimize our design to be more efficient in terms of communication and computation. The effectiveness and efficiency of PAGB are verified through theoretical analysis and extensive experiments. Haotian Wu 0001, Zecheng Li 0001, Rui Song 0010, Bin Xiao 0001 |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2022 | Slicer: Verifiable, Secure and Fair Search over Encrypted Numerical Data Using BlockchainabstractVerifiable Searchable Symmetric Encryption (SSE) enables reliable search over encrypted, privacy-preserving data on untrusted clouds. Most existing SSE designs only focus on keyword-file search. However, a more difficult but useful search, range search over encrypted numerical values remains unsolved. Moreover, the fairness of search in the mutual distrusted scenario without public verification, where data users may maliciously deny the results after the local result verification, is not well addressed yet. In this paper, we take the first step to study the public verification problem atop the blockchain for encrypted numerical search. We design a novel verifiable SSE scheme named Slicer based on a Succinct Order-Revealing Encryption (SORE) scheme to achieve range search on numerical data. Our search results are verifiable, updated and privacy-preserving by SSE and maintaining the forward security. We illustrate the security and practicality of our design through rigorous analysis and extensive evaluations respectively. Haotian Wu 0001, Rui Song 0010, Kai Lei, Bin Xiao 0001 |
ICDCS | 1 |
| 2022 | Pistis: Issuing Trusted and Authorized Certificates With Distributed Ledger and TEEabstractThe security of HTTPS fundamentally relies on SSL/TLS certificates issued by Certificate Authorities (CAs), which, however, are vulnerable to be compromised to issue unauthorized certificates (i.e., certificates issued without domains’ permission). Current countermeasures such as Certificate Transparency (CT) can only detect unauthorized certificates rather than preventing them. In this article, we presentPistis, a framework for issuing authorized and trusted certificates with the distributed ledger and Trusted Execution Environment (TEE) technology. InPistis, TEE nodes validate whether the domain in a requested certificate passes the domain ownership validation (i.e., under corresponding applicants’ control) and submit attested results to a smart contract in the distributed ledger. The smart contract issues a certificate to the applicant when an attested result shows a pass. Therefore,Pistiscan ensure its issued certificates are authorized due to the domain ownership validation mechanism in the TEE. Furthermore, as the issued certificates are stored in a Merkle Patricia Tree (MPT) inPistis, they are trusted and can be verified by a normal user easily. The security ofPistisis formally proved in the Universally Composable (UC) framework. Compared with state-of-the-art,Pistisavoids potential damages by preventing unauthorized certificates from issuing. Zecheng Li 0001, Haotian Wu 0001, Laphou Lao, Songtao Guo, Yuanyuan Yang 0001, Bin Xiao 0001 |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2022 | VQL: Efficient and Verifiable Cloud Query Services for Blockchain SystemsabstractDespite increasingly emerging applications, a primary concern for blockchain to be fully practical is the inefficiency of data query. Direct queries on the blockchain take much time by searching every block, while indirect queries on a blockchain database greatly degrade the authenticity of query results. To conquer the authenticity problem, we propose a Verifiable Query Layer (VQL) that can be deployed in the cloud to provide both efficient and verifiable data query services for blockchain systems. The middleware layer extracts data from the underlying blockchain system and efficiently reorganizes them in databases. To prevent falsified data from being stored in the middleware, a cryptographic fingerprint is calculated based on each constructed database. The database fingerprint will be first verified by miners and then written into the blockchain. Moreover, public users can verify the entire databases or several databases that interest them in the middleware layer. We implement VQL together with the verification schemes and conduct extensive experiments based on a practical blockchain system. The evaluation results demonstrate that VQL can efficiently support various data query services and guarantee the authenticity of query results for blockchain systems. Haotian Wu 0001, Zhe Peng, Songtao Guo, Yuanyuan Yang 0001, Bin Xiao 0001 |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2020 | Towards a Stable and Truthful Incentive Mechanism for Task Delegation in Hierarchical CrowdsensingabstractIn order to achieve the desired performance of crowdsensing, the incentive mechanism, which can stimulate the workers to serve the sensing tasks efficiently, is usually indispensable. Different from the existing research efforts of incentive mechanisms, we propose an incentive mechanism to facilitate the delegation of tasks among the workers in hierarchical crowdsensing. Considering the task converging at some skillful workers, which will degrade the system stability and unbalance the workload among the workers, we construct a Stable and Truthful Incentive Mechanism (STIM) to model and restrict the interactions between the requester and the workers. STIM mechanism comprises a queue control algorithm for the workers and an auction scheme with Multi-sEllers for the Divisible tAsks (MEDA), which exploits an optimal winning bids determination strategy and conducts a truthful payment algorithm. The soundness of the modeling and the accuracy of the analysis are verified through extensive simulations. Haotian Wu 0001, Jun Tao 0003, Bin Xiao 0001 |
ICC | 1 |
| 2018 | Collaborative Route Plan for Parking Sites Selection in Bike-Sharing SystemsabstractIn order to alleviate the traffic congestion caused by the bike-sharing system, the bicycles should be parked in designated parking sites, particularly around the hot scenic spots. A proper route, which guides the cyclers to select a vacant place among the sites to park the bike, is required. In this paper, the Expected Travel Distance (ETD) and the Probability of Successful Parking (PSP) are formulated to evaluate the routes, which will guide the users to travel all the parking sites. We exploit the Poisson process to model the increment of the bicycle number in the parking site and construct the travel tree for the route plan problem. To provide a proper route, we propose the GOR algorithm and the F-M method based on the travel tree. Through extensive simulations, our algorithms are compared with TSP in terms of ETD, PSP and the execution time. Yang Gao 0033, Jun Tao 0003, Yifan Xu 0002, Haotian Wu 0001, Noah Kwaku Baah |
CSCWD | 4 |
| 2018 | Contacts-aware opportunistic forwarding in mobile social networks: A community perspectiveabstractExploiting community structure for opportunistic forwarding decisions in mobile social networks offers a promising paradigm to improve the transmission performance and reduce the extra network overhead. Actually, people will have closer relationships and more opportunities to contact with each other if they are in the same community. In this paper, the activeness of nodes and the probability of reaching the destination are investigated based on the node contacts in the trace. Then the Contacts-Aware Opportunistic Forwarding (CAOF) scheme, which includes inter-community and intra-community phase, is proposed. In the inter-community phase, the node with higher global activeness and source-to-destination probability is selected to serve as the relay. Besides, in the intra-community phase, the forwarding decisions are determined by the local metrics. Furthermore, we compare the proposed CAOF scheme with several benchmark forwarding algorithms, including BUBBLE Rap, SPRINT, Epidemic and JDER. The validity of the modeling and the soundness of the analysis are verified through extensive experiments with real traces, which illustrates that it outperforms other routing strategies in heavy traffic scenarios. Jun Tao 0003, Haotian Wu 0001, Shujing Shi, Yang Gao 0033 |
WCNC | 2 |
| 2017 | A quality-enhancing coverage scheme for camera sensor networksabstractExploiting camera sensors to conduct intruder detection has attracted a lot of research attention. Different from the traditional sensor with omni-directional sensing model, a camera sensor usually has a specified direction with a fixed sensing angle of sensing area. The sensing quality of coverage is critical to the application of coverage scheme. In this paper, we first investigate the complete coverage issue with two alternative layouts of sensing area by 2 camera sensors. Considering the weighted image quality and the importance of sensing area, we propose a quality-enhancing coverage scheme for camera sensor networks, QCC, to improve the coverage performance. We then mathematically present a geometrical probability-based analysis to theoretically evaluate the performance of intruder detection approach. Furthermore, the extension of QCC scheme, QCC-D, is proposed to cover the sensing areas with differentiated importance. Through extensive simulations, our scheme is demonstrated to outperform the best known coverage algorithms, in terms of both overlap area ratio and total weighted quality. Jun Tao 0003, Tianqi Zhai, Haotian Wu 0001, Yifan Xu 0002, Yongqiang Dong |
IECON | 3 |