Meixia Miao

dblp:157/4691 · DBLP profile ↗
← Back
25ranked-venue papers
9as first author
15since 2021 · last 2026
0000-0002-9503-4013ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 8 · 3 first-author · 5 since 2021Security and privacy · 8 · 1 first-author · 5 since 2021Databases, data management, data science and information retrieval · 5 · 4 first-author · 4 since 2021Computer networks · 4 · 2 first-author · 3 since 2021Systems, architecture and hardware · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-authorTheory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2026 Verifiable and Controllable Data Sharing With Compliance Checking in Cloud Computing
abstract
Data capsule provides a feasible solution for controllable data sharing, where data owners outsource their data capsules containing encrypted data and compliance-checking policies to the cloud server, and only valid users can run a compliant analysis program to process the decrypted data capsules in the Trusted Execution Environment (TEE), without obtaining the raw data. However, existing schemes cannot achieve verifiable accesses and updates, which means that malicious servers may use corrupted/old data capsules to deceive users and TEE. In this paper, we introduce the concept of Verifiable Data Capsule (VDC) for secure and controllable data sharing. Specifically, we first design a lightweight authentication tag, dubbed Locally Verifiable Chameleon Tag (LVCT), which allows the data owner to bind all data capsules to a constant-size tag and enables users to recover the local tags for validating data capsules. On this basis, we present a concrete VDC scheme that utilizes a dual-level authentication structure to realize verifiable data updates, and verifiable state updates triggered by regular access without the aid of the data owner. Furthermore, we propose an efficient trust evaluation protocol to judge the credibility of cloud servers. Finally, both security analysis and performance evaluation demonstrate the practicability of the proposed scheme.
Guohua Tian, Meixia Miao, Jianghong Wei, Zheli Liu, Liang Guo 0013, Xiaofeng Chen 0001
IEEE Trans. Dependable Secur. Comput.2
2026 Verifiable Data Streaming Protocol Supporting Keyword Queries
abstract
The rapid deployment of emerging networks, such as the Internet of Things and cloud computing, has generated massive amounts of data. Data streaming is significant among these various data types due to its widespread use in many critical applications, such as gene sequencing, network intrusion detection, and stock trading. On the other hand, the continuously increased size of data streaming makes it impractical to store and manage the data locally, especially for those resource-constrained devices. Outsourcing the data streaming to cloud servers provides an ideal solution to the above storage issue. However, this raises the problem of how to guarantee the integrity of the outsourced data, as cloud servers may maliciously modify the data. To this end, the primitive of verifiable data streaming (VDS) was introduced to preserve the integrity of the outsourced data streaming, enabling data users to ensure that queried data items, including the contents and corresponding positions, are correct. Despite many proposed VDS protocols, most can only use the position index to query outsourced data streaming. Consequently, they fail to fulfill the requirements of those practical applications that need keyword queries. For example, in the setting of network intrusion detection, the data analyst would like to query all access records from the same IP address. In this paper, we extend the original VDS protocol to support keyword queries, i.e., allowing data users to retrieve outsourced data items with particular keywords. Specifically, we use a prefix tree to maintain keywords and another chameleon authentication tree to store data items. The two trees are bound together with cryptographic query proofs, ensuring the consistency between the position index and keyword queries. The proposed VDS protocol, which supports keyword queries, is proven secure in the standard model and outperforms previous VDS protocols in terms of functionality. The experimental results indicate that our proposal is also efficient and practical.
Meixia Miao, Peihong Qiang, Siqi Zhao, Jiawei Li 0011, Guohua Tian, Jianghong Wei
IEEE Trans. Netw. Serv. Manag.1
2025 Zeroth-Order Federated Private Tuning for Pretrained Large Language Models
Xiaoyu Zhang 0010, Meixia Miao, Jian Lou 0001, Jin Li 0002, Xiaofeng Chen 0001
ACISP (3)3
2024 Aggregatably Verifiable Data Streaming
abstract
In various real-time applications like intelligent transportation and stock trading systems, clients continuously generate the so-called data streaming that is sensitive to both the position and content. Due to the limitations of local storage resources, clients usually have to outsource the generated data to cloud servers that are not fully trusted. The primitive of verifiable data streaming (VDS) protocol was introduced to guarantee the integrity of the outsourced data streaming. Although many VDS protocols have been proposed to improve the efficiency and security of the original one, they mainly focus on how to verifiably retrieve specific data items, without considering the requirement of retrieving aggregated results. However, such a requirement is desirable in many practical applications that only need the aggregated results of the outsourced streaming data, such as satellite cloud atlas and real-time traffic data. In this paper, we introduce a new primitive named aggregatably verifiable data streaming (AVDS) that allows a data user to retrieve aggregated results of designated data items, while guaranteeing the validity of the aggregated results. Specifically, we introduce a new authenticated data structure named chameleon linear-map vector commitment (CLVC), and also provide a concrete construction. Furthermore, we propose a general framework of AVDS protocols from the building block of CLVC. The proposed AVDS protocol is proven to be secure in the standard model. Theoretical analysis and experimental results indicate that the proposed AVDS protocol extends previous VDS protocols in terms of functionality while having comparable computation and communication overhead.
Meixia Miao, Siqi Zhao, Jiawei Li 0011, Jianghong Wei
IEEE Internet Things J.1
2024 Blockchain-Based Compact Verifiable Data Streaming With Self-Auditing
abstract
The primitive of verifiable data streaming (VDS) provides a secure data outsourcing solution for resource-constrained users, that is, they can stream their continuously-generated data items to untrusted servers while enabling publicly verifiable query and update. However, existing VDS schemes either require the server to store the authentication tags of all data items to support data query and auditing, or bind all data items into a constant-size tag to achieve optimal storage on the server side, but cannot achieve public auditing. To close this gap, in this paper, we first design a novel authentication data structure, dubbed retrievable homomorphic verifiable tags (RHVTs), which allows users to aggregate the authentication tags of all data items into a constant-size tag, and enables them to retrieve the original tags from the aggregated tag when necessary. Based on this, we propose a compact verifiable and auditable data streaming (CVADS) scheme, which adopts a single-level authentication mechanism to achieve more efficient data append and update, as well as optimal storage and public auditing. For better robustness and performance, we introduce a nested dual-level authentication mechanism and propose a blockchain-based CVADS (BCVADS) scheme to achieve a distributed CVADS with self-auditing. Finally, we prove the security of our schemes in the random oracle model and demonstrate their practicality through a visual performance evaluation.
Guohua Tian, Jianghong Wei, Meixia Miao, Fuchun Guo, Willy Susilo, Xiaofeng Chen 0001
IEEE Trans. Dependable Secur. Comput.3
2024 Optimal Verifiable Data Streaming Under Concurrent Queries
abstract
The rapid development of both hardware and software has promoted the popularization of various real-time applications like health monitoring and intrusion detection that are widely deployed in outsourcing scenarios, e.g., mobile edge computing and cloud computing. In these applications, end devices continuously generate unbounded sequences of data items at a fast rate, i.e., the so-called streaming data. Nevertheless, storing and processing massive amounts of streaming data poses a challenge for resources-restricted end devices. Although outsourcing data items to edge servers or cloud servers is an attractive solution to the above problem, it also brings a new challenge, i.e., how to guarantee the integrity of outsourced data, since streaming data applications are usually sensitive of both location and the corresponding context, and servers are not completely trusted. To this end, the primitive of verifiable data streaming (VDS) protocol was introduced to maintain outsourced streaming data, while preserving its integrity. However, existing VDS constructions mainly use the structure of Merkle hash tree, and inherently have logarithmic costs. Consequently, they are infeasible for real-time applications that are delay sensitive and generate unpredictable size of streaming data. In this paper, we optimize previous VDS protocols from the aspects of communication overhead and computation cost. Specifically, we adopt a technical route different from Merkle hash tree, i.e, combining the digital signature with the cryptographic accumulator. In our construction, we employ Boneh-Lynn-Shacham (BLS) signature to guarantee the integrity of the context and position of each outsourced data item, and adopt an RSA accumulator to invalidate the old signature after the corresponding data item was updated. This immediately yields an optimal VDS construction that has constant costs even under concurrent queries, which is more desirable for those resource-limited mobile devices. In addition, the aggregability of BLS signature makes our VDS construction capable of data auditing, which enables the user to remotely verify the integrity of outsourced streaming data. We provide a formal security proof of the proposed VDS construction under well-studied complexity assumptions in the random oracle model. As a proof-of-concept, we also implement our proposal, and conduct extensive experiments to demonstrate its practicability.
Jianghong Wei, Meixia Miao, Guohua Tian, Jun Shen 0006, Xiaofeng Chen 0001, Willy Susilo
IEEE Trans. Mob. Comput.2
2023 Communication-Efficient Verifiable Data Streaming Protocol in the Multi-User Setting
abstract
Verifiable data streaming (VDS) protocols enable end users with limited storage space to continuously stream data items to an untrusted cloud server, while preserving the capacity of verifying the integrity of those retrieved data items for downstream tasks. Although there has been plenty of research around the construction of VDS, we observe that they all focus on the scenario of single-user. When deploying these VDS protocols into more common applications that involve multiple users’ data (e.g., network data monitoring and stock trends analysis), the size of the proof used to prove the integrity of retrieved data items grows linearly with the number of involved users. This would bring tremendous communication overhead, especially for lightweight users. To this end, we initiate the study of VDS protocols that are suitable for multi-user (or cross-user) setting. Specifically, we first introduce a new primitive called aggregatable chameleon vector commitment (ACVC) that allows to aggregate multiple proofs from different commitments into a single proof. Then, based on ACVC, we present a communication-efficient VDS protocol for the multi-user setting. That is, when querying data items from multiple users, the size of corresponding proof is constant and independent of the number of involved users. Theoretical analysis indicates that the proposed VDS protocol outperforms previous VDS protocols in terms of communication overhead. We also implement the proposed ACVC, and conduct extensive experiments to demonstrate its practicability.
Xuan Jing, Meixia Miao, Jianghong Wei, Jianfeng Wang 0001
IEEE Trans. Cloud Comput.2
2023 TinyEnc: Enabling Compressed and Encrypted Big Data Stores With Rich Query Support
abstract
Encryption and compression are two critical techniques to ensure data confidentiality and efficiency for a cloud-based data storage system, respectively. However, directly combing encryption and compression incurs substantial performance degradation. We propose TinyEnc, an encrypted data storage system for cloud-based key-value store, which supports encryption and compression simultaneously with rich query support. To reconcile encryption and compression without compromising performance, we first propose a new encrypted compression data structure to enable fine-grained access to compressed and encrypted key-value data. We then propose two new transforming mechanisms, namely orthogonal data dividing and hierarchical data padding, to transform a plaintext key-value table into the encrypted compression data structure in a privacy-preserving way. Finally, we craft order-revealing encryption (ORE) and symmetric searchable encryption (SSE) to design a new encrypted search index over the encrypted compression data structure to support rich types of data queries. We implement a prototype of TinyEnc on top of Cassandra. Besides, the evaluation result shows that TinyEnc increases the throughput by up to 7 times and compression ratio by up to 1.3 times with respect to previous works.
Saiyu Qi, Jianfeng Wang 0001, Meixia Miao, Xiaofeng Chen 0001
IEEE Trans. Dependable Secur. Comput.3
2022 Detection of global positioning system spoofing attack on unmanned aerial vehicle system
abstract
Summary Most of the existing global positioning system (GPS) spoofing detection schemes are vulnerable to the generative GPS spoofing attack, or require additional auxiliary equipment and extensive signal processing capabilities, leading to defects such as low real‐time performance and large communication overhead which are not available for the unmanned aerial vehicle (UAV, also known as drone) system. Therefore, we propose a novel solution which employs information fusion based on the GPS receiver and inertial measurement unit. We use a real‐time model of tracking and calculating to derive the current position of the drones which are then contrasted with the position information received by the receiver to verify whether the presence or absence of spoofing attack. Subsequent experimental work shows that, the proposed method can accurately detect the spoof within 8 seconds, with a detection rate (DR) of 98.6%. Compared with the existing schemes, the performance of real‐time detecting is improved while the DR is ensured. Even in our worst‐case, we detect the spoof within 28 seconds after the UAV system starts its mission.
Meixia Miao, Jianfeng Ma 0001, Hongyang Yan, Xinghua Li 0001
Concurr. Comput. Pract. Exp.2
2022 Blockchain-based cross-user data shared auditing
abstract
In cloud storage, public auditing is a more popular data integrity verification technique since it allows users to delegate auditing tasks to a fully trusted third-party auditor (TPA). However, it is difficult to find such a TPA in practical application. Besides, the centralised auditing model makes TPA have to bear burdensome work pressure, which limits the practicability of existing schemes. In this paper, we firstly proposed a blockchain-based generalised shared auditing mechanism BCSA in the cross-user scenario, which aims at achieving available public auditing with a non-fully trusted TPA, and reducing the user's auditing fees and TPA's work pressure by allowing data users to share their auditing procedure with others. Furthermore, we initialise a concrete construction BCSAD with Diffie–Hellman protocol for the cross-user auditing scenario with different data. Likewise, we also propose a novel construction BCSAI for the cross-user auditing scenario with identical data, which utilises a password-authenticated key exchange (PAKE) protocol to achieve shared auditing and ciphertext deduplication, reducing data storage and auditing fees for data users and alleviating service pressure on the cloud server and TPA. Security and performance analysis evaluate the practicability of the proposed scheme.
Angtai Li, Guohua Tian, Meixia Miao, Jianpeng Gong
Connect. Sci.3
2022 Verifiable data streaming protocol supporting update history queries
abstract
With the widespread development of intelligent systems, a considerable number of mobile devices are connected together, and continuously generate huge amounts of data. Although cloud storage provides perfect solution for effectively storing these massive data, how to ensure the integrity of the outsourced data becomes challenging. For this reason, the primitive of verifiable data streaming (VDS) protocol was introduced, and enables a data owner to continuously outsource streaming data to an untrusted cloud server, while capturing the integrity of the outsourced data. That is, when a data user retrieves some data item via its index from the server, he/she can publicly verify its integrity with the proof generated and returned by the server. Supporting data update is one of the major features of VDS, and allows the data owner to replace an old data item with a new one. Although many VDS protocols have been proposed to enhance the functionality and efficiency of the original VDS protocol, they all ignore the issue of preserving those updated data items. In fact, in various application scenarios of VDS, preserving and storing previously updated data items is actually necessary. For example, in the setting of DNA sequencing, there might be multiple versions of DNA fragments at the same location due to the genetic mutation. Obviously, for more precise treatment, all these DNA fragments need to be preserved. To this end, in this paper, we propose a VDS protocol that features of enabling the query of the update history of each data item. Specifically, we first put forward a new chameleon authentication tree with update history (UCAT), which consists of two CATs (the basic tree and the update history tree). In more detail, the basic tree is used to store the data item appended to the corresponding location for the first time, and the update history tree is utilized to preserve each updated version of the corresponding data item. Furthermore, based on UCAT, we propose a VDS protocol supporting update history queries, which allows a data user to retrieve any version of the data item. The theoretical analysis and performance evaluation indicate that our protocol outperforms previous ones in the field of functionality, and its computation/communication costs are acceptable. We also prove its security in the standard model.
Meixia Miao, Jiawei Li 0011, Yunling Wang, Jianghong Wei, Xinghua Li 0001
Int. J. Intell. Syst.1
2022 Verifiable data streaming with efficient update for intelligent automation systems
abstract
The wide deployment of Internet of Things (IoT) devices enables the controller to continuously collect massive volume data in automation systems, and makes it possible to make intelligent decisions based on machine learning techniques. In fact, data-driven intelligent automation systems have been common in the industrial community. Nevertheless, how to effectively store the collected stream data and ensure their integrity is still challenging. To this end, the notion of verifiable data streaming (VDS) protocol, which enables a client to outsource the stream data to an untrusted server in a verifiable manner, was introduced. However, we argue that existing VDS protocols based on the chameleon authentication tree (CAT) are inefficient in the data update, since the whole CAT must be updated accordingly to avoid acute exposure of chameleon hashing. Thus, they are infeasible for intelligent automation systems that need to frequently update data. In this article, we first introduce a new primitive called double-trapdoor chameleon hash tree (DCHT) based on the double-trapdoor chameleon hash families, where each leaf of DCHT is calculated and fixed by using a double-trapdoor chameleon hash family, making the entire DCHT always unchanged. Furthermore, we propose a novel VDS protocol based on the DCHT. Due to the distinctive properties of the underlying DCHT, the proposed VDS protocol has a constant update cost and more efficient than previous VDS protocols based on CAT. Besides, we prove that the proposed VDS protocol is secure in the standard model.
Meixia Miao, Jianghong Wei, Kuanching Li, Willy Susilo
Int. J. Intell. Syst.1
2022 Verifiable dynamic search over encrypted data in cloud-assisted intelligent systems
abstract
The cloud-assisted intelligent systems have attracted extensive attention due to their powerful data analysis and computation capabilities. However, how to handle encrypted data remains a challenging problem in intelligent systems. A promising solution is searchable symmetric encryption (SSE), which enables a client to privately outsource their data to the cloud while preserving keyword search functionality. In practice, dynamic SSE is more practical and supports efficient data addition and deletion. Unfortunately, data update will leak some additional information which can be exploited to break data privacy. To address this issue, forward and backward secure SSE schemes are proposed to reduce the leakage of data update. That is, forward security guarantees that the newly updated documents cannot reveal the previously searched keywords, while backward security guarantees that the server cannot recover the deleted documents. However, the existing forward and backward secure SSE schemes mainly consider curious-but-honest server. How to verify the soundness and completeness of search results is still a challenge. In this paper, we propose a noninteractive verifiable dynamic SSE scheme with forward and backward security from two universal accumulators. Specifically, the server in our scheme only needs one roundtrip to return the nondeleted search results to the client, which saves the communication overhead dramatically. Besides, our scheme can achieve public verification that anyone can verify the search results but not only the client who has the private key. Finally, we give a formal security analysis and compare the proposed scheme with other related work, the results show that our scheme can achieve the desired security properties with practical efficiency.
Yunling Wang, Pei Wei, Meixia Miao, Xuefeng Zhang 0004
Int. J. Intell. Syst.3
2021 CECMLP: New Cipher-Based Evaluating Collaborative Multi-layer Perceptron Scheme in Federated Learning
Yuqi Chen 0011, Xiaoyu Zhang 0010, Yi Xie 0011, Meixia Miao
ACNS (1)4
2021 New proofs of ownership for efficient data deduplication in the adversarial conspiracy model
abstract
The primitive of proofs of ownership (PoWs) enables a prover to efficiently convince a verifier that he/she indeed owns a certain message in a knowledge-proof manner. As a result, it can prevent an adversary who only has a short information of the message from accessing the whole one. We argue that the existing PoWs based on Merkle hash tree and specific encodings are not much efficient if the size of message is sufficiently huge. In this paper, we first propose a new PoW protocol based on the chameleon hash function without key exposure. Interestingly, it is equivalent to having the prover compute a new collision of chameleon hashing as the proof in our construction. Therefore, the proposed protocol is much efficient since the computation and storage overhead of proof is independent of the size of the message. Moreover, we utilize the proposed PoWs to design a deduplication scheme over ciphertext.
Meixia Miao, Guohua Tian, Willy Susilo
Int. J. Intell. Syst.1
2019 Enabling Compressed Encryption for Cloud Based Big Data Stores
Saiyu Qi, Meixia Miao, Fuyou Zhang
CANS3
2019 Publicly verifiable database scheme with efficient keyword search
Meixia Miao, Jianfeng Wang 0001, Sheng Wen, Jianfeng Ma 0001
Inf. Sci.1
2019 Towards efficient privacy-preserving encrypted image search in cloud computing
Meixia Miao, Jian Shen 0001, Jianfeng Wang 0001
Soft Comput.2
2018 Efficient Verifiable Databases With Insertion/Deletion Operations From Delegating Polynomial Functions
abstract
The notion of verifiable database with updates (VDB) enables a resource-limited client to securely outsource a very large database to an untrusted server, and the client could later retrieve a database record and update it efficiently. In addition, the client could detect any misbehavior of tampering with the data record by the server. To the best of our knowledge, the existing VDB schemes cannot efficiently support all updating operations (i.e., insertion, deletion, and replacement) simultaneously. In this paper, we introduce a new primitive called Merkle sum hash tree and then use it to design a new VDB scheme that supports for all updating operations from delegating polynomial functions. An interesting property of our scheme is that all updating operations can be viewed as a special case of “replacement” in the Benabbas-Gennaro-Vahlis VDB scheme. Thus, our construction is very efficient for real-world applications. Furthermore, we formally prove that the proposed construction can achieve the desired security properties when the subgroup member assumption holds.
Meixia Miao, Jianfeng Ma 0001, Xinyi Huang 0001, Qian Wang 0002
IEEE Trans. Inf. Forensics Secur.1
2017 Outsourcing Encrypted Excel Files
Ya-Nan Li 0007, Qianhong Wu, Wenyi Tang, Qin Wang 0008, Meixia Miao
ISPEC6
2017 A Secure and Efficient ID-Based Aggregate Signature Scheme for Wireless Sensor Networks
abstract
Affording secure and efficient big data aggregation methods is very attractive in the field of wireless sensor networks (WSNs) research. In real settings, the WSNs have been broadly applied, such as target tracking and environment remote monitoring. However, data can be easily compromised by a vast of attacks, such as data interception and data tampering, etc. In this paper, we mainly focus on data integrity protection, give an identity-based aggregate signature (IBAS) scheme with a designated verifier for WSNs. According to the advantage of aggregate signatures, our scheme not only can keep data integrity, but also can reduce bandwidth and storage cost for WSNs. Furthermore, the security of our IBAS scheme is rigorously presented based on the computational Diffie-Hellman assumption in random oracle model.
Jianfeng Ma 0001, Ximeng Liu, Fushan Wei, Meixia Miao
IEEE Internet Things J.5
2017 Publicly verifiable databases with efficient insertion/deletion operations
Meixia Miao, Jianfeng Wang 0001, Jianfeng Ma 0001, Willy Susilo
J. Comput. Syst. Sci.1
2017 An incentive mechanism for K-anonymity in LBS privacy protection based on credit mechanism
Xinghua Li 0001, Meixia Miao, Hai Liu 0011, Jianfeng Ma 0001, Kuanching Li
Soft Comput.2
2016 Enabling efficient approximate nearest neighbor search for outsourced database in cloud computing
Jianfeng Wang 0001, Meixia Miao, Yaqian Gao, Xiaofeng Chen 0001
Soft Comput.2
2015 Secure multi-server-aided data deduplication in cloud computing
Meixia Miao, Jianfeng Wang 0001, Xiaofeng Chen 0001
Pervasive Mob. Comput.1