VLDB 2026 Research / reviewers in the wild / expert
Jianyu Niu
dblp:161/2037
· DBLP profile ↗
34ranked-venue papers
8as first author
32since 2021 · last 2026
0000-0001-5253-941XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 3 first-author · 16 since 2021Computer networks · 8 · 3 first-author · 8 since 2021Systems, architecture and hardware · 7 · 2 first-author · 5 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Hydra: Breaking the Global Ordering Barrier in Multi-BFT ConsensusabstractMulti-Byzantine Fault Tolerant (Multi-BFT) consensus, which runs multiple BFT instances in parallel, has recently emerged as a promising approach to overcome the leader bottleneck in classical BFT protocols. However, existing designs rely on a global ordering layer to serialize blocks across instances, an intuitive yet costly mechanism that constrains scalability, amplifies failure propagation, and complicates deployment. In this paper, we challenge this conventional wisdom. We present HYDRA, the first Multi-BFT consensus framework that eliminates global ordering altogether. HYDRA introduces an object-centric execution model that partitions transactions by their accessed objects, enabling concurrent yet deterministic execution across instances. To ensure consistency, HYDRA combines lightweight lock-based coordination with a deadlock resolution mechanism, achieving both scalability and correctness. We implement HYDRA and evaluate it on up to 128 replicas in both LAN and WAN environments. Experimental results show HYDRA outperforms several state-of-the-art Multi-BFT protocols in the presence of a straggler. These results demonstrate strong consistency and high performance by removing global ordering, opening a new direction toward scalable Multi-BFT consensus design. Hanzheng Lyu, Shaokang Xie, Jianyu Niu, Mohammad Sadoghi, Yinqian Zhang, Cong Wang 0001, Ivan Beschastnikh, Chen Feng 0001 |
ICDE | 3 |
| 2026 | When Cache Poisoning Meets LLM Systems: Semantic Cache Poisoning and Its Countermeasures
Guanlong Wu, Taojie Wang, Jianyu Niu, Yinqian Zhang |
NDSS | 5 |
| 2026 | EBFT: Simplifying BFT Consensus Through Egalitarianism
Jianyu Niu, Runchao Han, Hanzheng Lyu, Ivan Beschastnikh, Yinqian Zhang, Chen Feng 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | Mercury: Practical Cross-Chain Exchange via Trusted HardwareabstractThe proliferation of blockchain-backed cryptocurrencies has sparked the need for cross-chain exchanges of diverse digital assets. Unfortunately, current exchanges suffer from high on-chain verification costs, weak threat models of central trusted parties, or synchronous requirements, making them impractical for currency trading applications. In this paper, we present MERCURY, a practical cryptocurrency exchange that is trust-minimized and efficient without online-client requirements. MERCURY leverages Trusted Execution Environments (TEEs) to shield participants from malicious behaviors, eliminating the reliance on trusted participants and making on-chain verification efficient. Despite the simple idea, building a practical TEE-assisted cross-chain exchange is challenging due to the security and unavailability issues of TEEs. MERCURY tackles the unavailability problem of TEEs by implementing an efficient challenge-response mechanism executed on smart contracts. Furthermore, MERCURY utilizes a lightweight transaction verification mechanism and adopts multiple optimizations to reduce on-chain costs. Comparative evaluations with XClaim, ZK-bridge, and Tesseract demonstrate that MERCURY significantly reduces on-chain costs by approximately 67.87%, 45.01%, and 47.70%, respectively. Xiaoqing Wen, Quanbi Feng, Jianyu Niu, Yinqian Zhang, Chen Feng 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | DisT-FL: Enhancing Security for TEE-Based Aggregation in Federated Learning
Guanlong Wu, Ju Yang, Jianyu Niu, Guoxing Chen, Jianzong Wang, Yinqian Zhang |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2026 | Leader Rotation is Not Enough: Scrutinizing Leadership Democracy of Chained BFT ConsensusabstractWith the growing popularity of blockchains, modern chained BFT protocols combining chaining and leader rotation to obtain better efficiency and leadership democracy have received increasing interest. Although the efficiency provisions of chained BFT protocols have been thoroughly analyzed, the leadership democracy has received little attention in prior work. In this paper, we scrutinize the leadership democracy of four representative chained BFT protocols, especially under attack. To this end, we propose a unified framework with two evaluation metrics,i.e., chain quality and censorship resilience, and quantitatively analyze chosen protocols through the Markov Decision Process (MDP). With this framework, we further examine the impact of two key components,i.e., voting pattern and leader rotation, on leadership democracy. Our results indicate that leader rotation is not enough to provide the leadership democracy guarantee; an adversary could utilize the design,e.g., voting pattern, to deteriorate the leadership democracy significantly. Based on the analysis results, we propose customized countermeasures for three evaluated protocols to improve their leadership democracy with only slight protocol overhead and no change of consensus rules. We also discuss future directions toward building more democratic chained BFT protocols. Jianyu Niu, Yining Tang, Runchao Han, Chen Feng 0001, Yinqian Zhang |
IEEE Trans. Netw. | 1 |
| 2025 | Ladon: High-Performance Multi-BFT Consensus via Dynamic Global OrderingabstractMulti-BFT consensus runs multiple leader-based consensus instances in parallel, circumventing the leader bottleneck of a single instance. However, it contains an Achilles' heel: the need to globally order output blocks across instances. Deriving this global ordering is challenging because it must cope with different rates at which blocks are produced by instances. Prior Multi-BFT designs assign each block a global index before creation, leading to poor performance. Hanzheng Lyu, Shaokang Xie, Jianyu Niu, Chen Feng 0001, Yinqian Zhang, Ivan Beschastnikh |
EuroSys | 3 |
| 2025 | Achilles: Efficient TEE-Assisted BFT Consensus via Rollback Resilient RecoveryabstractBFT consensus that uses Trusted Execution Environments (TEEs) to improve the system tolerance and performance is gaining popularity. However, existing works suffer from TEE rollback issues, resulting in a tolerance-performance tradeoff. In this paper, we propose Achilles, an efficient TEE-assisted BFT protocol that breaks the tradeoff. The key idea behind Achilles is removing the expensive rollback prevention of TEEs from the critical path of committing transactions. To this end, Achilles adopts a rollback resilient recovery mechanism, which allows nodes to assist each other in recovering their states. Besides, Achilles follows the chaining spirit in modern chained BFT protocols and leverages customized chained commit rules to achieve linear message complexity, end-to-end transaction latency of four communication steps, and fault tolerance for the minority of Byzantine nodes. Achilles is the first TEE-assisted BFT protocol in line with CFT protocols in these metrics. We implement a prototype of Achilles based on Intel SGX and evaluate it in both LAN and WAN, showcasing its outperforming performance compared to several state-of-the-art counterparts. Jianyu Niu, Xiaoqing Wen, Guanlong Wu, Shengqi Liu, Jiangshan Yu, Yinqian Zhang |
EuroSys | 1 |
| 2025 | Orthrus: Accelerating Multi-BFT Consensus Through Concurrent Partial Ordering of TransactionsabstractMulti-Byzantine Fault Tolerant (Multi-BFT) consensus allows multiple consensus instances to run in parallel, resolving the leader bottleneck problem inherent in classic BFT consensus. However, the global ordering of Multi-BFT consensus enforces a strict serialized sequence of transactions, imposing additional confirmation latency and also limiting concurrency. In this paper, we introduce Orthrus, a Multi-BFT protocol that accelerates transaction confirmation through partial ordering while reserving global ordering for transactions requiring stricter sequencing. To this end, Orthrus strategically partitions transactions to maximize concurrency and ensure consistency. Additionally, it incorporates an escrow mechanism to manage interactions between partially and globally ordered transactions. We evaluated Orthrus through extensive experiments in realistic settings, deploying 128 replicas in WAN and LAN environments. Our findings demonstrate latency reductions of up to 87% in WAN compared to existing Multi-BFT protocols. Hanzheng Lyu, Shaokang Xie, Jianyu Niu, Ivan Beschastnikh, Yinqian Zhang, Mohammad Sadoghi, Chen Feng 0001 |
ICDE | 3 |
| 2025 | Dissecting Ethereum Staking at Scale: A Comprehensive Measurement and AnalysisabstractDecentralization is a critical security property for blockchain systems. Ethereum adopts a protocol design with multiple incentive mechanisms to encourage validators to contribute to decentralization. However, little empirical evidence exists on the actual effectiveness of Ethereum's incentive mechanism. In this paper, we collect and analyze data on validator rewards from Ethereum's consensus and execution layers, examining both the distribution of rewards and the degree of decentralization in the current network. Our findings show that Ethereum's reward allocation exhibits a relatively balanced distribution, with neither staking pools nor exchanges earning disproportionately higher returns simply due to their larger stake. These findings reveal the effectiveness of Ethereum's incentive design and the current state of decentralization, providing a foundation for future improvements in mechanism design and exploration. Quanbi Feng, Yinan Mi, Hanzheng Lyu, Jianbin Zou, Jianyu Niu |
ICPADS | 5 |
| 2025 | I Know What You Asked: Prompt Leakage via KV-Cache Sharing in Multi-Tenant LLM Serving
Guanlong Wu, Weili Wang 0005, Jianyu Niu, Yinqian Zhang |
NDSS | 5 |
| 2025 | TeeRollup: Efficient Rollup Design Using Heterogeneous TEEabstractRollups have emerged as a promising approach to improving blockchains’ scalability by offloading transaction execution off-chain. Existing rollup solutions either leverage complex zero-knowledge proofs or optimistically assume execution correctness unless challenged. However, these solutions suffer from high gas costs and significant withdrawal delays, hindering their adoption in decentralized applications. This paper introducesTeeRollup, an efficient rollup protocol that leverages Trusted Execution Environments (TEEs) to achieve both low gas costs and short withdrawal delays. Sequencers (i.e., system participants) execute transactions within TEEs and upload signed execution results to the blockchain with confidential keys of TEEs. Unlike most TEE-assisted blockchain designs,TeeRollupadopts a practical threat model where the integrity and availability of TEEs may be compromised. To address these issues, we first introduce a distributed system of sequencers with heterogeneous TEEs, ensuring system security even if a certain proportion of TEEs are compromised. Second, we propose a challenge mechanism to solve the redeemability issue caused by TEE unavailability. Furthermore,TeeRollupincorporates Data Availability Providers (DAPs) to reduce on-chain storage overhead and uses a laziness penalty mechanism to regulate DAP behavior. We implement a prototype ofTeeRollupin Golang, using the Ethereum test network, Sepolia. Our experimental results indicate thatTeeRollupoutperforms zero-knowledge rollups (ZK-rollups), reducing on-chain verification costs by approximately 86% and withdrawal delays to a few minutes. Xiaoqing Wen, Quanbi Feng, Hanzheng Lyu, Jianyu Niu, Yinqian Zhang, Chen Feng 0001 |
IEEE Trans. Computers | 4 |
| 2025 | Chained HotStuff Under Performance AttackabstractChained HotStuff is a state-of-the-art Byzantine fault-tolerant protocol for building decentralized systems like blockchains. Although chained HotStuff has been widely adopted in many systems, its performance (e.g., throughput and latency) under attacks is still under-explored. In this paper, we develop a multi-metric evaluation framework to quantitatively analyze the performance of chained HotStuff with respect to its chain growth rate, chain quality, and latency. We propose several new attack strategies and evaluate their effects on the performance of chained HotStuff. Our analysis shows that the chain growth rate (resp, chain quality) of chained HotStuff under our attacks can drop to$4/9$(resp,$12/17$) of that without attacks when one-third of nodes are Byzantine. In addition, we use our framework to evaluate a variant of chained HotStuff, DiemBFT and find that some engineering optimizations render it more vulnerable to some attacks than the original chained HotStuff. Finally, we provide two countermeasures, i.e., broadcasting QCs and the longest chain rule, to thwart these attacks. Our analysis shows that the proposed countermeasures can significantly reduce the latency (almost half of that in chained HotStuff) and make it impossible for an attacker to lower the chain quality by simple attacks. Jianyu Niu, Fangyu Gai, Mohammad M. Jalalzai, Yinqian Zhang, Chen Feng 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Breaking the Privacy Barrier: On the Feasibility of Reorganization Attacks on Ethereum Private TransactionsabstractIn Ethereum, private transactions are designed to circumvent the public network, but they can sometimes be leaked into the public network before on-chain posting. Motivated by the huge profits of these private transactions, we propose reorganization attacks in the current Proof-of-Stake (PoS) consensus mechanism, enabling malicious validators to actively leak private transactions for profits. While prior research on reorganization attacks has focused on consensus security, our work is the first study shedding light on the economic implications of exploiting private transactions. Through theoretical analysis and extensive simulations, we confirm the effectiveness of our attacks. Additionally, we comprehensively examine real-world datasets covering 30,062,232 private transactions from September 15, 2022 to Decemeber 31, 2023 for profit analysis, uncovering that the most lucrative private transactions are often tied to Maximum Extractable Value (MEV). To further bolster the practicability and feasibility of our attacks, we scrutinize real-world cases aligning with our attack patterns. We find that attacks are risk-free due to the predictability of validators’ duties. Our findings offer valuable insights into the economics of exploiting private transactions, potential vulnerabilities, and consensus security, laying the foundation for future research. Xingyu Lyu, Jianyu Niu, Xiaokuan Zhang, Yinqian Zhang, Zhiqiang Lin 0001 |
ACSAC | 3 |
| 2024 | Formally Verifying a Rollback-Prevention Protocol for TEEs
Weili Wang 0005, Jianyu Niu, Michael K. Reiter, Yinqian Zhang |
FORTE | 2 |
| 2024 | A Secure Sidechain for Decentralized Trading in Internet of ThingsabstractSidechains allow transaction dissemination and execution outside the blockchain main network (i.e., the mainchain), enabling a scalable, efficient, and secure financial infrastructure for the Internet of Things (IoT) without trusting any central authority. Existing sidechains either have online requirements or rely on intensive computation on a central operator, which does not meet the needs of IoT for dynamic changes and high performance. This article proposes an alternative sidechain construction, called Cumulus, which meets the needs of IoT by leveraging the classic Byzantine fault-tolerant (BFT) consensus protocols, such as PBFT, that have commonly been applied in permissioned blockchains. Cumulus builds BFT-based sidechains atop public blockchains (e.g., Ethereum) using smart contracts and ensures the bidirectional safety of users’ assets. Cumulus sidechains periodically interact with the mainchain and submit checkpoints through representatives selected in an efficient and decentralized manner. The experiments show that Cumulus sidechains outperform rollup-based sidechains, and state-of-the-art sidechain constructions, achieving two and three orders of magnitude improvement in throughput and latency while retaining comparable operational cost. Fangyu Gai, Jianyu Niu, Mohammad M. Jalalzai, Seyed Ali Tabatabaee, Chen Feng 0001 |
IEEE Internet Things J. | 2 |
| 2024 | SodsBC: A Post-Quantum by Design Asynchronous Blockchain FrameworkabstractWe present a new framework for asynchronous permissioned blockchain with high performance and post-quantum security. The framework contains two quantum-secure asynchronous Byzantine fault tolerance (aBFT) protocols, SodsBC and SodsBC++. We leverage concurrent preprocessing to accelerate the preparation of three cryptographic objects for the repeated consensus procedure, including common random coins as the needed randomness, secret shares of symmetric encryption keys for censorship resilience, and nested hash values for external validation predicates. The key idea behind our design is that the concurrent preprocessing mechanism can be well-supported by the consensus process of blockchains. The consumed objects in a block have been generated and globally agreed upon in a previous block. All our preprocessed objects utilize proven or commonly believed to be post-quantum cryptographic tools to resist an adversary equipped with quantum computation capabilities. We evaluate our protocols and their competitors in AWS in a typical setting where, the number of participants is 100 and each block part has 20,000 transactions. The results show that SodsBC and SodsBC++ reduce the latency of two state-of-the-art but quantum-sensitive competitors Honeybadger and Dumbo by 53% and 6%, respectively. Shlomi Dolev, Bingyong Guo, Jianyu Niu, Ziyu Wang 0009 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Fast-HotStuff: A Fast and Robust BFT Protocol for Blockchainsabstracthe HotStuff protocol is a recent breakthrough in Byzantine Fault Tolerant (BFT) consensus that enjoys both responsiveness and linear view change by creatively adding a round to classic two-round BFT protocols like PBFT. Despite its great advantages, HotStuff has a few limitations. First, the additional round of communication during normal cases results in higher latency. Second, HotStuff is vulnerable to certain performance attacks, which can significantly deteriorate its throughput and latency. To address these limitations, we propose a new two-round BFT protocol called Fast-HotStuff, which enjoys responsiveness and efficient view change that is comparable to the linear view-change in terms of performance. Our Fast-HotStuff has lower latency and is more robust against the performance attacks that HotStuff is susceptible to. Mohammad M. Jalalzai, Jianyu Niu, Chen Feng 0001, Fangyu Gai |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Ensuring State Continuity for Confidential Computing: A Blockchain-Based ApproachabstractPublic cloud platforms have employed Trusted Execution Environment (TEE) technology to provide confidential computing services. However, applications running on cloud TEEs are susceptible to rollback or forking attacks. Their states can be rolled back to an outdated version or split into multiple conflicting versions, violating state continuity. Existing solutions against these attacks either rely on centralized trust assumption (e.g., trusted server) or have limited performance (e.g., tens of state updates per second). In this paper, we introduce Narrator-Pro (an upgrade to the original Narrator), a secure and practical distributed system that utilizes blockchain technology and TEEs to provide high-performance state continuity protection for TEE applications in the cloud. Specifically, we use the blockchain to initialize the system, which lays down the decentralized trust base with minimal interaction overhead. Meanwhile, we leverage the distributed system composed of TEEs to provide fast and unlimited state updates. We have implemented a proof-of-concept of Narrator-Pro in Intel SGX and conducted extensive evaluations in both the WAN and the LAN. Our results show that in a LAN environment with 5 nodes, Narrator-Pro can support around 8k state updates per second with a latency of 3.58ms. This performance is 30x higher than ROTE and 70× higher than using a TPM counter. Xiang Li 0166, Jianyu Niu, Xiaokuan Zhang, Yinqian Zhang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | A Privacy-Preserving Incentive Mechanism for Mobile Crowdsensing Based on BlockchainabstractMobile crowdsensing (MCS) is an efficient approach for large-scale sensing data collection by leveraging the mobility and capability of mobile devices. To avoid the weaknesses of traditional centralized crowdsensing systems, blockchain has been introduced to secure the process of MCS. This paper studies a location-aware scenario, where privacy of users are protected in a blockchain- based MCS system, and formulates an optimization problem to maximize the coverage given a budget based on reverse auction. An incentive mechanism named MMCB is further proposed and implemented as smart contracts in blockchain to solve the problem. We demonstrate that the mechanism achieves a set of desirable properties, including computation efficiency, individual rationality, truthfulness, budget feasibility, approximation, and privacy preservation. To protect the identity privacy of workers and obtain anonymity, a linkable ring signature is employed in smart contracts. In addition, a Pedersen commitment is utilized for protecting workers’ bid profile and the submitted sensing data is encrypted and only accessible to the requester. We implement a prototype system based on the Hyperledger Fabric platform, and the evaluation results show that our privacy-preserving incentive mechanism architecture improves 36.2% coverage and reduces 53.1% payment with better security level compared to the state-of-the-art schemes. Fei Tong 0001, Yuanhang Zhou, Kaiming Wang, Guang Cheng 0001, Jianyu Niu, Shibo He |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | Scaling Blockchain Consensus via a Robust Shared MempoolabstractLeader-based Byzantine fault-tolerant (BFT) consensus protocols used by permissioned blockchains have limited scalability and robustness. To alleviate the leader bottleneck in BFT consensus, we introduce Stratus, a robust shared mempool protocol that decouples transaction distribution from consensus. Our idea is to have replicas disseminate transactions in a distributed manner and have the leader only propose transaction ids. Stratus uses a provably available broadcast (PAB) protocol to ensure the availability of the referenced transactions. To deal with unbalanced load across replicas, Stratus adopts a distributed load balancing protocol.We implemented and evaluated Stratus by integrating it with state-of-the-art BFT-based blockchain protocols. Our evaluation of these protocols in both LAN and WAN settings shows that Stratus-based protocols achieve 5× to 20× higher throughput than their native counterparts in a network with hundreds of replicas. In addition, the performance of Stratus degrades gracefully in the presence of network asynchrony, Byzantine attackers, and unbalanced workloads. Fangyu Gai, Jianyu Niu, Ivan Beschastnikh, Chen Feng 0001, Sheng Wang 0011 |
ICDE | 2 |
| 2023 | Byzantine Protocols with Asymptotically Optimal Communication Complexity
Hanzheng Lyu, Shaokang Xie, Jianyu Niu, Chen Feng 0001 |
SecureComm (1) | 3 |
| 2023 | Crystal: Enhancing Blockchain Mining Transparency With Quorum CertificateabstractResearchers have discovered a series of theoretical attacks against Bitcoin's Nakamoto consensus; the most damaging ones are selfish mining, double-spending, and consistency delay attacks. These attacks have one common cause: block withholding. This paper proposes Crystal, which leverages quorum certificates to resist block withholding misbehavior. Crystal continuously elects committees from miners and requires each block to have a quorum certificate, i.e., a set of signatures issued by members of its committee. Consequently, an attacker has to publish its blocks to obtain quorum certificates, rendering block withholding impossible. To build Crystal, we design a novel two-round committee election in a Sybil-resistant, unpredictable and non-interactive way, and a reward mechanism to incentivize miners to follow the protocol. Our analysis and evaluations show that Crystal can significantly mitigate selfish mining and double-spending attacks. For example, in Bitcoin, an attacker with 30% of the total computation power will succeed in double-spending attacks with a probability of 15.6% to break the 6-confirmation rule; however, in Crystal, the success probability for the same attacker falls to 0.62%. We provide formal end-to-end safety proofs for Crystal, ensuring no unknown attacks will be introduced. To the best of our knowledge, Crystal is the first protocol that prevents selfish mining and double-spending attacks while providing safety proof. Jianyu Niu, Fangyu Gai, Runchao Han, Ren Zhang 0003, Yinqian Zhang, Chen Feng 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | ENGRAFT: Enclave-guarded Raft on Byzantine Faulty NodesabstractThis paper presents the first critical analysis of building highly secure, performant, and confidential Byzantine fault-tolerant (BFT) consensus by integrating off-the-shelf crash fault-tolerant (CFT) protocols with trusted execution environments (TEEs). TEEs, like Intel SGX, are CPU extensions that offer applications a secure execution environment with strong integrity and confidentiality guarantees, by leveraging techniques like hardware-assisted isolation, memory encryption, and remote attestation. It has been speculated that when implementing a CFT protocol inside Intel SGX, one would achieve security properties similar to BFT. However, we show in this work that simply combining CFT with SGX does not directly yield a secure BFT protocol, given the wide range of attack vectors on SGX. We systematically study the fallacies in such a strawman design by performing model checking, and propose solutions to enforce safety and liveness. We also present ENGRAFT, a secure enclave-guarded Raft implementation that, firstly, achieves consensus on a cluster of 2f+1 machines tolerating up to f nodes exhibiting Byzantine-fault behavior (but well-behaved enclaves); secondly, offers a new abstraction of confidential consensus for privacy-preserving state machine replication; and finally, allows the reuse of a production-quality Raft implementation, BRaft, in the development of a highly performant BFT system. Weili Wang 0005, Jianyu Niu, Michael K. Reiter, Yinqian Zhang |
CCS | 3 |
| 2022 | NARRATOR: Secure and Practical State Continuity for Trusted Execution in the CloudabstractPublic cloud platforms have leveraged Trusted Execution Environment (TEE) technology to provide confidential computing services. However, TEE-protected applications still suffer from rollback or forking attacks, in which their states could be rolled back to a stale version or be forked into multiple versions, resulting in state continuity violations. Existing solutions against these attacks either rely on weak threat models based on centralized trust (e.g., trusted server) or suffer from large performance overheads (e.g., tens of state updates per second). In this paper, we propose Narrator, a secure and practical system, (1) that relies on a blockchain (i.e., decentralized trust) and TEEs, and (2) that provides high-performance state continuity protection like unlimited and fast state updates for applications in cloud TEEs. The intuition behind our design is simple. Our design uses the blockchain to initialize a distributed system of TEEs, laying down the decentralized trust base with a small interaction overhead, while the distributed system provides performant state continuity protection. Our distributed system adopts a customized version of the consistent broadcast protocol and leverages advanced techniques to make state updates processed with one round trip delay on average. We build a proof-of-concept of Narrator on Intel SGX (i.e., a representative design of TEEs) and do extensive experiments to evaluate its performance. Our evaluation results show that in a LAN environment with 5 nodes, Narrator can support about 6k state updates per second, meanwhile keeping the latency as low as 3-8 ms. The throughput is 30x larger than that in ROTE and 70x larger than using a TPM counter. Jianyu Niu, Xiaokuan Zhang, Yinqian Zhang |
CCS | 1 |
| 2022 | When Power-of-d-Choices Meets PriorityabstractPower-of-d-choices (Pod) is a popular load balancing strategy, which has received much attention from both academia and industry. However, much prior work on Pod has focused on uniform tasks without priorities. In reality, tasks may have different priorities according to their service sensitivity, pricing, or importance to guarantee the quality of service (QoS). In this work, we distinguish two types of priorities in Pod: scheduling and service priorities. We propose Pod-SSP, which is a Pod algorithm with Scheduling and Service Priorities. To better understand the impact of priorities on the performance of tasks, we consider two simple variants of Pod-SSP: Pod with SCheduling Priorities (Pod-SCP) and Pod with SErvice Priorities (Pod-SEP). Utilizing mean-field approximation, we systematically study the performance of these protocols in the large-system regime. Our theoretical and simulation results show that high-priority tasks can have a more than 3x better delay relative to a system running the original Pod algorithm, and meanwhile, low-priority tasks only slightly sacrifice their delay. Jianyu Niu, Chunpu Wang, Chen Feng 0001, Hong Xu 0001 |
IWQoS | 1 |
| 2022 | A Time-Efficient Protocol for Unknown Tag Identification in Large-Scale RFID SystemsabstractIn radio-frequency identification (RFID) applications, RFID tags attached to new, misplaced, or counterfeited commodities sometimes may not be timely registered and are unknown for readers. In applications like inventory management and product tracking, these unknown tags pose several challenges for fast tag identification. A simple method to identify unknown tags is to first deactivate the registered known tags, and then collect IDs of the unknown ones. However, this is a nontrivial task. In fact, unknown tags cause interference with the deactivation of known tags. Moreover, the unknown tag collection methods used in existing protocols either suffer severe tag collisions or generate many empty slots, which increases the final execution time. In this article, we propose an efficient unknown tag identification (EUTI) protocol. First, EUTI builds a vector-based filter to exclude the tags that are not expected to reply in each slot, so that EUTI can use both predicted collision slots and singleton slots for unknown tag deactivation and avoid collisions caused by unknown tags. Second, EUTI adopts a reservation mechanism to reduce collision slots and guide each unknown tag to skip empty slots when replying, thus saving execution time. Moreover, we provide a theoretical analysis of EUTI to minimize execution time and extend EUTI to multi-reader scenarios. Numerical results show that EUTI outperforms the state-of-the-art solutions by reducing up to 44.12% in deactivation time, 26.47% in collection time, and 27.75% in total time. Chu Chu, Jianyu Niu, Wenxian Zheng, Jian Su 0001, Guangjun Wen |
IEEE Internet Things J. | 2 |
| 2022 | The Hermes BFT for Blockchains
Mohammad M. Jalalzai, Chen Feng 0001, Costas Busch, Golden G. Richard III, Jianyu Niu |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | Dissecting the Performance of Chained-BFTabstractPermissioned blockchains employ Byzantine fault-tolerant (BFT) state machine replication (SMR) to reach agreement on an ever-growing, linearly ordered log of transactions. A new paradigm, combined with decades of research in BFT SMR and blockchain (namely chained-BFT, or cBFT), has emerged for directly constructing blockchain protocols. Chained-BFT protocols have a unifying propose-vote scheme instead of multiple different voting phases with a set of voting and commit rules to guarantee safety and liveness. However, distinct voting and commit rules impose varying impacts on performance under different workloads, network conditions, and Byzantine attacks. Therefore, a fair comparison of the proposed protocols poses a challenge that has not yet been addressed by existing work. We fill this gap by studying a family of cBFT protocols with a two-pronged systematic approach. First, we present an evaluation and benchmarking framework, called Bamboo, for quick prototyping of cBFT protocols. To validate Bamboo, we introduce an analytic model using queuing theory which also offers a back-of-the-envelope guide for dissecting these protocols. We build multiple cBFT protocols using Bamboo and we are the first to fairly compare three cBFT representatives (i.e., HotStuff, two-chain HotStuff, and Streamlet). We evaluated these protocols under various parameters and scenarios, including two Byzantine attacks that have not been widely discussed in the literature. Our findings reveal interesting trade-offs (e.g., responsiveness vs. forking-resilience) between different cBFT protocols and their design choices, which provide developers and researchers with insights into the design and implementation of this protocol family. Fangyu Gai, Ali Farahbakhsh, Jianyu Niu, Chen Feng 0001, Ivan Beschastnikh |
ICDCS | 3 |
| 2021 | On the Performance of Pipelined HotStuffabstractHotStuff is a state-of-the-art Byzantine fault-tolerant consensus protocol. It can be pipelined to build large-scale blockchains. One of its variants called LibraBFT is adopted in Facebook's Libra blockchain. Although it is well known that pipelined HotStuff is secure against up to 1/3 of Byzantine nodes, its performance in terms of throughput and delay is still under-explored. In this paper, we develop a multi-metric evaluation framework to quantitatively analyze pipelined HotStuff's performance with respect to its chain growth rate, chain quality, and latency. We then propose several attack strategies and evaluate their effects on the performance of pipelined HotStuff. Our analysis shows that the chain growth rate (resp, chain quality) of pipelined HotStuff under our attacks can drop to as low as 4/9 (resp, 12/17) of that without attacks when 1/3 nodes are Byzantine. As another application, we use our framework to evaluate certain engineering optimizations adopted by LibraBFT. We find that these optimizations make the system more vulnerable to our attacks than the original pipelined HotStuff. Finally, we provide two countermeasures to thwart these attacks. We hope that our studies can shed light on the rigorous understanding of the state-of-the-art pipelined HotStuff protocol as well as its variants. Jianyu Niu, Fangyu Gai, Mohammad M. Jalalzai, Chen Feng 0001 |
INFOCOM | 1 |
| 2021 | Cumulus: A Secure BFT-based Sidechain for Off-chain ScalingabstractSidechains enable off-chain scaling by sending transactions in a private network rather than broadcasting them in the public blockchain (i.e., the mainchain) network. To this end, classic Byzantine fault-tolerant (BFT) consensus protocols such as PBFT seem an excellent fit to fuel sidechains for their permissioned settings and inherent robustness. However, designing a secure and efficient BFT-based sidechain protocol remains an open challenge.This paper presents Cumulus, a novel BFT-based sidechain framework for blockchains to achieve off-chain scaling without compromising any security and efficiency properties of both sides’ consensus protocols. Cumulus encompasses a novel cryptographic sortition algorithm called Proof-of-Wait to fairly select sidechain nodes to communicate with the mainchain in an efficient and decentralized manner. To further reduce the operational cost, Cumulus provides an optimistic checkpointing approach in which the mainchain will not verify checkpoints unless disputes happen. Meanwhile, end-users enjoy a two-step withdrawal protocol, ensuring that they can safely collect assets back to the mainchain without relying on the BFT committee. Our experiments show that Cumulus sidechains outperform ZK-Rollup, another promising sidechain construction, achieving one and two orders of magnitude improvement in throughput and latency while retaining comparable operational cost. Fangyu Gai, Jianyu Niu, Seyed Ali Tabatabaee, Chen Feng 0001, Mohammad M. Jalalzai |
IWQoS | 2 |
| 2021 | Publish or Perish: Defending Withholding Attack in Dfinity ConsensusabstractSynchronous Byzantine consensus has regained its popularity with the rise of permissioned blockchains due to its significantly better fault tolerance (up to minority faults) than its partially synchronous counterpart (less than one third). Dfinity Consensus is a state-of-the-art synchronous Byzantine consensus protocol. However, Dfinity is vulnerable to the withholding attack. For example, adversaries can strategically withhold blocks, resulting in an increase in latency and unbounded message complexity. Motivated by this observation, we present Dfinity++, which can effectively defend such an attack. The key idea behind Dfinity++ is simple. Since honest replicas would timely publish their blocks, one can detect delayed blocks and then trigger a fast switch to the next iteration, leading to better resource usage. Our results show that against a static/mildly adversary, Dfinity++ is able to reduce the latency (of committing a new block) by 10.7%, and at the same time enjoys a message complexity of $O\left(n^{2}\right)$. Hanzheng Lyu, Jianyu Niu, Fangyu Gai, Chen Feng 0001 |
MSN | 2 |
| 2020 | Incentive analysis of Bitcoin-NG, revisited
Jianyu Niu, Ziyu Wang 0009, Fangyu Gai, Chen Feng 0001 |
Perform. Evaluation | 1 |
| 2019 | Selfish Mining in EthereumabstractAs the second largest cryptocurrency by market capitalization and today's biggest decentralized platform that runs smart contracts, Ethereum has received much attention from both academia and industry. Nevertheless, there exist very few studies about the security of its mining strategies, especially from the selfish mining perspective. In this paper, we fill this research gap by analyzing selfish mining in Ethereum and understanding its potential threat. First, we introduce a 2-dimensional Markov process to model the behavior of a selfish mining strategy inspired by a Bitcoin mining strategy proposed by Eyal and Sirer. Second, we derive the stationary distribution of our Markov model and compute long-term average mining rewards. This allows us to determine the threshold of computational power which makes selfish mining profitable in Ethereum. We find that this threshold is lower than that in Bitcoin mining (which is 25% as discovered by Eyal and Sirer), suggesting that Ethereum is more vulnerable to selfish mining than Bitcoin. Chen Feng 0001, Jianyu Niu |
ICDCS | 2 |