VLDB 2026 Research / reviewers in the wild / expert
Jiangshan Yu
dblp:18/11043
· DBLP profile ↗
71ranked-venue papers
6as first author
51since 2021 · last 2026
0000-0001-8006-7392ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 48 · 4 first-author · 32 since 2021Systems, architecture and hardware · 11 · 1 first-author · 9 since 2021Software engineering, systems software and programming languages · 10 · 10 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SoK: Stablecoins in Retail PaymentsabstractStablecoins have emerged as a rapidly growing digital payment instrument, raising the question of whether blockchain-based settlement can function as a substitute for incumbent card networks in retail payments. This Systematization of Knowledge (SoK) provides a systematic comparison between stablecoin payment arrangements and card networks by situating both within a unified analytical framework. We first map their respective payment infrastructures, participant roles, and transaction lifecycles, highlighting fundamental differences in how authorization, settlement, and recourse are organized. Building on this mapping, we introduce the CLEAR framework, which evaluates retail payment systems across five dimensions: cost, legality, experience, architecture, and reach. Our analysis shows that stablecoins deliver efficient, continuous, and programmable settlement, often compressing rail-level merchant fees and enabling 24/7 value transfer. However, these advantages are accompanied by an inversion of the traditional pricing and risk-allocation structure. Card networks internalize consumer-side frictions through subsidies, standardized liability rules, and post-transaction recourse, thereby supporting mass-market adoption. Stablecoin arrangements, by contrast, externalize transaction fees, error prevention, and dispute resolution to users, intermediaries, and courts, resulting in weaker consumer protection, higher cognitive burden at the point of interaction, and fragmented acceptance. Accordingly, stablecoins exhibit a conditional comparative advantage in closed-loop environments, cross-border corridors, and high-friction payment contexts, but remain structurally disadvantaged as open-loop retail payment instruments. Yuexin Xiang, Qin Wang 0008, Tsz Hon Yuen, Andreas Deppeler, Jiangshan Yu |
ICBC | 6 |
| 2026 | Measuring Memecoin FragilityabstractMemecoins, emerging from internet culture and community-driven narratives, have rapidly evolved into a unique class of crypto assets. Unlike technology-driven cryptocurrencies, their market dynamics are primarily shaped by viral social media diffusion, celebrity influence, and speculative capital inflows. To capture the distinctive vulnerabilities of these ecosystems, we present the first Memecoin Ecosystem Fragility Framework (ME2F). ME2F formalizes memecoin risks in three dimensions: i) Volatility Dynamics Score capturing persistent and extreme price swings together with spillover from base chains; ii) Whale Dominance Score quantifying ownership concentration among top holders; and iii) Sentiment Amplification Score measuring the impact of attention-driven shocks on market stability. We apply ME2F to representative tokens (over 65% market share) and show that fragility is not evenly distributed across the ecosystem. Politically themed tokens such as TRUMP, MELANIA, and LIBRA concentrate the highest risks, combining volatility, ownership concentration, and sensitivity to sentiment shocks. Established memecoins such as DOGE, SHIB, and PEPE fall into an intermediate range. Benchmark tokens ETH and SOL remain consistently resilient due to deeper liquidity and institutional participation. Our findings provide the first ecosystem-level evidence of memecoin fragility and highlight governance implications for enhancing market resilience in the Web3 era. Yuexin Xiang, Qishuang Fu, Qin Wang 0008, Tsz Hon Yuen, Jiangshan Yu |
ICBC | 6 |
| 2026 | GumSwap: Griefing-Free Universal Multi-Party Atomic Swaps
Dongkun Hou, Yuanzhe Zhang, Shujie Cui, Tsz Hon Yuen, Joseph K. Liu, Jiangshan Yu |
ICDCS | 6 |
| 2026 | Pallas and Aegis: Rollback Resilience in TEE-Aided Blockchain Consensus
Jeremie Decouchant, David Kozhaya, Vincent Rahli, Jiangshan Yu |
NDSS | 4 |
| 2026 | Enhancing Security and Resilience in DER Integration: A Self-Sovereign Identity Approach for Smart Inverters in Virtual Power PlantsabstractUtility companies are expected to leverage privately owned distributed energy resources (DERs) to create virtual power plants (VPPs), which offer promising solutions for maintaining the demand–supply balance efficiently and reducing emissions. Smart inverters play a crucial role in integrating DERs into VPPs, making the security of smart inverters and the reliability of inverter data essential for the successful implementation of secure and effective VPPs. However, traditional public-key infrastructure and X.509 digital certificate-based security approaches (PKIX) are sub-optimal in this integration context due to their inherent limitations. Therefore, in this work, we analyse the self-sovereign identity concept in DER integration context and develop a secure and reliable framework for DER integration via smart inverters. The proposed framework aims to overcome the issues associated with the current PKIX-based design and enhance the overall resiliency of the DER integration process by extending the existing industry standards. Thusitha Dayaratne, Carsten Rudolph, Jiangshan Yu |
Distributed Ledger Technol. Res. Pract. | 3 |
| 2026 | $\mathsf {DisIMS}$DisIMS: A Distributed Identity Management System via BlockchainabstractThe increasing incidents of data breaches and personal data misuse highlight the urgent need for robust identity management systems. Self-Sovereign Identity (SSI) emerges as the future solution for digital identity management, underpinned by anonymous credentials (AC) and the distributed ledger technology (DLT) for security measures. However, current SSI models only achieve partial decentralization and none of them can fully meet the complex security requirements of real-world applications. In this paper, we address these limitations by constructing a Decentralized Anonymous Credential (DAC) scheme inspired by large universe attribute-based cryptographic primitives. Building on this foundation, we design a distributed identity management system (DisIMS), a comprehensive SSI system built on blockchain, achieving attribute flexibility, anonymity, unlinkability, revocability and selective disclosure. Compared to earlier blockchain-based identity management systems, our DisIMS allows users to selectively link previous transactions to generate verifiable eligibility proofs for the current transaction without leaking their real identities. We also implement DisIMS on both permissioned (Hyperledger Fabric v2.5) and permissionless (Ethereum Sepolia testnet) blockchains. Experimental results show that batch verification outperforms single verification by reducing execution times by approximately 76% to 81% on Hyperledger Fabric and 50% to 71% on Ethereum, based on 200 tests with 10 to 50 credentials containing 50 attributes each, which demonstrates DisIMS practicality for real-world batch verification scenarios. Zoey Ziyi Li, Hui Cui 0001, Alven C. Y. Leung, Dennis Y. W. Liu, Joseph K. Liu, Jiangshan Yu, Dragan Gasevic |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | Posterior Security: Anonymity and Message Hiding of Standard SignaturesabstractWe introduce posterior security of digital signatures, the additional security features after the original signature is generated. It is motivated by the scenario that some people store their secret keys in secure hardware and can only obtain a standard signature through a standardized interface. In this paper, we consider two different posterior security features: anonymity and message hiding. Tsz Hon Yuen, Ying-Teng Chen, Shimin Pan, Jiangshan Yu, Joseph K. Liu |
CCS | 4 |
| 2025 | Achilles: Efficient TEE-Assisted BFT Consensus via Rollback Resilient RecoveryabstractBFT consensus that uses Trusted Execution Environments (TEEs) to improve the system tolerance and performance is gaining popularity. However, existing works suffer from TEE rollback issues, resulting in a tolerance-performance tradeoff. In this paper, we propose Achilles, an efficient TEE-assisted BFT protocol that breaks the tradeoff. The key idea behind Achilles is removing the expensive rollback prevention of TEEs from the critical path of committing transactions. To this end, Achilles adopts a rollback resilient recovery mechanism, which allows nodes to assist each other in recovering their states. Besides, Achilles follows the chaining spirit in modern chained BFT protocols and leverages customized chained commit rules to achieve linear message complexity, end-to-end transaction latency of four communication steps, and fault tolerance for the minority of Byzantine nodes. Achilles is the first TEE-assisted BFT protocol in line with CFT protocols in these metrics. We implement a prototype of Achilles based on Intel SGX and evaluate it in both LAN and WAN, showcasing its outperforming performance compared to several state-of-the-art counterparts. Jianyu Niu, Xiaoqing Wen, Guanlong Wu, Shengqi Liu, Jiangshan Yu, Yinqian Zhang |
EuroSys | 5 |
| 2025 | Mosaic: Client-driven Account Allocation Framework in Sharded BlockchainsabstractRecent account allocation studies in sharded blockchains are typically miner-driven, requiring miners to perform global optimizations for all accounts to enhance system-wide performance. This forces each miner to maintain a complete copy of the entire ledger, resulting in significant storage, communication, and computation overhead.In this work, we explore an alternative research direction by proposing Mosaic, the first client-driven framework for distributed, lightweight local optimization. Rather than relying on miners to allocate all accounts, Mosaicenables clients to independently execute a local algorithm to determine their residing shards. Clients can submit migration requests to a beacon chain when relocation is necessary. Mosaicnaturally addresses key limitations of miner-driven approaches, including the lack of miner incentives and the significant overhead. While clients are flexible to adopt any algorithm for shard allocation, we design and implement a reference algorithm, Pilot, to guide them. Clients execute Pilotto maximize their own benefits, such as reduced transaction fees and confirmation latency.On a real-world Ethereum dataset, we implement and evaluate Pilotagainst state-of-the-art miner-driven global optimization solutions. The results demonstrate that Mosaicsignificantly enhances computational efficiency, achieving a four-order-of-magnitude reduction in computation time, with the reduced input data size from 1.44 GB to an average of 228.66 bytes per account. Despite these efficiency gains, Pilotintroduces only about a 5% increase in the cross-shard ratio and maintains approximately 98% of the system throughput, demonstrating a minimal trade-off in overall effectiveness. Yuanzhe Zhang, Shirui Pan, Jiangshan Yu |
ICDCS | 3 |
| 2025 | GenDetect: Generative Large Language Model Usage in Smart Contract Vulnerability Detection
Peter Ince, Jiangshan Yu, Joseph K. Liu, Xiaoning Du 0001, Xiapu Luo |
ProvSec | 2 |
| 2025 | SEARCHAIN: Searchable Encryption As Rewarded-Useful-Work on Blockchain
Jiangshan Yu, Xingliang Yuan, Joseph K. Liu, Cong Zuo 0001, Hui Cui 0001 |
ProvSec | 2 |
| 2025 | Constant Latency and Finality for Dynamically Available DAGabstractDirected Acyclic Graph (DAG) based protocols have shown great promise to improve the performance of blockchains. The CAP theorem shows that it is impossible to have a single system that achieves both liveness (known as dynamic availability) and safety under network partition. This paper explores two types of DAG-based protocols prioritizing liveness or safety, named structured dissemination and Graded Common Prefix (GCP), respectively. For the former, we introduce the first DAG-based protocol with constant expected latency, providing high throughput dynamic availability under the sleepy model. Its expected latency is 3Δ and its throughput linearly scales with participation. We validate these expected performance improvements over existing constant latency sleepy model BFT by running prototypes of each protocol across multiple machines. The latter, GCP, is a primitive that provides safety under network partition, while being weaker than standard consensus. As a result, we are able to obtain a construction that runs in only 2 communication steps, as opposed to the 4 steps of existing low latency partially synchronous BFT. In addition, GCP can easily avoid relying on single leaders' proposals, becoming more resilient to crashes. We also validate these theoretical benefits of GCP experimentally. We leverage our findings to extend the Ebb-and-Flow framework, where two BFT sub-protocols allow different types of clients in the same system to prioritize either liveness or safety. Our extension integrates our two types of DAG-based protocols. This provides a hybrid DAG-based protocol with high throughput, dynamical availability, and finality under network partitions, without running a standard consensus protocol twice as required in existing work. Hans Schmiedel, Runchao Han, Qiang Tang 0005, Ron Steinfeld, Jiangshan Yu |
SP | 5 |
| 2025 | Formal Treatment of Watchtowers and FPPW: A Fair and Privacy-Preserving Bitcoin WatchtowerabstractThis article formalises watchtower and its different properties includingagility,privacyagainst both watchtower and third parties,fairnesswith respect to both watchtower and its client andcoverage. We also evaluate the existing schemes regarding these properties and show they cannot achieve all properties altogether. Furthermore, we prove that there is a trade-off between the level of fairness that a watchtower provides to its clients and the coverage it can achieve. We also introduce FPPW, the first Fair and Privacy-Preserving Watchtower for Bitcoin. This new scheme provides fairness with respect to all channel participants including both channel parties and the watchtower. It means the funds of any honest channel participants are safe even assuming that the other two participants are corrupted and/or collude with each other. Furthermore, the watchtower in FPPW learns no information about the off-chain transactions and hence FPPW provides privacy against the watchtower. We also show that FPPW coverage, i.e., the total capacity of channels that an FPPW watchtower can cover, is higher than that of PISA and Cerberus and FPPW can be implemented without any update in the Bitcoin script. Arash Mirzaei, Amin Sakzad, Jiangshan Yu, Ron Steinfeld |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | New Bounds on the Accuracy of Majority Voting for Multiclass ClassificationabstractMajority voting is a simple mathematical function that returns the most frequently occurring value within a given set. As a popular decision fusion technique (DFT), the majority voting function (MVF) finds applications in resolving conflicts, where several independent voters report their opinions on a classification problem. Despite its importance and its various applications in ensemble learning, data crowdsourcing, remote sensing, and data oracles for blockchains, the accuracy of the MVF for the general multiclass classification problem has remained unknown. In this article, we derive a new upper bound on the accuracy of the MVF for the multiclass classification problem. More specifically, we show that under certain conditions, the error rate of the MVF exponentially decays toward 0 as the number of independent voters increases. Conversely, the error rate of the MVF exponentially grows with the number of voters if these conditions are not met. We first explore the problem for voters with independent and identically distributed (i.i.d.) outputs, where we assume that, given the true classification of the data point, every voter follows the same conditional probability distribution of voting for different classes. Next, we extend our results to encompass independent but nonidentically distributed votes. Using the derived results, we then provide a discussion on the accuracy of the truth discovery algorithms. We show that in the best-case scenarios, truth discovery algorithms operate as an amplified MVF and thereby achieve a small error rate only when the MVF achieves a small error rate too, and vice versa, achieve a large error rate when the MVF also achieves a large error rate. However, in the worst case scenario, the truth discovery algorithms may exhibit a significantly higher error rate than the MVF. Finally, we confirm our theoretical results using numerical simulations. Sina Aeeneh, Nikola Zlatanov, Jiangshan Yu |
IEEE Trans. Neural Networks Learn. Syst. | 3 |
| 2025 | MM-SCS: Leveraging Multimodal Features to Enhance Smart Contract Code SearchabstractSemantic code search technology allows searching for existing code snippets through natural language, which can greatly improve programming efficiency. Smart contracts, programs that run on the blockchain, have a code reuse rate of more than 79%, which means developers have a great demand for semantic code search tools. However, the existing code search models still have a semantic gap between code and query and perform poorly on specialized queries of smart contracts. In this paper, we propose a Multi-Modal Smart contract Code Search (MM-SCS) model. Specifically, we construct a Contract Elements Dependency Graph (CEDG) for MM-SCS as an additional modality to capture the data flow and control flow information of the code. To make the model more focused on the key contextual information, we use a multi-head attention network to generate embeddings for code features. In addition, we use a fine-tuned pretrained model to ensure the model's effectiveness when the training data is small. We compared MM-SCS with four state-of-the-art models on a dataset with 470K (code, docstring) pairs collected from Github and Etherscan. Experimental results show that MM-SCS achieves an MRR (Mean Reciprocal Rank) of 0.572, outperforming four state-of-the-art models UNIF, DeepCS, CARLCS-CNN, and TAB-CS by 34.2%, 59.3%, 36.8%, and 14.1%, respectively. Additionally, the search speed of MM-SCS is second only to UNIF, reaching 0.34s/query. Chaochen Shi, Yong Xiang 0001, Jiangshan Yu, Longxiang Gao |
IEEE Trans. Software Eng. | 3 |
| 2024 | Detect Llama - Finding Vulnerabilities in Smart Contracts Using Large Language Models
Peter Ince, Xiapu Luo, Jiangshan Yu, Joseph K. Liu, Xiaoning Du 0001 |
ACISP (3) | 3 |
| 2024 | AegisDB: Scalable Blockchain Database with Secure Decentralised Load Balancing
Jiangshan Yu, Xingliang Yuan, Joseph K. Liu |
ACISP (3) | 2 |
| 2024 | Janus: Enhancing Asynchronous Common Subset with Trusted HardwareabstractAsynchronous common subset (ACS) has been extensively studied since the asynchronous Byzantine fault tolerance (BFT) framework was introduced by Ben-Or, Kemler, and Rabin (BKR). The line of work (i.e., HoneyBadgerBFT, BEAT, EPIC) uses parallel reliable broadcast (RBC) and asynchronous binary agreement (ABA) instances to reach an agreement on a subset of proposed transactions.In this paper, we further progress the BKR paradigm by presenting Janus, the first hybrid ACS protocol leveraging trusted hardware components. Janus is the first ACS protocol that tolerates a minority of Byzantine processes and that has $\mathcal{O}\left( {{n^2}} \right)$ message complexity. Supported by trusted hardware components, we introduce a provable broadcast primitive to replace RBC, and develop a resilient binary agreement protocol. Messages for concurrent instances of agreement are aggregated into vectors. Our experimental results demonstrate significant performance improvements over predominant ACS constructions with a 92%+ increase compared to HoneyBadgerBFT and a 47%+ increase compared to BEAT. Additionally, we provide a comparison with open-source hybrid BFT protocols that operate under a partially synchronous network, highlighting the performance enhancement compared to previous hybrid protocols that also tolerate the Byzantine minority (e.g., MinBFT and Damysus, by 49%+). Liangrong Zhao, Hans Schmiedel, Qin Wang 0008, Jiangshan Yu |
ACSAC | 4 |
| 2024 | Modeling Mobile Crash in Byzantine ConsensusabstractTargeted Denial-of-Service (DoS) attacks have been a practical concern for permissionless blockchains. Potential solutions, such as random sampling, are adopted by blockchains. However, the associated security guarantees have only been informally discussed in prior work. This is due to the fact that existing adversary models are either not fully capturing this attack or giving up certain design choices (as in the sleepy model or asynchronous network model), or too strong to be practical (as in the mobile Byzantine adversary model). This paper provides theoretical foundations and desired properties for consensus protocols that resist against targeted DoS attacks. In particular, we define the Mobile Crash Adaptive Byzantine (MCAB) model to capture such an attack. In addition, we identify and formalize two properties for consensus protocols under the MCAB model, and analyze their trade-offs. As case studies, we prove that Ouroboros Praos and Algorand are secure in our MCAB model, giving the first formal proofs supporting their security guarantee against targeted DoS attacks, which were previously only informally discussed. We also illustrate an application of our properties to secure a streamlined BFT protocol, chained Hotstuff, against targeted DoS attacks. Hans Schmiedel, Runchao Han, Qiang Tang 0005, Ron Steinfeld, Jiangshan Yu |
CSF | 5 |
| 2024 | Test of Time Award; DSN 2024abstractThe Test-of-Time Award recognizes two outstanding papers published 10 years ago at DSN, in the DSN proceedings (research track, practical experience report or tool papers), that have had a sustained and important impact on the theory and/or practice of dependable systems and networks computing research. DSN has several areas under its umbrella and with two awards there are conditions to recognize more than one area. In exceptional situations (not enough nominations), the time frame for awards can be extended to 10-12 years, and only one paper can be awarded, in this order. Juan-Carlos Ruiz-Garcia 0001, Homa Alemzadeh, Jean-Charles Fabre, Jiangshan Yu, Sy-Yen Kuo, Elias P. Duarte Jr. |
DSN | 4 |
| 2024 | The Dark Side of NFTs: A Large-Scale Empirical Study of Wash TradingabstractNFTs (Non-Fungible Tokens) have seen significant growth since they first captured public attention in 2021. However, the NFT market is plagued by fake transactions and economic bubbles, e.g., NFT wash trading. Wash trading typically refers to a transaction involving the same person or two colluding individuals, and has become a major threat to the NFT ecosystem. Previous studies only detect NFT wash trading from the financial aspect, while the real-world wash trading cases are much more complicated (e.g., not aiming at inflating the market value). There is still a lack of multi-dimension analysis to better understand NFT wash trading. Therefore, we present the most comprehensive study of NFT wash trading, analyzing 8,717,031 transfer events and 3,830,141 sale events from 2,701,883 NFTs. We identify three types of NFT wash trading and propose identification algorithms. Our experimental results reveal 824 transfer events and 5,330 sale events (accounting for a total of $8,857,070.41) and 370 address pairs related to NFT wash trading behaviors, causing a minimum loss of $3,965,247.13. Furthermore, we provide insights from six aspects, i.e., marketplace design, profitability, NFT project design, payment token, user behavior, and NFT ecosystem. Shijian Chen, Jiachi Chen, Jiangshan Yu, Xiapu Luo, Yanlin Wang 0001 |
Internetware | 3 |
| 2024 | OneShot: View-Adapting Streamlined BFT Protocols with Trusted Execution EnvironmentsabstractByzantine fault-tolerance is arguably an expensive characteristic for protocols to support, especially when considering its overhead on message complexity, number of communication phases, and number of nodes for resilience. Various works in the literature have addressed optimizing one or more of these dimensions through the use of algorithmic optimizations, trusted execution environments, and streamlined view changes.The best achievable message complexity, resilience, and latency to date are respectively linear complexity, by ⌊(N − 1)/2⌋, and two communication phases attained Damysus (EuroSys’22), a streamlined hybrid protocol. This paper strictly advances the aforementioned state of the art results by introducing OneShot, a streamlined hybrid protocol that uses one communication phase in the normal case, and one or two phases otherwise. OneShot exploits the information nodes receive about the system to dynamically modify and adapt views. We prove that OneShot is safe and live, and moreover demonstrate through experimental evaluation that it improves throughput and latency by respectively up to 150% and 59% compared to the state of the art. Jeremie Decouchant, David Kozhaya, Vincent Rahli, Jiangshan Yu |
IPDPS | 4 |
| 2024 | Juno: Aggregated Vector Consensus for Optimal Asynchronous Common SubsetabstractIn this paper, we propose aggregated vector consensus, a new vector consensus primitive designed for asynchronous networks. The primitive achieves agreement by outputting a vector of values aggregated from independent process inputs. We then introduce Juno, an asynchronous common subset (ACS) protocol that fully implements our aggregated vector consensus to attain optimal ${\mathcal{O}}\left({{n^2}}\right)$ message complexity.We further implement and evaluate Juno in comparison with the legacy HoneyBadgerBFT and the state-of-the-art Dory. Experiment results demonstrate its efficacy and efficiency. Our protocol demonstrates an average throughput performance improvement of 93% compared with HoneyBadgerBFT and a 47% improvement compared with Dory. Notably, our study makes significant progress in addressing the gap in applying vector consensus protocol in fully asynchronous networks. Liangrong Zhao, Qin Wang 0008, Joseph K. Liu, Jiangshan Yu |
PRDC | 4 |
| 2024 | Trusted Hardware-Assisted Leaderless Byzantine Fault Tolerance ConsensusabstractByzantine Fault Tolerance (BFT) Consensus protocols with trusted hardware assistance have been extensively explored for their improved resilience to tolerate more faulty processes. Nonetheless, the potential of trust hardware has been scarcely investigated in leaderless BFT protocols. RedBelly is assumed to be the first blockchain network whose consensus is based on a truly leaderless BFT algorithm. This paper proposes a trusted hardware-assisted leaderless BFT consensus protocol by offering a hybrid solution for the set BFT problem defined in the RedBelly blockchain. Drawing on previous studies, we present two crucial trusted services: the counter and the collector. Based on these two services, we introduce two primitives to formulate our leaderless BFT protocol: a hybrid verified broadcast (VRB) protocol and a hybrid binary agreement. The hybrid VRB protocol enhances the hybrid reliable broadcast protocol by integrating a verification function. This addition ensures that a broadcast message is verified not only for authentication but also for the correctness of its content. Our hybrid BFT consensus is integrated with these broadcast protocols to deliver binary decisions on all proposals. We prove the correctness of the proposed hybrid protocol and demonstrate its enhanced performance in comparison to the prior trusted BFT protocol. Liangrong Zhao, Jeremie Decouchant, Joseph K. Liu, Qinghua Lu 0001, Jiangshan Yu |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | Analyzing the Performance of the Inter-Blockchain Communication ProtocolabstractWith the increasing demand for communication between blockchains, improving the performance of cross-chain communication protocols becomes an emerging challenge. We take a first step towards analyzing the limitations of cross-chain communication protocols by comprehensively evaluating Cosmos Network's Inter-Blockchain Communication Protocol. To achieve our goal we introduce a novel framework to guide empirical evaluations of cross-chain communication protocols. We implement an instance of our framework as a tool to evaluate the IBC protocol. Our findings highlight several challenges, such as high transaction confirmation latency, bottlenecks in the blockchain's RPC implementation and concurrency issues that hinder the scalability of the cross-chain message relayer. We also demonstrate how to reduce the time required to complete cross-chain transfers by up to 70% when submitting large amounts of transfers. Finally, we discuss challenges faced during deployment with the objective of contributing to the development and advancement of cross-chain communication. João Otávio Massari Chervinski, Diego Kreutz, Xiwei Xu 0001, Jiangshan Yu |
DSN | 4 |
| 2023 | Leveraging the Verifier's Dilemma to Double Spend in Bitcoin
Tong Cao, Jeremie Decouchant, Jiangshan Yu |
FC | 3 |
| 2023 | Fair Delivery of Decentralised Randomness Beacon
Runchao Han, Jiangshan Yu |
FC (1) | 2 |
| 2023 | Rational Ponzi Game in Algorithmic StablecoinabstractAlgorithmic stablecoins (AS) are one special type of stablecoins that are not backed by any asset. They stand to revolutionize the way a sovereign flat operates. As implemented, AS are poorly stabilized in most cases; their prices easily deviating from the target or even falling into a catastrophic collapse, and are as a result often dismissed as a Ponzi scheme. However, what is the essence of Ponzi? In this paper, we try to clarify such a deceptive concept and reveal how AS work from a higher level. We find that Ponzi is basically a financial protocol that pays existing investors with funds collected from new ones. Running a Ponzi, however, does not necessarily imply that any participant is in any sense losing out, as long as the game can be perpetually rolled over. Economists call such realization as a rational Ponzi game. We thereby propose a rational model in the context of AS and draw its holding conditions. We apply the model to examine: whether or not the algorithmic stablecoin is a rational Ponzi game. Accordingly, we discuss two types of algorithmic stablecoins (Rebase & Seigniorage Shares) and dig into the historical market performance of a number of impactful projects to demonstrate the effectiveness of our model. Shange Fu, Qin Wang 0008, Jiangshan Yu, Shiping Chen 0001 |
ICBC | 3 |
| 2023 | A Referable NFT SchemeabstractExisting NFTs confront restrictions of one-time incentive and product isolation. Creators cannot obtain benefits once having sold their NFT products due to the lack of relationships across different NFTs, which results in controversial profit sharing. This paper proposes a referable NFT solution to extend the incentive sustainability of NFTs. We construct the referable NFT (rNFT) network to increase exposure and enhance the referring relationship of inclusive items. We introduce the DAG topology to generate directed edges between each pair of NFTs with corresponding weights and labels for advanced usage. We accordingly implement and propose the scheme under Ethereum Improvement Proposal (EIP) standards, indexed in EIP-5521. Further, we provide the mathematical formation to analyze the utility for each rNFT participant. The discussion gives general guidance among multi-dimensional parameters. The solution, as a result, shape the recognition of potential values hidden in isolated NFTs and raise the interest of communities toward the discovery of NFT derivatives. To our knowledge, this is the first study to build a referable NFT network, explicitly showing the virtual connections among NFTs. Qin Wang 0008, Guangsheng Yu, Shange Fu, Shiping Chen 0001, Jiangshan Yu, Xiwei Xu 0001 |
ICBC | 5 |
| 2023 | TxAllo: Dynamic Transaction Allocation in Sharded Blockchain SystemsabstractThe scalability problem has been one of the most significant barriers limiting the adoption of blockchains. Blockchain sharding is a promising approach to this problem. However, the sharding mechanism introduces a significant number of cross-shard transactions, which are expensive to process.This paper focuses on the transaction allocation problem to reduce the number of cross-shard transactions for better scalability. In particular, we systematically formulate the transaction allocation problem and convert it to the community detection problem on a graph. A deterministic and fast allocation scheme TxAllo is proposed to dynamically infer the allocation of accounts and their associated transactions. It directly optimizes the system throughput, considering both the number of cross-shard transactions and the workload balance among shards.We evaluate the performance of TxAllo on an Ethereum dataset containing over 91 million transactions. Our evaluation results show that for a blockchain with 60 shards, TxAllo reduces the cross-shard transaction ratio from 98% (by using traditional hash-based allocation) to about 12%. In the meantime, the workload balance is well maintained. Compared with other methods, the execution time of TxAllo is almost negligible. For example, when updating the allocation every hour, the execution of TxAllo only takes 0.5 seconds on average, whereas other concurrent works, such as BrokerChain (INFOCOM’22) leveraging the classic METIS method, require 422 seconds. Yuanzhe Zhang, Shirui Pan, Jiangshan Yu |
ICDE | 3 |
| 2023 | BlindHub: Bitcoin-Compatible Privacy-Preserving Payment Channel Hubs Supporting Variable AmountsabstractPayment Channel Hub (PCH) is a promising solution to the scalability issue of first-generation blockchains or cryptocurrencies such as Bitcoin. It supports off-chain payments between a sender and a receiver through an intermediary (called the tumbler). Relationship anonymity and value privacy are desirable features of privacy-preserving PCHs, which prevent the tumbler from identifying the sender and receiver pairs as well as the payment amounts. To our knowledge, all existing Bitcoin-compatible PCH constructions that guarantee relationship anonymity allow only a (predefined) fixed payment amount. Thus, to achieve payments with different amounts, they would require either multiple PCH systems or running one PCH system multiple times. Neither of these solutions would be deemed practical.In this paper, we propose the first Bitcoin-compatible PCH that achieves relationship anonymity and supports variable amounts for payment. To achieve this, we have several layers of technical constructions, each of which could be of independent interest to the community. First, we propose BlindChannel, a novel bi-directional payment channel protocol for privacy-preserving payments, where one of the channel parties is unable to see the channel balances. Then, we further propose BlindHub, a three-party (sender, tumbler, receiver) protocol for private conditional payments, where the tumbler pays to the receiver only if the sender pays to the tumbler. The appealing additional feature of BlindHub is that the tumbler cannot link the sender and the receiver while supporting a variable payment amount. To construct BlindHub, we also introduce two new cryptographic primitives as building blocks, namely Blind Adaptor Signature (BAS), and Flexible Blind Conditional Signature (FBCS). BAS is an adaptor signature protocol built on top of a blind signature scheme. FBCS is a new cryptographic notion enabling us to provide an atomic and privacy-preserving PCH. Lastly, we instantiate both BlindChannel and BlindHub protocols and present implementation results to show their practicality. Xianrui Qin, Shimin Pan, Arash Mirzaei, Zhimei Sui, Oguzhan Ersoy, Amin Sakzad, Muhammed F. Esgin, Joseph K. Liu, Jiangshan Yu, Tsz Hon Yuen |
SP | 9 |
| 2023 | MATH - Finding and Fixing Exploits in AlgorandabstractWith the growth in assets managed on-chain comes more attention from hackers. As Algorand uses its own Algorand Virtual Machine (AVM), there is a need for new vulnerability and exploit detection tools, as those built for Ethereum’s EVM are not suitable. This paper presents the MATH static analysis tool with detectors for the math exploit and byte subtraction vulnerability on the Algorand network using only the deployed smart contract base64 code. We use it to analyse 144,006 stateful smart contracts, find and verify three new instances of the math exploit, and evaluate the tools’ runtime and effectiveness. Peter Ince, Xiapu Luo, Jiangshan Yu, Joseph K. Liu, Xiaoning Du 0001 |
TrustCom | 3 |
| 2023 | Rethinking Practical Blockchain-Based Symmetric Searchable Encryption ServicesabstractBlockchain-based cloud storage is one of the areas which have been developing rapidly in both academia and industry in recent years. As a key feature to improve the usability of such systems, keyword search is yet missing in existing blockchain-based cloud storage systems due to the encryption of uploaded files. To enable this important feature for blockchain-based cloud storage systems while preserving privacy, blockchain-based Symmetric Searchable Encryption schemes have attracted a lot of research interest. In this research, we pinpoint three important requirements for blockchain-based SSE systems to be practical. The first two requirements are fast query response and low on-chain storage cost. They are the key for a blockchain-based SSE system to be usable and feasible. The third requirement is soundness, which guarantees that dishonest behaviours from both users and service providers can be detected and prevented. To the best of our knowledge, none of the existing studies achieves these properties at the same time. To fill in this gap, we present a novel construction of the blockchain-based SSE system. We provide both theoretical analysis and empirical evaluation to show that the system achieves all the desired properties. Jiangshan Yu, Xingliang Yuan, Joseph K. Liu, Cong Zuo 0001 |
TrustCom | 2 |
| 2023 | Enhancing Blockchain Adoption through Tailored Software Engineering: An Industrial-grounded Study in Education CredentialingabstractRecent years have witnessed a marked increase in both academic proposals and industrial adoptions of blockchain technology. However, a majority of the projects remain at the stage of prototype proposals and their real-world deployment has not met the anticipated level. This gap can be attributed to three major barriers - technical difficulties, human factors, and social context. Most of the existing research leans towards addressing the technical challenges, leaving the human and social aspects inadequately explored. Moreover, a lack of practical insights in the existing blockchain software engineering frameworks further exacerbates the adoption problem. To address these gaps, we introduce a Blockchain-oriented Software Engineering Approach for Higher Adoption Possibility (BOSE-HAP) . This approach emphasizes collaboration, reflective thinking, and iterative development, aiming to bolster implementation consistency and stimulate industry adoption. We have applied this approach in the design, development, and launch of a blockchain credentialing product, CValid.org , in the context of a university-level summer school. The product achieves industry-accepted System Usability Score and has seen successful real-world deployment. In addition, this study embed usability considerations throughout the process, involved a total of 112 stakeholders across different development stages, with 25 of them participating in our in-depth interviews and usability testing. Drawing from our firsthand experience and industrial-grounded findings, we deliver eight reflections and propose five best practice suggestions relevant to blockchain adoption. We believe these insights will provide invaluable guidance for both academic researchers and industry practitioners involved in the field of blockchain technology. Zoey Ziyi Li, Han Wang 0023, Dragan Gasevic, Jiangshan Yu, Joseph K. Liu |
Distributed Ledger Technol. Res. Pract. | 4 |
| 2023 | Machine translation-based fine-grained comments generation for solidity smart contracts
Chaochen Shi, Yong Xiang 0001, Jiangshan Yu, Keshav Sood, Longxiang Gao |
Inf. Softw. Technol. | 3 |
| 2023 | CoopEdge+: Enabling Decentralized, Secure and Cooperative Multi-Access Edge Computing Based on BlockchainabstractMulti-access Edge Computing (MEC) has emerged as a new distributed computing paradigm for its ability to offer low-latency services to users. Suffering from constrained computational resources because of their limited physical sizes, edge servers usually cannot handle all the incoming compute tasks on time when they operate independently. Thus, they need to cooperate by peer-offloading. Incentive and trust are the two major challenges towards to cooperative computing among edge servers operating in a distrusted environment. Another specific challenge in the MEC environment is to facilitate incentive and trust in a decentralized manner. This article proposes CoopEdge+, a novel blockchain-based decentralized platform, to drive and support cooperative multi-access edge computing to tackle these challenges in a systematic manner. On CoopEdge+, an edge server can publish a compute task for other edge servers to contend for. A winner is selected from candidate edge servers as the task executor based on their reputation to perform the compute task. After that, CoopEdge+ employs a random leader election scheme to elect a task recorder without revealing its leadership until its consensus epoch. The task recorder will coordinate a consensus among edge servers to record the task executor's performance on blockchain. We implement CoopEdge+ based on Hyperledger fabric and evaluate it experimentally against a baseline implementation and three state-of-the-art implementations in a simulated MEC environment. The results validate the usefulness of CoopEdge+ and demonstrate its performance. Qiang He 0001, Siyu Tan, Bo Li 0103, Jiangshan Yu, Feifei Chen 0001, Yun Yang 0001 |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2022 | Garrison: A Novel Watchtower Scheme for Bitcoin
Arash Mirzaei, Amin Sakzad, Jiangshan Yu, Ron Steinfeld |
ACISP | 3 |
| 2022 | Analysing and Improving Shard Allocation Protocols for Sharded BlockchainsabstractSharding is a promising approach to scale permissionless blockchains. In a sharded blockchain, participants are split into groups, called shards, and each shard only executes part of the workloads. Despite its wide adoption in permissioned systems, transferring such success to permissionless blockchains is still an open problem. In permissionless networks, participants may join and leave the system at any time, making load balancing challenging. In addition, the adversary in such networks can launch the single-shard takeover attack by compromising a single shard's consensus. To address these issues, participants should be securely and dynamically allocated into different shards. However, the protocol capturing such functionality - which we call shard allocation - is overlooked. Runchao Han, Jiangshan Yu, Ren Zhang 0003 |
AFT | 2 |
| 2022 | AuxChannel: Enabling Efficient Bi-Directional Channel for Scriptless BlockchainsabstractPayment channels have been a promising solution to blockchain scalability. While payment channels for script-empowered blockchains (such as Bitcoin and Ethereum) have been well studied, developing payment channels for scriptless blockchains (such as Monero) is considered challenging. In particular, nabling bidirectional payment on scriptless blockchains remains an open challenge. Zhimei Sui, Joseph K. Liu, Jiangshan Yu, Man Ho Au, Jia Liu 0003 |
AsiaCCS | 3 |
| 2022 | DAMYSUS: streamlined BFT consensus leveraging trusted componentsabstractRecently, streamlined Byzantine Fault Tolerant (BFT) consensus protocols, such as HotStuff, have been proposed as a means to circumvent the inefficient view-changes of traditional BFT protocols, such as PBFT. Several works have detailed trusted components, and BFT protocols that leverage them to tolerate a minority of faulty nodes and use a reduced number of communication rounds. Inspired by these works we identify two basic trusted services, respectively called the Checker and Accumulator services, which can be leveraged by streamlined protocols. Based on these services, we design Damysus, a streamlined protocol that improves upon HotStuff's resilience and uses less communication rounds. In addition, we show how the Checker and Accumulator services can be adapted to develop Chained-Damysus, a chained version of Damysus where operations are pipelined for efficiency. We prove the correctness of Damysus and Chained-Damysus, and evaluate their performance showcasing their superiority compared to previous protocols. Jeremie Decouchant, David Kozhaya, Vincent Rahli, Jiangshan Yu |
EuroSys | 4 |
| 2022 | MoNet: A Fast Payment Channel Network for Scriptless Cryptocurrency MoneroabstractWe propose MoNet, the first bi-directional payment channel network with unlimited lifetime for Monero. It is fully compatible with Monero without requiring any modification of the current Monero blockchain. MoNet preserves transaction fungibility, i.e., transactions over MoNet and Monero are indistinguishable, and guarantees anonymity of Monero and MoNet users by avoiding any potential privacy leakage introduced by the new payment channel network. We also propose a new crypto primitive, named Verifiable Consecutive One-way Function (VCOF). It allows one to generate a sequence of statement-witness pairs in a consecutive and verifiable way, and these statement-witness pairs are one-way, namely it is easy to compute a statement-witness pair by knowing any of the pre-generated pairs, but hard in an opposite flow. By using VCOF, a signer can produce a series of consecutive adaptor signatures CAS. We further propose the generic construction of consecutive adaptor signature as an important building block of MoNet. We develop a proof-of-concept implementation for MoNet, and our evaluation shows that MoNet can reach the same transaction throughput as Lightning Network, the payment channel network for Bitcoin. Moreover, we provide a security analysis of MoNet under the Universal Composable (UC) security framework. Zhimei Sui, Joseph K. Liu, Jiangshan Yu, Xianrui Qin |
ICDCS | 3 |
| 2022 | Daric: A Storage Efficient Payment Channel with Punishment Mechanism
Arash Mirzaei, Amin Sakzad, Jiangshan Yu, Ron Steinfeld |
ISC | 3 |
| 2022 | CVallet: A Blockchain-Oriented Application Development for Education and Recruitment
Zoey Ziyi Li, Joseph K. Liu, Jiangshan Yu, Dragan Gasevic, Wayne Yang |
NSS | 3 |
| 2022 | Towards Accurate Knowledge Transfer between Transformer-based Models for Code SummarizationabstractAutomatic code summarization generates high-level natural language descriptions of code snippets, which can benefit software maintenance and code comprehension.Recently, Transformer-based models achieved state-of-the-art performance on code summarization tasks.However, there are data gaps in neural model training for some programming languages.To fill this gap, we propose a novel transfer learning approach to accurately transfer knowledge between Transformer-based models.We train a discriminator to identify which heads of the multi-head attention module should be transferred.On this basis, we define a transfer strategy of parameter matrices.We evaluated the proposed transfer learning approach on four state-of-the-art Transformer-based code summarization models.Experimental results show that models with transferred knowledge outperform original models up to 10.70% in BLEU, 5.36% in ROUGE-L, and 4.34% in METEOR. Chaochen Shi, Yong Xiang 0001, Jiangshan Yu, Longxiang Gao |
SEKE | 3 |
| 2022 | A Bytecode-based Approach for Smart Contract ClassificationabstractWith the development of blockchain technologies, the number of smart contracts deployed on blockchain platforms is growing exponentially, which makes it difficult for users to find desired services by manual screening. The automatic classification of smart contracts can provide blockchain users with keyword-based contract searching and helps to manage smart contracts effectively. Current research on smart contract classification focuses on Natural Language Processing (NLP) solutions which are based on contract source code. However, more than 94% of smart contracts are not open-source, so the application scenarios of NLP methods are very limited. Meanwhile, NLP models are vulnerable to adversarial attacks. This paper proposes a classification model based on features from contract bytecode instead of source code to solve these problems. We also use feature selection and ensemble learning to optimize the model. Our experimental studies on over 11K real-world Ethereum smart contracts show that our model can classify smart contracts without source code and has better performance than baseline models. Our model also has good resistance to adversarial attacks compared with NLP-based models. In addition, our analysis reveals that account features used in many smart contract classification models have little effect on classification and can be excluded. Chaochen Shi, Yong Xiang 0001, Jiangshan Yu, Longxiang Gao, Keshav Sood, Robin Doss |
SANER | 3 |
| 2022 | Security Analysis and Improvement of a Redactable Consortium Blockchain for Industrial Internet-of-ThingsabstractAbstract A redactable consortium blockchain (RCB) can build a trust layer for industrial internet of things (IIoT) so as to enable IIoT to resist certain powerful attacks resulting in improper block content. The redactability is particularly important for blockchains applied in IIoT with valuable or sensitive activities such as financial IoT or energy-trading IoT. Huang et al. proposed a threshold chameleon hash (TCH) scheme and then constructed an accountable-and-sanitizable chameleon signature scheme based on TCH. These two primitives are further used as fundamental modules to build an RCB, which empowers IIoT devices to operate the blockchain in a controllable way. However, our paper shows that Huang et al.’s RCB suffers from a security problem that weakens the crucial redactability. Specifically, we find out that if a transaction in a given block is legally redacted by all authorized sensors who collectively hold the private redacting key, anyone (without any private information) can further redact this redacted transaction and delete any transaction within this redacted block and, meanwhile, any sensor user with a private signing (not redacting) key can insert a forged transaction into this redacted block. We further address this threat by replacing the TCH module in Huang et al.’s RCB with our designed TCH. Wei Gao 0007, Liqun Chen 0002, Chunming Rong, Kaitai Liang, Xianghan Zheng, Jiangshan Yu |
Comput. J. | 6 |
| 2022 | TICK: Tiny Client for BlockchainsabstractIn order to be deployed on storage-limited devices, blockchains generally provide lightweight clients which only store all the block headers rather than all blocks. However, a lightweight client is hard to verify a newly issued transaction, thus making the zero-confirmation transactions between lightweight clients impossible. In particular, transaction verification needs to verify that each referred output of the transaction is not previously spent. The conventional lightweight client design is unscalable as it can only support such an operation in the complexity of$O$($N_{T}$), where$N_{T}$is the total number of transactions in the system. The latest proposals suggest summarizing all the unspent outputs in an ordered Merkle tree. Therefore, a light client can request proof of presence and/or absence of an element in it to prove whether a referred output is previously spent or not, in the complexity of$O$(log($N_{U}$)), where$N_{U}$is the total number of unspent output in the system. However, updating such ordered Merkle tree is slow, thus making the system impractical—by our evaluation, when a new block is generated in Bitcoin, it takes more than one minute to update the ordered Merkle tree. We propose a practical client, TICK, to solve this problem. TICK uses the AVL hash tree to store all the unspent outputs. The AVL hash tree can be updated in the time of$O$($M$*log($N_{U}$)), where$M$is the number of elements that need to be inserted or removed from the AVL hash tree. By evaluation, when a new block is generated, the AVL hash tree can be updated within 1 s. Similarly, the proof can also be generated in the time of$O$(log($N_{U}$)). Therefore,${\textsf {TICK}}$is practical and scalable. Benefited by the AVL hash tree, a storage-limited device can efficiently and cryptographically verify transactions. In addition, rather than requiring new miners to download the entire blockchain before mining, TICK allows new miners to download only a small portion of data to start mining. We implement TICK for Bitcoin and provide an experimental evaluation on its performance by using the current Bitcoin blockchain data. Our result shows that the proof for verifying whether an output of a transaction is spent or not is only several kB. The verification is very fast—generating a proof generally takes less than 1 ms and verifying a proof even takes much less time. In addition, to start mining, new miners only need to download several GB data, rather than downloading over 230-GB data. Wei Zhang 0173, Jiangshan Yu, Qingqiang He, Nan Guan |
IEEE Internet Things J. | 2 |
| 2022 | How to Democratise and Protect AI: Fair and Differentially Private Decentralised Deep LearningabstractThis article first considers the research problem of fairness in collaborative deep learning, while ensuring privacy. A novel reputation system is proposed through digital tokens and local credibility to ensure fairness, in combination with differential privacy to guarantee privacy. In particular, we build a fair and differentially private decentralised deep learning framework called FDPDDL, which enables parties to derive more accurate local models in a fair and private manner by using our developed two-stage scheme: during the initialisation stage, artificial samples generated by Differentially Private Generative Adversarial Network (DPGAN) are used to mutually benchmark the local credibility of each party and generate initial tokens; during the update stage, Differentially Private SGD (DPSGD) is used to facilitate collaborative privacy-preserving deep learning, and local credibility and tokens of each party are updated according to the quality and quantity of individually released gradients. Experimental results on benchmark datasets under three realistic settings demonstrate that FDPDDL achieves high fairness, yields comparable accuracy to the centralised and distributed frameworks, and delivers better accuracy than the standalone framework. Lingjuan Lyu, Yitong Li 0002, Karthik Nandakumar, Jiangshan Yu, Xingjun Ma |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | Fact and Fiction: Challenging the Honest Majority Assumption of Permissionless BlockchainsabstractHonest majority is the key security assumption of Proof-of-Work (PoW) based blockchains. However, the recent 51% attacks render this assumption unrealistic in practice. In this paper, we challenge this assumption against rational miners in the PoW-based blockchains in reality. In particular, we show that the current incentive mechanism may encourage rational miners to launch 51% attacks in two cases. In the first case, we consider a miner of a stronger blockchain launches 51% attacks on a weaker blockchain, where the two blockchains share the same mining algorithm. In the second case, we consider a miner rents mining power from cloud mining services to launch 51% attacks. As 51% attacks lead to double-spending, the miner can profit from these two attacks. If such double-spending is more profitable than mining, miners are more intended to launch 51% attacks rather than mine honestly. Runchao Han, Zhimei Sui, Jiangshan Yu, Joseph K. Liu, Shiping Chen 0001 |
AsiaCCS | 3 |
| 2021 | Characterizing the Impact of Network Delay on Bitcoin MiningabstractWhile previous works have discussed the network delay upper bound that guarantees the consistency of Nakamoto consensus, measuring the actual network latencies and evaluating their impact on miners/pools in Bitcoin remain open questions. This paper fills this gap by: (1) defining metrics that quantify the impact of network latency on the mining network; (2) developing a tool, named miner entanglement (ME), to experimentally evaluate these metrics with a focus on the network latency of the top mining pools; and (3) quantifying the impact of the current network delays on Bitcoin's mining network. For example, we evaluated that Poolin, a Bitcoin mining pool, was able to gain between 0.5% and 1.9% of blocks in addition (i.e., from 36.27 BTC to 137.83 BTC) per week thanks to its low network latency. Moreover, as pools are rational in Bitcoin, we model the strategy a pool would follow to improve its network latency (e.g., by leveraging our ME tool) as a two party game. We show that a Bitcoin mining pool could improve its effective hash rate by up to 4.5%. For a multi-party game, we use a state-of-the-art Bitcoin mining simulator to study the situation where all pools attempt to improve their network latency and show that the largest mining pools would improve their revenue and reach a Nash equilibrium while the smaller mining pools would suffer from a decreased access to the network, and therefore a decreased revenue. These conclusions further incentivize the centralisation of the mining network in Bitcoin, and provide an empirical explanation for the observed tendency of pools to design and rely on low latency private networks. Tong Cao, Jeremie Decouchant, Jiangshan Yu, Paulo Veríssimo |
SRDS | 3 |
| 2021 | CoopEdge: A Decentralized Blockchain-based Platform for Cooperative Edge ComputingabstractEdge computing (EC) has recently emerged as a novel computing paradigm that offers users low-latency services. Suffering from constrained computing resources due to their limited physical sizes, edge servers cannot always handle all the incoming computation tasks timely when they operate independently. They often need to cooperate through peer-offloading. Deployed and managed by different stakeholders, edge servers operate in a distrusted environment. Trust and incentive are the two main issues that challenge cooperative computing between them. Another unique challenge in the EC environment is to facilitate trust and incentive in a decentralized manner. To tackle these challenges systematically, this paper proposes CoopEdge, a novel blockchain-based decentralized platform, to drive and support cooperative edge computing. On CoopEdge, an edge server can publish a computation task for other edge servers to contend for. A winner is selected from candidate edge servers based on their reputations. After that, a consensus is reached among edge servers to record the performance in task execution on blockchain. We implement CoopEdge based on Hyperledger Sawtooth and evaluate it experimentally against a baseline and two state-of-the-art implementations in a simulated EC environment. The results validate the usefulness of CoopEdge and demonstrate its performance. Qiang He 0001, Siyu Tan, Bo Li 0103, Jiangshan Yu, Feifei Chen 0001, Hai Jin 0001, Yun Yang 0001 |
WWW | 5 |
| 2020 | Characterizing Erasable Accounts in Ethereum
Xiaoqi Li 0001, Ting Chen 0002, Xiapu Luo, Jiangshan Yu |
ISC | 4 |
| 2020 | Game Theoretic Analysis of Reputation Approach on Block Withholding Attack
Lianyang Yu, Jiangshan Yu, Yevhen Zolotavkin |
NSS | 2 |
| 2020 | Towards Fair and Privacy-Preserving Federated Deep ModelsabstractThe current standalone deep learning framework tends to result in overfitting and low utility. This problem can be addressed by either a centralized framework that deploys a central server to train a global model on the joint data from all parties, or a distributed framework that leverages a parameter server to aggregate local model updates. Server-based solutions are prone to the problem of a single-point-of-failure. In this respect, collaborative learning frameworks, such as federated learning (FL), are more robust. Existing federated learning frameworks overlook an important aspect of participation: fairness. All parties are given the same final model without regard to their contributions. To address these issues, we propose a decentralized Fair and Privacy-Preserving Deep Learning (FPPDL) framework to incorporate fairness into federated deep learning models. In particular, we design a local credibility mutual evaluation mechanism to guarantee fairness, and a three-layer onion-style encryption scheme to guarantee both accuracy and privacy. Different from existing FL paradigm, under FPPDL, each participant receives a different version of the FL model with performance commensurate with his contributions. Experiments on benchmark datasets demonstrate that FPPDL balances fairness, privacy and accuracy. It enables federated learning ecosystems to detect and isolate low-contribution parties, thereby promoting responsible participation. Lingjuan Lyu, Jiangshan Yu, Karthik Nandakumar, Yitong Li 0002, Xingjun Ma, Jiong Jin, Han Yu 0001, Kee Siong Ng |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2019 | On the optionality and fairness of Atomic SwapsabstractAtomic Swap enables two parties to atomically exchange their own cryptocurrencies without trusted third parties. This paper provides the first quantitative analysis on the fairness of the Atomic Swap protocol, and proposes the first fair Atomic Swap protocol with implementations. Runchao Han, Haoyu Lin, Jiangshan Yu |
AFT | 3 |
| 2019 | On The Unforkability of MoneroabstractMonero, ranked as one of the top privacy-preserving cryptocurrencies by market cap, introduced semi-annual hard fork in 2018. Although hard fork is not an uncommon event in the cryptocurrency industry, the two hard forks in 2018 caused an anonymity risk to Monero where transactions became traceable due to the problem of key reuse. Thisproblem was triggered by the existence of multiple copies of the same coin on different Monero blockchain branches such that the users spent the coins multiple times without preemptive action. We investigate the Monero hard fork events by analysing the transaction data on three different branches of the Monero blockchain. Although we have discovered an insignificant portion of traceable inputs compared to the total available inputs in our dataset, our analyses show that the scalability of the event depends on external factors such as market price and market availability. We propose a cheap, easy to implement strategy to prevent the problem of key reuse, should in the future stronger Monero forks emerge in the market. Dimaz Ankaa Wijaya, Joseph K. Liu, Ron Steinfeld, Dongxi Liu, Jiangshan Yu |
AsiaCCS | 5 |
| 2019 | Revocable and Linkable Ring Signature
Xinyu Zhang 0017, Joseph K. Liu, Ron Steinfeld, Veronika Kuchta, Jiangshan Yu |
Inscrypt | 5 |
| 2019 | Consolidating Hash Power in Blockchain Shards with a Forest
Jiangshan Yu, Joseph K. Liu |
Inscrypt | 2 |
| 2019 | Re-Thinking Untraceability in the CryptoNote-Style BlockchainabstractWe develop new foundations on transaction untraceability for CryptoNote-style blockchain systems. In particular, we observe new attacks; develop theoretical foundations to model transaction untraceability; provide the least upper bound of transaction untraceability guarantee; provide ways to efficiently and automatically verify whether a given ledger achieves optimal transaction untraceability; and provide a general solution that achieves provably optimal transaction untraceability. Unlike previous cascade effect attacks (ESORICS' 17 and PETS' 18) on CryptoNote-style transaction untraceability, we consider not only a passive attacker but also an active adaptive attacker. Our observed attacks allow both types of attacker to trace blockchain transactions that cannot be traced by using the existing attacks. We develop a series of new games, which we call "The Sun-Tzu Survival Problem", to model CryptoNote-style blockchain transaction untraceability and our identified attacks. In addition, we obtain seven novel results, where three of them are negative and the rest are positive. In particular, thanks to our abstract game, we are able to build bipartite graphs to model transaction untraceability, and provide reductions to formally relate the hardness of calculating untraceability to the hardness of calculating the number of perfect matchings in all possible bipartite graphs. We prove that calculating transaction untraceability is a #P-complete problem, which is believed to be even more difficult to solve than NP problems. In addition, we provide the first result on the least upper bound of transaction untraceability. Moreover, through our theoretical results, we are able to provide ways to efficiently and automatically verify whether a given ledger achieves optimal transaction untraceability. Furthermore, we propose a simple strategy for CryptoNote-style blockchain systems to achieve optimal untraceability. We take Monero as a concrete example to demonstrate how to apply this strategy to optimise the untraceability guarantee provided by Monero. Jiangshan Yu, Man Ho Au, Paulo Veríssimo |
CSF | 1 |
| 2019 | A Hidden Markov Model-Based Method for Virtual Machine Anomaly Detection
Chaochen Shi, Jiangshan Yu |
ProvSec | 2 |
| 2019 | P3LS: Plausible Deniability for Practical Privacy-Preserving Live StreamingabstractVideo consumption is one of the most popular Internet activities worldwide. The emergence of sharing videos directly recorded with smartphones raises important privacy concerns. In this paper we propose P3LS, the first practical privacy-preserving peer-to-peer live streaming system. To protect the privacy of its users, P3LS relies on k-anonymity when users subscribe to streams, and on plausible deniability for the dissemination of video streams. Specifically, plausible deniability during the dissemination phase ensures that an adversary is never able to distinguish a user's stream of interest from the fake streams from a statistical analysis (i.e., using an analysis of variance). We exhaustively evaluate P3LS and show that adversaries are not able to identify the real stream of a user with very high confidence. Moreover, P3LS consumes 30% less bandwidth than the standard k-anonymity approach where nodes fully contribute to the dissemination of k streams. Jeremie Decouchant, Antoine Boutet, Jiangshan Yu, Paulo Veríssimo |
SRDS | 3 |
| 2019 | Proof-of-QoS: QoS based blockchain consensus protocol
Bin Yu 0009, Joseph K. Liu, Surya Nepal, Jiangshan Yu, Paul Rimba |
Comput. Secur. | 4 |
| 2019 | RepuCoin: Your Reputation Is Your PowerabstractExisting proof-of-work cryptocurrencies cannot tolerate attackers controlling more than 50 percent of the network's computing power at any time, but assume that such a condition happening is “unlikely”. However, recent attack sophistication, e.g., where attackers can rent mining capacity to obtain a majority of computing power temporarily, render this assumption unrealistic. This paper proposes RepuCoin, the first system to provide guarantees even when more than 50 percent of the system's computing power is temporarily dominated by an attacker. RepuCoin physically limits the rate of voting power growth of the entire system. In particular, RepuCoin defines a miner's power by its `reputation', as a function of its work integrated over the time of the entire blockchain, rather than through instantaneous computing power, which can be obtained relatively quickly and/or temporarily. As an example, after a single year of operation, RepuCoin can tolerate attacks compromising 51 percent of the network's computing resources, even if such power stays maliciously seized for almost a whole year. Moreover, RepuCoin provides better resilience to known attacks, compared to existing proof-of-work systems, while achieving a high throughput of 10000 transactions per second (TPS). Jiangshan Yu, David Kozhaya, Jeremie Decouchant, Paulo Veríssimo |
IEEE Trans. Computers | 1 |
| 2019 | ANCHOR: Logically Centralized Security for Software-Defined NetworksabstractSoftware-defined networking (SDN) decouples the control and data planes of traditional networks, logically centralizing the functional properties of the network in the SDN controller. While this centralization brought advantages such as a faster pace of innovation, it also disrupted some of the natural defenses of traditional architectures against different threats. The literature on SDN has mostly been concerned with the functional side, despite some specific works concerning non-functional properties such as security or dependability. Though addressing the latter in an ad-hoc, piecemeal way may work, it will most likely lead to efficiency and effectiveness problems. We claim that the enforcement of non-functional properties as a pillar of SDN robustness calls for a systemic approach. We further advocate, for its materialization, the reiteration of the successful formula behind SDN: ‘logical centralization’. As a general concept, we propose anchor , a subsystem architecture that promotes the logical centralization of non-functional properties. To show the effectiveness of the concept, we focus on security in this article: we identify the current security gaps in SDNs and we populate the architecture middleware with the appropriate security mechanisms in a global and consistent manner. Essential security mechanisms provided by anchor include reliable entropy and resilient pseudo-random generators, and protocols for secure registration and association of SDN devices. We claim and justify in the article that centralizing such mechanisms is key for their effectiveness by allowing us to define and enforce global policies for those properties; reduce the complexity of controllers and forwarding devices; ensure higher levels of robustness for critical services; foster interoperability of the non-functional property enforcement mechanisms; and promote the security and resilience of the architecture itself. We discuss design and implementation aspects, and we prove and evaluate our algorithms and mechanisms, including the formalisation of the main protocols and the verification of their core security properties using the T amarin prover. Diego Kreutz, Jiangshan Yu, Fernando M. V. Ramos, Paulo Veríssimo |
ACM Trans. Priv. Secur. | 2 |
| 2018 | Evaluating CryptoNote-Style Blockchains
Runchao Han, Jiangshan Yu, Joseph K. Liu, Peng Zhang 0029 |
Inscrypt | 2 |
| 2018 | DECIM: Detecting Endpoint Compromise In MessagingabstractWe present DECIM, an approach to solve the challenge of detecting endpoint compromise in messaging. DECIM manages and refreshes encryption/decryption keys in an automatic and transparent way: it makes it necessary for uses of the key to be inserted in an append-only log, which the device owner can interrogate in order to detect misuse. We propose a multi-device messaging protocol that exploits our concept to allow users to detect unauthorised usage of their device keys. It is co-designed with a formal model, and we verify its core security property using the Tamarin prover. We present a proof-of-concept implementation providing the main features required for deployment. We find that DECIM messaging is efficient even for millions of users. The methods we introduce are not intended to replace existing methods used to keep keys safe (such as hardware devices, careful procedures, or key refreshment techniques). Rather, our methods provide a useful and effective additional layer of security. Jiangshan Yu, Mark Ryan 0001, Cas Cremers |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2017 | Automatically Detecting the Misuse of Secrets: Foundations, Design Principles, and ApplicationsabstractWe develop foundations and several constructions for security protocols that can automatically detect, without false positives, if a secret (such as a key or password) has been misused. Such constructions can be used, e.g., to automatically shut down compromised services, or to automatically revoke misused secrets to minimize the effects of compromise. Our threat model includes malicious agents, (temporarily or permanently) compromised agents, and clones.Previous works have studied domain-specific partial solutions to this problem. For example, Google's Certificate Transparency aims to provide infrastructure to detect the misuse of a certificate authority's signing key, logs have been used for detecting endpoint compromise, and protocols have been proposed to detect cloned RFID/smart cards. Contrary to these existing approaches, for which the designs are interwoven with domain-specific considerations and which usually do not enable fully automatic response (i.e., they need human assessment), our approach shows where automatic action is possible. Our results unify, provide design rationales, and suggest improvements for the existing domain-specific solutions.Based on our analysis, we construct several mechanisms for the detection of misuse. Our mechanisms enable automatic response, such as revoking keys or shutting down services, thereby substantially limiting the impact of a compromise.In several case studies, we show how our mechanisms can be used to substantially increase the security guarantees of a wide range of systems, such as web logins, payment systems, or electronic door locks. For example, we propose and formally verify an improved version of Cloudflare's Keyless SSL protocol that enables key misuse detection. Kevin Milner 0002, Cas Cremers, Jiangshan Yu, Mark Ryan 0001 |
CSF | 3 |
| 2016 | DTKI: A New Formalized PKI with Verifiable Trusted PartiesabstractThe security of public key validation protocols for web-based applications has recently attracted attention because of weaknesses in the certificate authority model, and consequent attacks. Recent proposals using public logs have succeeded in making certificate management more transparent and verifiable. However, those proposals involve a fixed set of authorities. This means an oligopoly is created. Another problem with current log-based system is their heavy reliance on trusted parties that monitor the logs. We propose a distributed transparent key infrastructure (DTKI), which greatly reduces the oligopoly of service providers and allows verification of the behaviour of trusted parties. In addition, this paper formalises the public log data structure and provides a formal analysis of the security that DTKI guarantees. Jiangshan Yu, Vincent Cheval, Mark Ryan 0001 |
Comput. J. | 1 |
| 2014 | An Efficient Generic Framework for Three-Factor Authentication With Provably Secure InstantiationabstractRemote authentication has been widely studied and adapted in distributed systems. The security of remote authentication mechanisms mostly relies on one of or the combination of three factors: 1) something users know—password; 2) something users have—smart card; and 3) something users are—biometric characteristics. This paper introduces an efficient generic framework for three-factor authentication. The proposed generic framework enhances the security of existing two-factor authentication schemes by upgrading them to three-factor authentication schemes, without exposing user privacy. In addition, we present a case study by upgrading a secure two-factor authentication scheme to a secure three-factor authentication scheme. Furthermore, implementation analysis, formal proof, and privacy discussion are provided to show that the derived scheme is practical, secure, and privacy preserving. Jiangshan Yu, Guilin Wang, Yi Mu 0001, Wei Gao 0007 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2013 | Security Analysis of a Single Sign-On Mechanism for Distributed Computer NetworksabstractSingle sign-on (SSO) is a new authentication mechanism that enables a legal user with a single credential to be authenticated by multiple service providers in a distributed computer network. Recently, Chang and Lee proposed a new SSO scheme and claimed its security by providing well-organized security arguments. In this paper, however, we demonstrative that their scheme is actually insecure as it fails to meet credential privacy and soundness of authentication. Specifically, we present two impersonation attacks. The first attack allows a malicious service provider, who has successfully communicated with a legal user twice, to recover the user's credential and then to impersonate the user to access resources and services offered by other service providers. In another attack, an outsider without any credential may be able to enjoy network services freely by impersonating any legal user or a nonexistent user. We identify the flaws in their security arguments to explain why attacks are possible against their SSO scheme. Our attacks also apply to another SSO scheme proposed by Hsu and Chuang, which inspired the design of the Chang–Lee scheme. Moreover, by employing an efficient verifiable encryption of RSA signatures proposed by Ateniese, we propose an improvement for repairing the Chang–Lee scheme. We promote the formal study of the soundness of authentication as one open problem. Guilin Wang, Jiangshan Yu, Qi Xie 0001 |
IEEE Trans. Ind. Informatics | 2 |
| 2012 | Provably Secure Single Sign-on Scheme in Distributed Systems and NetworksabstractDistributed systems and networks have been adopted by telecommunications, remote educations, businesses, armies and governments. A widely applied technique for distributed systems and networks is the single sign-on (SSO) which enables a user to use a unitary secure credential (or token) to access multiple computers and systems where he/she has access permissions. However, most existing SSO schemes have not been formally proved to satisfy credential privacy and soundness of credential based authentication. To overcome this drawback, we formalise the security model of single sign-on scheme with authenticated key exchange. Specially, we point out the difference between soundness and credential privacy, and define them together in one definition. Also, we propose a provably secure single sign-on authentication scheme, which satisfies soundness, preserves credential privacy, meets user anonymity, and supports session key exchange. The proposed scheme is very efficient so that it suits for mobile devices in distributed systems and networks. Jiangshan Yu, Guilin Wang, Yi Mu 0001 |
TrustCom | 1 |