Qianqian Xing

dblp:194/1475 · DBLP profile ↗
← Back
16ranked-venue papers
2as first author
13since 2021 · last 2026
0000-0002-8602-9175ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 1 first-author · 5 since 2021Security and privacy · 4 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 SPADE: Attention-Guided Split Diffusion for Precise Spatial Control in Interior Layout Image Generation
Lianghao Shen, Qianqian Xing, Ronghui Cao, Xiaoyong Tang, Tan Deng
MMM (2)6
2026 Deep Learning Based Side-Channel Attack on Polynomial Multiplication in Post-Quantum Cryptography
abstract
Polynomial multiplication, a critical operation in lattice-based post-quantum cryptography, is highly vulnerable to side-channel secret key leak. Recent advancements in deep learning have demonstrated notable effectiveness in side-channel attacks. However, existing deep learning based approaches to attack polynomial multiplication are constrained by several limitations, including the substantial reliance on extensive traces from the target device and the superficial exploration of the effectiveness of diverse deep learning models. In this work, we propose a novel deep learning based side-channel attack on polynomial multiplication, achieving a significant reduction in the number of required traces by fixing the ciphertext and directly employing the key coefficient values as labels. We evaluate the effectiveness of our approach on three key encapsulation mechanisms (KEMs) submitted to the third round of the NIST Post-Quantum Cryptography Standardization Project: NTRU, Saber and Kyber. Each of these KEMs is implemented on an ARM Cortex-M4 embedded processor, utilizing various polynomial multiplication approaches, including schoolbook multiplication, Toom-Cook multiplication, and NTT-based multiplication. We systematically evaluate the performance of four prominent deep learning models: Multi-Layer Perceptron (MLP), Convolutional Neural Network (CNN), Long Short-Term Memory Network (LSTM), and Transformer. Our results indicate that, to fully recover the complete key, CNN and Transformer demonstrate superior performance for NTRU, requiring only 7 traces during the attack stage. For Saber, Transformer exhibits the best performance with 9 traces. For Kyber, MLP outperforms the others with 19 traces. Compared to two recent state-of-the-art side-channel attacks targeting polynomial multiplication, our approach significantly reduces the number of traces required from the target device, with reductions ranging from 62% to 95.5% across different implementations. These results underscore the potential of advanced deep learning techniques in enhancing the efficiency and effectiveness of side-channel attacks on post-quantum cryptographic systems.
Yuxuan Meng, Qianqian Xing, Xiaofeng Wang 0002, Da Zhou, Linye Liu
ACM Trans. Embed. Comput. Syst.3
2025 TS-Seg: Temporal-Spatial Feature Fusion Based Side-Channel Trace Segmentation
Yuxuan Meng, Qianqian Xing
Inscrypt (1)3
2025 Fairness-Aware Federated Learning Based on Feature Attention and Contribution Calibration
Hanjing Li, Xiaoyong Tang, Qianqian Xing, Tan Deng, Mingfeng Huang, Ronghui Cao
ICIC (9)5
2025 Cellular-Snooper: A General and Real-Time Mobile Application Fingerprinting Attack in LTE Networks
Wenao Zhang, Shuhui Chen, Ziling Wei, Qianqian Xing, Jinshu Su
ICIC (4)5
2025 FactorArmor: A Hierarchical Dual-Factor Framework with Attack Resilience for Face Forgery Detection
abstract
Conventional watermarking techniques are predicated on the recovery accuracy of the watermark for the purpose of forgery detection and copyright protection. However, most existing cutting-edge watermarking schemes are susceptible to black-box query attacks, which has led to a significant increase in the misclassification rate of detections. We believe that the primary reason for this situation is the reliance on bit recovery accuracy, which are somewhat monolithic and susceptible to misjudgement. To address this issue, we propose a proactive defence framework, FactorArmor. Firstly, it consists of an internal factor (bit recovery accuracy) to assess the trustworthiness of an image, which uses a watermark decoder to extract watermark comparisons to achieve copyright authentication. Then we introduce an external factor (mean square error) to achieve tamper localisation. It evaluates the image using image bit steganography network and residual analysis to achieve tamper detection. Finally, the two factors work together in a hierarchical form to enhance the attack resistance of FactorArmor. Extensive experimentation has demonstrated that FactorArmor provides a five-fold enhancement in watermarking capacity and approximately 21% improvement in imperceptibility when compared to the most recent watermarking technologies. Additionally, we assessed the black-box query attacks resistance some frameworks across three datasets. Under the conditions of identical datasets and tampering methods, our framework achieved a score of 0.341, compared to 0.624 for other framework, a decrease of up to 45.3%. These results demonstrate the effectiveness of FactorArmor, especially for forgery detection under black-box query attacks.
Shicheng Fang, Qianqian Xing
IJCNN4
2025 DM-SCT: Side-Channel Trace Generation Via Attention-Enhanced Diffusion Model
abstract
Deep Learning-based Side-Channel Analysis (DLSCA) has demonstrated its potent attack capability against cryptographic systems, enabling the extraction of secret information from leaked physical signal traces. Unfortunately, the availability of real traces for classifier training is often limited due to restricted data collection or protective countermeasures. The generation and enhancement of signal trace is crucial in practical DL-SCA analysis. Existing methods often struggle to accurately model the feature distribution of real traces, and their applicability to emerging post-quantum cryptographic (PQC) algorithms remains unexplored. In this paper, we propose DMSCT, an attention-enhanced diffusion model framework for side-channel trace generation. DM-SCT precisely models the feature distributions of real traces through a conditional injection mechanism and an enhanced attention mechanism. We evaluate DM-SCT across three PQC algorithms: NTRU, Saber, and Kyber, demonstrating its ability to faithfully replicate the leakage features of original side-channel traces. By integrating DM-SCT into DL-SCA, we validate its practical efficacy. Compared to training with real traces alone, DM-SCT improves the accuracy of recovering individual key coefficients by 0.62% to 1.6%. Furthermore, DM-SCT reduces the required number of real training traces by 20% to 25%, outperforming state-of-the-art trace generation methods.
Yuxuan Meng, Qianqian Xing
IPCCC3
2025 A parallel and pipelined high speed Montgomery modular multiplier for IoT devices
Qianqian Xing, Xiaoyong Tang, Tan Deng, Ronghui Cao, Mingfeng Huang
Comput. Networks4
2025 BBAD: Blockchain-based data assured deletion and access control system for IoT
abstract
The massive data generated by the Internet of Things (IoT) is often outsourced to the cloud, leading to a separation between data ownership and management. Access control during the data’s validity period and assured deletion once that period expires are both crucial for protecting privacy. While recent research has primarily focused on access control, assured deletion has received less attention. Existing assured deletion schemes can be classified into key-control based and cryptographic policy based methods, but to varying degrees, they have limitations such as requiring a trusted third party, high encryption overhead, lack of support for deletion verification and fine-grained access control. To address these limitations, we propose BBAD, a blockchain-based assured deletion scheme that leverages smart contracts for fine-grained access control, employs Shamir secret sharing and re-encryption for assured key deletion, and utilizes Merkle Hash Tree (MHT) for public deletion verification. Notably, BBAD eliminates the need for a trusted third party, exhibits low computational overhead, supports customizable deletion time limit, and enables offline verification of deletion for users. Our experimental comparison with two prominent alternatives, Secure Electronic-Document Self-Destructing with Identity-Based Timed-Release Encryption (ESITE) and Key-Policy Attribute-Based Encryption for Assured Deletion (AD-KP-ABE), demonstrates that BBAD reduces data processing time by over 46.5%, data deletion time by 98.4%, and deletion verification time by 99.0%.
Yuxuan Meng, Qianqian Xing
Peer Peer Netw. Appl.3
2024 CART: Concurrent Asynchronous Ratchet Tree for Group Messaging
abstract
In this paper, we propose the Concurrent Asynchronous Ratchet Tree (CART), a novel Continuous Group Key Agreement (CGKA) protocol, specifically designed to facilitate smooth concurrent group key updates. Our approach innovatively leverages a chameleon hash collision-based trapdoor function as a strategic substitution for the single-step DH function traditionally utilized in the Asynchronous Ratchet Tree (ART) framework. This innovation effectively facilitates the resolution of conflicts arising during simultaneous updates, thereby ensuring the consistency of keys from the perspective of each participant. We have executed comprehensive simulations involving random concurrent updates across large group settings and performed comparative analyses against other CGKA methodologies, particularly The CoCoA protocol. Our empirical results indicate that CART presents a reduction in computational requirements at various scales, particularly noting that its advantages are magnified when there is a decrease in the proportion of updating participants. Moreover, our examination of communication overheads unequivocally demonstrates CART’s superior efficiency. This not only underscores its feasibility but also positions CART as a more resource-efficient solution, rendering it ideally suited for practical implementation in real-world group communication settings.
Qianqian Xing
IPCCC3
2024 Protecting unauthenticated messages in LTE/5G mobile networks: A two-level Hierarchical Identity-Based Signature (HIBS) solution
Chuan Yu 0003, Shuhui Chen, Qianqian Xing, Ziling Wei
Comput. Networks3
2024 REEDS: An Efficient Revocable End-to-End Encrypted Message Distribution System for IoT
abstract
To address the confidentiality concerns of malicious adversaries that fully compromise the message broker in pub/sub based IoT systems, several researchers use proxy re-encryption (PRE) to realize end-to-end encrypted message distribution (from publisher to subscriber). However, the all-or-nothing share feature of PRE poses a problem that the share cannot be efficiently revoked. The only way for publishers to revoke the access rights of subscribers is to pick a new public-private key pair and re-generate the re-encryption keys for all the remaining subscribers, which hampers the scalability in practice. To realize efficient user revocation, we present REEDS, an efficient revocable end-to-end encrypted message distribution system for IoT. The core of REEDS is a novel proxy-aided identity-based conditional proxy re-encryption (PIB-CPRE) scheme. Essentially, we use a binary-tree structure to organize re-encryption keys, so that the update of re-encryption keys is reduced from linear to logarithmic in the number of subscribers. We show that REEDS satisfies confidentiality, efficient immediate revocation, decentralized authorization, and maintains low overhead for publishers and subscribers. The prototype system is implemented and its performance is evaluated. The results show that REEDS is not only easy to deploy over existing message brokers but also highly efficient.
Rongmao Chen, Yi Wang 0055, Qianqian Xing
IEEE Trans. Dependable Secur. Comput.4
2021 DIIA: Blockchain-Based Decentralized Infrastructure for Internet Accountability
abstract
The Internet lacking accountability suffers from IP address spoofing, prefix hijacking, and DDoS attacks. Global PKI-based accountable network involves harmful centralized authority abuse and complex certificate management. The inherently accountable network with self-certifying addresses is incompatible with the current Internet and faces the difficulty of revoking and updating keys. This study presents DIIA, a blockchain-based decentralized infrastructure to provide accountability for the current Internet. Specifically, DIIA designs a public-permissioned blockchain called TIPchain to act as a decentralized trust anchor, allowing cryptographic authentication of IP addresses without any global trusted authority. DIIA also proposes the revocable trustworthy IP address bound to the cryptographic key, which supports automatic key renewal and efficient key revocation and eliminates complexity certificate management. We present several security mechanisms based on DIIA to show how DIIA can help to enhance network layer security. We also implement a prototype system and experiment with real-world data. The results demonstrate the feasibility and suitability of our work in practice.
Pengkun Li, Jinshu Su, Xiaofeng Wang 0002, Qianqian Xing
Secur. Commun. Networks4
2017 POSTER: BGPCoin: A Trustworthy Blockchain-based Resource Management Solution for BGP Security
abstract
Origin authentication is one of the most concentrated and advocated BGP security approach against IP prefix hijacking. However, the potential risk of centralized authority abuse and the fragile infrastructure may lead a sluggish deployment of such BGP security approach currently. We propose BGPCoin, a trustworthy blockchain-based Internet resource management solution which provides compliant resource allocations and revocations, and a reliable origin advertisement source. By means of a smart contract to perform and supervise resource assignments on the tamper-resistant Ethereum blockchain, BGPCoin yields significant benefits in the secure origin advertisement and the dependable infrastructure for object repository compared with RPKI. We demonstrate through an Ethereum prototype implementation that the deployment incentives and increased security are technically and economically viable.
Qianqian Xing, Xiaofeng Wang 0002
CCS1
2017 Deja Q Encore RIBE: Anonymous Revocable Identity-Based Encryption with Short Parameters
abstract
Revocable Identity-Based Encryption (RIBE) allows feasible key revoke to enable dynamic user management in certificateless system. The existing RIBE schemes fail to keep receivers anonymity, or short parameters, or adaptive security. Hence, we overcome the drawbacks of previous schemes and contribute to an Anonymous RIBE (ARIBE) scheme with two advantages: (1) the provable full security under the adaptive-ID attack in the standard model and (2) the sufficient efficiency in optimal parameters-the secret subkey and the update subkey are one group element each and decryption only requires two pairings. To our best knowledge, our construction is the first IBE scheme that simultaneously achieves efficient revocability, anonymity and full security in the exponent-inversion IBE family.
Qianqian Xing, Xiaofeng Wang 0002, Yong Tang 0005, Yi Wang 0055
GLOBECOM1
2017 Game theoretic analysis for the mechanism of moving target defense
abstract
Moving target defense (MTD) is a novel way to alter the asymmetric situation of attacks and defenses, and a lot of MTD studies have been carried out recently. However, relevant analysis for the defense mechanism of the MTD technology is still absent. In this paper, we analyze the defense mechanism of MTD technology in two dimensions. First, we present a new defense model named MP2R to describe the proactivity and effect of MTD technology intuitively. Second, we use the incomplete information dynamic game theory to verify the proactivity and effect of MTD technology. Specifically, we model the interaction between a defender who equips a server with different types of MTD techniques and a visitor who can be a user or an attacker, and analyze the equilibria and their conditions for these models. Then, we take an existing incomplete information dynamic game model for traditional defense and its equilibrium result as baseline for comparison, to validate the proactivity and effect of MTD technology. We also identify the factors that will influence the proactivity and effectiveness of the MTD approaches. This work gives theoretical support for understanding the defense process and defense mechanism of MTD technology and provides suggestions to improve the effectiveness of MTD approaches.
Guilin Cai, Qianqian Xing
Frontiers Inf. Technol. Electron. Eng.3