VLDB 2026 Research / reviewers in the wild / expert
Fan Zhang 0022
dblp:21/3626-22
· DBLP profile ↗
28ranked-venue papers
4as first author
16since 2021 · last 2026
0000-0002-8525-4514ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 26 · 4 first-author · 15 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Cirrus: Performant and Accountable Distributed SNARK
Fangyan Shi, Dani Vilardell, Fan Zhang 0022 |
NDSS | 4 |
| 2025 | $Proo\upvarphi $: A ZKP Market Mechanism
Lulu Zhou, Aviv Yaish, Fan Zhang 0022, Ben Fisch, Benjamin Livshits |
FC | 4 |
| 2025 | Decentralization of Ethereum's Builder MarketabstractBlockchains protect an ecosystem worth more than $500bn with strong security properties derived from the principle of decentralization. Is today's blockchain decentralized? In this paper, we empirically studied one of the least decentralized parts of Ethereum, its builder market. The builder market was introduced to fairly distribute Maximal Extractable Value (MEV) among validators and avoid validator centralization. As of the time of writing, two builders produced more than 85% of blocks in Ethereum, creating a concerning centralization factor. However, a common belief is that such centralization “is okay,” arguing that builder centralization will not lead to validator centralization. In this empirical study, we quantify the significant proposer losses within the centralized builder market and challenge the belief that this is acceptable. The significant proposer losses, if left uncontrolled, could undermine the goal of PBS. Moreover, MEV mitigation solutions slated for adoption are affected too because they rely on the builder market as an “MEV oracle,” which is made inaccurate by centralization. Our investigation reveals the incentive issue within the current MEV supply chain and its implications for builder centralization and proposer losses. Finally, we analyze why the proposed mitigation cannot work and highlight two properties essential for effective solutions. Sen Yang 0011, Kartik Nayak, Fan Zhang 0022 |
SP | 3 |
| 2025 | ZIPNet: Low-bandwidth anonymous broadcast from (dis)Trusted Execution EnvironmentsabstractAnonymous Broadcast Channels (ABCs) allow a group of clients to announce messages without revealing the exact author. Modern ABCs operate in a client-server model, where anonymity depends on some threshold (e.g, 1 of 2) of servers being honest. ABCs are an important application in their own right, e.g., for activism and whistleblowing. Recent work on ABCs (Riposte, Blinder) has focused on minimizing the bandwidth cost to clients and servers when supporting large broadcast channels for such applications. But, particularly for low bandwidth settings, they impose large costs on servers, make cover traffic costly, and make volunteer operators unlikely. In this paper, we describe the design, implementation, and evaluation of ZipNet, an anonymous broadcast channel that: 1) scales to hundreds of anytrust servers by minimizing the computational costs of each server, 2) substantially reduces the servers' bandwidth costs by outsourcing the aggregation of client messages to untrusted (for privacy) infrastructure, and 3) supports cover traffic that is both cheap for clients to produce and for servers to handle. Michael Rosenberg, Maurice Shih, Ian Miers, Fan Zhang 0022 |
Proc. Priv. Enhancing Technol. | 6 |
| 2024 | CrudiTEE: A Stick-And-Carrot Approach to Building Trustworthy Cryptocurrency Wallets with TEEsabstractCryptocurrency introduces usability challenges by requiring users to manage signing keys. Popular signing key management services (e.g., custodial wallets), however, either introduce a trusted party or burden users with managing signing key shares, posing the same usability challenges. TEE (Trusted Execution Environment) is a promising technology to avoid both, but practical implementations of TEEs suffer from various side-channel attacks that have proven hard to eliminate. This paper explores a new approach to side-channel mitigation through economic incentives for TEE-based cryptocurrency wallet solutions. By taking the cost and profit of side-channel attacks into consideration, we designed a Stick-and-Carrot-based cryptocurrency wallet, CrudiTEE, that leverages penalties (the stick) and rewards (the carrot) to disincentivize attackers from exfiltrating signing keys in the first place. We model the attacker’s behavior using a Markov Decision Process (MDP) to evaluate the effectiveness of the bounty and enable the service provider to adjust the parameters of the bounty’s reward function accordingly. Lulu Zhou, Zeyu Liu 0008, Fan Zhang 0022, Michael K. Reiter |
AFT | 3 |
| 2024 | Data Independent Order Policy Enforcement: Limitations and SolutionsabstractOrder manipulation attacks such as frontrunning and sandwiching have become an increasing concern in blockchain applications such as DeFi. To protect from such attacks, several recent works have designed order policy enforcement (OPE) protocols to order transactions fairly in a data-independent fashion. However, while the manipulation attacks are motivated by monetary profits, the defenses assume honesty among a significantly large set of participants. In existing protocols, if all participants are rational, they may be incentivized to collude and circumvent the order policy without incurring any penalty. Sarisht Wadhwa, Luca Zanolini, Aditya Asgaonkar, Francesco D'Amato, Chengrui Fang, Fan Zhang 0022, Kartik Nayak |
CCS | 6 |
| 2024 | Sprints: Intermittent Blockchain PoW Mining
Michael Mirkin, Lulu Zhou, Ittay Eyal, Fan Zhang 0022 |
USENIX Security Symposium | 4 |
| 2024 | $\mathsf {monoCash}$monoCash: A Channel-Free Payment Network via Trusted Monotonic CountersabstractCryptocurrencies such as Bitcoin and Ethereum are gaining popularity thanks to their prominent advantages compared to legacy financial transaction systems. However, they require all participants to reach a consensus on the order of transactions, which fundamentally limits their performance in terms of confirmation latency and throughput, thus hindering their further deployment. Off-chain payment network is the state-of-the-art approach of solving this performance issue. Unfortunately, all existing payment networks are based on payment channels, which bring extra overhead, cost and vulnerabilities. In this paper, by leveraging trusted monotonic counters, we propose monoCash, the first off-chain payment network that is channel-free, thereby it is one-hop, routing-free, concurrency-friendly, rebalancing-free and wormhole-resilient. We implement and deploy monoCash on a wide area network of 3,000 nodes. The benchmark shows that it provides a throughput up to 30,000 transactions per second (higher than credit card systems, e.g., VISA). Jian Liu 0012, Peilun Li, Fan Zhang 0022, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | DeFi '23: Workshop on Decentralized Finance and SecurityabstractDecentralized Finance (DeFi) heralds a transformative moment in the realm of finance, challenging traditional intermediaries with a blockchain-centric blueprint. As DeFi burgeons, the intricate dance between its evolution and security emerges as an area of pivotal significance. This workshop navigates the multifaceted landscape of DeFi, where inherent challenges intertwine with new vulnerabilities, emphasizing the necessity for vigilant evaluations and adaptive measures to ensure the integrity of the ecosystem. It further delves into the ripple effects of regulatory scrutiny and its subsequent influence on DeFi's security matrix. As we stand on the cusp of uncharted territories, the workshop aims to provide a comprehensive discourse on DeFi's security challenges, fortified by interdisciplinary expertise, inviting participants to explore, ideate, and collaboratively forge a path towards a robust and secure DeFi paradigm. Kaihua Qin, Fan Zhang 0022 |
CCS | 2 |
| 2023 | The Locality of Memory CheckingabstractMotivated by the extended deployment of authenticated data structures (e.g., Merkle Patricia Tries) for verifying massive amounts of data in blockchain systems, we begin a systematic study of the I/O efficiency of such systems. We first explore the fundamental limitations of memory checking, a previously-proposed abstraction for verifiable storage, in terms of its locality-a complexity measure that we introduce for the first time and is defined as the number of non-contiguous memory regions a checker must query to verifiably answer a read or a write query. Our central result is an Ω(log n/log log n) lower bound for the locality of any memory checker. Then we turn our attention to (dense and sparse) Merkle trees, one of the most celebrated memory checkers, and provide stronger lower bounds for their locality. For example, we show that any dense Merkle tree layout will have average locality at least (1/3)log n. Furthermore, if we allow node duplication, we show that if any write operation has at most polylog complexity, then the read locality cannot be less than log n/log log n. Our lower bounds help us construct two new locality-optimized authenticated data structures (DupTree and PrefixTree) which we implement and evaluate on random operations and real workloads, and which are shown to outperform traditional Merkle trees, especially as the number of leaves increases. Weijie Wang 0001, Charalampos Papamanthou, Fan Zhang 0022 |
CCS | 4 |
| 2023 | MISO: Legacy-compatible Privacy-preserving Single Sign-on using Trusted Execution EnvironmentsabstractSingle sign-on (SSO) allows users to authenticate to third-party applications through a central identity provider. Despite their wide adoption, deployed SSO systems suffer from privacy problems such as user tracking by the identity provider. While numerous solutions have been proposed by academic papers, none were adopted because they require modifying identity providers, a significant adoption barrier in practice. Solutions do get deployed, however, fail to eliminate major privacy issues.Leveraging Trusted Execution Environments (TEEs), we propose MISO, the first privacy-preserving SSO system that is completely compatible with existing identity providers (such as Google and Facebook). This means MISO can be easily integrated into existing SSO ecosystem today and benefit end users. MI SO also enables new functionality that standard SSO cannot offer: MISO allows users to leverage multiple identity providers in a single SSO workflow, potentially in a threshold fashion, to better protect user accounts. We fully implemented MISO based on Intel SGX. Our evaluation shows that MISO can handle high user concurrency with practical performance. Rongwu Xu, Sen Yang 0011, Fan Zhang 0022, Zhixuan Fang |
EuroS&P | 3 |
| 2023 | To Broadcast or Not to Broadcast: Decision-Making Strategies for Mining Empty BlocksabstractResource optimization in blockchain systems is a critical aspect of their architectural design. Despite frequent network congestion in Ethereum, a notable proportion of block space is underutilized, with occurrences of completely unused blocks exacerbating resource inefficiency in the network. This study investigates the motivations behind miners’ production of empty blocks. It is found that the immediate gains from mining empty blocks often outweigh the potential benefits derived from including transactions. Furthermore, our analysis indicates a substantial decrease in the frequency of empty blocks following Ethereum’s transition at the Merge, underscoring the effectiveness of the Proof-of-Stake (PoS) consensus mechanism in improving block space utilization in blockchain environments. Chon Kit Lao, Luyao Zhang 0001, Fan Zhang 0022, Kanye Ye Wang |
ICPADS | 4 |
| 2023 | He-HTLC: Revisiting Incentives in HTLC
Sarisht Wadhwa, Jannis Stoeter, Fan Zhang 0022, Kartik Nayak |
NDSS | 3 |
| 2022 | Empirical Analysis of EIP-1559: Transaction Fees, Waiting Times, and Consensus SecurityabstractA transaction fee mechanism (TFM) is an essential component of a blockchain protocol. However, a systematic evaluation of the real-world impact of TFMs is still absent. Using rich data from the Ethereum blockchain, the mempool, and exchanges, we study the effect of EIP-1559, one of the earliest-deployed TFMs that depart from the traditional first-price auction paradigm. We conduct a rigorous and comprehensive empirical study to examine its causal effect on blockchain transaction fee dynamics, transaction waiting times, and consensus security. Our results show that EIP-1559 improves the user experience by mitigating intrablock differences in the gas price paid and reducing users' waiting times. However, EIP-1559 has only a small effect on gas fee levels and consensus security. In addition, we find that when Ether's price is more volatile, the waiting time is significantly higher. We also verify that a larger block size increases the presence of siblings. These findings suggest new directions for improving TFMs. Yulin Liu 0002, Yuxuan Lu 0001, Kartik Nayak, Fan Zhang 0022, Luyao Zhang 0001, Yinhong Zhao |
CCS | 4 |
| 2022 | zkBridge: Trustless Cross-chain Bridges Made PracticalabstractBlockchains have seen growing traction with cryptocurrencies reaching a market cap of over 1 trillion dollars, major institution investors taking interests, and global impacts on governments, businesses, and individuals. Tiancheng Xie, Jiaheng Zhang, Zerui Cheng, Fan Zhang 0022, Yupeng Zhang 0001, Yongzheng Jia, Dan Boneh, Dawn Song |
CCS | 4 |
| 2021 | CanDID: Can-Do Decentralized Identity with Legacy Compatibility, Sybil-Resistance, and AccountabilityabstractWe present CanDID, a platform for practical, user-friendly realization of decentralized identity, the idea of empowering end users with management of their own credentials.While decentralized identity promises to give users greater control over their private data, it burdens users with management of private keys, creating a significant risk of key loss. Existing and proposed approaches also presume the spontaneous availability of a credential-issuance ecosystem, creating a bootstrapping problem. They also omit essential functionality, like resistance to Sybil attacks and the ability to detect misbehaving or sanctioned users while preserving user privacy.CanDID addresses these challenges by issuing credentials in a user-friendly way that draws securely and privately on data from existing, unmodified web service providers. Such legacy compatibility similarly enables CanDID users to leverage their existing online accounts for recovery of lost keys. Using a decentralized committee of nodes, CanDID provides strong confidentiality for user’s keys, real-world identities, and data, yet prevents users from spawning multiple identities and allows identification (and blacklisting) of sanctioned users.We present the CanDID architecture and report on experiments demonstrating its practical performance. Sai Krishna Deepak Maram, Harjasleen Malvai, Fan Zhang 0022, Nerla Jean-Louis, Alexander Frolov 0002, Tyler Kell, Tyrone Lobban, Christine Moy, Ari Juels, Andrew Miller 0001 |
SP | 3 |
| 2020 | DECO: Liberating Web Data Using Decentralized Oracles for TLSabstractThanks to the widespread deployment of TLS, users can access private data over channels with end-to-end confidentiality and integrity. What they cannot do, however, is prove to third parties the provenance of such data, i.e., that it genuinely came from a particular website. Existing approaches either introduce undesirable trust assumptions or require server-side modifications. Users' private data is thus locked up at its point of origin. Users cannot export data in an integrity-protected way to other applications without help and permission from the current data holder. We propose DECO (short for decentralized oracle) to address the above problems. DECO allows users to prove that a piece of data accessed via TLS came from a particular website and optionally prove statements about such data in zero-knowledge, keeping the data itself secret. DECO is the first such system that works without trusted hardware or server-side modifications. DECO can liberate private data from centralized web-service silos, making it accessible to a rich spectrum of applications. To demonstrate the power of DECO, we implement three applications that are hard to achieve without it: a private financial instrument using smart contracts, converting legacy credentials to anonymous credentials, and verifiable claims against price discrimination. Fan Zhang 0022, Sai Krishna Deepak Maram, Harjasleen Malvai, Steven Goldfeder, Ari Juels |
CCS | 1 |
| 2020 | Order-Fairness for Byzantine Consensus
Mahimna Kelkar, Fan Zhang 0022, Steven Goldfeder, Ari Juels |
CRYPTO (3) | 2 |
| 2019 | Paralysis Proofs: Secure Dynamic Access Structures for Cryptocurrency Custody and MoreabstractThe growing adoption of digital assets---including but not limited to cryptocurrencies, tokens, and even identities---calls for secure and robust digital assets custody. A common way to distribute the ownership of a digital asset is (M, N)-threshold access structures. However, traditional access structures leave users with a painful choice. Setting M = N seems attractive as it offers maximum resistance to share compromise, but it also causes maximum brittleness: A single lost share renders the asset permanently frozen, inducing paralysis. Lowering M improves availability, but degrades security. Fan Zhang 0022, Philip Daian, Iddo Bentov, Ian Miers, Ari Juels |
AFT | 1 |
| 2019 | Tesseract: Real-Time Cryptocurrency Exchange Using Trusted HardwareabstractWe propose Tesseract, a secure real-time cryptocurrency exchange service. Existing centralized exchange designs are vulnerable to theft of funds, while decentralized exchanges cannot offer real-time cross-chain trades. All currently deployed exchanges are also vulnerable to frontrunning attacks. Tesseract overcomes these flaws and achieves a best-of-both-worlds design by using a trusted execution environment. The task of committing the recent trade data to independent cryptocurrency systems presents an all-or-nothing fairness problem, to which we present ideal theoretical solutions, as well as practical solutions. Tesseract supports not only real-time cross-chain cryptocurrency trades, but also secure tokenization of assets pegged to cryptocurrencies. For instance, Tesseract-tokenized bitcoins can circulate on the Ethereum blockchain for use in smart contracts. We provide a demo implementation of Tesseract that supports Bitcoin, Ethereum, and similar cryptocurrencies. Iddo Bentov, Yan Ji 0001, Fan Zhang 0022, Lorenz Breidenbach, Philip Daian, Ari Juels |
CCS | 3 |
| 2019 | CHURP: Dynamic-Committee Proactive Secret SharingabstractWe introduce CHURP (CHUrn-Robust Proactive secret sharing). CHURP enables secure secret-sharing in dynamic settings, where the committee of nodes storing a secret changes over time. Designed for blockchains, CHURP has lower communication complexity than previous schemes: $O(n)$ on-chain and $O(n^2)$ off-chain in the optimistic case of no node failures. CHURP includes several technical innovations: An efficient new proactivization scheme of independent interest, a technique (using asymmetric bivariate polynomials) for efficiently changing secret-sharing thresholds, and a hedge against setup failures in an efficient polynomial commitment scheme. We also introduce a general new technique for inexpensive off-chain communication across the peer-to-peer networks of permissionless blockchains. We formally prove the security of CHURP, report on an implementation, and present performance measurements. Sai Krishna Deepak Maram, Fan Zhang 0022, Lun Wang 0001, Andrew Low, Yupeng Zhang 0001, Ari Juels, Dawn Song |
CCS | 2 |
| 2019 | Ekiden: A Platform for Confidentiality-Preserving, Trustworthy, and Performant Smart ContractsabstractSmart contracts are applications that execute on blockchains. Today they manage billions of dollars in value and motivate visionary plans for pervasive blockchain deployment. While smart contracts inherit the availability and other security assurances of blockchains, however, they are impeded by blockchains' lack of confidentiality and poor performance. We present Ekiden, a system that addresses these critical gaps by combining blockchains with Trusted Execution Environments (TEEs). Ekiden leverages a novel architecture that separates consensus from execution, enabling efficient TEE-backed confidentiality-preserving smart-contracts and high scalability. Our prototype (with Tendermint as the consensus layer) achieves example performance of 600× more throughput and 400× less latency at 1000× less cost than the Ethereum mainnet. Another contribution of this paper is that we systematically identify and treat the pitfalls arising from harmonizing TEEs and blockchains. Treated separately, both TEEs and blockchains provide powerful guarantees, but hybridized, though, they engender new attacks. For example, in naïve designs, privacy in TEE-backed contracts can be jeopardized by forgery of blocks, a seemingly unrelated attack vector. We believe the insights learned from Ekiden will prove to be of broad importance in hybridized TEE-blockchain systems. Raymond Cheng 0001, Fan Zhang 0022, Jernej Kos, Warren He, Nicholas Hynes 0001, Noah M. Johnson, Ari Juels, Andrew Miller 0001, Dawn Song |
EuroS&P | 2 |
| 2017 | Solidus: Confidential Distributed Ledger Transactions via PVORMabstractBlockchains and more general distributed ledgers are becoming increasingly popular as efficient, reliable, and persistent records of data and transactions. Unfortunately, they ensure reliability and correctness by making all data public, raising confidentiality concerns that eliminate many potential uses. Ethan Cecchetti, Fan Zhang 0022, Yan Ji 0001, Ahmed E. Kosba, Ari Juels, Elaine Shi |
CCS | 2 |
| 2017 | Sealed-Glass Proofs: Using Transparent Enclaves to Prove and Sell KnowledgeabstractTrusted hardware systems, such as Intel's new SGX instruction set architecture extension, aim to provide strong confidentiality and integrity assurances for applications. Recent work, however, raises serious concerns about the vulnerability of such systems to side-channel attacks. We propose, formalize, and explore a cryptographic primitive called a Sealed-Glass Proof (SGP) that models computation possible in an isolated execution environment with unbounded leakage, and thus in the face of arbitrary side-channels. A SGP specifically models the capabilities of trusted hardware that can attest to correct execution of a piece of code, but whose execution is transparent, meaning that an application's secrets and state are visible to other processes on the same host. Despite this strong threat model, we show that SGPs enable a range of practical applications. Our key observation is that SGPs permit safe verifiable computing in zero-knowledge, as data leakage results only in the prover learning her own secrets. Among other applications, we describe the implementation of an end-to-end bug bounty (or zero-day solicitation) platform that couples a SGX-based SGP with a smart contract. Our platform enables a marketplace that achieves fair exchange, protects against unfair bounty withdrawals, and resists denial-of-service attacks by dishonest sellers. We also consider a slight relaxation of the SGP model that permits black-box modules instantiating minimal, side-channel resistant primitives, yielding a still broader range of applications. Our work shows how trusted hardware systems such as SGX can support trustworthy applications even in the presence of side channels. Florian Tramèr, Fan Zhang 0022, Huang Lin, Jean-Pierre Hubaux, Ari Juels, Elaine Shi |
EuroS&P | 2 |
| 2017 | REM: Resource-Efficient Mining for Blockchains
Fan Zhang 0022, Ittay Eyal, Robert Escriva, Ari Juels, Robbert van Renesse |
USENIX Security Symposium | 1 |
| 2016 | Town Crier: An Authenticated Data Feed for Smart ContractsabstractSmart contracts are programs that execute autonomously on blockchains. Their key envisioned uses (e.g. financial instruments) require them to consume data from outside the blockchain (e.g. stock quotes). Trustworthy data feeds that support a broad range of data requests will thus be critical to smart contract ecosystems. Fan Zhang 0022, Ethan Cecchetti, Kyle Croman, Ari Juels, Elaine Shi |
CCS | 1 |
| 2016 | Stealing Machine Learning Models via Prediction APIs
Florian Tramèr, Fan Zhang 0022, Ari Juels, Michael K. Reiter, Thomas Ristenpart |
USENIX Security Symposium | 2 |
| 2015 | PlateClick: Bootstrapping Food Preferences Through an Adaptive Visual InterfaceabstractFood preference learning is an important component of wellness applications and restaurant recommender systems as it provides personalized information for effective food targeting and suggestions. However, existing systems require some form of food journaling to create a historical record of an individual's meal selections. In addition, current interfaces for food or restaurant preference elicitation rely extensively on text-based descriptions and rating methods, which can impose high cognitive load, thereby hampering wide adoption. Longqi Yang 0001, Yin Cui, Fan Zhang 0022, John P. Pollak, Serge J. Belongie, Deborah Estrin |
CIKM | 3 |