VLDB 2026 Research / reviewers in the wild / expert
Qiuyun Lyu
dblp:216/4989
· DBLP profile ↗
8ranked-venue papers
8as first author
7since 2021 · last 2026
0000-0002-7822-7905ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 3 · 3 first-author · 2 since 2021Security and privacy · 3 · 3 first-author · 3 since 2021Systems, architecture and hardware · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Secure Self-Sovereign Identity Scheme Based on Soulbound Token and Trusted Personal Data SpaceabstractSelf-Sovereign Identity (SSI) aims to enable a physical-world persona to autonomously own and manage his digital identity, which serves as a mapping of his real-world identity into cyberspace and has become an essential paradigm in trusted digital identity management. Although current state-of-the-art SSI schemes provide security properties such as Sybil-resistance, privacy-preserving, or regulation, they typically employ static identifier(s) to represent a persona's identity, rendering them vulnerable to identity forgery or theft, and they still fail to simultaneously address the problems of privacy leakage, Sybil attacks, and inadequate regulation. To overcome these limitations, we propose a secure self-sovereign identity scheme that integrates SoulBound Token (SBT) and a trusted personal data space. In our design, each physical-world persona has a unique, individual-specific identity engine generated from verified biometric data and metadata, with a non-transferable SBT bound to it via a smart contract, thereby enhancing resistance to Sybil attacks and making the identity misappropriation significantly harder. To further prevent an identity from being linked by service providers, we construct a distinct child identity engine for each service using behavioral history stored in a trusted personal data space. Moreover, we design a conditional and collaborative regulation mechanism that ensures malicious digital identities and service providers are traceable and subject to supervision. Finally, we perform a security and performance analysis to demonstrate that our scheme is practical, secure, and offers several advantages over state-of-the-art solutions. Qiuyun Lyu, Xiaoqi Lou, Butian Huang, Yingjie Xia |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Secure personal data sharing for simultaneous, parallel or sequential processing service: Autonomously and controllably
Qiuyun Lyu, Yilong Zhou, Yizhi Ren, Lingfei Zhou, Zekai Wu, Chengyao Zhao, Duohe Ma |
Future Gener. Comput. Syst. | 1 |
| 2025 | AATM: An Anonymous Authentication Protocol for Time Span of Membership With Self-Blindness and AccountabilityabstractInternet of Things (IoT) devices using subscription services (e.g. connected vehicles accessing entertainment programs) often purchase membership credentials from service providers with limited usage counts or validity periods, we call them pay-per-use or time span of membership services. However, users’ access records, usage preferences, and habits are collected by network adversarys or membership providers for creating users’ profiles, targeted advertising, and even for being sold maliciously. To deal with these problems, lots of anonymous authentication protocols are proposed to provide users with pseudonyms to conceal their real identities. Although these protocols effectively prevent network adversarys from compromising users’ privacy, membership service providers can still gather users’ behavioral privacy via their membership credentials. Therefore, several scholars proposed k-times anonymous authentication protocols and self-blind credentials to enhance users’ privacy protection, but the k-times anonymous authentication protocols are only for pay-per-use membership services and the schemes of self-blind credentials are lack of regulating malicious users. To address these issues, this article proposes an anonymous authentication protocol for time span of membership (AATM) with self-blindness and accountability. Specifically, we utilize Structure Preserving Signatures on Equivalence Classes (SPS-EQ) and Signatures with Flexible Public Key (SFPK) to build accountable, self-blinding credentials that ensure that every time a user visits a member, he or she can create a brand new identity on their own, which not only prevents users from being linked by service providers, but also supports conditional fair regulation. Security and performance analyses show that AATM is better than the state-of-the-art schemes in terms of security and privacy-preserving capabilities, and its computation cost also meets the practical application requirements. Qiuyun Lyu, Xiwen Liang, Shaopeng Cheng, Yizhi Ren, Chengli Xu, Weizhi Meng 0001, Duohe Ma |
IEEE Internet Things J. | 1 |
| 2024 | TFAN: A Task-adaptive Feature Alignment Network for few-shot website fingerprinting attacks on Tor
Qiuyun Lyu, Huihui Xie, Wei Wang 0527, Yanyu Cheng, Yongqun Chen, Z. Jane Wang 0001 |
Comput. Secur. | 1 |
| 2024 | Toward Personal Data Sharing Autonomy: A Task-Driven Data Capsule Sharing SystemabstractPersonal data custodian services enable data owners to share their data with data consumers in a convenient manner, anytime and anywhere. However, with data hosted in these services being beyond the control of the data owners, it raises significant concerns about privacy in personal data sharing. Many schemes have been proposed to realize fine-grained access control and privacy protection in data sharing. However, they fail to protect the rights of data owners to their data under the law, since their designs focus on the management of system administrators rather than enhancing the data owners’ privacy. In this paper, we introduce a novel task-driven personal data sharing system based on the data capsule paradigm realizing personal data sharing autonomy. It enables data owners in our system to fully control their data, and share it autonomously. Specifically, we present a tamper-resistant data capsule encapsulation method, where the data capsule is the minimal unit for independent and secure personal data storage and sharing. Additionally, to realize selective sharing and informed-consent based authorization, we propose a task-driven data sharing mechanism that is resistant to collusion and EDoS attacks. Furthermore, by updating parts of the data capsules, the permissions granted to data consumers can be immediately revoked. Finally, we conduct a security and performance analysis, proving that our scheme is correct, sound, and secure, as well as revealing more advantageous features in practicality, compared with the state-of-the-art schemes. Qiuyun Lyu, Yilong Zhou, Yizhi Ren, Zhen Wang 0013, Yunchuan Guo |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | A2UA: An Auditable Anonymous User Authentication Protocol Based on Blockchain for Cloud ServicesabstractRegulating illegal activities in cyberspace to balance user privacy and cyberspace governance has been a non-trivial challenge when designing anonymous authentication solutions. For example, while several existing anonymous authentication protocols support accountability, they either risk leaking users' private keys or incur significant overhead for accountability in each ongoing authentication, including in cloud service-based authentication schemes. Seeking to address these limitations, this paper proposes an auditable anonymous user authentication (A2UA) protocol based on blockchain for cloud services. The A2UA protocol mainly employs bilinear pairing, partial authentication factors, dynamic credits and fake-public keys (FPKs) to achieve anonymous mutual authentication between users and cloud service providers, and applies ring signature and blockchain to accomplish two-level accountability while maintaining user privacy. Our analysis results show that the A2UA protocol outperforms several other existing schemes in terms of security, computation and communication costs as well as security and privacy features. Additionally, it has good feasibility in terms of the Ethereum Gas cost as demonstrated in our evaluation. Qiuyun Lyu, Hao Li 0110, Zhining Deng, Yizhi Ren, Ning Zheng 0001, Huaping Liu 0002, Kim-Kwang Raymond Choo |
IEEE Trans. Cloud Comput. | 1 |
| 2022 | JRS: A Joint Regulating Scheme for Secretly Shared Content Based on BlockchainabstractFor the sake of privacy, encrypting the content shared on the Internet is becoming popular. However, it brings a nontrivial challenge in regulating the illicit shared content (e.g., viruses, rumors, malicious code, etc.). To deal with it, lots of schemes have been proposed, which mainly rely on a third-party—regulatory authority (RA), to perform auditing, regulating or supervising exclusively. Although these schemes mitigate the problem of illicit shared content, they still suffer from the following two issues. On one hand, relying on a single RA alone may lead to the serious problems of injustice and inadequate regulating. On the other hand, users’ privacy is violated since an independent RA unconditionally inspects all the files shared by users. Therefore, we propose a joint regulating scheme (JRS) for secretly shared content based on threshold secret sharing algorithm and blockchain technology. To make the censor activities democratic and public, they are authorized by both the RAs and blockchain miners during which two threshold secret sharing algorithms are applied. Further, only the suspicious users (or files) are censored and the whole process is recorded as blockchain transactions to balance the user privacy and censoring fairness. At last, the results of security and performance analysis show that JRS can resist the known attacks and the cost is acceptable in practice. Qiuyun Lyu, Hao Li 0110, Zhining Deng, Yizhen Qi, Huaping Liu 0002, Mengzhou Gao 0001 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2020 | SBAC: A secure blockchain-based access control framework for information-centric networking
Qiuyun Lyu, Yizhen Qi, Huaping Liu 0002, Qiuhua Wang, Ning Zheng 0001 |
J. Netw. Comput. Appl. | 1 |