Zhangshuang Guan

dblp:218/8858 · DBLP profile ↗
← Back
10ranked-venue papers
4as first author
9since 2021 · last 2026
0000-0002-8364-4578ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 2 first-author · 5 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 ClusterGuard: Secure Clustered Aggregation for Federated Learning With Robustness
abstract
Federated Learning, as a multi-party machine learning paradigm, has garnered significant attention, but model updates may still leak sensitive information. Secure aggregation protocols are considered an effective solution for privacy protection in Federated Learning. However, in large-scale federated learning systems, designing efficient and practical secure aggregation remains a critical challenge. Moreover, while secure aggregation effectively conceals model updates, it unintentionally complicates the detection and mitigation of poisoning attacks, thereby exposing the system to vulnerabilities from both data and model poisoning. To address these challenges, we propose ClusterGuard, a secure clustered aggregation scheme. ClusterGuard leverages Verifiable Random Function (VRF) to ensure fair and transparent client clustering. Within each cluster, it employs a lightweight key-homomorphic masking mechanism combined with verifiable secret sharing to enable secure and efficient aggregation. Fur thermore, we design a dual filtering mechanism based on cosine similarity and norm to effectively detect and resist poisoning attacks. We provide two variants of ClusterGuard for both client-server and decentralized environments with blockchains, respectively. Extensive experiments on standard datasets demonstrate that ClusterGuard achieves over 2× efficiency improvement compared to advanced secure aggregation methods. Even with 20% of clients being malicious, the trained model maintains accuracy comparable to the original model, outperforming state-of-the art robustness solutions. ClusterGuard provides a more efficient, secure, and robust solution for practical federated learning.
Zhiguo Wan, Zhangshuang Guan
IEEE Trans. Dependable Secur. Comput.3
2025 Communication-efficient Verifiable and Oblivious Aggregation with Client Dropouts
abstract
Federated learning (FL) allows each client to train data locally and share only model parameters with an aggregation server. A critical component of FL is secure aggregation (SA), which protects user privacy during the server-side aggregation of client model parameters. However, SA-based FL still faces several challenges from a malicious server, affecting both performance and security. To address these issues, we propose the first 2-round-trip verifiable and oblivious aggregation protocol. Specifically, our protocol incorporates: (1) a consistent temporary key disclosure mechanism for round-trip-efficient communication with client dropout resilience; (2) a message authentication code to verify aggregation results; and (3) a multi-round oblivious aggregation scheme that conceals both individual and global model parameters. These three key techniques collectively enable efficient communication while preventing a malicious server from tampering with aggregation results and accessing any individual or global parameters. We conducted a comprehensive evaluation to demonstrate the practicality and efficiency of our design compared to existing schemes.
Zhangshuang Guan, Longyun Yang, Zhiguo Wan, Jinsong Han
ICASSP1
2025 Input Integrity and Authentic Results: Towards Trustworthy Aggregation in Federated Learning
Zhangshuang Guan, Zhiguo Wan, Wei Wang 0012
INFOCOM1
2025 OPSA: Efficient and Verifiable One-Pass Secure Aggregation With TEE for Federated Learning
abstract
Federated learning enables collaborative model training while preserving data privacy by keeping data local. To protect user privacy during model aggregation, secure aggregation (SA) protocols are widely adopted to mask models. However, existing SA protocols require at least three round trips per aggregation and lack mechanisms to verify aggregation results. Verifiable SA addresses the verification gap but incurs high communication costs. TEE-based SA minimizes round trips but faces computational bottlenecks due to TEE's limited physical memory, especially when handling larger models or numerous clients. In this work, we introduce OPSA, an efficient and verifiable one-pass SA protocol based on TEE. By handling client dropouts via server-side TEE, OPSA enables the server to aggregate masked models in a single pass, significantly reducing round trips. To mitigate TEE's limitations, OPSA offloads tasks like model aggregation and mask elimination outside TEE, with only shared keys processed within TEE. Building on this design, we propose KhPRF-OPSA (single masking) and POT-OPSA (double masking) protocols, both incorporating novel cryptographic primitives. Furthermore, OPSA integrates commitment and signature mechanisms to ensure result verifiability with only$O(1)$additional communication overhead per client. Compared to state-of-the-art schemes, OPSA achieves a 2$\sim 10\times$speedup in multi-round aggregation while guaranteeing result verification.
Zhangshuang Guan, Zhiguo Wan, Jinsong Han
IEEE Trans. Dependable Secur. Comput.1
2024 A Lightweight Group Authentication Framework for Cross-Domain Internet of Things
Ivan Edmar Carvajal Roca, Zhangshuang Guan, Zhiguo Wan
SecureComm (4)2
2024 PIAS: Privacy-Preserving Incentive Announcement System Based on Blockchain for Internet of Vehicles
abstract
More vehicles are connecting to the Internet of Things (IoT), transforming Vehicle Ad hoc Networks (VANETs) into the Internet of Vehicles (IoV), providing a more environmentally friendly and safer driving experience. Vehicular announcement networks show promise in vehicular communication applications. However, two major issues arise when establishing such a system. First, user privacy cannot be guaranteed when messages are forwarded anonymously, thus the reliability of these messages is in question. Second, users often lack interest in responding to announcements. To address these problems, we introduce a Blockchain-based incentive announcement system called PIAS. This system enables anonymous message commitment in a semi-trusted environment and encourages witnesses to respond to requests for traffic information. Additionally, PIAS uses blockchain accounts as identities to participate in the system with incentives, ensuring privacy in anonymous announcements. PIAS successfully protects the privacy of participants and motivates witnesses to respond to requests. Furthermore, our assessment of security and compatibility shows that PIAS can maintain privacy and incentivization while being compatible with both the Bitcoin and Ethereum blockchains. Further evaluation has confirmed the system's efficiency in terms of performance.
Yonghua Zhan, Yang Yang 0026, Hongju Cheng, Xiangyang Luo 0001, Zhangshuang Guan, Robert H. Deng
IEEE Trans. Serv. Comput.5
2022 BlockMaze: An Efficient Privacy-Preserving Account-Model Blockchain Based on zk-SNARKs
abstract
The disruptive blockchain technology is expected to have broad applications in many areas due to its advantages of transparency, fault tolerance, and decentralization, but the open nature of blockchain also introduces severe privacy issues. Since anyone can deduce private information about relevant accounts, different privacy-preserving techniques have been proposed for cryptocurrencies under the UTXO model, e.g., Zerocash and Monero. However, it is more challenging to protect privacy for account-model blockchains (e.g., Ethereum) since it is much easier to link accounts in the account-model blockchain. In this article, we proposeBlockMaze, an efficient privacy-preserving account-model blockchain based on zk-SNARKs. Along with dual-balance model, BlockMaze achieves strong privacy guarantees by hiding account balances, transaction amounts, and linkage between senders and recipients. Moreover, we provide formal security definitions and prove the security ofBlockMaze. Finally, we implement a prototype ofBlockMazebased on Libsnark and Go-Ethereum, and conduct extensive experiments to evaluate its performance. Our 300-node experiment results show that BlockMaze has high efficiency in computation and transaction throughput: one transaction verification takes about 14.2 ms, one transaction generation takes 6.1-18.6 seconds, and its throughput is around 20 TPS.
Zhangshuang Guan, Zhiguo Wan, Yang Yang 0026, Butian Huang
IEEE Trans. Dependable Secur. Comput.1
2021 Scalable Decentralized Privacy-Preserving Usage-Based Insurance for Vehicles
abstract
Compared with traditional insurance schemes, usage-based insurance (UBI) for vehicles is more economic and accurate for drivers since its insurance premium calculation depends on how vehicles are driven. However, UBI requires sensitive driving data to determine insurance premiums, and this could result in serious privacy breach for drivers. Meanwhile, existing UBI solutions rely on a centralized entity (i.e., the insurance company) to manage insurances. In this article, we design a decentralized and privacy-preserving UBI scheme, called DUBI, based on the blockchain technology and zero-knowledge proof. In our scheme, a smart contract running over the blockchain serves as a “decentralized” insurance company, while drivers continuously upload their committed driving data to the blockchain. Periodically, the driver submits accumulated driving statistics with a zero-knowledge proof to the smart contract, which verifies the proof and calculates the insurance premium from the submitted statistics. We formulate an ideal functionality for DUBI under the universal composability framework, and then provide a formal security proof for DUBI. Furthermore, we give in-depth analysis and performance evaluation for DUBI with an implementation based on Ethereum. It shows that DUBI is highly efficient in processing UBI insurances in both storage and computation: DUBI is about seven times more efficient than existing schemes in storage, and proof generation and verification take only 7 and 30 ms, respectively.
Huayi Qi, Zhiguo Wan, Zhangshuang Guan, Xiuzhen Cheng
IEEE Internet Things J.3
2021 PriScore: Blockchain-Based Self-Tallying Election System Supporting Score Voting
abstract
Election and voting play crucial roles in democratic society for an elactorate to make a collective decision. E-voting is one of the most challenging problems in cryptographic research to provide multiple dimensions security assurances. In this paper, we study an important voting paradigm, score voting, with privacy protection, which has not been investigated in previous work. We propose a blockchain based self-tallying election system to support score voting, dubbed “PriScore”, where the ballots are recorded on blockchain to prevent vote forgery or tampering. PriScore makes it possible for each voter to assign different evaluation scores (within a certain range) for the candidates as ranked-choice, where the sum of the scores in each ballot should be a predefined constant, and the evaluation scores are encrypted to maintain confidentiality. A major challenge in score voting is to simultaneously prove two constraint conditions: range proof and sum proof. We introduce a new technique, called dual zero-knowledge proof (dual-ZKP), to prove the scores satisfying two crucial requirements, which integrates “1-out-of-$K$” proof and distributed ElGamal crypto in a non-trivial way. The self-tallying mechanism in PriScore enables any party in the system to calculate and verify the election result, which provides fairness, dispute-freeness. The security analysis demonstrates that PriScore achieves completeness, soundness, eligibility, universal/individual verifiability and multiple-voting detection. We evaluate the performance of PriScore on modern workbench to test the performance, and also on a blockchain platform to measure the resource consumption. The experiments show that PriScore preserves privacy of score voting with reasonable overheads.
Yang Yang 0026, Zhangshuang Guan, Zhiguo Wan, Jian Weng 0001, HweeHwa Pang, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.2
2017 BKI: Towards Accountable and Decentralized Public-Key Infrastructure with Blockchain
Zhiguo Wan, Zhangshuang Guan, Feng Zhuo, Hequn Xian
SecureComm2