VLDB 2026 Research / reviewers in the wild / expert
Ying Li 0051
dblp:22/1805-51
· DBLP profile ↗
8ranked-venue papers
3as first author
8since 2021 · last 2025
0000-0002-3296-5005ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 3 · 2 first-author · 3 since 2021Security and privacy · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Dominate data by yourself: a decentralized scheme for data interoperation when data is decoupled from applications
Jiuqi Wei, Xiaodong Lee, Yufan Fu, Ying Li 0051, Botao Peng |
World Wide Web (WWW) | 4 |
| 2024 | Securing the internet's backbone: A blockchain-based and incentive-driven architecture for DNS cache poisoning defenseabstractDomain Name System (DNS) is the backbone of the Internet infrastructure, converting human-friendly domain names into machine-processable IP addresses. However, DNS remains vulnerable to various security threats, such as cache poisoning attacks , where malicious attackers inject false information into DNS resolvers’ caches. Although efforts have been made to enhance DNS against such vulnerabilities, existing countermeasures often fall short in one or more areas: they may offer limited resistance to the collusion attack, introduce significant overhead, or require complex implementation that hinders widespread adoption. To address these challenges, this paper introduces TI-DNS+, a trusted and incentivized blockchain-based DNS resolution architecture for cache poisoning defense. TI-DNS+ introduces a Verification Cache exploiting blockchain ledger’s immutable nature to detect and correct forged DNS responses . The architecture also incorporates a multi-resolver Query Vote mechanism, enhancing the ledger’s credibility by validating each record modification through a stake-weighted algorithm. This algorithm selects resolvers as validators based on their stake proportion. To promote well-behaved participation, TI-DNS+ also implements a novel stake-based incentive mechanism that optimizes the generation and distribution of stake rewards. This ensures that incentives align with participants’ contributions, achieving incentive compatibility, fairness, and efficiency. Moreover, TI-DNS+ possesses high practicability as it requires only resolver-side modifications to current DNS. Finally, through comprehensive prototyping and experimental evaluations, the results demonstrate that our solution effectively mitigates DNS cache poisoning. Compared to competitors, our solution improves attack resistance by 1-3 orders of magnitude, while also reducing resolution latency by 5% to 68%. Yufan Fu, Xiaodong Lee, Jiuqi Wei, Ying Li 0051, Botao Peng |
Comput. Networks | 4 |
| 2024 | DiSAuth: A DNS-based secure authorization framework for protecting data decoupled from applications
Ying Li 0051, Jiuqi Wei, Ziyu Fei, Yufan Fu, Xiaodong Lee |
Comput. Networks | 1 |
| 2024 | Streaming Data Collection With a Private Sketch-Based ProtocolabstractData stream collection is critical to analyze service conditions and detect anomalies in time, especially in Internet of Things. However, it may undermine the individual privacy. Local differential privacy (LDP) has recently become a popular privacy-preserving technique protecting users’ privacy. However, most of them are still limited to the assumption of one-item collection, resulting in poor utility when extended to the multi-item collection from a very large domain. This article proposes a private streaming data collection framework, private sketch-based framework (PSF), which takes advantage of sketches. Combining the proposed background information and a decode-first collection-side workflow, the framework improves the utility by reducing the errors introduced by the sketching algorithm and the privacy budget utilization when collecting multiple items. We analytically prove the superior accuracy and privacy characteristics of PSF. In order to support specific computing tasks, we build two private protocols based on PSF, PrivSketch and PrivSketch+, aiming at frequency estimation and mean estimation, respectively. We demonstrate the utility of PrivSketch and PrivSketch+ theoretically, and also evaluate them experimentally. Our evaluation, with several diverse synthetic and real data sets, demonstrates that PrivSketch is 1–3 orders of magnitude better than the competitors in terms of utility in both frequency estimation and frequent item estimation, while being up to ~100x faster. PrivSketch+ performs ~4 orders of magnitude better than advanced solutions, such as piecewise mechanism (PM) and hybrid mechanism (HM), under a limited privacy budget. Ying Li 0051, Xiaodong Lee, Botao Peng, Themis Palpanas, Jing'an Xue |
IEEE Internet Things J. | 1 |
| 2023 | Data Interoperating Architecture (DIA): Decoupling Data and Applications to Give Back Your Data OwnershipabstractData has become a valuable resource that drives new business models and creates enormous business value. However, under the current data ownership model, many data-driven applications arbitrarily collect and overuse user data for commercial purposes, resulting in increased incidents of data breaches and data misuse. In this paper, we present Data Interoperating Architecture (DIA) that decouples applications and user data to give back data ownership to users. We design Data Interoperating System (DIS) based on blockchain, identity system, and identifier system to solve the key issues of data interoperation: identity management, data identification, data discovery, and data ownership protection. DIS provides services without collecting or accessing data, keeping data under the control of its owner. We formalize the interactions among components in DIA as Data Interoperating Protocol (DIP), which facilitates applications and personal data stores to be compatible with DIS. We develop a prototype of DIS and evaluate the system performance under adopted techniques. Experimental results show that DIS is effective and efficient in supporting real-world data interoperation. Jiuqi Wei, Ying Li 0051, Yufan Fu, Youyi Zhang |
COMPSAC | 2 |
| 2023 | PrivSketch: A Private Sketch-Based Frequency Estimation Protocol for Data Streams
Ying Li 0051, Xiaodong Lee, Botao Peng, Themis Palpanas, Jing'an Xue |
DEXA (1) | 1 |
| 2023 | FlexAuth: A Decentralized Authorization System with Flexible DelegationabstractThe dispersion of resource authorization across various authorization systems raises the complexity and inconsistency of authorization management. Therefore, the pursuit of a unified resource authorization management system is necessary. Most widely used authorization systems are based on centralized services with a single delegation pattern. These authorization systems can be easily compromised, leading to permissions tampering, and are unsuitable for complex usage scenarios. We propose a decentralized authorization system that provides flexible delegation called FlexAuth. We first define a decentralized data storage layer based on blockchain, using smart contracts to implement data writing and resolving, preventing data from being tampered with. On top of this, we implement active and passive delegation patterns of authorization services. We allow users to delegate permissions actively. Also, FlexAuth enables them to respond to authorization requests passively by making flexible and expressive access control policies based on relation-ships and attributes, using the proposed Hybrid Access Control Model (HACM). Furthermore, all delegations in FlexAuth are transitive. Finally, through analysis and experiments, we validate the usability and efficiency of FlexAuth. To our knowledge, FlexAuth is the first decentralized authorization system with transitive delegation in active and passive patterns, achieving flexible delegation. Ziyu Fei, Ying Li 0051, Jiuqi Wei, Yufan Fu, Botao Peng |
TrustCom | 2 |
| 2023 | TI-DNS: A Trusted and Incentive DNS Resolution Architecture based on BlockchainabstractDomain Name System (DNS) is a critical component of the Internet infrastructure, responsible for translating domain names into IP addresses. However, DNS is vulnerable to some malicious attacks, including DNS cache poisoning, which redirects users to malicious websites displaying offensive or illegal content. Existing countermeasures often suffer from at least one of the following weakness: weak attack resistance, high overhead, or complex implementation. To address these challenges, this paper presents TI-DNS, a blockchain-based DNS resolution architecture designed to detect and correct the forged DNS records caused by the cache poisoning attacks in the DNS resolution process. TI-DNS leverages a multi-resolver Query Vote mechanism to ensure the credibility of verified records on the blockchain ledger and a stake-based incentive mechanism to promote well-behaved participation. Importantly, TI-DNS is easy to be adopted as it only requires modifications to the resolver side of current DNS infrastructure. Finally, we develop a prototype and evaluate it against alternative solutions. The result demonstrates that TI-DNS effectively and efficiently solves DNS cache poisoning. Yufan Fu, Jiuqi Wei, Ying Li 0051, Botao Peng |
TrustCom | 3 |