VLDB 2026 Research / reviewers in the wild / expert
Axin Wu
dblp:221/2628
· DBLP profile ↗
19ranked-venue papers
9as first author
18since 2021 · last 2026
0000-0003-4422-1270ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 2 first-author · 7 since 2021Systems, architecture and hardware · 6 · 5 first-author · 6 since 2021Computer networks · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LFRkNN: Towards Leakage-Free Reverse K-Nearest Neighbor Queries on Encrypted Data
Tianqi Sun, Jialin Chi, Min Zhang 0043, Axin Wu, Dengguo Feng |
DASFAA (5) | 4 |
| 2026 | Bilateral-verifiable and robust secure aggregation via TEE for asynchronous federated learning
Wei Liu 0149, Yinghui Zhang 0002, Axin Wu, Jin Cao 0001, Yunling Wang, Yangguang Tian |
J. Inf. Secur. Appl. | 3 |
| 2026 | Anonymous and Byzantine-Robust Federated Learning With Secure and Efficient AggregationabstractFederated learning (FL) serves as a distributed machine learning framework that addresses the challenges of data silos while preserving data privacy. Specifically, FL enables multiple participants to collaboratively train a global model by sharing local updates without exposing their raw local data. Although FL achieves physical data isolation through local update sharing mechanisms, it still faces emerging security threats. On the one hand, adversaries may reconstruct sensitive data features or infer client attributes by analyzing local updates. On the other hand, clients might upload malicious updates to disrupt global model aggregation, causing performance degradation. To solve these issues, we propose an anonymous and Byzantine-robust FL scheme with secure and efficient aggregation. First, we propose a single-masking protocol that not only preserves data privacy but also enhances aggregation efficiency. Second, we eliminate client message metadata, such as source IP addresses and timestamps, through secure shuffling, achieving client anonymity in conjunction with the single-masking protocol. Additionally, we implement a baffle mechanism to resist the impact of malicious updates on the global model, thereby ensuring Byzantine robustness. Security analysis demonstrates that our scheme simultaneously preserves data privacy and identity anonymity. Experimental results show that our scheme can effectively resist poisoning attacks, even if 50% of the fog nodes are contaminated by malicious clients. Moreover, the aggregation efficiency of the proposed scheme is improved by over 20%. Wei Liu 0149, Yinghui Zhang 0002, Axin Wu, Jin Cao 0001, Yangguang Tian |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Privacy-Preserving Proxy Bilateral Access Control for Secure Data ForwardingabstractSecure data forwarding involves converting decrypted ciphertext, initially readable by one user, into a format that can be deciphered by another user. Proxy re-encryption is a commonly employed technique for secure data forwarding. However, this technique faces two inherent limitations. Firstly, only the data owner possesses the ability to control which data users can decrypt the ciphertext, resulting in receivers receiving irrelevant or uninterested information. Secondly, when data is forwarded through multiple nodes, it becomes vulnerable to various attacks such as impersonation and forgery. A solution called bilateral access control addresses these issues by letting the sender and receiver specify access control policies that the other party should comply with and ensure message confidentiality and authenticity. Nevertheless, to the best of our knowledge, there is currently no existing bilateral access control scheme capable of achieving secure data forwarding. In response to this issue, we propose a privacy-preserving proxy bilateral access control scheme, which simultaneously achieves all the above functionalities. Subsequently, we prove the message confidentiality and authenticity under the standard assumptions in the random oracle model. Finally, extensive theoretical analysis and performance evaluation demonstrate that the scheme provides unique features and comparable performance. Axin Wu, Dengguo Feng, Min Zhang 0043, Haining Yang, Jialin Chi |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Privacy-Preserving k-Nearest Neighbor Query: Faster and More Secure
Jialin Chi, Cheng Hong 0001, Axin Wu, Tianqi Sun, ZheChen Li, Min Zhang 0043, Dengguo Feng |
ESORICS (4) | 3 |
| 2025 | Non-interactive set intersection for privacy-preserving contact tracing
Axin Wu, Yuer Yang, Jinghang Wen, Yu Zhang 0201, Qiuxia Zhao |
J. Syst. Archit. | 1 |
| 2025 | EASNs: Efficient Anonymous Social Networks With Enhanced Security and High ScalabilityabstractPrivacy concerns have been persistently afflicting individuals within online social networks (OSNs), rendering privacy-preserving communications over the Internet with authentication especially important. Unfortunately, the guarantees of privacy and authenticity are not always provided in OSNs. Individuals are still facing the challenges of being deceived or exploited. To mitigate these issues, anonymous social networks (ASNs) have emerged as a remedy for OSNs, facilitating individuals to connect with others anonymously and authentically. Despite the existence of numerous and remarkable cryptographic primitives, there are no formal solutions for ASNs except for matchmaking encryption (ME), since ME can simultaneously provide various key functionalities, i.e. bilateral access control, identity anonymity, and message authentication, to address the requirements of ASNs. In this paper, we design a system for ASNs by adopting fuzzy identity-based matchmaking encryption (fuzzy IB-ME), and the proposed scheme in this work is highly efficient. The scheme also realizes adaptive security in generic group model (GGM), which is generally adopted in pairing-based cryptography. The proposed ASNs system offers various advantages compared to the previous solutions, including 1) bilateral access control, 2) enhanced security, 3) high scalability, and 4) high efficiency. In addition to theoretical evaluations, we conduct extensive experiments to evaluate our scheme’s computational and storage efficiency. These evaluations indicate that our solution outperforms previous solutions and as well as preserves many desired functionalities. Wenfeng Huang, Axin Wu, Shengmin Xu, Guowen Xu, Wei Wu 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Efficient public-key searchable encryption against inside keyword guessing attacks for cloud storage
Axin Wu, Fagen Li, Xiangjun Xin 0002, Yinghui Zhang 0002, Jianhao Zhu |
J. Syst. Archit. | 1 |
| 2024 | Flexible symmetric predicate encryption for data privacy in IoT environments
Qingquan Bian, Axin Wu |
Peer Peer Netw. Appl. | 4 |
| 2024 | Efficient Verifiable Cloud-Assisted PSI Cardinality for Privacy-Preserving Contact TracingabstractPrivate set intersection cardinality (PSI-CA) allows two parties to learn the size of the intersection between two private sets without revealing other additional information, which is a promising technique to solve privacy concerns in contact tracing. Efficient PSI protocols typically use oblivious transfer, involving multiple rounds of interaction and leading to heavy local computation overheads and protocol delays, especially when interacting with many receivers. Cloud-assisted PSI-CA is a better solution as it relieves participants' burdens of computation and communication. However, cloud servers may return incorrect or incomplete results for some reason, leading to an incorrectness issue. At present, to our knowledge, existing cloud-assisted PSI-CA protocols cannot address such a concern. To address this, we propose two specific verifiable cloud-assisted PSI-CA protocols: one based on a two-server protocol and the other on a single-server protocol. Further, we employ Cuckoo hashing to optimize these two protocols, enabling the receiver's computational costs independent of the size of the sender's set. We also prove the security of the protocols and implement them. Finally, we analyze and discuss their performance demonstrating that the single-server verifiable PSI-CA protocol does not introduce significant computation or communication costs while adding functionalities. Yafeng Chen, Axin Wu, Yuer Yang, Xiangjun Xin 0002 |
IEEE Trans. Cloud Comput. | 2 |
| 2024 | Cloud-Assisted Laconic Private Set Intersection CardinalityabstractLaconic Private Set Intersection (LPSI) is a type of PSI protocols characterized by the requirement of only two-round interactions and by having a reused message in the first round that is independent of the set size. Recently, Aranha et al. (CCS'2022) proposed a LPSI protocol that utilizes the pairing-based accumulator. However, this protocol heavily relies on time-consuming bilinear pairing operations, which can potentially cause a bottleneck. Furthermore, in certain scenarios like contact tracing, it is sufficient to only reveal the intersection cardinality. To tackle this problem and expand on its functionalities, we introduce a cloud-assisted two-party LPSI cardinality (TLPSI-CA) that inherits the properties of LPSI. Interestingly, the cloud-assisted TLPSI-CA eliminates the direct interaction between the sender and receiver, enabling the sender's message to be reused across any number of protocol executions. Besides, we further extend it to the multi-party scenario, which also possesses laconic properties. Then, we prove the two protocols' security in achieving the defined ideal functionalities. Finally, we evaluate the performance of both protocols and find that TLPSI-CA successfully reduces the local computation costs for participants. Additionally, the multi-party protocol performs similarly to TLPSI-CA, with the exception of the higher communication costs incurred by the receiver. Axin Wu, Xiangjun Xin 0002, Jianhao Zhu, Wei Liu 0149, Guoteng Li |
IEEE Trans. Cloud Comput. | 1 |
| 2024 | Hierarchal Bilateral Access Control With Constant Size Ciphertexts for Mobile Cloud ComputingabstractMobile cloud computing (MCC) integrates the advantages of mobile networks and cloud computing, enabling users to enjoy personalized services without constraints and restrictions of time and place. While this brings convenience, it also comes with risks such as privacy breaches and unauthorized access to outsourced data. Bilateral access control is a promising technique for addressing these issues. However, the current bilateral access control schemes cannot solve problems such as single point failure. To further enhance and enrich the existing schemes, we propose hierarchical bilateral access control. In the proposed scheme, the permission of generating encryption keys and decryption keys can be delegated to its child nodes, which alleviates the computation and communication overheads of the parent nodes and weaken the potential risks of single-point failure. Additionally, the ciphertext size remains constant, reducing the costs of transmitting and storing ciphertext and relieving resource limitations on devices. We then prove the privacy and authenticity of the scheme in the random oracle model. Finally, the comprehensive performance comparison and analysis demonstrate the efficiency of the proposed scheme. Axin Wu, Yinghui Zhang 0002, Jianhao Zhu, Qiuxia Zhao, Yu Zhang 0201 |
IEEE Trans. Cloud Comput. | 1 |
| 2024 | Privacy-Preserving Bilateral Multi-Receiver Matching With Revocability for Mobile Social NetworksabstractMobile social networks (MSNs) offer convenient and ubiquitous services to expand social circles, share information, etc. These services require strict security measures to prevent the spread of deceptive content, misleading information, and malicious behavior. Achieving bilateral access control, message confidentiality and authenticity, and identity privacy can establish a positive network environment. Identity-based matchmaking encryption (IB-ME) with all the above features is a promising cryptographic primitive for MSNs. However, IB-ME can only specify one receiver. To share data with multiple users, the sender needs to encrypt the same message many times, resulting in higher frequencies of communication. Moreover, in multi-receiver scenarios, revocation of decryption permission may be necessary due to the possibility of malicious behavior, organization changes, or discontinuing subscription services. To our knowledge, no cryptographic primitives have been developed that satisfy these requirements. To address these challenges, we introduce the concept of revocable multi-receiver IB-ME and formalize its syntax and security definitions. We propose a revocable multi-receiver IB-ME scheme that provides privacy and authenticity in the random oracle model. Our evaluation demonstrates that it is efficient, and the sizes of system parameters and secret keys are independent of the number of receivers and revoked receivers. Axin Wu, Dengguo Feng, Min Zhang 0043, Anjia Yang, Jialin Chi |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | Efficient Bilateral Privacy-Preserving Data Collection for Mobile CrowdsensingabstractMobile crowdsensing (MCS) utilizes ubiquitous mobile devices to collect massive amounts of data and offer various high-quality services. During the data collection and upload process, bilateral access control is implemented to recruit qualified data providers and prevent unauthorized access to collected data. However, the efficiency of existing bilateral access control schemes applicable in the data collection phase is dissatisfactory, as their ciphertext sizes are linear with the number of attributes. Additionally, data confidentiality and authenticity, as well as lightweight encryption and decryption processes, are crucial for the deployment of MCS since the former eliminate the risks of data abuse and false data injection, and the latter are typically limited in their computation and communication resources. To reduce the resource consumption of these devices, we present EBAC-CC, an efficient bilateral access control with constant-size ciphertexts that ensures data confidentiality and authenticity and allows for flexible threshold bilateral access control. Besides, offline/online techniques and outsourced decryption are employed to quickly generate ciphertexts and recover perceptual data, which also alleviates their computation burdens. We also prove its privacy and authenticity in the standard model and evaluate its efficacy theoretically and experimentally, demonstrating its superiority over other bilateral access control schemes. Axin Wu, Weiqi Luo 0002, Anjia Yang, Yinghui Zhang 0002, Jianhao Zhu |
IEEE Trans. Serv. Comput. | 1 |
| 2023 | Enabling Traceable and Verifiable Multi-User Forward Secure Searchable Encryption in Hybrid CloudabstractForward secure searchable encryption (FSSE) scheme allows one data user to search on encrypted databases while resisting the file injection attack. The data utilization can be further improved by extending the single-user scenario to the multi-user scenario. However, there are some issues needed to be considered when a data owner shares data with multiple data users. First, the public cloud server can not be completely trusted as it may be dishonest returning incorrect or incomplete results. Second, authorized users may trade their private keys for financial benefit. To our knowledge, state-of-the-art searchable encryption schemes only consider part of the following desirable features: the verifiability of results, the resistance to file injection attacks, the traceability and revocation of malicious users who abuse their private keys in the multi-user setting. Based on these motivations, we first propose enabling traceable and verifiable multi-user FSSE, which achieves the above functionalities. Besides, we carry out the security proof which demonstrates that our scheme can meet the requirements of security. We also assess the performance from theoretical analysis and experimental analysis, which shows that compared with other similar schemes, our scheme has richer functionalities with comparable efficiency. Axin Wu, Anjia Yang, Weiqi Luo 0002, Jinghang Wen |
IEEE Trans. Cloud Comput. | 1 |
| 2023 | Fuzzy Identity-Based Matchmaking Encryption and Its ApplicationabstractAteniese et al. introduced the primitive of matchmaking encryption (ME) at CRYPTO 2019 and left open several important questions, which include extending ME to fuzzy cases or giving an efficient ME in the identity-based setting without relying on random oracles. The main challenge is to achieve fuzzy bilateral access control while providing identity privacy of the sender and receiver, message confidentiality and authenticity without random oracles. In this work, we resolve the question by formalizing the first fuzzy identity-based ME (IB-ME) and presenting a concrete construction. Specifically, we propose the formal syntax definition of fuzzy IB-ME. In fuzzy IB-ME, the identities of senders and receivers are characterized by attribute sets. A ciphertext can be correctly decrypted if the overlaps between the attribute set of the sender or receiver and the attribute set specified by the other party are simultaneously greater than a threshold, which can be applied to many attractive applications such as fuzzy bilateral access control in online social dating. Then, we present concrete details of fuzzy IB-ME based on fuzzy identity-based encryption, which does not rely on other cryptographic tools such as two-input functional encryption and non-interactive zero-knowledge proof systems. In this process, fuzzy bilateral access control and identity privacy are achieved through the formalism of arranged ME and the splitting technique while message authenticity is provided through the authentication and binding of the encryption key. The identity privacy of the sender and receiver, confidentiality, and authenticity of messages are reduced to the decisional bilinear Diffie-Hellman, decision linear, and computational bilinear Diffie-Hellman assumptions in the selective model without random oracles. Finally, we implement the scheme and evaluate its performance through theoretical analyses and experiments to demonstrate its efficiency. Axin Wu, Weiqi Luo 0002, Jian Weng 0001, Anjia Yang, Jinghang Wen |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2021 | Flexible and anonymous network slicing selection for C-RAN enabled 5G service authentication
Yinghui Zhang 0002, Axin Wu, Dong Zheng 0001, Jin Cao 0001, Xiaohong Jiang 0001 |
Comput. Commun. | 2 |
| 2021 | Blockchain-Enabled Public Key Encryption with Multi-Keyword Search in Cloud ComputingabstractThe emergence of the cloud storage has brought great convenience to people’s life. Many individuals and enterprises have delivered a large amount of data to the third-party server for storage. Thus, the privacy protection of data retrieved by the user needs to be guaranteed. Searchable encryption technology for the cloud environment is adopted to ensure that the user information is secure with retrieving data. However, most schemes only support single-keyword search and do not support file updates, which limit the flexibility of the scheme. To eliminate these problems, we propose a blockchain-enabled public key encryption scheme with multi-keyword search (BPKEMS), and our scheme supports file updates. In addition, smart contract is used to ensure the fairness of transactions between data owner and user without introducing a third party. At the data storage stage, our scheme realizes the verifiability by numbering the files, which ensures that the ciphertext received by the user is complete. In terms of security and performance, our scheme is secure against inside keyword guessing attacks (KGAs) and has better computation overhead than other related schemes. Axin Wu, Qixuan Xing, Shengling Geng |
Secur. Commun. Networks | 2 |
| 2018 | Efficient and secure big data storage system with leakage resilience in cloud computing
Yinghui Zhang 0002, Menglei Yang, Dong Zheng 0001, Pengzhen Lang, Axin Wu |
Soft Comput. | 5 |