VLDB 2026 Research / reviewers in the wild / expert
Xiaohan Hao
dblp:236/6570
· DBLP profile ↗
12ranked-venue papers
7as first author
11since 2021 · last 2026
0000-0002-4770-7084ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Mitigating Delivery Fraud and Path Manipulation in UAV-Based E-Commerce: A Fair Exchange ProtocolabstractUAV-based e-commerce, which employs unmanned aerial vehicles (UAV) to deliver commodities from sellers to buyers, plays a central role in the low-altitude economy. In the interests of both buyers and sellers, UAV-based e-commerce usually relies on afair exchangeprotocol between them. Despite extensive research on fair exchange protocol design, UAV-based e-commerce has two features posing extra challenges to achieving mutual fairness:delivery fraudandpath manipulation. On one hand, the UAVs usually deliver real-world commodities rather than virtual assets (e.g., digital books), making it hard to verify the physical delivery status. Particularly, this verification can be easily done for virtual assets by checking their hash values, but inapplicable to real-world commodities, as they cannot be naturally hashed. On the other hand, since UAV costs may vary in different air areas, the seller may manipulate delivery bills by claiming unnecessarily expensive paths. These challenges are newly emerged in UAV-based e-commerce and have not been considered in traditional protocols. The primary goal of this work is to propose thefirstfair exchange protocol that achieving mutual fairness in UAV-based e-commerce. To verify commodity delivery, we develop atracingmechanism that transforms raw UAV-collected footage into immutable delivery evidence, which can be integrated into existing virtuality-oriented protocols for further verification. As for the path manipulation problem, we introduce anauditingmechanism that enables buyers to verify that the chosen delivery path was generated by a trustworthy algorithm (e.g., a well-trained artificial general intelligence model). By establishing these two mechanisms on cryptographic tools, we theoretically prove the fairness of our proposed protocol. We also implement a prototype and observe that the whole protocol has only minute-magnitude cost across different settings, which validates its practicality. Xiaohan Hao, Tianrui Song, Chao Lin 0003, Xinyi Huang 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Weakly-supervised Learning Based Spine Instance Segmentation for MRI PlanningabstractMagnetic Resonance Imaging (MRI) spine planning involves setting several positioning lines, termed localizer, through the intervertebral discs (IVDs) of interest to enable axial scans. Deep learning models that generate IVD masks facilitate the automation of MRI spine planning workflow. However, training an automatic IVD segmentation model typically requires extensive data across multiple spine regions and labor-intensive annotation of segmentation masks. To reduce the annotation burden, we propose a novel weakly supervised learning based two-stage training strategy for IVD instance segmentation models. During the first supervised learning stage, the model is trained on a public dataset with segmentation annotations. During the second weakly supervised stage, the pre-trained model is fine-tuned on a local spine dataset annotated only with localizers. To achieve the weakly supervised learning, a distance map generated by localizer is leveraged to refine the predicted mask’s principal axis, enabling the model to adapt to the data distribution of the local dataset. We conducted experiments by combining our strategy with several popular models on lumbar, cervical, and thoracic spine datasets. To quantify the performance of localizer predictions, we designed evaluation metrics based on angular deviation, centroid accuracy, and Hausdorff distance. Results demonstrate that the successful integration of the proposed strategy with various baseline instance segmentation models, resulting in notable improvements in performance across images with different signal-to-noise ratios and anatomical regions. In conclusion, the proposed weakly supervised method enhances generalizability across diverse scenarios and holds promise for improving the clinical adoption of automatic spine planning in MRI examinations. Xiaohan Hao, Mengdie Song, Bensheng Qiu |
ICASSP | 2 |
| 2025 | MDPG: Multi-domain Diffusion Prior Guidance for MRI Reconstruction
Lingtong Zhang, Mengdie Song, Xiaohan Hao, Huayu Mai, Bensheng Qiu |
MICCAI (2) | 3 |
| 2025 | GAMC: Generic and Anti-MDA Model Certification for Intellectual Property Protection in MLaaSabstractWhile machine learning as a service (MLaaS) enables users to leverage powerful pre-trained models at low cost, it also poses significant intellectual property risks for model builders. A widely adopted defense mechanism is to embed ownership credentials (e.g., watermarking information) into the model, allowing the verifier to examine them during ownership verification. Despite the effectiveness of such watermark-based schemes, we identify a critical vulnerability, termed the model defamation attack (MDA). If an adversary compromises a verifier and obtains the submitted credential, it can reuse this stolen information by embedding it into a malicious modelEˆ and falsely attribute its ownership to the original model builder, thereby damaging their reputation. This paper presents a generic anti-MDA model certification (GAMC) framework that can be seamlessly integrated with existing watermarking schemes to enhance their robustness. We identify two design goals: (1) credential confidentiality, which prevents sensitive watermark-related information from being leaked during verification; and (2) credential non-reusability, which prevents the reuse of any previously submitted credentials. To this end, we employ a cryptographic accumulator to construct the model certification mechanism and design a customized ΣOR protocol as a complement. We formally prove the security of our anti-MDA framework and conduct extensive experiments across various watermarking schemes and neural network architectures to evaluate its compatibility and effectiveness. The experimental results show that GAMC improves robustness against model defamation attacks by 86.67% with negligible overhead, demonstrating its practicality for real-world deployment Xiaohan Hao, Chao Lin 0003, Xinyi Huang 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | TMAS: A transaction misbehavior analysis scheme for blockchainabstractThe emergence of blockchain-based cryptocurrencies, such as Bitcoins, has presented a promising alternative for e-payment methods, owing to their unique features of decentralization and anonymity. The usage of these currencies has grown exponentially, particularly in anonymous e-payment and without any trusted third party. However, the decentralized and anonymous nature of these currencies has also resulted in misbehaviors, e.g., money laundering. Therefore, detecting transaction misbehaviors has garnered increasing attention. In this paper, we propose TMAS, a transaction misbehavior analysis scheme for blockchain-based cryptocurrencies. We propose various transaction analysis approaches, feature extraction algorithms, and detection models for misbehaviors, including money laundering. We have implemented a real experimental system to detect misbehaviors, including money laundering, in blockchain-based cryptocurrencies such as Bitcoins. The proposed system includes ten features in the transaction graph, two heuristic money laundering models, and an analysis method for account linkage, which identifies accounts that are distinct but controlled by an identical entity. To verify the effectiveness of our proposed indicators and models, we have analyzed a sample of 100M transactions and computed transaction features, leading to the identification of some suspicious accounts. Moreover, the proposed methods can be applied to other cryptocurrencies, no matter token-based such as Bitcoins or account-based such as Ethereum. Shiyong Huang, Xiaohan Hao, Yani Sun, Chenhuang Wu, Wei Ren 0002, Kim-Kwang Raymond Choo |
Blockchain Res. Appl. | 2 |
| 2024 | Robust and Secure Federated Learning Against Hybrid Attacks: A Generic ArchitectureabstractFederated Learning (FL) enables multiple clients to collaboratively train a model without sharing their private data. However, the deployment of FL in real-world applications is vulnerable to various attacks from both malicious servers and clients. While cryptographic methods are effective in resisting server-side attacks, they undermine the capability of client-side defenses that rely on plaintext updates. Several valuable defenses targeting hybrid attacks have been devised to address this challenge, concentrating on specific client-side threats. To improve scalability, we continue this research line to introduce a generic architecture covering more client-side attacks. In this paper, we propose a general architecture to enhance client-side defenses from plaintext to ciphertext domains. This architecture not only supports the server-side defenses, but also accommodates a broader range of client-side defenses, including Norm-based, Krum-based, and Cosine-based strategies. The core of our architecture is generic detection under ciphertext, which tackles the following conflict of integrating server-side and client-side defenses. That is, the former aims to protect parameters from exposure while the latter demands plaintext updates. We prove the security of our architecture through the Universal Composability framework. Additionally, we provide a comprehensive instantiation and extensive evaluations to demonstrate the effectiveness and robustness of our approach. Our experiments show that our architecture can maintain the effectiveness of current client-side defenses when parameters are encrypted, thus effectively resisting hybrid attacks. Xiaohan Hao, Chao Lin 0003, Wenhan Dong, Xinyi Huang 0001, Hui Xiong 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | BDIM: A Blockchain-Based Decentralized Identity Management Scheme for Large Scale Internet of ThingsabstractIn large-scale Internet of Things (IoT) systems, centralized authentication can be challenging, for example in terms of identity management, authentication overhead, and single point of failure. Distributed identity management has been envisioned as a promising approach for mitigating above all, but the security and performance of the overall solution have not been extensively evaluated. In this article, we proposed a decentralized identity management scheme based on blockchain for tackling large-scale IoT such as VANET. We implement smart contracts to support large-scale user access control, together with design trust management methods for reputation evaluation and credit penalty mechanisms, which can prevent various types of attacks in distributed identification contexts. The experiment results and analysis justified that our scheme is scalable with good performance. Specifically, the system response is on a millisecond scale and all the functions consume within 250 ms. Also, the time consumption of the query maintains a manageable delay within 0.5 ms no matter the remarkable growth of users. Finally, we observe that the throughput of the current blockchain platform could meet the requirement of our scheme with the increasing number of users’ upload request in real-world simulation. Ruoting Xiong, Wei Ren 0002, Xiaohan Hao, Kim-Kwang Raymond Choo |
IEEE Internet Things J. | 3 |
| 2023 | A Blockchain-Based Decentralized, Fair and Authenticated Information Sharing Scheme in Zero Trust Internet-of-ThingsabstractInternet-of-Things (IoT) are increasingly operating in the zero-trust environments where any devices and systems may be compromised and hence untrusted. In addition, data collected by and sent from IoT devices may be shared with and processed by edge computing systems, in order to reduce the reliance on centralized (cloud) servers, leading to further security and privacy issues. To cope with these challenges, this paper proposes an innovative blockchain-enabled information sharing solution in zero-trust context to guarantee anonymity yet entity authentication, data privacy yet data trustworthiness, and participant stimulation yet fairness. This new solution is able to support filtering of fabricated information through smart contracts, effective voting, and consensus mechanisms, which can prevent unauthenticated participants from sharing garbage information. We also prove that the proposed solution is secure in the universal composability framework, and further evaluate its performance over an Ethereum-based blockchain platform to demonstrate its utility. Xiaohan Hao, Wei Ren 0002, Ruoting Xiong, Tianqing Zhu, Kim-Kwang Raymond Choo, Geyong Min |
IEEE Trans. Computers | 2 |
| 2023 | A Blockchain-Based Cross-Domain and Autonomous Access Control Scheme for Internet of ThingsabstractThe volume, variety and value of data generated by Internet of Things (IoT) devices are expected to increase significantly in foreseeable future, hence, reinforcing the importance of secure and efficient access control solutions for these devices and their networks. However, existing access control solutions are not generally lightweight or scalable, particularly for geographically disperse, inexpensive resource constrained IoT devices. To tackle above challenges, we propose a lightweight consortium blockchain based architecture to enable intelligent autonomous access control for IoT devices. In our architecture, intelligent blockchain facilitates the storing of access policies, provision of authentication services for data access control, and trust evaluation for access request nodes through token accumulation mechanism. Specifically, the user's access request is approved only after it is confirmed by the blockchain network. To ensure the reliability of authenticity, a compromised resistant consensus algorithm is adapted and implemented to defend against at most$1/3$compromised authenticators. In addition, a cross-domain and flexible access control model is not only used to support data sharing among various users but can also be used for access control for exceptional blockchain situations. We explain how our system meets our design goals of reliability, availability, confidentiality, integrity, lightweight, security and scalability. In addition, we also analyze the proposed system's performance from computational, storage and network overheads (e.g., running cryptographic algorithms on a Raspberry Pi 4B), and the findings suggest that the time to run typical cryptographic algorithms is in the microsecond range. Xiaohan Hao, Wei Ren 0002, Yangyang Fei, Tianqing Zhu, Kim-Kwang Raymond Choo |
IEEE Trans. Serv. Comput. | 1 |
| 2022 | A Self-Trading and Authenticated Roaming Scheme Based on Blockchain for Smart GridsabstractThe increasing volume of user and household data and number of smart meters compound the challenge of ensuring efficiency and privacy protection of electricity trading in existing smart grids. Therefore, to minimize the cost and latency in electricity trading, in this article, we design a new architecture for smart meters that can support transactions (using a blockchain-based wallet) and initiate transmission switch instructions (using smart contacts). Specifically, our approach comprises a decentralized peer-to-peer electricity trading scheme to enable automated electricity transmission (using smart contract instead of some centralized entity), and our blockchain-based anonymous authentication scheme to facilitate fast and privacy-aware roaming, in order to achieve privacy protection. We demonstrate that our proposed scheme is secure under the universally composable framework. Xiaohan Hao, Wei Ren 0002, Kim-Kwang Raymond Choo, Naixue Xiong |
IEEE Trans. Ind. Informatics | 1 |
| 2021 | Asymmetric cryptographic functions based on generative adversarial neural networks for Internet of Things
Xiaohan Hao, Wei Ren 0002, Ruoting Xiong, Tianqing Zhu, Kim-Kwang Raymond Choo |
Future Gener. Comput. Syst. | 1 |
| 2020 | SCScan: A SVM-based Scanning System for Vulnerabilities in Blockchain Smart ContractsabstractThe application of blockchain has moved beyond cryptocurrencies, to applications such as credentialing and smart contracts. The smart contract allows ones to achieve fair exchange for values without relying on a centralized entity. However, as the smart contract can be automatically executed with token transfers, an attacker can seek to exploit vulnerabilities in smart contracts for illicit profits. Thus, this paper proposes a support vector machine (SVM)-based scanning system for vulnerabilities on smart contracts. Our evaluation on Ethereum demonstrate that we achieve a identification rate of over 90% based on several popular attacks. Xiaohan Hao, Wei Ren 0002, Wenwen Zheng, Tianqing Zhu |
TrustCom | 1 |