VLDB 2026 Research / reviewers in the wild / expert
Qingxuan Wang
dblp:251/1585
· DBLP profile ↗
9ranked-venue papers
4as first author
9since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021Systems, architecture and hardware · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Universally composable multi-factor authentication scheme for rail control systems
Xiaoya Hu, Zonghua Zhang, Qingxuan Wang |
J. Syst. Archit. | 5 |
| 2026 | Understanding Ephemeral Secret Leakage Attacks in Password-Based Multi-Factor Authentication for Mobile DevicesabstractAs the first defense for system security, multi-factor authentication has been deployed in various security-critical applications with mobile devices (e.g., smart grid, e-health, and Industrial Internet of Things). After three decades of intensive research, the question of how to design a secure multi-factor authentication protocol is still unsettled. In recent years, the ephemeral secret leakage (ESL) attack, originally used to cryptanalyze the authenticated key exchange (AKE) schemes, has been introduced into the field of multi-factor authentication. Considerable efforts have been made to resist the ESL attack, and it has also been listed as one of the common attacks that a secure multi-factor authentication scheme should resist. As one of the capabilities of an ESL attacker, she can obtain the ephemeral secret of public-key techniques adopted by multi-factor authentication schemes. However, public-key techniques have been proven indispensable for password-based protocols to resist offline password guessing attacks. Now a question arises:Is it possible to build a secure password-based multi-factor authentication protocol resistant to ESL attacks and offline password guessing attacks?This paper aims to answer this fundamental question. More specifically, we first revisit more than 100 multi-factor authentication schemes involving ESL attacks and present a comprehensive cryptanalysis of three representative protocols. Then, we reveal the relationship between ESL attacks and the failure of each representative protocol. mikablue Finally, we conduct a large-scale comprehensive comparative measurement of 41 multi-factor authentication schemes. Comparison results show thatallthese multi-factor authentication schemes considering ESL attacks do not perform better than those not. The above comprehensive approach leads to the key insight: ESL attacks areunsuitable/unrealisticfor evaluating password-based multi-factor authentication schemes because the leaked ephemeral secrets will lead to unavoidable offline password guessing attacks launched by ESL attackers, and the security of all these schemes would be compromised. We further conclude that employing hardware-protected devices (e.g., smart cards) as possession-based authentication factors can naturally resist ESL attacks, as the premise for ESL attackers to obtain ephemeral secrets is blocked. mikablue We believe our findings are general and also provide valuable guidance for defending against ESL attacks in multi-factor authentication protocols for non-mobile device environments as well. Ding Wang 0002, Meijia Xu, Qingxuan Wang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Cognitive Insights into Document Comprehension: The Role of Reading Order and Visual Attention in Human and Large Language Models
Qingxuan Wang, Hao Wang 0097, Huiran Zhang, Chenhui Chu, Rui Wang 0015, Pinpin Zhu |
CogSci | 1 |
| 2025 | Reading Between the Lines: How Eye-Tracking Data can Inform Reading Strategies for Large Language ModelsabstractLarge language models (LLMs) have made significant advancements in natural language processing, yet they still face challenges in tasks requiring deep comprehension of structurally complex and visually rich documents. Human reading patterns, captured through eye-tracking, provide valuable insights into how meaning is extracted from text, particularly in Visually Rich Documents (VRDs). In this work, we propose a novel approach to integrating eye-tracking data into LLMs to enhance reading strategies that more closely reflect human cognitive processes. By mimicking human gaze paths when reading a VRD, we explore how these insights can improve LLMs’ comprehension abilities. Our experiments demonstrate that LLMs enhanced with human-like reading orders outperform baseline models in VRD understanding tasks. These findings suggest that incorporating human-like reading strategies can bridge the gap between machine and human understanding. Overall, our results indicate that integrating eye-tracking data significantly enhances LLM performance, paving the way for more human-like document comprehension in future AI systems. Hao Wang 0097, Qingxuan Wang, Huiran Zhang, Pinpin Zhu |
ICIP | 2 |
| 2023 | Quantum2FA: Efficient Quantum-Resistant Two-Factor Authentication Scheme for Mobile DevicesabstractSmart-card based password authentication has been the most widely used two-factor authentication (2FA) mechanism for security-critical applications (e.g., e-Health, smart grid and e-Commerce) in the past decades, and it is likely to hold its status in the foreseeable future. Hundreds of this type of 2FA schemes have been proposed, yet to our knowledge, most of them are built on the intractability of conventional hard problems (e.g., discrete logarithm problems and integer factoring problems) which are no longer hard in the quantum era. With the recent advancements in quantum computing, the design of secure and efficient smart-card based password authentication schemes against quantum attacks is becoming increasingly urgent. However, it is not as simple as it seems,how to design such a quantum-resistant 2FA scheme is challenging due to the demanding security requirements and the resource-constrained nature of mobile devices. In this work, we take the first step towards this issue by proposing Quantum2FA, a practical quantum-resistant smart-card-based password authentication scheme that employs Alkimet al.’s lattice-based key exchange and Wang-Wang’s “fuzzy-verifier + honeywords” technique (IEEE TDSC’18). Particularly, Quantum2FA can thwart the newly revealed key-reuse attack (ACISP’18, CT-RSA’19) against lattice-based key exchange schemes in two aspects: signal leakage attacks and key mismatch attacks. Specifically, it restricts the necessary conditions (i.e., the attacker must be the initiator of the key exchange) for an adversary to analyze the signal; It introduces honeywords to detect the key mismatches between the smart card and the server, and thus smart card loss attack can be thwarted. We formally prove the security of Quantum2FA under the random oracle model and demonstrate its efficiency through experiments on a 32 MHz 8-bit AVR Embedded Processor. Comparison results show that Quantum2FA is not only more secure but also offers better computation efficiency than the state-of-the-art conventional 2FA schemes. Qingxuan Wang, Ding Wang 0002, Chi Cheng 0003, Debiao He |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Understanding Failures in Security Proofs of Multi-Factor Authentication for Mobile DevicesabstractMulti-factor authentication is a promising way to enhance the security of password-based authenticated key exchange (PAKE) schemes. It is widely deployed in various daily applications for mobile devices (e.g., e-Bank, smart home, and cloud services) to provide the first line of defense for system security. However, despite intensive research, how to design a secure and efficient multi-factor authentication scheme is still a challenging problem. Hundreds of new schemes have been successfully proposed, and many are even equipped with a formal security proof. However, most of them have been shortly found to be insecure and cannot achieve the claimed security goals. Now a paradox arises: How can a multi-factor scheme that was “formally proven secure” later be found insecure? To answer this seemingly contradicting question, this paper takes a substantial first step towards systematically exploring the security proof failures in multi-factor authentication schemes for mobile devices. We first investigate the root causes of the “provable security” failure in vulnerable multi-factor authentication schemes under the random oracle model, and classify them into eight different types in terms of the five steps of conducting a formal security proof. Then, we elaborate on each type of these eight proof failures by examining three typical vulnerable protocols, and suggest corresponding countermeasures. Finally, we conduct a large-scale comparative measurement of 70 representative multi-factor authentication schemes under our extended evaluation criteria. The schemes we select range from 2009 to 2022, and the comparison results suggest that understanding failures in formal security proofs is helpful to design more secure multi-factor authentication protocols for mobile devices. Qingxuan Wang, Ding Wang 0002 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | Analysis and Enhancement of a Lattice-Based Data Outsourcing Scheme With Public Integrity VerificationabstractRecently, Zhanget al.proposed a lattice-based data outsourcing scheme with public integrity verification (DOPIV), which enables an original data owner to delegate a proxy to generate the signatures of data and outsource them to the cloud server. They employed a third party auditor (TPA) to check the integrity of the outsourced data and any TPA can verify the data integrity efficiently. DOPIV is claimed to achieve proxy-oriented secure data outsourcing as well as storage correctness guarantee. Unfortunately, we find that there exist vulnerabilities in DOPIV which allow the cloud server to simply delete the received data without being noticed by the TPA. Fortunately, we come up with a simple and efficient solution to thwart the proposed attack. Our improved scheme maintains all the features claimed in DOPIV. Qingxuan Wang, Chi Cheng 0003, Jintai Ding, Zhe Liu 0001 |
IEEE Trans. Serv. Comput. | 1 |
| 2021 | Understanding security failures of anonymous authentication schemes for cloud environments
Meijia Xu, Ding Wang 0002, Qingxuan Wang, Qiaowen Jia |
J. Syst. Archit. | 3 |
| 2021 | Revisiting a Multifactor Authentication Scheme in Industrial IoTabstractNowadays, as one of the key applications of Internet of Things, Industry IoT (IIoT) has recently received significant attention and has facilitated our life. In IIoT environments, an amount of data generally requires to be transmitted between the user and sensing devices in an open channel. In order to ensure safe transmission of these data, it is necessary for the user and sensing devices to authenticate each other and establish a secure channel between them. Recently, a multifactor authenticated key agreement scheme for IIoT was proposed, which aims to tackle this problem and provide solutions for user multiple sensing devices’ access. This work claims that the proposed scheme is secure against vario us attacks and has less communication and computational costs than other existing related schemes. Unfortunately, we find that this scheme cannot resist smart card attack and sensing device capture attack. Furthermore, we show that this scheme fails to provide forward secrecy, which is essential for a secure multifactor authentication scheme. Ding Wang 0002, Shuhong Hong, Qingxuan Wang |
Secur. Commun. Networks | 3 |