VLDB 2026 Research / reviewers in the wild / expert
Yaqing Song
dblp:260/2472
· DBLP profile ↗
21ranked-venue papers
5as first author
21since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 7 · 2 first-author · 7 since 2021Security and privacy · 7 · 1 first-author · 7 since 2021Systems, architecture and hardware · 4 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Non-Interactive Distributed Key Management With Pre-Determined Shares
Yaqing Song, Shiyu Li 0002, Zeqi Lai, Qiang Tang 0005 |
ICDCS | 1 |
| 2026 | Cloud-Compatible and Scalable Private Messaging via Authentication Piggybacking
Jingwen Lu, Meng Hao, Yuan Zhang 0006, Yaqing Song, Tianhao Yang |
IWQoS | 4 |
| 2026 | How to Unleash the Value of Cloud Data? Secure and Efficient Data Delivery for Subscription-Based Entrusted TradingabstractExchange-assisted cloud-based data trading (ECDT) is a promising paradigm in current marketplaces, where an exchange provides underlying trading services while the cloud serves as a fundamental base for data sellers, brokers, and data buyers to enable them to benefit from data trading. However, directly integrating existing commercial cloud services into an exchange system suffers from practicality issues. In existing ECDT systems, the data outsourced to the cloud generally follows an “encrypt-then-outsource” paradigm, and the encrypted database makes it impractical for brokers to generate and deliver on-demand data products to the buyer, thereby hindering subscription-based data trading. In this paper, we propose a secure and efficient data delivery scheme, dubbed ESECDT, for subscription-based ECDT. ESECDT consists of data entrustment and data delivery and supports continuous data entrustment and customized data delivery while freeing the broker from heavy costs in terms of computation and communication. We formally define and prove the security of ESECDT in the random oracle model. We also implement an ESECDT prototype and conduct a comprehensive performance evaluation, which demonstrates the efficiency and practicality of ESECDT. Yuan Zhang 0006, Yaqing Song, Ningyuan Ma, Nan Cheng 0001, Kan Yang 0001, Hongwei Li 0001 |
IEEE Trans. Computers | 3 |
| 2025 | Belt and Braces! Fight against Key Compromising in Single Sign-On SystemsabstractSingle Sign-On (SSO) allows users to sign on to multiple relying providers (RPs) with a single authentication token issued by an identity provider (IdP), which provides users a convenient and efficient way to access multiple services from different RPs. As the security of SSO relies on the reliability of IdP (which needs to well maintain a secret used to issue tokens), it suffers from the single-point-of-failure problem. Existing schemes address the problem by utilizing multiple IdPs to issue tokens in a threshold way, so as to make the task of compromising the secret for adversaries as difficult as possible. However, no security guarantee is considered once the secret is compromised by adversaries. In this paper, we propose a distributed forward-secure SSO scheme, dubbed DFSSO, to achieve security in the “post-compromising case” with minimized costs: after the secret is compromised, only a small portion of users need to re-authenticate themselves with IdPs. The key technique behind DFSSO is a new cryptographic primitive, i.e., threshold forward-secure signature, which is interesting in its own right. We integrate DFSSO into OpenID Connect (i.e., OIDC, a popular SSO standard), implement a prototype, and conduct a comprehensive performance evaluation, which demonstrates that DFSSO is efficient and practical. Yuan Zhang 0006, Guowen Xu, Yaqing Song, Hongwei Li 0001 |
ACSAC | 4 |
| 2025 | End-to-End Encrypted Git ServicesabstractGit services such as GitHub, have been widely used to manage projects and enable collaborations among multiple entities. Just as in messaging and cloud storage, where end-to-end security has been gaining increased attention, such a level of security is also demanded for Git services. Content in the repositories (and the data/code supply-chain facilitated by Git services) could be highly valuable, whereas the threat of system breaches has become routine nowadays. However, existing studies of Git security to date (mostly open source projects) suffer in two ways: they provide only very weak security, and they have a large overhead. Ya-Nan Li 0007, Yaqing Song, Qiang Tang 0005, Moti Yung |
CCS | 2 |
| 2025 | Verifiable Weighted Electronic Voting against Tally Leakage for Popular Voting MethodsabstractElectronic voting (e-voting) plays a key role in modern democratic processes, especially in scenarios where consensus or collective decisions need to be reached. Existing e-voting schemes share the same paradigm of "one-person-one-vote" and treat all voters equally, which is unsatisfactory for weighted settings where every voter is associated with a weight. Furthermore, existing schemes suffer from critical threats towards voters’ privacy and voting results, which becomes a major hindrance towards the broad adoption of e-voting schemes in reality. In this paper, we propose a verifiable e-voting scheme, dubbed WEAPT, to support weighted e-voting with a strong security guarantee. The key technique behind WEAPT is a threshold weighted matrix aggregation mechanism with public verifiability and privacy preservation, where the Shamir secret sharing scheme, Pedersen vector commitment scheme, and zeroknowledge proofs are deployed. We provide security analyses to show that WEAPT is secure against internal and external adversaries. We implement a WEAPT prototype and conduct a comprehensive performance evaluation, which demonstrates its practical efficiency. Chenrui Zeng, Yuan Zhang 0006, Yaqing Song, Hongwei Li 0001 |
ICCCN | 3 |
| 2025 | EpiOracle: Privacy-Preserving Cross-Facility Early Warning for Unknown EpidemicsabstractSyndrome-based early epidemic warning plays a vital role in preventing and controlling unknown epidemic outbreaks. It monitors the frequency of each syndrome, issues a warning if some frequency is aberrant, identifies potential epidemic outbreaks, and alerts governments as early as possible. Existing systems adopt a cloud-assisted paradigm to achieve cross-facility statistics on the syndrome frequencies. However, in these systems, all symptom data would be directly leaked to the cloud, which causes critical security and privacy issues. In this paper, we first analyze syndrome-based early epidemic warning systems and formalize two security notions, i.e., symptom confidentiality and frequency confidentiality, according to the inherent security requirements. We propose extsf{EpiOracle}, a cross-facility early warning scheme for unknown epidemics. EpiOracle ensures that the contents and frequencies of syndromes will not be leaked to any unrelated parties; moreover, our construction uses only a symmetric-key encryption algorithm and cryptographic hash functions (e.g., [CBC]AES and SHA-3), making it highly efficient. We formally prove the security of EpiOracle in the random oracle model. We also implement an EpiOracle prototype and evaluate its performance using a set of real-world symptom lists. The evaluation results demonstrate its practical efficiency. Shiyu Li 0002, Yuan Zhang 0006, Yaqing Song, Fan Wu 0014, Feng Lyu 0001, Kan Yang 0001, Qiang Tang 0005 |
Proc. Priv. Enhancing Technol. | 3 |
| 2025 | What Makes a Good Exchange? Privacy-Preserving and Fair Contract Agreement in Data TradingabstractExchange-assisted data trading (EADT) has become an essential paradigm in current data marketplaces. With data exchanges, sellers and buyers can trade data in an efficient and convenient way. However, existing EADT systems are vulnerable to privacy violations. Sensitive information about the data owned by sellers (manifested as attributes of the data) and the purchasing requirements of buyers (manifested as interests) are highly susceptible to leakage. On the one hand, buyers and sellers have direct access to the type of data supplied or desired before the data transaction is established. On the other hand, the information about transactions between the seller and buyer is transparent to the exchange, including the content of the transaction contract. In addition, the participants are likely to repudiate the content of previously accepted contracts or trigger a bidding war by contract first authorized by others, which raises threats towards authenticity and fairness. In this paper, we investigate the contract agreement in actual EADT systems, enumerate the inherent requirements of secrecy and fairness, and formally define them. Then we propose a privacy-preserving and fair contract agreement framework, dubbed PFCA, which consists of order-matching, negotiation, and authorization. We further propose a practical instantiation of PFCA, dubbed BestPFCA, utilizing efficient private set intersection (PSI), secure messaging (SM), and three-party signature (TPS). In addition, we also implement a BestPFCA prototype and conduct a comprehensive performance evaluation, which demonstrates the efficiency and practicality of BestPFCA. Yuan Zhang 0006, Yaqing Song, Weidong Qiu, Hongwei Li 0001, Qiang Tang 0005 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | STAGE: Secure and Efficient Data Delivery for Exchange-Assisted Data MarketplacesabstractCloud-based exchange-assisted data trading (EADT) has become the most important paradigm to trade data, where the exchange builds a bridge between data owners, brokers, and buyers to enable them to gain benefits from data, and cloud storage services serve as a key component to deliver data. With cloud-based EADT, the data can be traded in a customized way and the value of data can be unleashed as much as possible. Despite the great advantages of such a paradigm, critical issues also arise. The data content is confronted with leakage, leading to privacy violation. Conventional encryption can be utilized to resolve this tension, but it makes customized data trading inefficient and even impossible. In this paper, we propose a secure data delivery scheme, dubbed STAGE, for cloud-based EADT. STAGE supports customized data trading while freeing the broker from heavy costs in terms of computation and communication. We formally define the security notions of STAGE and prove that STAGE is secure against various attacks. We also implement a STAGE prototype and conduct a comprehensive performance evaluation to demonstrate its efficiency and practicality. Yuan Zhang 0006, Yaqing Song, Nan Cheng 0001, Kan Yang 0001 |
ICC | 3 |
| 2024 | PPoD: Practical Proofs of Dealership for Authorized Data TradingabstractThree-layer data trading, where a data broker collects “data materials” from multiple data owners, and then provides customized data products to buyers, remains the most prevalent paradigm in current data marketplaces. However, a profit-driven broker may generate “low-quality” data products based on scratched data but sell them at a high price. Worse still, a malicious broker would pirate others' data products to disrupt data marketplaces. In this paper, we propose a practical proof of dealership scheme, dubbed PPoD, to resist malicious brokers. The key technique behind PPoD is a redactable certification generation mechanism, which enables a broker to prove its dealership of a customized data product in an efficient way. We provide a formal security proof of PPoD, which demonstrates that various attacks, e.g., piracy and deception, launched by a malicious broker can be thwarted. We also implement a PPoD prototype and conduct a comprehensive performance evaluation to show its efficiency and practicality. Yuan Zhang 0006, Yaqing Song, Nan Cheng 0001, Kan Yang 0001 |
ICC | 3 |
| 2024 | A DenseNet-based feature weighting convolutional network recognition model and its application in industrial part classificationabstractAbstract Traditional warehousing typically needs machine learning or manual tagging to classify objects. However, this method is less robust and consumes a lot of labour and material resources. Based on DenseNet, this work proposes a feature weighting convolutional network recognition model and designs a set of software and hardware for data acquisition, which is applied to the efficient classification of industrial parts in warehouse management. Firstly, this work modifies DenseNet by embedding SE‐Block, and replaces the cross‐entropy loss function with the focus loss function to optimize the model structure. Secondly, a multi‐view hardware and software acquisition system is designed to complete the functions of part image acquisition, image preprocessing, model training and part recognition. Finally, an industrial parts sorting experiment was designed. Compared with the original DenseNet model, the proposed weighted convolutional network identification model showed that the accuracy of the modified model was increased by 3.09% and the convergence rate was significantly improved. The modified model proposed in this work aims to improve the recognition accuracy of industrial parts in modern warehouse management, so as to modify the classification efficiency of warehouse parts in production. Xiaoqing Sun, Yaqing Song, Yebin Lu, Qianqian Shangguan |
IET Image Process. | 3 |
| 2024 | Blockchain-Based Portable Authenticated Data Transmission for Mobile Edge Computing: A Universally Composable Secure SolutionabstractIn mobile edge computing (MEC) systems, data is frequently transmitted between MEC servers and users holding mobile devices for supporting related services. However, critical threats towards data confidentiality and authenticity are raised: adversaries always attempt to extract data content from the transmission and impersonate others to spread malicious data for profits. Furthermore, users have to store the (secret and public) keys used for data transmission locally. Consequently, only devices maintaining the keys can be utilized to access the services provided by MEC servers, and “portability” cannot be achieved. In this paper, we propose a portable authenticated data transmission scheme (dubbed Biplane) via blockchain for MEC systems. Biplane is based on two techniques. One is a blockchain-based authenticated hybrid encryption mechanism, which guarantees data authenticity and confidentiality without requiring a third party (e.g., a Certificate Authority) to assist the MEC servers in certifying users’ public keys. The other one is a blockchain-based portable key management mechanism, which enables the user to transmit data without maintaining any parameter in her/his local devices. We formally prove that Biplane achieves confidential and authenticated data transmission in the universally composable (UC) framework. We also conduct a comprehensive evaluation to demonstrate that Biplane is efficient. Shiyu Li 0002, Yuan Zhang 0006, Yaqing Song, Nan Cheng 0001, Kan Yang 0001, Hongwei Li 0001 |
IEEE Trans. Computers | 3 |
| 2024 | PrivSSO: Practical Single-Sign-On Authentication Against Subscription/Access Pattern LeakageabstractSingle-sign-on (SSO) authentication employs an identity provider (IdP) to provide users with an efficient way to authenticate themselves with different service providers and has been widely applied in digital systems. However, existing SSO authentication schemes suffer from critical issues in terms of security and privacy. Regarding security, most SSO authentication schemes achieve a high convenience at the expense of security and are thereby susceptible to various attacks. Regarding privacy, most existing schemes fail to protect users’ subscription pattern and access pattern against adversaries who can easily extract users’ sensitive information from their authentications and launch subsequent attacks for profits. In this paper, we develop a practical SSO authentication system, dubbed PrivSSO, with the protection of users’ subscription pattern and access pattern. To balance the trade-off between security and convenience, the key technique is a secure “hybrid” key-based authentication mechanism: a long-term key stored in a well-guarded hardware token serves as the “primary” authentication factor (AF) to guarantee strong security; an ephemeral key bound with portable device(s) serves as the “daily-used” AF to achieve high convenience. To protect the subscription pattern and access pattern from leakage, we propose a redactable token generation mechanism, where the users themselves specify what IdP and the service providers can learn from their authentications. We formally define and prove the security of PrivSSO. We also implement a PrivSSO prototype and conduct a comprehensive performance evaluation to demonstrate its practicality. Yuan Zhang 0006, Yaqing Song, Shiyu Li 0002 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Beyond Security: Achieving Fairness in Mailmen-Assisted Timed Data DeliveryabstractTimed data delivery is a critical service for time-sensitive applications that allows a sender to deliver data to a recipient, but only be accessible at a specific future time. This service is typically accomplished by employing a set of mailmen to complete the delivery mission. While this approach is commonly used, it is vulnerable to attacks from realistic adversaries, such as a greedy sender (who accesses the delivery service without paying the service charge) and malicious mailmen (who release the data prematurely without being detected). Although some research works have been done to address these adversaries, most of them fail to achieve fairness. In this paper, we formally define the fairness requirement for mailmen-assisted timed data delivery and propose a practical scheme, dubbed DataUber, to achieve fairness. DataUber ensures that honest mailmen receive the service charge, lazy mailmen do not receive the service charge, and malicious mailmen are punished. Specifically, DataUber consists of two key techniques: 1) a new cryptographic primitive, i.e., Oblivious and Verifiable Threshold Secret Sharing (OVTSS), enabling a dealer to distribute a secret among multiple participants in a threshold and verifiable way without knowing any one of the shares; and 2) a smart-contract-based complaint mechanism, allowing anyone to become a reporter to complain about a mailman’s misbehavior to a smart contract and receive a reward. Furthermore, we formally prove the security of DataUber and demonstrate its practicality through a prototype implementation. Shiyu Li 0002, Yuan Zhang 0006, Yaqing Song, Hongbo Liu 0002, Nan Cheng 0001, Dahai Tao, Hongwei Li 0001, Kan Yang 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Hardening Password-Based Credential DatabasesabstractWe propose a protection mechanism for password-based credential databases maintained by service providers against leakage, dubbed PCDL. In PCDL, each authentication credential is derived from a user’s password and a salt, where a service provider employs a set of key servers to share the salt in a threshold way. With PCDL, an external adversary cannot derive any information about the underlying passwords from a compromised credential database, even if he can compromise some of the key servers. The most prominent manifestation of PCDL is transparency: integrating PCDL with existing password-based authentication schemes does not require users to perform any additional operation (and thereby does not change users’ interaction patterns), yet enhances the security guarantee significantly. PCDL serves as an independent component only deployed on the service provider side to harden the credential database. As such, PCDL is well compatible with existing password-based authentication schemes. We analyze the security of PCDL and conduct a performance evaluation, which shows that PCDL is secure and efficient. Yaqing Song, Chunxiang Xu, Yuan Zhang 0006, Shiyu Li 0002 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Privacy-Driven Fine-Grained Data TradingabstractIn this paper, we investigate actual exchange-assisted data trading systems and point out that the increment of data content in a sensitive dataset always results in the increment of its privacy level, i.e., making the dataset more sensitive than before. As a consequence, data trading always follows an incremental privacy-driven paradigm, where (1) buyers with various requirements would purchase subsets of the data with different privacy levels, and (2) when a buyer purchases a subset of the entire dataset with a higher level of privacy, the subsets with all lower levels of privacy are required (in other words, there is a containment relationship between subsets with different levels of privacy). A notable example is attribute-value type datasets. Based on these observations, we propose a new concept of privacy-driven and fine-grained data trading, which enables sellers and buyers to trade in data in an efficient and flexible way. We propose a concrete instantiation, dubbed PDFG, which enables sellers and buyers to conduct fine-grained data trading with minimal costs in terms of computation and communication. We prove that PDFG is indistinguishable against the chosen plaintext attack (CPA) under the real-or-random (RoR) model. We also conduct a comprehensive performance evaluation to demonstrate the practicality and efficiency of PDFG. Yuan Zhang 0006, Shiyu Li 0002, Yaqing Song, Hongwei Li 0001 |
PIMRC | 4 |
| 2023 | A novel action decision method of deep reinforcement learning based on a neural network and confidence bound
Yaqing Song, Xiangpeng Liu, Qianqian Shangguan |
Appl. Intell. | 2 |
| 2023 | Edge-Cloud-Assisted Certificate Revocation Checking: An Efficient Solution Against Irresponsible Service ProvidersabstractCertificate revocation checking (CRC) is a fundamental requirement in certificate-based public-key cryptographic systems. Most existing CRC schemes are not tailored for edge-cloud computing systems, and directly applying these schemes would cause security and efficiency problems. In this article, we first propose a two-layer edge-cloud-assisted CRC framework, dubbed ECA-CRC, where edge nodes utilizing a probabilistic checking algorithm serve as a first layer, and the cloud server utilizing a deterministic checking algorithm serves as a second layer. Both the edge nodes and the cloud server collaboratively provide verifiable CRC services for devices. The most prominent manifestations of ECA-CRC are that: 1) most CRC requests can be processed with the probabilistic checking layer, which reduces the checking delay significantly while providing an accurate CRC service and 2) devices can detect the irresponsible behavior of the service provider, including using an incorrect revoked certificate set (RCS) to compute checking results or procrastinating on updating the RCS, as soon as possible. We then propose an efficient instantiation of ECA-CRC, dubbed eECA-CRC, by utilizing a Merkle hash tree (MHT)-based homomorphic signature, Cuckoo filter, and Othello. We formally prove the security of eECA-CRC against the irresponsible service provider under the random oracle model. We implement an eECA-CRC prototype and conduct a comprehensive performance evaluation based on a public certificate database. Our results show that 95% of CRC requests are completed on the edge nodes, and only 5% of CRC requests need to be handled by the cloud server. Yaqing Song, Yuan Zhang 0006, Chunxiang Xu, Shiyu Li 0002, Anjia Yang, Nan Cheng 0001 |
IEEE Internet Things J. | 1 |
| 2022 | Badge: Blockchain-Assisted Secure Authenticated Data Transmission in Mobile Edge ComputingabstractIn mobile edge computing (MEC) systems, data is frequently transmitted between MEC servers and mobile devices for supporting related services. However, critical threats towards data confidentiality and authenticity are raised, where adversaries always attempt to extract data content from the transmission and impersonate others to spread malicious data for profits. In this paper, we propose a blockchain-based authenticated data transmission scheme, dubbed Badge, to establish secure channels between MEC servers and mobile devices. Badge is based on a blockchain-based authenticated hybrid encryption mechanism, which frees MEC servers from maintaining devices’ certificates and allows them to encrypt/decrypt a large volume of data in a highly efficient way. We present security analysis to demonstrate that Badge achieves data confidentiality and authenticity. We conduct a comprehensive evaluation to demonstrate that Badge is efficient and practical to deploy. Shiyu Li 0002, Yuan Zhang 0006, Nan Cheng 0001, Yaqing Song |
ICC | 4 |
| 2021 | Privacy-Preserving Friend Matching for Mobile Social NetworksabstractIn this paper, we propose an efficient private set intersection protocol, named LL-PSI, to enable two parties (where each party has an individual set) to obtain the intersection of their sets without leaking other information about their sets to each other. Compared with existing protocols, LL-PSI reduces the computational latency of the intersection between two sets significantly at the expense of communication costs between the parties. Based on LL-PSI, we propose a privacy-preserving friend matching scheme for mobile social networks, dubbed PAIRING. PAIRING allows users to match with those who have common interests while preserving users' private information against the semi-honest server and curious users. We analyze the security of PAIRING and conduct a comprehensive performance evaluation, which demonstrates that PAIRING is secure and efficient. Yaqing Song, Chunxiang Xu, Yuan Zhang 0006, Nan Cheng 0001 |
GLOBECOM | 1 |
| 2021 | Comments on an identity-based signature scheme for VANETs
Yaqing Song, Chunxiang Xu, Yuan Zhang 0006, Fagen Li |
J. Syst. Archit. | 1 |