Youshui Lu

dblp:261/5636 · DBLP profile ↗
← Back
17ranked-venue papers
6as first author
12since 2021 · last 2026
0000-0002-6598-7606ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 3 first-author · 5 since 2021Systems, architecture and hardware · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Security and privacy · 1Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 PRISM: A Secure Mobile Edge Computing Framework via Hierarchical Structure and Blockchain Governance
abstract
The rapid expansion ofMobile Edge Computing(MEC) enables latency-sensitive applications by extending computation to the network periphery. Yet its distributed and dynamic nature poses significant challenges for secure key management and consistent trust governance. ConventionalPublic Key Infrastructure(PKI) schemes suffer from heavy cross-domain overhead and fragile certificate maintenance, revealing a fundamental mismatch between centralized trust management and decentralized operation. To overcome these limitations, we present PRISM (Policy-Regulated Identity-Based Secure Messaging), a decentralized security framework designed for dynamic MEC ecosystems. PRISM integratesIdentity-Based Encryption(IBE) andAttribute-Based Access Control(ABAC) to realize unified authentication and fine-grained authorization. In parallel, blockchain-based smart contracts enforce network-wide policies and ensure global integrity. A hierarchical design supports scalable coordination and adaptive key lifecycle management, while a two-tier on-chain governance layer maintains transparency and state consistency. Formal analysis and experiments show that PRISM effectively constrains on-chain storage overhead, achieves a 100% failure detection rate when the reporting window exceeds six rounds, and maintains a stable topology (Adjusted Rand Index, ARI > 0.8) under intensive churn. These results demonstrate that PRISM effectively reconciles decentralized control with secure coordination, offering a practical foundation for consistent trust governance in large-scale MEC environments.
Rui Li 0047, Youshui Lu, Yueshen Xu
IEEE Internet Things J.3
2025 Next-generation web 3.0 for digitalized industrial applications in the 5G/6G era
Qingqi Pei, F. Richard Yu, Kaoru Ota, Mohammed Atiquzzaman, Youshui Lu
Future Gener. Comput. Syst.5
2025 Reducing Paging and Exit Overheads in Intel SGX for Oblivious Conjunctive Keyword Search
abstract
Paging and exit overheads have been proven to be the performance bottlenecks when adopting Searchable Symmetric Encryption (SSE) with trusted hardware such as Intel SGX for keyword search. This problem becomes more serious when incorporating ORAM and SGX to design oblivious SSE schemes such as POSUP [1] and Oblidb [2] which can defend against inference attacks. The main reason comes from high round communication complexity of ORAM and constrained trusted memory created by SGX. To overcome this performance bottleneck, we propose a set of novel SSE constructions with realistic security/performance trade-offs. Our core idea is to encode the keyword-identifier pairs into a bloom filter to reduce the number of ORAM operations during the search procedure. Specifically, Construction 1 loads the bloom filter into the enclave sequentially, which outperforms about$1.7\times$when the dataset is large compared with the performance of the baseline that directly combines ORAM and SGX. To further improve the performance of Construction 1, Construction 2 classifies keywords into groups and stores these groups in different bloom filters. By additionally leaking the keywords in search token belonging to which groups, Construction 2 outperforms Construction 1 by$16.5\sim 36.8\times$and provides an improvement of at least one order over state-of-the-art oblivious protocols.
Saiyu Qi, Xu Yang 0033, Yong Qi 0001, Jianfeng Wang 0001, Youshui Lu, Bochao An, Ee-Chien Chang
IEEE Trans. Computers6
2024 FEMD: Feature Enhancement-aided Multimodal Feature Fusion Approach for Smart Contract Vulnerability Detection
abstract
Smart contracts, due to their immutability and transparency upon deployment, entail significant economic and systemic risks from any vulnerabilities present. Traditional vulnerability detection methods suffer from low automation and high false positive rates, while existing deep learning-based approaches inadequately extract contract features, thereby limiting detection accuracy. To address these issues, this paper proposes FEMD: a feature-enhanced aided multimodal feature fusion method for smart contract vulnerability detection. Building on the foundation of addressing the low automation of traditional detection tools, our method improves the model’s feature extraction performance and detection capabilities. Specifically, we construct a contract graph through Comprehensive Expert-Graph Fusion, combining multi-modal feature fusion using a multi-head attention mechanism with expert patterns to ensure the capture and effective preservation of all critical information during the fusion process. To delve deeper into potential information within smart contract graphs, we employ a Feature Enhancer that leverages transpose operations on feature matrices to extract complex interaction patterns across different dimensions. Our approach is validated through batches of experiments on the Ethereum open dataset focusing on reentrancy and timestamp dependency vulnerabilities, demonstrating significant improvements in detection accuracy and robustness.
Rui Li 0047, Youshui Lu, Bowen Cai 0004, Yulin Cao, Chan Li
ICPADS3
2024 Tree-ORAP: A Tree-Based Oblivious Random-Access Protocol for Privacy-Protected Blockchain
abstract
Since the introduction of Bitcoin in 2008, blockchain technology has found widespread applications across various domains. While blockchain offers convenience and immense research value, it also raises privacy and security concerns among users and society at large. Notably, numerous studies have demonstrated the vulnerability of blockchain anonymity. Existing solutions based on bloom filters and SGX(Software Guard Extensions) may safeguard users' access patterns but remain susceptible to novel attacks, including protocol-level and side-channel attacks. To address these issues, we propose a Tree-based Oblivious Random Access Protocol (Tree-ORAP) that not only provides access pattern protection in privacy-preserving blockchain systems but also preserves the original blockchain performance. Furthermore, we design a Tree-ORAP State Version Controller to manage state synchronization across nodes in a multi-client blockchain network. We also analyze the system's security and implement a Tree-ORAP prototype, conducting a series of experiments to demonstrate its efficiency and technical feasibility. In summary, our protocol offers enhanced protection for blockchain systems against a wider range of attacks compared to previous methods, all while maintaining superior security performance and equal or better efficiency.
Youshui Lu, Bowen Cai 0004, Lei Liu 0031, Jun Du 0001, Shui Yu 0001, Mohammed Atiquzzaman, Schahram Dustdar
IEEE Trans. Serv. Comput.1
2023 Speeding at the Edge: An Efficient and Secure Redactable Blockchain for IoT-Based Smart Grid Systems
abstract
As a promising approach to extending cloud resources and services, blockchain-enabled Internet of Things (IoT)-based smart grid edge computing has attracted much attention. However, the edge node’s resource-constraint nature makes it difficult to store the entire chain as the sensing IoT data volume increases. To address this issue, we propose an FS scheme, a fast and secure multithreshold trapdoor Chameleon hash scheme which serves as the basis for block substitution at the edge nodes to solve the storage limitation problem. The FS scheme is used to achieve a consensus-based block substitution, which allows$t$-out-of-$n$edge nodes to compute a hash collision collaboratively to reliably substitute a historical block without leaking the randomness$R$. Also, inspired by the rationale of fast polynomial interpolation, we optimize the FS scheme to FS-I to reduce the time complexity from$\mathcal {O}(nt)$to$\mathcal {O}(t{\mathrm{ log}}^{2}t)$. In addition, we further optimize FS-I to FS-II by using a fast Fourier transform (FFT) to dramatically improve the computational efficiency of Lagrange interpolation, which leads to a significant improvement in terms of block substitution performance. Finally, We provide security analysis and evaluate the performance through comprehensive experiments and the results show that FS can achieve up to several magnitudes better than DTTCH. The results also demonstrate that the FS scheme can provide high service quality for large-scale IoT-based smart grid systems.
Youshui Lu, Lei Liu 0031, F. Richard Yu, Schahram Dustdar
IEEE Internet Things J.1
2023 Safety Warning! Decentralised and Automated Incentives for Disqualified Drivers Auditing in Ride-Hailing Services
abstract
Since 2011, the private ride-hailing companies Didi (2019), Uber (2019) and Lyft (2021) have expanded into more and more cities. These ride-hailing services (RHS) bring convenience to our life; however, at the same time they, also raise security concerns for users. For example, several recent news items show that a considerable number of registered drivers whose licenses have been revoked are still taking RHS orders on the respective platforms; this phenomenon directly leads to insecurity on part of its users and the bad reputation of the ride-hailing service provider (SP). The traditional solution to solve this problem is to periodically check the validity of the drivers’ licenses; however, it is a considerably time-consuming and costly process since the SPs have to manually interact with the governing authorities. Therefore, in this paper, we have presented an auditable self-sovereign identity system (named AudiSSI), which provides an efficient approach for the SPs to manage their registered drivers’ qualifications in a decentralized and automatic manner. Further, using smart contract technology, we propose a safety guarantee insurance in the form of an auditing contract to enable the RHS rider to check their driver's qualifications before the trip starts and get incentives once they detect a disqualified driver. We designed an incentive mechanism and have provided a game theoretical analysis. Finally, we implemented a prototype of AudiSSI and deployed it on Hyperledger Indy and Fabric to show that self-sovereign identity system for RHS driver with qualification auditing is efficient and technically feasible.
Youshui Lu, Jingning Zhang, Yong Qi 0001, Saiyu Qi, Yue Li 0060, Hongyu Song, Yuhao Liu 0004
IEEE Trans. Mob. Comput.1
2022 Correction to: Multi-level word features based on CNN for fake news detection in cultural communication
Qian Li 0024, Youshui Lu, Jingxian Cheng
Pers. Ubiquitous Comput.3
2022 Accelerating at the Edge: A Storage-Elastic Blockchain for Latency-Sensitive Vehicular Edge Computing
abstract
The application of blockchain to Vehicular Edge Computing (VEC) has attracted significant interests. As the Internet of Things plays an essential and fundamental role for data collecting, data analyzing, and data management in VEC, it is vital to guarantee the security of the data. However, the resource-constraint nature of edge node makes it challenging to meet the needs to maintain long life-cycle IoT data since vast volumes of IoT data quickly increase. In this paper, we propose Acce-chain, a storage-elastic blockchain based on different storage capacities at the edge. Acce-chain supports re-write operation to re-write the historical block with a newly generated block without breaking the hash links between the blocks. As a result, Acce-chain ensures that the hot data can be efficiently accessed at the edge without incurring much communication costs or increasing the total size of the chain. To guarantee the security of the re-write process, we propose a new cryptographic primitive named Dynamic Threshold Trapdoor Chameleon Hash (DTTCH). To guarantee the verifiability of query operation, we design a novel storage structure namedHybridStoreto ensure the verifiable query for on-chain/off-chain IoT data. As a result, Acce-chain achieves both authorized re-write and verifiable query simultaneously. We provide security analysis for the DTTCH scheme and the IoT data query algorithms. We evaluate Acce-chain through experiments and the results show that the performance of the re-write operation is feasible in real-world VEC settings, and the query efficiency can achieve up to several magnitudes better than which of the baseline. The results also demonstrate that Acce-chain can provide high service quality for the latency-sensitive VEC systems.
Youshui Lu, Jingning Zhang, Yong Qi 0001, Saiyu Qi, Yuanqing Zheng, Yuhao Liu 0004, Hongyu Song, Wei Wei 0006
IEEE Trans. Intell. Transp. Syst.1
2022 Say No to Price Discrimination: Decentralized and Automated Incentives for Price Auditing in Ride-Hailing Services
abstract
As the most successful application of the sharing economy, ride-hailing service is popular worldwide and serves millions of users per day worldwide. Ride-hailing service providers (SPs) usually collect users’ personal data to improve their services via big data technologies. However, SPs may also use the collected user data to apply personalized prices to different users, which raises price fairness concerns. In this paper, we propose a smart price auditing system named Spas. Spas allows a user to purchaseFair Price Insurancein the form ofPrice Auditing Contract, then the price of ride-hailing service (RHS) order will be audited automatically once completed. According to the auditing result, the contract punishes misbehaving SPs and also compensates affected users automatically. By replacing an untrustworthy centralized auditor with carefully designed smart contracts, we construct a decentralized price auditing system which is trustworthy and transparent. We demonstrate a theoretical model for practical payment flows based on real RHS user data and we implement Spas in Hyperledger Fabric to show that decentralizing and automating price auditing for RHS with financial incentives is technically feasible.
Youshui Lu, Yong Qi 0001, Saiyu Qi, Yue Li 0060, Hongyu Song, Yuhao Liu 0004
IEEE Trans. Mob. Comput.1
2021 Efficient Data Access Control With Fine-Grained Data Protection in Cloud-Assisted IIoT
abstract
The Industrial Internet of Things (IIoT) has provided a promising opportunity to build digitalized industrial systems. A fundamental technology of IIoT is the radio-frequency identification (RFID) technique, which allows industrial participants to identify items and anchor time-series IoT data for them. They can further share the IoT data through the cloud service to enable information exchange and support critical decisions in production operations. Storing IoT data in the cloud, however, requires a data access control mechanism to protect sensitive business issues. Unfortunately, using traditional cryptographic access control schemes for time-series IoT data face severe efficiency and key leakage problems. In this article, we design a secure industrial data access control scheme for cloud-assisted IIoT. Our scheme enables participants to enforce fine-grained access control policies for their IoT data via ciphertext policy-attribute-based encryption (CP-ABE) scheme. Our scheme adopts a hybrid cloud infrastructure for participants to outsource expensive CP-ABE tasks to the cloud service with strong privacy guarantees. Importantly, our scheme guarantees a new privacy notion named item-level data protection for IoT data to prevent key leakage problem. We achieve these goals via several encryption and optimization techniques. Our performance assessments combine system implementation with large-scale emulations and confirm the security and efficiency of our design.
Saiyu Qi, Youshui Lu, Wei Wei 0006, Xiaofeng Chen 0001
IEEE Internet Things J.2
2021 Cpds: Enabling Compressed and Private Data Sharing for Industrial Internet of Things Over Blockchain
abstract
Internet of Things (IoT) is a promising technology to provide product traceability for industrial systems. By using sensing and networking techniques, an IoT-enabled industrial system enables its participants to efficiently track products and record their status during production process. Current industrial IoT systems lack a unified product data sharing service, which prevents the participants from acquiring trusted traceability of products. Using emerging blockchain technology to build such a service is a promising direction. However, directly storing product data on blockchain incurs in efficiency and privacy issues in data management due to its distributed infrastructure. In response, we propose Cpds, a compressed and private data sharing framework, that provides efficient and private data management for product data stored on the blockchain. Cpds devises two new mechanisms to store compressed and policy-enforced product data on the blockchain. As a result, multiple industrial participants can efficiently share product data with fine-grained access control in a distributed environment without relying on a trusted intermediary. We conduct extensive empirical studies and demonstrate the feasibility of Cpds in improving the efficiency and security protection of product data storage on the blockchain.
Saiyu Qi, Youshui Lu, Yuanqing Zheng, Yumo Li, Xiaofeng Chen 0001
IEEE Trans. Ind. Informatics2
2020 Serving at the Edge: A Redactable Blockchain with Fixed Storage
Jingning Zhang, Youshui Lu, Yuhao Liu 0004, Xu Yang 0033, Yong Qi 0001, Xinpei Dong
WISA2
2020 PSM2: A Privacy-Preserving Self-sovereign Match-Making Platform
Youshui Lu, Saiyu Qi
BlockSys3
2020 Pbsx: A practical private boolean search using Intel SGX
Yong Qi 0001, Saiyu Qi, Wenjia Zhao, Youshui Lu
Inf. Sci.5
2020 Multi-level word features based on CNN for fake news detection in cultural communication
Qian Li 0024, Youshui Lu, Jingxian Cheng
Pers. Ubiquitous Comput.3
2020 TouristGo: a location-based mobile game to improve tourist experience by visiting path optimisation
Youshui Lu, Jinwei Lin, Kangyi Yuan
Pers. Ubiquitous Comput.1