VLDB 2026 Research / reviewers in the wild / expert
Saiyu Qi
dblp:27/4551
· DBLP profile ↗
69ranked-venue papers
18as first author
51since 2021 · last 2026
0000-0002-0394-4432ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 19 · 9 first-author · 15 since 2021Security and privacy · 17 · 4 first-author · 15 since 2021Systems, architecture and hardware · 15 · 4 first-author · 8 since 2021Artificial intelligence and machine learning · 6 · 5 since 2021Databases, data management, data science and information retrieval · 5 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 2 since 2021Software engineering, systems software and programming languages · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | vObliChain: Securing satellite networks with verifiable oblivious search over blockchain databases
Xu Yang 0033, Saiyu Qi, Hongguang Zhao |
Comput. Networks | 3 |
| 2026 | Practical volume-hiding range searchable symmetric encryption using trusted execution
Xu Yang 0033, Ke Li 0041, Saiyu Qi, Hongguang Zhao |
Future Gener. Comput. Syst. | 3 |
| 2026 | SecDAF: An efficient secure multi-source data analysis framework
Wenjia Zhao, Saiyu Qi, Yong Qi 0001 |
Future Gener. Comput. Syst. | 2 |
| 2026 | OCDS: Consortium Blockchain-Empowered Oblivious and Consistent Data Asset Sharing for Internet of VehiclesabstractThe Internet of Vehicles (IoV) produces massive volumes of vehicular data rich in traffic patterns, driving behavior, and location intelligence, rendering it a valuable asset for transportation systems, urban planning, and commercial applications, thus necessitating secure and efficient data asset sharing. However, existing vehicular data sharing solutions do not protect data access patterns, risking privacy leaks. In this paper, we propose OCDS, a consortium blockchain-empowered oblivious and consistent data asset sharing for IoV. OCDS enables vehicles to write and read data assets in an oblivious way by introducing BdcORAM, which employs a tree-structured world state and implements a two-phase oblivious write protocol alongside a consistent oblivious read protocol. Additionally, we further design two optimized variants of BdcORAM to optimize performance for unbalanced read-write workloads. Through comprehensive security analyses and experimental evaluation, OCDS demonstrates it achieves data confidentiality, access anonymity, and secure read consistency without incurring significant performance overhead. Saiyu Qi, Ke Li 0041, Wei Wei 0006, Xu Yang 0033 |
IEEE Internet Things J. | 1 |
| 2026 | Secure and Efficient Keyword Search Over Encrypted Graphs With Trusted Hardware
Qiuhao Wang, Xu Yang 0033, Saiyu Qi, Hongguang Zhao, Ke Li 0041, Wenjia Zhao |
IEEE Internet Things J. | 3 |
| 2026 | Lightweight multi-client order-revealing encryption with limited leakage
Chunyang Lv, Jianfeng Wang 0001, Shifeng Sun 0001, Saiyu Qi, Chao Chen 0015, Leo Yu Zhang, Kok-Leong Ong |
Inf. Sci. | 4 |
| 2026 | Model Stability Defense Against Model Poisoning in Federated LearningabstractFederated Learning (FL) exhibits susceptible to model poisoning attacks, which compromise the availability of the collaboratively trained model by introducing detrimental local updates during the training process. The predominant line of defense against such attacks has been to impose stringent restrictions on clients' model updates. However, this strategy raises new vulnerabilities where the global model can be infiltrated by meticulously crafted malicious perturbations. This vulnerability arises due to the model's inherent sensitivity to perturbations, making it exposed and fragile. In response, this work investigates a novel defensive paradigm centered on model stability-specifically, a model's resilience against perturbations within its parameter space. As a solution, we introduce a new method named Model Stability Defense for Federated Learning (MSDFL), designed to fortify the defense of FL systems against model poisoning attacks. MSDFL utilizes a minmax optimization framework, which is fundamentally linked to empirical risk for exploring the effects of model perturbations. The core aim of our approach is to minimize the norm of the model-output Jacobian matrix without compromising predictive performance, thereby establishing defense through enhanced model stability. Moreover, we propose a refined version of MSDFL, named Holistic Model Stability Defense for Federated Learning (HMSDFL), which considers model stability across all output dimensions of the logits to effectively eradicate the disparity in model convergence speed induced by MSDFL. Extensive experimental results fully demonstrate the fidelity, robustness, compatibility, and self-protection of our methods. The source codes are maintained athttps://github.com/qqoneone/MSDFL. Di Wu 0062, Yong Qi 0001, Saiyu Qi, Qian Li 0024, Minghao Yao, Kaitai Liang |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | TMVcrowd: An Authorized and Fine-Grained Encrypted Task Matching Framework on Blockchain for Vehicular Crowdsourcing
Xu Yang 0033, Wei Wei 0006, Saiyu Qi, Yuzhe Meng, Jingxian Cheng, Ke Li 0041, Hongguang Zhao |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2026 | SeaCQ: Secure and Efficient Authenticated Conjunctive Query in Hybrid-Storage Blockchains
Xu Yang 0033, Hongguang Zhao, Saiyu Qi, Yong Qi 0001 |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2026 | Invisible, Yet Trusted: Blockchain-Empowered Privacy-Preserving Spatio-Temporal Task Matching in Crowdsourcing With Efficient Public VerificationabstractTask matching is a core component of crowdsourcing systems, enabling efficient assignment of tasks to appropriate workers. However, this process often requires both task requesters and workers to disclose sensitive contextual information, such as spatial locations and temporal availability, raising serious privacy concerns. Although various cryptographic techniques and blockchain-based solutions have been proposed to preserve privacy and enhance trust, existing schemes still face three critical limitations: reliance on centralized key authorities, lack of support for fine-grained spatio-temporal constraints, and inefficient public verification mechanisms. To address these challenges, we propose PVSTMatch, a blockchain-empowered privacy-preserving spatio-temporal task matching scheme in crowdsourcing. PVSTMatch eliminates the need for trusted third parties through an authority-free authorization mechanism, supports secure spatio-temporal matching by designing a compact secure comparison method, and enables efficient public verifiability via a succinct verification mechanism. Furthermore, we introduce GE-PVSTMatch, a gas-efficient variant that significantly reduces on-chain storage costs. Security analysis and performance evaluation demonstrate that our schemes achieve strong bilateral privacy, verification correctness, and practical efficiency, making them well-suited for real-world decentralized crowdsourcing platforms. Xu Yang 0033, Saiyu Qi, Yong Qi 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2025 | BlindChain: Keeping Query Privacy in Blockchain Out of Sight
Jingxian Cheng, Saiyu Qi, Ke Li 0041, Zhangjie Fu 0001, Yong Qi 0001 |
DASFAA (4) | 4 |
| 2025 | Forgetting Through Transforming: Enabling Federated Unlearning via Class-Aware Representation TransformationabstractFederated Unlearning (FU) enables clients to selectively remove the influence of specific data from a trained federated learning model, addressing privacy concerns and regulatory requirements. However, existing FU methods often struggle to balance effective erasure with model utility preservation, especially for class-level unlearning in non-IID settings. We propose Federated Unlearning via Class-aware Representation Transformation (FUCRT), a novel method that achieves unlearning through class-aware representation transformation. FUCRT employs two key components: (1) a transformation class selection strategy to identify optimal forgetting directions, and (2) a transformation alignment technique using dual class-aware contrastive learning to ensure consistent transformations across clients. Extensive experiments on four datasets demonstrate FUCRT's superior performance in terms of erasure guarantee, model utility preservation, and efficiency. FUCRT achieves complete (100\%) erasure of unlearning classes while maintaining or improving performance on remaining classes, outperforming state-of-the-art baselines across both IID and Non-IID settings. Analysis of the representation space reveals FUCRT's ability to effectively merge unlearning class representations with the transformation class from remaining classes, closely mimicking the model retrained from scratch. Minghao Yao, Saiyu Qi, Yong Qi 0001, Bingyi Liu |
ICCV | 4 |
| 2025 | Secure blockchain-based reputation system for IIoT-enabled retail industry with resistance to sybil attack
Wenjia Zhao, Saiyu Qi, Junzhe Wei, Xinpei Dong, Xu Yang 0033, Yong Qi 0001 |
Future Gener. Comput. Syst. | 3 |
| 2025 | XB-Muse: Practical Multiuser Dynamic Searchable Symmetric Encryption for Adaptive RevocationabstractDynamic searchable symmetric encryption (DSSE) schemes support keyword search queries on encrypted dynamic datasets with add-or-delete operations stored on an untrusted remote server. Multi-user DSSE (MUDSSE) further considers multiple users to access the encrypted dataset. Most works of MUDSSE focus on how to promise forward and backward privacy of queries. However, the problem in which the data owner can not revocate the deleted encrypted data on the encrypted dataset adaptively and efficiently is not sufficiently considered. To solve this problem, we propose a new multi-user DSSE scheme named X-MUSE, extending cryptographic primitives Symmetric Revocable Encryption (SRE) to design a new searchable encryption with optimal search time for the deletion operation. Furthermore, to minimize communication size and counter new integrity threats raised by malicious clients, we extend X-MUSE to design a new MUDSSE named B-MUSE by integrating blockchain-based technology. Our evaluation confirms that our schemes have practical search performance and lower storage costs on both the server and the client side compared to the state-of-the-art. Xu Yang 0033, Saiyu Qi, Fuyuan Song, Zhangjie Fu 0001 |
IEEE Internet Things J. | 4 |
| 2025 | Efficient and Confidentiality-Preserving Bloom Filter-Encoded Video SearchabstractContent based video search services find extensive applications across various domains including video surveillance and object detection. In recent times, researchers have increasingly turned their attention towards enhancing the security of video search over outsourced encrypted videos. Nonetheless, prior researchers often leverage cost-expensive techniques like Homomorphic encryption or Order-preserving encryption to ensure privacy preservation. To reduce the overhead, Bloom Filter (BF)-encoded keyword search is a promising technology for retrieving encrypted videos with image queries. However, it generally suffers from serious data privacy leakage since it will reveal the inclusion relationship between “1” and “0” in the BF. Fortunately, the privacy-preserving bloom filter-based search scheme (PBKS) was recently proposed to achieve secure and effective search while protecting the values in BFs, but it still has two limitations. One is the size of a search token is very large in some cases and the other is the cloud server can infer the true value of each bit in the BF by doing a few operations. In this paper, we propose an efficient and confidentiality-preserving bloom filter-encoded video search (ECVS) scheme for retrieving encrypted videos with image queries. We first design a new CPRF (prefix-constrained pseudorandom function)-based token compression method to reduce the size of the search token and reduce the communication cost largely. Furthermore, we customize a periodic refresh mechanism to conceal the true value of each bit in the BF while avoiding excessive computational pressure on resource-limited users. Security analysis and experiments confirm the security and efficiency of our schemes. Xu Yang 0033, Hongguang Zhao, Saiyu Qi, Ke Li 0041, Qiuhao Wang, Yong Qi 0001, Wei Wei 0006, Shahid Mumtaz |
IEEE Internet Things J. | 3 |
| 2025 | DedupChain: A Secure Blockchain-Enabled Storage System With Deduplication for Zero-Trust NetworkabstractPermissioned blockchain is a promising methodology to build zero-trust storage foundation with trusted data storage and sharing for the zero-trust network. However, the inherent full-backup feature of the permissioned blockchain poses potential data privacy risks and substantial storage costs, hindering its usage as a storage medium. These issues necessitate the usage of secure data deduplication technology to mitigate them. Unfortunately, current secure data deduplication schemes are predominantly designed with centralized cloud servers in mind and are not suitable for distributed blockchain systems. The reason is that the full backup feature of the permissioned blockchain renders a wide attack surface to offline brute-force and frequency analysis attacks. In response, we propose DedupChain, a secure blockchain-enabled storage system with deduplication for zero-trust networks. DedupChain employs a trusted execution environment (i.e., Inter SGX enclave) in conjunction with Oblivious RAM (ORAM) to offer a novel security guarantee namedoblivious data deduplication, which empowers DedupChain with the ability to defend offline brute-force and frequency analysis attacks. DedupChain also proposes several novel techniques to address the security and efficiency issues raised by the SGX enclave. We implemented a system prototype of DedupChain and evaluated its performance metrics. Our experimental results show that DedupChain exhibits satisfactory operational delays, throughput, and storage overhead. Security analysis shows that DedupChain is robust enough to withstand several types of attacks. To the best of our knowledge, we are the first to apply secure data deduplication techniques to address data privacy and storage cost issues raised by permissioned blockchain when used as a zero-trust storage medium. Saiyu Qi, Qiuhao Wang, Wei Wei 0006, Hongguang Zhao, Yuhao Liu 0004, Xu Yang 0033, Yong Qi 0001 |
IEEE J. Sel. Areas Commun. | 1 |
| 2025 | Reducing Paging and Exit Overheads in Intel SGX for Oblivious Conjunctive Keyword SearchabstractPaging and exit overheads have been proven to be the performance bottlenecks when adopting Searchable Symmetric Encryption (SSE) with trusted hardware such as Intel SGX for keyword search. This problem becomes more serious when incorporating ORAM and SGX to design oblivious SSE schemes such as POSUP [1] and Oblidb [2] which can defend against inference attacks. The main reason comes from high round communication complexity of ORAM and constrained trusted memory created by SGX. To overcome this performance bottleneck, we propose a set of novel SSE constructions with realistic security/performance trade-offs. Our core idea is to encode the keyword-identifier pairs into a bloom filter to reduce the number of ORAM operations during the search procedure. Specifically, Construction 1 loads the bloom filter into the enclave sequentially, which outperforms about$1.7\times$when the dataset is large compared with the performance of the baseline that directly combines ORAM and SGX. To further improve the performance of Construction 1, Construction 2 classifies keywords into groups and stores these groups in different bloom filters. By additionally leaking the keywords in search token belonging to which groups, Construction 2 outperforms Construction 1 by$16.5\sim 36.8\times$and provides an improvement of at least one order over state-of-the-art oblivious protocols. Saiyu Qi, Xu Yang 0033, Yong Qi 0001, Jianfeng Wang 0001, Youshui Lu, Bochao An, Ee-Chien Chang |
IEEE Trans. Computers | 2 |
| 2025 | RO(SE)${}^{2}$ 2: Search-Efficient Robust Searchable Encryption With Forward and Backward SecurityabstractDynamic searchable symmetric encryption (DSSE) enables clients to store encrypted data on untrusted servers while retaining the ability to search and update the data efficiently. However, most existing DSSE schemes are vulnerable to incorrect update queries, such as duplicated insertions or invalid deletions, which can compromise both security and availability. Although existing robust schemes have made progress in addressing these issues, they still suffer from significant search inefficiencies, particularly when handling large numbers of updates. To overcome these limitations, we proposeRO(SE)2, a novel robust DSSE scheme that simultaneously achieves robustness, forward-and-Type-III-backward security, and optimal search performance.RO(SE)2introduces a hierarchical binary tree structure combined with an oblivious map (OMAP) to handle incorrect updates during the update phase, eliminating the need for filtering during search queries and significantly improving search efficiency. Additionally,RO(SE)2employs a two-layer encryption mechanism to ensure forward security and supports efficient search result verification through its verifiable extension,RO(SE)2-v. Rigorous security analysis proves thatRO(SE)2can achieve not only robustness, forward and backward security but optimal search efficiency as well. Comparative analysis reveals thatRO(SE)2outperforms existing robust schemes in terms of search performance, whileRO(SE)2-v outperforms the state-of-the-art verifiable robust schemes in verification performance. Xu Yang 0033, Qiuhao Wang, Saiyu Qi, Ke Li 0041, Yong Qi 0001 |
IEEE Trans. Computers | 3 |
| 2025 | AMA: Adaptive Model Poisoning Attacks Towards Federated LearningabstractFederated Learning (FL) is vulnerable to model poisoning attacks, where malicious updates (e.g., gradients) can adversely interfere with the global model. Existing attacks typically rely heavily on the updates of benign clients and aggregation algorithms to craft malicious updates. However, the benign updates and aggregation algorithms are usually hard to access for attackers, which makes their attacks weak and volatile. Therefore, in this work, we aim to design an adaptive model poisoning attack based on the agnostic adversary. Specifically, we propose a new concept from the perspective of adversarial learning, called adversarial model perturbation. This perturbation targets the parameters of the local model and aims to maximally mislead its predictions. Then, we develop a novel adaptive model poisoning attack namedAdversarial Model Attack (AMA), which utilizes the adversarial model perturbation as the malicious updates to attack the global model. Instead of the benign updates and aggregation algorithms, we only leverage the original data of the malicious client to adaptively craft the malicious updates. AMA resolves the conflict between the knowledge requirement of the adversary and the impact of model poisoning attacks. Empirical results against multiple robust FL methods show that AMA surpasses state-of-the-art attack methods and updates the benchmark of attack impact on Fedavg, Trimean, Multi-Krum, FoundationFL, RFA, and Median. Di Wu 0062, Yong Qi 0001, Saiyu Qi, Qian Li 0024 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Dual Class-Aware Contrastive Federated Semi-Supervised LearningabstractFederated semi-supervised learning (FSSL), facilitates labeled clients and unlabeled clients jointly training a global model without sharing private data. Existing FSSL methods predominantly employ pseudo-labeling and consistency regularization to exploit the knowledge of unlabeled data, achieving notable success in raw data utilization. However, the effectiveness of these methods is challenged by large deviations between uploaded local models of labeled and unlabeled clients, as well as confirmation bias introduced by noisy pseudo-labels, both of which negatively affect the global model's performance. In this paper, we present a novel FSSL method called Dual Class-aware Contrastive Federated Semi-Supervised Learning (DCCFSSL). This method considers both the local class-aware distribution of each client's data and the global class-aware distribution of all clients’ data within the feature space. By implementing a dual class-aware contrastive module, DCCFSSL establishes a unified training objective for different clients to tackle large deviations and incorporates contrastive information in the feature space to mitigate confirmation bias. Additionally, DCCFSSL introduces an authentication-reweighted aggregation technique to improve the server's aggregation robustness. Our comprehensive experiments show that DCCFSSL outperforms current state-of-the-art methods on three benchmark datasets and surpasses the FedAvg with relabeled unlabeled clients on CIFAR-10, CIFAR-100, and STL-10 datasets. Di Wu 0062, Yong Qi 0001, Saiyu Qi |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | SecGraph: Towards SGX-based Efficient and Confidentiality-Preserving Graph Search
Qiuhao Wang, Xu Yang 0033, Saiyu Qi, Yong Qi 0001 |
DASFAA (4) | 3 |
| 2024 | Lightweight verifiable blockchain top-k queries
Jingxian Cheng, Saiyu Qi, Bochao An, Yong Qi 0001, Jianfeng Wang 0001, Yanan Qiao |
Future Gener. Comput. Syst. | 2 |
| 2024 | POMF: A Privacy-preserved On-chain Matching Framework
Saiyu Qi, Junzhe Wei, Yong Qi 0001, Wei Wei 0006, Yanan Qiao |
Future Gener. Comput. Syst. | 2 |
| 2024 | Towards Gradient-Based Saliency Consensus Training for Adversarial RobustnessabstractIn recent works, robust networks have consistently exhibited more discriminative saliency map that proves to indicate sufficient adversarial robustness. In existed safe training paradigms e.g., adversarial training, however, the progressive saliency information regarding on what input semantic feature model prediction relies, have not yet been fully-explored. Due to this, we consider the incorporation of posterior saliency properties of robust model in training, as an efficient supervision signal on robust learning. It thus provides an alternative direction to enhance robustness, from the saliency interpretability perspective. In this article, to harden model we propose to optimize the discrimination of intermediate gradient-based saliency and maintain its consensus in training, which encourage model to behave according to task-relevant feature from the salient region such as object edges in image. Then, we introduce Adversarially Gradient-based Saliency Consensus Training method, dubbedAdv-GSCT. Within it, we preserve the similarity between the learned model saliency and the target one as label, approximated in the most offending case representing the least but essential information scenario. Meanwhile, a constructed pseudo-input coupled with feature importance, is feed into model to ensure the discrimination of estimated target saliency. Besides providing a novel insight into adversarial defense,Adv-GSCTdiffers from the current most effective adversarial training and does not need multiple iterative generations of adversarial perturbation whose computational cost and sensitivity direction of prediction concern. Finally, extensive performance evaluations on MNIST, CIFAR-10 and ImageNet datasets demonstrate the superiority of our proposed method. Qian Li 0024, Chao Shen 0001, Chenhao Lin, Saiyu Qi |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2024 | Towards Practical Multi-Client Order-Revealing Encryption: Improvement and ApplicationabstractOrder-revealing encryption (ORE) enables the untrusted server to perform greater-than-comparison over ciphertext without compromising data privacy, which allows anyone to evaluate the lexicographic ordering of two arbitrary ciphertexts with a public comparison algorithm. However, most ORE constructions merely support ciphertext comparison for single-user. Recently, a variant of ORE named delegatable ORE has been introduced, which achieves cross-user ciphertext comparison by employing token mutual authorization technique at the cost of weak security, i.e., reveals the most significant differing bit of underlying plaintexts. To tackle this problem, we first present a deterministic property-preserving hash called DPPH with short-size hash value, and then propose a novel multi-client ORE scheme (m-ORE) from DPPH that supports ciphertext comparison among multiple users while hiding the most significant differing bits. Furthermore, we present an enhanced construction dubbed m-H-ORE by introducing a two-phase comparison method, which can achieve supper-efficient comparison in some cases, i.e., two ciphertexts with different bit-length. Finally, we provide formal security proofs of the proposed schemes and run extensive experiments to evaluate their performance on real-world and synthetic datasets. The results demonstrate that both of the proposed schemes can achieve a speedup of 47× and 138× in comparison cost to that of parameter-hiding ORE, respectively. Chunyang Lv, Jianfeng Wang 0001, Shifeng Sun 0001, Yunling Wang, Saiyu Qi, Xiaofeng Chen 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Secure and Lightweight Blockchain-based Truthful Data Trading for Real-Time Vehicular CrowdsensingabstractAs the number of smart cars grows rapidly, vehicular crowdsensing (VCS) is gradually becoming popular. In a VCS infrastructure, sensing devices and computing units hold on smart cars as well as cloud servers form an IoT-edge-cloud continuum to perform real-time sensing tasks. In order to encourage the smart cars to participate in the real-time VCS process, blockchain technology can be combined with VCS to provide an automated incentive for VCS data trading without relying on trusted third parties. However, directly using blockchain to enforce the VCS data trading process incurs expensive service fees and participants still can conduct various misbehavior. In this article, we propose a secure blockchain-based data trading system for VCS named BTT system to address the above issues. In particular, we first integrate the blockchain-based data trading process with a lightweight privacy-preserving truth discovery algorithm to ensure the accuracy of sensing data while preserving data privacy. We then propose a gas-aware optimization mechanism to minimize the gas consumption of the data trading process. Finally, we carefully design a distributed judgment mechanism to regulate all participants to behave correctly in the data trading process. To demonstrate the practicability of our design, we implement a prototype of the BTT system deployed on an Ethereum test network and conduct extensive simulations. Saiyu Qi, Yong Qi 0001, Wei Wei 0006, Naixue Xiong |
ACM Trans. Embed. Comput. Syst. | 2 |
| 2024 | Secure Data Deduplication With Dynamic Access Control for Mobile Cloud StorageabstractData deduplication is of vital importance for mobile cloud computing to cope with the explosive growth of outsourced mobile data. In order to ensure the privacy of sensitive mobile data against an untrusted cloud, Message-Locked Encryption (MLE) has been proposed to enable deduplication over ciphertext. However, MLE prohibits data access control since it uses deterministic content-derived encryption keys. Recently, a lightweight rekeying-aware encrypted deduplication system (REED) has been proposed to achieve dynamic access control for secure data deduplication. However, REED is vulnerable to key-retaining attack and stub-retaining attack, which leads to insecure access revocation, and thus cannot support secure dynamic access control. In response, we present AC-Dedup, an encrypted deduplication storage system that supportssecure dynamic access controlfor mobile cloud storage. At the core of AC-Dedup are two novel encryption techniques namedmixed message locked encryptionandrandom stub re-encryptionto resist the two types of attacks, respectively. To the best of our knowledge, AC-Dedup is the first practical system that achieves secure data deduplication and secure dynamic access control simultaneously. We conduct security analysis and experimental evaluation on mobile device and cloud platform with real-world IoT datasets. The results show that AC-Dedup enables secure and efficient dynamic access control while preserving deduplication effectiveness. Saiyu Qi, Wei Wei 0006, Jianfeng Wang 0001, Shifeng Sun 0001, Leszek Rutkowski, Tingwen Huang, Janusz Kacprzyk, Yong Qi 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | Relation-consistency graph convolutional network for image super-resolution
Yue Yang 0022, Yong Qi 0001, Saiyu Qi |
Vis. Comput. | 3 |
| 2023 | EPPVChain: An Efficient Privacy-Preserving Verifiable Query Scheme for Blockchain DatabasesabstractBlockchain databases have been exploited in many applications to construct trust and share data among multiple participants. However, maintaining the entire blockchain locally will cause heavy communication and storage overhead for users with limited resources. Alternatively, the user could act as a light node that stores block headers only and delegates queries to full nodes that maintain the entire blockchain. However, introducing a light node raises several concerns about query integrity and privacy. In this paper, we propose EPPVChain, the first scheme that simultaneously achieves efficient, privacy-preserving and verifiable conjunctive query for blockchain databases. EPPVChain resorts to a novel symmetric cryptographic primitive named Symmetric Hidden Vector Encryption (SHVE), and deploys several new techniques to achieve the desired goals. In specific, we design a new SHVE-based authenticated data structure to support privacy-preserving verifiable conjunctive queries. We further propose two improved schemes to aggregate data records to optimize query performance. Finally, we propose a dual-chain key escrow protocol to securely escrow the symmetric key of SHVE without relying on any trusted third party. The security analysis and evaluation confirm EPPVChain’s ability to achieve query privacy and integrity with high efficiency. Jingxian Cheng, Saiyu Qi, Yong Qi 0001, Jianfeng Wang 0001, Di Wu 0062 |
TrustCom | 2 |
| 2023 | A Practical and Privacy-Preserving Vehicular Data Sharing Framework by Using BlockchainabstractAs the integration of the Internet of Vehicles and social networks, vehicular social networks (VSNs) are promising to boost the realization of intelligent transportation system. Recently, vehicular data privacy has been paid increasing attention in data sharing. Searchable encryption as a promising cryptographic primitive can be utilized to ensure vehicular data confidentiality without sacrificing data searchability. However, most vehicular data sharing schemes rely on centralized cloud servers, which are vulnerable to the single point of failure and distributed denial of service (DDoS) attacks. In this paper, we propose VehShare, a decentralized framework for privacy-preserving vehicular data sharing. We resort to the smart contract to implement a trusted platform for vehicles to share their encrypted vehicular data. To provide efficient access control, we design an authorization-based on-chain access control scheme with a lightweight cryptographic primitive. Moreover, we design a time synchronization-based non-interactive search token generation scheme to achieve efficient privacy-preserving search queries, while satisfying forward and backward security. We formally analyze the security of VehShare and extensive experiments demonstrate the efficiency of VehShare. Xu Yang 0033, Qiuhao Wang, Saiyu Qi, Yong Qi 0001 |
TrustCom | 4 |
| 2023 | Less payment and higher efficiency: A verifiable, fair and forward-secure range query scheme using blockchain
Xu Yang 0033, Jiahe Yu, Saiyu Qi, Qiuhao Wang, Jianfeng Wang 0001, Yanan Qiao, Yong Qi 0001 |
Comput. Networks | 3 |
| 2023 | FedMCSA: Personalized federated learning via model components self-attention
Yong Qi 0001, Saiyu Qi, Di Wu 0062, Qian Li 0024 |
Neurocomputing | 3 |
| 2023 | Blockchain-Aware Rollbackable Data Access Control for IoT-Enabled Digital TwinabstractThe rapid development of Internet of Things (IoT) enables digital twin (DT) technology to precisely represent a real product in a virtual space by generating a multitude of IoT data items to record many aspects of the product. To support various DT-based applications, the generated IoT data items need to be shared among multiple parties involving the lifecycle of the product, which raises increasing demand for data access control. The decentralization and tamper-proofing properties of blockchain enable it a promising technology to support immutability protection of shared IoT data items. Meanwhile, to protect the confidentiality of the shared IoT data items, attribute-based encryption (ABE) can be used as a common tool to construct a cryptographic enforced data access control scheme. However, its adoption has been severely hindered by the incompatibility between the immutability of blockchain and secure authority update of cryptographic enforced data access control. In this paper, a blockchain-aware rollbackable data access control scheme (Bdacs) is proposed to reconcile the above tension. Bdacs uses two novel encryption schemes named hierarchical encryption scheme and privacy-preserving rollback re-encryption scheme to realize secure dynamic access control while preserving the immutability of blockchain. We prove the security of Bdacs and evaluate it through theoretical comparison and experimental analysis to confirm its efficiency. This work can serve as a basis of development of future DT-based applications to enable privacy-preserving IoT data-sharing systems deployed on blockchain. Saiyu Qi, Xu Yang 0033, Jiahe Yu, Yong Qi 0001 |
IEEE J. Sel. Areas Commun. | 1 |
| 2023 | Understanding and defending against White-box membership inference attack in deep learning
Di Wu 0062, Saiyu Qi, Yong Qi 0001, Qian Li 0024, Bowen Cai 0004, Jingxian Cheng |
Knowl. Based Syst. | 2 |
| 2023 | TinyEnc: Enabling Compressed and Encrypted Big Data Stores With Rich Query SupportabstractEncryption and compression are two critical techniques to ensure data confidentiality and efficiency for a cloud-based data storage system, respectively. However, directly combing encryption and compression incurs substantial performance degradation. We propose TinyEnc, an encrypted data storage system for cloud-based key-value store, which supports encryption and compression simultaneously with rich query support. To reconcile encryption and compression without compromising performance, we first propose a new encrypted compression data structure to enable fine-grained access to compressed and encrypted key-value data. We then propose two new transforming mechanisms, namely orthogonal data dividing and hierarchical data padding, to transform a plaintext key-value table into the encrypted compression data structure in a privacy-preserving way. Finally, we craft order-revealing encryption (ORE) and symmetric searchable encryption (SSE) to design a new encrypted search index over the encrypted compression data structure to support rich types of data queries. We implement a prototype of TinyEnc on top of Cassandra. Besides, the evaluation result shows that TinyEnc increases the throughput by up to 7 times and compression ratio by up to 1.3 times with respect to previous works. Saiyu Qi, Jianfeng Wang 0001, Meixia Miao, Xiaofeng Chen 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Safety Warning! Decentralised and Automated Incentives for Disqualified Drivers Auditing in Ride-Hailing ServicesabstractSince 2011, the private ride-hailing companies Didi (2019), Uber (2019) and Lyft (2021) have expanded into more and more cities. These ride-hailing services (RHS) bring convenience to our life; however, at the same time they, also raise security concerns for users. For example, several recent news items show that a considerable number of registered drivers whose licenses have been revoked are still taking RHS orders on the respective platforms; this phenomenon directly leads to insecurity on part of its users and the bad reputation of the ride-hailing service provider (SP). The traditional solution to solve this problem is to periodically check the validity of the drivers’ licenses; however, it is a considerably time-consuming and costly process since the SPs have to manually interact with the governing authorities. Therefore, in this paper, we have presented an auditable self-sovereign identity system (named AudiSSI), which provides an efficient approach for the SPs to manage their registered drivers’ qualifications in a decentralized and automatic manner. Further, using smart contract technology, we propose a safety guarantee insurance in the form of an auditing contract to enable the RHS rider to check their driver's qualifications before the trip starts and get incentives once they detect a disqualified driver. We designed an incentive mechanism and have provided a game theoretical analysis. Finally, we implemented a prototype of AudiSSI and deployed it on Hyperledger Indy and Fabric to show that self-sovereign identity system for RHS driver with qualification auditing is efficient and technically feasible. Youshui Lu, Jingning Zhang, Yong Qi 0001, Saiyu Qi, Yue Li 0060, Hongyu Song, Yuhao Liu 0004 |
IEEE Trans. Mob. Comput. | 4 |
| 2022 | Practical Volume-Hiding Encrypted Multi-Maps with Optimal Overhead and BeyondabstractEncrypted multi-map (EMM), as a special case of structured encryption, has attracted extensive attention recently. However, most of EMM constructions reveal the real volumes of queried keys, which can be leveraged to launch leakage-abuse attacks, as demonstrated by Kellaris et al. in CCS 2016 and Kornaropoulos et al. in S&P 2021. Jianfeng Wang 0001, Shifeng Sun 0001, Saiyu Qi, Xiaofeng Chen 0001 |
CCS | 4 |
| 2022 | FLMJR: Improving Robustness of Federated Learning via Model Stability
Di Wu 0062, Yong Qi 0001, Saiyu Qi, Qian Li 0024 |
ESORICS (3) | 4 |
| 2022 | Stochastic Ghost Batch for Self-distillation with Dynamic Soft Label
Qian Li 0024, Saiyu Qi, Yong Qi 0001, Di Wu 0062, Yun Lin 0001, Jin Song Dong 0001 |
Knowl. Based Syst. | 3 |
| 2022 | Ants can Carry Cheese: Secure and Private RFID-Enabled Third-Party DistributionabstractRadio Frequency Identification (RFID) is a key emerging technology to improve data sharing in item distribution systems. By attaching RFID tags to items, item related data can be bound to items and participants involved in an item distribution system can directly store, access and update the data by interrogating the tags. Such a flexible data access manner of RFID technology, however, raises privacy and security concerns. In this article, we focus on a special item distribution system named RFID-enabled Third-party Distribution (RTD) system and identify two inherent security and privacy requirements. We further design a Secure RTD system called Ants, which uses cryptography to protect item messages carried by tags to satisfy both of the requirements while preserving the flexible data access manner of RFID technology. Ants introduces two new techniques named commitment accumulation and selective message proof for memory-constrained tags to carry long crypto-item messages. We conduct theoretical analysis and experiments to demonstrate the security and efficiency of Ants. Saiyu Qi, Yuanqing Zheng, Xiaofeng Chen 0001, Wei Wei 0006 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | DE-Sword: Incentivized Verifiable Tag Path Query in RFID-Enabled Supply Chain SystemsabstractIn this article, we propose Double Edged (DE)-Sword, an incentivized verifiable tag path query scheme. DE-Sword queries tag records stored across a path of participants within an RFID-enabled supply chain in a verifiable way. Different with previous works, DE-Sword works in a dishonest-data owner model in which participants are the owners of tag records and may be dishonest. DE-Sword introduces a novel double-edged reputation incentive mechanism to encourage participants to behave honestly; and couples it with cryptographic primitives to ensure query verifiability. We evaluate DE-Sword through game theory, security analysis, and performance evaluation. The game theory and security analysis shows that DE-Sword guarantees query verifiability. The evaluation results show that DE-Sword incurs low overhead in supply chain systems. Saiyu Qi, Yuanqing Zheng, Yue Li 0060, Xiaofeng Chen 0001, Jianfeng Ma 0001, Dongyi Yang, Yong Qi 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | Rphx: Result Pattern Hiding Conjunctive Query Over Private Compressed Index Using Intel SGXabstractDeploying data storage and query service in an untrusted cloud server raises critical privacy and security concerns. This paper focuses on the fundamental problem of processing conjunctive keyword queries over an untrusted cloud in a privacy-preserving manner. Previous tree-based searchable symmetric encryption (SSE) schemes, such asIBTreeandVBTree, can process conjunctive keyword queries in a secure and efficient way. However, these schemes cannot address “Result Pattern (RP)” leakage, which can be used to recover the keywords contained in a conjunctive keyword query. To combat this challenging problem, we propose a result pattern hiding conjunctive query scheme namedRphxusing Intel SGX. In particular, we first propose a new “SGX-aware” compressed index namedVIBTby combining variable-length bloom filter tree, matryoshka filter and online cipher. To achieveRPhiding, we then introduce a new tree-based SSE scheme namedRphxby deployingVIBTto Intel SGX. Security analysis shows thatRphxcan enhance the security requirements by hidingRPleakage under the IND-CKA2 security model. Experimental results show thatVIBTgains at least$30\times $improvement in storage efficiency andRphxcan achieve comparable search efficiency comparing with previous works. Ee-Chien Chang, Yong Qi 0001, Saiyu Qi, Pengfei Wu 0003, Jianfeng Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | Accelerating at the Edge: A Storage-Elastic Blockchain for Latency-Sensitive Vehicular Edge ComputingabstractThe application of blockchain to Vehicular Edge Computing (VEC) has attracted significant interests. As the Internet of Things plays an essential and fundamental role for data collecting, data analyzing, and data management in VEC, it is vital to guarantee the security of the data. However, the resource-constraint nature of edge node makes it challenging to meet the needs to maintain long life-cycle IoT data since vast volumes of IoT data quickly increase. In this paper, we propose Acce-chain, a storage-elastic blockchain based on different storage capacities at the edge. Acce-chain supports re-write operation to re-write the historical block with a newly generated block without breaking the hash links between the blocks. As a result, Acce-chain ensures that the hot data can be efficiently accessed at the edge without incurring much communication costs or increasing the total size of the chain. To guarantee the security of the re-write process, we propose a new cryptographic primitive named Dynamic Threshold Trapdoor Chameleon Hash (DTTCH). To guarantee the verifiability of query operation, we design a novel storage structure namedHybridStoreto ensure the verifiable query for on-chain/off-chain IoT data. As a result, Acce-chain achieves both authorized re-write and verifiable query simultaneously. We provide security analysis for the DTTCH scheme and the IoT data query algorithms. We evaluate Acce-chain through experiments and the results show that the performance of the re-write operation is feasible in real-world VEC settings, and the query efficiency can achieve up to several magnitudes better than which of the baseline. The results also demonstrate that Acce-chain can provide high service quality for the latency-sensitive VEC systems. Youshui Lu, Jingning Zhang, Yong Qi 0001, Saiyu Qi, Yuanqing Zheng, Yuhao Liu 0004, Hongyu Song, Wei Wei 0006 |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2022 | Say No to Price Discrimination: Decentralized and Automated Incentives for Price Auditing in Ride-Hailing ServicesabstractAs the most successful application of the sharing economy, ride-hailing service is popular worldwide and serves millions of users per day worldwide. Ride-hailing service providers (SPs) usually collect users’ personal data to improve their services via big data technologies. However, SPs may also use the collected user data to apply personalized prices to different users, which raises price fairness concerns. In this paper, we propose a smart price auditing system named Spas. Spas allows a user to purchaseFair Price Insurancein the form ofPrice Auditing Contract, then the price of ride-hailing service (RHS) order will be audited automatically once completed. According to the auditing result, the contract punishes misbehaving SPs and also compensates affected users automatically. By replacing an untrustworthy centralized auditor with carefully designed smart contracts, we construct a decentralized price auditing system which is trustworthy and transparent. We demonstrate a theoretical model for practical payment flows based on real RHS user data and we implement Spas in Hyperledger Fabric to show that decentralizing and automating price auditing for RHS with financial incentives is technically feasible. Youshui Lu, Yong Qi 0001, Saiyu Qi, Yue Li 0060, Hongyu Song, Yuhao Liu 0004 |
IEEE Trans. Mob. Comput. | 3 |
| 2022 | Secure and Efficient Item Traceability for Cloud-Aided IIoTabstractCloud computing is an essential technique to provide item traceability for industrial internet of things (IIoT) systems by providing item data sharing services. However, a malicious cloud server may prevent industrial participants from acquiring accurate traceability of items by providing inconsistent item data. To fix this issue, we propose Acics, an item data consistency auditing scheme in untrusted cloud services for cloud-aided IIoT systems. Acics presents two variants named S-Acics and L-Acics. S-Acics enables industrial participants to audit item data consistency for each item and circularly play the auditing role. L-Acics further enables industrial participants to audit item data consistency for a sampled subset of items while resisting data selection attack via a new separated storage mechanism. Finally, Acics integrates a fair payment mechanism built on smart contract to incentivize the cloud server to provide consistent item data access service for industrial participants. The experiment results show that our solution can audit item data consistency with reasonable cost. Saiyu Qi, Wei Wei 0006, Jingxian Cheng, Yuanqing Zheng, Zhou Su 0001, Jingning Zhang, Yong Qi 0001 |
ACM Trans. Sens. Networks | 1 |
| 2021 | Efficient Multi-client Order-Revealing Encryption and Its Applications
Chunyang Lv, Jianfeng Wang 0001, Shifeng Sun 0001, Yunling Wang, Saiyu Qi, Xiaofeng Chen 0001 |
ESORICS (2) | 5 |
| 2021 | Efficient Data Access Control With Fine-Grained Data Protection in Cloud-Assisted IIoTabstractThe Industrial Internet of Things (IIoT) has provided a promising opportunity to build digitalized industrial systems. A fundamental technology of IIoT is the radio-frequency identification (RFID) technique, which allows industrial participants to identify items and anchor time-series IoT data for them. They can further share the IoT data through the cloud service to enable information exchange and support critical decisions in production operations. Storing IoT data in the cloud, however, requires a data access control mechanism to protect sensitive business issues. Unfortunately, using traditional cryptographic access control schemes for time-series IoT data face severe efficiency and key leakage problems. In this article, we design a secure industrial data access control scheme for cloud-assisted IIoT. Our scheme enables participants to enforce fine-grained access control policies for their IoT data via ciphertext policy-attribute-based encryption (CP-ABE) scheme. Our scheme adopts a hybrid cloud infrastructure for participants to outsource expensive CP-ABE tasks to the cloud service with strong privacy guarantees. Importantly, our scheme guarantees a new privacy notion named item-level data protection for IoT data to prevent key leakage problem. We achieve these goals via several encryption and optimization techniques. Our performance assessments combine system implementation with large-scale emulations and confirm the security and efficiency of our design. Saiyu Qi, Youshui Lu, Wei Wei 0006, Xiaofeng Chen 0001 |
IEEE Internet Things J. | 1 |
| 2021 | Semi-supervised two-phase familial analysis of Android malware with normalized graph embedding
Qian Li 0024, Yong Qi 0001, Saiyu Qi, Xinxing Liu |
Knowl. Based Syst. | 4 |
| 2021 | Crypt-DAC: Cryptographically Enforced Dynamic Access Control in the CloudabstractEnabling cryptographically enforced access controls for data hosted in untrusted cloud is attractive for many users and organizations. However, designing efficient cryptographically enforced dynamic access control system in the cloud is still challenging. In this paper, we propose Crypt-DAC, a system that provides practical cryptographic enforcement of dynamic access control. Crypt-DAC revokes access permissions by delegating the cloud to update encrypted data. In Crypt-DAC, a file is encrypted by a symmetric key list which records a file key and a sequence of revocation keys. In each revocation, a dedicated administrator uploads a new revocation key to the cloud and requests it to encrypt the file with a new layer of encryption and update the encrypted key list accordingly. Crypt-DAC proposes three key techniques to constrain the size of key list and encryption layers. As a result, Crypt-DAC enforces dynamic access control that provides efficiency, as it does not require expensive decryption/re-encryption and uploading/re-uploading of large data at the administrator side, and security, as it immediately revokes access permissions. We use formalization framework and system implementation to demonstrate the security and efficiency of our construction. Saiyu Qi, Yuanqing Zheng |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | Adversarial Adaptive Neighborhood With Feature Importance-Aware Convex InterpolationabstractAdversarial Examples threaten to fool deep learning models to output erroneous predictions with high confidence. Optimization-based methods for constructing such samples have been extensively studied. While being effective in terms of aggression, they typically lack clear interpretation and constraint about their underlying generation process, which thus hinders us from leveraging the produced adversarial samples for model protection in the reverse direction. Hence, we expect them to repair bugs in the pre-trained models by produced additional training data equipped with strong attack ability rather than time-consuming full re-training from scratch. To address these issues, we first study the black-box behaviors and the intrinsic deficiency of neighborhood information in previous optimization-based adversarial attacks and defenses, respectively. Then we introduce a new method dubbed FeaCP, which uses correct predicted samples in disjoint classes to guide the generation of more explainable adversarial samples in the ambiguous region around the decision boundary instead of uncontrolled “blind spots”, via convex combination in a feature component-wise manner which takes the individual importance of feature ingredients into account. Our method incorporates the prior fact that for well-separated samples, the path connecting them would go through model's decision-boundary that lies in a low-density region, however, wherein adversarial examples are spread with high probability, thus having an impact on the ultimate trained model. In our work, the path is constructed by proposed inhomogeneous feature-wise convex interpolation rather than operating on sample-wise level, limiting the search space of FeaCP to obtain an adaptive neighborhood. Finally, we provide detailed insights and extend our method to adversarial fine-tuning using vicinity distribution to optimize the approximated decision boundary, and validate the significance of our FeaCP to model performance. The experimental results show that our method provides competitive performance on various datasets and networks. Qian Li 0024, Yong Qi 0001, Saiyu Qi, Yun Lin 0001, Jin Song Dong 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2021 | Cpds: Enabling Compressed and Private Data Sharing for Industrial Internet of Things Over BlockchainabstractInternet of Things (IoT) is a promising technology to provide product traceability for industrial systems. By using sensing and networking techniques, an IoT-enabled industrial system enables its participants to efficiently track products and record their status during production process. Current industrial IoT systems lack a unified product data sharing service, which prevents the participants from acquiring trusted traceability of products. Using emerging blockchain technology to build such a service is a promising direction. However, directly storing product data on blockchain incurs in efficiency and privacy issues in data management due to its distributed infrastructure. In response, we propose Cpds, a compressed and private data sharing framework, that provides efficient and private data management for product data stored on the blockchain. Cpds devises two new mechanisms to store compressed and policy-enforced product data on the blockchain. As a result, multiple industrial participants can efficiently share product data with fine-grained access control in a distributed environment without relying on a trusted intermediary. We conduct extensive empirical studies and demonstrate the feasibility of Cpds in improving the efficiency and security protection of product data storage on the blockchain. Saiyu Qi, Youshui Lu, Yuanqing Zheng, Yumo Li, Xiaofeng Chen 0001 |
IEEE Trans. Ind. Informatics | 1 |
| 2020 | PSM2: A Privacy-Preserving Self-sovereign Match-Making Platform
Youshui Lu, Saiyu Qi |
BlockSys | 4 |
| 2020 | MPTEE: bringing flexible and efficient memory protection to Intel SGXabstractIntel Software Guard extensions (SGX), a hardware-based Trusted Execution Environment (TEE), has become a promising solution to stopping critical threats such as insider attacks and remote exploits. SGX has recently drawn extensive research in two directions---using it to protect the confidentiality and integrity of sensitive data, and protecting itself from attacks. Both the applications and defense mechanisms of SGX have a fundamental need---flexible memory protection that updates memory-page permissions dynamically and enforces the least-privilege principle. Unfortunately, SGX does not provide such a memory-protection mechanism due to the lack of hardware support and the untrustedness of operating systems. Wenjia Zhao, Kangjie Lu, Yong Qi 0001, Saiyu Qi |
EuroSys | 4 |
| 2020 | Fast Consistency Auditing for Massive Industrial Data in Untrusted Cloud ServicesabstractCloud service is an essential technique to provide product traceability for industrial systems by providing data integration and sharing services. However, a malicious or corrupted cloud service may prevent industrial participants from acquiring accurate and consistent traceability of products. To fix this issue, we propose Acics, a fast consistency auditing scheme for massive industrial data in untrusted cloud services. Our scheme enables industrial participants to circularly play the role of the auditor to audit data consistency of products in real-time. Additionally, we design a separated storage mechanism to improve the auditing efficiency for massive industrial data by utilizing and tailoring ORAM. The evaluation indicates that our solution audits data consistency with reasonable cost. Jingxian Cheng, Saiyu Qi, Yong Qi 0001 |
ACM Great Lakes Symposium on VLSI | 2 |
| 2020 | Stochastic Batch Augmentation with An Effective Distilled Dynamic Soft Label RegularizerabstractData augmentation have been intensively used in training deep neural network to improve the generalization, whether in original space (e.g., image space) or representation space. Although being successful, the connection between the synthesized data and the original data is largely ignored in training, without considering the distribution information that the synthesized samples are surrounding the original sample in training. Hence, the behavior of the network is not optimized for this. However, that behavior is crucially important for generalization, even in the adversarial setting, for the safety of the deep learning system. In this work, we propose a framework called Stochastic Batch Augmentation (SBA) to address these problems. SBA stochastically decides whether to augment at iterations controlled by the batch scheduler and in which a ''distilled'' dynamic soft label regularization is introduced by incorporating the similarity in the vicinity distribution respect to raw samples. The proposed regularization provides direct supervision by the KL-Divergence between the output soft-max distributions of original and virtual data. Our experiments on CIFAR-10, CIFAR-100, and ImageNet show that SBA can improve the generalization of the neural networks and speed up the convergence of network training. Qian Li 0024, Yong Qi 0001, Saiyu Qi, Jie Ma 0001, Jian Zhang 0087 |
IJCAI | 4 |
| 2020 | Pbsx: A practical private boolean search using Intel SGX
Yong Qi 0001, Saiyu Qi, Wenjia Zhao, Youshui Lu |
Inf. Sci. | 3 |
| 2019 | Enabling Compressed Encryption for Cloud Based Big Data Stores
Saiyu Qi, Meixia Miao, Fuyou Zhang |
CANS | 2 |
| 2019 | Secure Data Deduplication with Resistance to Side-Channel Attacks via Fog Computing
Fuyou Zhang, Saiyu Qi, Haoran Yuan |
ICA3PP (2) | 2 |
| 2019 | LSTM-Based with Deterministic Negative Sampling for API SuggestionabstractModern programming relies on a large number of fundamental APIs, but programmers often take great effort to remember names and the usage of APIs when coding, and repeatedly search the related API documents or Q&A websites (e.g. Stack Overflow). To improve the programming efficiency, we present a Java API suggestion model called APIHelper which learns API sequence pattern via the Long Short-Term Memory (LSTM) network, then provides API suggestion based on the program context. Comparing with statistical methods (e.g. Hidden Markov Model (HMM), N-gram), which require establishing one specific model for each class, we propose Deterministic Negative Sampling (DNS) to make API suggestion for a large number of Java classes by one single end-to-end LSTM. To verify this approach, we make API suggestion for 50,000 Java classes and evaluate it with accuracy and top-K accuracy. The results show that APIHelper outperforms other research works both on accuracy and computation efficiency. Jinpei Yan, Yong Qi 0001, Qifan Rao, Saiyu Qi |
Int. J. Softw. Eng. Knowl. Eng. | 5 |
| 2017 | SecretSafe: A Lightweight Approach against Heap Buffer Over-Read AttackabstractSoftware memory disclosure attacks, such as buffer over-read, often work quietly and would cause secret data leakage. The well-known OpenSSL Heartbleed vulnerability leaked out millions of servers' private keys, which caused most of the Internet services insecure at that time. Existing solutions are either hard to apply to large code bases (e.g., through formal verification [20] or symbolic execution [8] on program code), or too heavyweight (e.g., by involving a hypervisor software [23], [24] or a modified operating system kernel [17]). In this paper, we propose SecretSafe, a lightweight and easy-to-use system which leverages the traditional x86 segmentation mechanism to isolate the application secrets from the remaining data. Software developers could prevent the secrets from being leaked out by simply declaring the secret variables with SECURE keyword. Our customized compiler will automatically separate the secrets from the remaining non-secret data with an isolated memory segment. Any legal instructions that have to access the secrets will be automatically instrumented to enable accesses to the isolated segment. We have implemented a SecretSafe prototype with the open source LLVM compiler framework. The evaluation shows that SecretSafe is both secure and efficient. Xiaoguang Wang 0003, Yong Qi 0001, Saiyu Qi, Peijian Wang |
COMPSAC (1) | 4 |
| 2017 | Double-Edged Sword: Incentivized Verifiable Product Path Query for RFID-Enabled Supply ChainabstractQuerying the path information of individual products in a supply chain is key to many applications. RFID (Radio-Frequency IDentification) is a main technology to enable product path information query today. With RFID technology, supply chain participants can efficiently track products in transit and record their production information in databases. In this paper, we investigate the following question: how can we conduct privacy-preserving product path information query with verifiability on an RFID-enabled distributedsupplychain?WeaddressthisquestionwithDouble Edged(DE)-Sword,anincentivizedverifiablequerysystem. DESword introduces a novel double-edged reputation incentive mechanism to encourage supply chain participants to behave; and couples it with cryptographic primitives and careful protocol design. We evaluate DE-Sword through security analysis and performance experiments. The security analysis shows that DE-Sword guarantees both verifiability and privacy. The experiment results show that DE-Sword achieves low overhead in RFID-enabled supply chain applications. Saiyu Qi, Yuanqing Zheng, Xiaofeng Chen 0001, Jianfeng Ma 0001, Yong Qi 0001 |
ICDCS | 1 |
| 2016 | Secure and Private RFID-Enabled Third-Party Supply Chain SystemsabstractRadio Frequency Identification (RFID) is a key emerging technology for supply chain systems. By attaching RFID tags to various products, product-related data can be efficiently indexed, retrieved and shared among multiple participants involved in an RFID-enabled supply chain. The flexible data access property, however, raises security and privacy concerns. In this paper, we target at security and privacy issues in RFID-enabled supply chain systems. We investigate RFID-enabled Third-party Supply chain (RTS) systems and identify several inherent security and efficiency requirements. We further design a Secure RTS system called SRTS, which leverages RFID tags to deliver computation-lightweight crypto-IDs in the RTS system to meet both the security and efficiency requirements. SRTS introduces a Private Verifiable Signature (PVS) scheme to generate computation-lightweight crypto-IDs for product batches, and couples the primitive in RTS system through careful design. We conduct theoretical analysis and experiments to demonstrate the security and efficiency of SRTS. Saiyu Qi, Yuanqing Zheng, Mo Li 0001, Li Lu 0001, Yunhao Liu 0001 |
IEEE Trans. Computers | 1 |
| 2016 | Scalable Industry Data Access Control in RFID-Enabled Supply ChainabstractBy attaching RFID tags to products, supply chain participants can identify products and create product data to record the product particulars in transit. Participants along the supply chain share their product data to enable information exchange and support critical decisions in production operations. Such an information sharing essentially requires a data access control mechanism when the product data relate to sensitive business issues. However, existing access control solutions are ill-suited to the RFID-enabled supply chain, as they are not scalable in handling a huge number of tags, introduce vulnerability to the product data, and perform poorly to support privilege revocation of product data. We present a new scalable industry data access control system that addresses these limitations. Our system provides an item-level data access control mechanism that defines and enforces access policies based on both the participants' role attributes and the products' RFID tag attributes. Our system further provides an item-level privilege revocation mechanism by allowing the participants to delegate encryption updates in revocation operation without disclosing the underlying data contents. We design a new updatable encryption scheme and integrate it with ciphertext policy-attribute-based encryption to implement the key components of our system. Saiyu Qi, Yuanqing Zheng, Mo Li 0001, Yunhao Liu 0001, Jinli Qiu |
IEEE/ACM Trans. Netw. | 1 |
| 2014 | Scalable Data Access Control in RFID-Enabled Supply ChainabstractBy attaching RFID tags to products, supply chain participants can identify products and create product data to record the product particulars in transit. Participants along the supply chain share their product data to enable information exchange and support critical decisions in production operations. Such an information sharing essentially requires a data access control mechanism when the product data relates to sensitive business issues. However, existing access control solutions are ill suited to the RFID-enabled supply chain, as they are not scalable in handling a huge number of tags, introduce vulnerability to the product data, and performs poorly to support privilege revocation of product data. We present a new scalable data access control system that addresses these limitations. Our system provides an item-level data access control mechanism that defines and enforces access policies based on both the participants' role attribute and the products' RFID tag attribute. Our system further provides an item-level privilege revocation mechanism by allowing the participants to delegate encryption updates in revocation operation without disclosing the underlying data contents. We design a new updatable encryption scheme and integrate it with Cipher text Policy-Attribute Based Encryption (CP-ABE) to implement the key components of our system. Saiyu Qi, Yuanqing Zheng, Mo Li 0001, Yunhao Liu 0001, Jinli Qiu |
ICNP | 1 |
| 2014 | COLLECTOR: A secure RFID-enabled batch recall protocolabstractBatch recall is a practically important problem for most industry manufacturers. The batches of products which contain flawed parts need to be recalled by manufacturers in time to prevent further economic and health loss. Accurate batch recall could be a challenging issue as flawed parts may have already been integrated into a large number of products and distributed to customers. The recent development of Radio Frequency Identification (RFID) provides us a promising opportunity to implement batch recall in an accurate and efficient way. RFID-enabled batch recall provides us the opportunity to further enhance the security of batch recall operation, allowing us to achieve recognition of problematic products, privacy preserving of production pattern, recall authentication and non-repudiation, etc. In this paper, we thoroughly study the security aspects and identify the unique requirements in RFID-enabled batch recall. We propose a practically secure protocol, COLLECTOR, to enable accurate, secure and efficient RFID batch recall. Saiyu Qi, Yuanqing Zheng, Mo Li 0001, Li Lu 0001, Yunhao Liu 0001 |
INFOCOM | 1 |
| 2012 | Achieving Private, Scalable, and Precise Data Collection in Wireless Sensor NetworksabstractWireless Sensor Networks (WSN) become increasingly popular to collect data over a large area. Given the collected data set, the network manager can extract various kinds of aggregate statistics from the set to characterize the physical space. On the collection of the data, three requirements should be imposed: (1) Privacy: as sensor nodes are source limited and often deployed in an open environment, the sensed data suffer from privacy vulnerabilities. Secure mechanism should be provided to protect data privacy, (2) Communication efficiency: collecting data from large-scale sensor networks often involves large-volume data generation and transmission, which may quickly consume the energy of the WSN. To prolong the lifetimes of the sensor nodes, the sensed data should be transmitted in lightweight manner, (3) Accuracy: the sensed data should be recovered accurately at the base station (BS) so that the manager can manipulate them freely to achieve any precise aggregate statistic he prefers. To satisfy these requirements, we propose two novel privacy-preserving data collection schemes based on compressive sensing techniques. Our schemes address the privacy, communication efficiency and accuracy issues simultaneously. Detailed theoretical analysis and simulation results confirm the high performance of the proposed schemes. Saiyu Qi, Zhenjiang Li 0001, Yunhao Liu 0001 |
ICPADS | 1 |
| 2012 | BEST: A Bidirectional Efficiency-Privacy Transferable Authentication Protocol for RFID-Enabled Supply ChainabstractRadio Frequency Identification (RFID) technique is gaining increasing popularity in supply chain for the product management. By attaching a tag to each product, a reader can employ an authentication protocol to interrogate the tag's information for verification, which facilitates the automatic processing and monitoring of products in many applications. However, most current solutions cannot be directly used as they cannot balance the tradeoff between the privacy and efficiency for individual parties. In this paper, we design a bidirectional efficiency-privacy transferable (BEST) authentication protocol to address this issue. In a relatively secure domain, BEST works in an efficient manner to authenticate batches of tags with less privacy guarantee. Once the tags flow into open environment, BEST can migrate to provide stronger privacy protection to the tags with moderate efficiency degradation. The analytic result shows that BEST can well adapt to the RFID-enabled supply chain. Saiyu Qi, Li Lu 0001, Zhenjiang Li 0001, Mo Li 0001 |
ICPADS | 1 |
| 2011 | MAP: Authenticating Multiple-TagsabstractThe prevalence of Radio Frequency Identification (RFID) technology requires Privacy-Preserving Authentication (PPA) protocols to combat the privacy leakage during authentication. Existing PPA protocols employ the per-tag authentication, in which the reader has to sequentially authenticate the tags within the detecting region. Such a processing pattern becomes a bottleneck in current RFID enabled systems, especially for batch-type processing applications. In this paper, we propose an efficient authentication protocol, which leverages the collaboration among multiple tags for accelerating the authentication speed. We also find that the collision, usually considered as a negative factor, is a helpful media to enable collaborative authentication among tags. Our protocol, termed as Multiple-tags privacy-preserving Authentication Protocol (MAP), authenticates a batch of tags concurrently with strong privacy protection and high efficiency guarantee. The analytical and simulation results show that the efficiency of MAP is better than O(logN) and asymptotically approaches O(1). Qingsong Yao, Jinsong Han, Saiyu Qi |
MASS | 3 |
| 2007 | Energy Efficient Multi-rate Based Time Slot Pre-schedule Scheme in WSNs for Ubiquitous EnvironmentabstractNowadays, smart spaces occupy an essential part of ubiquitous computing environment. The spaces integrated with wireless sensors networks, actuators and context-aware services become part of our daily life. Smart spaces are equipped with a large number of wireless sensors that aim to collect large quantities of context information, during the process, there exists a large amount of collisions and energy consumption. Therefore, this paper provides a novel multi-rate based local framing pre-schedule scheme to further reduce collisions and improve energy efficiency in CSMA/TDMA hybrid MAC layer of wireless sensor network. This MAC combines CSMA and TDMA functionalities together while obviates their shortcomings. Having been assigned, slot 0 is preserved as the pre-schedule slot, to inform neighbor nodes the schedule of the senders. During the pre-schedule slot, each node knows exactly the schedule of other neighbor nodes. Multi-rate and power scaling are applied to achieve further energy saving by adpoting an acceptable rate rather than maximum rate. Data rate is dynamically adjusted according to the traffic load of sending nodes, in an energy efficient data rate, to save energy. Being compared with Z-MAC in terms of performances, local framing pre-schedule and multi-rate in this experiment achieved further energy efficiency. Index Terms--MAC, CSMA, TDMA, Mult-Rate, Wireless Sensor Networks Wei Wei 0006, Yong Qi 0001, Saiyu Qi, Di Hou, Wei Wang 0015, Min Xi, Qingsong Yao |
APSCC | 3 |