Haiyan Wang 0009

dblp:27/59-9 · DBLP profile ↗
← Back
23ranked-venue papers
2as first author
22since 2021 · last 2026
0000-0002-5702-9897ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 7 since 2021Databases, data management, data science and information retrieval · 7 · 1 first-author · 7 since 2021Artificial intelligence and machine learning · 6 · 1 first-author · 6 since 2021Computer networks · 5 · 1 first-author · 5 since 2021Theory of computation · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 SecKQL-Agent: A Real-World APT29 Events Benchmark and Framework for Reliable Text-to-KQL in Security Analytics
Haiyan Wang 0009, Shaofang Long, Yan Jia 0001, Zhaoquan Gu
DASFAA (6)2
2026 FSSA: Fast secure single-server aggregation with optimal communication rounds
Saif M. Al-Kuwari, Haiyan Wang 0009, Xingfu Yan, Aiting Yao
Comput. Networks3
2026 An interpretable intrusion detection framework based on ensemble neural networks for dynamic network environments
Haiyan Wang 0009, Liyi Zeng, Rongxin Hu, Zhaoquan Gu
Expert Syst. Appl.2
2026 Attribute-Based Signatures With Constant-Size Signatures for Resource-Constrained IoT Applications
abstract
The rapid expansion of the Internet of Things (IoT) has introduced critical security challenges in authentication, data integrity, and privacy preservation. Traditional digital signature schemes, such as RSA and ECDSA, rely on identity-based trust models, which face scalability bottlenecks, lack fine-grained access control, and pose privacy risks in IoT environments. Attribute-based signatures (ABS) offer a promising solution by allowing devices to sign data only if their attributes satisfy a predefined policy, without revealing their exact identity. However, most existing ABS constructions rely on pairing-based cryptography, which is vulnerable to quantum computer attacks, while lattice-based ABS schemes often suffer from either large signature sizes or dependence on non-interactive zero-knowledge (NIZK) proofs. In this paper, we propose an efficient lattice-based ABS scheme that eliminates the need for NIZK proofs while achieving constant-size signatures. Our construction leverages the lattice-based vector commitment technique to achieve quantum resistance while reducing signature size to a constant independent of the number of attributes, significantly improving efficiency compared to prior works. Experimental evaluations confirm that our scheme outperforms existing lattice-based ABS in both computational cost and signature size, particularly for large attribute sets and deep policy circuits. Our results pave the way for practical ABS deployment in resource-constrained IoT applications, such as secure firmware updates, industrial access control, and vehicular networks.
Haiyan Wang 0009, Xingfu Yan
IEEE Internet Things J.2
2026 FreeFL: Privacy-Preserving Cross-Silo Federated Learning Without Third Party
abstract
Cross-silo federated learning (FL) allows organizations to collaboratively train machine learning (ML) models by aggregating local gradients from clients without sharing their training data. Despite its merits, it suffers from privacy concerns due to the leakage of local gradients. A popular approach is to have clients mask their local gradients using homomorphic encryption (HE). However, this not only results in a reliance on a trusted third party (TTP), but also leads to significant computational and communication overhead. In addition, in existing cross-silo FL protocols, the aggregation operation is performed by a centralized aggregator, raising new security issues. One of these issues involves verifying the correctness of the aggregated results returned by the aggregator. The aggregator has been removed in the cross-device setting by leveraging blockchain technology, but not in the cross-silo setting. In this paper, we propose FreeFL, an efficient privacy-preserving cross-silo FL that eliminates the need for the TTP and aggregator, as well as achieves the optimal communication rounds. The high-level idea behind FreeFL is to customize alightweightdecentralized symmetric encryption with additive homomorphism for cross-silo FL. To this end, we design an efficient decentralized multiparty symmetric encryption (DMSE) scheme and twolightweightmultiparty computation protocols. We evaluate the performance of FreeFL, and the experimental results indicate that FreeFL exhibits high efficiency in both computation and communication. Additionally, we conduct experimental comparisons between FreeFL and other existing HE-based cross-silo FL protocols to show that FreeFL achieves significant computational efficiency improvements.
Jiahui Wu 0001, Haiyan Wang 0009, Xingfu Yan
IEEE Trans. Dependable Secur. Comput.3
2026 Privacy-Preserving Federated Learning Scheme With Mitigating Model Poisoning Attacks: Vulnerabilities and Countermeasures
abstract
The privacy-preserving federated learning schemes based on the setting of two honest-but-curious and non-colluding servers offer promising solutions in terms of security and efficiency. However, our investigation reveals that these schemes still suffer from privacy leakage when considering model poisoning attacks from malicious users. Specifically, we demonstrate that the privacy-preserving computation process for defending against model poisoning attacks inadvertently leaks privacy to one of the honest-but-curious servers, enabling it to access users' gradients in plaintext. To address this issue, we propose an enhanced privacy-preserving and Byzantine-robust federated learning (PBFL) framework that simultaneously achieves privacy, robustness, and efficiency. Central to our design is a novel Byzantine-tolerant aggregation strategy that defends against both conventional and adaptive poisoning attacks. It integrates normalization judgment, cosine similarity computation, and adaptive user weighting, with a dual-scoring trust mechanism and outlier suppression for stealthy attacks. In addition, we develop two privacy-preserving subroutines, namely secure normalization judgment and secure cosine similarity measurement, which operate over encrypted gradients using a trapdoor fully homomorphic encryption (FHE) scheme, ensuring both confidentiality and robust aggregation correctness. Theoretical analyses confirm that our scheme guarantees security, convergence, and efficiency even with malicious users and one malicious server. Extensive experiments demonstrate that our method effectively breaks prior privacy attacks, maintains high accuracy under diverse poisoning strategies, and significantly reduces computation and communication overhead compared to state-of-the-art PBFL schemes.
Jiahui Wu 0001, Tiecheng Sun, Haiyan Wang 0009, Weizhe Zhang
IEEE Trans. Dependable Secur. Comput.4
2025 SemantiHunt: A New Behavioral Semantics-Driven Method for Network Threat Hunting
Haiyan Wang 0009, Rui Zong, Aiting Yao, Zhaoquan Gu
ADMA (1)1
2025 Adaptive Incremental Provenance Analysis for Trustworthy Federated Learning
Aiting Yao, Chengzu Dong, Shantanu Pal, Frank Jiang 0001, Haiyan Wang 0009, Wenying Feng 0003, Lichen Liu, Zhaoquan Gu
ADMA (2)5
2025 An Enhanced Knowledge Graph Embedding for Small-Scale Sparse Knowledge Graph
Yushun Xie, Haiyan Wang 0009, Runnan Tan, Zhaoquan Gu
DASFAA (3)2
2025 PAC-MC: An Efficient Password-Based Access Control Framework for Time Sequence Aware Media Cloud
abstract
Cloud storage makes it easier for users to access and share data remotely, but it often requires integration with cryptographic technologies to address consumer-oriented applications, such as fine-grained data access, secure data sharing and retrieval. This paper focuses on the fine-grained access problem of media applications based on time sequence, that is, certain critical media applications based on time sequences should ideally be accessible only to authorized clients. The traditional keyword-based searchable encryption (SE) allows effective search and access over encrypted data while preserving data privacy, but most existing solutions do not support temporal access control (i.e., a mechanism that grants access permissions to users within a specified time range). In this paper, we propose PAC-MC, an efficient password-based access control framework for media cloud relying on content control with the time sequence attribute. PAC-MC not only supports multi-keyword search using any monotonic boolean formulas but also allows media owners to control content-encryption keys for different time periods with an updatable password. Furthermore, it supports the self-retrieval of content-encryption keys. In addition, PAC-MC is provably secure under the standard model. Finally, the detailed performance evaluation results and experimental comparisons indicate that PAC-MC is very efficient and outperforms the previous solutions in terms of computation, communication, and storage costs.
Haiyan Wang 0009, Xiaoxiong Zhong, Bin Xiao 0001, Yuanyuan Yang 0001
IEEE Trans. Mob. Comput.1
2024 Semantic-Integrated Online Audit Log Reduction for Efficient Forensic Analysis
Wenhao Liao, Haiyan Wang 0009, Zhaoquan Gu, Jianye Yang 0001
ADMA (6)3
2024 CDGM: Controllable Dataset Generation Method for Cybersecurity
Yushun Xie, Haiyan Wang 0009, Runnan Tan, Zhaoquan Gu
ADMA (6)2
2024 Reinforced Negative Sampling for Knowledge Graph Embedding
Yushun Xie, Haiyan Wang 0009, Le Wang 0008, Jianxin Li 0001, Zhaoquan Gu
DASFAA (4)2
2024 P-I2Prange: An Automatic Construction Architecture for Scenarios in I2P Ranges
abstract
Anonymous networks play a crucial role in preserving information privacy, yet simultaneously spark technical conflicts and gamesmanship between their maintainers and regulatory authorities. To solve the above conflicts and economic losses in real networks, it is imminent to realize adversarial exercises in anonymous networks and validate new technologies and scenarios in the cyber range. It is well known that the two dominant types of anonymity networks are Tor and Invisible Internet Project (I2P). This paper establishes a cyber range based on I2P to realize a task-driven automated scenario construction technique. The proposed task-driven automated scenario construction technique can solve the problem of decoupling between business scenarios and I2P cyber range network infrastructure. Specifically, our approach allows users to upload models/executable code to extend flexibly and fine-grained control I2P nodes, protocols, and traffic behavior characteristics. Then it empowers users to define application scenarios as needed, enabling them to handle intricate business scenarios programmatically. Therefore, it further supports diverse adversarial exercises and the validation of new technologies and scenarios within the dark web.
Runnan Tan, Qingfeng Tan, Haiyan Wang 0009, Yushun Xie, Peng Zhang 0001
IJCNN3
2024 Fully collusion resistant trace-and-revoke functional encryption for arbitrary identities
Saif M. Al-Kuwari, Haiyan Wang 0009, Xingfu Yan
Theor. Comput. Sci.3
2024 Comments on "VERSA: Verifiable Secure Aggregation for Cross-Device Federated Learning"
abstract
Federated learning (FL) allows a large number of users to collaboratively train machine learning (ML) models by sending only their local gradients to a central server for aggregation in each training iteration, without sending their raw training data. The main security issues of FL, that is, the privacy of the gradient vector and the correctness verification of the aggregated gradient, are gaining increasing attention from industry and academia. To protect the privacy of the gradient, a secure aggregation was proposed; to verify the correctness of the aggregated gradient, a verifiable secure aggregation that requires the server to provide a verifiable aggregated gradient was proposed. In 2021, Hahn et al proposed VERSA, a verifiable secure aggregation. However, in this paper, we will point out a flaw in VERSA, which indicates that VERSA does not work. To address the flaw, we present several approaches with different advantages and disadvantages. We hope that by identifying the flaw, similar errors can be avoided in future designs of verifiable secure aggregation.
Haiyan Wang 0009, Xingfu Yan
IEEE Trans. Dependable Secur. Comput.2
2024 Public Trace-and-Revoke Proxy Re-Encryption for Secure Data Sharing in Clouds
abstract
Proxy re-encryption (PRE), as a promising cryptographic primitive for secure data sharing in clouds, has been widely studied for decades. PRE allows the proxies to use the re-encryption keys to convert ciphertexts computed under the delegator’s public key into ones that can be decrypted using the delegatees’ secret keys, without knowing anything about the underlying plaintext. This delegable property of decryption rights enables flexible cloud data sharing, but it raises an important issue: if some proxies reveal their re-encryption keys, or collude with some delegatees to create a pirate decoder, then anyone who gains access to the pirate decoder can decrypt all ciphertexts computed under the delegator’s public key without the delegator’s permission. This paper opens up a potentially new avenue of research to address the above (re-encryption) key abuse problem by proposing the first public trace-and-revoke PRE system, where the malicious delegatees and proxies involved in the generation of a pirate decoder can be identified by anyone who gains access to the pirate decoder, and their decryption capabilities can subsequently be revoked by the content distributor. Our construction is multi-hop, supports user revocation and public (black-box) traceability, and achieves significant efficiency advantages over previous constructions. Technically, our construction is a generic transformation from inner-product functional PRE (IPFPRE) that we introduce to trace-and-revoke PRE. In addition, we instantiate our generic construction of trace-and-revoke PRE from the Learning with Errors (LWE) assumption, which was widely believed to be quantum-resistant. This is achieved by proposing the first LWE-based IPFPRE scheme, which may be of independent interest. Finally, we conduct a comprehensive performance evaluation of our LWE-based trace-and-revoke PRE scheme, and the experimental results show that the proposed LWE-based trace-and-revoke PRE scheme is practical and outperforms current state-of-the-art traceable PRE schemes.
Haiyan Wang 0009, Willy Susilo, Xingfu Yan, Xiaofan Zheng
IEEE Trans. Inf. Forensics Secur.2
2024 Key-Policy Attribute-Based Encryption With Switchable Attributes for Fine-Grained Access Control of Encrypted Data
abstract
Fine-grained access control systems facilitate granting differential access rights to a set of users and allow flexibility in specifying the access rights of individual users. As an important fine-grained access control technique, key-policy attribute-based encryption (KP-ABE) has been introduced to achieve fine-grained access control over encrypted data, where each ciphertext is associated with an attribute set such that users satisfying the attribute set can decrypt the ciphertext. In the real-world application scenarios of KP-ABE, various situations such as users leaving the system, compromise of users’ private keys, and business requirements frequently occur, necessitating the revocation of decryption rights for large-scale users. To address the user revocation, numerous revocable KP-ABE schemes have been proposed. However, existing revocable KP-ABE schemes are vulnerable to quantum computer attacks. More importantly, existing solutions fail to address the user addition, where users capable of decrypting certain ciphertexts would like to grant decryption rights to others; this is a highly common requirement, such as changes in user decryption permissions and business needs. This paper explores a potentially new avenue of research to address the above issues by introducing a novel cryptographic primitive called key-policy ABE with switchable attributes (KP-ABE-SA). In the KP-ABE-SA system, each ciphertext linked to an attribute set can be transformed into one associated with another (distinct) attribute set, enabling both user revocation and addition. Furthermore, to withstand quantum computer attacks, we construct a KP-ABE-SA scheme based on the Learning with Errors (LWE) assumption, which is widely believed to be quantum-resistant. Finally, we conduct a comprehensive performance evaluation of our LWE-based KP-ABE-SA scheme, and the experimental results show that the proposed LWE-based KP-ABE-SA scheme is efficient and practical.
Haiyan Wang 0009, Xingfu Yan, Jiahui Wu 0001
IEEE Trans. Inf. Forensics Secur.2
2024 Re-PAEKS: Public-Key Authenticated Re-Encryption With Keyword Search
abstract
The rapid development of cloud computing and the exponential growth of data have led to an increasing demand for secure data sharing and querying. Proxy re-encryption (PRE) addresses the issue of secure data sharing, since it enables controlled data sharing and delegation of access rights without revealing the actual content of the encrypted data stored in the cloud; public-key encryption with keyword search (PEKS) tackles the issue of secure data querying, since it allows resource-constrained clients to effectively search over encrypted data stored in the cloud. As a combination of PRE and PEKS, proxy re-encryption with keyword search (PRES) enables both secure data sharing and querying. Despite their merits, existing PRES schemes are vulnerable to quantum computer attacks, keyword guessing attacks (KGAs), or incur high end-to-end delay. To address these vulnerabilities, this paper introduces a novel cryptographic primitive called public-key authenticated re-encryption with keyword search (Re-PAEKS), which combines the strengths of PRE and public-key authenticated encryption with keyword search (PAEKS). Our Re-PAEKS has low end-to-end delay, and is resistant to both quantum computer attacks and KGAs. Technically, we improve the previous lattice-based PAEKS scheme and achieve the delegation of access rights by exploiting the lattice-based identity-based encryption (IBE) techniques, which are widely believed to be secure against quantum computer attacks. In addition, we formalize the security model of the Re-PAEKS and prove its security in the random oracle model. Finally, we conduct a comprehensive performance evaluation of the Re-PAEKS, and the experimental results show that the Re-PAEKS is computationally efficient and practical. Particularly, the Re-PAEKS enjoys the lowest end-to-end delay compared to current state-of-the-art PRES.
Haiyan Wang 0009, Xingfu Yan
IEEE Trans. Mob. Comput.2
2023 ABAEKS: Attribute-Based Authenticated Encryption With Keyword Search Over Outsourced Encrypted Data
abstract
The widespread adoption of cloud computing and the exponential growth of data highlight the need for secure data sharing and querying. Attribute-based keyword search (ABKS) has emerged as an efficient means of searching encrypted data stored in the cloud. However, existing ABKS schemes incur high end-to-end delay and are vulnerable to quantum computer attacks and/or (insider) keyword guessing attacks (KGA). To address these vulnerabilities, this paper introduces a new concept called attribute-based authenticated encryption with keyword search (ABAEKS) and proposes an efficient ABAEKS scheme. Our ABAEKS has low end-to-end delay, and is resistant to both quantum computer attacks and (insider) KGA. In addition, we formalize the security model of ABAEKS system and prove its security in the random oracle model. Finally, we conduct a comprehensive performance evaluation of ABAEKS, and the experimental results show that our ABAEKS is computationally efficient and outperforms current state-of-the-art ABKS schemes.
Haiyan Wang 0009, Changlu Lin, Xingfu Yan
IEEE Trans. Inf. Forensics Secur.2
2022 Generic Construction of Trace-and-Revoke Inner Product Functional Encryption
Saif M. Al-Kuwari, Haiyan Wang 0009, Weihong Han
ESORICS (1)3
2022 An Efficient Ciphertext-Policy Attribute-Based Encryption Scheme Supporting Collaborative Decryption With Blockchain
abstract
In the last few decades, ciphertext-policy attribute-based encryption (CP-ABE) technology has attracted great interest, since it can provide fine-grained, flexible, and access control for sensitive data to implement a high secure and efficient data-sharing mechanism. In this article, based on the linear secret sharing scheme (LSSS), an efficient scheme is proposed to realize a collaborative decryption function. For any user group, when the user’s attribute set cannot access the ciphertext alone, the private key of other users in the same group can be used for collaborative decryption with the permission of the data owner. Our scheme uses the LSSS matrix that can significantly reduce the computation and storage overhead when comparing with the existing schemes. Then, a multiauthorization model is created based on the Bohen–Lynn–Shacham technology in order to solve the key-management issue. Finally, we implemented the specific functions of the framework through JAVA, and built a private chain to verify the feasibility of data transfer between users.
Ying He 0006, Haiyan Wang 0009, Victor C. M. Leung, F. Richard Yu, Zhong Ming 0001
IEEE Internet Things J.2
2019 An Efficient Attribute-Based Encryption Scheme With Policy Update and File Update in Cloud Computing
abstract
Recently, more and more users and enterprises have entrusted data storage and platform construction to proxy cloud service provider (PCSP) through cloud technology. Under this background, the attribute-based encryption (ABE) mechanism is an alternative to fill the drawbacks of the traditional encryption through flexible fine-grained access policy and collusion prevention. However, there exist some security issues when the access policy and file need to be updated in practical applications. And the ABE has the problems of excessive computation and storage costs. In this article, an efficient ciphertext-policy ABE scheme with policy update and file update is proposed in cloud computing. The ciphertext components generated by first encryption can be shared when the policy update and file update happens. It reduces the storage and communication costs of the client, and the computational cost of the PCSP. Moreover, the proposed scheme is proved to be secure under the assumption of decision q-parallel bilinear Diffie–Hellman exponent (BDHE). Finally, experimental simulation shows that the proposed scheme is highly efficient in terms of policy update and file update.
Jianqiang Li 0001, Shulan Wang, Haiyan Wang 0009, Huihui Wang 0001, Jianyong Chen, Zhu-Hong You
IEEE Trans. Ind. Informatics4