Yufan Fu

dblp:284/4031 · DBLP profile ↗
← Back
10ranked-venue papers
2as first author
10since 2021 · last 2026
0000-0001-8276-743XORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Structured policy modeling and context-aware generation for multi-jurisdictional compliance in global software systems
Zhixian Zhuang, Xiaodong Lee, Aiyao Zhang, Jiuqi Wei, Yufan Fu, Botao Peng
Inf. Softw. Technol.5
2025 DeFiAD: A Unified Method for Early-Stage Domain Abuse Detection Through Automated Deep Feature Interaction
abstract
As a key infrastructure of the Internet, the Domain Name System (DNS) is frequently abused because of its open-ness, which makes early detection of domain abuse a critical task in cybersecurity. However, most existing methods rely on external data sources such as webpage content or long-term DNS resolution logs, which are unavailable at the registration stage, delaying detection and limiting adaptability across attack types. To overcome these limitations, we propose DeFiAD, a unified framework for early-stage domain abuse detection that relies solely on multi-source static information available at registration, enabling detection at the beginning of the domain lifecycle. We first introduce UDIRP, a unified domain information representation paradigm, which maps multi-source heterogeneous DNS native data into three subspaces for model understanding, forming a unified multi-channel representation. Building on this representation, we design DCINet, a Deep & Cross Network–based feature interaction model that effectively learns and integrates multi-source heterogeneous features, improving robustness and adaptability across diverse domain abuse types. Experiments on phishing, DGA, and mixed-abuse datasets show that DeFiAD consistently achieves the best overall performance, improving detection accuracy by 4%–10% over existing methods while maintaining high inference efficiency, highlighting its practicality for timely deployment.
Zhaojun Dai, Xiaodong Lee, Yufan Fu, Botao Peng
TrustCom3
2025 POLARIS: Cross-Domain Access Control via Verifiable Identity and Policy-Based Authorization
abstract
Access control is a security mechanism designed to ensure that only authorized users can access specific resources. Cross-domain access control involves access to resources across different organizations, institutions, or applications. Traditional access control, however, which handles authentication and authorization separately in centralized environments, faces challenges in identity dispersion, privacy leakage, and diversified permission requirements, failing to adapt to cross-domain scenarios. Thus, there is an urgent need for a new access control mechanism that empowers autonomous control over user identity and resources, addressing the demands for privacy-preserving authentication and flexible authorization in cross-domain scenarios.To address cross-domain access control challenges, we propose POLARIS, a unified and extensible architecture that enables policy-based, verifiable and privacy-preserving access control across different domains. POLARIS features a structured commitment mechanism for reliable, fine-grained, policy-based identity disclosure. It further introduces VPPL, a lightweight policy language that supports issuer-bound evaluation of selectively revealed attributes. A dedicated session-level security mechanism ensures binding between authentication and access, enhancing confidentiality and resilience to replay attacks.We implement a working prototype and conduct comprehensive experiments, demonstrating that POLARIS effectively provides scalable, privacy-preserving, and interoperable access control across heterogeneous domains. Our results highlight the practical viability of POLARIS for enabling secure and privacy-preserving access control in decentralized, cross-domain environments.
Aiyao Zhang, Xiaodong Lee, Zhixian Zhuang, Jiuqi Wei, Yufan Fu, Botao Peng
TrustCom5
2025 Dominate data by yourself: a decentralized scheme for data interoperation when data is decoupled from applications
Jiuqi Wei, Xiaodong Lee, Yufan Fu, Ying Li 0051, Botao Peng
World Wide Web (WWW)3
2024 CBCMS: A Compliance Management System for Cross-Border Data Transfer
abstract
Cross-border data transfer is vital for the digital economy by enabling data flow across different countries or regions. However, ensuring compliance with diverse data protection regulations during the transfer introduces significant complexities. Existing solutions either focus on a single legal framework or neglect real-time and concurrent processing demands, resulting in incomplete and inconsistent compliance management. To address this issue, we propose Cross-Border Compliance Management System (CBCMS), which not only enables the unified management of data processing policies across multiple jurisdictions to ensure compliance with various legal frameworks involved in cross-border data transfer, but also supports real-time and high-concurrency processing capabilities. We design Policy Definition Language (PDL) that supports the unified management of data processing policies, bridging the gap between natural language policies and machine-processable expressions, thereby allowing various legal frameworks to be seamlessly integrated into CBCMS. We present Compliance Policy Generation Model (CPGM), the core component of CBCMS, which generates compliant data processing policies with high accuracy, achieving up to 25.16% improvement in F1 score (reaching 97.32%) compared to rule-based baseline. CPGM achieves inference time in the order of milliseconds (6 to 13 ms), and keeps low latency even under high-load scenarios, demonstrating high real-time and concurrent performance. To our knowledge, CBCMS is the first system to support unified compliance management across jurisdictions while ensuring real-time and concurrent processing capabilities.
Zhixian Zhuang, Xiaodong Lee, Jiuqi Wei, Yufan Fu, Aiyao Zhang
IEEE Big Data4
2024 Securing the internet's backbone: A blockchain-based and incentive-driven architecture for DNS cache poisoning defense
abstract
Domain Name System (DNS) is the backbone of the Internet infrastructure, converting human-friendly domain names into machine-processable IP addresses. However, DNS remains vulnerable to various security threats, such as cache poisoning attacks , where malicious attackers inject false information into DNS resolvers’ caches. Although efforts have been made to enhance DNS against such vulnerabilities, existing countermeasures often fall short in one or more areas: they may offer limited resistance to the collusion attack, introduce significant overhead, or require complex implementation that hinders widespread adoption. To address these challenges, this paper introduces TI-DNS+, a trusted and incentivized blockchain-based DNS resolution architecture for cache poisoning defense. TI-DNS+ introduces a Verification Cache exploiting blockchain ledger’s immutable nature to detect and correct forged DNS responses . The architecture also incorporates a multi-resolver Query Vote mechanism, enhancing the ledger’s credibility by validating each record modification through a stake-weighted algorithm. This algorithm selects resolvers as validators based on their stake proportion. To promote well-behaved participation, TI-DNS+ also implements a novel stake-based incentive mechanism that optimizes the generation and distribution of stake rewards. This ensures that incentives align with participants’ contributions, achieving incentive compatibility, fairness, and efficiency. Moreover, TI-DNS+ possesses high practicability as it requires only resolver-side modifications to current DNS. Finally, through comprehensive prototyping and experimental evaluations, the results demonstrate that our solution effectively mitigates DNS cache poisoning. Compared to competitors, our solution improves attack resistance by 1-3 orders of magnitude, while also reducing resolution latency by 5% to 68%.
Yufan Fu, Xiaodong Lee, Jiuqi Wei, Ying Li 0051, Botao Peng
Comput. Networks1
2024 DiSAuth: A DNS-based secure authorization framework for protecting data decoupled from applications
Ying Li 0051, Jiuqi Wei, Ziyu Fei, Yufan Fu, Xiaodong Lee
Comput. Networks4
2023 Data Interoperating Architecture (DIA): Decoupling Data and Applications to Give Back Your Data Ownership
abstract
Data has become a valuable resource that drives new business models and creates enormous business value. However, under the current data ownership model, many data-driven applications arbitrarily collect and overuse user data for commercial purposes, resulting in increased incidents of data breaches and data misuse. In this paper, we present Data Interoperating Architecture (DIA) that decouples applications and user data to give back data ownership to users. We design Data Interoperating System (DIS) based on blockchain, identity system, and identifier system to solve the key issues of data interoperation: identity management, data identification, data discovery, and data ownership protection. DIS provides services without collecting or accessing data, keeping data under the control of its owner. We formalize the interactions among components in DIA as Data Interoperating Protocol (DIP), which facilitates applications and personal data stores to be compatible with DIS. We develop a prototype of DIS and evaluate the system performance under adopted techniques. Experimental results show that DIS is effective and efficient in supporting real-world data interoperation.
Jiuqi Wei, Ying Li 0051, Yufan Fu, Youyi Zhang
COMPSAC3
2023 FlexAuth: A Decentralized Authorization System with Flexible Delegation
abstract
The dispersion of resource authorization across various authorization systems raises the complexity and inconsistency of authorization management. Therefore, the pursuit of a unified resource authorization management system is necessary. Most widely used authorization systems are based on centralized services with a single delegation pattern. These authorization systems can be easily compromised, leading to permissions tampering, and are unsuitable for complex usage scenarios. We propose a decentralized authorization system that provides flexible delegation called FlexAuth. We first define a decentralized data storage layer based on blockchain, using smart contracts to implement data writing and resolving, preventing data from being tampered with. On top of this, we implement active and passive delegation patterns of authorization services. We allow users to delegate permissions actively. Also, FlexAuth enables them to respond to authorization requests passively by making flexible and expressive access control policies based on relation-ships and attributes, using the proposed Hybrid Access Control Model (HACM). Furthermore, all delegations in FlexAuth are transitive. Finally, through analysis and experiments, we validate the usability and efficiency of FlexAuth. To our knowledge, FlexAuth is the first decentralized authorization system with transitive delegation in active and passive patterns, achieving flexible delegation.
Ziyu Fei, Ying Li 0051, Jiuqi Wei, Yufan Fu, Botao Peng
TrustCom4
2023 TI-DNS: A Trusted and Incentive DNS Resolution Architecture based on Blockchain
abstract
Domain Name System (DNS) is a critical component of the Internet infrastructure, responsible for translating domain names into IP addresses. However, DNS is vulnerable to some malicious attacks, including DNS cache poisoning, which redirects users to malicious websites displaying offensive or illegal content. Existing countermeasures often suffer from at least one of the following weakness: weak attack resistance, high overhead, or complex implementation. To address these challenges, this paper presents TI-DNS, a blockchain-based DNS resolution architecture designed to detect and correct the forged DNS records caused by the cache poisoning attacks in the DNS resolution process. TI-DNS leverages a multi-resolver Query Vote mechanism to ensure the credibility of verified records on the blockchain ledger and a stake-based incentive mechanism to promote well-behaved participation. Importantly, TI-DNS is easy to be adopted as it only requires modifications to the resolver side of current DNS infrastructure. Finally, we develop a prototype and evaluate it against alternative solutions. The result demonstrates that TI-DNS effectively and efficiently solves DNS cache poisoning.
Yufan Fu, Jiuqi Wei, Ying Li 0051, Botao Peng
TrustCom1