VLDB 2026 Research / reviewers in the wild / expert
Shihui Zheng
dblp:30/2120
· DBLP profile ↗
23ranked-venue papers
5as first author
13since 2021 · last 2026
0000-0001-6360-5777ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Databases, data management, data science and information retrieval · 7 · 2 first-authorSystems, architecture and hardware · 5 · 2 first-author · 5 since 2021Security and privacy · 5 · 5 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorComputer networks · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CRISP: An Efficient Cryptographic Framework for ML Inference Against Malicious Clients
Xiaoyu Fang, Shihui Zheng, Lize Gu |
NDSS | 2 |
| 2026 | Extended persistent-fault based differential analysis in the multiple-fault scenarioabstractAbstract Persistent fault analysis is effective when a single element of the S-box is altered. However, most fault injection techniques tend to induce multiple faults. In such multiple-fault scenarios, existing key recovery methods either fail to identify the unique key or require high computational complexity. To address this, we propose the count-ranking method to accelerate Persistent-Fault Based Differential Analysis (PFDA). The method counts subkey byte frequencies and selects the most frequent value per byte. Additionally, this approach allows us to further explore faults occurring during deeper rounds of encryption, as it independently determines the unique value of each subkey byte. Consequently, we successfully recover the unique key for both serial and parallel implementations of AES with a complexity of $$O(N_f^2 \times N_c)$$ O ( N f 2 × N c ) table lookups. Finally, the count-ranking method facilitates the recovery of several subkeys in Feistel ciphers without dramatically increasing the number of key candidates. We apply the revised PFDA to both DES and Camellia, efficiently achieving full-key recovery. These results demonstrate the practical applicability of the extended PFDA across both serial and parallel cipher architectures. Yingyan Chen, Shihui Zheng |
Cybersecur. | 2 |
| 2026 | Enhancing adversarial transferability via hybrid data and model augmentation
Yannan Jia, Shihui Zheng, Lize Gu |
Neurocomputing | 2 |
| 2026 | Enhancing adversarial transferability via importance-aware pixel-level mask
Yannan Jia, Lize Gu, Shihui Zheng |
Mach. Vis. Appl. | 3 |
| 2025 | Benchmarking and Understanding Compositional Relational Reasoning of LLMsabstractCompositional relational reasoning (CRR) is a hallmark of human intelligence, but we lack a clear understanding of whether and how existing transformer large language models (LLMs) can solve CRR tasks. To enable systematic exploration of the CRR capability of LLMs, we first propose a new synthetic benchmark called Generalized Associative Recall (GAR) by integrating and generalizing the essence of several tasks in mechanistic interpretability (MI) study in a unified framework. Evaluation shows that GAR is challenging enough for existing LLMs, revealing their fundamental deficiency in CRR. Meanwhile, it is easy enough for systematic MI study. Then, to understand how LLMs solve GAR tasks, we use attribution patching to discover the core circuits reused by Vicuna-33B across different tasks, and a set of vital attention heads. Intervention experiments show that the correct functioning of these heads significantly impacts task performance. Especially, we identify two classes of heads whose activations represent the abstract notion of true and false in GAR tasks respectively. They play fundamental roles in CRR across various models and tasks. Ruikang Ni, Da Xiao 0001, Qingye Meng, Shihui Zheng, Hongliang Liang |
AAAI | 5 |
| 2025 | How to Launch a Powerful Side-Channel Collision Attack?abstractA cryptographic implementation produces very similar power leakages when fed with the same input. Side-channel collision attacks exploit these similarities to establish the relationship between sub-keys and improve the efficiency of key recovery. Benefiting from independence of leakage model, they play an important role in non-profiled setting. However, performance of existing approaches against single collision value is still sub-optimal and optimization is promising. Motivated by this, we first theoretically analyze the mathematical dependency between the number of collisions and the number of encryptions, and propose an efficient side-channel attack named Collision-Paired Correlation Attack (CPCA) to guarantee that the side with fewer samples in a collision is completely paired in low noise scenario. This allows overcoming the inefficient utilization of information in existing works. Moreover, to further employ underlying informativeness, we maximize collision pairs as many as possible. This optimization significantly improves performance of CPCA and thereby extends it to large noise scenarios. Finally, to achieve moderate computational complexity, two equivalent variants of CPCA are investigated to address the potential problem of limited computing resources. Our further theoretical study illustrates that CPCA provides the upper security bound of Correlation-Enhanced Collision Attack (CECA), and experimental results fully verify its superiority. Jiangshan Long, Changhai Ou, Yajun Ma, Yifan Fan, Hua Chen 0011, Shihui Zheng |
IEEE Trans. Computers | 6 |
| 2025 | MinMaxEntropy: Bound Model Errors for Side-Channel Leakages From Information TheoryabstractSide-channel attacks and evaluations have been incessantly pursuing an accurate leakage model and try to address the following question: “How good is my leakage model?” However, the existing works do not well alleviate the attackers and evaluators from model assumption error and estimation error. The recent work named maximum entropy distribution (MED) model does not depend on any assumptions but uses nonlinear programming Newton-Raphson method to fit the leakage distribution, thus avoiding assumption error and making the estimation error arbitrarily small. It tries to address a more fundamental problem: “How to achieve the optimal leakage model?,” but still have to face with two issues: 1) the large deviation of MED model from leakage distribution and 2) the difficulty in determining the moments required in model profiling. In this article, we first introduce the nonlinear programming optimizations Levenberg-Marquardt and Conjugate Gradient methods to tackle the first issue. We then exploit Hopfield neural network to solve the minimum entropy for leakage model. Unlike the MED indicating the theoretically most unbiased, objective and reasonable leakage model, the minimum entropy corresponds to the theoretically most biased, subjective and unreasonable leakage model. This facilitates us to build a MinMaxEntropy bound from the maximum entropy and minimum entropy for estimation errors in leakage model, which theoretically represents the amount of information contained on unused higher moments. This bound well provides theoretical support for the moments constraints required to profile the MED model, thus well tackling the second issue. Experimental results fully demonstrate the superiority of our above schemes. Changhai Ou, Zhenfang Qiu, Xingshuo Han, Fan Zhang 0010, Shihui Zheng, Fei Yan 0008 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 5 |
| 2024 | Integral Attacks Against DIBO Structures: A Low-Complexity Key Extraction Method
Xinming Zhu, Shihui Zheng, Zihao Han |
Inscrypt (2) | 2 |
| 2024 | Concise RingCT Protocol Based on Linkable Threshold Ring SignatureabstractRing Confidential Transactions (RingCT) is a typical privacy-preserving protocol for blockchain, which is used for the most popular anonymous cryptocurrency Monero in recent years. RingCT provides the user's identity anonymity based on the linkable ring signature. At the cost of that, the transaction size is increased linearly to the involved users. In this article, we aim to overcome this inefficient aspect of RingCT by introducing the linkable threshold ring signature (LTRS). We first propose a construction of threshold ring signatures for homomorphic cryptosystems, and present an efficient instantiation based on the intractability assumption of the discrete logarithm problem. Based on this framework, an efficient LTRS scheme and a novel construction of the RingCT protocol are presented. Our proposed RingCT protocol enables multiple payers to co-construct an anonymous transaction without revealing their secret account keys, and it is more concise under multiple input accounts. For a transaction with a ring size of 100 and the input accounts number of 64, the communication overhead is about 4% of the original RingCT protocol. Junke Duan, Shihui Zheng, Wei Wang 0294, Licheng Wang 0004, Xiaoya Hu, Lize Gu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Breaking Fault Attack Countermeasures With Side-Channel InformationabstractIn the persistent fault-based collision attack (PFCA) (Zheng et al. 2021), the adversary captures the information that the intermediate states have collided through identical correct/incorrect ciphertexts. However, fault countermeasures achieve suppression of incorrect ciphertexts and prevent the PFCA. In this paper, we measure the collision of internal states (or state bytes) using side-channel information. First, for round-level countermeasures, we identify state bytes hitting the same persistent fault during the first round of encryption by the shortest runtime. Additionally, we design sliding-window algorithms to automatically identify the runtime of one-round encryptions suitable for different execution environments. Second, for algorithm-level protections, we detect the collision of the internal states after the first round of encryption through the maximum similarity of power consumption traces. Meanwhile, to address the low success rate of key recovery caused by miss detection due to noise within runtime or power consumption, we further revise the original filtering algorithm in PFCA. Third, we implement round-level protected AES on PC to measure runtime, and both AES protected by round-level (or algorithm-level) countermeasures and SM4 (ISO/IEC 2021) protected by a round-level countermeasure on a smart card to collect power consumption. Finally, the experimental result proves that the revised PFCA successfully recovers the key. Shihui Zheng, Ruihao Xing, Junlong Lai, Changhai Ou |
IEEE Trans. Computers | 1 |
| 2023 | CoTree: A Side-Channel Collision Tool to Push the Limits of Conquerable SpaceabstractBy introducing collision information into divide-and-conquer distinguishers, the existing collision-optimized side-channel attacks transform the given candidate space into a significantly smaller collision space, thus achieving more efficient key recovery. However, the candidates of the first several subkeys shared by collision chains are still repeatedly detected, which happens very frequently and brings huge computational overhead. To alleviate this, we propose a highly efficient collision-optimized attack named collision tree (CoTree). This collision detection tool exploits tree structure to store the chains created from the same subchain on the same branch, thus significantly reducing the storage requirements. It then benefits from the properties of both tree and collisions and exploits a top-down tree building procedure and traverses each node only once when detecting their collisions with a candidate of the subkey currently under consideration. Finally, unlike the traditional top-down node removal, CoTree launches a bottom-up branch removal procedure to remove the chains unsatisfying the collision conditions from the tree after traversing all the considered candidates of this subkey, thus avoiding the traversal of the branches satisfying the collision condition. These strategies make our CoTree significantly alleviate the repetitive collision detection, and our experiments verify that it significantly outperforms the existing works. Changhai Ou, Debiao He, Kexin Qiao, Shihui Zheng, Siew-Kei Lam, Fan Zhang 0010 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2021 | Effective Deep Learning-based Side-Channel Analyses Against ASCADabstractSide-channel analysis (SCA) based on deep learning (DL) techniques have the benefit that they can disclose the secret key of protected block ciphers without preprocessing. But the size of convolutional neural network (CNN) architecture is so large that the training process is too time-consuming and the required number of traces for recovering secret key is too much. In this paper, we apply heatmap and SNR to reduce the number of parameters of our CNN architecture to 5,269,568 (i.e., one to tenth to the CNNbest). We also combine our CNN architecture with the multi-label classification and the transfer learning techniques to reduce the number of required traces. Consequently, two new CNN architectures are presented and validated on the public ASCAD dataset. The execution time of the training process approximates 15 minutes on average. The first CNN architecture can recover a key byte with only 30 synchronized traces. Combined with the transfer learning technique, the second CNN architecture requires 141 and 171 traces respectively in two different desynchronization cases. To our knowledge, for both synchronization and desynchronization cases, our analysis methods need the smallest amount of traces to extract a key byte. Shihui Zheng, Lize Gu |
TrustCom | 2 |
| 2021 | A Persistent Fault-Based Collision Analysis Against the Advanced Encryption StandardabstractA transient fault-based collision attack always requires to inject fault multiple times. We present the first attack that uses collision information caused by a persistent fault in the substitution box (S-box) to recover the entire 128-bit key of the advanced encryption standard (AES). Moreover, a relatively relaxed fault model is required; i.e., the attacker does not know any information about the position, the length (i.e., the number of bytes), or the value of the injected fault. At most, 4096 chosen plaintexts are required for a persistent fault-based collision attack (PFCA), and the computational complexity is O(223) in the worst case in the single-byte fault setting. A filtering algorithm is presented in the multibyte fault setting, and we theoretically prove that the complexity can be reduced to O(212) in more than half of cases if the number of collision ciphertexts follows a uniform distribution. In addition, PFCAs against a software implementation of AES are simulated on a laptop, and the results show that the success probability of the attack either with online key searching or with offline key searching approaches 100%. In particular, more than 97% of all experiments output the right key with complexity O(212) in the multibyte fault setting. Therefore, the attack is more efficient in this scenario. Furthermore, the attack works on an AES implementation protected by Boolean masking. Finally, PFCAs against AES implementations separately protected by two widely used countermeasures-the inverse S-box and the parity-1 matrix-are performed. The experimental results illustrate that only a 10-round protection using the first method can completely defeat the attack. Shihui Zheng, Shoujin Zang, Yihao Deng, Dongqi Huang, Changhai Ou |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2008 | A New Construction of Multivariate Public Key Encryption Scheme through Internally Perturbed Plus
Zhiwei Wang 0003, Xuyun Nie, Shihui Zheng, Yixian Yang |
ICCSA (2) | 3 |
| 2005 | What makes the differences: benchmarking XML database implementationsabstractXML is emerging as a major standard for representing data on the World Wide Web. Recently, many XML storage models have been proposed to manage XML data. In order to assess an XML database's abilities to deal with XML queries, several benchmarks have also been proposed, including XMark and XMach. However, no reported studies using those benchmarks were found that can provide users with insights on the impacts of a variety of storage models on XML query performance. In this article, we report our first set of results on benchmarking a set of XML database implementations using two XML benchmarks. The selected implementations represent a wide range of approaches, including RDBMS-based systems with document-independent and document-dependent XML-relational schema mapping approaches, and XML native engines based on an Object-Oriented Model and the Document Object Model. Comprehensive experiments were conducted to study relative performance of different approaches and the important issues that affect XML query performance, such as path expression query processing, effectiveness of various partitioning, label-path, and indexing structures. Hongjun Lu, Jeffrey Xu Yu, Guoren Wang, Shihui Zheng, Ge Yu 0001, Aoying Zhou |
ACM Trans. Internet Techn. | 4 |
| 2003 | Cost-Driven Storage Schema Selection for XMLabstractVarious models and approaches have been proposed for mapping XML data into relational tables recently. Most of those approaches produce relational schema for given XML data, based on pre-defined rules, heuristics, and user specifications, without considering workload As the result, the schema obtained is often not optimal with respect to query performance. In this paper, we present a cost-driven approach to generate a near-optimal relational schema fir a given XML data and expected workload, in the presence of space constraint. An efficient heuristic algorithm based on Hill Climbing is proposed together with a set of state transformation operations. Experimental study using the prototype system implementing the proposed algorithm, indicates that the produced schema can provide better performance than those well-known mapping approaches published in the literature. Shihui Zheng, Ji-Rong Wen, Hongjun Lu |
DASFAA | 1 |
| 2003 | What Makes the Differences: Benchmarking XML Database ImplementationsabstractXML is emerging as a major standard for representing data on the World-Wide-Web. Recently, many XML storage models have been proposed to manage XML data. We propose several benchmarks including XMark and XMach in order to assess an XML database's abilities to deal with XML queries. We report our first set of results on benchmarking a set of XML database implementations using two XML benchmarks. In general, XML data can be managed as text files, by existing DBMSs, or by the so-called native XML engines. We implemented three XML database systems. VXMLR, and XParent were built on top of RDBMS, and XBase was implemented as a native XML engine. For each approach, variations on schema mapping and storage methods were also implemented for comparison. Hongjun Lu, Jeffrey Xu Yu, Guoren Wang, Shihui Zheng, Ge Yu 0001, Aoying Zhou |
ICDE | 4 |
| 2003 | TREX: DTD-Conforming XML to XML Transformations
Aoying Zhou, Qing Wang 0006, Zhimao Guo, Xueqing Gong, Shihui Zheng, Hongwei Wu, Jianchang Xiao, Kun Yue, Wenfei Fan |
SIGMOD Conference | 5 |
| 2003 | DVQ: Towards Visual Query Processing of XML Database Systems
Shihui Zheng, Aoying Zhou, Hongjun Lu |
World Wide Web | 1 |
| 2002 | DTD-Directed Publishing with Attribute Translation Grammars
Michael Benedikt, Chee Yong Chan, Wenfei Fan, Rajeev Rastogi, Shihui Zheng, Aoying Zhou |
VLDB | 5 |
| 2002 | Structural Map: A New Index for Efficient XML Path Expression Processing
Shihui Zheng, Aoying Zhou, Jeffrey Xu Yu, Han Tao |
WAIM | 1 |
| 2001 | VXMLR: A Visual XML-Relational Database System
Aoying Zhou, Hongjun Lu, Shihui Zheng, Wenyun Ji, Zengping Tian |
VLDB | 3 |
| 2001 | Enhancing XML Data Processing in Relational System with Indices
Aoying Zhou, Shihui Zheng, Wenyun Ji |
WAIM | 3 |