Jingyu Yao

dblp:301/2319 · DBLP profile ↗
← Back
5ranked-venue papers
1as first author
5since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 2 · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Thinking Alignment of Scenario-Oriented User Simulation
abstract
Existing user simulators based on prompting to role-play or SFT are generally confined to imitating users' textual utterances, without adequately considering the multi-faceted cognitive processes that underlie human decision-making during interactions.To facilitate better alignment with real human thinking patterns, we construct the LMSYS-UserThinking dataset, in which we augment 51k human-LLM conversations by reconstructing the user's inner reasoning both during and at the end of each dialogue.Furthermore, to enhance controllability and situational coherence, we introduce scenario settings that describe the global context and user goals throughout multi-turn conversations.Using this dataset, we train user simulators called ThinkingUS on different base models.We evaluate our approach from both offline and online user simulation perspectives, ultimately demonstrating its effectiveness.
Xiaoting Wu, Yi Huang 0017, Chunyang Gao, Mengfei Guo, Jingyu Yao, Junlan Feng
ACL (1)5
2026 StrokePIN: Enhancing PIN Authentication With Keystroke Dynamics for Mobile Devices
abstract
Keystroke dynamics-based authentication is a promising approach to enhance the security of personal identification number (PIN)-based authentication systems for mobile devices. While its effectiveness has been extensively studied, due to the limitations on the number of samples users can provide, most research struggles with the trade-off between system performance and user experience. Additionally, little effort has been devoted to quantifying the security of PIN keystroke dynamics. In this paper, we present StrokePIN, a user-friendly and efficient authentication system that utilizes multi-modality data. Specifically, we leverage a few-shot learning technique, called Siamese Network, which enables lightweight deployment of the system without retraining. To evaluate StrokePIN, we design a set of experiments and collect two new multi-modality datasets of keystroke dynamics of 20 PINs from 116 users. These datasets are the only publicly available resources of their kind to date, and we have made them accessible online. Furthermore, we quantify the security of keystroke dynamics of PINs with entropy, revealing its security boundaries. The evaluation results show that compared to the baselines, StrokePIN achieves state-of-the-art performance with False Acceptance Rate (FAR) of 2.2% and False Rejection Rate (FRR) of 1.9% on unseen users. For unseen PINs, StrokePIN achieves an FAR of 2.6% and an FRR of 1.4%. Additionally, by dynamically updating the template library, StrokePIN can mitigate the impact of user behavior drift over time, achieving the performance with FAR of 8.3% and FRR of 0.4%. Our security analysis results indicate that keystroke dynamics can provide 4.03-5.83 bits of security against 3 to 10 online guessing attacks.
Jingyu Yao, Ding Wang 0002
IEEE Trans. Dependable Secur. Comput.1
2025 Modeling Multi-Turn Spoken Language Understanding with Dynamic Graph Convolutional Networks
Yi Huang 0017, Jingyu Yao, Junlan Feng
INTERSPEECH3
2025 CR²-ABE: A Blockchain-Assisted Coercion-Resistant and Revocable Attribute-Based Encryption for IoMT
abstract
The Internet of Medical Things (IoMT) has rapidly developed due to its ability to enhance the efficiency of medical data collection and utilization. Encryption technology is vital for ensuring IoMT data security and privacy. However, existing solutions often fail when secret keys or random numbers are exposed under coercion, undermining their effectiveness and security. Additionally, medical data stored on cloud platforms is vulnerable to risks, such as tampering or loss. To address these challenges, we propose CR2-ABE, a novel encryption scheme specifically designed for the IoMT environment. CR2-ABE combines chameleon hash functions and deniable encryption techniques, enabling medical data owners and recipients to present deceptive messages under coercion, thereby enhancing the coercion resistance of sensitive medical data. Moreover, CR2-ABE employs ciphertext-policy attribute-based encryption (CP-ABE) to facilitate fine-grained access control for medical data, while also leveraging blockchain technology to ensure data integrity and tamper resistance within cloud services. In terms of user management, CR2-ABE implements a policy revocation mechanism that operates directly on ciphertexts using software Guard extensions (SGX). We rigorously prove the correctness and semantic security of CR2-ABE, demonstrating its resilience against coercion attacks. Comprehensive evaluation results show that CR2-ABE exhibits significant performance improvements in key generation, encryption, decryption, and policy revocation compared to other solutions. Therefore, CR2-ABE possesses strong security and scalability.
Yuan Zhai, Haochen Yang 0001, Jingyu Yao, Tao Wang 0039, Yanwei Zhou, Bo Yang 0003
IEEE Internet Things J.3
2025 DRAC: A dynamic fine-grained access control scheme for cloud storage with censorship-coerced resistance
Yuan Zhai, Haochen Yang 0001, Jingyu Yao, Tao Wang 0039, Yanwei Zhou, Bo Yang 0003
J. Inf. Secur. Appl.3