Ivy K. Y. Woo

dblp:313/7980 · DBLP profile ↗
← Back
12ranked-venue papers
1as first author
12since 2021 · last 2026
0000-0001-8905-1207ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 1 first-author · 12 since 2021
YearPublicationVenuePosition
2026 A Gaussian Leftover Hash Lemma for Modules over Number Fields
Martin R. Albrecht, Joël Felderhoff, Russell W. F. Lai, Oleksandra Lapiha, Ivy K. Y. Woo
EUROCRYPT (4)5
2026 Look Ahead! Practical CCA-Secure Steganography: Cover-Source Switching Meets Lattice Gaussian Sampling
Russell W. F. Lai, Ivy K. Y. Woo, Hoover H. F. Yin
EUROCRYPT (5)2
2026 Threshold Public-Key Encryption: Definitions, Relations, and CPA-to-CCA Transforms
Christopher Brzuska, Michael Klooß, Ivy K. Y. Woo
PKC (4)3
2025 Partial Lattice Trapdoors: How to Split Lattice Trapdoors, Literally
Martin R. Albrecht, Russell W. F. Lai, Oleksandra Lapiha, Ivy K. Y. Woo
ASIACRYPT (3)4
2025 Pilvi: Lattice Threshold PKE with Small Decryption Shares and Improved Security
Valerio Cini, Russell W. F. Lai, Ivy K. Y. Woo
ASIACRYPT (6)3
2025 Lattice-Based Obfuscation from NTRU and Equivocal LWE
Valerio Cini, Russell W. F. Lai, Ivy K. Y. Woo
CRYPTO (7)3
2025 Lattice-Based Proof-Friendly Signatures from Vanishing Short Integer Solutions
Adrien Dubois, Michael Klooß, Russell W. F. Lai, Ivy K. Y. Woo
PKC (1)4
2024 Traitor Tracing Without Trusted Authority from Registered Functional Encryption
Pedro Branco 0005, Russell W. F. Lai, Monosij Maitra, Giulio Malavolta, Ahmadreza Rahimi, Ivy K. Y. Woo
ASIACRYPT (3)6
2024 Evasive LWE Assumptions: Definitions, Classes, and Counterexamples
Christopher Brzuska, Akin Ünal, Ivy K. Y. Woo
ASIACRYPT (4)3
2024 Dataset, Noise Analysis, and Automated Parameter Estimation for Natural Steganography
abstract
Natural steganography concerns embedding a secret message in a cover-source following some distribution S_1, such that after embedding the distribution of the stego-media mimics another cover-source with distribution S_2 (without embedding). Prior works have studied natural steganography over image files, where S_1 and S_2 correspond to the light intensity distribution of a photo taken respectively at some ISO_1 and ISO_2, and much effort has been dedicated to various embedding methods. On the other hand, while the nature of mimicking the distribution S_2 by embedding messages into S_1 sources means that accurate estimations of such distributions are crucial, relatively little attention has been given to this aspect. Furthermore, deploying these stegosystems in practice requires users to estimate the noise distributions of their cameras, which poses a challenging technological barrier for average users and limits the utility of the stegosystems. An objective of this work is to verify the existing claim that, for each fixed ISO value, the pixel values follow a family of Gaussian distributions where the variance is an affine function of the mean. Towards estimating and verifying the concerned distributions, we have created a comprehensive image dataset with the mainstream Sony A6400 camera in a professional photo-shooting environment. Analyses over our dataset reveal that parameters of the light intensity distributions appear to have more complicated behaviour than reported in prior works -- they seem to depend on the overall exposure level induced by the camera settings. For the ease of analysis, we have also developed a set of tools for automating the parameter estimation process. We believe that these tools will eventually improve the accessibility of natural steganography.
Ivy K. Y. Woo, Sheung Yiu, Hoover H. F. Yin, Russell W. F. Lai
IH&MMSec1
2023 On Sustainable Ring-Based Anonymous Systems
abstract
Anonymous systems (e.g. anonymous cryptocurrencies and updatable anonymous credentials) often follow a construction template where an account can only perform a single anonymous action, which in turn potentially spawns new (and still single-use) accounts (e.g. UTXO with a balance to spend or session with a score to claim). Due to the anonymous nature of the action, no party can be sure which account has taken part in an action and, therefore, must maintain an ever-growing list of potentially unused accounts to ensure that the system keeps running correctly. Consequently, anonymous systems constructed based on this common template are seemingly not sustainable. In this work, we study the sustainability of ring-based anonymous systems, where a user performing an anonymous action is hidden within a set of decoy users, traditionally called a “ring”. On the positive side, we propose a general technique for ring-based anonymous systems to achieve sustainability. Along the way, we define a general model of decentralised anonymous systems (DAS) for arbitrary anonymous actions, and provide a generic construction which provably achieves sustainability. As a special case, we obtain the first construction of anonymous cryptocurrencies achieving sustainability without compromising availability. We also demonstrate the generality of our model by constructing sustainable decentralised anonymous social networks. On the negative side, we show empirically that Monero, one of the most popular anonymous cryptocurrencies, is unlikely to be sustainable without altering its current ring sampling strategy. The main subroutine is a sub-quadratic-time algorithm for detecting used accounts in a ring-based anonymous system.
Sherman S. M. Chow, Christoph Egger 0001, Russell W. F. Lai, Viktoria Ronge, Ivy K. Y. Woo
CSF5
2022 On Defeating Graph Analysis of Anonymous Transactions
abstract
In a ring-signature-based anonymous cryptocurrency, signers of a transaction are hidden among a set of potential signers, called a ring, whose size is much smaller than the number of all users. The ringmembership relations specified by the sets of transactions thus induce bipartite transaction graphs, whose distribution is in turn induced by the ring sampler underlying the cryptocurrency. Since efficient graph analysis could be performed on transaction graphs to potentially deanonymise signers, it is crucial to understand the resistance of (the transaction graphs induced by) a ring sampler against graph analysis. Of particular interest is the class of partitioning ring samplers. Although previous works showed that they provide almost optimal local anonymity, their resistance against global, e.g. graph-based, attacks were unclear. In this work, we analyse transaction graphs induced by partitioning ring samplers. Specifically, we show (partly analytically and partly empirically) that, somewhat surprisingly, by setting the ring size to be at least logarithmic in the number of users, a graph-analysing adversary is no better than the one that performs random guessing in deanonymisation up to constant factor of 2.
Christoph Egger 0001, Russell W. F. Lai, Viktoria Ronge, Ivy K. Y. Woo, Hoover H. F. Yin
Proc. Priv. Enhancing Technol.4