VLDB 2026 Research / reviewers in the wild / expert
Chuming Shi
dblp:383/5341
· DBLP profile ↗
7ranked-venue papers
0as first author
7since 2021 · last 2026
0009-0000-0223-5565ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021Computer networks · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | On the Security of Sequential Multi-Signer Ring Signature for Secure Medical Data Sharing in IoMTabstractIn the Internet of Medical Things (IoMT), transmitted medical data contain sensitive patient information. To protect patient identity privacy and address the adaptability limitations of traditional ring signatures, Xu et al. proposed the anonymous sequential multi-signature ring signature (ASMR) to enable secure medical data sharing in the IoMT (IEEE Transactions on Information Forensics and Security, DOI 10.1109/TIFS.2025.3574959). Although Xu et al. claim that the ASMR scheme is secure, our analysis demonstrates that it is insecure, as it is existentially and universally forgeable, allowing any entity to generate a valid ring signature for arbitrary messages. Following the presentation of the attack, we analyze the causes of these vulnerabilities and propose corresponding countermeasures. Jianhong Zhang 0001, Chuming Shi |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | An Enhanced-Security Certificateless Aggregate Signcryption for Secure Data Transmission in Resource-Constrained NetworksabstractThe terminal devices in resource-constrained networks face significant challenges in ensuring data privacy and integrity during transmission. Signcryption, which simultaneously provides both data confidentiality and authentication, offers a promising solution with reduced computational costs in such networks. Recently, three efficient pairing-avoiding CertificateLess Aggregate SignCryption (CLASC) schemes were introduced to enhance privacy and authenticity in vehicular sensor networks, the Industrial Internet of Thing, and 5G wireless network scenarios. These schemes achieve lower computational costs compared to previous schemes. However, further security analysis reveals that these CLASC schemes fail to meet their claimed security properties. Specifically, two of them are vulnerable to Type I attacks, while the third one is susceptible to Type II attacks. To address these vulnerabilities, we propose a new CLASC scheme with enhanced security. It not only resists Type I and Type II attacks in the random oracle model but also achieves Girault’s Level-3 security. Finally, our experimental assessments demonstrate that the proposed scheme outperforms several recent CLASC schemes. It maintains similar computational costs and communication overheads compared to state-of-the-art CLASC schemes, while providing stronger security guarantees. Jianhong Zhang 0001, Chuming Shi |
IEEE Internet Things J. | 2 |
| 2025 | Efficient Privacy-Preserving Federated Learning for IIoT Using Dual Proxy Re-EncryptionabstractThe Industrial Internet of Things (IIoT) is revolutionizing industries such as smart grids, healthcare, and predictive maintenance by harnessing big data and deep learning technologies. However, limited datasets in IIoT devices often result in suboptimal model performance and overfitting. Federated deep learning can mitigate this issue by leveraging distributed datasets across devices, but data privacy concerns persist, especially in sensitive applications like smart healthcare and energy management. rgb0.00,0.00,0.00Although numerous privacy-preserving federated learning schemes have been proposed, their vulnerabilities hinder widespread adoption due to insufficient guarantees for participant data privacy and the security of global model parameters. To address these challenges, we propose a novel deep learning framework that leverages proxy re-encryption techniques to enhance data privacy. Our scheme employs a dual proxy re-encryption mechanism to enhance data security, enabling each participant to securely access global model parameters without relying on a proxy server during training rounds. This not only prevents unauthorized access by the parameter server, but also resists collusion attacks between the parameter server and participants. Furthermore, the confidentiality of the proxy server’s private key is maintained, even in cases of collusion involving the parameter server and participants. A comparative analysis with existing schemes highlights the advantages of our approach, including reduced communication overhead and computational complexity, as demonstrated by experimental results. Jianhong Zhang 0001, Chuming Shi |
IEEE Internet Things J. | 2 |
| 2025 | Efficient Secure Data Aggregation for Real-Time Smart Grid Monitoring: A Lightweight Privacy-Preserving ApproachabstractData aggregation protocols play a crucial role in enabling real-time monitoring of the smart grid's operational status by the power control center. To ensure robust security, a data aggregation protocol should provide features such as data privacy, fault tolerance, lightweight computation, and fine-grained data aggregation. However, existing data aggregation protocols employing techniques such as homomorphic encryption, masking, or differential privacy fail to deliver these features concurrently. To address this challenge, we propose a novel lightweight privacy-preserving data aggregation scheme based on proxy reencryption and asymmetric scalar product-preserving encryption, in which encryption operations only involve addition and multiplication over the integer field, thus avoiding time-consuming exponentiation and pairing operations and achieving lightweight computation. Furthermore, through the use of an asymmetric scalar-product-preserving encryption scheme, we effectively align aggregation policies while maintaining the privacy of power consumption data. Finally, when compared to three recent data aggregation schemes with analogous structures, experimental results demonstrate that our proposed scheme outperforms others regarding computational and communication overheads, thus enhancing its efficiency. Jianhong Zhang 0001, Chuming Shi |
IEEE Trans. Comput. Soc. Syst. | 2 |
| 2025 | Two-Round Certificateless Multi-Signatures With Key Aggregation in Smart ContractsabstractMulti-signatures have recently garnered considerable attention, particularly within the domain of smart contracts in blockchain ecosystems, as they enhance account security and mitigate single points of failure by requiring the approval of multiple key holders for transaction execution. However, most existing multi-signature schemes heavily rely on traditional Public Key Infrastructure (PKI), which requires a trusted authority and conflicts with the decentralized nature of blockchain technology. Certificateless multi-signature (CLMS) schemes, which eliminate the requirement for a trusted authority, represent promising solutions to address this issue. Nevertheless, existing CLMS schemes encounter challenges that limit their suitability for smart contract applications, including high communication overhead, expensive verification costs, and “loose" security reductions. To address these challenges, we propose two novel two-round certificateless multi-signature schemes. These schemes not only support key aggregation but also optimize the signing process with two-round communication, maintaining fixed computational overhead during verification. Furthermore, the security proofs for the proposed schemes are independent of the Forking lemma, resulting in tighter security reductions and strengthened security assurance. Finally, experimental results demonstrate that the proposed schemes significantly reduce both communication and computational overhead compared to existing CLMS schemes, making them more efficient and practical for blockchain-based smart contract applications. Jianhong Zhang 0001, Chuming Shi |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Corrections to "On the Security of a Revocable Cross-Domain Anonymous Authentication in IIoT"abstractWith the rapid growth of the Industrial Internet of Things (IIoT), secure and efficient collaboration among devices from different domains is essential for achieving collaborative production tasks. Recently, Zeng et al. proposed a dynamic group signature scheme using dynamic accumulators and zero-knowledge proofs. Although they claim that their scheme ensures unlinkability of signatures, our analysis shows that their scheme is vulnerable and fails to provide unlinkability. After presenting our attack, we analyze the underlying causes of these vulnerabilities and propose an improvement to address them. Jianhong Zhang 0001, Chuming Shi |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Short Ciphertext-Size Privacy-Preserving Aggregation Against Malicious Aggregators
Jianhong Zhang 0001, Chuming Shi |
ICIC (5) | 2 |