VLDB 2026 Research / reviewers in the wild / expert
Kien Tuong Truong
dblp:389/5650
· DBLP profile ↗
3ranked-venue papers
1as first author
3since 2021 · last 2025
0009-0006-9370-9677ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Breaking and Fixing Content-Defined ChunkingabstractContent-defined chunking (CDC) algorithms split streams of data into smaller blocks, called chunks, in a way that preserves chunk boundaries when the data is partially changed. CDC is ubiquitous in applications that deduplicate data such as backup solutions, software patching systems, and file hosting platforms. Much like compression, CDC can introduce leakage when combined with encryption: fingerprinting attacks can exploit chunk length patterns to infer information about the data. Kien Tuong Truong, Simon-Philipp Merz, Matteo Scarlata, Felix Günther 0001, Kenneth G. Paterson |
CCS | 1 |
| 2024 | End-to-End Encrypted Cloud Storage in the Wild: A Broken EcosystemabstractEnd-to-end encrypted cloud storage offers a way for individuals and organisations to delegate their storage needs to a third-party, while keeping control of their data using cryptographic techniques. We conduct a cryptographic analysis of various products in the ecosystem, showing that many providers fail to provide an adequate level of security. In particular, we provide an in-depth analysis of five end-to-end encrypted cloud storage systems, namely Sync, pCloud, Icedrive, Seafile, and Tresorit, in the setting of a malicious server. These companies cumulatively have over 22 million users and are major providers in the field. We unveil severe cryptographic vulnerabilities in four of them. Our attacks invalidate the marketing claims made by the providers of these systems, showing that a malicious server can, in some cases, inject files in the encrypted storage of users, tamper with file data, and even gain direct access to the content of the files. Many of our attacks affect multiple providers in the same way, revealing common failure patterns in independent cryptographic designs. We conclude by discussing the significance of these patterns beyond the security of the specific providers. Jonas Hofmann, Kien Tuong Truong |
CCS | 2 |
| 2023 | Three Lessons From Threema: Analysis of a Secure Messenger
Kenneth G. Paterson, Matteo Scarlata, Kien Tuong Truong |
USENIX Security Symposium | 3 |