VLDB 2026 Research / reviewers in the wild / expert
Weiwei Li 0007
dblp:45/3709-7
· DBLP profile ↗
14ranked-venue papers
3as first author
12since 2021 · last 2026
0000-0003-1833-8950ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 10 · 2 first-author · 8 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Low-Latency Secure Data Sharing in IoV: A Smart Contract-Based Framework With Parallel Outsourced ComputingabstractWith the rapid development of the Internet of Vehicles (IoV), the need for reliable real-time communication and secure data sharing has become increasingly critical. However, existing solutions struggle with high computational demands and limited vehicle processing capability. While attribute-based encryption enables fine-grained data sharing, its high decryption overhead requires outsourcing to Roadside Units (RSUs), which introduces reliability risks such as ciphertext decryption errors, threatening system integrity. To address these issues, we propose a smart contract-based data sharing framework with parallel outsourced computing in IoV. Unlike most existing outsourced ABE (OABE) schemes that rely on serial decryption and lack robust parallel verification, and blockchain-integrated approaches that focus on general trust without tailored parallelism, our system uniquely combines MapReduce-based parallel decryption (dividing RSU tasks into distributed Map and Reduce stages) with a ciphertext verification mechanism (achieving 99.95% error detection with under 2% communication overhead) and smart contracts for auto-auditing (2 blocks, 0.003 ETH cost, preventing 98.7% malicious behaviors). Blockchain integration ensures service quality guarantees by providing accountability and ensuring that computation results are auditable, with responsible parties held accountable. Experiments and SUMO simulations show that our system maintains a decryption time of nearly 1 second with 100 attributes, improving by 1.6 seconds over serial decryption, while reducing transformation key generation complexity fromO(n) toO(1). These results confirm that our system achieves efficient data sharing with computational correctness and security in IoV. Longfang Wen, Liangliang Wang 0001, Weiwei Li 0007 |
IEEE Internet Things J. | 5 |
| 2026 | Fault-Tolerant and Key-Leakage Resilient Lightweight Multidimensional Privacy-Preserving Data Aggregation Scheme in Smart GridabstractEfficient power management in smart grid relies on collecting fine-grained power consumption data from users. However, these data may reveal sensitive information about individuals' habits and lifestyles. Various multidimensional data aggregation schemes leveraging public key encryption (PKE) algorithms have been proposed to address this problem. Never theless, most of these schemes come with significant performance costs. In addition, if the secret key of a smart meter was leaked, the confidentiality of encrypted user power data could be at risk. In this article, we propose a lightweight, multidimensional, and privacy-preserving data aggregation scheme with fault-tolerance and key-leakage resilience for smart grid without relying on a trusted third party (TTP), named FKLM-PDA, in which a novel data packaging method that transforms users' multidimensional data into a one-dimensional format is designed, enabling data center parse aggregated results in each dimension, reducing computation and communication costs. For better efficiency, an effective encryption algorithm is proposed to replace the expensive additive homomorphic PKE, like the Paillier cryptosystem, which combines a random masking with secret-sharing based key separation, ensuring threshold key-leakage resilience under a bounded, non-colluding leakage model. Furthermore, not only does FKLM-PDA enhance the fault tolerance mechanism of data transmission from smart meters to a corresponding fog node, but also it supports dynamic user management for joining and exiting improving scalability. Security analysis confirms that FKLM-PDA is privacy-preserving and secure while guaranteeing key-leakage resilience, fault tolerance, authentication, and data integrity. Through performance evaluations, FKLM-PDA outper forms the existing schemes and is superior in computation and functional in communication. Liangliang Wang 0001, Chuankun Zhao, Zhiquan Liu 0001, Kai Zhang 0016, Mingze He, Weiwei Li 0007 |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2025 | PPFL: Privacy-Preserving Federated Learning Based on Differential Privacy and Personalized Data TransformationabstractFederated learning (FL) prevents direct exposure of raw data. However, it remains vulnerable to privacy and security threats such as inference and poisoning attacks. Traditional differential privacy (DP) methods utilize noise injection to mitigate these attacks, which inherently degrades the accuracy of the model. In this paper, we propose a robust FL framework with two alternative effective defense mechanisms to enhance privacy preservation for various scenarios. We first propose a dual-layer client-server collaborative differential privacy (CLDP). Clients utilize adaptive local differential privacy (LDP) for data privacy, while the server uses central differential privacy (CDP) on the global model to mitigate poisoning attacks. Second, we propose enhanced central differential privacy (ECDP), a layer-specific protection mechanism that strategically injects targeted noise into non-batch normalization layers to further preserve data privacy. To mitigate noise-induced model performance degradation, our solution combines personalized data transformation and gradient sparsification, effectively alleviating both non-IID data distribution skew and cumulative noise effects. Architecturally, we decentralize the federated learning system through edge node integration, thereby eradicating single points of failure. Experimental results demonstrate that our framework achieves a superior accuracy-privacy trade-off under strict privacy constraints, providing robust protection without compromising practical utility. Jiali Han, Liangliang Wang 0001, Zhiquan Liu 0001, Baodong Qin, Kai Zhang 0016, Weiwei Li 0007 |
IEEE Internet Things J. | 6 |
| 2025 | A Security-Enhanced Pairing-Free Certificateless Aggregate Signcryption Scheme for Decentralized Vehicular Sensor NetworksabstractVehicular Sensor Networks (VSNs) are integral to intelligent transportation systems, enabling real-time communication and collaborative sensing among vehicles. However, their open wireless communication environment presents significant challenges in terms of data security and privacy protection. Although various certificateless aggregate signcryption (CLASC) schemes have been proposed to address these issues, many still suffer from security vulnerabilities and performance inefficiencies. We conduct a detailed security analysis of a recently proposed CLASC scheme by Dai et al., highlighting its susceptibility to public key replacement attacks. To demonstrate this vulnerability, we construct a specific attack algorithm and, based on our findings, propose a security-enhanced CLASC scheme. The proposed solution integrates blockchain technology to improve system decentralization, enhances resistance to collusion attacks, and supports malicious identity revocation mechanism. We provide formal security proofs under standard cryptographic hardness assumptions and evaluate the performance of the scheme through both theoretical analysis and experimental validation. The results show that our approach significantly strengthens security while maintaining high efficiency, making it well-suited for secure and scalable communication in vehicular sensor network (VSN) environments. Guangheng Wang, Yang Liu 0291, Liangliang Wang 0001, Zhiquan Liu 0001, Kai Zhang 0016, Weiwei Li 0007 |
IEEE Internet Things J. | 7 |
| 2025 | A Sanitizable and Bilateral Access Control Scheme Based on BlockchainabstractDriven by information technology, data trading promotes cross-industry collaboration and uncovers value by integrating multi-source data, yet it requires encryption and access controls to address increasing data security challenges. Existing schemes largely rely on attribute-based unilateral access control to protect data, facing challenges such as data source authenticity and requester autonomy. Bilateral access control requires data providers and requesters to define access policies, allowing decryption only when both policies match, often facilitated by cryptographic primitives such as matchmaking encryption (ME). However, the current bilateral schemes still face challenges of sensitive data leakage, unauthorized data access, and single points of failure. To date, no existing scheme has addressed these issues simultaneously. In this paper, we propose a blockchain-based, sanitizable and bilateral access control scheme with privacy-preserving (SBAC-PP) for data trading. Specifically, by extending ME via hash functions and policy-hidden identifiers to achieve a bilateral access control with privacy-preserving. Secondly, by combining access control encryption (ACE), we design a ciphertext sanitization mechanism to prevent unauthorized data access. Furthermore, by integrating SBAC-PP with blockchain (BC) and the interplanetary file system (IPFS), we use smart contracts for trusted matching and pre-decryption, and store encrypted data in IPFS, thereby achieving decentralized data management to avoid single points of failure. Finally, we analyze the security of SBAC-PP and evaluate its performance to demonstrate its efficiency and practicality. Mi Wen, Miling Xiao, Weiwei Li 0007, Bin Xiao 0001 |
IEEE Internet Things J. | 3 |
| 2025 | BPRM: Blockchain-Based Privacy Preserving and Robust Data Aggregation Supporting Multifunctionality for Fog-Assisted Smart GridabstractWhile the collection of users’ live or periodic electricity consumption data brings significant advantages for the operation of smart grids, it also heightens the risk of user privacy leakage. Numerous data aggregation schemes have been proposed to address this issue. However, most of these schemes either fail to accommodate the need for multifunctional data analysis or rely on a trusted third party (TTP). Given the efficient data processing capabilities offered by fog computing, we propose a blockchain-based privacy-preserving data aggregation (BPRM) scheme supporting multifunctionality for fog-assisted smart grid without TTP. This scheme ensures data confidentiality and data integrity while providing various statistical functions. In addition, we implement a consensus mechanism between smart meters, further enhancing the security and robustness of the smart grid system. Moreover, not only does the proposed the batch verification reduce the authentication costs but also support error detection in signatures. With BPRM, data center can calculate multiple statistical functions, achieving a win-win strategy. Extensive security and performance analyses demonstrate that BPRM can withstand various security threats and effectively protect user privacy while maintaining efficiency in both computational and communication overhead. Chuankun Zhao, Liangliang Wang 0001, Zhiquan Liu 0001, Kai Zhang 0016, Weiwei Li 0007, Kefei Chen |
IEEE Internet Things J. | 6 |
| 2025 | Contrastive Graph Semantic Learning via prototype for recommendation
Mi Wen, Weiwei Li 0007, Zizhu Fan, Xiaoqing Yu |
Inf. Sci. | 3 |
| 2025 | A security enhanced certificateless aggregate signcryption scheme for VANETs
Dong Li 0016, Liangliang Wang 0001, Yang Liu 0291, Zhiquan Liu 0001, Kai Zhang 0008, Weiwei Li 0007 |
Peer Peer Netw. Appl. | 7 |
| 2024 | An Approach for APT Attack Scenario Construction Based on Dynamic Attack GraphsabstractAs network complexities and software intricacies escalate, complex attacks such as Advanced Persistent Threat (APT) are growing more challenging. Because APT attacks often lurk within the target environment for a long time, they are not easily detected. Therefore, we use the attack scenario construction method to identify APT attacks. Existing methods for constructing attack scenarios often neglect the influences of the vulnerability life cycle on atomic attacks. Furthermore, these methods rely on extensive prior data, resulting in the inability to directly update the risk probabilities of nodes. Consequently, the hazardous nodes are difficult to be dynamically and effectively identified. To address the above problems, this paper proposes an approach for APT attack scenario construction based on dynamic attack graph. Firstly, this paper analyzes the impact of the vulnerability life cycle on atomic attacks and quantifies the attack graph by incorporating factors such as vulnerability value, attack cost, attack income, and attack preference. Then, this approach integrates the attack graph with a Bayesian network to build a static attack graph, demonstrating the static risk conditions of the network. Finally, the dynamic attack graph is constructed by using forward and backward updates, thus constructing the attack scenarios and efficiently mining out the hazardous nodes. The experimental results show that the proposed method reliably maintains high dynamic reachable probability and adapts node probabilities to actual conditions, helping network administrators assess threats and address potential attacks beforehand. Mingsi Jiang, Mi Wen, Yun Xiong, Weiwei Li 0007 |
GLOBECOM | 4 |
| 2024 | ADP-VFL: An Adaptive Differential Privacy Scheme for VPP Based on Federated LearningabstractIn recent years, with the remarkable development of Virtual Power Plants (VPP) and the surge in the number of Electric Vehicles (EVs), the issue of data privacy leakage has become increasingly prominent. The effectiveness of existing federated learning schemes in mitigating data privacy leakage, it still faces potential threats such as inference attacks and user and server collusion. To protect the privacy of federated learning, some schemes have introduced differential privacy(DP). Nevertheless, applying DP will inevitably affect the accuracy to some extent. In this paper, we propose an adaptive differential privacy scheme for VPP based on federated learning, named ADP-VFL. Our ADP-VFL scheme can achieve data privacy preservation by transmitting the noise-added data as a chain, defend against inference attacks by innovating offset noise mechanism and a parallel transmission scheme. The performance evaluation results demonstrate that the proposed scheme can improve the aggregation accuracy and reduces the communication overhead. Mi Wen, Weiwei Li 0007, Ben Niu 0001, Weidong Qiu, Fenghua Li 0001 |
ICC | 3 |
| 2024 | DPG: a model to build feature subspace against adversarial patch attack
Yunsheng Xue, Mi Wen, Weiwei Li 0007 |
Mach. Learn. | 4 |
| 2023 | Collusion Detection and Trust Management for Indoor Navigation System With CrowdsourcingabstractThe indoor navigation system supported by spatial crowdsourcing emerges as a promising application to provide customized location service for requesters. An important stage of crowdsourcing is to select trustworthy workers. Workers’ reputation, as an essential criterion of this selection, is usually evaluated by feedback ratings from requesters. However, the reputation in the crowdsourcing-based indoor navigation system is vulnerable to the collusion attack, that is malicious workers (i.e., attackers) collude with requesters to illegally increase reputation. In this paper, we propose a collusion detection scheme to distinguish attackers and provide a secure reputation mechanism. Specifically, we first identify collusive requesters categorized into three different levels according to their feedback rating behaviors. Then, the weighted logistic regression (WLR) is developed to distinguish the collusive requesters who provide exorbitant feedback ratings. Furthermore, we employ an outlying sequence detection based on the maximum mean discrepancy (MMD), to resist the multiple location queries initiated by the same collusive requester through analyzing the distribution distance. In addition, we propose a community detection algorithm, named Fastgreedy, to identify the collusion from many requesters. Finally, the extensive simulation results demonstrate that the proposed scheme can effectively detect collusive requesters and significantly outperform other methods. Weiwei Li 0007, Mi Wen, Zhou Su 0001, Kuan Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | Defending Malicious Check-in Based on Access Point Selection for Indoor Positioning SystemabstractWiFi fingerprint-based positioning system emerges to offer fundamental location information for indoor mobile users. It facilitates the check-in to point of interest (POI) through submitting received signal strength (RSS) fingerprints in order to evaluate the crowd traffic. However, the crowd traffic evaluation with RSS fingerprints is vulnerable to the malicious check-in attacks. Attackers who are not at the target POI may still submit the self-modified RSS fingerprints located at the target POI in order to illegally increase its crowd traffic and eventually profit from this fake information. In this paper, we propose a defense scheme against malicious check-in based on access point (AP) selection to significantly reduce the success rate of fingerprint modification from attackers. Specifically, we first exploit fingerprint distance between POIs for AP selection. Then, we explore the mutual information between different POI classes to select APs with high robustness. In addition, the level set method (LSM) is developed to search the optimal modified fingerprint to assess attacker's costs. The extensive simulation results show that the proposed scheme can effectively resist attackers with high accuracy and facilitate crowd traffic evaluation of target POI according to the submitted RSS fingerprints. Weiwei Li 0007, Zhou Su 0001, Kuan Zhang 0001, Abderrahim Benslimane |
ICC | 1 |
| 2018 | Anomalous Path Detection for Spatial Crowdsourcing-Based Indoor Navigation SystemabstractIndoor navigation system provides customized path planning for requesters who are unfamiliar with the indoor environment, such as shopping mall and airport. Spatial crowd-sourcing technology can be applied to indoor navigation to offer fundamental services related to location. However, spatial crowdsourcing-based indoor navigation is vulnerable to the intrusion of injected anomalous paths from attackers. In this paper, we propose an anomalous path detection (APD) scheme to classify attackers according to their reputation management and abnormal trajectory sequence. Specifically, we first develop a crowdsourcing system to support the indoor location service using the fog as the spatial crowdsourcing server. Then, we identify two levels of attackers, i.e., the malicious responders and the semi-honest responders in the indoor environment according to their attacking purposes. Through the responders' historical records from the fog server, we analyze a series of trajectory sequences consisting of the distance between the current position and the destination to distinguish the semi-honest responders from the normal. In addition, we propose a semi-supervised learning with hidden Markov model (HMM) to detect the semi-honest responders. Finally, the extensive simulations show that the APD scheme can achieve higher accuracy with the acceptable false rate. Weiwei Li 0007, Kuan Zhang 0001, Zhou Su 0001, Rongxing Lu, Ying Wang 0002 |
GLOBECOM | 1 |