VLDB 2026 Research / reviewers in the wild / expert
Dan Zhu 0001
dblp:50/6054-1
· DBLP profile ↗
21ranked-venue papers
7as first author
17since 2021 · last 2026
0000-0002-3365-6757ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 11 · 3 first-author · 9 since 2021Security and privacy · 4 · 1 first-author · 4 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 1 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Moderation is the Best Policy: Dynamic Defense Against Gradient-Based Data Reconstruction Attacks in Federated LearningabstractFederated learning (FL) is a privacy-preserving distributed machine learning framework. However, recent studies have shown that implementing gradient-based data reconstruction attacks (DRA) can still lead to the leakage of user privacy through frequently uploaded model parameters in FL. Existing works leverage differential privacy (DP) to prevent privacy leakage, but the lack of effective scheduling of the privacy budget results in significant accuracy loss in the trained models. In this paper, we propose a novel dynamic privacy preserving federated learning framework, named NDPP-FL, capable of delivering robust defenses against DRA while significantly mitigating performance loss. Our key insight is to regard the privacy budget as a non-replenishable resource and dynamically schedule it based on privacy leakage risks to provide self-adaptive privacy protection for clients across varying communication rounds. Specifically, based on the amount of information between the local dataset and the transmitted parameters, we first design a parameter channel information leakage model. Then, during each update iteration, we introduce saliency perturbations based on the Hessian matrix to enhance defensive capabilities. Meanwhile, to improve the performance of NDPP-FL, sample-adaptive clipping and decaying noise perturbations are adopted in the construction. Furthermore, extensive experiments demonstrate that our framework performs excellently in terms of model accuracy and resilience against DRA. Qinyang Miao, Wen Sun 0004, Dan Zhu 0001, Jinku Li, Yajin Zhou, Cristina Alcaraz |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | When Multimedia Meets Security: Privacy-Preserving Cross-Modal Retrieval for Large-Scale DataabstractIn recent years, Cross-Modal Retrieval (CMR), which can retrieve data across types based on query semantics, has become an attractive technology due to the widespread applications of multimedia data. Outsourcing multimedia data to a cloud server is a reliable way to improve the quality of CMR services, but it will also incur potential data privacy leakage issues. Existing schemes for privacy-preserving outsourced data search services are either inapplicable to CMR or limited by efficiency and scalability. To address the above issues, we investigate the problem of Searchable Symmetric Encryption (SSE) for CMR in this paper. Firstly, we formulate the definition of SSE for CMR (namely, SSECMR) and extend the SSE leakage functions to capture the leakage in SSECMR. Then, by constructing distance-computation-free Hamming inverted multi-index, we propose a practical SSECMRconstruction. Specifically, we transform Hamming distance-based range queries into multi-key queries, thereby avoiding computationally expensive comparison operations and enabling efficient Hamming distance queries over encrypted data. Our design supports secure CMR with sub-linear complexity in a single communication roundtrip. Through rigorous security analysis, we demonstrate that our construction can provide adaptive security. Empirical evaluations on real-world datasets demonstrate that SSECMRoutperforms the state-of-the-art scheme in both efficiency and accuracy, and is comparable to plaintext applications. Our code is available at https://github.com/SSE-CMR/SSECMR. Weikai Huang, Xiangyu Wang 0010, Dan Zhu 0001, XinDi Ma, Jianfeng Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | An MPC-based nonlinear data-driven model for cascading failure prediction in large-scale infrastructure networks
Wei Hu 0008, Lemei Da, Dan Zhu 0001 |
Comput. Networks | 4 |
| 2025 | OBIR-tree: An Efficient Oblivious Index for Spatial Keyword Queries on Secure EnclavesabstractIn recent years, the widely collected spatial-textual data has given rise to numerous applications centered on spatial keyword queries. However, securely providing spatial keyword query services in an outsourcing environment has been challenging. Existing schemes struggle to enable top- k spatial keyword queries on encrypted data while hiding search, access, and volume patterns, which raises concerns about availability and security. To address the above issue, this paper proposes OBIR-tree, a novel index structure for oblivious (provably hides search, access, and volume patterns) top- k spatial keyword queries on encrypted data. As a tight spatial-textual index tailored from the IR-tree and PathORAM, OBIR-tree can support sublinear search without revealing any useful information. Furthermore, we present extension designs to optimize the query latency of the OBIR-tree: (1) combine the OBIR-tree with hardware secure enclaves ( e.g., Intel SGX) to minimize client-server interactions; (2) build a Real/Dummy block Tree (RDT) to reduce the computational cost of oblivious operations within enclaves. Extensive experimental evaluations on real-world datasets demonstrate that the search efficiency of OBIR-tree outperforms state-of-the-art baselines by 25x ~ 723× and is practical for real-world applications. Zikai Ye, Xiangyu Wang 0010, Dan Zhu 0001, Jianfeng Ma 0001 |
Proc. ACM Manag. Data | 4 |
| 2025 | DPSLS: an efficient local search algorithm for pure MaxSAT
Huisi Zhou, Wei Hu 0008, Dan Zhu 0001 |
Peer Peer Netw. Appl. | 4 |
| 2025 | Toward Precise and Explainable Hardware Trojan Localization at LUT LevelabstractTrojans represent a severe threat to hardware security and trust. This work investigates the Trojan detection problem from a unique viewpoint and proposes a novel hardware Trojan localization method targeting FPGA netlists. The proposed method automatically extracts the rich structural and behavioral features at look-up-table (LUT) level to train an explainable graph neural network (GNN) model for classifying design nodes in FPGA netlists and identifying the Trojan-infected ones. Experimental results using 183 hardware Trojan benchmarks show that our method successfully pinpoints Trojan-infected nodes with true positive rate, accuracy and area under the ROC curve (AUC) of 95.14%, 95.71% and 95.46% respectively. To the best of our knowledge, this is the first LUT level Trojan localization solution using explainable GNNs. Wei Hu 0008, Dan Zhu 0001, Lingjuan Wu |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2025 | Enabling Efficient and Privacy-Preserving Sequence Similarity Query on Encrypted GenomesabstractOver the past decades, Sequence Similarity Query (SSQ) has been widely used in genomic analysis. Several privacy-preserving SSQ schemes have been proposed to protect sensitive genomic data but struggle to balance security and efficiency. This paper proposes a Privacy-preserving Genomic SSQ (PGSSQ) scheme to address the above issue. Specifically, we first design two fundamental privacypreserving genomic matching methods, Edit-distance Threshold Match (ETM) and Dual-Threshold Match (DTM), to support approximate editdistance based threshold SSQ matches and range-constrained SSQ matches on encrypted high-dimensional genomic sequences, respectively. Then, we present a genetic index structure called Genomic Evaluation Tree (GE-Tree) based on the ETM and DTM. GE-Tree enables dynamic pruning of query paths without disclosing any genomic information from encrypted nodes, thereby supporting privacy-preserving SSQ on encrypted genomic data with sublinear computational complexity. Security analysis proves that PGSSQ is secure under selective chosenplaintext attacks. Experiments on a real-world dataset show that PGSSQ is efficient compared to state-of-the-art schemes. Xiangyu Wang 0010, Dan Zhu 0001, Cheng Huang 0001, Zhuoran Ma 0002, Jianfeng Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | New Diagnostics for Inferring Multiple Fault Scenarios and Accurate Fault Localization
Huisi Zhou, Wei Hu 0008, Dan Zhu 0001 |
GLOBECOM | 3 |
| 2024 | LUT Level Information Flow Tracking for FPGA Design Security VerificationabstractAs the core engine of modern communication systems, digital circuits are encountering significant security risks of cyber-attacks. Hardware information flow tracking (IFT) is a powerful tool for integrated circuit design security verification and vulnerability detection. While there are a large body of hardware IFT methods at different levels of abstraction, look-up-table (LUT) level IFT is still an open research challenge due to the huge number of possible LUT configurations that all correspond to varying IFT behaviors. In this work, we make the first move towards LUT level IFT for field programmable gate array (FPGA) design security verification. Specifically, we design an algorithm that enables automatic creation of the precise IFT model for an arbitrary LUT and the generation of fine-grained IFT logic for FPGA netlists. Through using the generated IFT logic as the security model, we can formally prove security properties and hunt for security vulnerabilities. Experimental results have demonstrated that our method can detect the timing channels and hardware Trojans residing in the synthesized FPGA netlists of Trust-Hub benchmarks. Our work complements the spectrum of hardware security verification solutions at both the FPGA netlist and bitstream ends, which fills in the gap of post-synthesis FPGA design security verification tools. Wei Hu 0008, Lingjuan Wu, Dan Zhu 0001 |
GLOBECOM | 4 |
| 2024 | Enabling Efficient Spatio-Temporal Range Query over Encrypted DatabasesabstractSpatio-temporal query services have been playing an increasingly important role in people’s daily lives. While outsourcing such services to third parties (e.g., cloud servers) offers considerable benefits, it raises data privacy issues. However, no existing work can fully support secure and efficient spatio-temporal queries in outsourcing environments. In this paper, we investigate the problem of Spatio-Temporal Range queries over Encrypted databases (STRE). Firstly, we design a new index structure, called Hilbert Hierarchical Prefix Bloom tree (H2PB-tree), which reduces the search complexity of spatio-temporal range query to sublinear. Then, we build an efficient STRE construction called E-STRE in the single-cloud model based on H2PB-tree and symmetric hidden-vector encryption. Moreover, we perform sufficient security analysis and experimental test, and the results show E-STRE outperforms prior arts in terms of performance while guaranteeing data security. Compared with the prior arts presented under the single-cloud model, our construction reduces the query delay by at least 18×. Dan Zhu 0001, Xiangyu Wang 0010, Cheng Huang 0001, Peilin Han, Wei Hu 0008, Jianfeng Ma 0001 |
GLOBECOM | 1 |
| 2024 | Efficient and Accurate Cloud-Assisted Medical Pre-Diagnosis With Privacy PreservationabstractThe emergence of cloud computing enables various healthcare institutions to outsource pre-diagnostic models and provide timely and convenient services for patients. However, healthcare institutions and patients have serious concerns about potential privacy leakage as cloud servers cannot be fully trusted. In this paper, a privacy-preserving cloud-assisted medical pre-diagnosis scheme, named NAIAD, is proposed, where patients can securely query the outsourced model and obtain their pre-diagnostic results. Specifically, the pre-diagnostic model is constructed on$k$-Nearest Neighbor ($k$NN), and Mahalanobis Distance (MD) is chosen as the similarity metric to achieve high accuracy. Accordingly, a secure MD-based comparison method (SMDC) is designed based on a matrix encryption technique. The method is a basic module of NAIAD that enables cloud servers to compare encrypted medical records and achieve privacy-preserving$k$NN-based pre-diagnosis with linear complexity. To further improve the computational efficiency, medical records are first clustered and encrypted to construct a hierarchical index tree, then patients can query the tree to speed up the query process. Detailed security analysis indicates NAIAD can resist closeness-same-pattern chosen-plaintext attack, and extensive experiments on real-world and synthetic databases demonstrate NAIAD has high query efficiency and pre-diagnosis accuracy. Dan Zhu 0001, Hui Zhu 0001, Cheng Huang 0001, Rongxing Lu, Dengguo Feng, Xuemin Shen |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Enabling Efficient and Distributed Access Control for Pervasive Edge Computing ServicesabstractIn this paper, we propose an efficient and distributed service access control framework (E-DAC) in the pervasive edge computing (PEC) environment, where the resources of peer devices at the network edge are integrated to provide latencysensitive computing services to the nearby devices on behalf of edge servers. E-DAC addresses the challenge of efficient and distributed service access control, comprising edge service authorization, service access authorization, and mutual authentication between edge servers and edge devices. In dong so, E-DAC first extends a key-aggregate cryptosystem to enable batch service authorization, in which a service provider can aggregate the authorization keys of different services to produce a constant-size aggregate key for an edge server. Second, E-DAC enables users to acquire authorization from the service provider for service access on edge servers by using efficient secret sharing. Third, edge servers and users can authenticate with each other without interacting with a centralized server, while enabling secure zero-round trip communication, so that the service data is protected and the communication bandwidth cost is low. In addition, the service provider is capable of efficiently revoking the authorization of the dropout or compromised edge servers or users in response to the dynamics of the PEC environment. Finally, we prove the security of service access control in E-DAC, including unforgeability of service authorization and confidentiality of service data, and conduct extensive analysis and experiments to demonstrate that E-DAC is highly computational and communication-efficient on service authorization, authentication, and revocation. Lingshuang Liu, Cheng Huang 0001, Dan Zhu 0001, Jianbing Ni, Xuemin Shen |
IEEE Trans. Mob. Comput. | 3 |
| 2023 | Efficient and Privacy-Preserving Similar Patients Query Scheme Over Outsourced Genomic DataabstractOver the past decade, genomic data has grown exponentially and is widely used in promising medical and health-related applications, which opens up new opportunities for the field of medicine. Similar patients query (SPQ), which can help physicians formulate an optimal therapy, is one of such popular applications. Despite its popularity, since human genomes are usually highly sensitive, a series of policies have been launched by the government to strictly control its acquisitions and utilization. Thus, how to prevent privacy disclosure becomes of great importance to the flourish of SPQ services. In this article, aiming at the above challenge, we first design a novel genetic BK-tree (GBK-tree) for a genomic database. Then, combined with a random sorting mechanism and some existing encryption techniques, we propose an efficient and privacy-preserving similar patients query scheme over encrypted cloud data, named CASPER. With CASPER, a medical institution can securely outsource its private genomic database to a cloud server, and physicians can request SPQ services from the cloud server while keeping her/his query secret. Detailed security analysis shows that CASPER can preserve privacy in the presence of different threats. Furthermore, extensive performance evaluations demonstrate the high accuracy and efficiency of our proposed scheme. Dan Zhu 0001, Hui Zhu 0001, Xiangyu Wang 0010, Rongxing Lu, Dengguo Feng |
IEEE Trans. Cloud Comput. | 1 |
| 2023 | An Accurate and Privacy-Preserving Retrieval Scheme Over Outsourced Medical ImagesabstractWith the rapid advancement in medical imaging techniques, Content-Based (medical) Image Retrieval (CBIR), which can assist in disease diagnosis, has gained much attention in both academia and industry. However, due to patients’ sensitive information involved in medical images, privacy-preserving CBIR is a challenge worth exploiting. Though several privacy-preserving CBIR schemes have been put forth, they can only resist known-background attack (KBA), and do not suffice for protecting the image privacy in outsourced settings. In this article, aiming at the above challenge, we first design a novel Privacy-preserving Mahalanobis Distance Comparison (PMDC) method to improve the accuracy of medical images retrieval. Then, combined with the Mahalanobis distance based Fuzzy C-Means (FCM-M) algorithm, a scheme named TAMMIE is proposed to achieve accurate and privacy-preserving medical image retrieval over encrypted data. With TAMMIE, an image owner can securely outsource the images and indexes to a cloud server, and query users can request retrieval services from the cloud server while keeping their queries private. Detailed security analysis shows that our proposed schemes are secure under the attack stronger than KBA. Furthermore, thorough empirical experiments conducted on two real-world and one synthetic datasets also demonstrate the efficiency of TAMMIE. Dan Zhu 0001, Hui Zhu 0001, Xiangyu Wang 0010, Rongxing Lu, Dengguo Feng |
IEEE Trans. Serv. Comput. | 1 |
| 2022 | Secure and Distributed Access Control for Dynamic Pervasive Edge Computing ServicesabstractPervasive edge computing (PEC) integrates the re-sources of peer devices at the network edge to serve users' latency-sensitive computation needs. Due to the high dynamics of the PEC environment, it is very challenging to achieve efficient service access control of edge servers and users without an “always-online” centralized server. In this paper, we propose a secure, efficient, and distributed service access control frame-work (SE-DAC) in the PEC environment. Specifically, SE-DAC extends the key-aggregate cryptosystem to achieve batch service authorization, where the service provider aggregates the access keys of different services to produce a constant-size aggregate key for the edge servers. Meanwhile, user authentication tasks are delegated to the edge servers by integrating secret sharing. The mutual authentication between the edge servers and the users is based on zero-round trip communication, such that the communication bandwidth cost is low. In addition, the service provider can efficiently revoke the authorization of the dropout or compromised edge servers in response to the dynamics of the PEC environment. Finally, we conduct numerical analysis and experiments to demonstrate that SE-DAC is highly computational efficient on service authorization, authentication, and revocation. Lingshuang Liu, Cheng Huang 0001, Dan Zhu 0001, Jianbing Ni, Xuemin Shen |
GLOBECOM | 3 |
| 2022 | Efficient Server-Aided Personalized Treatment Recommendation with Privacy PreservationabstractWith AI-derived knowledge graph (KG), medical centers can recommend appropriate treatment options to physicians as references based on their patients' personal healthcare information (PHI). However, the treatment recommendation services may also cause serious privacy concerns. In this paper, we propose an efficient and privacy-preserving personalized treatment recommendation scheme with the aid of a third-party server. Specifically, a medical center denotes the KG of each disease by a directed graph with conditional edges and vertices that describe the treatment options and costs in different states. To prevent privacy leakage while reducing computational and management cost, the graphs are encrypted and then delegated to an honest-but-curious server. With the assistance of the server, physicians can set proper illness states and cost requirements according to patients' PHI, and correspondingly generate personalized ciphertexts to retrieve appropriate treatment options. The key component of the proposed scheme is a novel designed secure and flexible path comparison protocol, by tailoring a symmetric homomorphic encryption algorithm and combining it with a secure hash function. The protocol can enable the server to compare the uploaded ciphertexts with encrypted graphs in a secure and efficient way. Comprehensive security analysis indicates that the proposed scheme can meet desirable privacy requirements, and extensive experimental results demonstrate its practicality. Dan Zhu 0001, Hui Zhu 0001, Cheng Huang 0001, Rongxing Lu, Xuemin Shen, Dengguo Feng |
GLOBECOM | 1 |
| 2021 | Fast and Secure Location-Based Services in Smart Cities on Outsourced DataabstractWith the advancement of mobile Internet, cloud computing, and smart sensing devices, location-based services (LBSs) have become more and more indispensable in the Internet-of-Things (IoT)-based smart cities. Especially, spatial keyword queries have been widely deployed in real-life applications in recent years. Recently, several privacy-preserving spatial keyword queries schemes were proposed to guarantee data security and query privacy on outsourced data. However, these schemes support neither dynamic update nor diverse query types, which cannot meet the requirements in practical applications. This article proposes two secure dynamic spatial keyword queries (SDSKQs) constructions that support expressive query types and dynamic update. First, we present a basic SDSKQ construction based on hidden-vector encryption and order-revealing encryption. Specifically, we propose a secure hybrid index structure forspatio-textualdata, named encrypted textual signature quadtree (ETSQ-tree). Using ETSQ-tree, the server can prune the index tree according to search queries to reduce the search space. Besides, the ETSQ-tree can be updated dynamically. To resist the file-injection attack, which aims to infer query information according to newly inserted objects, we further improve the basic SDSKQ to achieve forward security. We implement our two constructions and evaluate them using real-world data sets. The experimental results show that they are efficient and feasible in practical applications, and the comparative evaluation confirms that the performance of our constructions outperforms that of the state-of-the-art schemes. Xiangyu Wang 0010, Jianfeng Ma 0001, Yinbin Miao, Ximeng Liu, Dan Zhu 0001, Robert H. Deng |
IEEE Internet Things J. | 5 |
| 2020 | Spatial Dynamic Searchable Encryption with Forward Security
Xiangyu Wang 0010, Jianfeng Ma 0001, Ximeng Liu, Yinbin Miao, Dan Zhu 0001 |
DASFAA (2) | 5 |
| 2020 | Search Me in the Dark: Privacy-preserving Boolean Range Query over Encrypted Spatial DataabstractWith the increasing popularity of geo-positioning technologies and mobile Internet, spatial keyword data services have attracted growing interest from both the industrial and academic communities in recent years. Meanwhile, a massive amount of data is increasingly being outsourced to cloud in the encrypted form for enjoying the advantages of cloud computing while without compromising data privacy. Most existing works primarily focus on the privacy-preserving schemes for either spatial or keyword queries, and they cannot be directly applied to solve the spatial keyword query problem over encrypted data. In this paper, we study the challenging problem of Privacy-preserving Boolean Range Query (PBRQ) over encrypted spatial databases. In particular, we propose two novel PBRQ schemes. Firstly, we present a scheme with linear search complexity based on the space-filling curve code and Symmetric-key Hidden Vector Encryption (SHVE). Then, we use tree structures to achieve faster-than-linear search complexity. Thorough security analysis shows that data security and query privacy can be guaranteed during the query process. Experimental results using real-world datasets show that the proposed schemes are efficient and feasible for practical applications, which is at least ×70 faster than existing techniques in the literature. Xiangyu Wang 0010, Jianfeng Ma 0001, Ximeng Liu, Robert H. Deng, Yinbin Miao, Dan Zhu 0001, Zhuoran Ma 0002 |
INFOCOM | 6 |
| 2020 | CREDO: Efficient and privacy-preserving multi-level medical pre-diagnosis based on ML-kNN
Dan Zhu 0001, Hui Zhu 0001, Ximeng Liu, Hui Li 0006, Fengwei Wang, Hao Li 0038, Dengguo Feng |
Inf. Sci. | 1 |
| 2018 | Achieve Efficient and Privacy-Preserving Medical Primary Diagnosis Based on kNNabstractOnline medical primary diagnosis system, which can provide the pre-diagnosis service anywhere anytime, has attracted considerable interest. However, the flourish of online medical primary diagnosis system still faces many serious challenges since the sensitivity of personal health information and service provider''s diagnosis model. In this paper, we propose an efficient and privacy-preserving medical primary diagnosis scheme based on k-nearest-neighbors classification (kNN), called EPDK. With EPDK, medical users can ensure that their sensitive health information are not compromised during the online medical diagnosis process, and service provider can provide high-accuracy service without revealing its diagnosis model. Specifically, based on lightweight multiparty random masking and polynomial aggregation techniques, a medical user preprocesses her/his query vector before sending out and the preprocessed vector is directly operated in the service provider without obtaining original data, meanwhile, the primary diagnosis result cannot be achieved by anyone except the medical user. Through extensive analysis, we show that EPDK can resist multifarious known security threats, and has significantly lower computation complexity than existing schemes. Moreover, performance evaluations via implementing EPDK in the real environment demonstrate that EPDK is highly efficient in terms of computation overhead. Dan Zhu 0001, Hui Zhu 0001, Ximeng Liu, Hui Li 0006, Fengwei Wang, Hao Li 0038 |
ICCCN | 1 |