VLDB 2026 Research / reviewers in the wild / expert
Liang Guo 0013
dblp:52/2803-13
· DBLP profile ↗
9ranked-venue papers
0as first author
9since 2021 · last 2026
0000-0002-5672-3721ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 5 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Verifiable and Controllable Data Sharing With Compliance Checking in Cloud ComputingabstractData capsule provides a feasible solution for controllable data sharing, where data owners outsource their data capsules containing encrypted data and compliance-checking policies to the cloud server, and only valid users can run a compliant analysis program to process the decrypted data capsules in the Trusted Execution Environment (TEE), without obtaining the raw data. However, existing schemes cannot achieve verifiable accesses and updates, which means that malicious servers may use corrupted/old data capsules to deceive users and TEE. In this paper, we introduce the concept of Verifiable Data Capsule (VDC) for secure and controllable data sharing. Specifically, we first design a lightweight authentication tag, dubbed Locally Verifiable Chameleon Tag (LVCT), which allows the data owner to bind all data capsules to a constant-size tag and enables users to recover the local tags for validating data capsules. On this basis, we present a concrete VDC scheme that utilizes a dual-level authentication structure to realize verifiable data updates, and verifiable state updates triggered by regular access without the aid of the data owner. Furthermore, we propose an efficient trust evaluation protocol to judge the credibility of cloud servers. Finally, both security analysis and performance evaluation demonstrate the practicability of the proposed scheme. Guohua Tian, Meixia Miao, Jianghong Wei, Zheli Liu, Liang Guo 0013, Xiaofeng Chen 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | BOMAP: A Round-Efficient Construction of Oblivious MapsabstractOblivious map is a cryptographic data structure for programs whose data access patterns exhibit some degree of predictability, which plays a pivot role in constructing high-security searchable encryption schemes that protect both search and access patterns. Typically, oblivious map schemes adopt the combination of an index tree and Oblivious RAM (ORAM) in their construction. However, the round complexity of access operations in these schemes is inherently linked to the height of the index tree, which is logarithmically proportional to the total number of blocks, denoted as$N$. This results in a traditional requirement of$O(\log N)$rounds of interaction per access, which is a significant inefficiency that hampers the practical applicability of oblivious maps. To this end, we design a new fixed-height index tree structure and employ it to construct a new oblivious map scheme, called BOMAP. This scheme features a small number of interaction rounds and does not require the client to store state information beyond the cache. Additionally, BOMAP achieves obliviousness with reduced padding in each access operation. We analyze the theoretical communication size for BOMAP and conclude that BOMAP has obvious advantages when an adaptive height is selected based on$N$(e.g., a 4-level index tree when$N=2^{24}$). Experimental results further demonstrate that the fewer interaction rounds and less padding strategy make BOMAP more efficient than previous oblivious map schemes. Siyi Lv, Xiang Li 0156, Haoshuai Gong, Zheli Liu, Tong Li 0011, Liang Guo 0013 |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2025 | Leveraging large language models for SQL behavior-based database intrusion detectionabstractDatabase systems are extensively used to store critical data across various domains. However, the frequency of abnormal database access behaviors, such as database intrusion by internal and external attacks, continues to rise. Internal masqueraders often have greater organizational knowledge, making it easier to mimic employee behavior effectively. In contrast, external masqueraders may behave differently due to their lack of familiarity with the organization. Current approaches lack the granularity needed to detect anomalies at the operational level, frequently misclassifying entire sequences of operations as anomalies, even though most operations are likely to represent normal behavior. On the other hand, some anomalous behaviors often resemble normal activities, making them difficult for existing detection methods to identify. This paper introduces a two-tiered anomaly detection approach for Structured Query Language (SQL) using the Bidirectional Encoder Representations from Transformers (BERT) model, specifically DistilBERT, a more efficient, pre-trained version. Our method combines both unsupervised and supervised machine learning techniques to accurately identify anomalous activities while minimizing the need for data labeling. First, the unsupervised method uses ensemble anomaly detectors that flag embedding vectors distant from learned normal patterns of typical user behavior across the database (out-of-scope queries). Second, the supervised method uses fine-tuned transformer-based models to detect internal attacks with high precision (in-scope queries), using role-labeled classification, even on limited labeled SQL data. Our findings make a significant contribution by providing an effective solution for safeguarding critical database systems from sophisticated threats. Meital Shlezinger, Shay Akirav, Liang Guo 0013, Avi Kessel, Guoliang Li 0001 |
TrustCom | 4 |
| 2025 | LUNA: Efficient Backward-Private Dynamic Symmetric Searchable Encryption Scheme With Secure Deletion in Encrypted DatabaseabstractDynamic symmetric searchable encryption (SSE) enables clients to perform searches and updates on an encrypted database outsourced to an untrusted server while preserving the privacy of data and queries. For restricting information leakage, it is very important to limit what the server can learn about the deleted data during searches after the deletion, i.e., to satisfy backward privacy. However, previous backward privacy definitions only considered the logical deletion of keywords in documents while ignoring security risks caused by the actual deletion of documents. Moreover, existing SSE schemes often depend on heavy cryptographic primitives for achieving high-level backward privacy, which greatly degrades the end-to-end performance. To this end, we define a new backward privacy notion named BP-DEL, which restricts the information leakage of the actual deletion. Moreover, we design a hybrid index structure that provides BP-DEL for SSE schemes such that they support deletions securely. Based on the hybrid index, we propose a BP-DEL construction named LUNA and design its protocols with a trusted execution environment (TEE) to maintain the index efficiently. Finally, we implement LUNA in the MySQL database by encapsulating it in UDFs. The experimental results show that LUNA has a performance much better than previous works satisfying BP-DEL. Siyi Lv, Yanyu Huang, Tong Li 0011, Liang Guo 0013, Xiaofeng Chen 0001, Zheli Liu |
IEEE Trans. Knowl. Data Eng. | 5 |
| 2024 | New approach for efficient malicious multiparty private set intersection
Siyi Lv, Yu Wei 0007, Jingyu Jia, Tong Li 0011, Zheli Liu, Xiaofeng Chen 0001, Liang Guo 0013 |
Inf. Sci. | 8 |
| 2024 | ABSyn: An Accurate Differentially Private Data Synthesis Scheme With Adaptive Selection and Batch ProcessesabstractIn private data publishing, a promising solution is generating synthetic data that enables any query on the private dataset while satisfying differential privacy. Over the past decade, researchers mainly focused on improving the query accuracy of synthetic data. However, the limitations of existing works restrict them from achieving a better trade-off between accuracy and privacy. In this paper, we propose ABSyn, a novel scheme for differentially private data synthesis. Under the Select-Measure-Generate paradigm, ABSyn has an adaptive mechanism for precisely selecting marginals and follows the batch processes. Our adaptive-batch scheme can provide a well-selected marginal set and the optimal allocation of privacy budget, which makes its synthetic data achieve high accuracy without compromising privacy. We implement an efficient prototype of ABSyn and compare it with existing works by analyzing public datasets. Experimental results show that ABSyn achieves query accuracy on synthetic datasets by a factor of$1.26\times $and efficiency by a factor of$18.60\times $over the state-of-the-art scheme on average. Jingyu Jia, Tong Li 0011, Zhewei Liu, Siyi Lv, Liang Guo 0013, Changyu Dong, Zheli Liu |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2024 | FRQ: Fast Range Query Over Large-Scale Encrypted Key-Value DataabstractWith the rapid growth of data size, a large number of data providers outsource their private data to cloud servers to reduce the high storage and computation burdens, but it also leads to security issues such as privacy leakage. Therefore, many privacy-preserving range query schemes have been proposed. However, most of existing secure range query schemes suffer from low query efficiency and expensive computation and update overheads. To address these issues, we propose a novel Fast Range Query (FRQ) scheme for large-scale encrypted Key-Value (KV) data. First, we introduce REMIX, a space-efficient KV index data structure based on Log-Structured Merge-trees (LSM-trees), which maintains a global sorted view of KV pairs across multiple table files for efficient range queries. Besides, we exploit the write-efficiency compression strategy of LSM-trees to ensure efficient dynamic data updates. Finally, we use Czech Havas Majewski (CHM) to protect the index structure, which reduces the computation overhead and ensures the retrieval accuracy. Formal security analysis proves that our scheme can achieve an acceptable level of security. Extensive experiments demonstrate that our scheme improves the query efficiency by nearly$8\times$and update efficiency by$7\times$compared to state-of-the-art solutions over million-level datasets. Yinbin Miao, Xinghua Li 0001, Yanguo Peng, Liang Guo 0013, Hongwei Li 0001, Robert H. Deng |
IEEE Trans. Serv. Comput. | 5 |
| 2022 | EncodeORE: Reducing Leakage and Preserving Practicality in Order-Revealing EncryptionabstractOrder-preserving encryption (OPE) is a cryptographic primitive that preserves the order of plaintexts. In the past few years, many OPE schemes were proposed to solve the problem of executing range queries in encrypted databases. However, OPE leaks some certain information (for example, the order of ciphertext), so it is vulnerable to many attacks. Subsequently, order-revealing encryption (ORE) was proposed by Bonehet al.(Eurocrypt 2015) as a generalization of order-preserving encryption. It breaks through the limitation of the numeric order of OPE plaintext. It implements ciphertext comparison for any specific form of plaintext through a publicly computable comparison function. In this article, we aim to design a new ORE scheme which reduces the leakages and preserves the practicality in terms of ciphertext length and encryption time. We first propose the hybrid model namedHybridORE. Then, we propose an improved scheme namedEncodeOREwhich achieves acceptable security and appropriate ciphertext length. They both explore the encode strategy of encoding plaintext into different parts and apply suitable ORE algorithms to each part according to its security characteristics to reduce leakages. Compared with the typical CLWW scheme (FSE 2016) and Lewi-Wu (CCS 2016) in large domain, they have fewer leakages. The experiment shows that the proposedEncodeOREis very practical. Zheli Liu, Siyi Lv, Jin Li 0002, Yanyu Huang, Liang Guo 0013, Yali Yuan, Changyu Dong |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | Frequency-Hiding Order-Preserving Encryption with Small Client StorageabstractThe range query on encrypted databases is usually implemented using the order-preserving encryption (OPE) technique which preserves the order of plaintexts. Since the frequency leakage of plaintexts makes OPE vulnerable to frequency-analyzing attacks, some frequency-hiding order-preserving encryption (FH-OPE) schemes are proposed. However, existing FH-OPE schemes require either the large client storage of size O ( n ) or O (log n ) rounds of interactions for each query, where n is the total number of plaintexts. To this end, we propose a FH-OPE scheme that achieves the small client storage without additional client-server interactions. In detail, our scheme achieves O ( N ) client storage and 1 interaction per query, where N is the number of distinct plaintexts and N ≤ n . Especially, our scheme has a remarkable performance when N ≪ n . Moreover, we design a new coding tree for producing the order-preserving encoding which indicates the order of each ciphertext in the database. The coding strategy of our coding tree ensures that encodings update in the low frequency when inserting new ciphertexts. Experimental results show that the single round interaction and low-frequency encoding updates make our scheme more efficient than previous FH-OPE schemes. Siyi Lv, Yanyu Huang, Yijing Liu 0007, Tong Li 0011, Zheli Liu, Liang Guo 0013 |
Proc. VLDB Endow. | 7 |