VLDB 2026 Research / reviewers in the wild / expert
Chao Li 0023
dblp:66/190-23
· DBLP profile ↗
41ranked-venue papers
18as first author
25since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 5 first-author · 10 since 2021Software engineering, systems software and programming languages · 11 · 4 first-author · 9 since 2021Systems, architecture and hardware · 6 · 3 first-author · 1 since 2021Databases, data management, data science and information retrieval · 5 · 3 first-author · 3 since 2021Computer networks · 4 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The Promise vs. Reality of NFT Decentralization: An Empirical Study of Storage Strategies and Defects
Yufang Wu, Siwen Chen, Chao Li 0023, Yuan Weng, Wei Wang 0012 |
WWW | 3 |
| 2026 | Lightweight Authentication for Drone Service Collaboration Using Blockchain-Based Decentralized Identity and Physically Unclonable FunctionsabstractIn an open and complex environment of drone service collaboration scenarios, efficient identity authentication is essential for secure service interactions. Traditional schemes suffer from high computational costs, low communication efficiency, and vulnerability to single-point failures. This paper presents a new lightweight authentication scheme (BDP-Auth) based on blockchain decentralized identity (DID) and physically unclonable functions (PUFs). PUF enables low-power, low-cost identity key generation without relying on complex computation or large storage, ensuring tamper-proof identifiers while reducing hardware and energy overhead. Using blockchain decentralization, the DID mechanism securely registers and stores drone identities, offering transparency and integrity. Security analysis shows that BDP-Auth achieves forward and backward security, meaning that the compromise of the current session key does not reveal past or subsequent session communications, and also resists physical capture and impersonation attacks. Experiments demonstrate that, compared to PRLAP-IoD, BDP-Auth reduces the computation overhead by 38.3% and 45.0% on the STM32F4 and NodeMCU platforms, respectively, decreases communication overhead by 36.9%, and reduces storage overhead by 27.5%, significantly improving overall efficiency. Pengrui Chen, Jiqiang Liu, Ye Du 0001, Ning Ruan, Chao Li 0023, Wei Wang 0012, Wei Ni 0001 |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2025 | Privacy-Preserving Authentication Using Blockchain and Implicit Certificates for Internet of VehiclesabstractIn Internet of Vehicles (IoV) environments, the scheme's openness and complexity create opportunities for malicious nodes to disseminate false information, leading to data tampering and privacy breaches. Traditional authentication methods rely on trusted third parties for digital certificate verification, which introduces storage overhead and a single point of failure, factors incompatible with the dynamic and resource-constrained nature of IoV networks. This paper proposes a privacy-preserving authentication scheme based on blockchain technology and implicit certificates. The method utilizes pseudonymous certificates to protect vehicle identity privacy and employs implicit certificates as a substitute for traditional digital certificates, addressing the challenges associated with the storage and transmission of conventional certificates in IoV settings. Furthermore, a decentralized management mechanism is implemented for certificate revocation lists (CRL) on the blockchain, mitigating the risk of a single point of failure. To accommodate the high mobility characteristics of vehicles, a rapid reconnection mechanism is introduced, substantially reducing reconnection times and improving communication efficiency. The security analysis and experimental results validate the effectiveness of the proposed method in preserving privacy and improving performance in IoV scenarios. Donghang Li, Chao Li 0023, Wei Ni 0001 |
ICWS | 5 |
| 2025 | CustomFair: A Customized Fairness Method for Federated Recommender Systems in Social Internet of ThingsabstractIn the Social Internet of Things (SIoT), edge computing integrates artificial intelligence to learn intricate relationships. The scale and complexity of SIoT cause a data explosion from diverse objects, hindering tailored services to users who own objects. Moreover, conventional edge computing in SIoT depends on centralized data collection, raising concerns about data privacy. To address the above two issues, federated recommender systems (FRSs) present a promising solution. FRSs can provide SIoT services to users and train a shared model while retaining sensitive data locally on objects. However, as FRSs are driven by data, they are inherently susceptible to algorithmic bias, raising substantial fairness concerns that have attracted considerable attention in SIoT. Recent fairness studies predominantly concentrate on a single sensitive attribute for users, thereby overlooking their autonomy. Therefore, we propose CustomFair, a personalized fairness framework that enables users in FRSs to select preferred sensitive attributes and acquire satisfied recommendation services in SIoT scenarios. First, we define customized fairness to ensure group fairness based on users’ sensitive attributes. The server segments users into subgroups in a privacy-preserving manner. Second, CustomFair employs the DynBalance method with a flexible regularization coefficient to improve recommendation performance and utilizes the AdaptEpoch strategy to achieve fairness. Extensive experiments indicate that CustomFair improves recommendation performance by 0.1–42.92 and enhances fairness by reducing disparities of 0.03–5.41 compared to two baselines across three datasets. Chao Li 0023, Zihang Yin, Bin Wang 0062, Tao Li 0022, Xuhua Bao, Wei Wang 0012 |
IEEE Internet Things J. | 2 |
| 2025 | Secure and Fine-Grained Data Sharing in Internet of Things: Integration of Interplanetary File System and Cross-Blockchain for Access ControlabstractWith the proliferation of data sharing in the Internet of Things (IoT), protecting privacy-sensitive information and preventing unauthorized access have become paramount concerns. Existing centralized access control methods faces single-point-of-failure risks and lacks scalability for dynamic IoT systems. This paper proposes a fine-grained access control framework based on cross-blockchain technology for transparent and flexible IoT data sharing. In our framework, the cross-blockchain module is facilitated to eliminate data isolation across domains, the Interplanetary File System (IPFS) is used to mitigate centralized storage risks and reduce blockchain storage overhead, CP-ABE and symmetric encryption are integrated to enforce attribute-based, fine-grained access control with strong security guarantees. Meanwhile, the blockchain records data and key references to enforce secure access to shared data content. We further conduct security analysis and experimental evaluations, demonstrating the effectiveness and efficiency of the proposed scheme. Jiqiang Liu, Wei Ni 0001, Chao Li 0023, Wei Wang 0012, Zhiquan Liu 0001, Abbas Jamalipour |
IEEE Internet Things J. | 5 |
| 2025 | FairReward: Towards Fair Reward Distribution Using Equity Theory in Blockchain-Based Federated LearningabstractEnsuring fairness in incentive mechanisms for federated learning (FL) is essential to attracting high-quality clients and building a sustainable FL ecosystem. Most existing fairness-aware incentive mechanisms distribute rewards to FL clients by quantifying their contributions to the performance of the global model. Essentially, these mechanisms pursuecontribution fairness, namely a constant contribution-reward ratio across FL clients, with an implicit assumption that clients would be satisfied with thecontribution fairness. However, research in social psychology has confirmed that this assumption may not hold in many real-world scenarios. According to equity theory proposed by Adams, an individual’s assessment and perception of receiving fair treatment significantly depend on the input-outcome ratio, where outcome simply refers to the rewards, while input is far more complex because it involves a bunch of subtle factors such as enthusiasm, experience and tolerance as well as the estimated contributions. Inspired by Adams’ equity theory, in this work, we expand the notion ofcontribution fairnesstoinput fairnessand propose a new fairness-aware incentive mechanism namedFairRewardthat distributes rewards under the joint consideration of self-reported inputs and computed contributions.FairRewardemploys a reputation mechanism to enhance the credibility of self-reported inputs and leverages blockchains to eliminate the need of a trusted FL server and monetarily incentivize/penalize clients. In addition,FairRewardadopts techniques including distributed differential privacy and locality-sensitive hashing to address privacy and non-IID issues in FL. Moreover, we conduct a comprehensive security and privacy analysis. Finally, we evaluateFairRewardthrough extensive experiments. The comprehensive experimental results demonstrate thatFairRewardis effective, scalable and attack-resistant, and provides theinput fairnessrequired. Chao Li 0023, Wei Wang 0012, Bin Wang 0062, Zhen Han 0001, Xiangliang Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | RobustPFL: Robust Personalized Federated LearningabstractConventional federated learning (FL) coordinated by a central server focuses on training a global model and protecting the privacy of clients' training data by storing it locally. However, the statistical heterogeneity hinders the global model from adapting to the non-IID distributions among clients. Moreover, untrusted and unreliable central servers and malicious clients may compromise model integrity and availability, thus degrading the robustness of FL. To address these challenges, we present RobustPFL, a decentralized personalized federated learning (PFL) approach that combines$\alpha$-based Layer-position Normalized Similarity ($\alpha$-LNS) and local collaborative training to improve personalized performance while utilizing a blockchain-based committee mechanism to coordinate the aggregation process, thereby achieving high personalized accuracy and robustness. Extensive experiments show that our RobustPFL approach outperforms multiple algorithms, including Local training, FedAvg, FedReptile, Per-FedAvg, FedBN, and SPFL, on MNIST, CIFAR10, EMNIST, and N-BaIoT datasets in four non-IID settings. We also evaluate RobustPFL's effectiveness against attacks—poisoning attacks and free-riding attacks. Particularly, for three prevalent poisoning attacks (backdoor, label flipping, and model poisoning attacks), we compare non-defensive (FedAvg) and defensive (Krum, trimmed mean, Bulyan, FedBN, FLAME, and FangTrmean) methods with our proposed RobustPFL. The results show that our approach achieves significant defensive effects. Wei Wang 0012, Yufang Wu, Chao Li 0023, Guangquan Xu, Shouling Ji, Tao Li 0022, Meng Shen 0001, Yufei Han 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Finding the PISTE: Towards Understanding Privacy Leaks in Vertical Federated Learning SystemsabstractVertical Federated Learning (VFL) is a collaborative learning paradigm where participants share the same sample space while splitting the feature space. In VFL, local participants host their bottom models for feature extraction and collaboratively train a classifier by exchanging intermediate results with the server owning the labels. Both local training data and bottom models contain privacy-sensitive information and are considered the intellectual property of each participant, and thus should be protected by the design of VFL. Our study exposes the fundamental susceptibility of VFL systems to privacy leaks, which arise from the collaboration between the server and clients during both training and testing. Based on our findings, we proposePISTE, a model-agnostic framework of privacy stealing attacks against VFL. PISTE delivers three privacy inference attacks, i.e., model stealing, data reconstruction, and property inference attacks on five benchmark datasets and four different model architectures. We further discuss four potential countermeasures. Experimental results show that all of them cannot prevent all three privacy stealing attacks in PISTE. In summary, our study demonstrates the inherent yet rarely uncovered vulnerability of VFL on leaking data and model privacy. Xiangrui Xu 0001, Wei Wang 0012, Bin Wang 0062, Chao Li 0023, Zhen Han 0001, Yufei Han 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | A Novel Cross-Chain Hierarchical Federated Learning Framework for Enhancing Service Security and Communication EfficiencyabstractTraditional federated learning (FL) uploads local models to a central server for model aggregation and suffers from server centralization. While blockchain-based FL addresses the issue of centralization, new challenges arise, including limited scalability of a single chain, expensive overhead of blockchain consensus, and inconsistent quality of uploaded models. This paper proposes a new cross-chain-based FL (CBFL) framework. Specifically, we propose a three-layer cross-chain FL architecture consisting of a task-releasing chain, a relay chain, and local model uploading chains. The task-releasing chain is used for task issuers to release FL tasks and global model aggregation. The local model uploading chain manages local devices, stores local models and aggregates these local models. To verify the quality of local models, we propose a dual-criteria model quality inspection method based on cross entropy and cosine similarity to exclude substandard local models. We also propose hierarchical FL before global model aggregation to further reduce the communication overhead. Moreover, multi-signature is used to ensure the consistent transmission of models in the cross-chain process. Experiments corroborate that the proposed CBFL improves performance by about 50% compared to the existing BFL framework. Moreover, the proposed dual-criteria model quality inspection method has better robustness than Krum and Trimmed Mean. Chao Li 0023, Wei Ni 0001, Bo Cheng 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2025 | Blockchain Takeovers in Web 3.0: An Empirical Study on the TRON-Steem IncidentabstractA fundamental goal of Web 3.0 is to establish a decentralized network and application ecosystem, thereby enabling users to retain control over their data while promoting value exchange. However, the recent TRON-Steem takeover incident poses a significant threat to this vision. In this paper, we present a thorough empirical analysis of the TRON-Steem takeover incident. By conducting a fine-grained reconstruction of the stake and election snapshots within the Steem blockchain, one of the most prominent social-oriented blockchains, we quantify the marked shifts in decentralization pre and post the takeover incident, highlighting the severe threat that blockchain network takeovers pose to the decentralization principle of Web 3.0. Moreover, by employing heuristic methods to identify anomalous voters and conducting clustering analyses on voter behaviors, we unveil the underlying mechanics of takeover strategies employed in the TRON-Steem incident and suggest potential mitigation strategies, which contribute to the enhanced resistance of Web 3.0 networks against similar threats in the future. We believe the insights gleaned from this research help illuminate the challenges imposed by blockchain network takeovers in the Web 3.0 era, suggest ways to foster the development of decentralized technologies and governance, as well as to enhance the protection of Web 3.0 user rights. Chao Li 0023, Runhua Xu, Balaji Palanisamy, Meng Shen 0001, Jiqiang Liu, Wei Wang 0012 |
ACM Trans. Web | 1 |
| 2024 | Detecting Unknown Threats in Smart Contracts With Domain AdaptationabstractUnknown smart contract vulnerabilities objectively exist in addition to common vulnerabilities, and their potential risks cannot be ignored. Therefore, it is crucial to enhance the model's ability to detect these unknown threats. Detection models are typically trained for specific types of vulnerability data. As a result, their effectiveness in detecting new vulnerabilities can be unsatisfactory. When a vulnerability is not defined in the model, it is considered an unknown vulnerability. Simulating attack scenarios or manual auditing is typically required for unknown threat detection. However, this results in a limited number of unknown threat samples available in the smart contract dataset, which greatly hinders the effectiveness of unknown threat detection due to dataset imbalance. In this paper, in order to improve the detection ability of unknown vulnerabilities of smart contracts, we propose a new method of unknown threat detection, which firstly expands the unknown threat samples by equalizing the data features of opcodes and source codes through a variational autoencoder. Then, a domain-adaptive training model DSN is used to learn the private and public features of the source and target domains of smart contracts, respectively. Trans-ferring features and adversarial learning between the source and target domains is achieved through domain classification and reconfiguration tasks. The experiments demonstrate that this method can significantly enhance the ability to identify unknown threats in smart contracts. Weiwei Ye, Chao Li 0023, Wei Ni 0001 |
SSE | 4 |
| 2024 | Timed Data Release Using Smart ContractsabstractWe present a decentralized secure data release application built on Ethereum, named Timed Data Release (TDR). TDR allows users to encrypt sensitive data by enabling the decryption of the data only after a predetermined period of time has elapsed. We present the technical foundation for TDR and its implementation on Ethereum. Our demonstration features a microblogging application that enables scheduled publication of microblogs, showing a practical application of timed data release using smart contracts. Jingzhe Wang, Chao Li 0023, Balaji Palanisamy |
ICDCS | 3 |
| 2024 | A Secure and Lightweight Aggregation Method for Blockchain-based Distributed Federated LearningabstractFederated learning (FL), typically coordinated by a centralized server, faces the risk of a single-point failure during the model aggregation process. Moreover, existing privacy protection methods for FL model parameters, such as homomorphic encryption (HE) and differential privacy (DP), still suffer from high computational costs or reduced model availability. Malicious trainers can also transmit erroneous model parameters in FL systems. To address these issues, this paper proposes a secure and efficient model aggregation approach with privacy protection for blockchain-based FL, named SLABFL. The method employs a blockchain network to establish a fully decentralized distributed FL (D-FL) framework, integrating a hybrid privacy protection strategy comprising DP and multi-key homomorphic encryption (MK-HE). This approach ensures the confidentiality of model parameters while achieving precise aggregation. Additionally, a reputation mechanism is introduced to deter malicious participant behavior. The paper concludes with experiments on the MNIST dataset, which show that our proposed SLABFL can achieve accuracy similar to Fedavg and reduce the time overhead caused by HE. Chao Li 0023, Wei Ni 0001 |
ICWS | 3 |
| 2024 | TLSCG: Transfer Learning-Based Efficient Anomalous Smart Contract Generation to Empower Unknown Vulnerability DetectionabstractSecurity vulnerabilities in smart contracts can have serious economic consequences. Existing smart contract vulnerability detection methods rely primarily on strict rules defined by experts, making current research limited to detecting specific known vulnerabilities and difficult to deal with other types of anomalous contracts (i.e., the variants of contracts with potentially known vulnerabilities). The imbalance of a smart contract dataset also affects the effectiveness of deep learning-based methods. This paper proposes a new transfer learning-based, anomalous smart contract generation (TLSCG) method for abnormal contract detection, aimed at effectively detecting known vulnerabilities and other anomalous contracts. This method trains a smart contract operation code sequence generation model and improves the authenticity of generating smart contracts by adding semantic regularization terms to the loss function. Through transfer learning, the generative model can be readily extended to new types of vulnerabilities, obtaining known vulnerabilities and anomalous contract generation models, expanding training data, improving the generalization of detection models, and enabling detection models to detect anomalous contracts. By using a real smart contract dataset for validation, experiments show that the proposed method can effectively improve the generalization of the model in detecting known vulnerabilities. Compared to the latest rule-based vulnerability detection tools, the accuracy of anomalous contract detection is improved by 40% and the F1 score is improved by 24%. Chunhong Liu, Zihang Sang, Wei Ni 0001, Wei Wang 0012, Chao Li 0023 |
ICWS | 6 |
| 2024 | Dual Defense: Enhancing Privacy and Mitigating Poisoning Attacks in Federated LearningabstractFederated learning (FL) is inherently susceptible to privacy breaches and poisoning attacks. To tackle these challenges, researchers have separately devised secure aggregation mechanisms to protect data privacy and robust aggregation methods that withstand poisoning attacks. However, simultaneously addressing both concerns is challenging; secure aggregation facilitates poisoning attacks as most anomaly detection techniques require access to unencrypted local model updates, which are obscured by secure aggregation. Few recent efforts to simultaneously tackle both challenges offen depend on impractical assumption of non-colluding two-server setups that disrupt FL's topology, or three-party computation which introduces scalability issues, complicating deployment and application. To overcome this dilemma, this paper introduce a Dual Defense Federated learning (DDFed) framework. DDFed simultaneously boosts privacy protection and mitigates poisoning attacks, without introducing new participant roles or disrupting the existing FL topology. DDFed initially leverages cutting-edge fully homomorphic encryption (FHE) to securely aggregate model updates, without the impractical requirement for non-colluding two-server setups and ensures strong privacy protection. Additionally, we proposes a unique two-phase anomaly detection mechanism for encrypted model updates, featuring secure similarity computation and feedback-driven collaborative selection, with additional measures to prevent potential privacy breaches from Byzantine clients incorporated into the detection process. We conducted extensive experiments on various model poisoning attacks and FL scenarios, including both cross-device and cross-silo FL. Experiments on publicly available datasets demonstrate that DDFed successfully protects model privacy and effectively defends against model poisoning threats. Runhua Xu, Shiqi Gao, Chao Li 0023, James B. D. Joshi, Jianxin Li 0002 |
NeurIPS | 3 |
| 2024 | TAPFed: Threshold Secure Aggregation for Privacy-Preserving Federated LearningabstractFederated learning is a computing paradigm that enhances privacy by enabling multiple parties to collaboratively train a machine learning model without revealing personal data. However, current research indicates that traditional federated learning platforms are unable to ensure privacy due to privacy leaks caused by the interchange of gradients. To achieve privacy-preserving federated learning, integrating secure aggregation mechanisms is essential. Unfortunately, existing solutions are vulnerable to recently demonstrated inference attacks such as the disaggregation attack. This paper proposesTAPFed, an approach for achieving privacy-preserving federated learning in the context of multiple decentralized aggregators with malicious actors.TAPFeduses a proposed threshold functional encryption scheme and allows for a certain number of malicious aggregators while maintaining security and privacy. We provide formal security and privacy analyses ofTAPFedand compare it to various baselines through experimental evaluation. Our results show thatTAPFedoffers equivalent performance in terms of model quality compared to state-of-the-art approaches while reducing transmission overhead by 29%-45% across different model training scenarios. Most importantly,TAPFedcan defend against recently demonstrated inference attacks caused by curious aggregators, which the majority of existing approaches are susceptible to. Runhua Xu, Bo Li 0005, Chao Li 0023, James B. D. Joshi, Shuai Ma 0001, Jianxin Li 0002 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | T-Watch: Towards Timed Execution of Private Transaction in BlockchainsabstractIn blockchains such as Bitcoin and Ethereum, transactions represent the primary mechanism that the external world can use to trigger a change of blockchain state. Timed transaction refers to a specific class of service that enables a user to schedule a transaction to change the blockchain state during a chosen future time-frame. This paper proposes$\mathsf{T-Watch}$, a decentralized and cost-efficient approach for users to schedule timed execution of any type of transaction in Ethereum with privacy guarantees.$\mathsf{T-Watch}$employs a novel combination of threshold secret sharing and decentralized smart contracts. To protect the private elements of a scheduled transaction from getting disclosed before the future time-frame,$\mathsf{T-Watch}$maintains shares of the decryption key of the scheduled transaction using a group of executors recruited in a blockchain network before the specified future time-frame and restores the scheduled transaction at a proxy smart contract to trigger the change of blockchain state at the required time-frame. To reduce the cost of smart contract execution in$\mathsf{T-Watch}$, we carefully design the proposed protocol to run in an optimistic mode by default and then switch to a pessimistic mode once misbehaviors occur. Furthermore, the protocol supports users to form service request pooling to further reduce the gas cost. We rigorously analyze the security of$\mathsf{T-Watch}$and implement the protocol over the Ethereum official test network. The results demonstrate that$\mathsf{T-Watch}$is more scalable compared to the state of the art and could reduce the cost by over 90% through pooling. Chao Li 0023, Balaji Palanisamy |
IEEE Trans. Serv. Comput. | 1 |
| 2023 | How Hard is Takeover in DPoS Blockchains? Understanding the Security of Coin-based Voting GovernanceabstractDelegated-Proof-of-Stake (DPoS) blockchains, such as EOSIO, Steem and TRON, are governed by a committee of block producers elected via a coin-based voting system. We recently witnessed the first de facto blockchain takeover that happened between Steem and TRON. Within one hour of this incident, TRON founder took over the entire Steem committee, forcing the original Steem community to leave the blockchain that they maintained for years. This is a historical event in the evolution of blockchains and Web 3.0. Despite its significant disruptive impact, little is known about how vulnerable DPoS blockchains are in general to takeovers and the ways in which we can improve their resistance to takeovers. Chao Li 0023, Balaji Palanisamy, Runhua Xu, Jiqiang Liu, Wei Wang 0012 |
CCS | 1 |
| 2023 | DeMonitor: Monitoring Decentralization in Blockchains using BigQueryabstractIn recent years, the development of blockchain technology has significantly accelerated in many countries. As a fundamental characteristic of blockchain, decentralization merits considerable attention. Nonetheless, a recent trend toward centralization has been noted, in which case the collusion of a few parties could threaten the immutability of blockchains. This paper introduces DeMonitor, a new BigQuery-based monitoring tool for blockchain decentralization. DeMonitor enables multi-dimensional and multi-level measurements of the decentralization of blockchain systems. It facilitates the monitoring and comparison of the degree of decentralization of any BigQuery-supported blockchain system. Zijing Li, Chao Li 0023 |
ICBC | 4 |
| 2023 | Secure Cross-domain Medical Data Sharing based on Distributed Cloud and Blockchain ServicesabstractElectronic Health Record (EHR) provides critical medical data. Sharing EHRs can add services and value for hospitals and patients and effectively improve medical services’ quality. In the process of cross-hospital diagnosis, EHRs cannot be shared across domains because they are separately stored in various hospitals, which may prevent timely diagnosis and lead to data isolation in medical data. Insecure storage and sharing also endanger the privacy of patients’ data, which likely leads to the disclosure of privacy-sensitive information or unauthorized access. To address these challenges, we propose a secure, cross-domain medical data-sharing scheme with data confidence protection. Specifically, we use a distributed cloud to realize cross-domain sharing of medical data, addressing the data isolation caused by the difference in hospital geographical locations. We combine a symmetric encryption algorithm with attribute encryption based on ciphertext policy (CP-ABE) to ensure the confidentiality and privacy of shared data, delivering fine-grained access control of shared medical data. Further, we introduce a key blockchain to store the ciphertext of the decryption key, the storage index of the data ciphertext, and store the ciphertext of the original data off-blockchain. Experiments show that the proposed scheme can perform better than existing cloud server-based data-sharing schemes. Jiasheng Cui, Wei Ni 0001, Chao Li 0023 |
ICWS | 4 |
| 2023 | Characterizing Coin-Based Voting Governance in DPoS BlockchainsabstractDelegated-Proof-of-Stake (DPoS) blockchains are governed by a committee of dozens of members elected via coin-based voting mechanisms. This paper presents a large-scale empirical study of two critical characteristics, personal impact and participation rate, of three leading DPoS blockchains. Our findings reveal the existence of decisive voters whose votes can alter election outcomes, as well as the fact that almost half of the coins have never been used in committee elections. Our research contributes to demystifying the actual use of coin-based voting governance and offers novel insights into the potential security risks of DPoS blockchains. Chao Li 0023, Runhua Xu |
ICWSM | 1 |
| 2023 | Blockchain-Based Transparency Framework for Privacy Preserving Third-Party ServicesabstractIncreasingly, information systems rely on computational, storage, and network resources deployed in third-party facilities such as cloud centers and edge nodes. Such an approach further exacerbates cybersecurity concerns constantly raised by numerous incidents of security and privacy attacks resulting in data leakage and identity theft, among others. These have, in turn, forced the creation of stricter security and privacy-related regulations and have eroded the trust in cyberspace. In particular, security-related services and infrastructures, such as Certificate Authorities (CAs) that provide digital certificate services and Third-Party Authorities (TPAs) that provide cryptographic key services, are critical components for establishing trust in crypto-based privacy-preserving applications and services. To address such trust issues, various transparency frameworks and approaches have been recently proposed in the literature. This paper proposes TAB framework that provides transparency and trustworthiness of third-party authority and third-party facilities using blockchain techniques for emerging crypto-based privacy-preserving applications. TAB employs the Ethereum blockchain as the underlying public ledger and also includes a novel smart contract to automate accountability with an incentive mechanism that motivates users to participate in auditing, and punishes unintentional or malicious behaviors. We implement TAB and show through experimental evaluation in the Ethereum official test network, Rinkeby, that the framework is efficient. We also formally show the security guarantee provided by TAB, and analyze the privacy guarantee and trustworthiness it provides. Runhua Xu, Chao Li 0023, James B. D. Joshi |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | NN-EMD: Efficiently Training Neural Networks Using Encrypted Multi-Sourced DatasetsabstractTraining complex neural network models using third-party cloud-based infrastructure among multiple data sources is a promising approach among existing machine learning solutions. However, privacy concerns of large-scale data collections and recent regulations have restricted the availability and use of privacy sensitive data in the third-party infrastructure. To address such privacy issues, a promising emerging approach is to train a neural network model over an encrypted dataset. Specifically, the model training process can be outsourced to a third party such as a cloud service that is backed by significant computing power, while the encrypted training data keeps the data confidential from the third party. Compared to training a traditional machine learning model over encrypted data, however, it is extremely challenging to train a deep neural network (DNN) model over encrypted data for two reasons: first, it requires large-scale computation over huge datasets; second, the existing solutions for computation over encrypted data, such as using homomorphic encryption, is inefficient. Further, for enhanced performance of a DNN model, we also need to use huge training datasets composed of data from multiple data sources that may not have pre-established trust relationships among each other. We propose a novel framework,NN-EMD, to train DNN overencrypted multiple datasetscollected from multiple sources. Toward this, we propose a set of secure computation protocols using hybrid functional encryption schemes. We evaluate our framework for performance with regards to the training time and model accuracy on the MNIST datasets. We show that compared to other existing frameworks, our proposedNN-EMDframework can significantly reduce the training time, while providing comparable model accuracy and privacy guarantees as well as supporting multiple data sources. Furthermore, the depth and complexity of neural networks do not affect the training time despite introducing a privacy-preservingNN-EMDsetting. Runhua Xu, James B. D. Joshi, Chao Li 0023 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | SilentDelivery: Practical Timed-Delivery of Private Information Using Smart ContractsabstractThis article proposesSilentDelivery, a secure, scalable, and cost-efficient protocol for implementing timed information delivery service in a decentralized blockchain network.SilentDeliveryemploys a novel combination of threshold secret sharing and decentralized smart contracts. The protocol maintains shares of the decryption key of the private information of an information sender using a group of mailman recruited in a blockchain network before the specified future time-frame and restores the information to the information recipient at the required time-frame. To tackle the key challenges that limit the security and scalability of the protocol,SilentDeliveryincorporates two novel countermeasure strategies. The first strategy, namelysilent recruitment, enables a mailman to get recruited by a sendersilentlywithout the knowledge of any third party. The second strategy, namelydual-mode execution, makes the protocol run in a lightweight mode by default, where the cost of running smart contracts is significantly reduced. We rigorously analyze the security ofSilentDeliveryand implement the protocol over the Ethereum official test network. The results demonstrate thatSilentDeliveryis more secure and scalable compared to the state of the art and reduces the cost of running smart contracts by 85 percent. Chao Li 0023, Balaji Palanisamy |
IEEE Trans. Serv. Comput. | 1 |
| 2021 | SteemOps: Extracting and Analyzing Key Operations in Steemit Blockchain-based Social Media PlatformabstractAdvancements in distributed ledger technologies are driving the rise of blockchain-based social media platforms such as Steemit, where users interact with each other in similar ways as conventional social networks. These platforms are autonomously managed by users using decentralized consensus protocols in a cryptocurrency ecosystem. The deep integration of social networks and blockchains in these platforms provides potential for numerous cross-domain research studies that are of interest to both the research communities. However, it is challenging to process and analyze large volumes of raw Steemit data as it requires specialized skills in both software engineering and blockchain systems and involves substantial efforts in extracting and filtering various types of operations. To tackle this challenge, we collect over 38 million blocks generated in Steemit during a 45 month time period from 2016/03 to 2019/11 and extract ten key types of operations performed by the users. The results generate SteemOps, a new dataset that organizes more than 900 million operations from Steemit into three sub-datasets namely (i) social-network operation dataset (SOD), (ii) witness-election operation dataset (WOD) and (iii) value-transfer operation dataset (VOD). We describe the dataset schema and its usage in detail and outline possible future research studies using SteemOps. SteemOps is designed to facilitate future research aimed at providing deeper insights on emerging blockchain-based social media platforms. Chao Li 0023, Balaji Palanisamy, Runhua Xu, Jinlai Xu, Jingzhe Wang |
CODASPY | 1 |
| 2020 | EventWarden: A Decentralized Event-driven Proxy Service for Outsourcing Arbitrary Transactions in Ethereum-like BlockchainsabstractTransactions represent a fundamental component in blockchains as they are the primary means for users to change the blockchain state. Current blockchain systems such as Bitcoin and Ethereum require users to constantly observe the state changes of interest or the events taking place in a blockchain and requires the user to explicitly release the required transactions to respond to the observed events in the blockchain. This paper proposes EventWarden, a decentralized event-driven proxy service for users to outsource transactions in Ethereum-like blockchains. EventWarden employs a novel combination of smart contracts and blockchain logs. EventWarden allows a user to create a proxy smart contract that specifies an interested event and also reserves an arbitrary transaction to release. Upon observing the occurrence of the prescribed event, anyone in the Blockchain network can call the proxy contract to earn the service fee reserved in the contract by proving to the contract that the event has been recorded into blockchain logs, which then automatically triggers the proxy contract to release the reserved transaction. We show that the reserved transaction can only get released from the proxy contract when the prescribed event has taken place. We also demonstrate that as long as a single member in the Blockchain network is incentivized by the service fee to call the proxy contract after the prescribed event has taken place, the reserved transaction is guaranteed to get released. We implement EventWarden over the Ethereum official test network. The results demonstrate that EventWarden is effective and is ready-to-use in practice. Chao Li 0023, Balaji Palanisamy |
ICWS | 1 |
| 2020 | NF-Crowd: Nearly-free Blockchain-based CrowdsourcingabstractAdvancements in distributed ledger technologies are rapidly driving the rise of decentralized crowdsourcing systems on top of open smart contract platforms like Ethereum. While decentralized blockchain-based crowdsourcing provides numerous benefits compared to centralized solutions, current implementations of decentralized crowdsourcing suffer from fundamental scalability limitations by requiring all participants to pay a small transaction fee every time they interact with the blockchain. This increases the cost of using decentralized crowdsourcing solutions, resulting in a total payment that could be even higher than the price charged by centralized crowdsourcing platforms. This paper proposes a novel suite of protocols called NF-Crowd that resolves the scalability issue by reducing the lower bound of the total cost of a decentralized crowdsourcing project to O(1). NF-Crowd is a highly reliable solution for scaling decentralized crowdsourcing. We prove that as long as participants of a project powered by NF-Crowd are rational, the O(1) lower bound of cost could be reached regardless of the scale of the crowd. We also demonstrate that as long as at least one participant of a project powered by NF-Crowd is honest, the project cannot be aborted and the results are guaranteed to be correct. We design NF-Crowd protocols for a representative type of project named crowdsourcing contest with open community review (CC-OCR). We implement the protocols over the Ethereum official test network. Our results demonstrate that NF-Crowd protocols can reduce the cost of running a CC-OCR project to less than $2 regardless of the scale of the crowd, providing a significant cost benefit in adopting decentralized crowdsourcing solutions. Chao Li 0023, Balaji Palanisamy, Runhua Xu, Jian Wang 0071, Jiqiang Liu |
SRDS | 1 |
| 2019 | CryptoNN: Training Neural Networks over Encrypted DataabstractEmerging neural networks based machine learning techniques such as deep learning and its variants have shown tremendous potential in many application domains. However, they raise serious privacy concerns due to the risk of leakage of highly privacy-sensitive data when data collected from users is used to train neural network models to support predictive tasks. To tackle such serious privacy concerns, several privacy-preserving approaches have been proposed in the literature that use either secure multi-party computation (SMC) or homomorphic encryption (HE) as the underlying mechanisms. However, neither of these cryptographic approaches provides an efficient solution towards constructing a privacy-preserving machine learning model, as well as supporting both the training and inference phases. To tackle the above issue, we propose a CryptoNN framework that supports training a neural network model over encrypted data by using the emerging functional encryption scheme instead of SMC or HE. We also construct a functional encryption scheme for basic arithmetic computation to support the requirement of the proposed CryptoNN framework. We present performance evaluation and security analysis of the underlying crypto scheme and show through our experiments that CryptoNN achieves accuracy that is similar to those of the baseline neural network models on the MNIST dataset. Runhua Xu, James B. D. Joshi, Chao Li 0023 |
ICDCS | 3 |
| 2019 | Reversible spatio-temporal perturbation for protecting location privacy
Chao Li 0023, Balaji Palanisamy |
Comput. Commun. | 1 |
| 2019 | Privacy in Internet of Things: From Principles to TechnologiesabstractUbiquitous deployment of low-cost smart devices and widespread use of high-speed wireless networks have led to the rapid development of the Internet of Things (IoT). IoT embraces countless physical objects that have not been involved in the traditional Internet and enables their interaction and cooperation to provide a wide range of IoT applications. Many services in the IoT may require a comprehensive understanding and analysis of data collected through a large number of physical devices that challenges both personal information privacy and the development of IoT. Information privacy in IoT is a broad and complex concept as its understanding and perception differ among individuals and its enforcement requires efforts from both legislation as well as technologies. In this paper, we review the state-of-the-art principles of privacy laws, the architectures for IoT and the representative privacy enhancing technologies (PETs). We analyze how legal principles can be supported through a careful implementation of PETs at various layers of a layered IoT architecture model to meet the privacy requirements of the individuals interacting with IoT systems. We demonstrate how privacy legislation maps to privacy principles which in turn drives the design of necessary PETs to be employed in the IoT architecture stack. Chao Li 0023, Balaji Palanisamy |
IEEE Internet Things J. | 1 |
| 2018 | Decentralized Privacy-Preserving Timed Execution in Blockchain-Based Smart Contract PlatformsabstractTimed transaction execution is critical for various decentralized privacy-preserving applications powered by blockchain-based smart contract platforms. Such privacy-preserving smart contract applications need to be able to securely maintain users' sensitive inputs off the blockchain until a prescribed execution time and then automatically make the inputs available to enable on-chain execution of the target function at the execution time, even if the user goes offline. While straight-forward centralized approaches provide a basic solution to the problem, unfortunately they are limited to a single point of trust. This paper presents a new decentralized privacy-preserving transaction scheduling approach that allows users of Ethereum-based decentralized applications to schedule transactions without revealing sensitive inputs before an execution time window selected by the users. The proposed approach involves no centralized party and allows users to go offline at their discretion after scheduling a transaction. The sensitive inputs are privately maintained by a set of trustees randomly selected from the network enabling the inputs to be revealed only at the execution time. The proposed protocol employs secret key sharing and layered encryption techniques and economic deterrence models to securely protect the sensitive information against possible attacks including some trustees destroying the sensitive information or secretly releasing the sensitive information prior to the execution time. We demonstrate the attack-resilience of the proposed approach through rigorous analysis. Our implementation and experimental evaluation on the Ethereum official test network demonstrates that the proposed approach is effective and has a low gas cost and time overhead associated with it. Chao Li 0023, Balaji Palanisamy |
HiPC | 1 |
| 2018 | Decentralized Release of Self-Emerging Data using Smart ContractsabstractIn the age of Big Data, releasing protected sensitive data at a future point in time is critical for various applications. Such self-emerging data release requires the data to be protected until a prescribed data release time and be automatically released to the recipient at the release time, even if the data sender goes offline. While straight-forward centralized approaches provide a basic solution to the problem, unfortunately they are limited to a single point of trust and involve a single point of control. This paper presents decentralized techniques for supporting self-emerging data using smart contracts in Ethereum blockchain networks. We design a credible and enforceable smart contract for supporting self-emerging data release. The smart contract employs a set of Ethereum peers to jointly follow the proposed timed-release service protocol allowing the participating peers to earn the remuneration paid by the service users. We model the problem as an extensive-form game with imperfect information to protect against possible adversarial attacks including some peers destroying the private data (drop attack) or secretly releasing the private data before the release time (release-ahead attack). We demonstrate the efficacy and attack-resilience of the proposed techniques through rigorous analysis and experimental evaluation. Our implementation and experimental evaluation on the Ethereum official test network demonstrate the low monetary cost and the low time overhead associated with the proposed approach and validate its guaranteed security properties. Chao Li 0023, Balaji Palanisamy |
SRDS | 1 |
| 2018 | k-Trustee: Location injection attack-resilient anonymization for location privacy
Lei Jin 0003, Chao Li 0023, Balaji Palanisamy, James B. D. Joshi |
Comput. Secur. | 2 |
| 2017 | Emerge: Self-Emerging Data Release Using Cloud Data StorageabstractIn the age of Big Data, advances in distributed technologies and cloud storage services provide highly efficient and cost-effective solutions to large scale data storage and management. Supporting self-emerging data using clouds is a challenging problem. While straight-forward centralized approaches provide a basic solution to the problem, unfortunately they are limited to a single point of trust. Supporting attack-resilient timed release of encrypted data stored in clouds requires new mechanisms for self emergence of data encryption keys that enables encrypted data to become accessible at a future point in time. Prior to the release time, the encryption key remains undiscovered and unavailable in a secure distributed system, making the private data unavailable. In this paper, we propose Emerge, a self-emerging timed data release protocol for securely hiding data encryption keys of private encrypted data in a large-scale Distributed Hash Table (DHT) network that makes the data available and accessible only at the defined release time. We develop a suite of erasure-coding-based routing path construction schemes for securely storing and routing encryption keys in DHT networks that protect an adversary from inferring the encryption key prior to the release time (release-ahead attack) or from destroying the key altogether (drop attack). Through extensive experimental evaluation, we demonstrate that the proposed schemes are resilient to both release-ahead attack and drop attack as well as to attacks that arise due to traditional churn issues in DHT networks. Chao Li 0023, Balaji Palanisamy |
CLOUD | 1 |
| 2017 | Group privacy-aware disclosure of association graph dataabstractIn the age of Big Data, we are witnessing a huge proliferation of digital data capturing our lives and our surroundings. Data privacy is a critical barrier to data analytics and privacy-preserving data disclosure becomes a key aspect to leveraging large-scale data analytics due to serious privacy risks. Traditional privacy-preserving data publishing solutions have focused on protecting individual's private information while considering all aggregate information about individuals as safe for disclosure. This paper presents a new privacy-aware data disclosure scheme that considers group privacy requirements of individuals in bipartite association graph datasets (e.g., graphs that represent associations between entities such as customers and products bought from a pharmacy store) where even aggregate information about groups of individuals may be sensitive and need protection. We propose the notion of εg-Group Differential Privacy that protects sensitive information of groups of individuals at various defined group protection levels, enabling data users to obtain the level of information entitled to them. Based on the notion of group privacy, we develop a suite of differentially private mechanisms that protect group privacy in bipartite association graphs at different group privacy levels based on specialization hierarchies. We evaluate our proposed techniques through extensive experiments on three real-world association graph datasets and our results demonstrate that the proposed techniques are effective, efficient and provide the required guarantees on group privacy. Balaji Palanisamy, Chao Li 0023, Prashant Krishnamurthy |
IEEE BigData | 2 |
| 2017 | Timed-Release of Self-Emerging Data Using Distributed Hash TablesabstractReleasing private data to the future is a challenging problem. Making private data accessible at a future point in time requires mechanisms to keep data secure and undiscovered so that protected data is not available prior to the legitimate release time and the data appears automatically at the expected release time. In this paper, we develop new mechanisms to support self-emerging data storage that securely hide keys of encrypted data in a Distributed Hash Table (DHT) network that makes the encryption keys automatically appear at the predetermined release time so that the protected encrypted private data can be decrypted at the release time. We show that a straight-forward approach of privately storing keys in a DHT is prone to a number of attacks that could either make the hidden data appear before the prescribed release time (release-ahead attack) or destroy the hidden data altogether (drop attack). We develop a suite of self-emerging key routing mechanisms for securely storing and routing encryption keys in the DHT. We show that the proposed scheme is resilient to both release-ahead attack and drop attack as well as to attacks that arise due to traditional churn issues in DHT networks. Our experimental evaluation demonstrates the performance of the proposed schemes in terms of attack resilience and churn resilience. Chao Li 0023, Balaji Palanisamy |
ICDCS | 1 |
| 2017 | ReverseCloak: A Reversible Multi-level Location Privacy Protection SystemabstractWith the fast popularization of mobile devices and wireless networks, along with advances in sensing and positioning technology, we are witnessing a huge proliferation of Location-based Services (LBSs). Location anonymization refers to the process of perturbing the exact location of LBS users as a cloaking region such that a user's location becomes indistinguishable from the location of a set of other users. However, existing location anonymization techniques focus primarily on single level unidirectional anonymization, which fails to control the access to the cloaking data to let data requesters with different privileges get information with varying degrees of anonymity. In this demonstration, we present a toolkit for ReverseCloak, a location perturbation system to protect location privacy over road networks in a multi-level reversible manner, consisting of an `Anonymizer' GUI to adjust the anonymization settings and visualize the multilevel cloaking regions over road network for location data owners and a `De-anonymizer' GUI to de-anonymize the cloaking region and display the reduced region over road network for location data requesters. With the toolkit, we demonstrate the practicality and effectiveness of the ReverseCloak approach. Chao Li 0023, Balaji Palanisamy, Aravind Kalaivanan, Sriram Raghunathan |
ICDCS | 1 |
| 2017 | Group Differential Privacy-Preserving Disclosure of Multi-level Association GraphsabstractTraditional privacy-preserving data disclosure solutions have focused on protecting the privacy of individual's information with the assumption that all aggregate (statistical) information about individuals is safe for disclosure. Such schemes fail to support group privacy where aggregate information about a group of individuals may also be sensitive and users of the published data may have different levels of access privileges entitled to them. We propose the notion ofεg-Group Differential Privacy that protects sensitive information of groups of individuals at various defined privacy levels, enabling data users to obtain the level of access entitled to them. We present a preliminary evaluation of the proposed notion of group privacy through experiments on real association graph data that demonstrate the guarantees on group privacy on the disclosed data. Balaji Palanisamy, Chao Li 0023, Prashant Krishnamurthy |
ICDCS | 2 |
| 2016 | SocialMix: Supporting Privacy-Aware Trusted Social Networking ServicesabstractOnline Social Networks (OSNs) have been one of the most successful web-based communication models. In the recent years, a new category of OSNs namely anonymous social networks are becoming popular. Unlike traditional Online Social Networks, anonymous social networks allow users to communicate without exposing their identity. This paper presents a trusted anonymous social network service that can anonymize user identities during interaction even though the communication happens with the user's own trusted friends and contacts on the social network. A fundamental requirement of such a trusted anonymous social networks is to protect the user's identity under the guarantees of anonymity. However, in existing approaches, even though the user information is anonymized, by continuously aggregating the information from the messages posted by a user, it is possible to re-identify the user with high probability. In this paper, we propose SocialMix that anonymizes the users of a trusted social network such that the aggregation of messages can be prevented. We make three original contributions. First, we develop the SocialMix model for trusted anonymous social networks so that communication privacy can be protected by k-anonymization. Second, by considering the features of OSNs, we analyze the vulnerabilities of the naive methods that might be exploited to break the privacy. We develop new techniques to improve the attack-resilience of the SocialMix approach. Third, we propose intelligent mix node selection methods to significantly reduce the required number of social mix nodes while still keeping high anonymization rate. Our experiments shows that SocialMix provides high attack resilience and keeps high anonymization rate with few mix nodes under the trusted social network model. Chao Li 0023, Balaji Palanisamy, James B. D. Joshi |
ICWS | 1 |
| 2015 | ReverseCloak: Protecting Multi-level Location Privacy over Road NetworksabstractWith advances in sensing and positioning technology, fueled by the ubiquitous deployment of wireless networks, location-aware computing has become a fundamental model for offering a wide range of life enhancing services. However, the ability to locate users and mobile objects opens doors for new threats - the intrusion of location privacy. Location anonymization refers to the process of perturbing the exact location of users as a cloaking region such that a user's location becomes indistinguishable from the location of a set of other users. A fundamental limitation of existing location anonymization techniques is that location information once perturbed to provide a certain anonymity level cannot be reversed to reduce anonymity or the degree of perturbation. This is especially a serious limiting factor in multi-level privacy-controlled scenarios where different users of the location information have different levels of access. This paper presents ReverseCloak, a new class of reversible location cloaking mechanisms that effectively support multi-level location privacy, allowing selective de-anonymization of the cloaking region to reduce the granularity of the perturbed location when suitable access credentials are provided. We evaluate the ReverseCloak techniques through extensive experiments on realistic road network traces generated by GTMobiSim. Our experiments show that the proposed techniques are efficient, scalable and provide the required level of privacy. Chao Li 0023, Balaji Palanisamy |
CIKM | 1 |
| 2015 | De-anonymizable Location Cloaking for Privacy-Controlled Mobile Systems
Chao Li 0023, Balaji Palanisamy |
NSS | 1 |