Tong Wu 0011

dblp:75/5056-11 · DBLP profile ↗
← Back
21ranked-venue papers
7as first author
19since 2021 · last 2026
0000-0001-5164-527XORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 2 first-author · 9 since 2021Databases, data management, data science and information retrieval · 4 · 2 first-author · 3 since 2021Computer networks · 3 · 2 first-author · 3 since 2021Systems, architecture and hardware · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 A Decentralized Blockchain Transaction Verification Scheme in the Weighted Setting
abstract
Blockchain transaction verification is fundamental to decentralized financial applications, ensuring both transaction authorization and integrity. Most existing verification schemes utilize an equal weight model that grants identical rights to all participants. However, these schemes fail to capture real-world scenarios like Proof-of-Stake blockchains, where participants have right discrepancies. Additionally, many schemes depend on trusted third parties for key generation, introducing single points of failure and compromising security. To address these limitations, we propose WBlock that is a weighted and decentralized verification scheme. WBlock involves a distributed key generation protocol that embeds each entity's weight into its secret share, eliminating the need for trusted third parties. It further employs a Schnorr-type weighted threshold signing protocol, enabling distributed transaction authorization while reflecting participant weight in signature shares. Security analysis shows that WBlock achieves both correctness and unforgeability. Comparative theoretical analysis shows that our key generation and signing protocols outperform existing methods in terms of round complexity, communication overhead and data size. Experimental results confirm that WBlock achieves a balance between security and efficiency, with acceptable overhead for real-world blockchain deployment.
Yumeng Xie, Tong Wu 0011, Cong Zuo 0001, Weixiao Wang, Chuan Zhang 0003, Liehuang Zhu
IEEE Trans. Dependable Secur. Comput.3
2025 Onion Encryption Revisited: Relations Among Security Notions
Daichong Chao, Liehuang Zhu, Tong Wu 0011, Chuan Zhang 0003, Fuchun Guo
Inscrypt (1)4
2025 P 2 FedRec: Towards Privacy-Preserving and Personalized Federated Recommendation via Relationship Awareness
abstract
Personalized federated recommendation systems can not only extract common prior knowledge from extensive decentralized data but also provide personalized models for different users to achieve independent and customized services. Incorporating user relationship graphs to enhance personalized modeling is highly promising in federated recommendation. However, it is challenging to construct such graphs and further capture personalized user information while guaranteeing multi-level (i.e., data-level and edge-level) privacy in reality. To this end, in this paper, we propose P 2 FedRec, a relationship-aware P rivacy-preserving and P ersonalized Fed erated Rec ommendation scheme, which can achieve multi-level privacy protection with personalized modeling guarantees. Specifically, we first develop a user-server collaborative mechanism for relationship graph generation and user-specific preferences capture in a privacy-preserving manner. Then, we design an embedding-shared local graph construction module and a noisy global graph-guided aggregation module to safeguard the data-level and edge-level privacy, respectively. Moreover, we introduce a personalized model training module that enables users to learn tailored local models. Theoretical analysis demonstrates that P 2 FedRec achieves both data-level and edge-level privacy preservation on the user and server sides. Extensive experiments conducted on five real-world datasets highlight the outstanding performance of P 2 FedRec.
Chenfei Hu, Tong Wu 0011, Chuan Zhang 0003, Liehuang Zhu
Proc. ACM Manag. Data3
2024 Toward Fine-Grained Task Allocation With Bilateral Access Control for Intelligent Transportation Systems
abstract
In this article, we propose a secure fine-grained task allocation scheme with bilateral access control (FTA-BAC) for intelligent transportation systems. To enhance the security, we formulate bilateral access control in task allocation, by adopting the matchmaking encryption (ME) to encrypt the task requirements/interests for secure task matching. In this way, both task requesters and workers can specify their match policies simultaneously, without revealing their sensitive information (i.e., attributes and geographical location). To realize fine-grained task allocation, we use a linear integer secret sharing (LISS) scheme to represent task requirements/interests, supporting theAND/ORoperation on match policies. To further improve the efficiency, we design a delegation mechanism to reduce the computation burden on resource-limited end devices, by diverting the high-frequency matching operations to edge nodes. Then, we prove the security of FTA-BAC under formally defined security model. Finally, we analyze the performance of FTA-BAC through theoretical analysis and experimental evaluation, demonstrating that FTA-BAC can provide practical task allocation for intelligent transportation systems compared with the state-of-the-art works.
Tong Wu 0011, Chuan Zhang 0003, Ximeng Liu, Guomin Yang, Liehuang Zhu
IEEE Internet Things J.1
2024 Accountable and Secure Threshold EdDSA Signature and Its Applications
abstract
Threshold signatures as a method to realize multi-party cooperation and trust distribution in blockchain have been widely studied in recent years. However, among these researches, few threshold signature schemes achieve all the properties of accountability, privacy, and key protection for the EdDSA-based blockchain systems. To fill this gap, we propose an EdDSA-based accountable threshold signature protocol with privacy and proactive refresh, named TAPS-PR. Meanwhile, we define new security models and give a detailed analysis to prove protocol security. In TAPS-PR, the threshold is variable and hidden with the signing quorum from the public view. However, the signing quorum can be traced when threshold signatures related to fraudulent events are generated. We also enhance the key security of each signer by proactive refresh, which realizes updating the private key while the public key remains unchanged. Apart from that, we present ATS-PR with increased efficiency and reduced communication cost at the cost of weaker security. The theoretical analysis and experimental results indicate that our protocols perform efficiently in terms of communication and computation overhead. Furthermore, we use Tezos, a blockchain project employing EdDSA, as a case study to demonstrate the compatibility of our protocol with real-world blockchain applications.
Yumeng Xie, Chuan Zhang 0003, Tong Wu 0011, Yuao Zhou, Debiao He, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.4
2024 Blockchain-Based Dynamic Time-Encapsulated Data Auditing for Outsourcing Storage
abstract
Outsourcing storage has emerged as an effective solution to manage the increasing volume of data. With the popularity of pay-as-you-go payment models in outsourcing storage, data auditing schemes that prioritize timeliness can be valuable evidence for elastic bill settlement. Unfortunately, existing data auditing schemes do not sufficiently consider timeliness during auditing. Furthermore, practical data auditing schemes should have the capability to check the integrity of scalable data. In this paper, we propose a blockchain-based dynamic data auditing scheme with strong timeliness to ensure that data stored in outsourcing storage systems remain intact. Our scheme encapsulates timestamps into homomorphic verifiable tags to simultaneously check data integrity and timestamp validity. To achieve dynamicity, we utilize the Merkle hash tree to store the tags, allowing for block-level dynamic operations. Additionally, by leveraging the transparency, non-repudiation, and tamper resistance of blockchain technology, we design a blockchain-based data auditing framework to prevent malicious behavior from all entities. We then formally prove the soundness and privacy of our scheme. Finally, we conduct theoretical analysis and experimental evaluation to demonstrate that the performance of our scheme is of acceptable efficiency to existing works in terms of computation cost, communication overhead, and storage overhead.
Chuan Zhang 0003, Haojun Xuan, Tong Wu 0011, Ximeng Liu, Guomin Yang, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.3
2024 Revocable and Privacy-Preserving Bilateral Access Control for Cloud Data Sharing
abstract
In this paper, we propose a revocable and privacy-preserving bilateral access control scheme (named PriBAC) for general cloud data sharing (i.e., end-cloud-based data sharing). PriBAC ensures that preference matching is successful only when both parties’ preferences are satisfied simultaneously. Otherwise, nothing is leaked beyond whether the preference matching occurs. There are three challenges in designing PriBAC. The first challenge is protecting matching information, i.e., concealing two preference matching processes, in a single cloud server. The second challenge is protecting preference content while preventing receivers from receiving much useless information. The third challenge is how to integrate efficient user revocation mechanisms into bilateral access control to handle frequent user revocation cases in practical cloud data sharing applications. To address the above challenges, the punchline in PriBAC is to leverage Newton’s interpolation formula-based secret sharing to enrich the matchmaking encryption technique for constructing a privacy-preserving preference matching mechanism. To achieve efficient user revocation, we integrate a unique symbol into each user’s keys and efficiently revoke users by invaliding the corresponding keys. Security analysis proves that PriBAC can resist the chosen-ciphertext attack and preserves preference privacy and matching privacy. Experiments show that PriBAC achieves approximately$3\times $user performance improvement compared with current state-of-the-art related schemes.
Mingyang Zhao 0002, Chuan Zhang 0003, Tong Wu 0011, Jianbing Ni, Ximeng Liu, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.3
2024 BADFL: Backdoor Attack Defense in Federated Learning From Local Model Perspective
abstract
There is substantial attention to federated learning with its ability to train a powerful global model collaboratively while protecting data privacy. Despite its many advantages, federated learning is vulnerable to backdoor attacks, where an adversary injects malicious weights into the global model, making the global model's targeted predictions incorrect. Existing defenses based on identifying and eliminating malicious weights ignore the similarity variation of the local weights during iterations in the malicious model detection and the presence of benign weights in the malicious model during the malicious local weight elimination, resulting in a poor defense and a degradation of global model accuracy. In this paper, we defend against backdoor attacks from the perspective of local models. First, a malicious model detection method based on interpretability techniques is proposed. The method appends a sampling check after clustering to identify malicious models accurately. We further design a malicious local weight elimination method based on local weight contributions. This method preserves the benign weights in the malicious model to maintain their contributions to the global model. Finally, we analyze the security of the proposed method in terms of model closeness and then verify the effectiveness of the proposed method through experiments. In comparison with existing defenses, the results show that BADFL improves the global model accuracy by 23.14% while reducing the attack success rate to 0.04% in the best case.
Xinghua Li 0001, Mengfan Xu, Ximeng Liu, Tong Wu 0011, Jian Weng 0001, Robert H. Deng
IEEE Trans. Knowl. Data Eng.5
2023 Enabling privacy-preserving multi-server collaborative search in smart healthcare
Chuan Zhang 0003, Xingqi Luo, Tong Wu 0011, Liehuang Zhu
Future Gener. Comput. Syst.4
2023 Blockchain-Based Anonymous Data Sharing With Accountability for Internet of Things
abstract
Blockchain has been a promising infrastructure for enabling secure data sharing for the Internet of Things (IoT). With the widespread of IoT applications, security issues, such as data privacy, anonymity, and accountability become critical concerns for the users, which are essential principles for secure communication in those applications. However, the existing blockchain-based data-sharing schemes mainly consider data privacy. Only a few works can support anonymity with strong, trusted assumptions. Thus, there is a research gap on the anonymity of blockchain-based data sharing for IoT, which does not rely on any trusted party. In this article, we propose a blockchain-based anonymous data-sharing scheme (BA-DS) by adopting a novel public key encryption derived from a ring signature. In BA-DS, we remove the trusted party and ensure anonymity by using an unconditional linkable ring signature and Signature of Knowledge (SoK). During the revocation, we apply blockchain infrastructure to record the valid revocation list and generate a tag for data stored on the cloud, providing solid accountability. The formal security analysis shows that BA-DS is selective indistinguishable secure in the random oracle model. Additionally, we also prove that BA-DS holds anonymity, data privacy, accountability, and authenticity. The extensive experiments indicate that our proposed BA-DS achieves reasonable efficiency in terms of computational complexity, communication overhead, and consumption on the blockchain.
Tong Wu 0011, Weijie Wang 0010, Chuan Zhang 0003, Weiting Zhang, Liehuang Zhu, Keke Gai
IEEE Internet Things J.1
2023 Achieving Efficient and Privacy-Preserving Neural Network Training and Prediction in Cloud Environments
abstract
The neural network has been widely used to train predictive models for applications such as image processing, disease prediction, and face recognition. To produce more accurate models, powerful third parties (e.g., clouds) are usually employed to collect data from a large number of users, which however may raise concerns about user privacy. In this paper, we propose an Efficient and Privacy-preserving Neural Network scheme, named EPNN, to deal with the privacy issues in cloud-based neural networks. EPNN is designed based on a two-cloud model and techniques of data perturbation and additively homomorphic cryptosystem. This scheme enables two clouds to cooperatively perform neural network training and prediction in a privacy-preserving manner and significantly reduces the computation and communication overhead among participating entities. Through a detailed analysis, we demonstrate the security of EPNN. Extensive experiments based on real-world datasets show EPNN is more efficient than existing schemes in terms of computational costs and communication overhead.
Chuan Zhang 0003, Chenfei Hu, Tong Wu 0011, Liehuang Zhu, Ximeng Liu
IEEE Trans. Dependable Secur. Comput.3
2023 Achieving Privacy-Preserving and Verifiable Support Vector Machine Training in the Cloud
abstract
With the proliferation of machine learning, the cloud server has been employed to collect massive data and train machine learning models. Several privacy-preserving machine learning schemes have been suggested recently to guarantee data and model privacy in the cloud. However, these schemes either mandate the involvement of the data owner in model training or utilize high-cost cryptographic techniques, resulting in excessive computational and communication overheads. Furthermore, none of the existing work considers the malicious behavior of the cloud server during model training. In this paper, we propose the first privacy-preserving and verifiable support vector machine training scheme by employing a two-cloud platform. Specifically, based on the homomorphic verification tag, we design a verification mechanism to enable verifiable machine learning training. Meanwhile, to improve the efficiency of model training, we combine homomorphic encryption and data perturbation to design an efficient multiplication operation for the encryption domain. A rigorous theoretical analysis demonstrates the security and reliability of our scheme. The experimental results indicate that our scheme can reduce computational and communication overheads by at least 43.94% and 99.58%, respectively, compared to state-of-the-art SVM training methods.
Chenfei Hu, Chuan Zhang 0003, Dian Lei, Tong Wu 0011, Ximeng Liu, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.4
2023 CITS-MEW: Multi-Party Entangled Watermark in Cooperative Intelligent Transportation System
abstract
Federated learning is good for building better cooperative intelligent transportation system (C-ITS). Intellectual property protection in C-ITS brings many benefits to all vehicles. Although the protection of model intellectual property by watermark has received much research attention, the existing works only deploy watermark in centralized models. Due to the difference of watermark distribution among vehicles, the global model accuracy of watermark in federated learning is significantly reduced or the local watermark is invalid. To solve these problems, we propose a multi-party entangled watermark algorithm in federated learning. Specifically, in the local training, we propose a watermark enhancement algorithm, which solves the problem of local watermark failure. Then, in the global aggregation, we propose an entanglement aggregation algorithm, which solves the problem of a great loss of global model accuracy. We conduct extensive experiments on public datasets to show the superiority of our proposal. The results show that our scheme can obtain more than 16% and 31% advantages in model accuracy and watermark success rate, respectively, compared with existing watermark schemes in federated learning.
Tong Wu 0011, Xinghua Li 0001, Yinbin Miao, Mengfan Xu, Ximeng Liu, Kim-Kwang Raymond Choo
IEEE Trans. Intell. Transp. Syst.1
2022 Achieving a Blockchain-based Privacy-preserving Quality-aware Knowledge Marketplace in Crowdsensing
abstract
It is increasingly popular to utilize the wisdom of the crowd for knowledge discovery and monetization. Most of the existing knowledge marketplaces in crowdsensing are implemented by a third-party platform, which may compromise users' rights and be vulnerable to incurring attacks in practice. To eliminate the untrustworthy behaviors of the third party and improve tolerance for the attacks, some blockchain-based knowledge marketplaces in crowdsensing have been proposed. However, the existing blockchain-based knowledge marketplaces fail to simultaneously guarantee privacy (i.e., data privacy and task privacy) and quality awareness. In this paper, we design a blockchain-based privacy-preserving quality-aware knowledge marketplace (PQKM) based on truth discovery, secure K-nearest neighbor computation, matrix decomposition, and data perturbation. PQKM privately calculates users' data quality and automatically rewards users based on their data quality. Detailed security analysis demonstrates that PQKM can preserve data privacy and task privacy during knowledge discovery and monetization. Extensive experiments are conducted on the open real-world dataset to show that PQKM has acceptable efficiency and affordable performance.
Mingyang Zhao 0002, Weiting Zhang, Jinyang Dong, Tong Wu 0011, Chuan Zhang 0003, Liehuang Zhu
EUC6
2022 Stealing Secrecy from Outside: A Novel Gradient Inversion Attack in Federated Learning
abstract
Knowing model parameters has been regarded as a vital factor for recovering sensitive information from the gradients in federated learning. But is it safe to use federated learning when the model parameters are unavailable for adversaries, i.e., external adversaries’ In this paper, we answer this question by proposing a novel gradient inversion attack. Speciffically, we observe a widely ignored fact in federated learning that the participants’ gradient data are usually transmitted via the intermediary node. Based on this fact, we show that an external adversary is able to recover the private input from the gradients, even if it does not have the model parameters. Through extensive experiments based on several real-world datasets, we demonstrate that our proposed new attack can recover the input with pixelwise accuracy and feasible efficiency.
Chuan Zhang 0003, Haotian Liang, Youqi Li, Tong Wu 0011, Liehuang Zhu, Weiting Zhang
ICPADS4
2022 FRUIT: A Blockchain-Based Efficient and Privacy-Preserving Quality-Aware Incentive Scheme
abstract
Incentive plays an important role in knowledge discovery, as it impels users to provide high-quality knowledge. To promise incentive schemes with transparency, blockchain technology has been widely used in incentive schemes. Currently, privacy, reliability, streamlined processing, and quality awareness are major challenges in designing blockchain-based incentive schemes. In this paper, we design a blockchain-based eFficient and pRivacy-preserving qUality-aware IncenTive scheme called FRUIT. With well-designed smart contracts, FRUIT achieves privacy, reliability, streamlined processing, and quality awareness during the whole procedure. Specifically, we design a novel lightweight encryption method by combining matrix decomposition with proxy re-encryption and a privacy-preserving task allocation based on the polynomial fitting function and hash function. Then, we leverage our proposed lightweight encryption and task allocation to build an efficient and privacy-preserving knowledge discovery protocol in order to securely calculate the data quality and truthful knowledge. To promise user reliability in the incentive scheme, we utilize the Dirichlet distribution to realize the automatic reputation prediction based on the data quality by deploying the reputation management on the blockchain. Moreover, we also deploy the payment management on the blockchain, endowing the incentive scheme to reward participants based on the data quality automatically. Through a detailed security analysis, we demonstrate that data privacy and task privacy are well preserved during the whole process. Theoretical analysis and extensive experiments on real-world datasets demonstrate that FRUIT has acceptable efficiency and affordable performance in terms of computation cost, communication overhead, and gas consumption.
Chuan Zhang 0003, Mingyang Zhao 0002, Liehuang Zhu, Weiting Zhang, Tong Wu 0011, Jianbing Ni
IEEE J. Sel. Areas Commun.5
2022 Enabling Efficient and Strong Privacy-Preserving Truth Discovery in Mobile Crowdsensing
abstract
Mobile crowdsensing has emerged as a popular platform to solve many challenging problems by utilizing users’ wisdom and resources. Due to user diversity, the data provided by different individuals may vary significantly, and thus it is important to analyze data quality during data aggregation. Truth discovery is effective in capturing data quality and obtaining accurate mobile crowdsensing results. Existing works on truth discovery either cannot protect both task privacy and data privacy, or introduce tremendous computational costs. In this paper, we propose an efficient and strong privacy-preserving truth discovery scheme, named EPTD, to protect users’ task privacy and data privacy simultaneously in the truth discovery procedure. In EPTD, we first exploit the randomizable matrix to express users’ tasks and sensory data. Then, based on the matrix computation properties, we design key derivation and (re-)encryption mechanisms to enable truth discovery to be performed in an efficient and privacy-preserving manner. Through a detailed security analysis, we demonstrate that data privacy and task privacy are well preserved. Extensive experiments based on real-world and simulated mobile crowdsensing applications show EPTD has practical efficiency in terms of computational cost and communication overhead.
Chuan Zhang 0003, Mingyang Zhao 0002, Liehuang Zhu, Tong Wu 0011, Ximeng Liu
IEEE Trans. Inf. Forensics Secur.4
2021 Privacy-preserving voluntary-tallying leader election for internet of things
Tong Wu 0011, Guomin Yang, Liehuang Zhu, Yulin Wu 0001
Inf. Sci.1
2021 Privacy-Preserving Proof of Storage for the Pay-As-You-Go Business Model
abstract
Proof of Storage (PoS) enables a cloud storage provider to prove that a client's data is intact. However, existing PoS protocols are not designed for the pay-as-you-go business model in which payment is made based on both storage volume and duration. In this paper, we propose two PoS protocols suitable for the pay-as-you-go storage business model. The first is a time encapsulated Proof of Retrievability (PoR) protocol that ensures retrievability of the original file upon successful auditing by a client. Considering the large size of outsourced data, we then extend the protocol to a privacy-preserving public auditing protocol which allows a third party auditor to audit outsourced data on behalf of its clients without sacrificing the privacy of the data or the timestamp (i.e., time of storage). We formalize the definition, system model and security model of the proposed PoS system and prove the security of the proposed protocols by a sequence of games in the algebraic group model with a random oracle. We analyze the performance of the protocols both theoretically and experimentally and show that the protocols are practical.
Tong Wu 0011, Guomin Yang, Yi Mu 0001, Fuchun Guo, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.1
2020 Privacy-enhanced remote data integrity checking with updatable timestamp
Tong Wu 0011, Guomin Yang, Yi Mu 0001, Rongmao Chen, Shengmin Xu
Inf. Sci.1
2017 ID-Based Encryption with Equality Test Against Insider Attack
Tong Wu 0011, Sha Ma, Yi Mu 0001, Shengke Zeng
ACISP (1)1