Yu Peng 0003

dblp:85/5580-3 · DBLP profile ↗
← Back
10ranked-venue papers
1as first author
10since 2021 · last 2026
0000-0002-2949-9728ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 3 since 2021Computer networks · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Boosting Adversarial Transferability via Ensemble Non-Attention
abstract
Ensemble attacks integrate the outputs of surrogate models with diverse architectures, which can be combined with various gradient-based attacks to improve adversarial transferability. However, previous work shows unsatisfactory attack performance when transferring across heterogeneous model architectures. The main reason is that the gradient update directions of heterogeneous surrogate models differ widely, making it hard to reduce the gradient variance of ensemble models while making the best of individual model. To tackle this challenge, we design a novel ensemble attack, NAMEA, which for the first time integrates the gradients from the non-attention areas of ensemble models into the iterative gradient optimization process. Our design is inspired by the observation that the attention areas of heterogeneous models vary sharply, thus the non-attention areas of ViTs are likely to be the focus of CNNs and vice versa. Therefore, we merge the gradients respectively from the attention and non-attention areas of ensemble models so as to fuse the transfer information of CNNs and ViTs. Specifically, we pioneer a new way of decoupling the gradients of non-attention areas from those of attention areas, while merging gradients by meta-learning. Empirical evaluations on ImageNet dataset indicate that NAMEA outperforms AdaEA and SMER, the state-of-the-art ensemble attacks by an average of 15.0% and 9.6%, respectively. This work is the first attempt to explore the power of ensemble non-attention in boosting cross-architecture transferability, providing new insights into launching ensemble attacks.
Yipeng Zou, Qin Liu 0001, Jie Wu 0001, Yu Peng 0003, Guo Chen 0001, Hui Zhou 0014, Guanghui Ye
AAAI4
2024 $\mathsf{MARS}$MARS: Enabling Verifiable Range-Aggregate Queries in Multi-Source Environments
abstract
The huge values created by Big Data and the recent advances in cloud computing have been driving data from different sources into cloud repositories for comprehensive query services. However, cloud-based data fusion makes it challenging to verify if an untrusted server faithfully integrates data and executes queries or not. This is even harder for range-aggregate queries that apply aggregate operations on data within given ranges. In this paper, we propose a query authentication scheme, named${\sf MARS}$, enabling a user to efficiently authenticate range-aggregate queries on multi-source data. Specifically,${\sf MARS}$creates a VG-tree by subtly integrating Expressive Set Accumulator into a multi-dimensional G-tree while signing the root digest with a multi-source aggregate signature scheme. Compared with previous solutions,${\sf MARS}$has the following merits: (1)Practicality.Instead of treating range and aggregate queries separately, the user can directly verify the statistical result of selected data. (2)Scalability.Instead of authenticating the individual result from each source, the user can perform an aggregative validation on the integrated result from multiple sources. The experimental results demonstrate the effectiveness of MARS. For large-scale data fusion, the user-side verification time increases by only 103 ms as the amount of data sources increases by five times.
Qin Liu 0001, Yu Peng 0003, Hongbo Jiang 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001, Shaobo Zhang 0001
IEEE Trans. Dependable Secur. Comput.2
2024 veffChain: Enabling Freshness Authentication of Rich Queries Over Blockchain Databases
abstract
With the wide adoption of blockchains in data-intensive applications, enabling verifiable queries over a blockchain database is urgently required. Aiming at reducing costs, previous solutions embed a small-sized authenticated data structure (ADS) in each block header, so that a user can verify search results without maintaining a full copy of blockchain databases. However, existing studies focus on exact queries with difficulty to guarantee the freshness of search results. In this article, we propose two frameworks, called$\mathsf{veffChain}$and$\mathsf{veffChain++}$, to realize freshness authentication of rich queries over blockchain databases. Specifically,$\mathsf{veffChain}$concerns about verifiable latest-$K$exact queries and employs RSA accumulator to generate constant-size ADSs;$\mathsf{veffChain++}$integrates RSA accumulator into the Trie tree to further authenticate latest-$K$fuzzy queries. For improved scalability, an adaptive keyword splitting (AKS) solution is proposed to enable ADSs to be incrementally updated. Compared with the state-of-the-art work, our frameworks have the following merits: (1)Freshness Guarantee. The user can efficiently retrieve the freshest data from a blockchain database in a verifiable way. (2)Flexibility. The user can specify different query patterns on demand to retrieve data as accurately as possible. The detailed security analysis and extensive experiments validate the practicality of our frameworks.
Qin Liu 0001, Yu Peng 0003, Hongbo Jiang 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001
IEEE Trans. Knowl. Data Eng.2
2024 MPV: Enabling Fine-Grained Query Authentication in Hybrid-Storage Blockchain
abstract
Due to the large-scale data streams produced by distributed terminals, hybrid-storage blockchain (HSB) that combines on-chain and off-chain storages has emerged as a promising solution for secure data storage in decentralized applications. Because all the raw data is outsourced to an untrusted service provider (SP), existing solutions suggest to utilize an on-chain authenticated data structure (ADS) to verify query results retrieved off-chain. However, existing solutions support onlycoarse-grained authenticationmaking a user abandon all the query results once the validation fails. In this paper, we focus on realizingfine-grained authenticationfor range queries, enabling a user to distinguish authentic data from falsified results. Considering the heavy gas consumption of on-chain storage, we propose two multi-dimensional parity-based verification (MPV) schemes with a trade-off between off-chain and on-chain efficiencies. Our main idea is to design an accumulator-based ADS to summarize well-designed verifiable hypercubes, so that fake results can be quickly located by combining multi-dimensional faces failed validation. Compared with previous solutions, our MPV schemes allow a user to make efficient use of query results by filtering out errors, and thus have higher data utility. The detailed security analysis and extensive experiments demonstrate the security and effectiveness of our MPV schemes, respectively.
Qin Liu 0001, Yu Peng 0003, Mingzuo Xu, Hongbo Jiang 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001
IEEE Trans. Knowl. Data Eng.2
2024 Authorized Keyword Search on Mobile Devices in Secure Data Outsourcing
abstract
With the increasing awareness of secure data outsourcing, dynamic searchable symmetric encryption (DSSE) that enables searches and updates over encrypted data has begun to receive growing attention. Despite promising, existing DSSE schemes with forward and backward privacy are still hard to achieve authorized keyword searches on mobile devices while supporting secure and flexible updates. In this article, we propose a DSSE scheme, named$\mathsf{FLY_{++}}$based on a flexible index structure$\mathsf{Hybrid}$that incorporates the merits of inverted indexes and forward indexes while compacting the index size. Specifically,$\mathsf{FLY_{++}}$encrypts the newly added data with a fresh key and disperses previous keys into$\mathsf{Hybrid}$for forward privacy, while applying symmetric puncturable encryption (SPE) and a dual-key mechanism to realize backward privacy further. Compared with the state-of-the-art work,$\mathsf{FLY_{++}}$has the following advantages: (1)Authorized search. It dispenses with caching or re-encrypting search results, enabling a mobile device to search only designated keywords over the data outsourced before authorization. (2)Flexibility.It not only allows for sublinear search time, but also simultaneously supports fine-grained and coarse-grained updates of outsourced data. The detailed security analysis and extensive experiments conducted on a real dataset demonstrate the security and practicality of$\mathsf{FLY_{++}}$, respectively.
Qin Liu 0001, Yu Peng 0003, Hongbo Jiang 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001
IEEE Trans. Mob. Comput.2
2023 SlimBox: Lightweight Packet Inspection over Encrypted Traffic
abstract
Due to the explosive increase of enterprise network traffic, middleboxes that inspect packets through customized rules have been widely outsourced for cost-saving. Despite promising, redirecting enterprise traffic to remote middleboxes raises privacy concerns about the exposure of corporate secrets. To address this, existing solutions mainly apply searchable encryption (SE) to encrypt traffic and rules, enabling middlebox to perform pattern matching over ciphertexts without learning any sensitive information. However, SE is designed for searching pre-chosen keywords, and may cause extensive costs when applied directly to inspecting traffic in which the keywords cannot be determined in advance. The inefficiency of existing SE-based approaches motivates us to investigate a privacy-preserving and lightweight middlebox. To this end, this paper designs$\mathsf{SlimBox}$, which rapidly screens out potentially malicious packets in constant time while incurring only moderate communication overhead. Our main idea is to fragment a traffic/rule string into sub-patterns to achieve conjunctive sub-pattern matching over ciphertexts, while incorporating the position information into the secure matching process to avoid false positives. Experiment results on real datasets show that$\mathsf{SlimBox}$can achieve a good tradeoff between matching latency and communication cost compared to prior work.
Qin Liu 0001, Yu Peng 0003, Hongbo Jiang 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001
IEEE Trans. Dependable Secur. Comput.2
2022 Prime Inner Product Encoding for Effective Wildcard-Based Multi-Keyword Fuzzy Search
abstract
With the prevalence of cloud computing, a growing number of users are delegating clouds to host their sensitive data. To preserve user privacy, it is suggested that data is encrypted before outsourcing. However, data encryption makes keyword-based searches over ciphertexts extremely difficult. This is even challenging forfuzzy searchthat allows uncertainties or misspellings of keywords in a query. In this article, we propose a prime inner product encoding (PIPE) scheme, which makes use of theindecomposableproperty of prime numbers to provide efficient, highly accurate, and flexible multi-keyword fuzzy search. Our main idea is to encode either a query keyword or an index keyword into a vector filled with primes or reciprocals of primes, such that the result of vectors’ inner product is an integer only when two keywords are similar. Specifically, we first construct$\text{PIPE}_{0}$that is secure in the known ciphertext model. Unlike existing works that have difficulty supporting AND and OR semantics simultaneously,$\text{PIPE}_{0}$gives users the flexibility to specify different search semantics in their queries. Then, we construct$\text{PIPE}_{\text{S}}$that subtly adds random noises to a query vector to resist linear analyses. Both theoretical analyses and experiment results demonstrate the effectiveness of our scheme.
Qin Liu 0001, Yu Peng 0003, Shuyu Pei, Jie Wu 0001, Tao Peng 0011, Guojun Wang 0001
IEEE Trans. Serv. Comput.2
2021 Dynamic Searchable Symmetric Encryption with Forward and Backward Privacy
abstract
Dynamic searchable symmetric encryption (DSSE) that enables a client to perform searches and updates on encrypted data has been intensively studied in cloud computing. Recently, forward privacy and backward privacy has engaged significant attention to protect DSSE from the leakage of updates. However, the research in this field almost focused on keyword-level updates. That is, the client needs to know the keywords of the documents in advance. In this paper, we proposed a document-level update scheme, DBP, which supports immediate deletion while guaranteeing forward privacy and backward privacy. Compared with existing forward and backward private DSSE schemes, our DBP scheme has the following merits: 1) Practicality. It achieves deletion based on document identifiers rather than document/keyword pairs; 2) Efficiency. It utilizes only lightweight primitives to realize backward privacy while supporting immediate deletion. Experimental evaluation on two real datasets demonstrates the practical efficiency of our scheme.
Yu Peng 0003, Qin Liu 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001
TrustCom1
2021 SecVKQ: Secure and verifiable kNN queries in sensor-cloud systems
Qin Liu 0001, Zhengzheng Hao, Yu Peng 0003, Hongbo Jiang 0001, Jie Wu 0001, Tao Peng 0011, Guojun Wang 0001, Shaobo Zhang 0001
J. Syst. Archit.3
2021 Secure Multi-keyword Fuzzy Searches With Enhanced Service Quality in Cloud Computing
abstract
With the ever-increasing amount of data resided in a cloud, how to provide users with secure and practical query services has become the key to improve the quality of cloud services. Fuzzy searchable encryption (FSE) is identified as one of the most promising approaches for enabling secure query services, since it allows searching encrypted data by using keywords with spelling errors. However, existing FSE schemes are far from the practical use for the following reasons: (1)Inflexibility.It is hard for them to simultaneously support AND and OR semantics in a multi-keyword query. (2)Inefficiency.They require sequentially scanning a whole dataset to find matched files, and thus are difficult to apply to a large-scale dataset. (3)Limited robustness.It is difficult for them to resist the linear analysis attack in the known-background model. To fix the above problems, this article proposes matrix-based multi-keyword fuzzy search (M2FS) schemes, which support approximate keyword matching by exploiting the indecomposable property of primes. Specifically, we first present a basic scheme, called M2FS-B, where multiple keywords in a query or a file are constructed as prime-related matrices such that the result of matrix multiplication can be employed to determine the level of matching for different query semantics. Then, we construct an advanced scheme, named M2FS-E, which builds a searchable index as a keyword balanced binary (KBB) tree for dynamic and parallel searches, while adding random noises into a query matrix for enhanced robustness. Extensive analyses and experiments demonstrate the validity of our M2FS schemes.
Qin Liu 0001, Yu Peng 0003, Jie Wu 0001, Tian Wang 0001, Guojun Wang 0001
IEEE Trans. Netw. Serv. Manag.2