VLDB 2026 Research / reviewers in the wild / expert
Pengfei Wu 0003
dblp:92/1320-3
· DBLP profile ↗
35ranked-venue papers
9as first author
30since 2021 · last 2026
0000-0003-0896-9476ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 25 · 8 first-author · 22 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Understanding the Security of Cloud Storage Services: A Case Study and UC-Secure Design
Pengfei Wu 0003, Xiaoguo Li, Guomin Yang, Tao Xiang 0001, Robert H. Deng |
ACISP (2) | 1 |
| 2026 | PriSrv+: Privacy and Usability-Enhanced Wireless Service Discovery with Fast and Expressive Matchmaking Encryption
Yang Yang 0026, Guomin Yang, Yingjiu Li, Pengfei Wu 0003, Minming Huang, Jian Weng 0001, HweeHwa Pang, Robert H. Deng |
NDSS | 4 |
| 2026 | AuthGraph: Authorized Search Over Encrypted Social Graph Database With Trusted HardwareabstractPrivacy-preserving social graph search allows the retrieval of relationships within social networks while not com promising individuals' private information. Although numerous solutions enable conjunctive queries for relationships on encrypted social networks, the multi-client model is neglected despite its crucial role in collaborative data sharing, and personalized recommendations. In this paper, we present AuthGraph, a privacy-preserving and conjunctive social graph search system with trusted hardware in the multi-client (i.e., multi-writer/multi reader) model. In AuthGraph, a data owner delegates update rights to writers for maintaining dynamic social relationships, while readers are allowed to perform edge-weighted conjunctive queries via writer-enforced access policy. Technically, AuthGraph builds a multi-writer/multi-reader model with access control delegation for writers via a set-constrained pseudo-random function, and uses attribute-based encryption to configure authorizations for readers. To give a provably secure conjunctive search system over a dynamic social graph database, AuthGraph revisits oblivious dynamic cross tag protocol via providing comprehensive forward privacy and Type-O backward privacy. Different from previous solutions, in AuthGraph, the semi-black-box deployment of trusted hardware effectively ensures system security while maintaining performance. Finally, we demonstrate the performance of AuthGraph through extensive experiments on real social network datasets on AliCloud, revealing that the writer enforced access policy has minimal impact on search time cost. Jiawen Wu 0001, Yifan Xu 0010, Kai Zhang 0016, Pengfei Wu 0003, Yuling Chen 0002, Jianting Ning |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Verifiable and Privacy-Preserving Deep Packet Inspection for Multiple Rule Service Providers
Zhentao Long, Pengfei Wu 0003, Kai Zhang 0016, Junqing Gong 0001, Jianting Ning |
Inscrypt (2) | 2 |
| 2025 | Conditional Attribute-Based PRE: Definition and Construction from LWE
Jian Weng 0001, Pengfei Wu 0003, Guofeng Tang, Guomin Yang, Haiyang Xue, Robert H. Deng |
ISC | 3 |
| 2025 | Attribute-Based Conditional PRE: A Novel Construction from LWE for Cloud Data-SharingabstractSecure and efficient data sharing is essential in cloud environments, where data owners must delegate decryption rights without re-encrypting data for each user. Proxy Re-Encryption (PRE) addresses this by allowing a proxy to transform ciphertexts for authorized recipients without accessing the plaintext. As a variant, Attribute-Based Conditional PRE (AB-CPRE) enhances traditional PRE by incorporating two key features: (1) attribute-based access control, and (2) conditional ciphertext transformation based on a specified policy. Despite significant advancements, existing AB-CPRE schemes face a trilemma in balancing functionality and security, hindering their use in cloud data-sharing: (1) support limited to single-hop re-encryption, restricting multi-hop scenarios; (2) a weak security model relying on selective security without allowing the adversary to choose the target attributes or policies adaptively; and (3) an insufficient security guarantee only targeting chosen plaintext attacks (CPA), offering no protection against honest re-encryption attacks (HRA).In this paper, we propose the first AB-CPRE scheme tailored to the cloud environment that simultaneously supports multi-hop transformation, adaptive-policy security, and resistance to HRA. Our construction is based on the learning with errors (LWE) assumption in the standard model, making it also quantum-resistant. We prove security through a novel re-encryption key simulatability technique, allowing the simulation of the re-encryption key without knowing the corresponding secret key, which is of independent interest. Through a comprehensive performance comparison, our scheme demonstrates a lower decryption overhead and a comparable re-encryption key size, showing its practicality compared to the state-of-the-art schemes while offering stronger security and functionality. Jian Weng 0001, Pengfei Wu 0003, Guofeng Tang, Haiyang Xue, Guomin Yang, Robert H. Deng |
TrustCom | 3 |
| 2025 | Practical Keyword Private Information Retrieval from Key-to-Index Mappings
Meng Hao 0001, Liqiang Peng, Pengfei Wu 0003, Lei Zhang 0006, Hongwei Li 0001, Robert H. Deng |
USENIX Security Symposium | 5 |
| 2025 | Achilles: A Formal Framework of Leaking Secrets from Signature Schemes via Rowhammer
Junkai Liang, Zhi Zhang 0001, Xin Zhang 0110, Qingni Shen, Yansong Gao 0001, Xingliang Yuan, Haiyang Xue, Pengfei Wu 0003, Zhonghai Wu |
USENIX Security Symposium | 8 |
| 2025 | SoK: Understanding zk-SNARKs: The Gap Between Research and Practice
Junkai Liang, Daqi Hu, Pengfei Wu 0003, Yunbo Yang, Qingni Shen, Zhonghai Wu |
USENIX Security Symposium | 3 |
| 2025 | Verifiable and Privacy-Enhanced Authorized Keyword Search for Mobile Cloud StorageabstractMobile cloud storage enables IoT devices to use on-demand resources and share data with different mobile devices, where these outsourced data on the cloud are encrypted due to data confidentiality concern. Although dynamic searchable symmetric encryption (DSSE) allows data owners to directly search and update its encrypted data, it rarely considers implementing authorized search toward different mobile devices. Existing authorized keyword search systems for mobile cloud storage suffer from the following limitations: 1) only achieves Type-III backward privacy; 2) no support for verification of search result; and 3) incurs high time overhead for data update and search. Therefore, we propose$\textsf {VE}{-}\textsf {FLY}{++}$, an efficient, verifiable, and authorized DSSE system with forward and enhanced backward privacy for mobile cloud storage. Technically,$\textsf {VE}{-}\textsf {FLY}{++}$presents a verifiable inverted bitmap index (VIBI) to achieve forward privacy and enhanced Type-I (a.k.a.,$\textrm {Type-I}^{-}$) backward privacy, with supporting verification of search results. In addition, we combine symmetric encryption with homomorphic addition with the introduced VIBI for a fast authorized search function. To further enable efficiently handling hundreds of millions of files, we adopt chunking technology to present a highly scalable$\textsf {VE}{-}\textsf {FLY}{++}$. Finally, we use Raspberry Pi, Rock Pi, and Huawei Cloud on real datasets to conduct extensive experiments to clarify the practical efficiency of$\textsf {VE}{-}\textsf {FLY}{++}$. Zhentao Long, Kai Zhang 0016, Jinguo Li, Pengfei Wu 0003, Jianting Ning |
IEEE Internet Things J. | 4 |
| 2025 | PrivBox: Privacy-Preserving Deep Packet Inspection With Dual Double-Masking Obfuscated Rule GenerationabstractMany network middleboxes have been deployed to performdeep packet inspection(DPI) over packet payloads. However, such middleboxes cannot accomplish their tasks when the traffic is encrypted.BlindBox(SIGCOMM 2015) provided the first solution for performing DPI over encrypted traffic. To improve its efficiency, a later proposalPrivDPI(CCS 2019) introduced a practical technique to generate encrypted rules. However, a recent proposalP2DPI(ASIACCS 2021) showed that the rule generator in PrivDPI can comprise the user's privacy. In this paper, we present a new attack on P2DPI and show that the privacy of its endpoints can still be compromised by the rule generator. We comprehensively analyze the vulnerability of prior studies and presentPrivBox, a new DPI system that achieves the same privacy guarantee as BlindBox while maintaining practical efficiency. This is based on a new technique calleddual double-masking obfuscated rule generation. For a ruleset of 3,000, PrivBox achieves connection establishment time on the endpoint side comparable to PrivDPI and supports up to 4,672 token encryptions per second, which is sufficient for a number of real-world applications. Overall, our experiment demonstrates that PrivBox is practical and well-suited for short, frequently established sessions, especially when token repeating is common. Pengfei Wu 0003, Jianting Ning, Xinyi Huang 0001, Rongmao Chen, Kai Zhang 0016, Kaitai Liang |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | AuditPCH: Auditable Payment Channel Hub With Privacy ProtectionabstractAnonymous Payment Channel Hub (PCH), one of the most promising layer-two solutions, settles the scalability issue in blockchain while guaranteeing the unlinkability of transacting parties. However, such developments bring conflicting requirements, i.e., hiding the sender-to-receiver relationships from any third party but opening the relationship to the auditor. Existing works do not support these requirements simultaneously since off-chain transactions are not recorded in the blockchain. Further, the privacy protection strategies hinder auditors from capturing the payment relationships. Thus, it is still a challenge to audit the finance activities of PCH transacting parties. This paper proposes a novel anonymous PCH solution called AuditPCH to achieve privacy and auditability. Concretely, we design a Linkable Randomizable Puzzle scheme for constructing conditional transactions, allowing a sender to pay for a receiver via the hub. As such, AuditPCH, with the new LRP scheme, ensures that 1) payment relationships can be protected from the hub and 2) an auditor with necessary trapdoors can associate the sender and receiver of a payment. We prove the security of AuditPCH under the Global Universal Composability framework. The extensive experimental evaluations on AuditPCH are established to demonstrate its functionality and flexibility. Jian Weng 0001, Junzuo Lai, Yingjiu Li, Jiahe Wu, Ming Li 0049, Jianfei Sun, Pengfei Wu 0003, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 8 |
| 2025 | TLARDA: Threshold Label-Aggregating Remote Data Auditing in Decentralized EnvironmentabstractRemote data integrity auditing enables a client to efficiently ensure the integrity of entire data stored in untrusted servers via auditing. Yet, existing solutions generally emphasize on various metrics (such as minimal storage, fast update, metadata privacy), but not audit performance (e.g., low audit time, small proof size). To this end, a label-aggregating remote data integrity auditing scheme (LARDA) was proposed in ESORICS ’22, which is the state-of-the-art work in terms of proof size and storage cost. However, LARDA needs a trusted third party (TTP) for performing data auditing for all data owners, which introduces a single point of failure since the audit process routinely needs to interact with the TTP. To address this issue, we introduce a new concept called threshold label-aggregating data auditing and propose two novel schemes. Our first solution is based on Pedersen secret sharing technique, which can significantly alleviate the key escrow problem of LARDA. Our second solution is an efficient batch verifying scheme for multiple TTP’s secret key shares, utilizing the KZG (Kate, Zaverucha and Goldberg) secret sharing technique. This scheme can maintain the size of commitment for TTP’s secret key constant rather than a linear factor with the number of TTPs. We conduct comprehensive experiments to demonstrate the scalability of our schemes. In particular, our second scheme improves the verification time for TTP’s secret key shares in constant, only requiring two pairings and one exponentiation in group with an average of 7.39 ms, regardless of the number of TTPs increasing. For our first scheme, the verification procedure requires$2t$exponentiations in group (where t is the threshold value), ranging from 2.37 ms ($t = 2$) to 26.85 ms ($t = 35$). Jianting Ning, Pengfei Wu 0003, Shengmin Xu, Rongmao Chen |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Breaking the Trilemma: Toward Efficient, Privacy-Preserving, and Forward-Secure Data Sharing in the Post-Quantum EraabstractCloud-based data sharing has emerged as a prevailing solution for enterprises and end users, supporting various online services in our daily lives. However, the current cloud security solutions are vulnerable to the “harvest now, decrypt later” threat imposed by future quantum computers. To encounter the threat, lattice-based cryptographic solutions for supporting cloud data encryption and search have been extensively investigated by both academia and industry. Despite these efforts, existing lattice-based schemes fall into a trilemma: (1) lack of efficient access control for data retrieval; (2) inadequate protection of keyword privacy in both ciphertext and search token; and (3) difficulty in realizing forward secrecy to safeguard historical data. These limitations result in a substantial burden for lattice-based solutions to be adopted in real-world cloud data sharing. To our knowledge, no prior work has comprehensively addressed these issues at the same time, motivating us to design a more flexible, efficient, and secure lattice-based solution. In this paper, we propose an efficient, privacy-preserving, and forward-secure data sharing framework centered around a novel primitive called Forward-Secure Authenticated Searchable Encryption (FS-ASE). Specifically, we first construct an Authenticated Searchable Encryption (ASE) scheme based on ideal lattices, enabling efficient one-to-many search functionality and ensuring keyword privacy in both ciphertext and search token. On top of this primitive, we present the FS-ASE scheme, which achieves forward secrecy through a highly efficient key evolution mechanism, thereby keeping the confidentiality of historical data even if the current secret key is compromised. Finally, the security of our construction is proven under the Ring Learning With Errors (RLWE) assumption, and experimental results show that it achieves performance improvements of 158× in data retrieval and 350× in token generation over state-of-the-art approaches, indicating its practicality in real use. Jian Weng 0001, Pengfei Wu 0003, Shixin Chen, Jianfei Sun, Guomin Yang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Efficient Temporal Extrapolation of Multimodal Large Language Models with Temporal Grounding BridgeabstractDespite progress in multimodal large language models (MLLMs), the challenge of interpreting long-form videos in response to linguistic queries persists, largely due to the inefficiency in temporal grounding and limited pre-trained context window size. In this work, we introduce Temporal Grounding Bridge (TGB), a novel framework that bootstraps MLLMs with advanced temporal grounding capabilities and broadens their contextual scope. Our framework significantly enhances the temporal capabilities of current MLLMs through three key innovations: an efficient multi-span temporal grounding algorithm applied to low-dimension temporal features projected from flow; a multimodal length extrapolation training paradigm that utilizes low-dimension temporal features to extend the training context window size; and a bootstrapping framework that bridges our model with pluggable MLLMs without requiring annotation. We validate TGB across seven video benchmarks and demonstrate substantial performance improvements compared with prior MLLMs. Notably, our model, initially trained on sequences of four frames, effectively handles sequences up to 16 longer without sacrificing performance, highlighting its scalability and effectiveness in real-world applications. Our code is publicly available. Yuxuan Wang 0004, Yueqian Wang, Pengfei Wu 0003, Jianxin Liang, Dongyan Zhao 0001, Yang Liu 0003, Zilong Zheng |
EMNLP | 3 |
| 2024 | Learning to Generate Style-Specific Adapters for Stylized Dialogue Generation
Jinpeng Li 0003, Yuhan Chen 0001, Pengfei Wu 0003, Yingce Xia, Shufang Xie 0003, Dongyan Zhao 0001, Rui Yan 0001 |
NLPCC (1) | 3 |
| 2024 | Towards Privacy-aware IoT Communications: Delegable, Revocable, and EfficientabstractThe Internet of Things (IoT) is widely recognized for its potential to enhance efficiency and productivity across various industries. However, its increasing prevalence has also made it a more attractive target for cybercriminals. While many advanced cryptographic solutions have been developed to secure IoT, some practical security and privacy issues such as self-sovereign delegation, flexible revocation, and lightweight access remain inadequately addressed in existing solutions. In this paper, we propose PLIC, a Privacy-aware Lightweight IoT Communication scheme, which not only enables any authorized user to flexibly delegate their lightweight access privileges to other delegatees, such that they can also access the authorized IoT targets in the same lightweight way, but also supports flexible revocation of access for specific users without affecting non-revoked users. Specifically, our solution leverages wildcard-based access control and tree-based encryption technologies to enable self-sovereign delegation, dynamic membership updates, and stably efficient decryption overhead in IoT. In addition, comprehensive security proofs are rendered to validate the robustness of our approach. Finally, experimental comparisons with similar methodologies demonstrate the practicality and superior performance of our solution, which indicates its effectiveness for practical IoT appli-cations. Pengfei Wu 0003, Jianfei Sun, Guomin Yang, Robert H. Deng |
TrustCom | 1 |
| 2023 | DCDPI: Dynamic and Continuous Deep Packet Inspection in Secure Outsourced MiddleboxesabstractSecure outsourced middleboxes are deployed in network function virtualization services that detect malicious activities on communications, which provides privacy-preserving deep packet inspection (DPI) over encrypted traffic. To boost filtering efficiency of packets, the two-layer middlebox architecture has been adopted in recent DPI systems. Nevertheless, state-of-the-art solutions based on two-layer architecture mainly suffer from two limitations: i) cannot support dynamic rule addition; ii) failed to inspect discontinuous token for rule matching. To address these limitations, this work proposes an efficient, dynamic and continuous DPI (DCDPI) system in secure outsourced middleboxes. To achieve dynamic rule addition with forward privacy, we refine a data structure called virtual binary tree (VBTree) and further introduce a variant of VBTree for DCDPI, termed VBTree+. VBTree+ supports two new desirable features: i) taking the rule action information into consideration; ii) achieving both rule identifier and rule action hiding. By introducing a token continuity check mechanism, DCDPI can effectively identify discontinuous tokens and categorize continuous tokens into one group. The extensive experiment over the real dataset and rule set confirms the practicality and efficiency of DCDPI. Compared to state-of-the-art works with same setting, DCDPI is 18%$\sim$110% more efficient for a connection establishment between gateway/client and server. Minjun Deng, Kai Zhang 0016, Pengfei Wu 0003, Mi Wen, Jianting Ning |
IEEE Trans. Cloud Comput. | 3 |
| 2023 | T-Counter: Trustworthy and Efficient CPU Resource Measurement Using SGX in the CloudabstractAs cloud services have become popular, and their adoption is growing, consumers are becoming more concerned about the cost of cloud services. Cloud Service Providers (CSPs) generally use a pay-per-use billing scheme in the cloud services model: consumers use resources as they needed and are billed for their resource usage. However, CSPs are untrusted and privileged; they have full control of the entire operating system (OS) and may tamper with bills to cheat consumers. So, how to provide a trusted solution that can keep track of and verify the consumers’ resource usage has been a challenging problem. In this article, we propose a T-Counter framework based on Intel SGX. The T-Counter allows applications to construct a trusted solution to measure its CPU usage by itself in cloud computing. These constructed applications are instrumented with counters in basic blocks and added three components in trusted parts to count instructions and defend against malicious CSPs’ manipulations. We propose two algorithms which selectively instrument counters in the CFG. T-Counter is implemented as an extension of the LLVM framework and integrated with the SGX SDK. Theoretical analyses and evaluations show that T-Counter can effectively measure CPU usage and defend against malicious CSPs’ manipulations. Chuntao Dong, Qingni Shen, Xuhua Ding, Daoqing Yu, Wu Luo, Pengfei Wu 0003, Zhonghai Wu |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2023 | Differentially Oblivious Two-Party Pattern Matching With Sublinear Round ComplexityabstractPrivacy-preserving pattern matching enables a user to find all occurrences of a pattern in a text without revealing any sensitive information. However, many previous works designed on homomorphic encryption suffer from expensive computational overhead and a simple way to use it can lead to potential input leakage via access pattern during the matching process. In this article, we propose a differentially oblivious pattern matching algorithm, calledDOPM. It is deployed on two servers by taking a series of lightweight secret-sharing-based protocols as building blocks. InDOPM, we utilize a witness array and the single instruction multiple data (SIMD) technique to parallelize the algorithm, which achieves sublinear round complexity in performing two-party computation. Additionally, we formally define a new access pattern privacy in the context of differential privacy, named$(\epsilon,\delta)$-differentially oblivious privacy ($(\epsilon,\delta)$-DOP), and present a pair of differentially oblivious algorithms to read and write elements in an array without using oblivious shuffle. Detailed security analysis demonstrates that the proposedDOPMachieves the goal of protecting confidentiality and access pattern during the matching process. Finally, we benchmark our scheme on a real-world human genome dataset, and experimental results show thatDOPMis$10.9\times$faster than the brute-force matching,$3.4-7.1\times$faster than two state-of-the-art approaches. Pengfei Wu 0003, Jianting Ning, Xinyi Huang 0001, Joseph K. Liu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Exploring Dynamic Task Loading in SGX-Based Distributed ComputingabstractNowadays, data privacy is one of the most critical concerns in cloud computing, and many privacy-preserving distributed computing systems based on the trusted execution environment (e.g., Intel SGX) have been proposed to protect the user's privacy during cloud-outsourced computation. However, these SGX-based solutions are vulnerable to some traffic analyses, and loading all tasks into the enclave introduces much overhead for frequent EPC-paging. In this paper, we propose a T-SGX framework, which keeps the confidentiality of a distributed job and guarantees the system efficiency by allowing dynamically loading an enclave shared object for the task under processing. In T-SGX, all these objects are secretly shared and stored in a verifiably distributed share management system (SMS) outside the TCB. To mitigate the exposure of sensitive information, we present an efficient oblivious transfer (OT) protocol under the Decisional Diffie-Hellman (DDH) assumption for obliviously transmitting desired shares. Detailed security analysis demonstrates that the proposed T-SGX achieves the goal of secure distributed computing without privacy leakage to unauthorized parties. Finally, we benchmark the framework in six real-world applications, and the experimental results show that T-SGX significantly outperforms a state-of-the-art solution, with 11.9%-29.7% less overhead performing an SGX-based application. Pengfei Wu 0003, Jianting Ning, Wu Luo, Xinyi Huang 0001, Debiao He |
IEEE Trans. Serv. Comput. | 1 |
| 2022 | ScriptChecker: To Tame Third-party Script Execution With Task Capabilities
Wu Luo, Xuhua Ding, Pengfei Wu 0003, Qingni Shen, Zhonghai Wu |
NDSS | 3 |
| 2022 | Hybrid Trust Multi-party Computation with Trusted Execution Environment
Pengfei Wu 0003, Jianting Ning, Jiamin Shen, Ee-Chien Chang |
NDSS | 1 |
| 2022 | Differentially Oblivious Data Analysis With Intel SGX: Design, Optimization, and EvaluationabstractA privacy-preserving data analytics system enables a cloud user to perform the distributed job in a secure manner such that the data privacy can be guaranteed during the cloud-outsourced computation. However, many SGX-based solutions are vulnerable to some side-channel attacks, including the access pattern leakage from both network and memory. Several data-oblivious algorithms with full obliviousness have been proposed in the literature, but they are impractical to be used in the cloud due to the expensive computational overhead. In this article, we propose a DPSpark system with the security defined in a notion of$(\epsilon,\delta)$-differentially private obliviousness ($(\epsilon,\delta)$-DPO), which relaxes full obliviousness to enable an efficiency improvement. Based on this definition, we present a perturbation-shuffle-analysis (PSA) computing architecture and design several typical differentially oblivious operators. In further, we optimize the system efficiency by reducing the number of oblivious shuffles and choosing an appropriate privacy budget. Finally, we benchmark the system in different parameters. The experimental results show that DPSpark significantly outperforms two state-of-the-art solutions, only with 10.1-85.4 percent additional overhead performing an SGX-based data analysis application. Pengfei Wu 0003, Qi Li 0002, Jianting Ning, Xinyi Huang 0001, Wei Wu 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | Rphx: Result Pattern Hiding Conjunctive Query Over Private Compressed Index Using Intel SGXabstractDeploying data storage and query service in an untrusted cloud server raises critical privacy and security concerns. This paper focuses on the fundamental problem of processing conjunctive keyword queries over an untrusted cloud in a privacy-preserving manner. Previous tree-based searchable symmetric encryption (SSE) schemes, such asIBTreeandVBTree, can process conjunctive keyword queries in a secure and efficient way. However, these schemes cannot address “Result Pattern (RP)” leakage, which can be used to recover the keywords contained in a conjunctive keyword query. To combat this challenging problem, we propose a result pattern hiding conjunctive query scheme namedRphxusing Intel SGX. In particular, we first propose a new “SGX-aware” compressed index namedVIBTby combining variable-length bloom filter tree, matryoshka filter and online cipher. To achieveRPhiding, we then introduce a new tree-based SSE scheme namedRphxby deployingVIBTto Intel SGX. Security analysis shows thatRphxcan enhance the security requirements by hidingRPleakage under the IND-CKA2 security model. Experimental results show thatVIBTgains at least$30\times $improvement in storage efficiency andRphxcan achieve comparable search efficiency comparing with previous works. Ee-Chien Chang, Yong Qi 0001, Saiyu Qi, Pengfei Wu 0003, Jianfeng Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2021 | Dynamic Curriculum Learning with Co-training for Medical Dialogue GenerationabstractThe purpose of medical dialogue generation is to provide automatic and accurate responses to help doctors provide diagnosis and treatment advice in an efficient w ay. However, due to the subjectivity and open-ended nature of human conversations, the complexity of training dataset varies greatly. Some methods try to solve this problem by using curriculum learning that organizes training data from easy to hard and optimizes the model with an “easy-to-difficult” scheme, but they ignore the intrinsic nature of conversation dataset that has different categories. To solve this problem, in this article, we learn a Dynamic Curriculum with Co-training (DCC) for generative dialogue systems considering both the quality and category of the data. Under our framework, we first t rain two models (query generation model and reply generation model) from dual view by leveraging end-to-end deep Gaussian Mixture Variational Autoencoders (GMVAE) architectures that combine generative and unsupervised clustering tasks together. Then we promote the clustering performance via an ensemble method by combining the clustering distribution of the two networks. Finally, we let the two models determine the training order for each other in each category according to their loss and category confidence dynamically through single-task and multitask curriculum learning. Evaluation results on the widely used medical dialogue generation dataset indicate that our proposed learning approach makes significant improvements compared to strong baselines. varies greatly. Qingqing Zhu, Zhouxing Tan, Jiaxin Duan, Pengfei Wu 0003, Dongyan Zhao 0001 |
BIBM | 4 |
| 2021 | Knowledge Distillation with Metric Learning for Medical Dialogue GenerationabstractIn recent years, the research of the medical dialogue system has attracted much attention. Considering that in the dialogue system, queries with similar meanings tend to have similar replies. In the medical field, this phenomenon is even more prevalent. For queries of the same class, their corresponding replies typically have similar meanings and can be classified into the same category. Having observed that, we propose to improve the neural sequence-to-sequence (Seq2Seq) based medical dialogue system by utilizing this internal relationship of category information between queries and replies. In our model, we first cluster similar queries into the same category according to their query vectors obtained from the encoder. Then we put forward the indirect and direct distillation learning approach to transfer the category information and category center distance from the queries to the replies. In the indirect distillation process, we employ metric learning to learn better representations of replies, in which replies of corresponding queries in the same category are closely grouped together, whereas those with different categories are far apart. In the direct distillation, to transfer the inter-class relationship, we minimize the Kullback-Leibler (KL) divergence between the category center distance distribution of queries and replies. A large number of experimental results on medical datasets have proved that our method is superior to the most advanced one. Qingqing Zhu, Pengfei Wu 0003, Zhouxing Tan, Jiaxin Duan, Dongyan Zhao 0001 |
BIBM | 2 |
| 2021 | Bidirectional Distillation for Multi-Guidance Medical Dialogue GenerationabstractAlthough researches on the dialogue system with deep learning methods have achieved good performance, medical dialogue generation confronts particular difficulties against other domains. As requiring highly accurate replies, many different types of external guidance signals are provided in previous studies to control the output and increase faithfulness. However, how these strategies compare and combine to each other is not known. In light of these challenges, we propose a multi-guidance model with bidirectional distillation for medical dialogue generation. Firstly, we fuse different guidance signals (keywords, categories and summaries) with neural sequence-to-sequence (Seq2Seq) model as teacher models. Meanwhile, we consider a simplified model without guidance as the student model. We also propose an attention mechanism to ensemble for the fusion of knowledge from multiple teachers. We further develop a bidirectional distillation module to exchange the knowledge between the teachers and a student from both sides during the training process. Through extensive experiments on medical dataset, we demonstrate the superiority of our proposed approach over state-of-the-art ones. Qingqing Zhu, Pengfei Wu 0003, Dongyan Zhao 0001 |
BIBM | 2 |
| 2021 | On the Security of Privacy-Preserving Attribute-Based Keyword Search in Shared Multi-Owner SettingabstractRecently in the IEEE Transactions on Dependable and Secure Computing (doi: 10.1109/TDSC.2019.28976752019), Miao et al. proposed a novel construction of Privacy-Preserving Attribute-Based Keyword Search in Shared Multi-owner Setting (ABKS-SM), which can delegate keyword search tasks to cloud server provider (CSP) without revealing any useful information. Although the authors claimed that the offline keyword guessing attacks can be resisted in ABKS-SM scheme, we show that this scheme indeed suffers from four types of offline keyword guessing attacks and hence fails to gain the claimed security property, which is an important goal to be achieved in searchable encryption schemes. Specifically, given the concrete attacks, we demonstrate that the underlying keyword information can be extracted from both encrypted keyword indexes and trapdoors by any malicious user and any adversarial CSP. We hope that the similar security vulnerabilities could be avoided in the future design of related searchable encryption schemes. Jianfei Sun, Hu Xiong, Xuyun Nie, Yinghui Zhang 0002, Pengfei Wu 0003 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | ObliComm: Towards Building an Efficient Oblivious Communication SystemabstractAnonymous Communication (AC) hides traffic patterns and protects message metadata from being leaked during message transmission. Many practical AC systems have been proposed aiming to reduce communication latency and support a large number of users. However, how to design AC systems which possess strong security property and at the same time achieve optimal performance (i.e., the lowest latency or highest horizontal scalability) has been a challenging problem. In this paper, we propose an ObliComm framework, which consists of six modular AC subroutines. We also present a strong security definition for AC, named oblivious communication, encompassing confidentiality, unobservability, and a new requirement sending-and-receiving operation hiding. The AC subroutines in ObliComm allow for modular construction of oblivious communication systems in different network topologies. All constructed systems satisfy oblivious communication definition and can be provably secure in the universal composability (UC) framework. Additionally, we model the relationship between the network topology and communication measurements by queuing theory, which enables the system's efficiency can be optimized and estimated by quantitative analysis and calculation. Through theoretical analyses and empirical experiments, we demonstrate the efficiency of our scheme and soundness of the queuing model. Pengfei Wu 0003, Robert H. Deng, Qingni Shen, Ximeng Liu, Qi Li 0002, Zhonghai Wu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | RSDS: Getting System Call Whitelist for Container Through Dynamic and Static AnalysisabstractContainer technology has been used for running multiple isolated operating system distros on a host or deploying large scale microservice-based applications. In most cases, containers share the same kernel with the host and other containers on the same host, and the application in the container can make system calls of the host kernel like a normal process on the host. Seccomp is a security mechanism for the Linux kernel, through which we can prohibit certain system calls from being executed by the program. Docker began to support the seccomp mechanism from version 1.10 and disables around 44 system calls out of 300+ by default. However, for a particular container, there are still many system calls that are unnecessary for running it allowed to be executed, and the abuse of system calls by a compromised container can trigger the security vulnerabilities of a host kernel. Unfortunately, Docker does not provide a way to get the necessary system calls for a particular container. In this paper, we propose RSDS, a method combining dynamic analysis and static analysis to get the necessary system calls for a particular container. Our experiments show that our solution can reduce system calls by 69.27%-85.89% compared to the default configuration on an x86-64 PC with Ubuntu 16.04 host OS and does not affect the functionalities of these containers. Xuhao Wang, Qingni Shen, Wu Luo, Pengfei Wu 0003 |
CLOUD | 4 |
| 2020 | Lightning-fast and privacy-preserving outsourced computation in the cloudabstractAbstract In this paper, we propose a framework for lightning-fast privacy-preserving outsourced computation framework in the cloud, which we refer to as LightCom. Using LightCom, a user can securely achieve the outsource data storage and fast, secure data processing in a single cloud server different from the existing multi-server outsourced computation model. Specifically, we first present a general secure computation framework for LightCom under the cloud server equipped with multiple Trusted Processing Units (TPUs), which face the side-channel attack. Under the LightCom, we design two specified fast processing toolkits, which allow the user to achieve the commonly-used secure integer computation and secure floating-point computation against the side-channel information leakage of TPUs, respectively. Furthermore, our LightCom can also guarantee access pattern protection during the data processing and achieve private user information retrieve after the computation. We prove that the proposed LightCom can successfully achieve the goal of single cloud outsourced data processing to avoid the extra computation server and trusted computation server, and demonstrate the utility and the efficiency of LightCom using simulations. Ximeng Liu, Robert H. Deng, Pengfei Wu 0003, Yang Yang 0026 |
Cybersecur. | 3 |
| 2020 | A new framework for privacy-preserving biometric-based remote user authenticationabstractIn this paper, we introduce the first general framework for strong privacy-preserving biometric-based remote user authentication based on oblivious RAM (ORAM) protocol and computational fuzzy extractors. We define formal security models for the general framework, and we prove that it can achieve user authenticity and strong privacy. In particular, the general framework ensures that: (1) a strong privacy and a log-linear time-complexity are achieved by using a new tree-based ORAM protocol; (2) a constant bandwidth cost is achieved by exploiting computational fuzzy extractors in the challenge-response phase of remote user authentications. Yangguang Tian, Yingjiu Li, Robert H. Deng, Nan Li 0007, Pengfei Wu 0003, Anyi Liu |
J. Comput. Secur. | 5 |
| 2019 | ObliDC: An SGX-based Oblivious Distributed Computing Framework with Formal ProofabstractData privacy is becoming one of the most critical concerns in cloud computing. Several proposals based on Intel SGX such as VC3 [1] and M2R [2] have been introduced in the literature to protect data privacy during job execution in the cloud. However, a comprehensive formal proof of their security guarantees is still lacking. In this paper, we propose ObliDC, a general UC-secure SGX-based oblivious distributed computing framework. First, we model the life-cycle of a distributed computing job as data-flow graphs. Under the assumption of malicious, adaptive adversaries in the cloud, we then formally define data privacy of a distributed computing job by introducing a notion named ODC-privacy, which encompasses both semantic security (to protect data confidentiality during computation and transmission) and oblivious traffic (to prevent data leakage from traffic analysis). ObliDC is composed of four two-party protocols -- job deployment, job initialization, job execution, and results return, which allow for modular construction of concrete privacy-preserving job protocols in different distributed computing frameworks. Finally, inspired by a formal abstraction for trusted processors proposed by R. Pass et al. [3], we formally prove the security of ObliDC under the universal composability (UC) framework. Pengfei Wu 0003, Qingni Shen, Robert H. Deng, Ximeng Liu, Yinghui Zhang 0002, Zhonghai Wu |
AsiaCCS | 1 |
| 2019 | Efficient and Robust Certificateless Signature for Data Crowdsensing in Cloud-Assisted Industrial IoTabstractWith the digitalization of various industries, the combination of cloud computing and the industrial Internet of Things (IIoT) has become an attractive data processing paradigm. However, the cloud-assisted IIoT still has challenging issues, including authenticity of data, untrustworthiness of third parties, and system robustness and efficiency. Recently, a lightweight certificateless signature (CLS) scheme for the cloud-assisted IIoT, that was claimed to address both authenticity of data and untrustworthiness of third parties, has been proposed by Karati et al. (2018). In this paper, we demonstrate that the CLS scheme fails to achieve the claimed security properties by presenting four types of signature forgery attacks. We also propose a robust certificateless signature (RCLS) scheme to address the aforementioned challenges. Our RCLS only needs public channels and is proven secure against both public key replacement attacks and malicious-but-passive third parties in the standard model. Performance evaluation indicates that the RCLS scheme outperforms other CLS schemes and is suitable for the IIoT. Yinghui Zhang 0002, Robert H. Deng, Dong Zheng 0001, Jin Li 0002, Pengfei Wu 0003, Jin Cao 0001 |
IEEE Trans. Ind. Informatics | 5 |