Wenying Zhang 0001

dblp:92/4677-1 · also WenYing Zhang 0001 · DBLP profile ↗
← Back
22ranked-venue papers
7as first author
10since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 14 · 4 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1Theory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2025 PPSKSQ: Towards Efficient and Privacy-Preserving Spatial Keyword Similarity Query in Cloud
abstract
The growth of cloud computing has led to the widespread use of location-based services, such as spatial keyword queries, which return spatial data points within a given range that have the highest similarity in keyword sets to the user’s. As the volume of spatial data increases, providers commonly outsource data to powerful cloud servers. Because cloud servers are untrustworthy, privacy-preserving keyword query schemes have been proposed. However, existing schemes consider only location queries or exact keyword matching. To address these issues, we propose the Privacy-Preserving Spatial Keyword Similarity Query Scheme (PPSKSQ), designed to search for spatial data points with the highest similarity while protecting the privacy of outsourced data, query requests, and results. First, we design two sub-protocols based on improved symmetric homomorphic encryption (iSHE): iSHE-SC for secure size comparison and iSHE-SIP for secure inner product computation. Then, we encode range information and integrate it with a quadtree to construct a novel index structure. Additionally, we use the Jaccard to measure similarity in conjunction with the iSHE-SC protocol, transforming similarity comparison into a matrix trace operation. Finally, rigorous security analysis and extensive simulation experiments confirm the flexibility, efficiency, and scalability of our scheme.
Changrui Wang, Lei Wu 0011, Lijuan Xu 0001, Hao Wang 0007, Wenying Zhang 0001, Weizhi Meng 0001
IEEE Trans. Cloud Comput.6
2025 MSecKNN: Maliciously Secure Outsourced KNN Classification Under Multiple Distance Metrics
Zhi Li 0056, Hao Wang 0007, Wenying Zhang 0001, Ye Su 0001, Willy Susilo
IEEE Trans. Inf. Forensics Secur.3
2024 Known-Key Attack on GIFT-64 and GIFT-64[g0c] Based on Correlation Matrices
Xiaomeng Sun, Wenying Zhang 0001, René Rodríguez
ACISP (1)2
2024 EPri-MDAS: An efficient privacy-preserving multiple data aggregation scheme without trusted authority for fog-based smart grid
abstract
With the increasingly pervasive deployment of fog servers, fog computing extends data processing and analysis to network edges. At the same time, as the next-generation power grid, the smart grid should meet the requirements of security, efficiency, and real-time monitoring of user energy consumption. By utilizing the low-latency and distributed properties of fog computing, it can improve communication efficiency and user service satisfaction in smart grids. For the sake of providing adequate functionality for the power grid, various schemes have been proposed. Whereas, many methods are vulnerable to privacy leakage since the existence of trusted authority may increase the exposure to threats. In this paper, we propose the EPri-MDAS: an Efficient Privacy-preserving Multiple Data Aggregation Scheme without trusted authority based on the ElGamal homomorphic cryptosystem, which achieves both data integrity verification and data source authentication with the most efficient block cipher-based authenticated encryption algorithm. It performs well in energy efficiency with strong security. Especially, the proposed multidimensional aggregation statistics scheme can perform the fine-grained data analyses; it also allows for fault tolerance while protecting personal privacy. The security analysis and simulation experiments show that EPri-MDAS can satisfy the security requirements and work efficiently in the smart grid.
Jinjiao Zhang, Wenying Zhang 0001, Xiaochao Wei
High Confid. Comput.2
2024 SecKNN: FSS-Based Secure Multi-Party KNN Classification Under General Distance Functions
abstract
As a practical machine learning method, the K-nearest neighbors (KNN) classification has received widespread attention. The achievement of the KNN classification relies heavily on a large amount of labeled data. However, in the real world, data is often held by different data owners. How to realize efficient joint computing among multiple data owners under the premise of protecting data security and privacy is an urgent problem to be solved. In this paper, we construct a secure multi-party KNN classification scheme (SecKNN) based on function secret sharing (FSS) technology, which is a novel cryptographic primitive and can achieve cheap communication and computation costs for secure computation. Compared with the existing works, our scheme dramatically reduces computational overhead and runs roughly 50.8 times faster than the state-of-the-art approach. Furthermore, our scheme supports the secure KNN classification under general distance functions such as Euclidean distance, Manhattan distance, and Hamming distance. To implement our SecKNN scheme, we design two efficient FSS schemes for Hamming distance function, which implements secure two-party and multi-party Hamming distance computation in a single round. They can be considered as independent research results. Finally, we give formal security proofs for the proposed protocols and validate the effectiveness and efficiency of our protocols through experiments.
Zhi Li 0056, Hao Wang 0007, Songnian Zhang, Wenying Zhang 0001, Rongxing Lu
IEEE Trans. Inf. Forensics Secur.4
2024 Privacy-Preserving Distributed Transfer Learning and Its Application in Intelligent Transportation
abstract
With the rapid development of intelligent transportation systems (ITS), more and more intelligent applications for ITS have received widespread attention, such as the vehicle detection, inference of typical routes, and traffic forecasting. In these applications, deep learning is widely used as a key artificial intelligence technology. However, most ITS providers fail to collect enough labeled traffic data for model training. As a complement to deep learning, transfer learning is an effective way to solve the scarcity of labeled data, which can transfer knowledge from labeled datasets to unlabeled datasets, thus improving the accuracy of prediction and classification. Nevertheless, when the labeled dataset and the unlabeled dataset are held by different entities, it is still unrealistic for two mutually distrustful entities to cooperate in transfer learning regarding data security and privacy preservation. Although some existing works provide privacy-preserving transfer learning methods, such methods fail to apply to traffic data with high sample dimensions due to their high computational cost and round complexity. To address this problem, we design an efficient privacy-preserving distributed transfer learning protocol, which is appropriate for traffic data. Compared to existing works, our protocol addresses the privacy-preserving problem of transfer learning for traffic data with high sample dimensions. In addition, our protocol has fewer interaction rounds and can be proved in the semi-honest model. Finally, we validate the effectiveness, efficiency and security of the proposed protocol via experiments. Furthermore, we show the application of the proposed protocol in intelligent transportation systems.
Zhi Li 0056, Hao Wang 0007, Guangquan Xu, Alireza Jolfaei, James Xi Zheng, Chunhua Su, Wenying Zhang 0001
IEEE Trans. Intell. Transp. Syst.7
2023 Vulnerability Analysis of Chinese Digital Passwords Related to ATM PIN Using Deep Learning
abstract
Human-made digital passwords are a dominant form of ATM card authentication. However, it is vulnerable to guessing attacks. Unfortunately, previous studies have focused on letters-only passwords or passwords that include both letters and digits, and few empirical studies have been conducted on the security of digital passwords, let alone the regional differences in digital passwords. In this paper, we studied the vulnerability of pure six-digit passwords extracted from the leaked dataset of the Chinese website. We used the Pearson chi-square test to check whether each digit in the password obeyed a uniform distribution. We showed regional conventions for Chinese digital passwords. We proposed using a recurrent neural network (RNN) to model password resistance to guessing attacks and explore how different architectures and training methods impact the effectiveness of neural networks. The experimental results on five website datasets demonstrate the superior performance of the proposed approach over state-of-the-art deep learning techniques in terms of both learning efficiency and matching accuracy.
Hongfang Shi, Wenying Zhang 0001, Zimin Zhang, Dewen Ding
IEEE Trans. Dependable Secur. Comput.2
2022 Clustering of differentials in CRAFT with correlation matrices
abstract
CRAFT is an substitution-permutation network tweakable block cipher proposed at fast software encryption 2019 by Beierle et al., which is designed to optimize the efficient protection against differential fault analysis (DFA) attacks. In this paper, the full round differential characteristics for CRAFT block cipher are given. A new method on counting the number of differentials by using correlation matrix is given. We can compute the number of all optimal characteristics or suboptimum differentials with the same input difference and output difference by hand. We explore the multiple differential trails and compute the probability of differential characteristic by using the multiplication of correlation matrices. Our work complements automatic search methods for the best differential with a careful manual analysis. Since the automatic search method is stranded by storage and search space limitations, which will cause a computer to crash as the number of search rounds increases. Thanks to the correlation matrix technique, we are able to find differential distinguishers for 9-round of the cipher with the probability of at least 2 − 40.68 + 2 − 48.60 ${2}^{-40.68}+{2}^{-48.60}$ . Moreover, we can construct differential distinguisher covers more rounds based on the 9-round differential distinguishers. As one of its typical application, we propose the differential characteristics for the full-round CRAFT which ensure that the probability of each round is optimal. Besides, we explore the clustering effect on the full round by exhibiting a class of high probability characteristics for 9-round. In general, we obtain a good understanding of the propagation of differences for CRAFT due to its algebraic structure.
Wenying Zhang 0001, Jinjiao Zhang, Xiaomeng Sun
Int. J. Intell. Syst.2
2022 Understanding digit-only financial account passwords: ID card, structure, and security
abstract
Password-based authentication is widely used in website access. Current studies on password security have focused considerable attention on letter-only passwords or passwords that include both letters and digits. However, little research has been conducted on commercial and digit-only passwords. In this paper, we comprehensively evaluate digit-only passwords by analyzing approximately 130,000 passwords from the 12306 data set. We observe that approximately 20% of six-digit passwords belonging to Chinese users include the user's identity document (ID) card information. Most of the passwords are found to be related to the user's birth dates. Additionally, we demonstrate that male users are more likely to set passwords with digits extracted from their ID card numbers than female users. It is the first time that the relation between real-user passwords and ID card series numbers was considered. It focuses on actual attack methodologies and real-user passwords, which renders this study an explicit study on digit-only password security. We propose a password-encryption authentication model based on FF3-1 to implement secure storage of passwords. We experiment with ciphertext and plaintext passwords using three–three and four–two structures combined with probabilistic context-free grammars. The cracking success rates of ciphertext passwords are found to be 0.086% and 1.06%, and they can recover 59.83% and 33.2% of the passwords in the test set. Conversely, using plaintext passwords results in the recovery of 98% and 85% of passwords in the test set. Our results demonstrate that the use of encryption for password storage can significantly reduce the cracking success rate of attackers.
Hongfang Shi, Wenying Zhang 0001, Zimin Zhang, Dewen Ding
Int. J. Intell. Syst.2
2021 Genetic Algorithm Assisted State-Recovery Attack on Round-Reduced Xoodyak
Zimin Zhang, Wenying Zhang 0001, Hongfang Shi
ESORICS (2)2
2020 The phantom of differential characteristics
Yunwen Liu, Wenying Zhang 0001, Bing Sun 0001, Vincent Rijmen, Chao Li 0002, Shaojing Fu, Meichun Cao
Des. Codes Cryptogr.2
2020 Improved Conditional Differential Analysis on NLFSR-Based Block Cipher KATAN32 with MILP
abstract
In this paper, a new method for constructing a Mixed Integer Linear Programming (MILP) model on conditional differential cryptanalysis of the nonlinear feedback shift register- (NLFSR-) based block ciphers is proposed, and an approach to detecting the bit with a strongly biased difference is provided. The model is successfully applied to the block cipher KATAN32 in the single-key scenario, resulting in practical key-recovery attacks covering more rounds than the previous. In particular, we present two distinguishers for 79 and 81 out of 254 rounds of KATAN32. Based on the 81-round distinguisher, we recover 11 equivalent key bits of 98-round KATAN32 and 13 equivalent key bits of 99-round KATAN32. The time complexity is less than 2 31 encryptions of 98-round KATAN32 and less than 2 33 encryptions of 99-round KATAN32, respectively. Thus far, our results are the best known practical key-recovery attacks for the round-reduced variants of KATAN32 regarding the number of rounds and the time complexity. All the results are verified experimentally.
Zhaohui Xing, Wenying Zhang 0001, Guoyong Han
Wirel. Commun. Mob. Comput.2
2019 Division cryptanalysis of block ciphers with a binary diffusion layer
abstract
In this study, the authors propose an accurate approach to model the propagation of the division property of linear layers by the smallest amount of inequalities. The solutions of the inequalities are exactly the division trails of a linear transformation. Therefore, the description is compact and optimal. As applications of their results, they present a 7‐round integral distinguisher for both Midori64 and Midori128. The designers of Midori only obtained a 3.5‐round integral characteristic. For Skinny64, they find a 10‐round integral distinguisher which was previously found by the designers. It is well to remind that their result proves that 7 rounds and 10 rounds are the upper bounds of Midori and Skinny64 correspondingly when searching for integral distinguishers based on division property. The significance of their result lies in that they shed light on how far division cryptanalysis can influence the security analysis of block ciphers with a binary diffusion layer, and their technique can be used to prove security against division cryptanalysis.
Wenying Zhang 0001, Vincent Rijmen
IET Inf. Secur.1
2018 Construction of rotation symmetric bent functions with maximum algebraic degree
Wenying Zhang 0001, Guoyong Han
Sci. China Inf. Sci.1
2018 Searching for perfect diffusion matrices with lightweight coefficients
Wenying Zhang 0001
J. Inf. Secur. Appl.2
2018 Differential Cryptanalysis on Block Cipher Skinny with MILP Program
abstract
With the widespread use of RFID technology and the rapid development of Internet of Things, the research of lightweight block cipher has become one of the hot issues in cryptography research. In recent years, lightweight block ciphers have emerged and are widely used, and their security is also crucial. Skinny-64/192 can be used to protect data security such as the applications of wireless multimedia and wireless sensor networks. In this paper, we use the new method to verify the security of Skinny-64/192. The method is called mixed-integer linear programming (MILP) which can characterize precisely the linear operation and nonlinear operation in a round function. By applying MILP program, we can automatically find a 11-round differential characteristic for Skinny-64/192 with the minimum number of active s-boxes. The probability of differential trail is 2-147 , that is, far greater than 2-192 which is the probability of success for an exhaustive search. In addition, comparing this method with the one proposed by Sun et al., we also have a great improvement; that is, no new variables will be added in ShiftRows operation. It can reduce greatly the number of variables and improve the running speed of the computer. Besides, the experimental result proves that Skinny-64/192 is safe on 11-round differential analysis and validates the effectiveness of the MILP method.
Wenying Zhang 0001
Secur. Commun. Networks2
2017 Improved Biclique Cryptanalysis of the Lightweight Block Cipher Piccolo
abstract
Biclique cryptanalysis is a typical attack through finding a biclique which is a type of bipartite diagram to reduce the computational complexity. By investigating the subkey distribution and the encryption structure, we find out a weakness in the key schedule of Piccolo-80. A 6-round biclique is constructed for Piccolo-80 and a 7-round biclique for Piccolo-128. Then a full round biclique cryptanalysis of Piccolo is presented. The results of the attacks are with data complexity of 240and 224chosen ciphertexts and with computational complexity of 279.22and 2127.14, respectively. They are superior to other known results of biclique cryptanalytic on Piccolo.
Guoyong Han, Wenying Zhang 0001
Secur. Commun. Networks2
2016 Algebraic techniques on searching linear diffusion layers in block cipher
abstract
Abstract Maximum branch number permutation plays an efficacious role in providing resistance against the most well‐known attacks on block ciphers, such as differential cryptanalysis and linear cryptanalysis. In this paper, we propose algebraic techniques in searching permutations with maximal branch number, which can be employed as the linear diffusion layers in block ciphers. We focus on permutations composed of simple operations such as word‐level XORs and rotations. Some necessary conditions are proposed to filter out linear permutations that cannot achieve the maximal branch number. With these conditions, the searching process of maximum permutation on 32‐bit word can be finished in 1 s, contrast to the previous searching method which spent several days on two computers. What is the most important is that it can be generalized to 64‐bit word and show that there is no 8‐byte word permutation, which is XOR of 9 right‐rotations or 11 right‐rotations with maximum branch number. Copyright © 2016 John Wiley & Sons, Ltd.
Wenying Zhang 0001
Secur. Commun. Networks1
2012 A new one-bit difference collision attack on HAVAL-128
Wenying Zhang 0001, Lei Wu 0011
Sci. China Inf. Sci.1
2009 Construction and enumeration of Boolean functions with maximum algebraic immunity
Wenying Zhang 0001, Chuankun Wu, XiangZhong Liu
Sci. China Ser. F Inf. Sci.1
2008 Impossible Differential Analysis of Reduced Round CLEFIA
Wenying Zhang 0001
Inscrypt1
2006 The Algebraic Normal Form, Linear Complexity and k-Error Linear Complexity of Single-Cycle T-Function
Wenying Zhang 0001, Chuan-Kun Wu
SETA1