Yong Li 0021

dblp:93/2334-21 · DBLP profile ↗
← Back
21ranked-venue papers
3as first author
14since 2021 · last 2026
0000-0002-6920-0663ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 17 · 3 first-author · 11 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1Theory of computation · 1
YearPublicationVenuePosition
2026 Realistic Face Reconstruction from Facial Embeddings via Diffusion Models
abstract
With the advancement of face recognition (FR) systems, privacy-preserving face recognition (PPFR) systems have gained popularity for their accurate recognition, enhanced facial privacy protection, and robustness to various attacks. However, there are limited studies to further verify privacy risks by reconstructing realistic high-resolution face images from embeddings of these systems, especially for PPFR. In this work, we propose the face embedding mapping (FEM), a general framework that explores Kolmogorov-Arnold Network (KAN) for conducting the embedding-to-face attack by leveraging pre-trained Identity-Preserving diffusion model against state-of-the-art (SOTA) FR and PPFR systems. Based on extensive experiments, we verify that reconstructed faces can be used for accessing other real-word FR systems. Besides, the proposed method shows the robustness in reconstructing faces from the partial and protected face embeddings. Moreover, FEM can be utilized as a tool for evaluating safety of FR and PPFR systems in terms of privacy leakage. All images used in this work are from public datasets.
Yong Li 0021, Joachim Denzler
AAAI2
2026 Completing Policy-based Anonymous Tokens: Private Bits, Public Metadata and more
abstract
Anonymous tokens are cryptographic protocols for restricting the access to online resources to eligible users. After proving eligibility to the token issuer, the client receives a set of tokens. Later, it proves eligibility to a resource provider by sending one of its tokens. The protocol ensures that the resource provider cannot link received tokens to their issuance. Recently, Faut et al. (EuroS&P'25) introduced policy-based anonymous tokens, in which a client obtains a single pre-token and locally derives additional tokens according to a publicly announced policy. The major advantage of policy-based tokens is that the communication complexity of the issuance phase is constant. While the work of Faut et al. constitutes a promising step into a new direction, their protocol lacks several desirable properties known from standard anonymous tokens - most notably, the ability to bind a pre-token and all tokens derived from it to a private metadata bit or a publicly known metadata string.
David Kretzler, Yong Li 0021, Codrin Ogreanu
AsiaCCS2
2026 Certificateless Key Exchange in QROM: Group-Action-based Construction and Performance
Yong Li 0021, Joao Sobral
EuroS&P2
2026 No Honor Among Crooks: Non-Transferable Anonymous Tokens from Betrayability
David Kretzler, Yong Li 0021
SP2
2025 Obfuscation for Deep Neural Networks Against Model Extraction: Attack Taxonomy and Defense Optimization
Yulian Sun, Vedant Bonde, Yong Li 0021
ACNS (3)4
2025 Diffusion-based Identity-Preserving Facial Privacy Protection
abstract
The efficacy of facial recognition systems that utilize deep learning techniques has led to significant concerns over privacy, since they possess the capability to facilitate unauthorized monitoring of individuals in the digital realm. Current techniques for improving privacy are ineffective in producing "naturalistic" photographs that can safeguard facial features and fail to ensure privacy while maintaining an optimal user experience. We present an innovative text-agnostic method for protecting facial privacy. Our method depends on manipulating the sampling process of a pretrained diffusion model utilizing the guidance from a target image face together with the original image and face guidance in an adversarial manner to produce a protected face image. We preserve the original visual information from the input face image for identity preservation while extracting general embedding information from the target face image for soft facial attribute transfer. The output protected face image from our method has imperceptible facial changes with enhanced privacy protection against state-of-the-art (SOTA) face recognition (FR) systems. Our extensive studies have shown that the faces generated using our method have a higher level of black-box adaptability, resulting in an absolute improvement of 6.4% on CelebA-HQ compared to the current most effective SOTA facial privacy protection technique in the face verification task while maintaining high image fidelity.
Salaheldin Mohamed, Yong Li 0021, Joachim Denzler
ICASSP3
2025 Honorific Security: Efficient Two-Party Computation with Offloaded Arbitration and Public Verifiability
abstract
In the secure two-party computation (2PC), an adversary is often categorized as semi-honest or malicious, depending on whether it follows the protocol specifications. Covert security (Aumann and Lindell, 2010) first looks into the “middle ground”, such that an active adversary who cheats will be caught with a predefined probability. Other security notions, such as publicly auditable security (Baum et al., 2014) and (robust) accountability family (Küsters et al., 2010; Graf et al., 2023; Rivinius et al., 2022), achieve public verifiability as a stronger security guarantee by relying on heavy offline and online constructions with zero knowledge proofs and (or) a bulletin board functionality. In this work, we propose a new security notion called honorific security, where an external arbiter can identify the cheater without a bulletin board. Specifically, we delay and outsource the verification steps to the arbiter, so that the original online computation is thus accelerated. We show that a maliciously secure garbled circuit (GC) (Yao, 1986) protocol can be constructed with only slightly more overhead than a passively secure protocol. Our construction performs up to 2.37 times and 13.30 times as fast as the state-of-the-art protocols with covert and malicious security, respectively.
Tianxiang Dai, Yufan Jiang, Yong Li 0021, Jörn Müller-Quade, Andy Rupp
SECRYPT3
2024 SiGBDT: Large-Scale Gradient Boosting Decision Tree Training via Function Secret Sharing
abstract
As a well known machine learning model, Gradient Boosting Decision Tree (GBDT) is widely used in many real-world scenes such as online marketing, risk management, fraud detection and recommendation systems. Due to limited data resources, two data owners may collaborate with each other to jointly train a high-quality model. As privacy regulations such as HIPPA and GDPR come into force, Privacy-Preserving Machine Learning (PPML) has drawn increasingly higher attention. Recently, a line of works [3--6] studies function secret sharing (FSS) schemes in the preprocessing model, where the online stage of secure two-party computation (2PC) is significantly improved. While recent privacy-preserving GDBT frameworks mainly focus on improving the performance of a singular module (e.g. secure bucket aggregation), we propose SiGBDT, a globally silent two-party GBDT framework via function secret sharing on a vertically partitioned dataset. During the training process, we apply FSS schemes to construct efficient modular protocols, such as secure bucket aggregation, argmax computation and a node split approach. We run in-depth experiments and discover that SiGBDT completely outperforms state-of-the-art frameworks. The experiment results show that SiGBDT is at least 3.32 X faster in LAN and at least 6.4 X faster in WAN.
Yufan Jiang, Fei Mei, Tianxiang Dai, Yong Li 0021
AsiaCCS4
2024 Protoss: Protocol for Tight Optimal Symmetric Security
Emanuele Di Giandomenico, Yong Li 0021, Sven Schäge
CCS2
2024 Privacy-Preserving Certificate-Less Authenticated Key Exchange with Key Registration Privacy
Yong Li 0021
Inscrypt (1)2
2024 Exploiting Internal Randomness for Privacy in Vertical Federated Learning
Yulian Sun, Ricardo Mendes, Derui Zhu, Yue Xia, Yong Li 0021, Asja Fischer
ESORICS (2)6
2024 Robust Skin Color Driven Privacy-Preserving Face Recognition Via Function Secret Sharing
abstract
In this work, we leverage the pure skin color patch from the face image as the additional information to train an auxiliary skin color feature extractor and face recognition model in parallel to improve performance of state-of-the-art (SOTA) privacy-preserving face recognition (PPFR) systems. Our solution is robust against black-box attacking and well-established generative adversarial network (GAN) based image restoration. We analyze the potential risk in previous work, where the proposed cosine similarity computation might directly leak the protected precomputed embedding stored on the server side. We propose a Function Secret Sharing (FSS) based face embedding comparison protocol without any intermediate result leakage. In addition, we show in experiments that the proposed protocol is more efficient compared to the Secret Sharing (SS) based protocol.
Yufan Jiang, Yong Li 0021, Ricardo Mendes, Joachim Denzler
ICIP3
2023 On the Privacy-Preserving Infrastructure for Authenticated Key Exchange
Yong Li 0021
ISC2
2023 Efficient Forward Secrecy for TLS-PSK from Pure Symmetric Cryptography
Yong Li 0021, Lijun Liao
ISC2
2020 Non-interactive certificate update protocol for efficient authentication in IoT
Yong Li 0021, Lijun Liao
Future Gener. Comput. Syst.2
2018 Secure Deduplication of Encrypted Data: Refined Model and New Constructions
Jian Liu 0012, Yong Li 0021, N. Asokan
CT-RSA3
2017 No-Match Attacks and Robust Partnering Definitions: Defining Trivial Attacks for Security Protocols is Not Trivial
abstract
An essential cornerstone of the definition of security for key exchange protocols is the notion of partnering. The de-facto standard definition of partnering is that of (partial) matching conversations (MC), which essentially states that two processes are partnered if every message sent by the first is actually received by the second and vice versa. We show that proving security under MC-based definitions is error-prone. To this end, we introduce no-match attacks, a new class of attacks that renders many existing security proofs invalid. We show that no-match attacks are often hard to avoid in MC-based security definitions without a) modifications of the original protocol or b) resorting to the use of cryptographic primitives with special properties. Finally, we show several ways to thwart no-match attacks. Most notably and as one of our major contributions, we provide a conceptually new definition of partnering that circumvents the problems of a MC-based partnering notion while preserving all its advantages. Our new notion of partnering not only makes security definitions for key exchange model practice much more closely. In contrast to many other security notions of key exchange it also adheres to the high standards of good cryptographic definitions: it is general, supports cryptographic intuition, allows for efficient falsification, and provides a fundamental composition property that MC-based notions lack.
Yong Li 0021, Sven Schäge
CCS1
2016 On the Impossibility of Tight Cryptographic Reductions
Christoph Bader, Tibor Jager, Yong Li 0021, Sven Schäge
EUROCRYPT (2)3
2015 Tightly-Secure Authenticated Key Exchange
Christoph Bader, Dennis Hofheinz, Tibor Jager, Eike Kiltz, Yong Li 0021
TCC (1)5
2014 New Modular Compilers for Authenticated Key Exchange
Yong Li 0021, Sven Schäge, Zheng Yang 0005, Christoph Bader, Jörg Schwenk
ACNS1
2013 Strongly Secure One-Round Group Authenticated Key Exchange in the Standard Model
Yong Li 0021, Zheng Yang 0005
CANS1