EDBT 2026 Demo / reviewers in the wild / expert
Xingwen Zhao
dblp:03/7631
· DBLP profile ↗
19ranked-venue papers
10as first author
11since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 4 first-author · 7 since 2021Security and privacy · 7 · 5 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Enhancing Security and Privacy in Multi-Server Federated LearningabstractFederated learning is a distributed learning approach designed to train models across multiple client devices with local data while preserving the privacy of that data. However, traditional federated learning suffers from three major f laws: 1.Vulnerability to Byzantine Attacks. 2.Privacy Leakage Risks. 3.Assumption of Third-Party Server Reliability. Few solutions currently address all three of these flaws at the same time. To address the above issues simultaneously, this paper introduces a multi-server federated learning approach that enhances security and privacy. We first set up a multi-server architecture to address the performance issues and single point of failure in traditional federated learning frameworks. And we set up and update different servers reputation on both the server and participant sides, which work together to resist aggregation attacks that can be implemented by malicious servers. It is also worth noting that we split models to be uploaded into two segments, each of which is uploaded to two different servers in conjunction with the last model of the previous round to defend against privacy attacks and keep model as complete as possible. Experiments on MNIST, IMDB, CIFAR10, and Adult indicate this method maintains accuracy, defends against label-flipping and Gaussian noise, and protects privacy. Xingwen Zhao, Yongfeng Bu, Kai Fan 0001, Hui Li 0006 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | A comprehensive and efficient CP-ABE scheme with full policy hiding and pre-decryption verification in peer-to-peer cyber-physical systems
Xingwen Zhao, Haimei Guan, Jiayin Cai, Hui Li 0006 |
Peer Peer Netw. Appl. | 1 |
| 2025 | EoTMP: Efficient Over-Threshold Multi-Party Private Set IntersectionabstractOver-Threshold Multi-Party Private Set Intersection (OT-MPSI) is a variant of MPSI that aims to return items that appear in at leastTof participants’ sets without revealing any other information. OT-MPSI is applicable to many practical scenarios and offers an advantage over MPSI when identifying items held by most but not all participants. The existing work processes binary vector representations of sets in a bit-wise manner and utilizes Secure Computation Protocols to achieve over-threshold functionality. This results in low computational efficiency, with the number of communication rounds scaling linearly with the number of participants. We propose an efficient OT-MPSI protocol (EoTMP) by utilizing ring learning with errors based multi-party homomorphic encryption. By introducing a new over-threshold functionality and leveraging additional optimization techniques, our EoTMP requirs only three communication rounds and offers faster computation than the state-of-the-art. In addition, our scheme supports thet-Nthreshold access-structure for participant collaboration. Specially, with 45 participants and a threshold of 40, EoTMP processes sets of size 256 in 0.6 seconds, achieving a reduction in computational overhead by three orders of magnitude compared to prior work. Song Bian 0001, Hui Li 0006, Xingwen Zhao |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Open set identification of malicious encrypted traffic based on multi-feature fusion
Xingwen Zhao, Hui Li 0006, Xuangui Chen |
Comput. Networks | 1 |
| 2024 | A Dynamic and Efficient Self-Certified Authenticated Group Key Agreement Protocol for VANETabstractAuthenticated group key agreement (AGKA) protocols protect the security of communications among a group of users. Dutta and Barua proposed a dynamic AGKA protocol, but it fails to the leaving user attacks and the attacks by two malicious users. In this paper, we propose a dynamic AGKA protocol based on the computational Diffie-Hellman problem. The proposed AGKA protocol achieves sound dynamicity and efficiency. With 10 users in a group, the improvements in computation and communication overheads achieve 82.5% and 72.6 %, respectively. Then the proposed AGKA protocol is applied to vehicular ad hoc network (VANET). SC-AGKA, a self-certified authentication and key agreement protocol for VANET is presented. Pseudonyms are employed with care in SC-AGKA to provide conditional privacy. It is suitable for SC-AGKA to protect the vehicular group communications in VANET considering its security strength and efficiency. Xuefei Cao, Lanjun Dang, Kai Fan 0001, Xingwen Zhao, Yingzi Luan |
IEEE Internet Things J. | 4 |
| 2024 | FLSG: A Novel Defense Strategy Against Inference Attacks in Vertical Federated LearningabstractAs a new machine learning (ML) paradigm, federated learning (FL) empowers different participants to jointly train a more effective model than traditional ML. Unlike horizontal FL (HFL), which expands the sample space by aggregating local models, vertical FL (VFL) is suitable for scenarios where the sample ID between participants is the same but differs in sample characteristics. For a long time, VFL has been considered safe due to no data exchange and heterogeneity between parties. However, the recently proposed label inference attacks pose a significant security threat to VFL. Specifically, by adding randomly initialized layers to the top of local models, the passive label inference attack can infer tens of thousands of local participants’ private data with only 40 auxiliary labels. Since the attack is entirely local, using privacy protection technologies such as differential privacy cannot effectively defend against these attacks. Therefore, we propose a new privacy protection scheme called FL similar gradients (FLSGs) to defend against this attack. Unlike differential privacy, the FLSG scheme randomly generates gradients of a Gaussian distribution similar in dimension to the original gradients and calculates their cosine distance. If the distance is less than a certain threshold, the gradients are used instead of the original gradients to pass to the local participants. We conducted extensive evaluations on six real-world data sets, and the results show that FLSG provides a better defensive effect at lower computational overhead than other known methods when defending the passive label inference attack. Kai Fan 0001, Jingtao Hong, Wenjie Li 0008, Xingwen Zhao, Hui Li 0006, Yintang Yang |
IEEE Internet Things J. | 4 |
| 2024 | Volume-Hiding Multidimensional Verifiable Dynamic Searchable Symmetric Encryption Scheme for Cloud ComputingabstractConsiderable attention has been directed toward dynamic searchable symmetric encryption (DSSE) since it has the capability to both search and update the encrypted database. Nevertheless, the majority of DSSE schemes operate in single dimensions, and the server is assumed to be honest but curious. Consequently, there are two significant issues that must be addressed. One concerns how searchable operations can be implemented in a multidimensional space. Another is the construction of a search-result-verifiable DSSE scheme within a malicious server model. In response to the above-mentioned problems, we proposed a multidimensional verifiable DSSE scheme with volume hiding. Our design leverages the combination of various query methods across different dimensions to enable a wide array of search modes. The state chain is used in the scheme to guarantee forward privacy, while backward privacy is ensured through the encryption of the index. Our scheme employs a bitmap index of the same length to represent multiple file addresses that match a keyword, ensuring size consistency in search results, also known as volume hiding. Multiset hash function is used to construct the verifiable search result. The security of the scheme is analyzed using a simulation-based proof method based on leakage functions. Xingwen Zhao, Hui Li 0006, Kai Fan 0001 |
IEEE Internet Things J. | 2 |
| 2024 | Privacy-Preserving Spatial Keyword Search With Lightweight Access Control in Cloud EnvironmentsabstractAs cloud computing continues to gain popularity, various applications have been deployed under Industrial Internet of Things (IIoT) scenarios. In order to alleviate the heavy burden of local storage and processing, a substantial amount of data is entrusted to the cloud server (CS), but attendant security risks like privacy leakages begin to appear. In addition, another vital security issue, access control, has come to attention. Many existing spatial keyword similarity search schemes are unable to implement access control. To solve these issues, we propose a novel scheme privacy-preserving spatial keyword similarity search with lightweight access control (PSKSSA) scheme. Specifically, we design an efficient access control IR-tree (ACIR-tree) that achieves sublinear query efficiency. Access control is implemented through role-based polynomial technology, which is integrated into the ACIR-tree and the query vector, so that spatial keywords and access control information are uniformly encoded into a vector. Meanwhile, privacy is protected by enhanced asymmetric scalar-product-preserving encryption (EASPE), which guarantees indistinguishability against the chosen-plaintext attack (IND-CPA) model. The most similar$k$results are found by the CS while implementing access control for data users. Through formal analysis and extensive experiments, it has proved that the proposed scheme is safe and effective, with good scalability. Xingwen Zhao, Luhui Gan, Kai Fan 0001 |
IEEE Internet Things J. | 1 |
| 2024 | Automatic Evasion of Machine Learning-Based Network Intrusion Detection SystemsabstractNetwork intrusion detection systems (IDS) are often considered effective to thwart cyber attacks. Currently, state-of-the-art (SOTA) IDSs are mainly based on machine learning (ML) including deep learning (DL) models, which suffer from their own security issues, especially evasion attacks by using adversarial examples. However, previous studies mostly focus on extracted features rather than the traffic sample itself, and/or assume that the adversary knows the information of the target model more or less, which severely restricts attack feasibility in practice. In this paper, we re-investigate this problem in a more realistic label-only black-box scenario and propose a practical evasion attack strategy to solve the above limitations. In this newly considered case that the adversary morphs the traffic sample and only obtains the results accepted or rejected without other knowledge, we successfully leverage the model extraction and transfer attack to evade the detection. The entire attack strategy is automated and a comprehensive evaluation is performed. Final results show that the proposed strategy effectively evades seven typical ML-based IDSs and one SOTA DL-based IDS with an average success rate of over$75\%$. We also discuss the corresponding countermeasures against our attack, which finally highlight the need for effective defenses against our attack. Haonan Yan, Wenjing Zhang 0002, Hui Li 0006, Xingwen Zhao, Fenghua Li 0001, Xiaodong Lin 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2022 | MARS: Automated Protocol Analysis Framework for Internet of ThingsabstractInternet of Things (IoT) devices generate a massive quantity of network traffic every moment, which undoubtedly poses an urgent demand for an accurate and efficient network protocol analysis tool in cyberspace management and security. However, the existing popular methods have limitations, such as incomplete functionality and insufficient accuracy. For example, the large number of novel network applications brings unprecedented protocols for protocol analysis, which greatly limit the analysis capabilities of existing tools. In this article, we devise an automated protocol analysis framework for IoT devices calledMARSto solve these problems. To the best of our knowledge, this is the first unified framework including all three analysis stages: 1) classifying protocol; 2) analyzing the protocol phase; and 3) parsing the protocol field. At each stage, we provide effective solutions to solve the corresponding tasks and improve the efficiency of protocol analysis.MARScan also deal with unknown protocols that are common in IoT scenarios but are rarely concerned by previous works. Finally, we develop a distributed computing engine to ensure the high throughput and processing speed of the whole framework for the huge amount of network traffic. The evaluation on a variety of different protocols shows the superiority of ourMARSover previous works in terms of comprehensiveness and accuracy. Haonan Yan, Hui Li 0006, Xingwen Zhao, Fenghua Li 0001 |
IEEE Internet Things J. | 5 |
| 2022 | Blockchain-assisted searchable attribute-based encryption for e-health systems
Xinyin Xiang, Xingwen Zhao |
J. Syst. Archit. | 2 |
| 2019 | PGSM-DPI: Precisely Guided Signature Matching of Deep Packet Inspection for Traffic AnalysisabstractIn the field of network traffic analysis, Deep Packet Inspection (DPI) technology is widely used at present. However, the increase in network traffic has brought tremendous processing pressure on the DPI. Consequently, detection speed has become the bottleneck of the entire application. In order to speed up the traffic detection of DPI, a lot of research works have been applied to improve signature matching algorithms, which is the most influential factor in DPI performance. In this paper, we present a novel method from a different angle called Precisely Guided Signature Matching (PGSM). Instead of matching packets with signature directly, we use supervised learning to automate the rules of specific protocol in PGSM. By testing the performance of a packet in the rules, the target packet could be decided when and which signatures should be matched with. Thus, the PGSM method reduces the number of aimless matches which are useless and numerous. After proposing PGSM, we build a framework called PGSM-DPI to verify the effectiveness of guidance rules. The PGSM-DPI framework consists of PGSM method and open source DPI library. The framework is running on a distributed platform with better throughput and computational performance. Finally, the experimental results demonstrate that our PGSM-DPI can reduce 59.23% original DPI time and increase 21.31% throughput. Besides, all source codes and experimental results can be accessed on our GitHub. Haonan Yan, Hui Li 0006, Mingchi Xiao, Xianchun Zheng, Xingwen Zhao, Fenghua Li 0001 |
GLOBECOM | 6 |
| 2016 | Efficient multi-party concurrent signature from lattices
Xinyin Xiang, Hui Li 0006, Xingwen Zhao |
Inf. Process. Lett. | 4 |
| 2014 | Achieving dynamic privileges in secure data sharing on cloud storageabstractABSTRACT With the rapid development of cloud computing, more and more enterprises will outsource their sensitive data for sharing in a cloud. Many data sharing and access control schemes have been submitted. However, dynamic privileges among user groups were not considered. In many circumstances, some users may have higher privileges than others, and they can decrypt more contents than those with low privileges. Moreover, the data owner may want to dynamically control the privileges in data sharing. In this paper, we present an efficient framework for data sharing system to achieve dynamic privileges, basing on chameleon hash function and one‐way function. With this framework, any data sharing and access control scheme can be turned into a dynamic privileged scheme, in which the data owner can change the group of each user dynamically and change the structure of privileges flexibly when it is needed. The proposed framework requires much less storage than previous schemes in handling dynamic privileges among the users. Copyright © 2013 John Wiley & Sons, Ltd. Xingwen Zhao, Hui Li 0006 |
Secur. Commun. Networks | 1 |
| 2012 | Codes Based Tracing and Revoking Scheme with Constant Ciphertext
Xingwen Zhao, Hui Li 0006 |
ProvSec | 1 |
| 2012 | Tracing and revoking scheme for dynamic privileges against pirate rebroadcast
Xingwen Zhao, Fangguo Zhang |
Comput. Secur. | 1 |
| 2012 | Fully CCA2 secure identity-based broadcast encryption with black-box accountable authority
Xingwen Zhao, Fangguo Zhang |
J. Syst. Softw. | 1 |
| 2011 | Traitor Tracing against Public Collaboration
Xingwen Zhao, Fangguo Zhang |
ISPEC | 1 |
| 2011 | Dynamic asymmetric group key agreement for ad hoc networks
Xingwen Zhao, Fangguo Zhang, Haibo Tian |
Ad Hoc Networks | 1 |