EDBT 2026 Demo / reviewers in the wild / expert
Yan Wu 0014
dblp:04/3001-14
· DBLP profile ↗
7ranked-venue papers
2as first author
5since 2021 · last 2026
0000-0003-4441-7230ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 3 · 1 first-author · 2 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Unveiling Ethereum Mixing Services Using Enhanced Graph Structure LearningabstractAs cryptocurrency prices continue to recover, crypto crimes such as money laundering are becoming increasingly rampant. Mixing services such as Tornado Cash have become the primary tools for obfuscating illegal financial transactions due to their inherent anonymity mechanisms. Tornado Cash is a non-custodial, smart contract-based mixing service (SC-CMS) that breaks the direct mapping between deposit and withdrawal accounts, hindering regulators from tracking illicit fund flows. Existing deanonymization methods for Tornado Cash suffer from several challenges, including vague theoretical concepts, evolving mixing mechanisms, and insufficient labeled samples. To address these concerns, this paper proposes the first formal concept of SC-CMS to facilitate and evaluate the deanonymization efforts systematically. We design a novel linkability attack, LASC, based on enhanced graph structure learning, to associate mixing accounts on Tornado Cash and mathematically prove its feasibility. Comprehensive experiments on real Ethereum transactions demonstrate that LASC outperforms state-of-the-art works in both performance and efficiency. Yan Wu 0014, Cong Wu 0003, Yebo Feng, Jiahang Sun, Zijian Zhang 0001, Jincheng An, Zhitao Guan, Liehuang Zhu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Resisting Poisoning Attacks in Federated Learning via Dual-Domain Distance and Trust AssessmentabstractSubsequently, by executing various attacks on benchmark datasets such as MNIST, we construct Federated Learning Malicious Parameter Identification (FLMPID) dataset to enable malicious client detection. Building on this dataset, we propose FORTRESS (Federated POisoning-Resistance Defense via Dual-Domain Distance and TRust AssESSment), a framework designed to detect and mitigate malicious updates from clients. FORTRESS employs a unique encoder-decoder architecture. The encoder utilizes dual-domain distance metrics on weights and gradients to extract hidden representations, while the decoder leverages Actor-Critic (AC) reinforcement learning for trust assessment. We evaluated FORTRESS under multiple attack scenarios and demonstrated its defense effectiveness, making it a promising solution for enhancing the security of FL systems. Zijian Zhang 0001, Yan Wu 0014, Ye Liu 0012, Meng Li 0006, Xin Li 0033, Jincheng An, Wei Liang 0005, Liehuang Zhu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | PrSeFL: Achieving Practical Privacy and Robustness in Blockchain-Based Federated LearningabstractWith the help of artificial intelligence, the large amount of data generated by Internet of Things (IoT) has unleashed significant value. Federated learning is emerging as a novel paradigm which can be applied to solve the privacy issues caused by analyzing IoT data. However, traditional federated learning protocols are vulnerable to inference and poisoning attacks. Various solutions have been proposed to enhance data privacy and robustness. Nonetheless, most of these solutions are usually centralized and rely on unrealistic security assumptions. Furthermore, the recently proposed blockchain-based decentralized solutions generally incur high costs, which is unaffordable for resource-constrained IoT devices. In this article, we propose a practical secure federated learning system named PrSeFL. We utilize blockchain to decentralize the federated learning process so that the security assumptions are easier to achieve in practice. To preserve data privacy, we implement secure multiparty computation-based secure aggregation in blockchain environment. To guarantee practical robustness, we enforce norm constraints on the masked updates via zero-knowledge proof. Moreover, we propose a modified dynamic accumulator which is utilized to realize lightweight anonymous authentication of users. Simulation results show that, compared with state-of-the-art systems, PrSeFL has superior performance on authentication and model training. And the advantage of PrSeFL becomes more significant as the number of users grows. Lei Xu 0016, Yan Wu 0014, Jiahang Sun, Liehuang Zhu |
IEEE Internet Things J. | 3 |
| 2023 | Privacy-Preserving and Traceable Blockchain-Based Charging Payment Scheme for Electric VehiclesabstractWith the rapid development of the global clean energy industry, the electric vehicle (EV) has gradually replaced the traditional fuel vehicle as a promising modern transportation tool due to its environmental friendliness and competitive prices. Its widespread adoption has led to a substantial increase in demand for subsidiary facilities, such as charging piles and stations. Despite the convenience and accessibility offered by charging services, the privacy of EV users may be compromised in the process, as malicious attackers can infer their true identities and consumption habits from service orders. Existing studies introduce blockchain technology into vehicle charging payment scenarios to protect the privacy of EV users. Unfortunately, it cannot achieve the desired full anonymity and may even hinder electricity regulators’ investigation of suspicious transactions and entities. Therefore, designing a vehicle charging payment scheme that simultaneously supports privacy protection and traceability is a challenge. To address these concerns, this article proposes a privacy-preserving and traceable blockchain-based charging payment (PTB-CP) scheme for EVs. It can protect users’ identity privacy and transaction unlinkability and track abnormal transactions or entities in exceptional circumstances. We conduct a comprehensive analysis of PTB-CP from both theoretical and experimental aspects. The analysis results demonstrate that our scheme can realize privacy protection, reliability and authentication, traceability, scalability, and high efficiency. Yan Wu 0014, Can Zhang 0002, Liehuang Zhu |
IEEE Internet Things J. | 1 |
| 2021 | Comment on "Achieving Secure, Universal, and Fine-Grained Query Results Verification for Secure Search Scheme Over Encrypted Cloud Data"abstractRecently in IEEE Transactions on Cloud Computing (TCC), Yinet al.[5]designed a fine-grained query verification mechanism where a novel certificateless short signature scheme is proposed for validating the data of encrypted query results. Despite the authors alleged that their scheme achieves the existential unforgeability to ensure the authenticity of verification objects, we found that this scheme fails to resist the forgery attack. Specifically, through launching the concrete attacks, a malicious adversary can forge a signature on any verification object without being detected. Zhiguang Qin, Yan Wu 0014, Hu Xiong |
IEEE Trans. Cloud Comput. | 2 |
| 2020 | Efficient and Privacy-Preserving Authentication Protocol for Heterogeneous Systems in IIoTabstractThe Industrial Internet of Things (IIoT) is expected to provide a promising opportunity to revolutionize the production operation of the existing industrial systems by leveraging smart devices. Due to the untrusted nature of communication channels, ensuring data authenticity is a critical challenge. Besides, devices' privacy and communication heterogeneity raise crucial concerns about the IIoT applications since the existing authentication protocols for the IIoT environment face the potential threats of privacy leakage and cannot achieve secure communication between heterogeneous industrial systems. To address these challenges, this article proposes an efficient privacy-preserving authentication protocol for heterogeneous systems in IIoT using proxy resignature. The presented protocol not only provides heterogeneous communication between ID-based and certificateless-based cryptosystems but also achieves various security requirements. The security of our protocol has been proven based on the extended Computational Diffie-Hellman (eCDH) assumption in the random oracle model. The experimental simulation demonstrates that our protocol is feasible for the IIoT-based environment. Hu Xiong, Yan Wu 0014, Chuanjie Jin, Saru Kumari |
IEEE Internet Things J. | 2 |
| 2020 | A secure and efficient certificateless batch verification scheme with invalid signature identification for the internet of things
Hu Xiong, Yan Wu 0014, Chunhua Su, Kuo-Hui Yeh |
J. Inf. Secur. Appl. | 2 |