EDBT 2026 Demo / reviewers in the wild / expert
Yongzhi Wang 0001
dblp:09/8502-1
· DBLP profile ↗
24ranked-venue papers
15as first author
7since 2021 · last 2025
0000-0002-7117-4097ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 7 · 3 first-author · 1 since 2021Security and privacy · 6 · 4 first-author · 2 since 2021Computer networks · 5 · 3 first-author · 1 since 2021Systems, architecture and hardware · 4 · 4 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Location Privacy Preservation Crowdsensing With Federated Reinforcement LearningabstractCrowdsensing has become a popular method of sensing data collection while facing the problem of protecting participants' location privacy. Existing location-privacy crowdsensing mechanisms focus on static tasks and participants without considering sensing tasks' time requirements and participants' mobility, which cannot achieve satisfactory collected data quality and task completion in crowdsensing with dynamic tasks and participants. Inspired by this, we proposed a location-preservation crowdsensing mechanism, FedSense, considering dynamic tasks and participants based on federated learning (FL) and reinforcement learning (RL). In FedSense, through RL's outstanding decision-making ability, participants select sensing tasks to perform by well-trained RL models without uploading location information to servers for task allocation. We propose an independent tasks selection environment that defines actions, states, and rewards of RL to enable FedSense to achieve satisfactory task completion and data quality while preserving location privacy. Besides, FedSense applies an asynchronous FL aggregation algorithm that reduces participants' network stabilization and device computing ability requirements. Analysis proves that participants' location information does not leave the local device during the model training and task selection process, effectively avoiding privacy leakage. Simulation shows that compared with existing location-preservation crowdsensing mechanisms, FedSense achieves the highest task completion and sensing accuracy for dynamic tasks and participants. Zhichao You, Xuewen Dong, Ximeng Liu, Sheng Gao 0002, Yongzhi Wang 0001, Yulong Shen 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Towards Protecting On-Device Machine Learning with RISC-V based Multi-Enclave TEEabstractOn-device machine learning is a trending paradigm that empowers the artificial intelligence of various smart devices, including IoT, mobile, and robotics, etc. On the other hand, this emerging paradigm has brought new security challenges that traditional system security techniques cannot harness. In this paper, we explored the possibility of using multi-enclave Trusted Execution Environments to address these security challenges. We first identified the challenges and threats that on-device machine learning systems are facing. Then, we presented our experimental results of using RISC-V-based multi-enclave TEE to secure on-device machine learning system, demonstrating a promising performance advantage. Finally, we discussed the technical directions for the threats that cannot be completely addressed by the TEE. Yongzhi Wang 0001, Venkata Sai Ramya Padmasri Boggaram |
ICCCN | 1 |
| 2024 | Sort-then-insert: A space efficient and oblivious model aggregation algorithm for top-k sparsification in federated learning
Yongzhi Wang 0001, Pengfei Gui, Mehdi Sookhak |
Future Gener. Comput. Syst. | 1 |
| 2022 | EdGENI: Making GENI User-Friendly for General Computer EducationabstractGENI (Global Environment for Network Innovations) has been used in network research and education for more than a decade. However, because GENI lacks Graphic User Interface (GUI) and customized VM images, very few institutions utilize virtual machines (VM) deployed on GENI for generalized computer education. Additionally, connecting VMs on GENI requires complex configuration, which is time-consuming and error-prone. In this paper, we introduce EdGENI, an educational experiment solution built on top of GENI. EdGENI introduces a desktop environment to the GENI VM and allows users to save, duplicate, and share VM environments with other users. Furthermore, EdGENI also introduces a client application, PuTTY Connect, to simplify the process of making VM connections. These features improve the user experience and extend the user base of GENI, thus delivering a generalized experiment platform for computer education. We also developed a series of labs in EdGENI, covering topics of cybersecurity and blockchain. These labs are suitable for a wide range of students, from entry-level students who are unfamiliar with command-line interface to advanced students who are interested in sophisticated network attacks and preventions. The paper also provides an empirical support on the potential of EdGENI in helping students learning and developing skills in the cybersecurity field. Yongzhi Wang 0001, Wen-Jung Hsin, Manish Lamsal |
SIGCSE (1) | 1 |
| 2022 | CFHider: Protecting Control Flow Confidentiality With Intel SGXabstractProgram control flow reflects the algorithm of that program and may reveal implementation vulnerabilities. Thus its confidentiality needs to be protected, especially in a cloud setting. However, most existing control flow obfuscation methods are software-based, which cannot offer high confidentiality while maintaining low performance overhead. In this paper, we propose CFHider, a hardware-assisted solution. By performing program transformation and leveraging Trusted Execution Environments (Intel SGX), CFHider moves branch statement conditions to an opaque and trusted memory space during the program execution. We proved that by generating Obfuscation Invariants, CFHider is able to provide provable control flow confidentiality protection. Based on the design of CFHider, we also developed a prototype system for Java applications. Our security analysis and experimental results indicate that CFHider is effective in protecting control flow confidentiality and incurs a much reduced performance overhead than existing software-based solutions (by a factor of 18.1). Yongzhi Wang 0001, Yulong Shen 0001, Yao Liu 0007 |
IEEE Trans. Computers | 1 |
| 2022 | Enhancing Leakage Prevention for MapReduceabstractWhen public clouds become the platform of choice for MapReduce processing, users are placing higher demands on the privacy of the job data and program. A number of solutions employed trusted hardware to protect MapReduce tasks. However, existing works pointed out that simply protecting individual nodes in the MapReduce cluster with trusted hardware and protecting cross-node communication with encryption still leak information from side-channels. Specifically, attackers can derive data information by observing and manipulating cross-node communication traffic volumes. Although existing works proposed some solutions to prevent such leakage, in this paper, we show that previous solutions still leak critical job information. Additionally, our study shows that previous solutions have limitations from other aspects, including data restriction, partition function restriction, reliability issue, and high overheads. To address all the discovered limitations, we introduced the Strong Shuffle solution. Our analysis and experimental results showed that our solution has reduced the information leakage and addressed other discovered limitations. To support Strong Shuffle, we proposed a variant Bloom Filter, named Group-based Dynamic Bloom Filter (GDBF). Our theoretical analysis showed that GDBF has lower performance and storage overhead than the traditional Scalable Bloom Filter. Yongzhi Wang 0001, Yulong Shen 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2021 | Secure $k$k-NN Query on Encrypted Cloud Data with Multiple KeysabstractThe k-nearest neighbors (k-NN) query is a fundamental primitive in spatial and multimedia databases. It has extensive applications in location-based services, classification & clustering and so on. With the promise of confidentiality and privacy, massive data are increasingly outsourced to cloud in the encrypted form for enjoying the advantages of cloud computing (e.g., reduce storage and query processing costs). Recently, many schemes have been proposed to support k-NN query on encrypted cloud data. However, prior works have all assumed that the query users (QUs) are fully-trusted and know the key of the data owner (DO), which is used to encrypt and decrypt outsourced data. The assumptions are unrealistic in many situations, since many users are neither trusted nor knowing the key. In this paper, we propose a novel scheme for secure k-NN query on encrypted cloud data with multiple keys, in which the DO and each QU all hold their own different keys, and do not share them with each other; meanwhile, the DO encrypts and decrypts outsourced data using the key of his own. Our scheme is constructed by a distributed two trapdoors public-key cryptosystem (DT-PKC) and a set of protocols of secure two-party computation, which not only preserves the data confidentiality and query privacy but also supports the offline data owner. Our extensive theoretical and experimental evaluations demonstrate the effectiveness of our scheme in terms of security and performance. Ke Cheng 0001, Liangmin Wang 0001, Yulong Shen 0001, Hua Wang 0002, Yongzhi Wang 0001, Xiaohong Jiang 0001, Hong Zhong 0001 |
IEEE Trans. Big Data | 5 |
| 2020 | A Lightweight Auction Framework for Spectrum Allocation with Strong Security GuaranteesabstractAuction is an effective mechanism to distribute spectrum resources. Although many privacy-preserving auction schemes for spectrum allocation have been proposed, none of them is able to perform practical spectrum auctions while ensuring enough security for bidders' private information, such as geo-locations, bid values, and data access patterns. To address this problem, we propose SLISA, a lightweight auction framework which enables an efficient spectrum allocation without revealing anything but the auction outcome, i.e., the winning bidders and their clearing prices. We present contributions on two fronts. First, as a foundation of our design, we adopt a Shuffle-then-Compute strategy to build a series of secure sub-protocols based on lightweight cryptographic primitives (e.g., additive secret sharing and basic garbled circuits). Second, we improve an advanced spectrum auction mechanism to make it data-oblivious, such that data access patterns can be hidden. Meanwhile, the modified protocols adapt to our elaborate building blocks without affecting its validity and security. We formally prove the security of all protocols under a semi-honest adversary model, and demonstrate performance improvements compared with state-of-the-art works through extensive experiments. Ke Cheng 0001, Liangmin Wang 0001, Yulong Shen 0001, Yongzhi Wang 0001, Lele Zheng |
INFOCOM | 5 |
| 2020 | A secured TPM integration scheme towards smart embedded system based collaboration network
Di Lu 0001, Ruidong Han, Yue Wang 0063, Yongzhi Wang 0001, Xuewen Dong, XinDi Ma, Teng Li 0003, Jianfeng Ma 0001 |
Comput. Secur. | 4 |
| 2020 | CryptSQLite: SQLite With High Data SecurityabstractSQLite, one of the most popular light-weighted database system, has been widely used in various systems. However, the compact design of SQLite did not make enough consideration on user data security. Specifically, anyone who has obtained the access to the database file will be able to read or tamper the data. Existing encryption-based solutions can only protect data on storage, while still exposing data when in computation. In this article, we combine the Trusted Execution Environment(TEE) technology and the authenticated encryption scheme, proposed and developed the CryptSQLite, a high security SQLite database system, which protects both the confidentiality and integrity of users' data. Our security analysis proves that CryptSQLite can protect data confidentiality and integrity. Our implementation and experiments indicate that CryptSQLite incurs an average of 21 percent of extra time for SQL statement executions, compared with traditional encryption-based solutions that failed to offer rigorous security guarantees. Yongzhi Wang 0001, Yulong Shen 0001, Cuicui Su, Jiawen Ma, Lingtong Liu, Xuewen Dong |
IEEE Trans. Computers | 1 |
| 2020 | Editorial: Special issue on security and privacy in network computing
Hua Wang 0002, Yongzhi Wang 0001, Tarek Taleb, Xiaohong Jiang 0001 |
World Wide Web | 2 |
| 2019 | Strongly Secure and Efficient Range Queries in Cloud Databases under Multiple KeysabstractCloud database provides an advantageous platform for outsourcing of database service. To protect data confidentiality from an untrusted cloud, the original database is often encrypted and then uploaded to the cloud. However, in order to support functional queries, existing secure databases require users to encrypt their data under the same public/symmetric key, which restricts the usage scenarios since users do not really trust each other in practice. Imagine a scenario where a user uploaded his/her own encrypted data to the cloud database and another user wants to execute private range queries on this data. This scenario occurs in many cases of collaborative statistical analysis where the data provider and analyst are different entities. Then either the data provider must reveal its encryption key or the analyst must reveal the private queries. In this paper, we overcome this restriction for secure range queries by enabling query executions on the multi-key encryption data. We propose a secure cloud database supporting range queries under multiple keys, in which all users could preserve the confidentiality of their own different keys, and do not have to share them with each other. At a higher level, our system is constructed on a two-cloud architecture and a novel distributed two-trapdoor public key cryptosystem. We prove that the proposed scheme achieves the goal of a secure query without leaking data privacy, query privacy, and data access patterns. Finally, we use extensive experiments over a real-world dataset on a commercial cloud platform to verify the efficacy of our proposed scheme. Ke Cheng 0001, Yulong Shen 0001, Yongzhi Wang 0001, Liangmin Wang 0001, Jianfeng Ma 0001, Xionghong Jiang, Cuicui Su |
INFOCOM | 3 |
| 2019 | CFHider: Control Flow Obfuscation with Intel SGXabstractWhen a program is executed on an untrusted cloud, the confidentiality of the program's logics needs to be protected. Control flow obfuscation is a direct approach to obtain this goal. However, existing methods in this direction cannot achieve both high confidentiality and low overhead. In this paper, we propose CFHider, a hardware-assisted method to protect the control flow confidentiality. By combining program transformation and Intel Software Guard Extension (SGX) technology, CFHider moves branch statement conditions to an opaque and trusted memory space, i.e., the enclave, thereby offering a guaranteed control flow confidentiality. Based on the design of CFHider, we developed a prototype system targeting on Java applications. Our analysis and experimental results indicate that CFHider is effective in protecting the control flow confidentiality and incurs a much reduced performance overhead than existing software-based solutions (by a factor of 8.8). Yongzhi Wang 0001, Yulong Shen 0001, Cuicui Su, Ke Cheng 0001, Anter Faree, Yao Liu 0007 |
INFOCOM | 1 |
| 2018 | MtMR: Ensuring MapReduce Computation Integrity with Merkle Tree-Based VerificationsabstractBig data applications have made significant impacts in recent years thanks to the fast growth of cloud computing and big data infrastructures. However, public cloud is still not widely accepted to perform big data computing, due to the concern with the public cloud's security. Result integrity is one of the most significant security problems that exists in the cloud-based big data computing scenario. In this paper, we propose MtMR, a Merkle tree-based verification method that assures high result integrity of MapReduce jobs. MtMR overlays MapReduce on a hybrid cloud environment and applies two rounds of Merkle tree-based verifications on the prereduce phase (i.e., the map phase and the shuffle phase) and the reduce phase, respectively. In each round, MtMR samples a small portion of reduce task input/output records on the private cloud and performs Merkle tree-based verification on all the task input/output records. Based on the design of MtMR, we perform a series of theoretical studies to analyze its security and performance overhead. Our results indicate that MtMR is a promising method in terms of high result integrity and low performance overhead. For example, by setting the sampled record ratio as an optimal value, MtMR can guarantee no more than 10 incorrect records in each reduce task by sampling only 4 percent of records in that task. Yongzhi Wang 0001, Yulong Shen 0001, Hua Wang 0002, Jinli Cao, Xiaohong Jiang 0001 |
IEEE Trans. Big Data | 1 |
| 2018 | Practical Verifiable Computation-A MapReduce Case StudyabstractPublic cloud vendors have been offering a variety of big data computing services on their clouds. However, runtime integrity is one of the major security concerns that hinder the wide adoption of those services. In this paper, we focus on MapReduce, a popular big data computing framework, and propose the runtime integrity audition (RIA), a solution that remotely verifies the runtime integrity of MapReduce applications. RIA records the runtime variable values of the MapReduce application on the public cloud and checks those values against the application's code on the private cloud. By doing so, RIA protects the runtime integrity of MapReduce applications. Based on the idea of RIA, we developed a prototype system, called MR Auditor, and tested its applicability and performance with several Hadoop applications. Our experimental results showed that MR Auditor is a general tool that can efficiently audit the runtime integrity of all the MapReduce applications that we tested. In addition, MR Auditor incurs a moderate performance overhead. For example, when verifying the Word Count application, a proper parameter setting of MR Auditor incurs 1% of extra execution time on the public cloud and 14% of extra execution time on the private cloud. Yongzhi Wang 0001, Yulong Shen 0001, Xiaohong Jiang 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2018 | Trustworthy service composition with secure data transmission in sensor networks
Tao Zhang 0029, Lele Zheng, Yongzhi Wang 0001, Yulong Shen 0001, Ning Xi 0002, Jianfeng Ma 0001, Jianming Yong |
World Wide Web | 3 |
| 2017 | Exploiting Content Delivery Networks for covert channel communications
Yongzhi Wang 0001, Yulong Shen 0001, Xiaopeng Jiao, Tao Zhang 0029, Xu Si, Ahmed Salem 0003, Jia Liu 0009 |
Comput. Commun. | 1 |
| 2016 | POSTER: RIA: an Audition-based Method to Protect the Runtime Integrity of MapReduce ApplicationsabstractPublic cloud vendors have been offering varies big data computing services. However, runtime integrity is one of the major concerns that hinders the adoption of those services. In this paper, we focus on MapReduce, a popular big data computing framework, propose the runtime integrity audition (RIA), a solution to verify the runtime integrity of MapReduce applications. Based on the idea of RIA, we developed a prototype system, called MR Auditor, and tested its applicability and the performance with multiple Hadoop applications. Our experimental results showed that MR Auditor is an efficient tool to detect runtime integrity violation and incurs a moderate performance overhead. Yongzhi Wang 0001, Yulong Shen 0001 |
CCS | 1 |
| 2016 | Toward integrity assurance of outsourced computing - a game theoretic perspective
Yongzhi Wang 0001, Jinpeng Wei, Shaolei Ren, Yulong Shen 0001 |
Future Gener. Comput. Syst. | 1 |
| 2015 | Toward protecting control flow confidentiality in cloud-based computation
Yongzhi Wang 0001, Jinpeng Wei |
Comput. Secur. | 1 |
| 2014 | Exploring Cloud Service Brokering from an Interface PerspectiveabstractService brokering has an increasingly prominent role in bridging the gap between business requirement and technology enablement. We propose the concept of service value brokering (SVB) to fulfil the possible missing linkages between business and technology layer. In this paper, we modeled a SVB Web service as an integration of two layers with the business interface (BIF) and the technical interface (TIF). With this distinction, Web service compositions can map to two layers of compositions at both BIF and TIF levels. We notice that any partial consideration on the consistency of either BIF or TIF layers would likely leave mismatching situations on the other layer. We employ SVB to solve these mismatching situations. With the help of SVB, we address the needs of coherent business planning and IT implementation in a model drivenmanner. Finally, we illustrate the feasibility of our approach in the development of a modern cloud-based tourism e-commerce platform. Yucong Duan, Nanjangud C. Narendra, Wencai Du, Yongzhi Wang 0001, Nianjun Zhou |
ICWS | 4 |
| 2013 | Result Integrity Check for MapReduce Computation on Hybrid CloudsabstractLarge scale adoption of MapReduce computations on public clouds is hindered by the lack of trust on the participating virtual machines, because misbehaving worker nodes can compromise the integrity of the computation result. In this paper, we propose a novel MapReduce framework, Cross Cloud MapReduce (CCMR), which overlays the MapReduce computation on top of a hybrid cloud: the master that is in control of the entire computation and guarantees result integrity runs on a private and trusted cloud, while normal workers run on a public cloud. In order to achieve high accuracy, CCMR proposes a result integrity check scheme on both the map phase and the reduce phase, which combines random task replication, random task verification, and credit accumulation, and CCMR strives to reduce the overhead by reducing cross-cloud communication. We implement our approach based on Apache Hadoop MapReduce and evaluate our implementation on Amazon EC2. Both theoretical and experimental analysis show that our approach can guarantee high result integrity in a normal cloud environment while incurring non-negligible performance overhead (e.g., when 16.7% workers are malicious, CCMR can guarantee at least 99.52% of accuracy with 33.6% of overhead when replication probability is 0.3 and the credit threshold is 50). Yongzhi Wang 0001, Jinpeng Wei, Mudhakar Srivatsa |
IEEE CLOUD | 1 |
| 2013 | Constructing E-Tourism platform based on service value broker: A knowledge management perspectiveabstractIn our previous work, we have introduced various service value broker (SVB) patterns which integrate business modeling, knowledge management and economic analysis. In this paper, working towards the target of maximizing the potential usage of available resource to achieve the optimization of the satisfaction on both the service provider side and the service consumer side under the guidance of the public administrative, we propose to build the E-Tourism platform based on SVB. This paper demonstrates the mechanism for SVB based E-Tourism framework. The advantages of employing SVB include that the SVB can help to increase the value added in a realtime and balanced manner which conforms to the economical goal of both long run and short run. An experiment is shown using a personnel recommendation system. Yucong Duan, Yongzhi Wang 0001, Jinpeng Wei, Ajay Kattepur, Wencai Du |
IEEE BigData | 2 |
| 2013 | IntegrityMR: Integrity assurance framework for big data analytics and management applicationsabstractBig data analytics and knowledge management is becoming a hot topic with the emerging techniques of cloud computing and big data computing model such as MapReduce. However, large-scale adoption of MapReduce applications on public clouds is hindered by the lack of trust on the participating virtual machines deployed on the public cloud. In this paper, we extend the existing hybrid cloud MapReduce architecture to multiple public clouds. Based on such architecture, we propose IntegrityMR, an integrity assurance framework for big data analytics and management applications. We explore the result integrity check techniques at two alternative software layers: the MapReduce task layer and the applications layer. We design and implement the system at both layers based on Apache Hadoop MapReduce and Pig Latin, and perform a series of experiments with popular big data analytics and management applications such as Apache Mahout and Pig on commercial public clouds (Amazon EC2 and Microsoft Azure) and local cluster environment. The experimental result of the task layer approach shows high integrity (98% with a credit threshold of 5) with non-negligible performance overhead (18% to 82% extra running time compared to original MapReduce). The experimental result of the application layer approach shows better performance compared with the task layer approach (less than 35% of extra running time compared with the original MapReduce). Yongzhi Wang 0001, Jinpeng Wei, Mudhakar Srivatsa, Yucong Duan, Wencai Du |
IEEE BigData | 1 |