EDBT 2026 Demo / reviewers in the wild / expert
Yuzhe Li 0001
dblp:140/0764-1
· DBLP profile ↗
7ranked-venue papers
4as first author
5since 2021 · last 2025
0000-0003-1720-4985ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 5 since 2021Systems, architecture and hardware · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | RevokAll: Hardware-Assisted Revocable Data Sharing Framework for Full Data Traffic With Rapid Deployment in Cloud-EdgeabstractSecure cloud-edge data sharing has been researched recently to provide high quality on-demand data service. Attribute-based encryption (ABE) is a promising solution that achieves data confidentiality and flexible access control simultaneously. But three major issues remain when adapting ABE in cloud-edge, namely reliable user revocation, high performance on devices, and trust issues of public cloud. First, existing direct user revocation mechanisms focus on preventing a revoked user from decrypting header ciphertexts even when key exposure occurs, but ignore the payload security. Second, how to conveniently apply deployment on diverse platforms and run programs on resource-constrained devices with high efficiency is a challenge. Finally, no universal guarantee of cloud computation and management tasks, thus lazy or malicious cloud may not follow the protocol and perform improper actions on purpose. In this work, we propose a Hardware-Assisted Hybrid Fully Outsourced Revocable Attribute-Based Proxy Re-Encryption (H²O-RABPRE) scheme that supports reliable user revocation for full data traffic and hardware-assisted fully outsourced computation. Moreover, we design a hardware-assisted data-sharing framework with rapid deployment for cloud-edge, which integrates the developed SGX-MCL to protect outsourced tasks executed by cloud/edge devices against malicious behaviors and utilizes the enhanced WebAssembly runtime, WasmCrypto, a unified deployment approach for IoT devices with near-native performance. We implement the scheme on an SGX cloud server, a laptop, a Raspberry Pi, and an ESP32 board, and the results indicate that the proposed scheme is practical. Shuaishuai Chang, Hui Ma 0002, Jianting Ning, Yuzhe Li 0001, Bo Li 0063, Weiping Wang 0005 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | T-ABE: A practical ABE scheme to provide trustworthy key hosting on untrustworthy cloudabstractAttribute-based encryption (ABE) is a highly promising mechanism for secure fine-grained access control over encrypted data, particularly in cloud storage applications. However, the integration of built-in key escrow and susceptibility to key exfiltration poses a prevalent challenge during the implementation of ABE. In this paper, we present a novel ABE scheme called T-ABE to address the above challenges. Specifically, T-ABE utilizes a Trusted Execution Environment (i.e. Intel SGX) to provide a precise security guarantee for the entire process, from establishing trust between users and ABE services to key generation and management, ensuring that the entire scheme can provide users with secure and reliable ABE key hosting services even when deployed in untrustworthy cloud service providers. Through comprehensive security analysis and experimental demonstration, we have demonstrated the advantages of T-ABE in practical applications. We are confident that this new scheme has the potential to effectively tackle the outsourced key escrow challenges encountered by ABE. Shuaishuai Chang, Yuzhe Li 0001, Jinchao Zhang 0002, Bo Li 0063 |
TrustCom | 2 |
| 2023 | Towards practical differential privacy in data analysis: Understanding the effect of epsilon on utility in private ERM
Yuzhe Li 0001, Yong Liu 0018, Bo Li 0063, Weiping Wang 0005, Nan Liu 0011 |
Comput. Secur. | 1 |
| 2022 | An Efficient Epsilon Selection Method for DP-ERM with Expected Accuracy ConstraintsabstractNowadays, the leakage of personal information and privacy becomes a major concern in various fields, such as social sciences, genomics, and medicine. To combat this problem, differential privacy has been proposed and soon be widely studied and applied. Meanwhile, the compositional nature of differential privacy has motivated the design and implementation of differentially private machine learning mechanisms. However, as these mechanisms are gradually deployed in practice, a serious problem appears: they find it hard to choose a meaningful ε value or understand the meaning of a chosen ε value in practice. To this end, we propose a novel and efficient approach that would allow users to choose ε according to their utility or accuracy requirement. Specifically, we can efficiently obtain the expected ε value that would generate a private model satisfying the expected empirical loss or expected accuracy, through at least one-round training and some calculations. As product requirements often impose hard accuracy constraints, our approach allows users to focus on their own benefits without paying too much attention to things they don’t understand or care. Both theoretical analysis and experimental results demonstrate high accuracy and broad applicability of our mechanism in practical applications. Yuzhe Li 0001, Bo Li 0063, Weiping Wang 0005, Nan Liu 0011 |
TrustCom | 1 |
| 2021 | Just Keep Your Concerns Private: Guaranteeing Heterogeneous Privacy and Achieving High Availability for ERM AlgorithmsabstractTraditional implementations of differential privacy implicitly assume that users have homogeneous privacy requirement for all attributes of data. They provide a uniform level of privacy guarantee for all attributes by using a single privacy budget,$\varepsilon$. However, this brings trouble to users in practice applications, where privacy requirements are often heterogeneous. In this case, users have to make a choice: either setting the privacy level high enough to satisfy even the privacy fundamentalists, which often results in poor model utility, or sacrificing the privacy of some attributes for practical model. Both are hard to be accepted by users. In this paper, we offer users what they probably want, an option that could provide a satisfactory privacy guarantee for important attributes with minimal utility loss. Our method, called heterogeneous differentially private ERM (HDP-ERM), allows the private learning algorithms to guarantee heterogeneous privacy for each attribute of training data. The noise injected in each parameter is adaptive according to its individual privacy budget, so that we can control the privacy-utility trade-off more finely. Experimental results show that our method is able to reach a satisfactory utility when only the important attributes need strong privacy guarantee, while the traditional DP-ERM would only get a useless model (one with low test accuracy) when providing the same level of privacy guarantee. Yuzhe Li 0001, Yong Liu 0018, Bo Li 0063, Weiping Wang 0005, Nan Liu 0011 |
TrustCom | 1 |
| 2019 | RE-Store: Reliable and Efficient KV-Store with Erasure Coding and ReplicationabstractIn-memory key/value stores (KV-stores) are a key building block for numerous applications running on a cluster. As cluster scales have grown, efficiency and availability have become increasingly critical characteristics. Traditional replication provides redundancy, but is inefficient due to its high storage overhead. Erasure coding can provide data reliability with significantly lower storage requirements, but is primarily used for long-term archival data due to the limitation of its write performance. Recent studies have attempted to combine these two techniques by using replication for frequently-updated metadata, and erasure coding for large, read-only data. In this study, we propose RE-Store, an in-memory key/value store system which utilizes a novel hybrid replication/erasure coding scheme to achieve both efficiency and reliability. RE-Store introduces replication into erasure coding by making one copy of each encoded datum and replacing partial parity with replicas for improved storage-efficiency. When failures occur, it uses these replicas to ensure data availability and thus avoids the inefficiencies of erasure coding during repair. RE-Store provides fault tolerance through fast, online recovery during different failure scenarios with little performance degradation. We have implemented RE-Store on a real key/value system and conducted extensive evaluations to validate its design and to study its performance, efficiency, and reliability. Experimental results show that RE-Store performs similarly to erasure coding and replication under normal operations while saving 18% to 34% of the memory used by replication when tolerating 2 to 4 failures. Yuzhe Li 0001, Weiping Wang 0005, Yong Chen 0001 |
CLUSTER | 1 |
| 2017 | Building an Efficient Put-Intensive Key-Value Store with Skip-TreeabstractMulti-component based Log-Structured Merge-tree (LSM-tree) has been becoming one of the mainstream indexes. LSM-tree adopts component-by-component KV item flowing down mechanism to push each KV item from one smaller component to the adjacent larger component during compaction procedures until the KV items reach the largest component. This process incurs significant write amplification and limits the write throughput. In this paper, we propose one multi-component Skip-tree to aggressively push the KV items to the non-adjacent larger components via skipping some components and then make the KV items' top-down move more efficient. We develop adaptive and reliable KV item movements among components. By reducing the number of steps during the flowing process from memory-resident component to the disk-resident largest component, Skip-tree can effectively reduce the write amplification and thus improve the system throughput. We design and implement one high performance key-value store, named SkipStore, based on Skip-tree. The experiments demonstrate that SkipStore outperforms the state-of-the-art open-sourced system RocksDB in Facebook by 66.5 percent under HDD and 61 percent under SSD. Yinliang Yue, Bingsheng He, Yuzhe Li 0001, Weiping Wang 0005 |
IEEE Trans. Parallel Distributed Syst. | 3 |