Dianhua Tang

dblp:140/7793 · DBLP profile ↗
← Back
12ranked-venue papers
1as first author
12since 2021 · last 2026
0000-0002-3169-4928ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 1 first-author · 7 since 2021Systems, architecture and hardware · 4 · 4 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Hidden Facial Verification Scheme in IoT Cloud Environment Based on Homomorphic Privacy Information Retrieval
abstract
With the popularization of face recognition technology in IoT-Cloud, the problem of privacy leakage caused by it is becoming more and more serious. Although traditional privacy protection schemes can improve security to a certain extent, there is still a risk of data leakage when facing semi-trusted cloud servers. To this end, this paper proposes an anonymized face verification scheme for IoT convergence scenarios, which achieves real-time retrieval and secure matching of dense face features in virtual device copies by combining homomorphic encryption (CKKS) and privacy information retrieval (PIR) for anonymized face verification. The scheme ensures that the semi-trusted cloud server cannot obtain user-specific index information and matching results. Experiments show that the scheme’s verification accuracy in the ciphertext state on the LFW dataset is consistent with the plaintext, up to 97.06%, and can complete a privacy-protected anonymized facial verification process within seconds. The scheme is feasible in security demanding scenarios.
Xu An Wang 0014, Wei Zhao 0054, Weiwei Jiang 0003, Lingling Wu, Haibo Lei, Zhiquan Liu 0001, Dianhua Tang
IEEE Internet Things J.8
2026 FastPaD: A Fast Privacy-Preserving Password Similarity Leakage Detection Protocol for IoT Services
abstract
In the digital age of the Internet of Things, users rely extensively on online accounts to access a variety of IoT services and applications. However, password leakage significantly threatens users’ privacy, assets, and reputations, making passwords primary targets for cyberattacks, including credential-guessing attacks. To address this vulnerability, this paper proposes FastPaD, a Fast privacy-preserving protocol designed to detect password similarity leakage using homomorphic encryption. FastPaD employs a novelhorizontal homomorphic batch encoding method, facilitating efficient batch detection of similar passwords. The protocol also incorporates optimization strategies such aspolynomial partitioning and power computation windowing, significantly reducing the depth of homomorphic multiplications. This enables the use of smaller encryption parameters, which improves computational efficiency. Moreover, FastPaD features a customizable mechanism to balance functionality and performance, effectively optimizing the trade-off between communication and computational overhead. Experimental results demonstrate that in scenarios without similarity detection, FastPaD achieves a detection computation time of 0.17 seconds and a total communication overhead of 3.88 MB, surpassing state-of-the-art protocols. When similarity detection is enabled, FastPaD completes the detection process in 6.45 seconds with a communication overhead of 10.64 MB. Compared to the Pipa protocol, FastPaD provides approximately a 2.70× improvement in computation time and a 22.27× improvement in communication efficiency. Relative to Yu’s protocol, FastPaD demonstrates a 15.78× faster computation and a 1.31× reduction in communication overhead.
Dianhua Tang, Hongwei Li 0001, Xinyuan Qian 0002, Xiaopeng Yu 0003, Shuailing Zhang, Guowen Xu
IEEE Internet Things J.1
2025 Secure credential monitor for safeguarding passenger accounts in smart rail systems
Dianhua Tang
J. Supercomput.2
2024 Benchmark GELU in Secure Multi-Party Computation
abstract
Recently, several technology companies have released online inference services for clients based on Transformer-based large language models, which show excellent performance in various tasks. However, in these services, the inputs usually involve clients’ sensitive information. To address this problem, many works have proposed secure inference on language models such as GPT. For language models, complex mathematical functions like Gaussian Error Linear Unit (GELU) are used extensively and dominate the main cost of secure inference. In this work, we systematically study the existing secure GELU protocols and classify previous methods into two categories: polynomial-based protocols and lookup table (LUT)-based protocols. We point out several important characteristics and tradeoffs for these two classes of secure GELU protocols. Based on these observations and analysis, we propose a new secure GELU protocol, called Simple. The main technique that Simple uses involves a LUT of small size to retrieve approximate polynomials for fitting residual error functions caused by a crude approximation for GELU, which achieves state-of-the-art (SOTA) overhead and accuracy performance. We conduct extensive experiments and benchmark the previous 6 secure GELU protocols. The experimental comparison shows that our Simple protocol achieves 1.1 ∼ 8784.3× computation and 1.4 ∼ 188.8× communication improvements while reducing 1.2∼80.2× errors.
Rui Zhang 0090, Hongwei Li 0001, Meng Hao 0001, Hanxiao Chen 0001, Yuan Zhang 0006, Dianhua Tang
GLOBECOM7
2024 Verifiable Privacy-Preserving Federated Learning Under Multiple Encrypted Keys
abstract
Federated learning is a distributed learning helpful approach for resolving data privacy concerns and eliminating data silos. Homomorphic encryption is a vital technology for preserving user privacy in federated learning, and current studies are mainly concentrated on a single-key environment. However, if one user key is exposed in a single-key environment, it implies that the whole system key has been revealed. To strengthen security, we should allow different participants of federated learning to choose different keys to encrypt their local models. The cloud server should finish model aggregation calculation on ciphertexts under different public keys. Besides, research in this area is insufficient to guarantee mobile users’ data integrity verification and authentication in open channels. Therefore, this article proposes a privacy protection federated learning scheme VPFL based on the BCP cryptosystem, which can verify user identity and data integrity in a multikey environment. First, this scheme employs the BCP cryptosystem with double trapdoors for data encryption and transmission, enhancing the user’s privacy security. Second, a method for verifying user data integrity and identity was created utilizing bilinear aggregate signatures and verifiable secret sharing. It can effectively eliminate some incorrect data of some users. Third, VPFL tolerates users dropping out during training while still guaranteeing high accuracy. Finally, theoretical analysis and experimental evaluation indicate that the proposed scheme is efficient and secure.
Xiaoying Shen, Baocang Wang, Yange Chen, Dianhua Tang
IEEE Internet Things J.6
2024 A Small-Size FHE Scheme for Better Privacy Protection of IoT
abstract
Fully homomorphic encryption (FHE) fundamentally solves the problems of confidentiality when data and operations are entrusted to third parties. It can play an important role in secure data computation for Internet of Things (IoT). However, the storage complexities of existing FHE schemes are still not friendly. Our work focuses on optimizing the storage complexity of FHE, in order to further promote the practical process of FHE in IoT. The FHE schemes based on learning with errors (LWE) have become the mainstream of FHE schemes due to its simplicity, security, and ease of efficient implementation. The key switching technology is the ingenious and crucial technique that led to LWE-based FHE. By proposing a low-noise key switching technology, and using Bin-LWE assumption twice (first on the public key, and then again on the ciphertext), we design a leveled FHE scheme with small parameters (without expensive bootstrapping technology). Meanwhile, a detailed analysis of noise growth for homomorphic evaluation is made, and the specific security parameters are given.
Wenzheng Zhang 0001, Dianhua Tang
IEEE Internet Things J.3
2023 Research on privacy information retrieval model based on hybrid homomorphic encryption
abstract
Abstract The computational complexity of privacy information retrieval protocols is often linearly related to database size. When the database size is large, the efficiency of privacy information retrieval protocols is relatively low. This paper designs an effective privacy information retrieval model based on hybrid fully homomorphic encryption. The assignment method is cleverly used to replace a large number of homomorphic encryption operations. At the same time, the multiplicative homomorphic encryption scheme is first used to deal with the large-scale serialization in the search, and then the fully homomorphic encryption scheme is used to deal with the remaining simple operations. The depth of operations supported by the fully homomorphic scheme no longer depends on the size of the database, but only needs to support the single homomorphic encryption scheme to decrypt the circuit depth. Based on this hybrid homomorphic encryption retrieval model, the efficiency of homomorphic privacy information retrieval model can be greatly improved.
Dianhua Tang
Cybersecur.4
2023 Privacy-preserving multi-party deep learning based on homomorphic proxy re-encryption
Xiaoying Shen, Baocang Wang, Yange Chen, Dianhua Tang
J. Syst. Archit.6
2023 Peer-to-peer privacy-preserving vertical federated learning without trusted third-party coordinator
Jie Feng 0004, Haomiao Yang, Dianhua Tang
Peer Peer Netw. Appl.5
2022 PIPC: Privacy- and Integrity-Preserving Clustering Analysis for Load Profiling in Smart Grids
abstract
Generally, power utilities can utilize smart-meter data to extract load patterns through load-profiling technologies, such as$K$-means clustering. To improve the efficiency of load profiling, both$K$-means clustering and smart-meter data can be outsourced to powerful clouds. However, clouds are not completely trustworthy: private meter data may be used for commercial interests;$K$-means clustering may also be performed with fewer iterations to save computational costs, which violates the integrity of outsourced clustering. In this article, therefore, a secure$K$-means-clustering scheme is proposed, called privacy-preserving and integrity-preserving clustering (PIPC), which aims to protect the privacy and integrity of load profiling. To this end, two techniques are designed: 1) encrypted distance measurement, in which a public comparison matrix is constructed by securely embedding a secret key matrix and 2) integrity assurance, in which a specific Stackelberg game is designed to create economic incentives. The former, as the core of$K$-means clustering, can protect the privacy of meter data. The latter ensures that clouds can obtain the maximum utility only when clouds execute$K$-means clustering in an honest manner, thereby preserving the integrity of outsourced computing. Experimental results demonstrate that PIPC reaches high clustering accuracy and computational efficiency for load profiling while retaining smart-meter data privacy and outsourced-clustering integrity.
Haomiao Yang, Shaopeng Liang, Xizhao Luo, Dianhua Tang, Hongwei Li 0001, Xuemin Shen
IEEE Internet Things J.4
2022 Efficient and provably secure multi-receiver signcryption scheme using implicit certificate in edge computing
abstract
Edge computing is an emerging computing paradigm, which extends the functions of cloud center to the edge of the networks, and brings great convenience to solving problems of delay and bandwidth in the traditional cloud computing paradigm. In edge computing architecture, one-to-many communication is a important communication mode that supports the edge nodes to send one message to multiple terminal devices in one broadcast report. To build a secure one-to-many communication, several multi-receiver signcryption (MRSC) schemes have been brought forward to ensure the security of broadcast messages. However, the existing MRSC schemes need the heavy computation and communication cost, and is not suitable for IoT terminal devices with limited resources. Besides, most of the existing MRSC schemes are vulnerable to the security and privacy leakage, and fail in achieving the decryption fairness. To solve these problems, based on the implicit certificate (IC) cryptosystem and polynomial interpolation evaluation, this paper proposes an provably secure multi-receiver IC-based signcryption (MRICSC) scheme for one-to-many communication in edge computing. The security analysis evidences the proposed MRICSC scheme can ensure the security. With the experimental results indicating that the proposed MRICSC scheme achieves the better performance than existing schemes.
Dianhua Tang
J. Syst. Archit.3
2021 A public key encryption scheme based on a new variant of LWE with small cipher size
Dianhua Tang, Haomiao Yang, Fagen Li
J. Syst. Archit.2