Ying Gao 0006

dblp:15/1300-6 · DBLP profile ↗
← Back
22ranked-venue papers
8as first author
20since 2021 · last 2026
0000-0001-8992-651XORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 6 first-author · 11 since 2021Computer networks · 4 · 4 since 2021Theory of computation · 3 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Controllable encrypted data sharing scheme with key update for blockchain-assisted IoT
Ying Gao 0006
Comput. Networks2
2026 GPU-accelerated Batch Private Information Retrieval with lower communication overheads
abstract
Abstract Private Information Retrieval (PIR) is a critical component in many privacy-preserving systems, and Batch PIR schemes constructed by Probabilistic Batch Code have garnered widespread attention in both academia and industry due to their relatively low average computational cost. However, existing Batch PIR still face challenges in balancing computational and communication efficiency, while some also exhibit poor adaptability to databases of large entries. In this paper, building upon the state-of-the-art Batch PIR schemes, we employ two approaches to enhance their overall performance. To reduce the communication cost of Batch PIR, we propose a novel Oblivious Ciphertext Decompression scheme $$\textsf{GCTObvDecomperss}$$ GCTObvDecomperss based on the 3-Hash Garbled Cuckoo Table algorithm. We use the hypergraph peeling algorithm to construct this scheme and give a formal security definition and proof of this scheme to ensure it is computationally oblivious. In the implementation, our scheme reduces the additional communication cost in Batch PIR by 27% while achieving a 7.9 $$\times$$ × improvement in efficiency compared to existing solutions. Moreover, to enhance computational performance, we analyze the computational bottleneck of Spiral PIR and optimize it using GPU technology, achieving a 267 $$\times$$ × speedup in the first-dimensional processing phase compared to serial execution, and reducing the total computation cost by 3.9 $$\times$$ × . Furthermore, we conduct comprehensive evaluations of our Batch PIR protocol, demonstrating its superior performance in both computational efficiency and communication overhead, as well as its capability to support efficient retrieval in databases of large entries. Finally, we use our Batch PIR in an anonymous messaging protocol Pung, and evaluate the performance of this real-world application. By using our Batch PIR, the latency can be reduced by 18.8% when the number of records reached $$2^{18}$$ 2 18 compared to the original protocol, indicating that our construction can provide a more effective and practical method in related scenarios.
Ying Gao 0006
Cybersecur.1
2026 Privacy-Preserving and Puncturable Bilateral Access Control From Lattices for Cloud-Assisted IoV
abstract
Cloud-assisted Internet of Vehicles (IoV) enables real-time data collection and processing through vehicle–cloud collaboration, thereby improving traffic scheduling efficiency and safety. However, ensuring data privacy and verifying data authenticity remain major challenges in such systems. Although existing primitives such as matchmaking encryption (ME) provide partial protection, they still lack quantum resistance and forward security for historical data. To address this limitation, we propose a lattice-based puncturable identity-based match-making encryption (PIB-ME) scheme, and design a revocable data sharing system with bilateral access control (RDSS-BAC) tailored for cloud-assisted IoV. We formalize the definition and security model of PIB-ME and prove its security under the RLWE assumption. The proposed PIB-ME enables bilateral access control between communicating vehicles, supports key puncturing for flexible revocation, and achieves post-quantum security. Security analysis demonstrates that, in addition to privacy and authenticity, the scheme resists tampering, collusion, and quantum attacks. Finally, theoretical complexity analysis and experimental evaluation confirm the efficiency and practicality of our scheme in cloud-assisted IoV scenarios.
Ying Gao 0006, Jie Chen 0021
IEEE Internet Things J.2
2026 When Specifications Meet Reality: Uncovering API Inconsistencies in Ethereum Infrastructure
abstract
The Ethereum ecosystem, which secures over $381 billion in assets, fundamentally relies on client APIs as the sole interface between users and the blockchain. However, these critical APIs suffer from widespread implementation inconsistencies, which can lead to financial discrepancies, degraded user experiences, and threats to network reliability. Despite this criticality, existing testing approaches remain manual and incomplete: they require extensive domain expertise, struggle to keep pace with Ethereum’s rapid evolution, and fail to distinguish genuine bugs from acceptable implementation variations. We present APIDiffer , the first specification-guided differential testing framework designed to automatically detect API inconsistencies across Ethereum’s diverse client ecosystem. APIDiffer transforms API specifications into comprehensive test suites through two key innovations: (1) specification-guided test input generation that creates both syntactically valid and invalid requests enriched with real-time blockchain data, and (2) specification-aware false positive filtering that leverages large language models to distinguish genuine bugs from acceptable variations. Our evaluation across all 11 major Ethereum clients reveals the pervasiveness of API bugs in production systems. APIDiffer uncovered 72 bugs, with 90.28% already confirmed or fixed by developers, including one critical error in the official specifications themselves. Beyond these raw numbers, APIDiffer achieves up to 89.67% higher code coverage than existing tools and reduces false positive rates by 37.38%. The Ethereum community’s response validates our impact: developers have integrated our test cases, expressed interest in adopting our methodology, and escalated one bug to the official Ethereum Project Management meeting. By making APIDiffer open-source, we enable continuous validation of Ethereum client API implementations, thereby strengthening the foundational integrity of the entire Ethereum ecosystem.
Ningyu He, Jinwen Xi, Mingzhe Xing, Liangxin Liu, Jiushenzi Luo, Xiaopeng Fu, Chiachih Wu, Haoyu Wang 0001, Ying Gao 0006, Yinliang Yue
Proc. ACM Program. Lang.10
2026 Matchmaking encryption for NC1 circuits without obfuscation
Ying Gao 0006, Jie Chen 0021, Yu Li 0011
Theor. Comput. Sci.1
2026 CVFL-Pro: A Collusion-Resistant Verification Federated Learning Framework With Adaptive Communication Optimization
Ying Gao 0006, Xiaofeng Chen 0001, Huanghao Deng, Yuxin Xie 0002, Jie Chen 0021
IEEE Trans. Inf. Forensics Secur.1
2025 Gradient Inversion Attack in Federated Learning: Exposing Text Data through Discrete Optimization
abstract
Federated learning has emerged as a potential solution to overcome the bottleneck posed by the near exhaustion of public text data in training large language models. There are claims that the strategy of exchanging gradients allows using text data including private information. Although recent studies demonstrate that data can be reconstructed from gradients, the threat for text data seems relatively small due to its sensitivity to even a few token errors. However, we propose a novel attack method FET, indicating that it is possible to Fully Expose Text data from gradients. Unlike previous methods that optimize continuous embedding vectors, we directly search for a text sequence with gradients that match the known gradients. First, we infer the total number of tokens and the unique tokens in the target text data from the gradients of the embedding layer. Then we develop a discrete optimization algorithm, which globally explores the solution space and precisely refines the obtained solution, incorporating both global and local search strategies. We also find that gradients of the fully connected layer are dominant, providing sufficient guidance for the optimization process. Our experiments show a significant improvement in attack performance, with an average increase of 39% for TinyBERT-6, 20% for BERT-base and 15% for BERT-large in exact match rates across three datasets. These findings highlight serious privacy risks in text data, suggesting that using smaller models is not an effective privacy-preserving strategy.
Ying Gao 0006, Yuxin Xie 0002, Huanghao Deng, Zukun Zhu
COLING1
2025 Upper bounds of differential branch number of n-bit permutations
abstract
Abstract The differential branch number is a key parameter used to measure the diffusion ability of a permutation. It is of great significance to study the upper bound of the differential branch number of permutations. This paper analyses the existence problem of binary codes with a specified dimension and minimum distance using combinatorial inequality. The result obtained is used to estimate the differential branch number of permutations on $${\mathbb{G}\mathbb{F}(2)}^n$$ G F ( 2 ) n associated with those codes, and this paper finally finds two upper bounds, one of which is the tightest upper bound currently known. Furthermore, inspired by the comparison between two specific bounds mentioned above, the asymptotic upper bound of the differential branch number is studied. The conclusion quantitatively illustrates the relation between the upper bound and the range of n. It is shown that when n is sufficiently large, the differential branch number of n-bit permutations has an asymptotic upper bound of 0.44012n. This is also the most accurate upper bound that can be proved using the scheme presented in this paper.
Ying Gao 0006
Cybersecur.1
2025 Efficient Forward and Backward Private Conjunctive Searchable Encryption With Comprehensive Verification
abstract
Dynamic searchable symmetric encryption (DSSE) enables the retrieval and update of massive encrypted data and is thus widely applied in cloud storage. Malicious cloud servers may tamper with outsourced data or return incorrect search results, making verification indispensable. However, current verifiable conjunctive DSSE with forward and backward privacy cannot simultaneously achieve accurate search and empty result verification. Given the above problems, we propose a novel forward and backward private conjunctive DSSE with comprehensive verification called VCFB. VCFB introduces the notion of random blinding factors and secure dynamic cross-tags to achieve accurate conjunctive search with sublinear overhead. We design the search state and construct chain structures to ensure forward security. The new verification algorithm based on bilinear-map dynamic accumulators can guarantee the verifiability of search results even if an empty result is returned. We use a sample check method to verify the new dynamic cross-tags, reducing computation costs. We precisely define the leakage function of VCFB and give detailed security proof, demonstrating that VCFB is forward and backward private under the malicious server model. Experimental results show that VCFB ensures efficient and accurate conjunctive search, outperforming the similar verifiable conjunctive DSSE scheme regarding indexing storage and update performance.
Yue Ge, Ying Gao 0006, JianKai Qiu
IEEE Trans. Big Data2
2025 Peafowl: Private Entity Alignment in Multi-Party Privacy-Preserving Machine Learning
abstract
In privacy-preserving machine learning with vertically distributed data, private entity alignment methods are used to securely match and utilize features of the same samples. However, existing methods not only risk exposing sample intersections and introducing unnecessary samples but also face a gap in adapting to multi-party scenarios. To address these limitations, we propose Peafowl, a novel multi-party private entity alignment protocol. Peafowlachieves entity alignment among multiple parties through a mapping from original datasets to intersections, termed permutation. This method mitigates intersection disclosure and sample redundancy concerns by avoiding direct use of the intersection. The proposed protocol leverages a cloud server that utilizes secret-shared shuffle to protect the privacy of the permutation, in case of colluding data providers reconstructing intersections. Further, by integrating a seed homomorphic pseudorandom generator, Peafowlavoids the intensive communication of secret sharing and achieves superior runtime performance. Additionally, an offline/online variant is introduced to ensure a linear growth in communication and computation complexity relative to the dataset size by pre-computing permutation calculations. Implemented on a real PPML framework, the protocol demonstrates practical efficiency in various multi-party settings. Experimental results indicate that Peafowl’s overhead is less than 1% of the total training cost, while the offline/online variant achieves approximately a 50% reduction in online runtime. Overall, Peafowloffers an efficient and straightforward solution for multi-party PPML, making it an attractive option for implementation and future improvements.
Ying Gao 0006, Huanghao Deng, Zukun Zhu, Xiaofeng Chen 0001, Yuxin Xie 0002, Pei Duan, Peixuan Chen
IEEE Trans. Inf. Forensics Secur.1
2024 Efficient Fuzzy Private Set Intersection from Fuzzy Mapping
Ying Gao 0006, Yuanchao Luo, Longxin Wang
ASIACRYPT (6)1
2024 Efficient Scalable Multi-Party Private Set Intersection(-Variants) from Bicentric Zero-Sharing
abstract
Multi-party private set intersection (MPSI) allows 𝑛(𝑛 ≥ 3) participants, each holding a dataset of size 𝑚, to compute the intersection of their sets without revealing any additional information.We extract a primitive called bicentric zero-sharing, which can reduce MPSI to two-party PSI between two central participants named Pivot and Leader.We introduce an efficient instantiation of bicentric zero-sharing, which involves a round of sharing and reconstruction of an oblivious key-value store (OKVS) object.We then combine this construction with two-party PSI to propose a new efficient scalable MPSI protocol.We also propose protocols for computing MPSI variants based on bicentric zero-sharing, such as multi-party private set intersection cardinality (MPSI-CA) and multi-party threshold private set intersection (MTPSI).Our protocols are mainly based on symmetric-key operations, and the communication complexity of each participant is at most O (𝑛 + 𝑚).The security of our protocols relies on the assumption * The first two authors contribute equally.
Ying Gao 0006, Yuanchao Luo, Longxin Wang, Wei Wang 0420, Mengmeng Zhou
CCS1
2024 On prefer-one sequences
Yupeng Jiang 0001, Ming Li 0033, Ying Gao 0006, Dongdai Lin
Des. Codes Cryptogr.3
2024 AIFL: Ensuring Unlinkable Anonymity and Robust Incentive in Cross-Device Federated Learning
abstract
While cross-device federated learning (FL) offers a privacy-preserving data processing approach for Internet of Things (IoT) devices, it introduces fresh privacy risks and elevated computational expenses. Current solutions prioritize data privacy, often overlooking identity privacy vulnerabilities that may lead to personal information disclosure. In addition, achieving personalized client incentives while protecting identity privacy is a serious challenge. In this article, we propose AIFL, an unlinkable anonymity and robust incentive mechanism in cross-device FL. We design a threshold-based accountable ring signature (TARS) protocol that achieves unlinkable anonymity between identity and model updates and ensures accuracy and cost-effectiveness. AIFL identifies dishonest clients by incorporating a detection mechanism that leverages entropy weighting and cosine similarity for malicious update identification. Moreover, our robust incentive mechanism, grounded in the Stackelberg game, adopts differential pricing strategies that take into account clients’ anonymity budgets, ensuring equitable rewards. Performance evaluation reveals that AIFL achieves superior accuracy and robustness compared to Krum, even under 50% Byzantine attackers. Specifically, AIFL outperforms Krum by 0.32%, 29.1%, 79.17%, and 11.86% on MNIST, CIFAR-10, CIFAR-100, and Tiny-ImageNet data sets in nonindependent identically distributed, respectively. Additionally, AIFL effectively imposes costly penalties on dishonest clients and enhances the overall utility for honest clients. Consequently, the proposed AIFL holds significant implications for promoting secure and trustworthy machine learning in the IoT domain.
Xiaofeng Chen 0001, Ying Gao 0006, Huanghao Deng
IEEE Internet Things J.2
2024 Verifiable Multilevel Dynamic Searchable Encryption With Forward and Backward Privacy in Cloud-Assisted IoT
abstract
The Internet of Things (IoT) boom has enabled massive data collection in cloud servers. Therefore, access efficiency and data privacy in cloud storage services have become a significant concern. Data and users are hierarchical in IoT applications, which require fine-grained multilevel access control. Additionally, achieving public verification to resist the malicious server and clients is indispensable. Aiming at the challenge above, we propose a new forward private multilevel dynamic searchable symmetric encryption (MLDSSE) scheme called Peony, employing multilevel linked lists and constrained pseudorandom function, which is more efficient and secure. Then, we introduce a cryptographic primitive named multilevel symmetric revocable encryption (MSRE), and we give a general method for constructing a novel forward and Type-II backward-private MLDSSE scheme Peony++ based on MSRE. Further, we design the multilevel digests and utilize the smart contract as a trusted platform to support public verification for Peony++. Theoretical analysis and experimental evaluations show that Peony achieves higher security and reduces search time by an average of 35.81% compared to the state-of-the-art MLDSSE scheme. To the best of our knowledge, Peony++ is the only multilevel searchable encryption currently available that can achieve forward and Type-II backward privacy, all while balancing efficiency and functionality.
Yue Ge, Ying Gao 0006, Jianting Ning, Xiaofeng Chen 0001
IEEE Internet Things J.2
2024 GMS: an efficient fully homomorphic encryption scheme for secure outsourced matrix multiplication
Ying Gao 0006
J. Supercomput.2
2023 Improved Fully Adaptive Decentralized MA-ABE for NC1 from MDDH
Jie Chen 0021, Qiaohan Chu, Ying Gao 0006, Jianting Ning, Luping Wang 0001
ASIACRYPT (5)3
2023 Scalable Multi-party Private Set Union from Multi-query Secret-Shared Private Membership Test
Ying Gao 0006
ASIACRYPT (1)2
2022 Efficient Private Set Intersection Cardinality Protocol in the Reverse Unbalanced Setting
Ying Gao 0006
ISC2
2022 CDEdit: Redactable Blockchain with Cross-audit and Diversity Editing
abstract
Redactable blockchain allows modifiers or voting committees with modification privileges to edit the data on the chain. Among them, trapdoor holders in chameleon-based hash redactable blockchains can quickly compute hash collisions for arbitrary data without breaking the link of the hash-chain. However, chameleon-based hash redactable blockchain schemes have difficulty solving issues such as editing operations with different granularity or conflicts and auditing modifiers that abuse editing privileges. To address the above challenges, we propose a redactable blockchain with Cross-audit and Diversity Editing (CDEdit). The proposed scheme distributes subdivided transaction-level and block-level tokens to the matching modifier committee to weaken the influence of central power. A number of modifiers are unpredictably selected based on reputation value proportions and the mapping of the consistent hash ring to enable diversity editing operations, and resist Sybil attacks. Meanwhile, an adaptive cross-auditing protocol is proposed to adjust the roles of modifiers and auditors dynamically. This protocol imposes a reputation penalty on the modifiers of illegal edits and solves the problems of abuse of editing privileges and collusion attacks. In addition, We used ciphertext policy attribute-based encryption (CP-ABE) and chameleon hashes with ephemeral trapdoor (CHET) for data modification, and present a system steps and security analysis of CDEdit. Finally, the extensive comparisons and evaluations show that our scheme costs less time overhead than other schemes and is suitable for complex application scenarios, e.g. IoT data management.
Xiaofeng Chen 0001, Ying Gao 0006
TrustCom2
2013 Five Families of Three-Weight Ternary Cyclic Codes and Their Duals
abstract
As a subclass of linear codes, cyclic codes have applications in consumer electronics, data storage systems, and communication systems as they have efficient encoding and decoding algorithms. In this paper, five families of three-weight ternary cyclic codes whose duals have two zeros are presented. The weight distributions of the five families of cyclic codes are settled. The duals of two families of the cyclic codes are optimal.
Cunsheng Ding, Ying Gao 0006, Zhengchun Zhou
IEEE Trans. Inf. Theory2
2004 Codes over algebraic integer rings of cyclotomic fields
abstract
Regarding any finite field as a residue field of the algebraic integer ring of a cyclotomic field, we select a system of representatives in the ring with minimal Manhattan metric, and introduce a Mannheim weight on the finite field. The linear codes over the finite field with the Mannheim weight are discussed. A geometric method to compute the representatives in Gaussian integers is provided.
Yun Fan, Ying Gao 0006
IEEE Trans. Inf. Theory2