EDBT 2026 Demo / reviewers in the wild / expert
Hung Dang
dblp:15/4165
· DBLP profile ↗
13ranked-venue papers
9as first author
2since 2021 · last 2026
0009-0008-7009-2509ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 5 first-author · 2 since 2021Software engineering, systems software and programming languages · 2Databases, data management, data science and information retrieval · 2 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 2 first-authorArtificial intelligence and machine learning · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Effectiveness of Distillation Attack and Countermeasure on Neural Network Watermarking
Hung Dang, Ee-Chien Chang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | TEEKAP: Self-Expiring Data Capsule using Trusted Execution EnvironmentabstractSafeguarding privacy in data sharing is challenging, especially when data owners lose control over their data once it is passed to another party. Our work aims to build a data-sharing platform that enables data owners to regain control over their shared data. Specifically, sensitive data is first encapsulated into a data capsule. The platform regulates functional access to the data capsule, i.e., the receiver can compute a predefined function on the data with its input and learns nothing else. The platform also enforces self-expiry of the data capsule. In addition, the data capsule features a notion of “send-and-forget” wherein data owners can go offline after releasing their data capsules. As a result, data capsules can be freely circulated. Mingyuan Gao, Hung Dang, Ee-Chien Chang |
ACSAC | 2 |
| 2019 | Towards a Marketplace for Secure Outsourced Computations
Hung Dang, Dat Le Tien, Ee-Chien Chang |
ESORICS (1) | 1 |
| 2019 | Towards Scaling Blockchain Systems via ShardingabstractExisting blockchain systems scale poorly because of their distributed consensus protocols. Current attempts at improving blockchain scalability are limited to cryptocurrency. Scaling blockchain systems under general workloads (i.e., non-cryptocurrency applications) remains an open question. This work takes a principled approach to apply sharding to blockchain systems in order to improve their transaction throughput at scale. This is challenging, however, due to the fundamental difference in failure models between databases and blockchain. To achieve our goal, we first enhance the performance of Byzantine consensus protocols, improving individual shards' throughput. Next, we design an efficient shard formation protocol that securely assigns nodes into shards. We rely on trusted hardware, namely Intel SGX, to achieve high performance for both consensus and shard formation protocol. Third, we design a general distributed transaction protocol that ensures safety and liveness even when transaction coordinators are malicious. Finally, we conduct an extensive evaluation of our design both on a local cluster and on Google Cloud Platform. The results show that our consensus and shard formation protocols outperform state-of-the-art solutions at scale. More importantly, our sharded blockchain reaches a high throughput that can handle Visa-level workloads, and is the largest ever reported in a realistic environment. Hung Dang, Tien Tuan Anh Dinh, Dumitrel Loghin, Ee-Chien Chang, Qian Lin 0002, Beng Chin Ooi |
SIGMOD Conference | 1 |
| 2017 | Privacy-Preserving Data Deduplication on Trusted ProcessorsabstractCloud storage providers can reduce storage costs by detecting identical files and storing only one instance of them. While appealing to the storage providers, this deduplication set-up raises various privacy concerns among clients. Various techniques to retrofit content confidentiality in deduplication have been studied in the literature. Nevertheless, data encryption alone is insufficient to protect users' privacy, for the ownership and equality information of the outsourced data left unprotected may have serious privacy implications. In this paper, we investigate a three-tier architecture that saves bandwidth otherwise incurred by server-side deduplication solutions, yet does not admit the client-side deduplication's leakage on file existence. Leveraging trusted SGX-enabled processors, we construct the first privacy-preserving data deduplication protocol that protects not only the confidentiality, but also the ownership and equality information of the outsourced data, offering better privacy guarantees in comparison with existing works on secure data deduplication. Our experiments show that the proposed protocol incurs low performance overhead over conventional solutions that provide weaker level of privacy protection. Hung Dang, Ee-Chien Chang |
CLOUD | 1 |
| 2017 | Evading Classifiers by Morphing in the DarkabstractLearning-based systems have been shown to be vulnerable to evasion through adversarial data manipulation. These attacks have been studied under assumptions that the adversary has certain knowledge of either the target model internals, its training dataset or at least classification scores it assigns to input samples. In this paper, we investigate a much more constrained and realistic attack scenario wherein the target classifier is minimally exposed to the adversary, revealing only its final classification decision (e.g., reject or accept an input sample). Moreover, the adversary can only manipulate malicious samples using a blackbox morpher. That is, the adversary has to evade the targeted classifier by morphing malicious samples "in the dark". We present a scoring mechanism that can assign a real-value score which reflects evasion progress to each sample based on the limited information available. Leveraging on such scoring mechanism, we propose an evasion method -- EvadeHC? and evaluate it against two PDF malware detectors, namely PDFRate and Hidost. The experimental evaluation demonstrates that the proposed evasion attacks are effective, attaining 100% evasion rate on the evaluation dataset. Interestingly, EvadeHC outperforms the known classifier evasion techniques that operate based on classification scores output by the classifiers. Although our evaluations are conducted on PDF malware classifiers, the proposed approaches are domain agnostic and are of wider application to other learning-based systems. Hung Dang, Ee-Chien Chang |
CCS | 1 |
| 2017 | Proofs of Data Residency: Checking whether Your Cloud Files Have Been RelocatedabstractWhile cloud storage services offer manifold benefits such as cost-effectiveness or elasticity, there also exist various security and privacy concerns. Among such concerns, we pay our primary attention to data residency -- a notion that requires outsourced data to be retrievable in its entirety from local drives of a storage server in-question. We formulate such notion under a security model called Proofs of Data Residency (PoDR). can be employed to check whether the data are replicated across different storage servers, or combined with storage server geolocation to "locate" the data in the cloud. We make key observations that the data residency checking protocol should exclude all server-side computation and that each challenge should ask for no more than a single atomic fetching operation. We illustrate challenges and subtleties in protocol design by showing potential attacks to naive constructions. Next, we present a secure PoDR scheme structured as a timed challenge-response protocol. Two implementation variants of the proposed solution, namely NVeri and EVeri, describe an interesting use-case of trusted computing, in particular the use of Intel SGX, in cryptographic timed challenge-response protocols whereby having the verifier co-locating with the prover offers security enhancement. Finally, we conduct extensive experiments to exhibit potential attacks to insecure constructions and validate the performance as well as the security of our solution. Hung Dang, Erick Purwanto, Ee-Chien Chang |
AsiaCCS | 1 |
| 2017 | Privacy-Preserving Computation with Trusted Computing via Scramble-then-ComputeabstractAbstract We consider privacy-preserving computation of big data using trusted computing primitives with limited private memory. Simply ensuring that the data remains encrypted outside the trusted computing environment is insufficient to preserve data privacy, for data movement observed during computation could leak information. While it is possible to thwart such leakage using generic solution such as ORAM [42], designing efficient privacy-preserving algorithms is challenging. Besides computation efficiency, it is critical to keep trusted code bases lean, for large ones are unwieldy to vet and verify. In this paper, we advocate a simple approach wherein many basic algorithms (e.g., sorting) can be made privacy-preserving by adding a step that securely scrambles the data before feeding it to the original algorithms. We call this approachScramble-then-Compute(StC), and give a sufficient condition whereby existing external memory algorithms can be made privacy-preserving via StC. This approach facilitates code-reuse, and its simplicity contributes to a smaller trusted code base. It is also general, allowing algorithm designers to leverage an extensive body of known efficient algorithms for better performance. Our experiments show that StC could offer up to 4.1× speedups over known, application-specific alternatives. Hung Dang, Tien Tuan Anh Dinh, Ee-Chien Chang, Beng Chin Ooi |
Proc. Priv. Enhancing Technol. | 1 |
| 2016 | Practical and Scalable Sharing of Encrypted Data in Cloud Storage with Key AggregationabstractWe study a sensor network setting in which samples are encrypted individually using different keys and maintained on a cloud storage. For large systems, e.g. those that generate several millions of samples per day, fine-grained sharing of encrypted samples is challenging. Existing solutions, such as Attribute-Based Encryption (ABE) and Key Aggregation Cryptosystem (KAC), can be utilized to address the challenge, but only to a certain extent. They are often computationally expensive and thus unlikely to operate at scale. We propose an algorithmic enhancement and two heuristics to improve KAC's key reconstruction cost, while preserving its provable security. The improvement is particularly significant for range and down-sampling queries -- accelerating the reconstruction cost from quadratic to linear running time. Experimental study shows that for queries of size 32k samples, the proposed fast reconstruction techniques speed-up the original KAC by at least 90 times on range and down-sampling queries, and by eight times on general (arbitrary) queries. It also shows that at the expense of splitting the query into 16 sub-queries and correspondingly issuing that number of different aggregated keys, reconstruction time can be reduced by 19 times. As such, the proposed techniques make KAC more applicable in practical scenarios such as sensor networks or the Internet of Things. Hung Dang, Yun Long Chong, Francois Brun, Ee-Chien Chang |
IH&MMSec | 1 |
| 2015 | Auto-patching DOM-based XSS at scaleabstractDOM-based cross-site scripting (XSS) is a client-side code injection vulnerability that results from unsafe dynamic code generation in JavaScript applications, and has few known practical defenses. We study dynamic code evaluation practices on nearly a quarter million URLs crawled starting from the the Alexa Top 1000 websites. Of 777,082 cases of dynamic HTML/JS code generation we observe, 13.3% use unsafe string interpolation for dynamic code generation — a well-known dangerous coding practice. To remedy this, we propose a technique to generate secure patches that replace unsafe string interpolation with safer code that utilizes programmatic DOM construction techniques. Our system transparently auto-patches the vulnerable site while incurring only 5.2 − 8.07% overhead. The patching mechanism requires no access to server-side code or modification to browsers, and thus is practical as a turnkey defense. Inian Parameshwaran, Enrico Budianto, Shweta Shinde, Hung Dang, Atul Sadhu, Prateek Saxena |
ESEC/SIGSOFT FSE | 4 |
| 2015 | DexterJS: robust testing platform for DOM-based XSS vulnerabilitiesabstractDOM-based cross-site scripting (XSS) is a client-side vulnerability that pervades JavaScript applications on the web, and has few known practical defenses. In this paper, we introduce DEXTERJS, a testing platform for detecting and validating DOM-based XSS vulnerabilities on web applications. DEXTERJS leverages source-to source rewriting to carry out character-precise taint tracking when executing in the browser context—thus being able to identify vulnerable information flows in a web page. By scanning a web page, DEXTERJS produces working exploits that validate DOM-based XSS vulnerability on the page. DEXTERJS is robust, has been tested on Alexa’s top 1000 sites, and has found a total of 820 distinct zero-day DOM-XSS confirmed exploits automatically. Inian Parameshwaran, Enrico Budianto, Shweta Shinde, Hung Dang, Atul Sadhu, Prateek Saxena |
ESEC/SIGSOFT FSE | 4 |
| 2013 | Maximum Complex Task Assignment: Towards Tasks Correlation in Spatial CrowdsourcingabstractSpatial crowdsourcing has gained emerging interest from both research communities and industries. Most of current spatial crowdsourcing frameworks assume independent and atomic tasks. However, there could be some cases that one needs to crowdsource a spatial complex task which consists of some spatial sub-tasks (i.e., tasks related to a specific location). The spatial complex task's assignment requires assignments of all of its sub-tasks. The currently available frameworks are inapplicable to such kind of tasks. In this paper, we introduce a novel approach to crowdsource spatial complex tasks. We first formally define the Maximum Complex Task Assignment (MCTA) problem and propose alternative solutions. Subsequently, we perform various experiments using both real and synthetic datasets to investigate and verify the usability of our proposed approach. Hung Dang, Tuan A. Nguyen, Hien To |
iiWAS | 1 |
| 2007 | On Sensitivity Ranking Using Analytic Hierarchy ProcessabstractWe present an application of the Analytic Hierarchy Process (AHP) in the sensitivity analysis of a multi-parameter decision support problem. In this problem, the Multi-Parametric Sensitivity Analysis (MPSA) appears appropriate and is employed. A drawback of MPSA is that it only produces a sensitivity comparison between every two parameters, and does not offer a systematic method for ranking all parameters at once. Without the overall sensitivity ranking, it is difficult to interpret the analysis result from MPSA, especially when the number of parameters is large. Our paper shows that AHP can be used to perform such ranking based on MPSA's pair-wise comparisons. Hung Dang |
Int. J. Uncertain. Fuzziness Knowl. Based Syst. | 1 |