EDBT 2026 Demo / reviewers in the wild / expert
Yuan Cheng 0002
dblp:15/5135-2
· DBLP profile ↗
12ranked-venue papers
4as first author
4since 2021 · last 2026
0000-0001-7176-3951ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 4 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Comparative Analysis of Third-Party Script Behaviour in Consent-Based and Implicit Web TrackingabstractModern websites rely heavily on third-party scripts for advertising and analytics, and they are required to obtain user consent before deploying non-essential tracking. However, it remains unclear whether websites that provide explicit consent interfaces actually behave differently from those that track users by default. This paper presents a comprehensive client-side measurement of third-party script behaviour under two tracking paradigms: consent-based tracking (CBT), which requires explicit user choice for executing non-essential scripts, and implicit tracking, where no such choice is given. We developed an automated measurement pipeline using Chromium to crawl a set of websites sourced from Tranco, classify tracking paradigms based on observable interfaces, and record third-party script activity during fixed pre- and post-interaction periods. Our analysis examines the scale and timing of script loading, dependency structure, and runtime execution behaviour. We specifically analyse the ''no-consent'' state, comparing implicit tracking with CBT sites after a scripted ''Reject'' action. Our results find that CBT sites load more third-party scripts and activate them earlier during the initial page load than implicit-tracking sites, often before users can even interact with a consent banner. While the overall number of third-party scripts is similar after rejection, a substantial subset of CBT sites exhibits a larger third-party footprint, more intensive dynamic code execution, and higher runtime error rates than their implicit-tracking counterparts. These findings reveal a gap between interface-level consent flows and script-level behaviour, offering practical implications for developers and regulators. Chongwen Ma, Yuan Cheng 0002 |
CODASPY | 2 |
| 2024 | User Perceptions of CAPTCHAs: University vs. Internet Users
Arun Reddy, Yuan Cheng 0002 |
DBSec | 2 |
| 2024 | Detecting Location Spoofing Attacks using Multiple Angle of Signal Arrivals in MM-Wave Vehicular NetworksabstractMillimeter-wave (mm-wave) vehicular communication networks are expected to revolutionize intelligent transportation systems by enabling ultra-reliable, low-latency, and high-speed data exchange. A major challenge that needs to be addressed in these networks is the presence of malicious user activity that can disrupt the network through various means. These malicious activities include manipulating safety messages or launching location spoofing attacks. To tackle this challenge, a physical-layer-based location spoofing attack detection technique for mm-wave vehicular networks is proposed in this paper. The proposed technique makes use of the additional channel measurements available in systems with hybrid antenna architectures to enable joint beamforming and channel sensing. Spoofing attack detection is achieved by verifying a cluster of estimated angles of arrivals with the reported location information. The numerical results show that the proposed technique is highly accurate in detecting location spoofing attacks using just a few communication packets at the receiver without the need for a dedicated channel sensing stage or extra communication overhead. Chandana Sai Thondebhavi Shanthakumar, Aishwarya Chawariya, Yuan Cheng 0002, Mohammed Eltayeb |
VTC Spring | 3 |
| 2023 | A Secure Distributed Learning Framework Using Homomorphic EncryptionabstractThe increasing complexity of artificial intelligence (AI) models poses a significant challenge for individuals and organizations without sufficient computing resources to train them. While cloud-based training services can offer a solution, they require sharing sensitive data with untrusted parties, posing risks to data privacy. To address this challenge, we explore the combination of distributed training and homomorphic encryption to parallelize the training process on encrypted data. We utilize the CKKS homomorphic encryption scheme to develop a framework that can train comparably accurate AI models in less time than other homomorphically encrypted training solutions. Our experiments demonstrate reduced total runtime for homomor-phically encrypted model training while maintaining competitive classification accuracy for the MNIST handwritten digits dataset, a well-known benchmarking dataset for machine learning. Our framework brings homomorphic encryption closer to becoming a practical data privacy solution for small stakeholders who cannot afford to compromise on security. Stephen Ly, Yuan Cheng 0002, Haiquan Chen 0001, Ted Krovetz |
PST | 2 |
| 2020 | A Performance Study on Cryptographic Algorithms for IoT DevicesabstractInternet of Things (IoT) devices have grown in popularity over the past few years. These inter-connected devices collect and share data for automating industrial or household tasks. Despite its unprecedented growth, this paradigm currently faces many challenges that could hinder the deployment of such a system. These challenges include power, processing capabilities, and security, etc. Our project aims to explore these areas by studying an IoT network that secures data using common cryptographic algorithms, such as AES, ChaCha20, RSA, and Twofish. We measure computational time and power usage while running these cryptographic algorithms on IoT devices. Our findings show that while Twofish is the most power-efficient, Chacha20 is overall the most suitable one for IoT devices. Eduardo Anaya, Jimil Patel, Prerak Shah, Vrushank Shah, Yuan Cheng 0002 |
CODASPY | 5 |
| 2020 | A Performance Comparison of WireGuard and OpenVPNabstractA fundamental problem that confronts virtual private network (VPN) applications is the overhead on throughput, ease of deployment and use, and overall utilization. WireGuard is a recently introduced light and secure cross-platform VPN application. It aims to simplify the process of setting up a secure connection while utilizing the multi-threading capability and minimizing the use of bandwidth. There have been several follow-up studies on WireGuard since its birth, most of which focus on the security analysis of the protocol. Despite the author's claim that WireGuard has impressive wins over OpenVPN and IPsec, there is no rigorous analysis of its performance to date. This paper presents a performance comparison of WireGuard and its main rival OpenVPN on various metrics. We construct an automated test framework and deploy it on a total of eight nodes, including remote AWS instances and local virtual machines. Our test results clearly show two main edges that WireGuard has over OpenVPN, its performance on multi-core machines and its light codebase. Steven Mackey, Ivan Mihov, Alex Nosenko, Francisco Vega, Yuan Cheng 0002 |
CODASPY | 5 |
| 2016 | Extended ReBAC Administrative Models with Cascading Revocation and Provenance SupportabstractRelationship-based access control (ReBAC) has been widely studied and applied in the domain of online social networks, and has since been extended to domains beyond social. Using ReBAC itself to manage ReBAC also becomes a natural research frontier, where we have two ReBAC administrative models proposed recently by Rizvi et al.[30] and Stoller[33]. In this paper, we extend these two ReBAC administrative models in order to apply ReBAC beyond online social networks, particularly where edges can have dependencies with each other and authorization for certain administrative operations requires provenance information. Basically, our policy specifications adopt the concepts of enabling precondition and applicability preconditions from Rizvi et al[30]. Then, we address several issues that need to be considered in order to properly execute operation effects, such as cascading revocation and integrity constraints on the relationship graph. With these extended features, we show that our administrative models can provide the administration capability of the MT-RBAC model originally designed for multi-tenant collaborative cloud systems[34]. Yuan Cheng 0002, Khalid Zaman Bijon, Ravi S. Sandhu |
SACMAT | 1 |
| 2016 | An Access Control Model for Online Social Networks Using User-to-User RelationshipsabstractUsers and resources in online social networks (OSNs) are interconnected via various types of relationships. In particular, user-to-user relationships form the basis of the OSN structure, and play a significant role in specifying and enforcing access control. Individual users and the OSN provider should be enabled to specify which access can be granted in terms of existing relationships. In this paper, we propose a novel user-to-user relationship-based access control (UURAC) model for OSN systems that utilizes regular expression notation for such policy specification. Access control policies on users and resources are composed in terms of requested action, multiple relationship types, the starting point of the evaluation, and the number of hops on the path. We present two path checking algorithms to determine whether the required relationship path between users for a given access request exists. We validate the feasibility of our approach by implementing a prototype system and evaluating the performance of these two algorithms. Yuan Cheng 0002, Ravi S. Sandhu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2014 | Attribute-Aware Relationship-Based Access Control for Online Social Networks
Yuan Cheng 0002, Ravi S. Sandhu |
DBSec | 1 |
| 2012 | A User-to-User Relationship-Based Access Control Model for Online Social Networks
Yuan Cheng 0002, Ravi S. Sandhu |
DBSec | 1 |
| 2011 | ACON: Activity-Centric Access Control for Social ComputingabstractWith increasing amount of sensitive user data stored in social computing systems (SCSs) and lack of consensus on how it should be protected under meaningful control by the average user, security and privacy has become a pressing problem that must be addressed. We propose the concept of user and SCS activity as a natural aspect of social computing which influences access control in a manner distinct to SCSs. We propose an activity-centric access control or Activity Control (ACON) framework for social computing to facilitate both privacy setting from user side and administration from SCS side. We further propose an ACONusermodel for user activity control and session management. We illustrate how the model captures the user activities using several SC examples. Ravi S. Sandhu, Yuan Cheng 0002 |
ARES | 3 |
| 2010 | Towards a framework for cyber social status based trusted open collaborationabstractCollaboration takes place in both closed and open environments. While closed collaboration focuses on information or resource sharing amongst selected participants, open collaboration assumes and emphasizes that anyone can participate. In open collaboration, although participation is open to anyone Yuan Cheng 0002, Ravi S. Sandhu |
CollaborateCom | 2 |