EDBT 2026 Demo / reviewers in the wild / expert
Xuan Shan
dblp:154/4723
· DBLP profile ↗
12ranked-venue papers
1as first author
10since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 4 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Similarity-Aware Defense Scheme for Online Brute-Force Attacks in Encrypted Deduplication
Guanxiong Ha, Chunfu Jia, Xiaowei Ge, Xuan Shan |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Understanding User Passwords Through Parsing TreeabstractPasswords are today’s dominant form of authentication, and password guessing is the most effective method for evaluating password strength. Most password guessing models (e.g., PCFG, Markov, and RFGuess) regard passwords as sequences composed of basic units (i.e., characters/segments), with the information flow being unidirectional (i.e., predicting the next unit based on the preceding units). However, modeling passwords in a single direction fails to capture users’ password creation behavior that is actually impacted by the full password context. Through an in-depth analysis of real-world passwords, we reveal that users often create passwords around a central keyword, like common words, names, or dates, and then embellish them with numbers or symbols. Based on this observation, we, for the first time, attempt to parse passwords as trees. Unlike existing sequence models, trees can reveal the semantic connections within passwords and the logical thought processes users follow when creating passwords. For instance, in the passwordiloveyou, the basic unitsiandyouare semantically dependent on the predicatelove, forming a natural tree structure.We propose a trawling guessing model called PassTree and a targeted guessing model based on personally identifiable information (PII), named PassTree-PII. Our extensive experiments demonstrate the effectiveness of our models: (1) PassTree outperforms its leading counterparts by 0.38%-2.51% when guessing numbers are below$10^{7}$107; (2) PassTree-PII achieves a cracking rate comparable to the state-of-the-art RFGuess-PII proposed in USENIX Security’23, but operates significantly more efficiently, using only 0.87% of the memory and being 16.60 times faster. Our work provides a new perspective on understanding user passwords and demonstrates a feasible technical route of applying tree structures to password guessing. Ding Wang 0002, Xuan Shan, Chunfu Jia |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Random Coding Responses for Resisting Side-Channel Attacks in Client-Side Deduplicated Cloud StorageabstractSide-channel attacks are widespread in client-side deduplication systems, compromising the privacy of outsourced data. The adversary may infer the existence status of data via the deterministic relations between duplication requests and responses to launch side-channel attacks. Random Response (RARE) is one of the state-of-the-art approaches to overcome this issue, where the cloud server returns the randomized deduplication response for two requests at once to mitigate the risk of side-channel attacks. However, it still has some inherent limitations on communication efficiency and security. In this paper, we propose Random Coding Responses (RACORE), a lightweight and secure multi-chunk coding algorithm to address the limitations of RARE. RACORE achieves efficient multi-chunk coding and obfuscation based on the linear mapping induced by a specially constructed pseudo-random matrix. Compared to existing schemes, RACORE can strike a flexible balance between security and performance by adjusting parameters. Further, we present an enhanced composite matrix generation strategy to extend the coding matrix. Based on this strategy, we design an enhanced coding algorithm RACORE$^+$to improve efficiency. Besides, we put forward a novel redundant chunk selection method to enhance the security of RACORE and RACORE$^+$. Rigorous security analysis and extensive experimental evaluation demonstrate that both RACORE and RACORE$^+$can effectively resist side-channel attacks while reducing overhead compared to existing schemes. Guanxiong Ha, Chunfu Jia, Xuan Shan |
IEEE Trans. Serv. Comput. | 5 |
| 2024 | A Secure and Lightweight Client-Side Deduplication Approach for Resisting Side Channel AttacksabstractClient-side deduplication system is widely used in cloud storage systems to reduce storage and communication overhead by eliminating the storing and uploading of duplicate data. However, it is vulnerable to side channel attacks, where an adversary can infer the existence status of uploaded data based on deterministic relations in duplication check responses. To address this issue, Random Response (RARE) was proposed, which sends duplication check requests for two chunks simultaneously. Nevertheless, RARE has limitations in terms of communication efficiency and security. In this paper, we propose Random Zero-one Coding Response (RZCR) to overcome these limitations. RZCR achieves lightweight coding of multiple chunks using a novel linear mapping algorithm, allowing for a balance between security and performance through the adjustment of system parameters. Furthermore, we, for the first time, formally define a security game to model these side channel attacks in client-side deduplication systems and introduce a stronger threat model compared to RARE. Security analysis demonstrates that RZCR effectively mitigates the risk of side channel attacks. We also implement a prototype of RZCR and evaluate its performance using large-scale real-world datasets (i.e., Enron Email and Fslhomes) as well as synthetic datasets. The results show that RZCR significantly reduces communication overhead compared to representative schemes. Chunfu Jia, Guanxiong Ha, Xuan Shan |
ICC | 4 |
| 2024 | Scalable Client-side Encrypted Deduplication beyond Secret Sharing of the Master KeyabstractIndividuals and companies increasingly adopt encrypted deduplication systems for their enhanced security and efficiency benefits. Server-aided encrypted deduplication systems are the state-of-the-art scheme to resist brute-force attacks. However, it is overly reliant on a single centralized key server and vulnerable to a single point of failure. To this end, existing schemes have implemented distributed key servers based on secret sharing of the master key to resist a single point of failure. Nevertheless, this design has some inherent limitations in balancing security and scalability. Secret sharing of the master key effectively mitigates single points of failure, while negatively impacting system scalability. To address the above limitations, we propose a scalable client-side encrypted deduplication with distributed key servers based on secret sharing of the data key. To resist brute-force attacks, we also design a double-layer matching mechanism to achieve secure and effective duplicate check and key delivery. Additionally, drawing inspiration from random oracle models, we put forward a pseudo-random response strategy for key servers to safeguard key privacy effectively. Rigorous theoretical analysis and extensive experiments demonstrate that our scheme achieves both security and scalability, which is well-suited for deployment in large-scale systems and offers robust protection against a single point of failure. Guanxiong Ha, Xuan Shan, Chunfu Jia, Qiaowen Jia |
TrustCom | 3 |
| 2023 | No Single Silver Bullet: Measuring the Accuracy of Password Strength Meters
Ding Wang 0002, Xuan Shan, Qiying Dong, Yaosheng Shen, Chunfu Jia |
USENIX Security Symposium | 2 |
| 2022 | Cross-Domain Graph Anomaly DetectionabstractAnomaly detection on attributed graphs has received increasing research attention lately due to the broad applications in various high-impact domains, such as cybersecurity, finance, and healthcare. Heretofore, most of the existing efforts are predominately performed in an unsupervised manner due to the expensive cost of acquiring anomaly labels, especially for newly formed domains. How to leverage the invaluable auxiliary information from a labeled attributed graph to facilitate the anomaly detection in the unlabeled attributed graph is seldom investigated. In this study, we aim to tackle the problem of cross-domain graph anomaly detection with domain adaptation. However, this task remains nontrivial mainly due to: 1) the data heterogeneity including both the topological structure and nodal attributes in an attributed graph and 2) the complexity of capturing both invariant and specific anomalies on the target domain graph. To tackle these challenges, we propose a novel framework COMMANDER for cross-domain anomaly detection on attributed graphs. Specifically, COMMANDER first compresses the two attributed graphs from different domains to low-dimensional space via a graph attentive encoder. In addition, we utilize a domain discriminator and an anomaly classifier to detect anomalies that appear across networks from different domains. In order to further detect the anomalies that merely appear in the target network, we develop an attribute decoder to provide additional signals for assessing node abnormality. Extensive experiments on various real-world cross-domain graph datasets demonstrate the efficacy of our approach. Kaize Ding, Kai Shu, Xuan Shan, Jundong Li, Huan Liu 0001 |
IEEE Trans. Neural Networks Learn. Syst. | 3 |
| 2021 | GLOW : Global Weighted Self-Attention Network for Web SearchabstractDeep matching models aim to facilitate search engines retrieving more relevant documents by mapping queries and documents into semantic vectors in the first-stage retrieval. When leveraging BERT as the deep matching model, the attention score across two words are solely built upon local contextualized word embeddings. It lacks prior global knowledge to distinguish the importance of different words, which has been proved to play a critical role in information retrieval tasks. In addition to this, BERT only performs attention across sub-words tokens which weakens whole word attention representation. We propose a novel Global Weighted Self-Attention (GLOW) network for web document search. GLOW fuses global corpus statistics into the deep matching model. By adding prior weights into attention generation from global information, like BM25, GLOW successfully learns weighted attention scores jointly with query matrix Q and key matrix K. We also present an efficient whole word weight sharing solution to bring prior whole word knowledge into sub-words level attention. It aids Transformer to learn whole word level attention. To make our models applicable to complicated web search scenarios, we introduce combined fields representation to accommodate documents with multiple fields even with variable number of instances. We demonstrate GLOW is more efficient to capture the topical and semantic representation both in queries and documents. Intrinsic evaluation and experiments conducted on public data sets reveal GLOW to be a general framework for document retrieve task. It significantly outperforms BERT and other competitive baselines by a large margin while retaining the same model complexity with BERT. The source code is available at https://github.com/GLOW-deep/GLOW. Xuan Shan, Chuanjie Liu, Yiqian Xia, Qi Chen 0009, Kaize Ding, Yaobo Liang, Angen Luo, Yuxiang Luo |
IEEE BigData | 1 |
| 2021 | Towards Anomaly-resistant Graph Neural Networks via Reinforcement LearningabstractIn general, graph neural networks (GNNs) adopt the message-passing scheme to capture the information of a node (i.e., nodal attributes, and local graph structure) by iteratively transforming, aggregating the features of its neighbors. Nonetheless, recent studies show that the performance of GNNs can be easily hampered by the existence of abnormal or malicious nodes due to the vulnerability of neighborhood aggregation. Thus it is necessary to learn anomaly-resistant GNNs without the prior knowledge of ground-truth anomalies, given the fact that labeling anomalies is costly and requires intensive domain knowledge. Though removing anomalies through unsupervised anomaly detection methods could be a possible solution, it may render unreasonable GNN model performance on target tasks due to the non-differentiable gap between the two learning procedures. In order to keep the effectiveness of GNNs on anomaly-contaminated graphs, in this paper, we propose a new framework named RARE-GNN (Reinforced Anomaly-REsistant Graph Neural Networks) which can detect anomalies from the input graph and learn anomaly-resistant GNNs simultaneously. Extensive experiments on real-world datasets demonstrate the effectiveness of the proposed framework. Kaize Ding, Xuan Shan, Huan Liu 0001 |
CIKM | 2 |
| 2021 | MIRA: Leveraging Multi-Intention Co-click Information in Web-scale Document Retrieval using Deep Neural NetworksabstractWe study the problem of deep recall model in industrial web search, which is, given a user query, retrieve hundreds of most relevant documents from billions of candidates. The common framework is to encoding queries and documents separately into distributed representations and match them in latent semantic space. However, all the exiting deep encoding models only leverage the information of the document itself, which is often not sufficient in practice when matching with query terms, especially for the hard tail queries. In this work we aim to leverage the additional information for documents from their co-click neighbours to help document retrieval. The challenges include how to effectively extract information and eliminate noise when involving co-click information while meet the demands of industrial scalability for real time online serving. Chuanjie Liu, Angen Luo, Hui Xue 0004, Xuan Shan, Yuxiang Luo, Yiqian Xia, Yuanchi Yan |
WWW | 5 |
| 2015 | SSDS-MC: Slice-based Secure Data Storage in Multi-Cloud Environment
Xiaqi Liu, Zhengguo Sheng, Xuan Shan, Kai Shuang |
QSHINE | 4 |
| 2014 | An Efficient ZigBee-WebSocket Based M2M Environmental Monitoring SystemabstractTechnologies to support the Machine-to-Machine (M2M) is becoming more important as the need to better understand our environments and make them smart increases. As a result it is predicted that intelligent devices and networks, such as wireless network, will not be isolated but connected and integrated composing computer networks. So far, to enable an End-to-end M2M service, WebSocket has attracted lots of attentions because of its unique full-duplex communications features. Besides, ZigBee technology has widely been deployed in short-range wireless communication systems with its low-power dissipation and high transmission speed. In this paper, we focus on the emerging M2M gateway development for home and industry applications. Specifically, by providing the detailed system architecture and user cases, we give a specific analysis on environmental monitoring implemented with WebSocket and ZigBee technology. The ZigBee sensor network is used to collect the temperature and humidity information. The foreground of the system shows the related data through B/S (Browser/Server) mode by utilizing WebSocket to push the information received by a web server to the client browser. Kai Shuang, Xuan Shan, Zhengguo Sheng, Chunsheng Zhu |
DASC | 2 |