Tanping Zhou

dblp:162/8959 · DBLP profile ↗
← Back
18ranked-venue papers
5as first author
16since 2021 · last 2026
0000-0001-6325-5965ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 1 first-author · 5 since 2021Security and privacy · 5 · 3 first-author · 3 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Authorized multi-key fully homomorphic encryption scheme with compact ciphertext
Tanping Zhou, Hongjian Yang, Long Chen 0018, Zhenfeng Zhang
Des. Codes Cryptogr.1
2026 An efficient collusion-resistant and drop-proof federated learning security aggregation scheme based on RLWE
Tanping Zhou, Wei Ke 0004, Weidong Zhong, Xiaoyuan Yang 0002
Peer Peer Netw. Appl.2
2026 Lattice-based linkable linearly homomorphic ring signature scheme
Ruifeng Li 0003, Yiliang Han, Tanping Zhou, Shuaishuai Zhu, Xiaoyuan Yang 0002
J. Supercomput.3
2025 Zephyr: Secure and Non-interactive Two-Party Inference for Transformers
abstract
The widespread adoption of Transformer models raises critical privacy concerns as users must expose sensitive inputs to service providers during inference. While existing secure Transformer frameworks have addressed this issue to some extent, most rely on interactive protocols with prohibitive communication overhead, limiting practicality in bandwidth-constrained scenarios. This paper introduces Zephyr, a secure and non-interactive two-party inference framework for Transformers that overcomes these limitations. First, Zephyr proposes two novel SIMD ciphertext decompression techniques, shifting from serial to parallel processing to accelerate decompression by 1.2× while preserving accuracy. Second, Zephyr optimizes the deployment strategy of bootstrapping operations (which refresh encrypted data noise) during computation. This allows using smaller encryption parameters while achieving 1.1× faster bootstrapping than NEXUS. Evaluated on BERT-base under challenging 100Mbps/80ms conditions, Zephyr demonstrates superior performance - 24.3× faster than Iron(NeurIPS22), 2.1× faster than BOLT, and 11% faster than NEXUS while reducing communication costs by 95% versus BOLT(Oakland24) and 32% versus NEXUS(NDSS25), making it particularly effective for bandwidth-constrained environments while maintaining security against semi-honest adversaries.
Wenchao Liu 0002, Huiyu Xie, Tanping Zhou, Weidong Zhong, Xiaoyuan Yang 0002
TrustCom3
2025 Verifiable secure aggregation scheme for privacy protection in federated learning networks
abstract
Federated learning enables multiple participants to construct a distributed machine learning system coordinated by a server. Most existing solutions assume a semi-honest system, considering each participant to be honest but curious, which does not align with the complex real-world environment. In reality, servers might act maliciously by tampering with or forging aggregation results, which directly threatens the integrity of global models.. To verify the integrity of server aggregation computations while protecting the privacy of clients, this paper introduces a privacy-preserving verifiable secure aggregation scheme for federated learning networks. Initially, we construct a functional reuse private key ring generation algorithm, enabling clients to encrypt and protect their private gradients using the private key ring. Subsequently, leveraging the discrete logarithm difficulty problem, we devise a commitment protocol where clients commit to their encrypted private gradients. Upon receiving the aggregation result from the server, they collaboratively unlock the commitment, thereby verifying the aggregation result. Security analysis demonstrates that our solution effectively ensures privacy protection. We tested the performance using a Raspberry Pi as an edge computing device. Experimental data reveals that, with 100 clients, our scheme demonstrates that the additional costs for proof generation and verification computations are 39.9% and 34.1% of the existing scheme, respectively, highlighting its lightweight nature.
Wujun Yao, Tanping Zhou, Yiliang Han
Discov. Comput.2
2025 VCFL: Verifiable and communication-efficient federated learning against collusion attack for secure aggregation
Huiyu Xie, Tanping Zhou, Xiaoyuan Yang 0002
Inf. Sci.2
2025 DP-FedSecure: a secure and efficient federated learning scheme based on adaptive differential privacy
Tanping Zhou, Huiyu Xie, Weidong Du, Xiaoyuan Yang 0002
Mach. Learn.2
2025 Enhanced security verifiable secure aggregation scheme in federated learning
Wujun Yao, Yiliang Han, Tanping Zhou
Peer Peer Netw. Appl.3
2024 MDA-FLH: Multidimensional Data Aggregation Scheme With Fine-Grained Linear Homomorphism for Smart Grid
abstract
Privacy-preserving multidimensional data aggregation aggregates the data of all different users into a single value, preventing the leakage of personal data while ensuring its availability. However, most current multidimensional data aggregation schemes only consider sum operations, i.e., the message of each dimension in the aggregation result is the sum of the corresponding dimensional messages of all individual message vectors. We propose a multidimensional data aggregation scheme with fine-grained linear homomorphism, called MDA-FLH. Firstly, we construct a fine-grained linear homomorphic encryption scheme which can assign different weights to each dimension of user’s data and maintain the linear homomorphic property in each dimension. We combine the Chinese remainder theorem and Paillier encryption to encode the multidimensional data with CRT and assign different weights to each dimension of user’s data in the Paillier ciphertext. Secondly, our scheme has the property of fault tolerance. In conjunction with extended Shamir’s threshold secret-sharing scheme, a security-enhanced and fault-tolerant data aggregation method has been designed so that it is resistant to internal attacks such as the control center (CC) access to individual private data if given the corresponding ciphertext. Finally, two practical schemes are designed based on MDA-FLH: fine-grained electricity price statistics scheme and multistep electricity price statistics scheme. Security analysis shows that our scheme can achieve privacy, confidentiality, integrity, and source authentication. Performance analysis shows that our scheme is efficient, especially that SMs are computationally economic, which makes our scheme more suitable for resource-constrained SM. Also, our scheme can provide linear homomorphism operations on each dimension, which further expands its applications.
Dong Chen 0024, Tanping Zhou, Wenchao Liu 0002, Ruifeng Li 0003, Liqiang Wu, Xiaoyuan Yang 0002
IEEE Internet Things J.2
2024 SFPDA: Secure Fault-Tolerant and Privacy-Enhanced Data Aggregation Scheme for Smart Grid Without TA
abstract
With the rapid development of smart grids (SGs), designing a data aggregation scheme that ensures both data availability and privacy security has become an urgent necessity. Particularly, considering the potential failures of smart meters (SMs), ensuring fault tolerance in data decryption has become a significant challenge in the design. Recently, Wu et al. proposed a fault-tolerant data aggregation scheme FPDA that excels in privacy protection and fault tolerance. However, like most data aggregation schemes in SG, FPDA relies on a trust authority (TA), which is difficult to find in real-world scenarios. Furthermore, the scheme is vulnerable to delay attacks, posing a risk of individual meter privacy leakage. Therefore, this article first designs an attack for FPDA scheme which capable of achieving 100% plaintext recovery when users delays, with an attack time of only 518 ms. Subsequently, we propose a secure fault-tolerant and privacy-enhanced data aggregation scheme for SG without TA (SFPDA). By employing multiuser Diffie-Hellman key exchange (MDHKE), we eliminate the need for a trusted third party, Additionally, we utilize dual masking to resist delay attacks. We conduct a security analysis of the scheme, which demonstrates that SFPDA can resist delay attacks and provide enhanced privacy protection. Finally, experimental results show that SFPDA reduces encryption time by approximately 40% and decryption time by approximately 83.3%, while offering better fault tolerance, making it more suitable for grid environments where the number of residents remains constant, but the failure rate of meters fluctuates.
Tanping Zhou, Huiyu Xie, Liqiang Wu, Xiaoyuan Yang 0002
IEEE Internet Things J.1
2024 Linearly Homomorphic Signature Scheme With High-Signature Efficiency and Its Application in IoT
abstract
As the Internet of Things (IoT) is booming, the transmission speed of data in the network is getting more and more attention. Network coding is an effective technique to improve network throughput. In network coding, the encoded packets must be integrity-checked to prevent pollution attacks. Some linearly homomorphic signature (LHS) schemes based on bilinear pairs have been used to check the integrity of packets, and so far the scheme LZL20 is the most efficient signature scheme among them. Here, we first analyze the security model and signature structure of LZL20, and find that there is a security vulnerability in the scheme. Experiments show that for a 12–18 kB file, our signature forgery algorithm can forge a message/signature pair with 100% probability within 3–5 ms. Then, we construct a LHS scheme with higher signature efficiency and shorter signature length. In random oracle model, we proved the scheme is existentially unforgeable under adaptive chosen message attacks. We theoretically analyze our signature length to be 320 bits shorter than LZL20. Finally, we implement our scheme, and for a 12–18 kB file, experiments show that the signature time of our scheme is 60.93%–62.59% of that of LZL20.
Tanping Zhou, Weidong Zhong, Xiaoyuan Yang 0002
IEEE Internet Things J.2
2023 Modified Multi-Key Fully Homomorphic Encryption Scheme in the Plain Model
abstract
Abstract Multi-key fully homomorphic encryption (MFHE) supports arbitrary meaningful computations on encrypted data under different public keys even without access to the secret key, which is well tailored for the secure multiparty computation scenarios. Based on the Gentry–Sahai–Waters scheme (a single-key FHE in Crypto 2013) with the underlying learning with errors problem, MW16 scheme (Eurocrypt 2016) utilizes the method of ‘linear combination procedure’ (LCP) as a subroutine to construct the auxiliary information for the expanded ciphertexts of MFHE scheme. However, every party shares a common random string (CRS) to be distributed by a trusted setup, which is unpractical. Meanwhile, the noise in the auxiliary information is too much compared with the one in fresh ciphertexts. In this paper, we propose a modified MFHE scheme in the plain model, i.e. without CRS, to enhance the practicability of MFHE. Specifically, every involved party generates his own public key independent on a CRS. Then a potential improvement on the LCP is developed to provide auxiliary information, which largely reduces the noise and leads to a smaller modulus for our MFHE. Furthermore, the feasibility of our proposal is also proved by theoretical performance comparisons.
Wenju Xu, Baocang Wang, Quanbo Qu, Tanping Zhou, Pu Duan
Comput. J.4
2023 Secure and Efficient Online Fingerprint Authentication Scheme Based On Cloud Computing
abstract
Privacy protection of biometrics-based on cloud computing is attracting increasing attention. In 2018, Zhuet al.proposed an efficient and privacy-preserving online fingerprint authentication scheme for data outsourcing e-Finga. Under the premise of ensuring user's fingerprint data privacy and message security authentication, the e-Finga scheme can provide accurate and efficient fingerprint identity authentication services. However, our analysis shows that the temporary fingerprint in this scheme uses the deterministic encryption algorithm, which has the risk of leaking the user's fingerprint characteristics. Therefore, we propose a temporary fingerprint attack method for the e-Finga scheme. Experiments demonstrate that an adversary can analyze specific secret parameters and fingerprint features when eavesdropping on a user's temporary fingerprint ciphertext. To counter the temporary fingerprint attack, we propose a secure e-fingerprint scheme– Secure e-finger that uses the learning with errors samples, which has the homomorphic addition property, to encrypt user's temporary fingerprints. Experiments show that the secure e-finger scheme can resist the temporary fingerprint attack. Compared with the unprotected e-Finga scheme, the client running time is increased by about 6% percent, the communication cost on the user side only increased by 0.3125% percent. As a result, our solution can realize secure online fingerprint authentication without losing efficiency. Single user authentication is likely to cause the problem of excessive authority. Based on the Secure e-finger scheme, we propose a threshold scheme based on biological characteristics.
Tanping Zhou, Zelun Yue, Wenchao Liu 0002, Yiliang Han, Qi Li 0033, Xiaoyuan Yang 0002
IEEE Trans. Cloud Comput.2
2023 Attacks and Improvement of Unlinkability of Biometric Template Protection Scheme Based on Bloom Filters
abstract
Biometric technologies are being prominently used everywhere. However, the leakage of biometric information can pose a serious security risk, making the protection of biometric templates particularly important and receiving more attention. Rathgeb et al. first proposed the cancelable biometric technology based on Bloom filters in 2013, which has been applied to protect different biometric templates. Bloom filter-based biometrics offer the advantages of alignment-free, fast recognition and high accuracy. An ideal biometric system should also be irreversibility and unlinkability. In this paper, firstly, we propose a reverse reconstruction attack. Through the reverse reconstruction of Bloom filters, we find that the reconstructed biometric data and the original biometric data have some strong statistical correlation, which proves that the scheme has the linkability defect. Experiments show that for the original Bloom filter-based biometric template protection scheme, we can judge whether two different biometric templates belong to the same user with a success probability of 71.0%. Secondly, to remedy above defect, we construct a structure-preserving encryption scheme, i.e., the feature template encrypted with it maintains the structure and length of the original template, making it impossible for an attacker to reconstruct meaningful data from Bloom filter. Finally, an improved biometric template protection scheme based on Bloom filters is proposed by introducing the proposed encryption. Attack experiment shows that the improved scheme can effectively resist the reverse reconstruction attack, with the success probability of attacking the unlinkability of the improved scheme being 50.0%, which is the same as the probability of random guessing. Performance evaluation shows that the proposed scheme maintains the biometric performance of the original system and the unprotected system.
Tanping Zhou, Dong Chen 0024, Wenchao Liu 0002, Xiaoyuan Yang 0002
IEEE Trans. Cloud Comput.1
2022 VCFL: A verifiable and collusion attack resistant privacy preserving framework for cross-silo federated learning
Weidong Du, Min Li 0030, Xiaoyuan Yang 0002, Liqiang Wu, Tanping Zhou
Pervasive Mob. Comput.5
2021 Efficient multi-key fully homomorphic encryption over prime cyclotomic rings with fewer relinearisations
abstract
Abstract Multi‐key fully homomorphic encryption (MKFHE) allows computations on ciphertexts encrypted by different users, which can be applied to implement secure multi‐party computing (MPC). The current NTRU‐based MKFHE has the following two drawbacks: One is that the relinearisation process during homomorphic evaluation is so complicated that the corresponding computation time is costly. The other is that a class of subfield attacks are proposed and affects the security of NTRU schemes over power‐of‐2 cyclotomic rings for large moduli q, especially for the NTRU‐based fully homomorphic encryption (FHE) schemes. In this work, an efficient MKFHE scheme is proposed over prime cyclotomic rings with fewer relinearisations, which seems a good choice because of its potential to resist a subfield attack. More specifically, the time of the relinearisation process is reduced by half in homomorphic evaluations by separating the homomorphic multiplication and the relinearisation process (implementing two homomorphic multiplication operations together before relinearisation), while in current NTRU‐type MKFHE schemes, these two processes are usually performed together. The error bound of the basic function components is re‐analysed over prime cyclotomic rings in the average case, which can be used in the error analysis of our scheme. We construct an efficient NTRU‐based single‐key FHE scheme and an efficient MKFHE scheme over prime cyclotomic rings through relinearisation and modulus‐switching techniques. The MKFHE scheme proposed has the on‐the‐fly property and has a tight ciphertext size compared with the GSW‐type and BGV‐type MKFHE schemes. An experiment shows that the homomorphic evaluation of the optimised single‐key FHE scheme proposed is 1.9 times faster than an efficient NTRU‐type MKFHE DHS16 proposed at DCC 2016.
Tanping Zhou, Qiqi Lai, Xiaoyuan Yang 0002, Yiliang Han, Wenchao Liu 0002
IET Inf. Secur.1
2019 A New Group Location Privacy-Preserving Method Based on Distributed Architecture in LBS
abstract
Nowadays, the location privacy problem has become an important problem for the users who enjoy the location-based services (LBSs). Researchers have focused on the problem of how to protect the location privacy of user efficiently for a long time. On one hand, many achievements adopt the centralized structure in which there is an additional center server. Additionally, some other researchers adopt the distributed structure to overcome the disadvantages brought by the center server in the centralized anonymous system structure. On the other hand, the existing methods of solving the problem are always to protect the individual user’s location privacy in LBSs, without considering the user group’s location privacy. This kind of methods is not very applicable to the status of a number of users who formed a group to complete a LBS task together by collaborative computing. In order to solve the problem of location privacy protection for a user group in the untrusted mobile social networks, a location privacy protection method based on the distributed structure is discussed in this paper. In the scheme, the special homomorphic features of BGN cryptosystem are cleverly used so that it can solve the group’s three classical location service applications simultaneously, namely, group nearest neighbor query, optimal group collection point determination, and group friend’s distance query, by only one security policy. If there are k users who formed the group, it could achieve k-anonymity without exposing the coordinate of each individual user or using any anonymous areas. Furthermore, theoretical and experimental analysis proves that the proposal can efficiently protect each user’s location privacy in the group through taking full advantage of the collaborative computing and communication capabilities of the mobile terminals. It can resist the existing distance interaction attack and collusion attack and can realize the secure and efficient fine-grained controllable location privacy protection for the user group.
Yiliang Han, Xiaoyuan Yang 0002, Tanping Zhou, Jiayong Chen
Secur. Commun. Networks4
2018 Secure Testing for Genetic Diseases on Encrypted Genomes with Homomorphic Encryption Scheme
abstract
The decline in genome sequencing costs has widened the population that can afford its cost and has also raised concerns about genetic privacy. Kim et al. present a practical solution to the scenario of secure searching of gene data on a semitrusted business cloud. However, there are three errors in their scheme. We have made three improvements to solve these three errors. (1) They truncate the variation encodings of gene to 21 bits, which causes LPCE error and more than 5% of the entries in the database cannot be queried integrally. We decompose these large encodings by 44 bits and deal with the components, respectively, to avoid LPCE error. (2) We abandon the hash function used in Kim’s scheme, which may cause HCE error with a probability of 2-22 and decompose the position encoding of gene into three parts with the basis 211 to avoid HCE error. (3) We analyze the relationship between the parameters and the CCE error and specify the condition that parameters need to satisfy to avoid the CCE error. Experiments show that our scheme can search all entries, and the probability of searching error is reduced to less than 2-37.4 .
Tanping Zhou, Xiaoyuan Yang 0002, Liqun Lv, Yitao Ding, Xu An Wang 0014
Secur. Commun. Networks1