EDBT 2026 Demo / reviewers in the wild / expert
Shukun Yang
dblp:172/8803
· DBLP profile ↗
6ranked-venue papers
1as first author
1since 2021 · last 2025
0000-0002-1272-9275ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 3 · 1 since 2021Security and privacy · 3 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
4 papers |
Authentication and access control · 87% Privacy and data protection · 10% Usable security · 3% |
Topics — the 8 heaviest of 9, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Authentication and access control
password security |
0.6 | 2 | 2018 | DPPG: A Dynamic Password Policy Generation System · IEEE Trans. Inf. Forensics Secur. 2018 Zero-Sum Password Cracking Game: A Large-Scale Empirical Study on the Crackability, Correlation, and Security of Passwords · IEEE Trans. Dependable Secur. Comput. 2017 |
Authentication and access control › password security
password policy |
0.3 | 1 | 2018 | DPPG: A Dynamic Password Policy Generation System · IEEE Trans. Inf. Forensics Secur. 2018 |
Authentication and access control › password security
password strength estimation |
0.3 | 1 | 2018 | DPPG: A Dynamic Password Policy Generation System · IEEE Trans. Inf. Forensics Secur. 2018 |
Authentication and access control › knowledge-based authentication
password |
0.3 | 1 | 2017 | Password correlation: Quantification, evaluation and application · INFOCOM 2017 |
Authentication and access control
password guessing |
0.3 | 1 | 2017 | Zero-Sum Password Cracking Game: A Large-Scale Empirical Study on the Crackability, Correlation, and Security of Passwords · IEEE Trans. Dependable Secur. Comput. 2017 |
Authentication and access control › password security
password strength |
0.3 | 1 | 2017 | Password correlation: Quantification, evaluation and application · INFOCOM 2017 |
Privacy and data protection
anonymization |
0.2 | 1 | 2016 | On the relative de-anonymizability of graph data: Quantification and evaluation · INFOCOM 2016 |
Authentication and access control › password security
password strength meter |
0.1 | 1 | 2017 | Password correlation: Quantification, evaluation and application · INFOCOM 2017 |
Methods — techniques the papers use, named apart from their topics
offline cracking simulation · 0.3diversity-based security metric · 0.3training-based cracking · 0.3statistical correlation analysis · 0.3empirical study · 0.3cracking algorithm comparison · 0.3structural importance analysis · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Multidiffusion Information Centrality for the Identification of Influential Spreaders in Temporal Social NetworksabstractIdentifying influential spreaders in a temporal social network, which has potential applications including network immunization, epidemic control, and viral marketing, is a fundamental class of problems. In this context, various centrality algorithms have been introduced to quantify influential spreaders, focusing on three categories: topology-based methods, dynamics-based methods, and machine learning-based methods. However, topology-based methods tend to consider single temporal features, while the consideration of multi-temporal features is subject to the same challenges of high temporal complexity as dynamics-based methods, and machine learning-based methods face challenges related to dependency on the training dataset. In this paper, we propose a novel centrality algorithm based on multiple diffusion information (RPT: Multi-diffusion information centrality based on R-path trees) to identify the influential node in a temporal social network. This algorithm considers three different temporal features and has lower temporal complexity using a newly proposed representation structure known as an R-path tree (a distinctive inverted tree that encompasses the earliest arrival paths from other nodes to the root node). Through experiments carried out on 12 empirical social networks, the results show that the effectiveness of RPT in identifying influential spreaders generally exceeds that of other baseline measures. Xuelong Yu, Shukun Yang, Hai Zhao 0002, Kuan Zhang 0001, Chong Yu 0002 |
IEEE Internet Things J. | 2 |
| 2018 | DPPG: A Dynamic Password Policy Generation SystemabstractTo keep password users from creating simple and common passwords, major websites and applications provide a password-strength measure, namely a password checker. While critical requirements for a password checker to be stringent have prevailed in the study of password security, we show that regardless of the stringency, such static checkers can leak information and actually help the adversary enhance the performance of their attacks. To address this weakness, we propose and devise the Dynamic Password Policy Generator, namely DPPG, to be an effective and usable alternative to the existing password strength checker. DPPG aims to enforce an evenly-distributed password space and generate dynamic policies for users to create passwords that are diverse and that contribute to the overall security of the password database. Since DPPG is modular and can function with different underlying metrics for policy generation, we further introduce a diversity-based password security metric that evaluates the security of a password database in terms of password space and distribution. The metric is useful as a countermeasure to well-crafted offline cracking algorithms and theoretically illustrates why DPPG works well. Shukun Yang, Shouling Ji, Raheem A. Beyah |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2017 | Password correlation: Quantification, evaluation and applicationabstractIn this paper, we study the correlation between passwords across different datasets which quantitatively explains the success of existing training-based password cracking techniques. We also study the correlation between a user's password and his/her social profile. This enabled us to develop the first social profile-aware password strength meter, namely SociaLShield. Our quantification techniques and SocialShield have meaningful implications to system administrators, users, and researchers, e.g., helping them quantitatively understand the threats posed by a password leakage incident, defending against emerging profile-based password attacks, and facilitating the research of countermeasures against existing and newly developed training-based password attacks. We validate our proposed quantification techniques and SocialShield through extensive experiments by leveraging real-world leaked passwords. Experimental results demonstrate that our quantification techniques are accurate in measuring correlation among different leaked datasets and that although SocialShield is light-weight, it is effective in defending against profile-based password attacks. Shouling Ji, Shukun Yang, Anupam Das 0001, Xin Hu 0001, Raheem A. Beyah |
INFOCOM | 2 |
| 2017 | Zero-Sum Password Cracking Game: A Large-Scale Empirical Study on the Crackability, Correlation, and Security of PasswordsabstractIn this paper, we conduct a large-scale study on the crackability, correlation, and security of 145 million real world passwords, which were leaked from several popular Internet services and applications. To the best of our knowledge, this is the largest empirical study that has been conducted. Specifically, we first evaluate the crackability of 145 million real world passwords against 6+ state-of-the-art password cracking algorithms in multiple scenarios. Second, we examine the effectiveness and soundness of popular commercial password strength meters (e.g., Google, QQ) and the security impacts of username/email leakage on passwords. Finally, we discuss the implications of our results, analysis, and findings, which are expected to help both password users and system administrators to gain a deeper understanding of the vulnerability of real passwords against state-of-the-art password cracking algorithms, as well as to shed light on future password security research topics. Shouling Ji, Shukun Yang, Xin Hu 0001, Weili Han, Zhigong Li, Raheem A. Beyah |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2016 | On the relative de-anonymizability of graph data: Quantification and evaluationabstractIn this paper, we propose a structural importance-aware approach to quantify the vulnerability/de-anonymizability of graph data to structure-based De-Anonymization (DA) attacks [1][2][3][4]. Specifically, we quantify both the seed-based and the seed-free Relative De-anonymizability (RD) of graph data for both perfect DA (successfully de-anonymizing all the target users) and partial DA (where some DA error is tolerated) under a general data model. In our relative quantification, instead of treating all the users in graph data as structurally equivalent, we adaptively quantify their RD in terms of their structural importance. Leveraging 15 real world graph datasets, we validate the accuracy of our relative quantifications and compare them with state-of-the-art seed-based and seed-free quantification techniques. The results demonstrate that our structural importance-aware relative quantifications are more sound and precise when measuring graph data's real vulnerability/de-anonymizability. Shouling Ji, Shukun Yang, Prateek Mittal, Raheem A. Beyah |
INFOCOM | 3 |
| 2015 | PARS: A Uniform and Open-source Password Analysis and Research SystemabstractIn this paper, we introduce an open-source and modular password analysis and research system, PARS, which provides a uniform, comprehensive and scalable research platform for password security. To the best of our knowledge, PARS is the first such system that enables researchers to conduct fair and comparable password security research. PARS contains 12 state-of-the-art cracking algorithms, 15 intra-site and cross-site password strength metrics, 8 academic password meters, and 15 of the 24 commercial password meters from the top-150 websites ranked by Alexa. Also, detailed taxonomies and large-scale evaluations of the PARS modules are presented in the paper. Shouling Ji, Shukun Yang, Ting Wang 0006, Changchang Liu, Wei-Han Lee, Raheem A. Beyah |
ACSAC | 2 |