Yingjie Xue

dblp:176/5678 · DBLP profile ↗
← Back
42ranked-venue papers
6as first author
25since 2021 · last 2026
0000-0003-1421-5427ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 17 · 3 first-author · 13 since 2021Graphics, computer vision, multimedia, augmented reality and games · 8Systems, architecture and hardware · 7 · 1 first-author · 5 since 2021Computer networks · 7 · 1 first-author · 5 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 SHARP: Self-adaptive Harmful Category-aware Prompt Generation for Black-box Jailbreaking
abstract
Large Language Models (LLMs) have been widely applied in various domains such as education and healthcare, making safety assurance crucial.Jailbreak attacks, a method used in red-teaming, can help evaluate and improve the defensive strategies of LLMs.However, existing jailbreak methods often overlook the semantic differences across categories of harmful questions, leading to inconsistent success rates and reduced overall attack effectiveness.We propose the first category-aware jailbreak framework, SHARP, which incorporates the semantic category of harmful questions into prompt generation.Trained on a verified jailbreak dataset, SHARP enables the model to learn category-specific semantic features and adaptively generate prompts that bypass safety mechanisms.The method combines two-stage LoRA fine-tuning, and DPO-based reinforcement learning to optimize both attack success and category alignment.Experiments show that SHARP significantly improves attack success rates and achieves better cross-category robustness compared to the state-of-the-art (SOTA) baselines, providing an efficient and scalable tool for evaluating LLM safety.
Yingjie Xue, Xingyou Xia, Yunbo Cao, Dengpan Ye, Guotong Geng
ACL (1)1
2026 Covert and Efficient DNS Traffic Loop Attacks Based on Intermediate Devices
Jiasi Sun, Lutong Chen, XuanChao Xie, Yingjie Xue, Kaiping Xue
ICC5
2026 VN-Dict: Lightweight Authenticated Spatial Queries over Hybrid-Storage Blockchain
Yunshu Wang, Yingjie Xue, Meiqi Li, Lutong Chen, Kaiping Xue
ICC2
2026 BLAS: A Blockchain-Enabled Efficient and Verifiable Log Audit System With Hybrid Storage
abstract
A reliable log audit system is a fundamental tool for efficient security management and attack detection. Blockchain has emerged as a prominent technology for building log audit systems, thanks to its non-repudiation and immutability properties. However, current blockchain-based solutions are computationally intensive and typically rely on coarse-grained queries, making them impractical for real-world systems. Therefore, we propose a blockchain-based verifiable log audit system, BLAS, which adopts three novel techniques. Firstly, we propose a novel data structure called the Index-Object Merkle Forest (IOMF), which combines modified Merkle Tree data structures and keyword-range bitmap indexes to support efficient log auditing. Secondly, we propose a hierarchical extension of IOMF to create an Authenticated Layered Index Structure (ALIS). ALIS enables fine-grained auditing at the entry level. Finally, we propose two optimization techniques in ALIS to reduce computational and communication costs. The performance evaluation confirms that BLAS is consistently faster than the baseline solutions with similar settings in various experiments, achieving speedups of hundreds to over ten thousand times for the most challenging workloads.
Xuanbo Huang, Mingrui Ai, Kaiping Xue, Yingjie Xue, Hyundong Shin
IEEE Trans. Dependable Secur. Comput.7
2026 FairRelay: Fair Off-Chain Incentives for Decentralized Physical Infrastructure Networks
abstract
Decentralized Physical Infrastructure Networks (DePINs) utilize token incentives to construct permissionless physical infrastructure, but face challenges in ensuring fair compensation for resource contributors. Focusing on bandwidth provision in decentralized data delivery, existing decentralized incentive mechanisms incur prohibitive on-chain costs or employ oversimplified network topologies. We proposeFairRelay, a protocol enablingfair,cost-efficientpayments incomplex multi-hop data delivery. We design two cryptographic primitives: 1)Accountable Multi-hop Data Delivery (AMDD)guaranteeing either correct data receipt or verifiable proof of misbehavior, reducing fair compensation to fee-for-secret exchange; and 2)Enforceable Accumulative HTLC (Enforceable A-HTLC)enabling atomic settlement across multiple off-chain payments via Payment Channel Networks (PCNs). FairRelay's fairness is formally proven within the Universal Composability (UC) framework. Evaluations demonstrate that FairRelay achieveszeroon-chain costs in optimistic execution. Pessimistic scenarios incur constant-cost disputes (O(1) complexity), achieving 13.5% lower overhead than FDE (CCS'24), the state-of-the-art simplified two-party exchange solution (no relays). FairRelay achieves over$95\%$encoding efficiency in 10-hop transmissions.
Yingjie Xue, Zifan Peng, Chao Lin 0003, Jianan Hong, Xinyi Huang 0001
IEEE Trans. Dependable Secur. Comput.1
2026 MSDT: A Secure Blockchain-Based Multi-Subset Data Trading Protocol With Atomicity and Quality Guarantees
abstract
Access to high-quality data resources is fundamental for generating insights, making decisions, and fostering innovation across various sectors. Data trading makes this possible, by which businesses, researchers, and developers can acquire the critical datasets necessary to propel forward-thinking developments. Traditionally, data trading is conducted through centralized platforms, which face challenges such as single points of failure and user mistrust. To address these issues, blockchain-based data trading protocols have been proposed, offering an alternative way for data trading with no trusted third-party involvement. However, ensuring trading atomicity (i.e. the data requester gets the data and the data owner gets the payment atomically) and data quality in the absence of a trusted third party is challenging. This paper introduces MSDT, a blockchain-based data trading protocol that guarantees trading atomicity and data quality. MSDT is a multi-subset data trading protocol, allowing users to verify data quality during the trading process. In MSDT, a state channel-based trading contract is designed, which reduces on-chain costs while ensuring transactions are executed atomically. Additionally, to deal with potential malicious behaviors of data owners, a staking mechanism and trading strategy are provided. Security and performance analyses demonstrate that MSDT ensures trading atomicity and data quality verification while maintains efficiency comparable to existing solutions.
Kaping Xue, Jiawen An, Yingjie Xue, Wentuo Sun
IEEE Trans. Dependable Secur. Comput.4
2026 Secure Acceleration of Aggregation Queries Over Homomorphically Encrypted Databases
Jinjiang Yang, Chunyi Zhang, Feng Liu 0059, Yingjie Xue, Kaiping Xue
IEEE Trans. Inf. Forensics Secur.4
2026 IFAD: Privacy-Preserving Isolation Forest-Based Anomaly Detection in Public Cloud Environments
abstract
Anomaly detection plays a vital role in processing multi-source data through public cloud servers, yet existing privacy-preserving schemes fail to efficiently detect anomalies while protecting data source privacy. Although isolation forest offer advantages for unsupervised high-dimensional data analysis, implementing its tree-based privacy-preserving mechanisms remains challenging. In this paper, we propose IFAD, a novel isolation forest-based scheme for detecting anomalies in private data. IFAD guarantees end-to-end privacy protection by safeguarding original data, tree structures, and intermediate information throughout detection workflows. Our design achieves efficiency through three key contributions: 1) Cryptographic building blocks combining function secret sharing (FSS) and secret sharing (SS) to enable secure computations; 2) A split index protocol and layer update protocol to facilitate efficient, layer-by-layer isolation forest construction; 3) A detection phase optimization converting the anomaly score calculations into lookup table operations. Experimental evaluations demonstrate that IFAD achieves superior performance, outperforming prior schemes by 2.4×-3.1× in runtime under LAN and WAN environments, and by 1.8×-7.8× in online communication overhead, while maintaining comparable detection accuracy. Our solution establishes an effective balance between privacy preservation and operational efficiency for cloud-based anomaly detection.
Jingcheng Zhao, Kaiping Xue, Meng Li 0006, Yingjie Xue, Yaxuan Huang
IEEE Trans. Inf. Forensics Secur.4
2026 PUF-Based Lightweight Decentralized Authentication for UAV Networks
abstract
Authentication and Key Agreement (AKA) are essential for UAV networks operating in open and hostile environments, as they assist in preventing common threats such as impersonation and replay attacks. However, traditional protocols often rely on a centralized server for key and identity management, creating risks of key leakage and a single point of failure. To address these issues, we propose a blockchain-based decentralized authentication mechanism that remains effective even under partial node compromise. Our design adopts Physical Unclonable Functions (PUFs) in place of key-based authentication to mitigate key leakage risk. To mitigate machine learning (ML) attacks inherent in existing PUF-based protocols, we design a lightweight Encrypted Randomized Challenge-Response Pair (ERCRP) structure, which incorporates external randomness to obfuscate underlying PUF mapping. Meanwhile, to address CRP leakage in prior centralized schemes, we combine Shamir's Secret Sharing and blockchain for secure CRP management. Specially, we introduce a decoupled design that separates interaction-intensive secret reconstruction process from blockchain consensus to ensure high efficiency. Finally, we develop a lightweight commitment-based management mechanism to prevent unauthorized CRP consumption and reuse from malicious authentication attempts. Additionally, the protocol provides UAV identity untraceability via dynamic identity updates. Comprehensive formal and informal security analyses, together with comparative performance evaluations, demonstrate the protocol's strong security guarantees and practical efficiency.
Kaiping Xue, Mingrui Ai, Yingjie Xue, Lutong Chen, Jian Li 0031, David S. L. Wei
IEEE Trans. Mob. Comput.4
2025 Efficient Privacy-Preserving Outsourced PCA with Optimized Matrix Update Operator
abstract
Principal component analysis (PCA) is an essential algorithm for dimensionality reduction in various data analysis tasks. Recently, PCA has gained widespread use in cloud outsourcing services due to its effectiveness and versatility. However, privacy concerns in outsourced PCA have led to the development of privacy-preserving schemes. Despite this, existing solutions face significant performance bottlenecks due to the iterative matrix computations involved in PCA, resulting in high overhead that limits their practicality. In this paper, we propose an efficient privacy-preserving outsourced PCA scheme. Specifically, we propose a secure Jacobi-EVD protocol, which improves efficiency by reducing nonlinear operations and iterations. Furthermore, by optimizing the matrix update operator in Jacobi-EVD using a hybrid protocol, we significantly reduce the communication overhead and communication rounds in iterative matrix computations. Security analysis demonstrates that our scheme preserves the privacy of data and PCA results. Performance evaluation shows our scheme significantly reduces 29.3× communication overhead compared to existing schemes.
Yuyang Fu, Yaxuan Huang, Yuandong Xie, Jingcheng Zhao, Yingjie Xue, Kaiping Xue
GLOBECOM5
2025 DPPDI: Efficient Distributed Privacy-Preserving Data Integration for Large Datasets
abstract
Privacy-preserving data integration (PPDI) is a secure method to integrate datasets from different data sources while protecting the privacy of data. Existing PPDI work usually uses the outsourced framework and executes data integration through a cloud server. Due to the need to protect the privacy of the relations between IDs and associated data, the associated data must be encrypted or blinded before uploading to the cloud server, which leads to poor performance. For the efficient PPDI solution, we first carefully analyze the privacy goals of PPDI. After that, we adopt the distributed computing model, and then propose a multi-party PPDI protocol named DPPDI. Our scheme removes the overhead caused by encrypting associated data while protecting privacy, and realizes the outer join functionality and arbitrary combination of data sources. Besides, to avoid dropping records when duplicate IDs exist, we propose a method embedded into the PPDI protocol to handle duplicate IDs. Finally, we conduct extensive experiments to evaluate our scheme's performance, and the result shows that our scheme outperforms previous PPDI schemes.
Jiaer Jiang, Jinjiang Yang, Jingcheng Zhao, Yingjie Xue, Kaiping Xue
ICC4
2025 ContractDB: Enabling Secure and Efficient DApps via Integrating Blockchain and External VDBs
abstract
The rapid growth of blockchain-based decentralized applications (DApps) highlights blockchain's potential to enhance application security. However, expensive on-chain data storage limits the deployment of DApps with large datasets. Additionally, DApp development tools, such as Ethereum smart contracts, lack support for complex queries, further hindering dataintensive DApps. To address the challenges of expensive storage and inability of complex queries, we propose ContractDB, a framework that integrates external verifiable databases (VDBs) with blockchain DApps. ContractDB offloads data storage and processing to VDBs, thereby reducing on-chain storage costs and enhancing data handling capabilities. Existing VDBs incur high verification costs and lack support for public verifiable update. In this paper, we propose a novel VDB design using authenticated dictionaries and authenticated set operations to reduce verification cost and enable verifiable updates. Performance evaluations show that ContractDB can verify the results of 6-condition conjunction (with mixed equivalent and range) queries on a 220-line data table within 2.4 million gas cost, with potential for optimization. For comparison, storing those data in contracts requires over 36 billion gas and still cannot support range or multi-condition queries. Therefore, the proposed ContractDB makes it feasible to support DApps with large datasets.
Meiqi Li, Yunshu Wang, Yingjie Xue, Kaiping Xue, Lutong Chen
ICPADS3
2025 AranVoting: Ensuring Anonymity and Fairness in Blockchain-Based Ranked-Choice Voting
abstract
Electronic voting is crucial for contemporary democratic processes. However, conventional systems often struggle with a single point of failure and insufficient support for intricate voting semantics, especially in ranked-choice elections requiring distinct ranking constraints. Although blockchain technology enhances fault tolerance and auditability, existing blockchainbased solutions primarily focus on simpler voting schemes, encountering difficulties in effectively verifying privacy-preserving ranked ballots. To address this gap, we propose AranVoting, an innovative blockchain-based ranked-choice voting scheme designed to ensure anonymity and fairness through homomorphic encryption. AranVoting employs a structured matrix ballot format alongside zero-knowledge proof to ensure the correctness of the ballot format. Furthermore, we introduce a smart contractdriven counting mechanism that facilitates the availability and transparency of ballot tallying through gradient incentive and committee election algorithms. Our security and performance evaluations demonstrate that AranVoting provides secure rankedchoice voting, effectively guaranteeing essential security properties such as anonymity, correctness, and verifiability while maintaining practicality and reasonable computational overhead throughout the voting process.
Meiqi Li, Qiantong Jiang, Wentuo Sun, Yingjie Xue, Kaiping Xue
ICPADS5
2025 Cross-Chain Options: A Bridgeless, Universal, and Efficient Approach
abstract
Options are fundamental to blockchain-based financial services, offering essential tools for risk management and price speculation, which enhance liquidity, flexibility, and market efficiency in decentralized finance (DeFi). Despite the growing interest in options for blockchain-resident assets, such as cryptocurrencies, current option mechanisms face significant challenges, including a high reliance on trusted third parties, limited asset support, high trading delays, and the requirement for option holders to provide upfront collateral. In this paper, we present a protocol that addresses the aforementioned issues. Our protocol is the first to eliminate the need for holders to post collateral when establishing options in trustless service environments (i.e., without a cross-chain bridge), which is achieved by introducing a guarantee from the option writer. Its universality allows for cross-chain options involving nearly any assets on any two different blockchains, provided the chains' programming languages can enforce and execute the necessary contract logic. Another key innovation is reducing option position transfer latency, which uses Double-Authentication-Preventing Signatures (DAPS). Our evaluation demonstrates that the proposed scheme reduces option transfer latency to less than half of that in existing methods. Rigorous security analysis proves that our protocol achieves secure option trading, even when facing adversarial behaviors.
Zifan Peng, Yingjie Xue
ICWS2
2025 A Privacy-Preserving and Highly Fault-Tolerant Cross-Chain Atomic Swap Scheme
abstract
As the blockchain ecosystem continues to diversify, the lack of interoperability among heterogeneous blockchain systems has become a critical bottleneck, leading to fragmented data silos and limited collaboration. Although numerous cross-chain protocols—such as atomic swaps, sidechains, and relay-based mechanisms—have been introduced to address this issue, they often face significant challenges related to privacy, security, and decentralization. In this paper, we propose a novel cross-chain protocol that enhances traditional hash-locking mechanisms by integrating zero-knowledge proofs and chameleon hash functions. Our approach ensures strong path confidentiality, such that reconstructing the payment path is computationally infeasible under the discrete logarithm assumption, even in partially compromised networks. Additionally, we introduce a multi-path atomic swap framework that supports concurrent routing and preserves transactional autonomy, enabling users to flexibly select preferred payment paths. We evaluate the performance through theoretical analysis and simulation. Comparative results demonstrate that our solution achieves secure atomicity with minimal trust assumptions and improved latency compared to existing methods.
Jianan Hong, Yingjie Xue, Jiayue Zhou
TrustCom3
2025 Structurally-Encrypted Databases Combined With Filters: Enhanced Security and Rich Queries
abstract
Building encrypted databases has been a long-standing challenge in the field of database security. In recent years, Structured Encryption (STE) has emerged as a promising approach to constructing encrypted databases, striking a balance between security and efficiency. Although existing STE-based encrypted database systems achieve high efficiency in query processing, all these schemes struggle to support rich queries with minimal information leakage. In this paper, we present a new STE-based encrypted database system, named Filter-integrated Encrypted Database (FinEDB), which supports exact-match and range queries, conjunctive queries and join operations, while maintaining limited information leakage. We first design a novel secure inverted index to avoid storage overhead blow-up when extending to support rich query capabilities. Then, we integrate Binary Fuse filters into our proposed inverted index to enable efficient query processing. By leveraging the homomorphic property of Binary Fuse filters, our approach leaks less information than existing STE-based solutions. Besides, we provide rigorous proof for our proposed scheme under the simulation paradigm. To evaluate the performance, we implement the prototype of FinEDB and compare it with the baseline STE-based scheme. Experiment results demonstrate that FinEDB is practical and can support rich queries on real-world databases.
Feng Liu 0059, Jinjiang Yang, Jingcheng Zhao, Yingjie Xue, Kaiping Xue
IEEE Trans. Inf. Forensics Secur.4
2025 Privacy-Preserving Statistical Analysis With Low Redundancy Over Task-Relevant Microdata
abstract
Privacy-preserving statistical analysis enables the data center to analyze datasets from multiple data owners, extracting valuable insights while safeguarding privacy. However, the observation of microdata involvement in various analysis tasks within the data center can indirectly lead to privacy breaches. For instance, when the data center observes microdata involved in a disease-related task, it may reveal information about the corresponding user’s disease. Existing schemes process the entire dataset for each analysis task to prevent privacy breaches, resulting in significant redundancy overhead due to the large amount of task-irrelevant data involved in processing. In this paper, we propose FDC, which can protect privacy and effectively reduce the redundancy overhead. It frees the data center from huge redundancy overhead. Specifically, we propose a co-design of local differential privacy and multiparty computation with preprocessing by the data owner. This design enables the data center to process only task-relevant and LDP noise-induced microdata instead of the entire dataset while maintaining analysis results without accuracy loss. In some scenarios where preprocessing by the data owner is unfeasible, we present a data center-assisted method to complete preprocessing within the data center. Additionally, we design and optimize a secure shuffle protocol within this method. Finally, we implement and evaluate FDC using the aggregation task as a baseline. With different proportions of task-relevant microdata, experimental results show that the runtime of FDC is 2~11x faster than existing schemes on LAN and 2~22x on WAN, and the communication overhead is up to 3~153x lower.
Jingcheng Zhao, Kaiping Xue, Yingjie Xue, Meng Li 0006, Bin Zhu 0010, Shaoxian Yuan
IEEE Trans. Inf. Forensics Secur.3
2024 Distributed runtime verification of metric temporal properties
Ritam Ganguly, Yingjie Xue, Aaron Jonckheere, Parker Ljung, Benjamin Schornstein, Borzoo Bonakdarpour, Maurice Herlihy
J. Parallel Distributed Comput.2
2024 A Secure and Efficient Blockchain Sharding Scheme via Hybrid Consensus and Dynamic Management
abstract
Sharding significantly enhances blockchain scalability by dividing the entire network into smaller shards that reach consensus and process transactions in parallel. Nevertheless, two new issues emerge with the adoption of sharding. One issue involves the shrinking size of consensus groups, which leads to vulnerability in consensus. Most existing works introduce periodic shuffle mechanisms to mitigate this problem. Nevertheless, these measures necessitate stronger security assumptions and can only offer a probabilistic assurance of consensus security. Another issue is the challenge in processing cross-shard transactions posed by the isolation of shards. Existing approaches utilize two-phase commit (2PC) or relay transaction mechanisms to handle cross-shard transactions. However, these approaches are vulnerable to double cross-shard attacks from malicious shards and are unable to achieve immediate atomicity. In this paper, to address the vulnerable consensus issue and achieve instant atomicity in cross-shard transactions, we design a hybrid consensus mechanism that embeds a lightweight global consensus into parallel intra-shard consensus processes. The global consensus allows all consensus nodes to jointly process cross-shard transactions, achieving cross-shard transaction instant atomicity. It also records shard snapshots to facilitate shard auditing to defend against malicious shards. Furthermore, we consider the performance of the proposed mechanism, and design a dynamic shard management mechanism. The dynamic shard management mechanism reduces transaction congestion and maintains an appropriate number of shards based on the system’s state. We conduct analyses of potential attacks and prove that our approach ensures safety and liveness even in the presence of malicious shards. We also evaluate the performance of our system and compare it with both non-sharded and classic blockchain-sharding systems. The evaluation results demonstrate the efficacy of our approach in dealing with transaction congestion while astutely controlling the number of shards.
Meiqi Li, Kaiping Xue, Yingjie Xue, Wentuo Sun, Jian Li 0031
IEEE Trans. Inf. Forensics Secur.4
2022 Transferable Cross-Chain Options
abstract
An option is a financial agreement between two parties to trade two assets. One party is given the right, but not the obligation, to complete the swap before a specified termination time. In today's financial markets, an option is considered an asset which can itself be transferred: while an option is active, one party can sell its rights (or obligations) to another.
Daniel Engel, Yingjie Xue
AFT2
2022 Distributed Runtime Verification of Metric Temporal Properties for Cross-Chain Protocols
abstract
Transactions involving multiple blockchains are implemented by cross-chain protocols. These protocols are based on smart contracts, programs that run on blockchains, executed by a network of computers. Verifying the runtime correctness of smart contracts is a problem of compelling practical interest since, smart contracts can automatically transfer ownership of cryptocurrencies, electronic securities, and other valuable assets among untrusting parties. Such verification is challenging since smart contract execution is time sensitive, and the clocks on different blockchains may not be perfectly synchronized. This paper describes a method for runtime monitoring of blockchain executions. First, we propose a generalized runtime verification technique for verifying partially synchronous distributed computations for the metric temporal logic (MTL) by exploiting bounded-skew clock synchronization. Second, we introduce a progression-based formula rewriting scheme for monitoring MTL specifications which employs SMT solving techniques and report experimental results.
Ritam Ganguly, Yingjie Xue, Aaron Jonckheere, Parker Ljung, Benjamin Schornstein, Borzoo Bonakdarpour, Maurice Herlihy
ICDCS2
2022 Invited Paper: Cross-Chain State Machine Replication
Yingjie Xue, Maurice Herlihy
SSS1
2021 Hedging Against Sore Loser Attacks in Cross-Chain Transactions
abstract
A sore loser attack in cross-blockchain commerce rises when one party decides to halt participation partway through, leaving other parties' assets locked up for a long duration. Although vulnerability to sore loser attacks cannot be entirely eliminated, it can be reduced to an arbitrarily low level. This paper proposes new distributed protocols for hedging a range of cross-chain transactions in a synchronous communication model, such as two-party swaps, n-party swaps, brokered transactions, and auctions.
Yingjie Xue, Maurice Herlihy
PODC1
2021 Failure is (literally) an Option: Atomic Commitment vs Optionality in Decentralized Finance
Daniel Engel, Maurice Herlihy, Yingjie Xue
SSS3
2021 Secure Halftone Image Steganography Based on Pixel Density Transition
abstract
Most state-of-the-art halftone image steganographic techniques only consider the flipping distortion according to the human visual system, which are not always secure when they are attacked by steganalyzers. In this paper, we propose a halftone image steganographic scheme that aims to generate stego images with good visual quality and strong statistical security of anti-steganalysis. First, the concept of pixel density is proposed and a novel construction called pixel density histogram (PDH) is proposed to design a “embedding” scheme for halftone images. Then, we optimize density pair selection to select density blocks that can improve visual quality. Finally, the messages are embedded through pixel density transition, where a novel pixel flipping strategy is proposed, which can maintain the structural dependence by optimizing the pixel mesh Markov transition matrix (PMMTM). The experimental results demonstrate that the proposed steganography scheme can achieve strong statistical security of anti-steganalysis with good visual quality without degrading the embedding capacity.
Wei Lu 0001, Yingjie Xue, Yuileong Yeung, Hongmei Liu 0001, Jiwu Huang, Yun Q. Shi 0001
IEEE Trans. Dependable Secur. Comput.2
2020 Upscaling factor estimation on double JPEG compressed images
Xianjin Liu, Wei Lu 0001, Yingjie Xue, Yuileong Yeung
Multim. Tools Appl.3
2020 Secure Binary Image Steganography With Distortion Measurement Based on Prediction
abstract
In this paper, a binary image steganographic scheme is presented, which aims at minimizing the embedding distortions measured by prediction. A prediction model of the center pixel's value is established in a 3 × 3 local region. A concept of “uncertainty” is introduced to represent the prediction result and the uncertainty is defined as the proximity of probabilities about whether the center pixel is black or white. A pixel with high uncertainty means that it is hard to distinguish whether it has been flipped or not, and thus the distortion introduced by flipping this pixel is small. The uncertainty is an appended statistical explanation of human visual perception and the distortion measurement based on it can evaluate the embedding changes on both vision and statistics. Benefiting from the statistics, uncertainty can evaluate the distortion influence in an extended local region. To play the advantage of distortion measurement, the syndrome-trellis code (STC) is employed to minimize the embedding distortions. Comparisons with prior schemes demonstrate that the proposed steganographic scheme achieves high vision imperceptibility and statistical security.
Yuileong Yeung, Wei Lu 0001, Yingjie Xue, Jiwu Huang, Yun Q. Shi 0001
IEEE Trans. Circuits Syst. Video Technol.3
2020 TAFC: Time and Attribute Factors Combined Access Control for Time-Sensitive Data in Public Cloud
abstract
The new paradigm of outsourcing data to the cloud is a double-edged sword. On the one hand, it frees data owners from the technical management, and is easier for data owners to share their data with intended users. On the other hand, it poses new challenges on privacy and security protection. To protect data confidentiality against the honest-but-curious cloud service provider, numerous works have been proposed to support fine-grained data access control. However, till now, no schemes can support both fine-grained access control and time-sensitive data publishing. In this paper, by embedding timed-release encryption into Ciphertext-Policy Attribute-based Encryption (CP-ABE), we propose a new time and attribute factors combined access control on time-sensitive data for public cloud storage (named TAFC). Based on the proposed scheme, we further propose an efficient approach to design access policies faced with diverse access requirements for time-sensitive data. Extensive security and performance analysis shows that our proposed scheme is highly efficient and satisfies the security requirements for time-sensitive data storage in public cloud.
Jianan Hong, Kaiping Xue, Yingjie Xue, Weikeng Chen, David S. L. Wei, Nenghai Yu, Peilin Hong
IEEE Trans. Serv. Comput.3
2019 Scaling factor estimation on JPEG compressed images by cyclostationarity analysis
Xianjin Liu, Wei Lu 0001, Hongmei Liu 0001, Yingjie Xue, Yuileong Yeung
Multim. Tools Appl.5
2019 Copy move forgery detection based on keypoint and patch match
Wei Lu 0001, Cong Lin 0003, Xinchao Huang, Xianjin Liu, Yuileong Yeung, Yingjie Xue
Multim. Tools Appl.7
2019 Secure binary image steganography based on LTP distortion minimization
Yuileong Yeung, Wei Lu 0001, Yingjie Xue, Junjia Chen
Multim. Tools Appl.3
2019 Reversible data hiding in binary images based on image magnification
Wei Lu 0001, Hongmei Liu 0001, Yuileong Yeung, Yingjie Xue
Multim. Tools Appl.5
2019 Secure Binary Image Steganography Based on Fused Distortion Measurement
abstract
Some state-of-the-art binary image steganographic methods aim to generate stego images with good visual quality, while others focus more on the statistical security of the anti-steganalysis. This paper proposes a binary steganographic scheme that improves both of them by selecting more appropriate flipped pixels. First, a fused distortion measurement is developed that combines the advantages of flipping distortion measurement (FDM) and two data-carrying pixel location methods, including the edge adaptive grid method (EAG) and the “Connectivity Preserving” criterion (CPc). The FDM measures the distortion score by statistical features and achieves high-statistical security, while the EAG and CPc select pixels by analyzing the local texture structures based on visual quality. Then, to eliminate the interference brought by adjacent flipped pixels, a flipping position optimization strategy is proposed to find better positions for flipping pixels to further improve the steganographic performance. Experimental results have demonstrated that the proposed steganographic scheme can achieve stronger statistical security with better visual quality without degrading the embedding capacity.
Wei Lu 0001, Liyu He, Yuileong Yeung, Yingjie Xue, Hongmei Liu 0001, Bingwen Feng
IEEE Trans. Circuits Syst. Video Technol.4
2019 An Attribute-Based Controlled Collaborative Access Control Scheme for Public Cloud Storage
abstract
In public cloud storage services, data are outsourced to semi-trusted cloud servers which are outside of data owners' trusted domain. To prevent untrustworthy service providers from accessing data owners' sensitive data, outsourced data are often encrypted. In this scenario, conducting access control over these data becomes a challenging issue. Attribute-based encryption (ABE) has been proved to be a powerful cryptographic tool to express access policies over attributes, which can provide a fine-grained, flexible, and secure access control over outsourced data. However, the existing ABE-based access control schemes do not support users to gain access permission by collaboration. In this paper, we explore a special attribute-based access control scenario where multiple users having different attribute sets can collaborate to gain access permission if the data owner allows their collaboration in the access policy. Meanwhile, the collaboration that is not designated in the access policy should be regarded as a collusion and the access request will be denied. We propose an attribute-based controlled collaborative access control scheme through designating translation nodes in the access structure. Security analysis shows that our proposed scheme can guarantee data confidentiality and has many other critical security properties. Extensive performance analysis shows that our proposed scheme is efficient in terms of storage and computation overhead.
Yingjie Xue, Kaiping Xue, Na Gai, Jianan Hong, David S. L. Wei, Peilin Hong
IEEE Trans. Inf. Forensics Secur.1
2018 Copy-move detection of digital audio based on multi-feature decision
Zhaozhi Xie, Wei Lu 0001, Xianjin Liu, Yingjie Xue, Yuileong Yeung
J. Inf. Secur. Appl.4
2018 Binary image steganalysis based on local texture pattern
Wei Lu 0001, Yanmei Fang, Xianjin Liu, Yuileong Yeung, Yingjie Xue
J. Vis. Commun. Image Represent.6
2017 CABE: A New Comparable Attribute-Based Encryption Construction with 0-Encoding and 1-Encoding
abstract
Attribute-based encryption (ABE) has opened up a popular research topic in cryptography over the past few years. It can be used in various circumstances, as it provides a flexible way to conduct fine-grained data access control. Despite its great advantages in data access control, current ABE based access control system cannot satisfy the requirement well when the system judges the access behavior according to attribute comparison, such as “greater than x” or “less than x”, which are called comparable attributes in this paper. In this paper, based on a set of well-designed sub-attributes representing each comparable attribute, we construct a comparable attribute-based encryption scheme (CABE for short) to address the aforementioned problem. The novelty lies in that we provide a more efficient construction based on the generation and management of the sub-attributes with the notion of 0-encoding and 1-encoding. Extensive analysis shows that: Compared with the existing schemes, our scheme drastically decreases the storage, communication and computation overheads, and thus is more efficient in dealing with the applications with comparable attributes.
Kaiping Xue, Jianan Hong, Yingjie Xue, David S. L. Wei, Nenghai Yu, Peilin Hong
IEEE Trans. Computers3
2017 Two-Cloud Secure Database for Numeric-Related SQL Range Queries With Privacy Preserving
abstract
Industries and individuals outsource database to realize convenient and low-cost applications and services. In order to provide sufficient functionality for SQL queries, many secure database schemes have been proposed. However, such schemes are vulnerable to privacy leakage to cloud server. The main reason is that database is hosted and processed in cloud server, which is beyond the control of data owners. For the numerical range query (“>,” “<;,” and so on), those schemes cannot provide sufficient privacy protection against practical challenges, e.g., privacy leakage of statistical properties, access pattern. Furthermore, increased number of queries will inevitably leak more information to the cloud server. In this paper, we propose a two-cloud architecture for secure database, with a series of intersection protocols that provide privacy preservation to various numeric-related range queries. Security analysis shows that privacy of numerical information is strongly protected against cloud providers in our proposed scheme.
Kaiping Xue, Shaohua Li 0002, Jianan Hong, Yingjie Xue, Nenghai Yu, Peilin Hong
IEEE Trans. Inf. Forensics Secur.4
2017 RAAC: Robust and Auditable Access Control With Multiple Attribute Authorities for Public Cloud Storage
abstract
Data access control is a challenging issue in public cloud storage systems. Ciphertext-policy attribute-based encryption (CP-ABE) has been adopted as a promising technique to provide flexible, fine-grained, and secure data access control for cloud storage with honest-but-curious cloud servers. However, in the existing CP-ABE schemes, the single attribute authority must execute the time-consuming user legitimacy verification and secret key distribution, and hence, it results in a single-point performance bottleneck when a CP-ABE scheme is adopted in a large-scale cloud storage system. Users may be stuck in the waiting queue for a long period to obtain their secret keys, thereby resulting in low efficiency of the system. Although multi-authority access control schemes have been proposed, these schemes still cannot overcome the drawbacks of single-point bottleneck and low efficiency, due to the fact that each of the authorities still independently manages a disjoint attribute set. In this paper, we propose a novel heterogeneous framework to remove the problem of single-point performance bottleneck and provide a more efficient access control scheme with an auditing mechanism. Our framework employs multiple attribute authorities to share the load of user legitimacy verification. Meanwhile, in our scheme, a central authority is introduced to generate secret keys for legitimacy verified users. Unlike other multi-authority access control schemes, each of the authorities in our scheme manages the whole attribute set individually. To enhance security, we also propose an auditing mechanism to detect which attribute authority has incorrectly or maliciously performed the legitimacy verification procedure. Analysis shows that our system not only guarantees the security requirements but also makes great performance improvement on key generation.
Kaiping Xue, Yingjie Xue, Jianan Hong, Hao Yue 0001, David S. L. Wei, Peilin Hong
IEEE Trans. Inf. Forensics Secur.2
2016 LABAC: A Location-Aware Attribute-Based Access Control Scheme for Cloud Storage
abstract
Data access control is a challenging issue in cloud storage. Ciphertext-Policy Attribute-based Encryption (CP-ABE) is a potential cryptographic technique to address the above issue, which is able to enforce data access control based on users' permanent characteristics. However, in some scenarios, access policies are associated with users' temporary conditions (such as access time and location) as well as their permanent ones. CP-ABE cannot deal with such situations commendably. In this paper, we focus on the scenario where users' access privilege is determined by their attributes, together with their locations. To cope with this data access control requirement, we propose a location-aware attribute-based access control mechanism (LABAC) for cloud. In LABAC, we uniquely integrate CP-ABE with location trapdoors to make up access policies. In this way, data owners can flexibly combine both users' attributes and locations to implement a fine-grained control of their data. A competitive advantage of LABAC is that it requires no any additional revocation mechanisms to revoke location-aware access privilege when user location changes. Security and performance analysis are presented which show the security and efficiency of LABAC for practical implementations.
Yingjie Xue, Jianan Hong, Kaiping Xue, Peilin Hong
GLOBECOM1
2016 TMACS: A Robust and Verifiable Threshold Multi-Authority Access Control System in Public Cloud Storage
abstract
Attribute-based Encryption (ABE) is regarded as a promising cryptographic conducting tool to guarantee data owners’ direct control over their data in public cloud storage. The earlier ABE schemes involve only one authority to maintain the whole attribute set, which can bring a single-point bottleneck on both security and performance. Subsequently, some multi-authority schemes are proposed, in which multiple authorities separately maintain disjoint attribute subsets. However, the single-point bottleneck problem remains unsolved. In this paper, from another perspective, we conduct a threshold multi-authority CP-ABE access control scheme for public cloud storage, named TMACS, in which multiple authorities jointly manage a uniform attribute set. In TMACS, taking advantage of ($t,n$) threshold secret sharing, the master key can be shared among multiple authorities, and a legal user can generate his/her secret key by interacting with any$t$authorities. Security and performance analysis results show that TMACS is not only verifiable secure when less than$t$authorities are compromised, but also robust when no less than$t$authorities are alive in the system. Furthermore, by efficiently combining the traditional multi-authority scheme with TMACS, we construct a hybrid one, which satisfies the scenario of attributes coming from different authorities as well as achieving security and system-level robustness.
Kaiping Xue, Yingjie Xue, Jianan Hong
IEEE Trans. Parallel Distributed Syst.3
2015 TAFC: Time and Attribute Factors Combined Access Control on Time-Sensitive Data in Public Cloud
abstract
The new paradigm of outsourcing data to the cloud is a double-edged sword. On one side, it frees up data owners from the technical management, and is easier for the data owners to share their data with intended recipients when data are stored in the cloud. On the other side, it brings about new challenges about privacy and security protection. To protect data confidentiality against the honest-but-curious cloud service provider, numerous works have been proposed to support fine-grained data access control. However, till now, no efficient schemes can provide the scenario of fine-grained access control together with the capacity of time-sensitive data publishing. In this paper, by embedding the mechanism of timed-release encryption into CP-ABE (Ciphertext-Policy Attribute-based Encryption), we propose TAFC: a new time and attribute factors combined access control on time-sensitive data stored in cloud. Extensive security and performance analysis shows that our proposed scheme is highly efficient and satisfies the security requirements for time-sensitive data storage in public cloud.
Jia-An Hong, Kaiping Xue, Yingjie Xue
GLOBECOM4