Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Yinhao Jiang

dblp:182/0970 · DBLP profile ↗
← Back
7ranked-venue papers
4as first author
4since 2021 · last 2024
0000-0002-1733-9479ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 first-authorDatabases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Cryptographic primitives and cryptanalysis · 36% Systems and software security · 20% Malware analysis · 20%
Software engineering, system software, and programming languages
1 paper
Software maintenance and evolution · 100%
Human-computer interaction and pervasive computing
1 paper
Collaborative and social computing · 44% Wearable and physiological sensing · 44% Usability and user experience research · 13%

Topics — the 8 heaviest of 11, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Malware analysis › malware detection
malicious package detection
0.812024
Malicious Package Detection using Metadata Information · WWW 2024
Systems and software security
software supply chain security
0.812024
Malicious Package Detection using Metadata Information · WWW 2024
Software maintenance and evolution › software ecosystems
package repositories
0.812024
Malicious Package Detection using Metadata Information · WWW 2024
Software maintenance and evolution
software ecosystems
0.812024
Malicious Package Detection using Metadata Information · WWW 2024
Cryptographic primitives and cryptanalysis › public-key cryptography
public-key encryption
0.712023
Secure Replication-Based Outsourced Computation Using Smart Contracts · IEEE Trans. Serv. Comput. 2023
Cryptographic primitives and cryptanalysis › public-key cryptography › public-key encryption
public key encryption with equality test
0.712023
Secure Replication-Based Outsourced Computation Using Smart Contracts · IEEE Trans. Serv. Comput. 2023
Cryptographic protocols and secure computation
secure outsourcing
0.712023
Secure Replication-Based Outsourced Computation Using Smart Contracts · IEEE Trans. Serv. Comput. 2023
Blockchain and cryptocurrency security
smart contract
0.212023
Secure Replication-Based Outsourced Computation Using Smart Contracts · IEEE Trans. Serv. Comput. 2023

Methods — techniques the papers use, named apart from their topics

metadata feature extraction · 1.5machine learning classification · 1.5smart contract · 0.7security proof · 0.7predictive modeling · 0.6electroencephalography · 0.6
YearPublicationVenuePosition
2024 A Graph-Based Approach for Software Functionality Classification on the Web
Yinhao Jiang, Michael Bewong, Arash Mahboubi, Sajal Halder, Md. Rafiqul Islam 0001, Md Zahidul Islam 0001, Ryan H. L. Ip, Praveen Gauravaram, Minhui Xue 0001
WISE (5)1
2024 Malicious Package Detection using Metadata Information
abstract
Protecting software supply chains from malicious packages is paramount in the evolving landscape of software development. Attacks on the software supply chain involve attackers injecting harmful software into commonly used packages or libraries in a software repository. For instance, JavaScript uses Node Package Manager (NPM), and Python uses Python Package Index (PyPi) as their respective package repositories. In the past, NPM has had vulnerabilities such as the event-stream incident, where a malicious package was introduced into a popular NPM package, potentially impacting a wide range of projects. As the integration of third-party packages becomes increasingly ubiquitous in modern software development, accelerating the creation and deployment of applications, the need for a robust detection mechanism has become critical. On the other hand, due to the sheer volume of new packages being released daily, the task of identifying malicious packages presents a significant challenge. To address this issue, in this paper, we introduce a metadata-based malicious package detection model, MeMPtec. This model extracts a set of features from package metadata information. These extracted features are classified as either easy-to-manipulate (ETM) or difficult-to-manipulate (DTM) features based on monotonicity and restricted control properties. By utilising these metadata features, not only do we improve the effectiveness of detecting malicious packages, but also we demonstrate its resistance to adversarial attacks in comparison with existing state-of-the-art. Our experiments indicate a significant reduction in both false positives (up to 97.56%) and false negatives (up to 91.86%).
Sajal Halder, Michael Bewong, Arash Mahboubi, Yinhao Jiang, Md. Rafiqul Islam 0001, Md Zahidul Islam 0001, Ryan H. L. Ip, M. Ejaz Ahmed, Gowri Sankar Ramachandran, Muhammad Ali Babar 0001
WWW4
2023 Secure Replication-Based Outsourced Computation Using Smart Contracts
abstract
The replication-Based Outsourced Computation (RBOC) mechanism allows a client to outsource the same computing job to multiple contractors and the honest contractors will get paid in the incentivized system based on the fact that a majority of contractors will honestly perform the computation. As self-executing contracts, smart contracts are utilized in the decentralized blockchain networks to execute coded programs automatically transparently, and publicly. It is natural to apply smart contracts to RBOC to improve performance by setting smart contracts as the converter between the client and contractors to reduce the load on the client. However, it is infeasible to directly combine these two blocks together because the data including returned computing results from contractors in the decentralized blockchain are in the form of plaintexts such that some lazy contractors could copy others’ results as their own and still get paid, which will compromise the security of RBOC. The existing public-key encryption with equality test (PKEET) is a promising candidate solution to stop the above lazy contractors, where the results are encrypted by PKEET and then transferred without hindering smart contracts to compare the equality of underlying results. Unfortunately, we found that the advanced lazy contractors can still compromise security by forging ciphertexts to pass the equality test only with the encrypted results of other contractors. In this paper, to achieve security against lazy contractors, we introduce the notion of PKEET against lazy encryptors (PKEET-LE). Besides the fundamental property of PKEET that performs equality test on ciphertexts without decryption, PKEET-LE additionally realizes the security against the lazy encryptors who aim to forge a ciphertext for a given one to pass the equality test between them without the knowledge of the underlying plaintext. We further propose a concrete and practical PKEET-LE construction along with formal security proof. Finally, we conduct a performance evaluation to demonstrate that our PKEET-LE scheme is efficient and practical in the RBOC system using smart contracts.
Willy Susilo, Fuchun Guo, Zhen Zhao 0005, Yinhao Jiang, Chunpeng Ge 0001
IEEE Trans. Serv. Comput.4
2022 Understanding Social Influence in Collective Product Ratings Using Behavioral and Cognitive Metrics
abstract
Online platforms commonly collect and display user-generated information to support subsequent users’ decision-making. However, studies have noticed that presenting collective information can pose social influences on individuals’ opinions and alter their preferences accordingly. It is essential to deepen understanding of people’s preferences when exposed to others’ opinions and the underlying cognitive mechanisms to address potential biases. Hence, we conducted a laboratory study to investigate how products’ ratings and reviews influence participants’ stated preferences and cognitive responses assessed by their Electroencephalography (EEG) signals. The results showed that social ratings and reviews could alter participants’ preferences and affect their status of attention, working memory, and emotion. We further conducted predictive analyses to show that participants’ Electroencephalography-based measures can achieve higher power than behavioral measures to discriminate how collective information is displayed to users. We discuss the design implications informed by the results to shed light on the design of collective rating systems.
Fu-Yin Cherng, Jingchao Fang, Yinhao Jiang, Taejun Choi, Hao-Chuan Wang
CHI3
2018 Ciphertext-policy attribute-based encryption against key-delegation abuse in fog computing
Yinhao Jiang, Willy Susilo, Yi Mu 0001, Fuchun Guo
Future Gener. Comput. Syst.1
2016 Ciphertext-Policy Attribute-Based Encryption with Key-Delegation Abuse Resistance
Yinhao Jiang, Willy Susilo, Yi Mu 0001, Fuchun Guo
ACISP (1)1
2016 Ciphertext-Policy Attribute Based Encryption Supporting Access Policy Update
Yinhao Jiang, Willy Susilo, Yi Mu 0001, Fuchun Guo
ProvSec1