EDBT 2026 Demo / reviewers in the wild / expert
Yinhao Jiang
dblp:182/0970
· DBLP profile ↗
7ranked-venue papers
4as first author
4since 2021 · last 2024
0000-0002-1733-9479ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 first-authorDatabases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Cryptographic primitives and cryptanalysis · 36% Systems and software security · 20% Malware analysis · 20% | |
| Software engineering, system software, and programming languages
1 paper |
Software maintenance and evolution · 100% | |
| Human-computer interaction and pervasive computing
1 paper |
Collaborative and social computing · 44% Wearable and physiological sensing · 44% Usability and user experience research · 13% |
Topics — the 8 heaviest of 11, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Malware analysis › malware detection
malicious package detection |
0.8 | 1 | 2024 | Malicious Package Detection using Metadata Information · WWW 2024 |
Systems and software security
software supply chain security |
0.8 | 1 | 2024 | Malicious Package Detection using Metadata Information · WWW 2024 |
Software maintenance and evolution › software ecosystems
package repositories |
0.8 | 1 | 2024 | Malicious Package Detection using Metadata Information · WWW 2024 |
Software maintenance and evolution
software ecosystems |
0.8 | 1 | 2024 | Malicious Package Detection using Metadata Information · WWW 2024 |
Cryptographic primitives and cryptanalysis › public-key cryptography
public-key encryption |
0.7 | 1 | 2023 | Secure Replication-Based Outsourced Computation Using Smart Contracts · IEEE Trans. Serv. Comput. 2023 |
Cryptographic primitives and cryptanalysis › public-key cryptography › public-key encryption
public key encryption with equality test |
0.7 | 1 | 2023 | Secure Replication-Based Outsourced Computation Using Smart Contracts · IEEE Trans. Serv. Comput. 2023 |
Cryptographic protocols and secure computation
secure outsourcing |
0.7 | 1 | 2023 | Secure Replication-Based Outsourced Computation Using Smart Contracts · IEEE Trans. Serv. Comput. 2023 |
Blockchain and cryptocurrency security
smart contract |
0.2 | 1 | 2023 | Secure Replication-Based Outsourced Computation Using Smart Contracts · IEEE Trans. Serv. Comput. 2023 |
Methods — techniques the papers use, named apart from their topics
metadata feature extraction · 1.5machine learning classification · 1.5smart contract · 0.7security proof · 0.7predictive modeling · 0.6electroencephalography · 0.6
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | A Graph-Based Approach for Software Functionality Classification on the Web
Yinhao Jiang, Michael Bewong, Arash Mahboubi, Sajal Halder, Md. Rafiqul Islam 0001, Md Zahidul Islam 0001, Ryan H. L. Ip, Praveen Gauravaram, Minhui Xue 0001 |
WISE (5) | 1 |
| 2024 | Malicious Package Detection using Metadata InformationabstractProtecting software supply chains from malicious packages is paramount in the evolving landscape of software development. Attacks on the software supply chain involve attackers injecting harmful software into commonly used packages or libraries in a software repository. For instance, JavaScript uses Node Package Manager (NPM), and Python uses Python Package Index (PyPi) as their respective package repositories. In the past, NPM has had vulnerabilities such as the event-stream incident, where a malicious package was introduced into a popular NPM package, potentially impacting a wide range of projects. As the integration of third-party packages becomes increasingly ubiquitous in modern software development, accelerating the creation and deployment of applications, the need for a robust detection mechanism has become critical. On the other hand, due to the sheer volume of new packages being released daily, the task of identifying malicious packages presents a significant challenge. To address this issue, in this paper, we introduce a metadata-based malicious package detection model, MeMPtec. This model extracts a set of features from package metadata information. These extracted features are classified as either easy-to-manipulate (ETM) or difficult-to-manipulate (DTM) features based on monotonicity and restricted control properties. By utilising these metadata features, not only do we improve the effectiveness of detecting malicious packages, but also we demonstrate its resistance to adversarial attacks in comparison with existing state-of-the-art. Our experiments indicate a significant reduction in both false positives (up to 97.56%) and false negatives (up to 91.86%). Sajal Halder, Michael Bewong, Arash Mahboubi, Yinhao Jiang, Md. Rafiqul Islam 0001, Md Zahidul Islam 0001, Ryan H. L. Ip, M. Ejaz Ahmed, Gowri Sankar Ramachandran, Muhammad Ali Babar 0001 |
WWW | 4 |
| 2023 | Secure Replication-Based Outsourced Computation Using Smart ContractsabstractThe replication-Based Outsourced Computation (RBOC) mechanism allows a client to outsource the same computing job to multiple contractors and the honest contractors will get paid in the incentivized system based on the fact that a majority of contractors will honestly perform the computation. As self-executing contracts, smart contracts are utilized in the decentralized blockchain networks to execute coded programs automatically transparently, and publicly. It is natural to apply smart contracts to RBOC to improve performance by setting smart contracts as the converter between the client and contractors to reduce the load on the client. However, it is infeasible to directly combine these two blocks together because the data including returned computing results from contractors in the decentralized blockchain are in the form of plaintexts such that some lazy contractors could copy others’ results as their own and still get paid, which will compromise the security of RBOC. The existing public-key encryption with equality test (PKEET) is a promising candidate solution to stop the above lazy contractors, where the results are encrypted by PKEET and then transferred without hindering smart contracts to compare the equality of underlying results. Unfortunately, we found that the advanced lazy contractors can still compromise security by forging ciphertexts to pass the equality test only with the encrypted results of other contractors. In this paper, to achieve security against lazy contractors, we introduce the notion of PKEET against lazy encryptors (PKEET-LE). Besides the fundamental property of PKEET that performs equality test on ciphertexts without decryption, PKEET-LE additionally realizes the security against the lazy encryptors who aim to forge a ciphertext for a given one to pass the equality test between them without the knowledge of the underlying plaintext. We further propose a concrete and practical PKEET-LE construction along with formal security proof. Finally, we conduct a performance evaluation to demonstrate that our PKEET-LE scheme is efficient and practical in the RBOC system using smart contracts. Willy Susilo, Fuchun Guo, Zhen Zhao 0005, Yinhao Jiang, Chunpeng Ge 0001 |
IEEE Trans. Serv. Comput. | 4 |
| 2022 | Understanding Social Influence in Collective Product Ratings Using Behavioral and Cognitive MetricsabstractOnline platforms commonly collect and display user-generated information to support subsequent users’ decision-making. However, studies have noticed that presenting collective information can pose social influences on individuals’ opinions and alter their preferences accordingly. It is essential to deepen understanding of people’s preferences when exposed to others’ opinions and the underlying cognitive mechanisms to address potential biases. Hence, we conducted a laboratory study to investigate how products’ ratings and reviews influence participants’ stated preferences and cognitive responses assessed by their Electroencephalography (EEG) signals. The results showed that social ratings and reviews could alter participants’ preferences and affect their status of attention, working memory, and emotion. We further conducted predictive analyses to show that participants’ Electroencephalography-based measures can achieve higher power than behavioral measures to discriminate how collective information is displayed to users. We discuss the design implications informed by the results to shed light on the design of collective rating systems. Fu-Yin Cherng, Jingchao Fang, Yinhao Jiang, Taejun Choi, Hao-Chuan Wang |
CHI | 3 |
| 2018 | Ciphertext-policy attribute-based encryption against key-delegation abuse in fog computing
Yinhao Jiang, Willy Susilo, Yi Mu 0001, Fuchun Guo |
Future Gener. Comput. Syst. | 1 |
| 2016 | Ciphertext-Policy Attribute-Based Encryption with Key-Delegation Abuse Resistance
Yinhao Jiang, Willy Susilo, Yi Mu 0001, Fuchun Guo |
ACISP (1) | 1 |
| 2016 | Ciphertext-Policy Attribute Based Encryption Supporting Access Policy Update
Yinhao Jiang, Willy Susilo, Yi Mu 0001, Fuchun Guo |
ProvSec | 1 |