Zecheng Li 0001

dblp:199/6409-1 · DBLP profile ↗
← Back
11ranked-venue papers
5as first author
9since 2021 · last 2026
0000-0003-4200-0941ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 first-author · 3 since 2021Systems, architecture and hardware · 4 · 3 first-author · 4 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Flexible and Privacy-Preserving Access Control Framework for Decentralized Identity Systems
abstract
Decentralized identity systems have emerged as a transformative paradigm, granting users unprecedented data sovereignty and privacy-preserving capabilities, fueling critical innovations in Web3 ecosystems. However, these systems primarily serve as identity-layer solutions, forcing verifiers to design special cryptographic protocols for access control deployment, which is an error-prone and expert-dependent process. Moreover, existing approaches fail to effectively combat credential fraud (e.g., credential theft and revoked credential reuse) without compromising privacy guarantees. This paper presents FRAC (Flexible Fraud-Resistant Access Control), an efficient decentralized access control framework that achieves two paradigm shifts: 1) Streamlined access control deployment: a logic-centric paradigm encodes access criteria through declarative verification rules, eliminating manual cryptographic protocol design while enabling instant verifier onboarding and efficient presentation generation; 2) Provable fraud resistance: a format-agnostic defensive mechanism based on Merkle trees prevents malicious credential use, requiring only lightweight hash operations and signature verification instead of computation-intensive operations. We conduct rigorous security analysis based on universally composable security and evaluate the performance, demonstrating FRAC’s security and efficiency.
Bin Xie 0006, Rui Song 0010, Zecheng Li 0001, Xiaotie Deng, Bin Xiao 0001
IEEE Trans. Inf. Forensics Secur.3
2025 SymProp: Scaling Sparse Symmetric Tucker Decomposition via Symmetry Propagation
abstract
Sparse symmetric tensors are an important class of tensors, and their decompositions serve as powerful tools for revealing low-rank structures. This paper introduces SymProp, a novel approach for scaling sparse symmetric Tucker decomposition by propagating symmetry through intermediate computations. SymProp optimizes two key computational kernels: Sparse Symmetric Tensor Times Same Matrix chain ($\mathrm{S}^{3}$TTMc) for Higher-Order Orthogonal Iteration (HOOI) and Sparse Symmetric Tensor Times Same Matrix chain Times Core ($\mathrm{S}^{3}$TTMcTC) for Higher-Order QR Iteration (HOQRI). Our method employs a metaprogramming-based index iteration approach to efficiently handle the upper triangular parts of intermediate dense symmetric tensors. SymProp achieves up to$50.9 \times$speedup over SPLATT and up to$360.8 \times$over Compressed Sparse Symmetric (CSS) format on the$\mathbf{S}^{3}$TTMc operation. Moreover, our$S^{3}$TTMc and$S^{3}$TTMcTC implementations support tensor orders four levels higher than state-of-the-art methods. Our HOQRI demonstrates superior scalability and up to a$33.6 \times$speedup over optimized HOOI. By enabling more scalable Tucker decompositions for higher orders, decomposition ranks, and dimension sizes, SymProp opens new possibilities for analyzing complex hypergraph structures in fields such as network science, data mining, and machine learning.
Zecheng Li 0001, Shruti Shivakumar, Jiajia Li 0001, Ramakrishnan Kannan
IPDPS1
2025 RedSan: A Redundant Memory Instruction Sanitizer for GPU Programs
abstract
CUDA is the de facto programming model for GPUs, which is widely used in the domains of HPC and AI. To obtain bare-metal performance, vendors and academia develop various profiling tools to guide optimization. However, most existing tools focus on hotspot analysis with limited capabilities in identifying actionable opportunities. To complement existing tools, we present RedSan, a novel profiling tool that leverages binary instrumentation to identify redundant instructions in fully optimized CUDA programs. Guided by RedSan, we are able to optimize programs such as PolybenchGPU, Rodinia, PASTA, DARKNET, and LULESH, yielding up to a 6.27 × speedup and 3.00 × reduction in memory instructions.
Yueming Hao, Zecheng Li 0001, Shuyin Jiao, Xu Liu 0001, Jiajia Li 0001
SC3
2023 n-MVTL Attack: Optimal Transaction Reordering Attack on DeFi
Jianhuan Wang, Jichen Li, Zecheng Li 0001, Xiaotie Deng, Bin Xiao 0001
ESORICS (3)3
2023 Enabling Privacy-Preserving and Efficient Authenticated Graph Queries on Blockchain-Assisted Clouds
abstract
Prior research has introduced a new scenario of blockchain-assisted clouds where the data owner outsources original data to cloud servers and stores some metadata on the blockchain. Despite some research on key-value query and range query in this hybrid-storage scenario, other more complicated data types are not yet supported. In this article, we conduct pioneering research on authenticated queries for graph data, which is a popular data type such as the knowledge graph data, on the blockchain-assisted cloud. The primary challenge is how to design an authenticated data structure (ADS) that supports authenticated queries and can be easily maintained by the blockchain. To this end, we propose a novel ADS, named PAGB, based on the RSA accumulator and completeness set. It can also prevent the original data from being revealed to the public through blockchain or irrelevant queries. We further optimize our design to be more efficient in terms of communication and computation. The effectiveness and efficiency of PAGB are verified through theoretical analysis and extensive experiments.
Haotian Wu 0001, Zecheng Li 0001, Rui Song 0010, Bin Xiao 0001
IEEE Trans. Knowl. Data Eng.2
2023 Securing Deployed Smart Contracts and DeFi With Distributed TEE Cluster
abstract
Smart contract technologies can be used to implement almost arbitrary business logic. They can revolutionize many businesses such as payments, insurance, and crowdfunding. The resulting birth of decentralized finance (DeFi) has gained significant momentum. Smart contracts and DeFi are now attractive targets for attacks. An important research question is how to protect deployed smart contracts and DeFi. Smart contracts cannot be modified once deployed, namely vulnerabilities cannot be fixed by patching. In this case, vulnerabilities in deployed contracts and DeFi might cause devastating consequences. In this paper, we put forward SolSaviour, a framework for protecting deployed smart contracts and DeFi. The core of SolSaviour is to build a smart contract protection mechanism based on democratic voting using a distributed trusted execution environment (TEE) cluster. Once a vulnerability in deployed contracts or DeFi is found, SolSaviour can destroy the defective contract and redeploy a patched contract via the distributed TEE cluster. Moreover, SolSaviour can migrate funds and state variables from the destroyed contract to the patched one. Compared with previous work, our approach can protect smart contracts and DeFi in a distributed manner, avoiding reliance on privileged users or trusted third parties. Our experiment results show that SolSaviour can protect smart contracts and complex DeFi protocols with feasible overhead.
Zecheng Li 0001, Bin Xiao 0001, Songtao Guo, Yuanyuan Yang 0001
IEEE Trans. Parallel Distributed Syst.1
2023 Abnormal Traffic Detection: Traffic Feature Extraction and DAE-GAN With Efficient Data Augmentation
abstract
Abnormal traffic detection is the core component of the network intrusion detection system. Although semisupervised methods can detect zero-day attack traffic, previous work suffers from high false alarms because the trained model is simply based on normal traffic. In this article, we propose an accurate abnormal traffic detection method using pseudoanomaly, consisting of an efficient feature extraction framework and a novel denoise autoencoder-generative adversarial network (DAE-GAN) model. The feature extraction framework adopts an innovative packet window scheme to extract spatial and temporal features from traffic flows. The DAE-GAN model has multiple DAEs to achieve efficient data augmentation and generate high-quality pseudoanomalies. The pseudoanomalies are obtained by adding noise on normal traffic and enhanced by adversarial learning in DAE-GAN. Our semisupervised detection method, exploiting both normal data and generated pseudoanomalies, achieves a precision of 98.6% on the NSL-KDD dataset and 98.5% on the UNSW-NB15 dataset. Compared with the state-of-the-art, the detection precision and recall under different user behaviors are significantly improved. The evaluation on four attack datasets shows that our method has a high flow-wise precision of over 99% and a high recall of 60.6%.
Zecheng Li 0001, Shengyuan Chen, Hongshu Dai, Dunyuan Xu, Cheng-Kang Chu, Bin Xiao 0001
IEEE Trans. Reliab.1
2022 Pistis: Issuing Trusted and Authorized Certificates With Distributed Ledger and TEE
abstract
The security of HTTPS fundamentally relies on SSL/TLS certificates issued by Certificate Authorities (CAs), which, however, are vulnerable to be compromised to issue unauthorized certificates (i.e., certificates issued without domains’ permission). Current countermeasures such as Certificate Transparency (CT) can only detect unauthorized certificates rather than preventing them. In this article, we presentPistis, a framework for issuing authorized and trusted certificates with the distributed ledger and Trusted Execution Environment (TEE) technology. InPistis, TEE nodes validate whether the domain in a requested certificate passes the domain ownership validation (i.e., under corresponding applicants’ control) and submit attested results to a smart contract in the distributed ledger. The smart contract issues a certificate to the applicant when an attested result shows a pass. Therefore,Pistiscan ensure its issued certificates are authorized due to the domain ownership validation mechanism in the TEE. Furthermore, as the issued certificates are stored in a Merkle Patricia Tree (MPT) inPistis, they are trusted and can be verified by a normal user easily. The security ofPistisis formally proved in the Universally Composable (UC) framework. Compared with state-of-the-art,Pistisavoids potential damages by preventing unauthorized certificates from issuing.
Zecheng Li 0001, Haotian Wu 0001, Laphou Lao, Songtao Guo, Yuanyuan Yang 0001, Bin Xiao 0001
IEEE Trans. Parallel Distributed Syst.1
2021 SolSaviour: A Defending Framework for Deployed Defective Smart Contracts
abstract
A smart contract cannot be modified once deployed. Bugs in deployed smart contracts may cause devastating consequences. For example, the infamous reentrancy bug in the DAO contract allows attackers to arbitrarily withdraw ethers, which caused millions of dollars loss. Currently, the main countermeasure against contract bugs is to thoroughly detect and verify contracts before deployment, which, however, cannot defend against unknown bugs. These detection methods also suffer from possible false negative results.
Zecheng Li 0001, Yu Zhou 0047, Songtao Guo, Bin Xiao 0001
ACSAC1
2019 Power Adjusting and Bribery Racing: Novel Mining Attacks in the Bitcoin System
abstract
Mining attacks allow attackers to gain an unfair share of the mining reward by deviating from the honest mining strategy in the Bitcoin system. Among the most well-known are block withholding (BWH), fork after withholding (FAW), and selfish mining. In this paper, we propose two new strategies: power adjusting and bribery racing, and introduce two novel mining attacks, Power Adjusting Withholding (PAW) and Bribery Selfish Mining (BSM) adopting the new strategies. Both attacks can increase the reward of attackers. Furthermore, we show PAW can avoid the "miner's dilemma" in BWH attacks. BSM introduces a new "venal miner's dilemma", which results in all targets (bribes) willing to help the attacker but getting less reward finally. Quantitative analyses and simulations are conducted to verify the effectiveness of our attacks. We propose some countermeasures to mitigate the new attacks, but a practical and efficient solution remains to be an open problem.
Shang Gao 0006, Zecheng Li 0001, Zhe Peng, Bin Xiao 0001
CCS2
2018 Software-Defined Firewall: Enabling Malware Traffic Detection and Programmable Security Control
abstract
Network-based malware has posed serious threats to the security of host machines. When malware adopts a private TCP/IP stack for communications, personal and network firewalls may fail to identify the malicious traffic. Current firewall policies do not have a convenient update mechanism, which makes the malicious traffic detection difficult.
Shang Gao 0006, Zecheng Li 0001, Yuan Yao 0004, Bin Xiao 0001, Songtao Guo, Yuanyuan Yang 0001
AsiaCCS2