EDBT 2026 Demo / reviewers in the wild / expert
Jiaheng Zhang
dblp:203/8611
· DBLP profile ↗
45ranked-venue papers
6as first author
37since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 20 · 4 first-author · 17 since 2021Artificial intelligence and machine learning · 12 · 10 since 2021Computer networks · 7 · 1 first-author · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ExtendAttack: Attacking Servers of LRMs via Extending ReasoningabstractLarge Reasoning Models (LRMs) have demonstrated promising performance in complex tasks. However, the resource-consuming reasoning processes may be exploited by attackers to maliciously occupy the resources of the servers, leading to a crash, like the DDoS attack in cyber. To this end, we propose a novel attack method on LRMs termed ExtendAttack to maliciously occupy the resources of servers by stealthily extending the reasoning processes of LRMs. Concretely, we systematically obfuscate characters within a benign prompt, transforming them into a complex, poly-base ASCII representation. This compels the model to perform a series of computationally intensive decoding sub-tasks that are deeply embedded within the semantic structure of the query itself. Extensive experiments demonstrate the effectiveness of our proposed ExtendAttack. Remarkably, it significantly increases response length and latency, with the former increasing by over 2.7 times for the o3 model on the HumanEval benchmark. Besides, it preserves the original meaning of the query and achieves comparable answer accuracy, showing the stealthiness. Zhenhao Zhu, Yue Liu 0008, Yingwei Ma, Hongcheng Gao, Nuo Chen 0002, Yanpei Guo, Wenjie Qu 0001, Zifeng Kang, Xinzhong Zhu, Jiaheng Zhang |
AAAI | 12 |
| 2026 | Efficient Test-Time Scaling of Multi-Step Reasoning by Probing Internal States of Large Language Models
Jingwei Ni, Ekaterina Fadeeva, Mubashara Akhtar, Jiaheng Zhang, Elliott Ash, Markus Leippold, Timothy Baldwin, See-Kiong Ng, Artem Shelmanov, Mrinmaya Sachan |
ACL (1) | 5 |
| 2026 | Beyond Hard Masks: Progressive Token Evolution for Diffusion Language ModelsabstractLinhao Zhong, Linyu Wu, Bozhen Fang, Tianjian Feng, Chenchen Jing, Wen Wang, Jiaheng Zhang, Hao Chen, Chunhua Shen. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Linhao Zhong 0001, Linyu Wu, Bozhen Fang, Tianjian Feng, Chenchen Jing, Wen Wang 0015, Jiaheng Zhang, Hao Chen 0041, Chunhua Shen |
ACL (1) | 7 |
| 2026 | Efficient Self-Evaluation for Diffusion Language Models via Sequence RegenerationabstractLinhao Zhong, Linyu Wu, Wen Wang, Yuling Xi, Chenchen Jing, Jiaheng Zhang, Hao Chen, Chunhua Shen. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Linhao Zhong 0001, Linyu Wu, Wen Wang 0015, Yuling Xi, Chenchen Jing, Jiaheng Zhang, Hao Chen 0041, Chunhua Shen |
ACL (1) | 6 |
| 2026 | Celer: A Lookup Argument for Large-Scale Queries
Wenjie Qu 0001, Yanpei Guo, Zhen Xuan, Xuanming Liu, Jiaheng Zhang |
CRYPTO (9) | 5 |
| 2026 | Hijacking Large Audio-Language Models via Context-Agnostic and Imperceptible Auditory Prompt Injection
Meng Chen 0011, Kun Wang 0025, Li Lu 0008, Jiaheng Zhang, Tianwei Zhang 0004 |
SP | 4 |
| 2026 | UltraProofs: Scalable Reed-Solomon Code Commitment
Yanpei Guo, Alex Luoyuan Xiong, Wenjie Qu 0001, Jiaheng Zhang |
SP | 4 |
| 2026 | VerfCNN, Optimal Complexity zkSNARK for Convolutional Neural Networks
Wenjie Qu 0001, Yanpei Guo, Yue Ying, Jiaheng Zhang |
SP | 4 |
| 2026 | ARuleCon: Agentic Security Rule ConversionabstractThe real-time demand for web security makes Security Information and Event Management (SIEM) platforms and their applied security rule an integral part of the intrusion detection life-cycle. However, the heterogeneity of vendor-specific rules (e.g., Splunk SPL, Microsoft KQL, IBM AQL, Google YARA-L, and RSA ESA) makes cross-platform rule reuse extremely difficult, requiring deep domain knowledge for reliable conversion. As a result, an autonomous and accurate rule conversion framework can significantly lead to effort savings, preserving the value of existing rules. In this paper, we propose ARuleCon, an agentic SIEM-rule conversion approach. Using ARuleCon, the security professionals do not need to distill the source rules' logic and re-map it to target vendors, instead, they provide the source rules, the documentation of the target rules and ARuleCon can purposely convert to the target vendors without more intervention. To achieve this, ARuleCon is equipped with intermediate representation (IR) that aligns core detection logic into vendor-neutral layer, agentic RAG pipeline that retrieves authoritative official vendor documentation to address the convension/schema mismatches, and Python-based consistency check that running both source and target rules in controlled test environments to mitigate subtle semantic drifts. We present a comprehensive evaluation of ARuleCon ranging from textual alignment between the source and target rules, and the execution success of target rules, showcasing ARuleCon can convert rules with higher fidelity, outperforming the baseline LLM models by 15% averagely. Finally, we perform a case study and interview with our industry collaborators 1, which showcases that ARuleCon can significantly save the expert's time on understanding the cross-SIEM's documentation and remapping the logic. Ming Xu 0006, Hongtai Wang, Yanpei Guo, Zhengmin Yu, Weili Han, Hoon Wei Lim, Jin Song Dong 0001, Jiaheng Zhang |
WWW | 8 |
| 2026 | Time-optimal path planning for robots via Deep Lagrangian Networks
Jiaheng Zhang, Zhiman Duan, Donghao Shi, Shaoping Bai, Qinchuan Li |
Eng. Appl. Artif. Intell. | 2 |
| 2026 | SWAP: Towards Copyright Auditing of Soft Prompts via Sequential Watermarking
Zhixuan Chu, Jiaheng Zhang, Yiming Li 0004, Dacheng Tao |
Int. J. Comput. Vis. | 5 |
| 2025 | BatchZK: A Fully Pipelined GPU-Accelerated System for Batch Generation of Zero-Knowledge ProofsabstractZero-knowledge proof (ZKP) is a cryptographic primitive that enables one party to prove the validity of a statement to other parties without disclosing any secret information. With its widespread adoption in applications such as blockchain and verifiable machine learning, the demand for generating zero-knowledge proofs has increased dramatically. In recent years, considerable efforts have been directed toward developing GPU-accelerated systems for proof generation. However, these previous systems only explored efficiently generating a single proof by reducing latency rather than batch generation to provide high throughput. Tao Lu 0015, Yuxun Chen, Zonghui Wang, Xiaohang Wang 0001, Wenzhi Chen, Jiaheng Zhang |
ASPLOS (1) | 6 |
| 2025 | Mosformer: Maliciously Secure Three-Party Inference Framework for Large TransformersabstractTransformer-based models like BERT and GPT have achieved state-of-the-art performance across a wide range of AI tasks but raise serious privacy concerns when deployed as cloud inference services. To address this, secure multi-party computation (MPC) is commonly employed, encrypting both user inputs and model parameters to enable inference without revealing any private information. However, existing MPC-based secure transformer inference protocols are predominantly designed under the semi-honest security model. Extending these protocols to support malicious security remains a significant challenge, primarily due to the substantial overhead introduced by securely evaluating complex non-linear functions required for adversarial resilience. We introduce Mosformer, the first maliciously secure three-party (3PC) inference framework that efficiently supports large transformers such as BERT and GPT. We first design constant-round comparison and lookup table protocols with malicious security, leveraging verifiable distributed point functions (VDPFs). Building on these, we develop a suite of 3PC protocols for efficient and secure evaluation of complex non-linear functions in transformers. Together with optimized modulus conversion, our approach substantially reduces the overhead of secure transformer inference while preserving model accuracy. Experimental results on the vanilla transformer block show that Mosformer achieves up to a 5.3× speedup and a 4.3× reduction in communication over prior maliciously secure protocols. Despite offering stronger security guarantees, Mosformer achieves comparable or even superior online performance to state-of-the-art semi-honest 2PC and 3PC frameworks, including BOLT (Oakland 2024), BumbleBee (NDSS 2025), SHAFT (NDSS 2025), and Ditto (ICML 2024), on full-scale models such as BERT and GPT-2. Ke Cheng 0001, Yuheng Xia, Anxiao Song, Jiaxuan Fu, Wenjie Qu 0001, Yulong Shen 0001, Jiaheng Zhang |
CCS | 7 |
| 2025 | Modular State Channels Enable Efficient Blockchain-based Web 3.0
Wei Chen 0131, Ru Huo, Yang Liu 0171, Tao Huang 0005, Jiaheng Zhang |
GLOBECOM | 5 |
| 2025 | Efficient Input-Level Backdoor Defense on Text-to-Image Synthesis via Neuron Activation VariationabstractIn recent years, text-to-image (T2I) diffusion models have gained significant attention for their ability to generate high quality images reflecting text prompts. However, their growing popularity has also led to the emergence of backdoor threats, posing substantial risks. Currently, effective defense strategies against such threats are lacking due to the diversity of backdoor targets in T2I synthesis. In this paper, we propose NaviT2I, an efficient input-level backdoor defense framework against diverse T2I backdoors. Our approach is based on the new observation that trigger tokens tend to induce significant neuron activation variation in the early stage of the diffusion generation process, a phenomenon we term Early-step Activation Variation. Leveraging this insight, NaviT2I navigates T2I models to prevent malicious inputs by analyzing Neuron activation variations caused by input tokens. Extensive experiments show that NaviT2I significantly outperforms the baselines in both effectiveness and efficiency across diverse datasets, various T2I backdoors, and different model architectures including UNet and DiT. Furthermore, we show that our method remains effective under potential adaptive attacks. Shengfang Zhai, Yue Liu 0008, Huanran Chen, Zhihua Tian, Wenjie Qu 0001, Qingni Shen, Ruoxi Jia 0001, Yinpeng Dong, Jiaheng Zhang |
ICCV | 10 |
| 2025 | FlipAttack: Jailbreak LLMs via FlippingabstractThis paper proposes a simple yet effective jailbreak attack named FlipAttack against black-box LLMs. First, from the autoregressive nature, we reveal that LLMs tend to understand the text from left to right and find that they struggle to comprehend the text when the perturbation is added to the left side. Motivated by these insights, we propose to disguise the harmful prompt by constructing a left-side perturbation merely based on the prompt itself, then generalize this idea to 4 flipping modes. Second, we verify the strong ability of LLMs to perform the text-flipping task and then develop 4 variants to guide LLMs to understand and execute harmful behaviors accurately. These designs keep FlipAttack universal, stealthy, and simple, allowing it to jailbreak black-box LLMs within only 1 query. Experiments on 8 LLMs demonstrate the superiority of FlipAttack. Remarkably, it achieves $\sim$78.97% attack success rate across 8 LLMs on average and $\sim$98% bypass rate against 5 guard models on average. Yue Liu 0008, Xiao-Xin He, Miao Xiong, Jinlan Fu, Shumin Deng, Yingwei Ma, Jiaheng Zhang, Bryan Hooi |
ICML | 7 |
| 2025 | GuardReasoner-VL: Safeguarding VLMs via Reinforced ReasoningabstractTo enhance the safety of VLMs, this paper introduces a novel reasoning-based VLM guard model dubbed GuardReasoner-VL. The core idea is to incentivize the guard model to deliberatively reason before making moderation decisions via online RL.
First, we construct GuardReasoner-VLTrain, a reasoning corpus with 123K samples and 631K reasoning steps, spanning text, image, and text-image inputs.
Then, based on it, we cold-start our model's reasoning ability via SFT.
In addition, we further enhance reasoning regarding moderation through online RL.
Concretely, to enhance diversity and difficulty of samples, we conduct rejection sampling followed by data augmentation via the proposed safety-aware data concatenation.
Besides, we use a dynamic clipping parameter to encourage exploration in early stages and exploitation in later stages.
To balance performance and token efficiency, we design a length-aware safety reward that integrates accuracy, format, and token cost.
Extensive experiments demonstrate the superiority of our model.
Remarkably, it surpasses the runner-up by 19.27% F1 score on average, as shown in Figure 1.
We release data, code, and models (3B/7B) of GuardReasoner-VL: https://github.com/yueliu1999/GuardReasoner-VL. Yue Liu 0008, Shengfang Zhai, Mingzhe Du, Tri Cao, Hongcheng Gao, Xinfeng Li, Kun Wang 0056, Junfeng Fang, Jiaheng Zhang, Bryan Hooi |
NeurIPS | 11 |
| 2025 | Prompt Inversion Attack Against Collaborative Inference of Large Language ModelsabstractLarge language models (LLMs) have been widely applied for their remarkable capability of content generation. However, the practical use of open-source LLMs is hindered by high resource requirements, making deployment expensive and limiting widespread development. The collaborative inference is a promising solution for this problem, in which users collaborate by each hosting a subset of layers and transmitting intermediate activation. Many companies are building collaborative inference platforms to reduce LLM serving costs, leveraging users' underutilized GPUs. Despite widespread interest in collaborative inference within academia and industry, the privacy risks associated with LLM collaborative inference have not been well studied. This is largely because of the challenge posed by inverting LLM activation due to its strong non-linearity. In this paper, to validate the severity of privacy threats in LLM collaborative inference, we introduce the concept of prompt inversion attack (PIA), where a malicious participant intends to recover the input prompt through the activation transmitted by its previous participant. Specifically, we design a two-stage method to execute this attack. In the first stage, we optimize the input embedding with a constraint term derived from the LLM's embedding matrix to enforce the optimized embedding to be close to the ground truth. In the second stage, we accurately recover discrete tokens by incorporating activation calibration and semantic speculation. Extensive experiments show that our PIA method substantially outperforms existing baselines. For example, our method achieves an 88.4% token accuracy on the Skytrax dataset with the Llama-65B model when inverting the maximum number of transformer layers, while the best baseline method only achieves 22.8% accuracy. The results verify the effectiveness of our PIA attack and highlights its practical threat to LLM collaborative inference systems. Wenjie Qu 0001, Yuguang Zhou, Tingsong Xiao, Binhang Yuan, Yiming Li 0004, Jiaheng Zhang |
SP | 7 |
| 2025 | HyperPianist: Pianist with Linear-Time Prover and Logarithmic Communication CostabstractRecent years have seen great improvements in zero-knowledge proofs (ZKPs). Among them, zero-knowledge SNARKs are notable for their compact and efficiently-verifiable proofs, but suffer from high prover costs. Wu et al. (Usenix Security 2018) proposed to distribute the proving task across multiple machines, and achieved significant improvements in proving time. However, existing distributed ZKP systems still have quasi-linear prover cost, and may incur a communication cost that is linear in circuit size. In this paper, we introduce HyperPianist. Inspired by the state-of-the-art distributed ZKP system Pianist (Liu et al., S&P 2024) and the multivariate proof system HyperPlonk (Chen et al., EUROCRYPT 2023), we design a distributed multivariate polynomial interactive oracle proof (PIOP) system with a linear-time prover cost and logarithmic communication cost. Unlike Pianist, HyperPianist incurs no extra overhead in prover time or communication when applied to general (non-data-parallel) circuits. To instantiate the PIOP system, we adapt two additively-homomorphic multivariate polynomial commitment schemes, multivariate KZG (Papamanthou et al., TCC 2013) and Dory (Lee et al., TCC 2021), into the distributed setting, and get HyperPianistKand HyperPianistDrespectively. Both systems have linear prover complexity and logarithmic communication cost; furthermore, HyperPianistDrequires no trusted setup. We also propose HyperPianist+, incorporating an optimized lookup argument based on Lasso (Setty et al., EUROCRYPT 2024) with lower prover cost. Experiments demonstrate HyperPianistKand HyperPianistDachieve speedups of 63.1x and 40.2x over HyperPlonk with 32 distributed machines. Compared to Pianist, HyperPianistKcan be 2.9x and 4.6x as fast and HyperPianistDcan be 2.4x and 3.8x as fast, on vanilla gates and custom gates respectively. With layered circuits, HyperPianistKis up to 5.9x as fast on custom gates, and HyperPianistDachieves a 4.7x speedup. Chongrong Li, Yun Li 0010, Cheng Hong 0001, Wenjie Qu 0001, Jiaheng Zhang |
SP | 6 |
| 2025 | zkGPT: An Efficient Non-interactive Zero-knowledge Proof Framework for LLM Inference
Wenjie Qu 0001, Yijun Sun, Xuanming Liu, Yanpei Guo, Jiaheng Zhang |
USENIX Security Symposium | 7 |
| 2025 | Provably Robust Multi-bit Watermarking for AI-generated Text
Wenjie Qu 0001, Wengrui Zheng, Tianyang Tao, Yanze Jiang, Zhihua Tian, Jinyuan Jia 0001, Jiaheng Zhang |
USENIX Security Symposium | 9 |
| 2025 | DeepFold: Efficient Multilinear Polynomial Commitment from Reed-Solomon Code and Its Application to Zero-knowledge Proofs
Yanpei Guo, Xuanming Liu, Kexi Huang, Wenjie Qu 0001, Tianyang Tao, Jiaheng Zhang |
USENIX Security Symposium | 6 |
| 2025 | Scalable Collaborative zk-SNARK and Its Application to Fully Distributed Proof Delegation
Xuanming Liu, Zhelei Zhou, Yinghao Wang, Yanxin Pang, Jinye He, Bingsheng Zhang, Xiaohu Yang 0001, Jiaheng Zhang |
USENIX Security Symposium | 8 |
| 2025 | An Edge-Guided SAM for effective complex object segmentation
Longyi Chen, Xiandong Wang, Fengqin Yao, Mingchen Song, Jiaheng Zhang, Shengke Wang |
Expert Syst. Appl. | 5 |
| 2025 | Arena: Multi-Leader Synchronous Byzantine Fault ToleranceabstractByzantine fault-tolerant state machine replication (BFT-SMR) replicates a deterministic state machine across a set of replicas, and processes requests as a single machine even in the presence of Byzantine faults. BFT-SMR is crucial for ensuring system reliability in distributed computing, where the integrity of data and the correct execution of operations are of utmost importance. Recently, synchronous BFT-SMRs have received tremendous attention due to their simple design and high fault-tolerance threshold. However, existing solutions are not efficient enough to achieve high throughput. In this paper, we propose Arena, the firstmulti-leadersynchronous BFT-SMR. Thanks to the synchrony assumption, Arena gains high throughput benefit from multi-leader with a much simpler design (compared to other partially synchronous multi-leader designs). Furthermore, it is more robust: “no progress” of a leader will not trigger a view-change. Our experimental results show that Arena achieves a peak throughput of up to 7.7× higher than the state-of-the-art. Jian Liu 0012, Jiaheng Zhang, Kui Ren 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | SelfLoc: High Quality Unsupervised Object Localization with Self-Prompt SAM
Jiaheng Zhang, Xiandong Wang, Conghui Li, Longyi Chen, Shengke Wang |
PRCV (12) | 1 |
| 2024 | Pianist: Scalable zkRollups via Fully Distributed Zero-Knowledge ProofsabstractIn the past decade, blockchains have seen various financial and technological innovations, with cryptocurrencies reaching a market cap of over 1 trillion dollars. However, scalability is one of the key issues hindering the deployment of blockchains in many applications. To improve the throughput of the transactions, zkRollups and zkEVM techniques using the cryptographic primitive of zero-knowledge proofs (ZKPs) have been proposed and many companies are adopting these technologies in the layer-2 solutions. However, in these technologies, the proof generation of the ZKP is the bottleneck and the companies have to deploy powerful machines with TBs of memory to batch a large number of transactions in a ZKP.In this work, we improve the scalability of these techniques by proposing new schemes of fully distributed ZKPs. Our schemes can improve the efficiency and the scalability of ZKPs using multiple machines, while the communication among the machines is minimal. With our schemes, the ZKP generation can be distributed to multiple participants in a model similar to the mining pools. Our protocols are based on Plonk, an efficient zero-knowledge proof system with a universal trusted setup. The first protocol is for data-parallel circuits. For a computation of M sub-circuits of size T each, using M machines, the prover time is O(T log T + M log M), while the prover time of the original Plonk on a single machine is O(MT log(MT )). Our protocol incurs only O(1) communication per machine, and the proof size and verifier time are both O(1), the same as the original Plonk. Moreover, we show that with minor modifications, our second protocol can support general circuits with arbitrary connections while preserving the same proving, verifying, and communication complexity. The technique is general and may be of independent interest for other applications of ZKP.We implement Pianist (Plonk vIA uNlimited dISTribution), a fully distributed ZKP system using our protocols. Pianist can generate the proof for 8192 transactions in 313 seconds on 64 machines. This improves the scalability of the Plonk scheme by 64×. The communication per machine is only 2.1 KB, regardless of the number of machines and the size of the circuit. The proof size is 2.2 KB and the verifier time is 3.5 ms. We further show that Pianist has similar improvements for general circuits. On a randomly generated circuit with 225gates, it only takes 5 s to generate the proof using 32 machines,24.2× faster than Plonk on a single machine. Tiancheng Xie, Jiaheng Zhang, Dawn Song, Yupeng Zhang 0001 |
SP | 3 |
| 2024 | Demodulation Scheme Against Phase Noise Using an Ensemble Clustering ApproachabstractMost wireless systems involve time-varying multipath channels, where the negative effect of the phase noise cannot be ignored. The phase noise can be introduced by imperfect phase-locked loop circuitry, imperfect channel estimation, or both. This paper considers the demodulation problem of wireless systems with phase noise. We propose an ensemble clustering algorithm to address the limitations of the existing demodulation schemes. The proposed ensemble clustering algorithm is named as the Ensemble Clustering algorithm using the Matrix Factorization and Information Theory (MFIT-EC). The MFIT-EC algorithm improves the performance of existing ensemble clustering algorithms, which neglect different clustering effects of different base-clustering algorithms or different effects of different clusters of the same base-clustering algorithm. Based on the MFIT-EC algorithm, we design a demodulation scheme in a coherent wireless system with phase noise, referred to as the MFIT-EC demodulation scheme. Specifically, we first utilize several base-clustering algorithms to obtain different base-clustering results. Second, we use a weighted ensemble mechanism to allocate different weights to different base-clustering results, and calculate the certainty of the clusters of each base-clustering algorithm to obtain a better and more robust demodulation performance. We implement the proposed approach and conduct extensive performance comparisons through simulations, which show that the proposed approach has better performance than the prior approaches in terms of both clustering performance and demodulation performance. Jiaheng Zhang, Ning Xie 0007 |
IEEE Trans. Mob. Comput. | 2 |
| 2024 | Hybrid Physical-Layer AuthenticationabstractPhysical-Layer Authentication (PLA) attracts a lot of research interests because of its significant advantages over upper-layer authentication mechanisms: high security and low complexity. The PLA schemes can be categorized into passive and active schemes. In this paper, we extensively leverage the advantages of both the active and passive schemes as a reference scheme, named as the Direct Hybrid (DH) scheme. Although the DH scheme improves the authentication performance of the prior PLA schemes, it has limitations, e.g., high communication overhead. Then, we further propose two hybrid PLA schemes to overcome the limitations of the DH scheme. The first proposed scheme further uses the advantage of the Challenge-Response Authentication Mechanism (CRAM) scheme, named as the CR-based Hybrid (CRH) scheme. Although both DH and CRH schemes significantly improve the authentication performance of the prior PLA schemes, they do not address one significant limitation of the active scheme, i.e., to set the power allocation of a tag empirically. Thus, based on the CRH scheme, we further propose the Adaptive CR-Based Hybrid (ACRH) scheme to adaptively set the parameter instead of the empirical setting. Moreover, we provide the theoretical analysis of the proposed schemes over wireless fading channels and derive their closed-form expressions in terms of the Probability of Detection (PD), Probability of False Alarm (PFA), and optimal threshold, respectively. At last, we discuss the advantages and disadvantages of the proposed schemes and give some useful suggestions for seeking a better tradeoff. Our experimental results show that, in comparison with the active scheme, the DH scheme has better robustness, and the CRH scheme has better both robustness and compatibility but it sacrifices the security. The ARCH scheme achieves a better tradeoff than the remaining schemes. Ning Xie 0007, Jiaheng Zhang, Qihong Zhang, Haijun Tan, Alex X. Liu, Dusit Niyato |
IEEE Trans. Mob. Comput. | 2 |
| 2024 | Privacy-Preserving Physical-Layer Authentication Under Cooperative AttacksabstractIn this paper, we are concerned about the problem of guaranteeing both privacy and security in a Location-Based Service (LBS) system, where a challenging scenario involving cooperative attack is considered. Since prior Physical-Layer Authentication (PLA) schemes do not consider cooperative attack, their security significantly declines under such attacks. We propose two privacy-preserving PLA schemes: the Privacy-Preserving Physical-Layer Authentication using Noise Variance (PPPLA-NV) scheme and the Privacy-Preserving Physical-Layer Authentication using Multiple Channel Responses (PPPLA-MCR) scheme, which significantly improve the privacy-preserving performance under a cooperative attack. Note that the proposed schemes protect not only user’s identity information but also data message. We theoretically analyze the performance of the proposed schemes, derive their closed-form expressions, and provide a theoretical comparison between both proposed schemes. We implement the proposed schemes and conduct extensive performance comparisons through simulations. Experimental results show a perfect match between the theoretical and simulation results. From the experimental results, we observe that if the overhead is not the priority, the PPPLA-MCR scheme is the best option; otherwise, the PPPLA-NV scheme may be a better option. Jiaheng Zhang, Yicong Chen, Ning Xie 0007, Hongbin Li 0001 |
IEEE/ACM Trans. Netw. | 2 |
| 2023 | Correlation Intractability and SNARGs from Sub-exponential DDH
Arka Rai Choudhuri, Sanjam Garg, Abhishek Jain 0002, Zhengzhong Jin, Jiaheng Zhang |
CRYPTO (4) | 5 |
| 2023 | Reading Multilevel 2-D Barcodes Using a Machine Learning ApproachabstractThis article addresses the reading problem of multilevel 2-D barcodes over a print-and-capture (PC) channel. The prior reading schemes have different limitations to hinder their applications, e.g., suffering from quantization error, being sensitive to the predetermined decision boundaries, and being sensitive to the selection of initial parameters. In this article, we introduce a machine learning approach to address the above limitations using a new ensemble clustering (EC) algorithm. Based on the new EC algorithm, we propose two reading schemes of a multilevel 2-D barcode. Specifically, the first proposed scheme is named the EC reading scheme. In the EC reading scheme, we introduce a weighted ensemble mechanism to assign different weights to different base clustering results. Then, we propose the second scheme, named the enhanced EC (EEC) reading scheme, to further improve the reading performance with the help of the reference symbols. We implement our approach and conduct extensive performance comparisons through an actual excremental platform under various multilevel 2-D barcodes and various capturing devices. From experimental results, we observe that both proposed reading schemes have better performance than the prior reading schemes. Moreover, the EEC reading scheme has better performance than the EC reading scheme, and their performance gap becomes more apparent as the distortion of a PC channel increases. Jiaheng Zhang, Le Ou-Yang, Changsheng Chen 0001, Ning Xie 0007 |
IEEE Internet Things J. | 1 |
| 2023 | Joint Estimation of Channel Responses and Phase Noises in Asynchronous MIMO Systems With Intentional Timing OffsetabstractThe reception performance of a Multiple-Input-Multiple-Output (MIMO) system suffers from not only the channel fading but also the phase noise. Accurate and efficient estimation algorithms of channel responses and phase noises that enable high-speed wireless communications in MIMO systems are of broad interest. The prior joint estimation schemes of channel responses and phase noises are designed for synchronous MIMO systems, where symbols transmitted from different transmit antennas are strictly synchronized. However, the estimation performance of the prior schemes suffers from the Inter Antenna Interference (IAI), which further limits the reception performance of a MIMO system. In this paper, we propose an asynchronous MIMO system with intentional timing offset. Based on the proposed asynchronous MIMO system, we further design the Joint Estimation of Channel responses and Phase noises using Intentional Timing Offset (JECP-ITO) scheme. We derive the Cramér-Rao Lower Bound (CRLB) of the JECP-ITO scheme in closed form. We provide rigorous theoretical comparisons between the JECP-ITO and the prior scheme in terms of IAI and CRLB. Moreover, we implement the proposed scheme and conduct extensive performance comparisons through simulations. Ning Xie 0007, Jiaheng Zhang |
IEEE Trans. Commun. | 3 |
| 2023 | Physical Layer Authentication in Spatial ModulationabstractSpatial Modulation (SM) is a promising low-complexity modulation scheme for Multiple-Input Multiple-Output (MIMO) systems. In this paper, we address the problem of authenticating the transmitter device in the SM. We propose an authentication approach for an SM system by using Physical-Layer Authentication (PLA) mechanisms because the PLA has the following advantages: high security and low complexity. Based on the features of an SM system, we propose two PLA schemes:PLA with Superimposed Authentication Tag(PLA-SAT) andPLA with Superimposed Imaginary authentication Tag(PLA-SIT). We provide performance analyses of our schemes over fading channels in terms of robustness, compatibility, and security. Moreover, we derive their closed-form expressions under both perfect and imperfect channel estimates, including the Probability of Detection (PD), Probability of False Alarm (PFA), and Average Error Probability (AEP). Although the two proposed schemes have the same robustness and security, the PLA-SIT scheme has better compatibility than the PLA-SAT scheme. Our schemes were implemented and extensive performance comparisons through simulations were conducted. We observe that the simulation results of the two proposed schemes perfectly match their corresponding theoretical analyses. The authentication accuracy of the two proposed schemes is close to one when the received SNR is greater than 20 dB and the security performances of the two proposed schemes improve as the variance of estimation errors increases. Jiaheng Zhang, Qihong Zhang, Peichang Zhang, Lei Huang 0001, Ning Xie 0007, Jian Lu 0002 |
IEEE Trans. Commun. | 2 |
| 2022 | zkBridge: Trustless Cross-chain Bridges Made PracticalabstractBlockchains have seen growing traction with cryptocurrencies reaching a market cap of over 1 trillion dollars, major institution investors taking interests, and global impacts on governments, businesses, and individuals. Tiancheng Xie, Jiaheng Zhang, Zerui Cheng, Fan Zhang 0022, Yupeng Zhang 0001, Yongzheng Jia, Dan Boneh, Dawn Song |
CCS | 2 |
| 2022 | Polynomial Commitment with a One-to-Many Prover and Applications
Jiaheng Zhang, Tiancheng Xie, Thang Hoang, Elaine Shi, Yupeng Zhang 0001 |
USENIX Security Symposium | 1 |
| 2021 | Doubly Efficient Interactive Proofs for General Arithmetic Circuits with Linear Prover TimeabstractWe propose a new doubly efficient interactive proof protocol for general arithmetic circuits. The protocol generalizes the interactive proof for layered circuits proposed by Goldwasser, Kalai and Rothblum to arbitrary circuits, while preserving the optimal prover complexity that is strictly linear to the size of the circuits. The proof size remains succinct for low depth circuits and the verifier time is sublinear for structured circuits. We then construct a new zero knowledge argument scheme for general arithmetic circuits using our new interactive proof protocol together with polynomial commitments. Our key technique is a new sumcheck equation that reduces a claim about the output of one layer to claims about its input only, instead of claims about all the layers above which inevitably incurs an overhead proportional to the depth of the circuit. We developed efficient algorithms for the prover to run this sumcheck protocol and to combine multiple claims back into one in linear time in the size of the circuit. Not only does our new protocol achieve optimal prover complexity asymptotically, but it is also efficient in practice. Our experiments show that it only takes 0.3 seconds to generate the proof for a circuit with more than 600,000 gates, which is 13 times faster than the original interactive proof protocol on the corresponding layered circuit. The proof size is 208 kilobytes and the verifier time is 66 milliseconds. Our implementation can take general arithmetic circuits directly, without transforming them to layered circuits with a high overhead on the size of the circuit. Jiaheng Zhang, Dawn Song, Yupeng Zhang 0001 |
CCS | 1 |
| 2020 | Zero Knowledge Proofs for Decision Tree Predictions and AccuracyabstractMachine learning has become increasingly prominent and is widely used in various applications in practice. Despite its great success, the integrity of machine learning predictions and accuracy is a rising concern. The reproducibility of machine learning models that are claimed to achieve high accuracy remains challenging, and the correctness and consistency of machine learning predictions in real products lack any security guarantees. In this paper, we initiate the study of zero knowledge machine learning and propose protocols for zero knowledge decision tree predictions and accuracy tests. The protocols allow the owner of a decision tree model to convince others that the model computes a prediction on a data sample, or achieves a certain accuracy on a public dataset, without leaking any information about the model itself. We develop approaches to efficiently turn decision tree predictions and accuracy into statements of zero knowledge proofs. We implement our protocols and demonstrate their efficiency in practice. For a decision tree model with 23 levels and 1,029 nodes, it only takes 250 seconds to generate a zero knowledge proof proving that the model achieves high accuracy on a dataset of 5,000 samples and 54 attributes, and the proof size is around 287 kilobytes. Jiaheng Zhang, Zhiyong Fang, Yupeng Zhang 0001, Dawn Song |
CCS | 1 |
| 2020 | Convolutional Transformer with Sentiment-aware Attention for Sentiment AnalysisabstractGiven certain data available for training, the keys to improving a sentiment analysis system lie in developing a good model that is capable of capturing both local and global features of texts, as well as incorporating external knowledge into the model effectively. In this paper, we propose a multi-window Convolutional Transformer (ConvTransformer) that takes the advantages of both Transformer and CNN for sentiment analysis. The proposed ConvTransformer is able to capture important local n-gram features effectively while preserving sequential information of texts. Furthermore, we propose a sentiment-aware attention mechanism to incorporate the sentiment intensity information of each word by utilizing an external knowledge base, SentiWordNet. The sentiment-aware attention mechanism takes both sentiment and position information of each token into consideration when computing attention weights, resulting in a global feature for final classification. Comparing with CNN, RNN and attention-based baseline models, our model achieves the best performance on multiple sentiment analysis datasets. Peixiang Zhong, Jiaheng Zhang, Kezhi Mao |
IJCNN | 3 |
| 2020 | Transparent Polynomial Delegation and Its Applications to Zero Knowledge ProofabstractWe present a new succinct zero knowledge argument scheme for layered arithmetic circuits without trusted setup. The prover time is O(C + nlogn) and the proof size is O(D logC +log2n) for a D-depth circuit with n inputs and C gates. The verification time is also succinct, O(D logC + log2n), if the circuit is structured. Our scheme only uses lightweight cryptographic primitives such as collision-resistant hash functions and is plausibly post-quantum secure. We implement a zero knowledge argument system, Virgo, based on our new scheme and compare its performance to existing schemes. Experiments show that it only takes 53 seconds to generate a proof for a circuit computing a Merkle tree with 256 leaves, at least an order of magnitude faster than all other succinct zero knowledge argument schemes. The verification time is 50ms, and the proof size is 253KB, both competitive to existing systems.Underlying Virgo is a new transparent zero knowledge verifiable polynomial delegation scheme with logarithmic proof size and verification time. The scheme is in the interactive oracle proof model and may be of independent interest. Jiaheng Zhang, Tiancheng Xie, Yupeng Zhang 0001, Dawn Song |
SP | 1 |
| 2020 | Bag-of-Concepts representation for document classification based on automatic knowledge acquisition from probabilistic knowledge base
Kezhi Mao, Yuecong Xu, Jiaheng Zhang |
Knowl. Based Syst. | 5 |
| 2019 | Libra: Succinct Zero-Knowledge Proofs with Optimal Prover Computation
Tiancheng Xie, Jiaheng Zhang, Yupeng Zhang 0001, Charalampos Papamanthou, Dawn Song |
CRYPTO (3) | 2 |
| 2019 | Searching for Cryptogenography Upper Bounds via Sum of Square ProgrammingabstractCryptogenography is a secret-leaking game in which one of n players is holding a secret to be leaked. The n players engage in communication as to (1) reveal the secret while (2) keeping the identity of the secret holder as obscure as possible. All communication is public, and no computational hardness assumptions are made, i.e., the setting is purely information theoretic. Brody, Jakobsen, Scheder, and Winkler [Joshua Brody et al., 2014] formally defined this problem, showed that it has an equivalent geometric characterization, and gave upper and lower bounds for the case in which the n players want to leak a single bit. Surprisingly, even the easiest case, where two players want to leak a secret consisting of a single bit, is not completely understood. Doerr and Künnemann [Benjamin Doerr and Marvin Künnemann, 2016] showed how to automatically search for good protocols using a computer, thus finding an improved protocol for the 1-bit two-player case. In this work, we show how the search for upper bounds (impossibility results) can be formulated as a Sum of Squares program. We implement this idea for the 1-bit two-player case and significantly improve the previous upper bound from 47/128 = 0.3671875 to 0.35183. Dominik Scheder, Shuyang Tang, Jiaheng Zhang |
ISAAC | 3 |
| 2017 | PDD Graph: Bridging Electronic Medical Records and Biomedical Knowledge Graphs via Entity Linking
Meng Wang 0009, Jiaheng Zhang, Jun Liu 0002, Wei Hu 0007, Sen Wang 0001, Xue Li 0001 |
ISWC (2) | 2 |
| 2017 | Modeling of a dynamic dual-input dual-output fast steeringmirror systemabstractA modeling method is proposed for a dynamic fast steering mirror (FSM) system with dual inputs and dual outputs. A physical model of the FSM system is derived based on first principles, describing the dynamics and coupling between the inputs and outputs of the FSM system. The physical model is then represented in a state-space form. Unknown parameters in the state-space model are identified by the subspace identification algorithm, based on the measured input-output data of the FSM system. The accuracy of the state-space model is evaluated by comparing the model estimates with measurements. The variance-accounted-for value of the state-space model is better than 97%, not only for the modeling data but also for the validation data set, indicating high accuracy of the model. Comparison is also made between the proposed dynamic model and the conventional static model, where improvement in model accuracy is clearly observed. The model identified by the proposed method can be used for optimal controller design for closed-loop FSM systems. The modeling method is also applicable to FSM systems with similar structures. Hong Song 0002, Jiaheng Zhang, Haocai Huang, Shu-yue Zhan, Tengjun Liu, Yilu Guo, Hangzhou Wang, Quanquan Mu, Mei-fen Fang, Mingyuan Yang |
Frontiers Inf. Technol. Electron. Eng. | 2 |