EDBT 2026 Demo / reviewers in the wild / expert
Huizhong Li
dblp:209/5740
· DBLP profile ↗
32ranked-venue papers
3as first author
23since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 1 first-author · 8 since 2021Software engineering, systems software and programming languages · 9 · 7 since 2021Systems, architecture and hardware · 8 · 1 first-author · 6 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Byzantine Fault Tolerance With Non-Determinism, RevisitedabstractConventional Byzantine fault tolerance (BFT) requires replicated state machines to execute deterministic operations only. In practice, numerous applications and scenarios, especially in the era of blockchains, contain various sources of non-determinism. Meanwhile, it is even sometimes desirable to support non-determinism, and replicas still agree on the execution results. Despite decades of research on BFT, we still lack an efficient and easy-to-deploy solution for BFT with non-determinism—BFT-ND, especially in the asynchronous setting. We revisit the problem of BFT-ND and provide a formal and asynchronous treatment of BFT-ND. In particular, we design and implement Block-ND that insightfully separates the task of agreeing on the order of transactions from the task of agreement on the state: Block-ND allows reusing existing BFT implementations; on top of BFT, we reduce the agreement on the state to multivalued Byzantine agreement (MBA), a somewhat neglected primitive by practical systems. Block-ND is completely asynchronous as long as the underlying BFT is asynchronous. We provide a new MBA construction that is significantly faster than existing MBA constructions. We instantiate Block-ND in both the partially synchronous setting (with PBFT, OSDI 1999) and the purely asynchronous setting (with PACE, CCS 2022). Via a 91-instance WAN deployment on Amazon EC2, we show that Block-ND has only marginal performance degradation compared to conventional BFT. Huizhong Li, Yi Sun 0004, Sisi Duan |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Confidential Distributed Ledgers for Online Syndicated LendingabstractOnline syndicated lending offers quick and convenient financing support to individuals, while diversifying risks by pooling funds from multiple lenders into loan projects. It has experienced explosive growth, reaching a multibillion-dollar market. Establishing transparency is essential for constructing a trusted, fair, and regulation-compliant financial collaboration model. Meanwhile, confidentiality must be maintained to protect the sensitive financial information of individual lenders. Multi-party computation (MPC) can protect the input privacy of lenders, but it cannot safeguard the sensitive information revealed by the fund flow itself. To address these challenges, we propose a new collaborative financial ledger for online syndicated lending. It leverages homomorphic encryption/commitment to enable the reuse of intermediary states without compromising privacy throughout the entire lifecycle of a loan. This system also supports efficient regulation-compliant auditing. We streamline the framework design to optimize performance and develop a prototype system. Even with a large syndicate of 100 lenders, the system still achieves low-latency performance. Xuefeng Liu 0002, Le Wang 0010, Wenhai Sun, Qingqi Pei, Xiaodong Lin 0001, Huizhong Li |
IEEE Trans. Serv. Comput. | 7 |
| 2023 | Phoenix: Detect and Locate Resilience Issues in Blockchain via Context-Sensitive ChaosabstractResilience is vital to blockchain systems and helps them automatically adapt and continue providing their service when adverse situations occur, e.g., node crashing and data discarding. However, due to the vulnerabilities in their implementation, blockchain systems may fail to recover from the error situations, resulting in permanent service disruptions. Such vulnerabilities are called resilience issues. Fuchen Ma, Yuanliang Chen, Yuanhang Zhou, Jingxuan Sun, Zhuo Su 0005, Yu Jiang 0001, Jia-Guang Sun 0001, Huizhong Li |
CCS | 8 |
| 2023 | Table Re-Computation Based Low Entropy Inner Product Masking Schemeabstractis a popular countermeasure due to its provable security. Table re-computation based Boolean masking (BM) is efficient at small masking share number, and addition chain based inner product masking (IPM) provides higher security order than BM. As a result, the natural question is: can we design a masking scheme that costs close to that of re-computation based BM while providing security comparable to that of addition chain based IPM? In this paper, we propose a table re-computation based IPM scheme that provides 3rd-order security while being slightly more expensive than table re-computation based BM. Furthermore, we improve the side-channel security of IPM by randomly selecting the parameter$L$from an elaborated low entropy set, which we call low entropy inner product masking (LE-IPM). In an Intel Core i7-4790 CPU and ARM Cortex M4 based MCU for AES, we implemented four masking schemes, namely the addition chain based IPM and table re-computation based BM, IPM, and LE-IPM. Our proposals perform slightly slower (by about 0.8 times) than table re-computation based BM but significantly faster (at least 30 times) than addition chain based IPM. Furthermore, we assess the security of our proposals using a standard method named test vector leakage assessment methodology (TVLA). Our proposals provide the expected security against side-channel attacks according to the evaluation. Jingdian Ming, Yongbin Zhou, Wei Cheng 0003, Huizhong Li |
DATE | 4 |
| 2023 | Detecting State Inconsistency Bugs in DApps via On-Chain Transaction Replay and FuzzingabstractDecentralized applications (DApps) consist of multiple smart contracts running on Blockchain. With the increasing popularity of the DApp ecosystem, vulnerabilities in DApps could bring significant impacts such as financial losses. Identifying vulnerabilities in DApps is by no means trivial, as modern DApps consist of complex interactions across multiple contracts. Previous research suffers from either high false positives or false negatives, due to the lack of precise contextual information which is mandatory for confirming smart contract vulnerabilities when analyzing smart contracts. Mingxi Ye, Yuhong Nan, Zibin Zheng, Dongpeng Wu, Huizhong Li |
ISSTA | 5 |
| 2023 | LOKI: State-Aware Fuzzing Framework for the Implementation of Blockchain Consensus Protocols
Fuchen Ma, Yuanliang Chen, Yuanhang Zhou, Yu Jiang 0001, Ting Chen 0002, Huizhong Li, Jia-Guang Sun 0001 |
NDSS | 7 |
| 2023 | FISCO-BCOS: An Enterprise-grade Permissioned Blockchain System with High-performanceabstractEnterprise-grade permissioned blockchain systems provide a promising infrastructure for data sharing and cooperation between different companies. However, performance bottlenecks seriously hinder the adoption of these systems in many industrial applications that process complex business logic and huge transaction volumes. Our research identifies two key factors that limit the system performance: 1) At the block level, the serial dependency of inter-block processing severely limits the system throughput. A new block must wait for the completion of all previous blocks. 2) At the transaction level, the lack of efficient intra-block transactions concurrency makes it difficult to achieve high performance, especially when dealing with multiple CPU-heavy contracts which are commonly used in industrial scenarios. Huizhong Li, Yujie Chen 0007, Xingqiang Bai, Nan Mo, Yi Sun 0004 |
SC | 1 |
| 2023 | Practical Public Template Attack Attacks on CRYSTALS-Dilithium With Randomness LeakagesabstractSide-channel security has become a significant concern in the NIST post-quantum cryptography standardization process. The lattice-based CRYSTALS-Dilithium (abbr. Dilithium) becomes the primary signature standard algorithm recommended by NIST for most use cases in July 2022 due to its excellent performance in security and efficiency. Compared to Dilithium’s rich theoretical security analysis results, the side-channel security of its physical implementations needs to be further explored. In 2021, Liu et al. proposed a two-stage randomness leakage attack against Dilithium, in which only one randomness bit with a probability$> 0.5$per signature is enough to recover the private key. However, they only carried out proof-of-concept experiments on “research-oriented” reference implementation of polynomial addition. Whether this method applies to complete real-world implementations of Dilithium is unknown. In this paper, we put this randomness leakage attack into real-world and recover the private key of unprotected and masked Dilithium on Arm Cortex-M4 processor using non-profiled power analysis attacks. Since randomness is introduced in the signing process, it is challenging to recover the randomness bit of Dilithium with high success rate in only one trace. Inspired by Liu et al., we propose a new non-profiled attack called Public Template Attack (PTA), a template-attack-like method that builds templates using public information. With PTA, we recover the randomness bit of unprotected and masked Dilithium with a success rate of 95% and 62% in one power trace, respectively. To demonstrate practicality, we perform practical power analysis attacks against different security levels of round 3 unprotected and masked Dilithium on STM32F405 microprocessor. Using 10,000 traces, the private key of unprotected Dilithium2 is recovered in 0.5 hours with an ordinary PC desktop. Our attack is 240 times faster than the state-of-the-art non-profiled attack. Moreover, the private key of masked Dilithium2 is recovered using 680,000 traces in 38 hours. To the best of our knowledge, we are the first to successfully attack masked Dilithium using non-profiled attacks. Zehua Qiao, Yuejun Liu, Yongbin Zhou, Jingdian Ming, Chengbin Jin, Huizhong Li |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2023 | V-Gas: Generating High Gas Consumption Inputs to Avoid Out-of-Gas VulnerabilityabstractOut-of-gas errors occur when smart contract programs are provided with inputs that cause excessive gas consumption and which will be easily exploited to perform Denial-of-Service attacks. Various approaches have been proposed to estimate the gas limit of a function in smart contracts to avoid such error. However, underestimation often occurs when the contract is complex In this work, we propose V-Gas, which automatically generates inputs that maximize the gas cost and reduce underestimation. V-Gas is designed based on static analysis and feedback-directed mutational fuzz testing. First, V-Gas builds the gas weighted control flow graph of functions in smart contracts. Then, V-Gas develops gas consumption guided selection and mutation strategies to generate the input that maximize the gas consumption. For evaluation, we implement V-Gas based on js-evm, a widely used Ethereum virtual machine written in Javascript, and conduct experiments on 736 real-world transactions recorded on Ethereum. A total of 44.02% of the transactions would have out-of-gas errors based on the estimation results given by solc, meaning that the recorded real gas consumption for those transactions is larger than the gas limit estimated by solc. In comparison, V-Gas could reduce the underestimation ratio to 13.86%. To evaluate the performance of feedback-directed engine in V-Gas, we implemented other directed fuzzing engines and compared their performance with that of V-Gas. The results showed that V-Gas generates the same or higher gas estimation value on 97.8% of the transactions with less time, usually within 5 minutes. Furthermore, V-Gas has exposed 25 previously unknown out-of-gas vulnerabilities in widely used smart contracts, 6 of which have been assigned unique CVE identifiers in the U.S. National Vulnerability Database. Fuchen Ma, Houbing Song, Heyuan Shi, Yu Jiang 0001, Huizhong Li |
ACM Trans. Internet Techn. | 8 |
| 2022 | FL-Market: Trading Private Models in Federated LearningabstractAcquiring a sufficient amount of training data is a significant bottleneck for machine learning (ML) based data analytics. Recently, commoditizing ML models has been proposed as an economical and moderate solution to ML-oriented data acquisition. However, existing model marketplaces assume that the broker can access data owners’ private training data, which may not be realistic in practice. In this paper, to promote trustworthy data acquisition for ML tasks, we propose FL-Market, a locally private model marketplace that protects privacy against not only model buyers but also an untrusted broker. FL-Market decouples ML from the need to centrally gather training data on the broker’s side using federated learning, a privacy-preserving ML paradigm in which data owners collaboratively train an ML model by uploading local gradients (to be aggregated into a global gradient for model updating). Then, FL-Market enables data owners to locally perturb their gradients by local differential privacy and thus further prevents privacy risks. To drive FL-Market, we propose a deep learning-empowered auction mechanism for intelligently deciding the local gradients’ perturbation levels and an optimal aggregation mechanism for aggregating the perturbed gradients. Our auction and aggregation mechanisms can jointly maximize the global gradient’s accuracy, which optimizes model buyers’ utility. Our experiments verify the effectiveness of the proposed mechanisms. Shuyuan Zheng, Yang Cao 0011, Masatoshi Yoshikawa, Huizhong Li, Qiang Yan 0001 |
IEEE Big Data | 4 |
| 2022 | WaLi: Control-Flow-Based Analysis of Wasm Smart Contracts
Shuo Yang 0012, Huizhong Li, Zibin Zheng |
BlockSys | 2 |
| 2022 | Cross-Grade Curriculum Group Based Teaching Experiment System for Innovative Design of IoT Intelligent Dynamic Measurement and ControlabstractOne of the key hot spots and difficulties in the construction of “Engineering Education Certification” and “New Engineering” is how to strengthen the cultivation of the college students’ ability to solve complex engineering problems. In this paper, a software and hardware experimental platform has been designed, which organically integrates automatic judgement and sensing communications with electromechanical integrated IoT measurement and control. And a teaching system of cross-grade supporting experimental course group based on this platform has been proposed, which is driven by the application function topics from the shallower to the deeper. It is an engineering ability training mechanism that can continuously carry out experimental teaching such as design, installation and adjustment from the lower grade to the higher grade. More than five years of teaching practice shows that this system has significantly improved the students’ professional research interest and ability to solve complex engineering problems. Hongqing Ma, Peihong Li, Xihua Li 0004, Xiangdong Jin, Qimin Zhou, Xiaoxing Shi, Huizhong Li |
ISCAS | 9 |
| 2022 | Accelerating Elliptic Curve Digital Signature Algorithms on GPUsabstractThe Elliptic Curve Digital Signature Algorithm (ECDSA) is an essential building block of various cryptographic protocols. In particular, most blockchain systems adopt it to ensure transaction integrity. However, due to its high computational intensity, ECDSA is often the performance bottleneck in blockchain transaction processing. Recent work has accelerated ECDSA algorithms on the CPU; in contrast, success has been limited on the GPU, which has great potential for parallelization but is challenging for implementing elliptic curve functions. In this paper, we propose RapidEC, a GPU-based ECDSA implementation for SM2, a popular elliptic curve. Specifically, we design architecture-aware parallel primitives for elliptic curve point operations, and parallelize the processing of a single SM2 request as well as batches of requests. Consequently, our GPU-based RapidEC outperformed the state-of-the-art CPU-based algorithm by orders of magnitude. Additionally, our GPU-based modular arithmetic functions as well as point operation primitives can be applied to other computation tasks. Zonghao Feng, Qipeng Xie, Qiong Luo 0001, Yujie Chen 0007, Huizhong Li, Qiang Yan 0001 |
SC | 6 |
| 2022 | DVREI: Dynamic Verifiable Retrieval Over Encrypted ImagesabstractThe increasing awareness in privacy has partly contributed to the renewed interest in privacy-preserving encrypted image retrieval, and designing for outsourced images stored on cloud servers, etc. However, there are some limitations in these existing schemes such as low retrieval accuracy, low retrieval efficiency, and less efficient result verification in the dynamic setting. Therefore, in this paper we present a novel Dynamic Verifiable Retrieval over Encrypted Images (DVREI) scheme. First, a pre-trained Convolutional Neural Network (CNN) model is utilized to extract image features to improve retrieval accuracy. Then, an encrypted index based on the K-means clustering algorithm is designed to improve retrieval efficiency. Finally, a dynamic verification tree based on the chameleon hash is used to verify the correctness of the retrieval results and support dynamic updates. We theoretically and experimentally evaluate the security and performance of DVREI to demonstrate its practicability. Yingying Li 0001, Jianfeng Ma 0001, Yinbin Miao, Huizhong Li, Qiang Yan 0001, Yue Wang 0063, Ximeng Liu, Kim-Kwang Raymond Choo |
IEEE Trans. Computers | 4 |
| 2022 | Optimizing Higher-Order Correlation Analysis Against Inner Product Masking SchemeabstractIn recent years, inner product masking (IPM) has been proposed as a promising code based masking scheme against side-channel attacks. However, most studies mainly focus on leakages in terms of information-theoretic metrics, and simulated experiments utilizing profiled attacks (with known templates). In this paper, we investigate the security of IPM scheme against one typical non-profiled side-channel attack, namely higher-order correlation analysis. We demonstrate that three factors mainly influence the efficiency of higher-order correlation analysis against IPM, and they are the attack order vector, output size of the target function and attack model. In particular, we propose a new method to measure the efficiency of higher-order correlation analyses. Generally speaking, this method is based on the correlation coefficient between leakage expectations with certain shares and sensitive values under the attack model. We validate our method by both simulation-based experiments and practical one with different attack factors. All experiments are running on the IPM in the different noise scenarios. The results demonstrate that our method works well as an indicator for higher-order correlation analyses against IPM. Jingdian Ming, Yongbin Zhou, Wei Cheng 0003, Huizhong Li |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | Pluto: Exposing Vulnerabilities in Inter-Contract ScenariosabstractAttacks on smart contracts have caused considerable losses to digital assets. Many techniques based on symbolic execution, fuzzing, and static analysis are used to detect contract vulnerabilities. Most of the current analyzers only consider vulnerability detection intra-contract scenarios. However, Ethereum contracts usually interact with others by calling their functions. A bug hidden in a path that depends on information from external contract calls is defined as an inter-contract vulnerability. Failure to deal with this kind of bug can result in potential false negatives and false positives. In this work, we propose Pluto, which supports vulnerability detection in inter-contract scenarios. It first builds an Inter-contract Control Flow Graph (ICFG) to extract semantic information among contract calls. Afterward, it symbolically explores the ICFG and deduces Inter-Contract Path Constraints (ICPC) to check the reachability of execution paths more accurately. Finally, Pluto detects whether there is a vulnerability based on some predefined rules. For evaluation, we compare Pluto with five state-of-the-art tools, including Oyente, Mythril, Securify, ILF, and Clairvoyance on a labeled benchmark and 39,443 real-world Ethereum smart contracts. The result shows that other tools can only detect 10% of the inter-contract vulnerabilities, while Pluto can detect 80% of them on the labeled dataset. Beyond that, Pluto has detected 451 confirmed vulnerabilities on real-world contracts, including 36 vulnerabilities in inter-contract scenarios. Two bugs have been assigned with unique CVE identifiers by the US National Vulnerability Database (NVD). On average, Pluto costs 16.9 seconds to analyze a contract, which is as fast as the state-of-the-art tools. Fuchen Ma, Zijing Yin, Yuanliang Chen, Lei Qiao 0002, Bin Gu 0006, Huizhong Li, Yu Jiang 0001, Jia-Guang Sun 0001 |
IEEE Trans. Software Eng. | 8 |
| 2021 | APT: Efficient Side-Channel Analysis Framework against Inner Product Masking SchemeabstractDue to its provable security and remarkable device-independence, masking has been widely accepted as a good algorithmic-level countermeasure against side-channel attacks. Subsequently, several code-based masking schemes are proposed to strengthen the original Boolean masking (BM) scheme, and Inner Product Masking (IPM) scheme is typically one of those. In this paper, we provide a framework, named analysis with predicted template (APT), for side-channel analysis against the IPM scheme. Following this framework, we propose two attacks based on maximum likelihood and Euclidean distance, respectively. To evaluate their efficiency, we perform simulated experiments on first-order BM and an optimal IPM scheme. The results show that our proposals are equivalent to a second-order CPA against BM scheme, but they are significantly efficient against an optimal IPM. In practical experiments based on an ARM Cortex-M4 architecture, the results of our proposals do not turn out well because of a few outliers in collected leakages. After filtering out these outliers, our proposals perform efficiently as expected. Finally, we argue that the side-channel security of IPM can be improved by keeping the vector L to be randomly selected from an elaborated small set. Jingdian Ming, Wei Cheng 0003, Yongbin Zhou, Huizhong Li |
ICCD | 4 |
| 2021 | SCStudio: a secure and efficient integrated development environment for smart contractsabstractWith the increasing popularity of block-chain technologies, more and more engineers use smart contracts for application implementation. Traditional supporting tools can either provide code completions based on static libraries or detect a limited set of vulnerabilities, which results in the manpower waste during coding and miss-detection of bugs. In this work, we propose SCStudio, a unified smart contract development platform, which aims to help developers implement more secure smart contracts easily. The core idea is to realize real-time security-reinforced recommendation through pattern-based learning; and to perform security-oriented validation via integrated testing. SCStudio was implemented as a plug-in of VS Code. It has been used as the official development tool of WeBank and integrated as the recommended development tool by FISCO-BCOS community. In practice, it outperforms existing contract development environments, such as Remix, improving the average word suggestion accuracy by 30%-60% and helping detect about 25% more vulnerabilities. Fuchen Ma, Zijing Yin, Huizhong Li, Ting Chen 0002, Yu Jiang 0001 |
ISSTA | 4 |
| 2021 | Empirical evaluation of smart contract testing: what is the best choice?abstractSecurity of smart contracts has attracted increasing attention in recent years. Many researchers have devoted themselves to devising testing tools for vulnerability detection. Each published tool has demonstrated its effectiveness through a series of evaluations on their own experimental scenarios. However, the inconsistency of evaluation settings such as different data sets or performance metrics, may result in biased conclusion. Zijing Yin, Fuchen Ma, Yu Jiang 0001, Chengnian Sun, Huizhong Li, Yan Cai 0001 |
ISSTA | 7 |
| 2021 | Making smart contract development more secure and easierabstractWith the rapid development of distributed applications, smart contracts have attracted more and more developers' attentions. However, developers or domain experts have different levels of familiarity with specific programming languages, like Solidity, and those vulnerabilities hidden in the code would be exploited and result in huge property losses. Existing auxiliary tools lack security considerations. Most of them only provide word completion based on fuzzy search and detection services for limited types of vulnerabilities, which results in the manpower waste during coding and potential vulnerability threats after deployment. Fuchen Ma, Zijing Yin, Huizhong Li, Wanli Chang 0001, Yu Jiang 0001 |
ESEC/SIGSOFT FSE | 5 |
| 2021 | Transparency order versus confusion coefficient: a case study of NIST lightweight cryptography S-BoxesabstractAbstract Side-channel resistance is nowadays widely accepted as a crucial factor in deciding the security assurance level of cryptographic implementations. In most cases, non-linear components (e.g. S-Boxes) of cryptographic algorithms will be chosen as primary targets of side-channel attacks (SCAs). In order to measure side-channel resistance of S-Boxes, three theoretical metrics are proposed and they are reVisited transparency order (VTO), confusion coefficients variance (CCV), and minimum confusion coefficient (MCC), respectively. However, the practical effectiveness of these metrics remains still unclear. Taking the 4-bit and 8-bit S-Boxes used in NIST Lightweight Cryptography candidates as concrete examples, this paper takes a comprehensive study of the applicability of these metrics. First of all, we empirically investigate the relations among three metrics for targeted S-boxes, and find that CCV is almost linearly correlated with VTO, while MCC is inconsistent with the other two. Furthermore, in order to verify which metric is more effective in which scenarios, we perform simulated and practical experiments on nine 4-bit S-Boxes under the non-profiled attacks and profiled attacks, respectively. The experiments show that for quantifying side-channel resistance of S-Boxes under non-profiled attacks, VTO and CCV are more reliable while MCC fails. We also obtain an interesting observation that none of these three metrics is suitable for measuring the resistance of S-Boxes against profiled SCAs. Finally, we try to verify whether these metrics can be applied to compare the resistance of S-Boxes with different sizes. Unfortunately, all of them are invalid in this scenario. Huizhong Li, Guang Yang 0042, Jingdian Ming, Yongbin Zhou, Chengbin Jin |
Cybersecur. | 1 |
| 2021 | A secure and highly efficient first-order masking scheme for AES linear operationsabstractAbstract Due to its provable security and remarkable device-independence, masking has been widely accepted as a noteworthy algorithmic-level countermeasure against side-channel attacks. However, relatively high cost of masking severely limits its applicability. Considering the high tackling complexity of non-linear operations, most masked AES implementations focus on the security and cost reduction of masked S-boxes. In this paper, we focus on linear operations, which seems to be underestimated, on the contrary. Specifically, we discover some security flaws and redundant processes in popular first-order masked AES linear operations, and pinpoint the underlying root causes. Then we propose a provably secure and highly efficient masking scheme for AES linear operations. In order to show its practical implications, we replace the linear operations of state-of-the-art first-order AES masking schemes with our proposal, while keeping their original non-linear operations unchanged. We implement four newly combined masking schemes on an Intel Core i7-4790 CPU, and the results show they are roughly 20% faster than those original ones. Then we select one masked implementation named RSMv2 due to its popularity, and investigate its security and efficiency on an AVR ATMega163 processor and four different FPGA devices. The results show that no exploitable first-order side-channel leakages are detected. Moreover, compared with original masked AES implementations, our combined approach is nearly 25% faster on the AVR processor, and at least 70% more efficient on four FPGA devices. Jingdian Ming, Yongbin Zhou, Huizhong Li, Qian Zhang 0042 |
Cybersecur. | 3 |
| 2021 | Security reinforcement for Ethereum virtual machine
Fuchen Ma, Huizhong Li, Houbing Song, Yu Jiang 0001 |
Inf. Process. Manag. | 5 |
| 2020 | Communication-Efficient Collaborative Learning of Geo-Distributed JointCloud from Heterogeneous DatasetsabstractWith the popularity of cloud computing, the use of services provided by the cloud is increasing. Due to the high communication cost, and data privacy issues, a new crosscloud collaborative computing model is demanded instead of a single giant cloud. Coping with federated learning and Joint-Cloud, we propose a federated learning-based collaborative learning framework, in which the distributed cloud entities are able to learn the same model collaboratively. As compared to traditional cloud-centric approaches, the framework for JointCloud can reduce the network bandwidth overhead and guarantee privacy. However, there are two crucial challenges in the federated manner: heterogeneity and high communication overhead. To address the heterogeneity, we propose a Teacher-Student mechanism, the key of which is a regularization term incorporated with the objective function so as to adjust the gradients from the clients among JointCloud with different data distribution. Then, based on the Teacher-Student mechanism, we further present a communication-efficient federated optimation approach via joint Identification-Verification to reduce the communication rounds. We conduct extensive experiments on Non-IID datasets. The experimental results demonstrate that the proposed framework can significantly reduce communication costs and improve performance. Xiaoli Li 0016, Chuan Chen 0001, Zibin Zheng, Huizhong Li, Qiang Yan 0001 |
JCC | 5 |
| 2020 | The Notion of Transparency Order, RevisitedabstractAbstract We revisit the definition of transparency order (TO) and that of modified transparency order (MTO) as well, which were proposed to measure the resistance of substitution boxes (S-boxes) against differential power analysis (DPA). We spot a definitional flaw in original TO, which is proved to significantly affect the soundness of TO. Regretfully, MTO overlooks this flaw, yet it happens to incur no bad effects on the correctness of MTO, even though the start point of this formulation is highly questionable. It is also this neglect that made MTO consider a variant of multi-bit DPA attack, which was mistakenly thought to appropriately serve as an alternative powerful attack. This implies the soundness of MTO is also more or less arguable. Therefore, we fix this definitional flaw and provide a revised definition named reVisited TO (VTO). For demonstrating validity and soundness of VTO, we present simulated and practical DPA attacks on implementations of $4\times 4$ and $8\times 8$ S-boxes. In addition, we also illustrate the soundness of VTO in masked S-boxes. Furthermore, as a concrete application of VTO, we present the distribution of VTO values of optimal affine equivalence classes of $4\times 4$ S-boxes and give some recommended guidelines on how to select $4\times 4$ S-boxes with higher DPA resistance at the identical level of implementation cost. Huizhong Li, Yongbin Zhou, Jingdian Ming, Guang Yang 0042, Chengbin Jin |
Comput. J. | 1 |
| 2020 | Mind the Balance: Revealing the Vulnerabilities in Low Entropy Masking SchemesabstractLow Entropy Masking Schemes (LEMS) have attracted wide attention due to their implementations simplicity and relatively good performance in protecting cryptographic implementations against Side-Channel-Attacks (SCAs). To achieve desired security, it is necessary (but not sufficient) to find proper low entropy mask sets to protect all sensitive secret-dependant intermediate variables. However, one crucial problem concerning this intuitive idea is that what `proper' mask sets should be. To formally capture such crucial qualification, we introduce the notion of balancedness to characterize this natural attribute of mask sets themselves. Considering that this notion is limited to characterize first-order security, we generalize it to d-dimension balancedness to accommodate dth-order security, then we exhibit lower and upper bounds on d-dimension balancedness for any d. With the help of these essential definitions, we prove that no balanced low entropy mask set really exists, which implies that LEMS implementations always have vulnerabilities in theory due to the unbalancedness of underlying mask sets. In order to further demonstrate the practical implications of balancedness, we show 4 different kinds of attacks on three state-of-the-art LEMS implementations. Specifically, the distribution attack proposed in this paper is a general first-order attack on LEMS. The results demonstrate that unbalanced mask sets actually do lead to serious vulnerabilities. Jingdian Ming, Yongbin Zhou, Wei Cheng 0003, Huizhong Li, Guang Yang 0042, Qian Zhang 0042 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2019 | DAPS: A Decentralized Anonymous Payment Scheme with Supervision
Qingqi Pei, Xuefeng Liu 0002, Lichuan Ma, Huizhong Li, Shui Yu 0001 |
ICA3PP (2) | 5 |
| 2019 | CDAE: Towards Empowering Denoising in Side-Channel Analysis
Guang Yang 0042, Huizhong Li, Jingdian Ming, Yongbin Zhou |
ICICS | 2 |
| 2019 | A Blockchain-Based IoT Data Management System for Secure and Scalable Data Sharing
Chenxu Wang 0001, Xiapu Luo, Huizhong Li |
NSS | 5 |
| 2019 | EVMFuzzer: detect EVM vulnerabilities via fuzz testingabstractEthereum Virtual Machine (EVM) is the run-time environment for smart contracts and its vulnerabilities may lead to serious problems to the Ethereum ecology. With lots of techniques being continuously developed for the validation of smart contracts, the testing of EVM remains challenging because of the special test input format and the absence of oracles. In this paper, we propose EVMFuzzer, the first tool that uses differential fuzzing technique to detect vulnerabilities of EVM. The core idea is to continuously generate seed contracts and feed them to the target EVM and the benchmark EVMs, so as to find as many inconsistencies among execution results as possible, eventually discover vulnerabilities with output cross-referencing. Given a target EVM and its APIs, EVMFuzzer generates seed contracts via a set of predefined mutators, and then employs dynamic priority scheduling algorithm to guide seed contracts selection and maximize the inconsistency. Finally, EVMFuzzer leverages benchmark EVMs as cross-referencing oracles to avoid manual checking. With EVMFuzzer, we have found several previously unknown security bugs in four widely used EVMs, and 5 of which had been included in Common Vulnerabilities and Exposures (CVE) IDs in U.S. National Vulnerability Database. The video is presented at https://youtu.be/9Lejgf2GSOk. Fuchen Ma, Heyuan Shi, Yu Jiang 0001, Huizhong Li |
ESEC/SIGSOFT FSE | 7 |
| 2019 | EVM*: From Offline Detection to Online Reinforcement for Ethereum Virtual MachineabstractAttacks on transactions of Ethereum could be dangerous because they could lead to a big loss of money. There are many tools detecting vulnerabilities in smart contracts trying to avoid potential attacks. However, we found that there are still many missed vulnerabilities in contracts. Motivated by this, we propose a methodology to reinforce EVM to stop dangerous transactions in real time even when the smart contract contains vulnerabilities. Basically, the methodology consists of three steps: monitoring strategy definition, opcode-structure maintenance and EVM instrumentation. Monitoring strategy definition refers to the specific rule to test whether there is a dangerous operation during transaction execution. Opcode-structure maintenance is to maintain a structure to store the rule related opcodes and analyze it before an operation execution. EVM instrumentation inserts the monitoring strategy, interrupting mechanism and the opcode-structure operations in EVM source code. For evaluation, we implement EVM*on js-evm, a widely-used EVM platform written in javascript. We collect 10 contracts online with known bugs and use each contract to execute a dangerous transaction, all of them have been interrupted by our reinforced EVM*, while the original EVM permits all attack transactions. For the time overhead, the reinforced EVM*is slower than the original one by 20-30%, which is tolerable for the financial critical applications. Fuchen Ma, Yu Jiang 0001, Huizhong Li |
SANER | 7 |
| 2018 | Convolutional Neural Network Based Side-Channel Attacks in Time-Frequency Representations
Guang Yang 0042, Huizhong Li, Jingdian Ming, Yongbin Zhou |
CARDIS | 2 |