EDBT 2026 Demo / reviewers in the wild / expert
Zhongxiang Zheng
dblp:22/10540
· DBLP profile ↗
12ranked-venue papers
3as first author
7since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-authorTheory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Practical Secure Inference Algorithm for a Fine-Tuned Large Language Model Based on Fully Homomorphic EncryptionabstractLarge language models (LLMs) are currently at the forefront of the machine learning field, showing broad application prospects but at the same time presenting certain risks of privacy leakage. Both the training datasets and the user’s input data during interactions face security issues, which need to be addressed urgently before their further development. To address this problem, we combine privacy-preserving techniques such as fully homomorphic encryption (FHE) and provable security theory with parameter-efficient fine-tuning (PEFT) to propose an efficient and secure inference scheme for LLMs that protects both the user-side’s input and the server-side’s private parameters. More specifically, we focus on pretrained LLMs that rely on open-sourced base models and then are fine-tuned with private datasets by LoRA. This is a popular roadmap for vertical domain large models such as LawGPT and BenTsao. To achieve this efficient and secure inference LLM scheme, we use two key technologies that are summarized below. • First, we divide the whole model into two parts, denoted as the public part and the private part. The weights of the public part are publicly accessible (e.g., the open-sourced base model), whereas those of the private part need to be protected (e.g., the LoRA matrices). Then, the public part is deployed on the client side, and the server maintains the private part. In this way, the overhead associated with computing on private data can be greatly reduced. • Second, we propose a general method to transform a linear layer into another one that provides security against model extraction attacks and preserves its original functionality, denoted as the private linear layer (PLL). Afterwards, we use this method on the LoRA matrices of the server side, where the PLL changes the computation of the LoRA matrices in a way that accomplishes correct inference and ensures that the server protects their private weights without restricting the user’s input. We also show that the difficulty of performing model extraction attacks for the PLL can be reduced to the well-known hard problem of learning with errors (LWE). Combining this method with FHE, we can obtain an inference algorithm for fine-tuned LLMs that protects the user’s input and the server’s private weights at the same time. In this paper, we use the open-source model ChatGLM2-6B as the base model, which is fine-tuned by LoRA. The experimental results show that the inference efficiency of our scheme reaches 1.61 s/token, demonstrating that the scheme is highly practical. Ruoyan Zhang, Zhongxiang Zheng, Wankang Bao |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Beyond Algorithmic Proofs: Towards Implementation-Level Provable SecurityabstractWhile traditional cryptographic research focuses on algorithm-level provable security, many real-world attacks exploit weaknesses in system implementations, such as memory mismanagement, poor entropy sources, and insecure key lifecycles. Existing approaches address these risks in isolation but lack a unified, verifiable framework for modeling implementation-layer security. In this work, we propose Implementation-Level Provable Security, a new paradigm that defines security in terms of structurally verifiable resilience against real-world attack surfaces during deployment. To demonstrate its feasibility, we present SEER (Secure and Efficient Encryption-based Erasure via Ransomware), a file destruction system that repurposes and reinforces the encryption core of Babuk ransomware. SEER incorporates key erasure, entropy validation, and execution consistency checks to ensure a well-constrained, auditable attack surface. Our evaluation shows that SEER achieves strong irrecoverability guarantees while maintaining practical performance. This work demonstrates a shift from abstract theoretical models toward practically verifiable implementation-layer security. Jiahui Shang, Luning Zhang, Zhongxiang Zheng |
TrustCom | 3 |
| 2025 | VeriKNN: A verifiable and efficient secure k-NN query scheme via homomorphic encryption in dual-cloud environments
Bao Wankang, Zhongxiang Zheng |
J. Inf. Secur. Appl. | 2 |
| 2022 | A detailed analysis of primal attack and its variants
Zhongxiang Zheng |
Sci. China Inf. Sci. | 2 |
| 2022 | A Refinement of Key Mismatch Attack on NewHopeabstractAbstract NewHope cryptosystem is one of the second-round submissions of the National Institute of Standards and Technology post-quantum cryptography standardization process, which is a suite of two key encapsulation mechanisms based on the ring-learning with errors (LWE) problem. It has received much attention from the research community due to its small key size and high efficiency. Recently, three key mismatch attacks are proposed against NewHope under the condition of key reuse. They do not solve the ring-LWE instance directly but exploit the leakage of secret information. As far as we know, the best result is given by Okada et al. ((2020) Improving Key Mismatch Attack on NewHope with Fewer Queries. In Proc. of the 25th Australasian Conf. on Information Security and Privacy, Perth, WA, Australia, November 30–December 2, pp. 505–524. Springer Cham, Switzerland), which recovers the whole secret with a success probability of $97\%$ and $233,803$ average queries. In this paper, we further improve the key mismatch attack of NewHope by reducing the average queries to $106,577$ and raising the success probability to $100\%$. Moreover, we analyze the key mismatch attack without key reuse for the first time and we propose a combinatorial attack against NewHope1024. The total complexity of the combinatorial attack is $2^{253}$, which is lower than the complexity of primal attack and the claimed security strength of NewHope1024. Zhongxiang Zheng, Anyu Wang 0001 |
Comput. J. | 2 |
| 2021 | Optimizing Bootstrapping and Evaluating Large FHE Gates in the LWE-Based GSW-FHE
Chao Liu 0060, Anyu Wang 0001, Zhongxiang Zheng |
ACISP | 3 |
| 2021 | Error estimation of practical convolution discrete Gaussian sampling with rejection sampling
Zhongxiang Zheng, Xiaoyun Wang 0001, Guangwu Xu, Chunhuan Zhao |
Sci. China Inf. Sci. | 1 |
| 2019 | Provably Secure Three-Party Password-Based Authenticated Key Exchange from RLWE
Chao Liu 0060, Zhongxiang Zheng, Keting Jia, Qidi You |
ISPEC | 2 |
| 2019 | Identity-Concealed Authenticated Encryption from Ring Learning with Errors
Chao Liu 0060, Zhongxiang Zheng, Keting Jia, Limin Tao |
ProvSec | 2 |
| 2019 | Improved analysis of the reduction from BDD to uSVP
Chunhuan Zhao, Zhongxiang Zheng |
Inf. Process. Lett. | 2 |
| 2018 | Orthogonalized lattice enumeration for solving SVP
Zhongxiang Zheng, Xiaoyun Wang 0001, Guangwu Xu, Yang Yu 0008 |
Sci. China Inf. Sci. | 1 |
| 2013 | Screen Space Anisotropic Blurred Soft Shadows by Efficient Separable Filtering MethodabstractShadow mapping is an efficient method to generate shadows in real time computer graphics and has broad variations from hard to soft shadow synthesis. Soft shadowing based on shadow mapping is a blurring technique on a shadow map or on screen space. Blurring on screen space can easily combine with a deferred shading pipeline. However, blurring on screen space has a drawback: the generated shadow is not correct when a view direction has a large angle to the normal of the shadowed plane. In this paper, we introduce a new screen space based method for soft shadowing that is faster and generates more accurate soft shadows than the previous screen space soft shadow mapping method. The resultant images show shadows by our method just stand in the same place, while shadows by the previous method change in terms of penumbra while the view moves. Surprisingly, although our method is more complex than the previous method, the measurement of the calculation time shows our method is also faster than the previous method. This is because our method controls the blurring area more accurately and thus successfully reduces multiplications for blurring. Zhongxiang Zheng, Suguru Saito |
CW | 1 |