EDBT 2026 Demo / reviewers in the wild / expert
Anxin Zhou
dblp:227/7175
· DBLP profile ↗
14ranked-venue papers
0as first author
10since 2021 · last 2024
0000-0003-1982-6200ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 7 since 2021Computer networks · 3 · 1 since 2021Systems, architecture and hardware · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Toward Full Accounting for Leakage Exploitation and Mitigation in Dynamic Encrypted DatabasesabstractEncrypted databases have garnered considerable attention for their ability to safeguard sensitive data outsourced to third parties. However, recent studies have revealed the vulnerability of encrypted databases to leakage-abuse attacks on their search module, prompting the development of countermeasures to address this issue. While most studies have focused on static databases, limited research has been conducted on dynamic encrypted databases. To bridge this gap, this paper focuses on undertaking a comprehensive examination of leakage exploitation in dynamic encrypted databases, with the aim of providing effective mitigations. Our investigation begins with two attacks that can be employed to recover encrypted queries. The first attack, known as an active attack, involves injecting encoded files and utilizing correlated file volume information. The second attack, referred to as a passive attack, identifies unique relational characteristics of queries across database updates, assuming certain background knowledge of the plaintext databases. To mitigate these attacks, a two-layer encrypted database hardening approach is proposed, which obfuscates both search indexes and files in a continuous way. Doing so allows us to eliminate the unique characteristics emerging after data updates constantly. We conduct a series of experiments to confirm the severity of our attacks and the effectiveness of our countermeasures. Lei Xu 0019, Anxin Zhou, Huayi Duan, Cong Wang 0001, Qian Wang 0002, Xiaohua Jia |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | DWare: Cost-Efficient Decentralized Storage With Adaptive MiddlewareabstractDistributed Outsourced Storage systems, exemplified by the InterPlanetary File System (IPFS), offer compelling alternatives to traditional centralized cloud storage by emphasizing resilience and openness. Advancing this paradigm, Decentralized Storage (DS) markets leverage distributed ledgers to facilitate the monetization of outsourced storage. However, these markets often prioritize security over cost-efficiency, leading to high costs in existing DS markets. In our work, we introduce a middleware service, DWare, utilizing trusted hardware to balance security and cost efficiency. DWare offers two key advantages: 1) It enhances storage auditing efficiency by delegating computational tasks and standardizing the batched audit process. This approach offers a more feasible solution for validating outsourced storage with recurring pay-offs. 2) It implements secure and verifiable data deduplication, thereby increasing storage efficiency and reducing operational costs. This step, commonplace in cloud storage services, remains largely unexplored in current DS designs. While DWare could empirically reduce costs to levels near raw storage fees, it entails certain security concessions due to middleware involvement. To address this, we propose a hybrid trust security model, granting data owners the flexibility to adjust the security-cost balance as needed. Yuefeng Du 0001, Anxin Zhou, Cong Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Towards secure and trustworthy crowdsourcing: challenges, existing landscape, and future directions
Rui Lian, Anxin Zhou, Yifeng Zheng 0001 |
Wirel. Networks | 2 |
| 2023 | Demystifying Web3 Centralization: The Case of Off-Chain NFT Hijacking
Felix Stöger, Anxin Zhou, Huayi Duan, Adrian Perrig |
FC | 2 |
| 2022 | Enhancing Cryptocurrency Blocklisting: A Secure, Trustless, and Effective RealizationabstractThe flourishing development of blockchain and cryptocurrency has made it a hotbed for cyber-criminals to implement virtually untraceable scams. Consequently, the blockchain ecosystem urgently needs an effective method to help users stay away from scams in order to create an enticing investment environment. Despite the massive deployment of blocklist query APIs for malicious and scam domains/URLs in the industry, we identify two core reasons why existing blocklist services find it difficult to thrive in the cryptocurrency paradigm: 1) the compelling need to protect a user query due to sensitivity and high value of query content, i.e., payment addresses; 2) the thorny issue of evaluating the quality of blocklists effectively, in the face of common practices of incompetent providers.To this end, we first provide a private and highly efficient blocklist query scheme as a basic design, which conveniently achieves backward compatibility with current blockchain payment systems at a considerably low cost. Based on this design, we propose a new framework for shareholders to evaluate the quality of blocklists. Our framework provides stronger security guarantees than other similar works, as it is capable of suppressing both individual biasing and coercive manipulation at the same time. We provide a complete game-theoretic analysis and demonstrate comprehensive evaluation results to confirm the effectiveness and efficiency of our solutions, under the settings of a practical number of shareholders. Yuefeng Du 0001, Anxin Zhou, Cong Wang 0001 |
ICDCS | 2 |
| 2022 | Toward a Secure, Rich, and Fair Query Service for Light Clients on Public BlockchainsabstractThe rapid growth of storage overhead on public blockchains has urged the use of light clients that only store a small fraction of blockchain data and rely on other bootstrapped full nodes for data retrievals. Unfortunately, current blockchain light client designs are far from satisfactory. First, outsourcing retrieval requests could raise severe concerns about result correctness and privacy threats. Second, current light clients do not support rich query and enforce fee payments to full nodes. Given that blockchain storage increases day by day, enabling effective rich blockchain queries and fairly compensating full nodes’ ever growing costs has become extremely necessary. In this article, we propose a general and secure paid query framework to simultaneously meet those demands above. Specifically, we leverage the integration of trusted hardware (e.g., Intel SGX) and smart contract as a starting point for building efficient yet secure query processing with fair payments. Then, we further craft several crucial performance and security refinement designs to boost query efficiency and enforce result correctness, and also explore an enclave-facilitated fair settlement mechanism for on-chain cost optimizations. We implement a prototype of our paid query framework and the experimental result has demonstrated its practically affordable cost. Chengjun Cai, Lei Xu 0019, Anxin Zhou, Cong Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | Enabling Secure and Efficient Decentralized Storage Auditing With BlockchainabstractAs a promising alternative solution to cloud storage, decentralized storage networks (DSN) are widely anticipated to develop continuously and reshape the storage market share in the foreseeable future. In particular, one of the most important research problems is how to enforce the quality of service (QoS) in the context of storage solutions. Despite plenty of auditing-related works in the context of cloud storage, none of them can be directly applied to the decentralized storage paradigm. The challenges of designing a feasible storage auditing framework emanate from two aspects: 1) security problems unique to the decentralized settings and 2) performance overhead due to on-chain operations. In this article, we first put forward a basic storage auditing framework that satisfies the security and efficiency requirements, and outperforms the existing approaches. We also identify a critical and overlooked security problem that would compromise the integrity of storage auditing solutions in the blockchain paradigm. With our refined storage auditing design based on customized zero knowledge protocols, we propose a convenient mitigation solution in our revised security model. The evaluation results confirm that our solution would only incur a 10–15 percent increase in the overall auditing costs for common usage scenarios, compared to the basic design. Yuefeng Du 0001, Huayi Duan, Anxin Zhou, Cong Wang 0001, Man Ho Au, Qian Wang 0002 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | Towards Secure and Trustworthy Crowdsourcing with Versatile Data Analytics
Rui Lian, Anxin Zhou, Yifeng Zheng 0001, Cong Wang 0001 |
QSHINE | 2 |
| 2021 | Building a Secure Knowledge Marketplace Over Crowdsensed Data StreamsabstractIt is increasingly popular to leverage the wisdom of crowd for knowledge discovery and monetization. Among others, crowdsensing with truth discovery has emerged as a promising way for leveraging the crowd wisdom, which can mine reliable knowledge from the generally unreliable sensory data contributed collected from diverse sources. Building a knowledge marketplace based on crowdsensing with truth discovery for knowledge discovery and monetization, however, is non-trivial and has to overcome several challenges. First, the sensory data should be protected as they may carry sensitive information. Second, many real crowdsensing applications usually yield sensory data in a streaming fashion, posing the demand that truth discovery should be conducted over data streams to continuously mine reliable knowledge in each data collection epoch. Third, knowledge monetization should be well treated, fully addressing the practical needs of parties in the monetization ecosystem. In this article, we take the first research attempt and propose a new full-fledged framework for building a secure knowledge marketplace over crowdsensed data streams. Our marketplace supports secure monetization of reliable knowledge mined privately from data streams in crowdsensing applications. Our framework leverages lightweight cryptographic techniques like additive secret sharing to enable privacy-preserving streaming truth discovery, continuously producing reliable knowledge over data streams. For monetization of the learned truth, i.e., knowledge, we resort to the emerging blockchain technology and deliver a tailored and full-fledged design, which promises monetization fairness, knowledge confidentiality, and streamlined processing. Extensive experiments on Amazon cloud and Ethereum blockchain demonstrate the practically affordable performance of our design. Chengjun Cai, Yifeng Zheng 0001, Anxin Zhou, Cong Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | Interpreting and Mitigating Leakage-Abuse Attacks in Searchable Symmetric EncryptionabstractSearchable symmetric encryption (SSE) enables users to make confidential queries over always encrypted data while confining information disclosure to pre-defined leakage profiles. Despite the well-understood performance and potentially broad applications of SSE, recent leakage-abuse attacks (LAAs) are questioning its real-world security implications. They show that a passive adversary with certain prior information of a database can recover queries by exploiting the legitimately admitted leakage. While several countermeasures have been proposed, they are insufficient for either security, i.e., handling only specific leakage like query volume, or efficiency, i.e., incurring large storage and bandwidth overhead. We aim to fill this gap by advancing the understanding of LAAs from a fundamental algebraic perspective. Our investigation starts by revealing that the index matrices of a plaintext database and its encrypted image can be linked by linear transformation. The invariant characteristics preserved under the transformation encompass and surpass the information exploited by previous LAAs. They allow one to unambiguously link encrypted queries with corresponding keywords, even with only partial knowledge of the database. Accordingly, we devise a new powerful attack and conduct a series of experiments to show its effectiveness. In response, we propose a new security notion to thwart LAAs in general, inspired by the principle of local differential privacy (LDP). Under the notion, we further develop a practical countermeasure with tunable privacy and efficiency guarantee. Experiment results on representative real-world datasets show that our countermeasure can reduce the query recovery rate of LAAs, including our own. Lei Xu 0019, Huayi Duan, Anxin Zhou, Xingliang Yuan, Cong Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | Towards Privacy-assured and Lightweight On-chain Auditing of Decentralized StorageabstractHow to audit outsourced data in centralized storage like cloud is well-studied, but it is largely under-explored for the rising decentralized storage network (DSN) that bodes well for a billion-dollar market. To realize DSN as a usable service in a fully decentralized manner, the blockchain comes in handy - to record and verify audit trails in forms of proof of storage, and based on that, to enforce fair payments with necessary dispute resolution. Leaving the audit trails on the blockchain offers transparency and fairness, yet it 1) sacrifices privacy, as they may leak information about the data under audit, and 2) overwhelms onchain resources, as they may be practically large in size and expensive to verify. Prior auditing designs in centralized settings are not directly applicable here. A handful of proposals targeting DSN cannot satisfactorily address these issues either. We present an auditing solution that addresses on-chain privacy and efficiency, from a synergy of homomorphic linear authenticators with polynomial commitments for succinct proofs, and the sigma protocol for provable privacy. The solution results in, per audit, 288-byte proof written to the blockchain, and constant verification cost. It can sustain long-term operation and easily scale to thousands of users on Ethereum. Yuefeng Du 0001, Huayi Duan, Anxin Zhou, Cong Wang 0001, Man Ho Au, Qian Wang 0002 |
ICDCS | 3 |
| 2020 | EncELC: Hardening and Enriching Ethereum Light Clients with Trusted EnclavesabstractThe rapid growth of Ethereum blockchain has brought extremely heavy overhead for coin owners or developers to bootstrap and access transactions on Ethereum. To address this, light client is enabled, which only stores a small fraction of blockchain data and relies on bootstrapped full nodes for transaction retrievals. However, because the retrieval requests are outsourced, it raises several severe concerns about the integrity of returned results and the leakage of sensitive blockchain access histories, largely hindering the wider adoption of this important lightweight design. In addition to security issues, the continuously increasing blockchain storage also urges for more effective query functionalities for the Ethereum blockchain, so as to enable more flexible and precise transaction retrievals.In this paper, we propose EncELC, a new Ethereum light client design that enforces full-fledged protections for clients and enables rich queries over the Ethereum blockchain. EncELC leverages trusted hardware (e.g., Intel SGX) as a starting point for building efficient yet secure processing, and further crafts several crucial performance and security refinement designs to boost query efficiency and conceal leakages inside and outside SGX enclave. We implement a prototype of EncELC and test its performance in several real settings, and the results have confirmed the practicality of EncELC. Chengjun Cai, Lei Xu 0019, Anxin Zhou, Cong Wang 0001, Qian Wang 0002 |
INFOCOM | 3 |
| 2019 | Aggregating Crowd Wisdom via Blockchain: A Private, Correct, and Robust RealizationabstractCrowdsensing, driven by the proliferation of sensor-rich mobile devices, has emerged as a promising data sensing and aggregation paradigm. Despite useful, traditional crowdsensing systems typically rely on a centralized third-party platform for data collection and processing, which leads to concerns like single point of failure and lack of operation transparency. Such centralization hinders the wide adoption of crowdsensing by wary participants. We therefore explore an alternative design space of building crowdsensing systems atop the emerging decentralized blockchain technology. While enjoying the benefits brought by the public blockchain, we endeavor to achieve a consolidated set of desirable security properties with a proper choreography of latest techniques and our customized designs. We allow data providers to safely contribute data to the transparent blockchain with the confidentiality guarantee on individual data and differential privacy on the aggregation result. Meanwhile, we ensure the service correctness of data aggregation and sanitization by delicately employing hardware-assisted transparent enclave. Furthermore, we maintain the robustness of our system against faulty data providers that submit invalid data, with a customized zero-knowledge range proof scheme. The experiment results demonstrate the high efficiency of our designs on both mobile client and SGX-enabled server, as well as reasonable on-chain monetary cost of running our task contract on Ethereum. Huayi Duan, Yifeng Zheng 0001, Yuefeng Du 0001, Anxin Zhou, Cong Wang 0001, Man Ho Au |
PerCom | 4 |
| 2018 | CrowdBuy: Privacy-friendly Image Dataset Purchasing via CrowdsourcingabstractIn recent years, advanced machine learning techniques have demonstrated remarkable achievements in many areas. Despite the great success, one of the bottlenecks in applying machine learning techniques in real world applications lies in the lack of a large amount of high-quality training data from diverse domains. Meanwhile, massive personal data is being generated by mobile devices and is often underutilized. To bridge the gap, we propose a general dataset purchasing framework, named CrowdBuy and CrowdBuy++, based on crowdsourcing, with which a buyer can efficiently buy desired data from available mobile users with quality guarantee in a way respecting users' data ownership and privacy. We present a complete set of tools including privacy-preserving image dataset quality measurements and image selection mechanisms, which are budget feasible, truthful and highly efficient for mobile users. We conducted extensive evaluations of our framework on large-scale images and demonstrate that the system is capable of crowdsourcing high quality datasets while preserving image privacy with little computation and communication overhead. Lan Zhang 0002, Yannan Li 0001, Xiang-Yang Li 0001, Anxin Zhou, Qiang Li 0054 |
INFOCOM | 6 |