EDBT 2026 Demo / reviewers in the wild / expert
Yuncong Hu
dblp:241/9318
· DBLP profile ↗
13ranked-venue papers
3as first author
10since 2021 · last 2026
0000-0002-8338-3507ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 2 first-author · 7 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Secure Lookup Tables: Faster, Leaner, and More General
Chongrong Li, Yun Li 0010, Zhanpeng Guo, Yuncong Hu, Cheng Hong 0001 |
SP | 6 |
| 2026 | Plontank: An FPGA-based zk-SNARK acceleration system for secure computing
Dahong Qian, Yuncong Hu |
J. Parallel Distributed Comput. | 3 |
| 2025 | DFS: Delegation-friendly zkSNARK and Private Delegation of Provers
Yuncong Hu, Pratyush Mishra 0001, Xiao Wang 0012, Kang Yang 0002, Yu Yu 0001 |
USENIX Security Symposium | 1 |
| 2024 | Hadamard Product Argument from Lagrange-Based Univariate Polynomials
Yuncong Hu |
ACISP (1) | 2 |
| 2024 | A Succinct Range Proof for Polynomial-based Vector CommitmentabstractA range proof serves as a protocol for the prover to prove to the verifier that a committed number lies in a specified range, such as [0,2n), without disclosing the actual value. Range proofs find extensive application in various domains. However, the efficiency of many existing schemes diminishes significantly when confronted with batch proofs encompassing multiple elements. Rui Gao 0007, Zhiguo Wan, Yuncong Hu, Huaqun Wang |
CCS | 3 |
| 2024 | HuRef: HUman-REadable Fingerprint for Large Language ModelsabstractProtecting the copyright of large language models (LLMs) has become crucial due to their resource-intensive training and accompanying carefully designed licenses. However, identifying the original base model of an LLM is challenging due to potential parameter alterations. In this
study, we introduce HuRef, a human-readable fingerprint for LLMs that uniquely identifies the base model without interfering with training or exposing model parameters to the public.
We first observe that the vector direction of LLM parameters remains stable after the model has converged during pretraining,
with negligible perturbations through subsequent training steps, including continued pretraining, supervised fine-tuning, and RLHF,
which makes it a sufficient condition
to identify the base model.
The necessity is validated by continuing to train an LLM with an extra term to drive away the model parameters' direction and the model becomes damaged. However, this direction is vulnerable to simple attacks like dimension permutation or matrix rotation, which significantly change it without affecting performance. To address this, leveraging the Transformer structure, we systematically analyze potential attacks and define three invariant terms that identify an LLM's base model.
Due to the potential risk of information leakage, we cannot publish invariant terms directly. Instead, we map them to a Gaussian vector using an encoder, then convert it into a natural image using StyleGAN2, and finally publish the image. In our black-box setting, all fingerprinting steps are internally conducted by the LLMs owners. To ensure the published fingerprints are honestly generated, we introduced Zero-Knowledge Proof (ZKP).
Experimental results across various LLMs demonstrate the effectiveness of our method. The code is available at https://github.com/LUMIA-Group/HuRef. Boyi Zeng, Yuncong Hu, Yi Xu 0004, Chenghu Zhou, Xinbing Wang, Zhouhan Lin |
NeurIPS | 3 |
| 2024 | A Verifiable and Privacy-Preserving Federated Learning Training FrameworkabstractFederated learning allows multiple clients to collaboratively train a global model without revealing their private data. Despite its success in many applications, it remains a challenge to prevent malicious clients to corrupt the global model through uploading incorrect model updates. Hence, one critical issue arises in how to validate the training is truly conducted on legitimate neural networks. To address the issue, we proposeVPNNT, a zero-knowledge proof scheme for neural network backpropagation.VPNNTenables each client to prove to others that the model updates (gradients) are indeed calculated on the global model of the previous round, without leaking any information about the client's private training data. Our proof scheme is generally applicable to any type of neural network. Different from conventional verification schemes constructing neural network operations by gate-level circuits, we improve verification efficiency by formulating the training process using custom gates — matrix operations, and apply an optimized linear time zero knowledge protocol for verification. Thanks to the recursive structure of neural network backward propagation, common custom gates are combined in verification thereby reducing prover and verifier costs over conventional zero knowledge proofs. Experimental results show thatVPNNTis a lightweighted verification scheme for neural network backpropagation with an improved prove time, verification time and proof size. Haohua Duan, Zedong Peng, Liyao Xiang, Yuncong Hu, Bo Li 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | Gemini: Elastic SNARKs for Diverse Environments
Jonathan Bootle, Alessandro Chiesa, Yuncong Hu, Michele Orrù |
EUROCRYPT (2) | 3 |
| 2022 | Question-Driven Graph Fusion Network for Visual Question AnsweringabstractExisting Visual Question Answering (VQA) models have ex-plored various visual relationships between objects in the im-age to answer complex questions, which inevitably introduces irrelevant information brought by inaccurate object detection and text grounding. To address the problem, we propose a Question-Driven Graph Fusion Network (QD-GFN). It first models semantic, spatial, and implicit visual relations in images by three graph attention networks, then question in-formation is utilized to guide the aggregation process of the three graphs, further, our QD-GFN adopts an object filtering mechanism to remove question-irrelevant objects contained in the image. Experiment results demonstrate that our QD-GFN outperforms the prior state-of-the-art on both VQA 2.0 and VQA-CP v2 datasets. Further analysis shows that both the novel graph aggregation method and object filtering mecha-nism play a significant role in improving the performance of the model. Yuxi Qian, Yuncong Hu, Fangxiang Feng, Xiaojie Wang 0006 |
ICME | 2 |
| 2021 | Merkle2: A Low-Latency Transparency Log SystemabstractTransparency logs are designed to help users audit untrusted servers. For example, Certificate Transparency (CT) enables users to detect when a compromised Certificate Authority (CA) has issued a fake certificate. Practical state-of-the-art transparency log systems, however, suffer from high monitoring costs when used for low-latency applications. To reduce monitoring costs, such systems often require users to wait an hour or more for their updates to take effect, inhibiting low-latency applications. We propose Merkle2, a transparency log system that supports both efficient monitoring and low-latency updates. To achieve this goal, we construct a new multi-dimensional, authenticated data structure that nests two types of Merkle trees, hence the name of our system, Merkle2. Using this data structure, we then design a transparency log system with efficient monitoring and lookup protocols that enables low-latency updates. In particular, all the operations in Merkle2are independent of update intervals and are (poly)logarithmic to the number of entries in the log. Merkle2not only has excellent asymptotics when compared to prior work, but is also efficient in practice. Our evaluation shows that Merkle2propagates updates in as little as 1 second and can support 100× more users than state-of-the-art transparency logs. Yuncong Hu, Kian Hooshmand, Harika Kalidhindi, Seung Jin Yang, Raluca A. Popa |
SP | 1 |
| 2020 | Marlin: Preprocessing zkSNARKs with Universal and Updatable SRS
Alessandro Chiesa, Yuncong Hu, Mary Maller, Pratyush Mishra 0001, Psi Vesely, Nicholas P. Ward |
EUROCRYPT (1) | 2 |
| 2020 | Ghostor: Toward a Secure Data-Sharing System from Decentralized Trust
Yuncong Hu, Sam Kumar, Raluca A. Popa |
NSDI | 1 |
| 2019 | JEDI: Many-to-Many End-to-End Encryption and Key Delegation for IoT
Sam Kumar, Yuncong Hu, Michael P. Andersen, Raluca A. Popa, David E. Culler |
USENIX Security Symposium | 2 |