EDBT 2026 Demo / reviewers in the wild / expert
Qiuyun Tong
dblp:251/1440
· DBLP profile ↗
14ranked-venue papers
9as first author
13since 2021 · last 2026
0000-0003-4715-5627ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 3 · 2 first-author · 3 since 2021Computer networks · 3 · 1 first-author · 2 since 2021Security and privacy · 3 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Traceable Cross-Domain Data Sharing With Expressive Keyword SearchabstractThe Internet of Vehicles (IoV) generates massive sensitive perception data, typically managed by manufacturer-specific domains. While encryption with domain-specific parameters protects confidentiality, many IoV applications require secure cross-domain data sharing to access complementary information, and expressive keyword search for efficient access. However, existing Attribute-Based Keyword Search (ABKS) schemes are designed for single-domain settings, and thus cannot address heterogeneous key management or provide traceability without a universally trusted authority. To address these issues, we propose TCroS, a traceable cross-domain data sharing scheme that generalizes CP-ABE via proxy re-encryption mechanism, enabling ciphertexts generated in one domain to be securely transformed for authorized requesters in another. To provide traceability, TCroS embeds requester identities into decryption keys using Boneh-Boyen signatures, allowing any party (rather than the universally trusted authority) to trace the source of a leaked key. We further extend TCroS to TCroSS, which incorporates privacy-preserving expressive keyword search supporting Boolean queries, thereby enabling efficient retrieval of authorized data while resisting keyword guessing attacks. Formal security analysis proves that our schemes achieve IND-SCPA and IND-SCKA security. Experimental results demonstrate their practicality, showing that cross-domain sharing can be realized with computation and storage overheads comparable to single-domain setting. Qiuyun Tong, Xiyun Yao, Zhe Ren, Yinbin Miao, Xinghua Li 0001, Meng Li 0006, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Oblivious Encrypted Keyword Search With Fine-Grained Access Control for Cloud StorageabstractWith the rapid expansion of data volumes in cloud computing, more data owners are opting to outsource their data to cloud service providers to reduce local storage and management costs. However, data outsourcing deprives data owners of direct physical control over their data, increasing the risk of unauthorized access and exposure of sensitive information. To mitigate these risks, various privacy-preserving keyword search schemes with access control have been developed, but many are vulnerable to leakage-abuse attacks due to the exposure of access, search or volume patterns, which can lead to privacy breaches in outsourced data and queries. To solve this problem, we propose an oblivious encrypted keyword search scheme with fine-grained access control, called OEKA. It enables efficient oblivious keyword search over encrypted multi-maps by using the adapted XOR filter and distributed point function, ensuring protection of access, search and volume patterns. Moreover, OEKA enforces role-based access control by using polynomial-based access strategy and keyword-based private information retrieval, allowing access policies of retrieved objects to be detecting without revealing the objects themselves. A formal security analysis verifies the scheme’s robustness, and experimental results demonstrate its practical efficiency. Qiuyun Tong, Junyi Deng, Xinghua Li 0001, Yinbin Miao, Yunwei Wang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | PLRQ: Practical and Less Leakage Range Query Over Encrypted Mobile Cloud DataabstractAs a fundamental service in mobile cloud computing, range query has attracted extensive attention. But the existing secure range query schemes not only leak data privacy but also have low query efficiency. To address those issues, we first design a novel range-matched code to convert the range query into code set matching, which aims to hide the order relationship of outsourced data as well as the index of most significant different bit. Based on the designed range-matched code, we propose aPractical andLess LeakageRangeQuery scheme over encrypted mobile cloud data (PLRQ) by integrating XOR filter and multiset hash function. Security analysis shows that PLRQ achieves semantic security and avoids data privacy leakage. Extensive experiments using real datasets demonstrate that, compared with two state-of-the-art solutions-RngMatch and LSRQ, our proposed PLRQ improves the query efficiency both by 2 orders of magnitude, and reduces the storage cost on Cloud Service Provider by about 79.5% and 73.6% respectively. Yunwei Wang, Xinghua Li 0001, Yinbin Miao, Qiuyun Tong, Ximeng Liu, Robert H. Deng |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | Beyond Result Verification: Efficient Privacy-Preserving Spatial Keyword Query With Suppressed LeakageabstractBoolean range query (BRQ) as a typical type of spatial keyword query that is widely used in geographic information systems, location-based services and other applications. It retrieves the objects inside the query range and containing all query keywords. Many privacy-preserving BRQ schemes have been proposed to support BRQ over encrypted data. However, most of them fail to achieve efficient retrieval and lightweight result verification while suppressing access and search pattern leakage. Thus, in this paper, we propose an efficient verifiable privacy-preserving Boolean range query with suppressed leakage. Firstly, we convert BRQ into multi-keyword query by using Gray code and Bloom filter. Then, we achieve efficient oblivious multi-keyword query by combining distributed point function and PRP-based Cuckoo hashing, which protects the access and search patterns. Moreover, we support lightweight and oblivious result verification based on oblivious query, aggregate MAC, keyed-hashing MAC and XOR-homomorphic pseudorandom function. It enables query users to verify the result integrity with a proof whose size is independent of the size of the outsourced dataset. Finally, formal security analysis and extensive experiments demonstrate that our proposed scheme is adaptively secure and efficient for practical applications, respectively. Qiuyun Tong, Xinghua Li 0001, Yinbin Miao, Yunwei Wang, Ximeng Liu, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Privacy-Preserving Boolean Range Query With Temporal Access Control in Mobile ComputingabstractWith increasingly popular GPS-equipped mobile devices (e.g., smartphones, tablets, laptops), massive spatio-textual data has been outsourced to cloud servers for storage and analysis such as spatial keyword search. However, existing privacy-preserving spatial keyword query schemes only support coarse-grained non-temporal access control in single-user sharing scenarios, which does not scale well in time-related scenes such as message valid period. To solve the above issues, we propose Privacy-preserving Boolean Range Query with Temporal access control in mobile computing (PBRQ-T). Specifically, we first achieve PBRQ with linear search complexity using the adapted Gray code, Bloom filter, and Katz-Sahai-Waters encryption. Then, we provide fine-grained and temporal access control in PBRQ based on the forward/backward derivation function and attribute-based encryption, where PBRQ is executed only when the spatio-textual data is accessible. Finally, an enhanced PBRQ-T (i.e., PBRQ-T+) with faster-than-linear search complexity is proposed by constructing a Quadtree index structure. Our formal security analysis shows that data privacy and index privacy can be guaranteed during the query process. Our extensive experiments using a real-world dataset demonstrate the efficiency and feasibility of our schemes. Qiuyun Tong, Xinghua Li 0001, Yinbin Miao, Ximeng Liu, Jian Weng 0001, Robert H. Deng |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2023 | Verifiable Fuzzy Multi-Keyword Search Over Encrypted Data With Adaptive SecurityabstractTo ensure the security of outsourced data without affecting data availability, one can use Symmetric Searchable Encryption (SSE) to achieve search over encrypted data. Considering that query users may search with misspelled words, the fuzzy search should be supported. However, conventional privacy-preserving fuzzy multi-keyword search schemes are incapable of achieving the result verification and adaptive security. To solve the above challenging issues, in this paper we propose a Verifiable Fuzzy multi-keyword Search scheme with Adaptive security (VFSA). VFSA first employs the locality sensitive hashing to hash the misspelled and correct keywords to the same positions, then designs a twin Bloom filter for each document to store and mask all keywords contained in the document, next constructs an index tree based on the graph-based keyword partition algorithm to achieve adaptive sublinear retrieval, finally combines the Merkle hash tree structure with the adapted multiset accumulator to check the correctness and completeness of search results. Our formal security analysis shows that VFSA is secure under the IND-CKA2 model and achieves query authentication. Our empirical experiments using the real-world dataset demonstrate the practicality of VFSA. Qiuyun Tong, Yinbin Miao, Jian Weng 0001, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2023 | Privacy-Preserving Ranked Spatial Keyword Query in Mobile Cloud-Assisted Fog ComputingabstractWith the increasing popularity of GPS-equipped mobile devices in cloud-assisted fog computing scenarios, massive spatio-textual data is generated and outsourced to cloud servers for storage and analysis. Existing privacy-preserving range query or ranked keyword search schemes does not support a unified index, and are just applicable for the symmetric environment where all users sharing the same secret key. To solve this issue, we propose aPrivacy-preservingRankedSpatial keywordQuery in mobile cloud-assistedFog computing (PRSQ-F). Specifically, we design a novel comparable product encoding strategy that combines both spatial and textual conditions tightly to retrieve the objects in query range and with the highest textual similarity. Then, we use a new conversion protocol and attribute-based encryption to support privacy-preserving retrieval and malicious user traceability in the asymmetric environment where different query users have different keys. Furthermore, we construct an R-tree-based index to achieve faster-than-linear retrieval. Our formal security analysis shows that data security can be guaranteed. Our empirical experiments using a real-world dataset demonstrate the efficiency and feasibility of PRSQ-F. Qiuyun Tong, Yinbin Miao, Hongwei Li 0001, Ximeng Liu, Robert H. Deng |
IEEE Trans. Mob. Comput. | 1 |
| 2023 | Owner-free Distributed Symmetric Searchable Encryption Supporting Conjunctive QueriesabstractSymmetric Searchable Encryption (SSE), as an ideal primitive, can ensure data privacy while supporting retrieval over encrypted data. However, existing multi-user SSE schemes require the data owner to share the secret key with all query users or always be online to generate search tokens. While there are some solutions to this problem, they have at least one weakness, such as non-supporting conjunctive query, result decryption assistance of the data owner, and unauthorized access. To solve the above issues, we propose an O wner-free Di stributed S ymmetric searchable encryption supporting C onjunctive query (ODiSC). Specifically, we first evaluate the Learning-Parity-with-Noise weak Pseudorandom Function (LPN-wPRF) in dual-cloud architecture to generate search tokens with the data owner free from sharing key and being online. Then, we provide fine-grained conjunctive query in the distributed architecture using additive secret sharing and symmetric-key hidden vector encryption. Finally, formal security analysis and empirical performance evaluation demonstrate that ODiSC is adaptively simulation-secure and efficient. Qiuyun Tong, Xinghua Li 0001, Yinbin Miao, Yunwei Wang, Ximeng Liu, Robert H. Deng |
ACM Trans. Storage | 1 |
| 2023 | VRFMS: Verifiable Ranked Fuzzy Multi-Keyword Search Over Encrypted DataabstractSearchable encryption(SE) allows users to efficiently retrieve data over encrypted cloud data, but most existing SE schemes only support exact keyword search, resulting in false results due to minor typos or format inconsistencies of queried keywords. The fuzzy keyword search can avoid this limitation, but still incurs low search accuracy and efficiency. Besides, most of fuzzy keyword search schemes do not consider malicious cloud servers which may execute a fraction of search operations or forge some results due to various interest incentives such as saving computation or storage resources. To solve these problems, we propose an efficient and Verifiable Ranked Fuzzy Multi-keyword Search scheme, called VRFMS. VRFMS uses locality-sensitive hashing and bloom filter to implement fuzzy keyword search, and employs Term Frequency-Inverse Document Frequency(TF-IDF) to sort the relevant results. Aiming to further improve the search accuracy, we design an improved bi-gram keyword transformation method. Furthermore, the homomorphic MAC technique and a random challenge technique are utilized to verify the correctness and completeness of returned results, respectively. Formal security analysis and empirical experiments demonstrate that VRFMS is secure and efficient in practical applications, respectively. Xinghua Li 0001, Qiuyun Tong, Jinwei Zhao, Yinbin Miao, Siqi Ma 0001, Jian Weng 0001, Jianfeng Ma 0001, Kim-Kwang Raymond Choo |
IEEE Trans. Serv. Comput. | 2 |
| 2023 | Privacy-Preserving and Verifiable Outsourcing Linear Inference Computing FrameworkabstractIn machine learning (ML), the massive data processing and dense computations based on matrices make outsourced inference computation a growing trend. The unreliability of cloud platforms makes privacy protection and inference correctness increasingly important in outsourced computations. Unfortunately, current works cannot provide an effective verification mechanism and privacy protection for outsourcing linear computing simultaneously. To address the issue, in the service architectures with malicious behaviors (such as curiosity, dishonesty, and collusion), we propose privacy-preserving and verifiable outsourcing inference computing (PPVLC) for the most fundamental linear computations in ML. PPVLC uses secret sharing and blinding techniques to protect privacy and achieve secure computation of matrix linear computation. Meanwhile, bilinear mapping based on matrix digest is utilized to verify computation correctness, ensuring the trustworthiness of the service. Security analysis and experiments demonstrate the reliability of our scheme and service efficiency. Jiao Liu 0002, Xinghua Li 0001, Ximeng Liu, Yunwei Wang, Qiuyun Tong, Jianfeng Ma 0001 |
IEEE Trans. Serv. Comput. | 6 |
| 2022 | Verifiable Searchable Encryption Framework Against Insider Keyword-Guessing Attack in Cloud StorageabstractSearchable encryption (SE) allows cloud tenants to retrieve encrypted data while preserving data confidentiality securely. Many SE solutions have been designed to improve efficiency and security, but most of them are still susceptible to insider Keyword-Guessing Attacks (KGA), which implies that the internal attackers can guess the candidate keywords successfully in an off-line manner. Also in existing SE solutions, a semi-honest-but-curious cloud server may deliver incorrect search results by performing only a fraction of retrieval operations honestly (e.g., to save storage space). To address these two challenging issues, we first construct the basic Verifiable SE Framework (VSEF), which can withstand the inside KGA and achieve verifiable searchability. Based on the basic VSEF, we then present the enhanced VSEF to support multi-keyword search, multi-key encryption and dynamic updates (e.g., data modification, data insertion, and data deletion) at the same time, which highlights the importance of practicability and scalability of SE in real-world application scenarios. We conduct extensive experiments using the Enron email dataset to demonstrate that the enhanced VSEF achieves high efficiency while resisting to the inside KGA and supporting the verifiability of search results. Yinbin Miao, Qiuyun Tong, Robert H. Deng, Kim-Kwang Raymond Choo, Ximeng Liu, Hongwei Li 0001 |
IEEE Trans. Cloud Comput. | 2 |
| 2022 | VPSL: Verifiable Privacy-Preserving Data Search for Cloud-Assisted Internet of ThingsabstractCloud-assisted Internet of Things (IoT) is increasingly prevalent used in various fields, such as the healthcare system. While in such a scenario, sensitive data (e.g., personal electronic medical records) can be easily revealed, which incurs potential security challenges. Thus, Symmetric Searchable Encryption (SSE) has been extensively studied due to its capability of supporting efficient search on encrypted data. However, most SSE schemes require the data owner to share the complete key with query users and take malicious cloud servers out of consideration. Seeking to address these limitations, in this article we propose a Verifiable Privacy-preserving data Search scheme with Limited key-disclosure (VPSL) for cloud-assisted Internet of Things. VPSL first designs a trapdoor generation protocol for obtaining a trapdoor with disclosing limited key information and without revealing plaintext query points to others. Then, VPSL provides an efficient result verification and search processing by employing the Merkle hash tree structure and k-means clustering technique, respectively. VPSL is secure against the level-2 attack. Finally, an enhanced VPSL (called VPSL+) resisting the level-3 attack is constructed by introducing the random splitting technique. Empirical experiments demonstrate the accuracy and efficiency of VPSL or VPSL+ using real-world datasets. Qiuyun Tong, Yinbin Miao, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng, Hongwei Li 0001 |
IEEE Trans. Cloud Comput. | 1 |
| 2022 | VFIRM: Verifiable Fine-Grained Encrypted Image Retrieval in Multi-Owner Multi-User SettingsabstractTo ensure the security of images outsourced to the malicious cloud without affecting searchability on such outsourced (typically encrypted) images, one could use privacy-preserving Content-Based Image Retrieval (CBIR) primitive. However, conventional privacy-preserving CBIR schemes based on Searchable Symmetric Encryption (SSE) are not capable of supporting efficient fine-grained access control and result verification simultaneously. Therefore, in this article, we propose aVerifiableFine-grained encryptedImageRetrieval scheme in theMulti-owner multi-user settings (VFIRM). VFIRM first utilizes a novel polynomial-based access strategy to provide efficient fine-grained access control. Then, it employs the dual secure$k$-nearest neighbor technique to distribute distinct keys to different data owners and data users, and finally implements an adapted homomorphic MAC technique to check the correctness of search results. Our formal security analysis shows that VFIRM is non-adaptive semantic secure if the client's search key is generated randomly and keeps in secret. Our empirical experiments using two real-world datasets (i.e., Caltech101 and Corel5k) demonstrate the practicality of VFIRM. Qiuyun Tong, Yinbin Miao, Lei Chen 0029, Jian Weng 0001, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Serv. Comput. | 1 |
| 2019 | Secure Online/Offline Data Sharing Framework for Cloud-Assisted Industrial Internet of ThingsabstractCiphertext-policy attribute-based keyword search (CP-ABKS) schemes facilitate the fine-grained keyword search over encrypted data, such as those sensed/collected from Industrial Internet of Things (IIoT) devices and stored in the cloud. However, existing CP-ABKS schemes generally have significant computation and storage requirements, which are beyond those of resource-constrained IIoT devices. Therefore, in this paper, we design a secure online/offline data sharing framework (DSF), which supports online/offline encryption and outsourced decryption. Using the healthcare setting as a case study, we demonstrate how DSF can be deployed in the cloud-assisted Healthcare IIoT (HealthIIoT) system. We not only prove that the DSF is selectively secure in the chosen access structure security model but also demonstrate its efficiency and feasibility in practical scenarios using experiments. Yinbin Miao, Qiuyun Tong, Kim-Kwang Raymond Choo, Ximeng Liu, Robert H. Deng, Hongwei Li 0001 |
IEEE Internet Things J. | 2 |