EDBT 2026 Demo / reviewers in the wild / expert
Wenting Li 0002
dblp:29/4801-2
· DBLP profile ↗
18ranked-venue papers
7as first author
11since 2021 · last 2025
0000-0002-2613-8257ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 4 first-author · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 1 first-author · 4 since 2021Systems, architecture and hardware · 1 · 1 first-authorComputer networks · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | GET-AID: Graph-Enhanced Transformer for Provenance-Based Advanced Persistent Threats Investigation and Detection
Fengyuan Xu, Jiahong Yang 0003, Wenting Li 0002, Zonghua Zhang, Chenbin Zhang, Meng Ma 0001, Ping Wang 0003 |
ESORICS (4) | 4 |
| 2025 | Personalized Password Guessing via Modeling Multiple Leaked Credentials of the Same User
Fugeng Huang, Jiahong Yang 0003, Haibo Cheng 0001, Wenting Li 0002, Ping Wang 0003 |
ESORICS (3) | 4 |
| 2025 | Username-Password Models Beyond Traditional Password Guessability AssessmentabstractPasswords are widely used for website authentication, but they are vulnerable to guessing attacks. To measure password guessability, the commonly used approach involves modeling the distribution of passwords with a password probability model and then estimating the guessability using Monte Carlo methods based on the model. We found that users’ passwords are closely linked to their usernames. However, few password models proposed by previous research consider this connection, which significantly overestimates the security of passwords and can result in inadequate security measures, potentially leading to data breaches and financial losses. In this paper, we propose a new category of password model called username-password model, which models the conditional probability of passwords given usernames. We also provide an instance of the username-password model using Transformer (TUPM). The experimental results of guessing attacks show that TUPM outperforms other password models in terms of crack rate across any number of guesses (up to 1020). Notably, TUPM cracks 100%–175% more passwords compared to the state-of-the-art models, within the first 1,000 guesses. This indicates that TUPM can provide a more accurate estimation of password guessability. Jiahong Yang 0003, Wenting Li 0002, Haibo Cheng 0001, Ping Wang 0003 |
ICASSP | 2 |
| 2025 | Targeted Password Guessing Using Neural Language ModelsabstractWith the increasing prevalence of personal information breaches, targeted password guessing based on user-specific data has emerged as a serious security threat. Existing targeted password guessing attacks primarily rely on traditional statistical language models, which have limited capability in addressing the complexities of password structures and user behavior. Recent advancements in neural language models, particularly Transformer-based architectures, have achieved significant success in natural language processing tasks by capturing complex patterns and dependencies. However, their potential for improving targeted password guessing remains largely unexplored.To address this gap, we conduct a systematic evaluation of several widely used neural language models from NLP and assess their effectiveness in targeted password guessing. Experimental results on multiple real-world password datasets show that neural language models outperform existing approaches. Our proposed models achieve an improvement of 1.4%–4.6% compared to RFGuess-PII model, and 18%–40% compared to TarPCFG model. This work provides new insights into the potential of neural language models to enhance the effectiveness of targeted password guessing attacks. Jiahong Yang 0003, Wenting Li 0002, Haibo Cheng 0001, Ping Wang 0003 |
ICASSP | 2 |
| 2025 | Practically Secure Honey Password Vaults: New Design and New Evaluation against Online Guessing
Haibo Cheng 0001, Fugeng Huang, Jiahong Yang 0003, Wenting Li 0002, Ping Wang 0003 |
USENIX Security Symposium | 4 |
| 2025 | User-Autonomous Multi-Factor Authentication Supporting Arbitrary Factor Configurations
Wenting Li 0002, Haibo Cheng 0001, Kaitai Liang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Improved Wordpcfg for Passwords with Maximum Probability SegmentationabstractModeling password distributions is a fundamental problem in password security, benefiting the research and applications on password guessing, password strength meters, honey password vaults, etc. As one of the best segment-based password models, WordPCFG has been proposed to capture individual semantic segments (called words) in passwords. However, we find WordPCFG does not address well the ambiguity of password segmentation by maximum matching, leading to the unreasonable segmentation of many password and further the inaccuracy of modeling password distributions. To address the ambiguity, we improve WordPCFG by maximum probability segmentation with A*-like pruning algorithm. The experimental results show that the improved WordPCFG cracks 99.26%–99.95% passwords, with nearly 5.67%–18.01% improvement. Wenting Li 0002, Jiahong Yang 0003, Haibo Cheng 0001, Ping Wang 0003, Kaitai Liang |
ICASSP | 1 |
| 2023 | HPAKE: Honey Password-Authenticated Key Exchange for Fast and Safer Online AuthenticationabstractPassword-only authentication is one of the most popular secure mechanisms for real-world online applications. But it easily suffers from a practical threat - password leakage, incurred by external and internal attackers. The external attacker may compromise the password file stored on the authentication server, and the insider may deliberately steal the passwords or inadvertently leak the passwords. So far, there are two main techniques to address the leakage: Augmented password-authentication key exchange (aPAKE) against insiders and honeyword technique for external attackers. But none of them can resist both attacks. To fill the gap, we propose the notion of honey PAKE (HPAKE) that allows the authentication server to detect the password leakage and achieve the security beyond the traditional bound of aPAKE. Further, we build an HPAKE construction on the top of the honeyword mechanism, honey encryption, and OPAQUE which is a standardized aPAKE. We formally analyze the security of our design, achieving the insider resistance and the password breach detection. We implement our design and deploy it in the real environment. The experimental results show that our protocol only costs 71.27 ms for one complete run, within 20.67 ms on computation and 50.6 ms on communication. This means our design is secure and practical for real-world applications. Wenting Li 0002, Ping Wang 0003, Kaitai Liang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2021 | Improved Probabilistic Context-Free Grammars for Passwords Using Word ExtractionabstractProbabilistic context-free grammars (PCFGs) have been pro-posed to capture password distributions, and further been used in password guessing attacks and password strength meters. However, current PCFGs suffer from the limitation of inaccurate segmentation of password, which leads to misestimation of password probability and thus seriously affects their performance. In this paper, we propose a word extraction approach for passwords, and further present an improved PCFG model, called WordPCFG. The WordPCFG using word extraction method can precisely extract semantic segments (called word) from passwords based on cohesion and freedom of words. We evaluate our WordPCFG on six large-scale datasets, showing that WordPCFG cracks 83.04%–95.47% passwords and obtains 12.96%–71.84% improvement over the state-of-the-art PCFGs. Haibo Cheng 0001, Wenting Li 0002, Ping Wang 0003, Kaitai Liang |
ICASSP | 2 |
| 2021 | Incrementally Updateable Honey Password Vaults
Haibo Cheng 0001, Wenting Li 0002, Ping Wang 0003, Chao-Hsien Chu, Kaitai Liang |
USENIX Security Symposium | 2 |
| 2021 | Practical Threshold Multi-Factor AuthenticationabstractMulti-factor authentication (MFA) has been widely used to safeguard high-value assets. Unlike single-factor authentication (e.g., password-only login), t-factor authentication ( tFA) requires a user always to carry and present t specified factors so as to strengthen the security of login. Nevertheless, this may restrict user experience in limiting the flexibility of factor usage, e.g., the user may prefer to choose any factors at hand for login authentication. To bring back usability and flexibility without loss of security, we introduce a new notion of authentication, called (t,n) threshold MFA, that allows a user to actively choose t factors out of n based on preference. We further define the “most-rigorous” multi-factor security model for the new notion, allowing attackers to control public channels, launch active/passive attacks, and compromise/corrupt any subset of parties as well as factors. We state that the model can capture the most practical security needs in the literature. We design a threshold MFA key exchange (T-MFAKE) protocol built on the top of a threshold oblivious pseudorandom function and an authenticated key exchange protocol. Our protocol achieves the “highest-attainable” security against all attacking attempts in the context of parties/factors being compromised/corrupted. As for efficiency, our design only requires 4+t exponentiations, 2 multi-exponentiations and2communication rounds. Compared with existing tFA schemes, even the degenerated (t,t) version of our protocol achieves the strongest security (stronger than most schemes) and higher efficiency on computational and communication. We instantiate our design on real-world platform to highlight its practicability and efficiency. Wenting Li 0002, Haibo Cheng 0001, Ping Wang 0003, Kaitai Liang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | Probability Model Transforming Encoders Against Encoding Attacks
Haibo Cheng 0001, Zhixiong Zheng, Wenting Li 0002, Ping Wang 0003, Chao-Hsien Chu |
USENIX Security Symposium | 3 |
| 2019 | Two-factor authentication in industrial Internet-of-Things: Attacks, evaluation and new construction
Wenting Li 0002, Ping Wang 0003 |
Future Gener. Comput. Syst. | 1 |
| 2018 | A Secure and Anonymous Two-Factor Authentication Protocol in Multiserver EnvironmentabstractWith the great development of network technology, the multiserver system gets widely used in providing various of services. And the two-factor authentication protocols in multiserver system attract more and more attention. Recently, there are two new schemes for multiserver environment which claimed to be secure against the known attacks. However, after a scrutinization of these two schemes, we found that (1) their description of the adversary’s abilities is inaccurate; (2) their schemes suffer from many attacks. Thus, firstly, we corrected their description on the adversary capacities to introduce a widely accepted adversary model and then summarized fourteen security requirements of multiserver based on the works of pioneer contributors. Secondly, we revealed that one of the two schemes fails to preserve forward secrecy and user anonymity and cannot resist stolen-verifier attack and off-line dictionary attack and so forth and also demonstrated that another scheme fails to preserve forward secrecy and user anonymity and is not secure to insider attack and off-line dictionary attack, and so forth. Finally, we designed an enhanced scheme to overcome these identified weaknesses, proved its security via BAN logic and heuristic analysis, and then compared it with other relevant schemes. The comparison results showed the superiority of our scheme. Chenyu Wang 0002, Guoai Xu, Wenting Li 0002 |
Secur. Commun. Networks | 3 |
| 2018 | Measuring Two-Factor Authentication Schemes for Real-Time Data Access in Industrial Wireless Sensor NetworksabstractDozens of two-factor authentication schemes have been proposed to secure real-time data access in industrial wireless sensor networks (WSNs). However, more often than not, the protocol designers advocate the merits of their scheme, but do not reveal (or unconsciously ignoring) the facets on which their scheme performs poorly. Such lack of an objective, comprehensive measurement leads to the unsatisfactory “break-fix-break-fix” cycle in this research area. In this paper, we make an attempt toward breaking this undesirable cycle by proposing a systematical evaluation framework for schemes to be assessed objectively, revisiting two foremost schemes proposed by Wu et al. (2017) and Srinivas et al. (2017) to reveal the challenges and difficulties in designing a sound scheme, and conducting a measurement of 44 representative schemes under our evaluation framework, thereby providing the missing evaluation for two-factor schemes in industrial WSNs. This work would help increase awareness of current measurement issues and improve the scientific process in our field. Ding Wang 0002, Wenting Li 0002, Ping Wang 0003 |
IEEE Trans. Ind. Informatics | 2 |
| 2018 | Cryptanalysis and Security Enhancement of Three Authentication Schemes in Wireless Sensor NetworksabstractNowadays wireless sensor networks (WSNs) have drawn great attention from both industrial world and academic community. To facilitate real‐time data access for external users from the sensor nodes directly, password‐based authentication has become the prevalent authentication mechanism in the past decades. In this work, we investigate three foremost protocols in the area of password‐based user authentication scheme for WSNs. Firstly, we analyze an efficient and anonymous protocol and demonstrate that though this protocol is equipped with a formal proof, it actually has several security loopholes been overlooked, such that it cannot resist against smart card loss attack and violate forward secrecy. Secondly, we scrutinize a lightweight protocol and point out that it cannot achieve the claimed security goal of forward secrecy, as well as suffering from user anonymity violation attack and offline password guessing attack. Thirdly, we find that an anonymous scheme fails to preserve two critical properties of forward secrecy and user friendliness. In addition, by adopting the “perfect forward secrecy (PFS)” principle, we provide several effective countermeasures to remedy the identified weaknesses. To test the necessity and effectiveness of our suggestions, we conduct a comparison of 10 representative schemes in terms of the underlying cryptographic primitives used for realizing forward secrecy. Wenting Li 0002, Ping Wang 0003, Fushan Wei |
Wirel. Commun. Mob. Comput. | 1 |
| 2016 | DDHCS: Distributed Denial-of-service Threat to YARN Clusters based on Health Check Service
Wenting Li 0002, Qingni Shen, Chuntao Dong, Yahui Yang, Zhonghai Wu |
ICISSP | 1 |
| 2015 | Eavesdropper: A Framework for Detecting the Location of the Processed Result in Hadoop
Chuntao Dong, Qingni Shen, Wenting Li 0002, Yahui Yang, Zhonghai Wu |
ICICS | 3 |