EDBT 2026 Demo / reviewers in the wild / expert
Mingrui Ai
dblp:332/3042
· DBLP profile ↗
6ranked-venue papers
1as first author
6since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 5 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | BLAS: A Blockchain-Enabled Efficient and Verifiable Log Audit System With Hybrid StorageabstractA reliable log audit system is a fundamental tool for efficient security management and attack detection. Blockchain has emerged as a prominent technology for building log audit systems, thanks to its non-repudiation and immutability properties. However, current blockchain-based solutions are computationally intensive and typically rely on coarse-grained queries, making them impractical for real-world systems. Therefore, we propose a blockchain-based verifiable log audit system, BLAS, which adopts three novel techniques. Firstly, we propose a novel data structure called the Index-Object Merkle Forest (IOMF), which combines modified Merkle Tree data structures and keyword-range bitmap indexes to support efficient log auditing. Secondly, we propose a hierarchical extension of IOMF to create an Authenticated Layered Index Structure (ALIS). ALIS enables fine-grained auditing at the entry level. Finally, we propose two optimization techniques in ALIS to reduce computational and communication costs. The performance evaluation confirms that BLAS is consistently faster than the baseline solutions with similar settings in various experiments, achieving speedups of hundreds to over ten thousand times for the most challenging workloads. Xuanbo Huang, Mingrui Ai, Kaiping Xue, Yingjie Xue, Hyundong Shin |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | PUF-Based Lightweight Decentralized Authentication for UAV NetworksabstractAuthentication and Key Agreement (AKA) are essential for UAV networks operating in open and hostile environments, as they assist in preventing common threats such as impersonation and replay attacks. However, traditional protocols often rely on a centralized server for key and identity management, creating risks of key leakage and a single point of failure. To address these issues, we propose a blockchain-based decentralized authentication mechanism that remains effective even under partial node compromise. Our design adopts Physical Unclonable Functions (PUFs) in place of key-based authentication to mitigate key leakage risk. To mitigate machine learning (ML) attacks inherent in existing PUF-based protocols, we design a lightweight Encrypted Randomized Challenge-Response Pair (ERCRP) structure, which incorporates external randomness to obfuscate underlying PUF mapping. Meanwhile, to address CRP leakage in prior centralized schemes, we combine Shamir's Secret Sharing and blockchain for secure CRP management. Specially, we introduce a decoupled design that separates interaction-intensive secret reconstruction process from blockchain consensus to ensure high efficiency. Finally, we develop a lightweight commitment-based management mechanism to prevent unauthorized CRP consumption and reuse from malicious authentication attempts. Additionally, the protocol provides UAV identity untraceability via dynamic identity updates. Comprehensive formal and informal security analyses, together with comparative performance evaluations, demonstrate the protocol's strong security guarantees and practical efficiency. Kaiping Xue, Mingrui Ai, Yingjie Xue, Lutong Chen, Jian Li 0031, David S. L. Wei |
IEEE Trans. Mob. Comput. | 3 |
| 2025 | EtherCloak: Enabling Multi-Level and Customized Privacy on Account-Model BlockchainsabstractThe lack of privacy-preserving capabilities hinders the further development of blockchains and smart contracts. While numerous privacy solutions have been proposed, limitations persist. First, most existing solutions focus on specific privacy protections such as anonymous payments, private data, or multi-party computation tasks. However, these solutions lack a general privacy ability, allowing users to deploy applications with diverse privacy requirements. Second, existing solutions have limited customizability, which means users cannot easily customize and adapt the privacy policies according to their specific demands or preferences. In this article, we present EtherCloak, which adopts trusted execution environments (TEEs) to achieve a general and customizable privacy policy on account model blockchains, enabling users to conceal any on-chain information. To address the security issues caused by the unreliability of the host the TEE runs on, we design the enclave state check and crash recovery mechanisms and employ them in the block generation process. In addition, we propose an access control mechanism for privacy policy management and data query. We prove that EtherCloak offers general and customizable privacy protection with a minimal increase in transaction size (less than triple) and communication overhead (approximately 10%) compared to Ethereum. Kaiping Xue, Mingrui Ai, Jianan Hong, Xianchao Zhang 0002, Qibin Sun, Jun Lu 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | You Can Obfuscate, but You Cannot Hide: CrossPoint Attacks against Network Topology Obfuscation
Xuanbo Huang, Kaiping Xue, Lutong Chen, Mingrui Ai, Huancheng Zhou, Bo Luo, Guofei Gu, Qibin Sun |
USENIX Security Symposium | 4 |
| 2024 | FakeBehalf: Imperceptible Email Spoofing Attacks against the Delegation Mechanism in Email Systems
Jinrui Ma, Lutong Chen, Kaiping Xue, Bo Luo, Xuanbo Huang, Mingrui Ai, Huanjie Zhang, David S. L. Wei |
USENIX Security Symposium | 6 |
| 2022 | Blacktooth: Breaking through the Defense of Bluetooth in SilenceabstractBluetooth is a short-range wireless communication technology widely used by billions of personal computing, IoT, peripheral, and wearable devices. Bluetooth devices exchange commands and data, such as keyboard/mouse inputs, audio, and files, through a secure communication channel that is established through a pairing process. Due to the sensitivity of those commands and data, security mechanisms, such as encryption, authentication, and authorization, have been developed and adopted in the standards. Nevertheless, vulnerabilities continue to be discovered. Mingrui Ai, Kaiping Xue, Bo Luo, Lutong Chen, Nenghai Yu, Qibin Sun, Feng Wu 0001 |
CCS | 1 |