EDBT 2026 Demo / reviewers in the wild / expert
Jincheng An
dblp:385/2238
· DBLP profile ↗
6ranked-venue papers
0as first author
6since 2021 · last 2026
0009-0004-6607-5993ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Combating Knowledge Corruption in Agent Systems: A Byzantine-Tolerant Secure Collaborative RAG FrameworkabstractWhile retrieval-augmented generation systems partially address the hallucination issues in large language models, it also introduces new vulnerabilities to knowledge corruption attacks. Adversaries exploit these vulnerabilities by poisoning documents provided by RAG system to manipulate LLM outputs. To counter this threat, we propose SecureCollaRAG, a Byzantine-tolerant collaborative RAG framework leveraging Multi-source Knowledge Validation Mechanism. Our approach enables agent system to securely verify document provenance through dynamic GNN-based credibility scoring, effectively preventing stealthy knowledge corruption attacks while preserving essential domain knowledge integrity. Through extensive evaluations and formal analysis, we demonstrate that SecureCollaRAG maintains robustness against attackers under non-IID data distributions. Daqing He, Zijian Zhang 0001, Ye Liu 0012, Jiamou Liu, Zhirui Zeng, Zhan Qin, Xin Li 0033, Hongwei Yao, Jincheng An, Yi Li 0008, Xiulei Liu, Liehuang Zhu |
WWW | 11 |
| 2026 | Hydra: Support Dynamic BFT With Weaker Assumptions and Explicit Request HandlingabstractThis paper presents Hydra, a dynamic BFT protocol that allows replicas to join and leave the system dynamically. It addresses the limitations of traditional static BFTs in managing membership changes and can be used to simplify the implementation of many features in modern blockchain applications. Hydra relies on weaker assumptions to achieve standard properties compared to the existing solution Dyno and introduces a configuration auto-transition protocol to ensure liveness. Through temporary configurations and explicitly defined replica responsibilities for request handling, Hydra pipelines membership requests alongside regular requests and realizes clarity, achieving a more efficient and smoother configuration transitions. It also employs a non-blocking configuration discovery mechanism, enabling new replicas to participate in consensus quickly. We formally prove Hydra's correctness under the dynamic BFT model. Experimental results demonstrate Hydra's ability to maintain throughput fluctuations within 5% during various replica join and leave scenarios, outperforming Dyno and existing BFT system supporting reconfiguration in both stability and efficiency. Hydra effectively manages scenarios that Dyno circumvents with stronger assumptions and quickly restores throughput to normal levels. Zijian Zhang 0001, Haibo Sun, Meng Li 0006, Jing Sun 0002, Jiamou Liu, Lei Xu 0016, Jincheng An, Mauro Conti, Liehuang Zhu |
IEEE Trans. Dependable Secur. Comput. | 10 |
| 2026 | Unveiling Ethereum Mixing Services Using Enhanced Graph Structure LearningabstractAs cryptocurrency prices continue to recover, crypto crimes such as money laundering are becoming increasingly rampant. Mixing services such as Tornado Cash have become the primary tools for obfuscating illegal financial transactions due to their inherent anonymity mechanisms. Tornado Cash is a non-custodial, smart contract-based mixing service (SC-CMS) that breaks the direct mapping between deposit and withdrawal accounts, hindering regulators from tracking illicit fund flows. Existing deanonymization methods for Tornado Cash suffer from several challenges, including vague theoretical concepts, evolving mixing mechanisms, and insufficient labeled samples. To address these concerns, this paper proposes the first formal concept of SC-CMS to facilitate and evaluate the deanonymization efforts systematically. We design a novel linkability attack, LASC, based on enhanced graph structure learning, to associate mixing accounts on Tornado Cash and mathematically prove its feasibility. Comprehensive experiments on real Ethereum transactions demonstrate that LASC outperforms state-of-the-art works in both performance and efficiency. Yan Wu 0014, Cong Wu 0003, Yebo Feng, Jiahang Sun, Zijian Zhang 0001, Jincheng An, Zhitao Guan, Liehuang Zhu |
IEEE Trans. Dependable Secur. Comput. | 9 |
| 2025 | Resisting Poisoning Attacks in Federated Learning via Dual-Domain Distance and Trust AssessmentabstractSubsequently, by executing various attacks on benchmark datasets such as MNIST, we construct Federated Learning Malicious Parameter Identification (FLMPID) dataset to enable malicious client detection. Building on this dataset, we propose FORTRESS (Federated POisoning-Resistance Defense via Dual-Domain Distance and TRust AssESSment), a framework designed to detect and mitigate malicious updates from clients. FORTRESS employs a unique encoder-decoder architecture. The encoder utilizes dual-domain distance metrics on weights and gradients to extract hidden representations, while the decoder leverages Actor-Critic (AC) reinforcement learning for trust assessment. We evaluated FORTRESS under multiple attack scenarios and demonstrated its defense effectiveness, making it a promising solution for enhancing the security of FL systems. Zijian Zhang 0001, Yan Wu 0014, Ye Liu 0012, Meng Li 0006, Xin Li 0033, Jincheng An, Wei Liang 0005, Liehuang Zhu |
IEEE Trans. Inf. Forensics Secur. | 9 |
| 2025 | Web-FTP: A Feature Transferring-Based Pre-Trained Model for Web Attack DetectionabstractWeb attack is a major threat to cyberspace security, so web attack detection models have become a critical task. Traditional supervised learning methods learn features of web attacks with large amounts of high-confidence labeled data, which are extremely expensive in the real world. Pre-trained models offer a novel solution with their ability to learn generic features on large unlabeled datasets. However, designing and deploying a pre-trained model for real-world web attack detection remains challenges. In this paper, we present a pre-trained model for web attack detection, including a pre-processing module, a pre-training module, and a deployment scheme. Our model significantly improves classification performance on several web attack detection datasets. Moreover, we deploy the model in real-world systems and show its potential for industrial applications. Qinghua Shang, Xin Li 0033, Chengyi Li, Zijian Zhang 0001, Jincheng An, Chuanming Huang, Yang Chen 0028, Yuguang Cai |
IEEE Trans. Knowl. Data Eng. | 8 |
| 2024 | A Blockchain-Based Privacy-Preserving Scheme for Sealed-Bid AuctionabstractThe sealed-bid auction enables bidders to secretly send their bids to the auctioneer, which compares all bids and publishes the winning one on the bid-opening day. This type of auction is friendly for protecting the bid privacy, and sufficiently fair for all bidders if the auctioneer acts faithfully. Unfortunately, the auctioneer may not always be trustworthy. The auctioneer has the ability to deliberately leak any bid information to a part of bidders for raising the final winning price based on the investigation. Meanwhile, the auctioneer can appoint any bidder as the winner, as long as the bidder accepts a higher winning price than the current highest bid. Since bidders cannot obtain any bid information from others, to the best of our knowledge, it is difficult to prevent bid leakage from the auctioneer, and support bidders to verify the bid comparison results without disclosing the winning bid, simultaneously. To alleviate these problems, we first construct a homomorphic encryption(HE)-based bid comparison circuit. All bidders can directly compute a cipher of the winning bid by using this circuit; hence, the winning bid does not need to be exposed to all bidders. Then, we propose a blockchain-based sealed-bid scheme (BSS) by integrating the circuit with commitment and zero-knowledge proof. The auctioneer only obtains the commitments of bids before the bid-opening day, and he has to prove that the winner's bid is the same as the plaintext of the bidders' computed cipher. Thus, the auctioneer can neither leak the bid information nor publish a higher winning price during in the auction. Detailed performance analysis shows that the computational complexity of BSS is linear with the binary length of bids. Zijian Zhang 0001, Meng Li 0006, Jincheng An, Yang Yu 0001, Liehuang Zhu, Jiamou Liu, Bakhadyr Khoussainov |
IEEE Trans. Dependable Secur. Comput. | 4 |