EDBT 2026 Demo / reviewers in the wild / expert
Minghong Sun
dblp:403/3722
· DBLP profile ↗
5ranked-venue papers
1as first author
5since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | User-Side Pairing-Free Lightweight Distributed Anonymous Counting TokensabstractCentralized issuer in Anonymous Counting Tokens (ACT) is prone to single-point failure and imposes prohibitive computational overhead on resource-constrained IoT devices, hindering practical deployment. To overcome these limitations, we propose a user-side pairing-free lightweight distributed anonymous counting tokens protocol called LDACT. LDACT enables efficient issuance within a distributed environment and ensures that each client receives at most one valid token per message without disclosing their identity. LDACT eliminates pairing operations for user-side, enhancing scalability for source-constrained scenarios. Additionally, the tokens are publicly verifiable, allowing any party to verify their validity without compromising user anonymity. We conduct security analysis that LDACT satisfies unforgeability and unlinkability. We evaluate the computational overhead of LDACT on both Ubuntu and Raspberry Pi system, and compare it with other schemes. The result of the experiment demonstrates that LDACT achieves computational overhead in milliseconds for source-constrained IoT devices. Yanqi Zhao, Minghong Sun, Xiaoyi Yang 0001, Yong Yu 0002 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | GhostCache: Timer- and Counter-Free Cache Attacks Exploiting Weak Coherence on RISC-V and ARM ChipsabstractMicroarchitectural side-channel attacks, which have become increasingly prevalent, often rely on high-resolution timers. Emerging processor architectures have sought to mitigate these vulnerabilities by restricting access to fine-grained timers. In this work, we verify the widespread existence of weak coherence in L1 cache on multiple RISC chips, exploit it to bypass this type of mitigation and propose GhostCache, which constructs timer-free and counter-free instruction cache attacks. It introduces two novel and widely applied attack primitives, Modify+Recall and Call+ModifyCall, which are applicable to both RISC-V and ARM architectures and affect 6 commercial and 3 open-source large RISC processors. To the best of our knowledge, we present the first demonstration of timer-free and counter-free cache attacks on RISC-V processors. We also identify undisclosed features, such as the next-three-line prefetching mechanism and direct forwarding of evicted instructions from data cache to instruction cache. Furthermore, we develop four types of covert channels, achieving up to 1.68 MB/s with a 0.01% error rate. For side-channel attacks, GhostCache enables three types of timer-free real-world attacks. The first is an end-to-end website fingerprinting attack, achieving 92.02% accuracy across 100 website classes. The second is a set of kernel leakage attacks, including the discovery of a new Spectre disclosure gadget via a function pointer to leak arbitrary kernel data at 92.91% accuracy. We also launched an attack to reconstruct cryptographic keys. Lastly, we propose potential countermeasures to address these vulnerabilities in both RISC-V and ARM architectures. Yu Jin 0010, Minghong Sun, Dongsheng Wang 0002, Pengfei Qiu, Yinqian Zhang, Shuwen Deng |
CCS | 2 |
| 2025 | Threshold Anonymous Counting Tokens with Batch Proofs for Online PaywallsabstractAs online application services evolve, an increasing number of users are opting for subscription-based or paywall models to access high-quality content. Anonymous counting tokens (ACTs), which regulate user access while protecting user privacy, are widely adopted in the online paywall model. However, the centralized server of ACT may lead to a single point of failure, thereby exposing users’ privacy. To address this challenge, in this paper, we propose threshold anonymous counting tokens with batch proofs (ThrACT) that balance privacy preservation and access count limitation for online paywalls. We define the system model for ThrACT and provide its concrete construction. We utilize the threshold Boneh-Boyen signature to facilitate distributed issuance of anonymous tokens and enable batch issuance. In addition, our ThrACT employs non-interactive zero-knowledge proofs to verify the label and token requests while allowing the correctness of multiple blind token shares to be validated simultaneously. We also prove that ThrACT satisfies unforgeable and unlinkable security properties. Finally, we evaluate the computational cost of our ThrACT and compare it with other schemes. The experiment result demonstrates that ThrACT not only supports distributed issuance, batch verification, and counting functionalities but also achieves computational overhead in milliseconds. In particular, when the threshold is set to (3,5), the token issuance time is approximately 9 milliseconds. Yanqi Zhao, Minghong Sun, Xiaoyi Yang 0001, Yong Yu 0002 |
IWCMC | 2 |
| 2025 | Probabilistic Visual Prompt Tuning
Minghong Sun, Lingye Zhao, Luojun Lin |
PRCV (6) | 1 |
| 2025 | A logarithmic size revocable linkable ring signature for privacy-preserving blockchain transactionsabstractMonero uses ring signatures to protect users’ privacy. However, Monero’s anonymity covers various illicit activities, such as money laundering, as it becomes difficult to identify and punish malicious users. Therefore, it is necessary to regulate illegal transactions while protecting the privacy of legal users. We present a revocable linkable ring signature scheme (RLRS), which balances the privacy and supervision for privacy-preserving blockchain transactions. By setting the role of revocation authority, we can trace the malicious user and revoke it in time. We define the security model of the revocable linkable ring signature and give the concrete construction of RLRS. We employ accumulator and ElGamal encryption to achieve the functionalities of revocation and tracing. In addition, we compress the ring signature size to the logarithmic level by using non-interactive sum arguments of knowledge (NISA). Then, we prove the security of RLRS, which satisfies anonymity, unforgeability, linkability, and non-frameability. Lastly, we compare RLRS with other ring signature schemes. RLRS is linkable, traceable, and revocable with logarithmic communication complexity and less computational overhead. We also implement RLRS scheme and the results show that its verification time is 1.5s with 500 ring members. Yanqi Zhao, Xiaoyi Yang 0001, Minghong Sun, Yong Yu 0002 |
High Confid. Comput. | 4 |