EDBT 2026 Demo / reviewers in the wild / expert
Zhipeng Wang 0009
dblp:56/5818-9
· DBLP profile ↗
14ranked-venue papers
5as first author
13since 2021 · last 2025
0000-0003-1089-1583ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 3 first-author · 11 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 first-author · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | DSKE: Digital Signatures with Key Extraction
Zhipeng Wang 0009, Orestis Alpos, Alireza Kavousi, Harry W. H. Wong, Sze Yiu Chau, Duc Viet Le 0001, Christian Cachin |
CT-RSA | 1 |
| 2025 | Towards Building Post-Quantum Secure Ethereum
Howell Liu, Zhipeng Wang 0009, William J. Knottenbelt |
ICBC | 2 |
| 2025 | Leverage Staking with Liquid Staking Derivatives (LSDs): Opportunities and Risks
Xihan Xiong, Zhipeng Wang 0009, Xi Chen 0015, William J. Knottenbelt, Michael Huth 0001 |
ICBC | 2 |
| 2025 | Toxic Ink on Immutable Paper: Content Moderation for Ethereum Input Data Messages (IDMs)abstractDecentralized communication is becoming an important use case within Web3. On Ethereum, users can repurpose the transaction input data field to embed natural-language messages, commonly known as Input Data Messages (IDMs). However, as IDMs gain wider adoption, there has been a growing volume of toxic content on-chain. This trend is concerning, as Ethereum provides no protocol-level support for content moderation.We propose two moderation frameworks for Ethereum IDMs: (i) BUILDERMOD, where builders perform semantic checks during block construction; and (ii) USERMOD, where users proactively obtain moderation proofs from external classifiers and embed them in transactions. Our evaluation reveals that BUILDERMOD incurs high block-time overhead, which limits its practicality. In contrast, USERMOD enables lower-latency validation and scales more effectively, making it a more practical approach in moderation-aware Ethereum environments.Our study lays the groundwork for protocol-level content governance in decentralized systems, and we hope it contributes to the development of a decentralized communication environment that is safe, trustworthy, and socially responsible. Xihan Xiong, Zhipeng Wang 0009, Qin Wang 0008, William J. Knottenbelt |
TrustCom | 2 |
| 2025 | TockOwl: Asynchronous Consensus with Fault and Network Adaptability
Minghang Li, Qianhong Wu, Zhipeng Wang 0009, Bohang Wei, Shihong Xiong, Zhenyang Ding |
USENIX Security Symposium | 3 |
| 2025 | $ \tt {zkFL}$zkFL: Zero-Knowledge Proof-Based Gradient Aggregation for Federated LearningabstractFederated learning (FL) is a machine learning paradigm, which enables multiple and decentralized clients to collaboratively train a model under the orchestration of a central aggregator. FL can be a scalable machine learning solution inbig datascenarios. Traditional FL relies on the trust assumption of the central aggregator, which forms cohorts of clients honestly. However, a malicious aggregator, in reality, could abandon and replace the client's training models, or insert fake clients, to manipulate the final training results. In this work, we introducezkFL, which leverages zero-knowledge proofs to tackle the issue of a malicious aggregator during the training model aggregation process. To guarantee the correct aggregation results, the aggregator provides a proof per round, demonstrating to the clients that the aggregator executes the intended behavior faithfully. To further reduce the verification cost of clients, we use blockchain to handle the proof in a zero-knowledge way, where miners (i.e., the participants validating and maintaining the blockchain data) can verify the proof without knowing the clients' local and aggregated models. The theoretical analysis and empirical results show thatzkFLachieves better security and privacy than traditional FL, without modifying the underlying FL network structure or heavily compromising the training speed. Zhipeng Wang 0009, Nanqing Dong, William J. Knottenbelt, Yike Guo |
IEEE Trans. Big Data | 1 |
| 2025 | TockCuckoo: Two-Phase BFT With Linearity and ResponsivenessabstractIt is critical to achieve the following objectives in partially synchronous Byzantine Fault Tolerance (BFT) protocols: (1) two-phase commit regime, (2) standard optimistic responsiveness, and (3) linear communication complexity. These three properties significantly affect the efficiency of BFT protocols. A number of attempts, such as HotStuff and Tendermint, have been made to solve this problem, but they typically manage to achieve only a subset of these properties. In this work, we propose a two-phase BFT protocol called TockCuckoo that fully achieves the aforementioned three properties. A primary challenge intwo-phaseBFT protocols is HiddenLock: when a leader lacks visibility into the latest locked block states of honest replicas, it cannot safely proceed, potentially stalling the protocol. To address this issue, we introduce the proactive voting paradigm, which explicitly distinguishes between rejection and non-receipt states. After global stable time, an honest leader can always collect sufficient votes through proactive voting, enabling quick responses. TockCuckoo operates in continuous rounds of proactive voting, ensuring responsiveness. The proactive voting process requires only linear communication overhead, which directly results in TockCuckoo achieving linear communication complexity overall. Furthermore, we introduce TockCuckoo+, an extension of TockCuckoo. By introducing a cross-pipelined design, TockCuckoo+ enables more frequent block proposals without sacrificing the key characteristics of TockCuckoo, leading to improved throughput. Our experiments in wide-area networks demonstrate that, TockCuckoo reduces commit latency by 20% to 40% compared to HotStuff across different network sizes, and TockCuckoo+ achieves a throughput increase of 1.1× to 1.5× over HotStuff. Minghang Li, Qianhong Wu, Zhipeng Wang 0009, Xuecheng Lin, Willy Susilo |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | SoK: Public RandomnessabstractPublic randomness is a fundamental component in many cryptographic protocols and distributed systems and often plays a crucial role in ensuring their security, fairness, and transparency properties. Driven by the surge of interest in blockchain and cryptocurrency platforms and the usefulness of such a building block in those areas, designing secure protocols to generate public randomness in a distributed manner has received considerable attention in recent years. This paper presents a systematization of knowledge on the topic of public randomness with a focus on cryptographic tools providing public verifiability and key themes underlying these systems. We provide concrete insights on how state-of-the-art protocols achieve this task efficiently in an adversarial setting and present various research gaps that may be of interest for future research. Alireza Kavousi, Zhipeng Wang 0009, Philipp Jovanovic |
EuroS&P | 2 |
| 2024 | A Transaction-Level Model for Blockchain Privacy
François-Xavier Wicht, Zhipeng Wang 0009, Duc Viet Le 0001, Christian Cachin |
FC (2) | 2 |
| 2024 | Exploring the Market Dynamics of Liquid Staking Derivatives (LSDs)abstractStaking has emerged as a crucial concept following Ethereum’s transition to Proof-of-Stake consensus. The introduction of Liquid Staking Derivatives (LSDs) has effectively addressed the illiquidity issue associated with solo staking, gaining significant market attention. This paper analyzes the LSD market dynamics from the perspectives of both liquidity takers (LTs) and liquidity providers (LPs). We first quantify the price discrepancy between the LSD primary and secondary markets. Then we investigate and empirically measure how LTs can leverage such discrepancy to exploit arbitrage opportunities, unveiling the potential barriers to LSD arbitrages. In addition, we evaluate the financial profit and losses experienced by LPs who supply LSDs for liquidity provision. Our results show that 66% of LSD liquidity positions generate returns lower than those from simply holding the corresponding LSDs. Xihan Xiong, Zhipeng Wang 0009, Qin Wang 0008 |
ICBC | 2 |
| 2023 | Pay Less for Your Privacy: Towards Cost-Effective On-Chain Mixers
Zhipeng Wang 0009, Marko Cirkovic, Duc Viet Le 0001, William J. Knottenbelt, Christian Cachin |
AFT | 1 |
| 2023 | SoK: Decentralized Finance (DeFi) AttacksabstractWithin just four years, the blockchain-based Decentralized Finance (DeFi) ecosystem has accumulated a peak total value locked (TVL) of more than 253 billion USD. This surge in DeFi’s popularity has, unfortunately, been accompanied by many impactful incidents. According to our data, users, liquidity providers, speculators, and protocol operators suffered a total loss of at least 3.24 billion USD from Apr 30, 2018 to Apr 30, 2022. Given the blockchain’s transparency and increasing incident frequency, two questions arise: How can we systematically measure, evaluate, and compare DeFi incidents? How can we learn from past attacks to strengthen DeFi security?In this paper, we introduce a common reference frame to systematically evaluate and compare DeFi incidents, including both attacks and accidents. We investigate 77 academic papers, 30 audit reports, and 181 real-world incidents. Our data reveals several gaps between academia and the practitioners’ community. For example, few academic papers address "price oracle attacks" and "permissonless interactions", while our data suggests that they are the two most frequent incident types (15% and 10.5% correspondingly). We also investigate potential defenses, and find that: (i) 103 (56%) of the attacks are not executed atomically, granting a rescue time frame for defenders; (ii) bytecode similarity analysis can at least detect 31 vulnerable/23 adversarial contracts; and (iii) 33 (15.3%) of the adversaries leak potentially identifiable information by interacting with centralized exchanges. Liyi Zhou, Xihan Xiong, Jens Ernstberger, Stefanos Chaliasos, Zhipeng Wang 0009, Kanye Ye Wang, Kaihua Qin, Roger Wattenhofer, Dawn Song, Arthur Gervais |
SP | 5 |
| 2023 | On How Zero-Knowledge Proof Blockchain Mixers Improve, and Worsen User PrivacyabstractZero-knowledge proof (ZKP) mixers are one of the most widely-used blockchain privacy solutions, operating on top of smart contract-enabled blockchains. We find that ZKP mixers are tightly intertwined with the growing number of Decentralized Finance (DeFi) attacks and Blockchain Extractable Value (BEV) extractions. Through coin flow tracing, we discover that 205 blockchain attackers and 2, 595 BEV extractors leverage mixers as their source of funds, while depositing a total attack revenue of 412.87M USD. Moreover, the US OFAC sanctions against the largest ZKP mixer, Tornado.Cash, have reduced the mixer’s daily deposits by more than . Zhipeng Wang 0009, Stefanos Chaliasos, Kaihua Qin, Liyi Zhou, Lifeng Gao, Pascal Berrang, Benjamin Livshits, Arthur Gervais |
WWW | 1 |
| 2019 | A Practical Lattice-Based Sequential Aggregate Signature
Zhipeng Wang 0009, Qianhong Wu |
ProvSec | 1 |