Liang Zhao 0020

dblp:63/5422-20 · DBLP profile ↗
← Back
14ranked-venue papers
8as first author
8since 2021 · last 2025
0000-0002-8846-9473ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 6 first-author · 4 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Exfiltration-Resistant Proxy Re-Encryption for IoT Data Sharing in Unreliable Clouds
abstract
The sharing of Internet of Things (IoT) data plays an extensive role in our everyday lives. Exploring secure and efficient methods for data sharing is a prominent area of research. Proxy re-encryption (PRE) in the cloud provides a solution. However, traditional PRE schemes are vulnerable to algorithm substitution attacks (ASA). Moreover, in most PRE schemes, the proxy can know the relevant identity information of the data owner or the data recipient through the re-encryption key, and some current PRE schemes cannot guarantee strong resistance to collision. To address the limitations of traditional PRE schemes and offer a robust solution for secure and efficient data sharing in IoT application, we propose a reverse firewall for proxy re-encryption (PRE-RF) scheme, which is implemented by JPBC library. Security analysis shows that our PRE-RF scheme provides effective resistance to ASA, along with strong collision security, chosen plaintext attack security, and key-private security. Compared with similar state-of-the-art PRE schemes, our scheme reduces the length of the re-encryption keys and ciphertext, thereby reducing the storage cost of the system. Meanwhile, our scheme’s computational cost is lower, thereby improving the operational efficiency of the system. Furthermore, the amount of time devoted to the reverse firewall in our scheme decreases as security level increases. As a result, these advantages make it a secure and efficient choice for sharing IoT data in unreliable cloud environments.
Liang Zhao 0020, Fagen Li, Tsuyoshi Takagi
IEEE Trans. Dependable Secur. Comput.2
2024 Privacy-Preserving Transformation Used in Verifiable (Outsourced) Computation, Revisited
abstract
Recently, a privacy-preserving technique called Privacy-Preserving Matrix Transformation (PPMT) is widely used to construct efficient privacy-preserving Verifiable (outsourced) Computation (VC) protocols for specific functions. This technique is first proposed and formalized by Salinas et al. in 2015, and it enjoys provable privacy and high efficiency. Although it seems that Salinas et al.'s PPMT scheme and the further modified scheme are elegant, we still need to take a step back and precisely discuss whether the PPMT schemes are suitable choices for VC protocols. Since Salinas et al. gave two concrete PPMT schemes to achieve the matrix-related VC in data protection and proved that their schemes are private (in terms of indistinguishability), and Zhou et al. devised a new type of PPMT scheme for the same purpose, we focus on exploring privacy of these three types of PPMT schemes. In this paper, to achieve our object, we first propose the concept of a linear distinguisher and two constructions of the linear distinguisher algorithms. In particular, the linear distinguisher is a polynomial-time algorithm employed by an adversary to explore the privacy property of a cryptographic primitive. Then, we take these three PPMT schemes (including Salinas et al.'s original work, Yu et al.'s generalization and Zhou et al.'s variant) as targets and analyze their privacy property by letting an adversary make use of our linear distinguisher algorithms. The analysis results show that all these three types of transformations do not hold privacy even against passive eavesdropping (i.e., a ciphertext-only attack), and subsequently, the privacy-preserving VC protocols, based on any of these PPMT schemes, also do not hold the same privacy.
Liang Zhao 0020, Liqun Chen 0002
IEEE Trans. Dependable Secur. Comput.1
2024 On the Privacy of Elementary Matrices Masking-Based Verifiable (Outsourced) Computation
abstract
Privacy-preserving Verifiable (outsourced) Computation (PVC) for face recognition is a significant research topic in the information security community. Recently, an efficient elementary matrices masking-based PVC protocol for face recognition has been published in IEEE Transactions on Dependable and Secure Computing [2]. In this paper, we analyze the privacy property of this protocol, and demonstrate that the output distribution of the problem generation algorithm in this protocol is not computationally indistinguishable from the uniform distribution over a matrix set, which breaks the original consequence (see Theorem 1). We introduce a formal definition of a privacy model for a PVC protocol and prove that the targeted PVC protocol does not hold privacy under this model. We then present our experimental results to support our theoretical analyses.
Liang Zhao 0020, Liqun Chen 0002
IEEE Trans. Dependable Secur. Comput.1
2023 EPPSQ: Achieving efficient and privacy-preserving statistics queries over encrypted data in smart grids
Beibei Li 0002, Linghao Zhang, Zhengwei Chang, Liang Zhao 0020, Arun Kumar 0006
Future Gener. Comput. Syst.5
2022 An Optimized GHV-Type HE Scheme: Simpler, Faster, and More Versatile
Liang Zhao 0020, Liqun Chen 0002, Xinyi Huang 0001
ACNS1
2022 Backdoor-resistant identity-based proxy re-encryption for cloud-assisted wireless body area networks
Liang Zhao 0020, Yuqiao Jin, Fagen Li
Inf. Sci.2
2021 Verifiable single-server private information retrieval from LWE with binary errors
Liang Zhao 0020, Xingfeng Wang, Xinyi Huang 0001
Inf. Sci.1
2021 DeepFed: Federated Deep Learning for Intrusion Detection in Industrial Cyber-Physical Systems
abstract
The rapid convergence of legacy industrial infrastructures with intelligent networking and computing technologies (e.g., 5G, software-defined networking, and artificial intelligence), have dramatically increased the attack surface of industrial cyber-physical systems (CPSs). However, withstanding cyber threats to such large-scale, complex, and heterogeneous industrial CPSs has been extremely challenging, due to the insufficiency of high-quality attack examples. In this article, we propose a novel federated deep learning scheme, named DeepFed, to detect cyber threats against industrial CPSs. Specifically, we first design a new deep learning-based intrusion detection model for industrial CPSs, by making use of a convolutional neural network and a gated recurrent unit. Second, we develop a federated learning framework, allowing multiple industrial CPSs to collectively build a comprehensive intrusion detection model in a privacy-preserving way. Further, a Paillier cryptosystem-based secure communication protocol is crafted to preserve the security and privacy of model parameters through the training process. Extensive experiments on a real industrial CPS dataset demonstrate the high effectiveness of the proposed DeepFed scheme in detecting various types of cyber threats to industrial CPSs and the superiorities over state-of-the-art schemes.
Beibei Li 0002, Yuhao Wu 0006, Rongxing Lu, Tao Li 0016, Liang Zhao 0020
IEEE Trans. Ind. Informatics6
2020 On the Privacy of Matrix Masking-Based Verifiable (Outsourced) Computation
abstract
Privacy-preserving verifiable (outsourced) computation (PPVC) is a useful technique for a resource-constrained client to outsource computationally heavy but sensitive tasks to a computationally powerful but untrusted worker and to obtain expected correct results from the worker. In this paper, we analyze the privacy property of three matrix masking-based PPVC protocols, which have recently been published in IEEE Transactions on Cloud Computing [2] , [3] . To do this, we present a formal definition of a privacy model for a PPVC protocol (see Definition 1 ), and then prove that neither of those three PPVC protocols holds privacy under this model. We also review the comments by Cao et al. [1] on two of the three protocols and show an issue in their comments.
Liang Zhao 0020, Liqun Chen 0002
IEEE Trans. Cloud Comput.1
2020 Sparse Matrix Masking-Based Non-Interactive Verifiable (Outsourced) Computation, Revisited
abstract
A Privacy-preserving Verifiable (outsourced) Computation (PVC) protocol enables a resource-constrained client to outsource expensive and sensitive workloads to computationally powerful but possibly untrusted service providers (called workers) and to verify the correctness of the results. In a PVC protocol, the inputs and outputs of the computation are hidden, so that the worker is unable to determine them. This is referred to as the privacy property. A Non-interactive PVC (NPVC) protocol is a PVC protocol without communications between a client and worker, apart from distributing the workloads and results. In the literature, Sparse Matrices (SMs) have been used in NPVC protocols to efficiently hide the inputs and outputs from the worker. However, to the best of our knowledge, how the low density of an SM affects privacy in such NPVC protocols has not been formally analyzed. In this work, we first propose a formal definition of the privacy property of an NPVC protocol with respect to matrix density. We use this definition to demonstrate that all of the SM masking-based NPVC protocols that we know of do not hold this privacy property under the ciphertext-only attack model. We then propose an SM masking construction to modify two of those protocols, chosen because they are state-of-the-art, and prove that the modified protocols hold the privacy property under the chosen-plaintext attack model. Our modifications do not require the client operating matrix inversion, and they are able to keep the same level of high performance and all other properties as the originals.
Liang Zhao 0020, Liqun Chen 0002
IEEE Trans. Dependable Secur. Comput.1
2019 Revisiting the Secret Hiding Assumption Used in Verifiable (Outsourced) Computation
Liang Zhao 0020
CT-RSA1
2018 A Linear Distinguisher and its Application for Analyzing Privacy-Preserving Transformation Used in Verifiable (Outsourced) Computation
abstract
A distinguisher is employed by an adversary to explore the privacy property of a cryptographic primitive. If a cryptographic primitive is said to be private, there is no distinguisher algorithm that can be used by an adversary to distinguish the encodings generated by this primitive with non-negligible advantage. Recently, two privacy-preserving matrix transformations first proposed by Salinas et al. have been widely used to achieve the matrix-related verifiable (outsourced) computation in data protection. Salinas et al. proved that these transformations are private (in terms of indistinguishability). In this paper, we first propose the concept of a linear distinguisher and two constructions of the linear distinguisher algorithms. Then, we take those two matrix transformations (including Salinas et al.$'$s original work and Yu et al.$'$s modification) as example targets and analyze their privacy property when our linear distinguisher algorithms are employed by the adversaries. The results show that those transformations are not private even against passive eavesdropping.
Liang Zhao 0020, Liqun Chen 0002
AsiaCCS1
2018 Verifiable Single-Server Private Information Retrieval
Xingfeng Wang, Liang Zhao 0020
ICICS2
2015 A New Statistical Approach for Integral Attack
Jiageng Chen, Atsuko Miyaji, Chunhua Su, Liang Zhao 0020
NSS4