Lei Wu 0011

dblp:68/5597-11 · DBLP profile ↗
← Back
20ranked-venue papers
2as first author
16since 2021 · last 2026
0000-0002-2691-0243ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 1 first-author · 3 since 2021Computer networks · 4 · 4 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 QSDA: Quality-Aware Secure Multidimensional Data Aggregation With Location Privacy for HIoT
abstract
Data aggregation, as a data processing technique, facilitates accurate diagnosis in the Healthcare Internet of Things (HIoT) by integrating multi-source heterogeneous health data. However, achieving efficient and secure aggregation of multi-dimensional medical data remains challenging, particularly when simultaneously preserving location privacy and providing fair, quality-driven incentives. To address these issues, this paper proposes a Quality-Aware Secure Multi-Dimensional Data Aggregation scheme with Location Privacy for HIoT (QSDA). First, the scheme employs inner product encryption to support aggregation task matching without revealing users’ actual coordinates, and further integrates symmetric homomorphic encryption with super-increasing sequences to enable one-stop compressed aggregation of multi-dimensional data, thereby effectively supporting common statistical operations such as mean and variance. Second, it introduces a data quality incentive mechanism based on offset metrics, while leveraging blockchain auditing to ensure the traceability of the aggregation process and the verifiability of the aggregation results. Finally, security analysis and performance evaluation demonstrate the scheme’s effectiveness and efficiency.
Lei Wu 0011, Ye Su 0001, Hao Wang 0007, Weizhi Meng 0001, Zhiquan Liu 0001
IEEE Internet Things J.2
2026 SecOIR: Enhancing Privacy and Accuracy in Outsourced Image Retrieval via Function Secret Sharing and Deep Hashing
abstract
With the increasing prevalence of outsourcing images to cloud servers, privacy-preserving content-based image retrieval (CBIR) has attracted significant research attention. Existing privacy-preserving CBIR schemes often prioritize retrieval speed by adopting methods that provide weak privacy guarantees and low-dimensional image features, which inevitably compromises security and retrieval accuracy. Additionally, most solutions directly employ CNN models pre-trained on public datasets for feature extraction, neglecting domain adaptation problem. To address these limitations, we propose SecOIR, a secure outsourced image retrieval scheme based on deep hashing networks, which achieves provable security under the semi-honest adversary model while hiding access patterns. Furthermore, domain adaptation is resolved through fine-tuning of feature extraction models. Experimental results demonstrate that SecOIR outperforms state-of-the-art schemes by 11%-12% in accuracy under identical datasets and configurations, while maintaining practical efficiency. To achieve SecOIR, we propose two modified function secret sharing (FSS) schemes that overcome the limited compatibility of the original FSS schemes with replicated secret sharing (RSS). Then, building upon the modified FSS schemes and RSS, we design a series of efficient sub-protocols. Benchmark tests reveal that our sub-protocols surpass existing mainstream solutions in efficiency, which can also serve as independent contributions to secure multi-party computation protocol design.
Zhi Li 0056, Hao Wang 0007, Ye Su 0001, Xiaochao Wei, Lei Wu 0011
IEEE Trans. Dependable Secur. Comput.5
2026 SAPP: Achieving Semantic-Aware Differential Privacy for Spatiotemporal Trajectory Data Publishing
abstract
With the increasing availability of large-scale spatiotemporal data from location-based services, trajectory publishing has become essential for data-driven analysis and intelligent applications. However, insufficient protection of trajectory location data may result in the disclosure of user privacy and social relationship information. To address this issue, we propose a semantic-aware privacy-preserving trajectory data publishing scheme (SAPP). First, a sliding-window algorithm is employed to extract stay points as key semantic locations and to generate a uniformly sampled set of candidate obfuscation points. Then, a semantic-aware scoring function is designed to probabilistically select candidate points that preserve semantics while avoiding sensitive regions. Furthermore, SAPP computes the sensitivity of each location based on semantic frequency and dynamically allocates the privacy budget. Finally, random noise is added to candidate trajectories using the Laplace mechanism. Through a dual-perturbation mechanism, spatial correlations in sensitive regions are weakened. Security analysis and experimental results further demonstrate that, compared with existing approaches, SAPP reduces TPPS and SFRR by up to 18% and 14%, respectively, indicating stronger resistance against trajectory inference and semantic leakage attacks while maintaining high data utility and time efficiency.
Lei Wu 0011, Ye Su 0001, Hao Wang 0007, Weizhi Meng 0001, Zhiquan Liu 0001
IEEE Trans. Knowl. Data Eng.2
2025 Privacy-Preserving Machine Learning in Cloud-Edge-End Collaborative Environments
abstract
We propose a privacy-preserving machine learning scheme based on the cloud-edge–end architecture to address issues like weak computing power of Internet of Things (IoT) terminals, poor communication quality, and heavy cloud server burdens in traditional frameworks. Edge servers aggregate and forward terminal data, relieving terminals of heavy communication tasks and undertaking part of the computing tasks, which reduces the burden on cloud servers and improves system response speed. For privacy protection, we flexibly use homomorphic encryption and secret sharing techniques, and dynamically add differential privacy noise to resist member inference attacks. Task allocation is coordinated between different layers to optimize computing overhead. Shallow model training is performed on edge servers using homomorphic encryption, while deep model training is conducted on cloud servers using secret sharing. To achieve the conversion from homomorphic ciphertext to secret sharing shares, we design a distributed decryption protocol. Experimental results show our scheme reduces computation overhead by 20%–30% compared to existing privacy-preserving machine learning schemes based on the cloud-edge–end framework, while maintaining privacy protection throughout all stages.
Hao Wang 0007, Zhi Li 0056, Ziyu Niu, Lei Wu 0011, Xiaochao Wei, Ye Su 0001, Willy Susilo
IEEE Internet Things J.5
2025 Privacy-preserving and verifiable multi-task data aggregation for IoT-based healthcare
Xinzhe Zhang, Lei Wu 0011, Lijuan Xu 0001, Zhien Liu, Ye Su 0001, Hao Wang 0007, Weizhi Meng 0001
J. Inf. Secur. Appl.2
2025 PPSKSQ: Towards Efficient and Privacy-Preserving Spatial Keyword Similarity Query in Cloud
abstract
The growth of cloud computing has led to the widespread use of location-based services, such as spatial keyword queries, which return spatial data points within a given range that have the highest similarity in keyword sets to the user’s. As the volume of spatial data increases, providers commonly outsource data to powerful cloud servers. Because cloud servers are untrustworthy, privacy-preserving keyword query schemes have been proposed. However, existing schemes consider only location queries or exact keyword matching. To address these issues, we propose the Privacy-Preserving Spatial Keyword Similarity Query Scheme (PPSKSQ), designed to search for spatial data points with the highest similarity while protecting the privacy of outsourced data, query requests, and results. First, we design two sub-protocols based on improved symmetric homomorphic encryption (iSHE): iSHE-SC for secure size comparison and iSHE-SIP for secure inner product computation. Then, we encode range information and integrate it with a quadtree to construct a novel index structure. Additionally, we use the Jaccard to measure similarity in conjunction with the iSHE-SC protocol, transforming similarity comparison into a matrix trace operation. Finally, rigorous security analysis and extensive simulation experiments confirm the flexibility, efficiency, and scalability of our scheme.
Changrui Wang, Lei Wu 0011, Lijuan Xu 0001, Hao Wang 0007, Wenying Zhang 0001, Weizhi Meng 0001
IEEE Trans. Cloud Comput.2
2024 Publicly Verifiable Secure Multi-Party Computation Framework Based on Bulletin Board
abstract
Although secure multi-party computation breaks down data barriers, its utility is reduced when participants have limited computation and communication resources. To make secure multi-party computation more practical, there exists an approach to distribute users' private inputs to multiple servers in a secret sharing manner, and the servers accomplish secure computation tasks through interaction. We propose a new secure computation framework that enables the detection of malicious cloud servers by introducing homomorphic MACs. We utilize pairing-based homomorphic commitments to record MACs on a bulletin board, providing public verifiability while reducing the computation burden on the cloud servers. Additionally, our framework not only supports the underlying general computation, but also prepares for various types of nontrivial high-level operations, such as comparison and bit decomposition. We design a smart payment platform enabling fair payment with the help of smart contracts to protect the rights of both data owners and cloud service providers. Compared to previous works, our framework breaks the limitations of servers being restricted to semi-honest or even honest and provides public verifiability. Performance evaluations demonstrate satisfactory computation and communication efficiency during the online phase of our system.
Hao Wang 0007, Zhi Li 0056, Lei Wu 0011, Xiaochao Wei, Ye Su 0001, Rongxing Lu
IEEE Trans. Serv. Comput.4
2024 Towards Auditable and Privacy-Preserving Online Medical Diagnosis Service Over Cloud
abstract
While online medical diagnosis provides significant convenience to users, it also incurs the risk of privacy breaches, which inspired the emergence of various privacy-preserving online medical schemes. Nonetheless, existing schemes either compromise partial privacy to third parties or rely on cryptographic methods with high computational complexity. In particular, they do not anticipate user’s disputes to the extent that there is no audit process to guarantee the correctness of the diagnosis results and the fairness of the schemes. Consequently, we propose an efficient and privacy-preserving online medical diagnosis scheme based on additive secret sharing (ASS). First, the anonymity of the user is provided in the medical diagnosis process, which ensures that the cloud cannot link the diagnosis results to the user. Then, we devise a minimum value protocol and a range comparison protocol to enhance the security of the online diagnosis. In addition, considering user’s disputes that arise in realistic scenarios (e.g., malicious users may cheat the diagnosis system for personal benefits), we construct a blockchain-based audit process to detect user’s behaviors and settle controversies. Finally, we demonstrate the security and efficiency of the proposed scheme with theoretical analysis and experimental evaluation.
Xinzhe Zhang, Lei Wu 0011, Zhien Liu, Hao Wang 0007, Lijuan Xu 0001, Songnian Zhang, Rongxing Lu
IEEE Trans. Serv. Comput.2
2023 A privacy-preserving blockchain-based tracing model for virus-infected people in cloud
Chengyi Qin, Lei Wu 0011, Weizhi Meng 0001, Zihui Xu, Hao Wang 0007
Expert Syst. Appl.2
2023 PPTA: Privacy-Preserving Task Assignment Based on Inner Product Functional Encryption in SAM
abstract
The explosions of mobile communications and the Internet of Things (IoT) have spawned a new distributed computing paradigm—spatial crowdsourcing, in which workers actively participate in spatiotemporal computing tasks for earning commissions, facilitating the development of urban sharing economic services. Furthermore, to reduce users’ storage space and computational overhead, the server assignment model (SAM) is widely used, which means that crowdsourcing platforms collect sensitive information about tasks and workers, e.g., locations and interests, to perform task assignments accurately. However, in the real world, crowdsourcing platforms are not fully trustworthy and may reveal sensitive information about workers and tasks, which can reduce users’ motivation to use crowdsourcing services. Therefore, how to assign tasks efficiently and securely is still an urgent problem to be solved. In this article, we propose a privacy-preserving task assignment scheme (PPTA), in which the crowdsourcing platform efficiently implements the nearest task assignments without revealing sensitive information about tasks and workers. In PPTA, we utilize inner product functional encryption to achieve circular range queries and multikeyword queries. Considering that workers usually prefer to query the nearest tasks for reducing travel costs, we use the grid location intersection to enable the nearest task assignment. In particular, we design a SAM algorithm, which can improve task assignment rates in multitask and multiworker scenarios. In addition, our scheme can implement user accountability and user revocation, which enhances the security and practicality of the scheme. Finally, we demonstrate the privacy preservation through security theoretical proofs and show the efficiency by constructing extensive comparative experiments, which respectively illustrate the security and the effectiveness of our scheme.
Zihui Xu, Lei Wu 0011, Chengyi Qin, Songnian Zhang, Rongxing Lu
IEEE Internet Things J.2
2023 TCPP: Achieving Privacy-Preserving Trajectory Correlation With Differential Privacy
abstract
The prevalence of mobile Internet, smart terminal devices, and GPS positioning technology has generated a vast number of trajectory data that location-based applications can utilize. However, delivering LBSs based on trajectories without extra protection may expose the personal information of users and even their social ties. Despite the fact that many works have been offered to achieve differential privacy for trajectory correlation, the vast majority of them only consider the trajectory correlation of a single user, and privacy protection for trajectory correlation amongst multiple users is not considered. Directly applying these works to protect correlation amongst multiple users may lead to the low availability of published trajectory data. To address the above challenges, we propose a trajectory correlation privacy-preserving mechanism (TCPP) that fulfills differential privacy. Specifically, we first apply the Euclidean distance to filter out a set of trajectories whose correlation needs to be protected. Then, we employ the Kalman filter to generate a dataset with high availability from the set of trajectories. Finally, we present a mechanism for publishing trajectories that preserves the trajectory correlation based on a customized privacy budget allocation strategy. Rigid security analysis shows that our proposed mechanism can well preserve the correlation privacy of trajectories. Experimental results on real-world datasets further demonstrate the privacy, availability and time efficiency advantages of our mechanism.
Lei Wu 0011, Chengyi Qin, Zihui Xu, Yunguo Guan, Rongxing Lu
IEEE Trans. Inf. Forensics Secur.1
2023 Distribution Network Topology Identification Using Smart Meter Data and Considering the Same-Bus-Different-Feeder Condition
abstract
Due to the rapid growth of distribution systems in urban areas, the increasing complexity of these distribution systems brings challenges to accurate topology identification. The collected voltage data from smart meters have been proven effective in topology identification applications. However, when multiple feeders are connected to the same bus, the accuracy of existing voltage-correlation-based topology identification can be degraded significantly. To address this challenge, a comprehensive inference method is proposed in this article to identify theon/offswitch state in the distribution system considering the same-bus-different-feeder condition. The voltage-power-dependence principle among connected nodes is revealed. Based on this theory, a physical probabilistic network model is proposed to represent the causal relationships between the switch states and the voltage-power dependence in a distribution network. The belief propagation algorithm is introduced to deduce the topology identification model, which can reduce the time consumption of the inference. The performance of the proposed method and its advantage over the existing methods are verified in case studies.
Zhiqi Xu, Wei Jiang 0011, Junjun Xu, Lei Wu 0011, Junbo Zhao 0001
IEEE Trans. Ind. Informatics4
2022 A electronic voting protocol based on blockchain and homomorphic signcryption
abstract
Summary Compared with traditional voting methods, electronic voting can effectively avoid the phenomenon of fraud for personal gains in various links, it is faster and more accurate in the tallying stage. However, many electronic voting systems have many problems such as inability to verify ballots, easy to be forged, and low computing efficiency. We propose an electronic voting protocol based on homomorphic signcryption and blockchain. The protocol makes the voting process public through blockchain and replaces the traditional trusted third party with the smart contract. It uses the homomorphic encryption algorithm and the homomorphic signcryption algorithm to encrypt and sign the ballot and uses their aggregation properties to perform homomorphic tally on the encrypted votes. This not only reduces the excessive burden on the voters but also improves the voting efficiency. At the same time, it can satisfy the security of electronic voting, and the amount of calculation is small, so it is more convenient and flexible to use in large‐scale voting.
Wenlei Qu, Lei Wu 0011, Wei Wang 0012, Zhaoman Liu, Hao Wang 0007
Concurr. Comput. Pract. Exp.2
2022 Privacy-preserving location-based traffic density monitoring
abstract
Traffic density monitoring is an important method to predict road traffic conditions, which can bring some convenience to people's travel in daily life. The common method of traffic density monitoring is to collect and process the location information uploaded by vehicles, but the information of these vehicle location contains a large amount of personal privacy information of vehicle owners, and there is a risk of privacy disclosure. In this paper, we propose a traffic density monitoring system by adding a pseudonym server and a location anonymisation server; the identity information and location information of the vehicles are saved separately. The system can protect both the location privacy of vehicles and the query privacy of users. To prevent dummy locations from being filtered, we calculate the probability distribution of historical location service requests to generate location anonymous sets, which can improve the success rate of anonymity. The location anonymisation server uses the location anonymous set instead of the real location of the vehicle to send to the location-based service provider, which can increase the location privacy security of the vehicle. According to the experimental results of this paper, compared with SimpMaxMinDistds algorithm and MMDS algorithm, our system has better location anonymous set generation efficiency and location privacy protection level.
Lei Wu 0011, Xia Wei, Lingzhen Meng, Hao Wang 0007
Connect. Sci.1
2022 DVPPIR: privacy-preserving image retrieval based on DCNN and VHE
Lei Wu 0011, Weizhi Meng 0001, Zihui Xu, Chengyi Qin, Hao Wang 0007
Neural Comput. Appl.2
2021 Accurate Range Query With Privacy Preservation for Outsourced Location-Based Service in IoT
abstract
With the maturity of Internet-of-Things technology, location-based service (LBS) is developing rapidly in intelligent terminal devices, and it brings new vitality to the fields of logistics, transportation, product traceability and so on. The popularity of LBS produces a lot of spatial data, which inevitably brings burden to the storage and management of LBS provider (LBSP). With the help of cloud computing and cloud storage, outsourcing spatial data to cloud server has become a new trend. However, due to the cloud server is not trusted, data outsourcing will face the problems of data disclosure and query disclosure. Range query is a common query in LBS, considering the situation of data outsourcing, this article proposes an accurate range query (ARQ) scheme, which can realize efficient range query while preserving LBSP's data privacy and user's query privacy from being disclosed to the cloud server. The ARQ scheme is suitable for spatial data in any form without being limited to the case that the data points are only integers, which has a certain practical significance. In addition, by dividing the region into atomic regions, ARQ can realize sublinear search time and ensure dynamic update of spatial data. We proved the security of the proposed scheme through security analysis, and demonstrated the effectiveness of the scheme through experiments.
Zhaoman Liu, Lei Wu 0011, Weizhi Meng 0001, Hao Wang 0007, Wei Wang 0012
IEEE Internet Things J.2
2019 Efficient Attribute-Based Encryption with Privacy-Preserving Key Generation and Its Application in Industrial Cloud
abstract
Due to the rapid development of new technologies such as cloud computing, Internet of Things (IoT), and mobile Internet, the data volumes are exploding. Particularly, in the industrial field, a large amount of data is generated every day. How to manage and use industrial Big Data primely is a thorny challenge for every industrial enterprise manager. As an emerging form of service, cloud computing technology provides a good solution. It receives more and more attention and support due to its flexible configuration, on-demand purchase, and easy maintenance. Using cloud technology, enterprises get rid of the heavy data management work and concentrate on their main business. Although cloud technology has many advantages, there are still many problems in terms of security and privacy. To protect the confidentiality of the data, the mainstream solution is encrypting data before uploading. In order to achieve flexible access control to encrypted data, attribute-based encryption (ABE) is an outstanding candidate. At present, more and more applications are using ABE to ensure data security. However, the privacy protection issues during the key generation phase are not considered in the current ABE systems. That is to say, the key generation center (KGC) knows both of attributes and corresponding keys of each user. This problem is especially serious in the industrial big data scenario, because it will cause great damage to the business secrets of industrial enterprises. In this paper, we design a new ABE scheme that protects user’s privacy during key issuing. In our new scheme, we separate the functionality of attribute auditing and key generating to ensure that the KGC cannot know user’s attributes and that the attribute auditing center (AAC) cannot obtain the user’s secret key. This is ideal for many privacy-sensitive scenarios, such as industrial big data scenario.
Yujiao Song, Hao Wang 0007, Xiaochao Wei, Lei Wu 0011
Secur. Commun. Networks4
2019 Integrity Audit of Shared Cloud Data with Identity Tracking
abstract
More and more users are uploading their data to the cloud without storing any copies locally. Under the premise that cloud users cannot fully trust cloud service providers, how to ensure the integrity of users’ shared data in the cloud storage environment is one of the current research hotspots. In this paper, we propose a secure and effective data sharing scheme for dynamic user groups. (1) In order to realize the user identity tracking and the addition and deletion of dynamic group users, we add a new role called Rights Distribution Center (RDC) in our scheme. (2) To protect the privacy of user identity, when performing third party audit to verify data integrity, it is not possible to determine which user is a specific user. Therefore, the fairness of the audit can be promoted. (3) Define a new integrity audit model for shared cloud data. In this scheme, the user sends the encrypted data to the cloud and the data tag to the Rights Distribution Center (RDC) by using data blindness technology. Finally, we prove the security of the scheme through provable security theory. In addition, the experimental data shows that our proposed scheme is more efficient and scalable than the state-of-the-art solution.
Yunxue Yan, Lei Wu 0011, Wenyu Xu, Hao Wang 0007, Zhaoman Liu
Secur. Commun. Networks2
2018 A dynamic integrity verification scheme of cloud storage data based on lattice and Bloom filter
Yunxue Yan, Lei Wu 0011, Hao Wang 0007, Wenyu Xu
J. Inf. Secur. Appl.2
2012 A new one-bit difference collision attack on HAVAL-128
Wenying Zhang 0001, Lei Wu 0011
Sci. China Inf. Sci.3