Mingyang Zhao 0002

dblp:74/3767-2 · DBLP profile ↗
← Back
14ranked-venue papers
3as first author
14since 2021 · last 2026
0000-0002-9854-2697ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 1 first-author · 9 since 2021Security and privacy · 4 · 2 first-author · 4 since 2021
YearPublicationVenuePosition
2026 $\mathsf {Trident}$Trident: A Secure Framework for Flexible Artificial Intelligence Model Lifecycle Management in Public Clouds
abstract
The growing demand for computing power drives more artificial intelligence (AI) model owners to outsource their models to public clouds, relying on cloud servers to manage which users can use, train, or upgrade AI models. Unfortunately, existing work cannot simultaneously manage the entire model lifecycle in public clouds when considering model stealing attacks, where cloud servers covertly replicate AI models and deliver AI services to unauthorized users for profit. As a result, model owners are forced to conduct training and upgrades in private environments before deploying models to clouds for service delivery, which poses significant challenges in collaboration and maintenance, particularly for models requiring frequent upgrades. In this paper, we introduce$\mathsf {Trident}$, the first secure cloud-based framework for flexible AI model lifecycle management, including availability, trainability, and upgradability. By leveraging multiple cryptographic techniques, such as access control trees,$\mathsf {Trident}$ensures that AI models and their management policies are tightly coupled, compelling cloud servers to execute only specified model operations without violating management policies, thereby resisting model stealing attacks. Rather than straightforward cryptographic applications, we address a series of technical challenges, including shifting the focus of access control trees from data to model management and maintaining downward-compatible model management rights. We propose two detailed constructions: Semi-$\mathsf {Trident}$and Full-$\mathsf {Trident}$, tailored for semi-delegation and full-delegation scenarios, i.e., whether model owners need to interact with cloud servers while delivering AI services. Theoretical complexity analysis and security analysis prove the competitive efficiency and security. Experimental results show that compared to assembling existing partial-function schemes, Semi-$\mathsf {Trident}$and Full-$\mathsf {Trident}$achieve around$3.6\times$improvement in time costs and$5\times$improvement in communication overhead.
Mingyang Zhao 0002, Zekai Yu, Chuan Zhang 0003, Song Guo 0001, Bin Xiao 0001
IEEE Trans. Dependable Secur. Comput.1
2026 PODS: Efficient and Secure Identity-Based Hierarchical Data Processing Control in Mobile Cloud Storage
abstract
Nowadays, mobile cloud storage has become increasingly prevalent for processing mobile data due to its convenience and resources. Towards the right to restriction of processing in current data regulations, some solutions have been proposed to empower data owners with identity-based hierarchical control for equality, comparison, and plaintext analytics operations. However, existing solutions either rely on specific hardware environments (i.e., trusted execution environments) or face two significant issues: identity privacy breaches, where attackers can identify targeted users, and excessive overhead in multi-user scenarios, as each user requires a distinct ciphertext. In this paper, we leverage multiple cryptographic primitives to introduce PODS, an efficient and secure hierarchical data processing control scheme for multi-user mobile cloud storage. PODS allows the data owner to generate a single ciphertext for multiple users without hardware reliance. Technically, we reconstruct identity-based encryption by leveraging well-designed common and private parameters, thereby shifting the focus from data itself to data processing operations. Then, we encode multiple targeted identities as polynomial coefficients and integrate these coefficients into identity-based data processing control. We achieve threefold benefits, effectively reducing overhead, hierarchically processing users' rights, and concealing the identities of targeted users to protect privacy. Security analysis proves the security of PODS. Experiments demonstrate that PODS achieves around$8\times$and$37\times$improvement in computation and communication compared to existing related works.
Mingyang Zhao 0002, Zhuoyu Sun, Chuan Zhang 0003, Liehuang Zhu, Song Guo 0001, Bin Xiao 0001
IEEE Trans. Mob. Comput.1
2025 DLM-IDS: Leveraging LLM for Efficient IoT Intrusion Detection with Limited Training Data
abstract
Artificial intelligence has demonstrated significant potential for traffic analysis in IoT intrusion detection systems. However, existing machine learning (ML) solutions struggle with high false alarm rates due to a lack of malicious data. The advantages of large language models (LLMs), particularly their few-shot learning capabilities, can effectively address this issue. Nonetheless, LLMs face challenges such as high computational overhead and detection latency, which make them impractical for IoT intrusion detection. One promising solution is to leverage knowledge distillation, shrinking the LLM, the teacher model, into a smaller student model that requires limited malicious examples while preserving the low latency characteristic of traditional ML-based models. In this paper, we propose DLM-IDS, an efficient and accurate traffic analysis framework for IoT intrusion detection with small training datasets, empowered by LLM knowledge distillation. Specifically, DLM-IDS introduces a chain-of-thought (CoT) mechanism that enables a pre-trained LLM to interpret network traffic patterns without requiring additional training or fine-tuning. By extracting rationales from the LLM (around 200B parameters), the teacher model, DLM-IDS constructs a small yet highly accurate student traffic analysis model (around 200 million parameters). Experiments show that with only 800 examples in the training dataset, DLM-IDS maintains over 98% AUC while reducing inference time from 3.2s to 0.037s per flow detection, enabling practical low-latency deployment on resource-constrained IoT devices.
Mingyang Zhao 0002, Guyue Li, Bin Xiao 0001
GLOBECOM2
2025 SecPoS: Slashable Proof-of-Stake Consensus with Low Transaction Delays and Checkpoint Costs
abstract
Nowadays, checkpoints have been proven to be an effective solution to ensure slashability in proof-of-stake (PoS) consensus, and Tas et al.'s cutting-edge solution in S&P 2023 is a typical example. Unfortunately, despite progress, hour-level transaction delays and annually around 10 K dollar checkpoint costs make existing related solutions still unacceptable in realworld PoS applications. In this paper, we propose SecPoS, a slashable PoS consensus with second-level transaction delays and one-time checkpoint costs. To achieve these design goals, we draw inspiration from Pixel+ signatures and chameleon hash functions to design a novel bilateral blockchain structure, achieving twoblock transaction finalization via only uploading the first block of our chain as checkpoints. Next, considering practical application requirements, we address a series of following challenges, such as bilateral immutability, blockchain forks, determination of the main chain, and malicious attacks from PoS members. In detail, we propose two constructions of SecPoS, i.e., SecPoS – A and SecPoS – B. SecPoS – A and SecPoS – B have a tradeoff between transaction delays and block numbers packed in an epoch. Compatible with most existing one-way blockchains, we implement and outsource a prototype SecPoS to facilitate research11https://github.com/Academic-Paper-Codes/SecPoS-Consensus, and prove the security of SecPoS. Experiments on this prototype show that SecPoS – A and SecPoS – B require around 5s and 100s transaction delays, respectively, and both require 2 dollars one-time checkpoint costs.
Chuan Zhang 0003, Zekai Yu, Zhe Peng, Mingyang Zhao 0002, Liehuang Zhu, Bin Xiao 0001
IWQoS4
2025 High-Dimensional and Secure Spatial Keyword Query With Arbitrary Ranges in Mobile Cloud
abstract
Spatial keyword query has emerged as a critical service in mobile cloud, enabling cloud servers to retrieve spatiotextual objects within a mobile user's query range that contain specified query keywords. Numerous secure spatial keyword query schemes have been developed to enable geometric range queries and keyword searches on encrypted spatial data. However, spatial keyword queries are typically designed for searching high-dimensional spatial data across arbitrary geographic ranges. Most of them fail to handle arbitrary geometric range queries and efficient spatial keyword query over high-dimensional encrypted data. To address these issues, we propose a high-dimEnsional and Privacy-preserving Spatial Keyword Query (EPSKQ) scheme with arbitrary geometric ranges over encrypted spatial data, leveraging Hilbert curve encoding and Enhanced Matrix-based Inner Product Encryption (EMIPE). In EPSKQ, spatial locations and multi-keywords are encoded into compact vectors, and arbitrary geometric range queries are transformed into range intersection tests. To reduce computational overhead, we employ vector bucketing technique to partition large-size vectors into several small-size sub-vectors. Furthermore, we design a novel index structure called Hilbert Binary tree (HB-tree) to optimize range intersection tests. Based on HB-tree, we propose an enhanced spatial keyword query scheme, named EPSKQ+, which further improves query performance. Security analysis demonstrates that both EPSKQ and EPSKQ+ achieve semantic security against indistinguishability under chosen-plaintext attack (INDCPA). Extensive experimental evaluations show that the proposed EPSKQ and EPSKQ+ schemes significantly outperform state-ofthe-art schemes in terms of computational and communication costs, with EPSKQ+ being 9× and 3× faster than the state-ofthe-art schemes in the index build and query phase, respectively
Fuyuan Song, Mingyang Zhao 0002, Chuan Zhang 0003, Zheng Qin 0001, Bin Xiao 0001
IEEE Trans. Mob. Comput.3
2024 Privacy-Preserving and Revocable Redactable Blockchains With Expressive Policies in IoT
abstract
With integrity and traceability, blockchains have been widely applied in Internet of Things (IoT) systems. However, immutable blockchains contradict recent data regulations (e.g., the right to be forgotten in General Data Protection Regulation), making redactable blockchain-based IoT emerge as a promising paradigm. In this paradigm, IoT users can specify expressive policies (i.e., containing multiple logical AND and OR operators) to achieve controllable data editability. Unfortunately, existing related schemes with expressive policies face several issues: high communication costs, data privacy leakage (i.e., data can be read by all users), and inefficient user revocation. This article proposes a privacy-preserving and revocable redactable blockchain scheme in IoT systems, named BlockENC. BlockENC allows owners to specify expressive policies for controlling which users can read or edit their data and ensures downward compatible privileges (i.e., editable users own the privilege of readable users but not vice versa) under only$\mathcal {O}(n)$communication costs$(\mathcal {O}(n^{2})$in other schemes). The punchline of BlockENC is to define readability policies as subsets of editability policies and introduce access control trees to embed these policies in distributing data decryption keys and chameleon hash trapdoors. Moreover, drawing inspiration from ciphertext division mechanisms in proxy re-encryption techniques, BlockENC creates globally unique random values to reconstruct user keys, converting updating all existing keys or ciphertexts when user revocation cases occur into simply invalidating corresponding keys. Security analysis proves that BlockENC is secure against chosen-plaintext attacks. Experiments on the FISCO blockchain platform show that BlockENC achieves around$5\times $computation and$10\times $communication improvement over related works.
Hongchen Guo, Liren Chen, Xuhao Ren, Mingyang Zhao 0002, Chunhai Li, Jingfeng Xue, Liehuang Zhu, Chuan Zhang 0003
IEEE Internet Things J.4
2024 VSpatial: Enabling Private and Verifiable Spatial Keyword-Based Positioning in 6G-Oriented IoT
abstract
For increasing Internet of Things (IoT) devices, 6G wireless technology aims for ubiquitous communications in which positioning services are necessary. Private spatial keyword-based positioning service is promising in 6G-oriented IoT since it positions users based on spatial locations and textual keywords while protecting user privacy. However, due to economic benefits or malicious attacks, positioning service providers may return erroneous or incomplete results, which cause tremendous economic damage and security threats, e.g., always assigning a selective driver for the specific car-hailing user. A technical challenge for extending existing private schemes to enable users to verify the correctness and completeness of positioning results is the distinctive positioning paradigm between compared spatial locations and matched textual keywords. This paper proposes a private and verifiable spatial keyword positioning scheme named VSpatial in 6G-oriented IoT. VSpatial enables users to verify the correctness and completeness of spatial keyword-based positioning results while preserving user privacy. The main inspiration for addressing the technical challenge is converting both spatial locations and textual keywords into an internal status, i.e., adapting comparison and matching to existence judging by multiple cryptographic tools, such as hierarchical cube and pseudorandom function. Based on this inspiration, we design a novel private authenticated data structure (named PVTree), and then propose two constructions of VSpatial, i.e., VSpatial-S and VSpatial-D, to suit static and dynamic environments, respectively. The core idea for adapting VSpatial-S to VSpatial-D is transferring one whole PVTree into multiple exponential-size partitions. Security analysis proves the security and verifiability of VSpatial. Theoretical and experimental evaluations show that VSpatial achieves faster-than-linear positioning efficiency and linear verification overhead.
Weiting Zhang, Mingyang Zhao 0002, Zhuoyu Sun, Chuan Zhang 0003, Jinwen Liang, Liehuang Zhu, Song Guo 0001
IEEE J. Sel. Areas Commun.2
2024 Privacy-Preserving Identity-Based Data Rights Governance for Blockchain-Empowered Human-Centric Metaverse Communications
abstract
Metaverse provides human-centric immersive communication experiences where humans can teleport across different virtual landscapes and build real-time communications via digital identities with others in the same landscape. Despite great benefits, a natural question in human-centric metaverse communications is how to secure digital content among humans. In this regard, blockchain has been widely applied due to its distinct features (e.g., decentralization, transparency, and immutability). Unfortunately, the inherent properties of the blockchain also hinder humans from further deploying preferences to flexibly govern the digital content (i.e., who can read and who can edit), limiting human-centric communication abilities. Some redactable blockchain-based solutions have been proposed, but most of them suffer from the issues of data and preference leakage. To address the issues, we propose a privacy-preserving identity-based data governance (IDRG) scheme for blockchain-empowered human-centric metaverse communications. Combining digital identities, IDRG cryptographically allows humans to govern readability and editability with the right downward compatibility (i.e., humans with editability are endowed with readability) while protecting policy privacy. Specifically, IDRG leverages the polynomial function technique to break through the bottleneck of the traditional identity-based encryption technique (i.e., a policy only contains a user) to achieve a policy for multiple users. Subsequently, the optimized policies are utilized to enrich chameleon hash-based redactable blockchains for comprehensive rights governance. Further, IDRG supports user accountability and revocation by combining the proxy re-encryption technique. Security analysis proves the security of IDRG under the chosen-ciphertext attack. Experiments on the FISCO blockchain platform demonstrate that IDRG requires approximately 0.1 s to process an encryption request, 0.01 s for a reading request, and 1 s for an editing request. Overall, IDRG achieves a$3\times $reduction in computational costs compared with state-of-the-art solutions.
Chuan Zhang 0003, Mingyang Zhao 0002, Weiting Zhang, Jianbing Ni, Liehuang Zhu
IEEE J. Sel. Areas Commun.2
2024 NANO: Cryptographic Enforcement of Readability and Editability Governance in Blockchain Databases
abstract
Recently, increasing personal data has been stored in blockchain databases, ensuring data integrity by consensus. Although transparent and immutable blockchains are mainly adopted, the need to deploy preferences on which users canreadandeditthe data is growing in importance. Based on chameleon hashes, recent blockchains support editability governance but can hardly prevent data breaches because the data is readable to all participants in plaintexts. This motivates us to propose NANO, the first permissioned blockchain database that provides downward compatible readability and editability governance (i.e., users who caneditthe data can alsoreadthe data). Two challenges are protecting policy privacy and efficiently revoking malicious users (e.g., users who abuse their editability privileges). The punchline is leveraging Newton's interpolation formula-based secret sharing to hide policies into polynomial parameters and govern the distribution of data decryption keys and chameleon hash trapdoors. Inspired by proxy re-encryption, NANO integrates unique user symbols into user keys, achieving linear user revocation overhead. Security analysis proves that NANO provides comprehensive privacy preservation under the chosen-ciphertext attack. Experiments on the FISCO blockchain platform demonstrate that compared with state-of-the-art related solutions, NANO achieves a 7× improvement on average regarding computational costs, gas consumption, and communication overhead.
Chuan Zhang 0003, Mingyang Zhao 0002, Jinwen Liang, Liehuang Zhu, Song Guo 0001
IEEE Trans. Dependable Secur. Comput.2
2024 Revocable and Privacy-Preserving Bilateral Access Control for Cloud Data Sharing
abstract
In this paper, we propose a revocable and privacy-preserving bilateral access control scheme (named PriBAC) for general cloud data sharing (i.e., end-cloud-based data sharing). PriBAC ensures that preference matching is successful only when both parties’ preferences are satisfied simultaneously. Otherwise, nothing is leaked beyond whether the preference matching occurs. There are three challenges in designing PriBAC. The first challenge is protecting matching information, i.e., concealing two preference matching processes, in a single cloud server. The second challenge is protecting preference content while preventing receivers from receiving much useless information. The third challenge is how to integrate efficient user revocation mechanisms into bilateral access control to handle frequent user revocation cases in practical cloud data sharing applications. To address the above challenges, the punchline in PriBAC is to leverage Newton’s interpolation formula-based secret sharing to enrich the matchmaking encryption technique for constructing a privacy-preserving preference matching mechanism. To achieve efficient user revocation, we integrate a unique symbol into each user’s keys and efficiently revoke users by invaliding the corresponding keys. Security analysis proves that PriBAC can resist the chosen-ciphertext attack and preserves preference privacy and matching privacy. Experiments show that PriBAC achieves approximately$3\times $user performance improvement compared with current state-of-the-art related schemes.
Mingyang Zhao 0002, Chuan Zhang 0003, Tong Wu 0011, Jianbing Ni, Ximeng Liu, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.1
2023 Fine-Grained Data Rights Governance in Blockchain-Based Cloud-Edge Communications
abstract
Nowadays, cloud-edge communication has emerged as a promising communication paradigm, which leverages edge devices to provide a series of advantages, such as a fast response for end devices. However, considering complicated communication environments, a practical requirement is improving security by constructing decentralized and traceable communications. Currently, blockchains have been widely applied in cloud-edge communications to ensure decentralization and traceability by consensus. Despite these promising benefits, existing transparent and immutable blockchains inevitably introduce two limitations to data rights governance in blockchain-based cloud-edge communications. The first limitation is that transparent blockchains can hardly guarantee data confidentiality since data is accessible to all users, especially unauthorized users. The second limitation is that immutable blockchains can hardly support improper content redaction, which violates the right to be forgotten in GDPR. This paper proposes FDRG, the first fine-grained data rights governance scheme in blockchain-based cloud-edge communications. FDRG cryptographically ensures the right downward compatibility and user collusion resistance. Specifically, based on attributes and policies, FDRG partitions users into three roles (i.e., unauthorized user, readable user, and editable user) and ensures that editable users are compatible with the rights of readable users. The punchline is that FDRG leverages the linear secret sharing matrix-based secret sharing to govern the distribution of data decryption keys and chameleon hashes trapdoors. Formal security analysis proves the security of FDRG under the chosen-plaintext attack in the random oracle model. A full implementation on the FISCO blockchain platform shows that FDRG achieves competitive efficiency compared to state-of-the-art related schemes.
Weilin Gan, Mingyang Zhao 0002, Hongchen Guo, Chuan Zhang 0003, Jianan Hong, Liehuang Zhu
GLOBECOM2
2022 Achieving a Blockchain-based Privacy-preserving Quality-aware Knowledge Marketplace in Crowdsensing
abstract
It is increasingly popular to utilize the wisdom of the crowd for knowledge discovery and monetization. Most of the existing knowledge marketplaces in crowdsensing are implemented by a third-party platform, which may compromise users' rights and be vulnerable to incurring attacks in practice. To eliminate the untrustworthy behaviors of the third party and improve tolerance for the attacks, some blockchain-based knowledge marketplaces in crowdsensing have been proposed. However, the existing blockchain-based knowledge marketplaces fail to simultaneously guarantee privacy (i.e., data privacy and task privacy) and quality awareness. In this paper, we design a blockchain-based privacy-preserving quality-aware knowledge marketplace (PQKM) based on truth discovery, secure K-nearest neighbor computation, matrix decomposition, and data perturbation. PQKM privately calculates users' data quality and automatically rewards users based on their data quality. Detailed security analysis demonstrates that PQKM can preserve data privacy and task privacy during knowledge discovery and monetization. Extensive experiments are conducted on the open real-world dataset to show that PQKM has acceptable efficiency and affordable performance.
Mingyang Zhao 0002, Weiting Zhang, Jinyang Dong, Tong Wu 0011, Chuan Zhang 0003, Liehuang Zhu
EUC2
2022 FRUIT: A Blockchain-Based Efficient and Privacy-Preserving Quality-Aware Incentive Scheme
abstract
Incentive plays an important role in knowledge discovery, as it impels users to provide high-quality knowledge. To promise incentive schemes with transparency, blockchain technology has been widely used in incentive schemes. Currently, privacy, reliability, streamlined processing, and quality awareness are major challenges in designing blockchain-based incentive schemes. In this paper, we design a blockchain-based eFficient and pRivacy-preserving qUality-aware IncenTive scheme called FRUIT. With well-designed smart contracts, FRUIT achieves privacy, reliability, streamlined processing, and quality awareness during the whole procedure. Specifically, we design a novel lightweight encryption method by combining matrix decomposition with proxy re-encryption and a privacy-preserving task allocation based on the polynomial fitting function and hash function. Then, we leverage our proposed lightweight encryption and task allocation to build an efficient and privacy-preserving knowledge discovery protocol in order to securely calculate the data quality and truthful knowledge. To promise user reliability in the incentive scheme, we utilize the Dirichlet distribution to realize the automatic reputation prediction based on the data quality by deploying the reputation management on the blockchain. Moreover, we also deploy the payment management on the blockchain, endowing the incentive scheme to reward participants based on the data quality automatically. Through a detailed security analysis, we demonstrate that data privacy and task privacy are well preserved during the whole process. Theoretical analysis and extensive experiments on real-world datasets demonstrate that FRUIT has acceptable efficiency and affordable performance in terms of computation cost, communication overhead, and gas consumption.
Chuan Zhang 0003, Mingyang Zhao 0002, Liehuang Zhu, Weiting Zhang, Tong Wu 0011, Jianbing Ni
IEEE J. Sel. Areas Commun.2
2022 Enabling Efficient and Strong Privacy-Preserving Truth Discovery in Mobile Crowdsensing
abstract
Mobile crowdsensing has emerged as a popular platform to solve many challenging problems by utilizing users’ wisdom and resources. Due to user diversity, the data provided by different individuals may vary significantly, and thus it is important to analyze data quality during data aggregation. Truth discovery is effective in capturing data quality and obtaining accurate mobile crowdsensing results. Existing works on truth discovery either cannot protect both task privacy and data privacy, or introduce tremendous computational costs. In this paper, we propose an efficient and strong privacy-preserving truth discovery scheme, named EPTD, to protect users’ task privacy and data privacy simultaneously in the truth discovery procedure. In EPTD, we first exploit the randomizable matrix to express users’ tasks and sensory data. Then, based on the matrix computation properties, we design key derivation and (re-)encryption mechanisms to enable truth discovery to be performed in an efficient and privacy-preserving manner. Through a detailed security analysis, we demonstrate that data privacy and task privacy are well preserved. Extensive experiments based on real-world and simulated mobile crowdsensing applications show EPTD has practical efficiency in terms of computational cost and communication overhead.
Chuan Zhang 0003, Mingyang Zhao 0002, Liehuang Zhu, Tong Wu 0011, Ximeng Liu
IEEE Trans. Inf. Forensics Secur.2