EDBT 2026 Demo / reviewers in the wild / expert
Xuefeng Liu 0002
dblp:96/600-2
· DBLP profile ↗
24ranked-venue papers
6as first author
5since 2021 · last 2025
0000-0002-7343-6302ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 2 first-author · 3 since 2021Computer networks · 8 · 1 first-author · 1 since 2021Systems, architecture and hardware · 3 · 1 first-authorSoftware engineering, systems software and programming languages · 3 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | DP-DID: A Dynamic and Proactive Decentralized Identity SystemabstractDecentralized identity (DID) is a transformative paradigm that leverages blockchain, decentralized identifiers and verifiable credentials (VCs) to enable self-sovereign and decentralized identity management with myriad application areas. However, existing DID implementations are confronted with two key challenges: insufficient decentralization and vulnerability to mobile adversary attacks. First, they paradoxically introduce central identity resolvers, intermediaries or static committees to manage critical identity services, key management or credential issuance, which violates the decentralized controlling aim against a single point of failure. Second, these systems are vulnerable to mobile adversaries who can gradually compromise multiple nodes or committee members over a long period, eventually seizing control of the system. In this paper, we propose DP-DID, the first dynamic and proactive decentralized identity system specifically designed to resist mobile adversary attacks in dynamic committee settings. To eliminate centralized authorities, DP-DID leverages blockchain, dynamic committees and BLS1signatures, which achieves decentralization. In addition, we design a dynamic and batch proactive secret sharing (DBPSS) scheme for DP-DID to ensure proactive security against mobile adversary attacks. This is achieved by allowing at mostt(threshold) committees to be corrupted per period, with the set of corrupted committees changing dynamically even if all players are eventually compromised. By incorporating DBPSS, DP-DID achieves efficient key management for multiple users in dynamic settings, enhancing overall system scalability. Through rigorous analysis, DP-DID is proven to be forward secure and secure against mobile adversary attacks under a widely adopted malicious model. Extensive experiments show that DP-DID has efficient performance, and our DBPSS scheme outperforms FaB-DPSS by over 11.67× in key handover efficiency. Yang Xiao 0014, Qian Chen 0032, Yong Zhi Lim, Xuefeng Liu 0002, Qingqi Pei, Jianying Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | PrivGrid: Privacy-Preserving Individual Load Forecasting Service for Smart GridabstractSmart meter-based individual load forecasts are more and more widely deployed to serve smart grid and home energy management. Customary load forecasting systems collect a massive amount of fine-grained electrical data from people’s smart meters in plaintext, inevitably raising privacy concerns and even anti-smart-meter initiatives. Current privacy solutions either compromise accuracy and efficacy or require the redeployment of trusted infrastructure. In this paper, we present PrivGrid, the first systematic solution for smart grids that collects, clusters, trains, and forecasts customers’ load data in a privacy-preserving way. Moreover, we highlight the technical contribution of our building block: a novel and fast arithmetic multiplication triple via secure inner product protocol outperforms the existing methods and may be included in other privacy computing modules. Then, we develop efficient secure protocols to enable the arithmetic operations of individual load forecasting in a server-aided model and utilize the best alternatives to nonlinear functions. Besides, aggregating all of our individual forecasts can produce a more accurate estimate of the system-level load than the typical aggregate technique. We rigorously prove that the servers cannot obtain the user’s historical load data and short-term load forecast values while providing services. PrivGrid is also tested on real residential smart meter data to show its efficiency, and the relevant code has been made available to the community for further research. Jing Lei 0007, Le Wang 0010, Qingqi Pei, Wenhai Sun, Xiaodong Lin 0001, Xuefeng Liu 0002 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | Confidential Distributed Ledgers for Online Syndicated LendingabstractOnline syndicated lending offers quick and convenient financing support to individuals, while diversifying risks by pooling funds from multiple lenders into loan projects. It has experienced explosive growth, reaching a multibillion-dollar market. Establishing transparency is essential for constructing a trusted, fair, and regulation-compliant financial collaboration model. Meanwhile, confidentiality must be maintained to protect the sensitive financial information of individual lenders. Multi-party computation (MPC) can protect the input privacy of lenders, but it cannot safeguard the sensitive information revealed by the fund flow itself. To address these challenges, we propose a new collaborative financial ledger for online syndicated lending. It leverages homomorphic encryption/commitment to enable the reuse of intermediary states without compromising privacy throughout the entire lifecycle of a loan. This system also supports efficient regulation-compliant auditing. We streamline the framework design to optimize performance and develop a prototype system. Even with a large syndicate of 100 lenders, the system still achieves low-latency performance. Xuefeng Liu 0002, Le Wang 0010, Wenhai Sun, Qingqi Pei, Xiaodong Lin 0001, Huizhong Li |
IEEE Trans. Serv. Comput. | 1 |
| 2023 | Lightweight Federated Learning for Large-Scale IoT Devices With Privacy GuaranteeabstractWith the massive deployment of the Internet of Things (IoT) devices, many data analysis applications emerge for the large amount of data accumulated by IoT. Federated learning (FedL) on IoT devices is an appealing mode to train a precise data analysis model. However, existing FedL schemes either take expensive computation costs (e.g., public-key cryptographic operations) or a large number of interactions among participants. Obviously, these schemes are unsuitable for IoT devices due to the limited computational and communication resources. In this work, we propose a lightweight privacy-preserving FedL scheme for IoT devices. To protect the privacy of individual local data, we add masks to intervening parameters. An effective secret-sharing scheme is adopted to ensure that masks can be eliminated accurately. Considering that FedL involves multiple iterations and mask generation for each iteration costs a large number of interactions among users for privacy guarantee, we also design a secure mask reusing mechanism for large-scale FedL tasks. We prove that our scheme is secure against the honest-but-curious model. In addition, we also expand our scheme to deal with the collusion attack. Extensive experiments on real IoT devices demonstrate the accuracy and efficiency of our work. Zhaohui Wei, Qingqi Pei, Ning Zhang 0007, Xuefeng Liu 0002, Celimuge Wu, Amirhosein Taherkordi |
IEEE Internet Things J. | 4 |
| 2022 | PrivFace: Fast Privacy-Preserving Face Authentication With Revocable and Reusable Biometric CredentialsabstractPrivacy concerns of using sensitive biometric data as credentials arise with the wide adoption of user-friendly face authentication. To protect the facial features of users, two important functions, i.e.,revocabilityandreusability, are anticipated to be realized in a privacy-preserving face authentication design. Revocability requires an effective approach to deregister or replace user credentials when the authentication server is compromised; For reusability, the same credentials should appear independently to non-cooperating applications. Accomplishing these two properties is challenging as the uniqueness of facial features. In this article, we presentPrivFace, a fast privacy-preserving face authentication, supporting revocable, and reusable biometric credentials. The core innovation is a novel secure inner product protocol that employs a lightweight random masking technique instead of time-consuming public-key cryptographic operations to efficiently measure facial data similarity. We rigorously analyze the security to show that the server cannot acquire the user's sensitive biological features during the authentication. Our experiment with real-world datasets shows thatPrivFaceis friendly to edge smart devices, which takes less than$100 ms$per successful authentication on a common smartphone and outperforms the prior art J. Lei, Q. Peiet al.[1]. by$20 \times$. We have made the relevant codes open-source to the community for further research. Jing Lei 0007, Qingqi Pei, Wenhai Sun, Xuefeng Liu 0002 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2020 | Efficient distributed privacy-preserving collaborative outlier detection
Zhaohui Wei, Qingqi Pei, Xuefeng Liu 0002, Lichuan Ma |
Peer-to-Peer Netw. Appl. | 3 |
| 2019 | DAPS: A Decentralized Anonymous Payment Scheme with Supervision
Qingqi Pei, Xuefeng Liu 0002, Lichuan Ma, Huizhong Li, Shui Yu 0001 |
ICA3PP (2) | 3 |
| 2019 | Privacy-Preserving Reputation Management for Edge Computing Enhanced Mobile CrowdsensingabstractMobile crowdsensing (MCS) has gained popularity for its potential to leverage individual mobile devices to sense, collect, and analyze data instead of deploying sensors. As the sensing data become increasingly fine-grained and complicated, there is a tendency to enhance MCS with the edge computing paradigm to reduce time delays and high bandwidth costs. The sensing data may reveal personal information, and thus it is of great significance to preserve the privacy of the participants. However, preserving privacy may hinder the process of handling malicious participants. In this paper, we propose two privacy preserving reputation management schemes for edge computing enhanced MCS to simultaneously preserve privacy and deal with malicious participants. In the basic scheme, a novel reputation value updating method is designed based on the deviations of the encrypted sensing data from the final aggregating result. The basic scheme is efficient at the expense of revealing the deviation value of each participant to the reputation manager. To conquer this drawback, we propose an advanced scheme by updating the reputation values utilizing the rank of deviations. Extensive experiments demonstrate that both these two schemes have high cost efficiency and are effective to deal with malicious participants. Lichuan Ma, Xuefeng Liu 0002, Qingqi Pei, Yong Xiang 0001 |
IEEE Trans. Serv. Comput. | 2 |
| 2018 | A Practical Privacy-Preserving Face Authentication Scheme with Revocability and Reusability
Jing Lei 0007, Qingqi Pei, Xuefeng Liu 0002, Wenhai Sun |
ICA3PP (4) | 3 |
| 2018 | Several classes of negabent functions over finite fields
Gaofei Wu, Nian Li 0005, Yuqing Zhang 0001, Xuefeng Liu 0002 |
Sci. China Inf. Sci. | 4 |
| 2018 | EGHR: Efficient group-based handover authentication protocols for mMTC in 5G wireless networks
Jin Cao 0001, Maode Ma, Hui Li 0006, Xuefeng Liu 0002 |
J. Netw. Comput. Appl. | 5 |
| 2017 | One-tag checker: Message-locked integrity auditing on encrypted cloud deduplication storageabstractIn this paper, we investigate the problem of integrity auditing for cloud deduplication storage. Specifically, in addition to the outsourced data confidentiality, we also aim to ensure the integrity of the deduplicated cloud storage. With the existing works based on Provable Data Possession (PDP)/Proof of Retrievability (PoR), we are either required to rely on a fully trusted proxy server or inevitably sacrifice the privacy and efficiency. In contrast, we present a novel message-locked integrity auditing scheme without an additional proxy server, which is applicable to both file-level and chunk-level deduplication systems. In particular, our scheme is storage efficient in the sense that apart from eliminating the ciphertext redundancy, we also enable the integrity tag deduplication by a message-derived signing key, which merely incurs minimal client-side computation overhead. Besides, we can still publicly perform the integrity check over any client's cloud storage by incorporating the proxy re-signature technique. We show that the proposed scheme will not disclose the data ownership information and is provably secure under the Computational Diffie-Hellman (CDH) assumption in the random oracle model. Finally, the performance evaluation demonstrates its effectiveness and efficiency. Xuefeng Liu 0002, Wenhai Sun, Wenjing Lou, Qingqi Pei, Yuqing Zhang 0001 |
INFOCOM | 1 |
| 2017 | Publicly Verifiable Inner Product Evaluation over Outsourced Data Streams under Multiple KeysabstractUploading data streams to a resource-rich cloud server for inner product evaluation, an essential building block in many popular stream applications (e.g., statistical monitoring), is appealing to many companies and individuals. On the other hand, verifying the result of the remote computation plays a crucial role in addressing the issue of trust. Since the outsourced data collection likely comes from multiple data sources, it is desired for the system to be able to pinpoint the originator of errors by allotting each data source a unique secret key, which requires the inner product verification to be performed under any two parties' different keys. However, the present solutions either depend on a single key assumption or powerful yet practically-inefficient fully homomorphic cryptosystems. In this paper, we focus on the more challenging multi-key scenario where data streams are uploaded by multiple data sources with distinct keys. We first present a novel homomorphic verifiable tag technique to publicly verify the outsourced inner product computation on the dynamic data streams, and then extend it to support the verification of matrix product computation. We prove the security of our scheme in the random oracle model. Moreover, the experimental result also shows the practicability of our design. Xuefeng Liu 0002, Wenhai Sun, Hanyu Quan, Wenjing Lou, Yuqing Zhang 0001, Hui Li 0006 |
IEEE Trans. Serv. Comput. | 1 |
| 2015 | Catch you if you lie to me: Efficient verifiable conjunctive keyword search over large dynamic encrypted cloud dataabstractEncrypted data search allows cloud to offer fundamental information retrieval service to its users in a privacy-preserving way. In most existing schemes, search result is returned by a semi-trusted server and usually considered authentic. However, in practice, the server may malfunction or even be malicious itself. Therefore, users need a result verification mechanism to detect the potential misbehavior in this computation outsourcing model and rebuild their confidence in the whole search process. On the other hand, cloud typically hosts large outsourced data of users in its storage. The verification cost should be efficient enough for practical use, i.e., it only depends on the corresponding search operation, regardless of the file collection size. In this paper, we are among the first to investigate the efficient search result verification problem and propose an encrypted data search scheme that enables users to conduct secure conjunctive keyword search, update the outsourced file collection and verify the authenticity of the search result efficiently. The proposed verification mechanism is efficient and flexible, which can be either delegated to a public trusted authority (TA) or be executed privately by data users. We formally prove the universally composable (UC) security of our scheme. Experimental result shows its practical efficiency even with a large dataset. Wenhai Sun, Xuefeng Liu 0002, Wenjing Lou, Y. Thomas Hou 0001, Hui Li 0006 |
INFOCOM | 2 |
| 2015 | A privacy preserving authentication scheme for roaming services in global mobility networksabstractAbstract To provide secure roaming services for mobile users in Global Mobility Networks, many schemes have been proposed in recent years. However, most of them focus only on authentication and fail to satisfy many practical security requirements such as user anonymity and untraceability. To address this problem, we propose a privacy‐preserving authentication scheme based on elliptic curve cryptography. The proposed scheme is provably secure under a formal model that satisfies all practical security requirements. Compared with existing authentication schemes, ours enjoys better performance in terms of computation cost and security. Copyright © 2015 John Wiley & Sons, Ltd. Dan Fan, Yuqing Zhang 0001, Xiaowei Li 0001, Xuefeng Liu 0002 |
Secur. Commun. Networks | 5 |
| 2014 | An anonymous data aggregation scheme for smart grid systemsabstractABSTRACT By integrating the traditional grid with the advanced communication and information technologies, smart grid can provide a reliable and efficient energy service for our modern society. Data aggregation plays an important role in evaluating the current energy usage information of consumer domains, based on which the operation center can accommodate distributed power sources to maximize the utilization efficiency. However, it also incurs a potential risk to the consumer privacy. In this paper, we propose an anonymous multi‐dimensional data aggregation for smart grid systems. With the proposed scheme, the operation center can compute both additive and non‐additive aggregation functions over the collected reports from consumers. The computation cost of each consumer is independent of the number of collected data types. In addition, by using the batch verification technique, the operation center's computation cost can be significantly reduced. The security analysis demonstrates that the proposed scheme can achieve identity privacy preserving, data authentication, and confidentiality. Copyright © 2013 John Wiley & Sons, Ltd. Xuefeng Liu 0002, Yuqing Zhang 0001, Boyang Wang 0001, Huaqun Wang |
Secur. Commun. Networks | 1 |
| 2014 | Preserving identity privacy on multi-owner cloud data during public verificationabstractABSTRACT The low prices on cloud data storage and sharing services incentive users to outsource their data to the cloud. Because data stored in the cloud may be lost or corrupted, users are suggested to verify data integrity before the utilization of cloud data. A series of schemes have been proposed to enable a public verifier to efficiently check the correctness of cloud data without downloading the whole data from the cloud server. Unfortunately, few of them have considered about public verification onmulti‐ownercloud data while still preserving identity privacy of owners from public verifiers, where each block in these cloud data should be signed by multiple owners. In this paper, we design a novel public verification scheme to audit the integrity of multi‐owner data stored in the cloud. With our scheme, a public verifier is able to efficiently check the integrity of multi‐owner data with a very small communication cost compared with the size of the entire data. Meanwhile, the private identities of these owners are protected and not revealed to any public verifier. In addition, our scheme can also efficiently support group dynamics for multiple owners and enable batch verification. Security analyses and experimental results indicate our scheme is correct, secure and efficient. Copyright © 2013 John Wiley & Sons, Ltd. Boyang Wang 0001, Hui Li 0006, Xuefeng Liu 0002, Xiaoqing Li 0001, Fenghua Li 0001 |
Secur. Commun. Networks | 3 |
| 2014 | Using fuzzy comprehensive evaluation method to establish a credible spectrum sensing and allocation modelabstractABSTRACT This study focuses on the false feedback of spectrum information and the malicious behavior that forcibly occupies spectrum resources in cognitive radio networks. A credible spectrum sensing and allocation model based on fuzzy theory is proposed. The spectrum sensing behavior and spectrum utilization behavior are taken as two evaluation factors. On the basis of subjectivity and uncertainty of trust, this study adopts the fuzzy comprehensive evaluation method to construct the trust evaluation of nodes. In cooperative spectrum sensing, comprehensive evaluation results can be used to identify malicious nodes and eliminate false feedback information. In spectrum allocation, the degree of lattice closeness among fuzzy sets is used to define and calculate the difference between the actual comprehensive evaluation set and the ideal comprehensive evaluation. The difference is calculated to quantify the credibility of non‐malicious nodes and to determine the allocation of spectrum resources to nodes using the multi‐objective optimization algorithm. These techniques can control the malicious behaviors of nodes and encourage cooperative behavior among nodes. Consequently, the joint design of spectrum sensing at the physical layer and spectrum allocation at the media access control layer is realized. Simulation results and analysis indicate that under malicious attacks, the proposed model has sound performance in terms of system sensing, throughput, and fair spectrum allocation compared with existing models. Copyright © 2013 John Wiley & Sons, Ltd. Yuqing Zhang 0001, Xuefeng Liu 0002 |
Secur. Commun. Networks | 3 |
| 2013 | A new framework against privilege escalation attacks on androidabstractThe Android provides a permission-based security model to restrict the operations that each application can perform; however, it has been shown to be vulnerable to privilege escalation attacks. Applications can cooperate to perform operations that forbidden to perform separately which may lead to privacy leakage. In this poster, we present the design of a new policy-centered security framework against the application-level privilege escalation attacks. Different from previous policy-centered schemes, the communication content is also considered into the inspection besides the permissions. Specially, we allow the privacy information selectively to be passed in the middleware and deploy a mandatory access control at the kernel based on the dynamical taint tracking. Test results show that it can prevent known confused deputy attacks and is also flexible to prevent the unknowns; furthermore it can reduce the false positives of preventing colluding attacks compared to the previous work. Wenming Zhou, Yuqing Zhang 0001, Xuefeng Liu 0002 |
CCS | 3 |
| 2013 | A privacy-preserving acceleration authentication protocol for mobile pay-TV systemsabstractABSTRACT It is highly probable that many requests for the same service (popular/hot videos) arrive at the service provider in a short time or even simultaneously in a pay‐TV system. In conventional schemes, for nonrepudiation of communication, the service provider verifies each service request signed by subscribers one by one, which results in a high computation burden and long delay. In this paper, we propose an efficient privacy‐preserving authentication mechanism for mobile pay‐TV systems. The mechanism adopts batch verification technique, allowing the service provider to verify multiple requests from different subscribers in a batch manner instead of one by one. In addition, a hand‐off authentication mechanism with privacy preserving based on proxy signature cryptography is also proposed to support mobile pay‐TV systems. With the proxy signature technique, the communication is only between a subscriber and a new transmitter while the head end system is no longer involved during hand‐off. Simulation results show that even in the case of high bogus request ratio (p = 25 %), batch verification still excels individual verification in performance. Moreover, the proposed protocol only requires point multiplication operations on subscribers. Therefore, this scheme enjoys computation and communication efficiency compared with the existing schemes. Copyright © 2012 John Wiley & Sons, Ltd. Xuefeng Liu 0002, Yuqing Zhang 0001 |
Secur. Commun. Networks | 1 |
| 2013 | Mona: Secure Multi-Owner Data Sharing for Dynamic Groups in the CloudabstractWith the character of low maintenance, cloud computing provides an economical and efficient solution for sharing group resource among cloud users. Unfortunately, sharing data in a multi-owner manner while preserving data and identity privacy from an untrusted cloud is still a challenging issue, due to the frequent change of the membership. In this paper, we propose a secure multi-owner data sharing scheme, named Mona, for dynamic groups in the cloud. By leveraging group signature and dynamic broadcast encryption techniques, any cloud user can anonymously share data with others. Meanwhile, the storage overhead and encryption computation cost of our scheme are independent with the number of revoked users. In addition, we analyze the security of our scheme with rigorous proofs, and demonstrate the efficiency of our scheme in experiments. Xuefeng Liu 0002, Yuqing Zhang 0001, Boyang Wang 0001, Jingbo Yan |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2012 | A lightweight roaming authentication protocol for anonymous wireless communicationabstractIn wireless network, a secure roaming authentication protocol enables a mobile user to get services from a foreign server when he/she is outside of the home server. However, the conventional approach requires the home server's participation during the authentication between the mobile user and the foreign server. So the larger number of the roaming requests are performed the heavier burden will be on the home server. Meanwhile, in wireless communication the privacy protection is also of great concern for the mobile user. In this paper we propose a lightweight roaming authentication protocol for anonymous wireless communication without the home server's participation. The new roaming authentication protocol takes advantage of the ID-based cryptography and provides user anonymity. It has good performance compared with the roaming authentication protocols whose authentication do not need the home server's participation in terms of security and computation costs. Moreover, it can be applied to various kinds of wireless networks such as Cellular Networks and Wireless Mesh Networks. Xiaowei Li 0001, Yuqing Zhang 0001, Xuefeng Liu 0002, Jin Cao 0001 |
GLOBECOM | 3 |
| 2012 | An efficient handover authentication scheme with location privacy preserving for EAP-based wireless networksabstractIn this paper, we propose a handover authentication scheme with location privacy preserving based on the proxy ring signature scheme for EAP-based wireless networks. First, we integrate an efficient ring signature and a proxy signature into a proxy ring signature scheme, which allows the mobile node (MN) to be authenticated without revealing its identity and location privacies due to the inherent anonymity of the proxy ring signature. Second, our scheme only requires point multiplication operations on the resource-constraints MN, thus, it is suitable for low-power mobile devices in the wireless networks. Finally, an extensive simulation is given to validate the performance of the proposed scheme. The results demonstrate that our scheme is relatively efficient in terms of computation and communication overhead. Yuqing Zhang 0001, Xuefeng Liu 0002, Anmin Fu |
ICC | 3 |
| 2011 | A Privacy Preserving Handover Authentication Scheme for EAP-Based Wireless NetworksabstractExtensible Authentication Protocol (EAP) is a framework which aims to provide a flexible authentication for wireless networks. Due to the involvement of an EAP server and several round trips between a mobile node (MN) and the EAP server, a full EAP authentication takes about 1000ms which is unacceptable in a handover process. This paper proposes a privacy preserving handover authentication scheme for EAP-based wireless networks. We use the proxy signature scheme to accomplish authentication between MN and an access point (AP) without involving the third party. The detailed security analysis shows that our scheme can achieve the privacy preserving and forward/backward security. In addition, we evaluate the latency performance of the proposed scheme by the analysis and simulation. The results demonstrate that our scheme is more efficient in terms of computation and communication overheads. Yuqing Zhang 0001, Anmin Fu, Xuefeng Liu 0002 |
GLOBECOM | 4 |