Haibo Cheng
Haibo Cheng
Home
Publications
Contact
Light
Dark
Automatic
CCF-A
Decomposition-Based Optimal Bounds for Privacy Amplification via Shuffling
We unify decomposition-based shuffle-privacy analyses, identify the optimal decomposition, and compute tight amplification bounds efficiently with FFT.
Pengcheng Su
,
Haibo Cheng
,
Ping Wang
PDF
Cite
DOI
IEEE S&P 2026 program
arXiv
User-Autonomous Multi-Factor Authentication Supporting Arbitrary Factor Configurations
AS-MFA supports user-configured, arbitrary combinations of passwords, biometrics, and devices through general access structures.
Wenting Li
,
Haibo Cheng
,
Kaitai Liang
Cite
DOI
Open-access record
Practically Secure Honey Password Vaults: New Design and New Evaluation against Online Guessing
We build a large-scale honey-vault dataset, develop stronger attacks and a Transformer-based decoy model, and evaluate practical security against online guessing.
Haibo Cheng
,
Fugeng Huang
,
Jiahong Yang
,
Wenting Li
,
Ping Wang
PDF
Cite
USENIX page
Artifact
Incrementally Updateable Honey Password Vaults
For HE-based honey vault schemes, we 1) propose a new generic construction and an incremental update mechanism, which resists intersection attacks; 2) formally investigate the optimal strategy for online verifications and further propose several practical attacks, which can effectively distinguish real and decoy vaults for the existing honey vault schemes; 3) instantiate our construction with a well-designed multi-similar-password model, which can generate more plausible-looking decoys.
Haibo Cheng
,
Wenting Li
,
Ping Wang
,
Chao-Hsien Chu
,
Kaitai Liang
Cite
Slides
Video
PDF: Full version
PDF: Conference version
Practical Threshold Multi-Factor Authentication
Multi-factor authentication (MFA) has been widely used to safeguard high-value assets. Unlike single-factor authentication (e.g., …
Wenting Li
,
Haibo Cheng
,
Ping Wang
,
Kaitai Liang
PDF
Cite
Probability Model Transforming Encoders Against Encoding Attacks
For existing honey encryption applications, we propose two types of attacks, encoding attacks and distribution difference attacks, and further show the insecurity of the applications. We propose a generic method to transform an arbitrary probability model to a probability model transforming encoder, which resists encoding attacks.
Haibo Cheng
,
Zhixiong Zheng
,
Wenting Li
,
Ping Wang
,
Chao-Hsien Chu
PDF
Cite
Slides
Video
Zipf’s Law in Passwords
Despite three decades of intensive research efforts, it remains an open question as to what is the underlying distribution of …
Ding Wang
,
Haibo Cheng
,
Ping Wang
,
Xinyi Huang
,
Gaopeng Jian
PDF
Cite
Cite
×