VLDB 2026 Research / reviewers in the wild / expert
Wei Yang 0008
dblp:03/1094-8
· DBLP profile ↗
16ranked-venue papers
5as first author
7since 2021 · last 2025
0000-0003-2923-1219ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 1 first-author · 1 since 2021Security and privacy · 5 · 2 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Just a little human intelligence feedback! Unsupervised learning assisted supervised learning data poisoning based backdoor removal
Huaibing Peng, Anmin Fu, Wei Yang 0008, Lihui Pang, Said F. Al-Sarawi, Derek Abbott, Yansong Gao 0001 |
Comput. Commun. | 4 |
| 2024 | Multi-Channel Leakage Detection Based on χ2 Test of IndependenceabstractSide-channel analysis (SCA) is a critical tool for evaluating the security of cryptographic devices, as physical leakage can reveal sensitive information such as cryptographic keys. Multi-channel fusion attacks (MCFAs) have proven to be efficient in exploiting side-channel leakages. However, a crucial step before performing MCFA is to assess whether the leakages from different channels can be effectively fused. To address this, we propose a black-box approach based on the χ2test of independence to assess multi-channel leakage suitability for fusion. By treating the leakages as categorical variables, our method evaluates their association without requiring knowledge of the cryptographic key or device implementation. Xiaoyong Kou, Wei Yang 0008, Peijin Cong, Gongxuan Zhang |
TrustCom | 2 |
| 2024 | Towards robustness evaluation of backdoor defense on quantized deep learning modelsabstractBackdoor attacks on deep learning (DL) models emerge as the most worrisome security threats to their secure and safe usage, especially for security-sensitive tasks. Great efforts have been devoted to thwarting backdoor attacks by devising detection or prevention countermeasures. By default, these countermeasures are designed and evaluated on models with full-precision parameters (e.g., floating32). It is unclear whether they are immediately applicable to mitigate backdoor attacks in the quantized model that are being pervasively deployed on mobile devices and Internet of Things (IoT) devices to save resources (i.e. power and memory) and reduce latency and privacy risks. This work, for the first time, initializes the critical examination of the robustness or applicability of existing state-of-the-art (SOTA) DL backdoor defenses for detecting or preventing backdoor attacks on quantized models. Based on extensive evaluations of four representative defenses (Neural Cleanse, ABS, Fine-Pruning and Trojan Signature) with three datasets (CIFAR10, GTSRB, and STL10), we found that only Neural Cleanse's defensive robustness is generally independent of model quantization, while all others exhibit degraded effectiveness or failures against quantized models (in particular, widely used int-8 and 1-bit models), especially when the model is quantized to be 1-bit. The identified main failure reason is that these defenses are based on examining the weight values of the model or the activation values of the neuron to identify or prevent the backdoor, often using the ranking as a step. Quantization with a small bit width leads to less fine-grained discrete values (e.g., 1-bit quantization only possesses two value elements of -1 and +1), rendering ranking effectiveness deteriorate in this case. Note that the quantization not only applies to the weight but also to activation, thus making these defenses less robust or trivially fail. This work highlights the demand for devising backdoor defenses that are generic to different quantization formats on top of the default full-precision model. Huaibing Peng, Anmin Fu, Wei Yang 0008, Said F. Al-Sarawi, Derek Abbott, Yansong Gao 0001 |
Expert Syst. Appl. | 4 |
| 2023 | Template Attack Assisted Linear Cryptanalysis on Outer Rounds Protected DES ImplementationsabstractAbstract In practice, when the security of a block cipher implementation is considered, the leakages related to the outer rounds encryptions can be used by side channel attacks (SCA) to recover the secret key. Therefore, the outer rounds of block cipher implementations should be protected. However, in order to lower the implementation price, the inner rounds of block cipher implementations may be unprotected. In light of this, the security of an outer rounds protected DES implementation is considered. In detail, template attack (TA), which is information theoretically the strongest SCA style, can be used to obtain the inner round output. Then, linear cryptanalysis (LC) can be used to recover the secret key. Finally, the optimal key enumeration algorithm can be used to optimize the efficiency of TA assisted LC. We evaluate the efficiency of TA assisted LC in simulated scenarios where a three outer rounds protected DES implementation is targeted. The evaluation results show that when 800 correct samples are available and the number of key enumeration is $2^{10}$, the efficiency of TA assisted LC can reach 83% of success rate. Overall, an efficient combination attack style that can be used to accurately evaluate the security of an outer rounds protected DES implementation is proposed. Hailong Zhang 0001, Wei Yang 0008 |
Comput. J. | 2 |
| 2023 | MLMSA: Multilabel Multiside-Channel-Information Enabled Deep Learning Attacks on APUF VariantsabstractTo improve the modeling resilience of silicon strong physical unclonable functions (PUFs), in particular, the APUFs that yield a very large number of challenge-response pairs (CRPs), a number of composited APUF variants, such as XOR-APUF, interpose-PUF (iPUF), feed-forward APUF (FF-APUF), and OAX-APUF, have been devised. When examining their security in terms of modeling resilience, utilizing multiple information sources, such as power side channel information (SCI) or/and reliability SCI, given a challenge is under-explored, which poses a challenge to their supposed modeling resilience in practice. Building upon multilabel/head deep learning (DL) model architecture, this work proposes multilabel multiside-channel-information-enabled DL attacks (MLMSAs) to thoroughly evaluate the modeling resilience of aforementioned APUF variants. Despite its simplicity, MLMSA can successfully break large-scaled APUF variants, which has not previously been achieved. More precisely, the MLMSA breaks 128-stage 30-XOR-APUF, (9, 9)- and (2, 18)-iPUFs, and$(2,2,30)$-OAX-APUF when CRPs, power SCI, and reliability SCI are concurrently used. It breaks 128-stage 12-XOR-APUF and$(2,2,9)$-OAX-APUF even when only the easy-to-obtain reliability SCI and CRPs are exploited. The 128-stage six-loop FF-APUF and one-loop 20-XOR-FF-APUF can be broken by simultaneously using reliability SCI and CRPs. All these attacks are normally completed within an hour with a standard personal computer. Therefore, MLMSA is a useful technique for evaluating other existing or any emerging strong PUF designs. Yansong Gao 0001, Jianrong Yao, Lihui Pang, Wei Yang 0008, Anmin Fu, Said F. Al-Sarawi, Derek Abbott |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2022 | TREVERSE: TRial-and-Error Lightweight Secure ReVERSE Authentication With Simulatable PUFsabstractA physical unclonable function (PUF) generates hardware intrinsic volatile secrets by exploiting uncontrollable manufacturing randomness. Although PUFs provide the potential for lightweight and secure authentication for increasing numbers of low-end Internet of Things devices, practical and secure mechanisms remain elusive. We aim to explore simulatable PUFs (SimPUFs) that are physically unclonable but efficiently modeled mathematically through privileged one-time PUF access to address the above problem. Given a challenge, a securely stored SimPUF in possession of a trusted server computes the corresponding response and its bit-specific reliability. Consequently, naturally noisy PUF responses generated by a resource limited prover can be immediately processed by a one-way function (OWF) and transmitted to the server, because the resourceful server can exploit the SimPUF to perform a trial-and-error search over likely error patterns to recover the noisy response to authenticate the prover. Security of trial-and-error reverse (TREVERSE) authentication under the random oracle model is guaranteed by the hardness of inverting the OWF. We formally evaluate the TREVERSE authentication capability with two SimPUFs experimentally derived from popular silicon PUFs. Yansong Gao 0001, Marten van Dijk, Lei Xu 0015, Wei Yang 0008, Surya Nepal, Damith Chinthana Ranasinghe |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | Theoretical Estimation on the Success Rate of the Asymptotic Higher Order Optimal DistinguisherabstractAbstract Since its first publication at ASIACRYPT 2014, higher order optimal distinguisher (HOOD) has been the most efficient style of higher order side channel attacks that can be used to evaluate the physical security of a masking device. In practice, the efficiency of HOOD can be empirically evaluated with the success rate (SR) metric. In the empirical evaluation, a large number of power traces are needed, and HOOD should be repeated thousands of times under the values of different parameters, which can make the evaluation process cumbersome and the evaluation price high. In light of this, the exact relationship between the SR of the asymptotic HOOD and the values of different parameters is theoretically built, and the soundness of the theoretical analysis is empirically verified in both the simulated scenario and the real scenario. Then, by setting the values of different parameters, the SR of the asymptotic HOOD can be theoretically estimated. Here, as the signal-to-noise ratio of a masking device approaches to zero, the SR of the asymptotic HOOD approaches to the SR of HOOD. Overall, this contribution may help evaluators to efficiently evaluate the physical security of a masking device with HOOD. Hailong Zhang 0001, Wei Yang 0008 |
Comput. J. | 2 |
| 2020 | Side-Channel Leakage Detection Based on Constant Parameter Channel ModelabstractSide-channel analysis (SCA) becomes a serious realistic threat to crypto devices, it is thus imperative to evaluate the resistance of a device to SCA. Side-channel leakage detection aiming to identify the leakage points potentially revealing secrets in side channel signals, is considered as a preliminary step before further security assessment. This work proposes a novel black-box leakage detection approach, which views the side channel as a constant parameter communication channel when it outputs leakage points. The approach distinguishes leakage points by utilizing the kurtosis-based consistency check for channel parameter estimators. To examine the efficiency of this approach, false negative and false positive rates were first quantitatively analyzed by comprehensive experiments. Considering the fact that side-channel leakage can be from multiple channels in practice, we further investigated the applicability of the proposed approach to multi-channel leakage detection. Interestingly, equipped with the proposed detection approach, we correspondingly devised a novel side-channel attack exploiting a kurtosis-based distinguisher. Overall, extensive experiments have validated the efficiencies of our proposed leakage detection method and the novel SCA attack. Wei Yang 0008, Hailong Zhang 0001, Yansong Gao 0001, Anmin Fu, Songjie Wei |
ICCD | 1 |
| 2020 | Improving Efficiency of Key Enumeration Based on Side-Channel AnalysisabstractSide-channel analysis (SCA) is usually used for analyzing the side-channel resistance of a crypto device. However, it does not mean “practical secure” when a SCA attack fails since SCA only provides a success or failure conclusion. On the basis of the SCA data about scores and ranks of all candidates for each subkey, it is still possible to apply key enumeration (KE) algorithms to search the correct master key at an affordable overhead. Nevertheless, the efficiency of KE is limited by the SCA data in essence. To address the issue, we proposed two methods to exploit the SCA data and Riemann integral of the rank curves of all subkey candidates to update each correct sub key rank before carrying out KE. We applied the proposed methods for different crypto implementations running on different devices to verify their performance. Experimental studies for both mono-channel and multi-channel leakages verified that the proposed methods were effective in improving the efficiency of KE to recover the correct key. The proposed methods are designed for processing the SCA data and can be deemed as a preliminary before executing KE. The work of this paper bridges the gap between SCA and KE. Wei Yang 0008, Anmin Fu, Hailong Zhang 0001, Chanying Huang |
TrustCom | 1 |
| 2020 | Privacy-Preserving Federated Learning in Fog ComputingabstractFederated learning can combine a large number of scattered user groups and train models collaboratively without uploading data sets, so as to avoid the server collecting user sensitive data. However, the model of federated learning will expose the training set information of users, and the uneven amount of data owned by users in multiple users' scenarios will lead to the inefficiency of training. In this article, we propose a privacy-preserving federated learning scheme in fog computing. Acting as a participant, each fog node is enabled to collect Internet-of-Things (IoT) device data and complete the learning task in our scheme. Such design effectively improves the low training efficiency and model accuracy caused by the uneven distribution of data and the large gap of computing power. We enable IoT device data to satisfy ε -differential privacy to resist data attacks and leverage the combination of blinding and Paillier homomorphic encryption against model attacks, which realize the security aggregation of model parameters. In addition, we formally verified our scheme can not only guarantee both data security and model security but completely resist collusion attacks launched by multiple malicious entities. Our experiments based on the Fashion-MNIST data set prove that our scheme is highly efficient in practice. Chunyi Zhou 0001, Anmin Fu, Shui Yu 0001, Wei Yang 0008, Huaqun Wang, Yuqing Zhang 0001 |
IEEE Internet Things J. | 4 |
| 2019 | Privacy Preserving Fog-Enabled Dynamic Data Aggregation in Mobile Phone SensingabstractWith the development of science and technology, mobile phones have gained unprecedented popularity, subsequently the applications based on mobile phone perception have become widespread. Mobile sensing encourages many users to participate in data collection tasks through their mobile phones, but this process raises privacy issues. Previous studies have either used additive homomorphism to protect data privacy or aggregated methods to provide identity privacy protection. However, little research has been done on data dynamics and how to improve aggregation efficiency in multi-user scenarios. To solve this problem, we propose a privacy preserving fog-enabled dynamic data aggregation protocol in mobile phone sensing, named FDDA. In the proposal, we first add fog nodes to our framework, allowing fog nodes to aggregate a set of user data at the same geographical location without identifying the data sources. Then, we design data dynamics strategy to support the user joining and revoking effectively. Finally, we show that our protocol can be well applied in actual scenarios through security analysis and simulation experiments. Lei Zhou 0026, Anmin Fu, Shui Yu 0001, Mang Su, Wei Yang 0008 |
GLOBECOM | 6 |
| 2019 | Side-Channel Leakage Amount Estimation Based on Communication TheoryabstractSide-channel attacks (SCAs) have been a serious threat to crypto devices. It is necessary to evaluate the resistance of a crypto device to SCAs. The evaluation criteria include information theoretic metrics and security metrics. The former measure the leakage amount of a crypto device, e.g. mutual information (MI). MI is one of the most commonly used metrics because of its clear information theoretic meaning. However, due to the fact that the real leakage distribution of a crypto device is hard to know, the estimation of MI is difficult. In previous work, there are two ways to estimate the leakage distribution: the nonparametric one and the parametric one. The former is non-profiling, but may bring a significant error because the leakage model is empirically selected by an evaluator. By comparison, the latter is more precise, but needs to profile the leakage model, which may be unfeasible in practice. To combine the merits of two kinds of methods, we bypass the estimation of the leakage distribution, and propose a parametric estimation method without profiling from the view of the noise distribution estimation. The side-channel is viewed as a communication channel in this paper, and naturally the side-channel MI can be deemed to be the average MI of the communication channel. Moreover, the channel capacity can be regarded as a new information theoretic metric which furnishes an estimation of the leakage amount in the worst case scenario. As compared to the previous research, the paper provides a novel black box method to estimate the side-channel leakage amount of a crypto device. The evaluation procedure can be viewed as a preliminary before advanced security evaluation. Wei Yang 0008, Hailong Zhang 0001 |
GLOBECOM | 1 |
| 2017 | Multi-Channel Fusion AttacksabstractSide channel attacks (SCAs) are a kind of the most powerful means to evaluate the physical security of a crypto device. Multi-channel fusion attacks (MCFAs) belong in SCAs and utilize multi-channel leakages simultaneously. As compared with the known mono-channel attacks, MCFAs have higher potential leakage utilization. However, previous research about MCFAs is scarce. MCFAs have not been studied systematically and classified explicitly. It is hard to select MCFAs strategies properly and perform MCFAs efficiently according to the existing research. In light of this, we classify MCFAs into three groups from the view of fusion for the first time, including data-level, feature-level, and decision-level fusion attacks. Accordingly, we construct six MCFAs and verify their effectiveness in typical scenarios. The applicable scopes and the different performances of MCFAs with different fusion activities are also first discussed. To the best of our knowledge, this paper is the first to systematically investigate MCFAs. We hope that this paper will be helpful to understand MCFAs and offer advice on MCFAs against the different implementations of a crypto algorithm. Besides, a fusion metric that determines which channels are suitable for combination is also proposed and verified by practical experiments. Wei Yang 0008, Yongbin Zhou, Yuchen Cao 0002, Hailong Zhang 0001, Qian Zhang 0042 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2016 | Hilbert Transform Based Vertical Preprocessing for Side-Channel AnalysisabstractEvaluating the success rate of a side-channel attack in design phase is of great significance for the design of secure crypto device. The reason is evaluation in design phase can help find and fix security vulnerabilities early. Existing methods of success rate evaluation in design phase ignore the preprocessing of real attacks. This results in a big gap between the success rate evaluated in design phase and that got in practical attacks. In this paper we propose a Hilbert Transform based vertical preprocessing, aiming at enhancing the signal-to-noise ratio. Compared to existing preprocessing methods aiming at a similar purposes, it can be mounted in design phase, which makes it possible to refine evaluation in design phase. Furthermore, the Hilbert Transform based vertical preprocessing can be used in real attacks as well, and its working efficiency is higher than that of other advanced preprocessing. We perform the vertical preprocessing not only in simulated scenarios but also in practical scenarios. Evaluation results confirm that vertical preprocessing leads to significant improvement of success rate. Therefore, we note vertical preprocessing can be an important tool for evaluating and analyzing of the practical security of crypto device. Yuchen Cao 0002, Yongbin Zhou, Hailong Zhang 0001, Wei Yang 0008 |
ICCCN | 4 |
| 2016 | A statistical model for DPA when algorithmic noise is dependent on targetabstractAbstract In side‐channel attacks, information about any intermediate data except the target data will be considered as noise, namely, the “algorithmic noise.” Algorithmic noise is always assumed to be independent of the target data. As a result, it is thought to be an equivalence of physical noise. Numerous investigations are built on this intuitive assumption. In this paper, we claim that this assumption is not always true and find the algorithm (e.g., SIMON) for which the algorithmic noise is dependent on the target data. On this condition, we reconsider the issue of success rate estimation and build a modified statistical model to accurately estimate the success rate when the algorithmic noise is dependent on the target data. Finally, experimental results for SIMON algorithm validate the soundness of our methodology. It is also worth mentioning that SIMON is a candidate proposed by the National Security Agency as the standard light‐weight block cipher. Copyright © 2016 John Wiley & Sons, Ltd. Shuang Qiu 0004, Rui Zhang 0002, Yuchen Cao 0002, Wei Yang 0008, Yongbin Zhou, Tian Ding |
Secur. Commun. Networks | 4 |
| 2016 | Distance Based Leakage Alignment for Side Channel AttacksabstractSide Channel Attack (SCA) recovers secret information from an embedded device with implementation of cryptographic algorithm by exploiting its physical leakages. For most SCA methods to achieve good performance, the measured leakages are often desired to be well aligned. However, due to some specific reasons such as inaccurate measurements or carefully designed countermeasures, misalignment of leakages frequently occurs in practice. Misalignment significantly reduces the efficiency of SCA methods, or even makes them fail. To address this issue, two alignment approaches are proposed: a local alignment based onshotgun distanceand a global alignment based onweighted edit distance. Compared with previous methods, the proposed methods are capable of keeping the secret dependant leakages, while not introducing any redundant information. In addition, the proposed methods could also reduce the negative effects of noise, which is another factor seriously decreasing the efficiency of SCA methods. Interestingly, it is pretty easy to set appropriate parameters for these two methods. Practical experiments show that the proposed methods outperform previous methods in three different circumstances and different noise levels. Wei Yang 0008, Yuchen Cao 0002, Yongbin Zhou, Hailong Zhang 0001, Qian Zhang 0042 |
IEEE Signal Process. Lett. | 1 |