Fang Jiang 0001

dblp:09/5767-1 · DBLP profile ↗
← Back
6ranked-venue papers
1as first author
6since 2021 · last 2026
0009-0002-7437-1632ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 5 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 CIBPU: A Conflict-Invisible Secure Branch Prediction Unit
abstract
Previous schemes for designing secure branch prediction unit (SBPU) based on physical isolation can only offer limited security and significantly affect BPU’s prediction capability, leading to prominent performance degradation. Moreover, encryption-based SBPU schemes based on periodic key rerandomization have the risk of being compromised by advanced attack algorithms, and the performance overhead is also considerable. To this end, this paper proposes conflict-invisible SBPU (CIBPU). CIBPU employs redundant storage design, load-aware indexing, and replacement design, as well as an encryption mechanism without requiring periodic key updates, to prevent attackers’ perception of branch conflicts. We provide a thorough security analysis, which shows that CIBPU achieves strong security throughout the BPU’s lifecycle. We implement CIBPU in a RISC-V core model in gem5. The experimental results show that CIBPU causes an average performance overhead of only 2.9%–4.0% with acceptable hardware storage overhead, which is the lowest among the state-of-the-art SBPU schemes. CIBPU has also been implemented in the open-source RISC-V core, SonicBOOM, which is then burned onto an FPGA board. The evaluation based on the board shows an average performance degradation of 2.01%, which is approximately consistent with the result obtained in gem5.
Zhe Zhou 0003, Xiaoyu Cheng 0001, Fang Jiang 0001, Fei Tong 0001, Zhikun Zhang 0001, Yuxing Mao
IEEE Trans. Inf. Forensics Secur.3
2025 SpectrePrefetch: Undermining Cache-Centric Secure Speculation with Modern Hardware Prefetchers
abstract
Transient execution attacks can exploit speculative execution to leak sensitive information through cache systems. Consequently, numerous cache-centric secure speculation defenses have been proposed. However, as we demonstrate both theoretically and empirically, these defenses remain vulnerable to data leakage because they neglect or fail to fully address the security issues posed by the hardware prefetcher, a critical component of modern cache systems, within the speculative execution path. In this work, we develop a new attack framework, SpectrePrefetch, which exploits hardware prefetchers as transmission mediums for leaking secrets during speculative execution. Specifically, we introduce two variants of SpectrePrefetch attacks that encode transient secrets into the prefetching patterns and prefetching confidence, respectively, and then recover secrets by probing the cache state or the prefetcher state. We launch SpectrePrefetch to attack several Intel CPUs and a Gem5 simulator, demonstrating its feasibility, robustness, bandwidth, scalability, and security implications on existing defenses. The results show that SpectrePrefetch can leak secrets at a high rate of 31.25 Kbps with an accuracy of 98.87%. More seriously, SpectrePrefetch undermines cache-centric secure speculation defenses or even secure cache designs, and is challenging to mitigate. Our experimental results show that simply restricting the prefetcher to update only on committed instructions, as proposed in MuonTrap, nearly loses all performance benefits provided by hardware prefetching. Finally, we propose a low-cost, scalable non-deterministic prefetching defense against transient execution attacks exploiting hardware prefetchers, while maintaining or even improving average performance on SPEC2017 benchmarks.
Fang Jiang 0001, Fei Tong 0001, Xiaoyu Cheng 0001, Zhe Zhou 0003, Yuxing Mao
ICCAD1
2025 SCSGuardian: A Practical Hardware Defense Against Speculative Cache Side-Channel Attacks
Xiaoyu Cheng 0001, Fei Tong 0001, Zhe Zhou 0003, Fang Jiang 0001, Guang Cheng 0001, Yuxing Mao
IEEE Trans. Inf. Forensics Secur.4
2025 A Lightweight and Dynamic Open-Set Intrusion Detection for Industrial Internet of Things
abstract
Recently intrusion detection technology has been deployed in the Industrial Internet of Things (IIoT), which is an efficacious approach to enhancing security. However, identifying previously unseen and unknown attacks, referred to as the open-set problem, has become increasingly difficult due to the openness of IoT architecture and the continuous evolution of attack patterns. Moreover, existing open-set intrusion detection solutions are challenging to be applied directly to IIoT because of their unique characteristics, such as limited computational and storage capabilities, long detection times, and the inability to continuously learn. In this paper, we propose an efficient, lightweight, and dynamic open-set intrusion detection scheme for IIoT. It consists of three stages: the known attack classification stage focuses on extracting features from known data to efficiently classify normal data and known attacks; the unknown attack recognition stage analyzes the distribution of reconstruction errors to effectively distinguish between known data and unknown attacks; and the dynamic update detection stage introduces a lightweight detection architecture for unknown attacks detection, significantly reducing the computational overhead and storage requirements of IIoT devices. Simultaneously, it learns from and updates with newly detected unknown attacks to further optimize detection capabilities. We conduct experiments on four widely used datasets to evaluate the performance of open-set intrusion detection for IIoT. The experimental results delineate the superiority of our proposed method over four state-of-the-art approaches in open-set intrusion detection. Meanwhile, our proposed lightweight model updating method significantly reduces detection time by over 65% and memory overhead by over 80% compared to retraining methods, while achieving an average detection accuracy of 96%.
Xueji Yang, Fei Tong 0001, Fang Jiang 0001, Guang Cheng 0001
IEEE Trans. Inf. Forensics Secur.3
2024 SpecLFB: Eliminating Cache Side Channels in Speculative Executions
Xiaoyu Cheng 0001, Fei Tong 0001, Zhe Zhou 0003, Fang Jiang 0001, Yuxing Mao
USENIX Security Symposium5
2022 Cache Design Effect on Microarchitecture Security: A Contrast between Xuantie-910 and BOOM
abstract
Modern processors make use of optimization techniques such as cache and speculation mechanisms to greatly improve performance. But recent research has found that these techniques can also be exploited by attackers to perform powerful side-channel attacks. A large number of powerful cache-based attacks have been replicated and enhanced over Intel X86- and ARM-based architectures, but there is a relative lack of research on RISC-V-based architectures. Xuantie-910 and BOOM are both RISC-V-based processors. So far, cache-side channels in the unprivileged case of Xuantie-910 have not been proven, while cache attacks against BOOM are proliferating. There are two types of caches, including physically-indexed physically-tagged (PIPT) cache (adopted by Xuantie-910) and virtually-indexed physically-tagged (VIPT) cache (adopted by BOOM), corresponding to two different cache addressing forms. VIPT has higher addressing performance than PIPT, since it can directly obtain cache line index from virtual address. In this paper, we study Xuantie-910 and BOOM to explore the impact of cache design on the security of RISC-V-based microarchitecture. Specifically, we compare the impact of their cache addressing forms on precise flushing of cache lines at specified locations, which plays an important role in cache side-channel attacks. Experimental results show that for the VIPT cache in BOOM, the location-specified cache lines can be accurately flushed, and Spectre attack can be successfully carried out by using the cache side-channel. On the other hand, for the PIPT cache in Xuantie-910, it is impossible for attackers to directly and accurately flush the specified location of cache without affecting performance, which hinders the success of cache side-channel attacks. This provides us with an insight that one can adopt a VIPT-based cache with a mechanism similar to PIPT for preventing the accurate access of cache line index, which can not only keep the advantage of high-performance addressing in VIPT but also improve chip security.
Zhe Zhou 0003, Xiaoyu Cheng 0001, Fang Jiang 0001, Fei Tong 0001, Yuxing Mao
TrustCom4