VLDB 2026 Research / reviewers in the wild / expert
Huili Chen
dblp:122/1230
· DBLP profile ↗
39ranked-venue papers
20as first author
16since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 13 · 9 first-author · 3 since 2021Artificial intelligence and machine learning · 11 · 9 first-author · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 8 · 4 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 8 · 4 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 1 since 2021Security and privacy · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 2 · 2 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | HRAI 2025: The 1st Workshop on Holistic and Responsible Affective IntelligenceabstractThe ICMI 2025 Workshop on Holistic and Responsible Affective Intelligence (HRAI 2025) aims to advance research in affective intelligence by fostering discussions on the holistic development of affective computing and the ethical challenges it entails. The workshop aims to strengthen interdisciplinary connections within the affective computing community, promoting better integration of methodologies and enhancing real-world applicability. By tackling both technical and ethical issues, HRAI 2025 aspires to shape the future of affective AI, ensuring it is not only powerful but also fair, safe, and socially responsible. Yuanchao Li, Dimitris Kollias, Guillaume Chanel, Marios A. Fanourakis, Michal Muszynski, Brandon M. Booth, Leimin Tian, Madhawa Perera, Catherine Lai, Huili Chen |
ICMI | 10 |
| 2025 | LSDNet: lightweight stochastic depth network for human pose estimation
Yongfeng Qi, Huili Chen, Panpan Cao, Anye Liang, Shengcong Wen |
Vis. Comput. | 3 |
| 2024 | Integrating Flow Theory and Adaptive Robot Roles: A Conceptual Model of Dynamic Robot Role Adaptation for the Enhanced Flow Experience in Long-term Multi-person Human-Robot InteractionsabstractIn this paper, we introduce a novel conceptual model for a robot's behavioral adaptation in its long-term interaction with humans, integrating dynamic robot role adaptation with principles of flow experience from psychology. This conceptualization introduces a hierarchical interaction objective grounded in the flow experience, serving as the overarching adaptation goal for the robot. This objective intertwines both cognitive and affective sub-objectives and incorporates individual and group-level human factors. The dynamic role adaptation approach is a cornerstone of our model, highlighting the robot's ability to fluidly adapt its support roles-from leader to follower-with the aim of maintaining equilibrium between activity challenge and user skill, thereby fostering the user's optimal flow experiences. Moreover, this work delves into a comprehensive exploration of the limitations and potential applications of our proposed conceptualization. Our model places a particular emphasis on the multi-person HRI paradigm, a dimension of HRI that is both under-explored and challenging. In doing so, we aspire to extend the applicability and relevance of our conceptualization within the HRI field, contributing to the future development of adaptive social robots capable of sustaining long-term interactions with humans. Huili Chen, Sharifa Alghowinem, Cynthia Breazeal, Hae Won Park 0001 |
HRI | 1 |
| 2024 | Adaptive module and accurate heatmap translator for multi-person human pose estimation
Yongfeng Qi, Shengcong Wen, Anye Liang, Panpan Cao, Huili Chen |
Comput. Graph. | 6 |
| 2024 | Face forgery detection by progressively enhancing spatial and frequency-aware features
Yongfeng Qi, Shengcong Wen, Anye Liang, Huili Chen, Panpan Cao |
Multim. Syst. | 5 |
| 2023 | Smarter Contracts: Detecting Vulnerabilities in Smart Contracts with Deep Transfer Learning
Christoph Sendner, Huili Chen, Hossein Fereidooni, Lukas Petzi, Jan König, Jasper Stang, Alexandra Dmitrienko, Ahmad-Reza Sadeghi, Farinaz Koushanfar |
NDSS | 2 |
| 2023 | Dyadic Affect in Parent-Child Multimodal Interaction: Introducing the DAMI-P2C Dataset and its Preliminary AnalysisabstractHigh-quality parent-child conversational interactions are crucial for children's social, emotional, and cognitive development. However, many children have limited exposure to these interactions at home. As increasingly accessible and scalable interventions in child development, interactive technologies, such as social robots, have great potential for facilitating parent-child interactions. However, such technology-based interventions are still underexplored, as the technologies' limited ability to understand the social-emotional dynamics of human dyadic interactions impedes their effective delivery of timely, adaptive interventions. To advance research on resolving this roadblock, we present a “dyadic affect in multimodal interaction-parent to child” (DAMI-P2C) dataset collected during a study of 34 parent-child pairs, where parents and children (3-7 years old) engaged in reading storybooks together. In contrast to existing public datasets for social-emotional behaviors in dyadic interactions, each instance for both participants in our dataset was annotated for affect by three labelers. Additionally, the dataset contains audiovisual recordings as well as each dyad's sociodemographic profiles, co-reading behaviors, affect labels, and body joints. We describe the dataset's main characteristics and provide a preliminary analysis of the interrelations between sociodemographic profiles, co-reading behaviors, and affect labels. The dataset provides us with useful insights into the computing and social science fields. Huili Chen, Sharifa Alghowinem, Soo Jung Jang, Cynthia Breazeal, Hae Won Park 0001 |
IEEE Trans. Affect. Comput. | 1 |
| 2023 | Tutorial: Toward Robust Deep Learning against Poisoning AttacksabstractDeep Learning (DL) has been increasingly deployed in various real-world applications due to its unprecedented performance and automated capability of learning hidden representations. While DL can achieve high task performance, the training process of a DL model is both time- and resource-consuming. Therefore, current supply chains of the DL models assume the customers obtain pre-trained Deep Neural Networks (DNNs) from the third-party providers that have sufficient computing power. In the centralized setting, the model designer trains the DL model using the local dataset. However, the collected training data may contain erroneous or poisoned data points. The model designer might craft malicious training samples and inject a backdoor in the DL model distributed to the users. As a result, the user’s model will malfunction. In the federated learning setting, the cloud server aggregates local models trained on individual local datasets and updates the global model. In this scenario, the local client could poison the local training set and/or arbitrarily manipulate the local update. If the cloud server incorporates the malicious local gradients in model aggregation, the resulting global model will have degraded performance or backdoor behaviors. In this article, we present a comprehensive overview of contemporary data poisoning and model poisoning attacks against DL models in both centralized and federated learning scenarios. In addition, we review existing detection and defense techniques against various poisoning attacks. Huili Chen, Farinaz Koushanfar |
ACM Trans. Embed. Comput. Syst. | 1 |
| 2023 | AdaTest: Reinforcement Learning and Adaptive Sampling for On-chip Hardware Trojan DetectionabstractThis paper proposes AdaTest, a novel adaptive test pattern generation framework for efficient and reliable Hardware Trojan (HT) detection. HT is a backdoor attack that tampers with the design of victim integrated circuits (ICs) . AdaTest improves the existing HT detection techniques in terms of scalability and accuracy of detecting smaller Trojans in the presence of noise and variations. To achieve high trigger coverage, AdaTest leverages Reinforcement Learning (RL) to produce a diverse set of test inputs. Particularly, we progressively generate test vectors with high ‘reward’ values in an iterative manner. In each iteration, the test set is evaluated and adaptively expanded as needed. Furthermore, AdaTest integrates adaptive sampling to prioritize test samples that provide more information for HT detection, thus reducing the number of samples while improving the samples’ quality for faster exploration. We develop AdaTest with a Software/Hardware co-design principle and provide an optimized on-chip architecture solution. AdaTest’s architecture minimizes the hardware overhead in two ways: (i) Deploying circuit emulation on programmable hardware to accelerate reward evaluation of the test input; (ii) Pipelining each computation stage in AdaTest by automatically constructing auxiliary circuit for test input generation, reward evaluation, and adaptive sampling. We evaluate AdaTest’s performance on various HT benchmarks and compare it with two prior works that use logic testing for HT detection. Experimental results show that AdaTest engenders up to two orders of test generation speedup and two orders of test set size reduction compared to the prior works while achieving the same level or higher Trojan detection rate. Huili Chen, Xinqiao Zhang, Ke Huang 0001, Farinaz Koushanfar |
ACM Trans. Embed. Comput. Syst. | 1 |
| 2023 | Systemization of Knowledge: Robust Deep Learning using Hardware-software co-design in Centralized and Federated SettingsabstractDeep learning (DL) models are enabling a significant paradigm shift in a diverse range of fields, including natural language processing and computer vision, as well as the design and automation of complex integrated circuits. While the deep models – and optimizations based on them, e.g., Deep Reinforcement Learning (RL) – demonstrate a superior performance and a great capability for automated representation learning, earlier works have revealed the vulnerability of DL to various attacks. The vulnerabilities include adversarial samples, model poisoning, and fault injection attacks. On the one hand, these security threats could divert the behavior of the DL model and lead to incorrect decisions in critical tasks. On the other hand, the susceptibility of DL to potential attacks might thwart trustworthy technology transfer as well as reliable DL deployment. In this work, we investigate the existing defense techniques to protect DL against the above-mentioned security threats. Particularly, we review end-to-end defense schemes for robust deep learning in both centralized and federated learning settings. Our comprehensive taxonomy and horizontal comparisons reveal an important fact that defense strategies developed using DL/software/hardware co-design outperform the DL/software-only counterparts and show how they can achieve very efficient and latency-optimized defenses for real-world applications. We believe our systemization of knowledge sheds light on the promising performance of hardware-software co-design of DL security methodologies and can guide the development of future defenses. Ruisi Zhang, Shehzeen Hussain, Huili Chen, Mojan Javaheripi, Farinaz Koushanfar |
ACM Trans. Design Autom. Electr. Syst. | 3 |
| 2022 | Self-Aware Personalized Federated LearningabstractIn the context of personalized federated learning (FL), the critical challenge is to balance local model improvement and global model tuning when the personal and global objectives may not be exactly aligned. Inspired by Bayesian hierarchical models, we develop a self-aware personalized FL method where each client can automatically balance the training of its local personal model and the global model that implicitly contributes to other clients' training. Such a balance is derived from the inter-client and intra-client uncertainty quantification. A larger inter-client variation implies more personalization is needed. Correspondingly, our method uses uncertainty-driven local training steps an aggregation rule instead of conventional local fine-tuning and sample size-based aggregation. With experimental studies on synthetic data, Amazon Alexa audio data, and public datasets such as MNIST, FEMNIST, CIFAR10, and Sent140, we show that our proposed method can achieve significantly improved personalization performance compared with the existing counterparts. Huili Chen, Jie Ding 0002, Eric W. Tramel, Anit Kumar Sahu, Amir Salman Avestimehr |
NeurIPS | 1 |
| 2022 | Designing Long-term Parent-child-robot Triadic Interaction at Home through Lived Technology Experiences and InterviewsabstractSocial agents have been mostly designed to engage with children one-on-one as tutors or learning peers. Besides this child-robot dyadic interaction paradigm, they have the potential to empower parents to more actively interact with their children. Robot-assisted parent-child interaction could be a sustainable future approach for promoting children’s in-home learning. Motivated by this new design direction, this work takes an iterative design approach to explore how we design triadic interactions through "lived technology experiences" and interviews. For 3-6 weeks, we deployed and remotely teleoperated a social robot in the homes of 12 families with 3-7-year-old children to engage in a triadic story reading activity with both parent and child for six 25-min sessions. Before and after the deployment, we conducted a semi-structured interview with participants on their triadic interaction experience and desired robot design features. The results of our qualitative analysis show that social robots can improve various aspects of parent-child interaction. We propose design guidelines for robot-assisted parent-child interactions at home, the considerations of participants’ values around technology design, and promotion of their long-term lived technology experiences as critical sources for design knowledge. Huili Chen, Anastasia K. Ostrowski, Soo Jung Jang, Cynthia Breazeal, Hae Won Park 0001 |
RO-MAN | 1 |
| 2022 | FLAME: Taming Backdoors in Federated Learning
Thien Duc Nguyen, Phillip Rieger, Huili Chen, Hossein Yalame, Helen Möllering, Hossein Fereidooni, Samuel Marchal, Markus Miettinen, Azalia Mirhoseini, Shaza Zeitouni, Farinaz Koushanfar, Ahmad-Reza Sadeghi, Thomas Schneider 0003 |
USENIX Security Symposium | 3 |
| 2022 | Safe distance prediction for braking control of bridge cranes considering anti-swingabstractCranes are widely deployed for lifting and moving heavy objects in dynamic environments with human coexistence. Suddenly appeared workers, vehicles, and robots can affect the safety of the cranes. To avoid possible collisions, the cranes must have prediction ability to know how dangerous the situation is. In this paper, we address the safety issues of bridge cranes based on its online physical states and control model. Due to the swing of the payload, the safe braking distance cannot be a constant value. Therefore, we here propose a model prediction control (MPC)-based anti-swing method for non-zero initial states, where a new reference trajectory and a new cost function for optimization are proposed, such that the proposed MPC method can control the crane to follow the proposed reference trajectory and achieve a stable stop state with anti-swing. Furthermore, an offline learning mechanism is introduced to learn a statistical model between the velocity of the crane and the safe braking distance achieved by using the proposed MPC braking control method. In this way, we can predict how far the crane would require to safely stop without swing based on its current velocity, which is the safe distance prediction to evaluate the dangerous level of the dynamic obstacle. Experiments using both a simulated crane and a real crane demonstrate that the proposed safe braking distance prediction method is effective for safe braking control of the bridge cranes. Huili Chen, Guohui Tian, Jianhua Zhang 0010, Ze Ji |
Int. J. Intell. Syst. | 1 |
| 2021 | Body Gesture and Head Movement Analyses in Dyadic Parent-Child Interaction as Indicators of RelationshipabstractParent-child nonverbal communication plays a crucial role in understanding their relationships and assessing their interaction styles. However, prior works have seldom studied the exchange of these nonverbal cues between the dyad and focused on isolated cues from one person at a time. In contrast, this work analyzes both parents' and children's individual and dyadic nonverbal behaviors in relation to their four relationship characteristics, i.e., child temperament, parenting style, parenting stress, and home literacy environment. We utilize a state-of-the-art feature selection framework on a dataset of 31 parent-child interactions to automatically extract and select a set of temporal nonverbal behaviors as key indicators of the dyad's relationship characteristics. The results show that relationship characteristics were associated with both individuals' and dyads' nonverbal behaviors. This finding highlights the importance of accounting for both individual- and dyad-scale nonverbal behaviors when predicting dyadic relationship characteristics as well as the potential limitations of utilizing single persons' nonverbal data in isolation. It therefore motivates future work on this topic to take a holistic and relational approach. The dataset and extracted nonverbal data are made public to aid the development of automated detection tools for parent-child relationship characteristics that trains on visual recordings of their dyadic interactions. Sharifa Alghowinem, Huili Chen, Cynthia Breazeal, Hae Won Park 0001 |
FG | 2 |
| 2021 | ProFlip: Targeted Trojan Attack with Progressive Bit FlipsabstractThe security of Deep Neural Networks (DNNs) is of great importance due to their employment in various safety-critical applications. DNNs are shown to be vulnerable against the Trojan attack that manipulates model parameters via poisoned training and gets activated by the pre-defined trigger during inference. In this work, we present ProFlip, the first targeted Trojan attack framework that can divert the prediction of the DNN to the target class by progressively identifying and flipping a small set of bits in model parameters. At its core, ProFlip consists of three key phases: (i) Determining significant neurons in the last layer; (ii) Generating an effective trigger pattern for the tar-get class; (iii) Identifying a sequence of susceptible bits of DNN parameters stored in the main memory (e.g., DRAM). After model deployment, the adversary can insert the Trojan by flipping the critical bits found by ProFlip using bit flip techniques such as Row Hammer or laser beams. As the result, the altered DNN predicts the target class when the trigger pattern is present in any inputs. We perform extensive evaluations of ProFlip on CIFAR10, SVHN, and ImageNet datasets with ResNet-18 and VGG-16 architectures. Empirical results show that, to reach an attack success rate (ASR) of over 94%, ProFlip requires only 12 bit flips out of 88 million parameter bits for ResNet-18 with CIFAR-10, and 15 bit flips for ResNet-18 with ImageNet. Compared to the SOTA, ProFlip reduces the number of required bits flips by 28× ∼ 34× while reaching the same or higher ASR. Huili Chen, Cheng Fu 0002, Jishen Zhao, Farinaz Koushanfar |
ICCV | 1 |
| 2020 | AHEC: End-to-end Compiler Framework for Privacy-preserving Machine Learning AccelerationabstractPrivacy-preserving machine learning (PPML) is driven by the emerging adoption of Machine Learning as a Service (MLaaS). In a typical MLaaS system, the end-user sends his personal data to the service provider and receives the corresponding prediction output. However, such interaction raises severe privacy concerns about both the user's proprietary data and the server's ML model. PPML integrates cryptographic primitives such as Multi-Party Computation (MPC) and/or Homomorphic Encryption (HE) into ML services to resolve the privacy issue. However, existing PPML solutions have not been widely deployed in practice since: (i) Privacy protection comes at the cost of additional computation and/or communication overhead; (ii) Adapting PPML to different front-end frameworks and back-end hardware incurs prohibitive engineering cost.We propose AHEC, the first automated, end-to-end HE compiler for efficient PPML inference. Leveraging the capability of Domain Specific Languages (DSLs), AHEC enables automated generation and optimization of HE kernels across diverse types of hardware platforms and ML frameworks. We perform extensive experiments to investigate the performance of AHEC from different abstraction levels: HE operations, HE-based ML kernels, and neural network layers. Empirical results corroborate that AHEC achieves superior runtime reduction compared to the state-of-the-art solutions built from static HE libraries. Huili Chen, Rosario Cammarota, Felipe Valencia, Francesco Regazzoni 0001, Farinaz Koushanfar |
DAC | 1 |
| 2020 | Developing Privacy-preserving AI Systems: The Lessons learnedabstractAdvances in customers' data privacy laws create pressures and pain points across the entire lifecycle of AI products. Working figures such as data scientists and data engineers need to account for the correct use of privacy-enhancing technologies such as homomorphic encryption, secure multi-party computation, and trusted execution environment when they develop, test and deploy products embedding AI models while providing data protection guarantees. In this work, we share the lessons learned during the development of frameworks to aid data scientists and data engineers to map their optimized workloads onto privacy-enhancing technologies seamlessly and correctly. Huili Chen, Siam U. Hussain, Fabian Boemer, Emmanuel Stapf, Ahmad-Reza Sadeghi, Farinaz Koushanfar, Rosario Cammarota |
DAC | 1 |
| 2020 | Unified Architectural Support for Secure and Robust Deep LearningabstractRecent advances in Deep Learning (DL) have enabled a paradigm shift to include machine intelligence in a wide range of autonomous tasks. As a result, a largely unexplored surface has opened up for attacks jeopardizing the integrity of DL models and hindering the success of autonomous systems. To enable ubiquitous deployment of DL approaches across various intelligent applications, we propose to develop architectural support for hardware implementation of secure and robust DL. Towards this goal, we leverage hardware/software co-design to develop a DL execution engine that supports algorithms specifically designed to defend against various attacks. The proposed framework is enhanced with two real-time defense mechanisms, securing both DL training and execution stages. In particular, we enable model-level Trojan detection to mitigate backdoor attacks and malicious behaviors induced on the DL model during training. We further realize real-time adversarial attack detection to avert malicious behavior during execution. The proposed execution engine is equipped with hardware-level IP protection and usage control mechanism to attest the legitimacy of the DL model mapped to the device. Our design is modular and can be tuned to task-specific demands, e.g., power, throughput, and memory bandwidth, by means of a customized hardware compiler. We further provide an accompanying API to reduce the nonrecurring engineering cost and ensure automated adaptation to various domains and applications. Mojan Javaheripi, Huili Chen, Farinaz Koushanfar |
DAC | 2 |
| 2020 | Impact of Interaction Context on the Student Affect-Learning Relationship in Child-Robot InteractionabstractPrior work in affect-aware educational robots has often relied on a common belief that the relationship between student affect and learning is independent of agent behaviors (child's/robot's) or unidirectional (positive/negative but not both) throughout the entire student-robot interaction. We argue that the student affect-learning relationship should be interpreted in two contexts: (1) social learning paradigm and (2) sub-events within child-robot interaction. In our paper, we examine two different social learning paradigms where children interact with a robot that acts either as a tutor or a tutee. Sub-events within child-robot interaction are defined as task-related events occurring in specific phases of an interaction (e.g., when the child/robot gets a wrong answer). We examine sub-events at a macro level (entire interaction) and a micro level (within specific sub-events). In this paper, we provide an in-depth correlation analysis of children's facial affect and vocabulary learning. We found that children's affective displays became more predictive of their vocabulary learning when children interacted with a tutee robot who did not scaffold their learning. Additionally, children's affect displayed during micro-level events was more predictive of their learning than during macro-level events. Last, we found that the affect-learning relationship is not unidirectional, but rather is modulated by context, i.e., several affective states facilitated student learning when displayed in some sub-events but inhibited learning when displayed in others. These findings indicate that both social learning paradigm and sub-events within interaction modulate student affect-learning relationship. Huili Chen, Hae Won Park 0001, Xiajie Zhang, Cynthia Breazeal |
HRI | 1 |
| 2020 | Dyadic Speech-based Affect Recognition using DAMI-P2C Parent-child Multimodal Interaction DatasetabstractAutomatic speech-based affect recognition of individuals in dyadic conversation is a challenging task, in part because of its heavy reliance on manual pre-processing. Traditional approaches frequently require hand-crafted speech features and segmentation of speaker turns. In this work, we design end-to-end deep learning methods to recognize each person's affective expression in an audio stream with two speakers, automatically discovering features and time regions relevant to the target speaker's affect. We integrate a local attention mechanism into the end-to-end architecture and compare the performance of three attention implementations - one mean pooling and two weighted pooling methods. Our results show that the proposed weighted-pooling attention solutions are able to learn to focus on the regions containing target speaker's affective information and successfully extract the individual's valence and arousal intensity. Here we introduce and use a "dyadic affect in multimodal interaction - parent to child" (DAMI-P2C) dataset collected in a study of 34 families, where a parent and a child (3-7 years old) engage in reading storybooks together. In contrast to existing public datasets for affect recognition, each instance for both speakers in the DAMI-P2C dataset is annotated for the perceived affect by three labelers. To encourage more research on the challenging task of multi-speaker affect sensing, we make the annotated DAMI-P2C dataset publicly available, including acoustic features of the dyads' raw audios, affect annotations, and a diverse set of developmental, social, and demographic profiles of each dyad. Huili Chen, Yue Zhang 0014, Felix Weninger, Rosalind W. Picard, Cynthia Breazeal, Hae Won Park 0001 |
ICMI | 1 |
| 2020 | SpecMark: A Spectral Watermarking Framework for IP Protection of Speech Recognition Systems
Huili Chen, Bita Darvish Rouhani, Farinaz Koushanfar |
INTERSPEECH | 1 |
| 2020 | Security of Microfluidic Biochip: Practical Attacks and CountermeasuresabstractWith the advancement of system miniaturization and automation, Lab-on-a-Chip (LoC) technology has revolutionized traditional experimental procedures. Microfluidic Biochip (MFB) is an emerging branch of LoC with wide medical applications such as DNA sequencing, drug delivery, and point of care diagnostics. Due to the critical usage of MFBs, their security is of great importance. In this article, we exploit the vulnerabilities of two types of MFBs: Flow-based Microfluidic Biochip (FMFB) and Digital Microfluidic Biochip (DMFB). We propose a systematic framework for applying Reverse Engineering (RE) attacks and Hardware Trojan (HT) attacks on MFBs as well as for practical countermeasures against the proposed attacks. We evaluate the attacks and defense on various benchmarks where experimental results prove the effectiveness of our methods. Security metrics are defined to quantify the vulnerability of MFBs. The overhead and performance of the proposed attacks as well as countermeasures are also discussed. Huili Chen, Seetal Potluri, Farinaz Koushanfar |
ACM Trans. Design Autom. Electr. Syst. | 1 |
| 2019 | DeepSigns: An End-to-End Watermarking Framework for Ownership Protection of Deep Neural NetworksabstractDeep Learning (DL) models have created a paradigm shift in our ability to comprehend raw data in various important fields, ranging from intelligence warfare and healthcare to autonomous transportation and automated manufacturing. A practical concern, in the rush to adopt DL models as a service, is protecting the models against Intellectual Property (IP) infringement. DL models are commonly built by allocating substantial computational resources that process vast amounts of proprietary training data. The resulting models are therefore considered to be an IP of the model builder and need to be protected to preserve the owner's competitive advantage. We propose DeepSigns, the first end-to-end IP protection framework that enables developers to systematically insert digital watermarks in the target DL model before distributing the model. DeepSigns is encapsulated as a high-level wrapper that can be leveraged within common deep learning frameworks including TensorFlow and PyTorch. The libraries in DeepSigns work by dynamically learning the Probability Density Function (pdf) of activation maps obtained in different layers of a DL model. DeepSigns uses the low probabilistic regions within the model to gradually embed the owner's signature (watermark) during DL training while minimally affecting the overall accuracy and training overhead. DeepSigns can demonstrably withstand various removal and transformation attacks, including model pruning, model fine-tuning, and watermark overwriting. We evaluate DeepSigns performance on a wide variety of DL architectures including wide residual convolution neural networks, multi-layer perceptrons, and long short-term memory models. Our extensive evaluations corroborate DeepSigns' effectiveness and applicability. We further provide a highly-optimized accompanying API to facilitate training watermarked neural networks with a training overhead as low as 2.2%. Bita Darvish Rouhani, Huili Chen, Farinaz Koushanfar |
ASPLOS | 2 |
| 2019 | SimBNN: A Similarity-Aware Binarized Neural Network Acceleration FrameworkabstractBinarized Neural Networks (BNNs) eliminate bitwidth redundancy in Convolutional Neural Networks (CNNs) by using a single bit (-1/+1) for network parameters and intermediate representations. This greatly reduces off-chip data transfer and storage overhead. However, considerable computation redundancy remains in BNN inference. To tackle this problem, we investigate the similarity property in input data and kernel weights. We identify an average of 79% input similarity and 61% kernel similarity measured by our proposed metric across common network architectures. Motivated by this observation, we propose SimBNN, a fast and energy-efficient acceleration framework for BNN inference that leverages similarity properties. SimBNN consists of a set of similarity-aware accelerators, a weight reuse optimization algorithm, and a similarity selection mechanism. SimBNN incorporates two types of BNN accelerators, which exploit the input similarity and kernel similarity, respectively. More specifically, the result from the previous stage is reused if similarity is identified, thus significantly reducing BNN computation overhead. Furthermore, we propose a weight reuse optimization algorithm, which increases the weight similarity by off-line re-ordering weight kernels. Finally, our framework provides a systematic method to determine the optimal strategy between input data and kernel weights reuse, based on the similarity characteristics of input data and pre-trained BNNs. Cheng Fu 0002, Shilin Zhu, Huili Chen, Farinaz Koushanfar, Hao Su 0001, Jishen Zhao |
FCCM | 3 |
| 2019 | GenUnlock: An Automated Genetic Algorithm Framework for Unlocking Logic EncryptionabstractLogic locking inserts additional key gates to the original circuit for protecting the intellectual property (IP) of modern integrated circuits (ICs). Prior works have identified the vulnerability of logic locking to satisfiability (SAT)-based attacks. However, SAT attacks are ineffective on circuits with SAT-hard structures. In this paper, we propose GenUnlock, the first genetic algorithm-based logic unlocking attack framework addressing the above limitation of SAT attacks. GenUnlock formulates logic unlocking (i.e., identifying the correct keys) as a combinatorial optimization problem and tackles it using genetic algorithms (GAs). Multiple key sequences form the individuals in the population and undergo the following main operations: circuit fitness evaluation, population selection, crossover, and mutation. The key sequences with high fitness scores `survive' the selection and are transformed into the offspring. GenUnlock's evolutionary process of key searching features high scalability, exploration efficiency, and parallelizable fitness evaluation. We take an Algorithm/Software/Hardware co-design approach to optimize GenUnlock's runtime overhead. More specifically, GenUnlock (i) Pipelines each computation stage by automatically constructing auxiliary circuitry for constraints checking, sorting, crossover, and mutation; (ii) Employs hardware emulation on programmable hardware for accelerating circuit fitness evaluation. We perform a comprehensive evaluation of GenUnlock's performance on various benchmarks and demonstrate that GenUnlock achieves up to 1014.1× speedup and is 3974.3× higher energy efficiency compared to the state-of-the-art SAT attacks for logic unlocking. Huili Chen, Cheng Fu 0002, Jishen Zhao, Farinaz Koushanfar |
ICCAD | 1 |
| 2019 | PlaidML-HE: Acceleration of Deep Learning Kernels to Compute on Encrypted DataabstractMachine Learning as a Service (MLaaS) is becoming a popular practice where Service Consumers, e.g., end-users, send their data to a ML Service and receive the prediction outputs. However, the emerging usage of MLaaS has raised severe privacy concerns about users' proprietary data. PrivacyPreserving Machine Learning (PPML) techniques aim to incorporate cryptographic primitives such as Homomorphic Encryption (HE) and Multi-Party Computation (MPC) into ML services to address privacy concerns from a technology standpoint. Existing PPML solutions have not been widely adopted in practice due to their assumed high overhead and integration difficulty within various ML front-end frameworks as well as hardware backends. In this work, we propose PlaidML-HE, the first end-toend HE compiler for PPML inference. Leveraging the capability of Domain-Specific Languages, PlaidML-HE enables automated generation of HE kernels across diverse types of devices. We evaluate the performance of PlaidML-HE on different ML kernels and demonstrate that PlaidML-HE greatly reduces the overhead of the HE primitive compared to the existing implementations. Huili Chen, Rosario Cammarota, Felipe Valencia, Francesco Regazzoni 0001 |
ICCD | 1 |
| 2019 | DeepInspect: A Black-box Trojan Detection and Mitigation Framework for Deep Neural NetworksabstractDeep Neural Networks (DNNs) are vulnerable to Neural Trojan (NT) attacks where the adversary injects malicious behaviors during DNN training. This type of ‘backdoor’ attack is activated when the input is stamped with the trigger pattern specified by the attacker, resulting in an incorrect prediction of the model. Due to the wide application of DNNs in various critical fields, it is indispensable to inspect whether the pre-trained DNN has been trojaned before employing a model. Our goal in this paper is to address the security concern on unknown DNN to NT attacks and ensure safe model deployment. We propose DeepInspect, the first black-box Trojan detection solution with minimal prior knowledge of the model. DeepInspect learns the probability distribution of potential triggers from the queried model using a conditional generative model, thus retrieves the footprint of backdoor insertion. In addition to NT detection, we show that DeepInspect’s trigger generator enables effective Trojan mitigation by model patching. We corroborate the effectiveness, efficiency, and scalability of DeepInspect against the state-of-the-art NT attacks across various benchmarks. Extensive experiments show that DeepInspect offers superior detection performance and lower runtime overhead than the prior work. Huili Chen, Cheng Fu 0002, Jishen Zhao, Farinaz Koushanfar |
IJCAI | 1 |
| 2019 | DeepAttest: an end-to-end attestation framework for deep neural networksabstractEmerging hardware architectures for Deep Neural Networks (DNNs) are being commercialized and considered as the hardware-level Intellectual Property (IP) of the device providers. However, these intelligent devices might be abused and such vulnerability has not been identified. The unregulated usage of intelligent platforms and the lack of hardware-bounded IP protection impair the commercial advantage of the device provider and prohibit reliable technology transfer. Our goal is to design a systematic methodology that provides hardware-level IP protection and usage control for DNN applications on various platforms. To address the IP concern, we present DeepAttest, the first on-device DNN attestation method that certifies the legitimacy of the DNN program mapped to the device. DeepAttest works by designing a device-specific fingerprint which is encoded in the weights of the DNN deployed on the target platform. The embedded fingerprint (FP) is later extracted with the support of the Trusted Execution Environment (TEE). The existence of the pre-defined FP is used as the attestation criterion to determine whether the queried DNN is authenticated. Our attestation framework ensures that only authorized DNN programs yield the matching FP and are allowed for inference on the target device. DeepAttest provisions the device provider with a practical solution to limit the application usage of her manufactured hardware and prevents unauthorized or tampered DNNs from execution. Huili Chen, Cheng Fu 0002, Bita Darvish Rouhani, Jishen Zhao, Farinaz Koushanfar |
ISCA | 1 |
| 2019 | DeepMarks: A Secure Fingerprinting Framework for Digital Rights Management of Deep Learning ModelsabstractDeep Neural Networks (DNNs) are revolutionizing various critical fields by providing an unprecedented leap in terms of accuracy and functionality. Due to the costly training procedure, high-performance DNNs are typically considered as the Intellectual Property (IP) of the model builder and need to be protected. While DNNs are increasingly commercialized, the pre-trained models might be illegally copied or redistributed after they are delivered to malicious users. In this paper, we introduce DeepMarks, the first end-to-end collusion-secure fingerprinting framework that enables the owner to retrieve model authorship information and identification of unique users in the context of deep learning (DL). DeepMarks consists of two main modules: (i) Designing unique fingerprints using anti-collusion codebooks for individual users; and (ii) Encoding each constructed fingerprint (FP) in the probability density function (pdf) of the weights by incorporating an FP-specific regularization loss during DNN re-training. We investigate the performance of DeepMarks on various datasets and DNN architectures. Experimental results show that the embedded FP preserves the accuracy of the host DNN and is robust against different model modifications that might be conducted by the malicious user. Furthermore, our framework is scalable and yields perfect detection rates and no false alarms when identifying the participants of FP collusion attacks under theoretical guarantee. The runtime overhead of retrieving the embedded FP from the marked DNN can be as low as 0.056%. Huili Chen, Bita Darvish Rouhani, Cheng Fu 0002, Jishen Zhao, Farinaz Koushanfar |
ICMR | 1 |
| 2019 | Coda: An End-to-End Neural Program DecompilerabstractReverse engineering of binary executables is a critical problem in the computer security domain. On the one hand, malicious parties may recover interpretable source codes from the software products to gain commercial advantages. On the other hand, binary decompilation can be leveraged for code vulnerability analysis and malware detection. However, efficient binary decompilation is challenging. Conventional decompilers have the following major limitations: (i) they are only applicable to specific source-target language pair, hence incurs undesired development cost for new language tasks; (ii) their output high-level code cannot effectively preserve the correct functionality of the input binary; (iii) their output program does not capture the semantics of the input and the reversed program is hard to interpret. To address the above problems, we propose Coda1, the first end-to-end neural-based framework for code decompilation. Coda decomposes the decompilation task into of two key phases: First, Coda employs an instruction type-aware encoder and a tree decoder for generating an abstract syntax tree (AST) with attention feeding during the code sketch generation stage. Second, Coda then updates the code sketch using an iterative error correction machine guided by an ensembled neural error predictor. By finding a good approximate candidate and then fixing it towards perfect, Coda achieves superior with performance compared to baseline approaches. We assess Coda’s performance with extensive experiments on various benchmarks. Evaluation results show that Coda achieves an average of 82% program recovery accuracy on unseen binary samples, where the state-of-the-art decompilers yield 0% accuracy. Furthermore, Coda outperforms the sequence-to-sequence model with attention by a margin of 70% program accuracy. Our work reveals the vulnerability of binary executables and imposes a new threat to the protection of Intellectual Property (IP) for software development. Cheng Fu 0002, Huili Chen, Haolan Liu, Yuandong Tian, Farinaz Koushanfar, Jishen Zhao |
NeurIPS | 2 |
| 2017 | Face Forward: Detecting Mind Wandering from Video During Narrative Film Comprehension
Angela Stewart, Nigel Bosch, Huili Chen, Patrick J. Donnelly, Sidney K. D'Mello |
AIED | 3 |
| 2017 | BioChipWork: Reverse Engineering of Microfluidic BiochipsabstractMicrofluidic biochip is an emerging platform that has wide applications in areas of immunoassays, DNA sequencing and point-of-care health service. This paper presents BioChipWork, the first practical framework for automatic reverse engineering and IP piracy of microfluidic biochips. Our work targets two types of presently available microfluidic biochips which are characterized based on working mechanisms: flow-based microfluidic biochip (FMFB) and droplet-based microlfuidic biochip (DMFB). More specifically, BioChipWork identifies two practical sets of reverse engineering attacks and demonstrates the attacks using our developed algorithm and an open source synthesis tool. In the first attack, the attacker extracts the hardware layout of the pertinent FMFB based on image analysis. In the second attack, the attacker reconstructs the proprietary protocol mapped onto the DMFB by analyzing the actuation sequence or the video frames recorded by the CCD camera. The proposed reverse engineering attacks are non-intrusive, scalable and easy to implement, rendering the IP of authentic owners in danger. As countermeasures to obscure the functional layout and reduce information leakage from side-channels, we suggest novel biochip camouflaging and obfuscation techniques. Huili Chen, Seetal Potluri, Farinaz Koushanfar |
ICCD | 1 |
| 2017 | Improving Identification of Key Players in Aging via Network De-Noising and Core InferenceabstractCurrent "ground truth" knowledge about human aging has been obtained by transferring aging-related knowledge from well-studied model species via sequence homology or by studying human gene expression data. Since proteins function by interacting with each other, analyzing protein-protein interaction (PPI) networks in the context of aging is promising. Unlike existing static network research of aging, since cellular functioning is dynamic, we recently integrated the static human PPI network with aging-related gene expression data to form dynamic, age-specific networks. Then, we predicted as key players in aging those proteins whose network topologies significantly changed with age. Since current networks are noisy , here, we use link prediction to de-noise the human network and predict improved key players in aging from the de-noised data. Indeed, de-noising gives more significant overlap between the predicted data and the "ground truth" aging-related data. Yet, we obtain novel predictions, which we validate in the literature. Also, we improve the predictions by an alternative strategy: removing "redundant" edges from the age-specific networks and using the resulting age-specific network "cores" to study aging. We produce new knowledge from dynamic networks encompassing multiple data types, via network de-noising or core inference, complementing the existing knowledge obtained from sequence or expression data. Boyoung Yoo, Fazle Elahi Faisal, Huili Chen, Tijana Milenkovic |
IEEE ACM Trans. Comput. Biol. Bioinform. | 3 |
| 2016 | Where's Your Mind At?: Video-Based Mind Wandering Detection During Film ViewingabstractMind wandering (MW) is a ubiquitous phenomenon in which attention involuntarily shifts from task-related processing to task-unrelated thoughts. This study reports preliminary results of a video-based MW detector during film viewing. We collected training data in a study where participants self-reported when they caught themselves MW over the course of watching a 32.5 minute commercial film. We trained classification models on automatically extracted facial features and bodily movement and were able to detect MW with an F1 of .30. The model was successful in reproducing the MW distribution obtained from the self-reports Angela Stewart, Nigel Bosch, Huili Chen, Patrick J. Donnelly, Sidney K. D'Mello |
UMAP | 3 |
| 2016 | Exploring the structure and function of temporal networks with dynamic graphletsabstractBioinformatics, (2015) 31(12): i171–i180 doi: 10.1093/bioinformatics/btv227 The authors wish to correct the following error in the above article: in the legend of figure 1, a sentence in the legend reads, ‘But there are two orbits in graphlet G2, as the two end nodes are topologically identical to each other but not to the middle node (and vice versa)’, this should be corrected to, ‘But there are two orbits in graphlet G1, as the two end nodes are topologically identical to each other but not to the middle node (and vice versa)’. The authors apologize for this error. Yuriy Hulovatyy, Huili Chen, Tijana Milenkovic |
Bioinform. | 2 |
| 2015 | Accuracy vs. Availability Heuristic in Multimodal Affect Detection in the WildabstractThis paper discusses multimodal affect detection from a fusion of facial expressions and interaction features derived from students' interactions with an educational game in the noisy real-world context of a computer-enabled classroom. Log data of students' interactions with the game and face videos from 133 students were recorded in a computer-enabled classroom over a two day period. Human observers live annotated learning-centered affective states such as engagement, confusion, and frustration. The face-only detectors were more accurate than interaction-only detectors. Multimodal affect detectors did not show any substantial improvement in accuracy over the face-only detectors. However, the face-only detectors were only applicable to 65% of the cases due to face registration errors caused by excessive movement, occlusion, poor lighting, and other factors. Multimodal fusion techniques were able to improve the applicability of detectors to 98% of cases without sacrificing classification accuracy. Balancing the accuracy vs. applicability tradeoff appears to be an important feature of multimodal affect detection. Nigel Bosch, Huili Chen, Sidney K. D'Mello, Ryan Baker 0001, Valerie J. Shute |
ICMI | 2 |
| 2015 | Exploring the structure and function of temporal networks with dynamic graphletsabstractMOTIVATION: With increasing availability of temporal real-world networks, how to efficiently study these data? One can model a temporal network as a single aggregate static network, or as a series of time-specific snapshots, each being an aggregate static network over the corresponding time window. Then, one can use established methods for static analysis on the resulting aggregate network(s), but losing in the process valuable temporal information either completely, or at the interface between different snapshots, respectively. Here, we develop a novel approach for studying a temporal network more explicitly, by capturing inter-snapshot relationships. RESULTS: We base our methodology on well-established graphlets (subgraphs), which have been proven in numerous contexts in static network research. We develop new theory to allow for graphlet-based analyses of temporal networks. Our new notion of dynamic graphlets is different from existing dynamic network approaches that are based on temporal motifs (statistically significant subgraphs). The latter have limitations: their results depend on the choice of a null network model that is required to evaluate the significance of a subgraph, and choosing a good null model is non-trivial. Our dynamic graphlets overcome the limitations of the temporal motifs. Also, when we aim to characterize the structure and function of an entire temporal network or of individual nodes, our dynamic graphlets outperform the static graphlets. Clearly, accounting for temporal information helps. We apply dynamic graphlets to temporal age-specific molecular network data to deepen our limited knowledge about human aging. AVAILABILITY AND IMPLEMENTATION: http://www.nd.edu/∼cone/DG. Yuriy Hulovatyy, Huili Chen, Tijana Milenkovic |
Bioinform. | 2 |
| 2014 | Resonator in Two Dimensional Photonic Crystal Structure with Square Lattice by Metallic PillarsabstractMeasurement of cavity in two-dimensional square-lattice photonic crystal structure composed of metallic pillars was done to investigate its fundamental resonance characteristics. For consideration of confinement of the propagating electromagnetic field, the structure with dielectric pillars are also measured. Both of the results showed good agreement with the propagation constant of rectangular waveguide with metallic walls. Implementation of the resonance based on another measurement of phase and wavelength along with the propagation axis could explain the resonance clearly. Hiroshi Maeda, Kiyotoshi Yasumoto, Huili Chen, Daichi Ogata, Kazuya Tomiura |
CISIS | 3 |