VLDB 2026 Research / reviewers in the wild / expert
Huifeng Zhu
dblp:125/7489
· DBLP profile ↗
12ranked-venue papers
4as first author
10since 2021 · last 2026
0000-0002-0099-1911ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 9 · 3 first-author · 8 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | From ICs to Device: A Survey on Hardware Tampering Detection via Power Delivery Network and Signal TraceabstractProtecting the integrity of hardware against invasive tampering within the supply chain is critical to ensuring overall system resilience, reliability, and trustworthiness. As electronic systems become increasingly complex and globally distributed, the risk of malicious modifications or unauthorized alterations to hardware components continues to grow. In this survey, we provide a comprehensive exploration of detection and mitigation strategies for invasive hardware tampering across multiple levels of the hardware stack. We consider threats at various granularities–from individual on-board integrated circuits (ICs), to Printed Circuit Board Assemblies (PCBAs), and up to complete end-user devices. Our focus centers on three primary categories of invasive tampering: hardware Trojans, counterfeit components, and physical manipulations. A key emphasis of this survey is on hardware security techniques that leverage alterations in electrical characteristics induced by tampering. These include changes in power delivery network (PDN), signal trace, and other low-level electrical pathways. Such variations often serve as sensitive indicators of physical intrusions or modifications and are particularly useful for monitoring hardware integrity throughout its lifecycle–from manufacturing and deployment to maintenance and eventual decommissioning. We examine both golden-reference-based and golden-free detection approaches, highlighting their operational principles, design tradeoffs, and applicability in different threat scenarios. Furthermore, we survey evaluation methodologies and metrics used to assess the effectiveness, scalability, and robustness of these techniques. This article aims at providing a unified and up-to-date overview of detection research framework based on electrical characteristic variation, offering critical insights for researchers and practitioners working to safeguard hardware systems against invasive tampering and supply chain threats. Minqing Sun, Lanqi Ding, Huifeng Zhu, Yier Jin, An Zou |
ACM Trans. Design Autom. Electr. Syst. | 3 |
| 2025 | RT-VirtIO: Towards the Real-Time Performance of VirtIO in a Two-Tier Computing ArchitectureabstractWith the popularity of virtualization technology, ensuring reliable I/O operations with timing constraints in virtual environments becomes increasingly critical. Timing-predictable virtual I/O enhances the responsiveness and efficiency of virtualized systems, facilitating their seamless integration into time-critical applications such as industrial automation and robotics. Its significance lies in meeting rigorous performance standards, minimizing latency, and consistently delivering predictable I/O performance. As a result, virtual machines can effectively support mission-critical and time-sensitive workloads. However, due to the complicated system architecture, the I/O operations in virtualization face competition from tasks within the same virtual machine and those in different virtual machines who share the same host machine. This study presents RT-VirtIO, a practical approach to provide predictable real-time I/O operations. RT-VirtIO addresses the challenges associated with lengthy data paths and complex resource management. Through early-stage characterization, this study identifies key factors contributing to poor I/O real-time performance and then builds an analytical model and a learning-based data-driven model to predict the tail I/O latency. Leveraging these two models, RT-VirtIO effectively captures these dynamics, enabling the development of a general and applicable optimization framework. Experimental results demonstrate that RT-VirtIO significantly improves real-time performance in virtual environments (by 20.07% ~ 30.90%) without necessitating hardware modifications, which exhibit promising applicability across a broader range of scenarios. Siwei Ye, Minqing Sun, Huifeng Zhu, Yier Jin, An Zou |
DATE | 3 |
| 2025 | CacheGuardian: A Timing Side-Channel Resilient LLC DesignabstractIn cloud computing environments, the last-level cache (LLC) shared by multiple tenants is frequently exploited through timing side-channel attacks, enabling unauthorized data leakage. To address this issue, various defense mechanisms have been proposed. However, existing works exhibit deficiencies in terms of performance overhead, coverage of attacks, and detection accuracy. In response to these challenges, we propose CacheGuardian, a hardware-based LLC protection design which aims to provide stronger, broader, and more accurate protection against timing side-channel attacks with low performance overhead. It includes: (1) A behavior-based, generic attack detector capable of identifying multiple timing side-channel attacks in real time; (2) A cache-set-level access control mechanism that strictly restricts cache usage exclusively for the identified attackers instead of influencing all security domains.We implement our design in a gem5 simulator to evaluate both its security and performance. Our proof-of-concept attacks and SPEC 2017 benchmarks show that our design is effective against a wide range of timing side-channel attacks, reducing attack success rates by up to 256×, including camouflaged variants. Moreover, it improves the performance of benign workloads by an average of 2.26% with only 2.4% storage overhead. Ziang Zhou, Huifeng Zhu, Wei Yan 0005, Chenglu Jin, Xuejun An, Xiaochun Ye |
ICCAD | 4 |
| 2023 | PDNSig: Identifying Multi-Tenant Cloud FPGAs with Power Distribution Network-Based SignaturesabstractThe increasing use of Field Programmable Gate Arrays (FPGAs) in modern cloud data centers, such as Amazon's EC2 F1 instances, has led to a rising concern regarding remote side-channel attacks, which necessitates thorough investigation and analysis. Existing threat models crucially depend on a critical assumption: attackers could uniquely identify the target FPGA chip (or the specific die in a chip). However, this assumption is impractical in real cloud scenarios since security measures routinely implemented by cloud FPGA providers can anonymize the devices. To address this critical limitation, we propose PDNSig-a power distribution network (PDN)-based signature generation framework. By recognizing the complexity and irregularity of the PDN network and its susceptibility to process variation, we reveal that the impedance profile of an FPGA's PDN can uniquely distinguish different FPGAs. Particularly, we inject pseudo-random noises into the PDN by turning on or off power-hungry circuits (e.g., ring oscillators). The corresponding response of PDN is subsequently captured by on-chip sensors (e.g., time-to-digital converter), followed by a statistical analysis to obtain the PDN impedance at different frequencies. This proposed novel random process-based PDN measurement methodology can be directly applied to prior attack infrastructures with low hardware overhead. We perform thorough characterizations and demonstrate the effectiveness of PDNSig by conducting multiple real-world experiments on 40 Amazon cloud FPGA chips (including 120 dies). Experimental results show that the extracted PDN-based signatures can distinguish all 40 chips reliably. Additionally, a 99% true positive rate and 0.4% false positive rate are also achieved when identifying the 120 distinctive dies associated with these FPGA chips. Huifeng Zhu, Weidong Cao 0001, Xuan Zhang 0001 |
ICCAD | 1 |
| 2023 | PDNPulse: Sensing PCB Anomaly With the Intrinsic Power Delivery NetworkabstractThe ubiquitous presence of printed circuit boards (PCBs) in modern electronic systems and embedded devices makes their integrity a top security concern. To take advantage of the economies of scale, today’s PCB design and manufacturing are often performed by suppliers around the globe, exposing them to many security vulnerabilities along the segmented PCB supply chain. Moreover, the increasing complexity of the PCB designs also leaves ample room for numerous sneaky board-level attacks to be implemented throughout each stage of a PCB’s lifetime, threatening many electronic devices. In this paper, we proposePDNPulse, a power delivery network (PDN) based PCB anomaly detection framework that can identify a wide spectrum of board-level malicious modifications. PDNPulse leverages the fact that the PDN’s characteristics are inevitably affected by modifications to the PCB. By detecting changes to the PDN impedance profile against the golden model and using the Frechet distance-based anomaly detection algorithms, PDNPulse can robustly and successfully discern malicious modifications across the system. Using PDNPulse, we conduct extensive experiments on seven commercial-off-the-shelf PCBs, covering different design scales, different threat models, and seven different anomaly types. The results confirm that PDNPulse creates an effective security asymmetry between attack and defense. Huifeng Zhu, Haoqi Shan, Dean Sullivan, Xiaolong Guo 0001, Yier Jin, Xuan Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | PowerTouch: A Security Objective-Guided Automation Framework for Generating Wired Ghost Touch Attacks on TouchscreensabstractThe wired ghost touch attacks are the emerging and severe threats against modern touchscreens. The attackers can make touchscreens falsely report nonexistent touches (i.e., ghost touches) by injecting common-mode noise (CMN) into the target devices via power cables. Existing attacks rely on reverse-engineering the touchscreens, then manually crafting the CMN waveforms to control the types and locations of ghost touches. Although successful, they are limited in practicality and attack capability due to the touchscreens' black-box nature and the immense search space of attack parameters. To overcome the above limitations, this paper presents PowerTouch, a framework that can automatically generate wired ghost touch attacks. We adopt a software-hardware co-design approach and propose a domain-specific genetic algorithm-based method that is tailored to account for the characteristics of the CMN waveform. Based on the security objectives, our framework automatically optimizes the CMN waveform towards injecting the desired type of ghost touches into regions specified by attackers. The effectiveness of PowerTouch is demonstrated by successfully launching attacks on touchscreen devices from two different brands given nine different objectives. Compared with the state-of-the-art attack, we seminally achieve controlling taps on an extra dimension and injecting swipes on both dimensions. We can place an average of 84.2% taps on the targeted side of the screen, with the location error in the other dimension no more than 1.53mm. An average of 94.5% of injected swipes with correct directions is also achieved. The quantitative comparison with the state-of-the-art method shows that a better attack performance can be achieved by PowerTouch. Huifeng Zhu, Zhiyuan Yu 0001, Weidong Cao 0001, Ning Zhang 0017, Xuan Zhang 0001 |
ICCAD | 1 |
| 2021 | PCBench: Benchmarking of Board-Level Hardware Attacks and TrojansabstractMost modern electronic systems are hosted by printed circuit boards (PCBs), making them a ubiquitous system component that can take many different shapes and forms. In order to achieve a high level of economy of scale, the global supply chain of electronic systems has evolved into disparate segments for the design, fabrication, assembly, and testing of PCB boards and their various associated components. As a consequence, the modern PCB supply chain exposes many vulnerabilities along its different stages, allowing adversaries to introduce malicious alterations to facilitate board-level attacks. Huifeng Zhu, Xiaolong Guo 0001, Yier Jin, Xuan Zhang 0001 |
ASP-DAC | 1 |
| 2021 | Quantifying Rowhammer Vulnerability for DRAM SecurityabstractRowhammer is a memory-based attack that leverages capacitive-coupling to induce faults in modern dynamic random-access memory (DRAM). Over the last decade, a significant number of Rowhammer attacks have been presented to reveal that it is a severe security issue capable of causing privilege escalations, launching distributed denial-of-service (DDoS) attacks, and even runtime attack such as control flow hijacking. Moreover, the Rowhammer vulnerability has also been identified and validated in both cloud computing and data center environments, threatening data security and privacy at a large scale. Various solutions have been proposed to counter Rowhammer attacks but existing methods lack a circuit-level explanation of the capacitive-coupling phenomenon in modern DRAMs, the key cause of Rowhammer attacks.In this paper, we develop an analytical model of capacitive-coupling vulnerabilities in DRAMs. We thoroughly analyze all parameters in the mathematical model contributing to the Rowhammer vulnerability and quantify them through real DRAM measurements. We validate the model with different attributions on a wide range of DRAM brands from various manufacturers. Through our model we re-evaluate existing Rowhammer attacks on both DDR3 and DDR4 memory, including the recently developed TRRespass attack. Our analysis presents a new Rowhammer attack insight and will guide future research in this area. Huifeng Zhu, Dean Sullivan, Xiaolong Guo 0001, Xuan Zhang 0001, Yier Jin |
DAC | 2 |
| 2021 | Funnel Deep Complex U-Net for Phase-Aware Speech Enhancement
Linju Yang, Huifeng Zhu |
Interspeech | 3 |
| 2021 | System-level Early-stage Modeling and Evaluation of IVR-assisted Processor Power Delivery System
An Zou, Huifeng Zhu, Jingwen Leng, Xin He 0011, Vijay Janapa Reddi, Christopher D. Gill, Xuan Zhang 0001 |
ACM Trans. Archit. Code Optim. | 2 |
| 2019 | When Capacitors Attack: Formal Method Driven Design and Detection of Charge-Domain TrojansabstractThe rapid growth and globalization of the integrated circuit (IC) industry put the threat of hardware Trojans (HTs) front and center among all security concerns in the IC supply chain. Current Trojan detection approaches always assume HTs are composed of digital circuits. However, recent demonstrations of analog attacks, such as A2 and Rowhammer, invalidate the digital assumption in previous HT detection or testing methods. At the system level, attackers can utilize the analog properties of the underlying circuits such as charge-sharing and capacitive coupling effects to create information leakage paths. These new capacitor-based vulnerabilities are rarely covered in digital testings. To address these stealthy yet harmful threats, we identify a large class of such capacitor-enabled attacks and define them as charge-domain Trojans. We are able to abstract the detailed charge-domain models for these Trojans and expose the circuit-level properties that critically contribute to their information leakage paths. Aided by the abstract models, an information flow tracking (IFT) based solution is developed to detect charge-domain leakage paths and then identify the charge-domain Trojans/vulnerabilities. Our proposed method is validated on an experimental RISC microcontroller design injected with different variants of charge-domain Trojans. We demonstrate that successful detection can be accomplished with an automatic tool which realizes the IFT-based solution. Xiaolong Guo 0001, Huifeng Zhu, Yier Jin, Xuan Zhang 0001 |
DATE | 2 |
| 2012 | Context-dependent Deep Neural Networks for audio indexing of real-life dataabstractWe apply Context-Dependent Deep-Neural-Network HMMs, or CD-DNN-HMMs, to the real-life problem of audio indexing of data across various sources. Recently, we had shown that on the Switchboard benchmark on speaker-independent transcription of phone calls, CD-DNN-HMMs with 7 hidden layers reduce the word error rate by as much as one-third, compared to discriminatively trained Gaussian-mixture HMMs, and by one-fourth if the GMM-HMM also uses fMPE features. This paper takes CD-DNN-HMM based recognition into a real-life deployment for audio indexing. We find that for our best speaker-independent CD-DNN-HMM, with 32k senones trained on 2000h of data, the one-fourth reduction does carry over to inhomogeneous field data (video podcasts and talks). Compared to a speaker-adaptive GMM system, the relative improvement is 18%, at very similar end-to-end runtime. In system building, we find that DNNs can benefit from a larger number of senones than the GMM-HMM; and that DNN likelihood evaluation is a sizeable runtime factor even in our wide-beam context of generating rich lattices: Cutting the model size by 60% reduces runtime by one-third at a 5% relative WER loss. Gang Li 0012, Huifeng Zhu, Gong Cheng 0005, Kit Thambiratnam, Behrooz Chitsaz, Dong Yu 0001, Frank Seide |
SLT | 2 |