VLDB 2026 Research / reviewers in the wild / expert
Cuiping Shao
dblp:159/2842
· DBLP profile ↗
10ranked-venue papers
6as first author
5since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 4 first-author · 2 since 2021Security and privacy · 4 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Adaptive sensor attack detection and defense framework for autonomous vehicles based on density
Zujia Miao, Cuiping Shao, Huiyun Li, Yunduan Cui |
Comput. Secur. | 2 |
| 2025 | Transient Fault Detection and Failure Effect Analysis Based on Design for Test and Fault Tree Analysis for Automotive ChipsabstractAutomotive-grade chips play a crucial role in the development of intelligent networked vehicles, and functional safety is a key issue of automotive-grade chips. Transient faults induced by high-energy particle radiation affect the functional safety of automotive-grade chips significantly and may lead to catastrophic accidents. Currently, research on transient faults and chip functional safety, both domestically and internationally, remains relatively fragmented, with a clear lack of comprehensive functional safety analysis and testing methods for transient faults. Requirements for the analysis of transient faults are included in the ISO 26262 standard on applications to semiconductors. This paper integrates fault probability, circuit structure, and safety objectives into the analysis and testing of transient faults, enabling the accurate identification of vulnerable components solely related to functional safety during the design phase and quantifying their safety impact. During the testing phase, the thesis focuses solely on testing the vulnerable components identified during the design phase and prioritizes test patterns based on the contribution of each test pattern, allowing for the rapid identification of safety vulnerabilities through a limited number of test patterns in the testing phase. The experimental results demonstrate that our proposed method is capable of accurately detecting transient faults associated with safety. By utilizing only 452 screened and optimized test patterns, the test results have attained a coverage rate of 97.16%. This signifies a notable 56.3% enhancement in test efficiency, with a minimal and insignificant loss of just 1.7% in coverage. Cuiping Shao, Xinhua Luo, Huiyun Li |
IEEE Trans. Circuits Syst. I Regul. Pap. | 1 |
| 2025 | A Novel Lattice-Based Fault Injection Attack Targeting the Nonce in the SM2 Digital Signature AlgorithmabstractIn embedded systems, particularly resource-constrained Internet of Things (IoT) devices, the SM2 Digital Signature Algorithm (SM2-DSA) standard is widely deployed for cryptographic security. While fault injection attacks can compromise digital signatures and extract private keys without physical damage, traditional approaches require precise temporal or spatial control, resulting in limited success rates and revealing insufficient research into the potential vulnerabilities of SM2-DSA. To address this issue, this article introduces a novel and efficient lattice-based fault attack method targeting SM2-DSA. The method involves injecting faults into the nonce before the fourth step of the signature operation. By leveraging both the correct and erroneous intermediate values of Q obtained from the signature and verification processes, we can deduce partial bits of the nonce. Following this, we construct a lattice attack to recover the private key. Additionally, we establish the theoretical security boundary for lattice attack against SM2-DSA. Building upon the boundary, we propose an efficient implementation scheme for the attack. Experimental results demonstrate a 100% success rate over 1,000 trials, using 61 signatures with six known bits of nonces for 256-bit SM2-DSA, with each recovery process completed in under three seconds. Finally, we propose countermeasures against this attack. Our proposed attack reveals potential security vulnerabilities in SM2-DSA implementations, providing constructive guidance for enhancing algorithmic security measures and defensive countermeasures. Cuiping Shao, Huiyun Li, Jianing Liang |
ACM Trans. Embed. Comput. Syst. | 1 |
| 2024 | Probabilistic Model-Based Reinforcement Learning Unmanned Surface Vehicles Using Local Update Sparse Spectrum ApproximationabstractIn this article, we focus on the computational efficiency of probabilistic model-based reinforcement learning (MBRL) in unmanned surface vehicles (USV) under unforeseeable and unobservable external disturbances. A novel MBRL approach, local update spectrum probabilistic model predictive control (LUSPMPC), is proposed to fully release the superiority of the probabilistic model approximated in the frequency domain in computational efficiency while mitigating its risk of overfitting during the learning procedure. It employs a local update strategy to relieve the violation of Bochner's theory, and a frequency clipping trick to encourage the approximated model to focus on the features in the low-frequency domain. Evaluated by the position-keeping task in a real USV data-driven simulation, LUSPMPC shows its significant advantages in computational efficiency while achieving better learning capability, generalization capability, and control performances in a wide range of sparse scales compared with the baseline MBRL approaches that approximate their models in sample space and frequency domain, and therefore becomes an appealing solution for MBRL USV system defending against rapidly changing ocean disturbances. Yunduan Cui, Huan Yang 0001, Cuiping Shao, Lei Peng 0002, Huiyun Li |
IEEE Trans. Ind. Informatics | 4 |
| 2022 | Efficient SM2 Hardware Design for Digital Signature of Internet of VehiclesabstractThe rapid development of the Internet of Vehicles (IoV) provides a strong technical guarantee for intelligent transportation, greatly facilitating people's daily travel. At the same time, its security problems are becoming increasingly prominent. Fortunately, the cryptographic integrated circuits (ICs) provide a security guarantee for the IoV access authentication, traffic management, data communication, etc., which is the core and cornerstone of the IoV cryptographic technology. However, the IoV has high requirements for timeliness, and its communication resources are precious, so its necessary to ensure that the overhead of the cryptographic module is small and the delay is low. In this paper, we adopt SM2 Elliptic Curve Public Key Digital Signature Algorithm-with fast operation speed and short signature data to implement cryptographic ICs. We design and optimize its hardware design to balance overhead and efficiency. Based on the Montgomery point multiplication algorithm in Lopez-Dahab (LD) projection coordinates, we have researched the core point multiplication operation in SM2 and optimized the time-consuming operation in finite fields, which improved the computational efficiency of SM2. Finally, we completed the hardware design of SM2 on GF(2233) domain and verified it on a Xilinx Kintex-7 FPGA development board. The experiment results show that the design occupies a total of 77,665 Slice LUTs and merely takes 2.57 μs to complete a signature verification. The signature verification rate is 389,105 times/s. Compared with traditional solutions, our proposed method achieves less overhead and little latency. Huiyun Li, Cuiping Shao |
TrustCom | 4 |
| 2019 | Detecting Fault Injection Attacks Based on Compressed Sensing and Integer Linear ProgrammingabstractCryptographic ICs have been widely applied to numerous security-critical environments nowadays. Fault injection has become a serious attack on cryptographic IC, especially soft-errors or single event upsets (SEUs) by fine-resolution fault injection attacks. Detection and tamper evidence of these attacks become important. Traditional SEU diagnose methods usually require special sensors embedded into the circuits. However, these methods require non-trivial design and test effort, and usually just yield statistic results. In this paper, we formulate the detection fault injection attacks as a compressed sensing problem, due to sparsity of soft errors. Besides, due to the binary characteristic of the coefficient matrix and the variables, integer linear programming is adopted to reconstruct the soft error signals. Simulation results on a cryptographic IC demonstrate that the proposed method is capable to accurately detect the locations of soft-errors caused by fault injection attacks with negligible hardware overhead. The abnormal test output of scan-chains can be tamper evidence of the fault injection attacks. Huiyun Li, Cuiping Shao, Zheng Wang 0027 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2019 | An Error Location and Correction Method for Memory Based on Data Similarity AnalysisabstractThe nanoscale CMOS technology has encountered severe reliability issues, especially in the on-chip memory. As the technology nodes keep shrinking, single-event upsets (SEUs) may encounter more frequent multiple-bit upsets (MBUs) per particle strike. The commonly used memory error correction methods, such as the single-error correction-double-error detection (SEC-DED) code, are no longer feasible. While the counterparts for multiple error correction codes (MECs) yield too costly overhead on delay and data redundancy, especially for MBUs in a word or a character, even with all bits upset, the error correcting ability of the existing error correcting methods is exceeded. In this paper, we introduce a novel block-based error detection and correction method for memory by analyzing the similarity of data. This method of error location and correction can cope with both single-word error (SWE) and multiple-word error (MWE), no matter how many corrupted bits of each word there are. Experimental results on the test system based on SRAM demonstrate that the proposed method can correct single-word-single-bit (SWSB), single-word-multiple-bit (SWMB), multiple-word-single-bit (MWSB), and multiple-word-multiple-bit (MWMB) errors. The proposed method based on block level greatly improved the correction ability with low redundancy, low decoding delay, and moderate complexity versus other homogeneous byte-level or bit-level protection methods. In particular, the detection and correction efficiency is more evident when the data size increases. Cuiping Shao, Huiyun Li, Jiayan Fang, Qihua Deng |
IEEE Trans. Very Large Scale Integr. Syst. | 1 |
| 2018 | Adaptive Balance of Quality-resources of Neural Networks with Principle Component AnalysisabstractDeep Neural Networks (DNNs) push the state-of-the-art in many machine learning applications, they often require millions of expensive floating-point operations for each input classification. This computation overhead limits the applicability of DNNs to low-power, embedded platforms and incurs high cost in data centers. In this paper, by exploiting the gap between the level of accuracy required by the applications/users and that provided by the computing system, we propose a model to balance the resource and quality of neural network with principal components analysis (PCA), which simplifies network structure (such as the number of input nodes and the number of network layers) by reducing the dimension of dataset and achieve diverse optimizations. The continuous iteration and optimization of the balance model can acquire the best balance of quality and resources of the neural network. As a result, the consumption of network resources is reduced to the greatest extent under the condition of satisfying the quality requirements. In this paper, a pedestrian recognition network is taken as an example. The results illustrate that the total number of network nodes is reduced by 69% while the recognition rate achieved (95.99%) can reach required level of recognition rate (95%), which is only 2% lower than the highest recognition rate (97.01%) of the original neural network of pedestrian recognition. Cuiping Shao, Huiyun Li, Jiayan Fang |
TENCON | 1 |
| 2018 | Identifying Single-Event Transient Location Based on Compressed SensingabstractSingle-event transients (SETs) have seriously deteriorated the reliability of integrated circuits (ICs), especially for those in mission- or security-critical applications. Detecting and locating SETs can be useful for fault analysis and design enhancement. Traditional methods of location identification of SETs usually require special sensors embedded into the circuits, or radiation scanning with fine resolutions over the surface for inspection. In this paper, we propose a method of location identification of SETs without sensors or image processing. We formulate location identification of SETs as a compressed sensing problem due to the sparsity and noncoherence observation. The simulation result on a cryptographic IC is demonstrated. The results illustrate that the proposed method has three advantages, compared to traditional SETs test methods: 1) the SETs sensitive area can be accurately identified; 2) the sampling rate is reduced by 64%; therefore, the test efficiency is largely enhanced with negligible hardware overhead; and 3) the method of location identification of SETs is robust to noise interference. Cuiping Shao, Huiyun Li |
IEEE Trans. Very Large Scale Integr. Syst. | 1 |
| 2017 | Fast and automatic security test on cryptographic ICs against fault injection attacks based on design for security testabstractFault injection attacks have constituted a serious threat against cryptographic integrated circuits (ICs). However, the security test nowadays is just sample test with workload statistics and experiences as the qualitative criterion, and results in costly, time‐consuming and error‐prone test procedures. This study presents a design for security test (DFST) method for cryptographic ICs against fault injection attacks. The DFST involves identifying the sensitive registers for various crypto modules, inserting the scan chains and generating the specific test patterns for security test. Then the security test is conducted on the manufactured cryptographic ICs with the industrial automatic test equipment. With this DFST method, a fast and automatic security test can be applied onto volume production of cryptographic ICs. Experimental results on an RSA implementation demonstrate the validity of this method. Cuiping Shao, Huiyun Li, Jianbin Zhou |
IET Inf. Secur. | 1 |