VLDB 2026 Research / reviewers in the wild / expert
Fan Zhang 0010
dblp:21/3626-10
· DBLP profile ↗
103ranked-venue papers
15as first author
73since 2021 · last 2026
0000-0001-6087-8243ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 34 · 2 first-author · 25 since 2021Systems, architecture and hardware · 26 · 7 first-author · 17 since 2021Computer networks · 12 · 1 first-author · 11 since 2021Applied, interdisciplinary, general and emerging computing · 12 · 4 first-author · 6 since 2021Databases, data management, data science and information retrieval · 10 · 8 since 2021Artificial intelligence and machine learning · 7 · 6 since 2021Software engineering, systems software and programming languages · 7 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 4 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MedLA: A Logic-Driven Multi-Agent Framework for Complex Medical Reasoning with Large Language ModelsabstractAnswering complex medical questions requires not only domain expertise and patient-specific information, but also structured and multi-perspective reasoning. Existing multi-agent approaches often rely on fixed roles or shallow interaction prompts, limiting their ability to detect and resolve fine-grained logical inconsistencies. To address this, we propose MedLA, a logic-driven multi-agent framework built on large language models. Each agent organizes its reasoning process into an explicit logical tree based on syllogistic triads (major premise, minor premise, and conclusion), enabling transparent inference and premise-level alignment. Agents engage in a multi-round, graph-guided discussion to compare and iteratively refine their logic trees, achieving consensus through error correction and contradiction resolution. We demonstrate that MedLA consistently outperforms both static role-based systems and single-agent baselines on challenging benchmarks such as MedDDx and standard medical QA tasks. Furthermore, MedLA scales effectively across both open-source and commercial LLM backbones, achieving state-of-the-art performance and offering a generalizable paradigm for trustworthy medical reasoning. Fan Zhang 0010, Jinlin Wu, Guohui Fan, Zelin Zang |
AAAI | 3 |
| 2026 | VQFlow: A Benchmark Dataset for Encrypted Video Streaming Traffic across QoS Configurations
Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Fan Zhang 0010 |
KDD (1) | 4 |
| 2026 | CHAMELEOSCAN: Demystifying and Detecting iOS Chameleon Apps via LLM-Powered UI Exploration
Haitao Xu 0002, Yanchen Lu, Mengxia Ren, Shuai Hao 0001, Chuan Yue, Zhao Li 0007, Fan Zhang 0010, Yixin Jiang |
NDSS | 9 |
| 2026 | RegimeGuard: Continual Learning Queue Scheduling for Socially Critical Web Services
Ziming Zhao 0008, Fan Zhang 0010 |
WWW | 3 |
| 2026 | DPF-PIR: a scheme of feasible two-server keyword PIR with logarithmic communication
Zi-Yuan Liang, Fan Zhang 0010, Bing-Sheng Zhang, Jian Liu 0012 |
Frontiers Comput. Sci. | 3 |
| 2026 | Portray learning: A novel learning paradigm for streaming emerging class detection
Ziming Zhao 0008, Zhaoxuan Li, Xiaofei Yue, Tingting Li 0004, Fan Zhang 0010 |
Inf. Sci. | 5 |
| 2026 | VCAlign: An Effective Method for the Removal of Random Delays by Vertical ClusteringabstractRandom Delay Insertion (RDI) is one of the most investigated types ofhidingcountermeasure. Multifarious approaches to compromise RDI have emerged over the past two decades, with a horizontal perspective considering waveform segment as a unit. Interestingly in this paper, we transform such traditional perspective to a novel vertical one and find that the distribution feature of samples extracted vertically exposures the existence of delays directly, which can be exploited for both RDI detection and measurements alignment. On this basis, we conceive a generic approach calledVCAlign, leveraging binary classification to align the measurements sample by sample vertically. This approach favors adversaries significantly since it requires no reference trace, no prior knowledge, no profiling stage. As a case study, we further propose a practical paradigm and evaluate it on several RDI-protected implementations on an ARM Cortex-M4 micro-controller. The experimental results demonstrate that VCAlign has a powerful capability to eliminate the delays completely while remaining the encryption-related segments, which can be regarded as an enhanced alignment solution to conquer RDI. We firmly believe that VCAlign is a valid application of instruction effects on physical leakage from the novel vertical perspective that could bring new vitality to the alignment solutions. Qianmei Wu, Chengdong Xie, Wei Cheng 0003, Fan Zhang 0010 |
IEEE Trans. Computers | 4 |
| 2026 | Side-Channel Leakage in Low-Entropy Masking Schemes Attributed to FPGA ArchitectureabstractMasking is one of the most popular to guarantee the security of the cryptographic implementation against side-channel analysis. Low Entropy Masking Scheme (LEMS) has been proposed to relieve the high overhead by reducing the entropy of the mask. The masks are selected carefully to resist univariate first-order attacks. However, in practice, securely implementing masking can be a challenging task. In this work, we exhibit the vulnerability of LEMS implementation on FPGA. Firstly, we provide the security model to characterize the masking balance at the implementation level. Based on the security model, we exhibit a first-order leakage in the netlist of the implementation. It can be proved that this defect is due to the uncontrollable EDA tool to optimize the AES Sbox implementation on the specific architecture of FPGA during synthesis. The discovered flaw can be exhibited by performing a couple of first-order attacks to recover the secret key successfully on FPGA. The vulnerability is verified by simulation and practical measurements. Finally, the potential countermeasure and security evaluation process for LEMS are provided to avoid leakage during the pre-silicon design phase. Yanbin Li 0001, Yikang Guo, Fan Zhang 0010 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2026 | Key in the Pocket: Intelligent Key Recovery With Genetic Algorithm in Correlation-Enhanced Collision AttacksabstractBy introducing collision information, the existing side-channel Correlation-Enhanced Collision Attacks (CECAs) performed collision-chain detection, quickly filtered out candidates unsatisfying collision conditions and extracted a part of optimal candidates for further process, thereby rapidly and significantly reducing the key candidate space and the difficulty of key recovery. However, they are still limited by disadvantages such as serial implementation, complex parameter settings and lack of intelligence, resulting in a low success rate of key recovery. To address these issues, we first present a Collision Detection framework with Genetic Algorithm (CDGA), which exploits Genetic Algorithm to detect the collision chains and has a strong capability of global searching. Secondly, we theoretically analyze the performance of CECA, and bound the searching depth of its output candidate vectors with a confidence level using a data-driven hypothesis test that provides confidence bounds for Gaussian leakages and an approximation based on Central Limit Theory (CLT)for non-Gaussian cases, which facilitates effective and stable population initialization. Thirdly, benefiting from our hypothesis-test-guided design, we propose a goal-directed mutation that prioritizes promising collision candidates, thus improving efficiency and adaptability of the CDGA. Finally, to optimize the evolution of CDGA, we introduce a roulette selection strategy to employ a probability assignment based on individual fitness values to guarantee the preferential selection of superior genes. Comprehensive experiments on DPA Contest v4.1 (AES-256 with Rotated S-boxes Masking) and an AT89S52 AES-128 platform demonstrate that CDGA achieves faster convergence and higher key-recovery success rates compared with TOC/FTC/FCC and Wiemers’ cumulative-correlation selection. Jiangshan Long, Changhai Ou, Kexin Qiao, Fan Zhang 0010, Debiao He |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 5 |
| 2026 | Approx-PSI: Efficient Differentially Private Set Intersection-Based AnalysisabstractThe Private Set Intersection (PSI) functionality is valuable which allows different organizations to collaborate in privacy-sensitive environments, and its intersection is highly valuable in analytics. With similar business interests, they can securely compute intersection and its associated values for insightful trends and patterns, which can be considered as intersection-based analysis. However, in such settings, existing PSI schemes are too costly or inadvertently leak sensitive information. Our proposed scheme, Approx-PSI, employs Oblivious Pseudo-Random Functions (OPRF) to provide two-party efficient PSI in a semi-honest model and introduces “noise” into the intersection through differential privacy (DP) to ensure individual privacy. Moreover, the noised intersection for approximate analysis has more flexibility and adaptability in both associated values and desired functions. Compared to existing schemes, Approx-PSI achieves at least$1.5 - 3 \times$faster than the most efficient prior protocols, and up to$77 - 81 \times$faster in certain settings, while reducing communication by at least 90%. Thus, the above benefits make our scheme more practical in the real-world. Ziyuan Liang, Fan Zhang 0010, Zhan Qin |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | Assessing and Improving DNN Robustness Against Adversarial Examples From the Perspective of Fully Connected LayersabstractRecent studies show that deep neural networks are extremely vulnerable, especially for adversarial examples of image classification models. However, existing defenses suffer from limited adaptability across attacks, an unfavorable tradeoff between clean accuracy and robustness, and substantial training-time overhead. To tackle these problems, we present a novel component, named the redundant fully connected layer, which can be combined with existing model backbones in a pluggable manner. Specifically, we design a tailor-made loss function for it that leverages cosine similarity to maximize the difference and diversity of multiple fully connected parts. We conduct extensive experiments against 12 representative attacks (white-box and black-box), based on two popular datasets. The empirical evaluations show that our scheme realizes significant outcomes against various attacks with negligible additional training overhead, while hardly bringing collateral damage for clean-instance accuracy. Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Fan Zhang 0010 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2026 | Enhanced Differential-Linear Cryptanalysis of Forró With MILPabstractARX-based design is a major building block of modern cryptographic ciphers due to its efficiency in software. Forró is an ARX-based stream cipher proposed by Coutinho et al. at ASIACRYPT 2022, which was designed to provide higher security margin than the ChaCha stream cipher. In this paper, we propose a full automated MILP model calledMinForró, to derive linear approximations for the Forró stream cipher. For the differential part, a two-stage strategy to search for single-bit differential trails with high differential correlations is presented, which helps us to find the first-ever 3-round differential trails for Forró. By combining the linear approximations obtained byMinForróand 3-round differential trail for Forró, we propose improved differential-linear distinguishers for 4-, 5-, 5.25-, 5.5-, 5.75-, 6-, 6.25- and 6.5-round Forró with complexities 232.44, 246, 250, 264.32, 287.12, 2117.92, 2174.92and 2226.88, respectively. The proposed differential-linear distinguishers for 4-, 5-, 5.25- and 5.5- round Forró significantly improve the existing distinguishers by factors of 24.11, 283.68, 2127.64and 2178.20, respectively. To the best of our knowledge, this is the first differential-linear distinguisher for Forró that reaches 6.5 rounds, which is a significant advancement over the existing record of 5.5 rounds. We have implemented the differential-linear distinguishers for 4- and 5- round Forró on a common PC, and the experimental results confirm the correctness of these distinguishers. Furthermore, when combined with theProbabilistic Neutral Bits(PNB) technique, we obtain key recovery attacks on 5.5-, 6-, 6.5- and 6.75-round Forró with time complexities 2149.20, 2151.84, 2213.49and 2251.97, respectively. The proposed key recovery attack on 5.5-round Forró significantly improves the time complexity of the existing attack by a factor of 275.84. To the best of our knowledge, this is the first key recovery attack on Forró that reaches 6.75 rounds, which is a significant advancement over the existing record of 5.5 rounds. Zhengting Li, Lin Ding 0001, Jiang Wan, Fan Zhang 0010 |
IEEE Trans. Inf. Theory | 6 |
| 2026 | SOFA: Service-Oriented Fine-Grained Attack Traffic Detection With Meta LearningabstractEnterprise networks face an ever-growing threat from various unknown cyberattacks originating from the Internet. Anomaly-based Network Intrusion Detection Systems (NIDS) have become essential for safeguarding corporate networks, but existing technologies have some limitations in practice. (i) The interweaving of traffic from different service types increases the difficulty of identification. (ii) The scarcity of labeled malicious samples hinders the detection of both known and emerging threats. To tackle these issues, we propose a service-oriented approach to model benign traffic and leverage meta-learning to construct a robust metric space for precise sample comparison. Based on this, we develop SOFA, a two-stage traffic detection framework. In the first stage, SOFA identifies distinct service types within the network and trains independent one-class models for each, ensuring service-specific attack traffic is detected with high precision. The second stage employs a ResNet-based Siamese network to overcome the limitations posed by scarce malicious samples, enhancing detection of both known and emerging attacks. We evaluate SOFA on four widely used network tracing datasets, demonstrating that it achieves state-of-the-art performance and significantly outperforms a diverse set of existing methods in fine-grained attack detection. These results highlight the potential of SOFA for improving network security in a highly dynamic and unbalanced threat environment. Feiyang Huang, Ziming Zhao 0008, Fan Zhang 0010, Wenrui Ma |
IEEE Trans. Netw. | 4 |
| 2026 | TNT: A Large-Scale P2P Botnet Detection Framework via Communication Topology and Network TrafficabstractWith the booming development of embedded systems and mobile networks, the attack surfaces of botnets are broadened and amplified. Especially recent adversaries tend to leverage peer-to-peer (P2P) manner propagation to construct large-scale botnets because P2P-based schemes eliminate single points of failure. Over the past few decades, the research and industry communities have proposed a variety of solutions to detect botnets, which mainly involve communication topology identification and network traffic analysis. Yet, coping with the large-scale P2P botnets, the former suffer topology indistinguishability, and the latter struggles under massive background traffic. In this paper, we present$\textsf {TNT}$, a large-scale P2P botnet detection framework via communication topology and network traffic. As its core,$\textsf {TNT}$is powered by three tightly-coupled components:$\textsf {(i)}$$\textsf {tScouter}$is responsible for profiling the communication topology;$\textsf {(ii)}$$\textsf {tCommander}$plans the strategy for node inspection; and$\textsf {(iii)}$$\textsf {tPatroller}$investigates the traffic of the corresponding node. Taken together,$\textsf {TNT}$advances the trade-off between detection accuracy (enhance topology-based results via traffic analysis) and overhead (only check part of node traffic according to the planning). Based on 42 groups of combinations involving 6 types of botnets and 7 legitimate P2P traffic, we perform extensive evaluation and demonstrate that$\textsf {TNT}$realizes outstanding detection performance,e.g.,after checking ~20K nodes, achieve ~99.9% accuracy for a communication graph (including >140K nodes). In addition, we develop the expansion experiments in terms of heterogeneous nodes and accuracy loss, as well as provide deep insights into interpretability from the aspect of the attribution matrix. Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Yu Li 0007, Qiang Xu 0001, Fan Zhang 0010 |
IEEE Trans. Netw. | 7 |
| 2025 | CyberLLM: Enable Mapping CVE to Tactics and Techniques of Cyber Threats via LLM
Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Fan Zhang 0010 |
DASFAA (5) | 4 |
| 2025 | Understanding PII Leakage in Large Language Models: A Systematic SurveyabstractLarge Language Models (LLMs) have demonstrated exceptional success across a variety of tasks, particularly in natural language processing, leading to their growing integration into numerous facets of daily life. However, this widespread deployment has raised substantial privacy concerns, especially regarding personally identifiable information (PII), which can be directly associated with specific individuals. The leakage of such information presents significant real-world privacy threats. In this paper, we conduct a systematic investigation into existing research on PII leakage in LLMs, encompassing commonly utilized PII datasets, evaluation metrics, and current studies on both PII leakage attacks and defensive strategies. Finally, we identify unresolved challenges in the current research landscape and suggest future research directions. Zhao Li 0007, Shu Meng, Mengxia Ren, Haitao Xu 0002, Shuai Hao 0001, Chuan Yue, Fan Zhang 0010 |
IJCAI | 8 |
| 2025 | Understanding the Business of Online Affiliate Marketing: An Empirical StudyabstractAffiliate marketing is a revenue-sharing marketing scheme by which an affiliate, such as a blogger or YouTuber, garners commissions for promoting a merchant's goods or services, thereby aiming to foster a mutually beneficial relationship between affiliates and merchants. Despite being a multi-billion-dollar global industry, affiliate marketing remains inadequately explored, and the research community lacks a comprehensive understanding of its intricate ecosystem. In this paper, we present the first comprehensive empirical study of the affiliate marketing ecosystem. We conduct thorough measurements to assess the prevalence of affiliate marketing, estimate the market size, and elucidate the characteristics of affiliates, merchants, and intermediary affiliate networks. Over a continuous span of 13 months, we monitored four of the most prominent affiliate aggregation platforms, yielding a substantial dataset. We observed 467,219 unique offers - tasks to be undertaken by affiliates - involving 37,109 merchants and 556 affiliate networks across the four platforms. Notably, these offers would cost the merchants more than 19 million USD for the completion of all the actions pre-defined in these offers, such as signing up or making a transaction. Additionally, we compiled a large-scale dataset comprising 124,462 affiliate links, enabling us to conduct a comprehensive investigation. Finally, we propose machine learning models incorporating the characteristics of affiliate links to detect real-world affiliate marketing campaigns. Haitao Xu 0002, Kaleem Ullah Qasim, Shuai Hao 0001, Wenrui Ma, Zhenyuan Li, Fan Zhang 0010, Zhao Li 0007 |
INFOCOM | 7 |
| 2025 | Towards Context-Aware Traffic Classification via Time-Wavelet Fusion Network
Ziming Zhao 0008, Zhuoxue Song, Xiaofei Xie, Zhaoxuan Li, Jiongchi Yu, Fan Zhang 0010, Tingting Li 0004 |
KDD (1) | 6 |
| 2025 | Stealthy-AE: Generating Stealthy Adversarial Examples through Online Social Networks
Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Fan Zhang 0010 |
ACM Multimedia | 4 |
| 2025 | Effective PII Extraction from LLMs through Augmented Few-Shot Learning
Shu Meng, Haitao Xu 0002, Shuai Hao 0001, Chuan Yue, Wenrui Ma, Fan Zhang 0010, Zhao Li 0007 |
USENIX Security Symposium | 9 |
| 2025 | Verify All Traffic: Towards Zero-Trust In-Network Intrusion Detection Against Multipath RoutingabstractWith the popularity of encryption protocols, machine learning (ML)-based traffic analysis technologies have attracted widespread attention. To adapt to modern high-speed bandwidth, recent research is dedicated to advancing zero-trust intrusion detection by offloading feature extraction and model inference into the network dataplane. Especially, with the rise of programmable switches, achieving line-speed ML inference becomes promising. However, existing research only considers a single switch node as a relay to conduct evaluation. This is far from real-world deployments involving multiple switches (given that zero-trust security assumes that threats can originate from anywhere, including within the network), particularly the multi-path routing phenomenon that exists in practice. In this paper, we reveal practical challenges in the context of enabling line-speed model inference in the network dataplane. Furthermore, we propose FCPlane, the forwarding and computing integrated dataplane for zero-trust intrusion detection that aims to enable efficient load balancing while providing reliable traffic analysis results, even against multipath routing. The core idea is to reconcile forwarding and computation to the flowlet level, for which a tailor-made Markov chain model is designed. Based on two public traffic datasets, we evaluate seven state-of-the-art in-network traffic analysis models deployed in four types of topologies (three with multipath routing and one without) to explore performance impact and demonstrate the effectiveness of our proposal. Ziming Zhao 0008, Zhaoxuan Li, Xiaofei Xie, Tingting Li 0004, Jiongchi Yu, Fan Zhang 0010, Binbin Chen 0001 |
IEEE J. Sel. Areas Commun. | 7 |
| 2025 | MinMaxEntropy: Bound Model Errors for Side-Channel Leakages From Information TheoryabstractSide-channel attacks and evaluations have been incessantly pursuing an accurate leakage model and try to address the following question: “How good is my leakage model?” However, the existing works do not well alleviate the attackers and evaluators from model assumption error and estimation error. The recent work named maximum entropy distribution (MED) model does not depend on any assumptions but uses nonlinear programming Newton-Raphson method to fit the leakage distribution, thus avoiding assumption error and making the estimation error arbitrarily small. It tries to address a more fundamental problem: “How to achieve the optimal leakage model?,” but still have to face with two issues: 1) the large deviation of MED model from leakage distribution and 2) the difficulty in determining the moments required in model profiling. In this article, we first introduce the nonlinear programming optimizations Levenberg-Marquardt and Conjugate Gradient methods to tackle the first issue. We then exploit Hopfield neural network to solve the minimum entropy for leakage model. Unlike the MED indicating the theoretically most unbiased, objective and reasonable leakage model, the minimum entropy corresponds to the theoretically most biased, subjective and unreasonable leakage model. This facilitates us to build a MinMaxEntropy bound from the maximum entropy and minimum entropy for estimation errors in leakage model, which theoretically represents the amount of information contained on unused higher moments. This bound well provides theoretical support for the moments constraints required to profile the MED model, thus well tackling the second issue. Experimental results fully demonstrate the superiority of our above schemes. Changhai Ou, Zhenfang Qiu, Xingshuo Han, Fan Zhang 0010, Shihui Zheng, Fei Yan 0008 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2025 | HTs-GCN: Identifying Hardware Trojan Nodes in Integrated Circuits Using a Graph Convolutional NetworkabstractHardware Trojans (HTs) present significant security threats to integrated circuits. Detecting and locating HTs is crucial for mitigating these threats. Thus, this article proposes a method called HTs-GCN, which utilizes a graph convolutional network (GCN) to identify HTs. First, it extracts two novel features of gate nodes using a depth-first search strategy and topological logical analysis to enrich the feature information of circuit nodes. Second, through a message-passing mechanism, it designs a local feature aggregation method based on the GCN and a global feature fusion method based on an attention mechanism to improve the representation capability of circuit node features. Then, leveraging the concept of stochastic gradient descent and incorporating mini-batch oversampling and under-sampling techniques, it employs a dataset imbalance handling method to address the scarcity of HT nodes in circuits. These approaches significantly enhance the distinguishability between gate nodes with HTs and other gate nodes while reducing computational complexity. Experimental results indicate that HTs-GCN outperforms the recently proposed NHTD-GL method in terms of recall: it achieves approximately 7.8% points higher recall while maintaining similar accuracy. HTs-GCN demonstrates exceptional generalizability, with an average recall and accuracy of 93.0% and 100%, respectively, on infrequently used circuits in the Trust-Hub benchmark. In addition, on the TRIT-TC benchmark, HTs-GCN achieves excellent average true positive rate (TPR) and true negative rate (TNR) of 95.1% and 94.4%, respectively. Furthermore, HTs-GCN exhibits robust performance under gate modification attacks, with average TPR and TNR reaching 82.1% and 92.5%, respectively. Jie Xiao 0003, Shuiliang Chai, Yanjiao Gao, Fan Zhang 0010, Tieming Chen |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 5 |
| 2025 | A Deep Investigation on Stealthy DVFS Fault Injection Attacks at DNN Hardware AcceleratorsabstractWith increasing computation of various applications, dynamic voltage and frequency scaling (DVFS) is gradually deployed on FPGAs to improve performance and save energy. However, its reliability and security have not been sufficiently evaluated, which incurs quite many concerns. In this article, we propose an evaluation framework for deep investigation of stealthy DVFS fault injection attacks on the state-of-the-art deep neural networks (DNNs) deployed on modern FPGAs. The evaluation framework mainly consists of a DVFS attack striker and a time-to-digital converter (TDC)-based hardware profiler. Two modes of evaluation are derived, and their effectiveness is demonstrated on a platform composed of a SkyNet accelerator and three ImageNet models built on a Xilinx deep learning processor unit (DPU). Experimental results show that more than 99% detection accuracy loss can be measured targeting at all tested DNN models under prospective operation mode but without any performance degradation in frame per second (FPS). In our investigation of sensitive layer mode, more than 93% average accuracy loss with 84.7% fault probability can be measured on a single bundle of the SkyNet. We characterize the vulnerabilities of different DNN layers subject to DVFS attacks through leveraging the TDC-based hardware profiler to precisely control the timing of fault injection. Junge Xu, Fan Zhang 0010, Wenguang Jin, Kun Yang 0012, Zeke Wang, Weixiong Jiang, Yajun Ha |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2025 | Exploring the Internals of Fault-Induced Data-Level Vulnerabilities in Cryptographic LibrariesabstractFault-induced vulnerabilities have been studied in various aspects. While traditional fault injection techniques easily detect system-level vulnerabilities like buffer overflows, fault executions can introduce subtle potential vulnerabilities that may not trigger any system-level observable behaviors. These are particularly dangerous in cryptography. Using advanced cryptanalysis methods, these vulnerabilities, such as producing faulty ciphertexts, have been successfully exploited and are regarded as great threats to the security of real-world cryptography. In this way, there is a pressing need to study this very area. Our paper generally explores the internals of the fault-induced data-level vulnerabilities, which are subtle vulnerabilities resulting from faults that may not cause system crashes or overt errors but can expose sensitive information or weaken cryptographic primitives under specific cryptanalytic techniques, in cryptographic libraries. We propose a novel framework which can systematically analyze the vulnerabilities in cryptographic libraries under different fault models. By employing this method, we identified numerous critical fault locations that could undermine the security of cryptographic systems across a broad spectrum of libraries, fault models, and platforms. Furthermore, we provide a comprehensive analysis of select case studies, and engage in detailed discussions about the strategies to alleviate such vulnerabilities. Guorui Xu, Qianmei Wu, Fan Zhang 0010, Xinjie Zhao 0001, Shize Guo |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Defending Data Inference Attacks Against Machine Learning Models by Mitigating Prediction DistinguishabilityabstractNeural networks are vulnerable to data inference attacks, including the membership inference attack, the model inversion attack, and the attribute inference attack. In this paper, we proposePurifierto defend against membership inference attacks by quantifying the differences between dataset members and non-members in three dimensions: individual shape, statistical distribution, and prediction label.Purifierinvolves transforming the confidence scores produced by the target classifier, resulting in purified confidence scores that are indistinguishable across the dimensions above. We conduct experiments on widely-used datasets and models. The results show thatPurifieroffers robust defense against membership inference attacks with superior efficacy compared to prior defense techniques while maintaining minimal utility degradation (e.g., less than 0.7% classification accuracy drop of most datasets). Additionally, our extended experiments explore the effectiveness ofPurifierin defending against the model inversion attack and the attribute inference attack. Yiran Zhu, ChuXiao Xiang, Ruite Xu, Lijin Wang, Fan Zhang 0010, Jiarong Xu, Zhan Qin |
IEEE Trans. Dependable Secur. Comput. | 9 |
| 2025 | Key Schedule Guided Persistent Fault AttackabstractPersistent Fault Analysis(PFA) is a powerful analysis technique proposed in CHES 2018, which utilizes those faults that are injected before execution and persist throughout the encryption. However, when it is applied to the block cipher which has multiple S-boxes, the key cannot be recovered in just one attack. The adversary has to conduct the fault attack several times and inject faults into all the distinct S-boxes. In this paper, we proposeKey Schedule Guided Persistent Fault Attack(KGPFA), which utilizes the key schedule to guide the fault injection and fault analysis. By analyzing the key schedule, KGPFA exploits the relations between the key leakages caused by the same faulty S-box in various rounds. It can reduce the number of attacks and the number of faults required to recover the key. Our major contributions are twofold. Firstly, in the fault injection step, we provideKey Schedule Guided Persistent Fault Injection(KGPFI) strategies to reduce the number of attacks and the number of faults under the assumption of both ciphertext-only and known-plaintext attacks. Secondly, in the fault analysis step, as our target ciphers are Feistel-based, we propose theIneffective Algebraic Persistent Fault Analysis(IAPFA) to extend the usage ofAlgebraic Persistent Fault Analysis(APFA) in the ineffective persistent fault setting. To demonstrate the effectiveness of our technique, we apply KGPFA to four widely used block ciphers with multiple S-boxes, DES, 3DES, LBlock, and Camellia. In our experiment, in the ciphertext-only attack, the key of DES can be recovered with 300 ineffective ciphertexts (coresponding to 827 ciphertexts) and four faulty S-boxes within 12.18min. Under the assumption of known-plaintext, the key of DES is recovered within two faulty S-boxes in 2.34h. For LBlock, the key is recovered with two faulty S-boxes and 100 ineffective ciphertexts (coresponding to 6211 ciphertexts) in 1.16min. Fan Zhang 0010, Xinjie Zhao 0001, Jie Xiao 0003, Shize Guo |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | The Mysteries of LRA: Roots and Progress in Side-Channel ApplicationsabstractEvaluating cryptographic implementations with respect to side-channel analysis (SCA) has been mandated at high security levels. Typically, the evaluation involves four stages: detection, modeling, certification and recovery. In pursuit of a specific goal at each stage, inherently different techniques were previously considered necessary. However, since the recent Eurocrypt 2022 and Eurocrypt 2024, linear regression analysis (LRA) has become the unique technique well-applied throughout all the stages. In this paper, we concentrate on this “silver bullet” technique within the field of SCA. In the first part of this paper, we answer three fundamental questions organized progressively. The first one relates to “why use LRA?”. Our discussion of the nominal and binary nature elucidates its critical role in underpinning the state-of-the-art techniques. Having understood the merits, a natural follow-up is “how to use it (correctly and effectively)?”. A theoretical analysis of the design matrix is provided, regarding the sample distribution of plaintext and the chosen degree of polynomial. We summarize the conditions for eliminating multicollinearity, a problem that can be harmful to all LRA-based techniques. The last question “who should use LRA?” reveals an intriguing evaluator-advantageous property: LRA can only unleash its full potential when the key is known. In the second part of this paper, we clarify the connections between LRA and traditional SCA techniques. Our proofs provide new insights into the prior investigation of SCA reduction, fostering a comprehensive understanding of this linear family. The conclusions suggest that the core working mechanisms of the state-of-the-art techniques can be traced back to those of earlier differential side-channel analyses. Experimental results are in line with the theory, confirming its correctness in practice. Jiangshan Long, Changhai Ou, Yukun Cheng, Tingting Wang 0010, Zhu Wang 0005, Fan Zhang 0010 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | CGIFuzz: Enabling Gray-Box Fuzzing for Web CGI of IoT DevicesabstractFuzz testing for Internet of Things (IoT) devices has become a critical area of research, as these devices play an increasingly vital role in modern networks and infrastructure. While significant efforts have been made, the Common Gateway Interface (CGI) programs that serve as an important component within these devices remain underexplored. Despite their extensive use in IoT web services, the specific characteristics of CGI programs have posed technical challenges to existing fuzzing infrastructures. To address these gaps, we propose CGIFuzz, the first gray-box fuzzing framework tailored for CGI programs in Linux-based IoT devices. CGIFuzz initially enables dynamic instrumentation of CGI programs throughRelay-Pass Instrumentation, then leverages Large Language Models (LLM) for assisting high-quality fuzz test input generation. Furthermore, CGIFuzz devises oracles for detecting command injection and memory corruption vulnerabilities by leveraging multiple critical features during program execution. Our evaluation of CGIFuzz on ten popular IoT devices demonstrates superior coverage exploration and vulnerability detection capabilities compared to the state-of-the-art fuzzers. Notably, CGIFuzz discovered 69 vulnerabilities, including 13 previously unknown ones for which 9 CVEs were assigned. Jiongchi Yu, Ziming Zhao 0008, Jiongyi Chen, Fan Zhang 0010 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | Statistical Analysis of Non-Profiling Higher-Order Distinguishers Against Inner Product MaskingabstractInner Product Masking (IPM) is one representative masking scheme, which captivates by so-called Security Order Amplification (SOA) property. It is commonly recognized that SOA holds under linear leakages. In this paper, we revisit SOA from a non-profiling attack perspective. Specifically, we conduct statistical analyses on three non-profiling distinguishers, including Pearson Coefficient Distinguisher (PCD), Spearman Coefficient Distinguisher (SCD) and Kruskal-Wallis Distinguisher (KWD). We find a fundamental connection between SCD and KWD such that SCD is a more generic distinguisher which encompasses KWD. Theoretical explanations for why KWD outperforms SCD under non-linear leakages are provided. We also propose a new adjusted SCD and present its optimal form, which bridges the efficiency gap with KWD. Grounded on this, SOA is extensively assessed and the observations are two-fold. On the one hand, we confirm again the effectiveness of SOA under Hamming weight leakage through the statistical analysis of PCD. On the other hand, we show that SOA can not resist rank-based distinguishers even under linear leakages, which has never been revealed before (to the best of our knowledge). At last, we verify the theoretical findings through both simulated and real-world measurements. Our results demonstrate the advantage of rank-based distinguishers in uncovering non-linear relationships hidden in leakage, enriching the tool-set for non-profiling class of side-channel attacks. Remarkably, we provide an adversary perspective to investigate SOA, highlighting that the side-channel resistance promised by SOA is vulnerable even considering the ideal linear leakage models. Qianmei Wu, Wei Cheng 0003, Fan Zhang 0010, Sylvain Guilley |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Topology-Preserved Information Bottleneck for Multiview Anomaly DetectionabstractAnomaly detection (AD) techniques are widely used in various fields. Existing techniques primarily focus on learning a normal region from single-view data, which may be not suitable for multiview data that provides more comprehensive information from multiple perspectives. Therefore, AD techniques designed for multiview data are necessary. Straightforwardly, one can concatenate the features learned from multiple single-view data into a joint representation to conduct AD. However, this may overlook the inevitable overlaps between views, potentially masking view-specific information due to the repetitive calculations of these overlaps. Among the various possible methods, one way to address this is to compress redundant information while maintaining comprehensive information across views. Following this way, in this article, we leverage the principle of information bottleneck (IB) to extract concise and comprehensive representations for multiview data. But it is problematic to directly use these representations for AD, since the multiview fusion process may disturb the intrinsic structure of the original data. That is, samples distributed at the edges/center of the original normal data distribution are mapped closer to the center/edges. This might cause abnormal samples (close to the normal data at the edges) to be incorrectly mapped into the normal region during inference. In the AD scenario, the absence of abnormal training samples makes it unfeasible to preserve this structure using supervised information. In this article, we design a topology-preserved regularization that unsupervisedly constrains the latent representations to preserve the original data's intrinsic structure, to improve the AD performance. Overall, we propose a topology-preserved multiview information bottleneck (TMVIB) feature extraction method to extract concise, comprehensive, and topology-preserved latent representations from multiview data. Interestingly, we find that the TMVIB feature extraction method itself can be viewed as a regularized anomaly detector, allowing it to output anomaly scores directly. Experiments on synthetic and real-world multiview datasets demonstrate the effectiveness of the proposed TMVIB. Tengfei Yan, Jiankai Tu, Chunguang Li 0001, Fan Zhang 0010 |
IEEE Trans. Neural Networks Learn. Syst. | 4 |
| 2024 | DDoSMiner: An Automated Framework for DDoS Attack Characterization and Vulnerability Mining
Xi Ling, Jiongchi Yu, Ziming Zhao 0008, Haitao Xu 0002, Binbin Chen 0001, Fan Zhang 0010 |
ACNS (2) | 7 |
| 2024 | HQsFL: A Novel Training Strategy for Constructing High-performance and Quantum-safe Federated LearningabstractFederated Learning (FL) has attracted increasing attention from both academia and industry due to its merit of securely constructing AI models across multiple entities while preserving the privacy of local training data. However, recent research shows two persisting problems in FL that have yet to be solved: (1) limited practical adaptation of federated learning because of time-consuming conventional privacy-preserving methods, and (2) the absence of quantum-computing resistance in these methods. To address these problems, we propose a novel vertical federated learning strategy, HQsFL, which relies on Fully Homomorphic Encryption (FHE) and Matrix Vector Product basing on Coefficient Encoding. The proposed method can be widely applied to FL algorithms such as logistic regression and XGBoost, etc. We fully implement our approach and evaluate its utility and efficiency through extensive experiments performed on four synthetic datasets. The experimental results demonstrate that our proposed methods for vertical LR and XGBoost achieve comparable levels of AUC to conventional methods, while significantly improving training efficiency and achieving security property of quantum-computing resistance. Huajie Shen, Qian Xu 0008, Wei He 0015, Wankui Mao, Fan Zhang 0010 |
AsiaCCS | 7 |
| 2024 | Demo: Enhancing Smart Contract Security Comprehensively through Dynamic Symbolic ExecutionabstractThe frequent security incidents of contracts indicate a pressing need to ensure contract security from deployment to running stages, but the state-of-the-art (SOTA) analysis methods cannot work well for three requirements.(i) Identify contract defective code snippets, while generating exploit call sequences to help developers fix them.(ii) Monitor abnormal call behaviors, especially for multiple continuous transactions.(iii) Validate numerous unexploitable detection results automatically because manual verification is labor-intensive.To tackle these problems, we propose SymX, a symbolic executionbased security analysis art accounting for contract development and running stages.The experiment results demonstrate that it can accurately identify 90.22% of contracts and 98.04% of call transactions, as well as validate misreports as intended, which is superior to SOTAs, thereby protecting contracts better during the contract lifecycle.Currently, SymX is available at https://github.com/Secbrain/SymX. Zhaoxuan Li, Ziming Zhao 0008, Wenhao Li 0005, Rui Zhang 0016, Rui Xue 0001, Siqi Lu, Fan Zhang 0010 |
CCS | 7 |
| 2024 | An Automated Alert Cross-Verification System with Graph Neural Networks for IDS EventsabstractIntrusion Detection Systems (IDSs) are vital in detecting network attacks and ensuring the confidentiality and integrity of network resources. Currently, industry-standard IDSs primarily rely on rule-based or anomaly-detection techniques. However, existing detection techniques often generate false positives and negatives, also known as the alert fatigue problem. This influx of incorrect events diminishes the IDS’s efficiency by overburdening security analysts. In this paper, we present ACVS, an innovative automated alert cross-verification system that leverages Graph Neural Networks for identifying misclassifications in security events. Initially, ACVS generates event graphs using attributes like IP addresses and timestamps from sequences of security events and then employs correlation analysis on these events, utilizing alert information to verify misclassifications. Finally, the system uses Graph Neural Networks to classify and correct these security events automatically. We conduct evaluations for ACVS on a substantial real-world dataset comprising over 5 million security events, which are categorized into 5 distinct groups. The results reveal that ACVS markedly enhances the accuracy of intrusion detection systems and substantially reduces the need for manual analysis. Yuanhui He, Feiyang Huang, Ziming Zhao 0008, Zhuoxue Song, Zhenyuan Li, Fan Zhang 0010 |
CSCWD | 8 |
| 2024 | RIDS: Towards Advanced IDS via RNN Model and Programmable Switches Co-Designed ApproachesabstractExisting Deep Learning (DL)-based network Intrusion Detection System (IDS) is able to characterize sequence semantics of traffic and discover malicious behaviors. Yet DL models are often nonlinear and highly non-convex functions that are difficult for in-network deployment. In this paper, we present RIDS, a hardware-friendly Recurrent Neural Network (RNN) model that is co-designed with programmable switches. As its core, RIDS is powered by two tightly-coupled components: (i) rLearner, the RNN learning module with in-network deployability as the first-class requirement; and (ii) rEnforcer, the concrete pipeline design to realize rLearner-generated models inside the network dataplane. We implement a prototype of RIDS and evaluate it on our physical testbed. The experiments show that RIDS could satisfy both detection performance and high-speed bandwidth adaptation simultaneously, when none of the other existing approaches could do so. Inspiringly, RIDS realizes remarkable intrusion/malware detection effect (e.g., ~99% F1 score) and model deployment (e.g., 100 Gbps per port), while only imposing nanoseconds of latency. Ziming Zhao 0008, Zhaoxuan Li, Zhuoxue Song, Fan Zhang 0010, Binbin Chen 0001 |
INFOCOM | 4 |
| 2024 | A Large-Scale P2P Botnet Detection Framework via Topology and Traffic Co-VerificationabstractBotnets are still serious threats to infrastructure security nowadays. Recently, adversaries tend to leverage peer-to-peer (P2P) manner propagation to construct large-scale botnets since P2P-based schemes have no single points of failure. Over the past few decades, the research and industry communities have proposed a variety of solutions to detect botnets, which mainly involve communication topology identification and network traffic analysis. Yet, coping with the large-scale P2P botnets, the former suffer topology indistinguishability, and the latter struggles under massive background traffic. In this paper, we present TNT, a large-scale P2P botnet detection framework via communication topology and network traffic. As its core, TNT is powered by three tightly-coupled components: (i) tScouter is responsible for profiling the communication topology; (ii) tCommander plans the strategy for node inspection; and (iii) tPatroller investigates the traffic of the corresponding node. Taken together, TNT advances the trade-off between detection accuracy (enhance topology-based results via traffic analysis) and overhead (only check part of node traffic according to the planning). Based on 42 groups of combinations involving 6 types of botnets and 7 legitimate P2P traffic, we perform extensive evaluation and demonstrate that TNT realizes outstanding detection performance, e.g., after checking ~20K nodes, achieve ~99.9% accuracy for a communication graph (including >140K nodes). Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Fan Zhang 0010 |
SECON | 4 |
| 2024 | Trident: A Universal Framework for Fine-Grained and Class-Incremental Unknown Traffic DetectionabstractTo detect unknown attack traffic, anomaly-based network intrusion detection systems (NIDSs) are widely used in Internet infrastructure. However, the security communities realize some limitations when they put most existing proposals into practice. The challenges are mainly concerned with (i) fine-grained emerging attack detection and (ii) incremental updates/adaptations. To tackle these problems, we propose to decouple the need for model capabilities by transforming known/new class identification issues into multiple independent one-class learning tasks. Based on the above core ideas, we develop Trident, a universal framework for fine-grained unknown encrypted traffic detection. It consists of three main modules, i.e., tSieve, tScissors, and tMagnifier are used for profiling traffic, determining outlier thresholds, and clustering respectively, each of which supports custom configuration. Using four popular datasets of network traces, we show that Trident significantly outperforms 16 state-of-the-art (SOTA) methods. Furthermore, a series of experiments (concept drift, overhead/parameter evaluation) demonstrate the stability, scalability, and practicality of Trident. Ziming Zhao 0008, Zhaoxuan Li, Zhuoxue Song, Wenhao Li 0005, Fan Zhang 0010 |
WWW | 5 |
| 2024 | metaNet: Interpretable unknown mobile malware identification with a novel meta-features mining algorithm
Zhaoxuan Li, Ziming Zhao 0008, Rui Zhang 0016, Wenhao Li 0005, Fan Zhang 0010, Siqi Lu, Rui Xue 0001 |
Comput. Networks | 6 |
| 2024 | TransURL: Improving malicious URL detection with multi-layer Transformer encoding and multi-scale pyramid features
Zhenhao Guo, Haitao Xu 0002, Zhan Qin, Wenrui Ma, Fan Zhang 0010 |
Comput. Networks | 7 |
| 2024 | DDoS family: A novel perspective for massive types of DDoS attacks
Ziming Zhao 0008, Zhaoxuan Li, Jiongchi Yu, Zhuoxue Song, Xiaofei Xie, Fan Zhang 0010, Rui Zhang 0016 |
Comput. Secur. | 7 |
| 2024 | IP2vec: an IP node representation model for IP geolocation
Fan Zhang 0010, Meijuan Yin, Fenlin Liu, Xiangyang Luo 0001, Shuodi Zu |
Frontiers Comput. Sci. | 1 |
| 2024 | Double laser-faults based PFA on cryptographic circuits with algebraic analysis
Tianxiang Feng, Guorui Xu, Shize Guo, Fan Zhang 0010 |
Integr. | 6 |
| 2024 | A Unified and Fully Automated Framework for Wavelet-Based Attacks on Random DelayabstractAs a common defense against side-channel attacks, random delay insertion introduces noise into the executive flow of encryption, which increases attack complexity. Accordingly, various techniques are exploited to mitigate the defense effect of such insertions. As an advanced mathematical technique, wavelet analysis is considered to be a more effective technology according to its detailed and comprehensive interpretation of signals. In this paper, we propose a unified and fully automated wavelet-based attack framework (denoted asUWAF), whose data processing is kept within one unified wavelet domain, with three enhanced components: denoising, alignment and key extraction. We put forward a new idea of combining machine learning with wavelet analysis to realize the full automation of the program for attack framework, rendering it possible to search exhaustively for the optimal combination of parameter settings in wavelet transform. Our proposal finds a new setting of wavelet parameters that have not been exploited ever before and achieves the performance enhancement for about 20 times fewer traces required for successful key recovery.UWAFis compared with several mainstream attack frameworks. Experimental results show that it outperforms those counterparts, and can be considered as an effective framework-level solution to defeat the countermeasure of random delay insertion. Qianmei Wu, Fan Zhang 0010, Shize Guo, Kun Yang 0012, Haoting Shen |
IEEE Trans. Computers | 2 |
| 2024 | TPE-Det: A Tamper-Proof External Detector via Hardware Traces Analysis Against IoT MalwareabstractWith the widespread use of Internet of Things (IoT) devices, malware detection has become a hot spot for both academic and industrial communities. A series of solutions based on system calls, system logs, or hardware performance counters achieve promising results. However, such internal monitors are easily tampered with, especially against adaptive adversaries. In addition, existing system log records typically exhibit substantial volume, resulting in data explosion problems. In this article, we present TPE-Det, a side-channel-based external monitor to cope with these issues. Specifically, TPE-Det leverages the serial peripheral interface bus to extract the on-chip traces and designs a recovery pipeline for operating logs. The advantages of this external monitor are adversary-unperceived and tamper-proof. The restored logs mainly include file operation commands, which are lightweight compared to complete records. Meanwhile, we deploy a series of machine learning models with respect to statistical, sequence, and graph features to identify malware. Empirical evaluation shows that our proposal has tamper-proof capability, high-detection accuracy, and low-time/space overhead compared to state-of-the-art methods. Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Fan Zhang 0010 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2024 | Effective DDoS Mitigation via ML-Driven In-Network Traffic ShapingabstractDefending against Distributed Denial of Service (DDoS) attacks is a fundamental problem in the Internet. Over the past few decades, the research and industry communities have proposed a variety of solutions, from adding incremental capabilities to the existing Internet routing stack, to clean-slate future Internet architectures, and to widely deployed commercial DDoS prevention services. Yet a recent interview with over 100 security practitioners in multiple sectors reveals that existing solutions arestill insufficient against, due to either unenforceable protocol deployment or non-comprehensive traffic filters. This seemingly endless arms race with attackers probably means that we need a fundamental paradigm shift. In this paper, we propose a new DDoS prevention paradigm namedpreference-driven and in-network enforced traffic shaping, aiming to explore the novel DDoS prevention norms that focus on delivering victim-preferred traffic rather than consistently chasing after the DDoS attacks. Towards this end, we propose DFNet, a novel DDoS prevention system that provides reliable delivery of victim-preferred trafficwithoutfull knowledge of DDoS attacks. At a very high level, the core innovative design of DFNet embraces the advances in Machine Learning (ML) and new network dataplane primitives, byencodingthe victim's traffic preference (in the form of complex ML models) into dataplane packet scheduling algorithms such that the victim-preferred traffic is forwarded with priority at line-speed, regardless of the attacker strategy. We implement a prototype of DFNet in 11,560 lines of code, and extensively evaluate it on our testbed. The results show thata single instanceof DFNet can forward 99.93% of victim-desired traffic when facing previously unseen attacks, while imposing less than 0.1% forwarding overhead on a dataplane with 80 Gbps upstream links and a 40 Gbps bottleneck. Ziming Zhao 0008, Zhuotao Liu, Huan Chen 0021, Fan Zhang 0010, Zhuoxue Song, Zhaoxuan Li |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | CMD: Co-Analyzed IoT Malware Detection and Forensics via Network and Hardware DomainsabstractWith the widespread use of Internet of Things (IoT) devices, malware detection has become a hot spot for both academic and industrial communities. Existing approaches can be roughly categorized into network-side and host-side. However, existing network-side methods are difficult to capture contextual semantics from cross-source traffic, and previous host-side methods could be adversary-perceived and expose risks for tampering. More importantly, a single perspective cannot comprehensively track the multi-stage lifecycle of IoT malware. In this paper, we present${\sf CMD}$, a co-analyzed IoT malware detection and forensics system by combining hardware and network domains. For the network part,${\sf CMD}$proposes a tailored capsule neural network to capture the contextual semantics from cross-source traffic. For the hardware part,${\sf CMD}$designs an entire file operation recovery process in a side-channel manner by leveraging the Serial Peripheral Interface (SPI) signals from on-chip traces. These traffic provenance and operating logs information could benefit the anti-virus countermeasures for security practitioners. By practical evaluation, we demonstrate that${\sf CMD}$realizes outstanding detection effects (e.g.,$\sim$99.88% F1-score) compared with seven state-of-the-art methods, and recovers 96.88%$\sim$99.75% operation commands even if against adaptive adversaries (that could kill processes or tamper with operation log files). A by-product benefit of such an external monitor is${\sf CMD}$introduces zero latency on the IoT device, and incurs negligible IoT CPU utilization. Also, since SPI focuses on file operations, the proposed hardware trace forensics does not have the data explosion problem like previous work,e.g.,recovered logs of${\sf CMD}$only take up limited extra space overhead (e.g.,$\sim$0.2 MB per malware). Furthermore, we provide the model interpretability for the capsule network and develop a case study (Hajime) of the operation logs recovery. Ziming Zhao 0008, Zhaoxuan Li, Jiongchi Yu, Fan Zhang 0010, Xiaofei Xie, Haitao Xu 0002, Binbin Chen 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | FOSS: Towards Fine-Grained Unknown Class Detection Against the Open-Set Attack Spectrum With Variable Legitimate TrafficabstractAnomaly-based network intrusion detection systems (NIDSs) are essential for ensuring cybersecurity. However, the security communities realize some limitations when they put most existing proposals into practice. The challenges are mainly concerned with (i) fine-grained unknown attack detection and (ii) ever-changing legitimate traffic adaptation. To tackle these problem, we present three key design norms. The core idea is to construct a model to split the data distribution hyperplane and leverage the concept of isolation, as well as advance the incremental model update. We utilize the isolation tree as the backbone to design our model, named FOSS, to echo back three norms. By analyzing the popular dataset of network intrusion traces, we show that FOSS significantly outperforms the state-of-the-art methods. Further, we perform an initial deployment of FOSS by working with the Internet Service Provider (ISP) to detect distributed denial of service (DDoS) attacks. With real-world tests and manual analysis, we demonstrate the effectiveness of FOSS to identify previously-unseen attacks in a fine-grained manner. Ziming Zhao 0008, Zhaoxuan Li, Xiaofei Xie, Jiongchi Yu, Fan Zhang 0010, Rui Zhang 0016, Binbin Chen 0001, Xiangyang Luo 0001, Ming Hu 0003, Wenrui Ma |
IEEE/ACM Trans. Netw. | 5 |
| 2023 | Purifier: Defending Data Inference Attacks via Transforming Confidence ScoresabstractNeural networks are susceptible to data inference attacks such as the membership inference attack, the adversarial model inversion attack and the attribute inference attack, where the attacker could infer useful information such as the membership, the reconstruction or the sensitive attributes of a data sample from the confidence scores predicted by the target classifier. In this paper, we propose a method, namely PURIFIER, to defend against membership inference attacks. It transforms the confidence score vectors predicted by the target classifier and makes purified confidence scores indistinguishable in individual shape, statistical distribution and prediction label between members and non-members. The experimental results show that PURIFIER helps defend membership inference attacks with high effectiveness and efficiency, outperforming previous defense methods, and also incurs negligible utility loss. Besides, our further experiments show that PURIFIER is also effective in defending adversarial model inversion attacks and attribute inference attacks. For example, the inversion error is raised about 4+ times on the Facescrub530 classifier, and the attribute inference accuracy drops significantly when PURIFIER is deployed in our experiment. Lijin Wang, Da Yang 0006, Ziming Zhao 0008, Ee-Chien Chang, Fan Zhang 0010, Kui Ren 0001 |
AAAI | 7 |
| 2023 | Poster: Detecting Adversarial Examples Hidden under Watermark Perturbation via Usable Information TheoryabstractImage watermark is a technique widely used for copyright protection. Recent studies show that the image watermark can be added to the clear image as a kind of noise to realize fooling deep learning models. However, previous adversarial example (AE) detection schemes tend to be ineffective since the watermark logo differs from typical noise perturbations. In this poster, we propose Themis, a novel AE detection method against watermark perturbation. Different from prior methods, Themis neither modifies the protected classifier nor requires knowledge of the process for generating AEs. Specifically, Themis leverages usable information theory to calculate the pointwise score, thereby discovering those instances that may be watermark AEs. The empirical evaluations involving 5 different logo watermark perturbations demonstrate the proposed scheme can efficiently detect AEs, and significantly (over 15% accuracy) outperforms five state-of-the-art (SOTA) detection methods. The visualization results display our detection metric is more distinguishable between AEs and non-AEs. Meanwhile, Themis realizes a larger Area Under Curve (AUC) in a threshold-resilient manner, while only introducing ∼0.04s overhead. Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Zhuoxue Song, Fan Zhang 0010, Rui Zhang 0016 |
CCS | 5 |
| 2023 | Stalker: A Framework to Analyze Fragility of Cryptographic Libraries under Hardware Fault ModelsabstractFor embedded devices, the uncertainty of target physical environments is always a great challenge. With constrained resources and common overloaded uses, they can be more exposed to hardware faults. Other than stability and ordinary security issues, there exist some subtle phenomenons that lead to potential cryptanalysis or secret leakage. In this paper, we present STALKER, a framework to analyze the fragility of libraries under hardware fault models. Compared with existing tools, our framework targets faulty execution outputs, and can flexibly work on different libraries, architectures and support different search schemes. We find dozens of security-sensitive bits that may cause critical issues and provide detailed analysis. Guorui Xu, Fan Zhang 0010, Xinjie Zhao 0001, Shize Guo, Kui Ren 0001 |
DAC | 2 |
| 2023 | DNAttest: Digital-twin-based Non-intrusive Attestation under Transient UncertaintyabstractProgrammable logic controllers (PLCs) are vulnerable to malware, which is a key security risk for Industrial Control Systems (ICSs). Existing attestation solutions are invasive because they require hardware security modules and software upgrades in legacy devices. We propose DNAttest, a Digital-twin-based Noninvasive Attestation solution to attest PLC behaviors in near-real time. DNAttest requires minimal ICS infrastructure changes and does not interfere with normal ICS operations. DNAttest detects PLC deviations by replicating all input messages for a PLC to its digital twin and comparing their output messages. Due to transient uncertainty in the PLC's internal processing state, DNAttest may output an incorrect comparison. To generate all plausible output values for comparison, we instantiate multiple emulated PLCs by replicating input messages with different timing profiles. We demonstrate on a close-to-real-world power grid testbed that DNAttest can provide a timely detection of a wide range of attacks non-invasively and accurately. DNAttest solution is lightweight and scalable. A typical desktop PC can attest more than 20 actual PLCs even if we use 10 emulators to monitor every actual PLC. Heng Chuan Tan, Binbin Chen 0001, Fan Zhang 0010 |
DSN | 4 |
| 2023 | GameRTS: A Regression Testing Framework for Video GamesabstractContinuous game quality assurance is of great importance to satisfy the increasing demands of users. To respond to game issues reported by users timely, game com-panies often create and maintain a large number of releases, updates, and tweaks in a short time. Regression testing is an essential technique adopted to detect regression issues during the evolution of the game software. However, due to the special characteristics of game software (e.g., frequent updates and long-running tests), traditional regression testing techniques are not directly applicable. To bridge this gap, in this paper, we perform an early exploratory study to investigate the challenges in regression testing of video games. We first performed empirical studies to better understand the game development process, bugs introduced during game evolution, and the context sensitivity. Based on the results of the study, we proposed the first regression test selection (RTS) technique for game software, which is a compromise between safety and practicality. In particular, we model the test suite of game software as a State Transition Graph (STG) and then perform the RTS on the STG. We establish the dependencies between the states/actions of STG and game files, including game art resources, game design files, and source code, and perform change impact analysis to identify the states/actions (in the STG) that potentially execute such changes. We implemented our framework in a tool, named GameRTS, and evaluated its usefulness on 10 tasks of a large-scale commercial game, including a total of 1,429 commits over three versions. The experimental results demonstrate the usefulness and effectiveness of GameRTS in game RTS. For most tasks, GameRTS only selected one trace from STG, which can significantly reduce the testing time. Furthermore, GameRTS detects all the regression bugs from the test evaluation suites. Compared with the file-level RTS, GameRTS selected fewer states/actions/traces (i.e., 13.77%, 23.97%, 6.85%). In addition, GameRTS identified 2 new critical regression bugs in the game. Jiongchi Yu, Yuechen Wu, Xiaofei Xie, Wei Le, Lei Ma 0003, Fan Zhang 0010 |
ICSE | 8 |
| 2023 | InfoMasker: Preventing Eavesdropping Using Phoneme-Based Noise
Yao Wei 0002, Peng Cheng 0007, Zhongjie Ba, Li Lu 0008, Feng Lin 0004, Fan Zhang 0010, Kui Ren 0001 |
NDSS | 7 |
| 2023 | Work-in-Progress: Towards Real-Time IDS via RNN and Programmable Switches Co-Designed ApproachabstractExisting Deep Learning (DL)-based network Intrusion Detection System (IDS) is able to characterize sequence semantics of traffic and discover malicious behaviors. Yet DL models are often nonlinear and highly non-convex functions that are difficult for in-network real-time deployment, i.e., existing DL solutions are essentially offline analysis. In this paper, we present RIDS, a hardware-friendly Recurrent Neural Network (RNN) model that is co-designed with programmable switches. As its core, RIDS is powered by two tightly-coupled components: (i) rLearner, the RNN learning module with in-network deployability as the first-class requirement; and (ii) rEnforcer, the concrete pipeline design to realize rLearner-generated models inside the network dataplane. We implement a prototype of RIDS and evaluate it on our physical testbed. The experiments show that RIDS could satisfy both detection performance and high-speed bandwidth adaptation simultaneously, when none of the other existing approaches could do so. Inspiringly, RIDS realizes remarkable intrusion/malware detection effect (e.g., ∽99% F1 score) and model deployment (e.g., 100 Gbps per port), while only imposing nanoseconds of latency. Ziming Zhao 0008, Zhaoxuan Li, Zhuoxue Song, Fan Zhang 0010 |
RTSS | 4 |
| 2023 | Investigating Fraud and Misconduct in Legitimate Internet Economy based on Customer ComplaintsabstractDifferent forms of cybercrimes, ranging from email spam and click fraud to the most sophisticated underground economy, have been studied extensively. Fraud and misconduct in legitimate Internet economy, however, have not received sufficient attention, even though potential damages may not be as severe as regular cybercrimes. In this paper, we have performed the first in-depth empirical investigation of fraud and misconduct in legitimate Internet businesses by collecting 6.6 million customer complaints, which were filed over 45 months by 2.7 million customers against 117 thousand merchants on one of the largest customer complaint platforms in the world, along with more than 13 million customer-uploaded images as photographic evidence. We characterized the complaints in terms of merchants, main issues, desired remedy, amount of money involved, customer ratings, and etc. Most importantly, we were able to uncover various fraud and misconduct in different Internet businesses, some of which should have caught law enforcement's attention. The sum of the amount of money involved in these complaints is 5.4 billion US dollars. We also investigated the privacy inference of the images, and found that the image content could disclose an unexpected amount of customers' personal information. Wenrui Ma, Ying Cong, Haitao Xu 0002, Fan Zhang 0010, Zhao Li 0007, Siqi Ren |
TrustCom | 4 |
| 2023 | Extending the classical side-channel analysis framework to access-driven cache attacks
Yingjian Yan, Fan Zhang 0010, Chunsheng Zhu, Zibin Dai |
Comput. Secur. | 3 |
| 2023 | FaultMorse: An automated controlled-channel attack via longest recurring sequence
Lifeng Hu, Fan Zhang 0010, Ziyuan Liang, Ruyi Ding, Xingyu Cai, Zonghui Wang, Wenguang Jin |
Comput. Secur. | 2 |
| 2023 | CoTree: A Side-Channel Collision Tool to Push the Limits of Conquerable SpaceabstractBy introducing collision information into divide-and-conquer distinguishers, the existing collision-optimized side-channel attacks transform the given candidate space into a significantly smaller collision space, thus achieving more efficient key recovery. However, the candidates of the first several subkeys shared by collision chains are still repeatedly detected, which happens very frequently and brings huge computational overhead. To alleviate this, we propose a highly efficient collision-optimized attack named collision tree (CoTree). This collision detection tool exploits tree structure to store the chains created from the same subchain on the same branch, thus significantly reducing the storage requirements. It then benefits from the properties of both tree and collisions and exploits a top-down tree building procedure and traverses each node only once when detecting their collisions with a candidate of the subkey currently under consideration. Finally, unlike the traditional top-down node removal, CoTree launches a bottom-up branch removal procedure to remove the chains unsatisfying the collision conditions from the tree after traversing all the considered candidates of this subkey, thus avoiding the traversal of the branches satisfying the collision condition. These strategies make our CoTree significantly alleviate the repetitive collision detection, and our experiments verify that it significantly outperforms the existing works. Changhai Ou, Debiao He, Kexin Qiao, Shihui Zheng, Siew-Kei Lam, Fan Zhang 0010 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 6 |
| 2023 | SAGE: Steering the Adversarial Generation of Examples With AccelerationsabstractTo generate image adversarial examples, state-of-the-art black-box attacks usually require thousands of queries. However, massive queries will introduce additional costs and exposure risks in the real world. Towards improving the attack efficiency, we carefully design an acceleration framework SAGE for existing black-box methods, which is composed of sLocator (initial point optimization) and sRudder (search process optimization). The core idea of SAGE in terms of 1) saliency map can guide the perturbations towards the most adversarial direction and 2) exploiting bounding box (bbox) to capture those salient pixels in the black-box attack. Meanwhile, we provide a series of observations and experiments that demonstrate bbox holds model invariance and process invariance. We extensively evaluate SAGE on four state-of-the-art black-box attacks involving three popular datasets (MNIST, CIFAR10, and ImageNet). The results show that SAGE could present fundamental improvements even against robust models that use adversarial training. Specifically, SAGE could reduce >20% of queries and improve the success rate of attacks to 95%~100%. Compared with the other acceleration framework, SAGE fulfills the more significant effect in a flexible, stable, and low-overhead manner. Moreover, our practical evaluation (Google Cloud Vision API) shows SAGE can be applied to real-world scenarios. Ziming Zhao 0008, Zhaoxuan Li, Fan Zhang 0010, Tingting Li 0004, Rui Zhang 0016, Kui Ren 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | VulHunter: Hunting Vulnerable Smart Contracts at EVM Bytecode-Level via Multiple Instance LearningabstractWith the economic development of Ethereum, the frequent security incidents involving smart contracts running on this platform have caused billions of dollars in losses. Consequently, there is a pressing need to identify the vulnerabilities in contracts, while the state-of-the-art (SOTA) detection methods have been limited in this regard as they cannot overcome three challenges at the same time. (i) Meet the requirements of detecting the source code, bytecode, and opcode of contracts simultaneously; (ii) reduce the reliance on manual pre-defined rules/patterns and expert involvement; (iii) assist contract developers in completing the contract lifecycle more safely,e.g., vulnerability repair and abnormal monitoring. With the development of machine learning (ML), using it to detect the contract runtime execution sequences (called instances) has made it possible to address these challenges. However, the lack of datasets with fine-grained sequence labels poses a significant obstacle, given the unreadability of bytecode/opcode. To this end, we propose a method named VulHunter that extracts the instances by traversing the Control Flow Graph built from contract opcodes. Based on the hybrid attention and multi-instance learning mechanisms, VulHunter reasons the instance labels and designs an optional classifier to automatically capture the subtle features of both normal and defective contracts, thereby identifying the vulnerable instances. Then, it combines the symbolic execution to construct and solve symbolic constraints to validate their feasibility. Finally, we implement a prototype of VulHunter with 15K lines of code and compare it with 9 SOTA methods on five open source datasets including 52,042 source codes and 184,289 bytecodes. The results indicate that VulHunter can detect contract vulnerabilities more accurately (90.04% accurate rate and 85.60% F1 score), efficiently (only took 4.4 seconds per contract), and robustly (0% analysis failed rate) than the SOTA methods. Also, it can focus on specific metrics such as precision and recall by employing different baseline models and hyperparameters to meet the various user requirements,e.g., vulnerability discovery and misreport mitigation. More importantly, compared with the previous ML-based arts, it can not only provide classification results, defective contract source code statements, key opcode fragments, and vulnerable execution paths, but also eliminate misreports and facilitate more operations such as vulnerability repair and attack simulation during the contract lifecycle. Zhaoxuan Li, Siqi Lu, Rui Zhang 0016, Ziming Zhao 0008, Rujin Liang, Rui Xue 0001, Wenhao Li 0005, Fan Zhang 0010, Sheng Gao 0002 |
IEEE Trans. Software Eng. | 8 |
| 2023 | Constructing Cyber-Physical System Testing Suites Using Active Sensor FuzzingabstractCyber-physical systems (CPSs) automating critical public infrastructure face a pervasive threat of attack, motivating research into different types of countermeasures. Assessing the effectiveness of these countermeasures is challenging, however, as benchmarks are difficult to construct manually, existing automated testing solutions often make unrealistic assumptions, and blindly fuzzing is ineffective at finding attacks due to the enormous search spaces and resource requirements. In this work, we proposeactive sensor fuzzing, a fully automated approach for building test suites without requiring anya priorknowledge about a CPS. Our approach employs active learning techniques. Applied to a real-world water treatment system, our approach manages to find attacks that drive the system into 15 different unsafe states involving water flow, pressure, and tank levels, including nine that were not covered by an established attack benchmark. Furthermore, we successfully generate targeted multi-point attacks which have been long suspected to be possible. We reveal that active sensor fuzzing successfully extends the attack benchmarks generated by our previous work, an ML-guided fuzzing tool, with two more kinds of attacks. Finally, we investigate the impact of active learning on models and the reason that the model trained with active learning is able to discover more attacks. Fan Zhang 0010, Qianmei Wu, Bohan Xuan, Yuqi Chen 0001, Christopher M. Poskitt, Jun Sun 0001, Binbin Chen 0001 |
IEEE Trans. Software Eng. | 1 |
| 2022 | DARPT: defense against remote physical attack based on TDC in multi-tenant scenarioabstractWith rapidly increasing demands for cloud computing, Field Programmable Gate Array (FPGA) has become popular in cloud datacenters. Although it improves computing performance through flexible hardware acceleration, new security concerns also come along. For example, unavoidable physical leakage from the Power Distribution Network (PDN) can be utilized by attackers to mount remote Side-Channel Attacks (SCA), such as Correlation Power Attacks (CPA). Remote Fault Attacks (FA) can also be successfully presented by malicious tenants in a cloud multi-tenant scenario, posing a significant threat to legal tenants. There are few hardware-based countermeasures to defeat both remote attacks that aforementioned. In this work, we exploit Time-to-Digital Converter (TDC) and propose a novel defense technique called DARPT (Defense Against Remote Physical attack based on TDC) to protect sensitive information from CPA and FA. Specifically, DARPT produces random clock jitters to reduce possible information leakage through the power side-channel and provides an early warning of FA by constantly monitoring the variation of the voltage drop across PDN. In comparison to the fact that 8k traces are enough for a successful CPA on FPGA without DARPT, our experimental results show that up to 800k traces (100 times) are not enough for the same FPGA protected by DARPT. Meanwhile, the TDC-based voltage monitor presents significant readout changes (by 51.82% or larger) under FA with ring oscillators, demonstrating sufficient sensitivities to voltage-drop-based FA. Fan Zhang 0010, Haoting Shen, Bolin Yang, Qianmei Wu, Kui Ren 0001 |
DAC | 1 |
| 2022 | Terminator on SkyNet: a practical DVFS attack on DNN hardware IP for UAV object detectionabstractWith increasing computation of various applications, dynamic voltage and frequency scaling (DVFS) is gradually deployed on FPGAs. However, its reliability and security haven't been sufficiently evaluated. In this paper, we present a practical DVFS fault attack targeting at the SkyNet accelerator IP and successfully destroy the detection accuracy. With no knowledge about the internal accelerator structure, our attack can achieve more than 98% detection accuracy loss under ten vulnerable operating point pairs (OPPs). Meanwhile, we explore the local injection with 1 ms duration and next double the intensity which can achieve more than 50% and 74% average accuracy loss respectively. Junge Xu, Bohan Xuan, Anlin Liu, Mo Sun 0001, Fan Zhang 0010, Zeke Wang, Kui Ren 0001 |
DAC | 5 |
| 2022 | FakeGuard: Exploring Haptic Response to Mitigate the Vulnerability in Commercial Fingerprint Anti-Spoofing
Aditya Singh Rathore, Yijie Shen, Chenhan Xu, Jacob Snyderman, Jinsong Han, Fan Zhang 0010, Zhengxiong Li, Feng Lin 0004, Wenyao Xu, Kui Ren 0001 |
NDSS | 6 |
| 2022 | AflIot: Fuzzing on linux-based IoT device with binary-level instrumentation
Xuechao Du, Boyuan He, Hao Chen 0003, Fan Zhang 0010, Yan Chen 0004 |
Comput. Secur. | 5 |
| 2022 | HEDA: Multi-Attribute Unbounded Aggregation over Homomorphically Encrypted DatabaseabstractRecent years have witnessed the rapid development of the encrypted database, due to the increasing number of data privacy breaches and the corresponding laws and regulations that caused millions of dollars in loss. These encrypted databases may rely on different techniques, such as cryptographic primitives and trusted execution environments. In this work, we investigate the feasibility of utilizing fully homomorphic encryption (FHE) to support unbounded database aggregation queries, which typically involve comparisons as filtering predicates and a final aggregation. These operators are theoretically supported by FHE, but need careful algorithm design to maximize the efficiency and have not been explored before. We creatively use two types of FHE schemes, i.e. , one for numerical and one for binary value, to enjoy their advantages respectively. To bridge the encrypted values between these two schemes for seamless query processing without client-server interaction, we propose a novel ciphertext transformation mechanism, which is of independent research interest, to close this gap. We further implement our system and test it over three TPC-H queries and a query over a real social media e-commerce database. Evaluation results show that, to process an aggregation query over 8 k encrypted rows takes about 430 seconds. Although it is slower than plaintext processing in magnitudes and still has much room for improvement, as the very first work in this domain, our system demonstrates the feasibility of using FHE to process OLAP queries. Xuanle Ren, Le Su, Sheng Wang 0011, Feifei Li 0001, Yuan Xie 0001, Song Bian 0001, Fan Zhang 0010 |
Proc. VLDB Endow. | 9 |
| 2021 | Towards Understanding and Demystifying Bitcoin Mixing ServicesabstractOne reason for the popularity of Bitcoin is due to its anonymity. Although several heuristics have been used to break the anonymity, new approaches are proposed to enhance its anonymity at the same time. One of them is the mixing service. Unfortunately, mixing services have been abused to facilitate criminal activities, e.g., money laundering. As such, there is an urgent need to systematically understand Bitcoin mixing services. Lei Wu 0012, Yajin Zhou, Haoyu Wang 0001, Xiapu Luo, Zhi Wang 0004, Fan Zhang 0010, Kui Ren 0001 |
WWW | 7 |
| 2021 | G2F: A Secure User Authentication for Rapid Smart Home IoT ManagementabstractInternet-of-Things (IoT) devices are widely deployed nowadays. A large number of smart home IoT devices are hosted on a cloud server for easy management. Users can use their accounts to initiate operations and management on IoT devices through a cloud server, such as updating firmware and configuring devices. However, the cloud account may be hacked resulting in adversarial attacks to the hosted IoT devices. As a consequence, an adversary may perform malicious operations through the cloud remotely to the hosted IoT devices without user awareness. Motivated by this, in this article we propose gateway-based 2 factor authentication (G2F), a secure user authentication framework dedicated for a gateway based on the universal 2nd factor (U2F) protocol to enhance the security of IoT devices management. In G2F, the user authentication on the gateway is completed utilizing a hardware token that interacts with the local gateway node to guarantee the token owner’s presence. Furthermore, G2F can grant multiple simultaneous operations on IoT devices through just one user authentication. We implement a prototype to further evaluate the performance of G2F. Based on our realization on the commercial IoT server, i.e., Alibaba Cloud, G2F demonstrates the ability to protect against malicious attacks with high authentication efficiency. Chao Wang 0097, Hao Luo 0001, Fan Zhang 0010, Feng Lin 0004, Guoai Xu |
IEEE Internet Things J. | 4 |
| 2021 | Pushing the Limit of PFA: Enhanced Persistent Fault Analysis on Block CiphersabstractPersistent fault analysis (PFA) is a newly proposed cryptanalysis for block ciphers. Although the injected fault is persistent during the entire encryption, the corresponding analysis is only applied to the last round in the original PFA. In this article, the enhanced PFA (EPFA) is proposed, which can push the limit of PFA by exploiting the fault leakage in deeper rounds and target to reduce the number of required ciphertexts as small as possible. EPFA is first introduced as a general method with a specific application to advanced encryption standard (AES). Then it is extended to other substitution–permutation network (SPN)-based block ciphers, such as LED and SKINNY, both of which have unique features that EPFA fits well. To improve the efficiency of EPFA, a parallel algorithm based on mixed radix numbers is developed, which fully utilizes the power of GPU. Our experimental results show that EPFA can reduce the number of required ciphertexts to be under 1000, which is only about 40% of the 2500 ciphertexts in previous PFA on AES. In contrast to the single-threaded implementation, the parallel EPFA can have a speedup roughly about 200 times. Guorui Xu, Fan Zhang 0010, Bolin Yang, Xinjie Zhao 0001, Wei He 0015, Kui Ren 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2021 | hPRESS: A Hardware-Enhanced Proxy Re-Encryption Scheme Using Secure EnclaveabstractProxy re-encryption (PRE) allows a proxy to transform one ciphertext to another under different encryption keys while keeping the underlying plaintext secret. Because of the ciphertext transformability of PRE, there are many potential private communicating applications of this feature. However, existing PRE schemes are not as full-fledged as expected. The lack of necessary features makes them hard to apply in real-world scenarios. So far, there does not exist a unidirectional multihop PRE scheme with constant decryption efficiency and constant ciphertext size without extensions. Impractical performance and weak scalability also hinder PRE from most real-world applications. In this work, we present a new PRE scheme with secure hardware enclave namedhPRESS(hardware-enhanced PRE scheme using secure enclave). To the best of our knowledge,hPRESSis the first unidirectional multihop PRE scheme which achieves both constant decryption efficiency and constant ciphertext size without extensions. A detailed security analysis demonstrates that our proposal is CCA secure based on the security of the underlying encryption schemes and the secure enclave. We also implement a prototype based on Intel SGX, one of the most popular secure enclave techniques in recent years, and evaluate its performance. The experimental results show that, compared with previous PRE schemes, ourhPRESSis almost one order of magnitude faster in terms of the decryption and transformation. Fan Zhang 0010, Ziyuan Liang, Cong Zuo 0001, Jun Shao 0001, Jianting Ning, Jun Sun 0001, Joseph K. Liu, Yibao Bao |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2021 | Design and Evaluation of Fluctuating Power Logic to Mitigate Power Analysis at the Cell LevelabstractIn this article, we design a novel cell-level power-analysis countermeasure, named fluctuating power logic (FPL), which diffuses the correlation between the real power consumption and the fixed data transitions by employing acascade voltage logic. The countermeasure further acts as a cell-level$V_{DD}$randomizer, making it a strong candidate for implementing algorithmic countermeasure and exploiting its noise generation capabilities. This proposed scheme is illustrated by a standard flip-flop (FF). HSPICE-based simulation results show that the modified FF is resistant against power analysis (PA) at the cost of doubled power dissipation. Two illustrative case studies of PRESENT and AES substitutions have been explored. Furthermore, our proposal can be combined with other cell-level countermeasures against PA, such as wave dynamic differential logic. The resistance is evaluated by the correlation PA and the test vector leakage assessment. The new logic outperforms other counterparts in consideration of both security and cost, which renders it as a practical solution for resource-constrained systems. The proposed cell-level countermeasure can naturally mitigate other side-channel analysis such as electromagnetic analysis. Fan Zhang 0010, Bolin Yang, Bojie Yang, Xuanle Ren, Shivam Bhasin, Kui Ren 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2021 | Stealthy and Robust Glitch Injection Attack on Deep Learning Accelerator for Target With Variational ViewpointabstractDeep neural network (DNN) accelerators overcome the power and memory walls for executing neural-net models locally on edge-computing devices to support sophisticated AI applications. The advocacy of “model once, run optimized anywhere” paradigm introduces potential new security threat to edge intelligence that is methodologically different from the well-known adversarial examples. Existing adversarial examples modify the input samples presented to an AI application either digitally or physically to cause a misclassification. Nevertheless, these input-based perturbations are not robust or surreptitious on multi-view target. To generate a good adversarial example for misclassifying a real-world target of variational viewing angle, lighting and distance, a decent number of target’s samples are required to extract the rare anomalies that can cross the decision boundary. The feasible perturbations are substantial and visually perceptible. In this paper, we propose a new glitch injection attack on DNN accelerator that is capable of misclassifying a target under variational viewpoints. The glitches injected into the computation clock signal induce transitory but disruptive errors in the intermediate results of the multiply-and-accumulate (MAC) operations. The attack pattern for each target of interest consists of sparse instantaneous glitches, which can be derived from just one sample of the target. Two modes of attack patterns are derived, and their effectiveness are demonstrated on four representative ImageNet models implemented on the Deep-learning Processing Unit (DPU) of FPGA edge and its DNN development toolchain. The attack success rates are evaluated on 118 objects in 61 diverse sensing conditions, including 25 viewing angles (−60° to 60°), 24 illumination directions and 12 color temperatures. In the covert mode, the success rates of our attack exceed existing stealthy adversarial examples by more than 16.3%, with only two glitches injected into ten thousands to a million cycles for one complete inference. In the robust mode, the attack success rates on all four DNNs are more than 96.2% with an average glitch intensity of 1.4% and a maximum glitch intensity of 10.2%. Wenye Liu, Chip-Hong Chang, Fan Zhang 0010 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | Imperceptible Misclassification Attack on Deep Learning Accelerator by Glitch InjectionabstractThe convergence of edge computing and deep learning empowers endpoint hardwares or edge devices to perform inferences locally with the help of deep neural network (DNN) accelerator. This trend of edge intelligence invites new attack vectors, which are methodologically different from the well-known software oriented deep learning attacks like the input of adversarial examples. Current studies of threats on DNN hardware focus mainly on model parameters interpolation. Such kind of manipulation is not stealthy as it will leave non-erasable traces or create conspicuous output patterns. In this paper, we present and investigate an imperceptible misclassification attack on DNN hardware by introducing infrequent instantaneous glitches into the clock signal. Comparing with falsifying model parameters by permanent faults, corruption of targeted intermediate results of convolution layer(s) by disrupting associated computations intermittently leaves no trace. We demonstrated our attack on nine state-of-the-art ImageNet models running on Xilinx FPGA based deep learning accelerator. With no knowledge about the models, our attack can achieve over 98% misclassification on 8 out of 9 models with only 10% glitches launched into the computation clock cycles. Given the model details and inputs, all the test images applied to ResNet50 can be successfully misclassified with no more than 1.7% glitch injection. Wenye Liu, Chip-Hong Chang, Fan Zhang 0010, Xiaoxuan Lou |
DAC | 3 |
| 2020 | From Homogeneous to Heterogeneous: Leveraging Deep Learning based Power Analysis across DevicesabstractIn this paper, we raise practical situations in profiling based power analysis when profiling and target devices are quite different at several levels. "Crossed devices" are newly termed, including homogeneous and heterogeneous devices, which have not been carefully investigated. We identify such device variations and take a further step towards leveraging the deep learning based power analysis. Traditional template attacks and straight-forward deep learning based power analysis will fail, when the gap across devices is significantly enlarged. In this paper, we propose a noval frequency and learning based power analysis machanism, which is able to explore new attacking power of deep learning and address challenges caused by device variations. For the first time, power traces collected from our own PIC devices can be utilized to successfully attack the public dataset in DPAContest v4 which is based on a totally different AVR microcontroller. Fan Zhang 0010, Guorui Xu, Bolin Yang, Zhan Qin, Kui Ren 0001 |
DAC | 1 |
| 2020 | Active fuzzing for testing and securing cyber-physical systemsabstractCyber-physical systems (CPSs) in critical infrastructure face a pervasive threat from attackers, motivating research into a variety of countermeasures for securing them. Assessing the effectiveness of these countermeasures is challenging, however, as realistic benchmarks of attacks are difficult to manually construct, blindly testing is ineffective due to the enormous search spaces and resource requirements, and intelligent fuzzing approaches require impractical amounts of data and network access. In this work, we propose active fuzzing, an automatic approach for finding test suites of packet-level CPS network attacks, targeting scenarios in which attackers can observe sensors and manipulate packets, but have no existing knowledge about the payload encodings. Our approach learns regression models for predicting sensor values that will result from sampled network packets, and uses these predictions to guide a search for payload manipulations (i.e. bit flips) most likely to drive the CPS into an unsafe state. Key to our solution is the use of online active learning, which iteratively updates the models by sampling payloads that are estimated to maximally improve them. We evaluate the efficacy of active fuzzing by implementing it for a water purification plant testbed, finding it can automatically discover a test suite of flow, pressure, and over/underflow attacks, all with substantially less time, data, and network access than the most comparable approach. Finally, we demonstrate that our prediction models can also be utilised as countermeasures themselves, implementing them as anomaly detectors and early warning systems. Yuqi Chen 0001, Bohan Xuan, Christopher M. Poskitt, Jun Sun 0001, Fan Zhang 0010 |
ISSTA | 5 |
| 2020 | Theoretical analysis of persistent fault attack
Fan Zhang 0010, Guorui Xu, Bolin Yang, Ziyuan Liang, Kui Ren 0001 |
Sci. China Inf. Sci. | 1 |
| 2020 | Side-Channel Analysis and Countermeasure Design on ARM-Based Quantum-Resistant SIKEabstractThe implementations of post-quantum cryptographic algorithms have been newly explored, whereas, the protection against side-channel attacks shall be considered upfront, since it can have a non-negligible impact on security and performance. In this article, the security of supersingular isogeny key encapsulation (SIKE), a second-round candidate of NIST's on-going post-quantum standardization process, is thoroughly evaluated under side-channel analysis. First, the vulnerabilities of reference and optimized implementations of SIKE are thoroughly analyzed in terms of both horizontal and vertical side-channel leakage. After the optimized SIKE, which is based on Three-point Montgomery Differential Ladder algorithm, is proved to be constant-time and there is no horizontal leakage, a vertical vulnerability is analyzed based on the source code at the algorithmic level, and a theoretical differential power analysis (DPA) attack is proposed. In order to exploit this vulnerability, the differential electromagnetic attack (DEMA) is put into practice to extract the private key of SIKE based on a 32-bit ARM platform. To the best of our knowledge, this is the first practical side-channel attack at SIKE implemented on real ARM-based devices. Our experiments show that the DEMA needs only hundreds of electromagnetic traces to carry out the attack. More importantly, an efficient window-based countermeasure is proposed to eliminate the vertical leakage and prevent side-channel attacks with only a little overhead. The security of our countermeasure is carefully evaluated against most of well-known power analysis attacks. Through careful evaluation and comparison with other countermeasures, this method can lead to higher security at a very small cost in terms of time and memory. Fan Zhang 0010, Bolin Yang, Xiaofei Dong, Sylvain Guilley, Zhe Liu 0001, Wei He 0015, Fangguo Zhang, Kui Ren 0001 |
IEEE Trans. Computers | 1 |
| 2020 | A Lightweight Detection Algorithm For Collision-Optimized Divide-and-Conquer AttacksabstractBy introducing collision information into divide-and-conquer attacks, several existing works transform the original candidate space, which may be too large to enumerate, into a significantly smaller collision space, thus making key recovery possible. However, the inefficient collision detection algorithms and fault tolerance mechanisms make them time-consuming and their success rate low. Moreover, they may still leave very huge chain spaces that makes it difficult for key recovery. In this article, we exploit collision attack to optimize Template Attack (TA), and propose a Lightweight Collision Detection (LCD) algorithm. The proposed method exploits a jump detection mechanism to efficiently reduce the repetitive collision detections on chains with the same prefix sub-chains. We then introduce guessing theory to reorder the collision detection of the sub-keys according to their guessing lengths, and provide us with an evaluation tool. Finally, we design a highly efficient fault tolerance mechanism for our LCD to allow flexible thresholds adjustment, and further optimize sieving mechanism to efficiently extract the best chains with the largest number of collisions. Experimental results fully demonstrate LCD's superiority. Changhai Ou, Siew-Kei Lam, Chengju Zhou, Guiyuan Jiang, Fan Zhang 0010 |
IEEE Trans. Computers | 5 |
| 2020 | A Systematic Evaluation of Wavelet-Based Attack Framework on Random Delay CountermeasuresabstractRandom delay countermeasure is a commonly used defense against side-channel attacks, which brings certain interference and disturbance to those calculation sequences in the time domain. Data alignment and frequency attack are considered as typical techniques to counteract the random delay countermeasure. However, these attacks have limitations from the perspectives of both efficiency and performance. In comparison, facing those delays, wavelet analysis is considered as a more efficient technique due to its detailed and comprehensive interpretation of a signal. This paper applies different wavelet techniques to three attack components: noise reduction, trace alignment and key extraction. For the first time, the unified wavelet-based attack framework against random delays is proposed where wavelet analysis is fully applied in the entire attack life cycle. In particular, a novel method of trace alignment at the wavelet level is proposed in this framework, which is based on wavelet pattern detection to synchronize the misaligned power traces. Most importantly, the overall wavelet-based attack framework is systematically evaluated over three random delay strategies, after the respective contribution of each component is investigated through a series of comparative experiments. Experimental results show that the performance of the wavelet-based attack framework is significantly improved compared to standard attack procedures and frequency ones, which can be regarded as a unified and effective solution to conquer random delay countermeasures. Fan Zhang 0010, Xiaofei Dong, Bolin Yang, Yajin Zhou, Kui Ren 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | Adversarial Structured Neural Network PruningabstractIn recent years, convolutional neural networks (CNN) have been successfully employed for performing various tasks due to their high capacity. However, just like a double-edged sword, high capacity results from millions of parameters, which also brings a huge amount of redundancy and dramatically increases the computational complexity. The task of pruning a pretrained network to make it thinner and easier to deploy on resource-limited devices is still challenging. In this paper, we employ the idea of adversarial examples to sparsify a CNN. Adversarial examples were originally designed to fool a network. Rather than adjusting the input image, we view any layer as an input to the layers afterwards. By performing an adversarial attack algorithm, the sensitivity information of the network components could be observed. With this information, we perform pruning in a structured manner to retain only the most critical channels. Empirical evaluations show that our proposed approach obtains the state-of-the-art structured pruning performance. Xingyu Cai, Jinfeng Yi, Fan Zhang 0010, Sanguthevar Rajasekaran |
CIKM | 3 |
| 2019 | Enhanced Differential Cache Attacks on SM4 with Algebraic Analysis and Error-Tolerance
Xiaoxuan Lou, Fan Zhang 0010, Guorui Xu, Ziyuan Liang, Xinjie Zhao 0001, Shize Guo, Kui Ren 0001 |
Inscrypt | 2 |
| 2019 | One Fault is All it Needs: Breaking Higher-Order Masking with Persistent Fault AnalysisabstractPersistent fault analysis (PFA) was proposed at CHES 2018 as a novel fault analysis technique. It was shown to completely defeat standard redundancy based countermeasure against fault analysis. In this work, we investigate the security of masking schemes against PFA. We show that with only one fault injection, masking countermeasures can be broken at any masking order. The study is performed on publicly available implementations of masking. Jingyu Pan, Fan Zhang 0010, Kui Ren 0001, Shivam Bhasin |
DATE | 2 |
| 2019 | Learning-Guided Network Fuzzing for Testing Cyber-Physical System DefencesabstractThe threat of attack faced by cyber-physical systems (CPSs), especially when they play a critical role in automating public infrastructure, has motivated research into a wide variety of attack defence mechanisms. Assessing their effectiveness is challenging, however, as realistic sets of attacks to test them against are not always available. In this paper, we propose smart fuzzing, an automated, machine learning guided technique for systematically finding 'test suites' of CPS network attacks, without requiring any knowledge of the system's control programs or physical processes. Our approach uses predictive machine learning models and metaheuristic search algorithms to guide the fuzzing of actuators so as to drive the CPS into different unsafe physical states. We demonstrate the efficacy of smart fuzzing by implementing it for two real-world CPS testbeds—a water purification plant and a water distribution system—finding attacks that drive them into 27 different unsafe states involving water flow, pressure, and tank levels, including six that were not covered by an established attack benchmark. Finally, we use our approach to test the effectiveness of an invariant-based defence system for the water treatment plant, finding two attacks that were not detected by its physical invariant checks, highlighting a potential weakness that could be exploited in certain conditions. Yuqi Chen 0001, Christopher M. Poskitt, Jun Sun 0001, Sridhar Adepu, Fan Zhang 0010 |
ASE | 5 |
| 2019 | Passive Attacks Against Searchable EncryptionabstractSearchable encryption (SE) provides a privacy-preserving mechanism for data users to search over encrypted data stored on a remote server. Researchers have designed a number of SE schemes with high efficiency yet allowing some degree of leakage profile to the remote server. The leakage, however, should be further measured to allow us to understand what types of attacks an SE scheme would encounter. This paper considers passive attacks that make inferences based on prior knowledge and observations on queries issued by users. This is in contrast to previously studied active attacks that adaptively inject files and queries. We consider several assumptions on the types or prior knowledge the attacker possessed and propose a few passive attacks. In particular, under the “full-fledged” assumption, the keyword recovery rate of our attack is optimal in the sense that it is equal to the theoretical upper bound. We further present several enhanced attacks under other weaker assumptions on various levels of the prior knowledge that the attacker can obtain, in which the keyword recovery rates are optimal or nearly optimal (i.e., approaching the theoretical upper bound). In addition, we provide extensive experiments to show the “power” of our passive attacks. This paper highlights the importance of minimizing the prior knowledge of a server and the leakage of search queries. It also shows that simply distorting the frequency of the keyword to hold against our passive attacks may not scale well. Jianting Ning, Jia Xu 0006, Kaitai Liang, Fan Zhang 0010, Ee-Chien Chang |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2019 | Managing Recurrent Virtual Network Updates in Multi-Tenant Datacenters: A System PerspectiveabstractWith the advent of software-defined networking, network configuration through programmable interfaces becomes practical, leading to various on-demand opportunities for network routing update in multi-tenant datacenters, where tenants have diverse requirements on network routings such as short latency, low path inflation, large bandwidth, high reliability, etc. Conventional solutions that rely on topology search coupled with an objective function to find desired routings have at least two shortcomings: ${\sf (i)}$(i) they run into scalability issues when handling consistent and frequent routing updates and ${\sf (ii)}$(ii) they restrict the flexibility and capability to satisfy various routing requirements. To address these issues, this paper proposes a novel search and optimization decoupled design, which not only saves considerable topology search costs via search result reuse, but also avoids possible sub-optimality in greedy routing search algorithms by making decisions based on the global view of all possible routings. We implement a prototype of our proposed system, OpReduce, and perform extensive evaluations to validate its design goals. Zhuotao Liu, Yuan Cao 0003, Xuewu Zhang 0001, Changping Zhu, Fan Zhang 0010 |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2018 | Optimized Lightweight Hardware Trojan-Based Fault Attack on DESabstractAn optimized lightweight Hardware Trojan (HT)based fault attack is proposed, especially for those resource-constrained environments such as IoT networks. Firstly, Algebraic fault analysis (AFA)is introduced to evaluate different fault models and search for the optimal one. Next, considering the limited resource, a lightweight HT is carefully designed which only flips one bit of the circuit in IoT device. Finally, AFA is applied again to exploit the fault and recover the secret key. An illustrative attack is demonstrated on DES implemented on an FPGA platform, SASEBO-GII. This paper shows that, for single bit fault injection at different rounds or different indexes in the same round, the reduced key search space of DES varies. The proposed technique can search for the optimal fault model, guide the lightweight Hardware Trojan design and automatically recover the secret key. Only one fault is required to recover the secret key of DES, which improves the stealthiness of the designed Hardware Trojan in IoT networks. The entire attack framework can also be applied to other block ciphers such as AES and PRESENT. Fan Zhang 0010, Shengwen Shi, Shize Guo, Ziyuan Liang, Samiya Qureshi, Congyuan Xu |
ICPADS | 1 |
| 2018 | Improved Differential Fault Analysis on LED with Constraint Equations: Towards Reaching Its LimitabstractThe block cipher LED is well suited for resource-constrained scenarios. However, it is vulnerable to the recent fault attacks and different results have been achieved even under the same fault model. In this paper, a comprehensive investigation is conducted on the fault analysis on LED. A novel differential fault analysis is proposed, which is based on the so-called constraint equations. The proposed attack can combine constraint equations at different levels, pushing the differential fault analysis on LED towards its limit in terms of the time complexity, the data complexity and the remained key search space. Under random nibble fault model, SINGLE fault injection can reduce the key search space of LED-64 to 27.90within 1.89s, compared to 217.65within 7 minutes in prior finest contributions. As to DFA on LED-128, TWO fault injections can reduce the key search space to 215.82within 247.88s, compared to 221.96within 16 minutes in previous work. To the best of our knowledge, the scheme that we proposed is the most efficient fault attack on LED cryptosystems. Fan Zhang 0010, Xinjie Zhao 0001, Shize Guo, Ziyuan Liang, Samiya Qureshi |
ICPADS | 1 |
| 2018 | Theoretical Round Modification Fault Analysis on AEGIS-128 with Algebraic TechniquesabstractThis paper proposed an advanced round modification fault analysis (RMFA) at the theoretical level on AEGIS-128, which is one of seven finalists in CAESAR competition. First, we clarify our assumptions and simplifications on the attack model, focusing on the encryption security. Then, we emphasize the difficulty of applying vanilla RMFA to AEGIS-128 in the practical case. Finally we demonstrate our advanced fault analysis on AEGIS-128 using machine-solver based algebraic techniques. Our enhancement can be used to conquer the practical scenario which is difficult for vanilla RMFA. Simulation results show that when the fault is injected to the initialization phase and the number of rounds is reduced to one, two samples of injections can extract the whole 128 key bits within less than two hours. This work can also be extended to other versions such as AEGIS-256. Fan Zhang 0010, Xiaofei Dong, Xinjie Zhao 0001, Samiya Qureshi, Xiaoxuan Lou, Yongkang Tang |
MASS | 1 |
| 2018 | Efficient Approximate Algorithms for the Closest Pair Problem in High Dimensional Spaces
Xingyu Cai, Sanguthevar Rajasekaran, Fan Zhang 0010 |
PAKDD (3) | 3 |
| 2018 | Optimal model search for hardware-trojan-based bit-level fault attacks on block ciphers
Xinjie Zhao 0001, Fan Zhang 0010, Shize Guo |
Sci. China Inf. Sci. | 2 |
| 2018 | Efficient flush-reload cache attack on scalar multiplication based signature algorithm
Tao Wang 0008, Xiaoxuan Lou, Xinjie Zhao 0001, Fan Zhang 0010, Shize Guo |
Sci. China Inf. Sci. | 5 |
| 2018 | Survey of design and security evaluation of authenticated encryption algorithms in the CAESAR competitionabstractThe Competition for Authenticated Encryption: Security, Applicability, and Robustness (CAESAR) supported by the National Institute of Standards and Technology (NIST) is an ongoing project calling for submissions of authenticated encryption (AE) schemes. The competition itself aims at enhancing both the design of AE schemes and related analysis. The design goal is to pursue new AE schemes that are more secure than advanced encryption standard with Galois/counter mode (AES-GCM) and can simultaneously achieve three design aspects: security, applicability, and robustness. The competition has a total of three rounds and the last round is approaching the end in 2018. In this survey paper, we first introduce the requirements of the proposed design and the progress of candidate screening in the CAESAR competition. Second, the candidate AE schemes in the final round are classified according to their design structures and encryption modes. Third, comprehensive performance and security evaluations are conducted on these candidates. Finally, the research trends of design and analysis of AE for the future are discussed. Fan Zhang 0010, Ziyuan Liang, Bolin Yang, Xinjie Zhao 0001, Shize Guo, Kui Ren 0001 |
Frontiers Inf. Technol. Electron. Eng. | 1 |
| 2017 | Transistor level SCA-resistant scheme based on fluctuating power logic
Liang Geng, Fan Zhang 0010, Jizhong Shen, Wei He 0015, Shivam Bhasin, Xinjie Zhao 0001, Shize Guo |
Sci. China Inf. Sci. | 2 |
| 2017 | Low-cost design of stealthy hardware trojan for bit-level fault attacks on block ciphers
Fan Zhang 0010, Xinjie Zhao 0001, Wei He 0015, Shivam Bhasin, Shize Guo |
Sci. China Inf. Sci. | 1 |
| 2017 | Stealthy Hardware Trojan Based Algebraic Fault Analysis of HIGHT Block CipherabstractHIGHT is a lightweight block cipher which has been adopted as a standard block cipher. In this paper, we present a bit-level algebraic fault analysis (AFA) of HIGHT, where the faults are perturbed by a stealthy HT. The fault model in our attack assumes that the adversary is able to insert a HT that flips a specific bit of a certain intermediate word of the cipher once the HT is activated. The HT is realized by merely 4 registers and with an extremely low activation rate of about 0.000025. We show that the optimal location for inserting the designed HT can be efficiently determined by AFA in advance. Finally, a method is proposed to represent the cipher and the injected faults with a merged set of algebraic equations and the master key can be recovered by solving the merged equation system with an SAT solver. Our attack, which fully recovers the secret master key of the cipher in 12572.26 seconds, requires three times of activation on the designed HT. To the best of our knowledge, this is the first Trojan attack on HIGHT. Hao Chen 0003, Tao Wang 0008, Fan Zhang 0010, Xinjie Zhao 0001, Wei He 0015, Lumin Xu |
Secur. Commun. Networks | 3 |
| 2016 | A Framework for the Analysis and Evaluation of Algebraic Fault Attacks on Lightweight Block CiphersabstractAlgebraic fault analysis (AFA), which combines algebraic cryptanalysis with fault attacks, has represented serious threats to the security of lightweight block ciphers. Inspired by an earlier framework for the analysis of side-channel attacks presented at EUROCRYPT 2009, a new generic framework is proposed to analyze and evaluate algebraic fault attacks on lightweight block ciphers. We interpret AFA at three levels: 1) the target; 2) the adversary; and 3) the evaluator. We describe the capability of an adversary in four parts: 1) the fault injector; 2) the fault model describer; 3) the cipher describer; and 4) the machine solver. A formal fault model is provided to cover most of current fault attacks. Different strategies of building optimal equation set are also provided to accelerate the solving process. At the evaluator level, we consider the approximate information metric and the actual security metric. These metrics can be used to guide adversaries, cipher designers, and industrial engineers. To verify the feasibility of the proposed framework, we make a comprehensive study of AFA on an ultra-lightweight block cipher called LBlock. Three scenarios are exploited, which include injecting a fault to encryption, to key scheduling, or modifying the round number or counter. Our best results show that a single fault injection is enough to recover the master key of LBlock within the affordable complexity in each scenario. To verify the generic feature of the proposed framework, we apply AFA to three other block ciphers, i.e., Data Encryption Standard, PRESENT, and Twofish. The results demonstrate that our framework can be used for different ciphers with different structures. Fan Zhang 0010, Shize Guo, Xinjie Zhao 0001, Tao Wang 0008, Jian Yang 0018, François-Xavier Standaert, Dawu Gu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2014 | Algebraic Fault Analysis on GOST for Key Recovery and Reverse EngineeringabstractGOST is a well-known block cipher as the official encryption standard for the Russian Federation. A special feature of GOST is that its eight S-boxes can be secret. However, most of the researches on GOST assume that the design of these S-boxes is known. In this paper, the security of GOST against side-channel attacks is examined with algebraic fault analysis (AFA), which combines the algebraic cryptanalysis with the fault attack. Three AFAs on GOST, which have different attack goals in different scenarios, are investigated. The results show that 8 fault injections are required to recover the secret key when the full design of GOST is known, which is less than 64 fault injections required in previous work. 64 fault injections are required to recover the eight unknown S-boxes assuming the key is known. 270 fault injections are required to recover the key and the eight S-boxes when both are unknown. The results prove that AFA is very effective and keeping some components in a cipher secret cannot guarantee its security against fault attacks. Xinjie Zhao 0001, Shize Guo, Fan Zhang 0010, Tao Wang 0008, Zhijie Jerry Shi, Chujiao Ma, Dawu Gu |
FDTC | 3 |
| 2014 | Exploiting the Incomplete Diffusion Feature: A Specialized Analytical Side-Channel Attack Against the AES and Its Application to Microcontroller ImplementationsabstractAlgebraic side-channel attack (ASCA) is a typical technique that relies on a general solver to solve the equations of a cipher and its side-channel leaks. It falls under analytical side-channel attack and can recover the entire key at once. Many ASCAs are proposed against the AES, and they utilize the Gröbner basis-based, SAT-based, or optimizer-based solver. The advantage of the general solver approach is its generic feature, which can be easily applied to different cryptographic algorithms. The disadvantage is that it is difficult to take into account the specialized properties of the targeted cryptographic algorithms. The results vary depending on what type of solver is used, and the time complexity is quite high when considering the error-tolerant attack scenarios. Thus, we were motivated to find a new approach that would lessen the influence of the general solver and reduce the time complexity of ASCA. This paper proposes a new analytical side-channel attack on AES by exploiting the incomplete diffusion feature in one AES round. We named our technique incomplete diffusion analytical side-channel analysis (IDASCA). Different from previous ASCAs, IDASCA adopts a specialized approach to recover the secret key of AES instead of the general solver. Extensive attacks are performed against the software implementation of AES on an 8-bit microcontroller. Experimental results show that: 1) IDASCA can exploit the side-channel leaks in all AES rounds using a single power trace; 2) it has less time complexity and more robustness than previous ASCAs, especially when considering the error-tolerant attack scenarios; and 3) it can calculate the reduced key search space of AES for the given amount of side-channel leaks. IDASCA can also interpret the mechanism behind previous ASCAs on AES from a quantitative perspective, such as why ASCA can work under unknown plaintext/ciphertext scenarios and what are the extreme cases in ASCAs. Shize Guo, Xinjie Zhao 0001, Fan Zhang 0010, Tao Wang 0008, Zhijie Jerry Shi, François-Xavier Standaert, Chujiao Ma |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2013 | Improving and Evaluating Differential Fault Analysis on LED with Algebraic TechniquesabstractThis paper proposes a fault analysis technique on LED by combining algebraic cryptanalysis and differential fault analysis (DFA). The technique is called algebraic differential fault analysis (ADFA). In ADFA on LED, we use DFA to deduce the possible fault differences of the correct and faulty S-Box input in the last round, and convert them into algebraic equations. We then combine the equation set of LED with the injected fault and use the CryptoMiniSat solver to recover the secret key. Our experiments show that, on a common PC, ADFA can succeed on LED under the nibble-based fault model within three minutes and with only one fault injection, which is more efficient than previous DFA work. To evaluate DFA on LED, we first propose an improved evaluation algorithm of DFA, then provide a modified ADFA approach to compute the solutions for the secret key. The results are more accurate than previous work. We also successfully extend ADFA on LED to other fault models using a single fault injection, where traditional DFAs are difficult to launch. Xinjie Zhao 0001, Shize Guo, Fan Zhang 0010, Zhijie Jerry Shi, Chujiao Ma, Tao Wang 0008 |
FDTC | 3 |
| 2013 | A comprehensive study of multiple deductions-based algebraic trace driven cache attacks on AES
Xinjie Zhao 0001, Shize Guo, Fan Zhang 0010, Tao Wang 0008, Zhijie Jerry Shi, Zhe Liu 0001, Jean-François Gallais |
Comput. Secur. | 3 |
| 2013 | Efficient Hamming weight-based side-channel cube attacks on PRESENT
Xinjie Zhao 0001, Shize Guo, Fan Zhang 0010, Tao Wang 0008, Zhijie Jerry Shi, Keke Ji |
J. Syst. Softw. | 3 |
| 2008 | Making register file resistant to power analysis attacksabstractPower analysis attacks are a type of side-channel attacks that exploits the power consumption of computing devices to retrieve secret information. They are very effective in breaking many cryptographic algorithms, especially those running in low-end processors in embedded systems, sensor nodes, and smart cards. Although many countermeasures to power analysis attacks have been proposed, most of them are software based and designed for a specific algorithm. Many of them are also found vulnerable to more advanced attacks. Looking for a low-cost, algorithm-independent solution that can be implemented in many processors and makes all cryptographic algorithms secure against power analysis attacks, we start with register file, where the operands and results of most instructions are stored. In this paper, we propose RFRF, a register file that stores data with a redundant flipped copy. With the redundant copy and a new precharge phase in write operations, RFRF provides data-independent power consumption on read and write for cryptographic algorithms. Although RFRF has large energy overhead, it is only enabled in the security mode. We validate our method with simulations. The results show that the power consumption of RFRF is independent of the values read out from or written to registers. Thus RFRF can help mitigate power analysis attacks. Fan Zhang 0010, Jianwei Dai, Lei Wang 0003, Zhijie Jerry Shi |
ICCD | 2 |