Haoqi Shan

dblp:211/3822 · DBLP profile ↗
← Back
7ranked-venue papers
1as first author
6since 2021 · last 2024
0000-0003-1440-1828ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 4 since 2021Systems, architecture and hardware · 3 · 2 since 2021
YearPublicationVenuePosition
2024 GAZEploit: Remote Keystroke Inference Attack by Gaze Estimation from Avatar Views in VR/MR Devices
abstract
The advent and growing popularity of Virtual Reality (VR) and Mixed Reality (MR) solutions have revolutionized the way we interact with digital platforms. The cutting-edge gaze-controlled typing methods, now prevalent in high-end models of these devices, e.g., Apple Vision Pro, have not only improved user experience but also mitigated traditional keystroke inference attacks that relied on hand gestures, head movements and acoustic side-channels. However, this advancement has paradoxically given birth to a new, potentially more insidious cyber threat, GAZEploit.
Hanqiu Wang, Zihao Zhan, Haoqi Shan, Siqi Dai, Max Panoff, Shuo Wang 0003
CCS3
2024 VoltSchemer: Use Voltage Noise to Manipulate Your Wireless Charger
Zihao Zhan, Yirui Yang, Haoqi Shan, Hanqiu Wang, Yier Jin, Shuo Wang 0003
USENIX Security Symposium3
2023 PDNPulse: Sensing PCB Anomaly With the Intrinsic Power Delivery Network
abstract
The ubiquitous presence of printed circuit boards (PCBs) in modern electronic systems and embedded devices makes their integrity a top security concern. To take advantage of the economies of scale, today’s PCB design and manufacturing are often performed by suppliers around the globe, exposing them to many security vulnerabilities along the segmented PCB supply chain. Moreover, the increasing complexity of the PCB designs also leaves ample room for numerous sneaky board-level attacks to be implemented throughout each stage of a PCB’s lifetime, threatening many electronic devices. In this paper, we proposePDNPulse, a power delivery network (PDN) based PCB anomaly detection framework that can identify a wide spectrum of board-level malicious modifications. PDNPulse leverages the fact that the PDN’s characteristics are inevitably affected by modifications to the PCB. By detecting changes to the PDN impedance profile against the golden model and using the Frechet distance-based anomaly detection algorithms, PDNPulse can robustly and successfully discern malicious modifications across the system. Using PDNPulse, we conduct extensive experiments on seven commercial-off-the-shelf PCBs, covering different design scales, different threat models, and seven different anomaly types. The results confirm that PDNPulse creates an effective security asymmetry between attack and defense.
Huifeng Zhu, Haoqi Shan, Dean Sullivan, Xiaolong Guo 0001, Yier Jin, Xuan Zhang 0001
IEEE Trans. Inf. Forensics Secur.2
2022 Invisible Finger: Practical Electromagnetic Interference Attack on Touchscreen-based Electronic Devices
abstract
Touchscreen-based electronic devices such as smart phones and smart tablets are widely used in our daily life. While the security of electronic devices have been heavily investigated recently, the resilience of touchscreens against various attacks has yet to be thoroughly investigated. In this paper, for the first time, we show that touchscreen-based electronic devices are vulnerable to intentional electromagnetic interference (IEMI) attacks in a systematic way and how to conduct this attack in a practical way. Our contribution lies in not just demonstrating the attack, but also analyzing and quantifying the underlying mechanism allowing the novel IEMI attack on touchscreens in detail. We show how to calculate both the minimum amount of electric field and signal frequency required to induce touchscreen ghost touches. We further analyze our IEMI attack on real touchscreens with different magnitudes, frequencies, duration, and multitouch patterns. The mechanism of controlling the touchscreen-enabled electronic devices with IEMI signals is also elaborated. We design and evaluate an out-of-sight touchscreen locator and touch injection feedback mechanism to assist a practical IEMI attack. Our attack works directly on the touchscreen circuit regardless of the touchscreen scanning mechanism or operating system. Our attack can inject short-tap, long-press, and omnidirectional gestures on touchscreens from a distance larger than the average thickness of common tabletops. Compared with the state-of-the-art touchscreen attack, ours can accurately inject different types of touch events without the need for sensing signal synchronization, which makes our attack more robust and practical. In addition, rather than showing a simple proof-of-concept attack, we present and demonstrate the first ready-to-use IEMI based touchscreen attack vector with end-to-end attack scenarios
Haoqi Shan, Zihao Zhan, Dean Sullivan, Shuo Wang 0003, Yier Jin
SP1
2022 A Review and Comparison of AI-enhanced Side Channel Analysis
abstract
Side Channel Analysis (SCA) presents a clear threat to privacy and security in modern computing systems. The vast majority of communications are secured through cryptographic algorithms. These algorithms are often provably-secure from a cryptographical perspective, but their implementation on real hardware introduces vulnerabilities. Adversaries can exploit these vulnerabilities to conduct SCA and recover confidential information, such as secret keys or internal states. The threat of SCA has greatly increased as machine learning, and in particular deep learning, enhanced attacks become more common. In this work, we will examine the latest state-of-the-art deep learning techniques for side channel analysis, the theory behind them, and how they are conducted. Our focus will be on profiling attacks using deep learning techniques, but we will also examine some new and emerging methodologies enhanced by deep learning techniques, such as non-profiled attacks, artificial trace generation, and others. Finally, different deep learning–enhanced SCA schemes attempted against the ANSSI SCA Database and their relative performance will be evaluated and compared. This will lead to new research directions to secure cryptographic implementations against the latest SCA attacks.
Max Panoff, Honggang Yu, Haoqi Shan, Yier Jin
ACM J. Emerg. Technol. Comput. Syst.3
2021 Cross-Device Profiled Side-Channel Attacks using Meta-Transfer Learning
abstract
Deep learning (DL) based profiling side channel analysis (SCA) pose a great threat to embedded devices. An adversary can break the target encryption engine through physical leakage of power or electromagnetic (EM) emanations collected from a profiling device. However, creating a successful DL based SCA model relies on a large amount of data. This presents a large barrier to those interested in applying DL for SCA. In this paper, we propose a novel attack mechanism that adopts meta-transfer learning to transfer DL networks among target devices by judiciously extracting information from a profiling device even using different side-channel sources. Supported by our method, a cross-device and/or cross-domain SCA attack becomes possible among different designs. In comparison to previous attack methodologies, we significantly reduce training costs and the number of traces $(\lt 3$ for power and $\lt 8$ for EM) required for SCA attacks on both unprotected or masked Advanced Encryption Standard (AES) implementations.
Honggang Yu, Haoqi Shan, Max Panoff, Yier Jin
DAC2
2020 SaeCAS: Secure Authenticated Execution Using CAM-Based Vector Storage
abstract
Authenticated execution (AE) is a security mechanism that cryptographically validates an application's code as it executes, as well as verifies its control flow. AE provides fully local guarantees which can deliver protection for control flow, instruction flow, and software intellectual property which makes it ideal for devices with little to no connectivity. However, we find that previous AE approaches make concessions in their implementation that severely hinder their security guarantees. In this article, we examine the weaknesses in previous AE approaches and why they occur. We also introduce SAECAS as a mechanism to reliably perform AE in an embedded device. We formally prove the security aspects of SAECAS, demonstrating its security capabilities. Moreover, we implement SAECAS on a RISC-V core and test it on a Terasic DE2-115 FPGA board to demonstrate its capabilities, showing that a reliable system can be made with a hardware overhead of ≈ 2× when including extra SoC components and no performance impact.
Orlando Arias, Dean Sullivan, Haoqi Shan, Yier Jin
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.3