Zhongkai Tong

dblp:224/9686 · DBLP profile ↗
← Back
9ranked-venue papers
4as first author
6since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Security and privacy · 2 · 1 first-authorComputer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 Sample augmentation-based adversarial training method to counter evasive spectre attacks
Zhongkai Tong
Eng. Appl. Artif. Intell.1
2024 A Module Level Security Evaluation Method Based on Model Checking
abstract
Processors are an important component of computer systems, but resource sharing in space and time, as well as performance first design concepts, result in a series of security issues for processors. On the one hand, processor security evaluation can systematically analyze and verify the security of the processor, deduce the key reasons for security risks, and on the other hand, it can assist in processor design, verifying processor security at a lower cost at the beginning of the design, compared to later software and hardware protection.This paper proposes a module level security evaluation method based on model checking, modeling the module as a mealy finite state machine to analyze the relationship between its outputs, inputs and states. Computational Logic Tree (CTL) is used to represent possible execution paths, and all paths are traversed to derive counterexample paths to represent possible attack paths and information leakage processes. We use the Common Vulnerability Scoring System(CVSS) to score each counterexample path. Based on these counterexample paths and CVSS scores, we ultimately obtained a total risk score to represent the security of the module. We conduct a case study on Cache to verify the effectiveness of our proposed method.
Yusha Zhang, Zhongkai Tong, Wenjing Cai, Dan Meng 0002
CSCWD4
2024 KSM: Killer of Spectre and Meltdown Attacks
abstract
In the relentless pursuit of bolstering processor performance, computer architects have harnessed a gamut of sophisticated optimization techniques. However, this pursuit of performance enhancements has inadvertently laid bare an underbelly of concealed security vulnerabilities, exemplified by notorious instances such as Meltdown and Spectre attacks. These attacks adeptly exploit optimization techniques, coupled with cache side-channel attacks, to expose protected data. The ripple effects of these vulnerabilities are indeed seismic, owing to their pervasive presence across existing and forthcoming processors. Regrettably, Meltdown and Spectre have remained elusive to satisfactory mitigation to date; instead, Spectre and Meltdown attack variations have sprung forth from them. In response to this challenge, this paper posits an approach. It proposes the optimization of four distinctive hardware performance events through feature selection, subsequently harnessing the prowess of machine learning algorithms to forge a real-time detection mechanism. This mechanism is primed to combat Spectre V1, V2, V4, and Meltdown attack variations, culminating in a robust accuracy rate exceeding 99%. This resounding success demonstrates that this paper’s framework not only confronts original attacks but also grapples effectively with diverse attack variants, a scenario that might manifest in everyday contexts.
Zhongkai Tong, Yusha Zhang, Dan Meng 0002
CSCWD1
2024 A Formal Verification Methodology for Cache Architectures Based on Noninterference Hyperproperties
abstract
The design of secure cache architectures within computer systems primarily aims to mitigate side-channel attacks and minimize the risks of information leakage. However, verifying the effectiveness of secure cache designs introduces numerous challenges. The assessment of cache architecture security in prior research has mainly been based on the evaluators’ expertise, which lacks convincing evidence. Therefore, it is imperative to establish a universal and comprehensive formal verification methodology to evaluate the security of cache designs. This paper analyzes the advantages and disadvantages of an existing formal verification method. Based on this analysis, we introduce an enhanced formal verification method that utilizes noninterference hyperproperties to verify the security of cache architectures.In this paper, an extended triple mutual information formula is utilized to verify the satisfaction of noninterference hyperproperties within cache architectures and identify potential information leakages through three independence conditions. The degree of information leakage is evaluated by measuring the dependencies between the victim’s inputs and the attacker’s observations through triple mutual information. This paper instantiates existing cache architectures and reveals potential vulnerabilities by formalizing the behavior specification and replacement policy of a cache as an extended abstract state machine. Lastly, the cache security structure is formally validated utilizing the proposed security model, with the aim of evidencing its effectiveness and soundness.
Yusha Zhang, Zhongkai Tong, Wenjing Cai, Dan Meng 0002
CSCWD4
2022 Analysis of DRAM Vulnerability Using Computation Tree Logic
abstract
Shared resources facilitate both side and covert channels and greatly endanger information security even in cloud environments. In cloud computing environments, multiple tenants often reside on the same multi-processor system. Therefore, it is important to prevent information leakage between tenants. Shared memory between tenants is usually disabled for security reasons. In addition, tenants typically do not share physical CPUs. In this case, cache attacks do not work. As a common shared resource, DRAM memory can also be exploited as a source of side and covert channels.In this paper, Computation Tree Logic (CTL) is used to model the behaviors of row buffer logic in DRAM and derive all possible timing-based vulnerabilities. The problem of state space explosion is alleviated by using bounded model checking in this method. In total, our method derives 24 kinds of DRAM timing-based vulnerabilities. Furthermore, we analyze DRAM vulnerabilities to help engineers understand them and take corresponding measures in the design according to derived security specifications.
Yusha Zhang, Zhongkai Tong, Wenjing Cai, Dan Meng 0002
ICC4
2021 An Effective Approach for Malware Detection and Explanation via Deep Learning Analysis
abstract
The next generation attackers often generate malware variants with Artificial Intelligence (AI) weapons, which are deliberately designed to evade antivirus engines. Security defenders propose many AI-based approaches to detect the massive number of malware variants. However, most AI-based malware detection approaches only output a label to users, and these labels are mainly unexplainable. The lack of transparency has introduced many black-box attacks. Malware developers can develop adversarial examples to evade these AI-based malware detection systems. In this paper, we propose an effective approach for malware detection and explanation, which can locate malicious code snippets by explaining the malware classifier decision result. To this end, firstly, we get the system call number sequence of the target sample with instrumentation tools in an elaborated sandbox. Secondly, we feed the mapped system call number sequence into a deep learning model to make a decision on whether the target sample is benign or malicious. Thirdly, we adopt the Layer-wise Relevance Propagation algorithm to find which slice of a sequence makes the greatest contribution in the decision. Our evaluation demonstrates that our approach achieves high classification accuracy (97.39%), reduces the neural network size by 20 times, and saves the malware analyst time to locate malicious code snippets.
Huozhu Wang, Zhongkai Tong, Yusi Feng, Dan Meng 0002
IJCNN3
2020 Cache side-channel attacks detection based on machine learning
abstract
Security has always been one of the main concerns in the field of computer architecture and cloud computing. Cache-based side-channel attacks pose a threat to almost all existing architectures and cloud computing. Especially in the public cloud, the cache is shared among multiple tenants, and cache attacks can make good use of this to extract information. Cache side-channel attacks are a problem to be solved for security, in which how to accurately detect cache side-channel attacks has been a research hotspot. Because the cache side-channel attack does not require the attacker to physically contact the target device and does not need additional devices to obtain the side channel information, the cache-side channel attack is efficient and hidden, which poses a great threat to the security of cryptographic algorithms. Based on the AES algorithm, this paper uses hardware performance counters to obtain the features of different cache events under Flush + Reload, Prime + Probe, and Flush + Flush attacks. Firstly, the random forest algorithm is used to filter the cache features, and then the support vector machine algorithm is used to model the system. Finally, high detection accuracy is achieved under different system loads. The detection accuracy of the system is 99.92% when there is no load, the detection accuracy is 99.85% under the average load, and the detection accuracy under full load is 96.57%.
Zhongkai Tong, Zhanpeng Wang, Yusha Zhang
TrustCom1
2020 SCPORAM: a hardware support scheme for protecting memory access patterns
abstract
Oblivious RAM is a cryptographic protocol for hiding memory access patterns in the un-trusted external storage environment. Recently, Path ORAM has received wide attentions due to its simplicity and efficiency in secure processor design. Unfortunately, the memory bandwidth demand for Path ORAM is still too high, which restricts Path ORAM from further development. But overlapping paths can be cached to reduce memory bandwidth without the loss of security. In this paper, we present SCPORAM (Self Clustering Path ORAM), a clustering method for path merging, which transform memory requests into different categories. For each set, the intersection can be cached for every member sharing. Therefore, SCPORAM has the ability to effectively reduce memory access bandwidth. Based on this algorithm, a new ORAM controller is proposed. Compared to baseline Path ORAM, SCPORAM can reduce system overhead by 53%.
Zhanpeng Wang, Zhongkai Tong
TrustCom4
2018 Emotion Recognition Based on Photoplethysmogram and Electroencephalogram
abstract
In modern life, emotions affect people in all aspects of their work and life. Long-term emotional problems tend to cause physical and mental problems such as depression. The photoplethysmogram(PPG) and electroencephalogram (EEG) etc are often used for emotion recognition, because the emotional state produces reactions from different biological systems of the human body. This article uses an internationally released emotional classification database called DEAP dataset that contains 32-channel standard EEG signals and 8-channel peripheral physiological signals. To achieve wearable emotion continuous recognition, this paper strives to obtain satisfactory emotion recognition through fewer EEG channels and peripheral physiological signals. Machine learning methods are used to classify arousal and valence that are often used in emotional recognition. The results show that the arousal classification accuracy can achieve 68% and the valence classification accuracy can achieve 66% with 5 channel EEG signal and one channel PPG signal, which can be monitored through a wearable headband.
Zhongkai Tong, Xianxiang Chen, Zhengling He, Kai Tong, Zhen Fang 0003
COMPSAC (2)1