Zi-Han Cheng

dblp:228/2178 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
4since 2021 · last 2026
0000-0002-4079-8681ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021Computer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 HScanner: A Knowledge-Driven Framework for Early-Stage Detection of Hardware Vulnerabilities in IIoT Devices
abstract
Recurring hardware vulnerabilities, which refer to previously discovered vulnerabilities inadvertently reintroduced into new devices by designers, pose a significant challenge to the hardware security of Industrial Internet of Things (IIoT). To tackle this issue, we propose a framework called HScanner, which detects recurring hardware vulnerabilities during the design phase of IIoT devices. First, we abstract a hierarchical hardware feature set comprising 16 features (i.e., 6 coarse-grained features and 10 fine-grained features), which encapsulate crucial architectural information of the IIoT device. Next, we construct two knowledge graphs (KGs) by separately extracting hardware features from the design specifications of the target device and a well-known public hardware vulnerability database, namely National Vulnerability Database (NVD). After that, we propose a subgraph matching algorithm that identifies all subgraph mappings between the two KGs, where each mapping indicates a public hardware vulnerability involved in the device. Finally, we conduct experiments on 30 classical IIoT devices spanning four IIoT layers, including the perception, network, processing, and application layers. The results demonstrate the effectiveness of our HScanner. In detail, it finds out 40 recurring hardware vulnerabilities in 15 out of 30 devices. Among them, 34 vulnerabilities are successfully validated to be exploited to launch attacks. Compared to two state-of-the-art feature analysis methods, namely CYBOK and ICScope, as well as a manual analysis approach (MA), HScanner significantly reduces both the false alarm rate (FAR) and false negative rate (FNR). Specifically, HScanner reduces the FAR and FNR by 84.6% and 5.9% to CYBOK, 21.4% and 58.8% to ICScope, and 43.5% and 50% to MA, respectively.
Zhaorui Yang 0003, Jian Wang 0024, Zi-Han Cheng
IEEE Internet Things J.4
2026 InStorm: An Instruction-Level Vulnerability Testing Framework for Graphics Processing Units
abstract
In the last decade, an increasing number of processor vulnerabilities have been disclosed. However, existing methods have not tested the integrity and security of the GPU instruction set and microarchitecture. In this paper, we propose an instruction-level vulnerability testing frameworkInStormfor modern GPUs. Due to manufacturers' closed-source strategies, we reverse engineer the target ISA and generate efficient testing instructions by skipping redundant ones. Then, the generated instructions are executed on the target GPU to identify the potential vulnerabilities. Unfortunately, we discovered dozens of undocumented instructions with unexpected functions across six NVIDIA GPUs. Even worse, these instructions can bypass the GPU exception handling mechanism. In addition, we study a vulnerability exploitation method. An attacker can inject undocumented instructions into the victim GPU application by calling a malicious kernel loading function. Finally, we evaluate our exploitation method on a generative adversarial network accelerated by the NVIDIA GPU. The attack result demonstrates that instruction vulnerabilities can pose a significant security risk to GPU applications. We have responsibly disclosed these vulnerabilities and obtained an identifier CNVD-2025-10321.
Jian Wang 0024, Zi-Han Cheng
IEEE Trans. Dependable Secur. Comput.3
2025 Hardware Trojan Detection for Incomplete Gate-Level Reverse Netlist
abstract
Hardware Trojan (HT) has become an increasing security concern due to the outsourcing of integrated circuit (IC) development. By performing reverse engineering for ICs, researchers can obtain gate-level netlists to detect HTs. However, with the advancement of IC process technology, the netlists extracted by reverse engineering may be incomplete due to various factors, thus compromising the effectiveness of existing HT detection methods. In this paper, we propose a method to estimate the testability values of incomplete netlists and identify whether they are implanted with HTs. First, we develop a testability estimation method based on the Range Search Mean (RSM) algorithm, which aims to accurately reconstruct the testability values of incomplete netlists. Based on these estimated testability values, we then propose a density peaks-based detection algorithm to identify Trojan wires and find out the incomplete netlists containing HTs. The experimental results reveal the effectiveness of our method. Specifically, for the incomplete netlists generated based on Trust-hub benchmarks, the detection accuracy rate of our method exceeds 96% even when the proportion of missing information in the netlists reaches up to 1%. In addition, we demonstrate the advantages of our method over several existing HT detection methods and provide an in-depth discussion of our method.
Tongfei Yan, Jian Wang 0024, Zi-Han Cheng
IEEE Trans. Dependable Secur. Comput.3
2024 Low Complexity Time Reversal Imaging Methods Based on Truncated Time Reversal Operator
abstract
Due to the spatiotemporal focusing property of the time reversal (TR) technique, the TR operator (TRO)-based imaging method offers favorable positioning accuracy and fine distinguishability. However, the conventional singular value decomposition (SVD) for the full TRO involves significant computational complexity in large-scale arrays. To reduce the large computational complexity, this article proposes a truncated TRO (TTRO)-based imaging method that eliminates the need for SVD. In the approach, the TTRO is constructed by a block matrix from the TRO to reduce dimensionality, which reduces the complexity of decomposing the full TRO. Then, the quadrature rectangle decomposition (QRD) is employed to decompose the TTRO instead of the full TRO to acquire the signal subspace and noise subspace. Based on different subspaces, the TTRO-based imaging method can be classified into the decomposition of the TTRO (DORTT) using the signal subspace and the TTRO-multiple signal classification (TTRO-MUSIC) using the noise subspace. Numerical results demonstrate that the proposed TTRO-based method significantly decreases computational complexity and saves approximately 95% of the runtime consumption compared to the conventional TRO-based imaging method. Moreover, compared to the derived propagator method-multiple signal classification (PM-MUSIC) with the estimated noise subspace, TTRO-MUSIC also provides lower computational complexity and achieves better positioning accuracy.
Zi-Han Cheng, Meng-Lu Ma, Deshuang Zhao, Bing-Zhong Wang
IEEE Trans. Geosci. Remote. Sens.1