Yusi Feng

dblp:302/7885 · DBLP profile ↗
← Back
7ranked-venue papers
4as first author
7since 2021 · last 2026
0009-0003-0703-6479ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 3 first-author · 4 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 TimeGaps Channels: Exploiting CPU Halted Time for Fun and Profit
abstract
What do computers do when they do not compute? To answer this question, we investigate TimeGaps, periods during program execution, in which the timestamp counter progresses while the CPU is halted. We develop techniques for identifying TimeGaps and find that on Intel processors, TimeGaps amount to over 1% of the elapsed time. We further find that TimeGaps occurrence correlate with frequency transitions at either the CPU or at the Integrated Graphics Processing Unit (iGPU). We then turn our attention to the security impact of TimeGaps under two settings: default Dynamic Voltage and Frequency Scaling (DVFS) configuration, and fixed-frequency countermeasures. Under default DVFS settings, TimeGaps exhibit leakage capabilities comparable to state-of-the-art CPU-frequency-based side channels, i.e., Hertzbleed. Leveraging this, we infer website visits with an accuracy of 98.0% on Chrome and 85.2% on Tor, and extract cryptographic keys from Cloudflare's CIRCL library. Under fixed CPU frequency, where Hertzbleed is no longer effective, TimeGaps induced by iGPU frequency transitions continue to leak iGPU instruction and operand-level information. Moreover, TimeGaps re-enable three frequency-based sidechannel attacks previously believed to be mitigated by fixing CPU frequency, including pixel stealing with a high accuracy of 98.2%, robust website fingerprinting (92.2% on Chrome, 87.4% on Tor), and keystroke detection with a precision of over 84.6%.
Yusi Feng, Xin Zhang 0110, Sioli O'Connell, Liangwei Qiu, Chitchanok Chuengsatiansup, Daniel Genkin, Yuval Yarom, Yinqian Zhang, Zhi Zhang 0001
ISCA1
2026 MUXLeak: Exploiting Multiplexers as a Power Side Channel Against Multitenant FPGAs
abstract
FPGA cloud acceleration, or “FPGA as a Service” (FaaS), offered by AWS, Microsoft Azure, Alibaba Cloud, and Huawei Cloud, has become a promising solution for tackling complex, compute-intensive workloads. It targets applications such as genomics, image and video processing, electronic design automation, compression, and big data analytics. While multi-tenant FPGAs significantly enhances resource utilization efficiency, it faces security threats from power side channels, where attackers craft a malicious circuit to detect voltage fluctuations from victim circuits. Observing that all the crafted circuits exploit either Carry Chain or Look-up Table to sense voltage fluctuations, existing defenses have focused on detecting the malicious use of the two basic FPGA computing resources. However, it remains unclear whether such countermeasures are sufficient to address the growing threat of power side channels in multi-tenant FPGAs. In this paper, we reveal MUXLeak, a novel on-chip sensor that exploitsMultiplexer (MUX)to craft a stealthy power side channel, which bypasses existing countermeasures. Particularly, we perform a thorough analysis of basic resources within an FPGA unit and unveil thatMUX, another basic resource,has never been exploited before. More importantly, it can be directly initialized on Xilinx FPGAs and its incurred signal propagation delay demonstrates an inverse correlation with changes in voltage, making itself exploitable for a new power side channel leakage. In our evaluation, we test MUXLeak on three Xilinx FPGA products and use TDC [18] (i.e., the most sensitive on-chip sensor until now) to benchmark the sensitivity of MUXLeak. Our results show that MUXLeak has achieved the same level of sensitivity as TDC to voltage fluctuations. Further, we apply MUXLeak to mount two attacks, i.e., extracting AES keys within 2.54 hours and stealing DNN model architectures with an accuracy of over 90%.
Xin Zhang 0110, Zhi Zhang 0001, Qingni Shen, Yansong Gao 0001, Jinhua Cui 0002, Yusi Feng, Zhonghai Wu, Derek Abbott
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.7
2026 Fish and Chips: On the Root Causes of Co-Located Website-Fingerprinting Attacks
abstract
Microarchitectural website-fingerprinting attacks use timing information to leak the browsing habits of a victim to co-resident attackers. Microarchitectural leakage in these attacks often comprises multiple sources. While most published attacks claim to identify the cause of leakage, these claims are not always well supported. Thus, so far the question of how to determine what leaks remains mostly unanswered. In this work, we develop a framework for identifying and measuring the contribution of leakage sources to the overall observations the attacker makes. Experimenting with three website-fingerprinting attacks in the literature, we qualitatively identify four main classes of leakage sources: core contention, interrupts, frequency scaling, and cache eviction. We demonstrate cases where we can completely mitigate leakage by controlling these sources. We then show that enabling each of the sources individually leaks enough to allow website-fingerprinting attacks. In the quantitative analysis, we use the correlation between events related to each source and the measured timing in the attacks as a metric to determine the relative contribution of each source to the specific attack. Our work provides insights into the leakage sources of coarse-grained microarchitectural attacks, aiding the design of secure processor systems as well as more effective attacks and defenses.
Yusi Feng, Sioli O'Connell, Xin Zhang 0110, Chitchanok Chuengsatiansup, Daniel Genkin, Yuval Yarom, Yinqian Zhang, Zhi Zhang 0001
IEEE Trans. Dependable Secur. Comput.1
2026 Hypnos: A Practical Power Side-Channel Attack via CPU Idle Time
abstract
The growing demand for high-performance computing has led to various optimization techniques, but these advancements have also raised concerns about energy consumption. In response, processor vendors have implemented power management features. On x86-based CPUs, C-states allow the processor to enter idle states, reducing power consumption during low workloads. While users cannot directly control these states, C-states provide an interface to monitor CPU idle time, offering transparency without user intervention. However, it remains unclear whether this design could be exploited for power side-channel leakages. In this paper, we propose Hypno, a new type of software-based power side-channel attack on x86-based systems. Our key observation is that the unprivileged access to the CPUIDLE interface provides fine-grained observations of the time spent in various idle states. As this time is directly correlated with CPU activities, unprivileged attackers can leverage this information to establish a new power side channel. To demonstrate the viability of Hypnos, we conduct three end-to-end case studies. First, we demonstrate cross core covert channels that operate even in isolated environments, achieving higher transmission rates than channels that read cpufreq and broader applicability than methods that rely on uncore idle states. Second, we demonstrate a website fingerprinting attack on Google Chrome with high accuracy. Lastly, we successfully break KASLR within 3 minutes.
Yusi Feng, Xin Zhang 0110, Zihui Guo, Ben Liu 0007, Yinqian Zhang
IEEE Trans. Dependable Secur. Comput.1
2024 SoK: Can We Really Detect Cache Side-Channel Attacks by Monitoring Performance Counters?
abstract
Sharing microarchitectural components between co-resident programs leads to potential information leaks, with devastating implications on security. Over the last decade, multiple proposals suggested monitoring hardware performance counters as a method for detecting such attacks.
William Kosasih, Yusi Feng, Chitchanok Chuengsatiansup, Yuval Yarom
AsiaCCS2
2021 An Effective Approach for Malware Detection and Explanation via Deep Learning Analysis
abstract
The next generation attackers often generate malware variants with Artificial Intelligence (AI) weapons, which are deliberately designed to evade antivirus engines. Security defenders propose many AI-based approaches to detect the massive number of malware variants. However, most AI-based malware detection approaches only output a label to users, and these labels are mainly unexplainable. The lack of transparency has introduced many black-box attacks. Malware developers can develop adversarial examples to evade these AI-based malware detection systems. In this paper, we propose an effective approach for malware detection and explanation, which can locate malicious code snippets by explaining the malware classifier decision result. To this end, firstly, we get the system call number sequence of the target sample with instrumentation tools in an elaborated sandbox. Secondly, we feed the mapped system call number sequence into a deep learning model to make a decision on whether the target sample is benign or malicious. Thirdly, we adopt the Layer-wise Relevance Propagation algorithm to find which slice of a sequence makes the greatest contribution in the decision. Our evaluation demonstrates that our approach achieves high classification accuracy (97.39%), reduces the neural network size by 20 times, and saves the malware analyst time to locate malicious code snippets.
Huozhu Wang, Zhongkai Tong, Yusi Feng, Dan Meng 0002
IJCNN5
2021 Constant-Time Loading: Modifying CPU Pipeline to Defeat Cache Side-Channel Attacks
abstract
Cache side-channel attacks exploit cache state changes to steal confidential information. The emergence of transient execution attacks, a new form of microarchitecture side-channel attack that can access any address, makes cache side-channel attacks more threatening. Most of these attacks infer information by measuring the execution time of load operations. Therefore, from the microarchitecture perspective, we propose a novel countermeasure against cache side-channel attacks by eliminating the access time difference caused by cache hits or misses. We use the constant-time loading mechanism to limit each load instruction's execution to a fixed time and specify this mechanism's wake-up condition to avoid excessive performance loss. We modify the CPU pipeline to simulate this design and run SPEC2006 applications. The results show that the performance loss of our mechanism is negligible.
Yusi Feng, Shuan Li, Ben Liu 0007, Huozhu Wang, Dan Meng 0002
TrustCom1