Yunqi He

dblp:329/6207 · DBLP profile ↗
← Back
13ranked-venue papers
3as first author
13since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 7 · 1 first-author · 7 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-author · 3 since 2021Security and privacy · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 LLA: Enhancing Security and Privacy for Generative Models with Logic-Locked Accelerators
abstract
We introduce LLA, an effective intellectual property (IP) protection scheme for generative AI models. LLA leverages the synergy between hardware and software to defend against various supply chain threats, including model theft, model corruption, and information leakage. On the software side, it embeds key bits into neurons that can trigger outliers to degrade performance and applies invariance transformations to obscure the key values. On the hardware side, it integrates a lightweight locking module into the AI accelerator while maintaining compatibility with various dataflow patterns and toolchains. An accelerator with a pre-stored secret key acts as a license to access the model services provided by the IP owner. The evaluation results show that LLA can withstand a broad range of oracle-guided key optimization attacks, while incurring a minimal computational overhead of less than 0.1% for 7,168 key bits.
You Li 0008, Guannan Zhao, Yuhao Ju, Yunqi He, Jie Gu 0001, Hai Zhou 0001
AAAI4
2026 Physical-Aware eFPGA Redaction for Secure and Efficient Hardware IP Protection
abstract
Embedded FPGA (eFPGA)-based hardware redaction has emerged as a promising technique for protecting the intellectual property (IP) of integrated circuits. Existing approaches select a subset of the logic at the register-transfer level (RTL) and replace it with a programmable eFPGA module. However, due to their lack of awareness of physical information, these approaches incur significant power, performance, and area (PPA) overhead on the resulting chip. This paper presents a physically guided partitioning approach that divides the original design into two parts: one implemented as an application-specific integrated circuit (ASIC) and the other redacted onto an embedded FPGA fabric. It leverages a graph neural network to encode both the structural and physical information of each gate into an embedding vector. It then employs a clustering and selection process to identify the redaction candidate. Experiments demonstrate that our approach consistently reduces timing overhead while achieving comparable or superior results in terms of area, security, and resource consumption.
Yunqi He, You Li 0008, Ruofan Huang, Guannan Zhao, Hai Zhou 0001
DATE1
2026 Graph Neural Network based Initialization for Timing Driven Placement
abstract
Timing-driven placement is very important to achieve timing closure especially as designs become increasingly complex. This article presents a novel Timing-Driven Placement (TDP) framework that integrates a graph convolutional network (GCN), Dirichlet boundary conditions, and a nonlinear placement engine to optimize placement quality with timing awareness throughout the flow. The proposed methodology begins by clustering components based on their interconnection topology, while Dirichlet boundary conditions are applied to handle fixed components such as IOs and macros. This yields a reduced graph with minimized inter-cluster connectivity, simplifying timing optimization. A GCN is then trained to learn a generalized and optimized mapping from circuit connectivity to physical wirelength. To improve early-stage timing estimation, virtual buffers are inserted prior to Static Timing Analysis (STA) to eliminate maximum capacitance violations. With this improved timing fidelity, STA provides pin-level slack, which is then used to dynamically adjust interconnection weights, guiding the placement of timing-critical components toward improved timing closure. Experimental results on ICCAD2015 contest benchmarks demonstrate that our algorithm can improve worse negative slack and total negative slack by 6% compared to the state-of-the-art method.
Ziyi Ju, Yunqi He, Hai Zhou 0001, Jia Wang 0003, Fan Yang 0001
ACM Trans. Design Autom. Electr. Syst.2
2025 RE3: Finding Refinement Relations with Relational Mapping Abstraction
abstract
A refinement relation captures the state equivalence between two sequential circuits. It finds applications in various tasks of VLSI design automation, including regression verification, behavioral model synthesis, assertion synthesis, and design space exploration. However, manually constructing a refinement relation requires an engineer to have both domain knowledge and expertise in formal methods, which is especially challenging for complex designs after significant transformations. This paper presents a rigorous and efficient sequential equivalence checking algorithm for non-cycle-accurate designs. The algorithm can automatically find a concise and human-comprehensible refinement relation between two designs, helping engineers understand the essence of design transformations. We demonstrate the usefulness and efficiency of the proposed algorithm with experiments and case studies. In particular, we showcase how refinement relations can facilitate error detection and correction for LLM-generated RTL designs.
You Li 0008, Guannan Zhao, Yunqi He, Hai Zhou 0001
DAC3
2025 DE2: SAT-Based Sequential Logic Decryption with a Functional Description
abstract
Logic locking is a promising approach to protect the intellectual properties of integrated circuits. Existing logic locking schemes assume that an adversary must possess a cycle-accurate oracle circuit to launch an I/O attack. This paper presents DE2, a novel and rigorous attacking algorithm based on a new adversarial model. DE2 only takes a high-level functional specification of the victim chip. Such specifications are increasingly prevalent in the modern IC design flow. DE2 closes the timing gap between the specification and the circuit with an automatic alignment mechanism, which enables effective logic decryption without cycle-accurate information. An essential enabler of DE2 is a synthesis-based sequential logic decryption algorithm called LIM, which introduces only a minimal overhead in every iteration. Experiments show that DE2 can efficiently attack logic-locked benchmarks without access to a cycle-accurate oracle circuit. Besides, LIM can solve 20% more ISCAS'89 benchmarks than state-of-the-art sequential logic decryption algorithms.
You Li 0008, Guannan Zhao, Yunqi He, Hai Zhou 0001
DATE3
2024 Multimodal Bayesian Networks for Automatic Skin Disease Diagnosis
abstract
Automatic diagnostic methods utilizing image analysis have seen a surge in development in recent years. However, achieving a comprehensive diagnosis necessitates considering clinical information. In the domain of skin disease, simply treating diagnosis as a multi-class image classification task poses inevitable bottlenecks. While existing methods incorporating Bayesian networks offer partial solutions, given the vast number of skin disease types, further integration with richer clinical information and diverse forms of deep neural networks would significantly escalate associated costs. This paper proposes an extensible diagnostic architecture. For newly added diseases and subsequently added clinical information, we integrate the output of deep neural networks into Bayesian networks more efficiently via semantic analysis. Through adjustments to node distribution types and the reduction of unnecessary connections, we expedite the development of a diagnostic system capable of addressing a wider range of skin diseases. Existing high-performing deep learning models, including multi-task and concept bottleneck, can be flexibly integrated into the system. Incorporating dermatologists’ expertise and reusing trained neural networks additionally reduces system development costs. At the same time, our architecture ensures excellent diagnostic accuracy. Through experiments leveraging the PAD-UFES-20 and SkinCon benchmarks, we have demonstrated that this architecture achieves a balanced diagnostic accuracy improvement of 19.3% over pure deep learning methods, with metrics including AUC surpassing those of existing published works. Our code can be accessed through the GitHub Repository: https://github.com/KevinInfinigon/MultimodalBayesianNetworks.
Yunqi He, Jiahe Liu, You Li 0008, Hai Zhou 0001, Linglong Cai, Taimei Cui
BIBM1
2024 Evaluating the Security of Logic Locking on Deep Neural Networks
abstract
Deep neural networks are susceptible to model piracy and adversarial attacks when malicious end-users have full access to the model parameters. Recently, a logic locking scheme called HPNN has been proposed. HPNN utilizes hardware root-of-trust to prevent end-users from accessing the model parameters. This paper investigates whether logic locking is secure on deep neural networks. Specifically, it presents a systematic I/O attack that combines algebraic and learning-based approaches. This attack incrementally extracts key values from the network to minimize sample complexity. Besides, it employs a rigorous procedure to ensure the correctness of the extracted key values. Our experiments demonstrate the accuracy and efficiency of this attack on large networks with complex architectures. Consequently, we conclude that HPNN-style logic locking and its variants we can foresee are insecure on deep neural networks.
You Li 0008, Guannan Zhao, Yunqi He, Hai Zhou 0001
DAC3
2024 Property Guided Secure Configuration Space Search
You Li 0008, Kaiyu Hou, Yunqi He, Yan Chen 0004, Hai Zhou 0001
ISC (2)3
2023 SE3: Sequential Equivalence Checking for Non-Cycle-Accurate Design Transformations †
abstract
In high-level design explorations, many useful optimizations transform a circuit into another with different operating cycles for a better trade-off between performance and resource usage. How to efficiently check their equivalence is critical and challenging since most existing equivalence checkers are designed for cycle-accurate circuits. This paper presents SE3, an efficient sequential equivalence checker without assumption on cycle-accuracy, latch mapping, or I/O interface of the checked circuits. It proves the equivalence of two circuits by computing an equivalence relation between the states of the two circuits and utilizes syntax abstraction to accelerate this process. Experimental results show that SE3 is significantly faster than state-of-the-art sequential equivalence checking algorithms.
You Li 0008, Guannan Zhao, Yunqi He, Hai Zhou 0001
DAC3
2023 ObfusLock: An Efficient Obfuscated Locking Framework for Circuit IP Protection†
abstract
With the rapid evolution of the IC supply chain, circuit IP protection has become a critical realistic issue for the semiconductor industry. One promising technique to resolve the issue is logic locking. It adds key inputs to the original circuit such that only authorized users can get the correct function, and it modifies the circuit to obfuscate it against structural analysis. However, there is a trilemma among locking, obfuscation, and efficiency within all existing logic locking methods that at most two of the objectives can be achieved. In this work, we propose ObfusLock, the first logic locking method that simultaneously achieves all three objectives: locking security, obfuscation safety, and locking efficiency. ObfusLock is based on solid mathematical proofs, incurs small overheads (<5% on average), and has passed experimental tests of various existing attacks.
You Li 0008, Guannan Zhao, Yunqi He, Hai Zhou 0001
DATE3
2023 Pose-guided adversarial video prediction for image-to-video person re-identification
abstract
Abstract The image‐to‐video (I2V) person re‐identification (Re‐ID) is a cross‐modality pedestrian retrieval task, whose crux is to reduce the large modality discrepancy between images and videos. To this end, this paper proposes to predict the following video frames from a single image. Thus, the I2V person Re‐ID can be transformed to video‐to‐video (V2V) Re‐ID. Considering that predicting video frames from a single image is an ill‐posed problem, this paper proposes two strategies to improve the quality of the predicted videos. First, a pose‐guided video prediction pipeline is proposed. The given single image and pedestrian pose are encoded via image encoder and pose encoder, respectively; then, the image feature and pose feature are concatenated as the input of the video decoder. The authors minimize the difference between the predicted video and true video, and simultaneously minimize the difference between the true pose and predicted pose. Second, the conditional adversarial training strategy is employed to generate high‐quality video frames. Specifically, the discriminator takes the source image as condition and distinguishes whether the input frames are fake or true following frames of the source image. Experimental results demonstrate that the pose‐guided adversarial video prediction can effectively improve accuracy of I2V Re‐ID.
Yunqi He, Liqiu Chen, Honghu Pan
IET Image Process.1
2023 Pose-Aided Video-Based Person Re-Identification via Recurrent Graph Convolutional Network
abstract
Existing methods for video-based person re- identification (ReID) mainly learn the appearance feature of a given pedestrian via a feature extractor and a feature aggregator. However, the appearance models would fail to learn a large inter-class variance when different pedestrians have similar appearances. Considering that different pedestrians have different walking postures and body proportions, we propose to learn the discriminative pose feature beyond the appearance feature for video retrieval. Specifically, we implement a two-branch architecture to separately learn the appearance feature and pose feature, and then concatenate them together for inference. To learn the pose feature, we first detect the pedestrian pose in each frame through an off-the-shelf pose detector, and construct a temporal graph using the pose sequence. We then exploit a recurrent graph convolutional network (RGCN) to learn the node embeddings of the temporal pose graph, which devises a global information propagation mechanism to simultaneously achieve the neighborhood aggregation of intra-frame nodes and message passing among inter-frame graphs. Finally, we propose a dual-attention method (DAM) consisting of node-attention and time-attention to obtain the temporal graph representation from the node embeddings, where the self-attention mechanism is employed to learn the importance of each node and each frame. We verify the proposed method on three video-based ReID datasets, i.e., Mars, DukeMTMC and iLIDS-VID, whose experimental results demonstrate that the learned pose feature can effectively improve the performance of existing appearance models.
Honghu Pan, Qiao Liu 0001, Yongyong Chen, Yunqi He, Yuan Zheng 0002, Feng Zheng 0001, Zhenyu He 0001
IEEE Trans. Circuits Syst. Video Technol.4
2023 Toward Complete-View and High-Level Pose-Based Gait Recognition
abstract
Model-based gait recognition methods usually adopt the pedestrian walking postures to identify human beings. However, existing methods did not explicitly resolve the large intra-class variance of human pose due to changes in camera view. In this paper, we propose a lower-upper generative adversarial network (LUGAN) to generate multi-view pose sequences for each single-view sample to reduce the cross-view variance. Based on the prior of camera imaging, we prove that the spatial coordinates between cross-view poses satisfy a linear transformation of a full-rank matrix. Hence, LUGAN employs the adversarial training to learn full-rank transformation matrices from the source pose and target views to obtain the target pose sequences. The generator of LUGAN is composed of graph convolutional (GCN) layers, fully connected (FC) layers and two-branch convolutional (CNN) layers: GCN layers and FC layers encode the source pose sequence and target view, then CNN layers take as input the encoded features to learn a lower triangular matrix and an upper one, finally the transformation matrix is formulated by multiplying the lower and upper triangular matrices. For the purpose of adversarial training, we develop a conditional discriminator that distinguishes whether the pose sequence is true or generated. Furthermore, to facilitate the high-level correlation learning, we propose a plug-and-play module, named multi-scale hypergraph convolution (HGC), to replace the spatial graph convolutional layer in baseline, which can simultaneously model the joint-level, part-level and body-level correlations. Extensive experiments on three large gait recognition datasets (i.e., CASIA-B, OUMVLP-Pose and NLPR) demonstrate that our method outperforms the baseline model by a large margin.
Honghu Pan, Yongyong Chen, Tingyang Xu, Yunqi He, Zhenyu He 0001
IEEE Trans. Inf. Forensics Secur.4