VLDB 2026 Research / reviewers in the wild / expert
Yongqiang Lyu 0001
dblp:43/6243 · also Yong-Qiang Lv 0001, Yongqiang Lu 0001
· DBLP profile ↗
58ranked-venue papers
9as first author
26since 2021 · last 2026
0000-0003-2573-963XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 29 · 5 first-author · 16 since 2021Computer networks · 7 · 6 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 1 first-authorSecurity and privacy · 4 · 1 since 2021Software engineering, systems software and programming languages · 4 · 4 since 2021Human-computer interaction and ubiquitous computing · 3 · 2 first-authorArtificial intelligence and machine learning · 2 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 2Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Pitfall: Uncovering and Exploiting the Store Forwarding Predictor on Intel CPUs
Dapeng Ju, Yongqiang Lyu 0001, Dongsheng Wang 0002 |
APPT | 4 |
| 2026 | X-Matrix Shield: Defeating Tilted FIB and Rerouting Attacks through 3D-Interlaced ProtectionabstractAs focused ion beam (FIB) technology advances and invasive attack methods evolve, tilted FIB and rerouting attacks pose serious threats to chip security. Existing single-layer active shields exhibit inherent limitations in defending against these advanced invasive attacks. This paper presents the X-Matrix Shield, a dual-layer structure that fortifies integrated circuits against sophisticated physical tampering. This research establishes a novel information theory-based evaluation framework with quantifiable direction entropy metrics. Additionally, the work develops an improved artificial fish-swarm algorithm (DAFSA) to generate optimized 3D-interlaced protection paths. X-Matrix Shield can be directly integrated into the standard EDA layout flow, enabling security-aware physical design co-optimization. When implemented in 55 nm standard process technology, the X-Matrix Shield achieves a quality metric of $\mathbf{1. 9 9}$. GDS3D simulations of protected AES modules further confirm the shield’s effectiveness against advanced physical attacks compared to single-layer protection. Jiaji He 0001, Junfeng Cai, Mao Ye 0007, Yongqiang Lyu 0001 |
ASP-DAC | 6 |
| 2026 | SCPrompt: Semantic Compression and Prompt-Guided LLM Reasoning for RTL Trojan DetectionabstractThe increasing scale and complexity of integrated circuit (IC) designs present significant challenges to hardware security. Hardware Trojans (HTs)-stealthy, malicious alterations to hardware logic-are especially difficult to detect at the register-transfer level (RTL), where both structural and semantic understanding are essential. While recent advances have explored the use of large language models (LLMs) for RTL analysis, their performance is often constrained by token limits and a lack of targeted semantic abstraction. To overcome these limitations, we propose SCPrompt, a novel and extensible framework that, for the first time, integrates RTL instance-level compression with prompt-guided LLM reasoning for hardware Trojan detection. SCPrompt compresses RTL inputs by over 90%, significantly reducing prompt length while retaining critical control and data flow semantics. This enables LLMs to perform accurate Trojan analysis without taskspecific fine-tuning. Unlike prior binary classification approaches, SCPrompt supports instance-grained localization of suspicious logic components, identifying both trigger and payload modules within a design. Evaluated on 51 RTL designs with hardware Trojans inserted, our method achieves up to 100% precision, 90% recall, and an F1 score of 94.74%, demonstrating strong generalization across diverse circuits. These results validate SCPrompt as the first effective and scalable framework to unify RTL feature engineering with general-purpose language model reasoning for advanced hardware security analysis. Jiaji He 0001, Yongqiang Lyu 0001 |
ASP-DAC | 5 |
| 2026 | Knowledge is Power: A Knowledge Graph-Based Approach for Mobile Malware Traceability Analysis
Yao Zhang 0019, Guangquan Xu, Xiaohong Li 0001, Sen Chen 0001, Zhenchang Xing, Yude Bai, Yongqiang Lyu 0001, Wei Gong 0001, Xibin Zhao |
IEEE Trans. Mob. Comput. | 8 |
| 2026 | LIMR: Intent-Aware Mashup API Recommendation via LLM-Augmented Multi-Scale FusionabstractThe increasing availability of Web APIs has amplified the complexity of mashup creation, where developers must identify compatible and functionally relevant APIs based on often ambiguous natural language descriptions. Traditional methods also fall short in capturing hierarchical semantic cues, modeling compatibility, and aligning with developer intent. Although large language models (LLMs) offer strong generalization capabilities, they remain unreliable in mashup recommendation due to hallucinated outputs, limited controllability, and token-length constraints when dealing with large-scale API repositories. To overcome these limitations, we introduceLIMR, an intent-aware mashup recommendation framework that combines LLM-augmented semantic reasoning with structured, multi-scale neural modeling.LIMRfirst prompts a LLM to extract high-level intent from user requirements, which serves as a global semantic signal. This intent is fused with low-level, multi-scale features extracted by a convolutional encoder, which are designed to capture fine-grained lexical/phrasal patterns at different granularities and provide precise semantic grounding for API matching. These heterogeneous representations are further contextually refined through a Transformer-based interaction module. To handle nonlinear semantic dependencies and compositional complexity,LIMRintegrates a Kolmogorov-Arnold Network (KAN) with learnable activation functions, enhancing the model's capacity to capture intricate feature interactions. The entire framework is optimized via LLM, incorporating auxiliary objectives such as mashup category prediction and API quality estimation to guide generalization and reduce overfitting. Comprehensive experiments on the ProgrammableWeb and APIBench datasets show thatLIMRsignificantly outperforms state-of-the-art baselines, which the ranking-oriented metrics, including NDCG and mAP, achieves improvements of 17.1%–34.2% over the strongest competitors. These results confirm the effectiveness ofLIMR's hybrid design in delivering precise, robust, and intent-aware mashup API recommendations, especially in scenarios where LLMs alone fail to meet accuracy and scalability demands. Yao Zhang 0019, Yude Bai, Minhong Dong, Keqing Cen, Ji Zhang 0001, Wei Ma 0014, Yongqiang Lyu 0001, Xiaohong Li 0001, Junjie Wang 0007, Lingxiao Jiang, Yang Liu 0003 |
IEEE Trans. Serv. Comput. | 8 |
| 2026 | CodeS+: Towards Assessing the Generalization Ability of Code Models Under Distribution Shift
Ziyue Shi, Junjie Wang 0007, Yuejun Guo 0001, Xiaofei Xie, Maxime Cordy, Sen Chen 0001, Mike Papadakis, Yves Le Traon, Yongqiang Lyu 0001 |
IEEE Trans. Software Eng. | 10 |
| 2025 | MDPeek: Breaking Balanced Branches in SGX with Memory Disambiguation Unit Side ChannelsabstractIn recent years, control flow attacks targeting Intel SGX have attracted significant attention from the security community due to their potent capacity for information leakage. Although numerous software-based defenses have been developed to counter these attacks, many remain inadequate in fully addressing other, yet-to-be-discovered side channels. Chang Liu 0117, Shuaihu Feng, Yuan Li 0061, Dongsheng Wang 0002, Wenjian He, Yongqiang Lyu 0001, Trevor E. Carlson |
ASPLOS (2) | 6 |
| 2025 | BPUFuzzer: Effective Fuzz Testing for Branching Transient Execution Vulnerabilities of RISC-V CPUabstractThis paper presents BPUFuzzer, a fuzz testing tool for detecting branching transient execution vulnerabilities in CPU RTL design. BPUFuzzer addresses two key challenges: generating testcases that capture complex control flows, and extracting essential data from vast hardware states to guide testcase selection. Utilizing a control flow graph-based testcase generation strategy with anomaly detection and employing fitness and coverage metrics, BPUFuzzer works on testcases that cover broader program flows and deliberately selects testcases to discover transient execution vulnerabilities effectively. When applied on RISC-V Boom v3, BPUFuzzer uncovered more Spectre types than the state-of-the-arts, including a previously unidentified variant, named Spectre-LOOP. Rihui Sun, Hanyin Liu, Zikang Tao, Gang Qu 0001, Dongsheng Wang 0002, Yongqiang Lyu 0001, Jian Dong 0010 |
DAC | 7 |
| 2025 | Sonar: A Hardware Fuzzing Framework to Uncover Contention Side Channels in Processors
Kanqi Zhang, Peinan Li, Zelong Du, Quanchen Liu, Yongqiang Lyu 0001, Yu Jiang 0001, Dan Meng 0002, Rui Hou 0001 |
MICRO | 7 |
| 2025 | Continuous Authentication via Wrist Photoplethysmogram: An Extensive StudyabstractContinuous authentication (CA) based on wrist photoplethysmogram (PPG) has been increasingly studied, but still requires further extensive investigation on PPG reliability over time and heart rates for real-world deployments. In this paper, we first analyze the inadequacy of current research, i.e., limited generalization capability for new users and insufficient experiments due to the absence of across-session data under different heart rates (HR). To address these problems, we then propose a unified and scalable feature extraction framework for wrist PPG-based CA. Given a continuous PPG waveform, our framework first encodes the PPG of each period separately, then extracts variability features contained in consecutive multi-period PPG for user authentication. On two datasets with a total of 155 subjects, we evaluate the performances of our system using different across-session levels and HR intervals, respectively. Despite more stringent experimental settings, we achieve even better performances than in previous studies. Using the subject-exclusive cross-validation protocol, our system reaches an average accuracy of 92.1% under the constraint of equal error rates in across-session evaluation, and average accuracy ranges from 86.4% (high HR) to 91.4% (low HR) for different HR intervals. Jinxiao Wu, Xuanshu Luo, Yongqiang Lyu 0001, Xiangyang Ji, Dongsheng Wang 0002 |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | Whisper: Timing the Transient Execution to Leak Secrets and Break KASLRabstractThe vulnerabilities of transient execution have been exploited in many side-channel attacks (SCA). We report Whisper, a novel transient execution timing (TET) side channel, which is based on the execution time difference of transient execution under different conditions. We develop TET version of SCAs including Meltdown, Zombieload, and Spectre-RSB that use Whisper as covert channel to leak information. We further propose TET-KASLR to break the kernel address space layout randomization (KASLR) mechanism under the protection of KPTI and FLARE. These attacks are simple to implement and can bypass the existing mitigation methods because the TET side channel relies on execution time that can be conveniently obtained by architectural level timing analysis. We demonstrate the correctness and effectiveness of these attacks on various x86-64 CPUs. The root cause of Whisper is analyzed with our toolset built on performance monitor unit (PMU) and potential defense against Whisper is also discussed. Yu Jin 0010, Chunlu Wang, Pengfei Qiu, Chang Liu 0117, Hongpei Zheng, Yongqiang Lyu 0001, Xiaoyong Li 0003, Gang Qu 0001, Dongsheng Wang 0002 |
DAC | 7 |
| 2024 | Uncovering and Exploiting AMD Speculative Memory Access Predictors for Fun and ProfitabstractThis paper presents a comprehensive investigation into the security vulnerabilities associated with speculative memory access on AMD processors. Firstly, employing novel reverse engineering techniques, our study uncovers two key predictors, namely the Predictive Store Forwarding Predictor (PSFP) and the Speculative Store Bypass Predictor (SSBP), along with elucidating their internal structures and state machine designs. Secondly, our research empirically confirms that these predictors can be deliberately manipulated and altered during transient execution, resulting in secret leakage across security domains. Leveraging these discoveries, we propose innovative attacks targeting these predictors, including an out-of-place variant of Spectre-STL and an entirely new form of Spectre attack named Spectre-CTL. Finally, we establish experimentally that enabling Speculative Store Bypass Disable alleviates the vulnerabilities. However, this comes at the expense of significant performance degradation. Chang Liu 0117, Dongsheng Wang 0002, Yongqiang Lyu 0001, Pengfei Qiu, Yu Jin 0010, Zhuoyuan Lu, Yinqian Zhang, Gang Qu 0001 |
HPCA | 3 |
| 2024 | SCAFinder: Formal Verification of Cache Fine-Grained Features for Side Channel DetectionabstractRecent research has unveiled numerous cache-timing side-channel attacks exploiting the side effects of fine-grained cache features, such as coherence protocol and prefetch, among others. Traditional modeling methods and verification techniques are insufficient for verifying caches with fine-grained features and detecting cache timing vulnerabilities. There is a necessity for comprehensive verification of such complex cache designs. This paper presents SCAFinder, a verification framework targeting the cache designs with fine-grained features; it identifies cache side-channel attacks through model checking techniques. Specifically, it proposes a modeling methodology for cache designs that enables us to abstract the cache’s behavior and latency characteristics. We implement a search algorithm for finding all counterexamples based on open-source model checking software. Subsequently, we add an attack scenario analysis module to discover attacks applicable to specific scenarios. We evaluate SCAFinder on Intel Skylake-X microarchitecture, demonstrating its capability to generate 7 new attack sequences exploiting coherence protocol and prefetch, and 12 new replacement policy-based side channels. As a case study, we successfully built a covert channel for one of the sequences on the real-world processor. To the best of our knowledge, we are the first to implement cross-core replacement policy-based attacks on non-inclusive caches. Haixia Wang 0001, Pengfei Qiu, Yongqiang Lyu 0001, Hongpeng Wang 0002, Dongsheng Wang 0002 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Touchscreens Can Reveal User Identity: Capacitive Plethysmogram-Based BiometricsabstractBiometrics are widely used for user identification/authentication, but the fact has rarely been noticed that general capacitive touchscreens can reveal user identities by touch signals. This paper proposes a new biometric method with inherent liveness detection for reliable user recognition based on the cardiac signal captured by the capacitive touchscreen, namely Capacitive Plethysmogram (CPG). And a systematic framework is designed for CPG collection, processing, and exploitation to identify users. Specifically, since the finger usually forms capacitors with multiple sensing electrodes during touching, we can extract several CPG signals simultaneously from the screen output. Then we propose a series of preprocessing algorithms to filter CPG for signal quality enhancement. Finally, to further leverage filtered CPG signals and extract efficient features for identifying users, we build an encoder based on 3D attention CNN and metric learning. Experimental results demonstrate that the proposed method can achieve an average accuracy of 96.73%, FAR of 3.03%, and FRR of 7.35% in the laboratory environment, which reveals the potential of CPG for user privacy protection and data security on various devices laced with capacitive touchscreens. Jinxiao Wu, Xiangyang Ji, Yongqiang Lyu 0001, Xuanshu Luo, Eric Morales, Dongsheng Wang 0002, Xiaomin Luo |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | Lightning: Leveraging DVFS-induced Transient Fault Injection to Attack Deep Learning Accelerator of GPUsabstractGraphics Processing Units (GPU) are widely used as deep learning accelerators because of its high performance and low power consumption. Additionally, it remains secure against hardware-induced transient fault injection attacks, a classic type of attacks that have been developed on other computing platforms. In this work, we demonstrate that well-trained machine learning models are robust against hardware fault injection attacks when the faults are generated randomly. However, we discover that these models have components, which we refer to as sensitive targets, that are vulnerable to faults. By exploiting this vulnerability, we propose the Lightning attack, which precisely strikes the model’s sensitive targets with hardware-induced transient faults based on the Dynamic Voltage and Frequency Scaling (DVFS). We design a sensitive targets search algorithm to find the most critical processing units of Deep Neural Network (DNN) models determining the inference results, and develop a genetic algorithm to automatically optimize the attack parameters for DVFS to induce faults. Experiments on three commodity Nvidia GPUs for four widely-used DNN models show that the proposed Lightning attack can reduce the inference accuracy by 69.1% on average for non-targeted attacks, and, more interestingly, achieve a success rate of 67.9% for targeted attacks. Rihui Sun, Pengfei Qiu, Yongqiang Lyu 0001, Jian Dong 0010, Haixia Wang 0001, Dongsheng Wang 0002, Gang Qu 0001 |
ACM Trans. Design Autom. Electr. Syst. | 3 |
| 2023 | PMU-Leaker: Performance Monitor Unit-Based Realization of Cache Side-Channel AttacksabstractPerformance Monitor Unit (PMU) is a special hardware module in processors that contains a set of counters to record various architectural and micro-architectural events. In this paper, we propose PMU-Leaker, a novel realization of all existing cache side-channel attacks where accurate execution time measurements are replaced by information leaked through PMU. The efficacy of PMU-Leaker is demonstrated by (1) leaking the secret data stored in Intel Software Guard Extensions (SGX) with the transient execution vulnerabilities including Spectre and ZombieLoad and (2) extracting the encryption key of a victim AES performed in SGX. We perform thorough experiments on a DELL Inspiron 15-7560 laptop that has an Intel® Core™ i5-7200U processor with the Kaby Lake architecture and the results show that, among the 176 PMU counters, 24 of them are vulnerable and can be used to launch the PMU-Leaker attack. Pengfei Qiu, Dongsheng Wang 0002, Yongqiang Lyu 0001, Chunlu Wang, Chang Liu 0117, Rihui Sun, Gang Qu 0001 |
ASP-DAC | 4 |
| 2023 | Leaky MDU: ARM Memory Disambiguation Unit Uncovered and Vulnerabilities ExposedabstractMemory Disambiguation Unit (MDU) is widely used on modern processors to speculatively execute load instructions and improve pipeline performance. Given that the MDU design details on ARM processors are not available to the public, it is unclear whether there are any security vulnerabilities associated with its MDU. In this paper, we first reverse engineer the undocumented features of ARM MDU, then we discover three potential user-privilege attacks to leak secret data via MDU: cross-process attack that allows users to communicate through a convert channel, cross-domain attack that leaks kernel information and a new variant of inner-process and inter-processes Spectre attacks. These attacks pose serious security challenges as they can bypass both all the known countermeasures against cache side-channel attacks and those against transient execution attacks. Potential mitigation against the proposed MDU-based attacks are also discussed. Chang Liu 0117, Yongqiang Lyu 0001, Haixia Wang 0001, Pengfei Qiu, Dapeng Ju, Gang Qu 0001, Dongsheng Wang 0002 |
DAC | 2 |
| 2023 | Processor Vulnerability DiscoveryabstractProcessor security vulnerability discovery has drawn increasing attention since the disclosure of Meltdown, Spectre and other vulnerabilities. This paper presents a concise roadmap of this emerging research direction from the simple manual discovery to automated discovery methodologies, as well as the major challenges along the roadmap. Yongqiang Lyu 0001, Rihui Sun, Gang Qu 0001 |
DAC | 1 |
| 2023 | PMU-Spill: A New Side Channel for Transient Execution AttacksabstractPerformance Monitor Unit (PMU) is an important hardware module in mainstream processors, which counts various architectural and microarchitectural events during the run-time of the processor. Theoretically, if an instruction is executed but doesn’t successfully retire (this is called transient execution), the events it triggers needn’t be recorded by PMU. However, in this study, we discover that current PMU implementations are capable of recording some events that are triggered in transient executions, which is a hardware vulnerability. Based on this vulnerability, we propose the PMU-Spill attack, a new kind of side channel attack that enables attackers to maliciously leak secret data in transient executions. We perform a thorough study of PMU counters on five Intel processors and find that they all have vulnerable PMU counters that will measure transient execution events (there are 162 vulnerable PMU counters among all the 383 PMU counters). We demonstrate on real hardware that 112 vulnerable PMU counters can be utilized in PMU-Spill attack to leak the secret data protected by Intel Software Guard Extensions (SGX). Besides, our experiments suggest that the throughput of PMU-Spill attack is up to 291.2 bytes per second (Bps) with an error rate of 2.45% on average. This discovery and the corresponding mitigation methods can be helpful for microarchitecture designers to reevaluate the security risks induced by the PMU module. Pengfei Qiu, Chang Liu 0117, Dongsheng Wang 0002, Yongqiang Lyu 0001, Xiaoyong Li 0003, Chunlu Wang, Gang Qu 0001 |
IEEE Trans. Circuits Syst. I Regul. Pap. | 5 |
| 2023 | OA-Cache: Oracle Approximation-Based Cache Replacement at the Network EdgeabstractWith the explosive increase in mobile data traffic and stringent quality-of-experience requirements of users, mobile edge caching is a promising paradigm to reduce delivery latency and network congestions by serving content requests locally. However, it is extremely challenging to conduct cache replacement when the cache is full and the future request pattern is unknown subject to enormous content volume but limited cache capacity at the network edge. In this paper, we propose a cache replacement algorithm based on the oracle approximation named OA-Cache in an end-to-end manner to maximize the cache hit rate. Specifically, we construct a complex model that uses a temporal convolutional network to capture the long and short dependencies between content requests. Then, an attention mechanism is adopted to find out the correlations between the requests in the sliding window and cached contents. Instead of training a policy to mimic Belady that evicts the content with the longest reuse distance, we cast the learning task into a classification model to distinguish unpopular contents from popular ones. Finally, we apply the knowledge distillation approach to assist in transferring knowledge from a large pre-trained complex network to a lightweight network to readily accommodate to the network edge scenario. To validate the effectiveness of OA-Cache, we conduct extensive experiments on real-world datasets. The evaluation results demonstrate that OA-Cache can achieve the superior performance compared to candidate algorithms. Shuting Qiu, Qilin Fan, Xiuhua Li 0001, Xu Zhang 0006, Geyong Min, Yongqiang Lyu 0001 |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2022 | DVFSspy: Using Dynamic Voltage and Frequency Scaling as a Covert Channel for Multiple ProceduresabstractDynamic Voltage and Frequency Scaling (DVFS) is a widely deployed low-power technology in modern systems. In this paper, we discover a vulnerability in the implementation of the DVFS technology that allows us to measure the processor's frequency in the userspace. By exploiting this vulnerability, we successfully implement a covert channel on the commercial Intel platform and demonstrate that the covert channel can reach a throughput of 28.41bps with an error rate of 0.53%. This work indicates that the processor's hardware information that is unintentionally leaked to the userspace by the privileged kernel modules may cause security risks. Pengfei Qiu, Dongsheng Wang 0002, Yongqiang Lyu 0001, Gang Qu 0001 |
ASP-DAC | 3 |
| 2022 | CacheGuard: A Behavior Model Checker for Cache Timing Side-Channel Security: (Invited Paper)abstractDefending cache timing side-channels has become a major concern in modern secure processor designs. However, a formal method that can completely check if a given cache design can defend against timing side-channel attacks is still absent. This study presents CacheGuard, a behavior model checker for cache timing side-channel security. Compared to current state-of-the-art prose rule-based security analysis methods, CacheGuard covers the whole state space for a given cache design to discover unknown side-channel attacks. Checking results on standard cache and state-of-the-art secure cache designs discovers 5 new attack strategies, and potentially makes it possible to develop a timing side channel-safe cache with the aid of CacheGuard. Lingfeng Yin, Yongqiang Lyu 0001, Haixia Wang 0001, Gang Qu 0001, Dongsheng Wang 0002 |
ASP-DAC | 3 |
| 2022 | DynaComm: Accelerating Distributed CNN Training Between Edges and Clouds Through Dynamic Communication SchedulingabstractTo reduce uploading bandwidth and address privacy concerns, deep learning at the network edge has been an emerging topic. Typically, edge devices collaboratively train a shared model using real-time generated data through the Parameter Server framework. Although all the edge devices can share the computing workloads, the distributed training processes over edge networks are still time-consuming due to the parameters and gradients transmission procedures between parameter servers and edge devices. Focusing on accelerating distributed Convolutional Neural Networks (CNNs) training at the network edge, we present DynaComm, a novel scheduler that dynamically decomposes each transmission procedure into several segments to achieve optimal layer-wise communications and computations overlapping during run-time. Through experiments, we verify that DynaComm manages to achieve optimal layer-wise scheduling for all cases compared to competing strategies while the model accuracy remains untouched. Shangming Cai, Dongsheng Wang 0002, Haixia Wang 0001, Yongqiang Lyu 0001, Guangquan Xu, James Xi Zheng, Athanasios V. Vasilakos |
IEEE J. Sel. Areas Commun. | 4 |
| 2022 | JOSP: Joint Optimization of Flow Path Scheduling and Virtual Network Function Placement for Delay-Sensitive Applications
Qing Lyu 0005, Yonghang Zhou, Qilin Fan, Yongqiang Lyu 0001, James Xi Zheng, Guangquan Xu |
Mob. Networks Appl. | 4 |
| 2021 | VoltJockey: A New Dynamic Voltage Scaling-Based Fault Injection Attack on Intel SGXabstractIntel software guard extensions (SGX) increase the security of applications by enabling them to be performed in a highly trusted space (called enclave). Most state-of-the-art attacks on SGX focus on either mining the software vulnerabilities in the enclave or speculating the secret data with side channels. In this study, we report our recent work on breaking SGX by inducing voltage-oriented hardware faults. The novelty and importance of this attack are that it is completely controlled by software and does not require any security vulnerability in the software. Our proposed attack, called VoltJockey, exploits a vulnerability in the implementation of dynamic voltage and frequency scaling (DVFS) that achieves energy saving by dynamically adjusting the processor's operating voltage and thus clock frequency. However, if the operating voltage is lower than a certain critical level, the circuit's timing constraint will fail and hardware fault would be created. We propose to deliberately trigger such voltage-oriented hardware faults by a loadable kernel module that can set the processor's voltage through Intel's undocumented model-specific register (MSR). We first utilize the module to furnish the processor with a transient low voltage with controlled timing to inject a temporal fault into the target location of the program running in the enclave. Then, we perform a differential fault attack on the outputs before and after the injection of faults. For demonstration, we successfully deploy the proposed attack to extract the key of an AES executed in the enclave and lead an SGX-protected RSA to output our specified result. Pengfei Qiu, Dongsheng Wang 0002, Yongqiang Lyu 0001, Ruidong Tian, Chunlu Wang, Gang Qu 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2021 | Towards Optimal Request Mapping and Response Routing for Content Delivery NetworksabstractThe decision of request mapping-which server to handle user request and response routing-which transit route to carry response back to user has great impact on the performance and cost of Content Delivery Networks (CDNs). Request mapping and response routing are traditionally treated independently. The information invisibility and inconsistent objectives may lead to worse performance and high cost. However, the rapid globalization of Internet eXchange Points (IXPs) has facilitated the cooperation between CDN and ISP. In this paper, we consider request mapping and response routing jointly. We formulate the joint problem to navigate the performance and cost tradeoff. To solve the large-scale optimization, we develop a distributed tide algorithm based on Gauss-Seidel. The joint problem can be decomposed to sub-problems which allows for a parallel implementation. Experiment result shows that the relative error between our distributed tide algorithm that iterates within 50 rounds and theoretical optimum is about 0.7 percent. Furthermore, the parallel runtime demonstrates the efficiency of our algorithm. Qilin Fan, Libo Jiao, Yongqiang Lyu 0001, Haojun Huang, Xu Zhang 0006 |
IEEE Trans. Serv. Comput. | 4 |
| 2020 | Mitigating Adversarial Attacks for Deep Neural Networks by Input Deformation and AugmentationabstractTypical Deep Neural Networks (DNN) are susceptible to adversarial attacks that add malicious perturbations to input to mislead the DNN model. Most of the state-of-theart countermeasures concentrate on the defensive distillation or parameter re-training, which require prior knowledge of the target DNN and/or the attacking methods and hence greatly limit their generality and usability. In this paper, we propose to defend against adversarial attacks by utilizing the input deformation and augmentation techniques that are currently widely utilized to enlarge the dataset during DNN's training phase. This is based on the observation that certain input deformation and augmentation methods will have little or no impact on DNN model's accuracy, but the adversarial attacks will fail when the maliciously induced perturbations are randomly deformed. We also use the ensemble of decisions to further improve DNN model's accuracy and the effectiveness of defending various attacks. Our proposed mitigation method is model independent (i.e. it does not require additional training, parameter finetuning, or any structure modifications of the target DNN model) and attack independent (i.e., it does not require any knowledge of the adversarial attacks). So it has excellent generality and usability. We conduct experiments on standard CIFAR-10 dataset and three representative adversarial attacks: Fast Gradient Sign Method, Carlini and Wagner, and Jacobian-based Saliency Map Attack. Results show that the average success rate of the attacks can be reduced from 96.5% to 28.7% while the DNN model accuracy is improved by about 2%. Pengfei Qiu, Qian Wang 0022, Dongsheng Wang 0002, Yongqiang Lyu 0001, Zhaojun Lu, Gang Qu 0001 |
ASP-DAC | 4 |
| 2019 | VoltJockey: Breaching TrustZone by Software-Controlled Voltage Manipulation over Multi-core FrequenciesabstractARM TrustZone builds a trusted execution environment based on the concept of hardware separation. It has been quite successful in defending against various software attacks and forcing attackers to explore vulnerabilities in interface designs and side channels. The recently reported CLKscrew attack breaks TrustZone through software by overclocking CPU to generate hardware faults. However, overclocking makes the processor run at a very high frequency, which is relatively easy to detect and prevent, for example by hardware frequency locking. In this paper, we propose an innovative software-controlled hardware fault-based attack, VoltJockey, on multi-core processors that adopt dynamic voltage and frequency scaling (DVFS) techniques for energy efficiency. Unlike CLKscrew, we manipulate the voltages rather than the frequencies via DVFS unit to generate hardware faults on the victim cores, which makes VoltJockey stealthier and harder to prevent than CLKscrew. We deliberately control the fault generation to facilitate differential fault analysis to break TrustZone. The entire attack process is based on software without any involvement of hardware. We implement VoltJockey on an ARM-based Krait processor from a commodity Android phone and demonstrate how to reveal the AES key from TrustZone and how to breach the RSA-based TrustZone authentication. These results suggest that VoltJockey has a comparable efficiency to side channels in obtaining TrustZone-guarded credentials, as well as the potential of bypassing the RSA-based verification to load untrusted applications into TrustZone. We also discuss both hardware-based and software-based countermeasures and their limitations. Pengfei Qiu, Dongsheng Wang 0002, Yongqiang Lyu 0001, Gang Qu 0001 |
CCS | 3 |
| 2019 | Photoplethysmogram-based Cognitive Load Assessment Using Multi-Feature Fusion ModelabstractCognitive load assessment is crucial for user studies and human--computer interaction designs. As a noninvasive and easy-to-use category of measures, current photoplethysmogram- (PPG) based assessment methods rely on single or small-scale predefined features to recognize responses induced by people’s cognitive load, which are not stable in assessment accuracy. In this study, we propose a machine-learning method by using 46 kinds of PPG features together to improve the measurement accuracy for cognitive load. We test the method on 16 participants through the classical n-back tasks (0-back, 1-back, and 2-back). The accuracy of the machine-learning method in differentiating different levels of cognitive loads induced by task difficulties can reach 100% in 0-back vs. 2-back tasks, which outperformed the traditional HRV-based and single-PPG-feature-based methods by 12--55%. When using “leave-one-participant-out” subject-independent cross validation, 87.5% binary classification accuracy was reached, which is at the state-of-the-art level. The proposed method can also support real-time cognitive load assessment by beat-to-beat classifications with better performance than the traditional single-feature-based real-time evaluation method. Xiao Zhang 0008, Yongqiang Lyu 0001, Tong Qu, Pengfei Qiu, Xiaomin Luo, Shunjie Fan, Yuanchun Shi |
ACM Trans. Appl. Percept. | 2 |
| 2019 | Constructing Novel Block Layouts for Webpage AnalysisabstractWebpage segmentation is the basic building block for a wide range of webpage analysis methods. The rapid development of Web technologies results in more dynamic and complex webpages, which bring new challenges to this area. To improve the performance of webpage segmentation, we propose a two-stage segmentation method that can combine visual, logic, and semantic features of the contents on a webpage. Specifically, we devise a new model to measure the similarities of the elements on webpages based on both visual layout and logic organization in the first stage, and we propose a novel block regrouping method using semantic statistics and visual positions in the second stage. This two-stage method can effectively conduct webpage segmentation on complicated and dynamic webpages. The performance and accuracy of the method are verified by comparing with two existing webpage segmentation methods. The experiment results show that the proposed method significantly outperforms the existing state of the art in terms of higher precision, recall, and accuracy. Zexun Jiang, Yulei Wu, Yongqiang Lyu 0001, Geyong Min, Xu Zhang 0006 |
ACM Trans. Internet Techn. | 4 |
| 2018 | SNrram: an efficient sparse neural network computation architecture based on resistive random-access memoryabstractThe sparsity in the deep neural networks can be leveraged by methods such as pruning and compression to help the efficient deployment of large-scale deep neural networks onto hardware platforms, such as GPU or FPGA, for better performance and power efficiency. However, for RRAM crossbar-based architectures, the study of efficient methods to consider the network sparsity is still in the early stage. In this study, we propose SNrram, an efficient sparse neural network computation architecture using RRAM, by exploiting the sparsity in both weights and activation. SNrram stores nontrivial weights and organizes them to eliminate zero-value multiplications for better resource utilization. Experimental results show that SNrram can save RRAM resources by 69.8%, reduce the power consumption by 35.9%, and speed up by 2.49× on popular deep learning benchmarks, compared to a state-of-the-art RRAM-based neural network accelerator. Peiqi Wang 0001, Yu Ji 0002, Chi Hong, Yongqiang Lyu 0001, Dongsheng Wang 0002, Yuan Xie 0001 |
DAC | 4 |
| 2018 | InterestFence: Countering Interest Flooding Attacks by Using Hash-Based Security Labels
Jiaqing Dong, Kai Wang 0014, Yongqiang Lyu 0001, Libo Jiao |
ICA3PP (4) | 3 |
| 2018 | Optimal Schedule of Mobile Edge Computing Under Imperfect CSI
Libo Jiao, Yongqiang Lyu 0001, Haojun Huang, Jiaqing Dong, Dongchao Guo |
ICA3PP (2) | 3 |
| 2018 | Evaluating Photoplethysmogram as a Real-Time Cognitive Load Assessment during Game PlayingabstractAccurate evaluation for user experience during computer game playing is very important in optimizing game design to improve the gaming experience. When evaluating user experiences, the concept of cognitive load is crucial for dynamically responding to game players’ mental status. In our former studies, the photoplethysmogram (PPG)-based Stress-Induced Vascular Response Index (sVRI) shows better sensitivity and reliability in measuring cognitive loads compared with heart-rate variation, blood pressure, and galvanic skin response. In this study, we use memory matrixes and Pop Cap’s tower defense game Plants vs. Zombies as cognitive tasks and use sVRI to assess players’ cognitive load dynamically during the real-time computer games. Evaluations on cognitive tasks verified the usability of sVRI in comparison with other indexes derived from PPG, such as heartbeat interval, area under curve, digital pulse amplitude, reflection index, and inflection point area ratio. Our findings indicate the potential of sVRI for assessing game players’ mental workload in real time. Xiao Zhang 0008, Yongqiang Lyu 0001, Ziyue Hu, Yuanchun Shi |
Int. J. Hum. Comput. Interact. | 2 |
| 2018 | A Dataflow-Oriented Programming Interface for Named Data Networking
Lijing Wang 0004, Yongqiang Lyu 0001, Ilya Moiseenko, Dongsheng Wang 0002 |
J. Comput. Sci. Technol. | 2 |
| 2018 | Non-Invasive Measurement of Cognitive Load and Stress Based on the Reflected Stress-Induced Vascular Response IndexabstractMeasuring cognitive load and stress is crucial for ubiquitous human--computer interaction applications to dynamically understand and respond to the mental status of users, such as in smart healthcare, smart driving, and robotics. Various quantitative methods have been employed for this purpose, such as physiological and behavioral methods. However, the sensitivity, reliability, and usability are not satisfactory in many of the current methods, so they are not ideal for ubiquitous applications. In this study, we employed a reflected photoplethysmogram-based stress-induced vascular response index, i.e., the reflected sVRI (sVRI-r), to non-invasively measure the cognitive load and stress. This method has high usability as well as good sensitivity and reliability compared with the previously proposed transmitted sVRI (sVRI-t). We developed the basic methodology and detailed algorithm framework to validate the sVRI-r measurements, and it was implemented by employing two light sources, i.e., infrared light and green light. Compared with the simultaneously recorded blood pressure, heart rate variation, and sVRI-t, our findings demonstrated the greater potential of the sVRI-r for use as a sensitive, reliable, and usable parameter, as well as suggesting its potential integration with ubiquitous touch interactions for dynamic cognition and stress-sensing scenarios. Yongqiang Lyu 0001, Xiao Zhang 0008, Xiaomin Luo, Ziyue Hu, Yuanchun Shi |
ACM Trans. Appl. Percept. | 1 |
| 2018 | Control Flow Integrity Based on Lightweight Encryption ArchitectureabstractControl-flow integrity (CFI) plays a very important role in defending against code reuse attacks by protecting the control flows of programs from being hijacked. However, previous CFI methods suffer from performance overheads, cost, or security issues. In this paper, we propose a new CFI based on a lightweight encryption architecture with advanced encryption standard (LEA-AES) to address the challenges above. The LEA exploits AES to encrypt and decrypt return addresses and instructions at indirect jump destinations, which protects function calls and indirect jumps from being reused by return-oriented programming (ROP) and jump-oriented programming (JOP) attacks. For ROP, the encryption and decryption of return addresses are performed when the call and ret instructions are executing; for JOP, the encryption of instructions are performed when programs are loading into memory and the decryption of instructions are performed right before they are executing. The LEA-AES does not need to revise instruction sets of CPU and its security is also guaranteed by the encryption mechanism in addition to its high performance. Experimental results showed that the run-time and loading time overheads of LEA-AES are both less than 4% and the memory overhead is 0.62%. Pengfei Qiu, Yongqiang Lyu 0001, Jiliang Zhang 0002, Dongsheng Wang 0002, Gang Qu 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2017 | UMCR: User Interaction-Driven Mobile Content RetrievalabstractAlthough mobile application ecosystems have experienced tremendous growth in recent years, retrieving content of mobile applications that serves a key to mobile content search engines still faces grand challenges. Compared to web content retrieval, it is much more difficult to capture content in mobile applications due to the diversity of applications and the lack of Uniform Resource Locator indices. In this study, we propose and implement a user interaction-driven mobile content retrieval (UMCR) system to address such issues, which is the first mobile content crawler in the current literature. UMCR is a distributed system that contains many measurement nodes, each of which combines the user interaction path traversing (UIPT) and Deep Package Inspection (DPI) together to obtain mobile content. UIPT determines the events of user interactions in various applications to capture the static content such as text and images, in which a traversal depth termination scheme and an optional cut-off component are adopted to balance the content coverage and traversing efficiency. Meanwhile, the analysis based on DPI is responsible for extracting the videos as well as digging the infrastructural information and performance metrics. In addition, a distributed traversal scheduling method is designed for UIPT tasks to improve the throughput and scalability in large-scale content retrieval. Experiments on retrieving content of 64 real mobile applications demonstrate that UMCR can handle diverse mobile applications efficiently. The scheduler can improve throughput by 3 times compared to the legacy arbitrary task assignment strategy. Wei Wang 0173, Xu Zhang 0006, Yongqiang Lyu 0001, Geyong Min, Dongchao Guo |
ACM Trans. Intell. Syst. Technol. | 4 |
| 2016 | Physical unclonable functions-based linear encryption against code reuse attacksabstractRecently, code reuse attacks (CRAs) have emerged as a new class of ingenious security threatens. Attackers can utilize CRAs to hijack the control flow of programs to perform malicious actions without injecting any codes. Existing defenses against CRAs often incur high memory and performance overheads or require extending the existing processors' instruction set architectures (ISAs). To tackle these issues, we propose a hardware-based control flow integrity (CFI) that employs physical unclonable functions (PUF)-based linear encryption architecture (LEA) to protect against CRAs with negligible hardware extending and run time overheads. The proposed method can protect ret and indirect jmp instructions from return oriented programming (ROP) and jump oriented programming (JOP) without any additional software manipulations and extending ISAs. The pre-process will be conducted on codes once the executable binary is loaded into memory, and the real-time control flow verification based on LEA can be done while ret and jmp instructions are executed. Performance evaluations on benchmarks show that the proposed method only introduces 0.61% run-time overhead and 0.63% memory overhead on average. Pengfei Qiu, Yongqiang Lyu 0001, Jiliang Zhang 0002, Xingwei Wang 0001, Di Zhai, Dongsheng Wang 0002, Gang Qu 0001 |
DAC | 2 |
| 2016 | Techniques for Design and Implementation of an FPGA-Specific Physical Unclonable Function
Jiliang Zhang 0002, Qiang Wu 0015, Yipeng Ding, Yongqiang Lyu 0001, Qiang Zhou 0001, Zhihua Xia, Xingming Sun, Xingwei Wang 0001 |
J. Comput. Sci. Technol. | 4 |
| 2015 | A Survey of Hardware Trojan Detection, Diagnosis and PreventionabstractHardware Trojans (HTs) can be implanted in security-weak parts of a chip with various means to steal the internal sensitive data or modify original functionality, which may lead to huge economic losses and great harm to society. Therefore, it is very important to perform hardware Trojan detection and diagnosis, find potential safety hazards and apply protection techniques in the whole IC design cycle, in order to enhance the security of chips. In this paper, we elaborate an IC market model, and describe the potential HT threats faced by the parties involved in the model. Then we survey the recent research advances in the countermeasures against HT attacks, which are classified into HT detection, diagnosis and prevention. Finally, the challenges and prospects for HT defense are illuminated. He Li 0008, Qiang Liu 0011, Jiliang Zhang 0002, Yongqiang Lyu 0001 |
CAD/Graphics | 4 |
| 2015 | Measuring Photoplethysmogram-Based Stress-Induced Vascular Response Index to Assess Cognitive Load and StressabstractQuantitative assessment for cognitive load and mental stress is very important in optimizing human-computer system designs to improve performance and efficiency. Traditional physiological measures, such as heart rate variation (HRV), blood pressure and electrodermal activity (EDA), are widely used but still have limitations in sensitivity, reliability and usability. In this study, we propose a novel photoplethysmogram-based stress induced vascular index (sVRI) to measure cognitive load and stress. We also provide the basic methodology and detailed algorithm framework. We employed a classic experiment with three levels of task difficulty and three stages of testing period to verify the new measure. Compared with the blood pressure, heart rate and HRV components recorded simultaneously, the sVRI reached the same level of significance on the effect of task difficulty/period as the most significant other measure. Our findings showed sVRI's potential as a sensitive, reliable and usable parameter. Yongqiang Lyu 0001, Xiaomin Luo, Chun Yu, Congcong Miao, Yuanchun Shi, Ken-ichi Kameyama |
CHI | 1 |
| 2015 | Mitigating Code-Reuse Attacks on CISC Architectures in a Hardware Approach
Zhijiao Zhang, Ya-Shuai Lü, Yu Chen 0004, Yongqiang Lyu 0001, Yuanchun Shi |
SEC | 4 |
| 2015 | A PUF-FSM Binding Scheme for FPGA IP Protection and Pay-Per-Device LicensingabstractWith its reprogrammability, low design cost, and increasing capacity, field-programmable gate array (FPGA) has become a popular design platform and a target for intellectual property (IP) infringement. Currently available IP protection solutions are usually limited to protect single FPGA configurations and require permanent secret key storage in the FPGA. In addition, they cannot provide a commercially popular pay-per-device licensing solution. In this paper, we propose a novel IP protection mechanism to restrict IP's execution only on specific FPGA devices in order to efficiently protect IPs from being cloned, copied, or used with unauthorized integration. This mechanism can also enforce the pay-per-device licensing, which enables the system developers to purchase IPs from the core vendors at the low price based on usage instead of paying the expensive unlimited IP license fees. In our proposed binding-based mechanism, FPGA vendors embed into each enrolled FPGA device with a physical unclonable function (PUF) customized for FPGAs; IP vendors embed augmented finite-state machines (FSM) into the original IPs such that the FSM can be activated by the PUF responses from the FPGA device. We propose protocols to lock and unlock FPGA IPs, demonstrate how PUF can be embedded onto FPGA devices, and analyze the security vulnerabilities of our PUF-FSM binding method. We implement a 128-bit delay-based PUF on 28-nm FPGAs with only 258 RAM-lookup tables and 256 flipflops. The PUF responses are unique and reliable against environment changes. We also synthesize a variety of FSM benchmark circuits. On large benchmarks, the average timing overhead is 0.64% and power overhead in 0.01%. Jiliang Zhang 0002, Yaping Lin, Yongqiang Lyu 0001, Gang Qu 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2014 | Trusted Integrated Circuits: The Problem and Challenges
Yongqiang Lyu 0001, Qiang Zhou 0001, Yici Cai, Gang Qu 0001 |
J. Comput. Sci. Technol. | 1 |
| 2014 | A Survey on Silicon PUFs and Recent Advances in Ring Oscillator PUFs
Jiliang Zhang 0002, Gang Qu 0001, Yongqiang Lyu 0001, Qiang Zhou 0001 |
J. Comput. Sci. Technol. | 3 |
| 2013 | Design and Implementation of a Delay-Based PUF for FPGA IP ProtectionabstractPhysical Unclonable Function (PUF) makes use of the uncontrollable process variations during the production of IC to generate a unique signature for each IC. It has a wide application in security such as FPGA Intellectual Property (IP) protection, key generation and digital rights management. Ring Oscillator (RO) based PUF and Arbiter-based PUF are the most popular PUFs, but they are not specially designed for FPGA. RO-based PUF incurs high resource overhead while obtaining less challenge-response pairs, and requires ``hard macros'' to implement on FPGA. The arbiter-based PUF brings low resource overhead, but its structure is hard to be mapped on FPGA. Anderson'PUF can address these weaknesses of current Arbiter-based and RO-based PUFs. However, it cannot be directly implemented on the new generation FPGAs, and therefore it has the scalability issue. In order to address these problems, this paper presents a delay-based PUF using the intrinsic structure of FPGA (look-up table and multiplexer). The proposed delay-based PUF is completely realized on 28nm FPGAs. The experimental results show its high uniqueness and reliability. Moreover, we test the proposed PUF in the high temperature, and the results show its availability. Finally, the prospect of the proposed PUF in the FPGA IP protection is discussed. Jiliang Zhang 0002, Qiang Wu 0015, Yongqiang Lyu 0001, Qiang Zhou 0001, Yici Cai, Yaping Lin, Gang Qu 0001 |
CAD/Graphics | 3 |
| 2013 | Binding Hardware IPs to Specific FPGA Device via Inter-twining the PUF Response with the FSM of Sequential CircuitsabstractThe continuous growth in both capability and capacity for FPGA now requires significant resources invested in the hardware design, which results in two classes of main security issues: 1) the unauthorized use and piracy attacks including cloning, reverse engineering, tampering etc. 2) the licensing issue. Binding hardware IPs (HW-IPs) to specific FPGA devices can efficiently resolve these problems. However, previous binding techniques are all based on encryption and hence have three main drawbacks: 1) encryption-based proposals in commercial are limited to protect the single large FPGA configuration, 2) many encryption-based proposals depend on a trusted third party to involve the licensing protocol, and 3) the encryption-based binding methods use costly mechanisms such as secure ROM or flash memory to store FPGA specific cryptographic keys, which is not only expensive but also vulnerable to side-channel attacks, and the management and transport of secret keys became a practical issue. In this work, we propose a PUF-FSM binding technique completely different from the traditional encryption-based methods to address these shortcomings. Jiliang Zhang 0002, Yaping Lin, Yongqiang Lyu 0001, Ray C. C. Cheung, Wenjie Che, Qiang Zhou 0001, Jinian Bian |
FCCM | 3 |
| 2013 | FPGA IP protection by binding Finite State Machine to Physical Unclonable FunctionabstractIn this paper we propose a novel binding mechanism that can protect FPGA IP from being cloned, tampered, or misused; and facilitate the pay-per-use licensing to limit the FPGA IP's execution to specific FPGA devices only. In this mechanism, the FPGA vendors will provide each enrolled device with a Physical Unclonable Function (PUF) that can be deployed securely during fabrication process. The core vendor will embed an augmented Finite State Machine (FSM) into the original FSM structure of the hardware IP (HW-IP) to react on the PUF response to a given challenge. The proposed binding method does not need any Trusted Third Party (TTP) or block cipher for key management and exchange. We analyze several known attacks to hardware IP and show that our method is secure against these attacks. Experimental results on MCNC benchmarks show that the proposed method incurs small design overhead in terms of area, power and delay. Jiliang Zhang 0002, Yaping Lin, Yongqiang Lyu 0001, Gang Qu 0001, Ray C. C. Cheung, Wenjie Che, Qiang Zhou 0001, Jinian Bian |
FPL | 3 |
| 2013 | A multi-communication-fusion based mobile monitoring system for maternal and fetal informationabstractMeasurements of vital signs can be translated into accurate predictors of pregnant diseases, even at an early stage. They can also be combined with alarm-triggering systems to initiate the appropriate actions. Because of the emphasis on healthcare awareness and their specific needs, gravidae prefer regular vital signs monitoring in a flexible manner. Thus, different types of sensors are used that involve complex operations, networks, and results. To enhance usability and feasibility, we propose a mobile vital signs monitoring system based on multi-communication fusion and the Android OS so pregnant women can monitor maternal and fetal information anywhere they want. They can also access comprehensive care by transferring data to the server for further processing and remote diagnosis. The accuracy of remote diagnosis is also improved. Pei Lyu, Manman Peng, Yongqiang Lyu 0001, Yu Chen 0004 |
Healthcom | 3 |
| 2013 | Linear time-invariant system based assessment model for coronary heart diseaseabstractThis study proposes a linear time-invariant (LTI) system based assessment approach for coronary heart disease (CHD) risk. Unlike traditional risk regression models, the new approach considers accumulated effects of CHD factors with time and can thus perform time-based simulation and real time assessment for the progression of coronary heart disease. There are several LTI-based models achieved in this study via black box system identification process on a 1,549-men cohort. These models have good fitting on the sample data and can adequately reproduce results of the current dominant risk models. Our findings verified that the LTI-based modeling approach works for time-based CHD assessment — such models can be used for time-based simulation and real time evaluation if sufficient sample data is observed. Zening Qu, Yongqiang Lyu 0001, Yida Tang, Wenyao Wang, Jiaming Hong, Nazim Agoulmine |
Healthcom | 2 |
| 2012 | UE-based optimization for self-service community healthcare kioskabstractThere is vigorous development in Healthcare terminals. It not only reduces much of medical resources, but also is more convenient for people to monitor their physical condition, so has met with a warm reception. However, all of the devices in the terminals are electronic. Some small factors have an impact on the measuring result, lead to more or less deviation even mistakes. The paper researches on the impact that physical posture acts on the precision and deduces the functional relations between postures and deviation. How to design the healthcare terminals and guide the user to measure in the comfort posture to get the more precise result is the topic of the paper. As the verification, a series of experiment based on the design from the paper is carried out. Experimental results show that 1) the user comfort can be gauged and evaluated by psycho-physiological (medical) measurement and 2) the comfort-gauged formulation works in the design methodology and 3) the design methodology is applicable in real designs. Yongqiang Lyu 0001, Yuanyuan Du, Fanxi Yan, Shuqi Xu |
Healthcom | 2 |
| 2010 | A Low-Cost Ubiquitous Family Healthcare Framework
Yongqiang Lyu 0001, Lei Zhang 0060, Yu Chen 0004, Yingjie Ren, Weikang Yang, Yuanchun Shi |
UIC | 1 |
| 2008 | An innovative Steiner tree based approach for polygon partitioningabstractAs device technology continues to scale past 65 nm, the heavy application of resolution enhancement techniques (RET) makes the complexity, run time and quality issues in mask data preparation (MDP) grow severely. As one major and core step in MDP, polygon partitioning converts the complex layout shapes into trapezoids suitable for mask writing. The partitioning run time and quality of the resulting polygon partitions directly impacts the cost, integrity, and quality of the written mask. In this work, we introduce an innovative approach to solve the polygon partition problem by constructing a variant Steiner minimal tree: minimal partition tree (MPT). We prove the equivalence between MPT and the optimal polygon partition. Also, the solution search space for MPT is further reduced for the efficiency of the MPT algorithms. Finally, a generic MPT algorithm flow and a linear-time heuristic algorithm based on it are proposed. Experiments show that MPT solves the polygon partitioning with very promising and high quality results. Yongqiang Lyu 0001, Jamil Kawa |
ASP-DAC | 1 |
| 2007 | An efficient quadratic placement based on search space traversing technology
Yongqiang Lyu 0001, Xianlong Hong, Qiang Zhou 0001, Yici Cai |
Integr. | 1 |
| 2005 | Clock network minimization methodology based on incremental placementabstractIn ultra-deep submicron VLSI circuits, clock network is a major source of power consumption and power supply noise. Therefore, it is very important to minimize clock network size. Traditional design methodologies usually let the clock router to undertake the task of clock network minimization independently. Since a clock routing is carried out based on register locations, register placement actually has fundamental influence to a clock network size. In this paper, we propose a new clock network design methodology that Incorporates register placement optimization. Given a cell placement result, incremental modifications are performed according to clock skew specifications. The incremental placement change moves registers toward preferred locations that may enable a small clock network size. At the same time, the side-effect to logic cell placement and wire connections is controlled. Experimental results on benchmark circuits show that the proposed methodology can reduce clock network size considerably with limited impact on signal net wirelength and critical path delay. Yici Cai, Qiang Zhou 0001, Xianlong Hong, Jiang Hu 0001, Yongqiang Lyu 0001 |
ASP-DAC | 6 |
| 2005 | Register placement for low power clock networkabstractIn modern VLSI designs, the increasingly severe power problem requests to minimize clock routing wirelength so that both power consumption and power supply noise can be alleviated. In contrast to most of traditional works that handle this problem only in clock routing, we propose to navigate standard cell register placement to locations that enable further less clock routing wirelength and power. To minimize adverse impacts to conventional cell placement goals such as signal net wirelength and critical path delay, the register placement is carried out in the context of a quadratic placement. The proposed technique is particularly effective for the recently popular prescribed skew clock routing. Experiments on benchmark circuits show encouraging results. Yongqiang Lyu 0001, Cliff C. N. Sze, Xianlong Hong, Qiang Zhou 0001, Yici Cai, Jiang Hu 0001 |
ASP-DAC | 1 |
| 2005 | Navigating registers in placement for clock network minimizationabstractThe progress of VLSI technology is facing two limiting factors: power and variation. Minimizing clock network size can lead to reduced power consumption, less power supply noise, less number of clock buffers and therefore less vulnerability to variations. Previous works on clock network minimization are mostly focused on clock routing and the improvements are often limited by the input register placement. In this work, we propose to navigate registers in cell placement for further clock network size reduction. To solve the conflict between clock network minimization and traditional placement goals, we suggest the following techniques in a quadratic placement framework: (1) Manhattan ring based register guidance; (2) center of gravity constraints for registers; (3) pseudo pin and net; (4) register cluster contraction. These techniques work for both zero skew and prescribed skew designs in both wirelength driven and timing driven placement. Experimental results show that our method can reduce clock net wirelength by 16%~33% with no more than 0.5% increase on signal net wirelength compared with conventional approaches. Yongqiang Lyu 0001, Cliff C. N. Sze, Xianlong Hong, Qiang Zhou 0001, Yici Cai, Jiang Hu 0001 |
DAC | 1 |