VLDB 2026 Research / reviewers in the wild / expert
Gang Li 0038
dblp:62/2655-38
· DBLP profile ↗
13ranked-venue papers
4as first author
12since 2021 · last 2026
0000-0001-9133-8282ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 9 · 3 first-author · 8 since 2021Computer networks · 4 · 1 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RRAM-based gradient-aware victim row monitoring circuit for mitigating Rowhammer attacks
Zhuo Ruan, Lixun Wang, Yuejun Zhang, Pengjun Wang, Donghao Xia, Mengfan Xu, Gang Li 0038 |
Integr. | 7 |
| 2026 | Feistel-PUF: Sequential Obfuscation-Based Machine Learning Attack-Resistant Physical Unclonable Function for IoT Device Security AuthenticationabstractDevice authentication protocols based on a strong physical unclonable function (PUF) show promise for enhancing Internet of Things security. However, a strong PUF is vulnerable to machine learning (ML) attacks. This paper proposes a Feistel structure sequential obfuscation-based PUF (Feistel-PUF) to resist ML attacks. When the PUF is obfuscated by the Feistel structure, the challenge-response relationship resembles that of sequential logic circuits. Specifically, each response depends on both current and historical challenges, thereby significantly increasing the complexity of the challenge-response mapping. Experimental results showed that even with 1 million collected challenge response pairs, the prediction accuracies of ML attacks on Feistel-PUF remained at approximately 50%. Notably, the obfuscation process excluded response data, thereby preserving the randomness, reliability, and uniqueness of PUF with negligible performance degradation. The Feistel structure was iteratively reused for sequential obfuscation processing, maintaining constant and minimal hardware overhead. We propose a novel approach that combines the Feistel-PUF with an authentication protocol. This system synchronizes obfuscation parameters during the initial registration phase and implements dynamic updates throughout the authentication process. This approach allows the obfuscation structure to be made public, thereby overcoming the reliance on structure or algorithm secrecy in traditional dynamic challenge obfuscation schemes. The security of the protocol was confirmed by subjecting it to ProVerif verification and security analysis. Gang Li 0038, Liangxiao Zhao, Ziyu Zhou 0001, Pengjun Wang, Xuejiao Ma, Yuejun Zhang, Zhenghe Wang |
IEEE Internet Things J. | 1 |
| 2025 | A Strong PUF-Based Security Protocol to Protect AI Model Parameters Against Privacy Information LeakageabstractIn the era of intelligent computing, with the aid of Internet of Things (IoT) technology, artificial intelligence (AI) chips can be embedded at the terminal, object, edge, and cloud levels, ultimately achieving the vision where there is computation, there is AI intelligence. This not only enhances the efficiency of production and daily life but also exponentially increases the risk of privacy information leakage within AI models. This article leverages the characteristics of strong physical unclonable functions (PUFs), in which the inherent feature information is hidden in physical variations and difficult to steal, to design a security protocol based on strong PUFs that provides effective protection for AI model parameters in the IoT environment. The protocol treats AI model parameters as responses and selects challenges capable of generating these responses. Since the responses generated by the challenges can be considered as randomly generated, transmitting the challenges does not disclose the response information, thus avoiding the risk of parameter hacking. Additionally, the protocol utilizes machine-learning modeling techniques and lightweight encryption technologies to reduce the storage costs for identity information and the computational overhead of encryption operations. Through a security analysis of the protocol, it demonstrates that even under ideal attack conditions, the proposed protocol can resist various attacks. By using formal verification with the ProVerif tool, it confirms the security of the protocol flow and the effective protection of private information. Ziyu Zhou 0001, Gang Li 0038, Yuejun Zhang, Tengfei Yuan, Pengjun Wang |
IEEE Internet Things J. | 2 |
| 2025 | Improving the Stability of APUF to 100% Without Extra Hardware Overhead for Enhancing the Performance of Security Authentication ProtocolsabstractWith the increasing number of devices in the Internet of Things (IoT), security has become a necessary feature. Compared to traditional key encryption methods, IoT device authentication protocols based on strong Physically unclonable function (PUF) have the advantage of being difficult to leak and tamper with. In addition, the protocol can enhance the resistance of strong PUFs to machine learning (ML) attacks by encrypting private information. However, the quality of the authentication is strongly related to the stability of the generated responses. If a large cost is incurred to improve the stability of the strong PUF, it will consume the already scarce resources of the device. This article proposes a challenge screening strategy to improve the response stability of a commonly used strong PUF, arbiter PUF (APUF). First, a precise modeling method of APUF is carried out using the logistic-regression ML algorithm. Subsequently, random noise is injected into the challenges or PUF mathematical model and then calculated to estimate whether a stable response can be produced. Finally, stable challenges are used for IoT device authentication, while the threshold of the protocol is increased in parallel. Experimental verification shows that the proposed strategy can increase the stability of APUF responses to 100% at different temperatures. Furthermore, it does not consume hardware overhead at the device end, which is of particular significance for applications in resource-constrained conditions. Ziyu Zhou 0001, Pengjun Wang, Gang Li 0038, Shuang Hu 0001, Yuejun Zhang |
IEEE Internet Things J. | 3 |
| 2025 | A 154 F 2 Bistable Physically Unclonable Function With Independent Responses Based on Dynamic Division Multiplexing TechniqueabstractPhysically unclonable functions (PUFs) have significant potential in the field of information security applications. To reduce the area of PUF cells and improve the utilization of the PUF entropy source, a dynamic division multiplexing bistable PUF with independent output response is proposed. Initially, a bistable PUF model is constructed by dividing traditional cross-coupled bistable PUF cells. The pull-up (pull-down) network employs large transistor sizes to minimize process variations, while the pull-down (pull-up) network, as the main PUF entropy source, utilizes the minimum transistor size to maximize random process variations. Subsequently, a cross-coupled twin cell with a symmetrical structure and shared word lines is designed, and a PUF cell array is composed ofntwin cells. Finally, the PUF cell array is dynamically configured using the output signal from a decoder. In this configuration, a single selected cell (with large deviation) and$n-1$unselected cells connected in parallel (with negligible deviation) collectively form a bistable PUF circuit for dynamic division multiplexing. The proposed PUF can operate in two independent modes, each of which can generate a 2304-bit feature key. The design is fully customized using the Taiwan Semiconductor Manufacturing Company (TSMC) 65-nm process, and the area (feature size) of a twin cell is only$1.32~\mu $m2(308 F2). Chip test results demonstrated that the proposed PUF achieved the entropy of 0.9999 (0.9997), the uniqueness of 49.9% (49.7%), and the reliability of 99.1% (97.7%) in the Ncell PUF (NC-PUF) [Pcell PUF (PC-PUF)] mode, respectively. Gang Li 0038, Pengjun Wang, Xuejiao Ma, Bo Chen 0045, Xilong Shao |
IEEE Trans. Very Large Scale Integr. Syst. | 1 |
| 2025 | A 578-TOPS/W RRAM-Based Binary Convolutional Neural Network Macro for Tiny AI Edge DevicesabstractThe novel nonvolatile computing-in-memory (nvCIM) technology enables data to be stored and processed in situ, providing a feasible solution for the widespread deployment of machine learning algorithms in edge AI devices. However, current nvCIM approaches based on weighted current summation face challenges such as device nonidealities and substantial time, storage, and energy overheads when handling high-precision analog signals. To address these issues, we propose a resistive random access memory (RRAM)-based binary convolution macro for constructing a complete binary convolutional neural network (BCNN) hardware circuit, accelerating edge AI applications with low-weight precision. This macro performs error compensation at the circuit level and provides stable rail-to-rail output, eliminating the need for any ADCs or processor to perform auxiliary computations. Experimental results demonstrate that the proposed BCNN full-hardware computing system achieves on-chip recognition accuracy of 90.7% (98.64%) on the CIFAR10 (MNIST) dataset, which represents a decrease of 0.98% (0.59%) compared to software recognition accuracy. In addition, this binary convolution macro achieves a maximum throughput of 320 GOPS and a peak energy efficiency of 578 TOPS/W at 136 MHz. Lixun Wang, Yuejun Zhang, Pengjun Wang, Huihong Zhang, Gang Li 0038, Qikang Li |
IEEE Trans. Very Large Scale Integr. Syst. | 6 |
| 2025 | A Pay-Per-ISE RISC-V Processor With Hardware-Assisted Orthogonal ObfuscationabstractSecurity and cost efficiency are of utmost importance for embedded processors when it comes to limiting hardware resources in IoT applications. This brief presents a security reduced instruction set computer-five (RISC-V) specific instruction set extension (ISE) designed based on hardware-assisted orthogonal obfuscation for hardware security. The orthogonal obfuscation defines an architecture geared toward high-security processors that supports a Pay-Per-ISE function using a key management unit (KMU), thus capable of supporting the customization of the key for a user’s partially authorized ISE and controlling the unlocking of the specific ISE. The proposed security RISC-V test chip is fabricated in a 65-nm CMOS technology with a core area occupying about 0.739 mm2. The measured results demonstrate that our processor realizes the instruction set authorization function. The results show an average power of 52.8 mW at 1.2 V, a hardware overhead of <3% at 50 MHz, and a 30% improvement in security. Yuejun Zhang, Lixun Wang, Yongzhong Wen, Huihong Zhang, Gang Li 0038, Pengjun Wang |
IEEE Trans. Very Large Scale Integr. Syst. | 6 |
| 2024 | Timing-violation-soft PUF design based on carry-lookahead adderabstractWith the development of Internet of Things technology, there is an increasing demand for security protection under extreme resource-constrained conditions. Hardware-based physical unclonable functions (PUFs) become less effective as they require hardware replacement. In this paper, a design scheme of timing-violation-soft PUF (TVS PUF) based on carry-lookahead adder (CLA) is proposed for resource-constrained systems, by studying the metastable characteristics of flip-flop under timing violation status and the transmission path delay deviation of arithmetic operation circuits. Firstly, a synchronous timing module (STM) composed of a 32-bit CLA and flip-flops is constructed using Xilinx Artix-7 FPGA. Then, timing violation are induced in the STM by increasing the clock frequency using a Mixed-Mode Clock Manager (MMCM). Finally, by comparing the output values of the STM under timing violation status with those under normal operation status, the parity of flipped bits is used as the judgment criterion for PUF response, establishing the mapping relationship between challenges and responses. Experimental results demonstrate that the proposed PUF can utilize the existing hardware structure to generate 264challenge-response pairs (CRPs), exhibiting good randomness (passing 12 NIST test items), uniqueness (49.93%), and reliability (97.39%). When collecting up to 106groups of CRPs, the attack prediction rates of four common machine learning algorithms remain close to the 50% baseline of random guessing. Pengjun Wang, Gang Li 0038 |
ITC-Asia | 3 |
| 2024 | Bagua Protocol: A Whole-Process Configurable Protocol for IoT Sensing Devices Security Based on Strong PUFabstractThe Internet of Things (IoT) plays an important role in all aspects of production and day-to-day life. However, owing to the frequently trusted authentication vulnerabilities, the physical unclonable function (PUF) has unique advantages in the field of equipment authentication because of its nonstorage and nonvolatility. Nevertheless, PUFs are vulnerable to machine learning (ML) attacks. Once a model is constructed accurately, the secrecy of the PUF is lost. Therefore, Bagua matrices are proposed in this study, which can greatly reduce the accuracy of modeling by encrypting the challenge information. On this basis, a whole-process configurable IoT sensing device protocol was constructed for authentication and transmission, and different matrix encryption methods were configured according to the needs of the different devices. Moreover, on the premise of trusted authentication, the perceptual information can be encrypted using a preset matrix. According to the implementation results of the scheme, the resistance to the ML attacks of the PUF improved significantly and the device authentication and encrypted transmission could operate normally. Ziyu Zhou 0001, Pengjun Wang, Gang Li 0038 |
IEEE Internet Things J. | 3 |
| 2023 | Design of a Novel Self-Test-on-Chip Interface ASIC for Capacitive AccelerometersabstractHigh-precision miniaturized micromechanical accelerometers are used extensively in the civilian and military fields. A novel self-test-on-chip method and time-multiplexing feedback method for capacitive accelerometers were proposed in this work. The self-test-on-chip circuit can simulate an acceleration signal to test the harmonic distortion without a high-precision shaker table. Using digital timing control, the time-multiplexing feedback can reduce the coupling between the feedback signal and the detection signal. In addition, a low-noise charge sensing and sigma-delta modulator were designed for a high-precision digital output. The interfaced circuit with fully differential topology was fabricated in a$0.35 \mu \text{m}$standard complementary metal-oxide semiconductor (CMOS) process. The integrated accelerometers can achieve a power consumption of 7 mW from a 5 V supply at a sampling frequency of 256 kHz, a noise floor of −140 dBV below 400 Hz. The equivalent input noise voltage density is 250nV/$\surd $Hz, corresponding to a reference voltage of 2.5V. It can achieve an equivalent noise acceleration of$0.14 \mu \text{g}\surd $Hz and a bias instability of$9 \mu \text{g}$at a bandwidth of 400 Hz, a nonlinearity of 0.13% within ±1 g. Xiangyu Li 0011, Pengjun Wang, Gang Li 0038, Yuejun Zhang |
IEEE Trans. Circuits Syst. I Regul. Pap. | 3 |
| 2021 | A 0.004% resolution & SAT
Yuejun Zhang, Pengjun Wang, Qiufeng Wu, Gang Li 0038 |
Integr. | 5 |
| 2021 | A Multimode Configurable Physically Unclonable Function With Bit-Instability-Screening and Power-Gating StrategiesabstractThis study presents a technique for designing a multimode configurable weak physically unclonable function (PUF) for security-key generation. The PUF cell is based on the maximum gain point deviations of bias-voltage-controlled inverters. By implementing a preselection strategy, the proposed PUF can simultaneously expose all unstable cells under normal voltage and temperature. Owing to the configurable bias circuit, the PUF cell can be biased at three operating modes, namely, traditional inverter (INV), current-starved inverter (CSI), and power gating (PG). The measurement results from a 65-nm prototype show that the proposed PUF has the following outstanding features: 1) it has a compact cell layout with a minimum feature size of 966 F2; 2) an autocorrelation function of 0.0099 is achieved; and 3) all unstable cells can be eliminated using a preselection procedure, which can drastically reduce the energy and area costs for error correction. In addition, in the CSI mode, the proposed PUF (standard voltage) has maximum frequency and throughput of 714 MHz and 45.7 Gb/s, respectively. Meanwhile, under the INV mode, the worst native bit error rate (low voltage) for 5000 evaluations is only 0.33%, indicating a desirable instability against voltage and temperature variations with a sensitivity coefficient of 1.85%/V and 0.018%/°C, respectively. Moreover, the measured energy efficiency at 0.6 V is 6.83 fJ/bit. Finally, under the PG mode, the standby powers at 0.6 and 1.2 V are only 18 and 86 nW, respectively. Gang Li 0038, Pengjun Wang, Xuejiao Ma, Yijian Shi, Bo Chen 0045, Yuejun Zhang |
IEEE Trans. Very Large Scale Integr. Syst. | 1 |
| 2020 | A 215-F² Bistable Physically Unclonable Function With an ACF of <0.005 and a Native Bit Instability of 2.05% in 65-nm CMOS ProcessabstractThis article presents a novel class of bistable physically unclonable functions (PUFs) for security-oriented applications. The traditional cross-coupled bistable PUF cell is divided into P-net and N-net, wherein the P-net (N-net) multiplexing acts as the shared head (foot), and the N-net (P-net) duplicating multiple acts as the PUF cell. The proposed PUF was fabricated in a Taiwan Semiconductor Manufacturing Company (TSMC) 65-nm process with full-custom design. It can parallelly generate 128-bit identifications (IDs) in one clock cycle owing to the random access word-level readout framework. The measurement results show that the randomness and uniqueness of the proposed PUF are consistent with those of the state-of-the-art works. In addition, the proposed PUF has the following features: 1) the PUF cell is composed only of four nMOS transistors with a minimum feature size of 215-F2; 2) the native bit instability at the golden condition (i.e., 1.2 V, 25 °C) with 500 evaluations is only 2.05%, showing a desirable native stability against supply noise; 3) the bit-error-rate dependences of the voltage and temperature are 3.35%/V and 0.011%/°C, respectively, with the voltage varying within the range 1.0-1.4 V and the temperature varying within the range -40 °C to 125 °C; 4) an autocorrelation function of 0.0049 at a 95% confidence level is achieved and is the lowest reported value to date; and 5) the energy efficiency and throughput at the maximum operating frequency (i.e., 433 MHz) are 99.48 fJ/b and 55.5 Gb/s, respectively. Gang Li 0038, Pengjun Wang, Xuejiao Ma, Jiana Lian, Junpeng Shu, Yuejun Zhang |
IEEE Trans. Very Large Scale Integr. Syst. | 1 |