VLDB 2026 Research / reviewers in the wild / expert
Xinjie Zhao 0001
dblp:66/10058 · also Xin-jie Zhao 0001
· DBLP profile ↗
20ranked-venue papers
5as first author
4since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 3 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-authorSystems, architecture and hardware · 3 · 2 since 2021Artificial intelligence and machine learning · 1Computer networks · 1Software engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Exploring the Internals of Fault-Induced Data-Level Vulnerabilities in Cryptographic LibrariesabstractFault-induced vulnerabilities have been studied in various aspects. While traditional fault injection techniques easily detect system-level vulnerabilities like buffer overflows, fault executions can introduce subtle potential vulnerabilities that may not trigger any system-level observable behaviors. These are particularly dangerous in cryptography. Using advanced cryptanalysis methods, these vulnerabilities, such as producing faulty ciphertexts, have been successfully exploited and are regarded as great threats to the security of real-world cryptography. In this way, there is a pressing need to study this very area. Our paper generally explores the internals of the fault-induced data-level vulnerabilities, which are subtle vulnerabilities resulting from faults that may not cause system crashes or overt errors but can expose sensitive information or weaken cryptographic primitives under specific cryptanalytic techniques, in cryptographic libraries. We propose a novel framework which can systematically analyze the vulnerabilities in cryptographic libraries under different fault models. By employing this method, we identified numerous critical fault locations that could undermine the security of cryptographic systems across a broad spectrum of libraries, fault models, and platforms. Furthermore, we provide a comprehensive analysis of select case studies, and engage in detailed discussions about the strategies to alleviate such vulnerabilities. Guorui Xu, Qianmei Wu, Fan Zhang 0010, Xinjie Zhao 0001, Shize Guo |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Key Schedule Guided Persistent Fault AttackabstractPersistent Fault Analysis(PFA) is a powerful analysis technique proposed in CHES 2018, which utilizes those faults that are injected before execution and persist throughout the encryption. However, when it is applied to the block cipher which has multiple S-boxes, the key cannot be recovered in just one attack. The adversary has to conduct the fault attack several times and inject faults into all the distinct S-boxes. In this paper, we proposeKey Schedule Guided Persistent Fault Attack(KGPFA), which utilizes the key schedule to guide the fault injection and fault analysis. By analyzing the key schedule, KGPFA exploits the relations between the key leakages caused by the same faulty S-box in various rounds. It can reduce the number of attacks and the number of faults required to recover the key. Our major contributions are twofold. Firstly, in the fault injection step, we provideKey Schedule Guided Persistent Fault Injection(KGPFI) strategies to reduce the number of attacks and the number of faults under the assumption of both ciphertext-only and known-plaintext attacks. Secondly, in the fault analysis step, as our target ciphers are Feistel-based, we propose theIneffective Algebraic Persistent Fault Analysis(IAPFA) to extend the usage ofAlgebraic Persistent Fault Analysis(APFA) in the ineffective persistent fault setting. To demonstrate the effectiveness of our technique, we apply KGPFA to four widely used block ciphers with multiple S-boxes, DES, 3DES, LBlock, and Camellia. In our experiment, in the ciphertext-only attack, the key of DES can be recovered with 300 ineffective ciphertexts (coresponding to 827 ciphertexts) and four faulty S-boxes within 12.18min. Under the assumption of known-plaintext, the key of DES is recovered within two faulty S-boxes in 2.34h. For LBlock, the key is recovered with two faulty S-boxes and 100 ineffective ciphertexts (coresponding to 6211 ciphertexts) in 1.16min. Fan Zhang 0010, Xinjie Zhao 0001, Jie Xiao 0003, Shize Guo |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Stalker: A Framework to Analyze Fragility of Cryptographic Libraries under Hardware Fault ModelsabstractFor embedded devices, the uncertainty of target physical environments is always a great challenge. With constrained resources and common overloaded uses, they can be more exposed to hardware faults. Other than stability and ordinary security issues, there exist some subtle phenomenons that lead to potential cryptanalysis or secret leakage. In this paper, we present STALKER, a framework to analyze the fragility of libraries under hardware fault models. Compared with existing tools, our framework targets faulty execution outputs, and can flexibly work on different libraries, architectures and support different search schemes. We find dozens of security-sensitive bits that may cause critical issues and provide detailed analysis. Guorui Xu, Fan Zhang 0010, Xinjie Zhao 0001, Shize Guo, Kui Ren 0001 |
DAC | 3 |
| 2021 | Pushing the Limit of PFA: Enhanced Persistent Fault Analysis on Block CiphersabstractPersistent fault analysis (PFA) is a newly proposed cryptanalysis for block ciphers. Although the injected fault is persistent during the entire encryption, the corresponding analysis is only applied to the last round in the original PFA. In this article, the enhanced PFA (EPFA) is proposed, which can push the limit of PFA by exploiting the fault leakage in deeper rounds and target to reduce the number of required ciphertexts as small as possible. EPFA is first introduced as a general method with a specific application to advanced encryption standard (AES). Then it is extended to other substitution–permutation network (SPN)-based block ciphers, such as LED and SKINNY, both of which have unique features that EPFA fits well. To improve the efficiency of EPFA, a parallel algorithm based on mixed radix numbers is developed, which fully utilizes the power of GPU. Our experimental results show that EPFA can reduce the number of required ciphertexts to be under 1000, which is only about 40% of the 2500 ciphertexts in previous PFA on AES. In contrast to the single-threaded implementation, the parallel EPFA can have a speedup roughly about 200 times. Guorui Xu, Fan Zhang 0010, Bolin Yang, Xinjie Zhao 0001, Wei He 0015, Kui Ren 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2019 | Enhanced Differential Cache Attacks on SM4 with Algebraic Analysis and Error-Tolerance
Xiaoxuan Lou, Fan Zhang 0010, Guorui Xu, Ziyuan Liang, Xinjie Zhao 0001, Shize Guo, Kui Ren 0001 |
Inscrypt | 5 |
| 2018 | Improved Differential Fault Analysis on LED with Constraint Equations: Towards Reaching Its LimitabstractThe block cipher LED is well suited for resource-constrained scenarios. However, it is vulnerable to the recent fault attacks and different results have been achieved even under the same fault model. In this paper, a comprehensive investigation is conducted on the fault analysis on LED. A novel differential fault analysis is proposed, which is based on the so-called constraint equations. The proposed attack can combine constraint equations at different levels, pushing the differential fault analysis on LED towards its limit in terms of the time complexity, the data complexity and the remained key search space. Under random nibble fault model, SINGLE fault injection can reduce the key search space of LED-64 to 27.90within 1.89s, compared to 217.65within 7 minutes in prior finest contributions. As to DFA on LED-128, TWO fault injections can reduce the key search space to 215.82within 247.88s, compared to 221.96within 16 minutes in previous work. To the best of our knowledge, the scheme that we proposed is the most efficient fault attack on LED cryptosystems. Fan Zhang 0010, Xinjie Zhao 0001, Shize Guo, Ziyuan Liang, Samiya Qureshi |
ICPADS | 3 |
| 2018 | Theoretical Round Modification Fault Analysis on AEGIS-128 with Algebraic TechniquesabstractThis paper proposed an advanced round modification fault analysis (RMFA) at the theoretical level on AEGIS-128, which is one of seven finalists in CAESAR competition. First, we clarify our assumptions and simplifications on the attack model, focusing on the encryption security. Then, we emphasize the difficulty of applying vanilla RMFA to AEGIS-128 in the practical case. Finally we demonstrate our advanced fault analysis on AEGIS-128 using machine-solver based algebraic techniques. Our enhancement can be used to conquer the practical scenario which is difficult for vanilla RMFA. Simulation results show that when the fault is injected to the initialization phase and the number of rounds is reduced to one, two samples of injections can extract the whole 128 key bits within less than two hours. This work can also be extended to other versions such as AEGIS-256. Fan Zhang 0010, Xiaofei Dong, Xinjie Zhao 0001, Samiya Qureshi, Xiaoxuan Lou, Yongkang Tang |
MASS | 3 |
| 2018 | Optimal model search for hardware-trojan-based bit-level fault attacks on block ciphers
Xinjie Zhao 0001, Fan Zhang 0010, Shize Guo |
Sci. China Inf. Sci. | 1 |
| 2018 | Efficient flush-reload cache attack on scalar multiplication based signature algorithm
Tao Wang 0008, Xiaoxuan Lou, Xinjie Zhao 0001, Fan Zhang 0010, Shize Guo |
Sci. China Inf. Sci. | 4 |
| 2018 | Survey of design and security evaluation of authenticated encryption algorithms in the CAESAR competitionabstractThe Competition for Authenticated Encryption: Security, Applicability, and Robustness (CAESAR) supported by the National Institute of Standards and Technology (NIST) is an ongoing project calling for submissions of authenticated encryption (AE) schemes. The competition itself aims at enhancing both the design of AE schemes and related analysis. The design goal is to pursue new AE schemes that are more secure than advanced encryption standard with Galois/counter mode (AES-GCM) and can simultaneously achieve three design aspects: security, applicability, and robustness. The competition has a total of three rounds and the last round is approaching the end in 2018. In this survey paper, we first introduce the requirements of the proposed design and the progress of candidate screening in the CAESAR competition. Second, the candidate AE schemes in the final round are classified according to their design structures and encryption modes. Third, comprehensive performance and security evaluations are conducted on these candidates. Finally, the research trends of design and analysis of AE for the future are discussed. Fan Zhang 0010, Ziyuan Liang, Bolin Yang, Xinjie Zhao 0001, Shize Guo, Kui Ren 0001 |
Frontiers Inf. Technol. Electron. Eng. | 4 |
| 2017 | Transistor level SCA-resistant scheme based on fluctuating power logic
Liang Geng, Fan Zhang 0010, Jizhong Shen, Wei He 0015, Shivam Bhasin, Xinjie Zhao 0001, Shize Guo |
Sci. China Inf. Sci. | 6 |
| 2017 | Low-cost design of stealthy hardware trojan for bit-level fault attacks on block ciphers
Fan Zhang 0010, Xinjie Zhao 0001, Wei He 0015, Shivam Bhasin, Shize Guo |
Sci. China Inf. Sci. | 2 |
| 2017 | Stealthy Hardware Trojan Based Algebraic Fault Analysis of HIGHT Block CipherabstractHIGHT is a lightweight block cipher which has been adopted as a standard block cipher. In this paper, we present a bit-level algebraic fault analysis (AFA) of HIGHT, where the faults are perturbed by a stealthy HT. The fault model in our attack assumes that the adversary is able to insert a HT that flips a specific bit of a certain intermediate word of the cipher once the HT is activated. The HT is realized by merely 4 registers and with an extremely low activation rate of about 0.000025. We show that the optimal location for inserting the designed HT can be efficiently determined by AFA in advance. Finally, a method is proposed to represent the cipher and the injected faults with a merged set of algebraic equations and the master key can be recovered by solving the merged equation system with an SAT solver. Our attack, which fully recovers the secret master key of the cipher in 12572.26 seconds, requires three times of activation on the designed HT. To the best of our knowledge, this is the first Trojan attack on HIGHT. Hao Chen 0003, Tao Wang 0008, Fan Zhang 0010, Xinjie Zhao 0001, Wei He 0015, Lumin Xu |
Secur. Commun. Networks | 4 |
| 2016 | A Framework for the Analysis and Evaluation of Algebraic Fault Attacks on Lightweight Block CiphersabstractAlgebraic fault analysis (AFA), which combines algebraic cryptanalysis with fault attacks, has represented serious threats to the security of lightweight block ciphers. Inspired by an earlier framework for the analysis of side-channel attacks presented at EUROCRYPT 2009, a new generic framework is proposed to analyze and evaluate algebraic fault attacks on lightweight block ciphers. We interpret AFA at three levels: 1) the target; 2) the adversary; and 3) the evaluator. We describe the capability of an adversary in four parts: 1) the fault injector; 2) the fault model describer; 3) the cipher describer; and 4) the machine solver. A formal fault model is provided to cover most of current fault attacks. Different strategies of building optimal equation set are also provided to accelerate the solving process. At the evaluator level, we consider the approximate information metric and the actual security metric. These metrics can be used to guide adversaries, cipher designers, and industrial engineers. To verify the feasibility of the proposed framework, we make a comprehensive study of AFA on an ultra-lightweight block cipher called LBlock. Three scenarios are exploited, which include injecting a fault to encryption, to key scheduling, or modifying the round number or counter. Our best results show that a single fault injection is enough to recover the master key of LBlock within the affordable complexity in each scenario. To verify the generic feature of the proposed framework, we apply AFA to three other block ciphers, i.e., Data Encryption Standard, PRESENT, and Twofish. The results demonstrate that our framework can be used for different ciphers with different structures. Fan Zhang 0010, Shize Guo, Xinjie Zhao 0001, Tao Wang 0008, Jian Yang 0018, François-Xavier Standaert, Dawu Gu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2014 | Algebraic Fault Analysis on GOST for Key Recovery and Reverse EngineeringabstractGOST is a well-known block cipher as the official encryption standard for the Russian Federation. A special feature of GOST is that its eight S-boxes can be secret. However, most of the researches on GOST assume that the design of these S-boxes is known. In this paper, the security of GOST against side-channel attacks is examined with algebraic fault analysis (AFA), which combines the algebraic cryptanalysis with the fault attack. Three AFAs on GOST, which have different attack goals in different scenarios, are investigated. The results show that 8 fault injections are required to recover the secret key when the full design of GOST is known, which is less than 64 fault injections required in previous work. 64 fault injections are required to recover the eight unknown S-boxes assuming the key is known. 270 fault injections are required to recover the key and the eight S-boxes when both are unknown. The results prove that AFA is very effective and keeping some components in a cipher secret cannot guarantee its security against fault attacks. Xinjie Zhao 0001, Shize Guo, Fan Zhang 0010, Tao Wang 0008, Zhijie Jerry Shi, Chujiao Ma, Dawu Gu |
FDTC | 1 |
| 2014 | Exploiting the Incomplete Diffusion Feature: A Specialized Analytical Side-Channel Attack Against the AES and Its Application to Microcontroller ImplementationsabstractAlgebraic side-channel attack (ASCA) is a typical technique that relies on a general solver to solve the equations of a cipher and its side-channel leaks. It falls under analytical side-channel attack and can recover the entire key at once. Many ASCAs are proposed against the AES, and they utilize the Gröbner basis-based, SAT-based, or optimizer-based solver. The advantage of the general solver approach is its generic feature, which can be easily applied to different cryptographic algorithms. The disadvantage is that it is difficult to take into account the specialized properties of the targeted cryptographic algorithms. The results vary depending on what type of solver is used, and the time complexity is quite high when considering the error-tolerant attack scenarios. Thus, we were motivated to find a new approach that would lessen the influence of the general solver and reduce the time complexity of ASCA. This paper proposes a new analytical side-channel attack on AES by exploiting the incomplete diffusion feature in one AES round. We named our technique incomplete diffusion analytical side-channel analysis (IDASCA). Different from previous ASCAs, IDASCA adopts a specialized approach to recover the secret key of AES instead of the general solver. Extensive attacks are performed against the software implementation of AES on an 8-bit microcontroller. Experimental results show that: 1) IDASCA can exploit the side-channel leaks in all AES rounds using a single power trace; 2) it has less time complexity and more robustness than previous ASCAs, especially when considering the error-tolerant attack scenarios; and 3) it can calculate the reduced key search space of AES for the given amount of side-channel leaks. IDASCA can also interpret the mechanism behind previous ASCAs on AES from a quantitative perspective, such as why ASCA can work under unknown plaintext/ciphertext scenarios and what are the extreme cases in ASCAs. Shize Guo, Xinjie Zhao 0001, Fan Zhang 0010, Tao Wang 0008, Zhijie Jerry Shi, François-Xavier Standaert, Chujiao Ma |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2013 | Improving and Evaluating Differential Fault Analysis on LED with Algebraic TechniquesabstractThis paper proposes a fault analysis technique on LED by combining algebraic cryptanalysis and differential fault analysis (DFA). The technique is called algebraic differential fault analysis (ADFA). In ADFA on LED, we use DFA to deduce the possible fault differences of the correct and faulty S-Box input in the last round, and convert them into algebraic equations. We then combine the equation set of LED with the injected fault and use the CryptoMiniSat solver to recover the secret key. Our experiments show that, on a common PC, ADFA can succeed on LED under the nibble-based fault model within three minutes and with only one fault injection, which is more efficient than previous DFA work. To evaluate DFA on LED, we first propose an improved evaluation algorithm of DFA, then provide a modified ADFA approach to compute the solutions for the secret key. The results are more accurate than previous work. We also successfully extend ADFA on LED to other fault models using a single fault injection, where traditional DFAs are difficult to launch. Xinjie Zhao 0001, Shize Guo, Fan Zhang 0010, Zhijie Jerry Shi, Chujiao Ma, Tao Wang 0008 |
FDTC | 1 |
| 2013 | A comprehensive study of multiple deductions-based algebraic trace driven cache attacks on AES
Xinjie Zhao 0001, Shize Guo, Fan Zhang 0010, Tao Wang 0008, Zhijie Jerry Shi, Zhe Liu 0001, Jean-François Gallais |
Comput. Secur. | 1 |
| 2013 | Efficient Hamming weight-based side-channel cube attacks on PRESENT
Xinjie Zhao 0001, Shize Guo, Fan Zhang 0010, Tao Wang 0008, Zhijie Jerry Shi, Keke Ji |
J. Syst. Softw. | 1 |
| 2010 | Fuzzy logic controller for freeway ramp metering with particle swarm optimization and PARAMICS simulationabstractIn this paper, two TS-type fuzzy logic controllers (FLC) in direct and incremental forms are constructed for freeway local ramp metering tasks. The values of consequent part of fuzzy rules are optimized with a particle swarm optimization algorithm (PSO). The optimization process under PSO is carried out on PARAMICS microscopic traffic simulation platform. FLC methods and the traditional ALINEA control method are examined and compared on the traffic density performance. Simulation results on PARAMICS show the applicability and efficiency of the proposed FLC. Jianxin Xu 0001, Xinjie Zhao 0001, Dipti Srinivasan |
FUZZ-IEEE | 2 |