VLDB 2026 Research / reviewers in the wild / expert
Yuejun Liu
dblp:91/10173
· DBLP profile ↗
28ranked-venue papers
3as first author
26since 2021 · last 2026
0000-0002-3821-4050ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 2 first-author · 15 since 2021Systems, architecture and hardware · 9 · 9 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Rejection Matters: Efficient Non-Profiling Side-Channel Attack on ML-DSA via Exploiting Public TemplatesabstractML-DSA (formerly CRYSTALS-Dilithium), NIST’s primary post-quantum signature standard, is increasingly deployed along with the post-quantum transitions. Yet when the implementations of ML-DSA are deployed in practice, their physical security remains underexplored. In this work, we reveal a new attack surface against ML-DSA by exploiting the leakages from both rejected signing trials and the final accepted signing trial. We present, to the best of our knowledge, the first side-channel attack that simultaneously leverages leakage from both trials without relying on clone devices. Unlike traditional Secret-based Template Attacks, which require profiling the leakage of the sensitive intermediates on a clone device, our PTA (Public-based Template Attack) builds leakage templates solely from publicly available data on the target device itself. With challenge c known, we then perform CPA on the sensitive intermediates using traces from both rejected and accepted signing trials, quadrupling (on average) exploitable leakage per signing request for ML-DSA-44. The experimental results on power traces from an ARM Cortex-M4 board show that challenges c are fully recovered with only 96 traces, and then the key recovery succeeds in around 300 traces — a fact of 10x fewer than prior art. We highlight that our attack can be applied across all three ML-DSA variants with different security levels. Moreover, our attack works straightforwardly in the hedged (non-deterministic) mode of ML-DSA, demonstrating that the hedging offers no SCA protection in this scenario. Wei Cheng 0003, Zehua Qiao, Yuejun Liu, Yongbin Zhou |
DATE | 4 |
| 2026 | Memory-Optimized Masked CRYSTALS-Kyber Implementation on ARM Cortex-M4
Ruiqi Hou, Yiwen Gao 0001, Wei Cheng 0003, Yuejun Liu, Jingdian Ming, Yongbin Zhou |
ICDCS | 4 |
| 2026 | Deep Learning-based Public Template Attack against ML-DSA on ARM Microcontrollers
Zehua Qiao, Wei Cheng 0003, Yuejun Liu, Yongbin Zhou |
ISCAS | 4 |
| 2026 | SERP-SCA: A Strengthened Side-Channel Attack Framework for FALCON SignatureabstractNIST has selected Falcon as one of the standardized post-quantum digital signature algorithms, making the security of Falcon against side-channel attacks (SCAs) a critical area of concern. This paper introduces SERP-SCA, a strengthened SCA framework for Falcon, which exploits leakage from floating-point multiplications to recover secret floating-point values, which can subsequently be mapped to the coefficients of the secret key. The framework adopts a divide-and-conquer strategy to target the mantissa, exponent, and sign bit of floating-point values, with specialized optimizations for attacks on the mantissa and exponent. For mantissa attacks, SERP-SCA integrates bit segmentation with a sequential attack strategy to fully exploit the leakage from mantissa multiplication and incorporates an error-correction mechanism to further enhance attack efficiency. For exponent attacks, SERP-SCA leverages Fast Fourier Transform (FFT) properties to narrow the enumeration space, significantly improving time efficiency. We conduct practical attacks on Falcon-512 and Falcon-1024 implementations running on ARM Cortex-M4. Compared to state-of-the-art methods, SERP-SCA achieves an improvement of 22.11% in success rate for Falcon-512 and 18.64% for Falcon-1024, with remarkable time efficiency gains of around 195,369× and 183,175× for mantissa attacks, and 180× and 185× for exponent attacks, respectively. Honglin Shao, Jingdian Ming, Yuejun Liu, Yiwen Gao 0001, Yongbin Zhou |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2025 | Breaking the Shield: Novel Fault Attacks on CRYSTALS-Dilithium
Dixiao Du, Yuejun Liu, Yiwen Gao 0001, Jingdian Ming, Yongbin Zhou |
ACISP (2) | 2 |
| 2025 | Enhanced Key Mismatch Attacks on Lattice-Based KEMs: Multi-bit Inference and Ciphertext Generalization
Yuejun Liu, Yongbin Zhou, Mingyao Shao |
ESORICS (2) | 2 |
| 2025 | MEML-KEM: A Memory-Efficient Implementation of ML-KEM for IoT Devices
Ruiqi Hou, Yiwen Gao 0001, Yuejun Liu, Jingdian Ming, Yongbin Zhou |
ICA3PP (7) | 3 |
| 2025 | Masked Gadgets for Integer-Floating-Point Conversion with Applications to FalconabstractFalcon has been selected by the National Institute of Standards and Technology (NIST) as one of the standardized post-quantum digital signature algorithms. Unlike other candidate algorithms, Falcon relies heavily on floating-point operations, which are known to be vulnerable to side-channel attacks (SCAs). Although recent research proposes masking schemes for basic floating-point operations, secure conversion between integer and floating-point representations remains unaddressed. These conversions operate directly on the private key or other sensitive variables and therefore constitute a potential attack surface. This paper proposes new masking gadgets that securely perform conversions between integers and floating-point representations, addressing this previously unprotected surface. As part of the design, we optimize existing normalization and floating-point composition components to support the conversion process. We formally prove that our gadgets satisfy$t$-Non-Interference$(t-\text{NI})$or$t$-Strong Non-Interference ($t$-SNI) in the probing model and evaluate their side-channel resistance using Test Vector Leakage Assessment (TVLA) on an Arm Cortex-M4 processor. We also assess performance on an Intel Core CPU, where the optimized normalization and floating-point composition components demonstrate improvements of approximately 47.6 % and 10.8 %, respectively, over prior work. Jingdian Ming, Yuejun Liu, Yiwen Gao 0001, Yongbin Zhou |
ICCD | 3 |
| 2025 | A Versatile Decentralized Attribute Based Signature Scheme for IoT
Dazhi Xu, Yuejun Liu, Jiabei Wang, Yiwen Gao 0001, Yongbin Zhou |
ICICS (1) | 2 |
| 2025 | Efficient CNN-Based Side-Channel Attacks on Dilithium without Device AccessabstractThe post-quantum cryptography standard, released in August 2024, faces significant threats from side-channel attacks (SCAs). While non-profiled attacks demand extensive traces and time, profiled attacks, though more effective, require access to identical devices. This paper proposes a hybrid SCA on Dilithium, leveraging the strengths of both approaches. Our method profiles a template using leakage from operations with known variables, then applies it to target sensitive variables. Specifically, Convolutional Neural Networks (CNNs) are employed to model leakages from Inverse Number Theoretic Transform (INTT) operations. This model is subsequently used to recover private keys by targeting INTT operations involving c. Implemented on an ARM Cortex-M4 platform, our attack requires only 10/27/18 power traces to recover keys for Dilithium2/3/5, respectively, significantly reducing the number of traces compared to prior non-profiled attacks requiring hundreds. Zehua Qiao, Yuejun Liu, Yongbin Zhou, Dixiao Du |
ISCAS | 2 |
| 2025 | Diverse Fault Attacks on Dilithium and Variant Implementation: Skipping, Aborting and ZeroingabstractAs one of the first post-quantum digital signature schemes standardized by NIST, Dilithium has gained significant attention due to its potential role in securing communication in the quantum era. However, ensuring the security of its practical implementations, particularly against fault attacks, remains a significant challenge. Despite various proposed countermeasures, their effectiveness remains inadequately explored. This paper presents a comprehensive analysis of fault attacks on Dilithium, introducing five distinct attack techniques across three fault types: instruction-skipping, loop-aborting, and zeroing, which target the polynomial structure and Number Theoretic Transform (NTT) operations in Dilithium. These attacks are shown to significantly reduce the number of faulty signatures required for private key recovery, with the most efficient technique requiring as few as one faulty signature. Our methods successfully compromise both the reference and the protected implementation designed to resist skip-addition attacks. Experimental validation on an ARM Cortex-M4 platform demonstrates the effectiveness of these attacks, with success rates ranging from 29% to 63%, enabling full private key recovery in both deterministic and randomized Dilithium implementations. These findings underscore the need for more robust, fault-resilient post-quantum cryptographic implementations. Yuejun Liu, Jingdian Ming, Yongbin Zhou |
TrustCom | 2 |
| 2024 | Pairwise and Parallel: Enhancing the Key Mismatch Attacks on Kyber and BeyondabstractMisuse resilience is an important research topic in the NIST PQC standardization process. Key mismatch attacks are a major type of misuse attack. In key mismatch attacks, the adversary aims to recover the reused secret key by sending special ciphertexts to the target party and observing whether the shared key matches his guesses or not. Mingyao Shao, Yuejun Liu, Yongbin Zhou |
AsiaCCS | 2 |
| 2024 | A Novel Power Analysis Attack against CRYSTALS-Dilithium ImplementationabstractPost-Quantum Cryptography (PQC) was proposed due to the potential threats quantum computer attacks against conventional public key cryptosystems, and four PQC algorithms besides CRYSTALS-Dilithium (Dilithium for short) have so far been selected for National Institute of Standards and Technology (NIST) standardization. However, the selected algorithms are still vulnerable to side-channel attacks in practice, and their physical security need to be further evaluated. This paper proposes two efficient power analysis attacks against Dilithium implementation, the optimized fast two-stage approach and the single-bit approach, aiming at reducing the key guess space. Our findings reveal that the optimized approach outperforms the conservative approach and the fast two-stage approach proposed in ICCD 2021 by factors of 338 and 49, respectively. Similarly, compared to these two approaches, the single-bit approach achieves acceleration of 367 times and 53 times, respectively. Yuejun Liu, Yongbin Zhou, Yiwen Gao 0001, Zehua Qiao, Huaxin Wang |
ETS | 2 |
| 2024 | Heterogeneous Performs Better: High Throughput Implementations of Falcon in Multi-Client ScenariosabstractThis paper investigates high-performance implementations of Falcon scheme, which is one of the four post-quantum cryptography algorithms standardized by NIST. We explore high-throughput implementation solutions by improving how critical components of Falcon execute on the GPU, with a focus on low latency requirements. Our research reveals that some components of Falcon cannot fully exploit the parallelism of the GPU. Consequently, we propose a heterogeneous parallel implementation of the Falcon signature scheme that utilizes the parallelism of both CPUs and GPUs, while mitigating the additional overhead introduced by heterogeneous computing. Finally, we conduct evaluations on three typical testbeds. The experimental results show that our improved GPU implementation is 222 percent faster for signing and 13.9 percent faster for verification in cloud scenarios compared to the state-of-the-art GPU implementations. On an embedded GPU platform (Jetson AGX Orin), our heterogeneous parallel implementation outperforms the CPU multi-threaded implementation by 46 percent and the GPU implementation by 297 percent. Quan Yang, Yiwen Gao 0001, Yuejun Liu, Jiabei Wang, Yongbin Zhou |
ISPA | 3 |
| 2024 | Solving ILWE Problem More Efficiently and Application to BLISS Side-Channel Attack
Yuejun Liu, Yiwen Gao 0001, Yongbin Zhou |
SecureComm (4) | 2 |
| 2024 | Towards High-Quality Electromagnetic Leakage Acquisition in Side-Channel AnalysisabstractSide-channel leakage acquisition plays a crucial role in side-channel analysis against cryptographic implementations, since it usually has a decisional impact on the security claims of the target devices. While most existing research has concentrated on power consumption acquisition settings, the exploration of electromagnetic (EM) radiation leakage acquisition remains limited and surprisingly under-discussed. In this study, we systematically investigate the parameter setting for EM leakage acquisition across two devices of different architectures. We specifically examine the effects of the amplifier, coupling mode, sampling rate, and EM probe on the quality of collected EM traces. For the first device STM32F405, our proposed optimal acquisition settings enhance the signal-to-noise ratio by a factor of 16 compared to the reference settings and reduce the number of EM traces required to achieve a success rate of 90% by a factor of 38. For the second device ATmega2560, the optimal settings improve the signal-to-noise ratio by a factor of 400 compared to the reference settings and reduce the number of EM traces required to achieve a success rate of 90% by a factor of 320. In summary, this work offers a comprehensive investigation into high-quality EM leakage acquisition. While some conclusions may be specific to certain devices, we believe that the proposed guidelines can be applied to EM trace acquisition in other devices as well. Xiaoran Huang, Yiwen Gao 0001, Wei Cheng 0003, Yuejun Liu, Jingdian Ming, Yongbin Zhou, Jian Weng 0001 |
TrustCom | 4 |
| 2024 | Enhancing Higher-Order Masking: A Faster and Secure Implementation to Mitigate Bit Interaction LeakageabstractHigher-order masking is an effective countermeasure against side-channel attacks but is often perceived as impractical due to its cost. Recent advancements in parallelization technologies have made higher-order masking more feasible. However, the security of these implementations can be jeopardized by the parallelization methods used, as their theoretical assurances may not hold in real-world scenarios. In this paper, we improve the security and efficiency of higher-order masking schemes for block ciphers through a refined bit-sliced implementation. Our method addresses lower-order leakage caused by bit interactions, which are prevalent in current schemes. We evaluated the efficiency of our approach across various widely used ARM and AVR platforms, demonstrating efficiency improvements across all test platforms. By optimizing the masking gadgets, our approach reduces the required clock cycles by 30% to 50% compared to the original implementation, across share numbers from 2 to 32 on the 32-bit ARM platform. We validate the enhanced security of our method through both theoretical analysis and practical leakage detection, proving its effectiveness against bit interaction leakage. Yuejun Liu, Jingdian Ming, Yiwen Gao 0001, Yongbin Zhou, Debao Wang |
TrustCom | 2 |
| 2024 | New partial key exposure attacks on RSA with additive exponent blindingabstractAbstract Partial key exposure attacks present a significant threat to RSA-type cryptosystems. These attacks factorize the RSA modulus by utilizing partial knowledge of the decryption exponent, which is typically revealed by side-channel attacks, cold boot attacks, etc. In practice, the RSA implementations typically employ countermeasures to resist physical attacks, such as additive exponent blinding $$d' = d + r \varphi (N)$$ d ′ = d + r φ ( N ) with unknown random blinding factor r. Although there are a couple of partial key exposure attacks on blinding RSA, these attacks require a considerable amount of leakage and fail to work when e is up to full size. In this paper, we propose new partial key exposure attacks on RSA with additive exponent blinding, focusing on leakage scenarios where the Most Significant Bits (MSBs) or Least Significant Bits (LSBs) of $$d'$$ d ′ are revealed. For the case where e is small, we first recover partial information of p by solving the quadratic congruence equation, and then find the small roots of the integer equation to recover entire private key. Our method relaxes the attack requirements, for instance, we reduce the amount of MSBs for a successful attack from 75 to 25% when $$e \approx N^{0.25}$$ e ≈ N 0.25 and $$r\approx N^{0}$$ r ≈ N 0 . Furthermore, we propose new attacks using the unique algebraic relationship in blinding RSA, which extend the attack to the case where e is of full size. Ziming Jiang, Yongbin Zhou, Yuejun Liu |
Cybersecur. | 3 |
| 2024 | In-depth Correlation Power Analysis Attacks on a Hardware Implementation of CRYSTALS-DilithiumabstractAbstract During the standardisation process of post-quantum cryptography, NIST encourages research on side-channel analysis for candidate schemes. As the recommended lattice signature scheme, CRYSTALS-Dilithium, when implemented on hardware, has seen limited research on side-channel analysis, and current attacks are incomplete or requires a substantial quantity of traces. Therefore, we conducted a more complete analysis to investigate the leakage of an FPGA implementation of CRYSTALS-Dilithium using the Correlation Power Analysis (CPA) method, where with a minimum of 70,000 traces partial private key coefficients can be recovered. Furthermore, we optimise the attack by extracting Point-of-Interests using known information due to parallelism (named CPA-PoI) and by iteratively utilising parallel leakages (named CPA-ITR). Our experimental results show that CPA-PoI reduces the number of traces by up to 16.67%, CPA-ITR by up to 25%, and both increase the number of recovered key coefficients by up to 55.17% and 93.10% using the same number of traces. They outperfom the CPA method. As a result, it suggests that the FPGA implementation of CRYSTALS-Dilithium is more vulnerable than thought before to side-channel analysis. Huaxin Wang, Yiwen Gao 0001, Yuejun Liu, Qian Zhang 0042, Yongbin Zhou |
Cybersecur. | 3 |
| 2024 | Partial key exposure attacks on Prime Power RSA with non-consecutive blocks
Ziming Jiang, Yongbin Zhou, Yuejun Liu |
Theor. Comput. Sci. | 3 |
| 2023 | Recovering Multi-prime RSA Keys with Erasures and Errors
Yuejun Liu, Yongbin Zhou, Yiwen Gao 0001 |
ISPEC | 2 |
| 2023 | CKDAN: Content and keystroke dual attention networks with pre-trained models for continuous authentication
Haitian Yang, Xuan Zhao 0011, Yan Wang 0081, Yuejun Liu, Xiaoyu Kang, Jiahui Shen, Weiqing Huang |
Comput. Secur. | 5 |
| 2023 | Practical Public Template Attack Attacks on CRYSTALS-Dilithium With Randomness LeakagesabstractSide-channel security has become a significant concern in the NIST post-quantum cryptography standardization process. The lattice-based CRYSTALS-Dilithium (abbr. Dilithium) becomes the primary signature standard algorithm recommended by NIST for most use cases in July 2022 due to its excellent performance in security and efficiency. Compared to Dilithium’s rich theoretical security analysis results, the side-channel security of its physical implementations needs to be further explored. In 2021, Liu et al. proposed a two-stage randomness leakage attack against Dilithium, in which only one randomness bit with a probability$> 0.5$per signature is enough to recover the private key. However, they only carried out proof-of-concept experiments on “research-oriented” reference implementation of polynomial addition. Whether this method applies to complete real-world implementations of Dilithium is unknown. In this paper, we put this randomness leakage attack into real-world and recover the private key of unprotected and masked Dilithium on Arm Cortex-M4 processor using non-profiled power analysis attacks. Since randomness is introduced in the signing process, it is challenging to recover the randomness bit of Dilithium with high success rate in only one trace. Inspired by Liu et al., we propose a new non-profiled attack called Public Template Attack (PTA), a template-attack-like method that builds templates using public information. With PTA, we recover the randomness bit of unprotected and masked Dilithium with a success rate of 95% and 62% in one power trace, respectively. To demonstrate practicality, we perform practical power analysis attacks against different security levels of round 3 unprotected and masked Dilithium on STM32F405 microprocessor. Using 10,000 traces, the private key of unprotected Dilithium2 is recovered in 0.5 hours with an ordinary PC desktop. Our attack is 240 times faster than the state-of-the-art non-profiled attack. Moreover, the private key of masked Dilithium2 is recovered using 680,000 traces in 38 hours. To the best of our knowledge, we are the first to successfully attack masked Dilithium using non-profiled attacks. Zehua Qiao, Yuejun Liu, Yongbin Zhou, Jingdian Ming, Chengbin Jin, Huizhong Li |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | (Full) Leakage resilience of Fiat-Shamir signatures over lattices
Yuejun Liu, Yongbin Zhou, Rui Zhang 0002, Yang Tao 0001 |
Frontiers Comput. Sci. | 1 |
| 2021 | Integer LWE with Non-subgaussian Error and Related Attacks
Tianyu Wang 0021, Yuejun Liu, Jun Xu 0022, Lei Hu 0003, Yang Tao 0001, Yongbin Zhou |
ISC | 2 |
| 2021 | On the Security of Lattice-Based Fiat-Shamir Signatures in the Presence of Randomness LeakageabstractLeakages during the signing process, including partial key exposure and partial (or complete) randomness exposure, may be devastating for the security of digital signatures. In this work, we investigate the security of lattice-based Fiat-Shamir signatures in the presence of randomness leakage. To this end, we present a generic key recovery attack that relies on minimum leakage of randomness, and then theoretically connect it to a variant of Integer-LWE (ILWE) problem. The ILWE problem, introduced by Bootle et al. at Asiacrypt 2018, is to recover the secret vector s given polynomially many samples of the form (a, 〈a〉, s)+e) ϵ ℤn+1, and it is solvable if the error e ϵ ℤ is not superpolynomially larger than the inner product (a, s). However, in our variant (we call the variant FS-ILWE problem in this paper), a ϵ ℤnis a sparse vector whose coefficients are NOT independent any more, and e is related to a and s as well. We prove that the FS-ILWE problem can be solved in polynomial time, and present an efficient algorithm to solve it. Our generic key recovery method directly implies that many lattice-based Fiat-Shamir signatures will be totally broken with one (deterministic or probabilistic) bit of randomness leakage per signature. Our attack has been validated by experiments on two NIST PQC signatures Dilithium and qTESLA. For example, as to Dilithium-III of 125-bit quantum security, the secret key will be recovered within 10 seconds over an ordinary PC desktop, with about one million signatures. Similarly, key recovery attacks on Dilithium under other parameters and qTESLA will be completed within 20 seconds and 31 minutes respectively. In addition, we also present a non-profiled attack to show how to obtain the required randomness bit in practice through power analysis attacks on a proof-of-concept implementation of polynomial addition. The experimental results confirm the practical feasibility of our method. Yuejun Liu, Yongbin Zhou, Tianyu Wang 0021, Rui Zhang 0002, Jingdian Ming |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | Fully Secure ABE with Outsourced Decryption against Chosen Ciphertext Attack
Ti Wang, Yongbin Zhou, Hui Ma 0002, Yuejun Liu, Rui Zhang 0002 |
Inscrypt | 4 |
| 2019 | Predicate encryption against master-key tampering attacksabstractMany real world attacks often target the implementation of a cryptographic scheme, rather than the algorithm itself, and a system designer has to consider new models that can capture these attacks. For example, if the key can be tampered by physical attacks on the device, the security of the scheme becomes totally unclear. In this work, we investigate predicate encryption (PE), a powerful encryption primitive, in the setting of tampering attacks. First, we show that many existing frameworks to construct PE are vulnerable to tampering attacks. Then we present a new security notion to capture such attacks. Finally, we take Attrapadung’s framework in Eurocrypt’14 as an example to show how to “compile" these frameworks to tampering resilient ones. Moreover, our method is compatible with the original pair encoding schemes without introducing any redundancy. Yuejun Liu, Rui Zhang 0002, Yongbin Zhou |
Cybersecur. | 1 |