VLDB 2026 Research / reviewers in the wild / expert
Chi Zhang 0061
dblp:91/195-61
· DBLP profile ↗
14ranked-venue papers
2as first author
11since 2021 · last 2026
0000-0003-3887-2878ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 7 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 2 since 2021Systems, architecture and hardware · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Teamwork Makes TEE Work: Open and Resilient Remote Attestation on Decentralized TrustabstractRemote Attestation (RA) enables the integrity and authenticity of applications in Trusted Execution Environment (TEE) to be verified. Existing TEE RA designs employ a centralized trust model where they rely on a single provisioned secret key and a centralized verifier to establish trust for remote parties. This model is however brittle and can be untrusted under advanced attacks nowadays. Besides, most designs only have fixed procedures once deployed, making them hard to adapt to different emerging situations and provide resilient functionalities. Therefore, we proposeJanus, an open and resilient TEE RA scheme. To decentralize trust, we, on one hand, introduce Physically Unclonable Function (PUF) as an intrinsic root of trust (RoT) in TEE to directly provide physical trusted measurements. On the other hand, we design novel decentralized verification functions on smart contract with result audits and RA session snapshot. Furthermore, we design an automated switch mechanism that allowsJanusto remain resilient and offer flexible RA services under various situations. We provide a UC-based security proof and demonstrate the scalability and generality ofJanusby implementing an complete prototype. Kailun Qin, Shipei Qu, Chi Zhang 0061, Dawu Gu |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | End-to-End Non-profiled Side-Channel Analysis on Long Raw Traces
Jintong Yu, Shipei Qu, Yipeng Shi, Pei Cao 0002, Xiangjun Lu, Chi Zhang 0061, Dawu Gu |
ESORICS (3) | 8 |
| 2025 | Secure and Scalable TLB Partitioning Against Timing Side-Channel Attacks
Tianyi Huang, Kailun Qin, Boshi Yuan 0002, Chenghao Chen, Yipeng Shi, Chi Zhang 0061, Dawu Gu |
ICICS (3) | 7 |
| 2025 | Find the Clasp of the Chain: Efficiently Locating Cryptographic Procedures in SoC Secure Boot by Semi-automated Side-Channel Analysis
Shipei Qu, Jintong Yu, Chi Zhang 0061, Dawu Gu |
ICICS (3) | 5 |
| 2025 | Building Provably Secure Pseudo-Strong PUFs via Weak PUFs and Pseudorandom Functions for Cryptographic ProtocolsabstractPhysical Unclonable Functions (PUFs) are widely used in hardware security due to their inherent unclonability and randomness. However, the temporal instability of strong PUFs remains a barrier to their adoption in latest PUF-based cryptographic protocols, as it incurs significant overhead from error correction. In this paper, we propose PS-PUF, a novel architecture that leverages weak PUFs and cryptographically secure pseudorandom functions (PRFs) to construct a pseudo-strong PUF with stable and reproducible outputs. Our design includes a PRF for secure mapping, and a buffer to optimize performance in batch-access scenarios. We formally analyze the threat surface of PS-PUF and provide cryptographic security proofs showing resistance against modeling attacks. Implemented on the Genesys 2 FPGA, PS-PUF achieves at least 2.72× in batch scenarios with negligible hardware overhead and a maximum performance reduction of 10.7%, enabled by reusing the PRF module in integrated environments. Chenghao Chen, Kailun Qin, Yipeng Shi, Tianyi Huang, Chi Zhang 0061, Dawu Gu |
TrustCom | 7 |
| 2025 | Mind the Faulty Keccak: A Practical Fault Injection Attack Scheme Applied to All Phases of ML-KEM and ML-DSA
Jintong Yu, Shipei Qu, Chi Zhang 0061, Dawu Gu |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | Trapped by Your WORDs: (Ab)using Processor Exception for Generic Binary Instrumentation on Bare-metal Embedded DevicesabstractAnalyzing the security of closed-source drivers and libraries in embedded systems holds significant importance, given their fundamental role in the supply chain. Unlike x86, embedded platforms lack comprehensive binary manipulating tools, making it difficult for researchers and developers to effectively detect and patch security issues in such closed-source components. Existing works either depend on full-fledged operating system features or suffer from tedious corner cases, restricting their application to bare-metal firmware prevalent in embedded environments. Shipei Qu, Chi Zhang 0061, Dawu Gu |
DAC | 3 |
| 2023 | A nonprofiled side-channel analysis based on variational lower bound related to mutual information
Chi Zhang 0061, Xiangjun Lu, Pei Cao 0002, Dawu Gu, Zheng Guo 0001 |
Sci. China Inf. Sci. | 1 |
| 2023 | Side-Channel Analysis for the Re-Keying Protocol of Bluetooth Low Energy
Pei Cao 0002, Chi Zhang 0061, Xiangjun Lu, Haining Lu, Dawu Gu |
J. Comput. Sci. Technol. | 2 |
| 2022 | Improving Deep Learning Based Second-Order Side-Channel Analysis With Bilinear CNNabstractIn recent years, deep learning techniques have received significant attention in the side-channel community due to their state-of-the-art performance in profiled attacks against embedded devices. Compared with template attacks, deep learning-based attacks can deal with the high dimensionality of trace and misalignment without pre-processing. However, the performance of attacks is very sensitive to the network architecture, especially when considering masking countermeasures. Although previous works have shown the potential of neural networks to break the first-order masking, the inner-working of how the network combines the leakage of mask and masked value is still unclear and could be suboptimal. To reduce this gap, we propose to embed product combination, which has been proved to be the best combination function in noisy situations, into the design of neural networks. To this end, we introduce a bilinear convolutional neural network (in short, B-CNN) for efficient profiled attacks against the widely used masking countermeasure. In order to interpret the inner-working and decision-making of B-CNN, we propose a new visualization tool called layer-wise correlation that can reveal the points of interest and help to understand the combination of leakages. We evaluate our networks on several public datasets, e.g., ASCAD and CHES CTF 2018. The results indicate that B-CNN converges significantly faster than classic CNN models, even using a very limited number of profiling traces (e.g., 8000 profiling traces for the ASCAD dataset). Moreover, our networks perform even systematically better (w.r.t. the number of attack traces) than the current state-of-the-art results on all the investigated datasets. Pei Cao 0002, Chi Zhang 0061, Xiangjun Lu, Dawu Gu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | Efficient Implementation of Dilithium Signature Scheme on FPGA SoC PlatformabstractIn the process of NIST postquantum cryptography standardization, module lattice-based Dilithium has been chosen as one of the three third-round finalists for digital signature schemes. More evaluations of its implementation efficiency on different platforms are required for further competition. In this article, we present an efficient implementation of Dilithium on a field-programmable gate array (FPGA) system-on-chip (SoC) platform. To achieve a high computation speed, we design a hardware architecture to perform the main body of the algorithm, and the preprocessing and postprocessing steps are accomplished by the processor. For the hardware architecture, we take some optimizations on the most time-consuming operations, that is, polynomial multiplication, hashing, and sampling. Polynomial multiplications are accelerated by the radix-4 number theoretic transform (NTT) architecture with a conflict-free memory mapping scheme. A fast modular multiplication on the Dilithium modulus is proposed to support the underlying calculations. For hashing and sampling, we design a multipurpose hashing unit and a compact sampling unit. The cooperative work of the two units accelerates the sampling process significantly. We implement the Key Generation, Signing, and Verification algorithms of the round-3 Dilithium at all three security levels on the Xilinx Zynq-7000 platform. Compared with existing software/hardware codesign for Dilithium on a similar platform, our design achieves about$17\times $and$40\times $improvements in performance for the Signing and Verification algorithms, respectively, at the cost of about$7.8\times $more look up table (LUT) resources. Chi Zhang 0061, Pei Cao 0002, Dawu Gu |
IEEE Trans. Very Large Scale Integr. Syst. | 2 |
| 2020 | Evaluating and Improving Linear Regression Based Profiling: On the Selection of Its Regularization
Xiangjun Lu, Chi Zhang 0061, Dawu Gu, Haifeng Zhang 0010 |
J. Comput. Sci. Technol. | 2 |
| 2019 | Side-Channel Analysis for the Authentication Protocols of CDMA Cellular Networks
Chi Zhang 0061, Dawu Gu, Weijia Wang 0003, Xiangjun Lu, Zheng Guo 0001, Haining Lu |
J. Comput. Sci. Technol. | 1 |
| 2017 | Ridge-Based Profiled Differential Power Analysis
Weijia Wang 0003, Yu Yu 0001, François-Xavier Standaert, Dawu Gu, Chi Zhang 0061 |
CT-RSA | 6 |