Derek Abbott

dblp:a/DerekAbbott · DBLP profile ↗
← Back
46ranked-venue papers
3as first author
16since 2021 · last 2026
0000-0002-0945-2674ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 14 · 3 first-author · 2 since 2021Artificial intelligence and machine learning · 10 · 3 since 2021Systems, architecture and hardware · 9 · 3 since 2021Security and privacy · 8 · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3Computer networks · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 MUXLeak: Exploiting Multiplexers as a Power Side Channel Against Multitenant FPGAs
abstract
FPGA cloud acceleration, or “FPGA as a Service” (FaaS), offered by AWS, Microsoft Azure, Alibaba Cloud, and Huawei Cloud, has become a promising solution for tackling complex, compute-intensive workloads. It targets applications such as genomics, image and video processing, electronic design automation, compression, and big data analytics. While multi-tenant FPGAs significantly enhances resource utilization efficiency, it faces security threats from power side channels, where attackers craft a malicious circuit to detect voltage fluctuations from victim circuits. Observing that all the crafted circuits exploit either Carry Chain or Look-up Table to sense voltage fluctuations, existing defenses have focused on detecting the malicious use of the two basic FPGA computing resources. However, it remains unclear whether such countermeasures are sufficient to address the growing threat of power side channels in multi-tenant FPGAs. In this paper, we reveal MUXLeak, a novel on-chip sensor that exploitsMultiplexer (MUX)to craft a stealthy power side channel, which bypasses existing countermeasures. Particularly, we perform a thorough analysis of basic resources within an FPGA unit and unveil thatMUX, another basic resource,has never been exploited before. More importantly, it can be directly initialized on Xilinx FPGAs and its incurred signal propagation delay demonstrates an inverse correlation with changes in voltage, making itself exploitable for a new power side channel leakage. In our evaluation, we test MUXLeak on three Xilinx FPGA products and use TDC [18] (i.e., the most sensitive on-chip sensor until now) to benchmark the sensitivity of MUXLeak. Our results show that MUXLeak has achieved the same level of sensitivity as TDC to voltage fluctuations. Further, we apply MUXLeak to mount two attacks, i.e., extracting AES keys within 2.54 hours and stealing DNN model architectures with an accuracy of over 90%.
Xin Zhang 0110, Zhi Zhang 0001, Qingni Shen, Yansong Gao 0001, Jinhua Cui 0002, Yusi Feng, Zhonghai Wu, Derek Abbott
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.9
2025 Try to Poison My Deep Learning Data? Nowhere to Hide Your Trajectory Spectrum!
Yansong Gao 0001, Huaibing Peng, Zhi Zhang 0001, Shuo Wang 0012, Rayne Holland, Anmin Fu, Minhui Xue 0001, Derek Abbott
NDSS9
2025 Just a little human intelligence feedback! Unsupervised learning assisted supervised learning data poisoning based backdoor removal
Huaibing Peng, Anmin Fu, Wei Yang 0008, Lihui Pang, Said F. Al-Sarawi, Derek Abbott, Yansong Gao 0001
Comput. Commun.7
2024 Watch Out! Simple Horizontal Class Backdoor Can Trivially Evade Defense
abstract
All current backdoor attacks on deep learning (DL) models fall under the category of a vertical class backdoor (VCB).In VCB attacks, any sample from a class activates the implanted backdoor when the secret trigger is present, regardless of whether it is a sub-type source-class-agnostic backdoor or a source-class-specific backdoor. For example, a trigger of sunglasses could mislead a facial recognition model when either an arbitrary (source-class-agnostic) or a specific (source-class-specific) person wears sunglasses. Existing defense strategiesoverwhelmingly focus on countering VCB attacks, especially those that are source-class-agnostic. This narrow focus neglects the potential threat of other simpler yet general backdoor types, leading to false security implications. It is, therefore, crucial to discover and elucidate unknown backdoor types, particularly those that can be easily implemented, as a mandatory step before developing countermeasures.
Shang Wang 0004, Yansong Gao 0001, Zhi Zhang 0001, Huming Qiu, Minhui Xue 0001, Alsharif Abuadbba, Anmin Fu, Surya Nepal, Derek Abbott
CCS10
2024 Towards robustness evaluation of backdoor defense on quantized deep learning models
abstract
Backdoor attacks on deep learning (DL) models emerge as the most worrisome security threats to their secure and safe usage, especially for security-sensitive tasks. Great efforts have been devoted to thwarting backdoor attacks by devising detection or prevention countermeasures. By default, these countermeasures are designed and evaluated on models with full-precision parameters (e.g., floating32). It is unclear whether they are immediately applicable to mitigate backdoor attacks in the quantized model that are being pervasively deployed on mobile devices and Internet of Things (IoT) devices to save resources (i.e. power and memory) and reduce latency and privacy risks. This work, for the first time, initializes the critical examination of the robustness or applicability of existing state-of-the-art (SOTA) DL backdoor defenses for detecting or preventing backdoor attacks on quantized models. Based on extensive evaluations of four representative defenses (Neural Cleanse, ABS, Fine-Pruning and Trojan Signature) with three datasets (CIFAR10, GTSRB, and STL10), we found that only Neural Cleanse's defensive robustness is generally independent of model quantization, while all others exhibit degraded effectiveness or failures against quantized models (in particular, widely used int-8 and 1-bit models), especially when the model is quantized to be 1-bit. The identified main failure reason is that these defenses are based on examining the weight values of the model or the activation values of the neuron to identify or prevent the backdoor, often using the ranking as a step. Quantization with a small bit width leads to less fine-grained discrete values (e.g., 1-bit quantization only possesses two value elements of -1 and +1), rendering ranking effectiveness deteriorate in this case. Note that the quantization not only applies to the weight but also to activation, thus making these defenses less robust or trivially fail. This work highlights the demand for devising backdoor defenses that are generic to different quantization formats on top of the default full-precision model.
Huaibing Peng, Anmin Fu, Wei Yang 0008, Said F. Al-Sarawi, Derek Abbott, Yansong Gao 0001
Expert Syst. Appl.7
2024 One-to-Multiple Clean-Label Image Camouflage (OmClic) based backdoor attack on deep learning
Guohong Wang, Yansong Gao 0001, Alsharif Abuadbba, Zhi Zhang 0001, Wei Kang 0004, Said F. Al-Sarawi, Gongxuan Zhang, Derek Abbott
Knowl. Based Syst.9
2024 Quantization Backdoors to Deep Learning Commercial Frameworks
abstract
Due to their low latency and high privacy preservation, there is currently a burgeoning demand for deploying deep learning (DL) models on ubiquitous edge Internet of Things (IoT) devices. However, DL models are often large in size and require large-scale computation, which prevents them from being placed directly onto IoT devices, where resources are constrained, and 32-bit floating-point (float-32) operations are unavailable. Commercial framework (i.e., a set of toolkits) empowered model quantization is a pragmatic solution that enables DL deployment on mobile devices and embedded systems by effortlessly post-quantizing a large high-precision model (e.g., float-32) into a small low-precision model (e.g., int-8) while retaining the model inference accuracy. However, their usability might be threatened by security vulnerabilities. This work reveals that standard quantization toolkits can be abused to activate a backdoor. We demonstrate that a full-precision backdoored model which does not have any backdoor effect in the presence of a trigger—as the backdoor is dormant—can be activated by (i) TensorFlow-Lite (TFLite) quantization, the onlyproduct-readyquantization framework to date, and (ii) thebeta releasedPyTorch Mobile framework. In our experiments, we employ three popular model architectures (VGG16, ResNet18, and ResNet50), and train each across three popular datasets: MNIST, CIFAR10 and GTSRB. We ascertain that all trained float-32 backdoored models exhibit no backdoor effecteven in the presence of trigger inputs. Particularly, four influential backdoor defenses are evaluated, and they fail to identify a backdoor in the float-32 models. When each of the float-32 models is converted into an int-8 format model through the standard TFLite or PyTorch Mobile framework's post-training quantization, the backdoor is activated in the quantized model, which shows a stable attack success rate close to 100% upon inputs with the trigger, while it usually behaves upon non-trigger inputs. This work highlights that a stealthy security threat occurs when an end-user utilizes the on-device post-training model quantization frameworks, informing security researchers of a cross-platform overhaul of DL models post-quantization even if these models pass security-aware front-end backdoor inspections. Significantly, we have identified Gaussian noise injection into the malicious full-precision model as an easy-to-use preventative defense against the PQ backdoor. The attack source code is released athttps://github.com/quantization-backdoor.
Huming Qiu, Yansong Gao 0001, Zhi Zhang 0001, Alsharif Abuadbba, Minhui Xue 0001, Anmin Fu, Jiliang Zhang 0002, Said F. Al-Sarawi, Derek Abbott
IEEE Trans. Dependable Secur. Comput.10
2024 NTD: Non-Transferability Enabled Deep Learning Backdoor Detection
abstract
To mitigate recent insidious backdoor attacks on deep learning models, advances have been made by the research community. Nonetheless, state-of-the-art defenses are either limited to specific backdoor attacks (i.e., source-agnostic attacks) or non-user-friendly in that machine learning expertise and/or expensive computing resources are required. This work observes that all existing backdoor attacks have an inadvertent and inevitable intrinsic weakness, termed as non-transferability —that is, a trigger input hijacks a backdoored model but is not effective in another model that has not been implanted with the same backdoor. With this key observation, we propose non-transferability enabled backdoor detection to identify trigger inputs for a model-under-test during run-time. Specifically, our detection allows a potentially backdoored model-under-test to predict a label for an input. Moreover, our detection leverages a feature extractor to extract feature vectors for the input and a group of samples randomly picked from its predicted class label, and then compares the similarity between the input and the samples in the feature extractor’s latent space to determine whether the input is a trigger input or a benign one. The feature extractor can be provided by a reputable party or is a free pre-trained model privately reserved from any open platform (e.g., ModelZoo, GitHub, Kaggle) by a user and thus our detection does not require the user to have any machine learning expertise or perform costly computations. Extensive experimental evaluations on four common tasks affirm that our detection scheme has high effectiveness (low false acceptance rate) and usability (low false rejection rate) with low detection latency against different types of backdoor attacks.
Yinshan Li, Zhi Zhang 0001, Yansong Gao 0001, Alsharif Abuadbba, Minhui Xue 0001, Anmin Fu, Yifeng Zheng 0001, Said F. Al-Sarawi, Derek Abbott
IEEE Trans. Inf. Forensics Secur.10
2024 On Model Outsourcing Adaptive Attacks to Deep Learning Backdoor Defenses
abstract
Deep learning models with backdoors act maliciously when triggered but seem normal otherwise. This risk, often increased by model outsourcing, challenges their secure use. Although countermeasures exist, their defense against adaptive attacks is under-examined, possibly leading to security misjudgments. This study is the first intricate examination illustrating the difficulty of detecting backdoors in outsourced models, especially when attackers adjust their strategies, even if their capabilities are significantly limited. It is relatively straightforward for attackers to circumvent detection by trivially violating its threat model (e.g., using advanced backdoor types or trigger designs not covered by the detection). However, this research highlights that various leading detection defenses can simultaneously be evaded using simple adaptive strategies, even under their defined threat models and with limited adversary capabilities (e.g., using easily detectable triggers while maintaining a high attack success rate). To be more specific, this study introduces a novel methodology that employs trigger specificity enhancement and training regulation in a symbiotic manner. This approach allows us to evade multiple backdoor detection defenses simultaneously, including Neural Cleanse (Oakland 19’), ABS (CCS 19’), and MNTD (Oakland 21’). These were the detection tools selected for the Evasive Trojans Track of the 2022 NeurIPS Trojan Detection Challenge. Even when applied in conjunction with these defenses under stringent conditions, such as a high attack success rate (> 97%) and the restricted use of the simplest trigger (small white square), our straightforward method garnered the second prize in NeurIPS Trojan Detection Challenge. Notably, for the first time, our adaptive attack successfully evaded other recent state-of-the-art defenses, including FeatureRE (NeurIPS 22’) and Beatrix (NDSS 23’). This study suggests that existing model outsourcing backdoor defenses remain vulnerable to adaptive attacks, and thus, the use of third-party models should be avoided whenever possible.
Huaibing Peng, Huming Qiu, Shuo Wang 0012, Anmin Fu, Said F. Al-Sarawi, Derek Abbott, Yansong Gao 0001
IEEE Trans. Inf. Forensics Secur.7
2023 TransCAB: Transferable Clean-Annotation Backdoor to Object Detection with Natural Trigger in Real-World
abstract
Object detection is the foundation of various critical computer-vision tasks such as segmentation, object tracking, and event detection, which can be deployed on pervasive Internet of Things (IoT) and edge devices. A large amount of data is often required to train an object detector with satisfactory accuracy. However, due to the intensive workforce involved with collecting and annotating large datasets, data curation task is often outsourced to a third party (e.g., Amazon Mechanical Turk) or volunteers. This work reveals severe vulnerabilities in this data curation pipeline. We propose TransCAB, the first work to craft clean-annotated images to stealthily implant the backdoor into the object detectors later trained on them by the data curator/user even when the data curator can manually audit the images and fully controls the training process. Existing clean-label poisoned images are only shown in classification tasks but not non-classification tasks, in particular, object detection due to unique challenges faced, generally owing to the complexity of having multiple objects within each frame (image), including the victim and non-victim objects. Furthermore, we demonstrate that the backdoor effect of both cloaking and misclassification are robustly achieved in the wild when the backdoor is activated with inconspicuously natural physical object as trigger (i.e., T-shirt). The efficacy of our TransCAB is ensured by constructively i) applying the image-camouflage attack that abuses the image-scaling function widely used by the deep learning framework (i.e., PyTorch), ii) incorporating the devised clean image replica technique, and iii) combining identified poison data selection criteria given constrained attacking budget. Extensive experi-ments on YOLOv3, YOLOv4, CenterNet, and Faster R-CNN affirm that TransCAB exhibits more than 90% attack success rate under various real-world scenes even when a very small (i.e., 0.14%) dataset fraction is poisoned. In addition, the small set of poisoned images crafted on one detector (i.e., YOLOv3) can be effectively transferred to insert a backdoor on another detector (i.e., CenterNet). A comprehensive video demo is at https://youtu.be/MA7L_LpXkp4, where a poison rate of merely 0.14% is set for YOLOv4 cloaking backdoor and Faster R-CNN misclassification backdoor. Our collected dataset with T-shirt as a natural trigger (about 11,350 frames in total) is open to the public at https://github.com/inconstance/T-shirt-natural-backdoor-dataset, which is the first relatively large-scale natural trigger backdoor dataset.
Yinshan Li, Yansong Gao 0001, Zhi Zhang 0001, Alsharif Abuadbba, Anmin Fu, Said F. Al-Sarawi, Surya Nepal, Derek Abbott
SRDS9
2023 MUD-PQFed: Towards Malicious User Detection on model corruption in Privacy-preserving Quantized Federated learning
Qun Li 0005, Yifeng Zheng 0001, Zhi Zhang 0001, Xiaoning Liu 0002, Yansong Gao 0001, Said F. Al-Sarawi, Derek Abbott
Comput. Secur.8
2023 MLMSA: Multilabel Multiside-Channel-Information Enabled Deep Learning Attacks on APUF Variants
abstract
To improve the modeling resilience of silicon strong physical unclonable functions (PUFs), in particular, the APUFs that yield a very large number of challenge-response pairs (CRPs), a number of composited APUF variants, such as XOR-APUF, interpose-PUF (iPUF), feed-forward APUF (FF-APUF), and OAX-APUF, have been devised. When examining their security in terms of modeling resilience, utilizing multiple information sources, such as power side channel information (SCI) or/and reliability SCI, given a challenge is under-explored, which poses a challenge to their supposed modeling resilience in practice. Building upon multilabel/head deep learning (DL) model architecture, this work proposes multilabel multiside-channel-information-enabled DL attacks (MLMSAs) to thoroughly evaluate the modeling resilience of aforementioned APUF variants. Despite its simplicity, MLMSA can successfully break large-scaled APUF variants, which has not previously been achieved. More precisely, the MLMSA breaks 128-stage 30-XOR-APUF, (9, 9)- and (2, 18)-iPUFs, and$(2,2,30)$-OAX-APUF when CRPs, power SCI, and reliability SCI are concurrently used. It breaks 128-stage 12-XOR-APUF and$(2,2,9)$-OAX-APUF even when only the easy-to-obtain reliability SCI and CRPs are exploited. The 128-stage six-loop FF-APUF and one-loop 20-XOR-FF-APUF can be broken by simultaneously using reliability SCI and CRPs. All these attacks are normally completed within an hour with a standard personal computer. Therefore, MLMSA is a useful technique for evaluating other existing or any emerging strong PUF designs.
Yansong Gao 0001, Jianrong Yao, Lihui Pang, Wei Yang 0008, Anmin Fu, Said F. Al-Sarawi, Derek Abbott
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.7
2023 RBNN: Memory-Efficient Reconfigurable Deep Binary Neural Network With IP Protection for Internet of Things
abstract
Currently, a high demand for on-device deep neural network (DNN) model deployment is limited by the large model size, computing-intensive floating-point operations (FLOPS), and intellectual property (IP) infringements (i.e., easy access to model duplication for the avoidance of license payments). One appealing solution to addressing the first two concerns is model quantization, which reduces the model size and uses integer operations commonly supported by microcontrollers (MCUs usually do not support FLOPS). To this end, a 1-bit quantized DNN model or deep binary neural network (BNN) significantly improves the memory efficiency, where each parameter in a BNN model has only 1 bit. However, BNN cannot directly provide IP protection (in particular, the functionality of the model is locked unless there is a license payment). In this article, we propose a reconfigurable BNN (RBNN) to further amplify the memory efficiency for resource-constrained Internet of Things (IoT) devices while naturally protecting the model IP. Generally, RBNN can be reconfigured on demand to achieve any one of$M$($M>1$) distinct tasks with the same parameter set, thus only a single task determines the memory requirements. In other words, the memory utilization is improved by a factor of$M$. Our extensive experiments corroborate that up to seven commonly used tasks ($M=7$, six of these tasks are image related and the last one is audio) can co-exist (the value of$M$can be larger). These tasks with a varying number of classes have no or negligible accuracy drop-off (i.e., within 1%) on three binarized popular DNN architectures, including VGG, ResNet, and ReActNet. The tasks span across different domains, e.g., computer vision and audio domains validated herein, with the prerequisite that the model architecture can serve those cross-domain tasks. To fulfill the IP protection of an RBNN model, the reconfiguration can be controlled by both a user key and a device-unique root key generated by the intrinsic hardware fingerprint (e.g., SRAM memory power-up pattern). By doing so, an RBNN model can only be used per paid user per authorized device, thus benefiting both the user and the model provider. The source code is released athttps://github.com/LearningMaker/RBNN.
Huming Qiu, Zhi Zhang 0001, Yansong Gao 0001, Yifeng Zheng 0001, Anmin Fu, Pan Zhou 0001, Derek Abbott, Said F. Al-Sarawi
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.8
2022 Role of astrocytes in the self-repairing characteristics of analog neural networks
Negin Veisi, Gholamreza Karimi, Mahnaz Ranjbar, Derek Abbott
Neurocomputing4
2021 Improved Subaperture Based Aperture-Dependent Motion Compensation Based on Adaptive Blocking and Apodization
abstract
Subaperture Topography and Aperture (SATA) dependent azimuthal motion compensation (MOCO) can yield satisfactory target focusing at slow to moderate track deviations. However, at faster track deviations, the algorithm has to make a trade-off between handling higher motion error frequency and finer instantaneous squint angles. Subaperture selection plays a crucial role in the overall performance of SATA. This paper proposes two techniques based on adaptive blocking and complex dual apodization (CDA) to improve the performance of SATA in the presence of high frequency motion error. The techniques are verified both using simulated and real L-band datasets. A significant improvement in the overall focusing quality of far range targets is achieved using the adaptive technique. The apodization based scheme can improve both the resolution and sidelobe levels that are otherwise traded-off in a fixed block length SATA.
Rifat Afroz, Rolf Scheiber, Brian Wai-Him Ng, Derek Abbott
IGARSS4
2021 Wide Bandgap DC-DC Converter Topologies for Power Applications
abstract
Over the last decade, dc-dc power converters have attracted significant attention due to their increased use in a number of applications from aerospace to renewable energy. The interest in wide bandgap (WBG) power semiconductor devices stems from outstanding features of WBG materials, power device operation at higher temperatures, larger breakdown voltages, and the ability to sustain larger switching transients than silicon (Si) devices. As a result, recent progress and development of converter topologies, based on WBG power devices, are well-established for power conversion applications in which classical Si-based power devices show limited operation. Currently, Si carbide (SiC) and gallium nitride (GaN) are the most promising semiconductor materials that are being considered for the new generation of power devices. The use of new power semiconductor devices, such as GaN high electron mobility transistors (GaN HEMTs), leads to minimization of switching losses, allowing high switching frequencies (from kHz to MHz) for realizing compact power converters. Finally, design recommendations and future research trends are also presented.
Mohammad Parvez, Aaron T. Pereira, Nesimi Ertugrul, Neil E. Weste, Derek Abbott, Said F. Al-Sarawi
Proc. IEEE5
2020 Deep learning-based cardiovascular image diagnosis: A promising challenge
Kelvin K. L. Wong, Giancarlo Fortino, Derek Abbott
Future Gener. Comput. Syst.3
2020 Composing recipes based on nutrients in food in a machine learning context
Zhenfeng Lei, Anwar Ul Haq 0003, Mohsen Dorraki, Derek Abbott
Neurocomputing5
2020 DC is the Future [Point of View]
abstract
For ac electricity grids, the aim has always been at low-cost and disruption-proof solutions. The power grid is inherently vulnerable to environmental disturbances. However, the introduction of power electronics (PEs) and changes in load and generator characteristics have introduced a game changer at an unprecedented pace over the last decade. During this change, load specifications, load characteristics, and control and monitoring requirements for power system security have also dramatically evolved. Efficiency and reliability of system components have progressed in parallel with this evolution. However, high penetration of renewable energy sources has reduced the percentage contribution of conventional electricity based on synchronous generation, which affects grid stability and hence reliability. Furthermore, numerous camouflaged dc generators and dc loads are being embedded in ac and dc microgrids at ever increasing rates. While embedded generation rapidly increases its share in the hybrid power grid (where ac and dc coexist), the current developments in PE switches-based on wide bandgap (WBG) technology-indicate that within the next two decades Max Planck's well-known sentiment that science advances one funeral at a time will repeat itself on the ac grid. This article aims to summarize the technical developments and problems facing the utilization of ac during widescale electrification of the world using numerous distributed energy resources (DERs). Then, it will map out evolutionary changes toward a future dc grid.
Nesimi Ertugrul, Derek Abbott
Proc. IEEE2
2018 PUF-FSM: A Controlled Strong PUF
abstract
Existing strong controlled physical unclonable function (PUF) designs are built to resist modeling attacks and they deal with noisy PUF responses by exploiting error correction logic. These designs are burdened by the costs of the error correction logic and information shown to leak through the associated helper data for assisting error corrections; leaving the design vulnerable to fault attacks or reliability-based attacks. We present a hybrid PUF-finite state machine (PUF-FSM) construction to realize a controlled strong PUF. The PUF-FSM design removes the need for error correction logic and related computation, storage of the helper data and loading it on-chip by only employing error-free responses judiciously determined on demand in the absence of the underlying PUF-an Arbiter PUF-with a large challenge response pair space. The PUF-FSM demonstrates improved security, especially to reliability-based attacks and is able to support a range of applications from authentication to more advanced cryptographic applications built upon shared keys. We experimentally validate the practicability of the PUF-FSM.
Yansong Gao 0001, Said F. Al-Sarawi, Derek Abbott, Damith Chinthana Ranasinghe
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.4
2016 Pattern identification of biomedical images with time series: Contrasting THz pulse imaging with DCE-MRIs
Xiao-Xia Yin, Sillas Hadjiloucas, Yanchun Zhang, Min-Ying Su, Yuan Miao 0001, Derek Abbott
Artif. Intell. Medicine6
2016 Read operation performance of large selectorless cross-point array with self-rectifying memristive device
Yansong Gao 0001, Omid Kavehei, Said F. Al-Sarawi, Damith Chinthana Ranasinghe, Derek Abbott
Integr.5
2015 mrPUF: A Novel Memristive Device Based Physical Unclonable Function
Yansong Gao 0001, Damith Chinthana Ranasinghe, Said F. Al-Sarawi, Omid Kavehei, Derek Abbott
ACNS5
2015 Digital multiplierless implementation of the biological FitzHugh-Nagumo model
Moslem Nouri, Gholamreza Karimi, Arash Ahmadi, Derek Abbott
Neurocomputing4
2015 Digital Implementation of a Biological Astrocyte Model and Its Application
abstract
This paper presents a modified astrocyte model that allows a convenient digital implementation. This model is aimed at reproducing relevant biological astrocyte behaviors, which provide appropriate feedback control in regulating neuronal activities in the central nervous system. Accordingly, we investigate the feasibility of a digital implementation for a single astrocyte and a biological neuronal network model constructed by connecting two limit-cycle Hopf oscillators to an implementation of the proposed astrocyte model using oscillator-astrocyte interactions with weak coupling. Hardware synthesis, physical implementation on field-programmable gate array, and theoretical analysis confirm that the proposed astrocyte model, with considerably low hardware overhead, can mimic biological astrocyte model behaviors, resulting in desynchronization of the two coupled limit-cycle oscillators.
Hamid Soleimani, Mohammad Bavandpour, Arash Ahmadi, Derek Abbott
IEEE Trans. Neural Networks Learn. Syst.4
2014 Spike-Based Synaptic Plasticity in Silicon: Design, Implementation, Application, and Challenges
abstract
The ability to carry out signal processing, classification, recognition, and computation in artificial spiking neural networks (SNNs) is mediated by their synapses. In particular, through activity-dependent alteration of their efficacies, synapses play a fundamental role in learning. The mathematical prescriptions under which synapses modify their weights are termed synaptic plasticity rules. These learning rules can be based on abstract computational neuroscience models or on detailed biophysical ones. As these rules are being proposed and developed by experimental and computational neuroscientists, engineers strive to design and implement them in silicon and en masse in order to employ them in complex real-world applications. In this paper, we describe analog very large-scale integration (VLSI) circuit implementations of multiple synaptic plasticity rules, ranging from phenomenological ones (e.g., based on spike timing, mean firing rates, or both) to biophysically realistic ones (e.g., calcium-dependent models). We discuss the application domains, weaknesses, and strengths of various representative approaches proposed in the literature, and provide insight into the challenges that engineers face when designing and implementing synaptic plasticity rules in VLSI technology for utilizing them in real-world applications.
Mostafa Rahimi Azghadi, Nicolangelo Iannella, Said F. Al-Sarawi, Giacomo Indiveri, Derek Abbott
Proc. IEEE5
2014 Geometric Algebra for Electrical and Electronic Engineers
abstract
In this paper, we explicate the suggested benefits of Clifford's geometric algebra (GA) when applied to the field of electrical engineering. Engineers are always interested in keeping formulas as simple or compact as possible, and we illustrate that geometric algebra does provide such a simplified representation in many cases. We also demonstrate an additional structural check provided by GA for formulas in addition to the usual checking of physical dimensions. Naturally, there is an initial learning curve when applying a new method, but it appears to be worth the effort, as we show significantly simplified formulas, greater intuition, and improved problem solving in many cases.
James M. Chappell, Samuel Picton Drake, Cameron L. Seidel, Lachlan J. Gunn, Andrew Allison, Derek Abbott
Proc. IEEE7
2013 A new compact analog VLSI model for Spike Timing Dependent Plasticity
abstract
Spike Timing Dependent Plasticity (STDP) is a time-based synaptic plasticity rule that has generated significant interest in the area of neuromorphic engineering and Very Large Scale Integration (VLSI) circuit design. During the last decade, STDP and STDP-like learning mechanisms have shown promising solutions for various real world applications, ranging from pattern recognition to robotics. This paper presents a novel analog VLSI model for STDP that possesses advantages compared to previously published VLSI STDP designs. The presented STDP circuit is capable of reproducing the outcomes of several well known experiments using various plasticity rules inducing STDP protocols that utilise pairs, triplets, and quadruplets of spike patterns. When the circuit is compared to state-of-the-art VLSI STDP circuits, it shows a compact and symmetric design that makes the proposed circuit a powerful component for use in designing STDP or time-based Hebbian learning experiments and applications.
Mostafa Rahimi Azghadi, Said F. Al-Sarawi, Nicolangelo Iannella, Derek Abbott
VLSI-SoC4
2013 A neuromorphic VLSI design for spike timing and rate based synaptic plasticity
Mostafa Rahimi Azghadi, Said F. Al-Sarawi, Derek Abbott, Nicolangelo Iannella
Neural Networks3
2013 The Reasonable Ineffectiveness of Mathematics [Point of View]
abstract
This article addresses the presupposition that mathematics is as effective as claimed and thus remove the quandary of Wigner's "miracle," leading to a non-Platonist viewpoint. Also revisits Hamming's four propositions and show how they may indeed largely explain that there is no miracle, given a reduced level of mathematical effectiveness.
Derek Abbott
Proc. IEEE1
2012 Design and implementation of BCM rule based on spike-timing dependent plasticity
abstract
The Bienenstock-Cooper-Munro (BCM) and Spike Timing-Dependent Plasticity (STDP) rules are two experimentally verified form of synaptic plasticity where the alteration of synaptic weight depends upon the rate and the timing of pre- and post-synaptic firing of action potentials, respectively. Previous studies have reported that under specific conditions, i.e. when a random train of Poissonian distributed spikes are used as inputs, and weight changes occur according to STDP, it has been shown that the BCM rule is an emergent property. Here, the applied STDP rule can be either classical pair-based STDP rule, or the more powerful triplet-based STDP rule. In this paper, we demonstrate the use of two distinct VLSI circuit implementations of STDP to examine whether BCM learning is an emergent property of STDP. These circuits are stimulated with random Poissonian spike trains. The first circuit implements the classical pair-based STDP, while the second circuit realizes a previously described triplet-based STDP rule. These two circuits are simulated using 0.35 µm CMOS standard model in HSpice simulator. Simulation results demonstrate that the proposed triplet-based STDP circuit significantly produces the threshold-based behaviour of the BCM. Also, the results testify to similar behaviour for the VLSI circuit for pair-based STDP in generating the BCM.
Mostafa Rahimi Azghadi, Said F. Al-Sarawi, Nicolangelo Iannella, Derek Abbott
IJCNN4
2012 Efficient design of triplet based Spike-Timing Dependent Plasticity
abstract
Spike-Timing Dependent Plasticity (STDP) is believed to play an important role in learning and the formation of computational function in the brain. The classical model of STDP which considers the timing between pairs of pre-synaptic and post-synaptic spikes (p-STDP) is incapable of reproducing synaptic weight changes similar to those seen in biological experiments which investigate the effect of either higher order spike trains (e.g. triplet and quadruplet of spikes) [1]-[3], or, simultaneous effect of the rate and timing of spike pairs [4] on synaptic plasticity. In this paper, we firstly investigate synaptic weight changes using a p-STDP circuit [5] and show how it fails to reproduce the mentioned complex biological experiments. We then present a new STDP VLSI circuit which acts based on the timing among triplets of spikes (t-STDP) that is able to reproduce all the mentioned experimental results. We believe that our new STDP VLSI circuit improves upon previous circuits, whose learning capacity exceeds current designs due to its capability of mimicking the outcomes of biological experiments more closely; thus plays a significant role in future VLSI implementation of neuromorphic systems.
Mostafa Rahimi Azghadi, Said F. Al-Sarawi, Nicolangelo Iannella, Derek Abbott
IJCNN4
2012 Memristive Device Fundamentals and Modeling: Applications to Circuits and Systems Simulation
abstract
The nonvolatile memory property of a memristor enables the realization of new methods for a variety of computational engines ranging from innovative memristive-based neuromorphic circuitry through to advanced memory applications. The nanometer-scale feature of the device creates a new opportunity for realization of innovative circuits that in some cases are not possible or have inefficient realization in the present and established design domain. The nature of the boundary, the complexity of the ionic transport and tunneling mechanism, and the nanoscale feature of the memristor introduces challenges in modeling, characterization, and simulation of future circuits and systems. Here, a deeper insight is gained in understanding the device operation, leading to the development of practical models that can be implemented in current computer-aided design (CAD) tools.
Jason Kamran Eshraghian, Omid Kavehei, Kyoung-Rok Cho, James M. Chappell, Said F. Al-Sarawi, Derek Abbott
Proc. IEEE7
2012 Addressing the Intermittency Challenge: Massive Energy Storage in a Sustainable Future [Scanning the Issue]
abstract
This Special Issue focuses mainly on massive energy storage systems, but also includes a vision for small to medium sized storage and a discussion of the driving forces.
William F. Pickard, Derek Abbott
Proc. IEEE2
2012 Exploring weak-periodic-signal stochastic resonance in locally optimal processors with a Fisher information metric
Fabing Duan, François Chapeau-Blondeau, Derek Abbott
Signal Process.3
2011 Memristor MOS Content Addressable Memory (MCAM): Hybrid Architecture for Future High Performance Search Engines
abstract
Large-capacity content addressable memory (CAM) is a key element in a wide variety of applications. The inevitable complexities of scaling MOS transistors introduce a major challenge in the realization of such systems. Convergence of disparate technologies, which are compatible with CMOS processing, may allow extension of Moore's Law for a few more years. This paper provides a new approach towards the design and modeling of Memory resistor (Memristor)-based CAM (MCAM) using a combination of memristor MOS devices to form the core of a memory/compare logic cell that forms the building block of the CAM architecture. The non-volatile characteristic and the nanoscale geometry together with compatibility of the memristor with CMOS processing technology increases the packing density, provides for new approaches towards power management through disabling CAM blocks without loss of stored data, reduces power dissipation, and has scope for speed improvement as the technology matures.
Jason Kamran Eshraghian, Kyoung-Rok Cho, Omid Kavehei, Soon-Ku Kang, Derek Abbott, Sung-Mo Kang 0001
IEEE Trans. Very Large Scale Integr. Syst.5
2010 Keeping the Energy Debate Clean: How Do We Supply the World's Energy Needs?
abstract
We take a fresh look at the major nonrenewable and renewable energy sources and examine their long-term viability, scalability, and the sustainability of the resources that they use. We achieve this by asking what would happen if each energy source was a single supply of power for the world, as a gedanken experiment. From this perspective, a solar hydrogen economy emerges as a dominant solution to the world's energy needs. If we globally tap sunlight over only 1% of the incident area at only an energy conversion efficiency of 1%, it is simple to show that this meets our current world energy consumption. As 9% of the planet surface area is taken up by desert and efficiencies well over 1% are possible, in practice, this opens up many exciting future opportunities. Specifically, we find solar thermal collection via parabolic reflectors - where focussed sunlight heats steam to about 600?C to drive a turbine - is the best available technology for generating electricity. For static power storage, to provide electricity at night, there are a number of viable options that are discussed. For mobile power storage, such as for fueling vehicles, we argue the case for both liquid and gaseous hydrogen for use in internal combustion engines. We outline a number of reasons why semiconductor solar cells and hydrogen fuel cells do not appear to scale up for a global solution. We adopt an approach that envisions exploiting massive economy of scale by establishing large arrays of solar collectors in hot desert regions of the world. For nonrenewable sources we argue that we cannot wait for them to be exhausted - we need to start conserving them imminently. What is often forgotten in the energy debate is that oil, natural gas, and coal are not only used as energy sources, but we also rely on them for embodying many crucial physical products. It is this fact that requires us to develop a solar hydrogen platform with urgency. It is argued that a solar future is unavoidable, as ultimately humankind has no other choice.
Derek Abbott
Proc. IEEE1
2010 A Systemized View of Superluminal Wave Propagation
abstract
This paper reviews earlier studies on superluminal wave propagation in anomalously dispersive media that have been carried out in the electronic, microwave, and optical regimes. Those studies are relevant to observation of modulated Gaussian pulses transmitted through various media at speeds apparently faster than c without distortion. This paper also presents the condition for superluminal propagation that is established based on the magnitude-phase relation of a causal and minimum-phase filter. Since the condition is modeled on the basis of filter theory, it is applicable to all types of media. A terahertz experiment with a periodic bandgap structure is also included to illustrate superluminal propagation.
Withawat Withayachumnankul, Bernd M. Fischer, Bradley Ferguson, Bruce R. Davis, Derek Abbott
Proc. IEEE5
2009 What Is Stochastic Resonance? Definitions, Misconceptions, Debates, and Its Relevance to Biology
abstract
Stochastic resonance is said to be observed when increases in levels of unpredictable fluctuations--e.g., random noise--cause an increase in a metric of the quality of signal transmission or detection performance, rather than a decrease. This counterintuitive effect relies on system nonlinearities and on some parameter ranges being "suboptimal". Stochastic resonance has been observed, quantified, and described in a plethora of physical and biological systems, including neurons. Being a topic of widespread multidisciplinary interest, the definition of stochastic resonance has evolved significantly over the last decade or so, leading to a number of debates, misunderstandings, and controversies. Perhaps the most important debate is whether the brain has evolved to utilize random noise in vivo, as part of the "neural code". Surprisingly, this debate has been for the most part ignored by neuroscientists, despite much indirect evidence of a positive role for noise in the brain. We explore some of the reasons for this and argue why it would be more surprising if the brain did not exploit randomness provided by noise--via stochastic resonance or otherwise--than if it did. We also challenge neuroscientists and biologists, both computational and experimental, to embrace a very broad definition of stochastic resonance in terms of signal-processing "noise benefits", and to devise experiments aimed at verifying that random variability can play a functional role in the brain, nervous system, or other areas of biology.
Mark D. McDonnell, Derek Abbott
PLoS Comput. Biol.2
2007 Wavelet Based Local Coherent Tomography with an Application in Terahertz Imaging
Xiao-Xia Yin, Brian Wai-Him Ng, Bradley Ferguson, Derek Abbott
CAIP4
2007 Special Issue on T-Ray Imaging, Sensing, and Retection
abstract
The seventeen articles in this special issue are devoted to the topic of t-ray pulsed imaging - or T-rays. This part of the spectrum has been coined "terahertz gap" due to the lack of efficient sources that could generate frequencies in this range. Reports on recent advancements in this technology and reports on applications for its use, with special emphasis on the biomedical field.
Derek Abbott
Proc. IEEE1
2007 T-Ray Sensing and Imaging
abstract
T-ray wavelengths are long enough to pass through dry, nonpolar objects opaque at visible wavelengths, but short enough to be manipulated by optical components to form an image. Sensing in this band potentially provides advantages in a number of areas of interest to security and defense such as screening of personnel for hidden objects and the retection of chemical and biological agents. Several private companies are developing smaller, reliable cheaper systems allowing for commercialization and this motivates us to review a number of promising applications within this paper. While there are a number of challenges to be overcome there is little doubt that T-ray technology will play a significant role in the near future for advancement of security, public health, and defense.
Withawat Withayachumnankul, Gretel M. Png, Xiao-Xia Yin, Shaghik Atakaramians, Inke Jones, Hungyen Lin, Benjamin Seam Yu Ung, Jegathisvaran Balakrishnan, Brian Wai-Him Ng, Bradley Ferguson, Samuel P. Mickan, Bernd M. Fischer, Derek Abbott
Proc. IEEE13
2004 Signal reconstruction via noise through a system of parallel threshold nonlinearities
abstract
We present an analysis of the exploitation of noise for signal reconstruction by an array of nonlinear threshold-based devices. This phenomenon has been described as a form of stochastic resonance known as suprathreshold stochastic resonance. It occurs when all devices in an array of size N have identical thresholds and are subject to independent additive noise. The original work showed that the mutual information between the input and output of the array has a maximum for a nonzero value of noise intensity, for a random input signal. In this paper, we extend the results on this phenomenon to the case of Laplacian signal and noise probability densities, and show conditions exist under which it is optimal.
Mark D. McDonnell, Derek Abbott
ICASSP (2)2
2004 Optimal quantization in neural coding
abstract
In this paper the optimality of the encoding by relaxing the constraint of identical threshold values for each neuron and determining the optimal encoding for a range of SNR's is presented. The population of neurons can be considered a semicontinuous information channel. Using Fisher information that the value of SNR at which bifurcation occurs asymptotically approaches a fixed value of SNR. This result indicates that in the presence of low SNR's, populations of neurons may be able to effectively encode information in a manner similar to a flash analog to digital converter, despite possessing identical thresholds.
Mark D. McDonnell, Derek Abbott
ISIT2
2004 Multiple embedding using robust watermarks for wireless medical images
abstract
Within the expanding paradigm of medical imaging and wireless communications there is increasing demand for transmitting diagnostic medical imagery over error-prone wireless communication channels such as those encountered in cellular phone technology. Medical images must be compressed with minimal file size to minimize transmission time and robustly coded to withstand these wireless environments. It has been reinforced through extensive research that the most crucial regions of medical images must not be degraded and compressed by a lossless or near lossless algorithm. This type of area is called the Region of Interest (ROI). Conversely, the Region of Backgrounds (ROB) may be compressed with some loss of information to achieve a higher compression level. This type of hybrid coding scheme is most useful for wireless communication where the 'bit-budget' is devoted to the ROI. This paper also develops a way for this system to operate externally to the Joint Picture Experts Group (JPEG) still image compression standard without the use of hybrid coding. A multiple watermarking technique is developed to verify the integrity of the ROI after transmission and in the situation where there may be incidental degradation that is hard to perceive or unexpected levels of compression that may degrade ROI content beyond an acceptable level. The most useful contribution in this work is assurance of ROI image content integrity after image files are subject to incidental degradation in these environments. This is made possible with extraction of DCT signature coefficients from the ROI and embedding multiply in the ROB. Strong focus is placed on the robustness to JPEG compression and the mobile channel as well as minimizing the image file size while maintaining its integrity with the use of semi-fragile, robust watermarking.
Dominic Osborne, Derek Abbott, Matthew Sorell, Derek Rogers
MUM2
1999 Low Power Techniques for Digital GaAs VLSI
abstract
This paper presents a survey of low-power digital Gallium Arsenide logic applicable to high performance VLSI circuits and systems and proposes new design concepts in methodology and architecture based on the implementation of Pseudo-Dynamic Latched Logic in order to achieve reasonable power-delay-area tradeoff. The approach is highly suitable for self-timed systems where the complexities of clock skew are avoided and power saving is achieved through pipelined architectures. The emergence of low-power Complementary HIGFET (C-HICFET) technology enables the realisation of new high performance low-power architectures. The viability of nu-GaAs (/spl nu/GaAs) as applied to C-HIGFET is discussed and the concept of 'soft' hardware referred as 'flexware' is introduced as a new design paradigm for GaAs.
José Francisco López, Roberto Sarmiento, Antonio Núñez, Jason Kamran Eshraghian, Stefan Lachowicz, Derek Abbott
Great Lakes Symposium on VLSI6