EDBT 2026 Demo / reviewers in the wild / expert
Yun Chen 0004
dblp:10/5680-4
· DBLP profile ↗
10ranked-venue papers
8as first author
7since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 7 · 5 first-author · 7 since 2021Security and privacy · 2 · 2 first-authorSoftware engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | NTT-LSU: Tightly Coupled Architecture for Efficient NTT Implementation on RISC-V ProcessorabstractPolynomial multiplication is one of the most computationally intensive operations in lattice-based cryptographic systems, directly impacting overall computational efficiency. Although the Number Theoretic Transform (NTT) reduces the time complexity of polynomial multiplication fromO(n2) toO(nlogn), the varying parameter requirements of different lattice algorithms limit the generality of hardware designs. To address this issue, we propose an innovative hardware architecture that tightly couples the NTT unit with the Load and Store Unit (LSU) in the pipeline of a RISC-V processor. We also propose a hybrid width data path method that effectively reduces data transfer time. Compared to previous designs, our architecture minimizes data transfer latency while enhancing computational flexibility and scalability. Specifically, we have customized NTT-related instructions to support Inverse Number Theoretic Transform (INTT) and various NTT parameter configurations. Experimental results demonstrate that our solution significantly shortens the NTT computation cycle, achieving over 10× speedup compared to software implementations. In comparison to existing solutions, our architecture exhibits superior area-time product (ATP) performance. Yinqiao Zhao, Zilong Xie, Ruidian Zhan, Xiaoming Xiong, Yun Chen 0004, Shuting Cai |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 5 |
| 2026 | A Low-Cost Local Masking Radix-4 NTT Against Soft-Analytical Side-Channel AttacksabstractThe number theoretic transform (NTT) is essential for accelerating polynomial multiplication in lattice-based cryptography. However, it is vulnerable to soft-analytical side-channel attacks (SASCAs). Although local masking countermeasure provides theoretical resistance against such attacks, its direct implementation in Radix-4 NTT architecture leads to more than a 4 times increase in modular multiplications, resulting in substantial hardware overhead. To address this challenge, we propose the modular multiplication parallel mask sharing (MMPMS) scheme, which optimizes the modular multiplication parallelism of the Radix-4 butterfly units and shares random twiddle factors, thereby achieving a balance between hardware overhead and security. Then, we construct a complete local masking NTT/INTT algorithm and efficiently implement it on the Artix-7 field-programmable gate array (FPGA). Experimental results show that compared with the state-of-the-art local masking NTT, our scheme reduces the equivalent area and ATP overhead by more than 8.24 times and 6.74 times, respectively. In addition, a nonspecifict-test analysis indicates no significant side-channel leakage. Congwei Chen, Jinwei Pu, Jianxiong Zhang 0003, Jiaying Liao, Ruidian Zhan, Yun Chen 0004, Shuting Cai |
IEEE Trans. Very Large Scale Integr. Syst. | 7 |
| 2025 | PARADISE: Criticality-Aware Instruction Reordering for Power Attack ResistanceabstractPower side-channel attacks exploit the correlation of power consumption with the instructions and data being processed to extract secrets from a device (e.g., cryptographic keys). Prior work primarily focused on protecting small embedded micro-controllers and in-order processors rather than high-performance, out-of-order desktop and server CPUs. In this article, we present Paradise , a general-purpose out-of-order processor with always-on protection, that implements a novel dynamic instruction scheduler to provide obfuscated execution and mitigate power analysis attacks. To achieve this, we exploit the time between operand availability of critical instructions ( slack ) and create high-performance random schedules. Further, we highlight the dangers of using incorrect adversarial assumptions, which can often lead to a false sense of security. Therefore, we perform an extended security analysis on AES-128 using different levels of adversaries, from basic to advanced, including a convolution neural networks–based attack. Our advanced security evaluation assumes a strong adversary with full knowledge of the countermeasure and demonstrates a significant security improvement of 556 × when combined with Boolean Masking over a baseline only protected by masking and 62,500× over an unprotected baseline. The resulting overhead in performance, power, and area of Paradise is 3.2%, 1.2%, and 0.8% respectively. 1 Yun Chen 0004, Ali Hajiabadi, Romain Poussier, Yaswanth Tavva, Andreas Diavastos, Shivam Bhasin, Trevor E. Carlson |
ACM Trans. Archit. Code Optim. | 1 |
| 2024 | Prime+Reset: Introducing A Novel Cross-World Covert-Channel Through Comprehensive Security Analysis on ARM TrustZoneabstractARM TrustZone, a robust security mechanism, aims to protect against a wide range of threats by partitioning the system-on-chip hardware and software into two distinct worlds, namely the normal world and the secure world. However, the secure world still remains susceptible to malicious attacks, including side-channel and covert-channel vulnerabilities. Previous efforts to leak data from TrustZone focused on cache-based and performance monitoring unit (PMU)-based channels; in this paper, we, however, propose a security analysis benchmark suite by traversing the hardware components involved in the microarchitecture to study their security impact on the secure world. Our investigation unveils an undisclosed leakage source stemming from the L2 prefetcher. We design a new cross-core and cross-world covert-channel attack based on our reverse engineering of the L2 prefetcher, named Prime+Reset. Compared to most cross-world covert-channel attacks, Prime+Reset is a cache- and PMU-agnostic attack that effectively bypasses many existing defenses. The throughput of Prime+Reset can achieve 776 Kib/s, which demonstrates a significant improvement, 70 ×, over the state-of-the-art, while maintaining a similar error rate (< 2 %). One can find the code at https://github.com/yunchen-juuuump/prime-reset. Yun Chen 0004, Arash Pashrashid, Yongzheng Wu, Trevor E. Carlson |
DATE | 1 |
| 2024 | GADGETSPINNER: A New Transient Execution Primitive Using the Loop Stream DetectorabstractTransient execution attacks constitute a major class of attacks affecting all modern out-of-order CPUs. These attacks exploit transient execution windows (i.e., the instructions that execute but never commit) to leak confidential information from victims. Existing attacks either rely on branch mispredictions, incorrect memory speculation, or deferred exception handling to create transient windows. In this work, we introduce a new transient execution primitive, called GADGETSPINNER. We exploit the Loop Stream Detector (LSD) in Intel processors to perform out-of-loop-bounds execution and perform illegal operations. Our key observation is that the LSD holds on to an old copy of branch predictions from the first iteration of the loop and keeps using this copy until a branch misprediction occurs, i.e., advances beyond the loop bound. We exploit the delay between the speculative iteration of the loop and when the branch misprediction is resolved. In this paper, we analyze the transient execution of the LSD and perform end-to-end attacks to (1) perform illegal reads from protected memory regions, (2) bypass Intel SGX and extract the weights of a trained CNN model in DNNL library, (3) break Kernel ASLR (KASLR), and finally (4) perform cross-core/cross-process attacks. We also show that many defenses for prior transient execution attacks, like secure Branch Prediction Unit (BPU) designs, fail to protect against GADGETSPINNER. Yun Chen 0004, Ali Hajiabadi, Trevor E. Carlson |
HPCA | 1 |
| 2024 | PREFETCHX: Cross-Core Cache-Agnostic Prefetcher-based Side-Channel AttacksabstractIn this paper, we reveal the existence of a new class of prefetcher, the XPT prefetcher, in modern Intel processors which has never been officially detailed. It speculatively issues a load, bypassing last-level cache (LLC) lookups, when it predicts that a load request will result in an LLC miss. We demonstrate that XPT prefetcher is shared among different cores, which enables an attacker to build cross-core side-channel and covertchannel attacks. We propose PREFETCHX, a cross-core attack mechanism, to leak users’ sensitive data and activities. We empirically demonstrate that PREFETCHX can be used to extract private keys of real-world RSA applications. Furthermore, we show that PREFETCHX can enable side-channel attacks that can monitor keystrokes and network traffic patterns of users. Our two cross-core covert-channel attacks also see a low error rate and a 122KiB/s maximum channel capacity. Due to the cache-independent feature of PREFETCHX, current cache-based mitigations are not effective against our attacks. Overall, our work uncovers a significant vulnerability in the XPT prefetcher, which can be exploited to compromise the confidentiality of sensitive information in both cryptography and non-cryptography-related applications among processor cores. Yun Chen 0004, Ali Hajiabadi, Lingfeng Pei, Trevor E. Carlson |
HPCA | 1 |
| 2023 | AfterImage: Leaking Control Flow Data and Tracking Load Operations via the Hardware PrefetcherabstractResearch into processor-based side-channels has seen both a large number and a large variety of disclosed vulnerabilities that can leak critical, private data to malicious attackers. While most previous works require speculative execution and the use of cache primitives to transmit data, our new approach, called AfterImage, requires neither, capitalizing on vulnerabilities in Intel’s IP-stride prefetcher to both expose and transmit victim data. By training this prefetcher with attacker-known values, and watching for changes to the prefetcher state when execution returns to the attacker, it is now possible to monitor and leak critical data from a large number of common userspace applications and kernel routines without speculation and additional cache accesses. To demonstrate the novel capabilities of AfterImage, we (1) present proof-of-concept attacks that leak data across different isolation levels, (2) present an end-to-end attack that leaks an entire RSA key from a modern, timing-balanced algorithm, and also (3) show how AfterImage can significantly improve the effectiveness of other attacks, such as power side-channel attacks, by using this technique as a high-precision marker. Yun Chen 0004, Lingfeng Pei, Trevor E. Carlson |
ASPLOS (2) | 1 |
| 2019 | DEPLEST: A blockchain-based privacy-preserving distributed database toward user behaviors in social networks
Yun Chen 0004, Shengjun Wei, Changzhen Hu |
Inf. Sci. | 1 |
| 2018 | A Dynamic Hidden Forwarding Path Planning Method Based on Improved Q-Learning in SDN EnvironmentsabstractCurrently, many methods are available to improve the target network’s security. The vast majority of them cannot obtain an optimal attack path and interdict it dynamically and conveniently. Almost all defense strategies aim to repair known vulnerabilities or limit services in target network to improve security of network. These methods cannot response to the attacks in real-time because sometimes they need to wait for manufacturers releasing corresponding countermeasures to repair vulnerabilities. In this paper, we propose an improved Q-learning algorithm to plan an optimal attack path directly and automatically. Based on this path, we use software-defined network (SDN) to adjust routing paths and create hidden forwarding paths dynamically to filter vicious attack requests. Compared to other machine learning algorithms, Q-learning only needs to input the target state to its agents, which can avoid early complex training process. We improve Q-learning algorithm in two aspects. First, a reward function based on the weights of hosts and attack success rates of vulnerabilities is proposed, which can adapt to different network topologies precisely. Second, we remove the actions and merge them into every state that reduces complexity from O(N3) to O(N2) . In experiments, after deploying hidden forwarding paths, the security of target network is boosted significantly without having to repair network vulnerabilities immediately. Yun Chen 0004, Changzhen Hu |
Secur. Commun. Networks | 1 |
| 2017 | Optimal Attack Path Generation Based on Supervised Kohonen Neural Network
Yun Chen 0004, Changzhen Hu |
NSS | 1 |