EDBT 2026 Demo / reviewers in the wild / expert
Xun Jiao 0002
dblp:117/5478-2
· DBLP profile ↗
49ranked-venue papers
8as first author
30since 2021 · last 2026
0000-0003-4476-2501ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 37 · 8 first-author · 21 since 2021Software engineering, systems software and programming languages · 12 · 3 first-author · 7 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Security and privacy · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Revisiting Lottery Ticket Hypothesis: Toward Efficient and Robust Deep Neural NetworksabstractDeep Neural Networks (DNNs) benefit from various model optimization strategies, among which the lottery ticket hypothesis (LTH) has emerged as a promising pruning strategy that achieves significant efficiency improvement while preserving model accuracy. However, for the first time, our study reveals that LTH can undermine the robustness of DNN models against soft errors. To mitigate the impact of soft errors, we propose to jointly optimize the efficiency and robustness of DNN models by enhancing the intrinsic soft error robustness of LT models. Specifically, we introduce two LT variants that strengthen soft error robustness by constraining parameter value ranges and compressing value spaces. Experimental results demonstrate that the proposed strategies can improve the soft error robustness of conventional LT models by up to 10,000 ×, while maintaining the memory efficiency of LT models, and incurring less than 1% execution latency overhead. Jinghao Wen, Xun Jiao 0002 |
ACM Great Lakes Symposium on VLSI | 3 |
| 2026 | MILEAM: Modeling Input-Aware Logic Errors of Approximate Multipliers using Machine Learning
Jinghao Wen, Dongning Ma, Xun Jiao 0002 |
ISCAS | 3 |
| 2026 | Stealing Black-box Hyperdimensional Computing Models Without DataabstractHyperdimensional computing (HDC) is an emerging bio-inspired machine learning scheme for its balance between accuracy and efficiency. Similar to other machine learning models, a trained HDC model is a valuable intellectual property (IP) and subject to model stealing attacks. In this paper, we propose StealHD to functionally steal the HDC model under the strict and challenging ''data-free and black-box'' scenario, where the attacker can only query input to HDC models and observe corresponding output without knowing what data are used to train the model or the parameters in the model. Inspired by the characteristics of HDC algorithm, we leverage three noise back-ends and eight different augmentations to generate a surrogate dataset for attack following those patterns. We then feed the input to the victim model as queries to obtain the output similarities, based on which we train a surrogate HDC model to mimic the performance of the victim model. Experimental results on three datasets show that StealHD can effectively steal an HDC model under a strict data-free black-box scenario. Dongning Ma, Xun Jiao 0002 |
WSDM | 3 |
| 2025 | Exploring Hyperdimensional Computing Robustness Against Hardware ErrorsabstractBrain-inspired hyperdimensional computing (HDC) is an emerging machine learning paradigm leveraging high-dimensional spaces for efficient tasks like pattern recognition and medical diagnostics. As a lightweight alternative to deep neural networks, HDC offers smaller model sizes, reduced computation, and memory-centric processing. However, deploying HDC in safety-critical applications, such as healthcare and robotics, is challenged by hardware-induced errors. This paper investigates HDC's robustness to memory errors via extensive bit-flip injection experiments on item and associative memories. Results reveal that certain bit-flips severely degrade accuracy. To address this, we introduce the Hyperdimensional Bit-Flip Search (HD-BFS), a similarity-guided method for identifying vulnerabilities and crafting efficient attacks, where flipping just 6 critical bits—3.9% of random bit-flips—reduces accuracy to chance levels. We further propose Hyperdimensional Accelerated Bit-Flip Search (HD-ABFS), which narrows the search space by targeting critical dimensions and most significant bits (MSBs), achieving up to 282$\times$speedup over HD-BFS. Finally, we develop an effective protection mechanism to enhance model safety. These insights highlight HDC's resilience to random errors, offer robust defenses against targeted attacks, and advance the security and reliability of HDC systems. Sizhe Zhang, Kyle Juretus, Xun Jiao 0002 |
IEEE Trans. Computers | 3 |
| 2024 | PP-HDC: A Privacy-Preserving Inference Framework for Hyperdimensional ComputingabstractRecently, brain-inspired hyperdimensional computing (HDC), an emerging neuro-symbolic computing scheme that imitates human brain functions to process information using abstract and high-dimensional patterns, has seen increasing applications in multiple application domains and deployment in edge-cloud collaborative processing. However, sending sensitive data to the cloud for inference may face severe privacy threats. Unfortunately, HDC is particularly vulnerable to privacy threats due to its reversible nature. To address this challenge, we propose PP-HDC, a novel privacy-preserving inference framework for HDC. PP-HDC is designed to protect the privacy of both inference input and output. To preserve the privacy of inference input, we propose a novel hash-encoding approach in high-dimensional space by implementing a sliding-window-based transformation on the input hypervector (HV). By leveraging the unique mathematical properties of HDC, we are able to seamlessly perform training and inference on the hash-encoded HV with negligible overhead. For inference output privacy, we propose a multi-model inference approach to encrypt the inference results by leveraging the unique structure of HDC item memories and ensuring the inference result is only accessible to the owner with a proper key. We evaluate PP-HDC on three datasets and demonstrate that PP-HDC enhances privacy-preserving effects compared with state-of-the-art works while incurring minimal accuracy loss. Wengying Wen, Kyle Juretus, Xun Jiao 0002 |
DATE | 4 |
| 2024 | Memory-Efficient Deep Recommender Systems using Approximate Rotary Compositional EmbeddingabstractEmbedding tables in deep recommender systems (DRS) process categorical data, which can be memory-intensive due to the high feature cardinality. In this paper, we propose Approximate Rotary Compositional Embedding (ARCE), which intentionally trades off performance to aggressively reduce the size of the embedding tables. Specifically, ARCE uses compositional embedding to split large embedding tables into smaller compositions and replaces index look-ups with vector rotations. To regain the performance loss of this trade-off, ARCE features an input approximation where one index is mapped into multiple indices, creating a larger space for a potential increased learning capability. Experimental results show that using ARCE can reduce the memory overhead of embedding tables in DRS by more than 1000x with less than 3% performance loss, highlighting the potential of using ARCE for less memory intensive DRS designs. We open-source ARCE at https://github.com/VU-DETAIL/arce. Dongning Ma, Xun Jiao 0002 |
SIGIR | 2 |
| 2024 | A Computing-in-Memory-Based One-Class Hyperdimensional Computing Model for Outlier DetectionabstractIn this work, we presentODHD, an algorithm for outlier detection based on hyperdimensional computing (HDC), a non-classical learning paradigm. Along with the HDC-based algorithm, we proposeIM-ODHD, a computing-in-memory (CiM) implementation based on hardware/software (HW/SW) codesign for improved latency and energy efficiency. The training and testing phases ofODHDmay be performed with conventional CPU/GPU hardware or ourIM-ODHD, SRAM-based CiM architecture using the proposed HW/SW codesign techniques. We evaluate the performance ofODHDon six datasets from different application domains using three metrics, namely accuracy, F1 score, and ROC-AUC, and compare it with multiple baseline methods such as OCSVM, isolation forest, and autoencoder. The experimental results indicate thatODHDoutperforms all the baseline methods in terms of these three metrics on every dataset for both CPU/GPU and CiM implementations. Furthermore, we perform an extensive design space exploration to demonstrate the tradeoff between delay, energy efficiency, and performance ofODHD. We demonstrate that the HW/SW codesign implementation of the outlier detection onIM-ODHDis able to outperform the GPU-based implementation ofODHDby at least 331.5×/889× in terms of training/testing latency (and on average 14.0×/36.9× in terms of training/testing energy consumption). Sabrina Hassan Moon, Xiaobo Sharon Hu, Xun Jiao 0002, Dayane Reis |
IEEE Trans. Computers | 4 |
| 2023 | Beyond von Neumann Era: Brain-Inspired Hyperdimensional Computing to the RescueabstractBreakthroughs in deep learning (DL) continuously fuel innovations that profoundly improve our daily life. However, DNNs overwhelm conventional computing architectures by their massive data movements between processing and memory units. As a result, novel computer architectures are indispensable to improve or even replace the decades-old von Neumann architecture. Nevertheless, going far beyond the existing von Neumann principles comes with profound reliability challenges for the performed computations. This is due to analog computing together with emerging beyond-CMOS technologies being inherently noisy and inevitably leading to unreliable computing. Hence, novel robust algorithms become a key to go beyond the boundaries of the von Neumann era. Hyper-dimensional Computing (HDC) is rapidly emerging as an attractive alternative to traditional DL and ML algorithms. Unlike conventional DL and ML algorithms, HDC is inherently robust against errors along a much more efficient hardware implementation. In addition to these advantages at hardware level, HDC's promise to learn from little data and the underlying algebra enable new possibilities at the application level. In this work, the robustness of HDC algorithms against errors and beyond von Neumann architectures are discussed. Further, the benefits of HDC as a machine learning algorithm are demonstrated with the example of outlier detection and reinforcement learning. Hussam Amrouch, Paul R. Genssler, Mohsen Imani, Mariam Issa, Xun Jiao 0002, Wegdan Mohammad, Gloria Sepanta |
ASP-DAC | 5 |
| 2023 | Robust Hyperdimensional Computing against Cyber Attacks and Hardware Errors: A SurveyabstractHyperdimensional Computing (HDC), also known as Vector Symbolic Architecture (VSA), is an emerging AI algorithm inspired by the way the human brain functions. Compared with deep neural networks (DNNs), HDC possesses several advantages such as smaller model size, less computation cost, and one/few-shot learning, making it a promising alternative computing paradigm. With the increasing deployment of AI in safety-critical systems such as healthcare and robotics, it is not only important to strive for high accuracy, but also to ensure its robustness under even highly uncertain and adversarial environments. However, recent studies show that HDC, just like DNNs, is vulnerable to both cyber attacks (e.g., adversarial attacks) and hardware errors (e.g., memory failures). While a growing body of research has been studying the robustness of HDC, there is a lack of systematic review of research efforts on this increasingly-important topic. To the best of our knowledge, this paper presents the first survey dedicated to review the research efforts made to the robustness of HDC against cyber attacks and hardware errors. While the performance and accuracy of HDC as an AI method still expects future theoretical advancement, this survey paper aims to shed light and call for community efforts on robustness research of HDC. Dongning Ma, Sizhe Zhang, Xun Jiao 0002 |
ASP-DAC | 3 |
| 2023 | Comprehensive Analysis of Hyperdimensional Computing Against Gradient Based AttacksabstractBrain-inspired Hyper-dimensional computing (HDC) has recently shown promise as a lightweight machine learning approach. Despite its success, there are limited studies on the robustness of HDC models to adversarial attacks. In this paper, we introduce the first comparative study of the robustness between HDC and deep neural network (DNN) to malicious attacks. We develop a framework that enables HDC models to generate gradient-based adversarial examples using state-of-the-art techniques applied to DNNs. Our evaluation shows that HDC with a proper neural encoding module provides significantly higher robustness to adversarial attacks than existing DNNs. In addition, HDC models have high robustness to adversarial samples generated for DNNs. Hamza Errahmouni Barkam, Sungheon Jeong 0001, Calvin Yeung 0002, Zhuowen Zou, Xun Jiao 0002, Mohsen Imani |
DATE | 5 |
| 2023 | Adversarial Attack on Hyperdimensional Computing-based NLP ApplicationsabstractThe security and robustness of machine learning algorithms have become increasingly important as they are used in critical applications such as natural language processing (NLP), e.g., text-based spam detection. Recently, the emerging brain-inspired hyperdimensional computing (HDC), compared to deep learning methods, has shown advantages such as compact model size, energy efficiency, and capability of few-shot learning in various NLP applications. While HDC has been demonstrated to be vulnerable to adversarial attacks in image and audio input, there is currently very limited study on its adversarial security to NLP tasks, which is arguable one of the most suitable applications for HDC. In this paper, we present a novel study on the adversarial attack of HDC-based NLP applications. By leveraging the unique properties in HDC, the similarity-based inference, we propose similarity-guided approaches to automatically generate adversarial text samples for HDC. Our approach is able to achieve up to 89% attack success rate. More importantly, by comparing with unguided brute-force approach, similarity-guided attack achieves a speedup of 2.4X in generating adversarial samples. Our work opens up new directions and challenges for future adversarially-robust HDC model design and optimization. Sizhe Zhang, Xun Jiao 0002 |
DATE | 3 |
| 2023 | Strategies for Enhanced Signal Modulation Classifications Under Unknown Symbol Rates and Noise ConditionsabstractRadio frequency signal modulation classifications find broad applications in cognitive sensing and RF spectrum coexistence. Recently, deep neural networks have been shown to be a powerful tool for automatic modulation classification (AMC). Accounting for different signal variations is paramount towards reliable classifications. In this paper, we examine the performance of AMC under varying sampling rates and signal-to-noise ratio (SNR). We consider a dynamic environment where the signal modulation and channel conditions can be assumed constant over a number of consecutive observations. We also show that a single ResNet can be used for both modulation classification and estimating SNR which allows network training and testing at the same noise levels. It is shown that significant signal modulation classification accuracy improvement can be achieved using multiple observations and known SNR. Yue Qi 0001, Mojtaba Vaezi, Xun Jiao 0002, Moeness G. Amin |
ICASSP | 4 |
| 2023 | Invited Paper: Hyperdimensional Computing for Resilient Edge LearningabstractRecent strides in deep learning have yielded impres-sive practical applications such as autonomous driving, natural language processing, and graph reasoning. However, the sus-ceptibility of deep learning models to subtle input variations, which stems from device imperfections and non-idealities, or adversarial attacks on edge devices, presents a critical challenge. These vulnerabilities hold dual significance-security concerns in critical applications and insights into human-machine sen-sory alignment. Efforts to enhance model robustness encounter resource constraints in the edge and the black box nature of neural networks, hindering their deployment on edge devices. This paper focuses on algorithmic adaptations inspired by the human brain to address these challenges. Hyper Dimensional Computing (HDC), rooted in neural principles, replicates brain functions while enabling efficient, noise-tolerant computation. HDC leverages high-dimensional vectors to encode information, seamlessly blending learning and memory functions. Its trans-parency empowers practitioners, enhancing both robustness and understanding of deployed models. In this paper, we introduce the first comprehensive study that compares the robustness of HDC to white-box malicious attacks to that of deep neural network (DNN) models and the first HDC gradient-based attack in the literature. We develop a framework that enables HDC models to generate gradient-based adversarial examples using state-of-the-art techniques applied to DNNs. Our evaluation shows that our HDC model provides, on average, 19.9% higher robustness than DNNs to adversarial samples and up to 90% robustness improvement against random noise on the weights of the model compared to the DNN. Hamza Errahmouni Barkam, Sungheon Jeong 0001, Sanggeon Yun, Calvin Yeung 0002, Zhuowen Zou, Xun Jiao 0002, Narayan Srinivasa, Mohsen Imani |
ICCAD | 6 |
| 2023 | On Hyperdimensional Computing-based Federated Learning: A Case StudyabstractFederated learning is a decentralized machine learning strategy that trains the model by using data stored across multiple decentralized edge devices or servers. Studies on federated learning currently focus primarily on neural network-based learning methods, which usually require powerful hardware and are relatively not energy-efficient. Recently, hyperdimensional computing (HDC) emerges as a potential alternative solution to neural networks, particularly on resource-constrained platforms such as edge intelligence systems. HDC mimics the “human brain” at the functionality level that learns with the attributes of brain circuits, including high-dimensionality and fully distributed holographic representation. Although there are existing works related to HDC-based federated learning, a comprehensive study on how HDC-based federated learning performs in different settings is still absent. To bridge this gap, we present a comprehensive case study on federated learning using HDC under two model aggregation strategies: hypervector aggregation and associative memory aggregation. We also perform extensive experiments with various settings, including data distribution, number of clients, and local training epochs. We also analyze their communication costs under these settings. Our results show that using the strategy of associative memory aggregation can achieve up to 95% communication cost reduction compared to hypervector aggregation. In addition, HDC-based federated learning system shows high robustness in training with Non-IID data. This study aims to shed light and provide guidance in opening up new directions and challenges for future HDC-based federated learning system design and optimization. Sizhe Zhang, Dongning Ma, Song Bian 0001, Lei Yang 0018, Xun Jiao 0002 |
IJCNN | 5 |
| 2023 | Testing and Enhancing Adversarial Robustness of Hyperdimensional ComputingabstractBrain-inspired hyperdimensional computing (HDC), also known as vector symbolic architecture (VSA), is an emerging “non-von Neumann” computing scheme that imitates human brain functions to process information or perform learning tasks using abstract and high-dimensional patterns. Compared with deep neural networks (DNNs), HDC shows advantages, such as compact model size, energy efficiency, and few-shot learning. Despite of those advantages, one under-investigated area of HDC is the adversarial robustness; existing works have shown that HDC is vulnerable to adversarial attacks where attackers can add minor perturbations onto the original inputs to “fool” HDC models, producing wrong predictions. In this article, we systematically study the adversarial robustness of HDC by developing a systematic approach to test and enhance the robustness of HDC against adversarial attacks with two main components: 1) TestHD, which is a highly automated testing tool that can generate high-quality adversarial data for a given HDC model and 2) GuardHD, which utilizes the adversarial data generated by TestHD to enhance the adversarial robustness of HDC models. The core idea of TestHD is built on top of fuzz testing method. We customize the fuzzing approach by proposing a similarity-based coverage metric to guide TestHD to continuously mutate original inputs to generate new inputs that can trigger incorrect behaviors of HDC model. Thanks to the use of differential testing, TestHD does not require knowing the labels of the samples beforehand. For enhancing the adversarial robustness, we design, implement, and evaluate GuardHD to defend HDC models against adversarial data. The core idea of GuardHD is an adversarial detector which can be trained by TestHD-generated adversarial samples. During inference, once an adversarial sample is detected, GuardHD will override the prediction result with an “invalid” signal. We evaluate the proposed methods on four datasets and five adversarial attack scenarios with six adversarial generation strategies and two defense mechanisms, and compare the performance correspondingly. GuardHD is able to differentiate between benign and adversarial inputs with over 90% accuracy, which is up to 55% higher than adversarial training-based baselines. To the best of our knowledge, this article presents the first comprehensive effort in systematically testing and enhancing the robustness against adversarial data of this emerging brain-inspired computational model. Dongning Ma, Tajana Rosing, Xun Jiao 0002 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2023 | AMITE: A Novel Polynomial Expansion for Analyzing Neural Network NonlinearitiesabstractPolynomial expansions are important in the analysis of neural network nonlinearities. They have been applied thereto addressing well-known difficulties in verification, explainability, and security. Existing approaches span classical Taylor and Chebyshev methods, asymptotics, and many numerical approaches. We find that, while these have useful properties individually, such as exact error formulas, adjustable domain, and robustness to undefined derivatives, there are no approaches that provide a consistent method, yielding an expansion with all these properties. To address this, we develop an analytically modified integral transform expansion (AMITE), a novel expansion via integral transforms modified using derived criteria for convergence. We show the general expansion and then demonstrate an application for two popular activation functions: hyperbolic tangent and rectified linear units. Compared with existing expansions (i.e., Chebyshev, Taylor, and numerical) employed to this end, AMITE is the first to provide six previously mutually exclusive desired expansion properties, such as exact formulas for the coefficients and exact expansion errors. We demonstrate the effectiveness of AMITE in two case studies. First, a multivariate polynomial form is efficiently extracted from a single hidden layer black-box multilayer perceptron (MLP) to facilitate equivalence testing from noisy stimulus-response pairs. Second, a variety of feedforward neural network (FFNN) architectures having between three and seven layers are range bounded using Taylor models improved by the AMITE polynomials and error formulas. AMITE presents a new dimension of expansion methods suitable for the analysis/approximation of nonlinearities in neural networks, opening new directions and opportunities for the theoretical analysis and systematic testing of neural networks. Mauro J. Sanchirico III, Xun Jiao 0002, Chandrasekhar Nataraj |
IEEE Trans. Neural Networks Learn. Syst. | 2 |
| 2022 | MoleHD: Efficient Drug Discovery using Brain Inspired Hyperdimensional ComputingabstractIn this paper, we propose MoleHD, an efficient learning model based on brain-inspired hyperdimensional computing (HDC) for molecular property prediction. We develop HDC encoders to project SMILES representation of a molecule into high-dimensional vectors that are used for HDC training and inference. We perform an extensive evaluation using 29 classification tasks from 3 widely-used molecule datasets (Clintox, BBBP, SIDER) under three splits methods (random, scaffold, and stratified). By a comprehensive comparison with 8 existing learning models, we show that MoleHD achieves highest ROC-AUC score on random and scaffold splits on average across 3 datasets and achieve second-highest on stratified split. More importantly, MoleHD achieves such performance with significantly reduced computing cost: no back-propagation needed, only around 10 minutes training time using CPU.MoleHD is open-sourced and available at https://github.com/VU-DETAIL/MoleHD. Dongning Ma, Rahul Thapa, Xun Jiao 0002 |
BIBM | 3 |
| 2022 | Brain-Inspired Hyperdimensional Computing for Ultra-Efficient Edge AIabstractHyperdimensional Computing (HDC) is rapidly emerging as an attractive alternative to traditional deep learning algorithms. Despite the profound success of Deep Neural Networks (DNNs) in many domains, the amount of computational power and storage that they demand during training makes deploying them in edge devices very challenging if not infeasible. This, in turn, inevitably necessitates streaming the data from the edge to the cloud which raises serious concerns when it comes to availability, scalability, security, and privacy. Further, the nature of data that edge devices often receive from sensors is inherently noisy. However, DNN algorithms are very sensitive to noise, which makes accomplishing the required learning tasks with high accuracy immensely difficult. In this paper, we aim at providing a comprehensive overview of the latest advances in HDC. HDC aims at realizing real-time performance and robustness through using strategies that more closely model the human brain. HDC is, in fact, motivated by the observation that the human brain operates on high-dimensional data representations. In HDC, objects are thereby encoded with high-dimensional vectors which have thousands of elements. In this paper, we will discuss the promising robustness of HDC algorithms against noise along with the ability to learn from little data. Further, we will present the outstanding synergy between HDC and beyond von Neumann architectures and how HDC opens doors for efficient learning at the edge due to the ultra-lightweight implementation that it needs, contrary to traditional DNNs. Hussam Amrouch, Mohsen Imani, Xun Jiao 0002, Yiannis Aloimonos, Cornelia Fermüller, Dehao Yuan, Dongning Ma, Hamza Errahmouni Barkam, Paul R. Genssler, Peter Sutor Jr. |
CODES+ISSS | 3 |
| 2022 | ODHD: one-class brain-inspired hyperdimensional computing for outlier detectionabstractOutlier detection is a classical and important technique that has been used in different application domains such as medical diagnosis and Internet-of-Things. Recently, machine learning-based outlier detection algorithms, such as one-class support vector machine (OCSVM), isolation forest and autoencoder, have demonstrated promising results in outlier detection. In this paper, we take a radical departure from these classical learning methods and propose ODHD, an outlier detection method based on hyperdimensional computing (HDC). In ODHD, the outlier detection process is based on a P-U learning structure, in which we train a one-class HV based on inlier samples. This HV represents the abstraction information of all inlier samples; hence, any (testing) sample whose corresponding HV is dissimilar from this HV will be considered as an outlier. We perform an extensive evaluation using six datasets across different application domains and compare ODHD with multiple baseline methods including OCSVM, isolation forest, and autoencoder using three metrics including accuracy, F1 score and ROC-AUC. Experimental results show that ODHD outperforms all the baseline methods on every dataset for every metric. Moreover, we perform a design space exploration for ODHD to illustrate the tradeoff between performance and efficiency. The promising results presented in this paper provide a viable option and alternative to traditional learning algorithms for outlier detection. Xun Jiao 0002, Xiaobo Sharon Hu |
DAC | 2 |
| 2022 | PoisonHD: Poison Attack on Brain-Inspired Hyperdimensional ComputingabstractWhile machine learning (ML) methods especially deep neural networks (DNNs) promise enormous societal and economic benefits, their deployments present daunting challenges due to intensive computational demands and high storage requirements. Brain-inspired hyperdimensional computing (HDC) has recently been introduced as an alternative computational model that mimics the “human brain” at the functionality level. HDC has already demonstrated promising accuracy and efficiency in multiple application domains including healthcare and robotics. However, the robustness and security aspects of HDC has not been systematically investigated and sufficiently examined. Poison attack is a commonly-seen attack on various ML models including DNNs. It injects noises to labels of training data to introduce classification error of ML models. This paper presents PoisonHD, an HDC-specific poison attack framework that maximizes its effectiveness in degrading the classification accuracy by leveraging the internal structural information of HDC models. By applying PoisonHD on three datasets, we show that PoisonHD can cause significantly greater accuracy drop on HDC model than a random label-flipping approach. We further develop a defense mechanism by designing an HDC-based data sanitization that can significantly recover the accuracy loss caused by poison attack. To the best of our knowledge, this is the first paper that studies the poison attack on HDC models. Xun Jiao 0002 |
DATE | 2 |
| 2022 | Energy-Efficient Brain-Inspired Hyperdimensional Computing Using Voltage ScalingabstractRecently, brain-inspired hyperdimensional computing (HDC) has demonstrated promising capability in a wide range of applications such as medical diagnosis, human activity recognition, and voice classification, etc. Despite the growing popularity of HDC, its memory-centric computing characteristics make the associative memory implementation under significant energy consumption due to the massive data storage and processing. In this paper, we present a systematic case study to leverage the application-level error resilience of HDC to reduce the energy consumption of HDC associative memory by using voltage scaling. Evaluation results on various applications show that our proposed approach can achieve 47.6% energy saving on associative memory with a 1% accuracy loss. We further explore two low-cost error masking methods: word masking and bit masking, to mitigate the impact of voltage scaling-induced errors. Experimental results show that the proposed word masking (bit masking) method can further enhance energy saving up to 62.3% (72.5%) with accuracy loss ≤1%. Sizhe Zhang, Dongning Ma, Jeff Zhang 0001, Xunzhao Yin, Xun Jiao 0002 |
DATE | 6 |
| 2022 | ScaleHD: Robust Brain-Inspired Hyperdimensional Computing via Adapative ScalingabstractBrain-inspired hyperdimensional computing (HDC) has demonstrated promising capability in various cognition tasks such as robotics, bio-medical signal analysis, and natural language processing. Compared to deep neural networks, HDC models show advantages such as light-weight model and one/few-shot learning capabilities, making it a promising alternative paradigm to traditional resource-demanding deep learning models particularly in edge devices with limited resources. Despite the growing popularity of HDC, the robustness of HDC models and the approaches to enhance HDC robustness has not been systematically analyzed and sufficiently examined. HDC relies on high-dimensional numerical vectors referred to as hypervectors (HV) to perform cognition tasks and the values inside the HVs are critical to the robustness of an HDC model. We propose ScaleHD, an adaptive scaling method that scales the value of HVs in the associative memory of an HDC model to enhance the robustness of HDC models. We propose three different modes of ScaleHD including Global-ScaleHD, Class-ScaleHD, and (Class + Clip)-ScaleHD which are based on different adaptive scaling strategies. Results show that ScaleHD is able to enhance HDC robustness against memory errors up to 10,000X. Moreover, we leverage the enhanced HDC robustness in exchange for energy saving via voltage scaling method. Experimental results show that ScaleHD can reduce energy consumption on HDC memory system up to 72.2% with less than 1% accuracy loss. Sizhe Zhang, Mohsen Imani, Xun Jiao 0002 |
ICCAD | 3 |
| 2022 | DEVoT: Dynamic Delay Modeling of Functional Units Under Voltage and Temperature VariationsabstractTiming errors of microelectronic circuits occur when the circuit timing specification is violated, i.e., the dynamic delay of circuits exceeds the circuit clock period. With the continuous scaling of CMOS technology, microelectronic circuits are increasingly susceptible to microelectronic variations such as variations in operating conditions. Such variations can cause delay uncertainty in microelectronic circuits, leading totiming errors. Circuit designers typically combat these errors using conservative guardbands in the circuit and architectural design, which can, however, cause significant loss of operational efficiency. In this article, we proposeDEVoT, a supervised learning model that can predict the dynamic delay of functional units (FUs) under different operating conditions, clock speeds, and input workload. The main contribution ofDEVoTis to jointly consider the impact of voltage, temperature, and input workload in path sensitization, hence predicting the dynamic delay. We measure the dynamic delay using switching activity generated through gate-level simulation of post place-and-route design in the TSMC 45-nm process. We characterize the delay of FUs under different operating conditions and input workload. We then extract useful features in the input workload that influences dynamic path sensitization. Using these features, we apply supervised learning methods to buildDEVoT. Across 100 different operating conditions, four widely used FUs, and three datasets,DEVoTachieves, on average, less than 2% relative deviation from the ground truth and is$100\times $faster than the gate-level simulation. We present two case studies usingDEVoT. First, we useDEVoTto predict timing errors of FUs, andDEVoTachieves an average prediction accuracy at 98.04%. We further useDEVoTto estimate application output quality under different operating conditions, andDEVoTachieves an average estimation accuracy at 97% for two image processing applications. Second, we present a fuzzing-based method to identify “critical” patterns that can cause longer delay for a given circuit. Built on top ofDEVoT, the generated input patterns can improve the sensitized delay by up to 8.3% compared to random patterns.DEVoTalso outperforms automatic test pattern generation (ATPG) in sensitizing circuit delay. We will opensourceDEVoT, which can assist circuit designers to perform early design space exploration and can also help software developers in approximate computing community to assess their program resilience to hardware approximation without performing circuit simulation. Dongning Ma, Xinqiao Zhang, Ke Huang 0001, Yu Jiang 0001, Wanli Chang 0001, Xun Jiao 0002 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 6 |
| 2021 | Assessing Robustness of Hyperdimensional Computing Against Errors in Associative Memory : (Invited Paper)abstractBrain-inspired hyperdimensional computing (HDC) is an emerging computational paradigm that has achieved success in various domains. HDC mimics brain cognition and lever-ages hyperdimensional vectors with fully distributed holographic representation and (pseudo)randomness. Compared to the traditional machine learning methods, HDC offers several critical advantages, including smaller model size, less computation cost, and one-shot learning capability, making it a promising candidate in low-power platforms. Despite the growing popularity of HDC, the robustness of HDC models has not been systematically explored. This paper presents a study on the robustness of HDC to errors in associative memory—the key component storing the class representations in HDC. We perform extensive error injection experiments to the associative memory in a number of HDC models (and datasets), sweeping the error rates and varying HDC configurations (i.e., dimension and data width). Empirically, we observe that HDC is considerably robust to errors in the associative memory, opening up opportunities for further optimizations. Further, results show that HDC robustness varies significantly with different HDC configurations such as data width. Moreover, we explore a low-cost error masking mechanism in the associative memory to enhance its robustness. Sizhe Zhang, Jeff Zhang 0001, Abbas Rahimi, Xun Jiao 0002 |
ASAP | 5 |
| 2021 | HDTest: Differential Fuzz Testing of Brain-Inspired Hyperdimensional ComputingabstractBrain-inspired hyperdimensional computing (HDC) is an emerging computational paradigm that mimics brain cognition and leverages hyperdimensional vectors with fully distributed holographic representation and (pseudo)randomness. Compared to other machine learning (ML) methods such as deep neural networks (DNNs), HDC offers several advantages including high energy efficiency, low latency, and one-shot learning, making it a promising alternative candidate on a wide range of applications. However, the reliability and robustness of HDC models have not been explored yet. In this paper, we design, implement, and evaluate HDTest to test HDC model by automatically exposing unexpected or incorrect behaviors under rare inputs. The core idea of HDTest is based on guided differential fuzz testing. Guided by the distance between query hypervector and reference hypervector in HDC, HDTest continuously mutates original inputs to generate new inputs that can trigger incorrect behaviors of HDC model. Compared to traditional ML testing methods, HDTest does not need to manually label the original input. Using handwritten digit classification as an example, we show that HDTest can generate thousands of adversarial inputs with negligible perturbations that can successfully fool HDC models. On average, HDTest can generate around 400 adversarial inputs within one minute running on a commodity computer. Finally, by using the HDTest-generated inputs to retrain HDC models, we can strengthen the robustness of HDC models. To the best of our knowledge, this paper presents the first effort in systematically testing this emerging brain-inspired computational model. Dongning Ma, Jianmin Guo, Yu Jiang 0001, Xun Jiao 0002 |
DAC | 4 |
| 2021 | Workload-Aware Approximate Computing ConfigurationabstractApproximate computing recently arises due to its success in many error-tolerant applications such as multimedia applications. Various approximation methods have demonstrated the effectiveness of relaxing precision requirements in a specific arithmetic unit. This provides a basis for exploring simultaneous use of multiple approximate units to improve efficiency. In this paper, we aim to identify a proper approximation configuration of approximate units in a program to minimize energy consumption while meeting quality constraints. To do this, we formulate a constrained optimization problem and develop a tool called WOAxC that uses genetic algorithm to solve this problem. WOAxC considers the impact of different input workload on the application quality. We evaluate the efficacy of WOAxC in minimizing the energy consumption of several image processing applications with varying size (i.e., number of operations), workload (i.e., input datasets), and quality constraints. Our evaluation shows that the configuration provided by WOAxC for a system with multiple approximate units improves the energy efficiency by, on average, 79.6%, 77.4%, and 70.94% for quality loss of 5%, 2.5% and 0% (no loss), respectively. To the best of our knowledge, WOAxC is the first workload-aware approach to identify proper approximation configuration for energy minimization under quality guarantee. Dongning Ma, Rahul Thapa, Xun Jiao 0002, Cong Hao |
DATE | 4 |
| 2021 | Towards scalable, secure, and smart mission-critical IoT systems: review and visionabstractRecent emerging technologies such as artificial intelligence and machine learning have been promising enormous economic and societal benefits. While it is desirable to deploy these technologies to Internet-of-Things (IoT) infrastructures in many applications such as medical, energy, transportation, and industrial automation systems, such deployments present daunting challenges in performance, efficiency, and dependability of scaling-up IoT infrastructure, due to the ever-increasing number of edge devices, ever-increasing levels of device and system heterogeneity, and more stringent requirements of reliability, robustness, and security in mission-critical settings. This position paper elaborates the needs for a cross-layer and full hardware/software stack solution for the design and deployment of scalable, secure, and smart mission-critical IoT systems from four different perspectives and research fields. We present a review of recent studies on such issues and identify the potential challenges and gaps, based on which we highlight some important research directions and future works that can be conducted to tackle such challenges. Xiaolong Guo 0001, Song Han 0002, Xiaobo Sharon Hu, Xun Jiao 0002, Yier Jin, Fanxin Kong, Michael Lemmon 0001 |
EMSOFT | 4 |
| 2021 | Brief Industry Paper: HDAD: Hyperdimensional Computing-based Anomaly Detection for Automotive Sensor AttacksabstractAs the connectivity of autonomous vehicles keeps growing, it is an accepted fact that they are even more vulnerable to malicious cyber-attacks. Recently, sensor spoofing has become an emerging attack that can compromise vehicle safety as vehicles are equipped with more sensors. Thus, it is critical to validate the sensor readings before utilizing them for future actions. In this paper, we develop HDAD, a hyperdimensional computing-based anomaly detection method. Hyperdimensional computing (HDC) is an emerging brain-inspired computing paradigm that mimics the brain cognition and leverages hyperdimensional vectors with fully distributed holographic representation and (pseudo)randomness. The key idea of HDAD is to use HDC to build encoder and decoder to reconstruct the sensor readings. The anomalous data typically have comparatively higher reconstruction errors than normal sensor readings. We explore three different metrics to measure the reconstruction error including mean squared error, mean absolute error, and cosine similarity. Using a real-world vehicle sensor reading dataset, we demonstrate the feasibility and efficacy of HDAD, opening the door for a new set of anomaly detection algorithm design. Fanxin Kong, Hasshi Sudler, Xun Jiao 0002 |
RTAS | 4 |
| 2021 | DeepFuzzer: Accelerated Deep Greybox FuzzingabstractFuzzing is one of the most effective vulnerability detection techniques, widely used in practice. However, the performance of fuzzers may be limited by their inability to pass complicated checks, inappropriate mutation frequency, arbitrary mutation strategy, or the variability of the environment. In this article, we present DeepFuzzer, an enhanced greybox fuzzer with qualified seed generation, balanced seed selection, and hybrid seed mutation. First, we use symbolic execution in a lightweight approach to generate qualified initial seeds which then guide the fuzzer through complex checks. Second, we apply a statistical seed selection algorithm to balance the mutation frequency between different seeds. Further, we develop a hybrid mutation strategy. The random and restricted mutation strategies are combined to maintain a dynamic balance between global exploration and deep search. We evaluate DeepFuzzer on the widely used benchmark Google fuzzer-test-suite which consists of real-world programs. Compared with AFL, AFLFast, FairFuzz, QSYM, and MOPT in the 24-hour experiment, DeepFuzzer discovers 30, 240, 102, 147, and 257 percent more unique crashes, executes 40, 36, 36, 98, and 15 percent more paths, and covers 37, 34, 34, 101, and 11 percent more branches, respectively. Furthermore, we present the practice of fuzzing a message middleware from Huawei with DeepFuzzer, and nine new vulnerabilities are reported. Jie Liang 0006, Yu Jiang 0001, Xun Jiao 0002, Yuanliang Chen, Houbing Song, Kim-Kwang Raymond Choo |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | Semantic Learning and Emulation Based Cross-Platform Binary Vulnerability SeekerabstractClone detection is widely exploited for software vulnerability search. The approaches based on source code analysis cannot be applied to binary clone detection because the same source code can produce significantly different binaries due to different operating systems, microprocessor architectures and compilers. In this paper, we presentBinSeeker, a cross-platform binary seeker that integrates semantic learning and emulation. With the help of the labeled semantic flow graph,BinSeekercan quickly identify$M$candidate functions that are most similar to the vulnerability from the target binary. The value of$M$is relatively large so this semantic learning procedure essentially eliminates those functions that are very unlikely to have the vulnerability. Then, semantic emulation is conducted on these$M$candidates to obtain their dynamic signature sequences. By comparing signature sequences,BinSeekerproduces top-$N$functions that exhibit most similar behavior to that of the vulnerability. With fast filtering of semantic learning and accurate comparison of semantic emulation,BinSeekerseeks vulnerability precisely with little overhead. The experiments on six widely used programs with fifteen known CVE vulnerabilities demonstrate thatBinSeekeroutperforms three state-of-the-art toolsGenius,GeminiandCACompare. Regarding search accuracy,BinSeekerachieves an MRR value of 0.65 in the target programs, whereas the MRR values byGenius,GeminiandCACompareare 0.17, 0.07 and 0.42, respectively. If we consider ranking a function with the targeted vulnerability in the top-5 as accurate,BinSeekerachieves the accuracy of 93.33 percent, while the accuracy of the other three tools is merely 33.33, 13.33 and 53.33 percent, respectively. Such accuracy is achieved with 0.27s on average to determine whether the target binary function contains a known vulnerability, and the time for the other three tools are 1.57s, 0.15s and 0.98s, respectively. Compared to the time used to manually identify the true positive vulnerability from the false positive candidates reported by Gemini, the time overhead ofBinSeekeris negligible. Evidently, the proposedBinSeekerachieves a better balance between accuracy and efficiency. Jian Gao 0008, Yu Jiang 0001, Zhe Liu 0001, Cong Wang 0020, Xun Jiao 0002, Zijiang Yang 0006, Jia-Guang Sun 0001 |
IEEE Trans. Software Eng. | 6 |
| 2020 | TEVoT: Timing Error Modeling of Functional Units under Dynamic Voltage and Temperature VariationsabstractWith the continuous scaling of CMOS technology, microelectronic circuits are increasingly susceptible to micro-electronic variations such as variations in operating conditions. Such variations can cause delay uncertainty in microelectronic circuits, leading to timing errors. Circuit designers typically combat these errors using conservative guardbands in the circuit and architectural design, which can, however, cause significant loss of operational efficiency. In this paper, we propose TEVoT, a supervised learning model that can predict the timing errors of functional units (FUs) under different operating conditions, clock speeds, and input workload. We perform dynamic timing analysis to characterize the delay variations of FUs under different conditions, based on which we collect training data. We then extract useful features from training data and apply supervised learning methods to establish TEVoT. Across 100 different operating conditions, 4 widely-used FUs, 3 clocking speeds, and 3 datasets, TEVoT achieves an average prediction accuracy at 98.25% and is 100X faster than gate-level simulation. We further use TEVoT to estimate application output quality under different operating conditions by exposing circuit-level timing errors to application level. TEVoT achieves an average estimation accuracy at 97% for two image processing applications across 100 operating conditions. Xun Jiao 0002, Dongning Ma, Wanli Chang 0001, Yu Jiang 0001 |
DAC | 1 |
| 2020 | ICS Protocol Fuzzing: Coverage Guided Packet Crack and GenerationabstractIndustrial Control System (ICS) protocols play an essential role in building communications among system components. Recently, many severe vulnerabilities, such as Stuxnet and DragonFly, exposed in ICS protocols have affected a wide distribution of devices. Therefore, it is of vital importance to ensure their correctness. However, the vulnerability detection efficiency of traditional techniques such as fuzzing is challenged by the complexity and diversity of the protocols.In this paper, we propose to equip the traditional protocol fuzzing with coverage-guided packet crack and generation. We collect the coverage information during the testing procedure, save those valuable packets that trigger new path coverage and crack them into pieces, based on which, we can construct higher-quality new packets for further testing. For evaluation, we build Peach*on top of Peach, which is one of the most widely used protocol fuzzers, and conduct experiments on several ICS protocols such as Modbus and DNP3. Results show that, compared with the original Peach, Peach*achieves the same code coverage and bug detection numbers at the speed of 1.2X-25X. It also gains final increase with 8.35%-36.84% more paths within 24 hours and has exposed 9 previously unknown vulnerabilities. Zhengxiong Luo 0002, Feilong Zuo, Yuheng Shen, Xun Jiao 0002, Wanli Chang 0001, Yu Jiang 0001 |
DAC | 4 |
| 2020 | AxBy: Approximate Computation Bypass for Data-Intensive ApplicationsabstractRecent years have witnessed a rapid growth of data-intensive applications such as machine learning and multimedia applications. However, such applications incur a heavy computation workload that stresses the existing computing systems, especially resource-constrained embedded systems. This paper is inspired by the key observation that many data-intensive applications naturally present a strong existence of trivial computations - a set of computations the results of which can be determined without actual computations. Typical examples include multiplication with 0, +1/-1 and addition with 0. Correspondingly, we develop and implement bypass circuits that are tightly integrated with computation units to detect and bypass the trivial computations. Once detected, the circuit delivers the pre-determined result without an actual computation. We implement bypass circuits in both hardware (Verilog) and software (C). Furthermore, we enhance the opportunities of computation bypass by developing AxBy, an approximate computation bypass method with pattern matching under limited data precision. This reconfigurability is key to achieving a “controllable approximation” and a tunable quality-energy tradeoff. Our experimental results show that for four image processing applications and three neural network applications, the computation bypass can enable 15% - 55% in image processing and 30% - 35% in neural networks of energy saving without any accuracy loss. For neural networks, we can further achieve 36% -44% energy saving with negligible accuracy loss. Dongning Ma, Xun Jiao 0002 |
DSD | 2 |
| 2020 | AxR-NN: Approximate Computation Reuse for Energy-Efficient Convolutional Neural NetworksabstractThe recent success of convolutional neural networks (CNN) has led its implementation in specialized accelerators such as graphics processing unit (GPUs). However, the intensive computing workloads of CNNs remain a challenge to existing accelerators. By leveraging the error tolerance of CNNs, we propose a novel method to design energy-efficient CNN accelerators using approximate computation reuse (ACR), referred to as AxRNN. Computation reuse aims to reuse the previously computed results to avoid redundant executions. However, it cannot be applied directly to CNNs because CNNs do not have enough data locality. Thus, AxRNN performs approximate computation reuse under relaxed precision requirements on input patterns and design a reconfigurable architecture to support the ACR. This reconfigurable pattern matching is central to achieve a "controllable approximation". We implement the AxRNN using content addressable memory and integrate them with floating point units. Simulation results show that AxRNN reduces the computation energy by 30-58% with only 1-2.5% accuracy degradation on MNIST, EMNIST, and CIFAR-10 dataset. Dongning Ma, Xunzhao Yin, Michael T. Niemier, Xiaobo Sharon Hu, Xun Jiao 0002 |
ACM Great Lakes Symposium on VLSI | 5 |
| 2020 | Fixed-Priority Scheduling and Controller Co-Design for Time-Sensitive NetworksabstractTime-sensitive networking (TSN) is a set of standardised communication protocols developed under the IEEE 802.1 working group. TSN aims to support deterministic communication based on network schedules that are distributively configured. It is widely considered as the future in-vehicle network solution for highly automated driving, where the requirement on timing guarantee is alongside the demand of high communication bandwidth. In this work, we study a setting of periodic control and non-control packets, with implicit and arbitrary deadlines, respectively. As the FIFO (first-in, first-out) queues in the 802.1Qbv switch incur long delay in the worst case, which prevents the control tasks from achieving short sampling periods and thus impedes control performance optimisation, we propose the first fixed-priority scheduling (FPS) approach for TSN by leveraging its gate control features. In this context, we develop a finer-grained frame-level response time analysis, which provides a tighter bound than the conventional packet-level analysis. Building upon FPS and the above analysis, we formulate a co-design optimisation problem to decide the sampling periods and poles of real-time controllers with settling time as the objective to minimise, whilst satisfying the schedulability constraint. Xiaotian Dai 0001, Shuai Zhao 0004, Yu Jiang 0001, Xun Jiao 0002, Xiaobo Sharon Hu, Wanli Chang 0001 |
ICCAD | 4 |
| 2020 | Introduction to the special issue on dependable cyber physical systems
Junlong Zhou, Xun Jiao 0002, Qingling Zhao, Xiaokang Wang 0001, Shiyan Hu 0001 |
J. Syst. Archit. | 2 |
| 2020 | EM-Fuzz: Augmented Firmware Fuzzing via Memory CheckingabstractEmbedded systems are increasingly interconnected in the emerging application scenarios. Many of these applications are safety critical, making it a high priority to ensure that the systems are free from malicious attacks. This work aims to detect vulnerabilities, that could be exploited by adversaries to compromise functional correctness, in the embedded firmware, which is challenging especially due to the absence of source code. In particular, we propose EM-Fuzz, a firmware vulnerability detection technique that tightly integrates fuzzing with real-time memory checking. Based on the memory instrumentation, the firmware fuzzing can not only be guided by the traditional branch coverage to generate high-quality seeds to explore hard-to-reach regions but also by the recorded memory sensitive operations to continuously exercise sensitive regions which are prone to being attacked. More importantly, the instrumentation integrates real-time memory checkers to expose memory vulnerabilities, which is not well-supported by existing fuzzers without source code. The experiments on several real-world embedded firmware such as OpenSSL demonstrate that EM-Fuzz significantly improves the performance of state-of-the-art fuzzing tools, such as AFL and AFLFast, with the coverage improvements of 93.98% and 46.89%, respectively. Furthermore, EM-Fuzz exposes a total of 23 vulnerabilities, with an average of about 7-h per vulnerability. AFL and AFLFast together find 10 vulnerabilities, costing about 13 h and 10-h per vulnerability on average, respectively. Out of these 23 vulnerabilities, 16 are previously unknown and have been reported to the upstream product vendors, 7 of which have been assigned with unique CVE identifiers in the U.S. National Vulnerability Database. Jian Gao 0008, Yu Jiang 0001, Zhe Liu 0001, Wanli Chang 0001, Xun Jiao 0002, Jia-Guang Sun 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 6 |
| 2020 | Dynamic DAG Scheduling on Multiprocessor Systems: Reliability, Energy, and MakespanabstractMultiprocessor systems are increasingly deployed in real-time applications, where reliability, energy consumption, and makespan are often the main scheduling objectives. In this work, we investigate the dynamic scheduling of tasks modeled by directed acyclic graphs (DAGs), which is an NP-hard problem with all existing methods being heuristics. Our contributions have two steps: 1) assuming that the allocation of DAG nodes to processors is given, we propose optimal energy allocation (OEA) and search-based OEA (SOEA)-the first optimal methods that minimize the energy consumption while satisfying the reliability requirement-for homogeneous and heterogeneous systems, respectively and 2) we present a novel scheduling algorithm out-degree scheduling (ODS) that allocates the DAG nodes according to their out-degrees, and considering energy consumption, reliability, as well as dynamic finish time. ODS dominates the widely applied heterogeneous earliest finish time (HEFT) in makespan. Combining SOEA with ODS makes a complete solution to the problem of dynamic DAG scheduling on multiprocessor systems, and achieves generally better results compared to the existing approaches. Specifically, in most cases, we are better on all the three objectives, i.e., reliability, energy, as well as makespan, and in other cases, we are better on some of the objectives. Jing Huang 0012, Renfa Li, Xun Jiao 0002, Yu Jiang 0001, Wanli Chang 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2020 | LEVAX: An Input-Aware Learning-Based Error Model of Voltage-Scaled Functional UnitsabstractAs Moore's Law comes to an end and transistor scaling increasingly falls short in improving energy efficiency, alternative computing paradigms are direly needed. This need is further highlighted by the overwhelming increase in computing demand posed by emerging applications, such as multimedia and data analysis. Fortunately, such driving workloads also present new opportunities since, thanks to their inherent error tolerance, they do not require completely accurate computations. Thus, by trading off accuracy for better performance or improved efficiency, approximate computing promises tremendous growth for future computing. Various approximation methods demonstrate the effectiveness of voltage scaling in functional units (FUs) for exploring this energy-error tradeoff. Yet, while an accurate error model is critical for assessing the error behavior of voltage-scaled FUs and its effects on application quality, existing error models of voltage-scaled FUs overlook the effects of input data and error rate disparity among different bits. To tackle this challenge, we propose LEVAX, an input-aware learning-based error model of voltage-scaled FUs that can predict the timing error rate (TER) for each output bit. This model is trained using random forest methods, with input features and output labels extracted from gate-level simulations. To validate its effectiveness and demonstrate its prediction accuracy, we use LEVAX on various FUs. Across all bit positions, voltage levels, and FUs, LEVAX achieves, on average, a relative error of 1.20%. LEVAX also achieves an average per-voltage root mean square error (RMSE) of 1.03% and per-bit RMSE of 1.17%. Exposing this error rate even up to the application level, LEVAX can estimate the quality of four image processing applications under-voltage scaling with an average accuracy of 97.9%. To the best of our knowledge, LEVAX is the first voltage scaling error model of FUs that can incorporate the effects of input data. Xun Jiao 0002, Dongning Ma, Wanli Chang 0001, Yu Jiang 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2019 | Engineering a Better Fuzzer with Synergically Integrated OptimizationsabstractState-of-the-art fuzzers implement various optimizations to enhance their performance. As the optimizations reside in different stages such as input seed selection and mutation, it is tempting to combine the optimizations in different stages. However, our initial attempts demonstrate that naive combination actually worsens the performance, which explains that most optimizations are still isolated by stages and metrics. In this paper, we present InteFuzz, the first framework that synergically integrates multiple fuzzing optimizations. We analyze the root cause for performance degradation in naive combination, and discover optimizations conflict in coverage criteria and optimization granularity. To resolve the conflicts, we propose a novel priority-based scheduling mechanism. The dynamic integration considers both branch-based and block-based coverage feedbacks that are used by most fuzzing optimizations. In our evaluation, we extract four optimizations from popular fuzzers such as AFLFast and FairFuzz and compare InteFuzz against naive combinations. The evaluation results show that InteFuzz outperforms the naive combination by 29% and 26% in path-and branch-coverage. Additionally, InteFuzz triggers 222 more unique crashes, and discovers 33 zero-day vulnerabilities in real-world projects with 12 registered as CVEs. Jie Liang 0006, Yuanliang Chen, Yu Jiang 0001, Zijiang Yang 0006, Chengnian Sun, Xun Jiao 0002, Jia-Guang Sun 0001 |
ISSRE | 7 |
| 2019 | Industry practice of coverage-guided enterprise Linux kernel fuzzingabstractCoverage-guided kernel fuzzing is a widely-used technique that has helped kernel developers and testers discover numerous vulnerabilities. However, due to the high complexity of application and hardware environment, there is little study on deploying fuzzing to the enterprise-level Linux kernel. In this paper, collaborating with the enterprise developers, we present the industry practice to deploy kernel fuzzing on four different enterprise Linux distributions that are responsible for internal business and external services of the company. We have addressed the following outstanding challenges when deploying a popular kernel fuzzer, syzkaller, to these enterprise Linux distributions: coverage support absence, kernel configuration inconsistency, bugs in shallow paths, and continuous fuzzing complexity. This leads to a vulnerability detection of 41 reproducible bugs which are previous unknown in these enterprise Linux kernel and 6 bugs with CVE IDs in U.S. National Vulnerability Database, including flaws that cause general protection fault, deadlock, and use-after-free. Heyuan Shi, Runzhe Wang, Xiaohai Shi, Xun Jiao 0002, Houbing Song, Yu Jiang 0001, Jia-Guang Sun 0001 |
ESEC/SIGSOFT FSE | 6 |
| 2019 | EnFuzz: Ensemble Fuzzing with Seed Synchronization among Diverse Fuzzers
Yuanliang Chen, Yu Jiang 0001, Fuchen Ma, Jie Liang 0006, Chijin Zhou, Xun Jiao 0002, Zhuo Su 0005 |
USENIX Security Symposium | 7 |
| 2019 | Polar: Function Code Aware Fuzz Testing of ICS ProtocolabstractIndustrial Control System (ICS) protocols are widely used to build communications among system components. Compared with common internet protocols, ICS protocols have more control over remote devices by carrying a specific field called “function code”, which assigns what the receive end should do. Therefore, it is of vital importance to ensure their correctness. However, traditional vulnerability detection techniques such as fuzz testing are challenged by the increasing complexity of these diverse ICS protocols. In this paper, we present a function code aware fuzzing framework — Polar, which automatically extracts semantic information from the ICS protocol and utilizes this information to accelerate security vulnerability detection. Based on static analysis and dynamic taint analysis, Polar initiates the values of the function code field and identifies some vulnerable operations. Then, novel semantic aware mutation and selection strategies are designed to optimize the fuzzing procedure. For evaluation, we implement Polar on top of two popular fuzzers — AFL and AFLFast, and conduct experiments on several widely used ICS protocols such as Modbus, IEC104, and IEC 61850. Results show that, compared with AFL and AFLFast, Polar achieves the same code coverage and bug detection numbers at the speed of 1.5X-12X. It also gains increase with 0%--91% more paths within 24 hours. Furthermore, Polar has exposed 10 previously unknown vulnerabilities in those protocols, 6 of which have been assigned unique CVE identifiers in the US National Vulnerability Database. Zhengxiong Luo 0002, Feilong Zuo, Yu Jiang 0001, Jian Gao 0008, Xun Jiao 0002, Jia-Guang Sun 0001 |
ACM Trans. Embed. Comput. Syst. | 5 |
| 2018 | Energy-efficient neural networks using approximate computation reuseabstractAs a problem-solving method, neural networks have shown broad success for medical applications, speech recognition, and natural language processing. Current hardware implementations of neural networks exhibit high energy consumption due to the intensive computing workloads. This paper proposes a methodology to design an energy-efficient neural network that effectively exploits computation reuse opportunities. To do so, we use Bloom filters (BFs) by tightly integrating them with computation units. BFs store and recall frequently occurring input patterns to reuse computations. We expand the opportunities for computation reuse by storing frequent input patterns specific to a given layer and using approximate pattern matching with hashing for limited data precision. This reconfigurable matching is key to achieving a “controllable approximation” for neural networks. To lower the energy consumption of BFs, we also use low-pow memristor arrays to implement BFs. Our experimental results show that for convolutional neural networks, the BFs enable 47.5% energy saving of multiplication operations, while incurring only 1% accuracy drop. While the actual savings will vary depending upon the extent of approximation and reuse, this paper presents a method for reducing computing workloads and improving energy efficiency. Xun Jiao 0002, Vahideh Akhlaghi, Yu Jiang 0001, Rajesh K. Gupta 0001 |
DATE | 1 |
| 2018 | CLIM: A Cross-Level Workload-Aware Timing Error Prediction Model for Functional UnitsabstractTiming errors that are caused by the timing violations of sensitized circuit paths, have emerged as an important threat to the reliability of synchronous digital circuits. To protect circuits from these timing errors, designers typically use a conservative timing margin, which leads to operational inefficiency. Existing adaptive approaches reduce such conservative margins by predicting the timing errors in advance and adjusting the timing margin adaptively. However, these error prediction approaches overlook the impact of input workload (i.e., operands) on path sensitization, thereby resulting in a loss of accuracy. The diversity of input operands leads to complex path sensitization behaviors, making them hard to represent in timing error modeling. In this paper, we propose CLIM, a cross-level workload-aware timing error prediction model for functional units (FUs). CLIM predicts whether there are timing errors in FU at two levels: bit-level and value-level. At the bit level or value level, CLIM predicts each output bit or entire output value as one of two classes: {timing correct, timing erroneous} as a function of input workload and clock period, respectively. We apply supervised learning methods to construct CLIM, by using input operands, computation history and circuit toggling as input features, as well as outputs' timing classes as labels. These training data are collected from gate-level simulations (GLS) of post place-and-route designs in TSMC 45nm process. We evaluate CLIM prediction accuracy for various FUs and compare it with baseline models. On average, CLIM exhibits 95 percent prediction accuracy at value-level, 97 percent at bit-level, and executes at a rate 173X faster than GLS. We utilize CLIM to analyze the value-level and bit-level reliability of FUs under random and real-world application workloads. At value-level, CLIM-based reliability estimation is within 2.8 percent deviation on average of detailed GLS ground truth. At bit-level, we introduce the concept of bit-level reliability specification of error-tolerant applications and compare this with the CLIM-based bit-level reliability estimation. By comparison, CLIM will classify the application quality into two classes: {acceptable, non-acceptable}. On average, 97 percent application quality classification is consistent with GLS ground truth. Xun Jiao 0002, Abbas Rahimi, Yu Jiang 0001, Jianguo Wang 0001, Hamed Fatemi, José Pineda de Gyvez, Rajesh K. Gupta 0001 |
IEEE Trans. Computers | 1 |
| 2017 | Combining structural and timing errors in overclocked inexact speculative addersabstractWorst-case design is used in IoT devices and high performance data centers to ensure reliability, leading to a power efficiency loss. Recently, approximate computing has been proposed to trade off accuracy for efficiency. In this paper, we use Inexact Speculative Adders, which redesign the adder architecture to shorten its critical path and improve performance, but introduces controlled structural errors. On the other hand, overclocking is used to reduce conservative timing guardbands but could normally introduce catastrophic timing errors, we thus apply a supervised learning model to overclock speculative adders and predict their timing errors. We build a methodology to combine both structural and timing errors and analyze how they interplay with each other to limit the overal errors. Xun Jiao 0002, Vincent Camus, Mattia Cacciotti, Yu Jiang 0001, Christian C. Enz, Rajesh K. Gupta 0001 |
DATE | 1 |
| 2017 | SLoT: A supervised learning model to predict dynamic timing errors of functional unitsabstractDynamic timing errors (DTEs), that are caused by the timing violations of sensitized critical timing paths, have emerged as an important threat to the reliability of digital circuits. Existing approaches model the DTEs without considering the impact of input operands on dynamic path sensitization, resulting in loss of accuracy. The diversity of input operands leads to complex path sensitization behaviors, making it hard to represent in DTE modeling. In this paper, we propose SLoT, a supervised learning model to predict the output of functional units (FUs) to be one of two timing classes: {timing correct, timing erroneous} as a function of input operands and clock period. We apply random forest classification (RFC) method to construct SLoT, by using input operands, computation history and circuit toggling as input features and outputs' timing classes as labels. The outputs' timing classes are measured using gate-level simulation (GLS) of a post place-and-route design in TSMC 45nm process. For evaluation, we apply SLoT to several FUs and on average 95% predictions are consistent with GLS, which is 6.3X higher compared to the existing instruction-level model. SLoT-based reliability analysis of FUs under different datasets can achieve 0.7-4.8% average difference compared with GLS-based analysis, and execute more than 20X faster than GLS. Xun Jiao 0002, Yu Jiang 0001, Abbas Rahimi, Rajesh K. Gupta 0001 |
DATE | 1 |
| 2017 | An assessment of vulnerability of hardware neural networks to dynamic voltage and temperature variationsabstractAs a problem solving method, neural networks have shown broad applicability from medical applications, speech recognition, and natural language processing. This success has even led to implementation of neural network algorithms into hardware. In this paper, we explore two questions: (a) to what extent microelectronic variations affects the quality of results by neural networks; and (b) if the answer to first question represents an opportunity to optimize the implementation of neural network algorithms. Regarding first question, variations are now increasingly common in aggressive process nodes and typically manifest as an increased frequency of timing errors. Combating variations - due to process and/or operating conditions - usually results in increased guardbands in circuit and architectural design, thus reducing the gains from process technology advances. Given the inherent resilience of neural networks due to adaptation of their learning parameters, one would expect the quality of results produced by neural networks to be relatively insensitive to the rising timing error rates caused by increased variations. On the contrary, using two frequently used neural networks (MLP and CNN), our results show that variations can significantly affect the inference accuracy. This paper outlines our assessment methodology and use of a cross-layer evaluation approach that extracts hardware-level errors from twenty different operating conditions and then inject such errors back to the software layer in an attempt to answer the second question posed above. Xun Jiao 0002, Mulong Luo, Jeng-Hau Lin, Rajesh K. Gupta 0001 |
ICCAD | 1 |
| 2016 | WILD: A workload-based learning model to predict dynamic delay of functional unitsabstractDynamic critical path analysis in modern processors is needed to reduce margins typically determined by the static timing analysis. Dynamic path analysis, however, is cost-prohibitive. In this paper, we propose WILD, a supervised learning model to predict dynamic delay of functional units (FUs) based on the input workload during execution. We measure the dynamic delay using switching activity generated through gate-level simulation of a post place-and-route design in TSMC 45nm process. We then look for `features' in the input data that influence dynamic path sensitization. Using these features we apply a logistic regression (LR) method to construct a predictive model trained and tested using three datasets: random, Sobel filter and Gaussian filter. We classify dynamic delay into five distinct classes. For a given test input, WILD predicts the class of output dynamic delay. On average across several FUs, 98.0% of WILD predictions are consistent with gate-level simulation. Using WILD-directed dynamic frequency scaling can improve instruction-level performance by 13%-44% compared to the state-of-the-art instruction-level timing model. Xun Jiao 0002, Yu Jiang 0001, Abbas Rahimi, Rajesh K. Gupta 0001 |
ICCD | 1 |