Honggang Yu

dblp:127/8463 · DBLP profile ↗
← Back
13ranked-venue papers
4as first author
7since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-authorArtificial intelligence and machine learning · 2 · 1 since 2021Security and privacy · 2 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Computer networks · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 Dynamic Deep Prompt Optimization for Defending Against Jailbreak Attacks on LLMs
abstract
Large Language Models (LLMs) demonstrate impressive capabilities across many applications but remain vulnerable to jailbreak attacks, which elicit harmful or unintended content. While model fine-tuning is an option for safety alignment, it is costly and prone to catastrophic forgetting. Prompt optimization has emerged as a promising alternative, yet existing prompt-based defenses typically rely on static modifications (e.g., fixed prefixes or suffixes) that cannot adapt to diverse and evolving attacks. We propose Dynamic Deep Prompt Optimization (DDPO), the first jailbreak defense based on deep prompt optimization. DDPO uses the target LLM's own intermediate layers as feature extractors to dynamically generate defensive embeddings via a lightweight multilayer perceptron. These tailored embeddings are then injected into a subsequent intermediate layer, enabling an input-dependent defense without modifying the LLM's weights. This design ensures high adaptability with minimal computational overhead. Experiments on a diverse set of models and attacks demonstrate that DDPO significantly outperforms static prompt optimization methods, particularly on weakly aligned models and when handling semantically ambiguous benign prompts, successfully distinguishing them from genuinely harmful requests.
Doniyorkhon Obidov, Honggang Yu, Kaichen Yang
AAAI2
2025 Guided by Noise: Vulnerable Poisoning Attack to Differentially Private Federated Learning
Siqi Dai, Yaodan Hu, Honggang Yu, Hanqiu Wang, Shuo Wang 0003
ICC3
2022 Graph Neural Network based Hardware Trojan Detection at Intermediate Representative for SoC Platforms
abstract
The rapid growth of the Internet of Things (IoT) industry has increased the demand for intellectual property (IP) cores. Increasing numbers of third-party vendors have raised security concerns for System-on-Chip (SoC) designers. With the growing complexity of SoC design, the workload is overwhelming for SoC designers to diagnose security vulnerabilities manually. Almost all existing SoC platforms are developed using SystemVerilog. However, there is a lack of reliable security static analysis tools for directly processing the SystemVerilog program. Due to its open-source, flexibility and extendability, RISC-V CPU has become an ideal platform for the IoT applications such as wearable devices, entertainment, smart thermostats, etc. As a result, assuring the trustworthiness of a given RISC-V system is highly desired. This paper proposes a graph neural network-based Trojan detection framework to protect the RISC-V SoC platform written in SystemVerilog from intruding malicious logic. The study is under-construction and planned to be validated on the Ariane RISC-V CPU with several peripheral IPs in the experimental section.
Weimin Fu, Honggang Yu, Orlando Arias, Kaichen Yang, Yier Jin, Tuba Yavuz, Xiaolong Guo 0001
ACM Great Lakes Symposium on VLSI2
2022 Generation of Black-box Audio Adversarial Examples Based on Gradient Approximation and Autoencoders
abstract
Deep Neural Network (DNN) is gaining popularity thanks to its ability to attain high accuracy and performance in various security-crucial scenarios. However, recent research shows that DNN-based Automatic Speech Recognition (ASR) systems are vulnerable to adversarial attacks. Specifically, these attacks mainly focus on formulating a process of adversarial example generation as iterative, optimization-based attacks. Although these attacks make significant progress, they still take large generation time to produce adversarial examples, which makes them difficult to be launched in real-world scenarios. In this article, we propose a real-time attack framework that utilizes the neural network trained by the gradient approximation method to generate adversarial examples on Keyword Spotting (KWS) systems. The experimental results show that these generated adversarial examples can easily fool a black-box KWS system to output incorrect results with only one inference. In comparison to previous works, our attack can achieve a higher success rate with less than 0.004 s. We also extend our work by presenting a novel ensemble audio adversarial attack and testing the attack on KWS systems equipped with existing defense mechanisms. The efficacy of the proposed attack is well supported by promising experimental results.
Po-Hao Huang, Honggang Yu, Max Panoff, Ting-Chi Wang
ACM J. Emerg. Technol. Comput. Syst.2
2022 A Review and Comparison of AI-enhanced Side Channel Analysis
abstract
Side Channel Analysis (SCA) presents a clear threat to privacy and security in modern computing systems. The vast majority of communications are secured through cryptographic algorithms. These algorithms are often provably-secure from a cryptographical perspective, but their implementation on real hardware introduces vulnerabilities. Adversaries can exploit these vulnerabilities to conduct SCA and recover confidential information, such as secret keys or internal states. The threat of SCA has greatly increased as machine learning, and in particular deep learning, enhanced attacks become more common. In this work, we will examine the latest state-of-the-art deep learning techniques for side channel analysis, the theory behind them, and how they are conducted. Our focus will be on profiling attacks using deep learning techniques, but we will also examine some new and emerging methodologies enhanced by deep learning techniques, such as non-profiled attacks, artificial trace generation, and others. Finally, different deep learning–enhanced SCA schemes attempted against the ANSSI SCA Database and their relative performance will be evaluated and compared. This will lead to new research directions to secure cryptographic implementations against the latest SCA attacks.
Max Panoff, Honggang Yu, Haoqi Shan, Yier Jin
ACM J. Emerg. Technol. Comput. Syst.2
2021 Robust Roadside Physical Adversarial Attack Against Deep Learning in Lidar Perception Modules
abstract
As Autonomous Vehicles (AVs) mature into viable transportation solutions, mitigating potential vehicle control security risks becomes increasingly important. Perception modules in AVs combine multiple sensors to perceive the surrounding environment. As such, they have been the focus of efforts to exploit the aforementioned risks due to their critical role in controlling autonomous driving technology. Despite extensive and thorough research into the vulnerability of camera-based sensors, vulnerabilities originating from Lidar sensors and their corresponding deep learning models in AVs remain comparatively untouched. Being aware that small roadside objects can be occasionally incorrectly identified as vehicles through on-board deep learning models, we propose a novel adversarial attack inspired by this phenomenon in both white-box and black-box scenarios. The adversarial attacks proposed in this paper are launched against deep learning models that perform object detection tasks through raw 3D points collected by a Lidar sensor in an autonomous driving scenario. In comparison to existing works, our attack creates not only adversarial point clouds in simulated environments, but also robust adversarial objects that can cause behavioral reactions in state of the art autonomous driving systems. Defense methods are then proposed and evaluated against this type of adversarial objects.
Kaichen Yang, Tzungyu Tsai, Honggang Yu, Max Panoff, Tsung-Yi Ho, Yier Jin
AsiaCCS3
2021 Cross-Device Profiled Side-Channel Attacks using Meta-Transfer Learning
abstract
Deep learning (DL) based profiling side channel analysis (SCA) pose a great threat to embedded devices. An adversary can break the target encryption engine through physical leakage of power or electromagnetic (EM) emanations collected from a profiling device. However, creating a successful DL based SCA model relies on a large amount of data. This presents a large barrier to those interested in applying DL for SCA. In this paper, we propose a novel attack mechanism that adopts meta-transfer learning to transfer DL networks among target devices by judiciously extracting information from a profiling device even using different side-channel sources. Supported by our method, a cross-device and/or cross-domain SCA attack becomes possible among different designs. In comparison to previous attack methodologies, we significantly reduce training costs and the number of traces $(\lt 3$ for power and $\lt 8$ for EM) required for SCA attacks on both unprotected or masked Advanced Encryption Standard (AES) implementations.
Honggang Yu, Haoqi Shan, Max Panoff, Yier Jin
DAC1
2020 Beyond Digital Domain: Fooling Deep Learning Based Recognition System in Physical World
abstract
Adversarial examples that can fool deep neural network (DNN) models in computer vision present a growing threat. The current methods of launching adversarial attacks concentrate on attacking image classifiers by adding noise to digital inputs. The problem of attacking object detection models and adversarial attacks in physical world are rarely touched. Some prior works are proposed to launch physical adversarial attack against object detection models, but limited by certain aspects. In this paper, we propose a novel physical adversarial attack targeting object detection models. Instead of simply printing images, we manufacture real metal objects that could achieve the adversarial effect. In both indoor and outdoor experiments we show our physical adversarial objects can fool widely applied object detection models including SSD, YOLO and Faster R-CNN in various environments. We also test our attack in a variety of commercial platforms for object detection and demonstrate that our attack is still valid on these platforms. Consider the potential defense mechanisms our adversarial objects may encounter, we conduct a series of experiments to evaluate the effect of existing defense methods on our physical attack.
Kaichen Yang, Tzungyu Tsai, Honggang Yu, Tsung-Yi Ho, Yier Jin
AAAI3
2020 Audio Adversarial Examples Generation with Recurrent Neural Networks*
abstract
Previous methods of performing adversarial attacks against speech recognition systems often treat this problem as a solely optimization problem and require iterative updates to generate optimal solutions. Although they can achieve high success rate, the process is too computational heavy even with the help of GPU. In this paper, we introduce a new type of real-time adversarial attack methodology, which applies Recurrent Neural Networks (RNN) with a two-step training process to generate adversarial examples targeting a Keyword Spotting (KWS) system. We extend our attack to physical world by adding extra constraints in order to eliminate the distortions in real world. In the experiment, we launch a real-time adversarial attack on the KWS system both in digital and physical world. The experimental results of digital world show that the execution time of our attack is more than 400 times faster than the state-of-the-art attack (i.e., C&W attack) with the comparable attack success rate. In physical world, after adding extra constraints, the perturbation becomes more robust such that the average attack success rate increases from 40.3% to 84.3%.
Kuei-Huan Chang, Po-Hao Huang, Honggang Yu, Yier Jin, Ting-Chi Wang
ASP-DAC3
2020 CloudLeak: Large-Scale Deep Learning Models Stealing Through Adversarial Examples
Honggang Yu, Kaichen Yang, Teng Zhang 0002, Yun-Yun Tsai, Tsung-Yi Ho, Yier Jin
NDSS1
2014 A Multiscale Optimization Approach to Detect Exudates in the Macula
abstract
Pathologies that occur on or near the fovea, such as clinically significant macular edema (CSME), represent high risk for vision loss. The presence of exudates, lipid residues of serous leakage from damaged capillaries, has been associated with CSME, in particular if they are located one optic disc-diameter away from the fovea. In this paper, we present an automatic system to detect exudates in the macula. Our approach uses optimal thresholding of instantaneous amplitude (IA) components that are extracted from multiple frequency scales to generate candidate exudate regions. For each candidate region, we extract color, shape, and texture features that are used for classification. Classification is performed using partial least squares (PLS). We tested the performance of the system on two different databases of 652 and 400 images. The system achieved an area under the receiver operator characteristic curve (AUC) of 0.96 for the combination of both databases and an AUC of 0.97 for each of them when they were evaluated independently.
Carla Agurto, Víctor Murray, Honggang Yu, Jeffrey Wigdahl, Marios S. Pattichis, Sheila C. Nemeth, E. Simon Barriga, Peter Soliz
IEEE J. Biomed. Health Informatics3
2012 Fast Localization and Segmentation of Optic Disk in Retinal Images Using Directional Matched Filtering and Level Sets
abstract
The optic disk (OD) center and margin are typically requisite landmarks in establishing a frame of reference for classifying retinal and optic nerve pathology. Reliable and efficient OD localization and segmentation are important tasks in automatic eye disease screening. This paper presents a new, fast, and fully automatic OD localization and segmentation algorithm developed for retinal disease screening. First, OD location candidates are identified using template matching. The template is designed to adapt to different image resolutions. Then, vessel characteristics (patterns) on the OD are used to determine OD location. Initialized by the detected OD center and estimated OD radius, a fast, hybrid level-set model, which combines region and local gradient information, is applied to the segmentation of the disk boundary. Morphological filtering is used to remove blood vessels and bright regions other than the OD that affect segmentation in the peripapillary region. Optimization of the model parameters and their effect on the model performance are considered. Evaluation was based on 1200 images from the publicly available MESSIDOR database. The OD location methodology succeeded in 1189 out of 1200 images (99% success). The average mean absolute distance between the segmented boundary and the reference standard is 10% of the estimated OD radius for all image sizes. Its efficiency, robustness, and accuracy make the OD localization and segmentation scheme described herein suitable for automatic retinal disease screening in a variety of clinical settings.
Honggang Yu, E. Simon Barriga, Carla Agurto, Sebastian Echegaray, Marios S. Pattichis, Wendall Bauman, Peter Soliz
IEEE Trans. Inf. Technol. Biomed.1
2005 A robust multi-view freehand three-dimensional ultrasound imaging system using volumetric registration
abstract
In this paper, we describe a freehand, three-dimensional ultrasound imaging system. The system uses an electromagnetic position and orientation measurement device to capture two-dimensional ultrasound images at arbitrary planar orientations in space. For robust performance, we use a novel electromagnetic interference detection algorithm that can be used to estimate the probability density function of position and orientation measurement errors. Another important contribution of the proposed system is its ability to reconstruct from multiple standard views. The multi-view reconstruction procedure results in significant reduction in reconstruction error. The system uses object-based 3D volume registration, allowing for arbitrary rigid object movements in inter-view acquisition. The proposed system has been validated on simulated data and a physical, 3D ultrasound calibration phantom. Quantitative experimental results demonstrate the effectiveness of the 3D registration system, and a significant reduction in the mean-squared error via the use of the proposed multi-view reconstruction method.
Honggang Yu, Marios S. Pattichis, M. Beth Goens
SMC1