Dake Chen

dblp:131/7232 · DBLP profile ↗
← Back
8ranked-venue papers
2as first author
8since 2021 · last 2024
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 4 · 2 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Mitigate Replication and Copying in Diffusion Models with Generalized Caption and Dual Fusion Enhancement
abstract
While diffusion models demonstrate a remarkable capability for generating high-quality images, their tendency to ‘replicate’ training data raises privacy concerns. Although recent research suggests that this replication may stem from the insufficient generalization of training data captions and duplication of training images, effective mitigation strategies remain elusive. To address this gap, our paper first introduces a generality score that measures the caption generality and employ large language model (LLM) to generalize training captions. Subsequently, we leverage generalized captions and propose a novel dual fusion enhancement approach to mitigate the replication of diffusion models. Our empirical results demonstrate that our proposed methods can significantly reduce replication by 43.5% compared to the original diffusion model while maintaining the diversity and quality of generations. Code is available at https://github.com/HowardLi0816/dual-fusion-diffusion.
Dake Chen, Peter A. Beerel
ICASSP2
2024 What Makes Vision Transformers Robust Towards Bit-Flip Attack?
Souvik Kundu 0002, Dake Chen, Peter A. Beerel
ICPR (8)3
2023 C2PI: An Efficient Crypto-Clear Two-Party Neural Network Private Inference
abstract
Recently, private inference (PI) has addressed the rising concern over data and model privacy in machine learning inference as a service. However, existing PI frameworks suffer from high computational and communication costs due to the expensive multi-party computation (MPC) protocols. Existing literature has developed lighter MPC protocols to yield more efficient PI schemes. We, in contrast, propose to lighten them by introducing an empirically-defined privacy evaluation. To that end, we reformulate the threat model of PI and use inference data privacy attacks (IDPAs) to evaluate data privacy. We then present an enhanced IDPA, named distillation-based inverse-network attack (DINA), for improved privacy evaluation. Finally, we leverage the findings from DINA and propose C2PI, a two-party PI framework presenting an efficient partitioning of the neural network model and requiring only the initial few layers to be performed with MPC protocols. Based on our experimental evaluations, relaxing the formal data privacy guarantees C2PI can speed up existing PI frameworks, including Delphi [1] and Cheetah [2], up to 2.89× and 3.88× under LAN and WAN settings, respectively, and save up to 2.75× communication costs.
Dake Chen, Souvik Kundu 0002, Haomei Liu, Ruiheng Peng, Peter A. Beerel
DAC2
2023 Island-based Random Dynamic Voltage Scaling vs ML-Enhanced Power Side-Channel Attacks
abstract
In this paper, we describe and analyze an island-based random dynamic voltage scaling (iRDVS) approach to thwart power side-channel attacks. We first analyze the impact of the number of independent voltage islands on the resulting signal-to-noise ratio and trace misalignment. As part of our analysis of misalignment, we propose a novel unsupervised machine learning (ML) based attack that is effective on systems with three or fewer independent voltages. Our results show that iRDVS with four voltage islands, however, cannot be broken with 200k encryption traces, suggesting that iRDVS can be effective. We finish the talk by describing an iRDVS test chip in a 12nm FinFet process that incorporates three variants of an AES-256 accelerator, all originating from the same RTL. This included a synchronous core, an asynchronous core with no protection, and a core employing the iRDVS technique using asynchronous logic. Lab measurements from the chips indicated that both unprotected variants failed the test vector leakage assessment (TVLA) security metric test, while the iRDVS was proven secure in a variety of configurations.
Dake Chen, Christine Goins, Maxwell Waugaman, Georgios D. Dimou, Peter A. Beerel
ACM Great Lakes Symposium on VLSI1
2023 RNA-ViT: Reduced-Dimension Approximate Normalized Attention Vision Transformers for Latency Efficient Private Inference
abstract
The concern over data and model privacy in machine learning inference as a service (MLaaS) has led to the development of private inference (PI) techniques. However, existing PI frameworks, especially those designed for large models such as vision transformers (ViT), suffer from high computational and communication overheads caused by the expensive multi-party computation (MPC) protocols. The encrypted attention module that involves the softmax operation contributes significantly to this overhead. In this work, we present a family of models dubbed RNA-ViT, that leverage a novel attention module called reduced-dimension approximate normalized attention and a latency efficient GeLU-alternative layer. In particular, RNA-ViT uses two novel techniques to improve PI efficiency in ViTs: a reduced-dimension normalized attention (RNA) architecture and a high order polynomial (HOP) softmax approximation for latency efficient normalization. We also propose a novel metric, accuracy-to-latency ratio (A2L), to evaluate modules in terms of their accuracy and PI latency. Based on this metric, we perform an analysis to identify a nonlinearity module with improved PI efficiency. Our extensive experiments show that RNA-ViT can achieve average 3.53×, 3.54×, 1.66× lower PI latency with an average accuracy improvement of 0.93%, 2.04%, and 2.73% compared to the state-of-the-art scheme MPCViT [1], on CIFAR-10, CIFAR-100, and Tiny-ImageNet, respectively.
Dake Chen, Souvik Kundu 0002, Peter A. Beerel
ICCAD1
2023 SAL-ViT: Towards Latency Efficient Private Inference on ViT using Selective Attention Search with a Learnable Softmax Approximation
abstract
Recently, private inference (PI) has addressed the rising concern over data and model privacy in machine learning inference as a service. However, existing PI frameworks suffer from high computational and communication overheads due to the expensive multi-party computation (MPC) protocols, particularly for large models such as vision transformers (ViT). The majority of this overhead is due to the encrypted softmax operation in each self-attention layer. In this work, we present SAL-ViT with two novel techniques to boost PI efficiency on ViTs. Our first technique is a learnable PI-efficient approximation to softmax, namely, learnable 2Quad (L2Q), that introduces learnable scaling and shifting parameters to the prior 2Quad softmax approximation, enabling improvement in accuracy. Then, given our observation that external attention (EA) presents lower PI latency than widely-adopted self-attention (SA) at the cost of accuracy, we present a selective attention search (SAS) method to integrate the strength of EA and SA. Specifically, for a given lightweight EA ViT, we leverage a constrained optimization procedure to selectively search and replace EA modules with SA alternatives to maximize the accuracy. Our extensive experiments show that our SAL-ViT can averagely achieve 1.28×, 1.28×, 1.14× lower PI latency with 1.79%, 1.41%, and 2.08% higher accuracy compared to the existing alternatives, on CIFAR-10, CIFAR-100, and Tiny-ImageNet, respectively.
Dake Chen, Souvik Kundu 0002, Peter A. Beerel
ICCV2
2023 On the Security of Sequential Logic Locking Against Oracle-Guided Attacks
abstract
The Boolean satisfiability (SAT) attack is an oracle-guided attack that can break most combinational logic locking schemes by efficiently pruning out all the wrong keys from the search space. Extending such an attack to sequential logic locking requires multiple time-consuming rounds of SAT solving, performed using an “unrolled” version of the sequential circuit, and model checking, used to determine the successful termination of the attack. This article addresses these challenges by formally characterizing the relation between the minimum unrolling depth required to prune out the wrong keys of an SAT-based attack and a notion of functional corruptibility (FC) for sequential circuits, which can be efficiently estimated from a locked circuit to indicate the progress of an SAT-based attack. Based on this analysis, we present an FC-guided SAT-based attack that can significantly reduce unnecessary SAT and model-checking tasks. We present two versions of the attack, namely,Fun-SATandFun-SAT+, based on whether the attacker has a priori knowledge of the key length.Fun-SATaims to find the correct key sequence, whileFun-SAT+aims to retrieve the correct initial state of the circuit. The numerical evaluation shows thatFun-SATcan be, on average,$90\boldsymbol {\times }$faster than previous attacks against state-of-the-art locking methods. On the other hand, when using an approximate termination condition,Fun-SAT+can find an initial state that leads to at most 0.1% FC in 76.9% instances that would otherwise time out after one day.
Yinghua Hu, Kaixin Yang, Dake Chen, Peter A. Beerel, Pierluigi Nuzzo 0002
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.4
2021 Exploiting the Potential of Coastal GNSS-R for Improving Storm Surge Modeling
abstract
The potential mymargin for improving storm surge simulation is demonstrated by using winds derived from ground-based Global Navigation Satellite System Reflectometry (GNSS-R) that uses BeiDou geostationary Earth orbit (GEO) satellite signals. We reconstruct wind fields by blending GNSS-R coastal winds with the European Center for Median Weather Forecasts (ECMWF) reanalysis product. The reconstructed winds agree well with the weather station data collected at Yangjiang in Guangdong, China. The ECMWF winds and the reconstructed winds are used to force a storm surge model off the Chinese coast during typhoon Utor 2013, respectively. The model storm surges forced by the reconstructed winds agree substantially better with tide-gauge observations than those forced by the ECMWF winds. The average error has been reduced by 30.5% from 24.3 cm with the ECMWF winds to 16.9 cm with the reconstructed winds. This letter suggests that GNSS-R coastal winds can have a positive impact on the accuracy of storm surge hindcasting directly and forecasting indirectly by improving the initial conditions.
Xiaohui Li 0011, Dongkai Yang, Guoqi Han, Lei Yang 0034, Jiuke Wang, Jingsong Yang, Dake Chen, Gang Zheng 0001
IEEE Geosci. Remote. Sens. Lett.7