Shan Li 0008

dblp:15/1152-8 · DBLP profile ↗
← Back
5ranked-venue papers
1as first author
5since 2021 · last 2026
0000-0001-5961-3969ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 1 first-author · 5 since 2021
YearPublicationVenuePosition
2026 Twins: Hardware Similarity Evaluation Framework Using Graph Neural Network
abstract
The globalization of the integrated circuit supply chain has introduced untrustworthy entities at various stages, arousing increasing attention to hardware security research from both academia and industry. Some tasks in hardware security research require matching two hardware designs. For example, in gate-level netlist reverse engineering, after recovering module boundaries and hierarchical structure from a netlist, one must match each candidate module against known library components to validate its functionality. Likewise, in Intellectual Property (IP) piracy detection, a suspected infringing IP can be matched against its original counterpart to determine whether infringement has occurred. We design and implement a hardware similarity evaluation framework called Twins. We develop two versions of the framework, called Twins-v1 with the basic Graph Neural Network (GNN) model and Twins-v2 with the node-independent GNN model, respectively. Twins employs a more effective training approach that substantially reduces training time and improves evaluation metrics compared to the current state-of-the-art models. Furthermore, to the best of our knowledge, Twins-v2 represents the first work to use independent graph convolutional network layers based on different node types in the context of hardware security research. The novel netlist graph extraction method has also been experimentally demonstrated to outperform the previously employed data flow graph approach in hardware similarity evaluation tasks. After conducting experimental evaluations on a dataset comprising 305 circuits, both Twins-v1 and Twins-v2 significantly surpass existing methods in terms of prediction accuracy and efficiency.
Haihua Shen, Zirui Jiang, Shan Li 0008, Xiao Ji, Huawei Li 0001
ACM Trans. Design Autom. Electr. Syst.4
2025 Oxpecker: Leaking Secrets via Fetch Target Queue
abstract
Modern processors integrate carefully designed micro-architectural components within the front-end to optimize performance. These components include instruction cache, micro-operation cache, and instruction prefetcher. Through experimentation, we observed that the rate of instruction generation in the fetch unit markedly exceeds the execution rate in the decode unit. However, existing frameworks of processors fail to explain this phenomenon. Consequently, we empirically validate the presence of an optimization feature, referred to as the Fetch Target Queue (FTQ), within the Intel processor. To the best of our knowledge, our study represents the first empirical validation of FTQ across various Intel processors and provides a comprehensive characterization of unrecorded FTQ micro-structural details on Intel processors. Our analysis uncovers overlooked insights that front-end rollbacks caused by the incorrectly ordered instructions or mismatched instruction lengths stored in FTQ introduce specific execution latencies. Based on these observations, we introduce the Oxpecker attack, consisting of two attack primitives, which leverages the FTQ to construct novel side-channel attacks. We construct two distinct exploitation scenarios for each attack primitive to demonstrate the Oxpecker attack’s capability to leak secret control flow information and break Kernel Address Space Layout Randomization.
Shan Li 0008, Zheliang Xu, Haihua Shen, Huawei Li 0001
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.1
2023 BGNN-HT: Bidirectional Graph Neural Network for Hardware Trojan Cells Detection at Gate Level
abstract
Recently, complex process of production forces Integrated Circuit (IC) to be designed by third-party Electronic Design Automation (EDA) tool or outsourcing, which will create an opportunity for malicious circuits to be inserted into ICs, known as Hardware Trojan (HT). Up to now, there are still challenges in existing researches, such as dependence on the golden model, unclear position of HTs, and difficulty in unknown HT detection. In this paper, a HT detection model called BGNN-HT based on bidirectional graph neural network is proposed, which can detect HT cells by assessing the structure of its surrounding cells at gate level. BGNN-HT can precisely detect HT cells in ICs, and it does not require the golden model or manual feature extraction, which greatly reduces the difficulty of detection and can adapt to unknown HTs. Experiments are conducted on Trust-hub benchmarks including TRIT-TC and TRIT-TS to evaluate our model. The results show that when detecting unknown circuits and HTs, BGNN-HT can reach 96% True Positive Rate (TPR) and 99% True Negative Rate (TNR) in various datasets, and even 99% TPR and TNR in TRIT-TC and TRIT-TS.
Peiheng Zhan, Haihua Shen, Shan Li 0008, Huawei Li 0001
ISCAS3
2022 A Hardware Trojan Trigger Localization Method in RTL based on Control Flow Features
abstract
Most proposed studies focus on detecting the entire hardware Trojan (HT) in one step, which is very difficult. Since the results of most proposed method have false positive, it is still necessary to check the detection results manually in real-world application. Therefore, what we need is an accurate and efficient method to locate the core part of HTs, which can assist designers to the follow-up verification and modification. In this paper, we define several RTL features based on hardware Trojan trigger control flow characteristics, and then use these features to train a decision tree-based hardware Trojan trigger localization model. The experimental results on Trust-Hub show that our method can obtain 100% true positive rate on all benchmarks and average 98.20% true negative rate. And our method can complete feature extraction and HT trigger localization within 0.1s on average.
Haihua Shen, Shan Li 0008, Huawei Li 0001
ATS3
2021 SeGa: A Trojan Detection Method Combined With Gate Semantics
abstract
Hardware Trojan has always been a major security threat to the integrated circuit industry. In this article, we propose a novel circuit gate embedding method called SeGa, which extracts the “semantic information” of gates in the netlist. The feature vectors that representing each type of gate extracted by SeGa are used as the inputs to the neural network classification model to detect Trojans. The experimental results on TRIT-TC benchmark show that SeGa can improve the performance of the neural network classification model to detect the Trojan gate sequence.
Yunying Ye, Shan Li 0008, Haihua Shen, Huawei Li 0001, Xiaowei Li 0001
ATS2