Chunlu Wang

dblp:16/2615 · DBLP profile ↗
← Back
16ranked-venue papers
2as first author
8since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 5 since 2021Artificial intelligence and machine learning · 4Computer networks · 3 · 2 first-authorSoftware engineering, systems software and programming languages · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 DecIR: Enhancing LLM-based LLVM IR decompilation through program analysis
Yuzhang Li, Chunlu Wang
Sci. Comput. Program.4
2025 A Novel Method for Detecting Geological Anomalies in Tunnel Space Using Multiparameter Elastic Full Waveform Inversion
abstract
During tunnel excavation, precise detection of low-velocity anomalies ahead of the tunnel face is crucial for ensuring the smooth construction of the tunnel project. However, current tunnel seismic prediction (TSP) system can only provide reflection interface imaging, which lacks the required accuracy and reliability in seismic data interpretation. In response to these limitations, this study presents a tunnel geological anomaly detection approach by utilizing the developed GEI-TSP system in combination with the multiparameter elastic full waveform inversion (EFWI) technique. This approach enables the retrieval of multiparameter distributions, including P-wave velocity, S-wave velocity, and density, for the geological anomalies ahead of the tunnel face, thereby enhancing the detection reliability. First, we design the tunnel forward model to generate the hybrid seismic data encompassing both body waves and Rayleigh surface waves. Second, we derive gradients and pseudo-Hessian operators using a wave mode decomposition strategy to mitigate crosstalk effects among various model parameters and improve inversion accuracy. With an activity level measurement, we conduct a novel model updating strategy to balance contributions from different wavefield combinations and avoid crosstalk between velocities and density. Experiments with several theoretical tunnel models demonstrate the feasibility of the proposed detection method and highlight its substantial potential for imaging anomalies. Meanwhile, the inversion performance of the proposed detection method is evaluated under different noise levels and observation layouts. Finally, a comprehensive assessment of the computational and storage performance of this method is carried out.
Chunyang Pei, Zhixian Zhu, Chunlu Wang, Jiwu Li, Xiaohua Zhou, Linhang Zhang, Zubin Chen
IEEE Trans. Geosci. Remote. Sens.3
2024 Whisper: Timing the Transient Execution to Leak Secrets and Break KASLR
abstract
The vulnerabilities of transient execution have been exploited in many side-channel attacks (SCA). We report Whisper, a novel transient execution timing (TET) side channel, which is based on the execution time difference of transient execution under different conditions. We develop TET version of SCAs including Meltdown, Zombieload, and Spectre-RSB that use Whisper as covert channel to leak information. We further propose TET-KASLR to break the kernel address space layout randomization (KASLR) mechanism under the protection of KPTI and FLARE. These attacks are simple to implement and can bypass the existing mitigation methods because the TET side channel relies on execution time that can be conveniently obtained by architectural level timing analysis. We demonstrate the correctness and effectiveness of these attacks on various x86-64 CPUs. The root cause of Whisper is analyzed with our toolset built on performance monitor unit (PMU) and potential defense against Whisper is also discussed.
Yu Jin 0010, Chunlu Wang, Pengfei Qiu, Chang Liu 0117, Hongpei Zheng, Yongqiang Lyu 0001, Xiaoyong Li 0003, Gang Qu 0001, Dongsheng Wang 0002
DAC2
2024 IRaDT: LLVM IR as Target for Efficient Neural Decompilation
abstract
Decompilation is a widely utilized technique in reverse engineering, aimed at restoring binary code to human-readable high-level language code. However, the readability of the output from traditional decompilers is often poor. With advancements in language models, several learning-based decompilation methods have emerged. Nevertheless, the probabilistic nature of language models leads to outputs whose correctness cannot be guaranteed, necessitating further analysis by engineers to identify the corresponding functionality of the code. Inspired by compiler toolchains, we propose a novel approach to enhance the effectiveness of language models in decompilation tasks. Traditional rule-based methods and learning-based techniques are fused together in our approach, drawing insights from both paradigms. Specifically, we present a pre-trained sequence-to-sequence model called IRaDT tailored to refine decompilation outputs at the intermediate representation level. Through this hybridization, we aim to address the limitations of existing methodologies and achieve more accurate and robust decompilation. We construct a diverse decompilation dataset targeting IR and evaluated IRaDT based on this dataset. The experimental results indicate that IRaDT has the ability to improve the readability of IR while ensuring its compileability, achieving a 74% improvement compared to RetDec and a 93% improvement compared to ChatGPT.
Yuzhang Li, Chunlu Wang
Int. J. Softw. Eng. Knowl. Eng.3
2023 PMU-Leaker: Performance Monitor Unit-Based Realization of Cache Side-Channel Attacks
abstract
Performance Monitor Unit (PMU) is a special hardware module in processors that contains a set of counters to record various architectural and micro-architectural events. In this paper, we propose PMU-Leaker, a novel realization of all existing cache side-channel attacks where accurate execution time measurements are replaced by information leaked through PMU. The efficacy of PMU-Leaker is demonstrated by (1) leaking the secret data stored in Intel Software Guard Extensions (SGX) with the transient execution vulnerabilities including Spectre and ZombieLoad and (2) extracting the encryption key of a victim AES performed in SGX. We perform thorough experiments on a DELL Inspiron 15-7560 laptop that has an Intel® Core™ i5-7200U processor with the Kaby Lake architecture and the results show that, among the 176 PMU counters, 24 of them are vulnerable and can be used to launch the PMU-Leaker attack.
Pengfei Qiu, Dongsheng Wang 0002, Yongqiang Lyu 0001, Chunlu Wang, Chang Liu 0117, Rihui Sun, Gang Qu 0001
ASP-DAC5
2023 Exploration and Exploitation of Hidden PMU Events
abstract
Performance Monitoring Unit (PMU) is a common hardware module in modern processors that monitors the processor's architectural and microarchitectural events (PMU events) for CPU performance analysis and optimization. Vendors publish PMU events in documents such as Intel's Software Development Manual (SDM) and ARM processor technical reference manuals. In this paper, we report our findings that these documented PMU events are only a very small portion of the PMU event space. We define hidden PMU events as those that can be triggered in the instruction's execution but are not documented by the vendors. The hidden PMU events may not be as useful as the documented ones for CPU performance analysis. However, they might introduce security vulnerabilities. We develop an automated tool to traverse all the possible PMU events during the execution of each valid instruction to locate the hidden PMU events. On six Intel processors with different micro-architectures, where there are about 307 documented PMU core events on average, our tool finds an average of 17,361 hidden PMU events. We further demonstrate the security implications in both defense and attack of these hidden PMU events. Our experimental results show that up to 6,613 hidden PMU events on the i7-6700 can be used to detect transient execution attacks and 1,192 hidden PMU events can be exploited for side-channel attacks.
Pengfei Qiu, Chunlu Wang, Yu Jin 0010, Xiaoyong Li 0003, Dongsheng Wang 0002, Gang Qu 0001
ICCAD3
2023 PMU-Spill: A New Side Channel for Transient Execution Attacks
abstract
Performance Monitor Unit (PMU) is an important hardware module in mainstream processors, which counts various architectural and microarchitectural events during the run-time of the processor. Theoretically, if an instruction is executed but doesn’t successfully retire (this is called transient execution), the events it triggers needn’t be recorded by PMU. However, in this study, we discover that current PMU implementations are capable of recording some events that are triggered in transient executions, which is a hardware vulnerability. Based on this vulnerability, we propose the PMU-Spill attack, a new kind of side channel attack that enables attackers to maliciously leak secret data in transient executions. We perform a thorough study of PMU counters on five Intel processors and find that they all have vulnerable PMU counters that will measure transient execution events (there are 162 vulnerable PMU counters among all the 383 PMU counters). We demonstrate on real hardware that 112 vulnerable PMU counters can be utilized in PMU-Spill attack to leak the secret data protected by Intel Software Guard Extensions (SGX). Besides, our experiments suggest that the throughput of PMU-Spill attack is up to 291.2 bytes per second (Bps) with an error rate of 2.45% on average. This discovery and the corresponding mitigation methods can be helpful for microarchitecture designers to reevaluate the security risks induced by the PMU module.
Pengfei Qiu, Chang Liu 0117, Dongsheng Wang 0002, Yongqiang Lyu 0001, Xiaoyong Li 0003, Chunlu Wang, Gang Qu 0001
IEEE Trans. Circuits Syst. I Regul. Pap.7
2021 VoltJockey: A New Dynamic Voltage Scaling-Based Fault Injection Attack on Intel SGX
abstract
Intel software guard extensions (SGX) increase the security of applications by enabling them to be performed in a highly trusted space (called enclave). Most state-of-the-art attacks on SGX focus on either mining the software vulnerabilities in the enclave or speculating the secret data with side channels. In this study, we report our recent work on breaking SGX by inducing voltage-oriented hardware faults. The novelty and importance of this attack are that it is completely controlled by software and does not require any security vulnerability in the software. Our proposed attack, called VoltJockey, exploits a vulnerability in the implementation of dynamic voltage and frequency scaling (DVFS) that achieves energy saving by dynamically adjusting the processor's operating voltage and thus clock frequency. However, if the operating voltage is lower than a certain critical level, the circuit's timing constraint will fail and hardware fault would be created. We propose to deliberately trigger such voltage-oriented hardware faults by a loadable kernel module that can set the processor's voltage through Intel's undocumented model-specific register (MSR). We first utilize the module to furnish the processor with a transient low voltage with controlled timing to inject a temporal fault into the target location of the program running in the enclave. Then, we perform a differential fault attack on the outputs before and after the injection of faults. For demonstration, we successfully deploy the proposed attack to extract the key of an AES executed in the enclave and lead an SGX-protected RSA to output our specified result.
Pengfei Qiu, Dongsheng Wang 0002, Yongqiang Lyu 0001, Ruidong Tian, Chunlu Wang, Gang Qu 0001
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.5
2019 An Ant Colony Optimization based Approach to Adjust Public Transportation Network
abstract
Planning public transportation network plays an important role in improving operational efficiency and service level. There are numerous literature on the planning of public transportation network; however, most of those works aim to plan the entire network. For big cities, planning the entire network is infeasible because it is impossible to replace the existing network with a whole new one. In this paper, we propose an ant colony optimization (ACO) based approach to adjust existing bus lines in the transportation network. ACO is used to adjust the existing bus lines one by one. To make ants in ACO able to plan new bus lines similar to existing ones, some pheromone is put on the routes of existing bus lines. As we concern the performance of the entire network, an evaluation function is devised to evaluate a bus line's route found by ACO using the performance of entire network. A penalty mechanism is introduced into the approach to avoid generating infeasible bus lines. The approach is applied to problem instances in literature as well as a real-world problem. Experimental results show that the proposed method can achieve satisfactory bus lines with low transfer rate and high direct rate.
Chunlu Wang, Xingquan Zuo
CEC2
2016 A MOEA/D based approach for hospital department layout design
abstract
Although there exist numerous literatures on facility layout in manufacturing systems, studies on department layout in hospitals are relatively scarce. In this paper, we proposed a MOEA/D based approach for a hospital department layout problem, where three objectives are simultaneously optimized, namely patient flow cost, the closeness of departments and rearrangement cost. A constraint handling technology is introduced to deal with infeasible solutions. Experiments show that the proposed approach is able to get satisfactory Pareto solutions with lower patients' flow cost and the closeness compared to the original layout, and that the optimized layouts decrease the patients' move time, thereby improving quality of service.
Yanmei Ma, Xingquan Zuo, Xuewen Huang, Fulai Gu, Chunlu Wang, Xinchao Zhao
CEC5
2015 A MOEA/D based approach for solving robust double row layout problem
abstract
In this paper, we propose a robust double row layout problem (RDRLP), where the material flow between any two machines may vary in different periods. A MOEA/D based solution approach is proposed to solve it. First, MOEA/D is used to find a collection of non-dominated machine sequences. Then, for each found machine sequence, MOEA/D is used to produce a set of non-dominated solutions. Finally, the final set of Pareto solutions is constructed from all the produced non-dominated solutions. The crowding-distance calculation is added to the procedure of updating the elite population to make nondominated solutions distributed uniformly. An integer coding and a real-valued coding with their corresponding crossover and mutation operators are presented. This approach is applied to a number of problem instances with 10-35 facilities and 3-5 periods. Experimental results show that the approach is able to effectively solve this problem.
Lingling Tang, Xingquan Zuo, Chunlu Wang, Xinchao Zhao
CEC3
2013 Effectively auditing IaaS cloud servers
abstract
Cloud computing is broadly recognized as one of major factors in achieving more flexible, scalable, and efficient systems. However, as customers lose the direct control of their data and applications hosted by cloud providers, the trustworthiness of cloud services is a main issue that hinders the deployment of cloud applications. In this paper, we have developed a novel framework to detect compromises on physical servers in cloud services, via remote attestation with a Trusted Third Party (TTP). Furthermore, to avoid the TTP becoming a bottleneck, we have designed a cloud based TTP platform, using a small private cloud to audit large clouds. We have implemented a prototype system, and evaluated it with several common benchmarks to demonstrate its efficiency. Our experimental results show that the proposed framework is effective in detecting compromise and adds little overhead to a common IaaS cloud environment.
Chunlu Wang, Chuanyi Liu, Yingfei Dong
GLOBECOM1
2011 A Novel Comprehensive Network Security Assessment Approach
abstract
Network security assessment is critical to the survivability and reliability of distributed systems. In this paper, we propose a novel assessment approach that supports automatic vulnerability assessment utilizing Bayesian attack graphs. We also integrate several major vulnerability database into a comprehensive database and build a customized vulnerability scanner to assist attack graph generation. Different from existing solutions that manually assign probabilities to a Bayesian attack graph, we design a set of quantitative metrics to automatically analyze vulnerability and evaluate the proposed approach with real-world examples. Our results show the promising capability of the proposed approach in further improving assessment quality.
Chunlu Wang, Yingfei Dong
ICC1
2011 A Bayesian regularized neural network approach to short-term traffic speed prediction
abstract
Short term traffic speed prediction is very important in intelligent transportation systems. Neural networks have been widely used for traffic speed prediction. However, the classical neural network usually lacks satisfactory generalization ability, which usually results in an imprecise prediction of traffic speed. Regularization is an essential technique to improve the generalization ability of neural network. Regularization is realized by adding a weight decay function to the energy function of the neural network. One of the key problems of the regularization technique is how to decide the parameter of the weight decay function. In this paper, the Bayesian technique is used to optimize these regularization parameters and a Bayesian regularized neural network (BRNN) used for traffic speed prediction is proposed. The speed prediction model was validated by the real-world traffic speeds of the Hangzhou city collected from the floating car system. The experimental results show that the proposed method is able to improve the generalization ability of neural networks, and can achieve better prediction results than several traditional prediction models.
Chenye Qiu, Chunlu Wang, Xingquan Zuo, Binxing Fang
SMC2
2010 A Model for Evaluating Connectivity Availability in Random Sleep Scheduled Delay-Tolerant Wireless Networks
abstract
In Wireless Sensor Network (WSN), one of the primary issues is energy conservation for extending network lifetime. Communication protocols for WSN help reduce the energy consumption via adopting sleep scheduling in the network. Random sleep scheduling is a desirable mechanism for its simplicity and steady duty cycle. However, the low duty cycle sleeping of nodes may destroy the connectivity of network, which is the assumption taken by most traditional routing protocols. If certain delay is acceptable, partially connected routing can achieve successful packet forwarding in networks with the deficiency of connectivity. This paper presents a connectivity availability model to evaluate the end to end packet delivery ratio of multi-hop networks subjected to the impact of both partial connectivity and sleep latency. Deployment guidelines are given for WSN with random sleep scheduling policy satisfying reliability, timeliness and duty cycle requirements. The simulated and computed results validate the proposed approach.
Zongwei Luo, Chunlu Wang, Edward C. Wong
GLOBECOM3
2010 An urban traffic speed fusion method based on principle component analysis and neural network
abstract
Real-time traffic speed is an important element for Intelligent Transportation Systems (ITS). Getting accurate road speed is very important for transportation service and management systems. Floating car system based on traces of GPS positions is an effective way to gather accurate real-time traffic speed information of a road network. But sometimes the real-time traffic speed information may get lost unexpectedly due to device faults or storage problems. In engineering practice, the historical speed is used to make up the missing real-time speed, but this method cannot estimate the missing speed accurately. Until now, to the best of our knowledge, there is no research on dealing with the missing floating car speed data. In this paper, we propose a novel urban speed fusion method based on principle component analysis (PCA) and neural network (NN) to fuse the speeds of correlated road sections to get the missing speed of the target road section. The floating car data of the Hangzhou city were used to test our method. The experimental results demonstrate that our method outperforms other methods.
Chenye Qiu, Xingquan Zuo, Chunlu Wang
IJCNN3