Guannan Zhao

dblp:18/7132 · DBLP profile ↗
← Back
9ranked-venue papers
1as first author
7since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 6 · 6 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 LLA: Enhancing Security and Privacy for Generative Models with Logic-Locked Accelerators
abstract
We introduce LLA, an effective intellectual property (IP) protection scheme for generative AI models. LLA leverages the synergy between hardware and software to defend against various supply chain threats, including model theft, model corruption, and information leakage. On the software side, it embeds key bits into neurons that can trigger outliers to degrade performance and applies invariance transformations to obscure the key values. On the hardware side, it integrates a lightweight locking module into the AI accelerator while maintaining compatibility with various dataflow patterns and toolchains. An accelerator with a pre-stored secret key acts as a license to access the model services provided by the IP owner. The evaluation results show that LLA can withstand a broad range of oracle-guided key optimization attacks, while incurring a minimal computational overhead of less than 0.1% for 7,168 key bits.
You Li 0008, Guannan Zhao, Yuhao Ju, Yunqi He, Jie Gu 0001, Hai Zhou 0001
AAAI2
2026 Physical-Aware eFPGA Redaction for Secure and Efficient Hardware IP Protection
abstract
Embedded FPGA (eFPGA)-based hardware redaction has emerged as a promising technique for protecting the intellectual property (IP) of integrated circuits. Existing approaches select a subset of the logic at the register-transfer level (RTL) and replace it with a programmable eFPGA module. However, due to their lack of awareness of physical information, these approaches incur significant power, performance, and area (PPA) overhead on the resulting chip. This paper presents a physically guided partitioning approach that divides the original design into two parts: one implemented as an application-specific integrated circuit (ASIC) and the other redacted onto an embedded FPGA fabric. It leverages a graph neural network to encode both the structural and physical information of each gate into an embedding vector. It then employs a clustering and selection process to identify the redaction candidate. Experiments demonstrate that our approach consistently reduces timing overhead while achieving comparable or superior results in terms of area, security, and resource consumption.
Yunqi He, You Li 0008, Ruofan Huang, Guannan Zhao, Hai Zhou 0001
DATE4
2025 RE3: Finding Refinement Relations with Relational Mapping Abstraction
abstract
A refinement relation captures the state equivalence between two sequential circuits. It finds applications in various tasks of VLSI design automation, including regression verification, behavioral model synthesis, assertion synthesis, and design space exploration. However, manually constructing a refinement relation requires an engineer to have both domain knowledge and expertise in formal methods, which is especially challenging for complex designs after significant transformations. This paper presents a rigorous and efficient sequential equivalence checking algorithm for non-cycle-accurate designs. The algorithm can automatically find a concise and human-comprehensible refinement relation between two designs, helping engineers understand the essence of design transformations. We demonstrate the usefulness and efficiency of the proposed algorithm with experiments and case studies. In particular, we showcase how refinement relations can facilitate error detection and correction for LLM-generated RTL designs.
You Li 0008, Guannan Zhao, Yunqi He, Hai Zhou 0001
DAC2
2025 DE2: SAT-Based Sequential Logic Decryption with a Functional Description
abstract
Logic locking is a promising approach to protect the intellectual properties of integrated circuits. Existing logic locking schemes assume that an adversary must possess a cycle-accurate oracle circuit to launch an I/O attack. This paper presents DE2, a novel and rigorous attacking algorithm based on a new adversarial model. DE2 only takes a high-level functional specification of the victim chip. Such specifications are increasingly prevalent in the modern IC design flow. DE2 closes the timing gap between the specification and the circuit with an automatic alignment mechanism, which enables effective logic decryption without cycle-accurate information. An essential enabler of DE2 is a synthesis-based sequential logic decryption algorithm called LIM, which introduces only a minimal overhead in every iteration. Experiments show that DE2 can efficiently attack logic-locked benchmarks without access to a cycle-accurate oracle circuit. Besides, LIM can solve 20% more ISCAS'89 benchmarks than state-of-the-art sequential logic decryption algorithms.
You Li 0008, Guannan Zhao, Yunqi He, Hai Zhou 0001
DATE2
2024 Evaluating the Security of Logic Locking on Deep Neural Networks
abstract
Deep neural networks are susceptible to model piracy and adversarial attacks when malicious end-users have full access to the model parameters. Recently, a logic locking scheme called HPNN has been proposed. HPNN utilizes hardware root-of-trust to prevent end-users from accessing the model parameters. This paper investigates whether logic locking is secure on deep neural networks. Specifically, it presents a systematic I/O attack that combines algebraic and learning-based approaches. This attack incrementally extracts key values from the network to minimize sample complexity. Besides, it employs a rigorous procedure to ensure the correctness of the extracted key values. Our experiments demonstrate the accuracy and efficiency of this attack on large networks with complex architectures. Consequently, we conclude that HPNN-style logic locking and its variants we can foresee are insecure on deep neural networks.
You Li 0008, Guannan Zhao, Yunqi He, Hai Zhou 0001
DAC2
2023 SE3: Sequential Equivalence Checking for Non-Cycle-Accurate Design Transformations †
abstract
In high-level design explorations, many useful optimizations transform a circuit into another with different operating cycles for a better trade-off between performance and resource usage. How to efficiently check their equivalence is critical and challenging since most existing equivalence checkers are designed for cycle-accurate circuits. This paper presents SE3, an efficient sequential equivalence checker without assumption on cycle-accuracy, latch mapping, or I/O interface of the checked circuits. It proves the equivalence of two circuits by computing an equivalence relation between the states of the two circuits and utilizes syntax abstraction to accelerate this process. Experimental results show that SE3 is significantly faster than state-of-the-art sequential equivalence checking algorithms.
You Li 0008, Guannan Zhao, Yunqi He, Hai Zhou 0001
DAC2
2023 ObfusLock: An Efficient Obfuscated Locking Framework for Circuit IP Protection†
abstract
With the rapid evolution of the IC supply chain, circuit IP protection has become a critical realistic issue for the semiconductor industry. One promising technique to resolve the issue is logic locking. It adds key inputs to the original circuit such that only authorized users can get the correct function, and it modifies the circuit to obfuscate it against structural analysis. However, there is a trilemma among locking, obfuscation, and efficiency within all existing logic locking methods that at most two of the objectives can be achieved. In this work, we propose ObfusLock, the first logic locking method that simultaneously achieves all three objectives: locking security, obfuscation safety, and locking efficiency. ObfusLock is based on solid mathematical proofs, incurs small overheads (<5% on average), and has passed experimental tests of various existing attacks.
You Li 0008, Guannan Zhao, Yunqi He, Hai Zhou 0001
DATE2
2018 Respond-CAM: Analyzing Deep Models for 3D Imaging Data by Visualizations
Guannan Zhao, Bo Zhou 0009, Rui Jiang 0001, Min Xu 0009
MICCAI (1)1
2017 Modified codewords design for space-time block coded spatial modulation
abstract
Two kinds of modified codewords for space–time block coded spatial modulation (STBC‐SM) are presented in this study. The first modified codeword introduces a concept of flexible coefficients into the M ‐ary phase shift keying STBC‐SM. A method is proposed to obtain the optimal flexible coefficients. Moreover, the first modified codewords can also be applied to the systems developed from the STBC‐SM. In the second provided codewords, super‐orthogonal space–time trellis codes are applied in STBC‐SM. Therefore, a higher spectral efficiency is obtained compared with the original STBC‐SM. Finally, the simulation results and theoretical analysis demonstrate these performance advantages of the two kinds of modified codewords for STBC‐SM.
Yuhao Hua, Guannan Zhao, Minglu Jin
IET Commun.2