EDBT 2026 Demo / reviewers in the wild / expert
Wenye Liu
dblp:181/5617
· DBLP profile ↗
13ranked-venue papers
5as first author
9since 2021 · last 2026
0000-0003-4590-5367ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 9 · 3 first-author · 5 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Live Demonstration: Hardware-Bound IP Protection for OWL-ViT on Edge Devices
Peichun Hua, Hanxiu Zhang, Wenye Liu |
ISCAS | 5 |
| 2026 | A Lightweight PUF-Based Secure Group Communication Scheme for Low Altitude Network With Dynamic Group MembershipabstractLow Altitude Network (LAN) has emerged as a critical infrastructure for applications such as surveillance and emergency response. Group communication for LAN offers enhanced energy efficiency and reduced network overhead. However, existing group communication protocols encounter difficulties in managing the rekeying process efficiently for a dynamic group or require computationally expensive public key primitives for shared secret handshaking to overcome this challenge. Moreover, the security of most of the existing protocols relies primarily on the safekeeping of some secrets on the group members' devices. To overcome these limitations, we propose a novel physical unclonable function (PUF)-based lightweight secure group communication protocol. The proposed protocol utilizes a combination of the device's PUF and the one-time pad (OTP) to eliminate secure key storage at both group verifier and prover nodes, and achieves perfect forward secrecy (PFS) by eliminating dependence on static long-term secrets. The proposed protocol also supports efficient group key renewal by using a full binary tree as a secret vault for sharing and updating distributed secrets with the Chinese Remainder Theorem (CRT). Meantime, this data structure also reduces the computation and communication complexity for key renewal to$O(\log _{2}N)$at the cluster head and$O(1)$at the sensor nodes. A comparative analysis shows that the proposed protocol surpasses related protocols in terms of security features and overheads in computation, communication, as well as secret storage requirements. The proposed protocol was also validated by formal security analyses and a physical LAN implementation using Ultra96-V2 boards as cluster nodes. Harishma Boyapally, Wenye Liu, Yongkui Yang, Chip-Hong Chang |
IEEE Trans. Mob. Comput. | 3 |
| 2025 | A quantum-resistant oracle-based conditional payment scheme from lattice
Wenye Liu, Debiao He, Zhichao Yang 0002, Xiaoying Jia 0002, Min Luo 0002 |
J. Inf. Secur. Appl. | 1 |
| 2024 | Efficient Fast Additive Homomorphic Encryption Cryptoprocessor for Privacy-Preserving Federated Learning AggregationabstractPrivacy leakage is a critical concern of collaboratively training a large-scale deep learning model from multiple clients. To protect the local data, homomorphic encryption (e.g., Paillier) could be utilized for data aggregation on the central server. Nevertheless, even with CPU-optimized libraries or FPGA-based accelerators, the computing power and throughput limitations remain a stumbling block for practical deployment of Paillier scheme. In this paper, we present an efficient and high-throughput cryptoprocessor based on a recently introduced Fast Additive Homomorphic Encryption (FAHE) algorithm. For encryption, we incorporate the asymmetric decomposition, time multiplexing resource reuse and hard-macro based wide-bus logic operations to efficiently map the large (>40 kbits) integer multiplications for low latency FPGA implementation. For decryption, we propose a table lookup method for rapid modular reduction by leveraging the relative short modulus size of FAHE. The single large precomputed lookup table is carefully partitioned into multiple subtables and deployed in dual-port RAMs to enable resource-efficient parallel computation. The FAHE cryptoprocessor is implemented on a Xilinx ZCU102 FPGA board for performance evaluation and comparison. The results show that the throughput of our design is 354 × to 404 × higher than the state-of-the-art Paillier accelerators. Compared to the FAHE software implementation, the latency of our proposed design is 14.95 × and 11.42 × lower for encryption and decryption, respectively. Wenye Liu, Nazim Altar Koca, Chip-Hong Chang |
DATE | 1 |
| 2024 | Live Demonstration: Man-in-the-Middle Attack on Edge Artificial IntelligenceabstractDeep neural networks (DNNs) are susceptible to evasion attacks. However, digital adversarial examples are typically applied to pre-captured static images. The perturbations are generated by loss optimization with knowledge of target model hyperparameters and are added offline. Physical adversarial examples, on the other hand, tamper with the physical target or use a realistically fabricated target to fool the DNN. A sufficient number of pristine target samples captured under different varying environmental conditions are required to create the physical adversarial perturbations. Both digital and physical input evasion attacks are not robust against dynamic object-scene variations and the adversarial effects are often weak-ened by model reduction and quantization when the DNNs are implemented on edge artificial intelligence (AI) accelerator platforms. This demonstration presents a practical man-in-the-middle (MITM) attack on an edge DNN first reported in [1]. A tiny MIPI FPGA chip with hardened CSI-2 and D-PHY blocks is attached between the camera and the edge AI accelerator to inject unobtrusive stripes onto the RAW image data. The attack is less influenced by dynamic context variations such as changes in viewing angle, illumination, and distance of the target from the camera. Weiyang He, Wenye Liu, Chip-Hong Chang |
ISCAS | 4 |
| 2023 | A Lightweight PUF-based Secure Group Key Agreement Protocol for Wireless Sensor NetworksabstractWireless sensor networks (WSNs) have gained considerable popularity in a wide range of applications such as military, healthcare, transportations, and environmental sensing. Data produced in these applications is highly sensitive and requires a high level of security protection. However, individual nodes in WSNs are typically resource constrained and have limited computing power to protect memory stored secrets, which are vulnerable to tampering and physical probing. As group messaging is commonly used in WSNs for efficient message exchanges among sensor nodes, this paper presents a lightweight secure group key agreement protocol using Physical Unclonable Function (PUF) as a hardware root of trust. The proposed scheme establishes secure group authentication and group session key simultaneously for all participating members of the group without resorting to complex public-key algorithms. By hiding the prover's authentication secrets in a secure mask, the verifier does not have to store the secrets but recover them for authentication by querying its PUF. The proposed protocol enables lightweight cluster head authentication at the sensor node and prevents stolen-verifier attack at the cluster head. Besides, it is robust against memory probing attacks at all group devices and man-in-the-middle attacks on the communication channel. Among existing PUF-based group key establishment protocols, it requires zero secret storage cost and exhibits excellent overall computation and communication performance. Wenye Liu, Chip-Hong Chang |
ISCAS | 2 |
| 2023 | An Imperceptible Data Augmentation Based Blackbox Clean-Label Backdoor Attack on Deep Neural NetworksabstractDeep neural networks (DNNs) have permeated into many diverse application domains, making them attractive targets of malicious attacks. DNNs are particularly susceptible to data poisoning attacks. Such attacks can be made more venomous and harder to detect by poisoning the training samples without changing their ground-truth labels. Despite its pragmatism, the clean-label requirement imposes a stiff restriction and strong conflict in simultaneous optimization of attack stealth, success rate, and utility of the poisoned model. Attempts to circumvent the pitfalls often lead to a high injection rate, ineffective embedded backdoors, unnatural triggers, low transferability, and/or poor robustness. In this paper, we overcome these constraints by amalgamating different data augmentation techniques for the backdoor trigger. The spatial intensities of the augmentation methods are iteratively adjusted by interpolating the clean sample and its augmented version according to their tolerance to perceptual loss and augmented feature saliency to target class activation. Our proposed attack is comprehensively evaluated on different network models and datasets. Compared with state-of-the-art clean-label backdoor attacks, it has lower injection rate, stealthier poisoned samples, higher attack success rate, and greater backdoor mitigation resistance while preserving high benign accuracy. Similar attack success rates are also demonstrated on the Intel Neural Compute Stick 2 edge AI device implementation of the poisoned model after weight-pruning and quantization. Chaohui Xu, Wenye Liu, Chip-Hong Chang |
IEEE Trans. Circuits Syst. I Regul. Pap. | 2 |
| 2023 | PUF-Based Mutual Authentication and Key Exchange Protocol for Peer-to-Peer IoT ApplicationsabstractPeer to Peer (P2P) or direct connection IoT has become increasingly popular owing to its lower latency and higher privacy compared to database-driven or server-based IoT. However, wireless vulnerabilities raise severe concerns on IoT device-to-device communication. This is further aggravated by the challenge to achieve lightweight direct mutual authentication and secure key exchange between IoT peer nodes in P2P IoT applications. Physical unclonable function (PUF) is a key enabler to lightweight, low-power and secure authentication of resource-constrained devices in IoT. Nevertheless, current PUF-enabled authentication protocols, with or without the challenge-response pairs (CRPs) of each of its interlocutors stored in the verifier's side, are incompatible for P2P IoT scenarios due to the security, storage and computing power limitations of IoT devices. To solve this problem, a new lightweight PUF-based mutual authentication and key exchange protocol is proposed. It allows two resource-constrained PUF embedded endpoint devices to authenticate each other directly without the need for local storage of CRPs or any private secrets, and simultaneously establish the session key for secure data exchange without resorting to the public-key algorithm. The proposed protocol is evaluated using the game-based formal security analysis method as well as the automatic security analysis tool ProVerif to corroborate its mutual authenticity, secrecy, and resistance against replay and man-in-the-middle (MITM) attacks. Using two Avnet Ultra96-V2 boards to emulate the two IoT endpoint devices, a physical prototype system is also constructed to demonstrate and validate the feasibility of the proposed secure P2P connection scheme. A comparative analysis shows that the proposed protocol outperforms related protocols in terms of security features, computational complexity as well as communication and storage costs. Wenye Liu, Chongyan Gu, Chip-Hong Chang |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | Stealthy and Robust Glitch Injection Attack on Deep Learning Accelerator for Target With Variational ViewpointabstractDeep neural network (DNN) accelerators overcome the power and memory walls for executing neural-net models locally on edge-computing devices to support sophisticated AI applications. The advocacy of “model once, run optimized anywhere” paradigm introduces potential new security threat to edge intelligence that is methodologically different from the well-known adversarial examples. Existing adversarial examples modify the input samples presented to an AI application either digitally or physically to cause a misclassification. Nevertheless, these input-based perturbations are not robust or surreptitious on multi-view target. To generate a good adversarial example for misclassifying a real-world target of variational viewing angle, lighting and distance, a decent number of target’s samples are required to extract the rare anomalies that can cross the decision boundary. The feasible perturbations are substantial and visually perceptible. In this paper, we propose a new glitch injection attack on DNN accelerator that is capable of misclassifying a target under variational viewpoints. The glitches injected into the computation clock signal induce transitory but disruptive errors in the intermediate results of the multiply-and-accumulate (MAC) operations. The attack pattern for each target of interest consists of sparse instantaneous glitches, which can be derived from just one sample of the target. Two modes of attack patterns are derived, and their effectiveness are demonstrated on four representative ImageNet models implemented on the Deep-learning Processing Unit (DPU) of FPGA edge and its DNN development toolchain. The attack success rates are evaluated on 118 objects in 61 diverse sensing conditions, including 25 viewing angles (−60° to 60°), 24 illumination directions and 12 color temperatures. In the covert mode, the success rates of our attack exceed existing stealthy adversarial examples by more than 16.3%, with only two glitches injected into ten thousands to a million cycles for one complete inference. In the robust mode, the attack success rates on all four DNNs are more than 96.2% with an average glitch intensity of 1.4% and a maximum glitch intensity of 10.2%. Wenye Liu, Chip-Hong Chang, Fan Zhang 0010 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | Imperceptible Misclassification Attack on Deep Learning Accelerator by Glitch InjectionabstractThe convergence of edge computing and deep learning empowers endpoint hardwares or edge devices to perform inferences locally with the help of deep neural network (DNN) accelerator. This trend of edge intelligence invites new attack vectors, which are methodologically different from the well-known software oriented deep learning attacks like the input of adversarial examples. Current studies of threats on DNN hardware focus mainly on model parameters interpolation. Such kind of manipulation is not stealthy as it will leave non-erasable traces or create conspicuous output patterns. In this paper, we present and investigate an imperceptible misclassification attack on DNN hardware by introducing infrequent instantaneous glitches into the clock signal. Comparing with falsifying model parameters by permanent faults, corruption of targeted intermediate results of convolution layer(s) by disrupting associated computations intermittently leaves no trace. We demonstrated our attack on nine state-of-the-art ImageNet models running on Xilinx FPGA based deep learning accelerator. With no knowledge about the models, our attack can achieve over 98% misclassification on 8 out of 9 models with only 10% glitches launched into the computation clock cycles. Given the model details and inputs, all the test images applied to ResNet50 can be successfully misclassified with no more than 1.7% glitch injection. Wenye Liu, Chip-Hong Chang, Fan Zhang 0010, Xiaoxuan Lou |
DAC | 1 |
| 2020 | Fired Neuron Rate Based Decision Tree for Detection of Adversarial Examples in DNNsabstractDeep neural network (DNN) is a prevalent machine learning solution to computer vision problems. The most criticized vulnerability of deep learning is its susceptibility towards adversarial images crafted by maliciously adding infinitesimal distortions to the benign inputs. Such negatives can fool a classifier. Existing countermeasures against these adversarial attacks are mainly developed based on software model of DNNs by using modified training during learning or modified input during testing, modifying networks or changing loss/activation functions, or relying on add-on models for classifying unseen examples. These approaches do not consider the optimization for hardware implementation of the learning models. In this paper, a new thresholding method is proposed based on comparators integrated into the most discriminative layers of the DNN determined by their layer-wise fired neuron rates between adversarial and normal inputs. Effectiveness of the method is validated on the ImageNet dataset with 8-bit truncated models for the state-of-the-art DNN architectures. A high detection rate of up to 98% with only 4.5% of false positive rate is achieved. The results show a significant improvement on both detection rate and false positive rate compared with previous countermeasures against the most practical non-invasive universal perturbation attack on deep learning based AI chip. Wenye Liu, Chip-Hong Chang |
ISCAS | 2 |
| 2019 | Analysis of Circuit Aging on Accuracy Degradation of Deep Neural Network AcceleratorabstractDeep neural networks have achieved phenomenal successes in vision recognition tasks, which motivate the deployment of deep learning in portable and smart wearable devices. To overcome the fundamental challenges of power and resource limitation, application-specific integrated circuit accelerators have emerged to compact the model and use lower precision arithmetic to increase the throughput of computation with reduced power consumption. Although very high energy efficiency has been achieved by removing redundant weights, compressing data and even sacrificing timing margin, such trend in hardware acceleration that pushes the deep learning systems to the error threshold can be disastrous for the tasks they performed due to failure or degraded performance of circuit components. Concerned by the lack of attention on the evolving unreliability effects in artificial intelligent accelerators implemented by the continuously scaled CMOS technology, this paper is the first to evaluate the effect of circuit aging on performance degradation of deep learning accelerator. Our findings indicate that DNN system running at their peak throughput rate can experience up to 84% accuracy drop after a year of aging and the accumulation of errors aggravates with the depth of learning. It is also found that relaxation of throughput rate can slow down the loss of classification accuracy considerably. Wenye Liu, Chip-Hong Chang |
ISCAS | 1 |
| 2018 | Active IC Metering of Digital Signal Processing Subsystem with Two-Tier Activation for Secure Split TestabstractActive integrated circuit (IC) metering is a class of hardware security protocols that enables the designer to track the number of chips produced from the same mask and remotely activate only the desired ones. This paper reviews existing IC metering approaches to incorporate the advantages of individual methods into a secure functional lock on digital signal processing submodule of wireless communication system to avoid legitimate channel exploitation and the risk of deploying unreliable out-of-specs gray market ICs. Our method makes use of aging-sensitive physical unclonable function to enable a two-tier activation of ICs in split test flow to track chip supply after production tests. Extraneous states are inserted into the state-space mapping of digital signal processing submodule as opposed to controller to provide a stronger state dependency on datapath and input signal. The scheme is illustrated experimentally on a pulse shaping filter of the transmitter for a wireless communication system. Sumedh Dhabu, Wenye Liu, Chip-Hong Chang |
ISCAS | 3 |