Ning Miao

dblp:230/7777 · DBLP profile ↗
← Back
17ranked-venue papers
7as first author
11since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 9 · 6 first-author · 3 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Security and privacy · 3 · 3 since 2021Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Know Me by My Pulse: Toward Practical Continuous Authentication on Wearable Devices via Wrist-Worn PPG
Zequan Liang, Ruoyu Zhang 0002, Ruijie Fang, Ning Miao, Ehsan Kourkchi, Setareh Rafatirad, Houman Homayoun, Chongzhou Fang
NDSS5
2025 LightBench: A Hardware-Aware Trusted Execution Platform for Intelligent Malware Detection at the Edge
Ning Miao, Hossein Sayadi, Kumara Srivatsa Kondapalli, Mahdi Eslamimehr, Houman Homayoun
ACM Great Lakes Symposium on VLSI1
2024 Advanced Energy-Efficient System for Precision Electrodermal Activity Monitoring in Stress Detection
abstract
This paper presents a novel Electrodermal Activ-ity (EDA) signal acquisition system, designed to address the challenges of stress monitoring in contemporary society, where stress affects one in four individuals. Our system focuses on enhancing the accuracy and efficiency of EDA measurements, a reliable indicator of stress. Traditional EDA monitoring solutions often grapple with trade-offs between sensor placement, cost, and power consumption, leading to compromised data accuracy. Our innovative design incorporates an adaptive gain mechanism, catering to the broad dynamic range and high-resolution needs of EDA data analysis. The performance of our system was extensively tested through simulations and a custom Printed Circuit Board (PCB), achieving an error rate below 1 % and maintaining power consumption at a mere$\mathbf{700}\mu \mathbf{A}$under a 3.$7\mathbf{V}$power supply. This research contributes significantly to the field of wearable health technology, offering a robust and efficient solution for long-term stress monitoring.
Ruoyu Zhang 0002, Ruijie Fang, Elahe Hosseini, Chongzhou Fang, Ning Miao, Houman Homayoun
BSN5
2024 SelfCheck: Using LLMs to Zero-Shot Check Their Own Step-by-Step Reasoning
abstract
The recent progress in large language models (LLMs), especially the invention of chain-of-thought prompting, has made it possible to automatically answer questions by stepwise reasoning. However, when faced with more complicated problems that require non-linear thinking, even the strongest LLMs make mistakes. To address this, we explore whether LLMs are able to recognize errors in their own step-by-step reasoning, without resorting to external resources. To this end, we propose SelfCheck, a general-purpose zero-shot verification schema for recognizing such errors. We then use the results of these checks to improve question-answering performance by conducting weighted voting on multiple solutions to the question. We test SelfCheck on math- and logic-based datasets and find that it successfully recognizes errors and, in turn, increases final answer accuracies.
Ning Miao, Yee Whye Teh, Tom Rainforth
ICLR1
2024 Large Language Models for Code Analysis: Do LLMs Really Do Their Job?
Chongzhou Fang, Ning Miao, Shaurya Srivastav, Jialin Liu 0006, Ruoyu Zhang 0002, Ruijie Fang, Asmita 0001, Ryan Tsang, Najmeh Nazari, Han Wang 0020, Houman Homayoun
USENIX Security Symposium2
2023 Gotcha! I Know What You Are Doing on the FPGA Cloud: Fingerprinting Co-Located Cloud FPGA Accelerators via Measuring Communication Links
abstract
In recent decades, due to the emerging requirements of computation acceleration, cloud FPGAs have become popular in public clouds. Major cloud service providers, e.g. AWS and Microsoft Azure have provided FPGA computing resources in their infrastructure and have enabled users to design and deploy their own accelerators on these FPGAs. Multi-tenancy FPGAs, where multiple users can share the same FPGA fabric with certain types of isolation to improve resource efficiency, have already been proved feasible. However, this also raises security concerns. Various types of side-channel attacks targeting multi-tenancy FPGAs have been proposed and validated. The awareness of security vulnerabilities in the cloud has motivated cloud providers to take action to enhance the security of their cloud environments.
Chongzhou Fang, Ning Miao, Han Wang 0020, Tyler David Sheaves, John Marty Emmert, Avesta Sasan, Houman Homayoun
CCS2
2023 Special Session: Mitigating Side-Channel Attacks Through Circuit to Application Layer Approaches
abstract
Side-Channel Attacks (SCAs), which are always considered a severe threat to the security of the cryptographic circuits, today can also be employed to extract IP secrets and neural network models. Hence, developing novel security solutions at different design levels is crucial. In this paper, we explore recent countermeasures at the circuit, algorithmic, and microarchitecture levels. First, we explain how Reconfigurable Field-Effect Transistor (RFET), as a beyond CMOS technology, enables us to provide both IP and data protection against SCAs at the circuit level. Second, we investigate an automated method for generating masked circuits as an algorithmic solution, and then we review machine learning-based SCA detection mechanisms at the microarchitecture level. Finally, we discuss emerging threats of SCAs from the industrial point of view.
Nima Kavand, Armin Darjani, Jens Trommer, Giulio Galderisi, Thomas Mikolajick, Nicolai Müller, Amir Moradi 0001, Chongzhou Fang, Ning Miao, Han Wang 0020, Sai Manoj Pudukotai Dinakarrao, Houman Homayoun, Benjamin Hettwer, Luca Parrini, Akash Kumar 0001
CODES+ISSS9
2023 Side Channel-Assisted Inference Attacks on Machine Learning-Based ECG Classification
abstract
The Electrocardiogram (ECG) measures the electrical cardiac activity generated by the heart to detect abnormal heartbeats and heart attacks. However, the irregular occurrence of the abnormalities demands continuous monitoring of heartbeats. Machine learning techniques are leveraged to automate this task, reducing the labor required during monitoring. In recent years, many companies have launched products with ECG monitoring and irregular heartbeat alerts. Among all classification algorithms, the time series-based algorithm dynamic time warping (DTW) is widely adopted to undertake the ECG classification task. Though progress has been achieved, the DTW-based ECG classification also introduces a new attack vector: the potential leakage of patients' diagnostic results. This paper investigates the potential of side channel-assisted inference attacks on the prevalent DTW-based ECG classification model. In particular, we first identify a vulnerability of DTW for ECG classification, that is, the correlation between warping path choice and prediction results. Based on the vulnerability, we further leverage two types of side-channel attacks, i.e., cache-based side-channel attack Flus+Reload, and trace-based side-channel attack with hardware performance counters, to assess the potential of stealing machine learning-based ECG input samples' labels. Afterward, we build prototypes that leverage Flush+Reload and hardware performance counters to monitor warping path selection with training ECG data, and then construct a predictor to establish a relation between side-channel observations and labels of input ECG samples. Based on experiments, we find that the Flush+Reload-based inference leakage can achieve up to 92.1% and 81.1% attack success rate with Flush+Reload and hardware performance counters to identify the labels of the two ECG samples in DTW.
Jialin Liu 0006, Houman Homayoun, Chongzhou Fang, Ning Miao, Han Wang 0020
ICCAD4
2023 Learning Instance-Specific Augmentations by Capturing Local Invariances
abstract
We introduce InstaAug, a method for automatically learning input-specific augmentations from data. Previous methods for learning augmentations have typically assumed independence between the original input and the transformation applied to that input. This can be highly restrictive, as the invariances we hope our augmentation will capture are themselves often highly input dependent. InstaAug instead introduces a learnable invariance module that maps from inputs to tailored transformation parameters, allowing local invariances to be captured. This can be simultaneously trained alongside the downstream model in a fully end-to-end manner, or separately learned for a pre-trained model. We empirically demonstrate that InstaAug learns meaningful input-dependent augmentations for a wide range of transformation classes, which in turn provides better performance on both supervised and self-supervised tasks.
Ning Miao, Tom Rainforth, Emile Mathieu, Yann Dubois, Yee Whye Teh, Adam Foster 0001, Hyunjik Kim
ICML1
2022 On the Efficient Design of RIS-Assisted MIMO Transmission
abstract
Recently, reconfigurable intelligent surface (RIS) has arisen as an excellent technology for assisting wireless communications. In order to handle the intractable non-convex problem for jointly optimizing beamforming and PSs in multiple-input multiple-output (MIMO) transmission, we propose a novel alternating direction (AD) method by maximizing the achievable rate (AR) at the receiver. Specifically, the initial problem is divided into the following two processes: i) optimizing the beamforming vector with fixed PSs, ii) determining a specific PS based on a closed-form solution when the other PSs and beamforming are fixed. Simulation results corroborate that the proposed AD method provides robust attainable performance with reduced computational complexity compared to its traditional counterparts.
Hong Niu 0001, Xia Lei 0001, Yue Xiao 0001, Ning Miao, Ming Xiao 0001, Shahid Mumtaz
GLOBECOM4
2022 On Incorporating Inductive Biases into VAEs
Ning Miao, Emile Mathieu, Siddharth N, Yee Whye Teh, Tom Rainforth
ICLR1
2020 Do you have the right scissors? Tailoring Pre-trained Language Models via Monte-Carlo Methods
abstract
It has been a common approach to pre-train a language model on a large corpus and finetune it on task-specific data.In practice, we observe that fine-tuning a pre-trained model on a small dataset may lead to over-and/or under-estimation problem.In this paper, we propose MC-Tailor, a novel method to alleviate the above issue in text generation tasks by truncating and transferring the probability mass from over-estimated regions to underestimated ones.Experiments on a variety of text generation datasets show that MC-Tailor consistently and significantly outperforms the fine-tuning approach.Our code is available at https://github.com/NingMiao/ MC-tailor.
Ning Miao, Yuxuan Song 0002, Hao Zhou 0012, Lei Li 0005
ACL1
2020 Improving Maximum Likelihood Training for Text Generation with Density Ratio Estimation
abstract
Autoregressive neural sequence generative models trained by Maximum Likelihood Estimation suffer the exposure bias problem in practical finite sample scenarios. The crux is that the number of training samples for Maximum Likelihood Estimation is usually limited and the input data distributions are different at training and inference stages. Many methods have been proposed to solve the above problem, which relies on sampling from the non-stationary model distribution and suffers from high variance or biased estimations. In this paper, we propose $\psi$-MLE, a new training scheme for autoregressive sequence generative models, which is effective and stable when operating at large sample space encountered in text generation. We derive our algorithm from a new perspective of self-augmentation and introduce bias correction with density ratio estimation. Extensive experimental results on synthetic data and real-world text generation tasks demonstrate that our method stably outperforms Maximum Likelihood Estimation and other state-of-the-art sequence generative models in terms of both quality and diversity.
Yuxuan Song 0002, Ning Miao, Hao Zhou 0012, Lantao Yu, Mingxuan Wang, Lei Li 0005
AISTATS2
2020 Dispersed Exponential Family Mixture VAEs for Interpretable Text Generation
abstract
Deep generative models are commonly used for generating images and text. Interpretability of these models is one important pursuit, other than the generation quality. Variational auto-encoder (VAE) with Gaussian distribution as prior has been successfully applied in text generation, but it is hard to interpret the meaning of the latent variable. To enhance the controllability and interpretability, one can replace the Gaussian prior with a mixture of Gaussian distributions (GM-VAE), whose mixture components could be related to hidden semantic aspects of data. In this paper, we generalize the practice and introduce DEM-VAE, a class of models for text generation using VAEs with a mixture distribution of exponential family. Unfortunately, a standard variational training algorithm fails due to the \emph{mode-collapse} problem. We theoretically identify the root cause of the problem and propose an effective algorithm to train DEM-VAE. Our method penalizes the training with an extra \emph{dispersion term} to induce a well-structured latent space. Experimental results show that our approach does obtain a meaningful space, and it outperforms strong baselines in text generation benchmarks. The code is available at \url{https://github.com/wenxianxian/demvae}.
Wenxian Shi, Hao Zhou 0012, Ning Miao, Lei Li 0005
ICML3
2019 CGMH: Constrained Sentence Generation by Metropolis-Hastings Sampling
abstract
In real-world applications of natural language generation, there are often constraints on the target sentences in addition to fluency and naturalness requirements. Existing language generation techniques are usually based on recurrent neural networks (RNNs). However, it is non-trivial to impose constraints on RNNs while maintaining generation quality, since RNNs generate sentences sequentially (or with beam search) from the first word to the last. In this paper, we propose CGMH, a novel approach using Metropolis-Hastings sampling for constrained sentence generation. CGMH allows complicated constraints such as the occurrence of multiple keywords in the target sentences, which cannot be handled in traditional RNN-based approaches. Moreover, CGMH works in the inference stage, and does not require parallel corpora for training. We evaluate our method on a variety of tasks, including keywords-to-sentence generation, unsupervised sentence paraphrasing, and unsupervised sentence error correction. CGMH achieves high performance compared with previous supervised methods for sentence generation. Our code is released at https://github.com/NingMiao/CGMH
Ning Miao, Hao Zhou 0012, Lili Mou, Rui Yan 0001, Lei Li 0005
AAAI1
2019 Generating Fluent Adversarial Examples for Natural Languages
abstract
Efficiently building an adversarial attacker for natural language processing (NLP) tasks is a real challenge.Firstly, as the sentence space is discrete, it is difficult to make small perturbations along the direction of gradients.Secondly, the fluency of the generated examples cannot be guaranteed.In this paper, we propose MHA, which addresses both problems by performing Metropolis-Hastings sampling, whose proposal is designed with the guidance of gradients.Experiments on IMDB and SNLI show that our proposed MHA outperforms the baseline model on attacking capability.Adversarial training with MHA also leads to better robustness and performance.
Huangzhao Zhang, Hao Zhou 0012, Ning Miao, Lei Li 0005
ACL (1)3
2019 Kernelized Bayesian Softmax for Text Generation
abstract
Neural models for text generation require a softmax layer with proper token embeddings during the decoding phase. Most existing approaches adopt single point embedding for each token. However, a word may have multiple senses according to different context, some of which might be distinct. In this paper, we propose KerBS, a novel approach for learning better embeddings for text generation. KerBS embodies two advantages: (a) it employs a Bayesian composition of embeddings for words with multiple senses; (b) it is adaptive to semantic variances of words and robust to rare sentence context by imposing learned kernels to capture the closeness of words (senses) in the embedding space. Empirical studies show that KerBS significantly boosts the performance of several text generation tasks.
Ning Miao, Hao Zhou 0012, Chengqi Zhao, Wenxian Shi, Lei Li 0005
NeurIPS1