EDBT 2026 Demo / reviewers in the wild / expert
Chongzhou Fang
dblp:232/9671
· DBLP profile ↗
22ranked-venue papers
6as first author
22since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 9 · 9 since 2021Security and privacy · 8 · 4 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 4 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Kumo: A Security-Focused Serverless Cloud Simulator
Khaled N. Khasawneh, Setareh Rafatirad, Houman Homayoun, Chongzhou Fang |
CCGrid | 5 |
| 2026 | Know Me by My Pulse: Toward Practical Continuous Authentication on Wearable Devices via Wrist-Worn PPG
Zequan Liang, Ruoyu Zhang 0002, Ruijie Fang, Ning Miao, Ehsan Kourkchi, Setareh Rafatirad, Houman Homayoun, Chongzhou Fang |
NDSS | 9 |
| 2026 | Bit of a Close Talker: A Practical Guide to Serverless Cloud Co-Location Attacks
Najmeh Nazari, Behnam Omidi, Setareh Rafatirad, Khaled N. Khasawneh, Houman Homayoun, Chongzhou Fang |
NDSS | 7 |
| 2025 | FaRAccel: FPGA-Accelerated Defense Architecture for Efficient Bit-Flip Attack Resilience in Transformer ModelsabstractForget and Rewire (FaR) methodology has demonstrated strong resilience against Bit-Flip Attacks (BFAs) on Transformer-based models by obfuscating critical parameters through dynamic rewiring of linear layers. However, the application of FaR introduces non-negligible performance and memory overheads, primarily due to the runtime modification of activation pathways and the lack of hardware-level optimization. To overcome these limitations, we propose FaRAccel, a novel hardware accelerator architecture implemented on FPGA, specifically designed to offload and optimize FaR operations. FaRAccel integrates reconfigurable logic for dynamic activation rerouting, and lightweight storage of rewiring configurations, enabling low-latency inference with minimal energy overhead. We evaluate FaRAccel across a suite of Transformer models and demonstrate substantial reductions in FaR inference latency and improvement in energy efficiency, while maintaining the robustness gains of the original FaR methodology. To the best of our knowledge, this is the first hardware-accelerated defense against BFAs in Transformers, effectively bridging the gap between algorithmic resilience and efficient deployment on real-world AI platforms. Najmeh Nazari, Banafsheh S. Latibari, Elahe Hosseini, Fatemeh Movafagh, Chongzhou Fang, Hosein Mohammadi Makrani, Kevin Immanuel Gubbi, Abhijit Mahalanobis, Setareh Rafatirad, Hossein Sayadi, Houman Homayoun |
ICCD | 5 |
| 2025 | Extended Operational Life for Wearable Health Devices: A Hybrid TinyML and Server-Side ML ApproachabstractWearable devices equipped with sensors like ECG, PPG, and heart rate monitors are pivotal in health monitoring, yet they face significant challenges due to limited battery life, particularly when using complex machine learning (ML) models for continuous monitoring. This paper explores an innovative approach to enhance energy efficiency in wearable health monitoring applications by integrating TinyML with advanced ML models. We propose using energy-efficient TinyML models for initial binary classification to detect abnormalities in ECG signals. Upon detecting an anomaly, the data is transmitted to a server where more complex ML models, perform detailed multi-label classification to identify specific conditions. Our methodology leverages event-driven software frameworks and adaptive data collection strategies to optimize power consumption, extending the operational life of wearable devices without sacrificing accuracy. The proposed system is evaluated on several metrics, including accuracy, F1-score, energy consumption, and model latency. Our findings demonstrate that the integration of TinyML can significantly extend battery life while maintaining high levels of accuracy and reliability in health monitoring, presenting a promising solution for long-term wearable device deployment. Najmeh Nazari, Vedant Patel, Chongzhou Fang, Setareh Rafatirad, Houman Homayoun |
ISCAS | 3 |
| 2025 | Assessing and Mitigating Heterogeneity-Driven Security Threats in the CloudabstractCloud computing has become crucial for the commercial world due to its computational capacity, storage capabilities, scalability, software integration, and billing convenience. Initially, clouds were relatively homogeneous, but now diverse machine configurations in heterogeneous clouds are recognized for their improved application performance and energy efficiency. This shift is driven by the integration of various hardware to accommodate diverse user applications. However, alongside these advancements, security threats like micro-architectural attacks are increasing concerns for cloud providers and users. Studies like Repttack and Cloak & Co-locate highlight the vulnerability of heterogeneous clouds to co-location attacks, where attacker and victim instances are placed together. The ease of these attacks isn’t solely linked to heterogeneity but also correlates with how heterogeneous the target systems are. Despite this, no numerical metrics exist to quantify cloud heterogeneity. This article introduces the Heterogeneity Score (HeteroScore) to evaluate server setups and instances. HeteroScore significantly correlates with co-location attack security. The article also proposes strategies to balance diversity and security. This study pioneers the quantitative analysis connecting cloud heterogeneity and infrastructure security. Chongzhou Fang, Najmeh Nazari, Behnam Omidi, Han Wang 0020, Aditya Puri, Manish Arora, Setareh Rafatirad, Houman Homayoun, Khaled N. Khasawneh |
ACM Trans. Internet Techn. | 1 |
| 2024 | Validation of WeBe Band During Physical ActivitiesabstractData reliability and algorithm robustness are both important for wearable devices. To validate the accuracy of a recently published research vehicle, WeBe band, we conducted a concurrent heart rate (HR) and galvanic skin response (GSR) validity study. WeBe band, Empatica E4 and MindWare, which is currently considered the gold standard for collecting these measures, are compared concurrently. Fifty healthy adult partic-ipants volunteered (female n=29, 49 in 18–25 age range, 1 in 26–30 age range; [mean (SD)]: height = 167.6 (8.9) cm, mass = 150.1 (33.1) lbs). Participants wore the WeBe band and the Empatica band on opposite wrists (alternating device placement between participants) and the MindWare electrodes were placed on the on chest, back, and palms. Each participant completed a study session (a total 51 minutes) that included sitting, standing, normal paced walking and faster paced walking. Data was processed and validity was measured though: mean absolute percent error (MAPE), Bland-Altman limits of aggreement (LOA) and concordance coefficient (rc). Results showed that WeBe band is valid under all conditions. Ruijie Fang, Sally Hang, Ruoyu Zhang 0002, Chongzhou Fang, Setareh Rafatirad, Camelia E. Hostinar, Houman Homayoun |
BSN | 4 |
| 2024 | Advanced Energy-Efficient System for Precision Electrodermal Activity Monitoring in Stress DetectionabstractThis paper presents a novel Electrodermal Activ-ity (EDA) signal acquisition system, designed to address the challenges of stress monitoring in contemporary society, where stress affects one in four individuals. Our system focuses on enhancing the accuracy and efficiency of EDA measurements, a reliable indicator of stress. Traditional EDA monitoring solutions often grapple with trade-offs between sensor placement, cost, and power consumption, leading to compromised data accuracy. Our innovative design incorporates an adaptive gain mechanism, catering to the broad dynamic range and high-resolution needs of EDA data analysis. The performance of our system was extensively tested through simulations and a custom Printed Circuit Board (PCB), achieving an error rate below 1 % and maintaining power consumption at a mere$\mathbf{700}\mu \mathbf{A}$under a 3.$7\mathbf{V}$power supply. This research contributes significantly to the field of wearable health technology, offering a robust and efficient solution for long-term stress monitoring. Ruoyu Zhang 0002, Ruijie Fang, Elahe Hosseini, Chongzhou Fang, Ning Miao, Houman Homayoun |
BSN | 4 |
| 2024 | Architectural Whispers: Robust Machine Learning Models Fingerprinting via Frequency Throttling Side-ChannelsabstractMachine Learning (ML) security practices include hiding ML model architectures to protect intellectual property and prevent attacks. We introduce a novel fingerprinting attack using frequency throttling-based Side-Channel Attack (SCA) to detect an ML model's architecture family by converting power side-channel data into timing variations. This method involves using adversary kernels and a time series ML classifier to discern the architecture from execution time patterns during model operation. We achieved up to 96% accuracy in identifying known ML models' architecture families under Ring 0 privileges and we demonstrated its effectiveness across different platforms. Moreover, our code is publicly available 1. Najmeh Nazari, Chongzhou Fang, Hosein Mohammadi Makrani, Behnam Omidi, Mahdi Eslamimehr, Setareh Rafatirad, Avesta Sasan, Hossein Sayadi, Khaled N. Khasawneh, Houman Homayoun |
DAC | 2 |
| 2024 | SpecScope: Automating Discovery of Exploitable Spectre Gadgets on Black-Box MicroarchitecturesabstractTransient execution attacks pose information leakage risks in current systems. Disabling speculative execution, though mitigating the issue, results in significant performance loss. Accurate identification of vulnerable gadgets is essential for balancing security and performance. However, uncovering all covert channels is challenging due to complex microarchitectural analysis. This paper introduces SpecScope, a framework for automating the detection of Spectre gadgets in code using a black-box microarchitecture approach. SpecScope focuses on contention between transient and non-transient instructions to precisely identify and reduce false-positive Spectre gadgets, minimizing mitigation overhead. Tested on public libraries, SpecScope outperforms existing methods, reducing False-Positive rates by 8.9% and increasing True-Positive rates by 10.4%. Najmeh Nazari, Behnam Omidi, Chongzhou Fang, Hosein Mohammadi Makrani, Setareh Rafatirad, Avesta Sasan, Houman Homayoun, Khaled N. Khasawneh |
DATE | 3 |
| 2024 | Securing On-Chip Learning: Navigating Vulnerabilities and Potential Safeguards in Spiking Neural Network ArchitecturesabstractOn-chip learning is the process of training or updating machine learning models directly on specialized hardware. This approach differs from traditional machine learning, which typically conducts training on external computing resources like Central Processing Units (CPUs) or Graphics Processing Units (GPUs). On-chip learning offers several advantages, including reduced latency, improved energy efficiency, enhanced privacy, and adaptability. Consequently, it holds great promise for enabling intelligent decision-making and adaptability in resource-constrained edge and IoT devices while addressing privacy concerns. In Spiking Neural Network (SNN), on-chip learning is enabled by adjusting synaptic weights, allowing the network’s behavior to dynamically align with desired outcomes. However, this adaptability may introduce potential security vulnerabilities. Unmitigated security risks in on-chip learning can lead to various threats, including data leaks, unauthorized access, and even adversarial manipulation of the learning process. This manuscript aims to provide a comprehensive overview of the security risks associated with on-chip learning, with a focus on potential vulnerabilities within the SNN architecture. We will explore real-world scenarios where these vulnerabilities can be exploited and outline protective measures and mitigation strategies to address these security concerns. Najmeh Nazari, Kevin Immanuel Gubbi, Banafsheh S. Latibari, Md Muhtasim Alam Chowdhury, Chongzhou Fang, Avesta Sasan, Setareh Rafatirad, Houman Homayoun, Soheil Salehi |
ISCAS | 5 |
| 2024 | Fuzzing BusyBox: Leveraging LLM and Crash Reuse for Embedded Bug Unearthing
Asmita 0001, Yaroslav Oliinyk, Michael Scott, Ryan Tsang, Chongzhou Fang, Houman Homayoun |
USENIX Security Symposium | 5 |
| 2024 | Large Language Models for Code Analysis: Do LLMs Really Do Their Job?
Chongzhou Fang, Ning Miao, Shaurya Srivastav, Jialin Liu 0006, Ruoyu Zhang 0002, Ruijie Fang, Asmita 0001, Ryan Tsang, Najmeh Nazari, Han Wang 0020, Houman Homayoun |
USENIX Security Symposium | 1 |
| 2024 | Forget and Rewire: Enhancing the Resilience of Transformer-based Models against Bit-Flip Attacks
Najmeh Nazari, Hosein Mohammadi Makrani, Chongzhou Fang, Hossein Sayadi, Setareh Rafatirad, Khaled N. Khasawneh, Houman Homayoun |
USENIX Security Symposium | 3 |
| 2023 | Introducing an Open-Source Python Toolkit for Machine Learning Research in Physiological Signal based Affective ComputingabstractIn the realm of physiological-based affective computing, significant progress has been witnessed in machine learning over the last two decades. Nevertheless, the lack of consistency in measurement tools and data organization across diverse datasets poses a challenge when integrating new datasets for algorithm testing, research, and result comparison across multiple datasets. Despite the expansion of artificial intelligence-driven affective computing, a notable gap remains in the form of a comprehensive toolkit tailored for both machine learning researchers and psychologists who are new to the field of machine learning. In response to these challenges, we introduce a Python toolkit designed to fulfill two key roles: establishing a standardized benchmark for affective computing datasets and offering an all-encompassing toolkit for machine learning in physiological signal based affective computing. This toolkit encompasses vital components essential to the machine learning process, encompassing tasks like dataset integration and interpretation, signal preprocessing, feature derivation, post-processing, classification models, and evaluation metrics. Our proposed toolkit is designed for working with seven publicly available datasets, embracing five different modalities and incorporating twenty diverse machine learning models spanning from conventional options like the support vector machine (SVM) to cutting-edge deep learning models. To the best of our knowledge, the proposed toolkit stands as the pioneering initiative for creating a standardized dataset benchmarking system and a comprehensive solution tailored for machine learning applications in affective computing. The open-source codebase for the proposed toolkit is accessible via https://github.com/rjfang/pyAffeCT. Ruijie Fang, Ruoyu Zhang 0002, Elahe Hosseini, Chongzhou Fang, Setareh Rafatirad, Houman Homayoun |
BIBM | 4 |
| 2023 | Gotcha! I Know What You Are Doing on the FPGA Cloud: Fingerprinting Co-Located Cloud FPGA Accelerators via Measuring Communication LinksabstractIn recent decades, due to the emerging requirements of computation acceleration, cloud FPGAs have become popular in public clouds. Major cloud service providers, e.g. AWS and Microsoft Azure have provided FPGA computing resources in their infrastructure and have enabled users to design and deploy their own accelerators on these FPGAs. Multi-tenancy FPGAs, where multiple users can share the same FPGA fabric with certain types of isolation to improve resource efficiency, have already been proved feasible. However, this also raises security concerns. Various types of side-channel attacks targeting multi-tenancy FPGAs have been proposed and validated. The awareness of security vulnerabilities in the cloud has motivated cloud providers to take action to enhance the security of their cloud environments. Chongzhou Fang, Ning Miao, Han Wang 0020, Tyler David Sheaves, John Marty Emmert, Avesta Sasan, Houman Homayoun |
CCS | 1 |
| 2023 | Special Session: Mitigating Side-Channel Attacks Through Circuit to Application Layer ApproachesabstractSide-Channel Attacks (SCAs), which are always considered a severe threat to the security of the cryptographic circuits, today can also be employed to extract IP secrets and neural network models. Hence, developing novel security solutions at different design levels is crucial. In this paper, we explore recent countermeasures at the circuit, algorithmic, and microarchitecture levels. First, we explain how Reconfigurable Field-Effect Transistor (RFET), as a beyond CMOS technology, enables us to provide both IP and data protection against SCAs at the circuit level. Second, we investigate an automated method for generating masked circuits as an algorithmic solution, and then we review machine learning-based SCA detection mechanisms at the microarchitecture level. Finally, we discuss emerging threats of SCAs from the industrial point of view. Nima Kavand, Armin Darjani, Jens Trommer, Giulio Galderisi, Thomas Mikolajick, Nicolai Müller, Amir Moradi 0001, Chongzhou Fang, Ning Miao, Han Wang 0020, Sai Manoj Pudukotai Dinakarrao, Houman Homayoun, Benjamin Hettwer, Luca Parrini, Akash Kumar 0001 |
CODES+ISSS | 8 |
| 2023 | Don't Cross Me! Cross-layer System SecurityabstractThe computing landscape has undergone significant transformations in recent decades. Modern computation systems involve multiple layers across software and hardware architecture, exposing various security vulnerabilities that can be exploited by attackers. In this paper, we review security threats in these systems and provide insights into future directions in the topic of cross-layer security. Najmeh Nazari, Chongzhou Fang, Sai Manoj Pudukotai Dinakarrao, Houman Homayoun |
DAC | 2 |
| 2023 | Side Channel-Assisted Inference Attacks on Machine Learning-Based ECG ClassificationabstractThe Electrocardiogram (ECG) measures the electrical cardiac activity generated by the heart to detect abnormal heartbeats and heart attacks. However, the irregular occurrence of the abnormalities demands continuous monitoring of heartbeats. Machine learning techniques are leveraged to automate this task, reducing the labor required during monitoring. In recent years, many companies have launched products with ECG monitoring and irregular heartbeat alerts. Among all classification algorithms, the time series-based algorithm dynamic time warping (DTW) is widely adopted to undertake the ECG classification task. Though progress has been achieved, the DTW-based ECG classification also introduces a new attack vector: the potential leakage of patients' diagnostic results. This paper investigates the potential of side channel-assisted inference attacks on the prevalent DTW-based ECG classification model. In particular, we first identify a vulnerability of DTW for ECG classification, that is, the correlation between warping path choice and prediction results. Based on the vulnerability, we further leverage two types of side-channel attacks, i.e., cache-based side-channel attack Flus+Reload, and trace-based side-channel attack with hardware performance counters, to assess the potential of stealing machine learning-based ECG input samples' labels. Afterward, we build prototypes that leverage Flush+Reload and hardware performance counters to monitor warping path selection with training ECG data, and then construct a predictor to establish a relation between side-channel observations and labels of input ECG samples. Based on experiments, we find that the Flush+Reload-based inference leakage can achieve up to 92.1% and 81.1% attack success rate with Flush+Reload and hardware performance counters to identify the labels of the two ECG samples in DTW. Jialin Liu 0006, Houman Homayoun, Chongzhou Fang, Ning Miao, Han Wang 0020 |
ICCAD | 3 |
| 2023 | HeteroScore: Evaluating and Mitigating Cloud Security Threats Brought by Heterogeneity
Chongzhou Fang, Najmeh Nazari, Behnam Omidi, Han Wang 0020, Aditya Puri, Manish Arora, Setareh Rafatirad, Houman Homayoun, Khaled N. Khasawneh |
NDSS | 1 |
| 2022 | Repttack: Exploiting Cloud Schedulers to Guide Co-Location Attacks
Chongzhou Fang, Han Wang 0020, Najmeh Nazari, Behnam Omidi, Avesta Sasan, Khaled N. Khasawneh, Setareh Rafatirad, Houman Homayoun |
NDSS | 1 |
| 2021 | Implementation of a concentration-controlled chemical clock
Chongzhou Fang, Lulu Ge, Xiaosi Tan, Ziyuan Shen, Zaichen Zhang, Xiaohu You 0001, Chuan Zhang 0001 |
Sci. China Inf. Sci. | 1 |