EDBT 2026 Demo / reviewers in the wild / expert
Sihang Hu
dblp:248/2303
· DBLP profile ↗
4ranked-venue papers
0as first author
3since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Compiled Models, Built-In Exploits: Uncovering Pervasive Bit-Flip Attack Surfaces in DNN Executables
Yanzuo Chen, Zhibo Liu 0001, Yuanyuan Yuan 0001, Sihang Hu, Shuai Wang 0011 |
NDSS | 4 |
| 2025 | BitShield: Defending Against Bit-Flip Attacks on DNN Executables
Yanzuo Chen, Yuanyuan Yuan 0001, Zhibo Liu 0001, Sihang Hu, Shuai Wang 0011 |
NDSS | 4 |
| 2024 | DeepCache: Revisiting Cache Side-Channel Attacks in Deep Neural Networks ExecutablesabstractDeep neural networks (DNN) are increasingly deployed in heterogeneous hardware, including high-performance devices like GPUs and low-power devices like mobile/IoT CPUs, FPGAs, and accelerators. In order to unlock the full performance potential of various hardware, deep learning (DL) compilers automatically optimize DNN inference computations and compile DNN models into DNN executables for efficient computations across hardware backends. As valuable intellectual properties, DNN architectures are one primary attack target. Since previous works already demonstrate the abuse of cache side channels to steal DNN architectures from DL frameworks (e.g., PyTorch and TensorFlow), we first study using those known side-channel attacks against DNN executables. We find that attacking DNN executables presents unique challenges, and existing works can hardly apply. Particularly, DNN executables exhibit a standalone paradigm that largely reduces cache side channel attack surfaces. Meanwhile, cache side channels capture only limited behaviors of the whole DNN execution while facing daunting technical challenges (e.g., noise and low time resolution). However, we unveil a unique attack vector in DNN executables, such that the cache-aware optimizations, which are extensively employed by contemporary DL compilers to harvest the full potentials of hardware, would result in distinguishable DNN operator cache access patterns, making model architecture recovery possible. We propose DeepCache, an end-to-end side channel attack framework, to infer DNN model architectures from DNN executables. DeepCache \ leverages cache side channels as the attacking primitives and combines contrastive learning and anomaly detection to enable precise inference. Our evaluation using the standard Prime+Probe shows that DeepCache \ yields a high accuracy in exploiting complex DNN executables under both the basic L1 cache attack and the more practical but challenging last level cache (LLC) attack settings. Zhibo Liu 0001, Yuanyuan Yuan 0001, Yanzuo Chen, Sihang Hu, Shuai Wang 0011 |
CCS | 4 |
| 2019 | DUSKG: A fine-grained knowledge graph for effective personalized service recommendation
Haifang Wang, Zhongjie Wang 0003, Sihang Hu, Xiaofei Xu 0001, Shiping Chen 0001, Zhiying Tu |
Future Gener. Comput. Syst. | 3 |