EDBT 2026 Demo / reviewers in the wild / expert
Haopeng Fan
dblp:257/2616
· DBLP profile ↗
8ranked-venue papers
4as first author
7since 2021 · last 2027
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2027 | SCALA-NIDS: Safety-constrained LLM-Advised closed-loop adaptation for online open-world network intrusion detection
Xiaojie Qin, Qingjun Yuan, Haopeng Fan, Pinghui Wang, Jihong Teng, Siqi Lu, Yongjuan Wang |
Expert Syst. Appl. | 3 |
| 2026 | Enhanced Template Attack Against Dilithium: Leveraging Dual-Loss Feature ExtractionabstractAs a post-quantum digital signature scheme, Dilithium was specifically designed to withstand known quantum algorithm attacks, and its side-channel resistance has garnered significant research attention. However, current side-channel attacks against Dilithium exhibit several limitations: (1) failure to leverage low-correlation characteristics in power traces, (2) loss functions limited to categorical information extraction from power traces, (3) dependency on specific coefficient recovery conditions while neglecting inter-coefficient statistical dependencies, (4) requirement for separate profiling models per intermediate value, resulting in substantial information loss. To address these limitations, we propose an enhanced template attack framework integrating deep learning with classical template attack methodology. Our approach employs a dual-loss similarity learning mechanism for feature extraction from high-dimensional power traces, enabling the construction of more discriminative templates while preserving weakly correlated features. Through assembly-level analysis of the y polynomial generation routine, we reveal inherent correlations among coefficientsyk0,yk1,yk2,yk3. Building on this discovery, our dual-loss similarity learning framework is designed to capture these inter-coefficient relationships, preserving their intrinsic dependencies while achieving effective inter-class separation and intra-class aggregation properties, which significantly enhances the effectiveness of subsequent template attacks. Experimental results on Cortex-M4 power traces demonstrate our method achieves 32.94% polynomial coefficient recovery accuracy for polynomial coefficients y, outperforming conventional SOD-based (83% improvement), T-Test-based (97%), and PCA-based template attacks (197% enhancement). Furthermore, complete private key recovery is achieved with merely 14 power traces under specific conditions. This DL-enhanced template attack framework demonstrates superior side-channel leakage exploitation, yielding substantial performance enhancements over conventional approaches. Haojin Zhang, Qingjun Yuan, Yaoling Ding, An Wang 0001, Hailong Zhang 0001, Haopeng Fan, Siqi Lu, Yongjuan Wang |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 6 |
| 2026 | GPU-accelerated Certified Hausdorff Distance Between Triangle MeshesabstractComputing the directed Hausdorff distance between two triangle meshes is a fundamental operation in geometry processing and simulation. While existing certified branch-and-bound (B&B) methods are efficient for well-separated geometry, they can become prohibitively expensive on large models under tight tolerances and near-zero distance configurations where pruning is limited. We present a GPU-accelerated certified B&B algorithm that explicitly maintains enclosing lower and upper bounds on the directed Hausdorff distance and terminates once their normalized gap, measured with respect to the bounding-box diagonal of the source mesh, meets a user-prescribed tolerance. To map the inherently prioritized search to SIMT (single-instruction, multiple-thread) hardware, we replace priority queues and recursion with a sorted, double-buffered wavefront pipeline built from bulk-parallel worklists for bound evaluation, culling, subdivision, and compaction. To mitigate loose bounds on thin primitives while preserving predictable stream behavior, we introduce a fixed-cardinality adaptive subdivision scheme that selectively applies double longest-edge bisection. To remain robust in deep-refinement regimes, we add a resource-aware deferral mechanism that enforces a device-capacity invariant by prioritizing candidates likely to be culled while postponing expensive ones. Finally, we improve numerical robustness under FP32 (single precision) via triangle-local coordinate transforms and other conservative numerical safeguards, and enhance coherence by spatially ordering the active set and traversing the BVH (bounding volume hierarchy) in triangle packets. Under the same stopping tolerance, experiments on an NVIDIA RTX 5090 show that our GPU solver remains numerically consistent with the FP64 CPU baseline, with normalized cross-platform deviation below 0.01% in over 99.9% of cases. Our method achieves millisecond-scale runtimes capable of supporting interactive frame rates, even on models with millions of triangles. Across the comparison set, it delivers throughput speedups of 836× on the Thingi10K/TetWild benchmark ( A → B ) and 709× on the Thingi10K/Decimation benchmark. Code and data for this paper are available at https://github.com/fhp-transient/gpu-hausdorff. Haopeng Fan, Min Tang 0001, Leonardo Sacht, Qiang Zou 0007, Ruofeng Tong 0001 |
ACM Trans. Graph. | 1 |
| 2025 | ECP: Coprocessor Architecture to Protect Program Logic ConsistencyabstractABSTRACT Contemporary program protection methods focus on safeguarding either program generation, storage, or execution; however, no unified protection strategy exists for ensuring the security of a full program lifecycle. In this study, we combine the static security of program generation with the dynamic security of process execution and propose a novel program logic consistency security property. An encryption core processing (ECP) architecture is presented that provides coprocessor solutions to protect the program logic consistency at the granularity of instructions and data flows. The new authenticated encryption mode in the architecture uses the offset value of the program's instructions and data in relation to the segment‐based address as its encryption parameters. Lightweight cryptographic primitives are adopted to ensure that the hardware burden added by the ECP is limited, especially under 64 architectures. We prove that the proposed scheme in the ECP architecture satisfies indistinguishability under chosen plaintext attack and demonstrate the effectiveness of the architecture against various attacks. Additionally, a theoretical performance analysis is provided for estimating the overhead introduced by the ECP architecture. Siqi Lu, Yongjuan Wang, Haopeng Fan, Qingdi Han, Jingsheng Li |
J. Softw. Evol. Process. | 4 |
| 2025 | Multivariate Template Attack Against NTT-Based Polynomial Multiplication of Dilithium
Haopeng Fan, Hailong Zhang 0001, Yongjuan Wang, Wenhao Wang 0001, Haojin Zhang, Qingjun Yuan |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Cache attacks on subkey calculation of BlowfishabstractCache attacks pose a serious security threat to cryptographic implementations in processor architectures. In this paper, we first propose cache attacks against Blowfish, which can break the protection of key-dependent S-box. This attack targets at the subkey calculation of Blowfish, and fully exploits features of the subkey calculation to construct a leakage equation group about the key. Without any knowledge of plaintext and ciphertext, the attacker only needs to obtain the cache leakage once to recover a variable-length key in minute-level time. More than that, we establish a leakage model for cache attack situations to evaluate the exhausting space of the intermediate value of block ciphers, and estimate the time complexity of cache attacks. In our experiments, we perform Flush + Reload and Prime + Probe attacks and recover the random key of Blowfish in OpenSSL 1.1.1h in 4 minutes. Furthermore, we have applied our attacks to existing systems, such as JavaScript-blowfish and Bcrypt. Our attack on JavaScript-blowfish can recover any plaintext input by the user. As for Bcrypt, our attack can recover the hash values stored in the database, thereby allowing attackers to impersonate the user’s identity. Haopeng Fan, Yongjuan Wang, Xiangbin Wang |
J. Comput. Secur. | 1 |
| 2024 | Screening Least Square Technique Assisted Multivariate Template Attack Against the Random Polynomial Generation of DilithiumabstractIn recent years, the security of Dilithium against side-channel attacks (SCA) has attracted great attentions from the cryptographic engineering community. However, existing power analysis attacks cannot fully utilize the side-channel leakages of the Dilithium reference implementation to efficiently recover the private key. In light of this, a screening least square technique assisted multivariate template attack (SLST assisted MTA) is proposed in this paper. In SLST assisted MTA, side-channel leakages of coefficient$y_{i}$of random polynomial y, unsigned number$x_{i}$and random byte string$a_{i^{\prime }}$can be utilized simultaneously to recover coefficient$y_{i}$of random polynomial y with MTA. Then, one can build error-tolerant equations, and the private key$\mathbf {s_{1}}$can be solved with SLST efficiently. We evaluate the private key recovery efficiency of SLST assisted MTA with real traces measured from the Cortex-M4 processor based Dilithium reference implementation, and the evaluation results show that with MTA, 19.41%, 15.70% and 16.88% of the coefficients of y can be accurately recovered in cases of Dilithium 2, 3 and 5. Besides, using SLST, after five times screening, only 38, 40 and 39 power traces are enough to recover private key$\mathbf {s_{1}}$of Dilithium 2, 3 and 5 with 100% of success rate. Haopeng Fan, Hailong Zhang 0001, Yongjuan Wang, Wenhao Wang 0001, Yanbei Zhu, Haojin Zhang, Qingjun Yuan |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | Manual Audit for BitUnits Contracts
Siqi Lu, Haopeng Fan, Yongjuan Wang, Huizhe Mi |
BlockSys | 2 |