Haoting Shen

dblp:259/5307 · also Hao-Ting Shen · DBLP profile ↗
← Back
14ranked-venue papers
1as first author
8since 2021 · last 2026
0000-0002-0244-9157ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 11 · 1 first-author · 5 since 2021Computer networks · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 How chatbot response features influence user adoption: A linguistic signaling perspective
Mingzhou Chen, Haoting Shen
Decis. Support Syst.4
2026 FBRE: Fuzzing Based Bit-Level Reverse Engineering of Vehicular CAN Bus
abstract
The Controller Area Network (CAN) bus serves as a foundational communication architecture in modern vehicles, supporting a wide range of functions, from engine control to auxiliary systems. However, lacking built-in security mechanisms makes CAN vulnerable to cyberattacks. Accurately mapping CAN signals to specific car-control actions becomes critical as it allows the detection of security breaches by pinpointing potential vulnerabilities exploited to compromise vehicular functions. Existing mapping techniques rely on CAN reverse engineering, which struggle to achieve bit-level resolution due to the huge search space of IDs and payload combinations. To address this challenge, we propose a systematic framework that includes signal boundary identification, targeted fuzz testing, and control bit analysis. Our method achieves high efficiency and precision in mapping control bits in CAN frames to car-control actions. Additionally, we developed a compact and user-friendly reverse engineering toolkit, incorporating a graphical interface to facilitate practical vehicle function testing and CAN message monitoring. Experiments on Tesla Model 3 and Leapmotor C11/C10 demonstrate that our framework is validated across different vehicle models and capable of identifying a wide range of car-control actions. Compared with previous works, our method significantly improves the resolution and automation of CAN reverse engineering.
Hanxue Shi, Yunlang Cai, Xiaohang Wang 0001, Haoting Shen, Li Lu 0008, Kui Ren 0001, Kaiwei Wu, Yinhe Shen
IEEE Trans. Computers4
2025 On Bit-level Reverse Engineering of Vehicular CAN Bus
abstract
The Controller Area Network (CAN) bus is a cornerstone of modern vehicles, orchestrating functions from engine control to auxiliary systems. However, its lack of inherent security measures makes it vulnerable to cyberattacks. Accurately mapping CAN signals with car-control actions is critical for detecting security breaches, as it allows pinpointing potential vulnerabilities exploited to compromise vehicular functions. Despite this, existing CAN reverse engineering methods struggle to achieve bit-level resolution due to the huge search space of unique IDs and payload combinations. To address this challenge, we propose a systematic framework for reverse engineering CAN bus messages, achieving precise mapping of control bits in CAN frames to car-control actions. The framework was validated on Tesla Model 3, Leapmotor C10 and C11, demonstrating its versatility across different vehicle platforms. In particular, it successfully identified 43 car-control actions on the Tesla Model 3, showcasing its extensive coverage. Furthermore, its low resource consumption enables seamless integration into compact platforms like the Raspberry Pi, supporting practical deployment in real-world automotive systems.
Yunlang Cai, Hanxue Shi, Xiaohang Wang 0001, Haoting Shen, Li Lu 0008, Kui Ren 0001
DAC4
2025 A Data-Centric Image Enhancement Framework for Reducing Domain Discrepancies in Autonomous Driving Safety Evaluation
abstract
With the rapid progress of autonomous driving technologies, large-scale, data-driven validation has become a cornerstone for ensuring system safety prior to deployment. While real-world road testing remains the gold standard, it is costly, time-consuming, and often infeasible for evaluating safety-critical edge cases. Consequently, simulation-based testing has gained traction as a scalable alternative, capable of generating diverse sensor data under controlled conditions. However, current simulation platforms primarily inherit techniques that focus on improving visual fidelity in the aspects along with human’s perception, but fail to optimize the scenario generation for the sensing of autonomous driving system. A big gap between the road perception performances of the system in field and simulation tests is demonstrated. Here we propose an image enhancement model, employing a generative adversarial network (GAN) to introduce real-world features that are imperceptible for human but critical for AI perception in the simulation. A YOLO model is used as the example perception part of the autonomous driving system. Experimental results demonstrate that the consistency of the recognition accuracies on simulated and real-world datasets is increased significantly. It improves the reliability of simulation-based testing scenarios and accelerates the development of autonomous driving perception models, ultimately contributing to safer vehicle deployment.
Zhilin Gao, Jianwen Zhou, Haoting Shen
GLOBECOM4
2024 A Unified and Fully Automated Framework for Wavelet-Based Attacks on Random Delay
abstract
As a common defense against side-channel attacks, random delay insertion introduces noise into the executive flow of encryption, which increases attack complexity. Accordingly, various techniques are exploited to mitigate the defense effect of such insertions. As an advanced mathematical technique, wavelet analysis is considered to be a more effective technology according to its detailed and comprehensive interpretation of signals. In this paper, we propose a unified and fully automated wavelet-based attack framework (denoted asUWAF), whose data processing is kept within one unified wavelet domain, with three enhanced components: denoising, alignment and key extraction. We put forward a new idea of combining machine learning with wavelet analysis to realize the full automation of the program for attack framework, rendering it possible to search exhaustively for the optimal combination of parameter settings in wavelet transform. Our proposal finds a new setting of wavelet parameters that have not been exploited ever before and achieves the performance enhancement for about 20 times fewer traces required for successful key recovery.UWAFis compared with several mainstream attack frameworks. Experimental results show that it outperforms those counterparts, and can be considered as an effective framework-level solution to defeat the countermeasure of random delay insertion.
Qianmei Wu, Fan Zhang 0010, Shize Guo, Kun Yang 0012, Haoting Shen
IEEE Trans. Computers5
2022 DARPT: defense against remote physical attack based on TDC in multi-tenant scenario
abstract
With rapidly increasing demands for cloud computing, Field Programmable Gate Array (FPGA) has become popular in cloud datacenters. Although it improves computing performance through flexible hardware acceleration, new security concerns also come along. For example, unavoidable physical leakage from the Power Distribution Network (PDN) can be utilized by attackers to mount remote Side-Channel Attacks (SCA), such as Correlation Power Attacks (CPA). Remote Fault Attacks (FA) can also be successfully presented by malicious tenants in a cloud multi-tenant scenario, posing a significant threat to legal tenants. There are few hardware-based countermeasures to defeat both remote attacks that aforementioned. In this work, we exploit Time-to-Digital Converter (TDC) and propose a novel defense technique called DARPT (Defense Against Remote Physical attack based on TDC) to protect sensitive information from CPA and FA. Specifically, DARPT produces random clock jitters to reduce possible information leakage through the power side-channel and provides an early warning of FA by constantly monitoring the variation of the voltage drop across PDN. In comparison to the fact that 8k traces are enough for a successful CPA on FPGA without DARPT, our experimental results show that up to 800k traces (100 times) are not enough for the same FPGA protected by DARPT. Meanwhile, the TDC-based voltage monitor presents significant readout changes (by 51.82% or larger) under FA with ring oscillators, demonstrating sufficient sensitivities to voltage-drop-based FA.
Fan Zhang 0010, Haoting Shen, Bolin Yang, Qianmei Wu, Kui Ren 0001
DAC3
2022 DEAN: A Lightweight and Resource-efficient Blockchain Protocol for Reliable Edge Computing
abstract
Edge computing draws a lot of recent research interests because of the performance improvement by offloading many workloads from the remote data center to nearby edge nodes. Nonetheless, one open challenge of this emerging paradigm lies in the potential security issues on edge nodes. This paper proposes a cooperative protocol, namely DEAN, equipped with a unique resource-efficient quorum building mechanism to adopt blockchain seamlessly in an edge computing infrastructure to prevent data manipulation and allow fair data sharing with quick recovery under resource constraints of limited storage, computing, and network capacity. Specifically, DEAN leverages a parallel mechanism equipped with three independent core components, effectively achieving low resource consumption while allowing secured parallel block processing on edge nodes. We have implemented a system prototype based on DEAN and experimentally verified its effectiveness with a comparison with four popular blockchain implementations: Ethereum, Parity, IOTA, and Hyperledger Fabric. Experimental results show that the system prototype exhibits high resilience to arbitrary failures. Performance-wise, DEAN-based blockchain implementation out-performs the state-of-the-art blockchain systems with up to 88.6 x higher throughput and 26 x lower latency.
Abdullah Al-Mamun 0001, Haoting Shen, Dongfang Zhao 0001
IPDPS2
2021 DeSMP: Differential Privacy-exploited Stealthy Model Poisoning Attacks in Federated Learning
abstract
Federated learning (FL) has become an emerging machine learning technique lately due to its efficacy in safeguarding the client’s confidential information. Nevertheless, despite the inherent and additional privacy-preserving mechanisms (e.g., differential privacy, secure multi-party computation, etc.), the FL models are still vulnerable to various privacy-violating and security-compromising attacks (e.g., data or model poisoning) due to their numerous attack vectors which in turn, make the models either ineffective or suboptimal. Existing adversarial models focusing on untargeted model poisoning attacks are not enough stealthy and persistent at the same time because of their conflicting nature (large scale attacks are easier to detect and vice versa) and thus, remain an unsolved research problem in this adversarial learning paradigm. Considering this, in this paper, we analyze this adversarial learning process in an FL setting and show that a stealthy and persistent model poisoning attack can be conducted exploiting the differential noise. More specifically, we develop an unprecedented DP-exploited stealthy model poisoning (DeSMP) attack for FL models. Our empirical analysis on both the classification and regression tasks using two popular datasets reflects the effectiveness of the proposed DeSMP attack. Moreover, we develop a novel reinforcement learning (RL)-based defense strategy against such model poisoning attacks which can intelligently and dynamically select the privacy level of the FL models to minimize the DeSMP attack surface and facilitate the attack detection.
Md Tamjid Hossain, Shafkat Islam, Shahriar Badsha, Haoting Shen
MSN4
2020 Reflector: a fine-grained I/O tracker for HPC systems
abstract
We present Reflector, to support both high-level and low-level I/O monitoring through user-defined interfaces such as HDF5 and NetCDF in addition to POSIX- and MPI-IO. We evaluate Reflector on both an on-premises 500-core HPC cluster and a leadership-class supercomputer at the Lawrence Berkeley National Laboratory. Preliminary results are promising as the system prototype incurs negligible performance overhead and clearly illustrates the I/O patterns and bottlenecks of multiple applications.
Abdullah Al-Mamun 0001, Jialin Liu 0002, Tonglin Li, Quincey Koziol, Zhongyi Zhai, Junyan Qian, Haoting Shen, Dongfang Zhao 0001
PPoPP7
2019 LPN-based Device Authentication Using Resistive Memory
abstract
Recent progress in the design and implementation of resistive memory components such as RRAMs and PCMs has introduced opportunities for developing novel hardware security solutions using unique physical properties of these devices. In this work, we utilize the faults in HfOx-based resistive RRAMs to design secure, lightweight device authentication protocols. To detail our design, first, we introduce the device breakdown problem due to high bias conditions in resistive memory and the physics behind non-recoverable resistive states. Then, using the concepts of learning with parity noise (LPN) based authentication protocols, we demonstrate that simple READ and WRITE operations on resistive memory cells with defects can perform necessary calculation required for LPN-based authentication schemes. Next, we design two simple authentication protocols using resistive memory based hardware and provide a detailed security analysis for these protocols. We find that these authentication mechanisms can offer significant improvement against its CMOS counterpart regarding the area and power budget. Finally, we provide detailed physical design requirements for the memory components. The resistive memory components that are capable of performing the proposed authentication protocols have also been designed and fabricated. From our analysis, we find that these memory dependent authentication protocols are lightweight, resistant to learning attacks from active and passive adversaries, and reliable under normal changes in operating conditions.
Md Tanvir Arafin, Haoting Shen, Mark Tehranipoor, Gang Qu 0001
ACM Great Lakes Symposium on VLSI2
2018 EMFORCED: EM-based Fingerprinting Framework for Counterfeit Detection with Demonstration on Remarked and Cloned ICs
abstract
Today’s globalized electronics supply chain is prone to counterfeit chip proliferation. Existing techniques to detect counterfeit integrated circuits (ICs) are limited by relatively high cost, lengthy inspection time, destructive nature, and restriction to a pre-packaging environment. We propose a novel method of counterfeit IC detection which takes advantage of design-specific electromagnetic (EM) fingerprints generated by simulating on-chip clock distribution networks. Through exploitation of the chip’s physical characteristics, our technique can help detect foundry of origin. We validate our approach on 8051 microcontrollers from three different vendors and utilize principal component analysis to distinguish the acquisitions by vendor. Our results show that near-field EM measurements combined with unsupervised machine learning provide ≈ 99% accuracy in counterfeit detection through design-specific fingerprint classification.
Andrew Stern, Ulbert Botero, Bicky Shakya, Haoting Shen, Domenic Forte, Mark Tehranipoor
ITC4
2018 UCR: An Unclonable Environmentally Sensitive Chipless RFID Tag For Protecting Supply Chain
abstract
Chipless Radio Frequency Identification (RFID) tags that do not include an integrated circuit (IC) in the transponder are more appropriate for supply-chain management of low-cost commodities and have been gaining extensive attention due to their relatively lower price. However, existing chipless RFID tags consume considerable tag area and manufacturing time/cost because of complex fabrication process (e.g., requiring removing or shorting some resonators on the tag substrate to encode data). Worse still, their identifiers (IDs) are deterministic, clonable, and small in terms of bitwidth. To address these shortcomings and help preserve the cold chain for commodities (e.g., vaccines, pharmaceuticals, etc.) sensitive to temperature, we develop a novel unclonable environmentally sensitive chipless RFID (UCR) tag that intrinsically generates a unique ID from both manufacturing variations and ambient temperature variation. A UCR tag consists of two parts: (i) a certain number of concentric ring slot resonators integrated on a certain laminate (e.g., TACONIC TLX-0), whose resonance frequencies rely on geometric parameters of slot resonators and dielectric constant of substrate material that are sensitive to manufacturing variations, and (ii) a stand-alone circular ring slot resonator integrated on a particular substrate (e.g., grease) that will be melted at a high temperature, whose resonance frequency relies on geometric parameters of slot resonator, dielectric constant of substrate material, and ambient temperature. UCR tags have the capability to track commodities and their temperatures in the supply chain. The area of UCR tag is comparable to regular quick response (QR) code. Experimental results based on UCR tag prototypes have verified their uniqueness and reliability.
Kun Yang 0012, Ulbert Botero, Haoting Shen, Damon L. Woodard, Domenic Forte, Mark Tehranipoor
ACM Trans. Design Autom. Electr. Syst.3
2018 Hardware-Enabled Pharmaceutical Supply Chain Security
abstract
The pharmaceutical supply chain is the pathway through which prescription and over-the-counter (OTC) drugs are delivered from manufacturing sites to patients. Technological innovations, price fluctuations of raw materials, as well as tax, regulatory, and market demands are driving change and making the pharmaceutical supply chain more complex. Traditional supply chain management methods struggle to protect the pharmaceutical supply chain, maintain its integrity, enhance customer confidence, and aid regulators in tracking medicines. To develop effective measures that secure the pharmaceutical supply chain, it is important that the community is aware of the state-of-the-art capabilities available to the supply chain owners and participants. In this article, we will be presenting a survey of existing hardware-enabled pharmaceutical supply chain security schemes and their limitations. We also highlight the current challenges and point out future research directions. This survey should be of interest to government agencies, pharmaceutical companies, hospitals and pharmacies, and all others involved in the provenance and authenticity of medicines and the integrity of the pharmaceutical supply chain.
Kun Yang 0012, Haoting Shen, Domenic Forte, Swarup Bhunia, Mark Tehranipoor
ACM Trans. Design Autom. Electr. Syst.2
2017 Poly-Si-Based Physical Unclonable Functions
abstract
Physically unclonable functions (PUFs) were introduced over a decade ago for a variety of security applications. Silicon PUFs exploit uncontrollable random variations from manufacturing to generate unique and random signatures/ responses. However, such sources of randomness may become limited during standard CMOS manufacturing as processes continue to mature especially with the advances in design for manufacturability. Recently, poly-Si is proposed to improve PUF quality by offering considerable random variations at the materials level, which is from randomly distributed grain boundaries and trapped charges in poly-Si. In this paper, we develop a poly-Si field-effect transistor (FET) model to study the properties of poly-Si-based PUFs under different supply voltages (VDD) and temperatures (T). Simulation results obtained from ring oscillator and arbiter PUFs show that compared with conventional CMOS-based PUFs, the reliability of poly-Si-based PUFs can be improved from around 90% to 98% and the PUF devices are robust against varying VDDand T.
Haoting Shen, Fahim Rahman, Bicky Shakya, Xiaolin Xu 0001, Mark Tehranipoor, Domenic Forte
IEEE Trans. Very Large Scale Integr. Syst.1