EDBT 2026 Demo / reviewers in the wild / expert
Fanjin Xu
dblp:268/1022
· DBLP profile ↗
4ranked-venue papers
1as first author
4since 2021 · last 2025
0000-0002-8045-3848ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Secure Token Pruning Mechanism and Accelerator for Vision TransformerabstractVision Transformers (ViTs) are vulnerable to adversarial patch attacks, posing serious challenges to their deployment in security-critical applications. Existing defense strategies improve robustness but at the cost of significant computational overhead, limiting their practicality. To address this, we propose STEM, a lightweight and parallelizable token pruning defense mechanism that enhances robustness while reducing inference cost. STEM integrates two components: Block-wise Selective Fusion (BSF), which fuses redundant tokens and flags suspicious ones, and Identify-Prune (IP), which identifies and prunes adversarial tokens based on multi-head attention statistics.To support STEM efficiently in hardware, we further design STEMA, a scalable accelerator featuring a dedicated Security Core operating in parallel with the ViT backbone. STEMA includes specialized engines for token fusion, top-k selection, and metadata management, occupying only 5% of chip area.Experimental results show that STEM achieves state-of-the-art (SOTA) defense performance and demonstrates excellent efficiency. Specifically, STEM improves robustness by up to 4.7× compared to token pruning methods and achieves 46.8×–105.8× runtime improvements over defense baselines. STEMA further delivers up to 71× speedups and 397× energy efficiency improvements, demonstrating its suitability for secure and efficient ViT deployment, especially in edge environments. Qiuran Li, Jingkui Yang, Fanjin Xu, Jinjin Shao |
ICCAD | 3 |
| 2025 | ViTProbe: Defending Vision Transformers against Adversarial Patch Attacks through Single-Layer InspectionabstractVision Transformer (ViT) has achieved remarkable performance in image classification but remains susceptible to natural corruptions and adversarial attacks. These attacks fabricate either global image-wide or localized patch-based perturbations. Although ViT demonstrates inherent resilience to natural corruptions and global image-wide adversarial attacks, it is still vulnerable to patch-based attacks. Current defense methods for ViT against such attacks typically involve re-inference or layer-by-layer analysis, incurring substantial computational costs. To address this issue, we introduce ViTProbe, a defense mechanism that identifies and removes adversarial patches within a single layer of the model. It is observed that the relative length of attention score associated with an adversarial patch is extremely low. Leveraging this insight, ViTProbe detects adversarial patches by assessing the ratio between components of the attention score matrix and the corresponding components of the input matrix in the model’s specific layer. Potential adversarial patches are discarded before forwarding the chosen layer’s output, thereby eliminating the need for re-inference. Comprehensive evaluations against three patched-based attacks demonstrate that ViTProbe can recover the classification accuracy under adversarial patch attacks to 94.17% of the clean accuracy on average, achieving performance comparable to state-of-the-art defense while significantly reducing computational costs by up to 95.67%. Fanjin Xu, Qiuran Li, Kaiyan Wen |
SMC | 1 |
| 2023 | Correlation-guided Placement for Nonvolatile FPGAsabstractNonvolatile FPGAs have advantages of high density and near-zero leakage power compared with traditional SRAM-based FPGAs. However, they have lifetime issue. To deal with this problem, a series of configuration files can be generated with various logical-to-physical mappings so that intensive writes can be distributed to different physical regions for wear leveling. Currently, the configuration files are independently generated, which is time-consuming. In this paper, we propose to investigate correlations between components and use them to guide the computer-aided design (CAD) flow to speed up the procedure of deriving configuration files. Specifically, we develop dynamic probabilities to drive the swapping of placement step in the CAD flow to push components to locate appropriate positions quickly. Evaluation shows that the proposed schemes can deliver 36.32% reduction in number of swappings when compared with existing strategies, while maintaining comparable performance and lifetime. Mengying Zhao, Fanjin Xu, Huichuan Zheng, Yuqing Xiong, Zhiping Jia, Xiaojun Cai |
DAC | 2 |
| 2022 | Adaptive Mode Transformation for Wear Leveling in Nonvolatile FPGAsabstractNowadays, field programmable gate arrays (FPGAs) have been widely adopted to serve as accelerators in artificial intelligence and big data related applications. Since the static random access memory (SRAM)-based FPGA is suffering from limited density and high leakage power, nonvolatile FPGAs have been proposed, where SRAM is replaced with emerging nonvolatile memories (NVMs). Multilevel cell (MLC), which can store multiple bits within one memory cell, further improves the density of nonvolatile FPGAs and shows great potential to enable large on-chip memory. However, it suffers from limited lifetime. In this article, we propose a wear leveling scheme to improve lifetime of MLC-based nonvolatile FPGAs. Instead of generating a series of configuration files for runtime reconfiguration, we propose to identify write-heavy MLC regions and dynamically transform them to durable single-level cell (SLC) mode. Specifically, we propose three modules: 1) pertaining to write behavior monitor; 2) approximate cost calculator; and 3) mode transformation manager to achieve adaptive mode transformations. We consider FPGA features to design these modules, which is different from implementations for MLC-SLC transformation in CPU architecture. Evaluation shows that the proposed scheme can improve lifetime for MLC nonvolatile FPGAs by$6.03\times $, at cost of 12.5% storage overhead. Huichuan Zheng, Fanjin Xu, Mengying Zhao |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |