EDBT 2026 Demo / reviewers in the wild / expert
Jhon Ordoñez
dblp:271/5073
· DBLP profile ↗
3ranked-venue papers
3as first author
3since 2021 · last 2025
0000-0002-3061-3428ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 3 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Targeted Fault Injection Attack on Semantic Segmentation ModelsabstractSemantic segmentation, a perception method that labels each pixel in an image with a category or class, is widely used in various domains, such as medical imaging and autonomous driving. The safety-critical nature of these applications imposes strict requirements of the underlying hardware accelerators being secure. Prior studies have shown that hardware accelerators are vulnerable to fault injection attacks, compromising their integrity and reliability. While these fault injection attacks are capable of causing a high accuracy drop, they are difficult to control, as faults affect the computation across random classes. In comparison, this work presents a targeted fault injection attack on black-box segmentation models. It first conducts a vulnerability analysis, demonstrating that faults injected into different parts of the model (e.g., encoder vs decoder) have distinct behaviors in terms of the region within the segmentation map affected and the pixel-level differences caused. Furthermore, this work reveals a linear relationship between the timing and duration of the fault and the region within the segmentation map affected. This translates to a new type of security vulnerability that an adversary can inject faults targeting regions that are more likely to contain critical classes, such as traffic lights or traffic signs, in the context of autonomous driving. The attack is implemented on different segmentation models, including ERFnet, ENet, and FPN with different backbones, to demonstrate its effectiveness. Jhon Ordoñez, Chengmo Yang |
ICCD | 1 |
| 2024 | Derailed: Arbitrarily Controlling DNN Outputs with Targeted Fault Injection AttacksabstractHardware accelerators have been widely deployed to improve the efficiency of DNN execution in terms of performance, power, and time predictability. Yet recent studies have shown that DNN accelerators are vulnerable to fault injection attacks, compromising their integrity and reliability. Classic fault injection attacks are capable of causing a high overall accuracy drop. However, one limitation is that they are difficult to control, as faults affect the computation across random classes. In comparison, this paper presents a controlled fault injection attack, capable of derailing arbitrary inputs to a targeted range of classes. Our observation is that the fully connected (FC) layers greatly impact inference results, whereas the computation in the FC layer is typically performed in order. Leveraging this fact, an adversary can perform a controlled fault injection attack even to a black-box DNN model. Specifically, this attack adopts a two-step search process that first identifies the time window during which the FC layer is computed and then pinpoints the targeted classes. This attack is implemented with clock glitching, and the target DNN accelerator is a DPU implemented in the FPGA. The attack is tested on three popular DNN models, namely, ResNet50, InceptionVl, and MobileNetV2. Results show that up to 93 % of inputs are derailed to the attacker-specified classes, demonstrating its effectiveness. Jhon Ordoñez, Chengmo Yang |
DATE | 1 |
| 2024 | Enhancing DNN Accelerator Integrity via Selective and Permuted RecomputationabstractHardware accelerators have been widely deployed in many machine learning applications due to their superior performance and energy efficiency. However, these accelerators are vulnerable to fault injection attacks, compromising their integrity and reliability. In particular, recent studies have revealed a targeted attack on black-box DNN models, which, through glitching the execution of the fully connected (FC) layer, is capable of derailing the DNN outputs to arbitrary classes. To defend DNN accelerators against this severe attack, this paper proposes a selective and permuted recomputation scheme. Instead of adopting dual or triple modular redundancy, which incurs high overhead, the proposed scheme selects a subset of critical FC outputs for recomputation. Meanwhile, it permutes the computation of the FC layer to prevent an adversary from pinpointing the exact time of executing the target class. The proposed defense is evaluated on three popular DNN models, namely, ResNet-50, InceptionV3, and MobileNetV3. Results show that under fault injection attacks, it can successfully recover 90--95% of the models' original accuracy, achieved with less than 1.61% runtime overhead and no storage overhead. Jhon Ordoñez, Chengmo Yang |
ICCAD | 1 |