EDBT 2026 Demo / reviewers in the wild / expert
Congming Wei
dblp:273/7945
· DBLP profile ↗
14ranked-venue papers
5as first author
13since 2021 · last 2026
0000-0003-4029-0746ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 3 first-author · 6 since 2021Systems, architecture and hardware · 4 · 4 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Locality Does Matter: An Assessment Metric Adapted for Cluster-Based Side-Channel Analysis on Public Key CryptosystemsabstractCluster-based side-channel analysis (SCA) is a commonly used side-channel analysis method for public key cryptography systems. This paper focuses on assessment metrics to improve the efficiency and accuracy of key recovery in cluster-based SCA processes. We introduce a novel metric called adjacent distance coefficient (AD coefficient). Different from traditional metrics like silhouette coefficient, membership degree, and information entropy, the AD coefficient, by considering local density and avoiding the computation of cluster centers, is less influenced by the shape and size of data, thereby overcoming limitations of traditional metrics. Experiments on RSA, SM2, and ECC demonstrate that the AD coefficient exhibits higher accuracy compared to traditional metrics, especially under conditions with noise and random delays, where it shows significant robustness. Incorporating the AD coefficient, we propose an assessment method to detect whether cryptographic devices are resistant to cluster-based SCA attacks, offering a convenient quantitative measure for the security evaluation of cryptographic devices. Jinghong Ding, An Wang 0001, Congming Wei, Weiping Gong, Jingjie Wu, Liehuang Zhu |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2026 | An Efficient Ensemble Framework to Assist Profiled Side-Channel Analysis by Machine LearningabstractThe application of machine learning techniques in side-channel analysis has recently received increased attention. Finding the best hyperparameters to achieve optimal performance for machine learning models in side-channel analysis is still a challenging endeavor. In order to solve the problem, we present an efficient ensemble framework designed to support profiled side-channel analysis for attacking cryptographic devices with countermeasures. Our proposed framework can partially mitigate the impact of traditional countermeasures employed in cryptographic devices. Additionally, we introduce a novel voting method called elite voting, which leverages candidate keys with higher probabilities to recover the secret key and adjusts the voting weights for better candidate keys. Experimental results illustrate that our proposed framework can effectively recover the right key from cryptographic devices with countermeasures through multiple experiments. It enhances the signal-to-noise ratio of traces and successfully recovers the right key across various datasets. Furthermore, when compared to traditional methods, our elite voting method further enhances the performance of ensemble learning by reducing the number of traces needed to recover the secret key. It exhibits superior performance compared to other ensemble methods, as it can reduce the minimum required number of traces significantly. Yaoling Ding, An Wang 0001, Shaofei Sun, Congming Wei, Liehuang Zhu |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 5 |
| 2026 | A UMAP-Based Clustering Side-Channel Analysis on Public-Key CryptosystemsabstractHorizontal analysis is a widely adopted method in side-channel analysis, particularly for public-key cryptosystems, where attackers aim to recover the key from a single trace. Current methods rely on trace segmentation, dimensionality reduction, and classification, but high noise and poor feature preservation hinder accuracy. Noise blurs cryptographic operation segment boundaries, and existing dimensionality reduction techniques fail to maintain the inherent distribution of trace points in a high-dimensional space. As a result, secret information recovery based on clustering remains inaccurate. This paper proposes an automated horizontal analysis framework named UMAP-HC to improve secret information recovery accuracy. The framework employs a sliding segmentation method to locate cryptographic operations in noisy traces with blurred segment boundaries. It leverages uniform manifold approximation and projection (UMAP) for feature preservation and hierarchical clustering for secret information recovery. Experimental results on four open access public-key algorithm power trace datasets, an SM2 power trace collected from a smart card, and an ECC power trace with dummy operation countermeasures demonstrate that UMAP-HC effectively classifies cryptographic operations, accurately locates operation segments, and recovers secret key. It achieves up to 100% recovery accuracy, surpassing previous methods by 40%-70%, with normalized mutual information reaching 1, an improvement of 0.02-0.99 over existing approaches. Yuhan Qian, Yaoling Ding, Shaofei Sun, Congming Wei, An Wang 0001, Liehuang Zhu |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2026 | Bridging Lab and Industry: Practical SPA-GPT on Cryptosystems Boosted by LSTM and Simulated AnnealingabstractSimple Power Analysis is a commonly used method in Side-Channel Analysis on cryptosystems, which requires a significant amount of labor costs for segmentation. General Pulse Tailor for Simple Power Analysis (SPA-GPT) proposed in CHES 2024 utilizes reinforcement learning to achieve automated segmentation. However, its low efficiency and only targeting public-key algorithms limit its practical applications. In this paper, we propose a practical method, which utilize long short-term memory network and attention mechanism, coupled with a new deep Q-network policy using Simulated Annealing strategy, to solve the contradiction between reinforcement learning and high efficiency in trace segmentation. Moreover, the novel agent proposed in this paper also demonstrates transferability, enabling direct segmentation of a trace under varying lengths and signal-to-noise ratio conditions once the agent has been fully trained. In addition, our new approach is applicable for locating each execution of block ciphers in various encryption modes. Comparative experiments are conducted on 14 datasets, which are collected from software or hardware implementations of RSA, ECC, ML-KEM, AES, PRESENT, and SIMON, running on microcontrollers, FPGAs, or smart cards. Experimental results show that the new method enhances time efficiency by 50.34% to 94.24% while reducing network parameters by 87.84% compared to SPA-GPT. Yaoling Ding, An Wang 0001, Congming Wei, Liehuang Zhu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | An Intelligent Framework for Cluster-Based Side-Channel Analysis on Public-Key CryptosystemsabstractClassical cluster-based side-channel analysis (SCA) uses clustering algorithms to analyze power traces and often, principal component analysis to reduce the dimension of data, resulting in that clustering may not deal well with high-dimensional traces, such as cryptographic algorithm implementations with countermeasures. In this article, we propose an intelligent framework for cluster-based SCA, which includes three steps of clustering, classification and correction, for processing large high-dimensional data. By combining unsupervised clustering and supervised deep learning techniques, the framework succeeds in mining the data for additional in-depth information. In addition, unlike traditional cluster-based SCA, our approach focuses on deep learning and deliberately avoids over-reliance on cluster labels during classification. And metrics for correction are adopted to achieve a high level of reliability in key recovery. Experiments on the RSA smart card based on Montgomery ladder implementation and FPGA-based ECC with random delay demonstrate that our framework can significantly improve the success rate with strong robustness. Congming Wei, Shulin He, An Wang 0001, Shaofei Sun, Yaoling Ding, Liehuang Zhu |
IEEE Internet Things J. | 1 |
| 2025 | Make It Easy! Timing Leakage Analysis on Cryptographic Chips Based on Horizontal LeakageabstractTiming analysis presents a significant threat to cryptographic modules. However, traditional timing leakage analysis has notable limitations, especially when precise execution times cannot be obtained. In this article, we propose a novel timing leakage analysis method that leverages horizontal leakage in the power/electromagnetic channel by detecting the trace length of encryption processes under varying inputs. To demonstrate the effectiveness of our approach, we conducted systematic experimental evaluations across a range of cryptographic devices. In comparison to timing leakage analysis based on plaintext-ciphertext correlation, our method offers higher accuracy at lower testing costs and exhibits improved resistance to vertical noise. Guangze Hong, An Wang 0001, Congming Wei, Yaoling Ding, Shaofei Sun, Liehuang Zhu |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2025 | CL-SCA: A Contrastive Learning Approach for Profiled Side-Channel AnalysisabstractSide-channel analysis (SCA) based on machine learning, particularly neural networks, has gained considerable attention in recent years. However, previous works predominantly focus on establishing connections between labels and related profiled traces. These approaches primarily capture label-related features and often overlook the connections between traces of the same label, resulting in the loss of some valuable information. Besides, the attack traces also contain valuable information that can be used in the training process to assist model learning. In this paper, we propose a profiled SCA approach based on contrastive learning named CL-SCA to address these issues. This approach extracts features by emphasizing the similarities among traces, thereby improving the effectiveness of key recovery while maintaining the advantages of the original SCA approach. Through experiments of different datasets from different platforms, we demonstrate that CL-SCA significantly outperforms other approaches. Moreover, by incorporating attack traces into the training process using our approach, we can further enhance its performance. This extension can improve the effectiveness of key recovery, which is fully verified through experiments on different datasets. Annyu Liu, An Wang 0001, Shaofei Sun, Congming Wei, Yaoling Ding, Yongjuan Wang, Liehuang Zhu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Release the Power of Rejected Signatures: An Efficient Side-Channel Attack on the ML-DSA CryptosystemabstractThe module-lattice-based digital signature standard, formerly known as CRYSTALS-DILITHIUM, is a lattice-based post-quantum cryptographic scheme. In August 2024, the National Institute of Standards and Technology officially standardized ML-DSA under FIPS 204. ML-DSA generates one valid signature and multiple rejected signatures during a single signing process. Most side-channel attacks targeting ML-DSA have focused solely on the valid signature, while largely neglecting the hints contained in rejected signatures. Building on prior SASCA frameworks originally proposed for ML-DSA, in this paper we present an efficient and fully practical instantiation of a private-key recovery attack on ML-DSA that jointly exploits side-channel leakages from both valid and rejected signatures within a unified factor graph. This concrete instantiation maximizes the information extracted from a single signing attempt and minimizes the number of required traces for full key recovery. We conducted a proof-of-concept experiment with both reference and ASM-optimized implementations on a Cortex-M4 core chip, where the results demonstrate that incorporating rejected signatures reduces the required number of traces by at least 50.0% for full key recovery. Moreover, we show that using only rejected signatures suffices to recover the key with fewer than 30 traces under our setup. Our findings highlight that protecting rejected signatures is crucial, as their leakage provides valuable side-channel information. We strongly recommend implementing countermeasures for rejected signatures during the signing process to mitigate potential threats. Zheng Liu 0029, An Wang 0001, Congming Wei, Yaoling Ding, Annyu Liu, Liehuang Zhu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | An efficient heuristic power analysis framework based on hill-climbing algorithm
Shaofei Sun, Shijun Ding, An Wang 0001, Yaoling Ding, Congming Wei, Liehuang Zhu, Yongjuan Wang |
Inf. Sci. | 5 |
| 2024 | Time Is Not Enough: Timing Leakage Analysis on Cryptographic Chips via Plaintext-Ciphertext Correlation in Non-Timing ChannelabstractIn side-channel testing, the standard timing analysis works when the vendor can provide a measurement to indicate the execution time of cryptographic algorithms. In this paper, we find that there exists timing leakage in power/electromagnetic channels, which is often ignored in traditional timing analysis. Hence a new method of timing analysis is proposed to deal with the case where execution time is not available. Different execution time leads to different execution intervals, affecting the locations of plaintext and ciphertext transmission. Our method detects timing leakage by studying changes in plaintext-ciphertext correlation when traces are aligned forward and backward. Experiments are then carried out on different cryptographic devices. Furthermore, we propose an improved timing analysis framework which gives appropriate methods for different scenarios. Congming Wei, Guangze Hong, An Wang 0001, Jing Wang 0150, Shaofei Sun, Yaoling Ding, Liehuang Zhu, Wenrui Ma |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Differential-Aided Preimage Attacks On Round-Reduced KeccakabstractAbstract At FSE 2008, Leurent introduced the preimage attack on MD4 by exploiting differential trails. In this paper, we apply the differential-aided preimage attack to Keccak with the message modification techniques. Instead of directly finding the preimage, we exploit differential characteristics to modify the messages, so that the differences of their hashing values and the changes of given target can be controlled. By adding some constraints, a trail can be used to change one bit at a time and reduce the time complexity by a factor of 2. When the number of rounds increases, we introduce two-stage modification techniques to satisfy part of constraints as well. In order to solve other constraints, we also combine the linear-structure technique and accordingly give a preimage attack on 5-round Keccak[$r=1440,c=160,l=80$]. Congming Wei, Xiaoyang Dong 0001, Willi Meier, Lingyue Qin, Ximing Fu |
Comput. J. | 1 |
| 2023 | Improved attacks against reduced-round Whirlwind
Congming Wei, Bingyou Dong, Jialiang Hua, Xiaoyang Dong 0001, Guoyan Zhang |
Des. Codes Cryptogr. | 1 |
| 2021 | Automatic Classical and Quantum Rebound Attacks on AES-Like Hashing by Exploiting Related-Key Differentials
Xiaoyang Dong 0001, Zhiyu Zhang 0009, Siwei Sun, Congming Wei, Xiaoyun Wang 0001, Lei Hu 0003 |
ASIACRYPT (1) | 4 |
| 2020 | x-only coordinate: with application to secp256k1 " >Chosen base-point side-channel attack on Montgomery ladder with x-only coordinate: with application to secp256k1abstractThis study revisits the side‐channel security of the elliptic curve cryptography (ECC) scalar multiplication implemented with Montgomery ladder. Focusing on a specific implementation that does not use the y ‐coordinate for point addition (ECADD) and point doubling (ECDBL), the authors show that Montgomery ladder on Weierstrass curves is vulnerable to a chosen base‐point attack. Unlike the normal implementation with y ‐coordinate, in the scenario of this study, the chosen base‐point strategy will not lead to operations with two same inputs during the ECADD and/or ECDBL. Instead, by choosing a suitable base‐point, one will find that there are operations that share a common operand; while it is not the case if the base‐point is not chosen correctly. This results in the recovery of the secret (fixed) scalar. They also experiment the methods of shared operand detection on a real‐world SoC, where a secp256k1 dedicated Montgomery ladder scalar multiplication with x ‐only coordinate is implemented, to show the efficiency of the scalar recovery attack. Naturally, the attack can be generalised to other Weierstrass curves when they contain special points. Congming Wei, Jiazhe Chen, An Wang 0001, Hongsong Shi, Xiaoyun Wang 0001 |
IET Inf. Secur. | 1 |