EDBT 2026 Demo / reviewers in the wild / expert
Zhangying He
dblp:292/6109
· DBLP profile ↗
9ranked-venue papers
8as first author
9since 2021 · last 2026
0000-0002-5072-2955ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 8 · 7 first-author · 8 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Transformers for Tabular Anomaly Detection in Hardware-Assisted Security: A Systematic and Empirical StudyabstractTransformer-based architectures have achieved remarkable success in language and vision tasks; however, their suitability for structured tabular data remains insufficiently understood. This limitation is particularly significant in hardware-assisted security, where anomaly detection relies on correlated, high-dimensional numerical measurements such as performance counters, power traces, and microarchitectural statistics. Unlike sequential or tokenized data, such inputs lack the inductive biases that Transformers naturally exploit, raising fundamental questions about their effectiveness in this domain. In this work, we present a principled and systematic investigation into the applicability of Transformer-based models for tabular anomaly detection in hardware-assisted security. We conduct a comprehensive empirical evaluation comparing Transformer-based models with state-of-the-art classical machine learning methods for hardware-assisted malware detection, across different feature sets and for both binary and multi-class classification tasks. Guided by these insights, we conclude by presenting a customized Transformer-based framework incorporating context-aware embedding strategies and architectural modifications for modeling tabular hardware data. Our findings provide empirical evidence on when and why Transformer architectures succeed or fail in this setting, offering practical guidance for their adoption in real-world hardware security systems. Zhangying He, Hossein Sayadi |
ACM Great Lakes Symposium on VLSI | 1 |
| 2025 | REACT: Randomized Encryption with AI-Controlled Targeting for Next-Gen Secure CommunicationabstractThis work introduces REACT (Randomized Encryption with AI-Controlled Targeting), a novel framework leveraging Deep Reinforcement Learning (DRL) and Moving Target Defense (MTD) to secure chaotic communication in resource-constrained environments. REACT employs a random generator to dynamically assign encryption modes, creating unpredictable patterns that thwart interception. At the receiver's end, four DRL agents collaborate to identify encryption modes and apply decryption methods, ensuring secure, synchronized communication. Evaluation results demonstrate up to 100% decryption accuracy and a 51% reduction in attack success probability, establishing REACT as a robust and adaptive defense for secure and reliable communication. Zhangying He, Hossein Sayadi |
DATE | 1 |
| 2025 | PowerPrint: Harnessing Machine Learning for Accurate and Scalable Device Fingerprinting via Power ConsumptionabstractThis paper examines the application of machine learning techniques for enhanced device fingerprinting based on power consumption. Existing works on device identification in large-scale networks struggle with accurately pinpointing individual machines among many identical devices, often relying on static fingerprinting or substantial human-involved decision-making, which is inefficient for real-time environments. In this work, we propose PowerPrint, a machine learning-based methodology designed to enhance device fingerprinting by analyzing power consumption data. PowerPrint leverages multiclass classification models to first detect two candidate machines, then further narrows down the identification to a single machine. This two-step online inference process, driven by power consumption analysis, enables precise identification within predefined categories, ensuring accurate and efficient device fingerprinting in large-scale networked systems. Experimental results indicate the effectiveness of our novel approach, with ExtraTrees and MLP classifiers achieving F1-scores of 95% and 93%, respectively, marking an improvement of up to 84% compared to baseline models not employing PowerPrint. Zhangying He, Hossein Sayadi |
ISCAS | 1 |
| 2024 | Beyond Conventional Defenses: Proactive and Adversarial-Resilient Hardware Malware Detection using Deep Reinforcement LearningabstractThis research investigates the vulnerability of machine learning-enabled Hardware Malware Detection (HMD) methods to adversarial attacks, a pressing concern undermining their efficacy against malware threats. While prior adversarial learning research primarily centered on image classification and/or overlooked adversarial attacks in HMDs, we delve into the distinctive challenges posed by adversarial attacks in the context of tabular data from processors' performance counters. This paper introduces a proactive and robust multi-phased adversarial learning and defense framework based on Deep Reinforcement Learning (DRL). In the initial phase, highly effective adversarial attacks are employed to circumvent ML-based detection mechanisms. Subsequently, an efficient deep reinforcement learning technique based on Advantage Actor Critic (A2C) is presented to predict adversarial attack patterns in realtime. Next, ML models are fortified through adversarial training to enhance their defense capabilities against both malware and adversarial attacks. To achieve greater efficiency, an RL-based constraint controller using an Upper Confidence Bounds (UCB) algorithm is proposed that dynamically assigns adversarial defense responsibilities to specialized RL agents based on different performance constraints. The results demonstrate the proposed framework's effectiveness, indicating up to 86% boost in F1-score for defending against adversarial attacks across all models, leading to detection rate of 96.1% for the top-performing adaptive malware detector. Zhangying He, Houman Homayoun, Hossein Sayadi |
DAC | 1 |
| 2024 | ObfusGate: Representation Learning-Based Gatekeeper for Hardware-Level Obfuscated Malware DetectionabstractIn this paper, we explore the interplay between code obfuscation techniques and performance counter traces to undermine Hardware Malware Detectors (HMDs) that rely on Machine Learning (ML) models. By crafting various obfuscated malware categories and analyzing a wide range of ML models, we demonstrate a notable detection performance reduction, showcasing the evasive impact of obfuscated malware in HMD methods. To counter these threats, we propose ObfusGate, an intelligent and robust defense mechanism based on feature representation learning that significantly enhances machine learning models against both obfuscated and unobfuscated malware attacks. The results indicate the effectiveness of Obfus Gate, attaining up to 24 % detection rate increase across diverse ML models assessed for hardware-level obfuscated malware detection at run-time. Zhangying He, Chelsea William Fernandes, Hossein Sayadi |
DATE | 1 |
| 2024 | The AI Companion in Education: Analyzing the Pedagogical Potential of ChatGPT in Computer Science and EngineeringabstractArtificial Intelligence (AI), with ChatGPT as a prominent example, has recently taken center stage in various domains including higher education, particularly in Computer Science and Engineering (CSE). The AI revolution brings both convenience and controversy, offering substantial benefits while lacking formal guidance on their application. The primary objective of this work is to comprehensively analyze the pedagogical potential of ChatGPT in CSE education, understanding its strengths and limitations from the perspectives of educators and learners. We employ a systematic approach, creating a diverse range of educational practice problems within CSE field, focusing on various subjects such as data science, programming, AI, machine learning, networks, and more. According to our examinations, certain question types, like conceptual knowledge queries, typically do not pose significant challenges to ChatGPT, and thus, are excluded from our analysis. Alternatively, we focus our efforts on developing more in-depth and personalized questions and project-based tasks. These questions are presented to ChatGPT, followed by interactions to assess its effectiveness in delivering complete and meaningful responses. To this end, we propose a comprehensive five-factor reliability analysis framework to evaluate the responses. This assessment aims to identify when ChatGPT excels and when it faces challenges. Our study concludes with a correlation analysis, delving into the relationships among subjects, task types, and limiting factors. This analysis offers valuable insights to enhance ChatGPT's utility in CSE education, providing guidance to educators and students regarding its reliability and efficacy. Zhangying He, Thomas Nguyen, Tahereh Miari, Mehrdad Aliasgari, Setareh Rafatirad, Hossein Sayadi |
EDUCON | 1 |
| 2024 | Redefining Trust: Assessing Reliability of Machine Learning Algorithms in Intrusion Detection SystemsabstractThe performance limitations of conventional software-based Intrusion Detection Systems (IDSs) have paved the way for the emergence of hardware-oriented approaches. These approaches harness the power of Machine Learning (ML) algorithms applied to processors’ hardware-related data, thereby enhancing the overall system’s security and efficiency. However, ensuring the dependability of ML models’ decisions is crucial, yet this aspect has been largely overlooked in previous studies. In this paper, we delve into the reliability of machine learning algorithms within hardware-oriented intrusion detection systems, focusing specifically on malware detection. Our investigation aims to bridge the existing gap by shedding light on the tradeoffs between performance vs. reliability and robustness levels exhibited by ML models in intrusion detection systems. We conduct a thorough evaluation of ML algorithms in hardware-oriented IDSs, considering factors such as training data size, number of hardware events used, and internal data separability (malware stealthiness). Additionally, we incorporate an effective model observer module to assess prediction probabilities in real-time; thereby, employing a threshold to determine the ML model’s confidence for enhanced reliable intrusion detection. Hossein Sayadi, Zhangying He, Tahereh Miari, Mehrdad Aliasgari |
ISCAS | 2 |
| 2022 | Deep Neural Network and Transfer Learning for Accurate Hardware-Based Zero-Day Malware DetectionabstractIn recent years, security researchers have shifted their attentions to the underlying processors' architecture and proposed Hardware-Based Malware Detection (HMD) countermeasures to address inefficiencies of software-based detection methods. HMD techniques apply standard Machine Learning (ML) algorithms to the processors' low-level events collected from Hardware Performance Counter (HPC) registers. However, despite obtaining promising results for detecting known malware, the challenge of accurate zero-day (unknown) malware detection has remained an unresolved problem in existing HPC-based countermeasures. Our comprehensive analysis shows that standard ML classifiers are not effective in recognizing zero-day malware traces using HPC events. In response, we propose Deep-HMD, a two-stage intelligent and flexible approach based on deep neural network and transfer learning, for accurate zero-day malware detection based on image-based hardware events. The experimental results indicate that our proposed solution outperforms existing ML-based methods by achieving a 97% detection rate (F-Measure and Area Under the Curve) for detecting zero-day malware signatures at run-time using the top 4 hardware events with a minimal false positive rate and no hardware redesign overhead. Zhangying He, Amin Rezaei 0001, Houman Homayoun, Hossein Sayadi |
ACM Great Lakes Symposium on VLSI | 1 |
| 2022 | Breakthrough to Adaptive and Cost-Aware Hardware-Assisted Zero-Day Malware Detection: A Reinforcement Learning-Based ApproachabstractIn this paper, we have identified and addressed pressing challenges associated with online and cost-effective malware detection based on Hardware Performance Counters (HPCs) information. Existing Hardware-Assisted Malware Detection (HMD) methods guided by standard Machine Learning (ML) algorithms have limited their study on detecting known signatures of malicious patterns; thus, neglecting to address unknown (zero-day) malware detection at run-time which is a more challenging problem since the malware HPC data does not match any known attack applications’ signatures in the existing database. In addition, prior works have not presented a flexible and balanced solution that considers the trade-off between detection rate and implementation cost for adaptive selection of the best performing ML algorithms for online malware detection. In this paper, we first propose a unified feature selection method based on a heterogeneous feature fusion technique to effectively determine the most important HPC events for low-cost yet accurate malware detection. Next, we present Reinforced-HMD, a novel reinforcement learning-based framework for adaptive and cost-aware hardware-assisted zero-day malware detection based on desired performance metric and available hardware resources. To this aim, six classical and two reinforcement learning algorithms are implemented and their efficiency is thoroughly analyzed for detecting unknown malware using HPC events. Experimental results demonstrate that our Reinforced-HMD framework based on Upper Confidence Bound (UCB) learning approach achieves an accurate and robust detection rate with a 96% in both F1-score and AUC metrics for flexible and efficient zero-day malware detection while utilizing an optimal set of built-in HPC events. Zhangying He, Hosein Mohammadi Makrani, Setareh Rafatirad, Houman Homayoun, Hossein Sayadi |
ICCD | 1 |