Qifan Wang 0003

dblp:33/8610-3 · DBLP profile ↗
← Back
7ranked-venue papers
5as first author
7since 2021 · last 2026
0000-0002-5304-7975ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 5 first-author · 7 since 2021
YearPublicationVenuePosition
2026 BarkBeetle: Stealing Decision Tree Models with Fault Injection
abstract
Machine learning (ML) models—particularly decision trees (DTs)—are widely adopted across various domains due to their interpretability and efficiency. However, as ML models become increasingly integrated into privacy-sensitive applications, concerns about their confidentiality have grown—particularly in light of emerging threats such as model extraction and fault injection attacks. Assessing the vulnerability of DTs under such attacks is therefore important. In this work, we present BarkBeetle, a novel model extraction attack that leverages fault injection to recover internal structural information of DT models under black-box settings. BarkBeetle employs a bottom-up recovery strategy that uses targeted fault injection at specific nodes to efficiently infer feature splits and threshold values. Our proof-of-concept implementation demonstrates that BarkBeetle requires significantly fewer queries and recovers more structural information compared to prior state-of-the-art approaches, when evaluated on DTs trained with public UCI datasets. To validate its practical feasibility, we implement BarkBeetle on a Raspberry Pi RP2350 microcontroller and perform fault injections using the Faultier voltage glitching tool. As BarkBeetle targets general DT models, we also provide an in-depth discussion on its applicability to a broader range of tree-based applications, including data stream classification, DT model variants, and tree-based cryptography schemes.
Qifan Wang 0003, Jonas Sander, Minmin Jiang, Thomas Eisenbarth 0001, David Oswald
AsiaCCS1
2025 FaultSpy: On the Insecurity of SPDM Protocols under Fault Injection
abstract
The Security Protocol and Data Model (SPDM) establishes device-level trust in hardware platforms through authentication, attestation, and secure session establishment. While prior research has focused on formal analyses and deployment considerations, the impact of implementation-level vulnerabilities, particularly under active physical adversaries, remains largely underexplored. This work presents FaultSpy, the first systematic framework for evaluating SPDM against Fault Injection Attacks (FIAs) and their combination with other prominent attack vectors, such as Man-In-The-Middle (MITM) attacks. Leveraging the fault injection simulation tool, FaultFinder, with our custom SPDM-specific hooks, we uncover nine concrete vulnerabilities spanning both threat models. These include bypassing mutual authentication, suppressing signature generation and verification, downgrading negotiated capabilities, skipping mandatory protocol steps, manipulating key update behavior, transmitting messages intended to be encrypted in plaintext, and extracting session keys. We further validate the feasibility of these attacks through practical voltage glitching experiments on an RP2350 microcontroller. Our findings demonstrate that FIAs-whether in isolation or combined with other attacks-significantly expand the SPDM attack surface, highlighting the need for robust implementation-level countermeasures.
Peiyao Sun, Qifan Wang 0003, David F. Oswald, Mark Ryan 0001, Vladimiro Sassone, Ahmad Atamli-Reineh
TrustCom2
2025 XGT: Fast and Secure Decision Tree Training and Inference on GPUs
abstract
The decision tree (DT) model is widely usedin various applications due to its versatility, speed, and interpretability. However, outsourcing DT training and inference to cloud platforms raises data privacy concerns. While significant strides have been made in developing private DT training and inference using cryptography such as Secure Multi-Party Computation (MPC), the performance is still not ideal in real-world applications. Only a few recent works have explored using GPUs to enhance the performance of MPC-based deep learning. Nevertheless, data-dependent operations and the high communication costs inherent in MPC-based DT make the integration of GPUs a challenge. We introduce the eXpress GPU-based Tree (XGT), a fast MPC-based framework for private DT training and inference on GPUs.XGTconverts the majority of operations in training and inference into parallelizable matrix operations, supplemented by various optimizations, including matrix dimension reductions. This innovative design leads to substantial reductions in communication overhead while maintaining the critical property of obliviousness.XGTalso achieves a stronger security guarantee, where all data items, the tree shape, access patterns, and data distributions generated during the training and inference are protected.XGTonly reveals the tree depth. The experimental results show thatXGTis up to$278{\times }$faster than the previous most efficient CPU-based approach.XGToutperforms the latest GPU-based DT work by$41{\times }$. For inference,XGTis up to$2,800{\times }$faster than previous CPU-based inference schemes and at least$18 \times$faster than GPU-based.
Qifan Wang 0003, Shujie Cui, Lei Zhou 0023, Ye Dong, Jianli Bai, Yun Sing Koh, Giovanni Russello
IEEE Trans. Dependable Secur. Comput.1
2024 GTree: GPU-friendly Privacy-preserving Decision Tree Training and Inference
abstract
Outsourcing Decision tree (DT) training and inference to cloud platforms raises privacy concerns. Recent Secure Multi-Party Computation (MPC)-based methods are hindered by heavy overhead. Few recent studies explored GPUs to improve MPC-protected deep learning, yet integrating GPUs into MPC-protected DT with massive data-dependent operations remains challenging, raising question: can MPC-protected DT training and inference fully leverage GPUs for optimal performance?We present GTree, the first scheme that exploits GPU to accelerate MPC-protected secure DT training and inference. GTree is built across 3 parties who jointly perform DT training and inference with GPUs. GTree is secure against semi-honest adversaries, ensuring that no sensitive information is disclosed. GTree offers enhanced security than prior solutions, which only reveal tree depth and data size while prior solutions also leak tree structure. With our oblivious array access, access patterns on GPU are also protected. To harness the full potential of GPUs, we design a novel tree encoding method and craft our MPC protocols into GPU-friendly versions. GTree achieves ~11× and ~21× improvements in training SPECT and Adult datasets, compared to prior most efficient CPU-based work. For inference, GTree outperforms the prior most efficient work by 126× when inferring 104instances with a 7-level tree.
Qifan Wang 0003, Shujie Cui, Lei Zhou 0023, Ye Dong, Jianli Bai, Yun Sing Koh, Giovanni Russello
TrustCom1
2023 Mostree: Malicious Secure Private Decision Tree Evaluation with Sublinear Communication
abstract
A private decision tree evaluation (PDTE) protocol allows a feature vector owner (FO) to classify its data using a tree model from a model owner (MO) and only reveals an inference result to the FO. This paper proposes Mostree, a PDTE protocol secure in the presence of malicious parties with sublinear communication. We design Mostree in the three-party honest-majority setting, where an (untrusted) computing party (CP) assists the FO and MO in the secure computation. We propose two low-communication oblivious selection (OS) protocols by exploiting nice properties of three-party replicated secret sharing (RSS) and distributed point function. Mostree combines OS protocols with a tree encoding method and three-party secure computation to achieve sublinear communication. We observe that most of the protocol components already maintain privacy even in the presence of a malicious adversary, and what remains to achieve is correctness. To ensure correctness, we propose a set of lightweight consistency checks and seamlessly integrate them into Mostree. As a result, Mostree achieves sublinear communication and malicious security simultaneously. We implement Mostree and compare it with the state-of-the-art. Experimental results demonstrate that Mostree is efficient and comparable to semi-honest PDTE schemes with sublinear communication. For instance, when evaluated on the MNIST dataset in a LAN setting, Mostree achieves an evaluation using approximately 768 ms with communication of around 168 KB.
Jianli Bai, Xiangfu Song, Qifan Wang 0003, Shujie Cui, Ee-Chien Chang, Giovanni Russello
ACSAC4
2023 HT2ML: An efficient hybrid framework for privacy-preserving Machine Learning using HE and TEE
abstract
Outsourcing Machine Learning (ML) tasks to cloud servers is a cost-effective solution when dealing with distributed data. However, outsourcing these tasks to cloud servers could lead to data breaches. Secure computing methods, such as Homomorphic Encryption (HE) and Trusted Execution Environments (TEE), have been used to protect outsourced data. Nevertheless, HE remains inefficient in processing complicated functions (e.g., non-linear functions) and TEE (e.g., Intel SGX) is not ideal for directly processing ML tasks due to side-channel attacks and parallel-unfriendly computation. In this paper, we propose a hybrid framework integrating SGX and HE, called HT2ML, to protect user's data and models. In HT2ML, HE-friendly functions are protected with HE and performed outside the enclave, while the remaining operations are performed inside the enclave obliviously. HT2ML leverages optimised HE matrix multiplications to accelerate HE computations outside the enclave while using oblivious blocks inside the enclave to prevent access-pattern-based attacks. We evaluate HT2ML using Linear Regression (LR) training and Convolutional Neural Network (CNN) inference as two instantiations. The performance results show that HT2ML is up to ∼11× faster than HE only baseline with 6-dimensional data in LR training. For CNN inference, HT2ML is ∼196× faster than the most recent approach (Xiao et al., ICDCS'21).
Qifan Wang 0003, Lei Zhou 0023, Jianli Bai, Yun Sing Koh, Shujie Cui, Giovanni Russello
Comput. Secur.1
2022 EnclaveTree: Privacy-preserving Data Stream Training and Inference Using TEE
abstract
The classification service over a stream of data is becoming an important offering for cloud providers, but users may encounter obstacles in providing sensitive data due to privacy concerns. While Trusted Execution Environments (TEEs) are promising solutions for protecting private data, they remain vulnerable to side-channel attacks induced by data-dependent access patterns. We propose a Privacy-preserving Data Stream Training and Inference scheme, called EnclaveTree, that provides confidentiality for user's data and the target models against a compromised cloud service provider. We design a matrix-based training and inference procedure to train the Hoeffding Tree (HT) model and perform inference with the trained model inside the trusted area of TEEs, which provably prevent the exploitation of access-pattern-based attacks. The performance evaluation shows that EnclaveTree is practical for processing the data streams with small or medium number of features. When there are less than 63 binary features,EnclaveTree is up to ~10x and ~9 faster than naïve oblivious solution on training and inference, respectively.
Qifan Wang 0003, Shujie Cui, Lei Zhou 0023, Ocean Wu, Yonghua Zhu, Giovanni Russello
AsiaCCS1