Yankun Zhu

dblp:348/4812 · DBLP profile ↗
← Back
4ranked-venue papers
4as first author
4since 2021 · last 2025
0009-0007-4690-9200ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 4 · 4 first-author · 4 since 2021
YearPublicationVenuePosition
2025 Defending Side-Channel Attacks in Convolutional Neural Networks with Channel-Level Parallelization
abstract
Side-channel attacks (SCAs) pose significant threats to the security of neural networks (NNs) deployed on hardware platforms, especially in cloud Field-Programmable Gate Array (FPGA) environments. This paper presents a novel approach to enhance the security of convolutional layers in NNs against SCAs by introducing a channel-level parallel structure. Compared with the original structure and the state-of-the-art masking technique, the channel-level parallel structure significantly reduces the success rate of SCAs (from 97.13% to 5.46% on average) and is able to be optimized for either low resource overhead (83.64% reduction) or good timing performance (83.01% improvement).
Yankun Zhu, Ranxi Lin, Pingqiang Zhou
FCCM1
2024 LDL-SCA: Linearized Deep Learning Side-Channel Attack Targeting Multi-tenant FPGAs✱
abstract
In recent years, deep-learning side-channel attacks (DL-SCA) have gained increasing attention due to their enhanced efficacy against cryptographic modules. This paper explores that traditional non-profiled DL-SCA is unable to discern correct cipher keys in multi-tenant Field Programmable Gate Array (FPGA) scenarios due to the low correlation between power traces and cipher keys. To address this challenge, we propose Linearized Deep Learning Side-Channel Attack (LDL-SCA). Through modifying the output layer and integrating K-means clustering, LDL-SCA is capable of capturing linear features regardless of the low correlation between input and label. Moreover, we introduce new evaluation metrics derived from R2 and Cohen-kappa score. Our experiments show that LDL-SCA generate results with improved distinguishability, which has about ten times smaller standard deviation and ten times larger peak differences compared with Correlation Power Analysis (CPA) and Linear Regression Analysis (LRA).
Yankun Zhu, Siting Liu 0001, Liyu Yang, Pingqiang Zhou
ACM Great Lakes Symposium on VLSI1
2024 Protecting Parallel Data Encryption in Multi-Tenant FPGAs by Exploring Simple but Effective Clocking Methodologies
abstract
Capitalizing on their versatility and high-performance attributes within heterogeneous designs, increasingly number of field-programmable gate arrays (FPGAs) are integrated into cloud data centers by cloud service providers (CSPs). While CSPs intend to reduce the cost by sharing one board among multiple users (called multi-tenant FPGA), hardware security problems such as side-channel attacks restrict it from spreading commercially. Existing research works have underscored the feasibility of remote side-channel attacks targeting a singular advanced encryption standard (AES) module on multi-tenant FPGAs, but they have not looked into the scenario of parallel data encryption on multiple AES modules for a single tenant, which is possible due to the small resource consumption of one AES module. In this work, we scrutinize correlation power analysis (CPA)-based side-channel attacks on parallel data encryption modules and develop two simple yet effective protective methods based on clocking methodologies—clocking phase shift and small frequency shift. The former technique adopts an identical clock frequency but with distinctive clocking phase to parallel encryption modules while the latter implements slightly different clock frequencies for parallel encryption modules. Experimental results show that both the methods can effectively increase the minimum required power traces for successful CPA, thus instituting a natural protective barrier for parallel data encryption.
Yankun Zhu, Pingqiang Zhou
IEEE Trans. Very Large Scale Integr. Syst.1
2023 Exploring Remote Power Attacks Targeting Parallel Data Encryption On Multi-Tenant FPGAs
abstract
Cloud service providers (CSPs) are increasingly incorporating Field Programmable Gate Arrays (FPGAs) into their cloud data centers due to the benefits of their flexibility and high performance in heterogeneous designs. However, the optimization of hardware resource utilization through multi-tenancy presents new security concerns. Prior research has demonstrated that remote side-channel attacks represent a significant security threat in the case of a single Advanced Encryption Standard (AES) module. However, it remains an open question whether parallel encryption can offer natural protection against Correlation Power Analysis (CPA). Our research focuses on side-channel attacks on parallel data encryption modules. We implemented delay-line based power sensors to collect mixed power traces and conducted CPA to steal the cipher key. Our results show that clocking methodology would have a significant influence on data protection. If parallel modules work at the same frequency without difference in clocking phase, the mixed voltage drops would contain sufficient information for attackers to decrypt the cipher key. Nevertheless, once the victim applies unique clocking phase to each module, he would convert voltage fluctuations from other modules into noises that offer a natural protection mechanism for parallel data encryption.
Yankun Zhu, Jindong Zhou, Pingqiang Zhou
ACM Great Lakes Symposium on VLSI1