EDBT 2026 Demo / reviewers in the wild / expert
Jian Wang 0024
dblp:39/449-24
· DBLP profile ↗
14ranked-venue papers
3as first author
7since 2021 · last 2026
0000-0001-5416-0649ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 1 since 2021Security and privacy · 4 · 4 since 2021Computer networks · 3 · 1 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | HScanner: A Knowledge-Driven Framework for Early-Stage Detection of Hardware Vulnerabilities in IIoT DevicesabstractRecurring hardware vulnerabilities, which refer to previously discovered vulnerabilities inadvertently reintroduced into new devices by designers, pose a significant challenge to the hardware security of Industrial Internet of Things (IIoT). To tackle this issue, we propose a framework called HScanner, which detects recurring hardware vulnerabilities during the design phase of IIoT devices. First, we abstract a hierarchical hardware feature set comprising 16 features (i.e., 6 coarse-grained features and 10 fine-grained features), which encapsulate crucial architectural information of the IIoT device. Next, we construct two knowledge graphs (KGs) by separately extracting hardware features from the design specifications of the target device and a well-known public hardware vulnerability database, namely National Vulnerability Database (NVD). After that, we propose a subgraph matching algorithm that identifies all subgraph mappings between the two KGs, where each mapping indicates a public hardware vulnerability involved in the device. Finally, we conduct experiments on 30 classical IIoT devices spanning four IIoT layers, including the perception, network, processing, and application layers. The results demonstrate the effectiveness of our HScanner. In detail, it finds out 40 recurring hardware vulnerabilities in 15 out of 30 devices. Among them, 34 vulnerabilities are successfully validated to be exploited to launch attacks. Compared to two state-of-the-art feature analysis methods, namely CYBOK and ICScope, as well as a manual analysis approach (MA), HScanner significantly reduces both the false alarm rate (FAR) and false negative rate (FNR). Specifically, HScanner reduces the FAR and FNR by 84.6% and 5.9% to CYBOK, 21.4% and 58.8% to ICScope, and 43.5% and 50% to MA, respectively. Zhaorui Yang 0003, Jian Wang 0024, Zi-Han Cheng |
IEEE Internet Things J. | 3 |
| 2026 | InStorm: An Instruction-Level Vulnerability Testing Framework for Graphics Processing UnitsabstractIn the last decade, an increasing number of processor vulnerabilities have been disclosed. However, existing methods have not tested the integrity and security of the GPU instruction set and microarchitecture. In this paper, we propose an instruction-level vulnerability testing frameworkInStormfor modern GPUs. Due to manufacturers' closed-source strategies, we reverse engineer the target ISA and generate efficient testing instructions by skipping redundant ones. Then, the generated instructions are executed on the target GPU to identify the potential vulnerabilities. Unfortunately, we discovered dozens of undocumented instructions with unexpected functions across six NVIDIA GPUs. Even worse, these instructions can bypass the GPU exception handling mechanism. In addition, we study a vulnerability exploitation method. An attacker can inject undocumented instructions into the victim GPU application by calling a malicious kernel loading function. Finally, we evaluate our exploitation method on a generative adversarial network accelerated by the NVIDIA GPU. The attack result demonstrates that instruction vulnerabilities can pose a significant security risk to GPU applications. We have responsibly disclosed these vulnerabilities and obtained an identifier CNVD-2025-10321. Jian Wang 0024, Zi-Han Cheng |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | Hardware Trojan Detection on PCBs Using Density Peak ClusteringabstractBoard-levelhardware Trojan (HT) is a malicious modification in the printed circuit board (PCB). It may lead the victim device to denial of service or leak confidential information. To tackle this issue, we propose an HT detection method which can detect and locate Trojan across layers. First, we obtain the thermal conductivity and temperature feature maps for a group of unauthentic PCBs. For each pixel in the maps, we construct a matrix which contains the above two feature pairs for all boards. Then, we apply the density peak clustering algorithm to distinguish Trojan-infected boards from Trojan-free ones in the feature space. Finally, we analyze the clustering result on each pixel and locate the Trojan position on the infected PCBs. The experimental results reveal that our method is effective. Generally, for the well-recognized PCBench and TRIT-PCB benchmarks, the Trojan detection accuracy is higher than 96.3% and the location error is less than 2.2%, even though the Trojan is as small as 3.5 mm$^{2}$. In addition, we demonstrate the advantages of our approach over two existing HT detection methods, namely, automated visual inspection and differential power monitoring. We also make a thorough discussion on how the PCB manufacturing process variation, feature map resolution, and Trojan area affect the detection results. Jian Wang 0024, Zhaorui Yang 0003 |
IEEE Trans. Reliab. | 2 |
| 2025 | A fast hardware Trojan detection method with parallel clustering for large-scale gate-level netlists
Gaoyuan Pan, Jian Wang 0024 |
Comput. Secur. | 3 |
| 2025 | A Covert and Efficient Attack on FPGA Cloud Based on Adaptive RONabstractThe security of the FPGA cloud has become a major concern for both industry and academia due to its widespread use in many vital domains. In this article, we expose a hardware vulnerability in the FPGA cloud and demonstrate a covert and efficient denial-of-service (DoS) attack method that severely threatens the security of the FPGA cloud. First, we adopt a flip-flop-based ring oscillator (RO) to construct an adaptive ring oscillator network (RON). Second, we devise a power and temperature-based resource adjustment algorithm to decide the maximum number of ROs in the adaptive RON. By constraining the size of the adaptive RON, the power and the thermal footprint of the attack process can be reduced. Finally, we design an adaptive frequency sweeping algorithm to automatically search for an effective frequency and perform a successful attack on the FPGA. To validate our method, we conduct exemplary attacks on FPGAs. The results reveal that our method can successfully bypass the design rule checking (DRC) and security measures of the FPGA cloud to crash the FPGA. Besides high-end FPGAs, we demonstrate our method is suitable for some FPGAs with moderate performance. Furthermore, we discuss the impact of the number of ROs and the duty cycle on the proposed method. She Tang, Jian Wang 0024, Shize Guo |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Hardware Trojan Detection for Incomplete Gate-Level Reverse NetlistabstractHardware Trojan (HT) has become an increasing security concern due to the outsourcing of integrated circuit (IC) development. By performing reverse engineering for ICs, researchers can obtain gate-level netlists to detect HTs. However, with the advancement of IC process technology, the netlists extracted by reverse engineering may be incomplete due to various factors, thus compromising the effectiveness of existing HT detection methods. In this paper, we propose a method to estimate the testability values of incomplete netlists and identify whether they are implanted with HTs. First, we develop a testability estimation method based on the Range Search Mean (RSM) algorithm, which aims to accurately reconstruct the testability values of incomplete netlists. Based on these estimated testability values, we then propose a density peaks-based detection algorithm to identify Trojan wires and find out the incomplete netlists containing HTs. The experimental results reveal the effectiveness of our method. Specifically, for the incomplete netlists generated based on Trust-hub benchmarks, the detection accuracy rate of our method exceeds 96% even when the proportion of missing information in the netlists reaches up to 1%. In addition, we demonstrate the advantages of our method over several existing HT detection methods and provide an in-depth discussion of our method. Tongfei Yan, Jian Wang 0024, Zi-Han Cheng |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | A Covert Attack Method Against FPGA CloudsabstractWith the widespread use of FPGA clouds in high-end fields such as artificial intelligence, its security issues have become a major focus for both academia and industry. In this paper, we propose a covert Denial-of-Service (DoS) attack method that specifically targets commercial FPGA clouds, posing a serious threat to the availability of FPGA clouds. Firstly, we design a malicious ring oscillator network (RON) that can evade the design rule checking of FPGA clouds. Then, we propose a resource adjustment algorithm to determine the maximum number of ring oscillators (ROs) in the RON while satisfying the FPGA's power and on-chip temperature constraints to guarantee the covertness of the attack process. Finally, we manually search for the efficient attack frequency for the RON to attack FPGAs. To validate our method, we perform DoS attacks on XVU9P and 10AX115 FPGAs. The results demonstrate that our method can evade the security measures of FPGA clouds and successfully crash FPGAs. She Tang, Jian Wang 0024, Shize Guo |
ATS | 2 |
| 2020 | Securing IoT Space via Hardware Trojan DetectionabstractHardware Trojan (HT) is a malicious modification in the chip circuitry, which may lead to undesired chip function changing or sensitive information leaking once activated. As recently studied, HT has become one of the main threats for Internet-of-Things (IoT) security, and therefore, protecting IoT against the HT attack attracts growing attention from IoT researchers. In this article, we propose an HT detection technique which makes use of chip temporal thermal information and self-organizing map (SOM) neural network to automatically isolate the Trojan-infected chips with the Trojan-free ones, and meanwhile, confirm the Trojan location at the infected chips. The experimental results reveal that our method is effective. Specifically, for the Trust-hub benchmarks, it can detect HTs which increase only 0.02% power consumption of the original design and localize the Trojan positions precisely without any error. In addition, we demonstrate the advantages of our method over two existing HT detection methods, namely, the thermal and power map (TPM) and ring oscillator net (RON), and make a thorough discussion on how the thermal image resolution, chip technology, and clustering algorithm affect the Trojan detection results. Shize Guo, Jian Wang 0024, Yubai Li, Zhonghai Lu |
IEEE Internet Things J. | 2 |
| 2019 | Toward FPGA Security in IoT: A New Detection Technique for Hardware TrojansabstractNowadays, field programmable gate array (FPGA) has been widely used in Internet of Things (IoT) since it can provide flexible and scalable solutions to various IoT requirements. Meanwhile, hardware Trojan (HT), which may lead to undesired chip function or leak sensitive information, has become a great challenge for FPGA security. Therefore, distinguishing the Trojan-infected FPGAs is quite crucial for reinforcing the security of IoT. To achieve this goal, we propose a clock-tree-concerned technique to detect the HTs on FPGA. First, we present an experimental framework which helps us to collect the electromagnetic (EM) radiation emitted by FPGA clock tree. Then, we propose a Trojan identifying approach which extracts the mathematical feature of obtained EM traces, i.e., 2-D principal component analysis (2DPCA) in this paper, and automatically isolates the Trojan-infected FPGAs from the Trojan-free ones by using a BP neural network. Finally, we perform extensive experiments to evaluate the effectiveness of our method. The results reveal that our approach is valid in detecting HTs on FPGA. Specifically, for the trust-hub benchmarks, we can find out the FPGA with always on Trojans (100% detection rate) while identifying the triggered Trojans with high probability (by up to 92%). In addition, we give a thorough discussion on how the experimental setup, such as probe step size, scanning area, and chip ambient temperature, affects the Trojan detection rate. Shize Guo, Jian Wang 0024, Yubai Li, Zhonghai Lu |
IEEE Internet Things J. | 3 |
| 2019 | Security-Aware Task Mapping Reducing Thermal Side Channel Leakage in CMPsabstractChip multiprocessor (CMP) suffers from growing threats on hardware security in recent years, such as side channel attack, hardware Trojan infection, chip clone, etc. In this paper, we propose a security-aware (SA) task mapping method to reduce the information leakage from CMP thermal side channel. First, we construct a mathematical function that can estimate the CMP security cost corresponding to a given mapping result. Then, we develop a greedy mapping algorithm that automatically allocates all threads of an application to a set of proper cores, such that the total security cost is optimized. Finally, we perform extensive experiments to evaluate our method. The experimental results show that our SA mapping effectively decreases the CMP side channel leakage. Compared to the two existing task mapping methods, Linux scheduler (LS; a standard Linux scheduler) and NoC-Sprinting (NS; a thermal-aware mapping technique), our method reduces side-channel vulnerability factor by up to 19% and 7%, respectively. Moreover, our method also gains higher computational efficiency, with improvement in million instructions per second achieving up to 100% against NS and up to 33% against LS. Shize Guo, Jian Wang 0024, Zhonghai Lu, Jinhong Guo |
IEEE Trans. Ind. Informatics | 2 |
| 2019 | Blood Triglyceride Monitoring With Smartphone as Electrochemical Analyzer for Cardiovascular Disease PreventionabstractNowadays, cardiovascular diseases have become one of the most risks threating human being's life in the world. The early screening and efficient management of cardiovascular diseases are critically important to extend the patients' life. Blood lipid level is a key biochemical factor used to estimate the cardiovascular disease in clinical situation. Triglyceride as one important blood lipid plays an indispensable role in the blood test. On the other hand, smartphone has unprecedentedly large scale users since the last decade, which paves the wide avenue for the dissemination of smartphone-associated medical devices. In this paper, we integrated the smartphone with the Triglyceride (TG) sensory module to monitor the finger pricked whole blood TG at the point of care scale. The miniaturized electrochemical analyzer was immobilized on the main board of the smartphone which enables the smartphone work as the blood TG analyzer incorporating with the disposable electrochemical TG test strip. The blood TG measured by the medical smartphone was compared to the results obtained from the conventional bulky biochemical analyzer with acceptable accuracy, which demonstrated that the proposed medical smartphone is capable of providing a point of care analytical device for blood TC monitoring at the medical level. Its potential in cardiovascular disease prevention and management was believed to be great, since the proposed system is ultracompact, smart, cost effective, reliable, and flexible with medical data acquisition. Jian Wang 0024, Xiwei Huang, Gong Ming Shi, Jinhong Guo |
IEEE J. Biomed. Health Informatics | 1 |
| 2018 | Empirical-Evolution of Frameworks Supporting Co-simulation Tool-Chain Development
Jinzhi Lu 0001, Didem Gürdür Broo, Dejiu Chen, Jian Wang 0024, Martin Törngren |
WorldCIST (1) | 4 |
| 2016 | A New CDMA Encoding/Decoding Method for on-Chip Communication NetworkabstractAs a high performance on-chip communication method, the code division multiple access (CDMA) technique has recently been applied to networks on chip (NoCs). We propose a new standard-basis-based encoding/decoding method to leverage the performance and cost of CDMA NoCs in area, power assumption, and network throughput. In the transmitter module, source data from different senders are separately encoded with an orthogonal code of a standard basis and these coded data are mixed together by an XOR operation. Then, the sums of data can be transmitted to their destinations through the on-chip communication infrastructure. In the receiver module, a sequence of chips is retrieved by taking an AND operation between the sums of data and the corresponding orthogonal code. After a simple accumulation of these chips, original data can be reconstructed. We implement our encoding/decoding method and apply it to a CDMA NoC with a star topology. Compared with the state-of-the-art Walsh-code-based (WB) encoding/decoding technique, our method achieves up to 67.46% power saving and 81.24% area saving together with decrease of 30%-50% encoding/decoding latency. Moreover, the CDMA NoC with different sizes applying our encoding/decoding method gains power saving, area saving, and maximal throughput improvement up to 20.25%, 22.91%, and 103.26%, respectively, than the WB CDMA NoC. Jian Wang 0024, Zhonghai Lu, Yubai Li |
IEEE Trans. Very Large Scale Integr. Syst. | 1 |
| 2011 | An analytical model for Network-on-Chip with finite input buffer
Jian Wang 0024, Yubai Li |
Frontiers Comput. Sci. China | 1 |