EDBT 2026 Demo / reviewers in the wild / expert
A. Adam Ding
dblp:50/3020 · also Aidong Adam Ding
· DBLP profile ↗
33ranked-venue papers
5as first author
16since 2021 · last 2026
0000-0003-1397-2442ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 2 first-author · 8 since 2021Systems, architecture and hardware · 11 · 6 since 2021Artificial intelligence and machine learning · 8 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 3 · 2 since 2021Computer networks · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Attack from Shadows: Unsupervised Side-channel Transfer Learning across Devices and ModalitiesabstractIn this work, we focus on unsupervised transfer learning attacks in side-channel analysis, where a passive adversary leverages only unlabeled traces from a target device to recover its secret key. This setting reflects a realistic assumption in practical scenarios where collecting labeled traces from the target device is infeasible, particularly for proprietary devices or cloud computing environments. Prior unsupervised deep learning side-channel analysis (DL-SCA) methods assume that a single domain-invariant model suffices across both source and target domains, but this assumption breaks down as device discrepancy increases, such as across different hardware platforms, side-channel modalities, or implementations. We address this gap with the Unsupervised Transfer Learning Attack (UTLA), which uses a separate encoder with a shared classifier to yield lower DL-SCA loss and improved key extraction fidelity. UTLA keeps the source classifier fixed while training a target-specific encoder, using Maximum Mean Discrepancy (MMD) regularization to align feature distributions. Unlike prior approaches that fail under significant domain mismatch, UTLA enables reliable key recovery across diverse scenarios: (a) different hardware platforms, from a Spartan-6 FPGA to an XMEGA MCU using only 61 traces; (b) different leakage modalities, from power measurements on an XMEGA MCU to cache-timing traces on an x86 processor using 435 traces; and (c) different implementations, from masked and shuffled AES on STM32 (ASCADv2) to masked AES on AVR (ASCADv1) using 1519 traces. Our results reveal a significant security implication: public side-channel datasets can serve as effective attack vectors against unseen devices implementing the same cryptographic algorithm. Saion Kumar Roy, A. Adam Ding, Yunsi Fei |
AsiaCCS | 3 |
| 2026 | Formal Methods-Assisted Chosen Ciphertext Attacks on PQC CRYSTALS-Kyber Using Electromagnetic EmanationsabstractNIST has released a set of post-quantum cryptography (PQC) standards that address the threat posed by the emergence of quantum computing. The standard includes a modular lattice-based key exchange mechanism (ML-KEM) based on the CRYSTALS-Kyber algorithm. Recent work has shown that Kyber is susceptible to electromagnetic (EM) and power side-channel attacks. A full understanding of the side-channel vulnerabilities in Kyber is of paramount importance for next-generation communication and computing infrastructures.In this study, we target a previously unexplored section of the Kyber algorithm and implement a chosen ciphertext side-channel attack. We focus our attack on the Barrett reduction operation in the decapsulation algorithm. Compared to previous attacks on Barrett reduction, which targeted variables after the Inverse-Number Theoretic Transform (INTT), we focus on Barrett reduction on NTT variables, allowing for more general chosen ciphertexts that can evade input sanity checking. We design a scheme that requires only a set of 12 ciphertexts and side-channel EM traces of the corresponding decapsulation processes, which can reveal distinct leakages under different key values. The secret key is retrieved by pattern matching of the EM leakages. We develop an algorithm that utilizes an SMT solver to automatically select a set of ciphertexts. We implement Kyber on an ARM Cortex M4-based microcontroller and launch this new EM side-channel attack. Our results show that the attack achieves a success rate of over 95% in recovering the secret key value. Yashaswini Makaram, Davis Ranney, A. Adam Ding, David Kaeli, Yunsi Fei |
DATE | 3 |
| 2026 | Exploring Side-Channel Protections in Hardware Implementations of PQC ML-KEM Verification
Davis Ranney, Yashaswini Makaram, A. Adam Ding, Yunsi Fei |
DSN | 3 |
| 2025 | EXAM: Exploiting Exclusive System-Level Cache in Apple M-Series SoCs for Enhanced Cache Occupancy AttacksabstractCache occupancy attacks exploit the shared nature of cache hierarchies to infer a victim's activities by monitoring overall cache usage, unlike access-driven cache attacks that focus on specific cache lines or sets.There exists some prior work that target the last-level cache (LLC) of Intel processors, which is inclusive of higher-level caches, and L2 caches of ARM systems.In this paper, we target the System-Level Cache (SLC) of Apple M-series SoCs, which is exclusive to higher-level CPU caches.We address the challenges of the exclusiveness and propose a suite of SLC-cache occupancy attacks, the first of its kind, where an adversary can monitor GPU and other CPU cluster activities from their own CPU cluster.We first discover the structure of SLC in Apple M1 SOC and various policies pertaining to access and sharing through reverse engineering.We propose two attacks against websites.One is a coarse-grained fingerprinting attack, recognizing which website is accessed based on their different GPU memory access patterns monitored through the SLC occupancy channel.The other attack is a fine-grained pixel stealing attack, which precisely monitors the GPU memory usage for rendering different pixels, through the SLC occupancy channel.Third, we introduce a novel screen capturing attack which works beyond webpages, with the monitoring granularity of 57 rows of pixels (there are 1600 rows for the screen).This significantly expands the attack surface, allowing the adversary to retrieve any screen display, posing a substantial new threat to system security.Our findings reveal critical vulnerabilities in Apple's M-series SoCs and emphasize the urgent need for effective countermeasures against cache occupancy attacks in heterogeneous computing environments. Tianhong Xu, A. Adam Ding, Yunsi Fei |
AsiaCCS | 2 |
| 2025 | MoEcho: Exploiting Side-Channel Attacks to Compromise User Privacy in Mixture-of-Experts LLMsabstractThe transformer architecture has become a cornerstone of modern AI, fueling remarkable progress across applications in natural language processing, computer vision, and multi-modal learning.As these models continue to scale explosively for performance, implementation efficiency remains a critical challenge.Mixtureof-Experts (MoE) architectures, selectively activating specialized subnetworks (experts), offer a unique balance between model accuracy and computational cost.However, the adaptive routing in MoE architectures-where input tokens are dynamically directed to specialized experts based on their semantic meaning-inadvertently opens up a new attack surface for privacy breaches.These inputdependent activation patterns leave distinctive temporal and spatial traces in hardware execution, which adversaries could exploit to deduce sensitive user data.In this work, we propose MoEcho (MoE-Echo), discovering a side-channel analysis-based attack surface that compromises user privacy on MoE-based systems.Specifically, in MoEcho, we introduce four novel architectural side-channels on different computing platforms, including Cache Occupancy Channels and Pageout+Reload on CPUs, and Performance Counter and TLB Evict+Reload on GPUs, respectively.Exploiting these vulnerabilities, we propose four attacks that effectively breach user privacy in large-language models (LLMs) and vision-language models (VLMs) based on MoE architectures: Prompt Inference Attack, Response Reconstruction Attack, Visual Inference Attack, and Visual Reconstruction Attack.We evaluate MoEcho on four open-source MoE-based models at different scales, with a specific focus on the DeepSeek architecture.Our end-to-end experiments on both CPUand GPU-deployed MoE models demonstrate a 99.8% success rate in inferring the patient's private inputs in healthcare records and 92.8% in reconstructing LLM responses.MoEcho is the first run-time * These authors contributed equally. Ruyi Ding, Tianhong Xu, A. Adam Ding, Yunsi Fei |
CCS | 4 |
| 2025 | Graph in the Vault: Protecting Edge GNN Inference with Trusted Execution EnvironmentabstractWide deployment of machine learning models on edge devices has rendered the model intellectual property (IP) and data privacy vulnerable. We propose GNNVault, the first secure Graph Neural Network (GNN) deployment strategy based on Trusted Execution Environment (TEE). GNNVault follows the design of “partition-before-training” and includes a private GNN rectifier to complement with a public backbone model. This way, both critical GNN model parameters and the private graph used during inference are protected within secure TEE compartments. Real-world implementations with Intel SGX demonstrate that GNNVault safeguards GNN inference against state-of-the-art link stealing attacks with a negligible accuracy degradation ($\lt 2 \%$). Ruyi Ding, Tianhong Xu, A. Adam Ding, Yunsi Fei |
DAC | 3 |
| 2025 | Probe-Me-Not: Protecting Pre-trained Encoders from Malicious Probing
Ruyi Ding, Tong Zhou 0002, Lili Su, A. Adam Ding, Xiaolin Xu 0001, Yunsi Fei |
NDSS | 4 |
| 2024 | Non-transferable Pruning
Ruyi Ding, Lili Su, A. Adam Ding, Yunsi Fei |
ECCV (86) | 3 |
| 2024 | GraphCroc: Cross-Correlation Autoencoder for Graph Structural ReconstructionabstractGraph-structured data is integral to many applications, prompting the development of various graph representation methods. Graph autoencoders (GAEs), in particular, reconstruct graph structures from node embeddings. Current GAE models primarily utilize self-correlation to represent graph structures and focus on node-level tasks, often overlooking multi-graph scenarios. Our theoretical analysis indicates that self-correlation generally falls short in accurately representing specific graph features such as islands, symmetrical structures, and directional edges, particularly in smaller or multiple graph contexts.To address these limitations, we introduce a cross-correlation mechanism that significantly enhances the GAE representational capabilities. Additionally, we propose the GraphCroc, a new GAE that supports flexible encoder architectures tailored for various downstream tasks and ensures robust structural reconstruction, through a mirrored encoding-decoding process. This model also tackles the challenge of representation bias during optimization by implementing a loss-balancing strategy. Both theoretical analysis and numerical evaluations demonstrate that our methodology significantly outperforms existing self-correlation-based GAEs in graph structure reconstruction. Shijin Duan, Ruyi Ding, A. Adam Ding, Yunsi Fei, Xiaolin Xu 0001 |
NeurIPS | 4 |
| 2023 | EMShepherd: Detecting Adversarial Samples via Side-channel LeakageabstractDeep Neural Networks (DNN) are vulnerable to adversarial perturbations — small changes crafted deliberately on the input to mislead the model for wrong predictions. Adversarial attacks have disastrous consequences for deep learning empowered critical applications. Existing defense and detection techniques both require extensive knowledge of the model, testing inputs and even execution details. They are not viable for general deep learning implementations where the model internal is unknown, a common ‘black-box’ scenario for model users. Inspired by the fact that electromagnetic (EM) emanations of a model inference are dependent on both operations and data and may contain footprints of different input classes, we propose a framework, EMShepherd, to capture EM traces of model execution, perform processing on traces and exploit them for adversarial detection. Only benign samples and their EM traces are used to train the adversarial detector: a set of EM classifiers and class-specific unsupervised anomaly detectors. When the victim model system is under attack by an adversarial example, the model execution will be different from executions for the known classes, and the EM trace will be different. We demonstrate that our air-gapped EMShepherd can effectively detect different adversarial attacks on a commonly used FPGA deep learning accelerator for both Fashion MNIST and CIFAR-10 datasets. It achieves a detection rate on most types of adversarial samples, which is comparable to the state-of-the-art ‘white-box’ software-based detectors. Ruyi Ding, Cheng Gongye, Siyue Wang, A. Adam Ding, Yunsi Fei |
AsiaCCS | 4 |
| 2023 | Deep-Learning Model Extraction Through Software-Based Power Side-ChannelabstractDeep learning (DL) techniques have been increasingly applied across various applications, facing a growing number of security threats. One such threat is model extraction, an attack that steals the Intellectual Property of DL models, either by recovering the same functionality or retrieving high-fidelity models. Current model extraction methods can be categorized as learning-based or cryptanalytic, with the latter relying on model queries and computational methods to recover parameters. However, these are limited to shallow neural networks and are computationally prohibitive for deeper DL models. In this paper, we propose leveraging software-based power analysis, specifically the Intel Running Average Power Limit (RAPL) technique, for DL model extraction. RAPL allows us to measure power leakage of the most popular activation function, ReLU, through a software interface. Consequently, the ReLU branch direction can be leaked in the software power side-channel, a vulnerability common in many state-of-the-art DL frameworks. We introduce a novel methodology for model extraction Algorithm from input gradient assisted by side channel information. We implement our attack on the oneDNN framework, the most popular library on Intel processors. Compared to prior work, our model extraction, assisted by the software power side-channel, only requires 0.8% of the queries to retrieve as-layer MLP. We also successfully apply our method to a common Convolutional Neural Network (CNN) - Lenet-5. To the best of our knowledge, this is the first work that extracts CNN models with more than 5 layers based solely on queries and software. A. Adam Ding, Yunsi Fei |
ICCAD | 2 |
| 2023 | A Guessing Entropy-Based Framework for Deep Learning-Assisted Side-Channel AnalysisabstractRecently deep-learning (DL) techniques have been widely adopted in side-channel power analysis. A DL-assisted SCA generally consists of two phases: a deep neural network (DNN) training phase and a follow-on attack phase using the trained DNN. However, currently the two phases are not well aligned, as there is no conclusion on what metric used in the training can result in the most effective attack in the second phase. When traditional loss functions such as negative log-likelihood (NLL) are used in training a DNN, the trained model does not yield optimal follow-on attack. Recently some information theoretical SCA leakage metrics are proposed, either as the validation metric to stop the DNN training with traditional loss functions, or as both the validation metric and the training loss function. None of those proposed metrics, however, directly measures the SCA effectiveness. We propose to conduct DNN training directly with a common SCA effectiveness metric, Guessing Entropy (GE). We overcome the prior practical difficulty of using GE in DNN training by utilizing the GEEA estimation algorithm introduced in CHES 2020. We show that using GEEA as either the validation metric or the loss function produces DNN models that lead to much more effective follow-on attacks. Our work consolidates the DL-assisted SCA framework with a consistent metric, which shows great potential to be adopted as the universal SCA-oriented DNN training framework. A. Adam Ding, Yunsi Fei |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | Finding Dynamics Preserving Adversarial Winning TicketsabstractModern deep neural networks (DNNs) are vulnerable to adversarial attacks and adversarial training has been shown to be a promising method for improving the adversarial robustness of DNNs. Pruning methods have been considered in adversarial context to reduce model capacity and improve adversarial robustness simultaneously in training. Existing adversarial pruning methods generally mimic the classical pruning methods for natural training, which follow the ’training, pruning, fine-tuning’ three stages pipeline. We observe that such pruning methods do not necessarily preserve the dynamics of dense networks, making it potentially hard to be fine-tuned to compensate the accuracy degradation in pruning. Based on recent works of neural tangent kernel (NTK), we systematically study the dynamics of adversarial training and prove the existence of trainable sparse sub-network at initialization which can be trained to be adversarial robust from scratch. This theoretically verifies the lottery ticket hypothesis in adversarial context and we refer such sub-network structure as adversarial winning ticket (AWT). We also show empirical evidences that AWT preserves the dynamics of adversarial training and achieve equal performance as dense adversarial training. Xupeng Shi, A. Adam Ding, Yuan Gao 0015 |
AISTATS | 3 |
| 2022 | A Cross-Platform Cache Timing Attack Framework via Deep LearningabstractWhile deep learning methods have been adopted in power side-channel analysis, they have not been applied to cache timing attacks due to the limited dimension of cache timing data. This paper proposes a persistent cache monitor based on cache line flushing instructions, which runs concurrently to a victim execution and captures detailed memory access patterns in high-dimensional timing traces. We discover a new cache timing side-channel across both inclusive and non-inclusive caches, different from the traditional “Flush+Flush” timing leakage. We then propose a non-profiling differential deep learning analysis strategy to exploit the cache timing traces for key recovery. We further propose a framework for cross-platform cache timing attack via deep learning. Knowledge learned from profiling a common reference device can be transferred to build models to attack many other victim devices, even in different processor families. We take the OpenSSL AES-128 encryption algorithm as an example victim and deploy an asynchronous cache attack. We target three different devices from Intel, AMD, and ARM processors. We examine various scenarios for assigning the teacher role to one device and the student role to other devices, and evaluate the cross-platform deep-learning attack framework. Experimental results show that this new attack is easily extendable to victim devices and is more effective than attacks without any prior knowledge. Ruyi Ding, Cheng Gongye, Yunsi Fei, A. Adam Ding |
DATE | 6 |
| 2022 | Ran$Net: An Anti-Ransomware Methodology based on Cache Monitoring and Deep LearningabstractRansomware has become a serious threat in the cyberspace. Existing software pattern-based malware detectors are specific for certain ransomware and may not capture new variants. Recognizing a common essential behavior of ransomware - employing local cryptographic software for malicious encryption and therefore leaving footprints on the victim machine's caches, this work proposes an anti-ransomware methodology, Ran$Net, based on hardware activities. It consists of a passive cache monitor to log suspicious cache activities, and a follow-on non-profiled deep learning analysis strategy to retrieve the secret cryptographic key from the timing traces generated by the monitor. We implement the first of its kind tool to combat an open-source ransomware and successfully recover the secret key. Ruyi Ding, Cheng Gongye, A. Adam Ding, Yunsi Fei |
ACM Great Lakes Symposium on VLSI | 5 |
| 2022 | Masking Feedforward Neural Networks Against Power Analysis AttacksabstractAbstract Recent advances in machine learning have enabled Neural Network (NN) inference directly on constrained embedded devices. This local approach enhances the privacy of user data, as the inputs to the NN inference are not shared with third-party cloud providers over a communication network. At the same time, however, performing local NN inference on embedded devices opens up the possibility of Power Analysis attacks, which have recently been shown to be effective in recovering NN parameters, as well as their activations and structure. Knowledge of these NN characteristics constitutes a privacy threat, as it enables highly effective Membership Inference and Model Inversion attacks, which can recover information about the sensitive data that the NN model was trained on. In this paper we address the problem of securing sensitive NN inference parameters against Power Analysis attacks. Our approach employs masking, a countermeasure well-studied in the context of cryptographic algorithms. We design a set of gadgets, i.e., masked operations, tailored to NN inference. We prove our proposed gadgets secure against power attacks and show, both formally and experimentally, that they are composable, resulting in secure NN inference. We further propose optimizations that exploit intrinsic characteristics of NN inference to reduce the masking’s runtime and randomness requirements. We empirically evaluate the performance of our constructions, showing them to incur a slowdown by a factor of about 2–5. Konstantinos Athanasiou, Thomas Wahl, A. Adam Ding, Yunsi Fei |
Proc. Priv. Enhancing Technol. | 3 |
| 2019 | Comprehensive Side-Channel Power Analysis of XTS-AESabstractXTS-advanced encryption standard (AES) is an advanced mode of AES for data protection of sector-based devices. It features two secret keys instead of one, and an additional tweak for each data block. These characteristics make the mode not only resistant against cryptoanalysis attacks, but also more challenging for side-channel attack. In this paper, we comprehensively analyze the side-channel power leakage of various XTS-AES implementations and invent effective attacks. We first run a simple power analysis of a software implementation. For a hardware implementation on field-programmable gate array (FPGA), we analyze side-channel leakage of the particular modular multiplication in XTS-AES mode. In addition, we utilize the relationship between two consecutive block tweaks and propose a method to work around the masking of ciphertext by the tweak. These attacks are verified on an FPGA implementation of XTS-AES. The results show that XTS-AES is susceptible to side-channel power analysis attacks, and therefore dedicated protections are required for security of XTS-AES in storage devices. Yunsi Fei, A. Adam Ding, Pau Closas |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2019 | Efficient Nonprofiling 2nd-Order Power Analysis on Masked Devices Utilizing Multiple Leakage Pointsabstract2nd-order attacks utilize power values at two leakage points to break cryptographic systems protected by 1st-order random masking. Without profiling, the attacker do not know the exact location of the two leakage points. Standard 2nd-order attacks with an exhaustive search over two windows of size nw has computational complexity O(nw2) and does not scale well with the window size nw. We propose to apply a decision-combination attack, the majority vote (MV) attack, to combine 2nd order attacks at multiple candidate pairs of leakage points selected through two filters. The first filter pre-process the power traces with Fast Fourier Transformation (FFT) techniques and reduce the complexity to O(nwlog2(nw)). The second filter use an advanced statistical feature selection procedure, Higher Criticism (HC), to select leakage candidates that improve the effectiveness of decision-combination MV attack and other leakage-combination attacks. We derive theoretical success conditions of MV attacks as well as the typical maximum attack and a leakage-combination sum attack. The theoretical conditions are confirmed through performance comparisons of the attacks on synthetic data sets and on two real data sets, an FPGA implementation and a software implementation of masked AES. The proposed FF-HC-MV attack is data-adaptive, working well in all data sets. A. Adam Ding, Yunsi Fei, Pei Luo |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2018 | SCADET: a side-channel attack detection tool for tracking prime+probeabstractMicroarchitectural side-channel attacks have posed serious threats to many computing systems, ranging from embedded systems and mobile devices to desktop workstations and cloud servers. Such attacks exploit side-channel vulnerabilities stemming from fundamental microarchitectural performance features, including the most common caches, out-of-order execution (for the newly revealed Meltdown exploit), and speculative execution (for Spectre). Prior efforts have focused on identifying and assessing these security vulnerabilities, and designing and implementing countermeasures against them. However, the efforts aiming at detecting specific side-channel attacks tend to be narrowly focused, which can make them effective but also makes them obsolete very quickly. In this paper, we propose a new methodology for detecting microarchitectural side-channel attacks that has the potential for a wide scope of applicability, as we demonstrate using a case study involving the Prime+Probe attack family. Instead of looking at the side-effects of side-channel attacks on microarchitectural elements such as hardware performance counters, we target the high-level semantics and invariant patterns of these attacks. We have applied our method to different Prime+Probe attack variants on the instruction cache, data cache, and last-level cache, as well as several benign programs as benchmarks. The method can detect all of the Prime+Probe attack variants with a true positive rate of 100% and an average false positive rate of 7.4%. Majid Sabbagh, Yunsi Fei, Thomas Wahl, A. Adam Ding |
ICCAD | 4 |
| 2017 | Rate Optimal Estimation for High Dimensional Spatial Covariance MatricesabstractSpatial covariance matrix estimation is of great significance in many applications in climatology, econometrics and many other fields with complex data structures involving spatial dependencies. High dimensionality brings new challenges to this problem, and no theoretical optimal estimator has been proved for the spatial high-dimensional covariance matrix. Over the past decade, the method of regularization has been introduced to high-dimensional covariance estimation for various structured matrices, to achieve rate optimal estimators. In this paper, we aim to bridge the gap in these two research areas. We use a structure of block bandable covariance matrices to incorporate spatial dependence information, and study rate optimal estimation of this type of structured high dimensional covariance matrices. A double tapering estimator is proposed, and is shown to achieve the asymptotic minimax error bound. Numerical studies on both synthetic and real data are conducted showing the improvement of the double tapering estimator over the sample covariance matrix estimator. A. Adam Ding, Jennifer G. Dy |
ACML | 2 |
| 2017 | Towards Sound and Optimal Leakage Detection Procedure
A. Adam Ding, François Durvaux, François-Xavier Standaert, Yunsi Fei |
CARDIS | 1 |
| 2017 | Side-channel power analysis of XTS-AESabstractXTS-AES is an advanced mode of AES for data protection of sector-based devices. Compared to other AES modes, it features two secret keys instead of one, and an additional tweak for each data block. These characteristics make the mode not only resistant against cryptoanalysis attacks, but also more challenging for side-channel attack. In this paper, we propose two attack methods on XTS-AES overcoming these challenges. In the first attack, we analyze side-channel leakage of the particular modular multiplication in XTS-AES mode. In the second one, we utilize the relationship between two consecutive block tweaks and propose a method to work around the masking of ciphertext by the tweak. These attacks are verified on an FPGA implementation of XTS-AES. The results show that XTS-AES is susceptible to side-channel power analysis attacks, and therefore dedicated protections are required for security of XTS-AES in storage devices. Yunsi Fei, A. Adam Ding |
DATE | 3 |
| 2017 | Compiler-Assisted Threshold Implementation against Power Analysis AttacksabstractSide-channel attack utilizes side-channel leakages to extract the secret in crypto systems. Various countermeasures for different algorithms and platforms have been proposed to protect crypto systems against such attacks. Manual countermeasure design requires deep understanding of the target algorithm and implementation, and oftentimes is platform-specific and error-prone. In this paper, we propose the construction of Threshold Implementation (TI), a provably secure countermeasure against power attacks, as an automated compiler pass in the open LLVM (Low Level Virtual Machine) framework. Attack results show that the automatically generated TI designs are secure against power attacks. As our proposed scheme implements the countermeasure at the intermediate representation (IR) level, our method can be applied to any cipher software in any programming language, and the generated implementations can be ported to different platforms and architectures. Pei Luo, Konstantinos Athanasiou, Zhen Hang Jiang, Yunsi Fei, A. Adam Ding, Thomas Wahl |
ICCD | 6 |
| 2017 | A Robust-Equitable Measure for Feature Ranking and SelectionabstractIn many applications, not all the features used to represent data samples are important. Often only a few features are relevant for the prediction task. The choice of dependence measures often affect the final result of many feature selection methods. To select features that have complex nonlinear relationships with the response variable, the dependence measure should be equitable, a concept proposed by Reshef et al. (2011); that is, the dependence measure treats linear and nonlinear relationships equally. Recently, Kinney and Atwal (2014) gave a mathematical definition of self- equitability. In this paper, we introduce a new concept of robust-equitability and identify a robust- equitable copula dependence measure, the robust copula dependence (RCD) measure. RCD is based on the $L_1$-distance of the copula density from uniform and we show that it is equitable under both equitability definitions. We also prove theoretically that RCD is much easier to estimate than mutual information. Because of these theoretical properties, the RCD measure has the following advantages compared to existing dependence measures: it is robust to different relationship forms and robust to unequal sample sizes of different features. Experiments on both synthetic and real-world data sets confirm the theoretical analysis, and illustrate the advantage of using the dependence measure RCD for feature selection. A. Adam Ding, Jennifer G. Dy, Yale Chang |
J. Mach. Learn. Res. | 1 |
| 2016 | A Robust-Equitable Copula Dependence Measure for Feature SelectionabstractFeature selection aims to select relevant features to improve the performance of predictors. Many feature selection methods depend on the choice of dependence measures. To select features that have complex nonlinear relationships with the response variable, the dependence measure should be equitable: treating linear and nonlinear relationships equally. In this paper we introduce the concept of robust-equitability and a robust-equitable dependence measure copula correlation (Ccor). This measure has the following advantages compared to existing dependence measures: it is robust to different relationship forms and robust to unequal sample sizes of different features. In contrast, existing dependence measures cannot take these factors into account simultaneously. Experiments on synthetic and real-world datasets confirm our theoretical analysis, and illustrates its advantage in feature selection. Yale Chang, A. Adam Ding, Jennifer G. Dy |
AISTATS | 3 |
| 2016 | Differential Fault Analysis of SHA3-224 and SHA3-256abstractThe security of SHA-3 against different kinds of attacks are of vital importance for crypto systems with SHA-3 as the security engine. In this paper, we look into the differential fault analysis of SHA-3, and this is the first work to conquer SHA3-224 and SHA3-256 using differential fault analysis. Comparing with one existing related work, we relax the fault models and make them realistic for different implementation architectures. We analyze fault propagation in SHA-3 under such single-byte fault models, and propose to use fault signatures at the observed output for analysis and secret retrieval. Results show that the proposed method can effectively identify the injected single-byte faults, and then recover the whole internal state of the input of last round χ operation (χi22) for both SHA3-224 and SHA3-256. Pei Luo, Yunsi Fei, A. Adam Ding |
FDTC | 4 |
| 2016 | SMARP: A Stochastic MAC Protocol with Randomized Power Control for Underwater Sensor NetworksabstractDesigning efficient medium access control (MAC) protocols for underwater sensor networks (UWSNs) is still a challenging issue, due to the long propagation delay and spatial-temporal uncertainty of underwater acoustic channel. In this paper, we make use of the capture effect in channel access, and propose a stochastic MAC protocol with randomized power control for UWSNs, called SMARP. Capture effect means when multiple packets arrive at the receiver simultaneously, it is possible that some packets can be decoded if its power strength is higher enough than other packets. We design a power control scheme by considering the non-negligible difference in acoustic propagation attenuation, and proactively create power captures at the receiver side to improve the network throughput. Fairness is maintained by randomly selecting the transmission power among a set of power levels. A utility-optimization framework is used to determine the optimal transmission strategy, which takes into account both the single-packet success probability and capture success probability. Extensive simulation results demonstrate that SMARP achieves higher network throughput and lower packet end-to-end delay than other representative underwater MAC protocols. Yunsi Fei, A. Adam Ding |
SECON | 3 |
| 2015 | Towards secure cryptographic software implementation against side-channel power analysis attacksabstractSide-channel attacks have been a real threat against many embedded cryptographic systems. A commonly used algorithmic countermeasure, random masking, incurs large execution delay and resource overhead. The other countermeasure, operation shuffling or permutation, can mitigate side-channel leakage effectively with minimal overhead. In this paper, we target automatically implementing operation shuffling in cryptographic algorithms to resist against side-channel power analysis attacks. We design a tool to detect independence among statements at the source code level and devise an algorithm for automatic operation shuffling. We test our algorithm on the new SHA3 standard, Keccak. Results show that the tool effectively implements operation-shuffling to reduce the side-channel leakage significantly, and therefore can guide automatic secure cryptographic software implementations against differential power analysis attacks. Pei Luo, Yunsi Fei, A. Adam Ding |
ASAP | 4 |
| 2015 | A Unified Metric for Quantifying Information Leakage of Cryptographic Devices Under Power Analysis Attacks
A. Adam Ding, Yunsi Fei, Pei Luo |
ASIACRYPT (2) | 2 |
| 2014 | A Statistical Model for Higher Order DPA on Masked Devices
A. Adam Ding, Yunsi Fei, Pei Luo |
CHES | 1 |
| 2012 | A Statistical Model for DPA with Novel Algorithmic Confusion Analysis
Yunsi Fei, Qiasi Luo, A. Adam Ding |
CHES | 3 |
| 2003 | Backpropagation of pseudo-errors: neural networks that are adaptive to heterogeneous noiseabstractNeural networks are used for prediction model in many applications. The backpropagation algorithm used in most cases corresponds to a statistical nonlinear regression model assuming the constant noise level. Many proposed prediction intervals in the literature so far also assume the constant noise level. There are no prediction intervals in the literature that are accurate under varying noise level and skewed noises. We propose prediction intervals that can automatically adjust to varying noise levels by applying the regression transformation model of Carroll and Rupert (1988). The parameter estimation under the transformation model with power transformations is shown to be equivalent to the backpropagation of pseudo-errors. This new backpropagation algorithm preserves the ability of online training for neural networks. A. Adam Ding, Xiali He |
IEEE Trans. Neural Networks | 1 |
| 1999 | Neural-network prediction with noisy predictorsabstractVery often the input variables for neural-network predictions contain measurement errors. In particular, this may happen because the original input variables are often not available at the time of prediction and have to be replaced by predicted values themselves. This issue is usually ignored and results in nonoptimal predictions. This paper shows that under some general conditions, the optimal prediction using noisy input variables can be represented by a neural network with the same structure and the same weights as the optimal prediction using exact input variables. Only the activation functions have to be adjusted. Therefore we can achieve optimal prediction without costly retraining of the neural network. We explicitly provide an exact formula for adjusting the activation functions in a logistic network with Gaussian measurement errors in input variables. This approach is illustrated by an application to short-term load forecasting. A. Adam Ding |
IEEE Trans. Neural Networks | 1 |