EDBT 2026 Demo / reviewers in the wild / expert
Yanbin Li 0001
dblp:57/10187-1
· DBLP profile ↗
21ranked-venue papers
11as first author
17since 2021 · last 2026
0000-0001-7151-9270ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 4 first-author · 8 since 2021Systems, architecture and hardware · 6 · 4 first-author · 3 since 2021Computer networks · 5 · 3 first-author · 5 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Nonprofiled Incremental Learning-Based Side-Channel Attack on Lattice-Based KEMs: The Case Study of KyberabstractPost-quantum key-encapsulation mechanisms (KEMs) usually use the well-known Fujisaki-Okamoto (FO) transformation during key decapsulation to achieve chosen ciphertext attack (CCA) security. In the FO transformation, the re-encryption procedure depends on the message. The side-channel leakage of re-encryption can be exploited to recover the coefficients of the secret key under chosen ciphertexts, even if the KEM scheme is CCA secure. However, it still requires a large amount of trace during the profiling and attacking phase. In this work, we introduce the first non-profiled deep learning-based attack on lattice-based KEMs. We propose a chosen ciphertexts method that is suitable for non-profiled deep learning-based attacks. The horizontal chunking strategy is employed to partition the coefficients into chunks, enabling the independent recovery of multiple secret key coefficients within each chunk. Then, we adopt an incremental learning strategy to allow the deep learning model to gradually learn the knowledge of each chunk. Moreover, we push the limits of traditional non-profiled deep learning-based attacks by combining the unsupervised domain adaptation with the correlation distinguisher, eliminating the necessity of neural network training for each possible key guess. The feasibility of the attack is verified by practical experiments for the unprotected and masked implementations of Kyber on the ARM Cortex-M4. Yanbin Li 0001, Yikang Guo, Xinru Cong, Chunpeng Ge 0001, Zhen Qin 0002, Willy Susilo |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2026 | Side-Channel Leakage in Low-Entropy Masking Schemes Attributed to FPGA ArchitectureabstractMasking is one of the most popular to guarantee the security of the cryptographic implementation against side-channel analysis. Low Entropy Masking Scheme (LEMS) has been proposed to relieve the high overhead by reducing the entropy of the mask. The masks are selected carefully to resist univariate first-order attacks. However, in practice, securely implementing masking can be a challenging task. In this work, we exhibit the vulnerability of LEMS implementation on FPGA. Firstly, we provide the security model to characterize the masking balance at the implementation level. Based on the security model, we exhibit a first-order leakage in the netlist of the implementation. It can be proved that this defect is due to the uncontrollable EDA tool to optimize the AES Sbox implementation on the specific architecture of FPGA during synthesis. The discovered flaw can be exhibited by performing a couple of first-order attacks to recover the secret key successfully on FPGA. The vulnerability is verified by simulation and practical measurements. Finally, the potential countermeasure and security evaluation process for LEMS are provided to avoid leakage during the pre-silicon design phase. Yanbin Li 0001, Yikang Guo, Fan Zhang 0010 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2026 | LCAG: A Lightweight Consensus Algorithm Based on Graph for the Internet of ThingsabstractConsensus algorithms are the core technology of blockchain and a focus in the current distributed system research. The consensus algorithms are widely used in distributed systems, it has solved the decentralization problem. The traditional consensus algorithm needs the process of node legitimacy checking, identity authentication, and primary node view change, so the time cost of reaching an agreement between nodes is still exponential. In response to the problem, a lightweight consensus algorithm based on graph (LCAG) is proposed for the Internet of Things (IoT) in this paper, which is proposes an access control table, and reaches an agreement among nodes by calculating the probability of nodes in the control table, and reduces the time overhead of the reaching an agreement in distributed systems. We have carried out simulation experiments for the new algorithm, and the experiments show that: the new algorithm needs less time overhead than the classical Byzantine algorithm need, as well as Byzantine Generals problem (BGP), practical Byzantine fault-tolerant algorithm (PBFT) and directed acyclic graph (DAG) algorithm, and so on. The new algorithm can be applied to the devices of IoT, which have limited computing power. Fusheng Wu, Xiuzhang Yang, Yanbin Li 0001, Mingtao Ni, Guangyan Jiang |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | On Exploiting Single-Trace Side-Channel Leakage of SEAL-Embedded Library
Yanbin Li 0001, Yikang Guo, Tingyu Gu, Chunpeng Ge 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | New Permutation Decomposition Techniques for Efficient Homomorphic PermutationabstractHomomorphic permutation is fundamental to privacy-preserving computations based on batch-encoding homomorphic encryption. It underpins nearly all homomorphic matrix operations and predominantly influences their complexity. Permutation decomposition as a potential approach to optimize this critical component remains underexplored. In this paper, we propose novel decomposition techniques to optimize homomorphic permutations, advancing homomorphic encryption-based privacy-preserving computations. We start by defining an ideal decomposition form for permutations and propose an algorithm searching for depth-1 ideal decompositions. Based on this, we prove the full-depth ideal decomposability of permutations used in specific homomorphic matrix transposition (HMT) and multiplication (HMM) algorithms, allowing them to achieve asymptotic improvement in speed and rotation key reduction. As a demonstration of applicability, substituting the HMM components in the best-known inference framework of encrypted neural networks with our enhanced version shows up to a 3.9× reduction in latency. We further devise a new method for computing arbitrary homomorphic permutations, specifically those with weak structures that cannot be ideally decomposed. We design a network structure that deviates from the conventional scope of decomposition and outperforms the state-of-the-art technique under a limited rotation key budget, achieving a speed-up of up to 1.69 ×. Xirong Ma, Junling Fang, Chunpeng Ge 0001, Dung Hoang Duong, Yali Jiang 0004, Yanbin Li 0001, Willy Susilo, Li-Zhen Cui 0001 |
CCS | 6 |
| 2025 | Adaptive Chosen-Plaintext Deep-Learning-Based Side-Channel AnalysisabstractProfiled side-channel analysis presents a significant risk to embedded devices in Internet of Things (IoT). Typically, a single trace is insufficient to successfully key recovery in practical scenarios. It still requires several traces based on Bayes’ posterior probability. In this article, we introduce a chosen-plaintext (CP) strategy into the deep learning-based profiled attacks to improve the attack efficiency. First, we present a general strategy to profile the leakage model by exploiting the sensitivity analysis and clustering analysis. The leakage model derived from deep neural network is to characterize the leakage of the target algorithm. Second, we propose an adaptive CP method in the deep learning-based attack, transforming the conditional probability distribution of the leakage into the entropy of the key candidates under the profiled leakage model. Finally, we evaluate the efficiency of the attack by practical measurements. The results demonstrate that the proposed method requires fewer traces to retrieve the key of AES on devices of different types, e.g., Smartcard, FPGA, and ARM. Moreover, our attack improves the attack efficiency on masked implementations. Yanbin Li 0001, Yikang Guo, Chunpeng Ge 0001, Fanyu Kong 0002, Yongjun Ren |
IEEE Internet Things J. | 1 |
| 2025 | B2DFL: Bringing butterfly to decentralized federated learning assisted with blockchain
Hao Wang 0189, Yichen Cai 0002, Yu Tao 0004, Yanbin Li 0001, Lu Zhou 0002 |
J. Parallel Distributed Comput. | 5 |
| 2024 | LπCET: A Logic Security Analysis for Cryptographic Protocols Based on π-Calculus Extension TheoryabstractThe π ‐calculus is a basic theory of mobile communication based on the notion of interaction, which, is aimed at analyzing and modeling the behaviors of communication processes in communicating and mobile systems, and is widely applied to the security analysis of cryptographic protocol’s design and implementation. But the π ‐calculus does not provide seamless logical security analysis, so the logical flaws in the design and the implementation of a cryptographic protocol cannot be discovered in time. This paper introduces logical rules and logical proofs, binary tree, and the KMP algorithm and proposes a new extension of the π ‐calculus theory, a logical security analysis method, and an algorithm. The aim is to analyze whether there are logical flaws in the design and the implementation of a cryptographic protocol, to ensure the security of the cryptographic protocol when it is encoded into software and implemented. This paper presents the logical security proof and analysis of the TLS1.3 protocol’s interactional implementation process. Empirical results show that the additional extension theory, the logical security analysis method, and the algorithm can effectively analyze whether there are logical flaws in the design and the implementation of a cryptographic protocol. Fusheng Wu, Yanbin Li 0001, Mingtao Ni |
IET Inf. Secur. | 3 |
| 2024 | Secure outsourced decryption for FHE-based privacy-preserving cloud computing
Xirong Ma, Yuchang Hu, Yunting Tao, Yali Jiang 0004, Yanbin Li 0001, Fanyu Kong 0002, Chunpeng Ge 0001 |
J. Inf. Secur. Appl. | 6 |
| 2024 | SF-CABD: Secure Byzantine fault tolerance federated learning on Non-IID data
Xiaoci Lin, Yanbin Li 0001, Xuehui Wu, Chunpeng Ge 0001 |
Knowl. Based Syst. | 2 |
| 2024 | Deep Learning Gradient Visualization-Based Pre-Silicon Side-Channel Leakage LocationabstractWhile side-channel attacks (SCAs) have become a significant threat to cryptographic algorithms, masking is considered as an effective countermeasure against SCAs. On the one hand, securely implementing the scheme is a challenging and error-prone task. It is essential to detect leakage in a complicated cryptographic circuit. However, the traditional method of leakage detection is always inaccuracy or time consumption. On the other hand, the deep learning-based power attacks have shown their threat to the masking without combining functions. Compared to the leakage detection done under the traditional provable security framework, the security evaluation against deep learning-based attacks at the pre-silicon stage has not been discussed. To this end, this paper investigates the strategies of leveraging the deep learning techniques to achieve an efficient leakage location method. In this paper, we present the first approach utilizing deep learning-based leakage location for both unprotected and protected implementations at the pre-silicon stage. Firstly, we propose the leakage location method named Gradient Visualization-based location (GVL), which provides leakage location at the different levels of design. Gradient visualization is known as a sensitivity analysis method to understand better how a natural network can learn to predict the sensitive label based on the input. We theoretically show how the gradient visualization can be used to locate leakage components in the netlist efficiently. Moreover, we link the result with the metric in deep learning-based leakage assessment, which fills the lack of leakage evaluation at the pre-silicon stage against deep learning-based SCAs. We further confirm the effectiveness of the proposed method on unprotected implementation, low entropy masked implementation, and provable secure masked implementation. The results show that the proposed methodology outperforms the traditional location methods in the masked cases, where the time consumption is reduced by about 2x to 10x with fewer false negatives and no false positives. Yanbin Li 0001, Zhe Liu 0001, Ming Tang 0002, Shougang Ren |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | Recovering the Weights of Convolutional Neural Network via Chosen Pixel Horizontal Power Analysis
Weibin Wu 0003, Yanbin Li 0001, Lu Zhou 0002, Liming Fang 0001, Zhe Liu 0001 |
WASA (2) | 3 |
| 2022 | An Efficient Soft Analytical Side-Channel Attack on Ascon
Sinian Luo, Weibin Wu 0003, Yanbin Li 0001, Zhe Liu 0001 |
WASA (1) | 3 |
| 2022 | TSCL: A time-space crossing location for side-channel leakage detection
Yanbin Li 0001, Ming Tang 0002, Shougang Ren, Fusheng Wu |
Comput. Networks | 1 |
| 2021 | Adaptive Chosen Plaintext Side-Channel Attacks for Higher-Order Masking Schemes
Yanbin Li 0001, Ming Tang 0002, Shougang Ren, Huanliang Xu |
WASA (2) | 1 |
| 2021 | An Adaptive Communication-Efficient Federated Learning to Resist Gradient-Based Reconstruction AttacksabstractThe widely deployed devices in Internet of Things (IoT) have opened up a large amount of IoT data. Recently, federated learning emerges as a promising solution aiming to protect user privacy on IoT devices by training a globally shared model. However, the devices in the complex IoT environments pose great challenge to federate learning, which is vulnerable to gradient-based reconstruction attacks. In this paper, we discuss the relationships between the security of federated learning model and optimization technologies of decreasing communication overhead comprehensively. To promote the efficiency and security, we propose a defence strategy of federated learning which is suitable to resource-constrained IoT devices. The adaptive communication strategy is to adjust the frequency and parameter compression by analysing the training loss to ensure the security of the model. The experiments show the efficiency of our proposed method to decrease communication overhead, while preventing privacy data leakage. Yanbin Li 0001, Huanliang Xu, Shougang Ren |
Secur. Commun. Networks | 1 |
| 2021 | Analysis of Multiplicative Low Entropy Masking Schemes Against Correlation Power AttackabstractLow Entropy Masking Schemes (LEMS) had been proposed to mitigate the high-performance overhead results from the Full Entropy Masking Schemes (FEMS) while offering good protection against side-channel attacks. The masking schemes usually rely on Boolean masking, however, splitting sensitive variables in a multiplicative way is more amenable to non-linear functions and it had been applied to both software and hardware with a competitive alternative to state-of-the-art masked design. Compared to the comprehensive analysis done for Boolean LEMS, the specific leakage characteristics of Multiplicative LEMS have not yet been analyzed. In this paper, we introduce security models for LEMS to characterize the balance of the mask set. Based on the security model, we present an inherent weakness of Multiplicative LEMS. We prove that this defect of Multiplicative LEMS cannot be compensated by choosing a proper mask set, and the security of FEMS is guaranteed thanks to the Dirac function which is used to resist zero-value attack. Then, we exhibit the leakages in the implementation of Multiplicative LEMS. In particular, we propose a new attack against Multiplicative LEMS more efficient by utilizing the distribution of masked intermediate values. The feasibility of the attack is verified by both simulation and practical experiments. Yanbin Li 0001, Zhe Liu 0001, Sylvain Guilley, Ming Tang 0002 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | A pre-silicon logic level security verification flow for higher-order masking schemes against glitches on FPGAs
Yanbin Li 0001, Ming Tang 0002, Yuguang Li, Huanguo Zhang |
Integr. | 1 |
| 2019 | Practical Evaluation Methodology of Higher-Order Maskings at Different Operating Frequencies
Yuguang Li, Ming Tang 0002, Yanbin Li 0001, Shan Fu |
ICICS | 4 |
| 2018 | Several weaknesses of the implementation for the theoretically secure masking schemes under ISW framework
Yanbin Li 0001, Ming Tang 0002, Yuguang Li, Huanguo Zhang |
Integr. | 1 |
| 2018 | Leak Point Locating in Hardware Implementations of Higher-Order Masking SchemesabstractSecure masking schemes have been proven in theory to be secure countermeasures against side-channel attacks. The security framework proposed by Ishai, Sahai and Wagner, known as the Ishai-Sahai-Wagner scheme, is one of the most acceptable secure models of the existing dth-order masking schemes, where d represents the masking order and plays the role of a security parameter. However, a gap may exist between scheme and design. Several analyses have determined that the glitch has been regarded as the main challenge of masking in hardware designs. A practical method of locating the precise position of leakage points (LPs) in the original hardware design is very rare. Existing research on this glitch mainly focuses on the first-order leakages; however, higher-order analysis can combine several shares to recover the secret key. In this paper, we propose a practical method, sensitive glitch location (SGL) method to locate the less order leakage in hardware design. Specifically, the SGL method can locate any-order of LP in the hardware implementation of dth-order masking schemes. We conducted experiments and verified that the time complexity of SGL on the dth-order masking schemes is O(nm), where m is the number of signals and n is the number of shares in masking scheme. It can therefore be regarded as an efficient tool for the masking designs. In addition, we analyzed the dth-order masking scheme proposed by Rivain and Prouff (2010) along with the SecMult algorithm from the Rivain-Prouff countermeasure, which has been analyzed by our SGL. The experimental results verified that a higher-order leakage may exist in certain hardware designs, even the masking scheme has been proven as a secure countermeasure. To the best of our knowledge, SGL is the first tool that can be used to locate any-order of power/electromagnetic LP in hardware designs. It thus shows the weakness in the original design file of hardware implementations. This property can help designers directly improve the real security of the designs. Moreover, SGL returns the path of the leakages, which can elucidate the original cause and propagation of the weakness. Ming Tang 0002, Yanbin Li 0001, Dongyan Zhao 0002, Yuguang Li, Fei Yan 0008, Huanguo Zhang |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |