Liji Wu

dblp:60/10347 · DBLP profile ↗
← Back
16ranked-venue papers
0as first author
6since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 3 since 2021Security and privacy · 5 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 LP-VFedNN: A Lightweight and Lossless Privacy-Preserving Vertical Federated Learning Framework For Heterogeneous Neural Network Via Homomorphic Encryption and Intel SGX
abstract
Vertical federated learning (VFL) enhances model performance by jointly leveraging features from multiple parties. However, its intensive interactions increase the risk of privacy leakage. Existing privacy-preserving VFL solutions based on cryptographic primitives suffer from high computation and communication costs, limited algorithmic support, and poor scalability. We propose LP-VFedNN, a lightweight and lossless heterogeneous neural network framework for VFL that integrates CKKS fully homomorphic encryption (FHE) with a trusted execution environment (TEE) and requires no trusted third party. LP-VFedNN adopts a linear-nonlinear separation design: linear operations are executed in the CKKS ciphertext domain, while nonlinear functions are decrypted and accelerated inside the TEE. This avoids the high cost of high-order homomorphic computations and eliminates accuracy degradation caused by polynomial approximations, overcoming the limitations of generalized linear models (GLMs). We further introduce enhanced remote attestation and key agreement to support bidirectional authentication and secure key delivery. For multi-party settings, we propose an adaptive strategy that operates in an efficiency-oriented, restricted-leakage execution mode, improving scalability by offloading substantial TEE computation to secure plaintext computation after decryption. Experiments show that, compared to Paillier-based and pure-TEE schemes, LP-VFedNN significantly reduces communication and computation costs while maintaining accuracy, demonstrating robust scalability with controlled complexity growth as the number of parties increases. Additional experiments on a real-world multimedia dataset further validate its applicability for privacy-aware multimedia retrieval systems.
Liji Wu, Baisong Li, Huiping Zhuang, Weiping Wang 0007, Yaoyi Deng, Hailong Zhang 0001
ICMR2
2025 Grafted Trees Bear Better Fruit: An Improved Multiple-Valued Plaintext-Checking Side-Channel Attack Against Kyber
abstract
As a prominent category of side-channel attacks (SCAs), plaintext-checking (PC) oracle-based SCAs offer the advantages of generality and operational simplicity on a targeted device. At TCHES 2023, Rajendran et al. and Tanaka et al. independently proposed the multiple-valued (MV) PC oracle, significantly reducing the required number of queries (a.k.a., traces) in the PC oracle. However, in practice, when dealing with environmental noise or inaccuracies in the waveform classifier, they still rely on majority voting or the other technique that usually results in three times the number of queries compared to the ideal case. In this paper, we propose an improved method to further reduce the number of queries of the MV-PC oracle, particularly in scenarios where the oracle is imperfect. Compared to the state-of-the-art at TCHES 2023, our proposed method reduces the number of queries for a full key recovery by more than 42.5%. The method involves three rounds. Our key observation is that coefficients recovered in the first round can be regarded as prior information to significantly aid in retrieving coefficients in the second round. This improvement is achieved through a newly designed grafted tree. Notably, the proposed method is generic and can be applied to both the NIST key encapsulation mechanism (KEM) standard Kyber and other significant candidates, such as Saber and Frodo. We have conducted extensive software simulations against Kyber-512, Kyber-768, Kyber-1024, FireSaber, and Frodo-1344 to validate the efficiency of the proposed method. An electromagnetic attack conducted on real-world implementations, using an STM32F407G board equipped with an ARM Cortex-M4 microcontroller and Kyber implementation from the public library pqm4, aligns well with our simulations.
Jinnuo Li, Muyan Shen, Qian Guo 0001, Liji Wu, Jian Weng 0001
DATE7
2025 PEAR: privacy-preserving and effective aggregation for byzantine-robust federated learning in real-world scenarios
abstract
Abstract Federated learning (FL) enables collaborative training of global models among distributed clients without sharing local data. Secure aggregation, a new security primitive of FL, enhances the confidentiality of data and model parameters. Unfortunately, privacy-preserving (PP) FL is vulnerable to common poisoning attacks by Byzantine adversaries. Existing defense strategies mainly focus on identifying abnormal local gradients over plaintexts, which provides a weak privacy guarantee. In PPFL, adversaries can escape existing defenses by uploading encrypted poisonous gradients. In addition, most mainstream aggregation algorithms assume that clients’ local training data is uniformly distributed, Independent and Identically Distributed (IID), which is unrealistic for real-world FL scenarios where data are only stored on large-scale terminal devices. To address these issues, we propose PEAR, a PP aggregation strategy based on single key-dual server CKKS full homomorphic encryption in real-world distributed scenarios, which can resist encrypted poisoning attacks. Specifically, we use cosine similarity to measure the distance between encrypted gradients. Then, we propose a novel Byzantine-tolerance aggregation mechanism using cosine similarity, which includes trust score generation that can tolerate differentiated local gradients and a two-step weight generation method that considers both the degree of gradient deviation in direction and training data size. This mechanism can achieve robustness for both IID and non-IID data without compromising privacy. Our extensive evaluations for two typical poisoning attacks on different datasets show that PEAR is robust and effective in IID and non-IID data and outperforms existing mainstream Byzantine-robust algorithms, especially achieving 16.4% to 53.2% testing error rate reduction in non-IID settings with significant label distribution and quantity skew while maintaining the same efficiency as FedAvg.
Yan Zhang 0014, Huiping Zhuang, Zhen Xu 0009, Liji Wu
Comput. J.6
2025 Catch the Star: Weight Recovery Attack Using Side-Channel Star Map Against DNN Accelerator
abstract
The rapid development of Artificial Intelligence (AI) technology must be connected to the arithmetic support of high-performance hardware. However, when the deep neural network (DNN) accelerator performs inference tasks at the edge end, the sensitive data of DNN will generate leakage through side-channel information. The adversary can recover the model structure and weight parameters of DNN by using the side-channel information, which seriously affects the protection of necessary intellectual property (IP) of DNN, so the hardware security of the DNN accelerator is critical. In the current research of Side-channel attack (SCA) for matrix multiplication units, such as systolic arrays, the linear multiplication operation leads to a more extensive weights search space for the SCA, and extracting all the weight parameters requires higher attack conditions. This article proposes a new power SCA method, which includes a Collision-Correlation Power Analysis (Collision-CPA) and Correlation-based Weight Search Algorithm (C-WSA) to address the problem. The Collision-CPA reduces the attack conditions for the SCA by building multiple Hamming Distance (HD)-based power leakage models for the systolic array. Meanwhile, the C-WSA dramatically reduces the weights search space. In addition, the concept of a Side-channel star map (SCSM) is proposed for the first time in this article, and the adversary can quickly and accurately locate the correct weight information in the SCSM. Through experiments, we recover all the weight parameters of a$3\times 3$systolic array based on 100000 power traces, in which the weight search space is reduced by up to 97.7%. For the DNN accelerator at the edge, especially the systolic array structure, our proposed novel SCA aligns more with practical attack scenarios, with lower attack conditions, and higher attack efficiency.
Le Wu 0002, Liji Wu, Xiangmin Zhang
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.2
2024 Dual-Rail Precharge Logic-Based Side-Channel Countermeasure for DNN Systolic Array
abstract
Deep neural network (DNN) accelerators are widely used in cloud-edge-end and other application scenarios. Researchers recently focused on extracting secret information from DNN through side-channel attacks (SCAs), which substantially threaten AI security. In this brief, we propose a high-security, high-performance side-channel countermeasure using dual-rail precharge logic (DPL) for the DNN systolic array. By collecting and analyzing 5000 power traces, our proposed DPL-based systolic array provides a significantly lower correlation coefficient of 0.045. Through system-level side-channel security evaluation on field-programmable gate arrays (FPGAs), the DPL-based systolic array can effectively defend against weight extraction under power SCAs.
Le Wu 0002, Liji Wu, Xiangmin Zhang, Munkhbaatar Chinbat
IEEE Trans. Very Large Scale Integr. Syst.2
2021 Gini-Impurity Index Analysis
abstract
In the past few decades, DPA-based side-channel attack strategies, such as DPA and CPA, have shown strong ability to analyze the security of the cryptographic implementations. However, the unpredictability of the leakage model and the correspondence between leakage behavior of the target device and the hypothetical leakage value make it less-effective without prior knowledge. Therefore, in this paper, we present a novel generic side-channel analysis method called Gini-impurity Index Analysis (GIA), utilizing Gini-impurity Index as the distinguisher, which can perform well even without any leakage model and is not sensitive to the existing methods' restrictions about the leakage behavior. Firstly, we introduce the basic idea of GIA. According to the proposed GIA attack strategy, the Gini-impurity index for each key hypothesis should be calculated, determined by the clustered power consumption and the classified subsets based on the key dependent target function. Secondly, we verify the feasibility and evaluate the efficiency of GIA with different target functions by the practical experimental results against AES-128 implemented on an AT89S52 microcontroller. We present one possible multivariate extension of GIA and find the advantage of GIA on leakage information utilization. Thirdly, we present the results of comparisons. On the one hand, we compare GIA with three widely-used distinguishers under simulated traces in various leakage scenarios and practical traces with Hamming-weight-related leakage. Results confirm that GIA can always perform well with different leakage models in most situations. On the other hand, we analyze the relationship between GIA and Mutual Information Analysis (MIA). Theoretical and experimental results confirm that these two methods can obtain similar attack results. However, the guessing entropy of GIA is lower than MIA by up to 21%, and the averaged computational time overhead of GIA is lower than MIA by up to 13.3%, indicating that GIA is more efficient than MIA. Compared to traditional MIA, GIA is easier to operate and more flexible with noise. Therefore, GIA is an efficient and useful alternative to these existed strategies.
Ye Yuan 0003, Liji Wu, Xiangmin Zhang
IEEE Trans. Inf. Forensics Secur.2
2019 Correlation power attack on a message authentication code based on SM3
abstract
Hash-based message authentication code (HMAC) is widely used in authentication and message integrity. As a Chinese hash algorithm, the SM3 algorithm is gradually winning domestic market value in China. The side channel security of HMAC based on SM3 (HMAC-SM3) is still to be evaluated, especially in hardware implementation, where only intermediate values stored in registers have apparent Hamming distance leakage. In addition, the algorithm structure of SM3 determines the difficulty in HMAC-SM3 side channel analysis. In this paper, a skillful bit-wise chosen-plaintext correlation power attack procedure is proposed for HMAC-SM3 hardware implementation. Real attack experiments on a field programmable gate array (FPGA) board have been performed. Experimental results show that we can recover the key from the hypothesis space of 2 256 based on the proposed procedure.
Ye Yuan 0003, Kaige Qu, Liji Wu, Jia-Wei Ma, Xiangmin Zhang
Frontiers Inf. Technol. Electron. Eng.3
2019 Erratum to "A Novel Multiple-Bits Collision Attack Based on Double Detection with Error-Tolerant Mechanism"
Ye Yuan 0003, Liji Wu, Xiangmin Zhang
Secur. Commun. Networks2
2018 A Novel Multiple-Bits Collision Attack Based on Double Detection with Error-Tolerant Mechanism
abstract
Side-channel collision attacks are more powerful than traditional side-channel attack without knowing the leakage model or establishing the model. Most attack strategies proposed previously need quantities of power traces with high computational complexity and are sensitive to mistakes, which restricts the attack efficiency seriously. In this paper, we propose a multiple-bits side-channel collision attack based on double distance voting detection (DDVD) and also an improved version, involving the error-tolerant mechanism, which can find all 120 relations among 16 key bytes when applied to AES (Advanced Encryption Standard) algorithm. In addition, we compare our collision detection method called DDVD with the Euclidean distance and the correlation-enhanced collision method under different intensity of noise, which indicates that our detection technique performs better in the circumstances of noise. Furthermore, 4-bit model of our collision detection method is proven to be optimal in theory and in practice. Meanwhile the corresponding practical attack experiments are also performed on a hardware implementation of AES-128 on FPGA board successfully. Results show that our strategy needs less computation time but more traces than LDPC method and the online time for our strategy is about 90% less than CECA and 96% less than BCA with 90% success rate.
Ye Yuan 0003, Liji Wu, Xiangmin Zhang
Secur. Commun. Networks2
2017 A 50Gb/s repeater and 2 × 50Gb/s 27-1 PRBS generator
abstract
For pursuing the high speed information transmission, the design and research of the high speed SerDes circuit are actively developing now. Due to the requirements for long transmission path, intensive equalization and high speed transmission circuit testing function, two high speed SerDes circuits are designed and fabricated based on 130nm SiGe BiCMOS technology. One is for the research of the equalization techniques in ultra-high data rate so an ultra-high speed repeater is designed, and it can work at up to 50Gb/s and compensate for more than 50dB channel loss, with a power consumption of 676.5mW at 3.3V. The other is a low power pseudo-random binary sequence generator chip which can output 2×50Gb/s data, and the power consumption is 270mW at 1.8V.
Dengrong Li, Liji Wu, Shuai Yuan 0005, Xiangmin Zhang
ISCAS2
2016 A High Precision Multi-Cell Battery Voltage Detecting Circuit for Battery Management Systems
abstract
This paper presents a high precision direct multi-cell Battery Voltage Detecting Circuit (BVDC) for Battery Management Systems (BMS) in electric vehicles. BVDC in BMS must be able to accommodate direct voltage input up to tens of volts from series connected batteries, fulfil the precision needs by battery state of charge estimation algorithm. The BVDC circuit is designed with a 0.5μm 1-poly 3-metal high voltage (HV) 60V Bipolar-CMOS-DMOS (BCD) semiconductor process. System optimization design of HV multiplexer and incremental sigma-delta analog-to-digital converter (ADC) in BVDC circuit eliminates the need of amplifier-resistor based level shift, and any static current through HV signal path, which greatly improved the conversion accuracy. Post layout extracted simulation result shows that the typical conversion error is less than 0.3mV@1MHz for series connected batteries without extra calibration.
Xue-Cheng Man, Liji Wu, Xiangmin Zhang, Tai-Kun Ma, Wen Jia
VTC Spring2
2015 Transient-Steady Effect Attack on Block Ciphers
Yanting Ren, An Wang 0001, Liji Wu
CHES3
2015 Efficient collision attacks on smart card implementations of masked AES
An Wang 0001, Zongyue Wang, Xuexin Zheng, Guoshuang Zhang, Liji Wu
Sci. China Inf. Sci.7
2015 A novel bit scalable leakage model based on genetic algorithm
abstract
Abstract With the growing popularity of smart integrated circuit (IC) cards, the chip security is attracting more and more attention. Researches on the attack and protection of smart IC cards have become increasingly hot. Side‐channel attack is the practical and effective method, which has brought enormous threat. The efficiency of attack depends on the extent of the leakage model, which characterizes the practical applications. In the power analysis attack, the classical leakage model usually exploits the power consumption of single S‐box, which is called divide and conquer. Taking data encryption standard (DES) algorithm, for example, the attack on each S‐box needs to search the key space of 2 6 in a brute‐force way. In this paper, we propose a novel leakage model, which is more flexible than the classical leakage model. The novel leakage model is based on the power consumption of multiple S‐boxes, and the implementation of this method is combined with genetic algorithm. We can establish leakage model based on the Hamming distance of round output generated by eight S‐boxes in DES algorithm. The experiment verifies the fact that the leakage model of eight S‐boxes can decrease the traces number up to 52% than the classical one based on single S‐box for DES algorithm. It also decreases the traces number up to 32% for SM4 algorithm. All the measurements of power data are acquired from a practical smart IC card. We also conclude that increasing noise, using variable clock, and limiting the lifetime of root key can be the choices of defensive strategy. Copyright © 2015 John Wiley & Sons, Ltd.
Zhenbin Zhang, Liji Wu, An Wang 0001, Zhaoli Mu, Xiangmin Zhang
Secur. Commun. Networks2
2014 Scalable behavior modeling for SCR based ESD protection structures for circuit simulation
abstract
This paper reports a new scalable behavioral modeling technique for silicon controlled rectifier (SCR) based electrostatic discharge (ESD) protection structures using Verilog-A language. Accurate models were developed for various low-triggering voltage SCR ESD (LVSCR) protection structures implemented in a foundry 180nm RF process, which were validated by circuit simulation and ESD measurement.
Li Wang 0058, Rui Ma 0003, Chen Zhang 0017, Zongyu Dong, Fei Lu 0004, Albert Wang 0001, Xin Wang 0031, Jian Liu 0027, Siqiang Fan, He Tang 0003, Baoyong Chi, Liji Wu
ISCAS12
2013 A 10 Gbps in-line network security processor based on configurable hetero-multi-cores
abstract
This paper deals with an in-line network security processor (NSP) design that implements the Internet Protocol Security (IPSec) protocol processing for the 10 Gbps Ethernet. The 10 Gbps high speed data transfer, the IPSec processing including the crypto-operation, the database query, and IPSec header processing are integrated in the design. The in-line NSP is implemented using 65 nm CMOS technology and the layout area is 2.5 mm×3 mm with 360 million gates. A configurable crossbar data transfer skeleton implementing an iSLIP scheduling algorithm is proposed, which enables simultaneous data transfer between the heterogeneous multiple cores. There are, in addition, a high speed input/output data buffering mechanism and design of high performance hardware structures for modules, wherein the transfer efficiency and the resource utilization are maximized and the IPSec protocol processing achieves 10 Gbps line speed. A high speed and low power hardware look-up method is proposed, which effectively reduces the area and power dissipation. The post simulation results demonstrate that the design gives a peak throughput for the Authentication Header (AH) transport mode of 10.06 Gbps with the average test packet length of 512 bytes under the clock rate of 250 MHz, and power dissipation less than 1 W is obtained. An FPGA prototype is constructed to verify the function of the design. A test bench is being set up for performance and function verification.
Yun Niu, Liji Wu, Xiangmin Zhang, Hong Yi Chen
J. Zhejiang Univ. Sci. C2