EDBT 2026 Demo / reviewers in the wild / expert
Shuo Wang 0003
dblp:63/1591-3
· DBLP profile ↗
16ranked-venue papers
0as first author
14since 2021 · last 2026
0000-0002-1827-4355ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 11 · 9 since 2021Security and privacy · 3 · 3 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Computer networks · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Bridging Backscattering and On-chip EM Sensing for Golden-Model Free Hardware Trojan DetectionabstractHardware Trojans (HTs) embedded in integrated circuits often remain dormant and activate only under rare conditions, making run-time detection particularly challenging. The problem is more severe for stealthy designs whose small impedance perturbations produce weak electromagnetic signatures that elude conventional side-channel analysis. This work presents an on-chip EM backscattering framework for HT detection based on a Programmable Sensor Array (PSA). Instead of measuring switching-current emissions, the method captures impedance-modulated reflections from a continuous-wave excitation. The PSA is repurposed as a reconfigurable on-chip H-field receiver whose coil geometry can be dynamically tuned to improve magnetic coupling and spatial observability. We validate the approach on a fabricated TSMC 65 nm AES-128 test chip containing four digital Trojans and an analog A2 Trojan. The PSA achieves a 40–55 dB SNR improvement over external probes and enables reliable detection with fewer than five measured traces, including the A2 Trojan, which is difficult to observe using conventional EM side-channel analysis. Moyao Huang, Hanqiu Wang, Shuo Wang 0003, Domenic Forte |
ACM Great Lakes Symposium on VLSI | 3 |
| 2025 | Guided by Noise: Vulnerable Poisoning Attack to Differentially Private Federated Learning
Siqi Dai, Yaodan Hu, Honggang Yu, Hanqiu Wang, Shuo Wang 0003 |
ICC | 5 |
| 2025 | Electric Vehicle Onboard Charger EMI AnalysisabstractOnboard chargers play a crucial role in electric and plug-in hybrid vehicles. Operating in switching mode, these chargers generate significant electromagnetic interference (EMI), which can propagate to the power grid. As a result, compliance with relevant EMI standards is essential. Conventional onboard charger designs include single-stage and two-stage topologies. This paper develops EMI models for both configurations. For single-stage chargers, a dual active bridge (DAB) charger is analyzed. For two-stage chargers, two configurations are examined: one integrating a totem-pole power factor correction (PFC) converter with a DAB DC/DC converter, and another combining a totem-pole PFC converter with a CLC DC/DC converter. EMI models for these topologies will be developed. Their EMI will be evaluated through simulations and comparative analysis. Based on the findings, EMI mitigation strategies will be proposed. Qinghui Huang, Yirui Yang, Yanwen Lai, Shuo Wang 0003, Mohamed Elshaer |
IECON | 4 |
| 2025 | Flyback Converter EMI Modeling and Reduction SurveyabstractFlyback converters in products must adhere to strict regulatory standards for conducted and radiated electromagnetic interference (EMI). Managing EMI has become increasingly complex in modern power electronics, particularly with the integration of high-speed wide bandgap (WBG) devices into compact system layouts. This paper presents a review of established modeling techniques and mitigation strategies for conducted EMI, focusing on differential mode (DM) and common mode (CM) noise, alongside radiated EMI in flyback converters. The discussion encompasses solutions at both component-level design and converter system optimization. Juntao Yao, Shuo Wang 0003 |
IECON | 2 |
| 2024 | GAZEploit: Remote Keystroke Inference Attack by Gaze Estimation from Avatar Views in VR/MR DevicesabstractThe advent and growing popularity of Virtual Reality (VR) and Mixed Reality (MR) solutions have revolutionized the way we interact with digital platforms. The cutting-edge gaze-controlled typing methods, now prevalent in high-end models of these devices, e.g., Apple Vision Pro, have not only improved user experience but also mitigated traditional keystroke inference attacks that relied on hand gestures, head movements and acoustic side-channels. However, this advancement has paradoxically given birth to a new, potentially more insidious cyber threat, GAZEploit. Hanqiu Wang, Zihao Zhan, Haoqi Shan, Siqi Dai, Max Panoff, Shuo Wang 0003 |
CCS | 6 |
| 2024 | Programmable EM Sensor Array for Golden-Model Free Run-Time Trojan Detection and LocalizationabstractSide-channel analysis has been proven effective at detecting hardware Trojans in integrated circuits (ICs). However, most detection techniques rely on large external probes and antennas for data collection and require a long measurement time to detect Trojans. Such limitations make these techniques impractical for run-time deployment and ineffective in detecting small Trojans with subtle side-channel signatures. To overcome these challenges, we propose a Programmable Sensor Array (PSA) for run-time hardware Trojan detection, localization, and identification. PSA is a tampering-resilient integrated on-chip magnetic field sensor array that can be re-programmed to change the sensors' shape, size, and location. Using PSA, EM side-channel measurement results collected from sensors at different locations on an IC can be analyzed to localize and identify the Trojan. The PSA has better performance than conventional external magnetic probes and state-of-the-art on-chip single-coil magnetic field sensors. We fabricated an AES-128 test chip with four AES Hardware Trojans. They were successfully detected, located, and identified with the proposed on-chip PSA within 10 milliseconds using our proposed cross-domain analysis. Hanqiu Wang, Max Panoff, Zihao Zhan, Shuo Wang 0003, Christophe Bobda, Domenic Forte |
DATE | 4 |
| 2024 | Vector Based Transformer Winding Power Loss Calculation and Reduction for Arbitrary CurrentsabstractThis paper proposes a technical approach to calculate the AC power loss of transformer windings for the currents with arbitrary shapes and phase-shifts. AC winding power loss formulas are derived based on vector form, and they are important for analyzing the power loss due to skin and proximity effects. Based on the proposed approach, guidelines to optimize transformer winding structures were proposed and applied to a transformer in an active-clamp Flyback power converter. The auxiliary, CM EMI cancellation, and shielding windings commonly used in power products are all taken into consideration in the guidelines. Simulations and experiments were conducted to verify the developed theory and techniques. Zhedong Ma, Shuo Wang 0003, Yirui Yang |
IECON | 3 |
| 2024 | VoltSchemer: Use Voltage Noise to Manipulate Your Wireless Charger
Zihao Zhan, Yirui Yang, Haoqi Shan, Hanqiu Wang, Yier Jin, Shuo Wang 0003 |
USENIX Security Symposium | 6 |
| 2023 | Warm-Boot Attack on Modern DRAMsabstractMemory plays a critical role in storing almost all computation data for various applications, including those with sensitive data such as bank transactions and critical business management. As a result, protecting memory security from attackers with physical access is ultimately important. Various memory attacks have been proposed, among which “cold boot” and RowHammer are two leading examples. DRAM manufacturers have deployed a series of protection mechanisms to counter these attacks. Even with the latest protection techniques, DRAM may still be vulnerable to attackers with physical access. In this paper, we proposed a novel “warm boot” attack which utilizes external power supplies to bypass the existing protection mechanisms and steal the data from the modern SODIMM DDR4 memory. The proposed “warm boot” attack is applied to various DRAM chips from different brands. Based on our experiments, the “warm boot” attack can achieve as high as 94% data recovery rate from SODIMM DDR4 memory. Shuo Wang 0003, Renato J. O. Figueiredo, Yier Jin |
DATE | 2 |
| 2023 | HT-EMIS: A Deep Learning Tool for Hardware Trojan Detection and Identification through Runtime EM Side-ChannelsabstractHardware Trojans (HTs) are malicious circuits planted in Integrated Circuits (ICs). Multiple techniques using Side-Channel signals to detect HTs have been developed over the past decade. However, most of this research focuses on HT detection. Few of them explore the possibility of either identifying different Hardware Trojans implemented inside ICs or detecting inactive HTs. We propose a runtime EM side-channel analysis workflow (HT-EMIS) that uses a convolutional neural network to address the shortcomings above. By analyzing EM side-channel leakage from an FPGA, our tool can identify known types of HTs implemented inside a design and reports whether they are inactive or active with 100% accuracy. Additionally, we are able to successfully detect new unseen HTs with this model in 98.7% of test cases, due to the fact that HTs inserted at the Register Transfer Level with similar triggers and payloads often have similar effects on a floorplan, and thus the EM radiation of a device. Hanqiu Wang, Max Panoff, Shuo Wang 0003, Domenic Forte |
ACM Great Lakes Symposium on VLSI | 3 |
| 2023 | Improve the Noise Immunity of In-Band Communications in Qi Wireless Charging Systems with A Synchronous Rectifier Switching Scheme to Double the Depth of Shift-Keying ModulationabstractQi standard, widely used in consumer electronics wireless charging, requires an information exchange between the charger and the charged device. The Amplitude Shift Keying (ASK) technique employed for data transmission from the charged device to the charger is susceptible to disturbances due to load variations or noises. The conventional approach to addressing this issue involves introducing extra modulation circuits to dynamically adjust the modulation depth in response to interference conditions. This paper introduces an innovative control strategy for the synchronous rectifier in the charged device, which doubles the ASK modulation depth. With this technology, the ASK communication can achieve more flexibility in modulating depth, potentially leading to the removal of redundant modulation circuits, reduction of overall system costs, size, complexity, and enhancement of system reliability. Yirui Yang, Zhedong Ma, Qinghui Huang, Shuo Wang 0003, Zhenxue Xu, Liang Jia, Srikanth Lakshmikanthan |
IECON | 4 |
| 2023 | Fairness-Guaranteed DER Coordination Under False Data Injection AttacksabstractThe development of the Internet of Energy (IoE) is facilitated by the integration of information technology and the growing utilization of distributed energy resources (DERs). The usage of DERs, particularly photovoltaic systems and battery energy storage systems, in IoE has revealed the potential for DERs to be leveraged for grid control. To encourage DER owners to participate in grid management, grid operators must coordinate DERs with guaranteed fairness. However, the fairness of DER coordination is now endangered due to the growing concerns about cyber attacks on DERs. This paper considers false data injection attacks (FDIAs), where attackers can tamper with measurements sent to the grid operator. We study the impact of FDIAs on the fairness of the DER coordination and develop an algorithm that guarantees fairness in the presence of FDIAs. DER coordination is formulated as an optimal power flow problem that reduces voltage fluctuations and attack impacts, increases DER revenues, and ensures system-wide fairness. To achieve fair DER coordination, we propose an analog definition of fairness for different DER types and incorporate the fairness measures into DER coordination. Additionally, a robust Least Absolute Shrinkage and Selection Operator regularizer is designed to forecast the actual values of fraudulent measurements and mitigate the attack’s impacts. Using a distribution feeder from the Southern California Edison system, we demonstrate the effectiveness of the proposed approach: fairness is assured both with and without attacks. Additionally, the proposed algorithm’s efficiency is justified by an average execution time of 2.56s. Yaodan Hu, Xiaochen Xian, Yier Jin, Shuo Wang 0003 |
IEEE Internet Things J. | 4 |
| 2022 | RTSEC: Automated RTL Code Augmentation for Hardware Security EnhancementabstractCurrent hardware designs have increased in complexity, resulting in a reduced ability to perform security checks on them. Further, the addition of any security features to these designs is still largely manual which further complicates the design and integration process. In this paper, we address these shortcomings by introducing Rtsec as a framework which is capable of performing security analysis on designs as well as integrating security features directly into the HDL code, a feature that commercial EDA tools do not provide. Rtsec first breaks down HDL code into an Abstract Syntax Tree which is then used to infer the logic of the design. We demonstrate how Rtsec can be utilized to automatically include security mechanisms in RTL designs: watermarking and logic locking. We also compare the efficacy of our analysis algorithms with state of the art tools, demonstrating that Rtsec has capabilities equal or superior to those of state of the art tools while also providing the means of enhancing security features to the design. Orlando Arias, Zhaoxiang Liu, Xiaolong Guo 0001, Yier Jin, Shuo Wang 0003 |
DATE | 5 |
| 2022 | Invisible Finger: Practical Electromagnetic Interference Attack on Touchscreen-based Electronic DevicesabstractTouchscreen-based electronic devices such as smart phones and smart tablets are widely used in our daily life. While the security of electronic devices have been heavily investigated recently, the resilience of touchscreens against various attacks has yet to be thoroughly investigated. In this paper, for the first time, we show that touchscreen-based electronic devices are vulnerable to intentional electromagnetic interference (IEMI) attacks in a systematic way and how to conduct this attack in a practical way. Our contribution lies in not just demonstrating the attack, but also analyzing and quantifying the underlying mechanism allowing the novel IEMI attack on touchscreens in detail. We show how to calculate both the minimum amount of electric field and signal frequency required to induce touchscreen ghost touches. We further analyze our IEMI attack on real touchscreens with different magnitudes, frequencies, duration, and multitouch patterns. The mechanism of controlling the touchscreen-enabled electronic devices with IEMI signals is also elaborated. We design and evaluate an out-of-sight touchscreen locator and touch injection feedback mechanism to assist a practical IEMI attack. Our attack works directly on the touchscreen circuit regardless of the touchscreen scanning mechanism or operating system. Our attack can inject short-tap, long-press, and omnidirectional gestures on touchscreens from a distance larger than the average thickness of common tabletops. Compared with the state-of-the-art touchscreen attack, ours can accurately inject different types of touch events without the need for sensing signal synchronization, which makes our attack more robust and practical. In addition, rather than showing a simple proof-of-concept attack, we present and demonstrate the first ready-to-use IEMI based touchscreen attack vector with end-to-end attack scenarios Haoqi Shan, Zihao Zhan, Dean Sullivan, Shuo Wang 0003, Yier Jin |
SP | 5 |
| 2017 | Investigation of multiple feedback active filter configurations for differential mode(DM) electromagnetic interference(EMI) noise in AC/DC converter applicationsabstractIn this paper multiple feedback(FB) active filter configurations for DM EMI noise in the input side of AC/DC converters has been analyzed using developed models and then their performance was compared over single FB active filters using measurements. First, a single FB active filter circuit model is developed in the open loop and then based on DM EMI noise model of AC/DC converters, a closed loop model is developed. Then, based on the single FB model, closed loop models for series and parallel FB active filter topologies are developed. Single FB, series FB and parallel FB topologies have been implemented in hardware. Loop gains and insertion gains for the topologies are firstly derived and then measured using network analyzer. Comparing the topologies, it was found that series FB topology can give much higher attenuation. Finally, spectral domain measurements in the conducted EMI frequency range were done to verify the frequency domain performance of series FB topology. Rajib Goswami, Shuo Wang 0003 |
IECON | 2 |
| 2017 | Develop common-mode EMI noise models for AC-DC-AC traction systemsabstractEMI noise could bring electromechanical damages to the motors as well as reduce the stability of AC traction system. Since the high frequency noises propagate paths are quite complicated compared with fundamental frequency components, the high frequency EMI noise coupled through system's parasitic parameters is difficult to analyze and eliminated. In this paper, a common-mode equivalent circuit as well as its simplified circuit is proposed for multi-cell AC-DC-AC traction system. Parasitic components of the AC traction system are extracted and EMI noise is predicted based on the simulation of the proposed circuit. The resonance of the measured noise is analyzed with the common-mode equivalent circuit. Based on the understanding of the propagating mechanism of the common-mode noise, a small capacitance balance technique is proposed to reduce the EMI noise in AC-DC-AC traction system. Hui Zhao 0004, Shuo Wang 0003, Yongjian Zhi, Bingquan Zhu, Jianjun Min |
IECON | 3 |