EDBT 2026 Demo / reviewers in the wild / expert
Jingbo Zhou 0002
dblp:82/8538-2
· DBLP profile ↗
11ranked-venue papers
3as first author
11since 2021 · last 2026
0000-0002-6321-6293ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 9 · 2 first-author · 9 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CHSM-Guard: Secure Boot and In-Field Firmware Updates for Chiplet-Based SiPs
Galib Ibne Haidar, Jingbo Zhou 0002, Mark Tehranipoor, Farimah Farahmandi |
ACM Great Lakes Symposium on VLSI | 2 |
| 2026 | Redefining Tradition: An Active Watermarking Approach for IP Protection in SoCsabstractGlobalization of the System-on-Chip (SoC) supply chain has resulted in increased intellectual property (IP) piracy, illegal reuse, and tampering by malicious actors. In response to these challenges, IP watermarking presents itself as a promising solution to protect against these risks; however, traditional methods rely heavily on labor-intensive manual tests by verification engineers and fail to account for the potential threat posed by malicious SoC design houses. To overcome these challenges and improve the efficiency of the watermark verification process while safeguarding against possible attacks, we developedActiWateas an innovative watermarking approach that not only provides proof of authorship but also prevents unauthorized usage of an IP. Using an automatic self-verification technique, the watermark establishes communication with various peripherals within the SoC. The versatility and effectiveness ofActiWatehave been proven through extensive experiments on multiple SoCs with diverse components and peripherals, including the testing of watermarking and the verification of various IPs. Moreover, we discuss the inclusion of this multiple serialized verification in more case studies and results, as well as analyzing prominent security threats, including reverse engineering attacks. Zahin Ibnat, Mridha Md Mashahedur Rahman, M. Sazadur Rahman, Jingbo Zhou 0002, Farimah Farahmandi |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2025 | NoXLock: SiP Activation and Licensing through Obfuscated on-Chip Network and Fuzzy TrafficabstractCountermeasures designed to protect system-on-chip (SoC) from intellectual property (IP) counterfeiting are inadequate for heterogeneously integrated systems-in-packages (SiP) due to shifts in manufacturing flow. Additionally, traditional obfuscation methods are now compromised by emerging deobfuscation techniques. This paper introduces network-on-chip (NoC) obfuscation, NoXLock, to effectively safeguard the IP of SiP designs. By obfuscating the routing algorithm, the performance of unauthorized SiPs, including throughput and packet loss, is effectively constrained. To securely activate the system, a novel method utilizing dynamic traffic patterns is proposed. Extensive security analyses and experimental results in this paper demonstrate that NoXLock resists state-of-the-art attacks, including oracle-guided SAT, oracle-less removal, and probing-based methods, without imposing a significant penalty on power, performance, and area (PPA) overheads. Md. Saad Ul Haque, Azim Uddin, Jingbo Zhou 0002, Hadi Mardani Kamali, Farimah Farahmandi, Mark Tehranipoor |
ASP-DAC | 3 |
| 2025 | Physical Design-Aware Power Side-Channel Leakage Assessment Framework using Deep LearningabstractPower side-channel (PSC) vulnerabilities present formidable challenges to the security of ubiquitous microelectronic devices in mission-critical infrastructure. Existing side-channel assessment techniques mostly focus on post-silicon stages by analyzing power profiles of fabricated devices, suffering from low flexibility and prohibitively high cost while deploying security countermeasures. While pre-silicon PSC assessments offer flexibility and low cost, the true nature of the power signatures cannot be fully captured through RTL or gate-level design. Although physical design-level analysis provides precise power traces, collecting data is time and resource-consuming at the layout level. To address this challenge, we propose, for the first time, a fast and efficient physical design-level PSC assessment framework using a graph neural network (GNN). This framework predicts dynamic power traces for new layouts, using them to assess physical design security through metrics evaluation. Our experiments on AES-GF layout implementations achieve a tremendous 133× speedup compared to conventional simulation-based flow without sacrificing substantial accuracy. Dipayan Saha, Jingbo Zhou 0002, Farimah Farahmandi |
ISCAS | 2 |
| 2025 | GEM-Water: Generation of EM-Based Watermark With Hidden FSM for SoC IPs to Combat PiracyabstractLeveraging the intellectual property (IP) core is a widely adopted strategy to expedite the development of new products within modern System-on-Chip (SoC) architectures. In today’s competitive market, reusing and sharing IP cores can significantly shorten the time-to-market for SoC designs. However, this practice also introduces security problems, such as IP piracy and overuse. Watermarking is one of the most popular methods to combat IP counterfeiting. Nevertheless, the current state-of-the-art watermarking approaches often overlook the threat posed by rogue SoC design houses and frequently require physical access to the target IP in the SoC for watermark authentication. To address these issues, this paper proposes GEM-Water, an effective IP/SoC-agnostic watermark verification mechanism that utilizes the electromagnetic (EM) radiation emitted by an IP within a packaged SoC to verify the watermark during SoC boot-up. Based on secret authorship information, the functional Finite State Machine (FSM) of the target IP is modified and subsequently translated into an EM signature. This signature can later be extracted using a near-field EM probe during SoC boot-up. With the assistance of such EM side-channel analysis, GEM-Water can authenticate the watermark without the need for physical access to the target IP itself. To validate the robustness and viability of GEM-Water, experiments were conducted on various AMD Xilinx 7 series and Microsemi FPGAs, demonstrating watermark detection accuracy consistently exceeding 95% across different benchmarks. Pantha Protim Sarker, Upoma Das, Mohammad Bin Monjil, Jingbo Zhou 0002, Farimah Farahmandi, Mark Tehranipoor |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2024 | SAP: Silicon Authentication Platform for System-on-Chip Supply Chain VulnerabilitiesabstractThe increasing complexity of system-on-chip (SoC) designs, prompted by the integration of additional functionalities, has led to a reliance on global sources in the SoC supply chain. This reliance introduces security concerns, including intellectual property (IP) theft, unauthorized usage, counterfeiting, and overproduction of integrated circuits (ICs). While various design-for-trust measures have been explored in academic research, such as watermarking, IC metering, IC camouflaging, and hardware obfuscation, there is currently no holistic approach within the SoC framework to support these measures. Secure provisioning of security assets within the chip is also critical for these measures, requiring the establishment of secure communication channels and the authentication of the chip by authorized entities. Existing root-of-trust mechanisms primarily target software-level threats during in-field operations but fall short of adequately addressing supply chain threats and ensuring secure asset provisioning. This paper introduces the Silicon Authentication Platform (SAP) security IP, specifically designed to address security vulnerabilities within the SoC supply chain. SAP is tailored to authenticate SoC dies within untrusted environments, ensuring secure provisioning of security assets and chip authentication during in-field operations. This hardware-based, plug-and-play IP facilitates lightweight integration into SoC designs, establishing a secure perimeter around its assets to protect them from potential leakage. In addition, a comprehensive security analysis showcasing SAP's resilience against contemporary attack scenarios, with minimal impact on performance and area overhead, is also provided in this paper. Md Sami Ul Islam Sami, Jingbo Zhou 0002, Sujan Kumar Saha, Fahim Rahman, Farimah Farahmandi, Mark Tehranipoor |
ISPASS | 2 |
| 2024 | SECT-HI: Enabling Secure Testing for Heterogeneous Integration to Prevent SiP CounterfeitsabstractDue to Moore’s law limitations, SiP became popular in recent years among industries to increase functionality density, by integrating multiple chiplets on a shared interposer substrate. To reduce the time-to-market, SiP designers need to outsource their SiPs to untrusted testing facilities, relinquishing control during testing. However, it leads to over-production and counterfeit threats. In this paper, we propose a novel framework SECT-HI aimed at establishing a secure testing environment for SiPs by granting control of the test procedure to the SiP designers. To mitigate the risks of overproduction and distribution of out-of-spec, faulty SiPs, the SiP’s functionality remains locked until the SiP designer provides the correct key. Additionally, the scan chain responses are also encrypted to prevent unauthorized access from test facilities creating a golden response database. Further, a watermark is added to deter counterfeits. Extensive simulation results demonstrate that the SECT-HI framework introduces an area and timing overhead of only 1.1-3.4% and 280ms respectively while adhering to the packaging criteria for 2.5D/3D SiPs. Galib Ibne Haidar, Md Sami Ul Islam Sami, Jingbo Zhou 0002, Kimia Zamiri Azar, Mark Tehranipoor, Farimah Farahmandi |
ITC | 3 |
| 2024 | Continuity in Security: Leveraging LLM for Translating Security Properties Across Hardware DesignsabstractSystems on Chips (SoCs) are integral to modern devices, from consumer electronics to critical applications in healthcare, finance, and defense, housing various vital assets. Ensuring comprehensive security verification is crucial to protect these assets from diverse vulnerabilities. However, traditional security verification is time-consuming, and the rapid pace of market-driven design cycles demands new versions within tight time-to-market windows. Conducting exhaustive security verification from scratch for each new design iteration is both challenging and impractical. This paper introduces a novel framework leveraging large language models (LLMs) to translate security properties from legacy designs to new versions at the Register Transfer Level (RTL). By reusing existing verification efforts, this approach significantly reduces verification time while maintaining security continuity. Our methodology not only trans-lates but also extends and expands security properties to detect new vulnerabilities. Experimental results demonstrate substantial improvements in security continuity and vulnerability detection, advancing hardware security verification for evolving SoCs. Bulbul Ahmed, Sujan Kumar Saha, Jingbo Zhou 0002, Sohrab Aftabjahani, Mark Tehranipoor, Farimah Farahmandi |
VLSI-SoC | 3 |
| 2023 | Algorithmic Obfuscation for LDPC DecodersabstractIn order to protect intellectual properties against untrusted foundry, many logic-locking schemes have been developed. The idea of logic locking is to insert a key-controlled block into the circuit to make the circuit function incorrectly or go through redundant states without right keys. However, in the case that the algorithm implemented by the circuit is self-correcting, existing logic-locking schemes do not affect the system performance much even if a wrong key is used and hence do not effectively protect the circuit. One example is low-density parity-check (LDPC) error-correcting decoders, which are used in numerous digital communication and storage systems. This article proposes two algorithmic-level obfuscation methods for LDPC decoders. By modifying the decoding process and locking the stopping criterion, our new designs substantially degrade the decoder throughput and/or error-correcting performance, and make the decoder unusable when a wrong key is applied. For an example of the LDPC decoder, our proposed methods reduce the throughput to less than 1/3 and/or increase the decoder error rate by at least two orders of magnitude with at most 0.55% area overhead. Besides, our designs are also resistant to the SAT, AppSAT, and removal attacks. Jingbo Zhou 0002, Xinmiao Zhang 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2023 | Joint Protection Scheme for Deep Neural Network Hardware Accelerators and ModelsabstractDeep neural networks (DNNs) are utilized in numerous image processing, object detection, and video analysis tasks and need to be implemented using hardware accelerators to achieve practical speed. Logic locking is one of the most popular methods for preventing chip counterfeiting. Nevertheless, existing logic-locking schemes need to sacrifice the number of input patterns leading to wrong output under incorrect keys to resist the powerful satisfiability (SAT)-attack. Furthermore, the DNN model inference is fault tolerant. Hence, using a wrong key for those SAT-resistant logic-locking schemes may not affect the accuracy of DNNs. This makes the previous SAT-resistant logic-locking scheme ineffective on protecting DNN accelerators. Besides, to prevent DNN models from being illegally used, the models need to be obfuscated by the designers before they are provided to end-users. Previous obfuscation methods either require a long time to retrain the model or leak information about the model. This article proposes a joint protection scheme for DNN hardware accelerators and models. The DNN accelerator is modified using a hardware key (Hkey) and a model key (Mkey). Different from previous logic locking, the Hkey, which is used to protect the accelerator, does not affect the output when it is wrong. As a result, the SAT attack can be effectively resisted. On the other hand, a wrong Hkey leads to substantial increase in memory accesses, inference time, and energy consumption and makes the accelerator unusable. A correct Mkey can recover the DNN model that is obfuscated by the proposed method. Compared to previous model obfuscation schemes, our proposed method avoids model retraining and does not leak model information. Jingbo Zhou 0002, Xinmiao Zhang 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2021 | Generalized SAT-Attack-Resistant Logic LockingabstractLogic locking is used to protect integrated circuits (ICs) from piracy and counterfeiting. An encrypted IC implements the correct function only when the right key is input. Many existing logic-locking methods are subject to the powerful satisfiability (SAT)-based attack. Recently, an Anti-SAT scheme has been developed. By adopting two complementary logic blocks that consist of AND/NAND trees, it makes the number of iterations needed by the SAT attack exponential to the number of input bits. Nevertheless, the Anti-SAT scheme is vulnerable to the later AppSAT and removal attacks. This article proposes a generalized (G-)Anti-SAT scheme. Different from the Anti-SAT scheme, a variety of complementary or non-complementary functions can be adopted for the two blocks in our G-Anti-SAT scheme. The Anti-SAT scheme is just a special case of our proposed design. Our design can achieve higher output corruptibility, which is also tunable, so that better resistance to the AppSAT and removal attacks is achieved. Meanwhile, unlike existing AppSAT-resilient designs, our design does not sacrifice the resistance to the SAT attack. Jingbo Zhou 0002, Xinmiao Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |