About Me

I am Chongzhou Fang, a PhD candidate at University of California, Davis. My main research interest lies in system and hardware security. I focus on both cloud scheduler security and side-channel attack & defense in heterogeneous computing resources like FPGAs. I also expolore how LLM techniques can be applied to to the field of cybersecurity.

Publication Highlights

[UsenixSecurity'24]
Large Language Models for Code Analysis: Do LLMs Really Do Their Job?
Chongzhou Fang, Ning Miao, Shaurya Srivastav, Jialin Liu, Ruoyu Zhang, Ruijie Fang, Asmita Asmita, Ryan Tsang, Najmeh Nazari, Han Wang and Houman Homayoun
[UsenixSecurity'24]
Forget and Rewire: Enhancing the Resilience of Transformer-based Models against Bit-Flip Attacks
Najmeh Nazari, Hosein Mohammadi Makrani, Chongzhou Fang, Hossein Sayadi, Setareh Rafatirad, Khaled N. Khasawneh and Houman Homayoun
[UsenixSecurity'24]
Fuzzing BusyBox: Leveraging LLM and Crash Reuse for Embedded Bug Unearthing
Asmita Asmita, Yaroslav Oliinyk, Michael Scott, Ryan Tsang, Chongzhou Fang and Houman Homayoun
[DAC'24]
Architectural Whispers: Unveiling Machine Learning Models with Frequency Throttling Side-Channel Fingerprinting
Najmeh Nazari, Chongzhou Fang, Hosein Mohammadi Makrani, Behnam Omidi, Setareh Rafatirad, Avesta Sasan, Hossein Sayadi, Houman Homayoun and Khaled N. Khasawneh
[DATE'24]
SpecScope: Automating Discovery of Exploitable Spectre Gadgets on Black-box Microarchitectures
Najmeh Nazari*, Behnam Omidi*, Chongzhou Fang, Hosein Mohammadi Makrani, Setareh Rafatirad, Avesta Sasan, Houman Homayoun and Khaled N. Khasawneh
[CCS'23]
CSAW'24 ARC Finalist & Technical Impact Award Runner-up
Gotcha! I Know What You are Doing on the FPGA Cloud: Fingerprinting Co-Located Cloud FPGA Accelerators via Measuring Communication Links
Chongzhou Fang, Ning Miao, Han Wang, Jiacheng Zhou, Tyler Sheaves, John M. Emmert, Avesta Sasan and Houman Homayoun
[ICCAD'23]
Side Channel-assisted Inference Attack on Machine Learning-based ECG Classification
Jialin Liu, Houman Homayoun, Chongzhou Fang, Ning Miao and Han Wang
[NDSS'23]
HeteroScore: Evaluating and Mitigating Cloud Security Threats Brought by Heterogeneity
Chongzhou Fang, Najmeh Nazari, Behnam Omidi, Han Wang, Aditya Puri, Manish Arora, Setareh Rafatirad, Houman Homayoun and Khaled N. Khasawneh
[NDSS'22]
Repttack: Exploiting Cloud Schedulers to Guide Co-Location Attacks
Chongzhou Fang, Han Wang, Najmeh Nazari, Behnam Omidi, Avesta Sasan, Khaled N. Khasawneh, Setareh Rafatirad and Houman Homayoun

News

  • Nov. 2024: Our FPGA attack paper was selected as the Runner-Up for the Technical Impact Award during the CSAW ‘24 Applied Research Competition.
  • Oct. 2024: Our FPGA attack paper was selected as a finalist in the CSAW ‘24 Applied Research Competition (15 out of 194 submissions).
  • Aug. 2024: I presented our evaluation for LLM for code analysis at Usenix Security’24 in Philadelphia.
  • Jun. 2024: Our paper about defence against bit-flip attacks was accepted by Usenix Security 2024.
  • Feb. 2024: Our LLM analysis paper and LLM fuzzing paper were accepted by Usenix Security 2024.
  • Nov. 2023: I presented FPGA fingerprinting attack paper at CCS’23 in Copenhagen.
  • Nov. 2023: Our SpecScope paper was accepted by DATE 2024.
  • Oct. 2023: I was awarded the travel grant to attend ACM CCS 2023.
  • Jul. 2023: Our ML side-channel attack paper was accepted by ICCAD 2023.
  • May 2023: Our FPGA attack paper was accepted by CCS 2023.
  • Apr. 2023: Our cloud RPS attack paper was accepted by IEEE Micro.
  • Feb. 2023: I presented HeteroScore at NDSS 2023 in San Diego.
  • Dec. 2022: Our heterogeneity metric paper is accepted by NDSS 2023.
  • Nov. 2022: I attended Noyce Symposium at UC Santa Barbara.
  • Sep. 2022: I finished my internship at Intel PSG.
  • Sep. 2022: I’m now a Ph.D. candidate at UC Davis.
  • Jul. 2022: Our FPGA security proposal is funded by CHEST. I will be leading the project.
  • Jun. 2022: I started my internship at Intel PSG and will be working on novel FPGA security features for the next 3 months.
  • Apr. 2022: I presented Repttack at NDSS 2022 in San Diego.
  • Sep. 2021: Our cloud attack paper was accepted by NDSS 2022.
  • Sep. 2020: I started my journey of Ph.D. at UC Davis. I am thrilled to have the chance to work with Prof. Houman Homayoun, Prof. Khasawneh and other awesome lab members!