Researcher profile

Ke Huang

Ke Huang contributes to research discovery and scholarly infrastructure.

ResearcherAffiliation not importedOpen to collaborate

Trust snapshot

Quick read

Trust 21 - EmergingVerification L1Unclaimed author
9works
0followers
9topics
4close collaborators

Actions

Decide how to stay connected

Follow researcher0

Identity and collaboration

How to connect with this researcher

Claiming links this public author record to a researcher profile and unlocks direct collaboration workflows.

Log in to claim

Direct collaboration

Open a focused conversation when the fit is right

Claim this author entity first to unlock direct invitations.

Research graph

See the researcher in context

Open full explorer

Inspect adjacent work, topics, institutions and collaborators without jumping out to a separate graph page.

Building this graph slice

BZPEER is loading the nearby papers, people, topics and institutions for this page.

Published work

9 published item(s)

preprint2023arXiv

Incommensurate many-body localization in the presence of long-range hopping and single-particle mobility edge

We study many-body localization (MBL) in the quasiperiodic $t_1$-$t_2$ model, focusing on the role of next-nearest-neighbor (NNN) hopping $t_2$, which introduces a single-particle mobility edge. The calculated phase diagram can be divided into three distinct regimes, depending on the strength of the short-range interaction $U$. For weak interactions ($U\ll t_1$), this model is always nonthermal. For intermediate interactions ($U\sim t_1$), the thermal-MBL phase transition in this model is qualitatively the same as that of the Aubry-Andre (AA) model, which is consistent with existing experimental observations. For strong interactions $(U\gg t_1)$, the NNN hopping produces qualitatively new physics because it breaks down the Hilbert space fragmentation present in the AA model. The NNN hopping is thus irrelevant when the interaction is intermediate but relevant for strong interactions.

preprint2022arXiv

AdaTest:Reinforcement Learning and Adaptive Sampling for On-chip Hardware Trojan Detection

This paper proposes AdaTest, a novel adaptive test pattern generation framework for efficient and reliable Hardware Trojan (HT) detection. HT is a backdoor attack that tampers with the design of victim integrated circuits (ICs). AdaTest improves the existing HT detection techniques in terms of scalability and accuracy of detecting smaller Trojans in the presence of noise and variations. To achieve high trigger coverage, AdaTest leverages Reinforcement Learning (RL) to produce a diverse set of test inputs. Particularly, we progressively generate test vectors with high reward values in an iterative manner. In each iteration, the test set is evaluated and adaptively expanded as needed. Furthermore, AdaTest integrates adaptive sampling to prioritize test samples that provide more information for HT detection, thus reducing the number of samples while improving the sample quality for faster exploration. We develop AdaTest with a Software/Hardware co-design principle and provide an optimized on-chip architecture solution. AdaTest's architecture minimizes the hardware overhead in two ways:(i) Deploying circuit emulation on programmable hardware to accelerate reward evaluation of the test input; (ii) Pipelining each computation stage in AdaTest by automatically constructing auxiliary circuit for test input generation, reward evaluation, and adaptive sampling. We evaluate AdaTest's performance on various HT benchmarks and compare it with two prior works that use logic testing for HT detection. Experimental results show that AdaTest engenders up to two orders of test generation speedup and two orders of test set size reduction compared to the prior works while achieving the same level or higher Trojan detection rate.

preprint2022arXiv

An Adaptive Black-box Backdoor Detection Method for Deep Neural Networks

With the surge of Machine Learning (ML), An emerging amount of intelligent applications have been developed. Deep Neural Networks (DNNs) have demonstrated unprecedented performance across various fields such as medical diagnosis and autonomous driving. While DNNs are widely employed in security-sensitive fields, they are identified to be vulnerable to Neural Trojan (NT) attacks that are controlled and activated by stealthy triggers. In this paper, we target to design a robust and adaptive Trojan detection scheme that inspects whether a pre-trained model has been Trojaned before its deployment. Prior works are oblivious of the intrinsic property of trigger distribution and try to reconstruct the trigger pattern using simple heuristics, i.e., stimulating the given model to incorrect outputs. As a result, their detection time and effectiveness are limited. We leverage the observation that the pixel trigger typically features spatial dependency and propose the first trigger approximation based black-box Trojan detection framework that enables a fast and scalable search of the trigger in the input space. Furthermore, our approach can also detect Trojans embedded in the feature space where certain filter transformations are used to activate the Trojan. We perform extensive experiments to investigate the performance of our approach across various datasets and ML models. Empirical results show that our approach achieves a ROC-AUC score of 0.93 on the public TrojAI dataset. Our code can be found at https://github.com/xinqiaozhang/adatrojan

preprint2022arXiv

FaceSigns: Semi-Fragile Neural Watermarks for Media Authentication and Countering Deepfakes

Deepfakes and manipulated media are becoming a prominent threat due to the recent advances in realistic image and video synthesis techniques. There have been several attempts at combating Deepfakes using machine learning classifiers. However, such classifiers do not generalize well to black-box image synthesis techniques and have been shown to be vulnerable to adversarial examples. To address these challenges, we introduce a deep learning based semi-fragile watermarking technique that allows media authentication by verifying an invisible secret message embedded in the image pixels. Instead of identifying and detecting fake media using visual artifacts, we propose to proactively embed a semi-fragile watermark into a real image so that we can prove its authenticity when needed. Our watermarking framework is designed to be fragile to facial manipulations or tampering while being robust to benign image-processing operations such as image compression, scaling, saturation, contrast adjustments etc. This allows images shared over the internet to retain the verifiable watermark as long as face-swapping or any other Deepfake modification technique is not applied. We demonstrate that FaceSigns can embed a 128 bit secret as an imperceptible image watermark that can be recovered with a high bit recovery accuracy at several compression levels, while being non-recoverable when unseen Deepfake manipulations are applied. For a set of unseen benign and Deepfake manipulations studied in our work, FaceSigns can reliably detect manipulated content with an AUC score of 0.996 which is significantly higher than prior image watermarking and steganography techniques.

preprint2022arXiv

Fermionic many-body localization for random and quasiperiodic systems in the presence of short- and long-range interactions

We study many-body localization (MBL) for interacting one-dimensional lattice fermions in random (Anderson) and quasiperiodic (Aubry-Andre) models, focusing on the role of interaction range. We obtain the MBL quantum phase diagrams by calculating the experimentally relevant inverse participation ratio (IPR) at half-filling using exact diagonalization methods and extrapolating to the infinite system size. For short-range interactions, our results produce in the phase diagram a qualitative symmetry between weak and strong interaction limits. For long-range interactions, no such symmetry exists as the strongly interacting system is always many-body localized, independent of the effective disorder strength, and the system is analogous to a pinned Wigner crystal. We obtain various scaling exponents for the IPR, suggesting conditions for different MBL regimes arising from interaction effects.

preprint2022arXiv

Nonreciprocal transport in a bilayer of MnBi2Te4 and Pt

MnBi2Te4 (MBT) is the first intrinsic magnetic topological insulator with the interaction of spin-momentum locked surface electrons and intrinsic magnetism, and it exhibits novel magnetic and topological phenomena. Recent studies suggested that the interaction of electrons and magnetism can be affected by the Mn-doped Bi2Te3 phase at the surface due to inevitable structural defects. Here we report an observation of nonreciprocal transport, i.e. current-direction-dependent resistance, in a bilayer composed of antiferromagnetic MBT and nonmagnetic Pt. The emergence of the nonreciprocal response below the Néel temperature confirms a correlation between nonreciprocity and intrinsic magnetism in the surface state of MBT. The angular dependence of the nonreciprocal transport indicates that nonreciprocal response originates from the asymmetry scattering of electrons at the surface of MBT mediated by magnon. Our work provides an insight into nonreciprocity arising from the correlation between magnetism and Dirac surface electrons in intrinsic magnetic topological insulators.

preprint2021arXiv

Nano-engineering the evolution of skyrmion crystal in synthetic antiferromagnets

The evolution of skyrmion crystal encapsulates skyrmion critical behaviors, such as nucleation, deformation and annihilation. Here, we achieve a tunable evolution of artificial skyrmion crystal in nanostructured synthetic antiferromagnet multilayers, which are comprised of perpendicular magnetic multilayers and nanopatterned arrays of magnetic nanodots. The out-of-plane magnetization hysteresis loops and first-order reversal curves show that the nucleation and annihilation of the artificial skyrmion can be controlled by tuning the diameter of and spacing between the nanodots. Moreover, when the bottom layer thickness increases, the annihilation of skyrmion shifts from evolving into a ferromagnetic spin texture to evolving into an antiferromagnetic spin texture. Most significantly, non-volatile multiple states are realized at zero magnetic field via controlling the proportion of the annihilated skyrmions in the skyrmion crystal. Our results demonstrate the tunability and flexibility of the artificial skyrmion platform, providing a promising route to achieve skyrmion-based multistate devices, such as neuromorphic spintronic devices.

preprint2020arXiv

Perturbative deflection angle for signal with finite distance and general velocities

We propose a perturbative method to compute the deflection angle of both null and massive particles for source and detector at finite distance. This method applies universally to the motion of particles with general velocity in the equatorial plane of stationary axisymmetric spacetimes or static spherical symmetric spacetimes that are asymptotically flat. The resultant deflection angle automatically arranges into a quasi-inverse series form of the impact parameter, with coefficients depending on the metric functions, the signal velocity and the source and detector locations through the apparent angles. In the large impact parameter limit, the series coefficients are reduced to rational functions of sine/cosine functions of the zero order apparent angle.

preprint2020arXiv

Perturbative deflection angles of timelike rays

Geodesics of both lightrays and timelike particles with nonzero mass are deflected in a gravitational field. In this work we apply the perturbative method developed in Ref. \cite{Jia:2020dap} to compute the deflection angle of both null and timelike rays in the weak field limit for four spacetimes. We obtained the deflection angles for the Bardeen spacetime to the eleventh order of $m/b$ where $m$ is the ADM mass and $b$ is the impact parameter, and for the Hayward, Janis-Newman-Winicour and Einstein-Born-Infeld spacetimes to the ninth, seventh and eleventh order respectively. The effect of the impact parameter $b$, velocity $v$ and spacetime parameters on the deflection angle are analyzed in each of the four spacetimes. It is found that in general, the perturbative deflection angle depends on and only on the asymptotic behavior of the metric functions, and in an order-correlated way. Moreover, it is shown that although these deflection angles are calculated in the large $b/m$ limit, their minimal valid $b$ can be as small as a few $m$'s as long as the order is high enough. At these impact parameters, the deflection angle itself is also found large. As velocity decreases, the deflection angle in all spacetime studied increases. For a given $b$, if the spacetime parameters allows a critical velocity $v_c$, then the perturbative deflection angle will deviate from its true value as $v$ decreases to $v_c$. It is also found that if the variation of spacetime parameters can only change the spacetime qualitatively at small but not large radius, then these spacetime parameter will not cause a qualitative change of the deflection angle, although its value is still quantitatively affected. The application and possible extension of the work are discussed.