王海霞

undefined

王海霞   副研究员

通信地址:北京市海淀区清华大学FIT楼3-412

联系电话:62785592

Email:hx-wang@tsinghua.edu.cn




教育背景

19989-20047 中国科学院计算技术研究所 计算机系统结构 工学博士

1994年9月-1998年7月 南开大学 自动控制 学士

工作履历

20051月-200611月 清华大学 博士后

2006年12月-至今 清华大学 助理研究员、副研究员

学术兼职

中国计算机学会高级会员,中国计算机学会体系结构专委会委员

研究领域

处理器硬件安全、处理器体系结构

研究概况

(1)构建通用处理器漏洞挖掘平台

使用代码块拼装的方式组成测试用例种群,采用细粒度处理器运行时状态监测获取测试信息,构建漏洞模型对异常行为进行判别,实现了自动化、大批量、高效率的黑盒处理器漏洞挖掘,测试结果除覆盖已知漏洞和变种外,发现了幻影(Leaky MDU)漏洞,论文发表在DAC会议上。

(2)提出处理器安全的形式化验证方法

提出一套基于模型检验的形式化验证方法,通过对处理器建模、定义安全属性,实现处理器安全属性的自动化验证。采用该方法对处理器是否存在分支预测类漏洞、微架构数据采样类漏洞以及缓存侧信道等进行验证,发现了1种新的分支预测类漏洞变种、5种缓存侧信道攻击策略以及1种针对非包含缓存的跨核攻击方式,论文发表在TIFS、ASP-DAC等会议和期刊上。

(3)提出安全缓存设计

提出一种隔离式安全缓存设计,能够提供至多512个分区,可抵御基于外部干涉的缓存侧信道,论文发表在TDSC期刊上。

奖励与荣誉

(1)科研成果入选世界互联网大会领先科技成果集(基础研究组)(2023)

(2)山东省科学技术进步一等奖(2022)

(3)中国计算机学会自然科学一等奖(2020)

(4)中国电子学会科技进步一等奖(2020)

学术成果

[1] Lingfeng Yin, Haixia Wang, Yongqiang Lyu, Chaojian Hu and Dongsheng Wang. VeriCache: Formally Verified Fine-Grained Partitioned Cache for Side-Channel-Secure Enclaves. IEEE Transactions on Dependable and Secure Computing, 2025: 1-12.

[2] Shixuan Zhang, Haixia Wang, Pengfei Qiu, Yongqiang Lyu, Hongpeng Wang, Dongsheng Wang. SCAFinder: Formal Verification of Cache Fine-Grained Features for Side Channel Detection. IEEE Trans. Inf. Forensics Secur. 19: 8079-8093 (2024).

[3] Rihui Sun,Pengfei Qiu,Yongqiang Lyu,Jian Dong,Haixia Wang,Dongsheng Wang,Gang Qu. Lightning: Leveraging DVFS-induced Transient Fault Injection to Attack Deep Learning Accelerator of GPUs. ACM Trans. Design Autom. Electr. Syst. 29(1): 14:1-14:22 (2024).

[4] Chang Liu, Yongqiang Lyu, Haixia Wang, Pengfei Qiu, Dapeng Ju, Gang Qu, Dongsheng Wang. Leaky MDU: ARM Memory Disambiguation Unit Uncovered and Vulnerabilities Exposed. In Proceedings of the 60th Annual Design Automation Conference, 2023: 1-6.

[5] 刘畅,杨毅,李昊儒,邱朋飞,吕勇强,王海霞,鞠大鹏,汪东升,处理器分支预测攻击研究综述, 计算机学报,2022 45(12):2475-2510.

[6] Zihan Xu, Lingfeng Yin, Yongqiang Lyu, Haixia Wang, Gang Qu, Dongsheng Wang. CacheGuard: A Behavior Model Checker for Cache Timing Side-Channel Security, 27th Asia and South Pacific Design Automation Conference, 2022 : 19-24.

[7] Qian Ke, Chunlu Wang, Haixia Wang, Yongqiang Lyu, Zihan Xu, Dongsheng Wang:Model Checking for Microarchitectural Data Sampling Security. DSC 2022: 56-63.

[8] Tongliang Li, Haixia Wang, Airan Shao, Dongsheng Wang. SSB-Tree: Making Persistent Memory B+-Trees Crash-Consistent and Concurrent by Lazy-Box. 36th IEEE International Parallel and Distributed Processing Symposium,2022: 70-80.

[9] Shangming Cai, Dongsheng Wang, Haixia Wang, Yongqiang Lyu, Guangquan Xu, Xi Zheng, Athanasios V. Vasilakos: DynaComm: Accelerating Distributed CNN Training Between Edges and Clouds Through Dynamic Communication Scheduling. IEEE J. Sel. Areas Commun. 40(2): 611-625,2022.

[10] Zizhong Wang, Tongliang Li, Haixia Wang, Airan Shao, Yunren Bai, Shangming Cai, Zihan Xu, Dongsheng Wang: CRaft: An Erasure-coding-supported Version of Raft for Reducing Storage Cost and Network Cost. FAST 2020: 297-308.

[11] Shangming Cai, Dongsheng Wang, Zhanye Wang, Haixia Wang: CARD: A Congestion-Aware Request Dispatching Scheme for Replicated Metadata Server Cluster. ICPP 2020: 5:1-5:11.

[12] Zizhong Wang, Haixia Wang, Airan Shao, Dongsheng Wang:An Adaptive Erasure-Coded Storage Scheme with an Efficient Code-Switching Algorithm. ICPP 2020: 35:1-35:11.

[13] Yuchen Qiao, Kazuma Hashimoto, Akiko Eriguchi, Haixia Wang, Dongsheng Wang, Yoshimasa Tsuruoka, Kenjiro Taura: Parallelizing and optimizing neural Encoder-Decoder models without padding on multi-core architecture. Future Gener. Comput. Syst. 108: 1206-1213, 2020.

人才培养

2023年,指导学生参加华为鲲鹏应用创新大赛获金奖

2020年,指导学生获清华大学优秀硕士学位论文和北京市优秀毕业生