VLDB 2026 Research / reviewers in the wild / expert
Hao Huang 0011
dblp:04/5616-11
· DBLP profile ↗
10ranked-venue papers
0as first author
6since 2021 · last 2024
0009-0007-7160-0483ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 5 · 2 since 2021Security and privacy · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Exploiting Flat Namespace to Improve File System Metadata Performance on Ultra-Fast, Byte-Addressable NVMsabstractThe conventional file system provides a hierarchical namespace by structuring it as a directory tree. Tree-based namespace structure leads to inefficient file path walk and expensive namespace tree traversal, underutilizing ultra-low access latency and superior sequential performance provided by non-volatile memories (NVMs). This article proposes FlatFS+, an NVM file system that features a flat namespace architecture while providing a compatible hierarchical namespace view. FlatFS+ incorporates three novel techniques: the direct file path walk model, range-optimized B r tree, and compressed index key design with scan and write dual optimization, to fully exploit flat namespace to improve file system metadata performance on ultra-fast, byte-addressable NVMs. Evaluation results demonstrate that FlatFS+ achieves significant performance improvements for metadata-intensive benchmarks and real-world applications compared to other file systems. Miao Cai 0001, Junru Shen, Bin Tang 0002, Hao Huang 0011 |
ACM Trans. Storage | 4 |
| 2022 | eSROP Attack: Leveraging Signal Handler to Implement Turing-Complete Attack Under CFI Defense
Tianning Zhang, Miao Cai 0001, Diming Zhang, Hao Huang 0011 |
SecureComm | 4 |
| 2022 | SigGuard: Hardening Vulnerable Signal Handling in Commodity Operating SystemsabstractSignal is a useful mechanism provided by many commodity operating systems. However, current signal handling has serious security concerns due to vulnerable design in missing integrity protections for signal handling control flow. Security weaknesses caused by vulnerable design are exploited by adversaries to mount dangerous control-flow attacks. To tackle these issues, this paper investigates root causes of signal-related attacks and proposes SigGuard to harden vulnerable signal handling mechanism. To protect unsafe signal handler execution flow, we design a customized signal handler CFI framework which supports low-cost, reentrant, online CFI analysis and enforcement. To secure signal handler return control flow, we propose an efficient, software-based, intra-process memory isolation method to ensure signal frame data integrity. We evaluate SigGuard with both security and performance experiments. In security experiments, SigGuard successfully thwarts four signal-based attacks, including two proof-of-concept exploits and two realistic attacks conducted in Nginx and Apache server programs, respectively. We also evaluate SigGuard key techniques with a series of microbenchmarks and real-world applications. Experimental results suggest that key defense techniques used in SigGuard introduce reasonable performance costs. Miao Cai 0001, Junru Shen, Tianning Zhang, Hao Huang 0011 |
SRDS | 4 |
| 2022 | FlatFS: Flatten Hierarchical File System Namespace on Non-volatile Memories
Miao Cai 0001, Junru Shen, Bin Tang 0002, Hao Huang 0011 |
USENIX ATC | 4 |
| 2022 | SeBROP: blind ROP attacks without returns
Tianning Zhang, Miao Cai 0001, Diming Zhang, Hao Huang 0011 |
Frontiers Comput. Sci. | 4 |
| 2021 | A survey of operating system support for persistent memory
Miao Cai 0001, Hao Huang 0011 |
Frontiers Comput. Sci. | 2 |
| 2020 | De-randomizing the Code Segment with Timing Function AttackabstractRecently, many effective defensive methods (e.g., ASLR, execute-only-memory) have been proposed to defeat the code reuse attack in the software system. These approaches provide strong system protection through address randomization or memory access restriction. However, this paper identifies a new weak point in these approaches, i.e., missing time protection. We propose a new attack method called timing function attack, which can initiate a code reuse attack even against the state-of-the-art defense techniques. Previous solutions utilize various techniques to hide the spatial information. However, we still can obtain critical security information through the time channel. Specifically, we leverage the function execution time to conduct a side-channel attack. Further, we de-randomize the code segment layout with the timing-channel attack result. Finally, we perform a code-reuse attack with gadgets gathered in previous steps, compromising the whole system. To validate our timing function attack in the real world, we conduct two attacks on two JavaScript engines, i.e., ChakraCore and Chrome v8. Evaluation results show that our attack can successfully bypass the existing defense techniques, such as function-granularity ASLR and XOM, and escalate the privilege. Besides, we also discuss some solutions to prevent and defend our proposed timing function attack. Tianning Zhang, Miao Cai 0001, Diming Zhang, Hao Huang 0011 |
TrustCom | 4 |
| 2020 | A Scalable Virtual memory system based on decentralization for many-cores
Miao Cai 0001, Diming Zhang, Hao Huang 0011 |
J. Syst. Archit. | 3 |
| 2018 | MedusaVM: Decentralizing Virtual Memory System for Multithreaded Applications on Many-core
Miao Cai 0001, Shenming Liu, Weiyong Yang, Hao Huang 0011 |
ICA3PP (1) | 4 |
| 2017 | tScale: A Contention-Aware Multithreaded Framework for Multicore Multiprocessor SystemsabstractOn the multicore and multiprocessor system, multithreaded applications which are kernel-intensive usually suffer from two kinds of performance issues, first one is frequent context switch between kernel/user mode. Another one is lock contention caused by non-scalable synchronization primitives (e.g., ticket spin lock) and may even result in performance degradation under heavy contention level. Unfortunately, current Linux threading model (i.e., NPTL) which adopts exception-based system call mechanism fails to reduce the excessive system call cost. Besides, conventional threading scheduler which is unconscious of lock contention also lacks the ability to limit the number of system-wide contending parallel threads. Both of them impede the application's throughput increment and may lead to the performance breakdown eventually. In this paper we propose a contention-aware threading framework to alleviate these two problems. Our proposed design is composed of two tightly contected components: system call batching via user-level thread library and a contention-aware scheduler based on non-work-conserving scheduling policy. The user-level threading library gathers multiple system call invocations transparently and deliverys these requests to the underlaying kernel working threads. Therefore, tScale improves application performance by reducing massive context switch cost. Then through continuing monitoring system-wide lock contention level and application's total throughput increment, tScale can quickly adjust the number of contending threads in order to sustain the maximum throughput. The prototype system is implemented on Linux 3.18.30 and Glibc 2.23. In microbenchmarks on a 32-core machine, experiment results show that our approach can not only improve the application throughput by up to 20% but also address the lock contention efficiently. Miao Cai 0001, Shenming Liu, Hao Huang 0011 |
ICPADS | 3 |