Donghui Yu

dblp:05/575 · DBLP profile ↗
← Back
11ranked-venue papers
4as first author
9since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 1 first-author · 4 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Pay Your Attention on Lib! Android Third-Party Library Detection via Feature Language Model
abstract
The widespread use of third-party libraries (TPL) has brought many conveniences to Android application devel-opment, fostering the development of the Android application ecosystem. Detecting the presence of TPLs in Android applications is crucial in the Android era, as it enables the rapid identification of their usage when security vulnerabilities arise in TPL code. Android code obfuscation can significantly impact the task of detecting TPLs, especially as obfuscation methods continue to iterate. Rule-based matching methods, which are commonly used in most approaches, often struggle to adapt to new obfuscation strategies. This paper proposes LibAttention, a feature-Ianguage-model-based Android TPL detection technique. LibAttention converts app binary code and TPL source code into Android intermediate representation Smali and extracts features that are less suscep-tible to obfuscation. These features are then fed into a language model to train an encoder from scratch. During the detection process, LibAttention encodes and compresses the app and TPL code representations and feeds them into downstream models for training and prediction. LibAttention is trained for third-party library detection tasks on downstream models, utilizing datasets compiled with various obfuscation modes and threshold adjustments to establish detection standards. Subsequently, de-tection and evaluation are conducted on the large-scale AndroZoo dataset. Its pretraining-fine-tuning model architecture eliminates the dependency on large amounts of labeled data samples. The experimental results indicate that the detection capabilities of LibAttention are more effective compared to the baseline results, significantly mitigating the impact of the Android R8 obfuscation tool on applications. Moreover, when compared to existing rule-based Android TPL detection techniques, LibAt-tention demonstrates significant improvements on the Android R8 obfuscation dataset, boasting over a 30% enhancement in the F1-score.
Dahan Pan, Runhan Feng, Donghui Yu, Ya Fang, Yuanyuan Zhang 0002
SANER4
2024 COMURICE: Closing Source Code Leakage in Cloud-Based Compiling via Enclave
abstract
Cloud-native-based software development is in trend now. The end-users use the cloud services to save the local computation resources for other intensive tasks. Compiling is one of the vital required services. The compiling-on-the-cloud service like CloudCompiling or CityCloud requires the user to upload their source code for online compiling. However, the latest online compiling service can neither protect the users' source code privacy nor prove the integrity of the whole compiling process. To fill this gap, we designed COMURICEto provide a user-transparent, secure compiling service employing the trusted execution environment (TEE) to enforce security by blocking all the attempts in code or data theft during the compiling procedure. COMURICEleverages the hardware security feature of TEE to prevent the compiling process from malicious access and modification while encrypting the communication channel to protect the integrity and privacy of the source code. The challenges in realizing COMURICElie in porting a fully functional compiler such as GCC or LLVM and designing an efficient compiling service to minimize the performance lag brought by confidential computing. According to the characteristics of the compiling process, it consists of several routines, pre-processing, compiling/obfuscation, and linking. The division of the routines requires multiple enclaves to run simultaneously. In the experiment, we compare COMURICE'Scompiling service with nativeLLVM, SCONELLVM, and GrapheneLLVM. From a performance perspective, COMURICEpays a fair cost for security. Generally, a project compiling with COMURICEsuffers 1–2 times more performance loss than nativeLLVM. Compared to other confidential compiling techniques like GrapheneLLVM or SCONELLVM, COMURICEis up to 20 times faster when compiling the same projects.
Dahan Pan, Yingpeng Chen, Donghui Yu, Yuanyuan Zhang 0002
CSCloud4
2024 DDGF: Dynamic Directed Greybox Fuzzing with Path Profiling
abstract
Coverage-Guided Fuzzing (CGF) has become the most popular and effective method for vulnerability detection. It is usually designed as an automated “black-box” tool. Security auditors start it and then just wait for the results. However, after a period of testing, CGF struggles to find new coverage gradually, thus making it inefficient. It is difficult for users to explain reasons that prevent fuzzing from making further progress and to determine whether the existing coverage is sufficient. In addition, there is no way to interact and direct the fuzzing process. In this paper, we design the dynamic directed greybox fuzzing (DDGF) to facilitate collaboration between the user and fuzzer. By leveraging Ball-Larus path profiling algorithm, we propose two new techniques: dynamic introspection and dynamic direction. Dynamic introspection reveals the significant imbalance in the distribution of path frequency through encoding and decoding. Based on the insight from introspection, users can dynamically direct the fuzzer to focus testing on the selected paths in real time. We implement DDGF based on AFL++. Experiments on Magma show that DDGF is effective in helping the fuzzer to reproduce vulnerabilities faster, with up to 100x speedup and only 13% performance overhead. DDGF shows the great potential of human-in-the-loop for fuzzing.
Haoran Fang, Kaikai Zhang, Donghui Yu, Yuanyuan Zhang 0002
ISSTA3
2024 Enhancing Effective Bidirectional Isolation for Function Fusion in Serverless Architectures
abstract
Serverless computing has emerged as a popular paradigm in modern cloud environments, offering flexibility and scalability to tenants. A serverless function might handle sensitive tenant data. Employing Trusted Execution Environment (TEE) techniques to protect such a function from untrusted cloud service providers is attractive for tenant privacy. However, this introduces response latency, thereby impacting the performance of function execution. This paper introduces Fundue, a serverless architecture with bidirectional isolation between tenant and cloud provider that achieves light-weight isolation of functions and reduces cold start latency by fusing functions. Fundue enables multiple functions uploaded by the same tenant to share a single execution environment embedded into the enclave. Fundue allocates separate memory for each serverless function within the execution environment and establishes robust isolation between functions through bounds checking mechanisms. We extensively evaluate Fundue with diverse workloads and representative serverless functions. Our results demonstrate a significant reduction in response latency of serverless function execution, ranging from 17.8% to 88.7% compared to AccTEE, an open-source two-way sandbox serverless framework. Additionally, Fundue mitigates vulnerabilities in existing execution environments, such as stack-based buffer overflows.
Yingpeng Chen, Donghui Yu, Yuanyuan Zhang 0002, Bert Lagaisse
Middleware3
2023 Small Signal Modeling of Fractional-Order Boost Converter with Non-Singular Fractional Derivative
abstract
The fractional-order models have received extensive attention as they could describe the system characteristics of the Boost converter more accurately compared with integer-order models. Due to the singular kernels of traditional definitions that would reduce the modeling accuracy, this paper proposes a Caputo-Fabrizio (C-F) definition-based fractional-order Boost converter model using the small signal modeling method by employing equivalent state variables instead of traditional ones. The proposed model has high accuracy, which is verified by scanning the frequency of the circuit model and comparing it with the mathematical model. Additionally, the influence of fractional order on the system characteristics of the model in the frequency domain is analyzed, providing theoretical support for further studies on fractional-order boost converters with non-singular kernels.
Donghui Yu, Xiaozhong Liao, Manjie Ran
CoDIT1
2023 Chaos Control of Fractional-Order Buck Converter Based on Caputo-Fabrizio Fractional Derivative
abstract
This paper presents, for the first time, a chaos control scheme for the fractional-order Buck converter with Caputo-Fabrizio derivative to suppress the chaos phenomenon. Chaos analysis of the peak current mode fractional-order Buck converter is first carried out by numerical simulation, with a focus on the impact of the fractional order on the system's chaos range. A chaos controller based on a genetic algorithm optimized neural network is then proposed, which combines the neural network algorithm with the parametric resonance perturbation method to optimize the design of control parameters. Finally, circuit simulations in MATLAB show that the proposed method effectively controls the system from a chaotic state to a stable state, demonstrating the effectiveness of the chaos control algorithm used in this paper.
Xiaozhong Liao, Manjie Ran, Donghui Yu
IECON3
2023 Modeling and Analysis of Fractional-order Boost Converter with a Constant Power Load
abstract
This paper models and analyzes a fractional-order Boost converter with a constant power load (CPL). The transfer function and state equation of the circuit are derived through the small signal linearization method. The boundary conditions for the circuit operating in Continuous Conduction Mode (CCM) are then analyzed. Finally, the correctness of the proposed model is verified by circuit simulation experi-ments, the influence of circuit parameters on CCM boundary conditions is analyzed, and a method for determining the stability of the circuit system is given. The experimental results show that the proposed model can accurately describe the system characteristics of circuits and that using fractional-order components to design the Boost converter with a CPL can effectively expand the stable range of systems.
Donghui Yu, Xiaozhong Liao, Manjie Ran
IECON1
2023 SEnFuzzer: Detecting SGX Memory Corruption via Information Feedback and Tailored Interface Analysis
abstract
Intel SGX provides protected memory called enclave to secure the private user data against corrupted or malicious OS environment. However, several researches have shown that the SGX applications suffer from memory corruption vulnerabilities, thus leading to critical information leakage. Detecting memory corruption vulnerability in SGX applications can be cumbersome. Existing works either use symbolic execution or formal methods to analyze the enclave library, which is known to be inefficient and errors prone. Fuzzing, an effective and efficient vulnerability detection method is rarely used in SGX and has limitations.
Donghui Yu, Haoran Fang, Ya Fang, Yuanyuan Zhang 0002
RAID1
2022 VirTEE: a full backward-compatible TEE with native live migration and secure I/O
abstract
Modern security architectures provide Trusted Execution Environments (TEEs) to protect critical data and applications against malicious privileged software in so-called enclaves. However, the seamless integration of existing TEEs into the cloud is hindered, as they require substantial adaptation of the software executing inside an enclave as well as the cloud management software to handle enclaved workloads. We tackle these challenges by presenting VirTEE, the first TEE architecture that allows strongly isolated execution of unmodified virtual machines (VMs) in enclaves, as well as secure live migration of VM enclaves between VirTEE-enabled servers. Combined with its secure I/O capabilities, VirTEE enables the integration of enclaved computing in today's complex cloud infrastructure. We thoroughly evaluate our RISC-V-based prototype, and show its effectiveness and efficiency.
Pouya Mahmoody, Ferdinand Brasser, Patrick Jauernig, Ahmad-Reza Sadeghi, Donghui Yu, Dahan Pan, Yuanyuan Zhang 0002
DAC6
2014 Data forwarding based on sensor device constraints in wireless multimedia sensor networks
Soyoung Hwang, Donghui Yu
Multim. Tools Appl.2
2004 A Stable Estimation Model for Time Synchronization on the Internet Using Kalman Filtering
Donghui Yu, Yongho Kim, Soyoung Hwang
EUC1