VLDB 2026 Research / reviewers in the wild / expert
Ben Liu 0007
dblp:07/3517-7
· DBLP profile ↗
2ranked-venue papers
0as first author
2since 2021 · last 2026
—ORCID · unresolved
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Hypnos: A Practical Power Side-Channel Attack via CPU Idle TimeabstractThe growing demand for high-performance computing has led to various optimization techniques, but these advancements have also raised concerns about energy consumption. In response, processor vendors have implemented power management features. On x86-based CPUs, C-states allow the processor to enter idle states, reducing power consumption during low workloads. While users cannot directly control these states, C-states provide an interface to monitor CPU idle time, offering transparency without user intervention. However, it remains unclear whether this design could be exploited for power side-channel leakages. In this paper, we propose Hypno, a new type of software-based power side-channel attack on x86-based systems. Our key observation is that the unprivileged access to the CPUIDLE interface provides fine-grained observations of the time spent in various idle states. As this time is directly correlated with CPU activities, unprivileged attackers can leverage this information to establish a new power side channel. To demonstrate the viability of Hypnos, we conduct three end-to-end case studies. First, we demonstrate cross core covert channels that operate even in isolated environments, achieving higher transmission rates than channels that read cpufreq and broader applicability than methods that rely on uncore idle states. Second, we demonstrate a website fingerprinting attack on Google Chrome with high accuracy. Lastly, we successfully break KASLR within 3 minutes. Yusi Feng, Xin Zhang 0110, Zihui Guo, Ben Liu 0007, Yinqian Zhang |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | Constant-Time Loading: Modifying CPU Pipeline to Defeat Cache Side-Channel AttacksabstractCache side-channel attacks exploit cache state changes to steal confidential information. The emergence of transient execution attacks, a new form of microarchitecture side-channel attack that can access any address, makes cache side-channel attacks more threatening. Most of these attacks infer information by measuring the execution time of load operations. Therefore, from the microarchitecture perspective, we propose a novel countermeasure against cache side-channel attacks by eliminating the access time difference caused by cache hits or misses. We use the constant-time loading mechanism to limit each load instruction's execution to a fixed time and specify this mechanism's wake-up condition to avoid excessive performance loss. We modify the CPU pipeline to simulate this design and run SPEC2006 applications. The results show that the performance loss of our mechanism is negligible. Yusi Feng, Shuan Li, Ben Liu 0007, Huozhu Wang, Dan Meng 0002 |
TrustCom | 4 |