Jiaqi Li 0023

dblp:118/4502-23 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
6since 2021 · last 2025
0009-0007-2446-2727ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 5 since 2021Systems, architecture and hardware · 2 · 1 since 2021
YearPublicationVenuePosition
2025 Detecting DBMS bugs with context-sensitive instantiation and multi-plan execution
Jiaqi Li 0023, Ke Wang 0042, Yaoguang Chen, Yajin Zhou, Lei Wu 0012, Jiashui Wang
Comput. Secur.1
2025 Improving Multitasking DBMS Fuzzing With More Accurate Coverage and Testcase Trimming
abstract
Coverage-guided fuzzing is prevalent in detecting DBMS (Database Management System) bugs. However, current coverage-guided DBMS fuzzers suffer from two limitations that prevent fuzzers from discovering bugs efficiently. First, the coverage feedback is imprecise which prevents fuzzers from making optimal decisions on fuzzing strategies. Second, DBMS fuzzers lack testcase trimming to control the increasing input sizes. The large input size makes DBMS execution slower and reduces the likelihood that a mutation would touch important structures. In this paper, we proposed corresponding methods to overcome these limitations. Specifically, the work-task coverage tracking and unstable edge filtering improve the coverage accuracy with low instrumentation overhead. Based on more accurate coverage, we further propose testcase trimming to improve the speed of bug detection. We implemented a prototype named Tuzz and evaluated it on three popular DBMSs. The evaluation result shows that Tuzz explores 16.3%, 26.1%, and 26.6% more edges than the state-of-the-art fuzzer in PostgreSQL, MySQL, and MariaDB, respectively. More importantly, Tuzz has discovered 10 and 4 previously unknown bugs in MySQL and MariaDB.
Jiaqi Li 0023, Yajin Zhou, Lei Wu 0012
IEEE Trans. Dependable Secur. Comput.1
2022 OPEC: operation-based security isolation for bare-metal embedded systems
abstract
Bare-metal embedded systems usually lack security isolation. Attackers can subvert the whole system with a single vulnerability. Previous research intends to enforce both privilege isolation (to run application code at the unprivileged level) and resource isolation for global variables and peripherals. However, it suffers from partition-time and execution-time over-privilege issues, due to the limited hardware resources (MPU regions) and the improper way to partition a program.
Jiaqi Li 0023, Yajin Zhou, Wenbo Shen, Kui Ren 0001
EuroSys2
2022 SGXLock: Towards Efficiently Establishing Mutual Distrust Between Host Application and Enclave for SGX
Jiaqi Li 0023, Guorui Xu, Yajin Zhou, Zhi Wang 0004, Cong Wang 0001, Kui Ren 0001
USENIX Security Symposium2
2022 Scriptable and composable SNARKs in the trusted hardware model
abstract
Non-interactive zero-knowledge proof or argument (NIZK) systems are widely used in many security sensitive applications to enhance computation integrity, privacy and scalability. In such systems, a prover wants to convince one or more verifiers that the result of a public function is correctly computed without revealing the (potential) private input, such as the witness. In this work, we introduce a new notion, called scriptable SNARK, where the prover and verifier(s) can specify the function (or language instance) to be proven via a script. We formalize this notion in UC framework and provide a generic trusted hardware based solution. We then instantiate our solution in both SGX and Trustzone with Lua script engine. The system can be easily used by typical programmers without any cryptographic background. The benchmark result shows that our solution is better than all the known SNARK proof systems w.r.t. prover’s running time (1000 times faster), verifier’s running time, and the proof size. In addition, we also give a lightweight scriptable SNARK protocol for hardware with limited state, e.g., Θ ( λ ) bits. Finally, we show how the proposed scriptable SNARK can be readily deployed to solve many well-known problems in the blockchain context, e.g. verifier’s dilemma, fast joining for new players, etc.
Zhelei Zhou, Bingsheng Zhang, Jiaqi Li 0023, Yajin Zhou, Yibiao Lu, Kui Ren 0001, Phuc Thai, Hong-Sheng Zhou
J. Comput. Secur.4
2021 Succinct Scriptable NIZK via Trusted Hardware
Bingsheng Zhang, Jiaqi Li 0023, Yajin Zhou, Phuc Thai, Hong-Sheng Zhou, Kui Ren 0001
ESORICS (1)3
2020 HybrIDX: New Hybrid Index for Volume-hiding Range Queries in Data Outsourcing Services
abstract
An encrypted index is a data structure that assisting untrusted servers to provide various query functionalities in the ciphertext domain. Although traditional index designs can prevent servers from directly obtaining plaintexts, the confidentiality of outsourced data could still be compromised by observing the volume of different queries. Recent volume attacks have demonstrated the importance of sealing volume-pattern leakage. To this end, several works are made to design secure indexes with the volume-hiding property. However, prior designs only work for encrypted keyword search. Due to the unpredictable range query results, it is difficult to protect the volume-pattern leakage while achieving efficient range queries.In this paper, for the first time, we define and solve the challenging problem of volume-hiding range queries over encrypted data. Our proposed hybrid index framework, called HybrIDX, allows an untrusted server to efficiently search encrypted data based on order conditions without revealing the exact volume size. It resorts to the trusted hardware techniques to assist range query processing by moving the comparison algorithm to trusted SGX enclaves. To enable volume-hiding data retrieval, we propose to host encrypted results outside the enclave in an encrypted multimaps manner. Apart from this novel hybrid index design, we further customize a bulk refresh mechanism to enable accesspattern obfuscation. We formally analyze the security strengths and complete the prototype implementation. Evaluation results demonstrate the feasibility and practicability of our designs.
Kui Ren 0001, Yu Guo 0003, Jiaqi Li 0023, Xiaohua Jia, Cong Wang 0001, Yajin Zhou, Sheng Wang 0011, Ning Cao 0001, Feifei Li 0001
ICDCS3