Xinhui Shao

dblp:12/5975 · DBLP profile ↗
← Back
13ranked-venue papers
2as first author
12since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 5 since 2021Computer networks · 3 · 2 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 UIEE: Secure and Efficient User-space Isolated Execution Environment for Embedded TEE Systems
Huaiyu Yan, Zhen Ling 0001, Xuandong Chen, Xinhui Shao, Yier Jin, Ming Yang 0001, Junzhou Luo
NDSS4
2026 Toward Secure and Efficient Driver Support for Embedded TEE Systems
abstract
Trusted execution environments (TEEs), like TrustZone, are pervasively employed to protect security sensitive programs and data from various attacks issued by untrusted rich execution environments (REEs) while they execute compact TEE operating systems which implement minimum security-critical operations but have poor device driver support. In this paper, we propose a twin driver approach where a pair of TEE and REE drivers is generated and cooperate to enable secure and efficient TEE driver support. To begin with, we propose a driver data flow analysis framework named driver analyzer (DrvAna) to automatically analyze the shared states between the TEE and REE driver where a novel data structure named value-type tree is investigated to facilitate field-sensitive data flow analysis upon the driver state. Furthermore, in order to maintain a minimal trusted computing base, we propose a Linux driver runtime (LDR) inside the TEE, a sandbox environment that confines the TEE driver based on the ARM domain access control features and mediates the driver's interaction with the TEE. We implement a DrvAna prototype based on LLVM as well as an LDR prototype on an NXP IMX6Q SABRE-SD evaluation board, adapt 6 existing Linux drivers into LDR, and evaluate their performance. The experimental results show that the LDR drivers can achieve comparable performance with their Linux counterparts with negligible overheads.
Huaiyu Yan, Zhen Ling 0001, Xinhui Shao, Ming Yang 0001, Junzhou Luo, Xinwen Fu
IEEE Trans. Dependable Secur. Comput.3
2025 The Cost of Performance: Breaking ThreadX with Kernel Object Masquerading Attacks
Xinhui Shao, Zhen Ling 0001, Yue Zhang 0025, Huaiyu Yan, Yumeng Wei, Zixia Liu, Junzhou Luo, Xinwen Fu
USENIX Security Symposium1
2025 NRAFN: a non-text reinforcement and adaptive fusion network for multimodal sentiment analysis
Jinlong Wei, Xinhui Shao
Multim. Tools Appl.2
2024 LDR: Secure and Efficient Linux Driver Runtime for Embedded TEE Systems
Huaiyu Yan, Zhen Ling 0001, Xinhui Shao, Kai Dong 0001, Ming Yang 0001, Junzhou Luo, Xinwen Fu
NDSS5
2024 A cross-model hierarchical interactive fusion network for end-to-end multimodal aspect-based sentiment analysis
abstract
For the aspect-based sentiment analysis task, traditional works are only for text modality. However, in social media scenarios, texts often contain abbreviations, clerical errors, or grammatical errors, which invalidate traditional methods. In this study, the cross-model hierarchical interactive fusion network incorporating an end-to-end approach is proposed to address this challenge. In the network, a feature attention module and a feature fusion module are proposed to obtain the multimodal interaction feature between the image modality and the text modality. Through the attention mechanism and gated fusion mechanism, these two modules realize the auxiliary function of image in the text-based aspect-based sentiment analysis task. Meanwhile, a boundary auxiliary module is used to explore the dependencies between two core subtasks of the aspect-based sentiment analysis. Experimental results on two publicly available multi-modal aspect-based sentiment datasets validate the effectiveness of the proposed approach.
Xinhui Shao
Intell. Data Anal.2
2024 Biomedical document-level relation extraction with thematic capture and localized entity pooling
Xinhui Shao
J. Biomed. Informatics2
2024 MATF: main-auxiliary transformer fusion for multi-modal sentiment analysis
Xinhui Shao
Soft Comput.2
2022 fASLR: Function-Based ASLR for Resource-Constrained IoT Systems
Xinhui Shao, Zhen Ling 0001, Huaiyu Yan, Yumeng Wei, Xinwen Fu
ESORICS (2)1
2022 fASLR: Function-Based ASLR via TrustZone-M and MPU for Resource-Constrained IoT Systems
abstract
The address space layout randomization (ASLR) has been widely deployed on modern operating systems against code reuse attacks (CRAs), such as return-oriented programming (ROP) and jump-oriented programming (JOP). However, porting ASLR to resource-constrained IoT devices is a great challenge due to the limited memory space for randomization. We propose a function-based ASLR scheme (fASLR) for IoT runtime security utilizing the ARM TrustZone-M technology and the memory protection unit (MPU) supported by ARM Cortex-M processors. fASLR loads a function from the flash and randomizes its base address in a randomization region in RAM when the function is being called. We design novel mechanisms on cleaning up finished functions from the RAM and memory addressing to tackle the complexity of function relocation and randomization. Optimizations are applied to effectively reduce overhead introduced by runtime memory management. We also formally prove that user applications will run correctly with fASLR enabled. Compared with the related work, a prominent advantage of fASLR is that fASLR can run an application even if the application code cannot be completely loaded into RAM for execution. We test fASLR with 21 applications. The experimental results show that fASLR achieves a high randomization entropy and incurs a runtime overhead of less than 10%.
Xinhui Shao, Zhen Ling 0001, Huaiyu Yan, Yumeng Wei, Xinwen Fu
IEEE Internet Things J.2
2022 On Security of TrustZone-M-Based IoT Systems
abstract
Internet of Things (IoT) devices have been increasingly integrated into our daily life. However, such smart devices suffer a broad attack surface. Particularly, attacks targeting the device software at runtime are challenging to defend against if IoT devices use resource-constrained microcontrollers (MCUs). TrustZone-M, a TrustZone extension designed specifically for MCUs, is an emerging hardware security technique fortifying software security of MCU-based IoT devices. This article introduces a comprehensive security framework for IoT devices using TrustZone-M-enabled MCUs, in which device security is protected in five dimensions, i.e., hardware, boot-time software, runtime software, network, and over-the-air (OTA) update. Along developing the framework, we also present the first security analysis of potential runtime software security issues in TrustZone-M-enabled MCUs. In particular, we explore the feasibility of launching stack-based buffer overflow (BOF) attack for code injection, return-oriented programming (ROP) attack, heap-based BOF attack, format string attack, and attacks against nonsecure callable (NSC) functions in the context of TrustZone-M. We validate these attacks using SAM L11, a microchip MCU with TrustZone-M and provide defense mechanisms in the runtime software dimension of the proposed framework. The security framework is implemented with a full-fledged secure and trustworthy air quality monitoring device using SAM L11 as its MCU.
Yue Zhang 0025, Clayton White, Brandon Keating, Bryan Pearson, Xinhui Shao, Zhen Ling 0001, Haofei Yu, Cliff C. Zou, Xinwen Fu
IEEE Internet Things J.6
2021 Secure boot, trusted boot and remote attestation for ARM TrustZone-based IoT Nodes
Zhen Ling 0001, Huaiyu Yan, Xinhui Shao, Junzhou Luo, Yiling Xu, Bryan Pearson, Xinwen Fu
J. Syst. Archit.3
2020 On Runtime Software Security of TrustZone-M Based IoT Devices
abstract
Internet of Things (IoT) devices have been increasingly integrated into our daily life. However, such smart devices suffer a broad attack surface. Particularly, attacks targeting the device software at runtime are challenging to defend against if IoT devices use resource-constrained microcontrollers (MCUs). TrustZone-M, a TrustZone extension for MCUs, is an emerging security technique fortifying MCU based IoT devices. This paper presents the first security analysis of potential software security issues in TrustZone-M enabled MCUs. We explore the stack-based buffer overflow (BOF) attack for code injection, return-oriented programming (ROP) attack, heap-based BOF attack, format string attack, and attacks against Non-secure Callable (NSC) functions in the context of TrustZone-M. We validate these attacks using the Microchip SAM L11 MCU, which uses the ARM Cortex-M23 processor with the TrustZone-M technology. Strategies to mitigate these software attacks are also discussed.
Yue Zhang 0025, Cliff C. Zou, Xinhui Shao, Zhen Ling 0001, Xinwen Fu
GLOBECOM4