Chengyan Ma 0001

dblp:133/4489-1 · DBLP profile ↗
← Back
11ranked-venue papers
3as first author
10since 2021 · last 2026
0000-0001-9256-6930ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 3 · 2 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Security and privacy · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Shielding MCP Tool: A Secure Execution Framework Using TEE and Automated Trimming
Ruidong Han, Chengyan Ma 0001, Ye Liu 0012, Yuqing Niu, David Lo 0001
ACISP (1)2
2026 What You Trust is Insecure: Demystifying How Developers (Mis)Use Trusted Execution Environments in Practice
Yuqing Niu, Jieke Shi, Ruidong Han, Ye Liu 0012, Chengyan Ma 0001, Yunbo Lyu, David Lo 0001
SANER5
2026 Automated TEE Adaptation With LLMs: Identifying, Transforming, and Porting Sensitive Functions in Programs
Ruidong Han, Zhou Yang 0003, Chengyan Ma 0001, Ye Liu 0012, Yuqing Niu, Siqi Ma 0001, Debin Gao, David Lo 0001
IEEE Trans. Software Eng.3
2026 Towards Secure Program Partitioning for Smart Contracts With LLM's In-Context Learning
abstract
Smart contracts are highly susceptible to manipulation attacks due to the leakage of sensitive information. Addressing manipulation vulnerabilities is particularly challenging because they stem from inherent data confidentiality issues rather than straightforward implementation bugs. To tackle this by preventing sensitive information leakage, we present PARTITIONGPT, the first LLM-driven approach that combines static analysis with the in-context learning capabilities of large language models (LLMs) to partition smart contracts into critical (privileged) and normal codebases, guided by a few annotated sensitive data variables. We evaluated PARTITIONGPT on 18 annotated smart contracts containing 99 sensitive functions. The results demonstrate that PARTITIONGPT successfully generatescompilable, andverifiedpartitions, achieving a precision of 80% while reducing more than 26% code compared to functionlevel partitioning approach. Furthermore, we evaluated PARTITIONGPT on nine real-world manipulation attacks that led to a total loss of 25 million dollars, PARTITIONGPT effectively prevents eight cases, highlighting its potential for broad applicability and the necessity for secure program partitioning during smart contract development to diminish manipulation vulnerabilities.
Ye Liu 0012, Yuqing Niu, Chengyan Ma 0001, Ruidong Han, Wei Ma 0014, Yi Li 0008, Debin Gao, David Lo 0001
IEEE Trans. Software Eng.3
2025 BiTDB: Constructing A Built-in TEE Secure Database for Embedded Systems (Extended Abstract)
abstract
In this paper, we propose BiTDB, a built-in Trusted Execution Environment (TEE) database for embedded systems, to realize higher system availability while ensuring data confidentiality. With BiTDB, dilemmas that the state-of-the-art research work on secure embedded databases has to face can be significantly reduced and eliminated, including (i) complicated research and realization on searchable encryption algorithms (SEA), (ii) limited support to all database operations, and (iii) almost none of specific design and optimizations toward built-in TEE embedded databases. Through BiTDB, all database operations can process plaintext in TEE instead of retrieving ciphertext by developing complicated SEAs. To enable BiTDB to handle database files in Rich Execution Environment (REE) as local ones, we extend the TEE OS with generic file I/O libraries. Then, we contribute three critical optimizations to significantly reduce redundant memory and file operations between TEE and REE, and BiTDB achieve better system performance and availability in embedded systems. Finally, we have implemented the prototype system based on OP-TEE and SQLite for several typical platforms, including virtualization and hardware environments. The TPC-H test shows BiTDB can achieve 85% (on average) of the original database performance while guaranteeing data confidentiality and integrity.
Chengyan Ma 0001, Di Lu 0001, Chaoyue Lv, Ning Xi 0002, Xiaohong Jiang 0001, Yulong Shen 0001, Jianfeng Ma 0001
ICDE1
2025 FC-TEE: Lightweight Trusted Execution Environment for Low-Cost UAV Flight Control Systems
abstract
Unmanned Aerial Vehicle (UAV) flight control systems are increasingly exposed to software-level security threats. However, existing Trusted Execution Environment (TEE) technologies that can effectively defend against software attacks are difficult to deploy on the low-cost UAVs due to: (1) the lack of onboard security hardware, (2) limited Memory Protection Unit (MPU) resources, and (3) strict real-time requirements. To address these issues, we design FC-TEE, a lightweight TEE framework tailored for low-cost UAV platforms, which integrates fine-grained memory isolation and a multi-level task scheduling strategy. By analyzing the flight control code and control principles, we provide three key attributes (task priority, maximum invocation frequency, and required argument types) of flight control tasks and classify these tasks into two categories (privileged tasks and common tasks) based on the attributes. Then, we run the privileged tasks in FC-TEE to achieve memory isolation from common tasks, protecting the privileged tasks from software attacks. Meanwhile, we design multi-level task scheduling based on the task priority and categories to ensure the real-time requirements of the flight control system. Compared with existing UAV protection solutions such as MINION and TrustZone-based RT-TEE, the average additional execution overhead introduced by FC-TEE only is 2.7%. We prototype FC-TEE on a real quadrotor platform and validate its effectiveness through task-level performance and security evaluations.
Peixue Lu, Ning Xi 0002, Chengyan Ma 0001, Qin Wang 0008, Di Lu 0001, Chuang Tian 0001, Jianfeng Ma 0001
IEEE Internet Things J.3
2024 CToMP: a cycle-task-oriented memory protection scheme for unmanned systems
Chengyan Ma 0001, Ning Xi 0002, Di Lu 0001, Yebo Feng, Jianfeng Ma 0001
Sci. China Inf. Sci.1
2024 Provably and Physically Secure UAV-Assisted Authentication Protocol for IoT Devices in Unattended Settings
abstract
As the core subject of IoT applications, IoT devices have faced numerous security challenges. Especially for IoT devices deployed in remote or harsh environments, they are often unattended for long periods, making it difficult to share the sensing data and susceptible to potential physical attacks. While aerial assistance methods represented by unmanned aerial vehicles (UAVs) can solve the problem of data sharing at a low cost, it is necessary to establish a secure channel between ground control stations, UAVs, and IoT devices due to the sensitivity of the sensing data. Recently, Physical Unclonable Function (PUF) has been proven to provide unique identity identification for devices using its tamper-proof feature. In this paper, we propose a lightweight UAV-assisted authentication and key agreement protocol for unattended IoT devices, ensuring secure communication and physical tamper-proof requirements. However, our work does not stop there. We noticed that some existing PUF-based authentication schemes misunderstand the ability of PUF, which leads to these schemes cannot actually provide physical protection. We analyzed the security vulnerabilities of these schemes and proposed rules that should be followed when designing authentication protocols using PUF. In addition, for the first time, we put forward the formal definitions and proof methods for PUF in the formal proof of the security protocol, which avoided the unreasonable initial assumptions adopted in the proof of the existing schemes. We extended Mao-Boyd (MB) logic and comprehensively analyzed the proposed protocol. We also evaluate the performance of the proposed scheme, and the results show that the proposed scheme has certain advantages in communication and computation overhead compared with existing schemes.
Chuang Tian 0001, Jianfeng Ma 0001, Teng Li 0003, Junwei Zhang 0008, Chengyan Ma 0001, Ning Xi 0002
IEEE Trans. Inf. Forensics Secur.5
2024 BiTDB: Constructing A Built-in TEE Secure Database for Embedded Systems
abstract
In this paper, we propose BiTDB, a built-in Trusted Execution Environment (TEE) database for embedded systems, to realize higher system availability while ensuring data confidentiality. With BiTDB, dilemmas that the state-of-the-art research work on secure embedded databases has to face can be significantly reduced and eliminated, including (i) complicated research and realization on searchable encryption algorithms (SEA), (ii) limited support to all database operations, and (iii) almost none of specific design and optimizations toward build-in TEE embedded databases. Through BiTDB, all database operations can process plaintext in TEE instead of retrieving ciphertext by developing complicated SEAs. To enable BiTDB to handle database files in Rich Execution Environment (REE) as local ones, we extend the TEE OS with generic file I/O libraries. Then, we contribute three critical optimizations to significantly reduce redundant memory and file operations between TEE and REE, and BiTDB achieve better system performance and availability in embedded systems. Finally, we have implemented the prototype system based on OP-TEE and SQLite for several typical platforms, including virtualization and hardware environments. The TPC-H test shows BiTDB can achieve 85% (on average) of the original database performance while guaranteeing data confidentiality and integrity. Our project repository is athttps://github.com/CharlieMCY/BiTDB.
Chengyan Ma 0001, Di Lu 0001, Chaoyue Lv, Ning Xi 0002, Xiaohong Jiang 0001, Yulong Shen 0001, Jianfeng Ma 0001
IEEE Trans. Knowl. Data Eng.1
2022 I Can Still Observe You: Flow-level Behavior Fingerprinting for Online Social Network
abstract
The privacy of online social networks (OSNs) remains a major concern for today's Internet. Researchers have demonstrated that by analyzing inter-packet or packet-level network traffic, a third-party analyzer is able to fingerprint a user's OSN behavior information even when the traffic is encrypted. In this paper, we propose a learning-based approach that steps further to perform OSN behavior fingerprinting only through highly compressed, flow-level network traffic (e.g., NetFlow). By preprocessing flow records, segmenting traffic flows into bursts, and leveraging a long short-term memory network to classify the bursts, our approach can identify major OSN behaviors (e.g., Facebook post, Twitter Read, Weibo video, etc.) with nearly 90% accuracy. Compared with packet-level fingerprinting approaches, our approach significantly improves the fingerprinting efficiency in evaluations, making large-scale OSN usage monitoring feasible only with limited computing resources and coarse-grained network traffic. This work also reveals the huge risks facing privacy of OSN users on today's Internet today.
Yebo Feng, Jian-Zhen Luo, Chengyan Ma 0001, Teng Li 0003, Liang Hui
GLOBECOM3
2019 Privacy-Preserving Verification and Root-Cause Tracing Towards UAV Social Networks
abstract
Unmanned Aerial Vehicles (UAV) have rapidly developed and been widely applied to military and civilian applications in recent years. Anomaly Detections and finding out the root causes are critically important for UAV social network security. In the UAV social networks, the drone can communicate with one another directly in a form of leading flights with followers during a far away mission. The ground controller cannot get their information directly. Besides, none of the works consider the privacy protection and anomaly root cause tracing during the distributed detection. This paper presents a self-verification approach among UAV flights which can check whether the flights have honestly obeyed the orders or suffered the anomalies. Besides, we do the verification without looking through the plaintext records or data of the drones. Finally, to instruct the drones to solve the problems, we trace the fundamental root causes leading to the anomalies by learning the fault tree. We apply our approach on raw UAV social network data and align our experiment with two former works as baselines for comparison. Our approach can reduce the time cost of verification from exponential growth to linear growth and improve the tracing accuracy rate around 4.3% higher than the former work.
Teng Li 0003, Jianfeng Ma 0001, Qingqi Pei, Chengyan Ma 0001, Dawei Wei, Cong Sun 0001
ICC4