VLDB 2026 Research / reviewers in the wild / expert
Zhihao Yao 0001
dblp:154/8284-1 · also Zhihao Zephyr Yao
· DBLP profile ↗
11ranked-venue papers
4as first author
9since 2021 · last 2026
0000-0001-9842-0713ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 1 first-author · 3 since 2021Computer networks · 3 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Trustworthy Data Paths for Sensitive Smartphone Workloads
Zhihao Yao 0001 |
MDM | 1 |
| 2025 | PyPitfall: Dependency Chaos and Software Supply Chain Vulnerabilities in Python
Jacob Mahon, Chenxi Hou, Zhihao Yao 0001 |
IEEE Big Data | 3 |
| 2025 | PACE: Policy Adaptation for Cybersecurity Events Through Formal Verification of LLM-Generated Firewall Policies
Mahya Samdaliri, Zhihao Yao 0001 |
IEEE Big Data | 2 |
| 2025 | NUSGuard: Smart Device Anti-Eavesdropping Protection Based on Near-Ultrasonic InterferenceabstractVoice assistants (VAs) have become ubiquitous in smart devices, and are highly valued for their ability to perform a variety of tasks through voice interaction, offering users hands-free convenience. However, the always-on microphones of VAs have raised significant privacy concerns in recent years. In this paper, we propose and implement NUSGuard, a novel and practical anti-eavesdropping system. To our knowledge, it is the first system to utilize the built-in speakers of commercial off-the-shelf (COTS) devices for anti-eavesdropping, thereby eliminating the need for dedicated ultrasonic transmitters. Specifically, it exploits human ears’ insensitivity to near-ultrasonic signals and the inherent non-linearity of mic to inject jamming noises into the microphones of unauthorized smart devices. Furthermore, we propose a robust mixed-noise scheme and a lexical-level automatic jammer control strategy, effectively disrupting unauthorized recordings while maintaining seamless voice interaction with authorized VA devices. Extensive digital and real-world experiments have demonstrated NUSGuard’s superior performance in terms of jamming effectiveness and security. Xiaoxiao Qiao, Man Zhou 0004, Hongwei Li 0001, Zhihao Yao 0001, Xiaojing Ma 0002 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | ProvCam: A Camera Module with Self-Contained TCB for Producing Verifiable VideosabstractOur perception of reality is under constant threat from ever-improving video manipulation techniques, including deep-fakes and generative AI. Therefore, proving authenticity of videos is increasingly important, especially in legal and news contexts. However, it is very challenging to prove it based on post-factum video content analysis. Yuxin (Myles) Liu, Zhihao Yao 0001, Ardalan Amiri Sani, Sharad Agarwal, Gene Tsudik |
MobiCom | 2 |
| 2024 | Poster: StreamGuard: Enabling Secure and Uncensored Video Calls on Mobile DevicesabstractWith the increasing use of application-based video calls, the security and privacy of video and audio data have become a major concern. Despite the use of encryption, applications that implement the encryption can still access the content of video calls for eavesdropping, censorship, and data mining. To address this issue, we propose a lightweight system service solution, StreamGuard, to provide End-to-End Encryption (E2EE) at mobile system level, effectively blocking applications from accessing unencrypted data. StreamGuard uses the Signal Protocol for key exchange, and AES for encryption. Additionally, StreamGuard's novel architecture supports video preview and editing while maintaining the confidentiality of data. Our preliminary results show that StreamGuard is feasible with minimal performance overhead. Chenxi Hou, Zhihao Yao 0001 |
MobiSys | 2 |
| 2023 | Minimizing a Smartphone's TCB for Security-Critical Programs with Exclusively-Used, Physically-Isolated, Statically-Partitioned HardwareabstractSmartphone owners often need to run security-critical programs on the same device as other untrusted and potentially malicious programs. This requires users to trust hardware and system software to correctly sandbox malicious programs, trust that is often misplaced. Our goal is to minimize the number and complexity of hardware and software components that a smartphone owner needs to trust. We present a split-trust hardware design composed of statically-partitioned, physically-isolated trust domains. We introduce a few simple, formally-verified hardware components to enable a program to gain provably exclusive and simultaneous access to both computation and I/O on a temporary basis. To manage this hardware, we present OctopOS, an OS composed of mutually distrustful subsystems. We present a prototype of this machine (hardware and OS) on a CPU-FPGA board and show that it incurs a small hardware cost compared to modern smartphone SoCs. For security-critical programs, we show that this machine significantly reduces the required trust compared to mainstream TEEs while achieving usable performance. For normal programs, performance is similar to a legacy machine. Zhihao Yao 0001, Seyed Mohammadjavad Seyed Talebi, Ardalan Amiri Sani, Thomas E. Anderson |
MobiSys | 1 |
| 2023 | GLeeFuzz: Fuzzing WebGL Through Error Message Guided Mutation
Zhihao Yao 0001, Ardalan Amiri Sani, Jing (Dave) Tian, Mathias Payer |
USENIX Security Symposium | 2 |
| 2021 | Undo Workarounds for Kernel Bugs
Seyed Mohammadjavad Seyed Talebi, Zhihao Yao 0001, Ardalan Amiri Sani, Zhiyun Qian, Daniel Austin |
USENIX Security Symposium | 2 |
| 2018 | Sugar: Secure GPU Acceleration in Web BrowsersabstractModern personal computers have embraced increasingly powerful Graphics Processing Units (GPUs). Recently, GPU-based graphics acceleration in web apps (i.e., applications running inside a web browser) has become popular. WebGL is the main effort to provide OpenGL-like graphics for web apps and it is currently used in 53% of the top-100 websites. Unfortunately, WebGL has posed serious security concerns as several attack vectors have been demonstrated through WebGL. Web browsers» solutions to these attacks have been reactive: discovered vulnerabilities have been patched and new runtime security checks have been added. Unfortunately, this approach leaves the system vulnerable to zero-day vulnerability exploits, especially given the large size of the Trusted Computing Base of the graphics plane. We present Sugar, a novel operating system solution that enhances the security of GPU acceleration for web apps by design. The key idea behind Sugar is using a dedicated virtual graphics plane for a web app by leveraging modern GPU virtualization solutions. A virtual graphics plane consists of a dedicated virtual GPU (or vGPU) as well as all the software graphics stack (including the device driver). Sugar enhances the system security since a virtual graphics plane is fully isolated from the rest of the system. Despite GPU virtualization overhead, we show that Sugar achieves high performance. Moreover, unlike current systems, Sugar is able to use two underlying physical GPUs, when available, to co-render the User Interface (UI): one GPU is used to provide virtual graphics planes for web apps and the other to provide the primary graphics plane for the rest of the system. Such a design not only provides strong security guarantees, it also provides enhanced performance isolation. Zhihao Yao 0001, Zongheng Ma, Yingtong Liu, Ardalan Amiri Sani, Aparna Chandramowlishwaran |
ASPLOS | 1 |
| 2018 | Milkomeda: Safeguarding the Mobile GPU Interface Using WebGL Security ChecksabstractGPU-accelerated graphics is commonly used in mobile applications. Unfortunately, the graphics interface exposes a large amount of potentially vulnerable kernel code (i.e., the GPU device driver) to untrusted applications. This broad attack surface has resulted in numerous reported vulnerabilities that are exploitable from unprivileged mobile apps. We observe that web browsers have faced and addressed the exact same problem in WebGL, a framework used by web apps for graphics acceleration. Web browser vendors have developed and deployed a plethora of security checks for the WebGL interface. We introduce Milkomeda, a system solution for automatically repurposing WebGL security checks to safeguard the mobile graphics interface. We show that these checks can be used with minimal modifications (which we have automated using a tool called CheckGen), significantly reducing the engineering effort. Moreover, we demonstrate an in-process shield space for deploying these checks for mobile applications. Compared to the multi-process architecture used by web browsers to protect the integrity of the security checks, our solution improves the graphics performance by eliminating the need for Inter-Process Communication and shared memory data transfer, while providing integrity guarantees for the evaluation of security checks. Our evaluation shows that Milkomeda achieves close-to-native GPU performance at reasonably increased CPU utilization. Zhihao Yao 0001, Saeed Mirzamohammadi, Ardalan Amiri Sani, Mathias Payer |
CCS | 1 |