VLDB 2026 Research / reviewers in the wild / expert
Jinhua Cui 0002
dblp:156/2428-2
· DBLP profile ↗
12ranked-venue papers
5as first author
10since 2021 · last 2026
0000-0001-5716-4995ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 7 · 3 first-author · 6 since 2021Security and privacy · 4 · 2 first-author · 3 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MUXLeak: Exploiting Multiplexers as a Power Side Channel Against Multitenant FPGAsabstractFPGA cloud acceleration, or “FPGA as a Service” (FaaS), offered by AWS, Microsoft Azure, Alibaba Cloud, and Huawei Cloud, has become a promising solution for tackling complex, compute-intensive workloads. It targets applications such as genomics, image and video processing, electronic design automation, compression, and big data analytics. While multi-tenant FPGAs significantly enhances resource utilization efficiency, it faces security threats from power side channels, where attackers craft a malicious circuit to detect voltage fluctuations from victim circuits. Observing that all the crafted circuits exploit either Carry Chain or Look-up Table to sense voltage fluctuations, existing defenses have focused on detecting the malicious use of the two basic FPGA computing resources. However, it remains unclear whether such countermeasures are sufficient to address the growing threat of power side channels in multi-tenant FPGAs. In this paper, we reveal MUXLeak, a novel on-chip sensor that exploitsMultiplexer (MUX)to craft a stealthy power side channel, which bypasses existing countermeasures. Particularly, we perform a thorough analysis of basic resources within an FPGA unit and unveil thatMUX, another basic resource,has never been exploited before. More importantly, it can be directly initialized on Xilinx FPGAs and its incurred signal propagation delay demonstrates an inverse correlation with changes in voltage, making itself exploitable for a new power side channel leakage. In our evaluation, we test MUXLeak on three Xilinx FPGA products and use TDC [18] (i.e., the most sensitive on-chip sensor until now) to benchmark the sensitivity of MUXLeak. Our results show that MUXLeak has achieved the same level of sensitivity as TDC to voltage fluctuations. Further, we apply MUXLeak to mount two attacks, i.e., extracting AES keys within 2.54 hours and stealing DNN model architectures with an accuracy of over 90%. Xin Zhang 0110, Zhi Zhang 0001, Qingni Shen, Yansong Gao 0001, Jinhua Cui 0002, Yusi Feng, Zhonghai Wu, Derek Abbott |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 6 |
| 2025 | IntraFuzz: Coverage-Guided Intra-Enclave Fuzzing for Intel SGX ApplicationsabstractIntel SGX is susceptible to intra-enclave software vulnerabilities. Existing automated bug-finding methods primarily focus on fuzzing enclave boundaries for SGX applications in simulated, rather than actual hardware-protected enclaves. This limits the ability to identify potential security violations originating from within SGX application code. This paper presents IntraFuzz, the first system that enables efficient fuzzing of SGX applications inside actual hardware enclaves. We evaluated IntraFUZZ with 21 real-world SGX applications, running on Intel Xeon scalable processors with up to 256 GB of enclave page cache. IntraFuzz successfully detected all vulnerabilities in SGX application code previously identified by the state-of-the-art tool EnclaveFuzz, as well as 6 previously undiscovered vulnerabilities. These results highlight the importance of hardware-based fuzzing in securing SGX applications. Jinhua Cui 0002, Yiwen Yao, Ke Ye, Jiliang Zhang 0002 |
DAC | 1 |
| 2024 | CPU Address-Leakage Transient Execution Attack Detection and Its CountermeasuresabstractModern advanced CPU designs are frequently exposed to transient execution vulnerabilities, which allow attackers to harness microarchitectural side effects for data exfiltration. The leaked data may encompass direct target data, such as RSA keys, or indirect information, like physical page mappings. Thus, transient execution attacks can be divided into data-leakage and address-leakage, depending on the specific targets that are exposed. Existing studies have developed practical defenses and detection mechanisms against the microarchitectural attacks. However, almost all of them focus solely on data leakage and are thus unable to detect and counter address-leakage attacks, like Spoiler, due to their unique mechanisms. This paper introduces AALERT, the first detection mechanism specifically designed for address-leakage transient execution attacks. AALERT integrates a Cuckoo filter module within the CPUs Memory Order Buffer (MOB) to screen buffered addresses on the fly. We further optimize the filtering algorithm to minimize false positives. We discuss and implement several countermeasures to defeat the detected attacks. Finally, we evaluate the effectiveness and performance of AALERT based on prototype implementations, demonstrating a detection rate of 99.99% with negligible performance overhead. Yiyun Yin, Jinhua Cui 0002, Jiliang Zhang 0002 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2024 | Write+Sync: Software Cache Write Covert Channels Exploiting Memory-Disk SynchronizationabstractMemory-disk synchronization is a critical technology for ensuring data correctness, integrity, and security, especially in systems that handle sensitive information like financial transactions and medical records. We propose Write+Sync, a group of attacks that exploit the memory-disk synchronization primitives. Write+Sync works by subtly varying the timing of synchronization on a software cache (i.e., the write buffer), offering two advantages: 1) implemented purely in software, enabling deployment on any hardware devices; 2) resilient against existing countermeasures. We present the principles of Write+Sync through the implementation of two write covert channel protocols, using either a single file or page, and introduce three enhanced strategies that utilize multiple files and pages. The feasibility of these channels is demonstrated in both cross-process and cross-sandbox scenarios across diverse operating systems (OSes). Experimental results show that, the average rate can reach 2.036 Kb/s (with a peak rate of 14.762 Kb/s) and the error rate is 0% on Linux; when running on macOS, the average rate achieves 10.211 Kb/s (with a peak rate of 253.022 Kb/s) and the error rate is 0.004%. To show its security implications, we evaluate it using two case studies-website fingerprinting and performance degradation attacks. To the best of our knowledge, Write+Sync is the first high-speed write covert channel for software cache. Jinhua Cui 0002, Gang Qu 0001, Jiliang Zhang 0002 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | A Comparison Study of the Compatibility Approaches for SGX EnclavesabstractConfidential computing technologies, such as that enabled by Intel SGX (Software Guard eXtensions), have been widely deployed in various commercial cloud platforms. Specifically, SGX uses hardware-isolated compartments named enclaves to shield user applications from Operating Systems (OSes) and hypervisors, thus providing confidentiality and integrity guarantees for code and data. However, some crucial problems are not fully analyzed yet, especially for the compatibility with binary applications. This work first delivers an overview of Intel SGX and reviews its five design constraints that may affect compatibility. Subsequently, we revisit three distinct compatibility solutions from the internals and analyze their impact on security, performance, and flexibility. At last, we lay out some fundamental lessons learned from prior SGX studies. Jinhua Cui 0002, Yiyun Yin, Zhiping Cai, Jiliang Zhang 0002 |
ATS | 1 |
| 2023 | Spoiler-Alert: Detecting Spoiler Attacks Using a Cuckoo FilterabstractSpoiler attacks leak physical address information, which is exploited to accelerate reverse engineering of virtual-to-physical address mapping, thus greatly boosting Rowhammer and cache attacks. However, existing approaches that detect data-leakage attacks no longer suit the requirements of identifying Spoiler. This paper proposes Spoiler-alert,the first hardware-level mechanism to detect the address-leakage Spoiler attacks in real time. It leverages a cuckoo filter module embedded into Memory Order Buffer component to screen buffer addresses on-the-fly. We further optimise the filtering algorithm to reduce false positives. We assess the effectiveness and performance based on prototype implementations, which achieve a detection rate of 99.99% and negligible performance loss. Finally, we discuss potential reactions of our detection mechanism after a Spoiler attack was discovered. Jinhua Cui 0002, Yiyun Yin, Jiliang Zhang 0002 |
DATE | 1 |
| 2022 | Dynamic Binary Translation for SGX EnclavesabstractEnclaves, such as those enabled by Intel SGX, offer a hardware primitive for shielding user-level applications from the OS. While enclaves are a useful starting point, code running in the enclave requires additional checks whenever control or data is transferred to/from the untrusted OS. The enclave-OS interface on SGX, however, can be extremely large if we wish to run existing unmodified binaries inside enclaves. This article presents Ratel , a dynamic binary translation engine running inside SGX enclaves on Linux. Ratel offers complete interposition , the ability to interpose on all executed instructions in the enclave and monitor all interactions with the OS. Instruction-level interposition offers a general foundation for implementing a large variety of inline security monitors in thefuture. We take a principled approach in explaining why complete interposition on SGX is challenging. We draw attention to five design decisions in SGX that create fundamental trade-offs between performance and ensuring complete interposition, and we explain how to resolve them in the favor of complete interposition. To illustrate the utility of the Ratel framework, we present the first attempt to offer binary compatibility with existing software on SGX. We report that Ratel offers binary compatibility with over 200 programs we tested, including micro-benchmarks and real applications, such as Linux shell utilities. Runtimes for two programming languages, namely, Python and R, tested with standard benchmarks work out-of-the-box on Ratel without any specialized handling. Jinhua Cui 0002, Shweta Shinde, Satyaki Sen, Prateek Saxena, Pinghai Yuan |
ACM Trans. Priv. Secur. | 1 |
| 2021 | SmashEx: Smashing SGX Enclaves Using ExceptionsabstractExceptions are a commodity hardware functionality which is central to multi-tasking OSes as well as event-driven user applications. Normally, the OS assists the user application by lifting the semantics of exceptions received from hardware to program-friendly user signals and exception handling interfaces. However, can exception handlers work securely in user enclaves, such as those enabled by Intel SGX, where the OS is not trusted by the enclave code? Jinhua Cui 0002, Zhijingcheng Yu, Shweta Shinde, Prateek Saxena, Zhiping Cai |
CCS | 1 |
| 2021 | TSAEns: Ensemble Learning for KPI Anomaly Detection
Chengyu Wang 0008, Tao Yang 0041, Jinhua Cui 0002, Tongqing Zhou, Zhiping Cai |
ICA3PP (1) | 3 |
| 2021 | Leveraging blockchain for cross-institution data sharing and authentication in mobile healthcareabstractThe rapid development of the Internet of Things (IoT) has promoted the wide adoption of mobile medical devices, which monitor patients’ body conditions in real-time. The collected health-related data are highly sensitive, requiring careful protection during the accessing and transmission for specialized analysis. Yet, existing efforts either rely on centralized authentication for the numerous end devices or are designed to be partially distributed for a closed institution, both lacking scalability for mobile healthcare scenarios. In this paper, we propose HealthTrust that provides a generalized and flexible authentication scheme for distributed medical devices in the cross-institution context. With blockchain as the building block, HealthTrust jointly exploits smart contracts and secure authentication to attain controlled transmission and secure exchanging of healthcare data between institutions. We have implemented the system functions with a prototype based on Ethereum. Experimental results and safety analysis demonstrate that HealthTrust can well satisfy both the safety and feasibility requirements. Le Lai, Tongqing Zhou, Zhiping Cai, Jiaping Yu, Jinhua Cui 0002 |
MSN | 6 |
| 2020 | A Distributed Storage System for Robust, Privacy-Preserving Surveillance CamerasabstractSurveillance cameras have been extensively used in smart cities and high security zones. Recent incidents have posed a new, powerful geo-range attack, where the attacker may compromise a group of surveillance cameras located within an area. To tackle the problem, we develop a distributed camera storage system that distributes video content across geographically dispersed surveillance cameras. It generates secure copies for the video content and enhances robustness by judiciously distributing erasure coded video blocks across optimally-chosen surveillance cameras. We implement the distributed storage system for surveillance cameras and evaluate its performance via real-world field test. Our system is the first solution that can defend against geo-range attacks in a robust and privacy-preserving manner. Jiaping Yu, Haiwen Chen, Kui Wu 0001, Zhiping Cai, Jinhua Cui 0002 |
ICDCS | 5 |
| 2017 | Presence Attestation: The Missing Link in Dynamic Trust BootstrappingabstractMany popular modern processors include an important hardware security feature in the form of a DRTM (Dynamic Root of Trust for Measurement) that helps bootstrap trust and resists software attacks. However, despite substantial body of prior research on trust establishment, security of DRTM was treated without involvement of the human user, who represents a vital missing link. The basic challenge is: how can a human user determine whether an expected DRTM is currently active on her device? Zhangkai Zhang, Xuhua Ding, Gene Tsudik, Jinhua Cui 0002, Zhoujun Li 0001 |
CCS | 4 |