VLDB 2026 Research / reviewers in the wild / expert
Huaiyu Yan
dblp:167/5749
· DBLP profile ↗
9ranked-venue papers
3as first author
8since 2021 · last 2026
0009-0008-3757-3044ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 5 since 2021Computer networks · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | UIEE: Secure and Efficient User-space Isolated Execution Environment for Embedded TEE Systems
Huaiyu Yan, Zhen Ling 0001, Xuandong Chen, Xinhui Shao, Yier Jin, Ming Yang 0001, Junzhou Luo |
NDSS | 1 |
| 2026 | Toward Secure and Efficient Driver Support for Embedded TEE SystemsabstractTrusted execution environments (TEEs), like TrustZone, are pervasively employed to protect security sensitive programs and data from various attacks issued by untrusted rich execution environments (REEs) while they execute compact TEE operating systems which implement minimum security-critical operations but have poor device driver support. In this paper, we propose a twin driver approach where a pair of TEE and REE drivers is generated and cooperate to enable secure and efficient TEE driver support. To begin with, we propose a driver data flow analysis framework named driver analyzer (DrvAna) to automatically analyze the shared states between the TEE and REE driver where a novel data structure named value-type tree is investigated to facilitate field-sensitive data flow analysis upon the driver state. Furthermore, in order to maintain a minimal trusted computing base, we propose a Linux driver runtime (LDR) inside the TEE, a sandbox environment that confines the TEE driver based on the ARM domain access control features and mediates the driver's interaction with the TEE. We implement a DrvAna prototype based on LLVM as well as an LDR prototype on an NXP IMX6Q SABRE-SD evaluation board, adapt 6 existing Linux drivers into LDR, and evaluate their performance. The experimental results show that the LDR drivers can achieve comparable performance with their Linux counterparts with negligible overheads. Huaiyu Yan, Zhen Ling 0001, Xinhui Shao, Ming Yang 0001, Junzhou Luo, Xinwen Fu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | The Cost of Performance: Breaking ThreadX with Kernel Object Masquerading Attacks
Xinhui Shao, Zhen Ling 0001, Yue Zhang 0025, Huaiyu Yan, Yumeng Wei, Zixia Liu, Junzhou Luo, Xinwen Fu |
USENIX Security Symposium | 4 |
| 2024 | LDR: Secure and Efficient Linux Driver Runtime for Embedded TEE Systems
Huaiyu Yan, Zhen Ling 0001, Xinhui Shao, Kai Dong 0001, Ming Yang 0001, Junzhou Luo, Xinwen Fu |
NDSS | 1 |
| 2022 | fASLR: Function-Based ASLR for Resource-Constrained IoT Systems
Xinhui Shao, Zhen Ling 0001, Huaiyu Yan, Yumeng Wei, Xinwen Fu |
ESORICS (2) | 4 |
| 2022 | fASLR: Function-Based ASLR via TrustZone-M and MPU for Resource-Constrained IoT SystemsabstractThe address space layout randomization (ASLR) has been widely deployed on modern operating systems against code reuse attacks (CRAs), such as return-oriented programming (ROP) and jump-oriented programming (JOP). However, porting ASLR to resource-constrained IoT devices is a great challenge due to the limited memory space for randomization. We propose a function-based ASLR scheme (fASLR) for IoT runtime security utilizing the ARM TrustZone-M technology and the memory protection unit (MPU) supported by ARM Cortex-M processors. fASLR loads a function from the flash and randomizes its base address in a randomization region in RAM when the function is being called. We design novel mechanisms on cleaning up finished functions from the RAM and memory addressing to tackle the complexity of function relocation and randomization. Optimizations are applied to effectively reduce overhead introduced by runtime memory management. We also formally prove that user applications will run correctly with fASLR enabled. Compared with the related work, a prominent advantage of fASLR is that fASLR can run an application even if the application code cannot be completely loaded into RAM for execution. We test fASLR with 21 applications. The experimental results show that fASLR achieves a high randomization entropy and incurs a runtime overhead of less than 10%. Xinhui Shao, Zhen Ling 0001, Huaiyu Yan, Yumeng Wei, Xinwen Fu |
IEEE Internet Things J. | 4 |
| 2021 | On Manually Reverse Engineering Communication Protocols of Linux-Based IoT SystemsabstractIoT security and privacy has raised grave concerns. Efforts have been made to design tools to identify and understand vulnerabilities of IoT systems. Most of the existing protocol security analysis techniques rely on a well understanding of the underlying communication protocols. In this article, we systematically present the first manual reverse engineering framework for discovering communication protocols of embedded Linux-based IoT systems. We have successfully applied our framework to reverse engineer a number of IoT systems. As an example, we present a detailed use of the framework reverse engineering the WeMo smart plug communication protocol by extracting the firmware from the flash, performing static and dynamic analysis of the firmware, and analyzing network traffic. The discovered protocol exposes severe design flaws that allow attackers to control or deny the service of victim plugs. Our manual reverse engineering framework is generic and can be applied to both read-only and writable embedded Linux filesystems. Kaizheng Liu, Ming Yang 0001, Zhen Ling 0001, Huaiyu Yan, Yue Zhang 0025, Xinwen Fu, Wei Zhao 0001 |
IEEE Internet Things J. | 4 |
| 2021 | Secure boot, trusted boot and remote attestation for ARM TrustZone-based IoT Nodes
Zhen Ling 0001, Huaiyu Yan, Xinhui Shao, Junzhou Luo, Yiling Xu, Bryan Pearson, Xinwen Fu |
J. Syst. Archit. | 2 |
| 2015 | Design of the intelligent braking system with PLC based on the USS interface protocolabstractThis article includes the principle of frequency control of motor speed and the Universal Serial (short for USS below) interface protocol. And design of the intelligent braking system based on USS interface protocol will be introduced from the principle of intelligent braking system based on frequency control of motor speed, composition of hardware, software designing and the realization of communication between PLC and frequency converter using USS interface protocol. This system has realized the intelligent adjustment of brake torque and improved the performance of traditional brake. Consequently it will be good for reducing the vibration impulse during the process of braking and enhancing braking stability. So the working life of brakes will be expanded. Zhenning Sun, Yanfang Yang, Jiquan Hu, Huaiyu Yan |
CSCWD | 4 |