VLDB 2026 Research / reviewers in the wild / expert
Zheng Zhang 0060
dblp:181/2621-60
· DBLP profile ↗
9ranked-venue papers
4as first author
9since 2021 · last 2025
0000-0001-9190-6454ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 4 · 1 first-author · 4 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | FlashAttest: Self-Attestation for Low-End Internet of Things via Flash DevicesabstractRemote Attestation (RA) is an effective security service that allows a trusted party (verifier) to initiate the attestation routine on a potentially untrusted remote device (prover) to verify its correct state. Despite their usefulness, traditional challenge-response remote attestation protocols suffer from certain limitations, such as challenges in scaling attestation collection and the forced suspension of normal operation during attestation. Self-attestation tackles these issues by enabling the prover to measure its own state asynchronously with the verifier’s attestation request. Existing self-attestation methods rely on hybrid architectures to provide the required security properties, which may not be compatible with low-end Internet of Things (IoT) devices due to hardware limitations. In addition, these protocols currently lack formal verification of design correctness. In this paper, we present FlashAttest, a formally verified self-attestation protocol for low-end IoT devices. FlashAttest leverages the flash device to fulfill the security properties required by self-attestation, eliminating the requirement for hardware modifications. In particular, FlashAttest allows the prover to initiate the attestation routine and guarantee the trustworthiness of the results based on the verified software-based security architecture. By collaborating with the flash device during attestation to generate timestamped reports, FlashAttest enables the verifier to collect and verify the legitimacy of the attestation results. More importantly, FlashAttest achieves strong security guarantees supported by a formally verified design using the Tamarin prover. We implement and evaluate FlashAttest on MSP430 architecture, showing a reasonable overhead in terms of memory footprint, communication overhead, runtime and power consumption. Compared with state-of-the-art self-attestation schemes, our approach achieves similar runtime overhead, low energy consumption, and reasonable memory overhead while eliminating the need for hardware modifications. The results confirm the suitability of FlashAttest for low-end devices. Zheng Zhang 0060, Jingfeng Xue, Weizhi Meng 0001, Xu Qiao, Yuanzhang Li 0001, Yu-an Tan 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | ATT&CK-based Advanced Persistent Threat attacks risk propagation assessment model for zero trust networks
Jingci Zhang, Jun Zheng 0007, Zheng Zhang 0060, Yu-an Tan 0001, Quanxin Zhang 0001, Yuanzhang Li 0001 |
Comput. Networks | 3 |
| 2024 | COVER: Enhancing virtualization obfuscation through dynamic scheduling using flash controller-based secure module
Zheng Zhang 0060, Jingfeng Xue, Thar Baker, Yu-an Tan 0001, Yuanzhang Li 0001 |
Comput. Secur. | 1 |
| 2024 | Bypassing software-based remote attestation using debug registersabstractRemote attestation (RA) is an essential feature in many security protocols to verify the memory integrity of remote embedded devices susceptible to malware infections.The attestation process needs to be consecutive and atomic to prevent a self-relocating malware from evading detection.Most of the prior attestation techniques disable interrupts during execution to prevent another process from interrupting the integrity check.This paper investigates the shortcomings of existing software-based attestation techniques and stresses the threat of debug exceptions to existing software-based attestation.We present Debug Register-based Self-relocating Attack (DRSA), a novel self-relocating malware against software-based attestation based on debug registers.DRSA gains control of the checksum function by raising debug exceptions and erasing itself before the next attestation.We further implement DRSA on commodity OSes and validate its effectiveness based on two existing software-based proposals.Our evaluation demonstrates that DRSA incurs low overhead, and it is extremely difficult for the verifier to detect it.can bypass the attestation with very little attack overhead. Zheng Zhang 0060, Jingfeng Xue, Tianshi Mu, Kefan Qiu, Yuanzhang Li 0001 |
Connect. Sci. | 1 |
| 2024 | Dataflow optimization with layer-wise design variables estimation method for enflame CNN accelerators
Yu-an Tan 0001, Zheng Zhang 0060, Nan Luo, Yuanzhang Li 0001 |
J. Parallel Distributed Comput. | 3 |
| 2024 | Flash controller-based secure execution environment for protecting code confidentialityabstractWith the rapid evolution of Internet-of-Things (IoT), billions of IoT devices have connected to the Internet, collecting information via tags and sensors. For an IoT device, the application code itself and data collected by sensors can be of great commercial value. It is challenging to protect them because IoT devices are prone to compromise due to the inevitable vulnerabilities of commodity OSes. Trusted Execution Environment (TEE) is one of the solutions that protects sensitive data by running security-sensitive workloads in a secure world. However, this solution does not work for most of the IoT devices that are limited in resources. In this paper, we propose Flash Controller-based Secure Execution Environment (FCSEE), an approach to protect security-sensitive code and data for IoT devices using the flash controller. Our approach constructs a secure execution environment on the target flash memory by modifying the execution logic of its controller, leveraging it as a co-processor to execute security-sensitive workloads of the host device. By extending the original functionality of the flash firmware, FCSEE also provides several much-needed security primitives to protect sensitive data. We constructed a prototype based on a Trans-Flash (TF) card and implemented proof of its confidentiality. Our evaluation results indicate that FCSEE can confidentially execute security-sensitive workloads from the host and efficiently protects its sensitive data. Zheng Zhang 0060, Jingfeng Xue, Yuhang Zhao 0003, Weizhi Meng 0001 |
J. Syst. Archit. | 1 |
| 2022 | Towards robust and stealthy communication for wireless intelligent terminalsabstractFifth-generation (5G) wireless systems provide an opportunity for improving the existing Voice over Internet Protocol communication service's user experience. To mitigate the security risk of 5G data leakage, building covert channel is an alternative approach of providing confidential data transmission. Due to the high transmission rate of 5G, the interpacket intervals become small and derandomized, this caused the encoding phase of the covert timing channel imports relatively large modulation errors. rearranging is a widespread phenomenon that is occurred over the data communications. In this paper, we propose a rearrangement covert channel approach named Hybrid Variable-length Packet Rearrangement Covert Timing Channel (HVPR-CTC), which artificially chooses the delimiter packets and identification (ID) packets from the overt traffics, and encodes the packet sending order between adjacent delimiter packets according to a generated hybrid variable-length codeword dictionary, and embeds the secret message by rearranging the sending order of the ID packets. The experiments demonstrate that the HVPR-CTC scheme can effectively perform strategy adjustment: its minimum Location Square Deviation is 0.832 and minimum Swap Deviation is 139. the maximum throughput reaches 14.37 bps, and the optimal Bit Error Rate is 3.27% and 9.70% for low-channel noise and high-channel noise communication conditions, respectively. Kefan Qiu, Zheng Zhang 0060, Yuanzhang Li 0001 |
Int. J. Intell. Syst. | 3 |
| 2022 | Security of federated learning for cloud-edge intelligence collaborative computingabstractFederated Learning (FL) is one of the key technologies to solve privacy protection for cloud-edge intelligent collaborative computing, and its security and privacy issues have attracted extensive attention from academia and industry. FL is a distributed privacy protection framework. Multiple edged nodes or servers jointly train a machine learning model by sharing model parameters without exchanging local data. However, there are still many security risks and privacy threats in FL in edge-cloud collaborative computing. In this paper, we mainly discuss the security and privacy challenges on FL in collaborative computing at the edge. First, we introduce the principle, classification, and threat model of FL in edge-cloud collaboration, which helps understand the challenges faced by edge-cloud collaborative computing. Second, privacy leakage attacks and poisoning attacks launched by adversaries or honest but curious actors are summarized and compared. Then, the problems existing on the attack method are summarized and analyzed. Finally, the future development direction of FL in the field of edge-cloud collaborative computing is further discussed. Jun Zheng 0007, Zheng Zhang 0060, Q. I. Chen, Duncan S. Wong, Yuanzhang Li 0001 |
Int. J. Intell. Syst. | 3 |
| 2022 | Hybrid isolation model for device application sandboxing deployment in Zero Trust architectureabstractWith recent cyber security attacks, the “border defense” security protection mechanism has often penetrated and broken through, and the “borderless” security defense idea—Zero Trust was proposed. The device application sandbox deployment model is one of the four essential Zero Trust architecture device deployment models. The isolation of the application sandbox directly affects the security of trusted applications. Given the security risks, such as sandbox escape in the sandbox application, we propose a hybrid isolation model based on access behavior and give the formal definition and security characteristics of the model. The model dynamically determines the security identity of the subject according to the access behavior and controls the access operation of the application sandbox. Therefore, the sandbox meets the characteristics of autonomous security, domain isolation, and integrity, ensuring that the system is always in an isolated safe state and easy to use. Finally, we implement the security model based on the container and Linux security module, and test the network and disk performance of this model. What is more, we make security comparison experiments based on the same container escape vulnerability. The experimental results show that the security model proposed in this paper effectively enhances the security of the device application sandboxing deployment model in Zero Trust architecture, and has a better performance compared with Container-SELinux. Jingci Zhang, Jun Zheng 0007, Zheng Zhang 0060, Kefan Qiu, Quanxin Zhang 0001, Yuanzhang Li 0001 |
Int. J. Intell. Syst. | 3 |