Ardalan Amiri Sani

dblp:20/8069 · DBLP profile ↗
← Back
43ranked-venue papers
8as first author
18since 2021 · last 2025
0000-0003-0130-587XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 20 · 5 first-author · 9 since 2021Systems, architecture and hardware · 9 · 2 first-authorSecurity and privacy · 8 · 6 since 2021Software engineering, systems software and programming languages · 8 · 2 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2025 SyzSpec: Specification Generation for Linux Kernel Fuzzing via Under-Constrained Symbolic Execution
abstract
Fuzzing has become one of the most effective and widely used techniques for discovering bugs and vulnerabilities, particularly in large-scale and complex programs like operating system kernels. A notable example is the kernel fuzzer syzkaller, which has identified over 6,800 bugs in the Linux kernel, with more than 5,500 already fixed. A crucial reason behind the success of the syzkaller is its collection of syscall descriptions, which are typically provided by human experts. Although some methods exist for automatically generating these syscall descriptions for device drivers, they often fall short when dealing with complex user inputs. These existing methods either lack precision or have a limited analysis scope, resulting in incomplete syscall descriptions.
Yu Hao 0006, Juefei Pu, Zhiyun Qian, Ardalan Amiri Sani
CCS5
2025 Spinner: Detecting Locking Violations in the eBPF Runtime
abstract
The eBPF technology is widely used for many applications, including tracing, packet filtering, network usage monitoring, and so on. The versatility of eBPF allows the kernel’s capabilities to be extended without needing to modify source code or load kernel modules. However, the eBPF subsystem may introduce new bugs that could lead to crashes, data loss, and other issues that can negatively impact system stability, reliability, availability, security, and overall performance. Specifically, locking violations, which occur when locks are not used correctly, can lead to problems like deadlocks and system hangs. Since eBPF operates at the kernel level, errors here have far-reaching consequences.To tackle this issue, we present Spinner, a tool for detecting locking violations in the eBPF runtime. Spinner uses static analysis to (1) detect cases of context confusion where incorrect locking primitives are used in eBPF helper functions given their execution context, and (2) identify locks in helper functions that can be called recursively using nested eBPF programs. Both of these situations could result in deadlocks. So far, Spinner has identified 34 locking violation bugs in the eBPF subsystem in Linux, only 5 of which were previously found by Syzbot.
Priya Govindasamy, Joseph Bursey, Hsin-Wei Hung, Ardalan Amiri Sani
ASE4
2025 SyzRetrospector: A Large-Scale Retrospective Study of Syzbot
abstract
Over the past 7 years, Syzbot has fuzzed the Linux kernel day and night to report over 6,700 bugs, of which nearly 5,500 have been patched. While this is impressive, we have found that $25 \%$ of bugs take longer than 738 days to find. Moreover, we have found that current metrics commonly used, such as time-to-find and number of bugs found, are inaccurate in evaluating Syzbot since bugs often spend the majority of their lives hidden from the fuzzer. In this paper, we set out to better understand and quantify Syzbot’s performance and improvement in finding bugs. Our tool, SyzRetrospector, takes a different approach to evaluating Syzbot by finding the earliest that Syzbot was capable of finding a bug, and why that bug was revealed. We use SyzRetrospector on a large scale to analyze 695 bugs and find that $40 \%$ of bugs are hidden for more than 258 days before Syzbot is even able to find them. We further present findings on why bugs were revealed to Syzbot (i.e., their revealing factors), the effort required to reveal bugs, the trends in delays, and how the location of bugs affects these delays. We also provide key takeaways for improving Syzbot’s delays.
Joseph Bursey, Ardalan Amiri Sani, Zhiyun Qian
RAID2
2025 Scoop: Mitigation of Recapture Attacks on Provenance-Based Media Authentication
Yuxin (Myles) Liu, Habiba Farrukh, Ardalan Amiri Sani, Sharad Agarwal, Gene Tsudik
USENIX Security Symposium3
2024 ProvCam: A Camera Module with Self-Contained TCB for Producing Verifiable Videos
abstract
Our perception of reality is under constant threat from ever-improving video manipulation techniques, including deep-fakes and generative AI. Therefore, proving authenticity of videos is increasingly important, especially in legal and news contexts. However, it is very challenging to prove it based on post-factum video content analysis.
Yuxin (Myles) Liu, Zhihao Yao 0001, Ardalan Amiri Sani, Sharad Agarwal, Gene Tsudik
MobiCom4
2023 Minimizing a Smartphone's TCB for Security-Critical Programs with Exclusively-Used, Physically-Isolated, Statically-Partitioned Hardware
abstract
Smartphone owners often need to run security-critical programs on the same device as other untrusted and potentially malicious programs. This requires users to trust hardware and system software to correctly sandbox malicious programs, trust that is often misplaced. Our goal is to minimize the number and complexity of hardware and software components that a smartphone owner needs to trust. We present a split-trust hardware design composed of statically-partitioned, physically-isolated trust domains. We introduce a few simple, formally-verified hardware components to enable a program to gain provably exclusive and simultaneous access to both computation and I/O on a temporary basis. To manage this hardware, we present OctopOS, an OS composed of mutually distrustful subsystems. We present a prototype of this machine (hardware and OS) on a CPU-FPGA board and show that it incurs a small hardware cost compared to modern smartphone SoCs. For security-critical programs, we show that this machine significantly reduces the required trust compared to mainstream TEEs while achieving usable performance. For normal programs, performance is similar to a legacy machine.
Zhihao Yao 0001, Seyed Mohammadjavad Seyed Talebi, Ardalan Amiri Sani, Thomas E. Anderson
MobiSys4
2023 SyzDescribe: Principled, Automated, Static Generation of Syscall Descriptions for Kernel Drivers
abstract
Fuzz testing operating system kernels has been effective overall in recent years. For example, syzkaller manages to find thousands of bugs in the Linux kernel since 2017. One necessary component of syzkaller is a collection of syscall descriptions that are often provided by human experts. However, to our knowledge, current syscall descriptions are largely written manually, which is both time-consuming and error-prone. It is especially challenging considering that there are many kernel drivers (for new hardware devices and beyond) that are continuously being developed and evolving over time. In this paper, we present a principled solution for generating syscall descriptions for Linux kernel drivers. At its core, we summarize and model the key invariants or programming conventions, extracted from the "contract" between the core kernel and drivers. This allows us to understand programmatically how a kernel driver is initialized and how its associated interfaces are constructed. With this insight, we have developed a solution in a tool called SyzDescribe that has been tested for over hundreds of kernel drivers. We show that the syscall descriptions produced by SyzDescribe are competitive to manually-curated ones, and much better than prior work (i.e., DIFUZE and KSG). Finally, we analyze the gap between our descriptions and the ground truth and point to future improvement opportunities.
Yu Hao 0006, Guoren Li, Xiaochen Zou, Weiteng Chen, Shitong Zhu, Zhiyun Qian, Ardalan Amiri Sani
SP7
2023 GLeeFuzz: Fuzzing WebGL Through Error Message Guided Mutation
Zhihao Yao 0001, Ardalan Amiri Sani, Jing (Dave) Tian, Mathias Payer
USENIX Security Symposium3
2022 Demystifying the Dependency Challenge in Kernel Fuzzing
abstract
Fuzz testing operating system kernels remains a daunting task to date. One known challenge is that much of the kernel code is locked under specific kernel states and current kernel fuzzers are not effective in exploring such an enormous state space. We refer to this problem as the dependency challenge. Though there are some efforts trying to address the dependency challenge, the prevalence and categorization of dependencies have never been studied. Most prior work simply attempted to recover dependencies opportunistically whenever they are relatively easy to recognize. In this paper, we undertake a substantial measurement study to systematically understand the real challenge behind dependencies. To our surprise, we show that even for well-fuzzed kernel modules, unresolved dependencies still account for 59% - 88% of the uncovered branches. Furthermore, we show that the dependency challenge is only a symptom rather than the root cause of failing to achieve more coverage. By distilling and summarizing our findings, we believe the research provides valuable guidance to future research in kernel fuzzing. Finally, we propose a number of novel research directions directly based on the insights gained from the measurement study.
Yu Hao 0006, Hang Zhang 0012, Guoren Li, Xingyun Du, Zhiyun Qian, Ardalan Amiri Sani
ICSE6
2022 Sifter: protecting security-critical kernel modules in Android through attack surface reduction
abstract
The Linux kernel is an important part of the Trusted Computing Base (TCB) of a mobile device using the Android OS, making it attractive to attackers. While all vulnerabilities in the kernel are important, those that are directly reachable by untrusted programs pose a grave threat. This paper introduces Sifter, a solution for protecting security-critical kernel modules, i.e., those modules that are directly exposed to untrusted programs. Sifter's key approach is the use of fine-grained, highly-selective filters to reduce the attack surface of these kernel modules and make their vulnerabilities unreachable for untrusted programs. The key observation in Sifter is that there are rich patterns in how legitimate programs issue syscalls to these kernel modules; thus, one can generate filters that only allow such syscall patterns, and as a result mitigate vulnerabilities (including zero-day ones) that could only be exploited by the use of unorthodox syscall patterns.
Hsin-Wei Hung, Yingtong Liu, Ardalan Amiri Sani
MobiCom3
2022 Vronicle: verifiable provenance for videos from mobile devices
abstract
Demonstrating veracity of videos is a longstanding problem that has recently become more urgent and acute. It is extremely hard to accurately detect manipulated videos using content analysis, especially in the face of subtle, yet effective, manipulations, such as frame rate changes or skin tone adjustments.
Yuxin (Myles) Liu, Yoshimichi Nakatsuka, Ardalan Amiri Sani, Sharad Agarwal, Gene Tsudik
MobiSys3
2022 Vronicle: verifiable provenance for videos from mobile devices
abstract
An increasing number of mobile devices are incorporating cameras, allowing users to record videos at any time, anywhere. This opens up a wide variety of applications, most notably security-critical ones, where videos are used as evidence or include sensitive content. Examples of such applications include (but are not limited to): (i) citizen journalists recording important events (e.g., protests), (ii) courts using videos as evidence, and (iii) electronic legal contract-signing platforms using videos to identify signing users [1].
Yuxin (Myles) Liu, Yoshimichi Nakatsuka, Ardalan Amiri Sani, Sharad Agarwal, Gene Tsudik
MobiSys3
2022 Vronicle: verifiable provenance for videos from mobile devices
abstract
An increasing number of mobile devices are incorporating cameras, allowing users to record videos at any time, anywhere. This opens up a wide variety of applications, most notably security-critical ones, where videos are used as evidence or include sensitive content. Examples of such applications include (but are not limited to): (i) citizen journalists recording important events (e.g., protests), (ii) courts using videos as evidence, and (iii) electronic legal contract-signing platforms using videos to identify signing users [1].
Yuxin (Myles) Liu, Yoshimichi Nakatsuka, Ardalan Amiri Sani, Sharad Agarwal, Gene Tsudik
MobiSys3
2022 IoT Notary: Attestable Sensor Data Capture in IoT Environments
abstract
Contemporary IoT environments, such as smart buildings, require end-users to trust data-capturing rules published by the systems. There are several reasons why such a trust is misplaced—IoT systems may violate the rules deliberately or IoT devices may transfer user data to a malicious third-party due to cyberattacks, leading to the loss of individuals’ privacy or service integrity. To address such concerns, we propose IoT Notary , a framework to ensure trust in IoT systems and applications. IoT Notary provides secure log sealing on live sensor data to produce a verifiable “proof-of-integrity,” based on which a verifier can attest that captured sensor data adhere to the published data-capturing rules. IoT Notary is an integral part of TIPPERS, a smart space system that has been deployed at the University of California, Irvine to provide various real-time location-based services on the campus. We present extensive experiments over real-time WiFi connectivity data to evaluate IoT Notary , and the results show that IoT Notary imposes nominal overheads. The secure logs only take 21% more storage, while users can verify their one day’s data in less than 2 s even using a resource-limited device.
Nisha Panwar, Shantanu Sharma 0001, Guoxi Wang, Sharad Mehrotra, Nalini Venkatasubramanian, Mamadou H. Diallo, Ardalan Amiri Sani
ACM Trans. Internet Things7
2022 SchrodinText: Strong Protection of Sensitive Textual Content of Mobile Applications
abstract
Many mobile applications deliver and showsensitive and private textual contentto users including messages, social network posts, account information, and verification codes. All such textual content must be displayed to users but must be strongly protected from unauthorized access in mobile devices. Unfortunately, this is not the case in mobile devices today: malware that can compromise the OS can easily access textual content of other applications. We present SchrodinText, a system solution for strongly protecting the confidentiality of an application's selected UI textual content from a fully compromised OS. SchrodinText leverages a novel security monitor based on two hardware features on ARM processors: virtualization hardware and TrustZone. Our key contribution is a set of novel techniques that allow the OS to perform text rendering without needing access to the text itself, hence minimizing the trusted computing base (TCB). These techniques, collectively calledoblivious rendering, enable the OS to rasterize and lay out all the characters without access to the text; the monitorresolvesthe right character glyphs onto the framebufferobservedby the user and protects them from the OS. Using our prototypes, we show that SchrodinText incurs noticeable overhead but that its performance is usable.
Nicholas Wei, Ardalan Amiri Sani
IEEE Trans. Mob. Comput.2
2021 User-defined cloud
abstract
Since its creation, cloud computing has always taken a provider-dictated approach, where cloud providers define and manage the cloud to accommodate the user needs they deem important. We propose "User-Defined Cloud", or UDC, a new cloud scheme that allows users to define their own "clouds", by defining hardware resource needs, system software features, and security requirements of their applications, and to do so without the need to build or manage low-level systems.
Yiying Zhang 0005, Ardalan Amiri Sani, Guoqing Harry Xu
HotOS2
2021 MegaMind: a platform for security & privacy extensions for voice assistants
abstract
Voice assistants raise serious security and privacy concerns because they use always-on microphones in sensitive locations (e.g., inside a home) and send audio recordings to the cloud for processing. The cloud transcribes these recordings and interprets them as user requests, and sometimes even shares these requests with third-party services. These steps may result in unintended or malicious voice data leaks and in unauthorized actions, such as a purchase. This paper presents MegaMind, a novel extensible platform that lets a user deploy security and privacy extensions locally on their voice assistant. MegaMind's extensions interpose on requests before sending them to the cloud and on responses before delivering them to the user. MegaMind's programming model enables writing powerful extensions with ease, such as one for secure conversations. Additionally, MegaMind protects against malicious extensions by providing two important guarantees, namely permission enforcement and non-interference. We implement MegaMind and integrate it with Amazon Alexa Service SDK. Our evaluation shows that MegaMind achieves a small conversation latency on platforms with adequate compute power, such as a Raspberry Pi 4 and an x86-based laptop.
Seyed Mohammadjavad Seyed Talebi, Ardalan Amiri Sani, Stefan Saroiu, Alec Wolman
MobiSys2
2021 Undo Workarounds for Kernel Bugs
Seyed Mohammadjavad Seyed Talebi, Zhihao Yao 0001, Ardalan Amiri Sani, Zhiyun Qian, Daniel Austin
USENIX Security Symposium3
2020 Dynamic Sharing in Multi-accelerators of Neural Networks on an FPGA Edge Device
abstract
Edge computing can potentially provide abundant processing resources for compute-intensive applications while bringing services close to end devices. With the increasing demands for computing acceleration at the edge, FPGAs have been deployed to provide custom deep neural network accelerators. This paper explores a DNN accelerator sharing system at the edge FPGA device, that serves various DNN applications from multiple end devices simultaneously. The proposed SharedDNN/PlanAhead policy exploits the regularity among requests for various DNN accelerators and determines which accelerator to allocate for each request and in what order to respond to the requests that achieve maximum responsiveness for a queue of acceleration requests. Our results show overall 2. 20x performance gain at best and utilization improvement by reducing up to 27% of DNN library usage while staying within the requests’ requirements and resource constraints.
Hsin-Yu Ting, Tootiya Giyahchi, Ardalan Amiri Sani, Elaheh Bozorgzadeh
ASAP3
2020 Mousse: a system for selective symbolic execution of programs with untamed environments
abstract
Selective symbolic execution (SSE) is a powerful program analysis technique for exploring multiple execution paths of a program. However, it faces a challenge in analyzing programs with environments that cannot be modeled nor virtualized. Examples include OS services managing I/O devices, software frameworks for accelerators, and specialized applications. We introduce Mousse, a system for analyzing such programs using SSE. Mousse uses novel solutions to overcome the above challenge. These include a novel process-level SSE design, environment-aware concurrent execution, and distributed execution of program paths. We use Mousse to comprehensively analyze five OS services in three smartphones. We perform bug and vulnerability detection, taint analysis, and performance profiling. Our evaluation shows that Mousse outperforms alternative solutions in terms of performance and coverage.
Yingtong Liu, Hsin-Wei Hung, Ardalan Amiri Sani
EuroSys3
2020 Tabellion: secure legal contracts on mobile devices
abstract
A legal contract is an agreement between two or more parties as to something that is to be done in the future. Forming contracts electronically is desirable since it is convenient. However, existing electronic contract platforms have a critical shortcoming. They do not provide strong evidence that a contract has been legally and validly created. More specifically, they do not provide strong evidence that an electronic signature is authentic, that there was mutual assent, and that the parties had an opportunity to read the contract. We present Tabellion, a system for forming legal contracts on mobile devices, such as smartphones and tablets, that addresses the above shortcoming. We define four secure primitives and use them in Tabellion to introduce self-evident contracts, the validity of which can be verified by independent inspectors. We show how these primitives can be implemented securely in the Trusted Execution Environment (TEE) of mobile devices as well as a secure enclave in a centralized server, all with a small Trusted Computing Base (TCB). Moreover, we demonstrate that it is feasible to build a fully functional contract platform on top of these primitives. We develop ~15,000 lines of code (LoC) for our prototype, only ~1,000 of which need to be trusted. Through analysis, prototype measurements, and a 30-person user study, we show that Tabellion is secure, achieves acceptable performance, and provides slightly better usability than the state-of-the-art electronic contract platform, DocuSign, for viewing and signing contracts.
Saeed Mirzamohammadi, Yuxin (Myles) Liu, Tianmei Ann Huang, Ardalan Amiri Sani, Sharad Agarwal, Sung Eun (Summer) Kim
MobiSys4
2020 Systemizing Interprocedural Static Analysis of Large-scale Systems Code with Graspan
abstract
There is more than a decade-long history of using static analysis to find bugs in systems such as Linux. Most of the existing static analyses developed for these systems are simple checkers that find bugs based on pattern matching. Despite the presence of many sophisticated interprocedural analyses, few of them have been employed to improve checkers for systems code due to their complex implementations and poor scalability. In this article, we revisit the scalability problem of interprocedural static analysis from a “Big Data” perspective. That is, we turn sophisticated code analysis into Big Data analytics and leverage novel data processing techniques to solve this traditional programming language problem. We propose Graspan , a disk-based parallel graph system that uses an edge-pair centric computation model to compute dynamic transitive closures on very large program graphs. We develop two backends for Graspan, namely, Graspan-C running on CPUs and Graspan-G on GPUs, and present their designs in the article. Graspan-C can analyze large-scale systems code on any commodity PC, while, if GPUs are available, Graspan-G can be readily used to achieve orders of magnitude speedup by harnessing a GPU’s massive parallelism. We have implemented fully context-sensitive pointer/alias and dataflow analyses on Graspan. An evaluation of these analyses on large codebases written in multiple languages such as Linux and Apache Hadoop demonstrates that their Graspan implementations are language-independent, scale to millions of lines of code, and are much simpler than their original implementations. Moreover, we show that these analyses can be used to uncover many real-world bugs in large-scale systems code.
Zhiqiang Zuo 0002, Kai Wang 0029, Aftab Hussain 0001, Ardalan Amiri Sani, Yiyu Zhang, Shenming Lu, Wensheng Dou, Linzhang Wang, Xuandong Li, Chenxi Wang 0005, Guoqing Harry Xu
ACM Trans. Comput. Syst.4
2019 The Case for Exploiting Underutilized Resources in Heterogeneous Mobile Architectures
abstract
Heterogeneous architectures are ubiquitous in mobile platforms, with mobile SoCs typically integrating multiple processors along with accelerators such as GPUs (for data-parallel kernels) and DSPs (for signal processing kernels). This strict partitioning of application execution on heterogeneous compute resources often results in underutilization of resources such as DSPs. We present a case study executing a mix of popular data-parallel workloads such as convolutional neural networks (CNNs), computer vision filters and graphics rendering kernels on mobile devices, and show that both performance and energy consumption of mobile platforms can be improved by synergistically deploying these underutilized compute resources. Our experiments on a mobile Snapdragon 835 platform under both single and multiple application scenarios executing the aforementioned workloads demonstrates average performance and energy improvements of 15-46% and 18-80%, respectively, by synergistically deploying all available compute resources, especially the underutilized DSP.
Chen-Ying Hsieh, Ardalan Amiri Sani, Nikil Dutt
DATE2
2019 The Case for I/O-Device-as-a-Service
abstract
Many computer systems, especially mobile and IoT systems, use a large number of I/O devices. A contemporary OS acts as a security guard for these devices, which trust the OS to correctly implement the "perimeter defense." Moreover, the OS also trusts these devices and their drivers to be well-behaved and bug-free. This interwoven trust model complicates the security of the system as a single vulnerable component can undermine all security guarantees. Not surprising, this architecture has failed to achieve strong security as evident by attacks that have targeted I/O devices or their drivers. In this paper, we call for a radically new approach, called I/O-Device-as-a-Service (IDaaS), where each I/O device acts a separate service and is responsible for its own security. Inspired by Service-Oriented Architecture (SOA), IDaaS requires every device to be equipped with its own software stack and provide an externalizable API that can be safely exposed to untrusted software. We discuss the design decisions in IDaaS, highlight its security benefits and research challenges, and present a case study.
Ardalan Amiri Sani, Thomas E. Anderson
HotOS1
2019 IoT Notary: Sensor Data Attestation in Smart Environment
abstract
Contemporary IoT environments, such as smart buildings, require end-users to trust data-capturing rules published by the systems. There are several reasons why such a trust is misplaced - IoT systems may violate the rules deliberately or IoT devices may transfer user data to a malicious third-party due to cyberattacks, leading to the loss of individuals' privacy or service integrity. To address such concerns, we propose IoT Notary, a framework to ensure trust in IoT systems and applications. IoT Notary provides secure log sealing on live sensor data to produce a verifiable `proof-of-integrity,' based on which a verifier can attest that captured sensor data adheres to the published data-capturing rules. IoT Notary is an integral part of TIPPERS, a smart space system that has been deployed at UCI to provide various real-time location-based services in the campus. IoT Notary imposes nominal overheads for verification, thereby users can verify their data of one day in less than two seconds.
Nisha Panwar, Shantanu Sharma 0001, Guoxi Wang, Sharad Mehrotra, Nalini Venkatasubramanian, Mamadou H. Diallo, Ardalan Amiri Sani
NCA7
2019 SURF: Self-aware Unified Runtime Framework for Parallel Programs on Heterogeneous Mobile Architectures
abstract
The following topics are dealt with: multiprocessing systems; microprocessor chips; logic design; power aware computing; field programmable gate arrays; integrated circuit design; low-power electronics; integrated circuit reliability; logic gates; radiation hardening (electronics).
Chen-Ying Hsieh, Ardalan Amiri Sani, Nikil Dutt
VLSI-SoC2
2018 Sugar: Secure GPU Acceleration in Web Browsers
abstract
Modern personal computers have embraced increasingly powerful Graphics Processing Units (GPUs). Recently, GPU-based graphics acceleration in web apps (i.e., applications running inside a web browser) has become popular. WebGL is the main effort to provide OpenGL-like graphics for web apps and it is currently used in 53% of the top-100 websites. Unfortunately, WebGL has posed serious security concerns as several attack vectors have been demonstrated through WebGL. Web browsers» solutions to these attacks have been reactive: discovered vulnerabilities have been patched and new runtime security checks have been added. Unfortunately, this approach leaves the system vulnerable to zero-day vulnerability exploits, especially given the large size of the Trusted Computing Base of the graphics plane. We present Sugar, a novel operating system solution that enhances the security of GPU acceleration for web apps by design. The key idea behind Sugar is using a dedicated virtual graphics plane for a web app by leveraging modern GPU virtualization solutions. A virtual graphics plane consists of a dedicated virtual GPU (or vGPU) as well as all the software graphics stack (including the device driver). Sugar enhances the system security since a virtual graphics plane is fully isolated from the rest of the system. Despite GPU virtualization overhead, we show that Sugar achieves high performance. Moreover, unlike current systems, Sugar is able to use two underlying physical GPUs, when available, to co-render the User Interface (UI): one GPU is used to provide virtual graphics planes for web apps and the other to provide the primary graphics plane for the rest of the system. Such a design not only provides strong security guarantees, it also provides enhanced performance isolation.
Zhihao Yao 0001, Zongheng Ma, Yingtong Liu, Ardalan Amiri Sani, Aparna Chandramowlishwaran
ASPLOS4
2018 Milkomeda: Safeguarding the Mobile GPU Interface Using WebGL Security Checks
abstract
GPU-accelerated graphics is commonly used in mobile applications. Unfortunately, the graphics interface exposes a large amount of potentially vulnerable kernel code (i.e., the GPU device driver) to untrusted applications. This broad attack surface has resulted in numerous reported vulnerabilities that are exploitable from unprivileged mobile apps. We observe that web browsers have faced and addressed the exact same problem in WebGL, a framework used by web apps for graphics acceleration. Web browser vendors have developed and deployed a plethora of security checks for the WebGL interface. We introduce Milkomeda, a system solution for automatically repurposing WebGL security checks to safeguard the mobile graphics interface. We show that these checks can be used with minimal modifications (which we have automated using a tool called CheckGen), significantly reducing the engineering effort. Moreover, we demonstrate an in-process shield space for deploying these checks for mobile applications. Compared to the multi-process architecture used by web browsers to protect the integrity of the security checks, our solution improves the graphics performance by eliminating the need for Inter-Process Communication and shared memory data transfer, while providing integrity guarantees for the evaluation of security checks. Our evaluation shows that Milkomeda achieves close-to-native GPU performance at reasonably increased CPU utilization.
Zhihao Yao 0001, Saeed Mirzamohammadi, Ardalan Amiri Sani, Mathias Payer
CCS3
2018 Empowering Cyber-Physical Systems with FADEX
abstract
No abstract available.
Vittorio Cozzolino, Aaron Yi Ding, Ardalan Amiri Sani, Richard Mortier, Dirk Kutscher, Jörg Ott
MobiSys3
2018 Charm: Facilitating Dynamic Analysis of Device Drivers of Mobile Systems
Seyed Mohammadjavad Seyed Talebi, Hamid Tavakoli, Hang Zhang 0012, Zheng Zhang 0058, Ardalan Amiri Sani, Zhiyun Qian
USENIX Security Symposium5
2018 Viola: Trustworthy Sensor Notifications for Enhanced Privacy on Mobile Systems
abstract
Modern mobile systems such as smartphones, tablets, and wearables contain a plethora of sensors such as camera, microphone, GPS, and accelerometer. These sensors can capture extremely sensitive and private information about the user including daily conversations, photos, videos, and visited locations, raising important privacy concerns. To address these concerns, we present Viola, our design and implementation of trustworthy sensor notifications, which use indicators such as LED to inform the user unconditionally when the sensors are on. We deploy Viola's runtime monitor in low-level system software, e.g., in the operating system kernel or in the hypervisor. Moreover, we use formal verification methods to prove the functional correctness of the compilation of our invariant checks from a high-level language. We demonstrate that Viola incurs almost no overhead to the sensor's performance and incurs only small power consumption overhead. Compared to our previous paper on Viola [1] , we present three important enhancements. First, we design, implement, and evaluate two-way sensor notifications, which guarantee that a sensor notification can be triggered if and only if the corresponding sensor is used. Second, we identify and add protection against concurrency attacks in Viola. Third, we implement Viola for an additional sensor and indicator combination.
Saeed Mirzamohammadi, Ardalan Amiri Sani
IEEE Trans. Mob. Comput.2
2017 Graspan: A Single-machine Disk-based Graph System for Interprocedural Static Analyses of Large-scale Systems Code
abstract
There is more than a decade-long history of using static analysis to find bugs in systems such as Linux. Most of the existing static analyses developed for these systems are simple checkers that find bugs based on pattern matching. Despite the presence of many sophisticated interprocedural analyses, few of them have been employed to improve checkers for systems code due to their complex implementations and poor scalability. In this paper, we revisit the scalability problem of interprocedural static analysis from a "Big Data" perspective. That is, we turn sophisticated code analysis into Big Data analytics and leverage novel data processing techniques to solve this traditional programming language problem. We develop Graspan, a disk-based parallel graph system that uses an edge-pair centric computation model to compute dynamic transitive closures on very large program graphs.
Kai Wang 0029, Aftab Hussain 0001, Zhiqiang Zuo 0002, Guoqing Harry Xu, Ardalan Amiri Sani
ASPLOS5
2017 SchrodinText: Strong Protection of Sensitive Textual Content of Mobile Applications
abstract
Many mobile applications deliver and show sensitive and private textual content to users including messages, social network posts, account information, and verification codes. All such textual content must only be displayed to the user but must be strongly protected from unauthorized access in the device. Unfortunately, this is not the case in mobile devices today: malware that can compromise the operating system, e.g., gain root or kernel privileges, can easily access textual content of other applications. In this paper, we present SchrodinText, a system solution for strongly protecting the confidentiality of application's selected UI textual content from a fully compromised operating system. SchrodinText leverages a novel security monitor based on two hardware features on modern ARM processors: virtualization hardware and TrustZone. Our key contribution is a set of novel techniques that allow the operating system to perform the text rendering without needing access to the text itself, hence minimizing the Trusted Computing Base (TCB). These techniques, collectively called oblivious rendering, enable the operating system to rasterize and lay out all the characters without access to the text; the monitor only resolves the right character glyphs onto the framebuffer observed by the user and protects them from the operating system, e.g., against DMA attacks. We present our prototype using an ARM Juno development board and Android operating system. We show that SchrodinText incurs noticeable overhead but that its performance is usable.
Ardalan Amiri Sani
MobiSys1
2017 Ditio: Trustworthy Auditing of Sensor Activities in Mobile & IoT Devices
abstract
Mobile and Internet-of-Things (IoT) devices, such as smartphones, tablets, wearables, smart home assistants (e.g., Google Home and Amazon Echo), and wall-mounted cameras, come equipped with various sensors, notably camera and microphone. These sensors can capture extremely sensitive and private information. There are several important scenarios where, for privacy reasons, a user might require assurance about the use (or non-use) of these sensors. For example, the owner of a home assistant might require assurance that the microphone on the device is not used during a given time of the day. Similarly, during a confidential meeting, the host needs assurance that attendees do not record any audio or video. Currently, there are no means to attain such assurance in modern mobile and IoT devices. To this end, this paper presents Ditio, a system approach for auditing sensor activities. Ditio records sensor activity logs that can be later inspected by an auditor and checked for compliance with a given policy. It is based on a hybrid security monitor architecture that leverages both ARM's virtualization hardware and TrustZone. Ditio includes an authentication protocol for establishing a logging session with a trusted server and a formally verified companion tool for log analysis. Ditio prototypes on ARM Juno development board and Nexus 5 smartphone show that it introduces negligible performance overhead for both the camera and microphone. However, it incurs up to 17% additional power consumption under heavy use for the Nexus 5 camera.
Saeed Mirzamohammadi, Justin A. Chen, Ardalan Amiri Sani, Sharad Mehrotra, Gene Tsudik
SenSys3
2016 Viola: Trustworthy Sensor Notifications for Enhanced Privacy on Mobile Systems
abstract
Modern mobile systems such as smartphones, tablets, and wearables contain a plethora of sensors such as camera, microphone, GPS, and accelerometer. Moreover, being mobile, these systems are with the user all the time, e.g., in user's purse or pocket. Therefore, mobile sensors can capture extremely sensitive and private information about the user including daily conversations, photos, videos, and visited locations. Such a powerful sensing capability raises important privacy concerns.
Saeed Mirzamohammadi, Ardalan Amiri Sani
MobiSys2
2014 I/o paravirtualization at the device file boundary
abstract
Paravirtualization is an important I/O virtualization technology since it uniquely provides all of the following benefits: the ability to share the device between multiple VMs, support for legacy devices without virtualization hardware, and high performance. However, existing paravirtualization solutions have one main limitation: they only support one I/O device class, and would require significant engineering effort to support new device classes and features. In this paper, we present Paradice, a solution that vastly simplifies I/O paravirtualization by using a common paravirtualization boundary for various I/O device classes: Unix device files. Using this boundary, the paravirtual drivers simply act as a class-agnostic indirection layer between the application and the actual device driver.
Ardalan Amiri Sani, Kevin Boos, Shaopu Qin, Lin Zhong 0001
ASPLOS1
2014 Rio: a system solution for sharing i/o between mobile systems
abstract
Mobile systems are equipped with a diverse collection of I/O devices, including cameras, microphones, sensors, and modems. There exist many novel use cases for allowing an application on one mobile system to utilize I/O devices from another. This paper presents Rio, an I/O sharing solution that supports unmodified applications and exposes all the functionality of an I/O device for sharing. Rio's design is common to many classes of I/O devices, thus significantly reducing the engineering effort to support new I/O devices. Our implementation of Rio on Android consists of about 7100 total lines of code and supports four I/O classes with fewer than 500 class-specific lines of code. Rio also supports I/O sharing between mobile systems of different form factors, including smartphones and tablets. We show that Rio achieves performance close to that of local I/O for audio devices, sensors, and modem, but suffers noticeable performance degradation for camera due to network throughput limitations between the two systems, which is likely to be alleviated by emerging wireless standards.
Ardalan Amiri Sani, Kevin Boos, Min Hong Yun, Lin Zhong 0001
MobiSys1
2014 Demo: Rio: a system solution for sharing I/O between mobile systems
abstract
A user nowadays owns a variety of mobile systems, including smartphones, tablets, smart glasses, and smart watches, each equipped with a plethora of I/O devices, such as cameras, speakers, microphones, sensors, and cellular modems. There are many interesting use cases in which an application running on one mobile system accesses I/O on another system, for three fundamental reasons. (i) Mobile systems can be in different physical locations or orientations. For example, one can control a smartphone's high-resolution camera from a tablet camera application to more easily capture a self-portrait. (ii) Mobile systems can serve different users. For example, one can a play music for another user if one's smartphone can access the other device's speaker. (iii) Certain mobile systems have unique I/O devices due to their distinct form factor and targeted use cases. For example, a user can make a phone call from her tablet using the modem and SIM card in her smartphone.
Ardalan Amiri Sani, Kevin Boos, Min Hong Yun, Lin Zhong 0001
MobiSys1
2014 Video: Rio: a system solution for sharing i/o between mobile systems
abstract
Modern mobile systems are equipped with a diverse collection of I/O devices, including cameras, microphones, various sensors, and cellular modem. There exist many novel use cases for allowing an application on one mobile system to utilize I/O devices from another. This video demonstrates Rio, an I/O sharing solution that supports unmodified applications and realizes many of these novel use cases. Rio's design is common to many classes of I/O devices, significantly reducing the engineering effort to support new I/O devices. Moreover, it supports all the functionalities of an I/O device for sharing. Rio also supports I/O sharing between mobile systems of different form factors, including smartphones and tablets.
Ardalan Amiri Sani, Kevin Boos, Min Hong Yun, Lin Zhong 0001
MobiSys1
2011 Data broadcasting using mobile FM radio: design, realization and application
abstract
In this work, we offer a novel system, MicroStation (μStation) that allows ubiquitous data broadcasting applications using the FM radio on mobile devices such as smartphones. μStation includes two key modules to enable data broadcasting based on existing mobile FM radio hardware. Channel Selector assigns different FM channels to neighboring μStation broadcasters to avoid collision and guides μStation listeners to find their broadcasting of interest. Data Codec realizes bit-level communication between mobile devices through existing FM radio hardware. We describe an implementation of μStation on the Nokia N900 smartphone, and provide low-level APIs and services to support application development. We also demonstrate two representative applications: Facebook-FM and Sync-Flash. These applications demonstrate the capability of μStation to readily enable a new class of ubiquitous data broadcasting applications on mobile devices.
Ahmad Rahmati, Ardalan Amiri Sani, Lin Zhong 0001, Jehan Wickramasuriya, Venu Vasudevan
UbiComp3
2010 Power-efficient directional wireless communication on small form-factor mobile devices
abstract
Wireless access is known to be power-hungry for mobile devices. A key reason is that devices radiate power in all directions and much of this power will not reach the destination. To address this waste, we present BeamSwitch, a multi-antenna system designed to realize directional communication efficiently. Unlike power-hungry and expensive beamforming, BeamSwitch requires only one transceiver. We provide an 802.11-compliant design and prototype of BeamSwitch. Our measurements show that with three passive directional antennas, BeamSwitch reduces the power consumption of a commercial 802.11 adapter by up to 20% and provide better quality under diverse propagation environments and extreme rotation.
Ardalan Amiri Sani, Hasan Dumanli, Lin Zhong 0001, Ashutosh Sabharwal
ISLPED1
2010 Directional antenna diversity for mobile devices: characterizations and solutions
abstract
We report a first-of-its-kind realization of directional transmission for smartphone-like mobile devices using multiple passive directional antennas, supported by only one RF chain. The key is a multi-antenna system (MiDAS) and its antenna selection methods that judiciously select the right antenna for transmission. It is grounded by two measurement-driven studies regarding 1) how smartphones rotate during wireless usage in the field and 2) how orientation and rotation impact the performance of directional antennas under various propagation environments.
Ardalan Amiri Sani, Lin Zhong 0001, Ashutosh Sabharwal
MobiCom1
2009 Demo abstract: Laser-based trace-gas chemical sensors for distributed wireless sensor networks
Stephen So, Ardalan Amiri Sani, Lin Zhong 0001, Frank K. Tittel, Gerard Wysocki
IPSN2