VLDB 2026 Research / reviewers in the wild / expert
Yusha Zhang
dblp:237/5086
· DBLP profile ↗
9ranked-venue papers
1as first author
8since 2021 · last 2024
—ORCID · unresolved
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 5 · 1 first-author · 5 since 2021Security and privacy · 2 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Oblivious Demand Paging with Ring ORAM in RISC-V Trusted Execution EnvironmentsabstractTrusted execution environments based on RISC-V architecture like Keystone remain susceptible to leaking page access patterns of applications via simple demand paging, in which a malicious Operating System (OS) deduces sensitive information from it. To address this issue, Keystone requires protecting sensitive access patterns from being revealed to the malicious OS by implementing oblivious demand paging. In this paper, we use Oblivious RAM (ORAM) techniques that obfuscate access patterns while simultaneously making demand paging oblivious for Keystone. Furthermore, we present customized optimizations to Ring ORAM, aimed at minimizing the performance overhead incurred by applications during both secure and unsecure demand paging in Keystone. These optimizations encompass strategies such as encoding the position map within the page table, utilizing a resizable tree structure and selective eviction of only the root bucket. These improvements collectively contribute to minimizing performance slowdown. We implement and evaluate our optimized Ring ORAM for oblivious demand paging, which shows the average performance slowdown of 7.1x in comparison to the simple Ring ORAM slowdown of 26.2x. Wenjing Cai, Yusha Zhang, Xu Cheng 0001 |
CSCWD | 4 |
| 2024 | A Module Level Security Evaluation Method Based on Model CheckingabstractProcessors are an important component of computer systems, but resource sharing in space and time, as well as performance first design concepts, result in a series of security issues for processors. On the one hand, processor security evaluation can systematically analyze and verify the security of the processor, deduce the key reasons for security risks, and on the other hand, it can assist in processor design, verifying processor security at a lower cost at the beginning of the design, compared to later software and hardware protection.This paper proposes a module level security evaluation method based on model checking, modeling the module as a mealy finite state machine to analyze the relationship between its outputs, inputs and states. Computational Logic Tree (CTL) is used to represent possible execution paths, and all paths are traversed to derive counterexample paths to represent possible attack paths and information leakage processes. We use the Common Vulnerability Scoring System(CVSS) to score each counterexample path. Based on these counterexample paths and CVSS scores, we ultimately obtained a total risk score to represent the security of the module. We conduct a case study on Cache to verify the effectiveness of our proposed method. Yusha Zhang, Zhongkai Tong, Wenjing Cai, Dan Meng 0002 |
CSCWD | 3 |
| 2024 | KSM: Killer of Spectre and Meltdown AttacksabstractIn the relentless pursuit of bolstering processor performance, computer architects have harnessed a gamut of sophisticated optimization techniques. However, this pursuit of performance enhancements has inadvertently laid bare an underbelly of concealed security vulnerabilities, exemplified by notorious instances such as Meltdown and Spectre attacks. These attacks adeptly exploit optimization techniques, coupled with cache side-channel attacks, to expose protected data. The ripple effects of these vulnerabilities are indeed seismic, owing to their pervasive presence across existing and forthcoming processors. Regrettably, Meltdown and Spectre have remained elusive to satisfactory mitigation to date; instead, Spectre and Meltdown attack variations have sprung forth from them. In response to this challenge, this paper posits an approach. It proposes the optimization of four distinctive hardware performance events through feature selection, subsequently harnessing the prowess of machine learning algorithms to forge a real-time detection mechanism. This mechanism is primed to combat Spectre V1, V2, V4, and Meltdown attack variations, culminating in a robust accuracy rate exceeding 99%. This resounding success demonstrates that this paper’s framework not only confronts original attacks but also grapples effectively with diverse attack variants, a scenario that might manifest in everyday contexts. Zhongkai Tong, Yusha Zhang, Dan Meng 0002 |
CSCWD | 3 |
| 2024 | A Formal Verification Methodology for Cache Architectures Based on Noninterference HyperpropertiesabstractThe design of secure cache architectures within computer systems primarily aims to mitigate side-channel attacks and minimize the risks of information leakage. However, verifying the effectiveness of secure cache designs introduces numerous challenges. The assessment of cache architecture security in prior research has mainly been based on the evaluators’ expertise, which lacks convincing evidence. Therefore, it is imperative to establish a universal and comprehensive formal verification methodology to evaluate the security of cache designs. This paper analyzes the advantages and disadvantages of an existing formal verification method. Based on this analysis, we introduce an enhanced formal verification method that utilizes noninterference hyperproperties to verify the security of cache architectures.In this paper, an extended triple mutual information formula is utilized to verify the satisfaction of noninterference hyperproperties within cache architectures and identify potential information leakages through three independence conditions. The degree of information leakage is evaluated by measuring the dependencies between the victim’s inputs and the attacker’s observations through triple mutual information. This paper instantiates existing cache architectures and reveals potential vulnerabilities by formalizing the behavior specification and replacement policy of a cache as an extended abstract state machine. Lastly, the cache security structure is formally validated utilizing the proposed security model, with the aim of evidencing its effectiveness and soundness. Yusha Zhang, Zhongkai Tong, Wenjing Cai, Dan Meng 0002 |
CSCWD | 1 |
| 2024 | Towards Enhanced Energy Aware Resource Optimization for Edge Devices Through Multi-cluster Communication Systems
Saihong Li, Yusha Zhang, Yinghui Xie |
J. Grid Comput. | 3 |
| 2023 | Detecting and Mitigating Cache Side Channel Threats on Intel SGXabstractIntel Software Guard Extensions (SGX) protect sensitive content of applications on the cloud platform by creating an isolated environment on an untrusted operating system. However, resent works have shown that the SGX is vulnerable to a variety of side channel attacks which could be severely damage the data confidentiality provided by SGX, such as the cache side channel attack. Unfortunately, existing defense mechanisms either provide an incomplete protection or incur too much performance costs. In this paper, we propose a defense countermeasure against cache side channel attacks for SGX by detecting abnormal each level cache use behaviors. We create auxiliary threads for each enclave thread and detect when asynchronous enclave exits (AEX) occur, which defeats the condition of L1/L2 cache side channel attacks that attacker and victim threads execute in the same physical core. We put some guard data to the cache lines and inspect access time, which detects last level cache eviction set behaviors. More importantly, we utilize optimizations to reduce the performance overhead caused by AEX detection. In comparison to existing approaches, our design is secure against any cache level side channel attacks and its performance loss increases less. Wenjing Cai, Yusha Zhang, Xu Cheng 0001 |
CSCWD | 4 |
| 2023 | Flush+Revisit: A Cross-CCX Side-Channel Attack on AMD ProcessorsabstractCross-core cache side-channel attacks allow attackers to launch more threatening cross-virtual machine (cross-VM) attacks in the virtualized environment. Most of these cross-core cache side-channel attacks take advantage of the feature that the last-level cache (LLC) is shared by all cores. However, these attacks may not perform well in cross-core attacks on processors that the LLC is not shared by all cores. This paper mainly focuses on the AMD Zen series processors, which introduce the design of the CPU complex (or Core Complex, CCX), and different CCXs have their independent LLCs. We find that previous cross-core cache side-channel attacks such as Flush+Reload do not work well in crossing CCXs on these processors, as these attacks mainly utilize the sharing characteristics of the LLC between different cores. In this paper, we present a cross-CCX side-channel attack named Flush+Revisit. As far as we know, we are the first to study cross-CCX side-channel attacks on AMD processors. Compared with traditional cache side-channel attacks, when crossing CCX, a more distinguishable time difference can be observed between accessed and unaccessed addresses with Flush+Revisit. We have carried out evaluation experiments to show that Flush+Revisit is an effective cross-CCX side-channel attack on an AMD Ryzen 7 3700X processor, which is known to have employed the CCX structure. In addition, we have also applied Flush+Revisit in a real-world attack scenario: attacking the T-Table-based AES implementation of OpenSSL in the cross-CCX scenario and leaking the full 128-bit key on the AMD Ryzen 7 3700X processor within 3.75 seconds successfully, with an error rate of 0.00%. Danping Li, Jiao Shen, Yusha Zhang, Dan Meng 0002 |
TrustCom | 4 |
| 2022 | Analysis of DRAM Vulnerability Using Computation Tree LogicabstractShared resources facilitate both side and covert channels and greatly endanger information security even in cloud environments. In cloud computing environments, multiple tenants often reside on the same multi-processor system. Therefore, it is important to prevent information leakage between tenants. Shared memory between tenants is usually disabled for security reasons. In addition, tenants typically do not share physical CPUs. In this case, cache attacks do not work. As a common shared resource, DRAM memory can also be exploited as a source of side and covert channels.In this paper, Computation Tree Logic (CTL) is used to model the behaviors of row buffer logic in DRAM and derive all possible timing-based vulnerabilities. The problem of state space explosion is alleviated by using bounded model checking in this method. In total, our method derives 24 kinds of DRAM timing-based vulnerabilities. Furthermore, we analyze DRAM vulnerabilities to help engineers understand them and take corresponding measures in the design according to derived security specifications. Yusha Zhang, Zhongkai Tong, Wenjing Cai, Dan Meng 0002 |
ICC | 3 |
| 2020 | Cache side-channel attacks detection based on machine learningabstractSecurity has always been one of the main concerns in the field of computer architecture and cloud computing. Cache-based side-channel attacks pose a threat to almost all existing architectures and cloud computing. Especially in the public cloud, the cache is shared among multiple tenants, and cache attacks can make good use of this to extract information. Cache side-channel attacks are a problem to be solved for security, in which how to accurately detect cache side-channel attacks has been a research hotspot. Because the cache side-channel attack does not require the attacker to physically contact the target device and does not need additional devices to obtain the side channel information, the cache-side channel attack is efficient and hidden, which poses a great threat to the security of cryptographic algorithms. Based on the AES algorithm, this paper uses hardware performance counters to obtain the features of different cache events under Flush + Reload, Prime + Probe, and Flush + Flush attacks. Firstly, the random forest algorithm is used to filter the cache features, and then the support vector machine algorithm is used to model the system. Finally, high detection accuracy is achieved under different system loads. The detection accuracy of the system is 99.92% when there is no load, the detection accuracy is 99.85% under the average load, and the detection accuracy under full load is 96.57%. Zhongkai Tong, Zhanpeng Wang, Yusha Zhang |
TrustCom | 5 |