VLDB 2026 Research / reviewers in the wild / expert
Yunjie Deng 0001
dblp:246/6970-1
· DBLP profile ↗
8ranked-venue papers
1as first author
7since 2021 · last 2026
0000-0003-0885-4185ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 1 first-author · 6 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Building Confidential Accelerator Computing Environment for Arm CCA
Chenxu Wang 0005, Fengwei Zhang, Yunjie Deng 0001, Kevin Leach, Jiannong Cao 0001, Zhenyu Ning, Shoumeng Yan, Tao Wei 0002, Zhengyu He |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | MOLE: Breaking GPU TEE with GPU-Embedded MCUabstractGraphics Processing Units (GPUs) are extensively used for applications such as machine learning, scientific computing, and graphics rendering. To protect sensitive data processed by GPUs, Trusted Execution Environments (TEEs) for GPUs have been proposed. GPU TEEs, built with hardware-based isolation primitives, can defend against high-privilege attackers like OS kernels. However, in this paper, we present MOLE, a novel attack that compromises the security of GPU TEEs on Arm Mali GPUs by exploiting the GPU-embedded Microcontroller Unit (MCU). By injecting malicious firmware into the MCU, an attacker can bypass GPU TEEs' security guarantees. We evaluated MOLE with state-of-the-art GPU TEE proposals under multiple real-world attack scenarios, such as in-GPU AES encryption and object detection tasks. Our evaluation shows that MOLE can successfully extract sensitive data or manipulate the computation results of GPU TEEs. We responsibly disclosed our findings to the authors of the affected GPU TEE proposals and received acknowledgments from all of them. Moreover, our findings prompted Arm to enhance the security of its GPU firmware supply chains. Hongyi Lu, Yunjie Deng 0001, J. Sukarno Mertoguno, Shuai Wang 0011, Fengwei Zhang |
CCS | 2 |
| 2024 | BootRIST: Detecting and Isolating Mercurial Cores at the Booting Stage
Yihao Luo, Yunjie Deng 0001, Jingquan Ge, Zhenyu Ning, Fengwei Zhang |
ESORICS (2) | 2 |
| 2024 | Rapid Autonomy Transfer in Reinforcement Learning with a Single Pre- Trained CriticabstractReinforcement learning (RL) is a well-studied framework to solve complex decision-making problems in unknown environments. The actor-critic model in RL facilitates autonomy transfer by allowing agents to iteratively update their policies using ongoing dynamic evaluations of value functions via a critic. In this paper, we examine the impact of using different pretrained critics on the performance of actor-critic algorithms. First, in any single given environment, we show that a pretrained critic can be effective in reducing the duration of an initial training phase, thereby accelerating convergence by a factor of up to 2×. In this setting, we identify the critical range of the number of episodes for which a critic will need to be trained in order for it to be an effective pretrained critic. Second, we show that a critic trained in one environment enables transfer of autonomy by aiding learning of behaviors in a different, yet related environment. We carry out extensive experiments on a bipedal locomotion task in the MuJoCo physics engine to verify our hypotheses. Our results in this paper mark the first step towards demonstrating the role and impact of pretrained critics to achieve rapid autonomy transfer for complex reinforcement learning tasks while minimizing costs associated with retraining in new environments. M. Faraz Karim, Yunjie Deng 0001, Luyao Niu, Bhaskar Ramasubramanian, Michail S. Alexiou, Dinuka Sahabandu, Radha Poovendran, J. Sukarno Mertoguno |
ICTAI | 2 |
| 2024 | CAGE: Complementing Arm CCA with GPU Extensions
Chenxu Wang 0005, Fengwei Zhang, Yunjie Deng 0001, Kevin Leach, Jiannong Cao 0001, Zhenyu Ning, Shoumeng Yan, Zhengyu He |
NDSS | 3 |
| 2024 | Building a Lightweight Trusted Execution Environment for Arm GPUsabstractA wide range of Arm endpoints leverage integrated and discrete GPUs to accelerate computation. However, Arm GPU security has not been explored by the community. Existing work has used Trusted Execution Environments (TEEs) to address GPU security concerns on Intel-based platforms, but there are numerous architectural differences that lead to novel technical challenges in deploying TEEs for Arm GPUs. There is a need for generalizable and efficient Arm-based GPU security mechanisms. To address these problems, we presentStrongBox, the first GPU TEE for secured general computation on Arm endpoints.StrongBoxprovides an isolated execution environment by ensuring exclusive access to GPU. Our approach is based in part on a dynamic, fine-grained memory protection policy as Arm-based GPUs typically share a unified memory with the CPU. Furthermore,StrongBoxreduces runtime overhead from the redundant security introspection operations. We also design an effective defense mechanism withinsecure worldto protect the confidential GPU computation. Our design leverages the widely-deployed Arm TrustZone and generic Arm features, without hardware modification or architectural changes. We prototypeStrongBoxusing an off-the-shelf Arm Mali GPU and perform an extensive evaluation. Results show thatStrongBoxsuccessfully ensures GPU computation security with a low (4.70%–15.26%) overhead. Chenxu Wang 0005, Yunjie Deng 0001, Zhenyu Ning, Kevin Leach, Jin Li 0002, Shoumeng Yan, Zhengyu He, Jiannong Cao 0001, Fengwei Zhang |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | StrongBox: A GPU TEE on Arm EndpointsabstractA wide range of Arm endpoints leverage integrated and discrete GPUs to accelerate computation such as image processing and numerical processing applications. However, in spite of these important use cases, Arm GPU security has yet to be scrutinized by the community. By exploiting vulnerabilities in the kernel, attackers can directly access sensitive data used during GPU computing, such as personally-identifiable image data in computer vision tasks. Existing work has used Trusted Execution Environments (TEEs) to address GPU security concerns on Intel-based platforms, while there are numerous architectural differences that lead to novel technical challenges in deploying TEEs for Arm GPUs. In addition, extant Arm-based GPU defenses are intended for secure machine learning, and lack generality. There is a need for generalizable and efficient Arm-based GPU security mechanisms. Yunjie Deng 0001, Chenxu Wang 0005, Shunchang Yu, Shiqing Liu, Zhenyu Ning, Kevin Leach, Jin Li 0002, Shoumeng Yan, Zhengyu He, Jiannong Cao 0001, Fengwei Zhang |
CCS | 1 |
| 2019 | An Experimental Study of Large-scale Capacitated Vehicle Routing ProblemsabstractThe recently proposed Scalable Approach Based on Hierarchical Decomposition (SAHiD) has shown its superiority on large-scale capacitated arc routing problems (CARP) in terms of both computational efficiency and solution quality. The main idea of SAHiD is that the underlying Hierarchical decomposition (HD) scheme is able to efficiently obtain a good permutation of tasks for CARP in a hierarchical divide-and-conquer way, where both the number and size of subproblems can be kept in tractable for large-scale problems with thousands of tasks. Motivated by the frequent observations of the similarity between CARP and Capacitated Vehicle Routing Problem (CVRP), the HD scheme and SAHiD algorithm are expected to work well on CVRPs. This paper applies SAHiD to large-scale CVRPs and discovers that SAHiD does not work as well as expected on large-scale CVRP. Possible reasons for this are given after extensive experimental studies. Two directions for improving SAHiD on large-scale CVRP are pointed out. Er Zhuo, Yunjie Deng 0001, Zhewei Su, Peng Yang 0008, Bo Yuan 0006, Xin Yao 0001 |
CEC | 2 |