Jiameng Ying

dblp:272/8290 · DBLP profile ↗
← Back
5ranked-venue papers
1as first author
4since 2021 · last 2026
0000-0003-0576-3202ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Security and privacy · 2 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
3 papers
Hardware security and side channels · 60% Systems and software security · 40%
Software engineering, system software, and programming languages
1 paper
Software testing · 100%
Computer architecture, parallel and distributed computing, and storage systems
2 papers
Memory systems · 54% Cloud and datacenter computing · 46%

Topics — the 9 heaviest of 9, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
memory safety
1.012026
MSTest: A Property-Oriented, Comprehensive, and Cross-Platform Test Suite of Memory Safety · IEEE Trans. Dependable Secur. Comput. 2026
Software testing › random testing
property-based testing
1.012026
MSTest: A Property-Oriented, Comprehensive, and Cross-Platform Test Suite of Memory Safety · IEEE Trans. Dependable Secur. Comput. 2026
Software testing
test suite
1.012026
MSTest: A Property-Oriented, Comprehensive, and Cross-Platform Test Suite of Memory Safety · IEEE Trans. Dependable Secur. Comput. 2026
Hardware security and side channels › side-channel countermeasures
cache side-channel defense
0.712023
Architecting the Autocuckoo Filter to Defend Against Cross-Core Cache Attacks · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2023
Memory systems › memory hierarchy
cache hierarchy
0.712023
Architecting the Autocuckoo Filter to Defend Against Cross-Core Cache Attacks · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2023
Hardware security and side channels › trusted execution environments
heterogeneous TEE
0.412020
Enabling Rack-scale Confidential Computing using Heterogeneous Trusted Execution Environment · SP 2020
Hardware security and side channels
trusted execution environments
0.412020
Enabling Rack-scale Confidential Computing using Heterogeneous Trusted Execution Environment · SP 2020
Cloud and datacenter computing › resource disaggregation
accelerator pooling
0.412020
Enabling Rack-scale Confidential Computing using Heterogeneous Trusted Execution Environment · SP 2020
Cloud and datacenter computing › cloud security
confidential computing
0.112020
Enabling Rack-scale Confidential Computing using Heterogeneous Trusted Execution Environment · SP 2020

Methods — techniques the papers use, named apart from their topics

property-oriented testing · 2.0prefetching · 1.3cuckoo filter · 1.3resource pooling · 0.9PCIe ExpressFabric · 0.9
YearPublicationVenuePosition
2026 MSTest: A Property-Oriented, Comprehensive, and Cross-Platform Test Suite of Memory Safety
abstract
The foundation of current software ecosystem is still unfortunately laid on memory unsafe languages, such as C/C++. Memory safety vulnerabilities remain as the primary source of bugs in the critical software stacks. Some of the advanced memory safety defenses are beginning to land on commercially available platforms, in the form of instruction-set architecture extensions, runtime enforcement by standard libraries and OSes, and compile-time checks. This tide of adoption of defenses brings us several questions: For a defense that is claimed supported on a platform, can it be actually deployed to directly benefit an application? For a defense claiming a certain level of protection regarding a type of memory safety on a platform, how solid is the protection? For two platforms implementing similar types of defenses, which one provides better guarantees? Endeavor to answer these questions, a memory safety test suite, namelyMSTest, is implemented. With its current 227 test cases, the test suite has already reached a wider coverage than all existing test suites and been ported to 19 platforms. To our best knowledge, MSTest is the first portable memory safety test suite conducting property-oriented testing, automatically resolving dependency between test cases, providing a comprehensive coverage on attack and defense capabilities, and capable of comparing memory safety cross platforms.
Ciyan Ouyang, Wei Song 0002, Jiameng Ying, Sihao Shen, Peng Liu 0005
IEEE Trans. Dependable Secur. Comput.5
2023 Architecting the Autocuckoo Filter to Defend Against Cross-Core Cache Attacks
abstract
Cross-core cache timing side-channel attacks, which observe cache access behavior of victims running on different physical cores to infer sensitive information, have become a significant threat. Although the attacks are covert, they cause the attacked cachelines to frequently migrate among cache hierarchies, rendering abnormal traffic. Based on this observation, the proposed scheme PiPoMonitor records cache-memory access traffic and prefetch suspicious lines under attack to interfere with adversaries’ probes. In pursuit of security and performance, PiPoMonitor exploits a Cuckoo filter as the recording structure and introduces two features to it: 1) autonomic deletion and 2) relocation accelerating. The former exponentially increases the uncertainty of record eviction against reverse engineering attacks, while the latter leverages a pipelined architecture to alleviate the impact of intensive filter queries on the memory critical path. PiPoMonitor is not only able to effectively mitigate cross-core cache attacks and defeat sophisticated defense-aware attackers but also induces a negligible performance penalty and acceptable hardware overhead.
Fengkai Yuan, Kai Wang 0061, Jiameng Ying, Rui Hou 0001, Lutan Zhao, Peinan Li, Yifan Zhu 0008, Zhenzhou Ji, Dan Meng 0002
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.3
2022 CPP: A lightweight memory page management extension to prevent code pointer leakage
abstract
Protecting code pointers (e.g., return address, function pointer) from leakage is desirable from a security perspective. Isolation mechanisms have been the favored candidate to protect code pointers. However, these mechanisms result in significant performance overhead as they need to instrument extra instructions for frequent permission switching or bound checking. In this paper, we propose CPP, a novel Code Pointer-only Memory Page Management to restrict attack-critical operations for code pointers by hardware. Our hardware–software co-design allows CPP mark code pointers at page granularity that requires minor hardware modification. CPP checks the legality of their operations in parallel with instruction execution. We implement a prototype system and our evaluation shows CPP can effectively mitigate the code pointer leakage attacks with less than 2.1% performance overhead.
Jiameng Ying, Rui Hou 0001, Lutan Zhao, Fengkai Yuan, Penghui Zhao, Dan Meng 0002
J. Syst. Archit.1
2021 PiPoMonitor: Mitigating Cross-core Cache Attacks Using the Auto-Cuckoo Filter
abstract
Cache side channel attacks obtain victim cache line access footprint to infer security-critical information. Among them, cross-core attacks exploiting the shared last level cache are more threatening as their simplicity to set up and high capacity. Stateful approaches of detection-based mitigation observe precise cache behaviors and protect specific cache lines that are suspected of being attacked. However, their recording structures incur large storage overhead and are vulnerable to reverse engineering attacks. Exploring the intrinsic non-determinate layout of a traditional Cuckoo filter, this paper proposes a space efficient Auto-Cuckoo filter to record access footprints, which succeed to decrease storage overhead and resist reverse engineering attacks at the same time. With Auto-Cuckoo filter, we propose PiPoMonitor to detect Ping-Pong patterns and prefetch specific cache line to interfere with adversaries' cache probes. Security analysis shows the PiPoMonitor can effectively mitigate cross-core attacks and the Auto-Cuckoo filter is immune to reverse engineering attacks. Evaluation results indicate PiPoMonitor has negligible impact on performance and the storage overhead is only 0.37%, an order of magnitude lower than previous stateful approaches.
Fengkai Yuan, Kai Wang 0061, Rui Hou 0001, Peinan Li, Lutan Zhao, Jiameng Ying, Amro Awad, Dan Meng 0002
DATE7
2020 Enabling Rack-scale Confidential Computing using Heterogeneous Trusted Execution Environment
abstract
With its huge real-world demands, large-scale confidential computing still cannot be supported by today's Trusted Execution Environment (TEE), due to the lack of scalable and effective protection of high-throughput accelerators like GPUs, FPGAs, and TPUs etc. Although attempts have been made recently to extend the CPU-like enclave to GPUs, these solutions require change to the CPU or GPU chips, may introduce new security risks due to the side-channel leaks in CPU-GPU communication and are still under the resource constraint of today's CPU TEE.To address these problems, we present the first Heterogeneous TEE design that can truly support large-scale compute or data intensive (CDI) computing, without any chip-level change. Our approach, called HETEE, is a device for centralized management of all computing units (e.g., GPUs and other accelerators) of a server rack. It is uniquely designed to work with today's data centres and clouds, leveraging modern resource pooling technologies to dynamically compartmentalize computing tasks, and enforce strong isolation and reduce TCB through hardware support. More specifically, HETEE utilizes the PCIe ExpressFabric to allocate its accelerators to the server node on the same rack for a non-sensitive CDI task, and move them back into a secure enclave in response to the demand for confidential computing. Our design runs a thin TCB stack for security management on a security controller (SC), while leaving a large set of software (e.g., AI runtime, GPU driver, etc.) to the integrated microservers that operate enclaves. An enclaves is physically isolated from others through hardware and verified by the SC at its inception. Its microserver and computing units are restored to a secure state upon termination.We implemented HETEE on a real hardware system, and evaluated it with popular neural network inference and training tasks. Our evaluations show that HETEE can easily support the CDI tasks on the real-world scale and incurred a maximal throughput overhead of 2.17% for inference and 0.95% for training on ResNet152.
Rui Hou 0001, XiaoFeng Wang 0001, Wenhao Wang 0001, Jiangfeng Cao, Boyan Zhao, Zhongpu Wang, Yuhui Zhang 0011, Jiameng Ying, Lixin Zhang 0002, Dan Meng 0002
SP9