Chia-Che Tsai

dblp:277/2163 · DBLP profile ↗
← Back
22ranked-venue papers
6as first author
8since 2021 · last 2025
0000-0002-0016-6487ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 8 · 1 first-author · 2 since 2021Systems, architecture and hardware · 7 · 3 first-author · 2 since 2021Security and privacy · 5 · 1 first-author · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Enhancing Program Analysis with Deterministic Distinguishable Calling Context
abstract
Calling context is crucial for improving the precision of program analyses in various use cases (clients), such as profiling, debugging, optimization, and security checking. Often the calling context is encoded using a numerical value. We have observed that many clients benefit not only from a deterministic but also globally distinguishable value across runs to simplify bookkeeping and guarantee complete uniqueness. However, existing work only guarantees determinism, not global distinguishability. Clients need to develop auxiliary helpers, which incurs considerable overhead to distinguish encoded values among all calling contexts. In this paper, we propose Deterministic Distinguishable Calling Context Encoding () that can enable both properties of calling context encoding natively. The key idea of is leveraging the static call graph and encoding each calling context as the running call path count. Thereby, a mapping is established statically and can be readily used by the clients. Our experiments with two client tools show that has a comparable overhead compared to two state-of-the-art encoding schemes, PCCE and PCC, and further avoids the expensive overheads of collision detection, up to 2.1× and 50%, for Splash-3 and SPEC CPU 2017, respectively.
Sungkeun Kim, Khanh Nguyen 0001, Chia-Che Tsai, Abdullah Muzahid, Eun Jung Kim 0001
CC3
2025 Adaptive and Efficient Dynamic Memory Management for Hardware Enclaves
abstract
The second version of Intel® Software Guard Extensions (Intel SGX), or SGX2, adds dynamic management of enclave memory and threads. The first version required the address space and thread counts to be fixed before execution. The Enclave Dynamic Memory Management (EDMM) feature of SGX2 has the potential to lower launch times and overall execution time. Despite reducing the enclave loading time by 28-93%, straightforward EDMM adoption strategies actually slow execution time down by as much as 58%.
Vijay Dhanraj, Harpreet Singh Chawla, Daniel Manila, Eric Thomas Schneider, Erica Fu, Donald E. Porter, Chia-Che Tsai, Mona Vij
SYSTOR7
2024 Endokernel: A Thread Safe Monitor for Lightweight Subprocess Isolation
Fangfei Yang, Bumjin Im, Weijie Huang 0001, Kelly Kaoudis, Anjo Vahldiek-Oberwagner, Chia-Che Tsai, Nathan Dautenhahn
USENIX Security Symposium6
2023 Attack of the Knights: Non Uniform Cache Side Channel Attack
abstract
For a distributed last-level cache (LLC) in a large multicore chip, the access time to one LLC bank can significantly differ from that to another due to the difference in physical distance. In this paper, we successfully demonstrate a new distance-based side-channel attack by timing the AES decryption operation and extracting part of an AES secret key on an Intel Knights Landing CPU. We introduce several techniques to overcome the challenges of the attack, including the use of multiple attack threads to ensure LLC hits, to detect vulnerable memory locations, and to obtain fine-grained timing of the victim operations. While operating as a covert channel, this attack can reach a bandwidth of 205 KBPS with an error rate of only 0.02%. We also observed that the side-channel attack can extract 4 bytes of an AES key with 100% accuracy with only 4000 trial rounds of encryption.
Farabi Mahmud, Sungkeun Kim, Harpreet Singh Chawla, Eun Jung Kim 0001, Chia-Che Tsai, Abdullah Muzahid
ACSAC5
2023 WHISTLE: CPU Abstractions for Hardware and Software Memory Safety Invariants
abstract
Memory safety invariants extracted from a program can help defend and detect against both software and hardware memory violations. For instance, by allowing only specific instructions to access certain memory locations, system can detect out-of-bound or illegal pointer dereferences that lead to correctness and security issues. In this paper, we propose CPU abstractions, called, to specify and check program invariants to provide defense mechanism against both software and hardware memory violations at runtime. ensures that the invariants must be satisfied at every memory accesses. We present a fast invariant address translation and retrieval scheme using a specialized cache. It stores and checks invariants related to global, stack and heap objects. The invariant checks can be performed synchronously or asynchronously. uses synchronous checking for high security-critical programs, while others are protected by asynchronous checking. A fast exception is proposed to alert any violations as soon as possible in order to close the gap for transient attacks. Our evaluation shows that can detect both software and hardware, spatial and temporal memory violations. incurs 53% overhead when checking synchronously, or 15% overhead when checking asynchronously.
Sungkeun Kim, Farabi Mahmud, Jiayi Huang 0001, Pritam Majumder, Chia-Che Tsai, Abdullah Muzahid, Eun Jung Kim 0001
IEEE Trans. Computers5
2022 Efficient Traffic Coordination for Resolving Temporary Bottlenecks on the Multi-lane Freeways
abstract
Resolving traffic bottlenecks caused by emergency situations on the freeways has been a challenge. It often takes much time for the vehicles voluntarily to line up and exit the congestion spot quickly. Unlike existing traffic scheduling schemes, which often rely on traffic signal controllers or are specified for known bottleneck areas, this paper introduces an efficient decentralized traffic coordination method, namely ETRACO, for resolving temporary bottlenecks on the multi-lane freeways. Initially, based on the Vehicle-to-Vehicle (V2V) warning notifications about the congestion, the vehicles negotiate with neighbors to determine a suitable configuration (platoon leader, distance gap, velocity, platoon size) for forming platoons. After that, each platoon leader commands the platoon members to change lane under the condition that there is a safe space on the lane next to the current lane so that the platoon can move safely to that lane. The experimental results demonstrate that our approach can reduce up to 22% delay for the last few vehicles driving through the congestion area during the congestion period. Furthermore, the proposed approach also effectively reduce congestion time for new incoming vehicles, and maintain the fairness for vehicles to leave the congestion area.
Chia-Che Tsai, Chia-Yiu Lin, Van Linh Nguyen, Ren-Hung Hwang
ICC1
2021 When threads meet events: efficient and precise static race detection with origins
abstract
Data races are among the worst bugs in software in that they exhibit non-deterministic symptoms and are notoriously difficult to detect. The problem is exacerbated by interactions between threads and events in real-world applications. We present a novel static analysis technique, O2, to detect data races in large complex multithreaded and event-driven software. O2 is powered by “origins”, an abstraction that unifies threads and events by treating them as entry points of code paths attributed with data pointers. Origins in most cases are inferred automatically, but can also be specified by developers. More importantly, origins provide an efficient way to precisely reason about shared memory and pointer aliases.
Bozhen Liu, Peiming Liu, Chia-Che Tsai, Dilma Da Silva, Jeff Huang 0001
PLDI4
2021 Platoon-based Vehicle Coordination Scheme for Resolving Sudden Traffic Jam in the IoV Era
abstract
In the next decades, the popularity of Internet of Vehicles (IoV) technologies and autonomous driving promises to fundamentally change the way of handling the traffic flow on the streets. Traffic separation can be entirely carried out from a remote traffic control center without the police. This work introduces a sequential coordination algorithm, namely SCA, to form and sort platoons of vehicles to quickly exit traffic bottleneck areas caused by temporary situations, such as vehicular accidents and a slow tractor. By exploiting maneuver information from IoV data sharing, SCA schedules the vehicles in a queue by their arrival and lane priority and then instructs them to safely drive through in order. The experimental results demonstrate our approach can reduce up to 32% waiting time for the vehicles to exit accident spots.
Ren-Hung Hwang, Van Linh Nguyen, Chia-Che Tsai, Po-Ching Lin
VTC Fall3
2020 An Off-Chip Attack on Hardware Enclaves via the Memory Bus
Dayeol Lee, Dongha Jung, Ian T. Fang, Chia-Che Tsai, Raluca A. Popa
USENIX Security Symposium4
2020 Civet: An Efficient Java Partitioning Framework for Hardware Enclaves
Chia-Che Tsai, Jeongseok Son, Bhushan Jain, John McAvey, Raluca A. Popa, Donald E. Porter
USENIX Security Symposium1
2019 x86-64 instruction usage among C/C++ applications
abstract
This paper presents a study of x86-64 instruction usage across 9,337 C/C++ applications and libraries in the Ubuntu 16.04 GNU/Linux distribution. We present metrics for reasoning about the relative importance of instructions weighted by the popularity of applications that contain them. From this data, we systematize and empirically ground conventional wisdom regarding the relative importance of various components of an ISA, with particular focus on building binary translation tools. We also verify the representativity of two commonly used benchmark suites, and highlight areas for improvement.
Amogh Akshintala, Bhushan Jain, Chia-Che Tsai, Michael Ferdman, Donald E. Porter
SYSTOR3
2017 CCS'17 Tutorial Abstract / SGX Security and Privacy
abstract
In this tutorial, we will first introduce the basic concepts of Intel SGX, its development workflows, potential applications and performance characteristics. Then, we will explain known security concerns, including cache/branch side-channel attacks and memory safety issues, and corresponding defenses with various working demos. Last but not least, we will introduce various ways to quickly start writing SGX applications, especially by utilizing library OSes or thin shielding layers; we will explain the pros and cons of each approach in terms of security and usability.
Taesoo Kim, Zhiqiang Lin 0001, Chia-Che Tsai
CCS3
2017 A Clairvoyant Approach to Evaluating Software (In)Security
abstract
Nearly all modern software has security flaws---either known or unknown by the users. However, metrics for evaluating software security (or lack thereof) are noisy at best. Common evaluation methods include counting the past vulnerabilities of the program, or comparing the size of the Trusted Computing Base (TCB), measured in lines of code (LoC) or binary size. Other than deleting large swaths of code from project, it is difficult to assess whether a code change decreased the likelihood of a future security vulnerability. Developers need a practical, constructive way of evaluating security.
Bhushan Jain, Chia-Che Tsai, Donald E. Porter
HotOS2
2017 Graphene-SGX: A Practical Library OS for Unmodified Applications on SGX
Chia-Che Tsai, Donald E. Porter, Mona Vij
USENIX ATC1
2016 A study of modern Linux API usage and compatibility: what to support when you're supporting
abstract
This paper presents a study of Linux API usage across all applications and libraries in the Ubuntu Linux 15.04 distribution. We propose metrics for reasoning about the importance of various system APIs, including system calls, pseudo-files, and libc functions. Our metrics are designed for evaluating the relative maturity of a prototype system or compatibility layer, and this paper focuses on compatibility with Linux applications. This study uses a combination of static analysis to understand API usage and survey data to weight the relative importance of applications to end users.
Chia-Che Tsai, Bhushan Jain, Nafees Ahmed Abdul, Donald E. Porter
EuroSys1
2015 How to get more value from your file system directory cache
abstract
Applications frequently request file system operations that traverse the file system directory tree, such as opening a file or reading a file's metadata. As a result, caching file system directory structure and metadata in memory is an important performance optimization for an OS kernel.
Chia-Che Tsai, Yang Zhan 0001, Jayashree Reddy, Yizheng Jiao, Tao Zhang 0045, Donald E. Porter
SOSP1
2014 Practical techniques to obviate setuid-to-root binaries
abstract
Trusted, setuid-to-root binaries have been a substantial, long-lived source of privilege escalation vulnerabilities on Unix systems. Prior work on limiting privilege escalation has only considered privilege from the perspective of the administrator, neglecting the perspective of regular users---the primary reason for having setuid-to-root binaries.
Bhushan Jain, Chia-Che Tsai, Jitin John, Donald E. Porter
EuroSys2
2014 Cooperation and security isolation of library OSes for multi-process applications
abstract
Library OSes are a promising approach for applications to efficiently obtain the benefits of virtual machines, including security isolation, host platform compatibility, and migration. Library OSes refactor a traditional OS kernel into an application library, avoiding overheads incurred by duplicate functionality. When compared to running a single application on an OS kernel in a VM, recent library OSes reduce the memory footprint by an order-of-magnitude.
Chia-Che Tsai, Kumar Saurabh Arora, Nehal Bandi, Bhushan Jain, William Jannen, Jitin John, Harry A. Kalodner, Vrushali Kulkarni, Daniela Oliveira 0001, Donald E. Porter
EuroSys1
2013 Virtualize Storage, Not Disks
William Jannen, Chia-Che Tsai, Donald E. Porter
HotOS2
2011 Finding Concurrency Errors in Sequential Code - OS-level, In-vivo Model Checking of Process Races
Oren Laadan, Chia-Che Tsai, Nicolas Viennot, Chris Blinn, Peter Senyao Du, Jason Nieh
HotOS2
2011 Pervasive detection of process races in deployed systems
abstract
Process races occur when multiple processes access shared operating system resources, such as files, without proper synchronization. We present the first study of real process races and the first system designed to detect them. Our study of hundreds of applications shows that process races are numerous, difficult to debug, and a real threat to reliability. To address this problem, we created RacePro, a system for automatically detecting these races. RacePro checks deployed systems in-vivo by recording live executions then deterministically replaying and checking them later. This approach increases checking coverage beyond the configurations or executions covered by software vendors or beta testing sites. RacePro records multiple processes, detects races in the recording among system calls that may concurrently access shared kernel objects, then tries different execution orderings of such system calls to determine which races are harmful and result in failures. To simplify race detection, RacePro models under-specified system calls based on load and store micro-operations. To reduce false positives and negatives, RacePro uses a replay and go-live mechanism to distill harmful races from benign ones. We have implemented RacePro in Linux, shown that it imposes only modest recording overhead, and used it to detect a number of previously unknown bugs in real applications caused by process races.
Oren Laadan, Nicolas Viennot, Chia-Che Tsai, Chris Blinn, Jason Nieh
SOSP3
2010 Stable Deterministic Multithreading through Schedule Memoization
Heming Cui, Jingyue Wu, Chia-Che Tsai
OSDI3