VLDB 2026 Research / reviewers in the wild / expert
Zechao Cai
dblp:353/7550
· DBLP profile ↗
5ranked-venue papers
1as first author
5since 2021 · last 2026
0009-0008-8354-9985ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Resolve the Unresolved: Systematic Work Profiling for DNS Resolvers
Huayi Duan, Zechao Cai, Adrian Perrig |
SP | 3 |
| 2026 | M1Pecker: A Dynamic Analysis Framework for Pointer Authentication in Apple M1 ChipsabstractPointer Authentication (PA) was introduced by ARMv8.3 to safeguard the integrity of pointers. While ARM specification allows vendors to implement and customize PA, Apple has tailored it to protect iPhones and Macs with M-series chips on their hardware. Since its debut, Apple PA has been considered to introduce domain isolation to defeat pointer corruption. However, its details have not been publicly disclosed. To shed light on Apple PA customization, this paper first establishes a security model for PA that defines expected properties for cross-domain and intra-domain isolation. We then introduce M1Pecker, a novel analysis framework built upon our Trap-Relay-Based Automated Analysis technique, to evaluate Apple's hardware and software dynamically and automatically against this model. Based on our framework, we perform a comprehensive kernel analysis that combines static and dynamic approaches. We confirm that Apple PA employs multiple diversifiers that robustly satisfy our model's cross-domain isolation property. In contrast, our intra-domain analysis of the XNU kernel identifies violations of intra-domain properties, resulting in four attack surfaces. Apple has fixed these issues in a security update, assigned us a new CVE, and publicly acknowledged our findings. Jiaxun Zhu, Zechao Cai, Wenbo Shen, Yutian Yang |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Chekhov's Gun: Uncovering Hidden Risks in macOS Application-Sandboxed PID-Domain ServicesabstractmacOS delegates many high-privilege operations to dedicated PID-domain services, which applications can register and communicate with through inter-process communication (IPC). This architecture improves userland stability and security but also introduces attractive attack surfaces for adversaries. In this paper, we systematically analyze PID-domain services and uncover an overlooked attack vector: PID-domain services that are restricted to an Application Sandbox identical to the calling application can still be exploited due to subtle entitlement differences. Minghao Lin, Jiaxun Zhu, Tingting Yin, Zechao Cai, Guanxing Wen, Yanan Guo 0002, Mengyuan Li 0004 |
CCS | 4 |
| 2024 | CrossFire: Fuzzing macOS Cross-XPU Memory on Apple SiliconabstractModern computing systems increasingly utilize XPUs, such as GPUs and NPUs, for specialized computation tasks.While these XPUs provide critical functionalities, their security protections are generally weaker than those of CPUs, making them attractive attack targets.In particular, Apple silicon optimizes memory usage by adopting a unified memory architecture (UMA), which employs shared memory regions (termed cross-XPU memory) to facilitate communication between CPUs and XPUs.Although the cross-XPU memory enhances performance, it also introduces a new attack surface.Unfortunately, the difficulty in identifying effective shared memory regions and generating valid payloads makes fuzzing cross-XPU memory a challenging problem that cannot be resolved effectively by existing fuzzing techniques.Therefore, we propose CrossFire, the first fuzzer targeting Apple silicon XPU by fuzzing cross-XPU memory, to evaluate this new attack surface.Initially, we conduct an in-depth cross-XPU memory analysis to investigate the challenges of fuzzing XPU.To address these challenges, CrossFire introduces two novel techniques to pinpoint effective fuzzing regions in cross-XPU memory and trace kernel execution information to extract data constraints.Leveraging these techniques, we develop CrossFire based on the m1n1 hypervisor to monitor cross-XPU memory accesses and perform grey-box hooking-based fuzzing.We further evaluate CrossFire on macOS Ventura, where it has identified 15 new zero-day bugs, 8 of which have been confirmed by Apple. Jiaxun Zhu, Minghao Lin, Tingting Yin, Zechao Cai, Yu Wang 0229, Wenbo Shen |
CCS | 4 |
| 2023 | Demystifying Pointer Authentication on Apple M1
Zechao Cai, Jiaxun Zhu, Wenbo Shen, Yutian Yang, Jinku Li, Kui Ren 0001 |
USENIX Security Symposium | 1 |