VLDB 2026 Research / reviewers in the wild / expert
Chengxuan Hou
dblp:420/7862
· DBLP profile ↗
1ranked-venue papers
0as first author
1since 2021 · last 2025
0009-0009-4023-6273ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
1 paper |
Systems and software security · 100% | |
| Software engineering, system software, and programming languages
1 paper |
Operating systems · 100% |
Topics — the 2 heaviest of 2, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security › operating system security
privilege separation |
0.9 | 1 | 2025 | Tide: An Efficient Kernel-level Isolation Execution Environment on AArch64 via Dynamically Adjusting Output Address Size · CCS 2025 |
Operating systems › system security › operating system security › protection mechanism › isolation
kernel isolation |
0.9 | 1 | 2025 | Tide: An Efficient Kernel-level Isolation Execution Environment on AArch64 via Dynamically Adjusting Output Address Size · CCS 2025 |
Methods — techniques the papers use, named apart from their topics
stage-2 translation · 1.7output address size · 1.7
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Tide: An Efficient Kernel-level Isolation Execution Environment on AArch64 via Dynamically Adjusting Output Address SizeabstractTo enforce the privilege separation in the kernel, kernel-level isolated execution environment (IEE) has become a recent research trend because it can protect critical resources and monitors. Our research found that to isolate the IEE memory, all existing IEEs must act as a reference monitor to isolate page tables and validate their updates, bringing a significant performance overhead. Hence, we propose Tide, a new kernel-level IEE based on the output address size hardware feature on AArch64, which could offload such checks to the hardware. However, it still faces the flexibility and security challenges. To address them, Tide presents using the stage-2 translation to expand the physical address range to flexibly map the IEE memory and perform extra access controls on the physical memory; it designs a novel gate to enter (sneak) into the IEE securely by disabling translation temporarily, and ensures it can only be executed at the fixed locations. The experimental results show that Tide is performant than all existing IEEs on protecting critical kernel structures and security tools. Shiyang Zhang, Chenggang Wu 0002, Chengxuan Hou, Jinglin Lv, Yinqian Zhang, Yuanming Lai, Mengyao Xie, Yan Kang 0002, Zhe Wang 0017 |
CCS | 3 |