Hongliang Tian

dblp:53/7761 · DBLP profile ↗
← Back
16ranked-venue papers
3as first author
12since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 6 · 1 first-author · 5 since 2021Software engineering, systems software and programming languages · 4 · 3 since 2021Databases, data management, data science and information retrieval · 4 · 2 first-author · 2 since 2021Security and privacy · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 first-author
YearPublicationVenuePosition
2026 Pyramid: A Secure, Resource-Efficient, and Pluggable Kubernetes for Multi-Tenancy
abstract
This work aims to achieve the best of both worlds with two prominent techniques adopted in cloud computing systems: hardware trusted execution environments (TEEs) for data processing security, and Kubernetes (k8s) for efficient container orchestration and resource management for multi-tenancy. A secure, resource-efficient, and pluggable container orchestration system, called Pyramid, is proposed, which incurs minimal intrusive modifications to the commercial k8s. Pyramid puts a separate trusted k8s on top of the original k8s cluster and carefully cooperates between the two layers. The workflow within each layer is maximally preserved without significant changes. The untrusted layer manages resource scheduling across different tenants to improve utilization and passes the resource information to the trusted layer to launch actual computations secured by TEEs, with the help of carefully designed interface and protection mechanisms. Evaluation results show that Pyramid achieves 1.4X higher throughput on the data plane, with comparable control-plane performance to previous work.
Xiang Li 0156, Weijie Liu 0004, Fabing Li, Hongliang Tian, Zheli Liu, Shoumeng Yan, Mingyu Gao 0001
EuroSys4
2026 MlsDisk: Trusted Block Storage for TEEs Based on Layered Secure Logging
Erci Xu, Lujia Yin, Xinyuan Luo, Shaowei Song, Qingsong Chen, Shoumeng Yan, Jiwu Shu, Hongliang Tian, Yiming Zhang 0003
FAST9
2026 Keystone-Vault: Hardware-Assisted Efficient Intra-Enclave Isolation for RISC-V TEEs
Tianming Yan, Kun Yang 0012, Hongliang Tian, Shoumeng Yan, Kui Ren 0001
IEEE Trans. Computers3
2026 CROSS-TEE: A Distributed Trusted Execution Environment Architecture for Cross-Module Automotive Security
Kun Yang 0012, Hongliang Tian, Shoumeng Yan, Kui Ren 0001
IEEE Trans. Inf. Forensics Secur.3
2025 AtomicDisk: A Secure Virtual Disk for TEEs against Eviction Attacks
Hongliang Tian, Shaowei Song, Qingsong Chen, Weijie Liu 0004, Erci Xu, Shoumeng Yan, Yiming Zhang 0003
FAST1
2025 CortenMM: Efficient Memory Management with Strong Correctness Guarantees
abstract
Modern memory management systems suffer from poor performance and subtle concurrency bugs, slowing down applications while introducing security vulnerabilities. We observe that both issues stem from the conventional design of memory management systems with two levels of abstraction: a software-level abstraction (e.g., VMA trees in Linux) and a hardware-level abstraction (typically, page tables). This design increases portability but requires correctly and efficiently synchronizing two drastically different and complex data structures, which is generally challenging.
Junyang Zhang 0003, Xiangcan Xu, Yonghao Zou, Xinyi Wan 0001, Siyuan Wang 0026, Di Wang 0017, Hao Chen 0023, Lin Huang 0005, Shoumeng Yan, Yuval Tamir, Yingwei Luo, Xiaolin Wang 0001, Huashan Yu, Zhenlin Wang 0003, Hongliang Tian, Diyu Zhou
SOSP18
2025 ASTERINAS: A Linux ABI-Compatible, Rust-Based Framekernel OS with a Small and Sound TCB
Yuke Peng, Hongliang Tian, Junyang Zhang 0003, Jinyi Xian, Xiaolin Wang 0001, Chenren Xu, Diyu Zhou, Yingwei Luo, Shoumeng Yan, Yinqian Zhang
USENIX ATC2
2025 Modeling and optimization of trajectory deviation for compound directional drilling in coal mines
Wangnian Li, Chengda Lu, Quanxin Li, Hengyu Huang, Haipeng Fan, Ningping Yao, Hongliang Tian, Min Wu 0002
Neurocomputing10
2024 rCanary: Detecting Memory Leaks Across Semi-Automated Memory Management Boundary in Rust
abstract
Rust is an effective system programming language that guarantees memory safety via compile-time verifications. It employs a novel ownership-based resource management model to facilitate automated deallocation. This model is anticipated to eliminate memory leaks. However, we observed that user intervention drives it into semi-automated memory management and makes it error-prone to cause leaks. In contrast to violating memory-safety guarantees restricted by theunsafekeyword, the boundary of leaking memory is implicit, and the compiler would not emit any warnings for developers. In this paper, we presentrCanary, a static, non-intrusive, and fully automated model checker to detect leaks across the semi-automated boundary. We design an encoder to abstract data with heap allocation and formalize a refined leak-free memory model based on boolean satisfiability. It can generate SMT-Lib2 format constraints for Rust MIR and is implemented as a Cargo component. We evaluaterCanaryby using flawed package benchmarks collected from the pull requests of open-source Rust projects. The results indicate that it is possible to recall all these defects with acceptable false positives. We further apply our tool to more than 1,200 real-world crates from crates.io and GitHub, identifying 19 crates having memory leaks. Our analyzer is also efficient, that costs 8.4 seconds per package.
Mohan Cui, Hui Xu 0009, Hongliang Tian, Yangfan Zhou 0002
IEEE Trans. Software Eng.3
2023 Lost along the Way: Understanding and Mitigating Path-Misresolution Threats to Container Isolation
abstract
Filesystem isolation enforced by today's container technology has been found to be less effective in the presence of host-container interactions increasingly utilized by container tools. This weakened isolation has led to a type of path misresolution (Pamir) vulnerabilities, which have been considered to be highly risky and continuously reported over the years. In this paper, we present the first systematic study on the Pamir risk and the existing fixes to related vulnerabilities. Our research reveals that in spite of significant efforts being made to patch vulnerable container tools and address the risk, the Pamir vulnerabilities continue to be discovered, including a new vulnerability (CVE-2023-0778) we rediscovered from patched software. A key insight of our study is that the Pamir risk is inherently hard to prevent at the level of container tools, due to their heavy reliance on third-party components. While security inspections should be applied to all components to mediate host-container interactions, third-party component developers tend to believe that container tools should perform security checks before invoking their components, and are therefore reluctant to patch their code with the container-specific protection. Moreover, due to the large number of components today's container tools depend on, re-implementing all of them is impractical.
Zhi Li 0048, Weijie Liu 0004, XiaoFeng Wang 0001, Bin Yuan 0002, Hongliang Tian, Hai Jin 0001, Shoumeng Yan
CCS5
2023 OOM-Guard: Towards Improving the Ergonomics of Rust OOM Handling via a Reservation-Based Approach
abstract
Out of memory (OOM) is an exceptional system state where any further memory allocation requests may fail. Such allocation failures would crash the process or system if not handled properly, and they may also lead to an inconsistent program state that cannot be recovered easily. Current mechanisms for preventing such hazards highly rely on the manual effort of the programmers themselves. This paper studies the OOM issues of Rust, which is an emerging system programming language that stresses the importance of memory safety but still lacks handy mechanisms to handle OOM well. Even worse, Rust employs an infallible mode of memory allocations by default. As a result, the program written by Rust would simply abort itself when OOM occurs. Such crashes would lead to critical robustness issues for services or modules of operating systems. We propose OOM-Guard, a handy approach for Rust programmers to handle OOM. OOM-Guard is by nature a reservation-based approach that aims to convert the handlings for many possible failed memory allocations into handlings for a smaller number of reservations. In order to achieve efficient reservation, OOM-Guard incorporates a subtle cost analysis algorithm based on static analysis and a proxy allocator. We then apply OOM-Guard to two well-known Rust projects, Bento and rCore. Results show that OOM-Guard can largely reduce developers' efforts for handling OOM and incurs trivial overhead in both memory space and execution time.
Hongliang Tian, Shoumeng Yan, Hui Xu 0009
ESEC/SIGSOFT FSE3
2023 Trust Beyond Border: Lightweight, Verifiable User Isolation for Protecting In-Enclave Services
abstract
Due to the absence of in-enclave isolation, today's trusted execution environment (TEE), specifically Intel's Software Guard Extensions (SGX), does not have the capability to securely run different users’ tasks within a single enclave, which is required for supporting real-world services, such as an in-enclave machine learning model that classifies the data from various sources, or a microservice (e.g., data search) that performs a very small task (within sub-seconds) for a user and therefore cannot afford the resources and the delay for creating a separate enclave for each user. To address this challenge, we developedLiveries, a technique that enables lightweight, verifiable in-enclave user isolation for protecting time-sharing services. Our approach restricts an in-enclave thread's privilege when configuring an enclave, and further performs integrity check and sanitization on critical enclave data upon user switches. For this purpose, we developed a novel technique that ensures the protection of sensitive user data (e.g., session keys) even in the presence of the adversary who may have compromised the enclave. Our study shows that the new technique is lightweight (1% overhead) and verifiable (about 3200 lines of code), making a step towards assured protection of real-world in-enclave services.
Wenhao Wang 0001, Weijie Liu 0004, XiaoFeng Wang 0001, Hongliang Tian, Dongdai Lin
IEEE Trans. Dependable Secur. Comput.5
2020 Occlum: Secure and Efficient Multitasking Inside a Single Enclave of Intel SGX
abstract
Intel Software Guard Extensions (SGX) enables user-level code to create private memory regions called enclaves, whose code and data are protected by the CPU from software and hardware attacks outside the enclaves. Recent work introduces library operating systems (LibOSes) to SGX so that legacy applications can run inside enclaves with few or even no modifications. As virtually any non-trivial application demands multiple processes, it is essential for LibOSes to support multitasking. However, none of the existing SGX LibOSes support multitasking both securely and efficiently.
Youren Shen, Hongliang Tian, Yu Chen 0004, Kang Chen 0001, Runji Wang, Yubin Xia, Shoumeng Yan
ASPLOS2
2020 Research on distributed blockchain-based privacy-preserving and data security framework in IoT
abstract
With the rapid development of the Internet of things (IoT), it has brought great convenience for people's life. However, the security and privacy of IoT still face a major challenge. To remedy these issues, in this study, the authors first introduce the three‐tier architecture of IoT and analyse the corresponding security problems of each layer, then they discussed the compatibility between IoT and blockchain. Secondly, they propose a new, distributed blockchain‐based security architecture of IoT, which rely on gateway nodes of perception layer to secure data storage and sharing, and use middleware servers to analyse and process data. Finally, they adopt game theory to model and analyse their designed scheme. The results demonstrate that their scheme is a safe and deployable framework for IoT data security and privacy.
Hongliang Tian, Xiaonan Ge, Hongle Pan
IET Commun.1
2017 When Will a Repost Cascade Settle Down?
Chi Chen 0005, Hongliang Tian, Jie Tang 0001, Chunxiao Xing
WISE (1)2
2012 Layout-Conscious Optimization: Beyond Hybrid Row-Column Storage Model
abstract
Hybrid row-column storage model [1][4], a common database approach for both OLTP and OLAP, have attracted a lot of attention in the past few years. Previous works about hybrid row-column approach mainly focus on physical storage. In this paper, we propose the idea of Layout-Conscious Optimization(LCO), techniques that fully exploits possibilities and take advantages of hybrid row-column data layout in all layers of DBMS, e.g., physical storage, query processing as well as network transfer. We believe LCO offer new opportunities to improve the performance of DBMS. To demonstrate the power of LCO, we present the design of a row-column hybrid network transfer protocol for DBMS, which reduces data transfer by 75% while incurs little extra cost on CPU.
Hongliang Tian, Chunxiao Xing
WISA1