VLDB 2026 Research / reviewers in the wild / expert
Ao Li 0006
dblp:54/2788-6
· DBLP profile ↗
20ranked-venue papers
8as first author
20since 2021 · last 2025
0000-0002-9389-5442ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 2 first-author · 7 since 2021Systems, architecture and hardware · 6 · 2 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 4 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Resilient Federated Learning on Embedded Devices with Constrained Network ConnectivityabstractFederated learning enables decentralized model training while preserving data privacy. However, since the learning process overlays the physical network infrastructure, the efficiency of learning can be impacted by network connectivity. In this work, we conducted extensive experiments to empirically characterize the impacts and leverage the insights to propose an adaptive federation framework, where clients with limited bandwidth are only prompted to transmit adaptively compressed gradient updates when the gradient similarity score is similar between the local and global models. Our evaluation in simulated environments and on real hardware devices shows bandwidth savings of 60% to 78% compared to state-of-the-art methods. Ao Li 0006, Ching-Hsiang Chan, Yevgeniy Vorobeychik, William Yeoh 0001, Wenjing Lou, Ning Zhang 0017 |
DAC | 3 |
| 2025 | Mad Monk: Arbitrary Criticality Escalation in Mixed Criticality Real-Time SystemsabstractIn safety critical computing, real-time and security concerns are often considered separately, though the behavior of a scheduling model itself may be an attack surface which can be exploited by an attacker to reduce system performance. In this work, we explore how the semantics of mode changes in mixed-criticality systems could be used as one such attack vector. This attack, dubbed Mad Monk, uses a mixed criticality scheduler's mode switches against itself by allowing a task of a lower criticality to interfere with tasks of a higher criticality, thereby forcing a disruptive mode switch which could possibly reduce service to some tasks. We describe this attack in detail, along with a case study demonstrating its risk. Furthermore, extensive simulations of this attack demonstrate its potential effectiveness based on a variety of timing and system factors. Mitchell Duncan, Ao Li 0006, Nathan Fisher, Ning Zhang 0017, Ryan M. Gerdes, Tanmaya Mishra, Thidapat Chantem |
ISORC | 2 |
| 2025 | Tintin: A Unified Hardware Performance Profiling Infrastructure to Uncover and Manage Uncertainty
Ao Li 0006, Marion Sudvarg, Sanjoy Baruah, Christopher D. Gill, Ning Zhang 0017 |
OSDI | 1 |
| 2025 | Optimal Priority Assignment for Synchronous Harmonic Tasks with Dynamic Self-SuspensionabstractSelf-suspension behavior happens when a job has to wait for some activity to complete and results in substantial schedulability degradation in real-time systems. Despite extensive studies for self-suspending real-time task systems, the state of the art has barely addressed the optimality of the scheduling algorithms, especially for tasks with dynamic self-suspension. In this paper, we explore optimal priority assignment for periodic real-time tasks with dynamic self-suspension under Task-level Fixed-Priority (T-FP) scheduling. To that end, we provide exact schedulability tests for frame-based and synchronous harmonic tasks. We show that the Suspension-Aware Deadline-Monotonic (SADM) priority assignment is an optimal fixed-priority scheduler for many scenarios. Further, for cases where SADM is not optimal, we adopt Audsley's Optimal Priority Assignment (OPA) approach to derive an optimal fixedpriority assignment. Evaluation results show that the exact tests outperform state-of-the-art schedulability tests from the literature, and that optimal priority assignments significantly improve schedulability over classical priority assignments. Mario Günzel, Marion Sudvarg, Max A. Deppert, Ao Li 0006, Ning Zhang 0017, Jian-Jia Chen |
RTAS | 4 |
| 2025 | Software Availability Protection in Cyber-Physical Systems
Ao Li 0006, Ning Zhang 0017 |
USENIX Security Symposium | 1 |
| 2024 | PhySense: Defending Physically Realizable Attacks for Autonomous Systems via Consistency ReasoningabstractAutonomous vehicles (AVs) empowered by deep neural networks (DNNs) are bringing transformative changes to our society. However, they are generally susceptible to adversarial attacks, especially physically realizable perturbations that can mislead perception and cause catastrophic outcomes. While existing defenses have shown success, there remains a pressing need for improved robustness while maintaining efficiency to meet real-time system operations. Zhiyuan Yu 0001, Ao Li 0006, Ruoyao Wen, Ning Zhang 0017 |
CCS | 2 |
| 2024 | Data-flow Availability: Achieving Timing Assurance in Autonomous Systems
Ao Li 0006, Ning Zhang 0017 |
OSDI | 1 |
| 2024 | An Empirical Study of Performance Interference: Timing Violation Patterns and ImpactsabstractMulti-core platforms are becoming increasingly prevalent in cyber-physical systems such as automobiles and robots. However, contention for shared resources makes it chal-lenging to guarantee timing predictability. Existing studies have primarily focused on characterizing the extent to which such interference can induce delays (usually from an adversarial perspective). Unfortunately, less is understood on the physical impacts of these timing delays in different cyber-physical plat-forms. In this paper, we fill this gap by providing an empirical examination of the end-to-end effects of performance interference on real-world applications. We analyze the root causes of harmful interference and summarize potential implementation pitfalls. To automate this process, we introduce TimeTrap, a tool that analyzes performance interference in autonomous systems through the lens of control outcome. To understand the extent to which timing interference may cause control deviations, TimeTrap has to strategically leverage different magnitudes of resource contention to trigger targeted deadline miss patterns. Through this exercise, we found that a naive approach that maximizes task latency via performance interference may fail to trigger worst-case outcomes (i.e. physical damages) due to built-in fail-safe mechanisms. As a result, delays have to be induced in a stealthy manner to avoid triggering fail-safes. To achieve this, TimeTrap first employs a system that actively injects fine-grained delays into the target software, adjusting the duration based on measured feedback. Second, TimeTrap leverages predictability in CPS execution patterns and resource usage to automatically tune its aggressor workloads, matching these patterns to achieve targeted interference and execution delays in a victim. We evaluate TimeTrap on two physical-world platforms and six platforms in a hardware-in-the-Ioop simulation environment, including robotic arms, UGVs, UAVs, self-driving cars, and humanoid robots. These studies demonstrate that an interference-based attack surface exists in different stages of the CPS pipeline, from perception to planning and control. Ao Li 0006, Sanjoy Baruah, Bruno Sinopoli, Ning Zhang 0017 |
RTAS | 1 |
| 2024 | Elastic Scheduling for Harmonic Task SystemsabstractElastic scheduling is a framework to reduce task utilizations (often by increasing periods) in response to system overload. This paper extends elastic scheduling to uniprocessor scheduling of implicit-deadline task sets for which periods must remain harmonic. We argue that for tasks with periods constrained to continuous intervals, the problem of selecting harmonic periods from those intervals is unlikely to have a polynomial time solution. However, we outline an approach that is pseudo-polynomial in the range of acceptable periods. We then show that the problem of elastic scheduling is NP-hard with harmonic constraints. Nonetheless, if a total order is imposed on task periods (a natural restriction in many applications with execution pipelines that synchronize input data sources), the problem can be reduced offline to a lookup table, enabling polynomial-time online adaptation if available CPU bandwidth changes. We implement the proposed algorithm in two real-world applications: the Fast Integrated Mobility Spectrometer (FIMS) and ORB-SLAM3. We demonstrate that elastic scheduling allows FIMS to adjust its execution to avoid missing deadlines on a SWaP-constrained computational platform, and that it improves ORB-SLAM3's localization results by as much as lO.4x when available CPU bandwidth changes dynamically during runtime. Marion Sudvarg, Ao Li 0006, Daisy Wang, Sanjoy Baruah, Jeremy Buhler, Christopher D. Gill, Ning Zhang 0017, Pontus Ekberg |
RTAS | 2 |
| 2024 | Opportunistic Data Flow Integrity for Real-time Cyber-physical Systems Using Worst Case Execution Time Reservation
Ao Li 0006, Sanjoy Baruah, Ning Zhang 0017 |
USENIX Security Symposium | 2 |
| 2024 | Priority-based concurrency and shared resource access mechanisms for nested intercomponent requests in CAmkES
Marion Sudvarg, Ao Li 0006, Christopher D. Gill, Ning Zhang 0017 |
Real Time Syst. | 3 |
| 2023 | Who's Afraid of Butterflies? A Close Examination of the Butterfly AttackabstractThe Butterfly Attack, introduced in an RTSS 2019 paper, was billed as a new kind of timing attack against control loops in cyber-physical systems. We conduct a close inspection of the Butterfly Attack in order to identify the root vulnerability that it exploits, and show that an appropriate application of real-time scheduling theory provides an effective countermeasure. We propose improved defenses against this and similar attacks by drawing upon techniques from real-time scheduling theory, control theory, and systems implementation, that are both provably secure and are able to make efficient use of computing resources. Sanjoy Baruah, Pontus Ekberg, Mehdi Hosseinzadeh 0002, Ao Li 0006, Bryan C. Ward, Ning Zhang 0017 |
RTSS | 4 |
| 2023 | ARI: Attestation of Real-time Mission Execution Integrity
Ao Li 0006, Yang Xiao 0010, Ruide Zhang, Wenjing Lou, Y. Thomas Hou 0001, Ning Zhang 0017 |
USENIX Security Symposium | 3 |
| 2023 | MS-PTP: Protecting Network Timing from Byzantine AttacksabstractTime-sensitive applications, such as 5G and IoT, are imposing increasingly stringent security and reliability requirements on network time synchronization. Precision time protocol (PTP) is a de facto solution to achieve high precision time synchronization. It is widely adopted by many industries. Existing efforts in securing the PTP focus on the protection of communication channels, but little attention has been given to the threat of malicious insiders. In this paper, we first present the security vulnerabilities of PTP and discuss why the current defense mechanisms are unable to counter Byzantine insiders. We demonstrate how a malicious insider can spoof a time source to arbitrarily shift the system time of a victim node on an IoT testbed. We further demonstrate the harmful consequence of the attack on a real Turtlebot3 robotic platform as the robot fails to locate itself and follows a false trajectory. As a countermeasure, we propose multi-source PTP, in short, MS-PTP, a Byzantine-resilient network time synchronization mechanism that relies on time crowdsourcing. MS-PTP changes the current PTP's single source hierarchy to a multi-source client-server architecture, in which PTP clients take responses from multiple time servers and apply a novel secure aggregation scheme to eliminate the effect of malicious responses from unreliable sources. MS-PTP is able to counter f Byzantine failures when the total number of time sources n used by a client satisfies n>=3f+1. We provide rigorous proof for its non-parametric accuracy guarantee---achieving bounded error regardless of the Byzantine population. We implemented a prototype of MS-PTP on our IoT testbed and the results show its resilience against Byzantine insiders while maintaining high synchronization accuracy. Shanghao Shi, Yang Xiao 0010, Changlai Du, Md Hasan Shahriar, Ao Li 0006, Ning Zhang 0017, Y. Thomas Hou 0001, Wenjing Lou |
WISEC | 5 |
| 2022 | From Timing Variations to Performance Degradation: Understanding and Mitigating the Impact of Software Execution Timing in SLAMabstractTiming is an important property for robotic systems that continuously interact with our physical world. Variation in program execution time caused by limited computational resources or system resource contention can lead to significant impact on algorithmic result accuracy. Even though recent work has found Simultaneous Localization And Mapping (SLAM) to be timing-sensitive, little exists in understanding the interactions between the timing variations in SLAM systems and the corresponding degradation. In this paper we conduct a systematic analysis of nine state-of-the-art SLAM systems and dissect the root causes of their degradation. We discovered that timing-induced errors are generated either from delayed execution in certain critical tasks, or from desynchronization in sensor fusion. Based on the insights from our analysis, we propose a solution that combines selective fusion on data in the front end and temporal budget optimization on bundle adjust-ment in the backend to mitigate the impacts of unexpected timing variation adaptively. Experimental results show that our proposed method makes it possible to migrate expensive algorithms to low-cost platforms without laborious tuning, while making the SLAM system robust against the effects of abnormal timing. Ao Li 0006, Ning Zhang 0017 |
IROS | 1 |
| 2022 | PolyRhythm: Adaptive Tuning of a Multi-Channel Attack Template for Timing InterferenceabstractAs cyber-physical systems have become increasingly complex, rising computational demand has led to the ubiquitous use of multicore processors in embedded environments. Size, Weight, Power, and Cost (SWaP-C) constraints have pushed more processes onto shared platforms, including real-time tasks with deadline requirements. To prevent temporal interference among tasks running concurrently or in parallel in such systems, many operating systems provide priority-based scheduling and enforce processor reservations based on Worst-Case Execution Time (WCET) estimates. However, shared resources (both architectural components and data structures within the operating system) provide channels through which these constraints can be broken. Prior work has demonstrated that malicious execution by one or more processes can cause significant delays, leading to potential deadline misses in victim tasks. In this paper, we introduce PolyRhythm, a three-phase attack template that combines primitives across multiple architectural and kernel-based channels: (1) it uses an offline genetic algorithm to tune attack parameters based on the target hardware and OS platform; then (2) it performs an online search for regions of the attack parameter space where contention is most likely; and finally (3) it runs the attack primitives, using online reinforcement learning to adapt to dynamic execution patterns in the victim task. On a representative platform (Raspberry Pi 3B) Poly Rhythm outperforms prior work, achieving significantly more slowdown. As we show for several hardware/software platforms, Poly Rhythm also allows us to characterize the extent to which interference can occur; this helps to inform better estimates of execution times and overheads, towards preventing deadline misses in real-time systems. Ao Li 0006, Marion Sudvarg, Zhiyuan Yu 0001, Christopher D. Gill, Ning Zhang 0017 |
RTSS | 1 |
| 2022 | Work-in-Progress: Measuring Security Protection in Real-time Embedded FirmwareabstractThe proliferation of real-time cyber-physical systems (CPS) is making profound changes to our daily life. Many real-time CPSs are security and safety-critical because of their continuous interactions with the physical world. While the general perception is that the security protection mechanism deployment is often absent in real-time embedded systems, there is no existing empirical study that measures the adoption of these mechanisms in the ecosystem. To bridge this gap, we conduct a measurement study for real-time embedded firmware from both a security perspective and a real-time perspective. To begin with, we collected more than 16 terabytes of embedded firmware and sampled 1,000 of them for the study. Then, we analyzed the adoption of security protection mechanisms and their potential impacts on the timeliness of real-time embedded systems. Besides, we measured the scheduling algorithms supported by real-time embedded systems since they are also security-critical. Yuhao Wu 0006, Shixuan Zhai, Ao Li 0006, Ning Zhang 0017 |
RTSS | 5 |
| 2022 | RT-TEE: Real-time System Availability for Cyber-physical Systems using ARM TrustZoneabstractEmbedded devices are becoming increasingly pervasive in safety-critical systems of the emerging cyber-physical world. While trusted execution environments (TEEs), such as ARM TrustZone, have been widely deployed in mobile platforms, little attention has been given to deployment on real-time cyber-physical systems, which present a different set of challenges compared to mobile applications. For safety-critical cyber-physical systems, such as autonomous drones or automobiles, the current TEE deployment paradigm, which focuses only on confidentiality and integrity, is insufficient. Computation in these systems also needs to be completed in a timely manner (e.g., before the car hits a pedestrian), putting a much stronger emphasis on availability.To bridge this gap, we present RT-TEE, a real-time trusted execution environment. There are three key research challenges. First, RT-TEE bootstraps the ability to ensure availability using a minimal set of hardware primitives on commodity embedded platforms. Second, to balance real-time performance and scheduler complexity, we designed a policy-based event-driven hierarchical scheduler. Third, to mitigate the risks of having device drivers in the secure environment, we designed an I/O reference monitor that leverages software sandboxing and driver debloating to provide fine-grained access control on peripherals while minimizing the trusted computing base (TCB).We implemented prototypes on both ARMv8-A and ARMv8-M platforms. The system is tested on both synthetic tasks and real-life CPS applications. We evaluated rover and plane in simulation and quadcopter both in simulation and with a real drone. Ao Li 0006, Chenyang Lu 0001, Ning Zhang 0017 |
SP | 2 |
| 2022 | SceGene: Bio-Inspired Traffic Scenario Generation for Autonomous Driving TestingabstractThe core value of simulation-based autonomy tests is to create densely extreme traffic scenarios to test the performance and robustness of the algorithms and systems. Test scenarios are usually designed or extracted manually from the real-world data, which is inefficient with a remarkable domain gap compared with testing in real scenarios. Therefore, it is crucial to automatically generate realistic and diverse dynamic traffic scenarios making autonomy tests efficient. Moreover, scenario generation is expected to be interpretable, controllable, and diversified, which can be hard to achieve simultaneously by methods based on rules or deep networks. In this paper, we propose a dynamic traffic scenario generation method called SceGene, inspired by genetic inheritance and mutation processes in biological intelligence. SceGene applies biological processes, such as crossover and mutation, to exchange and mutate the content of scenarios, and involves the natural selection process to control generation direction. SceGene has three main parts: 1) a new representation method for describing the traffic scenarios’ feature; 2) a new scenario generation algorithm based on crossover, mutation, and selection; and 3) an abnormal scenario information repair method based on the microscopic driving model. Evaluation on the public traffic scenario dataset shows that SceGene can ensure highly realistic and diversified scenario generation in an interpretable and controllable way, significantly improving the efficiency of the simulation-based autonomy tests. Ao Li 0006, Shi-tao Chen, Nanning Zheng 0001, Masayoshi Tomizuka |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2021 | Chronos: Timing Interference as a New Attack Vector on Autonomous Cyber-physical SystemsabstractTiming property plays a vital role in the Cyber-Physical System(CPS) due to its interaction with the physical world. The smooth operation of these robotic systems often relies on an accurate and timely perception and actuation of the physical world. In this poster, we demonstrated a unique new class of attack, Chronos, that exploits timing interference to cause system destabilization in cyber-physical systems. Using a compromised non-privileged non-critical task on the system, we launch timing interference attacks on both drone and autonomous vehicle platforms. Through both open-loop and close-loop testing on the end-to-end stack, we showed that the timing attack could lead to complete loss of control of the autonomous system, crashing them onto the surroundings when there is no software vulnerability. To further understand this novel attack vector, we perform preliminary investigations on the localization component of these two platforms, because they both make use of well-known simultaneous localization and mapping (SLAM) algorithms that depend on timing-sensitive multimodal data from different sensors. Building on the insights from the case study, we present our formulation of the timing attack surface and highlight future directions. Ao Li 0006, Ning Zhang 0017 |
CCS | 1 |