VLDB 2026 Research / reviewers in the wild / expert
Weijie Liu 0004
dblp:90/5130-4
· DBLP profile ↗
17ranked-venue papers
3as first author
10since 2021 · last 2026
0000-0002-3054-766XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 3 first-author · 5 since 2021Systems, architecture and hardware · 5 · 1 first-author · 4 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Pyramid: A Secure, Resource-Efficient, and Pluggable Kubernetes for Multi-TenancyabstractThis work aims to achieve the best of both worlds with two prominent techniques adopted in cloud computing systems: hardware trusted execution environments (TEEs) for data processing security, and Kubernetes (k8s) for efficient container orchestration and resource management for multi-tenancy. A secure, resource-efficient, and pluggable container orchestration system, called Pyramid, is proposed, which incurs minimal intrusive modifications to the commercial k8s. Pyramid puts a separate trusted k8s on top of the original k8s cluster and carefully cooperates between the two layers. The workflow within each layer is maximally preserved without significant changes. The untrusted layer manages resource scheduling across different tenants to improve utilization and passes the resource information to the trusted layer to launch actual computations secured by TEEs, with the help of carefully designed interface and protection mechanisms. Evaluation results show that Pyramid achieves 1.4X higher throughput on the data plane, with comparable control-plane performance to previous work. Xiang Li 0156, Weijie Liu 0004, Fabing Li, Hongliang Tian, Zheli Liu, Shoumeng Yan, Mingyu Gao 0001 |
EuroSys | 2 |
| 2025 | AtomicDisk: A Secure Virtual Disk for TEEs against Eviction Attacks
Hongliang Tian, Shaowei Song, Qingsong Chen, Weijie Liu 0004, Erci Xu, Shoumeng Yan, Yiming Zhang 0003 |
FAST | 7 |
| 2023 | Lost along the Way: Understanding and Mitigating Path-Misresolution Threats to Container IsolationabstractFilesystem isolation enforced by today's container technology has been found to be less effective in the presence of host-container interactions increasingly utilized by container tools. This weakened isolation has led to a type of path misresolution (Pamir) vulnerabilities, which have been considered to be highly risky and continuously reported over the years. In this paper, we present the first systematic study on the Pamir risk and the existing fixes to related vulnerabilities. Our research reveals that in spite of significant efforts being made to patch vulnerable container tools and address the risk, the Pamir vulnerabilities continue to be discovered, including a new vulnerability (CVE-2023-0778) we rediscovered from patched software. A key insight of our study is that the Pamir risk is inherently hard to prevent at the level of container tools, due to their heavy reliance on third-party components. While security inspections should be applied to all components to mediate host-container interactions, third-party component developers tend to believe that container tools should perform security checks before invoking their components, and are therefore reluctant to patch their code with the container-specific protection. Moreover, due to the large number of components today's container tools depend on, re-implementing all of them is impractical. Zhi Li 0048, Weijie Liu 0004, XiaoFeng Wang 0001, Bin Yuan 0002, Hongliang Tian, Hai Jin 0001, Shoumeng Yan |
CCS | 2 |
| 2023 | Trust Beyond Border: Lightweight, Verifiable User Isolation for Protecting In-Enclave ServicesabstractDue to the absence of in-enclave isolation, today's trusted execution environment (TEE), specifically Intel's Software Guard Extensions (SGX), does not have the capability to securely run different users’ tasks within a single enclave, which is required for supporting real-world services, such as an in-enclave machine learning model that classifies the data from various sources, or a microservice (e.g., data search) that performs a very small task (within sub-seconds) for a user and therefore cannot afford the resources and the delay for creating a separate enclave for each user. To address this challenge, we developedLiveries, a technique that enables lightweight, verifiable in-enclave user isolation for protecting time-sharing services. Our approach restricts an in-enclave thread's privilege when configuring an enclave, and further performs integrity check and sanitization on critical enclave data upon user switches. For this purpose, we developed a novel technique that ensures the protection of sensitive user data (e.g., session keys) even in the presence of the adversary who may have compromised the enclave. Our study shows that the new technique is lightweight (1% overhead) and verifiable (about 3200 lines of code), making a step towards assured protection of real-world in-enclave services. Wenhao Wang 0001, Weijie Liu 0004, XiaoFeng Wang 0001, Hongliang Tian, Dongdai Lin |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Robbery on DevOps: Understanding and Mitigating Illicit Cryptomining on Continuous Integration Service PlatformsabstractThe recent wave of in-browser cryptojacking has ebbed away, due to the new updates of mainstream cryptocurrrencies, which demand the level of mining resources browsers cannot afford. As replacements, resource-rich, loosely protected free Internet services, such as Continuous Integration (CI) platforms, have become attractive targets. In this paper, we report a systematic study on real-world illicit cryptomining on public CI platforms (called Cijacking). Unlike in-browser cryptojacking, Cijacks masquerade as CI jobs and are therefore more difficult to detect, since legitimate CI workflows such as container image building and testing also entail intensive computing. In our research, we leveraged the critical mining information the adversary has to specify, such as wallet addresses and mining pool domains, to recover the attack traces from GitHub repositories and the log files on CI platforms, leading to the discovery of 1,974 Cijacking instances, 30 campaigns across 12 different cryptocurrencies on 11 mainstream CI platforms. Further, our study unveils the evolution of attack strategies, in response to the protection put in place by the platforms, the duration of the mining jobs (as long as 33 months), and their lifecycle. Further discovered is the revenue of the attack, over ${\$}$20,000 per month. Since robust detection of cryptojacking is known to be hard, we developed a novel technique, called Cijitter, to strategically inject delays to the execution of a CI workflow to disproportionally penalize the mining jobs that need to work on a series of tasks under time constraints. Our analysis and evaluation, as conducted on both benchmarks and common CI jobs, show that our approach substantially suppresses the miner’s revenues, rendering them unprofitable, but only has small impacts on the performance of CI jobs and developer productivity (94.3% of CI jobs see a less than 10% delay). Zhi Li 0048, Weijie Liu 0004, XiaoFeng Wang 0001, Xiaojing Liao, Luyi Xing, Mingming Zha 0001, Hai Jin 0001, Deqing Zou |
SP | 2 |
| 2022 | The evolving privacy and security concerns for genomic data analysis and sharing as observed from the iDASH competitionabstractConcerns regarding inappropriate leakage of sensitive personal information as well as unauthorized data use are increasing with the growth of genomic data repositories. Therefore, privacy and security of genomic data have become increasingly important and need to be studied. With many proposed protection techniques, their applicability in support of biomedical research should be well understood. For this purpose, we have organized a community effort in the past 8 years through the integrating data for analysis, anonymization and sharing consortium to address this practical challenge. In this article, we summarize our experience from these competitions, report lessons learned from the events in 2020/2021 as examples, and discuss potential future research directions in this emerging field. Tsung-Ting Kuo, Xiaoqian Jiang, Haixu Tang, XiaoFeng Wang 0001, Arif Ozgun Harmanci, Miran Kim, Kai W. Post, Diyue Bu, Tyler Bath, Jihoon Kim 0001, Weijie Liu 0004, Lucila Ohno-Machado |
J. Am. Medical Informatics Assoc. | 11 |
| 2022 | Retrofitting LBR Profiling to Enhance Virtual Machine IntrospectionabstractCloud attack provenance is a well-established industrial practice for assuring transparency and accountability for a service provider to tenants. However, the multi-tenancy and self-service nature coupled with the sheer size of a cloud implies many unique challenges to cloud forensics. Although Virtual Machine Introspection (VMI) is a powerful tool for attack provenance due to the privilege isolation, the stealthiness of state-of-the-art attacks and the lack of precise information make existing attack provenance solutions difficult to fulfill real-time forensics when tracking enormous suspicious behaviors. To this end, we propose an instruction-level tracing framework for inspecting the presence of attacks by dynamically tracking shared processor hardware event patterns and analyzing the attack traces. To overcome the challenges of real-time detection and provenance, we advocate Last Branch Record (LBR) profiling, to extract the suspicious execution flows. With the hardware assistance and software-based virtualization introspection, we show that the framework can provide an effective response to threats in different cases, thereby enabling a quick attack provenance with high fidelity. The evaluation shows that our prototype introduces negligible performance penalties. Weijie Liu 0004, Ximeng Liu, Zhi Li 0048, Bin Liu 0029, Rongwei Yu, Lina Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2021 | HySec-Flow: Privacy-Preserving Genomic Computing with SGX-based Big-Data Analytics FrameworkabstractTrusted execution environments (TEE) such as Intel's Software Guard Extension (SGX) have been widely studied to boost security and privacy protection for the computation of sensitive data such as human genomics. However, a performance hurdle is often generated by SGX, especially from the small enclave memory. In this paper, we propose a new Hybrid Secured Flow framework (called "HySec-Flow") for large-scale genomic data analysis using SGX platforms. Here, the data-intensive computing tasks can be partitioned into independent subtasks to be deployed into distinct secured and non-secured containers, therefore allowing for parallel execution while alleviating the limited size of Page Cache (EPC) memory in each enclave. We illustrate our contributions using a workflow supporting indexing, alignment, dispatching, and merging the execution of SGX- enabled containers. We provide details regarding the architecture of the trusted and untrusted components and the underlying Scorn and Graphene support as generic shielding execution frameworks to port legacy code. We thoroughly evaluate the performance of our privacy-preserving reads mapping algorithm using real human genome sequencing data. The results demonstrate that the performance is enhanced by partitioning the time-consuming genomic computation into subtasks compared to the conventional execution of the data-intensive reads mapping algorithm in an enclave. The proposed HySec-Flow framework is made available as an open-source and adapted to the data-parallel computation of other large-scale genomic tasks requiring security and scalable computational resources. Chathura Widanage, Weijie Liu 0004, XiaoFeng Wang 0001, Haixu Tang, Judy Fox |
CLOUD | 2 |
| 2021 | Incremental CFG patching for binary rewritingabstractBinary rewriting has been widely used in software security, software correctness assessment, performance analysis, and debugging. One approach for binary rewriting lifts the binary to IR and then regenerates a new one, which achieves near-to-zero runtime overhead, but relies on several limiting assumptions on binaries to achieve complete binary analysis to perform IR lifting. Another approach patches individual instructions without utilizing any binary analysis, which has great reliability as it does not make assumptions about the binary, but incurs prohibitive runtime overhead. Xiaozhu Meng, Weijie Liu 0004 |
ASPLOS | 2 |
| 2021 | Practical and Efficient in-Enclave Verification of Privacy ComplianceabstractA trusted execution environment (TEE) such as Intel Software Guard Extension (SGX) runs attestation to prove to a data owner the integrity of the initial state of an enclave, including the program to operate on her data. For this purpose, the data-processing program is supposed to be open to the owner or a trusted third party, so its functionality can be evaluated before trust being established. In the real world, however, increasingly there are application scenarios in which the program itself needs to be protected (e.g., proprietary algorithm). So its compliance with privacy policies as expected by the data owner should be verified without exposing its code. To this end, this paper presents Deflection, a new model for TEE-based delegated and flexible in-enclave code verification. Given that the conventional solutions do not work well under the resource-limited and TCB-frugal TEE, we come up with a new design inspired by Proof-Carrying Code. Our design strategically moves most of the workload to the code generator, which is responsible for producing easy-to-check code, while keeping the consumer simple. Also, the whole consumer can be made public and verified through a conventional attestation. We implemented this model on Intel SGX and demonstrate that it introduces a very small part of TCB. We also thoroughly evaluated its performance on micro- and macro- benchmarks and real-world applications, showing that the design only incurs a small overhead when enforcing several categories of security policies. Weijie Liu 0004, Wenhao Wang 0001, XiaoFeng Wang 0001, Yaosong Lu, Kai Chen 0012, Qintao Shen, Yi Chen 0024, Haixu Tang |
DSN | 1 |
| 2018 | Controlled Channel Attack Detection Based on Hardware Virtualization
Chenyi Qiang, Weijie Liu 0004, Lina Wang 0001, Rongwei Yu |
ICA3PP (1) | 2 |
| 2018 | Factoring two-dimensional two-channel non-separable stripe filter banks into lifting stepsabstractSince the division with remainder cannot be implemented in multivariable polynomials, the two‐dimensional non‐separable wavelet transform cannot be lifted by using a similar way as that of univariate wavelet transforms. To solve this problem, a general lifting factoring method of two‐dimensional two‐channel non‐separable stripe filter banks is presented. The constructing form of the polyphase matrices of the stripe filter banks is deduced and the general factoring of the polyphase matrices is given. Compared with the separable lifting wavelet transform, the proposed lifting factoring method can extract better texture information. The lifting form is more succinct than that of the tensor product lifting wavelet transform. The computation amount of the proposed factoring method for image decomposition is a quarter of the two‐dimensional two‐channel non‐separable stripe filter bank and the original two‐dimensional two‐channel non‐separable wavelet system is quickened. Moreover, the proposed lifting factorising method is faster than the traditional two‐dimensional two‐channel non‐separable wavelet transform based on the Fourier transformation framework in which the size of each filter is greater than . The proposed lifting factorising method has better sparsity than that of the original wavelet transform and the famous two‐dimensional two‐channel biorthogonal symmetric non‐separable wavelet transform. Bin Liu 0029, Weijie Liu 0004 |
IET Image Process. | 2 |
| 2018 | The lifting factorization of 2D 4-channel nonseparable wavelet transforms
Bin Liu 0029, Weijie Liu 0004 |
Inf. Sci. | 2 |
| 2017 | On-Demand Time Blurring to Support Side-Channel Defense
Weijie Liu 0004, Debin Gao, Michael K. Reiter |
ESORICS (2) | 1 |
| 2016 | A novel covert channel detection method in cloud based on XSRM and improved event association algorithmabstractCovert channel is a major threat to the information system security and commonly found in operating systems, especially in cloud computing environment. Owing to the characteristics in cloud computing environment such as resources sharing and logic boundaries, covert channels become more varied and difficult to find. Focusing on those problems, this paper presents a universal method for detecting covert channel automatically. To achieve a global detection, we leveraged a virtual machine event record mechanism in hypervisor to gather necessary metadata. Combining the shared resources matrix methodology with events association mechanism, we proposed a distinctive algorithm that can accurately locate and analyze malicious covert channels from the respect of behaviors. Compared with the popular statistical test methods focusing on the single covert channel, our method is capable of recognizing and detecting more covert channels in real time. Experimental results show that this method is not only able to detect multilevel and multiform covert channels in cloud environment effectively but also facilitates the implementation and deployment in practical scenarios without modifying the existing system. Copyright © 2016 John Wiley & Sons, Ltd. Lina Wang 0001, Weijie Liu 0004, Neeraj Kumar 0001, Debiao He, Cheng Tan 0006, Debin Gao |
Secur. Commun. Networks | 2 |
| 2014 | Control Flow Obfuscation Using Neural Network to Fight Concolic Testing
Xinjie Ma, Weijie Liu 0004, Zhipeng Huang 0006, Debin Gao, Chunfu Jia |
SecureComm (1) | 3 |
| 2013 | Construction method of three-channel non-separable symmetric wavelets with arbitrary dilation matrices and its applications in multispectral image fusionabstractImage fusion method based on separable discrete wavelet transform has block effect and the spatial resolution is lower in the fusion result images. The design method of filter bank relies on the form of the dilation matrices in the image fusion method based on three‐channel non‐separable wavelet. To resolve these problems, a new construction method of the filter banks based on three‐channel non‐separable symmetric wavelet with arbitrary dilation matrices is presented. A new multispectral image fusion method based on this kind of wavelet filter bank is proposed. An example of the filter bank with those properties is constructed and applied to the fusion of multispectral image and panchromatic image. The experiment results show that this method has good visual effect. The fusion performance of the proposed method is better than that of the other methods in terms of several frequently used and the latest metrics. Bin Liu 0029, Weijie Liu 0004 |
IET Image Process. | 3 |