EDBT 2026 Demo / reviewers in the wild / expert
Shijun Zhao
dblp:145/1637
· DBLP profile ↗
22ranked-venue papers
5as first author
7since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 5 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Computer networks · 2Software engineering, systems software and programming languages · 2 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Formal Verification of a Rust-Based Buddy Physical Memory Allocator
Qianying Zhang, Weituo Dai, Tian'ao Xie, Shijun Zhao, Yongwang Zhao |
TASE | 6 |
| 2025 | TriAnomalyNet: A Microservice Anomaly Detection Model Based on Multi-Stream EncodersabstractAnomaly detection in microservice systems has attracted extensive attention in both academia and industry. However, two main problems still exist in the literature. First, many studies only consider single-modal data and ignore the useful information offered by other modalities. This may result in missing abnormal cases, leading to false alarms. Secondly, studies that use multimodal data for anomaly detection are still limited in capturing the correlation between different modalities. To address the above problems, we propose TriAnomalyNet, using a multi-stream Transformer encoder for feature extraction and fusion. It can effectively capture the correlation between the data for each modality and other modalities, using the features of other modalities to strengthen the features of the target modality, which can obtain a powerful feature representation. The graph attention network (GAT) is then adopted for anomaly detection. We verify the proposed TriAnomalyNet on two real datasets, and the results show that compared with state-of-the-art anomaly detection methods for microservice systems, TriAnomalyNet shows superiority. Zhuang Lu, Yulei Wu, Shijun Zhao, Chunjing Han |
IJCNN | 5 |
| 2025 | The Road to Trust: Building Enclaves within Confidential VMs
Wenhao Wang 0001, Linke Song, Benshan Mei, Shijun Zhao, Shoumeng Yan, XiaoFeng Wang 0001, Dan Meng 0002, Rui Hou 0001 |
NDSS | 5 |
| 2024 | HyperTEE: A Decoupled TEE Architecture with Secure Enclave ManagementabstractTrusted Execution Environment (TEE) architectures have been deployed in various commercial processors to provide secure environments for confidential programs and data. However, as a relatively new feature against security threats, existing designs still face a number of problems. Exploiting the management vulnerabilities, attackers can disclose secrets via controlled-channel or micro-architecture side-channel attacks. To address these problems, this paper proposes a novel TEE architecture, named HyperTEE. In our architecture, enclave management tasks are decoupled from the original computing subsystem to a dedicated, physically isolated Enclave Manage-ment Subsystem (EMS). A properly architected EMS prevents current management vulnerabilities and offers more secure enclave communication. We implemented the HyperTEE prototype on the FPGA platform. Experiments show that HyperTEE only introduces less than 1% area overhead, and 2.0 % and 1.9 % performance overhead on average for enclaves and non-enclave workloads, respectively. Yunkai Bai, Peinan Li, Yubiao Huang, Michael C. Huang 0001, Shijun Zhao, Lutan Zhao, Fengwei Zhang, Dan Meng 0002, Rui Hou 0001 |
MICRO | 5 |
| 2024 | MSMP: A Centralized Shared-memory Management for Building Efficient and Reliable File Systems on MicrokernelsabstractTraditional microkernel-based operating systems are popular in embedded and safety-critical applications due to their advantages in security, reliability, and scalability. In recent years, some OS projects like LionsOS and the Hong-Meng microkernel have focused on developing general-purpose operating systems based on microkernels. However, the strong isolation mechanisms of microkernel architectures often lead to performance degradation when implementing user-space system services. This is particularly evident in file systems, where data may need to be transferred across multiple system services, resulting in redundant data copying. To address this issue, this paper proposes a microkernel file system architecture based on a multi-server memory proxy, which reduces redundant data copying across processes in a multi-server design through centralized shared memory. Additionally, this architecture effectively abstracts the use of Direct Memory Access (DMA), allowing any process to securely and conveniently utilize DMA for zerocopy operations. Considering the high-reliability requirements of system services, we implemented the overall design using the Rust programming language, thus avoiding the security issues typically associated with traditional languages like C. Experimental results indicate that our design can enhance file buffered I/O throughput performance by 43%. Shijun Zhao, Dan Meng 0002, Rui Hou 0001 |
TrustCom | 2 |
| 2024 | Improving the validation of multiple-object detection using a complex-network-community-based relevance metricabstractAlthough many of today’s object detectors (ODs) are fairly powerful and advanced, most of them still suffer from high detection failure rates. To address this issue, we have developed an innovative, multiple-object detection validation method using a complex-network-community-based relevance metric. This metric aims to measure the relevance of multiple objects in the same OD output, based on our observation that a faulty OD output generally includes objects that are irrelevant or unrelated to each other. To verify the effectiveness of our method, we formulated four research questions, and performed an experiment with statistical analyses to address these questions. Our experiment provides strong support that our method (particularly the relevance metric) is highly effective at helping human testers in identifying faulty OD outputs. Kun Qiu 0001, Pak-Lok Poon, Shijun Zhao, Dave Towey, Lanlin Yu |
Knowl. Based Syst. | 3 |
| 2024 | Are the Cloud-Top Heights Retrieved From GOES-16/ABI and GOES-17/ABI Consistent?abstractThe U.S. Geostationary Operational Environmental Satellites GOES-16 and GOES-17 provide cloud-top height (CTH) data. A fusion model combining their CTH is vital for global high-resolution weather forecasting and climate analysis. However, ensuring a high degree of consistency between CTH from GOES-16 and GOES-17 is essential for building an effective CTH fusion model. In this article, a consistency analysis was conducted on the CTH in regions where GOES-16/ABI and GOES-17/ABI observations overlap. Results show that the CTH of GOES-16 and GOES-17 exhibits a small mean error (ME) and high correlation, but between 9:30 and 15:00 [universal time coordinated (UTC)], the ME, standard deviation (Std), and root mean square error (RMSE) are significantly larger than those during other periods, with the maximum values occurring between approximately 12:00 and 14:00. The difference in Satellite viewing zenith angle ($\Delta $VZA) at the same observation pixel had an impact on the CTH consistency. The larger$\Delta $VZA is, the larger are ME, Std, and RMSE. The increase in ME of between the two CTH from 9:30 to 15:00 was related to the difference in radiance of the 12.3 and$13.3~\mu $m channel, while the increase in Std was related to the difference in radiance of the$13.3~\mu $m. It is due to anomalies in the channel radiance observations caused by the degradation of the imager’s performance by solar radiation exposure during this period. The fusion of GOES-16 and GOES-17 CTH data needs to take into consideration the differences in VZA and the data quality control between 9:30 and 15:00. Yan Dong 0010, Shijun Zhao, Xuejin Sun, Qinghui Li |
IEEE Trans. Geosci. Remote. Sens. | 2 |
| 2020 | Formal Verification of Memory Isolation for the TrustZone-based TEEabstractThe trusted execution environment (TEE) is the security basis of embedded systems, which can provide a hardware-based isolated execution environment for security-sensitive components. Isolation of memory is a critical mechanism of TEE, the security of which plays a very important role in TEE's construction. In this paper, we present a formal verification of security properties about the memory isolation mechanism of TEE systems based on the ARM TrustZone, which is a hardware security technology commonly used on billions of ARM processors to create TEE. We establish a formal model of memory isolation, which consists of the formalization of ARMv8 architecture hardware components related to memory isolation and the formalization of a TrustZone monitor supporting world switch. We formally explicit and verify the correctness properties of memory management along with the information flow security properties of the memory isolation mechanism. The formalizations and verifications are all performed in the interactive theorem prover Isabelle/HOL. Yuwei Ma, Qianying Zhang, Shijun Zhao, Ximeng Li 0003, Zhi-Ping Shi 0002 |
APSEC | 3 |
| 2020 | A comprehensive formal security analysis and revision of the two-phase key exchange primitive of TPM 2.0
Qianying Zhang, Shijun Zhao |
Comput. Networks | 2 |
| 2020 | RIPTE: Runtime Integrity Protection Based on Trusted Execution for IoT DeviceabstractSoftware attacks like worm, botnet, and DDoS are the increasingly serious problems in IoT, which had caused large-scale cyber attack and even breakdown of important information infrastructure. Software measurement and attestation are general methods to detect software integrity and their executing states in IoT. However, they cannot resist TOCTOU attack due to their static features and seldom verify correctness of control flow integrity. In this paper, we propose a novel and practical scheme for software trusted execution based on lightweight trust. Our scheme RIPTE combines dynamic measurement and control flow integrity with PUF device binding key. Through encrypting return address of program function by PUF key, RIPTE can protect software integrity at runtime on IoT device, enabling to prevent the code reuse attacks. The results of our prototype’s experiment show that it only increases a small size TCB and has a tiny overhead in IoT devices under the constraint on function calling. In sum, RIPTE is secure and efficient in IoT device protection at runtime. Jingbin Liu, Shijun Zhao, Dengguo Feng |
Secur. Commun. Networks | 3 |
| 2019 | SecTEE: A Software-based Approach to Secure Enclave Architecture Using TEEabstractSecure enclaves provide a practical solution to secure computation, and current approaches to secure enclaves are implemented by extending hardware security mechanisms to the CPU architecture. Therefore, it is hard for a platform to offer secure computation if its CPU architecture is not equipped with any secure enclave features. Unfortunately, ARM CPUs, dominating mobile devices and having increasing momentum in cloud markets, do not provide any security mechanisms achieving the security equivalent to modern secure enclave architectures. In this paper, we propose SecTEE, a software-based secure enclave architecture which is based on the CPU's isolation mechanism and does not require specialized security hardware of the CPU architecture such as memory encryption engines. SecTEE achieves a high level of security even compared with hardware-based secure enclave architectures: resistance to privileged host software attacks, lightweight physical attacks, and memory access based side-channel attacks. Besides, SecTEE provides rich trusted computing primitives for enclaves: integrity measurement, remote attestation, data sealing, secrets provisioning, and life cycle management. We implement a SecTEE prototype based on the ARM TrustZone technology, but our approach can be applied to other CPU architectures with isolation mechanisms. The evaluation results show that most overhead comes from the software encryption and the runtime overhead imposed by trusted computing primitives is acceptable. Shijun Zhao, Qianying Zhang, Dengguo Feng |
CCS | 1 |
| 2019 | Minimal Kernel: An Operating System Architecture for TEE to Resist Board Level Physical Attacks
Shijun Zhao, Qianying Zhang, Dengguo Feng |
RAID | 1 |
| 2019 | SoftME: A Software-Based Memory Protection Approach for TEE System to Resist Physical AttacksabstractThe development of the Internet of Things has made embedded devices widely used. Embedded devices are often used to process sensitive data, making them the target of attackers. ARM TrustZone technology is used to protect embedded device data from compromised operating systems and applications. But as the value of the data stored in embedded devices increases, more and more effective physical attacks have emerged. However, TrustZone cannot resist physical attacks. We propose SoftME, an approach that utilizes the on-chip memory space to provide a trusted execution environment for sensitive applications. We protect the confidentiality and integrity of the data stored on the off-chip memory. In addition, we design task scheduling in the encryption process. We implement a prototype system of our approach on the development board supporting TrustZone and evaluate the overhead of our approach. The experimental results show that our approach improves the security of the system, and there is no significant increase in system overhead. Qianying Zhang, Shijun Zhao, Zhi-Ping Shi 0002 |
Secur. Commun. Networks | 3 |
| 2018 | AAoT: Lightweight attestation and authentication of low-resource things in IoT and CPS
Shijun Zhao, Dengguo Feng |
Comput. Networks | 3 |
| 2017 | Secure Code Updates for Smart Embedded Devices Based on PUFs
Shijun Zhao, XiaoBo Chu, Dengguo Feng |
CANS | 3 |
| 2015 | sHMQV: An Efficient Key Exchange Protocol for Power-Limited Devices
Shijun Zhao, Qianying Zhang |
ISPEC | 1 |
| 2015 | Security analysis of SM2 key exchange protocol in TPM2.0abstractAbstract The new released trusted platform module (TPM) specification, TPM2.0, adds cryptographic support for key exchange by providing SM2 authenticated key exchange (AKE) application programming interface (API) commands. Xu analyzed the SM2 AKE protocol and found that it was insecure in common computing environment by presenting two types of unknown key share attacks. Here, we present another design weakness of the SM2 AKE protocol, which might cause that the protocol cannot be proven secure in modern security models. We also analyze the security of SM2 AKE protocol in TPM2.0, whose running environment is very different and find that (i) it indeed gets some security improvements through the protection capability provided by the two SM2 AKE commands of TPM2.0 but (ii) it still has some weaknesses, which might lead to unknown key share and key‐compromise impersonation attacks because of the bad design of the TPM2.0 application programming interface. We solve the weaknesses of SM2 AKE protocol in TPM2.0 by slightly modifying one SM2 AKE command and finally give a formal proof of our solution in the Canetti and Krawczyk model. Our work shows that TPM2.0 could provide a proven secure SM2 AKE by slightly modifying one command. Copyright © 2014 John Wiley & Sons, Ltd. Shijun Zhao, Li Xi, Qianying Zhang, Dengguo Feng |
Secur. Commun. Networks | 1 |
| 2014 | Mdaak: A Flexible and Efficient Framework for Direct Anonymous Attestation on Mobile Devices
Qianying Zhang, Shijun Zhao, Li Xi, Dengguo Feng |
ICICS | 2 |
| 2014 | Universally Composable Secure TNC Protocol Based on IF-T Binding to TLS
Shijun Zhao, Qianying Zhang, Dengguo Feng |
NSS | 1 |
| 2014 | Improving the Security of the HMQV Protocol Using Tamper-Proof Hardware
Qianying Zhang, Shijun Zhao, Dengguo Feng |
SecureComm (1) | 2 |
| 2011 | A Property-Based Attestation Scheme with the Variable PrivacyabstractThe binary attestation mechanism is a basic remote attestation way for Trusted Platform Module (TPM) in Trusted Computing Group (TCG) specification. To improve the security and complexity of the binary attestation, the concept of property-based attestation (PBA) has been proposed by convincing the remote verifier that the platform satisfies the security properties without exposure of the configuration privacy. The existing PBA schemes have the disadvantage of the complex property revocations. To overcome this problem, we propose a simplified property based attestation model on the online TTP in this paper. During the attestation the prover attests the platform configuration property as well as the validation of the property certificate without verifying the property revocation. More concretely it presents a property based attestation protocol with variable privacy, which is provable security under the q-SDH assumption, discrete logarithm problem and the perfect hidden property of the commitment. We conduct the experiment to evaluate efficiency of our scheme in final. The experiment shows that the privacy parameter does not have the significant impacts on the performance, and we can adjust the parameter to make a trade-off between the performance and privacy. Dexian Chang, Shijun Zhao, Qianying Zhang |
TrustCom | 3 |
| 2011 | Enhancing Flexibility of TCG's TNC through Layered Property AttestationabstractTCG's trusted network connect (TNC) architecture improves network security through remote attestation. However, because of the deficiencies of existing binary attestation and property attestation, current TNC is not flexible and privacy- friendly enough to be used in a large scale network environment such as Internet. Aiming at these problems, this paper firstly analyzes the relations among system properties in the context of TCG-based remote attestation and proposes a new property relation model. Then a layered property attestation framework is proposed based on this model. Finally these ideas are used in the design of a real trusted network connect system. It is shown that the verifier need only obtain and verify the specific integrity measurement that he is interested in and the privacy of the attester's configuration is protected reasonably. Shijun Zhao |
TrustCom | 2 |