Mengyuan Li 0004

dblp:157/4437-4 · DBLP profile ↗
← Back
21ranked-venue papers
9as first author
12since 2021 · last 2026
0009-0008-2721-4021ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 7 first-author · 10 since 2021Computer networks · 5 · 2 first-authorSystems, architecture and hardware · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Wave: Leveraging Architecture Observation for Privacy-Preserving Model Oversight
abstract
Large Language Models (LLMs) inference increasingly require mechanisms that provide runtime visibility into what is actually executing, without exposing model weights or code. We present WAVE, a hardware-grounded monitoring framework that leverages GPU performance counters (PMCs) to observe LLM inference. WAVE is built on the insight that legitimate executions of a given model must satisfy hardware-constrained invariants, such as memory accesses, instruction mix, and tensor-core utilization, induced by the model's linear-algebraic structure. WAVE collects lightweight PMC traces and applies a two-stage pipeline: (1) inferring architectural properties (e.g., parameter count, layer depth, hidden dimension, batch size) from the observed traces; and (2) using an SMT-based consistency checker to assess whether the execution aligns with the provisioned compute and the claimed model's constraints. We evaluate WAVE on common open-source LLM architectures, such as LLaMA, GPT, and Qwen, across multiple GPU architectures, including NVIDIA Ada Lovelace, Hopper, and Blackwell. Results show that WAVE recovers key model parameters with an average error of 6.8% and identifies disguised executions under realistic perturbations. By grounding oversight in hardware invariants, WAVE provides a practical avenue for continuous, privacy-preserving runtime monitoring of LLM services.
Beijie Liu, Haizhong Zheng, Beidi Chen, Mengyuan Li 0004
ASPLOS (2)6
2026 Hollow-LLM Attack: Computationally Trivial Weights in Zero-Knowledge Verification of LLM Inference
abstract
As large language models (LLMs) grow in scale and are predominantly served from remote platforms, verifying faithful inference execution becomes critical (i.e., ensuring that a provider actually executes the advertised model and computational workload rather than a tampered or downsized variant). Zero-knowledge (ZK) LLM inference offers an appealing approach. It promises public verifiability and delivers per-instance guarantees of equational correctness by proving that an output is consistent with executing a public architecture under committed, private weights. Though, we show that it does not bind the effort expended to produce the output. In this paper, we formalize this overlooked effort gap and introduce the Hollow-LLM Attack, in which a dishonest provider retains the declared architecture and parameter count but embeds ghost weights whose algebraic structure collapses effective computation. These witnesses satisfy the verification circuit and yield valid proofs, even though the dishonest model owner, who serves as the prover, performs computation commensurate with a much smaller model than the declared public architecture. This creates a profitable equilibrium in which providers deliver provably correct outputs at small-model cost while overclaiming model size. Accordingly, we characterize concrete families of ghost weights that compose with standard transformer blocks and show that such hollow deployments substantially reduce serving cost with zero quality loss under the same verification circuit. These findings underscore that proof of correct inference is not proof of large-model execution and necessitate additional protections to bind correctness to verifiable computational work.
Beijie Liu, Mengyuan Li 0004
SP3
2025 Chekhov's Gun: Uncovering Hidden Risks in macOS Application-Sandboxed PID-Domain Services
abstract
macOS delegates many high-privilege operations to dedicated PID-domain services, which applications can register and communicate with through inter-process communication (IPC). This architecture improves userland stability and security but also introduces attractive attack surfaces for adversaries. In this paper, we systematically analyze PID-domain services and uncover an overlooked attack vector: PID-domain services that are restricted to an Application Sandbox identical to the calling application can still be exploited due to subtle entitlement differences.
Minghao Lin, Jiaxun Zhu, Tingting Yin, Zechao Cai, Guanxing Wen, Yanan Guo 0002, Mengyuan Li 0004
CCS7
2025 Few-Shot Graph Out-of-Distribution Detection with LLMs
Haoyan Xu, Zhengtao Yao, Yushun Dong, Ziyi Wang 0012, Ryan Rossi, Mengyuan Li 0004, Yue Zhao 0016
ECML/PKDD (4)6
2024 SoK: Understanding Design Choices and Pitfalls of Trusted Execution Environments
abstract
Trusted execution environment (TEE) is a revolutionary technology that enables secure remote execution (SRE) of cloud workloads on untrusted server-side computing platforms. Both commercial and academic TEEs have been proposed in the past few years, including Intel's SGX and TDX, AMD's SEV, ARM's CCA, IBM's PEF, and their academic counterparts built atop open-source RISC-V processors, such as Keystone, Sanctum, CURE, and Penglai. While great efforts from both sides have been made in developing a confidential computing ecosystem, the existence of server-side TEEs with drastically different designs and the presence of various known attacks have significantly increased the difficulty of understanding TEE designs and the reasons behind existing attacks.
Mengyuan Li 0004, Guoxing Chen, Mengjia Yan 0001, Yinqian Zhang
AsiaCCS1
2023 PwrLeak: Exploiting Power Reporting Interface for Side-Channel Attacks on AMD SEV
Wubing Wang, Mengyuan Li 0004, Yinqian Zhang, Zhiqiang Lin 0001
DIMVA2
2023 CipherH: Automated Detection of Ciphertext Side-channel Vulnerabilities in Cryptographic Implementations
Mengyuan Li 0004, Yining Tang, Shuai Wang 0011, Shoumeng Yan, Yinqian Zhang
USENIX Security Symposium2
2022 A Systematic Look at Ciphertext Side Channels on AMD SEV-SNP
abstract
Hardware-assisted memory encryption offers strong confidentiality guarantees for trusted execution environments like Intel SGX and AMD SEV. However, a recent study by Li et al. presented at USENIX Security 2021 has demonstrated the CipherLeaks attack, which monitors ciphertext changes in the special VMSA page. By leaking register values saved by the VM during context switches, they broke state-of-the-art constant-time cryptographic implementations, including RSA and ECDSA in the OpenSSL. In this paper, we perform a comprehensive study on the ciphertext side channels. Our work suggests that while the CipherLeaks attack targets only the VMSA page, a generic ciphertext side-channel attack may exploit the ciphertext leakage from any memory pages, including those for kernel data structures, stacks and heaps. As such, AMD’s existing countermeasures to the CipherLeaks attack, a firmware patch that introduces randomness into the ciphertext of the VMSA page, is clearly insufficient. The root cause of the leakage in AMD SEV’s memory encryption—the use of a stateless yet unauthenticated encryption mode and the unrestricted read accesses to the ciphertext of the encrypted memory—remains unfixed. Given the challenges faced by AMD to eradicate the vulnerability from the hardware design, we propose a set of software countermeasures to the ciphertext side channels, including patches to the OS kernel and cryptographic libraries. We are working closely with AMD to merge these changes into affected open-source projects.
Mengyuan Li 0004, Luca Wilke, Jan Wichelmann, Thomas Eisenbarth 0001, Radu Teodorescu, Yinqian Zhang
SP1
2022 vSGX: Virtualizing SGX Enclaves on AMD SEV
abstract
The growing need of trusted execution environment (TEE) has boomed the development of hardware enclaves. However, current TEEs and their applications are tightly bound to the hardware implementation, hindering their compatibility across different platforms. This paper presents vSGX, a novel system to virtualize the execution of an Intel SGX enclave atop AMD SEV. The key idea is to interpose the execution of enclave instructions transparently to support the SGX ISA extensions, consolidate encrypted virtual memory of separated SEV virtual machines to create a single virtualized SGX-like address space, and provide attestations for the authenticity of the TEE and the integrity of enclave software with a trust chain rooted in the SEV hardware. By design, vSGX achieves a comparable level of security guarantees on SEV as that on Intel SGX. We have implemented vSGX and demonstrated it imposes reasonable performance overhead for SGX enclave execution.
Shixuan Zhao 0002, Mengyuan Li 0004, Yinqian Zhang, Zhiqiang Lin 0001
SP2
2021 TLB Poisoning Attacks on AMD Secure Encrypted Virtualization
abstract
AMD’s Secure Encrypted Virtualization (SEV) is an emerging technology of AMD server processors, which provides transparent memory encryption and key management for virtual machines (VM) without trusting the underlying hypervisor. Like Intel Software Guard Extension (SGX), SEV forms a foundation for confidential computing on untrusted machines; unlike SGX, SEV supports full VM encryption and thus makes porting applications straightforward. To date, many mainstream cloud service providers, including Microsoft Azure and Google Cloud, have already adopted (or are planning to adopt) SEV for confidential cloud services.
Mengyuan Li 0004, Yinqian Zhang, Huibo Wang, Yueqiang Cheng
ACSAC1
2021 CrossLine: Breaking "Security-by-Crash" based Memory Isolation in AMD SEV
abstract
AMD's Secure Encrypted Virtualization (SEV) is an emerging security feature of modern AMD processors that allows virtual machines to run with encrypted memory and perform confidential computing even with an untrusted hypervisor. This paper first demystifies SEV's improper use of address space identifier (ASID) for controlling accesses of a VM to encrypted memory pages, cache lines, and TLB entries. We then present the CROSSLINE attacks, a novel class of attacks against SEV that allow the adversary to launch an attacker VM and change its ASID to that of the victim VM to impersonate the victim. We present two variants of CROSSLINE attacks: CROSSLINE V1 decrypts victim's page tables or any memory blocks conforming to the format of a page table entry; CROSSLINE V2 constructs encryption and decryption oracles by executing instructions of the victim VM. We discuss the applicability of CROSSLINE attacks on AMD's SEV, SEV-ES, and SEV-SNP processors.
Mengyuan Li 0004, Yinqian Zhang, Zhiqiang Lin 0001
CCS1
2021 CIPHERLEAKS: Breaking Constant-time Cryptography on AMD SEV via the Ciphertext Side Channel
Mengyuan Li 0004, Yinqian Zhang, Huibo Wang, Yueqiang Cheng
USENIX Security Symposium1
2019 Exploiting Unprotected I/O Operations in AMD's Secure Encrypted Virtualization
Mengyuan Li 0004, Yinqian Zhang, Zhiqiang Lin 0001, Yan Solihin
USENIX Security Symposium1
2018 Peeking Behind the Curtains of Serverless Platforms
Liang Wang 0023, Mengyuan Li 0004, Yinqian Zhang, Thomas Ristenpart, Michael M. Swift
USENIX ATC2
2017 STACCO: Differentially Analyzing Side-Channel Traces for Detecting SSL/TLS Vulnerabilities in Secure Enclaves
abstract
Intel Software Guard Extension (SGX) offers software applications a shielded execution environment, dubbed enclave, to protect their confidentiality and integrity from malicious operating systems. As processors with this extended feature become commercially available, many new software applications are developed to enrich to the SGX-enabled ecosystem. One important primitive for these applications is a secure communication channel between the enclave and a remote trusted party. The SSL/TLS protocol, which is the de facto standard for protecting transport-layer network communications, has been broadly regarded a natural choice for such purposes. However, in this paper, we show that the marriage between SGX and SSL may not be smooth sailing.
Yuan Xiao 0001, Mengyuan Li 0004, Sanchuan Chen, Yinqian Zhang
CCS2
2017 SPFM: Scalable and Privacy-Preserving Friend Matching in Mobile Cloud
abstract
Profile (e.g., contact list, interest, and mobility) matching is more than important for fostering the wide use of mobile social networks. The social networks such as Facebook, Line, or WeChat recommend the friends for the users based on users personal data such as common contact list or mobility traces. However, outsourcing users' personal information to the cloud for friend matching will raise a serious privacy concern due to the potential risk of data abusing. In this paper, we propose a novel scalable and privacy-preserving friend matching (SPFM) protocol, which aims to provide a scalable friend matching and recommendation solutions without revealing the users personal data to the cloud. Different from the previous works which involves multiple rounds of protocols, SPFM presents a scalable solution which can prevent honest-but-curious mobile cloud from obtaining the original data and support the friend matching of multiple users simultaneously. We give detailed feasibility and security analysis on SPFM and its accuracy and security have been well demonstrated via extensive simulations. The result show that our scheme works even better when original data is large.
Mengyuan Li 0004, Na Ruan, Qiyang Qian, Haojin Zhu, Xiaohui Liang 0002, Le Yu 0002
IEEE Internet Things J.1
2017 A novel broadcast authentication protocol for internet of vehicles
Na Ruan, Mengyuan Li 0004, Jie Li 0002
Peer-to-Peer Netw. Appl.2
2016 When CSI Meets Public WiFi: Inferring Your Mobile Phone Password via WiFi Signals
abstract
In this study, we present WindTalker, a novel and practical keystroke inference framework that allows an attacker to infer the sensitive keystrokes on a mobile device through WiFi-based side-channel information. WindTalker is motivated from the observation that keystrokes on mobile devices will lead to different hand coverage and the finger motions, which will introduce a unique interference to the multi-path signals and can be reflected by the channel state information (CSI). The adversary can exploit the strong correlation between the CSI fluctuation and the keystrokes to infer the user's number input. WindTalker presents a novel approach to collect the target's CSI data by deploying a public WiFi hotspot. Compared with the previous keystroke inference approach, WindTalker neither deploys external devices close to the target device nor compromises the target device. Instead, it utilizes the public WiFi to collect user's CSI data, which is easy-to-deploy and difficult-to-detect. In addition, it jointly analyzes the traffic and the CSI to launch the keystroke inference only for the sensitive period where password entering occurs. WindTalker can be launched without the requirement of visually seeing the smart phone user's input process, backside motion, or installing any malware on the tablet. We implemented Windtalker on several mobile phones and performed a detailed case study to evaluate the practicality of the password inference towards Alipay, the largest mobile payment platform in the world. The evaluation results show that the attacker can recover the key with a high successful rate.
Mengyuan Li 0004, Yan Meng 0001, Haojin Zhu, Xiaohui Liang 0002, Yao Liu 0007, Na Ruan
CCS1
2016 You Can Jam But You Cannot Hide: Defending Against Jamming Attacks for Geo-Location Database Driven Spectrum Sharing
abstract
The emerging paradigm for dynamic spectrum sharing is based on allowing secondary users (SUs) to exploit white space frequency that is not occupied by primary users. White space database provides an opportunity for SUs to obtain spectrum availability information by submitting a location-based query. However, this new paradigm can also be exploited by the attackers to significantly enhance their jamming capability due to the available channel information from spectrum queries, which is expected to increasingly block SUs. The challenge is that the unique characteristics (e.g., lack of the wide range frequencies or continuous broadband) make existing anti-jamming techniques (e.g., direct-sequence spread spectrum and frequency hopping spread spectrum) difficult to be applied. In this paper, we present a novel Jammer Inference-based Jamming Defense (jDefender) framework. The main idea of jDefender is inferring the likelihood of a user being a jammer based on the observed jamming events and then utilizing the inferred attack likelihood to enhance the effectiveness of a series of the proposed anti-jamming strategies. Specifically, we first propose the Channel Allocation-based Jammer Inference scheme to infer the likelihood of an SU being a jammer based on the channels occupied by SUs even under the collusion attack performed by multiple jammers. The strength of the anti-jamming strategies (e.g., puzzle difficulties, available spectrum resources) will be correlated with the possibility of an SU being a jammer to achieve the tradeoff between system performance and jamming tolerance. We then implement the proposed scheme on Universal Software Radio Peripheral and PC. Extensive evaluations are performed to validate the effectiveness of the attacks and countermeasures.
Haojin Zhu, Chenliaohui Fang, Yao Liu 0007, Cailian Chen, Mengyuan Li 0004, Xuemin Shen
IEEE J. Sel. Areas Commun.5
2014 Efficient and enhanced broadcast authentication protocols based on multilevel μTESLA
abstract
Providing lightweight authentication and resisting Denial of Service (DoS) attacks are challenging problems in wireless ad hoc networks, such as wireless sensor networks (WSNs). We introduce two improved protocols based on fault-tolerant protocol and DoS-resistant protocol in Multilevel μTESLA to overcome these difficulties. The proposed Efficient Fault-Tolerant Protocol contributes in shortening the recovery time when highlevel packets are lost, and hence reduces the risk of memory-based DoS attacks. The proposed Enhanced DoS-Resistant Protocol enhances the resistance to DoS attacks by offering packet-loss recovery of authentication message.
Na Ruan, Fan Wu 0006, Jie Li 0002, Mengyuan Li 0004
IPCCC5
2014 A Paralleling Broadcast Authentication Protocol for Sparse RSUs in Internet of Vehicles
abstract
Since the era of Internet of Vehicles (IoVs) is coming in next few years, real-time data transmission between vehicles and road-side sensor nodes has many application scenarios. However, due to different characteristics of IoVs and WSNs (Wireless Sensor Networks), real-time traffic data transmission is too complicated and slow when emergencies occurred in many RSUs-sparse (Road Side Units) areas. We build a simple integrated network model and propose a broadcast authentication protocol, namely Paralleling Broadcast Authentication Protocol (PBAP), aiming at enhance energy efficiency and providing network security in the direct communication between vehicles and WSNs. The simulation results demonstrate that the protocol can effectively extend lifetime of WSNs by improving the utilization rate of the keys and show nice properties in different channel loss ratio and different degrees of DoS attacks.
Mengyuan Li 0004, Na Ruan, Haojin Zhu, Jie Li 0002
MSN1