Guancheng Li

dblp:168/9579 · DBLP profile ↗
← Back
10ranked-venue papers
2as first author
8since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 1 first-author · 5 since 2021Security and privacy · 4 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 An LLM-based Quantitative Framework for Evaluating High-Stealthy Backdoor Risks in OSS Supply Chains
abstract
In modern software development workflows, the open-source software supply chain significantly contributes to efficient and convenient engineering practices. With increasing system complexity, it has become a common practice to use open-source software as third-party dependencies. However, due to the lack of maintenance for underlying dependencies and insufficient community auditing, ensuring the security of source code and the legitimacy of repository maintainers has become a challenge, particularly in the context of high-stealth backdoor attacks such as the XZ-Util incident. To address these problems, we propose a fine-grained project evaluation framework for backdoor risk assessment in open-source software. Our evaluation framework models highly stealthy backdoor attacks from the attacker’s perspective and defines targeted metrics for each attack stage. Moreover, to overcome the limitations of static analysis in assessing the reliability of repository maintenance activities, such as irregular committer privilege escalation and insufficient review participation, we employ large language models (LLMs) to perform semantic evaluation of code repositories while avoiding reliance on manually crafted patterns. The effectiveness of our framework is validated on 66 high-priority packages in the Debian ecosystem, and the experimental results reveal that the current open-source software supply chain is exposed to a series of security risks.
Zihe Yan, Zhuosheng Zhang 0001, Guancheng Li
AAAI6
2025 Poster: Black-box Attacks on Multimodal Large Language Models through Adversarial ICC Profiles
abstract
Despite their remarkable performance on vision-language tasks, multimodal large language models (MLLMs) remain vulnerable to adversarial examples. However, most existing attacks rely on gradient-based pixel perturbations and require white-box access to model parameters. In this paper, we propose ICCAdv, a novel black-box attack that requires no access to model parameters or gradients. The core idea of ICCAdv is to exploit the discrepancy between human and model perception of images during input processing. This discrepancy arises from the color management process, as human observers perceive rendered images based on ICC profile transformations, whereas most MLLMs circumvent this process and operate directly on raw RGB values. By embedding adversarial ICC profiles into image files, ICCAdv manipulates the perceived color semantics of MLLMs while preserving the natural visual appearance for human observers. Preliminary experiments indicate that ICCAdv can effectively attack state-of-the-art MLLMs while maintaining a natural visual appearance to human observers.
Chengbin Sun, Hailong Sun 0001, Guancheng Li, Jiashuo Liang
CCS3
2025 The Danger of Packet Length Leakage: Off-path TCP/IP Hijacking Attacks Against Wireless and Mobile Networks
abstract
To combat eavesdropping and injection attacks, wireless networks widely adopt encryption to provide confidentiality and integrity guarantees. In this paper, we present a novel and generic attack, termed LenOracle, which can hijack the TCP/UDP connections over encrypted wireless networks (e.g., 5G/4G/3G and Wi-Fi) via packet injections from the Internet. Due to the design nature of wireless networks and stream ciphers they used, the length of IP packets being transmitted can be acquired by radio sniffing. It thus provides a side channel for adversaries. We found that adversaries could utilize this side channel with TCP features to infer the presence of a connection, infer the protocol state (sequence number, acknowledge number) of the connection, and finally hijack TCP/IP connections over wireless networks. Through real-world experiments in commercial LTE networks and real Wi-Fi networks, we demonstrated that the LenOracle attack is practical and severe against both TCP and UDP connections. For the former, we successfully injected a fake short message into a victim TCP connection; For the latter, we were able to inject a fake DNS response into a UDP connection and poisoned the DNS cache of the victim device. Following the responsible disclosure policy, we have reported our findings and mitigation recommendations to GSMA and Wi-Fi Alliance. The GSMA acknowledged that the issue affects 5G/4G/3G, notified all its members (operators and vendors worldwide) of this issue, and highlighted the mitigation we proposed.
Guancheng Li, Jianjun Chen 0005, Ge Dai, Pinji Chen, Huiming Liu, Hai-Xin Duan, Zhiyun Qian
EuroS&P1
2025 Optimizing Data Acquisitions in Multi-Robot Systems
abstract
We present ROSfs, a novel user-level file system designed to address critical data query inefficiencies in multi-robot systems (MRS). ROSfs introduces an innovative file organization model where robot data is structured as labeled sub-files, coupled with a time-indexed architecture that enables efficient querying of actively modified data. This design enables real-time cross-robot data acquisition and collaboration capabilities previously unattainable in MRS deployments. Our implementation integrates seamlessly with the Robot Operating System (ROS) and has been extensively evaluated using both physical UAV/UGV platforms and data servers. Experimental results demonstrate that ROSfs achieves a 7x reduction in online data query latency under wireless network conditions compared to conventional ROS storage methods, while simultaneously improving data freshness (Age of Information) by up to 271x. These advancements position ROSfs as a transformative solution for high-performance robotic data management in distributed systems.
Yanhao Li, Xuanjun Wen, Guancheng Li, Shu Yin 0001
SC5
2024 A Data Optimizer for Region-Aware Self-describing Files in Scientific Computing
abstract
Acquiring data from scientific simulations for analytical purposes is inherently challenging due to the complex and irregularly shaped regions within which the data resides, particularly when using self-describing data formats. The process of region-based data distillation becomes even more arduous when employing persistent memory or parallel file systems. To tackle this challenge, we introduce RASTER (Region-Aware Self-describing daTa optimizER), a lightweight middleware designed for region-aware data preprocessing. RASTER dynamically reorganizes data into variable groups based on regional identifiers during runtime, thereby eliminating the need for sequential searches to locate the required data. We have developed a prototype of RASTER and successfully integrated it into three distinct computing environments: a single-node server equipped with Intel® Optane™ DC persistent memory, the Huawei® OceanStor cloud storage platform, and the Sunway TaihuLight supercomputer. We then conducted a thorough evaluation of the RASTER prototype on the latter two platforms using a real-world scientific application, CESM (Community Earth System Model). Our experimental results demonstrate that RASTER enhances data acquisition performance by up to 2.83× and achieves a 2.36× speedup over conventional netCDF and the state-of-the-art ADIOS2. Additionally, RASTER significantly reduces memory usage by up to 400%, showcasing its scalability potential.
Tianyuan Wu, Guancheng Li, Shu Yin 0001, Wei Xue 0003
SoCC4
2024 Portus: Efficient DNN Checkpointing to Persistent Memory with Zero-Copy
abstract
We introduce Portus, an efficient checkpointing system for DNN models. The core of Portus is a three-level index structure and a direct RDMA datapath that enables fast check-points between GPUs and persistent memory in a serialization-free way. Portus offers a zero-copy approach between GPU and persistent memory without involving main memory and kernel crossings to underlying file systems. Portus also applies an asynchronous mechanism to hide the checkpointing overhead in the model training procedures. We integrated a Portus prototype into a high-performance AI cluster with NVIDIA®V100 and A40 GPUs and Intel®Optane™persistent memory, then evaluated its performance in both single-GPU and multi-GPU large model training scenarios. Experiment results show that compared to a state-of-the-art checkpointing system, Portus achieves up to 9.23× and 7.0× speedup in checkpointing and restoring, respectively. Portus achieves up to 2.6× higher throughput and 8× faster checkpointing operation on a large language model, GPT-22B.
Tianyuan Wu, Guancheng Li, Shu Yin 0001
ICDCS3
2024 Dynamic Cache Partitioning for Enhancing Parallel I/O Performance in NVMe SSDs
abstract
Solid State Drive cache, implemented as on-board shared DRAM memory, can significantly enhance 110 performance by caching frequently accessed data. Although SSD caching strategies for single 110 data flows have been extensively explored, studies on cache partitioning to optimize parallel 110 in an SSD are scarce. In this paper, we present a novel dynamic cache partitioning approach designed to improve overall performance of multi-parallel 110 data flows by minimizing per-formance degradation of cache pollution and resource contention. By dynamically adjusting cache partition sizes for each data flow by considering cache sensitivity on performance, our strategy seeks to determine the optimal cache partition sizes to maximize overall 110 throughput. We implemented the strategy in the SSD simulator MQSim and evaluated its performance using various synthetic and real-world workloads. Our experimental results indicate that our dynamic cache partitioning strategy achieves an overall throughput increase of up to 33.22 % compared to shared cache methods and outperforms static cache partitioning strategies by up to 21.19%.
Guancheng Li, Songhui Cao, Shu Yin 0001, Xiaojun Ruan
NAS2
2023 Critique of "A Parallel Framework for Constraint-Based Bayesian Network Learning via Markov Blanket Discovery" by SCC Team From ShanghaiTech University
abstract
In SC20, (Srivastava et al. 2020) proposed a Parallel Framework forBayesianLearning, or ramBLe, for short, which is a highly parallel and efficient framework for learning the structure of Bayesian Networks (BNs) from samples,There was a discrepancy in Bibliography in the PDF and the source file. We have followed the source file. ?> particularly large genome-scale networks. As part of our participation in the SC21 Student Cluster Competition, our task was to verify conclusions from the original work (Srivastava et al. 2020). Here we present the outcome of our experiments, which were performed on a four-node cluster from the Oracle Cloud HPC platform. We reproduce the numerical results from (Srivastava et al. 2020), namely the algorithm's performance and scaling behavior using MPI and different Python and Boost libraries on the Oracle cloud.
Guancheng Li, Songhui Cao, Chuyi Zhao, Siyuan Zhang 0001, Yuchen Ji, Haotian Jing, Yiwei Yang 0002, Shu Yin 0001
IEEE Trans. Parallel Distributed Syst.1
2020 RIPT - An Efficient Multi-Core Record-Replay System
abstract
Given the same input, a program may not behave the same in two runs due to some non-deterministic features, e.g., context switch and randomization. Such behaviors would cause non-deterministic program bugs which are hard to discover or diagnose. Record-and-replay is a promising technique to address such issues, however, performance and transparency are the main obstacles of existing works. In this poster, we propose a novel record-and-replay system named RIPT. RIPT utilizes Intel Processor Trace to record control flow information with very low overhead, and transparently captures non-deterministic sources such as system calls and signals with a kernel module. During replay, RIPT recovers the effect of non-deterministic events from the collected information, and makes target programs behave the same as recorded. We evaluate it with real-world program bugs and show that RIPT works well in practice.
Jiashuo Liang, Guancheng Li, Chao Zhang 0008, Ming Yuan 0003, Xingman Chen, Xinhui Han
CCS2
2015 Walls Have Ears! Opportunistically Communicating Secret Messages Over the Wiretap Channel: from Theory to Practice
abstract
Physical layer (PHY) security has aroused great research interest in recent years, exploiting physical uncertainty of wireless channels to provide communication secrecy without placing any computational restrictions on the adversaries under the information-theoretic security model. Particularly, researches have been focused on investigating Wyner's Wiretap Channel for constructing practical wiretap codes that can achieve simultaneous transmission secrecy and reliability. While theoretically sound, PHY security through the wiretap channel has never been realized in practice, and the feasibility and physical limitations of implementing such channels in the real world are yet to be well understood. In this paper, we design and implement a practical opportunistic secret communication system over the wireless wiretap channel for the first time to our best knowledge. We show that, our system can achieve nearly perfect secrecy given a fixed codeword length by carefully controlling the structure of the parity-check matrix of wiretap codes to strike the proper balance between the transmission rate and secrecy. Our system is implemented and evaluated extensively on a USRP N210-based testbed. The experimental results demonstrate the physical limitations and the feasibility of building practical wiretap channels in both the worst channel case and the case where the sender has only the knowledge of instantaneous channel capacities. Our system design and implementation successfully attempts towards bridging the gap between the theoretical wiretap channel and its practice, alleviating the unrealistic and strong assumptions imposed by the theoretical model.
Qian Wang 0002, Kui Ren 0001, Guancheng Li, Chenbo Xia, Xiaobing Chen, Zhibo Wang 0001, Qin Zou 0001
CCS3