Jingquan Ge

dblp:224/4420 · DBLP profile ↗
← Back
16ranked-venue papers
7as first author
7since 2021 · last 2026
0000-0002-9879-0260ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 2 first-author · 3 since 2021Systems, architecture and hardware · 4 · 3 first-author · 2 since 2021Software engineering, systems software and programming languages · 4 · 3 first-author · 3 since 2021Computer networks · 2Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2026 OptRCA: A More Efficient and Accurate Approach for Automated Root Cause Analysis and Explanation
abstract
With the development of automated software testing technology, software developers can get a large number of crash test cases in a short period of time. However, analyzing these crash test cases and finding their root cause is a time-consuming and labor-intensive task. Techniques based on reverse execution and backward taint analysis are proposed to locate the root cause, but can’t provide context information or explanation of the underlying fault. To address these two limitations, researchers have proposed an automated root cause analysis technique called AURORA. Although this technique provides powerful root cause analysis capabilities, it also have two obvious shortcomings. First, the results of root cause analysis are not accurate enough. Second, the efficiency of root cause analysis is not high enough. In order to improve these two shortcomings, we propose OptRCA, a more efficient and accurate approach for root cause analysis and explanation. Like AURORA’s fuzzing strategy, OptRCA is also designed based on AFL’s crash mode. The difference between them is mainly reflected in three points. First of all, the goal pursued by OptRCA is different from that of normal fuzzing technology. OptRCA pursues maximum correlation to ensure that as many crash test cases as possible are related to the same root cause. This test case with maximum correlation can greatly improve the accuracy of root cause analysis. Second, OptRCA proposed a more efficient non-crash test case retention strategy, which we named “Hill-Climbing Retention.” Using the hill-climbing retention method, OptRCA can obtain sufficient root cause information while retaining only a few non-crash test cases. Since the number of test cases is greatly reduced, the efficiency of OptRCA’s subsequent root cause analysis process is also greatly improved. In addition, OptRCA also optimizes the analysis formula to obtain more accurate analysis results. In the evaluation experimental results, OptRCA is significantly better than AURORA in terms of accuracy and efficiency. Quantitative analysis shows that OptRCA is 65% more accurate and 61% more efficient than AURORA.
Jingquan Ge, Yaowen Zheng, Yuekang Li, Wei Ma 0014, Sheikh Mahbub Habib, Praveen Kakkolangara, Gabriel Byman, Yang Liu 0003
ACM Trans. Softw. Eng. Methodol.1
2025 Mission: Impossible - Image-Based Geolocation with Large Vision Language Models
abstract
In the age of ubiquitous smartphone use and widespread image sharing on social platforms, geolocation poses a critical privacy concern. Images often carry sensitive spatial and temporal details—such as street signs, architectural styles, or landmarks—that can inadvertently disclose the precise whereabouts of individuals and organizations. Recent advances in large vision-language models (LVLMs) present an emerging threat by enabling users, regardless of technical expertise, to extract location cues from seemingly benign photos. While existing AI-driven geolocation solutions often focus on narrow datasets or specialized contexts, the generalizable performance and privacy implications of zero-shot LVLMs in real-world settings remain critical questions. In this paper, we investigate the geolocation capabilities of state-of-the-art LVLMs. Our findings reveal that while these models demonstrate a non-negligible capability for image-based geolocation even without specialized training, their accuracy in absolute terms is often low, exposing clear limitations in their current state. We then introduce ETHAN, a framework integrating chain-of-thought (CoT) reasoning. Although ETHAN shows improved performance (e.g., 28.7% accuracy at the 1km threshold) and an 85.4% win rate on GeoGuessr, these results primarily highlight the potential trajectory of such technologies rather than their current widespread, high-accuracy applicability. Our study underscores the dual nature of LVLMs in this domain: they uncover an emerging privacy risk due to their inherent, albeit limited, geolocation abilities, yet also demonstrate significant constraints. We conclude by calling for further research into the limitations and risks of LVLM-based geolocation and the development of effective mitigation strategies to protect sensitive location data.
Yi Liu 0069, Gelei Deng, Junchen Ding, Yuekang Li, Tianwei Zhang 0004, Weisong Sun, Yaowen Zheng, Jingquan Ge
Proc. Priv. Enhancing Technol.8
2025 Open Source AI-based SE Tools: Opportunities and Challenges of Collaborative Software Learning
abstract
Large language models (LLMs) have become instrumental in advancing software engineering (SE) tasks, showcasing their efficacy in code understanding and beyond. AI code models have demonstrated their value not only in code generation but also in defect detection, enhancing security measures and improving overall software quality. They are emerging as crucial tools for both software development and maintaining software quality. Like traditional SE tools, open source collaboration is key in realizing the excellent products. However, with AI models, the essential need is in data. The collaboration of these AI-based SE models hinges on maximizing the sources of high-quality data. However, data, especially of high quality, often hold commercial or sensitive value, making them less accessible for open source AI-based SE projects. This reality presents a significant barrier to the development and enhancement of AI-based SE tools within the SE community. Therefore, researchers need to find solutions for enabling open source AI-based SE models to tap into resources by different organizations. Addressing this challenge, our position article investigates one solution to facilitate access to diverse organizational resources for open source AI models, ensuring that privacy and commercial sensitivities are respected. We introduce a governance framework centered on federated learning (FL), designed to foster the joint development and maintenance of open source AI code models while safeguarding data privacy and security. Additionally, we present guidelines for developers on AI-based SE tool collaboration, covering data requirements, model architecture, updating strategies, and version control. Given the significant influence of data characteristics on FL, our research examines the effect of code data heterogeneity on FL performance. We consider six different scenarios of data distributions and include four code models. We also include four most common FL algorithms. Our experimental findings highlight the potential for employing FL in the collaborative development and maintenance of AI-based SE models. We also discuss the key issues to be addressed in the co-construction process and future research directions.
Wei Ma 0014, Tao Lin 0004, Yaowen Zheng, Jingquan Ge, Jun Wang 0020, Jacques Klein, Tegawendé F. Bissyandé, Yang Liu 0003, Li Li 0029
ACM Trans. Softw. Eng. Methodol.5
2024 BootRIST: Detecting and Isolating Mercurial Cores at the Booting Stage
Yihao Luo, Yunjie Deng 0001, Jingquan Ge, Zhenyu Ning, Fengwei Zhang
ESORICS (2)3
2024 SnapMem: Hardware/Software Cooperative Memory Resistant to Cache-Related Attacks on ARM-FPGA Embedded SoC
abstract
ARM-FPGA embedded SoCs have been widely used in the fields of 5G Wireless, next-generation ADAS (Advanced Driver-Assistance Systems) and Industrial Internet-of-Things due to its high performance and hardware design flexibility. However, this type of SoC suffers various security threats, one of which is cross-domain cache-related attacks, such as Flush+Reload, Flush+Flush, Meltdown and Spectre. Many hardware and software defenses have been proposed to resist these cross-domain cache-related attacks. However, hardware defenses require modifications of basic architecture, which cannot be deployed on existing devices. On the other hand, software runtime defenses have incomplete coverage or introduce significant performance overhead. In this paper, we propose SnapMem, a hardware/software cooperative memory that can make sensitive data burn after reading on ARM-FPGA embedded SoC. Any process can only access the SnapMem created by itself. Through the cooperation of software and hardware, SnapMem can transfer sensitive data in or out of main memory in real time. Based on this burn-after-reading mechanism, SnapMem can effectively prevent attackers from stealing sensitive data of the victim process or kernel space. Security and performance evaluations show that SnapMem can resist all cross-domain cache-related attacks while introducing lower performance overhead than other software runtime defenses on ARM-FPGA embedded SoC.
Jingquan Ge, Fengwei Zhang
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.1
2023 FlushTime: Towards Mitigating Flush-based Cache Attacks via Collaborating Flush Instructions and Timers on ARMv8-A
abstract
ARMv8-A processors generally utilize optimization techniques such as multi-layer cache, out-of-order execution and branch prediction to improve performance. These optimization techniques are inevitably threatened by cache-related attacks including Flush+Reload, Flush+Flush, Meltdown, Spectre, and their variants. These attacks can break the isolation boundaries between different processes or even between user and kernel spaces. Researchers proposed many defense schemes to resist these cache-related attacks. However, they either need to modify the hardware architecture, have incomplete coverage, or introduce significant performance overhead.
Jingquan Ge, Fengwei Zhang
AsiaCCS1
2023 PumpChannel: An Efficient and Secure Communication Channel for Trusted Execution Environment on ARM-FPGA Embedded SoC
abstract
ARM TrustZone separates the system into the rich execution environment (REE) and the trusted execution environment (TEE). Data can be exchanged between REE and TEE through the communication channel, which is based on shared memory and can be accessed by both REE and TEE. Therefore, when the REE OS kernel is untrusted, the security of the communication channel cannot be guaranteed. The proposed schemes to protect the communication channel have high performance overhead and are not secure enough. In this paper, we propose PumpChannel, an efficient and secure communication channel implemented on ARM-FPGA embedded SoC. PumpChannel avoids the use of secret keys, but utilizes a hardware and software collaborative pump to enhance the security and performance of the communication channel. Besides, PumpChannel implements a hardware-based hook integrity monitor to ensure the integrity of all hook code. Security and performance evaluation results show that PumpChannel is more secure than the encrypted channel countermeasures and has better performance than all other evaluated schemes.
Jingquan Ge, Yuekang Li, Yang Liu 0003, Yaowen Zheng, Yi Liu 0069, Lida Zhao
DATE1
2020 Flush-Detector: More Secure API Resistant to Flush-Based Spectre Attacks on ARM Cortex-A9
abstract
ARM series processors are increasingly used in IoT and cloud services because of their high performance and flexibility of hardware design, especially Cortex-A9 MPCore processor. However, they also suffer from various types of security threats, typically such as flush-based cache attacks. Among these attacks, flush-based Spectre attacks(using Flush + Reload for Spectre attacks) represent a serious threat to system. They usually induce the victim to speculatively perform operations that would not occur during the correct program execution, and then leak the victim’s confidential information to the adversary via cache side channel attacks. So far, there is no widely accepted solution to defend against Spectre attacks. The proposed solutions either lead to large performance losses or sacrifice transparency. In this paper, we propose a secure flush operation API named Flush-Detector to mitigate flush-based Spectre attacks. We present the design and implement of Flush-Detector to detect and defend against flush-based Spectre attacks on ARM Cortex-A9 MPCore. The attack experimental results show that Flush-Detector can detect flush-based Spectre attacks in real time and reduce the attack success rate to less than 1%. Moreover, performance test results demonstrate that the time consumption of Flush-Detector API is about 17.7% longer than the original cache flush API.
Cunqing Ma, Jingquan Ge, Neng Gao, Chenyang Tu
ISCC3
2020 A Hardware/Software Collaborative SM4 Implementation Resistant to Side-channel Attacks on ARM-FPGA Embedded SoC
abstract
The SM4 algorithm is the first commercial cryptographic algorithm officially announced in China for wireless local area network products. It is suitable for scenarios that require high real-time performance, such as wireless communication and IoT sensor nodes. It can be seen that the security research of the SM4 algorithm is of great significance to wireless devices in the IoT. Like other symmetric encryption algorithms, the SM4 algorithm faces some security threats, such as side-channel attacks. Among them, cache timing attacks and power/electromagnetic analysis attacks are becoming more and more threatening due to their low execution difficulty and powerful attack capabilities. Most implementations of anti-side channel attacks against the SM4 algorithm can only resist one of above two attacks. However, side-channel leakages associated with above attacks often coexist.Therefore in this paper, we present a hardware/software collaborative SM4 implementation on ARM-FPGA embedded SoC which can resist above two types of attacks simultaneously. It randomly divides the 32 rounds of SM4 encryption into three stages: the beginning software stage, the middle hardware stage, and the final software stage. Besides, we shuffle the order of some independent operations in each round of the software stages and add dummy rounds to the hardware stage. Finally, we conduct above two types of attacks on unprotected software/hardware SM4, shuffled software SM4 and our scheme, then evaluate their performance respectively. The data throughput of our scheme is 0.86 times that of the original software SM4, while the FPGA resource requirements of our scheme are 0.87 times that of the unprotected hardware implementation.
Ping Peng, Cunqing Ma, Jingquan Ge, Neng Gao, Chenyang Tu
ISCC3
2020 Flush+Time: A High Accuracy and High Resolution Cache Attack On ARM-FPGA Embedded SoC
abstract
Flush based cache attacks have become a practical threat to data privacy and information security due to their advantages such as high accuracy and resolution. However, their accuracy and resolution still has room for improvement. In addition, although most of the attacks have been demonstrated on x86 processors, few of them have been executed on ARM devices. We propose a high accuracy, high resolution flush based cache attack, Flush+Time. This technique solves two important challenges for cache attacks on ARM: how to flush cache lines and how to achieve precise timing. Experiments show that Flush+Time increases accuracy from 95.1% of Flush+Reload, the most powerful general cache attack so far, to 99.3%. Flush+Time has a 30.5% higher resolution than Flush+Reload, but its execution time is only 0.59 times that of Spectre.
Churan Tang, Pengkun Liu, Cunqing Ma, Zongbin Liu, Jingquan Ge
VTS5
2020 MACM: How to Reduce the Multi-Round SCA to the Single-Round Attack on the Feistel-SP Networks
abstract
Since the master key length becomes longer and longer in ciphers, an adversary often needs to preform the multi-round side channel analysis (SCA) in order to recover the master key by enough round keys. Traditional multi-round SCA is launched by adaptive manner in practice, which means that the input of each round is calculated in an on-the-fly way based on all round keys of anterior rounds. However, compared to the classical single-round SCA, the multi-round SCA in adaptive manner is severely limited in several practical scenarios, because all round keys of anterior rounds must be properly recovered before the attack against the next round. In this paper, we focus on the Feistel-SP networks, break the interdependency between the alternating measurement and analysis phases, propose a Multi-round non-Adaptive Chosen Message (MACM) approach, which can reduce the multi-round SCA to the single-round attack. In MACM, the set of plaintexts applied to multiple rounds is calculated in an off-line way. We also prove that the revealed round keys by MACM are adequate to recover the master key. Furthermore, we carefully analyze the advantages of MACM regarding to robustness and compatibility. In order to further manifest the validity of MACM, we perform extensive experiments on three typical Feistel-SP ciphers, Camellia, CLEFIA and SM4, the master keys are recovered as expected, and the number of traces in MACM is at least 25% less than that in the adaptive manner.
Chenyang Tu, Zeyi Liu 0002, Neng Gao, Cunqing Ma, Jingquan Ge, Lingchen Zhang
IEEE Trans. Inf. Forensics Secur.5
2019 More Secure Collaborative APIs Resistant to Flush+Reload and Flush+Flush Attacks on ARMv8-A
abstract
With the popularity of smart devices such as mobile phones and tablets, the security problem of the widely used ARMv8-A processor has received more and more attention. Flush+Reload and Flush+Flush cache attacks have become two of the most important security threats due to their low noise and high resolution. In order to resist Flush+Reload and Flush+Flush attacks, researchers proposed many defense methods. However, these existing methods have various shortcomings. The runtime defense methods using hardware performance counters cannot detect attacks fast enough, effectively detect Flush+Flush or avoid a high false positive rate. Static code analysis schemes are powerless for obfuscation techniques. The approaches of permanently reducing the resolution can only be utilized on browser products and cannot be applied in the system. In this paper, we design two more secure collaborative APIs-flush operation API and high resolution time API-which can resist Flush+Reload and Flush+Flush attacks. When the flush operation API is called, the high resolution time API temporarily reduces its resolution and automatically restores. Moreover, the flush operation API also has the ability to detect and handle suspected Flush+Reload and Flush+Flush attacks. The attack and performance comparison experiments prove that the two APIs we designed are safer and the performance losses are acceptable.
Jingquan Ge, Neng Gao, Chenyang Tu, Ji Xiang, Zeyi Liu 0002
APSEC1
2019 AdapTimer: Hardware/Software Collaborative Timer Resistant to Flush-Based Cache Attacks on ARM-FPGA Embedded SoC
abstract
ARM-FPGA embedded SoCs have been widely used in the fields of drones, embedded and IoT devices due to its high performance and hardware design flexibility. However, ARM-FPGA embedded SoC suffers various types of security threats, one of which is flush-based cache attack. The proposed defense schemes either lead to a high false positive rate or a large performance loss. Due to the importance of high resolution time APIs in the system, schemes that permanently reduce the resolution of time APIs can only be implemented in specific applications such as browsers. Moreover, the method of protecting high resolution timers in software cannot defend against an attacker with root privileges. In this paper, we propose a more secure timer which is a hardware/software co-design on ARM-FPGA embedded SoC. When a software process calls the flush operation, the timer adaptively reduces its resolution and recover after a short period of time. In the case that the flush operation is not called, the impact of the timer on system performance is almost negligible. This hardware/software co-design guarantees the availability of a high resolution time API while defend against attackers with root privileges. The results of the attack experiments show that the success rates of Flush+Reload and flush-based Spectre attacks can be reduced to less than 1% when using the timer. Performance test results show that the timer access latency is 9.5% slower than the fastest PMCCNTR but 5% faster than the global timer of Cortex-A9 MPCore. The modified flush operation API for the design only increases the time consumption by about 12%.
Jingquan Ge, Neng Gao, Chenyang Tu, Ji Xiang, Zeyi Liu 0002
ICCD1
2019 SecFlush: A Hardware/Software Collaborative Design for Real-Time Detection and Defense Against Flush-Based Cache Attacks
Churan Tang, Zongbin Liu, Cunqing Ma, Jingquan Ge, Chenyang Tu
ICICS4
2019 Knowledge Graph Embedding with Order Information of Triplets
Jun Yuan 0008, Neng Gao, Ji Xiang, Chenyang Tu, Jingquan Ge
PAKDD (3)5
2018 Combination of Hardware and Software: An Efficient AES Implementation Resistant to Side-Channel Attacks on All Programmable SoC
Jingquan Ge, Neng Gao, Chenyang Tu, Ji Xiang, Zeyi Liu 0002, Jun Yuan 0008
ESORICS (1)1