EDBT 2026 Demo / reviewers in the wild / expert
Runyu Pan
dblp:224/5662
· DBLP profile ↗
13ranked-venue papers
3as first author
9since 2021 · last 2026
0000-0001-6090-2733ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 9 · 3 first-author · 5 since 2021Computer networks · 3 · 3 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Work in Progress: Enabling Deterministic User-Level Interrupts in Microcontrollers via Hardware Extension
Hongbin Yang 0001, Huanle Zhang, Tuo Wu, Runyu Pan |
RTAS | 4 |
| 2026 | LwRustIP: Memory-safe and efficient embedded networking stack with ownership semanticsabstractAs modern embedded systems are increasingly network connected, their protocol stacks expose themselves as a surface that is frequently attacked. While C-based implementations such as LwIP are efficient, their lack of memory safety induces critical vulnerabilities such as buffer overflows, dangling pointers, and use-after-free, leading to remote code execution or privilege escalation. In this paper, we present LwRustIP , a memory-safe embedded networking stack reimplemented in Rust and compatible with LwIP . We also share our development experience. LwRustIP replaces unsafe linked-list memory management with a custom allocator that honors the Rust ownership semantics, leverages zero-copy techniques for inter-layer packet handoffs, and applies lock-free object pools for concurrent buffer management. These design choices ensure memory safety while maintaining performance comparable to traditional C-based implementations. We deploy LwRustIP on ARM-based embedded platforms and evaluate its correctness, performance, and memory safety. Experimental results show that LwRustIP achieves memory safety without incurring measurable performance overhead compared to the original C-based implementation. Our experience highlights the practical challenges and benefits of using Rust for low-level system components and offers guidance for future efforts in memory-safe reengineering of legacy C codebases. Guangyong Shang, Guangpeng Qi, Jianing Ren, Xianqi Jin, Wanjiang Shen, Runyu Pan |
High Confid. Comput. | 7 |
| 2026 | MetaRFence: Protecting Human Motion Privacy Against RFID Sensing via MetasurfaceabstractRadio Frequency Identification (RFID) technology has emerged as a pervasive modality for human motion sensing in applications such as smart environments and healthcare monitoring. However, the inherent through-wall sensing capability of RFID technology raises critical privacy concerns regarding the unintended leakage of human motion information, a challenge that has not been adequately addressed. To fill this gap, we present a metasurface-based RFID sensing defence (MetaRFence), the first system designed to protect human motion privacy against adversarial through-wall RFID sensing. To this end, we first devise a programmable metasurface comprising 1-bit phase shifters to systematically obfuscate motion-induced signal patterns. Then, we characterize the metasurface's impact on RFID signals across temporal and spectral domains through comprehensive theoretical modeling and empirical investigations. However, our analysis reveals that it is non-trivial to achieve effective signal obfuscation in both domains, primarily due to a fundamental trade-off between increasing temporal signal variation and masking human motion in its spectrum. To overcome this, we judiciously devise a metasurface controlling strategy that jointly optimizes the signal entropy, variance, and spectrum distribution to reach a balance between temporal and spectral motion obfuscation. Our comprehensive experiments demonstrate thatMetaRFencereduces adversarial through-wall motion detection rates to$\leq$6%, decreases the F1-score of human gesture recognition to$\leq$0.11 on average, and amplifies respiration rate estimation errors by 3×, establishing a robust defense mechanism for RFID-based motion privacy protection. Zheng Shi 0006, Zhikai Ding, Yanni Yang 0003, Zhenlin An, Runyu Pan, Yanling Bu, Pengfei Hu 0001, Jiannong Cao 0001 |
IEEE Trans. Mob. Comput. | 5 |
| 2025 | RFNOID: Protecting RFID Motion Privacy via Metasurface
Yanni Yang 0003, Zheng Shi 0006, Zhenlin An, Runyu Pan, Yanling Bu, Pengfei Hu 0001, Jiannong Cao 0001 |
INFOCOM | 4 |
| 2025 | IoT-Enabled Supply Chain Management From a Customer Perspective: Challenges and OpportunitiesabstractSupply chain management (SCM), a critical factor in enhancing companies’ efficiency and competitiveness, has received significant attention from both industry and academia. Beyond the flow of products from supplier to customer, SCM also involves the flow of information necessary to monitor, track, and optimize the entire product lifecycle. Consequently, integrating the information flow in SCM with the Internet of Things (IoT) is imperative, as IoT provides the ability to onboard, interconnect, interact with, and sense products. However, IoT-enabled SCM also presents unique challenges, such as managing large volumes of data, ensuring credible and traceable data sources, and achieving low-cost, seamless connectivity. In this article, we systematically present recent advances in leveraging IoT to build robust and effective SCM systems. Unlike existing surveys and overviews, this article focuses on the customer side as customers are the destination of the information flow and tightly coupled with IoT networks. We offer deep insights into the principles, challenges, and research opportunities in IoT-enabled SCM, aiming to assist IoT practitioners in understanding and designing IoT solutions for SCM. Runyu Pan, Tianbo Gu, Xiuzhen Cheng, Huanle Zhang |
IEEE Internet Things J. | 2 |
| 2025 | FVM: Practical Feather-Weight Virtualization on Commodity MicrocontrollersabstractRecently, there has been an increasing drive to consolidate multiple microcontrollers into one physical entity, due to advantages in reducing overall costs, enhancing reliability, and simplifying hardware interconnections. To reduce consolidation engineering costs, minimizing system latency and memory footprint is important as well as maintaining compatibility with legacy software. In this paper, we propose a virtualization-based solution called Feather-weight Virtual Machine (FVM) that focuses on these goals.FVMenables low latency by specializing the virtualization model to Real-Time Operating Systems (RTOSes), achieves small footprint by adapting management policies to microcontroller memories, attains high compatibility by aligning with microcontroller ecosystem idiosyncrasies, finally allowing practical consolidation across a wide range of commodity microcontrollers. We implement and evaluateFVMon ARMv6-M, ARMv7-M, and RISC-V architectures with two toolchains and two RTOSes, and it can fit into 20 KiB of RAM with less than 5% latency bloat. Runsheng Hou, Guangyong Shang, Huanle Zhang, Xiuzhen Cheng, Runyu Pan |
IEEE Trans. Computers | 6 |
| 2024 | OmniWasm: Efficient, Granular Fault Isolation and Control-Flow Integrity for Arm MicrocontrollersabstractTraditional embedded systems often ignore security, instead focusing on simplicity. Unfortunately, increasingly per-vasive network connectivity exposes these systems to malicious input, and the consolidation of code of various qualities and sources onto single systems increases the chance of errant behavior. Microcontrollers do not often have advanced security facilities to help prevent malicious threats - even the use of memory protection to constrain the ill-effects of a compromise is not pervasive. Software techniques to provide strong security properties for application execution often focus on limiting accessible memory through dynamic checks on memory accesses through software fault isolation (SFI), and on ensuring that software cannot suffer from control-flow hijack attacks through control-flow integrity (CFI). This paper introduces OmniWasm, which provides sandboxes in which applications execute that provide both SFI and CFI. OmniWasm focuses on two core contributions. First, it reduces the overhead of these techniques by using a novel application of common, but obscure memory operations to both limit sandboxed memory accesses (SFI) using hardware, and allow memory accesses outside the sandbox to enable CFI. Second, it focuses on enabling embedded soft-ware to be decomposed into multiple sandboxes by providing optimized communication facilities between them that avoid thread context switching overheads and providing single-copy message passing. We show that the overheads of OmniWasm are better than existing software address validation techniques while also providing better memory utilization. We also show that OmniWasm enables significant performance gains for inter-sandbox communication across varying message sizes. Maorui Bai, Runyu Pan, Gabriel Parmer |
RTAS | 2 |
| 2022 | SBIs: Application Access to Safe, Baremetal Interrupt Latencies*abstractThe continued increase in Cyber-Physical System (CPS) complexity and tightening of Size, Weight and Power (SWaP) constraints are driving the need for consolidation of software tasks onto fewer microcontrollers. Many embedded systems, prominently including those in the Internet-of-Things (IoT), use software packages from multiple untrusted sources, while their network interfaces expose new attack surfaces that are not present in traditional off-line devices. Increased consolidation with untrusted code of various assurance levels complicates system design, and requires increased spatial and temporal isolation between the applications. Current microcontroller protection domain designs are limited by their long interrupt latencies to isolated applications, forcing the system designers to place timing-sensitive application code into the kernel interrupt handlers, trading spatial isolation for tightly-bounded temporal predictability.SBI (Secure Baremetal Interrupt) enables zero-software-cost delivery of interrupts to protection domains in a secure manner that maintains isolation. We demonstrate an implementation of SBI using the new hardware-accelerated interrupt delivery features on TrustZone-M-enabled microcontrollers. This implementation reduces interrupt latencies by up to 95%, while maintaining strong spatial and temporal isolation. We believe SBI could significantly enable future real-time systems that require both isolation and high responsiveness. Runyu Pan, Gabriel Parmer |
RTAS | 1 |
| 2021 | Practical Principle of Least Privilege for Secure Embedded SystemsabstractMany embedded systems have evolved from simple bare-metal control systems to highly complex network-connected systems. These systems increasingly demand rich and feature-full operating-systems (OS) functionalities. Furthermore, the network connectedness offers attack vectors that require stronger security designs. To that end, this paper defines a prototypical RTOS API called Patina that provides services common in featurerich OSes (e.g., Linux) but absent in more trustworthy μ -kernel based systems. Examples of such services include communication channels, timers, event management, and synchronization. Two Patina implementations are presented, one on Composite and the other on seL4, each of which is designed based on the Principle of Least Privilege (PoLP) to increase system security. This paper describes how each of these μ -kernels affect the PoLP based design, as well as discusses security and performance tradeoffs in the two implementations. Results of comprehensive evaluations demonstrate that the performance of the PoLP based implementation of Patina offers comparable or superior performance to Linux, while offering heightened isolation. Samuel Jero, Juliana Furgala, Runyu Pan, Phani Kishore Gadepalli, Alexandra Clifford, Bite Ye, Roger I. Khazan, Bryan C. Ward, Gabriel Parmer, Richard Skowyra |
RTAS | 3 |
| 2020 | Slite: OS Support for Near Zero-Cost, Configurable Scheduling *abstractDespite over 35 years of wildly changing requirements and applications, real-time systems have treated the kernel implementation of system scheduling policy as given. New time management policies are either adapted to the kernel, and rarely adopted, or emulated in user-level under the restriction that they must stay within the confines of the underlying system’s mechanisms. This not only hinders the agility of the system to adapt to new requirements, but also harms non-functional properties of the system such as the effective use of parallelism, and the application of isolation to promote security. This paper introduces Slite, a system designed to investigate the possibilities of near zero-cost scheduling of system-level threads at user-level. This system efficiently and predictably enables the user-level implementation of configurable scheduling policies. This capability has wide-ranging impact, and we investigate how it can increase the isolation, thus dependability, of a user-level real-time OS, and how it can provide a real-time parallel runtime with better analytical properties using thread-based – rather than the conventional task-based – scheduling. We believe these benefits motivate a strong reconsideration of the fundamental scheduling structure in future real-time systems. Phani Kishore Gadepalli, Runyu Pan, Gabriel Parmer |
RTAS | 2 |
| 2020 | eWASM: Practical Software Fault Isolation for Reliable Embedded DevicesabstractAs we connect more microcontrollers to the Internet and employ them to control the physical world around us, their reliability and security are increasingly important. Many microcontrollers provide limited facilities for hardware isolation, and real-time OSes offer custom APIs, that require coupling applications into the ecosystem and abstractions of that specific OS to leverage isolation. This article investigates the use of software sandboxing of applications to support isolation for resource-constrained devices. Toward this, we detail the design of eWASM, a processes abstraction that adapts a popular sandbox, Wasm, for microcontrollers. eWASM provides a runtime to constrain memory accesses and control flow, enabled by our aWsm Wasm compiler. We discuss and evaluate its multiple implementations that effectively trade time and space, optimizing for the constraints of embedded systems. This enables popular languages (e.g., C) to be effectively sandboxed by software. We demonstrate performance within 40% of native C on Polybench. We believe this is a practical and compelling result for many IoT domains, and it represents the first compiled sandboxing environment for microcontrollers. We show that restrictions of the current Wasm specification lead to significant memory consumption and provide suggestions for the creation of an embedded-specific Wasm variant. Gregor Peach, Runyu Pan, Zhuoyi Wu, Gabriel Parmer, Christopher Haster, Ludmila Cherkasova |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2019 | MxU: Towards Predictable, Flexible, and Efficient Memory Access Control for the Secure IoTabstractThe advanced functionality requirements of modern embedded and Internet of Things (IoT) devices -- from autonomous vehicles, to city and power-grid management -- are driving an ever-increasing software complexity. At the same time, the pervasive internet connections of these systems necessitate the fundamental design of security into these devices. The isolation of complex features from those that are critical through protection domains is an effective means to constrain the scope of faults and security breaches. Common hardware-provided memory facilities to enforce protection domains through memory access control -- including Memory Management Units (MMUs) usually found in microprocessors, and Memory Protection Units (MPUs) usually found in microcontrollers -- must meet the goals of enabling flexible, efficient and dynamic management of memory , and must enable tight bounds on the worst-case execution of critical code. Unfortunately, current system memory management facilities are ill-prepared to handle this challenge: MMUs that use extensive caches to achieve strong average-case performance suffer from debilitating worst-case and even average-case behavior under hefty interference, while MPUs struggle to provide flexible memory management. This paper details MxU, a memory protection and allocation abstraction that integrates temporal specifications into the memory management subsystem, to enable portable code to achieve both predictable, tightly-bounded execution and dynamic management across both MMU- and MPU-based systems. We implement MxU in the Composite microkernel, and evaluate its flexibility and predictability over two different architectures: a MPU-based Cortex-M7 microcontroller and a MMU-based Cortex-A9 microprocessor using a suite of modern applications including neural network-based inference, SQLite, and a javascript runtime. For MMU-based systems, MxU reduces application TLB stall by up to 68.0%. For MPU-based systems, MxU enables flexible dynamic memory management often with application overheads of 1%, increasing to 6.1% under significant interference. Runyu Pan, Gabriel Parmer |
ACM Trans. Embed. Comput. Syst. | 1 |
| 2018 | Predictable Virtualization on Memory Protection Unit-Based MicrocontrollersabstractWith the increasing penetration of embedded systems into the consumer market there is a pressure to have all of inexpensiveness, predictability, reliability, and security. As these systems are often attached to networks and execute complex code from varying sources, reliability and security become essential. To maintain low price and small power budgets, many systems use small microcontrollers with limited memory (on the order of 128KB of SRAM). Unfortunately, the isolation and protection facilities of these systems are often lackluster, making a principled treatment of reliability and security difficult. This paper details a system that provides isolation along the three dimensions of CPU, memory, and I/O on small microcontrollers. A key challenge is providing a effective means of harnessing the limited hardware memory protection facilities of microcontrollers. This is achieved through a combination of a static analysis to make the most of limited hardware protection facilities, and a run-time based on our Composite OS. On this foundation, we build a virtualization infrastructure to execute multiple embedded real-time operating systems predictably. We show that VMs based on FreeRTOS achieve reasonable efficiency and predictability, while easily enabling scaling up to 8 VMs in 512 KB SRAM. Runyu Pan, Gregor Peach, Yuxin Ren 0001, Gabriel Parmer |
RTAS | 1 |