EDBT 2026 Demo / reviewers in the wild / expert
Wende Tan
dblp:228/6653
· DBLP profile ↗
13ranked-venue papers
3as first author
10since 2021 · last 2026
0000-0002-7823-7441ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 6 since 2021Systems, architecture and hardware · 5 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 3 · 1 since 2021Artificial intelligence and machine learning · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LatticeBox: A Hardware-Software Co-Designed Framework for Scalable and Low-Latency Compartmentalization
Zhanpeng Liu, Wende Tan, Xinhui Han |
NDSS | 3 |
| 2025 | VulShield: Protecting Vulnerable Code Before Deploying Patches
Yuan Li 0061, Chao Zhang 0008, Jinhao Zhu, Penghui Li 0001, Songtao Yang 0001, Wende Tan |
NDSS | 7 |
| 2025 | CCTAG: Configurable and Combinable Tagged Architecture
Zhanpeng Liu, Wende Tan, Yuan Li 0061, Xinhui Han, Songtao Yang 0001, Chao Zhang 0008 |
NDSS | 4 |
| 2025 | Truman: Constructing Device Behavior Models from OS Drivers to Fuzz Virtual Devices
Zheyu Ma, Qiang Liu 0034, Zheming Li, Tingting Yin, Wende Tan, Chao Zhang 0008, Mathias Payer |
NDSS | 5 |
| 2024 | Improving ML-based Binary Function Similarity Detection by Assessing and Deprioritizing Control Flow Graph Features
Jialai Wang, Chao Zhang 0008, Yuxiao Wu, Hao Wang 0003, Wende Tan, Qi Li 0002, Zongpeng Li |
USENIX Security Symposium | 7 |
| 2024 | ROLoad-PMP: Securing Sensitive Operations for Kernels and Bare-Metal FirmwareabstractA common way for attackers to compromise victim systems is hijacking sensitive operations (e.g., control-flow transfers) with attacker-controlled inputs. Existing solutions in general only protect parts of these targets and have high performance overheads, which are impractical and hard to deploy on systems with limited resources (e.g., IoT devices) or for low-level software like kernels and bare-metal firmware. In this paper, we present a lightweight hardware-software co-design solution ROLoad-PMP to protect sensitive operations from being hijacked for low-level software. First, we propose new instructions, which only load data from read-only memory regions with specific keys, to guarantee the integrity of pointees pointed by (potentially corrupted) data pointers. Then, we provide a program hardening mechanism to protect sensitive operations, by classifying and placing their operands into read-only memory with different keys at compile-time and loading them with ROLoad-PMP-family instructions at runtime. We have implemented an FPGA-based prototype of ROLoad-PMP based on RISC-V, and demonstrated an important defense application, i.e., forward-edge control-flow integrity. Results showed that ROLoad-PMP only costs few extra hardware resources ($\lt 1.40\%$). Moreover, it enables many lightweight (e.g., with negligible overheads$\lt 0.853\%$) defenses, and provides broader and stronger security guarantees than existing hardware solutions, e.g., ARM BTI and Intel CET. Wende Tan, Yangyu Chen 0002, Yuan Li 0061, Chao Zhang 0008 |
IEEE Trans. Computers | 1 |
| 2023 | PTStore: Lightweight Architectural Support for Page Table IsolationabstractPage tables are critical data structures in kernels, serving as the trust base of most mitigation solutions. Their integrity is thus crucial but is often taken for granted. Existing page table protection solutions usually provide insufficient security guarantees, require heavy hardware, or introduce high overheads. In this paper, we present a novel lightweight hardware-software co-design solution, PTStore, consisting of a secure region storing page tables and tokens verifying page table pointers. Evaluation results on FPGA-based prototypes show that PTStore only introduces <0.92% hardware overheads and <0.86% performance overheads, but provides strong security guarantees, showing that PTStore is efficient and effective. Wende Tan, Yangyu Chen 0002, Yuan Li 0061, Ying Liu 0024, Chao Zhang 0008 |
DAC | 1 |
| 2023 | Thunderkaller: Profiling and Improving the Performance of SyzkallerabstractFuzzing is widely adopted to discover vulnerabilities in software, including the kernel. One of the most popular and state-of-the-art fuzzers for kernels is Syzkaller. However, Syzkaller has a much lower testing throughput compared to other user-space fuzzers, which affects the efficiency of both Syzkaller and other Syzkaller-based fuzzers. In this paper, we profiled the performance of Syzkaller, recognized that the major cost comes from program isolation and kernel instrumentation, and then proposed kernel image duplication and three optimization techniques to mitigate such overheads and present the solution Thunderkaller. Our solution does not change or depend on the fuzzing algorithm in any way, orthogonal to other refinements to Syzkaller. Our evaluation shows that, in 24 hours, Thunderkaller speeds up 2.8× compared to vanilla Syzkaller, achieves 25.8% more basic block coverage, detects 21 more unique bugs, and triggers the common bugs 6.3× faster. In a long time of fuzzing, we have found 6 unique Linux kernel bugs and obtained a CVE. Zhun Wang, Wende Tan, Zheyu Ma, Chao Zhang 0008 |
ASE | 4 |
| 2022 | PACMem: Enforcing Spatial and Temporal Memory Safety via ARM Pointer AuthenticationabstractMemory safety is a key security property that stops memory corruption vulnerabilities. Different types of memory safety enforcement solutions have been proposed and adopted by sanitizers or mitigations to catch and stop such bugs, at the development or deployment phase. However, existing solutions either provide partial memory safety or have overwhelmingly high performance overheads. Yuan Li 0061, Wende Tan, Zhizheng Lv, Songtao Yang 0001, Mathias Payer, Ying Liu 0024, Chao Zhang 0008 |
CCS | 2 |
| 2021 | ROLoad: Securing Sensitive Operations with Pointee IntegrityabstractSensitive operations (e.g. control-flow transfers) are attractive targets for attackers. To protect them from being hijacked, we propose a new solution ROLoad to guarantee the integrity of their operands, which are loaded from (potentially corrupted) memory. We extend the RISC-V instruction set, implement an FPGA-based prototype of ROLoad, and then demonstrate two specific defense applications. Results show that this solution only costs few extra hardware resources (< 3.32%). However, it could enable many lightweight (e.g. with overheads less than 0.31%) defenses, and provide broader and stronger security guarantees than existing hardware solutions, e.g. ARM BTI and Intel CET. Wende Tan, Yuan Li 0061, Chao Zhang 0008, Xingman Chen, Songtao Yang 0001, Ying Liu 0024 |
DAC | 1 |
| 2019 | DCNS: Automated Detection Of Conservative Non-Sleep Defects in the Linux KernelabstractFor waiting, the Linux kernel offers both sleep-able and non-sleep operations. However, only non-sleep operations can be used in atomic context. Detecting the possibility of execution in atomic context requires a complete inter-procedural flow analysis, often involving function pointers. Developers may thus conservatively use non-sleep operations even outside of atomic context, which may damage system performance, as such operations unproductively monopolize the CPU. Until now, no systematic approach has been proposed to detect such conservative non-sleep (CNS) defects. Jia-Ju Bai, Julia Lawall, Wende Tan, Shi-Min Hu 0001 |
ASPLOS | 3 |
| 2019 | TZC: Efficient Inter-Process Communication for Robotics Middleware with Partial SerializationabstractInter-process communication (IPC) is one of the core functions of modern robotics middleware. We propose an efficient IPC technique called TZC (Towards Zero-Copy). As a core component of TZC, we design a novel algorithm called partial serialization. Our formulation can generate messages that can be divided into two parts. During message transmission, one part is transmitted through a socket and the other part uses shared memory. The part within shared memory is never copied or serialized during its lifetime. We have integrated TZC with ROS and ROS2 and find that TZC can be easily combined with current open-source platforms. By using TZC, the overhead of IPC remains constant when the message size grows. In particular, when the message size is 4MB (less than the size of a full HD image), TZC can reduce the overhead of ROS IPC from tens of milliseconds to hundreds of microseconds and can reduce the overhead of ROS2 IPC from hundreds of milliseconds to less than 1 millisecond. We also demonstrate the benefits of TZC by integrating it with TurtleBot2 to be used in autonomous driving scenarios. We show that by using TZC, the braking distance can be 16% shorter than with ROS. Yu-Ping Wang 0001, Wende Tan, Xu-Qiang Hu, Dinesh Manocha, Shi-Min Hu 0001 |
IROS | 2 |
| 2019 | IVT: an efficient method for sharing subtype polymorphic objectsabstractShared memory provides the fastest form of inter-process communication. Sharing polymorphic objects between different address spaces requires solving the issue of sharing pointers. In this paper, we propose a method, named Indexed Virtual Tables (IVT for short), to share polymorphic objects efficiently. On object construction, the virtual table pointers are replaced with indexes, which are used to find the actual virtual table pointers on dynamic dispatch. Only a few addition and load instructions are needed for both operations. Experimental results show that the IVT can outperform prior techniques on both object construction time and dynamic dispatch time. We also apply the proposed IVT technique to several practical scenarios, resulting the improvement of overall performance. Yu-Ping Wang 0001, Xu-Qiang Hu, Zixin Zou, Wende Tan, Gang Tan |
Proc. ACM Program. Lang. | 4 |