EDBT 2026 Demo / reviewers in the wild / expert
Yunkai Bai
dblp:316/5755
· DBLP profile ↗
6ranked-venue papers
3as first author
6since 2021 · last 2026
0000-0001-8929-9421ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 6 · 3 first-author · 6 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | NXT: Sharable Trusted Execution Environment for Multi-Tenant NPU ClusterabstractCloud AI services have experienced rapid development, raising concerns to privacy protection of cloud tenants. Many proposals have been made to use the NPU Trusted Execution Environment (TEE) to protect AI workloads on the cloud. However, existing designs typically bind NPUs exclusively to a single tenant, preventing multiple tenants from sharing the computing power of the TEE-NPUs.As such, we have designed a novel TEE for discrete NPUs, named NXT (NPU eXtension for Trust), which breaks the exclusive binding architecture and allows multiple tenants to securely share the TEE-NPU cluster. Firstly, we introduced an NPU Trusted Agent (NTA) to the most privileged level of the TEE system to assist in the global scheduling of the TEE-NPU cluster. Secondly, we implemented a flexible isolation mechanism to provide security for multi-tenant fine-grained sharing of NPU resources. Thirdly, we support efficient communication between workloads within TEE-NPUs and with legacy NPUs, accelerating multi-workload collaborative computing. We evaluated NXT by extending gem5 and a cycle-accurate NPU simulator to build a prototype. Results show that NXT improves overall utilization by up to 3.49× and ANTT by up to 7.24×, with only 6.38% average overhead for scheduling and isolation. It also boosts parallel inference performance by 58.3% for GPT-2(XL) and 63.6% for LLaMA-13B compared to static protection schemes. Shiwen Wang 0002, Peinan Li, Yunkai Bai, Wu Luo, Guang Yan, Dan Meng 0002, Rui Hou 0001 |
IEEE Trans. Computers | 3 |
| 2025 | Tips: Augment Memory Tagging to Defend Against Prefetcher Side ChannelsabstractHardware prefetchers are essential for hiding memory latency and improving performance in commercial processors. However, recent studies have revealed that they can be exploited to launch side-channel attacks that leak sensitive data, recover cryptographic keys, and break the isolation of trusted execution environments. We observe that such attacks closely resemble classic memory safety violations, including buffer overflows, type confusion, use-after-free, and data race. This paper presents TIPS (Tag AugmentatIon for Prefetcher Security), a lightweight extension to the memory safety mechanisms already deployed in commercial processors. TIPS enhances memory tagging to protect prefetchers by enforcing tag-based array bounds, validating pointer types, associating prefetch patterns with their source threads or cores, and suppressing contentionbased interference. Experiments demonstrate that TIPS incurs less than 1.50 % performance overhead and 0.81 % area cost, while providing strong defense against a broad class of prefetcher side-channel attacks. Yubiao Huang, Peinan Li, Huan Qiao, Yunkai Bai, Shiwen Wang 0002, Dan Meng 0002, Rui Hou 0001 |
ICCD | 4 |
| 2024 | SecPaging: Secure Enclave Paging with Hardware-Enforced Protection against Controlled-Channel AttacksabstractAs a prevalent privacy-preserving technology, Trusted Execution Environment has become widely adopted in numerous commercial processors. Nonetheless, they remain susceptible to various controlled-channel attacks. Untrusted operating systems can deduce enclave secrets by manipulating page tables or observing allocation- or swap-based page faults. In this paper, we propose SecPaging, a novel secure enclave paging mechanism based on hardware-enforced and microcode-supported protection to prevent these attacks. First, enclave PTEs are protected through hardware isolation, preventing privileged attackers from malicious tampering or observations. Second, an Eager-Allocation mechanism is employed to prevent allocation-based controlled-channel attacks. Besides, a Record-Reload mechanism is proposed to prevent swap-based controlled-channel attacks. We simulate SecPaging on real SGX. Experiments demonstrate that controlled channel attacks can be defended with minimal performance overhead. Yunkai Bai, Peinan Li, Yubiao Huang, Shiwen Wang 0002, Xingbin Wang, Dan Meng 0002, Rui Hou 0001 |
DAC | 1 |
| 2024 | EnTurbo: Accelerate Confidential Serverless Computing via Parallelizing Enclave Startup ProcedureabstractServerless computing has gained widespread attention, and Trusted Execution Environments (TEEs) are well-suited for safeguarding user privacy. However, the additional startup procedure introduced by TEEs imposes considerable performance overhead on confidential serverless workloads. This paper introduces a novel parallelized enclave startup design, EnTurbo, which eliminates the integrity dependence of the enclave startup procedure, accelerating it while ensuring its security. Additionally, EnTurbo parallelizes the measurement procedure, enabling multi-thread measurement for acceleration with provable security. We evaluate EnTurbo by running confidential serverless workloads on SGX simulation mode. Results show that EnTurbo effectively speeds up enclave serverless by 1.42x-6.48x (SGXv1) and 1.33x-3.76x (SGXv2). Yifan Zhu 0008, Peinan Li, Yunkai Bai, Yubiao Huang, Shiwen Wang 0002, Xingbin Wang, Dan Meng 0002, Rui Hou 0001 |
DAC | 3 |
| 2024 | HyperTEE: A Decoupled TEE Architecture with Secure Enclave ManagementabstractTrusted Execution Environment (TEE) architectures have been deployed in various commercial processors to provide secure environments for confidential programs and data. However, as a relatively new feature against security threats, existing designs still face a number of problems. Exploiting the management vulnerabilities, attackers can disclose secrets via controlled-channel or micro-architecture side-channel attacks. To address these problems, this paper proposes a novel TEE architecture, named HyperTEE. In our architecture, enclave management tasks are decoupled from the original computing subsystem to a dedicated, physically isolated Enclave Manage-ment Subsystem (EMS). A properly architected EMS prevents current management vulnerabilities and offers more secure enclave communication. We implemented the HyperTEE prototype on the FPGA platform. Experiments show that HyperTEE only introduces less than 1% area overhead, and 2.0 % and 1.9 % performance overhead on average for enclaves and non-enclave workloads, respectively. Yunkai Bai, Peinan Li, Yubiao Huang, Michael C. Huang 0001, Shijun Zhao, Lutan Zhao, Fengwei Zhang, Dan Meng 0002, Rui Hou 0001 |
MICRO | 1 |
| 2022 | RASCv2: Enabling Remote Access to Side-Channels for Mission Critical and IoT SystemsabstractThe Internet of Things (IoT) and smart devices are currently being deployed in systems such as autonomous vehicles and medical monitoring devices. The introduction of IoT devices into these systems enables network connectivity for data transfer, cloud support, and more, but can also lead to malware injection. Since many IoT devices operate in remote environments, it is also difficult to protect them from physical tampering. Conventional protection approaches rely on software. However, these can be circumvented by the moving target nature of malware or through hardware attacks. Alternatively, insertion of the internal monitoring circuits into IoT chips requires a design trade-off, balancing the requirements of the monitoring circuit and the main circuit. A very promising approach to detecting anomalous behavior in the IoT and other embedded systems is side-channel analysis. To date, however, this can be performed only before deployment due to the cost and size of side-channel setups (e.g., and oscilloscopes, probes) or by internal performance counters. Here, we introduce an external monitoring printed circuit board (PCB) named RASC to provide r emote a ccess to s ide- c hannels. RASC reduces the complete side-channel analysis system into two small PCBs (2 \( \times \) 2 cm), providing the ability to monitor power and electromagnetic (EM) traces of the target device. Additionally, RASC can transmit data and/or alerts of anomalous activities detected to a remote host through Bluetooth. To demonstrate RASCs capabilities, we extract keys from encryption modules such as AES implemented on Arduino and FPGA boards. To illustrate RASC’s defensive capabilities, we also use it to perform malware detection. RASC’s success in power analysis is comparable to an oscilloscope/probe setup but is lightweight and two orders of magnitude cheaper. Yunkai Bai, Andrew Stern, Jungmin Park, Mark Tehranipoor, Domenic Forte |
ACM Trans. Design Autom. Electr. Syst. | 1 |