Weidong Zhu 0002

dblp:34/2615-2 · DBLP profile ↗
← Back
13ranked-venue papers
5as first author
9since 2021 · last 2025
0000-0002-9812-6634ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 8 · 2 first-author · 4 since 2021Security and privacy · 5 · 3 first-author · 5 since 2021
YearPublicationVenuePosition
2025 Enabling Plausible Deniability in Flash-based Storage through Data Permutation
abstract
Plausible deniability (PD) allows at-risk users to deny the existence of their sensitive data stored on storage devices. This is critical to protect the privacy and the personal safety of users, as adversaries might force users to decrypt their devices, risking the disclosure of sensitive data that could endanger their lives and liberty. In this work, we show how current PD systems built on flash memory fail to obscure distinguishable data layouts created when hidden data is written. This deficiency makes them vulnerable to coercive adversaries who can capture single or multiple data snapshots of storage devices for scrutiny. To defend against this threat, we propose MUTE, a perMUTation-based PD systEm designed for flash memory. Building upon widely-adopted full disk encryption (FDE) mechanisms that provide device-level data encryption, MUTE modifies the distribution of initialization vectors (IV s) for encryption blocks within FDE, translating the hidden data into a permutation derived from the IV. Unlike other PD solutions, MUTE allows for storing hidden data without requiring the reduction of storage capacity. Moreover, it preserves the plausible deni-ability of the hidden data in a provably secure manner by maintaining the original logic of data operations on the flash memory without changing the data layout. We implement MUTE in the flash translation layer (FTL) of flash-based SSDs using FEMU, a widely-used emulator supporting flash mem-ory research. Our evaluation with various micro-benchmarks and real-world workloads demonstrates that MUTE provides practical write and read throughputs of 23.4 MB/s and 15.7 MB/s and a capacity of 25.3 GB for hidden data in a 512 GB SSD, comparable with existing PD systems. MUTE achieves strong PD guarantees for flash-based devices against coercive adversaries, outperforming current PD systems. Index Terms-Plausible Deniability, Data Layout, Flash-based SSDs
Weidong Zhu 0002, Vincent Bindschaedler, Sara Rampazzi, Kevin R. B. Butler
ACSAC1
2025 Enabling Secure and Efficient Data Loss Prevention with a Retention-aware Versioning SSD
Weidong Zhu 0002, Carson Stillman, Sara Rampazzi, Kevin R. B. Butler
CCS1
2025 SrFTL: Leveraging Storage Semantics for Effective Ransomware Defense in Flash-based SSDs
abstract
Ransomware attacks have become increasingly frequent and high-profile, resulting in billions of dollars in data and operational losses annually. Current mechanisms typically deploy defenses in vulnerable operating systems, making them susceptible to advanced adversaries capable of compromising the OS. While implementing defense mechanisms within storage devices can address this vulnerability, they lack detection accuracy due to their inability to access data semantics, such as file system metadata. Moreover, these methods only expose block-level interfaces without file-level information, limiting the usability and practicality of data recovery management. Therefore, we develop SrFTL , a novel ransomware defense framework that allows leveraging data semantics for accurate ransomware detection and effective file-level data recovery against data compromise. Specifically, SrFTL employs defense enforcement within the flash translation layer (FTL) of SSDs. Then, SrFTL combines the secure enclave with the modified FTL through a secure channel to enable flexible ransomware defenses within the enclave. Finally, SrFTL deploys ransomware classification and data recovery defenses in the enclave, providing high detection accuracy and low-cost data recovery. Our evaluation demonstrates that SrFTL achieves zero false positives and negatives when detecting our collected real-world ransomware samples and benign applications, outperforming current FTL-level solutions (e.g., MimosaFTL). Moreover, SrFTL introduces on average a trivial performance overhead of 1.5% compared with a regular SSD. Finally, evaluating against multiple real-world ransomware samples, SrFTL enables fast data recovery with an average time of 9.3 seconds. SrFTL thus bridges the semantic gap between the FTL and OS-level file information to stop ransomware while maintaining the integrity and authenticity of employed defenses.
Weidong Zhu 0002, Grant Hernandez, Washington Garcia, Jing (Dave) Tian, Sara Rampazzi, Kevin R. B. Butler
ACM Trans. Storage1
2024 Leveraging Storage Semantics to Enhance Data Security and Privacy
abstract
Data within a system travels through an I/O path from its generation in an application to its final storage on a device. Ensuring data security and privacy is a significant design concern, but heavily modulated storage stacks complicate understanding the data, thus presenting challenges to maintaining these properties. For example, the firmware in a storage device cannot interpret the semantics of an I/O request from the host, making it challenging to employ a semantic-aware malware defense in the storage device. Additionally, the evolution of storage media can weaken data privacy protection guarantees due to varying physical characteristics. Preserving the guarantee of data security and privacy requires understanding storage semantics, which provides insights into the data content and the architectural components within the storage system.
Weidong Zhu 0002
CCS1
2024 RANsacked: A Domain-Informed Approach for Fuzzing LTE and 5G RAN-Core Interfaces
abstract
Cellular network infrastructure serves as the backbone of modern mobile wireless communication. As such, cellular cores must be proactively secured against external threats to ensure reliable service. Compromised base station attacks against the core are a rising threat to cellular networks, while user device inputs have long been considered as an attack vector; despite this, few techniques exist to comprehensively test RAN-Core interfaces against malicious input. In this work, we devise a fuzzing framework that performantly fuzzes cellular interfaces accessible from a base station or user device, overcoming several challenges in fuzzing specific to LTE/5G network components. We also introduce ASNFuzzGen, a tool that compiles ASN.1 specifications into structure-aware fuzzing modules, thereby facilitating effective fuzzing exploration of complex cellular protocols. We run fuzzing campaigns against seven open-source and commercial cores and discover 119 vulnerabilities, with 93 CVEs assigned. Our results reveal common implementation mistakes across several cores that lead to vulnerabilities, and the successful coordination of patches for these vulnerabilities across several vendors demonstrates the practical impact ASNFuzzGen has on hardening user-exposed cellular systems.
Nathaniel Bennett, Weidong Zhu 0002, Benjamin Simon, Ryon Kennedy, William Enck, Patrick Traynor, Kevin R. B. Butler
CCS2
2024 AquaSonic: Acoustic Manipulation of Underwater Data Center Operations and Resource Management
abstract
Underwater data centers (UDCs) hold promise as next-generation data storage due to their energy efficiency and environmental sustainability benefits. While the natural cooling properties of water save power, the isolated aquatic environment and long-range sound propagation characteristics in water create unique vulnerabilities which differ from those of on-land data centers. Our research discovers the unique vulnerabilities of fault-tolerant storage devices, resource allocation software, and distributed file systems to acoustic injection attacks in UDCs. With a realistic testbed approximating UDC server operations, we empirically characterize the capabilities of acoustic injection underwater and find that an attacker can reduce fault-tolerant RAID 5 storage system throughput by 17% up to 100%. Our closed-water analyses reveal that an attacker can (i) cause unresponsiveness and automatic node removal in a distributed filesystem with only 2.4 minutes of sustained acoustic injection, (ii) induce a distributed database’s latency to increase by up to 92.7% to reduce system reliability, and (iii) induce load-balance managers to redirect up to 74% of resources to a target server to cause overload or force resource colocation. Furthermore, we perform open-water experiments in a lake and find that an attacker can cause controlled throughput degradation at the maximum allowable distance of 6.35 m using a commercial speaker. We also investigate and discuss the effectiveness of standard defenses against acoustic injection attacks. Finally, we formulate a novel machine learning-based detection system that reaches 0% False Positive Rate and 98.2% True Positive Rate trained on our dataset of profiled hard disk drives under 30-second FIO benchmark execution. With this work, we aim to help manufacturers proactively protect UDCs against acoustic injection attacks and ensure the security of subsea computing infrastructures.
Jennifer Sheldon, Weidong Zhu 0002, Adnan Abdullah, S. Hrushikesh Bhupathiraju, Takeshi Sugawara 0001, Kevin R. B. Butler, Md Jahidul Islam, Sara Rampazzi
SP2
2023 Deep Note: Can Acoustic Interference Damage the Availability of Hard Disk Storage in Underwater Data Centers?
abstract
The growing worldwide attention toward large-scale subsea data centers has garnered substantial interest from commercial entities which have built and deployed underwater prototypes since 2015. These data centers utilize hard disk drives (HDDs) as a cost-effective method of data storage. However, researchers have demonstrated that acoustic waves can affect the availability and integrity of HDDs and applications that rely on them. These studies are all conducted in air on commercial laptops, hence their applicability and implications in submerged environments remain unexplored. In this position paper, we investigate potential vulnerabilities of storage devices deployed in underwater data centers and subsea storage platforms against targeted acoustic attacks. Based on our initial investigation of a simplified scenario, a victim HDD deployed in an enclosed submerged container is especially vulnerable to those acoustic attacks, which at frequencies ranging from 300 Hz 1300 Hz can result in up to 100% throughput loss and application crashes. Based on these findings, we argue that further study is necessary to assess underwater storage system security and develop effective defenses against overlooked acoustic attacks.
Jennifer Sheldon, Weidong Zhu 0002, Adnan Abdullah, Kevin R. B. Butler, Md Jahidul Islam, Sara Rampazzi
HotStorage2
2023 EaD: ECC-Assisted Deduplication With High Performance and Low Memory Overhead for Ultra-Low Latency Flash Storage
abstract
Data deduplication has become a commodity feature in flash storage products to effectively reduce redundant write data and improve space efficiency. However, it also introduces computing and memory overhead to generate and store the cryptographic hash (fingerprint) in face of the moderate data redundancy in primary storage. With the advent of 3D XPoint and Z-NAND technologies, and the stronger cryptographic hash functions in use, such as SHA-256, both the computing and memory overheads are increasingly serious performance bottlenecks for inline data deduplication in these ultra-low latency flash storage. To address these problems, we propose an ECC-assisted Deduplication approach, called EaD, which exploits the ECC property and the asymmetric read-write performance characteristics of modern flash storage. EaD first identifies data similarity by leveraging the device-generated ECC values of data chunks as their fingerprints, significantly reducing the costly MD5/SHA-based cryptographic hash computing and alleviating the memory space overhead. Based on the identification results, similar data chunks and their ECCs are read from the flash to perform a byte-by-byte comparison in memory to definitively identify and remove redundant data chunks. Our experiments show that the EaD approach significantly increases I/O performance by up to 4.2${\times }$, with an average of 2.5${\times }$, compared with the existing MD5/SHA- and sampling-based deduplication approaches.
Suzhen Wu, Chunfeng Du, Weidong Zhu 0002, Jindong Zhou, Hong Jiang 0001, Bo Mao 0003, Lingfang Zeng
IEEE Trans. Computers3
2022 NASA: NVM-Assisted Secure Deletion for Flash Memory
abstract
Secure deletion in flash-based storage is crucial for data security. However, existing secure deletion schemes for flash memory suffer from performance degradation and reliability issues and cannot provide secure deletion guarantees. Although emerging nonvolatile memory (NVM) allows in-place updates and provides high performance, it is unable to fully replace flash memory and, thus, cannot solve the secure deletion problem. In this article, we propose NVM-assisted secure deletion scheme for flash memory (NASA), a stale-free storage system that combines NVM and flash memory to provide immediate secure deletion without significant performance degradation in SSDs. NASA uses block erasure to provide secure deletion guarantees for flash memory and exploits NVM to conceal time-consuming erasure operations. We demonstrate that unless the unique characteristics of NVM are considered, schemes that merely implement existing approaches to secure deletion will end up with stale data replicas within their storage media. Moreover, we evaluate NASA with different real-world workloads and demonstrate that NASA increases the average latency by 0.01% compared to LRU and decreases 2.1% average latency over the FIFO caching policy. NASA is a novel storage system that provides strong secure deletion guarantees with high performance.
Weidong Zhu 0002, Kevin R. B. Butler
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.1
2020 EaD: a Collision-free and High Performance Deduplication Scheme for Flash Storage Systems
abstract
Inline deduplication is a popular technique to effectively reduce the write traffic and improve the space efficiency for flash-based storage. However, it also introduces computing and memory overhead to generate and store the cryptographic hash (fingerprint). Along the advent of 3D XPoint and Z-NAND technologies with vastly improved latency and bandwidth, both the computing and memory overheads are becoming much more pronounced in deduplication-based flash storage with cryptographic hash functions in use. To address these problems, we propose an ECC (Error Correcting Code) assisted deduplication approach, called EaD, which exploits the ECC property and the asymmetric read-write performance characteristics of modern flash-based storage. EaD first identifies data similarity based on the fingerprints of data chunks represented by their ECC values, thus significantly reducing the costly cryptographic hash computing and alleviating the memory space overhead. Based on the identification results, similar data chunks and their ECCs are read from the flash to perform a byte-by-byte comparison in memory to definitively identify and remove redundant data chunks. Our experiments show that the EaD approach significantly reduces the I/O latency by an average of 1.92× and 1.86×, and reduces the memory consumption by an average of 35.0% and 21.9%, compared with the existing SHA- and sampling-based deduplication approaches, respectively.
Suzhen Wu, Jindong Zhou, Weidong Zhu 0002, Hong Jiang 0001, Zhirong Shen, Bo Mao 0003
ICCD3
2020 GC-Steering: GC-Aware Request Steering and Parallel Reconstruction Optimizations for SSD-Based RAIDs
abstract
Solid-state disk (SSD)-based redundant array of independent disks (RAIDs) have been widely deployed in high-end enterprize systems to provide high-performance and highly reliable storage for data-intensive computing. However, SSD-based RAIDs suffer from significant performance degradation whenever user I/O requests conflict with the ongoing garbage collection (GC) operations which introduce tail latency. Moreover, the performance characteristics of SSDs make the traditional HDD-based RAID reconstruction algorithms are not compatible with or suitable for SSD-based RAIDs. In this article, we proposed GC-aware request steering (GC-Steering), a scheme aware of the GC process within an SSD-based RAID, to significantly boost the performance and reliability of SSD-based RAIDs. GC-Steering effectively outsources the popular read requests and all write requests addressed to the SSD currently in the GC state to a staging space, such as a dedicated spare SSD or the reserved space of each SSD within the RAID. GC-Steering also accelerates the performance of the failure-recovery process by both request steering and parallel recovery. Our extensive evaluations on a lightweight GC-Steering prototype driven by HPC-like and real-world enterprize workloads show that the GC-Steering scheme significantly reduces the average response time by an average of 63.3% and 65.8%, compared with the state-of-the-art local GC and global GC schemes. Moreover, the GC-Steering scheme also significantly reduces the average response times by an average of 62.3% during RAID reconstruction than the normal state.
Suzhen Wu, Weidong Zhu 0002, Yingxin Han, Hong Jiang 0001, Bo Mao 0003
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.2
2018 GC-Aware Request Steering with Improved Performance and Reliability for SSD-Based RAIDs
abstract
SSD-based RAIDs have been widely deployed in high-end enterprise systems to provide high-performance and highly reliable storage for data-intensive computing. However, SSD-based RAIDs suffer from significant performance degradation whenever user I/O requests conflict with the ongoing Garbage Collection (GC) operations which introduces tail latency. Moreover, the performance characteristics of SSDs make the traditional HDD-based RAID reconstruction algorithms are not compatible with or suitable for SSD-based RAIDs. In this paper, we proposed GC-aware Request Steering (short for GC-Steering), a scheme aware of the GC process within an SSD-based RAID, to significantly boost the performance and reliability of SSD-based RAIDs. GC-Steering effectively outsources the popular read requests and all write requests addressed to the SSD currently in the GC state to a staging space such as a dedicated spare SSD or the reserved space of each SSD within the RAID. GC-Steering also accelerates the performance of the failure-recovery process by both request steering and parallel recovery. Our extensive evaluations on a lightweight GC-Steering prototype driven by HPC-like and real-world enterprise workloads show that the GC-Steering scheme significantly reduces the average response time by an average of 63.3% and 65.8%, compared with the state-of-the-art LGC and GGC schemes. Moreover, GC-Steering scheme also significantly reduces the average response times by an average of 55.7% during RAID reconstruction than the normal state.
Suzhen Wu, Weidong Zhu 0002, Guixin Liu, Hong Jiang 0001, Bo Mao 0003
IPDPS2
2018 PP: Popularity-based Proactive Data Recovery for HDFS RAID systems
Suzhen Wu, Weidong Zhu 0002, Bo Mao 0003, Kuanching Li
Future Gener. Comput. Syst.2