EDBT 2026 Demo / reviewers in the wild / expert
Zhe Zhou 0001
dblp:34/6503-1
· DBLP profile ↗
23ranked-venue papers
6as first author
8since 2021 · last 2026
0000-0003-4879-6258ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 5 first-author · 6 since 2021Systems, architecture and hardware · 3 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Binary Compatible Critical Section DelegationabstractIn high-performance applications, critical sections often become performance bottlenecks due to contention among multiple cores. Critical section delegation mitigates this overhead by consistently executing critical sections on the same core, thereby reducing contention. Traditional delegation techniques, however, typically require manual code refactoring, which limits their practicality and adoption. More recent schemes that integrate with existing lock APIs have lowered this barrier, but delegating unsupported critical sections can still cause undefined behavior, including crashes. Junyao Zhang 0008, Zhe Zhou 0001 |
PPoPP | 3 |
| 2023 | On Adversarial Robustness of Point Cloud Semantic SegmentationabstractRecent research efforts on 3D point cloud semantic segmentation (PCSS) have achieved outstanding performance by adopting neural networks. However, the robustness of these complex models have not been systematically analyzed. Given that PCSS has been applied in many safety-critical applications like autonomous driving, it is important to fill this knowledge gap, especially, how these models are affected under adversarial samples. As such, we present a comparative study of PCSS robustness. First, we formally define the attacker's objective under performance degradation and object hiding. Then, we develop new attack by whether to bound the norm. We evaluate different attack options on two datasets and three PCSS models. We found all the models are vulnerable and attacking point color is more effective. With this study, we call the attention of the research community to develop new approaches to harden PCSS models. Jiacen Xu 0001, Zhe Zhou 0001, Boyuan Feng, Yufei Ding 0001, Zhou Li 0001 |
DSN | 2 |
| 2023 | Userspace Bypass: Accelerating Syscall-intensive Applications
Zhe Zhou 0001, Yanxiang Bi, Junpeng Wan, Zhou Li 0001 |
OSDI | 1 |
| 2022 | Play the Imitation Game: Model Extraction Attack against Autonomous Driving LocalizationabstractThe security of the Autonomous Driving (AD) system has been gaining researchers’ and public’s attention recently. Given that AD companies have invested a huge amount of resources in developing their AD models, e.g., localization models, these models, especially their parameters, are important intellectual property and deserve strong protection. Qifan Zhang 0002, Junjie Shen 0001, Mingtian Tan, Zhe Zhou 0001, Zhou Li 0001, Qi Alfred Chen, Haipeng Zhang 0004 |
ACSAC | 4 |
| 2022 | MeshUp: Stateless Cache Side-channel Attack on CPU MeshabstractCache side-channel attacks lead to severe security threats to the settings where a CPU is shared across users, e.g., in the cloud. The majority of attacks rely on sensing the micro-architectural state changes made by victims, but this assumption can be invalidated by combining spatial (e.g., Intel CAT) and temporal isolation. In this work, we advance the state of cache side-channel attacks by showing stateless cache side-channel attacks on server-grade CPUs, that can bypass both spatial and temporal isolation. Unlike stateful cache side-channel attacks that rely on the timing difference between a cache hit or miss, our attack exploits the timing difference caused by the interconnect congestion. Specifically, to complete cache transactions, for Intel server CPUs, which use non-inclusive and mesh interconnect, cache lines would travel across cores via the CPU mesh and UPI interconnects. Nonetheless, the interconnects are shared by all cores, and cache isolation does not segregate the traffic. An attacker can generate traffic to contend with a victim on a link, measure the extra delay, deduce the memory access pattern of the victim’s program, and infer its sensitive data. Based on this idea, we implement MESHUP, a stateless cache side-channel against mesh interconnect, and test it against the existing RSA implementations of JDK for the cross-core attack and application fingerprinting for the the cross-CPU attack. We found the RSA private key used by a victim process can be partially recovered and the co-running application can be inferred at high accuracy. Junpeng Wan, Yanxiang Bi, Zhe Zhou 0001, Zhou Li 0001 |
SP | 3 |
| 2021 | The Many-faced God: Attacking Face Verification System with Embedding and Image RecoveryabstractFace verification system (FVS), which can automatically verify a person’s identity, has been increasingly deployed in the real-world settings. Key to its success is the inclusion of face embedding, a technique that can detect similar photos of the same person by deep neural networks. Mingtian Tan, Zhe Zhou 0001, Zhou Li 0001 |
ACSAC | 2 |
| 2021 | Invisible Probe: Timing Attacks with PCIe Congestion Side-channelabstractPCIe (Peripheral Component Interconnect express) protocol is the de facto protocol to bridge CPU and peripheral devices like GPU, NIC, and SSD drive. There is an increasing demand to install more peripheral devices on a single machine, but the PCIe interfaces offered by Intel CPUs are fixed. To resolve such contention, PCIe switch, PCH (Platform Controller Hub), or virtualization cards are installed on the machine to allow multiple devices to share a PCIe interface. Congestion happens when the collective PCIe traffic from the devices overwhelm the PCIe link capacity, and transmission delay is then introduced.In this work, we found the PCIe delay not only harms device performance but also leaks sensitive information about a user who uses the machine. In particular, as user’s activities might trigger data movement over PCIe (e.g., between CPU and GPU), by measuring PCIe congestion, an adversary accessing another device can infer the victim’s secret indirectly. Therefore, the delay resulted from I/O congestion can be exploited as a side-channel. We demonstrate the threat from PCIe congestion through 2 attack scenarios and 4 victim settings. Specifically, an attacker can learn the workload of a GPU in a remote server by probing a RDMA NIC that shares the same PCIe switch and measuring the delays. Based on the measurement, the attacker is able to know the keystroke timings of the victim, what webpage is rendered on the GPU, and what machine-learning model is running on the GPU. Besides, when the victim is using a low-speed device, e.g., an Ethernet NIC, an attacker controlling an NVMe SSD can launch a similar attack when they share a PCH or virtualization card. The evaluation result shows our attack can achieve high accuracy (e.g., 96.31% accuracy in inferring webpage visited by a victim). Mingtian Tan, Junpeng Wan, Zhe Zhou 0001, Zhou Li 0001 |
SP | 3 |
| 2021 | A Smart Framework for Fine-Grained Microphone Acoustic Permission ManagementabstractMicrophones attracted a lot of attentions from attackers due to the sensitivity of voice data: attackers may control devices through abusing their microphones, fingerprint devices by measuring their microphones, or directly monitor the microphone readings to steal users’ private data. Nevertheless, OS developers failed to address the severe consequences. While the current security mechanism only offers a coarse-grained access control over the usage of microphones: recording all sound or shutting off, it is necessary to redesign the microphone security mechanism to enforce fine-grained restrictions over the usage of microphones. In this article, we propose a fine-grained microphone access control scheme on Android platform, referred to asFMC(Finer Microphone Controller). In our scheme, microphone acoustic permissions are granted with three finer policies:treble policy,timbre policyandexclusion policy, with which most of the attacks mentioned above can be defended against. In addition, to ease user’s policy management, we employ a smart policy recommendation method, avoiding additional manual policy approvals. The results in our experiments show that a negligible 1.06 percent performance overhead is incurred during policy enforcement. Besides, the policy recommendation system inFMCpromises an accuracy of 82.82 percent averagely. We believe that our work is a practical defense scheme against attacks exploiting microphone acoustic permissions and should be employed by OS developers. Weili Han, Zhe Zhou 0001, Shize Chen, Lingqi Huang, Xiaoyang Sean Wang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2020 | Leaky DNN: Stealing Deep-Learning Model Secret with GPU Context-Switching Side-ChannelabstractMachine learning has been attracting strong interests in recent years. Numerous companies have invested great efforts and resources to develop customized deep-learning models, which are their key intellectual properties. In this work, we investigate to what extent the secret of deep-learning models can be inferred by attackers. In particular, we focus on the scenario that a model developer and an adversary share the same GPU when training a Deep Neural Network (DNN) model. We exploit the GPU side-channel based on context-switching penalties. This side-channel allows us to extract the fine-grained structural secret of a DNN model, including its layer composition and hyper-parameters. Leveraging this side-channel, we developed an attack prototype named MosConS, which applies LSTM-based inference models to identify the structural secret. Our evaluation of MosConS shows the structural information can be accurately recovered. Therefore, we believe new defense mechanisms should be developed to protect training against the GPU side-channel. Yicheng Zhang 0004, Zhe Zhou 0001, Zhou Li 0001, Mohammad Abdullah Al Faruque |
DSN | 3 |
| 2019 | RoLMA: A Practical Adversarial Attack Against Deep Learning-Based LPR Systems
Mingming Zha 0001, Guozhu Meng, Chaoyang Lin, Zhe Zhou 0001, Kai Chen 0012 |
Inscrypt | 4 |
| 2018 | Beware of Your Screen: Anonymous Fingerprinting of Device Screens for Off-line Payment ProtectionabstractQR-code mobile payment becomes increasingly popular, being offered by major banks (e.g., ICBC) and payment service providers (e.g., PayPal). Unlike mobile payment solutions provided by hardware vendors (e.g., Apple Pay and Samsung Pay), QR code payment schemes do not rely on any hardware support and can therefore be easily deployed. However, the security guarantee of the new scheme is less clear: in the absence of hardware protection, users' digital wallet can be vulnerable to an OS-level adversary, who could steal her secret for generating payment tokens. Zhe Zhou 0001, Di Tang 0001, Wenhao Wang 0001, XiaoFeng Wang 0001, Zhou Li 0001, Kehuan Zhang |
ACSAC | 1 |
| 2018 | Face Flashing: a Secure Liveness Detection Protocol based on Light Reflections
Di Tang 0001, Zhe Zhou 0001, Yinqian Zhang, Kehuan Zhang |
NDSS | 2 |
| 2018 | A survey of practical adversarial example attacksabstractAdversarial examples revealed the weakness of machine learning techniques in terms of robustness, which moreover inspired adversaries to make use of the weakness to attack systems employing machine learning. Existing researches covered the methodologies of adversarial example generation, the root reason of the existence of adversarial examples, and some defense schemes. However practical attack against real world systems did not appear until recent, mainly because of the difficulty in injecting a artificially generated example into the model behind the hosting system without breaking the integrity. Recent case study works against face recognition systems and road sign recognition systems finally abridged the gap between theoretical adversarial example generation methodologies and practical attack schemes against real systems. To guide future research in defending adversarial examples in the real world, we formalize the threat model for practical attacks with adversarial examples, and also analyze the restrictions and key procedures for launching real world adversarial example attacks. Mingtian Tan, Zhe Zhou 0001 |
Cybersecur. | 3 |
| 2018 | Accessing mobile user's privacy based on IME personalization: Understanding and practical attacksabstractInput Method Editor (IME) is an indispensable component on current smartphones. With its assistance, the number of key presses is reduced, and non-Latin characters could be inputted. Furthermore, modern IMEs integrate several personalized features like reordering suggestion lists and predicting the next words based on user’s input history. Such optimization improves the user experience but turns the IME dictionary into a pool of user privacy. Previous works have discussed the privacy risks coming from malicious IMEs. Indeed, they could cause security and privacy issues if installed by common users, but their impact is limited as the majority of IMEs are well-behaved. However, whether legitimate IMEs are bullet-proof is not answered before. In this paper, we make the first attempt to study the security implications of IME personalization and the back-end infrastructure on Android devices. In the end, we identify a critical vulnerability lying under the Android KeyEvent processing framework, which can be exploited to launch cross-app KeyEvent injection (CAKI) attack and bypass the app-isolation mechanism. By abusing such design flaw, an adversary can harvest entries from the personalized user dictionary of IME through an ostensibly innocuous app only asking for common permissions. Our evaluation over a broad spectrum of Android OSes, devices, and IMEs suggests such issue should be fixed immediately. All Android versions we examined (from very old 2.3.4 to the latest 6.0.1) and most IME apps we surveyed (11 out of 18) are vulnerable. User’s private information, like contact names, location, etc., can be easily exfiltrated. Up to hundreds of millions of mobile users are under this threat. To mitigate this security issue, we propose a practical defense mechanism which augments the existing KeyEvent processing framework without forcing any change to IME apps. Wenrui Diao, Rui Liu 0002, Zhe Zhou 0001, Zhou Li 0001, Kehuan Zhang |
J. Comput. Secur. | 4 |
| 2017 | All Your VMs are Disconnected: Attacking Hardware Virtualized NetworkabstractSingle Root I/O Virtualization (SRIOV) allows one physical device to be used by multiple virtual machines simultaneously without the mediation from the hypervisor. Such technique significantly decreases the overhead of I/O virtualization. But according to our latest findings, in the meantime, it introduces a high-risk security issue that enables an adversary-controlled VM to cut off the connectivity of the host machine, given the limited filtering capabilities provided by the SRIOV devices. Zhe Zhou 0001, Zhou Li 0001, Kehuan Zhang |
CODASPY | 1 |
| 2017 | Picking Up My Tab: Understanding and Mitigating Synchronized Token Lifting and Spending in Mobile Payment
Xiaolong Bai, Zhe Zhou 0001, XiaoFeng Wang 0001, Zhou Li 0001, Xianghang Mi, Nan Zhang 0018, Tongxin Li 0002, Shi-Min Hu 0001, Kehuan Zhang |
USENIX Security Symposium | 2 |
| 2017 | Vulnerable GPU Memory Management: Towards Recovering Raw Data from GPUabstractAbstract According to previous reports, information could be leaked from GPU memory; however, the security implications of such a threat were mostly over-looked, because only limited information could be indirectly extracted through side-channel attacks. In this paper, we propose a novel algorithm for recovering raw data directly from the GPU memory residues of many popular applications such as Google Chrome and Adobe PDF reader. Our algorithm enables harvesting highly sensitive information including credit card numbers and email contents from GPU memory residues. Evaluation results also indicate that nearly all GPU-accelerated applications are vulnerable to such attacks, and adversaries can launch attacks without requiring any special privileges both on traditional multi-user operating systems, and emerging cloud computing scenarios. Zhe Zhou 0001, Wenrui Diao, Zhou Li 0001, Kehuan Zhang, Rui Liu 0002 |
Proc. Priv. Enhancing Technol. | 1 |
| 2016 | On Code Execution Tracking via Power Side-ChannelabstractWith the proliferation of Internet of Things, there is a growing interest in embedded system attacks, e.g., key extraction attacks and firmware modification attacks. Code execution tracking, as the first step to locate vulnerable instruction pieces for key extraction attacks and to conduct control-flow integrity checking against firmware modification attacks, is therefore of great value. Because embedded systems, especially legacy embedded systems, have limited resources and may not support software or hardware update, it is important to design low-cost code execution tracking methods that require as little system modification as possible. In this work, we propose a non-intrusive code execution tracking solution via power-side channel, wherein we represent the code execution and its power consumption with a revised hidden Markov model and recover the most likely executed instruction sequence with a revised Viterbi algorithm. By observing the power consumption of the microcontroller unit during execution, we are able to recover the program execution flow with a high accuracy and detect abnormal code execution behavior even when only a single instruction is modified. Yannan Liu, Lingxiao Wei, Zhe Zhou 0001, Kehuan Zhang, Wenyuan Xu 0001, Qiang Xu 0001 |
CCS | 3 |
| 2016 | Efficient Authenticated Multi-Pattern MatchingabstractMulti-pattern matching compares a large set of patterns against a given query string, which has wide application in various domains such as bio-informatics and intrusion detection. This paper shows how to authenticate the classic Aho-Corasick multi-pattern matching automation, without requiring the verifier to store the whole pattern set, nor downloading a proof for every single matching step. The storage complexity for the authentication metadata at the server side is the same as that of the unauthenticated version. The communication overhead is minimal since the proof size is linear in the query length and does not grow with the sizes of query result nor the pattern set. Our evaluation has shown that the query and verification times are practical. Zhe Zhou 0001, Tao Zhang 0014, Sherman S. M. Chow, Yupeng Zhang 0001, Kehuan Zhang |
AsiaCCS | 1 |
| 2015 | When Good Becomes Evil: Keystroke Inference with SmartwatchabstractOne rising trend in today's consumer electronics is the wearable devices, e.g., smartwatches. With tens of millions of smartwatches shipped, however, the security implications of such devices are not fully understood. Although previous studies have pointed out some privacy concerns about the data that can be collected, like personalized health information, the threat is considered low as the leaked data is not highly sensitive and there is no real attack implemented. In this paper we investigate a security problem coming from sensors in smartwatches, especially the accelerometer. The results show that the actual threat is much beyond people's awareness. Being worn on the wrist, the accelerometer built within a smartwatch can track user's hand movements, which makes inferring user inputs on keyboards possible in theory. But several challenges need to be addressed ahead in the real-world settings: e.g., small and irregular hand movements occur persistently during typing, which degrades the tracking accuracy and sometimes even overwhelms useful signals. Zhe Zhou 0001, Wenrui Diao, Zhou Li 0001, Kehuan Zhang |
CCS | 2 |
| 2015 | Mind-Reading: Privacy Attacks Exploiting Cross-App KeyEvent Injections
Wenrui Diao, Zhe Zhou 0001, Kehuan Zhang, Zhou Li 0001 |
ESORICS (2) | 3 |
| 2015 | An Empirical Study on Android for Saving Non-shared Data on Public Storage
Zhe Zhou 0001, Wenrui Diao, Zhou Li 0001, Kehuan Zhang |
SEC | 2 |
| 2014 | Acoustic Fingerprinting Revisited: Generate Stable Device ID Stealthily with Inaudible SoundabstractThe popularity of mobile devices has made people's lives more convenient, but threatened people's privacy at the same time. As end users are becoming more and more concerned on the protection of their private information, it is even harder for hackers to track a specific user by using conventional technologies. For example, cookies might be cleared by users regularly. Besides, OS designers have developed a series of measures to cope with tracker. Apple has stopped apps accessing UDIDs, and Android phones use some special permissions to protect IMEI code. However, some recent studies showed that attackers are able to find new ways to get around those limitations, even though these new methods should be improved in order to be practically deployed in large scale. For example, attackers can trace smart phones by using the hardware features resulting from the imperfect manufacturing process of accelerometers. In this paper, we will present another new and more practical method for the adversaries to generate stable and unique device ID stealthily for the smartphone by exploiting the frequency response of the speaker. With carefully selected audio frequencies and special sound wave patterns, we can reduce the impact of non-linear effects and noises, and keep our feature extraction process un-noticeable to phone owners. The extracted feature is not only very stable for a given smart phone, but also unique to that phone. The feature contains rich information, which is even enough to differentiate millions of smart phones of the same model. We have built a prototype to evaluate our method, and the results show that the generated device ID can be used to track users practically. Zhe Zhou 0001, Wenrui Diao, Kehuan Zhang |
CCS | 1 |