EDBT 2026 Demo / reviewers in the wild / expert
Kailun Qin
dblp:368/7276
· DBLP profile ↗
8ranked-venue papers
4as first author
8since 2021 · last 2026
0009-0004-3372-8724ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 6 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Teamwork Makes TEE Work: Open and Resilient Remote Attestation on Decentralized TrustabstractRemote Attestation (RA) enables the integrity and authenticity of applications in Trusted Execution Environment (TEE) to be verified. Existing TEE RA designs employ a centralized trust model where they rely on a single provisioned secret key and a centralized verifier to establish trust for remote parties. This model is however brittle and can be untrusted under advanced attacks nowadays. Besides, most designs only have fixed procedures once deployed, making them hard to adapt to different emerging situations and provide resilient functionalities. Therefore, we proposeJanus, an open and resilient TEE RA scheme. To decentralize trust, we, on one hand, introduce Physically Unclonable Function (PUF) as an intrinsic root of trust (RoT) in TEE to directly provide physical trusted measurements. On the other hand, we design novel decentralized verification functions on smart contract with result audits and RA session snapshot. Furthermore, we design an automated switch mechanism that allowsJanusto remain resilient and offer flexible RA services under various situations. We provide a UC-based security proof and demonstrate the scalability and generality ofJanusby implementing an complete prototype. Kailun Qin, Shipei Qu, Chi Zhang 0061, Dawu Gu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Secure and Scalable TLB Partitioning Against Timing Side-Channel Attacks
Tianyi Huang, Kailun Qin, Boshi Yuan 0002, Chenghao Chen, Yipeng Shi, Chi Zhang 0061, Dawu Gu |
ICICS (3) | 3 |
| 2025 | MVTEE: Multi-Variant Trusted Execution for Secure Model InferenceabstractTrusted Execution Environments (TEEs) have been proposed as a promising approach for secure model inference, providing in-use data protection to ensure confidentiality and integrity against untrusted third parties, with additional attestability. However, TEE-protected secure model inference remains susceptible to numerous software vulnerabilities and fault attacks, potentially undermining the designed protection objectives and giving a false sense of security and reliability. Kailun Qin, Dawu Gu |
Middleware | 1 |
| 2025 | MVMONT: Securing Confidential Deployments With Attestable Multi-Variant MonitoringabstractConfidential deployments, combining Trusted Execution Environments (TEEs) with cloud-native techniques, have become the primary model for protecting sensitive cloud workloads. However, they are not immune to memory vulnerabilities and runtime attacks. In particular, TEEs by design do not consider such threats and their built-in attestation only captures load-time compromises. Furthermore, existing cloud-native security tools, relying on untrusted system software, are inherently in conflict with the TEE threat model and are rendered ineffective due to TEE's memory protection, making the runtime exploit detection for confidential deployments even harder. In this paper, we present MVMONT - an attestable Multi-Variant Monitoring system for TEE-based confidential deployments. MVMONT introduces a new cloud-native abstraction that leverages the inherent redundancy of deployments and the concept of Multi-Variant Execution (MVX) to detect runtime compromises by checking execution divergences across concurrently running variants with a memory-safe out-of-band monitor enclave. To mitigate the overhead and complexity associated with MVX's synchronized execution, we opt for lightweight similarity-based event monitoring with carefully designed tracing and reporting mechanisms. To tightly control the size of the Trusted Computing Base (TCB), we specialize the design of our monitor and debloat its TEE runtime. To enable trust establishment for deployments, MVMONT provides built-in collective runtime attestation through the monitor, incorporating Property-Based Attestation for privacy considerations. We demonstrate the practicality of MVMONT through extensive evaluations on a set of real-world applications. We also show MVMONT's effectiveness in identifying runtime exploits at scale with minimal overhead, while achieving a minimal TCB and small attack surface. Kailun Qin, Dawu Gu |
SRDS | 1 |
| 2025 | Building Provably Secure Pseudo-Strong PUFs via Weak PUFs and Pseudorandom Functions for Cryptographic ProtocolsabstractPhysical Unclonable Functions (PUFs) are widely used in hardware security due to their inherent unclonability and randomness. However, the temporal instability of strong PUFs remains a barrier to their adoption in latest PUF-based cryptographic protocols, as it incurs significant overhead from error correction. In this paper, we propose PS-PUF, a novel architecture that leverages weak PUFs and cryptographically secure pseudorandom functions (PRFs) to construct a pseudo-strong PUF with stable and reproducible outputs. Our design includes a PRF for secure mapping, and a buffer to optimize performance in batch-access scenarios. We formally analyze the threat surface of PS-PUF and provide cryptographic security proofs showing resistance against modeling attacks. Implemented on the Genesys 2 FPGA, PS-PUF achieves at least 2.72× in batch scenarios with negligible hardware overhead and a maximum performance reduction of 10.7%, enabled by reusing the PRF module in integrated environments. Chenghao Chen, Kailun Qin, Yipeng Shi, Tianyi Huang, Chi Zhang 0061, Dawu Gu |
TrustCom | 3 |
| 2024 | One System Call Hook to Rule All TEE OSes in the CloudabstractConfidential computing has revolutionized the way of in-use data protection in the Cloud, using the concept of Trusted Execution Environments (TEEs). Emerging from this paradigm are TEE OSes. They are extensively deployed in production settings, providing isolation protection and allowing legacy code to execute with minimal changes. However, they encounter challenges in cloud environments, particularly in creating compatibility layers, ensuring runtime protection, and efficiently managing TEE boundary transitions. In response, our work proposes to extend TEE OSes through a unified approach centered on system call (syscall) rewriting and interposition. We present xpoline++ - a stepwise (++) binary rewriting strategy executed on-the-fly with its trampoline set up at a manageable address (x), This allows for efficient construction of a compatibility layer at the binary syscall level and seamless transition to custom hook functions. Further, we introduce two syscall interposition extensions, namely xfilter and xswitchless, which respectively reduce the attack surface and improve the efficiency of TEE boundary switching to better serve the needs of cloud applications. Evaluations on a set of real-world workloads confirmed their effectiveness. Kailun Qin, Dawu Gu |
CLOUD | 1 |
| 2024 | Gramine-TDX: A Lightweight OS Kernel for Confidential VMsabstractWhile Confidential Virtual Machines (CVMs) have emerged as a prominent way for hardware-assisted confidential computing, their primary usage is not suitable for small, specialized, security-critical workloads, i.e., legacy VMs with their conventional OS distributions result in a large trusted computing base. Dmitrii Kuvaiskii, Dimitrios Stavrakakis, Kailun Qin, Cedric Xing, Pramod Bhatotia, Mona Vij |
CCS | 3 |
| 2024 | To Share or Hide: Confidential Model Compilation as a Service with Privacy-Preserving TransparencyabstractModel Compilation as a Service (MCaaS) has emerged as critical Machine Learning (ML) supply chain infrastructure. It provides large-scale model optimization for heteroge-neous hardware devices in an easy-to-use, cost-efficient and fault-tolerant manner. However, a variety of attacks targeting the ML model supply chain have been reported. Further compounded by the complexity of the cloud environments where MCaaS operates, increasing security concerns have been raised about the generated model binaries. In response, we present Themis - confidential MCaaS with privacy-preserving transparency. To help build trust in model binaries, we increase supply chain transparency by introducing property-based integrity that captures complex property evidence throughout the compilation pipeline. Meanwhile, we underscore privacy preservation through the concept of a model property tree, which represents the provenance and integrity of a model binary. It allows constrained sharing and efficient verification of binary properties. In Themis, we enforce confidentiality to all generated binaries by default, but with fine-grained control through the use of hybrid selective encryption based on attribute-based encryption. Themis is further secured within distributed Trusted Execution Environments to ensure confidential and reliable execution. We build Themis on top of a state-of-the-art ML compiler, with our evaluations demonstrating its practicality. Kailun Qin, Dawu Gu |
SRDS | 1 |