Sirong Zhao

dblp:371/0599 · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
7since 2021 · last 2026
0000-0003-3363-4192ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 6 · 2 first-author · 6 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 TrustSpace: Trusted memory space against control hijacking attacks
Chenglai Xiong, Guoqi Xie, Xinxin Jiang, Shufeng Chen, Sirong Zhao, Xuejun Yu 0001
J. Syst. Archit.5
2026 Weighted Community Division for Automated Software Architecture Refactoring
abstract
Adopting Model-Based Development (MBD) in automotive software becomes necessary because it provides a rigorous development process. As the increase in the number of software components (SWCs) and their interactions, modifications to one part of the software might impact other parts due to the high coupling of SWCs. Developing an automated software refactoring technique to implement high cohesion and low coupling of software is necessary. Software refactoring usually contains code refactoring and architecture refactoring. Code refactoring only modifies the code inside the SWCs without changing its original functionality and external behavior, whereas current architecture refactoring does not consider the interaction weight (strength) between SWCs.In this study, we propose a weighted community division algorithm called Weighted-Girvan-Newman (W-GN) for software architecture refactoring. W-GN algorithm refactors the architecture by dividing SWCs into modules based on the interaction weights of SWCs. We further develop an automated architecture refactoring tool called AutoToolMD. This tool assists engineers in improving development efficiency and ensures the architecture aligns with the requirements of high cohesion and low coupling. Evaluations show that W-GN indicates more suitable modularity values than the traditional Girvan-Newman (GN) algorithm because the former can better reflect the real architecture with interaction weights. We apply AutoToolMD to automatically refactor architecture in automotive industry practice. Case study with the Zone_B PwrSplyMngt and Zone L_Lock modules in the Honda zone control software shows that AutoToolMD effectively refactors architecture with a significant improvement in testing efficiency and readability.
Sirong Zhao, Jialing Yang, Jiao Xie, Kaiwei Fan, Jianmei Lei, Guoqi Xie
IEEE Trans. Software Eng.1
2025 TMI: Two-dimensional maintainability index for automotive software maintainability measurement
Jiao Xie, Jialing Yang, Sirong Zhao, Jianmei Lei, Kaiwei Fan, Guoqi Xie
J. Syst. Archit.3
2025 Hypercall-Oriented Abnormal VM Status Detection System: A Non-Intrusive Solution for Both Hypervisor and Guests
abstract
Hypervisor is a VMM (Virtual Machine Monitor) that creates and runs multiple VMs (Virtual Machines) through abstracting resources from a physical machine. Hypercall is a special and crucial call used in virtualized systems as it serves as a main communication channel between VMs and the hypervisor. However, hypercall attacks occur when an attacker manipulates the communication channel, and it could cause abnormal VM status, potentially leading to the abnormal resource allocation of the host OS (Operating System) and crash of VMs. Therefore, the virtualized system should execute abnormal VM status detection to identify potential abnormal behaviors to protect VMs and the host OS; however, existing works are either for reconstructing the hypervisor or hardware isolation, not for the VM status detection for abnormal hypercall.This study develops a hypercall-oriented abnormal VM status detection system called HypercallDetector based on the following three innovations: 1) we implement a hypercall tracing based on eBPF to obtain the hypercall-related running status (including CPU usage, memory usage, network traffic, etc.) of each VM; 2) we implement a window division technology to divide the VM status into multiple status windows of the same size, and appropriate window size with balanced detection precision (95.0%) and latency (within 8.8 ms) obtained by proposing the window regulator; and 3) we implement a CS-H algorithm (Compressing Sensing for Hypercall) to distinguish whether the VM status is abnormal. HypercallDetector shows higher precision and lower latency than its opponent and consumes only 8.6% CPU of single core and 0.3% memory usage when starting 240 VMs.
Fangqi Bi, Guoqi Xie, Zhenli He, Shaowen Yao 0001, Sirong Zhao, Chenglai Xiong, Bo Wan 0008, Yiwen Jiang
IEEE Trans. Computers7
2025 AVL Function Table for LeafHooks Insertion With Obfuscated Control Flow Integrity
abstract
Control flow is the execution order of individual statements, instructions, or function calls within an imperative program. Malicious operation of control flow (e.g., tampering with normal function addresses) leads to severe consequences such as data leakage and system crash. Control Flow Integrity (CFI) is a defense restricting the execution order of program within Control Flow Graph (CFG). IndexHooks is an existing CFI solution designed against forward function calls tampering (including direct and indirect jump). This solution constructs a read-only linear function table that stores function addresses during compilation. Then, IndexHooks checks the table to make program jump to the correct target address during runtime. However, IndexHooks faces limitations in backtracking CFG construction, which can lead to excessive memory usage; the linear structure of the function table is vulnerable to brute force tampering. Addressing the limitations of IndexHooks, this study develops an obfuscated CFI solution called LeafHooks. LeafHooks is implemented during compilation by the LLVM compiler, which performs static analysis and instrumentation on the LLVM Intermediate Representation (IR) code of a program. We make the following three innovations: 1) we propose a speculation-free identification method for indirect function calls by linear traversing and analyzing codes to obtain legal function information (function address); 2) we save this information into a function table in the form of a Balanced Binary Tree (also known as AVL), enhancing the fuzzification of function addresses to defend against brute force; 3) we design a method to simulate control tamper attacks on ARM64 architecture to verify the ability of LeafHooks to protection. LeafHooks shows less overhead than state-of-the-art solutions and reduces 2.9% and 0.55% overhead on average using UnixBench and Phoronix, respectively.
Sirong Zhao, Guoqi Xie, Chenglai Xiong, Kenli Li 0001, Xuejun Yu 0001, Bo Wan 0008, Yiwen Jiang
IEEE Trans. Computers1
2025 Zram Instance Pool Framework for Adaptive Memory Compression in Resource-Sensitive Embedded Operating Systems
abstract
Memory compression can reduce the size of the inactive data in the random access memory (RAM), thereby freeing up unused space and allowing more programs to run; however, current mainstream memory compression frameworks (e.g., Zram and Zswap) and algorithms (e.g., Zstd and Lz4) do not effectively solve the problem of increased CPU utilization, causing they cannot be directly applied to the resource-sensitive embedded operating system, that is, sensitive to both CPU utilization and memory usage. In this study, we develop a Zram instance pool framework called ZramPool for adaptive memory compression. The framework consists of the swap space with multiple Zram instances and the adaptive Zram compression module. Through introducing linear regression analysis, the number of Zram instances can be adaptively adjusted based on the size of the compressed data, allowing Zram instances to work in parallel to match the workload. In ZramPool, we achieve two different requirements of reducing CPU utilization while keeping compression speed and increasing compression speed while keeping CPU utilization. ZramPool is deployed in the embedded Linux OS with a 8GB memory size running on the ARMv8 architecture. For the first requirement, ZramPool can reduce CPU utilization by an average of 11.42% while the compression speed only decreases by an average of 2.4%. For the second requirement, ZramPool can increase compression speed by an average of 11.71% while the CPU utilization only increases by an average of 1.9%.
Yin Deng, Guoqi Xie, Chenglai Xiong, Sirong Zhao, Wei Ren 0002, Kenli Li 0001
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.4
2025 vmPTP: Precise Time Protocol for Inter-VM Communication in Embedded Virtualized Systems
abstract
System virtualization techniques are gradually applied to embedded systems with the performance improvement of embedded devices; however, there is a large time offset (i.e., deviation) of hundreds of ms between virtual machines (VMs) due to the drift of the virtualization abstraction layer and the jitter phenomenon. It is urgent to significantly reduce this offset by time synchronization techniques. Unfortunately, the current mainstream time synchronization software (e.g., Chrony and LinuxPTP) cannot be used in the embedded virtualized system connected by the fieldbus, such as controller area network (CAN); meanwhile, drift correction-based time synchronization techniques dedicated to CAN bus cannot be utilized for virtualized systems. In this study, we design a general vmPTP, which is a precise time protocol (PTP) for inter-VM communication in embedded virtualized systems based on Linux kernel-based VM (KVM). This is the first time synchronization work focused on embedded virtualized systems. We implement two vmPTP versions based on VirtIO and inter-VM shared memory (IVSHMEM) according to the four message (i.e., packet) exchanges of PTP. We propose an asymmetry compensation strategy to solve the problem of asymmetric rate of I/O operations in the message exchange process, which optimizes the offset computation. We further produce a convergence stopping approach which can continuously converge the offset until the offset is within the given bound and stop. We conduct experimental evaluations on both X86-64 and ARM64 architectures. For two versions of vmPTP, the experimental results show that: 1) the offsets are always within$1~{\mu }$s on two architectures; 2) the offsets are less than that of LinuxPTP and Chrony; and 3) the vmPTP’s CPU and memory utilization on the X86-64 architecture are merely 0.3% and 0.1%, respectively, whereas those on the ARM64 architecture are 3.8% and 0.1%, respectively. We experiment with vmPTP in real-time application and the result demonstrates that vmPTP is feasible and reliable in the real platform.
Sirong Zhao, Guoqi Xie, Wenhong Ma, Wei Ren 0002, Kenli Li 0001
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.1