Tingting Yin

dblp:40/4177 · DBLP profile ↗
← Back
16ranked-venue papers
3as first author
15since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 2 first-author · 7 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021
YearPublicationVenuePosition
2025 Chekhov's Gun: Uncovering Hidden Risks in macOS Application-Sandboxed PID-Domain Services
abstract
macOS delegates many high-privilege operations to dedicated PID-domain services, which applications can register and communicate with through inter-process communication (IPC). This architecture improves userland stability and security but also introduces attractive attack surfaces for adversaries. In this paper, we systematically analyze PID-domain services and uncover an overlooked attack vector: PID-domain services that are restricted to an Application Sandbox identical to the calling application can still be exploited due to subtle entitlement differences.
Minghao Lin, Jiaxun Zhu, Tingting Yin, Zechao Cai, Guanxing Wen, Yanan Guo 0002, Mengyuan Li 0004
CCS3
2025 Truman: Constructing Device Behavior Models from OS Drivers to Fuzz Virtual Devices
Zheyu Ma, Qiang Liu 0034, Zheming Li, Tingting Yin, Wende Tan, Chao Zhang 0008, Mathias Payer
NDSS4
2025 Resilient Event-Triggered Formation Control and Secure Estimation of Multi-UAV Systems
abstract
This article studies the event-triggered formation control of multiple unmanned aerial vehicles (UAVs) in the presence of deception attacks. Unlike existing research focusing on deception attacks, the secure upper bound of deception attacks that the formation tracking of UAVs can tolerate is estimated to reduce the conservatism associated with the predefined upper bound of deception attacks. A dynamic event-triggered mechanism is developed by considering triggering and tracking errors to reduce data release rates while maintaining desired formation tracking performance. Leveraging information from neighboring UAVs, tracking control strategies for the multi-UAV system facing deception attacks are designed using the Lyapunov stability theory. Simulation analysis validates the effectiveness of the proposed strategies, demonstrating improved resilience in the presence of deception attacks.
Zhou Gu, Tingting Yin, Ju H. Park 0001
IEEE Trans. Ind. Informatics2
2025 A Novel Event-Triggered Load Frequency Control for Power Systems With Electric Vehicle Integration
abstract
This article proposes a novel even-triggered mechanism (ETM) to improve load frequency control (LFC) in power systems with electric vehicle (EV) integration, particularly when faced with bandwidth-constrained network communication. To mitigate the transmission of redundant packets that are typically found in conventional ETMs, a variable probabilistic release (VPR) scheme is introduced. The foundation of this VPR-based ETM rests on two crucial steps: 1) Construction of an Event Generator With Variable Probability: This generator facilitates the selection of actual released packets (ARPs) by using the VPR scheme from a group of triggered packets. Leveraging an algorithm, the probability of transmitting each triggered packet in the subsequent group is recomputed, enabling a more adaptive response to system dynamics. 2) Setting a Buffer With Delay Effect: A buffer is utilized to delay the release of ARPs until the final triggered instant in a group. The design not only simplifies timing division but also enhances system stability within fixed time intervals. Furthermore, this work formulates sufficient conditions that ensure the mean-square asymptotic stability (MSAS) of power systems. An illustrative example is presented to confirm the superiority of the proposed VPR-based ETM through comparative analysis with traditional ETMs.
Zhou Gu, Yujian Fan, Tingting Yin, Shen Yan 0003
IEEE Trans. Syst. Man Cybern. Syst.3
2024 CrossFire: Fuzzing macOS Cross-XPU Memory on Apple Silicon
abstract
Modern computing systems increasingly utilize XPUs, such as GPUs and NPUs, for specialized computation tasks.While these XPUs provide critical functionalities, their security protections are generally weaker than those of CPUs, making them attractive attack targets.In particular, Apple silicon optimizes memory usage by adopting a unified memory architecture (UMA), which employs shared memory regions (termed cross-XPU memory) to facilitate communication between CPUs and XPUs.Although the cross-XPU memory enhances performance, it also introduces a new attack surface.Unfortunately, the difficulty in identifying effective shared memory regions and generating valid payloads makes fuzzing cross-XPU memory a challenging problem that cannot be resolved effectively by existing fuzzing techniques.Therefore, we propose CrossFire, the first fuzzer targeting Apple silicon XPU by fuzzing cross-XPU memory, to evaluate this new attack surface.Initially, we conduct an in-depth cross-XPU memory analysis to investigate the challenges of fuzzing XPU.To address these challenges, CrossFire introduces two novel techniques to pinpoint effective fuzzing regions in cross-XPU memory and trace kernel execution information to extract data constraints.Leveraging these techniques, we develop CrossFire based on the m1n1 hypervisor to monitor cross-XPU memory accesses and perform grey-box hooking-based fuzzing.We further evaluate CrossFire on macOS Ventura, where it has identified 15 new zero-day bugs, 8 of which have been confirmed by Apple.
Jiaxun Zhu, Minghao Lin, Tingting Yin, Zechao Cai, Yu Wang 0229, Wenbo Shen
CCS3
2024 KextFuzz: A Practical Fuzzer for macOS Kernel EXTensions on Apple Silicon
abstract
macOS drivers, i.e., Kernel EXTensions (kexts), are attractive attack targets for adversaries. However, automatically discovering vulnerabilities in kexts is extremely challenging because kexts are mostly closed-source, and the latest macOS running on customized Apple Silicon has limited tool-chain support. Most existing static analysis and dynamic testing solutions cannot be applied to the latest macOS. In this paper, we present the first end-to-end fuzzing solution KextFuzz to detect bugs in the latest macOS kexts running on Apple Silicon. Unlike existing driver fuzzing solutions, KextFuzz does not require source code, execution traces, hypervisors, or hardware features (e.g., coverage tracing) and thus is universal and practical. We note that macOS has deployed many mitigations, including pointer authentication, code signature, and userspace kernel layer wrappers, to thwart potential attacks. These mitigations can provide extra knowledge and resources for us to enable kernel fuzzing. KextFuzz exploits these mitigation schemes to instrument the binary for coverage tracking, infer the type and semantic information of kext interfaces, and generate multi-dimension inputs. KextFuzz has found 49 unique kernel bugs in the macOS kexts and got five CVEs. Some bugs could cause severe consequences like running arbitrary code with kernel privilege.
Tingting Yin, Zicong Gao, Zhenghang Xiao, Zheyu Ma, Chao Zhang 0008
IEEE Trans. Dependable Secur. Comput.1
2024 Event-Based Intermittent Formation Control of Multi-UAV Systems Under Deception Attacks
abstract
This article investigates the problem of event-based intermittent formation control for multi-UAV systems subject to deception attacks. Compared to the available research studies on multi-UAV systems with continuous control strategy, the proposed intermittent control strategy saves a large amount of computation resources. An average method is introduced in developing the event-triggered mechanism (ETM) such that the amount of unexpected triggering events induced by uncertain disturbances is greatly reduced. Moreover, such a mechanism can further decrease the average data-releasing rate, thereby alleviating the burden of network bandwidth. Sufficient conditions for multi-UAV systems with deception attacks to achieve the predefined formation are obtained with the aid of Lyapunov stability theory. Finally, the validity of the proposed theoretical results is demonstrated via a simulation example.
Tingting Yin, Zhou Gu, Ju H. Park 0001
IEEE Trans. Neural Networks Learn. Syst.1
2023 KextFuzz: Fuzzing macOS Kernel EXTensions on Apple Silicon via Exploiting Mitigations
Tingting Yin, Zicong Gao, Zhenghang Xiao, Zheyu Ma, Chao Zhang 0008
USENIX Security Symposium1
2023 NSFuzz: Towards Efficient and State-Aware Network Service Fuzzing - RCR Report
abstract
We provide artifacts to reproduce the evaluation results of our article: “NSFuzz: Towards Efficient and State-Aware Network Service Fuzzing”. The provided artifacts can be downloaded from https://zenodo.org/record/7134490 . It includes 14 docker containers, several scripts for execution and analysis, one additional proof for the crash results, and six related documents for the running of experiments. We claim for all three badges, i.e., Available, Functional, and Reusable. This report gives instructions on how to reproduce the answers which mainly involve basic operations on the Ubuntu operating system.
Shisong Qin, Zheyu Ma, Bodong Zhao, Tingting Yin, Chao Zhang 0008
ACM Trans. Softw. Eng. Methodol.5
2023 NSFuzz: Towards Efficient and State-Aware Network Service Fuzzing
abstract
As an essential component responsible for communication, network services are security critical, thus, it is vital to find their vulnerabilities. Fuzzing is currently one of the most popular software vulnerability discovery techniques, widely adopted due to its high efficiency and low false positives. However, existing coverage-guided fuzzers mainly aim at stateless local applications, leaving stateful network services underexplored. Recently, some fuzzers targeting network services have been proposed but have certain limitations, for example, insufficient or inaccurate state representation and low testing efficiency. In this article, we propose a new fuzzing solution NSFuzz for stateful network services. We studied typical implementations of network service programs to determine how they represent states and interact with clients. Accordingly, we propose (1) a program variable–based state representation scheme and (2) an efficient interaction synchronization mechanism to improve fuzzing efficiency. We implemented a prototype of NSFuzz, which uses static analysis and annotation application programming interfaces (APIs) to identify synchronization points and state variables within the services. It then achieves fast I/O synchronization and accurate service state tracing to carry out efficient state-aware fuzzing via lightweight compile-time instrumentation. The evaluation results show that compared with other network service fuzzers, including AFL net and S tate AFL, our solution NSFuzz could infer a more accurate state model during fuzzing and improve fuzzing throughput by up to 200×. In addition, NSFuzz could improve code coverage by up to 25% and trigger more crashes in less time. We also performed a fuzzing campaign to find new bugs in the latest version of the target services; 8 zero-day vulnerabilities have been found by NSFuzz.
Shisong Qin, Zheyu Ma, Bodong Zhao, Tingting Yin, Chao Zhang 0008
ACM Trans. Softw. Eng. Methodol.5
2021 From Exposed to Exploited: Drawing the Picture of Industrial Control Systems Security Status in the Internet Age
Yixiong Wu, Jianwei Zhuge, Tingting Yin, Junmin Zhu, Guannan Guo, Jianju Hu
ICISSP3
2021 VScape: Assessing and Escaping Virtual Call Protections
Kaixiang Chen, Chao Zhang 0008, Tingting Yin, Xingman Chen
USENIX Security Symposium3
2021 Event-Based Secure Leader-Following Consensus Control for Multiagent Systems With Multiple Cyber Attacks
abstract
This article concentrates on event-based secure leader-following consensus control for multiagent systems (MASs) with multiple cyber attacks, which contain replay attacks and denial-of-service (DoS) attacks. A new multiple cyber-attacks model is first built by considering replay attacks and DoS attacks simultaneously. Different from the existing researches on MASs with a fixed topological graph, the changes of communication topologies caused by DoS attacks are considered for MASs. Besides, an event-triggered mechanism is adopted for mitigating a load of network bandwidth by scheduling the transmission of sampled data. Then, an event-based consensus control protocol is first developed for MASs subjected to multiple cyber attacks. In view of this, by using the Lyapunov stability theory, sufficient conditions are obtained to ensure the mean-square exponential consensus of MASs. Furthermore, the event-based controller gain is derived by solving a set of linear matrix inequalities. Finally, an example is simulated for confirming the effectiveness of the theoretical results.
Jinliang Liu 0001, Tingting Yin, Dong Yue 0001, Hamid Reza Karimi, Jinde Cao
IEEE Trans. Cybern.2
2021 Path Tracking Control of Autonomous Vehicles Subject to Deception Attacks via a Learning-Based Event-Triggered Mechanism
abstract
This article investigates the problem of event-triggered secure path tracking control of autonomous ground vehicles (AGVs) under deception attacks. To relieve the burden of the shareable vehicle communication network and to improve the tracking performance in the presence of deception attacks, a learning-based event-triggered mechanism (ETM) is proposed. Different from existing ETMs, the triggering threshold of the proposed mechanism can be dynamically adjusted with conditions of the latest vehicle state. Each vehicle in this study is deemed as an agent, under which a novel control strategy is developed for these autonomous agents with deception attacks. With the assistance of Lyapunov stability theory, sufficient conditions are obtained to guarantee the stability and stabilization of the overall system. Finally, a simulation example is provided to demonstrate the effectiveness of the proposed theoretical results.
Zhou Gu, Tingting Yin, Zhengtao Ding
IEEE Trans. Neural Networks Learn. Syst.2
2021 Security Control for T-S Fuzzy Systems With Adaptive Event-Triggered Mechanism and Multiple Cyber-Attacks
abstract
This article focuses on the security control for Takagi-Sugeno (T-S) fuzzy systems with adaptive event-triggered mechanism (AETM) and multiple cyber-attacks, which include deception attacks and denial-of-service (DoS) attacks. A multiple cyber-attacks model is first established for T-S fuzzy systems by considering deception attacks and DoS attacks at the same time. An AETM is introduced to relieve the network load, where the threshold of event-triggering condition can be adaptively adjusted while preserving the system performance. Then a novel mathematical model for T-S fuzzy systems with multiple cyber-attacks and AETM is proposed first. Based on the built model, sufficient conditions to guarantee the exponentially mean square stability of the system are achieved by utilizing the Lyapunov stability theory. Moreover, the controller gains are derived with the help of a linear matrix inequality technique. Finally, simulated examples are presented for illustrating the effectiveness of the proposed method.
Jinliang Liu 0001, Tingting Yin, Jie Cao 0001, Dong Yue 0001, Hamid Reza Karimi
IEEE Trans. Syst. Man Cybern. Syst.2
2017 Characterizing Passenger Flow for a Transportation Hub Based on Mobile Phone Data
abstract
As the vital node of a passenger transportation network, the transportation hub is the connection between multiple travel modes and the important port for the massive passenger flow to enter into or exit from a city area. Transportation operators need to understand the passenger flow pattern for hub management, transportation planning, and so on. However, it is difficult to use traditional methods, such as video detection, to provide such information. With the increasing number of mobile phone users, mobile phone data have shown remarkable potential in detecting the transportation information with high sampling coverage and low cost. This paper utilizes the mobile phone data to characterize the passenger flow of the Hongqiao transportation hub located in Shanghai, China. First, a temporal-spatial clustering method is proposed to identify the passenger active area of the Hongqiao hub in the wireless communication space. Second, a classification process is presented to extract different types of passengers in this transportation hub. Subsequently, the access characteristics of passengers in the city are studied for various time intervals. The results further verify the potential of using mobile phone data to monitor and characterize passenger flow related to the transportation hubs.
Gang Zhong, Xia Wan, Jian Zhang 0011, Tingting Yin, Bin Ran
IEEE Trans. Intell. Transp. Syst.4