EDBT 2026 Demo / reviewers in the wild / expert
Shengzhi Zhang
dblp:65/3618
· DBLP profile ↗
53ranked-venue papers
10as first author
28since 2021 · last 2026
0000-0001-9432-9779ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 39 · 5 first-author · 22 since 2021Systems, architecture and hardware · 5 · 1 first-author · 4 since 2021Computer networks · 5 · 2 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Electromagnetic interference (EMI) backdoor: An EMI-based backdoor attack against computer vision systemsabstractRecently, computer vision systems, for example, smart traffic surveillance systems, facial recognition systems, etc., have significantly changed our daily life. Even though the neural networks in such systems are known to suffer from backdoor attacks, causing the backdoored models to behave well on benign samples but maliciously on controlled samples (with triggers applied to activate the backdoor), it is generally believed that most of the triggers, when used in physical attacks, are noticeable to victim users and not robust in various settings, such as different angles, distances, lighting conditions, etc. In this paper, we leverage electromagnetic interference (EMI) to produce a specific pattern distortion in images captured by the camera system and utilize the pattern distortion as the backdoor trigger. To avoid the overhead of manually collecting poisoned images, we introduce a simulation sample generation approach, converting clean images to poisoned ones by simulating the distortion caused by EMI against the camera system. Additionally, we propose a contrast loss function to enhance the generalization of backdoor features, improving triggers’ capability to activate the embedded backdoors. We conduct extensive physical experiments using diverse deep neural networks across various camera systems in different practical environments, achieving a 92.54% average backdoor success rate. Mengjie Sun, Peizhuo Lv, Shengzhi Zhang, Jianshuo Liu, Kai Chen 0012, Hong Li 0004, Zhi Li 0018, Qinhong Jiang, Limin Sun 0001 |
J. Comput. Secur. | 3 |
| 2026 | FlexClave: An Extensible and Secure Trusted Execution Environment FrameworkabstractAs computer system software stacks become increasingly complex, the associated security risks also escalate. Trusted Execution Environments (TEEs) have emerged as a mainstream security solution to enhance system security. TEEs can be categorized into user-level TEEs, OS-level TEEs, and hybrid TEEs. However, these TEEs typically possess fixed security boundaries and isolation domains, limiting their adaptability to varying security requirements and dynamic scenarios. Moreover, the design of Trusted Computing Base (TCB) components in TEE frameworks often operates at the highest privilege levels of the architecture. This concentration of critical code at the highest privilege level increases the whole platform’s security risk due to the growing amount of code as more security functions are added. In this paper, we propose FlexClave, an extensible and secure TEE framework designed to address these issues. FlexClave leverages hardware primitives to create secure isolation boundaries tailored to different use cases. Additionally, our framework distributes TCB components across various privilege levels, reducing the concentration of security functions at the highest privilege levels and mitigating the risks associated with running extensive code in a single, highly privileged context. We implement two prototypes on ARMv9-A Fixed Virtual Platform and ARMv8 RK3399 SoC, each with two use cases (container and virtual machine), to evaluate the system’s security and performance. Qihang Zhou, Wenzhuo Cao, Xiaoqi Jia, Shaowen Xu, Jiayun Chen, Haichao Du, Yamin Xie, Peijie Yin, Shengzhi Zhang, Peng Liu 0005 |
IEEE Trans. Computers | 14 |
| 2026 | FedWM: Data-Free Watermarking for Model Ownership Protection in Federated LearningabstractThe widespread adoption of federated learning has been driven by growing demands for privacy protection in model training. Federated learning enables multiple clients to collaboratively train a global model coordinated by a central server without sharing their raw data. However, when distributing the global model to clients, the central server faces significant security risks from malicious clients who may steal and misuse the model, thereby compromising its ownership. While existing watermarking techniques typically rely on main task data for ownership protection, their application in federated learning is limited since the server lacks access to this data, which remains with the clients. To address this challenge, we propose a novel data-free watermarking method. We utilize substitute data unrelated to the main task and improve efficiency by filtering out redundant samples. To optimize the watermarking process, we introduce a logits alignment-based optimization strategy that uses the substitute dataset with watermark triggers for effective embedding. Additionally, we propose a dynamic optimization algorithm to balance the trade-off between watermark embedding and main task. We comprehensively evaluate our approach across four datasets, four model architectures, and three mainstream deep learning tasks. Our experimental results demonstrate nearly perfect watermark performance while maintaining minimal impact on the main task. Notably, our watermarking method proves resistant to existing backdoor detection techniques, establishing its effectiveness, robustness and stealthiness. Congyi Li, Peizhuo Lv, Xuejing Yuan, Shengzhi Zhang, Kai Chen 0012, Yingjiu Li |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | ERASE: Bypassing Collaborative Detection of AI Counterfeit via Comprehensive Artifacts EliminationabstractThe rapid advancement of AI-Generated Images (AIGI) has amplified concerns about increasingly undetectable deepfakes. Recent adversarial techniques further worsen this problem by enhancing the imperceptibility of synthetic forgeries to both human viewers and automated detection systems. To simulate realistic adversaries and expose detection vulnerabilities, AI-Generated Image Stealth (AIGI-S) methods specifically aim to make synthetic images harder to detect. However, existing AIGI-S approaches often lack universality and transferability across diverse detection models—especially in collaborative detection settings—and tend to prioritize machine deception over human perceptual fidelity, resulting in visible artifacts. Inspired by real-world antique painting forgery, we propose ERASE (comprehensivE counteRfeit ArtifactS Elimination), a stealth-oriented optimization framework designed for multi-detector environments. ERASE comprehensively suppresses generative artifacts and incorporates a perceptual optimization objective to improve deception against both detection algorithms and human examiners. Extensive evaluations across eight distinct generative subsets from the GenImage benchmark and fifteen detection models demonstrate that ERASE delivers substantially improved attack performance—improving single-detector evasion by +10.5% and collaborative detection evasion by +17.9%—while preserving high image quality. Qianyun Yang, Peizhuo Lv, Yingjiu Li, Shengzhi Zhang, Zhiwei Chen 0003, Zixu Li 0001, Yupeng Hu 0003 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | AI-Shielder: Exploiting Backdoors to Defend Against Adversarial AttacksabstractDeep neural networks (DNNs) have been widely used in many fields due to their increasingly high accuracy. However, they are also vulnerable to adversarial attacks, posing a serious threat to security-critical applications such as autonomous driving, remote diagnosis, etc. Existing solutions are limited in detecting/preventing such attacks, and also impacting the performance on the original tasks. In this paper, we present AI-Shielder, a novel approach to defeating adversarial attacks that leverages intentionally embedded backdoors to fail the adversarial perturbations and maintain the performance of the original main task. We extensively evaluate AI-Shielder using sixteen popular adversarial example generation approaches, and experimental results demonstrate its efficacy in defeating adversarial attacks. Specifically, AI-Shielder reduces the attack success rate from 91.8% to 3.8%, which outperforms the state-of-the-art works by 37.2%, with only a 0.6% decline in the clean data accuracy. Furthermore, AI-Shielder introduces only 1.43% overhead to the model prediction time, almost negligible in most cases. Shengzhi Zhang, Kai Chen 0012 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | RAG-WM: An Efficient Black-Box Watermarking Approach for Retrieval-Augmented Generation of Large Language ModelsabstractIn recent years, tremendous success has been witnessed in Retrieval-Augmented Generation (RAG), widely used to enhance Large Language Models (LLMs) in domain-specific, knowledge-intensive, and privacy-sensitive tasks. However, attackers may steal those valuable RAGs and deploy or commercialize them, making it essential to detect Intellectual Property (IP) infringement. Most existing ownership protection solutions, such as watermarks, are designed for relational databases and texts. They cannot be directly applied to RAGs because relational database watermarks require white-box access to detect IP infringement, which is unrealistic for the knowledge base in RAGs. Meanwhile, post-processing by the adversary's deployed LLMs typically destructs text watermark information. To address those problems, we propose a novel black-box ''knowledge watermark'' approach, named RAG-WM, to detect IP infringement of RAGs. RAG-WM uses a multi-LLM interaction framework, comprising a Watermark Generator, Shadow LLM & RAG, and Watermark Discriminator, to create watermark texts based on watermark entity-relationship tuples and inject them into the target RAG. We evaluate RAG-WM across three domain-specific and two privacy-sensitive tasks on four benchmark LLMs. Experimental results show that RAG-WM effectively detects the stolen RAGs in various deployed LLMs. Furthermore, RAG-WM is robust against paraphrasing, unrelated content removal, knowledge insertion, and knowledge expansion attacks. Lastly, RAG-WM can also evade watermark detection approaches, highlighting its promising application in detecting IP infringement of RAG systems. Peizhuo Lv, Mengjie Sun, Hao Wang 0034, XiaoFeng Wang 0001, Shengzhi Zhang, Kai Chen 0012, Limin Sun 0001 |
CCS | 5 |
| 2025 | A Model Stealing Attack Against Multi-Exit NetworksabstractCompared to traditional neural networks with a single output channel, a multi-exit network has multiple exits that allow for early outputs from the model's intermediate layers, thus significantly improving computational efficiency while maintaining similar main task accuracy. Existing model stealing attacks can only steal the model's utility while failing to capture its output strategy, i.e., a set of thresholds used to determine from which exit to output. This leads to a significant decrease in computational efficiency for the extracted model, thereby losing the advantage of multi-exit networks. In this paper, we propose the first model stealing attack against multi-exit networks to extract both the model utility and the output strategy. We employ Kernel Density Estimation to analyze the target model's output strategy and use performance loss and strategy loss to guide the training of the extracted model. Furthermore, we design a novel output strategy search algorithm to maximize the consistency between the victim model and the extracted model's output behaviors. In experiments across multiple multi-exit networks and benchmark datasets, our method always achieves accuracy and efficiency closest to the victim models. Peizhuo Lv, Kai Chen 0012, Shengzhi Zhang, Yuling Cai, Fan Xiang |
ICASSP | 4 |
| 2025 | RContainer: A Secure Container Architecture through Extending ARM CCA Hardware Primitives
Qihang Zhou, Wenzhuo Cao, Xiaoqi Jia, Peng Liu 0005, Shengzhi Zhang, Jiayun Chen, Shaowen Xu |
NDSS | 5 |
| 2025 | EvilHarmony: Stealthy Adversarial Attacks Against Black-Box Speech Recognition SystemsabstractAutomatic Speech Recognition (ASR) systems are vulnerable to adversarial examples (AEs), where small, carefully designed perturbations are added to original audio to mislead the systems into generating target commands. Existing adversarial attacks typically initialize perturbations either as zero or as Text-to-Speech clips of the target command. The former accumulates the features of the command in the perturbed audio, while the latter constantly reduces the features of the command, resulting in the generation of AEs. Although most target commands in the AEs are imperceptible to humans, the audio often exhibits noticeable distortions or disruptions, making it apparent that the sound has been tampered with. This work aims to retain only the essential features of adversarial audio, minimizing distortions from unnecessary elements to improve quality and make the attack less detectable. Our findings highlight the importance of formants as critical features for black-box adversarial attacks, motivating the development of a novel Formant Filter Bank (FFB) tailored to the target command. By inputting musical audio into the FFB, we utilize the filtered output as the perturbation seed, which retains the formant features of the target command and blends in certain features of the original music. Then we search for a minimum enhancement factor for the perturbation seed to generate high-quality AEs. Our perturbation can be regarded as local amplitude modulation of the music, so we define the AE as EvilHarmony. Experimental results demonstrate that our method successfully attacks commercial black-box ASR models, including Microsoft, Google, Amazon, Tencentyun, Aliyun, and OpenAI Whisper-V3. Compared to existing approaches, our AEs achieve significantly greater stealth, with 53% to 77% of participants perceiving them as indistinguishable from normal audio across the six ASR API services. Additionally, our approach successfully attacks Google Assistant and voice assistants on Surface Pro 9 in the real world. Demos are uploaded at https://sites.google.com/view/evilharmony. Xuejing Yuan, Jiangshan Zhang, Kai Chen 0012, XiaoFeng Wang 0001, Shengzhi Zhang, Dun Liu, Runnan Zhu |
SP | 6 |
| 2024 | SEDSpec: Securing Emulated Devices by Enforcing Execution SpecificationabstractDevice emulation is a vital aspect of virtualization, yet remains vulnerable to security threats. Prior research has focused on monitoring I/O data flow or identifying internal device anomalies but often falls short in precision and automation. In this paper, we propose a novel method that leverages the normal operations of an emulated device to formulate an execution specification. The specification acts as a criterion to evaluate the device's behavior and state transitions. We implement SEDSpec, a prototype system that automatically generates the execution specification for an emulated device and devises three check strategies for identifying any deviations from this specification, thereby ensuring normal operations and enhancing the security of the emulated device. We evaluate SEDSpec with five different execution specifications. The results show that SEDSpec can detect anomalies caused by vulnerability exploitation while maintaining the devices' regular functioning with minimal performance overhead. Shengzhi Zhang, Xiaoqi Jia, Qihang Zhou, Heqing Huang 0001, Shaowen Xu, Haochao Du |
DSN | 2 |
| 2024 | SSL-WM: A Black-Box Watermarking Approach for Encoders Pre-trained by Self-Supervised Learning
Peizhuo Lv, Shenchen Zhu, Shengzhi Zhang, Kai Chen 0012, Ruigang Liang, Chang Yue, Fan Xiang, Yuling Cai, Hualong Ma, Guozhu Meng |
NDSS | 4 |
| 2024 | MEA-Defender: A Robust Watermark against Model Extraction AttackabstractRecently, numerous highly-valuable Deep Neural Networks (DNNs) have been trained using deep learning algorithms. To protect the Intellectual Property (IP) of the original owners over such DNN models, backdoor-based watermarks have been extensively studied. However, most of such watermarks fail upon model extraction attack, which utilizes input samples to query the target model and obtains the corresponding outputs, thus training a substitute model using such input-output pairs. In this paper, we propose a novel watermark to protect IP of DNN models against model extraction, named MEA-Defender. In particular, we obtain the watermark by combining two samples from two source classes in the input domain and design a watermark loss function that makes the output domain of the watermark within that of the main task samples. Since both the input domain and the output domain of our watermark are indispensable parts of those of the main task samples, the watermark will be extracted into the stolen model along with the main task during model extraction. We conduct extensive experiments on four model extraction attacks, using five datasets and six models trained based on supervised learning and self-supervised learning algorithms. The experimental results demonstrate that MEA-Defender is highly robust against different model extraction attacks, and various watermark removal/detection approaches. Peizhuo Lv, Hualong Ma, Kai Chen 0012, Jiachen Zhou 0001, Shengzhi Zhang, Ruigang Liang, Shenchen Zhu |
SP | 5 |
| 2024 | Exploring Permission Control Flaws in Mini-appsabstractMini-apps, running within super apps like WeChat, Snapchat, Telegram, etc., have become quite popular these years, expanding the capability of super apps to offer almost any functionality users might desire in their daily lives. However, developers of both super apps and mini-apps typically focus on functionality, thus overlooking security measures essential for protecting users’ sensitive information and safeguarding critical operations. In this paper, we utilize a static analysis approach, revealing two major security flaws of mini-apps and super apps: users’ sensitive information leakage and caller impersonation attacks. We analyzed 10,000 popular mini-apps on WeChat and found that 2,554 are vulnerable to the users’ sensitive information leakage. For the caller impersonation attack, we found one example that is vulnerable to such an attack. Shengzhi Zhang |
TrustCom | 4 |
| 2024 | A Defensive Framework Against Adversarial Attacks on Machine Learning-Based Network Intrusion Detection SystemsabstractAs cyberattacks become increasingly sophisticated, advanced Network Intrusion Detection Systems (NIDS) are critical for modern network security. Traditional signature-based NIDS are inadequate against zero-day and evolving attacks. In response, machine learning (ML)-based NIDS have emerged as promising solutions; however, they are vulnerable to adversarial evasion attacks that subtly manipulate network traffic to bypass detection. To address this vulnerability, we propose a novel defensive framework that enhances the robustness of ML-based NIDS by simultaneously integrating adversarial training, dataset balancing techniques, advanced feature engineering, ensemble learning, and extensive model fine-tuning. We validate our framework using the NSL-KDD and UNSW-NB15 datasets. Experimental results show, on average, a 35% increase in detection accuracy and a 12.5% reduction in false positives compared to baseline models, particularly under adversarial conditions. The proposed defense against adversarial attacks significantly advances the practical deployment of robust ML-based NIDS in real-world networks. Benyamin Tafreshian, Shengzhi Zhang |
TrustCom | 2 |
| 2024 | HClave: An isolated execution environment design for hypervisor runtime security
Qihang Zhou, Wenzhuo Cao, Xiaoqi Jia, Shengzhi Zhang, Jiayun Chen, Weijuan Zhang, Haichao Du, Qingjia Huang |
Comput. Secur. | 4 |
| 2024 | NeuralSanitizer: Detecting Backdoors in Neural NetworksabstractDeep neural networks (DNNs) have been pervasively used in many areas, e.g., computer vision, speech recognition, natural language processing, etc. However, recent works show that they are vulnerable to backdoor/Trojan attacks, severely restricting their usage in various scenarios. In this paper, we proposeNeuralSanitizer, a novel approach to detect and remove backdoors in DNNs, capable of capturing various triggers with better accuracy and higher efficiency. In particular, we identify two fundamental properties of triggers, i.e., their effectiveness in the backdoored model and ineffectiveness in other clean models, and design a novel objective function to reconstruct triggers based on them. Then we present a new approach that leverages transferability to identify adversarial patches that could be generated during trigger reconstruction, thus detecting backdoors more accurately. We evaluate NeuralSanitizer on real-world backdoored DNNs and achieve 2.1% FNR and 0.9% FPR on average, significantly outperforming the state-of-the-art works by 1~14 times. In addition, NeuralSanitizer can reconstruct triggers up to 25% of the size of the original inputs on average, compared to only 6~10% by existing works. Finally, NeuralSanitizer is also 1~25 times faster than existing works. Yue Zhao 0018, Shengzhi Zhang, Kai Chen 0012 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | PEDI-GAN: power equipment data imputation based on generative adversarial networks with auxiliary encoder
Qianwei Lv, He Luo, Jianwei Tai, Shengzhi Zhang |
J. Supercomput. | 5 |
| 2023 | DBIA: Data-Free Backdoor Attack Against Transformer NetworksabstractRecently, transformer architecture has demonstrated its significance in both Natural Language Processing (NLP) and Computer Vision (CV) tasks. Although other network models are known to be vulnerable to the backdoor attack, which embeds triggers in the models and controls the models’ behavior when the triggers are presented, little is known about how such an attack performs on the transformer models. In this paper, we propose DBIA, a novel Data-free1Backdoor Attack against the CV-oriented transformer networks, leveraging the inherent attention mechanism of transformers to generate triggers and injecting the backdoor using a poisoned substitute dataset. We conducted extensive experiments using three benchmark transformers, i.e., ViT, DeiT, and Swin Transformer, on four mainstream image classification tasks, i.e., ImageNet, CIFAR-10, GTSRB, and Youtube Face. The evaluation results demonstrate that, with fewer resources, our approach can embed backdoors with a high success rate and a low impact on the performance of the victim transformers. Peizhuo Lv, Hualong Ma, Jiachen Zhou 0001, Ruigang Liang, Kai Chen 0012, Shengzhi Zhang, Yunfei Yang 0001 |
ICME | 6 |
| 2023 | AI-Guardian: Defeating Adversarial Attacks using BackdoorsabstractDeep neural networks (DNNs) have been widely used in many fields due to their increasingly high accuracy. However, they are also vulnerable to adversarial attacks, posing a serious threat to security-critical applications such as autonomous driving, remote diagnosis, etc. Existing solutions are limited in detecting/preventing such attacks, and also impacting the performance on the original tasks. In this paper, we present AI-Guardian, a novel approach to defeating adversarial attacks that leverages intentionally embedded backdoors to fail the adversarial perturbations and maintain the performance of the original main task. We extensively evaluate AI-Guardian using five popular adversarial example generation approaches, and experimental results demonstrate its efficacy in defeating adversarial attacks. Specifically, AI-Guardian reduces the attack success rate from 97.3% to 3.2%, which outperforms the state-of-the-art works by 30.9%, with only a 0.9% decline on the clean data accuracy. Furthermore, AI-Guardian introduces only 0.36% overhead to the model prediction time, almost negligible in most cases. Shengzhi Zhang, Kai Chen 0012 |
SP | 2 |
| 2023 | A Data-free Backdoor Injection Approach in Neural Networks
Peizhuo Lv, Chang Yue, Ruigang Liang, Yunfei Yang 0001, Shengzhi Zhang, Hualong Ma, Kai Chen 0012 |
USENIX Security Symposium | 5 |
| 2023 | Enhance the trust between IoT devices, mobile apps, and the cloud based on blockchain
Juan Wang 0006, Wenzhe Yi, Mengda Yang, Jiaci Ma, Shengzhi Zhang, Shirong Hao |
J. Netw. Comput. Appl. | 5 |
| 2023 | A Robustness-Assured White-Box Watermark in Neural NetworksabstractRecently, stealing highly-valuable and large-scale deep neural network (DNN) models becomes pervasive. The stolen models may be re-commercialized, e.g., deployed in embedded devices, released in model markets, utilized in competitions, etc, which infringes the Intellectual Property (IP) of the original owner. Detecting IP infringement of the stolen models is quite challenging, even with the white-box access to them in the above scenarios, since they may have experienced fine-tuning, pruning, functionality-equivalent adjustment to destruct any embedded watermark. Furthermore, the adversaries may also attempt to extract the embedded watermark or forge a similar watermark to falsely claim ownership. In this article, we propose a novel DNN watermarking solution, named$HufuNet$, to detect IP infringement of DNN models against the above mentioned attacks. Furthermore, HufuNet is the first one theoretically proved to guarantee robustness against fine-tuning attacks. We evaluate HufuNet rigorously on four benchmark datasets with five popular DNN models, including convolutional neural network (CNN) and recurrent neural network (RNN). The experiments and analysis demonstrate that HufuNet is highly robust against model fine-tuning/pruning, transfer learning, kernels cutoff/supplement, functionality-equivalent attacks and fraudulent ownership claims, thus highly promising to protect large-scale DNN models in the real world. Peizhuo Lv, Shengzhi Zhang, Kai Chen 0012, Ruigang Liang, Hualong Ma, Yue Zhao 0018, Yingjiu Li |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | SecFortress: Securing Hypervisor using Cross-layer IsolationabstractVirtualization is the corner stone of cloud computing, but the hypervisor, the crucial software component that enables virtualization, is known to suffer from various attacks. It is challenging to secure the hypervisor due to at least two reasons. On one hand, commercial hypervisors are usually integrated into a privileged Operating System (OS), which brings in a larger attack surface. On the other hand, multiple Virtual Machines (VM) share a single hypervisor, thus a malicious VM could leverage the hypervisor as a bridge to launch “cross-VM” attacks. In this work, we propose SecFortress, a dependable hypervisor design that decouples the virtualization layer into a mediator, an outerOS, and multiple HypBoxes through a cross-layer isolation approach. SecFortress extends the nested kernel approach to de-privilege the outerOS from accessing the mediator's memory and creates an isolated hypervisor instance, HypBox, to confine the impacts from the untrusted VMs. We implemented SecFortress based on KVM and evaluated its effectiveness and efficiency through case studies and performance evaluation. Experimental results show that SecFortress can significantly improve the security of the hypervisor with negligible runtime overhead. Qihang Zhou, Xiaoqi Jia, Shengzhi Zhang, Jiayun Chen, Weijuan Zhang |
IPDPS | 3 |
| 2022 | Practical Backdoor Attack Against Speaker Recognition System
Jianwei Tai, Xiaoqi Jia, Shengzhi Zhang |
ISPEC | 4 |
| 2022 | An Efficient Use-after-Free Mitigation Approach via Static Dangling Pointer Nullification
Xiaoqi Jia, Xun An, Shengzhi Zhang |
SEC | 4 |
| 2022 | EnShare: Sharing Files Securely and Efficiently in the Cloud using EnclaveabstractAs the cloud-based file sharing becomes increasingly popular, it is crucial to protect the outsourced data against unauthorized access. In this paper, we propose EnShare, a secure and practical file sharing system that leverages cooperation of server-side and client-side enclaves to enforce access control, with the former responsible for registration, authentication and access control enforcement and the latter performing file decryption. Such design significantly reduces the computation workload of server-side enclaves, thus capable of handling concurrent requests. Meanwhile, it also supports immediate permission revocation, since the file decryption keys inside the client-side enclaves are destroyed immediately after use. We implement a prototype of EnShare and the evaluation demonstrates it enforces access control securely with high throughput and low latency. Xiaoqi Jia, Shengzhi Zhang, Lubomir T. Chitkushev |
TrustCom | 3 |
| 2022 | SoK: A Modularized Approach to Study the Security of Automatic Speech Recognition SystemsabstractWith the wide use of Automatic Speech Recognition (ASR) in applications such as human machine interaction, simultaneous interpretation, audio transcription, and so on, its security protection becomes increasingly important. Although recent studies have brought to light the weaknesses of popular ASR systems that enable out-of-band signal attack, adversarial attack, and so on, and further proposed various remedies (signal smoothing, adversarial training, etc.), a systematic understanding of ASR security (both attacks and defenses) is still missing, especially on how realistic such threats are and how general existing protection could be. In this article, we present our systematization of knowledge for ASR security and provide a comprehensive taxonomy for existing work based on a modularized workflow. More importantly, we align the research in this domain with that on security in Image Recognition System (IRS), which has been extensively studied, using the domain knowledge in the latter to help understand where we stand in the former. Generally, both IRS and ASR are perceptual systems. Their similarities allow us to systematically study existing literature in ASR security based on the spectrum of attacks and defense solutions proposed for IRS, and pinpoint the directions of more advanced attacks and the directions potentially leading to more effective protection in ASR. In contrast, their differences, especially the complexity of ASR compared with IRS, help us learn unique challenges and opportunities in ASR security. Particularly, our experimental study shows that transfer attacks across ASR models are feasible, even in the absence of knowledge about models (even their types) and training data. Jiangshan Zhang, Xuejing Yuan, Shengzhi Zhang, Kai Chen 0012, XiaoFeng Wang 0001, Shanqing Guo |
ACM Trans. Priv. Secur. | 4 |
| 2021 | AI-Lancet: Locating Error-inducing Neurons to Optimize Neural NetworksabstractDeep neural network (DNN) has been widely utilized in many areas due to its increasingly high accuracy. However, DNN models could also produce wrong outputs due to internal errors, which may lead to severe security issues. Unlike fixing bugs in traditional computer software, tracing the errors in DNN models and fixing them are much more difficult due to the uninterpretability of DNN. In this paper, we present a novel and systematic approach to trace and fix the errors in deep learning models. In particular, we locate the error-inducing neurons that play a leading role in the erroneous output. With the knowledge of error-inducing neurons, we propose two methods to fix the errors: the neuron-flip and the neuron-fine-tuning. We evaluate our approach using five different training datasets and seven different model architectures. The experimental results demonstrate its efficacy in different application scenarios, including backdoor removal and general defects fixing. Yue Zhao 0018, Kai Chen 0012, Shengzhi Zhang |
CCS | 4 |
| 2020 | SEEF-ALDR: A Speaker Embedding Enhancement Framework via Adversarial Learning based Disentangled RepresentationabstractSpeaker verification, as a biometric authentication mechanism, has been widely used due to the pervasiveness of voice control on smart devices. However, the task of “in-the-wild” speaker verification is still challenging, considering the speech samples may contain lots of identity-unrelated information, e.g., background noise, reverberation, emotion, etc. Previous works focus on optimizing the model to improve verification accuracy, without taking into account the elimination of the impact from the identity-unrelated information. To solve the above problem, we propose SEEF-ALDR, a novel Speaker Embedding Enhancement Framework via Adversarial Learning based Disentangled Representation, to reinforce the performance of existing models on speaker verification. The key idea is to retrieve as much speaker identity information as possible from the original speech, thus minimizing the impact of identity-unrelated information on the speaker verification task by using adversarial learning. Experimental results demonstrate that the proposed framework can significantly improve the performance of speaker verification by 20.3% and 23.8% on average over 13 tested baselines on dataset Voxceleb1 and 8 tested baselines on dataset Voxceleb2 respectively, without adjusting the structure or hyper-parameters of them. Furthermore, the ablation study was conducted to evaluate the contribution of each module in SEEF-ALDR. Finally, porting an existing model into the proposed framework is straightforward and cost-efficient, with very little effort from the model owners due to the modular design of the framework. Jianwei Tai, Xiaoqi Jia, Qingjia Huang, Weijuan Zhang, Haichao Du, Shengzhi Zhang |
ACSAC | 6 |
| 2020 | EnclavePDP: A General Framework to Verify Data Integrity in Cloud Using Intel SGX
Yihua Xu, Xiaoqi Jia, Shengzhi Zhang, Peng Liu 0005, Shuai Chang |
RAID | 4 |
| 2020 | Devil's Whisper: A General Approach for Physical Adversarial Attacks against Commercial Black-box Speech Recognition Devices
Xuejing Yuan, Jiangshan Zhang, Yue Zhao 0018, Shengzhi Zhang, Kai Chen 0012, XiaoFeng Wang 0001 |
USENIX Security Symposium | 5 |
| 2019 | Seeing isn't Believing: Towards More Robust Adversarial Attack Against Real World Object DetectorsabstractRecently Adversarial Examples (AEs) that deceive deep learning models have been a topic of intense research interest. Compared with the AEs in the digital space, the physical adversarial attack is considered as a more severe threat to the applications like face recognition in authentication, objection detection in autonomous driving cars, etc. In particular, deceiving the object detectors practically, is more challenging since the relative position between the object and the detector may keep changing. Existing works attacking object detectors are still very limited in various scenarios, e.g., varying distance and angles, etc. In this paper, we presented systematic solutions to build robust and practical AEs against real world object detectors. Particularly, for Hiding Attack (HA), we proposed thefeature-interference reinforcement (FIR) method and theenhanced realistic constraints generation (ERG) to enhance robustness, and for Appearing Attack (AA), we proposed thenested-AE, which combines two AEs together to attack object detectors in both long and short distance. We also designed diverse styles of AEs to make AA more surreptitious. Evaluation results show that our AEs can attack the state-of-the-art real-time object detectors (i.e., YOLO V3 and faster-RCNN) at the success rate up to 92.4% with varying distance from 1m to 25m and angles from -60º to 60º. Our AEs are also demonstrated to be highly transferable, capable of attacking another three state-of-the-art black-box models with high success rate. Yue Zhao 0018, Ruigang Liang, Qintao Shen, Shengzhi Zhang, Kai Chen 0012 |
CCS | 5 |
| 2019 | Building a Trustworthy Execution Environment to Defeat Exploits from both Cyber Space and Physical Space for ARMabstractThe rapid evolution of Internet-of-Things (IoT) technologies has led to an emerging need to make them smarter. However, the smartness comes at the cost of multi-vector security exploits. From cyber space, a compromised operating system could access all the data in a cloud-aware IoT device. From physical space, cold-boot attacks and DMA attacks impose a great threat to the unattended devices. In this paper, we propose TrustShadow that provides a comprehensively protected execution environment for unmodified application running on ARM-based IoT devices. To defeat cyber attacks, TrustShadow takes advantage of ARM TrustZone technology and partitions resources into the secure and normal worlds. In the secure world, TrustShadow constructs a trusted execution environment for security-critical applications. This trusted environment is maintained by a lightweight runtime system. The runtime system does not provide system services itself. Rather, it forwards them to the untrusted normal-world OS, and verifies the returns. The runtime system further employs a page based encryption mechanism to ensure that all the data segments of a security-critical application appear in ciphertext in DRAM chip. When an encrypted data page is accessed, it is transparently decrypted to a page in the internal RAM, which is immune to physical exploits. Le Guan, Chen Cao 0004, Peng Liu 0005, Xinyu Xing 0001, Xinyang Ge, Shengzhi Zhang, Meng Yu 0001, Trent Jaeger |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2018 | Running OS Kernel in Separate Domains: A New Architecture for Applications and OS Services QuarantineabstractContainer-based PaaS cloud is ease of use and cost-efficient, but vulnerable to attacks due to the weak isolation provided by the built-in containers. In this paper, we present a lightweight virtualization based kernel decomposition approach to securely isolate cloud tenants as well as the operating system (OS) services against various threats. Our design decouples existing OS kernels based on their functionality and isolates different kernel partitions in separate domains. The kernel partition that enables application execution is quarantined in an application domain, while other partitions that offer various services are isolated in separate service domains. The application owned by one tenant can run transparently in a dedicated application domain, with strong isolation to those owned by other tenants. Furthermore, the kernel partition approach effectively defeats the malware that requires support from different kernel services. We have implemented a prototype based on Linux kernel and Xen hypervisor. Our evaluation demonstrates that the proposed kernel decomposition approach can defeat various OS kernel-targeted attacks with minimal performance overhead. Weijuan Zhang, Xiaoqi Jia, Shengzhi Zhang, Rui Wang 0032, Peng Liu 0005 |
APSEC | 3 |
| 2018 | All Your Alexa Are Belong to Us: A Remote Voice Control Attack against EchoabstractVoice controlled system becomes increasingly popular these days due to the convenient and natural control over lots of functionalities and smart devices. Amazon Echo, designed around Alexa, is capable of controlling smart devices such as locks, sending emails, making phone calls, and even bridging the gap between online services such as Twitter, Facebook, etc. Previously, researchers demonstrated that by carefully crafting obfuscated commands or transmitting commands over ultrasound carrier, voice controlled systems can be compromised without people's awareness. However, those researches require the target voice controlled systems to be close enough to their speaker or ultrasound transducer. In this paper, we proposed REEVE (REmotE VoicE control) attack that can manipulate Amazon Alexa remotely, e.g., via signal broadcasting to compromise radio, TV, speaker, etc. It works on behalf of the attackers to operate various commands beneficial to them. By analyzing more than 15,000 Alexa skills and 600 IFTTT Applets related to Alexa, we found that more than 100 of them can be used to attack Echo. We also thoroughly scrutinized the attack surface of Echo's voice control and conducted security analysis based on different consequences. Xuejing Yuan, Aohui Wang, Kai Chen 0012, Shengzhi Zhang, Heqing Huang 0001, Ian M. Molloy |
GLOBECOM | 5 |
| 2018 | CommanderSong: A Systematic Approach for Practical Adversarial Voice Recognition
Xuejing Yuan, Yue Zhao 0018, Yunhui Long, Kai Chen 0012, Shengzhi Zhang, Heqing Huang 0001, XiaoFeng Wang 0001, Carl A. Gunter |
USENIX Security Symposium | 7 |
| 2018 | A Security Model for Dependable Vehicle Middleware and Mobile Applications ConnectionabstractNowadays automotive industry has been working on the connectivity between automobile and smartphones, e.g., Ford’s SmartDeviceLink, MirrorLink, etc. However, as the interoperability between the sma ... Shengzhi Zhang, Omar Makke, Oleg Yu. Gusikhin, Ayush Shah, Athanasios V. Vasilakos |
VEHITS | 1 |
| 2017 | Towards comprehensive protection for OpenFlow controllersabstractOpenFlow has recently emerged as a powerful paradigm to help build dynamic, adaptive and agile networks. By decoupling control plane from data plane, OpenFlow allows network operators to program a centralized intelligence, OpenFlow controller, to manage network-wide traffic flows to meet the changing needs. However, from the security's point of view, a buggy or even malicious controller could compromise the control logic, and then the entire network. Even worse, the recent attack Stuxnet on industrial control systems also indicates the similar, severe threat to OpenFlow controllers from the commercial operating systems they are running on. In this paper, we comprehensively studied the attack vectors against the OpenFlow critical component, controller, and proposed a cross layer diversity approach that enables OpenFlow controllers to detect attacks, corruptions, failures, and then automatically continue correct execution. Case studies demonstrate that our approach can protect OpenFlow controllers from threats coming from compromised operating systems and themselves. Shengzhi Zhang, Xiaoqi Jia, Weijuan Zhang |
APNOMS | 1 |
| 2017 | TrustShadow: Secure Execution of Unmodified Applications with ARM TrustZoneabstractThe rapid evolution of Internet-of-Things (IoT) technologies has led to an emerging need to make them smarter. A variety of applications now run simultaneously on an ARM-based processor. For example, devices on the edge of the Internet are provided with higher horsepower to be entrusted with storing, processing and analyzing data collected from IoT devices. This significantly improves efficiency and reduces the amount of data that needs to be transported to the cloud for data processing, analysis and storage. However, commodity OSes are prone to compromise. Once they are exploited, attackers can access the data on these devices. Since the data stored and processed on the devices can be sensitive, left untackled, this is particularly disconcerting. In this paper, we propose a new system, TrustShadow that shields legacy applications from untrusted OSes. TrustShadow takes advantage of ARM TrustZone technology and partitions resources into the secure and normal worlds. In the secure world, TrustShadow constructs a trusted execution environment for security-critical applications. This trusted environment is maintained by a lightweight runtime system that coordinates the communication between applications and the ordinary OS running in the normal world. The runtime system does not provide system services itself. Rather, it forwards requests for system services to the ordinary OS, and verifies the correctness of the responses. To demonstrate the efficiency of this design, we prototyped TrustShadow on a real chip board with ARM TrustZone support, and evaluated its performance using both microbenchmarks and real-world applications. We showed TrustShadow introduces only negligible overhead to real-world applications. Le Guan, Peng Liu 0005, Xinyu Xing 0001, Xinyang Ge, Shengzhi Zhang, Meng Yu 0001, Trent Jaeger |
MobiSys | 5 |
| 2016 | A Comprehensive Study of Co-residence Threat in Multi-tenant Public PaaS Clouds
Weijuan Zhang, Xiaoqi Jia, Shengzhi Zhang, Qingjia Huang, Mingsheng Wang, Peng Liu 0005 |
ICICS | 4 |
| 2016 | Towards service continuity for transactional applications via diverse device driversabstractExisting techniques, such as state roll-back or replay can preserve as much accumulated 'state' as possible when one application is compromised. However, when operating system kernel is compromised, e.g., driver vulnerability exploitation, the default behaviour of most commodity operating systems today is to reboot from a clean initial state. All the running applications also need to be terminated and restarted, thus losing their accumulated 'work in progress' states. In this paper, we propose to leverage virtualisation technique to produce operating system replicas with driver diversity. By replicating transactional application on each replica and loosely synchronising them, we validate the output, critical memory regions and persistent data of transactional applications, thus detecting intrusion stemming from driver code vulnerability. We implement such diversity approach on Xen hypervisor, and rely on a proxy to conduct request replication and response validation. Our evaluation demonstrates that the proposed approach can accurately and immediately detect driver-bug-orientated exploitation and achieve on-the-fly intrusion response to ensure the correctness/continuity of the applications' execution. We only incur 4.44% and 4.7% overhead to response time and CPU respectively in the best case. Shengzhi Zhang, Xiaoqi Jia, Peng Liu 0005 |
Int. J. Inf. Comput. Secur. | 1 |
| 2015 | Comprehensive Analysis of the Android Google Play's Auto-update Policy
Craig Sanders, Ayush Shah, Shengzhi Zhang |
ISPEC | 3 |
| 2015 | A Study of Network Domains Used in Android Applications
Mark E. Fioravanti II, Ayush Shah, Shengzhi Zhang |
NSS | 3 |
| 2013 | Towards transparent and distributed workload management for large scale web servers
Shengzhi Zhang, Haishan Wu, Athanasios V. Vasilakos, Peng Liu 0005 |
Future Gener. Comput. Syst. | 1 |
| 2013 | Defending return-oriented programming based on virtualization techniquesabstractABSTRACT Over the past few years, return‐oriented programming (ROP) has drawn great attention of both academia and industry. Because of its Turing completeness, ROP reuses short instruction sequences already present in the victim program's address space to perform arbitrary computation. Hence, it can successfully bypass state‐of‐the‐art code integrity check mechanisms. In this paper, we look into using virtualization technologies to defeat return‐oriented programming. We design and implement HyperCropII, a virtualization‐based automatic runtime approach to defend such attacks. ROP attackers extract short instruction sequences ending in ret called “gadgets” and craft stack content to “chain” these gadgets together. We observe that a key characteristic of ROP is to fill the stack with plenty of addresses that are within the range of the program's libraries. Accordingly, we inspect the content of the stack to see if a potential ROP attack exists and quarantine the damages for further security purposes. We have implemented a proof‐of‐concept system based on the open source Xen hypervisor. The evaluation results exhibit that our solution is effective and efficient. Copyright © 2013 John Wiley & Sons, Ltd. Xiaoqi Jia, Rui Wang 0032, Shengzhi Zhang, Peng Liu 0005 |
Secur. Commun. Networks | 4 |
| 2012 | Letting applications operate through attacks launched from compromised driversabstractWith the rapid prevalence of E-Commerce, MMO and social networking, the demand on service availability and continuity is increasingly crucial to production servers or data centers. Hence, software failure recovery systems are thoroughly studied. However, stimulated by significant commercial revenue, attackers begin trying to evade the existing auditing/recovering techniques by manipulating the service applications through the compromised kernel. Nowadays, device drivers account for more than half (could be as high as 70%) of the source code of most commodity operating system kernels, with much more exploitable vulnerabilities than other kernel code [2]. This renders the attackers the opportunity to exploit the driver vulnerability and leverage the kernel privilege of the compromised drivers. With the unrestricted access to the whole (kernel/user) memory address space, successful attackers can launch denial of service attack by incurring driver fault, manipulating critical code/data or even the metadata of the service application process. Shengzhi Zhang, Peng Liu 0005 |
AsiaCCS | 1 |
| 2012 | Assessing the Trustworthiness of Drivers
Shengzhi Zhang, Peng Liu 0005 |
RAID | 1 |
| 2012 | Hidden node collision recovery protocol for low rate wireless personal area networksabstractABSTRACT Referring to most media access control (MAC) protocols in low rate personal area networks (LR‐WPANs), there is no hidden node collision avoidance mechanism utilized. Quantitative analysis in this paper based on the IEEE 802.15.4 specification shows a high probability of the continuous hidden node collisions (CHNCs), which seriously decreases network throughput. Based on this observation, we propose a cost‐efficient recovery mechanism to achieve fast self‐healing when LR‐WPANs suffer CHNCs, while introducing no overhead when there are no collisions. Simulation results demonstrate the efficiency of our proposed protocol in terms of network throughput and power saving. Copyright © 2011 John Wiley & Sons, Ltd. Shengzhi Zhang, Sang-Jo Yoo |
Wirel. Commun. Mob. Comput. | 1 |
| 2011 | Distributed workload and response time management for web applications
Shengzhi Zhang, Haishan Wu, Bo Yang 0013, Peng Liu 0005, Athanasios V. Vasilakos |
CNSM | 1 |
| 2011 | LeakProber: a framework for profiling sensitive data leakage pathsabstractIn this paper, we present the design, implementation, and evaluation of LeakProber, a framework that leverages the whole system dynamic instrumentation and the inter-procedural analysis to enable data propagation path profiling in production system. We integrate both the static analysis and runtime tracking to establish a holistic and practical approach to generating the sensitive data propagation graph (sDPG) with minimum runtime overhead. We evaluate our system on several data stealing attacks scenario for generating sDPG. The sDPG generated by our system captures multiple aspects of data accessing patterns and provides clear insights into the data leakage path. We also measure the performance of our system and find that it degrades the production system about 6% in the trace-on mode. When our prototype works in the trace-off mode, the runtime overhead is even lower, on an average of 1.5% across each benchmark we run. We believe that it is feasible to directly apply our prototype into production system environment. Junfeng Yu, Shengzhi Zhang, Peng Liu 0005, Zhitang Li |
CODASPY | 2 |
| 2011 | HyperCrop: A Hypervisor-Based Countermeasure for Return Oriented Programming
Xiaoqi Jia, Dengguo Feng, Shengzhi Zhang, Peng Liu 0005 |
ICICS | 4 |
| 2011 | PEDA: Comprehensive Damage Assessment for Production Environment Server SystemsabstractAnalyzing the intrusion to production servers is an onerous and error-prone work for system security technicians. Existing tools or techniques are quite limited. For instance, system events tracking lacks completeness of intrusion propagation, while dynamic taint tracking is not feasible to be deployed due to significant runtime overhead. Thus, we propose production environment damage assessment (PEDA), a systematic approach to do postmortem intrusion analysis for production workload servers. PEDA replays the “has-been-infected” execution with high fidelity on a separate analyzing instrumentation platform to conduct the heavy workload analysis. Though the replayed execution runs atop the instrumentation platform (i.e., binary-translation-based virtual machine), PEDA allows the first-run execution to run atop the hardware-assisted virtual machine to ensure minimum runtime overhead. Our evaluation demonstrates the efficiency of the PEDA system with a runtime overhead as low as 5%. The real-life intrusion studies show the advantage of PEDA intrusion analysis over existing techniques. Shengzhi Zhang, Xiaoqi Jia, Peng Liu 0005, Jiwu Jing |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2010 | Cross-layer comprehensive intrusion harm analysis for production workload server systemsabstractAnalyzing the (harm of) intrusion to enterprise servers is an onerous and error-prone work. Though dynamic taint tracking enables automatic fine-grained intrusion harm analysis for enterprise servers, the significant runtime overhead introduced is generally intolerable in the production workload environment. Thus, we propose PEDA (Production Environment Damage Analysis) system, which decouples the onerous analysis work from the online execution of the production servers. Once compromised, the "has-been-infected" execution is analyzed during high fidelity replay on a separate instrumentation platform. The replay is implemented based on the heterogeneous virtual machine migration. The servers' online execution runs atop fast hardware-assisted virtual machines (such as Xen for near native speed), while the infected execution is replayed atop binary instrumentation virtual machines (such as Qemu for the implementation of taint analysis). From identified intrusion symptoms, PEDA is capable of locating the fine-grained taint seed by integrating the backward system call dependency tracking and one-step-forward taint information flow auditing. Started with the fine-grained taint seed, PEDA applies dynamic taint analysis during the replayed execution. Evaluation demonstrates the efficiency of PEDA system with runtime overhead as low as 5%. The real-life intrusion studies successfully show the comprehensiveness and the precision of PEDA's intrusion harm analysis. Shengzhi Zhang, Xiaoqi Jia, Peng Liu 0005, Jiwu Jing |
ACSAC | 1 |