Shengjie Xu 0001

dblp:69/9079-1 · DBLP profile ↗
← Back
6ranked-venue papers
4as first author
6since 2021 · last 2025
0000-0001-5189-7610ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 PSan: Towards Hybrid Metadata Scheme for Efficient Pointer Checking
abstract
Memory safety remains at risk for programs written in unsafe languages like C. Pointer-checking schemes provide memory safety protection by attaching metadata for each pointer and checking them before dereference. Previously, sanitizers maintaining large per-pointer metadata (e.g., pointer bounds) were stuck with shadow memory for metadata storage, which incurs high overhead. Although fat pointers (i.e., instrumenting programs to inline metadata with pointers) incur less overhead, they introduce incompatibility issues to the instrumented programs, and are thus not considered by software-only sanitizers yet. In this paper, we push the status quo on adopting fat pointers for software-only pointer checking schemes and evaluate the benefit of this approach. We present PSan (short for “Pointer Sanitizer”), the first memory safety sanitizer that enables both inline and shadow memory metadata simultaneously in the same program. To reduce the overhead from shadow memory, PSan uses whole-program analysis and transformation to inline the metadata whenever possible, while using shadow memory only when necessary for compatibility. PSan-instrumented programs preserve binary compatibility with third-party uninstrumented code. In addition, PSan's framework decouples metadata management from checking, facilitating its augmentation with additional checkers. We evaluate the benefit of metadata inlining and observe that PSan's hybrid scheme reduces the runtime and memory overhead. Specifically, PSan incurs 40% lower overhead than popular memory checker SoftBoundCETS, which utilizes only shadow memory. Predictably, using inline metadata has a higher performance improvement when it can be applied to the majority of pointers in the program.
Shengjie Xu 0001, Eric Liu 0001, Wei Huang 0027, Ilya Grishchenko, David Lie
ACSAC1
2024 PrepPipe: Prototyping Compiler for Attainable Visual Novel Development
abstract
Visual novels are a low-cost storytelling genre in gaming. They can be developed by small teams or individuals within weeks or months. Despite their simplicity relative to other game categories, challenges persist that trap amateurs and lead to inefficiencies or even project failures. PrepPipe project seeks to accelerate visual novel prototyping, shorten development time, and reduce effort wasted due to planning errors. Our project includes a prototyping compiler that transforms story scripts and assets into game project files, supplemented by auxiliary tools and asset templates. Key features of the compiler include rich-text input handling, support for a user-guided incremental refinement process, and leniency towards erroneous inputs. We aim to make visual novel development more attainable and enjoyable for a wider audience.
Shengjie Xu 0001
CoG1
2023 FLUX: Finding Bugs with LLVM IR Based Unit Test Crossovers
abstract
Optimizing compilers are as ubiquitous as they are crucial to software development. However, bugs in compilers are not uncommon. Among the most serious are bugs in compiler optimizations, which can cause unexpected behavior in compiled binaries. Existing approaches for detecting such bugs have focused on end-to-end compiler fuzzing, which limits their ability for targeted exploration of a compiler's optimizations. This paper proposes FLUX (Finding bugs with LLVM IR based Unit test cross(X)overs), a fuzzer that is designed to generate test cases that stress compiler optimizations. Previous compiler fuzzers are overly constrained by having to construct well-formed inputs. FLUX sidesteps this constraint by using human-written unit test suites as a starting point, and then selecting random combinations of them to generate new tests. We hypothesize that tests generated this way will be able to explore new execution paths through compiler optimizations and find new bugs. Our evaluation of FLUX on LLVM indicates that it is able to increase path coverage over the baseline LLVM unit test suite and explores more edge coverage than previous work. Further, we demonstrate FLUX's ability to generate miscompiled and crash-producing IR on LLVM's optimizations. After a month of fuzzing, FLUX found 28 unique bugs in LLVM's active development branch. We have reported 11 of these bugs which led to 6 of them being patched by LLVM developers. 22 of these are crashes that are triggered by well-formed input programs, and 6 of these are miscompilation bugs that silently produced incorrect code.
Eric Liu 0001, Shengjie Xu 0001, David Lie
ASE2
2023 MIFP: Selective Fat-Pointer Bounds Compression for Accurate Bounds Checking
abstract
Bounds compression for fat pointers can reduce the memory and performance overhead of maintaining pointer bounds and is necessary for efficient hardware implementation. However, compression can introduce inaccuracy to the bounds, making certain out-of-bounds accesses undetectable. Although the security threat can be mitigated by padding the objects, no known mitigations can detect these out-of-bounds accesses deterministically.
Shengjie Xu 0001, Eric Liu 0001, Wei Huang 0027, David Lie
RAID1
2021 In-fat pointer: hardware-assisted tagged-pointer spatial memory safety defense with subobject granularity protection
abstract
Programming languages like C and C++ are not memory-safe because they provide programmers with low-level pointer manipulation primitives. The incorrect use of these primitives can result in bugs and security vulnerabilities: for example, spatial memory safety errors can be caused by dereferencing pointers outside the legitimate address range belonging to the corresponding object. While a range of schemes to provide protection against these vulnerabilities have been proposed, they all suffer from the lack of one or more of low performance overhead, compatibility with legacy code, or comprehensive protection for all objects and subobjects.
Shengjie Xu 0001, Wei Huang 0027, David Lie
ASPLOS1
2021 Aion Attacks: Manipulating Software Timers in Trusted Execution Environment
Wei Huang 0027, Shengjie Xu 0001, Yueqiang Cheng, David Lie
DIMVA2