Shiwen Wang 0002

dblp:69/9291-2 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
4since 2021 · last 2026
0009-0007-7500-2018ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 4 · 1 first-author · 4 since 2021
YearPublicationVenuePosition
2026 NXT: Sharable Trusted Execution Environment for Multi-Tenant NPU Cluster
abstract
Cloud AI services have experienced rapid development, raising concerns to privacy protection of cloud tenants. Many proposals have been made to use the NPU Trusted Execution Environment (TEE) to protect AI workloads on the cloud. However, existing designs typically bind NPUs exclusively to a single tenant, preventing multiple tenants from sharing the computing power of the TEE-NPUs.As such, we have designed a novel TEE for discrete NPUs, named NXT (NPU eXtension for Trust), which breaks the exclusive binding architecture and allows multiple tenants to securely share the TEE-NPU cluster. Firstly, we introduced an NPU Trusted Agent (NTA) to the most privileged level of the TEE system to assist in the global scheduling of the TEE-NPU cluster. Secondly, we implemented a flexible isolation mechanism to provide security for multi-tenant fine-grained sharing of NPU resources. Thirdly, we support efficient communication between workloads within TEE-NPUs and with legacy NPUs, accelerating multi-workload collaborative computing. We evaluated NXT by extending gem5 and a cycle-accurate NPU simulator to build a prototype. Results show that NXT improves overall utilization by up to 3.49× and ANTT by up to 7.24×, with only 6.38% average overhead for scheduling and isolation. It also boosts parallel inference performance by 58.3% for GPT-2(XL) and 63.6% for LLaMA-13B compared to static protection schemes.
Shiwen Wang 0002, Peinan Li, Yunkai Bai, Wu Luo, Guang Yan, Dan Meng 0002, Rui Hou 0001
IEEE Trans. Computers1
2025 Tips: Augment Memory Tagging to Defend Against Prefetcher Side Channels
abstract
Hardware prefetchers are essential for hiding memory latency and improving performance in commercial processors. However, recent studies have revealed that they can be exploited to launch side-channel attacks that leak sensitive data, recover cryptographic keys, and break the isolation of trusted execution environments. We observe that such attacks closely resemble classic memory safety violations, including buffer overflows, type confusion, use-after-free, and data race. This paper presents TIPS (Tag AugmentatIon for Prefetcher Security), a lightweight extension to the memory safety mechanisms already deployed in commercial processors. TIPS enhances memory tagging to protect prefetchers by enforcing tag-based array bounds, validating pointer types, associating prefetch patterns with their source threads or cores, and suppressing contentionbased interference. Experiments demonstrate that TIPS incurs less than 1.50 % performance overhead and 0.81 % area cost, while providing strong defense against a broad class of prefetcher side-channel attacks.
Yubiao Huang, Peinan Li, Huan Qiao, Yunkai Bai, Shiwen Wang 0002, Dan Meng 0002, Rui Hou 0001
ICCD5
2024 SecPaging: Secure Enclave Paging with Hardware-Enforced Protection against Controlled-Channel Attacks
abstract
As a prevalent privacy-preserving technology, Trusted Execution Environment has become widely adopted in numerous commercial processors. Nonetheless, they remain susceptible to various controlled-channel attacks. Untrusted operating systems can deduce enclave secrets by manipulating page tables or observing allocation- or swap-based page faults. In this paper, we propose SecPaging, a novel secure enclave paging mechanism based on hardware-enforced and microcode-supported protection to prevent these attacks. First, enclave PTEs are protected through hardware isolation, preventing privileged attackers from malicious tampering or observations. Second, an Eager-Allocation mechanism is employed to prevent allocation-based controlled-channel attacks. Besides, a Record-Reload mechanism is proposed to prevent swap-based controlled-channel attacks. We simulate SecPaging on real SGX. Experiments demonstrate that controlled channel attacks can be defended with minimal performance overhead.
Yunkai Bai, Peinan Li, Yubiao Huang, Shiwen Wang 0002, Xingbin Wang, Dan Meng 0002, Rui Hou 0001
DAC4
2024 EnTurbo: Accelerate Confidential Serverless Computing via Parallelizing Enclave Startup Procedure
abstract
Serverless computing has gained widespread attention, and Trusted Execution Environments (TEEs) are well-suited for safeguarding user privacy. However, the additional startup procedure introduced by TEEs imposes considerable performance overhead on confidential serverless workloads. This paper introduces a novel parallelized enclave startup design, EnTurbo, which eliminates the integrity dependence of the enclave startup procedure, accelerating it while ensuring its security. Additionally, EnTurbo parallelizes the measurement procedure, enabling multi-thread measurement for acceleration with provable security. We evaluate EnTurbo by running confidential serverless workloads on SGX simulation mode. Results show that EnTurbo effectively speeds up enclave serverless by 1.42x-6.48x (SGXv1) and 1.33x-3.76x (SGXv2).
Yifan Zhu 0008, Peinan Li, Yunkai Bai, Yubiao Huang, Shiwen Wang 0002, Xingbin Wang, Dan Meng 0002, Rui Hou 0001
DAC5