EDBT 2026 Demo / reviewers in the wild / expert
Lei Zhou 0023
dblp:72/5749-23
· DBLP profile ↗
17ranked-venue papers
6as first author
15since 2021 · last 2025
0000-0002-5027-1234ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 5 first-author · 9 since 2021Systems, architecture and hardware · 3 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SimFuzz: Conflict-Aware Parallel Fuzzing via Incremental Path Similarity ClusteringabstractParallel fuzzing boosts throughput by distributing testcase generation across multiple fuzzing instances. However, this architecture often suffers from task conflict—redundant exploration of similar execution paths—due to the lack of path-level awareness in seed scheduling. These conflicts waste computation and limit overall effectiveness.We present SIMFUZZ, a conflict-aware scheduling framework that mitigates redundancy by integrating path similarity into the fuzzing workflow. SIMFUZZ encodes seeds as branch-level coverage bitmaps and incrementally clusters them based on execution path overlap. It then applies a two-stage scheduling policy that assigns similar seeds to the same instance, while preserving global prioritization for high-potential inputs.We evaluate SIMFUZZ on 19 real-world programs and benchmark targets. Compared to a state-of-the-art baseline, it achieves a 6.7% average increase in branch coverage and reduces task conflict by 3.9%. In several cases, it also discovers substantially more unique crashes. Additionally, SIMFUZZ has uncovered 15 previously unknown vulnerabilities in widely used software projects, all of which have been assigned CVE identifiers. Xuan Meng, Danjun Liu, Xu Zhou 0004, Peihong Lin, Chenyifan Liu, Lei Zhou 0023, Wei Xie 0007 |
ISSRE | 6 |
| 2025 | SyzOrch: An Orchestration Framework for Resource-Aware and Composable Kernel FuzzingabstractKernel fuzzing plays a critical role in uncovering vulnerabilities, reproducing bugs, and testing patches in operating systems. While integrating external resources such as symbolic execution engines, static analyzers, and language models has proven effective in areas such as enhancing path exploration, optimizing seed generation, and improving seed mutation, existing approaches remain tightly coupled and task-specific, hindering the reuse, migration, scheduling, and composition of these external resources. This limitation further restricts the ability of researchers to explore flexible hybrid fuzzing strategies and hinders industry efforts to build stronger and more adaptable kernel fuzzers. We present SyzOrch to address this limitation. SyzOrch (1) decouples the kernel fuzzing workflow; (2) provides event-driven coordination between external resources and the fuzzer; (3) abstracts heterogeneous external resources through a generalized behavior model; and (4) supports user-defined dynamic control via a programmable DSL runner. We evaluate SyzOrch across diverse kernel fuzzing scenarios and show that it achieves a 30% speedup of directed kernel fuzzing by migrating existing techniques, improves coverage by 8.6% through hybrid composition with multiple external resources, and discovers previously unknown kernel bugs, including one assigned a CNNVD identifier. These results demonstrate SyzOrch’s effectiveness in orchestrating external resources to enhance kernel fuzzing. Lukai Xu, Bo Yu 0008, Boyu Chang, Shouling Ji, Danjun Liu, Lei Zhou 0023, Yaojia Yang |
ISSRE | 8 |
| 2025 | XGT: Fast and Secure Decision Tree Training and Inference on GPUsabstractThe decision tree (DT) model is widely usedin various applications due to its versatility, speed, and interpretability. However, outsourcing DT training and inference to cloud platforms raises data privacy concerns. While significant strides have been made in developing private DT training and inference using cryptography such as Secure Multi-Party Computation (MPC), the performance is still not ideal in real-world applications. Only a few recent works have explored using GPUs to enhance the performance of MPC-based deep learning. Nevertheless, data-dependent operations and the high communication costs inherent in MPC-based DT make the integration of GPUs a challenge. We introduce the eXpress GPU-based Tree (XGT), a fast MPC-based framework for private DT training and inference on GPUs.XGTconverts the majority of operations in training and inference into parallelizable matrix operations, supplemented by various optimizations, including matrix dimension reductions. This innovative design leads to substantial reductions in communication overhead while maintaining the critical property of obliviousness.XGTalso achieves a stronger security guarantee, where all data items, the tree shape, access patterns, and data distributions generated during the training and inference are protected.XGTonly reveals the tree depth. The experimental results show thatXGTis up to$278{\times }$faster than the previous most efficient CPU-based approach.XGToutperforms the latest GPU-based DT work by$41{\times }$. For inference,XGTis up to$2,800{\times }$faster than previous CPU-based inference schemes and at least$18 \times$faster than GPU-based. Qifan Wang 0003, Shujie Cui, Lei Zhou 0023, Ye Dong, Jianli Bai, Yun Sing Koh, Giovanni Russello |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Efficient Forward-Edge Control-Flow Integrity for COTS Binaries via Arm BTIabstractControl-Flow Integrity (CFI) has been widely recognized as an effective technique for mitigating control-flow hijacking attacks. However, many binary-level CFI approaches suffer from weaknesses in safeguarding forward edges, particularly for the obfuscated binaries, due to the imprecision in binary analysis or heuristic algorithms. Moreover, these approaches often involve non-negligible overhead and are challenging to deploy, as they instrument plenty of code or employ hardware tracing to enforce the CFI policies. This paper introduces Mobius, the first complete implementation of security-instruction-based binary-only CFI solution on commercial processors. Mobius leverages the Branch Target Identification (BTI) technology in Arm v8.5 to safeguard the forward edges of binaries and shared libraries efficiently. It determines the forward-edge targets without false negatives and carefully instruments the bti instructions to conduct the CFI checking efficiently. Then, it mounts a runtime monitor to detect potential attacks. We deploy Mobius on an Alibaba Cloud server with Yitian 710 processors in practice without modifying the kernel or loader. Remarkably, Mobius successfully provides efficient protection for real-world applications, including obfuscated code, with marginal overhead (5.78% on SPEC2006). Tai Yue, Kai Lu 0001, Zhenyu Ning, Pengfei Wang 0010, Lei Zhou 0023, Xu Zhou 0004, Fengwei Zhang, Gen Zhang |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Speed is Not All You Need When Fuzzing Stateful Network ServersabstractCurrent network protocol fuzzing is an efficient mechanism for uncovering protocol vulnerabilities, yet it faces several challenges. For instance, bugs in stateful protocols can significantly hinder the generation of effective fuzzing testcases. Additionally, factors such as network transmission and session synchronization can lead to substantial delays in the fuzzing process. However, we have observed a common phenomenon that existing fuzzing techniques often focus on optimizing either execution speed or state inference, but not both, which limits their overall effectiveness in analyzing protocol defects. We verify such a common issue by experimental analysis and seek to understand the specific reasons behind this. Then, we design an enhanced network protocol fuzzer that harnesses shared memory-based message transmission and session state synchronization to alleviate the heavy post-execution analysis in StateAFL state inference, named S2fuzzer, to optimize both speed and state inference simultaneously. Our experiments reveal that S2fuzzer enhances execution speed by 4.7x compared to StateAFL. Simultaneously, we find that S2Fuzzer can infer a more comprehensive state model. This leads to a 9.38% increase in code coverage and 371 additional crashes (1.42x) compared to StateAFL across tested programs. This state inference amplification, which has not been discovered in previous research, allows S2fuzzer to reach nearly equivalent coverage and superior bug finding ability, even if its execution speed is merely 1/10 of HNPFuzzer, the latest speedup scheme. Lei Zhou 0023, Xu Zhou 0004, Danjun Liu |
HPCC | 2 |
| 2024 | SSFuzz: State Sensitive Fuzzing for Network Protocol ImplementationsabstractProtocol implementations are stateful and reactive systems, where the protocol process communicates with the client through a session. Complex state changes of implementations limit the efficiency of fuzzing. Current methods typically send a mutated message sequence to the protocol implementation, then terminate the session and evaluate the message sequence based on the feedback. We observe the following issues: (1) The state changes of the protocol implementation are random because of mutated messages, and message schedule methods that do not consider the real-time state of the target are blind; (2) The value of a message can vary significantly in different states, making seeds value evaluation method based on the entire message sequence insufficiently precise. (3) Existing fuzzing approaches actively terminate sessions after a test, resulting in resource wastage.To solve these problem, we propose SSFuzz, a state sensitive fuzzing approach for protocol implementations. First, it monitors the state transitions and path feedback of the protocol implementation in real-time. Second, it dynamically schedules messages based on real-time state transitions during testing. According to the state transitions and path feedback after processing a message, it then conducts more precise evaluation of the messages. Last, we achieve testing multiple states within one session by reusing session. We believe that our approach better adapts to the characteristics of protocol implementations. We validated our approach on 9 widely used protocol implementations from ProFuzzBench. Compared to the state-of-the-art network protocol greybox fuzzing tool AFLnet, SSFuzz can increase discovered branch coverage on average 1.31% and discovers 25.28% more unique crashes within 24 hours. Chengnuo Cai, Lei Zhou 0023, Bo Yu 0008 |
ISPA | 2 |
| 2024 | FortifyPatch: Towards Tamper-Resistant Live Patching in Linux-Based HypervisorabstractLinux-based hypervisors in the cloud server suffer from an increasing number of vulnerabilities in the Linux kernel.To address these vulnerabilities in a timely manner while avoiding the economic loss caused by unplanned shutdowns, live patching schemes have been developed. Unfortunately, existing live patching solutions have failed to protect patches from post-deployment attacks. In addition, patches that involve changes to global variables can lead to practical issues with existing solutions. To address these problems, we present FortifyPatch, a tamper-resistant live patching solution for Linux-based hypervisors in cloud environments. Specifically, FortifyPatch employs multiple Granule Protection Tables from Arm Confidential Computing Architecture to protect the integrity of deployed patches. TrustZone Address Space Controller and Performance Monitor Unit are used to prevent the bypassing of the Patch via kernel code protection and timely page table verification. FortifyPatch is also able to patch global variables via well-designed data access traps.We prototype FortifyPatch and evaluate it using real-world CVE patches. The result shows that FortifyPatch is capable of deploying 81.5% of CVE patches. The performance evaluation indicates that FortifyPatch protects deployed patches with 0.98% and 3.1% overhead on average across indicative benchmarks and real-world applications, respectively. Zhenyu Ye, Lei Zhou 0023, Fengwei Zhang, Wenqiang Jin, Zhenyu Ning, Yupeng Hu 0004, Zheng Qin 0001 |
ISSTA | 2 |
| 2024 | GTree: GPU-friendly Privacy-preserving Decision Tree Training and InferenceabstractOutsourcing Decision tree (DT) training and inference to cloud platforms raises privacy concerns. Recent Secure Multi-Party Computation (MPC)-based methods are hindered by heavy overhead. Few recent studies explored GPUs to improve MPC-protected deep learning, yet integrating GPUs into MPC-protected DT with massive data-dependent operations remains challenging, raising question: can MPC-protected DT training and inference fully leverage GPUs for optimal performance?We present GTree, the first scheme that exploits GPU to accelerate MPC-protected secure DT training and inference. GTree is built across 3 parties who jointly perform DT training and inference with GPUs. GTree is secure against semi-honest adversaries, ensuring that no sensitive information is disclosed. GTree offers enhanced security than prior solutions, which only reveal tree depth and data size while prior solutions also leak tree structure. With our oblivious array access, access patterns on GPU are also protected. To harness the full potential of GPUs, we design a novel tree encoding method and craft our MPC protocols into GPU-friendly versions. GTree achieves ~11× and ~21× improvements in training SPECT and Adult datasets, compared to prior most efficient CPU-based work. For inference, GTree outperforms the prior most efficient work by 126× when inferring 104instances with a 7-level tree. Qifan Wang 0003, Shujie Cui, Lei Zhou 0023, Ye Dong, Jianli Bai, Yun Sing Koh, Giovanni Russello |
TrustCom | 3 |
| 2024 | Hardware-Assisted Live Kernel Function Updating on Intel PlatformsabstractTraditional kernel updates such as perfective maintenance and vulnerability patching requires shutting the system down, disrupting continuous execution of applications. Enterprises and researchers have proposed various live updating techniques to patch the kernel with lower downtime to reduce the loss of useful uptime. However, existing kernel live update techniques either rely on specific support from the target OS, or are deployed in virtualized environments (i.e., systems running in virtual machines). In this paper we presentKShot, a hardware-assisted live and secure kernel function update mechanism for native operating systems. By leveraging x86 SMM and Intel SGX,KShotruns in hardware-assisted Trusted Execution Environments and updates kernel functions at the binary-level without relying on the underlying OS support. We demonstrate the applicability ofKShotby successfully patching critical kernel vulnerabilities, upgrading base kernel functions and drivers nearly instantly and transparently. Our experimental results show thatKShotincurs merely 70 microseconds downtime to update a one kilobyte binary and 18 MB memory overhead. Lei Zhou 0023, Fengwei Zhang, Kevin Leach, Xuhua Ding, Zhenyu Ning, Guojun Wang 0001, Jidong Xiao |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Armor: Protecting Software Against Hardware Tracing TechniquesabstractMany modern processors have embedded hardware tracing techniques (e.g., Intel Processor Trace or ARM CoreSight). While these techniques are widely used due to their transparency and low overhead, they also bring serious security threats. Attackers can utilize hardware tracing to trace the trusted applications from a non-secure application. Existing protection techniques fail to effectively protect the runtime information when hardware tracing is employed. To counter these threats, in this paper, we propose a novel direction called anti-hardware tracing. Our key idea is to exploit the limitations of hardware tracing: trace buffer overflow can cause trace data loss. We build a model to analyse the overflow and outline three principles for efficient triggering overflows and achieving anti-hardware tracing: numerous branches in the program, high-speed execution of the program, and the high-water mark of the trace buffer. We develop a framework called Armor on ARM Juno R2 to realize our approach. Armor protects software against the trace unit Embedded Trace Macrocell (ETM) in CoreSight by instrumenting protection and loop functions. The protection function detects runtime environments, efficiently fills the trace buffer, and employs various protection strategies like PID (process identifier) replacement and PIE+STRIP+ASLR. Meanwhile, the loop function triggers overflows efficiently based on context-based calculations and anti-ETM loop. Our evaluation demonstrates that the overhead of Armor is 77.31% lower than that of OLLVM [1] on SPEC2006. Armor effectively hides 54.51% of basic blocks across 16 real-world applications, triggering 113× more overflows. Moreover, we showcase two practical applications of Armor. Firstly, we conduct a cryptographic and cross-world attack on GnuPG 1.4.13 RSA private keys using ETM, which can steal entire keys from a program in the Secure world with a single run. Armor successfully reduces leaked bits by 84.5%. Secondly, Armor impedes hardware-assisted fuzzing by reducing throughput by 89.71% and branch coverage by 47.99%. Tai Yue, Fengwei Zhang, Zhenyu Ning, Pengfei Wang 0010, Xu Zhou 0004, Kai Lu 0001, Lei Zhou 0023 |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2023 | HT2ML: An efficient hybrid framework for privacy-preserving Machine Learning using HE and TEEabstractOutsourcing Machine Learning (ML) tasks to cloud servers is a cost-effective solution when dealing with distributed data. However, outsourcing these tasks to cloud servers could lead to data breaches. Secure computing methods, such as Homomorphic Encryption (HE) and Trusted Execution Environments (TEE), have been used to protect outsourced data. Nevertheless, HE remains inefficient in processing complicated functions (e.g., non-linear functions) and TEE (e.g., Intel SGX) is not ideal for directly processing ML tasks due to side-channel attacks and parallel-unfriendly computation. In this paper, we propose a hybrid framework integrating SGX and HE, called HT2ML, to protect user's data and models. In HT2ML, HE-friendly functions are protected with HE and performed outside the enclave, while the remaining operations are performed inside the enclave obliviously. HT2ML leverages optimised HE matrix multiplications to accelerate HE computations outside the enclave while using oblivious blocks inside the enclave to prevent access-pattern-based attacks. We evaluate HT2ML using Linear Regression (LR) training and Convolutional Neural Network (CNN) inference as two instantiations. The performance results show that HT2ML is up to ∼11× faster than HE only baseline with 6-dimensional data in LR training. For CNN inference, HT2ML is ∼196× faster than the most recent approach (Xiao et al., ICDCS'21). Qifan Wang 0003, Lei Zhou 0023, Jianli Bai, Yun Sing Koh, Shujie Cui, Giovanni Russello |
Comput. Secur. | 2 |
| 2022 | EnclaveTree: Privacy-preserving Data Stream Training and Inference Using TEEabstractThe classification service over a stream of data is becoming an important offering for cloud providers, but users may encounter obstacles in providing sensitive data due to privacy concerns. While Trusted Execution Environments (TEEs) are promising solutions for protecting private data, they remain vulnerable to side-channel attacks induced by data-dependent access patterns. We propose a Privacy-preserving Data Stream Training and Inference scheme, called EnclaveTree, that provides confidentiality for user's data and the target models against a compromised cloud service provider. We design a matrix-based training and inference procedure to train the Hoeffding Tree (HT) model and perform inference with the trained model inside the trusted area of TEEs, which provably prevent the exploitation of access-pattern-based attacks. The performance evaluation shows that EnclaveTree is practical for processing the data streams with small or medium number of features. When there are less than 63 binary features,EnclaveTree is up to ~10x and ~9 faster than naïve oblivious solution on training and inference, respectively. Qifan Wang 0003, Shujie Cui, Lei Zhou 0023, Ocean Wu, Yonghua Zhu, Giovanni Russello |
AsiaCCS | 3 |
| 2022 | Smile: Secure Memory Introspection for Live EnclaveabstractSGX enclaves prevent external software from accessing their memory. This feature conflicts with legitimate needs for enclave memory introspection, e.g., runtime stack collection on an enclave under a return-oriented-programming attack. We propose SMILE for enclave owners to acquire live enclave contents with the assistance of a semi-trusted agent installed by the host platform’s vendor as a plug-in of the System Management Interrupt handler. SMILE authenticates the enclave under introspection without trusting the kernel nor depending on the SGX attestation facility. SMILE is enclave security preserving as breaking of SMILE does not undermine enclave security. It allows a cloud server to provide the enclave introspection service. We have implemented a SMILE prototype and run various experiments to read enclave code, heap, stack and SSA frames. The total cost for introspecting one page is less than 300 microseconds. Lei Zhou 0023, Xuhua Ding, Fengwei Zhang |
SP | 1 |
| 2021 | Secure fine-grained friend-making scheme based on hierarchical management in mobile social networks
Lei Zhou 0023, Guojun Wang 0001, Shui Yu 0001 |
Inf. Sci. | 1 |
| 2021 | A Coprocessor-Based Introspection Framework Via Intel Management EngineabstractDuring the past decade, virtualization-based (e.g., virtual machine introspection) and hardware-assisted approaches (e.g., x86 SMM and ARM TrustZone) have been used to defend against low-level malware such as rootkits. However, these approaches either require a large Trusted Computing Base (TCB) or they must share CPU time with the operating system, disrupting normal execution. In this article, we propose an introspection framework called Nighthawk that transparently checks system integrity and monitor the runtime state of target system. Nighthawk leverages the Intel Management Engine (IME), a co-processor that runs in isolation from the main CPU. By using the IME, our approach has a minimal TCB and incurs negligible overhead on the host system on a suite of indicative benchmarks. We use Nighthawk to introspect the system software and firmware of a host system at runtime. The experimental results show that Nighthawk can detect real-world attacks against the OS, hypervisors, and System Management Mode while mitigating several classes of evasive attacks. Additionally, Nighthawk can monitor the runtime state of host system against the suspicious applications running in target machine. Lei Zhou 0023, Fengwei Zhang, Jidong Xiao, Kevin Leach, Westley Weimer, Xuhua Ding, Guojun Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | KShot: Live Kernel Patching with SMM and SGXabstractLive kernel patching is an increasingly common trend in operating system distributions, enabling dynamic updates to include new features or to fix vulnerabilities without having to reboot the system. Patching the kernel at runtime lowers downtime and reduces the loss of useful state from running applications. However, existing kernel live patching techniques (1) rely on specific support from the target operating system, and (2) admit patch failures resulting from kernel faults. We present KSHOT, a kernel live patching mechanism based on x86 SMM and Intel SGX that focuses on patching Linux kernel security vulnerabilities. Our patching processes are protected by hardware-assisted Trusted Execution Environments. We demonstrate that our technique can successfully patch vulnerable kernel functions at the binary-level without support from the underlying OS and regardless of whether the kernel patching mechanism is compromised. We demonstrate the applicability of KSHOT by successfully patching 30 critical indicative kernel vulnerabilities. Lei Zhou 0023, Fengwei Zhang, Jinghui Liao, Zhenyu Ning, Jidong Xiao, Kevin Leach, Westley Weimer, Guojun Wang 0001 |
DSN | 1 |
| 2019 | Nighthawk: Transparent System Introspection from Ring -3
Lei Zhou 0023, Jidong Xiao, Kevin Leach, Westley Weimer, Fengwei Zhang, Guojun Wang 0001 |
ESORICS (2) | 1 |