EDBT 2026 Demo / reviewers in the wild / expert
Siqi Zhao
dblp:84/9827
· DBLP profile ↗
12ranked-venue papers
4as first author
9since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 2 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Computer networks · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | R-peak detection and ECG data compression scheme based on empirical mode decomposition and wavelet transform
Xuwen Gui, Siqi Zhao, Bo Yang 0019, Fanli Zhou, Hong Tang 0001, Tao Liu 0009 |
Artif. Intell. Medicine | 2 |
| 2026 | Verifiable Data Streaming Protocol Supporting Keyword QueriesabstractThe rapid deployment of emerging networks, such as the Internet of Things and cloud computing, has generated massive amounts of data. Data streaming is significant among these various data types due to its widespread use in many critical applications, such as gene sequencing, network intrusion detection, and stock trading. On the other hand, the continuously increased size of data streaming makes it impractical to store and manage the data locally, especially for those resource-constrained devices. Outsourcing the data streaming to cloud servers provides an ideal solution to the above storage issue. However, this raises the problem of how to guarantee the integrity of the outsourced data, as cloud servers may maliciously modify the data. To this end, the primitive of verifiable data streaming (VDS) was introduced to preserve the integrity of the outsourced data streaming, enabling data users to ensure that queried data items, including the contents and corresponding positions, are correct. Despite many proposed VDS protocols, most can only use the position index to query outsourced data streaming. Consequently, they fail to fulfill the requirements of those practical applications that need keyword queries. For example, in the setting of network intrusion detection, the data analyst would like to query all access records from the same IP address. In this paper, we extend the original VDS protocol to support keyword queries, i.e., allowing data users to retrieve outsourced data items with particular keywords. Specifically, we use a prefix tree to maintain keywords and another chameleon authentication tree to store data items. The two trees are bound together with cryptographic query proofs, ensuring the consistency between the position index and keyword queries. The proposed VDS protocol, which supports keyword queries, is proven secure in the standard model and outperforms previous VDS protocols in terms of functionality. The experimental results indicate that our proposal is also efficient and practical. Meixia Miao, Peihong Qiang, Siqi Zhao, Jiawei Li 0011, Guohua Tian, Jianghong Wei |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2025 | RBFUZZ: Network Protocol Fuzzing Guided by Rare Branch
Siqi Zhao, Rui Ma 0004, Jingwen Ren, Yuqi Zhai, Shitong Xu |
ICA3PP (7) | 1 |
| 2025 | Partitioned Dual Weighting Strategy for Combining Regression Estimates
Liusha Yang, Siqi Zhao |
ICIC (10) | 2 |
| 2025 | MSNFuzz: Multi-criteria state-sensitive network protocol fuzzing
Yuqi Zhai, Rui Ma 0004, Siqi Zhao, Yuche Yang |
Comput. Secur. | 4 |
| 2024 | sIOPMP: Scalable and Efficient I/O Protection for TEEsabstractTrusted Execution Environments (TEEs), like Intel SGX/TDX, AMD SEV-SNP, ARM TrustZone/CCA, have been widely adopted in prevailing architectures. However, these TEEs typically do not consider I/O isolation (e.g., defending against malicious DMA requests) as a first-class citizen, which may degrade the I/O performance. Traditional methods like using IOMMU or software I/O can degrade throughput by at least 20% for I/O intensive workloads. The main reason is that the isolation requirements for I/O devices differ from CPU ones. This paper proposes a novel I/O isolation mechanism for TEEs, named sIOPMP (scalable I/O Physical Memory Protection), with three key features. First, we design a Multi-stage-Tree-based checker, supporting more than 1,000 hardware regions. Second, we classify the devices into hot and cold, and support unlimited devices with the mountable entry. Third, we propose a remapping mechanism to switch devices between hot and cold status for dynamic I/O workloads. Evaluation results show that sIOPMP introduces only negligible performance overhead for both benchmarks and real-world workloads, and improves 20% ~ 38% network throughput compared with IOMMU-based mechanisms or software I/O adopted in TEEs. Erhu Feng, Dahu Feng, Dong Du 0003, Yubin Xia, Siqi Zhao, Haibo Chen 0001 |
ASPLOS (2) | 6 |
| 2024 | GeMuFuzz: Integrating Generative and Mutational Fuzzing with Deep LearningabstractCurrent grey-box protocol fuzzers may not work well with poor-quality initial seeds. That makes it difficult to cover diverse message types and protocol states defined in the protocol specification. To mitigate this issue, we propose GeMuFuzz, which integrates deep learning based seed generation into mutation-based grey-box fuzzing. Moreover, GeMuFuzz considers the high-dimensional information implied in seeds generated during fuzzing. We also evaluated the performance of GeMuFuzz by comparing with the baseline fuzzer AFLNET on 8 typical protocol implementations of ProFuzzBench. GeMuFuzz discovered 5.07% more paths and 6.19% more crashes, as well as 8.57% more states and 10.54% more state transitions than AFLNET. The experimental results highlight that GeMuFuzz could improve the effectiveness of fuzzing. Rui Ma 0004, Yuqi Zhai, Yuche Yang, Siqi Zhao |
TrustCom | 5 |
| 2024 | Aggregatably Verifiable Data StreamingabstractIn various real-time applications like intelligent transportation and stock trading systems, clients continuously generate the so-called data streaming that is sensitive to both the position and content. Due to the limitations of local storage resources, clients usually have to outsource the generated data to cloud servers that are not fully trusted. The primitive of verifiable data streaming (VDS) protocol was introduced to guarantee the integrity of the outsourced data streaming. Although many VDS protocols have been proposed to improve the efficiency and security of the original one, they mainly focus on how to verifiably retrieve specific data items, without considering the requirement of retrieving aggregated results. However, such a requirement is desirable in many practical applications that only need the aggregated results of the outsourced streaming data, such as satellite cloud atlas and real-time traffic data. In this paper, we introduce a new primitive named aggregatably verifiable data streaming (AVDS) that allows a data user to retrieve aggregated results of designated data items, while guaranteeing the validity of the aggregated results. Specifically, we introduce a new authenticated data structure named chameleon linear-map vector commitment (CLVC), and also provide a concrete construction. Furthermore, we propose a general framework of AVDS protocols from the building block of CLVC. The proposed AVDS protocol is proven to be secure in the standard model. Theoretical analysis and experimental results indicate that the proposed AVDS protocol extends previous VDS protocols in terms of functionality while having comparable computation and communication overhead. Meixia Miao, Siqi Zhao, Jiawei Li 0011, Jianghong Wei |
IEEE Internet Things J. | 2 |
| 2024 | Scythe: A Low-latency RDMA-enabled Distributed Transaction System for Disaggregated MemoryabstractDisaggregated memory separates compute and memory resources into independent pools connected by RDMA (Remote Direct Memory Access) networks, which can improve memory utilization, reduce cost, and enable elastic scaling of compute and memory resources. However, existing RDMA-based distributed transactions on disaggregated memory suffer from severe long-tail latency under high-contention workloads. In this article, we propose Scythe, a novel low-latency RDMA-enabled distributed transaction system for disaggregated memory. Scythe optimizes the latency of high-contention transactions in three approaches: (1) Scythe proposes a hot-aware concurrency control policy that uses optimistic concurrency control (OCC) to improve transaction processing efficiency in low-conflict scenarios. Under high conflicts, Scythe designs a timestamp-ordered OCC (TOCC) strategy based on fair locking to reduce the number of retries and cross-node communication overhead. (2) Scythe presents an RDMA-friendly timestamp service for improved timestamp management. And, (3) Scythe designs an RDMA-optimized RPC framework to improve RDMA bandwidth utilization. The evaluation results show that, compared with state-of-the-art distributed transaction systems, Scythe achieves more than 2.5× lower latency with 1.8× higher throughput under high-contention workloads. Kai Lu 0002, Siqi Zhao, Haikang Shan, Guokuan Li, Jiguang Wan 0001, Ting Yao 0001, Huatao Wu, Daohui Wang |
ACM Trans. Archit. Code Optim. | 2 |
| 2018 | FIMCE: A Fully Isolated Micro-Computing Environment for Multicore SystemsabstractVirtualization-based memory isolation has been widely used as a security primitive in various security systems to counter kernel-level attacks. In this article, our in-depth analysis on this primitive shows that its security is significantly undermined in the multicore setting when other hardware resources for computing are not enclosed within the isolation boundary. We thus propose to construct a fully isolated micro-computing environment (FIMCE) as a new primitive. By virtue of its architectural niche, FIMCE not only offers stronger security assurance than its predecessor, but also features a flexible and composable environment with support for peripheral device isolation, thus greatly expanding the scope of applications. In addition, FIMCE can be integrated with recent technologies such as Intel Software Guard Extensions (SGX) to attain even stronger security guarantees. We have built a prototype of FIMCE with a bare-metal hypervisor. To show the benefits of using FIMCE as a building block, we have also implemented four applications which are difficult to construct using the existing memory isolation method. Experiments with these applications demonstrate that FIMCE imposes less than 1% overhead on single-threaded applications, while the maximum performance loss on multithreaded applications is bounded by the degree of parallelism at the processor level. Siqi Zhao, Xuhua Ding |
ACM Trans. Priv. Secur. | 1 |
| 2017 | On the Effectiveness of Virtualization Based Memory Isolation on Multicore PlatformsabstractVirtualization based memory isolation has been widely used as a security primitive in many security systems. This paper firstly provides an in-depth analysis of its effectiveness in the multicore setting, a first in the literature. Our study reveals that memory isolation by itself is inadequate for security. Due to the fundamental design choices in hardware, it faces several challenging issues including page table maintenance, address mapping validation and thread identification. As demonstrated by our attacks implemented on XMHF and BitVisor, these issues undermine the security of memory isolation. Next, we propose a new isolation approach that is immune to the aforementioned problems. In our design, the hypervisor constructs a fully isolated micro computing environment (FIMCE) that exposes a minimal attack surface to an untrusted OS on a multicore platform. By virtue of its architectural niche, FIMCE offers stronger assurance and greater versatility than memory isolation. We have built a prototype of FIMCE and measured its performance. To show the benefits of using FIMCE as a building block, we have also implemented several practical applications which cannot be securely realized by using memory isolation alone. Siqi Zhao, Xuhua Ding |
EuroS&P | 1 |
| 2017 | Seeing Through The Same Lens: Introspecting Guest Address Space At Native Speed
Siqi Zhao, Xuhua Ding, Dawu Gu |
USENIX Security Symposium | 1 |