Pan Dong

dblp:98/3867 · DBLP profile ↗
← Back
24ranked-venue papers
6as first author
13since 2021 · last 2026
0000-0002-2890-260XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 9 · 1 first-author · 5 since 2021Security and privacy · 4 · 3 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Computer networks · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 DBBG-Net: a boundary-aware bidirectional feature enhancement model for Chinese named entity recognition
Pan Dong, Yilong Gao, Chuhang Ye, Yunlong Ji
Pattern Anal. Appl.2
2025 Unlocking a New Rust Programming Experience: Fast and Slow Thinking with LLMs to Conquer Undefined Behaviors
abstract
To provide flexibility and low-level interaction capabilities, the “unsafe” tag in Rust is essential, but undermines memory safety and introduces Undefined Behaviors (UBs) that reduce safety. Eliminating UBs requires a deep understanding of Rust’s safety rules and strong typing. Traditional methods require depth analysis of code, which is laborious and depends on knowledge design. The powerful semantic understanding capabilities of LLM offer new opportunities to solve this problem. Although existing large model debugging frameworks excel in semantic tasks, limited by fixed processes and lack adaptive and dynamic adjustment capabilities. Inspired by the dual process theory of decision-making (“Fast and Slow Thinking”), we present a LLM-based framework called RustBrain that automatically and flexibly minimizes UBs in Rust projects. Fast thinking extracts features to generate solutions, while slow thinking decomposes, verifies, and generalizes them abstractly. To apply verification and generalization results to solution generation, enabling dynamic adjustments and precise outputs, RustBrain integrates two thinking through a feedback mechanism. Experimental results on Miri dataset show a 94.3% pass rate and 80.4% execution rate, improving flexibility and Rust projects safety.
Renshuang Jiang, Pan Dong, Zhenling Duan, Xiaoxiang Fang, Jun Ma 0015, Shuai Zhao 0004, Zhe Jiang 0004
DAC2
2025 KERMIT: A BERT-Based Classification Method for Linux Kernel Crashes Through Stack Trace
Yunshan Yang, Pan Dong, Renshuang Jiang, Xiaoxiang Fang, Qirui Yu
ICIC (16)2
2025 Mixture of Experts for Node Classification
abstract
Nodes in the real-world graphs exhibit diverse patterns in numerous aspects, such as degree and homophily. However, most existent node predictors fail to capture a wide range of node patterns or to make predictions based on distinct node patterns, resulting in unsatisfactory classification performance. In this paper, we reveal that different node predictors are good at handling nodes with specific patterns and only apply one node predictor uniformly could lead to suboptimal result. To mitigate this gap, we propose a mixture of experts framework, MoE-NP, for node classification. Specifically, MoE-NP combines a mixture of node predictors and strategically selects models based on node patterns. Experimental results from a range of real-world datasets demonstrate significant performance improvements from MoE-NP.
Yiqi Wang 0001, Weixuan Liang, Jiaxin Zhang 0030, Pan Dong, Aiping Li
ICMR5
2025 Thetis-lathe: Guidance on Reducing Residual Safety Obstacle in System Software from Rust Source Codes
abstract
Programming languages play a crucial role in ensuring the safety of the Operating System (OS). Traditional low-level languages (e.g., C, C++), while high-performance, usually offer very limited protections on safety, and their vulnerability patches (e.g., AddressSanitizer, DangSan), while effective in mitigating some issues, are often too expensive. Rust language combines memory safety with performance, providing a fresh paradigm for constructing efficient, reliable, and dependable. However, existing Rust rely on unsafe code fragments to interface with low-level hardware and other programming languages, introducing critical issues: (1) compromised system-wide safety due to the presence of unsafe code, (2) inaccurate defect detection because of unavoidable interactions between unsafe and safe code; and (3) difficulty in finding an optimal balance between accuracy and efficiency of defect detection and elimination. In contrast to the previous work, we believe — “ prevention is always better than cure ”. Therefore, we propose a new methodology (namely Thetis) to detect and guide the minimization of unsafe fragments in Rust source code. For unsafe code detection, Thetis designs an automated inspection method based on feature extraction. For unsafe code elimination based on Unsafe Rust types and interchangeability, Thetis prop defect optimization suggestions and designs a framework to automatically provide safer code recommendations. We have designed and implemented a new tool called Thetis-lathe based on Thetis and have also ported Thetis-lathe to three mainstream Rust applications, i.e., BlogOS, rCore, and Miri Failure Set. Evaluations show that our tool improved the accuracy of defects and decreased the amount of unsafe code by 35% and undefined behavior by approximately 50%. Furthermore, Thetis-lathe speeds up the run-time about 5x compared with the sanitizer and LMbench results indicate that our approach introduces 7.6% (average) performance overhead on the entire system.
Renshuang Jiang, Pan Dong, Zhe Jiang 0004
ACM Trans. Embed. Comput. Syst.2
2024 Optimization of NUMA Aware DNN Computing System
Xiaoxiang Fang, Pan Dong, Zhe Jiang 0004
ICIC (4)2
2024 X-EDF: An Efficient Defensive Deception Framework against Reconnaissance Attacks
abstract
Deception techniques are increasingly recognized as trans-formative in the realm of cyber defense. With the advent of sophisticated, large-scale scanning technologies such as ZMap, attackers can swiftly pinpoint active and vulnerable ports on edge nodes. Given the diversity of these nodes, a versatile security tool adaptable to various deployment environments is essential. Moreover, edge nodes often encounter performance constraints, necessitating a defense strategy that balances cost-effectiveness for defenders. In response to these challenges, we introduce the X-EDF: an eXpress Data Path (XDP)-based Efficient Defensive De-ception Framework. This framework facilitates an efficient and lightweight deceptive defense leveraging XDP technology. The X-EDF can efficiently respond to attackers' scanning requests with deceptive messages before these requests enter the protocol stack, thus achieving deception defense at a minimal cost. We have validated the effectiveness of our defense strategy through game-theoretic proofs and real-world network deployments.
Zhihang Zhang, Chenlin Huang, Yan Ding 0004, Jinzhu Kong, Qing Liao 0001, Pan Dong, Haifang Zhou
MSN6
2024 Adaptive Optimisation of PyTorch Memory Pools for DNNs
Pan Dong, Xiaoxiang Fang, Axin Yu, Zhe Jiang 0004
PRICAI (1)3
2022 TZ-IMA: Supporting Integrity Measurement for Applications with ARM TrustZone
Liantao Song, Pan Dong
ICICS3
2022 PSpSys: A time-predictable mixed-criticality system architecture based on ARM TrustZone
Zhe Jiang 0004, Pan Dong, Qingling Zhao, Dizhong Zhu, Yan Zhuang 0013, Neil C. Audsley
J. Syst. Archit.2
2022 BlueVisor: Time-Predictable Hardware Hypervisor for Many-Core Embedded Systems
abstract
Whilst virtualization was once restricted to large-scale computing platforms, and it is now widely deployed on modern embedded computing systems. This has been driven by the availability of hardware support which alleviates the performance penalties incurred by traditional software virtualization technologies. In the domain of hard real-time systems, specialist virtualization technology which respects restricted timing requirements and constraints can be deployed to allow sharing of processors. However, other aspects of the embedded system (I/O, memory, and communication) are harder to analyse. In this paper, we argue that in order to support real-time virtualization on modern embedded systems, additional system-wide hardware support is required. We propose BlueVisor, an analyzable and scalable hardware hypervisor for many-core embedded systems, which enables time-predictable CPU, memory, and I/O virtualization, as well as supporting a fast interrupt handler, and inter-VM communication. We describe the design and implementation of the real-time hypervisor and demonstrate how a BlueVisor-based virtualization system can be leveraged to meet real-time requirements with significant improvement in system performance, and with a low-performance cost when executing different types of software.
Zhe Jiang 0004, Pan Dong, Yan Zhuang 0013, Neil C. Audsley, Ian Gray
IEEE Trans. Computers3
2022 Toward an Analysable, Scalable, Energy-Efficient I/O Virtualization for Mixed-Criticality Systems
abstract
In mixed-criticality systems (MCSs), timely handling of I/O operations is a key for the system being successfully implemented and appropriately functioned. The I/O system for an MCS must simultaneously enable different features, including isolation/separation, timing-predictability, performance, scalability, and energy-efficiency. Moreover, such an I/O system also requires to manage I/O resource in an adaptive manner to facilitate efficient yet safe resource sharing among components of different criticality levels. Existing approaches cannot achieve all of these requirements simultaneously. This article presents a mixed-criticality I/O management framework, termed MCS-IOV. MCS-IOV is based on hardware-assisted virtualization, which provides temporal and spatial isolation and prohibits fault propagation with limited extra overhead. MCS-IOV extends a real-time I/O virtualization system, by supporting the concept of mixed criticalities and customized interfaces for schedulers, which offers good timing predictability and scalability. Finally, we introduce an energy management framework for MCS-IOV, ensuring the power-efficiency of the design. The MCS-IOV is the first systematical solution that fulfills all the requirements as a mixed-criticality I/O system.
Zhe Jiang 0004, Xiaotian Dai 0001, Pan Dong, Neil C. Audsley, Nan Guan
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.3
2021 Work-in-Progress: a static partition for shared cache in mixed-time-sensitive system with balanced performance
abstract
In modern safety-critical embedded systems (e.g., automotive/avionic systems), it is increasingly important to integrate components with different critical levels into one physical platform considering space, weight, and heat generation. The most common case is a mixed-time-sensitive system (MTSS), which is usually composed of an RTOS (Real-Time Operating System) and a GPOS (General-Purpose Operating System). In MTSS, cache sharing between RTOS and GPOS often causes inter-task interference, making WCET estimation overly pessimistic due to the increase of cache miss rate and task execution time variances. The existing cache management solutions, such as dynamic and static schemes, are challenging to be applied to MTSS. In this paper, we propose a novel practical method, termed cacheSPM, to eliminate the cache interference in MTSS. CacheSPM statically partitions cache resources during the compilation phase, effectively preventing the GPOS from influencing the cache resources belonged to the RTOS. Compared to the traditional partition schemes, cacheSPM has no intervention of memory manager and additional runtime overhead. Evaluation reveals that this method improves the memory utilization and reduces overhead in a balanced way, with the memory access latency reduced by 80.7% on average, and guarantees the real-time capability of RTOS without negatively affecting the performance of GPOS.
Pan Yang 0021, Pan Dong, Zhe Jiang 0004, Jintao Xia
RTCSA2
2020 Re-Thinking Mixed-Criticality Architecture for Automotive Industry
abstract
Mixed-Criticality System (MCS) has been considered widely within academic literature, but is proving difficulty to implement in industry as the theoretical models underpinning the research do not always consider industrial safety standards and practice (e.g., DO-178C, ISO26262, and EN50128). This paper analyses and formalises the mismatches between theoretical models and industrial standards, and presents a generic industrial MCS architecture, termed as Z-MCS. Z-MCS is built upon the conventional theoretical MCS model (i.e., Adaptive Mixed-Criticality), but with additional satisfaction on the industrial safety requirements: i). run-time safety analysis, which determines preserved applications in each system mode; ii). correct partitioning and isolation of different critical elements with temporal, spatial and fault isolation. Furthermore, three implementing methods of Z-MCS are proposed, with a generic schedulability analysis for timing guarantee. Finally, we evaluate and demonstrate Z-MCS in terms of system schedulability and overheads, along with a real-world case study. In addition, this paper is the first attempt for connecting the theoretical MCS model with the industrial context.
Zhe Jiang 0004, Shuai Zhao 0004, Pan Dong, Nan Guan, Neil C. Audsley
ICCD3
2020 Build real-time communication for hybrid dual-OS system
Pan Dong, Zhe Jiang 0004, Alan Burns 0001, Jun Ma 0015
J. Syst. Archit.1
2020 SLR-SELinux: Enhancing the Security Footstone of SEAndroid with Security Label Randomization
abstract
The root privilege escalation attack is extremely destructive to the security of the Android system. SEAndroid implements mandatory access control to the system through the SELinux security policy at the kernel mode, making the general root privilege escalation attacks unenforceable. However, malicious attackers can exploit the Linux kernel vulnerability of privilege escalation to modify the SELinux security labels of the process arbitrarily to obtain the desired permissions and undermine system security. Therefore, investigating the protection method of the security labels in the SELinux kernel is urgent. And the impact on the existing security configuration of the system must also be reduced. This paper proposes an optimization scheme of the SELinux mechanism based on security label randomization to solve the aforementioned problem. At the system runtime, the system randomizes the mapping of the security labels inside and outside the kernel to protect the privileged security labels of the system from illegal obtainment and tampering by attackers. This method is transparent to users; therefore, users do not need to modify the existing system security configuration. A tamper-proof detection method of SELinux security label is also proposed to further improve the security of the method. It detects and corrects the malicious tampering behaviors of the security label in the critical process of the system timely. The above methods are implemented in the Linux system, and the effectiveness of security defense is proven through theoretical analysis and experimental verification. Numerous experiments show that the effect of this method on system performance is less than 1%, and the success probability of root privilege escalation attack is less than 10−9.
Pan Dong, Yusong Tan, Chenlin Huang, Lifeng Wei, Yudan Zuo
Wirel. Commun. Mob. Comput.2
2019 MCS-IOV: Real-Time I/O Virtualization for Mixed-Criticality Systems
abstract
In mixed-criticality systems, timely handling of I/O is a key for the system being successfully implemented and functioning appropriately. The criticality levels of functions and sometimes the whole system are often dependent on the state of the I/O. An I/O system for a MCS must provide simultaneously isolation/separation, performance/efficiency and timing-predictability, as well as being able to manage I/O resource in an adaptive manner to facilitate efficient yet safe resource sharing among components of different criticality levels. Existing approaches cannot achieve all of these requirements simultaneously. This paper presents a MCS I/O management framework, termed MCS-IOV. MCS-IOV is based on hardware assisted virtualisation, which provides temporal and spatial isolation and prohibits fault propagation with small extra overhead in performance. MCS-IOV extends a real-time I/O virtualisation system, by supporting the concept of mixed criticalities and customised interfaces for schedulers, which offers good timing-preditability. MCS-IOV supports I/O driven criticality mode switch (the mode switch can be triggered by detection of unexpected I/O behaviors, e.g., a higher I/O utilization than expected) and timely I/O resource reconfiguration up on that. Finally, We evaluated and demonstrate MCS-IOV in different aspects.
Zhe Jiang 0004, Neil C. Audsley, Pan Dong, Nan Guan, Xiaotian Dai 0001, Lifeng Wei
RTSS3
2019 Work-in-Progress: Real-Time RPC for Hybrid Dual-OS System
abstract
For the power and space sensitive systems such as automotive/avionic computers, an important trend is isolating and integrating multiple Operating Systems (OSs) in one physical platform, which is named as hybrid multi-OS system. Generally, in a commonly used hybrid dual-OS system, a RTOS (realtime operating system) and a GPOS (general-purpose operating system) are integrated. Cooperation (among the OSs) is a vital feature of a hybrid system to obtain the necessary capabilities, and inter-OS communication is the key. However, it is difficult to satisfy the real-time metrics of inter-OS communication required by the RTOS, due to the uncertainty in communication maintenance and the time-sharing policy of the GPOS. This paper aims to build a time predictable and secure RPC mechanism (i.e., the primary and critical communication unit in a hybrid multi-OS system). Afterwards, a real-time RPC scheme (termed RTRGRPC) is proposed, which is applied to a ready-built TrustZonebased hybrid dual-OS system (i.e., TZDKS). RTRG-RPC achieves accurate time control through three mechanisms: SGI message transforming, interrupt handler RPC servicing, and priorityswapping. Evaluations show that RTRG-RPC can achieve realtime predictability and can also reduce priority inversion.
Pan Dong, Zhe Jiang 0004, Alan Burns 0001, Jun Ma 0015
RTSS1
2019 BlueIO: A Scalable Real-Time Hardware I/O Virtualization System for Many-core Embedded Systems
abstract
In safety-critical systems, time predictability is vital. This extends to I/O operations that require predictability, timing-accuracy, parallel access, scalability, and isolation. Currently, existing approaches cannot achieve all these requirements at the same time. In this article, we propose a framework of hardware framework for real-time I/O virtualization—termed BlueIO —to meet all these requirements simultaneously. BlueIO integrates the functionalities of I/O virtualization, low-layer I/O drivers, and a clock cycle level timing-accurate I/O controller (using the GPIOCP [36]). BlueIO provides this functionality in the hardware layer, supporting abstract virtualized access to I/O from the software domain. The hardware implementation includes I/O virtualization and I/O drivers, provides isolation and parallel (concurrent) access to I/O operations, and improves I/O performance. Furthermore, the approach includes the previously proposed GPIOCP to guarantee that I/O operations will occur at a specific clock cycle (i.e., be timing-accurate and predictable). In this article, we present a hardware consumption analysis of BlueIO to show that it linearly scales with the number of CPUs and I/O devices, which is evidenced by our implementation in VLSI and FPGA. We also describe the design and implementation of BlueIO and demonstrate how a BlueIO-based system can be exploited to meet real-time requirements with significant improvements in I/O performance and a low running cost on different OSs.
Zhe Jiang 0004, Neil C. Audsley, Pan Dong
ACM Trans. Embed. Comput. Syst.3
2018 BlueVisor: A Scalable Real-Time Hardware Hypervisor for Many-Core Embedded Systems
abstract
Virtualization technology is widespread in real-time embedded systems, resulting from the availability of hardware support. Hardware assistance allows the penalties suffered by traditional software virtualization technologies to be alleviated, e.g., significant software overhead. However, current technologies are not necessarily applicable to real-time systems as they are not designed to satisfy strict timing requirements and constraints. In this paper, we propose a scalable real-time hardware hypervisor for many-core embedded system, named BlueVisor, developed from our previously proposed real-time I/O hypervisor (VCDC), I/O controller (GPIOCP) and memory interconnect (BlueTree), which enables predictable CPU, memory, and I/O virtualization, as well as fast interrupt handler, and inter-VM communication. We propose the design idea and specific implementation of the real-time hypervisor, as well as demonstrate how a BlueVisor-based virtualization system can be adequately exploited to meet the real-time requirements with significant improvements on system performance, while presenting a low performance cost executing different operating systems (OSs).
Zhe Jiang 0004, Neil C. Audsley, Pan Dong
RTAS3
2018 TZDKS: A New TrustZone-Based Dual-Criticality System with Balanced Performance
abstract
Many mixed-criticality systems are composed of a RTOS (Real-Time Operating System) and a GPOS (General Purpose Operating System), and we define them as mixed-time-sensitive systems. Complexity, isolation, real-time latency, and overhead are the main metrics to evaluate such a mixed-time-sensitive system (MTSS). These metrics may conflict with each other, so it is difficult for them to be consistently optimized. Most existing implementations only optimize part of the above metrics but not all. As the first contribution, this paper provides a detailed analysis of performance influencing factors which are exerted by various runtime mechanisms of existing MTSSs. We figure out the difference in performance across system designs, including task switch, memory management, interrupt handling, and resource isolation. We propose the philosophy of utilizing TrustZone characteristics to optimize various mechanisms in MTSS. The second contribution is to propose a TrustZone-based solution - termed TZDKS - for MTSS. Appropriate utilization of TrustZone extensions helps TZDKS to implement (i) virtualization environment for GPOS and RTOS, (ii) high efficient task switch, memory access, interrupt handling and device access which are verified by experiments. Therefore, TZDKS can achieve a full-scale balance amongst aforementioned metrics.
Pan Dong, Alan Burns 0001, Zhe Jiang 0004, Xiangke Liao
RTCSA1
2011 New Latch-Up Model for Deep Sub-micron Integrated Circuits
abstract
This paper mainly simulated the single event latch-up (SEL) for the CMOS inverter under the 0.18um technology. The SEL of integrated circuit (IC) was also analyzed in detail. The result showed that the parasitic lateral transistors NPN and PNP of NMOS and PMOS play a role in the SEL happening process. The changes of the drain voltage and the drain current and the functional failure of the circuit were also explained in further. Therefore the new SEL model could be established.
Pan Dong, Long Fan, Suge Yue, Hongchao Zheng, Shougang Du
DASC1
2011 Analysis of the New Latchup Model for Deep Sub-micron Integrated Circuits
abstract
The paper simulated the SEL happening process of the CMOS inverter fabricated the 0.18um technology. The results show that the intrinsic parasitic lateral NPN (QN) and PNP (QP) transistor of the NMOS and PMOS in the CMOS inverter, which could result in the changes of the voltage and the current of the drain when the SEL happening, can delay latch up occurring time and reduce the latch up current. The origin model was improved based on the simulated results. The result studying the improved latch up model shows that the smaller ratios of the internal parasitic resistors between RW1and RW2or RS1and RS2could lead to smaller latch up current and delay more time for the latch up occurrence.
Pan Dong, Long Fan, Suge Yue, Hongchao Zheng, Shougang Du
DASC1
2006 Brief Announcement: A Synthetic Public Key Management Scheme for Large-Scale MANET
Pan Dong, Peidong Zhu, Xicheng Lu
SSS1