Publications at Top-tier Security & System Conferences

A complete list may be found at publications.

  1. [NDSS'25] WAVEN: WebAssembly Memory Virtualization for Enclaves
  2. Weili Wang, Honghan Ji, Peixuan He, Yao Zhang, Ye Wu, Yinqian Zhang
    Network and Distributed System Security Symposium, alifornia, U.S.A., Feb 2025.
  3. [EuroSys'25] Ladon: High-Performance Multi-BFT Consensus via Dynamic Global Ordering
  4. Hanzheng Lyu, Shaokang Xie, Jianyu Niu, Chen Feng, Yinqian Zhang, Ivan Beschastnikh
    European Conference on Computer Systems, Rotterdam, The Netherlands, Mar. 2025.
  5. [CCS'24] DoubleUp Roll: Double-spending in Arbitrum by Rolling It Back
  6. Zhiyuan Sun, Zihao Li, Xinghao Peng, Xiapu Luo, Muhui Jiang, Hao Zhou, Yinqian Zhang
    ACM Conference on Computer and Communications Security, Salt Lake City, U.S.A., Oct. 2024.
  7. [CCS'24] HyperTheft: Thieving Model Weights from TEE-Shielded Neural Networks via Ciphertext Side Channels
  8. Yuanyuan Yuan, Zhibo Liu, Sen Deng, Yanzuo Chen, Shuai Wang, Yinqian Zhang, Zhendong Su
    ACM Conference on Computer and Communications Security, Salt Lake City, U.S.A., Oct. 2024.
  9. [Security'24] π-Jack: Physical-World Adversarial Attack on Monocular Depth Estimation with Perspective Hijacking
  10. Tianyue Zheng, Jingzhi Hu, Rui Tan, Yinqian Zhang, Ying He, Jun Luo
    USENIX Security Symposium, Philadelphia, PA, USA, Aug. 2024.
  11. [Security'24] HIVE: A Hardware-assisted Isolated Execution Environment for eBPF on AArch64
  12. Peihua Zhang, Chenggang Wu, Xiangyu Meng, Yinqian Zhang, Mingfan Peng, Shiyang Zhang, Bing Hu, Mengyao Xie, Yuanming Lai, Yan Kang, Zhe Wang
    USENIX Security Symposium, Philadelphia, PA, USA, Aug. 2024.
  13. [HPCA'24] Uncovering and Exploiting AMD Speculative Memory Access Predictors for Fun and Profit
  14. Chang Liu, Dongsheng Wang, Yongqiang Lyu, Pengfei Qiu, Yu Jin, Zhuoyuan Lu, Yinqian Zhang, Gang Qu
    IEEE International Symposium on High-Performance Computer Architecture, Edinburgh, Scotland, UK, Mar. 2024.
  15. [CCS'23] PANIC: PAN-assisted Intra-process Memory Isolation on ARM
  16. Jiali Xu, Mengyao Xie, Chenggang Wu, Yinqian Zhang, Qijing Li, Xuan Huang, Yuanming Lai, Yan Kang, Wei Wang, Qiang Wei, Zhe Wang
    ACM Conference on Computer and Communications SecurityCopenhagen, Denmark, 26-30 Nov., 2023.
    Distinguished Paper Award
    [Pdf] | [bib]
  17. [Security'23] Reusable Enclaves for Confidential Serverless Computing
  18. Shixuan Zhao, Pinshen Xu, Guoxing Chen, Mengya Zhang, Yinqian Zhang, Zhiqiang Lin
    USENIX Security Symposium, Anaheim, CA, USA, August 9–11, 2023.
    [Pdf] | [bib]
  19. [ISCA'23] TEESec: Pre-Silicon Vulnerability Discovery for Trusted Execution Environments
  20. Moein Ghaniyoun, Kristin Barber, Yuan Xiao, Yinqian Zhang, Radu Teodorescu
    International Symposium on Computer Architecture, Orlando, FL, USA, June 17–21, 2023.
    [Pdf] | [bib]
  21. [Security'23] Panda: Security Analysis of Algorand Smart Contracts
  22. Zhiyuan Sun, Xiapu Luo, Yinqian Zhang
    USENIX Security Symposium, Anaheim, CA, USA, August 9–11, 2023.
    [Pdf] | [bib]
  23. [Security'23] Controlled Data Races in Enclaves: Attacks and Detection
  24. Sanchuan Chen, Zhiqiang Lin, Yinqian Zhang
    USENIX Security Symposium, Anaheim, CA, USA, August 9–11, 2023.
    [Pdf] | [bib]
  25. [Security'23] CipherH: Automated Detection of Ciphertext Side-channel Vulnerabilities in Cryptographic Implementations
  26. Sen Deng, Mengyuan Li, Yining Tang, Shuai Wang, Shoumeng Yan, Yinqian Zhang
    USENIX Security Symposium, Anaheim, CA, USA, August 9–11, 2023.
    [Pdf] | [bib]
  27. [CCS'22] Narrator: Secure and Practical State Continuity for Trusted Execution in the Cloud
  28. Jianyu Niu, Wei Peng, Xiaokuan Zhang, Yinqian Zhang
    ACM Conference on Computer and Communications Security (CCS) , Los Angeles, USA, Nov. 2022.
    [Pdf] | [Bib]
  29. [CCS'22] ENGRAFT: Enclave-guarded Raft on Byzantine Faulty Nodes
  30. Weili Wang, Sen Deng, Jianyu Niu, Michael K. Reiter, Yinqian Zhang
    ACM Conference on Computer and Communications Security (CCS) , Los Angeles, USA, Nov. 2022.
    [Pdf] | [Bib]
  31. [CCS'22] CETIS: Retrofitting Intel CET for Generic and Efficient Intra-process Memory Isolation
  32. Mengyao Xie, Chenggang Wu, Zhe Wang, Yinqian Zhang, Jiali Xu, Yuanming Lai, Yan Kang, Wei Wang
    ACM Conference on Computer and Communications Security (CCS) , Los Angeles, USA, Nov. 2022.
    Best Paper Award Honorable Mention
    [Pdf] | [Bib]
  33. [S&P'22] A Systematic Look at Ciphertext Side Channels on AMD SEV-SNP
  34. Mengyuan Li, Luca Wilke, Jan Wichelmann, Thomas Eisenbarth, Radu Teodorescu and Yinqian Zhang
    IEEE Symposium on Security and Privacy, San California, May 2022.
    Top 10 Finalists of CSAW Best Applied Research Paper Award
    [Pdf] | [Bib]
  35. [S&P'22] vSGX: Virtualizing SGX Enclaves on AMD SEV
  36. Shixuan Zhao, Mengyuan Li, Yinqian Zhang, Zhiqiang Lin
    IEEE Symposium on Security and Privacy, Virtual, May 2022.
    [Pdf] | [Bib] | [Source Code]
  37. [NDSS'22] Multi-Certificate Attacks against Proof-of-Elapsed-Time And Their Countermeasures
  38. Huibo Wang, Guoxing Chen, Yinqian Zhang, Zhiqiang Lin
    Network and Distributed System Security Symposium, 2022.
    [Pdf]
  39. [Security'22] MAGE: Mutual Attestation for a Group of Enclaves without Trusted Third Parties
  40. Guoxing Chen, Yinqian Zhang
    USENIX Security Symposium, BOSTON, MA, USA, 2022.
    [Pdf] | [Source Code]
  41. [Security'21] Towards Formal Verification of State Continuity for Enclave Programs
  42. Mohit Kumar Jangid, Guoxing Chen, Yinqian Zhang, Zhiqiang Lin
    USENIX Security Symposium, Virtual, Aug. 2021.
    [Pdf] | [Slides]
  43. [Security'21] CIPHERLEAKS: Breaking Constant-time Cryptography on AMD SEV via the Ciphertext Side Channel
  44. Mengyuan Li Yinqian Zhang, Huibo Wang, Kang Li, Yueqiang Cheng
    USENIX Security Symposium, Virtual, Aug. 2021.
    [Pdf] | [Bib] | [Project Homepage]
  45. [Security'21] SelectiveTaint: Efficient Data Flow Tracking With Static Binary Rewriting
  46. Sanchuan Chen, Zhiqiang Lin, Yinqian Zhang
    USENIX Security Symposium, Virtual, Aug. 2021.
    [Pdf] | [Slides] | [Source Code]
  47. [ISCA'21] INTROSPECTRE: A Pre-Silicon Framework for Discovery and Analysis of Transient ExecutionVulnerabilities
  48. Moein Ghaniyoun, Kristin Barber, Yinqian Zhang, Radu Teodorescu
    International Symposium on Computer Architecture, Virtual, Jun. 2021.
    [Pdf] | [Bib]
  49. [CCS'21] CROSSLINE: Breaking "Security-by-Crash" based Memory Isolation in AMD SEV
  50. Mengyuan Li, Yinqian Zhang, Zhiqiang Lin
    ACM Conference on Computer and Communications Security, Virtual, Nov. 2021.
    Best Paper Award Runner-up
    [Pdf] | [Bib]
  51. [CCS'20] FirmXRay: Detecting Bluetooth Link Layer Vulnerabilities From Bare-Metal Firmware
  52. Haohuang Wen, Zhiqiang Lin, Yinqian Zhang
    ACM Conference on Computer and Communications Security, Nov. 2020.
    [Pdf] | [Bib]
  53. [Security'20] TXSPECTOR: Uncovering Attacks in Ethereum from Transactions
  54. Mengya Zhang, Xiaokuan Zhang, Yinqian Zhang, Zhiqiang Lin
    USENIX Security Symposium, Aug. 2020.
    [Pdf] | [Bib]
  55. [S&P'20] SEIMI: Efficient and Secure SMAP-Enabled Intra-process Memory Isolation
  56. Zhe Wang, Chenggang Wu, Mengyao Xie, Yinqian Zhang, Kangjie Lu, Xiaofeng Zhang, Yuanming Lai, Yang Kang, Min Yang
    IEEE Symposium on Security and Privacy, May 2020.
    [Pdf] | [Bib]
  57. [NDSS'20] SPEECHMINER: A Framework for Investigating and Measuring Speculative Execution Vulnerabilities
  58. Yuan Xiao, Yinqian Zhang, Mircea-Radu Teodorescu
    Network and Distributed System Security Symposium, San Diego, CA, USA, Feb. 2020.
    [Pdf] | [Bib]
  59. [CCS'19] OPERA: Open Remote Attestation for Intel’s Secure Enclaves
  60. Guoxing Chen, Yinqian Zhang, Ten-Hwang Lai
    ACM Conference on Computer and Communications Security, London, UK, Nov. 2019.
    [Pdf] | [Bib]
  61. [CCS'19] Automatic Fingerprinting of Vulnerable BLE IoT Devices with Static UUIDs from Mobile Apps
  62. Chaoshun Zuo, Haohuang Wen, Zhiqiang Lin, Yinqian Zhang
    ACM Conference on Computer and Communications Security, London, UK, Nov. 2019.
    [Pdf] | [Bib]
  63. [Security'19] Exploiting Unprotected I/O Operations in AMD’s Secure Encrypted Virtualization
  64. Mengyuan Li, Yinqian Zhang, Zhiqiang Lin, Yan Solihin
    USENIX Security Symposium, Santa Clara, CA, Aug. 2019.
    [Pdf] | [Bib] | [Presentation]
  65. [Security'19] SafeHidden: An Efficient and Secure Information Hiding Technique Using Re-randomization
  66. Zhe Wang, Chenggang Wu, Yinqian Zhang, Bowen Tang, Pen-Chung Yew, Mengyao Xie, Yuanming Lai, Yan Kang, Yueqiang Cheng, and Zhiping Shi
    USENIX Security Symposium, Santa Clara, CA, Aug. 2019.
    [Pdf] | [Bib] | [Slides]
  67. [NDSS'19] Statistical Privacy for Streaming Traffic
  68. Xiaokuan Zhang, Jihun Hamm, Michael K. Reiter, Yinqian Zhang
    Network and Distributed System Security Symposium, San Diego, CA, USA, Feb. 2019.
    [Pdf] | [Bib]
  69. [NDSS'19] OBFUSCURO: A Commodity Obfuscation Engine on Intel SGX
  70. Adil Ahmad, Byunggill Joe, Yuan Xiao, Yinqian Zhang, Insik Shin, and Byoungyoung Lee
    Network and Distributed System Security Symposium, San Diego, CA, USA, Feb. 2019.
    [Pdf] | [Bib]
  71. [S&P'19] Why Does Your Data Leak? Uncovering the Data Leakage in Cloud From Mobile Apps
  72. Chaoshun Zuo, Zhiqiang Lin, and Yinqian Zhang.
    IEEE Symposium on Security and Privacy, San Francisco, CA, USA, May. 2019.
    [Pdf] | [Bib] | [Slides]
  73. [CCS'18] HoMonit: Monitoring Smart Home Apps from Encrypted Traffic
  74. Wei Zhang, Yan Meng, Yugeng Liu, Xiaokuan Zhang, Yinqian Zhang, Haojin Zhu
    ACM Conference on Computer and Communications Security, Toronto, Canada, Oct. 2018.
    [Pdf] | [Bib]
  75. [S&P'18] Static Evaluation of Noninterference Using Approximate Model Counting
  76. Ziqiao Zhou, Zhiyun Qian, Michael K. Reiter, Yinqian Zhang
    IEEE Symposium on Security and Privacy, San Francisco, CA, USA, May. 2018.
    [Pdf] | [Bib]
  77. [S&P'18] Racing in Hyperspace: Closing Hyper-Threading Side Channels on SGX with Contrived Data Races
  78. Guoxing Chen*, Wenhao Wang*, Tianyu Chen, Sanchuan Chen, Yinqian Zhang, XiaoFeng Wang, Ten-Hwang Lai, Dongdai Lin
    IEEE Symposium on Security and Privacy, San Francisco, CA, USA, May. 2018. (* co-first authors)
    [Pdf] | [Bib]
  79. [NDSS'18] OS-level Side Channels without Procfs: Exploring Cross-App Information Leakage on iOS
  80. Xiaokuan Zhang, Xueqiang Wang, Xiaolong Bai, Yinqian Zhang, Xiaofeng Wang
    Network and Distributed System Security Symposium, San Diego, CA, USA, Feb. 2018.
    Top 10 Finalists of CSAW Best Applied Research Paper Award
    [Pdf] | [Bib] | [Video]
  81. [NDSS'18] Face Flashing: A Secure Liveness Detection Protocol based on Light Reflections
  82. Di Tang, Zhe Zhou, Yinqian Zhang, Kehuan Zhang
    Network and Distributed System Security Symposium, San Diego, CA, USA, Feb. 2018.
    [Pdf] | [Bib]
  83. [INFOCOM'18] Differentially Private Access Patterns for Searchable Symmetric Encryption
  84. Guoxing Chen, Ten H. Lai, Michael Reiter, Yinqian Zhang
    IEEE International Conference on Computer Communications, Honolulu, HI, USA, Apr. 2018.
    [Pdf] | [Bib]| [Source code]
  85. [ATC'18] Peeking Behind the Curtains of Serverless Platforms
  86. Liang Wang, Mengyuan Li, Yinqian Zhang, Thomas Ristenpart, Michael Swift
    Usenix Annual Technical Conference, Boston, MA, USA, Jul. 2018.
    [Pdf] | [Bib]
  87. [CCS'17] Stacco: Differentially Analyzing Side-Channel Traces for Detecting SSL/TLS Vulnerabilities in Secure Enclaves
  88. Yuan Xiao, Mengyuan Li, Sanchuan Chen, Yinqian Zhang
    ACM Conference on Computer and Communications Security, Dallas, Texas, USA, Oct. 2017.
    (The CCS version of this paper supersedes arxiv 1707.03473.)
    [Pdf] | [Bib] | [Slides] | [Project Homepage]
  89. [CCS'17] Leaky Cauldron on the Dark Land: Understanding Memory Side-Channel Hazards in SGX
  90. Wenhao Wang, Guoxing Chen, Xiaorui Pan, Yinqian Zhang, XiaoFeng Wang, Vincent Bindschaedler, Haixu Tang, Carl A. Gunter
    ACM Conference on Computer and Communications Security, Dallas, Texas, USA, Oct. 2017.
    (The CCS version of this paper supersedes arxiv 1705.07289.)
    [Pdf] | [Bib]
  91. [CCS'16] Return-Oriented Flush-Reload Side Channels on ARM and Their Implications for Android Devices
  92. Xiaokuan Zhang, Yuan Xiao, Yinqian Zhang
    ACM Conference on Computer and Communications Security, Vienna, Austria, Oct. 2016.
    [Pdf] | [Bib] | [Slides]
  93. [CCS'16] A Software Approach to Defeating Side Channels in Last-Level Caches
  94. Ziqiao Zhou, Michael K. Reiter, Yinqian Zhang
    ACM Conference on Computer and Communications Security, Vienna, Austria, Oct. 2016.
    (The CCS version of this paper supersedes arxiv 1603.05615.)
    [Pdf] | [Bib]
  95. [Security'16] One Bit Flips, One Cloud Flops: Cross-VM Row Hammer Attacks and Privilege Escalation
  96. Yuan Xiao, Xiaokuan Zhang, Yinqian Zhang, Mircea-Radu Teodorescu
    USENIX Security Symposium, Austin, TX, Aug. 2016.
    Top 10 Finalists of CSAW Best Applied Research Paper Award
    [Pdf] | [Bib] | [Slides]
  97. [CCS'15] Mitigating Storage Side Channels Using Statistical Privacy Mechanisms
  98. Qiuyu Xiao, Michael K. Reiter, Yinqian Zhang
    ACM Conference on Computer and Communications Security, Denver, Colorado, Oct. 2015.
    [Pdf] | [Bib]
  99. [Security'15] A Placement Vulnerability Study in Multi-Tenant Public Clouds
  100. Venkatanathan Varadarajan, Yinqian Zhang, Thomas Ristenpart and Michael Swift
    USENIX Security Symposium, Washington, D.C., Aug. 2015.
    [Pdf] | [Bib]
  101. [CCS'14] Cross-Tenant Side-Channel Attacks in PaaS Clouds
  102. Yinqian Zhang, Ari Juels, Michael K. Reiter, Thomas Ristenpart
    ACM Conference on Computer and Communications Security, Scottsdale, AZ, Nov. 2014.
    [Pdf] | [Bib]
  103. [CCS'13] Düppel: Retrofitting Commodity Operating Systems to Mitigate Cache Side Channels in the Cloud
  104. Yinqian Zhang, Michael K. Reiter
    ACM Conference on Computer and Communications Security, Berlin, Germany, Nov. 2013.
    [Pdf] | [Bib]
  105. [CCS'12] Cross-VM Side Channels and Their Use to Extract Private Keys
  106. Yinqian Zhang, Ari Juels, Michael K. Reiter, Thomas Ristenpart
    ACM Conference on Computer and Communications Security, Raleigh, NC, Oct. 2012.
    ACM CCS Test-of-Time Award
    [Pdf] | [Bib] | [Slides]
  107. [S&P'11] HomeAlone: Co-Residency Detection in the Cloud via Side-Channel Analysis
  108. Yinqian Zhang, Ari Juels, Alina Oprea, Michael K. Reiter
    IEEE Symposium on Security and Privacy, Oakland, CA, May 2011.
    [Pdf] | [Bib]
  109. [CCS'10] The Security of Modern Password Expiration: An Algorithmic Framework and Empirical Analysis
  110. Yinqian Zhang, Fabian Monrose, Michael K. Reiter
    ACM Conference on Computer and Communications Security, Chicago, IL, Oct. 2010.
    [Pdf] | [Bib]