FSE 2026
Sun 5 - Thu 9 July 2026 Montreal, Canada
Wed 8 Jul 2026 11:10 - 11:30 at MB 3.435 - Security 2 Chair(s): Amin Milani Fard

Trusted Execution Environments (TEEs) have become a cornerstone of confidential computing, attracting significant attention from academia and industry. To support secure and scalable application deployment on confidential clouds, TEE containers (Tcons) have been introduced as middleware to shield applications from malicious operating systems and orchestration layers while preserving usability. In this paper, we present the first comprehensive analysis of Tcons, focusing on three critical layers: OS interfaces, encrypted I/O, and orchestration mechanisms. To enable systematic evaluation, we design TBouncer, an automated analyzer that precisely exercises and benchmarks Tcon isolation boundaries. Our study uncovers fundamental flaws in existing Tcons, leading to exploitable vulnerabilities such as code execution, denial-of-service, and information leakage. In total, we identify six attack vectors, twelve new bugs, and three CVEs. These findings provide new insights into the underestimated attack surface of Tcons and highlight key directions for building more secure and trustworthy container solutions.

Wed 8 Jul

Displayed time zone: Eastern Time (US & Canada) change

10:30 - 12:30
Security 2Research Papers / Industry Papers at MB 3.435
Chair(s): Amin Milani Fard New York Institute of Technology
10:30
20m
Talk
YASA: Scalable Multi-Language Taint Analysis on the Unified AST at Ant Group
Industry Papers
Yayi Wang Ant Group, Shenao Wang Huazhong University of Science and Technology, Jian Zhao Huazhong University of Science and Technology, Shaosen Shi Ant Group, Ting Li Ant Group, Yan Cheng Ant Group, Lizhong Bian Ant Group, Kan Yu Ant Group, Yanjie Zhao Huazhong University of Science and Technology, Haoyu Wang Huazhong University of Science and Technology
10:50
20m
Talk
InDe-LLM: Defending Against Jailbreak Attacks in LLM-Powered Systems via Intention Disentangling
Research Papers
YujueWang Tsinghua University, Quan Zhang East China Normal University, Chijin Zhou East China Normal University, Gwihwan Go Tsinghua University, Dalong Shi AVIC International Digital Network Technology Co., Ltd., Yu Jiang Tsinghua University
11:10
20m
Talk
Characterizing Trust Boundary Vulnerabilities in TEE Container Systems: An Empirical Study
Research Papers
Weijie Liu Nankai University, Hongbo Chen Indiana University Bloomington, Shuo Huai Nankai University, Zhen Xu Nanyang Technological University, Wenhao Wang Institute of Information Engineering, CAS, XiaoFeng Wang Nanyang Technological University, Danfeng Zhang Duke University, Zhi Li Huazhong University of Science and Technology, Haixu Tang Indiana University Bloomington, Zheli Liu Nankai University
DOI Pre-print
11:30
20m
Talk
GadgetHunter: Region-Based Neuro-Symbolic Detection of Java Deserialization Vulnerabilities
Research Papers
Kaixuan Li Nanyang Technological University, Jian Zhang Beihang University, Chong Wang Nanyang Technological University, Sen Chen Nankai University, Zong Cao Imperial Global Singapore, Min Zhang East China Normal University, Yang Liu Nanyang Technological University
Pre-print
11:50
20m
Talk
ReGA: Model-based Safeguard for LLMs via Representation-Guided Abstraction
Research Papers
Zeming Wei Peking University, Chengcan Wu Peking University, Meng Sun Peking University
Pre-print
12:10
20m
Talk
Two-Level Adaptation for Budget-Constrained Continuous Dynamic Dependence Analysis
Research Papers
Xiaoqin Fu Washington State University, Haipeng Cai University at Buffalo, SUNY
Link to publication Pre-print