What You Trust Is Insecure: Demystifying How Developers (Mis)Use Trusted Execution Environments in Practice
Fuente:
arXiv
Saved in:
| Main Authors: | Niu, Yuqing, Shi, Jieke, Han, Ruidong, Liu, Ye, Ma, Chengyan, Lyu, Yunbo, Lo, David |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Finding Missing Input Validation in TEEs via LLM-Assisted Symbolic Execution
by: Ma, Chengyan, et al.
Published: (2026)
by: Ma, Chengyan, et al.
Published: (2026)
Automated Repair of TEE Partitioning Issues via DSL-Guided and LLM-Assisted Patching
by: Ma, Chengyan, et al.
Published: (2026)
by: Ma, Chengyan, et al.
Published: (2026)
DITING: A Static Analyzer for Identifying Bad Partitioning Issues in TEE Applications
by: Ma, Chengyan, et al.
Published: (2025)
by: Ma, Chengyan, et al.
Published: (2025)
Automated TEE Adaptation with LLMs: Identifying, Transforming, and Porting Sensitive Functions in Programs
by: Han, Ruidong, et al.
Published: (2025)
by: Han, Ruidong, et al.
Published: (2025)
"Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors
by: Liu, Yue, et al.
Published: (2025)
by: Liu, Yue, et al.
Published: (2025)
How Agentic AI Coding Assistants Become the Attacker's Shell
by: Liu, Yue, et al.
Published: (2026)
by: Liu, Yue, et al.
Published: (2026)
Finding Memory Leaks in C/C++ Programs via Neuro-Symbolic Augmented Static Analysis
by: Huang, Huihui, et al.
Published: (2026)
by: Huang, Huihui, et al.
Published: (2026)
Gotcha! This Model Uses My Code! Evaluating Membership Leakage Risks in Code Models
by: Yang, Zhou, et al.
Published: (2023)
by: Yang, Zhou, et al.
Published: (2023)
Towards Demystifying and Repairing LLM-in-the-Loop Vulnerabilities
by: Ma, Yujie, et al.
Published: (2026)
by: Ma, Yujie, et al.
Published: (2026)
On Practicality of Using ARM TrustZone Trusted Execution Environment for Securing Programmable Logic Controllers
by: Li, Zhiang, et al.
Published: (2024)
by: Li, Zhiang, et al.
Published: (2024)
Practical Secure Aggregation by Combining Cryptography and Trusted Execution Environments
by: de Laage, Romain, et al.
Published: (2025)
by: de Laage, Romain, et al.
Published: (2025)
Intent-Aware Authorization for Zero Trust CI/CD
by: Avirneni, Surya Teja
Published: (2025)
by: Avirneni, Surya Teja
Published: (2025)
Towards Trust Proof for Secure Confidential Virtual Machines
by: Mao, Jingkai, et al.
Published: (2024)
by: Mao, Jingkai, et al.
Published: (2024)
Beyond Trusting Trust: Multi-Model Validation for Robust Code Generation
by: McDanel, Bradley
Published: (2025)
by: McDanel, Bradley
Published: (2025)
Identity Control Plane: The Unifying Layer for Zero Trust Infrastructure
by: Avirneni, Surya Teja
Published: (2025)
by: Avirneni, Surya Teja
Published: (2025)
Characterizing Trust Boundary Vulnerabilities in TEE Containers: An Empirical Study
by: Liu, Weijie, et al.
Published: (2025)
by: Liu, Weijie, et al.
Published: (2025)
ColorGo: Directed Concolic Execution
by: Li, Jia, et al.
Published: (2025)
by: Li, Jia, et al.
Published: (2025)
Trusting code in the wild: Exploring contributor reputation measures to review dependencies in the Rust ecosystem
by: Hamer, Sivana, et al.
Published: (2024)
by: Hamer, Sivana, et al.
Published: (2024)
SecureVibeBench: Benchmarking Secure Vibe Coding of AI Agents via Reconstructing Vulnerability-Introducing Scenarios
by: Chen, Junkai, et al.
Published: (2025)
by: Chen, Junkai, et al.
Published: (2025)
SseRex: Practical Symbolic Execution of Solana Smart Contracts
by: Cloosters, Tobias, et al.
Published: (2026)
by: Cloosters, Tobias, et al.
Published: (2026)
Establishing Workload Identity for Zero Trust CI/CD: From Secrets to SPIFFE-Based Authentication
by: Avirneni, Surya Teja
Published: (2025)
by: Avirneni, Surya Teja
Published: (2025)
When "Correct" Is Not Safe: Can We Trust Functionally Correct Patches Generated by Code Agents?
by: Peng, Yibo, et al.
Published: (2025)
by: Peng, Yibo, et al.
Published: (2025)
In Specs we Trust? Conformance-Analysis of Implementation to Specifications in Node-RED and Associated Security Risks
by: Schneider, Simon, et al.
Published: (2025)
by: Schneider, Simon, et al.
Published: (2025)
Establishing Trust in the Beyond-5G Core Network using Trusted Execution Environments
by: Vomvas, Marinos, et al.
Published: (2024)
by: Vomvas, Marinos, et al.
Published: (2024)
Fakeium: A Dynamic Execution Environment for JavaScript Program Analysis
by: Moreno, José Miguel, et al.
Published: (2024)
by: Moreno, José Miguel, et al.
Published: (2024)
On Securing the Software Development Lifecycle in IoT RISC-V Trusted Execution Environments
by: Wilde, Annika, et al.
Published: (2026)
by: Wilde, Annika, et al.
Published: (2026)
Basic Legibility Protocols Improve Trusted Monitoring
by: Sreevatsa, Ashwin, et al.
Published: (2026)
by: Sreevatsa, Ashwin, et al.
Published: (2026)
Demystifying and Detecting Cryptographic Defects in Ethereum Smart Contracts
by: Zhang, Jiashuo, et al.
Published: (2024)
by: Zhang, Jiashuo, et al.
Published: (2024)
Demystifying Invariant Effectiveness for Securing Smart Contracts
by: Chen, Zhiyang, et al.
Published: (2024)
by: Chen, Zhiyang, et al.
Published: (2024)
Semantics-Aligned, Curriculum-Driven, and Reasoning-Enhanced Vulnerability Repair Framework
by: Yang, Chengran, et al.
Published: (2025)
by: Yang, Chengran, et al.
Published: (2025)
ARAP: Demystifying Anti Runtime Analysis Code in Android Apps
by: Suo, Dewen, et al.
Published: (2024)
by: Suo, Dewen, et al.
Published: (2024)
Backdoors in Code Summarizers: How Bad Is It?
by: Wang, Chenyu, et al.
Published: (2025)
by: Wang, Chenyu, et al.
Published: (2025)
Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web
by: Swierzy, Ben, et al.
Published: (2025)
by: Swierzy, Ben, et al.
Published: (2025)
Toward Secure Web to ERP Payment Flows: A Case Study of HTTP Header Trust Failures in SAP Based Systems
by: Dini, Vick
Published: (2026)
by: Dini, Vick
Published: (2026)
Trusted-Execution Environment (TEE) for Solving the Replication Crisis in Academia
by: Li, Jiasun, et al.
Published: (2026)
by: Li, Jiasun, et al.
Published: (2026)
Beyond Function-Level Analysis: Context-Aware Reasoning for Inter-Procedural Vulnerability Detection
by: Li, Yikun, et al.
Published: (2026)
by: Li, Yikun, et al.
Published: (2026)
One Signature, Multiple Payments: Demystifying and Detecting Signature Replay Vulnerabilities in Smart Contracts
by: Wang, Zexu, et al.
Published: (2025)
by: Wang, Zexu, et al.
Published: (2025)
PatUntrack: Automated Generating Patch Examples for Issue Reports without Tracked Insecure Code
by: Jiang, Ziyou, et al.
Published: (2024)
by: Jiang, Ziyou, et al.
Published: (2024)
All Your Tokens are Belong to Us: Demystifying Address Verification Vulnerabilities in Solidity Smart Contracts
by: Sun, Tianle, et al.
Published: (2024)
by: Sun, Tianle, et al.
Published: (2024)
The Data Enclave Advantage: A New Paradigm for Least-Privileged Data Access in a Zero-Trust World
by: Bistolfi, Nico, et al.
Published: (2025)
by: Bistolfi, Nico, et al.
Published: (2025)
Similar Items
-
Finding Missing Input Validation in TEEs via LLM-Assisted Symbolic Execution
by: Ma, Chengyan, et al.
Published: (2026) -
Automated Repair of TEE Partitioning Issues via DSL-Guided and LLM-Assisted Patching
by: Ma, Chengyan, et al.
Published: (2026) -
DITING: A Static Analyzer for Identifying Bad Partitioning Issues in TEE Applications
by: Ma, Chengyan, et al.
Published: (2025) -
Automated TEE Adaptation with LLMs: Identifying, Transforming, and Porting Sensitive Functions in Programs
by: Han, Ruidong, et al.
Published: (2025) -
"Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors
by: Liu, Yue, et al.
Published: (2025)