recallable resource isolation

Designs, implements, and evaluates mechanisms that isolate resources (e.g., memory regions, hardware accelerator or NPU partitions) while allowing those resources to be flexibly allocated to less‑privileged contexts and reliably recalled or reclaimed by an authority. Work includes specifying and enforcing access controls and confinement policies that restrict use to authorized contexts, and building allocation/reclamation protocols and enforcement techniques for recallable resource isolation.

recallableresourceisolation

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.35
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$200K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

This work addresses the programming challenges and error-proneness introduced by Arm’s POE2 architecture, which employs a complex spatiotemporal permission mechanism yet lacks a unified security model. We propose the first general-purpose secure programming model tailored for POE2, abstracting away the intricacies of its spatial and temporal indexing and encapsulating hardware features such as memory protection keys, dedicated registers, and table structures. By doing so, our model significantly simplifies permission management while preserving POE2’s strong security guarantees. It naturally supports common intra-process isolation patterns used in software partitioning, enabling developers to construct secure isolated systems more efficiently and with fewer errors.

architectural complexityintra-process isolationmemory protection keys

Locked In, Leaked Out: Measuring Isolation via Kernel Locks

Jul 28, 2025
A
Anjali
🏛️ University of Wisconsin-Madison

In multi-tenant environments, lock contention on shared kernel data structures—such as filesystem journals and page allocators—is a primary cause of performance interference and isolation failure. This paper proposes the first method to quantitatively assess software-layer isolation by measuring kernel lock contention: leveraging system-level monitoring to precisely track acquisition latency and blocking frequency of diverse kernel locks under concurrent multi-workload execution, thereby establishing a fine-grained isolation analysis framework. Experiments demonstrate that the method accurately identifies isolation bottlenecks across kernel subsystems in virtual machines and containers, revealing filesystem logging and memory management as the dominant sources of interference. Unlike conventional black-box performance profiling, this work pioneers modeling lock-level synchronization behavior as a principled metric for isolation—providing an interpretable, reproducible, and low-level analytical foundation for designing, optimizing, and scheduling resources in multi-tenant systems.

Assess isolation in shared kernel data structuresIdentify common sources of workload interferenceMeasure performance interference via kernel locks

NanoZone: Scalable, Efficient, and Secure Memory Protection for Arm CCA

Jun 08, 2025
SL
Shiqi Liu
🏛️ George Mason University | Huazhong University of Science and Technology

Arm CCA currently supports only VM-level isolation, rendering it ineffective against intra-process vulnerabilities such as Heartbleed; existing fine-grained isolation schemes suffer from high performance overhead or incompatibility with Confidential Virtual Machines (CVMs). This paper proposes a three-tiered region isolation model that enables infinitely lightweight, intra-process security domains, achieving fine-grained memory protection and coordinated defense across user- and kernel-space. We introduce the first CCA extension architecture supporting dynamic domain creation, integrated with a lightweight user-space Code Pointer Integrity (CPI) mechanism—ensuring strong security guarantees while preserving full CVM compatibility. Evaluated on both Arm simulator and physical development boards, our prototype incurs only ~20% average performance overhead while sustaining 95% throughput. It effectively mitigates Heartbleed, session key leakage, and sensitive data exfiltration from KV stores and non-volatile memory.

Arm CCA lacks fine-grained intra-VM memory protectionExisting solutions fail to prevent same-process attacks efficientlyIntra-enclave schemes are slow or incompatible with CVM isolation

Latest Papers

What's happening recently
View more

This study addresses a critical side-channel vulnerability in cloud environments where containers and virtual machines, despite employing software-based isolation mechanisms, remain susceptible to cross-tenant information leakage through the shared host page cache. The authors systematically evaluate the page cache risks across diverse runtime environments—including Docker, gVisor, Kata, and QEMU/KVM—under shared storage conditions, leveraging unprivileged timing measurements to infer cache residency across isolation boundaries. Their work is the first to demonstrate the pervasive nature of page cache leakage in modern isolation architectures and integrates this attack vector into a unified framework for OS-mediated microarchitectural timing side channels. Experiments confirm that the attack succeeds whenever the I/O path involves shared cacheable file objects, while mitigation strategies such as direct I/O or dedicated block devices significantly suppress the signal. The approach successfully recovers coarse-grained activity patterns from a real-world WordPress+MySQL deployment.

cloud isolationisolation failurepage-cache

This work addresses a critical privacy vulnerability in large language model (LLM) agents: although their isolated long-term memory is decoupled from user sessions, it can be inadvertently leaked through tool-calling interfaces. The paper introduces SPORE, the first extraction attack targeting such memory, which temporarily stores malicious instructions in short-term memory and leverages tool responses to generate semantically clean retrieval anchors. By integrating geometric coverage optimization in embedding space with a memory persistence mechanism, SPORE enables automated, cross-session memory extraction while decoupling attack instructions from retrieval signals. The method achieves an 80.0% memory extraction rate without trigger constraints (47.0% with 20 triggers) and successfully links memory records to user identities in multi-user settings, exposing tool interfaces as a pivotal privacy attack surface.

LLM agentsmemory extractionmemory isolation

Hot Scholars

RS

Rahul Singh

Professor of Computer Science, San Francisco State University
BioinformaticsComputational BiologyComputational Drug DiscoveryNeglected Tropical Diseases
ZZ

Zuowei Zhang

Professor, School of Automation, Northwestern Polytechnical University
Pattern RecognitionInformation FusionArtificial Intelligence
YZ

Yuning Zhang

The University of Sydney
Systems for Machine Learning
GC

Guanjie Cheng

Assistant Professor, School of Software Technology, Zhejiang University
AIoTMuti-Agent CollaborationEdge ComputingData Security and Blockchain