{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,9]],"date-time":"2026-03-09T23:17:52Z","timestamp":1773098272452,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":60,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,15]],"date-time":"2023-11-15T00:00:00Z","timestamp":1700006400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"National Natural Science Foundation of China (NSFC)","award":["61902374, 62272442, U1736208"],"award-info":[{"award-number":["61902374, 62272442, U1736208"]}]},{"name":"the Innovation Funding of ICT, CAS","award":["No.E161040"],"award-info":[{"award-number":["No.E161040"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,15]]},"DOI":"10.1145\/3576915.3623206","type":"proceedings-article","created":{"date-parts":[[2023,11,21]],"date-time":"2023-11-21T12:35:13Z","timestamp":1700570113000},"page":"919-933","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["PANIC: PAN-assisted Intra-process Memory Isolation on ARM"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7003-1257","authenticated-orcid":false,"given":"Jiali","family":"Xu","sequence":"first","affiliation":[{"name":"Institute of Computing Technology, CAS &amp; University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8511-1118","authenticated-orcid":false,"given":"Mengyao","family":"Xie","sequence":"additional","affiliation":[{"name":"Institute of Computing Technology, CAS &amp; University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1777-8110","authenticated-orcid":false,"given":"Chenggang","family":"Wu","sequence":"additional","affiliation":[{"name":"Institute of Computing Technology, CAS; University of Chinese Academy of Sciences; &amp; Zhongguancun Laboratory, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7585-1075","authenticated-orcid":false,"given":"Yinqian","family":"Zhang","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, SUSTech &amp; Research Institute of Trustworthy Autonomous Systems, SUSTech, Shenzhen, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-8875-1278","authenticated-orcid":false,"given":"Qijing","family":"Li","sequence":"additional","affiliation":[{"name":"University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-7409-468X","authenticated-orcid":false,"given":"Xuan","family":"Huang","sequence":"additional","affiliation":[{"name":"Peking University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5885-0858","authenticated-orcid":false,"given":"Yuanming","family":"Lai","sequence":"additional","affiliation":[{"name":"Institute of Computing Technology, CAS &amp; University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3439-551X","authenticated-orcid":false,"given":"Yan","family":"Kang","sequence":"additional","affiliation":[{"name":"Institute of Computing Technology, CAS &amp; University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1585-8731","authenticated-orcid":false,"given":"Wei","family":"Wang","sequence":"additional","affiliation":[{"name":"Institute of Computing Technology, CAS, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0896-0458","authenticated-orcid":false,"given":"Qiang","family":"Wei","sequence":"additional","affiliation":[{"name":"National Digital Switching System Engineering and Technological Research Center, Zhengzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4719-1804","authenticated-orcid":false,"given":"Zhe","family":"Wang","sequence":"additional","affiliation":[{"name":"Institute of Computing Technology, CAS; University of Chinese Academy of Sciences; &amp; Zhongguancun Laboratory, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,11,21]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"ARM. 2018. Memory Domain ARM Architecture Reference Manual ARMv7-A and ARMv7-R edition. https:\/\/developer.arm.com\/documentation\/ddi0406\/b\/System-Level-Architecture\/Virtual-Memory-System-Architecture-VMSA-\/Memory-access-control\/Domains"},{"key":"e_1_3_2_1_2_1","unstructured":"ARM. 2021. ARM Architecture Reference Manual ARMv8 for A-profile architecture."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.23919\/DATE.2018.8342161"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660350"},{"key":"e_1_3_2_1_5_1","first-page":"21","article-title":"SKEE: A lightweight Secure Kernel-level Execution Environment for ARM","volume":"16","author":"Azab Ahmed M","year":"2016","unstructured":"Ahmed M Azab, Kirk Swidowski, Rohan Bhutkar, Jia Ma, Wenbo Shen, Ruowen Wang, and Peng Ning. 2016. SKEE: A lightweight Secure Kernel-level Execution Environment for ARM.. In NDSS, Vol. 16. 21--24.","journal-title":"NDSS"},{"key":"e_1_3_2_1_6_1","volume-title":"Dune: Safe User-level Access to Privileged CPU Features. In OSDI. USENIX, 335--348.","author":"Belay Adam","year":"2012","unstructured":"Adam Belay, Andrea Bittau, Ali Mashtizadeh, David Terei, David Mazi\u00e8res, and Christos Kozyrakis. 2012. Dune: Safe User-level Access to Privileged CPU Features. In OSDI. USENIX, 335--348."},{"key":"e_1_3_2_1_7_1","volume-title":"Symposium on Network and Distributed System Security (NDSS).","author":"Burow Nathan","year":"2018","unstructured":"Nathan Burow, Derrick McKee, Scott A Carr, and Mathias Payer. 2018. Cfixx: Object type integrity for c virtual dispatch. In Symposium on Network and Distributed System Security (NDSS)."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00076"},{"key":"e_1_3_2_1_9_1","volume-title":"The A64 System Instruction Class","author":"Chapter","year":"2021","unstructured":"Chapter C5. The A64 System Instruction Class. 2021. ARM Architecture Reference Manual ARMv8, for A-profile architecture."},{"key":"e_1_3_2_1_10_1","volume-title":"The VMSAv8-64 address translation system","author":"Chapter","year":"2021","unstructured":"Chapter D5. The VMSAv8-64 address translation system. 2021. ARM Architecture Reference Manual ARMv8, for A-profile architecture."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.12"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.30"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.3390\/electronics9020236"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3061639.3062267"},{"key":"e_1_3_2_1_15_1","unstructured":"Yeongpil Cho Donghyun Kwon Hayoon Yi and Yunheung Paek. 2017b. Dynamic Virtual Address Range Adjustment for Intra-Level Privilege Separation on ARM. In NDSS."},{"key":"e_1_3_2_1_16_1","volume-title":"ARMore: Pushing Love Back Into Binaries. In USENIX Security Symposium","author":"Bartolomeo Luca Di","year":"2023","unstructured":"Luca Di Bartolomeo, Hossein Moghaddas, and Mathias Payer. 2023. ARMore: Pushing Love Back Into Binaries. In USENIX Security Symposium 2023."},{"key":"e_1_3_2_1_17_1","volume-title":"IMIX: In-Process Memory Isolation EXtension. In USENIX Security.","author":"Frassetto Tommaso","year":"2018","unstructured":"Tommaso Frassetto, Patrick Jauernig, Christopher Liebchen, and Ahmad-Reza Sadeghi. 2018. IMIX: In-Process Memory Isolation EXtension. In USENIX Security."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"crossref","unstructured":"Robert Gawlik Benjamin Kollenda Philipp Koppe Behrad Garmany and Thorsten Holz. 2016. Enabling Client-Side Crash-Resistance to Overcome Diversification and Information Hiding. In NDSS.","DOI":"10.14722\/ndss.2016.23262"},{"key":"e_1_3_2_1_19_1","unstructured":"Enes G\u00f6 ktas Robert Gawlik Benjamin Kollenda Elias Athanasopoulos Georgios Portokalidis Cristiano Giuffrida and Herbert Bos. 2016. Undermining Information Hiding (and What to Do about It). In USENIX Security."},{"key":"e_1_3_2_1_20_1","unstructured":"Google. 2017. The JavaScript Benchmark Suite for the modern web. http:\/\/chromium.github.io\/octane\/."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560625"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"crossref","unstructured":"Ben Gras Kaveh Razavi Erik Bosman Herbert Bos and Cristiano Giuffrida. 2017. ASLR on the Line: Practical Cache Attacks on the MMU. In NDSS.","DOI":"10.14722\/ndss.2017.23271"},{"key":"e_1_3_2_1_23_1","volume-title":"IskiOS: Lightweight defense against kernel-level code-reuse attacks. arXiv preprint arXiv:1903.04654","author":"Gravani Spyridoula","year":"2019","unstructured":"Spyridoula Gravani, Mohammad Hedayati, John Criswell, and Michael L Scott. 2019. IskiOS: Lightweight defense against kernel-level code-reuse attacks. arXiv preprint arXiv:1903.04654 (2019)."},{"key":"e_1_3_2_1_24_1","volume-title":"Hodor: Intra-Process Isolation for High-Throughput Data Plane Libraries. In USENIX ATC.","author":"Hedayati Mohammad","year":"2019","unstructured":"Mohammad Hedayati, Spyridoula Gravani, Ethan Johnson, John Criswell, Michael L. Scott, Kai Shen, and Mike Marty. 2019. Hodor: Intra-Process Isolation for High-Throughput Data Plane Libraries. In USENIX ATC."},{"key":"e_1_3_2_1_25_1","unstructured":"Intel. 2020. Intel 64 and IA-32 Architectures Software Developer's Manual."},{"key":"e_1_3_2_1_26_1","volume-title":"Tightly Seal Your Sensitive Pointers with PACTight. In 31st USENIX Security Symposium (USENIX Security 22)","author":"Ismail Mohannad","year":"2022","unstructured":"Mohannad Ismail, Andrew Quach, Christopher Jelesnianski, Yeongjin Jang, and Changwoo Min. 2022. Tightly Seal Your Sensitive Pointers with PACTight. In 31st USENIX Security Symposium (USENIX Security 22). 3717--3734."},{"key":"e_1_3_2_1_27_1","volume-title":"In-process Memory Isolation Using Hardware Watchpoint. In 2019 56th ACM\/IEEE Design Automation Conference (DAC) (2019-06)","author":"Jang Jinsoo","year":"2019","unstructured":"Jinsoo Jang and Brent Byunghoon Kang. 2019. In-process Memory Isolation Using Hardware Watchpoint. In 2019 56th ACM\/IEEE Design Automation Conference (DAC) (2019-06). 1--6. ISSN: 0738-100X."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3386901.3389023"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833650"},{"key":"e_1_3_2_1_30_1","volume-title":"USENIX Security Symposium","volume":"16","author":"Kemerlis Vasileios P","year":"2012","unstructured":"Vasileios P Kemerlis, Georgios Portokalidis, and Angelos D Keromytis. 2012. kGuard: Lightweight Kernel Protection against Return-to-User Attacks.. In USENIX Security Symposium, Vol. 16."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","unstructured":"Koen Koning Xi Chen Herbert Bos Cristiano Giuffrida and Elias Athanasopoulos. 2017. No Need to Hide: Protecting Safe Regions on Commodity Hardware. In EuroSys (Belgrade Serbia). 16 pages. https:\/\/doi.org\/10.1145\/3064176.3064217","DOI":"10.1145\/3064176.3064217"},{"key":"e_1_3_2_1_32_1","volume-title":"2022 USENIX Annual Technical Conference (USENIX ATC 22)","author":"Kuznetsov Dmitry","year":"2022","unstructured":"Dmitry Kuznetsov and Adam Morrison. 2022. Privbox: Faster system calls through sandboxed privileged execution. In 2022 USENIX Annual Technical Conference (USENIX ATC 22)."},{"key":"e_1_3_2_1_33_1","unstructured":"Volodymyr Kuznetsov L\u00e1szl\u00f3 Szekeres Mathias Payer George Candea R. Sekar and Dawn Song. 2014. Code-pointer Integrity. In OSDI."},{"key":"e_1_3_2_1_34_1","unstructured":"Donghyun Kwon Jangseop Shin Giyeol Kim Byoungyoung Lee Yeongpil Cho and Yunheung Paek. 2019. uXOM: Efficient eXecute-Only Memory on ARM Cortex-M. 231--247. https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/kwon"},{"key":"e_1_3_2_1_35_1","volume-title":"Color My World: Deterministic Tagging for Memory Safety. arXiv preprint arXiv:2204.03781","author":"Liljestrand Hans","year":"2022","unstructured":"Hans Liljestrand, Carlos Chinea, R\u00e9mi Denis-Courmont, Jan-Erik Ekberg, and N Asokan. 2022. Color My World: Deterministic Tagging for Memory Safety. arXiv preprint arXiv:2204.03781 (2022)."},{"key":"e_1_3_2_1_36_1","volume-title":"USENIX Security Symposium. 357--374","author":"Liljestrand Hans","year":"2021","unstructured":"Hans Liljestrand, Thomas Nyman, Lachlan J Gunn, Jan-Erik Ekberg, and N Asokan. 2021. PACStack: an Authenticated Call Stack.. In USENIX Security Symposium. 357--374."},{"key":"e_1_3_2_1_37_1","volume-title":"USENIX Security Symposium. 177--194","author":"Liljestrand Hans","year":"2019","unstructured":"Hans Liljestrand, Thomas Nyman, Kui Wang, Carlos Chinea Perez, Jan-Erik Ekberg, and N Asokan. 2019. PAC it up: Towards Pointer Integrity using ARM Pointer Authentication.. In USENIX Security Symposium. 177--194."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","unstructured":"Yutao Liu Tianyu Zhou Kexin Chen Haibo Chen and Yubin Xia. 2015. Thwarting Memory Disclosure with Efficient Hypervisor-enforced Intra-domain Isolation. In CCS (Denver Colorado USA). ACM 1607--1619. https:\/\/doi.org\/10.1145\/2810103.2813690","DOI":"10.1145\/2810103.2813690"},{"key":"e_1_3_2_1_39_1","unstructured":"LLVM. 2022. Shadow Call Stack. https:\/\/clang.llvm.org\/docs\/ShadowCallStack.html"},{"key":"e_1_3_2_1_40_1","unstructured":"LLVM. 2023. Pointer Authentication. https:\/\/llvm.org\/docs\/PointerAuth.html"},{"key":"e_1_3_2_1_41_1","volume-title":"Kernel Mode Linux: Toward an operating system protected by a type theory. Lecture notes in computer science","author":"Maeda Toshiyuki","year":"2003","unstructured":"Toshiyuki Maeda and Akinori Yonezawa. 2003. Kernel Mode Linux: Toward an operating system protected by a type theory. Lecture notes in computer science (2003), 3--17."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.24026"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"crossref","unstructured":"Lucian Mogosanu Ashay Rane and Nathan Dautenhahn. 2018. MicroStache: A Lightweight Execution Context for In-Process Safe Region Isolation. In RAID.","DOI":"10.1007\/978-3-030-00470-5_17"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"crossref","unstructured":"Vishwath Mohan Per Larsen Stefan Brunthaler Kevin W. Hamlen and Michael Franz. 2015. Opaque Control-Flow Integrity. In NDSS.","DOI":"10.14722\/ndss.2015.23271"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/2594291.2594295"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813644"},{"key":"e_1_3_2_1_47_1","unstructured":"Angelos Oikonomopoulos Elias Athanasopoulos Herbert Bos and Cristiano Giuffrida. 2016. Poking Holes in Information Hiding. In USENIX Security."},{"key":"e_1_3_2_1_48_1","volume-title":"2019 USENIX Annual Technical Conference (USENIX ATC). 241--254","author":"Park Soyeon","year":"2019","unstructured":"Soyeon Park, Sangho Lee, Wen Xu, Hyungon Moon, and Taesoo Kim. 2019. libmpk: Software abstraction for intel memory protection keys (intel MPK). In 2019 USENIX Annual Technical Conference (USENIX ATC). 241--254."},{"key":"e_1_3_2_1_49_1","volume-title":"NoJITsu: Locking Down JavaScript Engines. In 27th Annual Network and Distributed System Security Symposium, NDSS 2020","author":"Park Taemin","year":"2020","unstructured":"Taemin Park, Karel Dhondt, David Gens, Yeoul Na, Stijn Volckaert, and Michael Franz. 2020. NoJITsu: Locking Down JavaScript Engines. In 27th Annual Network and Distributed System Security Symposium, NDSS 2020, San Diego, California, USA, February 23-26, 2020. The Internet Society. https:\/\/www.ndss-symposium.org\/ndss-paper\/nojitsu-locking-down-javascript-engines\/"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00041"},{"key":"e_1_3_2_1_51_1","volume-title":"ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK). In USENIX Security.","author":"Vahldiek-Oberwagner Anjo","year":"2019","unstructured":"Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler, Peter Druschel, and Deepak Garg. 2019. ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK). In USENIX Security."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/173668.168635"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00087"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3064086"},{"key":"e_1_3_2_1_55_1","volume-title":"SafeHidden: An Efficient and Secure Information Hiding Technique Using Re-randomization. In 28th USENIX Security Symposium (USENIX Security 19)","author":"Wang Zhe","year":"2019","unstructured":"Zhe Wang, Chenggang Wu, Yinqian Zhang, Bowen Tang, Pen-Chung Yew, Mengyao Xie, Yuanming Lai, Yan Kang, Yueqiang Cheng, and Zhiping Shi. 2019. SafeHidden: An Efficient and Secure Information Hiding Technique Using Re-randomization. In 28th USENIX Security Symposium (USENIX Security 19). USENIX Association, 1239--1256."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3168089"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559344"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.44"},{"key":"e_1_3_2_1_59_1","volume-title":"Walls","author":"Zhou Jie","year":"2020","unstructured":"Jie Zhou, Yufei Du, Zhuojia Shen, Lele Ma, John Criswell, and Robert J. Walls. 2020. Silhouette: Efficient Protected Shadow Stacks for Embedded Systems. 1219--1236. https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/zhou-jie"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660344"}],"event":{"name":"CCS '23: ACM SIGSAC Conference on Computer and Communications Security","location":"Copenhagen Denmark","acronym":"CCS '23","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3623206","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3623206","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T01:53:56Z","timestamp":1755741236000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3623206"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,15]]},"references-count":60,"alternative-id":["10.1145\/3576915.3623206","10.1145\/3576915"],"URL":"https:\/\/doi.org\/10.1145\/3576915.3623206","relation":{},"subject":[],"published":{"date-parts":[[2023,11,15]]},"assertion":[{"value":"2023-11-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}