{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,15]],"date-time":"2026-03-15T15:30:47Z","timestamp":1773588647701,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":46,"publisher":"ACM","funder":[{"name":"The National Natural Science Foundation of China","award":["62202465"],"award-info":[{"award-number":["62202465"]}]},{"name":"The National Key Research and Development Program of China","award":["2021YFB2910109"],"award-info":[{"award-number":["2021YFB2910109"]}]},{"name":"The Beijing Key Laboratory of Network Security Protection Technology","award":["2022YFB3103900"],"award-info":[{"award-number":["2022YFB3103900"]}]},{"name":"The Outstanding Talent Scheme &#x28;Category B&#x29; - Qihang Zhou","award":["E3YY141116"],"award-info":[{"award-number":["E3YY141116"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,3,22]]},"DOI":"10.1145\/3779212.3790249","type":"proceedings-article","created":{"date-parts":[[2026,3,10]],"date-time":"2026-03-10T13:55:26Z","timestamp":1773150926000},"page":"2249-2263","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["WorksetEnclave: Towards Optimizing Cold Starts in Confidential Serverless with Workset-Based Enclave Restore"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-1248-7076","authenticated-orcid":false,"given":"Xiaolong","family":"Yan","sequence":"first","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8565-1923","authenticated-orcid":false,"given":"Qihang","family":"Zhou","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-8443-1263","authenticated-orcid":false,"given":"Zisen","family":"Wan","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-0581-2903","authenticated-orcid":false,"given":"Feifan","family":"Qian","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2112-6334","authenticated-orcid":false,"given":"Wentao","family":"Yao","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9858-3587","authenticated-orcid":false,"given":"Weijuan","family":"Zhang","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8376-3235","authenticated-orcid":false,"given":"Xiaoqi","family":"Jia","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2026,3,22]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338466.3358916"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2018.00031"},{"key":"e_1_3_2_1_3_1","unstructured":"Amazon Web Services. [n.d.]. AWS Lambda. https:\/\/aws.amazon.com\/lambda\/. Accessed: 2025-12-03."},{"key":"e_1_3_2_1_4_1","unstructured":"AMD. [n.d.]. Secure Encrypted Virtualization (SEV). https:\/\/www.amd.com\/en\/developer\/sev.html. Accessed: 2024-12-30."},{"key":"e_1_3_2_1_5_1","unstructured":"Apache Software Foundation. [n.d.]. Apache OpenWhisk. https:\/\/openwhisk.apache.org. Accessed: 2024-12-25."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319647.3325825"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3342195.3392698"},{"key":"e_1_3_2_1_8_1","volume-title":"Proceedings of the 19th USENIX Conference on Operating Systems Design and Implementation","author":"Chai Xiaohu","year":"2025","unstructured":"Xiaohu Chai, Tianyu Zhou, Keyang Hu, Jianfeng Tan, Tiwei Bie, Anqi Shen, Dawei Shen, Qi Xing, Shun Song, Tongkai Yang, Le Gao, Feng Yu, Zhengyu He, Dong Du, Yubin Xia, Kang Chen, and Yu Chen. 2025. Fork in the road: reflections and optimizations for cold start latency in production serverless systems. In Proceedings of the 19th USENIX Conference on Operating Systems Design and Implementation (Boston, MA, USA) (OSDI '25). USENIX Association, USA, Article 28, 20 pages."},{"key":"e_1_3_2_1_9_1","unstructured":"Google Cloud. [n.d.]. Google Cloud Functions. https:\/\/cloud.google.com\/functions\/. Accessed: 2025-12-03."},{"key":"e_1_3_2_1_10_1","volume-title":"Memory protection keys. https:\/\/lwn.net\/Articles\/643797\/. LWN.net","author":"Corbet Jonathan","year":"2015","unstructured":"Jonathan Corbet. 2015. Memory protection keys. https:\/\/lwn.net\/Articles\/643797\/. LWN.net (2015)."},{"key":"e_1_3_2_1_11_1","unstructured":"Intel Corporation. [n.d.]. Intel SGX for Linux. https:\/\/github.com\/intel\/linux-sgx. Accessed: 2024-12-03."},{"key":"e_1_3_2_1_12_1","unstructured":"Intel Corporation. 2023. Intel\u00ae Software Guard Extensions (Intel\u00ae SGX). https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/videos\/intel-software-guard-extensions-sgx.html?wapkw=intelsgx Accessed: 2025-10-22."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378512"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3419111.3421297"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354227"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2017.37"},{"key":"e_1_3_2_1_17_1","first-page":"3129","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Gu Jinyu","year":"2022","unstructured":"Jinyu Gu, Bojun Zhu, Mingyu Li, Wentai Li, Yubin Xia, and Haibo Chen. 2022. A Hardware-Software Co-design for Efficient Intra-Enclave Isolation. In 31st USENIX Security Symposium (USENIX Security 22). USENIX Association, Boston, MA, 3129-3145. https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/gu-jinyu"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3620665.3640424"},{"key":"e_1_3_2_1_19_1","unstructured":"Intel Community (MaryT_Intel). 2021. Better Together: Privacy?Preserving Machine Learning Powered by Intel\u00ae SGX and Intel\u00ae DL Boost. Technical Report. https:\/\/community.intel.com\/t5\/Blogs\/Tech-Innovation\/Artificial-Intelligence-AI\/Better-Together-Privacy-Preserving-Machine-Learning-Powered-by\/post\/1335716 Accessed: 2025-08-18."},{"key":"e_1_3_2_1_20_1","unstructured":"Intel Corporation. [n.d.]. SGX Protected File System. https:\/\/cdrdv2-public.intel.com\/671174\/sgx-protected-file-system.pdf. Accessed: 2025-12-15."},{"key":"e_1_3_2_1_21_1","unstructured":"Intel Corporation. 2022. Inteltextsuperscript\u00ae Trust Domain Extensions. https:\/\/cdrdv2-public.intel.com\/690419\/TDX-Whitepaper-February2022.pdf. Accessed: 2024-12-30."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3620678.3624783"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/CLOUD.2019.00091"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3620678.3624789"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA52012.2021.00032"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3585007"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/2948618.2954331"},{"key":"e_1_3_2_1_28_1","unstructured":"Microsoft. [n.d.]. Azure Functions. https:\/\/azure.microsoft.com\/en-us\/services\/functions\/. Accessed: 2024-12-03."},{"key":"e_1_3_2_1_29_1","unstructured":"Microsoft Learn. 2023. Confidential containers on Azure Kubernetes Service (AKS) with Intel SGX enclaves. Technical Report. https:\/\/learn.microsoft.com\/en-us\/azure\/confidential-computing\/confidential-containers-enclaves Accessed: 2025-08-18."},{"key":"e_1_3_2_1_30_1","unstructured":"MITRE. 2014. uppercaseCVE-2014-9357. https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-9357. Accessed: 2025-01-05."},{"key":"e_1_3_2_1_31_1","unstructured":"MITRE. 2015a. uppercaseCVE-2015-3456. https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2015-3456. Accessed: 2025-01-05."},{"key":"e_1_3_2_1_32_1","unstructured":"MITRE. 2015b. uppercaseCVE-2015-5154. https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2015-5154. Accessed: 2025-01-05."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01701-9_25"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3600006.3613155"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3492321.3524272"},{"key":"e_1_3_2_1_36_1","volume-title":"Proceedings of the 2020 USENIX Conference on Usenix Annual Technical Conference (USENIX ATC'20). USENIX Association, USA, Article 14","author":"Shahrad Mohammad","year":"2020","unstructured":"Mohammad Shahrad, Rodrigo Fonseca, \u00cd nigo Goiri, Gohar Chaudhry, Paul Batum, Jason Cooke, Eduardo Laureano, Colby Tresness, Mark Russinovich, and Ricardo Bianchini. 2020. Serverless in the wild: characterizing and optimizing the serverless workload at a large cloud provider. In Proceedings of the 2020 USENIX Conference on Usenix Annual Technical Conference (USENIX ATC'20). USENIX Association, USA, Article 14, 14 pages."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378469"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.5555\/3766078.3766135"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3492321.3519581"},{"key":"e_1_3_2_1_40_1","unstructured":"CRIU Team. [n.d.]. Checkpoint\/Restore In Userspace (CRIU). https:\/\/criu.org\/Main_Page. Accessed: 2024-12-25."},{"key":"e_1_3_2_1_41_1","volume-title":"Proceedings of the 2017 USENIX Conference on Usenix Annual Technical Conference (Santa Clara, CA, USA) (USENIX ATC '17). USENIX Association, USA, 645\u2013658","author":"Tsai Chia-Che","year":"2017","unstructured":"Chia-Che Tsai, Donald E. Porter, and Mona Vij. 2017. Graphene-SGX: a practical library OS for unmodified applications on SGX. In Proceedings of the 2017 USENIX Conference on Usenix Annual Technical Conference (Santa Clara, CA, USA) (USENIX ATC '17). USENIX Association, USA, 645\u2013658."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3445814.3446714"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3302424.3303978"},{"key":"e_1_3_2_1_44_1","unstructured":"WebAssembly Community Group. [n.d.]. WebAssembly. https:\/\/webassembly.org. Accessed: 2024-12-03."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.5555\/3620237.3620462"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3649329.3658492"}],"event":{"name":"ASPLOS '26: 31st ACM International Conference on Architectural Support for Programming Languages and Operating Systems","location":"Pittsburgh PA USA","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems","SIGPLAN ACM Special Interest Group on Programming Languages","SIGARCH ACM Special Interest Group on Computer Architecture","SIGBED ACM Special Interest Group on Embedded Systems"]},"container-title":["Proceedings of the 31st ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 2"],"original-title":[],"deposited":{"date-parts":[[2026,3,15]],"date-time":"2026-03-15T14:00:52Z","timestamp":1773583252000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3779212.3790249"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,22]]},"references-count":46,"alternative-id":["10.1145\/3779212.3790249","10.1145\/3779212"],"URL":"https:\/\/doi.org\/10.1145\/3779212.3790249","relation":{},"subject":[],"published":{"date-parts":[[2026,3,22]]},"assertion":[{"value":"2026-03-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}