Table of Contents
Erhu Feng (冯二虎)
Assistant Professor, IPADS, Shanghai Jiao Tong University
800 Dongchuan Road, Minhang District, Shanghai, P.R.China
Zip/Postal Code: 200240
Email: fengerhu1@sjtu.edu.cn
About Me
I am an Assistant Professor at the School of Artificial Intelligence, Shanghai Jiao Tong University. My research areas include operating systems, AI accelerators, and optimization for large model training and inference. My work has been published in top international conferences in the fields of operating systems and architecture, such as OSDI, ISCA, ASPLOS, and HPCA. I also serve as a reviewer for the prestigious operating systems conference, ATC. My representative work includes the Penglai Enclave and its related technologies, which have been utilized in over a hundred million RISC-V chips and have been integrated into the largest cloud operating system in China: openEuler. During my doctoral studies, I was awarded the first batch of the PhD’s National Natural Science Foundation and was selected for the inaugural Young Talent Support Program for doctoral students. I was also honored with the title of “Academic Star” at Shanghai Jiao Tong University.
Recent Projects
- Penglai Trusted Execution Environment (TEE): One of the three officially recommended trusted execution environments for RISC-V. The dynamic bare-metal isolation technology has been integrated into the official RISC-V firmware, OpenSBI, serving over a hundred million RISC-V chips. The Penglai TEE has also been incorporated into the OpenEuler 24.03 LTS release, the largest server operating system in China, and supports RISC-V chips from companies such as Nuclei, SiFive, and T-head. Related code repository
- RISC-V UEFI Secure Boot Standard (Lead Developer): Collaborated with Intel to establish the secure boot specifications and proof-of-concept validation under the RISC-V UEFI standard. Project link
- LeftOverLocals Vulnerability in AI Accelerators: First introduced an attack case targeting Scratchpad in AI accelerators, which has since been validated on AI accelerators from AMD, Apple, Qualcomm, and others, impacting over ten million chips. Related paper
- HeteroInfer Edge Heterogeneous Inference Engine: The first mobile inference engine architecture supporting GPU and NPU, achieving optimal performance in both the prefill and decoding phases. This technology has already served various applications within SenseTime. Related paper
- NPUSIM Agile Simulation Platform for Many-Core AI Accelerators: A simulation platform designed for data-stream and many-core architecture AI accelerators. Related code and document
- AgentRR Intelligent Agent System: Enhances the performance, accuracy, and robustness of intelligent agents using record-and-replay system capabilities. Related paper
Publications
- [ISCA'25]. Dahu Feng, Erhu Feng (co-author), Dong Du, Pinjie Xu, Yubin Xia, Haibo Chen and Rong Zhao. Topology-Aware Virtualization over Inter-Core Connected Neural Processing Units. 2025 ACM/IEEE 52st Annual International Symposium on Computer Architecture (ISCA), Tokyo, Japan, 2025.
- [ASPLOS'25]. Han Husheng, Zheng Xinyao, Wen Yuanbo, Hao Yifan, Feng Erhu, Liang Ling, Mu Jianan, Li Xiaqing , Ma Tianyun, Jin Pengwei, Song Xinkai, Du Zidong, Guo Qi, Hu Xing. TensorTEE: Unifying Heterogeneous TEE Granularity for Efficient Secure Collaborative Tensor Computing. The 30th ACM International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS 25), 2025.
- [ISCA'24]. Erhu Feng, Dahu Feng, Dong Du, Yubin Xia and Haibo Chen. sNPU: Trusted Execution Environments on Integrated NPUs. 2024 ACM/IEEE 51st Annual International Symposium on Computer Architecture (ISCA), Buenos Aires, Argentina, 2024, pp. 708-723, doi: 10.1109/ISCA59077.2024.00057.
- [ASPLOS'24]. Erhu Feng, Dahu Feng, Dong Du, Yubin Xia, Wenbin Zheng, Siqi Zhao, Haibo Chen. sIOPMP: Scalable and Efficient I/O Protection for TEEs. The 29th ACM International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS 24), 2024.
- [HPCA'23]. Erhu Feng, Dong Du, Yubin Xia, and Haibo Chen. Efficient distributed secure memory with migratable merkle tree. In 2023 IEEE International Symposium on High-Performance Computer Architecture (HPCA 23), pages 347–360, 2023.
- [OSDI'21]. Erhu Feng, Xu Lu, Dong Du, Bicheng Yang, Xueqiang Jiang, Yubin Xia, Binyu Zang, and Haibo Chen. Scalable Memory Protection in the PENGLAI Enclave. In 15th {USENIX} Symposium on Operating Systems Design and Implementation (OSDI 21), pp. 275-294. 2021.