Skip to main content

Characterizing Trust Boundary Vulnerabilities in TEE Container Systems: An Empirical Study

Journal articles
Liu, W; Chen, H; Huai, S; Xu, Z; Wang, W; Wang, X; Zhang, D; Li, Z; Tang, H; Liu, Z
Published in: Proceedings of the ACM on Software Engineering
June 30, 2026

Trusted Execution Environments (TEEs) have become a cornerstone of confidential computing, attracting significant attention from academia and industry. To support secure and scalable application deployment on confidential clouds, TEE containers (Tcons) have been introduced as middleware to shield applications from malicious operating systems and orchestration layers while preserving usability. In this paper, we present the first comprehensive analysis of Tcons, focusing on three critical layers: OS interfaces, encrypted I/O, and orchestration mechanisms. To enable systematic evaluation, we design TBouncer, an automated analyzer that precisely exercises and benchmarks Tcon isolation boundaries. Our study uncovers fundamental flaws in existing Tcons, leading to exploitable vulnerabilities such as code execution, denial-of-service, and information leakage. In total, we identify six attack vectors, twelve new bugs, and three CVEs. These findings provide new insights into the underestimated attack surface of Tcons and highlight key directions for building more secure and trustworthy container solutions.

Duke Scholars

Altmetric Attention Stats
Dimensions Citation Stats

Published In

Proceedings of the ACM on Software Engineering

DOI

EISSN

2994-970X

Publication Date

June 30, 2026

Volume

3

Issue

FSE

Start / End Page

3439 / 3462

Publisher

Association for Computing Machinery (ACM)
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Liu, W., Chen, H., Huai, S., Xu, Z., Wang, W., Wang, X., … Liu, Z. (2026). Characterizing Trust Boundary Vulnerabilities in TEE Container Systems: An Empirical Study. Proceedings of the ACM on Software Engineering, 3(FSE), 3439–3462. https://doi.org/10.1145/3808159
Liu, Weijie, Hongbo Chen, Shuo Huai, Zhen Xu, Wenhao Wang, XiaoFeng Wang, Danfeng Zhang, Zhi Li, Haixu Tang, and Zheli Liu. “Characterizing Trust Boundary Vulnerabilities in TEE Container Systems: An Empirical Study.” Proceedings of the ACM on Software Engineering 3, no. FSE (June 30, 2026): 3439–62. https://doi.org/10.1145/3808159.
Liu W, Chen H, Huai S, Xu Z, Wang W, Wang X, et al. Characterizing Trust Boundary Vulnerabilities in TEE Container Systems: An Empirical Study. Proceedings of the ACM on Software Engineering. 2026 Jun 30;3(FSE):3439–62.
Liu, Weijie, et al. “Characterizing Trust Boundary Vulnerabilities in TEE Container Systems: An Empirical Study.” Proceedings of the ACM on Software Engineering, vol. 3, no. FSE, Association for Computing Machinery (ACM), June 2026, pp. 3439–62. Crossref, doi:10.1145/3808159.
Liu W, Chen H, Huai S, Xu Z, Wang W, Wang X, Zhang D, Li Z, Tang H, Liu Z. Characterizing Trust Boundary Vulnerabilities in TEE Container Systems: An Empirical Study. Proceedings of the ACM on Software Engineering. Association for Computing Machinery (ACM); 2026 Jun 30;3(FSE):3439–3462.

Published In

Proceedings of the ACM on Software Engineering

DOI

EISSN

2994-970X

Publication Date

June 30, 2026

Volume

3

Issue

FSE

Start / End Page

3439 / 3462

Publisher

Association for Computing Machinery (ACM)