2024
- [CCS'24] Kaiming Huang, Mathias Payer, Zhiyun Qian, Jack Sampson, Gang Tan, Trent Jaeger. Top of the Heap: Efficient Memory Error Protection of Safe Heap Objects. In Proceedings of the 2024 ACM Conference on Computer and Communications Security (ACM CCS), October 2024.
- [CCS'24] Mingming Chen, Thomas La Porta, Teryl Taylor, Fred Araujo, Trent Jaeger. Manipulating OpenFlow Link Discovery Packet Forwarding for Topology Poisoning. In Proceedings of the 2024 ACM Conference on Computer and Communications Security (ACM CCS), October 2024.
- [USENIX Security'24] Rahul George, Mingming Chen, Kaiming Huang, Zhiyun Qian, Thomas La Porta, Trent Jaeger. OptiSan: Using Multiple Spatial Error Defenses to Optimize Stack Memory Protection within a Budget. In Proceedings of the 33rd USENIX Security Symposium, August 2024.
- [USENIX Security'24] Yizhuo Zhai, Zhiyun Qian, Chengyu Song, Manu Sridharan, Trent Jaeger, Paul Yu, Srikanth Krishnamurthy. Don’t Waste My Efforts: Pruning Redundant Sanitizer Checks of Developer-Implemented Type Checks. In Proceedings of the 33rd USENIX Security Symposium, August 2024.
- [USENIX Security'24] Meenatchi Sundaram Muthu Selva Annamalai, Georgi Ganev, Emiliano De Cristofaro. "What do you want from theory alone?" Experimenting with Tight Auditing of Differentially Private Synthetic Data Generation. In Proceedings of the 33rd USENIX Security Symposium, August 2024.
- [USENIX Security'24] Zhenxiao Qi, Jie Hu, Zhaoqi Xiao, Heng Yin:
SymFit: Making the Common (Concrete) Case Fast for Binary-Code Concolic Execution. In Proceedings of the 33rd USENIX Security Symposium, August 2024. - [USENIX Security'24] Carter Slocum, Yicheng Zhang, Erfan Shayegani, Pedram Zaree, Nael B. Abu-Ghazaleh, Jiasi Chen. That Doesn't Go There: Attacks on Shared State in Multi-User Augmented Reality. In Proceedings of the 33rd USENIX Security Symposium, August 2024.
- [Oakland'24] Weiteng Chen, Yu Hao, Zheng Zhang, Xiaochen Zou, Dhilung Kirat, Shachee Mishra, Douglas Schales, Jiyong Jang, Zhiyun Qian. SyzGen++: Dependency Inference for Augmenting Kernel Driver Fuzzing. In Proceedings of the 2024 IEEE Symposium on Security and Privacy, May 2024.
- [NDSS'24] Frank Capobianco, Quan Zhou, Aditya Basu, Trent Jaeger, Danfeng Zhang. Talisman: Tamper Analysis for Reference Monitors. In Proceedings of the 2024 Network and Distributed Systems Security Symposium (NDSS), February 2024.
- [NDSS'24] Zhengchuan Liang, Xiaochen Zou, Chengyu Song, Zhiyun Qian. K-LEAK: Towards Automating the Generation of Multi-Step Infoleak Exploits against the Linux Kernel. In Proceedings of the 2024 Network and Distributed Systems Security Symposium (NDSS), February 2024.
- [NDSS'24] Meenatchi Sundaram Muthu Selva Annamalai, Igor Bilogrevic, Emiliano De Cristofaro. FP-Fed: Privacy-Preserving Federated Detection of Browser Fingerprinting. In Proceedings of the 2024 Network and Distributed Systems Security Symposium (NDSS), February 2024.
- [NDSS'24] Xiaochen Zou, Yu Hao, Zheng Zhang, Juefei Pu, Weiteng Chen, Zhiyun Qian. SyzBridge: Bridging the Gap in Exploitability Assessment of Linux Kernel Bugs in the Linux Ecosystem. In Proceedings of the 2024 Network and Distributed Systems Security Symposium (NDSS), February 2024.
2023
- [USENIX Security'23] Guoren Li, Hang Zhang, Jinmeng Zhou, Wenbo Shen, Yulei Sui, Zhiyun Qian. A Hybrid Alias Analysis and Its Application to Global Variable Protection in the Linux Kernel. In Proceedings of the 32nd USENIX Security Symposium, August 2023.
- [USENIX Security'23] Jiyong Yu, Aishani Datta, Trent Jaeger, David Kohlbrenner, Christopher Fletcher. Synchronization Storage Channels (S2C): Timer-less Cache Side-Channel Attacks on the Apple M1 via Hardware Synchronization Instructions. In Proceedings of the 32nd USENIX Security Symposium, August 2023.
- [USENIX Security'23] Carter Slocum, Yicheng Zhang, Nael B. Abu-Ghazaleh, Jiasi Chen:
Going through the motions: AR/VR keylogging from user head motions. In Proceedings of the 32nd USENIX Security Symposium, August 2023. - [USENIX Security'23] Yicheng Zhang, Carter Slocum, Jiasi Chen, Nael B. Abu-Ghazaleh:
It's all in your head(set): Side-channel attacks on AR/VR systems. In Proceedings of the 32nd USENIX Security Symposium, August 2023. - [Oakland'23] Yu Hao, Guoren Li, Xiaochen Zou, Weiteng Chen, Shitong Zhu, Zhiyun Qian, Ardalan Amiri Sani. SyzDescribe: Principled, Automated, Static Generation of Syscall Descriptions for Kernel Drivers. In Proceedings of the 2023 IEEE Symposium on Security and Privacy, May 2023.
- [Oakland'23] Pujan Paudel, Jeremy Blackburn, Emiliano De Cristofaro, Savvas Zannettou, Gianluca Stringhini. Lambretta: Learning to Rank for Twitter Soft Moderation. In Proceedings of the 2023 IEEE Symposium on Security and Privacy, May 2023.
- [MobiCom'23] Qianru Li, Zhehui Zhang, Yanbing Liu, Zhaowei Tan, Chunyi Peng, Songwu Lu.
CA++: Enhancing Carrier Aggregation Beyond 5G. - [MobiCom'23] Yunqi Guo, Jinghao Zhao, Boyan Ding, Congkai Tan, Weichong Ling, Zhaowei Tan, Jennifer Miyaki, Hongzhe Du, Songwu Lu. Sign-to-911: Emergency Call Service for Sign Language Users with Assistive AR Glasses.
2022
- [CCS'22] Mohammad Naseri, Yufei Han, Enrico Mariconti, Yun Shen, Gianluca Stringhini, Emiliano De Cristofaro. CERBERUS: Exploring Federated Prediction of Security Events. In Proceedings of the 2022 ACM Conference on Computer and Communications Security (ACM CCS), October 2022.
- [CCS'22] Wai Man Si, Michael Backes, Jeremy Blackburn, Emiliano De Cristofaro, Gianluca Stringhini, Savvas Zannettou, Yang Zhang. Why So Toxic?: Measuring and Triggering Toxic Behavior in Open-Domain Chatbots. In Proceedings of the 2022 ACM Conference on Computer and Communications Security (ACM CCS), October 2022.
- [CCS'22] Xin'an Zhou, Jiale Guan, Luyi Xing, Zhiyun Qian. Perils and Mitigation of Security Risks of Cooperation in Mobile-as-a-Gateway IoT. In Proceedings of the 2022 ACM Conference on Computer and Communications Security (ACM CCS), October 2022.
- [USENIX Security'22] Ju Chen, Wookhyun Han, Mingjun Yin, Haochen Zeng, Chengyu Song, Byoungyoung Lee, Heng Yin, Insik Shin. SYMSAN: Time and Space Efficient Concolic Execution via Dynamic Data-flow Analysis. In Proceedings of the 31st USENIX Security Symposium, August 2022.
- [USENIX Security'22] Sheng Yu, Yu Qu, Xunchao Hu, Heng Yin. DeepDi: Learning a Relational Graph Convolutional Network Model on Instructions for Fast and Accurate Disassembly. In Proceedings of the 31st USENIX Security Symposium, August 2022.
- [USENIX Security'22] Yugeng Liu, Rui Wen, Xinlei He, Ahmed Salem, Zhikun Zhang, Michael Backes, Emiliano De Cristofaro, Mario Fritz, Yang Zhang. ML-Doctor: Holistic Risk Assessment of Inference Attacks Against Machine Learning Models. In Proceedings of the 31st USENIX Security Symposium, August 2022.
- [USENIX Security'22] Xuewei Feng, Qi Li, Kun Sun, Zhiyun Qian, Gang Zhao, Xiaohui Kuang, Chuanpu Fu, Ke Xu. Off-Path Network Traffic Manipulation via Revitalized ICMP Redirect Attacks. In Proceedings of the 31st USENIX Security Symposium, August 2022.
- [USENIX Security'22] Xiaochen Zou, Guoren Li, Weiteng Chen, Hang Zhang, Zhiyun Qian. SyzScope: Revealing High-Risk Security Impacts of Fuzzer-Exposed Bugs in Linux kernel. In Proceedings of the 31st USENIX Security Symposium, August 2022.
- [USENIX Security'22] Jian Liu, Lin Yi, Weiteng Chen, Chengyu Song, Zhiyun Qian, Qiuping Yi:
LinKRID: Vetting Imbalance Reference Counting in Linux kernel with Symbolic Execution. In Proceedings of the 31st USENIX Security Symposium, August 2022. - [Oakland'22] Ju Chen, Jinghan Wang, Chengyu Song, Heng Yin. JIGSAW: Efficient and Scalable Path Constraints Fuzzing. In Proceedings of the 2022 IEEE Symposium on Security and Privacy, May 2022.
- [Oakland'22] Mohammad Hammas Saeed, Shiza Ali, Jeremy Blackburn, Emiliano De Cristofaro, Savvas Zannettou, Gianluca Stringhini. TrollMagnifier: Detecting State-Sponsored Troll Accounts on Reddit. In Proceedings of the 2022 IEEE Symposium on Security and Privacy, May 2022.
- [Oakland'22] Xuancheng Jin, Xuangan Xiao, Songlin Jia, Wang Gao, Dawu Gu, Hang Zhang, Siqi Ma, Zhiyun Qian, Juanru Li. Annotating, Tracking, and Protecting Cryptographic Secrets with CryptoMPK. In Proceedings of the 2022 IEEE Symposium on Security and Privacy, May 2022.
- [NDSS'22] Zhenxiao Qi, Yu Qu, Heng Yin. LogicMEM: Automatic Profile Generation for Binary-Only Memory Forensics via Logic Inference. In Proceedings of the 2022 Network and Distributed Systems Security Symposium (NDSS), February 2022.
- [NDSS'22] Mohammad Naseri, Jamie Hayes, Emiliano De Cristofaro. Local and Central Differential Privacy for Robustness and Privacy in Federated Learning. In Proceedings of the 2022 Network and Distributed Systems Security Symposium (NDSS), February 2022.
- [NDSS'22] Bristena Oprisanu, Georgi Ganev, Emiliano De Cristofaro. On Utility and Privacy in Synthetic Genomic Data. In Proceedings of the 2022 Network and Distributed Systems Security Symposium (NDSS), February 2022.
- [NDSS'22] Yizhuo Zhai, Yu Hao, Zheng Zhang, Weiteng Chen, Guoren Li, Zhiyun Qian, Chengyu Song, Manu Sridharan, Srikanth V. Krishnamurthy, Trent Jaeger, Paul L. Yu. Progressive Scrutiny: Incremental Detection of UBI bugs in the Linux Kernel In Proceedings of the 2022 Network and Distributed Systems Security Symposium (NDSS), February 2022.
- [NDSS'22] Kaiming Huang, Yongzhe Huang, Mathias Payer, Zhiyun Qian, Jack Sampson, Gang Tan, Trent Jaeger. The Taming of the Stack: Isolating Stack Data from Memory Errors. In Proceedings of the 2022 Network and Distributed Systems Security Symposium (NDSS), February 2022.
- [NDSS'22] Xuewei Feng, Qi Li, Kun Sun, Ke Xu, Baojun Liu, Xiaofeng Zheng, Qiushi Yang, Haixin Duan, Zhiyun Qian. PMTUD is not Panacea: Revisiting IP Fragmentation Attacks against TCP. In Proceedings of the 2022 Network and Distributed Systems Security Symposium (NDSS), February 2022.
- [IMC'22] Ali Davanian, Michalis Faloutsos. MalNet: a binary-centric network-level profiling of IoT malware.
- [MobiCom'22] Yiwen Hu, Min-Yue Chen, Guan-Hua Tu, Chi-Yu Li, Sihan Wang, Jingwen Shi, Tian Xie, Li Xiao, Chunyi Peng, Zhaowei Tan, Songwu Lu. Uncovering insecure designs of cellular emergency services (911).
- [SIGCOMM'22] Jinghao Zhao, Zhaowei Tan, Yifei Xu, Zhehui Zhang, Songwu Lu. SEED: a SIM-based solution to 5G failures.
2021
- [NDSS'21] Zhenxiao Qi, Qian Feng, Yueqiang Cheng, Mengjia Yan, Peng Li, Heng Yin, and Tao Wei. SpecTaint: Speculative Taint Analysis for Discovering Spectre Gadgets. In Proceedings of the 2022 Network and Distributed Systems Security Symposium (NDSS), August 2021.
- [NDSS'21] Jinghan Wang, Chengyu Song, and Heng Yi. Reinforcement Learning-based Hierarchical Seed Scheduling for Greybox Fuzzing. In Proceedings of the 2022 Network and Distributed Systems Security Symposium (NDSS), February 2021.
- [USENIX Security'21] Yu-Tsung Lee, William Enck, Haining Chen, Hayawardh Vijayakumar, Ninghui Li, Zhiyun Qian, Daimeng Wang, Giuseppe Petracca, Trent Jaeger. PolyScope: Multi-Policy Access Control Analysis to Compute Authorized Attack Operations in Android Systems, in Proceedings of USENIX Security 2021.
- [USENIX Security'21] Seyed Mohammadjavad Seyed Talebi, Zhihao Yao, Ardalan Amiri Sani, Zhiyun Qian, Daniel Austin. Undo Workarounds for Kernel Bugs, in Proceedings of USENIX Security 2021.
- [USENIX Security'21] Zheng Zhang, Hang Zhang, Zhiyun Qian, Billy Lau. An Investigation of the Android Kernel Patch Ecosystem, in Proceedings of USENIX Security 2021.
- [HPCA'21] Zhihui Shao, Mohammad A. Islam, Shaolei Ren. Heat Behind the Meter: A Hidden Threat of Thermal Attacks in Edge Colocation Data Centers, in Proceedings of IEEE International Symposium on High-Performance Computer Architecture (HPCA), 2021.
- [AAAI'21] Jianyi Yang, Shaolei Ren. Robust Bandit Learning with Imperfect Context, in Proceedings of arXiv preprint arXiv:2102.05018 (2021).
2020
- [CCS'20] Lei Zhao, Yuncong Zhu, Jiang Ming, Yichen Zhang, Haotian Zhang, and Heng Yin. PatchScope: Memory Object Centric Patch Diffing, in the ACM Conference on Computer and Communications Security(CCS), November 2020.
- [ASPLOS'20] Pan Zhang, Chengyu Song, Heng Yin, Deqing Zou, Elaine Shi and Hai Jin. KLOTSKI: Efficient Obfuscated Execution against Controlled-Channel Attacks, in International Conference on Architectural Support for Programming Languages and Operating Systems, March 2020.
- [NDSS'20] Yue Duan, Xuezixiang Li, Jinghan Wang, and Heng Yin. DeepBinDiff: Learning Program-Wide Code Representations for Binary Diffing, in the Network and Distributed System Security Symposium, Feburary 2020.
- [CCS'20] Keyu Man, Zhiyun Qian, Zhongjie Wang, Xiaofeng Zheng, Youjun Huang, Haixin Duan. DNS Cache Poisoning Attack Reloaded: Revolutions with Side Channels, in Proceedings of ACM Conference on Computer and Communications Security (CCS) 2020.
- [FSE'20] Yizhuo Zhai, Yu Hao, Hang Zhang, Daimeng Wang, Chengyu Song, Zhiyun Qian, Mohsen Lesani, Srikanth V. Krishnamurthy, Paul Yu. UBITect: A Precise and Scalable Method to Detect Use-Before-Initialization bugs in Linux Kernel, in Proceedings of the 2020 ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering(FSE), Sacramento, CA.
- [USENIX Security'20] Xiaofeng Zheng, Chaoyi Lu, Jian Peng, Qiushi Yang, Dongjie Zhou, Baojun Liu, Keyu Man, Shuang Hao, Haixin Duan, Zhiyun Qian. Poison Over Troubled Forwarders: A Cache Poisoning Attack Targeting DNS Forwarding Devices, in Proceedings of USENIX Security 2020, Boston MA.
- [USENIX Security'20] Weiteng Chen, Xiaochen Zou, Guoren Li, Zhiyun Qian. KOOBE: Towards Facilitating Exploit Generation of Kernel Out-Of-Bounds Write Vulnerabilities, in Proceedings of USENIX Security 2020, Boston MA.
- [Sigmetrics'20] Pengxiong Zhu, Keyu Man, Zhongjie Wang, Zhiyun Qian, Roya Ensafi, J. Alex Halderman, Haixin Duan. Characterizing Transnational Internet Performance and the Great Bottleneck of China, in Proceedings of ACM SIGMETRICS 2020, Boston, MA.
- [NDSS'20] Zhongjie Wang, Shitong Zhu, Yue Cao, Zhiyun Qian, Chengyu Song, Srikanth Krishnamurthy, Tracy D. Braun, Kevin S. Chan. SymTCP: Eluding Stateful Deep Packet Inspection with Automated Discrepancy Discover, in Proceedings of Eurosys 2020, Dresden, Germany.
- [S&P'20] Umar Iqbal, Peter Snyder, Shitong Zhu, Benjamin Livshits, Zhiyun Qian, Zubair Shafiq. AdGraph: A Graph-Based Approach to Ad and Tracker Blocking, in Proceedings of IEEE Symposium on Security & Privacy (Oakland), 2020, San Francisco CA.
- [FSE'20] Suhwan Song, Chengyu Song, Yeongjin Jang, and Byoungyoung Lee. CrFuzz: Fuzzing Multi-purpose Programs through Input Validation, in Proceedings of the 2020 ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, Sacramento, CA, November 2020.
- [ECCV'20] Shasha Li, Shitong Zhu, Sudipta Paul, Amit K. Roy-Chowdhury, Chengyu Song, Srikanth V. Krishnamurthy, Ananthram Swami, and Kevin S. Chan. Connecting the Dots: Detecting Adversarial Perturbations Using Context Inconsistency, in Proceedings of the 16th European Conference on Computer Vision (ECCV'20), August 2020.
- [Oakland'20] Esmaeil M. Koruyeh, Shirin H. Shirazi, Khaled N. Khaswaneh, Chengyu Song, and Nael Abu-Ghazaleh. SPECCFI: CFI Informed Branch Prediction, in Proceedings of the 41st IEEE Symposium on Security and Privacy (Oakland'20), San Francisco, CA, May 2020.
- [Micro'20] Hodjat Asghari Esfeden, Amirali Abdolrashidi, Shafiur Rahman, Daniel Wong, Nael Abu-Ghazaleh. BOW: Breathing Operand Windows to Exploit Bypassing in GPUs, in Proceedings of 2020 53rd Annual IEEE/ACM International Symposium on Microarchitecture (MICRO), Athens, Greece.
- [Micro'20] Shafiur Rahman, Nael Abu-Ghazaleh, Rajiv Gupta. GraphPulse: An Event-Driven Hardware Accelerator for Asynchronous Graph Processing, in Proceedings of 2020 53rd Annual IEEE/ACM International Symposium on Microarchitecture (MICRO), Athens, Greece.
- [Micro'20] Liang Zhou, Laxmi Bhuyan, K. K. Ramakrishnan. Gemini: Learning to Manage CPU Power for Latency-Critical Search Engines, in Proceedings of Proc. 53rd IEEE/ACM International Symposium on Microarchitecture (MICRO 2020), Oct. 2020.
- [ICFP'20] Jeremiah Griffin, Mohsen Lesani, Narges Shadab, Xizhe Yin. TLC: Temporal Logic of Distributed Components, in Proceedings of ACM SIGPLAN International Conference on Functional Programming.
- [CAV'20] Xiao Li, Farzin Houshmand, Mohsen Lesani. Hampa: Solver-aided Recency-Aware Replication, in Proceedings of International Conference on Computer-Aided Verification.
- [SIGMETRICS'20] Zhihui Shao, Mohammad A. Islam, Shaolei Ren. Your Noise, My Signal: Exploiting Switching Noise for Stealthy Data Exfiltration from Desktop Computers, in Proceedings of ACM International Conference on Measurement and Modeling of Computer Systems (SIGMETRICS), 2020.