Publications (12)
ExAD: An Ensemble Approach for Explanation-based Adversarial Detection
Raj Vardhan, Ninghao Liu, Phakpoom Chinprutthiwong +4
Recent research has shown Deep Neural Networks (DNNs) to be vulnerable to adversarial examples that induce desired misclassifications in the models. Such risks impede the applicati…
TraceScope: Interactive URL Triage via Decoupled Checklist Adjudication
Haolin Zhang, William Reber, Yuxuan Zhang +2
Modern phishing campaigns increasingly evade snapshot-based URL classifiers using interaction gates (e.g., checkbox/slider challenges), delayed content rendering, and logo-less cre…
All You Need Is A Fuzzing Brain: An LLM-Powered System for Automated Vulnerability Detection and Patching
Ze Sheng, Qingxiao Xu, Jianwei Huang +5
Our team, All You Need Is A Fuzzing Brain, was one of seven finalists in DARPA's Artificial Intelligence Cyber Challenge (AIxCC), placing fourth in the final round. During the comp…
A Security Analysis of the OpenClaw AI Agent Framework
Surada Suwansathit, Yuxuan Zhang, Guofei Gu
AI agent frameworks connecting large language model (LLM) reasoning to host execution surfaces -- shell, filesystem, containers, and messaging -- introduce security challenges stru…
Examining User Behavior and Cognitive Biases in Personal Password Security
Evelyn Crowe, Patralika Ghosh, Shreyas Kumar +3
Despite increasing awareness of cybersecurity risks, users continue to engage in insecure password practices, such as reusing passwords, choosing weak credentials, and neglecting s…
Practical Speech Re-use Prevention in Voice-driven Services
Yangyong Zhang, Maliheh Shirvanian, Sunpreet S. Arora +2
Voice-driven services (VDS) are being used in a variety of applications ranging from smart home control to payments using digital assistants. The input to such services is often ca…
LLMs in Software Security: A Survey of Vulnerability Detection Techniques and Insights
Ze Sheng, Zhicheng Chen, Shuning Gu +3
Large Language Models (LLMs) are emerging as transformative tools for software vulnerability detection, addressing critical challenges in the security domain. Traditional methods,…
GuardianPWA: Enhancing Security Throughout the Progressive Web App Installation Lifecycle
Mengxiao Wang, Guofei Gu
Progressive Web App (PWA) installation is critical for integrating web and mobile app functionalities, offering a seamless user experience. However, ensuring the security of the PW…
Semantics Over Syntax: Uncovering Pre-Authentication 5G Baseband Vulnerabilities
Qiqing Huang, Xingyu Wang, Wanda Guo +2
Modern 5G user equipment (UE) processes Radio Resource Control (RRC) configuration messages during early control-plane exchanges, before authentication and integrity protection are…
On the Privacy and Integrity Risks of Contact-Tracing Applications
Jianwei Huang, Vinod Yegneswaran, Phillip Porras +1
Smartphone-based contact-tracing applications are at the epicenter of the global fight against the Covid-19 pandemic. While governments and healthcare agencies are eager to mandate…
PromptSleuth: Detecting Prompt Injection via Semantic Intent Invariance
Mengxiao Wang, Yuxuan Zhang, Guofei Gu
Large Language Models (LLMs) are increasingly integrated into real-world applications, from virtual assistants to autonomous agents. However, their flexibility also introduces new…
Demystifying Progressive Web Application Permission Systems
Mengxiao Wang, Guofei Gu
Progressive Web Applications (PWAs) blend the advantages of web and native apps, offering features like offline access, push notifications, and installability. Beyond these, modern…