13 citations · 30 across the 14 of their papers we have counts for
17 papers
No-Box Vulnerability Analysis: Description-only Detection of Indirect Prompt Injection Vulnerabilities in MCP Servers
Zehua Zhang, Jie Hu, Pratham Hegde +14
Conventional vulnerability analysis relies on either system access or dynamic interaction, all of which may be unavailable to third-party analysts auditing closed-source, remotely…
ARVO: Atlas of Reproducible Vulnerabilities for Open-Source Software
Xiang Mei, Jordi Del Castillo, Pulkit Singh Singaria +8
Achieving reproducibility, quantity, and diversity in vulnerability datasets has long been viewed as an inherent three-way trade-off, where improving one dimension often comes at t…
ExploitGym: Can AI Agents Turn Security Vulnerabilities into Real Attacks?
Zhun Wang, Nico Schiller, Hongwei Li +13
AI agents are rapidly gaining capabilities that could significantly reshape cybersecurity, making rigorous evaluation urgent. A critical capability is exploitation: turning a vulne…
Root-Cause-Driven Automated Vulnerability Repair
Hulin Wang, Zion Leonahenahe Basque, Jie Hu +13
Recent LLM-based systems have made automated vulnerability repair increasingly practical, but two challenges remain. First, without strong signals about where a bug originates, rep…
Pushan: Trace-Free Deobfuscation of Virtualization-Obfuscated Binaries
Ashwin Sudhir, Zion Leonahenahe Basque, Wil Gibbs +9
In the ever-evolving battle against malware, binary obfuscation techniques are a formidable barrier to effective analysis by both human security analysts and automated systems. In…
Do Hackers Dream of Electric Teachers?: A Large-Scale, In-Situ Measurement of Cybersecurity Student Behaviors and Educational Performance with AI Tutors
Michael Tompkins, Nihaarika Agarwal, Ananta Soneji +8
To meet the ever-increasing demands of the cybersecurity workforce, AI tutors have been proposed for personalized, scalable education. But, while AI tutors have shown promise in in…