6 papers
Heimdallr: Characterizing and Detecting LLM-Induced Security Risks in GitHub CI Workflows
Bonan Ruan, Yeqi Fu, Chuqi Zhang +3
GitHub Continuous Integration (CI) workflows increasingly integrate Large Language Models (LLMs) to automate review, triage, content generation, and repository maintenance. This cr…
Unraveling the Key of Machine Learning-based Android Malware Detection
Jiahao Liu, Jun Zeng, Fabio Pierazzi +3
With the rapid advancement of machine learning (ML), ML-based Android malware detection has gained significant popularity due to its ability to automatically learn malicious patter…
Propagation-Based Vulnerability Impact Assessment for Software Supply Chains
Bonan Ruan, Zhiwei Lin, Jiahao Liu +3
Identifying the impact scope and scale is critical for software supply chain vulnerability assessment. However, existing studies face substantial limitations. First, prior studies…
When MCP Servers Attack: Taxonomy, Feasibility, and Mitigation
Weibo Zhao, Jiahao Liu, Bonan Ruan +2
Model Context Protocol (MCP) servers enable AI applications to connect to external systems in a plug-and-play manner, but their rapid proliferation also introduces severe security…
PsyScam: A Benchmark for Psychological Techniques in Real-World Scams
Shang Ma, Tianyi Ma, Jiahao Liu +4
Over the years, online scams have grown dramatically, with nearly 50% of global consumers encountering scam attempts each week. These scams cause not only significant financial los…
Fuzzing the PHP Interpreter via Dataflow Fusion
Yuancheng Jiang, Chuqi Zhang, Bonan Ruan +4
PHP, a dominant scripting language in web development, powers a vast range of websites, from personal blogs to major platforms. While existing research primarily focuses on PHP app…