4 papers
Staying on the Attack Path: Structured State for Long-Horizon Automated Penetration Testing
Weizhe Wang, Yitong Zhang, Yao Zhang +4
Large language model (LLM) based agents are increasingly applied to cybersecurity tasks such as vulnerability discovery and automated penetration testing. On long-horizon security…
Domain Decoupling Attack: Exploiting the Validation Gap Between Protective DNS and Shared Edge Routing
Weizhe Wang, Minhong Dong, Jinhao Li +6
Network attackers often conceal malicious communication within legitimate Internet traffic. Existing CDN-based evasion techniques rely on SNI--Host inconsistency, insufficient doma…
AndroTruth: A Reliable Benchmark Android Malware Dataset Derived from Technical Expert Reports
Hongpeng Bai, Yao Zhang, Minhong Dong +6
Reliable family labels are essential for Android malware analysis, yet most widely used benchmarks derive such labels from aggregated VirusTotal engine outputs. Because antivirus v…
Unlocking User-oriented Pages: Intention-driven Black-box Scanner for Real-world Web Applications
Weizhe Wang, Yao Zhang, Kaitai Liang +5
Black-box scanners have played a significant role in detecting vulnerabilities for web applications. A key focus in current black-box scanning is increasing test coverage (i.e., ac…