Selected Papers
2026
-
NDSS
Bleeding Pathways: Vanishing Discriminability in LLM Hidden States Fuels Jailbreak AttacksNetwork and Distributed System Security Symposium (NDSS), 2026 PDF
- USENIX Security
-
USENIX Security
Firmenstein: Scaling Dynamic Analysis for Linux-Based Firmware Services via API-Centric Intervention Code SynthesisUSENIX Security Symposium (USENIX Security), 2026
-
USENIX Security
BugAuditor: Detecting Bugs via Inconsistent Defensive Code AuditingUSENIX Security Symposium (USENIX Security), 2026
-
TDSC
FedWM: Data-Free Watermarking for Model Ownership Protection in Federated LearningIEEE Transactions on Dependable and Secure Computing (TDSC) 2026, DOI: 10.1109/TDSC.2026.3651755
-
TDSC
AI-Shielder: Exploiting Backdoors to Defend against Adversarial AttacksIEEE Transactions on Dependable and Secure Computing (TDSC), Volume: 23, Issue: 1, Jan.-Feb. 2026, 1244 - 1259, DOI: 10.1109/TDSC.2025.3612270 PDF
-
TIFS
HEFLGuard: Backdoor Detection in Homomorphic Encryption-based Federated LearningIEEE Transactions on Information Forensics and Security (TIFS), 2026
-
TOSEM
VUI Testing of VPA Apps via Behavior Model-Enhanced LLM AgentsACM Transactions on Software Engineering and Methodology (TOSEM) PDF
2025
-
CCS
SCOPE: Expanding Client-Side Post-Processing for Efficient Privacy-Preserving Model InferenceACM Conference on Computer and Communications Security (CCS), 2025 PDF
-
CCS
RAG-WM: An Efficient Black-Box Watermarking Approach for Retrieval-Augmented Generation of Large Language ModelsACM Conference on Computer and Communications Security (CCS), 2025 PDF
-
S&P
EvilHarmony: Highly Stealthy Adversarial Attacks against Black-box Speech Recognition SystemsIEEE Symposium on Security and Privacy (S&P), 2025 PDF
- S&P
-
USENIX Security
PrivacyXray: Detecting Privacy Breaches in LLMs through Semantic Consistency and Probability CertaintyUSENIX Security Symposium (USENIX Security), 2025 PDF
- USENIX Security
- USENIX Security
- ISSTA
- ISSTA
- NDSS
-
NDSS
What's Done Is Not What's Claimed: Detecting and Interpreting Inconsistencies in App BehaviorsNetwork and Distributed System Security Symposium (NDSS), 2025 PDF
-
NDSS
The Midas Touch: Triggering the Capability of LLMs for RM-API Misuse DetectionNetwork and Distributed System Security Symposium (NDSS), 2025 PDF
- NDSS
-
TDSC
MalFocus: Locating Malicious Modules in Malware based on Hybrid Deep LearningIEEE Transactions on Dependable and Secure Computing, 2025 PDF
-
AAAI
RepeatLeakage: Leak Prompts from Repeating as Large Language Model is a Good RepeaterAAAI Conference on Artificial Intelligence (AAAI), 2025 PDF
-
TOPS
Adversarial Attack and Defense for Commercial Black-box Chinese-English Speech Recognition SystemsACM Transactions on Privacy and Security 2025 PDF
2024
-
ASE
Attribution-guided Adversarial Code Prompt Generation for Code Completion ModelsInternational Conference on Automated Software Engineering (ASE), 2024 CODE
- USENIX Security
- CCS
- CCS
- S&P
- NDSS
- NDSS
-
USENIX Security
DARKFLEECE: Probing the Dark Side of Android Subscription AppsUSENIX Security Symposium (USENIX Security), 2024 PDF
-
USENIX Security
AE-Morpher: Improve Physical Robustness of Adversarial Objects against LiDAR-based Detectors via Object ReconstructionUSENIX Security Symposium (USENIX Security), 2024 PDF
- USENIX Security
- ACL
-
TIFS
NeuralSanitizer: Detecting Backdoors in Neural NetworksIEEE Transactions on Information Forensics and Security (TIFS), 2024 CODE
-
ISSTA
Evaluating the Effectiveness of DecompilersInternational Symposium on Software Testing and Analysis (ISSTA), 2024 CODE
- TIFS
- AAAI
- AAAI
2023
- CCS
-
USENIX Security
Differential Testing of Cross Deep Learning Framework APIs: Revealing Inconsistencies and VulnerabilitiesUSENIX Security Symposium (USENIX Security), 2023 PDF
- USENIX Security
- USENIX Security
- S&P
-
USENIX Security
A Data-free Backdoor Injection Approach in Neural NetworksUSENIX Security Symposium (USENIX Security), 2023 PDF
- USENIX Security
- USENIX Security
-
NDSS
PPA: Preference Profiling Attack Against Federated LearningNetwork and Distributed System Security Symposium (NDSS), 2023 PDF
-
TDSC
A Robustness-Assured White-Box Watermark in Neural NetworksIEEE Transactions on Dependable and Secure Computing (accepted) PDF
-
ICME
DBIA: Data-free Backdoor Injection Attack against Transformer NetworksIEEE International Conference on Multimedia and Expo (ICME), 2023 PDF
2022
-
CCS
Understanding Real-world Threats to Deep Learning Models in Android AppsACM Conference on Computer and Communications Security (CCS), 2022 PDF
-
CCS
Clues in Tweets: Twitter-Guided Discovery and Analysis of SMS SpamACM Conference on Computer and Communications Security (CCS), 2022 PDF
- ASE
-
TDSC
Secure Aggregation is Insecure: Category Inference Attack on Federated LearningTDSC, 2022 (accepted) PDF
-
TOPS
SoK: A Modularized Approach to Study the Security of Automatic Speech Recognition SystemsACM Transactions on Privacy and Security, 2022 (accepted) PDF
2021
-
CCS
AI-Lancet: Locating Error-inducing Neurons to Optimize Neural NetworksACM Conference on Computer and Communications Security (CCS), 2021 PDF
-
USENIX Security
DRMI: A Dataset Reduction Technology based on Mutual Information for Black-box AttacksUSENIX Security Symposium (USENIX Security), 2021 PDF
-
S&P
Bookworm Game: Automatic Discovery of LTE Vulnerabilities Through Documentation AnalysisIEEE S&P 2021 PDF
-
UbiComp
Demystifying the Vetting Process of Voice-controlled Skills on MarketsACM International Joint Conference on Pervasive and Ubiquitous Computing (UbiComp), 2021 PDF
-
WWW
SEPAL: Towards a Large-scale Analysis of SEAndroid Policy Customizationin Proceedings of the 30th The Web Conference (WWW), Ljubljana, Slovenia, 2021 PDF
2020
-
CCS
RTFM! Automatic Assumption Discovery and Verification Derivation from Library Document for API Misuse DetectionACM Conference on Computer and Communications Security (CCS), 2020 PDF
- USENIX Security
-
USENIX Security
FuzzGuard: Filtering out Unreachable Inputs in Directed Grey-box Fuzzing through Deep LearningUSENIX Security Symposium (USENIX Security), 2020 PDF
- USENIX Security
-
UbiComp
SPEAKER-RADAR: a Sonar-based Liveness Detection System for Protecting Smart Speakers Against Remote AttackersACM International Joint Conference on Pervasive and Ubiquitous Computing (UbiComp), 2020 PDF
2019
- CCS
-
USENIX Security
Devils in the Guidance: Predicting Logic Vulnerabilities in Payment Syndication Services through Automated Documentation AnalysisUSENIX Security Symposium (USENIX Security), 2019
-
S&P
Demystifying Hidden Privacy Settings in Mobile AppsIEEE S&P 2019
-
DSN
1dVul: Discovering 1-day Vulnerabilities through Binary PatchesInternational Conference on Dependable Systems and Networks (DSN), 2019
-
EuroS&P
DroidEvolver: Self-Evolving and Scalable Android Malware Detection SystemIEEE European Symposium on Security and Privacy (EuroS&P), 2019
-
EuroS&P
TraffickStop: Detecting and Measuring Illicit Traffic Monetization Through Large-scale DNS AnalysisIEEE European Symposium on Security and Privacy (EuroS&P), 2019
2018
- USENIX Security
-
TIFS
Uncovering the Face of Android Ransomware: Characterization and Real-time DetectionIEEE Transactions on Information Forensics and Security (TIFS), (Accepted)
-
TIFS
Android Malware Familial Classification and Representative Sample Selection via Frequent Subgraph AnalysisIEEE Transactions on Information Forensics and Security (TIFS), (Accepted)
-
COSE
A Cyber Security Data Triage Operation Retrieval SystemComputers & Security (Accepted)
-
TMC
Leveraging Information Asymmetry to Transform Android Apps into Self-Defending Code against Repackaging AttacksIEEE Transactions on Mobile Computing (TMC), (Accepted)
-
EuroS&P
DeepRefiner: Multi-layer Android Malware Detection System Applying Deep Neural Networks3rd IEEE European Symposium on Security and Privacy (EuroS&P), London, UK, April 24-26, 2018 (Accepted)
-
Cybersecurity
Detecting telecommunication fraud by understanding the contents of a callCybersecurity, 2018, (Accepted) Dataset
2017
-
CCS
Mass Discovery of Android Traffic Imprints through Instantiated Partial ExecutionIn Proceedings of the 24th ACM Conference on Computer and Communications Security (CCS), 2017. (Accepted) PDF
-
CCS
SemFuzz: Semantics-based Automatic PoC GenerationIn Proceedings of the 24th ACM Conference on Computer and Communications Security (CCS), 2017. (Accepted) PDF
-
CCS
Unleashing the Walking Dead: Understanding Cross-App Remote Infections on Mobile WebViewsIn Proceedings of the 24th ACM Conference on Computer and Communications Security (CCS), 2017. (Accepted) PDF
-
RAID
Filtering for Malice through the Data Ocean: Large-Scale PHA Install Detection at the Communication Service Provider LevelRAID 2017 (Accepted)
-
DSN
Ghost Installer in the Shadow: Security Analysis of App Installation on AndroidDSN 2017. (Accepted)
-
MobiSys
System Service Call-oriented Symbolic Execution of Android Framework with Applications to Vulnerability Discovery and Exploit GenerationACM MobiSys 2017. (Accepted)
-
MobiSys
Characterizing Smartwatch Usage in The WildACM MobiSys 2017. (Accepted)
2016
- S&P
-
TRE
Dynamically Discovering Likely Memory Layout to Perform Accurate FuzzingIEEE Transactions on Reliability, 2016, accepted, to appear
-
ISSRE
Frequent Subgraph based Familial Classification of Android Malware27th IEEE International Symposium on Software Reliability Engineering (ISSRE), Ottawa, Canada, 2016Best Research Paper Award
2015
-
CCS
From System Service Freezing to System Server Shutdown in Android: All You Need Is a Loop in an ApplicationTo appear in the 22nd ACM Conference on Computer and Communications Security (CCS), Denver, Colorado, USA. October 12-16, 2015
-
CCS
Hare Hunting in the Wild Android: A Study on the Threat of Hanging Attribute References22nd ACM Conference on Computer and Communications Security (CCS), Denver, USA, 2015
-
CCS
Cracking App Isolation on Apple: Unauthorized Cross-App Resource Access on MAC OS X and iOSTo appear in the 22nd ACM Conference on Computer and Communications Security (CCS), Denver, Colorado, USA. October 12-16, 2015
-
CCS
Perplexed Messengers from the Cloud: Automated Security Analysis of Push-Messaging IntegrationsTo appear in the 22nd ACM Conference on Computer and Communications Security (CCS), Denver, Colorado, USA. October 12-16, 2015
-
USENIX Security
Finding Unknown Malice in 10 Seconds: Mass Vetting for New Threats at the Google-Play ScaleUSENIX Security Symposium (USENIX Security), 2015 PDF
-
SESA
Preface to special issue on miscellaneous emerging security problemsEAI Endorsed Transactions on Security and Safety, EAI, 2015, 15
-
ASIACCS
Towards Discovering and Understanding the Unexpected Hazards in Tailoring Antivirus Software for AndroidACM ASIACCS 2015, full paper
2014
- ICSE
-
ASE
Droidmarking: Resilient Software Watermarking for Impeding Android Application RepackagingASE 2014, Sept. 15-19, Sweden, 2014
-
SERE
AppMark: A Picture-based Watermark for Android AppsSERE 2014
-
JOE
Statically-Directed Dynamic Taint AnalysisJournal of Electronics, 2014
-
SIM
An Exploratory Study of White Hat Behaviors in a Web Vulnerability Disclosure ProgramACM CCS Workshop on Security Information Workers, 2014
-
SLSS
Timing-based Clone Detection on Android MarketsSLSS 2014
-
SLSS
Uncovering the Dilemmas on Antivirus Software Design in Modern Mobile PlatformsSLSS 2014
2013
-
SERE
Vulnerability-based Backdoors: Threats From Two-steps TrojansSERE 2013
-
ISPEC
Optimal Defense Strategies for DDoS Defender Using Bayesian Game ModelInformation Security Practice and Experience (ISPEC), 2013
-
ISPEC
VulLocator: Automatically Locating Vulnerable Code in Binary ProgramsInformation Security Practice and Experience (ISPEC), 2013
2012
-
CJC
Dynamic overflow vulnerability detection method based on finite CSPChinese journal of computers (in Chinese) ,2012
-
SCICHINA
Black-box testing based on colorful taint analysisSci China Inf Sci, 2012, 55: 171-183, doi: 10.1007/s11432-011-4291-y
2011
-
ICISC
AutoDunt: Dynamic Latency Dependence Analysis for Accurate Detection of Zero Day VulnerabilitiesICISC 2011, Springer
-
WISA
A Map-layer-based Access Control ModelWISA 2011, Springer, LNCS
2010
-
JOS
Multi-Cycle Vulnerability Discovery Model for PredictionJournal of Software (in Chinese), 2010, 21(9), 2367-2375
-
CJC
Exploring multiple execution paths based on dynamic lazy analysisChinese journal of computers (in Chinese), 2010, 33(3), 493-503
-
ICICS
Automatically Generating Patch in Binary Programs Using Attribute-based Taint AnalysisM. Soriano, S. Qing, and J. Lpez (Eds.): ICICS 2010, LNCS 6476, pp. 367--382. Springer, Heidelberg (2010)
2007
-
SEPCOM
SEPCOM: Customizable Zero Copy ModelProceedings of the Valuetools, 2007
Patents
-
CN Patent
CN. Patent 201510262774, An approach for Android application clone detection based on program dependence graph, Kai Chen, Bin Ma, September 23, 2015.
-
CN Patent
CN. Patent 2015104302255, An approach for dynamic memory layout inference, Kai Chen, Bin Ma, Yingjun Zhang, July 21, 2015.
-
CN Patent
CN. Patent 201510046705, Security check of user login interface in Android application, Bin Ma, Kai Chen, Yingjun Zhang, June 3, 2015.
-
CN Patent
CN. Patent 2014100897182, A approach for automatically generating watermarks of mobile applications, Kai Chen, Xianfeng Zhao, Yingjun Zhang, May 28, 2014.
-
CN Patent
CN. Patent 2014100558412, A approach for analyzing programs using optimized tree structure, Kai Chen, Xianfeng Zhao, Yingjun Zhang, May 14, 2014.
-
CN Patent
CN. Patent 201310104953.8, Locating vulnerabilities of binary executables, Kai Chen, Yingjun Zhang, Xianfeng Zhao, July 10, 2013.
-
CN Patent
CN. Patent 201110306771.X, An approach for constructing virtualized networks, Yi Qin, Dengguo Feng, Jiabin Wang, Kai Chen, Yifeng Lian, April 17, 2013.
-
CN Patent
CN. Patent 2011103593471, An approach for identificating the key attack paths in a system, Dengguo Feng, Di Wu, Yifeng Lian, Kai Chen, May 9, 2012.
-
CN Patent
CN. Patent 201210080975.0, An approach for identificating security threats and related attack paths, Di Wu, Dengguo Feng, Kai Chen, Jun Wei, Yifeng Lian, March 23, 2012.
-
CN Patent
CN. Patent ZL 200910081510.5, An approach for detecting vulnerabilities during attacks, Kai Chen, Duanfeng Si, Purui Su, August 17, 2011.
-
CN Patent
CN. Patent 200810239607.X, An approach for predicting of software vulnerabilities, Kai Chen, Dengguo Feng, Purui Su, May 20, 2009.
-
CN Patent
CN. Patent ZL 200610011477.5, An approach for driver-level package filtering on ethernet, Kai Chen, Dengguo Feng, Purui Su, November 19,2008.