Publication / Talk
Peer-reviewed papers, journals, and talks.
2026
-
(CCS) 𝑃𝐶²: Politically Controversial Content Generation via Jailbreaking Attacks on GPT-based Text-to-Image Models
-
(TCC) AccelFaaS: Accelerating FaaS via Pre-warmed Memory and Control Channel Offloading
-
(DAC) TDSnap: Enabling Secure Function-as-a-Service with Trusted Domain Snapshot
-
(ICLR) SafeMoE: Safe Fine-Tuning for MoE LLMs by Aligning Harmful Input Routing
-
(NSDI) HybridMesh: A Hardware-software Hybrid Approach for Accelerating Service Mesh Ingress
-
(INFOCOM) RDNet: An RDMA-aware Container Network Interface for Cloud Environments
2025
-
(COMSEC) BEACON: Automatic Container Policy Generation using Environment-aware Dynamic Analysis
-
(COMSEC) SECTRACER: A Framework for Uncovering the Root Causes of Network Intrusions via Security Provenance
-
(ESWA) PassREfinder-FL: Privacy-Preserving Credential Stuffing Risk Prediction via Graph-Based Federated Learning for Representing Password Reuse between Websites
-
(ACSAC) MoEvil: Poisoning Expert to Compromise the Safety of Mixture-of-Experts LLMs (Distinguished Paper Award)
-
(EMNLP) Improbable Bigrams Expose Vulnerabilities of Incomplete Tokens in Byte-Level Tokenizers
-
(Usenix Security) Refusal Is Not an Option: Unlearning Safety Alignment of Large Language Models
-
(SIGCOMM Shorts) HardMesh: Enabling High-performance Service Mesh Ingress Processing with SmartNICs
-
(Access) CR-ATTACKER: Exploiting Crash-reporting Systems using Timing Gap and Unrestricted File-based Workflow
-
(Usenix Security) When LLMs Go Online: The Emerging Threat of Web-Enabled LLMs
-
(NAACL Findings) Obliviate: Neutralizing Task-agnostic Backdoors within the Parameter-efficient Fine-tuning Paradigm
-
(NAACL Findings) Claim-Guided Textual Backdoor Attack for Practical Applications
-
(ASIACCS) AVXProbe: Enhancing Website Fingerprinting with Side-Channel-Assisted Kernel-Level Traces
-
(INFOCOM) MUFFLER: Secure Tor Traffic Obfuscation with Dynamic Connection Shuffling and Splitting
-
(KDD) Covering Cracks in Content Moderation: Delexicalized Distant Supervision for Illicit Drug Jargon Detection
-
(NDSS) Tweezers: A Framework for Security Event Detection via Event Attribution-centric Tweet Embedding
2024
-
(Access) Uncovering Threats in Container Systems: A Study on Misconfigured Container Components in the Wild
-
(Access) gShock: A GNN-based Fingerprinting System for Permissioned Blockchain Networks over Encrypted Channels
-
(Access) CENSor: Detecting Illicit Bitcoin Operation via GCN-based Hyperedge Classification
-
(Access) BotFence: A Framework for Network-Enriched Botnet Detection and Response with SmartNICs
-
(TIFS) Ambusher: Exploring the Security of Distributed SDN Controllers through Protocol State Fuzzing
-
(TCC) Hyperion: Hardware-based High-performance and Secure System for Container Networks
-
(ICDCS) HardWhale: A Hardware-isolated Network Security Enforcement System for Cloud Environments
-
(NAACL Findings) Ignore Me But Don’t Replace Me: Utilizing Non-Linguistic Elements for Pretraining on the Cybersecurity Domain
-
(Computer Networks) Enhancing Security in SDN: Systematizing Attacks and Defenses from a Penetration Perspective
-
(NDSS) DRAINCLoG: Detecting Rouge Accounts with Illegally-obtained NFTs using Classifiers Learned on Graphs
-
(IEEE S&P) PassREfinder: Credential Stuffing Risk Prediction by Representing Password Reuse between Websites on a Graph
2023
-
(Poster) Towards a Secure and Practical System to Obfuscate Tor Network Traffic
-
(SoCC) Cryonics: Trustworthy Function-as-a-Service using Snapshot-based Enclaves
-
(SoCC) HELIOS: Hardware-assisted High-performance Security Extension for Cloud
-
(IMC) Evolving Bots: The New Generation of Comment Bots and their Underlying Scam Campaigns in YouTube
-
(COMSEC) AVX-TSCHA: Leaking Information Through AVX Extensions in Commercial Processors
-
(RAID) Witnessing Erosion of Membership Inference Defenses: Understanding Effects of Data Drift in Membership Privacy
-
(ACL) DarkBERT: A Language Model for the Dark Side of the Internet
-
(DAC) AVX Timing Side-Channel Attacks against Address Space Layout Randomization
-
(NDSS) Partitioning Ethereum without Eclipsing It
2022
-
(COMSEC) Extended SDN Data Plane Architecture for In-Network Security Services
-
(Access) FuzzDocs: An Automated Security Evaluation Framework for IoT
-
(TON) Secure Inter-Container Communications using XDP/eBPF
-
(ACSAC) Heimdallr: Fingerprinting SD-WAN Control-Plane Architecture via Encrypted Control Traffic
-
(ACSAC) Closing the Loophole: Rethinking Reconstruction Attacks in Federated Learning from a Privacy Standpoint
-
(JNCA) Reconfigurable Regular Expression Matching Architecture for Real-time Pattern Update and Payload Inspection
-
(CIKM) Meta-Path-based Fake News Detection Leveraging Multi-level Social Context Information
-
(ICNP) MECaNIC: SmartNIC to Assist URLLC Processing in Multi-Access Edge Computing Platforms
-
(COMSEC) Vulcan: Automatic Extraction and Analysis of Cyber Threat Intelligence from Unstructured Text
-
(NAACL) Shedding New Light on the Language of the Dark Web
-
(TON) A Framework for Policy Inconsistency Detection in Software-Defined Networks
-
(NDSS) EqualNet: A Secure and Practical Defense for Long-term Network Topology Obfuscation
2021
-
(ACSAC) Reinhardt: Real-time Reconfigurable Hardware Architecture for Regular Expression Matching in DPI
-
(SCN) Understanding Block and Transaction Logs of Permissionless Blockchain Networks
-
(TIFS) BottleNet: Hiding Network Bottlenecks using SDN-based Topology Deception
-
(ICDCS) Behind Block Explorers: Public Blockchain Measurement and Security Implication
2020
-
(COMNET-J) Formullar: An FPGA-based network testing tool for flexible and precise measurement of Ultra-Low Latency networking systems
-
(JONS) Mobius: Packet re-processing hardware architecture for rich policy handling on a network processor
-
(TIFS) GapFinder: Finding Inconsistency of Security Information from Unstructured Text
-
(ATC) BASTION: A Security Enforcement Network Stack for Container Networks
-
(Eurosys) (Poster) AE-NIDS : Automated Evolving SDN-based Network Intrusion Detection System
-
(COMSEC) A Comprehensive Security Assessment Framework for Software-Defined Networks
-
(INFOCOM) AudiSDN: Automated Detection of Network Policy Inconsistencies in Software-Defined Networks
2019
-
(TIFS) Automated permission model generation for securing SDN control-plane
-
(CCS) (Poster) TCLP: Enforcing Least Privileges to Prevent Containers from Kernel Vulnerabilities
-
(COMNET) SODA: A Software-defined Security Framework for IoT Environments
-
(APNET) Rethinking Network Policy Coordination: A Database Perspective
-
(IoT-J) MC-SDN: Supporting Mixed-Criticality Real-Time Communication Using Software-Defined Networking
-
(TON) Operator-defined Reconfigurable Network OS for Software-Defined Networks
-
(DIMVA) DPX: Data-Plane eXtensions for SDN Security Service Instantiation
-
(INTERPOL World) Darknet. How will the darknet of future be like?
-
(COMNET) Astraea: Towards an Effective and Usable Application Permission System for SDN
-
(WWW) Doppelgängers on the Dark Web: A Large-scale Assessment on Phishing Hidden Web Services
-
(NDSS) Cybercriminal Minds: An investigative study of cryptocurrency abuses in the Dark Web
2018
-
(PRDC) (Fast abstract) Towards a security-enhanced cloud platform
-
(ACM NFV/SDN) RE-CHECKER: Towards Secure RESTful Service in Software-Defined Networking
-
(Physica A) Bypass rewiring and extreme robustness of Eulerian networks
-
(CCS) (Poster) Knowledge Seeking on The Shadow Brokers
-
(EYRE) Toward Semantic Assessment of Vulnerability Severity: A Text Mining Approach
-
(RTSS) MC-SDN: Supporting Mixed-Criticality Scheduling on Switched-Ethernet Using Software-Defined Networking
-
(ICNP) INDAGO: A New Framework For Detecting Malicious SDN Applications
-
(BlackHat USA) ( Briefing) The Finest Penetration Testing Framework for Software-Defined Networks
-
(BlackHat USA) (ARSENAL) DELTA: SDN Security Evaluation Framework
-
(ICCCN) CloudRand: Building Heterogeneous and Moving-target Network Interfaces
-
(SIGCOMM-SecSON) AEGIS: An Automated Permission Generation and Verification System for SDN
-
(SIGCOMM-SecSON) HEX Switch: Hardware-assisted security extensions of OpenFlow
-
(AsiaCCS) Who is knocking on Telnet Port: A Large-Scale Empirical Study of Network Scanning
-
(SOSR) Probius: Automated Approach for VNF and Service Chain Analysis in Software-Defined NFV
-
(SCN) NOSArmor: Building a Secure Network Operating System
-
(SCN) Duo: Software Defined Intrusion Tolerant System using Dual Cluster
-
(INFOCOM) Barista: An Event-centric NOS Composition Framework for Software-Defined Networks
-
(IT DEFENSE) Attacking SDN Infrastructure
2017
-
(ACSAC) A Security-Mode for Carrier-Grade SDN Controllers
-
(TON) Flow Wars: Systemizing the Attack Surface and Defenses in Software-Defined Networks
-
(SoCC) (Poster) Bridging the Architectural Gap between NOS Design Principles in Software-Defined Networks
-
(BlackHat USA) (ARSENAL) DELTA: SDN Security Evaluation Framework
-
(ICCCN) Mobility of Everything (MoE): An Integrated and Distributed Mobility Management
-
(DSN) (Fast abstract) Software-Defined HoneyNet: Towards Mitigating Link Flooding Attacks
-
(DSN) Athena: A Framework for Scalable Anomaly Detection in Software-Defined Networks
-
(NDSS) DELTA: A Security Assessment Framework for Software-Defined Networks
-
(SCN) A Collaborative Approach on Host and Network Level Android Malware Detection
2016
-
(ICCCN) Enhancing Network Security through Software-Defined Networking (SDN)
-
(BlackHat USA) (Briefing) Attacking SDN Infrastructure: Are We Ready for the Next-Gen Networking?
-
(ATC) (Poster) Barista: A Highly Composable NOS Brewing Framework for Software-Defined Networks
-
(ONS) Security Mode ONOS
-
(ONF) A Penetration Testing Framework for Software-Defined Networks
-
(ICC) QoSE:Quality of SEcurity (A network security module using a distributed NFV)
-
(INFOCOM) Just-in-time WLANs: On-demand Interference-managed WLAN Infrastructures
-
(ACM SDN/NFV) SHIELD: An Automated Framework for Static Analysis of SDN Applications
-
(ACM SDN/NFV) UNISAFE: A union of security actions for software switches
-
(ACM SDN/NFV) The smaller, the shrewder: a simple malicious application can kill an entire SDN environment
2015
-
(SCN) Vulnerabilities of Network OS and Mitigation with State-based Permission System
-
(CoolSDN) SPIRIT: A Framework for Profiling SDN
-
(SECURECOMM) (extended abstract) A Collaborative Approach on Behaivor-Based Android Malware Detection
-
(ONF) Security vulnerabilities in open-source SDN controllers
-
(TIFS) A First Step Towards Network Security Virtualization: From Concept To Prototype
-
(COMNET) Enabling Security Functions with SDN: A Feasibility Study
-
(SOSR) (Demo) A Playground for Software-defined Networking Security
-
(ONF) SDN Security Research Overview