2026
Attacking the First-Principle: A Black-Box Query-Free Targeted Mimicry Attack on Binary Function Classifiers.
The Tragedy of Convenience: Cascading User-Data Leakage from SMS-delivered URLs.
Investigating Shadow IT Use and Adoption in Educational Institutions and their Privacy Implications.
GraphQLify: Automated and Type Safety-Preserving GraphQL API Adoption.
Private Evaluation Protocol: Contamination-Resistant Black-Box Evaluation via Public-Slice Surrogates.
2025
2024
2023
Bilingual Problems: Studying the Security Risks Incurred by Native Extensions in Scripting Languages.
The Queen’s Guard: A Secure Enforcement of Fine-grained Access Control In Distributed Data Analytics Platforms.
A Tale of Reduction, Security and Correctness: Evaluating Program Debloating Paradigms and Their Compositions.
Evaluating Container Debloaters.
Blade: Towards Scalable Source Code Debloating.
SpanL: A Language for Screening Improper Use of Security APIs in High-level Languages.
2022
Being the Developers' Friend: Our Experience Developing a High-Precision Tool for Secure Coding.
Evaluation of Static Vulnerability Detection Tools with Java Cryptographic API Benchmarks.
“If security is required”: Engineering and Security Practices for Machine Learning-based IoT Devices.
2021
2020
Coding Practices and Recommendations of Spring Security for Enterprise Applications.
2019
Security Certification in Payment Card Industry: Testbeds, Measurements, and Recommendations.
CryptoGuard: High Precision Detection of Cryptographic Vulnerabilities in Massive-sized Java Projects.
CryptoAPI-Bench: A Comprehensive Benchmark on Java Cryptographic API Misuses.
2017
Before '17
Section
Patents
US Patents