From Assistance to Autonomy: An Empirical Study of AI Use in a Live Capture-the-Flag (CTF) CompetitionTingxuag TangNicolas Janiset al.2026USENIX Security 2026Conference paper
One Bug, Hundreds Behind: LLMs for Large-Scale Bug DiscoveryQiushi WuYue Xiaoet al.2026ICML 2026Conference paper
Lessons from Penetration Tests on Large-Scale Agent SystemsKevin EykholtDhilung Kiratet al.2026S&P 2026Workshop paper
Trust but Verify: Uncovering the Hidden Risks of Inaccurate SBOMs with JBomAuditYue XiaoDhilung Kiratet al.2025OSSNA 2025Talk
JBomAudit: Assessing the Landscape, Compliance, and Security Implications of Java SBOMsYue XiaoDhilung Kiratet al.2025NDSS 2025Conference paper
Uncovering Supply Chain Attack with Code Genome FrameworkDhilung KiratJiyong Janget al.2024Black Hat USA 2024Talk
SyzGen++: Dependency Inference for Augmenting Kernel Driver FuzzingWeiteng ChenYu Haoet al.2024S&P 2024Conference paper
Automated Synthesis of Effect Graph Policies for Microservice-Aware Stateful System Call SpecializationWill BlairFred Araujoet al.2024S&P 2024Conference paper
EdgeTorrent: Real-time Temporal Graph Representations for Intrusion DetectionIsaiah J. KingXiaokui Shuet al.2023RAID 2023Conference paper
URET: Universal Robustness Evaluation Toolkit (for Evasion)Kevin EykholtTaesung Leeet al.2023USENIX Security 2023Conference paper