Posts by Collection

portfolio

Dependency

Published:

A systematic study of dependency challenges in kernel fuzzing, including tools for measurement and mitigation.

SyzDescribe

Published:

Statically generates complete syscall descriptions for Linux kernel drivers to enable driver-specific fuzzing.

SyzSpec

Published:

Automatically infers syscall specifications for Linux kernel drivers using under-constrained symbolic execution.

publications

Automated Testing of Definition-Use Data Flow for Multithreaded Programs

Published in IEEE International Conference on Software Testing, Verification and Validation, ICST 17, 2017

Automated Testing of Definition-Use Data Flow for Multithreaded Programs

Recommended citation: Xiaodong Zhang, Zijiang Yang, Qinghua Zheng, Pei Liu, Jialiang Chang, Yu Hao, Ting Liu. "Automated Testing of Definition-Use Data Flow for Multithreaded Programs." IEEE International Conference on Software Testing, Verification and Validation, ICST 17 (2017).
Download Paper

Debugging Multithreaded Programs as if They Were Sequential

Published in IEEE International Conference on Software Analysis, Testing and Evolution, SATE 16, 2017

Debugging Multithreaded Programs as if They Were Sequential

Recommended citation: Xiaodong Zhang, Zijiang Yang, Qinghua Zheng, Yu Hao, Pei Liu, Lechen Yu, Ming Fan, Ting Liu. "Debugging Multithreaded Programs as if They Were Sequential." IEEE International Conference on Software Analysis, Testing and Evolution, SATE 16 (2017).
Download Paper

UBITect: A Precise and Scalable Method to Detect Use-before-Initialization Bugs in Linux Kernel

Published in ACM SIGSOFT International Symposium on Foundations of Software Engineering, FSE 20, 2020

UBITect: A Precise and Scalable Method to Detect Use-before-Initialization Bugs in Linux Kernel

Recommended citation: Yizhuo Zhai, Yu Hao, Hang Zhang, Daimeng Wang, Chengyu Song, Zhiyun Qian, Mohsen Lesani, Srikanth V. Krishnamurthy, Paul Yu. "UBITect: A Precise and Scalable Method to Detect Use-before-Initialization Bugs in Linux Kernel." ACM SIGSOFT International Symposium on Foundations of Software Engineering, FSE 20 (2020).
Download Paper

ConcSpectre: Be Aware of Forthcoming Malware Hidden in Concurrent Programs

Published in IEEE International Conference on Software Quality, Reliability, and Security, QRS 21, 2021

ConcSpectre: Be Aware of Forthcoming Malware Hidden in Concurrent Programs

Recommended citation: Yang Liu, Ming Fan, Ting Liu, Yu Hao, Zisen Xu, Kai Chen, Hao Chen, and Yan Cai. "ConcSpectre: Be Aware of Forthcoming Malware Hidden in Concurrent Programs." IEEE International Conference on Software Quality, Reliability, and Security, QRS 21 (2021).
Download Paper

Eluding ML-based Adblockers With Actionable Adversarial Examples

Published in Annual Computer Security Applications Conference, ACSAC 21, 2021

Eluding ML-based Adblockers With Actionable Adversarial Examples

Recommended citation: Shitong Zhu, Zhongjie Wang, Xun Chen, Shasha Li, Keyu Man, Umar Iqbal, Zhiyun Qian, Kevin S Chan, Srikanth V Krishnamurthy, Zubair Shafiq, Yu Hao, Guoren Li, Zheng Zhang, Xiaochen Zou. "Eluding ML-based Adblockers With Actionable Adversarial Examples." Annual Computer Security Applications Conference, ACSAC 21 (2021).
Download Paper

Statically Discovering High-Order Taint Style Vulnerabilities in OS Kernels

Published in ACM SIGSAC Conference on Computer and Communications Security, CCS 21, 2021

Statically Discovering High-Order Taint Style Vulnerabilities in OS Kernels

Recommended citation: Hang Zhang, Weiteng Chen, Yu Hao, Guoren Li, Yizhuo Zhai, Xiaochen Zou, Zhiyun Qian. "Statically Discovering High-Order Taint Style Vulnerabilities in OS Kernels." ACM SIGSAC Conference on Computer and Communications Security, CCS 21 (2021).
Download Paper

Themis: Ambiguity-Aware Network Intrusion Detection based on Symbolic Model Comparison

Published in ACM SIGSAC Conference on Computer and Communications Security, CCS 21, 2021

Themis: Ambiguity-Aware Network Intrusion Detection based on Symbolic Model Comparison

Recommended citation: Zhongjie Wang, Shitong Zhu, Keyu Man, Pengxiong Zhu, Yu Hao, Zhiyun Qian, Srikanth V. Krishnamurthy, Tom La Porta, Michael J. De Lucia. "Themis: Ambiguity-Aware Network Intrusion Detection based on Symbolic Model Comparison." ACM SIGSAC Conference on Computer and Communications Security, CCS 21 (2021).
Download Paper

Demystifying the Dependency Challenge in Kernel Fuzzing

Published in IEEE/ACM International Conference on Software Engineering, ICSE 22, 2022

Demystifying the Dependency Challenge in Kernel Fuzzing

Recommended citation: Yu Hao, Hang Zhang, Guoren Li, Xingyun Du, Zhiyun Qian, Ardalan Amiri Sani. "Demystifying the Dependency Challenge in Kernel Fuzzing." IEEE/ACM International Conference on Software Engineering, ICSE 22 (2022).
Download Paper

Progressive Scrutiny: Incremental Detection of UBI bugs in the Linux Kernel

Published in Network and Distributed System Security Symposium, NDSS 22, 2022

Progressive Scrutiny: Incremental Detection of UBI bugs in the Linux Kernel

Recommended citation: Yizhuo Zhai, Yu Hao, Zheng Zhang, Weiteng Chen, Guoren Li, Zhiyun Qian, Chengyu Song, Manu Sridharan, Srikanth V. Krishnamurthy, Trent Jaeger, Paul Yu. "Progressive Scrutiny: Incremental Detection of UBI bugs in the Linux Kernel." Network and Distributed System Security Symposium, NDSS 22 (2022).
Download Paper

Assisting Static Analysis with Large Language Models: A ChatGPT Experiment

Published in The ACM International Conference on the Foundations of Software Engineering, Ideas, Visions and Reflections, FSE 23 IVR, 2023

Assisting Static Analysis with Large Language Models: A ChatGPT Experiment

Recommended citation: Haonan Li, Yu Hao, Yizhuo Zhai, Zhiyun Qian. "Assisting Static Analysis with Large Language Models: A ChatGPT Experiment." The ACM International Conference on the Foundations of Software Engineering, Ideas, Visions and Reflections, FSE 23 IVR (2023).
Download Paper

SyzDescribe: Principled, Automated, Static Generation of Syscall Descriptions for Kernel Drivers

Published in IEEE Symposium on Security and Privacy, S\&P 23, 2023

SyzDescribe: Principled, Automated, Static Generation of Syscall Descriptions for Kernel Drivers

Recommended citation: Yu Hao, Guoren Li, Xiaochen Zou, Weiteng Chen, Shitong Zhu, Zhiyun Qian, Ardalan Amiri Sani. "SyzDescribe: Principled, Automated, Static Generation of Syscall Descriptions for Kernel Drivers." IEEE Symposium on Security and Privacy, S\&P 23 (2023).
Download Paper

Enhancing Static Analysis for Practical Bug Detection: An LLM-Integrated Approach

Published in ACM SIGPLAN International Conference on Object-Oriented Programming Systems, Languages, and Applications, OOPSLA 24, 2024

Enhancing Static Analysis for Practical Bug Detection: An LLM-Integrated Approach

Recommended citation: Haonan Li, Yu Hao, Yizhuo Zhai, Zhiyun Qian. "Enhancing Static Analysis for Practical Bug Detection: An LLM-Integrated Approach." ACM SIGPLAN International Conference on Object-Oriented Programming Systems, Languages, and Applications, OOPSLA 24 (2024).
Download Paper

SymBisect: Accurate Bisection for Fuzzer-Exposed Vulnerabilities

Published in USENIX Security Symposium 2024, 2024

SymBisect: Accurate Bisection for Fuzzer-Exposed Vulnerabilities

Recommended citation: Zheng Zhang, Yu Hao, Weiteng Chen, Xiaochen Zou, Xingyu Li, Haonan Li, Yizhuo Zhai, Zhiyun Qian, Billy Lau. "SymBisect: Accurate Bisection for Fuzzer-Exposed Vulnerabilities." USENIX Security Symposium 2024 (2024).
Download Paper

SyzBridge: Bridging the Gap in Exploitability Assessment of Linux Kernel Bugs in the Linux Ecosystem

Published in Network and Distributed System Security Symposium, NDSS 24, 2024

SyzBridge: Bridging the Gap in Exploitability Assessment of Linux Kernel Bugs in the Linux Ecosystem

Recommended citation: Xiaochen Zou, Yu Hao, Zheng Zhang, Juefei Pu, Weiteng Chen, Zhiyun Qian. "SyzBridge: Bridging the Gap in Exploitability Assessment of Linux Kernel Bugs in the Linux Ecosystem." Network and Distributed System Security Symposium, NDSS 24 (2024).
Download Paper

SyzGen++: Dependency Inference for Augmenting Kernel Driver Fuzzing

Published in IEEE Symposium on Security and Privacy, S\&P 24, 2024

SyzGen++: Dependency Inference for Augmenting Kernel Driver Fuzzing

Recommended citation: Weiteng Chen, Yu Hao, Zheng Zhang, Xiaochen Zou, Dhilung Kirat, Shachee Mishra, Douglas Schales, Jiyong Jang, Zhiyun Qian. "SyzGen++: Dependency Inference for Augmenting Kernel Driver Fuzzing." IEEE Symposium on Security and Privacy, S\&P 24 (2024).
Download Paper

SCAD: Towards a Universal and Automated Network Side-Channel Vulnerability Detection

Published in IEEE Symposium on Security and Privacy, S\&P 25, 2025

SCAD: Towards a Universal and Automated Network Side-Channel Vulnerability Detection

Recommended citation: Keyu Man, Zhongjie Wang, Yu Hao, Shenghan Zheng, Xin\'an Zhou, Yue Cao, Zhiyun Qian. "SCAD: Towards a Universal and Automated Network Side-Channel Vulnerability Detection." IEEE Symposium on Security and Privacy, S\&P 25 (2025).
Download Paper

SyzSpec: Specification Generation for Linux Kernel Fuzzing via Under-Constrained Symbolic Execution

Published in ACM SIGSAC Conference on Computer and Communications Security, CCS 25, 2025

SyzSpec: Specification Generation for Linux Kernel Fuzzing via Under-Constrained Symbolic Execution

Recommended citation: Yu Hao, Juefei Pu, Xingyu Li, Zhiyun Qian, Ardalan Amiri Sani. "SyzSpec: Specification Generation for Linux Kernel Fuzzing via Under-Constrained Symbolic Execution." ACM SIGSAC Conference on Computer and Communications Security, CCS 25 (2025).
Download Paper

NeuroMerge: ML-Guided State Merging for Efficient Symbolic Execution

Published in IEEE International Symposium on Software Reliability Engineering, ISSRE 26, 2026

NeuroMerge: ML-Guided State Merging for Efficient Symbolic Execution

Recommended citation: Shenghan Zhng, Shitong Zhu, Yu Hao, Xingyu Li, Keyu Man, Zhang Zheng, Qing Deng, Zhiyun Qian, Srikanth Krishnamurthy. "NeuroMerge: ML-Guided State Merging for Efficient Symbolic Execution." IEEE International Symposium on Software Reliability Engineering, ISSRE 26 (2026).
Download Paper

Tell You a Definite Answer: Whether Your Data is Tainted During Thread Scheduling

Published in IEEE Transactions on Software Engineering, \textbf{TSE}, 2099

Tell You a Definite Answer: Whether Your Data is Tainted During Thread Scheduling

Recommended citation: Xiaodong Zhang, Zijiang Yang, Qinghua Zheng, Yu Hao, Pei Liu, Ting Liu. "Tell You a Definite Answer: Whether Your Data is Tainted During Thread Scheduling." IEEE Transactions on Software Engineering, \textbf{TSE} (2099).
Download Paper

talks

teaching