VLDB 2026 Research / reviewers in the wild / expert
Robert J. Walls
dblp:17/9458
· DBLP profile ↗
21ranked-venue papers
7as first author
7since 2021 · last 2025
0000-0002-1338-6403ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 3 first-author · 3 since 2021Systems, architecture and hardware · 4 · 2 since 2021Computer networks · 2 · 2 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | 'We just did not have that on the embedded system': Insights and Challenges for Securing Microcontroller Systems from the Embedded CTF CompetitionsabstractMicrocontroller systems are integral to our daily lives, powering mission-critical applications such as vehicles, medical devices, and industrial control systems. Therefore, it is essential to investigate and outline the challenges encountered in developing secure microcontroller systems. While previous research has focused solely on microcontroller firmware analysis to identify and characterize vulnerabilities, our study uniquely leverages data from the 2023 and 2024 MITRE eCTF team submissions and post-competition interviews. This approach allows us to dissect the entire lifecycle of secure microcontroller system development from both technical and perceptual perspectives, providing deeper insights into how these vulnerabilities emerge in the first place. Zheyuan Ma, Gaoxiang Liu, Alex Eastman, Kai Kaufman, Md. Armanuzzaman, Xi Tan 0002, Katherine Jesse, Robert J. Walls, Ziming Zhao 0001 |
CCS | 8 |
| 2025 | ReFINE: A Reactive and Fine-Grained Scheduling Framework For Concurrency on General Purpose GPUsabstractConcurrency can be an effective technique for maximizing system utilization in general purpose GPUs (GPGPUs), enabling lower priority, best-effort tasks to run alongside higher-priority, latency-sensitive tasks to fully exploit available GPU resources. However, existing GPGPU concurrency mechanisms are inadequate for such workloads, as they lack the necessary components to sufficiently prioritize latency-sensitive tasks and ensure they meet their turnaround time deadlines. Guin Gilman, Robert J. Walls |
SPAA | 2 |
| 2025 | REVDECODE: Enhancing Binary Function Matching with Context-Aware Graph Representations and Relevance Decoding
Tongwei Ren, Ronghan Che, Guin Gilman, Lorenzo De Carli, Robert J. Walls |
USENIX Security Symposium | 5 |
| 2022 | Holistic Control-Flow Protection on Real-Time Embedded Systems with Kage
Yufei Du, Zhuojia Shen, Komail Dharsee, Jie Zhou 0022, Robert J. Walls, John Criswell |
USENIX Security Symposium | 5 |
| 2021 | Data-Free Model ExtractionabstractCurrent model extraction attacks assume that the adversary has access to a surrogate dataset with characteristics similar to the proprietary data used to train the victim model. This requirement precludes the use of existing model extraction techniques on valuable models, such as those trained on rare or hard to acquire datasets. In contrast, we propose data-free model extraction methods that do not require a surrogate dataset. Our approach adapts techniques from the area of data-free knowledge transfer for model extraction. As part of our study, we identify that the choice of loss is critical to ensuring that the extracted model is an accurate replica of the victim model. Further-more, we address difficulties arising from the adversary’s limited access to the victim model in a black-box setting. For example, we recover the model’s logits from its probability predictions to approximate gradients. We find that the proposed data-free model extraction approach achieves high-accuracy with reasonable query complexity – 0.99× and 0.92× the victim model accuracy on SVHN and CIFAR- 10 datasets given 2M and 20M queries respectively. Jean-Baptiste Truong, Pratyush Maini, Robert J. Walls, Nicolas Papernot |
CVPR | 3 |
| 2021 | Memory-Efficient Deep Learning Inference in Trusted Execution EnvironmentsabstractThis study identifies and proposes techniques to alleviate two key bottlenecks to executing deep neural networks in trusted execution environments (TEEs): page thrashing during the execution of convolutional layers and the decryption of large weight matrices in fully-connected layers. For the former, we propose a novel partitioning scheme, y-plane partitioning, designed to (i) provide consistent execution time when the layer output is large compared to the TEE secure memory; and (ii) significantly reduce the memory footprint of convolutional layers. For the latter, we leverage quantization and compression. In our evaluation, the proposed optimizations incurred latency overheads ranging from 1.09X to 2X baseline for a wide range of TEE sizes; in contrast, an unmodified implementation incurred latencies of up to 26X when running inside of the TEE. Jean-Baptiste Truong, William Gallagher, Tian Guo 0001, Robert J. Walls |
IC2E | 4 |
| 2021 | Characterizing concurrency mechanisms for NVIDIA GPUs under deep learning workloads
Guin Gilman, Robert J. Walls |
Perform. Evaluation | 2 |
| 2020 | Characterizing and Modeling Distributed Training with Transient Cloud GPU ServersabstractCloud GPU servers have become the de facto way for deep learning practitioners to train complex models on large-scale datasets. However, it is challenging to determine the appropriate cluster configuration-e.g., server type and number-for different training workloads while balancing the trade-offs in training time, cost, and model accuracy. Adding to the complexity is the potential to reduce the monetary cost by using cheaper, but revocable, transient GPU servers.In this work, we analyze distributed training performance under diverse cluster configurations using CM-DARE, a cloud-based measurement and training framework. Our empirical datasets include measurements from three GPU types, six geographic regions, twenty convolutional neural networks, and thousands of Google Cloud servers. We also demonstrate the feasibility of predicting training speed and overhead using regression-based models. Finally, we discuss potential use cases of our performance modeling such as detecting and mitigating performance bottlenecks. Shijian Li, Robert J. Walls, Tian Guo 0001 |
ICDCS | 2 |
| 2020 | DRAB-LOCUS: An Area-Efficient AES Architecture for Hardware Accelerator Co-Location on FPGAsabstractAdvanced Encryption Standard (AES) implementations on Field Programmable Gate Arrays (FPGA) commonly focus on maximizing throughput at the cost of utilizing high volumes of FPGA slice logic. High resource usage limits systems' abilities to implement other functions (such as video processing or machine learning) that may want to share the same FPGA resources. In this paper, we address the shared resource challenge by proposing and evaluating a low-area, but high-throughput, AES architecture. In contrast to existing work, our DSP/RAM-Based Low-CLB Usage (DRAB-LOCUS) architecture leverages block RAM tiles and Digital Signal Processing (DSP) slices to implement the AES Sub Bytes, Mix Columns, and Add Round Key sub-round transformations, reducing resource usage by a factor of 3 over traditional approaches. To achieve area-efficiency, we built an inner-pipelined architecture using the internal registers of block RAM tiles and DSP slices. Our DRAB-LOCUS architecture features a 12-stage pipeline capable of producing 7.055 Gbps of interleaved encrypted or decrypted data, and only uses 909 Look Up tables, 593 Flip Flops, 16 block RAMs, and 18 DSP slices in the target device. Jacob T. Grycel, Robert J. Walls |
ISCAS | 2 |
| 2020 | Silhouette: Efficient Protected Shadow Stacks for Embedded Systems
Jie Zhou 0022, Yufei Du, Zhuojia Shen, Lele Ma, John Criswell, Robert J. Walls |
USENIX Security Symposium | 6 |
| 2019 | Control-Flow Integrity for Real-Time Embedded SystemsabstractAttacks on real-time embedded systems can endanger lives and critical infrastructure. Despite this, techniques for securing embedded systems software have not been widely studied. Many existing security techniques for general-purpose computers rely on assumptions that do not hold in the embedded case. This paper focuses on one such technique, control-flow integrity (CFI), that has been vetted as an effective countermeasure against control-flow hijacking attacks on general-purpose computing systems. Without the process isolation and fine-grained memory protections provided by a general-purpose computer with a rich operating system, CFI cannot provide any security guarantees. This work proposes RECFISH, a system for providing CFI guarantees on ARM Cortex-R devices running minimal real-time operating systems. We provide techniques for protecting runtime structures, isolating processes, and instrumenting compiled ARM binaries with CFI protection. We empirically evaluate RECFISH and its performance implications for real-time systems. Our results suggest RECFISH can be directly applied to binaries without compromising real-time performance; in a test of over six million realistic task systems running FreeRTOS, 85% were still schedulable after adding RECFISH. Robert J. Walls, Nicholas F. Brown, Thomas Le Baron, Craig A. Shue, Hamed Okhravi, Bryan C. Ward |
ECRTS | 1 |
| 2019 | Account Lockouts: Characterizing and Preventing Account Denial-of-Service Attacks
Matthew R. Squires, Curtis R. Taylor, Robert J. Walls, Craig A. Shue |
SecureComm (2) | 4 |
| 2016 | BinDNN: Resilient Function Matching Using Deep Learning
Nathaniel Lageman, Eric D. Kilmer, Robert J. Walls, Patrick D. McDaniel |
SecureComm | 3 |
| 2016 | Domain-Z: 28 Registrations Later Measuring the Exploitation of Residual Trust in DomainsabstractAny individual that re-registers an expired domain implicitly inherits the residual trust associated with the domain's prior use. We find that adversaries can, and do, use malicious re-registration to exploit domain ownership changes - undermining the security of both users and systems. In fact, we find that many seemingly disparate security problems share a root cause in residual domain trust abuse. With this study we shed light on the seemingly unnoticed problem of residual domain trust by measuring the scope and growth of this abuse over the past six years. During this time, we identified 27,758 domains from public blacklists and 238,279 domains resolved by malware that expired and then were maliciously re-registered. To help address this problem, we propose a technical remedy and discuss several policy remedies. For the former, we develop Alembic, a lightweight algorithm that uses only passive observations from the Domain Name System (DNS) to flag potential domain ownership changes. We identify several instances of residual trust abuse using this algorithm, including an expired APT domain that could be used to revive existing infections. Charles Lever, Robert J. Walls, Yacin Nadji, David Dagon, Patrick D. McDaniel, Manos Antonakakis |
IEEE Symposium on Security and Privacy | 2 |
| 2015 | Measuring the Impact and Perception of Acceptable AdvertisementsabstractIn 2011, Adblock Plus---the most widely-used ad blocking software---began to permit some advertisements as part of their Acceptable Ads program. Under this program, some ad networks and content providers pay to have their advertisements shown to users. Such practices have been controversial among both users and publishers. In a step towards informing the discussion about these practices, we present the first comprehensive study of the Acceptable Ads program. Specifically, we characterize which advertisements are allowed and how the whitelisting has changed since its introduction in 2011. We show that the list of filters used to whitelist acceptable advertisements has been updated on average every 1.5 days and grew from 9 filters in 2011 to over 5,900 in the Spring of 2015. More broadly, the current whitelist triggers filters on 59% of the top 5,000 websites. Our measurements also show that the program allows advertisements on 2.6 million parked domains. Lastly, we take the lessons learned from our analysis and suggest ways to improve the transparency of the whitelisting process. Robert J. Walls, Eric D. Kilmer, Nathaniel Lageman, Patrick D. McDaniel |
Internet Measurement Conference | 1 |
| 2015 | Discovering specification violations in networked software systemsabstractPublicly released software implementations of network protocols often have bugs that arise from latent specification violations. We present Ape, a technique that explores program behavior to identify potential specification violations. Ape overcomes the challenge of exploring the large space of behavior by dynamically inferring precise models of behavior, stimulating unobserved behavior likely to lead to violations, and refining the behavioral models with the new, stimulated behavior. Ape can (1) discover new specification violations, (2) verify that violations are removed, (3) identify related violations in other versions and implementations of the protocols, and (4) generate tests. Ape works on binaries and requires a lightweight description of the protocol's network messages and a violation characteristic. We use Ape to rediscover the known heartbleed bug in OpenSSL, and discover one unknown bug and two unexpected uses of three popular BitTorrent clients. Manual inspection of Ape-produced artifacts reveals four additional, previously unknown specification violations in OpenSSL and μTorrent. Robert J. Walls, Yuriy Brun, Marc Liberatore, Brian Neil Levine |
ISSRE | 1 |
| 2013 | Measurement and analysis of child pornography trafficking on P2P networksabstractPeer-to-peer networks are the most popular mechanism for the criminal acquisition and distribution of child pornography (CP). In this paper, we examine observations of peers sharing known CP on the eMule and Gnutella networks, which were collected by law enforcement using forensic tools that we developed. We characterize a year's worth of network activity and evaluate different strategies for prioritizing investigators' limited resources. The highest impact research in criminal forensics works within, and is evaluated under, the constraints and goals of investigations. We follow that principle, rather than presenting a set of isolated, exploratory characterizations of users. Ryan Hurley, Swagatika Prusty, Hamed Soroush, Robert J. Walls, Jeannie R. Albrecht, Emmanuel Cecchet, Brian Neil Levine, Marc Liberatore, Brian Lynn, Janis Wolak |
WWW | 4 |
| 2012 | Functional Privacy or Why Cookies Are Better with Milk
Robert J. Walls, Shane S. Clark, Brian Neil Levine |
HotSec | 1 |
| 2011 | Forensic Triage for Mobile Phones with DEC0DE
Robert J. Walls, Erik G. Learned-Miller, Brian Neil Levine |
USENIX Security Symposium | 1 |
| 2011 | Effective Digital Forensics Research Is Investigator-Centric
Robert J. Walls, Brian Neil Levine, Marc Liberatore, Clay Shields |
HotSec | 1 |
| 2011 | Liquid: A detection-resistant covert timing channel based on IPD shaping
Robert J. Walls, Kush Kothari, Matthew Wright 0001 |
Comput. Networks | 1 |