VLDB 2026 Research / reviewers in the wild / expert
Gabriela F. Ciocarlie
dblp:21/4435 · also Gabriela F. Cretu, Gabriela F. Cretu-Ciocarlie, Gabriela Felicia Ciocarlie
· DBLP profile ↗
24ranked-venue papers
9as first author
8since 2021 · last 2025
0000-0002-4405-0742ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 4 first-author · 6 since 2021Software engineering, systems software and programming languages · 3 · 1 since 2021Systems, architecture and hardware · 2Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | AVOID: Automated Void Detection in STL FilesabstractAdditive manufacturing is a multi-billion dollar industry 21.58 billion in 2024), so its processes should be dependable and secure. Malicious actors can inject negative spaces, known as voids, in STL files, which can have a devastating impact on a final product's quality. Current ways of detecting voids use machine sensor or simulation data, and physical verification measures after printing. However, to the best of our knowledge, no method exists for detecting hidden voids solely at the STL level. Void detection at this level is inexpensive, and has the potential to detect voids in designs en masse. In this work, we proposeAVOID, a new approach to detect hidden voids. It both detects voids, and assesses their risk of weakening the manufactured part.AVOIDperforms risk assessment based on the size and location of each detected void. We empirically evaluatedAVOIDusing several large datasets, in total thousands of STL files, each with multiple hidden voids. We found thatAVOIDis highly accurate, with 97.7% recall, 98.1% precision, and 99% F1 on average across six data sets.AVOIDis also robust, scalable, and efficient. We find that high risk voids account for approximately 7% of all detected voids inserted randomly. Sarah Roscoe, Logan Hellbusch, Chamath Gunawardena, Jitender S. Deogun, Witawas Srisa-an, Yi Qian 0001, Gabriela F. Ciocarlie |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2024 | ACM CCS 2024 Doctoral SymposiumabstractACM CCS started Doctoral Symposium in 2024 to provide PhD students who are in the middle of their dissertation research an opportunity to present their work to the broader research community and get feedback. We briefly describe the design of the first CCS Doctoral Symposium, the rationale, and the submission/acceptance status. Gabriela F. Ciocarlie, Xinming Ou |
CCS | 1 |
| 2023 | Adversarial scratches: Deployable attacks to CNN classifiers
Loris Giulivi, Malhar Jere, Loris Rossi, Farinaz Koushanfar, Gabriela F. Ciocarlie, Briland Hitaj, Giacomo Boracchi |
Pattern Recognit. | 5 |
| 2023 | autoMPI: Automated Multiple Perspective Attack Investigation With Semantics Aware Execution PartitioningabstractMultiple Perspective attack Investigation (MPI) is a technique to partition application dependencies based on high-level semantics. It facilitates provenance analysis by generating succinct causal graphs. It involves an annotation process that identifies variables and data structures corresponding to the partitions and the communication channels between them. Though the amount of annotation is small, this process requires a detailed understanding of the source code. In this work, autoMPI, we extend the capability ofMPIby automating the identifying annotation requirements. We leverage a hybrid analysis approach, performing a differential analysis based on crafted inputs. Static analysis is conducted to identify the annotation sites within the application code afterward automatically. Our evaluation shows the proposed approach can significantly facilitate the annotation process. It correctly identifies all required annotation sites within an average 16 seconds analysis time for the majority of analyzed programs with average precision and recall 72.5% and 100%, respectively. Mohannad Alhanahnah, Shiqing Ma, Ashish Gehani, Gabriela F. Ciocarlie, Vinod Yegneswaran, Somesh Jha, Xiangyu Zhang 0001 |
IEEE Trans. Software Eng. | 4 |
| 2022 | Everything is Connected: Security and Reliability for Critical InfrastructureabstractFrom smart cities to smart cars and smart manufacturing, we live in a fully connected world. Critical infrastructure connects cyber and physical layers, and different critical infrastructures are in turn connected and interdependent (e.g., smart grids rely on cellular networks). However, the benefit of using such intelligent systems depends on their security and reliability just as much as it depends on their functionality. I work on approaches that operate across all these dimensions. This includes automated methods to identify and monitor Internet of Things devices, cellular networks and methods to detect and diagnose anomalous cells, and secure manufacturing, with formal methods to verify security properties. Gabriela F. Ciocarlie |
WISEC | 1 |
| 2022 | Wireless and Mobile Security Research and Teaching in the Post-Pandemic WorldabstractThe COVID-19 pandemic disrupted many aspects of our lives at a global scale. This includes the disruption of the research and teaching we perform within the security and privacy community. As the pandemic is weaning off, the lessons learnt during the pandemic can be very valuable in the future, both for navigating pandemic-like situations, and for accommodating greater inclination towards remote work and education. In this panel, international experts with various professional backgrounds and different points of view will discuss the impact they faced over the last two years, such as halting (or starting) specific research problems due to pandemic-related restrictions, unique challenges in deploying new experiments and how they overcame them, and finding novel ways to facilitate social events like conferences and hackathons. Anindya Maiti, Ahmad-Reza Sadeghi, Gabriela F. Ciocarlie, Patrick Tague |
WISEC | 3 |
| 2021 | ALchemist: Fusing Application and Audit Logs for Precise Attack Provenance without Instrumentation
Shiqing Ma, Zhuo Zhang 0002, Guanhong Tao 0001, Xiangyu Zhang 0001, Dongyan Xu, Vincent Urias, Han Wei Lin, Gabriela F. Ciocarlie, Vinod Yegneswaran, Ashish Gehani |
NDSS | 9 |
| 2021 | TRACE: Enterprise-Wide Provenance Tracking for Real-Time APT DetectionabstractWe present TRACE, a comprehensive provenance tracking system for scalable, real-time, enterprise-wide APT detection. TRACE uses static analysis to identify program unit structures and inter-unit dependences, such that the provenance of an output event includes the input events within the same unit. Provenance collected from individual hosts are integrated to facilitate construction of a distributed enterprise-wide causal graph. We describe the evolution of TRACE over a four-year period, during which our improvements to the system focused on performance, scalability, and fidelity. In this time span, the system call coverage increased (from 47 to 66) while the time and space overhead reduced by over one and two orders of magnitude, respectively. We also provide results from five adversarial engagements where an independent team of system evaluators conducted APT attacks and assessed system performance. The input from our system was used by three other teams to implement real-time APT detection logic. Retrospective analysis revealed that TRACE provided sufficient evidence to detect over 80% of the attack stages across all evaluations. By the last engagement, temporal and spatial overhead had been reduced significantly to 18% and 10%, respectively. Hassaan Irshad, Gabriela F. Ciocarlie, Ashish Gehani, Vinod Yegneswaran, Kyu Hyung Lee, Jignesh M. Patel, Somesh Jha, Yonghwi Kwon 0001, Dongyan Xu, Xiangyu Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2020 | ct-fuzz: Fuzzing for Timing LeaksabstractTesting-based methodologies like fuzzing are able to analyze complex software which is not amenable to traditional formal approaches like verification, model checking, and abstract interpretation. Despite enormous success a texposing countless security vulnerabilities in many popular software projects, applications of testing-based approaches mainly targeted checking traditional safety properties like memory safety. While unquestionably important, this class of properties does not precisely characterize other important security aspects such as information leakage, e.g., through side channels. In this work we extend testing-based software analysis methodologies to two-safety properties, which enables the precise discovery of information leaks in complex software. In particular, we present the ct-fuzz tool, which lends coverage-guided grey box fuzzers the ability to detect two safety property violations. Our approach is capable of exposing violations to any two-safety property expressed a sequality between two program traces. Empirically, we demonstrate that ct-fuzz swiftly reveals timing leaks in popular cryptographic implementations. Shaobo He 0002, Michael Emmi, Gabriela F. Ciocarlie |
ICST | 3 |
| 2020 | Behavioral simulation for smart contractsabstractWhile smart contracts have the potential to revolutionize many important applications like banking, trade, and supply-chain, their reliable deployment begs for rigorous formal verification. Since most smart contracts are not annotated with formal specifications, general verification of functional properties is impeded. Sidi Mohamed Beillahi, Gabriela F. Ciocarlie, Michael Emmi, Constantin Enea |
PLDI | 2 |
| 2018 | Risks and Benefits of Side-Channels in BattlefieldsabstractAs networked devices and applications make their way into our battlefields, their behaviors need to take into account these highly adversarial cyber-physical environments. On the dark side of the spectrum, undesired side-channels put our sensitive data at risk; hence, side-channel-protected devices and implementations should be promoted. On the bright side of the spectrum, side-channel analysis may be correlated with observed and hidden events, and enable causality inference and watermarking. This paper describes some unique risks and benefits that may be obtained from side-channel analyses in battlefields. Ioannis Agadakos, Gabriela F. Ciocarlie, Bogdan Copos, Tancrède Lepoint, Ulf Lindqvist, Michael E. Locasto, James Michaelis |
FUSION | 2 |
| 2018 | BlockCIS - A Blockchain-Based Cyber Insurance SystemabstractWhile the cyber insurance market has been growing significantly in recent years, its insurance providers face several challenges: first, there is a lack of standardized frameworks to rate ""cyber""; second, there's a shortage of relevant data to calculate premiums; and third, security postures of insured organizations constantly change. Unlike other types of insurance, cyber insurance requires creating a continuous feedback loop between customers and insurers. In this article, we introduce BlockCIS, a blockchain-based continuous monitoring and processing system for cyber insurance. BlockCIS aims to realize an automated, real-time, and immutable feedback loop between the insurer, its customer, third parties and potential auditors. As an example instantiation, we prototype BlockCIS using the open source Hyperledger Composer blockchain framework. Tancrède Lepoint, Gabriela F. Ciocarlie, Karim M. El Defrawy |
IC2E | 2 |
| 2018 | MCI : Modeling-based Causality Inference in Audit Logging for Attack Investigation
Yonghwi Kwon 0001, Fei Wang 0001, Weihang Wang 0001, Kyu Hyung Lee, Wen-Chuan Lee, Shiqing Ma, Xiangyu Zhang 0001, Dongyan Xu, Somesh Jha, Gabriela F. Ciocarlie, Ashish Gehani, Vinod Yegneswaran |
NDSS | 10 |
| 2018 | Kernel-Supported Cost-Effective Audit Logging for Causality Tracking
Shiqing Ma, Juan Zhai, Yonghwi Kwon 0001, Kyu Hyung Lee, Xiangyu Zhang 0001, Gabriela F. Ciocarlie, Ashish Gehani, Vinod Yegneswaran, Dongyan Xu, Somesh Jha |
USENIX ATC | 6 |
| 2017 | Low-Leakage Secure Search for Boolean Expressions
Fernando Krell, Gabriela F. Ciocarlie, Ashish Gehani, Mariana Raykova 0001 |
CT-RSA | 2 |
| 2016 | Diagnosis cloud: Sharing knowledge across cellular networksabstractDiagnosis functionality as a key component for automated Network Management (NM) systems allows rapid, machine-level interpretation of acquired data. In existing work, network diagnosis has focused on building “point solutions” using configuration and performance management, alarm, and topology information from one network. While the use of automated anomaly detection and diagnosis techniques within a single network improves operational efficiency, the knowledge learned by running these techniques across different networks that are managed by the same operator can be further maximized when that knowledge is shared. This paper presents a novel diagnosis cloud framework that enables the extraction and transfer of knowledge from one network to another. It also presents use cases and requirements. We present the implementation details of the diagnosis cloud framework for two specific types of models: topic models and Markov Logic Networks (MLNs). For each, we describe methods for assessing the quality of the local model, ranking models, adapting models to a new network, and performing detection and diagnosis. We performed experiments for the diagnosis cloud framework using real cellular network datasets. Our experiments demonstrate the feasibility of sharing topic models and MLNs. Gabriela F. Ciocarlie, Cherita Corbett, Eric Yeh, Christopher Connolly, Henning Sanneck, Muhammad Naseer ul Islam, Borislava Gajic, Szabolcs Nováczki, Kimmo Hätönen |
CNSM | 1 |
| 2014 | On the feasibility of deploying cell anomaly detection in operational cellular networksabstractThe Self-Organizing Networks (SON) concept includes the functional area known as self-healing, which aims to automate the detection and diagnosis of, and recovery from, network degradations and outages. In this paper, we build on our previous work [19] and study the feasibility of an operational deployment of an adaptive ensemble-method framework for modeling cell behavior. The framework uses Key Performance Indicators (KPIs) to determine cell-performance status. Our results, generated using real cellular network data, show that the computational overhead and the detection delay are sufficiently low for practical use of our methods to perform cell anomaly detection in operational networks. Gabriela F. Ciocarlie, Ulf Lindqvist, Kenneth Nitz, Szabolcs Nováczki, Henning Sanneck |
NOMS | 1 |
| 2014 | DCAD: Dynamic Cell Anomaly Detection for operational cellular networksabstractThe Self-Organizing Networks (SON) concept includes the functional area known as self-healing, which aims to automate the detection and diagnosis of, and recovery from, network degradations and outages. In this paper, we present Dynamic Cell Anomaly Detection (DCAD), a tool that implements an adaptive ensemble method for modeling cell behavior [5], [6]. DCAD uses Key Performance Indicators (KPIs) from real cellular networks to determine cell-performance status; enables KPI data exploration; visualizes anomalies; reduces the time required for successful detection of anomalies; and accepts user input. Gabriela F. Ciocarlie, Ulf Lindqvist, Kenneth Nitz, Szabolcs Nováczki, Henning Sanneck |
NOMS | 1 |
| 2013 | Detecting anomalies in cellular networks using an ensemble methodabstractThe Self-Organizing Networks (SON) concept includes the functional area known as self-healing, which aims to automate the detection and diagnosis of, and recovery from, network degradations and outages. This paper focuses on the problem of cell anomaly detection, addressing partial and complete degradations in cell-service performance, and it proposes an adaptive ensemble method framework for modeling cell behavior. The framework uses Key Performance Indicators (KPIs) to determine cell-performance status and is able to cope with legitimate system changes (i.e., concept drift). The results, generated using real cellular network data, suggest that the proposed ensemble method automatically and significantly improves the detection quality over univariate and multivariate methods, while using intrinsic system knowledge to enhance performance. Gabriela F. Ciocarlie, Ulf Lindqvist, Szabolcs Nováczki, Henning Sanneck |
CNSM | 1 |
| 2009 | Adaptive Anomaly Detection via Self-calibration and Dynamic Updating
Gabriela F. Ciocarlie, Angelos Stavrou, Michael E. Locasto, Salvatore J. Stolfo |
RAID | 1 |
| 2008 | Casting out Demons: Sanitizing Training Data for Anomaly SensorsabstractThe efficacy of anomaly detection (AD) sensors depends heavily on the quality of the data used to train them. Artificial or contrived training data may not provide a realistic view of the deployment environment. Most realistic data sets are dirty; that is, they contain a number of attacks or anomalous events. The size of these high-quality training data sets makes manual removal or labeling of attack data infeasible. As a result, sensors trained on this data can miss attacks and their variations. We propose extending the training phase of AD sensors (in a manner agnostic to the underlying AD algorithm) to include a sanitization phase. This phase generates multiple models conditioned on small slices of the training data. We use these "micro- models" to produce provisional labels for each training input, and we combine the micro-models in a voting scheme to determine which parts of the training data may represent attacks. Our results suggest that this phase automatically and significantly improves the quality of unlabeled training data by making it as "attack-free" and "regular" as possible in the absence of absolute ground truth. We also show how a collaborative approach that combines models from different networks or domains can further refine the sanitization process to thwart targeted training or mimicry attacks against a single site. Gabriela F. Ciocarlie, Angelos Stavrou, Michael E. Locasto, Salvatore J. Stolfo, Angelos D. Keromytis |
SP | 1 |
| 2007 | From STEM to SEAD: Speculative Execution for Automated Defense
Michael E. Locasto, Angelos Stavrou, Gabriela F. Ciocarlie, Angelos D. Keromytis |
USENIX ATC | 3 |
| 2006 | Intrusion and anomaly detection model exchange for mobile ad-hoc networksabstractMobile Ad-hoc NETworks (MANETs) pose unique security requirements and challenges due to their reliance on open, peer-to-peer models that often don't require authentication between nodes. Additionally, the limited processing power and battery life of the devices used in a MANET also prevent the adoption of heavy-duty cryptographic techniques. While traditional misuse-based Intrusion Detection Systems (IDSes) may work in a MANET, watching for packet dropouts or unknown outsiders is difficult as both occur frequently in both malicious and non-malicious traffic. Anomaly detection approaches hold out more promise, as they utilize learning techniques to adapt to the wireless environment and flag malicious data. The anomaly detection model can also create device behavior profiles, which peers can utilize to help determine its trustworthiness. However, computing the anomaly model itself is a time-consuming and processor-heavy task. To avoid this, we propose the use of model exchange as a device moves between different networks as a means to minimize computation and traffic utilization. Any node should be able to obtain peers' model(s) and evaluate it against its own model of "normal" behavior. We present this model, discuss scenarios in which it may be used, and provide preliminary results and a framework for future implementation. Gabriela F. Ciocarlie, Janak J. Parekh, Ke Wang 0009, Salvatore J. Stolfo |
CCNC | 1 |
| 2005 | Anomalous Payload-Based Worm Detection and Signature Generation
Ke Wang 0009, Gabriela F. Ciocarlie, Salvatore J. Stolfo |
RAID | 2 |