VLDB 2026 Research / reviewers in the wild / expert
Aditya Pakki
dblp:248/1695
· DBLP profile ↗
5ranked-venue papers
1as first author
2since 2021 · last 2022
0000-0003-4704-2606ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Unleashing Coveraged-Based Fuzzing Through Comprehensive, Efficient, and Faithful Exploitable-Bug ExposingabstractFuzzing has become an essential means of finding software bugs. Bug finding through fuzzing requires two parts—exploring code paths to reach bugs and exposing bugs when they are reached. Existing fuzzing research has primarily focused on improving code coverage but not on exposing bugs. Sanitizers such as AddressSanitizer (ASAN) and MemorySanitizer (MSAN) have been the dominating tools for exposing bugs. However, sanitizer-based bug exposing has the following limitations. (1) sanitizers are not compatible with each other. (2) sanitizers incur significant runtime overhead. (3) sanitizers may generate false positives, and (4) exposed bugs may not be exploitable. To address these limitations, we proposeExpozzer, a fuzzing system that can expose bugs comprehensively, efficiently, and faithfully. The intuition ofExpozzeris to detect bugs through divergences in a properly diversified dual-execution environment, which does not require maintaining or checking execution metadata. We design a practical and deterministic dual-execution engine, a co-design for dual-execution and fuzzers, bug-sensitive diversification, comprehensive, and efficient divergence detection to ensure the effectiveness ofExpozzer. The results of evaluations show thatExpozzercan detect not only CVE-assigned vulnerabilities reliably, but also new vulnerabilities in well-tested real-world programs.Expozzeris 10 times faster than MemorySanitizer and is similar to AddressSanitizer. Bowen Wang 0014, Kangjie Lu, Qiushi Wu, Aditya Pakki |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | Understanding and Detecting Disordered Error Handling with Precise Function Pairing
Qiushi Wu, Aditya Pakki, Navid Emamdoost, Stephen McCamant, Kangjie Lu |
USENIX Security Symposium | 2 |
| 2020 | Exaggerated Error Handling Hurts! An In-Depth Study and Context-Aware DetectionabstractOperating system (OS) kernels frequently encounter various errors due to invalid internal states or external inputs. To ensure the security and reliability of OS kernels, developers propose a diverse set of mechanisms to conservatively capture and handle potential errors. Existing research has thus primarily focused on the completeness and adequacy of error handling to not miss the attention. However, we find that handling an error with an over-severe level (e.g., unnecessarily terminating the execution) instead hurts the security and reliability. In this case, the error-handling consequences are even worse than the error it attempts to resolve. We call such a case Exaggerated Error Handling (EEH). The security impacts of EEH bugs vary, including denial-of-service, data losses, broken control-flow integrity, memory leaks, etc. Despite its significance, detecting EEH remains an unexplored topic. Aditya Pakki, Kangjie Lu |
CCS | 1 |
| 2019 | Automatically Identifying Security Checks for Detecting Kernel Semantic Bugs
Kangjie Lu, Aditya Pakki, Qiushi Wu |
ESORICS (2) | 2 |
| 2019 | Detecting Missing-Check Bugs via Semantic- and Context-Aware Criticalness and Constraints Inferences
Kangjie Lu, Aditya Pakki, Qiushi Wu |
USENIX Security Symposium | 2 |