VLDB 2026 Research / reviewers in the wild / expert
Blaine Hoak
dblp:293/7182
· DBLP profile ↗
8ranked-venue papers
1as first author
8since 2021 · last 2025
0000-0003-2960-0686ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 6 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Synthetic Texture Datasets: Challenges, Creation, and CurationabstractTexture data serves as a valuable tool for interpreting the high-level features models learn, uncovering biases, and identifying security vulnerabilities. However, works in this space have been limited by small texture datasets and synthesis methods that struggle to scale in the diversity and specificity required for these tasks. In this work, we introduce an extensible methodology for generating high-quality, diverse texture images, which we use to create the Prompted Textures Dataset (PTD), a new texture dataset spanning 246,285 images across 56 texture classes. Our comparison against real texture data demonstrates that PTD is more diverse while maintaining quality. Additionally, human evaluations confirm that every stage in our methodology enhances texture quality, yielding a 3.4% increase in quality and a 4.5% increase in representativeness overall. Our dataset is available for download at https://zenodo.org/records/15359142. Blaine Hoak, Patrick D. McDaniel |
ECAI | 1 |
| 2025 | On the Robustness Tradeoff in Fine-TuningabstractFine-tuning has become the standard practice for adapting pre-trained models to downstream tasks. However, the impact on model robustness is not well understood. In this work, we characterize the robustness-accuracy trade-off in fine-tuning. We evaluate the robustness and accuracy of fine-tuned models over 6 benchmark datasets and 7 different fine-tuning strategies. We observe a consistent trade-off between adversarial robustness and accuracy. Peripheral updates such as BitFit are more effective for simple tasks -- over 75% above the average measured by the area under the Pareto frontiers on CIFAR-10 and CIFAR-100. In contrast, fine-tuning information-heavy layers, such as attention layers via Compacter, achieves a better Pareto frontier on more complex tasks -- 57.5% and 34.6% above the average on Caltech-256 and CUB-200, respectively. Lastly, we observe that the robustness of fine-tuning against out-of-distribution data closely tracks accuracy. These insights emphasize the need for robustness-aware fine-tuning to ensure reliable real-world deployments. Kunyang Li 0001, Jean-Charles Noirot Ferrand, Ryan Sheatsley, Blaine Hoak, Yohan Beugin, Eric Pauley, Patrick D. McDaniel |
ICCV | 4 |
| 2025 | Secure IP Address Allocation at Cloud Scale
Eric Pauley, Kyle Domico, Blaine Hoak, Ryan Sheatsley, Quinn Burke 0002, Yohan Beugin, Engin Kirda, Patrick D. McDaniel |
NDSS | 3 |
| 2025 | Securing Cloud File Systems With Trusted ExecutionabstractCloud file systems offer organizations a scalable and reliable file storage solution. However, cloud file systems have become prime targets for adversaries, and traditional designs are not equipped to protect organizations against the myriad of attacks that may be initiated by a malicious cloud provider, co-tenant, or end-client. Recently proposed designs leveraging cryptographic techniques and trusted execution environments (TEEs) still force organizations to make undesirable trade-offs, consequently leading to either security, functional, or performance limitations. In this paper, we introduceBFS, a cloud file system that leverages the security capabilities provided by TEEs to bootstrap new security protocols that deliver strong security guarantees, high-performance, and a transparent POSIX-like interface to clients.BFSdelivers stronger security guarantees and up to a$2.5\times$speedup over a state-of-the-art secure file system. Moreover, compared to the industry standard NFS,BFSachieves up to$2.2\times$speedups across micro-benchmarks and incurs$< 1\times$overhead for most macro-benchmark workloads.BFSdemonstrates a holistic cloud file system design that does not sacrifice an organizations’ security yet can embrace all of the functional and performance advantages of outsourcing. Quinn Burke 0002, Yohan Beugin, Blaine Hoak, Eric Pauley, Ryan Sheatsley, Mingli Yu, Ting He 0001, Thomas La Porta, Patrick D. McDaniel |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | The Space of Adversarial Strategies
Ryan Sheatsley, Blaine Hoak, Eric Pauley, Patrick D. McDaniel |
USENIX Security Symposium | 2 |
| 2022 | Measuring and Mitigating the Risk of IP Reuse on Public CloudsabstractPublic clouds provide scalable and cost-efficient computing through resource sharing. However, moving from traditional on-premises service management to clouds introduces new challenges; failure to correctly provision, maintain, or decommission elastic services can lead to functional failure and vulnerability to attack. In this paper, we explore a broad class of attacks on clouds which we refer to as cloud squatting. In a cloud squatting attack, an adversary allocates resources in the cloud (e.g., IP addresses) and thereafter leverages latent configuration to exploit prior tenants. To measure and categorize cloud squatting we deployed a custom Internet telescope within the Amazon Web Services us-east-1 region. Using this apparatus, we deployed over 3 million servers receiving 1.5 million unique IP addresses ($\approx$ 56% of the available pool) over 101 days beginning in March of 2021. We identified 4 classes of cloud services, 7 classes of third-party services, and DNS as sources of exploitable latent configurations. We discovered that exploitable configurations were both common and in many cases extremely dangerous; we received over 5 million cloud messages, many containing sensitive data such as financial transactions, GPS location, and PII. Within the 7 classes of third-party services, we identified dozens of exploitable software systems spanning hundreds of servers (e.g., databases, caches, mobile applications, and web services). Lastly, we identified 5446 exploitable domains panning 231 eTLDs—including 105 in the top 10000 and 23 in the top 1000 popular domains. Through tenant disclosures we have identified several root causes, including (a) a lack of organizational controls, (b) poor service hygiene, and (c) failure to follow best practices. We conclude with a discussion of the space of possible mitigations and describe the mitigations to be deployed by Amazon in response to this study. Eric Pauley, Ryan Sheatsley, Blaine Hoak, Quinn Burke 0002, Yohan Beugin, Patrick D. McDaniel |
SP | 3 |
| 2022 | Building a Privacy-Preserving Smart Camera SystemabstractAbstract Millions of consumers depend on smart camera systems to remotely monitor their homes and businesses. However, the architecture and design of popular commercial systems require users to relinquish control of their data to untrusted third parties, such as service providers (e.g., the cloud). Third parties therefore can (and in some instances have) access the video footage without the users’ knowledge or consent—violating the core tenet of user privacy. In this paper, we present CaCTUs, a privacy-preserving smart Camera system Controlled Totally by Users. CaCTUs returns control to the user; the root of trust begins with the user and is maintained through a series of cryptographic protocols, designed to support popular features, such as sharing, deleting, and viewing videos live. We show that the system can support live streaming with a latency of 2 s at a frame rate of 10 fps and a resolution of 480 p. In so doing, we demonstrate that it is feasible to implement a performant smart-camera system that leverages the convenience of a cloud-based model while retaining the ability to control access to (private) data. Yohan Beugin, Quinn Burke 0002, Blaine Hoak, Ryan Sheatsley, Eric Pauley, Gang Tan, Syed Rafiul Hussain, Patrick D. McDaniel |
Proc. Priv. Enhancing Technol. | 3 |
| 2021 | On the Robustness of Domain ConstraintsabstractMachine learning is vulnerable to adversarial examples--inputs designed to cause models to perform poorly. However, it is unclear if adversarial examples represent realistic inputs in the modeled domains. Diverse domains such as networks and phishing have domain constraints--complex relationships between features that an adversary must satisfy for an attack to be realized (in addition to any adversary-specific goals). In this paper, we explore how domain constraints limit adversarial capabilities and how adversaries can adapt their strategies to create realistic (constraint-compliant) examples. In this, we develop techniques to learn domain constraints from data, and show how the learned constraints can be integrated into the adversarial crafting process. We evaluate the efficacy of our approach in network intrusion and phishing datasets and find: (1) up to 82% of adversarial examples produced by state-of-the-art crafting algorithms violate domain constraints, (2) domain constraints are robust to adversarial examples; enforcing constraints yields an increase in model accuracy by up to 34%. We observe not only that adversaries must alter inputs to satisfy domain constraints, but that these constraints make the generation of valid adversarial examples far more challenging. Ryan Sheatsley, Blaine Hoak, Eric Pauley, Yohan Beugin, Michael J. Weisman, Patrick D. McDaniel |
CCS | 2 |