VLDB 2026 Research / reviewers in the wild / expert
Carson Stillman
dblp:361/0817
· DBLP profile ↗
7ranked-venue papers
1as first author
7since 2021 · last 2026
0009-0001-4717-6316ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 1 first-author · 7 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Fizzle: A Framework for Deterministic and Reproducible Network Fuzzing
Nathaniel Bennett, Tyler Tucker, Carson Stillman, William Enck, Patrick Traynor, Kevin R. B. Butler |
SP | 3 |
| 2026 | The Final Security Frontier: Using Privacy-Preserving Computation to Secure Satellite Rendezvous and Proximity Operations
Caroline M. Brandon, Carson Stillman, Joel Hirschmann, Sara Rampazzi, Marina Blanton, Christopher Petersen, Kevin R. B. Butler |
WISEC | 2 |
| 2025 | EM-Flow: Advanced Electromagnetic Control Flow Verification for Embedded SystemsabstractEmbedded devices play a major role in supporting critical infrastructure, but lack many of the security pro-tections of sophisticated systems. Determining whether these devices are compromised is, therefore, a challenge. In this work, we describe a novel control flow verification methodology via electromagnetic (EM) emanations. We design a framework that incorporates signal processing and training to detect subtle control flow deviations as small as three clock cycles, the minimum required to execute a return with malicious activity on modern embedded hardware. Our methodology leverages basic block detection, enabling the discovery of these subtle control flow deviations that escape conventional detection approaches. We evaluate our framework's ability to detect insertion and modification control flow attacks on six different case studies of real-world critical operations and two processors featuring different architectures. Our results show 96.6% detection accuracy across all tested programs and attacks. Finally, we show the transferability of our methodology to different instances of our evaluated processors, reaching up to 98.7% convergence with our baseline models while requiring a third of the collected EM samples compared to standard retraining. In doing so, we reveal the feasibility of fine-grained EM-based control flow monitoring for low-power microcontrollers. Carson Stillman, Jennifer Sheldon, Ian Y. Garrett, Patrick Traynor, Ryan M. Gerdes, Sara Rampazzi, Kevin R. B. Butler |
ACSAC | 1 |
| 2025 | Enabling Secure and Efficient Data Loss Prevention with a Retention-aware Versioning SSD
Weidong Zhu 0002, Carson Stillman, Sara Rampazzi, Kevin R. B. Butler |
CCS | 2 |
| 2025 | Data to Infinity and Beyond: Examining Data Sharing and Reuse Practices in the Computer Security CommunityabstractSharing high-quality research data specifically for reuse in future work helps the scientific community progress by enabling researchers to build upon existing work and explore new research questions without duplicating data collection efforts. Because current discussions about research artifacts in Computer Security focus on reproducibility and availability of source code, the reusability of data is unclear. We examine data sharing practices in Computer Security and Measurement to provide resources and recommendations for sharing reusable data. Our study covers five years (2019–2023) and seven conferences in Computer Security and Measurement, identifying 948 papers that create a dataset as one of their contributions. We analyze the 265 accessible datasets, evaluating their under-standability and level of reuse. Our findings reveal inconsistent practices in data sharing structure and documentation, causing some datasets to not be shared effectively. Additionally, reuse of datasets is low, especially in fields where the nature of the data does not lend itself to reuse. Based on our findings, we offer data-driven recommendations and resources for improving data sharing practices in our community. Furthermore, we encourage authors to be intentional about their data sharing goals and align their sharing strategies with those goals. Anna Crowder, Allison Lu, Kevin Childs, Carson Stillman, Patrick Traynor, Kevin R. B. Butler |
SP | 4 |
| 2024 | "I Had Sort of a Sense that I Was Always Being Watched...Since I Was": Examining Interpersonal Discomfort From Continuous Location-Sharing ApplicationsabstractContinuous location sharing (CLS) applications are widely used for safety and social convenience. However, these applications have privacy concerns that can be used for control and harm. To understand user concerns, we performed the largest user study of CLS application usage performed to date, with 1500 of 3000 users indicating they use CLS applications and 896 of these users completing surveys. From survey responses, we conducted 23 interviews with participants who had uncomfortable experiences. With these interviews, we perform thematic analysis grounded by sociological frameworks of power dynamics and social exchange theory. We observe that CLS application users face discomfort related to three primary categories that build on each other: (1) overstepped boundaries, (2) continued discomfort, and (3) lifestyle-impacting behaviors. With this foundational understanding, we suggest features that aim to reduce relationship imbalances that CLS applications enable. Our resulting study demonstrates that CLS applications contribute to interpersonal discomfort, highlighting the need for design changes. Kevin Childs, Cassidy Gibson, Anna Crowder, Kevin Warren, Carson Stillman, Elissa M. Redmiles, Eakta Jain, Patrick Traynor, Kevin R. B. Butler |
CCS | 5 |
| 2023 | "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesabstractReproducibility is crucial to the advancement of science; it strengthens confidence in seemingly contradictory results and expands the boundaries of known discoveries. Computer Security has the natural benefit of creating artifacts that should facilitate computational reproducibility, the ability for others to use someone else's code and data to independently recreate results, in a relatively straightforward fashion. While the Security community has recently increased its attention on reproducibility, an independent and comprehensive measurement of the current state of reproducibility has not been conducted. In this paper, we perform the first such study, targeting reproducible artifacts generated specifically by papers on machine learning security (one of the most popular areas in academic research) published in Tier 1 security conferences over the past ten years (2013-2022). We perform our measurement study of indirect and direct reproducibility over nearly 750 papers, their codebases, and datasets. Our analysis shows that there is no statistically significant difference between the availability of artifacts before and after the introduction of Artifact Evaluation Committees in Tier 1 conferences. However, based on three years of results, artifacts that pass through this process work at a higher rate than those that do not. From our collected findings, we offer data-driven suggestions for improving reproducibility in our community, including five common problems observed in our study. In so doing, we demonstrate that significant progress still needs to be made in computational reproducibility in Computer Security research. Daniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren, Cole Kitroser, Alejandro Pascual, Divyajyoti Ukirde, Kevin R. B. Butler, Patrick Traynor |
CCS | 3 |