VLDB 2026 Research / reviewers in the wild / expert
Drew Davidson
dblp:70/1243-3 · also Andrew Davidson 0003
· DBLP profile ↗
21ranked-venue papers
6as first author
9since 2021 · last 2025
0000-0002-5096-1446ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 5 first-author · 8 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SCORED '25: Workshop on Software Supply Chain Offensive Research and Ecosystem DefensesabstractAttacks on the software supply chain have shed light on the fragility and importance of ensuring the security and integrity of this vital ecosystem. Addressing the technical and social challenges to building trustworthy software (including AI applications) requires innovative solutions and an interdisciplinary approach. The Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED) is the leading venue for academics, industry practitioners, and policymakers to present and discuss security vulnerabilities, novel defenses against attacks, deployment experiences, adoption requirements and best practices in the software supply chain. The complete SCORED '25 workshop proceedings are available at: https://doi.org/10.1145/3733827 Aditya Sirish A Yelgundhalli, Behnaz Hassanshahi, Dennis Roellke, Drew Davidson, Kathleen Moriarty, Lorenzo De Carli, Marcela S. Melara, Santiago Torres-Arias, Sarah Evans, Yuchen Zhang 0006 |
CCS | 4 |
| 2025 | Evaluating LLM-Based Detection of Malicious Package Updates in npmabstractThe npm software package ecosystem is a notable target for adversarial actors, who seek to compromise software dependencies to exploit software developers and the end-users of their software. One especially dangerous form of attack involves the compromise of a package update. By sneaking malicious code into a package update, adversaries can trick package users into unknowingly installing malware. Detecting malicious package updates is an active research problem, as prospective solutions need to keep pace with the near-constant stream of new package updates, while also maintaining high detection accuracy. In this context, one potentially interesting and emergent approach involves utilizing large language models (LLMs) to identify malicious behaviors from the text of package code. However, practical use of LLMs also poses unique first-order challenges, as models are expensive to run and are known to struggle with task performance as input size increases. This work provides a critical exploration into the practicality and effectiveness of LLMs for detecting malicious package updates. We overcome the immediate challenges for LLM-based applications by preprocessing inputs for analysis and post-processing outputs for malware classification. We find this approach to be practical at repository scale and effective at detecting historical malware incidents, with our best-performing model correctly flagging 209 out of 209 malicious samples across a collection of historical attacks, while only flagging 8 out of 2,000 benign samples across a dataset of typical package updates. With first-order obstacles overcome, we then conduct a deeper investigation into the reasoning capabilities of LLMs–demonstrating specific mild code obfuscations that uniquely challenge tested LLMs and enable adaptive adversaries to subvert detection. Ultimately, our findings demonstrate nuanced potential for employing LLMs as a part of a larger security tool-belt for detecting package malware. Elizabeth Wyss, Dominic Tassio, Lorenzo De Carli, Drew Davidson |
RAID | 4 |
| 2024 | CloudCover: Enforcement of Multi-Hop Network Connections in Microservice DeploymentsabstractMicroservices have emerged as a strong architecture for large-scale, distributed systems in the context of cloud computing and containerization. However, the size and complexity of microservice systems have strained current access control mechanisms. Intricate dependency structures, such as multi-hop dependency chains, go uncaptured by existing access control mechanisms and leave microservice deployments open to adversarial actions and influence.This work introduces CloudCover, an access control mechanism and enforcement framework for microservices. CloudCover provides holistic, deployment-wide analysis of microservice operations and behaviors. It implements a verification-in-the-loop access control approach, mitigating multi-hop microservice threats through control-flow integrity checks. We evaluate these domain-relevant multi-hop threats and CloudCover under existing, real-world scenarios such as Istio’s opensource microservice example and under theoretic and synthetic network loads of 10,000 requests per second. Our results show that CloudCover is appropriate for use in real deployments, requiring no microservice code changes by administrators. Dalton A. Brucker-Hahn, Shanchao Li, Matthew Petillo, Alexandru G. Bardas, Drew Davidson, Yuede Ji |
ACSAC | 6 |
| 2024 | Web-Armour: Mitigating Reconnaissance and Vulnerability Scanning with Scan-Impeding Delays in Web DeploymentsabstractReconnaissance is a critical phase in many cyber attacks. Vulnerability scanning, a key component of reconnaissance, has been shown to be a widespread phenomenon on the internet and commonly targets web application/server deployments. By increasing the costs for vulnerability scanning, many of these attacks may be deterred or even prevented, especially for large-scale, internet-wide campaigns.In this paper, we propose Web-Armour, a mitigation approach to adversarial reconnaissance. Operating as a delay injection mechanism to infrequently executed code portions of a web deployment, Web-Armour significantly increases the cost for attackers to perform automated reconnaissance and vulnerability scanning, while introducing minimal to negligible impact for benign users. We evaluated Web-Armour in a live environment, operated by real users, and in controlled (offline) scenarios. Using Web-Armour, our results show that automated scanning tools may require up to 396 times longer in an offline setting, and up to 357 times longer in a real-world operational deployment to complete compared to unprotected installations. In many instances, scanning tools fail to complete their tasks, due to request timeouts. Furthermore, the performance overhead incurred to benign users is minimal, and can be as low as a 0.6% increase over the baseline. Yousif Dafalla, Dalton A. Brucker-Hahn, Drew Davidson, Alexandru G. Bardas |
ACSAC | 3 |
| 2024 | Assessing UAV Sensor Spoofing: More Than A GNSS ProblemabstractAutonomous navigation systems present a unique attack surface: their sensors. This attack surface allows for sensor spoofing attacks, where an adversary gains control of an unmanned aerial vehicle (UAV) by manipulating one of its sensors to report incorrect data. Prior research has shown that many of the sensors, including those on UAVs, are vulnerable to sensor spoofing attacks. However, most of the work on sensor spoofing either focuses solely on the vulnerability of the sensor or considers only the Global Navigation Satellite System (GNSS) when attacking a UAV. The impact sensor spoofing has on UAVs and the extent of control an attacker can gain with different sensors is relatively unexplored. Concretely, we show that an adversary only needs to control one of the sensors a UAV uses for state estimation to control the UAV, even if the GNSS is faithful. We further characterize the extent of control an adversary can gain with each sensor and discuss why current defenses are insufficient to stop these attacks. Bailey Srimoungchanh, J. Garrett Morris, Drew Davidson |
ACSAC | 3 |
| 2023 | Beyond Typosquatting: An In-depth Look at Package Confusion
Shradha Neupane, Grant Holmes, Elizabeth Wyss, Drew Davidson, Lorenzo De Carli |
USENIX Security Symposium | 4 |
| 2022 | Wolf at the Door: Preventing Install-Time Attacks in npm with LatchabstractThe npm software ecosystem allows developers to easily import code written by others. However, manual vetting of every individual installed component is made difficult in many cases by the number of transitive dependencies brought in by installing popular packages. This has enabled attackers to propagate malicious code by hiding it deep into the dependency chains of popular packages. A particularly dangerous form of attack comes from malicious code embedded into package install scripts. Elizabeth Wyss, Alexander Wittman, Drew Davidson, Lorenzo De Carli |
AsiaCCS | 3 |
| 2022 | What the Fork? Finding Hidden Code Clones in npmabstractThis work presents findings and mitigations on an understudied issue, which we term shrinkwrapped clones, that is endemic to the npm software package ecosystem. A shrink-wrapped clone is a package which duplicates, or near-duplicates, the code of another package without any indication or reference to the original package. This phenomenon represents a challenge to the hygiene of package ecosystems, as a clone package may siphon interest from the package being cloned, or create hidden duplicates of vulnerable, insecure code which can fly under the radar of audit processes. Elizabeth Wyss, Lorenzo De Carli, Drew Davidson |
ICSE | 3 |
| 2021 | Parcae: A Blockchain-Based PRF Service for Everyone
Elizabeth Wyss, Drew Davidson |
ICDF2C | 2 |
| 2020 | Defending Against Package Typosquatting
Ruturaj K. Vaidya, Drew Davidson, Lorenzo De Carli, Vaibhav Rastogi |
NSS | 3 |
| 2020 | Identity Armour: User Controlled Browser Security
Ross Copeland, Drew Davidson |
SecureComm (1) | 2 |
| 2020 | MisMesh: Security Issues and Challenges in Service Meshes
Dalton A. Brucker-Hahn, Drew Davidson, Alexandru G. Bardas |
SecureComm (1) | 2 |
| 2020 | Assessing Adaptive Attacks Against Trained JavaScript Classifiers
Niels Hansen, Lorenzo De Carli, Drew Davidson |
SecureComm (1) | 3 |
| 2017 | Secure Integration of Web Content and Applications on Commodity Mobile Operating SystemsabstractA majority of today's mobile apps integrate web content of various kinds. Unfortunately, the interactions between app code and web content expose new attack vectors: a malicious app can subvert its embedded web content to steal user secrets; on the other hand, malicious web content can use the privileges of its embedding app to exfiltrate sensitive information such as the user's location and contacts. In this paper, we discuss security weaknesses of the interface between app code and web content through attacks, then introduce defenses that can be deployed without modifying the OS. Our defenses feature WIREframe, a service that securely embeds and renders external web content in Android apps, and in turn, prevents attacks between em- bedded web and host apps. WIREframe fully mediates the interface between app code and embedded web content. Un- like the existing web-embedding mechanisms, WIREframe allows both apps and embedded web content to define simple access policies to protect their own resources. These policies recognize fine-grained security principals, such as origins, and control all interactions between apps and the web. We also introduce WIRE (Web Isolation Rewriting Engine), an offline app rewriting tool that allows app users to inject WIREframe protections into existing apps. Our evaluation, based on 7166 popular apps and 20 specially selected apps, shows these techniques work on complex apps and incur acceptable end-to-end performance overhead. Drew Davidson, Yaohui Chen 0001, Franklin George, Long Lu, Somesh Jha |
AsiaCCS | 1 |
| 2017 | Enhancing Android Security Through App Splitting
Drew Davidson, Vaibhav Rastogi, Mihai Christodorescu, Somesh Jha |
SecureComm | 1 |
| 2017 | Cimplifier: automatically debloating containersabstractApplication containers, such as those provided by Docker, have recently gained popularity as a solution for agile and seamless software deployment. These light-weight virtualization environments run applications that are packed together with their resources and configuration information, and thus can be deployed across various software platforms. Unfortunately, the ease with which containers can be created is oftentimes a double-edged sword, encouraging the packaging of logically distinct applications, and the inclusion of significant amount of unnecessary components, within a single container. These practices needlessly increase the container size-sometimes by orders of magnitude. They also decrease the overall security, as each included component-necessary or not-may bring in security issues of its own, and there is no isolation between multiple applications packaged within the same container image. We propose algorithms and a tool called Cimplifier, which address these concerns: given a container and simple user-defined constraints, our tool partitions it into simpler containers, which (i) are isolated from each other, only communicating as necessary, and (ii) only include enough resources to perform their functionality. Our evaluation on real-world containers demonstrates that Cimplifier preserves the original functionality, leads to reduction in image size of up to 95%, and processes even large containers in under thirty seconds. Vaibhav Rastogi, Drew Davidson, Lorenzo De Carli, Somesh Jha, Patrick D. McDaniel |
ESEC/SIGSOFT FSE | 2 |
| 2014 | MoRePriv: mobile OS support for application personalization and privacyabstractPrivacy and personalization of mobile experiences are inherently in conflict: better personalization demands knowing more about the user, potentially violating user privacy. A promising approach to mitigate this tension is to migrate personalization to the client, an approach dubbed client-side personalization. This paper advocates for operating system support for client-side personalization and describes MoRePriv, an operating system service implemented in the Windows Phone OS. We argue that personalization support should be as ubiquitous as location support, and should be provided by a unified system within the OS, instead of by individual apps. Drew Davidson, Matt Fredrikson, Benjamin Livshits |
ACSAC | 1 |
| 2013 | FIE on Firmware: Finding Vulnerabilities in Embedded Systems Using Symbolic Execution
Drew Davidson, Benjamin Moench, Thomas Ristenpart, Somesh Jha |
USENIX Security Symposium | 1 |
| 2010 | Automatic Generation of Remediation Procedures for Malware Infections
Roberto Paleari, Lorenzo Martignoni, Emanuele Passerini, Drew Davidson, Matt Fredrikson, Jonathon T. Giffin, Somesh Jha |
USENIX Security Symposium | 4 |
| 2009 | Protocol Normalization Using Attribute Grammars
Drew Davidson, Randy Smith, Nic Doyle, Somesh Jha |
ESORICS | 1 |
| 2003 | Interactivity in Ico: initial involvement, immersion, investment
Drew Davidson |
ICEC | 1 |