Libo Chen 0001

dblp:08/4315-1 · also Li-Bo Chen 0001 · DBLP profile ↗
← Back
21ranked-venue papers
4as first author
21since 2021 · last 2026
0000-0003-3236-4805ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 4 first-author · 11 since 2021Computer networks · 4 · 4 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem
abstract
Large language models(LLMs) are increasingly integrated with external systems through the Model Context Protocol(MCP),which standardizes tool invocation and has rapidly become a backbone for LLM-powered applications. While this paradigm enhances functionality,it also introduces a fundamental security shift:LLMs transition from passive information processors to autonomous orchestrators of task-oriented toolchains,expanding the attack surface,elevating adversarial goals from manipulating single outputs to hijacking entire execution flows. In this paper,we identify and characterize a systematic privacy-leakage attack pattern,termed Parasitic Toolchain Attacks,instantiated as MCP Unintended Privacy Disclosure(MCP-UPD). These attacks require no direct victim interaction;instead,adversaries embed malicious instructions into external data sources that LLMs access during legitimate tasks. Unlike traditional prompt injection and tool poisoning attacks,our attack targets the interconnected toolchain itself,assembling multiple legitimate tools into a coordinated workflow whose combined behavior accomplishes malicious objectives. In MCP-UPD,the malicious logic infiltrates the toolchain and unfolds in three phases:Parasitic Ingestion,Privacy Collection,and Privacy Disclosure,culminating in stealthy exfiltration of private data. Our root cause analysis reveals that MCP lacks both context-tool isolation and least-privilege enforcement,enabling adversarial instructions to propagate unchecked into sensitive tool invocations. To assess the severity,we design MCP-SEC and conduct the first large-scale security census of the MCP ecosystem,analyzing 12230 tools across 1360 servers. Our findings show that the MCP ecosystem is rife with real-world exploitable gadgets and diverse attack methods,underscoring systemic risks in MCP platforms and the urgent need for defense mechanisms in LLM-integrated environments.
Shuli Zhao, Qinsheng Hou, Zihan Zhan, Yuchong Xie, Libo Chen 0001, Shenghong Li 0001, Zhi Xue
SP7
2025 Detecting Malicious Encrypted Traffic with Multimodal Representations
abstract
The rapid advancement of encryption technology enhances network security while enabling hidden attackers to avoid detection. Traditional methods for malicious encrypted traffic detection, which predominantly rely on a single modality such as statistical features or content representations, often fall short of adapting to dynamic network environments. Methods based on graph representations grapple with challenges such as insufficient modeling of the encryption properties and substantial computational resource requirements. Multimodal-based methods seldom consider the graph-based dynamic representation and often overlook the differences in feature spaces. Moreover, these methods are not evaluated for universality across platforms. To solve challenges above, we propose M2D, a multimodal-based framework for malicious encrypted traffic detection suitable for all versions of TLS protocols. M2D extracts (a) heterogeneous graph representation from spatial and temporal features to capture both dynamic patterns and complex interactions between different entities; (b) ciphertext visual representation to enhance content encapsulation; and (c) plaintext representation to explore semantics, then fuses them through the multi-head attention mechanism to emphasize more effective components. Furthermore, we set up an encrypted network traffic dataset generated by sandbox, with session keys embedded for decryption. Experimental results on both public and proposed datasets demonstrate the superior performance of M2D in binary and multi-class classification tasks. Additionally, ablation studies confirm the effectiveness of each component.
Ruijie Zhao 0001, Libo Chen 0001, Lingyun Ying, Zhengguang Han, Zhi Xue
ICC4
2025 Dr. Docker: A Large-Scale Security Measurement of Docker Image Ecosystem
abstract
Docker has transformed modern software development, enabling the widespread reuse of containerized applications. Currently, Docker images are primarily distributed through centralized registries, among which Docker Hub is the largest, allowing developers to share and reuse images easily. The threats within these images also spread through the supply chain via dependency relationships, posing risks to anyone using the image and all images built based on it. However, it is unclear to what extent the threats within Docker images are distributed and propagated.
Hequan Shi, Lingyun Ying, Libo Chen 0001, Hai-Xin Duan, Zhi Xue
WWW3
2025 A combined feature selection approach for malicious email detection based on a comprehensive email dataset
abstract
Abstract In recent years, new malicious email attacks have emerged. We summarize two major challenges in the current field of malicious email detection using machine learning algorithms. (1) Current works on malicious email detection use different datasets and lack a unified and comprehensive open source dataset standard for evaluating detection performance. In addition, outdated data makes it difficult to detect new types of malicious email attacks. (2) There are limitations in feature selection and extraction. Relying only on static features or body textual features cannot satisfy the detection of both common phishing or spam email and new malicious emails that exploit protocol vulnerabilities. To address these problems, we propose the Exploiting Protocol Vulnerability Malicious Email (EPVME) dataset, which contains 49,136 malicious email samples. The EPVME dataset is constructed by summarizing and simulating the novel types of malicious email attacks that exploit email protocol vulnerabilities. In our dataset, the coverage of the types of malicious emails and the number of them are significantly increased. By collecting the currently available open source datasets, we build a large-scale dataset with 660,985 samples. Through two sets of comparative experiments on the dataset containing EPVME, we verify the necessity, reliability, and validity of the EPVME dataset. By using a large and comprehensive open source email dataset, we hope to help subsequent work on malicious email detection achieve comparative performance. Furthermore, we propose a new feature selection and construction method that combines both static features and textual features. We extract 79 static features from both the header and body parts of email samples, perform textual feature extraction on the pre-processed body parts, and combine various machine learning algorithms for detection model construction and experimental comparison. Our detection model can achieve an accuracy of 99.968% and a false positive rate of 0.099%.
Libo Chen 0001, Zhi Xue
Cybersecur.4
2025 Enhancing Real-Time Operating System Security Analysis via Slice-Based Fuzzing
Yuchong Xie, Qinsheng Hou, Libo Chen 0001, Bo Zhang 0063, Shenghong Li 0001, Zhi Xue
IEEE Trans. Software Eng.6
2024 Vulnerability-oriented Testing for RESTful APIs
Wenlong Du, Libo Chen 0001, Ruijie Zhao 0001, Junmin Zhu, Zhengguang Han, Zhi Xue
USENIX Security Symposium4
2024 Code is not Natural Language: Unlock the Power of Semantics-Oriented Graph Representation for Binary Code Similarity Detection
Haojie He, Xingwei Lin, Ziang Weng, Ruijie Zhao 0001, Shuitao Gan, Libo Chen 0001, Yuede Ji, Jiashui Wang, Zhi Xue
USENIX Security Symposium6
2024 Detection and Analysis of Broken Access Control Vulnerabilities in App-Cloud Interaction in IoT
abstract
At present, there is less research on the detection of broken access control vulnerabilities in IoT systems, mostly using state machines to analyze abnormal state transitions, and no systematic tools have been developed. The main challenges include the inaccessibility of communication messages, a lack of effective detection for broken access control vulnerabilities, and excessive manual involvement. Moreover, due to the existence of encryption, signatures, and other fields, it is challenging to directly port web-based detection tools to IoT. In response to these challenges, we propose a framework for detecting broken access control vulnerabilities based on the interaction between applications and cloud platforms. The framework employs man-in-the-middle techniques to obtain communication messages between the two entities, enabling fast and effective fuzz testing through keyword extraction, database-guided fuzzing, and response-based detection algorithms. In addition, a combination of dynamic and static reverse analysis techniques are used to overcome anti-tampering measures, such as encryption and signatures. Following the detection framework, we implemented the semi-automated BACDetector system and tested it on six applications from four manufacturers. BACDetector discovered nine broken access control vulnerabilities, including risks of device hijacking and privacy leakage. This validated its effectiveness in detecting vulnerabilities in IoT.
Futai Zou, Jianan Hong, Libo Chen 0001, Ping Yi
IEEE Internet Things J.4
2024 SaTC: Shared-Keyword Aware Taint Checking for Detecting Bugs in Embedded Systems
abstract
IoT devices have brought invaluable convenience to our daily life. However, their pervasiveness also amplifies the impact of security vulnerabilities. Many widespread vulnerabilities of embedded systems reside in their vulnerable border services. Unfortunately, existing vulnerability detection methods can neither effectively nor efficiently analyze such border services: they either introduce heavy execution overheads or have many false positives and negatives. In this paper, we propose a novel static taint checking solution, SaTC, to effectively detect security vulnerabilities in border services provided by embedded devices. Our key insight is that string literals on border interfaces are commonly shared between front-end files and back-end binaries to encode user input. Thus, we extract common keywords from the front-end and use them to locate reference points in the back-end, which indicate the input entry. Then, we apply targeted data-flow analysis to detect dangerous uses of the untrusted user input accurately. We implemented a prototype of SaTC and evaluated it on 39 firmware samples from six popular vendors. SaTC discovered 36 unknown bugs, of which CVE/CNVD/PSV confirms 33. Compared to the state-of-the-art tool KARONTE, SaTC found significantly more bugs in the test set. It shows that SaTC is effective in discovering bugs in embedded systems.
Libo Chen 0001, Jiaqi Linghu, Qinsheng Hou, Quanpu Cai, Shanqing Guo, Zhi Xue
IEEE Trans. Dependable Secur. Comput.1
2023 VD-Guard: DMA Guided Fuzzing for Hypervisor Virtual Device
abstract
Virtualization has been widely used in various scenarios, such as cloud computing. As its core technology, virtualization hypervisor brings up the efficiency of sharing the physical machine's resources via virtual devices. However, virtualization hypervisor also introduces significant security risks due to defective design or implementation schemes on virtual devices. Although several methods have been proposed to detect vulnerabilities in virtual devices, they still cannot effectively discover them because of missing critical information related to the MMIO/PIO and DMA operations to guide their dynamic methods. In this paper, we propose a hybrid method, VD-GUARD, to detect vulnerabilities in virtual devices. Specifically, it first leverages static control flow analysis to track call traces from various data entry points of virtual devices (MMIO/PIO functions) to the critical dispatcher points (DMA functions), and generate seeds that can trigger this call trace via static analysis and limited fuzzing test. And then, it takes these seeds as input and leverages DMA guided fuzzing to discover bugs. To verify the effectiveness of Vd-guard, we build a dataset, including 10 bugs in QEMU, based on previous works, and Vd-guardoutperforms the state-of-the-art hypervisor fuzzer Morphuzz. Vd-guardalso has found 4 new vulnerabilities in QEMU and VirtualBox, all of which have been confirmed and fixed (have been assigned 3 CVE IDs).
Yuwei Liu 0001, Yuchong Xie, Libo Chen 0001, Yingming Zeng, Zhi Xue, Purui Su
ASE5
2023 Both Sides Needed: A Two-Dimensional Measurement Study of Email Security Based on SPF and DMARC
abstract
As important email authentication protocols, SPF and DMARC can effectively reduce the risk of spoofing and improve the security of email systems. In this paper, we perform, for the first time, a comprehensive and integrated measurement of the state of SPF and DMARC adoption on the Alexa Top Million Domains in 2023, both in two dimensions with email sending and receiving. We provide a detailed analysis and comparison of the results. Our measurement shows that the number of domains configured with SPF and DMARC records is increasing while the number of invalid records is also growing. Among domains with email sending/receiving capabilities, approximately 27% of domain mail servers cannot verify the SPF and DMARC of received emails. Email security must be achieved on both the sending and receiving sides. We recommend that all domain administrators pay more attention to the systemic issues of SPF and DMARC deployments.
Libo Chen 0001, Zhi Xue
MSN2
2023 SAWD: Structural-Aware Webshell Detection System with Control Flow Graph
abstract
With the increasing prevalence of web servers, protecting them from cyber attacks has become a crucial task for online service providers.Webshells, which are backdoors to websites, are commonly used by hackers to gain unauthorized access to web servers.However, traditional methods for detecting webshells often fail to produce satisfactory results due to the use of obfuscation or encryption to conceal their characteristics.In recent years, webshell detection methods based on deep learning (DL) have received significant attention, but they struggle to preserve the syntax and semantic information contained in the source code.In this paper, we propose a structuralaware webshell detection system to address these problems, denoted as SAWD.Specifically, we first generate the control flow graph (CFG) with syntax and semantic information from the PHP source code.Then, we leverage CFG to build our graph representation, which consists of the adjacency matrix and keywords-based basic block features.Finally, based on our graph representation, we adopt convolutional neural networks (GCN) combined with graph pooling to detect webshells more efficiently.Experimental results demonstrate that our method outperforms state-of-the-art webshell detection systems on the collected dataset.
Junmin Zhu, Yizhao Yao, Xianwen Deng, Yaoguang Yong, Libo Chen 0001, Zhi Xue, Ruijie Zhao 0001
SEKE6
2023 GeeSolver: A Generic, Efficient, and Effortless Solver with Self-Supervised Learning for Breaking Text Captchas
abstract
Although text-based captcha, which is used to differentiate between human users and bots, has faced many attack methods, it remains a widely used security mechanism and is employed by some websites. Some deep learning-based text captcha solvers have shown excellent results, but the labor-intensive and time-consuming labeling process severely limits their viability. Previous works attempted to create easy-to-use solvers using a limited collection of labeled data. However, they are hampered by inefficient preprocessing procedures and inability to recognize the captchas with complicated security features.In this paper, we propose GeeSolver, a generic, efficient, and effortless solver for breaking text-based captchas based on self-supervised learning. Our insight is that numerous difficult-to-attack captcha schemes that "damage" the standard font of characters are similar to image masks. And we could leverage masked autoencoders (MAE) to improve the captcha solver to learn the latent representation from the "unmasked" part of the captcha images. Specifically, our model consists of a ViT encoder as latent representation extractor and a well-designed decoder for captcha recognition. We apply MAE paradigm to train our encoder, which enables the encoder to extract latent representation from local information (i.e., without masking part) that can infer the corresponding character. Further, we freeze the parameters of the encoder and leverage a few labeled captchas and many unlabeled captchas to train our captcha decoder with semi-supervised learning.Our experiments with real-world captcha schemes demonstrate that GeeSolver outperforms the state-of-the-art methods by a large margin using a few labeled captchas. We also show that GeeSolver is highly efficient as it can solve a captcha within 25 ms using a desktop CPU and 9 ms using a desktop GPU. Besides, thanks to latent representation extraction, we successfully break the hard-to-attack captcha schemes, proving the generality of our solver. We hope that our work will help security experts to revisit the design and availability of text-based captchas. The code is available at https://github.com/NSSL-SJTU/GeeSolver.
Ruijie Zhao 0001, Xianwen Deng, Zhicong Yan, Zhengguang Han, Libo Chen 0001, Zhi Xue
SP6
2023 Subdomain Protection is Needed: An SPF and DMARC-Based Empirical Measurement Study and Proactive Solution of Email Security
abstract
SPF and DMARC are two important email authen-tication protocols that can effectively reduce the risk of spoofing attacks and improve email security. In this paper, we provide an empirical measurement study of how well SPF and DMARC are deployed and managed. We perform an active measurement on the Alexa Top Million Domains and their subdomains. For the first time, we present a measurement of subdomain configuration. SPF and DMARC adoption is growing, but still more than 70% of domains do not have proper configurations. More than 90% of all domains lack subdomain configurations. Through experiments, we show that in the absence of effective SPF and DMARC configurations, domains and subdomains can be used by attackers to send spoofed emails. To address this issue, we provide a complete set of proactive email security defense solutions. We summarize detailed mitigation measures and email security assessment methodologies. We also propose the SPF Macro-based Abnormal Email Detection System (SMAEDS), which enables proactive defense against spoofed email attacks. We recommend that the community pay more attention to the systemic issues of SPF and DMARC deployment. We hope that this work can help improve the security of the email ecosystem and reduce the risk of phishing attacks.
Dengke Mi, Libo Chen 0001, Zhi Xue
SRDS3
2022 SFuzz: Slice-based Fuzzing for Real-Time Operating Systems
abstract
Real-Time Operating System (RTOS) has become the main category of embedded systems. It is widely used to support tasks requiring real-time response such as printers and switches. The security of RTOS has been long overlooked as it was running in special environments isolated from attackers. However, with the rapid development of IoT devices, tremendous RTOS devices are connected to the public network. Due to the lack of security mechanisms, these devices are extremely vulnerable to a wide spectrum of attacks. Even worse, the monolithic design of RTOS combines various tasks and services into a single binary, which hinders the current program testing and analysis techniques working on RTOS. In this paper, we propose SFuzz, a novel slice-based fuzzer, to detect security vulnerabilities in RTOS. Our insight is that RTOS usually divides a complicated binary into many separated but single-minded tasks. Each task accomplishes a particular event in a deterministic way and its control flow is usually straightforward and independent. Therefore, we identify such code from the monolithic RTOS binary and synthesize a slice for effective testing. Specifically, SFuzz first identifies functions that handle user input, constructs call graphs that start from callers of these functions, and leverages forward slicing to build the execution tree based on the call graphs and pruning the paths independent of external inputs. Then, it detects and handles roadblocks within the coarse-grain scope that hinder effective fuzzing, such as instructions unrelated to the user input. And then, it conducts coverage-guided fuzzing on these code snippets. Finally, SFuzz leverages forward and backward slicing to track and verify each path constraint and determine whether a bug discovered in the fuzzer is a real vulnerability. SFuzz successfully discovered 77 zero-day bugs on 35 RTOS samples, and 67 of them have been assigned CVE or CNVD IDs. Our empirical evaluation shows that SFuzz outperforms the state-of-the-art tools (e.g., UnicornAFL) on testing RTOS.
Libo Chen 0001, Quanpu Cai, Zhenbang Ma, Hong Hu 0004, Minghang Shen, Shanqing Guo, Hai-Xin Duan, Kaida Jiang, Zhi Xue
CCS1
2022 3E-Solver: An Effortless, Easy-to-Update, and End-to-End Solver with Semi-Supervised Learning for Breaking Text-Based Captchas
abstract
Text-based captchas are the most widely used security mechanism currently. Due to the limitations and specificity of the segmentation algorithm, the early segmentation-based attack method has been unable to deal with the current captchas with newly introduced security features (e.g., occluding lines and overlapping). Recently, some works have designed captcha solvers based on deep learning methods with powerful feature extraction capabilities, which have greater generality and higher accuracy. However, these works still suffer from two main intrinsic limitations: (1) many labor costs are required to label the training data, and (2) the solver cannot be updated with unlabeled data to recognize captchas more accurately. In this paper, we present a novel solver using improved FixMatch for semi-supervised captcha recognition to tackle these problems. Specifically, we first build an end-to-end baseline model to effectively break text-based captchas by leveraging encoder-decoder architecture and attention mechanism. Then we construct our solver with a few labeled samples and many unlabeled samples by improved FixMatch, which introduces teacher forcing, adaptive batch normalization, and consistency loss to achieve more effective training. Experiment results show that our solver outperforms state-of-the-arts by a large margin on current captcha schemes. We hope that our work can help security experts to revisit the design and usability of text-based captchas. The source code of this work is available at https://github.com/SJTU-dxw/3E-Solver-CAPTCHA.
Xianwen Deng, Ruijie Zhao 0001, Libo Chen 0001, Zhi Xue
IJCAI4
2022 Flow Sequence-Based Anonymity Network Traffic Identification with Residual Graph Convolutional Networks
abstract
Identifying anonymity services from network traffic is a crucial task for network management and security. Currently, some works based on deep learning have achieved excellent performance for traffic analysis, especially those based on flow sequence (FS), which utilizes information and features of the traffic flow. However, these models still face a serious challenge because of lacking a mechanism to take into account relationships between flows, resulting in mistakenly recognizing irrelevant flows in FS as clues for identifying traffic. In this paper, we propose a novel FS-based anonymity network traffic identification framework to tackle this problem, which leverages Residual Graph Convolutional Network (ResGCN) to exploit relationships between flows for FS feature extraction. Moreover, we design a practical scheme to preprocess the raw data of real-world traffic, which further improves identification performance and efficiency. Experimental results on two real-world traffic datasets demonstrate that our method outperforms state-of-the-art methods by a large margin.
Ruijie Zhao 0001, Xianwen Deng, Libo Chen 0001, Zhi Xue
IWQoS4
2022 SEAF: A Scalable, Efficient, and Application-independent Framework for container security detection
abstract
Container technology has become a popular development that can conveniently accelerate building, running, and sharing applications. However, a container image packaging a collection of software usually lurks various defects threatening consumer safety, such as embedded malware, software vulnerability, privacy leakage, etc. Moreover, developers and users share container images through a centralized, public, and massive repository (e.g., Docker Hub), which can magnify the impact of these security defects in a fast-spreading way. Unfortunately, existing detection methods cannot effectively or efficiently discover such hidden flaws among the numerous images. This paper proposes a novel method to effectively detect and measure container security flaws embedded in images. Based on the crucial insight that container images are constructed hierarchically, each image depends on layers of forwarding image and adds updated content in layers of itself. Our work mines a Global Relationship Tree (GRT) based on dependency among the images that contain common layers. Meanwhile, by traversing the GRT and leveraging content differential analysis, we can locate the changing content in an image corresponding to defects. Therefore, when checking flaws among numerous images, we make a layer-sensitive detection by reusing common layers’ detection results in iterative processes to boost detection and accurately measure the influence scope of defects. Finally, we summarize and develop a set of detection primitives for scaling our approach to handle various flaws that may lead to multiple risks in potential. Depending upon this method, we implemented SEAF, a Scalable, Efficient, and Application-independent Framework, and evaluated it on popular images of diverse applications in Docker Hub. The experiment result shows that SEAF can discover different security flaws fast. Compared to the state-of-the-art tool, Clair, SEAF is more efficient and can find significantly more types of defects.
Libo Chen 0001, Yihang Xia, Zhenbang Ma, Ruijie Zhao 0001, Wenqi Sun, Zhi Xue
J. Inf. Secur. Appl.1
2022 Online Intrusion Detection for Internet of Things Systems With Full Bayesian Possibilistic Clustering and Ensembled Fuzzy Classifiers
abstract
The pervasive deployment of the Internet of Things (IoT) has significantly facilitated manufacturing and living. The diversity and continual updates of IoT systems make their security a crucial challenge, among which the detection of malicious network traffic turns out to be the most common yet destructive threat. Despite the efforts on feature engineering and classification backend designing, established intrusion detection systems sometimes lack robustness and are inflexible against the shift of the traffic distribution. To deal with these disadvantages, we design a fuzzy system for the online defense of IoT. Our framework incorporates a full Bayesian possibilistic clustering module for feature processing and an ensemble module motivated by reinforcement learning and adaptive boosting that dynamically fits the streaming data. The proposed clustering module overcomes the issue of determining the number of clusters and can dynamically identify new patterns. The classifier backend combines a collection of fuzzy decision trees that provide readable decision boundaries. The ensembled classifiers can accommodate the drift of data distribution to optimize the long-time performance. Our proposal is tested on settings including one dataset collected from real IoT systems and is compared to numerous competitors. Experimental results verified the advantage of our system regarding accuracy and stability.
Fangqi Li 0001, Ruijie Zhao 0001, Shi-Lin Wang, Libo Chen 0001, Alan Wee-Chung Liew, Weiping Ding 0001
IEEE Trans. Fuzzy Syst.4
2021 A Semi-supervised Deep Learning-Based Solver for Breaking Text-Based CAPTCHAs
abstract
Text-based CAPTCHAs are still the most widely used CAPTCHA mode. Many researchers have proposed attack methods to break them. In previous attacks, segmentation-based methods require at least three steps: preprocessing, segmentation, and recognition, which means that different modes of CAPTCHA require various preprocessing and segmentation algorithms. In recent years, a series of deep learning (DL) models have been designed for cracking text-based CAPTCHAs. However, these methods require annotating numerous images, which are time-consuming and labor-intensive. In this paper, we propose a semi-supervised DL-based solver for breaking text-based CAPTCHAs, which can use a small number of labeled CAPTCHAs to achieve a high-performance attack model. The CNN module and the attention-based Seq2Seq module are two key components for effective feature extraction and character recognition. The experimental results show that our solver successfully attacked 9 types of most popular text-based CAPTCHAs, and the attack success rate is better than the four latest attack models. In addition, our model does not perform any data preprocessing and has a fast attack speed, making it more suitable for real-time attacks. The code and dataset are available on the github.
Xianwen Deng, Ruijie Zhao 0001, Zhi Xue, Libo Chen 0001
TrustCom5
2021 Sharing More and Checking Less: Leveraging Common Input Keywords to Detect Bugs in Embedded Systems
Libo Chen 0001, Quanpu Cai, Yunfan Zhan, Hong Hu 0004, Jiaqi Linghu, Qinsheng Hou, Chao Zhang 0008, Hai-Xin Duan, Zhi Xue
USENIX Security Symposium1