EDBT 2026 Demo / reviewers in the wild / expert
Carter Yagemann
dblp:185/6250
· DBLP profile ↗
16ranked-venue papers
7as first author
12since 2021 · last 2025
0000-0002-8018-0341ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 7 first-author · 12 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | VerDiff: Vulnerability Presence Verification for Comprehensive Reporting Using Constraint ProgrammingabstractSecurity practitioners often rely on a collaborative ecosystem of analysts and authorities to publicly disclose and track program vulnerabilities. Vital to these disclosures is the list of affected program versions, which stakeholders depend on to assess their security posture and plan appropriate responses. It is vital that these lists be accurate and exhaustive because 81.5% of industry systems rely on outdated dependencies and the average time to develop a patch is 256 days. Unfortunately, existing solutions for determining affected program versions do not scale to analyzing the entire release history. This paper presents VERDIFF, a framework that leverages a novel payload-guided, semantically enriched signature isomorphism matching specifically designed for swift, comprehensive vulnerability detection across all versions of a software program. Utilizing the initial vulnerable version found by an analyst and their crafted triggering input, VERDIFF formulates a distinct multi-level signature that is grounded in a strong correlation between dynamic binary analysis and source code signature matching, enabling a rapid high-level triage while accounting for nuanced low-level behaviors. Evaluating 27 CVEs spanning 11 programs, VERDIFF correctly pinpoints 265 misclassifications contained in official advisories. Md Sakib Anwar, Carter Yagemann, Zhiqiang Lin 0001 |
ACSAC | 2 |
| 2025 | Recovering Peripheral Maps and Protocols to Expedite Firmware Reverse EngineeringabstractReverse engineering firmware binaries is vital to security due to the risks involved with manipulating the physical world. Automating the analysis of firmware relies on effective modeling of the interactions between software and hardware, especially when there is no intermediary operating system. Unfortunately, analysts still struggle with handling off-the-shelf firmware because information about the target hardware is limited. Driven by the need for better reverse engineering, we developed a method to expedite tasks, such as rehosting, by automatically recovering which peripheral registers and protocols the firmware uses. Our key technical contribution is the definition and use of “access chains” within the firmware to accurately identify the implemented protocol for each set of in-use peripheral registers. We implemented a prototype, ProtoReveal, and extensively evaluated it on 412 firmware samples from 6 manufacturer websites, covering 35 microcontrollers, and 82 protocols (SPI, UART, etc.) for ARM and MIPS. ProtoReveal surpasses previous binary analysis techniques at identifying protocols, achieving 92% accuracy. Furthermore, we demonstrate that by integrating ProtoReveal with an existing security framework, we can precisely skip over modeling the peripherals and protocols that are never used, even if they are available in the hardware, reducing the time to automatically rehost the firmware for fuzz testing by 99% without sacrificing any effectiveness. Bayan Turkistani, Carter Yagemann |
ACSAC | 2 |
| 2025 | An Empirical Study of C Decompilers: Performance Metrics and Error Taxonomy
Melih Sirlanci, Carter Yagemann, Zhiqiang Lin 0001 |
AsiaCCS | 2 |
| 2025 | GoSonar: Detecting Logical Vulnerabilities in Memory Safe Language Using Inductive Constraint ReasoningabstractAs the global community advocates for the adoption of memory-safe programming languages, a significant research gap persists in identifying the critical vulnerabilities that follow. Logical vulnerabilities represent the most formidable threat to these programs, in the absence of memory safety related vulnerabilities such as buffer overflow. Go, a prevalent memory-safe language for cloud-based applications where resource availability is paramount, is especially susceptible to nonter-minating, resource-exhaustive vulnerabilities. We present a novel approach to the problem, inductive constraint reasoning, designed to evaluate nontermination in complex, real-world programs, demonstrating superior performance compared to contemporary tools on a standardized dataset. Our methodology employs binary-level underconstrained symbolic execution to gather the constraints necessary for multiple recursive iterations. By applying a first-order derivative to these constraints, we model and classify various recursive functions, determining whether their subgoals converge to a global objective. This study addresses numerous challenges in the analysis of Go programs while simultaneously developing and implementing a practical solution to detect uncontrolled recursion, which has revealed 5 new vulnerabilities in the Go standard library. Md Sakib Anwar, Carter Yagemann, Zhiqiang Lin 0001 |
SP | 2 |
| 2024 | AI Psychiatry: Forensic Investigation of Deep Learning Networks in Memory Images
David Oygenblik, Carter Yagemann, Joseph Zhang, Arianna Mastali, Jeman Park 0001, Brendan Saltaformaggio |
USENIX Security Symposium | 2 |
| 2023 | Extracting Threat Intelligence From Cheat Binaries For Anti-CheatingabstractRampant cheating remains a serious concern for game developers who fear losing loyal customers and revenue. While numerous anti-cheating techniques have been proposed, cheating persists in a vibrant (and profitable) illicit market. Inspired by novel insights into the economics behind cheat development and recent techniques for defending against advanced persistent threats (APTs), we propose a fully automated methodology for extracting “cheat intelligence” from widely distributed cheat binaries to produce a “memory access graph” that guides selective data randomization to yield immune game clients. We have implemented a prototype system for Android and Windows games, CheatFighter, and evaluated it on 86 cheats collected from a variety of real-world sources, including Telegram channels and online forums. CheatFighter successfully counteracts 80 of the real-world cheats in under a minute, demonstrating practical end-to-end protection against widespread cheating. Md Sakib Anwar, Chaoshun Zuo, Carter Yagemann, Zhiqiang Lin 0001 |
RAID | 3 |
| 2023 | VulChecker: Graph-based Vulnerability Localization in Source Code
Yisroel Mirsky, George Macon, Michael D. Brown, Carter Yagemann, Matthew Pruett, Evan Downing, J. Sukarno Mertoguno, Wenke Lee |
USENIX Security Symposium | 4 |
| 2023 | PUMM: Preventing Use-After-Free Using Execution Unit Partitioning
Carter Yagemann, Simon P. Chung, Brendan Saltaformaggio, Wenke Lee |
USENIX Security Symposium | 1 |
| 2021 | Cryptographic Key Derivation from Biometric Inferences for Remote AuthenticationabstractBiometric authentication is getting increasingly popular because of its appealing usability and improvements in biometric sensors. At the same time, it raises serious privacy concerns since the common deployment involves storing bio-templates in remote servers. Current solutions propose to keep these templates on the client's device, outside the server's reach. This binds the client to the initial device. A more attractive solution is to have the server authenticate the client, thereby decoupling them from the device. Unfortunately, existing biometric template protection schemes either suffer from the practicality or accuracy. The state-of-the-art deep learning (DL) solutions solve the accuracy problem in face- and voice-based verification. However, existing privacy-preserving methods do not accommodate the DL methods, as they are tailored to hand-crafted feature space of specific modalities in general. In this work, we propose a novel pipeline, Justitia, that makes DL-inferences of face and voice biometrics compatible with the standard privacy-preserving primitives, like fuzzy extractors (FE). For this, we first form a bridge between Euclidean (or cosine) space of DL and Hamming space of FE, while maintaining the accuracy and privacy of underlying schemes. We also introduce efficient noise handling methods to keep the FE scheme practically applicable. We implement an end-to-end prototype to evaluate our design, then show how to improve the security for sensitive authentications and usability for non-sensitive, day-to-day, authentications. Justitia achieves the same, 0.33% false rejection at zero false acceptance, errors as the plaintext baseline does on the YouTube Faces benchmark. Moreover, combining face and voice achieves 1.32% false rejection at zero false acceptance. According to our systematical security assessments conducted through prior approaches and our novel black-box method, Justitia achieves ~25 bits and ~33 bits of security guarantees for face- and face&voice-based pipelines, respectively. Erkam Uzun, Carter Yagemann, Simon P. Chung, Vladimir Kolesnikov, Wenke Lee |
AsiaCCS | 2 |
| 2021 | Automated Bug Hunting With Data-Driven Symbolic Root Cause AnalysisabstractThe increasing cost of successful cyberattacks has caused a mindset shift, whereby defenders now employ proactive defenses, namely software bug hunting, alongside existing reactive measures (firewalls, IDS, IPS) to protect systems. Unfortunately the path from hunting bugs to deploying patches remains laborious and expensive, requires human expertise, and still misses serious memory corruptions. Motivated by these challenges, we propose bug hunting using symbolically reconstructed states based on execution traces to achieve better detection and root cause analysis of overflow, use-after-free, double free, and format string bugs across user programs and their imported libraries. We discover that with the right use of widely available hardware processor tracing and partial memory snapshots, powerful symbolic analysis can be used on real-world programs while managing path explosion. Better yet, data can be captured from production deployments of live software on end-host systems transparently, aiding in the analysis of user clients and long-running programs like web servers. Carter Yagemann, Simon P. Chung, Brendan Saltaformaggio, Wenke Lee |
CCS | 1 |
| 2021 | Validating the Integrity of Audit Logs Against Execution Repartitioning AttacksabstractProvenance-based causal analysis of audit logs has proven to be an invaluable method of investigating system intrusions. However, it also suffers from dependency explosion, whereby long-running processes accumulate many dependencies that are hard to unravel. Execution unit partitioning addresses this by segmenting dependencies into units of work, such as isolating the events that processed a single HTTP request. Unfortunately, we discover that current designs have a semantic gap problem due to how system calls and application log messages are used to infer complex internal program states. We demonstrate how attackers can modify existing code exploits to control event partitioning, breaking links in the attack and framing innocent users. We also show how our techniques circumvent existing program and log integrity defenses. Carter Yagemann, Mohammad A. Noureddine, Wajih Ul Hassan, Simon P. Chung, Adam Bates 0001, Wenke Lee |
CCS | 1 |
| 2021 | ARCUS: Symbolic Root Cause Analysis of Exploits in Production Systems
Carter Yagemann, Matthew Pruett, Simon P. Chung, Kennon Bittick, Brendan Saltaformaggio, Wenke Lee |
USENIX Security Symposium | 1 |
| 2020 | On the Feasibility of Automating Stock Market ManipulationabstractThis work presents the first findings on the feasibility of using botnets to automate stock market manipulation. Our analysis incorporates data gathered from SEC case files, security surveys of online brokerages, and dark web marketplace data. We address several technical challenges, including how to adapt existing techniques for automation, the cost of hijacking brokerage accounts, avoiding detection, and more. We consolidate our findings into a working proof-of-concept, man-in-the-browser malware, Bot2Stock, capable of controlling victim email and brokerage accounts to commit fraud. We evaluate our bots and protocol using agent-based market simulations, where we find that a 1.5% ratio of bots to benign traders yields a 2.8% return on investment (ROI) per attack. Given the short duration of each attack (< 1 minute), achieving this ratio is trivial, requiring only 4 bots to target stocks like IBM. 1,000 bots, cumulatively gathered over 1 year, can turn $100,000 into $1,022,000, placing Bot2Stock on par with existing botnet scams. Carter Yagemann, Simon P. Chung, Erkam Uzun, Sai Ragam, Brendan Saltaformaggio, Wenke Lee |
ACSAC | 1 |
| 2019 | Barnum: Detecting Document Malware via Control Flow Anomalies in Hardware Traces
Carter Yagemann, Salmin Sultana, Wenke Lee |
ISC | 1 |
| 2018 | Enforcing Unique Code Target Property for Control-Flow IntegrityabstractThe goal of control-flow integrity (CFI) is to stop control-hijacking attacks by ensuring that each indirect control-flow transfer (ICT) jumps to its legitimate target. However, existing implementations of CFI have fallen short of this goal because their approaches are inaccurate and as a result, the set of allowable targets for an ICT instruction is too large, making illegal jumps possible. In this paper, we propose the Unique Code Target (UCT) property for CFI. Namely, for each invocation of an ICT instruction, there should be one and only one valid target. We develop a prototype called uCFI to enforce this new property. During compilation, uCFI identifies the sensitive instructions that influence ICT and instruments the program to record necessary execution context. At runtime, uCFI monitors the program execution in a different process, and performs points-to analysis by interpreting sensitive instructions using the recorded execution context in a memory safe manner. It checks runtime ICT targets against the analysis results to detect CFI violations. We apply uCFI to SPEC benchmarks and 2 servers (nginx and vsftpd) to evaluate its efficacy of enforcing UCT and its overhead. We also test uCFI against control-hijacking attacks, including 5 real-world exploits, 1 proof of concept COOP attack, and 2 synthesized attacks that bypass existing defenses. The results show that uCFI strictly enforces the UCT property for protected programs, successfully detects all attacks, and introduces less than 10% performance overhead. Hong Hu 0004, Chenxiong Qian, Carter Yagemann, Simon P. Chung, William R. Harris, Taesoo Kim, Wenke Lee |
CCS | 3 |
| 2016 | Intentio Ex Machina: Android Intent Access Control via an Extensible Application Hook
Carter Yagemann, Wenliang Du 0001 |
ESORICS (1) | 1 |