Gabriela F. Ciocarlie

dblp:21/4435 · also Gabriela F. Cretu, Gabriela F. Cretu-Ciocarlie, Gabriela Felicia Ciocarlie · DBLP profile ↗
← Back
24ranked-venue papers
9as first author
8since 2021 · last 2025
0000-0002-4405-0742ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 4 first-author · 6 since 2021Software engineering, systems software and programming languages · 3 · 1 since 2021Systems, architecture and hardware · 2Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2025 AVOID: Automated Void Detection in STL Files
abstract
Additive manufacturing is a multi-billion dollar industry 21.58 billion in 2024), so its processes should be dependable and secure. Malicious actors can inject negative spaces, known as voids, in STL files, which can have a devastating impact on a final product's quality. Current ways of detecting voids use machine sensor or simulation data, and physical verification measures after printing. However, to the best of our knowledge, no method exists for detecting hidden voids solely at the STL level. Void detection at this level is inexpensive, and has the potential to detect voids in designs en masse. In this work, we proposeAVOID, a new approach to detect hidden voids. It both detects voids, and assesses their risk of weakening the manufactured part.AVOIDperforms risk assessment based on the size and location of each detected void. We empirically evaluatedAVOIDusing several large datasets, in total thousands of STL files, each with multiple hidden voids. We found thatAVOIDis highly accurate, with 97.7% recall, 98.1% precision, and 99% F1 on average across six data sets.AVOIDis also robust, scalable, and efficient. We find that high risk voids account for approximately 7% of all detected voids inserted randomly.
Sarah Roscoe, Logan Hellbusch, Chamath Gunawardena, Jitender S. Deogun, Witawas Srisa-an, Yi Qian 0001, Gabriela F. Ciocarlie
IEEE Trans. Dependable Secur. Comput.7
2024 ACM CCS 2024 Doctoral Symposium
abstract
ACM CCS started Doctoral Symposium in 2024 to provide PhD students who are in the middle of their dissertation research an opportunity to present their work to the broader research community and get feedback. We briefly describe the design of the first CCS Doctoral Symposium, the rationale, and the submission/acceptance status.
Gabriela F. Ciocarlie, Xinming Ou
CCS1
2023 Adversarial scratches: Deployable attacks to CNN classifiers
Loris Giulivi, Malhar Jere, Loris Rossi, Farinaz Koushanfar, Gabriela F. Ciocarlie, Briland Hitaj, Giacomo Boracchi
Pattern Recognit.5
2023 autoMPI: Automated Multiple Perspective Attack Investigation With Semantics Aware Execution Partitioning
abstract
Multiple Perspective attack Investigation (MPI) is a technique to partition application dependencies based on high-level semantics. It facilitates provenance analysis by generating succinct causal graphs. It involves an annotation process that identifies variables and data structures corresponding to the partitions and the communication channels between them. Though the amount of annotation is small, this process requires a detailed understanding of the source code. In this work, autoMPI, we extend the capability ofMPIby automating the identifying annotation requirements. We leverage a hybrid analysis approach, performing a differential analysis based on crafted inputs. Static analysis is conducted to identify the annotation sites within the application code afterward automatically. Our evaluation shows the proposed approach can significantly facilitate the annotation process. It correctly identifies all required annotation sites within an average 16 seconds analysis time for the majority of analyzed programs with average precision and recall 72.5% and 100%, respectively.
Mohannad Alhanahnah, Shiqing Ma, Ashish Gehani, Gabriela F. Ciocarlie, Vinod Yegneswaran, Somesh Jha, Xiangyu Zhang 0001
IEEE Trans. Software Eng.4
2022 Everything is Connected: Security and Reliability for Critical Infrastructure
abstract
From smart cities to smart cars and smart manufacturing, we live in a fully connected world. Critical infrastructure connects cyber and physical layers, and different critical infrastructures are in turn connected and interdependent (e.g., smart grids rely on cellular networks). However, the benefit of using such intelligent systems depends on their security and reliability just as much as it depends on their functionality. I work on approaches that operate across all these dimensions. This includes automated methods to identify and monitor Internet of Things devices, cellular networks and methods to detect and diagnose anomalous cells, and secure manufacturing, with formal methods to verify security properties.
Gabriela F. Ciocarlie
WISEC1
2022 Wireless and Mobile Security Research and Teaching in the Post-Pandemic World
abstract
The COVID-19 pandemic disrupted many aspects of our lives at a global scale. This includes the disruption of the research and teaching we perform within the security and privacy community. As the pandemic is weaning off, the lessons learnt during the pandemic can be very valuable in the future, both for navigating pandemic-like situations, and for accommodating greater inclination towards remote work and education. In this panel, international experts with various professional backgrounds and different points of view will discuss the impact they faced over the last two years, such as halting (or starting) specific research problems due to pandemic-related restrictions, unique challenges in deploying new experiments and how they overcame them, and finding novel ways to facilitate social events like conferences and hackathons.
Anindya Maiti, Ahmad-Reza Sadeghi, Gabriela F. Ciocarlie, Patrick Tague
WISEC3
2021 ALchemist: Fusing Application and Audit Logs for Precise Attack Provenance without Instrumentation
Shiqing Ma, Zhuo Zhang 0002, Guanhong Tao 0001, Xiangyu Zhang 0001, Dongyan Xu, Vincent Urias, Han Wei Lin, Gabriela F. Ciocarlie, Vinod Yegneswaran, Ashish Gehani
NDSS9
2021 TRACE: Enterprise-Wide Provenance Tracking for Real-Time APT Detection
abstract
We present TRACE, a comprehensive provenance tracking system for scalable, real-time, enterprise-wide APT detection. TRACE uses static analysis to identify program unit structures and inter-unit dependences, such that the provenance of an output event includes the input events within the same unit. Provenance collected from individual hosts are integrated to facilitate construction of a distributed enterprise-wide causal graph. We describe the evolution of TRACE over a four-year period, during which our improvements to the system focused on performance, scalability, and fidelity. In this time span, the system call coverage increased (from 47 to 66) while the time and space overhead reduced by over one and two orders of magnitude, respectively. We also provide results from five adversarial engagements where an independent team of system evaluators conducted APT attacks and assessed system performance. The input from our system was used by three other teams to implement real-time APT detection logic. Retrospective analysis revealed that TRACE provided sufficient evidence to detect over 80% of the attack stages across all evaluations. By the last engagement, temporal and spatial overhead had been reduced significantly to 18% and 10%, respectively.
Hassaan Irshad, Gabriela F. Ciocarlie, Ashish Gehani, Vinod Yegneswaran, Kyu Hyung Lee, Jignesh M. Patel, Somesh Jha, Yonghwi Kwon 0001, Dongyan Xu, Xiangyu Zhang 0001
IEEE Trans. Inf. Forensics Secur.2
2020 ct-fuzz: Fuzzing for Timing Leaks
abstract
Testing-based methodologies like fuzzing are able to analyze complex software which is not amenable to traditional formal approaches like verification, model checking, and abstract interpretation. Despite enormous success a texposing countless security vulnerabilities in many popular software projects, applications of testing-based approaches mainly targeted checking traditional safety properties like memory safety. While unquestionably important, this class of properties does not precisely characterize other important security aspects such as information leakage, e.g., through side channels. In this work we extend testing-based software analysis methodologies to two-safety properties, which enables the precise discovery of information leaks in complex software. In particular, we present the ct-fuzz tool, which lends coverage-guided grey box fuzzers the ability to detect two safety property violations. Our approach is capable of exposing violations to any two-safety property expressed a sequality between two program traces. Empirically, we demonstrate that ct-fuzz swiftly reveals timing leaks in popular cryptographic implementations.
Shaobo He 0002, Michael Emmi, Gabriela F. Ciocarlie
ICST3
2020 Behavioral simulation for smart contracts
abstract
While smart contracts have the potential to revolutionize many important applications like banking, trade, and supply-chain, their reliable deployment begs for rigorous formal verification. Since most smart contracts are not annotated with formal specifications, general verification of functional properties is impeded.
Sidi Mohamed Beillahi, Gabriela F. Ciocarlie, Michael Emmi, Constantin Enea
PLDI2
2018 Risks and Benefits of Side-Channels in Battlefields
abstract
As networked devices and applications make their way into our battlefields, their behaviors need to take into account these highly adversarial cyber-physical environments. On the dark side of the spectrum, undesired side-channels put our sensitive data at risk; hence, side-channel-protected devices and implementations should be promoted. On the bright side of the spectrum, side-channel analysis may be correlated with observed and hidden events, and enable causality inference and watermarking. This paper describes some unique risks and benefits that may be obtained from side-channel analyses in battlefields.
Ioannis Agadakos, Gabriela F. Ciocarlie, Bogdan Copos, Tancrède Lepoint, Ulf Lindqvist, Michael E. Locasto, James Michaelis
FUSION2
2018 BlockCIS - A Blockchain-Based Cyber Insurance System
abstract
While the cyber insurance market has been growing significantly in recent years, its insurance providers face several challenges: first, there is a lack of standardized frameworks to rate ""cyber""; second, there's a shortage of relevant data to calculate premiums; and third, security postures of insured organizations constantly change. Unlike other types of insurance, cyber insurance requires creating a continuous feedback loop between customers and insurers. In this article, we introduce BlockCIS, a blockchain-based continuous monitoring and processing system for cyber insurance. BlockCIS aims to realize an automated, real-time, and immutable feedback loop between the insurer, its customer, third parties and potential auditors. As an example instantiation, we prototype BlockCIS using the open source Hyperledger Composer blockchain framework.
Tancrède Lepoint, Gabriela F. Ciocarlie, Karim M. El Defrawy
IC2E2
2018 MCI : Modeling-based Causality Inference in Audit Logging for Attack Investigation
Yonghwi Kwon 0001, Fei Wang 0001, Weihang Wang 0001, Kyu Hyung Lee, Wen-Chuan Lee, Shiqing Ma, Xiangyu Zhang 0001, Dongyan Xu, Somesh Jha, Gabriela F. Ciocarlie, Ashish Gehani, Vinod Yegneswaran
NDSS10
2018 Kernel-Supported Cost-Effective Audit Logging for Causality Tracking
Shiqing Ma, Juan Zhai, Yonghwi Kwon 0001, Kyu Hyung Lee, Xiangyu Zhang 0001, Gabriela F. Ciocarlie, Ashish Gehani, Vinod Yegneswaran, Dongyan Xu, Somesh Jha
USENIX ATC6
2017 Low-Leakage Secure Search for Boolean Expressions
Fernando Krell, Gabriela F. Ciocarlie, Ashish Gehani, Mariana Raykova 0001
CT-RSA2
2016 Diagnosis cloud: Sharing knowledge across cellular networks
abstract
Diagnosis functionality as a key component for automated Network Management (NM) systems allows rapid, machine-level interpretation of acquired data. In existing work, network diagnosis has focused on building “point solutions” using configuration and performance management, alarm, and topology information from one network. While the use of automated anomaly detection and diagnosis techniques within a single network improves operational efficiency, the knowledge learned by running these techniques across different networks that are managed by the same operator can be further maximized when that knowledge is shared. This paper presents a novel diagnosis cloud framework that enables the extraction and transfer of knowledge from one network to another. It also presents use cases and requirements. We present the implementation details of the diagnosis cloud framework for two specific types of models: topic models and Markov Logic Networks (MLNs). For each, we describe methods for assessing the quality of the local model, ranking models, adapting models to a new network, and performing detection and diagnosis. We performed experiments for the diagnosis cloud framework using real cellular network datasets. Our experiments demonstrate the feasibility of sharing topic models and MLNs.
Gabriela F. Ciocarlie, Cherita Corbett, Eric Yeh, Christopher Connolly, Henning Sanneck, Muhammad Naseer ul Islam, Borislava Gajic, Szabolcs Nováczki, Kimmo Hätönen
CNSM1
2014 On the feasibility of deploying cell anomaly detection in operational cellular networks
abstract
The Self-Organizing Networks (SON) concept includes the functional area known as self-healing, which aims to automate the detection and diagnosis of, and recovery from, network degradations and outages. In this paper, we build on our previous work [19] and study the feasibility of an operational deployment of an adaptive ensemble-method framework for modeling cell behavior. The framework uses Key Performance Indicators (KPIs) to determine cell-performance status. Our results, generated using real cellular network data, show that the computational overhead and the detection delay are sufficiently low for practical use of our methods to perform cell anomaly detection in operational networks.
Gabriela F. Ciocarlie, Ulf Lindqvist, Kenneth Nitz, Szabolcs Nováczki, Henning Sanneck
NOMS1
2014 DCAD: Dynamic Cell Anomaly Detection for operational cellular networks
abstract
The Self-Organizing Networks (SON) concept includes the functional area known as self-healing, which aims to automate the detection and diagnosis of, and recovery from, network degradations and outages. In this paper, we present Dynamic Cell Anomaly Detection (DCAD), a tool that implements an adaptive ensemble method for modeling cell behavior [5], [6]. DCAD uses Key Performance Indicators (KPIs) from real cellular networks to determine cell-performance status; enables KPI data exploration; visualizes anomalies; reduces the time required for successful detection of anomalies; and accepts user input.
Gabriela F. Ciocarlie, Ulf Lindqvist, Kenneth Nitz, Szabolcs Nováczki, Henning Sanneck
NOMS1
2013 Detecting anomalies in cellular networks using an ensemble method
abstract
The Self-Organizing Networks (SON) concept includes the functional area known as self-healing, which aims to automate the detection and diagnosis of, and recovery from, network degradations and outages. This paper focuses on the problem of cell anomaly detection, addressing partial and complete degradations in cell-service performance, and it proposes an adaptive ensemble method framework for modeling cell behavior. The framework uses Key Performance Indicators (KPIs) to determine cell-performance status and is able to cope with legitimate system changes (i.e., concept drift). The results, generated using real cellular network data, suggest that the proposed ensemble method automatically and significantly improves the detection quality over univariate and multivariate methods, while using intrinsic system knowledge to enhance performance.
Gabriela F. Ciocarlie, Ulf Lindqvist, Szabolcs Nováczki, Henning Sanneck
CNSM1
2009 Adaptive Anomaly Detection via Self-calibration and Dynamic Updating
Gabriela F. Ciocarlie, Angelos Stavrou, Michael E. Locasto, Salvatore J. Stolfo
RAID1
2008 Casting out Demons: Sanitizing Training Data for Anomaly Sensors
abstract
The efficacy of anomaly detection (AD) sensors depends heavily on the quality of the data used to train them. Artificial or contrived training data may not provide a realistic view of the deployment environment. Most realistic data sets are dirty; that is, they contain a number of attacks or anomalous events. The size of these high-quality training data sets makes manual removal or labeling of attack data infeasible. As a result, sensors trained on this data can miss attacks and their variations. We propose extending the training phase of AD sensors (in a manner agnostic to the underlying AD algorithm) to include a sanitization phase. This phase generates multiple models conditioned on small slices of the training data. We use these "micro- models" to produce provisional labels for each training input, and we combine the micro-models in a voting scheme to determine which parts of the training data may represent attacks. Our results suggest that this phase automatically and significantly improves the quality of unlabeled training data by making it as "attack-free" and "regular" as possible in the absence of absolute ground truth. We also show how a collaborative approach that combines models from different networks or domains can further refine the sanitization process to thwart targeted training or mimicry attacks against a single site.
Gabriela F. Ciocarlie, Angelos Stavrou, Michael E. Locasto, Salvatore J. Stolfo, Angelos D. Keromytis
SP1
2007 From STEM to SEAD: Speculative Execution for Automated Defense
Michael E. Locasto, Angelos Stavrou, Gabriela F. Ciocarlie, Angelos D. Keromytis
USENIX ATC3
2006 Intrusion and anomaly detection model exchange for mobile ad-hoc networks
abstract
Mobile Ad-hoc NETworks (MANETs) pose unique security requirements and challenges due to their reliance on open, peer-to-peer models that often don't require authentication between nodes. Additionally, the limited processing power and battery life of the devices used in a MANET also prevent the adoption of heavy-duty cryptographic techniques. While traditional misuse-based Intrusion Detection Systems (IDSes) may work in a MANET, watching for packet dropouts or unknown outsiders is difficult as both occur frequently in both malicious and non-malicious traffic. Anomaly detection approaches hold out more promise, as they utilize learning techniques to adapt to the wireless environment and flag malicious data. The anomaly detection model can also create device behavior profiles, which peers can utilize to help determine its trustworthiness. However, computing the anomaly model itself is a time-consuming and processor-heavy task. To avoid this, we propose the use of model exchange as a device moves between different networks as a means to minimize computation and traffic utilization. Any node should be able to obtain peers' model(s) and evaluate it against its own model of "normal" behavior. We present this model, discuss scenarios in which it may be used, and provide preliminary results and a framework for future implementation.
Gabriela F. Ciocarlie, Janak J. Parekh, Ke Wang 0009, Salvatore J. Stolfo
CCNC1
2005 Anomalous Payload-Based Worm Detection and Signature Generation
Ke Wang 0009, Gabriela F. Ciocarlie, Salvatore J. Stolfo
RAID2