EDBT 2026 Demo / reviewers in the wild / expert
Michael J. De Lucia
dblp:241/6145
· DBLP profile ↗
7ranked-venue papers
0as first author
7since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | What Do They Fix? LLM-Aided Categorization of Security Patches for Critical Memory Bugs
Juefei Pu, Xiaochen Zou, Shitong Zhu, Qiushi Wu, Zheng Zhang 0058, Joshua Hsu, Zhiyun Qian, Kangjie Lu, Trent Jaeger, Michael J. De Lucia, Srikanth V. Krishnamurthy |
NDSS | 13 |
| 2026 | CLUE: Bringing Machine Unlearning to Mobile Devices
Sazzad Sayyed, Nathaniel D. Bastian, Michael J. De Lucia, Ananthram Swami, Francesco Restuccia 0001 |
WACV | 3 |
| 2025 | On the Adversarial Vulnerability of Label-Free Test-Time AdaptationabstractDespite the success of Test-time adaptation (TTA), recent work has shown that adding relatively small adversarial perturbations to a limited number of samples leads to significant performance degradation. Therefore, it is crucial to rigorously evaluate existing TTA algorithms against relevant threats and implement appropriate security countermeasures. Importantly, existing threat models assume test-time samples will be labeled, which is impractical in real-world scenarios. To address this gap, we propose a new attack algorithm that does not rely on
access to labeled test samples, thus providing a concrete way to assess the security vulnerabilities of TTA algorithms. Our attack design is grounded in theoretical foundations and can generate strong attacks against different state of the art TTA methods. In addition, we show that existing defense mechanisms are almost ineffective, which emphasizes the need for further research on TTA security. Through extensive experiments on CIFAR10-C, CIFAR100-C, and ImageNet-C, we demonstrate that our proposed approach closely matches the performance of state-of-the-art attack benchmarks, even without access to labeled samples. In certain cases, our approach generates stronger attacks, e.g., more than 4% higher error rate on CIFAR10-C. Shahriar Rifat, Jonathan D. Ashdown, Michael J. De Lucia, Ananthram Swami, Francesco Restuccia 0001 |
ICLR | 3 |
| 2024 | Improving Android Malware Detection with Entropy Bytecode-to-Image Encoding FrameworkabstractDetecting malicious software applications is crucial in protecting user data and privacy. The increasing popularity of operating systems (OS) such as Android, iOS, and Windows has led to an expansion in the number of malicious software applications targeting these platforms. Several studies have explored various techniques to detect malware threats, including signature-based detection, behavioral analysis, dynamic analysis, and static analysis. However, these conventional methods may fail to detect new variants of malware with unique characteristics. This research paper introduces a unified approach that combines entropy bytecode-to-image visualization with ensemble learning to enhance the identification of malicious patterns. To validate the efficacy of the entropy encoder, the AndroZoo-2011 application data set was used as a training set, comprising 184,474 samples, including 49,150 and 13,324 malicious and benign applications, respectively. The applied method demonstrates improved performance with an accuracy of 95.77%, a precision of 90.60%, and an F1 score of 92.21% compared to other existing encoders, making our approach more applicable to real-world scenarios. Saleh J. Makkawy, Abdalrahman Alblwi, Michael J. De Lucia, Kenneth E. Barner |
ICCCN | 3 |
| 2024 | A topological data analysis approach for detecting data poisoning attacks against machine learning based network intrusion detection systems
Galamo Monkam, Michael J. De Lucia, Nathaniel D. Bastian |
Comput. Secur. | 2 |
| 2023 | Transfer learning for raw network traffic detectionabstractTraditional machine learning models used for network intrusion detection systems rely on vast amounts of network traffic data with expertly engineered features. The abundance of computational and expert resources at the enterprise level allow for the employment of such models; however, these resources quickly dwindle in edge network scenarios. As Internet of Battlefield Things (IoBT) networks become common place in tactical environments, there is a need for improved and distributed models trained without these enterprise resources. Transfer learning – which allows us to take information learned in one domain and apply it to another – provides one way to create and distribute these models towards the edge. Using neural networks, we demonstrate the feasibility of transfer learning for intrusion detection using only raw network traffic in computationally limited environments. Our results show that with a transferred one-dimensional convolutional neural network model combined with a retrained random forest model, we obtain over 96% accuracy with only 5000 training samples on edge devices with an edge training time of approximately 67 s. David A. Bierbrauer, Michael J. De Lucia, Krishna Reddy, Paul Maxwell, Nathaniel D. Bastian |
Expert Syst. Appl. | 2 |
| 2021 | Themis: Ambiguity-Aware Network Intrusion Detection based on Symbolic Model ComparisonabstractNetwork intrusion detection systems (NIDS) can be evaded by carefully crafted packets that exploit implementation-level discrepancies between how they are processed on the NIDS and at the endhosts. These discrepancies arise due to the plethora of endhost implementations and evolutions thereof. It is prohibitive to proactively employ a large set of implementations at the NIDS and check incoming packets against all of those. Hence, NIDS typically choose simplified implementations that attempt to approximate and generalize across the different endhost implementations. Unfortunately, this solution is fundamentally flawed since such approximations are bound to have discrepancies with some endhost implementations. In this paper, we develop a lightweight system Themis, which empowers the NIDS in identifying these discrepancies and reactively forking its connection states when any packets with "ambiguities" are encountered. Specifically, Themis incorporates an offline phase in which it extracts models from various popular implementations using symbolic execution. During runtime, it maintains a nondeterministic finite automaton to keep track of the states for each possible implementation. Our extensive evaluations show that Themis is extremely effective and can detect all evasion attacks known to date, while consuming extremely low overhead. En route, we also discovered multiple previously unknown discrepancies that can be exploited to bypass current NIDS. Zhongjie Wang 0002, Shitong Zhu, Keyu Man, Pengxiong Zhu, Yu Hao 0006, Zhiyun Qian, Srikanth V. Krishnamurthy, Thomas La Porta, Michael J. De Lucia |
CCS | 9 |