Wai Tuck Wong

dblp:314/0021 · DBLP profile ↗
← Back
2ranked-venue papers
1as first author
2since 2021 · last 2023
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Security and privacy · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
1 paper
Trustworthy machine learning · 44% Optimization for machine learning · 44% Autonomous driving · 13%

Topics — the 3 heaviest of 3, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Optimization for machine learning › differentiable optimization
optimization layer
0.712023
Beyond NaN: Resiliency of Optimization Layers in the Face of Infeasibility · AAAI 2023
Machine learning › Trustworthy machine learning
robustness
0.712023
Beyond NaN: Resiliency of Optimization Layers in the Face of Infeasibility · AAAI 2023
Robotics › Autonomous driving › planning for self-driving vehicles
velocity planning
0.212023
Beyond NaN: Resiliency of Optimization Layers in the Face of Infeasibility · AAAI 2023

Methods — techniques the papers use, named apart from their topics

condition number control · 0.7adversarial perturbation · 0.7
YearPublicationVenuePosition
2023 Beyond NaN: Resiliency of Optimization Layers in the Face of Infeasibility
abstract
Prior work has successfully incorporated optimization layers as the last layer in neural networks for various problems, thereby allowing joint learning and planning in one neural network forward pass. In this work, we identify a weakness in such a set-up where inputs to the optimization layer lead to undefined output of the neural network. Such undefined decision outputs can lead to possible catastrophic outcomes in critical real time applications. We show that an adversary can cause such failures by forcing rank deficiency on the matrix fed to the optimization layer which results in the optimization failing to produce a solution. We provide a defense for the failure cases by controlling the condition number of the input matrix. We study the problem in the settings of synthetic data, Jigsaw Sudoku, and in speed planning for autonomous driving. We show that our proposed defense effectively prevents the framework from failing with undefined output. Finally, we surface a number of edge cases which lead to serious bugs in popular optimization solvers which can be abused as well.
Wai Tuck Wong, Sarah Eve Kinsey, Ramesha Karunasena, Thanh Hong Nguyen, Arunesh Sinha
AAAI1
2023 NodeMedic: End-to-End Analysis of Node.js Vulnerabilities with Provenance Graphs
abstract
Packages in the Node.js ecosystem often suffer from serious vulnerabilities such as arbitrary command injection and code execution. Existing taint analysis tools fall short in providing an end-to-end infrastructure for automatically detecting and triaging these vulnerabilities.We develop NodeMedic, an end-to-end analysis infrastructure that automates test driver creation, performs precise yet scalable dynamic taint propagation via algorithmically tuned propagation policies, and exposes taint provenance information as a provenance graph. Using provenance graphs we develop two post-detection analyses: automated constraint-based exploit synthesis to confirm vulnerabilities; Attack-defense-tree–based rating of flow exploitability.We demonstrate the effectiveness of NodeMedic through a large-scale evaluation of 10,000 Node.js packages. Our evaluation uncovers 155 vulnerabilities, of which 152 are previously undisclosed, and 108 were confirmed with automatically synthesized exploits. We have open-sourced NodeMedic and a suite of 589 taint precision unit tests.
Darion Cassel, Wai Tuck Wong, Limin Jia 0001
EuroS&P2