Paul Montague

dblp:50/805 · DBLP profile ↗
← Back
40ranked-venue papers
1as first author
23since 2021 · last 2026
0000-0001-9461-7471ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 21 · 1 first-author · 13 since 2021Security and privacy · 12 · 8 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 5 since 2021Databases, data management, data science and information retrieval · 4 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2026 Certified but Fooled! Breaking Certified Defenses with Ghost Certificates
abstract
Certified defenses promise provable robustness guarantees. We study the malicious exploitation of probabilistic certification frameworks to better understand the limits of guarantee provisions. Now, the objective is to not only mislead a classifier, but also to manipulate the certification process to generate a robustness guarantee for an adversarial input—certificate spoofing. A recent study in ICLR demonstrated that crafting large perturbations can shift inputs far into regions capable of generating a certificate for an incorrect class. Our study investigates if perturbations are needed to cause a misclassification and yet coax a certified model into issuing a deceptive, large robustness radius for a target class can still be made small and imperceptible. We explore the idea of region-focused adversarial examples to craft imperceptible perturbations, spoof certificates and achieve certification radii larger than the source class—ghost certificates. Extensive evaluations with the ImageNet demonstrate the ability to effectively bypass state-of-the-art certified defenses such as Densepure. Our work underscores the need to better understand the limits of robustness certification methods.
Viet Quoc Vo, Tashreque Mohammed Haq, Paul Montague, Tamas Abraham, Ehsan Abbasnejad, Damith Chinthana Ranasinghe
AAAI3
2025 Fantastic Targets for Concept Erasure in Diffusion Models and Where To Find Them
abstract
Concept erasure has emerged as a promising technique for mitigating the risk of harmful content generation in diffusion models by selectively unlearning undesirable concepts. The common principle of previous works to remove a specific concept is to map it to a fixed generic concept, such as a neutral concept or just an empty text prompt. In this paper, we demonstrate that this fixed-target strategy is suboptimal, as it fails to account for the impact of erasing one concept on the others. To address this limitation, we model the concept space as a graph and empirically analyze the effects of erasing one concept on the remaining concepts. Our analysis uncovers intriguing geometric properties of the concept space, where the influence of erasing a concept is confined to a local region. Building on this insight, we propose the Adaptive Guided Erasure (AGE) method, which dynamically selects optimal target concepts tailored to each undesirable concept, minimizing unintended side effects. Experimental results show that AGE significantly outperforms state-of-the-art erasure methods on preserving unrelated concepts while maintaining effective erasure performance. Our code is published at {https://github.com/tuananhbui89/Adaptive-Guided-Erasure}.
Anh Tuan Bui, Thuy-Trang Vu, Long Tung Vuong, Trung Le 0001, Paul Montague, Tamas Abraham, Junae Kim, Dinh Q. Phung
ICLR5
2025 Multi-level Certified Defense Against Poisoning Attacks in Offline Reinforcement Learning
abstract
Similar to other machine learning frameworks, Offline Reinforcement Learning (RL) is shown to be vulnerable to poisoning attacks, due to its reliance on externally sourced datasets, a vulnerability that is exacerbated by its sequential nature. To mitigate the risks posed by RL poisoning, we extend certified defenses to provide larger guarantees against adversarial manipulation, ensuring robustness for both per-state actions, and the overall expected cumulative reward. Our approach leverages properties of Differential Privacy, in a manner that allows this work to span both continuous and discrete spaces, as well as stochastic and deterministic environments---significantly expanding the scope and applicability of achievable guarantees. Empirical evaluations demonstrate that our approach ensures the performance drops to no more than 50% with up to 7% of the training data poisoned, significantly improving over the 0.008% in prior work (Wu et al., 2022), while producing certified radii that is 5 times larger as well. This highlights the potential of our framework to enhance safety and reliability in offline RL.
Shijie Liu 0004, Andrew C. Cullen, Paul Montague, Sarah M. Erfani, Benjamin I. P. Rubinstein
ICLR3
2025 3D-Prover: Diversity Driven Theorem Proving With Determinantal Point Processes
abstract
A key challenge in automated formal reasoning is the intractable search space, which grows exponentially with the depth of the proof. This branching is caused by the large number of candidate proof tactics which can be applied to a given goal. Nonetheless, many of these tactics are semantically similar or lead to an execution error, wasting valuable resources in both cases. We address the problem of effectively pruning this search, using only synthetic data generated from previous proof attempts. We first demonstrate that it is possible to generate semantically aware tactic representations which capture the effect on the proving environment, likelihood of success, and execution time. We then propose a novel filtering mechanism which leverages these representations to select semantically diverse and high quality tactics, using Determinantal Point Processes. Our approach, 3D-Prover, is designed to be general, and to augment any underlying tactic generator. We demonstrate the effectiveness of 3D-Prover on the miniF2F and LeanDojo benchmarks by augmenting popular open source proving LLMs. We show that our approach leads to an increase in the overall proof rate, as well as a significant improvement in the tactic success rate, execution time and diversity. We make our code available at https://github.com/sean-lamont/3D-Prover.
Sean Lamont, Christian Walder, Amir Dezfouli, Paul Montague, Michael Norrish
NeurIPS4
2025 Slice+Slice Baby: Generating Last-Level Cache Eviction Sets in the Blink of an Eye
abstract
An essential step for mounting cache attacks is finding eviction sets, collections of memory locations that contend on cache space. On Intel processors, one of the main challenges for identifying contending addresses is the sliced cache design, where the processor hashes the physical address to determine where in the cache a memory location is stored. While past works have demonstrated that the hash function can be reversed, they also showed that it depends on physical address bits that the adversary does not know. In this work, we make three main contributions to the art of finding eviction sets. We first exploit microarchitectural races to compare memory access times and identify the cache slice to which an address maps. We then use the known hash function to both reduce the error rate in our slice identification method and to reduce the work by extrapolating slice mappings to untested memory addresses. Finally, we show how to propagate information on eviction sets across different page offsets for the hitherto unexplored case of non-linear hash functions. Our contributions allow for entire LLC eviction set generation in 0.7 seconds on the Intel i7-9850H and 1.6 seconds on the i9-10900K, both using non-linear functions. This represents a significant improvement compared to state-of-the-art techniques taking 9× and 10× longer, respectively.
Bradley Morgan, Gal Horowitz, Sioli O'Connell, Stephan van Schaik, Chitchanok Chuengsatiansup, Daniel Genkin, Olaf Maennel, Paul Montague, Eyal Ronen, Yuval Yarom
SP8
2025 Graph spectral purification for backdoor defence in graph neural networks
Shuiqiao Yang, Bao Gia Doan, Paul Montague, Olivier Y. de Vel, Tamas Abraham, Alsharif Abuadbba, Ehsan Abbasnejad, Seyit Ahmet Çamtepe, Damith Chinthana Ranasinghe, Salil S. Kanhere
World Wide Web (WWW)3
2024 BAIT: Benchmarking (Embedding) Architectures for Interactive Theorem-Proving
abstract
Artificial Intelligence for Theorem Proving (AITP) has given rise to a plethora of benchmarks and methodologies, particularly in Interactive Theorem Proving (ITP). Research in the area is fragmented, with a diverse set of approaches being spread across several ITP systems. This presents a significant challenge to the comparison of methods, which are often complex and difficult to replicate. Addressing this, we present BAIT, a framework for the fair and streamlined comparison of learning approaches in ITP. We demonstrate BAIT’s capabilities with an in-depth comparison, across several ITP benchmarks, of state-of-the-art architectures applied to the problem of formula embedding. We find that Structure Aware Transformers perform particularly well, improving on techniques associated with the original problem sets. BAIT also allows us to assess the end-to-end proving performance of systems built on interactive environments. This unified perspective reveals a novel end-to-end system that improves on prior work. We also provide a qualitative analysis, illustrating that improved performance is associated with more semantically-aware embeddings. By streamlining the implementation and comparison of Machine Learning algorithms in the ITP context, we anticipate BAIT will be a springboard for future research.
Sean Lamont, Michael Norrish, Amir Dezfouli, Christian Walder, Paul Montague
AAAI5
2024 On the Credibility of Backdoor Attacks Against Object Detectors in the Physical World
abstract
Deep learning system components are vulnerable to backdoor attacks. Detectors are no exception. Detectors, in contrast to classifiers, possess unique characteristics, architecturally and in task execution; often operating in challenging conditions, for instance, detecting traffic signs in autonomous cars. But, our knowledge dominates attacks against classifiers and tests in the "digital domain".To address this critical gap, we conducted an extensive empirical study targeting multiple detector architectures and two challenging detection tasks in real-world settings: traffic signs and vehicles. Using diverse, methodically collected videos captured from driving cars and flying drones, incorporating physical object trigger deployments in authentic scenes, we investigated the viability of physical object-triggered backdoor attacks in application settings.Our findings revealed 7 key insights. Importantly, the prevalent "digital" data poisoning method for injecting backdoors into models does not lead to effective attacks against detectors in the real world, although proven effective in classification tasks. We construct a new, cost-efficient attack method, dubbed Morphing, incorporating the unique nature of detection tasks; ours is remarkably successful in injecting physical object-triggered backdoors, even capable of poisoning triggers with clean label annotations or invisible triggers without diminishing the success of physical object triggered backdoors. We discovered that the defenses curated are ill-equipped to safeguard detectors against such attacks. To underscore the severity of the threat and foster further research, we, for the first time, release an extensive video test set of real-world backdoor attacks. Our study not only establishes the credibility and seriousness of this threat but also serves as a clarion call to the research community to advance backdoor defenses in the context of object detection. Our dataset—DriveByFlyBy—release, demo videos and code is at https://BackdoorDetectors.github.io.
Bao Gia Doan, Dang Quang Nguyen, Callum Lindquist, Paul Montague, Tamas Abraham, Olivier Y. de Vel, Seyit Ahmet Çamtepe, Salil S. Kanhere, Ehsan Abbasnejad, Damith Chinthana Ranasinghe
ACSAC4
2024 Bayesian Learned Models Can Detect Adversarial Malware for Free
Bao Gia Doan, Dang Quang Nguyen, Paul Montague, Tamas Abraham, Olivier Y. de Vel, Seyit Ahmet Çamtepe, Salil S. Kanhere, Ehsan Abbasnejad, Damith Chinthana Ranasinghe
ESORICS (1)3
2024 Et Tu Certifications: Robustness Certificates Yield Better Adversarial Examples
abstract
In guaranteeing the absence of adversarial examples in an instance's neighbourhood, certification mechanisms play an important role in demonstrating neural net robustness. In this paper, we ask if these certifications can compromise the very models they help to protect? Our new *Certification Aware Attack* exploits certifications to produce computationally efficient norm-minimising adversarial examples $74$% more often than comparable attacks, while reducing the median perturbation norm by more than $10$%. While these attacks can be used to assess the tightness of certification bounds, they also highlight that releasing certifications can paradoxically reduce security.
Andrew C. Cullen, Shijie Liu 0004, Paul Montague, Sarah M. Erfani, Benjamin I. P. Rubinstein
ICML3
2024 Erasing Undesirable Concepts in Diffusion Models with Adversarial Preservation
abstract
Diffusion models excel at generating visually striking content from text but can inadvertently produce undesirable or harmful content when trained on unfiltered internet data. A practical solution is to selectively removing target concepts from the model, but this may impact the remaining concepts. Prior approaches have tried to balance this by introducing a loss term to preserve neutral content or a regularization term to minimize changes in the model parameters, yet resolving this trade-off remains challenging. In this work, we propose to identify and preserving concepts most affected by parameter changes, termed as *adversarial concepts*. This approach ensures stable erasure with minimal impact on the other concepts. We demonstrate the effectiveness of our method using the Stable Diffusion model, showing that it outperforms state-of-the-art erasure methods in eliminating unwanted content while maintaining the integrity of other unrelated elements. Our code is available at \url{https://github.com/tuananhbui89/Erasing-Adversarial-Preservation}.
Anh Bui, Tung Long Vuong, Khanh Doan, Trung Le 0001, Paul Montague, Tamas Abraham, Dinh Q. Phung
NeurIPS5
2024 It's Simplex! Disaggregating Measures to Improve Certified Robustness
abstract
Certified robustness circumvents the fragility of defences against adversarial attacks, by endowing model predictions with guarantees of class invariance for attacks up to a calculated size. While there is value in these certifications, the techniques through which we assess their performance do not present a proper accounting of their strengths and weaknesses, as their analysis has eschewed consideration of performance over individual samples in favour of aggregated measures. By considering the potential output space of certified models, this work presents two distinct approaches to improve the analysis of certification mechanisms, that allow for both dataset-independent and dataset-dependent measures of certification performance. Embracing such a perspective uncovers new certification approaches, which have the potential to more than double the achievable radius of certification, relative to current state-of-the-art. Empirical evaluation verifies that our new approach can certify 9% more samples at noise scale σ = 1, with greater relative improvements observed as the difficulty of the predictive task increases.
Andrew C. Cullen, Paul Montague, Shijie Liu 0004, Sarah M. Erfani, Benjamin I. P. Rubinstein
SP2
2024 EaTVul: ChatGPT-based Evasion Attack Against Software Vulnerability Detection
Shigang Liu, Junae Kim, Tamas Abraham, Paul Montague, Seyit Ahmet Çamtepe, Jun Zhang 0010, Yang Xiang 0001
USENIX Security Symposium5
2023 Feature-Space Bayesian Adversarial Learning Improved Malware Detector Robustness
abstract
We present a new algorithm to train a robust malware detector. Malware is a prolific problem and malware detectors are a front-line defense. Modern detectors rely on machine learning algorithms. Now, the adversarial objective is to devise alterations to the malware code to decrease the chance of being detected whilst preserving the functionality and realism of the malware. Adversarial learning is effective in improving robustness but generating functional and realistic adversarial malware samples is non-trivial. Because: i) in contrast to tasks capable of using gradient-based feedback, adversarial learning in a domain without a differentiable mapping function from the problem space (malware code inputs) to the feature space is hard; and ii) it is difficult to ensure the adversarial malware is realistic and functional. This presents a challenge for developing scalable adversarial machine learning algorithms for large datasets at a production or commercial scale to realize robust malware detectors. We propose an alternative; perform adversarial learning in the feature space in contrast to the problem space. We prove the projection of perturbed, yet valid malware, in the problem space into feature space will always be a subset of adversarials generated in the feature space. Hence, by generating a robust network against feature-space adversarial examples, we inherently achieve robustness against problem-space adversarial examples. We formulate a Bayesian adversarial learning objective that captures the distribution of models for improved robustness. To explain the robustness of the Bayesian adversarial learning algorithm, we prove that our learning method bounds the difference between the adversarial risk and empirical risk and improves robustness. We show that Bayesian neural networks (BNNs) achieve state-of-the-art results; especially in the False Positive Rate (FPR) regime. Adversarially trained BNNs achieve state-of-the-art robustness. Notably, adversarially trained BNNs are robust against stronger attacks with larger attack budgets by a margin of up to 15% on a recent production-scale malware dataset of more than 20 million samples. Importantly, our efforts create a benchmark for future defenses in the malware domain.
Bao Gia Doan, Shuiqiao Yang, Paul Montague, Olivier Y. de Vel, Tamas Abraham, Seyit Ahmet Çamtepe, Salil S. Kanhere, Ehsan Abbasnejad, Damith Chinthana Ranasinghe
AAAI3
2023 Enhancing the Antidote: Improved Pointwise Certifications against Poisoning Attacks
abstract
Poisoning attacks can disproportionately influence model behaviour by making small changes to the training corpus. While defences against specific poisoning attacks do exist, they in general do not provide any guarantees, leaving them potentially countered by novel attacks. In contrast, by examining worst-case behaviours Certified Defences make it possible to provide guarantees of the robustness of a sample against adversarial attacks modifying a finite number of training samples, known as pointwise certification. We achieve this by exploiting both Differential Privacy and the Sampled Gaussian Mechanism to ensure the invariance of prediction for each testing instance against finite numbers of poisoned examples. In doing so, our model provides guarantees of adversarial robustness that are more than twice as large as those provided by prior certifications.
Shijie Liu 0004, Andrew C. Cullen, Paul Montague, Sarah M. Erfani, Benjamin I. P. Rubinstein
AAAI3
2023 Leveraging Generative Models for Combating Adversarial Attacks on Tabular Datasets
Jiahui Zhou, Nayyar Abbas Zaidi, Yishuo Zhang, Paul Montague, Junae Kim, Gang Li 0009
PAKDD (1)4
2022 On Global-view Based Defense via Adversarial Attack and Defense Risk Guaranteed Bounds
abstract
It is well-known that deep neural networks (DNNs) are susceptible to adversarial attacks, which presents the most severe fragility of the deep learning system. Despite achieving impressive performance, most of the current state-of-the-art classifiers remain highly vulnerable to carefully crafted imperceptible, adversarial perturbations. Recent research attempts to understand neural network attack and defense have become increasingly urgent and important. While rapid progress has been made on this front, there is still an important theoretical gap in achieving guaranteed bounds on attack/defense models, leaving uncertainty in the quality and certified guarantees of these models. To this end, we systematically address this problem in this paper. More specifically, we formulate attack and defense in a generic setting where there exists a family of adversaries (i.e., attackers) for attacking a family of classifiers (i.e., defenders). We develop a novel class of f-divergences suitable for measuring divergence among multiple distributions. This equips us to study the interactions between attackers and defenders in a countervailing game where we formulate a joint risk on attack and defense schemes. This is followed by our key results on guaranteed upper and lower bounds on this risk that can provide a better understanding of the behaviors of those parties from the attack and defense perspectives, thereby having important implications to both attack and defense sides. Finally, benefited from our theory, we propose an empirical approach that bases on a global view to defend against adversarial attacks. The experimental results conducted on benchmark datasets show that the global view for attack/defense if exploited appropriately can help to improve adversarial robustness.
Trung Le 0001, Anh Tuan Bui, Le Minh Tri Tue, He Zhao 0001, Paul Montague, Quan Hung Tran, Dinh Q. Phung
AISTATS5
2022 Double Bubble, Toil and Trouble: Enhancing Certified Robustness through Transitivity
abstract
In response to subtle adversarial examples flipping classifications of neural network models, recent research has promoted certified robustness as a solution. There, invariance of predictions to all norm-bounded attacks is achieved through randomised smoothing of network inputs. Today's state-of-the-art certifications make optimal use of the class output scores at the input instance under test: no better radius of certification (under the $L_2$ norm) is possible given only these score. However, it is an open question as to whether such lower bounds can be improved using local information around the instance under test. In this work, we demonstrate how today's ``optimal'' certificates can be improved by exploiting both the transitivity of certifications, and the geometry of the input space, giving rise to what we term Geometrically-Informed Certified Robustness. By considering the smallest distance to points on the boundary of a set of certifications this approach improves certifications for more than $80 \%$ of Tiny-Imagenet instances, yielding an on average $5\%$ increase in the associated certification. When incorporating training time processes that enhance the certified radius, our technique shows even more promising results, with a uniform $4$ percentage point increase in the achieved certified radius.
Andrew C. Cullen, Paul Montague, Shijie Liu 0004, Sarah M. Erfani, Benjamin I. P. Rubinstein
NeurIPS2
2022 Transferable Graph Backdoor Attack
abstract
Graph Neural Networks (GNNs) have achieved tremendous success in many graph mining tasks benefitting from the message passing strategy that fuses the local structure and node features for better graph representation learning. Despite the success of GNNs, and similar to other types of deep neural networks, GNNs are found to be vulnerable to unnoticeable perturbations on both graph structure and node features. Many adversarial attacks have been proposed to disclose the fragility of GNNs under different perturbation strategies to create adversarial examples. However, vulnerability of GNNs to successful backdoor attacks was only shown recently.
Shuiqiao Yang, Bao Gia Doan, Paul Montague, Olivier Y. de Vel, Tamas Abraham, Seyit Ahmet Çamtepe, Damith Chinthana Ranasinghe, Salil S. Kanhere
RAID3
2022 CD-VulD: Cross-Domain Vulnerability Discovery Based on Deep Domain Adaptation
abstract
A major cause of security incidents such as cyber attacks is rooted in software vulnerabilities. These vulnerabilities should ideally be found and fixed before the code gets deployed. Machine learning-based approaches achieve state-of-the-art performance in capturing vulnerabilities. These methods are predominantly supervised. Their prediction models are trained on a set of ground truth data where the training data and test data are assumed to be drawn from the same probability distribution. However, in practice, the test data often differs from the training data in terms of distribution because they are from different projects or they differ in the types of vulnerability. In this article, we present a new system forCrossDomain SoftwareVulnerabilityDiscovery (CD-VulD) using deep learning (DL) and domain adaptation (DA). We employ DL because it has the capacity of automatically constructing high-level abstract feature representations of programs, which are likely of more cross-domain useful than the handcrafted features driven by domain knowledge. The divergence between distributions is reduced by learning cross-domain representations. First, given software program representations, CD-VulD converts them into token sequences and learns the token embeddings for generalization across tokens. Next, CD-VulD employs a deep feature model to build abstract high-level presentations based on those sequences. Then, the metric transfer learning framework (MTLF) technique is employed to learn cross-domain representations by minimizing the distribution divergence between the source domain and the target domain. Finally, the cross-domain representations are used to build a classifier for vulnerability detection. Experimental results show that CD-VulD outperforms the state-of-the-art vulnerability detection approaches by a wide margin. We make the new datasets publicly available so that our work is replicable and can be further improved.
Shigang Liu, Guanjun Lin, Lizhen Qu, Jun Zhang 0010, Olivier Y. de Vel, Paul Montague, Yang Xiang 0001
IEEE Trans. Dependable Secur. Comput.6
2021 Improving Ensemble Robustness by Collaboratively Promoting and Demoting Adversarial Robustness
abstract
Ensemble-based Adversarial Training is a principled approach to achieve robustness against adversarial attacks. An important technicality of this approach is to control the transferability of adversarial examples between ensemble members. We propose in this work a simple, but effective strategy to collaborate among committee models of an ensemble model. This is achieved via the secure and insecure sets defined for each model member on a given sample, hence help us to quantify and regularize the transferability. Consequently, our proposed framework provides the flexibility to reduce the adversarial transferability as well as promote the diversity of ensemble members, which are two crucial factors for better robustness in our ensemble approach. We conduct extensive and comprehensive experiments to demonstrate that our proposed method outperforms the state-of-the-art ensemble baselines, at the same time can detect a wide range of adversarial examples with a near perfect accuracy.
Tuan-Anh Bui, Trung Le 0001, He Zhao 0001, Paul Montague, Olivier Y. de Vel, Tamas Abraham, Dinh Q. Phung
AAAI4
2021 Information-theoretic Source Code Vulnerability Highlighting
abstract
Software vulnerabilities are a crucial and serious concern in the software industry and computer security. A variety of methods have been proposed to detect vulnerabilities in real-world software. Recent methods based on deep learning approaches for automatic feature extraction have improved software vulnerability identification compared with machine learning approaches based on hand-crafted feature extraction. However, these methods can usually only detect software vulnerabilities at a function or program level, which is much less informative because, out of hundreds (thousands) of code statements in a program or function, only a few core statements contribute to a software vulnerability. This requires us to find a way to detect software vulnerabilities at a fine-grained level. In this paper, we propose a novel method based on the concept of mutual information that can help us to detect and isolate software vulnerabilities at a fine-grained level (i.e., several statements that are highly relevant to a software vulnerability that include the core vulnerable statements) in both unsupervised and semi-supervised contexts. We conduct comprehensive experiments on real-world software projects to demonstrate that our proposed method can detect vulnerabilities at a fine-grained level by identifying several statements that mostly contribute to the vulnerability detection decision.
Van Nguyen 0002, Trung Le 0001, Olivier Y. de Vel, Paul Montague, John C. Grundy, Dinh Q. Phung
IJCNN4
2021 Software Vulnerability Discovery via Learning Multi-Domain Knowledge Bases
abstract
Machine learning (ML) has great potential in automated code vulnerability discovery. However, automated discovery application driven by off-the-shelf machine learning tools often performs poorly due to the shortage of high-quality training data. The scarceness of vulnerability data is almost always a problem for any developing software project during its early stages, which is referred to as the cold-start problem. This article proposes a framework that utilizes transferable knowledge from pre-existing data sources. In order to improve the detection performance, multiple vulnerability-relevant data sources were selected to form a broader base for learning transferable knowledge. The selected vulnerability-relevant data sources are cross-domain, including historical vulnerability data from different software projects and data from the Software Assurance Reference Database (SARD) consisting of synthetic vulnerability examples and proof-of-concept test cases. To extract the information applicable in vulnerability detection from the cross-domain data sets, we designed a deep-learning-based framework with Long-short Term Memory (LSTM) cells. Our framework combines the heterogeneous data sources to learn unified representations of the patterns of the vulnerable source codes. Empirical studies showed that the unified representations generated by the proposed deep learning networks are feasible and effective, and are transferable for real-world vulnerability detection. Our experiments demonstrated that by leveraging two heterogeneous data sources, the performance of our vulnerability detection outperformed the static vulnerability discovery toolFlawfinder. The findings of this article may stimulate further research in ML-based vulnerability detection using heterogeneous data sources.
Guanjun Lin, Jun Zhang 0010, Wei Luo 0001, Lei Pan 0002, Olivier Y. de Vel, Paul Montague, Yang Xiang 0001
IEEE Trans. Dependable Secur. Comput.6
2020 Improving Adversarial Robustness by Enforcing Local and Global Compactness
Tuan-Anh Bui, Trung Le 0001, He Zhao 0001, Paul Montague, Olivier Y. de Vel, Tamas Abraham, Dinh Q. Phung
ECCV (27)4
2020 Adversarial Reinforcement Learning under Partial Observability in Autonomous Computer Network Defence
abstract
Recent studies have demonstrated that reinforcement learning (RL) agents are susceptible to adversarial manipulation, similar to vulnerabilities previously demonstrated in the supervised learning setting. While most existing work studies the problem in the context of computer vision or console games, this paper focuses on reinforcement learning in autonomous cyber defence under partial observability. We demonstrate that under the black-box setting, where the attacker has no direct access to the target RL model, causative attacks-attacks that target the training process-can poison RL agents even if the attacker only has partial observability of the environment. In addition, we propose an inversion defence method that aims to apply the opposite perturbation to that which an attacker might use to generate their adversarial samples. Our experimental results illustrate that the countermeasure can effectively reduce the impact of the causative attack, while not significantly affecting the training process in non-attack scenarios.
Yi Han 0003, David Hubczenko, Paul Montague, Olivier Y. de Vel, Tamas Abraham, Benjamin I. P. Rubinstein, Christopher Leckie, Tansu Alpcan, Sarah M. Erfani
IJCNN3
2020 Code Pointer Network for Binary Function Scope Identification
abstract
Function identification is a preliminary step in binary analysis for many extensive applications from malware detection, common vulnerability detection and binary instrumentation to name a few. In this paper, we propose the Code Pointer Network that leverages the underlying idea of a pointer network to efficiently and effectively tackle function scope identification - the hardest and most crucial task in function identification. We establish extensive experiments to compare our proposed method with the deep learning based baseline. Experimental results demonstrate that our proposed method significantly outperforms the state-of-the-art baseline in terms of both predictive performance and running time.
Van Nguyen 0002, Trung Le 0001, Tue Le, Olivier Y. de Vel, Paul Montague, Dinh Q. Phung
IJCNN6
2020 Code Action Network for Binary Function Scope Identification
Van Nguyen 0002, Trung Le 0001, Tue Le, Olivier Y. de Vel, Paul Montague, John C. Grundy, Dinh Q. Phung
PAKDD (1)6
2020 Deep Cost-Sensitive Kernel Machine for Binary Software Vulnerability Detection
Tuan Nguyen 0004, Trung Le 0001, Olivier Y. de Vel, Paul Montague, John C. Grundy, Dinh Q. Phung
PAKDD (2)5
2020 Dual-Component Deep Domain Adaptation: A New Approach for Cross Project Software Vulnerability Detection
Van Nguyen 0002, Trung Le 0001, Olivier Y. de Vel, Paul Montague, John C. Grundy, Dinh Q. Phung
PAKDD (1)4
2019 Towards Attention Based Vulnerability Discovery Using Source Code Representation
Junae Kim, David Hubczenko, Paul Montague
ICANN (4)3
2019 Maximal Divergence Sequential Autoencoder for Binary Software Vulnerability Detection
Tue Le, Tuan Nguyen 0004, Trung Le 0001, Dinh Q. Phung, Paul Montague, Olivier Y. de Vel, Lizhen Qu
ICLR (Poster)5
2019 Deep Domain Adaptation for Vulnerable Code Function Identification
abstract
Due to the ubiquity of computer software, software vulnerability detection (SVD) has become crucial in the software industry and in the field of computer security. Two significant issues in SVD arise when using machine learning, namely: i) how to learn automatic features that can help improve the predictive performance of vulnerability detection and ii) how to overcome the scarcity of labeled vulnerabilities in projects that require the laborious labeling of code by software security experts. In this paper, we address these two crucial concerns by proposing a novel architecture which leverages deep domain adaptation with automatic feature learning for software vulnerability identification. Based on this architecture, we keep the principles and reapply the state-of-the-art deep domain adaptation methods to indicate that deep domain adaptation for SVD is plausible and promising. Moreover, we further propose a novel method named Semi-supervised Code Domain Adaptation Network (SCDAN) that can efficiently utilize and exploit information carried in unlabeled target data by considering them as the unlabeled portion in a semi-supervised learning context. The proposed SCDAN method enforces the clustering assumption, which is a key principle in semi-supervised learning. The experimental results using six real-world software project datasets show that our SCDAN method and the baselines using our architecture have better predictive performance by a wide margin compared with the Deep Code Network (VulDeePecker) method without domain adaptation. Also, the proposed SCDAN significantly outperforms the DIRT-T which to the best of our knowledge is currently the-state-of-the-art method in deep domain adaptation and other baselines.
Van Nguyen 0002, Trung Le 0001, Tue Le, Olivier Y. de Vel, Paul Montague, Lizhen Qu, Dinh Q. Phung
IJCNN6
2018 Cross-Project Transfer Representation Learning for Vulnerable Function Discovery
abstract
Machine learning is now widely used to detect security vulnerabilities in the software, even before the software is released. But its potential is often severely compromised at the early stage of a software project when we face a shortage of high-quality training data and have to rely on overly generic hand-crafted features. This paper addresses this cold-start problem of machine learning, by learning rich features that generalize across similar projects. To reach an optimal balance between feature-richness and generalizability, we devise a data-driven method including the following innovative ideas. First, the code semantics are revealed through serialized abstract syntax trees (ASTs), with tokens encoded by Continuous Bag-of-Words neural embeddings. Next, the serialized ASTs are fed to a sequential deep learning classifier (Bi-LSTM) to obtain a representation indicative of software vulnerability. Finally, the neural representation obtained from existing software projects is then transferred to the new project to enable early vulnerability detection even with a small set of training labels. To validate this vulnerability detection approach, we manually labeled 457 vulnerable functions and collected 30 000+ nonvulnerable functions from six open-source projects. The empirical results confirmed that the trained model is capable of generating representations that are indicative of program vulnerability and is adaptable across multiple projects. Compared with the traditional code metrics, our transfer-learned representations are more effective for predicting vulnerable functions, both within a project and across multiple projects.
Guanjun Lin, Jun Zhang 0010, Wei Luo 0001, Lei Pan 0002, Yang Xiang 0001, Olivier Y. de Vel, Paul Montague
IEEE Trans. Ind. Informatics7
2017 An efficient semi-supervised SVM for anomaly detection
abstract
Semi-Supervised Support Vector Machines (S3VMs) have been proposed to deal with the proliferation of partially labelled data available in many large-scale complex systems. Since most existing S3VMs do not correspond to convex problems nor have practical solutions especially on large imbalanced data, this limits their utility in practice. In this work, we propose an efficient approach to the semi-supervised problem especially for anomaly detection, termed S3VMAD. We formulate S3VMAD in unsupervised paradigm for anomaly detection. It is a convex objective function which is guaranteed to have a global optimum solution. The proposed approach is compatible with both supervised Support Vector Machines (SVMs) and unsupervised One-Class SVM (OCSVM). In addition, it exploits efficient optimisation techniques in an online fashion as well as in batch mode, which enables the solution to be scalable and therefore practical in the case of large datasets. In order to investigate the efficiency and effectiveness of the proposed S3VMAD, experiments on various sample datasets compare with supervised SVM learning, Semi-Supervised Anomaly Detection (SSAD), and unsupervised learning.
Paul Montague, Junae Kim
IJCNN1
2012 A Context-Based Integrity Framework
abstract
Although there is significant research and development into information security areas such as confidentiality and availability, scope remains for attention to the third fundamental security property: integrity. The Biba and Clark-Wilson models are still the most recognised for managing integrity of data in systems. After identifying several desirable extensions to the original ideas in these models, we present a new integrity framework, which can allow for a more flexible, quantitative, and context sensitive management of data integrity on a system wide basis.
Paul Montague, Benjamin Long
APSEC2
2005 GBD Threshold Cryptography with an Application to RSA Key Recovery
Chris Steketee, Jaimee Brown, Juan Manuel González Nieto, Paul Montague
ACISP4
2003 The Security of Fixed versus Random Elliptic Curves in Cryptography
Yvonne Hitchcock, Paul Montague, Gary Carter, Ed Dawson
ACISP2
2002 A New Elliptic Curve Scalar Multiplication Algorithm to Resist Simple Power Analysis
Yvonne Hitchcock, Paul Montague
ACISP2
2001 Elliptic Curve Based Password Authenticated Key Exchange Protocols
Colin Boyd, Paul Montague, Khanh Quoc Nguyen
ACISP2
1999 An elliptic curve authenticated key exchange based approach to key infrastructure
abstract
Introduces an elliptic curve analogue to the existing exponential/encrypted key exchange methods, with a view to optimizing such techniques for implementation within a mobile (wireless) framework. The complete scheme of how these methods can be adopted, along with the other security components (e.g. proxies) in the existing infrastructure is analysed. In this paper, we discuss the complete key setup procedures and various scenarios describing how confidential communication is performed once the key has been set up and mutual authentication achieved. The advantages of the proposed schemes are discussed.
Praveen Koduri, Anant Mahajan, Paul Montague, Philip Moseley
KES3