EDBT 2026 Demo / reviewers in the wild / expert
Hong Hu 0004
dblp:70/2543-4
· DBLP profile ↗
35ranked-venue papers
4as first author
20since 2021 · last 2026
0000-0002-6261-3190ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 28 · 4 first-author · 17 since 2021Software engineering, systems software and programming languages · 6 · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SACK: Systematic Generation of Function Substitution Attacks Against Control-Flow Integrity
Zhechang Zhang, Hengkai Ye, Hong Hu 0004 |
NDSS | 4 |
| 2026 | Identifying Non-Control Security-Critical Data Through Program Dependence LearningabstractAs control-flow protection gets widely deployed, it is difficult for attackers to corrupt control-data and achieve control-flow hijacking. Instead, data-oriented attacks, which manipulate non-control data, have been demonstrated to be feasible and powerful. In data-oriented attacks, a fundamental step is to identify non-control, security-critical data. However, critical data identification processes are not scalable in previous works, because they mainly rely on tedious human efforts to identify critical data. To address this issue, we propose a novel approach that combines traditional program analysis with deep learning. At a higher level, by examining how analysts identify critical data, we first propose dynamic analysis algorithms to identify the program semantics (and features) that are correlated with the impact of a critical data. Then, motivated by the unique challenges in the critical data identification task, we formalize the distinguishing features and use customized program dependence graphs (PDG) to embed the features. Different from previous works using deep learning to learn basic program semantics, this paper adopts a special neural network architecture that can capture the long dependency paths (in the PDG), through which a critical variable propagates its impact. We have implemented a fully-automatic toolchain and conducted comprehensive evaluations. According to the evaluations, our model can achieve 90% accuracy. The toolchain uncovers 80 potential critical variables in Google FuzzBench. In addition, we demonstrate the harmfulness of the exploits using the identified critical variables by simulating 7 data-oriented attacks through GDB. Hong Hu 0004, Peng Liu 0005 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Too Subtle to Notice: Investigating Executable Stack Issues in Linux Systems
Hengkai Ye, Hong Hu 0004 |
NDSS | 2 |
| 2024 | CountDown: Refcount-guided Fuzzing for Exposing Temporal Memory Errors in Linux KernelabstractKernel use-after-free (UAF) bugs are severe threats to system security due to their complex root causes and high exploitability.We find that 36.1% of recent kernel UAF bugs are caused by improper uses of reference counters, dubbed refcount-related UAF bugs.Current kernel fuzzing tools based on code coverage can detect common memory errors, but none of them is aware of the root cause.As a consequence, they only trigger refcount-related UAF bugs passively and coincidentally, and may miss many deep hidden vulnerabilities.To actively trigger refcount-related UAF bugs, in this paper, we propose CountDown, a novel refcount-guided kernel fuzzer.CountDown collects diverse refcount operations from kernel executions and reshapes syscall relations based on commonly accessed refcounts.When generating user-space programs, CountDown prefers to combine syscalls that ever access the same refcounts, aiming to trigger complex refcount behaviors.It also injects refcountdecreasing and refcount-accessing syscalls to intentionally free the refcounted object and trigger invalid accesses through dangling pointers.We test CountDown on mainstream Linux kernels and compare it with popular fuzzers.On average, our tool can detect 66.1% more UAF bugs and 32.9% more KASAN reports than stateof-the-art tools.CountDown has found nine new kernel memory bugs, where two are fixed and one is confirmed. Shuangpeng Bai, Zhechang Zhang, Hong Hu 0004 |
CCS | 3 |
| 2024 | MalwareTotal: Multi-Faceted and Sequence-Aware Bypass Tactics against Static Malware DetectionabstractRecent methods have demonstrated that machine learning (ML) based static malware detection models are vulnerable to adversarial attacks. However, the generated malware often fails to generalize to production-level anti-malware software (AMS), as they usually involve multiple detection methods. This calls for universal solutions to the problem of malware variants generation. In this work, we demonstrate how the proposed method, MalwareTotal, has allowed malware variants to continue to abound in ML-based, signature-based, and hybrid anti-malware software. Given a malicious binary, we develop sequential bypass tactics that enable malicious behavior to be concealed within multi-faceted manipulations. Through 12 experiments on real-world malware, we demonstrate that an attacker can consistently bypass detection (98.67%, and 100% attack success rate against ML-based methods EMBER and MalConv, respectively; 95.33%, 92.63%, and 98.52% attack success rate against production-level anti-malware software ClamAV, AMS A, and AMS B, respectively) without modifying the malware functionality. We further demonstrate that our approach outperforms state-of-the-art adversarial malware generation techniques both in attack success rate and query consumption (the number of queries to the target model). Moreover, the samples generated by our method have demonstrated transferability in the real-world integrated malware detector, VirusTotal. In addition, we show that common mitigation such as adversarial training on known attacks cannot effectively defend against the proposed attack. Finally, we investigate the value of the generated adversarial examples as a means of hardening victim models through an adversarial training procedure, and demonstrate that the accuracy of the retrained model against generated adversarial examples increases by 88.51 percentage points. Cai Fu, Hong Hu 0004, Jianqiang Lv |
ICSE | 3 |
| 2024 | DEEPTYPE: Refining Indirect Call Targets with Strong Multi-layer Type Analysis
Tianrou Xia, Hong Hu 0004, Dinghao Wu |
USENIX Security Symposium | 2 |
| 2024 | BinCola: Diversity-Sensitive Contrastive Learning for Binary Code Similarity DetectionabstractBinary Code Similarity Detection (BCSD) is a fundamental binary analysis technique in the area of software security. Recently, advanced deep learning algorithms are integrated into BCSD platforms to achieve superior performance on well-known benchmarks. However, real-world large programs embed more complex diversities due to different compilers, various optimization levels, multiple architectures and even obfuscations. Existing BCSD solutions suffer from low accuracy issues in such complicated real-world application scenarios. In this paper, we propose BinCola, a novel Transformer-based dual diversity-sensitive contrastive learning framework that comprehensively considers the diversity of compiler options and candidate functions in the real-world application scenarios and employs the attention mechanism to fuse multi-granularity function features for enhancing generality and scalability. BinCola simultaneously compares multiple candidate functions across various compilation option scenarios to learn the differences caused by distinct compiler options and different candidate functions. We evaluate BinCola's performance in a variety of ways, including binary similarity detection and real-world vulnerability search in multiple application scenarios. The results demonstrate that BinCola achieves superior performance compared to state-of-the-art (SOTA) methods, with improvements of 2.80%, 33.62%, 22.41%, and 34.25% in cross-architecture, cross-optimization level, cross-compiler, and cross-obfuscation scenarios, respectively. Cai Fu, Jianqiang Lv, Lansheng Han, Hong Hu 0004 |
IEEE Trans. Software Eng. | 6 |
| 2023 | µFUZZ: Redesign of Parallel Fuzzing using Microservice Architecture
Yongheng Chen, Yupeng Yang, Hong Hu 0004, Dinghao Wu, Wenke Lee |
USENIX Security Symposium | 4 |
| 2023 | VIPER: Spotting Syscall-Guard Variables for Data-Only Attacks
Hengkai Ye, Zhechang Zhang, Hong Hu 0004 |
USENIX Security Symposium | 4 |
| 2022 | Who goes first? detecting go concurrency bugs via message reorderingabstractGo is a young programming language invented to build safe and efficient concurrent programs. It provides goroutines as lightweight threads and channels for inter-goroutine communication. Programmers are encouraged to explicitly pass messages through channels to connect goroutines, with the purpose of reducing the chance of making programming mistakes and introducing concurrency bugs. Go is one of the most beloved programming languages and has already been used to build many critical infrastructure software systems in the data-center environment. However, a recent study shows that channel-related concurrency bugs are still common in Go programs, severely hurting the reliability of the programs. Shihao Xia, Yu Liang 0002, Linhai Song, Hong Hu 0004 |
ASPLOS | 5 |
| 2022 | SFuzz: Slice-based Fuzzing for Real-Time Operating SystemsabstractReal-Time Operating System (RTOS) has become the main category of embedded systems. It is widely used to support tasks requiring real-time response such as printers and switches. The security of RTOS has been long overlooked as it was running in special environments isolated from attackers. However, with the rapid development of IoT devices, tremendous RTOS devices are connected to the public network. Due to the lack of security mechanisms, these devices are extremely vulnerable to a wide spectrum of attacks. Even worse, the monolithic design of RTOS combines various tasks and services into a single binary, which hinders the current program testing and analysis techniques working on RTOS. In this paper, we propose SFuzz, a novel slice-based fuzzer, to detect security vulnerabilities in RTOS. Our insight is that RTOS usually divides a complicated binary into many separated but single-minded tasks. Each task accomplishes a particular event in a deterministic way and its control flow is usually straightforward and independent. Therefore, we identify such code from the monolithic RTOS binary and synthesize a slice for effective testing. Specifically, SFuzz first identifies functions that handle user input, constructs call graphs that start from callers of these functions, and leverages forward slicing to build the execution tree based on the call graphs and pruning the paths independent of external inputs. Then, it detects and handles roadblocks within the coarse-grain scope that hinder effective fuzzing, such as instructions unrelated to the user input. And then, it conducts coverage-guided fuzzing on these code snippets. Finally, SFuzz leverages forward and backward slicing to track and verify each path constraint and determine whether a bug discovered in the fuzzer is a real vulnerability. SFuzz successfully discovered 77 zero-day bugs on 35 RTOS samples, and 67 of them have been assigned CVE or CNVD IDs. Our empirical evaluation shows that SFuzz outperforms the state-of-the-art tools (e.g., UnicornAFL) on testing RTOS. Libo Chen 0001, Quanpu Cai, Zhenbang Ma, Hong Hu 0004, Minghang Shen, Shanqing Guo, Hai-Xin Duan, Kaida Jiang, Zhi Xue |
CCS | 5 |
| 2022 | COOPER: Testing the Binding Code of Scripting Languages with Cooperative Mutation
Hong Hu 0004, Purui Su |
NDSS | 3 |
| 2022 | FreeWill: Automatically Diagnosing Use-after-free Bugs via Reference Miscounting Detection on Binaries
Liang He 0011, Hong Hu 0004, Purui Su, Yan Cai 0001, Zhenkai Liang |
USENIX Security Symposium | 2 |
| 2022 | Detecting Logical Bugs of DBMS with Coverage-based Guidance
Yu Liang 0002, Hong Hu 0004 |
USENIX Security Symposium | 3 |
| 2021 | Identifying Behavior Dispatchers for Malware AnalysisabstractMalware is a major threat to modern computer systems. Malicious behaviors are hidden by a variety of techniques: code obfuscation, message encoding and encryption, etc. Countermeasures have been developed to thwart these techniques in order to expose malicious behaviors. However, these countermeasures rely heavily on identifying specific API calls, which has significant limitations as these calls can be misleading or hidden from the analyst. In this paper, we show that malicious programs share a key component which we call a behavior dispatcher, a code structure which is intercepted between various condition checks and malicious actions. By identifying these behavior dispatchers, a malware analysis can be guided into behavior dispatchers and activate hidden malicious actions more easily. We propose BDHunter, a system that automatically identifies behavior dispatchers to assist triggering malicious behaviors. BDHunter takes advantage of the observation that a dispatcher compares an input with a set of expected values to determine which malicious behaviors to execute next. We evaluate BDHunter on recent malware samples to identify behavior dispatchers and show that these dispatchers can help trigger more malicious behaviors (otherwise hidden). Our experimental results show that BDHunter identifies 77.4% of dispatchers within the top 20 candidates discovered. Furthermore, BDHunter-guided concolic execution successfully triggers 13.0x and 2.6x more malicious behaviors, compared to unguided symbolic and concolic execution, respectively. These demonstrate that BDHunter effectively identifies behavior dispatchers, which are useful for exposing malicious behaviors. Kyuhong Park, Burak Sahin, Yongheng Chen, Jisheng Zhao, Evan Downing, Hong Hu 0004, Wenke Lee |
AsiaCCS | 6 |
| 2021 | WINNIE : Fuzzing Windows Applications with Harness Synthesis and Fast Cloning
Jinho Jung 0001, Stephen Tong, Hong Hu 0004, Jungwon Lim, Yonghwi Jin, Taesoo Kim |
NDSS | 3 |
| 2021 | One Engine to Fuzz 'em All: Generic Language Processor Testing with Semantic ValidationabstractLanguage processors, such as compilers and interpreters, are indispensable in building modern software. Errors in language processors can lead to severe consequences, like incorrect functionalities or even malicious attacks. However, it is not trivial to automatically test language processors to find bugs. Existing testing methods (or fuzzers) either fail to generate high-quality (i.e., semantically correct) test cases, or only support limited programming languages.In this paper, we propose POLYGLOT, a generic fuzzing framework that generates high-quality test cases for exploring processors of different programming languages. To achieve the generic applicability, POLYGLOT neutralizes the difference in syntax and semantics of programming languages with a uniform intermediate representation (IR). To improve the language validity, POLYGLOT performs constrained mutation and semantic validation to preserve syntactic correctness and fix semantic errors. We have applied POLYGLOT on 21 popular language processors of 9 programming languages, and identified 173 new bugs, 113 of which are fixed with 18 CVEs assigned. Our experiments show that POLYGLOT can support a wide range of programming languages, and outperforms existing fuzzers with up to 30× improvement in code coverage. Yongheng Chen, Hong Hu 0004, Hangfan Zhang, Yupeng Yang, Dinghao Wu, Wenke Lee |
SP | 3 |
| 2021 | Sharing More and Checking Less: Leveraging Common Input Keywords to Detect Bugs in Embedded Systems
Libo Chen 0001, Quanpu Cai, Yunfan Zhan, Hong Hu 0004, Jiaqi Linghu, Qinsheng Hou, Chao Zhang 0008, Hai-Xin Duan, Zhi Xue |
USENIX Security Symposium | 5 |
| 2021 | Preventing Use-After-Free Attacks with Fast Forward Allocation
Brian Wickman, Hong Hu 0004, Insu Yun, Daehee Jang, Jungwon Lim, Sanidhya Kashyap, Taesoo Kim |
USENIX Security Symposium | 2 |
| 2021 | Abusing Hidden Properties to Attack the Node.js Ecosystem
Yichang Xiong, Guangliang Yang 0001, Hong Hu 0004, Guofei Gu, Wenke Lee |
USENIX Security Symposium | 5 |
| 2020 | SQUIRREL: Testing Database Management Systems with Language Validity and Coverage FeedbackabstractFuzzing is an increasingly popular technique for verifying software functionalities and finding security vulnerabilities. However, current mutation-based fuzzers cannot effectively test database management systems (DBMSs), which strictly check inputs for valid syntax and semantics. Generation-based testing can guarantee the syntax correctness of the inputs, but it does not utilize any feedback, like code coverage, to guide the path exploration. Yongheng Chen, Hong Hu 0004, Hangfan Zhang, Wenke Lee, Dinghao Wu |
CCS | 3 |
| 2020 | DESENSITIZATION: Privacy-Aware and Attack-Preserving Crash Report
Ren Ding 0001, Hong Hu 0004, Wen Xu 0002, Taesoo Kim |
NDSS | 2 |
| 2019 | Where Does It Go?: Refining Indirect-Call Targets with Multi-Layer Type AnalysisabstractSystem software commonly uses indirect calls to realize dynamic program behaviors. However, indirect-calls also bring challenges to constructing a precise control-flow graph that is a standard pre-requisite for many static program-analysis and system-hardening techniques. Unfortunately, identifying indirect-call targets is a hard problem. In particular, modern compilers do not recognize indirect-call targets by default. Existing approaches identify indirect-call targets based on type analysis that matches the types of function pointers and the ones of address-taken functions. Such approaches, however, suffer from a high false-positive rate as many irrelevant functions may share the same types. Kangjie Lu, Hong Hu 0004 |
CCS | 2 |
| 2019 | Fuzzification: Anti-Fuzzing Techniques
Jinho Jung 0001, Hong Hu 0004, David Solodukhin, Daniel Pagan, Kyu Hyung Lee, Taesoo Kim |
USENIX Security Symposium | 2 |
| 2019 | RAZOR: A Framework for Post-deployment Software Debloating
Chenxiong Qian, Hong Hu 0004, Mansour Alharthi, Simon P. Chung, Taesoo Kim, Wenke Lee |
USENIX Security Symposium | 2 |
| 2019 | APOLLO: Automatic Detection and Diagnosis of Performance Regressions in Database SystemsabstractThe practical art of constructing database management systems (DBMSs) involves a morass of trade-offs among query execution speed, query optimization speed, standards compliance, feature parity, modularity, portability, and other goals. It is no surprise that DBMSs, like all complex software systems, contain bugs that can adversely affect their performance. The performance of DBMSs is an important metric as it determines how quickly an application can take in new information and use it to make new decisions. Both developers and users face challenges while dealing with performance regression bugs. First, developers usually find it challenging to manually design test cases to uncover performance regressions since DBMS components tend to have complex interactions. Second, users encountering performance regressions are often unable to report them, as the regression-triggering queries could be complex and database-dependent. Third, developers have to expend a lot of effort on localizing the root cause of the reported bugs, due to the system complexity and software development complexity. Given these challenges, this paper presents the design of Apollo, a toolchain for automatically detecting, reporting, and diagnosing performance regressions in DBMSs. We demonstrate that Apollo automates the generation of regression-triggering queries, simplifies the bug reporting process for users, and enables developers to quickly pinpoint the root cause of performance regressions. By automating the detection and diagnosis of performance regressions, Apollo reduces the labor cost of developing efficient DBMSs. Jinho Jung 0001, Hong Hu 0004, Joy Arulraj, Taesoo Kim, Woon-Hak Kang |
Proc. VLDB Endow. | 2 |
| 2018 | Enforcing Unique Code Target Property for Control-Flow IntegrityabstractThe goal of control-flow integrity (CFI) is to stop control-hijacking attacks by ensuring that each indirect control-flow transfer (ICT) jumps to its legitimate target. However, existing implementations of CFI have fallen short of this goal because their approaches are inaccurate and as a result, the set of allowable targets for an ICT instruction is too large, making illegal jumps possible. In this paper, we propose the Unique Code Target (UCT) property for CFI. Namely, for each invocation of an ICT instruction, there should be one and only one valid target. We develop a prototype called uCFI to enforce this new property. During compilation, uCFI identifies the sensitive instructions that influence ICT and instruments the program to record necessary execution context. At runtime, uCFI monitors the program execution in a different process, and performs points-to analysis by interpreting sensitive instructions using the recorded execution context in a memory safe manner. It checks runtime ICT targets against the analysis results to detect CFI violations. We apply uCFI to SPEC benchmarks and 2 servers (nginx and vsftpd) to evaluate its efficacy of enforcing UCT and its overhead. We also test uCFI against control-hijacking attacks, including 5 real-world exploits, 1 proof of concept COOP attack, and 2 synthesized attacks that bypass existing defenses. The results show that uCFI strictly enforces the UCT property for protected programs, successfully detects all attacks, and introduces less than 10% performance overhead. Hong Hu 0004, Chenxiong Qian, Carter Yagemann, Simon P. Chung, William R. Harris, Taesoo Kim, Wenke Lee |
CCS | 1 |
| 2017 | Automatically assessing crashes from heap overflowsabstractHeap overflow is one of the most widely exploited vulnerabilities, with a large number of heap overflow instances reported every year. It is important to decide whether a crash caused by heap overflow can be turned into an exploit. Efficient and effective assessment of exploitability of crashes facilitates to identify severe vulnerabilities and thus prioritize resources. In this paper, we propose the first metrics to assess heap overflow crashes based on both the attack aspect and the feasibility aspect. We further present HCSIFTER, a novel solution to automatically assess the exploitability of heap overflow instances under our metrics. Given a heap-based crash, HCSIFTER accurately detects heap overflows through dynamic execution without any source code or debugging information. Then it uses several novel methods to extract program execution information needed to quantify the severity of the heap overflow using our metrics. We have implemented a prototype HCSIFTER and applied it to assess nine programs with heap overflow vulnerabilities. HCSIFTER successfully reports that five heap overflow vulnerabilities are highly exploitable and two overflow vulnerabilities are unlikely exploitable. It also gave quantitatively assessments for other two programs. On average, it only takes about two minutes to assess one heap overflow crash. The evaluation result demonstrates both effectiveness and efficiency of HC Sifter. Liang He 0011, Yan Cai 0001, Hong Hu 0004, Purui Su, Zhenkai Liang, Yi Yang 0040, Huafeng Huang, Jia Yan 0004, Xiangkun Jia, Dengguo Feng |
ASE | 3 |
| 2016 | "The Web/Local" Boundary Is Fuzzy: A Security Study of Chrome's Process-based SandboxingabstractProcess-based isolation, suggested by several research prototypes, is a cornerstone of modern browser security architectures. Google Chrome is the first commercial browser that adopts this architecture. Unlike several research prototypes, Chrome's process-based design does not isolate different web origins, but primarily promises to protect "the local system" from "the web". However, as billions of users now use web-based cloud services (e.g., Dropbox and Google Drive), which are integrated into the local system, the premise that browsers can effectively isolate the web from the local system has become questionable. In this paper, we argue that, if the process-based isolation disregards the same-origin policy as one of its goals, then its promise of maintaining the "web/local system (local)" separation is doubtful. Specifically, we show that existing memory vulnerabilities in Chrome's renderer can be used as a stepping-stone to drop executables/scripts in the local file system, install unwanted applications and misuse system sensors. These attacks are purely data-oriented and do not alter any control flow or import foreign code. Thus, such attacks bypass binary-level protection mechanisms, including ASLR and in-memory partitioning. Finally, we discuss various full defenses and present a possible way to mitigate the attacks presented. Yaoqi Jia, Zheng Leong Chua, Hong Hu 0004, Shuo Chen 0001, Prateek Saxena, Zhenkai Liang |
CCS | 3 |
| 2016 | Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksabstractAs control-flow hijacking defenses gain adoption, it is important to understand the remaining capabilities of adversaries via memory exploits. Non-control data exploits are used to mount information leakage attacks or privilege escalation attacks program memory. Compared to control-flow hijacking attacks, such non-control data exploits have limited expressiveness, however, the question is: what is the real expressive power of non-control data attacks? In this paper we show that such attacks are Turing-complete. We present a systematic technique called data-oriented programming (DOP) to construct expressive non-control data exploits for arbitrary x86 programs. In the experimental evaluation using 9 programs, we identified 7518 data-oriented x86 gadgets and 5052 gadget dispatchers, which are the building blocks for DOP. 8 out of 9 real-world programs have gadgets to simulate arbitrary computations and 2 of them are confirmed to be able to build Turing-complete attacks. We build 3 end-to-end attacks to bypass randomization defenses without leaking addresses, to run a network bot which takes commands from the attacker, and to alter the memory permissions. All the attacks work in the presence of ASLR and DEP, demonstrating how the expressiveness offered by DOP significantly empowers the attacker. Hong Hu 0004, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua, Prateek Saxena, Zhenkai Liang |
IEEE Symposium on Security and Privacy | 1 |
| 2015 | Identifying Arbitrary Memory Access Vulnerabilities in Privilege-Separated Software
Hong Hu 0004, Zheng Leong Chua, Zhenkai Liang, Prateek Saxena |
ESORICS (2) | 1 |
| 2015 | Automatic Generation of Data-Oriented Exploits
Hong Hu 0004, Zheng Leong Chua, Sendroiu Adrian, Prateek Saxena, Zhenkai Liang |
USENIX Security Symposium | 1 |
| 2014 | DroidVault: A Trusted Data Vault for Android DevicesabstractMobile OSes and applications form a large, complex and vulnerability-prone software stack. In such an environment, security techniques to strongly protect sensitive data in mobile devices are important and challenging. To address such challenges, we introduce the concept of the trusted data vault, a small trusted engine that securely manages the storage and usage of sensitive data in an untrusted mobile device. In this paper, we design and build Droid Vault - the first realization of a trusted data vault on the Android platform. Droid Vault establishes a secure channel between data owners and data users while allowing data owners to enforce strong control over the sensitive data with a minimal trusted computing base (TCB). We prototype Droid Vault via the novel use of hardware security features of ARM processors, i.e., Trust Zone. Our evaluation demonstrates its functionality for processing sensitive data and its practicality for adoption in the real world. Hong Hu 0004, Guangdong Bai, Yaoqi Jia, Zhenkai Liang, Prateek Saxena |
ICECCS | 2 |
| 2014 | Practical Analysis Framework for Software-Based Attestation Scheme
Li Li 0044, Hong Hu 0004, Jun Sun 0001, Yang Liu 0003, Jin Song Dong 0001 |
ICFEM | 2 |
| 2013 | A Quantitative Evaluation of Privilege Separation in Web Browser Designs
Xinshu Dong, Hong Hu 0004, Prateek Saxena, Zhenkai Liang |
ESORICS | 2 |