Albert Li

dblp:74/4422 · DBLP profile ↗
← Back
5ranked-venue papers
0as first author
3since 2021 · last 2023
0009-0006-6638-917XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 3 since 2021Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1Computer networks · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Software testing · 50% Program analysis · 50%
Network and information security
3 papers
Authentication and access control · 87% Systems and software security · 13%
Artificial intelligence
1 paper
Robot manipulation · 100%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Cloud and datacenter computing · 100%

Topics — the 10 heaviest of 13, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Authentication and access control › access control policy engineering
access control verification
1.122022
Quacky: Quantitative Access Control Permissiveness Analyzer✱ · ASE 2022
Quantifying Permissiveness of Access Control Policies · ICSE 2022
Software testing › fuzzing
coverage-guided fuzzing
0.712023
Rare Path Guided Fuzzing · ISSTA 2023
Program analysis › symbolic execution
dynamic symbolic execution
0.712023
Rare Path Guided Fuzzing · ISSTA 2023
Software testing
fuzzing
0.712023
Rare Path Guided Fuzzing · ISSTA 2023
Program analysis
symbolic execution
0.712023
Rare Path Guided Fuzzing · ISSTA 2023
Robotics › Robot manipulation › grasping
grasp quality evaluation
0.312018
Dex-Net 3.0: Computing Robust Vacuum Suction Grasp Targets in Point Clouds Using a New Analytic Model and Deep Learning · ICRA 2018
Systems and software security
vulnerability discovery
0.212023
Rare Path Guided Fuzzing · ISSTA 2023
Authentication and access control › access control
policy verification
0.212022
Quantifying Permissiveness of Access Control Policies · ICSE 2022
Cloud and datacenter computing › cloud security
cloud access control
0.212022
Quacky: Quantitative Access Control Permissiveness Analyzer✱ · ASE 2022
Network optimization and economics
network design
0.011989
The Programmable Network Prototyping System · INFOCOM 1989

Methods — techniques the papers use, named apart from their topics

model counting · 1.7quantitative symbolic analysis · 1.3path-guided concolic execution · 1.3SMT · 1.1constraint solving · 0.6convolutional neural network · 0.3compliant suction contact model · 0.3
YearPublicationVenuePosition
2023 Rare Path Guided Fuzzing
abstract
Starting with a random initial seed, fuzzers search for inputs that trigger bugs or vulnerabilities. However, fuzzers often fail to generate inputs for program paths guarded by restrictive branch conditions. In this paper, we show that by first identifying rare-paths in programs (i.e., program paths with path constraints that are unlikely to be satisfied by random input generation), and then, generating inputs/seeds that trigger rare-paths, one can improve the coverage of fuzzing tools. In particular, we present techniques 1) that identify rare paths using quantitative symbolic analysis, and 2) generate inputs that can explore these rare paths using path-guided concolic execution. We provide these inputs as initial seed sets to three state of the art fuzzers. Our experimental evaluation on a set of programs shows that the fuzzers achieve better coverage with the rare-path based seed set compared to a random initial seed.
Seemanta Saha, Laboni Sarker, Md Shafiuzzaman, Chaofan Shou, Albert Li, Ganesh Sankaran, Tevfik Bultan
ISSTA5
2022 Quantifying Permissiveness of Access Control Policies
abstract
Due to ubiquitous use of software services, protecting the confidentiality of private information stored in compute clouds is becoming an increasingly critical problem. Although access control specification languages and libraries provide mechanisms for protecting confidentiality of information, without verification and validation techniques that can assist developers in writing policies, complex policy specifications are likely to have errors that can lead to unintended and unauthorized access to data, possibly with disastrous consequences. In this paper, we present a quantitative and differential policy analysis framework that not only identifies if one policy is more permissive than another policy, but also quantifies the relative permissiveness of access control policies. We quantify permissiveness of policies using a model counting constraint solver. We present a heuristic that transforms constraints extracted from access control policies and significantly improves the model counting performance. We demonstrate the effectiveness of our approach by applying it to policies written in Amazon's AWS Identity and Access Management (IAM) policy language and Microsoft's Azure policy language.
William Eiers, Ganesh Sankaran, Albert Li, Emily O'Mahony, Benjamin Prince, Tevfik Bultan
ICSE3
2022 Quacky: Quantitative Access Control Permissiveness Analyzer✱
abstract
quacky is a tool for quantifying permissiveness of access control policies in the cloud. Given a policy, quacky translates it into a SMT formula and uses a model counting constraint solver to quantify permissiveness. When given multiple policies, quacky not only determines which policy is more permissive, but also quantifies the relative permissiveness between the policies. With quacky, policy authors can automatically analyze complex policies, helping them ensure that there is no unintended access to private data. quacky supports access control policies written in the Amazon Web Services (AWS) Identity and Access Management (IAM), Microsoft Azure, and Google Cloud Platform (GCP) policy languages. It has command-line and web interfaces. It is open-source and available at https://github.com/vlab-cs-ucsb/quacky.
William Eiers, Ganesh Sankaran, Albert Li, Emily O'Mahony, Benjamin Prince, Tevfik Bultan
ASE3
2018 Dex-Net 3.0: Computing Robust Vacuum Suction Grasp Targets in Point Clouds Using a New Analytic Model and Deep Learning
abstract
Vacuum-based end effectors are widely used in industry and are often preferred over parallel-jaw and multifinger grippers due to their ability to lift objects with a single point of contact. Suction grasp planners often target planar surfaces on point clouds near the estimated centroid of an object. In this paper, we propose a compliant suction contact model that computes the quality of the seal between the suction cup and local target surface and a measure of the ability of the suction grasp to resist an external gravity wrench. To characterize grasps, we estimate robustness to perturbations in end-effector and object pose, material properties, and external wrenches. We analyze grasps across 1,500 3D object models to generate Dex-Net 3.0, a dataset of 2.8 million point clouds, suction grasps, and grasp robustness labels. We use Dex-Net 3.0 to train a Grasp Quality Convolutional Neural Network (GQ-CNN) to classify robust suction targets in point clouds containing a single object. We evaluate the resulting system in 350 physical trials on an ABB YuMi fitted with a pneumatic suction gripper. When evaluated on novel objects that we categorize as Basic (prismatic or cylindrical), Typical (more complex geometry), and Adversarial (with few available suction-grasp points) Dex-Net 3.0 achieves success rates of 98%, 82%, and 58% respectively, improving to 81% in the latter case when the training set includes only adversarial objects. Code, datasets, and supplemental material can be found at http://berkeleyautomation.github.io/dex-net.
Jeffrey Mahler, Matthew Matl, Xinyu Liu 0014, Albert Li, David V. Gealy, Kenneth Y. Goldberg
ICRA4
1989 The Programmable Network Prototyping System
abstract
The Programmable Network Prototyping System (PNPS), which is a rapid-prototyping tool used for emulating a wide variety of communication networks, is discussed. There are two parts to the PNPS hardware: the reusable hardware modules and the control and observation system. The reusable hardware modules consist of a channel emulator and a collection of node emulators. The channel emulator can be programmed to behave like a variety of network topologies, and each node emulator is configured to behave like a node on a network under study. The control and observation system links these modules together for configuration, experimentation, and monitoring purposes. There are three phases to using PNPS. first, the various components of a proposed network are designed. Next, the components are combined and run on the hardware while its behavior is monitored. Finally, the monitoring data is analyzed in order to evaluate the network design. A menu-driven user interface guides the user through the various tools of the system.>
Randall A. Cieslak, Ayman Fawaz, Sonia Sachs, Pravin Varaiya, Jean C. Walrand, Albert Li
INFOCOM6