EDBT 2026 Demo / reviewers in the wild / expert
David Evans 0001
dblp:e/DavidEvans · also David E. Evans 0001
· DBLP profile ↗
77ranked-venue papers
7as first author
21since 2021 · last 2026
0000-0001-7988-8943ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 49 · 3 first-author · 9 since 2021Artificial intelligence and machine learning · 16 · 10 since 2021Software engineering, systems software and programming languages · 7 · 4 first-authorSystems, architecture and hardware · 4 · 1 since 2021Computer networks · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Beyond Indistinguishability: Measuring Extraction Risk in LLM APIs
Ruixuan Liu, David Evans 0001, Li Xiong 0001 |
SP | 2 |
| 2025 | Unsupervised Concept Vector Extraction for Bias Control in LLMsabstractLarge language models (LLMs) are known to perpetuate stereotypes and exhibit biases.Various strategies have been proposed to mitigate these biases, but most work studies biases as a black-box problem without considering how concepts are represented within the model.We adapt techniques from representation engineering to study how the concept of "gender" is represented within LLMs.We introduce a new method that extracts concept representations via probability weighting without labeled data and efficiently selects a steering vector for measuring and manipulating the model's representation.We develop a projection-based method that enables precise steering of model predictions and demonstrate its effectiveness in mitigating gender bias in LLMs and show that it also generalizes to racial bias. 1 Hannah Cyberey, Yangfeng Ji, David Evans 0001 |
EMNLP | 3 |
| 2024 | TrojanPuzzle: Covertly Poisoning Code-Suggestion ModelsabstractWith tools like GitHub Copilot, automatic code suggestion is no longer a dream in software engineering. These tools, based on large language models, are typically trained on massive corpora of code mined from unvetted public sources. As a result, these models are susceptible to data poisoning attacks where an adversary manipulates the model’s training by injecting malicious data. Poisoning attacks could be designed to influence the model’s suggestions at run time for chosen contexts, such as inducing the model into suggesting insecure code payloads. To achieve this, prior attacks explicitly inject the insecure code payload into the training data, making the poison data detectable by static analysis tools that can remove such malicious data from the training set. In this work, we demonstrate two novel attacks, Covert and TrojanPuzzle, that can bypass static analysis by planting malicious poison data in out-of-context regions such as docstrings. Our most novel attack, TrojanPuzzle, goes one step further in generating less suspicious poison data by never explicitly including certain (suspicious) parts of the payload in the poison data, while still inducing a model that suggests the entire payload when completing code (i.e., outside docstrings). This makes TrojanPuzzle robust against signature-based dataset-cleansing methods that can filter out suspicious sequences from the training data. Our evaluation against models of two sizes demonstrates that both Covert and TrojanPuzzle have significant implications for practitioners when selecting code used to train or tune code-suggestion models. Hojjat Aghakhani, Wei Dai 0007, Andre Manoel, Xavier Fernandes, Anant Kharkar, Christopher Krügel, Giovanni Vigna, David Evans 0001, Benjamin G. Zorn, Robert Sim |
SP | 8 |
| 2024 | Combing for Credentials: Active Pattern Extraction from Smart ReplyabstractPre-trained large language models, such as GPT-2 and BERT, are often fine-tuned to achieve state-of-the-art performance on a downstream task. One natural example is the "Smart Reply" application where a pre-trained model is tuned to provide suggested responses for a given query message. Since the tuning data is often sensitive data such as emails or chat transcripts, it is important to understand and mitigate the risk that the model leaks its tuning data. We investigate potential information leakage vulnerabilities in a typical Smart Reply pipeline. We consider a realistic setting where the adversary can only interact with the underlying model through a frontend interface that constrains what types of queries can be sent to the model. Previous attacks do not work in these settings, but require the ability to send unconstrained queries directly to the model. Even when there are no constraints on the queries, previous attacks typically require thousands, or even millions, of queries to extract useful information, while our attacks can extract sensitive data in just a handful of queries. We introduce a new type of active extraction attack that exploits canonical patterns in text containing sensitive data. We show experimentally that it is possible for an adversary to extract sensitive user information present in the training data, even in realistic settings where all interactions with the model must go through a front-end that limits the types of queries. We explore potential mitigation strategies and demonstrate empirically how differential privacy appears to be a reasonably effective defense mechanism to such pattern extraction attacks. Bargav Jayaraman, Esha Ghosh, Melissa Chase, Sambuddha Roy, Wei Dai 0007, David Evans 0001 |
SP | 6 |
| 2023 | Manipulating Transfer Learning for Property InferenceabstractTransfer learning is a popular method for tuning pretrained (upstream) models for different downstream tasks using limited data and computational resources. We study how an adversary with control over an upstream model used in transfer learning can conduct property inference attacks on a victim's tuned downstream model. For example, to infer the presence of images of a specific individual in the downstream training set. We demonstrate attacks in which an adversary can manipulate the upstream model to conduct highly effective and specific property inference attacks (AUC score > 0.9), without incurring significant performance loss on the main task. The main idea of the manipulation is to make the upstream model generate activations (intermediate features) with different distributions for samples with and without a target property, thus enabling the adversary to distinguish easily between downstream models trained with and without training examples that have the target property. Our code is available at https://github.com/yulongt23/Transfer-Inference. Yulong Tian, Fnu Suya, Anshuman Suri, Fengyuan Xu, David Evans 0001 |
CVPR | 5 |
| 2023 | GlucoSynth: Generating Differentially-Private Synthetic Glucose TracesabstractWe focus on the problem of generating high-quality, private synthetic glucose traces, a task generalizable to many other time series sources. Existing methods for time series data synthesis, such as those using Generative Adversarial Networks (GANs), are not able to capture the innate characteristics of glucose data and cannot provide any formal privacy guarantees without severely degrading the utility of the synthetic data. In this paper we present GlucoSynth, a novel privacy-preserving GAN framework to generate synthetic glucose traces. The core intuition behind our approach is to conserve relationships amongst motifs (glucose events) within the traces, in addition to temporal dynamics. Our framework incorporates differential privacy mechanisms to provide strong formal privacy guarantees. We provide a comprehensive evaluation on the real-world utility of the data using 1.2 million glucose traces; GlucoSynth outperforms all previous methods in its ability to generate high-quality synthetic glucose traces with strong privacy guarantees. Josephine Lamp, Mark Derdzinski, Christopher Hannemann, Joost van der Linden, Lu Feng 0001, Tianhao Wang 0001, David Evans 0001 |
NeurIPS | 7 |
| 2023 | What Distributions are Robust to Indiscriminate Poisoning Attacks for Linear Learners?abstractWe study indiscriminate poisoning for linear learners where an adversary injects a few crafted examples into the training data with the goal of forcing the induced model to incur higher test error. Inspired by the observation that linear learners on some datasets are able to resist the best known attacks even without any defenses, we further investigate whether datasets can be inherently robust to indiscriminate poisoning attacks for linear learners. For theoretical Gaussian distributions, we rigorously characterize the behavior of an optimal poisoning attack, defined as the poisoning strategy that attains the maximum risk of the induced model at a given poisoning budget. Our results prove that linear learners can indeed be robust to indiscriminate poisoning if the class-wise data distributions are well-separated with low variance and the size of the constraint set containing all permissible poisoning points is also small. These findings largely explain the drastic variation in empirical attack performance of the state-of-the-art poisoning attacks on linear learners across benchmark datasets, making an important initial step towards understanding the underlying reasons some learning tasks are vulnerable to data poisoning attacks. Fnu Suya, Xiao Zhang 0016, Yuan Tian 0001, David Evans 0001 |
NeurIPS | 4 |
| 2023 | SoK: Let the Privacy Games Begin! A Unified Treatment of Data Inference Privacy in Machine LearningabstractDeploying machine learning models in production may allow adversaries to infer sensitive information about training data. There is a vast literature analyzing different types of inference risks, ranging from membership inference to reconstruction attacks. Inspired by the success of games (i.e. probabilistic experiments) to study security properties in cryptography, some authors describe privacy inference risks in machine learning using a similar game-based style. However, adversary capabilities and goals are often stated in subtly different ways from one presentation to the other, which makes it hard to relate and compose results. In this paper, we present a game-based framework to systematize the body of knowledge on privacy inference risks in machine learning. We use this framework to (1) provide a unifying structure for definitions of inference risks, (2) formally establish known relations among definitions, and (3) to uncover hitherto unknown relations that would have been difficult to spot otherwise. Ahmed Salem 0001, Giovanni Cherubin, David Evans 0001, Boris Köpf, Andrew Paverd, Anshuman Suri, Shruti Tople, Santiago Zanella-Béguelin |
SP | 3 |
| 2023 | Efficient Privacy-Preserving Stochastic Nonconvex OptimizationabstractWhile many solutions for privacy-preserving convex empirical risk minimization (ERM) have been developed, privacy-preserving nonconvex ERM remains a challenge. We study nonconvex ERM, which takes the form of minimizing a finite-sum of nonconvex loss functions over a training set. We propose a new differentially private stochastic gradient descent algorithm for nonconvex ERM that achieves strong privacy guarantees efficiently, and provide a tight analysis of its privacy and utility guarantees, as well as its gradient complexity. Our algorithm reduces gradient complexity while matching the best-known utility guarantee. Our experiments on benchmark nonconvex ERM problems demonstrate superior performance in terms of both training cost and utility gains compared with previous differentially private methods using the same privacy budgets. Lingxiao Wang 0001, Bargav Jayaraman, David Evans 0001, Quanquan Gu |
UAI | 3 |
| 2022 | Are Attribute Inference Attacks Just Imputation?abstractModels can expose sensitive information about their training data. In an attribute inference attack, an adversary has partial knowledge of some training records and access to a model trained on those records, and infers the unknown values of a sensitive feature of those records. We study a fine-grained variant of attribute inference we call sensitive value inference, where the adversary's goal is to identify with high confidence some records from a candidate set where the unknown attribute has a particular sensitive value. We explicitly compare attribute inference with data imputation that captures the training distribution statistics, under various assumptions about the training data available to the adversary. Our main conclusions are: (1) previous attribute inference methods do not reveal more about the training data from the model than can be inferred by an adversary without access to the trained model, but with the same knowledge of the underlying distribution as needed to train the attribute inference attack; (2) black-box attribute inference attacks rarely learn anything that cannot be learned without the model; but (3) white-box attacks, which we introduce and evaluate in the paper, can reliably identify some records with the sensitive value attribute that would not be predicted without having access to the model. Furthermore, we show that proposed defenses such as differentially private training and removing vulnerable records from training do not mitigate this privacy risk. The code for our experiments is available at https://github.com/bargavj/EvaluatingDPML. Bargav Jayaraman, David Evans 0001 |
CCS | 2 |
| 2022 | Balanced Adversarial Training: Balancing Tradeoffs between Fickleness and Obstinacy in NLP ModelsabstractTraditional (fickle) adversarial examples involve finding a small perturbation that does not change an input's true label but confuses the classifier into outputting a different prediction.Conversely, obstinate adversarial examples occur when an adversary finds a small perturbation that preserves the classifier's prediction but changes the true label of an input.Adversarial training and certified robust training have shown some effectiveness in improving the robustness of machine learnt models to fickle adversarial examples.We show that standard adversarial training methods focused on reducing vulnerability to fickle adversarial examples may make a model more vulnerable to obstinate adversarial examples, with experiments for both natural language inference and paraphrase identification tasks.To counter this phenomenon, we introduce Balanced Adversarial Training, which incorporates contrastive learning to increase robustness against both fickle and obstinate adversarial examples. Hannah Cyberey, Yangfeng Ji, David Evans 0001 |
EMNLP | 3 |
| 2022 | An Empirical Analysis of Memorization in Fine-tuned Autoregressive Language ModelsabstractSeveral recent works have shown that large language models present privacy risks through memorization of training data.Little attention, however, has been given to the fine-tuning phase and it is not well understood how memorization risk varies across different fine-tuning methods (such as fine-tuning the full model, the model head, and adapter).This presents increasing concern as the "pre-train and fine-tune" paradigm proliferates.We empirically study memorization of fine-tuning methods using membership inference and extraction attacks, and show that their susceptibility to attacks is very different.We observe that fine-tuning the head of the model has the highest susceptibility to attacks, whereas fine-tuning smaller adapters appears to be less vulnerable to known extraction attacks. Niloofar Mireshghallah, Archit Uniyal, Tianhao Wang 0001, David Evans 0001, Taylor Berg-Kirkpatrick |
EMNLP | 4 |
| 2022 | Understanding Intrinsic Robustness Using Label Uncertainty
Xiao Zhang 0016, David Evans 0001 |
ICLR | 2 |
| 2022 | Comfortable Cohorts and Tractable Teams: Making Large Computing Theory Courses Feel SmallabstractInstructors of introductory theoretical computing courses need to overcome lower initial student motivation ("Why do I need to learn this if I just want to be a programmer?'') and higher student discomfort ("I'm not really a 'math person'.'') to provide an engaging, inclusive, and effective learning experience for students. We present a structure for teaching large ($\sim$300 students) theory of computation courses that enables rich student collaboration and frequent student-staff interaction. We developed this structure to adapt a course that we had previously taught in large lecture format to work in a fully-virtual environment, as mandated by our university's Covid lockdown. Our experience with it led us to adopt many elements of this structure in subsequent and future courses, including those that meet in person. We anecdotally observed that this structure improves students' understanding and enthusiasm for the material. It also facilitated easier teaching assistant recruitment and retention. This paper relates our experience with forming cohorts, designing assignments, and managing teaching assistants, and discusses application of insights gained from this experience to future in-person and virtual courses. Nathan Brunelle, David Evans 0001 |
SIGCSE (1) | 2 |
| 2022 | Formalizing and Estimating Distribution Inference RisksabstractDistribution inference, sometimes called property inference, infers statistical properties about a training set from access to a model trained on that data. Distribution inference attacks can pose serious risks when models are trained on private data, but are difficult to distinguish from the intrinsic purpose of statistical machine learning—namely, to produce models that capture statistical properties about a distribution. Motivated by Yeom et al.’s membership inference framework, we propose a formal definition of distribution inference attacks general enough to describe a broad class of attacks distinguishing between possible training distributions. We show how our definition captures previous ratio-based inference attacks as well as new kinds of attack including revealing the average node degree or clustering coefficient of training graphs. To understand distribution inference risks, we introduce a metric that quantifies observed leakage by relating it to the leakage that would occur if samples from the training distribution were provided directly to the adversary. We report on a series of experiments across a range of different distributions using both novel black-box attacks and improved versions of the state-of-the-art white-box attacks. Our results show that inexpensive attacks are often as effective as expensive meta-classifier attacks, and that there are surprising asymmetries in the effectiveness of attacks. Anshuman Suri, David Evans 0001 |
Proc. Priv. Enhancing Technol. | 2 |
| 2022 | Dynamic System Diversification for Securing Cloud-based IoT SubnetworksabstractRemote exploitation attacks use software vulnerabilities to penetrate through a network of Internet of Things (IoT) devices. This work addresses defending against remote exploitation attacks on vulnerable IoT devices. As an attack mitigation strategy, we assume it is not possible to fix all the vulnerabilities and propose to diversify the open-source software used to manage IoT devices. Our approach is to deploy dynamic cloud-based virtual machine proxies for physical IoT devices. Our architecture leverages virtual machine proxies with diverse software configurations to mitigate vulnerable and static software configurations on physical devices. We develop an algorithm for selecting new configurations based on network anomaly detection signals to learn vulnerable software configurations on IoT devices, automatically shifting towards more secure configurations. Cloud-based proxy machines mediate requests between application clients and vulnerable IoT devices, facilitating a dynamic diversification system. We report on simulation experiments to evaluate the dynamic system. Two models of powerful adversaries are introduced and simulated against the diversified defense strategy. Our experiments show that a dynamically diversified IoT architecture can be invulnerable to large classes of attacks that would succeed against a static architecture. Hussain M. J. Almohri, Layne T. Watson, David Evans 0001, Stephen C. Billups |
ACM Trans. Auton. Adapt. Syst. | 3 |
| 2022 | Stealthy Backdoors as Compression ArtifactsabstractModel compression is a widely-used approach for reducing the size of deep learning models without much accuracy loss, enabling resource-hungry models to be compressed for use on resource-constrained devices. In this paper, we study the risk that model compression could provide an opportunity for adversaries to inject stealthy backdoors. In a backdoor attack on a machine learning model, an adversary produces a model that performs well on normal inputs but outputs targeted misclassifications on inputs containing a small trigger pattern. We design stealthy backdoor attacks such that the full-sized model released by adversaries appears to be free from backdoors (even when tested using state-of-the-art techniques), but when the model is compressed it exhibits a highly effective backdoor. We show this can be done for two common model compression techniques—model pruning and model quantization—even in settings where the adversary has limited knowledge of how the particular compression will be done. Our findings demonstrate the importance of performing security tests on the models that will actually be deployed not in their precompressed version. Our implementation is available athttps://github.com/yulongtzzz/Stealthy-Backdoors-as-Compression-Artifacts. Yulong Tian, Fnu Suya, Fengyuan Xu, David Evans 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2021 | When Models Learn Too MuchabstractStatistical machine learning uses training data to produce models that capture patterns in that data. When models are trained on private data, such as medical records or personal emails, there is a risk that those models not only learn the hoped-for patterns, but will also learn and expose sensitive information about their training data. Several different types of inference attacks on machine learning models have been found, and methods have been proposed to mitigate the risks of exposing sensitive aspects of training data. David Evans 0001 |
CODASPY | 1 |
| 2021 | Improved Estimation of Concentration Under ℓp-Norm Distance Metrics Using Half Spaces
Jack Prescott, Xiao Zhang 0016, David Evans 0001 |
ICLR | 3 |
| 2021 | Model-Targeted Poisoning Attacks with Provable ConvergenceabstractIn a poisoning attack, an adversary who controls a small fraction of the training data attempts to select that data, so a model is induced that misbehaves in a particular way. We consider poisoning attacks against convex machine learning models and propose an efficient poisoning attack designed to induce a model specified by the adversary. Unlike previous model-targeted poisoning attacks, our attack comes with provable convergence to any attainable target model. We also provide a lower bound on the minimum number of poisoning points needed to achieve a given target model. Our method uses online convex optimization and finds poisoning points incrementally. This provides more flexibility than previous attacks which require an a priori assumption about the number of poisoning points. Our attack is the first model-targeted poisoning attack that provides provable convergence for convex models. In our experiments, it either exceeds or matches state-of-the-art attacks in terms of attack success rate and distance to the target model. Fnu Suya, Saeed Mahloujifar, Anshuman Suri, David Evans 0001, Yuan Tian 0001 |
ICML | 4 |
| 2021 | Revisiting Membership Inference Under Realistic AssumptionsabstractAbstract We study membership inference in settings where assumptions commonly used in previous research are relaxed. First, we consider cases where only a small fraction of the candidate pool targeted by the adversary are members and develop a PPV-based metric suitable for this setting. This skewed prior setting is more realistic than the balanced prior setting typically considered. Second, we consider adversaries that select inference thresholds according to their attack goals, such as identifying as many members as possible with a given false positive tolerance. We develop a threshold selection designed for achieving particular attack goals. Since previous inference attacks fail in imbalanced prior settings, we develop new inference attacks based on the intuition that inputs corresponding to training set members will be near a local minimum in the loss function. An attack that combines this with thresholds on the per-instance loss can achieve high PPV even in settings where other attacks are ineffective. Bargav Jayaraman, Lingxiao Wang 0001, Katherine Knipmeyer, Quanquan Gu, David Evans 0001 |
Proc. Priv. Enhancing Technol. | 5 |
| 2020 | Understanding the Intrinsic Robustness of Image Distributions using Conditional Generative ModelsabstractStarting with Gilmer et al. (2018), several works have demonstrated the inevitability of adversarial examples based on different assumptions about the underlying input probability space. It remains unclear, however, whether these results apply to natural image distributions. In this work, we assume the underlying data distribution is captured by some conditional generative model, and prove intrinsic robustness bounds for a general class of classifiers, which solves an open problem in Fawzi et al. (2018). Building upon the state-of-the-art conditional generative models, we study the intrinsic robustness of two common image benchmarks under L2 perturbations, and show the existence of a large gap between the robustness limits implied by our theory and the adversarial robustness achieved by current state-of-the-art robust models. Xiao Zhang 0016, Quanquan Gu, David Evans 0001 |
AISTATS | 4 |
| 2020 | Learning Adversarially Robust Representations via Worst-Case Mutual Information MaximizationabstractTraining machine learning models that are robust against adversarial inputs poses seemingly insurmountable challenges. To better understand adversarial robustness, we consider the underlying problem of learning robust representations. We develop a notion of representation vulnerability that captures the maximum change of mutual information between the input and output distributions, under the worst-case input perturbation. Then, we prove a theorem that establishes a lower bound on the minimum adversarial risk that can be achieved for any downstream classifier based on its representation vulnerability. We propose an unsupervised learning method for obtaining intrinsically robust representations by maximizing the worst-case mutual information between the input and output distributions. Experiments on downstream classification tasks support the robustness of the representations found using unsupervised learning with our training principle. Sicheng Zhu, Xiao Zhang 0016, David Evans 0001 |
ICML | 3 |
| 2020 | Hybrid Batch Attacks: Finding Black-box Adversarial Examples with Limited Queries
Fnu Suya, Jianfeng Chi, David Evans 0001, Yuan Tian 0001 |
USENIX Security Symposium | 3 |
| 2020 | Predictability of IP Address Allocations for Cloud Computing PlatformsabstractOne way to combat denial-of-service attacks on cloud-based virtual networks is to use unpredictable network addresses, aiming to increase attacker effort by requiring attackers to search a large IP address space to find a target host. IP address randomization is used by several moving target defenses, relying on the assumption that it is difficult for an attacker to predict newly allocated IP addresses. This paper analyzes whether IP addresses used by cloud providers are unpredictable enough in practice. We analyze the IP address allocation behaviors in two major cloud computing providers (Amazon Web Services and Google Cloud Platform) and find that the actual entropy provided by allocated IP addresses is limited. We evaluate several prediction models, including a simple frequency-based model as well as a Markov process model that produces an address prediction set from time series data of collected IP addresses. Our results show that simple models can reduce the search space for allocated IP addresses and diminish the effectiveness of randomization defenses. Hussain M. J. Almohri, Layne T. Watson, David Evans 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | An Attack-Resilient Architecture for the Internet of ThingsabstractWith current IoT architectures, once a single device in a network is compromised, it can be used to disrupt the behavior of other devices on the same network. Even though system administrators can secure critical devices in the network using best practices and state-of-the-art technology, a single vulnerable device can undermine the security of the entire network. The goal of this work is to limit the ability of an attacker to exploit a vulnerable device on an IoT network and fabricate deceitful messages to co-opt other devices. The approach is to limit attackers by using device proxies that are used to retransmit and control network communications. We present an architecture that prevents deceitful messages generated by compromised devices from affecting the rest of the network. The design assumes a centralized and trustworthy machine that can observe the behavior of all devices on the network. The central machine collects application layer data, as opposed to low-level network traffic, from each IoT device. The collected data is used to train models that capture the normal behavior of each individual IoT device. The normal behavioral data is then used to monitor the IoT devices and detect anomalous behavior. This paper reports on our experiments using both a binary classifier and a density-based clustering algorithm to model benign IoT device behavior with a realistic test-bed, designed to capture normal behavior in an IoT-monitored environment. Results from the IoT testbed show that both the classifier and the clustering algorithms are promising and encourage the use of application-level data for detecting compromised IoT devices. Hussain M. J. Almohri, Layne T. Watson, David Evans 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2019 | Cost-Sensitive Robustness against Adversarial Examples
Xiao Zhang 0016, David Evans 0001 |
ICLR (Poster) | 2 |
| 2019 | Empirically Measuring Concentration: Fundamental Limits on Intrinsic RobustnessabstractMany recent works have shown that adversarial examples that fool classifiers can be found by minimally perturbing a normal input. Recent theoretical results, starting with Gilmer et al. (2018b), show that if the inputs are drawn from a concentrated metric probability space, then adversarial examples with small perturbation are inevitable. A concentrated space has the property that any subset with Ω(1) (e.g.,1/100) measure, according to the imposed distribution, has small distance to almost all (e.g., 99/100) of the points in the space. It is not clear, however, whether these theoretical results apply to actual distributions such as images. This paper presents a method for empirically measuring and bounding the concentration of a concrete dataset which is proven to converge to the actual concentration. We use it to empirically estimate the intrinsic robustness to and L2 and Linfinity perturbations of several image classification benchmarks. Code for our experiments is available at https://github.com/xiaozhanguva/Measure-Concentration. Saeed Mahloujifar, Xiao Zhang 0016, Mohammad Mahmoody, David Evans 0001 |
NeurIPS | 4 |
| 2019 | Evaluating Differentially Private Machine Learning in Practice
Bargav Jayaraman, David Evans 0001 |
USENIX Security Symposium | 2 |
| 2018 | Fidelius Charm: Isolating Unsafe Rust CodeabstractThe Rust programming language has a safe memory model that promises to eliminate critical memory bugs. While the language is strong in doing so, its memory guarantees are lost when any unsafe blocks are used. Unsafe code is often needed to call library functions written in an unsafe language inside a Rust program. We present Fidelius Charm (FC), a system that protects a programmer-specified subset of data in memory from unauthorized access through vulnerable unsafe libraries. FC does this by limiting access to the program's memory while executing unsafe libraries. FC uses standard features of Rust and utilizes the Linux kernel as a trusted base for splitting the address space into a trusted privileged region under the control of functions written in Rust and a region available to unsafe external libraries. This paper presents our design and implementation of FC, presents two case studies for using FC in Rust TLS libraries, and reports on experiments showing its performance overhead is low for typical uses. Hussain M. J. Almohri, David Evans 0001 |
CODASPY | 2 |
| 2018 | Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks
Weilin Xu, David Evans 0001, Yanjun Qi |
NDSS | 2 |
| 2018 | Distributed Learning without Distress: Privacy-Preserving Empirical Risk MinimizationabstractDistributed learning allows a group of independent data owners to collaboratively learn a model over their data sets without exposing their private data. We present a distributed learning approach that combines differential privacy with secure multi-party computation. We explore two popular methods of differential privacy, output perturbation and gradient perturbation, and advance the state-of-the-art for both methods in the distributed learning setting. In our output perturbation method, the parties combine local models within a secure computation and then add the required differential privacy noise before revealing the model. In our gradient perturbation method, the data owners collaboratively train a global model via an iterative learning algorithm. At each iteration, the parties aggregate their local gradients within a secure computation, adding sufficient noise to ensure privacy before the gradient updates are revealed. For both methods, we show that the noise can be reduced in the multi-party setting by adding the noise inside the secure computation after aggregation, asymptotically improving upon the best previous results. Experiments on real world data sets demonstrate that our methods provide substantial utility gains for typical privacy requirements. Bargav Jayaraman, Lingxiao Wang 0001, David Evans 0001, Quanquan Gu |
NeurIPS | 3 |
| 2018 | Efficient Dynamic Searchable Encryption with Forward PrivacyabstractAbstract Searchable symmetric encryption (SSE) enables a client to perform searches over its outsourced encrypted files while preserving privacy of the files and queries. Dynamic schemes, where files can be added or removed, leak more information than static schemes. For dynamic schemes, forward privacy requires that a newly added file cannot be linked to previous searches. We present a new dynamic SSE scheme that achieves forward privacy by replacing the keys revealed to the server on each search. Our scheme is efficient and parallelizable and outperforms the best previous schemes providing forward privacy, and achieves competitive performance with dynamic schemes without forward privacy. We provide a full security proof in the random oracle model. In our experiments on the Wikipedia archive of about four million pages, the server takes one second to perform a search with 100,000 results. Mohammad Etemad, Alptekin Küpçü, Charalampos Papamanthou, David Evans 0001 |
Proc. Priv. Enhancing Technol. | 4 |
| 2018 | Misery Digraphs: Delaying Intrusion Attacks in Obscure CloudsabstractWhen remote command injection attacks succeed at the entry points of a cloud (servers exposed to the outside Internet), attackers targeting a specific asset in the cloud will pursue further exploration to find their targets. Attack targets, such as database servers, are often running on separate machines, forcing an extra step for a successful attack. However, compromising two or three machines is all an attacker needs to reach an isolated database through a simple attack path. The goal of this paper is to investigate the possibility of frustrating attackers by constructing a cloud network architecture that hides the path to a target asset in the network, utilizing multiple moving decoy virtual machines and confusing firewall configurations. A deceiving cloud network architecture can significantly delay attacks (by stretching the attack path from a handful of steps to thousands), providing time for system administrators to intervene and resolve the intrusion. This paper introduces the concept of misery digraphs, which provide a theoretical foundation for creating intrusion deception in clouds. This paper describes the necessary steps to convert a cloud to one that includes a misery digraph, and evaluates the feasibility and effectiveness of using the approach with Amazon Web Services. Our simulation results demonstrate that for a cloud implementing misery digraphs with a simple attack path of length five, there is a 91% probability that an attack requires at least 1000 steps to reach the target. Hussain M. J. Almohri, Layne T. Watson, David Evans 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2017 | Privacy-Preserving Distributed Linear Regression on High-Dimensional DataabstractAbstract We propose privacy-preserving protocols for computing linear regression models, in the setting where the training dataset is vertically distributed among several parties. Our main contribution is a hybrid multi-party computation protocol that combines Yao’s garbled circuits with tailored protocols for computing inner products. Like many machine learning tasks, building a linear regression model involves solving a system of linear equations. We conduct a comprehensive evaluation and comparison of different techniques for securely performing this task, including a new Conjugate Gradient Descent (CGD) algorithm. This algorithm is suitable for secure computation because it uses an efficient fixed-point representation of real numbers while maintaining accuracy and convergence rates comparable to what can be obtained with a classical solution using floating point numbers. Our technique improves on Nikolaenko et al.’s method for privacy-preserving ridge regression (S&P 2013), and can be used as a building block in other analyses. We implement a complete system and demonstrate that our approach is highly scalable, solving data analysis problems with one million records and one hundred features in less than one hour of total running time. Adrià Gascón, Phillipp Schoppmann, Borja Balle, Mariana Raykova 0001, Jack Doerner, Samee Zahur, David Evans 0001 |
Proc. Priv. Enhancing Technol. | 7 |
| 2016 | Secure Stable Matching at ScaleabstractWhen a group of individuals and organizations wish to compute a stable matching---for example, when medical students are matched to medical residency programs---they often outsource the computation to a trusted arbiter in order to preserve the privacy of participants' preferences. Secure multi-party computation offers the possibility of private matching processes that do not rely on any common trusted third party. However, stable matching algorithms have previously been considered infeasible for execution in a secure multi-party context on non-trivial inputs because they are computationally intensive and involve complex data-dependent memory access patterns. Jack Doerner, David Evans 0001, Abhi Shelat |
CCS | 2 |
| 2016 | Automatically Evading Classifiers: A Case Study on PDF Malware Classifiers
Weilin Xu, Yanjun Qi, David Evans 0001 |
NDSS | 3 |
| 2016 | Revisiting Square-Root ORAM: Efficient Random Access in Multi-party ComputationabstractHiding memory access patterns is required for secure computation, but remains prohibitively expensive for many interesting applications. Prior work has either developed custom algorithms that minimize the need for data-dependant memory access, or proposed the use of Oblivious RAM (ORAM) to provide a general-purpose solution. However, most ORAMs are designed for client-server scenarios, and provide only asymptotic benefits in secure computation. Even the best prior schemes show concrete benefits over naïve linear scan only for array sizes greater than 100. This immediately implies each ORAM access is 100 times slower than a single access at a known location. Even then, prior evaluations ignore the substantial initialization cost of existing schemes. We show how the classical square-root ORAM of Goldreich and Ostrovsky can be modified to overcome these problems, even though it is asymptotically worse than the best known schemes. Specifically, we show a design that has over 100x lower initialization cost, and provides benefits over linear scan for just 8 blocks of data. For all benchmark applications we tried, including Gale-Shapley stable matching and the scrypt key derivation function, our scheme outperforms alternate approaches across a wide range of parameters, often by several orders of magnitude. Samee Zahur, Xiao Wang 0012, Mariana Raykova 0001, Adrià Gascón, Jack Doerner, David Evans 0001, Jonathan Katz |
IEEE Symposium on Security and Privacy | 6 |
| 2015 | Two Halves Make a Whole - Reducing Data Transfer in Garbled Circuits Using Half Gates
Samee Zahur, Mike Rosulek, David Evans 0001 |
EUROCRYPT (2) | 3 |
| 2015 | Understanding and Monitoring Embedded Web ScriptsabstractModern web applications make frequent use of third-party scripts, often in ways that allow scripts loaded from external servers to make unrestricted changes to the embedding page and access critical resources including private user information. This paper introduces tools to assist site administrators in understanding, monitoring, and restricting the behavior of third-party scripts embedded in their site. We developed Script Inspector, a modified browser that can intercept, record, and check third-party script accesses to critical resources against security policies, along with a Visualizer tool that allows users to conveniently view recorded script behaviors and candidate policies and a Policy Generator tool that aids script providers and site administrators in writing policies. Site administrators can manually refine these policies with minimal effort to produce policies that effectively and robustly limit the behavior of embedded scripts. Policy Generator is able to generate effective policies for all scripts embedded on 72 out of the 100 test sites with minor human assistance. In this paper, we present the designs of our tools, report on what we've learned about script behaviors using them, evaluate the value of our approach for website administrator. David Evans 0001 |
IEEE Symposium on Security and Privacy | 2 |
| 2014 | SSOScan: Automated Testing of Web Applications for Single Sign-On Vulnerabilities
David Evans 0001 |
USENIX Security Symposium | 2 |
| 2013 | Efficient Secure Two-Party Computation Using Symmetric Cut-and-Choose
Yan Huang 0001, Jonathan Katz, David Evans 0001 |
CRYPTO (2) | 3 |
| 2013 | Circuit Structures for Improving Efficiency of Security and Privacy ToolsabstractSeveral techniques in computer security, including generic protocols for secure computation and symbolic execution, depend on implementing algorithms in static circuits. Despite substantial improvements in recent years, tools built using these techniques remain too slow for most practical uses. They require transforming arbitrary programs into either Boolean logic circuits, constraint sets on Boolean variables, or other equivalent representations, and the costs of using these tools scale directly with the size of the input circuit. Hence, techniques for more efficient circuit constructions have benefits across these tools. We show efficient circuit constructions for various simple but commonly used data structures including stacks, queues, and associative maps. While current practice requires effectively copying the entire structure for each operation, our techniques take advantage of locality and batching to provide amortized costs that scale polylogarithmically in the size of the structure. We demonstrate how many common array usage patterns can be significantly improved with the help of these circuit structures. We report on experiments using our circuit structures for both generic secure computation using garbled circuits and automated test input generation using symbolic execution, and demonstrate order of magnitude improvements for both applications. Samee Zahur, David Evans 0001 |
IEEE Symposium on Security and Privacy | 2 |
| 2013 | Explicating SDKs: Uncovering Assumptions Underlying Secure Authentication and Authorization
Rui Wang 0010, Shuo Chen 0001, Shaz Qadeer, David Evans 0001, Yuri Gurevich |
USENIX Security Symposium | 5 |
| 2012 | Private Set Intersection: Are Garbled Circuits Better than Custom Protocols?
Yan Huang 0001, David Evans 0001, Jonathan Katz |
NDSS | 2 |
| 2012 | Quid-Pro-Quo-tocols: Strengthening Semi-honest Protocols with Dual ExecutionabstractKnown protocols for secure two-party computation that are designed to provide full security against malicious behavior are significantly less efficient than protocols intended only to thwart semi-honest adversaries. We present a concrete design and implementation of protocols achieving security guarantees that are much stronger than are possible with semi-honest protocols, at minimal extra cost. Specifically, we consider protocols in which a malicious adversary may learn a single (arbitrary) bit of additional information about the honest party's input. Correctness of the honest party's output is still guaranteed. Adapting prior work of Mohassel and Franklin, the basic idea in our protocols is to conduct two separate runs of a (specific) semi-honest, garbled-circuit protocol, with the parties swapping roles, followed by an inexpensive secure equality test. We provide a rigorous definition and prove that this protocol leaks no more than one additional bit against a malicious adversary. In addition, we propose some heuristic enhancements to reduce the overall information a cheating adversary learns. Our experiments show that protocols meeting this security level can be implemented at cost very close to that of protocols that only achieve semi-honest security. Our results indicate that this model enables the large-scale, practical applications possible within the semi-honest security model, while providing dramatically stronger security guarantees. Yan Huang 0001, Jonathan Katz, David Evans 0001 |
IEEE Symposium on Security and Privacy | 3 |
| 2011 | Automated black-box detection of side-channel vulnerabilities in web applicationsabstractWeb applications divide their state between the client and the server. The frequent and highly dynamic client-server communication that is characteristic of modern web applications leaves them vulnerable to side-channel leaks, even over encrypted connections. We describe a black-box tool for detecting and quantifying the severity of side-channel vulnerabilities by analyzing network traffic over repeated crawls of a web application. By viewing the adversary as a multi-dimensional classifier, we develop a methodology to more thoroughly measure the distinguishably of network traffic for a variety of classification metrics. We evaluate our detection system on several deployed web applications, accounting for proposed client and server-side defenses. Our results illustrate the limitations of entropy measurements used in previous work and show how our new metric based on the Fisher criterion can be used to more robustly reveal side-channels in web applications. Peter Chapman, David Evans 0001 |
CCS | 2 |
| 2011 | Protecting Private Web Content from Embedded Scripts
David Evans 0001 |
ESORICS | 2 |
| 2011 | Efficient Privacy-Preserving Biometric Identification
Yan Huang 0001, Lior Malka, David Evans 0001, Jonathan Katz |
NDSS | 3 |
| 2011 | Privacy-Preserving Applications on Smartphones
Yan Huang 0001, Peter Chapman, David Evans 0001 |
HotSec | 3 |
| 2011 | Faster Secure Two-Party Computation Using Garbled Circuits
Yan Huang 0001, David Evans 0001, Jonathan Katz, Lior Malka |
USENIX Security Symposium | 2 |
| 2009 | Privacy through Noise: A Design Space for Private IdentificationabstractTo protect privacy in large systems, users should be able to authenticate against a central server without disclosing their identity to others. Private identification protocols based on public key cryptography are computationally expensive and cannot be implemented on small devices like RFID tags. Symmetric key protocols, on the other hand, provide only modest levels of privacy, but can be efficiently executed on servers and cheaply implemented on devices. The privacy of symmetric-key privacy protocols derives from the fact that an attacker only ever knows a small fraction of the keys in a system while the legitimate reader knows all keys. We propose to amplify this gap in the ability to distinguish users by adding noise to user responses. We focus on scenarios where an attacker is not able to acquire multiple different reads known to be from the same device, and justify this threat model by proposing a simple modification to RFID tag designs. In such scenarios, we can use noise to blur the borders between groups of users that the attacker would otherwise be able to distinguish. We evaluate the effectiveness and cost of this randomization and find that the information leakage from the tree protocol can be decreased to two thousandths of its original value with 150 times the number of server-side cryptographic operations and minimal cost to the tag. Degrees of privacy up to those achieved by public key protocols can be reached while staying well below the cost of public key cryptography. Karsten Nohl, David Evans 0001 |
ACSAC | 2 |
| 2008 | Security through redundant data diversityabstractUnlike other diversity-based approaches, N-variant systems thwart attacks without requiring secrets. Instead, they use redundancy (to require an attacker to simultaneously compromise multiple variants with the same input) and tailored diversity (to make it impossible to compromise all the variants with the same input for given attack classes). In this work, we develop a method for using data diversity in N-variant systems to provide high-assurance arguments against a class of data corruption attacks. Data is transformed in the variants so identical concrete data values have different interpretations. In order to corrupt the data without detection, an attacker would need to alter the corresponding data in each variant in a different way while sending the same inputs to all variants. We demonstrate our approach with a case study using that thwarts attacks that corrupt UID values. Anh Nguyen-Tuong, David Evans 0001, John C. Knight, Benjamin Cox, Jack W. Davidson |
DSN | 2 |
| 2008 | The user is not the enemy: fighting malware by tracking user intentionsabstractCurrent access control policies provide no mechanisms for incorporating user behavior in access control decisions, even though the way a user interacts with a program often indicates what the user expects that program to do. We develop a new approach to access control, focusing on single-user systems, in which the complete history of user and program actions can be used to improve the precision and expressiveness of access control policies. We describe mechanisms for securely capturing user actions, mapping those actions onto likely user intents, and a language for defining access control policies that incorporate user intentions. We implemented a prototype for capturing user intentions, and present results from experiments on malware mitigation using the prototype. Our results show that a very simple MAC policy can prevent a significant amount of system damage caused by malware while not interfering with most benign software. Jeff Shirley, David Evans 0001 |
NSPW | 2 |
| 2008 | Hiding in Groups: On the Expressiveness of Privacy Distributions
Karsten Nohl, David Evans 0001 |
SEC | 2 |
| 2008 | Reverse-Engineering a Cryptographic RFID Tag
Karsten Nohl, David Evans 0001, Starbug, Henryk Plötz |
USENIX Security Symposium | 2 |
| 2006 | Quantifying Information Leakage in Tree-Based Hash Protocols (Short Paper)
Karsten Nohl, David Evans 0001 |
ICICS | 2 |
| 2006 | Inculcating invariants in introductory coursesabstractOne goal of introductory software engineering courses is to motivate and instill good software engineering habits. Unfortunately, practical constraints on typical courses often lead to student experiences that are antithetical to that goal: instead of working in large teams and dealing with changing requirements and maintaining programs over many years, courses generally involve students working alone or in small teams with short projects that end the first time the program works correctly on some selected input. Small projects tend to reinforce poor software engineering practices. Since the programs are small enough to manage cognitively in ad hoc ways, effort spent more precisely documenting assumptions seems wasteful. It is infeasible to carry out full industrial software development within the context of a typical university course. However, it is possible to simulate some aspects of safety critical software engineering in an introductory software engineering course. This paper describes an approach that focuses on thinking about and precisely documenting invariants, and checking invariants using lightweight analysis tools. We describe how assignments were designed to emphasize the importance of invariants and to incorporate program analysis tools with typical software engineering material and report on results from an experiment measuring students understanding of program invariants. David Evans 0001, Michael Peck |
ICSE | 1 |
| 2006 | Perracotta: mining temporal API rules from imperfect tracesabstractDynamic inference techniques have been demonstrated to provide useful support for various software engineering tasks including bug finding, test suite evaluation and improvement, and specification generation. To date, however, dynamic inference has only been used effectively on small programs under controlled conditions. In this paper, we identify reasons why scaling dynamic inference techniques has proven difficult, and introduce solutions that enable a dynamic inference technique to scale to large programs and work effectively with the imperfect traces typically available in industrial scenarios. We describe our approximate inference algorithm, present and evaluate heuristics for winnowing the large number of inferred properties to a manageable set of interesting properties, and report on experiments using inferred properties. We evaluate our techniques on JBoss and the Windows kernel. Our tool is able to infer many of the properties checked by the Static Driver Verifier and leads us to discover a previously unknown bug in Windows. Jinlin Yang, David Evans 0001, Deepali Bhardwaj, Thirumalesh Bhat, Manuvir Das |
ICSE | 2 |
| 2006 | N-Variant Systems: A Secretless Framework for Security through Diversity
Benjamin Cox, David Evans 0001 |
USENIX Security Symposium | 2 |
| 2006 | Secure and practical defense against code-injection attacks using software dynamic translationabstractOne of the most common forms of security attacks involves exploiting a vulnerability to inject malicious code into an executing application and then cause the injected code to be executed. A theoretically strong approach to defending against any type of code-injection attack is to create and use a process-specific instruction set that is created by a randomization algorithm. Code injected by an attacker who does not know the randomization key will be invalid for the randomized processor effectively thwarting the attack. This paper describes a secure and efficient implementation of instruction-set randomization (ISR) using software dynamic translation. The paper makes three contributions beyond previous work on ISR. First, we describe an implementation that uses a strong cipher algorithm--the Advanced Encryption Standard (AES), to perform randomization. AES is generally believed to be impervious to known attack methodologies. Second, we demonstrate that ISR using AES can be implemented practically and efficiently (considering both execution time and code size overheads) without requiring special hardware support. The third contribution is that our approach detects malicious code before it is executed. Previous approaches relied on probabilistic arguments that execution of non-randomized foreign code would eventually cause a fault or runtime exception. Jason Hiser, Daniel W. Williams, Adrian Filipi, Jack W. Davidson, David Evans 0001, John C. Knight, Anh Nguyen-Tuong, Jonathan C. Rowanhill |
VEE | 6 |
| 2006 | Comparing Java and .NET security: Lessons learned and missed
Nathanael Paul, David Evans 0001 |
Comput. Secur. | 2 |
| 2005 | Automatically Hardening Web Applications Using Precise Tainting
Anh Nguyen-Tuong, Salvatore Guarnieri, Doug Greene, Jeff Shirley, David Evans 0001 |
SEC | 5 |
| 2005 | Where's the FEEB? The Effectiveness of Instruction Set Randomization
Ana Nora Sovarel, David Evans 0001, Nathanael Paul |
USENIX Security Symposium | 2 |
| 2004 | .NET Security: Lessons Learned and Missed from JavaabstractMany systems execute untrusted programs in virtual machines (VMs) to limit their access to system resources. Sun introduced the Java VM in 1995, primarily intended as a lightweight platform for execution of untrusted code inside Web pages. More recently, Microsoft developed the .NET platform with similar goals. Both platforms share many design and implementation properties, but there are key differences between Java and .NET that have an impact on their security. This paper examines how .NET's design avoids vulnerabilities and limitations discovered in Java and discusses lessons learned (and missed) from Java's experience with security. Nathanael Paul, David Evans 0001 |
ACSAC | 2 |
| 2004 | EnviroTrack: Towards an Environmental Computing Paradigm for Distributed Sensor NetworksabstractDistributed sensor networks are quickly gaining recognition as viable embedded computing platforms. Current techniques for programming sensor networks are cumbersome, inflexible, and low-level. We introduce EnviroTrack, an object-based distributed middleware system that raises the level of programming abstraction by providing a convenient and powerful interface to the application developer geared towards tracking the physical environment. EnviroTrack is novel in its seamless integration of objects that live in physical time and space into the computational environment of the application. Performance results demonstrate the ability of the middleware to track realistic targets. Tarek F. Abdelzaher, Brian M. Blum, Qing Cao 0001, David Evans 0001, Jemin George, Selvin George, Lin Gu 0001, Tian He 0001, Sudha Krishnamurthy, Liqian Luo, Sang Hyuk Son, John A. Stankovic, Radu Stoleru, Anthony D. Wood |
ICDCS | 5 |
| 2004 | Second International Workshop on Dynamic Analysis (WODA 2004)
David Evans 0001, Raimondas Lencevicius |
ICSE | 1 |
| 2004 | Automatically Inferring Temporal Properties for Program Evolution abstractIt is important that program maintainers understand important properties of the programs they modify and ensure that the changes they make do not alter essential properties in unintended ways. Manually documenting those properties, especially temporal ones that constrain the ordering of events, is difficult and rarely done in practice. We propose an automatic approach to inferring a target system's temporal properties based on analyzing its event traces. The core of our technique is a set of pre-defined property patterns among a few events. These patterns form a partial order in terms of their strictness. Our approach finds the strictest properties satisfied by a set of events based on the traces. We report results from experiments on two sets of programs: student solutions for a class assignment, and several recent versions of OpenSSL Comparing properties inferred from different implementations led us to discover important behavioral differences which revealed flaws in the programs. Differences in automatically inferred temporal properties can provide useful information to programmers evolving complex, often unspecified, programs whose correctness depends on preservation of undocumented temporal properties. Jinlin Yang, David Evans 0001 |
ISSRE | 2 |
| 2004 | Localization for mobile sensor networksabstractMany sensor network applications require location awareness, but it is often too expensive to include a GPS receiver in a sensor network node. Hence, localization schemes for sensor networks typically use a small number of seed nodes that know their location and protocols whereby other nodes estimate their location from the messages they receive. Several such localization techniques have been proposed, but none of them consider mobile nodes and seeds. Although mobility would appear to make localization more difficult, in this paper we introduce the sequential Monte Carlo Localization method and argue that it can exploit mobility to improve the accuracy and precision of localization. Our approach does not require additional hardware on the nodes and works even when the movement of seeds and nodes is uncontrollable. We analyze the properties of our technique and report experimental results from simulations. Our scheme outperforms the best known static localization schemes under a wide range of conditions. Lingxuan Hu, David Evans 0001 |
MobiCom | 2 |
| 2004 | Using Directional Antennas to Prevent Wormhole Attacks
Lingxuan Hu, David Evans 0001 |
NDSS | 2 |
| 2004 | Dynamically inferring temporal propertiesabstractModel checking requires a specification of the target system's desirable properties, some of which are temporal. Formulating a temporal property of the system based on either its abstract model or implementation requires a deep understanding of its behavior and sophisticated knowledge of the chosen formalism. This has been a major impediment to documenting and verifying temporal properties. We propose a dynamic approach to automatically infer a program's temporal properties based on a set of property pattern templates. We describe a preliminary implementation of this approach, and report on our experience using it to discover interesting temporal properties of a small program. Jinlin Yang, David Evans 0001 |
PASTE | 2 |
| 2004 | What Biology Can (and Can't) Teach Us About Security
David Evans 0001 |
USENIX Security Symposium | 1 |
| 2001 | Behavior Combination and Swarm Programming
Keen Browne, Jon McCune, Adam Trost, David Evans 0001, David C. Brogan |
RoboCup | 4 |
| 2001 | Statically Detecting Likely Buffer Overflow Vulnerabilities
David Larochelle, David Evans 0001 |
USENIX Security Symposium | 2 |
| 1999 | Flexible Policy-Directed Code SafetyabstractThe article introduces a new approach to code safety. We present Naccio, a system architecture that allows a large class of safety policies to be expressed in a general and platform-independent way. Policies are defined in terms of abstract resource manipulations. We describe mechanisms that can be used to efficiently and conveniently enforce these safety policies by transforming programs. We are developing implementations of Naccio that enforce policies on JavaVM classes and Win32 executables. We report on results using the JavaVM prototype. David Evans 0001, Andrew Twyman |
S&P | 1 |
| 1996 | Static Detection of Dynamic Memory ErrorsabstractMany important classes of bugs result from invalid assumptions about the results of functions and the values of parameters and global variables. Using traditional methods, these bugs cannot be detected efficiently at compile-time, since detailed cross-procedural analyses would be required to determine the relevant assumptions. In this work, we introduce annotations to make certain assumptions explicit at interface points. An efficient static checking tool that exploits these annotations can detect a broad class of errors including misuses of null pointers, uses of dead storage, memory leaks, and dangerous aliasing. This technique has been used successfully to fix memory management problems in a large program. David Evans 0001 |
PLDI | 1 |
| 1994 | LCLint: A Tool for Using Specifications to Check CodeabstractThis paper describes LCLint, an efficient and flexible tool that accepts as input programs (written in ANSI C) and various levels of formal specification. Using this information, LCLint reports inconsistencies between a program and its specification. We also describe our experience using LCLint to help understand, document, and re-engineer legacy code. David Evans 0001, John V. Guttag, James J. Horning, Yang Meng Tan |
SIGSOFT FSE | 1 |