Select Publications
Book Chapters
, 2027, 'Holmes: Forensic-Aware Design and Evaluation of Large Language Models for Procedurally Constrained Digital Investigations', in , pp. 3 - 18, http://dx.doi.org/10.1007/978-981-92-2859-1_1
, 2026, 'Prompt to Pwn: Automated Exploit Generation for Smart Contracts', in , pp. 445 - 473, http://dx.doi.org/10.1007/978-981-92-3012-9_19
Journal articles
, 2026, 'Determining the Unreachable: Constraint-Guided Reachability Analysis for Dependency Vulnerabilities', Proceedings of the ACM on Programming Languages, 10, pp. 1514 - 1541, http://dx.doi.org/10.1145/3798255
, 2026, 'Spectre: Automated Aliasing Specification Generation for Library APIs with Fuzzing', ACM Transactions on Software Engineering and Methodology, 35, http://dx.doi.org/10.1145/3725811
, 2026, 'OptRCA: A More Efficient and Accurate Approach for Automated Root Cause Analysis and Explanation', ACM Transactions on Software Engineering and Methodology, 35, http://dx.doi.org/10.1145/3736718
, 2026, 'Detecting LLM Fact-conflicting Hallucinations Enhanced by Temporal-logic-based Reasoning', IEEE Transactions on Software Engineering, http://dx.doi.org/10.1109/TSE.2026.3731191
, 2025, 'MiniScope: Automated UI Exploration and Privacy Inconsistency Detection of MiniApps via Two-phase Iterative Hybrid Analysis', ACM Transactions on Software Engineering and Methodology, 34, http://dx.doi.org/10.1145/3709351
, 2025, 'TransferFuzz-Pro: Large Language Model Driven Code Debugging Technology for Verifying Propagated Vulnerability', IEEE Transactions on Software Engineering, 51, pp. 2396 - 2411, http://dx.doi.org/10.1109/TSE.2025.3584774
, 2025, 'Mission: Impossible – Image-Based Geolocation with Large Vision Language Models', Proceedings on Privacy Enhancing Technologies, 2025, pp. 410 - 428, http://dx.doi.org/10.56553/popets-2025-0137
, 2024, 'A Survey of Protocol Fuzzing', ACM Computing Surveys, 57, http://dx.doi.org/10.1145/3696788
, 2024, 'Drowzee: Metamorphic Testing for Fact-Conflicting Hallucination Detection in Large Language Models', Proceedings of the ACM on Programming Languages, 8, http://dx.doi.org/10.1145/3689776
, 2024, 'Glitch Tokens in Large Language Models: Categorization Taxonomy and Effective Detection', Proceedings of the ACM on Software Engineering, 1, pp. 2075 - 2097, http://dx.doi.org/10.1145/3660799
, 2022, 'Avoiding Structural Collapse to Reduce Lead Leakage in Perovskite Photovoltaics', Angewandte Chemie International Edition, 61, pp. e202204314, http://dx.doi.org/10.1002/anie.202204314
, 2022, 'Deep Learning for Coverage-Guided Fuzzing: How Far are We?', IEEE Transactions on Dependable and Secure Computing, pp. 1 - 13, http://dx.doi.org/10.1109/TDSC.2022.3200525
, 2022, 'An integrated hydrodynamic and multicriteria evaluation Cellular Automata–Markov model to assess the effects of a water resource project on waterbird habitat in wetlands', Journal of Hydrology, 607, pp. 127561, http://dx.doi.org/10.1016/j.jhydrol.2022.127561
, 2020, 'New assessment indicator of habitat suitability for migratory bird in wetland based on hydrodynamic model and vegetation growth threshold', Ecological Indicators, 117, pp. 106556, http://dx.doi.org/10.1016/j.ecolind.2020.106556
, 2019, 'Development and Validation of a Prognostic Tool for Identifying Residents at Increased Risk of Death in Long-Term Care Facilities', Journal of Palliative Medicine, 22, pp. 258 - 266, http://dx.doi.org/10.1089/jpm.2018.0219
Conference Papers
, 2027, 'Uncovering Logit Suppression Vulnerabilities in LLM Safety Alignment', in Lecture Notes in Computer Science, pp. 61 - 76, http://dx.doi.org/10.1007/978-3-032-31583-0_5
, 2026, 'NgCaptcha: A CAPTCHA Bridging the Past and the Future', in Www Companion 2026 Companion Proceedings of the ACM Web Conference 2026, pp. 104 - 107, http://dx.doi.org/10.1145/3774905.3793112
, 2026, 'LifeFuzz: Lifecycle-Guided Fuzzing for Windows Driver Cross-Handler Vulnerabilities', in Eurosys 2026 Proceedings of the 2026 European Conference on Computer Systems, pp. 2022 - 2036, http://dx.doi.org/10.1145/3767295.3803624
, 2026, 'SpecGuru: Hierarchical LLM-Driven API Points-to Specification Generation with Self-Validation', Association for Computing Machinery (ACM), pp. 1200 - 1212, presented at Proceedings of the 2026 IEEE/ACM 48th International Conference on Software Engineering, http://dx.doi.org/10.1145/3744916.3773209
, 2026, 'Diverse Claire: An AI-Powered UDL Approach Bridging Educational Experience Gaps in CS1', Association for Computing Machinery (ACM), pp. 1714 - 1714, presented at Proceedings of the 57th ACM Technical Symposium on Computer Science Education V.2, http://dx.doi.org/10.1145/3770761.3777125
, 2026, 'CSTutorBench: Benchmarking Large Language Models for Realistic Computer Science Tutoring', in SIGCSE TS 2026 Proceedings of the 57th ACM Technical Symposium on Computer Science Education V 2, pp. 1263 - 1264, http://dx.doi.org/10.1145/3770761.3777333
, 2026, 'DiverseClaire: Simulating Students to Improve Introductory Programming Course Materials for All CS1 Learners', in SIGCSE TS 2026 Proceedings of the 57th ACM Technical Symposium on Computer Science Education V 2, pp. 1585 - 1586, http://dx.doi.org/10.1145/3770761.3777340
, 2026, 'Exploring Trust in Human-LLM Feedback Systems: Observation of Student Behaviour in Software Engineering Education', in SIGCSE TS 2026 Proceedings of the 57th ACM Technical Symposium on Computer Science Education V 2, pp. 1419 - 1420, http://dx.doi.org/10.1145/3770761.3777342
, 2026, 'A Multi-Agent System for Inclusive Automatic Speech Recognition for People Who Stutter', in Proceedings of the Aaai Conference on Artificial Intelligence, pp. 39495 - 39503, http://dx.doi.org/10.1609/aaai.v40i46.41300
, 2026, 'An Ontology-Driven Service-Oriented System for ESG Metric Computation and Reporting', in Proceedings of the IEEE International Conference on Web Services Icws, pp. 347 - 353, http://dx.doi.org/10.1109/ICWS72778.2026.00052
, 2026, 'PufferDoS: Efficient and Effective Attack String Generation for Regular Expression Denial of Service Vulnerabilities', in Proceedings IEEE Symposium on Security and Privacy, pp. 3984 - 4002, http://dx.doi.org/10.1109/SP63933.2026.00169
, 2026, 'SceneJailEval: A Scenario-Adaptive Multi-Dimensional Framework for Jailbreak Evaluation', in Proceedings of the Aaai Conference on Artificial Intelligence, pp. 35553 - 35561, http://dx.doi.org/10.1609/aaai.v40i42.40866
, 2026, 'Socrates or Smartypants: Testing Logic Reasoning Capabilities of Large Language Models with Logic Programming-Based Test Oracles', in Proceedings of the Aaai Conference on Artificial Intelligence, pp. 19433 - 19440, http://dx.doi.org/10.1609/aaai.v40i23.39021
, 2025, 'IllusionCAPTCHA: A CAPTCHA based on Visual Illusion', in Www 2025 Proceedings of the ACM Web Conference, pp. 3683 - 3691, http://dx.doi.org/10.1145/3696410.3714726
, 2025, 'A Large Scale Study of AI-based Binary Function Similarity Detection Techniques for Security Researchers and Practitioners', in Proceedings 2025 40th IEEE ACM International Conference on Automated Software Engineering Ase 2025, pp. 1070 - 1082, http://dx.doi.org/10.1109/ASE63991.2025.00093
, 2025, 'A Methodology for Replicating Historical Exploits on EVM-Compatible Blockchains', in Proceedings 2025 IEEE ACM 7th International Workshop on Emerging Trends in Software Engineering for Blockchain Wetseb 2025, pp. 57 - 60, http://dx.doi.org/10.1109/WETSEB66605.2025.00014
, 2025, 'A Rusty Link in the AI Supply Chain: Detecting Evil Configurations in Model Repositories', in Proceedings 46th IEEE Symposium on Security and Privacy Workshops Spw 2025, pp. 260 - 264, http://dx.doi.org/10.1109/SPW67851.2025.00036
, 2025, 'Continuous Embedding Attacks via Clipped Inputs in Jailbreaking Large Language Models', in Proceedings 46th IEEE Symposium on Security and Privacy Workshops Spw 2025, pp. 270 - 277, http://dx.doi.org/10.1109/SPW67851.2025.00038
, 2025, 'From Constraints to Cracks: Constraint Semantic Inconsistencies as Vulnerability Beacons for Embedded Systems', in Proceedings of the 34th Usenix Security Symposium, pp. 685 - 704
, 2025, 'Good News for Script Kiddies? Evaluating Large Language Models for Automated Exploit Generation', in Proceedings 46th IEEE Symposium on Security and Privacy Workshops Spw 2025, pp. 278 - 282, http://dx.doi.org/10.1109/SPW67851.2025.00039
, 2025, 'It Only Gets Worse: Revisiting DL-Based Vulnerability Detectors from a Practical Perspective', in Proceedings Asia Pacific Software Engineering Conference APSEC, pp. 947 - 956, http://dx.doi.org/10.1109/APSEC66846.2025.00109
, 2025, 'KRAKEN-FUZZ: Minimizing Corpus During Ensemble Fuzzing', in Proceedings 2025 IEEE ACM International Workshop on Search Based and Fuzz Testing Sbft 2025, pp. 47 - 48, http://dx.doi.org/10.1109/SBFT66712.2025.00017
, 2025, 'MMLU-ProX: A Multilingual Benchmark for Advanced Large Language Model Evaluation', in Emnlp 2025 2025 Conference on Empirical Methods in Natural Language Processing Proceedings of the Conference, pp. 1513 - 1532, http://dx.doi.org/10.18653/v1/2025.emnlp-main.79
, 2025, 'Source Code Summarization in the Era of Large Language Models', in Proceedings International Conference on Software Engineering, pp. 1882 - 1894, http://dx.doi.org/10.1109/ICSE55347.2025.00034
, 2025, 'TOMBRAIDER: Entering the Vault of History to Jailbreak Large Language Models', in Emnlp 2025 2025 Conference on Empirical Methods in Natural Language Processing Proceedings of the Conference, pp. 5478 - 5493, http://dx.doi.org/10.18653/v1/2025.emnlp-main.279
, 2025, 'TransferFuzz: Fuzzing with Historical Trace for Verifying Propagated Vulnerability Code', in Proceedings International Conference on Software Engineering, pp. 268 - 280, http://dx.doi.org/10.1109/ICSE55347.2025.00061
, 2025, 'Truman: A Large Language Model-based Multi-agent Simulator for Synthetic Money Laundering Data Generation', in Proceedings of the International Joint Conference on Autonomous Agents and Multiagent Systems Aamas, pp. 2594 - 2596
, 2024, 'Demystifying RCE Vulnerabilities in LLM-Integrated Apps', in Ccs 2024 Proceedings of the 2024 ACM Sigsac Conference on Computer and Communications Security, pp. 1716 - 1730, http://dx.doi.org/10.1145/3658644.3690338
, 2024, 'Rust-twins: Automatic Rust Compiler Testing through Program Mutation and Dual Macros Generation', in Proceedings 2024 39th ACM IEEE International Conference on Automated Software Engineering Ase 2024, pp. 631 - 642, http://dx.doi.org/10.1145/3691620.3695059
, 2024, 'Bugs in Pods: Understanding Bugs in Container Runtime Systems', in Issta 2024 Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis, pp. 1364 - 1376, http://dx.doi.org/10.1145/3650212.3680366
, 2024, 'How Effective Are They? Exploring Large Language Model Based Fuzz Driver Generation', in Issta 2024 Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis, pp. 1223 - 1235, http://dx.doi.org/10.1145/3650212.3680355
, 2024, 'A Comprehensive Study of Jailbreak Attack versus Defense for Large Language Models', in Martins A; Srikumar V; Ku LW (eds.), FINDINGS OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS: ACL 2024, ASSOC COMPUTATIONAL LINGUISTICS-ACL, THAILAND, Bangkok, pp. 7432 - 7449, presented at 62nd Annual Meeting of the Association-for-Computational-Linguistics (ACL) / Student Research Workshop (SRW), THAILAND, Bangkok, 11 August 2024 - 16 August 2024
, 2024, 'A Hitchhiker’s Guide to Jailbreaking ChatGPT via Prompt Engineering', in Sea4dq 2024 Proceedings of the 4th International Workshop on Software Engineering and AI for Data Quality in Cyber Physical Systems Internet of Things Co Located with Esec Fse 2024, pp. 12 - 21, http://dx.doi.org/10.1145/3663530.3665021