Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Databases and Information Systems (3560)
- Software Engineering (2205)
- Artificial Intelligence and Robotics (1897)
- Information Security (1108)
- Numerical Analysis and Scientific Computing (1060)
-
- Graphics and Human Computer Interfaces (947)
- Engineering (884)
- Social and Behavioral Sciences (808)
- Business (748)
- Theory and Algorithms (513)
- Computer Engineering (449)
- Programming Languages and Compilers (413)
- Operations Research, Systems Engineering and Industrial Engineering (407)
- OS and Networks (345)
- Communication (326)
- Social Media (264)
- Public Affairs, Public Policy and Public Administration (230)
- Medicine and Health Sciences (197)
- Education (194)
- Transportation (194)
- Management Information Systems (176)
- Data Storage Systems (167)
- E-Commerce (154)
- International and Area Studies (147)
- Technology and Innovation (146)
- Asian Studies (145)
- Health Information Technology (118)
- Higher Education (105)
- Keyword
-
- Machine learning (145)
- Deep learning (129)
- Artificial intelligence (124)
- Social media (82)
- Singapore (73)
-
- Reinforcement learning (72)
- Data mining (70)
- Privacy (67)
- Security (62)
- Cloud computing (60)
- Deep Learning (58)
- Empirical study (55)
- Software engineering (55)
- Optimization (54)
- Online learning (51)
- Visualization (51)
- Neural networks (50)
- Anomaly detection (49)
- Training (49)
- Twitter (49)
- Task analysis (48)
- Blockchain (47)
- Large Language Models (47)
- Natural language processing (47)
- Collaboration (46)
- Feature extraction (45)
- Algorithms (44)
- Access control (43)
- Machine Learning (43)
- Semantics (43)
- Publication Year
- Publication
-
- Research Collection School Of Computing and Information Systems (8479)
- Dissertations and Theses Collection (Open Access) (189)
- Research Collection Lee Kong Chian School Of Business (59)
- Research Collection Yong Pung How School Of Law (49)
- Research Collection School of Social Sciences (27)
-
- Asian Management Insights (26)
- Research Collection College of Integrative Studies (23)
- Perspectives@SMU (21)
- Research Collection School Of Accountancy (18)
- Dissertations and Theses Collection (15)
- FORCE 2026 (14)
- SMU Press Releases and News (12)
- MITB Thought Leadership Series (11)
- Research Collection School of Computing and Information Systems (11)
- Research Collection Library (10)
- Research@SMU: Connecting the Dots (10)
- PhD Student’s Publications Collection (8)
- LARC Research Publications (7)
- Research Collection School Of Economics (6)
- CCX Research (4)
- SMU Research Data (4)
- Student Publications (4)
- 2024 AI for Research Week (3)
- SCIS Student Publications (3)
- Centre for AI & Data Governance (2019-2025) (2)
- Research Collection Office of Research (2)
- CASTLe: Collection of Articles on Scholarship for Teaching and Learning (1)
- Centre for Computational Law (2022-2025) (1)
- Library Events (1)
- ROSA Journal Articles and Publications (1)
- Publication Type
- File Type
Articles 4021 - 4050 of 9025
Full-Text Articles in Computer Sciences
Bidding Mechanisms In Graph Games, Guy Avni, Thomas A. Henzinger, Dorde Zikelic
Bidding Mechanisms In Graph Games, Guy Avni, Thomas A. Henzinger, Dorde Zikelic
Research Collection School Of Computing and Information Systems
In two-player games on graphs, the players move a token through a graph to produce a finite or infinite path, which determines the qualitative winner or quantitative payoff of the game. We study bidding games in which the players bid for the right to move the token. Several bidding rules were studied previously. In Richman bidding, in each round, the players simultaneously submit bids, and the higher bidder moves the token and pays the other player. Poorman bidding is similar except that the winner of the bidding pays the “bank” rather than the other player. Taxman bidding spans the spectrum …
Who Should Pay The Cost: A Game-Theoretic Model For Government Subsidized Investments To Improve National Cybersecurity, Xinrun Wang, Bo An, Hau Chan
Who Should Pay The Cost: A Game-Theoretic Model For Government Subsidized Investments To Improve National Cybersecurity, Xinrun Wang, Bo An, Hau Chan
Research Collection School Of Computing and Information Systems
Due to the recent cyber attacks, cybersecurity is becoming more critical in modern society. A single attack (e.g., WannaCry ransomware attack) can cause as much as $4 billion in damage. However, the cybersecurity investment by companies is far from satisfactory. Therefore, governments (e.g., in the UK) launch grants and subsidies to help companies to boost their cybersecurity to create a safer national cyber environment. The allocation problem is hard due to limited subsidies and the interdependence between self-interested companies and the presence of a strategic cyber attacker. To tackle the government's allocation problem, we introduce a Stackelberg game-theoretic model where …
Constructing Strong Designated Verifier Signatures From Key Encapsulation Mechanisms, Borui Gong, Ho Man Au, Haiyang Xue
Constructing Strong Designated Verifier Signatures From Key Encapsulation Mechanisms, Borui Gong, Ho Man Au, Haiyang Xue
Research Collection School Of Computing and Information Systems
A designated verifier signature (DVS) allows a signer to convince a verifier that a message has been endorsed in a way that the conviction cannot be transferred to any third party. This is achieved by the property that the signature can be generated by one of them. Since DVS is publicly verifiable, a valid DVS implies that the signature must be created by either the signer or the verifier. To enhance privacy of signers' identity, a strong DVS (SDVS) disallows public verification. In this paper, we investigate various aspects of SDVS with making two contributions. Firstly, we consider SDVS in …
Fintech Empowerment: Data Science, Ai, And Machine Learning, Keng Siau, Michael Hilgers, Langtao Chen, Steve Liu, Fiona Fui-Hoon Nah, Richard Hall, Barry Flachsbart
Fintech Empowerment: Data Science, Ai, And Machine Learning, Keng Siau, Michael Hilgers, Langtao Chen, Steve Liu, Fiona Fui-Hoon Nah, Richard Hall, Barry Flachsbart
Research Collection School Of Computing and Information Systems
The article discusses how data science, artificial intelligence and machine learning are affecting the evolution of “fintech,” the technologies used to deliver financial services. After presenting fintech’s competitive advantages in combination with these other advanced technologies, the article posits that financial institutions that don’t move forward with the innovations will be eliminated from the marketplace.
Shared Dynamic Data Audit Supporting Anonymous User Revocation In Cloud Storage, Yinghui Zhang, Chen Chen, Dong Zheng, Rui Guo, Shengmin Xu
Shared Dynamic Data Audit Supporting Anonymous User Revocation In Cloud Storage, Yinghui Zhang, Chen Chen, Dong Zheng, Rui Guo, Shengmin Xu
Research Collection School Of Computing and Information Systems
Collusion between revoked users and cloud service providers can pose a threat to the security of cloud storage data. If the original legitimate users cannot be revoked securely, it will lead to the leakage of shared data, thus affecting the security of cloud storage. In this paper, we combine vector commitment and anonymous revocation of group signature to propose an integrity audit scheme for cloud storage data that can support data modification. The anonymity of the group signature ensures that users’ privacy information will not be snooped by the server. The proposed scheme supports the dynamic operation of stored data …
Definitions And Mathematical Models Of Single Vehicle Routing Problems With Profits, Pieter Vansteenwegen, Aldy Gunawan
Definitions And Mathematical Models Of Single Vehicle Routing Problems With Profits, Pieter Vansteenwegen, Aldy Gunawan
Research Collection School Of Computing and Information Systems
In this chapter, single vehicle routing problems with profits are introduced anddefined. Three variants are considered: the profitable tour problem, the prizecollecting traveling salesperson problem, and the orienteering problem. The difference between these variants is the way in which the profit and the travel cost, mostlydistance or time, are modeled. Profit and travel cost can be modeled as (part of) theobjective or as a constraint. All three problems differ from the well-known travelingsalesperson problem, for which the only objective is to find the shortest route to visitall customers in a given set. In vehicle routing problems with profits, some customerswill …
Topic Enhanced Word Embedding For Toxic Content Detection In Q&A Sites, Do Yeon Kim, Xiaohang Li, Sheng Wang, Yunying Zhuo, Ka Wei, Roy Lee
Topic Enhanced Word Embedding For Toxic Content Detection In Q&A Sites, Do Yeon Kim, Xiaohang Li, Sheng Wang, Yunying Zhuo, Ka Wei, Roy Lee
Research Collection School Of Computing and Information Systems
Increasingly, users are adopting community question-and-answer (Q&A) sites to exchange information. Detecting and eliminating toxic and divisive content in these Q&A sites are paramount tasks to ensure a safe and constructive environment for the users. Insincere question, which is founded upon false premises, is one type of toxic content in Q&A sites. In this paper, we proposed a novel deep learning framework enhanced pre-trained word embeddings with topical information for insincere question classification. We evaluated our proposed framework on a large real-world dataset from Quora Q&A site and showed that the topically enhanced word embedding is able to achieve better …
State-Of-The-Art Solution Techniques For Optw And Toptw, Pieter Vansteenwegen, Aldy Gunawan
State-Of-The-Art Solution Techniques For Optw And Toptw, Pieter Vansteenwegen, Aldy Gunawan
Research Collection School Of Computing and Information Systems
In Chaps. 2 and 3, different orienteering problems (or routing problems with profits) were introduced. The single vehicle problems were discussed in Chap. 2: the profitable tour problem (PTP), the prize-collecting traveling salesperson problem (PCTSP), and the orienteering problem (OP). The multi vehicle problems were discussed in Chap. 3: the team orienteering problem (TOP) and the team orienteering problem with time windows (TOPTW). For discussing the state-of-the-art solution techniques for these different orienteering problems in Chaps. 4, 5, and 6, the problems will be classified differently, based on the similarities between the solution techniques. Therefore, the PTP and PCTSP are …
Itaa: An Intelligent Trajectory-Driven Outdoor Advertising Deployment Assistant, Yipeng Zhang, Zhifeng Bao, Songsong Mo, Yuchen Li, Yanghao Zhou
Itaa: An Intelligent Trajectory-Driven Outdoor Advertising Deployment Assistant, Yipeng Zhang, Zhifeng Bao, Songsong Mo, Yuchen Li, Yanghao Zhou
Research Collection School Of Computing and Information Systems
In this paper, we demonstrate an Intelligent Trajectory-driven outdoor Advertising deployment Assistant (ITAA), which assists users to find an optimal strategy for outdoor advertising (ad) deployment. The challenge is how to measure the influence to the moving trajectories of ads, and how to optimize the placement of ads among billboards that maximize the influence has been proven NP-hard. Therefore, we develop a framework based on two trajectory-driven influence models. ITAA is built upon this framework with a user-friendly UI. It serves both ad companies and their customers. We enhance the interpretability to improve the user's understanding of the influence of …
State-Of-The-Art Solution Techniques For Op And Top, Pieter Vansteenwegen, Aldy Gunawan
State-Of-The-Art Solution Techniques For Op And Top, Pieter Vansteenwegen, Aldy Gunawan
Research Collection School Of Computing and Information Systems
Definitions and mathematical models of the OP and the TOP were introduced in Chaps. 2 and 3. In this chapter, we will discuss the benchmark instances and state-of-the-art solution techniques for both OP and TOP. Some illustrations of benchmark instances and solutions are included in order to increase the understanding in the difficulty of solving this problem and to provide additional insights. The solution techniques are classified into two different categories: exact approaches and (meta)heuristic techniques.
Applications Of The Op, Pieter Vansteenwegen, Aldy Gunawan
Applications Of The Op, Pieter Vansteenwegen, Aldy Gunawan
Research Collection School Of Computing and Information Systems
In recent years, we observe from literature that the VRP and OP, including their variants, have been used to model many different planning and scheduling problems from practice, such as the routing of technicians, athlete recruitment, or military applications. Recently, other practical applications, such as the tourist trip design problem, the mobile crowdsourcing problem, the smuggler search problem, the wildfire routing problem, and the integration of vehicle routing, inventory management, and customer selection problems, have been studied and use the OP as a basic model. In this chapter, various practical applications will be discussed in more detail. We will describe …
Towards Robust Resnet: A Small Step But A Giant Leap, Jingfeng Zhang, Bo Han, Laura Wynter, Bryan Kian Hsiang Low, Mohan Kankanhalli
Towards Robust Resnet: A Small Step But A Giant Leap, Jingfeng Zhang, Bo Han, Laura Wynter, Bryan Kian Hsiang Low, Mohan Kankanhalli
Research Collection School Of Computing and Information Systems
This paper presents a simple yet principled approach to boosting the robustness of the residual network (ResNet) that is motivated by a dynamical systems perspective. Namely, a deep neural network can be interpreted using a partial differential equation, which naturally inspires us to characterize ResNet based on an explicit Euler method. This consequently allows us to exploit the step factor h in the Euler method to control the robustness of ResNet in both its training and generalization. In particular, we prove that a small step factor h can benefit its training and generalization robustness during backpropagation and forward propagation, respectively. …
How Can Ai Help To Enhance Diversity And Inclusion?, Keng Siau
How Can Ai Help To Enhance Diversity And Inclusion?, Keng Siau
Research Collection School Of Computing and Information Systems
In many organizations, promoting diversity and enhancing inclusion are still major concerns. Unconscious biases and stereotyping cause us to have preconceived ideas about what an ideal employee or leader should look like. Unconscious biases are also a major roadblock to an inclusive environment and business culture. Organizations have been investing heavily in training programs for their employees attempting to changes these patterns. Human habits, especially unconscious ones, are not easy to overcome. This research looks at the use of AI to enhance diversity and inclusion in organizations. Literature has shown that a more diverse and inclusive workforce has a competitive …
Higher Education In The Ai Age, Yizhi Ma, Keng Siau
Higher Education In The Ai Age, Yizhi Ma, Keng Siau
Research Collection School Of Computing and Information Systems
A perfect storm is hitting higher education. Decrease funding from traditional funding sources such as State Governments and transformative changes caused by artificial intelligence (AI) will revolutionize higher education (Siau 2018). Higher education needs to change and evolve quickly and continuously to prepare students for the upheavals in the job market caused by AI, machine learning, and automation. Further, continuous organizational and curriculum changes will be necessary for a higher education institution to stay relevant and to stay afloat. This qualitative research looks at higher education in the AI age. Stakeholders (i.e., administrators, faculty, students, industry recruiters) in higher education …
Industry 4.0: Challenges And Opportunities In Different Countries, Keng Siau, Yingrui Xi, Cui Zou
Industry 4.0: Challenges And Opportunities In Different Countries, Keng Siau, Yingrui Xi, Cui Zou
Research Collection School Of Computing and Information Systems
Along with the rapid development of artificial intelligence (AI), cyber-physical systems (CPSs), big data analytics, and cloud computing, Industry 4.0 — a subset of the fourth Industrial Revolution — has started to emerge and take root in many countries. Many expect that Industry 4.0 will be transformative and revolutionary for multiple industries and countries. Its impact will be much more significant than those of Industry 1.0, 2.0, and 3.0. Most studies and papers on Industry 4.0 have examined its impact on various industries, jobs, and organizations. In this article, we investigate the impact of Industry 4.0 on countries and groups …
Industry 4.0: Ethical And Moral Predicaments, W. Wang, Keng Siau
Industry 4.0: Ethical And Moral Predicaments, W. Wang, Keng Siau
Research Collection School Of Computing and Information Systems
The advancements in software technology and data science are enabling Industry 4.0, aka the Fourth Industrial Revolution or the Industrial Internet of Things (IIoT). While the first three industrial revolutions have brought about immense change, the impact of Industry 4.0 will be much wider and far greater, especially with regard to the easily overlooked ethical and moral aspects. Widening wealth gaps between countries and among classes of people within countries, a potential growing unemployment rate, data privacy and accessibility issues, and the treatment of intelligent agents (e.g., military robots) present new and complex ethical and moral dilemmas. In this article, …
Digital Marketing In The Artificial Intelligence And Machine Learning Age, Z. Ruan, Keng Siau
Digital Marketing In The Artificial Intelligence And Machine Learning Age, Z. Ruan, Keng Siau
Research Collection School Of Computing and Information Systems
We are living in a period of profound change driven by digitization, information and communication technology, artificial intelligence, machine learning, and robotics (Gupta, Keen, Shah, and Verdier, 2017; Wang and Siau, 2019). Traditional marketing is shifting to digital marketing enabled by AI and machine learning. Customer consumption behavior has changed from traditional in-store shopping to online shopping (Thiraviyam, 2018). The large volume of transaction and demographic data enables business analytics, AI, and machine learning to analyze and predict customer behavior to improve customer satisfaction and enhance sales (Siau and Wang, 2018). For example, predictive analytics uses different algorithms to predict …
Potential Impact Of Artificial Intelligence On Mental Well-Being, Weiyu Wang, Keng Siau
Potential Impact Of Artificial Intelligence On Mental Well-Being, Weiyu Wang, Keng Siau
Research Collection School Of Computing and Information Systems
Artificial Intelligence (AI) will result in job replacement and job elimination. Some AI technologies, such as self-driving vehicles, have the potential to disrupt existing industries. Self-driving trucks may replace the 3.5 million truck drivers in the US. Scholars at Oxford University estimated that no less than 47% of American jobs and 54% of those in Europe are at a high risk of being taken over by machines. Routine, repetitive, and predictable jobs are expected to be automated (Siau, 2018). Although new jobs will be created, unemployment rate may go up in the short term and the emergence of a “useless …
Ai-Fashion: Collaborative Ai In The Fashion Industry, Y. Luo, Keng Siau
Ai-Fashion: Collaborative Ai In The Fashion Industry, Y. Luo, Keng Siau
Research Collection School Of Computing and Information Systems
Abstract The word vintage is generally accepted to mean clothing produced in the period between 1920s and 1980s (Cervellon et al., 2012). According to Fischer (2015), fashion usually means rapid changes and up-to-date trendiness. Vintage dressing, however, has been a fashionable trend for over 40 years. Can AI be used to predict the next fashion trend? Fashion industry is currently exploring the use of AI to analyze customer behavior and predict next year’s fashion trends. Predicting the correct next trend is vital to the competitiveness and survivability of fashion brands. Research in this area is not new. For example, research …
Gradient Boosting With Piece-Wise Linear Regression Trees, Yu Shi, Jian Li, Zhize Li
Gradient Boosting With Piece-Wise Linear Regression Trees, Yu Shi, Jian Li, Zhize Li
Research Collection School Of Computing and Information Systems
Gradient Boosted Decision Trees (GBDT) is a very successful ensemble learning algorithm widely used across a variety of applications. Recently, several variants of GBDT training algorithms and implementations have been designed and heavily optimized in some very popular open sourced toolkits including XGBoost, LightGBM and CatBoost. In this paper, we show that both the accuracy and efficiency of GBDT can be further enhanced by using more complex base learners. Specifically, we extend gradient boosting to use piecewise linear regression trees (PL Trees), instead of piecewise constant regression trees, as base learners. We show that PL Trees can accelerate convergence of …
Let Me In: Guidelines For The Successful Onboarding Of Newcomers To Open Source Projects, Igor Steinmacher, Christoph Treude, Marco Aurélio Gerosa
Let Me In: Guidelines For The Successful Onboarding Of Newcomers To Open Source Projects, Igor Steinmacher, Christoph Treude, Marco Aurélio Gerosa
Research Collection School Of Computing and Information Systems
Many community-based open source software (OSS) projects depend on a continuous influx of newcomers for their survival and continuity, yet newcomers face many barriers to contributing to a project. We provide guidelines based on our previous work for both OSS communities and newcomers to OSS projects.
Locating Vulnerabilities In Binaries Via Memory Layout Recovering, Haijun Wang, Xiaofei Xie, Shang-Wei Lin, Yun Lin, Yuekang Li, Shengchao Qin, Yang Liu, Ting Liu
Locating Vulnerabilities In Binaries Via Memory Layout Recovering, Haijun Wang, Xiaofei Xie, Shang-Wei Lin, Yun Lin, Yuekang Li, Shengchao Qin, Yang Liu, Ting Liu
Research Collection School Of Computing and Information Systems
Locating vulnerabilities is an important task for security auditing, exploit writing, and code hardening. However, it is challenging to locate vulnerabilities in binary code, because most program semantics (e.g., boundaries of an array) is missing after compilation. Without program semantics, it is difficult to determine whether a memory access exceeds its valid boundaries in binary code. In this work, we propose an approach to locate vulnerabilities based on memory layout recovery. First, we collect a set of passed executions and one failed execution. Then, for passed and failed executions, we restore their program semantics by recovering fine-grained memory layouts based …
Deepstellar: Model-Based Quantitative Analysis Of Stateful Deep Learning Systems, Xiaoning Du, Xiaofei Xie, Yi Li, Lei Ma, Yang Liu, Jianjun Zhao
Deepstellar: Model-Based Quantitative Analysis Of Stateful Deep Learning Systems, Xiaoning Du, Xiaofei Xie, Yi Li, Lei Ma, Yang Liu, Jianjun Zhao
Research Collection School Of Computing and Information Systems
Deep Learning (DL) has achieved tremendous success in many cutting-edge applications. However, the state-of-the-art DL systems still suffer from quality issues. While some recent progress has been made on the analysis of feed-forward DL systems, little study has been done on the Recurrent Neural Network (RNN)-based stateful DL systems, which are widely used in audio, natural languages and video processing, etc. In this paper, we initiate the very first step towards the quantitative analysis of RNN-based DL systems. We model RNN as an abstract state transition system to characterize its internal behaviors. Based on the abstract model, we design two …
Cerebro: Context-Aware Adaptive Fuzzing For Effective Vulnerability Detection, Yuekang Li, Yinxing Xue, Hongxu Chen, Xiuheng Wu, Cen Zhang, Xiaofei Xie, Haijun Wang, Yang Liu
Cerebro: Context-Aware Adaptive Fuzzing For Effective Vulnerability Detection, Yuekang Li, Yinxing Xue, Hongxu Chen, Xiuheng Wu, Cen Zhang, Xiaofei Xie, Haijun Wang, Yang Liu
Research Collection School Of Computing and Information Systems
Existing greybox fuzzers mainly utilize program coverage as the goal to guide the fuzzing process. To maximize their outputs, coverage-based greybox fuzzers need to evaluate the quality of seeds properly, which involves making two decisions: 1) which is the most promising seed to fuzz next (seed prioritization), and 2) how many efforts should be made to the current seed (power scheduling). In this paper, we present our fuzzer, Cerebro, to address the above challenges. For the seed prioritization problem, we propose an online multi-objective based algorithm to balance various metrics such as code complexity, coverage, execution time, etc. To address …
Diffchaser: Detecting Disagreements For Deep Neural Networks, Xiaofei Xie, Lei Ma, Haijun Wang, Yuekang Li, Yang Liu, Xiaohong Li
Diffchaser: Detecting Disagreements For Deep Neural Networks, Xiaofei Xie, Lei Ma, Haijun Wang, Yuekang Li, Yang Liu, Xiaohong Li
Research Collection School Of Computing and Information Systems
The platform migration and customization have become an indispensable process of deep neural network (DNN) development lifecycle. A highprecision but complex DNN trained in the cloud on massive data and powerful GPUs often goes through an optimization phase (e.g., quantization, compression) before deployment to a target device (e.g., mobile device). A test set that effectively uncovers the disagreements of a DNN and its optimized variant provides certain feedback to debug and further enhance the optimization procedure. However, the minor inconsistency between a DNN and its optimized version is often hard to detect and easily bypasses the original test set. This …
Deep Anomaly Detection With Deviation Networks, Guansong Pang, Chunhua Shen, Anton Van Den Hengel
Deep Anomaly Detection With Deviation Networks, Guansong Pang, Chunhua Shen, Anton Van Den Hengel
Research Collection School Of Computing and Information Systems
Although deep learning has been applied to successfully address many data mining problems, relatively limited work has been done on deep learning for anomaly detection. Existing deep anomaly detection methods, which focus on learning new feature representations to enable downstream anomaly detection methods, perform indirect optimization of anomaly scores, leading to data-inefficient learning and suboptimal anomaly scoring. Also, they are typically designed as unsupervised learning due to the lack of large-scale labeled anomaly data. As a result, they are difficult to leverage prior knowledge (e.g., a few labeled anomalies) when such information is available as in many real-world anomaly detection …
Control-Flow Carrying Code, Yan Lin, Debin Gao
Control-Flow Carrying Code, Yan Lin, Debin Gao
Research Collection School Of Computing and Information Systems
Control-Flow Integrity (CFI) is an effective approach in mitigating control-flow hijacking attacks including code-reuse attacks. Most conventional CFI techniques use memory page protection mechanism, Data Execution Prevention (DEP), as an underlying basis. For instance, CFI defenses use read-only address tables to avoid metadata corruption. However, this assumption has shown to be invalid with advanced attacking techniques, such as Data-Oriented Programming, data race, and Rowhammer attacks. In addition, there are scenarios in which DEP is unavailable, e.g., bare-metal systems and applications with dynamically generated code. We present the design and implementation of Control-Flow Carrying Code (C3), a new CFI enforcement without …
Dynopvm: Vm-Based Software Obfuscation With Dynamic Opcode Mapping, Xiaoyang Cheng, Yan Lin, Debin Gao
Dynopvm: Vm-Based Software Obfuscation With Dynamic Opcode Mapping, Xiaoyang Cheng, Yan Lin, Debin Gao
Research Collection School Of Computing and Information Systems
VM-based software obfuscation has emerged as an effective technique for program obfuscation. Despite various attempts in improving its effectiveness and security, existing VM-based software obfuscators use potentially multiple but static secret mappings between virtual and native opcodes to hide the underlying instructions. In this paper, we present an attack using frequency analysis to effectively recover the secret mapping to compromise the protection, and then propose a novel VM-based obfuscator in which each basic block uses a dynamic and control-flow-aware mapping between the virtual and native instructions. We show that our proposed VM-based obfuscator not only renders the frequency analysis attack …
Practical And Effective Sandboxing For Linux Containers, Zhiyuan Wan, David Lo, Xin Xia, Liang Cai
Practical And Effective Sandboxing For Linux Containers, Zhiyuan Wan, David Lo, Xin Xia, Liang Cai
Research Collection School Of Computing and Information Systems
A container is a group of processes isolated from other groups via distinct kernel namespaces and resource allocation quota. Attacks against containers often leverage kernel exploits through the system call interface. In this paper, we present an approach that mines sandboxes and enables fine-grained sandbox enforcement for containers. We first explore the behavior of a container by running test cases and monitor the accessed system calls including types and arguments during testing. We then characterize the types and arguments of system call invocations and translate them into sandbox rules for the container. The mined sandbox restricts the container’s access to …
Network-Clustered Multi-Modal Bug Localization, Thong Hoang, Richard J. Oentaryo, Tien-Duy B. Le, David Lo
Network-Clustered Multi-Modal Bug Localization, Thong Hoang, Richard J. Oentaryo, Tien-Duy B. Le, David Lo
Research Collection School Of Computing and Information Systems
Developers often spend much effort and resources to debug a program. To help the developers debug, numerous information retrieval (IR)-based and spectrum-based bug localization techniques have been devised. IR-based techniques process textual information in bug reports, while spectrum-based techniques process program spectra (i.e., a record of which program elements are executed for each test case). While both techniques ultimately generate a ranked list of program elements that likely contain a bug, they only consider one source of information—either bug reports or program spectra— which is not optimal. In light of this deficiency, this paper presents a new approach dubbed Network-clustered …