Abstract is missing.
- Fuzzing the Physical Space: Physics-Aware Testing of Black-Box Industrial Control SystemsBurak Sahin, David Oygenblik, Mingxuan Yao, Yizhi Huang, Brendan Saltaformaggio, Saman A. Zonouz. 1-18 [doi]
- StepStone: LLM-Based GPU Kernel Driver Fuzzing via User-Space LibrariesXiaochen Zou, Juefei Pu, Arrdya Srivastav, Jonathan Cox, Zhengchuan Liang, yuan Tan, Xingyu Li, Yilin Zhu, Zhiyun Qian. 1-18 [doi]
- The Person Behind the Sound: Demystifying Audio Private Attribute Profiling Via Multimodal Large Language ModelsLixu Wang, Kaixiang Yao, Xinfeng Li, Dong Yang, Haoyao Li, Xiaofeng Wang 0001, Wei Dong 0007. 1-20 [doi]
- Responsible Disclosure is a Two-Way Street: Empirically Measuring the Responsible Disclosure Contract in the Firmware EcosystemHui Jun Tay, Souradip Nath, Arvind S. Raj, Abhay Bhat, Ishan Bansal, Audrey Dutcher, Moritz Schloegel, Adam Doupé, Tiffany Bao, Yan Shoshitaishvili, Ruoyu Wang 0001. 1-18 [doi]
- Descriptors of Exposure: Undermining Tor Anonymity Through Exploiting Descriptor FloodChunmian Wang, Junzhou Luo, Zhen Ling 0001, Yue Zhang 0025, Shan Wang 0008, Ming Yang 0001, Guangchi Liu, Xinwen Fu. 1-18 [doi]
- SoK: All You Ever Wanted to Know About Bootloader Security but Were Afraid to AskConnor Glosner, Aravind Machiry. 1-22 [doi]
- One Tap to Hijack Them All: A Security Analysis of the Google Fast Pair ProtocolSayon Duttagupta, Seppe Wyns, Nikola Antonijevic, Dave Singelée, Bart Preneel. 1-18 [doi]
- Keytar: Practical Keystroke Timing Attacks and Input ReconstructionMufan Qiu, Lihsuan Chuang, Dohhyun Kim, Huaizhi Qu, Tianlong Chen 0001, Andrew Kwong. 1-20 [doi]
- Blinding Post-Quantum Hash-and-Sign SignaturesCharles Bouillaguet, Thibauld Feneuil, Jules Maire, Matthieu Rivain, Julia Sauvage, Damien Vergnaud. 1-18 [doi]
- DY* Unchained: Now with Composable Security Proofs and Precise Compromise ScenariosThéophile Wallez. 1-18 [doi]
- LLM Unlearning Should Be Form-IndependentXiaotian Ye, Mengqi Zhang, Shu Wu. 1-18 [doi]
- VerfCNN, Optimal Complexity zkSNARK for Convolutional Neural NetworksWenjie Qu 0001, Yanpei Guo, Yue Ying, Jiaheng Zhang. 1-18 [doi]
- SoK: Critical Evaluation of Quantum Machine Learning for Adversarial RobustnessSaeefa Rubaiyet Nowmi, Jesus Rafael Lopez, Md Mahmudul Alam Imon, Shahrooz Pouryousef, Mohammad Saidur Rahman 0002. 19-38 [doi]
- Sok: Evaluating Jailbreak Guardrails for Large Language ModelsXunguang Wang, Zhenlan Ji, Wenxuan Wang 0001, Zongjie Li, Daoyuan Wu, Shuai Wang 0011. 39-58 [doi]
- URLcoat: Exploiting Web Search Capability to Jailbreak Large Language ModelsYiheng Sun, Linkang Du, Zhou Su 0001, Yuntao Wang 0004, Han Liu. 59-77 [doi]
- MetaBreak: Jailbreaking Online LLM Services via Special Token ManipulationWentian Zhu, Zhen Xiang, Wei Niu 0002, Le Guan. 98-117 [doi]
- SoK: Robustness in Large Language Models against Jailbreak AttacksFeiyue Xu, Hongsheng Hu, Chaoxiang He, Sheng Hang, Hanqing Hu, Xiuming Liu, Yubo Zhao, Zhengyan Zhou, Bin Benjamin Zhu, Shifeng Sun 0001, Dawu Gu, Shuo Wang 0012. 118-137 [doi]
- Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP EcosystemShuli Zhao, Qinsheng Hou, Zihan Zhan, Yanhao Wang, Yuchong Xie, Yu Guo, Libo Chen 0001, Shenghong Li 0001, Zhi Xue. 138-155 [doi]
- Ensemble Conformal Predictor (EnCP): A New Conformal Predictor with Robustness Guarantees Against Data Poisoning AttacksYuxin Yang, Qiang Li, Runyang Feng, Liren Shan, Binghui Wang. 156-174 [doi]
- Exploiting Leaderboards for Large-Scale Distribution of Malicious ModelsAnshuman Suri, Harsh Chaudhari, Yuefeng Peng, Ali Naseh, Alina Oprea, Amir Houmansadr. 175-194 [doi]
- GraphRAG Under FireJiacheng Liang, Yuhui Wang 0003, Changjiang Li, Tanqiu Jiang, Rongyi Zhu, Neil Gong 0001, Ting Wang 0006. 195-212 [doi]
- AI Wrote My Paper and All I Got was This False Negative:* Measuring the Efficacy of Commercial AI Text DetectorsSeth Layton, Bernardo B. P. Medeiros, Kevin R. B. Butler, Patrick Traynor. 213-232 [doi]
- Your Compiler is Backdooring Your Model: Understanding and Exploiting Compilation Inconsistency Vulnerabilities in Deep Learning CompilersSimin Chen, Jinjun Peng, Yixin He 0002, Junfeng Yang, Baishakhi Ray. 233-251 [doi]
- DREAM: Scalable Red Teaming for Text-to-Image Generative Systems via Distribution ModelingBoheng Li, Junjie Wang 0007, Yiming Li 0004, Zhiyang Hu, Leyi Qi, Jianshuo Dong, Run Wang 0001, Han Qiu 0001, Zhan Qin, Tianwei Zhang 0004. 252-271 [doi]
- On the (In)Security of Loading Machine Learning ModelsGabriele Digregorio, Marco Di Gennaro 0001, Stefano Zanero, Stefano Longari, Michele Carminati. 272-289 [doi]
- Evaluating Concept Filtering Defenses against Child Sexual Abuse Material Generation by Text-to-Image ModelsAna-Maria Cretu 0002, Klim Kireev, Amro Abdalla, Wisdom Obinna, Raphael Meier, Sarah Adel Bargal, Elissa M. Redmiles, Carmela Troncoso. 290-309 [doi]
- Hijacking Large Audio-Language Models via Context-Agnostic and Imperceptible Auditory Prompt InjectionMeng Chen 0011, Kun Wang 0025, Li Lu 0008, Jiaheng Zhang, Tianwei Zhang 0004. 310-328 [doi]
- Adversarial Hubness in Multi-Modal RetrievalTingwei Zhang, Fnu Suya, Rishi D. Jha, Collin Zhang, Vitaly Shmatikov. 329-344 [doi]
- Recovering and Rehosting Mobile Local LLM Conversations and Contexts via Memory ForensicsHaichuan Xu, David Oygenblik, Runze Zhang, Mingxuan Yao, Muhammad Ibrahim, Brendan Saltaformaggio. 345-363 [doi]
- Nonlocalizable Jamming with Curving BeamsCaroline Jane Spindel, Edward W. Knightly. 364-378 [doi]
- WRATH: Turning Watermark Robustness Against Itself via a Watermark-Agnostic Black-Box Invalidation AttackNan Jiang, Juan Hu, Bangjie Sun, Terence Sim, Jun Han 0001. 379-397 [doi]
- Are LLM-Enhanced Graph Neural Networks Robust Against Poisoning Attacks?Yuhang Ma, Jie Wang, Zheng Yan. 398-416 [doi]
- Breaking Free from Ivory Tower: Evaluating and Enhancing Real-world Chinese Underground Adversarial Jargon DetectionZhifan Jiang, Mingxuan Liu 0006, Yue Qin, Baojun Liu 0002. 417-435 [doi]
- WebCloak: Characterizing and Mitigating Threats From LLM-Driven Web Agents as Intelligent ScrapersXinfeng Li, Tianze Qiu, Yingbin Jin, Lixu Wang, Hanqing Guo, Xiaojun Jia, Xiaofeng Wang 0001, Wei Dong 0007. 436-455 [doi]
- GHost in the Shell: A GPU-to-Host Memory Attack and its MitigationSihyun Roh, Woohyuk Choi, Jaeyoung Chung, Yoochan Lee, Suhwan Song, Byoungyoung Lee. 456-471 [doi]
- Demystifying and Exploiting ASLR on NVIDIA GPUsRuofan Zhu, Ganhao Chen, Wenbo Shen, Lyuye Zhang, Dakun Shen, Rui Chang, Yanan Guo. 472-488 [doi]
- Phoenix: Rowhammer Attacks on DDR5 with Self-Correcting SynchronizationDiego Meyer, Patrick Jattke, Michele Marazzi, Salman Qazi, Daniel Moghimi, Kaveh Razavi. 489-507 [doi]
- GPUBreach: Privilege Escalation Attacks on GPUs Using RowhammerChris S. Lin, Yuqin Yan, Guozhen Ding, Joyce Qu, Joseph Zhu, David Lie, Gururaj Saileshwar. 526-545 [doi]
- GDDRHammer: Greatly Disturbing DRAM Rows - Cross-Component Rowhammer Attacks From Modern GPUsYichang Hu, Noah Brown, Yuhang Chen, Joshua Bakita, Tianlong Chen 0001, Daniel Genkin, Andrew Kwong. 546-564 [doi]
- GeForge: Hammering GDDR Memory to Forge GPU Page Tables for Fun and ProfitJunpeng Wan, Yanan Guo 0002, Zhi Zhang, Zhuo Li, Dave Jing Tian, Zhenkai Zhang 0002. 565-583 [doi]
- Defeating Transient Execution Attacks by Limiting Secret Reachability Through Register Hiding and ShadowCFIDaniël Trujillo, Jagadish Kotra, David Kaplan, Mengjia Yan 0001. 602-620 [doi]
- Transient Architectural Execution: From Weird Gates to Weird ProgramsPing-Lun Wang, Fraser Brown, Riccardo Paccagnella, Eyal Ronen, Riad S. Wahby, Yuval Yarom. 621-637 [doi]
- SeqAss: Using SeqUential Associative Caches to Mitigate Conflict-Based Cache Attacks with Reduced Cache Misses and Performance OverheadWei Song 0002, Zhidong Wang, Jinchi Han, Da Xie, Hao Ma, Peng Liu 0005. 638-655 [doi]
- Trevex: A Black-Box Detection Framework for Data-Flow Transient Execution VulnerabilitiesDaniel Weber 0007, Fabian Thomas, Leon Trampert, Ruiyi Zhang 0001, Michael Schwarz 0001. 676-695 [doi]
- AESpoly: Symmetric-Key Cryptographic Designs Using Instruction-Level Parallelism Between AES and Polynomial HashYukihito Hiraga, Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001. 696-715 [doi]
- Crucible: Retrofitting Commodity CPUs with Vulnerabilities via Transparent Software EmulationTristan Hornetz, Lukas Gerlach 0001, Michael Schwarz 0001. 716-731 [doi]
- RISCy Cache Coherence: Timer-Free Architectural Cache Attacks via Instruction/Data Cache IncoherenceFabian Thomas, Michael Schwarz 0001. 732-749 [doi]
- "I Wonder if These Warnings are Accurate": Security and Privacy Advice in Nine Majority World CountriesCollins W. Munyendo, Veronica A. Rivera, Jackie Hu, Emmanuel Tweneboah, Amna Shahnawaz, Karen Sowon, Dilara Keküllüoglu, Marcos Silva, Yue Deng, Mercy Omeiza, Gayatri Priyadarsini Kancherla, Marianne Batista Diniz Da Silva, Abhishek Bichhawat, Maryam Mustafa, Francisco J. Marmolejo Cossío, Elissa M. Redmiles, Yixin Zou. 750-769 [doi]
- Privacy Perspectives and Practices of Chinese Smart Home Product TeamsShijing He, Yaxiong Lei, Xiao Zhan, Chi Zhang 0084, Juan Ye, Ruba Abu-Salma, Jose Such. 770-788 [doi]
- Searching for a Farang: Collective Security Among Women in Pattaya, ThailandTaylor-Robinson, Rikke Bjerg Jensen. 789-808 [doi]
- Toward Inclusive Security and Privacy for Deaf and Hard-of-Hearing People: A Community-Based Interview StudyMindy Tran, Xinru Tang, Adryana Hutchinson, Adam J. Aviv, Yixin Zou. 809-828 [doi]
- XDup: Privacy-Preserving Deduplication for Humanitarian Organizations Using Fuzzy PSITim Rausch, Sylvain Chatel, Wouter Lueks. 829-847 [doi]
- Human-Centered Threat Modeling in Practice: Lessons, Challenges, and Paths ForwardWarda Usman, Yixin Zou, Daniel Zappala. 848-866 [doi]
- LISA: A Scale-Optimized and Psychometrically-Validated Instrument for the Lightweight Assessment of Organizational Information Security Awareness in Heterogeneous OrganizationsDavid Langer, Jan Tolsdorf, Luigi Lo Iacono. 867-886 [doi]
- Perceived Privacy Risk and Mitigation Post-RoeAlan F. Luo, Phoebe Moh, Cora Sula, Michelle L. Mazurek, Nora McDonald. 887-904 [doi]
- Breaking the Illusion: Automated Reasoning of GDPR Consent ViolationsYing Li 0095, Wenjun Qiu, Faysal Hossain Shezan, Kunlin Cai, Michelangelo van Dam, Lisa M. Austin, David Lie, Yuan Tian 0001. 905-923 [doi]
- Understanding and Analyzing Privacy Risks in Mobile Consent-Management PlatformsJingzhou Ye, Fares Alharbi, Luyi Xing, Xueqiang Wang. 924-942 [doi]
- Convenience at a Cost: the Security Risks of Template-Based Development in the App-in-App EcosystemYizhe Shi, Zhemin Yang, Yifan Yang, Yunteng Yang, Min Yang. 943-960 [doi]
- When VR Meets BCI: (Un)Observable Brainwave-Aware Privacy Reconstruction in the Metaverse via Unrestricted Inbuilt Motion SensorsTao Ni 0003, Zehua Sun, Qingchuan Zhao, Wei-Bin Lee, Cong Wang 0001. 961-979 [doi]
- Secret State Leakage Attacks and Their Impacts on EMV Contactless Payment AppsJesse Chen, Rubin Yuchan Yang, Ahmad Musa, Syed Rafiul Hussain, Omar Chowdhury, Sazzadur Rahaman. 980-998 [doi]
- Navigating Developers' Quagmire: LLM-Enabled Privacy Compliance Analysis for SDK IntegrationsZhaojie Hu, Xueqiang Wang. 999-1018 [doi]
- LLMThief: Evaluating Configuration Leaking Risks in Commercial LLM App StoresPinji Chen, Jinlong Jiang, Jianjun Chen 0005, Feiran Qin, Minghao Zhang, Jiahe Zhang, Haixin Duan, Kaiwen Shen, Hui Jiang. 1019-1037 [doi]
- LEAKYLINKS: Measuring the Security and Privacy Risks of URL Scanning ServicesAli Mustafa, Jannis Rautenstrauch, Florian Hantke, Shubham Agarwal 0006, Stefano Calzavara, Ben Stock. 1038-1057 [doi]
- Concretely-Efficient Multi-Key Homomorphic Secret Sharing and ApplicationsKaiwen He, Sacha Servan-Schreiber, Geoffroy Couteau, Srinivas Devadas. 1058-1077 [doi]
- No Honor Among Crooks: Non-Transferable Anonymous Tokens from BetrayabilityDavid Kretzler, Yong Li 0021. 1078-1097 [doi]
- Revisiting PQ Wireguard: A Comprehensive Security Analysis with a New Design Using Reinforced KEMsKeitaro Hashimoto, Shuichi Katsumata, Guilhem Niot, Thom Wiggers. 1098-1117 [doi]
- Can I Get More? An Incremental Inference Attack on Encrypted SQLXiaoqian Sun, Ruiqi He, Yang Zhang, Siyi Lv, Guiyun Qin, FangZhou Yi, Zheli Liu, Xiaofeng Chen 0001. 1118-1137 [doi]
- Starfighters-On the General Applicability of X-WingDeirdre Connolly, Kathrin Hövelmanns, Andreas Hülsing, Stavros Kousidis, Matthias Meijers. 1138-1156 [doi]
- A Leakage-Free Framework for Private Set OperationsWenhao Wu, Yuyue Chen, Bowen Shen, Peng Yang 0016, Ximing Fu, Zoe Lin Jiang, Junbin Fang. 1157-1175 [doi]
- Hardware Trojans from Invisible Inversions: On the Trojanizability of Standard Cell LibrariesKolja Dorschel, René Walendy, Lukas Plätz, Thorben Moos, Christof Paar, Steffen Becker 0003. 1176-1194 [doi]
- A Maliciously-Secure Post-Quantum OPRF from Crypto Dark MatterDiego F. Aranha, Aron van Baarsen, Adam Blatchley Hansen, Kent Nielsen, Peter Scholl. 1195-1214 [doi]
- Scalable Accountable Byzantine Agreement and BeyondPierre Civit, Daniel Collins 0001, Vincent Gramoli, Rachid Guerraoui, Jovan Komatovic, Manuel Vidigueira, Pouriya Zarbafian. 1215-1234 [doi]
- Practical Asynchronous Distributed Key Reconfiguration and Its ApplicationsHanwen Feng 0001, Yingzi Gao, Yuan Lu 0001, Qiang Tang 0005, Jing Xu 0002. 1253-1272 [doi]
- Lattice-Based Threshold Blind SignaturesSebastian Faller, Guilhem Niot, Michael Reichle. 1273-1292 [doi]
- A Full Threshold NIST PQC-Compliant Framework for Distributed Trust in Federal Public Key InfrastructureKiarash Sedghighadikolaei, Changqi Sun, Thang Hoang, Bechir Hamdaoui, Attila A. Yavuz. 1293-1312 [doi]
- Mad-Dag: Protecting Blockchain Consensus From MEVRoi Bar Zur, Ittay Eyal, Aviv Tamar. 1313-1331 [doi]
- Robot: Robust Threshold BBS+ in Two RoundsGuoFeng Tang, Tian Qiu, Bowen Jiang, Haiyang Xue, Guomin Yang, Man Ho Au, Robert H. Deng, Kwok-Yan Lam. 1332-1349 [doi]
- New Constructions of Functional Adaptor Signatures: Broader Functions and Improved EfficiencyNikhil Vanjani, Garrett Greiner, Sri Aravinda Krishnan Thyagarajan, Pratik Soni. 1350-1368 [doi]
- Practical Multi-Party Private Set Intersection with Reducible Zero-SharingYewei Guan, Hua Guo 0001, Man Ho Au, Jiarong Huo, Jin Tan, Zhenyu Guan 0002. 1369-1384 [doi]
- Single-Server Stateful PIR with Verifiability and Balanced EfficiencyPranav Shriram Arunachalaramanan, Ling Ren 0001. 1385-1402 [doi]
- ZELDA: Efficient Multi-Server Preprocessing PIR With Unconditional SecurityAshrujit Ghoshal, Mingxun Zhou, Bo Peng 0030, Elaine Shi. 1403-1422 [doi]
- Verifiable PIR with Small Client StorageMayank Rathee, Keewoo Lee, Raluca Ada Popa. 1423-1442 [doi]
- Euston: Efficient and User-Friendly Secure Transformer Inference with Non-InteractivityXinwen Gao, Shaojing Fu, Lin Liu 0018, Zhuotao Liu, Yuchuan Luo, Yongjun Wang. 1443-1462 [doi]
- InsPIRe: Communication-Efficient PIR with Server-Side PreprocessingRasoul Akhavan Mahdavi, Sarvar Patel, Joon Young Seo, Kevin Yeo. 1463-1482 [doi]
- LatORAM: ORAMs from Lateral Stashes and Delayed ShufflingSarvar Patel, Giuseppe Persiano, Joon Young Seo, Kevin Yeo. 1483-1502 [doi]
- VIA: Communication-Efficient Single-Server Private Information RetrievalChenyang Liu, Xukun Wang, Zhifang Zhang. 1503-1521 [doi]
- Automated Formal Analysis of Signal's Double Ratchet: Attacks, Fixes and Security ProofsVincent Cheval, Charlie Jacomme, Jessica Richards. 1522-1538 [doi]
- Banshee: Target Switch Attacks on Gimbal-Stabilized Visual Tracking Systems via Acoustic InjectionJiarui Li, Joseph Brewington, Qingzhao Zhang 0001, Z. Morley Mao. 1539-1557 [doi]
- Rain: Transiently Leaking Data from Public Clouds Using Old VulnerabilitiesMathé Hertogh, Dave Quakkelaar, Thijs Raymakers, Mahesh Hari Sarma, Marius Muench, Herbert Bos, Erik van der Kouwe. 1558-1574 [doi]
- Chypnosis: Undervolting-based Static Side-channel AttacksKyle Mitard, Saleh Khalaj Monfared, Fatemeh Khojasteh Dana, Robert Dumitru 0002, Yuval Yarom, Shahin Tajik. 1575-1593 [doi]
- SoK: Systematizing a Decade of Architectural Rowhammer Defenses Through the Lens of Streaming AlgorithmsMichael Jaemin Kim, Seungmin Baek, Jumin Kim, Hwayong Nam, Nam Sung Kim, Jung Ho Ahn. 1594-1612 [doi]
- RadKey: An LLM-Guided RF Backscatter System for Through-Wall Keystroke InferenceQijun Wang, Chunqi Qian, Huacheng Zeng. 1613-1631 [doi]
- Beyond Indistinguishability: Measuring Extraction Risk in LLM APIsRuixuan Liu, David Evans 0001, Li Xiong 0001. 1654-1672 [doi]
- Agentic Concolic ExecutionZhengxiong Luo 0002, Huan Zhao, Dylan Wolff, Cristian Cadar, Abhik Roychoudhury. 1673-1691 [doi]
- C-Verifier: Understanding and Formally Verifying Cross-Service Flaws in AWS CognitoZhen Chen, Ze Jin, Le Gong, Kexin Chen, Xiangyi Zeng, Qixu Liu. 1692-1709 [doi]
- VMSCAPE: Exposing and Exploiting Incomplete Branch Predictor Isolation in Cloud EnvironmentsJean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, Kaveh Razavi. 1710-1727 [doi]
- Practical Covert Channel Across Isolated Browser Instances via GPU Command Queue ContentionJinhong Liu, Zifeng Kang, Song Li 0006, Yinzhi Cao. 1728-1746 [doi]
- Detecting Privilege Escalation in Polyglot Microservices via Agentic Program AnalysisPenghui Li, Hong Yau Chong, Yinzhi Cao, Junfeng Yang. 1747-1765 [doi]
- State of Browser Process-Isolation: The Same-Site WeaknessFabian Kilger, Hannah Fischer, Adrian Staeves, Robin Marchart, Josef Schönberger, Fabian Franzen. 1766-1784 [doi]
- KeyChaser: Unveiling API Keys in Browser ExtensionsShijin Chen, Willy Susilo, Yudi Zhang 0001, Fuchun Guo. 1785-1803 [doi]
- Site Isolation is Dead: How Site Isolation is Broken in Agentic Browsers and ExtensionsSuyoung Lee, Seongho Keum, Changoo Lee, Dongwon Shin, Sanghyun Hong 0001, Byoungyoung Lee, Sooel Son. 1804-1821 [doi]
- The Secrets Must Not Flow: Scaling Security Verification to Large CodebasesLinard Arquint, Samarth Kishor, Jason R. Koenig, Joey Dodds, Daniel Kroening, Peter Müller 0001. 1822 [doi]
- Mechanized Safety and Liveness Proofs for the Mysticeti Consensus Protocol Under the LiDO-DAG FrameworkLongfei Qiu, Jingqi Xiao, Zhong Shao 0001. 1842-1861 [doi]
- Towards Practical Zero-Knowledge Proof for PSPACEAshwin Karthikeyan, Hengyu Liu, Kuldeep S. Meel, Ning Luo 0002. 1842-1861 [doi]
- Coral: Fast Succinct Non-Interactive Zero-Knowledge CFG ProofsSebastian Angel, Sofía Celi, Elizabeth Margolin, Pratyush Mishra 0001, Martin Sander, Jess Woods. 1882-1901 [doi]
- Dory: Streaming PCG with Small MemoryXiaojie Guo 0004, Hanlin Liu, Zhicong Huang, Hongrui Cui, Wenhao Zhang, Cheng Hong 0001, Xiao Wang 0012, Kang Yang 0002, Yu Yu 0001. 1902-1920 [doi]
- CAVERN: Efficient Honest-Majority Maliciously Secure (2+1)-PC for $\mathbb{Z}_{2^{n}}$ via DPFYang Liu 0003, Liang Feng Zhang. 1921-1936 [doi]
- Sort, Sweep, Mirror: Batch Private Interval Lookup with Logarithmic CostAndes Y. L. Kei, Lucien K. L. Ng, Jack P. K. Ma, Sherman S. M. Chow. 1937-1950 [doi]
- Vega: Low-Latency Zero-Knowledge Proofs over Existing CredentialsDarya Kaviani, Srinath Setty. 1951-1969 [doi]
- The Pipes Model for Latency and Throughput AnalysisAndrew Lewis-Pye, Kartik Nayak, Nibesh Shrestha. 1970-1988 [doi]
- Generate-then-Verify: Reconstructing Data from Limited Published StatisticsTerrance Liu, Eileen Xiao, Adam D. Smith 0001, Pratiksha Thaker, Zhiwei Steven Wu. 1989-2003 [doi]
- Setting the Course, but Forgetting to Steer: Analyzing Compliance with GDPR's Right of Access to Data by Instagram, TikTok, and YoutubeSai Keerthana Karnam, Abhisek Dash, Antariksh Das, Sepehr Mousavi, Stefan Bechtold, Krishna P. Gummadi, Animesh Mukherjee 0001, Ingmar Weber, Savvas Zannettou. 2004-2022 [doi]
- Practical Anonymous Two-Party Gradient Boosting Decision TreeChenyu Huang, Fan Zhang, Minxin Du, Sherman S. M. Chow, Huangxun Chen, Huaming Rao, Danqing Huang, Bo Qian, Peng Chen 0021. 2023-2041 [doi]
- Consumer Beware! Exploring Data Brokers' CCPA ComplianceElina van Kempen, Isita Bagayatkar, Pavel Frolikov, Chloe Georgiou, Gene Tsudik. 2042-2056 [doi]
- Private Data ImputationAddelkarim Kati, Florian Kerschbaum, Marina Blanton. 2057-2075 [doi]
- It's a Feature, Not a Bug: Secure and Auditable State Rollback for Confidential Cloud ApplicationsQuinn Burke 0002, Anjo Vahldiek-Oberwagner, Michael Swift, Patrick D. McDaniel. 2076-2095 [doi]
- Understanding Data Collection, Brokerage, and Spam in the Lead Marketing EcosystemYash Vekaria, Nurullah Demir, Konrad Kollnig, Zubair Shafiq. 2096-2115 [doi]
- CBUE: Conclusion Based Utility Evaluation for Differentially Private Categorical DataFurkan Sarikaya, ShaoHua Lu, Johes Bater, Mark Hempstead. 2116-2132 [doi]
- Fast Deterministically Safe Proof-of-Work ConsensusAli Farahbakhsh, Giuliano Losa, Youer Pu, Lorenzo Alvisi. 2133-2151 [doi]
- Hadal: Centralized Label DP without a Trusted PartyJames Choncholas, Stanislav Peceny, Amit Agarwal, Mariana Raykova 0001, Baiyu Li, Karn Seth. 2152-2170 [doi]
- Privacy-Conscious Algorithm Design Via PAC PrivacyMayuri Sridhar, Xiaochen Zhu 0003, Srinivas Devadas. 2171-2190 [doi]
- Decomposition-Based Optimal Bounds for Privacy Amplification via ShufflingPengcheng Su, Haibo Cheng 0001, Ping Wang 0003. 2191-2210 [doi]
- Making Privacy Public: Toward a Differential Privacy Deployment RegistryPriyanka Nanayakkara, Elena Ghazi, Salil P. Vadhan. 2211-2229 [doi]
- Auditing Apple's DifferentialPrivacy.framework: Implementation Bugs, Misconfigurations, and Practical RisksRishav Chourasia, Ergute Bao, Uzair Javaid, Xiaokui Xiao. 2230-2249 [doi]
- Sparse Estimation Under Local Differential Privacy at All Privacy LevelsPuning Zhao, Qingqing Ye, Shaowei Wang, Jun Feng, Sheng Yue, Zhen Chen, Xiaochun Cao. 2250-2268 [doi]
- Shared Spotlight Meridian: Distributed Sparse Pseudorandom Functions for Scalable Federated LearningYoulong Ding, Peihua Mai, Jingqi Zhang, Sherman S. M. Chow, Minxin Du, Yan Pang. 2269-2287 [doi]
- Jigsaw: Doubly Private Smart ContractsSanjam Garg, Aarushi Goel, Dimitris Kolonelos, Rohit Sinha 0001. 2288-2306 [doi]
- CHORUS: Secret Recovery with Ephemeral Client CommitteesDeevashwer Rathee, Emma Dauterman, Allison Li, Raluca Ada Popa. 2307-2326 [doi]
- ARES: Scalable and Practical Gradient Inversion Attack in Federated Learning Through Activation RecoveryZirui Gong, Leo Yu Zhang, Yanjun Zhang, Viet Vo, Tianqing Zhu, Shirui Pan, Cong Wang. 2327-2345 [doi]
- On the Detectability of Active Gradient Inversion Attacks in Federated LearningVincenzo Carletti, Pasquale Foggia, Carlo Mazzocca, Giuseppe Parrella, Mario Vento. 2346-2365 [doi]
- Toward Efficient Membership Inference Attacks Against Federated Large Language Models: A Projection Residual ApproachGuilin Deng, Silong Chen, Yuchuan Luo, Yi Liu 0057, Songlei Wang, Zhiping Cai, Lin Liu 0018, Xiaohua Jia, Shaojing Fu. 2366-2384 [doi]
- STIR/SHAKEN: A Cocktail of Cryptographic ClumsinessJoshua Brown, Paul Grubbs, Matthew Hardeman. 2385-2404 [doi]
- A Liveness Attack to Ethereum PoS with No Additional CostMingfei Zhang, Rujia Li 0001, Xueqian Lu, Sisi Duan. 2405-2423 [doi]
- Sealing the Window: Efficient Tamper Protection for Provenance LogsSagar Mishra, R. Sekar. 2424-2441 [doi]
- Efficient Fuzzy Private Set Intersection from Secret-Shared OPRFXinpeng Yang, Meng Hao 0001, Chenkai Weng, Robert H. Deng, Yonggang Wen 0001, Tianwei Zhang 0004. 2442-2461 [doi]
- Weighted Batched Threshold Encryption With Applications to Mempool PrivacyAmit Agarwal, Kushal Babel, Sourav Das 0001, Babak Poorebrahim Gilkalaye, Arup Mondal, Benny Pinkas, Peter Rindal, Aayush Yadav. 2462-2481 [doi]
- GoSSamer: Lightweight and Linear-Communication Asynchronous (Dynamic Proactive) Secret Sharing and the ApplicationsXinxin Xing, Yizhong Liu, Boyang Liao, Jianwei Liu 0001, Bin Hu 0001, Xun Lin, Yuan Lu 0001, Tianwei Zhang 0004. 2482-2501 [doi]
- UltraProofs: Scalable Reed-Solomon Code CommitmentYanpei Guo, Alex Luoyuan Xiong, Wenjie Qu 0001, Jiaheng Zhang. 2502-2519 [doi]
- Scalable Registration-Based Encryption from LatticesMichael Klooß, Russell W. F. Lai, Jan Niklas Siemer, Monisha Swarnakar. 2520-2538 [doi]
- From Perfect to Approximate Hints: Efficient LWE Secret Recovery Leveraging Low Hamming WeightMinki Hhan, Ga Hee Hong, Jiseung Kim, Changmin Lee, Jeonghwan Lee. 2539-2553 [doi]
- International Students and Scams: At Risk AbroadKatherine Zhang, Arjun Arunasalam, Pubali Datta, Z. Berkay Celik. 2554-2569 [doi]
- Lost in Translation: Text Message Spoofing via EmailSumanth Rao, Ye Shu, Stefan Savage, Aaron Schulman, Geoffrey M. Voelker, Enze Liu 0001. 2570-2588 [doi]
- From "Be Careful" to "Here's Why": Investigating User Reasoning with Context-Specific SMS Scam WarningsElijah Robert Bouma-Sims, Enze Liu 0001, Alexandra Xinran Li, Lorrie Faith Cranor. 2589-2608 [doi]
- Towards Automating Data Access Permissions in AI AgentsYuhao Wu 0006, Ke Yang, Franziska Roesner, Tadayoshi Kohno, Ning Zhang 0017, Umar Iqbal 0002. 2609-2627 [doi]
- COSSETER: GitHub Actions Permission Reduction Using Demand-Driven Static AnalysisGreg Tystahl, Jonah Ghebremichael, Siddharth Muralee, Sourag Cherupattamoolayil, Antonio Bianchi, Aravind Machiry, Alexandros Kapravelos, William Enck. 2628-2645 [doi]
- EyeSpy: Inferring Eye Gaze via Side-Channel Attacks Against Foveated RenderingPaul Maynard, Harris Amjad, Camila Molinares, Bo Ji 0001, Brendan David-John. 2646-2665 [doi]
- SaTor: Exploring Satellite Routing in Tor to Reduce LatencyHaozhi Li, Tariq Elahi. 2666-2684 [doi]
- A Context Is Worth a Thousand Lies: Evading Intrusion Detectors via Intelligent Context DistortionMagdy Nasr, Vansh Rastogi, Azadeh TabibanB. 2703-2720 [doi]
- MadeYouReset: Exploiting HTTP/2 Server-Side Resets for Large-Scale DoSGal Bar Nahum, Anat Bremler-Barr, Yaniv Harel. 2721-2738 [doi]
- Guardians of the Air: In-Device Detection of 5G Control-Plane ThreatsTianwei Wu, Abdullah Al Ishtiaq, Tianchang Yang, Yilu Dong, Kai Tu, Zeyu Song, Ridwanul Hasan Tanvir, Md. Toufikuzzaman, Shagufta Mehnaz, Syed Rafiul Hussain. 2759-2778 [doi]
- The Threat Landscape of IP Leasing in the RPKI EraWeitong Li, Yongzhe Xu, Taejoong Chung. 2779-2797 [doi]
- Batch Me If You Can: Coverage-Guided RPKI Fuzzing at ScaleHaya Schulmann, Niklas Vogel. 2798-2814 [doi]
- The Fault in Our Drafts: Vulnerabilities in RPKI Specification and SoftwareOliver Jacobsen, Tobias Kirsch, Haya Schulmann, Niklas Vogel, Michael Waidner. 2815-2833 [doi]
- Camveil: Unveiling Security Camera Vulnerabilities Through Multi-Protocol Coordinated FuzzingFuchen Ma, Yuqiao Yang, Yuanliang Chen, Yanyang Zhao, Ting Chen 0002, Yu Jiang 0001. 2834-2849 [doi]
- Designing Transport-Level Encryption for Datacenter NetworksTianyi Gao 0001, Xinshu Ma, Suhas Narreddy, Eugenio Luo, Steven W. D. Chien, Michio Honda. 2850-2867 [doi]
- Fizzle: A Framework for Deterministic and Reproducible Network FuzzingNathaniel Bennett, Tyler Tucker, Carson Stillman, William Enck, Patrick Traynor, Kevin R. B. Butler. 2868-2884 [doi]
- The Battle of Metasurfaces: Understanding Security in Smart Radio EnvironmentsPaul Staat, Christof Paar, Swarun Kumar. 2885-2903 [doi]
- SatBleed: Security of Commoditized Communication Modules in SatellitesUlysse Planta, Julian Rederlechner, Martin Strohmeier, Mathias Fischer, Ali Abbasi 0002. 2904-2921 [doi]
- RIS-CLA: Reviving CSI-Based Continuous Location Authentication With Reconfigurable Intelligent SurfacesYan Zhang, Jiawei Li, Yizhou Wang, Dianqi Han, Yanchao Zhang, Aditya Shekhawat, Georgios Trichopoulos 0002. 2922-2937 [doi]
- MUSICSHIELD: Protection for Musicians in the Era of Generative AISyed Irfan Ali Meerza, Jian Liu 0001. 2938-2956 [doi]
- MAYA: Addressing Inconsistencies in Generative Password Guessing Through a Unified BenchmarkWilliam Corrias, Fabio De Gaspari, Dorjan Hitaj, Luigi V. Mancini. 2957-2976 [doi]
- Credential Extraction Attacks Against Compromised Credential Checking Services of Password ManagersYihe Duan, Ding Wang 0002, Yutong Li. 2977-2996 [doi]
- Can Foundation LLMs Accurately Estimate Password Strength and Provide Appropriate Password Feedback?Madison Pickering, Garrison Hinson-Hasty, Luca Dovichi, Helena Williams, Nathaniel Kim, Aybala Esmer, Blase Ur. 2997-3016 [doi]
- MoPE: A Mixture of Password Experts for Improving Password GuessingMingjian Duan, Ming Xu, Shenghao Zhang, Weili Han. 3017-3036 [doi]
- zkFuzz: Foundation and Framework for Effective Fuzzing of Zero-Knowledge CircuitsHideaki Takahashi, Jihwan Kim, Suman Jana, Junfeng Yang. 3055-3074 [doi]
- Single-Server Private Outsourcing of zk-SNARKsKasra Abbaszadeh, Hossein Hafezi, Jonathan Katz, Sarah Meiklejohn. 3075-3090 [doi]
- Language-Agnostic Detection of Computation-Constraint Inconsistencies in ZKP Programs Via Value InferenceArman Kolozyan, Bram Vandenbogaerde, Janwillem Swalens, Lode Hoste, Stefanos Chaliasos, Coen De Roover. 3091-3110 [doi]
- APEX: Accurate Parallel Expressive Homomorphic Execution for Encrypted DatabasesWei Chen 0161, Qi Hu, Siu-Ming Yiu, Heming Cui. 3111-3129 [doi]
- Secure Lookup Tables: Faster, Leaner, and More GeneralChongrong Li, Pengfei Zhu, Yun Li 0010, Zhanpeng Guo, Jingyu Li, Yuncong Hu, Zhicong Huang, Cheng Hong 0001. 3130-3149 [doi]
- Efficient Arithmetic-and-Comparison Homomorphic Encryption with Space SwitchingErwin Eko Wahyudi, Yan Solihin, Qian Lou. 3168-3184 [doi]
- Code-Based Scalable Collaborative SNARKsChristodoulos Pappas, Dimitrios Papadopoulos 0001, Charalampos Papamanthou. 3185-3203 [doi]
- Optimistic Asynchronous Dynamic-Committee Proactive Secret SharingBin Hu 0001, Jianwei Liu 0001, Zhenliang Lu, Qiang Tang 0005, Zhuolun Xiang, Zongyang Zhang. 3204-3222 [doi]
- Nebula: Proving Machine Executions via Folding SchemesArasu Arun, Srinath T. V. Setty. 3223-3242 [doi]
- Consistent Estimation of Numerical Distributions Under Local Differential Privacy by Wavelet ExpansionPuning Zhao, Zhikun Zhang 0001, Bo Sun, Li Shen 0008, Liang Zhang, Shaowei Wang 0003, Zhe Liu 0001. 3243-3261 [doi]
- Breaking the Barrier for Asynchronous MPC with a FriendBanashri Karmakar, Aniket Kate, Shravani Patil, Arpita Patra, Sikhar Patranabis, Protik Paul, Divya Ravi 0001. 3262-3280 [doi]
- Best of Both Worlds: Effective Foreign Bridge Identification in V8 Embedders for Security AnalysisGeorgios Alexopoulos, Thodoris Sotiropoulos, Zhendong Su 0001, Dimitris Mitropoulos. 3281-3300 [doi]
- Decor: Delegated Computation on Randomness for Secure Evaluation of Nonlinear FunctionsHaris Smajlovic, Kyle Sheng, Timos Antonopoulos, Ruzica Piskac, Hyunghoon Cho. 3301-3319 [doi]
- Bridge: High-Order Taint Vulnerabilities Detection in Linux-Based IoT FirmwareJiaqian Peng, Puzhuo Liu, Yicheng Zeng, Kai Cheng, Yongji Liu, Yun Yang, Hongsong Zhu. 3320-3339 [doi]
- SFA-Miner: Mining Path-Sensitive API Usage Patterns Via Symbolic Finite AutomataJiasheng Jiang, Mingwei Zheng, Qingkai Shi, Xiangyu Zhang 0001. 3340-3357 [doi]
- ENCHTABLE: Unified Safety Alignment Transfer in Fine-Tuned Large Language ModelsJialin Wu 0001, Kecen Li, Zhicong Huang, Xinfeng Li, Xiaofeng Wang 0001, Cheng Hong 0001. 3358-3376 [doi]
- QuickSafe: Targeted Hardening Against Memory CorruptionJohannes Blaser, Floris Gorter, Klaus von Gleissenthall, Herbert Bos. 3377-3395 [doi]
- SpecAuditor: Generating Audit Specifications for LLM-Driven Bug DetectionMiaoqian Lin, Hao Chen. 3396-3413 [doi]
- BACHunter: Detecting Broken Access Control Vulnerabilities in Intelligent Connected VehiclesYanbang Sun, Xiaohong Li 0001, Quanzhou Wang, Hebo Leng, Guangzheng Yao, Zhihua Xie, Qiang Hu, Junjie Wang 0007. 3414-3432 [doi]
- Oxidizer: Toward Concise and High-fidelity Rust DecompilationYibo Liu, Zion Leonahenahe Basque, Arvind S. Raj, Chavin Udomwongsa, Chang Zhu, Jie Hu 0031, Changyu Zhao, Fangzhou Dong, Adam Doupé, Tiffany Bao, Yan Shoshitaishvili, Ruoyu Wang 0001. 3433-3451 [doi]
- NanoTag: Systems Support for Efficient Byte-Granular Overflow Detection on ARM MTEMingkai Li, Hang Ye 0010, Joseph Devietti, Suman Jana, Tanvir Ahmed Khan 0001. 3452-3470 [doi]
- Parasol Compiler: Pushing the Boundaries of FHE Program EfficiencyRick Weber, Ryan Orendorff, Ghada Almashaqbeh, Ravital Solomon. 3471-3489 [doi]
- The First Large-Scale Systematic Study of Python Class Pollution VulnerabilityZhengyu Liu, Jiacheng Zhong, Jianjia Yu, Muxi Lyu, Zifeng Kang, Yinzhi Cao. 3490-3508 [doi]
- Cottontail: Large Language Model-Driven Concolic Execution for Highly Structured Test Input GenerationHaoxin Tu, Seongmin Lee 0001, Yuxian Li, Peng Chen, Lingxiao Jiang, Marcel Böhme. 3509-3527 [doi]
- Catch Me If You Can: Detector-Resistant Evasion via Semantics-Preserving Command Re-RealizationMuhammad Shoaib, Hare Sudhan Muthusamy, Tareq Alkhatib, Wajih Ul Hassan. 3528-3547 [doi]
- INSIGHT: Automatic Generation of Explanations for Efficient Identification of Hardware Bugs and UnderspecificationsVincent Quentin Ulitzsch, Alessandro Bertani, Peter W. Deutsch, David Langus Rodriguez, Kelly Xu, Aarti Gupta, Sharad Malik, Mengjia Yan 0001. 3548-3566 [doi]
- Interplay of Efficient Model Checking and Secure Processor Design: A Case Study on Secure SpeculationTingzhen Dong, Qinhan Tan, Kunpeng Wang, Thomas Bourgeat, Yuheng Yang, Sharad Malik, Yu-Wei Fan, Mengjia Yan 0001. 3567-3586 [doi]
- CiRCLE: Recovering Complex Data Structures in Binaries Beyond FragmentationZeyu Gao, Junlin Zhou, Songtao Yang 0001, Chao Zhang 0008. 3587-3606 [doi]
- No Password, No Problem? A Large-Scale Field Study of Passkey Adoption and UsageTobias Reittinger, Günther Pernul. 3607-3626 [doi]
- Usable Anonymity in Reproductive Health PrivacyQiurong Song, Yanlai Wu, Rie Helene Hernandez, Yao Li 0006, Yubo Kou, Xinning Gui. 3627-3646 [doi]
- The Passkey Promise: A Comparative Usability Study of MFA MethodsErwin Kupris, Thomas Schreck. 3647-3666 [doi]
- 2FiA: Towards WiFi Sensing-Based Authentication with Unique BiometricsBofan Li, Zhankai Ye, Weikuan Yu, Yongning Tang, Liu Xiu. 3667-3683 [doi]
- SmuFuzz: Enable Deep System Management Mode Fuzzing in Fully Featured UEFI Runtime EnvironmentJianqiang Wang, Yi Xiang, Meng Wang 0071, Qinying Wang, Ali Abbasi 0002, Thorsten Holz. 3702-3719 [doi]
- Jazzer: Coverage-Guided Fuzzing for Semantic Vulnerabilities in the Java EcosystemSergej Dechand, Tobias Wienand, Fabian Meumertzheim, Peter Samarin, Simon Resch, Khaled Yakdan, Thorsten Holz, Flavio Toffalini. 3720-3739 [doi]
- Beyond Nodes vs. Edges: A Multi-View Fusion Framework for Provenance-Based Intrusion DetectionFan Yang, Binyan Xu, Di Tang 0001, Kehuan Zhang. 3739-3758 [doi]
- Specializing Language Models for Textual Fuzzing via Reinforcement LearningJiayi Lin 0007, LiangCai Su, Junzhe Li, Chenxiong Qian. 3740-3756 [doi]
- PILOT: Command-Line Interface Fuzzing Via Path-Guided, Iterative Large Language Model PromptingMomoko Shiraishi, Yinzhi Cao, Takahiro Shinagawa. 3757-3775 [doi]
- Contextualizing Sink Knowledge for Java Vulnerability DiscoveryFabian Fleischer 0001, Cen Zhang, Joonun Jang, Jeongin Cho, Meng Xu, Taesoo Kim. 3776-3795 [doi]
- deepSURF: Detecting Memory Safety Vulnerabilities in Rust Through Fuzzing LLM-Augmented HarnessesGeorgios C. Androutsopoulos, Antonio Bianchi. 3796-3815 [doi]
- CenRL: A Framework for Performing Intelligent Censorship MeasurementsHieu Le, Armin Huremagic, Kevin Wang, Roya Ensafi, Ram Sundara Raman. 3816-3834 [doi]
- Prrr: Personal Random Rewards for Blockchain ReportingHongyin Chen, Yubin Ke, Xiaotie Deng, Ittay Eyal. 3835-3853 [doi]
- CenAlert: Amplifying User Voices to Rally Censorship InvestigationAaron Ortwein, Anna Ablove, Armin Huremagic, Luqin Chang, Vinicius Fortuna, Roya Ensafi. 3854-3872 [doi]
- Promoguardian: Detecting Promotion Abuse Fraud with Multi-Relation Fused Graph Neural NetworksShaofei Li, Xiao Han, Ziqi Zhang, Minyao Hua, Shuli Gao, Zhenkai Liang, Yao Guo 0001, Xiangqun Chen, Ding Li 0001. 3873-3890 [doi]
- Hidden Secrets in the arXiv: Discovering, Analyzing, and Preventing Unintentional Information Disclosure in Source Files of Scientific PreprintsJan Pennekamp, Johannes Lohmöller, David Schütte, Joscha Loos, Martin Henze. 3891-3910 [doi]
- Revelio: Blurred Images Can Still Disclose Your IdentityHaoyu Zhai, Shuo Wang, Pirouz Naghavi, Qingying Hao, Gang Wang 0011. 3911-3929 [doi]
- Fine-Grained Kernel Auditing Using Augmented Syscall Reference Behavior Analysis and Virtualized Selective TracingChuqi Zhang, Spencer Faith, Feras Al-Qassas, Theodorus Februanto, Zhenkai Liang, Adil Ahmad. 3930-3948 [doi]
- Fractal: An Operating System Designed for Microarchitecture Reverse EngineeringJoseph Ravichandran, Mengjia Yan 0001. 3949-3964 [doi]
- Stop Starving or Stuffing Me: Boosting Firmware Fuzzing Efficiency with On-Demand Input DeliveryShandian Shen, Wei Zhou 0026, Keming Zhao, Peng Liu 0005, Chung Hwan Kim, Le Guan. 3965-3983 [doi]
- PufferDoS: Efficient and Effective Attack String Generation for Regular Expression Denial of Service VulnerabilitiesShangzhi Xu, Ziqi Ding, Xiao Cheng, Yuekang Li, Nan Sun 0002, Benjamin Turnbull, Shuangxiang Kan, Siqi Ma 0001. 3984-4002 [doi]
- HEAP LOCALIZATION: Cache Side-Channel Based Linux Kernel Heap Exploit TechniquesYoochan Lee, Sihyun Roh, Hyuk Kwon, Byoungyoung Lee, Thorsten Holz. 4003-4019 [doi]
- NetPanic: the Attack Surface You Can't SyscallTianshuo Han, Zong Cao, Zhen Dong, Xiapu Luo, Zhenyu Song, Jian Liu. 4020-4035 [doi]
- APIECHO: Training-Less Anomaly Detection via Intra-API Behavioral Comparison for Web ApplicationsYihao Peng, Yiming Wu 0009, Du Wu, Shouling Ji, Hai Wan, Xibin Zhao. 4072-4088 [doi]
- PortGPT: Towards Automated Backporting Using Large Language ModelsZhaoyang Li, Zheng Yu, Jingyi Song, Meng Xu, Yuxuan Luo, Dongliang Mu. 4089-4108 [doi]
- Behind the Curtain: How Shared Hosting Providers Respond to Vulnerability NotificationsGiada Stivala, Rafael Mrowczynski, Maria Hellenthal, Giancarlo Pellegrino. 4109-4127 [doi]
- TRIGFUZZ: Triggering Conditions Guided Directed FuzzingYiyang Chen, Nuoqi Gui, Long Wang, Longfei Chen, Xuanqing Shi, Xi Cao, Chao Zhang 0008. 4128-4146 [doi]
- Death Is Not the End: a Longitudinal Study on the Impact of Automatic Updates on Container Vulnerability LifespansSimge Tekin, Octavian Suciu, Sungsu Kwag, Yonghwi Kwon 0001, Tudor Dumitras. 4147-4164 [doi]
- Web Application Vulnerability Repair Via Context-Aware Fault Localization and Directed Differential FuzzingChenlin Wang, Wei Meng. 4165-4184 [doi]
- Papers, Please: A First Look at Age Verification on the WebShreyas Minocha, Isaac Sheridan, Harry Oppenheimer, Paul Pearce, Michael A. Specter. 4185-4202 [doi]
- Who Taught the Lie? Responsibility Attribution for Poisoned Knowledge in Retrieval-Augmented GenerationBaolei Zhang, Haoran Xin 0002, Yuxi Chen, Zhuqing Liu, Biao Yi, Tong Li 0011, Lihai Nie, Zheli Liu, Minghong Fang. 4203-4222 [doi]
- When AI Meets the Web: Prompt Injection Risks in Third-Party AI Chatbot PluginsYigitcan Kaya, Anton Landerer, Stijn Pletinckx, Michelle Zimmermann, Christopher Kruegel, Giovanni Vigna. 4223-4242 [doi]
- PromptLocate: Localizing Prompt Injection AttacksYuqi Jia, Yupei Liu, Zedian Shao, Jinyuan Jia 0001, Neil Zhenqiang Gong. 4243-4261 [doi]
- LLMs in the SOC: An Empirical Study of Human-AI Collaboration in Security Operations CentresRonal Singh, Shahroz Tariq, Fatemeh Jalalvand, Mohan Baruwal Chhetri, Surya Nepal, Cécile Paris, Martin Lochner. 4262-4281 [doi]
- Incalmo: an Autonomous Llm-Assisted System for Red Teaming Multi-Host NetworksBrian Singer, Keane Lucas, Lakshmi Adiga, Meghna Jain, Lujo Bauer, Vyas Sekar. 4282-4300 [doi]
- PromptCOS: Towards Content-Only System Prompt Copyright Auditing for LLMsYuchen Yang, Yiming Li 0004, Hongwei Yao, Enhao Huang, Shuo Shao 0002, Yuyi Wang, Zhibo Wang 0001, Dacheng Tao, Zhan Qin. 4301-4319 [doi]
- AttnTrace: Contextual Attribution of Prompt Injection and Knowledge CorruptionYanting Wang 0001, Runpeng Geng, Ying Chen, Jinyuan Jia 0001. 4320-4338 [doi]
- Hollow-LLM Attack: Computationally Trivial Weights in Zero-Knowledge Verification of LLM InferenceChen Gong, Beijie Liu, Mengyuan Li 0004. 4339-4355 [doi]
- Leafblower: a Leakage Attack Against Tee-Based Encrypted DatabasesZachary Espiritu, Seny Kamara, Tarik Moataz, Valentin Ogier. 4356-4375 [doi]
- AEX-NStep: Probabilistic Interrupt Counting Attacks on Intel SGXNicolas Dutly, Friederike Groschupp, Ivan Puddu, Kari Kostiainen, Srdjan Capkun. 4376-4390 [doi]
- Battering RAM: Low-Cost Interposer Attacks on Confidential Computing via Dynamic Memory AliasingJesse De Meulemeester, David F. Oswald, Ingrid Verbauwhede, Jo Van Bulck. 4391-4407 [doi]
- TEE.Fail: Breaking Trusted Execution Environments via DDR5 Memory Bus InterpositionJalen Chuang, Alexander Seto, Nicolás Berrios, Stephan van Schaik, Christina Garman, Daniel Genkin. 4408-4426 [doi]
- PrintSpy: Pixel-Level Eavesdropping on Commodity Laser Printers via Electromagnetic Side ChannelsWenhao Li 0008, Jiarong Yang, Mingda Han, Xiuzhen Cheng, Pengfei Hu 0001, Cong Wang. 4427-4444 [doi]
- TÄMU: Emulating Trusted Applications at the (GlobalPlatform)-API LayerPhilipp Mao, Li Shi, Marcel Busch, Mathias Payer. 4445-4460 [doi]
- Goldilocks and the Three P-States: Mitigating Hertzbleed with Formal Leakage GuaranteesInwhan Chun, Christine Guo, Riccardo Paccagnella. 4461-4478 [doi]
- TDXRay: Microarchitectural Side-Channel Analysis of Intel TDX for Real-World WorkloadsTristan Hornetz, Hosein Yavarzadeh, Albert Cheu, Adrià Gascón, Lukas Gerlach 0001, Daniel Moghimi, Phillipp Schoppmann, Michael Schwarz 0001, Ruiyi Zhang 0001. 4479-4496 [doi]
- Investigating the Impact of Dark Patterns on LLM-Based Web AgentsDevin Ersoy, Brandon Lee, Ananth Shreekumar, Arjun Arunasalam, Muhammad Ibrahim 0004, Antonio Bianchi, Z. Berkay Celik. 4497-4516 [doi]
- Demystifying the (In)Security of Oauth-Based Account Linking in Connector EcosystemsKaixuan Luo, Xianbo Wang, Adonis P. H. Fung, Wing Cheong Lau. 4517-4536 [doi]
- When Designers Meet GenAI: Understanding the Role of Prompt-to-Design Generators in Privacy Dark PatternsJingzhou Ye, Zhaojie Hu, Yao Li, Xueqiang Wang. 4537-4556 [doi]
- SoK: After Decades of Web Tracker Detection, What's Next?Wolf Rieder, Philip Raschke, Thomas Cory, Christian René Sechting, Aditya Kumar, Axel Küpper. 4557-4582 [doi]
- Your Eyes Won't Lie: Snooping Online Voting Privacy from User WebcamZeyu Deng, Jingwei Zhang, Chen Wang. 4583-4599 [doi]
- Weaponizing Reflectivity for Pointcloud Deception with Forged Invisible GeometriesHengwei Chen, Menglan Hu, Tianyue Zheng. 4618-4635 [doi]
- PLaTypus: Restricting Cross-Module Transitions to Mitigate Code-Reuse AttacksApostolos Chatzianagnostou, Marcos Bajo, Christian Rossow. 4636-4655 [doi]
- Crashing Through Defenses: Exploiting Segfaults and Chaining Around Intel CETMarcos Bajo, Ritvik Goyal, Apostolos Chatzianagnostou, Christian Rossow. 4656-4675 [doi]
- BreakFAST: Confused Deputy Attack on Infinity Fabric to Break AMD SEV-SNPPhilipp Giersfeld, Benedict Schlüter, Shweta Shinde. 4676-4692 [doi]
- One Char to Rule Them All: Systematically Exploring and Exploiting DNS Silent Vulnerabilities in Domain Name ResolutionFasheng Miao, Xiang Li 0108, Changqing An, Wenbin Xu, Jilong Wang 0001. 4693-4712 [doi]
- Resolve the Unresolved: Systematic Work Profiling for DNS ResolversLiwen Xu, Huayi Duan, Zechao Cai, Adrian Perrig. 4713-4729 [doi]
- Poisoned by the Host: Large-Scale Measurement of Host Name Poisoning in Web ApplicationsRui Yang, Haoyu Wang, Zhicheng Sun, Zhengyu Liu, Yinzhi Cao. 4730-4748 [doi]
- Knocking on the Front Door: An LLM-Guided Systematic Analysis of DNS Query Processing VulnerabilitiesYuqi Qiu, Xiang Li 0108, Zheli Liu. 4749-4768 [doi]
- APT to Disagree: A Comparative Analysis of Attribution in Commercial TIAksel Ethembabaoglu, Rolf van Wegberg, Yury Zhauniarovich, Michel van Eeten. 4769-4787 [doi]