| 2025 | NDSS | Density Boosts Everything: A One-stop Strategy for Improving Performance, Robustness, and Sustainability of Malware Detectors. | Jianwen Tian, Wei Kong, Debin Gao, Tong Wang, Taotao Gu, Kefan Qiu, Zhi Wang, Xiaohui Kuang |
| 2024 | ICSE | MiniMon: Minimizing Android Applications with Intelligent Monitoring-Based Debloating. | Jiakun Liu, Zicheng Zhang, Xing Hu, Ferdian Thung, Shahar Maoz, Debin Gao, Eran Toch, Zhipeng Zhao, David Lo |
| 2024 | ICSE | Beyond a Joke: Dead Code Elimination Can Delete Live Code. | Haoxin Tu, Lingxiao Jiang, Debin Gao, He Jiang |
| 2024 | TrustCom | Custom Permission Misconfigurations in Android: A Large-Scale Security Analysis. | Rui Li, Wenrui Diao, Debin Gao |
| 2023 | ACISP | BinAlign: Alignment Padding Based Compiler Provenance Recovery. | Maliha Ismail, Yan Lin, DongGyun Han, Debin Gao |
| 2023 | CCS | TypeSqueezer: When Static Recovery of Function Signatures for Binary Executables Meets Dynamic Analysis. | Ziyi Lin, Jinku Li, Bowen Li, Haoyu Ma, Debin Gao, Jianfeng Ma |
| 2022 | ICSE | UIPDroid: Unrooted Dynamic Monitor of Android App UIs for Fine-Grained Permission Control. | Mulin Duan, Lingxiao Jiang, Lwin Khin Shar, Debin Gao |
| 2022 | NDSS | Chosen-Instruction Attack Against Commercial Code Virtualization Obfuscators. | Shijia Li, Chunfu Jia, Pengda Qiu, Qiyuan Chen, Jiang Ming, Debin Gao |
| 2021 | DSN | When Program Analysis Meets Bytecode Search: Targeted and Efficient Inter-procedural Analysis of Modern Android Apps in BackDroid. | Daoyuan Wu, Debin Gao, Robert H. Deng, Rocky K. C. Chang |
| 2021 | SP | When Function Signature Recovery Meets Compiler Optimization. | Yan Lin, Debin Gao |
| 2019 | ACNS | DynOpVm: VM-Based Software Obfuscation with Dynamic Opcode Mapping. | Xiaoyang Cheng, Yan Lin, Debin Gao, Chunfu Jia |
| 2019 | CCS | Control-Flow Carrying Code. | Yan Lin, Xiaoyang Cheng, Debin Gao |
| 2019 | CCS | Towards Understanding Android System Vulnerabilities: Techniques and Insights. | Daoyuan Wu, Debin Gao, Eric K. T. Cheng, Yichen Cao, Jintao Jiang, Robert H. Deng |
| 2019 | IWQoS | An empirical study of mobile network behavior and application performance in the wild. | Shiwei Zhang, Weichao Li, Daoyuan Wu, Bo Jin, Rocky K. C. Chang, Debin Gao, Yi Wang, Ricky K. P. Mok |
| 2019 | NDSS | Understanding Open Ports in Android Applications: Discovery, Diagnosis, and Security Assessment. | Daoyuan Wu, Debin Gao, Rocky K. C. Chang, En He, Eric K. T. Cheng, Robert H. Deng |
| 2019 | PST | SplitSecond: Flexible Privilege Separation of Android Apps. | Jehyun Lee, Akshaya Venkateswara Raja, Debin Gao |
| 2018 | ICECCS | Towards Mining Comprehensive Android Sandboxes. | Tien-Duy B. Le, Lingfeng Bao, David Lo, Debin Gao, Li Li |
| 2017 | ACISP | SafeStack ^+ : Enhanced Dual Stack to Combat Data-Flow Hijacking. | Yan Lin, Xiaoxiao Tang, Debin Gao |
| 2017 | ESORICS | On-Demand Time Blurring to Support Side-Channel Defense. | Weijie Liu, Debin Gao, Michael K. Reiter |
| 2017 | PST | On Return Oriented Programming Threats in Android Runtime. | Akshaya Venkateswara Raja, Jehyun Lee, Debin Gao |
| 2017 | USENIX | MopEye: Opportunistic Monitoring of Per-app Mobile Network Performance. | Daoyuan Wu, Rocky K. C. Chang, Weichao Li, Eric K. T. Cheng, Debin Gao |
| 2016 | CCS | MobiPot: Understanding Mobile Telephony Threats with Honeycards. | Marco Balduzzi, Payas Gupta, Lion Gu, Debin Gao, Mustaque Ahamad |
| 2016 | ICISC | On the Effectiveness of Code-Reuse-Based Android Application Obfuscation. | Xiaoxiao Tang, Yu Liang, Xinjie Ma, Yan Lin, Debin Gao |
| 2015 | CCS | Software Watermarking using Return-Oriented Programming. | Haoyu Ma, Kangjie Lu, Xinjie Ma, Haining Zhang, Chunfu Jia, Debin Gao |
| 2015 | ICDCS | Replica Placement for Availability in the Worst Case. | Peng Li, Debin Gao, Michael K. Reiter |
| 2015 | ICISC | Stack Layout Randomization with Minimal Rewriting of Android Binaries. | Yu Liang, Xinjie Ma, Daoyuan Wu, Xiaoxiao Tang, Debin Gao, Guojun Peng, Chunfu Jia, Huanguo Zhang |
| 2014 | SecureComm | Control Flow Obfuscation Using Neural Network to Fight Concolic Testing. | Haoyu Ma, Xinjie Ma, Weijie Liu, Zhipeng Huang, Debin Gao, Chunfu Jia |
| 2013 | ACNS | Launching Generic Attacks on iOS with Approved Third-Party Applications. | Jin Han, Su Mon Kywe, Qiang Yan, Feng Bao, Robert H. Deng, Debin Gao, Yingjiu Li, Jianying Zhou |
| 2013 | ACNS | Keystroke Timing Analysis of on-the-fly Web Apps. | Chee Meng Tey, Payas Gupta, Debin Gao, Yan Zhang |
| 2013 | CCS | Your love is public now: questioning the use of personal information in authentication. | Payas Gupta, Swapna Gottipati, Jing Jiang, Debin Gao |
| 2013 | DSN | Mitigating access-driven timing channels in clouds using StopWatch. | Peng Li, Debin Gao, Michael K. Reiter |
| 2013 | ICICS | Defending against Heap Overflow by Using Randomization in Nested Virtual Clusters. | Chee Meng Tey, Debin Gao |
| 2013 | NDSS | Comparing Mobile Privacy Protection through Cross-Platform Applications. | Jin Han, Qiang Yan, Debin Gao, Jianying Zhou, Robert H. Deng |
| 2013 | NDSS | I can be You: Questioning the use of Keystroke Dynamics as Biometrics. | Chee Meng Tey, Payas Gupta, Debin Gao |
| 2012 | AAMAS | Active malware analysis using stochastic games. | Simon Andrew Williamson, Pradeep Varakantham, Ong Chen Hui, Debin Gao |
| 2012 | CCS | Coercion resistance in authentication responsibility shifting. | Payas Gupta, Xuhua Ding, Debin Gao |
| 2012 | CCS | OTO: online trust oracle for user-centric trust establishment. | Tiffany Hyun-Jin Kim, Payas Gupta, Jun Han, Emmanuel Owusu, Jason I. Hong, Adrian Perrig, Debin Gao |
| 2012 | ICISC | iBinHunt: Binary Hunting with Inter-procedural Control Flow. | Jiang Ming, Meng Pan, Debin Gao |
| 2012 | PERCOM | HuMan: Creating memorable fingerprints of mobile users. | Payas Gupta, Tan Kiat Wee, Narayan Ramasubbu, David Lo, Debin Gao, Rajesh Krishna Balan |
| 2011 | ACSAC | deRop: removing return-oriented programming from malware. | Kangjie Lu, Dabi Zou, Weiping Wen, Debin Gao |
| 2011 | ESORICS | Linear Obfuscation to Combat Symbolic Execution. | Zhi Wang, Jiang Ming, Chunfu Jia, Debin Gao |
| 2011 | NSS | Towards ground truthing observations in gray-box anomaly detection. | Jiang Ming, Haibin Zhang, Debin Gao |
| 2011 | RAID | Packed, Printable, and Polymorphic Return-Oriented Programming. | Kangjie Lu, Dabi Zou, Weiping Wen, Debin Gao |
| 2011 | TrustCom | Launching Return-Oriented Programming Attacks against Randomized Relocatable Executables. | Limin Liu, Jin Han, Debin Gao, Jiwu Jing, Daren Zha |
| 2011 | SecureComm | On Detection of Erratic Arguments. | Jin Han, Qiang Yan, Robert H. Deng, Debin Gao |
| 2010 | ACSAC | A multi-user steganographic file system on untrusted shared storage. | Jin Han, Meng Pan, Debin Gao, HweeHwa Pang |
| 2010 | ICISC | Revisiting Address Space Randomization. | Zhi Wang, Renquan Cheng, Debin Gao |
| 2010 | RAID | On Challenges in Evaluating Malware Clustering. | Peng Li, Limin Liu, Debin Gao, Michael K. Reiter |
| 2009 | DIMVA | On the Effectiveness of Software Diversity: A Systematic Study on Real-World Vulnerabilities. | Jin Han, Debin Gao, Robert H. Deng |
| 2009 | ICICS | Denial-of-Service Attacks on Host-Based Generic Unpackers. | Limin Liu, Jiang Ming, Zhi Wang, Debin Gao, Chunfu Jia |
| 2009 | RAID | Automatically Adapting a Trained Anomaly Detector to Software Patches. | Peng Li, Debin Gao, Michael K. Reiter |
| 2008 | ACSAC | Bridging the Gap between Data-Flow and Control-Flow Analysis for Anomaly Detection. | Peng Li, Hyundo Park, Debin Gao, Jianming Fu |
| 2008 | ICICS | BinHunt: Automatically Finding Semantic Differences in Binary Programs. | Debin Gao, Michael K. Reiter, Dawn Xiaodong Song |
| 2006 | RAID | Behavioral Distance Measurement Using Hidden Markov Models. | Debin Gao, Michael K. Reiter, Dawn Xiaodong Song |
| 2005 | RAID | Behavioral Distance for Intrusion Detection. | Debin Gao, Michael K. Reiter, Dawn Xiaodong Song |
| 2004 | CCS | Gray-box extraction of execution graphs for anomaly detection. | Debin Gao, Michael K. Reiter, Dawn Xiaodong Song |