| 2026 | ACNS | Deception by Design: A Configurable Platform for Flexible Cyber Deception Strategy Testing and Evaluation. | Sukwha Kyung, Souradip Nath, Jaejong Baek, Gail-Joon Ahn |
| 2026 | SACMAT | Towards Agentic AI for Access Control in Cyber-infrastructures: Exploring the Security and Human Factors: [BlueSky Paper]. | Carlos E. Rubio-Medrano, Souradip Nath, Ananta Soneji, Jennifer Mondragon, Jaejong Baek, Gail-Joon Ahn |
| 2026 | SOUPS | Like a Hammer, It Can Build, It Can Break: Large Language Model Uses, Perceptions, and Adoption in Cybersecurity Operations on Reddit. | Souradip Nath, Chih-Yi Huang, Aditi Ganapathi, Kashyap Thimmaraju, Jaron Mink, Gail-Joon Ahn |
| 2025 | NDSS | SCAMMAGNIFIER: Piercing the Veil of Fraudulent Shopping Website Campaigns. | Marzieh Bitaab, Alireza Karimi, Zhuoer Lyu, Adam Oest, Dhruv Kuchhal, Muhammad Saad, Gail-Joon Ahn, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, Adam Doup |
| 2025 | PRDC | Dependable Code Repair with LLMs: AI-Driven Vulnerability Detection and Automated Patching. | Sungmin Han, Hyoungshick Kim, Hojoon Lee, Hyungon Moon, Yuseok Jeon, Ho Bae, Donghyun Yeo, Gail-Joon Ahn, Sangkyun Lee |
| 2025 | SP | "It's almost like Frankenstein": Investigating the Complexities of Scientific Collaboration and Privilege Management within Research Computing Infrastructures. | Souradip Nath, Ananta Soneji, Jaejong Baek, Tiffany Bao, Adam Doup, Carlos E. Rubio-Medrano, Gail-Joon Ahn |
| 2024 | RAID | From Victims to Defenders: An Exploration of the Phishing Attack Reporting Ecosystem. | Zhibo Sun, Faris Bugra Kokulu, Penghui Zhang, Adam Oest, Gianluca Stringhini, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, Adam Doup, Gail-Joon Ahn |
| 2024 | SP | "Watching over the shoulder of a professional": Why Hackers Make Mistakes and How They Fix Them. | Irina Ford, Ananta Soneji, Faris Bugra Kokulu, Jayakrishna Vadayath, Zion Leonahenahe Basque, Gaurav Vipat, Adam Doup, Ruoyu Wang, Gail-Joon Ahn, Tiffany Bao, Yan Shoshitaishvili |
| 2023 | DSN | Targeted Privacy Attacks by Fingerprinting Mobile Apps in LTE Radio Layer. | Jaejong Baek, Pradeep Kumar Duraisamy Soundrapandian, Sukwha Kyung, Ruoyu Wang, Yan Shoshitaishvili, Adam Doup, Gail-Joon Ahn |
| 2023 | SACMAT | SpaceMediator: Leveraging Authorization Policies to Prevent Spatial and Privacy Attacks in Mobile Augmented Reality. | Luis Claramunt, Carlos E. Rubio-Medrano, Jaejong Baek, Gail-Joon Ahn |
| 2022 | ASPLOS | ViK: practical mitigation of temporal memory safety violations through object ID inspection. | Haehyun Cho, Jinbum Park, Adam Oest, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, Adam Doup, Gail-Joon Ahn |
| 2022 | CCS | I'm SPARTACUS, No, I'm SPARTACUS: Proactively Protecting Users from Phishing by Intentionally Triggering Cloaking Behavior. | Penghui Zhang, Zhibo Sun, Sukwha Kyung, Hans Walter Behrens, Zion Leonahenahe Basque, Haehyun Cho, Adam Oest, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, Gail-Joon Ahn, Adam Doup |
| 2021 | AsiaCCS | Security Analysis on Practices of Certificate Authorities in the HTTPS Phishing Ecosystem. | Doowon Kim, Haehyun Cho, Yonghwi Kwon, Adam Doup, Sooel Son, Gail-Joon Ahn, Tudor Dumitras |
| 2021 | NDSS | Favocado: Fuzzing the Binding Code of JavaScript Engines Using Semantically Correct Test Cases. | Sung Ta Dinh, Haehyun Cho, Kyle Martin, Adam Oest, Kyle Zeng, Alexandros Kapravelos, Gail-Joon Ahn, Tiffany Bao, Ruoyu Wang, Adam Doup, Yan Shoshitaishvili |
| 2021 | SP | CrawlPhish: Large-scale Analysis of Client-side Cloaking Techniques in Phishing. | Penghui Zhang, Adam Oest, Haehyun Cho, Zhibo Sun, RC Johnson, Brad Wardman, Shaown Sarker, Alexandros Kapravelos, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, Adam Doup, Gail-Joon Ahn |
| 2020 | CCS | HoneyPLC: A Next-Generation Honeypot for Industrial Control Systems. | Efrn Lpez-Morales, Carlos E. Rubio-Medrano, Adam Doup, Yan Shoshitaishvili, Ruoyu Wang, Tiffany Bao, Gail-Joon Ahn |
| 2020 | Mobisys | SmokeBomb: effective mitigation against cache side-channel attacks on the ARM architecture. | Haehyun Cho, Jinbum Park, Donguk Kim, Ziming Zhao, Yan Shoshitaishvili, Adam Doup, Gail-Joon Ahn |
| 2020 | SACMAT | Proactive Risk Assessment for Preventing Attribute-Forgery Attacks to ABAC Policies. | Carlos E. Rubio-Medrano, Luis Claramunt, Shaishavkumar Jogani, Gail-Joon Ahn |
| 2019 | CCS | Matched and Mismatched SOCs: A Qualitative Study on Security Operations Center Issues. | Faris Bugra Kokulu, Ananta Soneji, Tiffany Bao, Yan Shoshitaishvili, Ziming Zhao, Adam Doup, Gail-Joon Ahn |
| 2019 | SAC | iCore: continuous and proactive extrospection on multi-core IoT devices. | Penghui Zhang, Haehyun Cho, Ziming Zhao, Adam Doup, Gail-Joon Ahn |
| 2019 | SP | PhishFarm: A Scalable Framework for Measuring the Effectiveness of Evasion Techniques against Browser Phishing Blacklists. | Adam Oest, Yeganeh Safaei, Adam Doup, Gail-Joon Ahn, Brad Wardman, Kevin Tyers |
| 2019 | SACMAT | Effectively Enforcing Authorization Constraints for Emerging Space-Sensitive Technologies. | Carlos E. Rubio-Medrano, Shaishavkumar Jogani, Maria Leitner, Ziming Zhao, Gail-Joon Ahn |
| 2018 | ACSAC | Wi Not Calling: Practical Privacy and Availability Attacks in Wi-Fi Calling. | Jaejong Baek, Sukwha Kyung, Haehyun Cho, Ziming Zhao, Yan Shoshitaishvili, Adam Doup, Gail-Joon Ahn |
| 2018 | ACSAC | Prime+Count: Novel Cross-world Covert Channels on ARM TrustZone. | Haehyun Cho, Penghui Zhang, Donguk Kim, Jinbum Park, Choong-Hoon Lee, Ziming Zhao, Adam Doup, Gail-Joon Ahn |
| 2018 | CCS | AIM-SDN: Attacking Information Mismanagement in SDN-datastores. | Vaibhav Hemant Dixit, Adam Doup, Yan Shoshitaishvili, Ziming Zhao, Gail-Joon Ahn |
| 2018 | CCS | CacheLight: Defeating the CacheKit Attack. | Mauricio Gutierrez, Ziming Zhao, Adam Doup, Yan Shoshitaishvili, Gail-Joon Ahn |
| 2018 | CCS | vNIDS: Towards Elastic Security with Safe and Efficient Virtualization of Network Intrusion Detection Systems. | Hongda Li, Hongxin Hu, Guofei Gu, Gail-Joon Ahn, Fuqiang Zhang |
| 2018 | CHASE | The Danger of Missing Instructions: A Systematic Analysis of Security Requirements for MCPS. | Josephine Lamp, Carlos E. Rubio-Medrano, Ziming Zhao, Gail-Joon Ahn |
| 2018 | SAC | Measuring E-mail header injections on the world wide web. | Sai Prashanth Chandramouli, Pierre-Marie Bajan, Christopher Kruegel, Giovanni Vigna, Ziming Zhao, Adam Doup, Gail-Joon Ahn |
| 2017 | CCS | Mutated Policies: Towards Proactive Attribute-based Defenses for Access Control. | Carlos E. Rubio-Medrano, Josephine Lamp, Adam Doup, Ziming Zhao, Gail-Joon Ahn |
| 2017 | NDSS | On the Safety and Efficiency of Virtual Firewall Elasticity Control. | Juan Deng, Hongda Li, Hongxin Hu, Kuang-Ching Wang, Gail-Joon Ahn, Ziming Zhao, Wonkyu Han |
| 2017 | SACMAT | Poster: On the Safety and Efficiency of Virtual Firewall Elasticity Control. | Hongda Li, Juan Deng, Hongxin Hu, Kuang-Ching Wang, Gail-Joon Ahn, Ziming Zhao, Wonkyu Han |
| 2017 | SACMAT | Towards PII-based Multiparty Access Control for Photo Sharing in Online Social Networks. | Nishant Vishwamitra, Yifang Li, Kevin Wang, Hongxin Hu, Kelly Caine, Gail-Joon Ahn |
| 2017 | SecureComm | Defining and Detecting Environment Discrimination in Android Apps. | Yunfeng Hong, Yongjian Hu, Chun-Ming Lai, Shyhtsun Felix Wu, Iulian Neamtiu, Patrick D. McDaniel, Paul L. Yu, Hasan Cam, Gail-Joon Ahn |
| 2016 | CCS | Checking Intent-based Communication in Android with Intent Space Analysis. | Yiming Jing, Gail-Joon Ahn, Adam Doup, Jeong Hyun Yi |
| 2016 | IRI | Understanding Anti-forensic Techniques with Timestamp Manipulation (Invited Paper). | Dae-il Jang, Gail-Joon Ahn, Hyunuk Hwang, Kibom Kim |
| 2016 | SP | SoK: Everyone Hates Robocalls: A Survey of Techniques Against Telephone Spam. | Huahong Tu, Adam Doup, Ziming Zhao, Gail-Joon Ahn |
| 2016 | SACMAT | State-aware Network Access Management for Software-Defined Networks. | Wonkyu Han, Hongxin Hu, Ziming Zhao, Adam Doup, Gail-Joon Ahn, Kuang-Ching Wang, Juan Deng |
| 2015 | CCS | ACTRA: A Case Study for Threat Information Sharing. | Jon C. Haass, Gail-Joon Ahn, Frank Grimmelmann |
| 2015 | IRI | Toward a Moving Target Defense for Web Applications. | Marthony Taguinod, Adam Doup, Ziming Zhao, Gail-Joon Ahn |
| 2015 | SACMAT | Federated Access Management for Collaborative Network Environments: Framework and Case Study. | Carlos E. Rubio-Medrano, Ziming Zhao, Adam Doup, Gail-Joon Ahn |
| 2014 | ACSAC | Morpheus: automatically generating heuristics to detect Android emulators. | Yiming Jing, Ziming Zhao, Gail-Joon Ahn, Hongxin Hu |
| 2014 | CCS | WPES 2014: 13th Workshop on Privacy in the Electronic Society. | Gail-Joon Ahn, Anupam Datta |
| 2014 | DBSEC | LPM: Layered Policy Management for Software-Defined Networks. | Wonkyu Han, Hongxin Hu, Gail-Joon Ahn |
| 2014 | IRI | Policy-driven security management for fog computing: Preliminary framework and a case study. | Clinton D'Souza, Gail-Joon Ahn, Marthony Taguinod |
| 2014 | SIGCOMM | FLOWGUARD: building robust firewalls for software-defined networks. | Hongxin Hu, Wonkyu Han, Gail-Joon Ahn, Ziming Zhao |
| 2014 | SACMAT | Game theoretic analysis of multiparty access control in online social networks. | Hongxin Hu, Gail-Joon Ahn, Ziming Zhao, Dejun Yang |
| 2013 | COMPSAC | Verifying Access Control Properties with Design by Contract: Framework and Lessons Learned. | Carlos E. Rubio-Medrano, Gail-Joon Ahn, Karsten Sohr |
| 2013 | IRI | Simulation-based validation for smart grid environments. | Wonkyu Han, Mike Mabey, Gail-Joon Ahn |
| 2013 | IRI | Simulation-Based Validation for Smart Grid Environments: Framework and Experimental Results. | Wonkyu Han, Mike Mabey, Gail-Joon Ahn, Tae Sung Kim |
| 2012 | ESORICS | SocialImpact: Systematic Analysis of Underground Social Dynamics. | Ziming Zhao, Gail-Joon Ahn, Hongxin Hu, Deepinder Mahi |
| 2012 | GLOBECOM | Enabling Collaborative data sharing in Google+. | Hongxin Hu, Gail-Joon Ahn, Jan Jorgensen |
| 2012 | GLOBECOM | Secure and efficient constructions of hash, MAC and PRF for mobile devices. | Yan Zhu, Shan-Biao Wang, Di Ma, Hongxin Hu, Gail-Joon Ahn |
| 2012 | INFOCOM | Towards temporal access control in cloud computing. | Yan Zhu, Hongxin Hu, Gail-Joon Ahn, Dijiang Huang, Shan-Biao Wang |
| 2012 | IWSEC | Model-Based Conformance Testing for Android. | Yiming Jing, Gail-Joon Ahn, Hongxin Hu |
| 2011 | ACSAC | Detecting and resolving privacy conflicts for collaborative data sharing in online social networks. | Hongxin Hu, Gail-Joon Ahn, Jan Jorgensen |
| 2011 | CCS | Poster: temporal attribute-based encryption in clouds. | Yan Zhu, Hongxin Hu, Gail-Joon Ahn, Xiaorui Gong, Shimin Chen |
| 2011 | COMPSAC | MasterBlaster: Identifying Influential Players in Botnet Transactions. | Napoleon Paxton, Gail-Joon Ahn, Mohamed Shehab |
| 2011 | DBSEC | Multiparty Authorization Framework for Data Sharing in Online Social Networks. | Hongxin Hu, Gail-Joon Ahn |
| 2011 | GLOBECOM | Examining Social Dynamics for Countering Botnet Attacks. | Ziming Zhao, Gail-Joon Ahn, Hongxin Hu |
| 2011 | IRI | Securing and utilizing social dynamics. | Gail-Joon Ahn |
| 2011 | IRI | Towards collaborative forensics: Preliminary framework. | Mike Mabey, Gail-Joon Ahn |
| 2011 | SAC | Dynamic audit services for integrity verification of outsourced storages in clouds. | Yan Zhu, Huaixi Wang, Zexing Hu, Gail-Joon Ahn, Hongxin Hu, Stephen S. Yau |
| 2011 | SACMAT | Anomaly discovery and resolution in web access control policies. | Hongxin Hu, Gail-Joon Ahn, Ketan Kulkarni |
| 2010 | CCS | Cryptographic role-based security mechanisms based on role-key hierarchy. | Yan Zhu, Gail-Joon Ahn, Hongxin Hu, Huaixi Wang |
| 2010 | CCS | Efficient provable data possession for hybrid clouds. | Yan Zhu, Huaixi Wang, Zexing Hu, Gail-Joon Ahn, Hongxin Hu, Stephen S. Yau |
| 2010 | COMPSAC | Representing and Reasoning about Web Access Control Policies. | Gail-Joon Ahn, Hongxin Hu, Joohyung Lee, Yunsong Meng |
| 2010 | COMPSAC | SecureCloud: Towards a Comprehensive Security Framework for Cloud Computing Environments. | Hassan Takabi, James B. D. Joshi, Gail-Joon Ahn |
| 2010 | ESORICS | DR@FT: Efficient Remote Attestation Framework for Dynamic Systems. | Wenjuan Xu, Gail-Joon Ahn, Hongxin Hu, Xinwen Zhang, Jean-Pierre Seifert |
| 2010 | GLOBECOM | Risk-Aware Response for Mitigating MANET Routing Attacks. | Ziming Zhao, Hongxin Hu, Gail-Joon Ahn, Ruoyu Wu |
| 2009 | COMPSAC | A Framework for Enabling User-Controlled Persona in Online Social Networks. | Dongwan Shin, Rodrigo Lopes, William R. Claycomb, Gail-Joon Ahn |
| 2009 | DBSEC | Towards System Integrity Protection with Graph-Based Policy Analysis. | Wenjuan Xu, Xinwen Zhang, Gail-Joon Ahn |
| 2009 | SACMAT | Patient-centric authorization framework for sharing electronic health records. | Jing Jin, Gail-Joon Ahn, Hongxin Hu, Michael J. Covington, Xinwen Zhang |
| 2008 | ACSAC | Enforcing Role-Based Access Control Policies in Web Services with UML and OCL. | Karsten Sohr, Tanveer Mustafa, Xinyu Bao, Gail-Joon Ahn |
| 2008 | ER | Risk Evaluation for Personal Identity Management Based on Privacy Attribute Ontology. | Mizuho Iwaihara, Kohei Murakami, Gail-Joon Ahn, Masatoshi Yoshikawa |
| 2008 | ICICS | Beyond User-to-User Access Control for Online Social Networks. | Mohamed Shehab, Anna Cinzia Squicciarini, Gail-Joon Ahn |
| 2008 | SACMAT | Enabling verification and conformance testing for access control model. | Hongxin Hu, Gail-Joon Ahn |
| 2008 | SACMAT | Visualization based policy analysis: case study in SELinux. | Wenjuan Xu, Mohamed Shehab, Gail-Joon Ahn |
| 2008 | SEC | Portable User-Centric Identity Management. | Gail-Joon Ahn, Moonam Ko, Mohamed Shehab |
| 2007 | CCS | Managing heterogeneous network environments using an extensible policy framework. | Lawrence Teo, Gail-Joon Ahn |
| 2007 | IRI | Towards Practical Framework for Collecting and Analyzing Network-Centric Attacks. | Napoleon Paxton, Gail-Joon Ahn, Bill Chu |
| 2007 | ISCC | Enabling Role-Based Delegation and Revocation on Security-Enhanced Linux. | Gail-Joon Ahn, Dhruv Gami |
| 2007 | SACMAT | Towards realizing a formal RBAC model in real systems. | Gail-Joon Ahn, Hongxin Hu |
| 2006 | ICSE | Building problem domain ontology from security requirements in regulatory documents. | Seok Won Lee, Robin A. Gandhi, Divya Muthurajan, Deepak S. Yavagal, Gail-Joon Ahn |
| 2006 | SACMAT | Role-based access management for ad-hoc collaborative sharing. | Jing Jin, Gail-Joon Ahn |
| 2005 | ESORICS | Specification and Validation of Authorisation Constraints Using UML and OCL. | Karsten Sohr, Gail-Joon Ahn, Martin Gogolla, Lars Migge |
| 2005 | ICSE | Establishing trustworthiness in services of the critical infrastructure through certification and accreditation. | Seok Won Lee, Robin A. Gandhi, Gail-Joon Ahn |
| 2005 | ICSE | Articulating and enforcing authorisation policies with UML and OCL. | Karsten Sohr, Gail-Joon Ahn, Lars Migge |
| 2005 | ISI | Active Automation of the DITSCAP. | Seok Won Lee, Robin A. Gandhi, Gail-Joon Ahn, Deepak S. Yavagal |
| 2005 | SAC | Formal specification of role-based security policies for clinical information systems. | Karsten Sohr, Michael Drouineaud, Gail-Joon Ahn |
| 2005 | VDA | Interactive exploration of large filesystems. | Joshua Foster, Kalpathi R. Subramanian, Gail-Joon Ahn |
| 2004 | IPCCC | Ensuring information assurance in federated identity management. | Dongwan Shin, Gail-Joon Ahn, Prasad Shenoy |
| 2004 | WISE | Information Assurance in Federated Identity Management: Experimentations and Issues. | Gail-Joon Ahn, Dongwan Shin, Seng-Phil Hong |
| 2004 | TrustBus | Role-Based Privilege Management Using Attribute Certificates and Delegation. | Gail-Joon Ahn, Dongwan Shin, Longhua Zhang |
| 2003 | SMC | Authorization management for role-based collaboration. | Gail-Joon Ahn, Longhua Zhang, Dongwan Shin, Bill Chu |
| 2003 | SMC | Locale-based access control: placing collaborative authorization decisions in context. | William J. Tolone, Robin A. Gandhi, Gail-Joon Ahn |
| 2003 | SAC | Role-Based Authorization in Decentralized Health Care Environments. | Gail-Joon Ahn, Badrinath Mohan |
| 2003 | SAC | A Role Administration System in Role-based Authorization Infrastructures - Design and Implementation. | Dongwan Shin, Gail-Joon Ahn, Sangrae Cho, Seunghun Jin |
| 2003 | WETICE | Specification and Classification of Role-based Authorization Policies. | Gail-Joon Ahn |
| 2003 | SACMAT | The role control center: features and case studies. | David F. Ferraiolo, Ramaswamy Chandramouli, Gail-Joon Ahn, Serban I. Gavrila |
| 2003 | SACMAT | On modeling system-centric information for role engineering. | Dongwan Shin, Gail-Joon Ahn, Sangrae Cho, Seunghun Jin |
| 2003 | SACMAT | Dynamic and risk-aware network access management. | Lawrence Teo, Gail-Joon Ahn, Yuliang Zheng |
| 2003 | SEC | Constrained Role-based Delegation. | Longhua Zhang, Gail-Joon Ahn |
| 2002 | COMPSAC | An Application of Directory Service Markup Language (DSML) for Role-Based Access Control (RBAC). | Dongwan Shin, Gail-Joon Ahn, Joon S. Park |
| 2002 | DBSEC | Using X.509 Attribute Certificates for Role-Based EAM. | Dongwan Shin, Gail-Joon Ahn, Sangrae Cho |
| 2002 | WETICE | Towards Scalable Authentication in Health Services. | Gail-Joon Ahn, Dongwan Shin |
| 2002 | SACMAT | A role-based delegation framework for healthcare information systems. | Longhua Zhang, Gail-Joon Ahn, Bei-tseng Chu |
| 2001 | DBSEC | Role-based Access Control on the Web Using LDAP. | Joon S. Park, Gail-Joon Ahn, Ravi S. Sandhu |
| 2001 | WETICE | Role-Based Authorization Constraints Specification Using Object Constraint Language. | Gail-Joon Ahn, Michael E. Shin |
| 2001 | SACMAT | A rule-based framework for role based delegation. | Longhua Zhang, Gail-Joon Ahn, Bei-tseng Chu |
| 2000 | WETICE | UML-Based Representation of Role-Based Access Control. | Michael E. Shin, Gail-Joon Ahn |