| 2026 | SACMAT | Mining Domain-Based Policies from Massive and Noisy Access Logs. | Si Zhang, Philip W. L. Fong |
| 2024 | ESORICS | Social Control and Interactivity in Anonymous Public Events. | Md Mushfekur Rahman, Philip W. L. Fong |
| 2022 | SACMAT | Higher-Order Relationship-Based Access Control: A Temporal Instantiation with IoT Applications. | Chahal Arora, Syed Zain R. Rizvi, Philip W. L. Fong |
| 2022 | SACMAT | A Capability-based Distributed Authorization System to Enforce Context-aware Permission Sequences. | Adrian Shuai Li, Reihaneh Safavi-Naini, Philip W. L. Fong |
| 2019 | ESORICS | SEPD: An Access Control Model for Resource Sharing in an IoT Environment. | Henrique G. G. Pereira, Philip W. L. Fong |
| 2019 | SACMAT | Brokering Policies and Execution Monitors for IoT Middleware. | Juan Carlos Fuentes Carranza, Philip W. L. Fong |
| 2018 | SIGCOMM | Towards a Resilient Smart Home. | Tam Thanh Doan, Reihaneh Safavi-Naini, Shuai Li, Sepideh Avizheh, Muni Venkateswarlu K., Philip W. L. Fong |
| 2018 | SACMAT | HCAP: A History-Based Capability System for IoT Devices. | Lakshya Tandon, Philip W. L. Fong, Reihaneh Safavi-Naini |
| 2017 | SACMAT | An Enforcement Model for Preventing Inference Attacks in Social Computing Platforms. | Seyed Hossein Ahmadinejad, Philip W. L. Fong |
| 2016 | CCS | Privacy and Utility of Inference Control Mechanisms for Social Computing Applications. | Seyed Hossein Ahmadinejad, Philip W. L. Fong, Reihaneh Safavi-Naini |
| 2016 | SACMAT | Policy Negotiation for Co-owned Resources in Relationship-Based Access Control. | Pooya Mehregan, Philip W. L. Fong |
| 2015 | SACMAT | Relationship-Based Access Control for an Open-Source Medical Records System. | Syed Zain R. Rizvi, Philip W. L. Fong, Jason Crampton, James Sellwood |
| 2014 | DBSEC | Design Patterns for Multiple Stakeholders in Social Computing. | Pooya Mehregan, Philip W. L. Fong |
| 2014 | SACMAT | Access control models for geo-social computing systems. | Ebrahim Tarameshloo, Philip W. L. Fong |
| 2013 | CCS | On the feasibility of inference attacks by third-party extensions to social network systems. | Seyed Hossein Ahmadinejad, Philip W. L. Fong |
| 2013 | CCS | Relational abstraction in community-based secure collaboration. | Philip W. L. Fong, Pooya Mehregan, Ram Krishnan |
| 2013 | SACMAT | A white-box policy analysis and its efficient implementation. | Jayalakshmi Balasubramaniam, Philip W. L. Fong |
| 2012 | CCS | The specification and compilation of obligation policies for program monitoring. | Cheng Xu, Philip W. L. Fong |
| 2012 | ESORICS | Satisfiability and Feasibility in a Relationship-Based Workflow Authorization Model. | Arif Akram Khan, Philip W. L. Fong |
| 2012 | SAC | A visualization tool for evaluating access control policies in facebook-style social network systems. | Mohd M. Anwar, Philip W. L. Fong |
| 2011 | PERCOM | Inference attacks by third-party extensions to social network systems. | Seyed Hossein Ahmadinejad, Mohd M. Anwar, Philip W. L. Fong |
| 2011 | SP | Preventing Sybil Attacks by Privilege Attenuation: A Design Principle for Social Network Systems. | Philip W. L. Fong |
| 2011 | SACMAT | Relationship-based access control policies and their policy languages. | Philip W. L. Fong, Ida Sri Rejeki Siahaan |
| 2009 | CCS | Efficient IRM enforcement of history-based access control policies. | Fei Yan, Philip W. L. Fong |
| 2009 | ESORICS | Visualizing Privacy Implications of Access Control Policies in Social Network Systems. | Mohd M. Anwar, Philip W. L. Fong, Xue-Dong Yang, Howard J. Hamilton |
| 2009 | ESORICS | A Privacy Preservation Model for Facebook-Style Social Network Systems. | Philip W. L. Fong, Mohd M. Anwar, Zhen Zhao |
| 2006 | ACSAC | A Module System for Isolating Untrusted Software Extensions. | Philip W. L. Fong, Simon A. Orr |
| 2006 | ESORICS | Discretionary Capability Confinement. | Philip W. L. Fong |
| 2005 | PST | Link-Time Enforcement of Confined Types for JVM Bytecode. | Philip W. L. Fong |
| 2004 | OOPSLA | Pluggable verification modules: an extensible protection mechanism for the JVM. | Philip W. L. Fong |
| 2004 | SP | Access Control By Tracking Shallow Execution History. | Philip W. L. Fong |
| 1998 | ICSE | Techniques for Trusted Software Engineering. | Premkumar T. Devanbu, Philip W. L. Fong, Stuart G. Stubblebine |
| 1995 | ICML | A Quantitative Study of Hypothesis Selection. | Philip W. L. Fong |