Tiffany Bao
Publication record assembled from the DBLP archive of ranked conferences.
Papers indexed
30
Venues
11
Active years
2017–2026
Best venue rank
A*
Where they publish
Papers
30 indexed papers, newest first.
| Year | Venue | Title | Authors |
|---|---|---|---|
| 2026 | CHI | I Can SE Clearly Now: Investigating the Effectiveness of GUI-based Symbolic Execution for Software Vulnerability Discovery. | Yi Jou Li, Zeming Yu, James Mattei, Ananta Soneji, Zhibo Sun, Ruoyu Wang, Jaron Mink, Daniel Votipka, Tiffany Bao |
| 2026 | Mobisys | Fragile Deliveries: Inconsistencies in Android Parcel and Their Security Consequences. | Hongkai Chen, Chao Wang, Yuqing Yang, Jennifer Miller, Tiffany Bao, Ruoyu Wang, Adam Doup, Zhiqiang Lin, Yan Shoshitaishvili |
| 2026 | NDSS | Discovering Blind-Trust Vulnerabilities in PLC Binaries via State Machine Recovery. | Fangzhou Dong, Arvind S. Raj, Efrn Lpez-Morales, Siyu Liu, Yan Shoshitaishvili, Tiffany Bao, Adam Doup, Muslum Ozgur Ozmen, Ruoyu Wang |
| 2026 | NDSS | ropbot: Reimaging Code Reuse Attack Synthesis. | Kyle Zeng, Moritz Schloegel, Christopher Salls, Adam Doup, Ruoyu Wang, Yan Shoshitaishvili, Tiffany Bao |
| 2026 | SP | Oxidizer: Toward Concise and High-fidelity Rust Decompilation. | Yibo Liu, Zion Leonahenahe Basque, Arvind S. Raj, Chavin Udomwongsa, Chang Zhu, Jie Hu, Changyu Zhao, Fangzhou Dong, Adam Doup, Tiffany Bao, Yan Shoshitaishvili, Ruoyu Wang |
| 2026 | SP | Responsible Disclosure is a Two-Way Street: Empirically Measuring the Responsible Disclosure Contract in the Firmware Ecosystem. | Hui Jun Tay, Souradip Nath, Arvind S. Raj, Abhay Bhat, Ishan Bansal, Audrey Dutcher, Moritz Schloegel, Adam Doup, Tiffany Bao, Yan Shoshitaishvili, Ruoyu Wang |
| 2025 | AAAI | ScamNet: Toward Explainable Large Language Model-Based Fraudulent Shopping Website Detection. | Marzieh Bitaab, Alireza Karimi, Zhuoer Lyu, Ahmadreza Mosallanezhad, Adam Oest, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, Adam Doup |
| 2025 | NDSS | SCAMMAGNIFIER: Piercing the Veil of Fraudulent Shopping Website Campaigns. | Marzieh Bitaab, Alireza Karimi, Zhuoer Lyu, Adam Oest, Dhruv Kuchhal, Muhammad Saad, Gail-Joon Ahn, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, Adam Doup |
| 2025 | SP | "It's almost like Frankenstein": Investigating the Complexities of Scientific Collaboration and Privilege Management within Research Computing Infrastructures. | Souradip Nath, Ananta Soneji, Jaejong Baek, Tiffany Bao, Adam Doup, Carlos E. Rubio-Medrano, Gail-Joon Ahn |
| 2024 | AsiaCCS | Deep Dive into Client-Side Anti-Phishing: A Longitudinal Study Bridging Academia and Industry. | Rana Pourmohamad, Steven Wirsz, Adam Oest, Tiffany Bao, Yan Shoshitaishvili, Ruoyu Wang, Adam Doup, Rida A. Bazzi |
| 2024 | CCS | Fuzz to the Future: Uncovering Occluded Future Vulnerabilities via Robust Fuzzing. | Arvind S. Raj, Wil Gibbs, Fangzhou Dong, Jayakrishna Menon Vadayath, Michael Tompkins, Steven Wirsz, Yibo Liu, Zhenghao Hu, Chang Zhu, Gokulkrishna Praveen Menon, Brendan Dolan-Gavitt, Adam Doup, Ruoyu Wang, Yan Shoshitaishvili, Tiffany Bao |
| 2024 | DIMVA | SandPuppy: Deep-State Fuzzing Guided by Automatic Detection of State-Representative Variables. | Vivin Paliath, Erik Trickel, Tiffany Bao, Ruoyu Wang, Adam Doup, Yan Shoshitaishvili |
| 2024 | RAID | From Victims to Defenders: An Exploration of the Phishing Attack Reporting Ecosystem. | Zhibo Sun, Faris Bugra Kokulu, Penghui Zhang, Adam Oest, Gianluca Stringhini, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, Adam Doup, Gail-Joon Ahn |
| 2024 | SP | "Watching over the shoulder of a professional": Why Hackers Make Mistakes and How They Fix Them. | Irina Ford, Ananta Soneji, Faris Bugra Kokulu, Jayakrishna Vadayath, Zion Leonahenahe Basque, Gaurav Vipat, Adam Doup, Ruoyu Wang, Gail-Joon Ahn, Tiffany Bao, Yan Shoshitaishvili |
| 2024 | SP | AirTaint: Making Dynamic Taint Analysis Faster and Easier. | Qian Sang, Yanhao Wang, Yuwei Liu, Xiangkun Jia, Tiffany Bao, Purui Su |
| 2023 | CCS | RetSpill: Igniting User-Controlled Data to Burn Away Linux Kernel Protections. | Kyle Zeng, Zhenpeng Lin, Kangjie Lu, Xinyu Xing, Ruoyu Wang, Adam Doup, Yan Shoshitaishvili, Tiffany Bao |
| 2023 | SP | Beyond Phish: Toward Detecting Fraudulent e-Commerce Websites at Scale. | Marzieh Bitaab, Haehyun Cho, Adam Oest, Zhuoer Lyu, Wei Wang, Jorij Abraham, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, Adam Doup |
| 2023 | SP | Toss a Fault to Your Witcher: Applying Grey-box Coverage-Guided Mutational Fuzzing to Detect SQL and Command Injection Vulnerabilities. | Erik Trickel, Fabio Pagani, Chang Zhu, Lukas Dresel, Giovanni Vigna, Christopher Kruegel, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, Adam Doup |
| 2022 | ASPLOS | ViK: practical mitigation of temporal memory safety violations through object ID inspection. | Haehyun Cho, Jinbum Park, Adam Oest, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, Adam Doup, Gail-Joon Ahn |
| 2022 | CCS | I'm SPARTACUS, No, I'm SPARTACUS: Proactively Protecting Users from Phishing by Intentionally Triggering Cloaking Behavior. | Penghui Zhang, Zhibo Sun, Sukwha Kyung, Hans Walter Behrens, Zion Leonahenahe Basque, Haehyun Cho, Adam Oest, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, Gail-Joon Ahn, Adam Doup |
| 2022 | RAID | Context-Auditor: Context-sensitive Content Injection Mitigation. | Faezeh Kalantari, Mehrnoosh Zaeifi, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, Adam Doup |
| 2022 | SP | "Flawed, but like democracy we don't have a better system": The Experts' Insights on the Peer Review Process of Evaluating Security Papers. | Ananta Soneji, Faris Bugra Kokulu, Carlos E. Rubio-Medrano, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, Adam Doup |
| 2021 | FC | Everything You Ever Wanted to Know About Bitcoin Mixers (But Were Afraid to Ask). | Jaswant Pakki, Yan Shoshitaishvili, Ruoyu Wang, Tiffany Bao, Adam Doup |
| 2021 | NDSS | Favocado: Fuzzing the Binding Code of JavaScript Engines Using Semantically Correct Test Cases. | Sung Ta Dinh, Haehyun Cho, Kyle Martin, Adam Oest, Kyle Zeng, Alexandros Kapravelos, Gail-Joon Ahn, Tiffany Bao, Ruoyu Wang, Adam Doup, Yan Shoshitaishvili |
| 2021 | RAID | SyML: Guiding Symbolic Execution Toward Vulnerable States Through Pattern Learning. | Nicola Ruaro, Kyle Zeng, Lukas Dresel, Mario Polino, Tiffany Bao, Andrea Continella, Stefano Zanero, Christopher Kruegel, Giovanni Vigna |
| 2021 | SP | CrawlPhish: Large-scale Analysis of Client-side Cloaking Techniques in Phishing. | Penghui Zhang, Adam Oest, Haehyun Cho, Zhibo Sun, RC Johnson, Brad Wardman, Shaown Sarker, Alexandros Kapravelos, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, Adam Doup, Gail-Joon Ahn |
| 2020 | CCS | HoneyPLC: A Next-Generation Honeypot for Industrial Control Systems. | Efrn Lpez-Morales, Carlos E. Rubio-Medrano, Adam Doup, Yan Shoshitaishvili, Ruoyu Wang, Tiffany Bao, Gail-Joon Ahn |
| 2020 | NDSS | Not All Coverage Measurements Are Equal: Fuzzing by Coverage Accounting for Input Prioritization. | Yanhao Wang, Xiangkun Jia, Yuwei Liu, Kyle Zeng, Tiffany Bao, Dinghao Wu, Purui Su |
| 2019 | CCS | Matched and Mismatched SOCs: A Qualitative Study on Security Operations Center Issues. | Faris Bugra Kokulu, Ananta Soneji, Tiffany Bao, Yan Shoshitaishvili, Ziming Zhao, Adam Doup, Gail-Joon Ahn |
| 2017 | SP | Your Exploit is Mine: Automatic Shellcode Transplant for Remote Exploits. | Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, David Brumley |