| 2024 | CCS | ACM CCS 2024 Doctoral Symposium. | Gabriela F. Ciocarlie, Xinming Ou |
| 2021 | SOUPS | An Analysis of the Role of Situated Learning in Starting a Security Culture in a Software Company. | Anwesh Tuladhar, Daniel Lende, Jay Ligatti, Xinming Ou |
| 2020 | CCS | A Multi-phased Multi-faceted IoT Honeypot Ecosystem. | Armin Ziaie Tabari, Xinming Ou |
| 2020 | SOUPS | An Ethnographic Understanding of Software (In)Security and a Co-Creation Model to Improve Secure Software Development. | Hernan M. Palombo, Armin Ziaie Tabari, Daniel Lende, Jay Ligatti, Xinming Ou |
| 2019 | SecureComm | Topology-Aware Hashing for Effective Control Flow Graph Similarity Analysis. | Yuping Li, Jiyong Jang, Xinming Ou |
| 2018 | CCS | JN-SAF: Precise and Efficient NDK/JNI-aware Inter-language Static Analysis Framework for Security Vetting of Android Applications with Native Code. | Fengguo Wei, Xingwei Lin, Xinming Ou, Ting Chen, Xiaosong Zhang |
| 2018 | NDSS | InstaGuard: Instantly Deployable Hot-patches for Vulnerable System Programs on Android. | Yaohui Chen, Yuping Li, Long Lu, Yueh-Hsun Lin, Hayawardh Vijayakumar, Zhi Wang, Xinming Ou |
| 2018 | SoMeT | A Population-Based Incremental Learning Approach to Network Hardening. | Alexander Paulsen, Anis Yazidi, Boning Feng, Xinming Ou |
| 2017 | AAAI | Android Malware Detection with Weak Ground Truth Data. | Jordan DeLoach, Doina Caragea, Xinming Ou |
| 2017 | CCS | MTD 2017: Fourth ACM Workshop on Moving Target Defense (MTD). | Hamed Okhravi, Xinming Ou |
| 2017 | DIMVA | Deep Ground Truth Analysis of Current Android Malware. | Fengguo Wei, Yuping Li, Sankardas Roy, Xinming Ou, Wu Zhou |
| 2017 | ESORICS | MTD CBITS: Moving Target Defense for Cloud-Based IT Systems. | Alexandru G. Bardas, Sathya Chandran Sundaramurthy, Xinming Ou, Scott A. DeLoach |
| 2017 | RAID | Android Malware Clustering Through Malicious Payload Mining. | Yuping Li, Jiyong Jang, Xin Hu, Xinming Ou |
| 2016 | SOUPS | Turning Contradictions into Innovations or: How We Learned to Stop Whining and Improve Security Operations. | Sathya Chandran Sundaramurthy, John McHugh, Xinming Ou, Michael Wesch, Alexandru G. Bardas, S. Raj Rajagopalan |
| 2015 | ACSAC | Experimental Study with Real-world Data for Android App Security Analysis using Machine Learning. | Sankardas Roy, Jordan DeLoach, Yuping Li, Nic Herndon, Doina Caragea, Xinming Ou, Venkatesh Prasad Ranganath, Hongmin Li, Nicolais Guevara |
| 2015 | CCS | Secure RTOS Architecture for Building Automation. | Xiaolong Wang, Masaaki Mizuno, Mitchell L. Neilsen, Xinming Ou, S. Raj Rajagopalan, Will G. Boldwin, Bryan Phillips |
| 2015 | CCS | A Theory of Cyber Attacks: A Step Towards Analyzing MTD Systems. | Rui Zhuang, Alexandru G. Bardas, Scott A. DeLoach, Xinming Ou |
| 2015 | HotOS | Practical Always-on Taint Tracking on Mobile Devices. | Justin Paupore, Earlence Fernandes, Atul Prakash, Sankardas Roy, Xinming Ou |
| 2015 | NSS | Assessing Attack Surface with Component-Based Package Dependency. | Su Zhang, Xinwen Zhang, Xinming Ou, Liqun Chen, Nigel Edwards, Jing Jin |
| 2015 | SOUPS | A Human Capital Model for Mitigating Security Analyst Burnout. | Sathya Chandran Sundaramurthy, Alexandru G. Bardas, Jacob Case, Xinming Ou, Michael Wesch, John McHugh, S. Raj Rajagopalan |
| 2014 | CCS | Amandroid: A Precise and General Inter-component Data Flow Analysis Framework for Security Vetting of Android Apps. | Fengguo Wei, Sankardas Roy, Xinming Ou, Robby |
| 2014 | CCS | After we knew it: empirical study and modeling of cost-effectiveness of exploiting prevalent known vulnerabilities across IaaS cloud. | Su Zhang, Xinwen Zhang, Xinming Ou |
| 2014 | CCS | Towards a Theory of Moving Target Defense. | Rui Zhuang, Scott A. DeLoach, Xinming Ou |
| 2013 | ICMLA | Aiding Intrusion Analysis Using Machine Learning. | Loai Zomlot, Sathya Chandran Sundaramurthy, Doina Caragea, Xinming Ou |
| 2011 | ACSAC | Distilling critical attack graph surface iteratively through minimum-cost SAT solving. | Heqing Huang, Su Zhang, Xinming Ou, Atul Prakash, Karem A. Sakallah |
| 2011 | CCS | Prioritizing intrusion analysis using Dempster-Shafer theory. | Loai Zomlot, Sathya Chandran Sundaramurthy, Kui Luo, Xinming Ou, Siva Raj Rajagopalan |
| 2011 | DEXA | An Empirical Study on Using the National Vulnerability Database to Predict Software Vulnerabilities. | Su Zhang, Doina Caragea, Xinming Ou |
| 2011 | DIMVA | Effective Network Vulnerability Assessment through Model Abstraction. | Su Zhang, Xinming Ou, John Homer |
| 2010 | DSN | Using Bayesian networks for cyber security analysis. | Peng Xie, Jason H. Li, Xinming Ou, Peng Liu, Renato Levy |
| 2009 | ACSAC | An Empirical Approach to Modeling Uncertainty in Intrusion Analysis. | Xinming Ou, Siva Raj Rajagopalan, Sakthiyuvaraja Sakthivelmurugan |
| 2008 | ESORICS | Identifying Critical Attack Assets in Dependency Attack Graphs. | Reginald E. Sawilla, Xinming Ou |
| 2008 | VizSec | Improving Attack Graph Visualization through Data Reduction and Attack Grouping. | John Homer, Ashok Varikuti, Xinming Ou, Miles A. McQueen |
| 2006 | CCS | A scalable approach to attack graph generation. | Xinming Ou, Wayne F. Boyer, Miles A. McQueen |
| 2005 | TACAS | A Two-Tier Technique for Supporting Quantifiers in a Lazily Proof-Explicating Theorem Prover. | K. Rustan M. Leino, Madan Musuvathi, Xinming Ou |
| 2003 | CAV | Theorem Proving Using Lazy Proof Explication. | Cormac Flanagan, Rajeev Joshi, Xinming Ou, James B. Saxe |