Yan Shoshitaishvili
Publication record assembled from the DBLP archive of ranked conferences.
Papers indexed
62
Venues
18
Active years
2012–2026
Best venue rank
A*
Where they publish
Papers
62 indexed papers, newest first.
| Year | Venue | Title | Authors |
|---|---|---|---|
| 2026 | Mobisys | Fragile Deliveries: Inconsistencies in Android Parcel and Their Security Consequences. | Hongkai Chen, Chao Wang, Yuqing Yang, Jennifer Miller, Tiffany Bao, Ruoyu Wang, Adam Doup, Zhiqiang Lin, Yan Shoshitaishvili |
| 2026 | NDSS | Decompiling the Synergy: An Empirical Study of Human-LLM Teaming in Software Reverse Engineering. | Zion Leonahenahe Basque, Samuele Doria, Ananta Soneji, Wil Gibbs, Adam Doup, Yan Shoshitaishvili, Eleonora Losiouk, Ruoyu Wang, Simone Aonzo |
| 2026 | NDSS | Discovering Blind-Trust Vulnerabilities in PLC Binaries via State Machine Recovery. | Fangzhou Dong, Arvind S. Raj, Efrn Lpez-Morales, Siyu Liu, Yan Shoshitaishvili, Tiffany Bao, Adam Doup, Muslum Ozgur Ozmen, Ruoyu Wang |
| 2026 | NDSS | ropbot: Reimaging Code Reuse Attack Synthesis. | Kyle Zeng, Moritz Schloegel, Christopher Salls, Adam Doup, Ruoyu Wang, Yan Shoshitaishvili, Tiffany Bao |
| 2026 | SIGCSE | Open Cybersecurity Education: Five Years of pwn.college. | Connor Nelson, Robert Wasinger, Adam Doup, Yan Shoshitaishvili |
| 2026 | SIGCSE | The Linux Luminarium: Learning Linux by Leveraging Lightweight Labs and Ludicrous Lessons. | Yan Shoshitaishvili, Adam Doup, Connor Nelson |
| 2026 | SP | Oxidizer: Toward Concise and High-fidelity Rust Decompilation. | Yibo Liu, Zion Leonahenahe Basque, Arvind S. Raj, Chavin Udomwongsa, Chang Zhu, Jie Hu, Changyu Zhao, Fangzhou Dong, Adam Doup, Tiffany Bao, Yan Shoshitaishvili, Ruoyu Wang |
| 2026 | SP | Responsible Disclosure is a Two-Way Street: Empirically Measuring the Responsible Disclosure Contract in the Firmware Ecosystem. | Hui Jun Tay, Souradip Nath, Arvind S. Raj, Abhay Bhat, Ishan Bansal, Audrey Dutcher, Moritz Schloegel, Adam Doup, Tiffany Bao, Yan Shoshitaishvili, Ruoyu Wang |
| 2025 | AAAI | ScamNet: Toward Explainable Large Language Model-Based Fraudulent Shopping Website Detection. | Marzieh Bitaab, Alireza Karimi, Zhuoer Lyu, Ahmadreza Mosallanezhad, Adam Oest, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, Adam Doup |
| 2025 | CHI | Investigating the Security & Privacy Risks from Unsanctioned Technology Use by Educators. | Easton Kelso, Ananta Soneji, Syed Zami-Ul-Haque Navid, Yan Shoshitaishvili, Sazzadur Rahaman, Rakibul Hasan |
| 2025 | NDSS | SCAMMAGNIFIER: Piercing the Veil of Fraudulent Shopping Website Campaigns. | Marzieh Bitaab, Alireza Karimi, Zhuoer Lyu, Adam Oest, Dhruv Kuchhal, Muhammad Saad, Gail-Joon Ahn, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, Adam Doup |
| 2025 | SIGCSE | SENSAI: Large Language Models as Applied Cybersecurity Tutors. | Connor Nelson, Adam Doup, Yan Shoshitaishvili |
| 2024 | AsiaCCS | Deep Dive into Client-Side Anti-Phishing: A Longitudinal Study Bridging Academia and Industry. | Rana Pourmohamad, Steven Wirsz, Adam Oest, Tiffany Bao, Yan Shoshitaishvili, Ruoyu Wang, Adam Doup, Rida A. Bazzi |
| 2024 | CCS | Trust, Because You Can't Verify: Privacy and Security Hurdles in Education Technology Acquisition Practices. | Easton Kelso, Ananta Soneji, Sazzadur Rahaman, Yan Shoshitaishvili, Rakibul Hasan |
| 2024 | CCS | Fuzz to the Future: Uncovering Occluded Future Vulnerabilities via Robust Fuzzing. | Arvind S. Raj, Wil Gibbs, Fangzhou Dong, Jayakrishna Menon Vadayath, Michael Tompkins, Steven Wirsz, Yibo Liu, Zhenghao Hu, Chang Zhu, Gokulkrishna Praveen Menon, Brendan Dolan-Gavitt, Adam Doup, Ruoyu Wang, Yan Shoshitaishvili, Tiffany Bao |
| 2024 | DIMVA | SandPuppy: Deep-State Fuzzing Guided by Automatic Detection of State-Representative Variables. | Vivin Paliath, Erik Trickel, Tiffany Bao, Ruoyu Wang, Adam Doup, Yan Shoshitaishvili |
| 2024 | ICML | The WMDP Benchmark: Measuring and Reducing Malicious Use with Unlearning. | Nathaniel Li, Alexander Pan, Anjali Gopal, Summer Yue, Daniel Berrios, Alice Gatti, Justin D. Li, Ann-Kathrin Dombrowski, Shashwat Goel, Gabriel Mukobi, Nathan Helm-Burger, Rassin Lababidi, Lennart Justen, Andrew B. Liu, Michael Chen, Isabelle Barrass, Oliver Zhang, Xiaoyuan Zhu, Rishub Tamirisa, Bhrugu Bharathi, Ariel Herbert-Voss, Cort B. Breuer, Andy Zou, Mantas Mazeika, Zifan Wang, Palash Oswal, Weiran Lin, Adam A. Hunt, Justin Tienken-Harder, Kevin Y. Shih, Kemper Talley, John Guan, Ian Steneker, David Campbell, Brad Jokubaitis, Steven Basart, Stephen Fitz, Ponnurangam Kumaraguru, Kallol Krishna Karmakar, Uday Kiran Tupakula, Vijay Varadharajan, Yan Shoshitaishvili, Jimmy Ba, Kevin M. Esvelt, Alexandr Wang, Dan Hendrycks |
| 2024 | IMC | Browser Polygraph: Efficient Deployment of Coarse-Grained Browser Fingerprints for Web-Scale Detection of Fraud Browsers. | Faezeh Kalantari, Mehrnoosh Zaeifi, Yeganeh Safaei, Marzieh Bitaab, Adam Oest, Gianluca Stringhini, Yan Shoshitaishvili, Adam Doup |
| 2024 | RAID | From Victims to Defenders: An Exploration of the Phishing Attack Reporting Ecosystem. | Zhibo Sun, Faris Bugra Kokulu, Penghui Zhang, Adam Oest, Gianluca Stringhini, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, Adam Doup, Gail-Joon Ahn |
| 2024 | SIGCSE | DOJO: Applied Cybersecurity Education in the Browser. | Connor Nelson, Yan Shoshitaishvili |
| 2024 | SIGCSE | PWN The Learning Curve: Education-First CTF Challenges. | Connor Nelson, Yan Shoshitaishvili |
| 2024 | SP | "Watching over the shoulder of a professional": Why Hackers Make Mistakes and How They Fix Them. | Irina Ford, Ananta Soneji, Faris Bugra Kokulu, Jayakrishna Vadayath, Zion Leonahenahe Basque, Gaurav Vipat, Adam Doup, Ruoyu Wang, Gail-Joon Ahn, Tiffany Bao, Yan Shoshitaishvili |
| 2024 | SP | "Len or index or count, anything but v1": Predicting Variable Names in Decompilation Output with Transfer Learning. | Kuntal Kumar Pal, Ati Priya Bajaj, Pratyay Banerjee, Audrey Dutcher, Mutsumi Nakamura, Zion Leonahenahe Basque, Himanshu Gupta, Saurabh Arjun Sawant, Ujjwala Anantheswaran, Yan Shoshitaishvili, Adam Doup, Chitta Baral, Ruoyu Wang |
| 2023 | CCS | RetSpill: Igniting User-Controlled Data to Burn Away Linux Kernel Protections. | Kyle Zeng, Zhenpeng Lin, Kangjie Lu, Xinyu Xing, Ruoyu Wang, Adam Doup, Yan Shoshitaishvili, Tiffany Bao |
| 2023 | DSN | Targeted Privacy Attacks by Fingerprinting Mobile Apps in LTE Radio Layer. | Jaejong Baek, Pradeep Kumar Duraisamy Soundrapandian, Sukwha Kyung, Ruoyu Wang, Yan Shoshitaishvili, Adam Doup, Gail-Joon Ahn |
| 2023 | SP | Beyond Phish: Toward Detecting Fraudulent e-Commerce Websites at Scale. | Marzieh Bitaab, Haehyun Cho, Adam Oest, Zhuoer Lyu, Wei Wang, Jorij Abraham, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, Adam Doup |
| 2023 | SP | Toss a Fault to Your Witcher: Applying Grey-box Coverage-Guided Mutational Fuzzing to Detect SQL and Command Injection Vulnerabilities. | Erik Trickel, Fabio Pagani, Chang Zhu, Lukas Dresel, Giovanni Vigna, Christopher Kruegel, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, Adam Doup |
| 2023 | SecureComm | Street Rep: A Privacy-Preserving Reputation Aggregation System. | Christophe Hauser, Shirin Nilizadeh, Yan Shoshitaishvili, Ni Trieu, Srivatsan Ravi, Christopher Kruegel, Giovanni Vigna |
| 2022 | AsiaCCS | The Convergence of Source Code and Binary Vulnerability Discovery - A Case Study. | Alessandro Mantovani, Luca Compagna, Yan Shoshitaishvili, Davide Balzarotti |
| 2022 | ASPLOS | ViK: practical mitigation of temporal memory safety violations through object ID inspection. | Haehyun Cho, Jinbum Park, Adam Oest, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, Adam Doup, Gail-Joon Ahn |
| 2022 | CCS | I'm SPARTACUS, No, I'm SPARTACUS: Proactively Protecting Users from Phishing by Intentionally Triggering Cloaking Behavior. | Penghui Zhang, Zhibo Sun, Sukwha Kyung, Hans Walter Behrens, Zion Leonahenahe Basque, Haehyun Cho, Adam Oest, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, Gail-Joon Ahn, Adam Doup |
| 2022 | DIMVA | Hybrid Pruning: Towards Precise Pointer and Taint Analysis. | Dipanjan Das, Priyanka Bose, Aravind Machiry, Sebastiano Mariani, Yan Shoshitaishvili, Giovanni Vigna, Christopher Kruegel |
| 2022 | RAID | Context-Auditor: Context-sensitive Content Injection Mitigation. | Faezeh Kalantari, Mehrnoosh Zaeifi, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, Adam Doup |
| 2022 | SP | "Flawed, but like democracy we don't have a better system": The Experts' Insights on the Peer Review Process of Evaluating Security Papers. | Ananta Soneji, Faris Bugra Kokulu, Carlos E. Rubio-Medrano, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, Adam Doup |
| 2021 | FC | Everything You Ever Wanted to Know About Bitcoin Mixers (But Were Afraid to Ask). | Jaswant Pakki, Yan Shoshitaishvili, Ruoyu Wang, Tiffany Bao, Adam Doup |
| 2021 | NDSS | Favocado: Fuzzing the Binding Code of JavaScript Engines Using Semantically Correct Test Cases. | Sung Ta Dinh, Haehyun Cho, Kyle Martin, Adam Oest, Kyle Zeng, Alexandros Kapravelos, Gail-Joon Ahn, Tiffany Bao, Ruoyu Wang, Adam Doup, Yan Shoshitaishvili |
| 2021 | SP | CrawlPhish: Large-scale Analysis of Client-side Cloaking Techniques in Phishing. | Penghui Zhang, Adam Oest, Haehyun Cho, Zhibo Sun, RC Johnson, Brad Wardman, Shaown Sarker, Alexandros Kapravelos, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, Adam Doup, Gail-Joon Ahn |
| 2020 | CCS | HoneyPLC: A Next-Generation Honeypot for Industrial Control Systems. | Efrn Lpez-Morales, Carlos E. Rubio-Medrano, Adam Doup, Yan Shoshitaishvili, Ruoyu Wang, Tiffany Bao, Gail-Joon Ahn |
| 2020 | Mobisys | SmokeBomb: effective mitigation against cache side-channel attacks on the ARM architecture. | Haehyun Cho, Jinbum Park, Donguk Kim, Ziming Zhao, Yan Shoshitaishvili, Adam Doup, Gail-Joon Ahn |
| 2020 | SP | Karonte: Detecting Insecure Multi-binary Interactions in Embedded Firmware. | Nilo Redini, Aravind Machiry, Ruoyu Wang, Chad Spensky, Andrea Continella, Yan Shoshitaishvili, Christopher Kruegel, Giovanni Vigna |
| 2019 | ACSAC | Sleak: automating address space layout derandomization. | Christophe Hauser, Jayakrishna Menon, Yan Shoshitaishvili, Ruoyu Wang, Giovanni Vigna, Christopher Kruegel |
| 2019 | CCS | Matched and Mismatched SOCs: A Qualitative Study on Security Operations Center Issues. | Faris Bugra Kokulu, Ananta Soneji, Tiffany Bao, Yan Shoshitaishvili, Ziming Zhao, Adam Doup, Gail-Joon Ahn |
| 2019 | DIMVA | BinTrimmer: Towards Static Binary Debloating Through Abstract Interpretation. | Nilo Redini, Ruoyu Wang, Aravind Machiry, Yan Shoshitaishvili, Giovanni Vigna, Christopher Kruegel |
| 2018 | ACSAC | Wi Not Calling: Practical Privacy and Availability Attacks in Wi-Fi Calling. | Jaejong Baek, Sukwha Kyung, Haehyun Cho, Ziming Zhao, Yan Shoshitaishvili, Adam Doup, Gail-Joon Ahn |
| 2018 | CCS | AIM-SDN: Attacking Information Mismanagement in SDN-datastores. | Vaibhav Hemant Dixit, Adam Doup, Yan Shoshitaishvili, Ziming Zhao, Gail-Joon Ahn |
| 2018 | CCS | CacheLight: Defeating the CacheKit Attack. | Mauricio Gutierrez, Ziming Zhao, Adam Doup, Yan Shoshitaishvili, Gail-Joon Ahn |
| 2018 | CCS | FEAST'18 - 2018 Workshop on Forming an Ecosystem around Software Transformation. | Yan Shoshitaishvili, Mayur Naik |
| 2018 | SP | A Binary Analysis Approach to Retrofit Security in Input Parsing Routines. | Jayakrishna Menon, Christophe Hauser, Yan Shoshitaishvili, Stephen Schwab |
| 2018 | SP | T-Fuzz: Fuzzing by Program Transformation. | Hui Peng, Yan Shoshitaishvili, Mathias Payer |
| 2017 | ACSAC | Piston: Uncooperative Remote Runtime Patching. | Christopher Salls, Yan Shoshitaishvili, Nick Stephens, Christopher Kruegel, Giovanni Vigna |
| 2017 | CCS | DIFUZE: Interface Aware Fuzzing for Kernel Drivers. | Jake Corina, Aravind Machiry, Christopher Salls, Yan Shoshitaishvili, Shuang Hao, Christopher Kruegel, Giovanni Vigna |
| 2017 | CCS | Rise of the HaCRS: Augmenting Autonomous Cyber Reasoning Systems with Human Assistance. | Yan Shoshitaishvili, Michael Weissbacher, Lukas Dresel, Christopher Salls, Ruoyu Wang, Christopher Kruegel, Giovanni Vigna |
| 2017 | NDSS | Ramblr: Making Reassembly Great Again. | Ruoyu Wang, Yan Shoshitaishvili, Antonio Bianchi, Aravind Machiry, John Grosen, Paul Grosen, Christopher Kruegel, Giovanni Vigna |
| 2017 | SP | Your Exploit is Mine: Automatic Shellcode Transplant for Remote Exploits. | Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, David Brumley |
| 2016 | NDSS | Driller: Augmenting Fuzzing Through Selective Symbolic Execution. | Nick Stephens, John Grosen, Christopher Salls, Andrew Dutcher, Ruoyu Wang, Jacopo Corbetta, Yan Shoshitaishvili, Christopher Kruegel, Giovanni Vigna |
| 2016 | RAID | Taming Transactions: Towards Hardware-Assisted Control Flow Integrity Using Transactional Memory. | Marius Muench, Fabio Pagani, Yan Shoshitaishvili, Christopher Kruegel, Giovanni Vigna, Davide Balzarotti |
| 2016 | SP | SOK: (State of) The Art of War: Offensive Techniques in Binary Analysis. | Yan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens, Mario Polino, Andrew Dutcher, John Grosen, Siji Feng, Christophe Hauser, Christopher Krgel, Giovanni Vigna |
| 2015 | NDSS | Firmalice - Automatic Detection of Authentication Bypass Vulnerabilities in Binary Firmware. | Yan Shoshitaishvili, Ruoyu Wang, Christophe Hauser, Christopher Kruegel, Giovanni Vigna |
| 2014 | DIMVA | PExy: The Other Side of Exploit Kits. | Giancarlo De Maio, Alexandros Kapravelos, Yan Shoshitaishvili, Christopher Kruegel, Giovanni Vigna |
| 2014 | RAID | Protecting Web-Based Single Sign-on Protocols against Relying Party Impersonation Attacks through a Dedicated Bi-directional Authenticated Secure Channel. | Yinzhi Cao, Yan Shoshitaishvili, Kevin Borgolte, Christopher Krgel, Giovanni Vigna, Yan Chen |
| 2014 | SAC | Do you feel lucky?: a large-scale analysis of risk-rewards trade-offs in cyber security. | Yan Shoshitaishvili, Luca Invernizzi, Adam Doup, Giovanni Vigna |
| 2012 | CCS | Blacksheep: detecting compromised hosts in homogeneous crowds. | Antonio Bianchi, Yan Shoshitaishvili, Christopher Kruegel, Giovanni Vigna |