Publications
Underlined are students advised by me.
[USENIX Sec'25] COLLISIONREPAIR: First-Aid and Automated Patching for Storage Collision Vulnerabilities in Smart Contracts
Yu Pan, Wanjing Han, Yue Duan, and Mu Zhang
In the 34th USENIX Security Symposium (USENIX Sec'25)
Seattle, WA, USA, August 2025.[CCS'25] Needle in a Haystack: Automated and Scalable Vulnerability Hunting in the Windows ALPC Sea
Haoyi Liu, Feng Dong, Yunpeng Tian, Mu Zhang, Xuefeng Li, Fangming Gu, Zhiniang Peng and Haoyu Wang
In The 32nd ACM Conference on Computer and Communications Security (CCS'25)
Taipei, Taiwan, October 2025.[CCS'25] Error Messages to Fuzzing: Detecting XPS Parsing Vulnerabilities in Windows Printing Components
Yunpeng Tian, Feng Dong, Junhai Wang, Mu Zhang, Zhiniang Peng, Zesen Ye, Xiapu Luo, and Haoyu Wang
In The 32nd ACM Conference on Computer and Communications Security (CCS'25)
Taipei, Taiwan, October 2025.[DSN'25] ICSTRACKER: Backtracking Intrusions in Modern Industrial Control Systems
Md Raihan Ahmed, Jainta Paul, Levi Taiji Li, Luis Garcia and Mu Zhang
In The 55th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN'25)
Naples, Italy, June 2025.[TIFS'25] DeepVMUnProtect: Neural Network-Based Recovery of VM-Protected Android Apps for Semantics-Aware Malware Detection
Xin Zhao, Mu Zhang, Xiaopeng Ke, Yu Pan, Yue Duan, Sheng Zhong and Fengyuan Xu
In IEEE Transactions on Information Forensics & Security (TIFS), Impact factor: 6.3, 2025.[FSE-LLMapp'25] A Systematic Threat Modeling of LLM Applications
Guanhong Tao, Siyuan Cheng, Zhuo Zhang, Junmin Zhu, Guangyu Shen, Wanjing Han, Mu Zhang, and Xiangyu Zhang
In The 1st International Workshop on LLM App Store Analysis (LLMapp), held in conjunction with the ACM International Conference on the Foundations of Software Engineering (FSE 2025)
Trondheim, Norway, June 2025.[ISSTA'24] WASMaker: Differential Testing of WebAssembly Runtimes via Semantic-aware Binary Generation
Shangtong Cao, Ningyu He, Xinyu She, Yixuan Zhang, Mu Zhang and Haoyu Wang
In The International Symposium on Software Testing and Analysis (ISSTA'24)
Vienna, Austria, September 2024.[NDSS'24] VetEOS: Statically Vetting EOSIO Contracts for the “Groundhog Day” Vulnerabilities
Levi Taiji Li, Ningyu He, Haoyu Wang and Mu Zhang
In The Network and Distributed System Security Symposium (NDSS’24)
San Diego, February 2024.[CCS-RICSS'24] Context-Aware Intrusion Detection in Industrial Control Systems
Md Raihan Ahmed and Mu Zhang
In The 2nd International Workshop on Re-design Industrial Control Systems with Security (RICSS), co-located with The 31th ACM Conference on Computer and Communications Security (CCS)
Salt Lake City, Utah, October 2024.[CCS-RICSS'24] Towards Cross-Physical-Domain Threat Inference for Industrial Control System Defense Adaptation
Jainta Paul, Lawrence Ponce, Mu Zhang and Luis Garcia
In The 2nd International Workshop on Re-design Industrial Control Systems with Security (RICSS), co-located with The 31th ACM Conference on Computer and Communications Security (CCS)
Salt Lake City, Utah, October 2024.[ISSTA'23] Automated Generation of Security-Centric Descriptions for Smart Contract Bytecode
Yu Pan, Zhichao Xu, Levi Taiji Li, Yunhe Yang and Mu Zhang
In ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA)
Seattle, July 2023.
ACM SIGSOFT Distinguished Paper (9/372 = 2%)[EuroS&P-RICSS'23] From Tactics to Techniques: A Systematic Attack Modeling for Advanced Persistent Threats in Industrial Control Systems
Yunhe Yang and Mu Zhang
In The 1st International Workshop on Re-design Industrial Control Systems with Security (Collocated with IEEE EuroS&P: 8th IEEE European Symposium on Security and Privacy)
Delft, Netherlands, July 2023.[AsiaCCS'23] Arvin: Greybox Fuzzing Using Approximate Dynamic CFG Analysis
Sirus Shahini, Mu Zhang, Mathias Payer and Robert Ricci
The 18th ACM ASIA Conference on Computer and Communications Security
Melbourne, Australia, July 2023.[RAID'22] Automated Runtime Mitigation for Misconfiguration Vulnerabilities in Industrial Control Systems
Qingzhao Zhang, Xiao Zhu, Mu Zhang, and Z. Morley Mao
In the 25th International Symposium on Research in Attacks, Intrusions and Defenses
Limassol, Cyprus, October 2022.[CCS'22] Towards Automated Safety Vetting of Smart Contracts in Decentralized Applications
Yue Duan, Xin Zhao, Yu Pan, Shucheng Li, Minghao Li, Fengyuan Xu and Mu Zhang
In ACM Conference on Computer and Communications Security
Los Angeles, November 2022.
Best Paper Honorable Mention (20/972 = 2%)[SC-Correctness'20] Correctness-preserving Compression of Datasets and Neural Network Models
Nithin Chalapathi, Vinu Joseph, Aditya Bhaskara, Mu Zhang, Pavel Panchekha, Ganesh Gopalakrishnan
In Fourth International Workshop on Software Correctness for HPC Applications (Collocated with SC20: The International Conference for High Performance Computing, Networking, Storage and Analysis)
Virtual Event, Atlanta, Georgia, November 2020
Jiaping Gui, Ding Li, Zhengzhang Chen, Junghwan Rhee, Xusheng Xiao, Mu Zhang, Kangkook Jee, Zhichun Li and Haifeng Chen
In 36th IEEE International Conference on Data Engineering (Industry and Application Track)
Dallas, Texas, April 2020.
Joseph P. Near, David Darais, Chike Abuah, Tim Stevens, Pranav Gaddamadugu, Lun Wang, Neel Somani, Mu Zhang, Nikhil Sharma, Alex Shan, Dawn Song
In ACM SIGPLAN International Conference on Object-Oriented Programming, Systems, Languages, and Applications
Athens, Greece, October 2019.
ACM SIGPLAN Distinguished Paper Award
Mu Zhang, Chien-Ying Chen, Bin-Chou Kao, Yassine Qamsane, Yuru Shao, Yikai Lin, Elaine Shi, Sibin Mohan, Kira Barton, James Moyne, Z. Morley Mao
In 40th IEEE Symposium on Security and Privacy (Acceptance Ratio: 12%)
San Francisco, CA, May 2019.
Yutao Tang, Ding Li, Zhichun Li, Mu Zhang, Kangkook Jee, Xusheng Xiao, Zhenyu Wu, Junghwan Rhee, Fengyuan Xu, Qun Li
In the 25th ACM Conference on Computer and Communications Security (Acceptance Ratio: 16.6%)
Toronto, Canada, October 2018.
Yushan Liu*, Mu Zhang*, Ding Li, Kangkook Jee, Zhichun Li, Zhenyu Wu, Junghwan Rhee, Prateek Mittal
In 2018 Network and Distributed System Security Symposium (Acceptance Ratio: 21.5%)
San Diego, CA, February 2018.
*This work was conducted when the first author was an intern at NEC Labs, mentored by me, who was a Research Staff Member at NEC.
Yue Duan, Mu Zhang, Abhishek Vasisht Bhaskar, Heng Yin, Xiaorui Pan, Tongxin Li, Xueqiang Wang, XiaoFeng Wang
In 2018 Network and Distributed System Security Symposium (Acceptance Ratio: 21.5%)
San Diego, CA, February 2018.
Qian Feng, Minghua Wang, Mu Zhang, Rundong Zhou, Andrew Henderson and Heng Yin
In ACM Asia Conference on Computer and Communications Security
Abu Dhabi, UAE, April 2017.
Mu Zhang and Heng Yin
SpringerBriefs in Computer Science
September 2016
Curtis Carmony, Mu Zhang, Xunchao Hu, Abhishek Vasisht Bhaskar and Heng Yin
In 2016 Network and Distributed System Security Symposium (Acceptance Ratio: 15.4%)
San Diego, CA, February 2016.
Mu Zhang, Yue Duan, Qian Feng and Heng Yin
In the 22nd ACM Conference on Computer and Communications Security (Acceptance Ratio: 19.3%) [Slides]
Denver, Colorado, October 2015.
Yue Duan, Mu Zhang, Heng Yin and Yuzhe Tang
In The 7th USENIX Workshop on Hot Topics in Cloud Computing
Santa Clara, CA, July 2015.
[CCS'14] Semantics-Aware Android Malware Classification Using Weighted Contextual API Dependency Graphs
Mu Zhang, Yue Duan, Heng Yin and Zhiruo Zhao
In the ACM Conference on Computer and Communications Security (Acceptance Ratio: 19.5%) [Slides]
Scottsdale, Arizona, USA, November 2014.
Mu Zhang and Heng Yin
In the 21st Annual Network & Distributed System Security Symposium (Acceptance Ratio: 18.6%) [Slides]
San Diego, CA, February 2014.
[ASIACCS'14] Efficient, Context-Aware Privacy Leakage Confinement for Android Applications without Firmware Modding
Mu Zhang and Heng Yin
In the 9th ACM Symposium on Information, Computer and Communications Security
Kyoto, Japan, June 2014.
Lok-Kwong Yan, Manjukumar Jayachandra, Mu Zhang, and Heng Yin
In the Eighth Annual International Conference on Virtual Execution Environments
London, UK, March 2012.
Patents
Template based data reduction for security related information flow data
Ding Li, Kangkook Jee, Zhichun Li, Mu Zhang, Zhenyu Wu
US Patent 10,733,149
August 4, 2020
Security monitoring with progressive behavioral query language databases
Xusheng Xiao, Zhichun Li, Mu Zhang, Guofei Jiang, Jiaping Gui, Ding Li
US Patent 10,831,750
November 10, 2020
Progressive processing for querying system behavior
Xusheng Xiao, Zhichun Li, Mu Zhang, Guofei Jiang, Jiaping Gui
US Patent 10,885,027
January 5, 2021