InfoSec Research Group

Welcome to CURIOSITY!

CURIOSITY is a cybersecurity research group led by Prof. Zhenkai Liang at NUS.

Our research mainly focuses on system security, covering provenance, anomaly detection, trusted computing, Android malware detection, cyber range and attack replay, vulnerability detection and management, program analysis, fuzzing and testing, AI for security, etc.

Group Motto: Understanding systems, abstracting knowledge, and connecting facts.

理解系统,提炼知识,参悟规律。

research loop

Latest News

Jul 2024

🎉 Our recent work on cryptographic misuse detection is accepted in RAID'24!

Jun 2024

🎉 Our recent work on kernel vulnerability reproduction is accepted in RAID'24!

Jun 2024

🎉 Our VulZoo vulnerability intelligence dataset is released!

Apr 2024

🎉 Our group website is ready!

Feb 2024

🎉 Our recent work on evaluating disassemblers via dynamic tracing is accepted in NDSS BAR'24!

Aug 2023

🎉 Our recent work on detecting logic bugs in graph database engines is accepted in ICSE'24!

Selected Publications

Refer to this link for the full list of publications.

CrypTody: Cryptographic Misuse Analysis of IoT Firmware via Data-flow Reasoning

Jianing Wang, Shanqing Guo, Wenrui Diao, Yue Liu, Haixin Duan, Yichen Liu, Zhenkai Liang

In 27th International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2024).

KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities

Bonan Ruan, Jiahao Liu, Chuqi Zhang, Zhenkai Liang.

In 27th International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2024).

Detecting Logic Bugs in Graph Database Management Systems via Injective and Surjective Graph Query Transformation

Yuancheng Jiang, Jiahao Liu, Jinsheng Ba, Roland Yap, Zhenkai Liang, Manuel Rigger.

In Proceedings of the 46th IEEE/ACM International Conference on Software Engineering, 2024.

Learning Graph-based Code Representations for Source-level Functional Similarity Detection

Jiahao Liu*, Jun Zeng*, Xiang Wang and Zhenkai Liang.

In Proceedings of the 45th International Conference on Software Engineering, 2023.

PalanTír: Optimizing Attack Provenance with Hardware-enhanced System Observability

Jun Zeng*, Chuqi Zhang*, and Zhenkai Liang.

In Proceedings of the 29th ACM Conference on Computer and Communications Security, 2022.

FlowMatrix: GPU-Assisted Information-Flow Analysis through Matrix-Based Representation

Kaihang Ji, Jun Zeng, Yuancheng Jiang, Zhenkai Liang, Zheng Leong Chua, Prateek Saxena, and Abhik Roychoudhury

In Proceedings of the 31st USENIX Security Symposium, 2022.

Tell: Log Level Suggestions via Modeling Multi-level Code Block Information

Jiahao Liu, Jun Zeng, Xiang Wang, Kaihang Ji, and Zhenkai Liang.

In Proceedings of the 31st ACM SIGSOFT International Symposium on Software Testing and Analysis, 2022.

ShadeWatcher: Recommendation-guided Cyber Threat Analysis using System Audit Records

Jun Zeng, Xiang Wang, Jiahao Liu, Yinfang Chen, Zhenkai Liang, Tat-Seng Chua, and Zheng Leong Chua.

In Proceedings of the 43rd IEEE Symposium on Security and Privacy, 2022.

Watson: Abstracting Behaviors from Audit logs via Aggregation of Contextual Semantics

Jun Zeng, Zheng Leong Chua, Yinfang Chen, Kaihang Ji, Zhenkai Liang, and Jian Mao.

In Proceedings of the 28th Annual Network and Distributed System Security Symposium, 2021.