Readings
Paper Response Guidelines
Write a ~400 word critical response and comments to each required paper. Focus on the following:
- State the problem that they try to solve and the main contributions.
- Describe the key insight or novelty of their proposed work or approach.
- What are the weakness/limitations of the paper? Write the criticisms.
- Any improvements or related ideas that you can suggest?
Your most important task is to demonstrate that you've read the paper and thought carefully about the topic. No copy and paste of the original paper text!
Paper responses are due before the start of class via Canvas Assignments.
Discussion Lead and Bonus
Please take a look at the papers in each session. If you are interested in leading the discussion of any session, you should sign up on the sign-up sheet in Canvas and get a bonus for waiving 3 paper summaries.As a discussion lead, two tasks are expected: 1) You will provide a 20-min presentation of the paper that will be discussed in class with slides. 2) You should prepare yourself by reading the technical details carefully and coming up with a list of discussion points. The discussion points should be designed to engage students in critical and creative thinking. Think about the points ahead of time and be prepared to answer questions other students may throw at you.
Send ahead of time your discussion points to me on Canvas and get feedback from me. Please allow 2 days to receive the feedback. This will be a good opportunity for you to learn to discuss ideas around a research topic and it generally helps your presentation/communication skills.
Reading List
Most papers should be publicly accessible. If any links are broken, please search for them. If any of them require paid subscription, you can access them for free when connecting on campus. For off-campus access, try UCI VPN.
Week 1
Monday, September 28
Wednesday, September 30 - Security Mindset
- The Security Mindset, Bruce Schneier. 2008. -- No summary required; Just read this and come to class
Week 2
Monday, October 5 - Software Security I
- Smashing the Stack for Fun and Profit. Aleph One. Phrack 49(14), Nov. 1996. -- No summary required; Just read this and come to class
Wednesday, October 7 - Software Security II
- StackGuard: Automatic Adaptive Detection and Prevention of Buffer-Overflow Attacks. Cowan, Pu, Maier, Hinton, Walpole, Bakke, Beattie, Grier, Wagle, and Zhang. Usenix Security 1998.
- On the Effectiveness of Address-Space Randomization. Shacham, Page, Pfaff, Goh, Modadugu, and Boneh. CCS 2004.
- A First Step Towards Automated Detection of Buffer Overrun Vulnerabilities, Wagner, Foster, Brewer, and Aiken. NDSS 2000
Week 3
Monday, October 12
- Form your project group by today!
- Alfred is travelling. No class!
Wednesday, October 14 - Guest Lecture: Software Security, Prof. Joshua Garcia (Informatics)
- No readings!
- Recommended readings TBD
Week 4
Monday, October 19 – Software Security III
- The Geometry of Innocent Flesh on the Bone: Return-into-libc without Function Calls (on the x86). Hovav Shacham. CCS 2007.
- Control Flow Integrity for COTS Binaries. Zhang and Sekar. Usenix Security 2013.
- N-Variant Systems: A Secretless Framework for Security through Diversity, Cox, Evans, Filipi, Rowanhill, Hu, Davidson, Knight, Nguyen-Tuong, Hiser. USENIX Security 2006
- Modular Control-Flow Integrity. Niu and Tan. PLDI 2014.
Wednesday, October 21 – Smartphone Systems Security
- Peeking into Your App without Actually Seeing It: UI State Inference and Novel Android Attacks. Chen, Qian, and Mao. Usenix Security 2014.
- What the App is That? Deception and Countermeasures in the Android User Interface. Bianchi, Corbetta, Invernizzi, Fratantonio, Kruegel, and Vigna. IEEE S&P 2015.
- Cloak and Dagger: From Two Permissions to Complete Control of the UI Feedback Loop. Fratantonio, Qian, Chung, and Lee. IEEE S&P 2017.
Week 5
Monday, October 26 – IoT/CPS Systems Security
- An Experimental Security Analysis of an Industrial Robot Controller. Quarta, Pogliani, Polino, Maggi, Zanchettin, and Zanero. IEEE S&P 2017.
- Plug-N-Pwned: Comprehensive Vulnerability Analysis of OBD-II Dongles as A New Over-the-Air Attack Surface in Automotive IoT. Wen, Chen, and Lin. Usenix Security 2020.
- Comprehensive Experimental Analyses of Automotive Attack Surfaces. Checkoway, McCoy, Kantor, Anderson, Shacham, Savage, Koscher, Czeskis, Roesner, and Kohno. Usenix Security 2011.
- Experimental Security Analysis of a Modern Automobile. Koscher, Czeskis, Roesner, Patel, Kohno, Checkoway, McCoy, Kantor, Anderson, Shacham, and Savage. IEEE S&P 2010.
- Remote Exploitation of an Unaltered Passenger Vehicle. Miller and Valasek. DEF CON 23, Aug. 2015.
Wednesday, October 28 – Pre-Proposal Presentation
- No readings!
Week 6
Monday, November 2 – AI Security I
- Adversarial Examples Are Not Bugs, They Are Features. Ilyas, Santurkar, Tsipras, Engstrom, Tran, and Madry. NeurIPS 2019.
- On Adaptive Attacks to Adversarial Example Defenses. Tramer, Carlini, Brendel, and Madry. NeurIPS 2020.
- Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples. Athalye, Carlini, and Wagner. ICML 2018.
- Towards Evaluating the Robustness of Neural Networks. Carlini, and Wagner. IEEE S&P 2017.
- Intriguing properties of neural networks. Szegedy, Zaremba, Sutskever, Bruna, Erhan, Goodfellow, and Fergus. arXiv:1312.6199, 2013.
Wednesday, November 4 – AI Security II
- Written proposal due!
- FlyTrap: Physical Distance-Pulling Attack Towards Camera-based Autonomous Target Tracking Systems. Xie, Fakih, Lu, Alshammari, Wang, Sato, Bouzidi, Al Faruque, and Chen. NDSS 2026.
- Revisiting Physical-World Adversarial Attack on Traffic Sign Recognition: A Commercial Systems Perspective. Wang, Xie, Sato, Luo, Xu, and Chen. NDSS 2025.
- On the Realism of LiDAR Spoofing Attacks against Autonomous Driving Vehicle at High Speed and Long Distance. Sato, Suzuki, Hayakawa, Ikeda, Sako, Nagata, Yoshida, Chen, and Yoshioka. NDSS 2025.
- Invisible in both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World Attacks. Cao, Wang, Xiao, Yang, Fang, Yang, Chen, Liu, and Li. IEEE S&P 2021.
- Robust Physical-World Attacks on Deep Learning Visual Classification. Eykholt, Evtimov, Fernandes, Li, Rahmati, Xiao, Prakash, Kohno, and Song. CVPR 2018.
Week 7
Monday, November 9 – AI Security III
- PatchCURE: Improving Certifiable Robustness, Model Utility, and Computation Efficiency of Adversarial Patch Defenses. Xiang, Wu, Dai, Petit, Jana, and Mittal. Usenix Security 2024.
- DorPatch: Distributed and Occlusion-Robust Adversarial Patch to Evade Certifiable Defenses. He, Ma, Zhu, Zeng, Hu, Bai, Jin, and Zhang. NDSS 2024.
- That Person Moves Like A Car: Misclassification Attack Detection for Autonomous Systems Using Spatiotemporal Consistency. Man, Muller, Li, Celik, and Gerdes. Usenix Security 2023.
- Towards Robust LiDAR-based Perception in Autonomous Driving: General Black-box Adversarial Sensor Attack and Countermeasures. Sun, Cao, Chen, and Mao. Usenix Security 2020.
- Distillation as a Defense to Adversarial Perturbations against Deep Neural Networks. Papernot, McDaniel, Wu, Jha and Swami. IEEE S&P 2016.
Wednesday, November 11
No class! Enjoy the Veterans Day!Week 8
Monday, November 16 – Guest Lecture: Sensor Security & CPS, Dr. Sri Hrushikesh Varma Bhupathiraju (CS)
- No readings!
- Recommended readings TBD
Wednesday, November 18 – Guest Lecture: Prompt Injection Attacks, Xiaoqing Liang & Junchi Lu (CS)
- No readings!
- Recommended readings TBD
Week 9
Monday, November 23 – AI Security IV
- TBD
- POEX: Understanding and Mitigating Policy Executable Jailbreak Attacks against Embodied AI. Lu, Huang, Li, Ji, and Xu. arXiv:2412.16633, 2024.
- Stateful Defenses for Machine Learning Models Are Not Yet Secure Against Black-box Attacks. Feng, Hooda, Mangaokar, Fawaz, Jha, and Prakash. ACM CCS 2023.
- Blacklight: Scalable Defense for Neural Networks against Query-Based Black-Box Attacks. Li, Shan, Wenger, Zhang, Zheng and Zhao. Usenix Security 2022.
- Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural Networks. Wang, Yao, Shan, Li, Viswanath, Zheng, and Zhao. IEEE S&P 2019.
- Certified Robustness to Adversarial Examples with Differential Privacy. Lecuyer, Atlidakis, Geambasu, Hsu, and Jana. IEEE S&P 2019.
- Formal Security Analysis of Neural Networks using Symbolic Intervals. Wang, Pei, Whitehouse, Yang, and Jana. Usenix Security 2018.
Wednesday, November 25 - Physical Security
- An Introduction to Lock Picking: How to Pick Pin Tumbler Locks -- No summary required; Just read this and come to class
- Reconsidering Physical Key Secrecy: Teleduplication via Optical Decoding. Laxton, Wang, and Savage. CCS, 2008.
- Cryptology and Physical Security: Rights Amplification in Master-Keyed Mechanical Locks. Matt Blaze. IEEE Security and Privacy, 2003.
- Security Analysis of a Widely Deployed Locking System. Weiner, Massar, Tews, Giese, and Wieser. CCS 2013.
Week 10
Monday, November 30 – Project Presentation
- No readings!
Wednesday, December 2 – Project Presentation
- No readings!