UBC Security & Privacy Group
UBC Security & Privacy Group
People
Publications
Courses
Seminars
1
KAIROS: Practical Intrusion Detection and Investigation using Whole-system Provenance
Provenance graphs are structured audit logs that describe the history of a system’s execution. Recent studies have explored a …
Z Cheng
,
Q Lv
,
J Liang
,
Y Wang
,
D Sun
,
T Pasquier
,
X Han
PDF
Cite
Project
Turbo: Effective Caching in Differentially-Private Databases
The Adam optimizer is a popular choice in contemporary deep learning due to its strong empirical performance. However we observe that …
Q Tang
,
F Shpilevskiy
,
M Lécuyer
Preprint
Cite
Turbo: Effective Caching in Differentially-Private Databases
Differentially-private (DP) databases allow for privacy-preserving analytics over sensitive datasets or data streams. In these systems, …
K Kostopoulou
,
P Tholoniat
,
A Cidon
,
R Geambasu
,
M Lécuyer
Preprint
Cite
Unleashing Unprivileged eBPF Potential with Dynamic Sandboxing
For safety reasons, unprivileged users today have only limited ways to customize the kernel through the extended Berkeley Packet Filter …
SY Lim
,
X Han
,
T Pasquier
PDF
Cite
Project
Measuring the Effect of Training Data on Deep Learning Predictions via Randomized Experiments
We develop a new, principled algorithm for estimating the contribution of training data points to the behavior of a deep learning …
J Lin
,
A Zhang
,
M Lécuyer
,
J Li
,
A Panda
,
S Sen
Preprint
Cite
DP-Adam: Correcting DP Bias in Adam's Second Moment Estimation
We observe that the traditional use of DP with the Adam optimizer introduces a bias in the second moment estimation, due to the …
Q Tang
,
M Lécuyer
Preprint
Cite
Pacer: Comprehensive Network Side-Channel Mitigation in the Cloud
Network side channels (NSCs) leak secrets through packet timing and packet sizes. They are of particular concern in public IaaS Clouds, …
A Mehta
,
M Alzayat
,
R D Viti
,
B B Brandenburg
,
P Druschel
,
D Garg
PDF
Cite
Code
Secure Namespaced Kernel Audit for Containers
Despite the wide usage of container-based cloud computing, container auditing for security analysis relies mostly on built-in host …
SY Lim
,
B Stelea
,
X Han
,
T Pasquier
PDF
Cite
SIGL: Securing Software Installations Through Deep Graph Learning
Many users implicitly assume that software can only be exploited after it is installed. However, recent supply-chain attacks …
X Han
,
X Yu
,
T Pasquier
,
D Li
,
J Rhee
,
J Mickens
,
M Seltzer
,
C Haifeng
PDF
Cite
UNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats
Advanced Persistent Threats (APTs) are difficult to detect due to their low-and-slow attack patterns and frequent use of zero-day …
X Han
,
T Pasquier
,
A Bates
,
J Mickens
,
M Seltzer
PDF
Cite
«
»
Cite
×