We (myself, @michaelmarcozzi, Stefano Zacchiroli, Emilien Decoux) release the ROSA toolchain, enabling fuzzing-based backdoor detection 🎉
Tool: https://t.co/UXn25CW6st
Benchmark: https://t.co/UXc5POkpYw
This work received both Available & Reusable badges at @ICSEconf 🥳
How to detect backdoors efficiently?
▶️ Backdoors were found in firmware & open-source code
▶️ Detection requires much manual reverse-engineering
▶️ Fuzzers cannot see backdoors
Our @ICSEconf preprint on finding backdoors with fuzzing is at https://t.co/AsuqAxgvoE
A thread ⬇️
Finding backdoors in software is like hunting for a needle that’s actively trying to hide. 🪡🕵️
Check out our @fosdem talk with @plumtrie on using fuzzing to automate the search!
📺 Watch: https://t.co/jAjuugW2ic
📜 ICSE Paper: https://t.co/NUOF7zCtQn
Proud that our latest work on black-box deobfuscation has just been accepted to @acm_ccs 2025!
Title: "Augmenting Search-based Program Synthesis with Local Inference Rules to Improve Black-box Deobfuscation".
Joint work with @grmenguy Vidal_Attias Nicolas_Bellec and @Jean_YvesMarion
Stay tuned for the camera ready version!
Back from @PLDI 2025, where Frédéric Recoules and I had the pleasure to give a tutorial on BINSEC and binary-level symbolic execution. Here it is, playable in your browser: https://t.co/pUUw41V8eR
Happy to have presented our SECUBIC project to the French research community in system security (RESSI'25)!
🏠 https://t.co/aafO9G0s9x
🧑🔬 @Seb_Bardin@Jean_YvesMarion Stefano Zacchiroli
Thanks to the RESSI organizers who had even provided a pool to finish my #OOPSLA reviews! 😇
Check out our ROSARUM benchmark, part of our #icse2025 paper on backdoors and fuzzing:
▶️ It is a fuzzing benchmark (can fuzzers trigger backdoors reliably and fast?)
▶️ It is a backdoor detection benchmark (can code analyses find backdoors reliably?)
⬇️ https://t.co/heJyRbRVib
How to detect backdoors efficiently?
🗣️ The slides of our #icse2025 presentation on "Finding Backdoors with Fuzzing" are now available at
⬇️ https://t.co/6DOvrsk3vY
11am today at #ICSE2025: Rust provides memory safety to low-level code, but in practice Rust libraries link to unsafe C. @icmccorm, @joshsunshine, and I used dynamic analysis to find 46 cases where the C code broke Rust's memory rules, causing undefined behavior.
Very honored to receive the Best Artifact award at #icse2025 🥳
Congrats and thank you to my coauthors! @michaelmarcozzi, Emilien Decoux, Stefano Zacchiroli
Too many bugs in the queue, not enough time to fix them all? Happy to share that our work on automated bug priorization has been accepted at @USENIXSecurity 2025 -- joint work with Guilhem Lacombe https://t.co/ZiE5pimLfx
How to detect backdoors efficiently?
▶️ Backdoors were found in firmware & open-source code
▶️ Detection requires much manual reverse-engineering
▶️ Fuzzers cannot see backdoors
Our @ICSEconf preprint on finding backdoors with fuzzing is at https://t.co/AsuqAxgvoE
A thread ⬇️
📢 I am looking for a postdoc on fuzzing, to prevent backdoors and supply-chain attacks!
Come and join the team here in Paris (or spread the word)! 🙂
Details and application: https://t.co/mi71a6UDeE
🏆 Our ROSA tool for backdoor detection has won a best artifact award at @ICSEconf!
Try it out: https://t.co/kKrreOlERn
Huge thanks and congrats to my student @plumtrie for his huge and great work! 👏👏👏
Happy to read such enthusiastic reactions to our @ICSEconf paper! ☺️
"ROSA Sets a New Standard for Backdoor Detection."
"If you work in cybersecurity, penetration testing, or software auditing, ROSA is a must-try in the fight against hidden threats."
https://t.co/L5zK9tAy9h