• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Home
  • People
  • News
  • Research
  • Publications
  • Releases
  • Resources
  • Contact Us

SUCCESS Lab

SUCCESS Lab

Texas A&M University College of Engineering

Research

Overview

SUCCESS Lab conducts research in network and systems security with the overarching goal of making cybersecurity intelligent, programmable, and ubiquitous. We combine systems and networking, program analysis, artificial intelligence, and security measurement to discover new vulnerabilities, understand emerging attack surfaces, and develop principled and practical defenses.

Our mission is to make computing and networking more secure.

  • Intelligent Security — AI for Cybersecurity and Security for AI
  • Programmable Security — Next-Generation Networks and Systems
  • Ubiquitous Security — Pervasive and Emerging Computing Ecosystems


Intelligent Security

Artificial intelligence is transforming both cyber threats and cyber defense. We investigate how AI—including large language models (LLMs) and increasingly capable AI agents—can enable new approaches to vulnerability discovery, program analysis, threat reasoning, and automated defense. At the same time, we study the security and trustworthiness of AI-enabled systems, including models, agents, tools, skills, memory, execution environments, and the trust boundaries connecting AI reasoning to real-world actions.

From LipFuzzer to AI Agents: Semantic and Agentic Security

OpenClaw AI-agent security architecture
Representative architecture for security analysis of an agentic AI framework.

Our work on semantic security began before today’s LLM agents. LipFuzzer used linguistic knowledge to expose semantic misinterpretation in voice-assistant applications, demonstrating that a system can behave incorrectly even when speech recognition appears successful.

We now extend this line of thinking to agentic AI systems. Rather than treating an LLM as an isolated model, we study the full agent stack—prompts, memory, tools and skills, browsers, sandboxes, gateways, communication channels, and execution policies—to understand how cross-layer interactions create new attack surfaces and trust failures.

LipFuzzer Project
OpenClaw Research

AI-Powered Vulnerability Discovery and Repair

FuzzingBrain automated vulnerability discovery and patching architecture
FuzzingBrain combines LLM reasoning with vulnerability discovery and patching workflows.

FuzzingBrain explores how LLM reasoning can work with fuzzing, static analysis, program understanding, and automated repair to build autonomous cyber-reasoning systems. Developed for DARPA’s AI Cyber Challenge, the project demonstrates a practical path from AI-assisted analysis toward increasingly autonomous vulnerability discovery and patching.

Paper
Software Release


Programmable Security

Modern network and system infrastructures are increasingly software-defined and programmable. We develop abstractions, architectures, and systems that make security a programmable property of the infrastructure itself, so that monitoring, policy, detection, and response can be expressed and enforced dynamically across networks, hosts, cloud and edge environments, programmable data planes, and next-generation communication systems.

From FRESCO and S2OS to SysFlow: Programmable Security Abstractions

SysFlow programmable zero-trust system security architecture
SysFlow extends programmable security concepts to fine-grained runtime system security.

This research thread has evolved across multiple generations of infrastructure. FRESCO introduced modular, composable security services for software-defined networks (SDN). S2OS broadened the idea into an SDI-defined Security OS that abstracts security capabilities across infrastructure layers. SysFlow carries the same principle into host and system security through a programmable framework for dynamic, fine-grained zero-trust control.

FRESCO Project
S2OS Project
SysFlow

Programmable Data-Plane Security: Poseidon, Mew, Cerberus, and Heracles

Cerberus in-network monitoring workflow on programmable switches
Cerberus enables efficient, adaptive in-network monitoring on programmable switches.

Our programmable data-plane research moves security functions closer to where packets are processed. Poseidon uses programmable switches for volumetric DDoS mitigation; Mew enables large-scale and dynamically adaptable link-flooding defense; Cerberus supports efficient concurrent in-network monitoring; and Heracles studies new security risks introduced by adaptive memory mechanisms in data-plane defenses and develops corresponding mitigations.

Cerberus
Tools & Releases

NextSec: Securing 5G, 6G, and Beyond

Recent NextG work uses specification-aware semantic testing to uncover 5G baseband vulnerabilities.

NextSec is our broader research program on programmable, zero-trust, and verifiable security for next-generation wireless systems spanning the user-to-edge-to-cloud continuum. It explores security transformers, programmable security interfaces, composition and verification, and data-plane defenses.

A recent extension of this agenda targets semantic vulnerabilities in 5G baseband implementations: messages can be syntactically valid while violating specification-level relationships that drive implementations into unsafe states. This connects NextSec’s architectural vision with specification-aware vulnerability discovery in real 5G systems.

NextSec Project
CONSET


Ubiquitous Security

Computing is increasingly embedded throughout everyday devices, applications, platforms, and digital ecosystems. We study security problems that arise when functionality crosses boundaries among platforms, protocols, applications, devices, and users. Our work identifies new attack surfaces, develops scalable analysis techniques, and builds practical defenses for mobile, IoT, Web/PWA, Web3, voice-driven, and other emerging computing environments.

From Mobile-Web Boundaries to the Appified Web

Service-worker attack surfaces in appified web applications
The Appified Web Security project studies service-worker attack surfaces and defenses.

Our work has long examined security failures created when application models cross platform boundaries. OSV-Free addressed origin-stripping vulnerabilities in hybrid mobile applications. Our Appified Web Security work then examined service workers as both a new attack surface and a programmable defensive mechanism, leading to tools such as SW-Scanner and the SWAPP security platform. More recent work continues this trajectory through modern web and progressive web application permission systems.

OSV-Free Project
Appified Web Security Project

IoT, Edge, and Voice-Driven Ecosystems

LipFuzzer aims to assess vApp’s problematic Intent Classifier at a large scale.

We study how new interaction models and resource-constrained platforms reshape attack surfaces. Representative work includes understanding and detecting remote infection on Linux-based IoT devices, edge-assisted security mechanisms, Alexa skill ecosystems, and voice-driven applications. These efforts connect traditional systems-security principles with increasingly pervasive and human-facing computing environments.

LipFuzzer Project
IoT Malware

Web3 Security: Trust and Risk in Decentralized Applications

WIRE evaluates decentralized applications using behavioral and structural signals to support risk assessment.

Our Web3 research examines risks that arise in decentralized ecosystems where code, identity, financial value, and user trust interact. WIRE develops an integrated reputation engine for decentralized applications using behavioral properties, related-contract structure, machine learning, and explainable trust signals. Related work studies crypto-asset risks from leaked keys and normalization inconsistencies that facilitate homoglyph attacks.

WIRE Paper
Tools & Releases


Across all three research directions, we emphasize real-world problems, fundamental security insights, working systems, and measurable practical impact.

Browse Publications
Software & Data Releases

© 2016–2026 SUCCESS Lab Log in

Texas A&M Engineering Experiment Station Logo
  • Opportunities
  • Prof. Gu’s Personal Website
  • Department of Computer Science & Engineering