SUCCESS Lab conducts research in network and systems security with the overarching goal of making cybersecurity intelligent, programmable, and ubiquitous. We combine systems and networking, program analysis, artificial intelligence, and security measurement to discover new vulnerabilities, understand emerging attack surfaces, and develop principled and practical defenses.
Our mission is to make computing and networking more secure.
- Intelligent Security — AI for Cybersecurity and Security for AI
- Programmable Security — Next-Generation Networks and Systems
- Ubiquitous Security — Pervasive and Emerging Computing Ecosystems
Intelligent Security
Artificial intelligence is transforming both cyber threats and cyber defense. We investigate how AI—including large language models (LLMs) and increasingly capable AI agents—can enable new approaches to vulnerability discovery, program analysis, threat reasoning, and automated defense. At the same time, we study the security and trustworthiness of AI-enabled systems, including models, agents, tools, skills, memory, execution environments, and the trust boundaries connecting AI reasoning to real-world actions.
From LipFuzzer to AI Agents: Semantic and Agentic Security
Our work on semantic security began before today’s LLM agents. LipFuzzer used linguistic knowledge to expose semantic misinterpretation in voice-assistant applications, demonstrating that a system can behave incorrectly even when speech recognition appears successful.
We now extend this line of thinking to agentic AI systems. Rather than treating an LLM as an isolated model, we study the full agent stack—prompts, memory, tools and skills, browsers, sandboxes, gateways, communication channels, and execution policies—to understand how cross-layer interactions create new attack surfaces and trust failures.
AI-Powered Vulnerability Discovery and Repair
FuzzingBrain explores how LLM reasoning can work with fuzzing, static analysis, program understanding, and automated repair to build autonomous cyber-reasoning systems. Developed for DARPA’s AI Cyber Challenge, the project demonstrates a practical path from AI-assisted analysis toward increasingly autonomous vulnerability discovery and patching.
Programmable Security
Modern network and system infrastructures are increasingly software-defined and programmable. We develop abstractions, architectures, and systems that make security a programmable property of the infrastructure itself, so that monitoring, policy, detection, and response can be expressed and enforced dynamically across networks, hosts, cloud and edge environments, programmable data planes, and next-generation communication systems.
From FRESCO and S2OS to SysFlow: Programmable Security Abstractions
This research thread has evolved across multiple generations of infrastructure. FRESCO introduced modular, composable security services for software-defined networks (SDN). S2OS broadened the idea into an SDI-defined Security OS that abstracts security capabilities across infrastructure layers. SysFlow carries the same principle into host and system security through a programmable framework for dynamic, fine-grained zero-trust control.
Programmable Data-Plane Security: Poseidon, Mew, Cerberus, and Heracles
Our programmable data-plane research moves security functions closer to where packets are processed. Poseidon uses programmable switches for volumetric DDoS mitigation; Mew enables large-scale and dynamically adaptable link-flooding defense; Cerberus supports efficient concurrent in-network monitoring; and Heracles studies new security risks introduced by adaptive memory mechanisms in data-plane defenses and develops corresponding mitigations.
NextSec: Securing 5G, 6G, and Beyond
NextSec is our broader research program on programmable, zero-trust, and verifiable security for next-generation wireless systems spanning the user-to-edge-to-cloud continuum. It explores security transformers, programmable security interfaces, composition and verification, and data-plane defenses.
A recent extension of this agenda targets semantic vulnerabilities in 5G baseband implementations: messages can be syntactically valid while violating specification-level relationships that drive implementations into unsafe states. This connects NextSec’s architectural vision with specification-aware vulnerability discovery in real 5G systems.
Ubiquitous Security
Computing is increasingly embedded throughout everyday devices, applications, platforms, and digital ecosystems. We study security problems that arise when functionality crosses boundaries among platforms, protocols, applications, devices, and users. Our work identifies new attack surfaces, develops scalable analysis techniques, and builds practical defenses for mobile, IoT, Web/PWA, Web3, voice-driven, and other emerging computing environments.
From Mobile-Web Boundaries to the Appified Web
Our work has long examined security failures created when application models cross platform boundaries. OSV-Free addressed origin-stripping vulnerabilities in hybrid mobile applications. Our Appified Web Security work then examined service workers as both a new attack surface and a programmable defensive mechanism, leading to tools such as SW-Scanner and the SWAPP security platform. More recent work continues this trajectory through modern web and progressive web application permission systems.
IoT, Edge, and Voice-Driven Ecosystems
We study how new interaction models and resource-constrained platforms reshape attack surfaces. Representative work includes understanding and detecting remote infection on Linux-based IoT devices, edge-assisted security mechanisms, Alexa skill ecosystems, and voice-driven applications. These efforts connect traditional systems-security principles with increasingly pervasive and human-facing computing environments.
Web3 Security: Trust and Risk in Decentralized Applications
Our Web3 research examines risks that arise in decentralized ecosystems where code, identity, financial value, and user trust interact. WIRE develops an integrated reputation engine for decentralized applications using behavioral properties, related-contract structure, machine learning, and explainable trust signals. Related work studies crypto-asset risks from leaked keys and normalization inconsistencies that facilitate homoglyph attacks.
Across all three research directions, we emphasize real-world problems, fundamental security insights, working systems, and measurable practical impact.
