{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T15:54:08Z","timestamp":1783007648012,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":51,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,4,12]],"date-time":"2024-04-12T00:00:00Z","timestamp":1712880000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,4,12]]},"DOI":"10.1145\/3597503.3639158","type":"proceedings-article","created":{"date-parts":[[2024,4,12]],"date-time":"2024-04-12T16:43:26Z","timestamp":1712940206000},"page":"1-12","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["Semantic-Enhanced Static Vulnerability Detection in Baseband Firmware"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-3389-513X","authenticated-orcid":false,"given":"Yiming","family":"Liu","sequence":"first","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"},{"name":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"},{"name":"Key Laboratory of Network Assessment Technology, Chinese Academy of Sciences, Beijing, China"},{"name":"Beijing Key Laboratory of Network Security and Protection Technology, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5603-1322","authenticated-orcid":false,"given":"Cen","family":"Zhang","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-2126-663X","authenticated-orcid":false,"given":"Feng","family":"Li","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"},{"name":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"},{"name":"Key Laboratory of Network Assessment Technology, Chinese Academy of Sciences, Beijing, China"},{"name":"Beijing Key Laboratory of Network Security and Protection Technology, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0991-4231","authenticated-orcid":false,"given":"Yeting","family":"Li","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"},{"name":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"},{"name":"Key Laboratory of Network Assessment Technology, Chinese Academy of Sciences, Beijing, China"},{"name":"Beijing Key Laboratory of Network Security and Protection Technology, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-3092-5527","authenticated-orcid":false,"given":"Jianhua","family":"Zhou","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"},{"name":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"},{"name":"Key Laboratory of Network Assessment Technology, Chinese Academy of Sciences, Beijing, China"},{"name":"Beijing Key Laboratory of Network Security and Protection Technology, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-8212-2907","authenticated-orcid":false,"given":"Jian","family":"Wang","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"},{"name":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"},{"name":"Key Laboratory of Network Assessment Technology, Chinese Academy of Sciences, Beijing, China"},{"name":"Beijing Key Laboratory of Network Security and Protection Technology, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-6572-8819","authenticated-orcid":false,"given":"Lanlan","family":"Zhan","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"},{"name":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"},{"name":"Key Laboratory of Network Assessment Technology, Chinese Academy of Sciences, Beijing, China"},{"name":"Beijing Key Laboratory of Network Security and Protection Technology, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7300-9215","authenticated-orcid":false,"given":"Yang","family":"Liu","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-7121-1196","authenticated-orcid":false,"given":"Wei","family":"Huo","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"},{"name":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"},{"name":"Key Laboratory of Network Assessment Technology, Chinese Academy of Sciences, Beijing, China"},{"name":"Beijing Key Laboratory of Network Security and Protection Technology, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,4,12]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2666356.2594299"},{"key":"e_1_3_2_1_2_1","volume-title":"2019 USENIX Annual Technical Conference (USENIX ATC 19)","author":"Bai Jia-Ju","year":"2019","unstructured":"Jia-Ju Bai, Julia Lawall, Qiu-Liang Chen, and Shi-Min Hu. 2019. Effective static analysis of concurrency {Use-After-Free} bugs in linux device drivers. In 2019 USENIX Annual Technical Conference (USENIX ATC 19). 255--268."},{"key":"e_1_3_2_1_3_1","volume-title":"Steven and Ewan Klein","author":"Bird Edward Loper","year":"2009","unstructured":"Edward Loper Bird, Steven and Ewan Klein. 2009. Natural Language Processing with Python. O'Reilly Media Inc. https:\/\/github.com\/nltk\/nltk."},{"key":"e_1_3_2_1_4_1","unstructured":"BVFinder. 2023. BVFinder-Data. https:\/\/sites.google.com\/view\/bvfinder-data."},{"key":"e_1_3_2_1_5_1","unstructured":"A. Cama. 2018. A walk with Shannon."},{"key":"e_1_3_2_1_6_1","unstructured":"Anna Dorfman Charles Muiruri Nitay Artenstein. 2018. The Baseband Basics: Understanding Debugging and Attacking the Mediatek Communication Processor. https:\/\/kenya.opcde.com\/speakers.html."},{"key":"e_1_3_2_1_7_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Chen Libo","year":"2021","unstructured":"Libo Chen, Yanhao Wang, Quanpu Cai, Yunfan Zhan, Hong Hu, Jiaqi Linghu, Qinsheng Hou, Chao Zhang, Haixin Duan, and Zhi Xue. 2021. Sharing more and checking less: Leveraging common input keywords to detect bugs in embedded systems. In 30th USENIX Security Symposium (USENIX Security 21). 303--319."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00104"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2018.00052"},{"key":"e_1_3_2_1_10_1","volume-title":"Hot Chips Symposium. 1--23","author":"Lucian","unstructured":"Lucian Codrescu et al. 2013. Qualcomm Hexagon DSP: An architecture optimized for mobile multimedia and communications.. In Hot Chips Symposium. 1--23."},{"key":"e_1_3_2_1_11_1","volume-title":"29th USENIX security symposium (USENIX Security 20). 2379--2396.","author":"Elsabagh Mohamed","unstructured":"Mohamed Elsabagh, Ryan Johnson, Angelos Stavrou, Chaoshun Zuo, Qingchuan Zhao, and Zhiqiang Lin. 2020. {FIRMSCOPE}: Automatic uncovering of {Privilege-Escalation} vulnerabilities in {Pre-Installed} apps in android firmware. In 29th USENIX security symposium (USENIX Security 20). 2379--2396."},{"key":"e_1_3_2_1_12_1","unstructured":"FIRMWIRE. 2022. FIRMWIRE-Dataset. https:\/\/zenodo.org\/record\/6516030\/."},{"key":"e_1_3_2_1_13_1","unstructured":"FirmWire. 2022. FirmWire-Ghidra. https:\/\/github.com\/FirmWire\/ghidra."},{"key":"e_1_3_2_1_14_1","unstructured":"Nico Golde and Daniel Komaromy. 2016. Breaking Band: reverse engineering and exploiting the shannon baseband."},{"key":"e_1_3_2_1_15_1","unstructured":"Marius Muench Grant Hernandez. 2020. Reversing & Emulating Samsung's Shannon Baseband. https:\/\/hardwear.io\/netherlands-2020\/presentation\/samsung-baseband-hardwear-io-nl-2020.pdf."},{"key":"e_1_3_2_1_16_1","volume-title":"Exploitation of a modern smartphone baseband. Black Hat USA","author":"Grassi Marco","year":"2018","unstructured":"Marco Grassi, Muqing Liu, and Tianyi Xie. 2018. Exploitation of a modern smartphone baseband. Black Hat USA (2018)."},{"key":"e_1_3_2_1_17_1","unstructured":"GSMA. 2022. The mobile economy. https:\/\/www.gsma.com\/mobileeconomy\/wp-content\/uploads\/2022\/02\/280222-The-Mobile-Economy-2022.pdf."},{"key":"e_1_3_2_1_18_1","volume-title":"WASA 2014, Harbin, China, June 23--25, 2014. Proceedings 9. Springer, 624--635","author":"Hahn Changhee","year":"2014","unstructured":"Changhee Hahn, Hyunsoo Kwon, Daeyoung Kim, Kyungtae Kang, and Junbeom Hur. 2014. A privacy threat in 4th generation mobile telephony and its countermeasure. In Wireless Algorithms, Systems, and Applications: 9th International Conference, WASA 2014, Harbin, China, June 23--25, 2014. Proceedings 9. Springer, 624--635."},{"key":"e_1_3_2_1_19_1","unstructured":"Grant Hernandez. 2020. ShannonBaseband. https:\/\/github.com\/grant-h\/ShannonBaseband."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23136"},{"key":"e_1_3_2_1_21_1","unstructured":"Hex-Rays. [n. d.]. IDA PRO. https:\/\/www.hex-rays.com\/products\/ida.."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23313"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354263"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485388"},{"key":"e_1_3_2_1_25_1","volume-title":"The distribution of the flora in the alpine zone. 1. New phytologist 11, 2","author":"Jaccard Paul","year":"1912","unstructured":"Paul Jaccard. 1912. The distribution of the flora in the alpine zone. 1. New phytologist 11, 2 (1912), 37--50."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS51616.2021.00079"},{"key":"e_1_3_2_1_27_1","unstructured":"KeenSecurityLab. 2022. BinAbsInspector. https:\/\/github.com\/KeenSecurityLab\/BinAbsInspector."},{"key":"e_1_3_2_1_28_1","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Kim Eunsoo","year":"2023","unstructured":"Eunsoo Kim, Min Woo Baek, CheolJun Park, Dongkwan Kim, Yongdae Kim, and Insu Yun. 2023. {BASECOMP}: A Comparative Analysis for Integrity Protection in Cellular Baseband Software. In 32nd USENIX Security Symposium (USENIX Security 23). 3547--3563."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"crossref","unstructured":"Eunsoo Kim Dongkwan Kim CheolJun Park Insu Yun and Yongdae Kim. 2021. BaseSpec: Comparative Analysis of Baseband Software and Cellular Specifications for L3 Protocols.. In NDSS.","DOI":"10.14722\/ndss.2021.24365"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00038"},{"key":"e_1_3_2_1_31_1","unstructured":"Kira M. Grassi. 2020. Exploring the MediaTek baseband. https:\/\/speakerdeck.com\/marcograss\/exploring-the-mediatek-baseband."},{"key":"e_1_3_2_1_32_1","volume-title":"26th USENIX Security Symposium (USENIX Security 17)","author":"Machiry Aravind","year":"2017","unstructured":"Aravind Machiry, Chad Spensky, Jake Corina, Nick Stephens, Christopher Kruegel, and Giovanni Vigna. 2017. {DR}.{CHECKER}: A soundy analysis for linux kernel drivers. In 26th USENIX Security Symposium (USENIX Security 17). 1007--1024."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3395351.3399360"},{"key":"e_1_3_2_1_34_1","unstructured":"Mediatek. 2023. Product Security Bulletin. https:\/\/corp.mediatek.com\/product-security-bulletin."},{"key":"e_1_3_2_1_35_1","volume-title":"USENIX Security Symposium","volume":"168","author":"Mulliner Collin","year":"2011","unstructured":"Collin Mulliner, Nico Golde, and Jean-Pierre Seifert. 2011. SMS of Death: From Analyzing to Attacking Mobile Phones on a Large Scale.. In USENIX Security Symposium, Vol. 168. San Francisco, CA."},{"key":"e_1_3_2_1_36_1","first-page":"31","article-title":"Fuzzing the Phone in your Phone","volume":"25","author":"Mulliner Collin","year":"2009","unstructured":"Collin Mulliner and Charlie Miller. 2009. Fuzzing the Phone in your Phone. Black Hat USA 25 (2009), 31.","journal-title":"Black Hat USA"},{"key":"e_1_3_2_1_37_1","unstructured":"NSA. 2019. Ghidra. https:\/\/github.com\/NationalSecurityAgency\/ghidra."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2021.108137"},{"key":"e_1_3_2_1_39_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Park CheolJun","year":"2022","unstructured":"CheolJun Park, Sangwook Bae, BeomSeok Oh, Jiho Lee, Eunkyu Lee, Insu Yun, and Yongdae Kim. 2022. {DoLTEst}: In-depth Downlink Negative Testing Framework for {LTE} Devices. In 31st USENIX Security Symposium (USENIX Security 22). 1325--1342."},{"key":"e_1_3_2_1_40_1","unstructured":"Qualcomm. 2023. Hexagon DSP SDK. https:\/\/developer.qualcomm.com\/forums\/software\/hexagon-dsp-hlos."},{"key":"e_1_3_2_1_41_1","unstructured":"Qualcomm. 2023. Qualcomm Product Security. https:\/\/www.qualcomm.com\/company\/product-security."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00036"},{"key":"e_1_3_2_1_43_1","volume-title":"10th USENIX Workshop on Offensive Technologies (WOOT 16)","author":"Rupprecht David","year":"2016","unstructured":"David Rupprecht, Kai Jansen, and Christina P\u00f6pper. 2016. Putting {LTE} security functions to the test: A framework to evaluate implementation correctness. In 10th USENIX Workshop on Offensive Technologies (WOOT 16)."},{"key":"e_1_3_2_1_44_1","unstructured":"SamMobile. 2023. Download firmware updates for your Samsung mobile phone and tablet. https:\/\/sammobile.com\/firmwares"},{"key":"e_1_3_2_1_45_1","unstructured":"Samsungmobile. 2023. Samsung Mobile Security. https:\/\/security.samsungmobile.com\/main.smsb."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.17"},{"key":"e_1_3_2_1_47_1","unstructured":"Siemens. 2023. Nucleus RTOS. https:\/\/www.plm.automation.siemens.com\/global\/en\/products\/embedded\/nucleus-rtos.html."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2015.2404336"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3183575"},{"key":"e_1_3_2_1_50_1","volume-title":"Baseband Attacks: Remote Exploitation of Memory Corruptions in Cellular Protocol Stacks.. In WOOT. 12--21.","author":"Weinmann Ralf-Philipp","year":"2012","unstructured":"Ralf-Philipp Weinmann. 2012. Baseband Attacks: Remote Exploitation of Memory Corruptions in Cellular Protocol Stacks.. In WOOT. 12--21."},{"key":"e_1_3_2_1_51_1","unstructured":"Project Zero. 2023. Multiple Internet to Baseband Remote Code Execution Vulnerabilities in Exynos Modems. https:\/\/googleprojectzero.blogspot.com\/2023\/03\/multiple-internet-to-baseband-remote-rce.html."}],"event":{"name":"ICSE '24: IEEE\/ACM 46th International Conference on Software Engineering","location":"Lisbon Portugal","acronym":"ICSE '24","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","IEEE CS","Faculty of Engineering of University of Porto"]},"container-title":["Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3597503.3639158","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3597503.3639158","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T22:49:12Z","timestamp":1750286952000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3597503.3639158"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4,12]]},"references-count":51,"alternative-id":["10.1145\/3597503.3639158","10.1145\/3597503"],"URL":"https:\/\/doi.org\/10.1145\/3597503.3639158","relation":{},"subject":[],"published":{"date-parts":[[2024,4,12]]},"assertion":[{"value":"2024-04-12","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}