{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,2]],"date-time":"2026-03-02T12:50:57Z","timestamp":1772455857678,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":32,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,26]],"date-time":"2023-11-26T00:00:00Z","timestamp":1700956800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,26]]},"DOI":"10.1145\/3605758.3623493","type":"proceedings-article","created":{"date-parts":[[2023,11,23]],"date-time":"2023-11-23T01:52:11Z","timestamp":1700704331000},"page":"1-9","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Firmulti Fuzzer: Discovering Multi-process Vulnerabilities in IoT Devices with Full System Emulation and VMI"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-8925-2443","authenticated-orcid":false,"given":"Yung-Tai","family":"Cheng","sequence":"first","affiliation":[{"name":"National Taiwan University of Science and Technology, Taipei, Taiwan Roc"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9796-0643","authenticated-orcid":false,"given":"Shin-Ming","family":"Cheng","sequence":"additional","affiliation":[{"name":"National Taiwan University of Science and Technology, Taipei, Taiwan Roc"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,11,26]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"[n. d.]. QEMU A generic and open source machine emulator and virtualizer. https: \/\/www.qemu.org\/"},{"key":"e_1_3_2_1_2_1","volume-title":"Consumer IoT: Security vulnerability case studies and solutions. 9, 2 (Feb","author":"Alladi Tejasvi","year":"2020","unstructured":"Tejasvi Alladi, Vinay Chamola, Biplab Sikdar, and Kim-Kwang Raymond Choo. 2020. Consumer IoT: Security vulnerability case studies and solutions. 9, 2 (Feb. 2020), 17--25."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427280"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23415"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23159"},{"key":"e_1_3_2_1_6_1","volume-title":"Proc. 30th USENIX Security Symposium. 303--319","author":"Chen Libo","year":"2021","unstructured":"Libo Chen, Yanhao Wang, Quanpu Cai, Yunfan Zhan, Hong Hu, Jiaqi Linghu, Qinsheng Hou, Chao Zhang, Haixin Duan, and Zhi Xue. 2021. Sharing More and Checking Less: Leveraging Common Input Keywords to Detect Bugs in Embedded Systems.. In Proc. 30th USENIX Security Symposium. 303--319."},{"key":"e_1_3_2_1_7_1","volume-title":"Integrating Taint Analysis with Symbolic Execution for IoT Peripheral Modeling. Master's thesis","author":"Chung Cheng-Yen","unstructured":"Cheng-Yen Chung. 2022. Integrating Taint Analysis with Symbolic Execution for IoT Peripheral Modeling. Master's thesis. National Taiwan University of Science and Technology. https:\/\/hdl.handle.net\/11296\/bjc948"},{"key":"e_1_3_2_1_8_1","volume-title":"d.]. FirmSE: Integrating taint analysis with symbolic execution for IoT peripheral modeling. ([n. d.]). (Paper submitted to) IEEE Transactions on Dependable and Secure Computing","author":"Chung Cheng-Yen","year":"2023","unstructured":"Cheng-Yen Chung, Nien-Jen Tsai, and Shin-Ming Cheng. [n. d.]. FirmSE: Integrating taint analysis with symbolic execution for IoT peripheral modeling. ([n. d.]). (Paper submitted to) IEEE Transactions on Dependable and Secure Computing Mar 2023."},{"key":"e_1_3_2_1_9_1","unstructured":"decaf project. [n. d.]. Dynamic Executable Code Analysis Framework. https: \/\/github.com\/decaf-project\/DECAF"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3056179"},{"key":"e_1_3_2_1_11_1","volume-title":"Proc. 29th USENIX Security Symposium. 1237--1254","author":"Feng Bo","year":"2020","unstructured":"Bo Feng, Alejandro Mera, and Long Lu. 2020. P2IM: Scalable and hardwareindependent firmware testing via automatic peripheral interface modeling. In Proc. 29th USENIX Security Symposium. 1237--1254."},{"key":"e_1_3_2_1_12_1","volume-title":"CinfoFuzz: Fuzzing Method Based on Web Service Correlation Information of Embedded Devices. In 10th IEEE International Conference on Information, Communication and Networks (ICICN","author":"Feng Qi","year":"2022","unstructured":"Qi Feng and Weiyu Dong. 2022. CinfoFuzz: Fuzzing Method Based on Web Service Correlation Information of Embedded Devices. In 10th IEEE International Conference on Information, Communication and Networks (ICICN 2022). 242--249."},{"key":"e_1_3_2_1_13_1","unstructured":"Ghidra. 2021. Ghidra. https:\/\/ghidra-sre.org\/"},{"key":"e_1_3_2_1_14_1","unstructured":"Google. [n. d.]. American Fuzzy Lop. https:\/\/lcamtuf.coredump.cx\/afl\/"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"crossref","unstructured":"Wan Haslina Hassan et al. 2019. Current research on Internet of Things (IoT) security: A survey. Computer networks 148 (2019) 283--294.","DOI":"10.1016\/j.comnet.2018.11.025"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/2610384.2610407"},{"key":"e_1_3_2_1_17_1","first-page":"321","article-title":"Jetset","volume":"2021","author":"Johnson Evan","year":"2021","unstructured":"Evan Johnson, Maxwell Bland, YiFei Zhu, Joshua Mason, Stephen Checkoway, Stefan Savage, and Kirill Levchenko. 2021. Jetset: Targeted Firmware Rehosting for Embedded Systems. In Proc. USENIX Security 2021. 321--338.","journal-title":"Targeted Firmware Rehosting for Embedded Systems. In Proc. USENIX Security"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427294"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE.2015.7381820"},{"key":"e_1_3_2_1_20_1","unstructured":"NCC-Group. [n. d.]. TriforceAFL. https:\/\/github.com\/nccgroup\/TriforceAFL"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00036"},{"key":"e_1_3_2_1_22_1","unstructured":"Bhagyashri Tushir Hetesh Sehgal Rohan Nair Behnam Dezfouli and Yuhong Liu. 2021. The Impact of DoS Attacks onResource-constrained IoT Devices:A Study on the Mirai Attack. arXiv:2104.09041 [cs.CR]"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.3837\/tiis.2013.08.014"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3485447.3512213"},{"key":"e_1_3_2_1_25_1","volume-title":"Automation & Test in Europe Conference & Exhibition (DATE","author":"Yu Lei","year":"2021","unstructured":"Lei Yu, Linyu Li, Haoyu Wang, Xiaoyu Wang, Houhua He, and Xiaorui Gong. 2021. Towards Automated Detection of Higher-Order Memory Corruption Vulnerabilities in Embedded Devices. In Design, Automation & Test in Europe Conference & Exhibition (DATE 2021). 1707--1710."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.4018\/IJDCF.286755"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3538644"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3457913.3457934"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359826"},{"key":"e_1_3_2_1_30_1","volume-title":"Proc. USENIX Security Symposium","author":"Zheng Yaowen","year":"2019","unstructured":"Yaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song, Hongsong Zhu, and Limin Sun. 2019. FIRM-AFL: High-Throughput Greybox Fuzzing of IoT Firmware via Augmented Process Emulation. In Proc. USENIX Security Symposium 2019. 1099--1114."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3533767.3534414"},{"key":"e_1_3_2_1_32_1","volume-title":"Proc. 30th USENIX Security Symposium.","author":"Zhou Wei","year":"2021","unstructured":"Wei Zhou, Le Guan, Peng Liu, and Yuqing Zhang. 2021. Automatic Firmware Emulation through Invalidity-guided Knowledge Inference. In Proc. 30th USENIX Security Symposium."}],"event":{"name":"CCS '23: ACM SIGSAC Conference on Computer and Communications Security","location":"Copenhagen Denmark","acronym":"CCS '23","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 5th Workshop on CPS&amp;IoT Security and Privacy"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3605758.3623493","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3605758.3623493","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:46:10Z","timestamp":1750178770000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3605758.3623493"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,26]]},"references-count":32,"alternative-id":["10.1145\/3605758.3623493","10.1145\/3605758"],"URL":"https:\/\/doi.org\/10.1145\/3605758.3623493","relation":{},"subject":[],"published":{"date-parts":[[2023,11,26]]},"assertion":[{"value":"2023-11-26","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}