{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T08:17:38Z","timestamp":1783153058473,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":47,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,13]]},"DOI":"10.1145\/3774904.3792431","type":"proceedings-article","created":{"date-parts":[[2026,4,27]],"date-time":"2026-04-27T12:38:33Z","timestamp":1777293513000},"page":"3066-3077","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["FalconScope: Effective and Efficient Detection of Hidden Web Interfaces in IoT Devices"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-8464-810X","authenticated-orcid":false,"given":"Jiaming","family":"Guo","sequence":"first","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-8559-0507","authenticated-orcid":false,"given":"Haoran","family":"Yang","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-8527-9957","authenticated-orcid":false,"given":"Kuihao","family":"Yan","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-5615-7116","authenticated-orcid":false,"given":"Jiekang","family":"Hu","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8376-3235","authenticated-orcid":false,"given":"Xiaoqi","family":"Jia","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2783-3232","authenticated-orcid":false,"given":"Haichao","family":"Du","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8565-1923","authenticated-orcid":false,"given":"Qihang","family":"Zhou","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,4,12]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Hybrid approaches (ABAC and RBAC) toward secure access control in smart home IoT","author":"Ameer Safwa","year":"2022","unstructured":"Safwa Ameer, James Benson, and Ravi Sandhu. 2022. Hybrid approaches (ABAC and RBAC) toward secure access control in smart home IoT. IEEE transactions on dependable and secure computing, Vol. 20, 5 (2022), 4032-4051."},{"key":"e_1_3_2_1_2_1","volume-title":"Number of connected IoT devices to reach 40 billion by","author":"Analytics T","year":"2030","unstructured":"IoT Analytics. 2024. Number of connected IoT devices to reach 40 billion by 2030. https:\/\/iot-analytics.com\/number-connected-iot-devices."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23415"},{"key":"e_1_3_2_1_4_1","volume-title":"30th USENIX Security Symposium.","author":"Chen Libo","year":"2021","unstructured":"Libo Chen, Yanhao Wang, Quanpu Cai, Yunfan Zhan, Hong Hu, Jiaqi Linghu, Qinsheng Hou, Chao Zhang, Haixin Duan, and Zhi Xue. 2021. Sharing more and checking less: Leveraging common input keywords to detect bugs in embedded systems. In 30th USENIX Security Symposium."},{"key":"e_1_3_2_1_5_1","unstructured":"Django Software Foundation. 2025. Django. https:\/\/github.com\/django\/django"},{"key":"e_1_3_2_1_6_1","unstructured":"Expressjs. 2025. Express. https:\/\/github.com\/expressjs\/express"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484543"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3597503.3608134"},{"key":"e_1_3_2_1_9_1","first-page":"135","volume-title":"22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID","author":"Gustafson Eric","year":"2019","unstructured":"Eric Gustafson, Marius Muench, Chad Spensky, Nilo Redini, Aravind Machiry, Yanick Fratantonio, Davide Balzarotti, Aur\u00e9lien Francillon, Yung Ryn Choe, Christophe Kruegel, et al., 2019. Toward the analysis of embedded firmware through automated re-hosting. In 22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2019). 135-150."},{"key":"e_1_3_2_1_10_1","unstructured":"Hex-Rays. 2025. IDA Pro: The Industry Standard Disassembler and Debugger. https:\/\/hex-rays.com\/ida-pro\/"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3578527.3578530"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00051"},{"key":"e_1_3_2_1_13_1","volume-title":"Shiqi Wang, Amir Rahmati, Earlence Fernandes, Zhuoqing Morley Mao, Atul Prakash, and SJ Unviersity.","author":"Jia Yunhan Jack","year":"2017","unstructured":"Yunhan Jack Jia, Qi Alfred Chen, Shiqi Wang, Amir Rahmati, Earlence Fernandes, Zhuoqing Morley Mao, Atul Prakash, and SJ Unviersity. 2017. ContexloT: Towards providing contextual integrity to appified IoT platforms. In ndss, Vol. 2. San Diego, 2-2."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560680"},{"key":"e_1_3_2_1_15_1","first-page":"321","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Johnson Evan","year":"2021","unstructured":"Evan Johnson, Maxwell Bland, YiFei Zhu, Joshua Mason, Stephen Checkoway, Stefan Savage, and Kirill Levchenko. 2021. Jetset: Targeted firmware rehosting for embedded systems. In 30th USENIX Security Symposium (USENIX Security 21). 321-338."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3635059.3635104"},{"key":"e_1_3_2_1_17_1","volume-title":"Understanding the effectiveness of large language models in detecting security vulnerabilities. arXiv preprint arXiv:2311.16169","author":"Khare Avishree","year":"2023","unstructured":"Avishree Khare, Saikat Dutta, Ziyang Li, Alaia Solko-Breslin, Rajeev Alur, and Mayur Naik. 2023. Understanding the effectiveness of large language models in detecting security vulnerabilities. arXiv preprint arXiv:2311.16169 (2023)."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427294"},{"key":"e_1_3_2_1_19_1","unstructured":"LangChain AI. 2025. langchain. https:\/\/github.com\/langchain-ai\/langchain"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00127"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2025.240399"},{"key":"e_1_3_2_1_22_1","volume-title":"Harnessing the power of llm to support binary taint analysis. arXiv preprint arXiv:2310.08275","author":"Liu Puzhuo","year":"2023","unstructured":"Puzhuo Liu, Chengnian Sun, Yaowen Zheng, Xuan Feng, Chuan Qin, Yuncheng Wang, Zhi Li, and Limin Sun. 2023. Harnessing the power of llm to support binary taint analysis. arXiv preprint arXiv:2310.08275 (2023)."},{"key":"e_1_3_2_1_23_1","unstructured":"Puzhuo Liu Chengnian Sun Yaowen Zheng Xuan Feng Chuan Qin Yuncheng Wang Zhenyang Xu Zhi Li Peng Di Yu Jiang et al. 2025a. Llm-powered static binary taint analysis. ACM Transactions on Software Engineering and Methodology (2025)."},{"key":"e_1_3_2_1_24_1","unstructured":"National Vulnerability Database. 2024. CVE-2024-13030. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-13030."},{"key":"e_1_3_2_1_25_1","unstructured":"National Vulnerability Database. 2025. Vulnerability Metrics (CVSS). https:\/\/nvd.nist.gov\/vuln-metrics\/cvss."},{"key":"e_1_3_2_1_26_1","unstructured":"OpenAI. 2025. GPT-4 Models - OpenAI API. https:\/\/platform.openai.com\/docs\/models\/gpt-4."},{"key":"e_1_3_2_1_27_1","unstructured":"OWASP. 2021. OWASP Top Ten Web Application Security Risks. https:\/\/owasp.org\/www-project-top-ten. Discusses Broken Access Control (A01)."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00036"},{"key":"e_1_3_2_1_29_1","unstructured":"ReFirm Labs. 2025. binwalk. https:\/\/github.com\/ReFirmLabs\/binwalk"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243817"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338507.3358616"},{"key":"e_1_3_2_1_32_1","first-page":"5791","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Tay Hui Jun","year":"2023","unstructured":"Hui Jun Tay, Kyle Zeng, Jayakrishna Menon Vadayath, Arvind S Raj, Audrey Dutcher, Tejesh Reddy, Wil Gibbs, Zion Leonahenahe Basque, Fangzhou Dong, Zack Smith, et al., 2023. Greenhouse: rehosting of firmware binaries in emulation. In 32nd USENIX Security Symposium (USENIX Security 23). 5791-5808."},{"key":"e_1_3_2_1_33_1","unstructured":"The Pallets Projects. 2025. Flask. https:\/\/github.com\/pallets\/flask"},{"key":"e_1_3_2_1_34_1","unstructured":"ThreatPost. 2020. Half of IoT devices are vulnerable to severe attacks. https:\/\/threatpost.com\/half-iot-devices-vulnerable-severe-attacks\/153609."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3491101.3519665"},{"key":"e_1_3_2_1_36_1","volume-title":"Denny Zhou, et al.","author":"Wei Jason","year":"2022","unstructured":"Jason Wei, Xuezhi Wang, Dale Schuurmans, Maarten Bosma, Fei Xia, Ed Chi, Quoc V Le, Denny Zhou, et al., 2022. Chain-of-thought prompting elicits reasoning in large language models. Advances in Neural Information Processing Systems (2022)."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3485447.3512213"},{"key":"e_1_3_2_1_38_1","volume-title":"Llm lies: Hallucinations are not bugs, but features as adversarial examples. arXiv preprint arXiv:2310.01469","author":"Yao Jia-Yu","year":"2023","unstructured":"Jia-Yu Yao, Kun-Peng Ning, Zhen-Hui Liu, Mu-Nan Ning, Yu-Yang Liu, and Li Yuan. 2023. Llm lies: Hallucinations are not bugs, but features as adversarial examples. arXiv preprint arXiv:2310.01469 (2023)."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103971"},{"key":"e_1_3_2_1_40_1","first-page":"1","article-title":"AVATAR: A Framework to Support Dynamic Security Analysis of Embedded Systems","volume":"14","author":"Zaddach Jonas","year":"2014","unstructured":"Jonas Zaddach, Luca Bruno, Aurelien Francillon, Davide Balzarotti, et al., 2014. AVATAR: A Framework to Support Dynamic Security Analysis of Embedded Systems' Firmwares. In NDSS, Vol. 14. 1-16.","journal-title":"Firmwares. In NDSS"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359826"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2024.3400858"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.5555\/3698900.3699295"},{"key":"e_1_3_2_1_44_1","first-page":"1099","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Zheng Yaowen","year":"2019","unstructured":"Yaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song, Hongsong Zhu, and Limin Sun. 2019. : greybox fuzzing of firmware via augmented process emulation. In 28th USENIX Security Symposium (USENIX Security 19). 1099-1114."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3038912.3052609"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00009"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134089"}],"event":{"name":"WWW '26: The ACM Web Conference 2026","location":"Dubai United Arab Emirates","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Proceedings of the ACM Web Conference 2026"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3774904.3792431","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T07:40:55Z","timestamp":1783150855000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3774904.3792431"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,12]]},"references-count":47,"alternative-id":["10.1145\/3774904.3792431","10.1145\/3774904"],"URL":"https:\/\/doi.org\/10.1145\/3774904.3792431","relation":{},"subject":[],"published":{"date-parts":[[2026,4,12]]},"assertion":[{"value":"2026-04-12","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}