Publications

(2025). KubeKeeper: Protecting Kubernetes Secrets Against Excessive Permissions. In Proceedings of the 10th IEEE European Symposium on Security and Privacy (EuroS&P). Venice, Italy..

PDF Code

(2025). LeakLess: Selective Data Protection Against Memory Leakage Attacks for Serverless Platforms. In Proceedings of the Network and Distributed System Security Symposium (NDSS). San Diego, CA.

PDF Code Dataset

(2023). Confine: Fine-grained System Call Filtering for Container Attack Surface Reduction. In Computers & Security, vol. 132, September 2023.

PDF Code Dataset