EVENT DETAILS
How vulnerable to input-driven attacks are the large applications used for computational science? Can these attacks be mitigated? Despite growing concerns about the security of scientific software, no work has empirically evaluated its resistance to adversarial input, and efforts to address concerns of correctness in scientific software are not currently applicable to mitigating vulnerabilities. This thesis begins to address these gaps.
I apply standard fuzzing and triage tools to demonstrate that large, open-source scientific applications are highly exploitable through their inputs with ready avenues to arbitrary code execution and thus full control over program output. Next, I implement Crucible, a novel grammar-based fuzzer that searches for small input perturbations, or "nudges", permitting an adversary to steer the numerical results of such applications by orders of magnitude without relying on conventional vulnerabilities.
I propose an expansion of the scope of my studies to include additional applications, variants of attack, and bug detection techniques. I further propose assessing the extent to which formal specification and AI-assisted proof construction could help mitigate - or rule out - a subset of these vulnerabilities, such as the discovered numerical "nudging attacks".
TIME Thursday September 10, 2026 at 2:00 PM - 5:00 PM
LOCATION 3514, Mudd Hall ( formerly Seeley G. Mudd Library) map it
ADD TO CALENDAR&group= echo $value['group_name']; ?>&location= echo htmlentities($value['location']); ?>&pipurl= echo $value['ppurl']; ?>" class="button_outlook_export">
CONTACT Jensen Smith jensen.smith@northwestern.edu
CALENDAR Department of Computer Science (CS)