Xiaoyan (Sherry) Sun

Xiaoyan (Sherry) Sun

Associate Professor
Department of Computer Science
Worcester Polytechnic Institute
Email: xsun7 AT wpi.edu · Office: Fuller Labs 306

Publications

Selected Publications
  1. [NDSS'26] Xue Tan, Hao Luan, Mingyu Luo, Zhuyang Yu, Jun Dai, Xiaoyan Sun, Ping Chen, "Was My Data Used for Training? Membership Inference in Open-Source LLMs via Neural Activations", The Network and Distributed System Security (NDSS) Symposium, 2026.
  2. [NDSS'26] Hao Luan, Xue Tan, Zhiheng Li, Jun Dai, Xiaoyan Sun, and Ping Chen, "Dataset Reduction and Watermark Removal via Self-supervised Learning for Model Extraction Attack", The Network and Distributed System Security (NDSS) Symposium, 2026.
  3. [TMC'26] Tianya Zhao, Junqing Zhang, Jun Dai, Xiaoyan Sun, Xuyu Wang, "Unveiling the Threat: Data-Free Backdoor Attacks on Pre-Trained Models for RF Fingerprinting". IEEE Transactions on Mobile Computing (TMC). (Impact Factor: 6.5)
  4. [TDSC'25] Zhilong Wang, Chen Cao, Li Yu, Suhang Wang, Peng Liu, Xiaoyan Sun, Anoop Singhal, "DeepSanitizer: Combining Heuristic Rules and Deep Learning Models to Spot Silent Buffer Overflows in Binary", IEEE Transactions on Dependable and Secure Computing. (Impact Factor: 7).
  5. [TDSC'25] Duohe Ma, Junye Jiang, Jun Dai, Xiaoyan Sun, Zhimin Tang, Chaozhen Zhang, Kai Chen, "Got My "Invisibility" Patch: Towards Physical Evasion Attacks on Black-box Face Detection Systems", IEEE Transactions on Dependable and Secure Computing. (Impact Factor: 7).
  6. [EMNLP'25 Findings] Xue Tan, Hao Luan, Mingyu Luo, Xiaoyan Sun, Ping Chen, Jun Dai, "RevPRAG: Revealing Poisoning Attacks in Retrieval-Augmented Generation through LLM Activation Analysis", The 2025 Conference on Empirical Methods in Natural Language Processing (EMNLP 2025).
  7. [NDSS'25] Chang Yue, Kai Chen, Zhixiu Guo, Jun Dai, Xiaoyan Sun, Yi Yang, "What's Done Is Not What's Claimed: Detecting and Interpreting Inconsistencies in App Behaviors", The Network and Distributed System Security (NDSS) Symposium 2025. Acceptance rate: 16.1%.
  8. [SIGCSE'25] "Strengthening Workforce Education: Excellence in Programming Securely (SWEEPS)", Deborah Kariuki, Ida Ngambeki, Jun Dai, Matt Bishop, Phillip Nico, Melissa Dark and Xiaoyan Sun, the 56th ACM Technical Symposium on Computer Science Education 2025.
  9. [ICICS'25] "MagWatch: Exposing Privacy Risks in Wearable Devices Through Electromagnetic Signals", Haowen Xu, Tianya Zhao, Xuyu Wang, Jun Dai, Xiaoyan Sun, The 27th International Conference on Information and Communications Security (ICICS 2025). Acceptance rate: 28%.
  10. [COMPSAC'25] "Towards Development of Ready-to-Use Hands-on Labs with Portable Operating Environments for Digital Forensics Education". Tran Huynh, Haowen Xu, Brian Almaguer, Jun Dai, Xiaoyan Sun, The 49th IEEE International Conference on Computers, Software, and Applications (COMPSAC 2025). Acceptance rate: 27%.
  11. [MILCOM'25] "VibLeak: Towards Practical Covert Data Leakage via Phone Vibrations", Junye Jiang, Jingcheng Ju, Haowen Xu, Zhenlu Tan, Duohe Ma, Jun Dai, Xiaoyan Sun, The IEEE Military Communications Conference (MILCOM).
  12. [JCS'25] Jin Wei, Ping Chen, Zhihao Zhang, Jun Dai, Xiaoyan Sun, Chang Xu, Yi Wang. "HuntFUZZ: Testing Error Handling Code through Concolic Execution-Assisted Fuzzing with Optimization", Journal of Computer Security. 2025.
  13. [WISE'25] "A Car Hacking Mini-Unit for High School Cybersecurity Education". The 17th World Conference on Information Security Education (WISE 2025). Cooper Dean, Brian Almaguer, Timothy Buck, Nichole Kunkle, Christian Nguyen, Preet Patel, Anne Roberts, Marti Shirley, Huirong Fu, Xiaoyan Sun, Jun Dai.
  14. [WISE'25] "INFER: Enhancing Digital Forensics Education through Ready-to-Use Hands-on Labs with Portable Operating Environments". The 17th World Conference on Information Security Education (WISE 2025). Tran Huynh, Haowen Xu, Brian Almaguer, Jun Dai, Xiaoyan Sun.
  15. [JCS'24] "SQLaser: Detecting DBMS Logic Bugs with Clause-Guided Fuzzing'', Jin Wei, Ping Chen, Kangjie Lu, Jun Dai, Xiaoyan Sun, Journal of Computer Security. Journal paper.
  16. [JCS'24] Qingtian Zou, Lan Zhang, Anoop Singhal, Xiaoyan Sun and Peng Liu, "Analysis of Neural Network Detectors for Network Attacks", Journal of Computer Security. 2024.
  17. [ISCC‘23] Zhimin Tang, Duohe Ma, Xiaoyan Sun, Kai Chen, Liming Wang and Junye Jiang, "Every Time Can Be Different: A Data Dynamic Protection Method Based on Moving Target Defense", 2023 IEEE Symposium on Computers and Communications. 2023.
  18. [JCS'21] Qingtian Zou, Anoop Singhal, Xiaoyan Sun and Peng Liu, “Deep Learning for Detecting Logic-flaw-exploiting Network Attacks: An End-to-end Approach”, Journal of Computer Security. 2021.
  19. [TIFS'18] Xiaoyan Sun, Jun Dai, Peng Liu, Anoop Singhal, John Yen, Using Bayesian Networks for Probabilistic Identification of Zero-day Attack Paths. Journal paper, IEEE Transactions on Information Forensics and Security (TIFS), Oct 2018.
  20. [CNS'16] Xiaoyan Sun, Jun Dai, Peng Liu, Anoop Singhal, John Yen; Towards Probabilistic Identification of Zero-day Attack Paths;, IEEE Conference on Communications and Network Security (CNS 2016), Philadelphia, PA USA, 2016 (Best Paper Runner-Up Award).
  21. [SecureComm'14] Xiaoyan Sun, Jun Dai, Anoop Singhal, Peng Liu;Inferring the Stealthy Bridges between Enterprise Network Islands in Cloud Using Cross-Layer Bayesian Networks;, 10th International Conference on Security and Privacy in Communication Networks (SecureComm), Beijing, China, 2014 (Best Paper Award Nomination).
  22. [ESORICS'13] Jun Dai, Xiaoyan Sun, Peng Liu, Patrol: Revealing Zero-day Attack Paths through Network-wide System Object Dependencies”, 18th European Symposium on Research in Computer Security (ESORICS), RHUL, Egham, U.K., 2013.
Full Publication List
Full Publication List can be accessed here.