About me:

Hello! I’m Muhammad Shoaib, a Ph.D. candidate in the Department of Computer Science at the University of Virginia, advised by Professor Wajih Ul Hassan. My primary research focuses on attack forensics and threat detection.

Research interests:

My current research interests include Emerging Systems Security, Threat Detection, Program Analysis, SIEM Evasion, and Attack Forensics in general. I am currently exploring how to evade SIEM systems more reliably.


News:

  • Oct β€˜25: Won Distinguished Paper Award πŸ† for our CCS’25 paper.
  • Oct ’25: Invited to give a talk at MITRE ATT&CKcon 6.0.
  • Oct ’25: Attended MITRE’s Threat-Informed Defense training by the CTID Council.
  • Oct β€˜25: Invited to serve as a reviewer for IEEE Transactions on Information Forensics & Security (TIFS).
  • Aug β€˜25: Workshop paper accepted to the 1st XR Security Workshop, co-located with ACM MobiHoc 2025.
  • Jul β€˜25: β€œRethinking Tamper-Evident Logging: A High-Performance, Co-Designed Auditing System” has been accepted at ACM CCS β€˜25.
  • Jul β€˜25: Talk proposal for β€œREALITYCHECK: An ATT&CK-Aligned, Principled, and Automated Investigation of AR/VR Attacks” has been accepted at MITRE’s ATT&CKcon 6.0.
  • Jul β€˜25: Was awarded a travel grant to attend USENIX Security β€˜25.
  • May β€˜25: CCI has recognized my USENIX Security β€˜25 paper by accepting it for their Research Paper Showcase 2025 under the Resilience to Cyberattacks track.
  • April β€˜25: I have won the Best Poster Award for my work on Graph-based CVE Detection using Program Analysis and ML at CCI Symposium 2025, selected from over 40 students representing diverse computer-science disciplines across Virginia.
  • Feb β€˜25: Passed my qualifying exam defense. Now a Ph.D. candidate!
  • Jan β€˜25: My first-authored paper β€œPrincipled and Automated Approach for Investigating AR/VR Attacks” has been accepted at USENIX Security β€˜25.
  • August β€˜24: Passed my qualifying exam proposal.
  • July β€˜24: β€œAccurate and Scalable Detection and Investigation of Cyber Persistence Threats” available on arXiv.
  • Jan β€˜24: The Computing Research Association has awarded my mentee Alex Suh an honorable mention in their Outstanding Undergraduate Research Awards 2023-24 for our work that was later accepted at USENIX Security β€˜25.
  • April β€˜23: Was awarded a travel grant to attend IEEE S&P β€˜23.
  • October β€˜22: Won best new student poster award at the UVA CS research symposium.
  • August β€˜22: Joined DART Lab as a Ph.D. Student.

Publications & Talks

  1. Principled and Automated Approach for Investigating AR/VR Attacks (Slides): Muhammad Shoaib, Alex Suh, and Wajih Ul Hassan. In Proc. of the 34th USENIX Security Symposium (SEC ’25).

  2. Rethinking Tamper-Evident Logging: A High-Performance, Co-Designed Auditing System: Rui Zhao, Muhammad Shoaib, Viet Tung Hoang, and Wajih Ul Hassan. In Proc. of the 32nd ACM Conference on Computer and Communications Security (CCS ’25) πŸ† Distinguished Paper Award.

  3. Investigating Immersive Attacks with REALITYCHECK. Demonstrated at the 1st XR Security Workshop (co-located with MobiHoc ’25).

  4. REALITYCHECK: An ATT&CK-Aligned, Principled, and Automated Investigation of AR/VR Attacks. Invited talk at MITRE ATT&CKcon 6.0 (Oct 15, 2025).

  5. Accurate and Scalable Detection and Investigation of Cyber Persistence Threats: Qi Liu, Muhammad Shoaib, Mati Ur Rehman, Kaibin Bao, Veit Hagenmeyer, and Wajih Ul Hassan. arXiv preprint arXiv:2407.18832.