About me:
Hello! Iβm Muhammad Shoaib, a Ph.D. candidate in the Department of Computer Science at the University of Virginia, advised by Professor Wajih Ul Hassan. My primary research focuses on attack forensics and threat detection.
Research interests:
My current research interests include Emerging Systems Security, Threat Detection, Program Analysis, SIEM Evasion, and Attack Forensics in general. I am currently exploring how to evade SIEM systems more reliably.
News:
- Oct β25: Won Distinguished Paper Award π for our CCSβ25 paper.
- Oct β25: Invited to give a talk at MITRE ATT&CKcon 6.0.
- Oct β25: Attended MITREβs Threat-Informed Defense training by the CTID Council.
- Oct β25: Invited to serve as a reviewer for IEEE Transactions on Information Forensics & Security (TIFS).
- Aug β25: Workshop paper accepted to the 1st XR Security Workshop, co-located with ACM MobiHoc 2025.
- Jul β25: βRethinking Tamper-Evident Logging: A High-Performance, Co-Designed Auditing Systemβ has been accepted at ACM CCS β25.
- Jul β25: Talk proposal for βREALITYCHECK: An ATT&CK-Aligned, Principled, and Automated Investigation of AR/VR Attacksβ has been accepted at MITREβs ATT&CKcon 6.0.
- Jul β25: Was awarded a travel grant to attend USENIX Security β25.
- May β25: CCI has recognized my USENIX Security β25 paper by accepting it for their Research Paper Showcase 2025 under the Resilience to Cyberattacks track.
- April β25: I have won the Best Poster Award for my work on Graph-based CVE Detection using Program Analysis and ML at CCI Symposium 2025, selected from over 40 students representing diverse computer-science disciplines across Virginia.
- Feb β25: Passed my qualifying exam defense. Now a Ph.D. candidate!
- Jan β25: My first-authored paper βPrincipled and Automated Approach for Investigating AR/VR Attacksβ has been accepted at USENIX Security β25.
- August β24: Passed my qualifying exam proposal.
- July β24: βAccurate and Scalable Detection and Investigation of Cyber Persistence Threatsβ available on arXiv.
- Jan β24: The Computing Research Association has awarded my mentee Alex Suh an honorable mention in their Outstanding Undergraduate Research Awards 2023-24 for our work that was later accepted at USENIX Security β25.
- April β23: Was awarded a travel grant to attend IEEE S&P β23.
- October β22: Won best new student poster award at the UVA CS research symposium.
- August β22: Joined DART Lab as a Ph.D. Student.
Publications & Talks
Principled and Automated Approach for Investigating AR/VR Attacks (Slides): Muhammad Shoaib, Alex Suh, and Wajih Ul Hassan. In Proc. of the 34th USENIX Security Symposium (SEC β25).
Rethinking Tamper-Evident Logging: A High-Performance, Co-Designed Auditing System: Rui Zhao, Muhammad Shoaib, Viet Tung Hoang, and Wajih Ul Hassan. In Proc. of the 32nd ACM Conference on Computer and Communications Security (CCS β25) π Distinguished Paper Award.
Investigating Immersive Attacks with REALITYCHECK. Demonstrated at the 1st XR Security Workshop (co-located with MobiHoc β25).
REALITYCHECK: An ATT&CK-Aligned, Principled, and Automated Investigation of AR/VR Attacks. Invited talk at MITRE ATT&CKcon 6.0 (Oct 15, 2025).
Accurate and Scalable Detection and Investigation of Cyber Persistence Threats: Qi Liu, Muhammad Shoaib, Mati Ur Rehman, Kaibin Bao, Veit Hagenmeyer, and Wajih Ul Hassan. arXiv preprint arXiv:2407.18832.
