Securitatis inquisitor and professor at @EPFL_en leading the #HexHive 🐝 group, focusing on system/software security. @gannimo@infosec.exchange (he/him)

Lausanne, Switzerland
Joined December 2010
It's not you, it's the platform. I've been taking a break from Twitter/X. You can follow me at infosec.exchange/@gannimo for unfiltered stuff, linkedin.com/in/mathias-paye… for brags, or bsky.app/profile/gannimo.bsk…
3
14
The review process is under threat and we must make it resilient against adversarial attacks. Proud to be part of @TheOfficialACM PROTECT where we'll look into securing academic reviewing sigsac.org/protect.html
3
9
3
94
We'll still see some per-niche customization where the contribution is not in fuzzing but in the customization for each target environment.
1
7
I'd argue the opposite. General purpose grey box fuzzing research is complete as it is no longer feasible to distinguish between optimizations and over-fitting. Per-target optimizations should be left as an engineering exercise.
Are general-purpose fuzzing research dead? Our answer is probably no. Check our new fuzzer work FOX. The awesome fuzzer @aflplusplus is already super-powerful and quite an effective baseline in academics and industry. But there is still room to improve upon. We introduce FOX (CCS 2024), a new general-purpose fuzzer. We formulate the fuzzing as a scholastic online control problem and advance the performance of AFL++ by up to 26.45% in real-world standalone programs and 6.59% in FuzzBench programs. Check our talk at CCS'24 @acm_ccs, fuzzing session 1, Oct 16th, 1:30 PM – 3:00 PM, at Grand Ballroom Salon F. Paper: arxiv.org/abs/2406.04517 Code: github.com/FOX-Fuzz/FOX
2
6
1
28
France, as always going with the times. Nearby we saw a cyber café as well so they are future proof!
5
They grow up so fast. Happy first review anniversary to our paper in ACM TOPS! 🥳🎉 Looking forward to getting our first set of reviews soon!
6
5
3
65
Who's around for @acm_ccs? Come say hi if you want to talk about software security, fuzzing, or compartmentalization, just to rant about academia, or grab a Swiss chocolate that I brought along!
1
1
29
Mail from this morning: "we kindly ask you to submit this letter by 15th August 2024 (17:00 CET) at the very latest." BRB, just getting my Delorean's flux compensator warmed up 🏎️🔥
3
11
Mathias Payer retweeted
🚨 #PhD Opportunity at #RUB! 🎓 Join our team on #fuzzing! If you're passionate about #interpreters and want to dive into their #security aspects, this is your chance! 🚀✨ We offer incredible growth opportunities, with personalized mentorship from experienced researchers.
Mathias Payer retweeted
📢 I am seeking candidates interested in applying for a Tenured Research Position @Inria to join my team! The interested candidate must reach out and express their interest before the end of October 2024. 👉 More info here: www-sop.inria.fr/members/Nat…
15
1
34
I'm well aware of the tensions between the French and German speaking parts of Switzerland and the friendly rivalry between @EPFL_en and @ETH_en but nothing says welcome to Zürich as much as being shat on by a pigeon 2s after leaving the train 🚅🕊️💩
3
38
When fuzzers play Doom (or learn to dance Tango). Our paper on automatic state inference through coverage abstraction received the best paper award @RAID_Conference. Congrats @PickleBryne and @qiangliu717! nebelwelt.net/files/24RAID.p…
3
13
93
This is how all research projects should start (cc @cyan_pencil)
3
56
And we got @NDSSSymposium for #NDSS24 indexed as well 🎉 Trending upwards 😅
DBLP has finally indexed this year's @IEEESSP papers and I've updated the security circus statistics (along with the systems statistics). With @NDSSSymposium and @acm_ccs missing for 2024, I predict quite an increase in papers: nebelwelt.net/pubstats/top-a…
15
DBLP has finally indexed this year's @IEEESSP papers and I've updated the security circus statistics (along with the systems statistics). With @NDSSSymposium and @acm_ccs missing for 2024, I predict quite an increase in papers: nebelwelt.net/pubstats/top-a…
4
1
30
What a great time hosting Chao for a short visit @EPFL_en. This is the first time I trust ML-based binary analysis. Cool stuff!
1
5
41
To all the students searching for an adviser: check out to @tregua87. He's one of the best and most passionate advisers I've seen. He's building his research group in Bochum and looking for great PhD students, so reach out to him! I wonder if he'd take me as a post doc? 🤔
Happy to announce I'll be joining RUB as a Professor of Cyber Security in September! Looking for PhD students interested in Automated Testing and System Security. If you love fuzzing, PL, or have a passion for infosec, DM me! #RUB #SysSec #InfoSec @CASA_EXC @ruhrunibochum
9
25
Just FYI: the picture shows my lunch spot from where I posted the job announcement. We have lunch there regularly (or down at the lake for a swim).
We're opening 3 TT positions focusing on cyber-physical security, security and privacy, and learning sciences. Join us at one of the top research universities and clearly the most beautiful place in🇨🇭with lake and mountains nearby epfl.ch/about/working/page-2… @EPFL_en @ICepfl Plese RT
1
1
18
We're opening 3 TT positions focusing on cyber-physical security, security and privacy, and learning sciences. Join us at one of the top research universities and clearly the most beautiful place in🇨🇭with lake and mountains nearby epfl.ch/about/working/page-2… @EPFL_en @ICepfl Plese RT
32
2
67
We have just published the CfP of EuroS&P 2025! Check out eurosp2025.ieee-security.org… and get your papers registered by October 21 and submitted by October 24. Also check out the change in rebuttal already after round 1 of reviews!
1
12
28