Carter Yagemann

Assistant Professor of Computer Science and Engineering at The Ohio State University, specializing in systems and software security, including vulnerability discovery, exploit prevention, fault injection, cyber-physical systems, and financial market security.

Articles


PathGlow to Appear in DSC 2026

My coauthors and I will be presenting the paper "PathGlow: SSE-Driven on-Demand Data-Flow Analysis for Detecting Path Traversal in Binaries" at the 2026 IEEE Conference on Dependable and Secure Computing (DSC) in October. Below is a preview of the abstract: Taint-style vulnerabilities such as path traversal remain difficult to identify …

Semantic Shields to Appear in Military Cyber Affairs

A journal article written by my coauthors and I will be appearing in Volume 10 of Military Cyber Affairs. Below is a preview of the abstract: Ransomware poses a growing threat to critical infrastructure, where successful attacks can disrupt operational technology (OT) and industrial control systems (ICS) with significant public …

TraceHunter to Appear in ESORICS 2026

My coauthors and I will be presenting the paper "TraceHunter: Efficient Language Agnostic Verification of Constant-Time Cryptographic Implementations via Processor Tracing" at the 31st European Symposium on Research in Computer Security (ESORICS) in September. Below is a preview of the abstract: Timing side-channel attacks pose a persistent threat to cryptographic …

FlipShield to Appear in DRAMSec 2026

My coauthors and I will be presenting the paper "FlipShield: Self-Improving Software Mitigation Against Rowhammer" at the Sixth Workshop on DRAM Security (DRAMSec) this weekend. Below is a preview of the abstract: Secure memory is built on the assumption of correct hardware execution, yet the Rowhammer vulnerability demonstrates that repeated …

Rise of arXiv and the Role of Formal Publications

When I started my Ph.D. in 2016, it was a well-established norm in my area of systems security within computer science that you could defend a dissertation and graduate once you had three top-tier publications (meaning USENIX Security, ACM CCS, IEEE S&P, or NDSS) on a related topic …

ProtoReveal to Appear in ACSAC 2025

My coauthors and I will be presenting the paper "Recovering Peripheral Maps and Protocols to Expedite Firmware Reverse Engineering" at the Annual Computer Security Applications Conference (ACSAC) in December. Below is a preview of the abstract: Reverse engineering firmware binaries is vital to security due to the risks involved with …

VerDiff Vulnerability Presence Verification to Appear in ACSAC 2025

My coauthors and I will be presenting the paper "VerDiff: Vulnerability Presence Verification for Comprehensive Reporting Using Constraint Programming" at the Annual Computer Security Applications Conference (ACSAC) in December. Below is a preview of the abstract: Security practitioners often rely on a collaborative ecosystem of analysts and authorities to publicly …

DiscScope Decompiler Study to Appear in ASIACCS 2025

My coauthors and I will be presenting the paper "An Empirical Study of C Decompilers: Performance Metrics and Error Taxonomy" at ACM ASIACCS 2025 in August. Below is a preview of the abstract: Decompilation aims to simplify reverse engineering by transforming binary code into a high-level representation, such as C-like …

GoSonar to Appear in IEEE S&P 2025

My coauthors and I will be presenting the paper "GoSonar: Detecting Logical Vulnerabilities in Memory Safe Language Using Inductive Constraint Reasoning" at IEEE S&P 2025 in May. Below is a preview of the abstract: As the global community advocates for the adoption of memory-safe programming languages, a significant research …

Awarded DARPA Young Faculty Award

I'm excited to announce that I've been recently awarded a DARPA Young Faculty Award (YFA) under the mentorship of Dr. Lok Yan. More details are available on the Ohio State College of Engineering website, to summarize: Carter Yagemann, who joined the Department of Computer Science and Engineering in 2022, was …