Adam Bates
· Associate ProfessorUniversity of Illinois Urbana-Champaign · Computer Science
Active 2008–2025
Academic metrics are sourced from OpenAlex and public funding records; values may differ from Google Scholar.
About
Adam Bates is an Associate Professor at the Siebel School of Computing and Data Science at the University of Illinois Urbana-Champaign. He holds a Ph.D. in Computer Science from the University of Florida, earned in 2016, with a thesis focused on designing and leveraging trustworthy provenance-aware systems. His academic background also includes a Master of Science in Computer Science from the University of Oregon and a Bachelor of Science in Computer Science from the University of Maryland. His research interests encompass intrusion detection systems, digital privacy in everyday user technologies, threat detection, investigation, and response. His work primarily addresses operating systems security and privacy, contributing to the development of scalable, efficient, and secure alert triage systems for endpoint detection and response, as well as exploring privacy concerns in fitness tracking and smart home devices. Dr. Bates has authored numerous articles in conference proceedings, emphasizing his active engagement in advancing security and privacy research within the computing community.
Research topics
- Computer Science
- Data Mining
- Physics
- Theoretical computer science
- Materials science
- Algorithm
- Geology
- Nanotechnology
Selected publications
Tactical Provenance Analysis for Endpoint Detection and Response Systems
2022 IEEE Symposium on Security and Privacy (SP) · 2020 · 257 citations
Endpoint Detection and Response (EDR) tools provide visibility into sophisticated intrusions by matching system events against known adversarial behaviors. However, current solutions suffer from three challenges: 1) EDR tools generate a high volume of false alarms, creating backlogs of investigation tasks for analysts; 2) determining the veracity of these threat alerts requires tedious manual labor due to the overwhelming amount of low-level system logs, creating a "needle-in-a-haystack" problem…
OmegaLog: High-Fidelity Attack Investigation via Transparent Multi-layer Log Analysis
2020 · 117 citations
Senior authorCorrespondingRecent advances in causality analysis have enabled investigators to trace multi-stage attacks using provenance graphs. Based on system-layer audit logs (e.g., syscalls), these approaches omit vital sources of application context (e.g., email addresses, HTTP response codes) that can be found in higher layers of the system. Although such information is often essential to understanding attack behaviors, it is difficult to incorporate this evidence into causal analysis engines because of the semanti…
UNICORN:Runtime Provenance-Based Detector for Advanced Persistent Threats
2020 · 75 citations
Advanced Persistent Threats (APTs) are difficult to detect due to their low-and-slow attack patterns and frequent use of zero-day exploits. We present UNICORN, an anomaly-based APT detector that effectively leverages data provenance analysis. From modeling to detection, UNICORN tailors its design specifically for the unique characteristics of APTs. Through extensive yet time-efficient graph analysis, UNICORN explores provenance graphs that provide rich contextual and historical information to id…
SoK: History is a Vast Early Warning System: Auditing the Provenance of System Intrusions
2023-05-01 · 51 citations
articleAuditing, a central pillar of operating system security, has only recently come into its own as an active area of public research. This resurgent interest is due in large part to the notion of data provenance, a technique that iteratively parses audit log entries into a dependency graph that explains the history of system execution. Provenance facilitates precise threat detection and investigation through causal analysis of sophisticated intrusion behaviors. However, the absence of a foundationa…
2023-01-01 · 46 citations
articleSenior authorIDS would refine this technique and incorporate additional host context (e.g., argument dataflows [13]), the Forrest IDS codifies the general strategy for host-based anomaly detection: monitor a stream of audit events to differentiate typical behaviors from anomalous (potentially malicious) activity.
Recent grants
CAREER: Scalable Information Flow Monitoring and Enforcement through Data Provenance Unification
NSF · $528k · 2018–2024
NSF · $1.2M · 2021–2026
CRII: SaTC: Transparent Capture and Aggregation of Secure Data Provenance for Smart Devices
NSF · $175k · 2017–2020
Frequent coauthors
- 27 shared
Wajih Ul Hassan
University of Virginia
- 22 shared
Kevin Butler
- 15 shared
Patrick Traynor
University of Florida
- 14 shared
Pedro Beltrán-Álvarez
Hull York Medical School
- 13 shared
Riccardo Paccagnella
Carnegie Mellon University
- 13 shared
Nolen Scaife
University of Colorado Boulder
- 13 shared
Michael Bailey
- 12 shared
Kathleen Bulmer
Hull York Medical School
Labs
STS LabPI
The STS Lab Team
Awards & honors
- 28th International Symposium on Research in Attacks, Intrusi…
- 46th IEEE Symposium on Security and Privacy (S&P'25) (2025)
- ACM CHI Conference on Human Factors in Computing Systems (20…
- 33rd USENIX Security Symposium (Security'24) (2024)
- 45th IEEE Symposium on Security and Privacy (Oakland'24) (20…
Similar researchers at University of Illinois Urbana-Champaign
- Resume-aware match score
- Save to shortlist
- AI-drafted outreach
See your match with Adam Bates
PhdFit ranks faculty by your research interests, methods, and publications — grounded in their actual work, not templates.
- Free to start
- No credit card
- 30-second signup
