Dr. Jee’s research spans three primary areas: system provenance, reversing and decompiling high-level dynamic languages, and the security and safety of small satellites in Low Earth Orbit (LEO). His work has been supported by private organizations and public agencies, including the National Science Foundation (NSF) and the National Institute of Standards and Technology (NIST).
System Provenance. Dr. Jee is a leading researcher in system provenance, with contributions to the design and deployment of comprehensive frameworks for collecting system events across diverse real-world networks. His work has focused on automating forensic analysis using system-provenance data, while improving the scalability of storage and processing systems needed to support such analysis. His current research investigates machine-learning-based security models built on system provenance, with an emphasis on adversarial evasion, model explainability, the scarcity of public datasets, and privacy challenges in provenance data sharing.
Decompilation of High-Level Dynamic Languages. As software products and malware are increasingly packaged and distributed as bytecode for high-level dynamic languages, the lack of reliable decompiler support has become a significant challenge. To address this problem, Dr. Jee’s group developed a novel approach to Python bytecode decompilation: a hybrid system that combines machine learning and programming-language techniques and adapts to changes in Python over time. PyLingual, now available as a public online service, provides a strict accuracy guarantee through perfect decompilation, enabling users to validate results and refine outputs. PyLingual was showcased at PyCon US 2024 and Black Hat USA 2024, and was accepted for presentation at the IEEE Symposium on Security and Privacy 2025.
Security and Safety of Small Satellites in LEO. Dr. Jee’s research also addresses the security and safety challenges of small satellites, whose deployment has accelerated with advances in reusable launch systems and resilient microelectronics. Building on his expertise in systems security, Dr. Jee has developed a strong foundation in space-security research. He has served as a technical panelist at an NSF SaTC workshop, presented his work at aerospace conferences, and hosted the annual small-satellite security workshop at UT Dallas. NSF supports his research on space-system security.
Selected publications (full list)
Papers are listed in chronological order.
- The Consequences of Benchmark Scarcity in Provenance-Based Intrusion Detection
S Klancher, J Flores, J Wiedemeier, M Kantarcioglu, K Jee
In Proceedings of Network and Distributed System Security Symposium (NDSS), Feb 2027 - Walking the Last Mile: Studying Decompiler Output Correction in Practice
J Wiedemeier, S Klancher, J Flores, M Zheng, J Park, SK Cha, K Jee
ACM conference on Computer and Communication Security (CCS), Oct 2025 - PyLingual: Toward Perfect Decompilation of Evolving High-Level Languages
J Wiedemeier, E Tarbet, M Zheng, S Ko, J Ouyang, SK Cha, K Jee
IEEE Symposium on Security and Privacy (Oakland), May 2025 - Evading Provenance-Based ML Detectors with Adversarial System Actions
K Mukherjee, J Wiedemeier, T Wang, J Wei, M Kim, M Kantarcioglu, K Jee
In Proceedings of Usenix Security (SEC), Aug 2023 - Reassembly is Hard: A Reflection on Challenges and Strategies
H Kim, S Kim, J Lee, K Jee, SK Cha
In Proceedings of Usenix Security (SEC), Aug 2023 - Back-Propagating System Dependency Impact for Attack Investigation
P Fang, P Gao, C Liu, E Ayday, K Jee, T Wang, Y Ye, Z Liu, X Xiao
In Proceedings of Usenix Security (SEC), Aug 2022 - SEAL: Storage-efficient Causality Analysis on Enterprise Logs with Query-friendly Compression
P Fei, Z Li, Z Wang, X Yu, D Li, K Jee
In Proceedings of Usenix Security (SEC), Aug 2021 - APTrace: A Responsive System for Agile Enterprise Level Causality Analysis
J Gui, D Li, Z Chen, J Rhee, X Xiao, M Zhang, K Jee, Z Li, and H Chen
In Proceedings of ICDE, May 2020 - You Are What You Do: Hunting Stealthy Malware via Data Provenance Analysis
Q. Wang, W. U. Hassan, D. Li, K. Jee, X. Yu, K. Zou, J. Rhee, Z. Chen, W. Cheng, C. A. Gunter, H. Chen
In Proceedings of Network and Distributed System Security Symposium (NDSS), Feb 2020 - Countering Malicious Processes with End-point DNS Monitoring
S. Sivakorn, K. Jee, Y. Sun, L. Kort-Parn, Z. Li, C. Lumezanu, Z. Wu, L. Tang, D. Li
In Proceedings of Network and Distributed System Security Symposium (NDSS), Feb 2019 - NoDoze: Combatting Threat Alert Fatigue with Automated Provenance Triage
W. U. Hassan, S. Guo, D. Li, Z. Chen, K. Jee, Z. Li, A. Bates
In Proceedings of Network and Distributed System Security Symposium (NDSS), Nov 2019 - NodeMerge: Template-Based Efficient Data Reduction For Big-Data Causality Analysis
Y. Tang, D. Li, Z. Li, M. Zhang, K. Jee, Z. Wu, J. Rhee, X. Xiao, F. Xu, Q. Li
In Proceedings of ACM conference on Computer and Communication Security (CCS), Nov 2018 - SAQL: A Stream-based Query System for Real-Time Abnormal System Behavior Detection
P. Gao, X. Xiao, D. Li, Z. Li, K. Jee, Z. Wu, C. H. Kim, S. R. Kulkarni, P. Mittal
In Proceedings of Usenix Security (SEC), Aug 2018 - AIQL: Enabling Efficient Attack Investigation from System Monitoring Data
P. Gao, X. Xiao, Z. Li, K. Jee, F. Xu, S. R. Kulkarni, P. Mittal
In Proceedings of Usenix ATC, Jul 2018 - Towards a timely causality analysis for enterprise security
Y. Liu, M. Zhang, D. Li, K. Jee, Z. Li, Z Wu, J Rhee, P Mittal
In Proceedings of Network and Distributed System Security Symposium (NDSS), Feb 2018 - High fidelity data reduction for big data security dependency analyses
Z Xu, Z Wu, Z Li, K Jee, J Rhee, X Xiao, F Xu, H Wang, G Jiang
In Proceedings of ACM conference on Computer and Communication Security (CCS), Nov 2016 - ShadowReplica: Efficient Parallelization of Dynamic Data Flow Tracking
K. Jee, V. P. Kemerlis, A. D. Keromytis, and G. Portokalidis
In Proceedings of ACM conference on Computer and Communication Security (CCS), Nov 2013 - A General Approach for Efficiently Accelerating Software-based Dynamic Data Flow Tracking on Commodity Hardware
K. Jee, G. Portokalidis, V. P. Kemerlis, S. Ghosh, D. I. August, and A. D. Keromytis
In Proceedings of Network and Distributed System Security Symposium (NDSS), Feb 2012