VLDB 2026 Research / reviewers in the wild / expert
Wanpeng Li
dblp:132/9738
· DBLP profile ↗
16ranked-venue papers
5as first author
9since 2021 · last 2026
0000-0002-6396-9578ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 4 first-author · 4 since 2021Systems, architecture and hardware · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CRX-ray: Large-Scale Detection of API Key Leakage in Browser ExtensionsabstractThe rapid proliferation of AI-enabled browser extensions has introduced significant security vulnerabilities. These client-side applications, distributed with exposed source files, frequently embed API keys from AI platforms - credentials designed to track usage for billing and prevent misuse. The exposure of these API keys poses substantial financial and operational risks to extension developers. This study presents the first comprehensive security analysis of API key leakage in browser extensions. We systematically analyzed 163,924 extensions across Chrome, Firefox, and Edge stores, uncovering 3,677 unique leaked API keys across 4,145 extensions. Most critically we identified 300 exposed AI platform keys across 309 extensions that collectively serve 1,045,339 users. Furthermore, our analysis reveals prominent reuse of API keys across different extensions, along with instances of multiple keys being used by single extensions. In this paper, we introduce the CRX-ray detection framework to identify API key leakage in browser extensions. By open-sourcing CRX-ray, we aim to empower developers to identify and mitigate API key leakage, fostering the development of more secure browser extensions that protect both developers and users. Zhi Wang 0014, Valerio Bucci, Yuejun Guo 0001, Wanpeng Li |
AsiaCCS | 8 |
| 2026 | PerCheck: An AST-Based Framework for Detecting Over-Privilege in Chrome Extensions
Zhi Wang 0014, Wanpeng Li, Lifei Sun |
ICIC (11) | 3 |
| 2025 | Time-delayed fractional grey Bernoulli model with independent fractional orders for fossil energy consumption forecasting
Xin Ma 0004, Qingping He, Wanpeng Li, Wenqing Wu 0001 |
Eng. Appl. Artif. Intell. | 3 |
| 2025 | Group-Grained Data Search and Sharing With Privacy Protection for Vehicular Social NetworksabstractVehicular social networks (VSNs) play a crucial role in intelligent transportation systems, offering high-quality data management services that enhance various aspects of daily life. Due to their convenience, VSN systems, equipped with advanced data search and sharing capabilities, are increasingly integrated into modern vehicles. While earlier VSNs focused on securing data communication between users, the transmission of sensitive vehicle and traffic data, like road conditions and vehicle trajectories, has raised privacy concerns and the risk of data leakage, which could harm vehicle owners’ interests. Historically, these systems focused primarily on securing data communication between VSN users. However, the transmission of sensitive vehicle and traffic data, such as road conditions and vehicle trajectory information, has raised concerns about data privacy and the potential risks of data leakage, which could compromise the interests of vehicle owners. To address these challenges, we propose a novel group-grained data search and sharing scheme for VSN systems. Unlike traditional attribute-based encryption methods used in data management, our approach introduces a group-grained model that enables fine-grained control over search rights and data-sharing isolation, ensuring enhanced data privacy. Additionally, to reduce the computational burden on these Internet of Thing (IoT) devices, our scheme ensures constant-sized keyword index generation, data index generation, trapdoor creation, and decryption processes. We evaluate the efficiency of our construction and compare it with similar constructions. The results demonstrate that our construction is well suited for resource-constrained IoT devices in VSN systems. Rang Zhou, Wanpeng Li, Xiaojiang Du, Mohsen Guizani |
IEEE Internet Things J. | 3 |
| 2025 | Subversion-resistant public-key searchable encryption for data sharing in IIoT
Rang Zhou, Yongkang He, Wanpeng Li |
J. Syst. Archit. | 3 |
| 2024 | Poster: Automated Dependency Mapping for Web API Security Testing Using Large Language ModelsabstractDependency extraction is crucial in web API security testing, as it helps identify the required API sequences to exploit a vulnerability. Traditional methods are generally rule-based and require extensive manual analysis of API specification documents by domain experts to formulate appropriate rules. This manual process is not only time-consuming and labor-intensive but also prone to missing dependencies and inaccuracies, which can compromise the effectiveness of security testing. In this paper, we explore the potential of large language models (LLMs) to automate dependency mapping in web APIs. By leveraging the capabilities of advanced LLMs such as GPT-3.5, Mistral-7B-Instruct, and Llama-3-8B-Instruct, which include understanding and generating natural language, we aim to streamline the dependency mapping process, reducing the need for manual analysis and enhancing accuracy. Our preliminary experiments demonstrate that this approach can effectively build dependency mappings, offering a a promising alternative to traditional rule-based approaches. Wanpeng Li, Yuejun Guo 0001 |
CCS | 1 |
| 2023 | From Manifest V2 to V3: A Study on the Discoverability of Chrome Extensions
Valerio Bucci, Wanpeng Li |
ISC | 2 |
| 2023 | A Broadband Subliminal Channel in Signatures Without Sharing the Signing KeyabstractThe utilization of the broadband subliminal channel allows a sender to covertly transmit a message to a receiver through digital signatures. This method requires the sender to relinquish the signing key to the receiver. As a result, the receiver has the ability to employ the signing key to sign any data on behalf of the sender without the sender’s knowledge or consent. Meanwhile, difficulties may arise if the sender is unwilling to disclose the signing key to the receiver. In this paper, we propose a broadband subliminal channel that can be used in digital signature schemes (e.g., DSA, ECDSA, ElGamal, and Schnorr) without disclosing the signing key to the receiver. As it writes the message on a digital signature, we call it WMoS. We first implement WMoS in the Elliptic Curve Digital Signature Algorithm (ECDSA). We then provide the security proof to show that signatures generated in WMoS have the same security level as standard ECDSA signatures. Moreover, we discuss the variants of WMoS in ECDSA and use them to construct applications. Furthermore, we use the implementation of WMoS to generate a signature for an Ethereum transaction to demonstrate its feasibility. We also evaluate the efficiency of WMoS in ECDSA, and the results show that WMoS in ECDSA can generate a signature as efficiently as the standard ECDSA. Qinghua Hu, Chunxiang Xu, Wanpeng Li |
TrustCom | 3 |
| 2021 | ICAS: Two-factor identity-concealed authentication scheme for remote-servers
Chunxiang Xu, Chuang Li 0008, S. M. Hasan Mahmud, Wanpeng Li |
J. Syst. Archit. | 6 |
| 2018 | Keyword Searchable Encryption with Fine-Grained Forward Secrecy for Internet of Thing Data
Rang Zhou, Xiaosong Zhang 0001, Guowu Yang, Wanpeng Li |
ICA3PP (4) | 5 |
| 2018 | Beyond Cookie Monster Amnesia: Real World Persistent Online Tracking
Nasser Mohammed Al-Fannah, Wanpeng Li, Chris J. Mitchell |
ISC | 2 |
| 2018 | Mitigating CSRF attacks on OAuth 2.0 SystemsabstractMany millions of users routinely use Google, Facebook and Microsoft to log in to websites supporting OAuth 2.0 and/or OpenID Connect. The security of OAuth 2.0 and OpenID Connect is therefore of critical importance. Unfortunately, as previous studies have shown, real-world implementations of both schemes are often vulnerable to attack, and in particular to cross-site request forgery (CSRF) attacks. In this paper we propose a new and practical technique which can be used to mitigate CSRF attacks against both OAuth 2.0 and OpenID Connect. Wanpeng Li, Chris J. Mitchell, Thomas M. Chen |
PST | 1 |
| 2016 | Analysing the Security of Google's Implementation of OpenID Connect
Wanpeng Li, Chris J. Mitchell |
DIMVA | 1 |
| 2014 | Security Issues in OAuth 2.0 SSO Implementations
Wanpeng Li, Chris J. Mitchell |
ISC | 1 |
| 2013 | New forward-secure signature schemes with untrusted update
Wanpeng Li, Chunxiang Xu, Shixiong Zhu, Xiujie Zhang |
Frontiers Comput. Sci. | 1 |
| 2013 | Threshold public key encryption scheme resilient against continual leakage without random oracles
Xiujie Zhang, Chunxiang Xu, Wanpeng Li |
Frontiers Comput. Sci. | 4 |