VLDB 2026 Research / reviewers in the wild / expert
Mingxuan Yao
dblp:210/4952
· DBLP profile ↗
13ranked-venue papers
2as first author
10since 2021 · last 2026
0000-0002-0225-5141ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 2 first-author · 10 since 2021Computer networks · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Achieving Zen: Combining Mathematical and Programmatic Deep Learning Model Representations for Attribution and Reuse
David Oygenblik, Dinko Dermendzhiev, Filippos Sofias, Mingxuan Yao, Haichuan Xu, Jeman Park 0001, Amit Kumar Sikder, Brendan Saltaformaggio |
NDSS | 4 |
| 2026 | Fuzzing the Physical Space: Physics-Aware Testing of Black-Box Industrial Control Systems
Burak Sahin, David Oygenblik, Mingxuan Yao, Brendan Saltaformaggio, Saman A. Zonouz |
SP | 3 |
| 2026 | Recovering and Rehosting Mobile Local LLM Conversations and Contexts via Memory Forensics
Haichuan Xu, David Oygenblik, Mingxuan Yao, Brendan Saltaformaggio |
SP | 4 |
| 2025 | Enhanced Web Application Security Through Proactive Dead Drop Resolver Remediation
Jonathan Fuller 0001, Mingxuan Yao, Saumya Agarwal, Srimanta Barua, Taleb Hirani, Amit Kumar Sikder, Brendan Saltaformaggio |
CCS | 2 |
| 2025 | Lock the Door But Keep the Window Open: Extracting App-Protected Accessibility Information from Browser-Rendered WebsitesabstractThe Android accessibility (a11y) service has been widely utilized by malware to abuse benign services.To prevent such abuse, developers need to secure a11y content access in both their apps and mobile websites.However, a misalignment of a11y protection mechanisms exists between them.Prior research has focused on attacking and defending a11y information embedded in native Android apps.However, our research found that a11y malware can retrieve app-protected a11y information in its mobile browser-rendered website counterpart, leaving mobile browser users more vulnerable to a11y attacks than app users.To help benign service developers vet this attack surface, we developed SOMBRA, an automated analysis pipeline to vet browser-side leakage of a11y information that is a11y-protected in apps.Using SOMBRA, we analyzed 294 benign services and found 29 of them deploy app-side a11y protection mechanisms to secure 256 views.SOMBRA discovered that 241, 402, 244, and 251 elements corresponding to their protected app-side views are a11y-exposed in their websites rendered by Chrome, Firefox, Brave, and Edge browsers, respectively.The leaked elements contain sensitive personal identifiable information.Finally, SOMBRA discovered that most developers do not adopt browser-side a11y protections because existing mechanisms either have ineffective protection or hinder the usability of their content. Haichuan Xu, Mingxuan Yao, David Oygenblik, Jeman Park 0001, Brendan Saltaformaggio |
CCS | 3 |
| 2025 | Hitchhiking Vaccine: Enhancing Botnet Remediation With Remote Code Deployment Reuse
Mingxuan Yao, Haichuan Xu, Omar Alrawi, Jeman Park 0001, Brendan Saltaformaggio |
NDSS | 2 |
| 2025 | Identifying Incoherent Search Sessions: Search Click Fraud Remediation Under Real-World ConstraintsabstractSearch engines and advertisers continuously suffer substantial financial losses from click fraud, which poses challenges to existing detection algorithms. Even more concerning, despite ongoing advancements, our understanding of click fraud remains limited, leaving room for sophisticated fraudulent techniques to bypass existing detection measures. In this study, we pivot from examining individual search requests to analyzing search sessions, defined as sequences of consecutive search queries made by the same user. We found that benign users exhibit coherent behavior patterns within these sessions, which contrast clearly with those of fraudulent actors. Specifically, legitimate users tend to conduct searches focused on a single topic at a time. In contrast, fraudsters or automated bots often exhibit diverse, illogical, and incoherent search behaviors within a session. To address this behavioral distinction, we propose CoSeC, a system designed to quantify the “incoherence index” of search sessions. CoSeC integrates literal semantic, temporal, and ad-click behavioral features to evaluate sessions' coherence quantitatively. Our evaluation of CoSeC demonstrates high efficacy, achieving a precision of 95.79% and a recall of 92.40% in identifying incoherent sessions, highlighting CoSeC's substantial potential to enhance real-world click fraud detection. Ranjita Pai Sridhar, Mingxuan Yao, David Oygenblik, Haichuan Xu, Vacha Dave, Cormac Herley, Paul England, Brendan Saltaformaggio |
SP | 3 |
| 2024 | Pulling Off The Mask: Forensic Analysis of the Deceptive Creator Wallets Behind Smart Contract FraudabstractCriminals, using crypto wallets referred to as Deceptive Creator Wallets (DCWs), have orchestrated fraudulent activities by luring victims to transfer funds to fraud smart contracts. Since it is almost impossible to reverse the transactions or pinpoint the true identity of the criminals, the industry has turned to flagging such contracts as user warnings. However, current mitigation efforts focus on individual contracts, overlooking the DCWs behind the scenes. Consequently, our research found that this oversight allows fraud to thrive. To address this, we developed CoCo, an automated forensic analysis pipeline that processes a single fraud contract and generates evidence that the legal authorities need to mitigate the fraud. Applying CoCo to 157 confirmed fraud contracts, our research uncovered 1,283,198 associated contracts linked to 91 DCWs, responsible for 2,638,752 ETH ($2,089,504,682) in illicit profits. More alarmingly, CoCo traces the fraudulent activities back to September 2017. In response, we are closely collaborating with Etherscan and the FBI to combat the fraud identified in our study. Mingxuan Yao, Haichuan Xu, Shih-Huan Chou, Paturi Varun Chowdhary, Amit Kumar Sikder, Brendan Saltaformaggio |
SP | 1 |
| 2024 | DVa: Extracting Victims and Abuse Vectors from Android Accessibility Malware
Haichuan Xu, Mingxuan Yao, Mohamed Moustafa Dawoud, Jeman Park 0001, Brendan Saltaformaggio |
USENIX Security Symposium | 2 |
| 2023 | Hiding in Plain Sight: An Empirical Study of Web Application Abuse in Malware
Mingxuan Yao, Jonathan Fuller 0001, Ranjita Pai Kasturi, Saumya Agarwal, Amit Kumar Sikder, Brendan Saltaformaggio |
USENIX Security Symposium | 1 |
| 2019 | A Practical and Compatible Cryptographic Solution to ADS-B SecurityabstractAs the heart of next-generation air transportation systems, the automatic dependent surveillance-broadcast (ADS-B) is becoming a substitute for the radar, because it can enhance flight safety by requiring aircraft to regularly broadcast their precise geographic positions. Despite its promise, the lack of security mechanisms, e.g., not providing data encryption and message authentication, is a significant barrier to realistically deploy this new technology. While many methods have been proposed for ADS-B security, they can deal with either privacy or integrity unilaterally, and also need to change current ADS-B standards. In this paper, we present a new cryptographic solution to ADS-B security by first carefully exploiting some cryptographic primitives, and then adapting them to the air traffic-monitoring scenario. In contrast to previous approaches, our proposed solution is not only of high compatibility with existing protocols of ADS-B, but also lightweight for congested data links and resource-constraint avionics. Furthermore, it can also tolerate package loss and disorder that frequently occur in ADS-B wireless broadcast networks, making the proposed solution easy-to-deploy and practical. Security analysis shows that our proposal simultaneously achieves the confidentiality and authenticity of ADS-B messages. In addition, performance evaluation also demonstrates the efficiency of communication and computation for the proposal by using flight data of OpenSky-a sensor network that covers Central Europe aiming at gathering ADS-B flight data. Finally, the deployment in a real airport environment also proves the effectiveness of our solution. Haomiao Yang, Qixian Zhou, Mingxuan Yao, Rongxing Lu, Hongwei Li 0001, Xiaosong Zhang 0001 |
IEEE Internet Things J. | 3 |
| 2017 | LHCSAS: A Lightweight and Highly-Compatible Solution for ADS-B SecurityabstractAutomatic Dependent Surveillance - Broadcast (ADS-B), as the key component of next-generation air transportation system, becomes the replacement of secondary surveillance radar (SSR) since it will enhance air traffic control by requiring the aircraft periodically broadcast its geographical information. But the obstacle blocking the deployment of the promising ADS-B belongs to security concerns where ADS-B messages are all transmitted in the clear and can be forged and modified easily. The already proposals for ADS-B security refer to the privacy or integrity unilaterally, and all require the modification of existing ADS-B protocols. In this paper, we design ingeniously a solution for ADS-B security, by integrating carefully some recent specific crypto primitives, and then modifying properly them to adapt to ADS-B features. As opposed to previous methods, our solution is at the same time (1) lightweight for resource- constraint avionics devices and already congested data links, (2) highly-compatible to existing ADS-B protocols, (3) tolerating package loss for ADS-B broadcast data links. This makes our solution particularly practical and easy-deploying. Security analysis indicates that our solution can achieve confidentiality and integrity of ADS-B messages, and performance evaluation, based on the real-world ADS-B data, proves efficiency of our solution from cost of computation and communication. Furthermore, the deployment on a real airport environment demonstrates high compatibility of our solution. Haomiao Yang, Mingxuan Yao, Zili Xu, Baoshu Liu |
GLOBECOM | 2 |
| 2017 | Privacy-Preserving Extraction of HOG Features Based on Integer Vector Homomorphic Encryption
Haomiao Yang, Yunfan Huang, Yong Yu 0002, Mingxuan Yao, Xiaosong Zhang 0001 |
ISPEC | 4 |