Mark Huasong Meng

dblp:218/5770 · also Huasong Meng 0001 · DBLP profile ↗
← Back
17ranked-venue papers
6as first author
13since 2021 · last 2026
0000-0003-1039-2151ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 7 · 2 first-author · 7 since 2021Security and privacy · 5 · 3 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 3 since 2021
YearPublicationVenuePosition
2026 Assessing Privacy Disclosure Compliance of Android Third-Party SDKs
Mark Huasong Meng, Chuan Yan, Zhang Qing cnwatcher, Kailong Wang 0001, Sin G. Teo, Guangdong Bai, Jin Song Dong 0001
IEEE Trans. Software Eng.1
2025 Understanding and Detecting File Knowledge Leakage in GPT App Ecosystem
abstract
OpenAI has enabled third-party developers to build applications around ChatGPT, known as GPTs, to expand its capability to handle complex and specialized tasks. A key feature of GPTs is Retrieval-Augmented Generation (RAG), which allows developers to upload documents containing domain knowledge or application context, referred to as file knowledge. However, these documents often contain sensitive information, and the security mechanisms governing access control in GPTs remains an underexplored area.
Chuan Yan, Bowei Guan, Yazhi Li, Mark Huasong Meng, Liuhuo Wan, Guangdong Bai
WWW4
2024 Analyzing Excessive Permission Requests in Google Workspace Add-Ons
Liuhuo Wan, Chuan Yan, Mark Huasong Meng, Kailong Wang 0001, Haoyu Wang 0001
ICECCS3
2024 Are Your Requests Your True Needs? Checking Excessive Data Collection in VPA App
abstract
Virtual personal assistants (VPA) services encompass a large number of third-party applications (or apps) to enrich their functionalities. These apps have been well examined to scrutinize their data collection behaviors against their declared privacy policies. Nonetheless, it is often overlooked that most users tend to ignore privacy policies at the installation time. Dishonest developers thus can exploit this situation by embedding excessive declarations to cover their data collection behaviors during compliance auditing.
Fuman Xie, Chuan Yan, Mark Huasong Meng, Shao-Ming Teng, Yanjun Zhang 0002, Guangdong Bai
ICSE3
2024 Exploring ChatGPT App Ecosystem: Distribution, Deployment and Security
abstract
ChatGPT has enabled third-party developers to create plugins to expand ChatGPT's capabilities. These plugins are distributed through OpenAI's plugin store, making them easily accessible to users. With ChatGPT as the backbone, this app ecosystem has illustrated great business potential by offering users personalized services in a conversational manner. Nonetheless, many crucial aspects regarding app development, deployment, and security of this ecosystem have yet to be thoroughly studied in the research community, potentially hindering a broader adoption by both developers and users. In this work, we conduct the first comprehensive study of the ChatGPT app ecosystem, aiming to illuminate its landscape for our research community. Our study examines the distribution and deployment models in the integration of LLMs and third-party apps, and assesses their security and privacy implications. We uncover an uneven distribution of functionality among ChatGPT plugins, highlighting prevalent and emerging topics. We also identify severe flaws in the authentication and user data protection for third-party app APIs integrated within LLMs, revealing a concerning status quo of security and privacy in this app ecosystem. Our work provides insights for the secure and sustainable development of this rapidly evolving ecosystem.
Chuan Yan, Ruomai Ren, Mark Huasong Meng, Liuhuo Wan, Tian Yang Ooi, Guangdong Bai
ASE3
2024 GlitchProber: Advancing Effective Detection and Mitigation of Glitch Tokens in Large Language Models
abstract
Large language models (LLMs) have achieved unprecedented success in the field of natural language processing. However, the black-box nature of their internal mechanisms has brought many concerns about their trustworthiness and interpretability. Recent research has discovered a class of abnormal tokens in the model's vocabulary space and named them "glitch tokens". Those tokens, once included in the input, may induce the model to produce incorrect, irrelevant, or even harmful results, drastically undermining the reliability and practicality of LLMs.
Wuxia Bai, Yuxi Li 0010, Mark Huasong Meng, Kailong Wang 0001, Ling Shi 0002, Li Li 0029, Jun Wang 0020, Haoyu Wang 0001
ASE4
2024 Privacy-Preserving and Fairness-Aware Federated Learning for Critical Infrastructure Protection and Resilience
abstract
The energy industry is undergoing significant transformations as it strives to achieve net-zero emissions and future-proof its infrastructure, where every participant in the power grid has the potential to both consume and produce energy resources. Federated learning -- which enables multiple participants to collaboratively train a model without aggregating the training data -- becomes a viable technology. However, the global model parameters that have to be shared for optimization are still susceptible to training data leakage. In this work, we propose confined gradient descent (CGD) that enhances the privacy of federated learning by eliminating the sharing of global model parameters. CGD exploits the fact that a gradient descent optimization can start with a set of discrete points and converges to another set in the neighborhood of the global minimum of the objective function. As such, each participant can independently initiate its own private global model~(referred to as the confined model ), and collaboratively learn it towards the optimum. The updates to their own models are worked out in a secure collaborative way during the training process.In such a manner, CGD retains the ability of learning from distributed data but greatly diminishes information sharing. Such a strategy also allows the proprietary confined models to adapt to the heterogeneity in federated learning, providing inherent benefits of fairness. We theoretically and empirically demonstrate that decentralized CGD øne provides a stronger differential privacy (DP) protection; \two is robust against the state-of-the-art poisoning privacy attacks; þree results in bounded fairness guarantee among participants; and \four provides high test accuracy (comparable with centralized learning) with a bounded convergence rate over four real-world datasets.
Yanjun Zhang 0002, Ruoxi Sun 0001, Liyue Shen, Guangdong Bai, Minhui Xue 0001, Mark Huasong Meng, Xue Li 0001, Ryan Kok Leong Ko, Surya Nepal
WWW6
2024 On the Quality of Privacy Policy Documents of Virtual Personal Assistant Applications
abstract
An app ecosystem built around virtual personal assistant (VPA) services becomes flourishing in recent years, fueled by the booming of the Internet of Things (IoT). A large number of functionality-rich VPA applications (or apps for short) have been released through app stores, and become easily-accessible by users through their smart speakers. In response to the increasingly stringent data protection regulations around the world, VPA service providers require app developers to include a privacy policy that declares their data handling practices. These privacy policies serve as the de facto agreement between developers and users, and may be taken as the basis in resolving conflicts in the event of a data breach. Therefore, it is essential that privacy policy documents are crafted in a clear, easy-to-understand, and unambiguous way. In this work, we conduct the first systematic study on the quality of privacy policies in the VPA app domain. Based on our review of literature and documents from standard working groups, we identify four metrics that enable the quality of the privacy policy to become measurable, including timeliness, availability, completeness and readability. We then develop QuPer, which extracts the meta features (e.g., update history) and linguistic features (e.g., sentence semantics) from privacy policies, and assesses their quality. Our analysis reveals that the status of the quality of privacy policies in the VPA app domain is concerning. For instance, only 1.17% of privacy policies completely cover all contents that are regarded as privacy concerns by legislation (e.g., GDPR article 13) and relevant literature. Our findings are expected to raise an alert among the VPA app developers and provide them with guidelines for creating high-quality privacy policy documents. We also encourage app store operators to implement a vetting process that ensures the quality of privacy policies before apps are released to the public.
Chuan Yan, Fuman Xie, Mark Huasong Meng, Yanjun Zhang 0002, Guangdong Bai
Proc. Priv. Enhancing Technol.3
2023 Supervised Robustness-preserving Data-free Neural Network Pruning
abstract
When deploying pre-trained neural network models in real-world applications, model consumers often encounter resource-constraint platforms such as mobile and smart devices. They typically use the pruning technique to reduce the size and complexity of the model, generating a lighter one with less resource consumption. Nonetheless, most existing pruning methods are proposed with a premise that the model after being pruned has a chance to be fine-tuned or even retrained based on the original training data. This may be unrealistic in practice, as the data controllers are often reluctant to provide their model consumers with the original data. In this work, we study the neural network pruning in the data-free context, aiming to yield lightweight models that are not only accurate in prediction but also robust against undesired inputs in open-world deployments. Considering the absence of fine-tuning and retraining that can fix the mis-pruned units, we replace the traditional aggressive one-shot strategy with a conservative one that treats model pruning as a progressive process. We propose a pruning method based on stochastic optimization that uses robustness-related metrics to guide the pruning process. Our method is evaluated with a series of experiments on diverse neural network models. The experimental results show that it significantly outperforms existing one-shot data-free pruning approaches in terms of robustness preservation and accuracy.
Mark Huasong Meng, Guangdong Bai, Sin G. Teo, Jin Song Dong 0001
ICECCS1
2023 Formalizing Robustness Against Character-Level Perturbations for Neural Network Language Models
Zhongkui Ma, Xinguo Feng, Shuofeng Liu, Mengyao Ma, Hao Guan 0001, Mark Huasong Meng
ICFEM7
2023 Post-GDPR Threat Hunting on Android Phones: Dissecting OS-level Safeguards of User-unresettable Identifiers
Mark Huasong Meng, Zhang Qing cnwatcher, Guangshuai Xia, Yuwei Zheng, Yanjun Zhang 0002, Guangdong Bai, Sin G. Teo, Jin Song Dong 0001
NDSS1
2023 Enhancing Federated Learning Robustness Using Data-Agnostic Model Pruning
Mark Huasong Meng, Sin G. Teo, Guangdong Bai, Kailong Wang 0001, Jin Song Dong 0001
PAKDD (2)1
2022 Detecting Contradictions from CoAP RFC Based on Knowledge Graph
Xinguo Feng, Yanjun Zhang 0002, Mark Huasong Meng, Sin G. Teo
NSS3
2018 Analyzing Use of High Privileges on Android: An Empirical Case Study of Screenshot and Screen Recording Applications
Mark Huasong Meng, Guangdong Bai, Joseph K. Liu, Xiapu Luo, Yu Wang 0017
Inscrypt1
2018 BIFF: A Blockchain-based IoT Forensics Framework with Identity Privacy
abstract
The ubiquitous deployment of Internet of Things (IoT) devices enhances connectivity and communication, and benefits almost every aspect of our lives from manufacturing to retail to smart homes. However, low levels of security protection in these devices due to their limited resources open opportunities for malicious users. An IoT forensics system collecting, processing, analyzing and reporting evidence of attack is required to mitigate the IoT security issues. Although such system has been studied over the past decade and solutions such as cloud-based IoT forensic were proposed, limitation still exist. In this paper, leveraging on the blockchain technology, we propose a per-missioned blockchain-based IoT forensics framework to enhance the integrity, authenticity and non-repudiation properties for the collected evidence. We formally define the system architecture, provide framework details, and propose a cryptographic-based approach to mitigate identity privacy concern.
Duc-Phong Le, Mark Huasong Meng, Le Su, Sze Ling Yeo, Vrizlynn L. L. Thing
TENCON2
2018 Progressive Control Flow Obfuscation for Android Applications
abstract
Android bytecode is easy to reverse engineer. It has been a common practice for Android application developers to protect their applications with obfuscation techniques. Control flow obfuscation aims to make it more difficult to determine the actual application control flows and thereby impede the understanding of the application logic by the attacker. Despite of the strong potency (i.e., high complexity increment), control flow obfuscation usually incurs a large overhead due to the call and return instructions inserted, which makes the application developer reluctant to use it in practice. In this paper, we present a pragmatic control-flow obfuscation approach where the application developer has more freedom to customize the trade-off between the achieved complexity and overhead. A new subset of application methods will be obfuscated by using a combination of packed-switch and try-catch constructs in different rounds, and larger methods are obfuscated by creating more code fragments in earlier rounds. After each round, the complexity increment will be automatically calculated using our implemented cyclomatic complexity based metric and checked against the target complexity increment. In other words, the obfuscation is conducted in a progressive manner until the target complexity increment is reached. The experimental results show that our method incurs averaged area overhead of 4.07% while achieving almost double complexity increment than the existing method when the same number of application methods are obfuscated.
Mark Huasong Meng, Vrizlynn L. L. Thing
TENCON2
2018 A survey of Android exploits in the wild
Mark Huasong Meng, Vrizlynn L. L. Thing, Zhongmin Dai
Comput. Secur.1