Yiyu Yang

dblp:219/9331 · DBLP profile ↗
← Back
13ranked-venue papers
3as first author
12since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 2 first-author · 6 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 WLCHAT-PDP: Provable Data Possession Based on Weighted Link-List Chameleon Hash Authentication Tree in Edge Computing
abstract
In Internet of Things (IoT) scenarios, the integrity audit of massive amounts of data uploaded from Edge Nodes (ENs) to the cloud poses significant challenge to researchers. Existing Provable Data Possession (PDP) schemes suffer from low communication and computational efficiency, as well as the issue of Third-Party Auditors (TPAs) not being completely trustworthy, especially in dynamic data update scenarios. This paper designs an efficient authentication structure, named the Weighted Link-list Chameleon Hash Authentication Tree (WLCHAT), to reduce cloud storage overhead and improve dynamic update efficiency. Based on this, the paper further proposes the WLCHAT-PDP scheme, which is built upon the WLCHAT structure. Building on the PDP model, the proposed scheme introduces the ENs to proxy user operations for tag generation and to participate in the audit process. By combining this with a user authorization signature mechanism, the proposed scheme not only alleviates terminal computational load but also guarantees that all operations are authorized. To enhance the credibility of the audit process, the proposed scheme incorporates blockchain-anchored log records to effectively prevent collusive behavior between cloud service providers and TPAs. Theoretical analyses and comparative evaluation demonstrate that the scheme achieves a balance between security and computational overhead, rendering it suitable for dynamic and trusted IoT cloud storage environments.
Youjun Xu, Yiyu Yang, Dengqi Yang, Chengzhe Lai
Peer Peer Netw. Appl.4
2026 Low-resource video-conditioned music generation via reliability-aware visual-text-audio fusion
Yiyu Yang
Vis. Comput.2
2025 A prompt tuning method based on relation graphs for few-shot relation extraction
Yiyu Yang, Benhui Chen
Neural Networks2
2025 Sharing Can be Threatening: Uncovering Security Flaws of RBAC Model on Smart Home Platforms
abstract
The “sharing” feature provided by smart home platforms enables multiple users to access the device simultaneously with different roles and permissions, but it also presents new security challenges for the design and implementation of the permission management. The key issue is that the platform adopts two different permission assignments on the app side and the cloud side, and these two assignments must maintain consistency in authorizing. Unfortunately, real-world smart home platforms may not be able to ensure this when implementing RBAC (Role-Based Access Control) model. The inconsistency between these assignments may lead to security vulnerabilities, which can be easily exploited by malicious users. Although many existing studies have revealed security issues with smart home platforms, less attention has been paid to the sharing feature and permission assignments, as well as security issues that arise from this. In this work, we conducted a systematic study on the RBAC model and permission management of smart home platforms. To overcome technical challenges imposed by the “black-box” platform, we also proposed a novel testing framework. By testing 10 smart home platforms that all belong to the “device-connected, black-box, and multi-user supported” category, we collected each platform's “configurable permission assignment” and inferred “enforced permission assignment”. At last, we identified 44 inconsistencies that could lead to security vulnerabilities. Malicious users could exploit these vulnerabilities to initiate attacks such as device hijacking, unauthorized access, illegal control, and eavesdropping. We promptly reported these vulnerabilities to vendors and CNVD, and proposed mitigation measures.
Yiyu Yang, Yilian Li, Xiaowei Li 0001, Peng Liu 0005, Yuqing Zhang 0001
IEEE Trans. Dependable Secur. Comput.1
2025 Identifying Implementation Flaws of SMS OTP Authentication
abstract
Currently, the Short Message Service (SMS) One-Time Passwords (OTP) authentication is widely adopted in mobile applications. However, due to improper implementation by developers, significant security flaws exist in the SMS OTP authentication mechanisms of some apps. To provide a comprehensive and accurate assessment, we propose a new approach. First, we locate the SMS OTP authentication page through UI exploration. Then, using hooking technology, we conduct simulated attacks to verify the security of the SMS OTP authentication in the app, focusing on its susceptibility to brute-force attacks. This approach is applicable to apps with app-side or UI-layer protection measures, uncovering hidden implementation flaws beneath these protections. Technically, we employ dynamic analysis based on the ART virtual machine instrumentation to obtain runtime information of the app and generate vulnerability verification scripts, overcoming the challenges posed by code-packing in program analysis. We implemented a semi-automatic tool namedAuthCheckerand tested it on 950 popular apps, identifying 87 apps with security flaws that potentially allow attackers to achieve unauthorized account access. Our findings highlight the security issues in SMS OTP authentication of apps, promoting improvements in vulnerability patching and preventive strategies by developers.
Fannv He, Yiyu Yang, Yuqing Zhang 0001
IEEE Trans. Mob. Comput.3
2024 Prompt Tuning for Few-shot Relation Extraction via Modeling Global and Local Graphs
abstract
Recently, prompt-tuning has achieved very significant results for few-shot tasks. The core idea of prompt-tuning is to insert prompt templates into the input, thus converting the classification task into a masked language modeling problem. However, for few-shot relation extraction tasks, how to mine more information from limited resources becomes particularly important. In this paper, we first construct a global relation graph based on label consistency to optimize the feature representation of samples between different relations. Then the global relation graph is further divided to form a local relation subgraph for each relation type to optimize the feature representation of samples within the same relation. This fully uses the limited supervised information and improves the tuning efficiency. In addition, the existence of rich semantic knowledge in relation labels cannot be ignored. For this reason, this paper incorporates the knowledge in relation labels into prompt-tuning. Specifically, the potential knowledge implicit in relation labels is injected into constructing learnable prompt templates. In this paper, we conduct extensive experiments on four datasets under low-resource settings, showing that this method achieves significant results.
Yiyu Yang, Benhui Chen
LREC/COLING2
2024 SHPAC: Fine-grained and Multi-platform Supported Access Control System for Smart Home Scenario
abstract
In the scenario of multi-user access in smart homes, the platform’s access control mechanism is crucial in ensuring that users can legitimately and appropriately access devices. However, we have found that the permission management mechanisms provided by smart home platforms and the solutions proposed in academic research are insufficient to fully meet the new requirements of access control. This can result in issues such as unauthorized access, inability to coordinate access conflicts, and lack of support for black-box platforms. In this paper, we present SHPAC, a new smart home access control scheme based on Policy-Based Access Control. This scheme not only provides fine-grained permission management, but also supports users in submitting their personalized access preferences, as well as automatic conflict resolution and multi-platform support. We also implemented a prototype system and evaluated the system from the perspectives of black-box platform support, access control performance, and policy management effectiveness. The results show that our design can address the shortcomings of existing solutions, enhancing the flexibility and effectiveness of smart home access control.
Yiyu Yang, Yuqing Zhang 0001
ICCCN1
2024 Relation-aware heterogeneous graph neural network for entity alignment
Yiyu Yang, Benhui Chen
Neurocomputing2
2024 Uncovering Access Token Security Flaws in Multiuser Scenario of Smart Home Platforms
abstract
Access tokens have been thoroughly researched in website and mobile application security. However, we believe that the traditional application of access tokens must fulfill new security requirements in smart home environments due to the distinct features of multiuser sharing usage. Smart home platforms allow different types of users to share access to a single IoT device through mobile apps, with varying levels of permissions that are closely tied to access tokens. One security concern is that existing security standards or literature, as well as the development and implementation by vendors, may overlook these features, thereby introducing potential security risks to the application of access tokens. In this work, we propose a novel testing framework and conduct a systematic study to test the extent to which real-world smart home platform implementations neglect these new requirements. The testing results show that seven out of the 11 real-world smart home platforms are plagued by access token management flaws, which collectively violate four security properties. We have found that these security flaws can be exploited to enable unrestricted file upload, DoS attack, remote command execution, and illegal surveillance in real-world scenarios. Finally, we conducted responsible disclosure of these flaws and attacks and obtained seven China national vulnerability database vulnerability IDs and one CVE vulnerability ID. Additionally, we also provide suggestions for mitigating the vulnerabilities.
Yiyu Yang, Jice Wang, Peng Liu 0005, Anmin Fu, Yuqing Zhang 0001
IEEE Internet Things J.1
2023 An Improved Relation Extraction Method Based on Information Control Injection and Attention-Guided Densely Connected Graph Convolutional Network
abstract
The extraction of entities and multi-type relations in overlapping triples has been a challenging problem. This paper proposes a relation extraction method based on information control injection and attention-guided densely connected graph convolutional networks by dividing the model into two stages inspired by the GraphRel [1] approach. Considering that the shallow graph convolutional network (GCN) used by GraphRel can only capture local structural information on large graphs, this paper uses the multi-head attention mechanism to form different weight matrices. It extracts deeper structural information in the text by combining it with a densely connected graph convolutional network (DCGCN). In addition, the features extracted by DCGCN are not entirely correct. Therefore, this paper uses KL-divergence to control the degree of information injection to obtain a better feature representation. To verify the model's effectiveness, we conducted extensive experiments on two widely used public datasets: NYT and WebNLG. The results show that compared to GraphRel, the F1 value of the model improves by 24.8% on the NYT dataset and 35.9% on the WebNLG dataset. More importantly, the model significantly improved in extracting overlapping relations.
Fanfang Meng, Yuanhui Meng, Yiyu Yang, Benhui Chen
IJCNN5
2022 Unfettered Access Tokens: Discovering Security Flaws of the Access Token in Smart Home Platforms
abstract
In the smart home platform communication, the access token might properly represent the user’s identity and access permissions. Any access token used in multi-user smart home access should be rigorously regulated by the cloud to guarantee that users only use their devices in permitted ways. However, we were astonished to discover that access tokens in certain popular smart home platforms are unfettered, allowing attackers to illegally eavesdrop on or control IoT devices connected to the cloud. While the access token is essential for managing smart home permissions, there are currently no security checks in place. The fundamental reason is that many standard Web testing tools that check the security of access tokens are disabled by SSL/TLS encryption. Furthermore, whereas many previous studies have focused on the security of OAuth2.0 or smart home apps, only a small amount of research has combined the two. We presented a systematic analysis on smart home platform access token security in this paper. Furthermore, we created a testing tool that allowed us to reuse the app’s underlying logic while also overcoming SSL/TLS encryption issues. We used this tool to examine the security of access tokens in a number of major smart home platforms. Finally, we discovered three types of security issues in seven platforms, one of which is the DoR (Denial of Refresh) flaw, which we discovered for the first time. Our tests revealed that attackers may use these security issues to exploit a total of 106 cloud APIs, posing a serious security risk to device owners.
Yiyu Yang, Yuqing Zhang 0001
ICC2
2022 Fingerprinting Mainstream IoT Platforms Using Traffic Analysis
abstract
The Internet of Things (IoT) platforms have been widely used in many application scenarios, especially for the smart home. Under the management of the IoT platform, a massive amount of IoT devices have been connected between remote cloud servers and users’ mobile terminals. While bringing unprecedented convenience for device manufacturers and smart home users, the existence of mainstream IoT platforms has also become the primary target for malicious attackers. Thus, many intrusion detection mechanisms of specific IoT platform traffic have been proposed. However, as a prerequisites work of intrusion detection or vulnerability assessment, identifying target IoT platform traffic among real-world network traffic has not been deeply studied. Given this situation, we first time proposed and achieved “fingerprinting” for IoT platform traffic. We designed a set of standardized workflows of traffic capturing, fingerprint feature extraction, and fingerprint model construction. Based on such workflow, we implemented a software tool named IoTPF for distinguishing the traffic between the mobile terminal and remote server of different mainstream IoT platforms among network traffic. We also tested the usability and performance of IoTPF. Finally, we discuss the application scenarios of fingerprinting on IoT platforms.
Xixun He, Yiyu Yang, Wei Zhou 0026, Peng Liu 0005, Yuqing Zhang 0001
IEEE Internet Things J.2
2020 IoT-APIScanner: Detecting API Unauthorized Access Vulnerabilities of IoT Platform
abstract
The Internet of Things enables interaction between IoT devices and users through the cloud. The cloud provides services such as account monitoring, device management, and device control. As the center of the IoT platform, the cloud provides services to IoT devices and IoT applications through APIs. Therefore, the permission verification of the API is essential. However, we found that some APIs are unverified, which allows unauthorized users to access cloud resources or control devices; it could threaten the security of devices and cloud. To check for unauthorized access to the API, we developed IoT-APIScanner, a framework to check the permission verification of the cloud API. Through observation, we found there is a large amount of interactive information between IoT application and cloud, which include the APIs and related parameters, so we can extract them by analyzing the code of the IoT application, and use this for mutating API test cases. Through these test cases, we can effectively check the permissions of the API. In our research, we extracted a total of 5 platform APIs. Among them, the proportion of APIs without permission verification reached 13.3%. Our research shows that attackers could use the API without permission verification to obtain user privacy or control of devices.
Yilian Li, Yiyu Yang, Lihua Dong, Wengjie Wang
ICCCN2