VLDB 2026 Research / reviewers in the wild / expert
Le Yu 0002
dblp:23/7122-2
· DBLP profile ↗
52ranked-venue papers
11as first author
34since 2021 · last 2026
0000-0003-1457-6329ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 17 · 4 first-author · 10 since 2021Security and privacy · 15 · 4 first-author · 11 since 2021Computer networks · 11 · 1 first-author · 6 since 2021Systems, architecture and hardware · 5 · 4 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MTFuzz: A Novel Efficacy Fuzzing Framework for Aerospace Monolithic Firmware
Shuai Wang 0012, Xi Xiao 0001, Guangwu Hu, Kehuan Zhang, Le Yu 0002, Chengpei Tang, Qing Li 0006, Qizhen Xu |
DSN | 5 |
| 2026 | RisConFix: LLM-Based Automated Repair of Risk-Prone Drone Configurations
Liping Han, Tingting Nie, Le Yu 0002, Mingzhe Hu, Tao Yue 0002 |
SANER | 3 |
| 2026 | Traffic burst relational graph attention network combined position encoding for traffic classification
Xi Xiao 0001, Siji Chen, Guangwu Hu, Le Yu 0002, Qing Li 0006, Hao Li 0027, Qingjun Yuan |
Comput. Networks | 5 |
| 2026 | NASchecker: Automatically Identifying the Performance, Security, and Privacy Issues of NAS DevicesabstractNetwork attached storage (NAS) devices are widely deployed for personal data storage. However, their distributed architecture and limited inspection interfaces pose significant challenges for comprehensive performance, security, and privacy analysis. In this paper, we first establish a threat model for NAS ecosystems. Then, we present a systematic framework NASchecker for discovering performance optimization mechanisms, security threats, and privacy leakage in NAS devices. By analyzing traffic generated during varied file operations on crafted files, NASchecker infers implemented optimizations and identifies security flaws within the traffic (e.g., susceptibility to passive sniffing and replay attacks). NASchecker also integrates NAS-specific protocol fuzzing and firmware reverse engineering to uncover deep-seated command injection, memory corruption, and improper access control vulnerabilities. NASchecker compares personally identifiable information (PII) leaked in traffic against declarations in privacy policies to detect privacy compliance issues. We evaluated NASchecker on twelve commercial NAS devices. Our results reveal that none of the tested devices employ file compression or deduplication. From a security standpoint, ten devices are vulnerable to passive sniffing and seven to replay attacks. Moreover, seven devices are affected by command injection, four by memory corruption, and eleven by improper access control. From a privacy perspective, four devices leaked PIIs that were not disclosed in their respective privacy policies. After reporting the findings to the manufacturers, we have been acknowledged by several manufacturers, resulting in the assignment of 20 CVEs and 6 NVDB entries (16 of them are rated as high severity). These findings validate NASchecker’s effectiveness and underscore the urgent need for improved design and testing practices of NAS. Guangyue Ren, Le Yu 0002, Liping Han, Mingzhe Hu, Wei Chen 0006, Tingting Liu 0005, Xiapu Luo, Guozi Sun |
IEEE Internet Things J. | 3 |
| 2026 | Clash: Enhancing context-sensitivity in data-flow analysis for mitigating the impact of indirect calls
Jinyan Xie, Yingzhou Zhang, Mingzhe Hu, Liping Han, Le Yu 0002, Qiuran Ding |
J. Syst. Softw. | 5 |
| 2026 | DSMalConv: Multi-Modal Malware Detection Based on Dempster-Shafer Evidence Uncertainty
Haiping Huang, Le Yu 0002, Reza Malekian, Fu Xiao 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | MCLPF: Malware Collaborative Detection With LLM-Enhanced Pruning for Attributed Interpretable Flow GraphsabstractWith the increasing sophistication of malware, enhanced Attributed Control Flow Graphs (ACFGs) have become a fundamental representation and are widely applied in malware detection. However, existing CFG-based detection techniques primarily extract shallow features of malware, neglecting deeper structural and semantic characteristics. Additionally, retaining all basic blocks in CFGs significantly increases the memory overhead of detection models. To address these issues, we propose MCLPF, collaborative malware detection with interpretable pruning, to improve the overall performance of existing malware detection systems that rely on fine-grained control flow features. MCLPF first introduces a novel Attributed Interpretable Flow Graph (AIFG) to extract functional attributes, integrating node-level features, edge-level features, and assembly language embedding features derived from Large Language Models (LLMs). Subsequently, it proposes an efficient and reliable detection scheme by alternately updating the graph structure and language learning modules through L-Step and G-Step, rather than synchronously training Language Models (LMs) with Graph Neural Networks (GNNs) on large-scale graphs. We conduct experiments using public datasets involving four different architectures (i.e., PE-32, PE-64, ELF-32, and ELF-64) and demonstrate that our model achieves an exceptionally high detection accuracy (i.e., 99.30%). After pruning 100% of noncritical nodes and edges, the sample size is reduced to approximately 8% of the original, with an average time cost reduction of 74.7%, while the detection performance fluctuation averages only about 1%. Extensive cross-dataset evaluations validate the effectiveness and efficiency of the proposed method. Haiping Huang, Le Yu 0002, Fu Xiao 0001, Ruilong Deng |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2026 | Code Language Models for Security Patch Management: How Far are We?abstractThe rapid expansion of open-source software has also brought significant security challenges to cloud infrastructure, particularly introducing and propagating vulnerabilities. In response, effective security patch management establishes a continuous, structured pipeline by systematically identifying, testing, and deploying security patches to fix vulnerabilities. However, manually managing a large number of security patches (i.e., any update is approved and installed by hand) is time-consuming, leading to a great motivation for automating this process. Although Code Language Models (CodeLMs) have shown potential in various code-centric tasks, there remains an open question as to how well CodeLMs perform within the context of security patch management. To bridge this gap, we performed the first comprehensive empirical study on fine-tuning or prompting nine state-of-the-art CodeLMs for three security-patch-related downstream tasks, including silent patch identification (distinguishing security patches from normal commits), record-patch linking (connecting authoritative vulnerability records, e.g., CVE, to the corresponding fixing commits), and vulnerability description generation (providing a piece of text summarizing the vulnerability fixed by the patch), covering classification, ranking, and generation problems. Our findings reveal that there is no “one-size-fits-all” model that can always perform the best. Furthermore, due to the lack of task-specific knowledge, naively prompting LLMs with the basic strategies is not consistently reliable and may even underperform smaller PTMs. Additionally, existing automated evaluation metrics cannot fully reflect the capability of LLMs in considered tasks. These findings underscore the considerable gap between current capabilities and the practical requirements for deploying CodeLMs in automating security patch management. Xingwei Lin, Sicong Cao, Le Yu 0002, Xiaobing Sun 0001, Fu Xiao 0001, Lei Xue 0001, Chunming Wu 0001, Kui Ren 0001, David Lo 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2026 | Mind the Service: What Crypto Wallets Aren't Telling You
Shuohan Wu, Zihao Li 0001, Hao Zhou 0043, Le Yu 0002, Shu-Di Bao, Xiapu Luo |
IEEE Trans. Serv. Comput. | 4 |
| 2025 | Revolutionizing Encrypted Traffic Classification with MH-Net: A Multi-View Heterogeneous Graph ModelabstractWith the growing significance of network security, the classification of encrypted traffic has emerged as an urgent challenge. Traditional byte-based traffic analysis methods are constrained by the rigid granularity of information and fail to fully exploit the diverse correlations between bytes. To address these limitations, this paper introduces MH-Net, a novel approach for classifying network traffic that leverages multi-view heterogeneous traffic graphs to model the intricate relationships between traffic bytes. The essence of MH-Net lies in aggregating varying numbers of traffic bits into multiple types of traffic units, thereby constructing multi-view traffic graphs with diverse information granularities. By accounting for different types of byte correlations, such as header-payload relationships, MH-Net further endows the traffic graph with heterogeneity, significantly enhancing model performance. Notably, we employ contrastive learning in a multi-task manner to strengthen the robustness of the learned traffic unit representations. Experiments conducted on the ISCX and CIC-IoT datasets for both the packet-level and flow-level traffic classification tasks demonstrate that MH-Net achieves the best overall performance compared to dozens of SOTA methods. Haozhen Zhang, Haodong Yue, Xi Xiao 0001, Le Yu 0002, Qing Li 0006, Zhen Ling 0001 |
AAAI | 4 |
| 2025 | Relational Graph Attention Network Combined with Burst Position Encoding for Traffic ClassificationabstractNetwork traffic classification has become an essential technology for information service providers. While existing methods predominantly focus on packet-level features such as port numbers and payload content, they fundamentally overlook the dynamic interaction patterns revealed by traffic burst sequences and the inherent relational characteristics between consecutive traffic bursts. To overcome the limitation of existing methods, we design a new burst position relational graph attention network (BP-RGAT) for traffic classification. We introduce the Heterogeneous Traffic Burst Graph (HTBG) to obtain more traffic interaction information. We also incorporate Relative Traffic Burst Position Encoding (RBPE) to capture sequence information between bursts. To evaluate the performance of BPRGAT, we conduct experiments with ISCX-VPN and USTC-TFC datasets. The results show that BP-RGAT achieves the highest F1 score compared to existing baseline methods (e.g. NetMamba, ET-BERT, BehavSniffer, TFE-GNN). Siji Chen, Xi Xiao 0001, Guangwu Hu, Le Yu 0002, Qing Li 0006, Hao Li 0027, Qingjun Yuan, Dengpan Ye |
IWQoS | 4 |
| 2025 | Update If You Dare: Demystifying Bare-Metal Device Firmware Update Security of Appified IoT SystemsabstractDue to the economy and low power consumption features, bare-metal IoT devices have been widely used in various areas of our life, and they are usually paired with companion mobile apps to configure them and view their states (a.k.a., appified IoT system). The IoT systems have already become the lucrative and profitable targets for attackers because the compromised IoT devices will pose severe threats to IoT security and reliability. This problem become worse on bare-metal IoT devices since the tradeoff among price, functionality, performance, and energy efficiency usually results in insufficient security protection. Such bare-metal IoT devices usually adopt OTA (Over-The-Air) methods to update firmware, which is managed by the companion apps running on smartphones. Despite the prevalence of these appified IoT systems, there is a lack of systematic research on the security of bare-metal IoT device firmware update (DFU), although recent studies have reported security flaws in such systems. In this article, we propose a holistic approach to investigate DFU security of these appified IoT systems through collaborative analyzing the bare-metal firmware and the companion app. Additionally, we have developed an IoT system analysis framework named$\mathsf{BareDFU}$to automate the complex and time-consuming analysis tasks and facilitate the investigation. After applying$\mathsf{BareDFU}$to analyze 1,637 companion IoT apps, we found 710 of them contained security flaws spanning all three DFU stages: authentication, firmware acquisition, and firmware verification. Furthermore, we leveraged$\mathsf{BareDFU}$to investigate the bare-metal DFU security of six commercial appified IoT systems, and discovered they all had DFU flaws, which we successfully exploited to launch proof-of-concept firmware modification attacks. The affected vendors have acknowledged our findings and addressed the security flaws. Lei Xue 0001, Yuxiao Yan, Qiyi Tang 0003, Le Yu 0002, Xiapu Luo, Sen Nie, Shi Wu, Guofei Gu, Chenxu Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | A Survey of Multilanguage Interoperability and Its Program AnalysisabstractSince multilanguage programming has the strength of interoperating languages with different features and paradigms, and it also enables the reuse of existing libraries, developers often use multilanguage interoperability in software systems of different application domains. Program analysis is an effective way to maintain the reliability and safety of software. However, numerous challenges appear when using program analysis to analyze multilanguage interoperability. However, there still lacks a systematic overview of the multilanguage interoperability and the corresponding program analysis (e.g., what are the research trends, how existing works solve them). To bridge this gap, we conducted a comprehensive investigation of the 195 research works related to multilanguage interoperability and its program analysis in the past 38 years (1987–2024). In this article, we classify these works into three categories with 10 research perspectives, including foreign interface design, interface definition and generation, intermediate representation (IR), semantics, static analysis of memory management, type system, exception handling and concurrency, dynamic analysis, and others. Then, we evaluate research trends that affect multilanguage interoperability and key static/dynamic language futures of multilanguage program analysis. Finally, we discuss the open challenges and future research directions of multilanguage interoperability. Mingzhe Hu, Le Yu 0002, Yu Zhang 0086, Liping Han |
IEEE Trans. Reliab. | 2 |
| 2025 | ARAP: Demystifying Anti Runtime Analysis Code in Android AppsabstractWith the continuous growth in the usage of Android apps, ensuring their security has become critically important. An increasing number of malicious apps adopt anti-analysis techniques to evade security measures. Although some research has started to consider anti-runtime analysis (ARA), it is unfortunate that they have not systematically examined ARA techniques. Furthermore, the rapid evolution of ARA technology exacerbates the issue, leading to increasingly inaccurate analysis results. To effectively analyze Android apps, understanding their adopted ARA techniques is necessary. However, no systematic investigation has been conducted thus far.In this paper, we conduct the first systematic study of the ARA implementations in a wide range of 117,270 Android apps (including both malicious and benign ones) collected between 2016 and 2023. Additionally, we propose a specific investigation tool namedARAPto assist this study by leveraging both static and dynamic analysis. According to the evaluation results,ARAPnot only effectively identifies the ARA implementations in Android apps but also reveals many important findings. For instance, almost all apps have implemented at least one category of ARA technology (99.6% for benign apps and 97.0% for malicious apps). Dewen Suo, Lei Xue 0001, Le Yu 0002, Runze Tan, Weihao Huang, Guozi Sun |
IEEE Trans. Software Eng. | 3 |
| 2024 | Giving without Notifying: Assessing Compliance of Data Transmission in Android AppsabstractMobile apps often access personal information to meet business needs, raising concerns about privacy breaches. Compliance detection methods are proposed to check for inconsistencies between program code and privacy policies. However, existing methods face challenges with the low efficiency of static data flow analysis tools and often neglect physical data transmission destinations. Ming Fan 0002, Jifei Shi, Le Yu 0002, Haijun Wang 0002, Wuxia Jin, Ting Liu 0002 |
ASE | 4 |
| 2024 | Inferring Activities and Profiles of Users Based on Trajectory Leakage in Mobile Ad NetworkabstractWith the widespread use of smartphones and the development of ad networks, mobile in-app targeted ads have become more and more prevalent, leveraging users' geolocation for targeting purposes. This service involves a large amount of user location data, which may not only expose sensitive locations closely associated with the users, but also reveal the users' activities and profiles. Previous studies have utilized various machine learning methods to infer users' activities or predict their future activities based on the location data from location-based social networks (LBSNs). These approaches, however, often require large datasets for training and are also resource-intensive. Unlike active behaviors, such as checking in, where users intentionally record their location, location data are passively recorded by mobile apps in the background, making inferring activities more challenging. Considering the rapid progress in the reasoning abilities of the large language models (LLMs) in recent years, we aim to evaluate user's activity and profile leakage through LLMs with the assistance of map APIs. We conduct the experiment on the location dataset, which is generated according to specified profiles. The results of the experiment show that the LLM can infer users' activities with an accuracy rate scoring up to 96.1 %, and there is also a high probability of predicting the users' profiles, such as the occupation. Le Yu 0002, Tian Dong 0003, Yan Meng 0001, Shaofeng Li 0001, Guoxing Chen, Haojin Zhu |
MSN | 2 |
| 2024 | Revisiting Automotive Attack Surfaces: a Practitioners' PerspectiveabstractAs modern vehicles become increasingly complex in terms of both external attack surfaces and internal in-vehicle network (IVN) topology, ensuring their cybersecurity remains a challenge. Existing standards and regulations, such as WP29 R155e and ISO 21434, attempt to establish a baseline for automotive cybersecurity, but their sufficiency in addressing the evolving threats is unclear. To fill in this gap, we first carried out an in-depth interview study with 15 experts in automotive cybersecurity, uncovering the particular challenges encountered during security activities and the limitations of current regulations. We identified 20 key insights from the interview data, ranging from the challenges and gaps in the existing automotive security industry to the limitations and recommendations for current regulations. Notably, we discovered that the quality of threat cases provided by existing regulations is unsatisfactory, and the Threat Analysis and Risk Assessment (TARA) process is often highly inefficient due to the lack of automatic tools. In response to the above limitations, we first built an improved threat database for automotive systems using the collected interview data, which enhanced the existing database both quantitatively and qualitatively. Additionally, we present CarVal, a datalog-based approach designed to infer multi-stage attack paths in IVNs and calculate risk values, thereby making TARA more efficient for automotive systems. By applying CarVal to five real vehicles, we performed extensive security analysis based on the generated attack paths and successfully exploited the corresponding attack chains in the newly gateway-segmented IVN, uncovering new automotive attack surfaces that previous research failed to cover, including the in-vehicle browser, official mobile app, backend server, and in-vehicle malware. Pengfei Jing, Yingjie Cao, Le Yu 0002, Yuefeng Du 0006, Chenxiong Qian, Xiapu Luo, Sen Nie, Shi Wu |
SP | 4 |
| 2024 | LLMIF: Augmented Large Language Model for Fuzzing IoT DevicesabstractDespite the efficacy of fuzzing in verifying the implementation correctness of network protocols, existing IoT protocol fuzzing approaches grapple with several limitations, including obfuscated message formats, unresolved message dependencies, and a lack of evaluations on the testing cases. These limitations significantly curtail the capabilities of IoT fuzzers in vulnerability identification. In this work, we show that the protocol specification contains fruitful descriptions of protocol messages, which can be used to overcome the above limitations and guide IoT protocol fuzzing. To automate the specification analysis, we augment the large language model with the specification contents, and drive it to perform two tasks (i.e., protocol information extraction, and device response reasoning). We further design and implement a fuzzing algorithm, LLMIF, which incorporates the LLM into IoT fuzzing. Finally, we select Zigbee as the target protocol and initiate comprehensive evaluations. The evaluation result shows that LLMIF successfully addressed the above limitations. Compared with the existing Zigbee fuzzers, it increases the protocol message coverage and code coverage by 55.2% and 53.9%, respectively. Besides the enhanced coverage, LLMIF unearthed 11 vulnerabilities on real-world Zigbee devices, which include eight previously unknown vulnerabilities. Seven of them are not covered by the existing Zigbee fuzzers. Le Yu 0002, Xiapu Luo |
SP | 2 |
| 2024 | DevDet: Detecting IoT Device Impersonation Attacks via Traffic Based Identification
Hongliang Yong, Le Yu 0002, Tian Dong 0003, Yan Meng 0001, Guoxing Chen, Haojin Zhu |
WASA (2) | 2 |
| 2024 | A comprehensive analysis of website fingerprinting defenses on Tor
Xi Xiao 0001, Le Yu 0002, Bin Zhang 0048, Qixu Liu, Xiapu Luo |
Comput. Secur. | 4 |
| 2024 | Privacy-Preserving Location-Based Advertising via Longitudinal Geo-IndistinguishabilityabstractAs location data have been increasingly adopted in location-based advertising (LBA), revealing locations to untrusted service providers has raised severe privacy concerns. Recent studies propose obfuscation mechanisms built upon geo-indistinguishability (geo-IND) to provide formal privacy guarantee. Unfortunately, due to the high degree of spatiotemporal regularity in human mobility pattern, the privacy cost will be unacceptably high in this situation, leading to accurate inference of user real locations. In this study, we identify this privacy risk in LBA scenarios under long-term and multi-platform assumption. We demonstrate an attacker can infer 75%∼90% of top-1 locations within a range of only 200 meters. To address it, we proposePrivLocAd, a novel system which can provide longitudinal privacy guarantee. The novelty of PrivLocAd stems from a novel surrogate-based obfuscation, which generates multiple surrogate locations to improve the privacy-utility trade-off. In addition, two novel obfuscation mechanisms, the two-stage Gaussian and multi-level surrogate generation mechanism in charge of surrogate generation can achieve the longitudinal privacy guarantee in intra- and inter-platform condition respectively. Our experimental results demonstrate PrivLocAd is able to defend against the attack, which reduces the inference rate to less than 1% of user top-1 locations in the 200 meter range. Le Yu 0002, Shufan Zhang 0001, Yan Meng 0001, Suguo Du, Yuling Chen 0002, Yanli Ren, Haojin Zhu |
IEEE Trans. Mob. Comput. | 1 |
| 2023 | ReviewLocator: Enhance User Review-Based Bug Localization with Bug Reports
Renjie Xiao, Xi Xiao 0001, Le Yu 0002, Bin Zhang 0048, Guangwu Hu, Qing Li 0006 |
ADMA (5) | 3 |
| 2023 | Poster: DP-Reverser: Automatically Reverse Engineering Vehicle Diagnostic ProtocolsabstractIn-vehicle protocols are important for the security assessment and protection of modern vehicles since they are used in communicating with, accessing, and even manipulating ECUs (Electronic Control Units). Unfortunately, the majority of in-vehicle protocols are proprietary (i.e., without publicly available documents). Although recent studies proposed methods to reverse engineer the CAN protocol used in the communication among ECUs, they cannot be applied to vehicle diagnostics protocols, which have been widely exploited to launch remote attacks. Thus, we propose a novel framework for automatically reverse engineering the diagnostic protocols of vehicles by leveraging professional diagnostic tools. We design and develop a new cyber-physical system that uses a set of algorithms to control a programmable robotics arm with the aid of cameras to automatically trigger and capture the messages of diagnostics protocols as well as reverse engineer their formats, semantic meanings, and proprietary formulas required for processing the response messages. We perform a large-scale experiment to evaluate our prototype using 18 real vehicles. Le Yu 0002, Zhanlei Zhang |
ICDCS | 1 |
| 2023 | Demystifying Privacy Policy of Third-Party Libraries in Mobile AppsabstractThe privacy of personal information has received significant attention in mobile software. Although researchers have designed methods to identify the conflict between app behavior and privacy policies, little is known about the privacy compliance issues relevant to third-party libraries (TPLs). The regulators enacted articles to regulate the usage of personal information for TPLs (e.g., the CCPA requires businesses clearly notify consumers if they share consumers' data with third parties or not). However, it remains challenging to investigate the privacy compliance issues of TPLs due to three reasons: 1) Difficulties in collecting TPLs' privacy policies. In contrast to Android apps, which are distributed through markets like Google Play and must provide privacy policies, there is no unique platform for collecting privacy policies of TPLs. 2) Difficulties in analyzing TPL's user privacy access behaviors. TPLs are mainly provided in binary files, such as jar or aar, and their whole functionalities usually cannot be executed independently without host apps. 3) Difficulties in identifying consistency between TPL's functionalities and privacy policies, and host app's privacy policy and data sharing with TPLs. This requires analyzing not only the privacy policies of TPLs and host apps but also their functionalities. In this paper, we propose an automated system named ATPChecker to analyze whether Android TPLs comply with the privacy-related regulations. We construct a data set that contains a list of 458 TPLs, 247 TPL's privacy policies, 187 TPL's binary files and 641 host apps and their privacy policies. Then, we analyze the bytecode of TPLs and host apps, design natural language processing systems to analyze privacy policies, and implement an expert system to identify TPL usage-related regulation compliance. The experimental results show that 23% TPLs violate regulation requirements for providing privacy policies. Over 47% TPLs miss disclosing data usage in their privacy policies. Over 65% host apps share user data with TPLs while 65% of them miss disclosing interactions with TPLs. Our findings remind developers to be mindful of TPL usage when developing apps or writing privacy policies to avoid violating regulations, Kaifa Zhao, Xian Zhan, Le Yu 0002, Shiyao Zhou, Hao Zhou 0043, Xiapu Luo, Haoyu Wang 0001, Yepang Liu 0001 |
ICSE | 3 |
| 2023 | TFE-GNN: A Temporal Fusion Encoder Using Graph Neural Networks for Fine-grained Encrypted Traffic ClassificationabstractEncrypted traffic classification is receiving widespread attention from researchers and industrial companies. However, the existing methods only extract flow-level features, failing to handle short flows because of unreliable statistical properties, or treat the header and payload equally, failing to mine the potential correlation between bytes. Therefore, in this paper, we propose a byte-level traffic graph construction approach based on point-wise mutual information (PMI), and a model named Temporal Fusion Encoder using Graph Neural Networks (TFE-GNN) for feature extraction. In particular, we design a dual embedding layer, a GNN-based traffic graph encoder as well as a cross-gated feature fusion mechanism, which can first embed the header and payload bytes separately and then fuses them together to obtain a stronger feature representation. The experimental results on two real datasets demonstrate that TFE-GNN outperforms multiple state-of-the-art methods in fine-grained encrypted traffic classification tasks. Haozhen Zhang, Le Yu 0002, Xi Xiao 0001, Qing Li 0006, Francesco Mercaldo, Xiapu Luo, Qixu Liu |
WWW | 2 |
| 2023 | Towards Automatically Localizing Function Errors in Mobile Apps With User ReviewsabstractRemoving all function errors is critical for making successful mobile apps. Since app testing may miss some function errors given limited time and resource, the user reviews of mobile apps are very important to developers for learning the uncaught errors. Unfortunately, manually handling each review is time-consuming and even error-prone. Existing studies on mobile apps’ reviews could not help developers effectively locate the problematic code according to the reviews, because the majority of such research focus on review classification, requirements engineering, sentiment analysis, and summarization [1]. They do not localize the function errors described in user reviews in apps’ code. Moreover, recent studies on mapping reviews to problematic source files look for the matching between the words in reviews and that in source code, bug reports, commit messages, and stack traces, thus may result in false positives and false negatives since they do not consider the semantic meaning and part of speech tag of each word. In this paper, we propose a novel approach to localize function errors in mobile apps by exploiting the context information in user reviews and correlating the reviews and bytecode through their semantic meanings. We realize our new approach as a tool namedReviewSolver, and carefully evaluate it with reviews of real apps. The experimental result shows thatReviewSolverhas much better performance than the state-of-the-art tools (i.e.,ChangeAdvisorandWhere2Change). Le Yu 0002, Haoyu Wang 0001, Xiapu Luo, Tao Zhang 0001, Kang Liu 0001, Jiachi Chen, Hao Zhou 0043, Yutian Tang, Xusheng Xiao |
IEEE Trans. Software Eng. | 1 |
| 2022 | A Fine-grained Chinese Software Privacy Policy Dataset for Sequence Labeling and Regulation Compliant IdentificationabstractPrivacy protection raises great attention on both legal levels and user awareness.To protect user privacy, countries enact laws and regulations requiring software privacy policies to regulate their behavior.However, privacy policies are written in natural languages with many legal terms and software jargon that prevent users from understanding and even reading them.It is desirable to use NLP techniques to analyze privacy policies for helping users understand them.Furthermore, existing datasets ignore law requirements and are limited to English.In this paper, we construct the first Chinese privacy policy dataset, namely CA4P-483, to facilitate the sequence labeling tasks and regulation compliance identification between privacy policies and software.Our dataset includes 483 Chinese Android application privacy policies, over 11K sentences, and 52K fine-grained annotations.We evaluate families of robust and representative baseline models on our dataset.Based on baseline performance, we provide findings and potential research directions on our dataset.Finally, we investigate the potential applications of CA4P-483 1 combing regulation requirements and program analysis. Kaifa Zhao, Le Yu 0002, Shiyao Zhou, Jing Li 0049, Xiapu Luo, Aemon Yat Fei Chiu |
EMNLP | 2 |
| 2022 | Thwarting Longitudinal Location Exposure Attacks in Advertising Ecosystem via Edge ComputingabstractAs geo-location data has been increasingly adopted as a high-profile feature in targeted advertising, exposing user real locations to untrusted cloud services or advertisers has raised severe privacy concerns. To protect location privacy with formal guarantee, a wide-stretched line of recent studies focuses on injecting controlled geo-indistinguishability (geo-IND) noise as per each location exposure. However, in advertising, over the course of 2 years, a single user can report and contribute near 1k location data points on average, which allows a longitudinal attacker to infer some statistics from the perturbed locations.In this study, we demonstrate the above-mentioned privacy risk via revealing an inference attack mechanism, coined as a longitudinal location exposure attack. This novel attack illustrates the possibility of recovering 75%∼90% of user top-1 locations (within only 200-meter range) among 37k users. In light of this deficiency, we propose a novel edge-assisted location privacy protection system, entitled Edge-PrivLocAd, that is adapted to location-based advertising. The novelty of Edge-PrivLocAd stems from our n-fold Gaussian mechanism, which adds permanent noise to the statistical user location profile and thus can defend against longitudinal attackers while balancing the privacy-utility trade-off. In addition, our system incorporates a posterior-based sampling technique into the location re-mapping process, that boosts location utility without privacy loss. We develop a fully-functioning prototype and empirically evaluate the proposed system. Our experimental results show that Edge-PrivLocAd is practical and scalable in real-world scenarios. Le Yu 0002, Shufan Zhang 0001, Yan Meng 0001, Suguo Du, Haojin Zhu |
ICDCS | 1 |
| 2022 | SAID: State-aware Defense Against Injection Attacks on In-vehicle Network
Lei Xue 0001, Kaifa Zhao, Jianfeng Li 0006, Le Yu 0002, Xiapu Luo, Yajin Zhou, Guofei Gu |
USENIX Security Symposium | 6 |
| 2022 | Towards Automatically Reverse Engineering Vehicle Diagnostic Protocols
Le Yu 0002, Pengfei Jing, Xiapu Luo, Lei Xue 0001, Kaifa Zhao, Yajin Zhou, Ting Wang 0006, Guofei Gu, Sen Nie, Shi Wu |
USENIX Security Symposium | 1 |
| 2022 | PackerGrind: An Adaptive Unpacking System for Android AppsabstractApp developers are increasingly using packing services (or packers) to protect their code against being reverse engineered or modified. However, such packing techniques are also leveraged by the malicious developers to prevent the malware from being analyzed and detected by the static malware analysis and detection systems. Though there are already studies on unpacking packed Android apps, they usually leverage the manual reverse engineered packing behaviors to unpack apps packed by the specific packers and cannot be appified to the evolved and new packers. In this paper, we propose a novel unpacking approach with the capacity of adaptively unpacking the evolved and newly encountered packers. Also, we develop a new system, namedPackerGrind, based on this adaptive approach for unpacking Android packers. The evaluation with real packed apps demonstrates thatPackerGrindcan successfully reveal packers protection mechanisms, effectively handle their evolution and recover Dex files with low overhead. Lei Xue 0001, Hao Zhou 0043, Xiapu Luo, Le Yu 0002, Dinghao Wu, Yajin Zhou, Xiaobo Ma 0001 |
IEEE Trans. Software Eng. | 4 |
| 2021 | Understanding and Detecting Mobile Ad Fraud Through the Lens of Invalid TrafficabstractAlong with gaining popularity of Real-Time Bidding (RTB) based programmatic advertising, the click farm based invalid traffic, which leverages massive real smartphones to carry out large-scale ad fraud campaigns, is becoming one of the major threats against online advertisement. In this study, we take an initial step towards the detection and large-scale measurement of the click farm based invalid traffic. Our study begins with a measurement on the device's features using a real-world labeled dataset, which reveals a series of features distinguishing the fraudulent devices from the benign ones. Based on these features, we develop EvilHunter, a system for detecting fraudulent devices through ad bid request logs with a focus on clustering fraudulent devices. EvilHunter functions by 1) building a classifier to distinguish fraudulent and benign devices; 2) clustering devices based on app usage patterns; and 3) relabeling devices in clusters through majority voting. EvilHunter demonstrates 97% precision and 95% recall on a real-world labeled dataset. By investigating a super click farm, we reveal several cheating strategies that are commonly adopted by fraudulent clusters. We further reduce the overhead of EvilHunter and discuss how to deploy the optimized EvilHunter in a real-world system. We are in partnership with a leading ad verification company to integrate EvilHunter into their industrial platform. Suibin Sun, Le Yu 0002, Xiaokuan Zhang, Minhui Xue 0001, Ren Zhou, Haojin Zhu, Shuang Hao 0001, Xiaodong Lin 0001 |
CCS | 2 |
| 2021 | Structural Attack against Graph Based Android Malware DetectionabstractMalware detection techniques achieve great success with deeper insight into the semantics of malware. Among existing detection techniques, function call graph (FCG) based methods achieve promising performance due to their prominent representations of malware's functionalities. Meanwhile, recent adversarial attacks not only perturb feature vectors to deceive classifiers (i.e., feature-space attacks) but also investigate how to generate real evasive malware (i.e., problem-space attacks). However, existing problem-space attacks are limited due to their inconsistent transformations between feature space and problem space. Kaifa Zhao, Hao Zhou 0043, Yulin Zhu 0001, Xian Zhan, Kai Zhou 0001, Jianfeng Li 0006, Le Yu 0002, Wei Yuan 0001, Xiapu Luo |
CCS | 7 |
| 2021 | PPChecker: Towards Accessing the Trustworthiness of Android Apps' Privacy PoliciesabstractRecent years have witnessed a sharp increase of malicious apps that steal users' personal information. To address users' concerns about privacy risks and to comply with data protection laws, more and more apps are supplied with privacy policies written in natural language to help users understand an app's privacy practices. However, little is known whether these privacy policies are trustworthy or not. Questionable privacy policies may be prepared by careless app developers or someone with malicious intention. In this paper, we carry out a systematic study on privacy policy by proposing a novel approach to automatically identify five kinds of problems in privacy policy. After tackling several challenging issues, we implement the approach in a system, named PPChecker, and evaluate it with real apps and their privacy policies. The experimental results show that PPChecker can effectively identify questionable privacy policies with high precision. Applying PPChecker to 2,500 popular apps, we find that 1,850 apps (i.e., 74.0 percent) have at least one kind of problems. This study sheds light on the research of improving and regulating apps' privacy policies. Le Yu 0002, Xiapu Luo, Jiachi Chen, Hao Zhou 0043, Tao Zhang 0001, Henry Chang, Hareton K. N. Leung |
IEEE Trans. Software Eng. | 1 |
| 2020 | An Empirical Evaluation of GDPR Compliance Violations in Android mHealth AppsabstractThe purpose of the General Data Protection Regulation (GDPR) is to provide improved privacy protection. If an app controls personal data from users, it needs to be compliant with GDPR. However, GDPR lists general rules rather than exact step-by-step guidelines about how to develop an app that fulfills the requirements. Therefore, there may exist GDPR compliance violations in existing apps, which would pose severe privacy threats to app users. In this paper, we take mobile health applications (mHealth apps) as a peephole to examine the status quo of GDPR compliance in Android apps. We first propose an automated system, named HPDROID, to bridge the semantic gap between the general rules of GDPR and the app implementations by identifying the data practices declared in the app privacy policy and the data relevant behaviors in the app code. Then, based on HPDROID, we detect three kinds of GDPR compliance violations, including the incompleteness of privacy policy, the inconsistency of data collections, and the insecurity of data transmission. We perform an empirical evaluation of 796 mHealth apps. The results reveal that 189 (23.7%) of them do not provide complete privacy policies. Moreover, 59 apps collect sensitive data through different measures, but 46 (77.9%) of them contain at least one inconsistent collection behavior. Even worse, among the 59 apps, only 8 apps try to ensure the transmission security of collected data. However, all of them contain at least one encryption or SSL misuse. Our work exposes severe privacy issues to raise awareness of privacy protection for app users and developers. Ming Fan 0002, Le Yu 0002, Sen Chen 0001, Hao Zhou 0043, Xiapu Luo, Shuyue Li, Yang Liu 0003, Jun Liu 0002, Ting Liu 0002 |
ISSRE | 2 |
| 2020 | UI Obfuscation and Its Effects on Automated UI Analysis for Android AppsabstractThe UI driven nature of Android apps has motivated the development of automated UI analysis for various purposes, such as app analysis, malicious app detection, and app testing. Although existing automated UI analysis methods have demonstrated their capability in dissecting apps' UI, little is known about their effectiveness in the face of app protection techniques, which have been adopted by more and more apps. In this paper, we take a first step to systematically investigate UI obfuscation for Android apps and its effects on automated UI analysis. In particular, we point out the weaknesses in existing automated UI analysis methods and design 9 UI obfuscation approaches. We implement these approaches in a new tool named UIObfuscator after tackling several technical challenges. Moreover, we feed 3 kinds of tools that rely on automated UI analysis with the apps protected by UIObfuscator, and find that their performances severely drop. This work reveals limitations of automated UI analysis and sheds light on app protection techniques. Hao Zhou 0043, Ting Chen 0002, Haoyu Wang 0001, Le Yu 0002, Xiapu Luo, Ting Wang 0006, Wei Zhang 0122 |
ASE | 4 |
| 2020 | STAN: Towards Describing Bytecodes of Smart ContractabstractMore than eight million smart contracts have been deployed into Ethereum, which is the most popular blockchain that supports smart contract. However, less than 1% of deployed smart contracts are open-source, and it is difficult for users to understand the functionality and internal mechanism of those closed-source contracts. Although a few decompilers for smart contracts have been recently proposed, it is still not easy for users to grasp the semantic information of the contract, not to mention the potential misleading due to decompilation errors. In this paper, we propose the first system named Stan to generate descriptions for the bytecodes of smart contracts to help users comprehend them. In particular, for each interface in a smart contract, Stan can generate four categories of descriptions, including functionality description, usage description, behavior description, and payment description, by leveraging symbolic execution and NLP (Natural Language Processing) techniques. Extensive experiments show that Stan can generate adequate, accurate and readable descriptions for contract's bytecodes, which have practical value for users. Xiaoqi Li 0001, Ting Chen 0002, Xiapu Luo, Tao Zhang 0001, Le Yu 0002, Zhou Xu 0003 |
QRS | 5 |
| 2020 | Resource Race Attacks on AndroidabstractSmartphones are frequently involved in accessing private user data. Although many studies have been done to prevent malicious apps from leaking private user data, only a few recent works examine how to remove the sensitive information from the data collected by smartphone hardware resources (e.g., camera). Unfortunately, none of them investigates whether a malicious app can obtain such sensitive information when (or right before/after) a legitimate app collects such data (e.g., taking photos). To fill in the gap, in this paper, we model such attacks as the Resource Race Attack (RRAttack) based on races between two apps during their requests to exclusive resources to access sensitive information. RRAttacks have three categories according to when a race on requesting resources occurs: Pre-Use, In-Use, and Post-Use attacks. We further conduct the first systematic study on the feasibility of launching the RRAttacks on two heavily used exclusive Android resources: camera and touchscreen. In details, we perform Proof-of-Concept (PoC) attacks to reveal that, (a) camera is highly vulnerable to both In-Use and Post-Use attacks; and (b) touchscreen is vulnerable to Pre-Use attacks. Particularly, we demonstrate successful RRAttacks on them to steal private information, to cause financial loss, and to steal user passwords from Android 6 to the latest Android Q. Moreover, our analyses on 1,000 apps indicate that most of them are vulnerable to one to three RRAttacks. Finally, we propose a set of defense strategies against RRAttacks for user apps, system apps, and Android system itself. Yan Cai 0001, Yutian Tang, Haicheng Li, Le Yu 0002, Hao Zhou 0043, Xiapu Luo, Liang He 0011, Purui Su |
SANER | 4 |
| 2019 | Achieving Differentially Private Location Privacy in Edge-Assistant Connected VehiclesabstractConnected vehicles can provide safer and more satisfying services for drivers by using information sensing and sharing. However, current network architecture cannot support massive and real-time data transmissions due to the poor-quality wireless links. To provide real-time data processing and improve drivers' security, edge computing is regarded as a promising method to offer more efficient services by placing computing and storage resources at the network edge. In this paper, we will introduce the concept of edge-assistant connected vehicles and propose some promising applications to reduce the network traffic and provide real-time services with the help of massive edge nodes. Unlike in the traditional cloud-based connected vehicles, edge nodes are introduced to enable vehicles to obtain real-time and distributed processing services. Furthermore, considering the location privacy issue in the new architecture, we propose a novel differentially privacy-preserving location-based service usage framework deployed on the edge node, designed to provide an adjustable privacy protection solution to balance the utility and privacy. Finally, we conduct extensive experiments to verify the proposed framework. Le Yu 0002, Suguo Du, Haojin Zhu, Cailian Chen |
IEEE Internet Things J. | 2 |
| 2018 | Localizing Function Errors in Mobile Apps with User ReviewsabstractRemoving all function errors is critical for making successful mobile apps. Since app testing may miss some function errors given limited time and resource, the user reviews of mobile apps are very important to developers for learning the uncaught errors. Unfortunately, manually handling each review is time-consuming and even error-prone. Existing studies on mobile apps' reviews could not help developers effectively locate the problematic code according to the reviews, because the majority of such research does not take into account apps' code. Moreover, recent studies on mapping reviews to problematic source files just look for the matching between the words in reviews and that in source code, and thus result in many false positives and false negatives. In this paper, we propose a novel approach to localize function errors in mobile apps by exploiting the context information in user reviews and correlating the reviews and bytecode through their semantic meanings. We realize our new approach as a tool named ReviewSolver, and carefully evaluate it with reviews of real apps. The experimental result shows that ReviewSolver has much better performance than the state-of-the-art tool. Le Yu 0002, Jiachi Chen, Hao Zhou 0043, Xiapu Luo, Kang Liu 0001 |
DSN | 1 |
| 2018 | Enhancing the Description-to-Behavior Fidelity in Android Apps with Privacy PolicyabstractSince more than 96 percent of mobile malware targets the Android platform, various techniques based on static code analysis or dynamic behavior analysis have been proposed to detect malicious apps. As malware is becoming more complicated and stealthy, recent research proposed a promising detection approach that looks for the inconsistency between an app's permissions and its description. In this paper, we first revisit this approach and reveal that using description and permission will lead to many false positives because descriptions often fail to declare all sensitive operations. Then, we propose exploiting an app's privacy policy and its bytecode to enhance the malware detection based on description and permissions. It is non-trivial to automatically analyze privacy policy and perform the cross-verification among these four kinds of software artifacts including, privacy policy, bytecode, description, and permissions. To address these challenging issues, we first propose a novel data flow model for analyzing privacy policy, and then develop a new system, named TAPVerifier, for carrying out investigation of individual software artifacts and conducting the cross-verification. The experimental results show that TAPVerifier can analyze privacy policy with a high accuracy and recall rate. More importantly, integrating privacy policy and bytecode level information can remove up to 59.4 percent false alerts of the state-of-the-art systems, such as AutoCog, CHABADA, etc. Le Yu 0002, Xiapu Luo, Chenxiong Qian, Shuai Wang 0012, Hareton K. N. Leung |
IEEE Trans. Software Eng. | 1 |
| 2017 | Adaptive unpacking of Android appsabstractMore and more app developers use the packing services (or packers) to prevent attackers from reverse engineering and modifying the executable (or Dex files) of their apps. At the same time, malware authors also use the packers to hide the malicious component and evade the signature-based detection. Although there are a few recent studies on unpacking Android apps, it has been shown that the evolving packers can easily circumvent them because they are not adaptive to the changes of packers. In this paper, we propose a novel adaptive approach and develop a new system, named PackerGrind, to unpack Android apps. We also evaluate PackerGrind with real packed apps, and the results show that PackerGrind can successfully reveal the packers' protection mechanisms and recover the Dex files with low overhead, showing that our approach can effectively handle the evolution of packers. Lei Xue 0001, Xiapu Luo, Le Yu 0002, Shuai Wang 0012, Dinghao Wu |
ICSE | 3 |
| 2017 | Is what you measure what you expect? Factors affecting smartphone-based mobile network measurementabstractMany apps have been developed to measure the performance of mobile networks. Unfortunately, their measurement results may not be what users expect, because the results could be biased by various factors and the apps' descriptions may confuse users. Although a few recent studies pointed out several factors, they missed other important factors and lacked of finegrained analysis on the factors and measurement apps. Moreover, none has studied whether or not the descriptions of such apps will mislead users. In this paper, we conduct the first systematic study of the factors that could bias the result from measurement apps and their descriptions. We identify new factors, revisit known factors, and propose a novel approach with new tools to discover these factors in proprietary apps. We also develop a new measurement app named MobiScope for demonstrating how to mitigate the negative effects of these factors. Furthermore, we construct enhanced descriptions for measurement apps to provide users more information about what is measured. The extensive experimental results illustrate the negative effects of various factors, the improvement in performance measurement brought by MobiScope, and the clarity of the enhanced descriptions. Lei Xue 0001, Xiaobo Ma 0001, Xiapu Luo, Le Yu 0002, Shuai Wang 0012, Ting Chen 0002 |
INFOCOM | 4 |
| 2017 | SPFM: Scalable and Privacy-Preserving Friend Matching in Mobile CloudabstractProfile (e.g., contact list, interest, and mobility) matching is more than important for fostering the wide use of mobile social networks. The social networks such as Facebook, Line, or WeChat recommend the friends for the users based on users personal data such as common contact list or mobility traces. However, outsourcing users' personal information to the cloud for friend matching will raise a serious privacy concern due to the potential risk of data abusing. In this paper, we propose a novel scalable and privacy-preserving friend matching (SPFM) protocol, which aims to provide a scalable friend matching and recommendation solutions without revealing the users personal data to the cloud. Different from the previous works which involves multiple rounds of protocols, SPFM presents a scalable solution which can prevent honest-but-curious mobile cloud from obtaining the original data and support the friend matching of multiple users simultaneously. We give detailed feasibility and security analysis on SPFM and its accuracy and security have been well demonstrated via extensive simulations. The result show that our scheme works even better when original data is large. Mengyuan Li 0004, Na Ruan, Qiyang Qian, Haojin Zhu, Xiaohui Liang 0002, Le Yu 0002 |
IEEE Internet Things J. | 6 |
| 2017 | Toward Automatically Generating Privacy Policy for Android AppsabstractA privacy policy is a statement informing users how their information will be collected, used, and disclosed. Failing to provide a correct privacy policy may result in a fine. However, writing privacy policy is tedious and error-prone, because the author may not understand the source code well as it could have been written by others (e.g., outsourcing), or the author does not know the internal working of third-party libraries used. In this paper, we propose and develop a novel system named AutoPPG to automatically construct correct and readable descriptions to facilitate the generation of privacy policy for Android applications (i.e., apps). Given an app, AutoPPG first conducts static code analysis to characterize its behaviors related to users' personal information, and then applies natural language processing techniques to generating correct and accessible sentences for describing these behaviors. The experimental results using real apps and crowdsourcing indicate that: 1) AutoPPG creates correct and easy-to-understand descriptions for privacy policies; 2) the privacy policies constructed by AutoPPG usually reveal more operations related to users' personal information than existing privacy policies; and 3) most developers, who reply us, would like to use AutoPPG to facilitate them. Le Yu 0002, Tao Zhang 0001, Xiapu Luo, Lei Xue 0001, Henry Chang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2016 | Can We Trust the Privacy Policies of Android Apps?abstractRecent years have witnessed the sharp increase of malicious apps that steal users' personal information. To address users' concerns about privacy risks, more and more apps are accompanied with privacy policies written in natural language because it is difficult for users to infer an app's behaviors according to the required permissions. However, little is known whether these privacy policies are trustworthy or not. It is worth noting that a questionable privacy policy may result from careless preparation by an app developer or intentional deception by an attacker. In this paper, we conduct the first systematic study on privacy policy by proposing a novel approach to automatically identify three kinds of problems in privacy policy. After tackling several challenging issues, we realize our approach in a system, named PPChecker, and evaluate it with real apps and privacy policies. The experimental results show that PPChecker can effectively identify questionable privacy policies with high precision. Moreover, applying PPChecker to 1,197 popular apps, we found that 282 apps (i.e., 23.6%) have at least one kind of problems. This study sheds light on the research of improving and regulating apps' privacy policies. Le Yu 0002, Xiapu Luo, Xule Liu, Tao Zhang 0001 |
DSN | 1 |
| 2016 | Revisiting the Description-to-Behavior Fidelity in Android ApplicationsabstractSince more than 96% of mobile malware targets on Android platform, various techniques based on static code analysis or dynamic behavior analysis have been proposed to detect malicious applications. As malware is becoming more complicated and stealthy, recent research proposed a promising detection approach that looks for the inconsistency between an application's permissions and its description. In this paper, we revisit this approach and find that using description and permission will lead to many false positives. Therefore, we propose employing app's privacy policy and its bytecode to enhance description and permission for malware detection. It is non-trivial to automatically analyze privacy policy and perform the cross-verification among these four kinds of software artifacts including, privacy policy, bytecode, description, and permissions. We propose a novel data flow model for analyzing privacy policy, and develop a novel system, named TAPVerifier, for carrying out investigation of individual software artifacts and conducting the cross-verification. The experimental results show that TAPVerifier can analyze privacy policy with a high accuracy and recall rate. More importantly, integrating privacy policy and code level information removes 8.1%-65.5% false positives of existing systems based on description and permission. Le Yu 0002, Xiapu Luo, Chenxiong Qian, Shuai Wang 0012 |
SANER | 1 |
| 2016 | Characterizing mobile *-box applications
Xiapu Luo, Haocheng Zhou, Le Yu 0002, Lei Xue 0001, Yi Xie 0004 |
Comput. Networks | 3 |
| 2014 | POSTER: LocMask: A Location Privacy Protection Framework in Android SystemabstractThe mobile users are facing a serious risk of losing location privacy (e.g., users' location information transmitted by open advertisement network, and the reported event of involuntary tracking of mobile users in popular mobile social apps). In this study, we design and implement LocMask, a system-level solution that provides location privacy protection in Android system. LocMask achieves the tradeoff of the privacy and the utility of location based services by providing the Quality of Protection (QoP) on demand, which sets different privacy protection levels to different locations based on how sensitive these locations are. Motivated by the fact that Top locations (e.g, user's home or office) are more sensitive than less visiting locations, LocMask provides location profile management module that records the user's mobility history and ranks the locations in terms of the user's visiting frequency. With users' location profiles, LocMask can automatically determines the sensitiveness of these locations as well as their corresponding privacy protection level. LocMask is also designed to incorporate various obfuscation techniques. The effectiveness of LocMask is supported by extensive real-world data based evaluations. Qiuyu Xiao, Le Yu 0002, Huaxin Li, Haojin Zhu, Muyuan Li, Kui Ren 0001 |
CCS | 3 |
| 2014 | All your location are belong to us: breaking mobile social networks for automated user location trackingabstractLocation-based social networks (LBSNs) feature friend discovery by location proximity that has attracted hundreds of millions of users world-wide. While leading LBSN providers claim the well-protection of their users' location privacy, for the first time we show through real world attacks that these claims do not hold. In our identified attacks, a malicious individual with the capability of no more than a regular LBSN user can easily break most LBSNs by manipulating location information fed to LBSN client apps and running them as location oracles. We further develop an automated user location tracking system and test it on leading LBSNs including Wechat, Skout, and Momo. We demonstrate its effectiveness and efficiency via a 3 week real-world experiment on 30 volunteers and show that we could geo-locate any target with high accuracy and readily recover his/her top 5 locations. Finally, we also develop a framework that explores a grid reference system and location classifications to mitigate the attacks. Our result serves as a critical security reminder of the current LBSNs pertaining to a vast number of users. Muyuan Li, Haojin Zhu, Zhaoyu Gao, Si Chen 0009, Le Yu 0002, Shangqian Hu, Kui Ren 0001 |
MobiHoc | 5 |
| 2006 | A Matching-Based Automatic Registration for Remotely Sensed ImageryabstractHow to register and rectify the multi-resource images of remote sensing is becomes one of the urgent problems in the field of earth observation and information acquirement recently. To meet this requirement of multi-source image application, an automatic imagery registration algorithm based on image matching was proposed and described, and an automatic registration workflow of multi-source remote sensing imagery was established and implemented in this paper. Many remote sensing images of SPOT5 (5 m), SPOT4 (10 m) and TM(30 m) which cover Hangzhou area were employed for the experimentation. It could be clearly indicated by the result that the algorithm and workflow designed here are precise, prompt, and practical for geometry registration. Dengrong Zhang, Le Yu 0002, Zhigang Cai |
IGARSS | 2 |
| 2006 | Implementation of a Data Node in China's Spatial Information Grid Based on NWGISSabstractSpatial Information Grid (SIG) is the fundamental structure of share and interoperation with geospatial. Several SIG reference specifications have been constituted by ISO and OGC to provide standard interfaces. This paper pays attention to construct and implement SIG's resource layer, which is the most important part, studies its conception structure and required functions. A SIG data service node is designed based on OGC and NWGISS. Three different access modes are employed to test the availability of this node. Experimental results demonstrate this service node can successfully respond to standard OGC requests and returns specific spatial data in different network environment, also shows a good capability of sharing data under isomerous operation environment. Dengrong Zhang, Le Yu 0002, Liping Di |
IGARSS | 2 |