VLDB 2026 Research / reviewers in the wild / expert
Yan Jia 0009
dblp:230/3262-9
· DBLP profile ↗
19ranked-venue papers
3as first author
14since 2021 · last 2026
0000-0003-0689-2508ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 2 first-author · 7 since 2021Computer networks · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Security and privacy measurement on Chinese consumer IoT traffic based on device lifecycle
Chenghua Jin, Yan Jia 0009, Qingyin Tan, Zheli Liu |
Sci. China Inf. Sci. | 3 |
| 2026 | Rethinking software misconfigurations in the real world: an empirical study and literature analysis
Yuhao Liu 0007, Yingnan Zhou, Hanfeng Zhang, Zhiwei Chang, Sihan Xu, Yan Jia 0009, Wei Wang 0012, Juncheng Hu 0002, Zheli Liu |
Empir. Softw. Eng. | 6 |
| 2026 | Analyzing consumer IoT traffic from security and privacy perspectives: a comprehensive survey
Yan Jia 0009, Zihou Liu, Qingyin Tan, Zheli Liu |
Frontiers Comput. Sci. | 1 |
| 2026 | DMCGuard: risky perils and fine-grained control on IoT multiple device management channels
Bin Yuan 0002, Kaimin Zheng, Yan Jia 0009, Jiajun Ren, Kunming Wang 0003, Shengjiu Shi, Deqing Zou, Hai Jin 0001 |
Frontiers Comput. Sci. | 3 |
| 2024 | Maginot Line: Assessing a New Cross-app Threat to PII-as-Factor Authentication in Chinese Mobile Apps
Fannv He, Yan Jia 0009, Jice Wang, Mengyue Feng, Peng Liu 0005, Yuqing Zhang 0001 |
NDSS | 2 |
| 2024 | MQTTactic: Security Analysis and Verification for Logic Flaws in MQTT ImplementationsabstractIoT messaging protocols are critical to connecting users and IoT devices. Among all the protocols, the Message Queuing and Telemetry Transport (MQTT) is arguably the most widely used. Mainstream IoT platforms leverage MQTT brokers, server side implementation of MQTT, to enable and mediate user-device communication (e.g., the transmission of control commands). There are over 70 open-source MQTT brokers, which have been widely adopted in production. Any security defects in those open-source MQTT brokers easily get into many vendors’ IoT deployments with amplified impacts, inevitably endangering the security of IoT applications and millions of users. We report the first systematic security analysis of open-source MQTT brokers in the wild. To enable the analysis, we designed and developed MQTTactic, a semi-automatic tool that can formally verify MQTT broker implementations based on generated security properties. MQTTactic is based on static code analysis, formal modeling, and automated model checking (with off-the-shelf model checker Spin). In designing MQTTactic, we characterize and address key technical challenges. MQTTactic currently focuses on authorization-related properties, and discovered 7 novel, zero-day flaws practically enabling serious, unauthorized access. We reported all flaws to related parties, who acknowledged the issues and have been taking actions to fix them. Our thorough evaluation shows that MQTTactic is effective and practical. Bin Yuan 0002, Zhanxiang Song, Yan Jia 0009, Deqing Zou, Hai Jin 0001, Luyi Xing |
SP | 3 |
| 2024 | Low-cost fuzzing drone control system for configuration errors threatening flight safety in edge terminals
Zhiwei Chang, Hanfeng Zhang, Yan Jia 0009, Sihan Xu, Tong Li 0011, Zheli Liu |
Comput. Commun. | 3 |
| 2023 | Union under Duress: Understanding Hazards of Duplicate Resource Mismediation in Android Software Supply Chain
Xueqiang Wang, Yifan Zhang 0010, XiaoFeng Wang 0001, Yan Jia 0009, Luyi Xing |
USENIX Security Symposium | 4 |
| 2023 | Multi-Misconfiguration Diagnosis via Identifying Correlated Configuration ParametersabstractSoftware configuration requires that the user sets appropriate values to specified variables, known as configuration parameters, which potentially affect the behaviors of software system. It is an essential means for software reliability, but how to ensure correct configurations remains a great challenge, especially when a large number of parameter settings are involved. Existing studies on misconfiguration diagnosis treat all configurations independently, ignoring the constraints and correlations among different configurations. In this article, we reveal the phenomenon of multi-misconfigurations and present a tool, MMD, for multi-misconfigurations diagnosis. Specifically, MMD consists of two modules: Correlated Configurations Analysis and Primary Misconfigurations Diagnosis. The former determines the correlation among each pair of configurations by analyzing the control and data flows related to each configuration. The latter is responsible for collecting a list of configurations ranked according to their suspiciousness. Combining the outputs of two modules, MMD is able to assist the user in multi-misconfigurations diagnosis. We evaluate MMD on seven popular Java projects: Randoop, Soot, Synoptic, Hdfs, Hbase, Yarn, and Zookeeper. MMD identifies 510 configuration correlations with a 4.9% false positive rate. Furthermore, it effectively diagnoses 22 multi-misconfigurations collected from StackOverflow, outperforming two state-of-the-art baselines. Yingnan Zhou, Sihan Xu, Yan Jia 0009, Yuhao Liu 0007, Guangquan Xu, Wei Wang 0012, Shaoying Liu, Thar Baker |
IEEE Trans. Software Eng. | 4 |
| 2022 | P-Verifier: Understanding and Mitigating Security Risks in Cloud-based IoT Access PoliciesabstractModern IoT device manufacturers are taking advantage of the managed Platform-as-a-Service (PaaS) and Infrastructure-as-a-Service (IaaS) IoT clouds (e.g., AWS IoT, Azure IoT) for secure and convenient IoT development/deployment. The IoT access control is achieved by manufacturer-specified, cloud-enforced IoT access policies (cloud-standard JSON documents, called IoT Policies) stating which users can access which IoT devices/resources under what constraints. In this paper, we performed a systematic study on the security of cloud-based IoT access policies on modern PaaS/IaaS IoT clouds. Our research shows that the complexity in the IoT semantics and enforcement logic of the policies leaves tremendous space for device manufacturers to program a flawed IoT access policy, introducing convoluted logic flaws which are non-trivial to reason about. In addition to challenges/mistakes in the design space, it is astonishing to find that mainstream device manufacturers also generally make critical mistakes in deploying IoT Policies thanks to the flexibility offered by PaaS/IaaS clouds and the lack of standard practices for doing so. Our assessment of 36 device manufacturers and 310 open-source IoT projects highlights the pervasiveness and seriousness of the problems, which once exploited, can have serious impacts on IoT users' security, safety, and privacy. To help manufacturers identify and easily fix IoT Policy flaws, we introduce P-Verifier, a formal verification tool that can automatically verify cloud-based IoT Policies. With evaluated high effectiveness and low performance overhead, P-Verifier will contribute to elevating security assurance in modern IoT deployments and access control. We responsibly reported all findings to affected vendors and fixes were deployed or on the way. Ze Jin, Luyi Xing, Yiwei Fang, Yan Jia 0009, Bin Yuan 0002, Qixu Liu |
CCS | 4 |
| 2022 | Birds of a Feather Flock Together: How Set Bias Helps to Deanonymize You via Revealed Intersection Sizes
Xiaojie Guo 0004, Zheli Liu, Ding Wang 0002, Yan Jia 0009, Jin Li 0002 |
USENIX Security Symposium | 5 |
| 2022 | How Are Your Zombie Accounts? Understanding Users' Practices and Expectations on Mobile App Account Deletion
Yijing Liu 0007, Yan Jia 0009, Qingyin Tan, Zheli Liu, Luyi Xing |
USENIX Security Symposium | 2 |
| 2021 | Who's In Control? On Security Risks of Disjointed IoT Device Management ChannelsabstractAn IoT device today can be managed through different channels, e.g., by its device manufacturer's app, or third-party channels such as Apple's Home app, or a smart speaker. Supporting each channel is a management framework integrated in the device and provided by different parties. For example, a device that integrates Apple HomeKit framework can be managed by Apple Home app. We call the management framework of this kind, including all its device- and cloud-side components, a device management channel (DMC). 4 third-party DMCs are widely integrated in today's IoT devices along with the device manufacturer's own DMC: HomeKit, Zigbee/Z-Wave compatible DMC, and smart-speaker Seamless DMC. Each of these DMCs is a standalone system that has full mandate on the device; however, if their security policies and control are not aligned, consequences can be serious, allowing a malicious user to utilize one DMC to bypass the security control imposed by the device owner on another DMC. We call such a problem Chaotic Device Management (Codema). Yan Jia 0009, Bin Yuan 0002, Luyi Xing, Dongfang Zhao 0010, Yifan Zhang 0010, XiaoFeng Wang 0001, Yijing Liu 0007, Kaimin Zheng, Peyton Crnjak, Yuqing Zhang 0001, Deqing Zou, Hai Jin 0001 |
CCS | 1 |
| 2021 | Reviewing IoT Security via Logic Bugs in IoT Platforms and SystemsabstractIn recent years, Internet-of-Things (IoT) platforms and systems have been rapidly emerging. Although IoT is a new technology, new does not mean simpler (than existing networked systems). Contrarily, the complexity (of IoT platforms and systems) is actually being increased in terms of the interactions between the physical world and cyberspace. The increased complexity indeed results in new vulnerabilities. This article seeks to provide a review of the recently discovered logic bugs that are specific to IoT platforms and systems and discuss the lessons we learned from these bugs. In particular, 20 logic bugs and one weakness falling into seven categories of vulnerabilities are reviewed in this survey. Wei Zhou 0026, Chen Cao 0004, Dongdong Huo, Lan Zhang 0008, Le Guan, Yan Jia 0009, Yaowen Zheng, Yuqing Zhang 0001, Limin Sun 0001, Yazhe Wang, Peng Liu 0005 |
IEEE Internet Things J. | 8 |
| 2020 | Burglars' IoT Paradise: Understanding and Mitigating Security Risks of General Messaging Protocols on IoT CloudsabstractWith the increasing popularity of the Internet of Things (IoT), many IoT cloud platforms have emerged to help the IoT manufacturers connect their devices to their users. Serving the device-user communication is general messaging protocol deployed on the platforms. Less clear, however, is whether such protocols, which are not designed to work in the adversarial environment of IoT, introduce new risks. In this paper, we report the first systematic study on the protection of major IoT clouds (e.g., AWS, Microsoft, IBM) put in place for the arguably most popular messaging protocol - MQTT. We found that these platforms' security additions to the protocol are all vulnerable, allowing the adversary to gain control of the device, launch a large-scale denial-of-service attack, steal the victim's secrets data and fake the victim's device status for deception. We successfully performed end-to-end attacks on these popular IoT clouds and further conducted a measurement study, which demonstrates that the security impacts of our attacks are real, severe and broad. We reported our findings to related parties, which all acknowledged the importance. We further propose new design principles and an enhanced access model MOUCON. We implemented our protection on a popular open-source MQTT server. Our evaluation shows its high effectiveness and negligible performance overhead. Yan Jia 0009, Luyi Xing, Yuhang Mao, Dongfang Zhao 0010, XiaoFeng Wang 0001, Shangru Zhao, Yuqing Zhang 0001 |
SP | 1 |
| 2020 | Shattered Chain of Trust: Understanding Security Risks in Cross-Cloud IoT Access Delegation
Bin Yuan 0002, Yan Jia 0009, Luyi Xing, Dongfang Zhao 0010, XiaoFeng Wang 0001, Deqing Zou, Hai Jin 0001, Yuqing Zhang 0001 |
USENIX Security Symposium | 2 |
| 2019 | Identifying Privilege Separation Vulnerabilities in IoT Firmware with Symbolic Execution
Wei Zhou 0026, Yan Jia 0009, Lipeng Zhu 0003, Peng Liu 0005, Yuqing Zhang 0001 |
ESORICS (1) | 3 |
| 2019 | Discovering and Understanding the Security Hazards in the Interactions between IoT Devices, Mobile Apps, and Clouds on Smart Home Platforms
Wei Zhou 0026, Yan Jia 0009, Lipeng Zhu 0003, Le Guan, Yuhang Mao, Peng Liu 0005, Yuqing Zhang 0001 |
USENIX Security Symposium | 2 |
| 2019 | The Effect of IoT New Features on Security and Privacy: New Threats, Existing Solutions, and Challenges Yet to Be SolvedabstractInternet of Things (IoT) is an increasingly popular technology that enables physical devices, vehicles, home appliances, etc., to communicate and even inter operate with one another. It has been widely used in industrial production and social applications including smart home, healthcare, and industrial automation. While bringing unprecedented convenience, accessibility, and efficiency, IoT has caused acute security and privacy threats in recent years. There are increasing research works to ease these threats, but many problems remain open. To better understand the essential reasons of new IoT threats and the challenges in current research, this survey first proposes the concept of “IoT features.” Then, we discuss the security and privacy effects of eight IoT features including the threats they cause, existing solutions to threats and research challenges yet to be solved. To help researchers follow the up-to-date works in this field, this paper finally illustrates the developing trend of IoT security research and reveals how IoT features affect existing security research by investigating most existing research works related to IoT security from 2013 to 2017. Wei Zhou 0026, Yan Jia 0009, Anni Peng, Yuqing Zhang 0001, Peng Liu 0005 |
IEEE Internet Things J. | 2 |