Wei Minn

dblp:276/9978 · DBLP profile ↗
← Back
6ranked-venue papers
1as first author
5since 2021 · last 2026
0000-0002-3191-9795ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 5 · 1 first-author · 4 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Studying SATD in drone systems with Human-AI collaboration
Leevi Rantala, Lwin Khin Shar, Mika Mäntylä, Wei Minn, Yan Naing Tun
J. Syst. Softw.4
2025 Virtualization-based Penetration Testing Study for Detecting Accessibility Abuse Vulnerabilities in Banking Apps in East and Southeast Asia
abstract
Android banking applications have revolutionized financial management by allowing users to perform various financial activities through mobile devices. However, this convenience has attracted cybercriminals who exploit security vulnerabilities to access sensitive financial data. FjordPhantom, a malware identified by our industry collaborator, uses virtualization and hooking to bypass the detection of malicious accessibility services, allowing it to conduct keylogging, screen scraping, and unauthorized data access. This malware primarily affects banking and finance apps across East and Southeast Asia region where our industry partner’s clients are primarily based in. It requires users to be deceived into installing a secondary malicious component and activating a malicious accessibility service. In our study, we conducted an empirical study on the susceptibility of banking apps in the region to FjordPhantom, analyzed the effectiveness of protective measures currently implemented in those apps, and discussed ways to detect and prevent such attacks by identifying and mitigating the vulnerabilities exploited by this malware.
Wei Minn, Phong Phan, Vikas Kumar Malviya, Benjamin Adolphi, Yan Naing Tun, Henning Benzon Treichl, Albert Ching, Lwin Khin Shar, David Lo 0001
APSEC1
2025 Runtime Anomaly Detection for Drones: An Integrated Rule-Mining and Unsupervised-Learning Approach
Ivan Tan 0001, Wei Minn, Christopher M. Poskitt, Lwin Khin Shar, Lingxiao Jiang
ICECCS2
2025 Fuzzing drones for anomaly detection: A systematic literature review
Vikas Kumar Malviya, Wei Minn, Lwin Khin Shar, Lingxiao Jiang
Comput. Secur.2
2022 DronLomaly: Runtime Detection of Anomalous Drone Behaviors via Log Analysis and Deep Learning
abstract
Drones are increasingly popular and getting used in a variety of missions such as area surveillance, pipeline inspection, cinematography, etc. While the drone is conducting a mission, anomalies such as sensor fault, actuator fault, configuration errors, bugs in controller program, remote cyberattack, etc., may affect the drone’s physical stability and cause serious safety violations such as crashing into the public. During a flight mission, drones typically log flight status and state units such as GPS coordinates, actuator outputs, accelerator readings, gyroscopic readings, etc. These log data may reflect the abovementioned anomalies. In this paper, we propose a novel, deep learning-based log analysis approach for detecting anomalies in the drone log that could lead to physical instabilities. We train a LSTM-based deep learning model on the normal flight logs produced by a baseline drone. Essentially, the model learns the sequential patterns of flight state units and correlations among them. The model can then be used to detect anomalies in the state units as the log entries are being recorded by the drone’s control program at runtime. In our experiments, we built detection models based on several logs produced by 3 different drone control programs, namely DJI, ArduPilot and PX4, and used them to detect anomalies in the logs. On average, our approach achieves 0.968 recall and 0.963 precision, and it can detect anomalies during runtime within a few milliseconds.
Lwin Khin Shar, Wei Minn, Ta Nguyen Binh Duong, Jiani Fan, Lingxiao Jiang, Daniel Lim Wai Kiat
APSEC2
2020 SmartFuzz: An Automated Smart Fuzzing Approach for Testing SmartThings Apps
abstract
As IoT ecosystem has been fast-growing recently, there have been various security concerns of this new computing paradigm. Malicious IoT apps gaining access to IoT devices and capabilities to execute sensitive operations (sinks), e.g., controlling door locks and switches, may cause serious security and safety issues. Unlike traditional mobile/web apps, IoT apps highly interact with a wide variety of physical IoT devices and respond to environmental events, in addition to user inputs. It is therefore important to conduct comprehensive testing of IoT apps to identify possible anomalous behaviours. On the other hand, it is also important to optimize the number of test cases generated, considering that there may be many possible ways in which apps, devices, environmental events, and user inputs interact. Existing works investigating security in IoT apps have been using ad-hoc testing approaches, in which test cases are usually designed to test some particular aspects of apps or devices. In this work, we develop an automated, smart fuzzing approach, called SmartFuzz, for testing Samsung SmartThings IoT apps. More specifically, SmartFuzz combines combinatorial test generation with light-weight program analysis, and aims to improve test coverage of sinks in an efficient, automated manner. We have implemented and evaluated our approach using a publicly available dataset of 60 SmartApps. The results have demonstrated the effectiveness and efficiency of SmartFuzz. In particular, SmartFuzz improved coverage of sinks by 184%, while generating and executing 20% fewer test cases as compared to ad-hoc testing.
Lwin Khin Shar, Ta Nguyen Binh Duong, Lingxiao Jiang, David Lo 0001, Wei Minn, Glenn Kiah Yong Yeo
APSEC5