VLDB 2026 Research / reviewers in the wild / expert
Jingkun Zhang
dblp:313/4669
· DBLP profile ↗
3ranked-venue papers
1as first author
3since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LibPass: An Entropy-Guided Black-Box Adversarial Attack Against Third-Party Library Detection Tools in the WildabstractTo mitigate the security and compliance risks posed by Android third-party libraries (TPLs), researchers have proposed many automated detection tools aimed at accurately identifying TPLs within Android applications (apps). The detection results serve as the foundation for practical downstream tasks such as software bill of materials (SBOM) generation, n-day vulnerability identification, compliance auditing, and software supply chain risk tracing, among others. However, despite the high levels of detection accuracy and efficiency achieved by state-of-the-art TPL detection tools, existing studies lack a systematic evaluation of these tools' robustness against potential malicious attacks. As a result, the risk of detection failure in real-world scenarios remains unmanageable. Tools with poor robustness may be rendered ineffective under attack, allowing unsafe and non-compliant TPLs within apps to evade scrutiny and analysis, thereby compromising user interests. To bridge this gap, we propose the first adversarial attack against TPL detection tools,LibPass. The core idea ofLibPassis to generate adversarial apps by crafting perturbations that go beyond the code transformations introduced by obfuscation techniques. These adversarial perturbations hinder the generalization capability of existing detection tools, which are primarily designed to counter code obfuscation, thereby enabling the evasion of TPL detection. To minimize attack overhead and enhance stealthiness,LibPassemploys an improved firefly algorithm to search for optimal adversarial apps. This work evaluates the effectiveness ofLibPassagainst five state-of-the-art TPL detection tools on three datasets of different types and benchmarks its performance against three baseline attack methods. Experimental results demonstrate thatLibPassachieves an average attack success rate of 61.33%, with a peak of 99.46%, underscoring the insufficient robustness of current TPL detection tools. Bolin Zhou, JingZheng Wu, Xiang Ling 0001, Jingkun Zhang, Tianyue Luo |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Version-level Third-Party Library Detection in Android Applications via Class Structural SimilarityabstractAndroid applications (apps) integrate reusable and well-tested third-party libraries (TPLs) to enhance functionality and shorten development cycles. However, recent research reveals that TPLs have become the largest attack surface for Android apps, where the use of insecure TPLs can compromise both developer and user interests. To mitigate such threats, researchers have proposed various tools to detect TPLs used by apps, supporting further security analyses such as vulnerable TPLs identification. Although existing tools achieve notable library-level TPL detection performance in the presence of obfuscation, they struggle with version-level TPL detection due to a lack of sensitivity to differences between versions. This limitation results in a high version-level false positive rate, significantly increasing the manual workload for security analysts. To resolve this issue, we propose SAD, a TPL detection tool with high version-level detection performance. SAD generates a candidate app class list for each TPL class based on the feature of nodes in class dependency graphs (CDGs). It then identifies the unique corresponding app class for each TPL class by performing class matching based on the similarity of their class summaries. Finally, SAD identifies TPL versions by evaluating the structural similarity of the sub-graph formed by matched classes within the CDGs of the TPL and the app. Extensive evaluation on three datasets demonstrates the effectiveness of SAD and its components. SAD achieves F1 scores of 97.64% and 84.82% for library-level and version-level detection on obfuscated apps, respectively, surpassing existing state-of-the-art tools. The version-level false positives reported by the best tool is 1.61 times that of SAD. We further evaluate the degree to which TPLs identified by detection tools correspond to actual TPL classes. Experimental results show that SAD achieves a class-level F1 score of 94.12%, 11% higher than the best tool, demonstrating the reliability of SAD and better supporting downstream tasks that rely on specific code. Bolin Zhou, JingZheng Wu, Xiang Ling 0001, Tianyue Luo, Jingkun Zhang |
EASE | 5 |
| 2025 | Shrunk, Yet Complete: Code Shrinking-Resilient Android Third-Party Library DetectionabstractManaging third-party libraries is a costly and critical task for enterprises, essential for both vulnerability assessment and license compliance. Existing android software composition analysis tools focus on mitigating code obfuscation but neglect the impact of code optimization, which is deeply integrated into build pipelines and disrupts library structure.To tackle these challenges, we developed LibSleuth, a detection tool designed to be resilient to code shrinking and obfuscation. It is based on the observation that even after shrinking, the remaining code still retains functional completeness. LibSleuth adopts two novel strategies: (1) Method level functional module matching: We break down feature matching to method level and define a functional module as related methods that represent used functionality. This allows us to detect libraries based on functional module completeness to address code shrinking. (2) Context-enhanced multi-level filtering: To improve robustness against obfuscation and reduce the cost of pairing, LibSleuth leverages contextual relationships to enhance feature stability and adopts a coarse-to-fine progressive matching process.We evaluated LibSleuth on datasets containing obfuscated and optimized Android apps. LibSleuth outperforms state-of-the-art academic and commercial tools in both scenarios. Under combined code shrinking and obfuscation, LibSleuth achieves an average 27.74% higher version level F1-score. Moreover, our analysis of 10,000 real world Android apps shows that 20.35% still depend on vulnerable library, demonstrating the practical utility of LibSleuth for downstream tasks. Jingkun Zhang, JingZheng Wu, Xiang Ling 0001, Tianyue Luo, Bolin Zhou, Mutian Yang |
ASE | 1 |