VLDB 2026 Research / reviewers in the wild / expert
Shujun Tang
dblp:329/5533
· DBLP profile ↗
7ranked-venue papers
0as first author
7since 2021 · last 2026
0009-0004-5598-135XORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 6 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Small Cell, Big Risk: A Security Assessment of 4G LTE Femtocells in the Wild
Yiming Zhang 0009, Tao Wan 0004, Hai-Xin Duan, Deliang Chang, Yishen Li, Shujun Tang |
NDSS | 7 |
| 2025 | Poster: A First Look at Large Language Model Applications in the Wild from Dual PerspectivesabstractLarge language models (LLMs) have become the foundational technology for numerous applications. Various self-hosted LLM-related applications are deployed on the Internet for purposes such as intelligent assistants. However, their Internet exposure can introduce new security risks. To address this issue, this study conducts a large-scale, long-term measurement of LLM application exposure in the wild through active probing. Numerous publicly accessible instances of various LLM applications, such as Ollama, are deployed without authentication, posing risks of unauthorized access or data leakage. Meanwhile, this paper deploys a series of honeypots that mimic LLM applications to uncover the behaviors and strategies of scanners targeting online LLM applications. Deliang Chang, Xuedong Wu, Xiang Li 0108, Zhengpeng Yang 0001, Asiya, Shujun Tang |
IMC | 10 |
| 2025 | Revealing the Black Box of Device Search Engine: Scanning Assets, Strategies, and Ethical Consideration
Mengying Wu, Geng Hong, Shujun Tang, Youhao Li, Baojun Liu 0002, Hai-Xin Duan, Min Yang 0002 |
NDSS | 5 |
| 2024 | Dissecting Open Edge Computing Platforms: Ecosystem, Usage, and Security RisksabstractEmerging in recent years, open edge computing platforms (OECPs) claim large-scale edge nodes, the extensive usage and adoption, as well as the openness to any third parties to join as edge nodes. For instance, OneThingCloud, a major OECP operated in China, advertises 5 million edge nodes, 70TB bandwidth, and 1,500PB storage. However, little information is publicly available for such OECPs with regards to their technical mechanisms and involvement in edge computing activities. Furthermore, different from known edge computing paradigms, OECPs feature an open ecosystem wherein any third party can participate as edge nodes and earn revenue for the contribution of computing and bandwidth resources, which, however, can introduce byzantine or even malicious edge nodes and thus break the traditional threat model for edge computing. In this study, we conduct the first empirical study on two representative OECPs, which is made possible through the deployment of edge nodes across locations, the efficient and semi-automatic analysis of edge traffic as well as the carefully designed security experiments. As the results, a set of novel findings and insights have been distilled with regards to their technical mechanisms, the landscape of edge nodes, the usage and adoption, and the practical security/privacy risks. Particularly, millions of daily active edge nodes have been observed, which feature a wide distribution in the network space and the extensive adoption in content delivery towards end users of 16 popular Internet services. Also, multiple practical and concerning security risks have been identified along with acknowledgements received from relevant parties, e.g., the exposure of long-term and crossedge-node credentials, the co-location with malicious activities of diverse categories, the failures of TLS certificate verification, the extensive information leakage against end users, etc. Yu Bi, Mingshuo Yang, Xianghang Mi, Shanqing Guo, Shujun Tang, Hai-Xin Duan |
ACSAC | 6 |
| 2024 | ChatScam: Unveiling the Rising Impact of ChatGPT on Domain Name AbuseabstractSince 2022, ChatGPT has been a big breakthrough in technology, creating lots of discussions online. It has had big effects in different areas, but in cybersecurity, it is both good and bad. There has been a lot of misuse, especially with squatting domains. Our research aims to understand this misuse and the potential threats it poses. We develop a novel method that looks at historical Passive DNS (PDNS) data. Based on the two-stage identification, our method can efficiently and accurately collect ChatGPT-related squatting domains. In the end, we found over 1.3 million ChatGPT-related squatting domains, part of which were shared with the security community. Our findings show that these squatting domains are increasing quickly. This is the case whether the keywords related to ChatG PT are registered with the domain registrar or set up on sub domains. Even though the number of domains is increasing, only 5.3 % set up meaningful content on their websites. After digging into their web contents, we found that these web sites show various signs of misuse, such as promotion on illegal underground websites and emerging fraudulent activities related to dialogue features. The security community is not fully aware of these threats yet. We are the first to conduct a large-scale quantitative analysis of ChatGPT-related abusive behavior. We believe that our work unveils the abuse ecosystem surrounding ChatGPT-related squatting domains. We hope to underscore the urgent need for increased attention and protective measures against ChatGPT-related domain abuse. Mingxuan Liu 0006, Zhenglong Jin, Jiahai Yang 0001, Baoiun Liu, Hai-Xin Duan, Ying Liu 0024, Ximeng Liu, Shujun Tang |
DSN | 8 |
| 2022 | An Extensive Study of Residential Proxies in ChinaabstractWe carry out the first in-depth characterization of residential proxies (RESIPs) in China, for which little is studied in previous works. Our study is made possible through a semantic-based classifier to automatically capture RESIP services. In addition to the classifier, new techniques have also been identified to capture RESIPs without interacting with and relaying traffic through RESIP services, which can significantly lower the cost and thus allow continuous monitoring of RESIPs. Our RESIP service classifier has achieved good performance with a recall of 99.7% and a precision of 97.6% in 10-fold cross validation. Applying the classifier has identified 399 RESIP services, a much larger set compared to 38 RESIP services collected in all previous works. Our effort of RESIP capturing leads to a collection of 9,077,278 RESIP IPs (51.36% are located in China), 96.70% of which are not covered in publicly available RESIP datasets. An extensive measurement on RESIPs and their services has uncovered a set of interesting findings as well as several security implications. Especially, 80.05% RESIP IPs located in China have sourced at least one malicious traffic flows during 2021, resulting in 52-million malicious traffic flows in total. And RESIPs have also been observed in corporation networks of 559 sensitive organizations including government agencies, education institutions and enterprises. Also, 3,232,698 China RESIP IPs have opened at least one TCP/UDP port for accepting relaying requests, which incurs non-negligible security risks to the local network of RESIPs. Besides, 91% China RESIP IPs are of a lifetime fewer than 10 days while most China RESIP services show up a crest-trough pattern in terms of the daily active RESIPs across time. Mingshuo Yang, Yunnan Yu, Xianghang Mi, Shujun Tang, Shanqing Guo, Yilin Li 0016, Hai-Xin Duan |
CCS | 4 |
| 2022 | Building an Open, Robust, and Stable Voting-Based Domain Top List
Qinge Xie, Shujun Tang, Qingran Lin, Baojun Liu 0002, Hai-Xin Duan, Frank Li 0001 |
USENIX Security Symposium | 2 |