Yuxi Ling

dblp:336/8051 · DBLP profile ↗
← Back
4ranked-venue papers
3as first author
4since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Sound and Efficient Generation of Data-Oriented Exploits via Programming Language Synthesis
Yuxi Ling, Gokul Rajiv, Kiran Gopinathan, Ilya Sergey
USENIX Security Symposium1
2025 Lamb Wave Communication Based on Airborne Ultrasound Excitation and Reception
abstract
Ultrasound serves as an alternative to traditional communication methods in environments with considerable electromagnetic shielding and interference. Ultrasonic-guided waves, such as Lamb waves, demonstrate advantageous transmission properties in plate-like structures, allowing for long-distance propagation with minimal energy loss. This article introduces a noncontact data transmission technique using air-coupled leaky Lamb waves. Ultrasound signals are emitted and collected by airborne ultrasound transducers. Wave conversion and the dispersion interference of Lamb waves contribute to nonlinear effects in air-coupled leaky Lamb wave communication. To address the nonlinear interference present in the received signal, the receiver uses a deep neural network for effective signal decoding. Transmission experiments in real-world conditions were performed on a plate-like structure using a pitch-catch configuration, evaluating three modulation techniques: amplitude-shift keying, frequency-shift keying, and binary phase-shift keying (BPSK). Among these methods, BPSK exhibited the most effective anti-interference performance. The actual communication system platform successfully achieved a data transmission rate of 50 kbps, with a bit error rate recorded at less than 0.2$\%$.
Yuxi Ling, Zichuan Fan
IEEE Trans. Ind. Informatics2
2024 Essential or Excessive? MINDAEXT: Measuring Data Minimization Practices among Browser Extensions
abstract
Since browser extensions are prevailingly executed in the background to enable extra functionalities and enhance the user experience for web browsers, the potential over-collection of personal data beyond the necessity for given purposes is always ignored by ordinary users. Existing privacy regulations, such as the principle of Data Minimization in GDPR, have provided the criteria that only directly relevant and necessary data for specified purposes should be collected. Various tools have made efforts to examine the compliance of data minimization and its equivalent in different application domains. To our knowledge, in the area of browser extensions, there is still a gap between the general data minimization principle and precisely defined extension behaviors. We propose MINDAExT, a framework that takes one step further to automatically examine end-to-end data minimization practices in browser extensions by description text analysis and hybrid program analysis techniques. In our large-scale measurement, covering around 200K extensions collected in October 2023, we find that 38.0 % of extensions are likely to collect private user data outside their essential functionality scopes. They are distributed across all categories, exhibiting distinct patterns of the target data types. Our evaluation shows that MINDAEXT can detect the data over-collection with a precision of 74.3 %.
Yuxi Ling, Kailong Wang 0001, Guangdong Bai, Jin Song Dong 0001
SANER1
2022 Are they Toeing the Line? Diagnosing Privacy Compliance Violations among Browser Extensions
abstract
Browser extensions have emerged as integrated characteristics in modern browsers, with the aim to boost the online browsing experience. Their advantageous position between a user and the Internet endows them with easy access to the user’s sensitive data, which has raised mounting privacy concerns from both legislators and extension users. In this work, we propose an end-to-end approach to automatically diagnosing the privacy compliance violations among extensions. It analyzes the compliance of privacy policy versus regulation requirements and their actual privacy-related practices during runtime. This approach can serve the extension users, developers and store operators as an efficient and practical detection mechanism for privacy compliance violations.
Yuxi Ling, Kailong Wang 0001, Guangdong Bai, Haoyu Wang 0001, Jin Song Dong 0001
ASE1