VLDB 2026 Research / reviewers in the wild / expert
Kailun Yan
dblp:341/9518
· DBLP profile ↗
8ranked-venue papers
5as first author
8since 2021 · last 2026
0000-0003-0216-9793ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | From Patterns to Precision: LLM-Guided Detection of Signature Verification Flaws in Smart Contracts
Huixin Wang, Kailun Yan, Wenrui Diao |
SANER | 2 |
| 2026 | Unveiling the Centralized Security Risks in Decentralized EcosystemsabstractThe decentralized ecosystem is claimed to avoid security risks caused by centralization. Decentralized services, such as crypto wallets and decentralized applications (DApps), are purported to offer more reliable security and better protect user privacy. However, our research suggests a different reality: centralized components or scenarios are still prevalent within decentralized ecosystems, introducing security risks typically associated with centralization. This work systematically investigated the centralized security risks in crypto wallets and DApps. We found seven security risks and developed a series of methods to identify these risks. The detection results indicate that centralized security risks are widespread in the decentralized ecosystem. Among the 28 Ethereum-recommended crypto wallets, 96.4% have security risks. Of the 78 Web3 sites (frontends of DApps), 100% contain third-party scripts, and 44.9% expose the user's address to third parties. Furthermore, we developed a high-precision automated tool and inspected 110,506 on-chain smart contracts (backends of DApps), discovering that 83.5% contain at least one security risk. These risks affect 260 well-known tokens with a combined market capitalization exceeding${\$}$98 billion. Kailun Yan, Jilian Zhang, Wenrui Diao |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | An Empirical Study on Cross-chain Transactions: Costs, Inconsistencies, and Activities
Kailun Yan, Pranav Agrawal 0002, Jiasun Li, Wenrui Diao, Xiaokuan Zhang |
AsiaCCS | 1 |
| 2024 | Stealing Trust: Unraveling Blind Message Attacks in Web3 AuthenticationabstractAs the field of Web3 continues its rapid expansion, the security of Web3 authentication, often the gateway to various Web3 applications, becomes increasingly crucial. Despite its widespread use as a login method by numerous Web3 applications, the security risks of Web3 authentication have not received much attention. This paper investigates the vulnerabilities in the Web3 authentication process and proposes a new type of attack, dubbed blind message attacks. In blind message attacks, attackers trick users into blindly signing messages from target applications by exploiting users' inability to verify the source of messages, thereby achieving unauthorized access to the target application. We have developed Web3AuthChecker, a dynamic detection tool that interacts with Web3 authentication-related APIs to identify vulnerabilities. Our evaluation of real-world Web3 applications shows that a staggering 75.8% (22/29) of Web3 authentication deployments are at risk of blind message attacks. In response to this alarming situation, we implemented Web3AuthGuard on the open-source wallet MetaMask to alert users of potential attacks. Our evaluation results show that Web3AuthGuard can successfully raise alerts in 80% of the tested Web3 authentications. We have responsibly reported our findings to vulnerable websites and have been assigned two CVE IDs. Kailun Yan, Xiaokuan Zhang, Wenrui Diao |
CCS | 1 |
| 2024 | Understanding Android OS Forward Compatibility Support for Legacy Apps: A Data-Driven AnalysisabstractThe update of Android OS constantly brings users various new features and enhances system security. On the other hand, the system and API modifications with the update may introduce the app compatibility issue. The app's SDK version may not align with the Android OS version, making apps not work adequately. This condition will inevitably damage the Android ecosystem. Thus, while developing Android OS, Google considered and deployed compatibility support. The software engineering research community also noticed the Android compatibility issue and conducted some investigations. However, most previous studies focus on apps' performance and solutions on compatibility (apps running on multiple OS versions). Rare work considers the Android OS side's forward compatibility implementations (supporting legacy apps running on the latest OS). This work systematically studied how Android OS implements forward compatibility for the apps developed with outdated SDKs, primarily focusing on the targetSdkVersion-based fine-grained control. Specifically, we propose three research questions, covering: 1) the forward compatibility support approaches; 2) the stability of foforward compatibility support in third-party market apps. To address these questions, we conducted comprehensive measurements on Android's forward compatibility support, including its implementation, implications, and evolution. Our measurements were based on large-scale datasets covering the source code of Android 8.0~ 13 and 130,461 apps. Finally, we provide rich data support and analysis to answer these questions. This study offers new insights into Android's forward compatibility support, helping the research community understand the evolution of Android's API design. Rui Li 0102, Kailun Yan, Shishuai Yang, Wenrui Diao |
SANER | 4 |
| 2023 | Bad Apples: Understanding the Centralized Security Risks in Decentralized EcosystemsabstractThe blockchain-powered decentralized applications and systems have been widely deployed in recent years. The decentralization feature promises users anonymity, security, and non-censorship, which is especially welcomed in the areas of decentralized finance and digital assets. From the perspective of most common users, a decentralized ecosystem means every service follows the principle of decentralization. However, we find that the services in a decentralized ecosystem still may contain centralized components or scenarios, like third-party SDKs and privileged operations, which violate the promise of decentralization and may cause a series of centralized security risks. In this work, we systematically study the centralized security risks existing in decentralized ecosystems. Specifically, we identify seven centralized security risks in the deployment of two typical decentralized services – crypto wallets and DApps, such as anonymity loss and overpowered owner. Also, to measure these risks in the wild, we designed an automated detection tool called Naga and carried out large-scale experiments. Based on the measurement of 28 Ethereum crypto wallets (Android version) and 110,506 on-chain smart contracts, the result shows that the centralized security risks are widespread. Up to 96.4% of wallets and 83.5% of contracts exist at least one security risk, including 260 well-known tokens with a total market cap of over $98 billion. Kailun Yan, Jilian Zhang, Wenrui Diao, Shanqing Guo |
WWW | 1 |
| 2023 | Improving Bitcoin Transaction Propagation Efficiency through Local Clique NetworkabstractAbstract Bitcoin is a popular decentralized cryptocurrency, and the Bitcoin network is essentially an unstructured peer-to-peer (P2P) network that can synchronize distributed database of replicated ledgers through message broadcasting. In the Bitcoin network, the average clustering coefficient of nodes is very high, resulting in low message propagation efficiency. In addition, average node degree in the Bitcoin network is also considerably large, causing high message redundancy when nodes use the gossip protocol to broadcast messages. These may affect message propagation speed, hindering Bitcoin from being applied to scenarios of high transactional throughputs. To illustrate, we have collected single-hop propagation data of transactions of 366 blocks from Bitcoin Core. The analysis results show that transaction verification and network delay are two major causes of low transaction propagation efficiency. In this paper, we propose a novel P2P network structure, called local clique network (LCN), for message broadcasting in the Bitcoin network. Specifically, to reduce transaction validation latency and message redundancy, in LCN local nodes (logically) form cliques, and only a few nodes in a clique broadcast messages to the other cliques, instead of each node sending messages to its neighboring nodes. We have conducted extensive experiments, and the results show that message redundancy is low in LCN, and message propagation speed increases significantly. Meanwhile, LCN exhibits excellent robustness when average node degree remains high in the Bitcoin network. Kailun Yan, Jilian Zhang, Yongdong Wu |
Comput. J. | 1 |
| 2022 | Cast Away: On the Security of DLNA Deployments in the SmartTV EcosystemabstractThe casting service on SmartTV has been increasingly used for home entertainment and business, given the convenience offered in media broadcast and screen sharing. Among the underlying protocols that support TV cast, DLNA (Digital Living Networking Alliance) – established by a group of tech giants – has become a prevailing standard in the consumer market. Although DLNA has launched the market for years, concerns may arise about whether its real-world deployment has been clearly understood.In this work, we systematically evaluate the security of DLNA deployments in the SmartTV ecosystem. Specifically, we identify a series of critical security issues in the interactions between SmartTVs and casting apps on the smartphone, ranging from non-mandatory encryption to unauthorized file access. The identified security risks can be exploited by a malicious app on the victim’s phone, without requesting sensitive permissions, to launch multiple attacks, including arbitrary command execution, data theft, MITM (man-in-the-middle) attack, and DoS (denial-of-service) attack. To measure the impact of the identified security issues, we designed semi-automated analysis solutions to facilitate the measurements and conducted real-world experiments on 10 on-shelf TV boxes. The results show that most DLNA implementations of products and apps in the wild are insecure. In the end, we provide immediate improvement solutions to mitigate the identified security issues. Guangwei Tian, Jiongyi Chen, Kailun Yan, Shishuai Yang, Wenrui Diao |
QRS | 3 |