VLDB 2026 Research / reviewers in the wild / expert
Ruixuan Li 0008
dblp:364/5622
· DBLP profile ↗
11ranked-venue papers
7as first author
11since 2021 · last 2026
0000-0002-0729-9661ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 5 since 2021Computer networks · 4 · 3 first-author · 4 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CoordMail: Exploiting SMTP Timeout and Command Interaction to Coordinate Email Middleware for Convergence Amplification Attack
Ruixuan Li 0008, Chaoyi Lu, Baojun Liu 0002, Yanzhong Lin, Qingfeng Pan, Jun Shao 0001 |
NDSS | 1 |
| 2026 | Characterizing Iran's Phased National Internet Shutdown in 2025: A Progressive and Distributed Action
Shibo Cui, Mingxuan Liu 0006, Baojun Liu 0002, Hai-Xin Duan, Ruixuan Li 0008, Chaoyi Lu, Jinghua Bai |
WWW | 5 |
| 2026 | Traffic Shadowing: A Global Investigation of Internet Traffic Observation and User Data Reutilization
Yunpeng Xing, Chaoyi Lu, Baojun Liu 0002, Ruixuan Li 0008, Hai-Xin Duan |
IEEE Trans. Netw. | 4 |
| 2025 | Email Cloaking: Deceiving Users and Spam Email Detectors with Invisible HTML Settings
Bingyang Guo, Mingxuan Liu 0006, Yihui Ma, Ruixuan Li 0008, Fan Shi 0003, Min Zhang 0054, Baojun Liu 0002, Chengxi Xu, Hai-Xin Duan, Geng Hong, Min Yang 0002, Qingfeng Pan |
ESORICS (4) | 4 |
| 2025 | Understanding and Characterizing Intermediate Paths of Email Delivery: The Hidden DependenciesabstractIn the cloud era, hosting-based email services have become a common business model. Various entities can participate in the email delivery process. However, the intermediate paths of email delivery have received little attention. In particular, the vulnerabilities and centralization of email intermediate paths have already posed real-world security threats. This paper conducts the first systematic analysis of intermediate paths of email delivery, aiming to understand dependence patterns and characterize the centralization. In collaboration with a large email service provider, we collected Received headers from email reception logs spanning nine months and reconstructed the complete intermediate paths of 105M clean emails. Our results reveal that Microsoft is the dominant provider of intermediate paths, participating in 66.4% of emails. We find that 86.9M (82.7%) emails rely on third-party providers in intermediate paths, and 9.1M (8.7%) paths involve multiple providers. Email signature providers frequently appear in cross-vendor intermediate paths. In addition, we reveal significant differences in the regional dependencies and centralization of email intermediate paths across countries and continents. The centralization observed in email intermediate paths also differs from incoming and outgoing servers. We hope our work prompts more attention to email intermediate paths to enhance the security of the email ecosystem. Ruixuan Li 0008, Chaoyi Lu, Baojun Liu 0002, Yanzhong Lin, Hai-Xin Duan, Qingfeng Pan, Jun Shao 0001 |
IMC | 1 |
| 2025 | HADES Attack: Understanding and Evaluating Manipulation Risks of Email Blocklists
Ruixuan Li 0008, Chaoyi Lu, Baojun Liu 0002, Geng Hong, Hai-Xin Duan, Yanzhong Lin, Qingfeng Pan, Min Yang 0002, Jun Shao 0001 |
NDSS | 1 |
| 2024 | Bounce in the Wild: A Deep Dive into Email Delivery Failures from a Large Email Service ProviderabstractAbnormal email bounces seriously disrupt user lives and company transactions. Proliferating security protocols and protection strategies have made email delivery increasingly complex. A natural question is how and why email delivery fails in the wild. Filling this knowledge gap requires a representative global email delivery dataset, which is rarely disclosed by email service providers (ESPs). Ruixuan Li 0008, Shaodong Xiao, Baojun Liu 0002, Yanzhong Lin, Hai-Xin Duan, Qingfeng Pan, Jianjun Chen 0005, Jia Zhang 0004, Ximeng Liu, Xiuqi Lu, Jun Shao 0001 |
IMC | 1 |
| 2024 | Tickets or Privacy? Understand the Ecosystem of Chinese Ticket Grabbing Apps
Yijing Liu 0007, Yiming Zhang 0009, Baojun Liu 0002, Hai-Xin Duan, Mingxuan Liu 0006, Ruixuan Li 0008 |
USENIX Security Symposium | 7 |
| 2024 | A Worldwide View on the Reachability of Encrypted DNS ServicesabstractTo protect user DNS privacy, four DNS over Encryption (DoE) protocols have been proposed, including DNS over TLS (DoT), DNS over HTTPS (DoH), DNS over QUIC (DoQ), and DNS over HTTP/3 (DoH3). Ensuring reachability stands as a prominent prerequisite for the proper functionality of these DoE protocols, driving considerable efforts in this domain. However, existing studies predominantly concentrate on a limited number of DoT/DoH domains or employ a restricted subset of vantage points (VPs). Ruixuan Li 0008, Baojun Liu 0002, Chaoyi Lu, Hai-Xin Duan, Jun Shao 0001 |
WWW | 1 |
| 2024 | The Potential Harm of Email Delivery: Investigating the HTTPS Configurations of Webmail ServicesabstractWebmail, protected by the HTTPS protocol, only works correctly if both the server and client implement HTTPS-related features without vulnerability. Nevertheless, the deployment situation of these features in the webmail world is still unclear. To this end, we perform the first end-to-end and large-scale measurement of webmail service. For the server side, we first build an email address set with a size of 2.2 billion. Then we construct two webmail domain datasets: one contains 21 k domains filtered from the email address set; the other only includes 34 domains but supports more than 75% of the 2.2 billion email addresses. After performing a comprehensive measurement on these two webmail domain datasets, we find that some features are poorly deployed. Furthermore, we also rank servers by analyzing the properties of HTTPS-related features. For the client side, we investigate implement of HTTPS-related features in 50 different combinations of web browsers and operating systems (OSes). We find that even the latest browsers have poor support for some features. For example, Firefox in all OSes does not support CT. Our findings highlight that the full deployment of the security features for the HTTPS ecosystem is still a challenge, even in the webmail service. Ruixuan Li 0008, Zhenyong Zhang, Jun Shao 0001, Rongxing Lu, Xiaoqi Jia, Guiyi Wei |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | A Longitudinal and Comprehensive Measurement of DNS Strict PrivacyabstractThe DNS privacy protection mechanisms, DNS over TLS (DoT) and DNS over HTTPS (DoH), only work correctly if both the server and client support the Strict Privacy profile and no vulnerability exists in the implemented TLS/HTTPS. A natural question then arises: what is the landscape of DNS Strict Privacy? To this end, we provide the first longitudinal and comprehensive measurement of DoT/DoH deployments in recursive resolvers, authoritative servers, and browsers. With the collected data, we find the number of DoT/DoH servers increased substantially during our ten-month-long scan. However, around 60% of DoT and 44% of DoH recursive resolver certificates are invalid. Worryingly, our measurements confirm the centralization problem of DoT/DoH. Furthermore, we classify DNS Strict Privacy servers into four levels according to daily scanning results on TLS/HTTPS-related security features. Unfortunately, around 25% of DoH Strict Privacy recursive resolvers fail to meet the minimum level requirements. To help the Internet community better perceive the landscape of DNS Strict Privacy, we implement a DoT/DoH server search engine and recommender system. Additionally, we investigate five popular browsers across four operating systems and find some inconsistent behavior with their DNS privacy implementations. For example, Firefox in Windows, Linux, and Android allows DoH communication with the server without the SAN certificate. At last, we advocate that all participants head together for a bright DNS Strict Privacy landscape by discussing current hindrances and controversies in DNS privacy. Ruixuan Li 0008, Zhenyong Zhang, Jun Shao 0001, Rongxing Lu, Jingqiang Lin 0001, Xiaoqi Jia, Guiyi Wei |
IEEE/ACM Trans. Netw. | 1 |