VLDB 2026 Research / reviewers in the wild / expert
Jiapeng Deng
dblp:370/5563
· DBLP profile ↗
3ranked-venue papers
0as first author
3since 2021 · last 2025
—ORCID · unresolved
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
3 papers |
Privacy and data protection · 50% Web and mobile security · 25% Authentication and access control · 19% | |
| Software engineering, system software, and programming languages
1 paper |
Program analysis · 100% |
Topics — the 8 heaviest of 8, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Web and mobile security
mobile security |
1.1 | 2 | 2025 | Born with a Silver Spoon: On the (In)Security of Native Granted App Privileges in Custom Android ROMs · SP 2025 HarmoBridge: Bridging ArkTS and C/C++ for Cross-Language Static Analysis on HarmonyOS · ASE 2025 |
Authentication and access control › access control
permission management |
0.9 | 1 | 2025 | Born with a Silver Spoon: On the (In)Security of Native Granted App Privileges in Custom Android ROMs · SP 2025 |
Program analysis › static analysis
cross-language analysis |
0.9 | 1 | 2025 | HarmoBridge: Bridging ArkTS and C/C++ for Cross-Language Static Analysis on HarmonyOS · ASE 2025 |
Program analysis
data flow analysis |
0.9 | 1 | 2025 | HarmoBridge: Bridging ArkTS and C/C++ for Cross-Language Static Analysis on HarmonyOS · ASE 2025 |
Privacy and data protection
mobile privacy |
0.8 | 1 | 2024 | Exploring Covert Third-party Identifiers through External Storage in the Android New Era · USENIX Security Symposium 2024 |
Privacy and data protection › web tracking
third-party tracking |
0.8 | 1 | 2024 | Exploring Covert Third-party Identifiers through External Storage in the Android New Era · USENIX Security Symposium 2024 |
Privacy and data protection › online tracking
user tracking |
0.8 | 1 | 2024 | Exploring Covert Third-party Identifiers through External Storage in the Android New Era · USENIX Security Symposium 2024 |
Systems and software security
vulnerability discovery |
0.3 | 1 | 2025 | Born with a Silver Spoon: On the (In)Security of Native Granted App Privileges in Custom Android ROMs · SP 2025 |
Methods — techniques the papers use, named apart from their topics
summary-based analysis · 1.7intermediate representation · 1.7large-scale ROM analysis · 0.9external storage analysis · 0.8
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | HarmoBridge: Bridging ArkTS and C/C++ for Cross-Language Static Analysis on HarmonyOSabstractHarmonyOS is Huawei’s distributed operating system designed for diverse smart devices, featuring ArkTS as its primary app development language. To enhance performance and leverage existing libraries, HarmonyOS apps can integrate native C/C++ modules through its Native Development Kit (NDK) mechanism. This creates significant challenges for static analysis, as critical data flows spanning ArkTS and native C/C++ boundaries remain invisible to existing single-language analyzers. Therefore, we present HarmoBridge, the first cross-language static analysis system for HarmonyOS that bridges this gap through novel summary based SumIR abstraction and seamless ecosystem integration. Our approach extracts dataflow summaries from native code (supporting both binary and source code analysis) and translates these summaries into intermediate representations that integrate seamlessly with the existing HarmonyOS analysis infrastructure. HarmoBridge introduces SumIR, a specialized intermediate representation that captures Node-API interaction semantics and converts them to ArkIR-compatible function bodies for downstream analysis tools. Also, we develop CrossFlowBench, a comprehensive benchmark covering representative Node-API interaction patterns, and identify potential security implications where established cross-language attack patterns widely prevalent in mobile ecosystems could adapt to HarmonyOS’s architecture. Results demonstrate that HarmoBridge achieves 81.0% accuracy in recovering cross-language data flows on CrossFlowBench, significantly outperforming baseline approaches that treat native calls as opaque operations, establishing a foundation for comprehensive cross-language analysis in the emerging HarmonyOS ecosystem. Jiapeng Deng, Yanjie Zhao 0001, Li Li 0029, Haoyu Wang 0001 |
ASE | 2 |
| 2025 | Born with a Silver Spoon: On the (In)Security of Native Granted App Privileges in Custom Android ROMsabstractThe customization and fragmentation of the Android ecosystem have fostered its prosperity and highlighted the growing importance of conducting security audits on these customized systems. This significance is driven by the distinct strategies that Original Equipment Manufacturers (OEMs) deploy to enhance device performance and user experience, which are important to their competitive differentiation. A key aspect of these strategies includes system-level optimizations for super apps and other widely used apps, marking a competitive trend among OEMs. Granting privileges to such apps often stems from trust in these apps. However, without proper validation of apps' identities, this can lead to severe implicit trust vulnerabilities, providing a convenient pathway for malicious apps to impersonate privileged ones and gain their access rights. For malicious developers, exploiting these vulnerabilities is both cost-effective and potentially highly rewarding. In this study, we undertook a comprehensive analysis of 686 custom Android ROMs from 46 OEMs, aimed at uncovering potential security risks associated with implicit trust vulnerabilities in apps. Our investigation identified 3,085 instances where thirdparty app package names were embedded within the ROMs. Alarmingly, only seven of these instances had implemented adequate authentication mechanisms to mitigate the associated risks, exposing 3,078 potential vulnerabilities that exhibited an increasing trend over time. We have reported 22 manually confirmed cases to seven relevant OEMs. As of the time of writing this paper, four vulnerabilities have been explicitly acknowledged by the OEMs, and one has been assigned a CVE ID. Chao Wang 0097, Yanjie Zhao 0001, Jiapeng Deng, Haoyu Wang 0001 |
SP | 3 |
| 2024 | Exploring Covert Third-party Identifiers through External Storage in the Android New Era
Zikan Dong, Tianming Liu 0002, Jiapeng Deng, Haoyu Wang 0001, Li Li 0029, Guosheng Xu 0001, Guoai Xu |
USENIX Security Symposium | 3 |