Ruoyan Lin

dblp:392/3328 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
4since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Dialing Danger: Large-Scale Risk Assessment of Android Secret Codes in OEM Firmware
Ruoyan Lin, Shishuai Yang, Fenghao Xu, Wenrui Diao
SANER1
2026 Investigating cross-market android apps: Security, protection, and components
Shishuai Yang, Ruoyan Lin, Jialong Guo, Guangdong Bai, Yujia Luo, Wenrui Diao
Empir. Softw. Eng.2
2024 Beyond the Horizon: Exploring Cross-Market Security Discrepancies in Parallel Android Apps
abstract
Multi-channel distribution of Android apps offers convenience to users, yet simultaneously introduces security concerns. Although apps published on Google Play and third-party markets share the same version code, differences in app content may still arise. Notably, a recent incident involving the third-party market version of Pinduoduo app containing malicious code highlights the intentionally-differentiated implementations of app functionalities by developers between Google Play and third-party markets. The case of Pinduoduo may be just the tip of the iceberg, underscoring the need for a comprehensive investigation of the disparities between Google Play and third-party market versions of apps.In this work, we systematically analyze the differences in security and privacy of cross-market apps that claim to share the same version code. Specifically, we propose three research questions that cover differences in app protection, security threats, and permission usage. To answer these questions, we constructed a dataset containing 17,218 app pairs (filtered from 236,731 apps) and permission mappings (27,046 SDK mappings, 1,656 ContentProvider mappings, and 309 Intent mappings) for API levels 16 - 33. This dataset enables us to perform a comprehensive differential analysis. Consequently, our investigation unveiled a series of captivating and insightful findings. Approximately 29.02% of apps show differences in one or all three aspects. For example, the third-party market versions of apps often request more permissions compared to their Google Play counterparts, particularly among apps in the game category. Our work can help developers and app store operators improve cross-market app consistency, enhancing the quality of the Android app ecosystem and user experience.
Shishuai Yang, Guangdong Bai, Ruoyan Lin, Jialong Guo, Wenrui Diao
ISSRE3
2024 Security Assessment of Customizations in Android Smartwatch Firmware
abstract
The widespread use of mobile technology has led to the integration of mobile devices, especially smartwatches, into daily life due to their convenience and functionality. With Android being the most popular mobile operating system, Android-based smartwatches, such as those powered by Google’s Wear OS, have become increasingly popular. However, the customization of smartwatch firmware by manufacturers, while improving user experience, poses significant security risks. This study conducts a comprehensive security analysis of Android smartwatch firmware, focusing on security configurations, patch management, and pre-installed applications. Through the analysis of 176 firmware images from 24 vendors, the study identifies 1,684 insecure configurations resulting from customization, significant delays in applying security patches, and reveals that 26.1% of pre-installed apps have potential security risks. These findings underscore security concerns in Android smartwatch firmware and highlight the need to prioritize security in firmware development and customization practices.
Ruoyan Lin, Qinsheng Hou, Peng Tang 0002, Wenrui Diao
TrustCom2