VLDB 2026 Research / reviewers in the wild / expert
Yi Chen 0024
dblp:49/6574-24
· DBLP profile ↗
13ranked-venue papers
6as first author
8since 2021 · last 2026
0009-0006-3123-0329ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 6 first-author · 8 since 2021Systems, architecture and hardware · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Unidentifiable Identifier: Attacking Bluetooth Applications with Duplicated UUIDs
Siyu Shen, Yi Chen 0024, Fenghao Xu, Shuaike Dong, Wenrui Diao, Di Tang 0001, Kehuan Zhang |
EuroS&P | 2 |
| 2024 | Stealthy Peers: Understanding Security and Privacy Risks of Peer-Assisted Video StreamingabstractPeer-assisted delivery network (PDN) can significantly reduce the bandwidth cost incurred by traditional CDN services. However, it is unclear whether they have been deployed extensively and their security implications have never been investigated thoroughly. In this paper, we report the first effort to address this issue through an automatic pipeline to discover real-world PDN services and their customers, and a PDN analysis framework to test the potential security and privacy risks of these services. Our results have revealed the extensive adoption of PDN across the Internet, especially by Chinese video platforms. Most importantly, our analysis on these PDN services has brought to light a series of novel security vulnerabilities, i.e., free riding of PDN services, video segment pollution, and unreported privacy risks, i.e., resource squatting and extensive leakage of video viewers' IPs. We have responsibly disclosed these security risks to relevant PDN providers which in turn have well acknowledged our findings. Eihal Alowaisheq, Xianghang Mi, Yi Chen 0024, XiaoFeng Wang 0001, Yanzhi Dou |
DSN | 4 |
| 2024 | Racing on the Negative Force: Efficient Vulnerability Root-Cause Analysis through Reinforcement Learning on Counterexamples
Dandan Xu, Di Tang 0001, Yi Chen 0024, XiaoFeng Wang 0001, Kai Chen 0012, Haixu Tang, Longxing Li |
USENIX Security Symposium | 3 |
| 2023 | Sherlock on Specs: Building LTE Conformance Tests through Automated Reasoning
Yi Chen 0024, Di Tang 0001, Yepeng Yao, Mingming Zha 0001, XiaoFeng Wang 0001, Xiaozhong Liu 0001, Haixu Tang, Baoxu Liu |
USENIX Security Symposium | 1 |
| 2022 | Seeing the Forest for the Trees: Understanding Security Hazards in the 3GPP Ecosystem through Intelligent Analysis on Change Requests
Yi Chen 0024, Di Tang 0001, Yepeng Yao, Mingming Zha 0001, XiaoFeng Wang 0001, Xiaozhong Liu 0001, Haixu Tang, Dongfang Zhao 0010 |
USENIX Security Symposium | 1 |
| 2021 | Android on PC: On the Security of End-user Android EmulatorsabstractAndroid emulators today are not only acting as a debugging tool for developers but also serving the massive end-users. These end-user Android emulators have attracted millions of users due to their advantages of running mobile apps on desktops and are especially appealing for mobile game players who demand larger screens and better performance. Besides, they commonly provide some customized assistant functionalities to improve the user experience, such as keyboard mapping and app installation from the host. To implement these services, emulators inevitably introduce communication channels between host OS and Android OS (in the Virtual Machine), thus forming a unique architecture which mobile phone does not have. However, it is unknown whether this architecture brings any new security risks to emulators. Fenghao Xu, Siyu Shen, Wenrui Diao, Zhou Li 0001, Yi Chen 0024, Rui Li 0102, Kehuan Zhang |
CCS | 5 |
| 2021 | Practical and Efficient in-Enclave Verification of Privacy ComplianceabstractA trusted execution environment (TEE) such as Intel Software Guard Extension (SGX) runs attestation to prove to a data owner the integrity of the initial state of an enclave, including the program to operate on her data. For this purpose, the data-processing program is supposed to be open to the owner or a trusted third party, so its functionality can be evaluated before trust being established. In the real world, however, increasingly there are application scenarios in which the program itself needs to be protected (e.g., proprietary algorithm). So its compliance with privacy policies as expected by the data owner should be verified without exposing its code. To this end, this paper presents Deflection, a new model for TEE-based delegated and flexible in-enclave code verification. Given that the conventional solutions do not work well under the resource-limited and TCB-frugal TEE, we come up with a new design inspired by Proof-Carrying Code. Our design strategically moves most of the workload to the code generator, which is responsible for producing easy-to-check code, while keeping the consumer simple. Also, the whole consumer can be made public and verified through a conventional attestation. We implemented this model on Intel SGX and demonstrate that it introduces a very small part of TCB. We also thoroughly evaluated its performance on micro- and macro- benchmarks and real-world applications, showing that the design only incurs a small overhead when enforcing several categories of security policies. Weijie Liu 0004, Wenhao Wang 0001, XiaoFeng Wang 0001, Yaosong Lu, Kai Chen 0012, Qintao Shen, Yi Chen 0024, Haixu Tang |
DSN | 9 |
| 2021 | Bookworm Game: Automatic Discovery of LTE Vulnerabilities Through Documentation AnalysisabstractIn the past decade, the security of cellular networks has been increasingly under scrutiny, leading to the discovery of numerous vulnerabilities that expose the network and its users to a wide range of security risks, from denial of service to information leak. However, most of these findings have been made through ad-hoc manual analysis, which is inadequate for fundamentally enhancing the security assurance of a system as complex as the cellular network. An important observation is that the massive amount of technical documentation of cellular network can provide key insights into the protection it puts in place and help identify potential security flaws. Particularly, we found that such documentation often contains hazard indicators (HIs) – the statement that describes a risky operation (e.g., abort an ongoing procedure) when a certain event happens at a state, which can guide a test on the system to find out whether the operation can indeed be triggered by an unauthorized party to cause harm to the cellular core or legitimate users’ equipment. Based upon this observation, we present in this paper a new framework that makes the first step toward intelligent and systematic security analysis of cellular networks. Our approach, called Atomic, utilizes natural-language processing and machine learning techniques to scan a large amount of LTE documentation for HIs. The HIs discovered are further parsed and analyzed to recover state and event information for generating test cases. These test cases are further utilized to automatically construct tests in an LTE simulation environment, which runs the tests to detect the vulnerabilities in the LTE that allow the risky operations to happen without proper protection. In our research, we implemented Atomic and ran it on the LTE NAS specification, including 549 pages with 13,598 sentences and 283,850 words. In less than 5 hours, our prototype reported 42 vulnerabilities from 192 HIs discovered, including 10 never reported before, under two threat models. All these vulnerabilities have been confirmed through end-to-end attacks, which lead to unauthorized disruption of the LTE service a legitimate user’s equipment receives. We reported our findings to authorized parties and received their confirmation that these vulnerabilities indeed exist in major commercial carriers and $2,000 USD reward from Google. Yi Chen 0024, Yepeng Yao, XiaoFeng Wang 0001, Dandan Xu, Chang Yue, Xiaozhong Liu 0001, Kai Chen 0012, Haixu Tang, Baoxu Liu |
SP | 1 |
| 2019 | Demystifying Hidden Privacy Settings in Mobile AppsabstractMobile apps include privacy settings that allow their users to configure how their data should be shared. These settings, however, are often hard to locate and hard to understand by the users, even in popular apps, such as Facebook. More seriously, they are often set to share user data by default, exposing her privacy without proper consent. In this paper, we report the first systematic study on the problem, which is made possible through an in-depth analysis of user perception of the privacy settings. More specifically, we first conduct two user studies (involving nearly one thousand users) to understand privacy settings from the user's perspective, and identify these hard-to-find settings. Then we select 14 features that uniquely characterize such hidden privacy settings and utilize a novel technique called semantics- based UI tracing to extract them from a given app. On top of these features, a classifier is trained to automatically discover the hidden privacy settings, which together with other innovations, has been implemented into a tool called Hound. Over our labeled data set, the tool achieves an accuracy of 93.54%. Further running it on 100,000 latest apps from both Google Play and third-party markets, we find that over a third (36.29%) of the privacy settings identified from these apps are “hidden”. Looking into these settings, we observe that they become hard to discover and hard to understand primarily due to the problematic categorization on the apps' user interfaces and/or confusing descriptions. Further importantly, though more privacy options have been offered to the user over time, also discovered is the persistence of their usability issue, which becomes even more serious, e.g., originally easy-to-find settings now harder to locate. And among all such hidden privacy settings, 82.16% are set to leak user privacy by default. We provide suggestions for improving the usability of these privacy settings at the end of our study. Yi Chen 0024, Mingming Zha 0001, Nan Zhang 0018, Dandan Xu, Xuan Feng 0005, Kan Yuan, Fnu Suya, Yuan Tian 0001, Kai Chen 0012, XiaoFeng Wang 0001 |
IEEE Symposium on Security and Privacy | 1 |
| 2019 | Stealthy Porn: Understanding Real-World Adversarial Images for Illicit Online PromotionabstractRecent years have witnessed the rapid progress in deep learning (DP), which also brings their potential weaknesses to the spotlights of security and machine learning studies. With important discoveries made by adversarial learning research, surprisingly little attention, however, has been paid to the real-world adversarial techniques deployed by the cybercriminal to evade image-based detection. Unlike the adversarial examples that induce misclassification using nearly imperceivable perturbation, real-world adversarial images tend to be less optimal yet equally effective. As a first step to understand the threat, we report in the paper a study on adversarial promotional porn images (APPIs) that are extensively used in underground advertising. We show that the adversary today's strategically constructs the APPIs to evade explicit content detection while still preserving their sexual appeal, even though the distortions and noise introduced are clearly observable to humans. To understand such real-world adversarial images and the underground business behind them, we develop a novel DP-based methodology called Male`na, which focuses on the regions of an image where sexual content is least obfuscated and therefore visible to the target audience of a promotion. Using this technique, we have discovered over 4,000 APPIs from 4,042,690 images crawled from popular social media, and further brought to light the unique techniques they use to evade popular explicit content detectors (e.g., Google Cloud Vision API, Yahoo Open NSFW model), and the reason that these techniques work. Also studied are the ecosystem of such illicit promotions, including the obfuscated contacts advertised through those images, compromised accounts used to disseminate them, and large APPI campaigns involving thousands of images. Another interesting finding is the apparent attempt made by cybercriminals to steal others' images for their advertising. The study highlights the importance of the research on real-world adversarial learning and makes the first step towards mitigating the threats it poses. Kan Yuan, Di Tang 0001, Xiaojing Liao, XiaoFeng Wang 0001, Xuan Feng 0005, Yi Chen 0024, Menghan Sun, Kehuan Zhang |
IEEE Symposium on Security and Privacy | 6 |
| 2019 | Devils in the Guidance: Predicting Logic Vulnerabilities in Payment Syndication Services through Automated Documentation Analysis
Yi Chen 0024, Luyi Xing, Xiaojing Liao, XiaoFeng Wang 0001, Kai Chen 0012 |
USENIX Security Symposium | 1 |
| 2017 | Mass Discovery of Android Traffic Imprints through Instantiated Partial ExecutionabstractMonitoring network behaviors of mobile applications, controlling their resource access and detecting potentially harmful apps are becoming increasingly important for the security protection within today's organizational, ISP and carriers. For this purpose, apps need to be identified from their communication, based upon their individual traffic signatures (called imprints in our research). Creating imprints for a large number of apps is nontrivial, due to the challenges in comprehensively analyzing their network activities at a large scale, for millions of apps on today's rapidly-growing app marketplaces. Prior research relies on automatic exploration of an app's user interfaces (UIs) to trigger its network activities, which is less likely to scale given the cost of the operation (at least 5 minutes per app) and its effectiveness (limited coverage of an app's behaviors). Yi Chen 0024, Wei You 0001, Yeonjoon Lee, Kai Chen 0012, XiaoFeng Wang 0001 |
CCS | 1 |
| 2016 | Following Devil's Footprints: Cross-Platform Analysis of Potentially Harmful Libraries on Android and iOSabstractIt is reported recently that legitimate libraries are repackaged for propagating malware. An in-depth analysis of such potentially-harmful libraries (PhaLibs), however, has never been done before, due to the challenges in identifying those libraries whose code can be unavailable online (e.g., removed from the public repositories, spreading underground, etc.). Particularly, for an iOS app, the library it integrates cannot be trivially recovered from its binary code and cannot be analyzed by any publicly available anti-virus (AV) systems. In this paper, we report the first systematic study on PhaLibs across Android and iOS, based upon a key observation that many iOS libraries have Android versions that can potentially be used to understand their behaviors and the relations between the libraries on both sides. To this end, we utilize a methodology that first clusters similar packages from a large number of popular Android apps to identify libraries, and strategically analyze them using AV systems to find PhaLibs. Those libraries are then used to search for their iOS counterparts within Apple apps based upon the invariant features shared cross platforms. On each discovered iOS PhaLib, our approach further identifies its suspicious behaviors that also appear on its Android version and uses the AV system on the Android side to confirm that it is indeed potentially harmful. Running our methodology on 1.3 million Android apps and 140,000 popular iOS apps downloaded from 8 markets, we discovered 117 PhaLibs with 1008 variations on Android and 23 PhaLibs with 706 variations on iOS. Altogether, the Android PhaLibs is found to infect 6.84% of Google Play apps and the iOS libraries are embedded within thousands of iOS apps, 2.94% among those from the official Apple App Store. Looking into the behaviors of the PhaLibs, not only do we discover the recently reported suspicious iOS libraries such as mobiSage, but also their Android counterparts and 6 other back-door libraries never known before. Those libraries are found to contain risky behaviors such as reading from their host apps' keychain, stealthily recording audio and video and even attempting to make phone calls. Our research shows that most Android-side harmful behaviors have been preserved on their corresponding iOS libraries, and further identifies new evidence about libraries repackaging for harmful code propagations on both sides. Kai Chen 0012, Xueqiang Wang, Yi Chen 0024, Peng Wang 0088, Yeonjoon Lee, XiaoFeng Wang 0001, Bin Ma 0019, Aohui Wang |
IEEE Symposium on Security and Privacy | 3 |