VLDB 2026 Research / reviewers in the wild / expert
Shuai Li 0006
dblp:57/2281-6
· DBLP profile ↗
6ranked-venue papers
4as first author
4since 2021 · last 2024
0000-0003-4593-7019ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 4 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Are We Getting Well-informed? An In-depth Study of Runtime Privacy Notice Practice in Mobile AppsabstractUnder the General Data Protection Regulation (GDPR), mobile app developers are required to inform users of necessary information at the time when user data is collected (called users' "Right-to-be-Informed"). This is typically done by app developers via providing runtime privacy notices (RPNs for short). However, given the heterogeneous privacy data types and data access patterns in modern apps, it is not clear to what extent apps (app developers) effectively fulfill this compliance requirement in practice. Shuai Li 0006, Zhemin Yang, Yuhong Nan, Shutian Yu, Qirui Zhu, Min Yang 0002 |
CCS | 1 |
| 2024 | Identifying Cross-User Privacy Leakage in Mobile Mini-Apps at a Large ScaleabstractWith the characteristics of free installation and rich functionalities, mobile mini-apps have become more and more popular in people’s daily life. A large amount of sensitive personal data is thus involved in them and shared across users for providing various services, which raises great privacy concerns. However, few researchers have paid attention to the potential privacy risks that may exist when user data is shared across users in mobile mini-apps. In this paper, we introduce a novel privacy risk that is brought forward by cross-user personal data over-delivery (denoted as XPO) in mobile mini-apps. Such a discovered privacy risk is demonstrated to be able to cause serious leakage of diverse user data. To detect XPO risk, a dynamic and lightweight mini-app analysis framework – XPOScope is proposed. XPOScope is able to automatically identify XPO risk at a large scale. By applying it to 4,273 mini-apps hosted on three popular platforms, i.e., WeChat, Baidu and Alipay, XPOScope reported 71 vulnerable ones, with a precision of 92.21% and a recall of 80.68%. In addition to the mere exposure of diverse private user data, case studies performed show that XPO in mini-apps can further lead to impersonation attacks, the infringement of employees’ privacy, economic loss and even the leakage of sensitive business secrets. The results call for the awareness and actions of mobile mini-app developers to secure cross-user personal data delivery. The code of this work is available at https://github.com/ppflower/XPOScope. Shuai Li 0006, Zhemin Yang, Yunteng Yang, Dingyi Liu, Min Yang 0002 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Notice the Imposter! A Study on User Tag Spoofing Attack in Mobile Apps
Shuai Li 0006, Zhemin Yang, Guangliang Yang 0001, Hange Zhang, Nan Hua, Yurui Huang, Min Yang 0002 |
USENIX Security Symposium | 1 |
| 2022 | Collect Responsibly But Deliver Arbitrarily?: A Study on Cross-User Privacy Leakage in Mobile AppsabstractRecent years have witnessed the interesting trend that modern mobile apps perform more and more likely as user-to-user platforms, where app users can be freely and conveniently connected. Upon these platforms, rich and diverse data is often delivered across users, which brings users great conveniences and plentiful services, but also introduces privacy security concerns. While prior work has primarily studied illegitimate personal data collection problems in mobile apps, few paid little attention to the security of this emerging user-to-user platform feature, thus providing a rather limited understanding of the privacy risks in this aspect. Shuai Li 0006, Zhemin Yang, Nan Hua, Peng Liu 0005, Xiaohan Zhang 0001, Guangliang Yang 0001, Min Yang 0002 |
CCS | 1 |
| 2020 | TextExerciser: Feedback-driven Text Input Exercising for Android ApplicationsabstractDynamic analysis of Android apps is often used together with an exerciser to increase its code coverage. One big obstacle in designing such Android app exercisers comes from the existence of text-based inputs, which are often constrained by the nature of the input field, such as the length and character restrictions.In this paper, we propose TextExerciser, an iterative, feedback-driven text input exerciser, which generates text inputs for Android apps. Our key insight is that Android apps often provide feedback, called hints, for malformed inputs so that our system can utilize such hints to improve the input generation.We implemented a prototype of TextExerciser and evaluated it by comparing TextExerciser with state-of-the-art exercisers, such as The Monkey and DroidBot. Our evaluation shows that TextExerciser can achieve significantly higher code coverage and trigger more sensitive behaviors than these tools. We also combine TextExerciser with dynamic analysis tools and show they are able to detect more privacy leaks and vulnerabilities with TextExerciser than with existing exercisers. Particularly, existing tools, under the help of TextExerciser, find several new vulnerabilities, such as one user credential leak in a popular social app with more than 10,000,000 downloads. Yuyu He 0001, Lei Zhang 0096, Zhemin Yang, Yinzhi Cao, Keke Lian, Shuai Li 0006, Wei Yang 0013, Zhibo Zhang 0006, Min Yang 0002, Yuan Zhang 0009, Hai-Xin Duan |
SP | 6 |
| 2018 | BAVP: Blockchain-Based Access Verification Protocol in LEO Constellation Using IBE KeysabstractLEO constellation has received intensive research attention in the field of satellite communication. The existing centralized authentication protocols traditionally used for MEO/GEO satellite networks cannot accommodate LEO satellites with frequent user connection switching. This paper proposes a fast and efficient access verification protocol named BAVP by combining identity-based encryption and blockchain technology. Two different key management schemes with IBE and blockchain, respectively, are investigated, which further enhance the authentication reliability and efficiency in LEO constellation. Experiments on OPNET simulation platform evaluate and demonstrate the effectiveness, reliability, and fast-switching efficiency of the proposed protocol. For LEO networks, BAVP surpasses the well-known existing solutions with significant advantages in both performance and scalability which are supported by theoretical analysis and simulation results. Songjie Wei, Shuai Li 0006, Peilong Liu |
Secur. Commun. Networks | 2 |