VLDB 2026 Research / reviewers in the wild / expert
Yue Li 0002
dblp:61/500-2
· DBLP profile ↗
16ranked-venue papers
8as first author
8since 2021 · last 2025
0000-0001-7682-811XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 4 first-author · 5 since 2021Computer networks · 6 · 4 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | When LLMs Copy to Think: Uncovering Copy-Guided Attacks in Reasoning LLMsabstractLarge Language Models (LLMs) have become integral to automated code analysis, enabling tasks such as vulnerability detection and code comprehension. However, their integration introduces novel attack surfaces. In this paper, we identify and investigate a new class of prompt-based attacks, termed Copy-Guided Attacks (CGA), which exploit the inherent copying tendencies of reasoning-capable LLMs. By injecting carefully crafted triggers into external code snippets, adversaries can induce the model to replicate malicious content during inference. This behavior enables two classes of vulnerabilities: inference length manipulation, where the model generates abnormally short or excessively long reasoning traces; and inference result manipulation, where the model produces misleading or incorrect conclusions. We formalize CGA as an optimization problem and propose a gradient-based approach to synthesize effective triggers. Empirical evaluation on state-of-the-art reasoning LLMs shows that CGA reliably induces infinite loops, premature termination, false refusals, and semantic distortions in code analysis tasks. While highly effective in targeted settings, we observe challenges in generalizing CGA across diverse prompts due to computational constraints, posing an open question for future research. Our findings expose a critical yet underexplored vulnerability in LLM-powered development pipelines and call for urgent advances in prompt-level defense mechanisms. Yue Li 0002, Xiao Li 0082, Hao Wu 0067, Yue Zhang 0025, Fengyuan Xu, Xiuzhen Cheng, Sheng Zhong 0002 |
MASS | 1 |
| 2025 | Make a Feint to the East While Attacking in the West: Blinding LLM-Based Code Auditors with Flashboom AttacksabstractLLM-based vulnerability auditors (e.g., GitHub Copilot) represent a significant advancement in automated code analysis, offering precise detection of security vulnerabilities. This paper explores the potential to circumvent LLM-based vulnerability auditors by diverting their focus, decided by the LLM attention mechanism, away from real vulnerable code segments. In these LLM-based vulnerability auditors, the attention mechanism is supposed to focus on potentially vulnerable code sections to identify security issues. Our approach introduces high-attention code snippets (code fragments designed to draw focus) into the codebase under review. By strategically diverting the model's focus away from actual vulnerabilities, this technique effectively “blinds” the LLM, resulting in missed detections. To scale this approach, we present Crazy-Ivan11Source code, dataset and attack results are available at https://github.com/oxygen-hunter/Flashboom., an automated system that identifies and seamlessly integrates high-attention code snippets, shifting focus away from genuine vulnerabilities to decoy functions. Through systematic function-level prioritization and refinement, Crazy-Ivan optimizes the blinding effect, producing the Flashboom that can reduce the model's capacity to detect true security risks. Our evaluation underscores the effectiveness of Flashboom, achieving blinding success rates of up to 96.3% on CodeLlama and 83.05% on Gemma, with notable cross-model transferability and applicability across multiple programming languages. In a case study with GitHub Copilot, Flashboom led the tool to overlook a critical blockchain vulnerability, underscoring the security implications of such attention-diverting attacks and the risks inherent in relying solely on LLM-based automated auditing systems. We have reported our findings to the respective LLM-based code auditor vendors, who have acknowledged the issues and are currently working on fixes. Xiao Li 0082, Yue Li 0002, Hao Wu 0067, Yue Zhang 0025, Kaidi Xu, Xiuzhen Cheng, Sheng Zhong 0002, Fengyuan Xu |
SP | 2 |
| 2025 | OPRE: Towards Better Availability of PCNs Through RecoveringabstractThe Payment Channel Network (PCN) stands out as one of the most promising technologies for scaling blockchain-based cryptocurrencies. However, a noteworthy challenge arises during the utilization of PCNs, where a substantial portion of payment channels gradually becomes exhausted, leading to a reduction in the overall availability of PCNs. This issue is crucial in the context of blockchain off-chain PCNs and warrants a comprehensive investigation. In this paper, we introduce the problem of optimal recover and propose OPtimal REcovering protocols, denoted asOPREandOPRE+, to address this challenge. The protocols target at recovering the optimal number of nearly exhausted channels in the PCN. OPRE provides a basic solution, and OPRE+ is an augmentation which provides a more efficient and effective solution. Furthermore, to address users’ privacy concerns, we propose privacy-preserving versions of the protocols, ensuring that users’ balance on payment channels remains undisclosed during the execution of the protocols. Beyond the theoretical design and analysis, we implement these protocols and conduct experimental evaluations to assess their performance. The results affirm that our protocols exhibit efficiency and effectiveness in significantly improving the availability of PCNs. Minze Xu, Yue Li 0002, Chenglu Shi, Yuan Zhang 0004, Yongchuan Niu, Fengyuan Xu, Sheng Zhong 0002 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | vTrust: Remotely Executing Mobile Apps Transparently With Local Untrusted OSabstractIncreasingly, many security and privacy sensitive applications (apps for short) are running in the mobile platforms. However, as the mobile operating systems are becoming increasingly sophisticated, they are vulnerable to various attacks. In addressing the need of running high assurance mobile apps in a secure environment even though the operating systems are untrusted, this paper presents VTRUST, a new mobile app trusted execution environment, which offloads the general execution and storage of a mobile app to a trusted remote server (e.g., a VM running in a cloud) and secures the I/O between the server and the mobile device with the aid of a trusted hypervisor on the mobile device. Specifically, VTRUST establishes an encrypted I/O channel between the local hypervisor and the remote server, such that any sensitive data flowing through the mobile OS, which is hosted by the hypervisor, is encrypted from the perspective of the local mobile OS. To enhance the performance of VTRUST, we have also designed multiple optimizations, such as output data compression and selective sensor data transmission. We have implemented VTRUST and our evaluation shows that it has limited impact on both user experience and the app performance. Yutao Tang, Zhengrui Qin, Zhiqiang Lin 0001, Yue Li 0002, Shanhe Yi, Fengyuan Xu, Qun Li 0001 |
IEEE Trans. Computers | 4 |
| 2022 | Understanding Account Recovery in the Wild and its Security ImplicationsabstractAccount recovery (usually through a password reset) on many websites has mainly relied on accessibility to a registered email, due to its favorable deployability and usability. However, it makes a user's online accounts vulnerable to a single point of failure when the registered email account is compromised. While previous research focuses on strengthening user passwords, the security risk imposed by email-based password recovery has not yet been well studied. In this article, we first conduct a measurement study to characterize the password recovery activities in the wild. Specifically, we examine the authentication and password recovery protocols from 239 traffic-heavy websites, confirming that most of them use emails for password recovery. We further scrutinize the security policy of leading email service providers and show that a significant portion of them takes no or marginal effort to protect user email accounts, leaving compromised email accounts readily available for mounting password recovery attacks. Then, we conduct case studies to assess potential losses caused by such attacks. Finally, we propose and implement a lightweight email security enhancement called Secure Email Account Recovery (SEAR) to defend against password recovery attacks by adding an extra layer of protection to password recovery emails. Yue Li 0002, Haining Wang 0001, Kun Sun 0001, Sushil Jajodia |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | UTrack: Enterprise User Tracking Based on OS-Level Audit LogsabstractTracking user activities inside an enterprise network has been a fundamental building block for today's security infrastructure, as it provides accurate user profiling and helps security auditors to make informed decisions based on the derived insights from the abundant log data. Towards more accurate user tracking, we propose a novel paradigm named UTrack by leveraging rich system-level audit logs. From a holistic perspective, we bridge the semantic gap between user accounts and real users, tracking a real user's activities across different user accounts and different network hosts based on causal relationship among processes. To achieve better scalability and a more salient view, we apply a variety of data reduction and compression techniques to process the large amount of data. %and significantly reduce the data volume. We implement UTrack in a real enterprise environment consisting of 111 hosts, which generate more than 4 billion events in total during the experiment time of one month. Through our evaluation, we demonstrate that UTrack is able to accurately identify the events that are relevant to user activities. Our data reduction and compression modules largely reduce the output data size, producing a both accurate and salient overview on a user session profile. Yue Li 0002, Zhenyu Wu 0003, Haining Wang 0001, Kun Sun 0001, Zhichun Li, Kangkook Jee, Junghwan Rhee |
CODASPY | 1 |
| 2021 | Remotely controlling TrustZone applications?: a study on securely and resiliently receiving remote commandsabstractMobile devices are becoming an indispensable part of work for corporations and governments to store and process sensitive information. Thus, it is important for remote administrators to maintain control of these devices via Mobile Device Management (MDM) solutions. ARM TrustZone has been widely regarded as the de facto solution for protecting the security-sensitive software, such as MDM agents, from attacks of a compromised rich OS. However, little attention has been given to protecting the MDM control channel, a fundamental component for a remote administrator to invoke the TrustZone-based MDM agents and perform specific management operations. In this work, we design an ARM TrustZone-based network mechanism, called TZNIC, towards enabling resilient and secure access to TrustZone-based software, even in the presence of a malicious rich OS. TZNIC deploys two NIC drivers, one secure-world driver and one normal-world driver, multiplexing one physical NIC. We utilize the ARM TrustZone-based high privilege to protect the secure-world driver and further resolve several challenges on sharing one set of hardware peripherals between two isolated software environments. TZNIC does not require any changes or collaboration of the rich OS. We implement a prototype of TZNIC, and the evaluation results show that TZNIC can provide a reliable network channel to invoke the security software in the secure world, with minimal system overhead on the rich OS. Shengye Wan, Kun Sun 0001, Ning Zhang 0017, Yue Li 0002 |
WISEC | 4 |
| 2021 | User input enrichment via sensing devices
Yutao Tang, Yue Li 0002, Qun Li 0001, Kun Sun 0001, Haining Wang 0001, Zhengrui Qin |
Comput. Networks | 2 |
| 2019 | PathMarker: protecting web contents against inside crawlersabstractWeb crawlers have been misused for several malicious purposes such as downloading server data without permission from the website administrator. Moreover, armoured crawlers are evolving against new anti-crawler mechanisms in the arm races between crawler developers and crawler defenders. In this paper, based on one observation that normal users and malicious crawlers have different short-term and long-term download behaviours, we develop a new anti-crawler mechanism called PathMarker to detect and constrain persistent distributed crawlers. By adding a marker to each Uniform Resource Locator (URL), we can trace the page that leads to the access of this URL and the user identity who accesses this URL. With this supporting information, we can not only perform more accurate heuristic detection using the path related features, but also develop a Support Vector Machine based machine learning detection model to distinguish malicious crawlers from normal users via inspecting their different patterns of URL visiting paths and URL visiting timings. In addition to effectively detecting crawlers at the earliest stage, PathMarker can dramatically suppress the scraping efficiency of crawlers before they are detected. We deploy our approach on an online forum website, and the evaluation results show that PathMarker can quickly capture all 6 open-source and in-house crawlers, plus two external crawlers (i.e., Googlebots and Yahoo Slurp). Shengye Wan, Yue Li 0002, Kun Sun 0001 |
Cybersecur. | 2 |
| 2018 | Email as a Master Key: Analyzing Account Recovery in the WildabstractAccount recovery (usually through a password reset) on many websites has mainly relied on accessibility to a registered email due to its favorable deployability and usability. However, it makes a user's online accounts vulnerable to a single point of failure when the registered email account is compromised. While previous research focuses on strengthening user passwords, the security risk imposed by email-based account recovery has not yet been well studied. In this paper, we investigate the possibility of mounting an email-based account recovery attack. Specifically, we examine the account authentication and recovery protocols in 239 traffic-heavy websites, confirming that most of them use emails for account recovery. We further scrutinize the security policy of major email service providers and show that a significant portion of them take no or marginal effort to protect user email accounts, leaving compromised email accounts readily available for mounting account recovery attacks. Then, we conduct case studies to assess potential losses caused by such attacks. Finally, we propose a lightweight email security enhancement called Secure Email Account Recovery (SEAR) to defend against account recovery attacks as an extra layer of protection to account recovery emails. Yue Li 0002, Haining Wang 0001, Kun Sun 0001 |
INFOCOM | 1 |
| 2017 | A measurement study on Amazon wishlist and its privacy exposureabstractUser preference plays an important factor in E-commerce websites for advertising and marketing, and the disclosure of user preference could also raise privacy concerns. As one of the largest E-commerce platform, Amazon features a wishlist that allows users to keep track of their desired products. In this paper, we investigate Amazon wishlist, and its possible privacy exposure. To this end, we collect complete wishlists of over 30,000 users, by analyzing which we are able to make interesting observations based on user online shopping preference in multiple dimensions. Specifically, we show user preference variation from different demographical groups, including gender and geo-locations. Taking timing factors into consideration, we also observe that unlike traditional walk-in-shop type of shopping, there is no significant difference in the dynamics of Amazon wishlists between weekdays and weekend. In the investigation of user information exposure in Amazon wishlists, we parse and analyze list-descriptions, illustrating which and to what extent user personal information is exposed to the public. Finally, we demonstrate that the information in wishlists has potential to leak a user's private personal information. Based on the collected user data, we can predict user gender with over 80% accuracy by just exploiting items present in Amazon wishlists. Yue Li 0002, Haining Wang 0001, Kun Sun 0001 |
ICC | 1 |
| 2017 | Protecting web contents against persistent distributed crawlersabstractWeb crawlers have been misused for several malicious purposes such as downloading server data without permission from the website administrator. In this paper, based on one observation that normal users and malicious crawlers have different short-term and long-term download behaviors, we develop a new anti-crawler mechanism called PathMarker to detect and constrain persistent distributed crawlers. For each URL, by adding a marker to record its parent page that leads to the access to this URL and the user identity who accesses this URL, we can not only perform more accurate heuristic detection and Support Vector Machine (SVM) based machine learning detection to detect malicious crawlers at an earlier stage, but also dramatically suppress the efficiency of crawlers before they are detected. We deploy our approach on a forum website, and the evaluation results show that PathMarker can quickly capture all 6 open-source and in-house crawlers. Shengye Wan, Yue Li 0002, Kun Sun 0001 |
ICC | 2 |
| 2017 | BluePass: A Secure Hand-Free Password Manager
Yue Li 0002, Haining Wang 0001, Kun Sun 0001 |
SecureComm | 1 |
| 2017 | Personal Information in Passwords and Its Security ImplicationsabstractWhile it is not recommended, Internet users tend to include personal information in their passwords for easy memorization. However, the use of personal information in passwords and its security implications have yet to be studied. In this paper, we dissect user passwords from several leaked data sets to investigate the extent to which a user's personal information resides in a password. Then, we introduce a new metric called coverage to quantify the correlation between passwords and personal information. Afterward, based on our analysis, we extend the probabilistic context-free grammars (PCFGs) method to be semantics-rich and propose personal-PCFG to crack passwords by generating personalized guesses. Through offline and online attack scenarios, we demonstrate that personal-PCFG cracks passwords much faster than PCFG and makes online attacks much more likely to succeed. To defend against such semantics-aware attacks, we examine the use of simple distortion functions that are chosen by users to mitigate unwanted correlation between personal information and passwords. Yue Li 0002, Haining Wang 0001, Kun Sun 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2016 | Amnesia: A Bilateral Generative Password ManagerabstractWhile numerous flaws have been recognized in using passwords as a method of authentication, passwords still remain the de-facto authentication standard in use today. Though password managers can ameliorate password fatigue, the vast majority of password managers require the user to choose and maintain a strong master password while offering little to no recourse in the event that the master password is compromised. The wide-application of cloud-based password managers congregate passwords in an encrypted database, which becomes an attractive target for attackers and also represents a single point of failure. In this paper, we propose Amnesia, a bilateral generative password manager that requires both the knowledge of the master password and the possession of the user's smartphone to generate website passwords for the user. Our generative password manager is not vulnerable to the password database leakage, since it generates the requested password on demand using both the master password and the secret information on the smartphone. An attacker wishing to steal the user's website passwords has to compromise both the user's smartphone and the master password. Amnesia also has strong recovery capability when either the master password is compromised or the smartphone is lost/stolen. By using an Amnesia server, a user can have the access to the password manager on multiple computers without installing any software on those computers. We implemented an Amnesia system prototype using Android and Cherrypy web framework and evaluated it in terms of security, usability, and overhead. A user study of 31 testers shows that Amnesia increases password security while maintaining reasonable user convenience. Luren Wang, Yue Li 0002, Kun Sun 0001 |
ICDCS | 2 |
| 2016 | A study of personal information in human-chosen passwords and its security implicationsabstractThough not recommended, Internet users often include parts of personal information in their passwords for easy memorization. However, the use of personal information in passwords and its security implications have not yet been studied systematically in the past. In this paper, we first dissect user passwords from a leaked dataset to investigate how and to what extent user personal information resides in a password. In particular, we extract the most popular password structures expressed by personal information and show the usage of personal information. Then we introduce a new metric called Coverage to quantify the correlation between passwords and personal information. Afterwards, based on our analysis, we extend the Probabilistic Context-Free Grammars (PCFG) method to be semantics-rich and propose Personal-PCFG to crack passwords by generating personalized guesses. Through offline and online attack scenarios, we demonstrate that Personal-PCFG cracks passwords much faster than PCFG and makes online attacks much easier to succeed. Yue Li 0002, Haining Wang 0001, Kun Sun 0001 |
INFOCOM | 1 |