Yiming Zhang 0009

dblp:76/5416-9 · DBLP profile ↗
← Back
23ranked-venue papers
3as first author
20since 2021 · last 2026
0000-0002-6774-5299ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 18 · 3 first-author · 16 since 2021Computer networks · 4 · 4 since 2021Artificial intelligence and machine learning · 1Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2026 Small Cell, Big Risk: A Security Assessment of 4G LTE Femtocells in the Wild
Yiming Zhang 0009, Tao Wan 0004, Hai-Xin Duan, Deliang Chang, Yishen Li, Shujun Tang
NDSS2
2026 Understanding the Status and Strategies of the Code Signing Abuse Ecosystem
Yiming Zhang 0009, Lingyun Ying, Mingming Zhang 0010, Baojun Liu 0002, Hai-Xin Duan, Zi-Quan You
NDSS2
2025 Dive into the Cloud: Unveiling the (Ab)Usage of Serverless Cloud Function in the Wild
abstract
Serverless cloud functions transfer server management responsibilities to service providers, offering scalability and cost-efficiency. This convenience not only facilitates normal activities but also raises abuse concerns. So far, public understanding of real-world cloud functions remains limited. To fill this gap, we conducted an in-depth measurement study to uncover their practical usage and abuse. Through empirical analysis of nine leading providers (e.g., AWS, Tencent), we identified 531,089 function domains from a passive DNS dataset spanning April 2022 to March 2024. We first investigated the usage status of serverless cloud functions, showing the different practices between providers. Additionally, based on active requests to these functions, we pointed out privacy risks of unauthorized access and identified four abuse types, including covert C2 communication, hosting malicious websites, promoting illicit services, and abusing egress nodes as IP proxies. Alarmingly, 4.89% of cloud functions are being abused, with over 614k invocations recorded. Only four abused functions were flagged by existing threat intelligence systems, indicating critical gaps in security monitoring for serverless environments. Our work offers insights into the serverless cloud ecosystem and provides recommendations for better management. With responsible disclosure, we hope to raise awareness and improve protective measures against abuses among cloud function providers.
Yijing Liu 0007, Mingxuan Liu 0006, Yiming Zhang 0009, Baojun Liu 0002, Jia Zhang 0004, Geng Hong, Hai-Xin Duan, Min Yang 0002
IMC3
2025 Chaos in the Chain: Evaluate Deployment and Construction Compliance of Web PKI Certificate Chain
abstract
Transport Layer Security (TLS) is a cornerstone to secure Internet communications. It requires proper deployment and validation of certificate chains. During validation, clients must first construct the chain from server-provided certificates. However, existing research often integrates chain construction into the broader validation process, lacking independent analysis of this crucial step. This paper presents the first systematic assessment of certificate chain construction, covering server-side deployment compliance and client-side capabilities. On the server side, we summarized structural requirements from RFC standards and evaluated real-world website compliance. We found that approximately 3% of Tranco Top 1M domains have deployed non-compliant chains, with common issues including reversed sequences and incomplete chains. The compliance would be influenced by HTTP server and Certificate Authority checks and guidance during the configuration process. On the client side, we evaluated 9 types of chain-building capabilities across 8 mainstream TLS implementations, uncovering prevalent deficiencies like inadequate backtracking and difficulties with long chains. These deficiencies could compromise TLS security, causing a fallback to insecure HTTP or making the service unavailable. Our findings highlight critical gaps in current certificate chain practices. Based on our findings, we also propose recommendations for improving the deployment and construction of certificate chains.
Yiming Zhang 0009, Baojun Liu 0002, Mingming Zhang 0010, Hai-Xin Duan
IMC2
2025 Analyzing Compliance and Complications of Integrating Internationalized X.509 Certificates
abstract
The global PKI supports the issuance of Unicerts, which are X.509 certificates that integrate internationalized content such as IDNs and multilingual text. This integration introduces complexity in Unicert issuance and usage. Past incidents showed that poor Unicode handling can cause security risks, including spoofing and remote code execution, yet threats specific to PKI and Unicerts remain underexplored. This paper presents the first large-scale study of Unicerts, examining both issuance and parsing compliance. By analyzing 34.8 million Unicerts from CT logs and 9 mainstream TLS libraries, we found the PKI ecosystem struggles with adopting Unicode. On the issuing side, 373 issuers produced 249.3K (0.72%) noncompliant Unicerts due to weak validation on character ranges, normalization, and formatting, of which 65.3% arise from publicly trusted CAs. These issues arise from overly complex standard requirements. On the parsing side, TLS libraries like GnuTLS and PyOpenSSL exhibited issues in decoding and handling special characters, such as incompatible decoding and improper escaping, which could lead to incorrect entity extraction or subfield forgery. We further empirically identified threat surfaces, including user spoofing, CT monitor misleading, and traffic obfuscation. Finally, we analyzed root causes and proposed recommendations to enhance Unicert compliance in the global PKI ecosystem.
Mingming Zhang 0010, Jinfeng Guo, Yiming Zhang 0009, Shenglin Zhang, Baojun Liu 0002, Xiang Li 0108, Hai-Xin Duan
IMC3
2025 Cross-Origin Web Attacks via HTTP/2 Server Push and Signed HTTP Exchange
Pinji Chen, Jianjun Chen 0005, Mingming Zhang 0010, Qi Wang 0094, Yiming Zhang 0009, Hai-Xin Duan
NDSS5
2025 Automatic Insecurity: Exploring Email Auto-configuration in the Wild
Shushang Wen, Yiming Zhang 0009, Yuxiang Shen, Bingyu Li 0003, Hai-Xin Duan, Jingqiang Lin 0001
NDSS2
2025 Invade the Walled Garden: Evaluating GTP Security in Cellular Networks
abstract
Cellular backhaul and core networks have traditionally been considered as Walled Garden, with their security ensured by physical isolation. Therefore, prior security studies primarily focused on radio access networks with limited treatment of backhaul and core network interfaces. In this paper, we performed a security evaluation of real-world GPRS Tunnelling Protocol (GTP) deployments. GTP is the fundamental protocol for user traffic management between base stations and core networks (inside the Walled Garden) from 3G to 5G, thus often assumed inaccessible and non-exploitable from the Internet. However, our study reveals for the first time the troubling state of GTP access control in real-world deployments. Aided by a semi-automated tool, our measurements discovered around 749,000 valid GTP hosts accessible via the public Internet, spanning across 1,176 service providers in 162 countries. Our results demonstrate potential exposure of mobile core network infrastructures to external threats. We then evaluated the attack surface of exposed GTP infrastructures, and found out that as many as 38 types of GTP messages can be misused to launch various attacks such as denial-of-service and session hijacking. Our experiments using open source 4G and 5G projects in isolated lab environments further confirm the feasibility of those GTP-based attacks, including remote hijacking of user traffic sent through cellular core networks. In addition to threats against cellular networks and their subscribers, exposed GTP devices could also be weaponized to launch large-scale reflective denial-of-services (RDoS) attacks. We hope our findings will increase awareness of GTP vulnerabilities among operators and the security community, highlighting the urgent need to further strengthen security in cellular core networks.
Yiming Zhang 0009, Tao Wan 0004, Hai-Xin Duan, Jianjun Chen 0005, Zixiang Wei, Xiang Li 0108
SP1
2025 NOKEScam: Understanding and Rectifying Non-Sense Keywords Spear Scam in Search Engines
Mingxuan Liu 0006, Lijie Wu, Baojun Liu 0002, Geng Hong, Yiming Zhang 0009, Jia Zhang 0004, Hai-Xin Duan, Min Zhang 0054, Fan Shi 0003, Min Yang 0002
USENIX Security Symposium6
2024 Understanding the Implementation and Security Implications of Protective DNS Services
Mingxuan Liu 0006, Yiming Zhang 0009, Xiang Li 0108, Chaoyi Lu, Baojun Liu 0002, Hai-Xin Duan
NDSS2
2024 Tickets or Privacy? Understand the Ecosystem of Chinese Ticket Grabbing Apps
Yijing Liu 0007, Yiming Zhang 0009, Baojun Liu 0002, Hai-Xin Duan, Mingxuan Liu 0006, Ruixuan Li 0008
USENIX Security Symposium2
2024 Into the Dark: Unveiling Internal Site Search Abused for Black Hat SEO
Mingxuan Liu 0006, Baojun Liu 0002, Yiming Zhang 0009, Hai-Xin Duan, Min Zhang 0054, Fan Shi 0003
USENIX Security Symposium4
2024 Uncovering Security Vulnerabilities in Real-world Implementation and Deployment of 5G Messaging Services
abstract
5G messaging services, based on Global System for Mobile Communications Association (GSMA) Rich Communication Service (RCS) and 3rd Generation Partnership Project (3GPP) IP Multimedia Subsystem (IMS), have been deployed globally by more than 90 mobile operators serving over 421 million monthly active users via 1.2 billion devices. Despite the widespread use, security research of 5G messaging remains sparse. In this paper, we present a comprehensive security analysis and measurement of 5G messaging services, assisted by a semi-automated testing tool we developed. We considered both carrier-side deployment and phone-side software implementations by testing against three large operators, each with hundreds of millions of subscribers, and six popular 5G messaging-enabled devices. We uncovered 4 categories of vulnerabilities, allowing for a wide range of attacks, including Man-In-The-Middle (MITM) attacks, zero-click remote information leakage, phone storage exhaustion and mobile data consumption, and Denial-of-Services (DoS) attacks. Our study underscores the need for further security enhancements in security specifications, implementation, and deployment of 5G messaging services.
Yiming Zhang 0009, Tao Wan 0004, Chuhan Wang 0001, Hai-Xin Duan, Jianjun Chen 0005, Yishen Li
WISEC2
2023 Automatic Generation of Adversarial Readable Chinese Texts
abstract
Natural language processing (NLP) models are known vulnerable to adversarial examples, similar to image processing models. Studying adversarial texts is an essential step to improve the robustness of NLP models. However, existing studies mainly focus on generating adversarial texts for English, with no prior knowledge that whether those attacks could be applied to Chinese. After analyzing the differences between Chinese and English, we propose a novel adversarial Chinese text generation solution Argot, by utilizing the method for adversarial English examples and several novel methods developed on Chinese characteristics. Argot could effectively and efficiently generate adversarial Chinese texts with good readability in both white-box and black-box settings. Argot could also automatically generatetargetedChinese adversarial texts, achieving a high success rate and ensuring the readability of the generated texts. Furthermore, we apply Argot to the spam detection task in both local detection models and a public toxic content detection system from a well-known security company. Argot achieves a relatively high bypass success rate with fluent readability, which proves that the real-world toxic content detection system is vulnerable to adversarial example attacks. We also evaluate some available defense strategies, and the results indicate that Argot can still achieve high attack success rates.
Mingxuan Liu 0006, Yiming Zhang 0009, Chao Zhang 0008, Zhou Li 0001, Qi Li 0002, Hai-Xin Duan, Donghong Sun
IEEE Trans. Dependable Secur. Comput.3
2022 Exploring the Characteristics and Security Risks of Emerging Emoji Domain Names
Mingxuan Liu 0006, Yiming Zhang 0009, Baojun Liu 0002, Hai-Xin Duan
ESORICS (3)2
2022 Measuring the Deployment of 5G Security Enhancement
abstract
The fifth-generation(5G) cellular network is entering an era of rapid development. Not only is 5G supposed to be fast, it also offers enhanced security based on 5G security specifications developed by the 3rd Generation Partnership Project (3GPP). However, little is known about 5G security in real world deployment. This paper analyzes 5G security features and measures their implementation in commercial 5G networks. By collecting and analyzing signaling messages between a cell phone and several commercial 5G networks, we measured multiple aspects of 5G security in real world deployment including, crypto algorithms used in the control plane, user plane (UP) security activation, subscriber identifier protection, and initial None-Access Stratum(NAS) message protection. We evaluated the compliance of commercial 5G networks with 5G security specifications. The results show that major discrepancy exists between 5G security standards and real world deployment, especially in the areas of UP protection and subscriber identifier protection. Therefore, well-known security risks, such as user data leakage, location exposure and Denial-of-Service(DoS) attacks, still apply to 5G commercial networks.
Shiyue Nie, Yiming Zhang 0009, Tao Wan 0004, Hai-Xin Duan
WISEC2
2021 Detecting and Characterizing SMS Spearphishing Attacks
abstract
Although spearphishing is a well-known security issue and has been widely researched, it is still an evolving threat with emerging forms. In recent years, Short Message Service (SMS) has been revealed as a new distribution channel for spearphishing messages, which already has caused a serious impact in the real world, but has not yet attracted enough attention from the academic community. In this paper, we report the first systemic study to spotlight this emerging threat, SMS spearphishing attack. Through cooperating with a leading security vendor, we obtain 31.96M real-world spam messages that span three months. We design and implement a novel NLP-based detection algorithm, and uncover 90,801 spearphishing messages on the entire dataset. And then, a large-scale measurement was performed on the detected messages to reveal and understand the characteristics of SMS spearphishing attack. Our findings are multi-fold. We discover that SMS spearphishing has a significant negative impact on the real-world, and a large number of victims have been affected. And the distribution of active illicit types between spearphishing message and common spam is quite inconsistent. At the micro-level, to evade detection and increase the probability of success, adversary campaigns have evolved a set of sophisticated strategies. Our research highlights the impact of SMS spearphishing attack is prominent. We call on different communities to work together to mitigate this emerging security threat.
Mingxuan Liu 0006, Yiming Zhang 0009, Baojun Liu 0002, Zhou Li 0001, Hai-Xin Duan, Donghong Sun
ACSAC2
2021 Rusted Anchors: A National Client-Side View of Hidden Root CAs in the Web PKI Ecosystem
abstract
HTTPS secures communications in the web and heavily relies on the Web PKI for authentication. In the Web PKI, Certificate Authorities (CAs) are organizations that provide trust and issue digital certificates. Web clients rely on public root stores maintained by operating systems or browsers, with hundreds of audited CAs as trust anchors. However, as reported by security incidents, hidden root CAs beyond the public root programs have been imported into local root stores, which allows adversaries to gain trust from web clients.
Yiming Zhang 0009, Baojun Liu 0002, Chaoyi Lu, Zhou Li 0001, Hai-Xin Duan, Zaifeng Zhang
CCS1
2021 On Evaluating Delegated Digital Signing of Broadcasting Messages in 5G
abstract
In 5G networks, base stations, namely gNBs (5G NodeB, as per 3GPP nomenclature) periodically broadcast the system information messages including network identifiers to facilitate User Equipment (UE) to connect to the network. As in prior generations, the system information messages in 5G are transmitted in clear text without any security protection. Therefore, an adversary could spoof a legitimate gNB to become a man-on-the-side (MOTS) or man-in-the-middle (MITM) attacker. This vulnerability is being studied by 3GPP and a number of solutions have been proposed in the Technical Report (TR 33.809), including a promising solution namely Digital Signing Network Function (DSnF). In this paper, we provided an evaluation of DSnF, including the practicality of its assumption, feasibility of its certificate trans-mission within the system information message, and quantitative analysis of its performance. Our evaluation results show that DSnF is practical in general. Initial results from this paper have been provided to 3GPP and incorporated into TR 33.809.
Yiming Zhang 0009, Tao Wan 0004, Jia Zhang 0004, Hai-Xin Duan
GLOBECOM2
2021 From WHOIS to WHOWAS: A Large-Scale Measurement Study of Domain Registration Privacy under the GDPR
Chaoyi Lu, Baojun Liu 0002, Yiming Zhang 0009, Zhou Li 0001, Fenglu Zhang, Hai-Xin Duan, Ying Liu 0024, Joann Qiongna Chen, Jinjin Liang, Zaifeng Zhang, Shuang Hao 0001, Min Yang 0002
NDSS3
2020 Lies in the Air: Characterizing Fake-base-station Spam Ecosystem in China
abstract
Fake base station (FBS) has been exploited by criminals to attack mobile users by spamming fraudulent messages for over a decade. Despite that prior work has proposed several techniques to mitigate this issue, FBS spam is still a long-standing challenging issue in some countries, such as China, and causes billions of dollars of financial loss every year. Therefore, understanding and exploring the thematic strategies in the FBS spam ecosystem at a large scale would improve the defense mechanisms.
Yiming Zhang 0009, Baojun Liu 0002, Chaoyi Lu, Zhou Li 0001, Hai-Xin Duan, Shuang Hao 0001, Mingxuan Liu 0006, Ying Liu 0024
CCS1
2020 Argot: Generating Adversarial Readable Chinese Texts
abstract
Natural language processing (NLP) models are known vulnerable to adversarial examples, similar to image processing models. Studying adversarial texts is an essential step to improve the robustness of NLP models. However, existing studies mainly focus on analyzing English texts and generating adversarial examples for English texts. There is no work studying the possibility and effect of the transformation to another language, e.g, Chinese. In this paper, we analyze the differences between Chinese and English, and explore the methodology to transform the existing English adversarial generation method to Chinese. We propose a novel black-box adversarial Chinese texts generation solution Argot, by utilizing the method for adversarial English samples and several novel methods developed on Chinese characteristics. Argot could effectively and efficiently generate adversarial Chinese texts with good readability. Furthermore, Argot could also automatically generate targeted Chinese adversarial text, achieving a high success rate and ensuring readability of the Chinese.
Mingxuan Liu 0006, Chao Zhang 0008, Yiming Zhang 0009, Zhou Li 0001, Qi Li 0002, Hai-Xin Duan, Donghong Sun
IJCAI4
2019 TraffickStop: Detecting and Measuring Illicit Traffic Monetization Through Large-Scale DNS Analysis
abstract
Illicit traffic monetization is a type of Internet fraud that hijacks users' web requests and reroutes them to a traffic network (e.g., advertising network), in order to unethically gain monetary rewards. Despite its popularity among Internet fraudsters, our understanding of the problem is still limited. Since the behavior is highly dynamic (can happen at any place including client-side, transport-layer and server-side) and selective (could target a regional network), prior approaches like active probing can only reveal a small piece of the entire ecosystem. So far, questions including how this fraud works at a global scale and what fraudsters' preferred methods are, still remain unanswered. To fill the missing pieces, we developed TraffickStop the first system that can detect this fraud passively. Our key contribution is a novel algorithm that works on large-scale DNS logs and efficiently discovers abnormal domain correlations. TraffickStop enables the first landscape study of this fraud, and we have some interesting findings. By analyzing over 231 billion DNS logs of two weeks, we discovered 1,457 fraud sites. Regarding its scale, the fraud sites receive more than 53 billion DNS requests within one year, and a company could lose up to 53K dollars per day due to fraud traffic. We also discovered two new strategies that are leveraged by fraudsters to evade inspection. Our work provides new insights into illicit traffic monetization, raises its public awareness, and contributes to a better understanding and ultimate elimination of this threat.
Baojun Liu 0002, Zhou Li 0001, Peiyuan Zong, Chaoyi Lu, Hai-Xin Duan, Ying Liu 0024, Sumayah A. Alrwais, XiaoFeng Wang 0001, Shuang Hao 0001, Yaoqi Jia, Yiming Zhang 0009, Kai Chen 0012, Zaifeng Zhang
EuroS&P11