VLDB 2026 Research / reviewers in the wild / expert
Yue Xiao 0007
dblp:80/6791-7
· DBLP profile ↗
11ranked-venue papers
3as first author
10since 2021 · last 2025
0009-0005-7945-464XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 3 first-author · 10 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SaTS '25: The 3rd ACM Workshop on Security and Privacy of AI-Empowered Mobile Super AppsabstractMobile super apps, which bundle multiple mini-apps into a single platform, have become central to the consumer-facing digital ecosystem. Services such as WeChat, Alipay, Grab, and TikTok integrate payments, messaging, commerce, and entertainment, while at the same time collecting and processing large volumes of sensitive personal data. This concentration of functionality creates unprecedented opportunities to businesses and online services but also raises significant security and privacy risks. Meanwhile, a growing trend is the integration of large language models (LLMs) into mobile apps, transforming them into LLM-driven agentic systems. These systems are capable of orchestrating mini-apps and other mobile apps, interacting with external services, and carrying out privileged tasks on behalf of users. While this enables powerful new applications, it also expands the attack surface and introduces new forms of data exposure, misuse of privileges, and adversarial manipulation. The workshop seeks contributions including but not limited secure architectural design, permission frameworks, threat modeling, privacy-preserving methods, and case studies of real-world deployments in order to build a foundation for safer and more trustworthy LLM-empowered super apps and more generally mobile apps. Luyi Xing, Yue Xiao 0007 |
CCS | 2 |
| 2025 | JBomAudit: Assessing the Landscape, Compliance, and Security Implications of Java SBOMs
Yue Xiao 0007, Dhilung Kirat, Douglas Lee Schales, Jiyong Jang, Luyi Xing, Xiaojing Liao |
NDSS | 1 |
| 2025 | Automated Expansion of Privacy Data Taxonomy for Compliant Data Breach Notification
Yue Xiao 0007, Xiaojing Liao |
NDSS | 2 |
| 2024 | Understanding Legal Professionals' Practices and Expectations in Data Breach Incident ReportingabstractLegal professionals are essential in analyzing data breach incident reports and guiding the response to comply with data privacy laws and regulations. Their expertise helps mitigate privacy and security risks and prevents failures in privacy compliance. However, little research has been done to understand how legal professionals perceive, react to, and face challenges within the data breach incident reporting procedure. In this study, we conducted a simulated incident report assessment experiment and semi-structured interviews with 33 legal professionals who varied in age, gender, and legal background. We reported the criteria used by legal professionals to identify privacy-related items and also uncovered that the agreement among legal professionals on the concepts of privacy-related items is low. Furthermore, we presented findings regarding the perceptions and strategies of legal professionals concerning legal and regulatory compliance, as well as the key features of incident responses that facilitate efficient analysis of data privacy and security law compliance. After taking into account the challenges and suggestions provided by legal professionals, we concluded this study with recommendations for enhancing the effectiveness of legal compliance analysis for incident responses. Ece Gumusel, Yue Xiao 0007, Jiaxin Qin, Xiaojing Liao |
CCS | 2 |
| 2024 | Measuring Compliance Implications of Third-party Libraries' Privacy Label Disclosure GuidelinesabstractPrivacy label disclosure guideline, which specifies the data usage practices of third-party libraries (TPL), is a valuable resource for iOS app developers to accurately complete their iOS privacy labels. This is particularly important given the mandatory requirement for all apps on the App Store to disclose their data practices via privacy labels. However, it is essential to ensure the accuracy and compliance of these guidelines to ensure that accurate TPL data usage has been provided to app developers. Despite the significance of these guidelines, there is little understanding of how accurate and compliant they are in reflecting the actual data practices of third-party libraries used in iOS apps. To address this issue, our study implements a tool called Colaine to automatically check the compliance of privacy label disclosure guidelines, taking into account the configurable data practices in TPLs. Colaine analyzed 107 TPLs associated with 1,605 different configurations, shedding light on the prevalence and seriousness of privacy label disclosure guideline non-compliance issues. Yue Xiao 0007, Chaoqi Zhang 0006, Fares Fahad S. Alharbi, Luyi Xing, Xiaojing Liao |
CCS | 1 |
| 2024 | iHunter: Hunting Privacy Violations at Scale in the Software Supply Chain on iOS
Dexin Liu, Yue Xiao 0007, Chaoqi Zhang 0006, Kaitao Xie, Xiaolong Bai, Shikun Zhang, Luyi Xing |
USENIX Security Symposium | 2 |
| 2023 | Vulnerability Intelligence Alignment via Masked Graph Attention NetworksabstractCybersecurity vulnerability information is often sourced from multiple channels, such as government vulnerability repositories, individually maintained vulnerability-gathering platforms, or vulnerability-disclosure email lists and forums. Integrating vulnerability information from different channels enables comprehensive threat assessment and quick deployment to various security mechanisms. However, automatic integration of vulnerability information, especially those lacking decisive information (e.g., CVE-ID), is hindered by the limitations of today's entity alignment techniques. Yue Xiao 0007, Xiaojing Liao |
CCS | 2 |
| 2023 | Lalaine: Measuring and Characterizing Non-Compliance of Apple Privacy Labels
Yue Xiao 0007, Xiaolong Bai, Jiale Guan, Xiaojing Liao, Luyi Xing |
USENIX Security Symposium | 1 |
| 2022 | OS-Aware Vulnerability Prioritization via Differential Severity Analysis
Qiushi Wu, Yue Xiao 0007, Xiaojing Liao, Kangjie Lu |
USENIX Security Symposium | 2 |
| 2021 | Understanding Malicious Cross-library Data Harvesting on Android
Jice Wang, Yue Xiao 0007, Xueqiang Wang, Yuhong Nan, Luyi Xing, Xiaojing Liao, Jinwei Dong, XiaoFeng Wang 0001, Yuqing Zhang 0001 |
USENIX Security Symposium | 2 |
| 2020 | Demystifying Resource Management Risks in Emerging Mobile App-in-App EcosystemsabstractApp-in-app is a new and trending mobile computing paradigm in which native app-like software modules, called sub-apps, are hosted by popular mobile apps such as Wechat, Baidu, TikTok and Chrome, to enrich the host app's functionalities and to form an "all-in-one app" ecosystem. Sub-apps access system resources through the host, and their functionalities come close to regular mobile apps (taking photos, recording voices, banking, shopping, etc.). Less clear, however, is whether the host app, typically a third-party app, is capable of securely managing sub-apps and their access to system resources. In this paper, we report the first systematic study on the resource management in app-in-app systems. Our study reveals high-impact security flaws, which allow the adversary to stealthily escalate privilege (e.g., accessing the camera, photo gallery, microphone, etc.) or acquire sensitive data (e.g., location, passwords of Amazon, Google, etc.). To understand the impacts of those flaws, we developed an analysis tool that automatically assesses 11 popular app-in-app platforms on both Android and iOS. Our results brought to light the prevalence of the security flaws. We further discuss the lessons learned and propose mitigation strategies. Luyi Xing, Yue Xiao 0007, Yifan Zhang 0010, Xiaojing Liao, XiaoFeng Wang 0001, Xueqiang Wang |
CCS | 3 |