VLDB 2026 Research / reviewers in the wild / expert
Jun Ma 0010
dblp:91/4845-10
· DBLP profile ↗
22ranked-venue papers
8as first author
9since 2021 · last 2025
0000-0002-7896-3152ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 18 · 6 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 3 first-author · 2 since 2021Computer networks · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Optimizing Type Duplication in WebAssembly Module SplittingabstractWebAssembly has been widely used in numerous fields due to its near-native execution performance, compact size, and cross-platform compatibility. However, as WebAssembly applications become increasingly complex, the size of WebAssembly files and their initialization time have also increased. Existing work addresses this issue by splitting a WebAssembly module into multiple modules and loading them on demand. Nevertheless, the total size of the split modules suffers significant bloat, which consume more server and network resources. One of the reasons is redundant types, which, in particular, contribute significantly to this bloat after WebAssembly garbage collection feature was introduced, and such redundancy cannot be reduced under the current WebAssembly specification.In this work, we have developed a tool to optimize the size of split WebAssembly modules by replacing duplicate types in secondary modules with references to types in the primary module. The reduced secondary modules are recovered during loading for module instantiation. Our experiments show that our tool can effectively reduce the size of secondary modules, achieving an average reduction of over 20% when splitting into a large number of modules. In network environments with low throughput, it can reduce loading time by 16% to 18%. Xifan Xu, Jun Ma 0010, Chun Cao |
APSEC | 2 |
| 2025 | Leveraging Visible Widget Sizes for Detecting Repackaged Android AppsabstractAndroid currently holds a significant share of the mobile market.However, the repackaging of Android applications is a widespread issue.Attackers can use repackaging to crack applications, insert malicious code, and add or replace advertisements.This poses a serious threat to the Android ecosystem.As such, detecting repackaged applications is of great importance.Noticing that repackaged applications seldom modify the GUI of the original applications, in recent years, researchers have proposed a series of dynamic software birthmarks based on the runtime GUI of the application to detect repackaged applications.However, existing dynamic GUIbased software falls short in three areas: (1) unreliable GUI dumping channel, (2) sensitive to widget position, and (3) slow birthmark generation.To address these limits, in this paper, we propose Box-Droid.In summary, BoxDroid offers a more reliable GUI dumping channel by disregarding transparent widgets or layouts.Additionally, it significantly increases the speed of birthmark generation through a DFS exploration strategy.Finally, it generates birthmarks using the distribution of the bounding boxes of widgets in each layout encountered at runtime.We have evaluated BoxDroid on 499 repackaging pairs and it shows a precision of 0.955 and a recall of 0.926.BoxDroid also detected 1,441 undocumented repackaging pairs in a dataset sampled from the RePack repository. Jun Ma 0010, Chun Cao |
Internetware | 1 |
| 2024 | Actor of Things: Resilient and Efficient Distributed AIoT Applications in an Actor System
Tianqi Ren, Chun Cao, Jun Ma 0010 |
APSEC | 3 |
| 2024 | NEST: Node with Statistics Tree for IoT Data Persistence and Real-time QueriesabstractData persistence is a critical foundation for Internet of Things (IoT), it provides the capability of data collection from IoT devices and pulls out these data by queries for applications to consume. In most cases, both the relationship between devices and the metrics on devices are required, so polyglot persistence systems consisting of graph databases and time series databases are deployed for data persistence. However, as the scale of IoT device network continues to grow, polyglot persistence finds it hard to achieve the need of real-time queries demanded by query-bound applications like artificial intelligence in IoT, which is where multi-model database be proficient in. Jiahua Huang, Chun Cao, Jun Ma 0010, Xiaoxing Ma |
Internetware | 3 |
| 2024 | Understanding and Detecting Inefficient Image Displaying Issues in Android Apps
Jun Ma 0010, Yanyan Jiang 0001, Chang Xu 0001, Xiaoxing Ma |
J. Comput. Sci. Technol. | 2 |
| 2022 | AexPy: Detecting API Breaking Changes in Python PackagesabstractWith the popularity of the Python language, com-munity developers create and maintain a lot of third-party packages. APIs change frequently during the package evolving. Package developers need keeping backward compatibility of APIs to avoid breaking client code. Detecting breaking changes in Python packages is challenging because of Python's dynamic features and flexible designs, such as dynamic typing, API aliases, confusing public boundary and flexible argument passing. Despite the language's popularity, there have been few tools aiming to detect breaking changes, and existing approaches lack sufficient consideration of the mentioned challenges, resulting in imprecise and incomplete detection. Briefly, we propose an API-model-based systematic approach to address this problem. We design a Python-specific API model and classify API changes in different breaking levels. Based on the model, we obtain APIs with their types by a robust hybrid analysis and detect graded changes by checking constraints on API pairs. We implement a prototype, AexPy. Thanks to the more comprehensive model and hybrid analysis adopted, AexPy outperforms the state-of-the-art techniques for Python with an 86.9% recall on a dataset of 61 known breaking changes. Besides, AexPy detects 405 (manually verified) high and medium breaking changes with a precision of 93.5% on the latest versions of 45 packages. Specifically, in addition to 291 documented breaking changes, AexPy detects 114 undocumented changes. We report 63 undocumented breaking changes to active package developers, and 31 have been confirmed. Xingliang Du, Jun Ma 0010 |
ISSRE | 2 |
| 2022 | A Study on Screen Logging Risks of Secure Keyboards of Android Financial AppsabstractTo ensure the security of users' property, financial applications in particular require special security guarantee. Specially, to prevent the theft of user's passwords, many financial apps provide their secure keyboards. However, password compromise is still possible if the security keyboard is not implemented properly, putting the user's property at risk. In this paper, we focus on investigating secure keyboards of Android financial apps as well as their risks under screenloggers. We conducted a study on 428 financial apps downloaded from Huawei App Store, Google Play, Wandoujia and Xiaomi GetApps. Our study shows that the status of secure keyboard of financial apps is not optimistic. We find that only 161 apps (37.6%) provide app-specific secure keyboard implementations and the keyboards provided by 60 apps are not secure under screenlogger attacks. Specially, the fundamental causes of all studied insecure keyboards can be attributed to the inappropriate settings of the secure flag of the window or surface that renders the secure keyboard or its feedback animation. Jun Ma 0010 |
SANER | 2 |
| 2022 | GridDroid - An Effective and Efficient Approach for Android Repackaging Detection Based on Runtime Graphical User Interface
Jun Ma 0010, Qingwei Sun, Chang Xu 0001, XianPing Tao |
J. Comput. Sci. Technol. | 1 |
| 2021 | Automatic Performance Testing for Image Displaying in Android AppsabstractImage displaying in Android apps is resource-intensive. Improperly displayed images result in performance degradation or even more severe consequences like app crashes. Existing static performance anti-pattern checkers are conservative and limited to a small set of bugs. This paper presents ImMut, the first test augmentation approach to performance testing for image displaying in Android apps to complement these static checkers. Given a functional test case, ImMut mutates it towards a performance test case by either (1) injecting external-source images with large ones or (2) copy-pasting a repeatable fragment and slightly mutating the copies to display many (potentially distinct) images. Evaluation on our prototype implementation showed promising results that ImMut revealed 14 previously unknown performance bugs that are beyond the capability of state-of-the-art static checkers. Yanyan Jiang 0001, Jun Ma 0010, Chang Xu 0001 |
APSEC | 3 |
| 2020 | Perspectives on search strategies in automated test input generation
Yanyan Jiang 0001, Chang Xu 0001, Jun Ma 0010, Xiaoxing Ma |
Frontiers Comput. Sci. | 4 |
| 2018 | ELEGANT: Towards Effective Location of Fragmentation-Induced Compatibility Issues for Android AppsabstractAndroid fragmentation is a double-edged sword of the Android ecosystem. On the one hand, it promotes Android's prevalence. On the other hand, the numerous combinations of various system versions, customized features, system drivers, and device models make it infeasible, if not impossible, for developers to exhaustively test their apps for potential compatibility issues. Previous research has proposed promising techniques for detecting these issues. However, they suffer from severe false positive problems due to their lack of third-party library detection or imprecise program analysis. In this paper, we present ELEGANT, an automated tool to effectively detect and locate fragmentation-induced compatibility issues for Android apps. ELEGANT exploits whitelist-enhanced or obfuscation-insensitive techniques to detect and alleviate the impact of third-party libraries on the analysis precision, and uses a three-step static detection algorithm to increase the precision of its program analysis. We experimentally evaluated ELEGANT with 22 real-world popular Android apps. The experimental results confirmed ELEGANT's effectiveness on detecting and locating Android fragmentation-induced compatibility issues, as well as realizing an impressive reduction on false positives by around 70%. Cong Li 0003, Chang Xu 0001, Lili Wei 0001, Jun Ma 0010, Jian Lu 0001 |
APSEC | 5 |
| 2018 | CARMUS: Towards a General Framework for Continuous Activity Recognition with Missing Values on SmartphonesabstractThis paper presents the CARMUS framework for continuous activity recognition with missing values on smartphones. Besides the power and resource constraints discussed in existing work, our framework is proposed to further tackle the critical issue of missing values during data collection. We demonstrate the issue's impact on continuous recognition through a motivating example, and specify two challenges-blackouts and resource constraints-with respect to smartphone-based sensing and processing platforms. To address the challenges, CARMUS provides a novel framework which involves a light-weight admission control unit and a data imputation unit intuited by the daily repeated pattern and temporal smoothness of human activity data. Based on extensive experiments conducted on a real-world data set with 37% of the data missing, we show that the CARMUS framework is effective for achieving an 85.5% recognition accuracy by adopting the state-of-the-art imputation algorithms. Tianheng Wu, Liang Wang 0006, Simeng Wu, Jun Ma 0010, XianPing Tao, Jian Lu 0001 |
COMPSAC (1) | 5 |
| 2018 | RegionDroid: A Tool for Detecting Android Application Repackaging Based on Runtime UI Region FeaturesabstractWith the rapid development of mobile devices, Android applications (apps) are universally used. However, attackers repackage Android apps and release them to the markets for illegal purposes, which brings great threats to the Android ecosystem. To leverage the popularity of original apps, they keep similar software behaviors to confuse app users. Furthermore, repackaged apps can be obfuscated or encrypted to avoid being detected. Besides, hybrid mobile apps, built by combining web technology and native elements, are becoming a preferred choice for developers. The structure of hybrid apps differs a lot from that of native apps which would raise great challenges to repackaging detection. Existing works still have some limitations in detecting repackaging from obfuscated and encrypted apps. Besides, few of them can deal with hybrid apps. In this paper, we proposed an approach based on the app UI regions extracted from app's runtime UI traces. We also implement a tool named RegionDroid based on the approach. We apply RegionDroid to tree datasets with totally 369 apps. It successfully finds all the 98 obfuscated or encrypted repackaged pairs in dataset S1. It also shows good credibility in distinguishing another 114 commercial apps in dataset S2. We also test our approach in dataset S3with 157 hybrid apps by comparing them pairwisely and the false positive rate is 0.016%. Shengtao Yue, Qingwei Sun, Jun Ma 0010, XianPing Tao, Chang Xu 0001, Jian Lu 0001 |
ICSME | 3 |
| 2018 | LESdroid: a tool for detecting exported service leaks of Android applicationsabstractServices are widely used in Android apps. However, services may leak such that they are no longer used but cannot be recycled by the Garbage Collector. Service leaks may cause an app to misbehave, and are vulnerable to malicious external apps when the service is exported or it is accessible through other exported services. In this paper, we present LESDroid for exported service leaks detection. LESDroid automatically generates service instances and workloads (start/stop or bind/unbind of exported services) of the app under test, and applies a designated oracle to the heap snapshot for service leak detection. We evaluated LESDroid using 375 commercial apps, and found 97 leaked services and 98 distinct leak entries in 70 apps. Jun Ma 0010, Shaocong Liu, Yanyan Jiang 0001, XianPing Tao, Chang Xu 0001, Jian Lu 0001 |
ICPC | 1 |
| 2018 | AATT+: Effectively manifesting concurrency bugs in Android apps
Yanyan Jiang 0001, Chang Xu 0001, Tianxiao Gu, Jun Ma 0010, Xiaoxing Ma, Jian Lu 0001 |
Sci. Comput. Program. | 6 |
| 2017 | LeakDAF: An Automated Tool for Detecting Leaked Activities and Fragments of Android ApplicationsabstractMemory leak, one of the most common problems threatening android apps, might drain the limited memory of mobile devices, cause unexpected delays, no-responses or even crashes to apps. Activity/Fragment Leak is one of the most common and serious causes of memory leaks and has a vast influence on the Android app market. Existing work to identify leaked activities/fragments either depend highly on the experience of developers, or require app's source code and manual interactions. In this paper, we propose an automatic tool named LeakDAF for detecting leaked activities/fragments automatically without manual intervention. LeakDAF makes use of UI testing technique to execute automatically the app under test, and applies memory analysis technique to inspect dumped heap files to identify leaked activities and fragments based on Android's mechanisms for managing them. To evaluate the effectiveness of LeakDAF, we successfully applied it to 35 open source and 64 commercial apps, and we detected at least one leaked activity or fragment for 10 open source apps and 35 commercial apps. Jun Ma 0010, Shengtao Yue, XianPing Tao, Jian Lu 0001 |
COMPSAC (1) | 1 |
| 2017 | RepDroid: an automated tool for Android application repackaging detectionabstractIn recent years, with the explosive growth of mobile smart phonesnes, the number of Android applications (apps) increases rapidly. Attackers usually leverage the popumobile smart phoneslarity of Android apps by inserting malwares, modifying the original apps, repackaging and releasing them for their own illegal purposes. To avoid repackaged apps from being detected, they usually use sorts of obfuscation and encryption tools. As a result, it's important to detect which apps are repackaged. People often intuitively judge whether two apps are a repackaged pair by executing them and observing their runtime user interface (UI) traces. Hence, we propose layout group graph (LGG) built from UI trances to model those UI behaviors and use LGG as the birthmark of Android apps for identification. Based on LGG, we also implement a dynamic repackaging detection tool, RepDroid. Since our method does not require the apps' source code, it is resilient to app obfuscation and encryption. We conducted an experiment with two data sets. The first set contains 98 pairs of repackaged apps. The original apps and repackaged ones are compared and we can detect all of these repackaged pairs. The second set contains 125 commercial apps. We compared them pair-wisely and the false positive rate was 0.08%. Shengtao Yue, Weizan Feng, Jun Ma 0010, Yanyan Jiang 0001, XianPing Tao, Chang Xu 0001, Jian Lu 0001 |
ICPC | 3 |
| 2016 | Effectively Manifesting Concurrency Bugs in Android AppsabstractSmartphones are indispensable in people's daily lives. As smartphone apps are being increasingly concurrent, developers are increasingly unable to tackle the complexity and to avoid subtle concurrency bugs. To better address this issue, we propose a novel approach to manifesting concurrency bugs in Android apps based on the fact that one can simultaneously generate input events and their schedules for an app. We conduct static-dynamic hybrid analysis to find potentially conflicting resource accesses in an app. The app is then automatically pressure-tested by guided event and schedule generation. We implemented the prototype tool AATT and evaluated it over thirteen popular real-world open-source apps. AATT successfully found 9 concurrency bugs out of which 7 were previously unknown. Yanyan Jiang 0001, Tianxiao Gu, Chang Xu 0001, Jun Ma 0010, Xiaoxing Ma, Jian Lu 0001 |
APSEC | 5 |
| 2015 | ReCEC: Resolving Conflicts of Environmental Constraints among Multiple Applications in a Smart SpaceabstractAs applications deployed in a smart space share the same physical environment, they may interfere (or even conflict) with one another. To guarantee the performance and user experience of the entire smart space, mechanisms for handling such interferes (or conflicts) have to be introduced. We believe that conflicts among multiple applications are caused by their different requirements and impacts on the shared environment, and we model the conflict resolution problem as a Constraint Satisfaction Problem(CSP). We further propose a framework for managing and coordinating context-aware applications in a smart space, and provide an effective and efficient strategy to solve the corresponding CSP. Exhausted simulations are carried out to show the effectiveness of the proposed resolution strategy. Jun Ma 0010, XianPing Tao, Haijun Wu, Jian Lu 0001 |
COMPSAC | 1 |
| 2013 | Presence-pattern aware service selection and composition in a smart spaceabstractService composition provides supports for automatic construction of required services on the fly from component services provided by different providers. In a smart space, as new providers may come in and existing ones may leave from time to time, the collection of available component services may change dynamically, resulting in broken compositions. Automatic reselection or recomposition mechanisms can be applied to fix broken compositions. However, they may introduce extra efforts and time and there are applications requiring (composed)services to be continuously available (at least) during a period of time, otherwise the applications would break down. Both the situations affect users' experience. If we could know how long each component service would be continuously available, we could optimize the composition process by reducing the frequency of broken compositions. In this paper we propose a scheme to achieve the goal. It utilizes presence-patterns of providers to estimate how long a component service may continuously available and it always selects the most continuously available composition that matches requirements. Simulations are carried out to show how and how well the presence-patterns based scheme work. Jun Ma 0010, XianPing Tao, Jian Lu 0001 |
Internetware | 1 |
| 2010 | Probe: a system for context collection, dissemination and processingabstractThe open, dynamic and uncertain internet platform requires software systems running on it should be able to probe the changes of their running environments and adapt themselves accordingly. The Internetware paradigm and the environment driven application model open a promising way to cope with these requirements. A uniform middleware for environmental context information handling is essential to achieve the environment driven application model. In this paper, we argue that mobile agent technology is competent for building such a middleware and propose the Probe system, implemented based on mobile agent technology, with respects to the environment driven application model. The Probe system provides a uniform, hierarchical, and dynamic configurable platform for environmental context information collection, dissemination and processing for Internetware applications. Jun Ma 0010, XianPing Tao |
Internetware | 1 |
| 2008 | Cluster filtered KNN: A WLAN-based indoor positioning schemeabstractLocation Based Service (LBS) is one kind of ubiquitous applications whose functions are based on the locations of clients. The core of LBS is an effective positioning system. As wireless LAN (WLAN) costs less and is easy to access, using WLAN for indoor positioning has been widely studied recently. K nearest neighbors (KNN) is one of the basic deterministic fingerprint based algorithms and widely used for WLAN-based indoor positioning. However, KNN takes all the nearest K neighbors for calculating the estimated result, which could be improved if some selective work could be done to those neighbors beforehand. In this paper we propose a new scheme called "cluster filtered KNN" (CFK). CFK utilizes clustering technique to partition those neighbors into different clusters and chooses one cluster as the delegate. In the end, the final estimate can be calculated only based on the elements of the delegate. With experiments, we found that CFK does outperform KNN. Jun Ma 0010, Xuansong Li, XianPing Tao, Jian Lu 0001 |
WOWMOM | 1 |