EDBT 2026 Demo / reviewers in the wild / expert
Yong Yang 0017
dblp:11/357-17
· DBLP profile ↗
3ranked-venue papers
2as first author
3since 2021 · last 2025
0000-0003-3526-560XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Unveiling Security Vulnerabilities in Git Large File Storage ProtocolabstractAs an extension to the Git version control system that optimizes the handling of large files and binary content, Git Large File Storage (LFS) has been widely adopted by nearly all Git platforms. While Git LFS offers significant improvements in managing large files, it introduces new security implications that remain largely unexplored. This paper presents the first comprehensive security analysis of Git LFS, identifying 11 critical security properties that LFS servers must uphold. Building on our analysis of these property violations, we propose four new attack vectors: Private LFS File Leakage, LFS File Replacement, Quota-based Denial of Service (DoS), and Quota Escape. These attacks exploit weaknesses in practical LFS server implementations and can lead to serious consequences, including unauthorized access to sensitive files, malware injection, denial of service affecting all public repositories, and resource abuse. To evaluate the security of LFS implementations, we develop a semi-automated black-box testing tool and apply it to 14 major Git platforms. We uncover 36 previously unknown vulnerabilities and have responsibly disclosed them to the respective platform maintainers, receiving positive feedback and over $1800 in bug bounty rewards. Qinying Wang, Yong Yang 0017, Yuanchao Chen, Yuwei Li 0002, Shouling Ji |
SP | 3 |
| 2025 | PRSA: Prompt Stealing Attacks against Real-World Prompt Services
Yong Yang 0017, Changjiang Li, Qingming Li, Oubo Ma, Zonghui Wang, Yandong Gao, Wenzhi Chen, Shouling Ji |
USENIX Security Symposium | 1 |
| 2025 | Invisible-Face: Rethinking Facial Attribute Privacy in Social Media Photo SharingabstractAs social media gains popularity, users frequently share personal photos without recognizing the risks of exposing their faces to advanced facial attribute detection technologies. These technologies can extract sensitive attributes such as age, race, sexual orientation, and potential health information from facial images, raising significant privacy concerns. Despite the availability of various anonymization techniques, our research reveals that current methods inadequately protect facial attribute privacy. They often fail to balance effectiveness and utility, underscoring the pressing need for more robust solutions in today’s pervasive photo-sharing culture. To remedy this gap, we introduce Invisible-Face, a tool designed to safeguard users’ facial attribute privacy using advanced adversarial perturbation techniques. Invisible-Face uses local, directional, and resilient perturbation generative strategies to obfuscate multiple facial attributes effectively, thus ensuring privacy while retaining the utility of the facial images. Our comprehensive evaluation across various datasets and model architectures shows that Invisible-Face significantly outperforms existing privacy-preserving methods in terms of effectiveness while maintaining high image naturalness. Furthermore, our extensive real-world evaluations on four popular MLaaS platforms—Baidu Brain, Tencent Cloud, Aliyun, and Face++—reveal that Invisible-Face achieves comparable privacy protection results while preserving the visual naturalness of images, outperforming existing methods. These findings boost public awareness about the importance of facial attribute privacy and urge online social platforms to improve their protection measures. Yong Yang 0017, Changjiang Li, Xuhong Zhang 0002, Zonghui Wang, Shouling Ji, Wenzhi Chen |
IEEE Trans. Inf. Forensics Secur. | 1 |