EDBT 2026 Demo / reviewers in the wild / expert
Lianying Zhao
dblp:140/6495
· DBLP profile ↗
22ranked-venue papers
6as first author
17since 2021 · last 2026
0000-0002-6376-4062ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 5 first-author · 9 since 2021Computer networks · 3 · 1 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Tool-Assisted CVSS Vulnerability Scoring: A Controlled Quantitative Study of Human AssessmentabstractQuantitative vulnerability assessment is central to security management, guiding how risks are prioritized and mitigated. Yet, severity scoring relies on human judgment and is therefore subject to differences in experience, interpretation, and diligence; prior work has even shown expert disagreement. We examine an NLP-based assistive tool that visualizes keyword cues during assessment. In a controlled survey of 389 participants recruited via Amazon MTurk and Prolific, we statistically analyze how participant skills/demographics, vulnerability characteristics, and tool support affect outcomes. Results show the tool does not consistently improve assessment accuracy across expertise levels, but can help for specific vulnerability types (e.g., CWE-787) and CVSS metrics (AC, PR, Scope), and can increase user confidence. Beyond immediate performance, the tool can support training for manual assessment tasks that are hard to automate, as learning effects yield significant improvements on subsequent tasks. This work informs the design of cybersecurity decision-support tools and motivates future research on security training and human-centered security. Minjie Cai, Lianying Zhao, Xavier de Carné de Carnavalet, Fabio Massacci, Mengyuan Zhang 0001 |
CHI | 3 |
| 2026 | ForenThings: An Interactive Framework for Crime Scene Reconstruction in IoT ForensicsabstractIn IoT platforms, devices and sensors can interact with each other via smart apps that utilize automation settings preconfigured by users, resulting in significant amounts of potential forensic data. Existing IoT forensic approaches can pinpoint relevant data sources for specific activities in smart environments using static code analysis and instrumentation techniques. However, recent IoT platforms like SmartThings no longer run application code on their infrastructure, making access to source code impossible for existing IoT forensic solutions. To bridge this gap, this paper introduces ForenThings , an interactive framework for crime scene reconstruction in smart environments. The main idea is to convert each IoT device and smart app to a responsive agent, enabling them to participate in a forensic investigation of a security incident collaboratively. Instead of relying on static code analysis or instrumentation, ForenThings reconstructs the scene from the device and app events forwarded by the IoT platform. We develop a ForenThings prototype for the SmartThings platform and test its effectiveness for both normal scenarios and 12 real-world IoT attack scenarios. The evaluation shows that ForenThings can achieve 100% data provenance coverage in reconstructing various crime scenes in a smart environment with negligible runtime and resource overhead. Ehsan Khodayarseresht, Sofya Smolyakova, Lianying Zhao, Armin Mansouri, Suryadipta Majumdar, Mauro Conti |
ACM Trans. Internet Things | 3 |
| 2025 | Understanding Home Router Configuration Habits & AttitudesabstractContains fulltext : 319673.pdf (Publisher’s version ) (Open Access) Junjian Ye, Xavier de Carné de Carnavalet, Lianying Zhao, Lifa Wu, Mengyuan Zhang 0001 |
CHI | 3 |
| 2025 | Duumviri: Detecting Trackers and Mixed Trackers with a Breakage Detector
He Shuang, Lianying Zhao, David Lie |
NDSS | 2 |
| 2025 | Exposed by Default: A Security Analysis of Home Router Default Settings and BeyondabstractWith the popularity of the Internet, home routers have become crucial for the security of home networks. However, according to the results of our user survey, home routers are often deployed with minimal changes to the factory default settings, which may pose risks to user security and privacy. To systematically evaluate potential risks, we designed a threat-model-based framework and conducted a comprehensive analysis of 40 commercial off-the-shelf home routers from 14 brands. We found a variety of security issues, among which incorrect implementation of TLS is the most common. To improve the efficiency of manually detecting TLS certificate validation vulnerabilities without real routers, we proposed a heuristic method that can narrow down the search scope in firmware and proved its effectiveness with 30 available firmware images of the routers we purchased. Moreover, we evaluated the security of custom remote management protocols and found several cryptographic misuses. Finally, we proposed several recommendations for extending the analysis framework and discussed our ideas about automatically detecting security issues to highlight the need for heightened scrutiny of default settings and inspire other researchers. Junjian Ye, Xavier de Carné de Carnavalet, Lianying Zhao, Mengyuan Zhang 0001, Lifa Wu, Wei Zhang 0122 |
IEEE Internet Things J. | 3 |
| 2024 | Exposed by Default: A Security Analysis of Home Router Default SettingsabstractWith ubiquitous Internet connectivity, home routers have become a cornerstone of our digital lives, often deployed with minimal changes to the factory default settings. However, if left unexamined, these settings can pose risks to user security and privacy. To systematically evaluate potential risks, we developed a threat model-based framework and conducted a comprehensive analysis of 40 commercial off-the-shelf home routers, representative of recent models across 14 brands. We surveyed 81 parameters and behaviors including default and deep default settings. We identified a variety of security flaws including the exposure of IPv6 local devices due to a lack of firewall protection, vulnerable Wi-Fi security protocols, open Wi-Fi networks and trivial admin passwords for "plug-and-play" routers, and unencrypted firmware update communications. We also discovered concealed WPS PIN support --- at times associated with a trivial PIN. In total, we are reporting 30 exploitable vulnerabilities to the vendors. This paper highlights the need for heightened scrutiny of default router settings, providing valuable insights to both manufacturers and consumers for enhancing home network security. Our findings underscore the importance of meticulous device configuration, advocating for proactive measures from all stakeholders to mitigate the threats posed by insecure router default settings. Junjian Ye, Xavier de Carné de Carnavalet, Lianying Zhao, Mengyuan Zhang 0001, Lifa Wu, Wei Zhang 0122 |
AsiaCCS | 3 |
| 2024 | Multi-target Risk Score Aggregation for Security Evaluation of Network EnvironmentsabstractScoring computer systems/networks in terms of specific threats or concerns can enable the comparison of their security level, in a quantitative manner, to facilitate decision making, e.g., mitigation prioritization. The state-of-the-art approaches have mostly focused on scoring the security of a given target, while aggregating scores of multiple systems where each system can be a potential target remains less explored, e.g., whether network A is relatively more secure than network B. In this paper, we take advantage of the well-established attack path representation and use such paths as inter-system influences to derive a risk score of the entire network. We consider the security semantics of various forms of score aggregation, which has not been studied by prior work, and propose to use what we call pairwise path aggregation. We evaluate our approach with a typical fifth Generation (5G) core network, supplemented by evaluations for other network types. The results show that our approach is able to reflect how the overall security varies with multiple factors in common operational scenarios of IT environments. Taous Madi, Matthew Nitschke, Lianying Zhao, Makan Pourzandi |
CloudCom | 4 |
| 2024 | TEE-Receipt: A TEE-Based Non-repudiation Framework for Web Applications
Mahmoud Hofny, Lianying Zhao, Mohammad Mannan, Amr M. Youssef |
SecureComm (2) | 2 |
| 2024 | Racing for TLS Certificate Validation: A Hijacker's Guide to the Android TLS Galaxy
Sajjad Pourali, Xiufen Yu, Lianying Zhao, Mohammad Mannan, Amr M. Youssef |
USENIX Security Symposium | 3 |
| 2024 | Detecting command injection vulnerabilities in Linux-based embedded firmware with LLM-based taint analysis of library functions
Junjian Ye, Xincheng Fei, Xavier de Carné de Carnavalet, Lianying Zhao, Lifa Wu, Mengyuan Zhang 0001 |
Comput. Secur. | 4 |
| 2023 | The Flaw Within: Identifying CVSS Score Discrepancies in the NVDabstractCloud security frameworks, like OpenSCAP, rely on vulnerability databases such as the National Vulnerability Database (NVD) to assess threats, ensure compliance, and manage patches efficiently. However, despite their popularity, vulnerability databases are not exempt from errors. Prior research showed inconsistencies between multiple databases, as well as incorrect software or vendor names, and publication dates. In this study, we discovered and proposed a systematic approach to detect a new form of inconsistency whereby entries with identical or semantically similar vulnerability descriptions are assigned distanced scores, which can skew risk assessments, and potentially misguide mitigation strategies. Our analysis identified 12,866 entries suffering from such inconsistencies, highlighting the most error-prone Common Vulnerability Scoring System (CVSS) metrics and vulnerability types, as well as the observed score deviation. We believe our study can bring this inconsistency issue to the community’s attention and pave the way for further investigation thereof. Minjie Cai, Mengyuan Zhang 0001, Lianying Zhao, Xavier de Carné de Carnavalet |
CloudCom | 4 |
| 2023 | VIET: A Tool for Extracting Essential Information from Vulnerability Descriptions for CVSS Evaluation
Mengyuan Zhang 0001, Lianying Zhao |
DBSec | 3 |
| 2023 | vWitness: Certifying Web Page Interactions with Computer VisionabstractWeb servers service client requests, some of which might cause the web server to perform security-sensitive operations (e.g. money transfer, voting). An attacker may thus forge or maliciously manipulate such requests by compromising a web client. Unfortunately, a web server has no way of knowing whether the client from which it receives a request has been compromised or not-current “best practice” defenses such as user authentication or network encryption cannot aid a server as they all assume web client integrity. To address this shortcoming, we propose vWitness, which “witnesses” the interactions of a user with a web page and certifies whether they match a specification provided by the web server, enabling the web server to know that the web request is user-intended. The main challenge that vWitness overcomes is that even benign clients introduce unpredictable variations in the way they render web pages. vWitness differentiates between these benign variations and malicious manipulation using computer vision, allowing it to certify to the web server that 1) the web page user interface is properly displayed 2) observed user interactions are used to construct the web request. Our vWitness prototype achieves compatibility with modern web pages, is resilient to adversarial example attacks and is accurate and performant-vWitness achieves 99.97% accuracy and adds 197ms of overhead to the entire interaction session in the average case. He Shuang, Lianying Zhao, David Lie |
DSN | 2 |
| 2023 | Measuring the Leakage and Exploitability of Authentication Secrets in Super-apps: The WeChat CaseabstractSuper-apps such as WeChat and Baidu host millions of mini-apps, which are very popular among users and developers because of the mini-apps’ convenience, lightweight, ease of sharing, and not requiring explicit installation. Such ecosystems involve several entities, such as the super-app and mini-app clients, the super-app backend server, the mini-app developer server, and other hosting platforms and services used by the mini-app developer. To support various user-level functionalities, these components must authenticate each other, which differs from regular user authentication to the super-app platform. In this paper, we explore the mini-app to super-app authentication problem caused by insecure development practices. This type of authentication allows the mini-app code to access super-app services on the developer’s behalf. Supraja Baskaran, Lianying Zhao, Mohammad Mannan, Amr M. Youssef |
RAID | 2 |
| 2022 | A Hybrid Decision-making Approach to Security Metrics Aggregation in Cloud EnvironmentsabstractIn cybersecurity, being able to quantity the level of security has been a long quest so that decisions can be made toward improving security. Various metrics have been proposed and applied, which can usually be computed from collected measurements. However, only certain aspects of the target system are measured corresponding to the purpose the metrics were designed for, be it software vulnerabilities or configuration errors, thus lacking a concise and clear image of the overall security of a system for the practitioners to act on, especially when it comes to large-scale or complex systems.We argue that overall security metrics are defined by humans based on specific security goals before they can be computed. Therefore, we propose a hybrid approach to the aggregation of well-established individual security metrics by combining machine computation with human decision making. In particular, we modify the Analytic Hierarchy Process (AHP) to reach a group decision of selected “experts”, which can derive the weights of individual metrics for their aggregation. We showcase its feasibility by selecting several common metrics to measure the target systems in our testbed, and conducting an AHP survey with seventeen experts. The resulted overall security score for the target systems shows how our approach enables comparison of the overall security between those systems. By considering cloud-oriented settings, we also showcase how this approach can be applicable to today’s virtualized environments. Lianying Zhao, Makan Pourzandi, Fereydoun Farrahi Moghaddam |
CloudCom | 2 |
| 2021 | Towards 5G-ready Security MetricsabstractThe fifth-generation (5G) mobile telecom network has been garnering interest in both academia and industry, with better flexibility and higher performance compared to previous generations. Along with functionality improvements, new attack vectors also made way. Network operators and regulatory organizations wish to have a more precise idea about the security posture of 5G environments. Meanwhile, various security metrics for IT environments have been around and attracted the community’s attention. However, 5G-specific factors are less taken into consideration.This paper considers such 5G-specific factors to identify potential gaps if existing security metrics are to be applied to the 5G environments. In light of the layered nature and multi-ownership, the paper proposes a new approach to the modular computation of security metrics based on cross-layer projection as a means of information sharing between layers. Finally, the proposed approach is evaluated through simulation. Lianying Zhao, Muhammad Shafayat Oshman, Mengyuan Zhang 0001, Fereydoun Farrahi Moghaddam, Shubham Chander, Makan Pourzandi |
ICC | 1 |
| 2021 | Emilia: Catching Iago in Legacy Code
Rongzhen Cui, Lianying Zhao, David Lie |
NDSS | 2 |
| 2019 | TEE-aided Write Protection Against Privileged Data Tampering
Lianying Zhao, Mohammad Mannan |
NDSS | 1 |
| 2016 | Hypnoguard: Protecting Secrets across Sleep-wake CyclesabstractAttackers can get physical control of a computer in sleep (S3/suspend-to-RAM), if it is lost, stolen, or the owner is being coerced. High-value memory-resident secrets, including disk encryption keys, and private signature/encryption keys for PGP, may be extracted (e.g., via cold-boot or DMA attacks), by physically accessing such a computer. Our goal is to alleviate threats of extracting secrets from a computer in sleep, without relying on an Internet-facing service. We propose Hypnoguard to protect all memory-resident OS/user data across S3 suspensions, by first performing an in-place full memory encryption before entering sleep, and then restoring the plaintext content at wakeup-time through an environment-bound, password-based authentication process. The memory encryption key is effectively "sealed" in a Trusted Platform Module (TPM) chip with the measurement of the execution environment supported by CPU's trusted execution mode (e.g., Intel TXT, AMD-V/SVM). Password guessing within Hypnoguard may cause the memory content to be permanently inaccessible, while guessing without Hypnoguard is equivalent to brute-forcing a high-entropy key (due to TPM protection). We achieved full memory encryption/decryption in less than a second on a mainstream computer (Intel i7-4771 CPU with 8GB RAM, taking advantage of multi-core processing and AES-NI), an apparently acceptable delay for sleep-wake transitions. To the best of our knowledge, Hypnoguard provides the first wakeup-time secure environment for authentication and key unlocking, without requiring per-application changes. Lianying Zhao, Mohammad Mannan |
CCS | 1 |
| 2016 | Deceptive Deletion Triggers Under CoercionabstractFor users in possession of password-protected encrypted data in persistent storage (i.e., “data at rest”), an obvious problem is that the password may be extracted by an adversary through dictionary attacks, or by coercing the user. Traditional full disk encryption (FDE) or plausibly deniable encryption cannot adequately address such situations. Therefore, making data verifiably inaccessible in a stealthy and quick fashion may be the preferred choice, specifically for users, such as government/corporate agents, journalists, and human rights activists with highly confidential secrets, when caught and interrogated in a hostile territory. Using secure storage on a trusted platform module (TPM) and modern CPU's trusted execution mode (e.g., Intel TXT), we design Gracewipe to enable secure and verifiable deletion of encryption keys through a special deletion password. When coerced, a user can fake compliance and enter the deletion password; and then, the user can prove to the adversary that Gracewipe has been executed and the real key is no longer available (through a TPM quote), hoping for a favorable situation (e.g., end of torture). To unlock the target encryption key, the adversary can only guess passwords through the valid Gracewipe environment with a high-risk of triggering deletion of the real key. Based on our two primary Gracewipe prototypes (i.e., software-based FDE with TrueCrypt and hardware-based FDE with self-encrypting drive), we also design and implement an extended family of unlocking schemes for triggering deletion, to achieve better plausibility, security and usability. We incur between 2-2.5 seconds delay during boot, and no performance penalty at run-time. Lianying Zhao, Mohammad Mannan |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2015 | Gracewipe: Secure and Verifiable Deletion under Coercion
Lianying Zhao, Mohammad Mannan |
NDSS | 1 |
| 2013 | Explicit authentication response considered harmfulabstractAutomated online password guessing attacks are facilitated by the fact that most user authentication techniques provide a yes/no answer as the result of an authentication attempt. These attacks are somewhat restricted by Automated Turing Tests (ATTs, e.g., captcha challenges) that attempt to mandate human assistance. ATTs are not very difficult for legitimate users, but always pose an inconvenience. Several current ATT implementations are also found to be vulnerable to improved image processing algorithms. ATTs can be made more complex for automated software, but that is limited by the trade-off between user-friendliness and effectiveness of ATTs. As attackers gain control of large-scale botnets, relay the challenge to legitimate users at compromised websites, or even have ready access to cheap, sweat-shop human solvers for defeating ATTs, online guessing attacks are becoming a greater security risk. Using deception techniques (as in honeypots), we propose the user-verifiable authentication scheme (Uvauth) that tolerates, instead of detecting or counteracting, guessing attacks. Uvauth provides access to all authentication attempts; the correct password enables access to a legitimate session with valid user data, and all incorrect passwords lead to fake sessions. Legitimate users are expected to learn the authentication outcome implicitly from the presented user data, and are relieved from answering ATTs; the authentication result never leaves the server and thus remains (directly) inaccessible to attackers. In addition, we suggest using adapted distorted images and pre-registered images/text as a complement to convey an authentication response, especially for accounts that do not host much personal data. Lianying Zhao, Mohammad Mannan |
NSPW | 1 |