EDBT 2026 Demo / reviewers in the wild / expert
Qingchuan Zhao
dblp:156/1033
· DBLP profile ↗
45ranked-venue papers
4as first author
35since 2021 · last 2026
0000-0003-0163-2846ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 33 · 4 first-author · 23 since 2021Artificial intelligence and machine learning · 5 · 5 since 2021Computer networks · 4 · 4 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MartDE: A Privacy-Preserving and Cost-Efficient Evaluation Framework for Data MarketplacesabstractThe development of machine learning models increasingly relies on high-quality data that resides in private domains. To enable secure and value-driven data exchange under strict privacy regulations, federated learning (FL) has emerged as a key primitive by enabling the trading of model utilities instead of raw data. Among existing solutions, martFL (CCS 2023) represents the state-of-the-art FL-based data marketplace architecture, integrating privacy-preserving model evaluation and verifiable trading protocols to enable robust and fair model utility trading without revealing raw data. Despite its strengths, martFL suffers from critical weaknesses at the evaluation layer, including plaintext score exposure and unverifiable and manipulable participant selection. To address these challenges, we propose MartDE, a dedicated evaluation framework that builds model-centric data marketplaces with robust, privacy-preserving, and verifiable mechanisms. MartDE introduces encrypted utility scoring with client-side decryption to preserve score confidentiality, formally bounded anomaly filtering, adaptive participant selection based on global model performance, and commitment-based verification to ensure consistency between declared and evaluated scores and selection verification. We implement MartDE and evaluate it across diverse datasets and adversarial conditions. Results show that MartDE achieves superior accuracy, robustness, and cost-efficiency, providing a strong foundation for secure and trustworthy utility-driven data marketplaces. Xinyuan Qian 0002, Haoyong Wang, Hangcheng Cao, Shuai Yuan 0009, Senkang Hu, Qingchuan Zhao, Hongwei Li 0001, Guowen Xu |
AAAI | 6 |
| 2026 | MPMA: Preference Manipulation Attack Against Model Context ProtocolabstractModel Context Protocol (MCP) standardizes interface mapping for large language models (LLMs) to access external data and tools, which revolutionizes the paradigm of tool selection and facilitates the rapid expansion of the LLM agent tool ecosystem. However, as the MCP is increasingly adopted, third-party customized versions of the MCP server expose potential security vulnerabilities. In this paper, we first introduce a novel security threat, which we term the MCP Preference Manipulation Attack (MPMA). An attacker deploys a customized MCP server to manipulate LLMs, causing them to prioritize it over other competing MCP servers. This can result in economic benefits for attackers, such as revenue from paid MCP services or advertising income generated from free servers. To achieve MPMA, we first design a Direct Preference Manipulation Attack (DPMA) that achieves significant effectiveness by inserting the manipulative word and phrases into the tool name and description. However, such a direct modification is obvious to users and lacks stealthiness. To address these limitations, we further propose Genetic-based Advertising Preference Manipulation Attack (GAPMA). GAPMA employs four commonly used strategies to initialize descriptions and integrates a Genetic Algorithm (GA) to enhance stealthiness. The experiment results demonstrate that GAPMA balances high effectiveness and stealthiness. Our study reveals a critical vulnerability of the MCP in open ecosystems, highlighting an urgent need for robust defense mechanisms to ensure the fairness of the MCP ecosystem. Rui Zhang 0090, Wenshu Fan, Wenbo Jiang 0001, Qingchuan Zhao, Hongwei Li 0001, Guowen Xu |
AAAI | 6 |
| 2026 | ConfGuard: A Simple and Effective Backdoor Detection for Large Language ModelsabstractBackdoor attacks pose a significant threat to Large Language Models (LLMs), where adversaries can embed hidden triggers to manipulate LLM's outputs. Most existing defense methods, primarily designed for classification tasks, are ineffective against the autoregressive nature and vast output space of LLMs, thereby suffering from poor performance and high latency. To address these limitations, we investigate the behavioral discrepancies between benign and backdoored LLMs in output space. We identify a critical phenomenon which we term sequence lock: a backdoored model generates the target sequence with abnormally high and consistent confidence compared to benign generation. Building on this insight, we propose ConfGuard, a lightweight and effective detection method that monitors a sliding window of token confidences to identify sequence lock. Extensive experiments demonstrate ConfGuard achieves a near 100% true positive rate (TPR) and a negligible false positive rate (FPR) in the vast majority of cases. Crucially, the ConfGuard enables real-time detection almost without additional latency, making it a practical backdoor defense for real-world LLM deployments. Rui Zhang 0086, Hongwei Li 0001, Wenshu Fan, Wenbo Jiang 0001, Qingchuan Zhao, Guowen Xu |
AAAI | 6 |
| 2026 | Demystifying LLM API Misuses: A Lifecycle-Based Empirical Study on Real-World Android AppsabstractLarge Language Model (LLM) services are increasingly utilized by Android apps to provide advanced reasoning and generation capabilities. However, the secure integration of these LLM APIs (LlmAPIs) in real-world mobile apps remains a challenge due to the misunderstood trust boundaries between client and server. This paper presents the first systematic empirical analysis of LlmAPI misuses in Android apps from the perspective of the LLM interaction lifecycle. First, we delineate the threat models and categorize three prevalent types of LlmAPI misuses—ranging from credential leakage to prompt injection risks—through a detailed lifecycle analysis. Then, we develop an automated static analysis framework to detect these misuses in the wild. Specifically, we analyze 206,867 real-world Android apps and identify 1,207 LLM-enabled apps, among which 66.28% (800) exhibit at least one type of misuse. Specifically, 41.01% leak sensitive API credentials, 24.28% expose proprietary system prompts to local inspection, and 39.11% fail to sanitize inputs, leaving apps susceptible to Prompt Injection attacks. The consequences of such misuses are significant, including financial quota theft, intellectual property loss, and remote exploitation via indirect injection. We hope this work raises awareness and emphasizes the importance of adopting secure architectures, such as the Backend Proxy pattern, for mobile AI integration. Jinghang Wen, Qingchuan Zhao |
CODASPY | 2 |
| 2026 | ProtocolGuard: Detecting Protocol Non-compliance Bugs via LLM-guided Static Analysis and Dynamic Verification
Xiangpu Song, Longjia Pei, Jianliang Wu 0002, Yingpei Zeng, Gaoshuo He, Chaoshun Zuo, Xiaofeng Liu 0013, Qingchuan Zhao, Shanqing Guo |
NDSS | 8 |
| 2026 | When VR Meets BCI: (Un)Observable Brainwave-Aware Privacy Reconstruction in the Metaverse via Unrestricted Inbuilt Motion Sensors
Tao Ni 0003, Zehua Sun, Qingchuan Zhao, Wei-Bin Lee, Cong Wang 0001 |
SP | 3 |
| 2026 | Your Copied Data is Under Monitoring: A Study of Clipboard Usage in Android ApplicationsabstractClipboard usage is prevalent in mobile applications nowadays. However, insufficient access control on the clipboard in mobile operating systems exposes its contained data to high risks where one application can read the data, store it locally, or even send it to remote servers. Unfortunately, the literature only has ad-hoc studies in this respect and lacks a comprehensive and systematic study of the entire mobile application ecosystem. Therefore, this paper proposes an automated tool, ClipboardScope+, that leverages the principled static program analysis to uncover the clipboard data usage in mobile applications at scale by defining a usage as a combination of two aspects, i.e., how the clipboard data is validated and where does it go. It defines four primary categories of clipboard data operation, namely spot-on, grand-slam, selective, and cherry-pick, based on the clipboard usage in an application. ClipboardScope+ is evaluated on over1.2 millionmobile applications available on Google Play, spanning the years 2022 and 2023. It uncovered an increase of 5.9% in behaviors of storing and transferring clipboard data over the one-year time, most of which occur automatically in background services. We also conducted a comprehensive case study to characterize different clipboard usages and reveal their privacy issues. Moreover, we uncovered a prevalent programming habit of using theSharedPreferencesobject to store historical data, which can become an unnoticeable privacy leakage channel. Jiayimei Wang, Ruoqin Tang, Chaoshun Zuo, Lei Xue 0001, Weitao Xu, Xiapu Luo, Qingchuan Zhao |
IEEE Trans. Dependable Secur. Comput. | 8 |
| 2026 | Characterizing Contactless Side-Channel Eavesdropping on Wireless ChargersabstractToday, there are an increasing number of smartphones equipped with wireless charging capabilities that use electromagnetic induction to transfer power from a wireless charger to devices that are being charged. In this paper, we unveil a novelcontactlessandcontext-awareside-channel attack in wire less charging, which harnesses two physical phenomena,i.e., the coil whine and the magnetic field perturbations, emanating from the wireless charging process and further infers user interactions on the charging smartphone. To validate the feasibility of this new side channel, we design and implement a three-stage attack framework, dubbed WISERS+, that first captures the coil whine and the magnetic field perturbation emitted by the wireless charger, then infers (i) inter-interface switches (e.g., switching from the home screen to an app interface) and (ii) intra-interface activities (e.g., keyboard inputs inside an app) to builduser interaction contexts, and further reveals sensitive information. We extensively evaluate the effectiveness of our proposed attacks with different commercial-off-the-shelf (COTS) smartphones and wireless chargers. Our evaluation results suggest that WISERS+canachieve over 90.4% accuracy in inferring sensitive information, such as the unlocking passcode on the screen and the launch of mobile apps. In addition, our study also demonstrates that WISERS+ is resilient to several practical impact factors, and presents its potential to be extended to attack the fast charging mode. Finally, we propose effective countermeasures and mitigate threats from the WISERS+ attack. Tao Ni 0003, Chaoshun Zuo, Jianfeng Li 0006, Wubing Wang, Weitao Xu, Xiapu Luo, Qingchuan Zhao |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2026 | An Advanced Gradient Leakage Attack Against Duplicate Labels via Model Outputs ReconstructionabstractFederated learning (FL) is a prevalent distributed machine learning framework that allows multiple clients to train one model by uploading gradients without sharing data, enabling cooperative learning while preserving the training data privacy. Nevertheless, recent research has revealed that shared gradients can still expose clients' private training data. These attacks, however, often become ineffective in two practical scenarios: (1) gradients are computed on high-resolution data; (2) labels are duplicated within the attacked batch. In this work, we introduce an advancedGradientLeakageAttack againstDuplicate labels (GLAD), which can effectively recover high-resolution training data from gradients while considering duplicate labels, making it applicable in more realistic FL scenarios. The key technique ofGLADis to formalize the relationships between model outputs, gradients, model parameters, and training data labels. Based on these relationships,GLADfurther reconstructs the model outputs and inverts the reconstructed model outputs back to the corresponding model inputs. Our method can achieve state-of-the-art recovery accuracy while ensuring efficiency. Extensive experimental results demonstrate thatGLADcan reconstruct images of 224× 224pixels with a batch size of 256 with duplicate labels. Our source code is available athttps://github.com/SuperX612/GLAD. Kunlan Xiang, Haomiao Yang, Meng Hao 0001, Zikang Ding, Hongwei Li 0001, Qingchuan Zhao, Tianwei Zhang 0004 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2026 | No Trespassing: Ground-View Adversarial Patches for Privacy-Aware Management in COTS Robot Vacuum CleanerabstractRobot vacuum cleaners (RVCs) with autonomous navigation and decision-making capabilities have become an integral part of modern homes. During their operations, these devices may inadvertently enter privacy-sensitive areas, leading to potential privacy breaches. However, existing defense methods risk exposing the location of private areas, require root privileges, or are designed for infrared sensors that are ineffective for camera-based RVCs. To overcome these limitations, we propose a novel solution, a ground-view adversarial patch named GPatch, preventing RVCs from entering privacy-sensitive areas. Users only need to place GPatch at the entrance of restricted areas to prevent an RVC's unauthorized access, while also providing a warning to unauthorized individuals. We evaluate GPatch in realworld environments with an average success rate of 87.27%, and experimental results demonstrate its effectiveness, robustness, and transferability, making it a practical, user-friendly, and reliable solution for safeguarding privacy in home environments. Shuai Yuan 0009, Guowen Xu, Hongwei Li 0001, Rui Zhang 0090, Hangcheng Cao, Xinyuan Qian 0002, Tao Ni 0003, Qingchuan Zhao, Yuguang Fang |
IEEE Trans. Dependable Secur. Comput. | 8 |
| 2026 | FIGhost: Fluorescent Ink-Based Stealthy and Flexible Backdoor Attacks on Physical Traffic Sign RecognitionabstractTraffic sign recognition (TSR) systems are crucial for autonomous driving but are vulnerable to backdoor attacks. Existing physical backdoor attacks either lack stealth, provide inflexible attack control, or ignore emerging Vision-Large-Language-Models (VLMs). In this paper, we introduce FIGhost, the first physical-world backdoor attack leveraging fluorescent ink as triggers. Fluorescent triggers are invisible under normal conditions and activated stealthily by ultraviolet light, providing superior stealthiness, flexibility, and untraceability. Inspired by real-world graffiti, we derive realistic trigger shapes and enhance their robustness via an interpolation-based fluorescence simulation algorithm. Furthermore, we develop an automated backdoor sample generation method to support three attack objectives. Extensive evaluations in the physical world demonstrate FIGhost's effectiveness against state-of-the-art detectors and VLMs, maintaining robustness under environmental variations and effectively evading existing defenses. Shuai Yuan 0009, Guowen Xu, Hongwei Li 0001, Rui Zhang 0090, Xinyuan Qian 0002, Hangcheng Cao, Qingchuan Zhao |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2026 | Hidden Tail: Adversarial Attack for Stealthy Resource Consumption Against Vision-Language ModelsabstractVision-Language Models (VLMs) are increasingly deployed in real-world applications, but their high inference cost makes them vulnerable to resource consumption attacks. Prior attacks attempt to extend VLM output sequences by optimizing adversarial images, thereby increasing inference costs. However, these extended outputs often introduce irrelevant abnormal content, compromising attack stealthiness. This trade-off between effectiveness and stealthiness poses a major limitation for existing attacks. To address this challenge, we proposeHidden Tail, a stealthy resource consumption attack that crafts prompt-agnostic adversarial images, inducing VLMs to generate maximum-length outputs by appending special tokens invisible to users. Our method employs a composite loss function that balances semantic preservation, repetitive special token induction, and suppression of the end-of-sequence (EOS) token, optimized via a dynamic weighting strategy. Extensive experiments show thatHidden Tailoutperforms existing attacks, increasing output length by up to 19.2× and reaching the maximum token limit, while preserving attack stealthiness. These results highlight the urgent need to improve the robustness of VLMs against efficiency-oriented adversarial threats. Our code is available athttps://github.com/zhangrui4041/Hidden_Tail. Rui Zhang 0086, Tianli Yang, Wenbo Jiang 0001, Rui Zhang 0090, Qingchuan Zhao, Hongwei Li 0001, Yang Liu 0003, Guowen Xu |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2026 | PriLabel: Toward Comprehensively Uncovering Omitted Disclosures in Privacy Labels of Android Apps on a Large ScaleabstractPrivacy labels (e.g., Data Safety section on Google Play) aim to replace lengthy privacy policies with concise and standardized summaries of in-app privacy practices. However, studies reveal widespread inaccuracies in these self-reported labels, with developers omitting or misrepresenting privacy practices, undermining user trust and regulatory compliance. Existing methods for detecting such discrepancies lack coverage or scalability and fail to address the semantic ambiguity inherent in privacy label auditing. We present Iterative Context Reconstruction (ICR), an evidence-driven workflow that reconstructs context from decompiled code to resolve the ambiguity. Based on ICR, PriLabel: Towards Comprehensively Uncovering Omitted Disclosures in Privacy Labels of Android Apps on a Large Scale is a context-aware static auditor that comprehensively uncoversomitted disclosuresin Android privacy labels, mapping transmitted data to Google’s label taxonomy in asource-freeandontology-freemanner. Our evaluation demonstrates PriLabel: Towards Comprehensively Uncovering Omitted Disclosures in Privacy Labels of Android Apps on a Large Scale’s high precision (91.5%) in detecting omitted disclosures in privacy labels. Applied to 4,851 top-installed Google Play apps, it revealed that 2,374 apps omitted at least one disclosure, with 210 transmitting sensitive financial data (e.g., credit card numbers) without proper labeling, exposing systemic risks of non-compliance. Jinghang Wen, Ruoqin Tang, Xichen Yu, Guowen Xu, Lei Xue 0001, Qingchuan Zhao, Jian Weng 0001 |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2025 | Omni-Angle Assault: An Invisible and Powerful Physical Adversarial Attack on Face RecognitionabstractDeep learning models employed in face recognition (FR) systems have been shown to be vulnerable to physical adversarial attacks through various modalities, including patches, projections, and infrared radiation. However, existing adversarial examples targeting FR systems often suffer from issues such as conspicuousness, limited effectiveness, and insufficient robustness. To address these challenges, we propose a novel approach for adversarial face generation, UVHat, which utilizes ultraviolet (UV) emitters mounted on a hat to enable invisible and potent attacks in black-box settings. Specifically, UVHat simulates UV light sources via video interpolation and models the positions of these light sources on a curved surface, specifically the human head in our study. To optimize attack performance, UVHat integrates a reinforcement learning-based optimization strategy, which explores a vast parameter search space, encompassing factors such as shooting distance, power, and wavelength. Extensive experimental evaluations validate that UVHat substantially improves the attack success rate in black-box settings, enabling adversarial attacks from multiple angles with enhanced robustness. Shuai Yuan 0009, Hongwei Li 0001, Rui Zhang 0090, Hangcheng Cao, Wenbo Jiang 0001, Tao Ni 0003, Wenshu Fan, Qingchuan Zhao, Guowen Xu |
ICML | 8 |
| 2025 | Non-intrusive and Unconstrained Keystroke Inference in VR Platforms via Infrared Side Channel
Tao Ni 0003, Yuefeng Du 0001, Qingchuan Zhao, Cong Wang 0001 |
NDSS | 3 |
| 2025 | The Fluorescent Veil: A Stealthy and Effective Physical Adversarial Patch Against Traffic Sign RecognitionabstractRecently, traffic sign recognition (TSR) systems have become a prominent target for physical adversarial attacks. These attacks typically rely on conspicuous stickers and projections, or using invisible light and acoustic signals that can be easily blocked. In this paper, we introduce a novel attack medium, i.e., fluorescent ink, to design a stealthy and effective physical adversarial patch, namely FIPatch, to advance the state-of-the-art. Specifically, we first model the fluorescence effect in the digital domain to identify the optimal attack settings, which guide the real-world fluorescence parameters. By applying a carefully designed fluorescence perturbation to the target sign, the attacker can later trigger a fluorescent effect using invisible ultraviolet light, causing the TSR system to misclassify the sign and potentially leading to traffic accidents. We conducted a comprehensive evaluation to investigate the effectiveness of FIPatch, which shows a success rate of 98.31% in low-light conditions. Furthermore, our attack successfully bypasses five popular defenses and achieves a success rate of 96.72%. Shuai Yuan 0009, Xingshuo Han, Hongwei Li 0001, Guowen Xu, Wenbo Jiang 0001, Tao Ni 0003, Qingchuan Zhao, Yuguang Fang |
NeurIPS | 7 |
| 2025 | A Thorough Security Analysis of BLE Proximity Tracking Protocols
Xiaofeng Liu 0013, Chaoshun Zuo, Qinsheng Hou, Jianliang Wu 0002, Qingchuan Zhao, Shanqing Guo |
USENIX Security Symposium | 6 |
| 2025 | THEMIS: Towards Practical Intellectual Property Protection for Post-Deployment On-Device Deep Learning Models
Yujin Huang, Zhi Zhang 0001, Qingchuan Zhao, Xingliang Yuan, Chunyang Chen 0001 |
USENIX Security Symposium | 3 |
| 2025 | MBFuzzer: A Multi-Party Protocol Fuzzer for MQTT Brokers
Xiangpu Song, Jianliang Wu 0002, Yingpei Zeng, Chaoshun Zuo, Qingchuan Zhao, Shanqing Guo |
USENIX Security Symposium | 6 |
| 2025 | CSFuzzer: A grey-box fuzzer for network protocol using context-aware state feedback
Xiangpu Song, Yingpei Zeng, Jianliang Wu 0002, Hao Li 0092, Chaoshun Zuo, Qingchuan Zhao, Shanqing Guo |
Comput. Secur. | 6 |
| 2025 | Stealthiness Assessment of Adversarial Perturbation: From a Visual PerspectiveabstractAssessing the stealthiness of adversarial perturbations is challenging due to the lack of appropriate evaluation metrics. Existing evaluation metrics, e.g.,$L_{p}$norms or Image Quality Assessment (IQA), fall short of assessing the pixel-level stealthiness of subtle adversarial perturbations since these metrics are primarily designed for traditional distortions. To bridge this gap, we present the first comprehensive study on the subjective and objective assessment of the stealthiness of adversarial perturbations from a visual perspective at a pixel level. Specifically, we propose new subjective assessment criteria for human observers to score adversarial stealthiness in a fine-grained manner. Then, we create a large-scale adversarial example dataset comprising 10586 pairs of clean and adversarial samples encompassing twelve state-of-the-art adversarial attacks. To obtain the subjective scores according to the proposed criterion, we recruit 60 human observers, and each adversarial example is evaluated by at least 15 observers. The mean opinion score of each adversarial example is utilized for labeling. Finally, we develop a three-stage objective scoring model that mimics human scoring habits to predict adversarial perturbation’s stealthiness. Experimental results demonstrate that our objective model exhibits superior consistency with the human visual system, surpassing commonly employed metrics like PSNR and SSIM. Hangcheng Liu, Yuan Zhou 0005, Ying Yang 0019, Qingchuan Zhao, Tianwei Zhang 0004, Tao Xiang 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | SCR-Auth: Secure Call Receiver Authentication on Smartphones Using Outer Ear EchoesabstractReceiving calls is one of the most universal functions of smartphones, involving sensitive information and critical operations. Unfortunately, to prioritize convenience, the current call receiving process bypasses smartphone authentication mechanisms (e.g., passwords, fingerprint recognition, and face recognition), leaving a significant security gap. To address this issue, we propose SCR-Auth, a secure call receiver authentication scheme for smartphones that leverages outer ear echoes. It sends inaudible acoustic signals through the earpiece speaker to actively sense the call receiver’s outer ear structure and records the resulting echoes using the top microphone. These echoes are then analyzed to extract unique outer ear biometric information for authentication. It operates implicitly, without requiring extra hardware or imposing additional burden. Comprehensive experiments conducted under diverse conditions demonstrate SCR-Auth’s effectiveness and security, showing an average balanced accuracy of 96.95% and resilience against potential attacks. Xiping Sun, Jing Chen 0003, Kun He 0008, Zhixiang He, Ruiying Du, Yebo Feng, Qingchuan Zhao, Cong Wu 0003 |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2025 | HeadSonic: Usable Bone Conduction Earphone Authentication via Head-Conducted SoundsabstractEarables (ear wearables) are rapidly emerging as a new platform encompassing a diverse of personal applications, prompting the development of authentication schemes to protect user privacy. Existing earable authentication methods are all specifically designed for air-conduction earphones, which are not suited for bone conduction earphones (BCEs) that rely on bone conduction mechanisms. In this paper, we propose HeadSonic, a usable BCE authentication system based on the unique head-conducted sounds, which can be acquired when the user wears the BCE device. Specifically, the system emits a millisecond-level sound to initiate the authentication session. The signal captured by the BCE microphone is propagated through the user's head, which is unique in density, geometry, and bone-tissue ratio. It operates implicitly, while maintaining robustness across different behaviors. Extensive experiments involving 60 subjects demonstrate that HeadSonic achieves a commendable balanced accuracy of 96.59%, proving its efficacy and resilience against replay and synthesis attacks. Our dataset and source codes are available athttps://anonymous.4open.science/r/HeadSonic-1CE4. Zhixiang He, Jing Chen 0003, Kun He 0008, Yangyang Gu, Qiyi Deng, Zijian Zhang 0001, Ruiying Du, Qingchuan Zhao, Cong Wu 0003 |
IEEE Trans. Mob. Comput. | 8 |
| 2025 | When Good Becomes Evil: Exploring Crosstalk Attack Surfaces on Multi-Port USB ChargersabstractMulti-port chargers, designed to simultaneously charge multiple mobile devices such as smartphones, have gained significant popularity, with millions of units sold in recent years. However, this multi-device charging feature introduces security and privacy risks. If not properly designed and implemented, these chargers can enable communication between connected devices because they are inherently interconnected, which leads to crosstalk voltage leakages. Despite their widespread use, these risks have not been thoroughly investigated. We have identified novel attack surfaces in the circuit design of multi-port chargers that allow an adversary who shares the multi-port charger with the target victim in close proximity to exploit one port to (i) recognize fine-grained user activities of other devices being charged, (ii) eavesdrop on secret audio transmission from USB-C audio pins, and (iii) inject malicious audio commands into built-in voice assistants of charging devices (e.g., Siri, Google Assistant). In this paper, we design and implement XPORTHEFT, a novel system to analyze and demonstrate the uncovered security and privacy threats in multi-port chargers. Specifically, it leverages changes in voltage signals in one neighbor port to monitor voltage changes in the charging port induced by user activities in various user interfaces, such as recognizing running apps and detecting keystrokes. Moreover, XPORTHEFT can also achieve audio transmission eavesdropping and launch inaudible audio injection attacks from the neighbor port to the charging mobile device via the USB-C interface. We extensively evaluate the effectiveness of XPORTHEFT using five commercial multi-port chargers and five mobile devices. The evaluation results show its high effectiveness in recognizing the launch of 20 mobile apps (88.7%) and revealing unlocking passcodes (98.8%), as well as eavesdropping on the audios of numeric digits (97.1%) and alphabetic characters (98.0%). Furthermore, XPORTHEFT achieves 100% success rates in inaudible audio injection attacks on three commercial voice assistants. In addition, our study also shows that XPORTHEFT is resilient to various impact factors and presents the potential to attack multiple victims. Tao Ni 0003, Zehua Sun, Yihe Zhou, Jiayimei Wang, Weitao Xu, Qingchuan Zhao, Cong Wang 0001 |
IEEE Trans. Mob. Comput. | 7 |
| 2025 | Towards Effective Detection of Ponzi Schemes on Ethereum with Contract Runtime Behavior GraphabstractPonzi schemes, a form of scam, have been discovered in Ethereum smart contracts in recent years, causing massive financial losses. Existing detection methods primarily focus on rule-based approaches and machine learning techniques that utilize static information as features. However, these methods have significant limitations. Rule-based approaches rely on pre-defined rules with limited capabilities and domain knowledge dependency. Using static information like opcodes for machine learning fails to effectively characterize Ponzi contracts, resulting in poor reliability and interpretability. Our research shows no significant difference between Ponzi and non-Ponzi contracts at the opcode level. Moreover, relying on static information like transactions for machine learning requires a certain number of transactions to achieve detection, which limits the scalability of detection and hinders the identification of 0-day Ponzi schemes. In this article, we propose PonziGuard , an efficient Ponzi scheme detection approach based on contract runtime behavior. Inspired by the observation that a contract’s runtime behavior is more effective in disguising Ponzi contracts from the innocent contracts, PonziGuard establishes a comprehensive graph representation called contract runtime behavior graph (CRBG), to accurately depict the behavior of Ponzi contracts. Furthermore, it formulates the detection process as a graph classification task on CRBG, enhancing its overall effectiveness. The experiment results show that PonziGuard surpasses the current state-of-the-art approaches in the ground-truth dataset, achieving a precision of 96.9%, recall of 98.2%, and F1-score of 97.5%. It also exhibits the highest level of interpretability among the current tools. We applied PonziGuard to Ethereum Mainnet and demonstrated its effectiveness in real-world scenarios. Using PonziGuard , we identified 805 Ponzi contracts on Ethereum Mainnet, which have resulted in an estimated economic loss of 281,700 Ether or approximately \($\) 500 million USD. We also found 0-day Ponzi schemes in the recently deployed 10,000 smart contracts. Ruichao Liang, Jing Chen 0003, Cong Wu 0003, Kun He 0008, Yueming Wu 0001, Weisong Sun, Ruiying Du, Qingchuan Zhao, Yang Liu 0003 |
ACM Trans. Softw. Eng. Methodol. | 8 |
| 2024 | Attention! Your Copied Data is Under Monitoring: A Systematic Study of Clipboard Usage in Android AppsabstractRecently, clipboard usage has become prevalent in mobile apps allowing users to copy and paste text within the same app or across different apps. However, insufficient access control on the clipboard in the mobile operating systems exposes its contained data to high risks where one app can read the data copied in other apps and store it locally or even send it to remote servers. Unfortunately, the literature only has ad-hoc studies in this respect and lacks a comprehensive and systematic study of the entire mobile app ecosystem. To establish the missing links, this paper proposes an automated tool, ClipboardScope, that leverages the principled static program analysis to uncover the clipboard data usage in mobile apps at scale by defining a usage as a combination of two aspects, i.e., how the clipboard data is validated and where does it go. It defines four primary categories of clipboard data operation, namely spot-on, grand-slam, selective, and cherry-pick, based on the clipboard usage in an app. ClipboardScope is evaluated on 26,201 out of a total of 2.2 million mobile apps available on Google Play as of June 2022 that access and process the clipboard text. It identifies 23,948, 848, 1,075, and 330 apps that are recognized as the four designated categories, respectively. In addition, we uncovered a prevalent programming habit of using the SharedPreferences object to store historical data, which can become an unnoticeable privacy leakage channel. Ruoqin Tang, Chaoshun Zuo, Xiaokuan Zhang, Lei Xue 0001, Xiapu Luo, Qingchuan Zhao |
ICSE | 7 |
| 2024 | DEMISTIFY: Identifying On-device Machine Learning Models Stealing and Reuse Vulnerabilities in Mobile AppsabstractMobile apps have become popular for providing artificial intelligence (AI) services via on-device machine learning (ML) techniques. Unlike accomplishing these AI services on remote servers traditionally, these on-device techniques process sensitive information required by AI services locally, which can mitigate the severe concerns of the sensitive data collection on the remote side. However, these on-device techniques have to push the core of ML expertise (e.g., models) to smartphones locally, which are still subject to similar vulnerabilities on the remote clouds and servers, especially when facing the model stealing attack. To defend against these attacks, developers have taken various protective measures. Unfortunately, we have found that these protections are still insufficient, and on-device ML models in mobile apps could be extracted and reused without limitation. To better demonstrate its inadequate protection and the feasibility of this attack, this paper presents DeMistify, which statically locates ML models within an app, slices relevant execution components, and finally generates scripts automatically to instrument mobile apps to successfully steal and reuse target ML models freely. To evaluate DeMistify and demonstrate its applicability, we apply it on 1,511 top mobile apps using on-device ML expertise for several ML services based on their install numbers from Google Play and DeMistify can successfully execute 1250 of them (82.73%). In addition, an in-depth study is conducted to understand the on-device ML ecosystem in the mobile application. Chaoshun Zuo, Xiaofeng Liu 0013, Wenrui Diao, Qingchuan Zhao, Shanqing Guo |
ICSE | 5 |
| 2024 | AVA: Inconspicuous Attribute Variation-based Adversarial Attack bypassing DeepFake DetectionabstractWhile DeepFake applications are becoming popular in recent years, their abuses pose a serious privacy threat. Unfortunately, most related detection algorithms to mitigate the abuse issues are inherently vulnerable to adversarial attacks because they are built atop DNN-based classification models, and the literature has demonstrated that they could be bypassed by introducing pixel-level perturbations. Though corresponding mitigation has been proposed, we have identified a new attribute-variation-based adversarial attack (AVA) that perturbs the latent space via a combination of Gaussian prior and semantic discriminator to bypass such mitigation. It perturbs the semantics in the attribute space of DeepFake images, which are inconspicuous to human beings (e.g., mouth open) but can result in substantial differences in DeepFake detection. We evaluate our proposed AVA attack on nine state-of-the-art DeepFake detection algorithms and applications. The empirical results demonstrate that AVA attack defeats the state-of-the-art black box attacks against DeepFake detectors and achieves more than a 95% success rate on two commercial DeepFake detectors. Moreover, our human study indicates that AVA-generated DeepFake images are often imperceptible to humans, which presents huge security and privacy concerns. Xiangtao Meng, Li Wang 0120, Shanqing Guo, Lei Ju 0001, Qingchuan Zhao |
SP | 5 |
| 2023 | Recovering Fingerprints from In-Display Fingerprint Sensors via Electromagnetic Side ChannelabstractRecently, in-display fingerprint sensors have been widely adopted in newly-released smartphones. However, we find this new technique can leak information about the user's fingerprints during a screen-unlocking process via the electromagnetic (EM) side channel that can be exploited for fingerprint recovery. We propose FPLogger to demonstrate the feasibility of this novel side-channel attack. Specifically, it leverages the emitted EM emanations when the user presses the in-display fingerprint sensor to extract fingerprint information, then maps the captured EM signals to fingerprint images and develops 3D fingerprint pieces to spoof and unlock the smartphones. We have extensively evaluated the effectiveness of FPlogger on five commodity smartphones equipped with both optical and ultrasonic in-display fingerprint sensors, and the results show it achieves promising similarities in recovering fingerprint images. In addition, results from 50 end-to-end spoofing attacks also present FPLogger achieves 24% (top-1) and 54% (top-3) success rates in spoofing five different smartphones. Tao Ni 0003, Xiaokuan Zhang, Qingchuan Zhao |
CCS | 3 |
| 2023 | XPorter: A Study of the Multi-Port Charger Security on Privacy Leakage and Voice InjectionabstractMulti-port chargers, capable of simultaneously charging multiple mobile devices such as smartphones, have gained immense popularity and sold millions of units in recent years. However, this charging-targeted feature can also pose security and privacy risks by allowing one of the simultaneously charging devices to communicate with another one if not properly designed and implemented as these devices are actually interconnected. Unfortunately, such risks have not been thoroughly investigated and we have identified a novel attack surface in the circuit design of multi-port chargers, which allows an adversary to exploit one port to (i) eavesdrop on the activities of other devices being charged and (ii) inaudibly inject malicious audio commands if the charging device supports voice assistants and USB-C interface. Tao Ni 0003, Weitao Xu, Lei Xue 0001, Qingchuan Zhao |
MobiCom | 5 |
| 2023 | Exploiting Contactless Side Channels in Wireless Charging Power Banks for User Privacy Inference via Few-shot LearningabstractRecently, power banks for smartphones have begun to support wireless charging. Although these wireless charging power banks appear to be immune to most reported vulnerabilities in either power banks or wireless charging, we have found a new contactless wireless charging side channel in these power banks that leaks user privacy from their wireless charging smartphones without compromising either power banks or victim smartphones. We have proposed BankSnoop to demonstrate the practicality of the newly discovered wireless charging side channel in power banks. Specifically, it leverages the coil whine and magnetic field disturbance emitted by a power bank when wirelessly charging a smartphone and adopts the few-shot learning to recognize the app running on the smartphone and uncover keystrokes. We evaluate the effectiveness of BankSnoop using commodity wireless charging power banks and smartphones, and the results show it achieves over 90% accuracy on average in recognizing app launching and keystrokes. It also presents high adaptability when apply to different smartphone models, power banks, etc., achieving over 85% accuracy with 10-shot learning. Tao Ni 0003, Jianfeng Li 0006, Xiaokuan Zhang, Chaoshun Zuo, Wubing Wang, Weitao Xu, Xiapu Luo, Qingchuan Zhao |
MobiCom | 8 |
| 2023 | Uncovering User Interactions on Smartphones via Contactless Wireless Charging Side ChannelsabstractToday, there is an increasing number of smartphones supporting wireless charging that leverages electromagnetic induction to transmit power from a wireless charger to the charging smartphone. In this paper, we report a new contactless and context-aware wireless-charging side-channel attack, which captures two physical phenomena (i.e., the coil whine and the magnetic field perturbation) generated during this wireless charging process and further infers the user interactions on the charging smartphone. We design and implement a three-stage attack framework, dubbed WISERS, to demonstrate the practicality of this new side channel. WISERS first captures the coil whine and the magnetic field perturbation emitted by the wireless charger, then infers (i) inter-interface switches (e.g., switching from the home screen to an app interface) and (ii) intra-interface activities (e.g., keyboard inputs inside an app) to build user interaction contexts, and further reveals sensitive information. We extensively evaluate the effectiveness of WISERS with popular smartphones and commercial-off-the-shelf (COTS) wireless chargers. Our evaluation results suggest that WISERS can achieve over 90.4% accuracy in inferring sensitive information, such as screen-unlocking passcode and app launch. In addition, our study also shows that WISERS is resilient to a list of impact factors. Tao Ni 0003, Xiaokuan Zhang, Chaoshun Zuo, Jianfeng Li 0006, Zhenyu Yan 0002, Wubing Wang, Weitao Xu, Xiapu Luo, Qingchuan Zhao |
SP | 9 |
| 2023 | Eavesdropping Mobile App Activity via Radio-Frequency Energy Harvesting
Tao Ni 0003, Guohao Lan, Jia Wang 0008, Qingchuan Zhao, Weitao Xu |
USENIX Security Symposium | 4 |
| 2022 | PeriScope: Comprehensive Vulnerability Analysis of Mobile App-defined Bluetooth PeripheralsabstractMany IoT devices today talk to each other via Bluetooth Low Energy (BLE), a wireless communication technology often used to exchange data between a paired central and peripheral. These peripheral devices include not only firmware-defined bare-metal peripherals but also mobile application defined peripherals where a mobile app turns a smartphone into a peripheral instead of their usual central role. However, this role reversal increases the attack surface and brings vulnerabilities in bare-metal Bluetooth peripherals to mobile apps where relevant security and privacy have not been well studied. To fill this knowledge gap, this paper presents PeriScope, an automated tool to unveil the security and privacy vulnerabilities at the link layer of app-defined Bluetooth peripherals in the procedures of broadcasting, pairing, and communication by systematically analyzing their companion mobile apps. PeriScope has analyzed 1,160 Bluetooth peripheral apps from Google Play and identified 69.13% of them that broadcast device or personal identifiable information in cleartext, and, in addition, there are 95% pieces of data managed by these apps (e.g., personal health data and digital keys to unlock doors) to exchange with connected devices can be accessed without authentication. Finally, a set of guidelines for secure app-defined Bluetooth peripherals development is also provided. Qingchuan Zhao, Chaoshun Zuo, Jorge Blasco Alís, Zhiqiang Lin 0001 |
AsiaCCS | 1 |
| 2022 | No-Fuzz: Efficient Anti-fuzzing Techniques
Zhengxiang Zhou, Cong Wang 0001, Qingchuan Zhao |
SecureComm | 3 |
| 2020 | Automated Cross-Platform Reverse Engineering of CAN Bus Commands From Mobile Apps
Haohuang Wen, Qingchuan Zhao, Qi Alfred Chen, Zhiqiang Lin 0001 |
NDSS | 2 |
| 2020 | A Study of the Privacy of COVID-19 Contact Tracing Apps
Haohuang Wen, Qingchuan Zhao, Zhiqiang Lin 0001, Dong Xuan, Ness Shroff |
SecureComm (1) | 2 |
| 2020 | On the Accuracy of Measured Proximity of Bluetooth-Based Contact Tracing Apps
Qingchuan Zhao, Haohuang Wen, Zhiqiang Lin 0001, Dong Xuan, Ness Shroff |
SecureComm (1) | 1 |
| 2020 | Automatic Uncovering of Hidden Behaviors From Input Validation in Mobile AppsabstractMobile applications (apps) have exploded in popularity, with billions of smartphone users using millions of apps available through markets such as the Google Play Store or the Apple App Store. While these apps have rich and useful functionality that is publicly exposed to end users, they also contain hidden behaviors that are not disclosed, such as backdoors and blacklists designed to block unwanted content. In this paper, we show that the input validation behavior-the way the mobile apps process and respond to data entered by users-can serve as a powerful tool for uncovering such hidden functionality. We therefore have developed a tool, InputScope, that automatically detects both the execution context of user input validation and also the content involved in the validation, to automatically expose the secrets of interest. We have tested InputScope with over 150,000 mobile apps, including popular apps from major app stores and preinstalled apps shipped with the phone, and found 12,706 mobile apps with backdoor secrets and 4,028 mobile apps containing blacklist secrets. Qingchuan Zhao, Chaoshun Zuo, Brendan Dolan-Gavitt, Giancarlo Pellegrino, Zhiqiang Lin 0001 |
SP | 1 |
| 2020 | FIRMSCOPE: Automatic Uncovering of Privilege-Escalation Vulnerabilities in Pre-Installed Apps in Android Firmware
Mohamed Elsabagh, Ryan Johnson 0002, Angelos Stavrou, Chaoshun Zuo, Qingchuan Zhao, Zhiqiang Lin 0001 |
USENIX Security Symposium | 5 |
| 2019 | Your IoTs Are (Not) Mine: On the Remote Binding Between IoT Devices and UsersabstractNowadays, IoT clouds are increasingly deployed to facilitate users to manage and control their IoT devices. Unlike the traditional cloud services with communication between a client and a server, IoT cloud architectures involve three parties: the IoT device, the user, and the cloud. Before a user can remotely access her IoT device, remote communication between them is bootstrapped through the cloud. However, the security implications of such a unique process in IoT are less understood today. In this paper, we report the first step towards systematic analyses of IoT remote binding. To better understand the problem, we describe the life cycle of remote binding with a state-machine model which helps us demystify the complexity in various designs and systematically explore the attack surfaces. With the evaluation of 10 real-world remote binding solutions, our study brings to light questionable practices in the designs of authentication and authorization, including inappropriate use of device IDs, weak device authentication, and weak cloud-side access control, as well as the impact of the discovered problems, which could cause sensitive user data leak, persistent denial-of-service, connection disruption, and even stealthy device control. Jiongyi Chen, Chaoshun Zuo, Wenrui Diao, Shuaike Dong, Qingchuan Zhao, Menghan Sun, Zhiqiang Lin 0001, Yinqian Zhang, Kehuan Zhang |
DSN | 5 |
| 2019 | Geo-locating Drivers: A Study of Sensitive Data Leakage in Ride-Hailing Services
Qingchuan Zhao, Chaoshun Zuo, Giancarlo Pellegrino, Zhiqiang Lin 0001 |
NDSS | 1 |
| 2018 | IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based Fuzzing
Jiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo, Zhiqiang Lin 0001, XiaoFeng Wang 0001, Wing Cheong Lau, Menghan Sun, Ronghai Yang, Kehuan Zhang |
NDSS | 3 |
| 2017 | AUTHSCOPE: Towards Automatic Discovery of Vulnerable Authorizations in Online ServicesabstractWhen accessing online private resources (e.g., user profiles, photos, shopping carts) from a client (e.g., a desktop web-browser or a mobile app), the service providers must implement proper access control, which typically involves both authentication and authorization. However, not all of the service providers follow the best practice, resulting in various access control vulnerabilities. To understand such a threat in a large scale, and identify the vulnerable access control implementations in online services, this paper introduces AuthScope, a tool that is able to automatically execute a mobile app and pinpoint the vulnerable access control implementations, particularly the vulnerable authorizations, in the corresponding online service. The key idea is to use differential traffic analysis to recognize the protocol fields and then automatically substitute the fields and observe the server response. One of the key challenges for a large scale study lies in how to obtain the post-authentication request-and-response messages for a given app. We have thus developed a targeted dynamic activity explorer to perform an in-context analysis and drive the app execution to automatically log in the service. We have tested AuthScope with 4,838 popular mobile apps from Google Play, and identified 597 0-day vulnerable authorizations that map to 306 apps. Chaoshun Zuo, Qingchuan Zhao, Zhiqiang Lin 0001 |
CCS | 2 |
| 2017 | PT-CFI: Transparent Backward-Edge Control Flow Violation Detection Using Intel Processor TraceabstractThis paper presents PT-CFI, a new backward-edge control flow violation detection system based on a novel use of a recently introduced hardware feature called Intel Processor Trace (PT). Designed primarily for offline software debugging and performance analysis, PT offers the capability of tracing the entire control flow of a running program. In this paper, we explore the practicality of using PT for security applications, and propose to build a new control flow integrity (CFI) model that enforces a backward-edge CFI policy for native COTS binaries based on the traces from Intel PT. By exploring the intrinsic properties of PT with a system call based synchronization primitive and a deep inspection capability, we have addressed a number of technical challenges such as how to make sure the backward edge CFI policy is both sound and complete, how to make PT enforce our CFI policy, and how to balance the performance overhead. We have implemented PT-CFI and evaluated with a number of programs including SPEC2006 and HTTP daemons. Our experimental results show that PT-CFI can enforce a perfect backward-edge CFI with only small overhead for the protected program. Yufei Gu, Qingchuan Zhao, Yinqian Zhang, Zhiqiang Lin 0001 |
CODASPY | 2 |