EDBT 2026 Demo / reviewers in the wild / expert
Boyuan He
dblp:165/5420
· DBLP profile ↗
7ranked-venue papers
2as first author
4since 2021 · last 2023
0000-0001-9841-3513ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 1 first-author · 2 since 2021Computer networks · 3 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Raft: Hardware-assisted Dynamic Information Flow Tracking for Runtime Protection on RISC-VabstractDynamic Information Flow Tracking (DIFT) is a fundamental computer security technique that tracks the data flow of interest at runtime, overcoming the limitations of discovering data dependencies statically at compilation time. However, software-based DIFT tools often suffer from unbearably high runtime overhead due to dynamic binary instrumentation or virtual machine, limiting the usefulness of DIFT. Even though hardware-assisted DIFT frameworks cut down the performance overhead effectively, it is still unacceptable for applications under rigorous time constraints. Yu Wang 0204, Jinting Wu, Haodong Zheng, Zhenyu Ning, Boyuan He, Fengwei Zhang |
RAID | 5 |
| 2023 | FlowCog: Context-Aware Semantic Extraction and Analysis of Information Flow Leaks in Android AppsabstractAndroid apps having access to private information may be legitimate, depending on whether the app provides users enough semantics to justify the access. Existing works analyzing app semantics are coarse-grained, staying on the app-level. They can only identify whether an app, as a whole, should request special permission but cannot answer whether a specific app behavior under a particular runtime context, such as information flow, is correctly justified. We proposeFlowCog, an automated system to extract semantics related to information flows and correlate such semantics with given information flows to address these issues. Particularly,FlowCogstatically finds all the Android views related to the given flow via control or data dependencies and then extracts semantics, such as texts and images, from these views and associated layouts. Next, FlowCog adopts natural language processing and deep learning approaches to infer whether the extracted semantics correlate with the given flow.FlowCogis open-source and available athttps://github.com/xcdu/FlowCog. Our evaluation shows thatFlowCogcan achieve an accuracy rate of 95.4% and an$\mathrm{F}_{1}$score of 0.953. Xuechao Du, Yinzhi Cao, Boyuan He, Gan Fang, Yan Chen 0004, Daigang Xu |
IEEE Trans. Mob. Comput. | 4 |
| 2022 | AflIot: Fuzzing on linux-based IoT device with binary-level instrumentation
Xuechao Du, Boyuan He, Hao Chen 0003, Fan Zhang 0010, Yan Chen 0004 |
Comput. Secur. | 3 |
| 2021 | MAdLens: Investigating Into Android In-App Ad Practice at API GranularityabstractIn-app advertising has served as the major revenue source for millions of app developers in the mobile Internet ecosystem. Ad networks play an important role in app monetization by providing third-party libraries for developers to choose and embed into their apps. Various ad mediations help developers manage all of the ad libraries used in apps to show the best available ad among received ads from different ad network servers. However, developers lack guidelines on how to choose from hundreds of ad networks or ad mediations and various ad features to maximize their revenues without hurting the user experience of their apps. Our work aims to provide app developers guidelines on the selection of ad networks, ad mediations, and ad placement by observing current common practices. To this end, we investigate 838 unique APIs from 207 ad networks which are extracted from 277,616 Android apps, develop a methodology of ad type classification based on UI interaction and behavior, and perform a large scale measurement study of in-app ads with static analysis techniques at the API granularity. We found that developers have more choices about ad networks than several years before. Most developers are conservative about ad placement and about 77 percent of the apps contain at most one ad library. Besides, the likeliness of an app containing ads depends on the app category to which it belongs. Furthermore, we propose a terminology and classify mobile ads into five ad types: Embedded, Popup, Notification, Offerwall, and Floating. Also, our research shows that it is a better solution for developers to integrate ad libraries with ad mediation feature in their apps because it may avoid bad ratings and improve user experience. And in our findings, more than 95 percent of embedded, popup, notification, and offer ads locate in the zero activity (main activity), the first activity and the second activity of Android apps. More interestingly, developers tend to put high aggressive ads on activities which need deeper user interaction. Our research is the first to reveal the preference of both developers and users for ad networks, ad mediation feature and ad types. Ling Jin 0005, Boyuan He, Guangyao Weng, Haitao Xu 0002, Yan Chen 0004, Guanyu Guo |
IEEE Trans. Mob. Comput. | 2 |
| 2018 | An Investigation into Android In-App Ad Practice: Implications for App DevelopersabstractIn-app advertising has served as the major revenue source for millions of app developers in the mobile Internet ecosystem. Ad networks play an important role in app monetization by providing third-party libraries for developers to choose and embed into their apps. However, developers lack guidelines on how to choose from hundreds of ad networks and various ad features to maximize their revues without hurting the user experience of their apps. Our work aims to uncover the best practice and provide app developers guidelines on ad network selection and ad placement. To this end, we investigate 697 unique APIs from 164 ad networks which are extracted from 277,616 Android apps, develop a methodology of ad type classification based on UI interaction and behavior, and perform a large scale measurement study of in-app ads with static analysis techniques at the API granularity. We found that developers have more choices about ad networks than several years before. Most developers are conservative about ad placement and about 71% apps contain at most one ad library. In addition, the likeliness of an app containing ads depends on the app category to which it belongs. The app categories featuring young audience usually contain the most ad libraries maybe because of the ad-tolerance characteristic of young people. Furthermore, we propose a terminology and classify mobile ads into five ad types: Embedded, Popup, Notification, Offerwall, and Floating. We found that embedded and popup ad types are popular with apps in nearly all categories. Our results also suggest that developers should embed at most 6 ad libraries into an app, which otherwise would anger the app users. Also, a developer should use at most one ad network when her app is still at the initial stage and could start using more (2 or 3) ad networks when the app becomes popular. Our research is the first to reveal the preference of both developers and users for ad networks and ad types. Boyuan He, Haitao Xu 0002, Ling Jin 0005, Guanyu Guo, Yan Chen 0004, Guangyao Weng |
INFOCOM | 1 |
| 2018 | FlowCog: Context-aware Semantics Extraction and Analysis of Information Flow Leaks in Android Apps
Yinzhi Cao, Xuechao Du, Boyuan He, Gan Fang, Rui Shao 0003, Yan Chen 0004 |
USENIX Security Symposium | 4 |
| 2015 | Vetting SSL Usage in Applications with SSLINTabstractSecure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols have become the security backbone of the Web and Internet today. Many systems including mobile and desktop applications are protected by SSL/TLS protocols against network attacks. However, many vulnerabilities caused by incorrect use of SSL/TLS APIs have been uncovered in recent years. Such vulnerabilities, many of which are caused due to poor API design and inexperience of application developers, often lead to confidential data leakage or man-in-the-middle attacks. In this paper, to guarantee code quality and logic correctness of SSL/TLS applications, we design and implement SSLINT, a scalable, automated, static analysis system for detecting incorrect use of SSL/TLS APIs. SSLINT is capable of performing automatic logic verification with high efficiency and good accuracy. To demonstrate it, we apply SSLINT to one of the most popular Linux distributions -- Ubuntu. We find 27 previously unknown SSL/TLS vulnerabilities in Ubuntu applications, most of which are also distributed with other Linux distributions. Boyuan He, Vaibhav Rastogi, Yinzhi Cao, Yan Chen 0004, V. N. Venkatakrishnan, Runqing Yang, Zhenrui Zhang |
IEEE Symposium on Security and Privacy | 1 |