EDBT 2026 Demo / reviewers in the wild / expert
Yuhong Nan
dblp:167/0416
· DBLP profile ↗
42ranked-venue papers
4as first author
37since 2021 · last 2026
0000-0001-9597-9888ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 23 · 4 first-author · 18 since 2021Software engineering, systems software and programming languages · 16 · 16 since 2021Systems, architecture and hardware · 2 · 2 since 2021Computer networks · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PiCo: Privacy-Preserving Code Sanitization for Cloud-Based LLMs
Yuhong Nan, Jiequan Zheng, Jiangrong Wu, Yixi Lin, Zibin Zheng |
SANER | 2 |
| 2026 | UpgradeShield: Detecting logic-state in-consistencies in smart contract upgrades
Wei Li 0121, Yuxin Su 0001, Yuhong Nan, Kaiwen Ning, Jiajing Wu, Zibin Zheng |
Autom. Softw. Eng. | 3 |
| 2026 | Detecting and Analyzing Fine-grained Third-party Library Dependencies in Solidity Smart ContractsabstractSolidity is the primary programming language for writing smart contracts. As a lightweight language, Solidity does not have a unified way to manage third-party library (TPL) dependencies. Instead, the copy-and-paste pattern and other dependency managers such as NPM and Git submodules have become alternatives. However, these mechanisms significantly increase the complexity of TPL usage with security concerns. Similar to other programming language ecosystems, incorrect TPL usage can influence the reliability of contracts and even introduce vulnerabilities from outdated versions. Therefore, there is an urgent need to understand and comprehend Solidity TPL dependencies. In this work, we conduct a comprehensive study on TPL dependency usage in Solidity. To achieve this, we first present SPADE , which leverages additional metadata (e.g., package and remapping configurations) to infer fine-grained TPL dependencies with version and contract details in various Solidity projects. With SPADE , we investigate a broad spectrum of 5,242 Solidity repositories to understand the TPL dependencies, including their landscape and version-level usage. Our research reveals a set of interesting and important findings that can be beneficial to the Solidity ecosystem. In particular, TPL dependencies are prevalent in Solidity, but the version management remains inadequate. The propagation of vulnerability is severe, affecting 8.87% of the repositories. Finally, we use on-chain contracts to validate the findings and provide suggestions for future research and development on Solidity TPL dependencies. Sicheng Hao 0001, Yuhong Nan, Zeqin Liao, Juan Zhai, Zibin Zheng |
ACM Trans. Softw. Eng. Methodol. | 2 |
| 2026 | Toward Understanding Functional Bugs in EVM-Based Blockchain SystemsabstractFunctional bugs within blockchain systems have led to financial losses exceeding millions of dollars. Blockchain systems, such as Ethereum, play a critical role in supporting decentralized applications and managing significant financial assets. Despite the urgent need for enhanced security, relatively few studies have systematically investigated the functional bugs specific to blockchain systems. Unlike in conventional software, functional bugs in blockchain systems are often domain-specific and linked to core blockchain functionalities, necessitating a comprehensive understanding.In this study, we conduct a systematic analysis of functional bugs in Ethereum Virtual Machine (EVM)-based blockchain systems. We focus on the EVM-based architecture, as it is one of the most widely adopted models for blockchain systems. Specifically, we analyze bug-related issues reported in the GitHub repositories of leading blockchain systems, building a dataset of 205 real-world bugs classified into 18 categories. We investigate these collected bugs with respect to their taxonomies, root causes, and detection methods. From this analysis, we summarize eight key findings for enhancing blockchain security. The discovery of seven previously unknown bugs, yielding approximately $12,000 in bug bounties, demonstrates the practical impact of this work. A further investigation of state-of-the-art tools highlights the limitations of existing detection and analysis research. Mingxi Ye, Yuhong Nan, Jianzhong Su, Yuming Xiao, Peilin Zheng, Zibin Zheng |
IEEE Trans. Software Eng. | 2 |
| 2025 | Identifying Unusual Personal Data in Mobile Apps for Better Privacy Compliance Check
Jiatao Cheng, Yuhong Nan, Xueqiang Wang, Zhefan Chen |
ICICS (1) | 2 |
| 2025 | Why Biting the Bait? Understanding Bait and Switch UI Dark Patterns in Mobile Apps
Yixi Lin, Zitong Yao, Yuhong Nan, Queping Kong, Xueqiang Wang |
ICICS (1) | 4 |
| 2025 | Smartreco: Detecting Read-Only Reentrancy via Fine-Grained Cross-DApp AnalysisabstractDespite the increasing popularity of Decentralized Applications (DApps), they are suffering from various vulnerabilities that can be exploited by adversaries for profits. Among such vulnerabilities, Read-Only Reentrancy (called ROR in this paper), is an emerging type of vulnerability that arises from the complex interactions between DApps. In the recent three years, attack incidents of ROR have already caused around 30M USD losses to the DApp ecosystem. Existing techniques for vulnerability detection in smart contracts can hardly detect Read-Only Reentrancy attacks, due to the lack of tracking and analyzing the complex interactions between multiple DApps. In this paper, we propose SmartReco, a new framework for detecting Read-Only Reentrancy vulnerability in DApps through a novel combination of static and dynamic analysis (i.e., fuzzing) over smart contracts. The key design behind SmartReco is threefold: (1) SmartReco identifies the boundary between different DApps from the heavy-coupled cross-contract interactions. (2) SmartReco performs fine-grained static analysis to locate points of interest (i.e., entry functions) that may lead to ROR. (3) SmartReco utilizes the on-chain transaction data and performs multi-function fuzzing (i.e., the entry function and victim function) across different DApps to verify the existence of ROR. Our evaluation of a manual-labeled dataset with 45 RORs shows that SmartReco achieves a precision of 88.64 % and a recall of 86.67 %. In addition, SmartReco successfully detects 43 new RORs from 123 popular DApps. The total assets affected by such RORs reach around 520,000 USD. Zibin Zheng, Yuhong Nan, Mingxi Ye, Kaiwen Ning, Yu Zhang 0036, Weizhe Zhang |
ICSE | 3 |
| 2025 | Finding Insecure State Dependency in DApps via Multi-Source Tracing and Semantic EnrichmentabstractDecentralized Applications (DApps) serve as the gateway to utilizing blockchain technology. As their prevalence continues to grow, DApps are becoming increasingly interconnected. For instance, a DApp does not need to manage the prices of various tokens internally, as it can retrieve this information from other DApps that provide more up-to-date data. However, such deep reliance also introduces more attack surfaces, posing greater risks to both DApps and their users. In this paper, we refer to the security threat arising from the interdependence of DApps as Insecure State Dependency (ISD). Public reports indicate that ISD has led to losses exceeding 340 million USD.Existing ISDs are mostly found by extensive manual auditing and lucky incidents, as automated discovery of such issues is extremely difficult. More specifically, it is by no means trivial to (1) achieve precise data tracking in the intertwined and invisible interactions of DApps, (2) obtain fine-grained semantic information in low semantic bytecode. In this paper, we propose a novel framework, called InsFinder, for detecting ISD in DApps. Specifically, InsFinder consists of three unique modules to overcome the aforementioned challenges. (1) InsFinder employs dynamic cross-DApp taint analysis to achieve accurate multi-source data tracking in heavily coupled DApp interactions. (2) InsFinder uses source mapping to map bytecode identifiers into meaningful source code, such as variable names or statements, enabling a deeper understanding of bytecode. (3) InsFinder implements fine-grained access control and static analysis for ISD entry point detection. Evaluation on a manually annotated dataset with 93 real-world ISDs shows that InsFinder successfully detects 72 of them, achieving a precision of 84.7% and a recall of 77.4%. Furthermore, InsFinder successfully uncovers 165 previously unreported ISDs across 122 DApp projects. These ISDs collectively impact over 2 million USD. Yuhong Nan, Wei Li 0121, Kaiwen Ning, Zewei Lin, Zitong Yao, Yuming Feng 0002, Weizhe Zhang, Zibin Zheng |
ASE | 2 |
| 2025 | Demystifying the (In)Security of QR Code-based Login in Real-world Deployments
Xin Zhang 0146, Xiaohan Zhang 0001, Yuhong Nan, Zhichen Liu, Jianzhou Chen, Huijun Zhou, Min Yang 0002 |
USENIX Security Symposium | 4 |
| 2025 | An Empirical Study of High-Risk Vulnerabilities in IoT SystemsabstractInternet of Things (IoT) systems are increasingly widespread across various fields. Concurrently, vulnerabilities in IoT devices are continuously emerging, potentially leading to severe consequences, such as information leakage, system failure, or even resource abuse. For IoT system developers, understanding the characteristics of these critical vulnerabilities is crucial for safeguarding the security of IoT systems. However, existing studies on IoT vulnerabilities have not specifically focused on such severe or critical vulnerabilities, i.e., high-risk vulnerabilities. Moreover, previous works analyzed IoT vulnerabilities based on unofficial information sources, such as online reports, GitHub issues, or open-sourced projects. To fill this gap, this article presents the first large-scale empirical study on high-risk IoT vulnerabilities based on the well-known vulnerability data source, i.e., the national vulnerability database (NVD), which is maintained by the U.S. government. We constructed a database consisting of 1739 IoT-related vulnerabilities archived over the last two decades (from 1999 to 2023), including 1076 high-risk vulnerabilities for analysis. We classified the high-risk vulnerabilities into four categories, consisting of 25 different weakness types. We further collected 11 detection tools and summarized their capabilities in detecting IoT vulnerabilities. Our study sheds lights on new findings and insights for developers to secure the IoT system. Changlin Yang, Yuhong Nan, Zibin Zheng |
IEEE Internet Things J. | 3 |
| 2025 | Connector: Enhancing the Traceability of Decentralized Bridge Applications via Automatic Cross-Chain Transaction AssociationabstractDecentralized bridge applications are important software that connects various blockchains and facilitates cross-chain asset transfer in the decentralized finance (DeFi) ecosystem which currently operates in a multi-chain environment. Cross-chain transaction association identifies and matches unique transactions executed by bridge DApps, which is important research to enhance the traceability of cross-chain bridge DApps. However, existing methods rely entirely on unobservable internal ledgers or APIs, violating the open and decentralized properties of blockchain. In this paper, we analyze the challenges of this issue and then present CONNECTOR, an automated cross-chain transaction association analysis method based on bridge smart contracts. Specifically, CONNECTOR first identifies deposit transactions by extracting distinctive and generic features from the transaction traces of bridge contracts.With the accurate deposit transactions, CONNECTOR mines the execution logs of bridge contracts to achieve withdrawal transaction matching. We conduct real-world experiments on different types of bridges to demonstrate the effectiveness of CONNECTOR. The experiment demonstrates that CONNECTOR successfully identifies 100% deposit transactions, associates 95.95% withdrawal transactions, and surpasses methods for CeFi bridges. Based on the association results, we obtain interesting findings about cross-chain transaction behaviors in DeFi bridges and analyze the tracing abilities of CONNECTOR to assist the DeFi bridge apps. Dan Lin 0007, Jiajing Wu, Yuxin Su 0001, Ziye Zheng, Yuhong Nan, Qinnan Zhang, Zibin Zheng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | ASTRO: Detecting Access Control Vulnerabilities in Smart Contracts via Graph Similarity ComparisonabstractSmart contracts are programs running on blockchains, managing substantial volumes of wealth stored within the blockchain platforms. To safeguard these assets, developers design and implement access control policies. However, incomplete and incorrect access control policies allow malicious attackers to gain unauthorized access and exploit additional assets. Previous tools for detecting access control vulnerabilities in smart contracts rely on predefined patterns, specifications, or mining access control policies from historical transactions. However, these methods are constrained due to their predetermined nature and the diversity and complexity of smart contracts.In this paper, we presentASTRO, a new framework employing code similarity to detect access control vulnerabilities in smart contracts. In contrast to prior approaches that heavily rely on predefined, vulnerable code samples,ASTROdetects whether a target contract has access control vulnerabilities by comparing it against a database of audited contracts. Moreover, to mitigate the impact of language-specific features (e.g., diverse conditional statements and modifiers) and writing style characteristics, we integrate pruning and normalization techniques. We evaluateASTROon a total of 22 smart contracts with assigned access control CVEs and those attacked because of access control vulnerabilities from the past two years. Evaluation results demonstrate that, compared to state-of-the-art tools (i.e., AChecker, SpCon),ASTROsurpasses all tools in recall and achieves an improvement in recall by at least 2.8 times. In addition,ASTROachieves a precision of 78.33% on a dataset consisting of real-wild contracts. Furthermore,ASTROsuccessfully identified 19 exploitable vulnerable contract that can be used to directly gain access to the contract’s permissions and obtain benefits. Wei Li 0121, Yuhong Nan, Mingxi Ye, Peilin Zheng, Zibin Zheng |
IEEE Trans. Software Eng. | 2 |
| 2025 | Augmenting Smart Contract Decompiler Output Through Fine-Grained Dependency Analysis and LLM-Facilitated Semantic RecoveryabstractDecompiler is a specialized type of reverse engineering tool extensively employed in program analysis tasks, particularly in program comprehension and vulnerability detection. However, current Solidity smart contract decompilers face significant limitations in reconstructing the original source code. In particular, the bottleneck of SOTA decompilers lies in inaccurate function identification, incorrect variable type recovery, and missing contract attributes. These deficiencies hinder downstream tasks and understanding of the program logic. To address these challenges, we propose SmartHalo, a new framework that enhances decompiler output by combining static analysis (SA) and large language models (LLM). SmartHalo leverages the complementary strengths of SA’s accuracy in control and data flow analysis and LLM’s capability in semantic prediction. More specifically, SmartHalo constructs a new data structure - Dependency Graph (DG), to extract semantic dependencies via static analysis. Then, it takes DG to create prompts for LLM optimization. Finally, the correctness of LLM outputs is validated through symbolic execution and formal verification. Evaluation on a dataset consisting of 465 randomly selected smart contract functions shows that SmartHalo significantly improves the quality of the decompiled code, compared to SOTA decompilers (e.g., Gigahorse). Notably, integrating GPT-4o mini with SmartHalo further enhances its performance, achieving a precision of 91.32% and a recall of 87.38% for function boundaries, a precision of 90.40% and a recall of 88.82% for variable types, and a precision of 80.66% and a recall of 91.78% for contract attributes. Zeqin Liao, Yuhong Nan, Zixu Gao, Henglong Liang, Sicheng Hao 0001, Peifan Reng, Zibin Zheng |
IEEE Trans. Software Eng. | 2 |
| 2025 | Satellite: Detecting and Analyzing Smart Contract Vulnerabilities Caused by Subcontract MisuseabstractCode reuse is a common practice in software engineering. Developers of smart contracts pervasively reuse subcontracts to improve development efficiency. Like any program language, such subcontract reuse may unexpectedly include, or introduce vulnerabilities to the end-point smart contract. Indeed, prior empirical studies have identified a number of issues caused by code reuse in smart contracts. Unfortunately, automatically detecting such issues poses several unique challenges. Particularly, in most cases, smart contracts are compiled as bytecode, whose class-level information (e.g., inheritance, virtual function table), and even semantics (e.g., control flow and data flow) are fully obscured as a single smart contract after compilation. Therefore, it is rather difficult to identify the reused parts of subcontract from a given smart contract, not to mention finding potential vulnerabilities caused by subcontract misuse.In this paper, we propose Satellite, a new bytecode-level static analysis framework for subcontract misuse vulnerability (SMV) detection in smart contracts. Satellite incorporates a series of novel designs to enhance its overall effectiveness.. Particularly, Satellite utilizes a transfer learning method to recover the inherited methods, which are critical for identifying subcontract reuse in smart contracts. Further, Satellite extracts a set of fine-grained method-level features and performs a method-level comparison, for identifying the reuse part of subcontract in smart contracts. Finally, Satellite summarizes a set of SMV indicators according to their types, and hence effectively identifies SMVs. To evaluate Satellite, we construct a dataset consisting of 58 SMVs derived from real-world attacks and collect additional 56 SMV patterns from SOTA studies. Experiment results indicate that Satellite exhibits good performance in identifying SMV, with a precision rate of 84.68% and a recall rate of 92.11%. In addition, Satellite successfully identifies 14 new/unknown SMV over 10,011 realworld smart contracts, affecting a total amount of digital assets worth 201,358 USD. Zeqin Liao, Yuhong Nan, Zixu Gao, Henglong Liang, Sicheng Hao 0001, Jiajing Wu, Zibin Zheng |
IEEE Trans. Software Eng. | 2 |
| 2024 | Are We Getting Well-informed? An In-depth Study of Runtime Privacy Notice Practice in Mobile AppsabstractUnder the General Data Protection Regulation (GDPR), mobile app developers are required to inform users of necessary information at the time when user data is collected (called users' "Right-to-be-Informed"). This is typically done by app developers via providing runtime privacy notices (RPNs for short). However, given the heterogeneous privacy data types and data access patterns in modern apps, it is not clear to what extent apps (app developers) effectively fulfill this compliance requirement in practice. Shuai Li 0006, Zhemin Yang, Yuhong Nan, Shutian Yu, Qirui Zhu, Min Yang 0002 |
CCS | 3 |
| 2024 | Understanding Cross-Platform Referral Traffic for Illicit Drug Promotion
Mingming Zha 0001, Zilong Lin 0001, Xiaojing Liao, Yuhong Nan, XiaoFeng Wang 0001 |
CCS | 5 |
| 2024 | PrettySmart: Detecting Permission Re-delegation Vulnerability for Token Behaviors in Smart ContractsabstractAs an essential component in Ethereum and other blockchains, token assets have been interacted with by diverse smart contracts. Effective permission policies of smart contracts must prevent token assets from being manipulated by unauthorized adversaries. Recent efforts have studied the accessibility of privileged functions or state variables to unauthorized users. However, little attention is paid to how publicly accessible functions of smart contracts can be manipulated by adversaries to steal users' digital assets. This attack is mainly caused by the permission re-delegation (PRD) vulnerability. In this work, we propose PrettySmart, a bytecode-level Permission re-delegation vulnerability detector for Smart contracts. Our study begins with an empirical study on 0.43 million open-source smart contracts, revealing that five types of widely-used permission constraints dominate 98% of the studied contracts. Accordingly, we propose a mechanism to infer these permission constraints, as well as an algorithm to identify constraints that can be bypassed by unauthorized adversaries. Based on the identification of permission constraints, we propose to detect whether adversaries could manipulate the privileged token management functionalities of smart contracts. The experimental results on real-world datasets demonstrate the effectiveness of the proposed PrettySmart, which achieves the highest precision score and detects 118 new PRD vulnerabilities. Zibin Zheng, Hongning Dai, Junjia Chen, Yuhong Nan |
ICSE | 6 |
| 2024 | Midas: Mining Profitable Exploits in On-Chain Smart Contracts via Feedback-Driven Fuzzing and Differential AnalysisabstractIn the context of boosting smart contract applications, prioritizing their security becomes paramount. Smart contract exploits often result in notable financial losses. Ensuring their security is by no means trivial. Rather than resulting in program crashes, most attacks in on-chain smart contracts aim to induce financial loss, referred to as profitable exploits. By constructing seemingly innocuous inputs, profitable exploits try to extract extra profit or compromise the interests of others. However, due to the complexity of call chains in on-chain smart contracts and the need for effective oracles for profitable exploits, smart contract fuzzing suffers from low efficiency and low effectiveness in finding profitable exploits. In this paper, we present Midas, a novel feedback-driven fuzzing framework to mine profitable exploits in on-chain smart contracts effectively. Midas consists of two modules: diverse validity fuzzing and profitable transaction identification. The diverse validity fuzzing module applies two waypoints to efficiently generate valid transactions, addressing the complexity of on-chain smart contract call chains. The profitable transaction identification module applies differential analysis to effectively identify profitable exploits, addressing the limitation of ad-hoc oracles. Evaluation of Midas over on-chain smart contracts showed it effectively identified 40 real-world exploits with a precision of 80%, outperforming state-of-the-art tools (i.e., ItyFuzz and Slither) in both efficiency and effectiveness. Particularly, Midas effectively mines five unknown exploits in valuable smart contracts, and two of them have already been confirmed by their DApp developers. Mingxi Ye, Xingwei Lin, Yuhong Nan, Jiajing Wu, Zibin Zheng |
ISSTA | 3 |
| 2024 | Leaking the Privacy of Groups and More: Understanding Privacy Risks of Cross-App Content Sharing in Mobile Ecosystem
Jiangrong Wu, Yuhong Nan, Luyi Xing, Jiatao Cheng, Zimin Lin, Zibin Zheng, Min Yang 0002 |
NDSS | 2 |
| 2024 | Navigating the Privacy Compliance Maze: Understanding Risks with Privacy-Configurable Mobile SDKs
Yifan Zhang 0010, Zhaojie Hu, Xueqiang Wang, Yuhui Hong, Yuhong Nan, XiaoFeng Wang 0001, Jiatao Cheng, Luyi Xing |
USENIX Security Symposium | 5 |
| 2024 | MAGIC: Detecting Advanced Persistent Threats via Masked Graph Representation Learning
Zian Jia, Yun Xiong, Yuhong Nan, Yao Zhang 0009, Jinjing Zhao, Mi Wen |
USENIX Security Symposium | 3 |
| 2024 | Understanding Privacy Risks of Intelligent Connected Vehicles Through Their Companion Mobile AppsabstractThe rapid advancement of intelligent connected vehicles (ICVs) in the automotive sector has significantly intensified security and privacy issues. Particularly, the previous studies have indicated that the ICV users (owners) are deeply concerned about the extensive data gathered by these vehicles. However, current research into vehicle security predominantly concentrates on the analysis and discussion of sensitive data from ICVs of specific brands or models. There is a notable lack of studies that conduct a comprehensive, large-scale investigation into the sensitive data collected by ICVs and assess the privacy implications of such data collection. In this article, we undertake an extensive investigation to comprehend the privacy risks associated with Internet-connected vehicles (ICVs) through their companion mobile apps. To accomplish this, we have devised a semi-automatic pipeline leveraging program analysis and large language model (LLM) to identify and track sensitive data across these apps. Specifically, we begin by constructing a detailed knowledge base of ICV sensitive data extracted from the privacy policies of companion apps. Subsequently, we conduct static analysis on the car companion apps, pinpointing instances of sensitive data usage within the app code and analysing their potential privacy risks. Our analysis, covering 401 car companion apps spanning 271 unique vehicle brands, unveils several noteworthy findings concerning the usage of user sensitive data in the ICV ecosystem. For instance, various entities within the ICV ecosystem collect a wide array of sensitive data, including brake status, passenger occupancy, and insurance details. Alarmingly, we discover that 37.91% of car companion apps fail to adequately disclose their data usage practices. Moreover, we observe extensive involvement of entities beyond vehicle manufacturers in the handling of vehicle sensitive data, including data analytics companies, charging service providers, and cloud service vendors. Peifu Yang, Yuhong Nan, Lei Xue 0001, Juan Zhai, Zibin Zheng |
IEEE Internet Things J. | 2 |
| 2024 | FunFuzz: A Function-Oriented Fuzzer for Smart Contract Vulnerability Detection with High Effectiveness and EfficiencyabstractWith the increasing popularity of Decentralized Applications (DApps) in blockchain, securing smart contracts has been a long-term, high-priority subject in the domain. Among the various research directions for vulnerability detection, fuzzing has received extensive attention because of its high effectiveness. However, with the increasing complexity of smart contracts, existing fuzzers may waste substantial time exploring locations irrelevant to smart contract vulnerabilities. In this article, we present FunFuzz, a function-oriented fuzzer, which is dedicatedly tailored for detecting smart contract vulnerability with high effectiveness and efficiency. The key observation in our research is that most smart contract vulnerabilities exist in specific functions rather than randomly distributed in all program code like other traditional software. To this end, unlike traditional fuzzers which mainly target code coverage, FunFuzz identifies risky functions while pruning non-risky ones in smart contracts. In this way, it significantly narrows down the exploration scope during the fuzzing process. In addition, FunFuzz employs three unique strategies to direct itself toward effectively discovering vulnerabilities specific to smart contracts (e.g., reentrancy, block dependency, and gasless send). Extensive experiments on 170 real-world contracts demonstrate that FunFuzz outperforms state-of-the-art fuzzers in terms of effectiveness and efficiency. Mingxi Ye, Yuhong Nan, Hongning Dai, Shuo Yang 0012, Xiapu Luo, Zibin Zheng |
ACM Trans. Softw. Eng. Methodol. | 2 |
| 2023 | DARPA: Combating Asymmetric Dark UI Patterns on Android with Run-time View DecoratorabstractIt has been extensively discussed that online services, such as shopping websites, may exploit dark user interface (UI) patterns to mislead users into performing unwanted and even harmful activities on the UI, e.g., subscribing to recurring purchases unknowingly. Most recently, the growing popularity of mobile platforms has led to an ever-extending reach of dark UI patterns in mobile apps, leading to security and privacy risks to end users. A systematic study of such patterns, including how to detect and mitigate them on mobile platforms, unfortunately, has not been conducted. In this paper, we fill the research gap by investigating the dark UI patterns in mobile apps. Specifically, we show the prevalence of the asymmetric dark UI patterns (AUI) in real-world apps, and reveal their risks by characterizing the AUI (e.g., subjects, hosts, and patterns). Then, through user studies, we demonstrate the demand for effective solutions to mitigate the potential risks of AUI. To meet the needs, we propose DARPA - an end-to-end and generic CV-based solution to identify AUIs at run-time and mitigate the risks by highlighting the AUIs with run-time UI decoration. Our evaluation shows that DARPA is highly accurate and introduces negligible overhead. Additionally, running DARPA does not require any modifications to the apps being analyzed and to the operating system. Zhaoxin Cai, Yuhong Nan, Xueqiang Wang, Mengyi Long, Qihua Ou, Min Yang 0002, Zibin Zheng |
DSN | 2 |
| 2023 | SmartState: Detecting State-Reverting Vulnerabilities in Smart Contracts via Fine-Grained State-Dependency AnalysisabstractSmart contracts written in Solidity are widely used in different blockchain platforms such as Ethereum, TRON and BNB Chain. One of the unique designs in Solidity smart contracts is its statereverting mechanism for error handling and access control. Unfortunately, a number of recent security incidents showed that adversaries also utilize this mechanism to manipulate critical states of smart contracts, and hence, bring security consequences such as illegal profit-gain and Deny-of-Service (DoS). In this paper, we call such vulnerabilities as the State-reverting Vulnerability (SRV). Automatically identifying SRVs poses unique challenges, as it requires an in-depth analysis and understanding of the state-dependency relations in smart contracts. Zeqin Liao, Sicheng Hao 0001, Yuhong Nan, Zibin Zheng |
ISSTA | 3 |
| 2023 | Detecting State Inconsistency Bugs in DApps via On-Chain Transaction Replay and FuzzingabstractDecentralized applications (DApps) consist of multiple smart contracts running on Blockchain. With the increasing popularity of the DApp ecosystem, vulnerabilities in DApps could bring significant impacts such as financial losses. Identifying vulnerabilities in DApps is by no means trivial, as modern DApps consist of complex interactions across multiple contracts. Previous research suffers from either high false positives or false negatives, due to the lack of precise contextual information which is mandatory for confirming smart contract vulnerabilities when analyzing smart contracts. Mingxi Ye, Yuhong Nan, Zibin Zheng, Dongpeng Wu, Huizhong Li |
ISSTA | 2 |
| 2023 | SmartCoCo: Checking Comment-Code Inconsistency in Smart Contracts via Constraint Propagation and BindingabstractSmart contracts are programs running on the blockchain. Comments in source code provide meaningful information for developers to facilitate code writing and understanding. Given various kinds of token standards in smart contracts (e.g., ERC-20, ERC-721), developers often copy&paste code from other projects as templates, and then implement their own logic as add-ons to such templates. In many cases, the consistency between code and comment is not well-aligned, leading to comment-code inconsistencies (as we call CCIs). Such inconsistencies can mislead developers and users, and even introduce vulnerabilities to the contracts. In this paper, we present SmartCoCo, a novel framework to detect comment-code inconsistencies in smart contracts. In particular, our research focuses on comments related to roles, parameters, and events that may lead to security implications. To achieve this, SmartCoCo takes the original smart contract source code as input and automatically analyzes the comment and code to find potential inconsistencies. SmartCoCo associates comment constraints and code facts via a set of propagation and binding strategies, allowing it to effectively discover inconsistencies with more contextual information. We evaluated SmartCoCo on 101,780 unique smart contracts on Ethereum. The evaluation result shows that SmartCoCo achieves good effectiveness and efficiency. In particular, SmartCoCo reports 4,732 inconsistencies from 1,745 smart contracts, with a precision of over 79% on 439 manual-labeled comment-code inconsistencies. Meanwhile, it only takes 2.64 seconds to check a smart contract on average. Sicheng Hao 0001, Yuhong Nan, Zibin Zheng |
ASE | 2 |
| 2023 | AIRTAG: Towards Automated Attack Investigation by Unsupervised Learning with Log Texts
Hailun Ding, Juan Zhai, Yuhong Nan, Shiqing Ma |
USENIX Security Symposium | 3 |
| 2023 | Are You Spying on Me? Large-Scale Analysis on IoT Data Exposure through Companion Apps
Yuhong Nan, Xueqiang Wang, Luyi Xing, Xiaojing Liao, Jianliang Wu 0002, Yifan Zhang 0010, XiaoFeng Wang 0001 |
USENIX Security Symposium | 1 |
| 2022 | SIMulation: Demystifying (Insecure) Cellular Network based One-Tap Authentication ServicesabstractA recently emerged cellular network based One-Tap Authentication (OTAuth) scheme allows app users to quickly sign up or log in to their accounts conveniently: Mobile Network Operator (MNO) provided tokens instead of user passwords are used as identity credentials. After conducting a first in-depth security analysis, however, we have revealed several fundamental design flaws among popular OTAuth services, which allow an adversary to easily (1) perform unauthorized login and register new accounts as the victim, (2) illegally obtain identities of victims, and (3) interfere OTAuth services of legitimate apps. To further evaluate the impact of our identified issues, we propose a pipeline that integrates both static and dynamic analysis. We examined 1,025/894 Android/iOS apps, each app holding more than 100 million installations. We confirmed 396/398 Android/iOS apps are affected. Our research systematically reveals the threats against OTAuth services. Finally, we provide suggestions on how to mitigate these threats accordingly. Xing Han, Zeyuan Chen 0002, Yuhong Nan, Juanru Li, Dawu Gu |
DSN | 4 |
| 2022 | SmartDagger: a bytecode-based static analysis approach for detecting cross-contract vulnerabilityabstractWith the increasing popularity of blockchain, automatically detecting vulnerabilities in smart contracts is becoming a significant problem. Prior research mainly identifies smart contract vulnerabilities without considering the interactions between multiple contracts. Due to the lack of analyzing the fine-grained contextual information during cross-contract invocations, existing approaches often produced a large number of false positives and false negatives. This paper proposes SmartDagger, a new framework for detecting cross-contract vulnerability through static analysis at the bytecode level. SmartDagger integrates a set of novel mechanisms to ensure its effectiveness and efficiency for cross-contract vulnerability detection. Particularly, SmartDagger effectively recovers the contract attribute information from the smart contract bytecode, which is critical for accurately identifying cross-contract vulnerabilities. Besides, instead of performing the typical whole-program analysis which is heavy-weight and time-consuming, SmartDagger selectively analyzes a subset of functions and reuses the data-flow results, which helps to improve its efficiency. Our further evaluation over a manually labelled dataset showed that SmartDagger significantly outperforms other state-of-the-art tools (i.e., Oyente, Slither, Osiris, and Mythril) for detecting cross-contract vulnerabilities. In addition, running SmartDagger over a randomly selected dataset of 250 smart contracts in the real-world, SmartDagger detects 11 cross-contract vulnerabilities, all of which are missed by prior tools. Zeqin Liao, Zibin Zheng, Yuhong Nan |
ISSTA | 4 |
| 2022 | Hazard Integrated: Understanding Security Risks in App Extensions to Team Chat Systems
Mingming Zha 0001, Jice Wang, Yuhong Nan, XiaoFeng Wang 0001, Yuqing Zhang 0001, Zelin Yang |
NDSS | 3 |
| 2022 | Security Evaluation of Smart Contracts based on Code and Transaction - A SurveyabstractAs a computer program running on top of blockchain, smart contract not only proliferates the diversity of applications but also brings a myriad of security issues that lead to huge financial losses. As a result, security evaluation of smart contracts, such as vulnerability identification and attack detection, has received extensive attention in recent years. Given that various types of approaches have been proposed for smart contract security analysis, a systematization of knowledge for this domain is needed. To this end, in this paper, we systematically review the related literature in recent years and describe the mainstream approaches to the security evaluation of smart contracts. Specifically, we classify state-of-the-art analysis techniques for smart contract analysis into two categories, namely, code-based approaches and transaction-based approaches. Further, we elaborate on the key techniques adopted by these works respectively. We highlight and summarize the key challenges in future research for smart contract security analysis. Our research provides a more in-depth understanding of the state-of-the-art works for securing smart contracts, which may shed light on future research in this area. Jianzhong Su, Jiyi Liu, Yuhong Nan |
ICSS | 3 |
| 2022 | ProFactory: Improving IoT Security via Formalized Protocol Customization
Fei Wang 0046, Jianliang Wu 0002, Yuhong Nan, Yousra Aafer, Xiangyu Zhang 0001, Dongyan Xu, Mathias Payer |
USENIX Security Symposium | 3 |
| 2021 | On the Insecurity of SMS One-Time Password Messages against Local Attackers in Modern Mobile Devices
Zeyu Lei, Yuhong Nan, Yanick Fratantonio, Antonio Bianchi |
NDSS | 2 |
| 2021 | ATLAS: A Sequence-based Learning Approach for Attack Investigation
Abdulellah Alsaheel, Yuhong Nan, Shiqing Ma, Gregory Walkup, Z. Berkay Celik, Xiangyu Zhang 0001, Dongyan Xu |
USENIX Security Symposium | 2 |
| 2021 | Understanding Malicious Cross-library Data Harvesting on Android
Jice Wang, Yue Xiao 0007, Xueqiang Wang, Yuhong Nan, Luyi Xing, Xiaojing Liao, Jinwei Dong, XiaoFeng Wang 0001, Yuqing Zhang 0001 |
USENIX Security Symposium | 4 |
| 2020 | BlueShield: Detecting Spoofing Attacks in Bluetooth Low Energy Networks
Jianliang Wu 0002, Yuhong Nan, Vireshwar Kumar, Mathias Payer, Dongyan Xu |
RAID | 2 |
| 2018 | How You Get Shot in the Back: A Systematical Study about Cryptojacking in the Real WorldabstractAs a new mechanism to monetize web content, cryptocurrency mining is becoming increasingly popular. The idea is simple: a webpage delivers extra workload (JavaScript) that consumes computational resources on the client machine to solve cryptographic puzzles, typically without notifying users or having explicit user consent. This new mechanism, often heavily abused and thus considered a threat termed "cryptojacking", is estimated to affect over 10 million web users every month; however, only a few anecdotal reports exist so far and little is known about its severeness, infrastructure, and technical characteristics behind the scene. This is likely due to the lack of effective approaches to detect cryptojacking at a large-scale (e.g., VirusTotal). In this paper, we take a first step towards an in-depth study over cryptojacking. By leveraging a set of inherent characteristics of cryptojacking scripts, we build CMTracker, a behavior-based detector with two runtime profilers for automatically tracking Cryptocurrency Mining scripts and their related domains. Surprisingly, our approach successfully discovered 2,770 unique cryptojacking samples from 853,936 popular web pages, including 868 among top 100K in Alexa list. Leveraging these samples, we gain a more comprehensive picture of the cryptojacking attacks, including their impact, distribution mechanisms, obfuscation, and attempts to evade detection. For instance, a diverse set of organizations benefit from cryptojacking based on the unique wallet ids. In addition, to stay under the radar, they frequently update their attack domains (fastflux) on the order of days. Many attackers also apply evasion techniques, including limiting the CPU usage, obfuscating the code, etc. Geng Hong, Zhemin Yang, Sen Yang 0011, Lei Zhang 0096, Yuhong Nan, Zhibo Zhang 0006, Min Yang 0002, Yuan Zhang 0009, Zhiyun Qian, Hai-Xin Duan |
CCS | 5 |
| 2018 | Finding Clues for Your Secrets: Semantics-Driven, Learning-Based Privacy Discovery in Mobile Apps
Yuhong Nan, Zhemin Yang, XiaoFeng Wang 0001, Yuan Zhang 0009, Donglai Zhu, Min Yang 0002 |
NDSS | 1 |
| 2017 | Identifying User-Input Privacy in Mobile Applications at a Large ScaleabstractIdentifying sensitive user inputs is a prerequisite for privacy protection in mobile applications. When it comes to today's program analysis systems, however, only those data that go through well-defined system Application Program Interface (system controlled resources) can be automatically labeled. In this paper, we show that this conventional approach is far from adequate, as most sensitive inputs are actually entered by the user at an app's runtime. In this paper, we inspect 13,072 top apps from Google Play, and find that 38.69% of them involve sensitive user inputs. Just like system controlled resources, these data are also exposed to a series of privacy leakage threats. For these sensitive user inputs, manually marking them involves a lot of efforts, impeding a large-scale, automated analysis of apps to defend against potential privacy leakage. To address this important issue, we present UIPicker, an adaptable framework for automatic identification of sensitive user inputs as the first step. UIPicker is designed to detect the semantic information within the application layout resources and the program code, and further analyze it for the locations where security-critical information may show up. This approach can support a variety of existing security analysis on mobile apps. We evaluate our approach over randomly selected popular apps on Google Play. UIPicker is able to accurately label sensitive user inputs most of the time, with 94.0% precision and 96.0% recall. Yuhong Nan, Zhemin Yang, Min Yang 0002, Shunfan Zhou, Yuan Zhang 0009, Guofei Gu, XiaoFeng Wang 0001, Limin Sun 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2015 | UIPicker: User-Input Privacy Identification in Mobile Applications
Yuhong Nan, Min Yang 0002, Zhemin Yang, Shunfan Zhou, Guofei Gu, XiaoFeng Wang 0001 |
USENIX Security Symposium | 1 |